AEGIS Draft RFP Sections A-M.pdf
PDF 23 MB Posted
- Attached to
- Advanced Enterprise Global Information Technology (IT) Solutions (AEGIS) Federal contract opportunity
- Solicitation number
- 80JSC020R0039
About this file
This notice provides details for the Advanced Enterprise Global Information Technology (IT) Solutions (AEGIS) Draft Request for Proposal (DRFP). The National Aeronautics and Space Administration Johnson Space Center intends to issue a solicitation for AEGIS as a hybrid Cost-Plus Award-Fee contract with Firm-Fixed-Price, Award Term, and Firm-Fixed-Price Indefinite-Delivery Indefinite Quantity Task Orders. The purpose of the AEGIS contract is to serve as a follow-on to the current NASA Integrated Communications Services contract by supporting the agency with high-quality, reliable, and cost-effective telecommunications systems and services. Prospective offerors are invited to comment on all aspects of the DRFP by August 21, 2020. Relevant documents and information can be found on the AEGIS website and related technical library.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Industry Q and A of AEGIS Draft RFP.pdf | ||
| AEGIS Draft RFP J-Attachments.pdf | ||
| ATT L-8 Cost Price Templates.xlsx | XLSX spreadsheet | |
| BJ-20-023 - AEGIS DRFP Cover Letter.pdf | ||
| AEGIS Draft RFP L-Attachments.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT PRICE AMOUNT
CONTINUATION SHEET REFERENCE NO. OF DOCUMENT BEING CONTINUED
NAME OF OFFEROR OR CONTRACTOR
(A) (B) (C) (D) (E) (F)
UNIT
OPTIONAL FORM 336 (4-86)
Sponsored by GSA FAR (48 CFR) 53.110
Page of
80JSC020R0039
Advanced Enterprise Global Information
Technology (IT) Solutions (AEGIS)
80JSC020R0039
A-1
SECTION A - SOLICITATION/CONTRACT FORM
TABLE OF CONTENTS
PART I – THE SCHEDULE
SECTION A – SOLICITATION/CONTRACT FORM, (STANDARD FORM 33)
SECTION B – SUPPLIES OR SERVICES AND PRICES/COSTS
SECTION C – DESCRIPTIONS/SPECIFICATIONS/STATEMENT OF WORK
SECTION D – PACKAGING AND MARKING
SECTION E – INSPECTION AND ACCEPTANCE
SECTION F – DELIVERIES OR PERFORMANCE
SECTION G – CONTRACT ADMINISTRATION DATA
SECTION H – SPECIAL CONTRACT REQUIREMENTS
PART II – CONTRACT CLAUSES
SECTION I – CONTRACT CLAUSES
PART III – LIST OF DOCUMENTS, EXHIBITS, AND OTHER ATTACHMENTS
SECTION J – LIST OF ATTACHMENTS
PART IV – REPRESENTATIONS AND INSTRUCTIONS
SECTION K – REPRESENTATIONS, CERTIFICATIONS, AND OTHER STATEMENTS
OF OFFERORS OR RESPONDENTS
SECTION L – INSTRUCTIONS, CONDITIONS, AND NOTICES TO OFFERORS OR
RESPONDENTS
SECTION L – ATTACHMENTS
SECTION M – EVALUATION FACTORS FOR AWARD
B-1
SECTION B - SUPPLIES OR SERVICES AND PRICES/COSTS
B.1 LISTING OF CLAUSES INCORPORATED BY REFERENCE
I. FEDERAL ACQUISITION REGULATION (48 CFR CHAPTER 1)
CLAUSE
NUMBER
DATE TITLE
None included by reference
II. NASA FAR SUPPLEMENT (48 CFR CHAPTER 18) CLAUSES
CLAUSE
NUMBER
DATE TITLE
None included by reference
(End of clause)
B.2 CONTRACT TYPE
This contract is a single award hybrid contract consisting of Cost-Plus Award Fee (CPAF) for the Core AEGIS requirements, with Award Term (AT), and Firm-Fixed-Price (FFP), with a FFP Indefinite-Delivery-Indefinite-Quantity (IDIQ) feature.
B.3 1852.216-78 FIRM FIXED PRICE (DEC 1988)
The total firm fixed price of this contract is $ [OFI].
B.4 1852.216-85 ESTIMATED COST AND AWARD FEE (SEP 1993)
The estimated cost of this contract is $[OFI]. The maximum available award fee, excluding base fee, if any, is $[OFI]. The base fee is $0. Total estimated cost, base fee, and maximum award fee are $[OFI].
B.5 CONTRACT VALUE
The total contract value is as follows:
B-2
Table B-1: Base Period (2-Years)
Firm-Fixed- Price
Estimated Cost
Maximum Award Fee Available
Earned Award Fee
Total Contract Value
FFP Phase-In $[OFI] N/A N/A N/A $[OFI]
CPAF N/A $[OFI] $[OFI] [TBD] $[OFI]
FFP $[OFI] N/A N/A N/A $[OFI]
FFP IDIQ $[TBD] N/A N/A N/A $[TBD]
Total Contract Value $[OFI] $[OFI] $[OFI] N/A $[OFI]
Table B-2: Total Contract Value
Firm- Fixed-Price FFP IDIQ Estimated
Cost
Maximum Award Fee Available
Total Contract Value
FFP Phase-In $[OFI] N/A N/A N/A $[OFI] Base Period (CY1 and 2)
$[OFI] N/A $[OFI] $[OFI] $[OFI]
Option 1
(CY3)
$[OFI] N/A $[OFI] $[OFI] $[OFI]
Award Term
1 (CY4)
$[OFI] N/A $[OFI] $[OFI] $[OFI]
Award Term
2 (CY5)
$[OFI] N/A $[OFI] $[OFI] $[OFI]
Award Term
3 (CY6)
$[OFI] N/A $[OFI] $[OFI] $[OFI]
Award Term
4 (CY7)
$[OFI] N/A $[OFI] $[OFI] $[OFI]
Award Term
5 (CY8)
$[OFI] N/A $[OFI] $[OFI] $[OFI]
Award Term
6 (CY9)
$[OFI] N/A $[OFI] $[OFI] $[OFI]
Award Term
7 (CY10)
$[OFI] N/A $[OFI] $[OFI] $[OFI]
Total Contract Value
$[OFI]
N/A
$[OFI] $[OFI] $[OFI]
B.6 1852.232-81 CONTRACT FUNDING (JUN 1990)
(a) For purposes of payment of cost, exclusive of fee, in accordance with the Limitation of Funds clause, the total amount allotted by the Government to this contract is $[TBD]. This allotment is for Advanced Enterprise Global IT Solutions and covers the following estimated period of performance: [TBD].
B-3
(b) An additional amount of $[TBD] is obligated under this contract for payment of fee.
B.7 IDIQ RATES
(Will be provided for final as an OFI table)
B.8 CORPORATE COLLABORATIVE SERVICES UNIT PRICES
The prices are to be quoted Firm Fixed Price (FFP) for hardware requirement specified including labor for support and installation. Consumables including labor used in the design and installation or refresh of a VITS room shall be borne by NASA as actual consumable costs based on quote/line item (consumable pricing established via CRQ). Consumable replacements (i.e.
projector bulbs, cables, etc.) to be funded by NASA. Quote hardware replacement if items cannot be repaired, cost to be funded by NASA.
(Will be provided for final as an OFI table)
[END OF SECTION]
C-1
SECTION C - DESCRIPTION/SPECIFICATIONS/STATEMENT OF WORK
C.1 DESCRIPTION/SPECIFICATIONS/PERFORMANCE WORK STATEMENT
(End of Clause)
AEGIS
C-2
Table of Contents
1 ADVANCED ENTERPRISE GLOBAL INFORMATION TECHNOLOGY (IT) SOLUTIONS
(AEGIS)
1.1 INTRODUCTION AND OVERVIEW
1.2 GOALS AND OBJECTIVES
1.3 GOVERNMENT-RETAINED AUTHORITIES
1.4 PERFORMANCE WORK STATEMENT (PWS) OVERVIEW
2 CONTRACT MANAGEMENT
2.1 PROGRAM MANAGEMENT
2.2 CRITICAL STAFFING POSITIONS
2.3 FINANCIAL MANAGEMENT
2.4 LOGISTICS
2.4.1 PROPERTY/INVENTORY MANAGEMENT
2.4.2 SHIPPING/RECEIVING/INSPECTION SERVICES
2.4.3 VEHICLES
2.5 CONTRACT PHASE-IN MANAGEMENT
2.6 PROCUREMENT SERVICES
2.6.1 PROCUREMENT SERVICES FOR DATA CENTER
2.7 PHYSICAL SECURITY MANAGMENT AND CYBERSECURITY MANAGEMENT
2.7.1 PHYSICAL SECURITY MANAGEMENT
2.7.2 CYBERSECURITY MANAGEMENT
2.8 EXPORT CONTROL
2.9 EMERGENCY MANAGEMENT
2.10 SAFETY, HEALTH AND ENVIRONMENTAL (SHE) MANAGEMENT
2.11 FACILITY MANAGEMENT
2.12 QUALITY ASSURANCE AND MANAGEMENT
2.13 CONTRACT AND SUBCONTRACT ADMINISTRATION
2.13.1 GSA CONTRACT INTEGRATION
3 INNOVATION SERVICES
3.1 GENERAL
3.1.1 DEFINITION
3.1.2 PURPOSE
3.1.3 INNOVATION ACTIVITIES
3.1.4 INNOVATION PRINCIPLES
3.1.5 COOPERATIVE COMMITMENT
3.2 INNOVATION PROCESS
3.2.1 INNOVATION RELATIONSHIP MANAGEMENT
3.2.2 AUDIENCE AND STAKEHOLDERS
3.2.3 TOOLS AND METHODS
3.3 WORKSHOPS
3.4 WORKSHOP PARTICIPATION
3.5 WORKSHOP PREPARATION
3.6 BUSINESS AND IT MONITORING WORKSHOP PROCESS
3.7 INNOVATION VISIONING WORKSHOP PROCESS
3.8 INNOVATION VISIONING WORKSHOP PROCESS
3.9 BUSINESS CONTEXT AND CHOICES WORKSHOP PROCESS
C-3
3.10 ACTION WORKSHOP PROCESS
3.11 ROLES AND RESPONSIBILITIES
4 IT SERVICE MANAGEMENT
4.1 SERVICE DELIVERY SUPPORT
4.2 SERVICE DESIGN AND IMPLEMENTATION
4.3 SERVICE OPERATIONS
4.4 INCIDENT MANAGEMENT
4.5 PROBLEM MANAGEMENT
4.6 PERFORMANCE MANAGEMENT
4.7 REPORTING
4.8 MAINTENANCE
4.9 PROGRAMMATIC RISK ANALYSIS
4.10 CONFIGURATION MANAGEMENT
4.11 CUSTOMER RELATIONSHIP MANAGEMENT
4.12 CRM APPLICABLE TO CP NASCOM MISSION SERVICES
5 ENTERPRISE SERVICES
5.1 ENTERPRISE CROSS-CUTTING SERVICES
5.1.1 DNS DYNAMIC HOST CONFIGURATION PROTOCOL (DHCP) INTERNET
PROTOCOL ADDRESS MANAGEMENT (IPAM) (DDI)
5.1.2 LAYER 2 BACKBONE SERVICES
5.1.3 ENTERPRISE SERVICE PROGRAM INTEGRATION
5.1.4 CABLE PLANT SERVICES
5.2 ENTERPRISE CP CORPORATE SERVICES
5.2.1 CORPORATE VOICE SERVICES
5.2.2 CORPORATE DATA SERVICES
5.2.3 CORPORATE COLLABORATIVE SERVICES
5.2.4 SYSTEM AND SOFTWARE ADMINISTRATION
5.2.5 VOIP/TELEPHONE SERVICES
5.2.6 ENTERPRISE VIDEO CONTENT DELIVERY NETWORK (EVCDN)
5.2.7 CORPORATE MANAGEMENT AND OPERATIONS
5.3 CP NASA COMMUNICATIONS (CP NASCOM) MISSION SERVICES
5.3.1 NASCOM MISSION ENGINEERING AND SERVICE DELIVERY
5.3.2 CP NASCOM MISSION DATA SERVICES
5.3.3 CP NASCOM MISSION SYSTEMS ADMINISTRATION AND SOFTWARE
DEVELOPMENT
5.3.4 INSTALLATION AND MAINTENANCE OF CP NASCOM INFRASTRUCTURE
5.3.5 MISSION FACILITIES MANAGEMENT OF CP NASCOM INFRASTRUCTURE
5.3.6 CP NASCOM PHYSICAL SECURITY
5.3.7 CP NASCOM MISSION MANAGEMENT AND OPERATIONS
6 INFRASTRUCTURE PROJECTS
6.1 INDEFINITE DELIVERY INDEFINITE QUANTITY (IDIQ) PROJECTS
6.2 INTERNET PROTOCOL TELEVISION (IPTV) PROJECT
6.3 SOFTWARE DEFINED NETWORK (SDN)/INTENT BASED NETWORK (IBN)
ENTERPRISE DEPLOYMENT PROJECT
6.4 MISSION NEXT GENERATION VOICE (MNGV) PROJECT
7 CENTER AND ASSOCIATED COMPONENT FACILITY SERVICES
7.1 AMES RESEARCH CENTER (ARC)
C-4
7.1.1 Cellular Redistribution Services
7.1.2 Emergency Warning Systems
7.1.3 Public Address Systems
7.1.4 Radio Services
7.1.5 Cable Television Services
7.1.6 Cable Plant Services
7.1.7 VoIP/Telephone Services
7.1.8 Electronic Physical Access Control Systems
7.1.9 Emergency Telecommunications
7.2 ARMSTRONG FLIGHT RESEARCH CENTER (AFRC)
7.2.1 Cellular Redistribution Services
7.2.2 Emergency Warning Systems
7.2.3 Public Address Systems
7.2.4 Radio Services
7.2.5 Cable Television Services
7.2.6 Cable Plant Services
7.2.7 VoIP/Telephone Services
7.2.8 Electronic Physical Access Control Systems
7.2.9 Emergency Telecommunications
7.3 GLENN RESEARCH CENTER (GRC)
7.3.1 Cellular Redistribution Services
7.3.2 Emergency Warning Systems
7.3.3 Public Address Systems
7.3.4 Radio Services
7.3.5 Cable Television Services
7.3.6 Cable Plant Services
7.3.7 VoIP/Telephone Services
7.3.8 Electronic Physical Access Control Systems
7.3.9 Emergency Telecommunications
7.4 GODDARD SPACE FLIGHT CENTER (GSFC)
7.4.1 Cellular Redistribution Services
7.4.2 Emergency Warning Systems
7.4.3 Public Address Systems
7.4.4 Radio Services
7.4.5 Cable Television Services
7.4.6 Cable Plant Services
7.4.7 VoIP/Telephone Services
7.4.8 Electronic Physical Access Control Systems
7.4.9 Emergency Telecommunications
7.5 HEADQUARTERS (HQ)
7.5.1 Cellular Redistribution Services
7.5.2 Emergency Warning Systems
7.5.3 Public Address Systems
7.5.4 Radio Services
7.5.5 Cable Television Services
7.5.6 Cable Plant Services
7.5.7 VoIP/Telephone Services
7.5.8 Electronic Physical Access Control Systems
7.5.9 Emergency Telecommunications
C-5
7.6 JET PROPULSION LABORATORY (JPL)
7.6.1 Cellular Redistribution Services
7.6.2 Emergency Warning Systems
7.6.3 Public Address Systems
7.6.4 Radio Services
7.6.5 Cable Television Services
7.6.6 Cable Plant Services
7.6.7 VoIP/Telephone Services
7.6.8 Electronic Physical Access Control Systems
7.6.9 Emergency Telecommunications
7.7 JOHNSON SPACE FLIGHT CENTER (JSC)
7.7.1 Cellular Redistribution Services
7.7.2 Emergency Warning Systems
7.7.3 Public Address Systems
7.7.4 Radio Services
7.7.5 Cable Television Services
7.7.6 Cable Plant Services
7.7.7 VoIP/Telephone Services
7.7.8 Electronic Physical Access Control Systems
7.7.9 Emergency Telecommunications
7.8 KENNEDY SPACE CENTER (KSC)
7.8.1 Cellular Redistribution Services
7.8.2 Emergency Warning Systems
7.8.3 Public Address Systems
7.8.4 Radio Services
7.8.5 Cable Television Services
7.8.6 Cable Plant Services
7.8.7 VoIP/Telephone Services
7.8.8 Electronic Physical Access Control Systems
7.8.9 Emergency Telecommunications
7.9 LANGLEY RESEARCH CENTER (LARC)
7.9.1 Cellular Redistribution Services
7.9.2 Emergency Warning Systems
7.9.3 Public Address Systems
7.9.4 Radio Services
7.9.5 Cable Television Services
7.9.6 Cable Plant Services
7.9.7 VoIP/Telephone Services
7.9.8 Electronic Physical Access Control Systems
7.9.9 Emergency Telecommunications
7.10 MARSHALL SPACE FLIGHT CENTER (MSFC)
7.10.1 Cellular Redistribution Services
7.10.2 Emergency Warning Systems
7.10.3 Public Address Systems
7.10.4 Radio Services
7.10.5 Cable Television Services
7.10.6 Cable Plant Services
7.10.7 VoIP/Telephone Services
7.10.8 MSFC and MAF Physical Access Control Systems
C-6
7.10.9 Emergency Telecommunications
7.10.10 Facsimile Services at MSFC and MAF
7.10.11 Lab Services
7.10.12 Customer Driven Specialized IT Solutions
7.11 NASA SHARED SERVICES CENTER (NSSC)
7.11.1 Cellular Redistribution Services
7.11.2 Emergency Warning Systems
7.11.3 Public Address Systems
7.11.4 Radio Services
7.11.5 Cable Television Services
7.11.6 Cable Plant Services
7.11.7 VoIP/Telephone Services
7.11.8 Electronic Physical Access Control Systems
7.11.9 Emergency Telecommunications
7.12 STENNIS SPACE CENTER (SSC)
7.12.1 Cellular Redistribution Services
7.12.2 Emergency Warning Systems
7.12.3 Public Address Systems
7.12.4 Radio Services
7.12.5 Cable Television Services
7.12.6 Cable Plant Services
7.12.7 VoIP/Telephone Services
7.12.8 Electronic Physical Access Control Systems
7.12.9 Emergency Telecommunications
8 AGENCY-WIDE ASSOCIATED COMPUTING SERVICES (AWACS)
8.1 AGENCY DATA CENTER CONSOLIDATION (ADCC)
8.2 ENTERPRISE MANAGED CLOUD COMPUTING (EMCC)
8.3 AGENCY DATA CENTER MANAGEMENT AND OPERATIONS
8.3.1 AGENCY DATA CENTER CONSOLIDATION (ADCC)
8.3.2 ENTERPRISE MANAGED CLOUD COMPUTING (EMCC)
8.4 MANAGED CLOUD ENVIRONMENT (MCE) ARCHITECTURE DEVELOPMENT,
ENGINEERING, IMPLEMENTATION, MANAGEMENT, AND OPERATIONS
8.4.1 MANAGED CLOUD ENVIRONMENT DELIVERY AND MANAGEMENT
8.4.2 COMPUTE
8.4.3 STORAGE
8.4.4 OBJECT STORAGE SERVICE CRITERIA
8.4.5 FILE STORAGE SERVICE CRITERIA
8.4.6 CONTINUOUS DIAGNOSTICS AND MONITORING
8.4.7 MCE CONFIGURATION MANAGEMENT
8.4.8 ENVIRONMENT IMPROVEMENTS AND COST EFFICIENCIES
8.4.9 ABSTRACTED COMPUTE SERVICES CRITERIA
8.4.10 CLOUD ARCHITECTURE AND ENGINEERING (SOLUTIONS, SECURITY AND
NETWORK)
8.5 DATA CENTER MANAGEMENT AND OPERATIONS
8.5.1 GENERAL FOR CIO DATA CENTERS
8.5.2 ENTERPRISE DATA CENTER MANAGEMENT AND OPERATIONS
8.6 DATA CENTER NETWORKS (DCNS)
8.6.1 NETWORK
8.7 AGENCY DATA CENTER AND COMPUTING SERVICES
C-7
8.7.1 IT INFRASTRUCTURE, COMPUTING AND CLOUD SERVICES
8.7.2 CONTINUITY OF OPERATIONS (COOP) PLAN
8.7.3 CUSTOMER SERVICE, CHANGE REQUESTS (CRS) AND TIER 1 HELP DESK
SUPPORT
8.7.4 ENGINEERING SUPPORT
8.7.5 SYSTEMS BUILD, INTEGRATION, AND TESTING
8.7.6 INSTALLATION
8.7.7 ASSESSMENT AND ACCEPTANCE TESTING
8.7.8 SYSTEMS ADMINISTRATION
8.7.9 OPERATIONS
8.7.10 HIGH PERFORMANCE COMPUTING SUPPORT
8.7.11 BACKUP AND STORAGE
8.7.12 LARGE SCALE DATA STORAGE AND RETRIEVAL SYSTEM
8.7.13 MEDIA OPERATIONS ROLES AND RESPONSIBILITIES
8.7.14 HARDWARE, CLOUD AND SYSTEMS SOFTWARE MAINTENANCE
8.7.15 PREVENTIVE MAINTNANCE (PM)
8.7.16 REMEDIAL MAINTENANCE (RM)
8.7.17 SYSTEM SOFTWARE AND HARDWARE UPGRADES/ENHANCEMENTS
8.7.18 IT SYSTEM CONFIGURATION MANAGEMENT
8.7.19 DATABASE ADMINISTRATION
8.7.20 INSTALLATION OF DATABASE SOFTWARE AND TOOLS
8.7.21 DATABASE ADMINISTRATION – DATABASE CREATION/BUILD
8.7.22 DATABASE ADMINISTRATION – SECURITY
8.7.23 DATABASE ADMINISTRATION – AVAILABILITY
8.7.24 MONITORING AND CONFIGURING DATABASE ENGINES AND TOOLS
8.7.25 DATABASE CAPACITY PLANNING & PERFORMANCE
8.7.26 DATABASE ARCHIVING AND RESTORING
8.7.27 SECURITY OF DATABASES AND INSTANCES
8.7.28 DATABASE CHANGE ASSESSMENT AND IMPLEMENTATION
8.7.29 DATABASE DOCUMENTATION AND ACCOUNT MANAGEMENT
8.7.30 MIDDLEWARE AND INFRASTRUCTURE ADMINISTRATION
8.7.31 CYBERSECURITY ADMINISTRATION
8.7.32 CONFIGURATION MANAGEMENT (CM) AND CONTROL
8.7.33 DATA CENTER MANAGEMENT AND CONTROL
8.7.34 FACILITY ACCESS
8.7.35 FACILITIES MANAGEMENT
8.7.36 ELECTRICAL AND MECHANICAL SYSTEMS
8.7.37 DISTRIBUTED SYSTEMS AT OTHER NASA CENTERS
8.7.38 CUSTOMER DRIVEN SPECIALIZED IT SOLUTIONS FOR LABS OR MISSION
AREAS 140
8.7.39 CUSTOMER UNIQUE IT SUPPORT SERVICE FOR LABS OR MISSION AREAS .. 142
8.7.40 OCIO DATA SERVICES
8.7.41 JSC’S USE OF CLOUD TECHNICAL ENVIRONMENTS (CTES)
9 SPECIALIZED SERVICES
9.1 HYPERSONIC NETWORK SUPPORT
9.2 RUSSIA SERVICES
9.2.1 RUSSIA IT END-USER SUPPORT
9.2.2 RUSSIA CYBERSECURITY
9.2.3 BI-ANNUAL CONGRESSIONAL REPORTING
C-8
9.2.4 TIER 1 SERVICE DESK SUPPORT
9.3 NASA NATIONAL SECURITY SYSTEMS (NSS) SERVICE IT SUPPORT
9.4 NASA IMAGERY EXPERTS PROGRAM (NIEP) OFFICE ENGINEERING SERVICES .. 151
9.5 UNIQUE VIDEO SERVICES (UVS)
9.5.1 VIDEO CLOSED CAPTIONING SERVICES
9.6 HUNTSVILLE OPERATIONS SUPPORT CENTER (HOSC) NETWORK SERVICES
10 ENTERPRISE CYBERSECURITY SUPPORT SERVICES
10.1 REMOTE ACCESS SERVICES (RAS)
10.2 NETWORK ACCESS CONTROL (NAC)
10.3 FIREWALL SERVICES
10.4 PROXY SERVICES
10.5 CONTINUOUS DIAGNOTICS & MITIGATION (CDM) AND CYBERSECURITY &
POLICY DIVISION (CSPD) SUPPORT
10.6 CORPORATE CYBERSECURITY SUPPORT SERVICES
10.6.1 Intrusion Detection Systems and Incident Response Support
10.6.2 Cybersecurity Perimeter
10.7 MISSION CYBERSECURITY SUPPORT SERVICES
10.8 CENTER LEVEL CYBERSECURITY AND PRIVACY PROGRAM SERVICES
10.8.1 Center Level Cybersecurity & Privacy Program Services
10.8.2 GSFC Cybersecurity Support Services
10.8.3 AFRC Cybersecurity Support Services
10.8.4 MSFC IT and Security
C-9
1 ADVANCED ENTERPRISE GLOBAL INFORMATION TECHNOLOGY (IT)
SOLUTIONS (AEGIS)
1.1 INTRODUCTION AND OVERVIEW
The National Aeronautics and Space Administration (NASA) Office of the Chief Information Officer’s (OCIO) mission is to increase the productivity of employees, including but not limited to scientists, engineers, and mission support personnel, by responsively and efficiently delivering reliable, innovative, and secure Information Technology (IT) services. Within the OCIO there are six program offices:
Cybersecurity and Privacy, Data Center/Computing Services, End-User Services, Applications, Communications, and Information Management. The Communications Program (CP) oversees the portfolio of services and capabilities associated with communications domain which includes defining and executing overall strategy, roadmaps, standards, policies, investments and projects.
To support NASA, the CP provides high-quality, reliable, cost-effective telecommunications systems and services. Customers include all NASA facilities, flight projects and programs, as well as national and international partners. CP provides Wide Area Network (WAN) services to support administrative applications, such as email, general Internet connectivity, agency-wide Domain Name System (DNS) and Internet Protocol (IP) address management, access to Cloud-based and NASA data center applications, voice and video conferencing, and collaboration tools that enable NASA’s workforce. CP engineers and provides support to enterprise Cybersecurity employing infrastructure tools and capabilities to include Remote Access, Network Access Control (NAC), Firewall and Web Application Firewall Services, Virtual Private Networks (VPNs), Intrusion Prevention Systems (IPS), Intrusion Detection Systems, NASA SOC Incident Response process, Continuous Diagnostics & Mitigation (CDM) and Cybersecurity & Privacy Program (CSPP). CP also provides local services to NASA Centers that include Local Area Networks (LANs), voice systems, radio systems, Public Address (PA) Systems, Emergency Notification Systems (ENS), cable television and Cable Plant Services. The CP provides mission critical data and voice services to connect Flight Projects to Space Communications and Network (SCaN) Tracking Networks and other resources, including, but not limited to, Space Network (SN), Near Earth Network (NEN), Deep Space Network (DSN), Flight Dynamics Facility (FDF), Launch Complexes and satellite manufacturer and test facilities. CP’s Mission Services directly support Human Space Flight (HSF) and the International Space Station (ISS), including in-country Russia IT Services.
The Contractor shall support the OCIO in advancing NASA’s communications services to provide secure enterprise network management and flexible communications services for NASA. More specifically, the Contractor shall partner with the CP to work with the various OCIO and Mission programs to provide secure and innovative solutions for both mission and mission support customers that are highly secure, cost effective, and advanced such that they increase ability to securely collaborate between NASA and NASA partners beyond current capabilities.
NASA considers its IT communications infrastructure assets vital to its continuing success as the world leader in aeronautics, space exploration, and scientific research and to advance NASA’s mission to the moon and Mars. NASA personnel use IT to support NASA’s core business, HSF, scientific, research, and computational activities. It is imperative that the commercial sector deliver secure and cost-effective IT services that meet NASA mission and program needs while achieving efficiency and high-level customer satisfaction.
C-10
1.2 GOALS AND OBJECTIVES
AEGIS will continue Operations and Maintenance of NASA’s Communications Infrastructure through Information Technology products and services that provide assets vital to its continuing success as the world leader in aeronautics, space exploration, and scientific research; and to advance NASA’s mission to the moon, Mars, and beyond. AEGIS will include end-to-end seamless communications network and infrastructure that encompasses both WAN and Center LAN, Telecommunications, Cybersecurity support, on-premises and Managed Cloud Data Center Resources, online Collaboration tools, Cable Plant, Emergency and Early Warning and Notification Systems, Telephony, and Radio systems. The OCIO has established the following as goals of the AEGIS contract.
Accountability: Be a trusted partner by providing timely and high-quality secure communication infrastructure services, being accountable to not only the OCIO but also to the NASA programs and their mission success.
Effectiveness: Consistently provide stakeholders communication infrastructure services that meet customer requirements, are efficient, and of a high quality. Successful effectiveness will be measured against industry standards and demonstrated by increased consumption of services.
Innovation: Bring innovative, secure solutions to our stakeholders, including modernizing existing services. Continually improve communications services and methods for service delivery, cost effectiveness and operations that enable and advance NASA’s missions and program.
Highly Secure Solutions: Design, operate, and deploy network solutions that enhance
Cybersecurity posture and visibility while enabling near real-time response.
The OCIO is looking to increase the use of network automation to increase operational efficiency and Cybersecurity, to incorporate device and end-user identity and credential management as a basis for network enrollment and connectivity to resources, and to implement network solutions that allow automated segmentation or isolation of network traffic based upon machine learning and other data analytics in compliance with NASA policy.
In compliance with the Federal IT Acquisition Reform Act (FITARA), Federal regulations, Supply Chain Risk Management (SCRM) and OCIO policies and guidelines, the Contractor shall improve its engagement with NASA missions and programs through effective partnership and delivery of quality mission-critical communications, devices, and services while maintaining NASA mission and programmatic governance and compliance.
The Contractor shall provide innovative business, management, and secure technical solutions in the delivery of cost-effective communications services to our customers that reduce cost, improve collaboration, and enhanced Cybersecurity posture.
1.3 GOVERNMENT-RETAINED AUTHORITIES
NASA will retain a set of key authorities that encompass the overall service strategy and service design related to IT communications infrastructure services. NASA will also retain authority for all demand management (management of suppliers and customers), governance, and approval functions associated
C-11 with AEGIS. In addition, NASA shall perform key roles in Customer Relationship Management (CRM), as delineated in PWS 4.1, Customer Relationship Management.
To assure maintenance of the NASA IT architectural configuration, the contractor shall follow the process set forth in NASA Policy Directive (NPD) 2800.1E, Managing Information Technology. The contractor shall bring recommendations for changes to the NASA IT architecture and standards to the attention of the AEGIS Contracting Officer’s Representative (COR). The AEGIS COR is responsible for ensuring that the review and approval process is conducted in compliance with NPD 2800.1E, Managing Information Technology.
In addition to Project Office Configuration Control Boards (CCBs), which are Government Retained, each Center or associated component facility may convene their local CCB, which will include an AEGIS contractor representative. Functions of the CCB include approving proposed changes to local architectures and standards, to ensure consistency with Agency interoperability and compatibility standards.
1.4 PERFORMANCE WORK STATEMENT (PWS) OVERVIEW
Within this framework, the contractor's mission is to provide secure IT services to meet the requirements as defined by this PWS. The PWS consists of the following sections:
a. Contract Management: These services include Program Management, financial management, logistics, contract Phase-In/Transition management, procurement, Physical security management and Cybersecurity management, safety, health & environmental management, Facilities Management, quality assurance and management, program integration, other interface points, and contract and subcontract administration.
b. Innovation Services: These services include continuous improvement for ongoing effort to enhance the efficiency and effectiveness of the IT and Cybersecurity services that drives the agreed and committed year-over-year cost efficiency improvements, and innovation to identify and implement new ideas and break-through solutions that change and/or enhance the services and results in IT and Cybersecurity transformation through automation.
c. Service Management: These services and operations processes shall align with the current version of the Information Technology Infrastructure Library (ITIL) IT Service Management Framework to establish common terminology and processes.
d. Enterprise Services: Enterprise services encompasses both corporate and mission services (defined below) with crosscutting areas into both corporate and mission. These services include network services, voice services, data services, collaboration services, corporate management and operations, Mission Services, Mission Management and Operations, Customer Relationship Management, Service Management, Strategy Generation, Cybersecurity support, General Services Administration (GSA) contract integration, Cable Plant Services, and Voice over Internet Protocol (VoIP)/telephone services. This is to include WAN and LAN communication services at all NASA Centers and associated component facilities.
1. Enterprise Cross-Cutting Services: Refers to services that span across both Corporate and Mission service areas
2. Corporate Services: Includes Enterprise and Center-unique administrative voice, video, and data services in support of NASA’s mission, programmatic and institutional communications needs.
3. Mission Services: Includes support for the Agency’s ground communications infrastructure for spacecraft control and operations. It is comprised of a world-
C-12 wide complex of systems and capabilities which have been designed to carry real-time mission data and voice services.
e. Center and Associated Component Facility Services: These services include Center and associated component facility-specific services such as Emergency Warning System (EWS), PA System, radio, and Cable Television (CATV).
f. Infrastructure Projects: This activity includes both continuation and new projects and shall include all the effort to perform projects such as Internet Protocol Television, Software Defined Access Enterprise Deployment, Mission Next Generation Voice and other NASA-approved projects. These projects shall be accomplished in accordance with NASA Interim Directive (NID) 7120.99, NASA Information Technology and Institutional Infrastructure Program and Project Management Requirements.
g. Agency Computing Services: These services include the operating and maintaining of agency data centers, including asset inventory and analyzing NASA’s data center performance against NASA policy, Office of Management and Budget (OMB) directed performance metrics by the Agency Data Center Consolidation (ADCC) team and the facilitation of broad adoption of commercial cloud computing across NASA through the Computing Services Program’s Enterprise Managed Cloud Computing (EMCC) capability.
Services that are included are as follows:
1. Computing Services
1.1. Compute as a Service (CaaS) - Provisioning, maintenance, monitoring and administration of virtual or cloud servers configured to customer requirements for application hosting.
1.2. Kubernetes Platform as a Service (KPaaS) - Managed Kubernetes Linux container environment for deployment of customer’s containerized applications.
1.3. Infrastructure as a Service (IaaS) - A pool of virtual or cloud IT resources that the customer can configure and manage as needed.
1.4. Storage Services - Tiered, networked, fault tolerant, file, block, and object storage resources on-premises and in the cloud.
C-13
1.5. Database Services - Managed database systems and services including database administration, DBMS software and associated database tools both on-premises and in the cloud.
1.6. Government Funded Equipment (GFE) support services - System administration and other software services associated with the maintenance of GFE such as engineering workstations, lab connected servers, etc.
1.7. Lab Support Services - System administration and infrastructure services for “data center” like requirements in labs and other mission areas.
1.8. Data Center Housing Services –
1.8.1 Housing of customer computing infrastructure, including data center network access.
1.8.2 Install, move, add, and change (IMAC) customer hardware.
1.9. Brokered Cloud Services - Abstracted High-level, Cloud Native, Compute and Platform services offered by commercial cloud providers - NASA brokered and managed access to a full range of X-as-a-Service capabilities including, but not limited to, analytics, bots, game development, Application Programming Interface (API) management, search, software development and operations (DevOps) enablement, artificial and virtual reality, serverless functions, queuing, notification, streaming, developer tools, Internet of Things (IoT), Machine Learning (ML), Artificial Intelligence (AI), media services, data and application migration/transfer, mobile application services, cloud-native networking, content delivery, advance compute technologies (e.g., Quantum), ground station services, High-Performance Computing (HPC), robotic platform services, and cloud native compliance and security services. Authority to Operate (ATO) provided access to cloud services including, but not limited to, AI/ML, Database as a Service (DBaaS), cloud functions, etc.
1.9.1. Solution Engineering - Engineering cloud native and hybrid cloud (cloud and on-premises; cloud-cloud) solutions suitable to address NASA requirements.
1.9.2. Security Engineering - Engineer cloud native and hybrid (cloud and on-premises; cloud-cloud) Cybersecurity approaches suitable for meeting NASA requirements.
1.9.3. Cloud-Native Networking - Cloud-native network design, implementation, and operations to enable use of cloud-based computing services in a responsive, secure, and compliant manner.
2. Data Center Infrastructure Management (DCIM)
2.1. Data Center Facility Services - Facility and capacity planning/management, asset management through DCIM tool.
3. Solutions Architect Design Assistance
3.1. Data center, cloud, networking and infrastructure engineering and design assistance services.
4. Business Operations and Continuity Management
4.1. Data Center Procurement Services - Procurement of hardware, software and services for data center, lab and housed customers.
4.2. Continuity of Operations (COOP) Services - Backup and restoration, disaster recovery, or high availability of customer data and system state.
C-14
4.3. Accounting and Billing Services - Provides a yearly billing statement in advance, of all costs required to operate for the upcoming fiscal year and an estimate for the four following years.
4.4. Compliance Services - Data center services are secure and compliant with NASA policy and covered by a system security plan and ATO for the scope of those services that can be inherited by the customer.
h. Specialized Services: These services include sustainment of point-to-point Custom Networks, system engineering and sustainment of the secure Hypersonic Network, infrastructure (i.e.
desktop, WAN/LAN management) for Russia IT Services, NASA National Security Systems (NSS) service IT support, engineering and capacity management support for NASA Imagery Experts Program (NIEP), engineering and support of video services content developers of Unique Video Services (UVS), and infrastructure engineering and support (i.e., WAN/LAN, voice, data, mission operations, Cybersecurity support) for Huntsville Operations Support Center (HOSC).
i. Enterprise Cybersecurity Support Services: These services include Remote Access, Network Access Control, Firewall, Proxy Services, CDM, Corporate Cybersecurity Support, Intrusion Detection Systems and Incident Response Support, Cybersecurity Perimeter, Mission Cybersecurity Support, and Cybersecurity & Privacy Program, Center Specific Support.
C-21 deliverables (not otherwise furnished by NASA) required to perform the services and functions specified in the PWS and to accomplish the AEGIS mission.
3. Utilize Agency-wide or Government-wide contracts or site software license agreements for the systems assigned to the contractor. Commodities or services of the types normally purchased under the AEGIS contract to support the AEGIS mission may be purchased for use outside of the AEGIS contract at the request of NASA.
4. Develop and execute documentation to support the procurement of services, supplies, materials, and equipment including, but not limited to: appropriate federal, state, and local tax clauses; consumables and store stock; replacement parts or equipment; routine and critical spares; purchase, rental, lease, or maintenance of equipment; hardware and hardware upgrades; temporary labor services; vendor maintenance agreements; software, such as software necessary to perform the operations and maintenance functions of this contract; and software licenses, such as systems and applications licenses, subscription, renewal and enhancement services, and software maintenance.
5. Procurements shall be tax exempt to the maximum extent practicable.
6. Maintain management, control and visibility of intra-company, subcontractor, lease agreements, and major vendor activities that are used to fulfill contract requirements.
7. Maintain accountability for quality and timeliness, including expediting of high priority items, of the goods and services that are subcontracted or procured.
8. Establish and ensure continuous certification of a Government-approved purchasing system in accordance with the FAR and NFS.
9. Ensure all products and vendors are validated against the existing Assessed and Cleared List (ACL) prior to acquisition and complete an NF1823, Request for Investigation (RFI)/IT Product Source Assessment, for supply chain verification for any products or vendors that do not already exist on the
ACL.
10. Provide small business and small disadvantaged business concerns opportunities to receive a fair portion of procurement awards, in accordance with the approved Attachment J-4, Small Business Subcontracting Plan.
11. Establish a status and tracking system for all acquisitions from receipt of purchase request through close-out of acquisition documentation. The tracking system shall provide visibility of order status to the requestor. Documentation in the tracking system shall include, but is not limited to:
11.1. Assigned work or purchase request number.
11.2. Date of receipt.
11.3. Date order or subcontract is placed.
11.4. Order delivery or completion date.
11.5. Actual receipt or completion date.
11.6. Actual delivery date to requestor.
11.7. Vendor name, address, and contact information.
11.8. Order dollar value.
11.9. Assigned buyer.
12. Coordinate with requestors to confirm requirements for any item with hazardous content, prior to ordering.
13. Generate and maintain purchasing and subcontracting documentation sufficient to ensure compliance with the Contractor's approved purchasing system and allow for audit of all such documentation as required by NASA. The files should be consistent in format and content regardless of whether the procurements are performed by prime or subcontractor.
14. Procure and manage telecommunications services that are not available via GSA contracts, as defined in PWS 2.13, Table 17, GSA Contract Integration.
C-23 years and requests for Tier 5 reinvestigation (T5R formerly known as Single Scope Background Period Reinvestigation (SBPR) or Phased Periodic Reinvestigation (PPR)) will be initiated prior to the 5-year anniversary date of the previous Tier 5.
8. All personnel requiring Secret access under this contract/order shall undergo a favorably adjudicated Tier 3 (T3) Investigation formerly known as a National Agency Check, Local Agency Check and Credit Check or Access National Agency Check and Inquiries as a minimum investigation. The Tier 3 Investigation will be maintained current within 10-years and requests for Secret Periodic Reinvestigations will be initiated by submitting a Tier 3R investigation prior to the 10-year anniversary date of the previous Tier 3 Investigation.
9. Contract personnel found ineligible by the appropriate central adjudication facility for Top Secret or Secret access will not be allowed to support a NASA contract requiring Top Secret or Secret access.
10. Visit Access Requests (VAR) shall be processed and verified through the NASA OPS personnel.
Visits for contracts/orders are identified as “Other” or “TAD/TDY” and will include the Contract/Order Number and NASA Access level of the contract/order with any additional information. Contractors that do not have access to the OPS personnel may submit visit authorizations by e-mail in a password protected .pdf to the Contracting Officer Representative (COR) or Center Government representative.
11. Contractor personnel must comply with all local security requirements including entry and exit control for personnel and property at the government facility
12. Contractor personnel will be required to comply with all Government security regulations and requirements. Initial and periodic safety and security training and briefings will be provided by Government security personnel. Failure to comply with Government security regulations and requirements will require the company to provide the Government with a written remediation/corrective action plan; furthermore, failure to comply with such requirements can be cause for removal and the contractor will not be able to provide service on this contract.
13. Contractor personnel with an incident or adverse information report who have had their access to classified information suspended will not be permitted to provide or to fill positions requiring access to classified information on a NASA contract/order.
14. The Contractor shall not divulge any information, classified or unclassified SBU\CUI, about NASA files, data processing activities or functions, user identifications, passwords, or any other knowledge that may be gained, to anyone who is not authorized to have access to such information. The Contractor shall observe and comply with the security provisions in effect at the NASA facility.
Identification shall be worn and displayed as required.
15. NASA retains the right to request removal of contractor personnel regardless of prior clearance or adjudication status, whose actions, while assigned to this contract, clearly conflict with the interest of the Government.
16. Contractor personnel will generate or handle documents that contain Sensitive But Unclassified (SBU) or Controlled Unclassified Information (CUI) according to NASA policies and procedures.
Contractor shall have access to generate and handle classified material only at specified location(s) listed in this PWS. All contractor deliverables shall be marked in accordance NASA policy, procedures, and standards to include Freedom of Information Act Program, unless otherwise directed by the Government. The contractor shall comply with the provisions of the NASA policy for handling classified material and producing deliverables.
17. The Contractor shall afford the Government access to the contractor’s facilities, installations, operations, documentation, databases and personnel used in performance of the contract. Access shall be provided to the extent required to carry out a program of IT inspection (to include vulnerability testing), investigation and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of data or to the function of information technology
C-24 systems operated on behalf of NASA or NASA partners, and to preserve evidence of computer crime.
2.7.2 CYBERSECURITY MANAGEMENT
18. Comply with the Cybersecurity requirements as defined in NPDs, NPRs, NIDs, Cybersecurity and
Privacy Division Handbooks, and NASA Standards as identified in Attachment J-7, Applicable Documents List (ADL), and cited in NFS 1852.204-76, Security Requirements for Unclassified Information Technology Resources.
19. Comply with information protection requirements in accordance with ITS-HBK-1382.03-01, Privacy Risk Management: Collections, PIAs, and SORNs, to ensure compliance with federal regulations and privacy protection requirements.
20. As it relates to Cybersecurity, incorporate appropriate safeguards in accordance with applicable NASA CSPP standards, as noted in 18 above, to ensure availability, integrity, and confidentiality of information and IT resources utilized in performance of this contract. Also, submit all data in accordance with applicable Government standard formats and protocols.
21. Assist NASA in the development, documentation, and integration of operational and technical Cybersecurity policies, procedures and control measures in accordance with NASA policies, procedures and other guidelines identified in Attachment J-7, Applicable Documents List (ADL).
22. Ensure that systems secure sensitive data, as it is stored or transmitted across the network, complies with Federal Information Processing Standard (FIPS) 140-2, Security Requirements for Cryptographic Modules, and Attachment J-7, Applicable Documents List (ADL).
23. Prepare, submit, and maintain Contractor Account Management documentation to include personnel clearance information, training records, contractor user account information (e.g. user-ids, access, quotas, and requirements) in accordance with DRD MA-014, Documentation.
24. Personnel Security Clearance is required. The work to be performed under this contract is up to the Top Secret level and will require Sensitive Compartmented Information (SCI) access eligibility for some personnel. Therefore, the company must have personnel that have and maintain a Final Top Secret Clearance commensurate with OPM Tier 4.
25. Ensure that when using NASA IP address space, only NASA-provided external Internet connections shall be used in accordance with Attachment J-7, Applicable Documents List (ADL), and associated NASA Information Technology Requirements (NITRs).
26. Comply with NASA Supply Chain Risk Management process and practices for Federal Information Systems and Organizations by obtaining NASA approval using NF1823, Request for Investigation (RFI)/IT Product Source Assessment, before procuring any IT applications or systems, hardware or software, including all offerings in the Product Catalog.
27. Support a comprehensive Intrusion Detection System (IDS), IPS and Incident Response (IR) capability, in coordination with the NASA Security Operations Center (SOC).
28. Make available logs from any information systems, as requested by the SOC and Cybersecurity Official. Electronic raw log data shall be forwarded to the SOC, in accordance with NASA policies, procedures and guidance.
29. Support NASA incident investigations. This includes providing analysis of the NASA traffic passing through NASA connections to any connections between NASA and its partners, even if they are utilizing NASA address space, including Internet connections.
30. Promptly coordinate Intrusion Detection/Incident Response identification/support on CP system activities with the NASA SOC, the Center Cybersecurity Official (Center Information Security Officer (CISO), and Incident Response Manager (IRM)).
31. In support of CSPP, utilize NASA’s IT and CP capabilities to perform the Cybersecurity support functions at all Centers, component facilities and Headquarters, in accordance with item 18 above.
C-25
32. Provide rapid response and mitigation as directed to any vulnerabilities or incidents that might occur.
This includes responses to threat notification, Risk Management, network monitoring, centralized database collections, Cybersecurity response tracking and analysis, and forensics in the Cybersecurity Incident Management Environment and provide to the Cybersecurity Official.
33. Establish and maintain contact with internal and external technical working groups to include IT and Cybersecurity professional associations, NASA Centers and component facilities, vendors, other Government agencies, and national/international industry organizations.
34. For systems CP is responsible for: evaluate, recommend, and test prototypes of Cybersecurity tools, techniques, and training in coordination with NASA CSPP.
35. Provide system information to authorized recipients within NASA Cybersecurity and law enforcement agencies as requested to support investigations, audits, personnel actions, and legal proceedings
36. Coordinate with Agency and Center information systems and disaster recovery experts across NASA to verify integration of procedures and planning techniques.
2.7.2.1 ASSESSMENT AND AUTHORIZATION
37. Ensure that systems institute Cybersecurity controls as outlined by CSPP and in the National Institute of Standards and Technologies (NIST) Special Publication (SP) 800-53, Security and Privacy Controls for Federal Information Systems and Organizations, and Attachment J-7, Applicable Documents List (ADL).
38. Ensure that systems meet the Federal Information Security Management Act (FISMA) requirements for Certification and Accreditation (C&A) in accordance with NASA Policies, Directives, Handbooks, and Attachment J-7, Applicable Documents List (ADL).
39. Support the Assessment and Authorization process for all associated System Security Plans (SSPs) including but not limited to assisting the Information System Owners and data owners in recommending categorizations of NASA information and information systems, preparing and providing SSP supporting documentation, Cybersecurity documentation support, process and coordination support, and ensuring Risk Based Decisions (RBDs) and Plan of Action and Milestones (POA&Ms) are properly captured and maintained in the NASA approved system of record.
40. The contractor shall submit an RBD for any system that cannot use the anti-malware solution or for a system for which no anti-malware software exists, in accordance with NASA policy and procedures in NASA system of record.
41. Prepare and review supporting artifacts in support of NASA’s methodology for adhering to the FISMA for Assessment and Authorization (A&A) and inclusion in the NASA approved system of record. Support the Assessment and Authorization process for all associated SSPs including but not limited to preparing and providing SSP supporting documentation, Cybersecurity documentation support, process and coordination support, and ensuring RBDs and POA&Ms are properly captured and maintained in the NASA approved system of record.
42. Develop, maintain, and test the Contingency and related Disaster Recovery Plans, in accordance with NASA policy as listed in item 18 above, and DRD MA-014, Documentation, to ensure the orderly recovery from a disaster that may render all or part of information facilities, systems, and equipment inoperable.
43. Perform continuous monitoring of SSP, Cybersecurity controls, and related documentation
2.7.2.2 PATCH AND CONFIGURATION MANAGEMENT
44. Address all vulnerabilities of all information systems under the scope of this contract in accordance with NASA policy and guidelines, including any organizationally defined values (ODV) and NASA configuration management standards.
45. The contractor shall receive vulnerabilities reports from multiple sources, including, but not limited to: external reports, the NASA SOC Mitigation Action Recommendation (MAR) actions, Center
C-26 vulnerability patch actions issued through the individual Center/NASA Facility action tracking process, and Federal/Agency/Center security assessments (Examples include, but are not limited to:
Department of Homeland Security, Agency Network Penetration Test, Web Application Deep Dive, Web Application Security Project, CSPP regularly scheduled network vulnerability scans, Government Accountability Office (GAO) and Office of Inspector General (OIG) audits).
46. Meet the current Agency standard timelines for remediation of vulnerabilities and the creation and management of POA&Ms or requests for RBDs as needed based on the CSPP defined timelines in NASA system of record.
47. Scan all information systems supported under this Contract for vulnerabilities (both credential and non-credentialed) in accordance with the NASA defined schedule and policy, using NASA approved tools and templates.
48. Review vulnerability reports provided from NASA and implement system patching as required. The contractor shall be held accountable for patching of all systems covered by CP managed SSP.
49. Provide scan configuration files and scan reports for all systems with an approved RBD that cannot run NASA approve reporting agent software.
50. Ensure that managed systems are rebooted on a regular basis, no less than weekly, to ensure patches are fully installed on systems and shall also provide deviation reporting and RBD requests in accordance with NASA policy for approval for mission-essential functions that would be adversely affected
51. Implement NASA approved ODV and Cybersecurity Standards and Engineering Team (CSET) baseline configurations as documented in Agency policy. Ensure all deviations are documented in NASA system of record
52. Plan for and implement the full system development lifecycle maintenance and updates of assets and systems, including but not limited to:
1. Near real time asset tracking and reporting (to include configuration management) from procurement to retirement in order to optimize the most accurate Cybersecurity response and analysis
2. Removal of retired systems from Active Directory, DNS Dynamic Host Configuration Protocol (DHCP) Internet Protocol Address Management (IPAM) (DDI) and pertinent Cybersecurity asset databases
3. End of Life and End of Support replacement strategy in accordance with NASA policy and requirements.
4. Complete data sanitization for assets in accordance with NASA policy and procedures.
53. Protect all information systems…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .