ATT B - DRDs.pdf
PDF 1 MB Posted
- Attached to
- NASA Consolidated Applications and Platform Services (NCAPS) Request for Proposal Federal contract opportunity
- Solicitation number
- 80TECH23R0002
View the file
Other files for this federal contract opportunity
Show all 47
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT B
NASA CONSOLIDATED APPLICATIONS AND
PLATFORM SERVICES (NCAPS)
DATA REQUIREMENTS LIST
AND
DATA REQUIREMENTS DESCRIPTIONS
RFP 80TECH23R0002
CONTRACT #TBD
DATE: MARCH 2023
Attachment B
80TECH23R0002
INTRODUCTION
This document defines the requirements for contractual data to be delivered by the contractor to the Government. The data requirements are set forth in each Data Requirements Description (DRD) and shall govern that data required by the contract. The contractor shall furnish data defined by the DRDs as listed on the Contract Data Requirements List (CDRL) by category of data, attached hereto, and made a part of this contract. Such data shall be prepared, maintained, and delivered to NASA in accordance with the requirements set forth within this document. In cases where data requirements are covered by a Federal Acquisition Regulation (FAR) or NASA FAR Supplement (NFS) clause or other term (e.g., requirements statement), that clause or term shall take precedence over the DRD.
Contract Data Requirements List (CDRL): Throughout the performance of the contract, the CDRL provides a listing by number, data type, title, and Office of Primary Responsibility (OPR).
Data Requirements Description (DRD): Each DRD included in this CDRL prescribes content, format, and submittal requirements. The DRDs included in this CDRL are ordered sequentially as listed in the CDRL page(s) that precede(s) the actual DRDs.
Data Type Description: Each DRD is classified by data type as defined below:
TYPE DESCRIPTION
1 - All submittals of and interim changes to Type 1 DRDs require written approval from the contracting officer before formal release for use or implementation.
2 - NASA reserves a time-limited right to disapprove in writing any submittal of and interim changes to Type 2 DRDs. The contractor shall submit the required data to NASA for review within the time period established in the DRD prior to its release for use or implementation. The contractor shall clearly identify the release target date. If the data is unacceptable, the contracting officer will notify the contractor within the time period established in the DRD from the date of submission, regardless of the intended release date. The contractor shall resubmit the information for reevaluation if disapproved. The submittal is considered approved if the contractor does not receive disapproval or an extension request from the contracting officer within the time period established in the DRD.
3 – Type 3 DRDs shall be delivered as required by the contract and do not require NASA approval.
STATEMENT OF GENERAL REQUIREMENTS
Subcontractor Data Requirement The prime contractor is responsible for flowing down any specific data requirements that apply to subcontracts and vendor agreements.
Reference to subcontractor data in the contractor’s responses is permissible and a copy of the referenced subcontractor data must be supplied with the response document at time of delivery to
NASA.
Data Distribution, Format, and Transmittal Distribution: Distribution recipients and number of copies are identified within each DRD, provided within the contract, or as directed by the Contracting Officer (CO).
Format Electronic Format: Electronic submission of data deliverables is required. Electronic deliverables shall be printable. Data deliverables shall be delivered to NASA in the format specified below unless a specific format is required by a DRD. Data submittals shall consist of a single Adobe Acrobat PDF file and the native format electronic file(s). The preferred native formats include Microsoft Word, Excel, or PowerPoint, as appropriate.
Hardcopy Format: Hardcopy of data deliverables is not required unless electronic delivery is not possible OR practical.
Transmittal Data shall be transmitted to NASA by [entry into Specify electronic system (e.g., Electronic Document Management System (EDMS/Repository)), or choose one or a combination of the following: email or CD or DVD or hardcopy] or other mechanism agreed to by the Contracting Officer (CO), Contracting Officer’s Representative (COR), and project representatives who are responsible to receive, index, and store the data deliverables.
If email is used to transmit data deliverables, the email size shall be 10 megabytes or less to ensure receipt by the NASA email servers. Encrypted email format shall be used to transmit data.
Data Transmittal Package: Each data transmittal package shall include a transmittal memorandum that specifies the following:
1. Contract number
2. DRD number
3. DRD data type
4. Submission date or milestone being satisfied
5. Document number and revision
6. Document title
7. File names of all files being delivered; file naming convention shall clearly identify the document being delivered
8. NASA Records Retention Schedule (NRRS) number, if applicable (See NRRS 1441.1, NASA Records Retention Schedules)
Document Identification: For all data types, the document number, change legend, date, and title constitute the minimum identification of the specific document and shall appear on the cover and title page. The contract number shall also appear on the cover and title page as separate markings.
The originator and organization shall be included on the title page. The document number, change legend, and date shall appear on each page of the document. All Type 1 documentation shall be marked “PRELIMINARY PENDING NASA APPROVAL,” and once approved shall be reissued with “APPROVED BY NASA” and the date and approval authority annotated on the cover.
Data Restriction Determination and Marking Requirements: The contractor shall properly mark data in accordance with the data rights clause(s) included in the contract. The contractor must make a determination for each individual data deliverable, and shall not apply a default or blanket data restriction marking to all data deliverables (e.g., “data may be export restricted”). If NASA does not agree with the contractor applied data restriction, the CO shall return the data to the contractor, cancel the markings, or ignore the markings consistent with the procedures set forth in the “data rights” clause(s) contained in the contract.
Reference to Other Documents and Data Deliverables in Data Submittals: All referenced documents shall be made readily available to the cognizant NASA organization upon request.
Document Revisions
Revisions of documentation previously submitted may be accomplished either by individual page revision or by a complete reissue of the document.
A document shall be completely reissued when, in the opinion of the contractor and/or NASA, the document has been revised to the extent that it is unusable in its present state, or when directed by the CO. When complete reissues are made, the entire contents of the document shall be brought up to date and shall incorporate revised pages. All revisions shall be recorded. A revision log shall identify complete reissues except for periodic reports and documents which are complete within themselves as final.
Individual page revisions shall be made as deemed necessary by the contractor or as directed by the
CO.
Changes of a minor nature to correct obvious typing errors, misspelled words, etc., shall only be made when a substantial change is made, unless the accuracy of the document is affected.
All revised pages shall be identified by a revision identifier and a new date. Each document shall contain a log of revised pages that identify the revision status of each page with the revision symbol.
This list shall follow the table of contents in each document. The line or lines revised on a given page shall be designated using vertical line in the margin of the page, and the change authority shall be indicated adjacent to the change.
CDRL/DRD MAINTENANCE PROCEDURES
NASA-Initiated Change: New and/or revised data requirements shall be incorporated by contract modification to which the new or revised portion shall be appended. The contractor shall notify the CO in the event a deliverable data requirement is imposed and is not covered by a DRD, or when a DRD is changed by a contract modification and for which no revision is appended.
CDRL or DRD Change Procedures Revisions to the CDRL or DRDs will be identified by NASA in the Document Change Log. The date of the revision, DRD number, title, and revision description will be annotated in the Document Change Log. Revision descriptions will include the modification number, which implements the change, and a brief description of the portions of the CDRL and/or DRD affected within the “Revision” column of the Document Change Log.
Interrelationships: (Identify Statement of Work/Performance Work Statement (SOW/PWS) references, contract line item number (CLIN) references, clauses and/or provisions numbers)
Contract Data Requirements List
DRD
No.
DRD
Type
DRD Title OPR
NCAPS-CD CD – Contractual Data CD-001 3 Technology Reports Engineering CD-002 3 Deliverable Products and Services (DPS) Report Enterprise Business
Management Office
(EBMO)
NCAPS-MA MA - Management MA-001 1 Contract Management Plan EBMO MA-002 1 Contract Phase-In Plan EBMO MA-003 2 IT Security Management Plan (ITSMP) EBMO MA-004 1 Information Technology (IT) System Security Plan (SSP) EBMO MA-005 2 Service Asset and Configuration Management (SACM)
Plan
EBMO
MA-006 2 IT Service Continuity Management (ITSCM) Plan Office of the Chief Information Officer
(OCIO)
MA-007 3 Contractor Self-Assessment Report OCIO MA-008 3 Problem Documentation OCIO MA-009 1/2/3 Documentation OCIO Service Lines MA-010 2 Service Delivery Standards and Metrics Report OCIO Service Lines MA-011 2 Cost Reports OCIO MA-012 2/3 Export Control Plan and Reports OCIO MA-013 3 Financial Management Report (533M, 533Q) Office of Chief
Financial Office
(OCFO)
MA-014 3 Organizational Conflicts of Interest (OCI) Plan Office of Procurement
MA-015 3 NCAPS Monthly Performance Management Review Report
OCIO
MA-016 2 Re-procurement Data Package Office of Procurement
MA-017 2 Work Year Equivalent (WYE) Reports OCIO MA-018 2 Small Business Subcontracting Plan Office of
Procurement MA-019 Reserved MA-020 1 Contract Close-out Plan Office of
Procurement MA-021 1 Fixed Price Capacity Transition Plan (FPCTP) OCIO MA-022 2 NCAPS Systems Readiness Report OCIO MA-023 2 Technology Business Management (TBM) Reporting OCIO
MA-024 3 Diversity, Equity, Inclusion, and Accessibility (DEIA) Plan
Office of Procurement
MA-025 1 Annual Work Plan (AWP) OCIO NCAPS-SA SA - Safety SA-001 1 Safety, Health, and Environmental (SHE) Plan Office of Safety and
Mission Assurance SA-002 3 Mishap and Safety Statistics Reports Office of Safety and
Mission Assurance NCAPS-QE QE – Quality Engineering QE-001 1 Quality Plan Office of Safety and
Mission Assurance QE-002 1 Innovation Plan and Reports OCIO QE-003 1 Software Engineering Quality Plan OCIO
1. DRD Title: Technology Reports
2. DRD No.: CD-001 3. Data Type: 3 4. OPR: Engineering
Directorate
5. Solicitation No.: 80TECH23R0002 6. Contract No.: (Insert contract number)
7. Date Issued: TBD
8. Date Revised: 9. DRD Category:
Technical ☒ Administrative ☐
S&MA ☐
10. Description/Use: Provides NASA with technical information concerning any invention, discovery, improvement, or innovation made by a contractor in the performance of work under this contract for the purpose of disseminating this information to obtain increased use. Also, provides NASA with data to review for possible patentable items.
11. Distribution: COR
Initial Submission:
Technology Reporting Plan: Upon Contracting Officer’s request.
Disclosure of Invention and New Technology (NF1679): Within 2 months of identification of reportable item.
Interim NASA New Technology Summary Report (NTSR) Form: 12 months from the effective date of the contract.
Submission Frequency:
Technology Reporting Plan: Upon Contracting Officer’s request.
Disclosure of Invention and New Technology (NF1679): For each reportable item as soon as it occurs or within three months of identification.
Interim NASA NTSR Form: Every 12 months.
Final NASA NTSR Form: Immediately or within three months after completion of contracted work. Final Payment is contingent upon submission of the Final NTSR.
Format: The Disclosure of Invention and New Technology (Including Software) report may use NF1679, Disclosure of Invention and New Technology (Including Software), (latest version) or the online system at:
https://invention.nasa.gov/ or provide sufficient information to meet the reporting requirement.
The interim and final NASA New Technology Summary Reports may use the NTSR Form (Interim or Final whichever is applicable) utilizing the online system at: https://invention.nasa.gov/ or provide sufficient information to meet the reporting requirement.
Interrelationship: PWS Sections 3. Q., Technical Performance Management, and 5.3, Innovation Service, Reports.
Applicable Documents:
FAR 52.227-11 Patent Rights – Ownership by the Contractor (May 2014) as modified by NASA FAR
Supplement 1852.227-11 (Apr 2015) NFS 1852.227-70 New Technology - Other Than a Small Business Firm or NonProfit Organization
(Apr 2015)
Scope: The Technology Reports should include sufficient technical detail as is necessary to identify and fully describe a "Reportable Item." Per NFS 1852.227-70, New Technology-Other Than a Small Business Firm or
NonProfit Organization, "Reportable Item" means any invention, discovery, improvement, or innovation of the contractor, whether or not the same is or may be patentable or otherwise protectable under Title 35 of the United States Code, conceived or first actually reduced to practice in the performance of any work under this contract or in the performance of any work that is reimbursable under any clause in this contract providing for reimbursement of costs incurred prior to the effective date of this contract.
Contents: The Technology Reports consist of:
a. Disclosure of Invention and New Technology (Including Software): In accordance with NFS
1852.227-70 (e)(2), New Technology, the disclosure to the agency shall be in the form of a written report and shall identify the contract under which the reportable item was made and the inventor(s) or innovator(s). It shall be sufficiently complete in technical detail to convey a clear understanding, to the extent known at the time of the disclosure, of the nature, purpose, operation, and physical, chemical, biological, or electrical characteristics of the reportable item. The disclosure shall also identify any publication, on sale, or public use of any subject invention and whether a manuscript describing such invention has been submitted for publication and, if so, whether it has been accepted for publication at the time of disclosure. In addition, after disclosure to the agency, the contractor shall promptly notify the agency of the acceptance of any manuscript describing a subject invention for publication or of any on sale or public use planned by the contractor for such invention. This reporting requirement may be met by completing NF1679, Disclosure of Invention and New Technology (Including Software), (latest revision) online at: https://invention.nasa.gov/. Use of this form and the online system is preferred; however, if the form is not used the following information should be provided in order to meet the reporting requirement:
1. Descriptive title.
2. Innovator(s) name(s), title(s), phone number(s), and home address(es).
3. Employer when innovation made (name and division).
4. Address (place of performance).
5. Employer status (e.g., Government, college or university, non-profit organization, small business firm, large entity).
6. Origin (e.g., NASA grant number, NASA prime contract number, subcontractor, joint effort, multiple contractor contribution, other).
7. NASA Contracting Officer’s Representative (COR).
8. Contractor/grantee New Technology Representative.
9. Brief abstract providing a general description of the innovation:
(a) Description of the problem or objective that motivated the innovation’s development.
(b) Technically complete and easily understandable description of innovation developed to solve or meet the objective.
(c) Unique or novel features of the innovation and the results or benefits of its application.
(d) Speculation regarding potential commercial applications and points of contact (including names of companies producing or using similar products).
10. Additional documentation.
11. Degree of technological significance (e.g., modification of existing technology, substantial advancement in the art, major breakthrough).
12. State of development (e.g., concept only, design, prototype, modification, production model, used in current work).
13. Patent status.
14. Dates or approximate time period during which this innovation was developed.
15. Previous or contemplated publication or public disclosure including dates.
16. Answers to the following questions (for software only):
(a) Using outsiders to beta-test code? If yes, done under beta-test agreement?
(b) Modifications to this software continue by civil servant and/or contractual agreement?
(c) Previously copyrighted (if so, by whom?)?
(d) Were prior versions distributed (if yes, supply NASA or contractor contract)?
(e) Contains or is based on code owned by a non-federal entity (if yes, has a license for use been obtained?)?
(f) Has the latest version been distributed without restrictions as to use or disclosure for more than one year (if yes, supply date of disclosure)?
17. Name(s) and signature(s) of innovator(s).
Interim NASA NTSR: This report shall consist of a listing of reportable items for the reporting period or certification that there are none. This report shall also contain a list of subcontracts containing a patent rights clause or certification that there were no such subcontracts. Completion of the Interim NTSR shall satisfy this reporting requirement. Use of the form utilizing the online system at https://invention.nasa.gov/ is preferred; however, an alternate format is acceptable provided all required information is provided.
a. Final NASA NTSR: This report shall consist of a comprehensive list of all reportable items for the contract duration or certification that there are none. This report shall also contain a list of subcontracts containing a patent rights clause or certification that there were no such subcontracts.
Completion of the Final NTSR shall satisfy this reporting requirement. Use of the form utilizing the online system at https://invention.nasa.gov/ is preferred; however, an alternate format is acceptable provided all required information is provided.
b. Subcontracts: The contractor shall provide copies of subcontracts containing a patent rights clause upon Contracting Officer’s request.
Remarks: Copies of NF1679 and the NASA NTSR Form (Interim and Final) may be obtained and/or filled out at: https://invention.nasa.gov/.
Maintenance: None required.
1. DRD Title: Deliverable Products and Services (DPS) Report
2. DRD No.: CD-002 3. Data Type: 3 4. OPR: Enterprise Business
Management Office (EBMO)
5. Solicitation No.: 80TECH23R0002
6. Contract No.: (Insert contract number)
Administrative ☐
S&MA ☐
10. Description/Use: To provide the Government oversight on the quantities of products and services. COR will solicit Technical Monitors review for oversight input.
11. Distribution: CO; COR; Technical Area Monitor (TAM); APS Business Services Coordinator, Contract Resource Analyst
Initial Submission: The contractor shall provide the DPS report no later than 5 calendar days after the close of the first reporting period which ends on the last calendar day of the first month.
Submission Frequency: The Contractor shall provide the DPS report no later than 5 calendar days after the close of each reporting period which ends on the last calendar day of each month.
Format:
a. The Summary Report shall include at a minimum, the following fields:
1. Catalog ID
2. Catalog Description
3. DPS Name
4. DPS Units of Measure
5. Fiscal Year (FY) Target
6. Current Month Consumed
7. Year to Date (YTD) Cumulative
8. Remaining Balance
9. Remaining %
10. Notes
b. The Detail Report shall include at a minimum, the following fields:
1. Catalog ID
2. Catalog Description
3. DPS Name
4. Service #
5. Work Order #
6. Work Order Description
7. Requestor
8. Requestor Org. Code
9. Final Approved Date by Government
10. Actual Finish Date
11. # DPS Consumed
12. Notes
1. DRD Title: Contract Management Plan (CMP)
2. DRD No.: MA-001 3. Data Type: 1 4. OPR: EBMO
Technical ☐ Administrative ☒
S&MA ☐
10. Description/Use: To document the Contractor's overall contract management approach and organization for accomplishing the contract requirements.
11. Distribution: CO; COR; Electronic submission to Government-provided database
Initial Submission: Preliminary draft of plan 30 calendar days after contract award.
Submission Frequency: Final 30 calendar days after effective date of contract. Submit revisions for Government approval after any major change in management organization and approach.
Format: Contractor format is acceptable (not to exceed twenty (20) pages in Times New Roman 12 font, paper size 8-1/2 x 11).
Interrelationship: PWS Section 2.2, B., Program Management.
Applicable Documents:
N/A IT Investment Handbook NPR 2810.1 Security of Information and Information Systems NPR 2830.1 NASA Enterprise Architecture Procedures FAR 42.708, Quick-closeout procedure NFS 1842.708, Quick-closeout procedure NFS 1842.708-70, NASA Quick-closeout procedures
Scope: The Management Plan describes the contractor's summary concept plans, practices, and approach for accomplishing the requirements set forth in the contract, i.e., managing and controlling tasks, experimental work, and management interfaces. The plan shall be in such detail as necessary to convey the Contractor's internal procedures.
Contents: The Management Plan shall include the following:
a. The contractor shall describe the overall proposed contract management approach, strategies, policies, processes for work planning, subcontractor management, and indirect cost management including any efficiencies proposed. This description shall include a description of the organizational structure and elements, including a chart depicting the organization and the overall rationale for this approach.
b. Describe the management relationships between the contractor’s key personnel and associated NASA personnel, including communication channels, lines of authority (including the line of succession if Program Manager is unavailable), reporting relationships, and responsibilities of all organizational elements. Include in this discussion any subcontractors, team members, or joint venture partners, to illustrate their relationships within the structure or between the organizational elements and any other subcontractors, team members, or joint venture partners. Describe the reporting responsibilities of the Program Manager to corporate management and the relationship between the Program Manager and the prime’s corporate management as well as the management of any subcontractors, team members, or joint venture partners. Describe the overall authority of the Program Manager to make decisions independent of corporate management.
c. Recruitment and employment methods and policies including any special provisions your company has regarding hiring incumbent employees. Strategy to ensure personnel will maintain the minimum qualification standards described in the Standard Labor Category guidelines.
d. Approach to providing flexible workforce planning. Include discussion on recruiting; communication of promotion opportunities; retention of personnel; and the effects on management, subcontractors, continuity and quality of services, and other factors resulting from changes in staffing levels.
e. Describe the staffing location plans, including lease arrangements, for the contractor’s off-site facilities including a discussion of the on-site and off-site approach. Discuss any other issues related to logistics management.
f. A description of risks anticipated in successful performance of the SOW requirements. Include the decision to accept, mitigate, or other action for each risk and include the rationale for each.
g. The methods to ensure timely delivery of quality services. Describe how the contractor will ensure the Government will receive the services ordered by providing the method, level, and frequency of internal surveillance. Describe how the management policies, procedures, and techniques are monitored to ensure their effectiveness and facilitate continuous improvement. Describe the methods of identifying deficiencies and plans for correcting deficiencies. Describe the process for Management reviews/status reviews to NASA management.
h. Describe the process for the coordination and execution of all contract technical and administrative tasks, and how the contractor’s technical personnel (individuals and line managers) will interact with NASA line management. Process of setting goals and establishing policies, practices, procedures, and organizational structure to support the NASA Chief Information Officer (CIO) and NASA IT Governance processes, as defined in: IT Investment Handbook; NPR 2810.1, Security of Information and Information Systems; NPR 2830.1, NASA Enterprise Architecture Procedures.
i. Process of setting goals and establishing policies, practices, procedures, and organizational structure to support accomplishment of NCAPS objectives. As a minimum, this includes both transition and transformation management.
j. Process for identification and resolution of as a minimum problems, issues, and weaknesses.
k. Discuss strategies/approach to ensure that the contractor can facilitate a proactive and efficient close out of the contract at contract end in as short a time as practicable including but not limited to possible use of the Quick Closeout procedures of FAR 42.708, Quick-closeout procedure, NFS 1842.708, Quick-closeout procedure, and NFS 1842.708-70, NASA Quick-closeout procedure. FAR 42.708, Quick-closeout procedures.
Remarks: This is the contractor’s summary of their management approach and its relationship to their organization.
Maintenance: The Contractor may revise the CMP at any time or at the direction of the Contracting Officer.
Revisions to the CMP are subject to Contracting Officer review and approval. Changes shall be incorporated as required by or complete reissue. Note: Upon Contract Award, the Contractor’s Contract Management Plan becomes a part of the contract.
1. DRD Title: Contract Phase-In Plan
2. DRD No.: MA-002 3. Data Type: 1 4. OPR: EBMO
Administrative ☒
S&MA ☐
10. Description/Use: To describe activities planned to transition from the processes and services as defined at contract start to those accepted by the Government during the proposal and contract award process.
11. Distribution: CO; COR
Initial Submission: Plan due with initial proposal.
Submission Frequency: Final Plan due 7 calendar days prior to Phase-In. Revised for significant changes that may be required during the implementation of the specific changes in processes and services.
Format: Submitted electronically; MS Word
Interrelationship: PWS Section 2.9, A. and B., Contract Phase-In Management
Applicable Documents: None.
Scope: This plan defines tasks, schedule, responsibilities, and agreements for both the contractor and the Government, necessary to transition from the processes and services as defined at contract start to those accepted by the Government during the proposal and contract award process. The results of the accepted processes and services shall be contained in the Model Contract. The total time allocated for the implementation of the transition of processes and services shall not exceed 90 calendar days from phase-in start.
Contents: The Phase-in Plan shall address, as a minimum, the following:
a. Describe in detail the plan for maintaining continuous and efficient operations at NASA. Describe how you will work with incumbent Contractors and NASA, including resources and interfaces expected from each to ensure an effective transition and continuous service. The phase-in plan shall clearly demonstrate the Offeror’s ability to assume full contract responsibility on the contract’s effective date
b. Provide an innovative phase-in schedule which will accomplish all proposed phase-in steps/milestones within the 90-day phase-in period, while minimizing cost and maximizing efficiency. Include the personnel responsible for the steps/milestones. Describe your approach for how you will implement the schedule.
c. The phase-in plan shall also specifically address how ongoing work will be transitioned, the proposed management organization, schedule, orientation, and training of personnel.
d. Approach for ensuring completion of badging requirements and personnel security clearances to ensure employees are cleared for access to NASA and associated facilities, as required, prior to start of the contract, the Offeror shall address its preparation for the timely processing of the Personal Identify Verification (PIV) requirements.
e. Describes how an inventory will be performed with the Incumbent Contractor of all records that will be transitioned. Records transition shall be completed at contract start.
f. Describe your approach and risk mitigation strategies to identify any requirements for application or system connectivity or integration with NASA.
g. Identify the risks associated with your plan and ways to mitigate those risks.
Remarks: None
1. DRD Title: IT Security Management Plan (ITSMP)
2. DRD No.: MA-003 3. Data Type: 2 4. OPR: EBMO
Administrative ☐
S&MA ☐
10. Description/Use: To describe the Contractor’s methodology for addressing and managing all Cybersecurity requirement, including addressing the cross-functional and service-specific Cybersecurity requirements.
11. Distribution: CO; COR
Initial Submission: 60 calendar days after effective date of the contract.
Submission Frequency: One time; revise as required.
Format: Contractor format is acceptable with NASA approval.
Interrelationship: PWS Section 4, Cybersecurity Services Overview, and 4.7 F and G, Incident Response Support
Applicable Documents:
NPR 2810.1F Security of Information Technology NPD 2810.1E NASA Information Security Policy
Scope: The IT Security Management Plan (ITSMP) provides the Contractor’s proposed management approach for meeting cross-functional and service-specific Cybersecurity requirements.
Contents: The Cybersecurity Support Management Plan shall include, at a minimum, the following:
a. Contractor’s cybersecurity personnel and roles and responsibilities. This should include names, titles and contact information for specific individuals assigned to these roles.
b. Proposed grouping of information systems supported under the contract into IT System Security Plans (SSP) in the NASA system of record in accordance with NASA policy and Federal Information Processing Standard (FIPS) 199 security category of each information system.
c. Process for meeting security authorization requirements, including development and maintenance of IT SSPs, implementation and validation of controls, remediation, authorization, continuous monitoring, etc.
d. Processes for addressing all applicable Cybersecurity requirements, including patch requirements and mitigation, maintaining secure system configurations, patch/configuration management and reporting, malware protection.
e. Process for information security incident identification and response, including coordination with NASA Security Operations Center (SOC) and Chief Information Security Officer (CISO), Incident Response Managers.
f. Process for information security incident management and response, including coordination with NASA Security Operations Center (SOC).
g. Call list for all Contractor and sub-Contractor points of contact required for resolving Cybersecurity and information security problems.
h. Escalation procedures for emergency or urgent Cybersecurity and information security problems
i. Process for ensuring supply chain risk mitigation.
j. Process for ensuring that Contractor employees meet Cybersecurity and Privacy Program requirements, such as IT Security Awareness training, qualifications for system administrators, security clearance requirements, and others with elevated privileges, etc., and that Contractor employees are knowledgeable of NASA Cybersecurity policies and procedures.
Remarks: None.
Maintenance: Update as required to maintain current with program changes.
1. DRD Title: Information Technology (IT) System Security Plan (SSP)
2. DRD No.: MA-004 3. Data Type: 1 4. OPR: EBMO
Administrative ☒
S&MA ☐
10. Description/Use: To provide the Contractor’s compliance with the Cybersecurity requirements in NFS 1852-204-76, Security Requirements for Unclassified Information Technology Resources, and any additions/ augmentations described in NPR 2810.1E, Security of Information Technology and NASA Cybersecurity policy, standards, and handbooks. These documents will be used as part of the NASA Cybersecurity assessment and authorization process and to identify IT system inventories and appropriate Contractor Cybersecurity support points of contact.
11. Distribution: In NASA’s authoritative system of record, as verified by the relevant NASA Cybersecurity Risk Manager (CSRM)
Initial Submission: As required by the NASA Assessment & Authorization (A&A) process, in coordination with the information system’s NASA authorizing official and the relevant NASA CSRM.
Submission Frequency: The IT SSP shall be reviewed and updated in the NASA system of record on a continual basis to include any contractor personnel point of contact (POC) information changes. The SSP will be resubmitted for ATO at least annually and/or after any significant changes to the IT System. Updated copies shall be documented in the NASA system of record, upon any significant changes or annually.
Format: The Contractor shall use the format as defined in the Agency’s A&A tool, Risk Information Security Compliance System (RISCS), and following guidelines listed in Section 4.5, I.
Interrelationship: As applicable throughout PWS Section 4.5 A. iv.
Applicable Documents:
FIPS 200 Minimum Security Requirements for Federal Information and Information Systems
FIPS 199 Standards for Security Categorization of Federal Information and Information Systems
NFS 1852.204-76 Security Requirements for Unclassified Information Technology Resources
NPR 2810.1A Security of Information Technology
NIST SP 800-18 Guide for Developing Security Plans for Federal Information Systems
NIST SP 800-30 Guide for Conducting Risk Assessments
NIST SP 800-34 Contingency Planning Guide for Information Systems
NIST SP 800-61 Computer Security Incident Handling Guide
NIST SP 800-37 Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy
NIST SP 800-53 Security and Privacy Controls for Federal Information Systems and Organizations
NIST SP 800-53A Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans
ITS-HBK-AASTEP0.v1.0.0 Step 0: Prepare Policy
ITS-HBK-AASTEP1.v1.0.0 Step 1: Categorize Policy
ITS-HBK-AASTEP2.v1.0.0 Step 2: Select Policy
ITS-HBK-AASTEP3.v.1.0.0 Step 3: Implement Policy
ITS-HBK-AASTEP4.v1.0.0 Step 4: Assess Policy
ITS-HBK-AASTEP5.v1.0.0 Step 5: Authorize Policy
ITS-HBK-AASTEP6.v.1.0.0 Step 6: Monitor Policy
Scope: The Information Technology (IT) System Security Plan includes a description of the IT system, network and data flow diagrams, ports protocols and services used, hardware and software lists and its implementation of security controls, risk assessment, self-assessment of security plans, and contingency plan, in compliance with NIST SP 800-18, Guide for Developing Security Plans for Federal Information Systems, and NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations and NASA CSPP policy, standards and handbooks.
Contents: The Information Technology (IT) System Security Plan shall include the following:
a. The IT System Security Plan shall be written in accordance with NFS 1852.204-76, Security Requirements for Unclassified Information Technology Resources, NASA ITS Handbooks, and NIST SP 800-18, Guide for Developing Security Plans for Federal Information Systems, and following the process defined in NIST SP 800-37, Risk Management Framework for Information Systems and Organizations:
A System Life Cycle Approach for Security and Privacy. It should also address all the required security controls defined in the latest revision of the NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations, based upon the security categorization (per FIPS 199, Standards for Security Categorization of Federal Information and Information Systems).
b. Risk Assessment: The IT Risk Assessment report shall be written in accordance with NFS 1852.204-76, Security Requirements for Unclassified Information Technology Resources, and following the guidelines of NIST SP 800-30, Guide for Conducting Risk Assessments.
c. Self-Assessment: The self-assessment shall be conducted and provided in the format defined by NIST SP 800-53A, Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans.
d. Contingency Plan: The IT Contingency Plan shall be written in accordance with NASA policy as well as NFS 1852.204-76, Security Requirements for Unclassified Information Technology Resources, and following the guidelines of NIST SP 800-34, Contingency Planning Guide for Information Systems.
Maintenance: Changes shall be incorporated by change page or complete reissue.
1. DRD Title: Service Asset and Configuration Management (SACM) Plan
2. DRD No.: MA-005 3. Data Type: 2 4. OPR: EBMO
Administrative ☐
S&MA ☐
10. Description/Use: To describe the Contractor’s approach for managing and protecting the integrity of service assets and configuration items.
11. Distribution: Electronic submission to Government-provided database; CO; COR
Initial Submission: Draft 60 calendar days after effective date of the contract.
Submission Frequency: Preliminary 120 calendar days after effective date of the contract; Baseline 180 calendar days after effective date of the contract; update as required.
Format: Contractor format is acceptable.
Interrelationship: PWS Section 2.19, A., Configuration Management.
Applicable Documents: None.
Scope: The SACM Plan provides the Contractor’s proposed management approach for incorporating, managing, and protecting the Agency integrity of Service Assets and Configuration Items in accordance with NASA policies, procedures and configuration baselines as prescribed by the Cybersecurity Standards and Engineering Team (CSET) as listed in Attachment D, Applicable Documents List (ADL).
Contents: The SACM Plan shall include, at a minimum, the following:
a. Process for identifying and maintaining Configuration Items/Service Assets (including relevant tools, attributes, relationships, baselines and detail, and status and changes thereto) in NASA’s system of record.
b. Process for verifying and auditing Configuration Items and Service Assets.
c. Process for implementing corrective actions to resolve Configuration Item/Service Asset discrepancies.
Maintenance: Changes shall be incorporated by complete reissue. Update as required to maintain current with program changes.
1. DRD Title: Information Technology Service Continuity Management (ITSCM) Plan
2. DRD No.: MA-006 3. Data Type: 2 4. OPR: OCIO
Administrative ☐
S&MA ☐
10. Description/Use: To describe the Contractor’s method for establishing and maintaining ongoing recovery capability for required Applications, Platforms, and their components.
11. Distribution: CO; COR
Initial Submission: Draft 60 calendar days after effective date of the contract.
Submission Frequency: Preliminary 120 calendar days after effective date of the contract; baseline 180 calendar days after effective date of the contract; update as required.
Format: Contractor format is acceptable with NASA approval.
Interrelationship: PWS Section 4.10, H., Contingency Planning
Applicable Documents: None.
Scope: The IT SCM Plan provides the Contractor’s proposed management approach for establishing and maintaining ongoing recovery capability for IT services and their components in accordance Federal Information Security Management Act (FISMA) compliance requirements.
Contents: The ITSCM Plan shall include, at a minimum, the following:
a. Process for managing product and service continuity.
b. Process for notifying the Enterprise Service Desk regarding potential issues.
c. Process for identifying contingency options and impact mitigation actions and strategies.
d. Process for enabling the effective identification, analysis, and management of risk responses.
e. Process for development, production, testing, maintenance, and training of the plan.
f. Process, including criteria, for invoking the plan, executing recovery plans, restoring service to normal operation, and leading and/or coordinating recovery efforts.
g. Process for testing and documenting results of disaster recovery testing.
h. Process for identifying required contingency services that impact the required IT services.
Maintenance: Changes shall be incorporated by complete reissue. Update at least annually or quarterly based on system categorization to maintain current with program changes and requirements.
1. DRD Title: Contractor Self-Assessment Report
2. DRD No.: MA-007 3. Data Type: 3 4. OPR: OCIO
Administrative ☐
S&MA ☐
10. Description/Use: To provide the contractor’s self-assessment of performance of Attachment A, Performance Work Statement (PWS), per Attachment Z, Contract Evaluation Plan, and performance against Attachment M, Service Delivery Standards and Metrics.
11. Distribution: CO; COR
Initial Submission: 15th calendar day of the month after completion of first quarterly reporting period.
Submission Frequency: No later than the 15th calendar day of the month following the end of mid-term and final for each award fee period.
Format:
The Contractor Self-Assessment Report shall be structured in three sections – Accomplishments, Strengths and Weaknesses, and Cost Reports – and shall include no more than thirty (30) pages in Times New Roman 12 font, paper size 8-1/2 x 11, no foldouts. Reports shall be submitted electronically.
Accomplishments – Mapped to the Areas of Emphasis.
Strengths and Weaknesses - Mapped to the Areas of Emphasis.
Cost Assessment Reports – Up to two charts per page for a total of no more than two (2) pages (inclusive in the 30 pages), to meet the following format: Period of Performance Cost Assessment Report (Attachment 1) and Contract-to-date Cost Assessment Report (Attachment 2).
An Addendum A shall provide Procurement Business Data to include the following: (1) procurement contractor quarterly summary data (total # of POs awarded by business type for the period, percentage of dollars awarded by business type, dollars awarded, and percentage of total dollars awarded); (2) competitive versus non-competitive (total # of POs awarded by type (competitive./non-competitive) for the period, percentage of dollars awarded by type, dollars awarded, and percentage of total dollars awarded; (3) cost savings and cost avoidance; (4) report listing POs awarded to include PO number, Buyer Name, Value of PO, Business Type, and competitive/non-competitive;
(5) Lost Time Incident Rate (LTIR) data for each Center; (6) Center report showing number of incidence, number of lost days, number of close calls, number of safety walk thrus, and whether safety reports were submitted; and (7) property management data. This Addendum is limited to 15 pages.
An Addendum B shall provide Budget Management Reporting to include a roll-up of budget spending for all WPs (planned versus actual and a variance analysis explaining the variances for each element. Format to be approved by the COR.
The “Contractor Self-Assessment” column in Attachment M, Service Delivery Standards and Metrics, shall be completed as defined in “Contents.” Reports shall be submitted electronically.
Interrelationship: DRD MA-011, Cost Reports; MA-013, Financial Management Report (533M, 533Q); MA-015, NCAPS Monthly Performance Management Review Report; and as applicable throughout the PWS.
Applicable Documents: None.
Scope: The Contractor Self-Assessment Report provides the Contractor’s self-assessment of performance of the Performance Work Statement (PWS), to include as a minimum significant accomplishments and strengths/ weaknesses. Additionally, the Contractor shall include their performance against Attachment M, Service Delivery Standards and Metrics.
Contents:
The Contractor Self-Assessment Report shall include the following:
Accomplishments as related to NASA-defined Areas of Emphasis. Examples of quarterly Areas of Emphasis are as follows:
Execute successful operations, safely and within cost control, while minimizing risk.
Successfully manage customer requirements as relates to programs and projects.
Strengths.
Weaknesses and associated corrective actions.
Period of Performance Cost Assessment Report.
Contract-to-date Cost Assessment Report.
Remarks: This document shall be the official correspondence from the contractor regarding their overall performance evaluation.
Maintenance: None. Update as required to maintain current with program changes.
1. DRD Title: Problem Documentation
2. DRD No.: MA-008 3. Data Type: 3 4. OPR: OCIO
Administrative ☒
S&MA ☐
10. Description/Use: To provide documentation, scripts, and procedures for the ESD to facilitate the resolution of problems.
11. Distribution: COR
Initial Submission: 30 calendar days prior to operational change to NCAPS Tier 2 documentation, scripts, and procedures that interface with the ESD.
Submission Frequency: As required.
Format: For Tier 0 input, the ESD will define the format. For other input, Contractor format is acceptable with NASA approval.
Interrelationship: PWS Sections 6.4, O. i. & vii.
Applicable Documents: None.
Scope: The Problem Documentation applies to all cross-functional and service-specific problems.
Contents: The Problem Documentation shall include, at a minimum, the following:
a. Documentation:
1. Problem description.
2. Problem characteristics/key indicators that enable quick identification.
3. Actual/potential applicability and resolution guidance once problem determination is made.
b. Scripts: Specific guidance for Enterprise Service Desk or end user to enable the identification/ determination and resolution of recurring problems.
c. Procedures: Step-by-step guidance for identifying, assigning resolution responsibility, and resolving the problem.
d. Knowledge Article solution documentation shall be entered online in the Enterprise Service Desk tool and shall include, at a minimum, the following:
1. Knowledge base
2. Category
3. Valid to date
4. Article Type
5. Short description
6. Article Body
Remarks: The documentation, scripts and procedures shall be fully developed, documented, and tested prior to release in accordance with ITIL (current version) Change, Release, and Deployment processes. ESD will provide access to the online https://esd.nasa.gov/kb_knowledge.do?sysparm_stack=kb_knowledge_list.do, in the interim a copy of the template is provided as Enclosure 3, KnowledgeArticleTemplate.pdf.
Maintenance: Changes shall be incorporated by change page or complete reissue. Update as required to maintain current with program changes.
1. DRD Title: Documentation
2. DRD No.: MA-009 3. Data Type: 1/2/3 4. OPR: OCIO Service Lines
Administrative ☒
S&MA ☐
10. Description/Use:
11. Distribution: COR
Initial Submission: See Attachment 1 and 2.
Submission Frequency: See Attachment 1 and 2.
Format: Contractor format is acceptable with COR approval. See Attachment 1 for specific format requirements.
Interrelationship: See Attachment 1 and 2; as applicable throughout the PWS.
Applicable Documents:
NPR 1040.1 NASA Continuity of Operations (COOP) Planning Procedural Requirements ITS-HBK-2810.08-01A Contingency Planning
Scope: Documentation will be provided on all software covered by the contract to the extent necessary to permit effective utilization.
Contents: Documentation shall be in the form of manuals, plans, studies, technical bulletin, user guides, quick references, newsletters, and online files. Information is to be provided in sufficient detail and with such clarity to allow understanding necessary to plan and process work. Administrative, operating, and technical information shall be included with examples as appropriate. A documentation tree shall be maintained for applicable documents. Specific documentation requirements are detailed in Attachment 1.
Maintenance: Revisions made periodically to reflect current information.
1. DRD Title: Service Delivery Standards and Metrics Report
2. DRD No.: MA-010 3. Data Type: 2 4. OPR: OCIO Service Lines
5. Solicitation No.: 80TECH23R0002 6. Contract No.: (Insert contract number)
7. Date Issued: TBD 8. Date Revised: 9. DRD Category:
Technical ☒ Administrative ☐
S&MA ☐
10. Description/Use: To validate contractor performance and provide oversight on resolution of problems and service delivery standards. COR will solicit Technical Area Monitor, Technical POCs, and Task Monitors review for oversight input. Result of data may also result in invoice credit.
11. Distribution: CO; COR
Initial Submission: Five (5) business days after the end of the first month of contract assumption.
Submission Frequency: Monthly within five (5) business days after the close of reporting period which ends on the last calendar day of each month.
Format: Contractor format is acceptable.
Interrelationship: DRD MA-015, NCAPS Monthly Performance Management Review Report and PWS 2.2, G., Program Management.
Applicable Documents: None
Scope: The Service Delivery Standards and Metrics Report provides the monthly statistics for all performance against specifications for all services.
Contents: The contractor shall provide monthly Service Delivery Standards and Metrics report in accordance with Attachment M,…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .