ATT D - Applicable Documents List.pdf

PDF 267 KB Posted

Attached to
NASA Consolidated Applications and Platform Services (NCAPS) Request for Proposal Federal contract opportunity
Solicitation number
80TECH23R0002
Issued by
National Aeronautics and Space Administration

View the file

Other files for this federal contract opportunity

Other files attached to NASA Consolidated Applications and Platform Services (NCAPS) Request for Proposal, newest first.
File Type Posted
ATT G - Acronyms Terms and Definitions - Amendment 02.pdf PDF
NCAPS Request for Proposal - 80TECH23R0002 - Amendment 02.pdf PDF
Questions and Answers for Request for Proposal 80TECH23R0002 Amendment 02.pdf PDF
ATT J - Fixed Price Story Point Process - Amendment 01.pdf PDF
Request for Proposal 80TECH23R0002 Amendment 01.pdf PDF
ATT L - Service Catalog Descriptions - Amendment 01.pdf PDF
Question and Answers for Request for Proposals 80TECH23R0002.pdf PDF
ATT B - DRDs - Amendment 01.pdf PDF
ATT S - Application Inventory - Amendment 01.pdf PDF
Exhibit 1-NCAPS Pricing Matrix Amendment 01.xlsx XLSX spreadsheet
ATT A - Performance Work Statement.pdf PDF
ATT G - Acronyms Terms and Definitions.pdf PDF
ATT L - Service Catalog Descriptions.pdf PDF
Enclosure 1 - Quality Assurance Surveillance Plan.pdf PDF
Exhibit 2 Small Business Subcontracting Plan Goals.xlsx XLSX spreadsheet
Exhibit 3 - Past Performance Questionnaire.pdf PDF
AAO Program Increment.pdf PDF
ATT O - Contract Management Plan.pdf PDF
ATT E - SHE Plan.pdf PDF
ATT I - Service Catalog Pricing Matrix.pdf PDF
ATT J - Fixed Price Story Point Process.pdf PDF
ATT N - IT Security Management Plan.pdf PDF
ATT P - Deliverable Products and Services (DPS).pdf PDF
ATT S - Application Inventory.pdf PDF
ATT V - SB Subcontracting Plan.pdf PDF
ATT W - Financial Management Reporting.pdf PDF
Exhibit 1-NCAPS Pricing Matrix.xlsx XLSX spreadsheet
NCAPS 80TECH23R0002 Request for Proposal.pdf PDF
ATT K - Application Support Levels.pdf PDF
ATT M - Service Delivery Standards and Metrics.pdf PDF
ATT Q - DD Form 254 Cover.pdf PDF
ATT Q - Attachment 1 to DD Form 254.pdf PDF
ATT U - Labor Category Position Descriptions.pdf PDF
ATT Y - NCAPS Contract Demarks.pdf PDF
Enclosure 3 - IT Security Management Plan Template.pdf PDF
Historical IT WYEs.pdf PDF
NCAPS Question Template.xlsx XLSX spreadsheet
ATT B - DRDs.pdf PDF
ATT C - Wage Determinations.pdf PDF
ATT F - Organizational Conflict of Interest (OCI) Plan.pdf PDF
ATT H - Phase-in Plan.pdf PDF
ATT Q - DD Form 254.pdf PDF
ATT R - CATS - iSite Contractor On-boarding Guide.pdf PDF
Enclosure 2 - KnowledgeArticleTemplate.pdf PDF
Agency Background and Historical.pdf PDF
Center Background and Historical.pdf PDF
Internal NASA Documents.pdf PDF
Show all 47

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ATTACHMENT D

NASA CONSOLIDATED APPLICATIONS AND

PLATFORM SERVICES (NCAPS)

APPLICABLE DOCUMENTS LIST (ADL)

RFP 80TECH23R0002

CONTRACT #TBD

DATE: JANUARY 2023

Attachment D

80TECH23R0002

This attachment contains a representative list of applicable documents for the contract effort. The document number reference in the contract may not contain the revision number. The latest revision of each document is the applicable document, and the contractor is responsible for ensuring application of the latest revisions. The contractor shall comply with these requirements in performing the Performance Work Statement (PWS) activities. Requirements written in these documents shall have full force and effect as if their text was written in this contract to the extent that the requirements relate to context of the work to be performed within the scope of this contract.

Document Number Title 15 CFR Parts 730-799 Export Administration Regulations (EAR) 22 CFR Parts 120-130 International Traffic in Arms Regulations (ITAR) 29 CFR Part 1903 Inspections, Citations, and Proposed Penalties

29 CFR Part 1910 Department of Labor; Occupational Safety and Health Administration Standards for General Industry

29 CFR Part 1926 Department of Labor; Occupational Safety and Health Administration Standards for Construction Industry

32 CFR Part 2001 Classified National Security Information 32 CFR Part 2002 Controlled Unclassified Information (CUI) 36 CFR Part 1220 Federal Records 40 U.S.C. § 11101 et seq. Clinger-Cohen Act of 1996 40 U.S.C. 11331 Responsibilities for Federal Information Systems Standards AA-Role-AODR Authorizing Official Designated Representative Summary AA-Role-AO Authorizing Official Summary AA-Role-CISO Center Chief Information Security Officer Summary AA-Role-CCRM Center Cybersecurity Risk Manager Summary AA-Role-CPM Center Privacy Manager Summary AA-Role-ISO Information System Owner Summary AA-Role-ISSE Information System Security Engineer Summary AA-Role-ISSO Information System Security Officer Summary AA-Role-SCA Security Control Assessor Summary ANSI/ISO/ASQ Q9001-2000 Quality Management Systems – Requirements AP-NASA-HDBK-001, V3.1 Applications Program Handbook Policy Handbook

BOD 18-02 Department of Homeland Security’s Binding Operational Directive 18-02, Securing High Value Assets

CNSSI 4009 Committee on National Security Systems (CNSS) Glossary CP-001-V4 CP Service Document (CSD)

CSO-SOP-0002

Communications Service Office (CSO) Standard Operating Procedure for Trouble Reporting, Activity Scheduling, Mission Freeze, and Major Outage Notifications

Executive Order (EO) 13526 Classifying and declassifying National Security Information EO 13556 Controlled Unclassified Information EO 13636 Improving Critical Infrastructure Cybersecurity EO 13834 Efficient Federal Operations EO 14028 Improving the Nation’s Cybersecurity

FIPS 140-3 Security Requirements For Cryptographic Modules FIPS 180-4 Secure Hash Standard (SHS) FIPS 186-4 Digital Signature Standard (DSS) FIPS 197 Advanced Encryption Standard (AES) FIPS 198-1 The Keyed-Hash Message Authentication Code (HMAC)

FIPS 199 Standards for Security Categorization of Federal Information and Information Systems

FIPS 200 Minimum Security Requirements for Federal Information and Information Systems

FIPS 201-3 Personal Identity Verification (PIV) of Federal Employees and Contractors

FIPS 202 SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions

HSPD-12 Policy for a Common Identification Standard for Federal Employees and Contractors

IETF RFC Memorandum 778 DCNET Internet Clock Service IETF RFC Memorandum 891 DCN Local-Network Protocols IETF RFC Memorandum 956 Algorithms for Synchronizing Network Clocks

IETF RFC Memorandum 5905 Network Time Protocol Version 4: Protocol and Algorithms Specification

ISO/IEC 17025 General Requirements for the Competence of Testing and Calibration Laboratories

IT-HBK-1440.01-01 Records Management Program and Records Life Cycle: Chapter 1

— Overview

IT-HBK-1441.01-01 Records Retention and Disposition: Chapter 1 — Overview ITS-HBK-1382.03-01 Privacy – Collections, PTAs, and PIAs

ITS-HBK-1382.03-02 Privacy Annual Reporting Procedures: Reviewing and Reducing PII and Unnecessary Use of SSN

ITS-HBK-1382.04-01 Privacy and Cybersecurity: Supporting and Integrated Controls Framework

ITS-HBK-1382.05-01 Privacy Incident Response and Management: Breach Response Team Checklist

ITS-HBK-1382.06-01 Privacy Notice and Redress — Web Privacy and Written Notice, Complaints, Access, and Redress

ITS-HBK-1382.07-01 Privacy Awareness and Training ITS-HBK-1382.08-01 Privacy Accountability ITS-HBK-1382.09-01 Privacy Rules of Behavior and Consequences ITS-HBK-2810.03-02B Planning ITS-HBK-2810.04-01A Risk Assessment, Vulnerability Scanning, and Expedited Patching ITS-HBK-2810.05-02B System and Service Acquisition ITS-HBK-2810.06-2B IT Security Awareness, Training, and Education ITS-HBK-2810.07-02B Configuration Management ITS-HBK-2810.08-01A Contingency Planning ITS-HBK-2810.09-01 Incident Response and Management

ITS-HBK-2810.09-02A NASA Information Security Incident Management (CUI) ITS-HBK-2810.09-03A Collection of Electronic Data (CUI)

ITS-HBK-2810.09-04 Incident Response and Management: Guidelines for Data Spillage and Sanitization Procedures

ITS-HBK-2810.10-02C Maintenance ITS-HBK-2810.11-2C Media Protection and Sanitization ITS-HBK-2810.12-02B Physical and Environmental Protection ITS-HBK-2810.13-01B Personnel Security ITS-HBK-2810.14-03D System and Information Integrity – System and Info Integrity ITS-HBK-2810.15-01A Access Control ITS-HBK-2810.15-02A Access Control: Managed Elevated Privileges (CUI) ITS-HBK-2810.16-02B Audit and Accountability ITS-HBK-2810.17-02B Identification and Authentication ITS-HBK-2810.18-02B System and Communications Protection ITS-HBK-2810.19-01 Operational Technology IT-HBK-2841-03A Identity, Credential, and Access Management (ICAM) Services ITS-HBK-CUI v1.0.0 Controlled Unclassified Information Handbook

ITS-HBK-SCRM.2810.v1.0.0 Information & Communications Technology Supply Chain Risk Management (ICT SCRM)

ITS-HBK-AASTEP0.v1.0.0 Step 0: Prepare Policy ITS-HBK-AASTEP1.v1.0.0 Step 1: Categorize Policy ITS-HBK-AASTEP2.v1.0.0 Step 2: Select Policy ITS-HBK-AASTEP3.v.1.0.0 Step 3: Implement Policy ITS-HBK-AASTEP4.v1.0.0 Step 4: Assess Policy ITS-HBK-AASTEP5.v1.0.0 Step 5: Authorize Policy ITS-HBK-AASTEP6.v.1.0.0 Step 6: Monitor Policy MIL-HDBK-881D Department of Defense Handbook Work Breakdown Structure NAII 2190.1E NASA Export Control Program Operations Manual

NAII 2810.1 Networks in NASA Internet Protocol (IP) Space or NASA Physical Space

NAII 2810.2 Email Services NASA-HDBK-2203 Software Engineering Handbook NASA/SP-2007-6105 NASA Systems Engineering Handbook NASA-SPEC-2600 Enumeration of ASCS Cybersecurity Requirements

NASA-SPEC-2661.Controls Control Baselines and Critical Controls for NASA Information Systems

NASA-SPEC-2661.ODVr5 NASA’s Organization-Defined Values for NIST SP 800-53 Revision 5

NASA-STD-2601 Minimum Cybersecurity Requirements for Computing Systems

NASA-STD-2602 Minimum Information System Owner and End User Security for Data at Rest

NASA-STD-2603 Minimum Security and Privacy Requirements for Agency and Center Information System Implementations

NASA-STD-2604 Computing System Configuration Management

NASA-STD-2804 Minimum Interoperability Software Suite NASA-STD-2805 Minimum Hardware Configurations NASA-STD-2818 Digital Television for NASA NASA-STD-8739.8B Software Assurance and Software Safety Standard NASA-STD-8739.9 Software Formal Inspection Standard National Defense Authorization Act (NDAA) section 889

Prohibition On Certain Telecommunications and Video Surveillance Services or Equipment

NIST SP 1800-10 Protecting Information and System Integrity in Industrial Control System Environments: Cybersecurity for the Manufacturing Sector

NIST SP 800-12 Rev. 1 An Introduction to Computer Security: the NIST Handbook

NIST SP 800-18 Rev. 1 Guide for Developing Security Plans for Federal Information Systems

NIST SP 800-22 Rev. 1a A Statistical Test Suite for Random and Pseudorandom Number Generators for Cryptographic Applications

NIST SP 800-28 Version 2 Guidelines on Active Content and Mobile Code NIST SP 800-30 Rev. 1 Guide for Conducting Risk Assessments NIST SP 800-34 Rev. 1 Contingency Planning Guide for Federal Information Systems NIST SP 800-35 Guide to Information Technology Security Services

NIST SP 800-37 Rev. 2 Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy

NIST SP 800-38A Recommendation for Block Cipher Modes of Operation: Methods and Techniques

NIST SP 800-38A Addendum Recommendation for Block Cipher Modes of Operation: Three Variants of Ciphertext Stealing for CBC Mode

NIST SP 800-38B Recommendation for Block Cipher Modes of Operation: the CMAC Mode for Authentication

NIST SP 800-38C Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality

NIST SP 800-38D Recommendation for Block Cipher Modes of Operation:

Galois/Counter Mode (GCM) and GMAC

NIST SP 800-38E Recommendation for Block Cipher Modes of Operation: the XTS- AES Mode for Confidentiality on Storage Devices

NIST SP 800-38F Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping

NIST SP 800-38G Recommendation for Block Cipher Modes of Operation: Methods for Format-Preserving Encryption

NIST SP 800-39 Managing Information Security Risk: Organization, Mission, and Information System View

NIST SP 800-40 Rev. 4 Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology

NIST SP 800-41 Rev. 1 Guidelines on Firewalls and Firewall Policy NIST SP 800-44 Version 2 Guidelines on Securing Public Web Servers NIST SP 800-45 Version 2 Guidelines on Electronic Mail Security

NIST SP 800-46 Rev. 2 Guide to Enterprise Telework, Remote Access, and Bring Your Own Device (BYOD) Security

NIST SP 800-47 Rev. 1 Managing the Security of Information Exchanges NIST SP 800-49 Federal S/MIME V3 Client Profile

NIST SP 800-50 Building an Information Technology Security Awareness and Training Program

NIST SP 800-51 Rev. 1 Guide to Using Vulnerability Naming Schemes

NIST SP 800-52 Rev. 2 Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations

NIST SP 800-53 Rev. 5 Security and Privacy Controls for Federal Information Systems and Organizations

NIST SP 800-53A Rev. 5 Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans

NIST SP 800-53B Control Baselines for Information Systems and Organizations NIST SP 800-55 Rev. 1 Performance Measurement Guide for Information Security

NIST SP 800-56A Rev. 3 Recommendation for Pair-Wise Key-Establishment Schemes Using Discrete Logarithm Cryptography

NIST SP 800-56B Rev. 2 Recommendation for Pair-Wise Key-Establishment Using Integer Factorization Cryptography

NIST SP 800-56C Rev. 2 Recommendation for Key-Derivation Methods in Key- Establishment Schemes

NIST SP 800-57 Part 1 Rev. 5 Recommendation for Key Management: Part 1 – General

NIST SP 800-57 Part 2 Rev. 1 Recommendation for Key Management: Part 2 – Best Practices for Key Management Organizations

NIST SP 800-57 Part 3 Rev. 1 Recommendation for Key Management, Part 3: Application-Specific Key Management Guidance

NIST SP 800-58 Security Considerations for Voice Over IP Systems

NIST SP 800-59 Guideline for Identifying an Information System as a National Security System

NIST SP 800-60 Vol. 1 Rev. 1 Guide for Mapping Types of Information and Information Systems to Security Categories

NIST SP 800-60 Vol. 2 Rev. 1 Guide for Mapping Types of Information and Information Systems to Security Categories: Appendices

NIST SP 800-61 Rev. 2 Computer Security Incident Handling Guide NIST SP 800-63-3 Digital Identity Guidelines NIST SP 800-63A Digital Identity Guidelines: Enrollment and Identity Proofing

NIST SP 800-63B Digital Identity Guidelines: Authentication and Lifecycle Management

NIST SP 800-63C Digital Identity Guidelines: Federation and Assertions

NIST SP 800-66 Rev. 1 An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule

NIST SP 800-67 Rev. 2 Recommendation for the Triple Data Encryption Algorithm (TDEA) Block Cipher

NIST SP 800-70 Rev. 4 National Checklist Program for IT Products: Guidelines for Checklist Users and Developers

NIST SP 800-72 Guidelines on PDA Forensics NIST SP 800-73-4 Interfaces for Personal Identity Verification NIST SP 800-76-2 Biometric Specifications for Personal Identity Verification NIST SP 800-77 Rev. 1 Guide to IPsec VPNs

NIST SP 800-78-4 Cryptographic Algorithms and Key Sizes for Personal Identity Verification

NIST SP 800-79-2 Guidelines for the Authorization of Personal Identity Verification Card Issuers (PCI) and Derived PIV Credential Issuers (DPCI)

NIST SP 800-81-2 Secure Domain Name System (DNS) Deployment Guide NIST SP 800-82 Rev. 2 Guide to Industrial Control Systems (ICS) Security

NIST SP 800-83 Rev. 1 Guide to Malware Incident Prevention and Handling for Desktops and Laptops

NIST SP 800-84 Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities

NIST SP 800-85A-4 PIV Card Application and Middleware Interface Test Guidelines (SP 800-73-4 Compliance)

NIST SP 800-85B PIV Data Model Test Guidelines NIST SP 800-86 Guide to Integrating Forensic Techniques into Incident Response

NIST SP 800-87 Rev. 2 Codes for Identification of Federal and Federally-Assisted Organizations

NIST SP 800-88 Rev. 1 Guidelines for Media Sanitization

NIST SP 800-89 Recommendation for Obtaining Assurances for Digital Signature Applications

NIST SP 800-90A Rev. 1 Recommendation for Random Number Generation Using Deterministic Random Bit Generators

NIST SP 800-90B Recommendation for the Entropy Sources Used for Random Bit Generation

NIST SP 800-92 Guide to Computer Security Log Management NIST SP 800-94 Guide to Intrusion Detection and Prevention Systems (IDPS) NIST SP 800-95 Guide to Secure Web Services NIST SP 800-96 PIV Card to Reader Interoperability Guidelines

NIST SP 800-97 Establishing Wireless Robust Security Networks: A Guide to IEEE 802.11i

NIST SP 800-98 Guidelines for Securing Radio Frequency Identification (RFID) Systems

NIST SP 800-100 Information Security Handbook: A Guide for Managers NIST SP 800-101 Rev. 1 Guidelines on Mobile Device Forensics NIST SP 800-102 Recommendation for Digital Signature Timeliness NIST SP 800-106 Randomized Hashing for Digital Signatures

NIST SP 800-107 Rev. 1 Recommendation for Applications Using Approved Hash Algorithms

NIST SP 800-108 Rev. 1 Recommendation for Key Derivation Using Pseudorandom Functions

NIST SP 800-111 Guide to Storage Encryption Technologies for End User Devices NIST SP 800-113 Guide to SSL VPNs

NIST SP 800-114 Rev. 1 User's Guide to Telework and Bring Your Own Device (BYOD) Security

NIST SP 800-115 Technical Guide to Information Security Testing and Assessment NIST SP 800-116 Rev. 1 Guidelines for the Use of PIV Credentials in Facility Access NIST SP 800-119 Guidelines for the Secure Deployment of IPv6 NIST SP 800-121 Rev. 2 Guide to Bluetooth Security

NIST SP 800-122 Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)

NIST SP 800-123 Guide to General Server Security

NIST SP 800-124 Rev. 1 Guidelines for Managing the Security of Mobile Devices in the Enterprise

NIST SP 800-125 Guide to Security for Full Virtualization Technologies NIST SP 800-125A Rev. 1 Security Recommendations for Server-based Hypervisor Platforms

NIST SP 800-125B Secure Virtual Network Configuration for Virtual Machine (VM) Protection

NIST SP 800-126 Rev. 3 The Technical Specification for the Security Content Automation Protocol (SCAP): SCAP Version 1.3

NIST SP 800-126A SCAP 1.3 Component Specification Version Updates: An Annex to NIST Special Publication 800-126 Revision 3

NIST SP 800-128 Guide for Security-Focused Configuration Management of Information Systems

NIST SP 800-130 A Framework for Designing Cryptographic Key Management Systems

NIST SP 800-131A Rev. 2 Transitioning the Use of Cryptographic Algorithms and Key Lengths

NIST SP 800-132 Recommendation for Password-Based Key Derivation: Part 1:

Storage Applications

NIST SP 800-133 Rev. 2 Recommendation for Cryptographic Key Generation

NIST SP 800-135 Rev. 1 Recommendation for Existing Application-Specific Key Derivation Functions

NIST SP 800-137 Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations

NIST SP 800-137A Assessing Information Security Continuous Monitoring (ISCM) Programs: Developing an ISCM Program Assessment

NIST SP 800-140 FIPS 140-3 Derived Test Requirements (DTR): CMVP Validation Authority Updates to ISO/IEC 24759

NIST SP 800-140A CMVP Documentation Requirements: CMVP Validation Authority Updates to ISO/IEC 24759

NIST SP 800-140B CMVP Security Policy Requirements: CMVP Validation Authority Updates to ISO/IEC 24759 and ISO/IEC 19790 Annex B

NIST SP 800-140C Rev. 1 CMVP Approved Security Functions: CMVP Validation Authority Updates to ISO/IEC 24759

NIST SP 800-140D Rev. 1 CMVP Approved Sensitive Parameter Generation and Establishment Methods: CMVP Validation Authority Updates to

ISO/IEC 24759

NIST SP 800-140E

CMVP Approved Authentication Mechanisms: CMVP Validation Authority Requirements for ISO/IEC 19790 Annex E and ISO/IEC 24579 Section 6.17

NIST SP 800-140F CMVP Approved Non-Invasive Attack Mitigation Test Metrics:

CMVP Validation Authority Updates to ISO/IEC 24759

NIST SP 800-142 Practical Combinatorial Testing NIST SP 800-144 Guidelines on Security and Privacy in Public Cloud Computing NIST SP 800-145 The NIST Definition of Cloud Computing NIST SP 800-146 Cloud Computing Synopsis and Recommendations NIST SP 800-147 BIOS Protection Guidelines NIST SP 800-147B BIOS Protection Guidelines for Servers NIST SP 800-150 Guide to Cyber Threat Information Sharing

NIST SP 800-152 A Profile for U.S. Federal Cryptographic Key Management Systems

(CKMS)

NIST SP 800-153 Guidelines for Securing Wireless Local Area Networks (WLANs) NIST SP 800-156 Representation of PIV Chain-of-Trust for Import and Export

NIST SP 800-157 Guidelines for Derived Personal Identity Verification (PIV) Credentials

NIST SP 800-16 Information Technology Security Training Requirements: A Role-and Performance-Based Model

NIST SP 800-160 Vol. 1 Systems Security Engineering: Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems

NIST SP 800-160 Vol. 2 Rev. 1 Developing Cyber-Resilient Systems: A Systems Security Engineering Approach

NIST SP 800-161 Rev. 1 Supply Chain Risk Management Practices for Federal Information Systems and Organizations

NIST SP 800-162 Guide to Attribute Based Access Control (ABAC) Definition and Considerations

NIST SP 800-163 Rev. 1 Vetting the Security of Mobile Applications NIST SP 800-166 Derived PIV Application and Data Model Test Guidelines NIST SP 800-167 Guide to Application Whitelisting NIST SP 800-168 Approximate Matching: Definition and Terminology

NIST SP 800-171 Rev. 2 Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

NIST SP 800-171A Assessing Security Requirements for Controlled Unclassified Information

NIST SP 800-172

Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171

NIST SP 800-172A Assessing Security Requirements for Controlled Unclassified Information

NIST SP 800-175A Guideline for Using Cryptographic Standards in the Federal Government: Directives, Mandates and Policies

NIST SP 800-175B Rev. 1 Guideline for Using Cryptographic Standards in the Federal Government: Cryptographic Mechanisms

NIST SP 800-177 Rev. 1 Trustworthy Email

NIST SP 800-178

A Comparison of Attribute Based Access Control (ABAC) Standards for Data Service Applications: Extensible Access Control Markup Language (XACML) and Next Generation Access Control

(NGAC)

NIST SP 800-181 Rev. 1 National Initiative for Cybersecurity Education (NICE) Cybersecurity Workforce Framework

NIST SP 800-183 Networks of 'Things' NIST SP 800-184 Guide for Cybersecurity Event Recovery

NIST SP 800-185 SHA-3 Derived Functions: cSHAKE, KMAC, TupleHash, and ParallelHash

NIST SP 800-187 Guide to LTE Security

NIST SP 800-189 Resilient Interdomain Traffic Exchange: BGP Security and DDoS Mitigation

NIST SP 800-190 Application Container Security Guide NIST SP 800-192 Verification and Test Methods for Access Control Policies/Models NIST SP 800-193 Platform Firmware Resiliency Guidelines NIST SP 800-202 Quick Start Guide for Populating Mobile Test Devices NIST SP 800-204 Security Strategies for Microservices-based Application Systems

NIST SP 800-204A Building Secure Microservices-based Applications Using Service- Mesh Architecture

NIST SP 800-204B Attribute-based Access Control for Microservices-based Applications using a Service Mesh

NIST SP 800-204C Implementation of DevSecOps for a Microservices-based Application with Service Mesh

NIST SP 800-205 Attribute Considerations for Access Control Systems NIST SP 800-207 Zero Trust Architecture NIST SP 800-208 Recommendation for Stateful Hash-Based Signature Schemes NIST SP 800-209 Security Guidelines for Storage Infrastructure NIST SP 800-210 General Access Control Guidance for Cloud Systems

NIST SP 800-213 IoT Device Cybersecurity Guidance for the Federal Government:

Establishing IoT Device Cybersecurity Requirements

NIST SP 800-213A IoT Device Cybersecurity Guidance for the Federal Government:

IoT Device Cybersecurity Requirement Catalog

NIST SP 800-218

Secure Software Development Framework (SSDF) Version 1.1:

Recommendations for Mitigating the Risk of Software Vulnerabilities

NIST SP 800-219 Automated Secure Configuration Guidance from the macOS Security Compliance Project (mSCP)

NIST SP 800-220 Fiscal Year 2021 Cybersecurity and Privacy Annual Report NPD 1000.0C NASA Governance and Strategic Management Handbook NPD 1280.1A NASA Integrated Management System Policy NPD 1380.1 Managing Agency Communications NPD 1382.17K NASA Privacy Policy NPD 1383.1C Release and Management of Audiovisual Products NPD 1385.2I Public Appearances of NASA Personnel, Including Astronauts NPD 1420.1A NASA Forms Management NPD 1440.6I NASA Records Management NPD 1600.2E NASA Security Policy NPD 1600.3 Policy on Prevention of and Response to Workplace Violence NPD 1600.4 National Security Programs NPD 1600.9A NASA Insider Threat Program NPD 2190.1B NASA Export Control Program NPD 2200.1D Management of NASA Scientific and Technical Information

NPD 2540.1K

Acceptable Use of Government Furnished Information Technology Equipment, Services and Resources Equipment, Services and Resources

NPD 2800.1E Managing Information Technology NPD 2810.1F NASA Information Security Policy NPD 2830.1D NASA Enterprise Architecture NPD 4200.1C Equipment Management NPD 7120.4E NASA Engineering and Program/Project Management Policy NPD 7120.6A Knowledge Policy for Program and Projects

NPD 7410.1H Management of Contract and Grant Support Services Obtained from External Sources (Revalidated 8/14/2018)

NPD 7500.1D Program and Project Life-Cycle Logistics Support Policy NPD 7620.1I Official Names for Major NASA Projects NPD 8610.23C Launch Vehicle Technical Oversight Policy NPD 8610.24C Launch Services Program Pre-Launch Readiness Reviews

NPD 8610.7D Launch Services Risk Mitigation Policy for NASA-Owned and/or NASA-Sponsored Payloads/Missions

NPD 8700.1F NASA Policy for Safety and Mission Success NPD 8710.1D Emergency Management Program NPD 9501.1I NASA Contractor Financial Management Reporting System

NPR 1040.1 NASA Continuity of Operations (COOP) Planning Procedural Requirements

NPR 1382.1B NASA Privacy Procedural Requirements NPR 1385.1A Public Appearances of NASA Personnel, Including Astronauts

NPR 1441.1E NASA Records Management Program Requirements

NPR 1450.10D NASA Correspondence Management and Communications Standards and Style

NPR 1600.1A NASA Security Program Procedural Requirements NPR 1600.2A NASA Classified National Security Information (CNSI) NPR 1600.3A Personnel Security NPR 1600.4A Identity and Credential Management NPR 1600.6A Communications Security (COMSEC) NPR 1660.1C NASA Counterintelligence and Counterterrorism NPR 2190.1C NASA Export Control Program NPR 2210.1C Release of NASA Software NPR 2800.2A Information and Communication Technology Accessibility NPR 2810.1F Security of Information and Information Systems

NPR 2810.2 Possession and Use of NASA Information and Information Systems Outside of the United States and United States Territories

NPR 2810.7 Controlled Unclassified Information NPR 2830.1A NASA Enterprise Architecture Procedures NPR 2841.1 Identity, Credential, and Access Management NPR 3792.1D NASA’s Plan for a Drug Free Workplace NPR 4100.1F NASA Supply Support and Material Management NPR 4200.1H NASA Equipment Management Procedural Requirements NPR 4300.1C NASA Personal Property Disposal Procedural Requirements NPR 4500.1 Administration of Property in Custody of Contractors

NPR 7120.5F NASA Space Flight Program and Project Management Requirements

NPR 7120.6A Knowledge Policy for Programs and Projects

NPR 7120.7A NASA Information Technology Program and Project Management Requirements

NPR 7120.8A NASA Research and Technology Program and Project Management Requirements

NPR 7120.10B Technical Standards for NASA Programs and Projects NPR 7123.1C NASA Systems Engineering Processes and Requirements NPR 7150.2D NASA Software Engineering Requirements NPR 7500.2A NASA Technology Transfer Requirements NPR 8000.4C Agency Risk Management Procedural Requirements

NPR 8621.1D NASA Procedural Requirements for Mishap and Close Call Reporting, Investigating, and Recordkeeping

NPR 8705.5A Technical Probabilistic Risk Assessment (PRA) Procedures for Safety and Mission Success for NASA Programs and Projects

NPR 8705.6D Safety and Mission Assurance (SMA) Audits, Reviews, and Assessments

NPR 8715.3D NASA General Safety Program Requirements NPR 9501.2E NASA Contractor Financial Management Reporting NPR 9610.1B Accounts Receivable, Billing, and Collection

NPR 9640.1A Financial Management of Contractor Claims Against NASA NRRS 1441.1 NASA Records Retention Schedules NSTS 08117 Certification of Flight Readiness Requirements OIP 50952 International Space Station Program

OMB Circular A-108 Federal Agency Responsibilities for Review, Reporting and Publication under the Privacy Act, December 23, 2016.

OMB Circular A-11 Preparation, Submission, and Execution of the Budget.

OMB Circular A-123 Management's Responsibility for Internal Control OMB Circular A-130 Managing Information as a Strategic Resource OMB M-00-13 Privacy Policies and Data Collection on Federal Web Sites.

OMB M-01-05 Guidance on Inter-Agency Sharing of Personal Data - Protecting Personal Privacy.

OMB M-02-01 Guidance for Preparing and Submitting Security Plans of Actions and Milestones.

OMB M-03-22 OMB Guidance for Implementing the Privacy Provisions of the E- Government Act of 2002.

OMB M-04-04 E-Authentication Guidance for Federal Agencies.

OMB M-04-26 Personal Use Policies and "File Sharing" Technology.

OMB M-05-08 Designation of Senior Agency Officials for Privacy.

OMB M-05-24 Implementation of Homeland Security Directive (HSPD) 12.

OMB M-06-15 Safeguarding Personally Identifiable Information, May 22, 2006.

OMB M-06-16 Protection of Sensitive Agency Information

OMB M-07-16 Safeguarding Against and Responding to the Breach of Personally Identifiable Information

OMB M-10-23 Guidance for Agency Use of Third-Party Websites and Applications.

OMB M-11-11

Continued Implementation of Homeland Security Presidential Directive 12 (HSPD-12) – Policy for a Common Identification Standard for Federal Employees and Contractors

OMB M-13-10 Antideficiency Act Implications of Certain Online Terms of Service Agreements.

OMB M-15-13 Policy to require Secure Connections across Federal Websites and Web Services

OMB M-15-14 Management and Oversight of Federal Information Technology, Federal Information Technology (FITARA)

OMB M-16-04 Cybersecurity Strategy and Implementation Plan (CSIP) for the Federal Civilian Government

OMB M-17-12 Preparing for and Responding to a Breach of Personally Identifiable Information

OMB M-19-03

Office of Management and Budget (OMB) Memorandum 19-03, Strengthening the Cybersecurity of Federal Agencies by enhancing the High Value Asset Program

OMB M-19-17 Enabling Mission Delivery through Improved Identity, Credential, and Access Management

OMB M-21-07 Completing the Transition to Internet Protocol version 6 (IPv6), dated November 19, 2020

OMB M-21-30 Software Supply Chain Security OMB M-21-31 Event Security Logging OMB M-22-01 Endpoint Detection and Response

OMB M-22-09 Moving the U.S. Government Toward Zero Trust Cybersecurity Principles

Public Law 93-579 Privacy Act, December 1974 (Privacy Act)

Public Law 113-283, S. 2521 The Federal Information Security Modernization Act of 2014 (FISMA Reform)

Public Law 115-390 Secure Technology Act SAE AS9003 Inspection and Test Quality System SSP 50108 Certification of Flight Readiness for Space Station

SSP 50200-01-ANX AA

Station Program Implementation Plan (SPIP) Volume 1: Station Program Management Plan, Annex AA: Payload and Mission Operations Division

SSP-50952 Operations Interface Procedures (OIP) Management Plan

NASA Information Technology Strategic Plan Fiscal Years (2018- 2021)

Memoranda

Memo Subject From Date Annual Cybersecurity and Sensitive Unclassified Information Awareness Training

Office of the Chief Information Officer Sep 14, 2020

Government Furnished Equipment (GFE) and Personal Device Business Rules for Enrollment in NASA’s Mobile Device Management (MDM) Service

Chief Information Officer Nov 05, 2018

Use of Personally-Owned Mobile Devices to Connect to NASA Email, Calendar and Contacts Services

Chief Information Officer Oct 25, 2018

Office of the CIO (OCIO) Reviews of Survey Monkey

NASA Associate Chief lnformation Officer/Senior Agency Information Security Officer

Jun 07, 2018

NASA Information Technology Warning Banner Update NASA CIO Aug 09, 2017

Managing Software in Support of NASA's Mission NASA Administrator (Acting) May 05, 2017

Federal Source Code Policy: Achieving Efficiency, Transparency, and Innovation through Reusable and Open Source Software, OCIO Memorandum

NASA CIO Nov 07, 2016

Memo Subject From Date Federal Source Code Policy: Achieving Efficiency, Transparency, and Innovation through Reusable and Open Source Software, Framework and Implementation Guide

NASA CIO Nov 07, 2016

ITSD End of Life Vulnerability Memo NASA CIO Mar 30, 2016

NASA Policy Regarding Vulnerability Remediation and POA&M Timeline Standards

Information Technology Management Board

(ITMB)

Mar 04, 2016

Rescinding and/or Archiving Memos NASA Chief Information Officer Sep 01, 2015

Extension Verification 2810-02.05 (Acting) Senior Agency Information Security Officer

Nov 19, 2014

Extension Verification 2810-02.05 (Acting) Senior Agency Information Security Officer

Nov 19, 2014

Electronic and Information Technology Accessibility NASA Chief Information Officer Oct 10, 2014

NASA Guidance for Use of IT Contracts for Supporting End User Services (Mission Focus Review 137)

Associate Administrator Apr 30, 2014

NASA Digital Strategy

Associate Administrator for Communications, and Chief Information Officer

Mar 12, 2014

Implementation of National Institute of Standards and Technology Special Publication 800-53, Revision 4

Deputy Chief Information Officer for Information Technology Security

Dec 19, 2013

Rescinding and/or Archiving Information Technology (IT) Security Memoranda

Chief Information Officer Sep 20, 2012

File details come from the government source that posted it. Updated .