ATT D - Applicable Documents List.pdf
PDF 267 KB Posted
- Attached to
- NASA Consolidated Applications and Platform Services (NCAPS) Request for Proposal Federal contract opportunity
- Solicitation number
- 80TECH23R0002
View the file
Other files for this federal contract opportunity
Show all 47
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT D
NASA CONSOLIDATED APPLICATIONS AND
PLATFORM SERVICES (NCAPS)
APPLICABLE DOCUMENTS LIST (ADL)
RFP 80TECH23R0002
CONTRACT #TBD
DATE: JANUARY 2023
Attachment D
80TECH23R0002
This attachment contains a representative list of applicable documents for the contract effort. The document number reference in the contract may not contain the revision number. The latest revision of each document is the applicable document, and the contractor is responsible for ensuring application of the latest revisions. The contractor shall comply with these requirements in performing the Performance Work Statement (PWS) activities. Requirements written in these documents shall have full force and effect as if their text was written in this contract to the extent that the requirements relate to context of the work to be performed within the scope of this contract.
Document Number Title 15 CFR Parts 730-799 Export Administration Regulations (EAR) 22 CFR Parts 120-130 International Traffic in Arms Regulations (ITAR) 29 CFR Part 1903 Inspections, Citations, and Proposed Penalties
29 CFR Part 1910 Department of Labor; Occupational Safety and Health Administration Standards for General Industry
29 CFR Part 1926 Department of Labor; Occupational Safety and Health Administration Standards for Construction Industry
32 CFR Part 2001 Classified National Security Information 32 CFR Part 2002 Controlled Unclassified Information (CUI) 36 CFR Part 1220 Federal Records 40 U.S.C. § 11101 et seq. Clinger-Cohen Act of 1996 40 U.S.C. 11331 Responsibilities for Federal Information Systems Standards AA-Role-AODR Authorizing Official Designated Representative Summary AA-Role-AO Authorizing Official Summary AA-Role-CISO Center Chief Information Security Officer Summary AA-Role-CCRM Center Cybersecurity Risk Manager Summary AA-Role-CPM Center Privacy Manager Summary AA-Role-ISO Information System Owner Summary AA-Role-ISSE Information System Security Engineer Summary AA-Role-ISSO Information System Security Officer Summary AA-Role-SCA Security Control Assessor Summary ANSI/ISO/ASQ Q9001-2000 Quality Management Systems – Requirements AP-NASA-HDBK-001, V3.1 Applications Program Handbook Policy Handbook
BOD 18-02 Department of Homeland Security’s Binding Operational Directive 18-02, Securing High Value Assets
CNSSI 4009 Committee on National Security Systems (CNSS) Glossary CP-001-V4 CP Service Document (CSD)
CSO-SOP-0002
Communications Service Office (CSO) Standard Operating Procedure for Trouble Reporting, Activity Scheduling, Mission Freeze, and Major Outage Notifications
Executive Order (EO) 13526 Classifying and declassifying National Security Information EO 13556 Controlled Unclassified Information EO 13636 Improving Critical Infrastructure Cybersecurity EO 13834 Efficient Federal Operations EO 14028 Improving the Nation’s Cybersecurity
FIPS 140-3 Security Requirements For Cryptographic Modules FIPS 180-4 Secure Hash Standard (SHS) FIPS 186-4 Digital Signature Standard (DSS) FIPS 197 Advanced Encryption Standard (AES) FIPS 198-1 The Keyed-Hash Message Authentication Code (HMAC)
FIPS 199 Standards for Security Categorization of Federal Information and Information Systems
FIPS 200 Minimum Security Requirements for Federal Information and Information Systems
FIPS 201-3 Personal Identity Verification (PIV) of Federal Employees and Contractors
FIPS 202 SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions
HSPD-12 Policy for a Common Identification Standard for Federal Employees and Contractors
IETF RFC Memorandum 778 DCNET Internet Clock Service IETF RFC Memorandum 891 DCN Local-Network Protocols IETF RFC Memorandum 956 Algorithms for Synchronizing Network Clocks
IETF RFC Memorandum 5905 Network Time Protocol Version 4: Protocol and Algorithms Specification
ISO/IEC 17025 General Requirements for the Competence of Testing and Calibration Laboratories
IT-HBK-1440.01-01 Records Management Program and Records Life Cycle: Chapter 1
— Overview
IT-HBK-1441.01-01 Records Retention and Disposition: Chapter 1 — Overview ITS-HBK-1382.03-01 Privacy – Collections, PTAs, and PIAs
ITS-HBK-1382.03-02 Privacy Annual Reporting Procedures: Reviewing and Reducing PII and Unnecessary Use of SSN
ITS-HBK-1382.04-01 Privacy and Cybersecurity: Supporting and Integrated Controls Framework
ITS-HBK-1382.05-01 Privacy Incident Response and Management: Breach Response Team Checklist
ITS-HBK-1382.06-01 Privacy Notice and Redress — Web Privacy and Written Notice, Complaints, Access, and Redress
ITS-HBK-1382.07-01 Privacy Awareness and Training ITS-HBK-1382.08-01 Privacy Accountability ITS-HBK-1382.09-01 Privacy Rules of Behavior and Consequences ITS-HBK-2810.03-02B Planning ITS-HBK-2810.04-01A Risk Assessment, Vulnerability Scanning, and Expedited Patching ITS-HBK-2810.05-02B System and Service Acquisition ITS-HBK-2810.06-2B IT Security Awareness, Training, and Education ITS-HBK-2810.07-02B Configuration Management ITS-HBK-2810.08-01A Contingency Planning ITS-HBK-2810.09-01 Incident Response and Management
ITS-HBK-2810.09-02A NASA Information Security Incident Management (CUI) ITS-HBK-2810.09-03A Collection of Electronic Data (CUI)
ITS-HBK-2810.09-04 Incident Response and Management: Guidelines for Data Spillage and Sanitization Procedures
ITS-HBK-2810.10-02C Maintenance ITS-HBK-2810.11-2C Media Protection and Sanitization ITS-HBK-2810.12-02B Physical and Environmental Protection ITS-HBK-2810.13-01B Personnel Security ITS-HBK-2810.14-03D System and Information Integrity – System and Info Integrity ITS-HBK-2810.15-01A Access Control ITS-HBK-2810.15-02A Access Control: Managed Elevated Privileges (CUI) ITS-HBK-2810.16-02B Audit and Accountability ITS-HBK-2810.17-02B Identification and Authentication ITS-HBK-2810.18-02B System and Communications Protection ITS-HBK-2810.19-01 Operational Technology IT-HBK-2841-03A Identity, Credential, and Access Management (ICAM) Services ITS-HBK-CUI v1.0.0 Controlled Unclassified Information Handbook
ITS-HBK-SCRM.2810.v1.0.0 Information & Communications Technology Supply Chain Risk Management (ICT SCRM)
ITS-HBK-AASTEP0.v1.0.0 Step 0: Prepare Policy ITS-HBK-AASTEP1.v1.0.0 Step 1: Categorize Policy ITS-HBK-AASTEP2.v1.0.0 Step 2: Select Policy ITS-HBK-AASTEP3.v.1.0.0 Step 3: Implement Policy ITS-HBK-AASTEP4.v1.0.0 Step 4: Assess Policy ITS-HBK-AASTEP5.v1.0.0 Step 5: Authorize Policy ITS-HBK-AASTEP6.v.1.0.0 Step 6: Monitor Policy MIL-HDBK-881D Department of Defense Handbook Work Breakdown Structure NAII 2190.1E NASA Export Control Program Operations Manual
NAII 2810.1 Networks in NASA Internet Protocol (IP) Space or NASA Physical Space
NAII 2810.2 Email Services NASA-HDBK-2203 Software Engineering Handbook NASA/SP-2007-6105 NASA Systems Engineering Handbook NASA-SPEC-2600 Enumeration of ASCS Cybersecurity Requirements
NASA-SPEC-2661.Controls Control Baselines and Critical Controls for NASA Information Systems
NASA-SPEC-2661.ODVr5 NASA’s Organization-Defined Values for NIST SP 800-53 Revision 5
NASA-STD-2601 Minimum Cybersecurity Requirements for Computing Systems
NASA-STD-2602 Minimum Information System Owner and End User Security for Data at Rest
NASA-STD-2603 Minimum Security and Privacy Requirements for Agency and Center Information System Implementations
NASA-STD-2604 Computing System Configuration Management
NASA-STD-2804 Minimum Interoperability Software Suite NASA-STD-2805 Minimum Hardware Configurations NASA-STD-2818 Digital Television for NASA NASA-STD-8739.8B Software Assurance and Software Safety Standard NASA-STD-8739.9 Software Formal Inspection Standard National Defense Authorization Act (NDAA) section 889
Prohibition On Certain Telecommunications and Video Surveillance Services or Equipment
NIST SP 1800-10 Protecting Information and System Integrity in Industrial Control System Environments: Cybersecurity for the Manufacturing Sector
NIST SP 800-12 Rev. 1 An Introduction to Computer Security: the NIST Handbook
NIST SP 800-18 Rev. 1 Guide for Developing Security Plans for Federal Information Systems
NIST SP 800-22 Rev. 1a A Statistical Test Suite for Random and Pseudorandom Number Generators for Cryptographic Applications
NIST SP 800-28 Version 2 Guidelines on Active Content and Mobile Code NIST SP 800-30 Rev. 1 Guide for Conducting Risk Assessments NIST SP 800-34 Rev. 1 Contingency Planning Guide for Federal Information Systems NIST SP 800-35 Guide to Information Technology Security Services
NIST SP 800-37 Rev. 2 Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy
NIST SP 800-38A Recommendation for Block Cipher Modes of Operation: Methods and Techniques
NIST SP 800-38A Addendum Recommendation for Block Cipher Modes of Operation: Three Variants of Ciphertext Stealing for CBC Mode
NIST SP 800-38B Recommendation for Block Cipher Modes of Operation: the CMAC Mode for Authentication
NIST SP 800-38C Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality
NIST SP 800-38D Recommendation for Block Cipher Modes of Operation:
Galois/Counter Mode (GCM) and GMAC
NIST SP 800-38E Recommendation for Block Cipher Modes of Operation: the XTS- AES Mode for Confidentiality on Storage Devices
NIST SP 800-38F Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping
NIST SP 800-38G Recommendation for Block Cipher Modes of Operation: Methods for Format-Preserving Encryption
NIST SP 800-39 Managing Information Security Risk: Organization, Mission, and Information System View
NIST SP 800-40 Rev. 4 Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology
NIST SP 800-41 Rev. 1 Guidelines on Firewalls and Firewall Policy NIST SP 800-44 Version 2 Guidelines on Securing Public Web Servers NIST SP 800-45 Version 2 Guidelines on Electronic Mail Security
NIST SP 800-46 Rev. 2 Guide to Enterprise Telework, Remote Access, and Bring Your Own Device (BYOD) Security
NIST SP 800-47 Rev. 1 Managing the Security of Information Exchanges NIST SP 800-49 Federal S/MIME V3 Client Profile
NIST SP 800-50 Building an Information Technology Security Awareness and Training Program
NIST SP 800-51 Rev. 1 Guide to Using Vulnerability Naming Schemes
NIST SP 800-52 Rev. 2 Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations
NIST SP 800-53 Rev. 5 Security and Privacy Controls for Federal Information Systems and Organizations
NIST SP 800-53A Rev. 5 Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans
NIST SP 800-53B Control Baselines for Information Systems and Organizations NIST SP 800-55 Rev. 1 Performance Measurement Guide for Information Security
NIST SP 800-56A Rev. 3 Recommendation for Pair-Wise Key-Establishment Schemes Using Discrete Logarithm Cryptography
NIST SP 800-56B Rev. 2 Recommendation for Pair-Wise Key-Establishment Using Integer Factorization Cryptography
NIST SP 800-56C Rev. 2 Recommendation for Key-Derivation Methods in Key- Establishment Schemes
NIST SP 800-57 Part 1 Rev. 5 Recommendation for Key Management: Part 1 – General
NIST SP 800-57 Part 2 Rev. 1 Recommendation for Key Management: Part 2 – Best Practices for Key Management Organizations
NIST SP 800-57 Part 3 Rev. 1 Recommendation for Key Management, Part 3: Application-Specific Key Management Guidance
NIST SP 800-58 Security Considerations for Voice Over IP Systems
NIST SP 800-59 Guideline for Identifying an Information System as a National Security System
NIST SP 800-60 Vol. 1 Rev. 1 Guide for Mapping Types of Information and Information Systems to Security Categories
NIST SP 800-60 Vol. 2 Rev. 1 Guide for Mapping Types of Information and Information Systems to Security Categories: Appendices
NIST SP 800-61 Rev. 2 Computer Security Incident Handling Guide NIST SP 800-63-3 Digital Identity Guidelines NIST SP 800-63A Digital Identity Guidelines: Enrollment and Identity Proofing
NIST SP 800-63B Digital Identity Guidelines: Authentication and Lifecycle Management
NIST SP 800-63C Digital Identity Guidelines: Federation and Assertions
NIST SP 800-66 Rev. 1 An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule
NIST SP 800-67 Rev. 2 Recommendation for the Triple Data Encryption Algorithm (TDEA) Block Cipher
NIST SP 800-70 Rev. 4 National Checklist Program for IT Products: Guidelines for Checklist Users and Developers
NIST SP 800-72 Guidelines on PDA Forensics NIST SP 800-73-4 Interfaces for Personal Identity Verification NIST SP 800-76-2 Biometric Specifications for Personal Identity Verification NIST SP 800-77 Rev. 1 Guide to IPsec VPNs
NIST SP 800-78-4 Cryptographic Algorithms and Key Sizes for Personal Identity Verification
NIST SP 800-79-2 Guidelines for the Authorization of Personal Identity Verification Card Issuers (PCI) and Derived PIV Credential Issuers (DPCI)
NIST SP 800-81-2 Secure Domain Name System (DNS) Deployment Guide NIST SP 800-82 Rev. 2 Guide to Industrial Control Systems (ICS) Security
NIST SP 800-83 Rev. 1 Guide to Malware Incident Prevention and Handling for Desktops and Laptops
NIST SP 800-84 Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities
NIST SP 800-85A-4 PIV Card Application and Middleware Interface Test Guidelines (SP 800-73-4 Compliance)
NIST SP 800-85B PIV Data Model Test Guidelines NIST SP 800-86 Guide to Integrating Forensic Techniques into Incident Response
NIST SP 800-87 Rev. 2 Codes for Identification of Federal and Federally-Assisted Organizations
NIST SP 800-88 Rev. 1 Guidelines for Media Sanitization
NIST SP 800-89 Recommendation for Obtaining Assurances for Digital Signature Applications
NIST SP 800-90A Rev. 1 Recommendation for Random Number Generation Using Deterministic Random Bit Generators
NIST SP 800-90B Recommendation for the Entropy Sources Used for Random Bit Generation
NIST SP 800-92 Guide to Computer Security Log Management NIST SP 800-94 Guide to Intrusion Detection and Prevention Systems (IDPS) NIST SP 800-95 Guide to Secure Web Services NIST SP 800-96 PIV Card to Reader Interoperability Guidelines
NIST SP 800-97 Establishing Wireless Robust Security Networks: A Guide to IEEE 802.11i
NIST SP 800-98 Guidelines for Securing Radio Frequency Identification (RFID) Systems
NIST SP 800-100 Information Security Handbook: A Guide for Managers NIST SP 800-101 Rev. 1 Guidelines on Mobile Device Forensics NIST SP 800-102 Recommendation for Digital Signature Timeliness NIST SP 800-106 Randomized Hashing for Digital Signatures
NIST SP 800-107 Rev. 1 Recommendation for Applications Using Approved Hash Algorithms
NIST SP 800-108 Rev. 1 Recommendation for Key Derivation Using Pseudorandom Functions
NIST SP 800-111 Guide to Storage Encryption Technologies for End User Devices NIST SP 800-113 Guide to SSL VPNs
NIST SP 800-114 Rev. 1 User's Guide to Telework and Bring Your Own Device (BYOD) Security
NIST SP 800-115 Technical Guide to Information Security Testing and Assessment NIST SP 800-116 Rev. 1 Guidelines for the Use of PIV Credentials in Facility Access NIST SP 800-119 Guidelines for the Secure Deployment of IPv6 NIST SP 800-121 Rev. 2 Guide to Bluetooth Security
NIST SP 800-122 Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)
NIST SP 800-123 Guide to General Server Security
NIST SP 800-124 Rev. 1 Guidelines for Managing the Security of Mobile Devices in the Enterprise
NIST SP 800-125 Guide to Security for Full Virtualization Technologies NIST SP 800-125A Rev. 1 Security Recommendations for Server-based Hypervisor Platforms
NIST SP 800-125B Secure Virtual Network Configuration for Virtual Machine (VM) Protection
NIST SP 800-126 Rev. 3 The Technical Specification for the Security Content Automation Protocol (SCAP): SCAP Version 1.3
NIST SP 800-126A SCAP 1.3 Component Specification Version Updates: An Annex to NIST Special Publication 800-126 Revision 3
NIST SP 800-128 Guide for Security-Focused Configuration Management of Information Systems
NIST SP 800-130 A Framework for Designing Cryptographic Key Management Systems
NIST SP 800-131A Rev. 2 Transitioning the Use of Cryptographic Algorithms and Key Lengths
NIST SP 800-132 Recommendation for Password-Based Key Derivation: Part 1:
Storage Applications
NIST SP 800-133 Rev. 2 Recommendation for Cryptographic Key Generation
NIST SP 800-135 Rev. 1 Recommendation for Existing Application-Specific Key Derivation Functions
NIST SP 800-137 Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations
NIST SP 800-137A Assessing Information Security Continuous Monitoring (ISCM) Programs: Developing an ISCM Program Assessment
NIST SP 800-140 FIPS 140-3 Derived Test Requirements (DTR): CMVP Validation Authority Updates to ISO/IEC 24759
NIST SP 800-140A CMVP Documentation Requirements: CMVP Validation Authority Updates to ISO/IEC 24759
NIST SP 800-140B CMVP Security Policy Requirements: CMVP Validation Authority Updates to ISO/IEC 24759 and ISO/IEC 19790 Annex B
NIST SP 800-140C Rev. 1 CMVP Approved Security Functions: CMVP Validation Authority Updates to ISO/IEC 24759
NIST SP 800-140D Rev. 1 CMVP Approved Sensitive Parameter Generation and Establishment Methods: CMVP Validation Authority Updates to
ISO/IEC 24759
NIST SP 800-140E
CMVP Approved Authentication Mechanisms: CMVP Validation Authority Requirements for ISO/IEC 19790 Annex E and ISO/IEC 24579 Section 6.17
NIST SP 800-140F CMVP Approved Non-Invasive Attack Mitigation Test Metrics:
CMVP Validation Authority Updates to ISO/IEC 24759
NIST SP 800-142 Practical Combinatorial Testing NIST SP 800-144 Guidelines on Security and Privacy in Public Cloud Computing NIST SP 800-145 The NIST Definition of Cloud Computing NIST SP 800-146 Cloud Computing Synopsis and Recommendations NIST SP 800-147 BIOS Protection Guidelines NIST SP 800-147B BIOS Protection Guidelines for Servers NIST SP 800-150 Guide to Cyber Threat Information Sharing
NIST SP 800-152 A Profile for U.S. Federal Cryptographic Key Management Systems
(CKMS)
NIST SP 800-153 Guidelines for Securing Wireless Local Area Networks (WLANs) NIST SP 800-156 Representation of PIV Chain-of-Trust for Import and Export
NIST SP 800-157 Guidelines for Derived Personal Identity Verification (PIV) Credentials
NIST SP 800-16 Information Technology Security Training Requirements: A Role-and Performance-Based Model
NIST SP 800-160 Vol. 1 Systems Security Engineering: Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems
NIST SP 800-160 Vol. 2 Rev. 1 Developing Cyber-Resilient Systems: A Systems Security Engineering Approach
NIST SP 800-161 Rev. 1 Supply Chain Risk Management Practices for Federal Information Systems and Organizations
NIST SP 800-162 Guide to Attribute Based Access Control (ABAC) Definition and Considerations
NIST SP 800-163 Rev. 1 Vetting the Security of Mobile Applications NIST SP 800-166 Derived PIV Application and Data Model Test Guidelines NIST SP 800-167 Guide to Application Whitelisting NIST SP 800-168 Approximate Matching: Definition and Terminology
NIST SP 800-171 Rev. 2 Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
NIST SP 800-171A Assessing Security Requirements for Controlled Unclassified Information
NIST SP 800-172
Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171
NIST SP 800-172A Assessing Security Requirements for Controlled Unclassified Information
NIST SP 800-175A Guideline for Using Cryptographic Standards in the Federal Government: Directives, Mandates and Policies
NIST SP 800-175B Rev. 1 Guideline for Using Cryptographic Standards in the Federal Government: Cryptographic Mechanisms
NIST SP 800-177 Rev. 1 Trustworthy Email
NIST SP 800-178
A Comparison of Attribute Based Access Control (ABAC) Standards for Data Service Applications: Extensible Access Control Markup Language (XACML) and Next Generation Access Control
(NGAC)
NIST SP 800-181 Rev. 1 National Initiative for Cybersecurity Education (NICE) Cybersecurity Workforce Framework
NIST SP 800-183 Networks of 'Things' NIST SP 800-184 Guide for Cybersecurity Event Recovery
NIST SP 800-185 SHA-3 Derived Functions: cSHAKE, KMAC, TupleHash, and ParallelHash
NIST SP 800-187 Guide to LTE Security
NIST SP 800-189 Resilient Interdomain Traffic Exchange: BGP Security and DDoS Mitigation
NIST SP 800-190 Application Container Security Guide NIST SP 800-192 Verification and Test Methods for Access Control Policies/Models NIST SP 800-193 Platform Firmware Resiliency Guidelines NIST SP 800-202 Quick Start Guide for Populating Mobile Test Devices NIST SP 800-204 Security Strategies for Microservices-based Application Systems
NIST SP 800-204A Building Secure Microservices-based Applications Using Service- Mesh Architecture
NIST SP 800-204B Attribute-based Access Control for Microservices-based Applications using a Service Mesh
NIST SP 800-204C Implementation of DevSecOps for a Microservices-based Application with Service Mesh
NIST SP 800-205 Attribute Considerations for Access Control Systems NIST SP 800-207 Zero Trust Architecture NIST SP 800-208 Recommendation for Stateful Hash-Based Signature Schemes NIST SP 800-209 Security Guidelines for Storage Infrastructure NIST SP 800-210 General Access Control Guidance for Cloud Systems
NIST SP 800-213 IoT Device Cybersecurity Guidance for the Federal Government:
Establishing IoT Device Cybersecurity Requirements
NIST SP 800-213A IoT Device Cybersecurity Guidance for the Federal Government:
IoT Device Cybersecurity Requirement Catalog
NIST SP 800-218
Secure Software Development Framework (SSDF) Version 1.1:
Recommendations for Mitigating the Risk of Software Vulnerabilities
NIST SP 800-219 Automated Secure Configuration Guidance from the macOS Security Compliance Project (mSCP)
NIST SP 800-220 Fiscal Year 2021 Cybersecurity and Privacy Annual Report NPD 1000.0C NASA Governance and Strategic Management Handbook NPD 1280.1A NASA Integrated Management System Policy NPD 1380.1 Managing Agency Communications NPD 1382.17K NASA Privacy Policy NPD 1383.1C Release and Management of Audiovisual Products NPD 1385.2I Public Appearances of NASA Personnel, Including Astronauts NPD 1420.1A NASA Forms Management NPD 1440.6I NASA Records Management NPD 1600.2E NASA Security Policy NPD 1600.3 Policy on Prevention of and Response to Workplace Violence NPD 1600.4 National Security Programs NPD 1600.9A NASA Insider Threat Program NPD 2190.1B NASA Export Control Program NPD 2200.1D Management of NASA Scientific and Technical Information
NPD 2540.1K
Acceptable Use of Government Furnished Information Technology Equipment, Services and Resources Equipment, Services and Resources
NPD 2800.1E Managing Information Technology NPD 2810.1F NASA Information Security Policy NPD 2830.1D NASA Enterprise Architecture NPD 4200.1C Equipment Management NPD 7120.4E NASA Engineering and Program/Project Management Policy NPD 7120.6A Knowledge Policy for Program and Projects
NPD 7410.1H Management of Contract and Grant Support Services Obtained from External Sources (Revalidated 8/14/2018)
NPD 7500.1D Program and Project Life-Cycle Logistics Support Policy NPD 7620.1I Official Names for Major NASA Projects NPD 8610.23C Launch Vehicle Technical Oversight Policy NPD 8610.24C Launch Services Program Pre-Launch Readiness Reviews
NPD 8610.7D Launch Services Risk Mitigation Policy for NASA-Owned and/or NASA-Sponsored Payloads/Missions
NPD 8700.1F NASA Policy for Safety and Mission Success NPD 8710.1D Emergency Management Program NPD 9501.1I NASA Contractor Financial Management Reporting System
NPR 1040.1 NASA Continuity of Operations (COOP) Planning Procedural Requirements
NPR 1382.1B NASA Privacy Procedural Requirements NPR 1385.1A Public Appearances of NASA Personnel, Including Astronauts
NPR 1441.1E NASA Records Management Program Requirements
NPR 1450.10D NASA Correspondence Management and Communications Standards and Style
NPR 1600.1A NASA Security Program Procedural Requirements NPR 1600.2A NASA Classified National Security Information (CNSI) NPR 1600.3A Personnel Security NPR 1600.4A Identity and Credential Management NPR 1600.6A Communications Security (COMSEC) NPR 1660.1C NASA Counterintelligence and Counterterrorism NPR 2190.1C NASA Export Control Program NPR 2210.1C Release of NASA Software NPR 2800.2A Information and Communication Technology Accessibility NPR 2810.1F Security of Information and Information Systems
NPR 2810.2 Possession and Use of NASA Information and Information Systems Outside of the United States and United States Territories
NPR 2810.7 Controlled Unclassified Information NPR 2830.1A NASA Enterprise Architecture Procedures NPR 2841.1 Identity, Credential, and Access Management NPR 3792.1D NASA’s Plan for a Drug Free Workplace NPR 4100.1F NASA Supply Support and Material Management NPR 4200.1H NASA Equipment Management Procedural Requirements NPR 4300.1C NASA Personal Property Disposal Procedural Requirements NPR 4500.1 Administration of Property in Custody of Contractors
NPR 7120.5F NASA Space Flight Program and Project Management Requirements
NPR 7120.6A Knowledge Policy for Programs and Projects
NPR 7120.7A NASA Information Technology Program and Project Management Requirements
NPR 7120.8A NASA Research and Technology Program and Project Management Requirements
NPR 7120.10B Technical Standards for NASA Programs and Projects NPR 7123.1C NASA Systems Engineering Processes and Requirements NPR 7150.2D NASA Software Engineering Requirements NPR 7500.2A NASA Technology Transfer Requirements NPR 8000.4C Agency Risk Management Procedural Requirements
NPR 8621.1D NASA Procedural Requirements for Mishap and Close Call Reporting, Investigating, and Recordkeeping
NPR 8705.5A Technical Probabilistic Risk Assessment (PRA) Procedures for Safety and Mission Success for NASA Programs and Projects
NPR 8705.6D Safety and Mission Assurance (SMA) Audits, Reviews, and Assessments
NPR 8715.3D NASA General Safety Program Requirements NPR 9501.2E NASA Contractor Financial Management Reporting NPR 9610.1B Accounts Receivable, Billing, and Collection
NPR 9640.1A Financial Management of Contractor Claims Against NASA NRRS 1441.1 NASA Records Retention Schedules NSTS 08117 Certification of Flight Readiness Requirements OIP 50952 International Space Station Program
OMB Circular A-108 Federal Agency Responsibilities for Review, Reporting and Publication under the Privacy Act, December 23, 2016.
OMB Circular A-11 Preparation, Submission, and Execution of the Budget.
OMB Circular A-123 Management's Responsibility for Internal Control OMB Circular A-130 Managing Information as a Strategic Resource OMB M-00-13 Privacy Policies and Data Collection on Federal Web Sites.
OMB M-01-05 Guidance on Inter-Agency Sharing of Personal Data - Protecting Personal Privacy.
OMB M-02-01 Guidance for Preparing and Submitting Security Plans of Actions and Milestones.
OMB M-03-22 OMB Guidance for Implementing the Privacy Provisions of the E- Government Act of 2002.
OMB M-04-04 E-Authentication Guidance for Federal Agencies.
OMB M-04-26 Personal Use Policies and "File Sharing" Technology.
OMB M-05-08 Designation of Senior Agency Officials for Privacy.
OMB M-05-24 Implementation of Homeland Security Directive (HSPD) 12.
OMB M-06-15 Safeguarding Personally Identifiable Information, May 22, 2006.
OMB M-06-16 Protection of Sensitive Agency Information
OMB M-07-16 Safeguarding Against and Responding to the Breach of Personally Identifiable Information
OMB M-10-23 Guidance for Agency Use of Third-Party Websites and Applications.
OMB M-11-11
Continued Implementation of Homeland Security Presidential Directive 12 (HSPD-12) – Policy for a Common Identification Standard for Federal Employees and Contractors
OMB M-13-10 Antideficiency Act Implications of Certain Online Terms of Service Agreements.
OMB M-15-13 Policy to require Secure Connections across Federal Websites and Web Services
OMB M-15-14 Management and Oversight of Federal Information Technology, Federal Information Technology (FITARA)
OMB M-16-04 Cybersecurity Strategy and Implementation Plan (CSIP) for the Federal Civilian Government
OMB M-17-12 Preparing for and Responding to a Breach of Personally Identifiable Information
OMB M-19-03
Office of Management and Budget (OMB) Memorandum 19-03, Strengthening the Cybersecurity of Federal Agencies by enhancing the High Value Asset Program
OMB M-19-17 Enabling Mission Delivery through Improved Identity, Credential, and Access Management
OMB M-21-07 Completing the Transition to Internet Protocol version 6 (IPv6), dated November 19, 2020
OMB M-21-30 Software Supply Chain Security OMB M-21-31 Event Security Logging OMB M-22-01 Endpoint Detection and Response
OMB M-22-09 Moving the U.S. Government Toward Zero Trust Cybersecurity Principles
Public Law 93-579 Privacy Act, December 1974 (Privacy Act)
Public Law 113-283, S. 2521 The Federal Information Security Modernization Act of 2014 (FISMA Reform)
Public Law 115-390 Secure Technology Act SAE AS9003 Inspection and Test Quality System SSP 50108 Certification of Flight Readiness for Space Station
SSP 50200-01-ANX AA
Station Program Implementation Plan (SPIP) Volume 1: Station Program Management Plan, Annex AA: Payload and Mission Operations Division
SSP-50952 Operations Interface Procedures (OIP) Management Plan
NASA Information Technology Strategic Plan Fiscal Years (2018- 2021)
Memoranda
Memo Subject From Date Annual Cybersecurity and Sensitive Unclassified Information Awareness Training
Office of the Chief Information Officer Sep 14, 2020
Government Furnished Equipment (GFE) and Personal Device Business Rules for Enrollment in NASA’s Mobile Device Management (MDM) Service
Chief Information Officer Nov 05, 2018
Use of Personally-Owned Mobile Devices to Connect to NASA Email, Calendar and Contacts Services
Chief Information Officer Oct 25, 2018
Office of the CIO (OCIO) Reviews of Survey Monkey
NASA Associate Chief lnformation Officer/Senior Agency Information Security Officer
Jun 07, 2018
NASA Information Technology Warning Banner Update NASA CIO Aug 09, 2017
Managing Software in Support of NASA's Mission NASA Administrator (Acting) May 05, 2017
Federal Source Code Policy: Achieving Efficiency, Transparency, and Innovation through Reusable and Open Source Software, OCIO Memorandum
NASA CIO Nov 07, 2016
Memo Subject From Date Federal Source Code Policy: Achieving Efficiency, Transparency, and Innovation through Reusable and Open Source Software, Framework and Implementation Guide
NASA CIO Nov 07, 2016
ITSD End of Life Vulnerability Memo NASA CIO Mar 30, 2016
NASA Policy Regarding Vulnerability Remediation and POA&M Timeline Standards
Information Technology Management Board
(ITMB)
Mar 04, 2016
Rescinding and/or Archiving Memos NASA Chief Information Officer Sep 01, 2015
Extension Verification 2810-02.05 (Acting) Senior Agency Information Security Officer
Nov 19, 2014
Extension Verification 2810-02.05 (Acting) Senior Agency Information Security Officer
Nov 19, 2014
Electronic and Information Technology Accessibility NASA Chief Information Officer Oct 10, 2014
NASA Guidance for Use of IT Contracts for Supporting End User Services (Mission Focus Review 137)
Associate Administrator Apr 30, 2014
NASA Digital Strategy
Associate Administrator for Communications, and Chief Information Officer
Mar 12, 2014
Implementation of National Institute of Standards and Technology Special Publication 800-53, Revision 4
Deputy Chief Information Officer for Information Technology Security
Dec 19, 2013
Rescinding and/or Archiving Information Technology (IT) Security Memoranda
Chief Information Officer Sep 20, 2012
File details come from the government source that posted it. Updated .