ATT Y - NCAPS Contract Demarks.pdf

PDF 268 KB Posted

Attached to
NASA Consolidated Applications and Platform Services (NCAPS) Request for Proposal Federal contract opportunity
Solicitation number
80TECH23R0002
Issued by
National Aeronautics and Space Administration

View the file

Other files for this federal contract opportunity

Other files attached to NASA Consolidated Applications and Platform Services (NCAPS) Request for Proposal, newest first.
File Type Posted
ATT G - Acronyms Terms and Definitions - Amendment 02.pdf PDF
Questions and Answers for Request for Proposal 80TECH23R0002 Amendment 02.pdf PDF
NCAPS Request for Proposal - 80TECH23R0002 - Amendment 02.pdf PDF
ATT J - Fixed Price Story Point Process - Amendment 01.pdf PDF
Request for Proposal 80TECH23R0002 Amendment 01.pdf PDF
ATT L - Service Catalog Descriptions - Amendment 01.pdf PDF
Question and Answers for Request for Proposals 80TECH23R0002.pdf PDF
Exhibit 1-NCAPS Pricing Matrix Amendment 01.xlsx XLSX spreadsheet
ATT B - DRDs - Amendment 01.pdf PDF
ATT S - Application Inventory - Amendment 01.pdf PDF
ATT A - Performance Work Statement.pdf PDF
ATT D - Applicable Documents List.pdf PDF
ATT G - Acronyms Terms and Definitions.pdf PDF
ATT L - Service Catalog Descriptions.pdf PDF
Enclosure 1 - Quality Assurance Surveillance Plan.pdf PDF
Exhibit 2 Small Business Subcontracting Plan Goals.xlsx XLSX spreadsheet
Exhibit 3 - Past Performance Questionnaire.pdf PDF
AAO Program Increment.pdf PDF
ATT O - Contract Management Plan.pdf PDF
ATT E - SHE Plan.pdf PDF
ATT I - Service Catalog Pricing Matrix.pdf PDF
ATT J - Fixed Price Story Point Process.pdf PDF
ATT N - IT Security Management Plan.pdf PDF
ATT P - Deliverable Products and Services (DPS).pdf PDF
ATT S - Application Inventory.pdf PDF
ATT V - SB Subcontracting Plan.pdf PDF
ATT W - Financial Management Reporting.pdf PDF
Exhibit 1-NCAPS Pricing Matrix.xlsx XLSX spreadsheet
NCAPS Question Template.xlsx XLSX spreadsheet
ATT B - DRDs.pdf PDF
ATT C - Wage Determinations.pdf PDF
ATT F - Organizational Conflict of Interest (OCI) Plan.pdf PDF
ATT H - Phase-in Plan.pdf PDF
ATT Q - DD Form 254.pdf PDF
ATT R - CATS - iSite Contractor On-boarding Guide.pdf PDF
Enclosure 2 - KnowledgeArticleTemplate.pdf PDF
Agency Background and Historical.pdf PDF
Center Background and Historical.pdf PDF
Internal NASA Documents.pdf PDF
NCAPS 80TECH23R0002 Request for Proposal.pdf PDF
ATT K - Application Support Levels.pdf PDF
ATT M - Service Delivery Standards and Metrics.pdf PDF
ATT Q - DD Form 254 Cover.pdf PDF
ATT Q - Attachment 1 to DD Form 254.pdf PDF
ATT U - Labor Category Position Descriptions.pdf PDF
Enclosure 3 - IT Security Management Plan Template.pdf PDF
Historical IT WYEs.pdf PDF
Show all 47

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ATTACHMENT Y

NASA CONSOLIDATED APPLICATIONS AND

PLATFORM SERVICES (NCAPS)

NCAPS – CONTRACTS DEMARKS

RFP 80TECH23R0002

CONTRACT #TBD

DATE: MARCH 2023

Attachment Y

80TECH23R0002

Microsoft SQL Database Demarks

Tasks NCAPS AEGIS Comments OS Loading X OS Patching X Certificates & Permissions Management (OS) X Coordination with NCAPS; least privileged; NAMS workflow creation

Troubleshooting Expertise Provided X X AEGIS troubleshooting will stop at the OS level.

DB SW Loaded X X AEGIS loads according to the request submitted by NCAPS.

Coordination between contracts required.

DB SW Patching

X X NCAPS responsible for testing patch prior to patching and verification of functionality post patching. Coordination between contracts required.

Backup & Restores Management. Server Wide Databases X

AEGIS performs routine DB backups and stores for 30 days; anything outside of this would need to be requested and coordinated between contractors.

Initial DB instance created X NCAPS to also specify storage size Individual DB Management X IT Security Plan Creation and Maintenance Infrastructure X

Application Specific data for IT Security Plan X

Non-Microsoft SQL Database (Oracle, mysql, mongodb, etc) Demarks

Tasks NCAPS AEGIS Comments OS Loading X OS Patching X Certificates & Permissions Management

(OS)

X Coordination with NCAPS; least privileged; NAMS workflow creation

Troubleshooting Expertise Provided X X AEGIS Troubleshooting stops at OS DB SW Loaded X DB SW Patching X Backup & Restores Management. Server Wide Databases X

NCAPS configures the database backups and performs the database restore.

AEGIS maintenance the responsibility for storage, protection, and any offsite DR capabilities.

Initial DB instance created X Individual DB Management X IT Security Plan Creation and Maintenance/Infrastructure

X

Middleware (Java, ColdFusion, WordPress, etc.)

Tasks NCAPS AEGIS Comments OS Loading X OS Patching X Certificates & Permissions Management

(OS)

X Coordination with NCAPS; least privileged; NAMS workflow creation

Troubleshooting Expertise Provided X X AEGIS troubleshooting stops at OS Certificates & Permissions Management (Web server and middleware; e.g., Java Keystore)

X OS and Middleware

Day to Day Operations Management (Middleware Configuration) X

Plug-in management X Middleware permissions X Middleware patching X IT Security Plan Creation and Maintenance

X

COTS software (Windchill, SharePoint, GIS) Tasks NCAPS AEGIS Comments OS Loading X OS Patching X Certificates & Permissions Management

(OS)

X Coordination with NCAPS; least privileged;

NAMS workflow creation

Troubleshooting Expertise Provided X X AEGIS troubleshooting stops at OS Certificates & Permissions Management (Web server and middleware e.g., Java Keystore)

X OS and COTS that's required beyond the baseline that's provided by AEGIS that's unique to the COTS product.

Day to Day Operations Management (COTS Configuration) X

COTS permissions X COTS patching X IT Security Plan Creation and Maintenance/Infrastructure

X

OnPrem Containers Tasks NCAPS AEGIS Comments OS Loading X OS Patching X Certificates & Permissions Management

(OS)

X Coordination with NCAPS; least privileged;

NAMS workflow creation

Troubleshooting Expertise Provided X X AEGIS troubleshooting stops at OS VM Load Kubernetes SW X VM Maintance Kubernetes SW X Configuration Management & Certificates (Day-to-Day Operations) (Kubernetes) X

Internal Kubernetes Security Management (Container & Container to Container) X

Workflows (Creation & Configuration Management) X Workflows/DevSecOps Pipeline

Container Templates (including Containerized DB) (Creation & Configuration Management)

X

IT Security Plan Creation and Maintenance/Infrastructure

X

(08/2022)

Cloud Containers Tasks NCAPS AEGIS Comments Security & Permissions Management (Kubernetes) X

Configuration Management & Certificates (Day-to-Day Operations) (Kurbernetes) X

Internal Kubernetes Security Management (Container & Container to Container) X

Workflows (Creation & Configuration Management) X

Container Templates (including Containerized DB) (Creation & Configuration Management)

X

Database Connection Management X IT Security Plan Creation and Maintenance X Infrastructure (CPU, RAM, Storage) needed to run Cloud Containers X

Cybersecurity Tasks NCAPS ICAM* AEGIS CYPRESS Comments

NASA

CONTINUOUS

DIAGNOTICS &

MITIGATION

(CDM) Tool (e.g., BigFix, ITSEC-

EDW)

X X X

AEGIS is responsible for installation, configuration, and management of tools.

CyPrESS is responsible for procuring these tools and measuring compliance.

NCAPS is responsible for utilizing tools to respond to vulnerabilities and other non-compliance issues under the contract purview.

Endpoint Virus Protection - Anti- Malware and Anti- Virus Software

X X

AEGIS is responsible for installation, configuration, and management of tools.

CyPrESS is responsible for procuring these tools for measuring and validating compliance.

Trust Anchor Management (NTAM) - Per

NASA-SPEC-2664

X X

AEGIS is responsible for installation, configuration, and management of tools.

ICAM is responsible for procuring certificates and ensuring compliance.

Note: NTAM is a NASA-provided block of trusted Public Key Infrastructure (PKI) root and intermediate certificates used to identify an assigned certificate authority.

Agency Network Access Control (NAC) solution

X AEGIS is responsible for installation, configuration, and management of NAC solution.

Transport Layer Security (TLS) Security Configuration

X X X

NCAPS is responsible for installation, configuration, and management for applications/systems that are under purview of the contract.

ICAM is responsible for providing certificates.

CyPrESS is responsible for measuring compliance.

Note: TLS is commonly used for web services, electronic mail, instant messaging, and other protocols to provide integrity and confidentiality of information conveyed by the protocol. This TLS specification includes guidance for Windows operating systems as well as Linux web services such as Apache.

Determination of Authorization Boundaries X X X

NCAPS is responsible for assisting CyPrESS in determining authorization boundaries and documenting security control implementation in RISCS.

AEGIS is responsible for determining authorization boundaries for infrastructure systems.

Agency Common Control Identification

X CyPrESS is responsible for maintaining Agency common controls.

Identify Infrastructure Security Controls for Application Inheritance X X X

NCAPS is responsible for coordinating with CyPrESS to identify infrastructure security controls for inheritance and documenting deviations.

AEGIS is responsible for identifying and documenting all infrastructure security controls. AEGIS is responsible for providing technical expertise to NCAPS.

CyPrESS is responsible for understanding, implementing and validating infrastructure security controls.

Application Security Categorization (Low, Mod, High)

X X X

NCAPS is responsible for coordinating with CyPrESS to determine system security categorization and coordinating with AEGIS to ensure the applications get hosted in the appropriate infrastructure based on security category level.

AEGIS is responsible for correctly categorizing their infrastructure.

Note: Categorization is done in accordance with FIPS PUB 199 and NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories.

Application:

Security Control Selection and Tailoring X X X

NCAPS is responsible for coordinating with CyPrESS for security control selection and tailoring for systems/application under purview of contract.

NCAPS is responsible for coordinating deviations with AEGIS prior to implementing them to ensure that they accept the risk and/or are able to isolate the risk and/or mitigate the associated risk.

Application: NIST 800-53 Rev 5 Security Control Implementation

X X X

NCAPS is responsible for implementing security controls for systems/application under purview of contract.

NCAPS is responsible for assisting CyPrESS with documenting security control implementation in RISCS.

AEGIS is responsible for implementing security controls for infrastructure.

Note: Coordination between NCAPS and CyPrESS is needed to determine control inheritance.

For Application SSPs currently complaint with NIST 800-53 rev 4, transition from NIST 800-53 Rev 5 to Security Control implementation and documentation into infrastructure SSPs

X X X

NCAPS is responsible for implementing security controls for systems/application under purview of contract.

NCAPS is responsible for assisting CyPrESS with documenting security control implementation in RISCS.

AEGIS is responsible for implementing security controls for infrastructure.

Note: Coordination between NCAPS, CyPrESS, and AEGIS is needed to migrate application-based security controls into infrastructure level SSPs.

For SSPs currently complain with NIST 800-53 rev 4, transition from NIST 800-53 Rev 4 to NIST 800-53 Rev 5 Security Control implementation & documentation - Infrastructure

X X X

NCAPS is responsible for providing technical expertise to CyPrESS and working with CyPrESS in updating security control documentation in RISCS.

AEGIS is responsible for working with CyPrESS and NCAPS to determine if any revision changes could impact hosted applications prior to implementation and allow adequate time for testing and validation.

Infrastructure Security Plan development and maintenance in Risk Information Security Compliance System

(RISCS)

X X X

AEGIS and CyPrESS will coordinate SSP development and maintenance for infrastructure systems.

Note: In instances where application security controls are maintained in infrastructure SSPs, coordination is required between NCAPS, CyPrESS and AEGIS to ensure application PIAs, PTAs, SIAs, POA&Ms, and RBDs are attached to the infrastructure security plans in RISCS, any controls deviations must also be documented in RISCS.

Application Security Plan Development in Risk Information Security Compliance System

(RISCS)

X X X

NCAPS is responsible for providing technical expertise to CyPrESS and working with CyPrESS in documenting security controls and developing security plans.

Note: In instances where application security controls are maintained in infrastructure SSPs, coordination is required between NCAPS, CyPrESS and AEGIS to ensure application PIAs, PTAs, SIAs, POA&Ms, and RBDs are attached to the infrastructure security plans in RISCS, any controls deviations must also be documented in RISCS.

Application Security Plan Maintenance in Risk Information Security Compliance System

(RISCS)

X X X

NCAPS is responsible for providing technical expertise to CyPrESS and working CyPrESS in maintaining security control documentation and the maintenance of security plans.

Note: In instances where application security controls are maintained in infrastructure SSPs coordination is required between NCAPS, CyPrESS and AEGIS. Application PIAs, PTAs, SIAs, POA&Ms, and RBDs shall be attached to the infrastructure SSP in RISCS, any controls deviations must also be documented in RISCS.

For current application-based SSPs, the migration/inclusion of application-based security plans into infrastructure-level security plans

X X X

NCAPS is responsible for providing technical expertise to CyPrESS and working with CyPrESS and AEGIS to ensure the migration/inclusion of application-based security plans into infrastructure-level security plans.

Application PIAs, PTAs, SIAs, POA&Ms, and RBDs migration/inclusion into infrastructure-level security plans in RISCS

X X X

NCAPS is responsible for providing technical expertise to CyPrESS and working with CyPrESS and AEGIS to ensure the migration/inclusion of application-based security plans into infrastructure-level security plans, this includes the migration/inclusion of application-level PIAs, PTAs, SIAs, POA&Ms, and RBDs into infrastructure security plans in RISCS.

Completion of RISCS Data Import Form: Adversarial Threat Sources Events Import File 8 February 2022

(NEW) X X X

NCAPS, AEGIS, and CyPrESS coordination may be required in instances where applications security controls/security plans are incorporated in infrastructure level security plans.

AEGIS is responsible for coordinating the review with stakeholders (e.g., SOC, NOSC, CSPP, system and application owners) to determine relevancy before uploading as this, when uploaded into RISCS, will automatically populate a value that uniquely identifies the record across all applications within the system. The submittal form can be downloaded from the link below:

https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx/

Completion of RISCS Data Import Form: Create New POA&Ms for an SSP Submittal Form 6 October 2021

X X X

NCAPS, AEGIS, and CyPrESS coordination may be required in instances where applications security controls/security plans are incorporated in infrastructure level security plans. The submittal form can be downloaded from the link below:

https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx

Completion of RISCS Data Import Form: Create New RBDs for an SSP Submittal Form 6 October 2021

X X X

NCAPS, AEGIS, and CyPrESS coordination may be required in instances where applications security controls/security plans are incorporated in infrastructure level security plans. The submittal form can be downloaded from the link below:

https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx

Completion of RISCS Data Import Form: HTTPS Internal POA&M Device Upload File

X X

NCAPS, AEGIS, and CyPrESS coordination may be required in instances where applications security controls/security plans are incorporated in infrastructure level security plans. The submittal form can be downloaded from the link below:

https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx

Completion of RISCS Data Import Form: HTTPS Internal RBD Device Upload File

X X

NCAPS, AEGIS, and CyPrESS coordination may be required in instances where applications security controls/security plans are incorporated in infrastructure level security plans. The submittal form can be downloaded from the link below:

https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx

Completion of RISCS Data Import Form:

Implementation and Assessment Import File Updated 2 Sept

X X X

NCAPS, AEGIS, and CyPrESS coordination may be required in instances where applications security controls/security plans are incorporated in infrastructure level security plans. The submittal form can be downloaded from the link below:

https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx

Completion of RISCS Data Import Form: NASA Manual Inventory (NMI) Template

X X X

NCAPS, AEGIS, and CyPrESS coordination may be required in instances where applications security controls/security plans are incorporated in infrastructure level security plans. The submittal form can be downloaded from the link below:

https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx

Completion of RISCS Data Import Form: Non- Adversarial Threat Sources Events Import File 8 February 2022

(NEW)

X X X

NCAPS, AEGIS, and CyPrESS coordination may be required in instances where applications security controls/security plans are incorporated in infrastructure level security plans. The submittal form can be downloaded from the link below:

https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx

Completion of RISCS Data Import Form: POA&M or RBD Hardware Upload File

X X X

NCAPS, AEGIS, and CyPrESS coordination may be required in instances where applications security controls/security plans are incorporated in infrastructure level security plans. The submittal form can be downloaded from the link below:

https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx

Privacy Threshold Assessments (PTA)

X X X

NACPS is responsible for application related PTAs and PIAs.

Note: NCAPS, AEGIS, and will work with CyPrESS to complete PTAs prior to the release of an application, website, or information system under purview of the contract.

Note: PTAs and PIA's must be uploaded in RISCS. Coordination with AEGIS is required if the application is part of an infrastructure security plan.

Privacy Impact Assessments (PIA)

X X X

NACPS is responsible for application related PTAs and PIAs.

Note: NCAPS, AEGIS, and CyPrESS coordination required. In instances where PIA in indicated during the PTA, NCAPS will work with CyPrESS to complete PIAs to determine if a system contains a Privacy Act System of Records (SOR).

Note: PTAs and PIA's must be created in RISCS. Coordination with AEGIS is required if the application is part of an infrastructure security plan.

Systems of Records Notice (SORN)

X X X

NCAPS is responsible for working with CyPrESS to determine if a system will need a Privacy Act System of Records (SOR) and identify existing NASA or Government wide SORN that covers the information collected. If no SORN exists, NCAPS is responsible for working with CyPrESS to revise or write a new SORN and publish it in the Federal Register.

Note: NCAPS, AEGIS, and CyPrESS coordination required.

System Security Risk Assessments

X X X

CyPrESS is responsible for the completing system security risk assessments and developing the Security Assessment Report (SAR) and uploading in RISCS.

Note: NCAPS, AEGIS, and CyPrESS coordination required.

Security Information and Event Management (SIEM) Tool Installation

X X

CyPrESS is responsible for ensuring compliance with Agency approved tools.

AEGIS is responsible for installation and functionality of tool.

Security Information and Event Management (SIEM) Tool Configuration & Identification of events to support and after the fact investigation

X X X

NCAPS, AEGIS, and CyPrESS coordination required.

CyPrESS is responsible for providing compliant tool and AEGIS is responsible for installing, configuring, and maintaining the tool.

NCAPS is responsible for coordination with AEGIS to ensure the tool is configured to identify application-level events.

Note: All parties are responsible for identifying and reporting suspicious activity.

Note: Splunk is provided as an enterprise solution. Some centers are still migrating to the enterprise solution.

At MSFC AlienVault is configured for application event management and SolarWinds Security and Monitoring is configured for event management for the operating systems is interim solution. Other centers may also be in the process of migrating and have unique implementations.

KSC has a unique tool and does not use Splunk at this time.

Source for Providing Audit Logs to the SOC (raw logs)

X X

NCAPS is responsible for providing any logs that occur at the application level.

AEGIS is responsible for proving OS and infrastructure level logs.

Sec Configuration Management Plan

X X X

NCAPS is responsible for creation and maintenance of plans for systems/applications under contract purview.

AEGIS is responsible for infrastructure plans.

CyPrESS is responsible for providing guidance and ensuring compliance with Agency configuration management policies and procedures.

Sec Configuration Control Tools

X X X

CyPrESS is responsible for ensuring compliance with Agency approved tools.

AEGIS is responsible for implementing tools that monitor file system and registry changes.

NCAP is responsible for identifying unique configurations needed to support systems/applications under purview of the contract and coordinating the configuration of tools with AEGIS.

Sec Configuration Control Board X X X NCAP, AEGIS, and CyPrESS are responsible for participating in security focused configuration control boards.

Configuration Control Approvals X X X NCAP, AEGIS, and CyPrESS are responsible for following

Agency defined configuration control processes.

Baseline Configuration Documentation

X X X

NCAPS is responsible for documenting all deviations form baseline configurations and retaining records of configuration-controlled changes for applications/systems they are responsible for.

CyPrESS responsible for ensuring the baseline are compliant.

NCAPS is responsible for coordinating with AEGIS for any impact to changes in infrastructure.

Security Impact Assessments (SIA) for Application changes

X X X

NCAPS is responsible for coordinating with CyPrESS and informing AEGIS of any impacts.

Security Impact Assessments (SIA) for Infrastructure changes

X X X

AEGIS is responsible for coordinating with CyPrESS and informing NCAPS of any impacts.

Approved Standard Configuration Implementation

X X

NCAPS is responsible for implementing approved standard configuration on systems/applications under contract purview.

CyPrESS is responsible for ensuring security baseline configurations conform to Cybersecurity Standards and Engineering Team (CSET) Agency Security Configuration Standards (ASCS) at https://cset.nasa.gov/ascs/ and enforces compliance with those Standards.

Approved Standard Configuration Validation X X X

CyPrESS is responsible for validating the implementation of approved standard configurations and reporting results to NCAPS and AEGIS.

Note: The Agency standard metrics requires 90% compliance.

CSPD-Provides the standards on CSET

Contingency Plan X X X

NCAPS, AEGIS, and CyPrESS are responsible for coordinating contingency planning activities to include recovery objectives and restoration priorities.

Contingency Exercises X X X NCAPS, AEGIS, and CyPrESS are responsible for participating in contingency exercises as requested by the Government.

Continuity of Operation Plans

(COOP)

X X X NCAPS, AEGIS, and CyPrESS are responsible for participating in COOP planning as requested by the Government.

Crisis Management Plan (CMP) X X X NCAPS, AEGIS, and CyPrESS are responsible for participating in CMP planning activities as requested by the Government.

Disaster Recovery Plan X X X NCAPS, AEGIS, and CyPrESS are responsible for participating in disaster recovery planning as requested by the Government.

Incident Response Plan - Application X X X NCAPS, AEGIS, and CyPrESS are responsible for participating in incident response planning as requested by the Government.

Incident Response Plan - Infrastructure X X X NCAPS, AEGIS, and CyPrESS are responsible for participating in incident response planning as requested by the Government.

OS Level Permissions

X X X

AEGIS is responsible for implementing OS level permissions via tools such as Active Directory and Centrify.

AEGIS is responsible for identifying and requesting OS level permissions.

ICAM is responsible for configuring and maintaining Active Directory and Centrify.

NCAPS is responsible for identifying and requesting OS level permissions for unique instances to support system/applications under purview of the contract.

NAMS Workflow Creation for OS Level Permissions/Access

X X

AEGIS is responsible for NAMS workflow creation and maintenance for OS level permissions/access.

ICAM is responsible for maintaining the NAMS system and procedural documentation.

NAMS Workflow Creation for Application-Level Permissions/Access

X X

NCAPS is responsible for NAMS workflow creation and maintenance for application-level permissions/access.

ICAM is responsible for maintaining the NAMS system and procedural documentation.

NAMS Workflow Creation for Database Level Permissions/Access

X X

NCAPS is responsible for NAMS workflow creation and maintenance for database level permissions/access.

ICAM is responsible for maintaining the NAMS system and procedural documentation.

Recurring reviews of all accounts and access privileges -

OS

X AEGIS is responsible for recurring reviews of all accounts and access privileges at the OS level.

Recurring reviews of all accounts and access privileges - Application

X NCAPS is responsible for recurring reviews of all accounts and access privileges at the application level.

Recurring reviews of all accounts and access privileges - Database

X NCAPS is responsible for recurring reviews of all accounts and access privileges at the database level.

NASA Domain Name System (DNS) Registration

- OS

X AEGIS is responsible for DNS registration at the OS level.

NASA Domain Name System (DNS) Registration

- Web App

X NCAPS is responsible for DNS registration at the application level.

Removal of retired systems from Active Directory, DNS, Dynamic Host Configuration Protocol (DHCP), Internet Protocol Address Management (IPAM) (DDI) and pertinent Cybersecurity asset databases.

X X

NCAPS is responsible for ensuring proper retirement of applications.

AEGIS is responsible for proper retirement of OS and related infrastructure systems.

Code vulnerability scan, analysis, and remediation support (e.g., Burp Suite, Atomic Scan) X X X

NCAPS is responsible for executing scans, producing, and analyzing reports, remediating findings, and installing, configuring, and managing the tool.

AEGIS is responsible for hosting the tool(s).

CyPrESS is responsible for providing guidance and ensuring adherence with Agency policies and procedures.

Web vulnerability scan, analysis, and remediation support (e.g., Nessus, WebInspect)

X X X

NCAPS is responsible for executing scans, producing, and analyzing reports, and remediating findings.

AEGIS is responsible for hosting the tool(s).

CyPrESS is responsible for providing guidance and ensuring adherence with Agency policies and procedures.

Database vulnerability scan, analysis, and remediation support X X X

NCAP is responsible for executing scans, producing, and analyzing reports, and remediating findings.

AEGIS is responsible for hosting vulnerability management tool(s).

CyPrESS is responsible for providing guidance and ensuring adherence with Agency policies and procedures.

Operating system vulnerability scan, analysis, and remediation support (Currently Nessus)

X X

AEGIS is responsible for executing scans, producing, and analyzing reports, and remediating findings - Also Hosts the tool(s).

CyPrESS is responsible for providing the approved standard configurations; ensuring compliance; tracking agency-wide compliance metrics via Agency tools such as BigFix and ITSEC-

EDW.

Security Configuration Standards Implementation -

OS

X X

AEGIS is responsible for implementation and validation of OS security configuration standards.

CyPrESS is responsible for providing the approved standard configurations; ensuring compliance; tracking agency-wide compliance metrics via BigFix and ITSEC-EDW.

Security Configuration Standards Implementation -

DB

X X

NCAPS is responsible for implementation and validation of security configuration standards at the database level.

CyPrESS is responsible for providing the approved standard configurations; ensuring compliance; tracking agency-wide compliance metrics via BigFix and ITSEC-EDW.

Security Configuration Standards Implementation -

APP

X X

NCAPS is responsible for implementation and validation of security configuration standards at the application level.

CyPrESS is responsible for providing the approved standard configurations; ensuring compliance; tracking agency-wide compliance metrics via BigFix and ITSEC-EDW.

Launchpad Integration - OS

X AEGIS is responsible for Launchpad integration at the OS level.

Launchpad Integration - APP X NCAPS is responsible for Launchpad integration at the application level.

Launchpad Integration - DB X NCAPS is responsible for Launchpad integration at the database level.

Launchpad Integration - Web X NCAPS is responsible for Launchpad integration at the website level NASA Consolidated Active Directory (NCAD) System Registration (OS)

X X

ICAM is responsible for managing NASA Consolidated Active Directory (NCAD).

AEGIS is responsible for requesting and coordinating OS level system registration with ICAM.

Procurement of Cloud Technologies

X X X

NCAPS, AEGIS, and CyPrESS are responsible for evaluating and making recommendations on the adoption of various cloud technologies such as cloud environments (e.g., AWS GovCloud, Azure Government Cloud, Salesforce Government Cloud, SAP NS2 Cloud, Slack); cloud services (e.g., Amazon Web Services, iSite, Snowflake); and cloud service models (e.g., IaaS, PaaS, SaaS).

CyPrESS is responsible for providing guidance and ensuring adherence with Agency policies and procedures.

Note: The Government may purchase cloud services directly from the vendor/FedRamp Market Place or via the either contract vehicle..

Data at Rest (DAR) Windows OS - BitLocker

X X X

ICAM is responsible for maintaining policy settings in Active Directory (AD). Some configuration settings are pushed from NCAD via AD policy settings.

AEGIS is responsible for installation, configuration, and management of DAR tools.

CyPrESS is responsible for providing guidance and ensuring adherence with Agency policies and procedures.

Note: Federally mandated critical controls are required by federal policy (e.g., E. O. 14028, Improving the Nation’s Cybersecurity, and M-22-09, Moving the U.S. Government Toward Zero Trust Cybersecurity Principles) and SHALL NOT be tailored out of a NASA System Security Plan (SSP) for any reason. As such, all DAR, PIV-M, and MFA configuration settings are defined in ASCS security configuration specifications and are required on every NASA endpoint.

https://cset.nasa.gov/ascs/supporting-information/dar-mfa-and-piv-m-check-configurations-by-operating-system/

Data at Rest (DAR) Linux - Linux Unified Key Setup

(LUKS)

X X

AEGIS is responsible for installation, configuration, and management of LUKS.

CyPrESS is responsible for providing guidance and ensuring adherence with Agency policies and procedures.

Note: Federally mandated critical controls are required by federal policy (e.g., E. O. 14028, Improving the Nation’s Cybersecurity, and M-22-09, Moving the U.S. Government Toward Zero Trust Cybersecurity Principles) and SHALL NOT be tailored out of a NASA System Security Plan (SSP) for any reason. As such, all DAR, PIV-M, and MFA configuration settings are defined in ASCS security configuration specifications and are required on every NASA endpoint.

https://cset.nasa.gov/ascs/supporting-information/dar-mfa-and-piv-m-check-configurations-by-operating-system/

Personal Identity Verification Mandatory (PIV- M)/multi-factor authentication (MFA) Linux

X X

AEGIS is responsible for installation, configuration, and management.

CyPrESS is responsible for providing guidance and ensuring adherence with Agency policies and procedures.

Note: Federally mandated critical controls are required by federal policy (e.g., E. O. 14028, Improving the Nation’s Cybersecurity, and M-22-09, Moving the U.S. Government Toward Zero Trust Cybersecurity Principles) and SHALL NOT be tailored out of a NASA System Security Plan (SSP) for any reason. As such, all DAR, PIV-M, and MFA configuration settings are defined in ASCS security configuration specifications and are required on every NASA endpoint.

For both PIV and MFA on Linux OSs, local authentication uses Pluggable Authentication Modules (PAM), while network authentication uses OpenSSH. If a system is PIV compliant, it is MFA compliant.

In order to comply with Agency-wide PIV-M requirements, Linux administrators must employ an authentication option that has been reviewed and approved by the Agency PIV working groups.

(https://cset.nasa.gov/ascs/supporting-information/dar-mfa-and-piv-m-check-configurations-by-operating-system/)

Personal Identity Verification Mandatory (PIV- M)/multi-factor authentication (MFA) Windows

X X

AEGIS is responsible for installation, configuration, and management.

CyPrESS is responsible for providing guidance and ensuring adherence with Agency policies and procedures.

Note: Federally mandated critical controls are required by federal policy (e.g., E. O. 14028, Improving the Nation’s Cybersecurity, and M-22-09, Moving the U.S. Government Toward Zero Trust Cybersecurity Principles) and SHALL NOT be tailored out of a NASA System Security Plan (SSP) for any reason. As such, all DAR, PIV-M, and MFA configuration settings are defined in ASCS security configuration specifications and are required on every NASA endpoint.

Windows systems comply with PIV-M requirements by setting the configuration called “Interactive logon: Require Windows Hello for Business or smart card” to “enabled”. This setting is applied on Agency Windows systems via the ASCS Windows security specification group policy.

Note: When a Windows system joins the NDC Active Directory domain, PIV-M compliance occurs automatically via top-level domain Group Policy “AG-GPO- ASPEC_B1_SmartcardOnlyLogon” (https://cset.nasa.gov/ascs/supporting-information/dar-mfa-and-piv-m-check-configurations-by-operating-system/)

Automated Performance Monitoring Tools -

OS

X X

AEGIS is responsible for installation, configuration, and management.

CyPrESS is responsible for providing guidance and ensuring adherence with Agency policies and procedures.

Automated Performance Monitoring Tools - APP (e.g., Nagios, Whatsapp Gold)

X X

AEGIS is responsible for installation, configuration, and management of infrastructure/OS level performance monitoring tools.

Note: Coordination between AEGIS and NCAP is required to configure infrastructure/OS level performance monitoring tools that are capable of monitoring application-level performance.

NCAPS may install application performance monitoring tool on the OS or may have to coordinate with AEGIS in instances where they own OS level monitoring tools that can be configured to monitor application performance.

*These items will be provided by the ICAM group. It is anticipated that ICAM will provide this work utilizing the NCAPS contract. AEGIS and CyPrESS may be used to provide some capabilities.

File details come from the government source that posted it. Updated .