Attachment 03 Data Requirements Deliverables.pdf

PDF 1 MB Posted

Attached to
NASA STEM (NSTEM) Services Federal contract opportunity
Solicitation number
80NSSC22R0001FRFP
Issued by
National Aeronautics and Space Administration Shared Services Center

About this file

This document outlines requirements for NASA STEM services. The solicitation seeks proposals to provide a range of STEM engagement programs, projects, activities and products across NASA to attract, engage and educate students and support educators. Requirements include managing internships, fellowships and other stipended student experiences; collecting associated placement and financial metrics on a weekly, quarterly and annual basis; and developing a diversity, equity and inclusion plan. The selected contractor must also prepare a contract management plan, safety and health plan, and phase-in plan within specified timeframes following award. The contractor will be responsible for executing NASA's STEM strategy to inspire and support participation in STEM fields through a comprehensive education portfolio.

View the file

Other files for this federal contract opportunity

Other files attached to NASA STEM (NSTEM) Services, newest first.
File Type Posted
Section III Instructions to Offerors Amendment 00004.pdf PDF
80NSSC22R0001 SF30 Amendment Combined 00004.pdf PDF
NSTEM FRFP Combined QA.pdf PDF
Section IV Evaluation Criteria Amendment 00003.pdf PDF
Section I Model Contract Amendment 00003.pdf PDF
80NSSC22R0001 SF30 Amendment Combined 00003.pdf PDF
Section III Instructions to Offerors Amendment 00003.pdf PDF
Attachment 01 PWS_Amendment 00003.pdf PDF
Section IV Evaluation Criteria Amendment 00002.pdf PDF
80NSSC22R0001 SF30 Amendment 00002 Signed.pdf PDF
Section III Instructions to Offerors Amendment 00002.pdf PDF
Attachment 02-NSTEM Price Schedule _Amendment 00002.xlsx XLSX spreadsheet
NSTEM Combined OA.pdf PDF
80NSSC22R0001 FRFP.pdf PDF
80NSSC22R0001 SF30 Amendment 00001 Signed.pdf PDF
Attachment 04 - Labor Categories Position Descriptions Amendment 00001.pdf PDF
80NSSC22R0001 FRFP.pdf PDF
80NSSC22R0001 Combined Reference Material Amendment 0001.pdf PDF
80NSSC22R0001 NSTEM FRFP QA.pdf PDF
Section IV Evaluation Criteria Amendment 00001.pdf PDF
Attachment 02-NSTEM Price Schedule Rev4 Amendment 00001.xlsx XLSX spreadsheet
80NSSC22R0001 SF30 Amendment 00001 Signed.pdf PDF
Section I Model Contract Amendment 00001.pdf PDF
Attachment 01 PWS_Amendment 00001.pdf PDF
Section II - Reps and Certs.pdf PDF
Section III Instructions to Offerors.pdf PDF
Section IV Evaluation Criteria.pdf PDF
Attachment 12 -Quality Control Plan.pdf PDF
Attachment 16 - Historical Data.pdf PDF
NSTEM D and F for Consolidation of Requirements 11_17_2021.pdf PDF
NPR 4200.1, NASA Equipment Management.pdf PDF
Section I Model Contract.pdf PDF
Attachment 01 PWS.pdf PDF
Attachment 06 - Wage Determinations.pdf PDF
Final RFP Cover Letter_ Signed.pdf PDF
NPD 8800.14 Policy for Real Estate Management.pdf PDF
NPR 4300.1, NASA Personal Property Disposal Procedural Requirements.pdf PDF
NPR 8831.2 Facilities Maintenance and Operations Management.pdf PDF
Attachment 09 - Phase In Plan.pdf PDF
Attachment 14 - Past Performance Questionnaire.docx DOCX document
80NSSC22R0001 DRFP and Industry Day QA.pdf PDF
NPR 4100.1, Supply Support and Material Management Updated with Change 1.pdf PDF
Attachment 02-NSTEM Price Schedule Rev3.xlsx XLSX spreadsheet
Attachment 04 - Labor Categories Position Descriptions.pdf PDF
Attachment 05 - List of GFP.pdf PDF
Attachment 07 - Acronyms_Definitions.pdf PDF
Attachment 10 - Safety and Health Plan.pdf PDF
Attachment 11 - IT Security Plan.pdf PDF
Attachment 13 - Requirements Traceability Matrix Template.xlsx XLSX spreadsheet
Attachment 15 - References.pdf PDF
Show all 50

NASA STEM (NSTEM) Services has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

80NSSC22R0001 NSTEM Services Attachment 03

NASA Shared Services Center (NSSC) Stennis Space Center, MS 39529

NASA SCIENCE, TECHNOLOGY, ENGINEERING AND

MATHEMATHICS (NSTEM) SERVICES

SOLICITATION No. 80NSSC22R0001

DATA REQUIREMENTS DELIVERABLES (DRDS)

80NSSC22R0001 Attachment 03 Data Requirements

DATA REQUIREMENTS LIST

DRL NUMBER:

NSTEM Services

REVISION

Solicitation

PROJECT/SYSTEM

NSTEM Services Contract

CONTRACT NUMBER

TBD

PREPARATION DATE

October 2021

CONTRACTOR

TBD

TECHNICAL APPROVAL

TBD

ATTACHMENT NUMBER

Attachment 03

EXHIBIT NUMBER

N/A

ITEM NO. TITLE CHANGE STATUS

MA-01 Contract Management Plan MA-02 Financial Management Reporting MA-03 Contract Management Review (CMR) MA-04 Continuity of Operations Plan (COOP) MA-05 Information Technology (IT) Security Plan and Reports MA-06 Phase-In Plan MA-07 Organizational Conflict of Interest Plan MA-08 Workforce Experience Reporting MA-09 Diversity, Equity, and Inclusion (DE&I) Plan SA-01 Safety and Health Plan

Solicitation

80NSSC22R0001 Page 1 of 35

1. DRD Title: Contract Management Plan

2. DRD No.: MA-01 3. Data Type: 1

4. Solicitation No.: 80NSSC22R0001 5. Contract No.: TBD

6. Date Issued: TBD 7. Date Revised: TBD 8. DRD Category:

Technical ☐

Administrative ☒

S&MA ☐

9. Description/Use: The Contractor must provide plans to coordinate and execute all technical and administrative tasks for all management activities required to satisfy the requirements of this contract.

10. Distribution: CO, COR

Initial Submission: 15 calendar days after Phase-In start date

Submission Frequency: One time; revise annually or more frequently to reflect significant changes

Format: Contractor format is acceptable within guidance from Section 14.3.

Interrelationship: Performance Work Statement, Sections VII.A, VII.D, VII.G

Applicable Documents: Identify applicable directives, plans, guides, etc.

Scope: The Contract Management Plan describes the approach for managing all technical and administrative tasks required to satisfy requirements of the contract.

Contents: The Contract Management Plan contains the plans for oversight, coordination, and execution of all contract technical and administrative tasks. The initial Contract Management Plan will be considered a baseline document and shall be updated annually or more frequently if needed to reflect significant changes. Significant changes may include new business practices or methodologies as well as scope/descope the plan. All updates to the Contract Management Plan will be approved by the Contracting Officer (CO) and the Contracting Officer’s Representative (COR). The Contract Management Plan is an umbrella document that encompasses and integrates all contract management activities. The Contract Management Plan shall include:

1. Contract Management The Contractor’s management plan to:

a. Manage the activities of the contract to include management and integration of the Contractor “team”

i. Should include an employee listing section with

1. Employee Breakout by Center

80NSSC22R0001 Page 2 of 35

2. The number of on-site and off-site employees (headcount) by company to include all subcontractors.

3. Information for each employee: employee’s name, position, security level, location (building/room number), supervisor’s name and supervisor’s location

4. Delta report identifying all changes since the previous report

b. Manage and communicate the roles, responsibilities, interactions, and expectations, to include the provision of a seamless interface between contractors and civil service employees

c. Provide products and services to the Government

i. CLARIFICATION (Enterprise Environment): The Contractor will be providing products and services to multiple Centers (and possibly Mission Directorates) in the execution of this contract. The Contractor shall outline the plan for evaluating multiple organizational governance structures and using that analysis to recommend innovative and efficient plans to the provision of products and services.

d. Identify, elevate, resolve, and report issues and problems on the contract.

e. Provide Root-cause analysis and Corrective actions – whether requested/required by the

Government or internally-directed.

f. Ensure and maintain accuracy in schedule and cost estimates made to the Government

g. Implement a Records Management Program (in accordance with NPR 1441.1) – to include: the identification of Contractor-generated and Contractor-owned records of interest to the Government (i.e., purchase records) and the plan to manage, retain, disposition and destroy those records throughout the life of the contract

h. Incorporate Integrated Service Management principles into the delivery of integrated products and services.

i. Innovate and retain agility in meeting the evolving requirements of the customer

i. Define the Contractor’s plan and implementation strategy for business agility, to include how stakeholder requirements will be managed and verified.

j. Seamlessly interface and integrate between OSTEM and other Agency contractors necessary to execute the requirements of this contract (without Government intervention)

k. Address Resource management – to include how a qualified workforce will be attracted and retained as well as the plan for on-demand staffing and how impacts to the Government are assessed.

l. Address Diversity, benchmarking, technology infusion, and risk management (technical, schedule, cost, safety, and IT security risks) and measures to demonstrate success in these areas

i. Governance process(es), to include any key, internal contractor boards integral in the implementation of the Contractor’s management plan

ii. The significant policies, plans, and processes of all aspects of the contract as well as a process for ensuring the currency of those elements.

m. Define the Contractor’s Organizational (prime and subcontractors) structure:

i. Include organization charts, with emphasis on roles and responsibilities of organizational elements

ii. Define operating parameters for the Contractors and expectations the Contractor has of the

Government’s role to achieve mission success

80NSSC22R0001 Page 3 of 35

iii. Identify points-of-contact (position/location/phone) for incidents which involve the security of information technology for the contract

iv. Identify Key operational areas

v. Identify flow of authority and approval levels

vi. Describe functional relationships between internal organizational elements that differ from the flow of line authority

2. Communications The Communications portion shall outline the plan the Contractor intends to use to communicate with Government technical personnel.

Technical, Cost, Schedule, and Risk (TCSR) Reviews:

The Contractor shall outline how they will ensure that team members clearly understand the contract plan(s) for evaluation of performance. The reviews should include the following:

a. Technical, Cost, Schedule, and Risk (TCSR) reviews and monthly reviews

b. Concerns/deficiencies identification. Specifically, outline the Contractor responsibilities to facilitate corrections for concerns or deficiencies and minimize impact to mission success.

c. Identification (by role) of board members/representatives involved in the evaluation process

d. Opportunities for the Contractor to present/emphasize aspects of their performance to the

Government

e. Criteria identified by the Government with respect to the evaluation process.

3. Data Management Plan The Contractor must describe the plan to be implemented to analyze, manage, and administer Government-owned and Contractor-managed data across the contract. The plan must include a detailed discussion on how data is identified, tagged (for keyword searching), and modeled across repositories, collections, and websites contract-wide.

4. Continuous Service Improvement (CSI) and Continuous Process Improvement (CPI) The Contractor shall prescribe the process to be implemented to ensure that CSI/CPI is incorporated into the contract. CSI provides instructions for customer added value in the form of improvements. It combines principles, practices, and methods of quality management, change management and process improvements to optimize the service strategy, design, and transitional phases. The CPI strives to make small step efficiencies in standard processes. The CPI may be to standardize/streamline existing processing, remove things which have value, and/or improve customer satisfaction.

a. At the first major revision of the Contract Management Plan (end of contract year 1), the Contractor shall provide its plan for identifying portions of this contract that could progress from 100% IDIQ to a fixed price or base services (or a combination thereof) methodology. This plan shall be revisited and revised as appropriate on an annual basis.

b. The Contractor shall provide its plan for developing new technologies, innovations, and process improvements that when implemented, shall result in improved quality of products and services while maintaining or reducing costs to the government. The plan shall include the Contractor’s process for continuous assessment and prioritization.

80NSSC22R0001 Page 4 of 35

i. Define how continuous improvement will be recorded and documented.

ii. Identify the specific part of the organization responsible for administering continuous improvement.

iii. Identify the specific contract elements which are categorized subject areas of emphasis

(e.g., Business processes)

iv. Describe the procedures to ensure organization is actively working CSI/CPI.

v. Define how NASA will be involved in final decisions in the change process.

vi. CSI/CPI may be considered fully implemented after Contract update.

5. Innovation Management The Contractor shall outline its plan to foster a work environment conducive to developing innovative plans through the creation, adoption, and implementation of new ideas. The Offeror shall identify the process(es), procedure(s), and guideline(s) to be used to ensure innovations and technology infusion is encouraged, managed, and addressed.

a. Define how innovations will be recorded and documented.

b. Identify the specific contract elements involved and how they are impacted.

c. Define how innovations will be vetted internally and the criteria by which innovations to be brought forward to the Government will be internally evaluated.

d. Define how NASA will be involved with final decisions in the change process.

e. An innovation cannot be considered fully accepted until it has been approved and accepted by the appropriate Government Control Board or the Contract has been updated.

6. Quality Control Plan (QCP) The QCP shall set forth the staffing and procedures for self-inspecting the quality, timeliness, responsiveness, customer satisfaction, and other performance requirements in the PWS. The contractor will develop and implement a performance management system with processes to assess and report its performance to the designated government representative.

7. Risk Management This section shall describe the contractor’s plan for assessing, evaluating, documenting, and managing all risks associated with the performance of contract requirements in compliance with NPR 8000.4, Agency Risk Management Procedural Requirements, and NPR 2810.1, Security of Information Technology.

Remarks: N/A

Maintenance: Changes shall be incorporated by complete reissue. Update as required.

80NSSC22R0001 Page 5 of 35

1. DRD Title: Financial Management Reporting

2. DRD No.: MA-02 3. Data Type: 3

4. Solicitation No.: 80NSSC22R0001 5. Contract No.: TBD

6. Date Issued: TBD 7. Date Revised: TBD 8. DRD Category:

Technical ☐

Administrative ☒

S&MA ☐

9. Description/Use: The contractor must report financial information on a monthly basis using approved NASA formats.

10. Distribution: CO, COR, ERM, RMO

Initial Submission: 45 Calendar Days after Contract start date

Submission Frequency: Monthly on the 10th business day of the month

Format: The reporting requirements formats are outlined in this DRD.

Interrelationship: Performance Work Statement, Section VII.C, VII.I

Applicable Documents:

Scope: Cost is a financial measurement of resources used in accomplishing a specified purpose, such as performing a service, carrying out an activity, acquiring an asset, or completing a unit of work or project. Cost Reports are used to provide a more detailed set of financial information. The additional details are communicated through the reporting structure below. Reporting at this detailed level is necessary to support reporting of costs to customers for incorporating into larger work packages.

Contents:

In support of this DRD, the Contractor shall provide the following:

1. Cost Reports: The reports shall reflect Actuals, Current Month Estimates, Next Month Estimates, and Government Fiscal year (GFY)Estimates at Complete.

a. The reports shall consist of the following information:

i. Labor (Prime and Sub hours, FTE Count, Prime and Sub Costs)

ii. Non-labor (material, travel, training, consulting, license/maintenance, and other CDCs)

iii. Fee (Earned Fee)

b. Estimate at Completion (EAC) is the estimate for the remainder of the Government fiscal year

c. Provide at the initiation of the contract and then annually at the beginning of each GFY:

i. The conversion factor from EP’s to direct labor hours

ii. An accounting calendar with beginning and ending dates for each accounting month and effective hours per equivalent person.

80NSSC22R0001 Page 6 of 35

The Contractor is required to coordinate with the NASA Resource Analyst assigned to the contract in order to establish and maintain the reporting categories the Contractor shall use to comply with this data requirement.

2. Purchasing Documentation: for all articles purchased under this contract including purchase request, purchase order, contact information, purchasing organization, Internal Task Agreements (ITA) Memorandums of Understanding (MOU), and other agreement types and invoices.

a. The Contractor shall ensure that all purchases used in support of this contract are consistent with current Federal and NASA specific regulations and OSTEM policies.

b. All purchase records shall be tracked as part of the Contractor’s Record Management system (in accordance with DRD -MA-01, Contract Management Plan) and delivered to the Government upon request and expiration/termination of the contract.

3. Variance Analysis Report: The Contractor shall provide a written variance explanation (estimates versus actuals) when: a) the monthly variance per reporting period is the greater of +/- 10% or $10,000 overrun or underrun in cost; b) the variance at completion for the task order is the greater of +/- 10% or $50,000 overrun or underrun in cost, unless otherwise directed by NASA. This variance explanation shall be provided at the task order level.

4. Workforce Reporting: The Contractor shall support various workforce exercises requested by the Government. For example, the Contractor may be asked to provide the total contract headcount and how this number is split between on-site versus off-site. These exercises typically occur once or twice a year. The exact requirements and schedules will be determined as these exercises occur.

5. Budget Planning Support: The Contractor shall support the Government Internal Task Agreement (ITA) process. This process is two-fold. Prior to the Program Planning and Budget Execution (PPBE) (formerly known as Program Operating Plan) process each spring, the Contractor shall provide estimates at the Task Order and Unique Work Item levels for the next fiscal year. The Contractor shall support the Government in creating an annual cost-operating plan prior to the beginning of each Government fiscal year (October 1 – September 30). As part of the annual budget planning, the Contractor shall provide cost estimates, technical impact statements, and decision packages as required. The exact support requirements and their schedule will be given when the support task is assigned.

Once the cost plan has been finalized and task orders have been completed, the Contractor shall assist the Government in the management of the plan as cost and workload variances occur. The Contractor will also be asked to support the Government throughout the life of the contract as it responds to variations in funding levels and technical priorities.

Maintenance: None Required

80NSSC22R0001 Page 7 of 35

1. DRD Title: Contract Management Review (CMR)

2. DRD No.: MA-03 3. Data Type: 3

4. Solicitation No.: 80NSSC22R0001 5. Contract No.: TBD

6. Date Issued: TBD 7. Date Revised: TBD 8. DRD Category:

Technical ☐

Administrative ☒

S&MA ☐

9. Description/Use: The CMR documents the monthly status of the Contract.

10. Distribution: CO, COR, ERM

Initial Submission: Sixty (60) calendar days after the Contract start date

Submission Frequency: Monthly no later than the 10th calendar day of the month.

Format: The Monthly Progress Report and Metrics shall be in electronic MS PowerPoint format and presented orally by the Contractor’s Program Manager at the monthly Contract Management Review Meeting (CMRM).

Interrelationship: DRD MA-01, DRD MA-02, Performance Work Statement, Section VII.C, VII.K

Applicable Documents: N/A

Scope: The purpose of the Contract Management Review is a monthly opportunity for the Contract to present to the Government an overall contract status, which includes providing the performance metrics identified in Attachment J- Performance Requirements. On a quarterly basis, the CMR will be replaced with a quarterly review.

Contents:

CMR Framework:

a. CMR Action Item and Meeting Minutes Review

b. Contract Highlights

c. Technical, Cost, Schedule, and Risk (TCSR) Statuses

i. Total Contract

1. Technical, Schedule, Management, and Quality Performance Summary

a. Technical/Schedule/Quality Performance Metrics

b. Management Summary

c. Issues and Actions taken to resolve issues

i. The lessons learned documentation, at a minimum shall include

1. Subject

2. Description of lesson learned

3. Description of circumstance(s) surrounding lesson learned

4. Recommendation(s) of use of lesson learned

80NSSC22R0001 Page 8 of 35

5. Supporting documentation - as needed to give clear picture of lesson (photographs, illustrations, drawings, etc.)

ii. The corrective actions reporting, at a minimum shall include:

1. Title of corrective action

2. Requester

3. Affected products, services, or customers and length of time affected

4. Incident description

a. Problem Statement

b. Problem Description

c. Timeline of events prior to incident resolution beginning

d. Impacted resources, system, services, etc.

5. Action Taken towards resolution

a. Troubleshooting conducted

b. Plan of Action

c. Action (s) utilized to resolve the incident, the anticipated outcome, and the resulting outcome (more than one action may have been utilized to resolve the incident)

d. Timeline of events of actions taken between problem resolution beginning and resolution of the incident.

6. Root Cause Analysis (RCA)

a. Description of RCA methodology utilized and the results of that methodology

b. Root Cause Summary

c. Environmental factors attributing to the incident

7. Preventative Action (Best Value Options to the Government)

a. Schedule to implement recommended preventative action

b. Rough Order of Magnitude (ROM) to implement the recommended preventative action

8. Supporting documentation - as needed to give clear picture of the corrective action

9. Contact name and e-mail address

d. Innovation and Continuous Improvement initiatives status

2. Financial Status (DRD MA-02 Financial Management Reporting)

3. Risk Management Status (Risk identification and mitigation plans)

ii. Customers

1. Technical, Schedule, Management, and Quality Performance Summary

a. Technical/Schedule/Quality Performance Metrics

b. Management Summary

c. Issues and Actions taken to resolve issues

d. Innovation and Continuous Improvement initiatives status

2. Financial Status (ref. DRD MA-02 Financial Management Reporting)

80NSSC22R0001 Page 9 of 35

3. Risk Management Status (Risk identification and mitigation plans)

d. Total Contract Safety Summary

e. Stays of Areas of Emphasis

f. Special Topics as determined by the COR (for example: Specific Project TCSR status, staffing, etc.)

Major Functional Area(s) TCSR (PWS Sections 4.0 – 9.0):

1. Technical, Schedule, and Quality Performance Summary

a. Technical/Schedule/Quality Performance Metrics (include appropriate metrics from J-22 (Performance Metrics))

b. Issues and Actions taken to resolve issues

c. Innovation and Continuous Improvement initiatives status

2. Financial Status (ref. DRD MA-02 Financial Management)

3. Risk Management Status (Risk Identification and mitigation plans)

4. Narrative summary in each major functional area discussing areas of excellence, areas of Improvements, areas of focus, and significant events within the following categories:

a. Quality

b. Customer Service

c. Timeliness

The Major Functional Area(s) TCSRs shall be completed at least 5 working days before the CMR.

Quarterly Review Framework:

1. Three-month aggregate and trend analysis of:

a. Performance assessment data

b. Financial status

c. Risk Management status

d. Contract Safety incidents/mitigations

e. TCR status

2. Issues and Concerns

3. Projected outlook for next quarter and progress against expected trends, including a corrective action plan analysis.

4. Recommendations for improved efficiency and/or effectiveness.

5. Issues arising from the performance monitoring processes.

Maintenance: Changes shall be incorporated by complete reissue; Update as required.

80NSSC22R0001 Page 10 of 35

1. DRD Title: Continuity of Operations Plan (COOP)

2. DRD No.: MA-04 3. Data Type: 1

4. Solicitation No.: 80NSSC22R0001 5. Contract No.: TBD

6. Date Issued: TBD 7. Date Revised: TBD 8. DRD Category:

Technical ☐

Administrative ☒

S&MA ☐

9. Description/Use: The Contractor must prepare and maintain a COOP to ensure the continual execution of the mission essential functions supported by the Contract during an emergency situation or event.

10. Distribution: CO, COR

Initial Submission: Ninety (90) calendar days after the Contract start date

Submission Frequency: Re-baselined on or before May 30 each year

Format: Contractor format is acceptable.

Interrelationship: Performance Work Statement, Section VII.L

Applicable Documents: N/A

Scope: The Contractor must prepare and maintain a COOP to ensure the continual execution of the mission essential functions supported by the Contract during an emergency situation or event.

Contents: The COOP shall include plans for continual operations in a facility threatened or incapacitated due to an emergency situation or event, the relocation (if necessary) of selected personnel and services, response and recovery, and mitigation of the potential damage to facilities, equipment and other assets impacts.

The COOP shall identify all support required prior to, during, and after an emergency situation or event. The plan shall address how the Contractor shall coordinate with all affected organizations to assure compatibility and integration with other organizations’ emergency plans. The COOP shall define processes to provide the Government a status of the mission essential functions during and immediately after the emergency situation or event. The Contractor shall include and maintain a contingency contact roster of individuals with decision and implementation authority to carry out elements of the plan including preparations, shutdown, re-start and recovery phases.

Maintenance: Changes shall be incorporated by complete reissue. Update annually to maintain current.

80NSSC22R0001 Page 11 of 35

1. DRD Title: Information Technology (IT) Security Plan and Reports

2. DRD No.: MA-05 3. Data Type: 2

4. Solicitation No.: 80NSSC22R0001 5. Contract No.: TBD

6. Date Issued: TBD 7. Date Revised: TBD 8. DRD Category:

Technical ☐

Administrative ☐

S&MA ☐

9. Description/Use: To ensure that IT security reporting requirements are met for all IT systems utilized during work associated with the Contract

10. Distribution: CO, COR, SISO, AO

Initial Submission: IT Security Program Management Plan - Fifteen (15) calendar days after the Contract start date. IT Security Plan(s) - assume maintenance of existing plans (for Government-owned and Contractor-managed systems) at Phase-In start; IT Security Plan(s) for contractor-owned systems due 15 calendar days after the Contract start date.

Submission Frequency: IT Security Program Management Plan - Annually by September 30. IT Security Plan(s)

- must be kept up-to-date as changes to the baseline configuration of the system(s) occur

Format: The formats described in this Data Requirements Description, including Exhibit 3.

Interrelationship: Performance Work Statement, Section VII.M

Applicable Documents: NASA FAR Supplement 1845.204-76, NPR 2810.0, OMB Circular A-130

Scope: All contracts that purchase, lease, network to, or otherwise utilize Government-funded IT (as defined by the Clinger-Cohen Act of 1996 and referenced by OMB Circular A-130) must comply with NASA IT Security Requirements.

Contents:

IT Security Management Program Plan:

The Contractor shall submit an IT Security Management Program Plan for its unclassified technology information resources. This program plan shall describe the policy, processes, and procedures that will be followed to ensure appropriate security of IT resources that are developed, processed, or used under this contact. The Contractor’s IT Security Management Program Plan shall be compliant with the IT security requirements in accordance with Federal and NASA policies as referenced in OMB Circular A-130 and NPR2810.1(series). Exhibit 4 shall be used as a template for IT Security Management Plan submittals.

IT Security Plan:

The Contractor shall have Information Systems Security Officer (ISSO) who is responsible for the Contractor’s system(s) in accordance with the definitions set forth in NPR 2810.1(series). The IT security plan shall be kept up to date as changes to the baseline configuration of the system occur and shall be

80NSSC22R0001 Page 12 of 35 documented in the IT Security Plan. Note: An IT Security Plan is specific to a system or group of systems, while an IT Security Management Program Plan is defined as the elements a contractor has outlined to meet the IT Security requirements for interfacing with other contractors and NASA, training requirements and meeting the requirements in NPR 2810.1(series).

See the CIO-Procurement Website for any supporting documentation. The Contractor shall also submit IT Security Plans for any Contractor-managed IT systems as well as any Contractor-owned systems that manage or manipulate NASA data.

IT Security Awareness Training:

Employees subject to this contract shall complete the NASA approved IT Security Awareness Training annually. The Contractor shall provide evidence that periodic IT security awareness training has been met for all employees subject on this contract. The Contractor shall submit periodic reports (as required by the CO) detailing the overall status of the annual training program. The annual training program is defined as the period from October 1st through September 30th.

IT Security Role Based Training:

Employees subject to this contract shall complete NASA approved IT Security Training annually related to the following Role Based functions:

• IT Security Manager

• Information System Owner (ISO)

• Information Systems Security Officer (ISSO)

• Organizational Computer Security Official – Representative (OCSO-R)

The Contractor shall provide evidence that periodic IT security training has been met for all employees subject on this contract. Contractor provided IT security awareness training may be substituted but must be approved annually by the Government (via the JSC Center IT Security Officer [CISO]) as an acceptable substitute. The Contractor shall submit periodic reports (as required by the CO) detailing the overall status of the annual training program. The annual training program is defined as the period from October 1st through September 30th.

Information on Employees in Sensitive Positions/Assignments Report:

The Information on Employees is Sensitive. The ITS Positions/Assignments Report shall provide information annually for personnel screening as required by NPR 2810.1(series), and NPR 1600.1 on position risk.

IT Point of Contact:

The Contractor shall identify a point of contact that NASA may reach in its attempt to address IT and IT Security issues. The point of contact shall have the authority to ensure appropriate actions occur.

A list of all lead system administrators shall be updated by September 30 of each year. This list will be used to ensure the Contractor, as outlined in PN 04-03, has met the system administrator certification requirements.

Maintenance: Changes shall be incorporated by complete reissue. Update annually to maintain as current.

80NSSC22R0001 Page 13 of 35

DRD-MA-05 Exhibit 3, Page 1

1.0 Document Overview

1.1 Purpose

To provide an overview of the requirements for the [Directorate Name] Security Management Plan and to describe the security program management controls and common controls in place for meeting those requirements.

1.2 Scope

The object of the scope is to identify all data and IT assets that are covered by this plan.

1.3 Objectives

The overall objective of this plan is to document how the [Directorate Name] will protect information and IT assets related to the directorate and manage the risk to organizational mission/business functions in an efficient and effective manner.

In support of its objectives, the plan will:

• Identify assigned roles and responsibilities, allow coordination among organizational entities, and demonstrate management commitment and compliance

• Describe the policies processes, and procedures that will be followed to ensure appropriate security of IT resources developed, processed, and employed within the directorate.

1.4 Assumptions

Describe any assumptions that need to be stated for this plan.

1.5 Responsible Organizations/Personnel

Describe roles and responsibilities of security personnel and any delegated responsibilities. The organizations and personnel responsible for the security of [System Name] are identified in Table 1.5- 1.

80NSSC22R0001 Page 14 of 35

DRD-MA-05 Exhibit 3, Page 2

Table 1.5-1 System Security Management Personnel Function Name Area of

Responsibility (SSP# or Org)

Email Address / Phone Number

Authorizing Official (AO) Insert name Insert title System Owner (SO) Insert name Insert title

Information System Security Officer (ISSO)

Insert name Insert title

Organization Computer Security Official (OCSO)

Insert name Insert title

1.6 System Interconnection Agreements

The current System Interconnection Agreements applicable to [System Name] are identified in Table 1.6-1. If there are no System Interconnection Agreements that apply to this system, place “NONE” in the table below System Name.

Table 1.6-1 System Interconnection Agreements

System Name Organization

Type Agreement

(ISA, MOU/A) &

Date

FIPS 199

Category of the other system

ATO status of the other system

AO of the other system

2.0 Access Control

(ITS-HBK-2810.15-01, ITS-HBK-2810.15-02A)

Access Control relates to the ability to permit or deny access to computer systems, system locations, and system information based on a user’s need to know. It encompasses the management of unique account identifiers (IDs), passwords, physical access, badges and tokens, and user permissions to ensure the proper level of system access.

The section should address access control requirements for:

• Account Management

• Access Enforcement

• Separation of Duties

• Least Privilege

• Elevated Privilege

• System Use Notification

• Session Control

• Remote Access

• Mobile Devices

80NSSC22R0001 Page 15 of 35

DRD-MA-05 Exhibit 3, Page 3

• Foreign National Access Management

• Data at Rest (DAR) and Public Key Infrastructure (PKI) encryption

3.0 Awareness and Training

(ITS-HBK-2810.06-01)

Security Awareness and Training relates to the information security knowledge requirements for all users of information systems, and the development and delivery of courses and other training resources to enable and validate satisfaction of those requirements. Users are responsible for meeting Agency security training requirements in order to gain and maintain access to any NASA information resource. Furthermore, certain roles, including managers and those with significant information security responsibilities, have to comply with additional security training and awareness requirements.

This section should address requirements for:

• Security Awareness Training

• Role Based Security Training

• Training Record Documentation

• Personal Identifiable Information (PII)

4.0 Audit and Accountability

(ITS-HBK-2810.16-01)

Audit and Accountability relates to the documentation and management of events that occur on or to information system components. Generally, it helps to answer the questions of “who,” “what,” “when,” “where,” and sometimes “how” revolving around various types of information system events (i.e., who logged into a given machine, when, and from where, etc.?). Such audit trails are used for individual accountability, intrusion detection, and problem identification. Such details are stored in logs which are used to produce useful, actionable information by applying data analysis techniques to detect anomalous trends and patterns that may be cause for concern. The logs can be used both retroactively to determine the causes of an adverse event, and proactively to detect and take action to avert an imminent adverse event.

This section should address requirements for:

• Audit Events and Audit Generation

• Content of Audit Records

• Audit Record Storage and Retention

• Response to Audit Failures

• Audit Review, Analysis, and Reporting

• Audit Reduction and Report Generation

• Time Stamps

• Protection of Audit Information

80NSSC22R0001 Page 16 of 35

DRD-MA-05 Exhibit 3, Page 4

5.0 Security Assessment and Authorization

(ITS-HBK-2810.02-01, ITS HBK-2810.02-02, ITS-HBK-2810.02-03)

Security Assessment and Authorization relates to the activities and requirements surrounding the routine testing of security controls, the continuous monitoring of system security posture, and the ongoing risk-based decisions to approve or deny the use of a system. It includes continuously ensuring the effectiveness of security control implementations throughout the life cycle of a system.

This section should address requirements for:

• Security Assessments

• Information System Connections

• Plan of Action and Milestones

• Security Authorization

• Continuous Monitoring

6.0 Configuration Management

(ITS-HBK-2810.07-01, ITS-HBK-2810.02-04A)

Configuration Management relates to the organizational aspects of information system baseline configurations, establishing review and validation, and change control. It also manages administrator roles, and the ability of individuals to make changes to the information systems’ configuration. The concept of configuration management is critical to the continuous monitoring processes. Strict methodologies for the regulation of information system baselines and changes to system configurations are necessary for near real-time understanding of a system’s risk posture.

This section should address requirements for:

• Baseline Configuration

• Configuration Change Control

• Security Impact Analysis

• Access Restrictions for Change

• Configuration Settings

• Least Functionality

• Inventory

• Configuration Management Plan

• Software Usage Restrictions

• Configuration Management Training

80NSSC22R0001 Page 17 of 35

DRD-MA-05 Exhibit 3, Page 5

7.0 Contingency Planning

(ITS-HBK-2810.08-01)

Contingency Planning relates to the preparation of information security response, recovery, and continuity activities to avoid disruptions to critical business processes. Successful contingency planning increases the likelihood that essential information and information systems will be available and assists an organization with maintaining continuity of operations in emergency situations. Effective contingency planning, training, testing, and execution are essential to mitigating the impacts resulting from system and service disruptions.

This section should address requirements for:

• Contingency Plan and Contingency Plan Testing

• Contingency Training

• Alternate Storage Site

• Alternate Processing Site

• Information System Backup

• Information System Recovery and Reconstitution

8.0 Identification and Authentication

(ITS-HBK-2810.17-01)

Identification and Authentication relates to the activities and provisions which ensure the identity of a given entity requesting access to resources (e.g., a person logging in to a computer, or a laptop computer connecting to a wireless network). It addresses the creation, management, usage, and protection of identities (e.g., usernames) and authenticators (e.g., smart cards and tokens).

This section should address requirements for:

• Organizational and Non-Organizational Users

• Device Identification and Authentication

• Authenticator Management

• Cryptographic Module Authentication

80NSSC22R0001 Page 20 of 35

DRD-MA-05 Exhibit 3, Page 6

9.0 Incident Response

(ITS-HBK-2810.09-01)

Incident Response relates to dealing with the potential for and actual damage and disruption to information systems. An “incident” is any adverse event or situation associated with a system that poses a threat to the system’s integrity, availability, or confidentiality. An incident may result in or stem from one of the following: a failure of security controls; an attempted or actual compromise of information; and/or waste, fraud, abuse, loss, or damage of government property information.

This section should address requirements for:

• Incident Response Training

10.0 Maintenance

(ITS-HBK-2810.10-01)

Maintenance relates to the continuous upkeep of information system components. In general, maintenance controls are very system specific and are typically performed based upon vendor recommendations. Many variable factors are considered when making the appropriate maintenance decisions for a system. The business impact, cost, and likelihood of equipment failure, the cost of the maintenance agreement, and the availability of spare equipment can all influence the application of specific maintenance controls.

This section should address requirements for:

• Controlled Maintenance

• Maintenance Tools

• Non-Local Maintenance

• Timely Maintenance

11.0 Media Protection

(ITS-HBK-2810.11-01, ITS-HBK-2810.11-02)

Media Protection relates to the secure use of information storage media. Storage media can take one of two forms – digital or non-digital. Non-digital media typically consists of paper, film, microfilm, microfiche, etc.

Digital media is comprised of mobile computing devices, laptops, PDAs, “smart phones,” and removable storage devices such as USB drives, flash drives, writeable CDs and DVDs, memory cards, external hard drives, storage cards, diskettes, magnetic tapes, or any electronic device that can be used to copy, save store, and/or move data from one system to another.

This section should address requirements for:

• Media Access

• Media Marking

• Media Storage

• Media Transportation

• Media Sanitation

• Media Use

DRD-MA-05 Exhibit 3, Page 7

11.0 Physical and Environmental Protection

(ITS-HBK-2810.12-01)

Physical and Environmental Protection relates to the activities and requirements surrounding the development, implementation, and maintenance of physical access authorizations and controls (e.g., key and security badge distribution, visitor management, and related record keeping), and the protection, proofing, and regulation of facilities. This section also addresses protection of facilities and the essential utilities and infrastructure which support those facilities (e.g., door locks, backup power and lighting, emergency plumbing shutoff switches, and fire suppression systems), and environmental controls for those facilities (e.g., temperature regulation, humidity monitoring), as appropriate.

This section should address requirements for:

• Physical Access Authorizations

• Access Control for Transmission Medium and Output Devices

• Visitor Access Records

• Emergency Shutoff

• Emergency Power and Lighting

• Temperature and Humidity Controls

• Water Protection

• Delivery and Removal

• Alternate Work Site

• Location of Information System Components (High Systems only)

12.0 Planning

(ITS-HBK-2810.03-01, ITS-HBK-2810.03-02)

Planning relates to the definition and documentation of the key resources and activities used to protect information and information systems. Effective security planning is both comprehensive and flexible. NASA uses a System Security Plan (SSP) template to specify the set of security controls that must be considered for each system. The plan content for any specific system is governed by a risk assessment of the particular threats facing the system and a tailoring of security controls to meet those threats.

This section should address requirements for:

• System Security Plan

• Rules of Behavior

• Information Security Architecture

• Service Level Agreement Process

DRD-MA-05 Exhibit 3, Page 8

13.0 Personnel Security

(ITS-HBK-2810.13-01)

Personnel Security relates to the security activities that surround various facets of the employment life cycle (i.e., initial employee screening, position categorization, authority delegation, sanctioning, transfers, and termination). Personnel Security applies to both direct employees of the Agency as well as contracted personnel, and service bureaus.

This section should address requirements for:

• Personnel Termination and Transfer

• Access Agreements

• Third-Party Personnel Security

14.0 Risk Assessment

(ITS-HBK-2810.04-01A, ITS-HBK-2810.04-02, ITS-HBK-2810.04.03)

Risk Assessment relates to a framework for the identification, tracking, and mitigation of information security risks. The goal of effective risk management is to articulate the likelihood and impact that threats may have on owned assets, data and personnel, and to minimize the likelihood and impact by applying security controls. In order to make informed decisions about the security of assets and personnel, organizations have the responsibility of understanding the risks that affect their systems, and the mitigating controls which address them.

This section should address requirements for:

• Security Categorization

• Risk Assessment

• Vulnerability Scanning

14.0 System and Services Acquisition

(ITS-HBK-2810.05-01)

System and Services Acquisition relates to the need to adequately plan for, appropriately fund, and efficiently acquire the resources necessary to maintain information security. It defines the actions that best enable an organization’s security program to make effective use of externally‐sourced expertise and tools and mandates that security considerations not be treated as an afterthought, but are addressed early‐ on in parallel with funding and design decisions.

This section should address requirements for:

• Allocation of Resources

• System Development Lifecycle

• Information System Documentation

80NSSC22R0001 Page 21 of 35

DRD-MA-05 Exhibit 3, Page 9

• Security Engineering Principles

• Developer Configuration Management

• Developer Security Testing and Evaluation

• Supply Chain Protection (High systems only)

• Development Process, Standards, and Tools (High systems only)

• Developer-Provided Training (High systems only)

• Developer Security Architecture and Design (High systems only)

• IT Portfolio

15.0 Systems and Communications Protection

(ITS-HBK-2810.18-01)

System and Communication relates to the protection of confidentiality, integrity, and availability of information systems and information as it flows between communications networks. It ensures the establishment of an effective physical and logical network security perimeter and provides guidance for best protecting information as it moves both within the security perimeter and as it moves to and from other networks outside the security perimeter such as the Internet.

This section should address requirements for:

• Application Partitioning

• Information in Shared Resources

• Denial of Service Protection

• Boundary Protection

• Transmission confidentiality and Integrity

• Network Disconnect

• Cryptographic Key Establishment and Management

• Use of Cryptography

• Public Access Protections

• Collaborative Computing Devices

• Mobile Code

• Voice over Internet Protocol

• Session Authenticity

• Protection of Information at Rest

• Process Isolation

• Security Function Isolation (High systems only)

• Fail in Known State (High systems only)

80NSSC22R0001 Page 22 of 35

DRD-MA-05 Exhibit 3, Page 10

16.0 System and Information Integrity

(ITS-HBK-2810.14-01)

System and Information Integrity relates to the prevention and detection of improper modification or destruction of an information system. It also includes ensuring the nonrepudiation and authenticity of information, as well as flaw remediation (e.g., patching vulnerable software), malicious code prevention (e.g., anti-virus software), and monitoring of attempts to subvert integrity (e.g., an intrusion detection system).

This section should address requirements for:

• Flaw Remediation

• Malicious Code Protection

• Information System Monitoring

• Software, Firmware and Information Integrity

• Spam Protection

• Information Input Validation

• Error Handling

• Memory Protection

17.0 Privacy Impact Assessment

Privacy Impact Assessment relates to the need to protect an individual's privacy with respect to personally identifiable information (PII). Protecting the privacy of individuals and their PII that is collected, used, maintained, shared, and disposed of by programs and information systems, is a fundamental responsibility of federal organizations.

This section should address requirements for:

• Privacy Impact and Risk Assessment

• Privacy Notice

• Privacy Notices for Websites

17.0 Program Management

Program management provides a foundation for the organization’s information security program and is typically implemented at the directorate level. The focus is on the programmatic, organization-wide information security requirements that are independent of any particular information system and are essential for managing information security programs.

This section should address requirements for:

• Information Security Resources (Budget/CPIC)

• Enterprise Architecture

• Critical Infrastructure Plan

• Mission/Business Process Definition

• Contractor Evaluations

• Contractors Security Requirements (SOW/DRD)

80NSSC22R0001 Page 23 of 35

DRD-MA-05 Exhibit 3, Page 11

Appendix A – Related Laws, Regulations, Policies and Reference Material

1. Federal Information Processing Standard 199, Standards for Security Categorization of Federal Information and Information Systems, 2/1/2004

2. NPR 1600.1, NASA Security Program Procedural Requirements, 8/12/2013

3. NPR 2810.1A, Security of Information Technology, 5/16/2006

4. ITS-HBK-2810.0002A, Roles and Responsibilities Crosswalk, 5/2/2013

5. ITS-HBK-2810.02-01, Security Assessment and Authorization, 5/6/2013

6. ITS-HBK-2810.02-02, Security Assessment and Authorization: FIPS 199 Moderate & High Systems, 11/24/2012

7. ITS-HBK-2810.02-03, Security Assessment and Authorization: FIPS 199 Low Systems, 11/24/2012

8. ITS-HBK-2810.02-04A, Security Assessment and Authorization:

Continuous Monitoring - Annual Security Control Assessments, 3/18/2014

9. ITS-HBK-2810.02-05, Security Assessment and Authorization:

External Information Systems, 11/24/2012

10. ITS-HBK-2810.02-08A, Security Assessment and Authorization:

Information System Security Plan Numbering Schema, 12/11/2013

11. ITS-HBK-2810.03-01, Planning, 5/6/2011

12. ITS-HBK-2810.03-02, Planning: Information System Security Plan Template, Requirements, Guidance and Examples, 2/9/2011

13. ITS-HBK-2810.04-01A, Risk Assessment: Security Categorization, Risk Assessment, Vulnerability Scanning, Expedited Patching, & Organizationally Defined Values, 10/12/2012

14. ITS-HBK-2810.04-02, Risk Assessment: Procedures for Information System Security Penetration Testing and Rules of Engagement, 4/30/2013

15. ITS-HBK-2810.04-03, Risk Assessment: Web Application Security Program, 4/30/2013

16. ITS-HBK-2810.05-01, Systems and Service Acquisition, 11/21/2011

17. ITS-HBK-2810.06-01, Awareness and Training, 5/6/2011

18. ITS-HBK-2810.07-01, Configuration Management, 5/6/2011

19. ITS-HBK-2810.08-01, Contingency Planning, 4/26/2012

80NSSC22R0001 Page 24 of 35

DRD-MA-05 Exhibit 3, Page 12

20. ITS-HBK-2810.08-02, Contingency Planning: Guidance and Templates for Development, Maintenance, and Test, 2/11/2011

21. ITS-HBK-2810.09-01, Incident Response and Management, 5/6/2011

22. ITS-HBK-2810.09-02, NASA Information Security Incident Management, 8/24/2011

23. ITS-HBK-2810.09-03, Targeted Collection of Electronic Data, 8/24/2011 5. ITS-HBK-2810.10-01, Maintenance, 5/6/2011

24. ITS-HBK-2810.11-01, Media Protection, 5/6/2011

25. ITS-HBK-2810.11-02, Media Protection: Digital Media

Sanitization, 7/13/2012

26. ITS-HBK-2810.12-01, Physical and Environmental Protection, 5/6/2011

27. ITS-HBK-2810.13-01, Personnel Security, 5/6/2011

28. ITS-HBK-2810.14-01, System and Information Integrity, 5/6/2011 11. ITS-HBK-2810.15-01, Access Control, 9/4/2012

29. ITS-HBK-2810.15-02A, Access Control: Elevated Privileges (EIP), 1/3/2012

30. ITS-HBK-2810.16-01, Audit and Accountability, 5/6/2011

31. ITS-HBK-2810.17-01, Identification and Authentication, 5/6/2011

32. ITS-HBK-2810.18-01, System and Communications Protection, 5/6/2011

33. NASA Form 1686, Sensitive But Unclassified, 6/15/2009

34. NIST SP 800-30 Rev1, Guide for Conducting Risk Assessments, September

2012.

35. NIST SP 800-39, Managing Information Security Risk:

Organization, Mission, and Information System View, March 2011.

36. NIST SP 800-37 Rev1, Guide for Applying the Risk Management

Framework to Federal Information Systems: A Security Life Cycle Approach, February 2010.

37. NIST SP 800-47, Security Guide for Interconnecting Information Technology Systems, August 2002

38. NIST SP 800-53 Rev 4, Security and Privacy Controls for Federal Information Systems and Organizations, April 2013

39. NIST SP 800-60 Rev. 1, Guide for Mapping Types of Information and Information Systems to Security Categories, August 2008

40. NIST SP 800-64 Rev. 1, Security Considerations in the System Development Life Cycle, October 2008

80NSSC2…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .