Attachment B - Applicable Documents List.pdf
PDF 425 KB Posted
- Attached to
- Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) Federal contract opportunity
- Solicitation number
- 80TECH21R0007
About this file
This document provides an Applicable Documents List for the Cybersecurity and Privacy Enterprise Solutions and Services solicitation issued by the National Aeronautics and Space Administration. The solicitation seeks cybersecurity and privacy enterprise solutions, services, and related support for all NASA Centers and Facilities. Applicable documents include NASA policies, standards, and guidance related to IT security, privacy, records management, software engineering, and safety. Also included are Office of Management and Budget policies, National Institute of Standards and Technology special publications, Federal Information Processing Standards, and relevant sections of the Code of Federal Regulations regarding export controls. Offerors must comply with all current revisions and future updates to these documents as applicable to the work performed under the resulting contract.
View the file
Other files for this federal contract opportunity
Show all 50
Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT B
CYBERSECURITY AND PRIVACY
ENTERPRISE SOLUTIONS AND SERVICES
(CyPrESS) APPLICABLE DOCUMENTS LIST
RFP 80TECH21R0007
CONTRACT # TBD
DATE: October 2020
J-10-2
Information Technology (IT) Security Applicable Documents List October 2020
NASA Policy Directives (NPD) and NASA Procedural Requirements (NPR)
Document Subject
NPR 1040.1 NASA Continuity of Operations (COOP) Planning Procedural Requirements
NPD 1280.1 NASA Integrated Management System Policy
NPR 1382.1 NASA Privacy Procedural Requirements
NPD 1382.17 NASA Privacy Policy
NPD 1440.6 NASA Records Management
NPR 1441.1 NASA Records Management Program Requirements
NPR 1600.1 NASA Security Program Procedural Requirements
NPR 1600.2 NASA Classified National Security Information (CNSI)
NPR 1620.3 Physical Security Requirements for NASA Facilities and Property
NPR 1800.1 Occupational Health Programs
NPD 2190.1 NASA Export Control Program
NPR 2190.1 NASA Export Control Program
NPD 2540.1
Acceptable Use of Government Office Property Including Information Technology
NPD 2800.1 Managing Information Technology
NPR 2800.1 Managing Information Technology
NPD 2810.1 NASA Information Security Policy
J-10-3
NPR 2810.1 Security of Information Technology
NPR 2810.2
Use of NASA Information and Information Systems while Outside of the U.S.
and Territories
NPD 2830.1 NASA Enterprise Architecture
NPR 2830.1 NASA Enterprise Architecture Procedures
NPR 2841.1 Identity, Credential, and Access Management
NPR 3792.1 NASA’s Plan for a Drug Free Workplace
NPR 4100.1 NASA Supply Support and Material Management
NPD 4200.1 Equipment Management
NPR 4200.1 NASA Equipment Management Procedural Requirements
NPR 4300.1 NASA Personal Property Disposal Procedural Requirements
NPD 6000.1 Transportation Management
NPR 6200.1 NASA Transportation and General Traffic Management
NPR 7120.5 NASA Space Flight Program and Project Management Requirements (The document is applicable to PWS <number> ISSO Services only.)
NPR 7120.7 NASA Information Technology Program and Project Management Requirements
NPR 7120.8
NASA Research and Technology Program and Project Management Requirements (The document is applicable to PWS <number> ISSO Services only.)
NPR 7123.1 NASA Systems Engineering Processes and Requirements
NPR 7150.2 NASA Software Engineering Requirements
NPR 7500.2 NASA Technology Transfer Requirements
NPR 8621.1 NASA Procedural Requirements for Mishap and Close Call Reporting, Investigating, and Recordkeeping
NPR 8715.1 NASA Safety and Health Programs
NPR 8715.3 NASA General Safety Program Requirements
NPD 8730.5 NASA Quality Assurance Program Policy
NPD 8800.14 Policy for Real Estate Management
J-10-4
NPR 8831.2 Facilities Maintenance and Operations Management
NPR 9501.2 NASA Contractor Financial Management Reporting
NASA Interim Directive (NID)
J-10-5
NASA Records Retention Schedules (NRRS)
NRRS 1441.1 NASA Records Retention Schedule
IT Security Handbooks (ITS-HBK)
ITS-HBK-1382.02-01 Privacy Goals and Objectives: Overview
ITS-HBK-1382.03-01
Privacy Risk Management and Compliance: Collections, PIAs and SORNs
ITS-HBK-1382.03-02
Privacy Risk Management and Compliance: Annual Reporting Procedures for Reviewing and Reducing Personally Identifiable Information (PII) and Eliminating the Unnecessary Use of SSN
ITS-HBK-1382.04-01 Privacy and Information Security: Overview
ITS-HBK-1382.05-01
Privacy Incident Response and Management: Breach Response Team
ITS-HBK-1382.06-01
Privacy Notice and Redress: Web Privacy and Written Notice, Complaints, Access and Redress
ITS-HBK-1382.07-01 Privacy Awareness and Training: Overview
ITS-HBK-1382.08-01 Privacy Accountability
ITS-HBK-1382.09-01 Privacy Rules of Behavior and Consequences: Overview
J-10-6
IT-HBK-1441.01.01 Records Retention and Disposition: Overview
IT-HBK-1440.01.01 Records Planning & Management: Records Management and Records Life Cycle - Overview
ITS-HBK-2841.003 Identity, Credential, and Access Management Services (ICAM)
ITS-HBK-2810.02-01 Security Assessment and Authorization
ITS-HBK-2810.02-02
Security Assessment and Authorization: Information System Security Assessment and Authorization Process
ITS-HBK-2810.02-04
Security Assessment and Authorization: Continuous Monitoring
– Security Control Ongoing Assessments and Authorization
ITS-HBK-2810.02-05
Security Assessment and Authorization: External Information Systems
ITS-HBK-2810.02-06
Security Assessment and Authorization: Extending and Information Systems Authorization to Operate Process and Template
ITS-HBK-2810.02-08
Security Assessment and Authorization: Plan of Action and Milestones
(POA&M)
J-10-7
ITS-HBK-2810.03-02
Planning
ITS-HBK-2810.04-01
Risk Assessment: Security Categorization, Risk Assessment, Vulnerability Scanning, Expedited Patching & Organizationally Defined Values
ITS-HBK-2810.05-02 Systems and Service Acquisition
ITS-HBK-2810.06-02 IT Security Awareness, Training, and Education
ITS-HBK-2810.07-02 Configuration Management
ITS-HBK-2810.08-01 Contingency Planning
ITS-HBK-2810.09-01 Incident Response and Management
ITS-HBK-2810.09-02 NASA Information Security Incident Management
ITS-HBK-2810.09-03 Collection of Electronic Data
ITS-HBK-2810.09-04
Incident Response and Management: Guidelines for Data Spillage & Sanitization Procedures
ITS-HBK-2810.10-02 Maintenance
J-10-8
ITS-HBK-2810.11-2 Media Protection and Sanitization
ITS-HBK-2810.12-02 Physical and Environmental Protection
ITS-HBK-2810.13-01 Personnel Security
ITS-HBK-2810.14-03 System and Information Integrity
ITS-HBK-2810.15-01 Access Control
ITS-HBK-2810.15-02 Access Control: Managed Elevated Privileges (EP)
ITS-HBK-2810.16-02 Audit and Accountability
ITS-HBK-2810.17-02 Identification and Authentication
ITS-HBK-2810.18-02 System and Communications Protection
ITS-HBK-2810.19.01 Operational Technology
ITS-HBK-2810.002-1 Format and Procedures for IT Security Policies and Handbooks: Privacy, Security & Sensitive Information
Standards
NASA-STD-2804 Minimum Interoperability Software Suite
NASA-STD-2805 Minimum Hardware Configurations
J-10-9
Executive
Orders and FIPS
Document Subject
Executive Order
(EO) 13556
Controlled Unclassified Information (CUI)
EO 13636 Improving Critical Infrastructure Cybersecurity
EO 13834 Efficient Federal Operations Federal Information Processing Standards (FIPS) 140-2
Security Requirements For Cryptographic Modules
FIPS 180 Secure Hash Standard (SHS)
FIPS 186 Digital Signature Standard (DSS)
FIPS 197 Advanced Encryption Standard (AES)
FIPS 198 The Keyed-Hash Message Authentication Code (HMAC)
FIPS 199 Standards for Security Categorization of Federal Information and Information Systems
FIPS 200 Minimum Security Requirements for Federal Information and Information Systems
FIPS 202 SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions
NIST
NIST SP 800-100 Information Security Handbook: A Guide for Managers
NIST SP 800-101 Guidelines on Mobile Device Forensics
NIST SP 800-107
Recommendation for Applications Using Approved Hash Algorithms
NIST SP 800-111 Guide to Storage Encryption Technologies for End User Devices
NIST SP 800-113 Guide to SSL VPNs
NIST SP 800-114
User’s Guide to Telework and Bring Your Own Device (BYOD) Security
J-10-10
NIST SP 800-115 Technical Guide to Information Security Testing and Assessment
NIST SP 800-116 Guidelines for the Use of PIV Credentials in Facility Access
NIST SP 800-12 An Introduction to Information Security
NIST SP 800-121 Guide to Bluetooth Security
NIST SP 800-122
Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)
NIST SP 800-123 Guide to General Server Security
NIST SP 800-124
Guidelines for Managing the Security of Mobile Devices in the Enterprise
NIST SP 800-125 Guide to Security for Full Virtualization Technologies
NIST SP 800-125A
Security Recommendations for Server-based Hypervisor Platforms
NIST SP 800-125B
Secure Virtual Network Configuration for Virtual Machine (VM) Protection
NIST SP 800-126
The Technical Specification for Security Content Automation Protocol (SCAP): SCAP Version 1.1
NIST SP 800-126A
SCAP 1.3 Component Specification Version Updates: An Annex to NIST Special Publication 800-126 Revisions 3
NIST SP 800-126
Rev. 2
The Technical Specification for Security Content Automation Protocol (SCAP): SCAP Version 1.2
NIST SP 800-126
Rev. 3
The Technical Specification for Security Content Automation Protocol (SCAP): SCAP Version 1.3
NIST SP 800-128
Guide for Security-Focused Configuration Management of Information Systems
NIST SP 800-130
A Framework for Designing Cryptographic Key Management Systems
NIST SP 800-133 Recommendation for Cryptographic Key Generation
NIST SP 800-135
Recommendation for Existing Application-Specific Key Derivation Functions
J-10-11
NIST SP 800-137
Series
Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations
NIST SP 800-140
including A-F
FIPS 140-3 Derived Test Requirements (DTR): Cryptographic Module Validation Program (CMVP) Validation Authority Updates to ISO/IEC 24759 and all requirements from the series
NIST SP 800-144 Guidelines on Security and Privacy in Public Cloud Computing
NIST SP 800-145 The NIST Definition of Cloud Computing
NIST SP 800-146 Cloud Computing Synopsis and Recommendations
NIST SP 800-147 BIOS Protection Guidelines
NIST SP 800-147B BIOS Protection Guidelines for Servers
NIST SP 800-150 Guide to Cyber Threat Information Sharing
NIST SP 800-152
A Profile for U.S. Federal Cryptographic Key Management System (CKMS)
NIST SP 800-156 Representation of PIV Chain-of-Trust for Import and Export
NIST SP 800-157
Guidelines for Derived Personal Identity Verification (PIV) Credentials.
NIST SP 800-16
Information Technology Security Training Requirements: a Role-and Performance-Based Model
NIST SP 800-160
Vol. 1 & 2
Systems Security Engineering: Multidisciplinary Approach and Developing Cyber Resilient Systems
NIST SP 800-161
Supply Chain Risk Management Practices for Federal Information Systems and Organizations
NIST SP 800-163 Vetting the Security of Mobile Applications
J-10-12
NIST SP 800-166 Derived PIV Application and Data Model Test Guidelines
NIST SP 800-167 Guide to Application Whitelisting
NIST SP 800-168 Approximate Matching: Definition and Terminology
NIST SP 800-171
Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
NIST SP 800-171A
Assessing Security Requirements for Controlled Unclassified Information
NIST SP 800-
175A
Guideline for Using Cryptographic Standards in the Federal Government: Directives, Mandates and Policies
NIST SP 800-
175B
Guideline for Using Cryptographic Standards in the Federal Government: Cryptographic Mechanisms
NIST SP 800-177 Trustworthy Email
NIST SP 800-18
Guide for Developing Security Plans for Federal Information Systems
NIST SP 800-181
National Initiative for Cybersecurity Education (NICE) Cybersecurity Workforce Framework
NIST SP 800-183 Network of ‘Things’
NIST SP 800-184 Guide for Cybersecurity Event Recovery
NIST SP 800-187 Guide to LTE Security
NIST SP 800-189
Resilient Interdomain Traffic Exchange: BGP Security and DDoS Mitigation
NIST SP 800-190 Application Container Security Guide
NIST SP 800-192
Verification and Test Methods for Access Control Policies/Models
J-10-13
NIST SP 800-193 Platform Firmware Resiliency Guidelines
NIST SP 800-204
Series
Security Strategies for Microservices-based Applications Systems
NIST SP 800-205 Attribute Considerations for Access Control Systems
NIST SP 800-207 Zero Trust Architecture
NIST SP 800-210 General Access Control Guidance for Cloud Systems
NIST SP 800-25 Federal Agency Use of Public Key Technology for Digital Signatures and Authentication
NIST SP 800-30 Guide for Conducting Risk Assessments
NIST SP 800-32 Introduction to Public Key Technology and the Federal PKI Infrastructure
NIST SP 800-34 Contingency Planning Guide for Federal Information Systems
NIST SP 800-35 Guide to Information Technology Security Services
NIST SP 800-37
Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy
NIST SP 800-39 Managing Information Security Risk: Organization, Mission, and Information System View
NIST SP 800-40 Guide to Enterprise Patch Management Technologies
NIST SP 800-41 Guidelines on Firewalls and Firewall Policy
NIST SP 800-44 Guidelines on Securing Public Web Servers
NIST SP 800-45 Guidelines on Electronic Mail Security
NIST SP 800-46 Guide to Enterprise Telework, Remote Access, and Bring Your Own Device (BYOD) Security
NIST SP 800-47 Security Guide for Interconnecting Information Technology Systems
NIST SP 800-50 Building an Information Technology Security Awareness and
NIST SP 800-52 Guidelines for Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations
NIST SP 800-53 Security and Privacy Controls for Federal Information Systems and Organizations
J-10-14
NIST SP 800-53A Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans
NIST SP 800-53B Control Baselines for Information Systems and Organizations
NIST SP 800-55 Performance Measurement Guide for Information Technology Systems
NIST SP 800-57
Parts 1- 3 Recommendation for Key Management
NIST SP 800-58 Security Considerations for Voice Over IP Systems
NIST SP 800-59 Guideline for Identifying an Information System as a National Security System
NIST SP 800-60
Volume I
Guide for Mapping Types of Information and Information Systems to Security Categories
NIST SP 800-60
Volume II
Guide for Mapping Types of Information and Information Systems to Security Categories: Appendices
NIST SP 800-61 Computer Security Incident Handling Guide
NIST SP 800-63
also includes B and C
Digital Identity Guidelines
NIST SP 800-66 An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule
NIST SP 800-70 National Checklist Program for IT Products: Guidelines for Checklist Users and Developers
NIST SP 800-72 Guidelines on PDA Forensics
NIST SP 800-73 Interfaces for Personal Identity Verification
NIST SP 800-76 Biometric Specifications for Personal Identity Verification
NIST SP 800-77 Guide to IPsec VPNs
NIST SP 800-79 Guidelines for the Authorization of Personal Identity Verification Card Issuers (PCI) and Derived PIV Credential Issuers (DPCI)
NIST SP 800-81 Secure Domain Name System (DNS) Deployment Guide
NIST SP 800-82 Guide to Industrial Control Systems (ICS) Security
NIST SP 800-83 Guide to Malware Incident Prevention and Handling for Desktops and Laptops
NIST SP 800-84 Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities
NIST SP 800-85A PIV Card Application and Middleware Interface Test Guidelines
NIST SP 800-85B PIV Data Model Test Guidelines
J-10-15
NIST SP 800-86 Guide to Integrating Forensic Techniques into Incident Response
NIST SP 800-88 Guidelines for Media Sanitization
NIST SP 800-89 Recommendation for Obtaining Assurances for Digital Signature Applications
NIST SP 800-92 Guide to Computer Security Log Management
NIST SP 800-94 Guide to Intrusion Detection and Prevention Systems (IDPS)
NIST SP 800-95 Guide to Secure Web Services
NIST SP 800-96 PIV Card to Reader Interoperability Guidelines
NIST SP 800-98 Guidelines for Security Radio Frequency Identification (RFID) Systems
NIST SP 1800-2 Identity and Access Management for Electric Utilities
NIST SP 1800-4 Cloud and Hybrid Builds
NIST SP 1800-5 IT Asset Management
NIST SP 1800-6 Domain Name System-Based Electronic Mail Security
NIST SP 1800-7 Situational Awareness for Electric Utilities
NIST SP 1800-11 Data Integrity: Recovering from Ransomware and Other Destructive Events
NIST SP 1800-12 Derived Personal Identity Verification (PIV) Credentials
NIST SP 1800-16 Securing Web Transactions: TLS Server Certificate Management
NIST SP 1800-17 Multifactor Authentication for E-Commerce: Risk-Based, FIDO Universal Second Factor Implementations for Purchasers
NIST SP 1800-21 Mobile Device Security: Corporate-Owned Personally-Enabled (COPE)
NIST SP 1800-23 Energy Sector Asset Management: For Electric Utilities, Oil & Gas Industry
*NOTE: There are NIST documents in draft within the series that will be applicable to the contract.
Code of Federal Regulations
15 CFR Parts 730-
Export Administration Regulations (EAR)
File details come from the government source that posted it. Updated .