Attachment C - Data Requirements Descriptions.pdf
PDF 513 KB Posted
- Attached to
- Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) Federal contract opportunity
- Solicitation number
- 80TECH21R0007
About this file
This document outlines data requirements for a cybersecurity and privacy enterprise solutions and services contract. The contractor must provide a variety of reports, plans, and assessments to the National Aeronautics and Space Administration. These include technology reports, a contract management plan, an information security management plan, application and capacity reports, and financial reports. The contractor must also submit a quality plan, safety and environmental plans, and various status and performance reviews. Submission dates and formats are specified for each required deliverable. The contract aims to provide cybersecurity and privacy solutions and related services across all NASA centers and facilities.
View the file
Other files for this federal contract opportunity
Show all 50
Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CYPRESS 80TECH21R0007
J-1-1
Attachment C
Data Requirements List And
Data Requirements Descriptions
RFP 80TECH21R0007
Contract #TBD
April 2021
J-1-2
DATA REQUIREMENTS LIST (DRL) AND
DATA REQUIREMENTS DESCRIPTIONS
(DRD)
The following pages set out the documentation requirements of this contract, starting with a DRL, which is an index to the DRDs. Each DRD prescribes the required data product content, schedule, type, and other particulars for specific data submission requirements.
Data Requirements List
DRD
Line # DRD # Data
Type DRD Title OPR CyPrESS-CD CD-Contractual Data
1 1 3 Technology Reports Space Technology Mission Directorate
CyPrESS-LS LS – Logistics Support
2 1 Reserved
3 2 Reserved
CyPrESS-MA MA – Management
4 1 1 Contract Management Plan OCIO 5 2 1 Contract Phase-In Plan OCIO 6 3 2 Information Security Management Plan OCIO
7 4 1 Information Technology (IT) System Security Plan
(SSP) OCIO
8 5 2 Service Asset and Configuration Management (SACM) Plan OCIO
9 6 2 Release and Deployment Management (RDM) Plan OCIO 10 7 3 Application Inventory Report OCIO 11 8 2 Capacity Management Plan OCIO 12 9 3 Service and Component Capacity Report OCIO 13 10 2 IT Service Continuity Management (ITSCM) Plan OCIO 14 11 3 Interface Definition Agreement (IDA) OCIO 15 12 3 Reserved OCIO 16 13 3 Problem Documentation OCIO 17 14 1/2/3 Reserved OCIO 18 15 Reserved 19 16 2 Reserved OCIO 20 17 Reserved
21 18 1 Annual Work Plan (AWP) OCIO 22 19 2/3 Export Control Plan and Reports OCIO 23 20 3 Financial Management Report (533M AND 533Q) Chief Financial Office 24 21 3 Contractor Self-Assessment Report OCIO
J-1-3
25 22 1 Fixed Price Transition Plan (FPTP) OCIO
26 23 2 Corporate Target Architecture (CTA) and 5-Year Service Line Plans Annual Report OCIO
27 24 2 Organizational Conflicts of Interest (OCI) Plan Office of Procurement
28 25 3 CyPrESS Monthly Status Review Report OCIO 29 26 Reserved
30 27 2 Re-procurement Data Package Office of Procurement
31 28 Reserved 32 29 2 WYE Reports OCIO
33 30 2 Small Business Subcontracting Plan Office of Procurement
34 31 2 Total Compensation Plan Office of Procurement
35 32 2 Notification of Potential Labor Dispute and Contingency Strike Plan
Office of Procurement
36 33 1 Close-out Plan Office of Procurement
37 34 1 Innovation Plan and Reports OCIO 38 35 2 Supplemental FFP Invoicing Data OCIO
CyPrESS-QE QE – Quality Engineering
39 1 1 Quality Plan Office of Safety and Mission Assurance
CyPrESS-RM RM – Reliability and Maintainability
40 1 1 Operability/Maintainability Plan OCIO
CyPrESS-SA SA – Safety
41 1 1 Safety, Healthy, and Environmental (SHE) Plan Office of Safety and Mission Assurance
42 2 3 Mishap and Safety Statistics Reports Office of Safety and Mission Assurance
43 3 3 Environmental and Energy Consuming Product Compliance Reports
Office of Center Operations
Subject to FAR 52.227-14 Rights in Data-General, Alternate II and Alternate III, as modified by NFS 1852.227-14 Rights in Data-General, this Data Procurement Document (DPD) sets forth the data requirements in each Data Requirements Description (DRD) and shall govern that data required by the DPD for this contract. The contractor shall furnish data defined by the DRDs listed on the Data Requirements List (DRL) by category of data. Such data shall be prepared, maintained, and delivered to NASA in accordance with the requirements set forth within this DPD. In cases where data requirements are covered by a Federal Acquisition Regulation (FAR) or NASA FAR Supplement (NFS) regulation or clause, the regulation shall take precedence over the DPD, per FAR 52.215-33 Order of Precedence. NASA-Owned/Contractor-Held records shall be managed by
J-1-4 the contractor in accordance with Title 36 of the Code of Federal Regulations, Chapter XII B, Records Management, and NPD 1440.6I, NASA Records Management Program. The records shall be organized in accordance with the instructions in NPR 1441.1E, NASA Records Retention Schedules, as applicable. The contractor shall disposition records and non-records in accordance with NPR 1441.1E, NASA Records Retention Schedules, which has been approved by NASA and the National Archives and Records Administration (NARA). All questions on records management issues shall be directed to the Contracting Officer.
Documents included as applicable documents in this DPD are the issue specified in the Statement of Work and form a part of the DPD to the extent specified herein. References to documents other than applicable documents in the data requirements of this DPD may sometimes be utilized. These do not constitute a contractual obligation on the contractor. They are to be used only as a possible example or to provide related information to assist the contractor in developing a response to that particular data requirement.
DESCRIPTION
This document identifies and defines the requirements and data types for information and data required under this contract.
The Data Requirement Descriptions (DRDs) define, by an individual Data Requirement (DR), the information and data required for each deliverable document.
The data types are used to identify the approval and control required for each DR. The Data Requirements List (DRL) is an index of all the DRs by category.
OPR indicates the program office for the respective DRD. DM indicates the document manager or owner.
Documentation submitted pursuant to this clause may incorporate references to other current approved documentation, provided the references are adequate and include such identification elements as title, document number, and approval date (where applicable). However, if the pertinent information is of relatively minor size, the contractor shall incorporate the information itself, in lieu of using a reference. The contractor shall assure that any referenced information is readily available to appropriate users of the submitted document.
DATA TYPES
For the purpose of this clause, the following information/documentation types are applicable:
Type 1 That information and documentation which requires NASA approval prior to release.
Approved type 1 information and documentation shall be controlled, and deviations from or changes to the concepts, techniques, and/or requirements stated therein shall require NASA approval prior to implementation. All work under this contract covered by approved type 1 documents shall be performed in accordance with those approved documents. The Contracting Officer’s Representative shall have approval authority and shall sign the data prior to its release. Contractually binding documents shall not be implemented nor revised without contractual authorization.
J-1-5
In addition, 30 calendar days in advance of the DRD due date the Contractor shall notify the Contracting Officer in writing of their intent to submit a type 1 deliverable marked as proprietary, reference FAR 52.227-14, Rights in Data - General.
Type 2 That information and documentation for which NASA reserves a time-limited right to disapprove, in whole or in part. Type 2 data shall be submitted to NASA for review not less than 30 calendar days prior to its release for use or implementation.
The contractor shall clearly identify the release target date in the "submitted for review" transmittal. If the contractor has not received any comment prior to the released target date, the document may be released for appropriate use. Any NASA comment received shall be appropriately dispositioned before the document is to be used. Type 2 data may be approved by NASA prior to its submittal. In addition, 30 calendar days in advance of the DRD due date the Contractor shall notify the Contracting Officer in writing of their intent to submit a type 2 deliverable marked as proprietary, reference FAR 52.227-14, Rights in Data - General.
Type 3 That information and documentation which is provided to NASA for surveillance, information, review, and/or management control. This information does not require formal NASA review and approval. Information in this category would include design solutions, status, and schedule reporting; analyses and test results, handbooks; and other designated lists, reports, etc. Type 3 deliverables shall not contain proprietary information.
Type 1 submissions shall be marked “TYPE 1 PRELIMINARY pending NASA approval or Type I APPROVED BY NASA, as appropriate." Additional special designations and deviations may be required on specific submissions in accordance with configuration management requirements.
Type 2 submissions shall be marked “TYPE 2 PRELIMINARY - RELEASE TARGET DATE, xx/xx/xx" or "TYPE 2 FINAL - NASA COMMENTS INCLUDED" or “TYPE 2 FINAL DOCUMENT," where NASA comments were not received.
NOTE: Documents submitted under this clause, even though directly (Type 1) or implicitly (Type
2) approved by NASA, shall not take precedence over the specifications as set out in the Statement of Work, Section C.
The contractor shall normally deliver a complete revised Type 1 or Type 2 data requirement with NASA comments incorporated within 45 calendar days of receipt of comments.
Type 3 submissions shall be marked "TYPE 3 DOCUMENT - FOR INFORMATION, SURVEILLANCE, REVIEW OR MANAGEMENT CONTROL."
DISTRIBUTION REQUIREMENTS
The contractor shall provide one copy of each DR to the standard distribution list stated in the DRD. Additional distribution shall be made as directed, in writing, by the Contracting Officer.
Data Transmittal Forms shall be used to confirm delivery of electronically resident DR
J-1-6 deliverables.
ELECTRONIC FORMAT
DRDs shall be maintained electronically in the contractor's own format, unless a specified format is defined in the DRD. The Government may define specific DRD data format to support the utilization of this data in the Management Information System. “Program Authorized Repository” should always be assumed as the ISS Program’s Electronic Document Management System (EDMS), unless another Program’s repository is specified.
J-1-7
DATA REQUIREMENTS DESCRIPTION (DRD)
1. ISSUE: DRAFT 2. DRD NO.: CD-001
3. DATA TYPE: 3 4. DATE REVISED:
6.
TITLE: Technology Reports
5. PAGE: 1/3
7. DESCRIPTION/USE: Provides NASA with technical information concerning any invention, discovery, improvement, or innovation made by a contractor in the performance of work under this contract for the purpose of disseminating this information to obtain increased use. Also, provides NASA with data to review for possible patentable items.
8. OPR: Space Technology Mission Directorate 9. DM: Office of Chief Technologist
10. DISTRIBUTION: Contracting Officer Representative (COR)
11. INITIAL SUBMISSION:
Technology Reporting Plan: Upon Contracting Officer’s request.
Disclosure of Invention and New Technology (NF1679): Within 2 months of identification of reportable item.
Interim NASA New Technology Summary Report (NTSR) Form: 12 months from the effective date of the contract.
12. SUBMISSION FREQUENCY:
Technology Reporting Plan: Upon Contracting Officer’s request.
Disclosure of Invention and New Technology (NF1679): For each reportable item as soon as it occurs or within three months of identification.
Interim NASA NTSR Form: Every 12 months.
Final NASA NTSR Form: Immediately or within three months after completion of contracted work.
Final Payment is contingent upon submission of the Final NTSR.
13. REMARKS: Copies of NF1679 and the NASA NTSR Form (Interim and Final) may be obtained and/or completed at: https://invention.nasa.gov/.
INTERRELATIONSHIP: 52.227-11 Patent Rights – Ownership by the Contractor AS modified by NASA FAR Supplement 1852.227-11 1852.227-70 New Technology - Other Than a Small Business Firm or Nonprofit Organization
14. DATA PREPARATION INFORMATION:
14.1 SCOPE: The Technology Reports should include sufficient technical detail as is necessary to identify and fully describe a "Reportable Item." Per NFS 1852.227-70, New Technology-Other Than a Small Business Firm or Nonprofit Organization, "Reportable Item" means any invention, discovery, improvement, or innovation of the contractor, whether or not the same is or may be patentable or otherwise protectable under Title 35 of the United States Code, conceived or first actually reduced to practice in the performance of any work under this contract or in the performance of any work that is reimbursable under any clause in this contract providing for reimbursement of costs incurred prior to the effective date of this contract.
14.2 APPLICABLE DOCUMENTS:
NPR 7500.2, NASA Technology Transfer Requirements
J-1-8
DRD Continuation Sheet TITLE: Technology Reports DRD NO.: CD-001
DATA TYPE: 3 PAGE: 2/3
15. DATA PREPARATION INFORMATION (CONTINUED):
14.3 CONTENTS: The Technology Reports consist of:
a. Disclosure of Invention and New Technology (Including Software): In accordance with NFS 1852.227-70 (e) (2), New Technology, the disclosure to the agency shall be in the form of a written report and shall identify the contract under which the reportable item was made and the inventor(s) or innovator(s). It shall be sufficiently complete in technical detail to convey a clear understanding, to the extent known at the time of the disclosure, of the nature, purpose, operation, and physical, chemical, biological, or electrical characteristics of the reportable item.
The disclosure shall also identify any publication, on sale, or public use of any subject invention and whether a manuscript describing such invention has been submitted for publication and, if so, whether it has been accepted for publication at the time of disclosure. In addition, after disclosure to the agency, the contractor shall promptly notify the agency of the acceptance of any manuscript describing a subject invention for publication or of any on sale or public use planned by the contractor for such invention. This reporting requirement may be met by completing NF1679, Disclosure of Invention and New Technology (Including Software), (latest revision) online at: https://invention.nasa.gov/. Use of this form and the online system is preferred;
however, if the form is not used the following information should be provided in order to meet the reporting requirement:
1. Descriptive title.
2. Innovator(s) name(s), title(s), phone number(s), and home address(es).
3. Employer when innovation made (name and division).
4. Address (place of performance).
5. Employer status (e.g., Government, college or university, non-profit organization, small business firm, large entity).
6. Origin (e.g., NASA grant number, NASA prime contract number, subcontractor, joint effort, multiple contractor contribution, other).
7. NASA COR.
8. Contractor/grantee New Technology Representative.
9. Brief abstract providing a general description of the innovation:
(a) Description of the problem or objective that motivated the innovation’s development.
(b) Technically complete and easily understandable description of innovation developed to solve or meet the objective.
(c) Unique or novel features of the innovation and the results or benefits of its application.
(d) Speculation regarding potential commercial applications and points of contact
(including names of companies producing or using similar products).
10. Additional documentation.
11. Degree of technological significance (e.g., modification of existing technology, substantial advancement in the art, major breakthrough).
12. State of development (e.g., concept only, design, prototype, modification, production model, used in current work).
13. Patent status.
14. Dates or approximate time period during which this innovation was developed.
15. Previous or contemplated publication or public disclosure including dates.
16. Answers to the following questions (for software only):
(a) Using outsiders to beta-test code? If yes, done under beta-test agreement?
(b) Modifications to this software continue by civil servant and/or contractual agreement?
(c) Previously copyrighted (if so, by whom?)?
(d) Were prior versions distributed (if yes, supply NASA or contractor contract)?
J-1-9
DRD Continuation Sheet TITLE: Technology Reports DRD NO.: CD-001
DATA TYPE: 3 PAGE: 3/3
15.3 CONTENTS: (CONTINUED)
(e) Contains or is based on code owned by a non-federal entity (if yes, has a license for use been obtained?)?
(f) Has the latest version been distributed without restrictions as to use or disclosure for more than one year (if yes, supply date of disclosure)?
17. Name(s) and signature(s) of innovator(s).
Interim NASA NTSR: This report shall consist of a listing of reportable items for the reporting period or certification that there are none. This report shall also contain a list of subcontracts containing a patent rights clause or certification that there were no such subcontracts.
Completion of the Interim NTSR shall satisfy this reporting requirement. Use of the form utilizing the online system at https://invention.nasa.gov/ is preferred; however, an alternate format is acceptable provided all required information is provided.
c. Final NASA NTSR: This report shall consist of a comprehensive list of all reportable items for the contract duration or certification that there are none. This report shall also contain a list of subcontracts containing a patent rights clause or certification that there were no such subcontracts. Completion of the Final NTSR shall satisfy this reporting requirement. Use of the form utilizing the online system at https://invention.nasa.gov/ is preferred; however, an alternate format is acceptable provided all required information is provided.
d. Subcontracts: The contractor shall provide copies of subcontracts containing a patent rights clause upon Contracting Officer’s request.
15.4 FORMAT: The Disclosure of Invention and New Technology (Including Software) report may use
NF1679, Disclosure of Invention and New Technology (Including Software), (latest version) or the online system at: https://invention.nasa.gov/ or provide sufficient information to meet the reporting requirement.
The interim and final NASA New Technology Summary Reports may use the NTSR Form (Interim or Final whichever is applicable) utilizing the online system at: https://invention.nasa.gov/ or provide sufficient information to meet the reporting requirement.
15.5 MAINTENANCE: None required
J-1-10
1. ISSUE: DRAFT 2. DRD NO.: MA-001
3. DATA TYPE: 1 4. DATE REVISED:
TITLE: Contract Management Plan (CMP)
5. PAGE: 1/2
7. DESCRIPTION/USE: To document the Contractor's overall contract management approach and organization for accomplishing the contract requirements.
8. OPR: OCIO 9. DM: CSPP
10. DISTRIBUTION: Electronic submission to Government-provided database; COR; Contracting Officer
11. INITIAL SUBMISSION: Due 30 calendar days after contract effective date in which will be incorporated under Clause J1 and Attachment K.
12. SUBMISSION FREQUENCY: Submit revisions for Government approval after any major change in management organization and approach.
13. REMARKS: This is the contractor’s summary of their management approach and its relationship to their organization.
14. INTERRELATIONSHIP: PWS Section 2.1, Program Management; CMP will be attached to
Section J.
15. DATA PREPARATION INFORMATION:
15.1 SCOPE: The CMP describes the contractor's summary concept plans, practices, and approach for accomplishing the requirements set forth in the contract, i.e., managing and controlling tasks, experimental work, and management interfaces. The plan shall be in such detail as necessary to convey the Contractor's internal procedures.
15.2 APPLICABLE DOCUMENTS: NPR 2800.1, Managing Information Technology
15.3 CONTENTS: The Management Plan shall include the following:
a. The contractor shall describe the overall proposed contract management approach, strategies, policies, processes for work planning, subcontractor management, and indirect cost management including any efficiencies proposed. This description shall include a description of the organizational structure and elements, including a chart depicting the organization and the overall rationale for this approach.
b. Describe the management relationships between the contractor’s key personnel and associated NASA personnel, including communication channels, lines of authority (including the line of succession if Program Manager is unavailable), reporting relationships, and responsibilities of all organizational elements. Include in this discussion any subcontractors, team members, or joint venture partners, to illustrate their relationships within the structure or between the organizational elements and any other subcontractors, team members, or joint venture partners.
Describe the reporting responsibilities of the Program Manager to corporate management and the relationship between the Program Manager and the prime’s corporate management as well as the management of any subcontractors, team members, or joint venture partners. Describe the overall authority of the Program Manager to make decisions independent of corporate management.
J-1-11
DRD Continuation Sheet TITLE: Contract Management Plan DRD NO.: MA-001
DATA TYPE: 1 PAGE: 2/2
c. Recruitment and employment methods and policies including any special provisions your company has regarding hiring incumbent employees. Strategy to ensure personnel will maintain the minimum qualification standards described in the Standard Labor Category guidelines.
d. Approach to providing flexible workforce planning. Include discussion on recruiting;
communication of promotion opportunities; retention of personnel; and the effects on management, subcontractors, continuity and quality of services, and other factors resulting from changes in staffing levels.
e. Describe the staffing location plans, including lease arrangements, for the contractor’s off-site facilities including a discussion of the on-site and off-site approach. Discuss any other issues related to logistics management.
f. A description of risks anticipated in successful performance of the SOW requirements. Include the decision to accept, mitigate, or other action for each risk and include the rationale for each.
g. The methods to ensure timely delivery of quality services. Describe how the contractor will ensure the Government will receive the services ordered by providing the method, level and frequency of internal surveillance. Describe how the management policies, procedures, and techniques are monitored to ensure their effectiveness and facilitate continuous improvement.
Describe the methods of identifying deficiencies and plans for correcting deficiencies. Describe the process for Management reviews/status reviews to NASA management.
h. Describe the process for the coordination and execution of all contract technical and administrative tasks, and how the contractor’s technical personnel (individuals and line managers) will interact with NASA line management. Process of setting goals and establishing policies, practices, procedures, and organizational structure to support the NASA CIO and NASA IT Governance processes, as defined in NPR 2800.1, Managing Information Technology.
i. Process of setting goals and establishing policies, practices, procedures, and organizational structure to support accomplishment of CyPrESS’s objectives. As a minimum, this includes both transition and transformation management.
j. Process for identification and resolution of as a minimum problems, issues, and weaknesses.
k. Discuss strategies/approach to ensure that the contractor can facilitate a proactive and efficient close out of the contract at contract end in as short a time as practicable including but not limited to possible use of the Quick Closeout procedures of FAR 42.708, NFS 1842.708 and 1842.708- 70.
15.4 FORMAT: Contractor format is acceptable (not to exceed twenty (20) pages in Times New Roman
12 font, paper size 8-1/2 x 11).
15.5 MAINTENANCE: The Contractor may revise the CMP at any time or at the direction of the Contracting Officer. Revisions to the CMP are subject to Contracting Officer review and approval.
Changes shall be incorporated as required by or complete reissue.
J-1-12
1. ISSUE: DRAFT 2. DRD NO.: MA-002
TITLE: Contract Phase-In Plan
7. DESCRIPTION/USE: To describe activities planned to transition from the processes and services as defined at contract start to those accepted by the Government during the proposal and contract award process.
10. DISTRIBUTION: COR
11. INITIAL SUBMISSION: Due at time of proposal submission in which will be incorporated under Clause
J1 and Attachment N.
12. SUBMISSION FREQUENCY: N/A
13. REMARKS: None
14. INTERRELATIONSHIP: PWS Section 2.2, Contract Administration System; PWS Section 2.3, Critical Staffing; Phase-In Plan will be attached to the contract in Section J.
15. DATA PREPARATION INFORMATION: None
15.1 SCOPE: This plan defines tasks, schedule, responsibilities, and agreements for both the contractor and the Government, necessary to transition from the processes and services as defined at contract start to those accepted by the Government during the proposal and contract award process. The results of the accepted processes and services shall be contained in the Model Contract. The total time allocated for the implementation of the transition of processes and services shall not exceed 60 calendar days from phase-in start.
15.2 APPLICABLE DOCUMENTS: None
15.3 CONTENTS: The Phase-in Plan shall address, as a minimum, the following:
a. Describe in detail the plan for maintaining continuous and efficient operations at NASA. Describe how you will work with incumbent Contractors and NASA, including resources and interfaces expected from each to ensure an effective transition and continuous service.
b. Provide an innovative phase-in schedule which will accomplish all proposed phase-in steps/milestones within the 60-day phase-in period, while minimizing cost and maximizing efficiency.
c. Include the personnel responsible for the steps/milestones. Describe your approach for how you will implement the schedule.
d. Provide details for initial staffing and training of personnel, including the percentage of incumbent personnel that you plan to hire. Discuss proposed key personnel, if applicable and demonstrate that the key personnel are committed to employment prior to start of contract.
e. Address the office space that is required for phase-in, beyond what is to be provided by the Government, if any.
J-1-13
TITLE: Phase-In Plan DRD NO.: MA-002
15. DATA PREPARATION INFORMATION (CONTINUED):
15.3 CONTENTS (CONTINUED):
f. Approach for ensuring completion of badging requirements and personnel security clearances to ensure employees are cleared for access to NASA and associated facilities, as required, prior to start of the contract.
g. Describes how an inventory will be performed with the Incumbent Contractor(s) of all records that will be transitioned. Records transition shall be completed at contract start.
h. Describe your approach and risk mitigation strategies to identify any requirements for application or system connectivity or integration with NASA.
i. Address property control transfer, including schedule and milestones for completing 100% inventory including but not limited to Government Furnished Property and Installation Accountable Government Property.
j. Identify the risks associated with your plan and ways to mitigate those risks.
15.4 FORMAT: Submitted electronically; MS Word
J-1-14
1. ISSUE: DRAFT 2. DRD NO.: MA-003
3. DATA TYPE: 2 4. DATE REVISED:
TITLE: Information Technology Security Management Plan
7. DESCRIPTION/USE: To describe the Contractor’s methodology for managing all aspects of cybersecurity support, including addressing the cross-functional and service-specific cybersecurity requirements.
10. DISTRIBUTION: Contracting Officer; COR
11. INITIAL SUBMISSION: 30 calendar days after effective date of the contract.
12. SUBMISSION FREQUENCY: Annual update as required.
14. INTERRELATIONSHIP: As applicable throughout the PWS; 1852.204-76 Security Requirements for
Unclassified Information Technology Resources; IT Security Management Plan will be attached to Section J.
15.1 SCOPE: The Information Technology Support Management Plan provides the Contractor’s proposed management approach for meeting cross-functional and service-specific cybersecurity requirements.
15.3 CONTENTS: The Information Technology Support Management Plan shall include, at a minimum, the following:
a. Contractor’s cybersecurity support POC(s) and roles and responsibilities for the POC(s).
b. Proposed grouping of information systems supported under the contract into IT System Security
Plans (IT SSP) in the NASA system of record in accordance with NASA policy and FIPS 199 security category of each information system.
c. Process for meeting security authorization requirements, including development and maintenance of IT SSPs, implementation and validation of controls, remediation, authorization, continuous monitoring, etc.
d. Processes for addressing all applicable cybersecurity requirements, including patch requirements and mitigation, maintaining secure system configurations, patch/configuration management and reporting, malware protection.
e. Process for information security incident identification and response, including coordination with NASA Security Operations Center (SOC),Center Chief Information Security Officer (CISO) and Incident Response Managers.
f. Process for providing required data to the NASA SOC.
g. Process for ensuring that Contractor employees meet Cybersecurity and Privacy Program requirements, such as Cybersecurity Awareness training, qualifications for system
J-1-15 administrators, TITLE: Information Technology Security Management Plan DRD NO.: MA-003
DATA TYPE: 2 PAGE: 2/2
15. DATA PREPARATION INFORMATION (CONTINUED):
15.3 CONTENTS (CONTINUED):
security clearance requirements, and others with elevated privileges, etc., and that Contractor employees are knowledgeable of NASA Cybersecurity policies and procedures.
15.4 FORMAT: Contractor format is acceptable with NASA approval.
15.5 MAINTENANCE: Annual updates as required.
J-1-16
1. ISSUE: DRAFT 2. DRD NO.: MA-004
6. TITLE: Information Technology (IT) System Security Plan (SSP)
7. DESCRIPTION/USE: To provide the Contractor’s compliance with the Cybersecurity requirements in NFS 1852-204-76, Security Requirements for Unclassified Information Technology Resources, and any additions/ augmentations described in NPR 2810.1E, Security of Information Technology and NASA Cybersecurity policy, standards and handbooks. These documents will be used as part of the NASA Cybersecurity assessment and authorization process and to identify IT system inventories and appropriate Contractor Cybersecurity support points of contact.
10. DISTRIBUTION: CO; COR
11. INITIAL SUBMISSION: As required by the NASA Assessment and Authorization process, in coordination with the information system’s NASA authorizing official and OCSS.
12. SUBMISSION FREQUENCY: The IT SSP shall be reviewed and updated in the NASA system of record on a continual basis to include any contractor personnel point of contact (POC) information changes. The SSP will be resubmitted for ATO at least annually and/or after any significant changes to the IT System. Updated copies shall be documented in the NASA system of record, upon any significant changes or annually.
13. REMARKS: All System Security Plans and their supporting artifacts must be submitted through the RISCS system.
14. INTERRELATIONSHIP: As applicable throughout the PWS; 1852.204-76 Security Requirements for Unclassified Information Technology Resources
15.1 SCOPE: The Information Technology (IT) System Security Plan includes a description of the IT system, network and data flow diagrams, ports protocols and services used, hardware and software lists and its implementation of security controls, risk assessment, self-assessment of security plans, and contingency plan, in compliance with NIST SP 800-18, Guide for Developing Security Plans for Federal Information Systems, and NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations and NASA CSPP policy, standards and handbooks.
15.2 APPLICABLE DOCUMENTS:
FIPS 200 Minimum Security Requirements for Federal Information and Information Systems
FIPS 199 Standards for Security Categorization of Federal Information and Information Systems
NPR 2810.1A Security of Information Technology NIST SP 800-18 Guide for Developing Security Plans for Federal Information Systems NIST SP 800-30 Guide for Conducting Risk Assessments
J-1-17
TITLE: Information Technology (IT) System Security Plan (SSP) DRD NO.: MA-004
DATA TYPE: 1 PAGE: 2/2
15.2 APPLICABLE DOCUMENTS (CONTINUED):
NIST SP 800-34 Contingency Planning Guide for Information Systems NIST SP 800-61 Computer Security Incident Handling Guide NIST SP 800-37 Risk Management Framework for Information Systems and Organizations:
A System Life Cycle Approach for Security and Privacy ITS-HBK 2810.02.02-E Security Assessment and Authorization: Information System Security
Assessment and Authorization Process ITS-HBK 2810.02-05 Security Assessment and Authorization External Systems ITS-HBK 2810.02-08 Security Assessment and Authorization: Plan of Action Milestones IT-SOP 2810.02-01 Internal Information Assurance (A&A) Review NIST SP 800-53 Security and Privacy Controls for Federal Information Systems and
Organizations NIST SP 800-53A Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans
15.2 CONTENTS: The Information Technology (IT) System Security Plan shall include the following:
a. The IT System Security Plan shall be written in accordance with NFS 1852.204-76, Security
Requirements for Unclassified Information Technology Resources, NASA ITS Handbooks, and NIST SP 800-18, Guide for Developing Security Plans for Federal Information Systems, and following the process defined in NIST SP 800-37, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy. It should also address all the required security controls defined in the latest revision of the NIST SP 800- 53, Security and Privacy Controls for Federal Information Systems and Organizations, based upon the security categorization (per FIPS 199, Standards for Security Categorization of Federal Information and Information Systems).
b. Risk Assessment: The IT Risk Assessment report shall be written in accordance with NFS 1852.204-76, Security Requirements for Unclassified Information Technology Resources, and following the guidelines of NIST SP 800-30, Guide for Conducting Risk Assessments.
c. Self-Assessment: The self-assessment shall be conducted and provided in the format defined by NIST SP 800-53A, Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans.
d. Contingency Plan: The IT Contingency Plan shall be written in accordance with NASA policy as well as NFS 1852.204-76, Security Requirements for Unclassified Information Technology Resources, and following the guidelines of NIST SP 800-34, Contingency Planning Guide for Information Systems.
15.3 FORMAT: Contractor format is acceptable following guidelines listed in 15.3.
15.4 MAINTENANCE: Changes shall be incorporated by change page or complete reissue.
J-1-18
1. ISSUE: DRAFT 2. DRD NO.: MA-007
TITLE: Application Inventory Report
5. PAGE: 1/1
7. DESCRIPTION/USE: To collect and provide an inventory of applications being used to support NASA services.
11. INITIAL SUBMISSION: 120 calendar days after effective date of the contract.
12. SUBMISSION FREQUENCY: Annually or as needed.
13. REMARKS:
14. INTERRELATIONSHIP: As applicable throughout the PWS.
15.1 SCOPE: The Application Inventory Report includes all applications being used to support
NASA services.
15.3 CONTENTS: The Application Inventory Report shall include, at a minimum, the following:
a. Application Name (as documented in the NASA Application Repository).
b. Unique Application ID (as documented in the NASA Application Repository).
c. Application Owner (responsible NASA government official).
d. Technical POC for the application (individual with the most technical knowledge about the application, i.e., government or contractor).
e. Application description/services provided.
f. Total Annual Cost: development, maintenance, enhancement or steady state to include:
1. Total hardware costs e.g., server(s), storage, upgrades, application specific hardware devices.
2. Total software licensing/purchase fees.
3. Total recurring maintenance and support agreement fees.
4. Total application data center hosting costs e.g., infrastructure, facilities, HVAC, power, labor.
5. Total contractor work year equivalent cost (required to directly support the application).
15.5 MAINTENANCE: Update annually to maintain current with program changes.
J-1-19
1. ISSUE: DRAFT 2. DRD NO.: MA-008
TITLE: Capacity Management Plan
7. DESCRIPTION/USE: To describe the Contractor’s methodology and approach for managing capacity and associated performance issues.
10. DISTRIBUTION: CO; COR, CSPP Service Element Managers (SEM)
11. INITIAL SUBMISSION: Draft 60 calendar days after effective date of the contract.
12. SUBMISSION FREQUENCY: Preliminary 120 calendar days after effective date of the contract;
baseline 180 calendar days after effective date of the contract; update as required.
15.1 SCOPE: The Capacity Management Plan describes the Contractor’s methodology and approach for managing capacity and associated performance issues.
15.3 CONTENTS: The Capacity Management Plan shall include, at a minimum, the following:
a. Process for identifying service and component capacity including trends and profiles.
b. Process for recommending effective use of existing capacity.
c. Standard templates to support capacity planning.
d. Process for coordinating and collaborating with Government, Enterprise Services contractors, and other contractors, to support capacity planning.
e. Process for providing advice on new technologies.
f. Process for notifying the Enterprise Service Desk regarding potential issues.
15.5 MAINTENANCE: Changes shall be incorporated by complete reissue. Update as required to maintain current with program changes.
J-1-20
1. ISSUE: DRAFT 2. DRD NO.: MA-009
TITLE: Service and Component Capacity Report
7. DESCRIPTION/USE: To collect and provide service and component capacity data showing trends and utilization.
10. DISTRIBUTION: COR, CSPP Service Element Managers (SEM)
11. INITIAL SUBMISSION: 10 business days following completion of the first monthly reporting period.
12. SUBMISSION FREQUENCY: Monthly within 10 business days after the end of each calendar month.
15.1 SCOPE: The Service and Component Capacity Report provides monthly data showing capacity utilization, volumes, and historical trends against forecast and baselines.
15.3 CONTENTS: The Service and Component Capacity Report shall provide statistics for the current month as well as the two (2) previous months and shall be reported by PWS location, (NASA location as applicable) and as a total for NASA. The report shall include, at a minimum, the following:
a. Results of performance monitoring, service capacity analysis, and service performance tuning.
b. Current, historical, and projected capacity thresholds.
c. Reporting against Government-established standards and metrics.
d. Results of formal reviews of projected capacity requirements.
e. Capacity and performance trends and volumes against forecasts and baselines.
f. Results of prototyping and sizing exercises.
g. Testing and sizing models for capacity impacts.
15.4 FORMAT: SEM to provide format for all reports.
15.5 MAINTENANCE: None required.
J-1-21
1. ISSUE: DRAFT 2. DRD NO.: MA-010
6. TITLE: Information Technology (IT) Service Continuity Management (SCM) Plan
7. DESCRIPTION/USE: To describe the Contractor’s method for establishing and maintaining ongoing recovery capability for required IT services and their components for the SOC and the CSI organizations.
11. INITIAL SUBMISSION: Draft 60 calendar days after effective date of the contract.
12. SUBMISSION FREQUENCY: Preliminary 120 calendar days after effective date of the contract;
baseline 180 calendar days after effective date of the contract; update as required.
15.1 SCOPE: The Information Technology (IT) Service Continuity Management (SCM) Plan provides the Contractor’s proposed management approach for establishing and maintaining ongoing recovery capability for IT services and their components in accordance FISMA compliance requirements.
15.3 CONTENTS: The Information Technology (IT) Service Continuity Management (SCM) Plan shall include, at a minimum, the following:
a. Process for managing product and service continuity.
b. Process for notifying the Enterprise Service Desk regarding potential issues.
c. Process for identifying contingency options and impact mitigation actions and strategies.
d. Process for enabling the effective identification, analysis, and management of risk responses.
e. Process for development, production, testing, maintenance, and training of the plan.
g. Process, including criteria, for invoking the plan, executing recovery plans, restoring service to normal operation, and leading and/or coordinating recovery efforts.
h. Process for testing and documenting results of disaster recovery testing.
i. Process for identifying required contingency services that impact the required IT services.
15.5 MAINTENANCE: Changes shall be incorporated by complete reissue. Update at least annually or quarterly based on system categorization to maintain current with program changes and requirements unless otherwise directed by the COR.
J-1-22
1. ISSUE: DRAFT 2. DRD NO.: MA-013
6. TITLE: Problem Documentation
7. DESCRIPTION/USE: To provide documentation, scripts, and procedures for the Enterprise Service Desk to facilitate the resolution of problems.
11. INITIAL SUBMISSION: 30 calendar days prior to operational change to CyPrESS
Tier 2 documentation, knowledge articles, and procedures that interface with the ESD.
12. SUBMISSION FREQUENCY: As required.
13. REMARKS: The documentation, scripts and procedures shall be fully developed, documented, and tested prior to release in accordance with ITIL (current version) Change, Release, and Deployment processes.
15.1 SCOPE: The Problem Documentation applies to all cross-functional and service-specific problems.
15.3 CONTENTS: The Problem Documentation shall include, at a minimum, the following:
a. Documentation:
1. Problem description.
2. Problem characteristics/key indicators that enable quick identification.
3. Actual/potential applicability and resolution guidance once problem determination is made.
b. Scripts: Specific guidance for Enterprise Service Desk or end user to enable the identification/ determination and resolution of recurring problems.
c. Procedures: Step-by-step guidance for identifying, assigning resolution responsibility and resolving the problem.
15.4 FORMAT: For Tier 0 input, the ESD will define the format. For other input, contractor format is acceptable with NASA approval.
15.5 MAINTENANCE: Changes shall be incorporated by change page or complete reissue. Update as required to maintain current with program changes.
J-1-23
1. ISSUE: DRAFT 2. DRD NO.: MA-018
TITLE: Annual Work Plan (AWP)
7. DESCRIPTION/USE: The AWP shall detail the Contractor’s overall approach to meet the PWS requirements associated with the successful accomplishment of program/project goals, objectives, and milestones. It reflects the most efficient operational approach within and across the PWS sections.
8. OPR: OCIO
9. DM: CO/COR
10. DISTRIBUTION: Electronic submission to COR and the Contracting Officer
11. INITIAL SUBMISSION: Due 30 calendar days after contract effective date.
12. SUBMISSION FREQUENCY: Submit draft plan annually by August 31st of each year with bi-annual updates or otherwise directed by the CO. The CO will provide comments within 15 days after AWP submission. The Contractor shall submit the final plan within 15 days after receipt of CO comments. The Contractor shall submit the final plan no later than September 30th.
13. REMARKS: The AWP is intended to be a flexible working document, incorporating changes throughout the year (with COR concurrence, and CO approval) to accommodate emerging mission and customer requirements in addition to existing requirements. Government personnel and Contractor will continuously collaborate and coordinate on changes to the AWP to ensure a clear understanding of the requirements, the division of roles and responsibilities, and the content that will be included in the AWP.
14. INTERRELATIONSHIP: PWS Section 2.0, Contract Management
15.1 SCOPE: The AWP defines and integrates contract work activities and requirements across the contract, including subcontractor efforts. The Contractor shall develop the AWP and changes thereto in coordination and collaboration with appropriate NASA personnel associated with the contract including, but not limited to, the Contracting Officer (CO), Contracting Officer’s Representative (COR), Technical Monitors (TMs), and Technical Points of Contact (POCs). The plan ensures focus is placed on defining the requirements and matching those requirements to projected funding levels.
15.3 CONTENTS: The Annual Work Plan shall include the following:
a. Describe the overall approach to develop workforce plan and resource allocations
b. Annual staffing plan associated with projected workloads, including information regarding skill mixes, staffing levels, and distribution of Contractor workforce across Work Packages and Task Orders
J-1-24
TITLE: Annual Work Plan DRD NO.: MA-018
c. Management approach (including the criteria, methods, and procedures) for identifying, analyzing, planning, tracking, mitigating, controlling, communicating, and documenting contract related risks associated with contract administration; and performance of Base Contract Requirements and TOs
d. Approach to implementing new skills within the workforce to align with requirements
e. Approach to maintaining core capabilities and knowledge to meet future requirements
f. Impact of requirements changes
g. Projected metrics and objectives to demonstrate continuous process improvement/innovation
15.4 FORMAT: The submissions will the following:
AWP Submission (Microsoft Word Document) Provides management and organization structure Outlines approach to annual staffing, resource allocation, and management processes Provides analyses, assumptions, and risks due to dynamic nature of NASA missions
AWP Supplemental Submission (Excel Document) Outlines workforce planning Detailed plan at summary level down to individual Work Packages Outlines anticipated ODCS (Travel, material & equipment)
16. MAINTENANCE: The Contractor may revise the AWP at any time or at the direction of the Contracting Officer. Revisions to the AWP are subject to the review and concurrence of the COR and CO’s approval. Changes shall be incorporated as required by or complete reissue.
J-1-25
1. ISSUE: DRAFT 2. DRD NO.: MA-019
3. DATA TYPE: 2/3 4. DATE REVISED:
6. TITLE: Export Control Plan and Reports
7. DESCRIPTION/USE: To provide the contractor’s plan for complying with Agency and Center level export control requirements and reports of export control activities by Contractor and Subcontractors.
11. INITIAL SUBMISSION: Electronically within 10 calendar days of effective date of the contract.
12. SUBMISSION FREQUENCY: Make recommendations for update to the Export Control Plan within 30 calendar days of changes found during annual review and changes in Contractor and/or Agency/Center policy; submit reports monthly.
13. REMARKS: *The plan is Data Type 2. The reports are Data Type 3.
14. INTERRELATIONSHIP: As applicable throughout the PWS. 1852.225-70 Export Licenses
15.1 SCOPE: The Export Control Plan and Reports provides export control processes and procedures and the report details export control activities.
NPD 2190.1B NASA Export Control Program NPR 2190.1C NASA Export Control Program NPR 2810.2 Use of NASA Information and Information Systems while Outside of the
U.S. and Territories MPR 2190.1A MSFC Export Control Program NAII 2190.1E NASA Export Control Program Operations Manual 15 CFR Parts 730-799 Export Administration Regulations (EAR) 22 CFR Parts 120-130 International Traffic in Arms Regulations (ITAR)
15.3 CONTENTS: The Export Control Support Plan and Reports shall include the following:
a. The plan shall be submitted via encrypted email in Word format (to allow edits) with final (for signature in pdf format). Changes shall be incorporated by change page or complete reissue. The plan shall detail:
i. The contractor’s plan for supporting the export control local requirements of NASA systems and data to include the Export Administration Regulations (EAR), the International Traffic and Arms (ITAR), NFS 1852.225-70, Export Licenses; NPD 2190.1B, NASA Export Control Program; NPR 2810.2 Use of NASA Information and Information Systems while Outside of the U.S. and Territories; MPR 2190.1A, MSFC Export Control Program; and NAII 2190.1E, NASA Export Control Program Operations Manual.
ii. Title, contract number, preparer, approver(s), revision with date, page numbers, table of contents, list of applicable definitions, revision history, introduction, and scope.
J-1-26
DRD Continuation Sheet TITLE: Export Control Plan and Reports DRD NO.: MA-019
15.3 CONTENTS (CONTINUED):
iii. The support processes and procedures that are functionally able to address the elements of export control including, NASA systems; NASA data; software release; foreign visitors/ workers; scientific and technical information release; hardware; shipments; internet and web page information; and US Postal services, facsimile, and electronic mail information exchange.
iv. The support processes and procedures which are functionally able to address any issues and incidents related to NASA support systems and training of all personnel on export control processes and procedures. Definition of periodic checks for compliance to requirements and process to assure non-conformance are identified and remedied with follow-up to assure remedies are effective describe how the Contractor shall support and provide a…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .