Attachment F - IT Security Applicable Documents List.pdf
PDF 136 KB Posted
- Attached to
- Sounder for Microwave-Based Applications (SMBA) Phase A Study Federal contract opportunity
- Solicitation number
- 80GSFC23R0008
About this file
This document contains an attachment to a federal solicitation for a study contract. The attachment lists applicable IT security documents that a contractor would need to comply with for a Sounder for Microwave-Based Applications Phase A study contract with NASA Goddard Space Flight Center. The contract is a firm fixed-price contract not to exceed $5 million with a one-year period of performance to begin on October 20, 2023. The study is for a proposed NASA/NOAA instrument named Sounder for Microwave-Based Applications that would fly on NOAA's Near Earth Object Network satellites beginning in 2031. The attachment provides a list of over 70 NASA security directives, handbooks, memoranda and technical standards the contractor must comply with, related to areas such as privacy, records management, IT security policies, software requirements and security authorization processes.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFP 80GSFC23R0008 Amendment 2.pdf | ||
| RFP 80GSFC23R0008 SMBA Phase A QA 2 (20230309).pdf | ||
| RFP 80GSFC23R0008 SMBA - Phase A - Cover Letter (Amendment 1).pdf | ||
| Attachment A - SMBA Statement of Work Revision A.pdf | ||
| RFP 80GSFC23R0008 SMBA Phase A QA 1 (20230306).pdf | ||
| RFP 80GSFC23R0008 Amendment 1.pdf | ||
| Attachment I - Contract Data Requirements List.pdf | ||
| Attachment I DRD 2- DEIA Plan.pdf | ||
| Attachment I DRD 1 - OCI Plan.pdf | ||
| RFP 80GSFC23R0008 SMBA - Phase A.pdf | ||
| Attachment C - SMBA Instrument Mission Assurance Requirements.pdf | ||
| RFP 80GSFC23R0008 SMBA - Phase A - Cover Letter.pdf | ||
| Attachment A - SMBA Statement of Work.pdf | ||
| Attachment B - SMBA Performance Specification Document.pdf | ||
| IT Security Management Plan Fillable Form V9.pdf |
Show all 15
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT F
INFORMATION TECHNOLOGY (IT) SECURITY
APPLICABLE DOCUMENTS LIST
March 2021
CONTRACT TBD
Contract TBD Attachment F
(03/2021) 2
Information Technology (IT) Security Applicable Documents List March 2021
Document Subject
NPR 1382.1 NASA Privacy Procedural Requirements
NPD 1382.17 NASA Privacy Policy
NPD 1440.6 NASA Records Management
NPR 1441.1 NASA Records Management Program Requirements
NPD 2540.1 Personal Use of Government Office Equipment Including Information Technology
NPD 2800.1 Managing Information Technology
NPR 2800.1 Managing Information Technology
NPD 2810.1 NASA Information Security Policy
NPR 2810.1 Security of Information Technology
NPD 2830.1A NASA Enterprise Architecture
NPR 2830.1A NASA Enterprise Architecture Procedures
NPR 2841.1 Identity, Credential, and Access Management
NPR 7120.7 NASA Information Technology and Institutional Infrastructure Program and Project Management Requirements
NASA Records Retention Schedules (NRRS)
NRRS 1441.1 NASA Records Retention Schedule
(03/2021) 3
ITS-HBK-1382.02-01 Privacy Goals and Objectives
ITS-HBK-1382.03-01
Privacy Risk Management and Compliance: PIAs and SORNs
ITS-HBK-1382.03-02
Privacy Risk Management and Compliance: Annual Reporting Procedures for Reviewing and Reducing Personally Identifiable Information (PII) and Eliminating the Unnecessary Use of SSN
ITS-HBK-1382.04-01 Privacy and Information Security: Overview
ITS-HBK-1382.05-01
Privacy Incident Response and Management: Breach Response Team
ITS-HBK-1382.06-01
Privacy Notice and Redress: Web Privacy & Written Notice, Complaints, Access and Redress
ITS-HBK-1382.07-01 Privacy Awareness and Training: Overview
ITS-HBK-1382.08-01 Privacy Accountability: Overview
ITS-HBK-1382.09-01 Privacy Rules of Behavior and Consequences: Overview
ITS-HBK-2810.002-1
Format and Procedures for an IT Security Policies and Handbooks
ITS-HBK-
1441.01.01
Records Retention and Disposition: Overview
ITS-HBK-
1440.01.01
Records Planning & Management: Records
IT-HBK-2841.003 Identity, Credential, and Access Management (ICAM)
ITS-HBK-2810.02-01 Security Assessment and Authorization
ITS-HBK-2810.02-02
Security Assessment and Authorization: Information System Security Assessment and Authorization Process
ITS-HBK-2810.02-04
Security Assessment and Authorization: Continuous Monitoring – Annual Security Control Assessments
(03/2021) 4
ITS-HBK-2810.02-05 Security Assessment and Authorization: External Information Systems
ITS-HBK-2810.02-06
Security Assessment and Authorization: Extending and Information Systems Authorization to Operate Process and Templates
ITS-HBK-2810.02-08
Security Assessment and Authorization: Plan of Action and Milestones (POA&M)
ITS-HBK-2810.03-02 Planning
ITS-HBK-2810.04-01
Risk Assessment: Security Categorization, Risk Assessment, Vulnerability Scanning, Expedited Patching & Organizationally Defined Values
ITS-HBK-2810.05-02 Systems and Service Acquisition
ITS-HBK-2810.06-02 IT Security Awareness, Training, and Education
ITS-HBK-2810.07-02 Configuration Management
ITS-HBK-2810.08-01 Contingency Planning
ITS-HBK-2810.09-01 Incident Response and Management
ITS-HBK-2810.09-02 NASA Information Security Incident Management
ITS-HBK-2810.09-03 Collection of Electronic Data
ITS-HBK-2810.09-04
Incident Response and Management: Guidelines for Data Spillage & Sanitization Procedures
ITS-HBK-2810.10-02 Maintenance
ITS-HBK-2810.11-2 Media Protection and Sanitization
ITS-HBK-2810.12-02 Physical and Environmental Protection
ITS-HBK-2810.13-01 Personnel Security
ITS-HBK-2810.14-03 System and Information Integrity
ITS-HBK-2810.15-01 Access Control
ITS-HBK-2810.15-02 Access Control: Elevated Privileges (EP)
(03/2021) 5
ITS-HBK-2810.16-02 Audit and Accountability
ITS-HBK-2810.17-02 Identification and Authentication
ITS-HBK-2810.18-02 System and Communications Protection
ITS-HBK-2810.19.01 Operational Technology
ITS-HBK-2810.002-1 Format and Procedures for IT Security Policies and Handbooks: Privacy, Security & Sensitive Information
NASA-STD-2804 Minimum Interoperability Software Suite
NASA-STD-2805 Minimum Hardware Configurations
(03/2021) 6
Memoranda
From To Subject Date
Office of the Chief Information Office
Distribution Annual Cybersecurity and Sensitive Unclassified Information Awareness Training
September 14, Chief Information Officer, Office of Procurement, and Office of Protective Services
Officials in Charge, Center Directors, CIOs, CISOs
Your Role in Protecting NASA: Ensuring No Use of Prohibited IT/Telecommunications Services or Equipment at NASA
August 26, 2020
NASA Administrator NASA Workforce Web Site Modernization and Enhanced Security Protocols
May 15, 2019
Chief Information Officer
Distribution Authorizing Officials and Authorizing Official Designated Representatives
February 27, 2019
Chief Information Officer
Distribution Use of Personally-Owned Mobile Devices to Connect to NASA Email, Calendar and Contacts Services
October 25, 2018
Chief Information Officer
Officials-in-Charge of Headquarters Offices Directors, NASA Centers
Use of Unauthorized Devices April 16, 2018
Administrator Officials-in-Charge of Headquarters Offices Directors, NASA Centers
Updated Guidance for Traveling Abroad with NASA IT Assets
May 17, 2017
Administrator Officials-in-Charge of Headquarters Offices Directors, NASA Centers
Managing Software in Support of NASA’s Mission
May 5, 2017
Chief Information Officer
Distribution NASA Federal Source Code Framework November 7, 2016
Chief Information Officer
Center Chief Information Officers, Associate CIO for Enterprise Services
Remediating Vulnerabilities in Unsupported or End of Life Software
March 30, 2016
(03/2021) 7
ACIO for Information Technology Security Division, ACIO for Enterprise Services and Integration Division
Distribution NASA Transport Layer Security (TLS) Implementation and Certificate Requirements
March 17, 2016
Chief Information Officer
Distribution Establishment and Maintenance of Secure Communications
February 28, 2014
Reminder: Within 30 days after contract effective date, the Contractor shall develop and deliver an IT Security Management Plan to the Contracting Officer for approval.
File details come from the government source that posted it. Updated .