Attachment J - DRDs.pdf
PDF 414 KB Posted
- Attached to
- Program and Analysis Control (PAAC VI) Support Services - Final Request for Propopsal (RFP) Federal contract opportunity
- Solicitation number
- 80GSFC24R0042
About this file
This document is an Attachment J Data Requirements Description (DRDs) for NASA Goddard Space Flight Center's Program and Analysis Control (PAAC VI) Support Services contract. The file contains three detailed Data Requirements Descriptions (DRDs) outlining specific reporting and compliance requirements for potential contractors: 1) Organizational Conflicts of Interest (OCI) Plan, 2) Security Requirements for Unclassified IT Resources, and 3) Commercial Information Technology Authorizations Report (CITAR).
The DRDs establish comprehensive requirements for contractors, including mandatory processes for identifying and resolving organizational conflicts of interest, detailed IT security protocols, cybersecurity supply chain risk management, employee training, and monthly reporting of IT procurement activities. The contract is an 8(a) set-aside competitive acquisition for a Single Award Indefinite Delivery Indefinite Quantity (IDIQ) contract with a 5-year ordering period, supporting NASA Headquarters, Langley Research Center, and Goddard Space Flight Center with Project Planning and Control, Financial Services, and associated functions. Contractors must submit various plans and reports electronically, with specific training, certification, and compliance requirements outlined in each DRD.
View the file
Other files for this federal contract opportunity
Show all 50
Program and Analysis Control (PAAC VI) Support Services - Final Request for Propopsal (RFP) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT J
DATA REQUIREMENTS DESCRIPTION (DRD)
AUGUST 2024
DRFP NUMBER: 80GSFC24R0042
CONTRACT NUMBER: TBD
Data Distribution, Format, and Transmittal
Distribution: Distribution recipients and number of copies are identified within each DRD, provided within the contract, or as directed by the Contracting Officer.
Electronic Format: Electronic submission of data deliverables is preferred. Electronic deliverables shall be printable. Data deliverables shall be delivered to NASA in the format specified below unless a specific format is required by a DRD. Data submittals shall consist of a single Adobe Acrobat PDF file and the native format electronic file(s). The preferred native formats include Microsoft Word, Excel, or PowerPoint, as appropriate.
Hardcopy Format: Hardcopy of data deliverables is not required unless electronic delivery is not possible.
Transmittal: Data shall be transmitted to NASA by email or other mechanism agreed to by the Contracting Officer, Contracting Officer’s Representative (COR), and project representatives who are responsible to receive, index, and store the data deliverables.
If email is used to transmit data deliverables, the email size shall be 10 megabytes or less to ensure receipt by the NASA email servers. Encrypted email format shall be used to transmit data.
Data Transmittal Package: Each data transmittal package shall include a transmittal memorandum that specifies the following:
1. Contract number
2. Data Requirements Description (DRD) number
3. DRD data type
4. Submission date or milestone being satisfied
5. Document number and revision
6. Document title
7. File names of all files being delivered; file naming convention shall clearly identify the document being delivered
8. NASA Records Retention Schedule (NRRS) number, if applicable (See NRRS 1441.1, NASA Records
Retention Schedules)
Document Identification: For all data types, the document number, change legend, date, and title constitute the minimum identification of the specific document and shall appear on the cover and title page. The contract number shall also appear on the cover and title page as separate markings. The originator and organization shall be included on the title page. The document number, change legend, and date shall appear on each page of the document. All Type 1 documentation shall be marked “PRELIMINARY PENDING NASA APPROVAL,” and once approved shall be reissued with “APPROVED BY NASA” and the date and approval authority annotated on the cover.
Data Restriction Determination and Marking Requirements: The Contractor shall properly mark data in accordance with the data rights clause(s) included in the contract. The Contractor must make a determination for each individual data deliverable and shall not apply a default or blanket data restriction marking to all data deliverables (e.g., “data may be export restricted”). If NASA does not agree with the Contractor applied data restriction, the CO shall return the data to the Contractor, cancel the markings, or ignore the markings consistent with the procedures set forth in the “data rights” clause(s) contained in the contract.
Reference to Other Documents and Data Deliverables in Data Submittals: All referenced documents shall be made readily available to the cognizant NASA organization upon request.
Document Revisions:
Revisions of documentation previously submitted may be accomplished either by individual page revision or by a complete reissue of the document.
A document shall be completely reissued when, in the opinion of the Contractor and/or NASA, the document has been revised to the extent that it is unusable in its present state, or when directed by the CO. When complete reissues are made, the entire contents of the document shall be brought up to date and shall incorporate revised pages. All revisions shall be recorded. A revision log shall identify complete reissues except for periodic reports and documents which are complete within themselves as final.
Individual page revisions shall be made as deemed necessary by the Contractor or as directed by the CO.
Changes of a minor nature to correct obvious typing errors, misspelled words, etc., shall only be made when a substantial change is made, unless the accuracy of the document is affected.
All revised pages shall be identified by a revision identifier and a new date. Each document shall contain a log of revised pages that identify the revision status of each page with the revision symbol. This list shall follow the table of contents in each document. The line or lines revised on a given page shall be designated using vertical line in the margin of the page, and the change authority shall be indicated adjacent to the change.
CDRL/DRD MAINTENANCE PROCEDURES
NASA-Initiated Change: New and/or revised data requirements shall be incorporated by contract modification to which the new or revised portion shall be appended. The Contractor shall notify the CO in the event a deliverable data requirement is imposed and is not covered by a DRD, or when a DRD is changed by a contract modification and for which no revision is appended.
CDRL or DRD Change Procedures:
Revisions to the CDRL or DRDs will be identified by NASA in the Document Change Log. The date of the revision, DRD number, title, and revision description will be annotated in the Document Change Log. Revision descriptions will include the modification number, which implements the change, and a brief description of the portions of the CDRL and/or DRD affected within the “Revision” column of the Document Change Log.
1. DRD Title: Organizational Conflicts of Interest (OCI) Plan
2. DRD No.: DRD-001 3. Data Type: 1 4.OPR: Office of Procurement (OP)
5. Solicitation No.: 80GSFC24R0042 6. Contract No.: TBD
7. Date Issued: 8. Date Revised: 9. DRD Category:
Technical ☐
Administrative ☒
S&MA ☐
10. Description/Use: The Plan will communicate the Contractor’s approach to identify and resolve OCIs. The Contractor will be held accountable for identifying, dispositioning, and reporting OCIs during contract performance.
11. Distribution: Distribution shall be as instructed by the Contracting Officer.
Initial Submission: Plan shall be submitted with proposal.
Submission Frequency: As needed.
Format: Electronic format shall be compatible with Microsoft Office
Interrelationship: NASA Federal Acquisition Regulation (FAR) Supplement (NFS) 1852.209-71, Limitation of Future Contracting, NFS 1852.237-72, Access to Sensitive Information, NFS 1852.237-73, Release of Sensitive Information.
Applicable Documents: FAR Subpart 9.5, Organizational and Consultant Conflicts of Interest, NFS 1809.500, NASA Guide on Organizational Conflicts of Interest.
Scope: The OCI Plan describes the Contractor’s comprehensive approach to identify, avoid, mitigate, neutralize, and report potential OCI issues, including conflicts described in the solicitation and those discovered during contract performance.
Contents: The OCI Plan shall meet the requirements of FAR 9.5 and include the following:
1. Point of contact for OCI issues and reports.
2. Demonstrate an understanding of (1) OCI principles and (2) the full breadth of OCI issues and the types of harm that can result. The Plan at a minimum addresses the three primary types of OCIs (i.e., biased ground rules, unequal access to information, and impaired objectivity).
3. Define company roles, responsibilities, and procedures for (1) screening (i.e., identifying/recognizing, analyzing/evaluating, resolving, and reporting) existing and new business opportunities for actual/potential OCIs and (2) monitoring and reporting all potential/actual OCIs that arise, resolving conflicts, and reporting previously unidentified OCIs or potential OCIs to the Government.
4. Describe how employees are notified of the Plan’s requirements and how this notification will be documented. Establish and require entrance training for new employees, refresher training for existing employees, and exit training for departing employees. Describe how completion of this training will be documented, including a copy of any training certification template that the contractor will use to document that its employees have completed training.
5. Describe how the Contractor will report breaches of the protective measures in the Plan to the Contracting
Officer. Describe what processes the Contractor will implement following any breach and indicate that final resolution of the corrective action must be approved by the Contracting Officer.
6. Identify any affiliated companies/entities (e.g., a parent company or a wholly owned subsidiary) and procedures for coordinating OCIs with such affiliated companies/entities.
7. Address the process for reporting all potential/actual OCIs that arise during performance of the contract.
An OCI report shall include (1) a description of the conflict, (2) the plan for resolving the conflict, and (3) the benefits/risks to contract performance associated with plan approval/acceptance. Specific resolution strategies shall be appended to the Plan upon approval by the Government.
8. Explain how the Contractor will flow down the provisions of this Plan to any Subcontractor that may have a conflict with regard to performing the requirements of this contract. Discuss affected Subcontractors’ OCI program as it relates to this contract and specifically explain how affected Subcontractors will identify, resolve, and report actual/potential OCIs associated with this contract.
9. Define organizational and employee sanctions for violations of established OCI procedures/requirements/guidelines.
10. Include an assertion from the Contractor that to the best of their knowledge no OCIs exist currently, if applicable. Provide a list of all the Prime’s and Subcontractor’s NASA contracts and subcontracts, which would provide the Contracting Officer a better understanding of other NASA work performed by the Offeror that may give rise to an actual or potential conflict.
11. Include a requirement to update this plan as necessary to address specific OCIs. All updates to the plan must be approved by the Contracting Officer and the updates/changes must be incorporated in the contract to be effective.
12. Require periodic self-audits to ensure compliance with established OCI procedures/requirements/guidelines.
13. Define records related to the OCI plan (e.g., training and audit records) that will be made available to the Government upon request. Note: The OCI Plan as outlined in Paragraphs 1 through 12 above is not for the purpose of addressing other very important contractual obligations such as (1) the Contractor’s obligation to protect sensitive information in accordance with NFS 1852.237-72, Access to Sensitive Information,
(2) the Contractor’s obligation to conduct business in an ethical manner in accordance with FAR 52.203- 13, contractor’s Code of Business Ethics and Conduct, and (3) the Contractor’s obligation to prevent personal conflicts of interest in accordance with FAR 52.203-16, Preventing Personal Conflicts of Interest.
14. In an appendix to the OCI Plan identify the strategy (e.g., mitigation, limitation on future contracting, etc.) for resolving each OCI that is either identified in the solicitation or created by the requirements of the solicitation/contract and explain the effect of such strategy on performance of the contract. If using a firewall, explain how these actions will operate to successfully address the conflict without adversely affecting performance of the contract. (Note: Specific plans to limit future competition are reflected in the clause at NFS 1852.209-71, Limitation of Future Contracting.)
Remarks: N/A
Maintenance: The Contractor shall review the OCI Plan on an annual basis or as directed by the Contracting Officer to revise the OCI Plan if necessary. Revisions are subject to Contracting Officer approval and shall be incorporated by change page or complete reissue.
1. DRD Title: Security Requirements for Unclassified IT Resources
2. DRD No.: DRD-002 3. Data Type: 1 4. OPR: OCIO
5. Solicitation No.: 80GSFC24R0042 6. Contract No.: TBD
7. Date Issued: 8. Date Revised: 9. DRD Category:
Technical ☒
Administrative ☐
S&MA ☐
10. Description/Use: To ensure that IT security reporting requirements, including Cyber Supply Chain Risk Management (C-SCRM), are met for all IT systems utilized during work associated with this contract and necessary training requirements are fulfilled.
11. Distribution: All deliverables required by this DRD, except for the C-SCRM plan, shall be submitted electronically to the CO, COR, and NASA Organization’s Information System Security Officer (ISSO) (i.e., Security Officer). Approval will be provided by the ISSO. C-SCRM plans shall be submitted to and approved by the ICT/C- SCRM Service Element Lead at agency-dl-ocio-cys-cp-scrm@mail.nasa.gov.
Initial Submission: TBD
Information System Security and C-SCRM Plan(s): For Contractor-owned systems, due at the start of Phase-in.
Initial submission not required for existing, approved plans for Government-owned and Contractor-managed systems.
Non-Federal System Certification: Prior to any transfer of NASA non-public information to the Contractor, the Contractor shall provide documentation of the certification of the non-federal system to the security officer of the NASA organization that owns the information (typically the organization responsible for the contract).
Information on Employees in Sensitive Positions/Assignments Report: At the start of Phase-in
IT Security Point of Contact: At the start of Phase-in
IT Security Awareness Training: Training required prior to access to NASA information and systems.
IT Security Role Based Training: Foundational training is provided prior to performance of assigned role. Initial evidence showing completion due at the end of Phase-in.
Submission Frequency:
Information System Security Plan(s) and C-SCRM Plan: As Required
Non-Federal System Certification: Annually
Information on Employees in Sensitive Positions/Assignments Report: Annually
IT Security Point of Contact: As Required
IT Security Awareness Training: Annual on anniversary date of initial training
IT Security Role Based Training: Annual on anniversary date of initial training. Evidence of completion due annually.
Format: Unless otherwise directed, the data requested in this DRD shall be delivered to the Government in soft-copy via an electronic transfer mechanism (e.g., electronic mail, flash drive, or file transfer protocol) in a format readable by a Government device utilizing the standards in NASA-STD-2804, “Minimum Interoperability Software Suite.”
Interrelationship: Section 5, Security: Compliance with Security
Requirements
Applicable Documents:
FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems FAR 52.204–29, Federal Acquisition Supply Chain Security Act Orders-Representation and Disclosures FISMA 2014, Federal Information Security Modernization Act 2014 NFS 1852.204-76, Security Requirements for Unclassified IT Resources NFS 1852.223-75, Major Breach of Safety or Security NFS 1852.237-72, Access to Sensitive Information NFS 1852.237-73, Release of Sensitive Information NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations NIST SP 800-161, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations NPR 1382.1, NASA Privacy Procedural Requirements NPD 2810.1, Information Security Policy NPR 2810.1, Security of Information and Information Systems NPR 2810.7, Controlled Unclassified Information NPR 7120.7, NASA Information Technology Program and Project Management Requirements OMB Circular A-130, Management of Federal Information Resources
Scope: All contracts that purchase, lease, network to, or otherwise utilize covered articles, which includes Government-funded IT (as defined by the FAR) must comply with NASA IT Security and C-SCRM Requirements.
Contents: The Federal Information Security Modernization Act (FISMA) and Executive Branch policy require external providers that process, store, or transmit Federal information or operate information systems on behalf of the Federal Government to meet the same security and privacy requirements as Federal Agencies.
Information System Security Plan (i.e., System Security Plan, IT Security Plan, or Security Plan):
When the Contractor is operating a Federal Information System (FIS) on behalf of NASA or is providing a FIS in the execution of this contract, that system must have an Information System Security Plan in accordance with NIST Special Publication (SP) 800-53, “Security and Privacy Controls for Information Systems and Organizations” at the revision number required at the issuance of the contract. This plan and supporting documents shall be entered into the NASA cybersecurity system of record pursuant to Authorization to Operate (ATO) requirements set forth in NASA Policy Directive 2810.1, “NASA Information Security Policy” and NASA Procedural Requirement (NPR) 2810.1, “Security of Information and Information Systems.” The FIS security plan and ATO must be in place before any system may operate in the NASA environment.
Non-Federal System Security Certification:
When the Contractor will receive, process, store or transmit NASA non-public information, especially Controlled Unclassified Information (CUI) including Personally Identifiable Information (PII) on a non-federal system (e.g., the contractor’s corporate system) the system must meet the requirements for data protections detailed in NIST Special Publication 800-171, “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations.”
This documentation may take the form of:
a. A third-party review/audit certifying that the non-federal system meets the requirements of NIST SP
800-171 or equivalent standard of information protection, such as the ISO 27001 standard.
b. A certification from another Federal Agency such as the DOD Cybersecurity Maturity
Model Certification (CMMC) Level 2.
Incident Notification:
The Contractor shall report immediately upon notification any incident involving NASA information on non-federal (i.e., Contractor) systems to SOC@nasa.gov.
IT Security Point Of Contact:
The Contractor shall identify a point of contact that NASA may reach in its attempt to address IT and cybersecurity issues. The point of contact shall have the authority to ensure the immediate notification of the NASA Security Operations Center of any incident involving NASA information.
IT Security Awareness Training:
Contractor employees subject to this contract shall complete the NASA approved IT Security Awareness Training annually. NASA Cybersecurity and Privacy Awareness training is available through the SATERN online system and must be completed prior to access to NASA information and systems. Completion of the training is tracked automatedly by NASA and must recur each year by the anniversary of the initial training as a condition of continued access. Cybersecurity and Privacy training is updated throughout the year as needed, so there is no defined training period.
IT Security Role Based Training:
Contractor employees subject to this contract shall complete NASA’s Foundational IT Security Training in SATERN related to the following role-based functions prior to performing the role:
• IT Security Manager
• Information System Owner (ISO)
• Information Systems Security Officer (ISSO)
• Information System Security Engineer (ISSE)
It is highly recommended, but not required, that Contractor employees complete advanced role-based training every other year following completion of the initial training provided by NASA. This training is also provided by NASA but may be fulfilled externally. If fulfilled externally, the Contractor shall provide the “External Role- Based Training Validation Form” to the center CISO. The process for completing this form and receiving credit may be found at: External RBT Validation Form (sharepoint.com).
Information on Employees In Sensitive Position(s)/Assignments Report:
The Information on Employees is Sensitive. IT Security (ITS) Positions/Assignments Report shall provide information annually for personnel screening as required by NPR 2810.1 (series), and NPR 1600.1 on position risk.
Cyber Supply Chain Risk Management (C-SCRM) Plan:
NIST defines C-SCRM as a systematic process for managing exposure to cybersecurity risks throughout the supply chain and developing appropriate response strategies, policies, process, and procedures. A C-SCRM plan, consistent with the recommended template in NIST SP 800-161, Section 3.1 shall be delivered prior to the processing, transmission, or storage of non-public NASA information in performance of the contract.
Remarks: None
Maintenance: Information System Security Plan(s) shall be kept up to date as changes to the baseline configuration of the system(s) occur.
Non-Federal System Certifications shall be maintained annually or per the certifying body’s standard.
Information on Employees in Sensitive Positions/Assignments Report shall be maintained annually.
It Security Point of Contact shall be kept up to date as changes occur.
Evidence of completion of IT Security Role Based Training is due annually.
C-SCRM plans shall be kept up to date as changes occur to organizational C-SCRM processes, policies, and procedures, and/or, new components are introduced.
1. DRD Title: Commercial Information Technology Authorizations Report (CITAR)
2. DRD No.: DRD-003 3. Data Type: 1 4. OPR: Office of Procurement
(OP)
5. Solicitation No.: 80GSFC24R0042
6. Contract No.: TBD
7. Date Issued:
8. Date Revised: 9. DRD Category:
Technical ☐
Administrative ☒
S&MA ☐
10. Description/Use: In accordance with the Enterprise IT Acquisition Management (eITAM) requirements an approval process has been developed to capture procurement detail of IT purchases under this Contract that the Contractor will need to provide.
11. Distribution: Electronic submission to COR and the Contracting Officer
Initial Submission: Due within one (1) month of contract award.
Submission Frequency: Monthly
Format: Electronic format shall be compatible with Microsoft Office
Interrelationship: TBD
Applicable Documents: N/A
Scope: Purchasing of Information Technology.
Contents: The Commercial IT Authorizations Report shall include the following columns of information:
Contract:
Contract #:
Work Package #:
TPOC:
Status (In process, Procured):
Part #:
Description:
Quantity:
Authorization #:
Date of Authorization:
Dollar Amount (Not required if "In Process"):
Date of Purchase (Not required if "In Process"):
Remarks: N/A
Maintenance: Update as required to maintain current with program changes with 60 day notice.
File details come from the government source that posted it. Updated .