Attachment M IT Security Applicable Docs.pdf

PDF 1 MB Posted

Attached to
Wallops Range Contract (WRC) Federal contract opportunity
Solicitation number
80GSFC23R0009FRFP
Issued by
National Aeronautics and Space Administration Goddard Space Center

About this file

This document provides an applicable documents list for a federal contract supporting the Wallops Range Contract (WRC) opportunity issued by the National Aeronautics and Space Administration Goddard Space Center. The list includes over 80 applicable National Institute of Standards and Technology special publications related to cybersecurity, information security controls, cryptography, identity management, and privacy that must be followed under the contract. Key areas addressed include requirements for hardware configurations, minimum security and privacy standards, computing system configuration management, information system owner and end user security, microservices application security, platform and application container security, interdomain traffic exchange security, mobile device and wireless network security, supply chain risk management practices, systems security engineering, and controls for protecting controlled unclassified information. Adherence to the documents on this list will be required under the terms of the solicitation for the Wallops Range Contract supporting work at NASA Goddard Space Center.

View the file

Other files for this federal contract opportunity

Other files attached to Wallops Range Contract (WRC), newest first.
File Type Posted
80GSFC23R0009 RFI-6.pdf PDF
80GSFC23R0009 RFI-5.pdf PDF
80GSFC23R0009 - SF33 - 11-27-2023.pdf PDF
80GSFC23R0009 Amendment 003.pdf PDF
80GSFC23R0009 RFI-3.pdf PDF
80GSFC23R0009 Amendment 002.pdf PDF
Attachment A - WRC SOW 9NOV2023.pdf PDF
Attachment S - OCI-Plan-Data-Requirements - Rev.1.pdf PDF
Plug Numbers for Cost Exhibits A and B - Rev.1.pdf PDF
Enclosure 1 - Phase-in SOW - Rev. 1.pdf PDF
Exhibit A - Cost Plus FF Hybrid CORE 10-6-2023 - Rev. 1.pdf PDF
Exhibit B - WRC Exh RTO Cost - Rev. 1.pdf PDF
Plug Numbers for Cost Exhibits A and B.pdf PDF
80GSFC23R0009 RFI-1.pdf PDF
80GSFC23R0009 Amendment 001.pdf PDF
ROC II Contract Historical Data - 2.pdf PDF
ROC II Contract Historical Data - 1.pdf PDF
Exhibit C - PPQ.pdf PDF
Enclosure 2 RTO-Sounding Rocket 46-031 Requirements.pdf PDF
Attachment L - Contract Historical Data.pdf PDF
CBA-2023-222 KBR.pdf PDF
Attachment F - IT Security Management Plan REV.pdf PDF
Final Request for Proposal (RFP) Cover Letter signed.pdf PDF
Exhibit A - Cost Plus FF Hybrid CORE 10-6-2023.pdf PDF
Exhibit B - WRC Exh RTO Cost 9-15-23.pdf PDF
Enclosure 3 - Government WRC QASP.pdf PDF
Enclosure 2 RTO-ELV Requirements.pdf PDF
Enclosure 2 RTO-RTO (Campaign and ELV) 7SEP2023 Final.pdf PDF
Attachment S - OCI-Plan-Data-Requirements.pdf PDF
Attachment O - GFP.pdf PDF
Attachment E - Small Business Subcontracting Plan.pdf PDF
Attachment B - Direct Labor Rates_Indirect Rates and Fee.pdf PDF
Attachment N - Contractor Proposed Enhancements.pdf PDF
IAM AW and Saalex- ROC II - CBA -Final (signed).pdf PDF
Attachment K - OCI Avoidance Plan.pdf PDF
Enclosure 1 - Phase-in SOW 28MAR.pdf PDF
Attachment Q - DEIA Plan.pdf PDF
IAM AW and KBR - ROC II - Fully Executed CBA - 2022.PDF PDF
CBA-2023-223 Saalex Solutions Inc..pdf PDF
CBA-2023-224 Rothe Enterprises Inc..pdf PDF
Attachment A-WRC SOW_GO_Chem 11SEP2023FINAL.pdf PDF
Attachment G-533 Attach Core and IDIQ--Both Onsite and Offsite.pdf PDF
Attachment C - IAGP.pdf PDF
WRC - FRFP-80GSFC23R0009 Final.pdf PDF
Enclosure 4 - IT Security Management Plan Template.pdf PDF
Enclosure 2 RTO-Sounding Rocket 36-360 Requirements.pdf PDF
Attachment R - DEIA Plan.pdf PDF
Attachment P - Requirements Statements List.pdf PDF
Attachment J - DD254 - WRC.pdf PDF
Attachment I - Quality Assurance Plan.pdf PDF
Show all 50

Wallops Range Contract (WRC) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Applicable Documents List

Attachment M

RFP 80GSFC23R0009

CONTRACT TBD

Applicable Documents List

08/11/2023

Applicable Documents List Contract TBD

NASA-STD-2805 Minimum Hardware Configurations December 10, 2020

NASA-STD-2603 Minimum Security and Privacy Requirements for

Agency and Center Information System

Implementations

October 9, 2019

NASA-STD-2601 Minimum Cybersecurity Requirements for

Computing Systems

June 14, 2023

NASA-STD-2604 Computing System Configuration Management August 12, 2019

NASA-STD-2602 Minimum Information System Owner and End User

Security for Data at Rest

April 12, 2023

SP 800-204A Building Secure Microservices-based Applications Using

Service-Mesh Architecture

May 27, 2020

SP 800-204 Security Strategies for Microservices-based Application

Systems

August 7, 2019

SP 800-202 Quick Start Guide for Populating Mobile Test Devices May 10, 2018

SP 800-193 Platform Firmware Resiliency Guidelines May 4, 2018

SP 800-192 Verification and Test Methods for Access Control

Policies/Models

June 27, 2017

SP 800-190 Application Container Security Guide September 25, 2017

SP 800-189 Resilient Interdomain Traffic Exchange: BGP Security and

DDoS Mitigation

December 17, 2019

SP 800-187 Guide to LTE Security December 21, 2017

SP 800-185 SHA-3 Derived Functions: cSHAKE, KMAC, TupleHash, and

ParallelHash

December 22, 2016

SP 800-184 Guide for Cybersecurity Event Recovery December 22, 2016

SP 800-183 Networks of 'Things' July 28, 2016

SP 800-181 Rev. 1 Workforce Framework for Cybersecurity (NICE Framework) November 16, 2020

SP 800-178 A Comparison of Attribute Based Access Control (ABAC)

Standards for Data Service Applications: Extensible Access

Control Markup Language (XACML) and Next Generation

Access Control (NGAC)

October 03, 2016

SP 800-177 Rev. 1 Trustworthy Email February 26, 2019

SP 800-175B Rev. 1 Guideline for Using Cryptographic Standards in the Federal

Government: Cryptographic Mechanisms

March 31, 2020

SP 800-175A Guideline for Using Cryptographic Standards in the Federal

Government: Directives, Mandates and Policies

August 22, 2016

SP 800-172A Assessing Enhanced Security Requirements for Controlled

Unclassified Information

March 15, 2022

SP 800-172 Enhanced Security Requirements for Protecting Controlled

Unclassified Information: A Supplement to NIST Special

Publication 800-171

February 02, 2021

SP 800-171 Rev. 2 Protecting Controlled Unclassified Information in Nonfederal

Systems and Organizations

January 28, 2021

SP 800-171A Assessing Security Requirements for Controlled Unclassified

Information

June 13, 2018

SP 800-168 Approximate Matching: Definition and Terminology July 02, 2014

SP 800-167 Guide to Application Whitelisting October 28, 2015

SP 800-166 Derived PIV Application and Data Model Test Guidelines June 06, 2016

SP 800-163 Rev. 1 Vetting the Security of Mobile Applications April 19, 2019

SP 800-162 Guide to Attribute Based Access Control (ABAC) Definition and Considerations

August 02, 2019

SP 800-161 Rev. 1 Cybersecurity Supply Chain Risk Management Practices for

Systems and Organizations

May 05, 2022

SP 800-160 Vol. 2

Rev. 1

Developing Cyber-Resilient Systems: A Systems Security

Engineering Approach

December 09, 2021

SP 800-160 Vol. 1 Systems Security Engineering: Considerations for a

Multidisciplinary Approach in the Engineering of Trustworthy

Secure Systems

March 21, 2018

SP 800-157 Guidelines for Derived Personal Identity Verification (PIV)

Credentials

December 19, 2014

SP 800-156 Representation of PIV Chain-of-Trust for Import and Export May 20, 2016

SP 800-153 Guidelines for Securing Wireless Local Area Networks

(WLANs)

February 21, 2012

SP 800-152 A Profile for U.S. Federal Cryptographic Key Management

Systems (CKMS)

October 28, 2015

SP 800-150 Guide to Cyber Threat Information Sharing October 04, 2016

SP 800-147B BIOS Protection Guidelines for Servers August 28, 2014

SP 800-147 BIOS Protection Guidelines April 29, 2011

SP 800-146 Cloud Computing Synopsis and Recommendations May 29, 2012

SP 800-145 The NIST Definition of Cloud Computing September 28, 2011

SP 800-144 Guidelines on Security and Privacy in Public Cloud

Computing

December 09, 2011

SP 800-142 Practical Combinatorial Testing October 07, 2010

SP 800-140F CMVP Approved Non-Invasive Attack Mitigation Test

Metrics: CMVP Validation Authority Updates to ISO/IEC

24759

March 20, 2020

SP 800-140E CMVP Approved Authentication Mechanisms: CMVP

Validation Authority Requirements for ISO/IEC 19790 Annex

E and ISO/IEC 24579 Section 6.17

March 20, 2020

SP 800-140D Rev. 1 CMVP Approved Sensitive Parameter Generation and

Establishment Methods: CMVP Validation Authority Updates to ISO/IEC 24759

May 20, 2022

SP 800-140C Rev. 1 CMVP Approved Security Functions: CMVP Validation

Authority Updates to ISO/IEC 24759

May 20, 2022

SP 800-140B CMVP Security Policy Requirements: CMVP Validation

Authority Updates to ISO/IEC 24759 and ISO/IEC 19790

Annex B

March 20, 2020

SP 800-140A CMVP Documentation Requirements: CMVP Validation

Authority Updates to ISO/IEC 24759

March 20, 2020

SP 800-140 FIPS 140-3 Derived Test Requirements (DTR): CMVP

Validation Authority Updates to ISO/IEC 24759

March 20, 2020

SP 800-137A Assessing Information Security Continuous Monitoring

(ISCM) Programs: Developing an ISCM Program Assessment

May 21, 2020

SP 800-137 Information Security Continuous Monitoring (ISCM) for

Federal Information Systems and Organizations

September 30, 2011

SP 800-135 Rev. 1 Recommendation for Existing Application-Specific Key

Derivation Functions

December 23, 2011

SP 800-133 Rev. 2 Recommendation for Cryptographic Key Generation June 04, 2020

SP 800-132 Recommendation for Password-Based Key Derivation: Part 1:

Storage Applications

December 22, 2010

SP 800-131A Rev. 2 Transitioning the Use of Cryptographic Algorithms and Key

Lengths

March 21, 2019

SP 800-130 A Framework for Designing Cryptographic Key Management

Systems

August 15, 2013

SP 800-128 Guide for Security-Focused Configuration Management of

Information Systems

October 10, 2019

SP 800-126 Rev. 3 The Technical Specification for the Security Content

Automation Protocol (SCAP): SCAP Version 1.3

February 14, 2018

SP 800-126 Rev. 2 The Technical Specification for the Security Content

Automation Protocol (SCAP): SCAP Version 1.2

March 19, 2012

SP 800-126A SCAP 1.3 Component Specification Version Updates: An

Annex to NIST Special Publication 800-126 Revision 3

February 14, 2018

SP 800-126 Rev. 1 The Technical Specification for the Security Content

Automation Protocol (SCAP): SCAP Version 1.1

February 25, 2011

SP 800-125B Secure Virtual Network Configuration for Virtual Machine

(VM) Protection

March 7, 2016

SP 800-125A Rev. 1 Security Recommendations for Server-based Hypervisor

Platforms

June 7, 2018

SP 800-125 Guide to Security for Full Virtualization Technologies January 28, 2011

SP 800-124 Rev. 1 Guidelines for Managing the Security of Mobile Devices in the Enterprise

June 21, 2013

SP 800-123 Guide to General Server Security July 25, 2008

SP 800-122 Guide to Protecting the Confidentiality of Personally

Identifiable Information (PII)

April 06, 2010

SP 800-121 Rev. 2 Guide to Bluetooth Security January 19, 2022

SP 800-119 Guidelines for the Secure Deployment of IPv6 December 29, 2010

SP 800-116 Rev. 1 Guidelines for the Use of PIV Credentials in Facility Access June 29, 2018

SP 800-115 Technical Guide to Information Security Testing and

Assessment

September 30, 2008

SP 800-114 Rev. 1 User's Guide to Telework and Bring Your Own Device

(BYOD) Security

July 29, 2016

SP 800-113 Guide to SSL VPNs July 01, 2008

SP 800-111 Guide to Storage Encryption Technologies for End User

Devices

November 15, 2007

SP 800-108 Rev. 1 Recommendation for Key Derivation Using Pseudorandom

Functions

August 17, 2022

SP 800-107 Rev. 1 Recommendation for Applications Using Approved Hash

Algorithms

August 24, 2012

SP 800-106 Randomized Hashing for Digital Signatures February 25, 2009

SP 800-102 Recommendation for Digital Signature Timeliness September 23, 2009

SP 800-101 Rev. 1 Guidelines on Mobile Device Forensics May 15, 2014

SP 800-98 Guidelines for Securing Radio Frequency Identification

(RFID) Systems

April 06, 2007

SP 800-97 Establishing Wireless Robust Security Networks: A Guide to

IEEE 802.11i

February 07, 2007

SP 800-96 PIV Card to Reader Interoperability Guidelines December 29, 2006

SP 800-95 Guide to Secure Web Services August 29, 2007

SP 800-94 Guide to Intrusion Detection and Prevention Systems (IDPS) February 20, 2007

SP 800-92 Guide to Computer Security Log Management September 13, 2006

SP 800-90B Recommendation for the Entropy Sources Used for Random

Bit Generation

January 10, 2018

SP 800-90A Rev. 1 Recommendation for Random Number Generation Using

Deterministic Random Bit Generators

June 24, 2015

SP 800-89 Recommendation for Obtaining Assurances for Digital

Signature Applications

November 30, 2006

SP 800-88 Rev. 1 Guidelines for Media Sanitization December 17, 2014

SP 800-87 Rev. 2 Codes for Identification of Federal and Federally-Assisted

Organizations

April 19, 2018

SP 800-86 Guide to Integrating Forensic Techniques into Incident

Response

September 01, 2006

SP 800-85B PIV Data Model Test Guidelines July 31, 2006

SP 800-85A-4 PIV Card Application and Middleware Interface Test

Guidelines (SP 800-73-4 Compliance)

April 13, 2016

SP 800-84 Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities

September 21, 2006

SP 800-83 Rev. 1 Guide to Malware Incident Prevention and Handling for

Desktops and Laptops

July 22, 2013

SP 800-82 Rev. 2 Guide to Industrial Control Systems (ICS) Security June 03, 2015

SP 800-81-2 Secure Domain Name System (DNS) Deployment Guide September 18, 2013

SP 800-79-2 Guidelines for the Authorization of Personal Identity

Verification Card Issuers (PCI) and Derived PIV Credential

Issuers (DPCI)

July 30, 2015

SP 800-78-4 Cryptographic Algorithms and Key Sizes for Personal Identity

Verification

May 29, 2015

SP 800-77 Rev. 1 Guide to IPsec VPNs June 30, 2020

SP 800-76-2 Biometric Specifications for Personal Identity Verification July 11, 2013

SP 800-73-4 Interfaces for Personal Identity Verification February 12, 2016

SP 800-72 Guidelines on PDA Forensics November 01, 2004

SP 800-70 Rev. 4 National Checklist Program for IT Products: Guidelines for

Checklist Users and Developers

February 15, 2018

SP 800-67 Rev. 2 Recommendation for the Triple Data Encryption Algorithm

(TDEA) Block Cipher

November 17, 2017

SP 800-66 Rev. 1 An Introductory Resource Guide for Implementing the Health

Insurance Portability and Accountability Act (HIPAA)

Security Rule

October 23, 2008

SP 800-63-3 Digital Identity Guidelines March 02, 2020

SP 800-63C Digital Identity Guidelines: Federation and Assertions March 02, 2020

SP 800-63B Digital Identity Guidelines: Authentication and Lifecycle

Management

March 02, 2020

SP 800-63A Digital Identity Guidelines: Enrollment and Identity Proofing March 02, 2020

SP 800-61 Rev. 2 Computer Security Incident Handling Guide August 08, 2012

SP 800-60 Vol. 2

Rev. 1

Guide for Mapping Types of Information and Information

Systems to Security Categories: Appendices

August 01, 2008

SP 800-60 Vol. 1

Rev. 1

Guide for Mapping Types of Information and Information

Systems to Security Categories

August 01, 2008

SP 800-59 Guideline for Identifying an Information System as a National

Security System

August 08, 2003

SP 800-58 Security Considerations for Voice Over IP Systems January 01, 2005

SP 800-57 Part 3

Rev. 1

Recommendation for Key Management, Part 3: Application-

Specific Key Management Guidance

January 22, 2015

SP 800-57 Part 2

Rev. 1

Recommendation for Key Management: Part 2 – Best

Practices for Key Management Organizations

May 23, 2019

SP 800-57 Part 1

Rev. 5

Recommendation for Key Management: Part 1 – General May 04, 2020

SP 800-56C Rev. 2 Recommendation for Key-Derivation Methods in Key-

Establishment Schemes

August 18, 2020

SP 800-56B Rev. 2 Recommendation for Pair-Wise Key-Establishment Using

Integer Factorization Cryptography

March 21, 2019

SP 800-56A Rev. 3 Recommendation for Pair-Wise Key-Establishment Schemes

Using Discrete Logarithm Cryptography

April 16, 2018

SP 800-55 Rev. 1 Performance Measurement Guide for Information Security July 16, 2008

SP 800-53 Rev. 5 Security and Privacy Controls for Information Systems and

Organizations

December 10, 2020

SP 800-53B Control Baselines for Information Systems and Organizations December 10, 2020

SP 800-53A Rev. 5 Assessing Security and Privacy Controls in Information

Systems and Organizations

January 25, 2022

SP 800-53A Rev. 4 Assessing Security and Privacy Controls in Federal

Information Systems and Organizations: Building Effective

Assessment Plans

December 18, 2014

SP 800-52 Rev. 2 Guidelines for the Selection, Configuration, and Use of

Transport Layer Security (TLS) Implementations

August 29, 2019

SP 800-51 Rev. 1 Guide to Using Vulnerability Naming Schemes February 25, 2011

SP 800-50 Building an Information Technology Security Awareness and

Training Program

October 01, 2003

SP 800-49 Federal S/MIME V3 Client Profile November 05, 2002

SP 800-47 Rev. 1 Managing the Security of Information Exchanges July 20, 2021

SP 800-46 Rev. 2 Guide to Enterprise Telework, Remote Access, and Bring

Your Own Device (BYOD) Security

July 29, 2016

SP 800-45 Version 2 Guidelines on Electronic Mail Security February 20, 2007

SP 800-44 Version 2 Guidelines on Securing Public Web Servers October 09, 2007

SP 800-41 Rev. 1 Guidelines on Firewalls and Firewall Policy September 28, 2009

SP 800-40 Rev. 4 Guide to Enterprise Patch Management Planning: Preventive

Maintenance for Technology

April 06, 2022

SP 800-39 Managing Information Security Risk: Organization, Mission, and Information System View

March 01, 2011

SP 800-38G Recommendation for Block Cipher Modes of Operation:

Methods for Format-Preserving Encryption

August 04, 2016

SP 800-38F Recommendation for Block Cipher Modes of Operation:

Methods for Key Wrapping

December 13, 2012

SP 800-38E Recommendation for Block Cipher Modes of Operation: the

XTS-AES Mode for Confidentiality on Storage Devices

January 18, 2010

SP 800-38D Recommendation for Block Cipher Modes of Operation:

Galois/Counter Mode (GCM) and GMAC

November 28, 2007

SP 800-38C Recommendation for Block Cipher Modes of Operation: the

CCM Mode for Authentication and Confidentiality

July 20, 2007

SP 800-38B Recommendation for Block Cipher Modes of Operation: the

CMAC Mode for Authentication

October 06, 2016

SP 800-38A

Addendum

Recommendation for Block Cipher Modes of Operation:

Three Variants of Ciphertext Stealing for CBC Mode

October 21, 2010

SP 800-38A Recommendation for Block Cipher Modes of Operation:

Methods and Techniques

December 01, 2001

SP 800-37 Rev. 2 Risk Management Framework for Information Systems and

Organizations: A System Life Cycle Approach for Security and Privacy

December 20, 2018

SP 800-35 Guide to Information Technology Security Services October 09, 2003

SP 800-34 Rev. 1 Contingency Planning Guide for Federal Information Systems November 11, 2010

SP 800-30 Rev. 1 Guide for Conducting Risk Assessments September 17, 2012

SP 800-28 Version 2 Guidelines on Active Content and Mobile Code March 07, 2008

SP 800-22 Rev. 1a A Statistical Test Suite for Random and Pseudorandom

Number Generators for Cryptographic Applications

April 30, 2010

SP 800-18 Rev. 1 Guide for Developing Security Plans for Federal Information

Systems

February 24, 2006

SP 800-16 Information Technology Security Training Requirements: A

Role- and Performance-Based Model

April 01,1998

SP 800-12 Rev. 1 An Introduction to Information Security June 22, 2017

File details come from the government source that posted it. Updated .