CyPrESS DRAFT Statement of Work (SOW).docx

DOCX document 136 KB Posted

Attached to
Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) Federal contract opportunity
Solicitation number
80GRC020R0027
Issued by
National Aeronautics and Space Administration Glenn Research Center

About this file

This sources sought notice solicits capability statements for a potential Cybersecurity and Privacy Enterprise Solutions and Services procurement to provide services to the National Aeronautics and Space Administration. Services include security operations center support, assessment and authorization, incident response, cybersecurity architecture and engineering, penetration testing, vulnerability management, supply chain risk management, training and awareness, and cybersecurity infrastructure support. Responses are limited to 10 pages describing general company information, relevant past performance on similar contracts over the past three years, and capabilities to meet the draft statement of work requirements. Capability statements must be submitted by July 10, 2020 to Amanda L. George via email. The North American Industry Classification code is 541519 with a size standard of $30 million. Questions may be directed to the specified points of contact by the reference number 80GRC020R0027.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) DRAFT Statement of Work (SOW)

OVERALL CONTRACT SUPPORT

The Contractor shall:

· Manage and maintain all Information Technology (IT) hardware, software, and data storage required by the Government to sustain the full scope of this Performance Work Statement (PWS)

· Prepare and submit monthly reports of project plans, status, resources and schedules in accordance with all Data Requirements Descriptions (DRDs) specified in Attachment XX of this PWS (Deliverable XX)

· Plan, document and execute all projects, tasks and operational functions in accordance with NASA program and project management policies and procedures

· Complete requirements of this contract so work performed fully meets the performance objectives of the contract; is performed within the schedule; is accomplished within the contract value and any executed LOE Task Orders; and is accomplished in a safe, professional and high-quality manner

· Respond to changing service requirements and prioritize tasks to best accomplish the requirements of the contract to meet government priorities

· Collect and report contract metrics data, including all metrics data specified in this PWS and additional metrics identified by the Government

· Prepare and conduct monthly project/contract management reviews including presentation and discussion of project priorities, project statuses (technical, financial and schedule), significant accomplishments, contract metrics, risk management and problem areas

· Provide a contract management capability to meet the requirements of this PWS

· Designate a single Point of Contact (POC) with contractual obligation authority for all contract administration functions and activities required in performance of this contract. This POC shall have access to all contract administration data and information related to performance of this contract. Additionally, this POC will function as an onsite Program Manager (PM) who shall have authority over all technical, business, personnel, performance, schedule and cost components of Contractor activities in execution of this PWS.

· Perform technical, business and safety functions to plan, implement, track, report and deliver the required products and services described in the PWS

· Ensure the implementation of effective systems engineering, business management and other quality practices to deliver the services in an efficient and integrated manner

· Provide resources that are proficient in all of the NASA provided tools

· Continuously analyze NASA cybersecurity posture and planning to identify any gaps in Enterprise capabilities required to achieve desired policy

BUSINESS MANAGEMENT

This function provides the nontechnical overall support for Cyber Security & Privacy Program (CSPP). This includes, but not limited to, budget, logistics, program performance (metrics), asset tracking, etc.

The Contractor shall:

· Support the Government in implementing and managing the NASA CSPP services in accordance with NASA policies

· Provide recommendations to the government on a variety of relevant topics, within the pertinent subject domain

· Maintain an expanded body of knowledge of Commercial, Industry, Federal, Agency, Regional, and Local technical and administrative regulations, policies, procedural guides, laws, other governing manuals, and tools that are necessary to meet the agency’s cybersecurity goals and objectives

· Provide resources with sufficient clearances to access classified information and attend classified briefings on cybersecurity threats and related information

· Support processes and procedures to ensure the analysis and effective evaluation, selection, prioritization, and funding of IT security investments

· Provide support and reporting necessary to meet cybersecurity requirements in accordance with the Capital Planning and Investment Control (CPIC) process

· Support Planning, Programming, Budgeting, and Execution (PPBE) process to develop, publish, and track expenditures associated with agency cybersecurity goals and objectives

· Support internal, functional, competitive/peer, and generic benchmarking activities by comparing cybersecurity processes, procedures, and performance metrics to industry, Federal, and agency Best Business Practices (BBP)

· Be aware of technology trends and other factors in order to recommend, develop, or implement innovative cybersecurity processes, procedures, tools, and mechanisms that help improve and advance the agency’s cybersecurity posture

· Support external reporting and other communications in response to Congressional and Executive Branch mandates. (Deliverable XX)

· Assist with developing, communicating, and tracking CSPP performance metrics. This includes both internal and external performance metrics

· Review and recommend updates to the OCIO business continuity plan, consistent with CSPP continuity of operations requirements. Support the business continuity planning for all CSPP portfolios

· Support cybersecurity-related communications with NASA and external organizations.

· Support the governance functions for cybersecurity services and other cybersecurity-related changes (refer back to CSPP or the Appendix with the governance structure)

· Support the review and response to all cybersecurity audit findings, including ensuring that all findings are tracked and responses are submitted in a timely manner

· Support the CSPP meetings, including agenda planning, speaker and topic preparation, meeting conduct, and meeting follow-up

· Recommend, develop, and implement service level agreements (SLA)

· Ensure performance metrics are tracked and reported to meet cybersecurity goals and objectives

· Provide technical, financial, schedule and risk management of all CSPP functions and tasks in accordance with applicable NASA policies and procedures

OFFICE OF CYBERSECURITY SERVICES (OCSS) AND SUPPORT

The Office of Cybersecurity Services (OCSS) manages and deliver enterprise security services across the Agency. The OCSS is established to serve the missions in identifying and protecting NASA's information assets, promoting continuous service improvement, attaining economies of scale and cost efficiencies, and increasing leadership's cyber situational awareness to enable informed risk-based decisions.

The Contractor shall:

· Assist the government with managing the Change Management and Governance Processes for the OCSS to minimize the impact of change-related requests with the prompt handling of all changes of service quality

· Assist with facilitating the Change Management Boards/Meetings

· Develop marketing and outreach notifications, including executive support email

· Assist the government with maintaining the OCSS Service Portfolio

· Assist with engaging the customer to gather requirements

· Support the government with weekly engagements

· Assist with the development and delivery of OCSS provided services to the Service Catalog

· Assist the government with Service Level and Organizational Level Agreements (OLAs) documentation, training and processes

· Monitor metrics and deliverables to ensure that Service Level Agreements (SLAs) and OLAs are being met

· Support the Continual Service Improvement Processes

· Assist the government with developing CSI process

PRIVACY SERVICES

The Contractor shall:

a) Assist NASA organizations in understanding and interpreting NASA policy and procedures relative to privacy

b) Assist NASA in implementing privacy information protection in accordance with NASA policies and federal mandates

c) Support the NASA Privacy Program Managers (PPM) in all privacy related aspects

d) Assist NASA in responding to federal privacy inquiries and reporting requests

e) Assist NASA stakeholders to meet and validate the privacy requirements as defined in NASA policies

f) Assist the Breach Response Team (BRT), as needed

g) Provide preliminary cybersecurity privacy specifications for verification, in relation to standard configurations, system security plans, personally identifiable information (PII), CUI, and initial Privacy Threshold Assessment (PTA), Privacy Impact Assessments (PIA), and Systems of Registry Notifications (SORN)

CONTROLLED UNCLASSIFIED INFORMATION (CUI) SERVICES

The Contractor shall:

a) Support the NASA PPM with Sensitive But Classified (SBU) transition to Controlled Unclassified Information (CUI) based on NASA’s requirements, procedures and processes

b) Provide the Agency OCIO with subject matter expertise that can support the CUI roadmap implementation

c) Assist with developing and providing communications and outreach material

d) Assist with developing required annual reports based on the Federal mandates and guidelines

e) Recommend and draft enterprise policy and procedures, in coordination with the NASA CSPD

f) Ensure appropriate banner markings are labeled on CUI documents

g) Store and maintain the documentation in the NASA Repository

h) Provide resources that are knowledgeable in the NASA provided tools

ASSESSMENT & AUTHORIZATION (A&A)

The CSPP continues to develop, document and maintain the Agency’s A&A processes and tools in order to maintain the compliancy of the NIST 800 series. This includes, but not limited to, developing, documenting, tracking and continuing to improve NASA’s processes and tools for A&A of the Agency’s information systems to support cybersecurity risk management and compliance with Federal mandates.

The Contractor shall:

· Provide support for an effective and comprehensive Assessment & Authorization (A&A) program for systems, ensuring improvements to the A&A process are developed, implemented, maintained and executed for the Center/Agency per NASA policies and procedures

· Update and maintain Government Common Controls System Security Plan (Deliverable XX)

· Support the development and maintenance of security authorization documentation.

· Provide implementation of remediation assistance with various Center specific missions, projects and groups as requested

· Prepare any necessary documentation, participate in interviews, and support any other methods necessary to complete the risk assessment

· Provide support for continuous monitoring and work with the Government to assist in mitigation for findings and ensure remediation activities are being tracked in the approved Agency Continuous Monitoring tool/application

· Develop and recommend a plan to evaluate security plans for accuracy and completeness

· Conduct security control assessments of NASA’s information systems in accordance with the Security Assessment and Authorization policies and process as described in various NASA IT Security policies

· Participate and assist independent risk assessments, as requested, that will be performed by an independent third party

· Provide subject matter expertise and support to NASA Information System Owners in development and updates of systems security plans ad associate documentation

POLICY

The Contractor shall:

· Assist in the identification of any gaps in Enterprise capabilities required to achieve desired policy and directives as well as developing integrated cybersecurity roadmaps, touch points and dependencies between multiple service lines and Agency IT Programs

· Provide training, outreach, FAQs, and other communications on new or updated policies to NASA through a variety of mechanisms

· Support cybersecurity and privacy policy lifecycle management – including policy development, maintenance, and governance

· Ensure the policies are compliant with NASA and other Federal mandates

· Support NASA in the development, review and maintenance of cybersecurity and privacy policy, NPDs, NPRs, and other policy documents

· Support the continuous updating of the NASA policy tools / websites (currently NODIS, CIO web site, and Inside NASA intranet) with the latest version of all policies and interim directives

· Maintain expertise in all NASA cybersecurity and privacy policies and provide support in researching and supporting applicable policies

· Support the governance of new or updated cybersecurity and privacy policies to result in approval or rejection of proposed policies/changes

· Ensure coordination with other NASA policy owners to incorporate as applicable appropriate integrations of cybersecurity and privacy policy

OPERATIONAL TECHNOLOGY

The Operational Technology (OT) is a new technology being assessed throughout the Agency. The NASA IT OT POC collaborates with the NASA Enterprise Protection Program (EPP) to identity all OT and it is compliant to the NIST Federal mandates.

The Contractor shall:

· Provide recommendation on NIST SP800 series controls that would be applicable to all systems designated as OT (Deliverable XX)

· Provide an initial general criticality rating for all NIST 800-53 controls and enhancements and then tailor control criticality based on the differing missions at the Agency (Deliverable XX)

· Review relevant NASA policies, procedures, standards, handbooks and other applicable documents relating to OT Cybersecurity

· Provide recommendations to address gaps identified that are associated with the A&A for NASA OT systems in accordance with NIST SP800 series and NASA requirements (Deliverable XX)

· Track technology trends and other factors in order to recommend, develop, or implement innovative OT security processes, procedures, tools, and mechanisms that help improve and advance the agency’s OT security posture

· Provide support of the development IT/OT security policies and procedures

NASA CYBERSECURITY STANDARDS AND ARCHITECTURE

Cybersecurity Standards and Engineering Team (CSET) leads the NASA Agency Security Configuration Standards (ASCS) Project to ensure NASA is compliant with system configuration requirements of the Federal Information Systems Modernization Act (FISMA). When the project is complete, CSET will maintain the Agency standards.

The Contractor shall:

•Assist in the development and maintenance of NASA cybersecurity standards, specification, and handbooks.
•Research, recommend, promote, advertise, and revise Agency cybersecurity standards for computing systems, cloud, networking, applications, and data management.
•Ratify standards, specifications, and handbooks via approved governance mechanisms.
•Develop, solicit, and incorporate stakeholder feedback as required by the appropriate governance process.
•Create, maintain, and support compliance content that utilizes or feeds into the Agency CDM Toolset to accurately measure target system compliance against Security Configuration Specifications. Engage the appropriate service provider (e.g. Cybersecurity Infrastructure) during the development cycle and adhere to established OLAs.
•Assist with related Agency cybersecurity initiatives and incorporate security into NASA standards and other deliverables.
•Track and support the governance of common Agency commercial off-the-shelf application and operating system lifecycles.
•Provide consultation on development of the cybersecurity architecture.
•Maintain an in-depth awareness of the NASA IT Enterprise Cybersecurity Architecture.
•Identify opportunities for leveraging standards and cybersecurity architecture in support of the NASA Enterprise IT Architecture.
•Recommend requirements and integration design of enterprise technologies in the NASA environment.
•Maintain awareness of other federal agency posture and efforts and communicates with federal and Agency peers to leverage inter- and intra-agency knowledge, lessons learned and resources regarding platform specific security and compliance information.
•Maintains awareness of the next generation technologies requiring advanced cybersecurity controls and implementation strategies.
•Create and maintain the CSET website including ASCS and engineering/architecture efforts.
•Ensure that CSET communications are professional, consistent, and support a positive group identity to effectively advertise and promote the technical standards and work products as established by CSET.
•CSET's engineering responsibilities include performing cybersecurity technology assessments and significant support of cybersecurity design, development and engineering aspects of NASA 7120.7 and 7120.8 projects and initiatives.

IDENTITY, CREDENTIAL AND ACCESS MANAGEMENT (ICAM)

ICAM provides identity, credential, and access management services to the Agency. The NASA Integrated Information Infrastructure Program (IIIP), under the management of the NASA Chief Information Officer (CIO), will provide the NASA workforce with the information infrastructure and tools that adapt and evolve to support management, science, research, and technology programs and eliminate the barriers caused by single solution systems.

ICAM manages identities, credentials, physical access, and logical access in an integrated enterprise environment, thus enabling NASA to ensure that individuals have the access they need to further the NASA mission without putting agency assets at risk. The figure below shows the three major parts and functions of ICAM:

In this contract, the contractor shall support the ICAM program areas listed above.

· Participate in Federal and Agency-wide ICAM working groups to determine and review business and mission application architectures to engineer software and hardware solutions which will meet NASA and Federal requirements.

· Interpret Federal ICAM requirements articulated in the Federal ICAM Trust Framework and various supporting documentation; NIST (National Institute of Standards and Technology), FIPS (Federal Information Processing Standard) and others including FIPS 201 (PIV), NIST 800-53 (Security Controls for Information Systems), NIST 800-63 (Electronic Authentication), and NIST 800-116 (PIV in Physical Access Control Systems).

· Facilitate NASA's continued compliance with Federal ICAM initiatives including Homeland Security Presidential Directive 12 (HSPD-12), OMB M-11-11 (Continued Implementation of Homeland Security Presidential Directive Policy for a Common Identification Standard for Federal Employees and Contractors), and OMB M-19-17 (Enabling Mission Delivery through Improved Identity, Credential, and Access Management).

· As ICAM functional, security and technical requirements are discovered, assist with incorporating approved requirements into the cybersecurity technical roadmap and architecture documentation.

· Provide secure architecture and engineering planning, analysis, design, support and documentation of NASA’s ICAM integration of the Federated ICAM initiatives.

· Coordinate with other entities in the Federal Government on emerging requirements and standards.

· Act as liaison between the ICAM Program and other NASA Programs and Projects.

· Provide resources that are proficient in the areas of smartcard integration and compliance with federal computer security configuration regulations contained in NIST SP 800 series.

· Provide engineering support for technologies involving ICAM device integration, upgrades, and oversight of authentication and authorization components.

· Investigate, integrate and test new or current infrastructures, components and applications in the NASA environment.

· Provide customer support for any Personnel Identity Verification (PIV) and device certificate issue.

· Manage the ICAM component of the CSET website and make recommendations on the content and layout.

· Develop and maintain the access management workflows.

· Disseminate all pertinent information to all stakeholders as directed by the NASA POC.

· Develop and support policies, standards, handbooks and any other guidance documentation.

· Perform requirements analysis, investigated alternative solutions, performed architecture trade-off, make/buy assessments, system capacity analyses, operations concept development, and documented results for ICAM.

· Ensure all systems, technical capabilities and business processes aligned with the NASA CSPP.

· Support the development and design of the Agency authentication and authorization infrastructure into NASA business and mission systems.

· Provide knowledgeable resources in smartcard integration and compliance with the federal computer security configuration regulations.

· When requested and approved via the agency project management and change control governance process(es), provide CSET engineering resources to ensure adherence with cybersecurity requirements for all 7120.7 and 7120.8 projects, initiatives and activities that will leverage ICAM services.

· Coordinate weekly technical interchange meetings between stakeholders from each necessary external service office outside of CSPD in order to gather related requirements that will drive the development and evolution of the cybersecurity technical roadmap.

· Support the timely administration, maintenance, continual improvement, and overall security of CSET testbed infrastructure.

· Support CSET Testbed Configuration and Maintenance and assist with maintenance of the CSET System Security Plan, risk assessments, the associated dev-test facility (ETAF) and associated services.

· Support necessary testbed system integration and system testing to support CSET group engineering and development activities.

· Identify opportunities for improving the integrated dev-test environment.

· Assist with bringing parity to CSET development infrastructure with what is currently in the ICAM portfolio.

· While building out and/or closing gaps in the CSET development infrastructure, leverage existing expertise within EAST2 engineering so that CSET engineers gain knowledge of the current state of the infrastructure that will be used to support engineering of new ICAM solutions.

· Document existing ICAM portfolio designs, processes, and configuration standards to aid in the ICAM knowledge assimilation for assigned engineers to the CSET Team

· Assist in the development of ICAM-segment of the overall cybersecurity technical architecture including capabilities, services, and roadmap planning for the current and future capabilities in areas including but not limited to:

· eAuthentication infrastructure including Launchpad, SIteMinder, API Gateway and ADFS

· NASA Enterprise Directory (NED)

· NASA PKI services and data encryption/digital signing solutions including the NOCA, NICA, External Email Encryption service, Hardware security modules, and associated client-side encryption software

· Device Enrollment Gateway and related ICAM supporting NAC capabilities including NAC clients and self-registration portal

· NASA Consolidated Active Directory, associated ADMS (Active Directory Management System), and SMAD (Security Monitoring of Active Directory)

· NASA AzureAD and associated supporting infrastructure for synchronizing/establishing Cloud Identity Provider services

· Credential Issuance and lifecycle management including the Smartcard Issuance Card Management System and associated client-side applications and identity management system integrations

· PIV/ASB Mandatory Services

· NPriAMS (Password Vault) including Agency CA PAM and Center CA PAM instances

· Sailpoint (DHS Federal dashboard)

· Enterprise Physical Access Control System (EPACS)

· Device Inventory Enrollment and Management/Configuration (modern device management)

· Authenticator/Credential Issuance

· Smartcard enablement capabilities

· Privilege Access Management capabilities

· Zero Trust architecture and associated capabilities (NIST 800-207)

· Data Categorization and Protection

APPLICATIONS

The contractor shall:

· Review, analyze and document application baseline configurations and security specifications.

· Conduct security analysis and recommendations for Enterprise NASA security software.

· Assist with creating and managing applications whitelist and blacklist

CLOUD

CSET’s engineering responsibilities include NASA’s cloud environments. This includes, but is not limited to, Amazon Web Services, Google Cloud Platform, and Microsoft Azure.

The Contractor shall:

· Provide resources that are proficient in cloud computing technologies with a focus on cybersecurity.

· Provide consultation on the development of cloud environments.

· Assist with the creation and documentation of current and future state cloud architectures

· Act as a liaison between CSET and NASA’s cloud service providers

· Support NASA’s cloud service providers by ensuring cybersecurity requirements are met and efforts align with the desired cloud architecture states

· Assist applicable NASA projects as a subject matter expert to ensure cybersecurity requirements are satisfied and aligned with desired cloud architecture states

· Provide senior technical expertise in cloud security for all NASA cloud-based services

· Maintain an in-depth awareness of next generation cloud technologies and the impact they may have on the NASA environment

· Recommend cloud technologies and implementations that will maximize NASA’s investment and have the greatest impact

CYBERSECURITY NETWORK ENGINEERING AND DESIGN SUPPORT

· Support collaboration of designs and engineering of network security; including both initial design and sustaining engineering and capacity management; according to the NASA policies

· Collaborate designs of identity models, threat models and risk scoring for software defined access (SDA) /software defined network (SDN) / zero-trust network (ZTN)

· Collaborate with NASA in developing network access control policies and requirements, including specifying logging events for SDA/SDN/ZTN infrastructure

· Assist with analyzing results of log file and security event information

· Assist NASA with identifying gaps within NASA’s LAN and WAN

REMOTE ACCESS SERVICES (RAS) SUPPORT

In performance of RAS, the Contractor shall:

· Submit change requests, assist with collecting requirements and ensure effective coordination with responsible organizations utilizing the NASA provided tools.

FIREWALL SERVICES SUPPORT

The Contractor shall:

· Ensure that firewall policies are adequate to meet performance (availability and throughput) and log retention requirements.

· Collect and assess security requirements against network data flow requirements and define network firewall implementation.

· Submit change requests, assist with collecting requirements and ensure effective coordination with responsible organizations utilizing the NASA provided tools.

· Assist with developing firewall rules and configuration management of NASA Corporate enterprise, center and project network and web application firewall systems in accordance with Agency IT security policy and standards and Center IT operations procedures.

PROXY SERVICES SUPPORT

· Submit change requests, assist with collecting requirements and ensure effective coordination with responsible organizations utilizing the NASA provided tools.

· Assist with developing proxy rules and configuration management in accordance with Agency IT security policy and standards

OPERATIONAL, RESEARCH AND TEST ENVIRONMENTS

The Contractor shall:

· Support necessary system configuration, application testing, and network services to ensure that CSET group recommendations and other Agency efforts are based on sound technical solutions.

· Identify opportunities for improving the dev-test environment.

· Ensure security and availability of the environment for evaluating and testing the integration of services into the NASA environment.

· Recommend and deliver the appropriate requirements and design packages to assigned projects.

· Assist in the development and maintenance of CSET’s System Security Plans and Risk Assessments for all CSET’s systems.

· Track and maintain CSET hardware, software, and services inventory.

· Initiate and track purchase requests.

· Recommend technologies that will maximize NASA’s investment by having the greatest overall impact to the environment.

· Propose any necessary modifications to the environment to accommodate recommendations.

PROJECT MANAGEMENT TECHNICAL REVIEWS

CSET’s engineering responsibilities include significant support of NASA 7120.x and internal efforts.

The Contractor shall:

· As requested, support the IT related Agency projects (e.g. project engineering support member) and if requested, maintain membership on the System Engineering Review Team (SERT).

· Provide cybersecurity knowledge to the project team during the project lifecycle.

· Be proficient in the NASA Project Management Lifecycle.

· Track internal and external efforts by utilizing CSET’s issue tracking system (i.e. Jira)

CYBERSECUIRTY INFRASTRUCTURE (CSI)

The NASA CSPP is executing a project to manage the operations of the Continuous Diagnostics and Mitigation (CDM) Dynamic Evolving Federal Enterprise Network Defense (DEFEND) tools and resources as part of a Department of Homeland Security (DHS) program to improve NASA’s IT cybersecurity posture and situational awareness of overall IT cybersecurity health. NASA has obtained tools and licenses through the DHS CDM contract for this project and has deployed these tools across the NASA Enterprise. The CDM/DEFEND tools and other NASA tools will provide the capability to continuously monitor network devices, software and user accounts for IT system threats, vulnerabilities, and potential security violations. CSPP requires on-going assessment and recommendations of maintenance for the deployed NASA cybersecurity systems, software, and toolsets.

The Contractor shall:

· Develop and update SOPs for cybersecurity infrastructure support (Deliverable X)

· Operate, maintain and support NASA cybersecurity systems, software, and toolsets

· Perform full lifecycle project management for new cybersecurity services utilizing the NASA policies and procedures

· Assess and provide recommendations on the security and operational implementation of network infrastructure equipment

· Assess and provide recommendations on software code supporting NASA’s cyber security reporting tools

· Provide database support for Commercial Off The Shelf (COTS) and Government Off The Shelf (GOTS) cybersecurity systems

· Continually assess and provide recommendations for the secure configuration of server, storage, backup, and network appliance system infrastructure, operating systems, middleware and applications

· Provide senior cybersecurity engineering support in order to design, deploy and maintain the NASA cybersecurity systems, software, and toolsets on the NASA Operational environment

· Perform analysis, development, recommendation, and deployment methodologies for the application of NASA security controls to devices on the NASA networks

· Develop, maintain, and continuously enhance multi-level reporting and dashboard analysis of vulnerability assessment findings and compliance with prescribed security controls.

· Provide systems engineering and operational support for the NASA Logging Solution to include systems architecture, Security Information and Event Management (SIEM) application administration, and server systems administration.

· Provide operational assessments and support recommendations for CDM/DEFEND and other NASA cybersecurity systems, software, and toolsets in NASA Corporate and Mission environments

· Provide direct support to the CSPP Security Architect and Cybersecurity Integration by assisting in the coordination of cybersecurity requirements to ensure compliance with Federal mandates and NASA Enterprise security policy.

· Assess and provide recommendations on standard and emergency system updates, including security and functionality updates

· Assess and recommend disposition of access to DHS CDM requirements and other NASA tools as required

· Assess and provide guidance and recommendations for on-going cybersecurity validation of the CDM toolset and other NASA tools as required

· Assess, provide recommendations, and implementation to NASA’s CSPP on submitted CDM/DEFEND tool configuration change requests

· Assess, test, and provide recommendations on remediation for tool specific issues.

· Assess and provide recommendations on industry best practices for the NASA’s Enterprise Endpoint Security operations and maintenance

· Assess and provide Subject Matter Expert level recommendations on the configuration of the NASA enterprise cybersecurity authorization and assessment repository system.

· Participate in the Agency project meetings and/or reviews

· Provide all resources to obtain and maintain a NASA Level of Confidence (LoC) of 60

TRAINING AND AWARENESS

The Information Technology Security Awareness and Training Center (ITSATC) is responsible for providing agency-wide IT cybersecurity training, awareness activities and products. The vendor requirements in this area are focused on providing the technical expertise and support for the agency-wide IT Security training initiatives and program. This work will enable NASA to continue its efforts in safeguarding computer resources by enhancing IT cybersecurity awareness, knowledge, and skills across the Agency.

The Contractor shall:

· Support the Information Technology Security Awareness Training Center (ITSATC)

· Support outreach about cybersecurity and privacy awareness.

· Assist with the development of NASA Cybersecurity training policies, procedures and specific agreed course content, in coordination with the NASA CSPD.

· Collaborate OCHCO Training Office about cybersecurity courses.

· Develop and promote cybersecurity and privacy training strategies.

· Assist the Government with cybersecurity and privacy awareness.

· Ensure the cybersecurity and privacy training website is current.

· Provide administrative support at meetings (deliverable XX).

· Provide support agency-wide regarding FAQs, metrics data, training requests and course inquiries (deliverable xx)

· Provide resources that are proficient in the NASA provide tools

· Develop and maintain ITSATC technical training as needed

· Support any cybersecurity and privacy events

· Be knowledgeable on the latest cybersecurity and privacy trends

· Schedule all NASA Cybersecurity and Privacy courses

· Develop and support cybersecurity and privacy course materials, as needed

· Support other cybersecurity and privacy duties in relation to training and awareness

· Maintain awareness of current cybersecurity and privacy policies as it relates to NASA cybersecurity and privacy and the Federal Government. (Deliverable xx)

SUPPLY CHAIN RISK MANAGEMENT (SCRM)

The Supply Chain Risk Management (SCRM) provides awareness on supply chain risk from threat nations, in accordance with the FY2014 516 appropriation law, which governs the activities of NASA and three other agencies.

The Contractor shall:

· Operate & enhance an enterprise supply chain risk program with vendor risk intelligence and continuous monitoring

· Provide the Agency OCIO with subject matter expertise that can support the SCRM roadmap implementation.

· Collect program information from the NASA enterprise and provide reports to leadership and others as requested (OMB, Congress, GAO, IG, and CNSS)

· Ensure SCRM integration with Enterprise risk management processes by performing supply chain criticality and dependency analysis, collaboration, and information sharing of risks and to prioritize their actions

· Recommend and draft enterprise policy and procedures, in coordination with the NASA CSPD, including SCRM policy requirements into existing NASA Procurement Policies or develop a new SCRM Policy to implement an enterprise-wide SCRM program

· Recommend and draft policy and guidance, in coordination with the NASA CSPD, to include the required FIPS 199 High and/or Moderate - impact systems into the SCRM Program

· Develop Objectives and Key Results (OKRs) to demonstrate program success: Quantity of SCRM support requests, risk threshold determinations, quantity of customers and impact to enterprise, and productivity-oriented metrics(deliverable XX daily/weekly/monthly)

· Provide support for any collaborative development projects

· Perform analysis of NASA Requests for Investigation (RFIs) / IT Product Assessments and/or Product clearance questionnaires to enable NASA to make risk based acquisition decisions.

· Document risk mitigation recommendations and communicate to stakeholders.

· Maintain and transition the current NASA tool to the new NASA provided tool.

· Store all documentation and resources in the NASA approved document repository.

COMSEC SERVICES*

The NASA Office of Protective Services oversees the NASA Classified Communications Security (COMSEC) Program. The Contractor provides account management support and manage the COMEC Program at each site.

The Contractor shall:

· Serve as a COMSEC Account Manager for NASA’s COMSEC program

· Administer and maintain the NASA Secure Network

· Identify the specifications to support any requested classified containers

· Maintain an inventory of keying material and represent NASA during audits

· Ensure all encryption devices are current with the appropriate keying material

· Attend the NASA COMSEC Workshops, as requested

· Interface with the NASA Central Office of Record and, if requested, the National Security Agency (NSA)

· Provide assistance to Resident organizations and tenants on a reimbursable basis

· Provide COMSEC User training and education

SECURITY OPERATIONS CENTER (SOC)

The NASA SOC functions as the only authorized single agency-wide cybersecurity operational entity whose mission is to provide proactive prevention, detection, and response to computer security incidents targeting NASA’s unclassified networks and systems. These unclassified NASA networks and systems include but are not limited to the corporate, mission and operational technology domains across NASA’s vast spectrum.

The NASA SOC operates 24/7/365 and functions as the nerve center for all cybersecurity incident monitoring, reporting, detection, prevention, response, mitigation, and cyber threat analysis for the Agency. The NASA SOC provides the Agency with real-time, continuous cybersecurity monitoring and triage; uninterrupted event detection; incident analysis, coordination and response; situational awareness; and cybersecurity countermeasure implementation capabilities for maintaining a secure cyber and information assurance posture. Furthermore, the SOC provides incident data, data on the exposure of sensitive information and threat indicators to the Department of Homeland Security's (DHS) National Cybersecurity and Communications Integration Center (NCCIC).

As the only authorized single agency-wide cybersecurity operational entity, the NASA SOC operates from multiple distributed operation sites ensuring NASA’s corporate, mission, and operational security business continuity and security operations assurance. Distributed operations sites provide a single synchronized and collaborative entity for security operation services to the corporate, mission and operational technology domains across NASA’s vast spectrum.

These distributed operations sites operate 24/7/365 and singularly function as the nerve center for all cybersecurity incident monitoring, reporting, detection, prevention, response, mitigation, and cyber threat analysis for the Agency. Each distributed operations site is designed with operational capabilities to maintain security operations services when a distributed operations site is degraded or disabled for varying reasons or lengths of time.

SOC is the first point of contact and customer service interface for all service requests related to SOC services. SOC communicates through a variety of continually changing customer channels (currently, telephone, email, and web inquiries) to provide guidance, support, and resolve cyber incidents in a timely manner. The SOC provides support for mission applications, first call resolution for SOC service requests, and dispatch-ready cyber incident response teams to assist NASA personnel. SOC is responsible for the coordination, resolution, and closure of all SOC service requests beyond first call resolution.

The SOC receives SOC services requests through all accessible communication channels and utilizes a SOC enterprise ticket management system (Incident Management System) to track and monitor SOC service requests and incidents. The SOC is responsible for responding, prioritizing, and coordinating resolution of cyber incidents and service requests. The SOC provides remote support as well as onsite support. The SOC includes a geographically dispersed team of technicians located across NASA locations identified in Section XXX. Onsite (permanent) support is required in accordance with the locations identified in Section XXX.

The SOC provides key services to the NASA enterprise: Continuous Monitoring and Detection and Triage Analysis Support, Incident Response (IR) and Management Support, Cyber Forensics & Incident Analysis, Cyber Threat Detection & Hunt Support, Cyber Threat Analysis Support and SOC Communications and SOC System Support.

SOC CONTINUOUS MONITORING AND DETECTION (M&D) AND TRIAGE ANALYSIS SUPPORT

M&D: Provides timely identification of and response to events and resolution of issues arising from those events that indicate cyber incident. The NASA SOC will maintain a continuous monitoring capability to maintain situational awareness of current cyber security operational status and report to the affected NASA stakeholders.

Triage Analysis: The SOC Triage Analysis function handles most incoming and outgoing communication from the SOC. The primary activity of Triage Analysts is to triage end-user actions, coming into the SOC. The secondary function of SOC Triage Analysis is to provide real time-triage analysis of security-relevant feeds from NASA SOC tools and agency security systems. Triage Analysis will identify potentially malicious or unauthorized cyber events that require further analysis. Triage Analysis will categorize and prioritize the cyber events and other SOC service requests. Triage Analysis escalate cyber incidents that require further in-depth analysis to SOC Incident Analysis.

The Contractor shall:

· Maintain 24x7x365 staffing on premises at the two NASA SOC Distributed Operating Sites

· Balance 24/7/365 staffing workload/staffing/coverage between the two designated NASA SOC Distributed Operations Sites to ensure business continuity of NASA SOC to provide 100% Triage and Monitoring & Detection coverage for an initial 24 hours of unscheduled outage and 50% Triage and Monitoring & Detection coverage beyond the initial 24 hours of any unscheduled outage from either distributed operation site. If one distributed location suffers an unscheduled / unplanned outage that affects the operational capabilities of that one location, the other distributed operations site must be able sustain 100% of workload of both locations for a duration of 24 hours and then a diminished sustainment of 50% of workload for the remaining duration of a single site outage

· Ensure there is staff on all shifts with access to the National Security System (NSS) Secret physical space(s) to include access to voice/data workstations/devices, maintain active user and email accounts, and access to physical safes in those designated space(s)

· Provide situational awareness throughout NASA on cybersecurity-related issues impacting NASA enterprise.

· Develop, update and maintain the SOPs for SOC continuous monitoring, detection, and triage functions (Deliverable XXX).

· Develop and maintain a dashboard(s) or tracking technology to track the SOC tasks, status, and compliance of orders and directives including, but not limited to, SOC SAR, SOC MAR and DHS/CISA directives to display on NASA collaboration services and multimedia (i.e. SOC Video Wall)

· Develop, maintain, and leverage system default dashboard (s) to provide real-time status of SOC monitoring tools and executive-level views for daily and weekly briefs that can be presented on NASA collaboration services and multimedia (i.e. SOC Video Wall)

· Develop, maintain, and provide a daily morning brief and an end-of-day brief to provide current cyber security posture, issuance of directives, cyber events, and compliance status (Deliverable XXX).

· Develop, maintain, and provide a weekly brief that captures all of the cyber events with metrics and trends (Deliverable XXX).

· Provide trend analysis and reports on cybersecurity activity (Deliverable XXX) such as higher echelon directives, log/monitoring reports from Security Information and Event Management (SIEM), alerts, incident status, trouble ticket status, and firewall and web content filtering metrics.

· Document and track incidents (currently via IMS) in accordance with the reporting procedure and archive historical SOC data.

· Submit and track all service tickets submitted on behalf of NASA SOC internally and to external organizations.

· Obtain and maintain accounts from external government agencies in order to receive reports from multiple sources to incorporate into SOC briefs and distribute to stakeholders.

· Maintain situational awareness on cyber incidents and activity with the appropriate government partners (e.g., FBI, CIA, NSA, USCYBERCOM, etc.) via various tools and reporting mechanisms (e.g., DHS/CISA, NASA IMS).

· Review and determine if external reports, orders, and directives are applicable to NASA enclaves and execute response actions as required.

· Develop, update, and manage the existing NASA secure collaborative web presence (e.g. SharePoint site) and coordinate operations, maintain libraries, briefs, and SOC technical training.

· Develop, update, and manage the content of NASA SOC current and future web presence on the NASA SOC web sites.

· Provide weekly status reports on all relevant events impacting NASA networks (Deliverable XXX).

· Provide user account administration and creation and assistance with user registration and respond to user account requests (e.g. SOC mailing list, Call down rosters, IMS account resets, POCs)

· Provide timely acknowledgement of SOC service requests, problem identification, root cause analysis, escalation, resolution, and closure for all SOC service requests in accordance with SLAs.

· Provide customers a self-help capability, such as SOC intranet site, and continually enhance self-service capabilities to reduce SOC service requests.

· Document and track call metrics, service request/resolutions, and analyze trends (Deliverables XXX) to implement measures that prevent recurring problems and improve customer experience. Trend analysis and reporting shall be customized based on the request of the Government (may request details on the type of technical issue, location, tier, etc.).

· Provide a weekly status report (Deliverable XX) on all call and service metrics.

· Provide customer service satisfaction measurements (e.g., surveys) (Deliverable XX).

· Provide internal SOC training and knowledge transfer as required

INCIDENT RESPONSE (IR) & MANAGEMENT SUPPORT

NASA IR function protects, monitors, analyses, detects, and responds to unauthorized activity on NASA information systems and networks. The contractor shall respond to incidents with the approved courses of action that focus on containment, eradication, and recovery. The contractor shall conduct initial and final incident reports in accordance with DHS/CISA Federal Incident Notification Guidelines, NASA Incident Response Management IT Security Handbook, NIST 800-61, or subsequent versions, and all other applicable government mandates. All reporting shall be conducted in accordance with government-mandated timelines. All technical details and reports shall be maintained on a central IM repository (currently via IMS). IR support is required 24/7/365. The contractor shall support a comprehensive intrusion detection/intrusion prevention and incident response capability, in coordination with the NASA SOC. Intrusion detection is the full range of activities aimed at detecting attempts to compromise the confidentiality, integrity or availability of NASA’s network and information resources. Intrusion prevention is the full range of activities aimed at continuously monitoring the network, looking for malicious incidents and capturing information about them. This includes, but is not limited to, examining network traffic, log files or other evidence for signs of intrusions. Incident response includes activities such as preparation, identification, analysis, investigation, containment, eradication, recovery, reporting, and follow-up.

The Contractor shall:

· In support of NASA SOC, maintain 24x7x365 staffing on premises at the two NASA SOC Distributed Operating Sites.

· Balance 24/7/365 staffing workload/staffing/coverage between the two designated NASA SOC Distributed Operations Sites to ensure business continuity of NASA SOC to provide 100% IR coverage for an initial 24 hours of unscheduled outage and 50% IR coverage beyond the initial 24 hours of any unscheduled outage from either distributed operation site. If one distributed location suffers an unscheduled / unplanned outage that affects the operational capabilities of that one location, the other distributed operations site must be able sustain 100% of workload of both locations for a duration of 24 hours and then a diminished sustainment of 50% of workload for the remaining duration of a single site outage.

· In support of IR at NASA facilities, maintain on premise coverage during the designated core hours; after hour support on call; must respond on premise within 2 hours of notification

· Ensure there is staff with access to the National Security System (NSS) Secret physical space(s) to include access to voice/data workstations/devices, maintain active user and email accounts, and access to physical safes in those designated space(s).

· Develop, update and maintain the SOPs for IR

· Respond to cyber incidents, perform initial incident triage, contain, mitigate and report

· Track, document, and report incidents from initial detection to final resolution in accordance with NASA procedures and timelines

· Provide after action incident reports

· Analyze and correlate incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation.

· Analyze SOC provided cyber intelligence threats reports to include but not limited to SOC MARs, SARs, and DHS/CISA Emergency Directives.

· Provide analysis reports to potentially affected…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .