D. ENCLOSURE 2 SEM IT Security Management Plan.pdf
PDF 1 MB Posted
- Attached to
- MARS SAMPLE RETURN (MSR) CAPTURE, CONTAINMENT AND RETURN SYSTEM (CCRS) EARTH ENTRY SYSTEM (EES) SPIN EJECT MECHANISM (SEM) Request for Proposals Amendment 5 Federal contract opportunity
- Solicitation number
- 80GSFC21R0039
About this file
This document contains an Information Technology Security Management Plan (ITSMP) for a NASA contract. The ITSMP outlines security controls that will be implemented to protect information systems and data involved in the contract. It identifies the contract name and number, responsible organization, physical and contact information, system categorization, security categorization, information system details, badging requirements, supply chain risk management practices, and applicable laws and regulations. Security controls covered include access control, awareness and training, audit and accountability, configuration management, contingency planning, identification and authentication, incident response, maintenance, media protection, physical and environmental protection, planning, personnel security, risk assessment, system and services acquisition, system and communications protection, and system and information integrity. The document also addresses FISMA reporting requirements and includes an acronyms appendix.
This federal contract opportunity is a solicitation from NASA's Goddard Space Flight Center for a Spin Eject Mechanism as part of the Mars Sample Return Capture, Containment and Return System Earth Entry System. Offerors are invited to submit proposals by October 12, 2021 for the preliminary design, final design, fabrication, integration and testing, delivery, and post-delivery support. The NAICS code is 336414 and the small business size standard is 1,250 employees. The contract type will be cost-plus-fixed-fee and has a delivery period of 27 months, with anticipated award by March 2022. The solicitation, amendments, and any communications should be through the identified contracting officer.
View the file
Other files for this federal contract opportunity
Show all 50
MARS SAMPLE RETURN (MSR) CAPTURE, CONTAINMENT AND RETURN SYSTEM (CCRS) EARTH ENTRY SYSTEM (EES) SPIN EJECT MECHANISM (SEM) Request for Proposals Amendment 5 has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SENSITIVE BUT UNCLASSIFIED (SBU)
Information Technology Security Management Plan
Issue Date Effective Date:
Version 1 03-01-17
(Insert Contract # Here)
IT Security Management Plan Review and Approval
This Information Technology Security Management Plan (ITSMP) for the was prepared for the exclusive use of NASA and completed on
I have reviewed the contents of this plan, and believe that it presents an accurate representation.
Reviewed by: ________________________________
ISSO, or equivalent Date
Concurred by: ________________________________
COR/Task Monitor Date
Approved by: ________________________________
Center CISO Date
Accepted by: ________________________________
Contracting Officer Date
Contents
Change History .......................................................................................................................................................................................... ii IT Security Management Plan Review and Approval ............................................................................................................................... iii 1 Contract Identification
1.1 Contract Name
1.2 Contract Number
1.3 Responsible Organization
1.4 Contact Information
1.4.1 Physical Location
1.4.2 Points of Contact
1.5 General Contract Description
1.5.1 Information System Categorization
1.5.2 Security Categorization
1.5.3 Information System
1.5.4 Contractor Badging
1.5.5 Supply Chain Risk Management (SCRM)
1.5.6 Related Laws/Regulations/Policies
2 Security Control Implementations 3 Federal Information Security Management Act (FISMA) Reporting Appendix A: Acronyms
1.5.6 Related Laws/Regulations/Policies
• 5 U.S.C. 552, Freedom of Information Act, 1967
• 5 U.S.C. 552a, Privacy Act, 1974
• FIPS 199, Standards for Security Categorization of Federal Information and Information Systems
• FIPS 200, Minimum Security Requirements for Federal Information and Information Systems
• NIST SP 800-18, Guide for Developing Security Plans for Federal Information Systems
• NIST SP 800-30, Risk Management Guide for Information Technology Systems
• NIST SP 800-34, Contingency Planning Guide for Information Technology Systems
• NIST SP 800-37, Guide for the Security Authorization of Federal Information Systems
• NIST SP 800-42, Guideline on Network Security Testing
• NIST SP 800-53, Recommended Security Controls for Federal Information Systems
• NIST SP 800-53A, Techniques and Procedures for Verifying the Effectiveness of Security Controls in Federal Information
Systems
• NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories
• NIST SP 800-61, Computer Security Incident Handling Guide
• NIST SP 800-64, Security Considerations in the Information System Development Life Cycle
• OMB Circular A-130, Appendix III, Security of Federal Automated Information Systems
• Public Law (PL) 99-474, The Computer Fraud and Abuse Act of 1986
• PL 93-502 -Freedom of Information Act 1974
• Presidential Decision Directive (PDD-63), Critical Infrastructure Protection Federal Information Security Management Act of 2002 (FISMA)
• NPR 2810.1, Security of Information Technology
Additional Information: If there is any additional information that you wish to provide, please use the box below.
File details come from the government source that posted it. Updated .