Enclosure 1_ITSMP_Template.pdf
PDF 3 MB Posted
- Attached to
- Commercial SmallSat Data Acquisition (CSDA) Program, Final RFP Federal contract opportunity
- Solicitation number
- 80HQTR23R0007
About this file
This document contains an Information Technology Security Management Plan (ITSMP) template for a National Aeronautics and Space Administration (NASA) contract. The ITSMP addresses how the contractor will manage personnel and processes associated with IT security on the contract. It requires contractors to describe security processes and procedures for ensuring appropriate protection of developed, processed, or used IT resources. The contractor must submit the completed ITSMP within 30 days of contract award. The template outlines required sections for contract identification, security control implementations, and Federal Information Security Management Act reporting requirements. It provides guidance on documenting management, operational, and technical security controls.
This opportunity posting is a solicitation for the Commercial SmallSat Data Acquisition Program. NASA seeks to acquire earth observation data and related services from commercial vendors to support its Science Mission Directorate's earth science research and applications. Contractors must adhere to government-defined End User License Agreements for disseminating and sharing commercial data with other US agencies and partners. The solicitation involves a multiple-award IDIQ contract with a five-year ordering period and the ability to issue fixed-price task orders. The NAICS code is 541990 with a $19.5 million small business size standard. Responses are due as outlined on the attached statement of work and EULA documents.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amend 002 - Enclosure 1_ITSMP_Template._Rev2.pdf | ||
| 80HQTR23R0007_CSDA FRFP_Amend 002_Conformed Solicitation.pdf | ||
| Amend 002 - Attachment B_EULA_Rev1.pdf | ||
| Amend 002 - Attachment H_IT Sec Applicable Doc List_Rev1.pdf | ||
| Amend 002 - Enclosure 1_ITSMP_Template._Rev1.pdf | ||
| 80HQTR23R00007_Amendment 002_Exe.pdf | ||
| CSDA FRFP Q-A.pdf | ||
| 80HQTR23R0007_Amendment 001.pdf | ||
| 80HQTR23R0007_FRFP Cover Ltr.pdf | ||
| Attachment D_Price List Template.pdf | ||
| Attachment F_CDRL.pdf | ||
| Attachment C_Catalog_Cover Page.pdf | ||
| Attachment G_DEIA Plan Cover Pg.pdf | ||
| 80HQTR23R0007_CSDA FRFP.pdf | ||
| Attachment A_SOW.pdf | ||
| Attachment B_EULA.pdf | ||
| Enclosure 2_TO Sample.pdf | ||
| Attachment E_ITSMP_Cover Page.pdf | ||
| Attachment H_IT Sec Applicable Doc List.pdf | ||
| Attachment I_2003 CRSP.pdf |
Show all 20
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CUI
VERSION 8 2/2022
Preface To carry out its wide-ranging responsibilities, the National Aeronautics and Space Administration (NASA), and its employees and managers have access to diverse and complex automated information systems, which include file servers, local and wide area networks running on various platforms, and telecommunications systems to include communications equipment. The offices within NASA depend on the confidentiality, integrity, and availability of these systems and their data in order to accomplish day-to-day activities.
This plan shall describe the processes and procedures that will be followed to ensure appropriate security of IT resources that are developed, processed, or used under this contract. Unlike the IT security plan, which addresses the IT system, the IT Security Management Plan addresses how the contractor will manage personnel and processes associated with IT Security on the instant contract.
The ITSMP is a document required by the NASA FAR to be created and submitted within 30 days of contract award for all contracts, regardless of whether they encompass an information system. The ITSMP should be utilized by all contracts to satisfy the ITSMP FAR clause requirement. Additionally, if the contractor is responsible for an external information system, this document may be leveraged for the completion of an external information system IT Security Plan (reference Information Technology Security Handbook ITS- HBK-AASTEP5.v1.0.0).
VERSION 8 2/2022
Contents Preface ....................................................................................................................................................................................................... ii
Change History ......................................................................................................................................................................................... iii
IT Security Management Plan Review and Approval ............................................................................................................................... iv
1 Contract Identification
1.1 Contract Name
1.2 Contract Number
1.3 Responsible Organization
1.4 Contact Information
1.4.1 Physical Location
1.4.2 Points of Contact
1.5 General Contract Description
1.5.1 Information System
1.5.2 Contractor Badging
1.5.3 Supply Chain Risk Management (SCRM)
1.5.4 Related Documents
2 Security Control Implementations
2.1 Management Controls
2.2 Operational Controls
2.3 Technical Controls
3 Federal Information Security Management Act (FISMA) Reporting
Appendix A: Acronyms
VERSION 8 2/2022
1.5.3 Supply Chain Risk Management (SCRM)
Will IT components be procured/purchased in performance of the contract?
Yes No
Are you meeting Federal SCRM requirements documented in the Consolidated Appropriations Act, 2021 (Section 208)?
Yes No
1.5.4 Related Documents
5 U.S.C. 552, Freedom of Information Act, 1967 5 U.S.C. 552a, Privacy Act, 1974 FIPS 199, Standards for Security Categorization of Federal Information and Information Systems FIPS 200, Minimum Security Requirements for Federal Information and Information Systems NIST SP 800-18, Guide for Developing Security Plans for Federal Information Systems NIST SP 800-30, Risk Management Guide for Information Technology Systems NIST SP 800-34, Contingency Planning Guide for Information Technology Systems NIST SP 800-37, Guide for the Security Authorization of Federal Information Systems NIST SP 800-42, Guideline on Network Security Testing NIST SP 800-53, Recommended Security Controls for Federal Information Systems NIST SP 800-53A, Techniques and Procedures for Verifying the Effectiveness of Security Controls in Federal Information
Systems NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories NIST SP 800-61, Computer Security Incident Handling Guide NIST SP 800-64, Security Considerations in the Information System Development Life Cycle OMB Circular A-130, Appendix III, Security of Federal Automated Information Systems Public Law (PL) 99-474, The Computer Fraud and Abuse Act of 1986 PL 93-502 -Freedom of Information Act 1974 Presidential Decision Directive (PDD-63), Critical Infrastructure Protection Federal Information Security Management Act of 2002 (FISMA) NPR 2810, Security of Information Technology H.R.133-Consolidated Appropriations Act, 2021 (Section 208)
N/A
VERSION 8 2/2022
The organization establishes terms and conditions, consistent with any trust relationships established with other organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to
a. Access the information system from the external information systems; and
b. Process, store, and/or transmit organization-controlled information using the external information systems.
3 Federal Information Security Management Act (FISMA) Reporting The contractor shall adhere to the NASA FISMA reporting requirements and provide inputs upon request. In general this includes:
Security Control Review/Assessment Date Authorization to Process/Store (ATP/S) Date2
Contingency Plan Test Date Contingency Plan Test Type (Tabletop, Simulation or Full)
2 ATP/S is not applicable to contactors who are not operating an external system, rather, components used in the performance of the contract are covered under an internal, NASA information system.
File details come from the government source that posted it. Updated .