Enclosure 2 - IT Security Management Plan Template.pdf

PDF 1 MB Posted

Attached to
Environmental Services Follow-on Federal contract opportunity
Solicitation number
80GSFC20R0005
Issued by
National Aeronautics and Space Administration Goddard Space Center

About this file

This document contains an IT Security Management Plan template for a federal contract to provide environmental services. The template outlines security controls and procedures that will be implemented to protect any federal information systems used during contract performance. Key details include categorizing information and systems as sensitive but unclassified, describing security roles and responsibilities, and identifying applicable federal laws and regulations regarding information security, such as FISMA and NIST guidance. The template requests information about the contract, such as the number, responsible organization, and general description. It also includes sections for change history, review and approval, and an acronym list appendix.

The related federal contract opportunity notice is for environmental services follow-on work at NASA's Goddard Space Flight Center and Wallops Flight Facility. The hybrid cost-plus-fixed-fee contract has a potential five-year period of performance. Services will help meet environmental regulatory requirements and stewardship objectives. The solicitation number is provided, as well as details on submitting any procurement questions. An electronic library with supporting documents is available online. The response due date is listed as May 20, 2020.

View the file

Other files for this federal contract opportunity

Other files attached to Environmental Services Follow-on, newest first.
File Type Posted
Set 4 Environmental Questions and Answers 80GSFC20R0005.pdf PDF
Set 1 Environmental Questions and Answers 80GSFC20R0005.pdf PDF
SF30 Amendment 3 to 80GSFC20R0005.pdf PDF
Set 2 Environmental Questions and Answers 80GSFC20R0005.pdf PDF
Set 3 Environmental Questions and Answers 80GSFC20R0005.pdf PDF
Enclosure 1 - RFP Clauses - 6-9-20.pdf PDF
Attachment C - Wallops IAGP_list 6-9-20.pdf PDF
Set 2 Envrionmental Questions and Answsers 80GSFC20R0005.pdf PDF
Signed SF30 Amend 2 to 80GSFC20R0005.pdf PDF
SF1408-14b (1).pdf PDF
Final Amendment 2 Pg 2 - 29.pdf PDF
Enclosure 8 - SF1408 Cover Page.pdf PDF
Attachment F - Work Breakdown Struction - replace pge 3 WBS 20200518 corrected.pdf PDF
SF30 - Amendment 1 to 80GSFC20R0005 - CO Signed.pdf PDF
Enclosure 1 - Form -- SF33-14a - Amendment 1.pdf PDF
Amendment 1 Pg 2 - 4.pdf PDF
Set 1 Envrionmental Questions and Answsers 80GSFC20R0005.pdf PDF
Enclosure 7 - Work Load Indicators Document - corrected.pdf PDF
Enclosure 1 - RFP Clauses - 5-15-20.pdf PDF
Attachment A - SOW.pdf PDF
Enclosure 6 - Cover Pg RTOs.pdf PDF
Attachment I - OCI Avoidance Plan.pdf PDF
GPM Exhibits 1A-1B Hybrid Core-IDIQ Std by CY MAR 2016.pdf PDF
Enclosure 8 - Contract Historical Data.pdf PDF
signed Cover Letter Final RFP.pdf PDF
Enclosure 4 - QASP.pdf PDF
Enclosure 1 - Cover Pg - SF33 Clauses w Attachments.pdf PDF
Enclosure 5 - GPM-Specified Non-Mgmt DL Categories DL Hours and PDs Enclosure.pdf PDF
Enclosure 3 - OCI Cover Pg.pdf PDF
Enclosure 6 - RTO 1 Release Response and Remediation.pdf PDF
Enclosure 2 - IT Sec Mgmt Plan Cover Pg.pdf PDF
Enclosure 1 - RFP Clauses.pdf PDF
Attachment F WBS Breakdown.pdf PDF
Enclosure 6 - RTO 2 WFF Fiberoptics EA.pdf PDF
Attachment D - 533 Attach Core and IDIQ--Both Onsite and Offsite.pdf PDF
Attachment C - Cover Pg Govt Property.pdf PDF
Attachment C - Wallops IAGP_list Feb 2020.pdf PDF
Attachment H - Rate Matrix.pdf PDF
Attachment A - SOW.pdf PDF
Attachment J - IT Sec Mgmt Plan.pdf PDF
Enclosure 1 - Form -- SF33-14a.pdf PDF
Attachment C - IAGP MEMD EquipmentRpt.pdf PDF
Attachment B - PIV Attachment.pdf PDF
Attachment K - IT Security Applicable Documents List.pdf PDF
EXHIBITS 1 - 18 Cost Exhibits Cover Pg.pdf PDF
Enclosure 7 - Work Load Indicators Document.pdf PDF
Attachment E - Safety and Health Plan.pdf PDF
Attachment G - Contract Historical Data.pdf PDF
Enclosure 3 - Template OCI Avoidance Plan Outline.pdf PDF
GPM Exhibits 2-18 Hybrid Core-IDIQ by CY OCT 2016.pdf PDF
Show all 50

Environmental Services Follow-on has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SENSITIVE BUT UNCLASSIFIED (SBU)

Information Technology Security Management Plan

Issue Date Effective Date:

Version 1 03-01-17

(Insert Contract # Here)

IT Security Management Plan Review and Approval

This Information Technology Security Management Plan (ITSMP) for the was prepared for the exclusive use of NASA and completed on

I have reviewed the contents of this plan, and believe that it presents an accurate representation.

Reviewed by: ________________________________

ISSO, or equivalent Date

Concurred by: ________________________________

COR/Task Monitor Date

Approved by: ________________________________

Center CISO Date

Accepted by: ________________________________

Contracting Officer Date

Contents

Change History .......................................................................................................................................................................................... ii IT Security Management Plan Review and Approval ............................................................................................................................... iii 1 Contract Identification

1.1 Contract Name

1.2 Contract Number

1.3 Responsible Organization

1.4 Contact Information

1.4.1 Physical Location

1.4.2 Points of Contact

1.5 General Contract Description

1.5.1 Information System Categorization

1.5.2 Security Categorization

1.5.3 Information System

1.5.4 Contractor Badging

1.5.5 Supply Chain Risk Management (SCRM)

1.5.6 Related Laws/Regulations/Policies

2 Security Control Implementations 3 Federal Information Security Management Act (FISMA) Reporting Appendix A: Acronyms

1.5.6 Related Laws/Regulations/Policies

• 5 U.S.C. 552, Freedom of Information Act, 1967

• 5 U.S.C. 552a, Privacy Act, 1974

• FIPS 199, Standards for Security Categorization of Federal Information and Information Systems

• FIPS 200, Minimum Security Requirements for Federal Information and Information Systems

• NIST SP 800-18, Guide for Developing Security Plans for Federal Information Systems

• NIST SP 800-30, Risk Management Guide for Information Technology Systems

• NIST SP 800-34, Contingency Planning Guide for Information Technology Systems

• NIST SP 800-37, Guide for the Security Authorization of Federal Information Systems

• NIST SP 800-42, Guideline on Network Security Testing

• NIST SP 800-53, Recommended Security Controls for Federal Information Systems

• NIST SP 800-53A, Techniques and Procedures for Verifying the Effectiveness of Security Controls in Federal Information

Systems

• NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories

• NIST SP 800-61, Computer Security Incident Handling Guide

• NIST SP 800-64, Security Considerations in the Information System Development Life Cycle

• OMB Circular A-130, Appendix III, Security of Federal Automated Information Systems

• Public Law (PL) 99-474, The Computer Fraud and Abuse Act of 1986

• PL 93-502 -Freedom of Information Act 1974

• Presidential Decision Directive (PDD-63), Critical Infrastructure Protection Federal Information Security Management Act of 2002 (FISMA)

• NPR 2810.1, Security of Information Technology

Additional Information: If there is any additional information that you wish to provide, please use the box below.

File details come from the government source that posted it. Updated .