Enclosure 5 IT Security Management Plan Template.pdf

PDF 3 MB Posted

Attached to
DRAFT RFP - Repairs, Operations, Maintenance, and Engineering (ROME) Services - DRAFT RFP Federal contract opportunity
Solicitation number
80GSFC22R0011-DRFP
Issued by
National Aeronautics and Space Administration Goddard Space Center

About this file

This document is an Information Technology Security Management Plan template for a federal contract. The template outlines requirements for an IT security plan covering a contract to provide facilities support services at the Goddard Space Flight Center in Greenbelt, Maryland and Wallops Flight Facility in Wallops Island, Virginia. The services include facilities operations and maintenance, architect-engineering services, construction, and facilities information resources support. Facilities range from office buildings to technical facilities such as clean rooms, laboratories, and launch facilities supported by utilities including electrical power, water, wastewater, steam, chilled water, gas, fire alarm, and geothermal systems. The template provides sections for contract identification details, applicable security control implementations, and requirements for Federal Information Security Management Act reporting.

View the file

Other files for this federal contract opportunity

Other files attached to DRAFT RFP - Repairs, Operations, Maintenance, and Engineering (ROME) Services - DRAFT RFP, newest first.
File Type Posted
M.1 WD CBA 2022-99 Maryland.pdf r1.pdf PDF
ROME E-Library Documents.zip ZIP file
Exhibits 1-13A ROME COST.pdf PDF
Attachment A - ROME Contract SOW.pdf PDF
Attachment B IDIQ Cost-Fixed Price Rate Matrix All IDIQ Contract.pdf PDF
Attachment C - List of IAGP.pdf PDF
Attachment D DD254.pdf PDF
Attachment E A-E Const IDIQ Pricing.pdf PDF
Attachment G IT Security Applicable Documents List.pdf PDF
M.1 WD CBA 2022-99 Maryland.pdf PDF
N.1 Davis Bacon Wage Determination MD 20220044.txt TXT text file
O.1 Wage Determination SCA MD 2015-4281.txt TXT text file
Appendix 2 - ROME A-E Specifications.pdf PDF
Appendix 3 - FMD CADD Manual 2021.pdf PDF
Appendix 6 - WFF Asset List and Count.pdf PDF
Appendix 5 - GB Asset Listing and count.pdf PDF
Attachment D DD254-ROME.pdf PDF
Attachment F Quality Control Plan.pdf PDF
Attachment J Contract Historical Data.pdf PDF
O.2 Wage Determination SCA VA 2015-4327.txt TXT text file
Appendix 12 As-Built.pdf PDF
Appendix 10 - ROME Specifications.pdf PDF
Appendix 1 - ROME SRD -2021 .pdf PDF
Appendix 14 Snow and Ice Removal GB.pdf PDF
Appendix 18 Snow Removal Area 200 GB.pdf PDF
80GSFC22R0011 ROME DRFP.pdf PDF
Exhibits 15-15E A-E Const IDIQ Pricing.pdf PDF
Enclosure 1 ROME RTO1 Greenbelt OM IR.pdf PDF
Enclosure 2 ROME RTO2 WFF OM IR.pdf PDF
Enclosure 4 ROME QA Surveillance Plan.pdf PDF
Attachment I OCI Avoidance Plan Outline.pdf PDF
Attachment L ROME FINANCIAL REPORTING 533.pdf PDF
Attachment M Collective Bargaining Agreement.pdf PDF
M.2 WD CBA 2022-134 Virginia.pdf PDF
Attachment O Wage Determinations SCA.pdf PDF
Appendix 8 - RESERVED.pdf PDF
Appendix 16 Snow Removal Sidewalks GB.pdf PDF
Appendix 4 - List of Facilities final.pdf PDF
80GSFC22R0011 SF33 ROME DRFP.pdf PDF
Appendix 4 - List of Facilities.pdf PDF
Appendix 7 - Navy SCSC Assets.pdf PDF
Exhibit 14 ROME Past Perf Questionaire.pdf PDF
Enclosure 3 ROME RTO3 Navy OM IR.pdf PDF
Attachment C1 - GB List of IAGP.pdf PDF
Attachment C2 - Wallops List of IAGP.pdf PDF
Attachment H IT Security Management Plan.pdf PDF
Attachment K Safety and Health Plan.pdf PDF
Attachment N Wage Determinations Building.pdf PDF
N.2 Davis Bacon Wage Determination VA 20220007.txt TXT text file
Appendix 17 Snow Removal Area 100 GB.pdf PDF
Show all 50

DRAFT RFP - Repairs, Operations, Maintenance, and Engineering (ROME) Services - DRAFT RFP has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Information Technology Security Management Plan

Issue Date Effective Date:

SENSITIVE BUT UNCLASSIFIED

(SBU) Version 7 03/2021

(Insert Contract # Here)

IT Security Management Plan Review and Approval

This Information Technology Security Management Plan (ITSMP) for the was prepared for the exclusive use of NASA and completed on

I have reviewed the contents of this plan, and believe that it presents an accurate representation.

Reviewed by: ________________________________

ISSO, or equivalent Date

Concurred by: ________________________________

COR/Task Monitor Date

Approved by: ________________________________

Center CISO Date

Accepted by: ________________________________

Contracting Officer Date

SENSITIVE BUT UNCLASSIFIED

Contents

Change History .......................................................................................................................................................................................... ii IT Security Management Plan Review and Approval ............................................................................................................................... iii 1 Contract Identification

1.1 Contract Name

1.2 Contract Number

1.3 Responsible Organization

1.4 Contact Information

1.4.1 Physical Location

1.4.2 Points of Contact

1.5 General Contract Description

1.5.1 Information System Categorization

1.5.2 Security Categorization

1.5.3 Information System

1.5.4 Contractor Badging

1.5.5 Supply Chain Risk Management (SCRM)

1.5.6 Related Laws/Regulations/Policies

2 Security Control Implementations 3 Federal Information Security Management Act (FISMA) Reporting Appendix A: Acronyms

1.5.6 Related Laws/Regulations/Policies

• 5 U.S.C. 552, Freedom of Information Act, 1967

• 5 U.S.C. 552a, Privacy Act, 1974

• FIPS 199, Standards for Security Categorization of Federal Information and Information Systems

• FIPS 200, Minimum Security Requirements for Federal Information and Information Systems

• NIST SP 800-18 Rev. 1, Guide for Developing Security Plans for Federal Information Systems

• NIST SP 800-30 Rev. 1, Guide for Conducting Risk Assessments

• NIST SP 800-34 Rev. 1, Contingency Planning Guide for Information Technology Systems

• NIST SP 800-37 Rev. 2, Guide for the Security Authorization of Federal Information Systems

• NIST SP 800-42, Guideline on Network Security Testing

• NIST SP 800-53 Rev. 4, Recommended Security Controls for Federal Information Systems

• NIST SP 800-53A Rev. 4, Techniques and Procedures for Verifying the Effectiveness of Security Controls in Federal

Information Systems

• NIST SP 800-60 v1 Rev. 1, Guide for Mapping Types of Information and Information Systems to Security Categories

• NIST SP 800-61 Rev. 2, Computer Security Incident Handling Guide

• NIST SP 800-64 v1, Security Considerations in the Information System Development Life Cycle

• OMB Circular A-130, Appendix III, Security of Federal Automated Information Systems

• Public Law (PL) 99-474, The Computer Fraud and Abuse Act of 1986

• PL 93-502 -Freedom of Information Act 1974

• Presidential Decision Directive (PDD-63), Critical Infrastructure Protection Federal Information Security Management Act of 2002 (FISMA)

• NPR 2810.1A, Security of Information Technology

Additional Information: If there is any additional information that you wish to provide, please use the box below.

Version 7 03/2021

File details come from the government source that posted it. Updated .