Enclosure CC - IT Security Management Plan Template.pdf

PDF 1 MB Posted

Attached to
Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) Federal contract opportunity
Solicitation number
80TECH21R0007
Issued by
National Aeronautics and Space Administration

About this file

This document is an Information Technology Security Management Plan template for a NASA contract. The template provides guidance for contractors on developing an IT security plan covering their responsibilities to protect NASA information systems and data during contract performance. Key details include categorizing the information system as low-impact according to FIPS 199, requiring at minimum a moderate security control baseline from NIST SP 800-53, and complying with laws and regulations such as FISMA, the Privacy Act, and NASA security policies. Contractors must also implement security controls, report security incidents, ensure supply chain risks are managed, and obtain badges for physical access. The related federal contract opportunity is a solicitation from NASA to provide cybersecurity and privacy enterprise solutions, services, and support across all NASA centers to strengthen IT security posture and compliance under the OCIO.

View the file

Other files for this federal contract opportunity

Other files attached to Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS), newest first.
File Type Posted
80TECH21R0007 Amendment 02.pdf PDF
Exhibit 1 - 21 Cost Templates Amendment 02.xlsx XLSX spreadsheet
Questions and Answers for 80TECH21R0007 - Amendment 02.pdf PDF
Questions and Answers for 80TECH21R0007.pdf PDF
80TECH21R0007 Amendment 01.pdf PDF
Attachment A - CyPrESS PWS Updated Amendment 01.pdf PDF
Enclosure DD - Estimated Historical Core Labor Updated Amendment 01.pdf PDF
Enclosure EE Labor Categories Updated Amendment 01.xlsx XLSX spreadsheet
Exhibit 1 - 21 Cost Templates Updated Amendment 01.xlsx XLSX spreadsheet
Attachment E - Attachment 1 to DD Form 254_20210125 DRAFT.pdf PDF
Attachment G - Safety and Health Plan Cover Page.pdf PDF
Attachment H - Small Business Subcontracting Plan Cover Page.pdf PDF
Attachment L - IT Security Management Plan Cover Page.pdf PDF
Attachment N - Phase-in Plan Cover Page.docx DOCX document
Exhibit 22 - L-1 Business Systems Reviews and Status Information Template.xlsx XLSX spreadsheet
Enclosure AA - Quality Assurance Surveillance Plan (QASP).pdf PDF
Enclosure CC - Cover Page.pdf PDF
Enclosure DD - Estimated Historical Core Labor.pdf PDF
Historical Data - MITS II-pws section 3.pdf PDF
Attachment C - Data Requirements Descriptions.pdf PDF
Attachment I - Installation Accountable Government Property (IAGP) Cover Page.pdf PDF
Attachment P - DIRECT LABOR RATES AND INDIRECT RATES AND FEE MATRICES.pdf PDF
Attachment Q - Fixed Price Rate Matrix.pdf PDF
Historical Data - LAMPS_2_PWS_rev_11_102720.pdf PDF
Enclosure BB - CyPrESS CPAF PEP Core Plus IDIQ Services.pdf PDF
Attachment E - DD Form 254 Contract Security Classification Specification.pdf PDF
Attachment B - Applicable Documents List.pdf PDF
Attachment D - Financial Management Reporting.pdf PDF
Attachment J - OCI Avoidance Plan Cover Page.pdf PDF
Attachment O - Wage Determinations.pdf PDF
Exhibit 23 - L-2 Cognizant Audit Office Template.xlsx XLSX spreadsheet
Exhibit 24 PastPerfQues.doc DOC document
Historical Data - SSC PWS.pdf PDF
Historical Data - GSFC SES II - NNG15CR67C.pdf PDF
Historical Data - AEGIS PWS.pdf PDF
Historical Data - PACE V Statement of Work.pdf PDF
80TECH21R0007 Request For Proposals.pdf PDF
Attachment A - CyPrESS PWS.pdf PDF
Attachment E - DD Form 254 Cover Page.pdf PDF
Attachment E - Attachment 2 to DD Form 254_SBU_20210125 DRAFT.pdf PDF
Attachment F - Personal Identiy Verification (PIV) Card Issuance Procedures.pdf PDF
Attachment I - IAGP.pdf PDF
Attachment K - Contract Management Plan Cover Page - Copy.pdf PDF
Exhibit 1 - 21 Cost Templates.xlsx XLSX spreadsheet
Enclosure EE CyPrESS Labor Categories.xlsx XLSX spreadsheet
Historical Data - HQ - HITSS_III_RFP_Attach._A_-PWS Page 295.pdf PDF
Historical Metrics.pdf PDF
Historical Data - COMIT Section C - Statement of Work.pdf PDF
Historical Data - ACITS4 SOW 80ARC020D0006.pdf PDF
Historical Data - BITSec SOW.pdf PDF
Show all 50

Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Information Technology Security Management Plan

Issue Date Effective Date:

SENSITIVE BUT UNCLASSIFIED (SBU)

Version 4 11/2020

(Insert Contract # Here)

SENSITIVE BUT UNCLASSIFIED (SBU)

IT Security Management Plan Review and Approval

This Information Technology Security Management Plan (ITSMP) for the was prepared for the exclusive use of NASA and completed on

I have reviewed the contents of this plan, and believe that it presents an accurate representation.

Reviewed by: ________________________________

ISSO, or equivalent Date

Concurred by: ________________________________

COR/Task Monitor Date

Approved by: ________________________________

Center CISO Date

Accepted by: ________________________________

Contracting Officer Date

Contents

Change History .......................................................................................................................................................................................... ii IT Security Management Plan Review and Approval ............................................................................................................................... iii 1 Contract Identification

1.1 Contract Name

1.2 Contract Number

1.3 Responsible Organization

1.4 Contact Information

1.4.1 Physical Location

1.4.2 Points of Contact

1.5 General Contract Description

1.5.1 Information System Categorization

1.5.2 Security Categorization

1.5.3 Information System

1.5.4 Contractor Badging

1.5.5 Supply Chain Risk Management (SCRM)

1.5.6 Related Laws/Regulations/Policies

2 Security Control Implementations 3 Federal Information Security Management Act (FISMA) Reporting Appendix A: Acronyms

1.5.6 Related Laws/Regulations/Policies

• 5 U.S.C. 552, Freedom of Information Act, 1967

• 5 U.S.C. 552a, Privacy Act, 1974

• FIPS 199, Standards for Security Categorization of Federal Information and Information Systems

• FIPS 200, Minimum Security Requirements for Federal Information and Information Systems

• NIST SP 800-18, Guide for Developing Security Plans for Federal Information Systems

• NIST SP 800-30, Risk Management Guide for Information Technology Systems

• NIST SP 800-34, Contingency Planning Guide for Information Technology Systems

• NIST SP 800-37, Guide for the Security Authorization of Federal Information Systems

• NIST SP 800-42, Guideline on Network Security Testing

• NIST SP 800-53, Recommended Security Controls for Federal Information Systems

• NIST SP 800-53A, Techniques and Procedures for Verifying the Effectiveness of Security Controls in Federal Information

Systems

• NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories

• NIST SP 800-61, Computer Security Incident Handling Guide

• NIST SP 800-64, Security Considerations in the Information System Development Life Cycle

• OMB Circular A-130, Appendix III, Security of Federal Automated Information Systems

• Public Law (PL) 99-474, The Computer Fraud and Abuse Act of 1986

• PL 93-502 -Freedom of Information Act 1974

• Presidential Decision Directive (PDD-63), Critical Infrastructure Protection Federal Information Security Management Act of 2002 (FISMA)

• NPR 2810.1, Security of Information Technology

Additional Information: If there is any additional information that you wish to provide, please use the box below.

File details come from the government source that posted it. Updated .