About this file

This document is the eLibrary for the NASA Sounding Rocket Operations Contract (NSROC) IV solicitation. The eLibrary contains documentation to support the NSROC IV Request for Proposal for providing sounding rocket mission operations, integration, launch, and data services. Services required include mission planning, payload integration, launch operations, data acquisition, and post-flight analysis. The solicitation is open to all offerors and proposals are due by July 16, 2021. The period of performance for the awarded contract is a one year base period starting in 2022 with four one-year options. Pricing will be on a cost-plus-fixed-fee basis. The incumbent contractor is Sounding Rocket Operations Consortium led by Utah State University. The solicitation is issued by the National Aeronautics and Space Administration Goddard Space Center to support their suborbital research program.

View the file

Other files for this federal contract opportunity

Other files attached to NASA Sounding Rocket Operations Contract (NSROC) IV - FINAL Request for Proposal, eLibrary, newest first.
File Type Posted
NSROC CBA IAMAW 11.01.21 final FULLY EXECUTED.pdf PDF
Rocket_Report_1st_quarter_2019.pdf PDF
Rocket Report 2nd quarter 2021.pdf PDF
Rocket_Report_3rd_quarter_2019.pdf PDF
Rocket Report 4th quarter 2020.pdf PDF
Rocket Report 1st quarter 2021.pdf PDF
SRPO Annual Report 2017.pdf PDF
Rocket Report 1st quarter 2020.pdf PDF
SRWG_Findings_Jan_2021.pdf PDF
Sounding rocket litho 2017.pdf PDF
SRWG_Findings_July_2020.pdf PDF
GSFC-STD-8009T-SRPO WFF Range Safety Manual Rev B.pdf PDF
300-PG-8730.6.1 ESD Control Plan.pdf PDF
800-WI-8715.2.1B Severe Weather Notification.pdf PDF
810-PG-5100.1.3G NSROC Development and Routine Project Assignments Process.pdf PDF
GPR 4220.1.pdf PDF
GPR 1700.7.pdf PDF
GPR 1860.2.pdf PDF
GPR 8730.1.pdf PDF
GPR 8710.8.pdf PDF
GPR 8500.5.pdf PDF
GPR 5340.3.pdf PDF
NPR 2190.1.pdf PDF
GPR 8500.8.pdf PDF
GPR 1700.8.pdf PDF
GPR 1800.5.pdf PDF
NPR 8735.2.pdf PDF
810-FORM-0003H SRPO MRR Checklist.pdf PDF
NPD 1490.1.pdf PDF
NPD 4200.1.pdf PDF
NPR 1441.1.pdf PDF
GPR 8730.6.pdf PDF
NPD 6000.1.pdf PDF
NPD 2540.1.pdf PDF
NPD 1440.6.pdf PDF
803-PG-3410.2.2 WFF Safety Office Training and Certification Program.pdf PDF
NPD 1280.1.pdf PDF
NPR 8705.6.pdf PDF
810-FORM-0002G SRPO DR Checklist.pdf PDF
810-FORM-0004H SRPO MCR Checklist.pdf PDF
NPR 8715.5.pdf PDF
NPR 4200.1.pdf PDF
SRPO Cryogenic Safety Users Guide Revision A Final.pdf PDF
NSROC III NNG16WA70C Attachment M - Contract Historical Data 19-20.pdf PDF
SRPO Technology Roadmap June 2021.pdf PDF
NSROC III List of Ongoing Work - October 2021.pdf PDF
SRPO Annual Report 2016.pdf PDF
Rocket_Report_4th_quarter_2019.pdf PDF
SR User Handbook Final_July 2015.pdf PDF
SRPO Annual Report 2019.pdf PDF
Show all 50

NASA Sounding Rocket Operations Contract (NSROC) IV - FINAL Request for Proposal, eLibrary has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DIRECTIVE NO. GPD 7150.0A

EFFECTIVE DATE: September 1, 2020

EXPIRATION DATE: September 1, 2025

CHECK THE GSFC DIRECTIVES MANAGEMENT SYSTEM AT

https://gdms.gsfc.nasa.gov TO VERIFY THAT THIS IS THE CORRECT VERSION PRIOR TO USE.

08/16

Goddard Policy Directive

(GPD)

Goddard Policy Directive

(GPD)

Responsible Office: 580/Software Engineering Division

Title: Software Engineering

1. POLICY

It is the Goddard Space Flight Center (GSFC) policy to engineer software using a disciplined approach in accordance with NASA policies for the management and engineering of its programs and projects.

This approach includes activities to continually advance the Center’s in-house software engineering capability and monitor the software engineering capability of its contractors. This Goddard Policy

Directive (GPD) documents the Center’s software engineering policy and provides clarification regarding the flow-down of NASA software engineering policies and requirements to GSFC-led software engineering efforts. In the event of a conflict between this directive and a NASA policy, the information provided in the NASA policy takes precedence.

NASA documents the policy for the management and engineering of its programs and projects in NASA

Policy Directive (NPD) 7120.4, NASA Engineering and Program/Project Management Policy and NPD

7120.6, Knowledge Policy for Programs and Projects. NPD 7120.4 contains Agency requirements for the acquisition, development, maintenance, and management of software. NASA Procedural

Requirements (NPR) directive: NPR 7120.5, NASA Space Flight Program and Project Management

Requirements; NPR 7120.7, NASA Information Technology and Institutional Infrastructure Program and Project Management Requirements; and NPR 7120.8, NASA Research and Technology Program and Project Management Requirements specify the administration, management, and review of NASA programs and projects.

NASA applies a common systems engineering approach to its space flight, research and technology, as well as information technology (IT) and institutional programs and projects. NASA documents the general requirements for systems engineering in NPR 7123.1, NASA Systems Engineering Processes and

Requirements. NPR 7150.2, NASA Software Engineering Requirements elaborates on the requirements for software engineering and determines the applicability of requirements based on a NASA-wide software classification structure. NPR 2210.1, Release of NASA Software established the procedures and responsibilities for the reporting, review, assessment, and release of software created by or for NASA.

2. APPLICABILITY

a. This directive applies to software activities performed by GSFC civil servants and by GSFC contractors to the extent specified or referenced in applicable contracts, grants, or agreements.

b. In this directive, all document citations are to the latest version unless otherwise noted.

c. In this directive, all mandatory actions (i.e., requirements) are denoted by statements containing the term “shall.” The terms “may” or “can” denote discretionary privilege or permission; “should” denotes https://gdms.gsfc.nasa.gov/

DIRECTIVE NO. GPD 7150.0A Page 2 of 28 a good practice and is recommended but not required; “will” denotes expected outcome; and “are/is” denotes descriptive material.

3. AUTHORITY

NPD 7120.4, NASA Engineering and Program/Project Management Policy

NPD 7120.6, Knowledge Policy for Programs and Projects

NPR 7150.2, NASA Software Engineering Requirements

4. APPLICABLE DOCUMENTS AND FORMS

a. NPD 2091.1, Inventions Made by Government Employees

b. NPR 2210.1, Release of NASA Software

c. NPR 2200.2, Requirements for Documentation, Approval and Dissemination of Scientific and

Technical Information

d. NPR 2800.2, Electronic and Information Technology Accessibility

e. NPR 2810.1, Security of Information Technology

f. NPR 7120.5, NASA Space Flight Program and Project Management Requirements

g. NPR 7120.7, NASA Information Technology and Institutional Infrastructure Program and

Project Management Requirements

h. NPR 7120.8, NASA Research and Technology Program and Project Management Requirements

i. NPR 7123.1, NASA Systems Engineering Processes and Requirements

j. NPR 8000.4, Agency Risk Management Procedural Requirements

k. NPR 8705.4, Risk Classification for NASA Payloads

l. NASA-STD-8739.8, Software Assurance and Software Safety Standard

m. NASA/SP-2007-6105, NASA Systems Engineering Handbook

n. NASA-HDBK-2203, NASA Software Engineering and Assurance Handbook (https://swehb.nasa.gov)

o. GPD 7123.0, Independent Verification and Validation of Software Development

p. GPR 1410.2, Configuration Management

q. GPR 7120.4, Risk Management

r. GPR 7123.1, Systems Engineering

s. GPR 7150.4, Software Safety and Software Reliability Process

t. GPR 8705.4, Risk Classification Guidelines and Risk-Based SMA Practices for GSFC Payloads and

Systems

u. 372-PG-7120.2.1, Procedure for Planning and Implementing Software Assurance Programs

v. 500-PG-7120.0.1, Engineering Technical Authority Implementation Plan

w. GSFC-STD-1000, Rules for the Design, Development, Verification, and Operation of Flight Systems

(known as the Goddard Open-Learning Design or “GOLD” Rules)

x. GSFC-STD-1001, Criteria for Flight and Flight Support System Lifecycle Reviews

y. GSFC 4-56, GSFC Software Classification https://swehb.nasa.gov/

DIRECTIVE NO. GPD 7150.0A Page 3 of 28

z. Capability Maturity Model Integration (CMMI): Guidelines for Process Integration and Product

Improvement

aa. NIST SP 800-161, Supply Chain Risk Management Practices for Federal Information Systems and

Organizations

Software Engineering Division/Code 580 is authorized to release additional policies and guidance relevant to software engineering after the issuance of this directive. Check the GSFC Software Process Asset

Library (PAL) at https://software.gsfc.nasa.gov for software engineering guidance, templates, and tools.

Check the NASA On-line Directives Information System (NODIS) at https://nodis-dms.gsfc.nasa.gov/ for the latest versions of NASA directives and check the Goddard Directives Management System (GDMS) at https://gdms.gsfc.nasa.gov/ for the latest versions of GSFC directives. Check the NASA Technical

Standards System (NTSS) at https://standards.nasa.gov/ for the latest versions of NASA Technical

Standards, including NASA Handbooks, and GSFC Technical Standards. Attachment B provides a graphical representation of the documents listed in Section 3 and 4 followed by a table providing the purpose of the document or policy statement.

5. RESPONSIBILITIES

5.1 The GSFC Center Director delegates Center Engineering Technical Authority (ETA) to the Director of the Engineering and Technology Directorate (ETD). ETA then flows down to Division Chiefs, Branch

Chiefs, and Program/Project Lead Engineers. ETD maintains configuration control of the ETA

Implementation Plan.

5.2 The Engineering and Technology Directorate (ETD) maintains the Center’s Engineering Technical

Authority Implementation Plan, 500-PG-7120.0.1. [SWE-122]1 In accordance with this plan, the

Chief of the Software Engineering Division (SED) serves as the ETA2 for the discipline of software engineering. The SED provides leadership, guidance, and engineering services to continually advance the Center’s in-house software engineering capability and monitor the software engineering capability of GSFC’s contractors. [SWE-003] Additional information about the services SED provides is available at https://etd.gsfc.nasa.gov/580/.

1 In this directive, a procedural requirement from NPR 7150.2 is referenced using its requirement number [SWE-###].

2 All but two NPR 7150 procedural requirements have been delegated to the Center Level for Technical Authority. NASA

Headquarters Office of the Chief Engineer (OCE) and the Office of Safety and Mission Assurance (OSMA) will designate the technical authority for the requirement regarding software independent verification and validation (IV&V) [SWE-141] and the requirement regarding CMMI rating [SWE-32].

https://software.gsfc.nasa.gov/ https://nodis-dms.gsfc.nasa.gov/ https://standards.nasa.gov/

DIRECTIVE NO. GPD 7150.0A Page 4 of 28

5.3 The SED Chief or designee has the following responsibilities:

a. Serves as the Center’s Engineering Technical Authority for ensuring GSFC’s implementation of

Engineering Technical Excellence for software.

b. Checks the accuracy of the project’s classification of software components3 against the definitions in

Appendix D of NPR 7150.2 and assesses the project’s Requirements Mapping Matrix4, tailoring, waivers, and deviations from requirements set forth in NPR 7150.2 [SWE-126].

c. Provides personnel skilled in flight, ground and science architectures, data systems, simulators and technologies, mission environments, software engineering, software systems engineering, software/data systems project management, mission operations, mission validation capabilities and sustaining engineering.

d. Sponsors the periodic benchmark5 of the Center’s in-house software engineering capability in accordance with NPR 7150.2 [SWE-032]

e. Assists Center software engineers in preparing for the evaluations listed in Section 7.

f. Identifies training6 to advance the Center’s in-house software engineering capability and as a reference for GSFC civil servants and contractors.

g. Provides software-related content for the Product Development Lead (PDL) workshops and Technical

Managers Training (TMT).

h. Implements a Configuration Control Board (CCB) to establish, document, and maintain configuration control for software processes [SWE-005], associated guidance, and templates for software planning.

The SED CCB operates in accordance with GPR 1410.2, Configuration Management. The SED CCB approved items are stored in a process asset library (PAL) accessed by GSFC employees through the

Software Website (https://software.gsfc.nasa.gov/).

i. Assists the Strategic Partnership Office (SPO), Office of Patent Counsel (OPC), and Center software engineers in the reporting, review, assessment, and release of software in accordance with NPR 2210.1, Release of NASA Software.

3 GSFC 4-56, Software Classification form is used to initially document the software classification and safety-criticality, and the mission criticality of the software. [SWE-020]. This information is maintained in the software plan. The information from this form is used to validate the list of Center programs and projects containing software. [SWE-006].

4 Requirements Mapping Matrix documents the project's intent to comply with the requirements of NPR 7150.2, justification for tailoring, or waiver requests for specific requirements. Previously referred to as a Requirements Compliance Matrix, this name was removed from NPR 7150.2C to imphasize the matrix is to be completed before the software is developed and not afterward as a compliance check. Appendix C of NPR 7150.2 contains the table of requirements and NASA-HDBK-2203 provides requirements mapping matrices organized by software class.

5 Capability Maturity Model Integration (CMMI) appraisals are the preferred benchmarks for measuring software engineering improvement at NASA Centers.

6 Courses on software project and engineering management are part of NASA’s Academy of Program/Project and

Engineering Leadership (APPEL). Technical training is requested by GSFC employees in consultation with their supervisors.

https://software.gsfc.nasa.gov/

DIRECTIVE NO. GPD 7150.0A Page 5 of 28

j. Assesses the project’s waiver requests from software-related technical standards, including Software

GOLD Rules.

5.4 Directors have the following responsibilities:

a. Maintain and provide upon request a reliable list7 of their Directorate’s programs and projects containing

Class A, B, C, and D software in accordance with NPR 7150.2 [SWE-006].

b. Ensure compliance with NPR 7150.2 for software activities within their Directorates performed by

GSFC civil servants and GSFC contractors to the extent specified or referenced in applicable contracts, grants, or agreements.

5.5 GSFC Program and Project Managers:|

a. Ensure the makeup and organization of technical teams for systems containing software, include software engineering leads for software products and software system engineers for systems containing more than one software product, providing coverage for both flight and ground software system engineering domains.

b. Ensure compliance with NPR 7150.2 for software activities performed within their programs and projects by GSFC civil servants and GSFC contractors to the extent specified or referenced in applicable contracts, grants, or agreements.

c. Ensure that all contracts, grants, or agreements that include software engineering activities, are reviewed by appropriate Subject Matter Experts (SMEs) during proposal evaluation, including Source Evaluation

Boards (SEBs). For NASA software classes A, B, and C acquisitions, the SME should be from an organization that has met the requirements of NPR 7150.2, SWE-032 with established or certified processes.

d. Report software metrics in accordance with NASA’s Cost Analysis Data Requirement (CADRe) and the

One NASA Cost Engineering (ONCE) database.8

5.6 The technical team:

a. Identifies and collects software metrics in accordance with NPR 7150.2 based on program and project needs.

7 The Office of the Chief Engineer maintains the Agency Mission Directorate Programs and Projects List (AMPL) under the

Program/Project Community on the Web-based environment called the NASA Engineering Network (https://nen.nasa.gov/).

8 CADRe is a requirement per NPR 7120.5. For information, go to http://www.nasa.gov/offices/ooe/CADRe_ONCE.html.

https://nen.nasa.gov/ http://www.nasa.gov/offices/ooe/CADRe_ONCE.html

DIRECTIVE NO. GPD 7150.0A Page 6 of 28

b. Ensures the performance of software engineering in accordance with NPR 7150.2 based on the NASA software classification of the software. Uses GSFC Form 4-56, Software Classification9 to document initially the software classification. [SWE-020] Changes to the software classification are documented and maintained in the software plan.

c. Verifies and maintains compliance with NPR 7150.2, and submits completed NPR 7150.2 Requirements

Mapping Matrix(ces), including any approved waivers and deviations to appropriate Center technical authority.10 [SWE-125]

d. Determines the technology readiness levels for software in accordance with NPR 7123.1 and references the measures for assessing software technology maturity described in NASA/SP-2007-6105, NASA

Systems Engineering Handbook.

e. Develops and maintains a software management plan or product plan in accordance with NPR 7150.2 and NPR 7123.1 and with enough content for life cycle and independent reviews. Maintains the software classification, in the software plan. The planning information may be maintained in a format other than a text document.

f. Proposes innovative and streamlined implementation approaches to software engineering within acceptable risk while maintaining compliance with NPR requirements, requesting waivers when applicable.

g. Implements quality, reliable, safe, and secure software products.11 NPR 7150.2 describes software security requirements. NPR 2810.1, Security of Information Technology identifies security requirements for the acquisition, development, integration, and modification of ground software systems.

h. Reports software as a new technology12 and obtains approval for the release of software in accordance with NPR 2210.1, Release of NASA Software.

i. Applies technical standards for flight systems, including hardware and software as documented in

GSFC-STD-1000, Rules for the Design, Development, Verification, and Operation of Flight Systems

(known as the Goddard Open-Learning Design or “GOLD” Rules).

j. Applies technical standards for the review of flight systems, including software, as documented in

GSFC-STD-1001, Criteria for Flight and Flight Support System Lifecycle Reviews.

k. Ensures that software is accessible to individuals with disabilities in accordance with NPR 2800.2, Policy on Electronic Information Technology Accessibility. Before the release of any software, those responsible for the software, with the assistance of the Software Release Authority, coordinates with the

NASA Center 508 Coordinator, for the purposes of obtaining a decision from the Coordinator regarding

9 The information from this form is used to validate the list of Center programs and projects containing software. [SWE-006] 10 The Software Requirements Review is the expected point in the lifecycle for completing the matrix(ces) as recommended in the NASA Software Engineering and Assurance Handbook, Section 7.8 Maturity of Life-Cycle Products at Milestone

Reviews. The appropriate technical authority in accordance with NPR 7150.2 approves waivers and deviations.

11 NASA’s Secure Coding Portal (SCP) is a resource on the Web-based environment NASA Engineering Network

(https://nen.nasa.gov/).

12 Civil servants are subject to NASA Policy Directive 2091.1B, Inventions Made by Government Employees. Contractors and grantees may be subject to NASA Federal Acquisition Regulations (FAR) Supplement 1852.227.

https://nen.nasa.gov/

DIRECTIVE NO. GPD 7150.0A Page 7 of 28 the software's Section 508 compliance, including any appropriate exceptions in accordance with NPR

2800.2.

l. Ensures compliance with intellectual property requirements and copyright laws.

m. Obtains authorization in accordance with NPR 2200.2D, Requirements for Documentation, Approval and Dissemination of Scientific and Technical Information before technical information (STI) about software can be published or otherwise disseminated external to NASA or presented at internal meetings or conferences where foreign nationals may be present.

5.7 ETD’s Mission Systems Engineering Branch/Code 599 defines in GPR 7123.1, NASA Systems

Engineering the flow-down of Agency-level policies to outline a set of requirements that provide a consistent method for performing systems engineering across GSFC projects where the major parts of a system include the separate subsystems and their embedded hardware and software functions.

5.8 Strategic Partnerships Office (SPO)/Code 102

a. Manages the Center’s reporting, review, assessment, and release of software in accordance with NPR

2210.1, Release of NASA Software.

b. Serves as the Center’s Software Release Authority.

5.9 Office of Patent Counsel (OPC)/Code 140

a. Reviews and advises on the Center’s reporting, review, assessment, and release of software in accordance with NPR 2210.1, Release of NASA Software managed by the Strategic Partnerships Office

(SPO).

b. Serves as the Center’s legal authority on software rights, including the use and development of software usage agreements.

5.10 Flight Projects Directorate

a. Defines in GPR 1410.2, Configuration Management the Center’s approach to controlling and documenting changes to selected baseline documents, hardware and software.

b. Defines in GPD 7123.0, Independent Verification and Validation of Software Development the flow-down of Agency-level Independent Verification and Validation (IV&V) policies to applicable GSFC-led software development efforts.

DIRECTIVE NO. GPD 7150.0A Page 8 of 28

5.11 Safety and Mission Assurance (SMA) Directorate

a. Defines the Center’s approach in GPR 8705.4, Risk Classification Guidelines and Risk-based SMA

Practices for GSFC Payloads and Systems to risk classification in accordance with NPR 8705.4, Risk

Classification for NASA Payloads.

b. Defines the Center’s approach to risk management in accordance with NPR 8000.4, Agency Risk

Management Procedural Requirements.

c. Defines the Center’s approach in GPR 7150.4, Software Safety and Software Reliability Process and

Greenbelt’s implementation in 372-PG-7120.2.1, Procedure for Planning and Implementing Software

Assurance Programs.

d. Performs software assurance in accordance with NASA-STD-8739.8, Software Assurance and Software

Safety Standard, as invoked by NPR 7150.2 [SWE-022, SWE-023].

e. Uses GSFC 4-56, Software Classification form to concur with or document independently the software classification of the software. [SWE-020] Any changes to the software classification are documented and maintained in the software plan.

f. Documents and maintains the mission criticality and safety criticality of the software in the software assurance plan.

g. Supports the periodic benchmark of the Center’s in-house software engineering capability in accordance with NPR 7150.2.

5.12 Chief Information Officer (CIO)

a. Enforces acquisition and supply chain policies to ensure tools and repositories used are compliant with cybersecurity goals, including NIST SP 800-161 Supply Chain Risk Management Practices for Federal

Information Systems and Organizations.

b. Ensures software cybersecurity is included throughout the software development, testing, maintenance, retirement, operations, management, acquisition and assurance activities, as per NPR 7150.2 NASA

Software Engineering Requirements [SWE-126].

c. Provides consultation and collaboration with software developers to meet goals of secure code and software cybersecurity hygiene, including the mitigation of cybersecurity threats as they are known.

6. DELEGATION OF AUTHORITY

Directors and project managers have the authority to delegate their respective responsibilities defined in

Section 5.

DIRECTIVE NO. GPD 7150.0A Page 9 of 28

7. MEASUREMENT/VERIFICATION

The applicable Center technical authority collects and tracks measurement data on compliance with this

GPD. Verification documentation includes completed GSFC 4-56, Software Classification forms, NPR

7150.2 Requirements Mapping Matrices, and waivers submitted, approved, and denied by SWE requirement number. Specific responsibilities for collecting, analyzing, and reporting software engineering and software release metrics are contained in NPR 7150.2 and NPR 2210.1.

8. CANCELLATION

GPD 7150.0, Software Engineering Policy

Original Signed By

Dennis Andrucyk

Director

DIRECTIVE NO. GPD 7150.0A Page 10 of 28

Attachment A – Definitions

None

DIRECTIVE NO. GPD 7150.0A Page 11 of 28

Attachment B – Acronyms

AMPL Agency Mission Directorate Programs and Projects List

APPEL Academy of Program/Project and Engineering Leadership

CADRe Cost Analysis Data Requirement

CCB Configuration Control Board

CIO Chief Information Officer

CMMI Capability Maturity Model Integration

CSO Chief Safety and Mission Assurance Officer

ETA Engineering Technical Authority

ETD Engineering and Technology Directorate

FPD Flight Projects Directorate

GDMS Goddard Directives Management System

GOLD Goddard Open-Learning Design

GSFC Goddard Space Flight Center

GPR GSFC Procedural Requirements

GPD GSFC Policy Directive

HDBK Handbook

ISO International Standards Organization

IT Information Technology

IV&V Independent Verification and Validation

NEN NASA Engineering Network

NODIS NASA On-line Directives Information System

NPD NASA Policy Directive

NPR NASA Procedural Requirements

NSC NASA Safety Center

PAL Process Asset Library

PDL Product Development Lead

OCE Office of the Chief Engineer

OCIO Office of the Chief Information Officer

OPC Office of Patent Counsel

ONCE One NASA Cost Engineering

OSMA Office of Safety and Mission Assurance

NSC NASA Safety Center

PG Procedures and Guidelines

SAE Software Assurance Engineer

SCP Secure Coding Portal

SEB Source Evaluation Board

SED Software Engineering Division

SMA Safety and Mission Assurance

SME Subject Matter Expert

SPO Strategic Partnership Office

SRA Software Release Authority

STD Standard

SWE Software Engineering

TMT Technical Managers Training

DIRECTIVE NO. GPD 7150.0A Page 12 of 28

Attachment C – Graphical Representation and Purpose of the Document or Policy Statement

DIRECTIVE NO. GPD 7150.0A Page 13 of 28

Authority Purpose of the Document or Policy Statement

The National Aeronautics and Space Act, as amended, 51 U.S.C. § 20113(a).

Reference https://www.nasa.gov/offices/ogc/about/space_act1.html.

NPD 1000.0, NASA

Governance and Strategic Management Handbook.

This NASA Policy Directive (NPD) has two primary aims: (1) to set forth NASA’s governance framework—principles and structures through which the Agency manages mission, roles, and responsibilities; and (2) to describe NASA’s Strategic Management System—processes by which the Agency manages strategy and its implementation through planning, performance, and results.

NPD 1000.3, The NASA Organization.

This NASA Policy Directive (NPD) documents the NASA organization, defines terms, and sets forth the standards and requirements for establishing, modifying, and documenting the NASA organizational structure and for assigning organizational responsibilities. Specific duties of NASA officials are described in their official position descriptions rather than in this document.

NPD 1000.5, Policy for NASA Acquisition.

This NASA Policy Directive (NPD) provides the overall policy framework for NASA's strategic acquisition process with appropriate references to other key processes and directives. This strategic acquisition process complies with NASA obligations as a Federal agency and is applicable to each of NASA's major areas of investment (Flight Programs and Projects, Information Technology and Institutional Infrastructure, and Research and Technology) to ensure the efficient, effective use of the resources entrusted to the Agency.

NASA's strategic acquisition process supports obtaining, or advancing the development of, the systems, research, services, construction, and supplies to fulfill the Agency's mission and other activities, which advance the Agency's statutory objectives. Within the framework of this strategic acquisition process, NASA utilizes multiple authorities to meet these objectives. NASA's authorities include, but are not limited to, grants, cooperative agreements, international agreements, and Space Act Agreements (SAAs), in addition to NASA's acquisition authority to contract for goods and services through procurements. The Agency also has the authority to enter into other types of arrangements depending on the circumstances, such as Inter-Agency Agreements (IAAs), leases, concession agreements, property loan agreements, and Cooperative Research and Development Agreements (CRADAs). This NPD establishes the strategic acquisition governance framework under which these authorities will be used.

DIRECTIVE NO. GPD 7150.0A Page 14 of 28

NPD 1200.1, NASA Internal Control.

NASA's policy is to comply with Office of Management and Budget (OMB) Circular A-123, Management's Responsibility for Internal Control, which provides government-wide requirements for internal control and accountability, based on 31U.S.C. § 3512 (b) and (c). Specifically, it is NASA's policy to:

(1) Develop and maintain internal control policies, procedures, plans, and assessments to provide reasonable assurance that the objectives of effective and efficient operations, reliable financial reporting, and compliance with applicable laws and regulations are achieved.

(2) Hold Officials-in-Charge (OICs) and Center Directors responsible for the development, implementation and effectiveness of internal controls, and for annually assessing and reporting on the effectiveness of internal controls.

(3) Ensure that internal control and accountability underpin decisive governance over organizational structure; policies and procedures; processes for managing programmatic, financial and institutional activities; checks and balances; and tools and techniques to uphold the Agency's integrity, efficiency, and effectiveness.

(4) Ensure that internal controls are well integrated into new or revised activities when making changes to ongoing activities and implementing new activities in programmatic and institutional operations or financial management processes.

NPD 1210.2, NASA Surveys, Audits, and Reviews Policy.

NASA's policy is to establish minimum criteria for the conduct of Headquarters-initiated surveys, audits, and reviews (SARs) of NASA activities in such a way that the SARs are value-added and effective in support of the Agency's mission.

NPD 1600.2, NASA Security Policy.

NASA's policy is to provide security and protection for its personnel, including employees, authorized contractors, subcontractors, tenants, and visitors; its missions, facilities, property, and information that are in its possession or under its control, consistent with all applicable laws, national level directives, and Agency requirements.

NPD 2091.1, Inventions Made By Government Employees.

NASA's policy is to:

(1) Protect the Government's interest in, and to provide for, the widest practicable and appropriate dissemination, early utilization, expeditious commercial development, and continued availability of inventions reported to NASA that are made by Government employees.

DIRECTIVE NO. GPD 7150.0A Page 15 of 28

(2) Be fair and impartial in the administration of the rights to such inventions and to afford an employee making an invention the opportunity to retain title to such invention if there is insufficient Government interest or equity for the Government to acquire title.

(3) Subject to availability of funding, ensure that each employee making and reporting an invention on which a patent application is filed is considered by the Inventions and Contributions Board (ICB) for an initial monetary award, as well as, upon application, a supplemental monetary award, based both on the commercial application of the invention and its value in the conduct of aeronautical and/or space activities.

NPD 7120.4, NASA

Engineering and Program/Project Management Policy.

This NASA Policy Directive (NPD) provides the statement of policy, principles, and responsibilities for program and project management and system and software engineering disciplines at NASA. Implementing procedural requirements under the purview of the Office of the Chief Engineer (OCE) comprise space flight programs and projects as described in NASA Procedural Requirements (NPR) 7120.5, research and technology programs and projects as described in NPR 7120.8, systems engineering as described in NPR 7123.1, technical standards as described in NPR 7120.10, the use of the metric system, knowledge management as described in NPD 7120.6, and software engineering as described in NPR 7150.2. This NPD also consolidates the Agency’s crosscutting software policy and responsibilities across NASA Headquarters offices and Mission Directorates. These principles also apply to program and project management for information technology under the purview of the Office of the Chief Information Officer (OCIO) as described in NPR 7120.7 and institutional infrastructure under the purview of the Office of Strategic Infrastructure (OSI) as described in NPR 8590.1 and NPR 8820.2.

NPD 7120.6, Knowledge Policy for Programs and Projects

NASA’s policy is to effectively manage the Agency's technical and program/project management knowledge to cultivate, identify, capture, retain, utilize, and share knowledge in order to continuously improve the performance of NASA in implementing its mission, in accordance with NPD 1000.0, Governance and Strategic Management Handbook. In order to meet future challenges, innovate successfully, and keep pace with the state of the art in rapidly changing times, NASA will focus on the following critical activities:

(a) Ensure that the Agency's technical and program/project knowledge is captured and accessible across all Centers and Mission Directorates.

Historically, NASA's principal mechanism for collecting and sharing lessons learned from Agency programs and projects has been an online database

DIRECTIVE NO. GPD 7150.0A Page 16 of 28 called the Lessons Learned Information System (LLIS). The LLIS is one component of NASA¹s larger knowledge management and sharing system, which has evolved to include numerous training sessions, knowledge-sharing events, and tools that contribute to organizational learning and mission success.

(b) Promote an environment for the technical workforce that fosters continuous learning and adaptation to emerging technological and governing conditions.

(c) Enhance awareness of Agency knowledge management resources, such as the APPEL Knowledge Services Web site (appel.nasa.gov), where NASA's technical workforce can find knowledge needed to support project learning and mission success.

(d) Promote the use of leading practices in knowledge cultivation, identification, capture, retention, utilization, and sharing of the Agency's collective know-how on programs and projects. NASA Centers, Mission Directorates, and mission support organizations, as identified in NPD 1000.3, The NASA Organization, employ a range of knowledge management approaches and practices to address their unique capabilities, missions, and institutions. NASA Centers and Mission Directorates share their knowledge management practices and solutions to common knowledge challenges and adopt leading practices from others to achieve continuous improvement and increased efficiency.

(e) Mitigate the impacts of attrition and other workforce demographic trends or program/project closeouts on knowledge loss and close anticipated knowledge gaps to benefit future knowledge users.

(f) Support NASA policy that NASA leaders, managers, supervisors, and personnel participate in ongoing training and skills enhancement for project and program excellence, in accordance with NPD 7120.4, NASA Engineering and Program/Project Management Policy, NPR 7120.5, NASA Space Flight Program and Project Management Requirements, NPR 7120.7, NASA Information Technology and Institutional and Infrastructure Program and Project Management Requirements, NPR 7120.8, NASA Research and Technology Program and Project Management Requirements, NPR 7123.1, NASA Systems Engineering Processes and Requirements, NPR 7150.2, Software Engineering Requirements, and NPR 8621.1C, NASA Procedural Requirements for Mishap and Close Call Reporting, Investigating, and Recordkeeping. This includes skills development in the effective cultivation, identification, capture, retention, utilization, and sharing of knowledge. NASA is committed to

DIRECTIVE NO. GPD 7150.0A Page 17 of 28 developing new ways of sharing and transferring knowledge, as well as developing tools, practices, and processes that facilitate learning.

(g) Govern the knowledge management enterprise on a federated basis, such that each Center or Mission Directorate determines the approach that best meets its needs, with the understanding that knowledge applicable to all NASA missions and Centers will be shared to the greatest extent possible across the entire Agency.

NPR 1600.1, NASA Security Program Procedural Requirements.

This NPR prescribes NASA protective services procedural requirements for NASA Centers and Component Facilities in executing the NASA security program to protect people, property, operations, and Classified National Security Information (CNSI). It establishes program specifications necessary to achieve uniformity, standardization, centralization, and decision-making authority where appropriate. Policy and procedural requirements for the protection of CNSI is further promulgated in NASA NPR 1600.2, NASA Classified National Security Information.

NPR 2210.1C, Release of NASA Software

This NASA Procedural Requirements (NPR) establishes procedures and responsibilities for the reporting, review, assessment, and release of software created by or for NASA. These procedures reinforce that NASA software is reported and released both internally and externally, according to law and NASA policies, with appropriate restrictions on the use and redistribution of the software. The unrestricted release of NASA software, as defined in Appendix A at paragraph A.2.7, is prohibited.

NPR 2800.1, Managing Information Technology.

This document establishes requirements and responsibilities for information technology (IT) Management relative to the policy set forth in NASA Policy Directive (NPD) 2800. IT is defined as any equipment or interconnected system(s) or subsystem(s) of equipment that is used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the Agency. By implementing IT procedures and requirements that are aligned with NASA`s Strategic Plan and integrated with its strategic management process, NASA seeks to make measurable improvements in mission performance, cost of program/project development and operations, and service delivery to the public through the strategic application of IT.

DIRECTIVE NO. GPD 7150.0A Page 18 of 28

NPR 2810.1, Security of Information Technology.

The purpose of this document is to:

a. Establish the information security requirements for the National Aeronautics and Space Administration (NASA) relative to the policy set forth in NASA Policy Directive (NPD) 2810.1, NASA Information Security Program. The procedural requirements herein prescribe roles, responsibilities, and conditions that directly or indirectly promote information security throughout the life cycle of all NASA information and information systems.

b. Identify information security policies, procedures, and practices which are appropriate to NASA's mission, and are consistent with applicable federal laws, executive orders, directives, policies, and regulations.

c. Serve as a reference to the NASA community regarding specific information security roles and responsibilities, and provide resources where more detailed information may be found.

d. Satisfy security policy guidance as outlined by National Institute of Standards Technology (NIST), Special Publication (SP) 800-53.

Recommended Security Controls for Federal Information Systems and Organizations.

NPR 7120.5, NASA Space Flight Program and Project Management Requirements.

This document establishes the requirements by which NASA formulates and implements space flight programs and projects, consistent with the governance model contained in NASA Policy Directive (NPD) 1000.0, NASA Governance and Strategic Management Handbook.

NPR 7120.7, NASA

Information Technology and Institutional Infrastructure Program and Project Management Requirements.

This document establishes the requirements by which NASA will formulate and execute information technology and institutional infrastructure programs and projects, consistent with the governance model contained in the NASA Governance and Strategic Management Handbook (NPD 1000.0).

NPR 7120.8, NASA Research and Technology Program and Project Management Requirements.

This document establishes the program and project management requirements by which the National Aeronautics and Space Administration (NASA) will formulate and execute research and technology (R&T) programs and projects, consistent with the governance model contained in NASA Policy Directive (NPD) 1000.0.

NPR 7123.1, NASA Systems Engineering Processes and Requirements.

This document establishes the NASA processes and requirements for implementation of Systems Engineering (SE) by programs/projects. NASA SE is a logical systems approach performed by multidisciplinary teams to engineer and integrate NASA’s systems to ensure NASA products meet the customer’s

DIRECTIVE NO. GPD 7150.0A Page 19 of 28 needs. Implementation of this systems approach will enhance NASA’s core engineering capabilities while improving safety, mission success, and affordability. This systems approach is applied to all elements of a system (i.e., hardware, software, and human) and all hierarchical levels of a system over the complete program/project life cycle.

NPR 7150.2, NASA Software Engineering Requirements

Software engineering is a core capability and key enabling technology for NASA's missions and supporting infrastructure. This directive establishes the engineering requirements for software acquisition, development, maintenance, retirement, operations, and management consistent with the governance model contained in NASA Policy Directive (NPD) 1000.0. This NASA Procedural Requirements (NPR) supports the implementation of NPD 7120.4.

NPR 8000.4, Agency Risk Management Procedural Requirements.

a. This NASA Procedural Requirements (NPR) provides the requirements for risk management for the Agency, its institutions, and its programs and projects as required by NPD 1000.0; NPD 7120.4; NPD 8700.1, and other Agency directives. Risk management includes two complementary processes: Risk-Informed Decision Making (RIDM) and Continuous Risk Management (CRM).

b. This NPR establishes requirements applicable to all levels of the Agency's organizational hierarchy. It provides a framework that integrates the RIDM and CRM processes across levels. It requires formal processes for risk acceptance and accountability that are clear, transparent, and definitive. This directive also establishes the roles, responsibilities, and authority to execute the defined requirements Agency-wide. It builds on the principle that program, project, and institutional requirements should be directly coupled to Agency strategic goals and applies this principle to risk management processes within all Agency organizations at a level of rigor that is commensurate with the stakes and complexity of the decision situation that is being addressed.

c. The implementation of these requirements leads to a risk management approach that is coherent across the Agency in that (a) it applies to all Agency strategic goals and the objectives and requirements that derive from them, (b) it addresses all sources of risk, both internal and external to NASA, (c) all risks are considered collectively during decision-making, and (d) risk management activities are coordinated horizontally and vertically, across and within programs, projects, and institutions, to ensure timely identification of cross-cutting risks and balanced management of risks Agency wide.

DIRECTIVE NO. GPD 7150.0A Page 20 of 28

d. This directive contains requirements for risk management. Detailed explanations, descriptions, and technical guidance are provided in associated handbooks, including NASA/SP-2011-3422, NASA Risk Management Handbook (Reference D.7).

NPR 8705.2, Human-Rating Requirements for Space Systems.

a. NASA's policy is to protect the health and safety of humans involved in or exposed to space activities, specifically the public, crew, passengers, and ground personnel. This policy is implemented through the application of NASA directives and standards.

b. The significant monetary investment for complex space hardware requires all missions to meet high standards of reliability and mission success. The purpose of this NASA Procedural Requirements (NPR) document is to define and implement the additional processes, procedures, and requirements necessary to produce human-rated space systems that protect the safety of the crew and passengers on NASA space missions.

c. A human-rated system accommodates human needs, effectively utilizes human capabilities, controls hazards and manages safety risk associated with human spaceflight, and provides, to the maximum extent practical, the capability to safely recover the crew from hazardous situations. Human-rating is not and should not be construed as certification for any activities other than carefully managed missions where safety risks are evaluated and determined to be acceptable for human spaceflight.

d. Human-rating must be an integral part of all program activities throughout the life cycle of the system including (but not limited to) design and development; test and verification; program management and control; flight readiness certification; mission operations;

sustaining engineering; and maintenance, upgrades, disposal, and ground processing.

e. This NPR requires applicable space systems as defined in paragraph P.2 to obtain a Human-Rating Certification prior to the first crewed mission and maintain the rating throughout the systems' life cycle.

NPR 8705.4, Risk Classification for NASA Payloads.

This NPR establishes baseline criteria that enable a user to define the risk classification level for NASA payloads on human- or nonhuman-rated launch systems or carrier vehicles and the design and test philosophy and the common assurance practices applicable to each level. The establishment of the risk level early in programs and projects provides the basis for program and project managers to develop and implement appropriate mission assurance and risk management strategies and requirements and to effectively communicate the acceptable level of risk.

DIRECTIVE NO. GPD 7150.0A Page 21 of 28

NPR 8715.3, NASA General Safety Program Requirements.

a. This NASA Procedural Requirements (NPR) provides the basis for the NASA Safety Program and serves as a general framework to structure more specific and detailed requirements for NASA Headquarters, Programs, and Centers. This document does not stand alone and is to be used in conjunction with the references listed in paragraph P.4.

b. This NPR is directed toward safety requirements and to augment requirements for occupational health and environmental health of personnel and activities. Some health and environmental safety references are included to assist Center safety personnel in interactions with occupational health and environmental personnel.

Occupational safety and health requirements that implement 29 CFR Part 1960, are specified in NPR 8715.1. Environmental requirements are specified in NPD 8500.1.

c. This NPR does not provide requirements for emergency planning.

Emergency planning requirements are specified in NPD 8710.1, Emergency Preparedness Program. d. To address special processes and/or discipline-unique processes, the Office of Safety and Mission Assurance publishes standards that provide specific instructions that are beyond the scope and detail of this document. A listing of applicable Federal requirements, NPRs, and standards can be found in paragraphs P.3 and P.4 of this NPR.

NPR 8735.2, Management of Government Quality Assurance Functions for NASA Contracts.

This NASA Procedural Requirements (NPR) document sets forth Agency requirements for performance of Government contract quality assurance functions as required by Federal Acquisition Regulation (FAR) Part 46, FAR Part 12, NASA FAR Supplement (NFS) Part 1846, and NPD 8730.5, NASA Quality Assurance Program Policy. The purpose of Government contract quality assurance is to ensure that supplies and services acquired under Government contract conform to contract requirements.

Applicability

a. This NPR applies to NASA Headquarters and NASA Centers, including Component Facilities and Technical and Service Support Centers.

b. This NPR provides requirements for quality assurance functions to ensure that supplies and services acquired under Government contract conform to the contract's quality requirements. Supplies include Government Furnished Equipment (GFE) (i.e., Government-procured equipment that is furnished to NASA contractors). Services include contractor work that directly supports the establishment or verification of product configuration (e.g., basic and applied research, design, manufacture, nondestructive testing, laboratory testing, DIRECTIVE NO. GPD 7150.0A Page 22 of 28 fabrication, assembly, integration, performance testing, maintenance, refurbishment, repair, calibration) and contractor operation of the delivered acquisition product (e.g., hazardous test facility). The term "services" does not refer to Government contract quality assurance functions assigned to support contractors.

c. This NPR does not apply to Government contract quality assurance functions related to software. Software assurance functions are defined by NASA-STD-8739.8 and NPR 7150.2.

d. This NPR does not apply to quality assurance functions related to the acquisition of NASA institutional facilities or to facility maintenance.

Quality assurance requirements for facility acquisitions/services are performed in accordance with NPR 8820.2, Facility Project Requirements, NPR 8831.2, Facilities Maintenance and Operations Management, and FAR/NFS regulations.

e. This NPR does not apply to information technology (IT) services.

f. f. This NPR does not apply to grants and cooperative agreements covered by 31 U.S.C. 6301 et seq. or Space Act agreements covered by

51 USC 20113.

DIRECTIVE NO. GPD 7150.0A Page 23 of 28

NASA/SP-2010-576, Risk- Informed Decision Making

Risk management (RM) is an integral aspect of virtually every challenging human endeavor, but well-defined RM processes have only recently begun to be developed and implemented as an integral part of systems engineering at NASA, given the complex concepts that RM encapsulates and the many forms it can take. However, few will disagree that effective risk management is critical to program and project success. Recent NASA RM processes have been based on Continuous Risk Management (CRM), which stresses the management of risk during implementation. In December of 2008, NASA issued NPR 8000.4A [1], which introduced Risk-Informed Decision Making (RIDM) as a complementary process to CRM that is concerned with analysis of important and/or direction-setting decisions. Before, RM was considered equivalent to CRM; now, RM is defined as comprising both CRM and RIDM.

This handbook addresses the RIDM component of RM. This is an essential part of RM since the decisions made during the course of a program ultimately “burn-in” the risk that must be retired/mitigated during the life cycle of the program (primarily during the development portion of the life cycle) using CRM processes to track progress towards the program’s goal. RIDM helps to ensure that decisions between alternatives are made with an awareness of the risks associated with each, thereby helping to prevent late design changes, which can be key drivers of risk, cost overruns, schedule delays, and cancellation. Most project cost-saving opportunities occur in the definition, planning, and early design phases of a project.

DIRECTIVE NO. GPD 7150.0A Page 24 of 28

NASA/SP-2011-3422, NASA

Risk Management Handbook

The purpose of this handbook is to provide guidance for implementing the Risk…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .