Historical Data - AEGIS PWS.pdf

PDF 27 MB Posted

Attached to
Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) Federal contract opportunity
Solicitation number
80TECH21R0007
Issued by
National Aeronautics and Space Administration

About this file

This document provides details on a federal solicitation from the National Aeronautics and Space Administration seeking proposals for Cybersecurity and Privacy Enterprise Solutions and Services. The solicitation seeks to establish an indefinite delivery/indefinite quantity contract to provide cybersecurity and privacy solutions, services, and related support to all NASA Centers and Facilities. Key requirements include providing enterprise solutions and services to support NASA's Office of Chief Information Technology in the areas of cybersecurity and privacy. The period of performance and pricing terms were not specified.

View the file

Other files for this federal contract opportunity

Other files attached to Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS), newest first.
File Type Posted
80TECH21R0007 Amendment 02.pdf PDF
Exhibit 1 - 21 Cost Templates Amendment 02.xlsx XLSX spreadsheet
Questions and Answers for 80TECH21R0007 - Amendment 02.pdf PDF
Questions and Answers for 80TECH21R0007.pdf PDF
80TECH21R0007 Amendment 01.pdf PDF
Attachment A - CyPrESS PWS Updated Amendment 01.pdf PDF
Enclosure DD - Estimated Historical Core Labor Updated Amendment 01.pdf PDF
Enclosure EE Labor Categories Updated Amendment 01.xlsx XLSX spreadsheet
Exhibit 1 - 21 Cost Templates Updated Amendment 01.xlsx XLSX spreadsheet
Attachment E - Attachment 1 to DD Form 254_20210125 DRAFT.pdf PDF
Attachment G - Safety and Health Plan Cover Page.pdf PDF
Attachment H - Small Business Subcontracting Plan Cover Page.pdf PDF
Attachment L - IT Security Management Plan Cover Page.pdf PDF
Attachment N - Phase-in Plan Cover Page.docx DOCX document
Exhibit 22 - L-1 Business Systems Reviews and Status Information Template.xlsx XLSX spreadsheet
Enclosure AA - Quality Assurance Surveillance Plan (QASP).pdf PDF
Enclosure CC - Cover Page.pdf PDF
Enclosure DD - Estimated Historical Core Labor.pdf PDF
Historical Data - MITS II-pws section 3.pdf PDF
Attachment C - Data Requirements Descriptions.pdf PDF
Attachment I - Installation Accountable Government Property (IAGP) Cover Page.pdf PDF
Attachment P - DIRECT LABOR RATES AND INDIRECT RATES AND FEE MATRICES.pdf PDF
Attachment Q - Fixed Price Rate Matrix.pdf PDF
Historical Data - LAMPS_2_PWS_rev_11_102720.pdf PDF
Enclosure BB - CyPrESS CPAF PEP Core Plus IDIQ Services.pdf PDF
Attachment E - DD Form 254 Contract Security Classification Specification.pdf PDF
Attachment B - Applicable Documents List.pdf PDF
Attachment D - Financial Management Reporting.pdf PDF
Attachment J - OCI Avoidance Plan Cover Page.pdf PDF
Attachment O - Wage Determinations.pdf PDF
Exhibit 23 - L-2 Cognizant Audit Office Template.xlsx XLSX spreadsheet
Exhibit 24 PastPerfQues.doc DOC document
Enclosure CC - IT Security Management Plan Template.pdf PDF
Historical Data - SSC PWS.pdf PDF
Historical Data - GSFC SES II - NNG15CR67C.pdf PDF
Historical Data - PACE V Statement of Work.pdf PDF
80TECH21R0007 Request For Proposals.pdf PDF
Attachment A - CyPrESS PWS.pdf PDF
Attachment E - DD Form 254 Cover Page.pdf PDF
Attachment E - Attachment 2 to DD Form 254_SBU_20210125 DRAFT.pdf PDF
Attachment F - Personal Identiy Verification (PIV) Card Issuance Procedures.pdf PDF
Attachment I - IAGP.pdf PDF
Attachment K - Contract Management Plan Cover Page - Copy.pdf PDF
Exhibit 1 - 21 Cost Templates.xlsx XLSX spreadsheet
Enclosure EE CyPrESS Labor Categories.xlsx XLSX spreadsheet
Historical Data - HQ - HITSS_III_RFP_Attach._A_-PWS Page 295.pdf PDF
Historical Metrics.pdf PDF
Historical Data - COMIT Section C - Statement of Work.pdf PDF
Historical Data - ACITS4 SOW 80ARC020D0006.pdf PDF
Historical Data - BITSec SOW.pdf PDF
Show all 50

Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

AEGIS

80JSC020R0039

C-2

Table of Contents

1 ADVANCED ENTERPRISE GLOBAL INFORMATION TECHNOLOGY (IT) SOLUTIONS

(AEGIS)

1.1 INTRODUCTION AND OVERVIEW

1.2 PRINCIPAL AEGIS STAKEHOLDERS

1.2.1 THE COMMUNICATIONS PROGRAM

1.2.2 THE COMPUTING SERVICES PROGRAM

1.2.3 THE CYBERSECURITY AND PRIVACY PROGRAM

1.3 GOALS AND OBJECTIVES

1.4 GOVERNMENT-RETAINED AUTHORITIES

1.5 PERFORMANCE WORK STATEMENT (PWS) OVERVIEW

2 CONTRACT MANAGEMENT

2.1 PROGRAM MANAGEMENT

2.2 CONTRACT ADMINISTRATION SYSTEM

2.3 CRITICAL STAFFING POSITIONS

2.4 FINANCIAL MANAGEMENT

2.5 LOGISTICS

2.5.1 PROPERTY/INVENTORY MANAGEMENT

2.5.2 SHIPPING/RECEIVING/INSPECTION SERVICES

2.5.3 VEHICLES

2.6 CONTRACT PHASE-IN MANAGEMENT

2.7 PROCUREMENT SERVICES

2.7.1 PROCUREMENT SERVICES FOR DATA CENTER

2.8 PHYSICAL SECURITY MANAGEMENT AND CYBERSECURITY MANAGEMENT

2.8.1 PHYSICAL SECURITY MANAGEMENT

2.8.2 CYBERSECURITY MANAGEMENT

2.9 EXPORT CONTROL

2.10 EMERGENCY MANAGEMENT

2.11 SAFETY, HEALTH AND ENVIRONMENTAL (SHE) MANAGEMENT

2.12 FACILITY MANAGEMENT

2.13 QUALITY ASSURANCE AND MANAGEMENT

2.14 CONTRACT AND SUBCONTRACT ADMINISTRATION

2.14.1 GSA CONTRACT INTEGRATION

3 INNOVATION SERVICES

3.1 GENERAL

3.1.1 DEFINITION

3.1.2 PURPOSE

3.1.3 INNOVATION ACTIVITIES

3.1.4 COOPERATIVE COMMITMENT

3.2 INNOVATION PROCESS

3.2.1 INNOVATION RELATIONSHIP MANAGEMENT

3.2.2 AUDIENCE AND STAKEHOLDERS

3.3 WORKSHOPS

3.4 WORKSHOP PARTICIPATION AND PREPARATION

3.5 BUSINESS AND TECHNOLOGY REVIEW WORKSHOP PROCESS

3.6 INNOVATION VISIONING WORKSHOP PROCESS

3.7 ACTION PLANNING WORKSHOP PROCESS

C-3

3.8 STRATEGY GENERATION

4 IT SERVICE MANAGEMENT

4.1 SERVICE DELIVERY SUPPORT

4.2 SERVICE DESIGN AND IMPLEMENTATION

4.3 SERVICE OPERATIONS

4.4 OPERATIONAL INCIDENT MANAGEMENT

4.5 PROBLEM MANAGEMENT

4.6 PERFORMANCE MANAGEMENT

4.7 REPORTING

4.8 MAINTENANCE

4.9 PROGRAMMATIC RISK ANALYSIS

4.10 CONFIGURATION MANAGEMENT

4.11 CUSTOMER RELATIONSHIP MANAGEMENT

4.12 CRM APPLICABLE TO CP NASCOM MISSION SERVICES

4.13 ENTERPRISE SERVICE PROGRAM INTEGRATION

4.13.1 ENTERPRISE SERVICES PROGRAM INTEGRATION ROLES AND

RESPONSIBILITIES

4.13.2 NASA END-USER SERVICES AND TECHNOLOGIES (NEST)

4.13.3 ENTERPRISE APPLICATIONS SERVICE TECHNOLOGIES 2 (EAST2)

4.13.4 ENTERPRISE SERVICE DESK (ESD)

5 ENTERPRISE SERVICES

5.1 ENTERPRISE CROSS-CUTTING SERVICES

5.1.1 DNS DYNAMIC HOST CONFIGURATION PROTOCOL (DHCP) INTERNET

PROTOCOL ADDRESS MANAGEMENT (IPAM) (DDI)

5.1.2 LAYER 2 BACKBONE SERVICES

5.1.3 CABLE PLANT SERVICES

5.2 ENTERPRISE CP CORPORATE SERVICES

5.2.1 CORPORATE VOICE SERVICES

5.2.2 CORPORATE DATA SERVICES

5.2.3 CORPORATE COLLABORATIVE SERVICES

5.2.4 SYSTEM AND SOFTWARE ADMINISTRATION

5.2.5 VOIP/TELEPHONE SERVICES

5.2.6 ENTERPRISE VIDEO CONTENT DELIVERY NETWORK (EVCDN)

5.2.7 CORPORATE MANAGEMENT AND OPERATIONS

5.3 CP NASA COMMUNICATIONS (CP NASCOM) MISSION SERVICES

5.3.1 NASCOM MISSION ENGINEERING AND SERVICE DELIVERY

5.3.2 CP NASCOM MISSION DATA SERVICES

5.3.3 CP NASCOM MISSION SYSTEMS ADMINISTRATION AND SOFTWARE

DEVELOPMENT

5.3.4 INSTALLATION AND MAINTENANCE OF CP NASCOM INFRASTRUCTURE

5.3.5 MISSION FACILITIES MANAGEMENT OF CP NASCOM INFRASTRUCTURE

5.3.6 CP NASCOM PHYSICAL SECURITY

5.3.7 CP NASCOM MISSION MANAGEMENT AND OPERATIONS

6 INFRASTRUCTURE PROJECTS

6.1 INDEFINITE DELIVERY INDEFINITE QUANTITY (IDIQ) PROJECTS

6.2 INTERNET PROTOCOL TELEVISION (IPTV) PROJECT

6.3 SOFTWARE DEFINED NETWORK (SDN)/INTENT BASED NETWORK (IBN)

ENTERPRISE DEPLOYMENT PROJECT

C-4

6.4 MISSION NEXT GENERATION VOICE (MNGV) PROJECT

7 CENTER AND ASSOCIATED COMPONENT FACILITY SERVICES

7.1 AMES RESEARCH CENTER (ARC)

7.1.1 CELLULAR REDISTRIBUTION SERVICES

7.1.2 EMERGENCY WARNING SYSTEMS

7.1.3 PUBLIC ADDRESS SYSTEMS

7.1.4 RADIO SERVICES

7.1.5 MULTIMEDIA SERVICES

7.1.6 CABLE PLANT SERVICES

7.1.7 VOIP/TELEPHONE SERVICES

7.1.8 EMERGENCY TELECOMMUNICATIONS

7.2 ARMSTRONG FLIGHT RESEARCH CENTER (AFRC)

7.2.1 CELLULAR REDISTRIBUTION SERVICES

7.2.2 EMERGENCY WARNING SYSTEMS

7.2.3 PUBLIC ADDRESS SYSTEMS

7.2.4 RADIO SERVICES

7.2.5 MULTIMEDIA SERVICES

7.2.6 CABLE PLANT SERVICES

7.2.7 VOIP/TELEPHONE SERVICES

7.2.8 EMERGENCY TELECOMMUNICATIONS

7.3 GLENN RESEARCH CENTER (GRC)

7.3.1 CELLULAR REDISTRIBUTION SERVICES

7.3.2 EMERGENCY WARNING SYSTEMS

7.3.3 PUBLIC ADDRESS SYSTEMS

7.3.4 RADIO SERVICES

7.3.5 MULTIMEDIA SERVICES

7.3.6 CABLE PLANT SERVICES

7.3.7 VOIP/TELEPHONE SERVICES

7.3.8 EMERGENCY TELECOMMUNICATIONS

7.4 GODDARD SPACE FLIGHT CENTER (GSFC)

7.4.1 CELLULAR REDISTRIBUTION SERVICES

7.4.2 EMERGENCY WARNING SYSTEMS

7.4.3 PUBLIC ADDRESS SYSTEMS

7.4.4 RADIO SERVICES

7.4.5 MULTIMEDIA SERVICES

7.4.6 CABLE PLANT SERVICES

7.4.7 VOIP/TELEPHONE SERVICES

7.4.8 EMERGENCY TELECOMMUNICATIONS

7.4.9 FACILITIES INFRASTRUCTURE RESOURCE ENVIRONMENT (FIRENET)

SYSTEMS

7.4.10 LAUNCH RANGE SUPPORT SERVICES (WFF)

7.5 HEADQUARTERS (HQ)

7.5.1 CELLULAR REDISTRIBUTION SERVICES

7.5.2 EMERGENCY WARNING SYSTEMS

7.5.3 PUBLIC ADDRESS SYSTEMS

7.5.4 RADIO SERVICES

7.5.5 MULTIMEDIA SERVICES

7.5.6 CABLE PLANT SERVICES

7.5.7 VOIP/TELEPHONE SERVICES

C-5

7.5.8 EMERGENCY TELECOMMUNICATIONS

7.6 JET PROPULSION LABORATORY (JPL)

7.6.1 CELLULAR REDISTRIBUTION SERVICES

7.6.2 EMERGENCY WARNING SYSTEMS

7.6.3 PUBLIC ADDRESS SYSTEMS

7.6.4 RADIO SERVICES

7.6.5 MULTIMEDIA SERVICES

7.6.6 CABLE PLANT SERVICES

7.6.7 VOIP/TELEPHONE SERVICES

7.6.8 EMERGENCY TELECOMMUNICATIONS

7.6.9 JPL NASA MANAGEMENT OFFICE (NMO) NETWORK REQUIREMENTS

7.7 JOHNSON SPACE CENTER (JSC)

7.7.1 CELLULAR REDISTRIBUTION SERVICES

7.7.2 EMERGENCY WARNING SYSTEMS

7.7.3 PUBLIC ADDRESS SYSTEMS

7.7.4 RADIO SERVICES

7.7.5 MULTIMEDIA SERVICES

7.7.6 CABLE PLANT SERVICES

7.7.7 VOIP/TELEPHONE SERVICES

7.7.8 EMERGENCY TELECOMMUNICATIONS

7.8 KENNEDY SPACE CENTER (KSC)

7.8.1 CELLULAR REDISTRIBUTION SERVICES

7.8.2 EMERGENCY WARNING SYSTEMS

7.8.3 PUBLIC ADDRESS SYSTEMS

7.8.4 RADIO SERVICES

7.8.5 MULTIMEDIA SERVICES

7.8.6 CABLE PLANT SERVICES

7.8.7 VOIP/TELEPHONE SERVICES

7.8.8 EMERGENCY TELECOMMUNICATIONS

7.8.9 OPERATIONAL INTERCOMMUNICATIONS SYSTEMS

7.8.10 ASTRONAUT COMMUNICATIONS

7.8.11 SOUND REINFORCEMENT

7.8.12 OPERATIONAL TELEVISION

7.8.13 ENGINEERING IMAGERY

7.8.14 ASCENT IMAGERY SERVICES

7.8.15 DATA TRANSMISSIONS SERVICES

7.8.16 TIMING AND COUNTDOWN SERVICES

7.9 LANGLEY RESEARCH CENTER (LARC)

7.9.1 CELLULAR REDISTRIBUTION SERVICES

7.9.2 EMERGENCY WARNING SYSTEMS

7.9.3 PUBLIC ADDRESS SYSTEMS

7.9.4 RADIO SERVICES

7.9.5 MULTIMEDIA SERVICES

7.9.6 CABLE PLANT SERVICES

7.9.7 VOIP/TELEPHONE SERVICES

7.9.8 EMERGENCY TELECOMMUNICATIONS

7.10 MARSHALL SPACE FLIGHT CENTER (MSFC)

7.10.1 CELLULAR REDISTRIBUTION SERVICES

7.10.2 EMERGENCY WARNING SYSTEMS

C-6

7.10.3 PUBLIC ADDRESS SYSTEMS

7.10.4 RADIO SERVICES

7.10.5 MULTIMEDIA SERVICES

7.10.6 CABLE PLANT SERVICES

7.10.7 VOIP/TELEPHONE SERVICES

7.10.8 EMERGENCY TELECOMMUNICATIONS

7.10.9 FACSIMILE SERVICES AT MSFC AND MAF

7.11 NASA SHARED SERVICES CENTER (NSSC)

7.11.1 CELLULAR REDISTRIBUTION SERVICES

7.11.2 EMERGENCY WARNING SYSTEMS

7.11.3 PUBLIC ADDRESS SYSTEMS

7.11.4 RADIO SERVICES

7.11.5 MULTIMEDIA SERVICES

7.11.6 CABLE PLANT SERVICES

7.11.7 VOIP/TELEPHONE SERVICES

7.11.8 EMERGENCY TELECOMMUNICATIONS

7.12 STENNIS SPACE CENTER (SSC)

7.12.1 CELLULAR REDISTRIBUTION SERVICES

7.12.2 EMERGENCY WARNING SYSTEMS

7.12.3 PUBLIC ADDRESS SYSTEMS

7.12.4 RADIO SERVICES

7.12.5 MULTIMEDIA SERVICES

7.12.6 CABLE PLANT SERVICES

7.12.7 VOIP/TELEPHONE SERVICES

7.12.8 EMERGENCY TELECOMMUNICATIONS

8 AGENCY COMPUTING SERVICES

8.1 AGENCY DATA CENTER CONSOLIDATION (ADCC)

8.2 ENTERPRISE MANAGED CLOUD COMPUTING (EMCC)

8.3 MANAGED CLOUD ENVIRONMENT (MCE) ARCHITECTURE DEVELOPMENT,

ENGINEERING, IMPLEMENTATION, MANAGEMENT, AND OPERATIONS

8.3.1 MANAGED CLOUD ENVIRONMENT DELIVERY AND MANAGEMENT

8.3.2 COMPUTE

8.3.3 STORAGE

8.3.4 OBJECT STORAGE SERVICE CRITERIA

8.3.5 FILE STORAGE SERVICE CRITERIA

8.3.6 CONTINUOUS DIAGNOSTICS AND MONITORING

8.3.7 MCE CONFIGURATION MANAGEMENT

8.3.8 ENVIRONMENT IMPROVEMENTS AND COST EFFICIENCIES

8.3.9 ABSTRACTED COMPUTE SERVICES CRITERIA

8.3.10 CLOUD ARCHITECTURE AND ENGINEERING (SOLUTIONS, CYBERSECURITY

AND NETWORK)

8.4 DATA CENTER MANAGEMENT AND OPERATIONS

8.4.1 GENERAL FOR CIO DATA CENTERS

8.4.2 ENTERPRISE DATA CENTER MANAGEMENT AND OPERATIONS

8.5 DATA CENTER NETWORKS (DCNS)

8.5.1 NETWORK

8.6 AGENCY DATA CENTER AND COMPUTING SERVICES

8.6.1 IT INFRASTRUCTURE, COMPUTING AND CLOUD SERVICES

8.6.2 CONTINUITY OF OPERATIONS (COOP) PLAN

C-7

8.6.3 CUSTOMER SERVICE, CHANGE REQUESTS (CRS) AND TIER 1 HELP DESK

SUPPORT

8.6.4 ENGINEERING SUPPORT

8.6.5 SYSTEMS BUILD, INTEGRATION, AND TESTING

8.6.6 INSTALLATION

8.6.7 TECHNICAL ASSESSMENT AND ACCEPTANCE TESTING

8.6.8 SYSTEMS ADMINISTRATION

8.6.9 OPERATIONS

8.6.10 HIGH PERFORMANCE COMPUTING SUPPORT

8.6.11 BACKUP AND STORAGE

8.6.12 LARGE SCALE DATA STORAGE AND RETRIEVAL SYSTEM

8.6.13 MEDIA OPERATIONS ROLES AND RESPONSIBILITIES

8.6.14 HARDWARE, CLOUD AND SYSTEMS SOFTWARE MAINTENANCE

8.6.15 PREVENTIVE MAINTNANCE (PM)

8.6.16 REMEDIAL MAINTENANCE (RM)

8.6.17 SYSTEM SOFTWARE AND HARDWARE UPGRADES/ENHANCEMENTS

8.6.18 IT SYSTEM CONFIGURATION MANAGEMENT

8.6.19 DATABASE ADMINISTRATION

8.6.20 INSTALLATION OF DATABASE SOFTWARE AND TOOLS

8.6.21 DATABASE ADMINISTRATION – DATABASE CREATION/BUILD

8.6.22 DATABASE ADMINISTRATION – CYBERSECURITY

8.6.23 DATABASE ADMINISTRATION – AVAILABILITY

8.6.24 MONITORING AND CONFIGURING DATABASE ENGINES AND TOOLS

8.6.25 DATABASE CAPACITY PLANNING & PERFORMANCE

8.6.26 DATABASE ARCHIVING AND RESTORING

8.6.27 CYBERSECURITY OF DATABASES AND INSTANCES

8.6.28 DATABASE CHANGE ASSESSMENT AND IMPLEMENTATION

8.6.29 DATABASE DOCUMENTATION AND ACCOUNT MANAGEMENT

8.6.30 MIDDLEWARE AND INFRASTRUCTURE ADMINISTRATION

8.6.31 CYBERSECURITY ADMINISTRATION

8.6.32 CONFIGURATION MANAGEMENT (CM) AND CONTROL

8.6.33 DATA CENTER MANAGEMENT AND CONTROL

8.6.34 FACILITY ACCESS

8.6.35 FACILITIES MANAGEMENT

8.6.36 ELECTRICAL AND MECHANICAL SYSTEMS

8.6.37 DISTRIBUTED SYSTEMS AT OTHER NASA CENTERS

8.6.38 CUSTOMER DRIVEN SPECIALIZED IT SOLUTIONS FOR LABS OR MISSION

AREAS 151

8.6.39 CUSTOMER UNIQUE IT SUPPORT SERVICE FOR LABS OR MISSION AREAS .. 155

8.6.40 OCIO DATA SERVICES

8.6.41 JSC’S USE OF CLOUD TECHNICAL ENVIRONMENTS (CTES)

9 SPECIALIZED SERVICES

9.1 HYPERSONIC NETWORK SUPPORT

9.2 RUSSIA SERVICES

9.2.1 RUSSIA IT END-USER SUPPORT

9.2.2 RUSSIA CYBERSECURITY

9.2.3 BI-ANNUAL CONGRESSIONAL REPORTING

9.2.4 TIER 1 SERVICE DESK SUPPORT

9.3 NASA NATIONAL SECURITY SYSTEMS (NSS) SERVICE IT SUPPORT

C-8

9.4 NASA IMAGERY EXPERTS PROGRAM (NIEP) OFFICE ENGINEERING SERVICES .. 163

9.5 UNIQUE VIDEO SERVICES (UVS)

9.5.1 VIDEO CLOSED CAPTIONING SERVICES

9.6 HUNTSVILLE OPERATIONS SUPPORT CENTER (HOSC) NETWORK SERVICES

9.7 PHYSICAL ACCESS CONTROL SYSTEMS (PACS)

10 ENTERPRISE CYBERSECURITY SUPPORT SERVICES

10.1 REMOTE ACCESS SERVICES (RAS)

10.2 NETWORK ACCESS CONTROL (NAC)

10.3 FIREWALL SERVICES

10.4 PROXY SERVICES

10.5 CONTINUOUS DIAGNOTICS & MITIGATION (CDM) AND CYBERSECURITY &

PRIVACY PROGRAM (CSPP) SUPPORT

10.6 CORPORATE CYBERSECURITY SUPPORT SERVICES

10.6.1 CORPORATE CYBERSECURITY SUPPORT SERVICES ROLES AND

RESPONSIBILITIES

10.6.2 INTRUSION DETECTION SYSTEMS AND INCIDENT RESPONSE SUPPORT

10.6.3 CYBERSECURITY PERIMETER

10.7 MISSION CYBERSECURITY SUPPORT SERVICES

11 CENTER LEVEL CYBERSECURITY AND PRIVACY PROGRAM SERVICES

11.1 GSFC CYBERSECURITY SUPPORT SERVICES

11.2 AFRC CYBERSECURITY SUPPORT SERVICE

11.3 MSFC CYBERSECURITY SUPPORT SERVICE

11.4 SSC CYBERSECURITY SUPPORT SERVICES

11.5 NASCOM CYBERSECURITY SUPPORT SERVICES

C-9

1 ADVANCED ENTERPRISE GLOBAL INFORMATION TECHNOLOGY (IT) SOLUTIONS

(AEGIS)

1.1 INTRODUCTION AND OVERVIEW

The National Aeronautics and Space Administration (NASA) Office of the Chief Information Officer’s (OCIO) mission is to increase the productivity of employees, including but not limited to scientists, engineers, and mission support personnel, by responsively and efficiently delivering reliable, innovative, and secure Information Technology (IT) services. Within the OCIO there are six program offices:

Cybersecurity and Privacy, Data Center/Computing Services, End-User Services, Applications, Communications, and Information Management.

The AEGIS contract will be awarded during a period of significant transformation for NASA. NASA has proactively engaged in a disciplined approach to improving the agency’s operating model over the past several years. One of the top initiatives under NASA’s Mission Support Directorate is the Mission Support Future Architecture Program or MAP. MAP will transform mission support services to an enterprise operating model while maintaining mission focus, improving efficiency, ensuring local authority and valuing the workforce. Mission support services are the functions traditionally managed and operated at each NASA center and headquarters and include information technology. The NASA OCIO is currently in the design phase of its MAP Project. This Project will culminate in a fundamental reshaping of the way NASA provisions and consumes IT services. Through MAP, the OCIO endeavors to:

While the timing of the AEGIS acquisition does not allow full integration of the output from NASA OCIO’s MAP implementation, there are two elements of the AEGIS performance work statement that anticipate the OCIO MAP end-state. First, is the inclusion of performance work statement elements that span the current

C-10

OCIO program offices. Along with the requirements that generally represent the current NASA Integrated Communication Services (NICS) contract, the AEGIS PWS includes requirements for cloud and data center services, and Cybersecurity support services. Inclusion of these three functional areas set the stage for broader technology integration where it makes sense and creates the opportunity to be intentional about creating cross-service management efficiencies like incident management, performance management, business management, etc. The post-MAP service management approach for communications, data center and Cybersecurity support services continues to be developed. The second MAP-driven strategic sourcing step is the inclusion of contract language and mechanisms to allow NASA Centers and Missions to more efficiently consume services and capabilities offered by the AEGIS contract to support Center-specific and Mission-specific requirements. These mechanisms most significantly include on-boarding and performance management strategies. The OCIO MAP Project will be in the implementation phase during Summer 2021.

1.2 PRINCIPAL AEGIS STAKEHOLDERS

While the AEGIS contract is intended to support and be accessible by all NASA organizations, the OCIO’s Communications Program (CP), Computing Services Program, and Cybersecurity and Privacy Program (CSPP) are principal stakeholders and partners of the AEGIS contract.

1.2.1 THE COMMUNICATIONS PROGRAM

The CP oversees the portfolio of services and capabilities associated with communications domain which includes defining and executing overall strategy, roadmaps, standards, policies, investments and projects.

To support NASA, the CP provides high-quality, reliable, cost-effective telecommunications systems and services. Customers include all NASA facilities, flight projects and programs, as well as national and international partners. CP provides Wide Area Network (WAN) services to support administrative applications, such as email, general Internet connectivity, agency-wide Domain Name System (DNS) and Internet Protocol (IP) address management, access to Cloud-based and NASA data center applications, voice and video conferencing, and collaboration tools that enable NASA’s workforce. CP also provides support to enterprise Cybersecurity by employing infrastructure tools and capabilities to include Remote Access, Network Access Control (NAC), Firewall and Web Application Firewall Services, Virtual Private Networks (VPNs), Intrusion Prevention Systems (IPS), Intrusion Detection Systems, NASA Security Operations Center (SOC) Incident Response process, Continuous Diagnostics & Mitigation (CDM) and Cybersecurity & Privacy Program (CSPP). CP also provides local services to NASA Centers that include Local Area Networks (LANs), voice systems, radio systems, Public Address (PA) Systems, Emergency Notification Systems (ENS), cable television and Cable Plant Services. The CP provides mission critical data and voice services to connect Flight Projects to Space Communications and Network (SCaN) Tracking Networks and other resources, including, but not limited to, Space Network (SN), Near Earth Network (NEN), Deep Space Network (DSN), Flight Dynamics Facility (FDF), Launch Complexes and satellite manufacturer and test facilities. CP’s Mission Services directly support Human Space Flight (HSF) and the International Space Station (ISS), including support of IT services inside the Russian Federation (Russia IT Services).

The Contractor shall support the OCIO in advancing NASA’s communications services to provide secure enterprise network management and flexible communications services for NASA. More specifically, the Contractor shall partner with the CP to work with the various OCIO and Mission programs to provide secure and innovative solutions for both mission and mission support customers that are highly secure, cost effective, and advanced such that they increase ability to securely collaborate between NASA and NASA partners beyond current capabilities.

C-11

NASA considers its IT communications infrastructure assets vital to its continuing success as the world leader in aeronautics, space exploration, and scientific research and to advance NASA’s mission to the moon and Mars. NASA personnel use IT to support NASA’s core business, HSF, scientific, research, and computational activities. It is imperative that the commercial sector deliver secure and cost-effective IT services that meet NASA mission and program needs while achieving efficiency and high-level customer satisfaction.

1.2.2 THE COMPUTING SERVICES PROGRAM

The Computing Services Program provides portfolio management oversight of NASA’s data center and cloud computing portfolios and is the focal point for management and business activities of all OCIO computing services and related initiatives. The Computing Services Program is responsible for the execution of NASA’s compliance with the federal Data Center Optimization Initiative (DCOI), formerly the Federal Data Center Consolidation Initiative (FDCCI). The Computing Services Program is designated as the cloud computing program management office with authority to promulgate cloud computing strategy and related standards, and approve, coordinate, and oversee acquisition of cloud computing services intended for Agency-wide use. The Computing Services Program is also designated as the official NASA interface to the Federal Risk and Authorization Management Program (FedRAMP) and commercial cloud service providers for Agency-level business. The Computing Services Program implements and maintains an enterprise-managed cloud infrastructure framework accommodating all types of cloud services in use at NASA. This framework enables NASA users to obtain quick and easy access to cloud services without an onerous amount of start-up work and expense.

As local CIO Center-based, on-premises IT Computing Services contracts expire, it is expected that the scope within those contracts will transition to AEGIS as soon as possible after expiration in order to leverage the benefits of AEGIS. Any local mission organizations may “opt-in” to utilize AEGIS services to gain efficiencies at the discretion of NASA leadership.

Contractor shall partner with the Computing Services Program to work with the various OCIO and Mission programs to provide secure and innovative solutions for both mission and mission support customers that are highly secure, cost effective, and advanced such that they increase ability to securely collaborate between NASA and NASA partners beyond current capabilities.

1.2.3 THE CYBERSECURITY AND PRIVACY PROGRAM

The Cybersecurity & Privacy Program (CSPP) manages the Agency-wide information and cybersecurity program to correct known vulnerabilities, reduce barriers to cross-Center collaboration, and provide cost-effective cybersecurity services in support of NASA’s information systems and e-Gov initiatives. The CSPP ensures that cybersecurity across NASA meets confidentiality, integrity, and availability objectives for data and information systems, to include disaster recovery and continuity of operations for systems, in order to support the business continuity requirements of critical Agency programs and processes. The CSPP develops and maintains a cybersecurity program that ensures consistent Cybersecurity policy, identifies and implements risk-based security controls, and tracks security metrics to gauge compliance and effectiveness.

Contractor shall partner with the CSPP to work with the various OCIO and Mission programs to provide secure and innovative solutions for both mission and mission support customers that are highly secure, cost effective, and advanced such that they increase ability to securely collaborate between NASA and NASA partners beyond current capabilities.

C-12

1.3 GOALS AND OBJECTIVES

AEGIS will continue operations and maintenance of NASA’s Communications Infrastructure through Information Technology products and services that provide assets vital to its continuing success as the world leader in aeronautics, space exploration, and scientific research; and to advance NASA’s mission to the moon, Mars, and beyond. AEGIS will include end-to-end seamless communications network and infrastructure that encompasses WAN, Center LAN, Telecommunications, Cybersecurity support, on-premises and Managed Cloud Data Center Resources, online Collaboration tools, Cable Plant, Emergency and Early Warning and Notification Systems, Telephony, and Radio systems that will maximize the use of Fixed Price Services in coordination with and approval of NASA. The OCIO has established the following as goals of the AEGIS contract.

• Accountability: Be a trusted partner by providing timely and high-quality services, being accountable to not only the OCIO but also to the NASA programs and their mission success.

• Effectiveness: Consistently provide stakeholders services that meet customer requirements, are efficient, and of a high quality. Successful effectiveness will be measured against industry standards and demonstrated by increased consumption of services.

• Innovation: Bring innovative, secure solutions to our stakeholders, including modernizing existing services. Continually improve services and methods for service delivery, cost effectiveness and efficient operations that enable and advance NASA’s missions and program.

• Highly Secure Solutions: Design, operate, and deploy network and computing solutions that enhance Cybersecurity posture and visibility while enabling near real-time response.

The OCIO is looking to increase the use of network automation to improve operational/change management efficiency and Cybersecurity, through Intent Based Networking (IBN) and Zero Trust Architecture, to incorporate device and end-user identity and credential management as a basis for network enrollment and connectivity to resources, and to implement more robust and flexible network solutions that allow automated segmentation or isolation of network traffic based upon machine learning and other data analytics in compliance with NASA policy as governed by Cybersecurity and Privacy Program (CSPP).

In compliance with applicable federal regulations and laws (i.e. Federal IT Acquisition Reform Act (FITARA), Federal Information Security Management Act (FISMA)), Supply Chain Risk Management (SCRM) and OCIO policies and guidelines, the Contractor shall engage with NASA missions and programs through effective partnership and delivery of quality mission-critical communications, devices, and services while maintaining NASA mission and programmatic governance and compliance.

The Contractor shall provide innovative business, management, and secure technical solutions in the delivery of cost-effective communications and computing services to our customers that reduce cost, improve collaboration, and enhance Cybersecurity posture.

1.4 GOVERNMENT-RETAINED AUTHORITIES

NASA will retain a set of key authorities that encompass the overall service strategy and service design.

NASA will also retain authority for all demand management, (management of suppliers and customers), C-13 governance, and approval functions associated with AEGIS. NASA shall perform key roles in Customer Relationship Management (CRM), as delineated in PWS 4.1, Customer Relationship Management.

To assure maintenance of the NASA IT architectural configuration, the contractor shall follow the process set forth in NASA Policy Directive (NPD) 2800.1E, Managing Information Technology. The contractor shall bring recommendations for changes to the NASA IT architecture and standards to the attention of the AEGIS Contracting Officer’s Representative (COR). NASA retains the authority to review and approve all designs and concepts as requested or needed.

In addition to Program Office Configuration Control Boards (CCBs), which are Government Retained, each Center or associated component facility may convene their local CCB, which will include an AEGIS contractor representative. Functions of the CCB include approving proposed changes to local architectures and standards, to ensure consistency with Agency interoperability and compatibility standards.

1.5 PERFORMANCE WORK STATEMENT (PWS) OVERVIEW

Within this framework, the contractor's mission is to provide secure IT services to meet the requirements as defined by this PWS. The PWS consists of the following sections:

a. Contract Management: These services include Program Management, financial management, logistics, contract phase-in/transition management, procurement, physical security management and Cybersecurity management, safety, health & environmental management, facilities management, quality assurance and management, program integration, other interface points, and contract and subcontract administration.

b. Innovation Services: These services include continuous improvement for ongoing effort to enhance the efficiency and effectiveness of the IT and Cybersecurity services that drives the agreed and committed year-over-year cost efficiency improvements, and innovation to identify and implement new ideas and break-through solutions that change and/or enhance the services and results in IT and Cybersecurity transformation through automation.

c. Service Management: These services and operations processes shall align with the current version of the Information Technology Infrastructure Library (ITIL) IT Service Management Framework to establish common terminology and processes.

d. Enterprise Services: Enterprise services encompasses both corporate and mission services (defined below) with crosscutting areas into both corporate and mission. These services include network services, voice services, data services, collaboration services, corporate management and operations, Mission Services, Mission Management and Operations, Customer Relationship Management, Service Management, Strategy Generation, Cybersecurity support, General Services Administration (GSA) contract integration, Cable Plant Services, and Voice over Internet Protocol (VoIP)/telephone services. This is to include WAN and LAN communication services at all NASA Centers and associated component facilities.

1. Enterprise Cross-Cutting Services: Refers to services that span across both Corporate and Mission service areas

2. Corporate Services: Includes Enterprise and Center-unique administrative voice, video, and data services in support of NASA’s mission, programmatic and institutional communications needs.

3. Mission Services: Includes support for the Agency’s ground communications infrastructure for spacecraft control and operations. It is comprised of a world-wide complex of systems and capabilities which have been designed to carry real-time mission data and voice services.

C-14

e. Center and Associated Component Facility Services: These services include Center and associated component facility-specific services such as Emergency Warning System (EWS), PA System, radio, Internet of Things (IoT), and Cable Television (CATV).

f. Infrastructure Projects: This activity includes both continuation and new projects and shall include all the effort to perform projects such as Internet Protocol Television, Software Defined Access Enterprise Deployment, Mission Next Generation Voice and other NASA-approved projects. These projects shall be accomplished in accordance with NASA Interim Directive (NID) 7120.99, NASA Information Technology and Institutional Infrastructure Program and Project Management Requirements.

g. Agency Computing Services: These services include the operating and maintaining of agency data centers, including asset inventory and analyzing NASA’s data center performance against NASA policy, Office of Management and Budget (OMB) directed performance metrics by the Agency Data Center Consolidation (ADCC) team and the facilitation of broad adoption of commercial cloud computing across NASA through the Computing Services Program’s Enterprise Managed Cloud Computing (EMCC) capability.

Services that are included are as follows:

1. Computing Services

1.1. Compute as a Service (CaaS) - Provisioning, maintenance, monitoring and administration of virtual or cloud servers configured to customer requirements for application hosting.

1.2. Containerization - Managed container environment (e.g. Kubernetes) for deployment of customer’s containerized applications.

1.3. Infrastructure as a Service (IaaS) - A pool of virtual or cloud IT resources that the customer can configure and manage as needed.

1.4. Storage Services - Tiered, networked, fault tolerant, file, block, and object storage resources on-premises and in the cloud.

C-15

1.5. Database Services - Managed database systems and services including database administration, DBMS software and associated database tools both on-premises and in the cloud.

1.6. Government Funded Equipment (GFE) support services - System administration and other software services associated with the maintenance of GFE such as engineering workstations, lab connected servers, etc.

1.7. Lab Support Services - System administration and infrastructure services for “data center” like requirements in labs and other mission areas.

1.8. Data Center Co-Location Services –

1.8.1 Co-Location of customer computing infrastructure, including data center network access.

1.8.2 Install, move, add, and change (IMAC) customer hardware inside co-location facility.

1.9. Brokered Cloud Services - Abstracted high-level, cloud native, compute and platform services offered by commercial cloud providers - NASA brokered and managed access to a full range of X-as-a-Service capabilities including, but not limited to, analytics, bots, game development, Application Programming Interface (API) management, search, software development and operations (DevOps) enablement, artificial and virtual reality, serverless functions, queuing, notification, streaming, developer tools, Internet of Things (IoT), Machine Learning (ML), Artificial Intelligence (AI), media services, data and application migration/transfer, mobile application services, cloud-native networking, content delivery, advance compute technologies (e.g., Quantum), ground station services, High-Performance Computing (HPC), robotic platform services, and cloud native compliance and security services. Authority to Operate (ATO) provided access to cloud services including, but not limited to, AI/ML, Database as a Service (DBaaS), cloud functions, etc.

1.9.1. Solution Engineering - Engineering cloud native and hybrid cloud (cloud and on-premises; cloud-cloud) solutions suitable to address NASA requirements.

1.9.2. Security Engineering - Engineer cloud native and hybrid (cloud and on-premises; cloud-cloud) Cybersecurity approaches suitable for meeting NASA requirements.

1.9.3. Cloud-Native Networking - Cloud-native network design, implementation, and operations to enable use of cloud-based computing services in a responsive, secure, and compliant manner.

2. Data Center Infrastructure Management (DCIM)

2.1. Data Center Facility Services - Facility and capacity planning/management, asset management through DCIM tool.

3. Solutions Architect Design Assistance

3.1. Data center, cloud, networking and infrastructure engineering and design assistance services.

4. Business Operations and Continuity Management

4.1. Data Center Procurement Services - Procurement of hardware, software and services for data center, lab and housed customers.

4.2. Continuity of Operations (COOP) Services - Backup and restoration, disaster recovery, or high availability of customer data and system state.

4.3. Accounting and Billing Services - Provides a yearly billing statement in advance, of all costs required to operate for the upcoming fiscal year and an estimate for the four following years.

C-16

4.4. Compliance Services - Data center services are secure and compliant with NASA policy and covered by a System Security Plan (SSP) and ATO for the scope of those services that can be inherited by the customer.

h. Specialized Services: These services include sustainment of point-to-point Custom Networks, system engineering and sustainment of the secure Hypersonic Network, infrastructure (i.e.

desktop, WAN/LAN management) for Russia IT Services, NASA National Security Systems (NSS) service IT support, engineering and capacity management support for NASA Imagery Experts Program (NIEP), engineering and support of video services content developers of Unique Video Services (UVS), and infrastructure engineering and support (i.e., WAN/LAN, voice, data, mission operations, Cybersecurity support) for Huntsville Operations Support Center (HOSC).

i. Enterprise Cybersecurity Support Services: These services include Remote Access, Network Access Control, Firewall, Proxy Services, CDM, Corporate Cybersecurity Support, Intrusion Detection Systems and Incident Response Support, Cybersecurity Perimeter, Mission Cybersecurity Support, and Cybersecurity & Privacy Program, Center Specific Support.

C-24

3. Utilize Agency-wide or Government-wide contracts or site software license agreements for the systems assigned to the contractor. Commodities or services to support the AEGIS mission may be purchased for use outside of the AEGIS contract at the request of NASA.

4. Develop and execute documentation to support the procurement of services, supplies, materials, and equipment including, but not limited to: appropriate federal, state, and local tax clauses; consumables and store stock; replacement parts or equipment; routine and critical spares; purchase, rental, lease, or maintenance of equipment; hardware and hardware upgrades; temporary labor services; vendor maintenance agreements; software, such as software necessary to perform the operations and maintenance functions of this contract; and software licenses, such as systems and applications licenses, subscription, renewal and enhancement services, and software maintenance.

5. Procurements shall be tax exempt to the maximum extent practicable.

6. Maintain management, control and visibility of intra-company, subcontractor, lease agreements, and major vendor activities that are used to fulfill contract requirements.

7. Maintain accountability for quality and timeliness, including expediting of high priority items, of the goods and services that are subcontracted or procured.

8. Establish and ensure continuous certification of a Government-approved purchasing system in accordance with the FAR and NFS.

9. Ensure all products and vendors are approved through the OCIO’s standard approval process. This includes, but is not limited to, FITARA, Supply Chain Risk Management, IPv6, and 508 Compliance.

No purchases of IT should be made prior to approval.

10. Provide small business and small disadvantaged business concerns opportunities to receive a fair portion of procurement awards, in accordance with the approved Attachment J-4, Small Business Subcontracting Plan.

11. Establish a status and tracking system for all acquisitions from receipt of purchase request through close-out of acquisition documentation. The tracking system shall provide visibility of order status to the requestor. Documentation in the tracking system shall include, but is not limited to:

11.1. Assigned work or purchase request number.

11.2. Date of receipt.

11.3. Date order or subcontract is placed.

11.4. Order delivery or completion date.

11.5. Actual receipt or completion date.

11.6. Actual delivery date to requestor.

11.7. Vendor name, address, and contact information.

11.8. Order dollar value.

11.9. Assigned buyer.

11.10. Section 508 Supporting Documents (Standard Subsection numbers noted in parenthesis)

11.10.1. Software Applications and Operating Systems (1194.21).

11.10.2. Web-based Intranet and Internet Information and Applications (1194.22).

11.10.3. Telecommunications Products (1194.23).

11.10.4. Video or Multimedia Products (1194.24).

11.10.5. Self-Contained Closed Products (1194.25).

11.10.6. Desktop and Portable Computers (1194.26)

12. Coordinate with requestors to confirm requirements for any item with hazardous content, prior to ordering.

13. Generate and maintain purchasing and subcontracting documentation sufficient to ensure compliance with the Contractor's approved purchasing system and allow for audit of all such documentation as required by NASA. The files should be consistent in format and content regardless of whether the procurements are performed by prime or subcontractor.

C-27

Documents List (ADL), and cited in NFS 1852.204-76, Security Requirements for Unclassified Information Technology Resources.

19. Comply with information protection requirements in accordance with ITS-HBK-1382.03-01, Privacy Risk Management and NFS 1852.204-76: Collections, PIAs, and SORNs, to ensure compliance with federal regulations and privacy protection requirements.

20. As it relates to Cybersecurity, incorporate appropriate safeguards in accordance with applicable NASA CSPP standards, as noted in 18 above, to ensure availability, integrity, and confidentiality of information and IT resources utilized in performance of this contract. Also, submit all data in accordance with applicable Government standard formats and protocols.

21. Support NASA in the implementation, documentation, and integration of operational and technical Cybersecurity policies, procedures and control measures in accordance with NASA policies, procedures and other guidelines identified in the Applicable Documents List (ADL) covered by the

NFS 1852.204-76.

22. Ensure that systems secure sensitive data, as it is stored or transmitted across the network, complies with Federal Information Processing Standard (FIPS) 140-2, Security Requirements for Cryptographic Modules, and Attachment J-7, Applicable Documents List (ADL), and NFS 1852.204-76,

23. Prepare, submit, and maintain Contractor Account Management documentation to include personnel clearance information, training records, contractor user account information (e.g. user-ids, access, quotas, and requirements) in accordance with DRD MA-014, Documentation.

24. Personnel Security Clearance is required. The work to be performed under this contract is up to the Top Secret level and will require Sensitive Compartmented Information (SCI) access eligibility for some personnel. Therefore, the company must have personnel that have and maintain a Final Top Secret Clearance commensurate with OPM Tier 4.

25. Ensure that when using NASA IP address space, only NASA-provided external Internet connections shall be used in accordance with Attachment J-7, Applicable Documents List (ADL), and NFS 1852.204-76, Applicable Documents List (ADL) and associated NASA Information Technology Requirements (NITRs).

26. Support a comprehensive Intrusion Detection System (IDS), IPS and Incident Response (IR) capability, in coordination with the NASA Security Operations Center (SOC).

27. Make available logs from any information systems, as requested by the NASA SOC and Cybersecurity Official. Electronic raw log data shall be forwarded to the SOC, in accordance with NASA policies, procedures and guidance.

28. Support NASA incident investigations. This includes providing analysis of the NASA traffic passing through NASA connections to any connections between NASA and its partners, even if they are utilizing NASA address space, including Internet connections.

29. Promptly coordinate Intrusion Detection/Incident Response identification/support on AEGIS systems and activities with the NASA SOC, the Center Cybersecurity Official (Center Information Security Officer (CISO), and Incident Response Manager (IRM)).

30. In support of CSPP, utilize NASA’s IT, Compute Services, and CP capabilities to perform the Cybersecurity support functions at all Centers, component facilities and Headquarters, in accordance with item 18 above.

31. Provide rapid response and mitigation as directed to any vulnerabilities or incidents that might occur.

This includes responses to threat notification, Risk Management, network monitoring, centralized database collections, Cybersecurity response tracking and analysis, and forensics in the Cybersecurity Incident Management Environment and provide to the Cybersecurity Official.

32. Establish and maintain information feeds with internal and external technical working groups to include IT and Cybersecurity professional associations, NASA Centers and component facilities, vendors, and national/international industry organizations.

C-29

45. Scan all information systems supported under this Contract for vulnerabilities (both credential and non-credentialed) in accordance with the NASA defined schedule and policy, using NASA approved tools and templates.

46. Review vulnerability reports provided from NASA and implement system patching as required. The contractor shall be held accountable for patching of all systems covered by CP managed SSP.

47. Provide scan configuration files and scan reports for all systems with an approved RBD that cannot run NASA approve reporting agent software.

48. Ensure that managed systems are rebooted on a regular basis, as necessary, to ensure patches are fully installed on systems and shall also provide deviation reporting and RBD requests in accordance with NASA policy for approval for mission-essential functions that would be adversely affected

49. Implement NASA approved ODV and Cybersecurity Standards and Engineering Team (CSET) baseline configurations as documented in Agency policy. Ensure all deviations are documented in NASA system of record

50. Plan for and implement the full system development lifecycle maintenance and updates of assets and systems, including but not limited to:

1. Near real time asset tracking and reporting (to include configuration management) from procurement to retirement in order to optimize the most accurate Cybersecurity response and analysis

2. Removal of retired systems from Active Directory, DNS Dynamic Host Configuration Protocol (DHCP) Internet Protocol Address Management (IPAM) (DDI) and pertinent Cybersecurity asset databases

3. End of Life and End of Support replacement strategy in accordance with NASA policy and requirements.

4. Complete data sanitization for assets in accordance with NASA policy and procedures.

51. Protect all information systems using NASA enterprise defined baseline configurations and other

NASA approved tools (including anti-virus and anti-spyware) solutions, which provide automated updates of malware/malicious code detection definitions at least once every 24 hours and automated logging and reporting.

52. Apply appropriate least-privilege access of system in accordance with NASA policy and guidance, as noted in item 18 above.

53. Comply with the Risk Information Security Compliance System (RISCS) and IT Security Enterprise Data Warehouse (ITSEC-EDW) reporting requirements, including security configuration profiles, patch management, hardware inventory, and software inventory. The CDM tools must be installed for reporting. For systems that cannot install CDM tools, a NASA-approved RBD must be submitted for approval, and the devices must be manually inventoried and reported in accordance with NASA policy and procedures, as noted in item 18 above.

54. For all managed systems, meet directives, emergency directives, required mitigations and compliance deadlines as set forth in Department of Homeland Security (DHS), OIG, GAO as well as any corresponding changes or updates within the directed timeframes.

55. Ensure the NASA-provided CDM solutions are installed and continue to function properly (based on NASA CSPP) on all supported IT devices and integrated with NASA reporting mechanisms, including RISCS and IT ITSEC-EDW.

56. Configure and maintain operating systems and software on all systems provided under this Contract in accordance with Federal and NASA Cybersecurity configuration policies and guidance. The Contractor shall ensure all applicable IT systems, applications, and services are securely configured based on the security configuration standards defined by CSPP

2.9 EXPORT CONTROL

C-35

17. As permitted by GSA regulations, initiate, prepare, submit, and track service orders on the GSA contracts and escalate any issues related to processing of these orders.

18. As permitted by GSA regulations, initiate, submit, and track requests for new accounts, deletion of accounts, and changes to GSA accounts on contractor business systems and GSA Services.

19. Coordinate telecommunications provider service orders and service order issues with the AEGIS contractor's internal organizations (for example, engineering, operations, business functions) and with NASA.

20. Support the COs and CORs of the NASA GSA Task Orders in performing acceptance testing of new services and perform ongoing monitoring of services delivered by the GSA contractors to ensure that the delivered services are in accordance with the requirements specified in the GSA's telecommunications services master contracts, NASA's task orders, and individual service orders.

21. Monitor GSA contractor performance relative to requirements and analysis of GSA contractor-provided reports and report results to COs and CORs of the NASA GSA Task Orders.

22. Coordinate network management and operations functions with GSA contractors, including but not limited to sharing of network monitoring and problem resolution information and processes, sharing of trouble ticketing information, and maintenance and exercise of escalation processes.

23. Conduct GSA contractor billing analysis, to include:

23.1. Maintenance of NASA's Agency Hierarchy Code (AHC) in accordance with NASA's requirements to report usage and billing to multiple accounts.

23.2. Ensuring that all service orders and associated invoices contain the correct AHC.

23.3. Reviewing and reporting of all GSA Contractor bills to ensure that the Contractor(s) are billing in accordance with the requirements specified in the GSA master contract, NASA's master agreement/delivery order, and individual service orders per DRD MA-014, Documentation.

23.4. Initiating, documenting, filing, tracking, reporting, reconciliation, and escalation of billing disputes with GSA Contractor(s) and ensuring that billing credits are applied to the correct NASA account per DRD MA-014, Documentation.

23.5. Identifying and reporting to NASA CO and COR any instances of fraud or abuse of GSA Contractor services.

23.6. Creating, maintaining, and distributing GSA telecommunications services contract(s) Task Order(s), contractor billing reports, and data to report costs by consumer (e.g., center, program/project, user, and account).

23.7. Review new/changed/deleted GSA contractor service offerings to determine the impact to NASA users.

23.8. Coordinate project management of activities related to transition of any GSA contractor services to new or different contract vehicles or service offerings.

23.9. Execute AEGIS individual nondisclosure agreements and conflict of interest forms for all employees supporting NASA in the placement of orders under the GSA contracted services contracts.

C-36

3 INNOVATION SERVICES

The Contractor shall provide Innovation Services that include both Innovation efforts of continuous improvement and innovation. Continuous improvement is defined as the ongoing effort to enhance the efficiency and effectiveness of the IT services. Innovation is defined as the process to identify and implement new ideas and break-through solutions that change and/or enhance the services and results in additional Business and/or IT value.

Innovation differs in that the former is identifiable and driven contractually committed year-over-year cost improvements for which a number of initiatives have been agreed between the Parties. Any updates and/or changes to the improvement initiatives that drive additional costs savings are considered part of Contractor’s continuous improvement efforts. Innovations are brand new and emerging ideas that cannot be identified upfront and emerge through market changes or completely new mechanisms that can become applicable and value adding to NASA. The innovation process may result in new discrete projects that each requires a business case for which the Return on Investment (ROI) will need to be identified and for which the funding will have to be agreed.

This Section describes the requirements for the Innovation Plan that the Contractor must create including the associated execution process. Such a plan must be established and agreed to with NASA within 90 days of the Contract Award Date.

3.1 GENERAL

This Section outlines process is fundamental to the continuous improvement of IT and its contribution to NASA’s competitive edge. The purpose is to describe the Business and Technology Innovation process, and the role of involved Parties in that process.

NASA expects the innovation ideas and results align with the NASA’s key drivers and the results are achievable in a short period, lead the NASA organization to be nimble, flexible and be agile in addressing the Business’ demands. NASA expects the Contractor executive leadership to be participative in this process, guide their teams in bringing practical ideas to bear.

Continuous Improvement is part of ongoing…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .