Historical Data - BITSec SOW.pdf
PDF 981 KB Posted
- Attached to
- Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) Federal contract opportunity
- Solicitation number
- 80TECH21R0007
About this file
This statement of work outlines IT security support services required, including contract management, policy management, risk management, identity management, authorization management, accountability management, availability management, configuration management, and incident management. Key requirements include web application security, vulnerability scanning and mitigation tracking, configuration compliance monitoring, and incident response support. The contractor shall utilize government-provided tools and systems to perform monitoring, scanning, tracking, and incident response. Deliverables include management plans, reports, and documentation to support the NASA IT security program.
The federal contract opportunity solicits proposals for cybersecurity and privacy enterprise solutions and services to support the NASA OCIO at all Centers and Facilities. Anticipated services include cybersecurity, privacy, related solutions, and services. The soliciting agency is the National Aeronautics and Space Administration.
View the file
Other files for this federal contract opportunity
Show all 50
Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CIO-SP3 – NITAAC Statement of Work (SOW)
4. Scope
The Contractor shall provide IT security support services that conform to best practices for protecting Federal Government IT systems and information to achieve the objectives listed in Section 3 above.
The Contractor shall provide support services for the following task areas in accordance with Section C, Description/Specification/Work Statement of the CIO-SP3 Small Business (SB) conformed contract:
1) Task Area 5: IT Operations and Maintenance
2) Task Area 7: Critical Infrastructure Protection and Information Assurance
The requirements of this task order are allocated among the following functional areas:
1) Contract Management
2) Policy Management
3) Risk Management
4) Identity Management
5) Authorization Management
6) Accountability Management
7) Availability Management
8) Configuration Management
9) Incident Management
5. Specific Tasks
5.1Contract Management
5.1.1Contract Management and Administration
The Contractor shall provide the management and administrative functions to satisfy the requirement of this contract. (DRD-1, Contract Management Plan)
The Contractor shall comply with all policies and procedures included in the Policy and Procedure Library. The Contractor shall ensure compliance with current approved versions.
The Contractor shall provide an Organizational Conflict of Interest Plan (DRD-6, Organizational Conflict of Interest Avoidance Plan) that details the approach and implementation methods to be used for avoiding organizational conflicts of interest.
The Contractor shall maintain the ability to obtain security clearances as required for work on this contract. The required National Security Facility Clearance (FCL) level for this contract is Secret (S). The specific security clearance requirement for work to be performed will be documented in the work orders.
The Contractor shall comply with the National Industrial Security Program Operating Manual (NISPOM) with respect to ensuring all contract personnel have a National security clearance commensurate with the highest level of classified information to which they have access.
The Contractor shall ensure that Contractor employees fulfill requirements for security screening so that the NASA Personal Identity Verification (PIV) card may be issued in a timely manner.
The Contractor shall provide an Annual Report of Onsite Employees (DRD-13, JSC IT Security Operations – Annual) which includes the physical location for each employee as well as the total headcount of onsite employees.
The Contractor shall establish Associate Contractor Agreements (ACAs) as necessary with other JSC and NASA Contractors as required to successfully fulfill the requirements of the BITSec task order (Attachment 2, Associate Contractor Listing).
The Contractor shall provide a Contract Status Report (DRD-12, JSC IT Security Operations – Monthly) that includes a brief narrative of significant accomplishments and other significant activities supported during the month, upcoming milestones of significance, and concerns. This input is used by the IT Security Office for Directorate, Center, and NASA Headquarters reporting.
The Contractor shall provide lessons learned per DRD-7, Safety and Health Plan, and also per JSC Procedural Requirement (JPR) 2310.1, JSC Organizational Learning Program and JPD 2310.2, JSC Organizational Learning Plan.
The Contractor shall provide all required deliverables (Attachment 1, JSC Data Requirements List (DRL) and Data Requirements Deliverable (DRD)) in electronic format unless otherwise directed.
5.1.2Safety and Health Management
The Contractor shall perform tasks to ensure the protection of personnel, property, equipment, and the environment in contractor products and activities. To ensure compliance with pertinent NASA policies, requirements, federal, state, and local regulations for safety, health, environmental protection, and fire protection, the contractor will develop and implement a safety and health program in accordance with DRD-07, Safety and Health Plan.
The Contractor shall provide an annual safety and health program self-evaluation per DRD-7, Safety and Health Plan.
The Contractor shall provide monthly safety and health metrics report per DRD-7, Safety and Health Plan.
JPR 1700.1, the “JSC Safety and Health Handbook” provides detailed requirements and instructions regarding safety and health procedures and policies at JSC. It can be viewed at http://jscHandbook.jsc.nasa.gov. Compliance with the Handbook is mandatory.
5.1.3Resources Management
The Contractor shall provide accurate and timely financial reports in accordance with NASA Policy Directive (NPD) 9501.1, NASA Contractor Financial Management Reporting System, NASA Procedural Requirement (NPR) 9501.2, NASA Contractor Financial Management Reporting, and NPR 9060.1, Cost Accruals. The Contractor shall deliver DRD-3, NF533.
The Contractor shall provide ongoing business analysis and respond to Government requests for financial information. In performing these functions, the Contractor shall:
1) Maintain detailed order and invoice records that support Government-performed invoicing (to customer organizations) and allow Government-performed invoice reconciliation.
2) Maintain customer order information as directed by the Government
3) Provide financial information maintained by the Contractor for use by the Government for budgeting purposes and business case analysis
4) Provide financial planning data to support the Government budget process including but not limited to: Planning, Programming, Budgeting, and Execution (PPBE) budget calls, Operating Plan budget calls, and special requests for budget impacts.
The Contractor’s internal accounting system shall fully accommodate Government reporting requirements as defined in DRD-3, NF533.
The Contractor shall conduct quarterly accounting reconciliations (planned versus actual expenditures).
The Contractor shall support a contract-wide requirements/budget review meeting with the Government on a quarterly basis. This internal review shall be scheduled for completion prior to the annual Capital Planning and Investment Control Process (CPIC) (DRD-2, IT CPIC) and the IRD Internal Task Agreements (ITA) Process.
5.1.4Risk Management
The Contractor shall identify, assess, evaluate, document, and manage risks associated with the performance of this task order.
The Contractor shall develop and utilize a Risk Management methodology that is complimentary to the JSC Risk Management Plan (JPR 8000.4) process and document its methodology for managing risk in DRD-1, Contract Management Plan.
5.1.5Facilities
The Contractor shall first consider utilizing facilities furnished by the Government. If offsite or corporate resources are proposed, the Contractor’s approach shall ensure that all required interfaces and collaboration with the Government and JSC contractors is attained. The Contractor shall be responsible for ensuring that all Contractor and Subcontractor staff complies with the operational policies and procedures for all contract specified facilities. Compliance also applies to Contractor-based facilities for the purposes of performance on this task order.
5.1.6Records Management
The Contractor shall maintain accurate and complete records (including legacy, electronic, paper, and vital records) and administer the disposition of these records and non-records in accordance with NPR 1441.1, NASA Records Retention Schedules, which has been approved by NASA and the National Archives and Records Administration (NARA).
The Contractor shall segregate NASA records from company-owned records and from non-record materials, and shall provide NASA or authorized representatives’ access to all Government records in accordance with FAR subpart 4.7, Contractor Records Retention. The Government reserves the right to inspect, audit, and copy record holdings.
The Contractor shall ensure that Government-owned data is in a format that is accessible, readable, and usable by the Government.
The Contractor shall deliver Government-owned records to the appropriate Center records manager for dissemination to the Office of Primary Responsibility (OPRs).
The Contractor shall provide the Government (or authorized representative as designate by the Contracting Officer’s Representative (COR)) with access to all Government records upon request.
The Contractor shall maintain a records management program for all data/records produced as part of this task order and electronically submit a records management plan in accordance with JPR 1440.3, JSC Records Management Procedural Requirements (shall be submitted as part of DRD- 1, Contract Management Plan). The Contractor shall utilize specific contract and account record management systems when such systems are provided by the Government.
The Contractor shall deliver records to the Center Records Manager in accordance with NPR
1441.1 at the completion or termination of this task order or as the record retention schedule expires. When in doubt of the ownership of records, the Contractor shall submit electronically to the Contracting Officer (CO) a request for a determination from the Center Records Manager as to which records are subject to this direction.
5.1.7Configuration Management
The Contractor shall provide, utilize, and maintain a configuration management (CM) process that is compliant with the Information Resources Directorate (IRD) Configuration Management Plan (JSC-29173). The process shall be documented in DRD-1, Contract Management Plan. The plan shall, at a minimum, describe the Contractor’s approach for establishing and documenting configuration baselines; describe the systems and processes to be used for configuration management and change control; describe how the Government will be involved in the change review and approval process; and artifacts and quality records that are produced and relevant to documenting configuration baselines and decision, including those which provide traceability across versions.
5.1.8Work Authorization Management
The Government will authorize work by issuing work orders in accordance with Clause 15.3 of the BITSec task order
The Contractor shall utilize a Government-provided electronic repository, such as the IRD SharePoint Installation, for processing work orders.
5.1.9Business Hours
The Contractor has the option to conform with the JSC Super-Flex work schedule per JSC Procurement Instruction (JPI) 52.242-90, JSC Super-Flex Work Schedule. The Contractor shall provide support during non-standard periods as needed to address special needs, such as incident handling, immediate responses to high risk threats and vulnerabilities, and responses to actions such as quick-turnaround data calls.
5.1.10 Quality Management and Control
The Contractor shall establish and maintain a Quality Management System (QMS) in conformance with International Organization for Standardization (ISO) 9001 current version and the JSC Quality Manual, JPR 1280.2. The Contractor shall document key processes and procedures using JSC-approved ISO formats where required.
5.1.11 Training and Certifications
Contractor employees performing work under this task order shall complete the NASA-provided annual IT Security Awareness Training. The Contractor shall provide evidence that IT security awareness training requirements have been met for all employees subject to this contract. The Contractor shall submit periodic reports (as required by the CO) detailing the overall status of BITSec compliance with the annual training requirement. The annual training program is defined as the period from October 1 through September 30. The due date for JSC is identified by NASA Headquarters and can vary by year. The IT Security Awareness Training is delivered via desktop workstation and takes approximately 1 hour to complete.
The Contractor shall maintain the technical skills and relevant certifications necessary to fulfill the requirements of the task order. Certification and skill requirements are identified in Attachment 4, Standard Labor Categories.
5.1.12 Innovation and Continuous Improvement
The Contractor shall incorporate strategies for achieving Innovation and Continuous Improvement as an element of DRD-1, Contract Management Plan. Contractor proposed innovations and improvement shall result in improved products or services while maintaining or reducing costs to the Government. An increase in costs to the Government or change in scope requires concurrence from the CO before implementation.
The Contractor shall continuously seek to identify process and service improvement through benchmarking of other government or private institutions, industry offerings, standards bodies, best practices, etc., and shall present recommendations to the Government using the Innovation and Continuous Improvement Report (DRD-17, JSC IT Security Operations – Semi-Annual).
The Contractor shall consider the Statement of Work (SOW) in its approach to ensure alignment with security program objectives, but proposed changes shall not be limited by the SOW.
5.1.13 Information Technology (IT) Security Management
The Contractor shall provide for the protection of information and secure operation of any IT resources used in the execution of this task order and the services it provides.
The Contractor shall provide an Information Technology Security Management Plan (ITSMP) (DRD- 11, Information Technology Security Management Plan) that describes how the Contractor will meet IT Security requirements in the performance of this task order. This includes information and systems managed on behalf of the Government, as well as information and systems that are owned and managed by the Contractor used in performance of the BITSec task order. The ITSMP shall be maintained on an annual basis to reflect changes to security related processes or the baseline configuration of the systems, or as otherwise directed by the Government.
The Contractor shall provide a System Security Plan (SSP) (DRD-15, JSC IT Security Operations
– As Directed) for Government-owned systems managed or operated in support of this task order.
The System Security Plans are maintained continuously, with self-assessments performed annually. All System Security Plans are assessed by the IT Security Program every 3 years.
The Contractor shall designate an Information Systems Security Officer (ISSO) who is responsible for the Contractor’s system(s) in accordance with the definitions set forth in NPR 2810.1, Security of Information Technology. The Contractor’s ISSO shall be responsible for ensuring the development of System Security Plans for resources owned and managed by the Contractor to perform work on this task order.
The Contractor shall designate an IT Security Point of Contact for matters pertaining to IT Security that occur during the performance of this task order.
5.1.14 Capital Planning and Investment Control (CPIC)
The Contractor shall provide, annually as part of the Government’s CPIC and PPBE reporting cycle, a comprehensive and detailed report of all Contractor-planned and actual task order IT expenditures (labor and materials) in support of an annual Office of Management and Budget (OMB) data call.
Details of reporting requirements for this task may be found in DRD-2, CPIC. The Contractor shall provide CPIC data which is consistent with the Financial Reporting identified in Section 5.1.3, Resources Management.
5.1.15 Technical Support
The Contractor shall participate in control boards, working groups, meetings, and other forums for information gathering, sharing of technical expertise, or as technical representatives of the IT Security Office. Involvement shall be coordinated in advance with the Government to ensure that the support requirement is understood and the appropriate skill level is identified. Meeting artifacts such as handouts, decisions made, actions assigned, etc. are to be provided to the Government within 5 working days of the activity supported, unless otherwise directed by the Government.
The Contractor shall provide support for planning, organizing, data gathering, analysis, development of documentation artifacts, and status tracking, for Agency data calls and other initiatives. Examples include the recent Cyber Sprit initiative, and the efforts to remove Windows XP and Server 2003 from the NASA IT environment. This support also extends to the preparation of official responses. Any associated artifacts shall be defined by working closely with the Government, and shall be provided as directed.
The Contractor shall provide support for tracking customer questions, requests for support, security consideration of proposed technical changes and other issues and actions. The Contractor shall assist in monitoring the IT Security Mailboxes, distributing actions to appropriate personnel as identified by the Government, and ensuring that responses are disseminated, logged, and marked as closed.
The Contractor shall participate with the Government in the development of a customer feedback process to assess the products and services provided under the JSC IT Security Program. This includes the development of a feedback process, documentation artifacts, and a statistical summarization method to assist in the evaluation of customer responses.
5.1.16 Customer Support
The Contractor shall utilize the Government provided Enterprise Service Desk ticketing system to enable accurate tracking, routing, and reporting of customer requests and ensure a timely response to customer requests for service. Request types currently include Web and Vulnerability Scanning and Consolidated Logging.
The Contractor shall develop and deliver a JSC IT Security Help Desk Interface Plan (DRD-16, JSC IT Security Policies, Procedures, and Plans) to describe how the tickets will be assigned, monitored, updated, and closed. The Contractor shall make revision to this plan as requirements change or as directed by the Government.
The Contractor shall work with end-users to gather detailed requirements when needed.
The Contractor shall monitor and assign help desk tickets to the responsible area of this task order, and initiate response efforts as described in Attachment 6, Response Times.
The Contractor shall immediately notify the Government of any disruption to ticket issuance or management process.
The Contractor shall provide a Customer Service Report. (DRD-12, IT Security Operations – Monthly)
5.2Policy Management
5.2.1Policies, Procedures, and Documentation
The Contractor shall develop and maintain policy and procedural documentation in support of the JSC IT Security Program.
The Contractor shall propose policy and procedure documentation requirements, and shall work closely with the Government to agree upon the specific documents to be supported as well as the overall intent of a proposed document, or change to an existing document.
The Contractor shall research NASA policy, Public Law, and Industry Best Practices to develop requirements for new or revised policies and procedures which enhance the daily operation of the JSC IT Security Program.
The Contractor shall comply with JPR 1410.2 JSC Directives Procedural Requirements and JSC- 27835 Information Resources Directorate Document Control Procedures.
The Contractor shall develop and maintain Standard Operating Procedures (SOPs) in support of this task. (DRD-13, JSC IT Security Operations – Annual)
The Contractor shall develop establish internal processes and controls to ensure compliance with document management processes and standards, and that documents submitted meet Government specified requirements.
The Contractor shall ensure that document elements are integrated to avoid overlap and inconsistencies with other published guidance.
The Contractor shall ensure that all documents are reviewed annually in order to ensure they are current with respect to public law, and other policy and procedural requirements, as well as with directorate document control standards.
The Contractor shall propose the retirement of any documents which are no longer required.
The contractor shall provide an outline and draft of new or revised documents for review and feedback in order to ensure efforts are in alignment with office and program objectives. At the Contractor’s discretion, a review may be held with the Government when document development is approximately 80% completed. A final review shall be held with the document is delivered for final review.
The Contractor shall prepare and lead a document delivery review for any documents submitted for Government consideration.
The Contractor shall deliver released documents into a Government-owned and approved document repository including SharePoint, IRD Organizational Master List, and the NASA Online Directives System.
The Contractor shall deliver requested documents by the agreed-upon due date.
The Contractor shall participate in directorate documentation management initiatives as directed, and shall work to ensure seamless integration of document support processes with directorate document control processes, standards, and procedures.
The Contractor shall provide an annual Policy and Procedure Report of all documents currently maintained or in work. (DRD-13, JSC IT Security Operations – Annual)
5.3Risk Management
5.3.1Risk Assessment
Risk Assessments of organizational security programs and plans are to be performed using a Risk Management Framework and methodology that is compliant with National Institute of Standards and Technology (NIST) Special Publications (SP) 800-39, Managing Information Security Risk, and NIST SP 800-37, Guide for Applying Risk Management Framework to Federal Information Systems.
Security plans and organizational program plans are assessed by the organizations themselves for compliance using NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations. The artifacts of these assessments feed the risk assessment activities performed by the BITSec task order, which in turn inform the JSC Security Program Review process. Results of risk assessment shall be used to compute an aggregate risk score for the
Center as a whole. This is to be provided in the Security Program Review Annual Status Report (DRD-13, JSC IT Security Operations – Annual)
The Contractor shall train JSC organizations to perform risk management activities consistent with the Risk Management Framework.
The Contractor shall facilitate customer access to Risk Management Framework templates and other documentation artifacts.
The Contractor shall create and/or customize templates as requested by the Government. The Contractor shall deliver Risk Management Framework templates and checklists to the Government.
(DRD-15, JSC IT Security Operations – As Directed)
The Contractor shall provide assistance to the JSC Organizations in the form of intranet sites, printed training material, meeting support, presentations, and other resources as directed by the Government.
The Contractor shall conduct reviews to assess the quality and completeness of documentation artifacts produced by JSC organizations related to the Risk Management framework.
At the direction of the Government, the Contractor shall review JSC and NASA risk assessment policy and standard documentation, Public Laws, and Industry Best Practices, and propose changes to JSC documents and processes as necessary in order to ensure that risk assessment processes and standards adhered to are the most current and relevant.
The Contractor shall update relevant online systems as necessary. Examples include the JSC Integrated Risk Management Application (IRMA) and the NASA Security Assessment and Authorization Repository (NSAAR).
The Contractor shall notify the JSC CISO within 4 hours of any observation that presents an imminent or particularly harmful risk to the Center. Examples typical of this type of concern may include a finding of a high security system or high valued asset that has an ineffective systems control implementation, a misconfigured boundary protection system that exposes the Center to attack, and unprotected Personally Identifiable Information (PII).
The Contractor shall provide a quarterly report of JSC Risk Assessment Summary Report. (DRD- 14, JSC IT Security Operations – Quarterly)
5.3.2Security of Specialized Systems
Specialized systems are defined as those systems which provide capabilities above and beyond those of general computing systems, and which do not conform to standard computing systems management and security methods. Examples include Industrial Control Systems (ICS), Robotics Systems, and Laboratory Equipment Control Systems.
The Contractor shall work closely with the IT Security Office and Center organizations to develop and maintain an inventory of specialized systems which will be used to monitor compliance as well as serve to determine and manage the risk to the Center posed by these systems. The inventory will support the development of response to data calls, and lend structure to efforts to mitigate special risk situations as they arise. The inventory shall typically include system name, physical address, network address, physical location, Information System Owner (ISO), key points of contact, and may include other fields as determined necessary in the implementation of this effort.
The Contractor shall provide a JSC Specialized System Status Report. (DRD-17, JSC IT Security Operations – Semi-Annual)
5.3.3IT Security Training and Awareness
The Contractor shall provide content, develop materials, and deliver briefings in support of IT Security training and awareness outreach efforts. The Contractor shall support Government-requested initiatives and shall propose new initiatives for Government consideration. Training and awareness topics may include the full breadth of the JSC IT Security Program and IT Security discipline. Examples include training for IT Security professionals at JSC, such as the Organizational Computer Security Officials (OCSOs), training and awareness initiatives for the general JSC population such as the annual “Cybersecurity Month” event, JSC Total Safety and Health event, special events offered to address areas of concern or interest to enhance the overall effectiveness of the JSC IT security effort, or training to help organizations and individuals fully understand the many aspects of compliance that contribute to overall security effectiveness. The Contractor shall propose and support methods and initiatives which maximize the sharing of information and lessons learned across the full scope of the IT Security Program.
The Contractor shall work closely with the IT Security training and awareness lead in the development and maintenance of an IT Security Awareness and Outreach Plan (DRD-16, JSC IT Security Policies, Procedures and Plans) that describes the initiatives and the schedule for delivery of each.
The Contractor shall develop and maintain professional quality IT security awareness, training presentations, and outreach materials that are thoroughly researched, logically organized, and free of formatting, grammar, and spelling mistakes.
The Contractor shall provide content and customization for the JSC IT Security Intranet site hosted in SharePoint. The site includes awareness and training materials and other resources. The site will be provided by the Government, and will be utilized by the JSC community for IT Security awareness and education purposes.
The Contractor shall monitor and report the completion status of the Center for the annual Information Security Awareness program and other training initiatives. Examples include the Managed Elevated Privileges and Role-based Training initiatives. The Contractor shall submit periodic reports (as required by the CO) detailing the overall status and effectiveness of the annual training program, including recommendations for improvement. The annual training program is defined as the period from October 1 through September 30.
The Contractor shall provide a Required IT Security Training Report. (DRD-15, JSC IT Security Operations – As Directed)
The Contractor shall provide the JSC IT Security Training and Awareness Report. (DRD-17, JSC IT Security Operations – Semi-Annual)
5.3.4Program Review
The Contractor shall implement the JSC Security Program Review (SPR) process under the guidance of the Government to ensure the JSC IT Security Program and its constituent parts fulfill security requirements specified by the NASA Agency IT Security policies and handbooks. The JSC SPR process utilizes the NIST Program Review for Information Security management Assistance (PRISMA) approach and reporting techniques outlined in NISTIR 7358 (NIST Interagency Report:
Program Review for Information Security Management Assistance).
The Contractor shall provide a certified lead auditor in support of the JSC Security Program Review effort.
The Contractor shall create and deliver a JSC IT Security SPR plan (DRD-16, JSC IT Security Policies, Procedures and Plans) which describes how the Contractor will implement support for the JSC IT Security SPR program. This plan shall be delivered within 45 calendar days of task order start, and then updated as directed.
The Contractor shall assess the impact of modifications to the program implementation as the program evolves and matures. The Contractor shall ensure the SPR implementation is efficient and effective, and shall recommend improvements to the SPR program processes and artifacts.
The Contractor shall provide an overview of JSC and Agency security program changes to JSC organization and their support contractors as directed by the Chief Information Security Officer (CISO). Overviews may be expected to identify and discuss the details of changes and describe their impact on systems operations, security plans, staff, audit and assessment requirements, documentation artifacts, processes, etc. A schedule for change effectivity would also typically be included.
The Contractor shall review each JSC Directorate’s organization security program on an annual basis, including those of contractors supporting the organization, and rate these according to their effectiveness in managing risk inherent in the use, operation and maintenance of IT systems and the management of information. Reviews are comprehensive in terms of reviewing systems, processes, and other artifacts which contribute to understanding the nature and effectiveness of the security management program. A list of artifacts typically include in an SPR review is included in the document Sample Security Program Review: Review Criteria. (Attachment 5, Sample Security Program Review: Review Criteria.) The Contractor shall integrate the results of reviews into the Security Program Review Annual Status Report (DRD-13, JSC IT Security Operations – Annual). The Contractor shall develop and maintain a Government Security Program Review Schedule (DRD-13, JSC IT Security Operations – Annual). The Contractor shall prepare supporting materials and participate in CISO-led SPR review. The Contractor shall provide support for tracking and resolving questions and actions resulting from SPR reviews.
The Contractor shall maintain the results of SPR reviews as an evidence package, which is also a Quality Record. This provides objective evidence to NASA internal auditors, the NASA Office of Inspector General and external organizations that the System Security Plan is in compliance with public law, Federal policies and standards, and NASA policies. Examples of evidentiary items include interview notes, intermediate risk calculate inputs and scores, analysis products to determine risk scores, and research conducted to independently validate statements about systems capabilities.
The Contractor shall develop and maintain best practices, guides, and presentations which illustrate the JSC SPR process and assist organizations in their implementation. The Contractor shall deliver these artifacts into a Government-owned and approved document repository. Examples include SharePoint, the IRD Organization Master List, and the NASA Online Directives System.
The Contractor shall, as JSC and WSTF contracts are being awarded or renewed, review the contractor’s SMP and provide the findings of the review to the Government. Upon notification by the Government that a contractor SMP review is needed, the Contractor shall complete the review within 30 calendar days.
The Contractor shall perform Security Control Assessments (SCAs) annually in support of the Assessment and Authorization Official (AAO) and the SPR process. The SCA effort includes the assessment of Agency and Center hybrid security controls; validation of continuous monitoring of NASA selected security controls; assessments of applicable security controls related to existing Plan of Action and Milestones (POA&M) and Risk Acceptances; assessment of agency-specific critical security controls; review of System Security Plan (SSP) and associated documentation including the Contingency Plan and Security Assessment Report (SAR); verification that systems are compliance with standards and other technical requirements and guidelines such as the US Government Configuration Baseline (USGCB), required patch levels, awareness and management of vulnerabilities and security logging requirements; interview of organization security personnel;
documentation of annual security control results and generalization of a SAR; and notification to organizations of due dates for documentation and annual assessment. The product of this assessment effort is the Authorization to Operate (ATO) Package, which is delivered to the Government Assessment and Authorization Official (AAO) for review. The finalized package is then used as supporting material for the ATO discussion.
The Contractor shall support the development and distribution of assessment and authorization related templates, documents, and procedures for the assessment and authorization program;
review the Center’s common and hybrid security controls as defined in the Center’s Common Control providers and pull them all together in a Center SSP; and provide technical support and consultation to JSC organizations.
The Contractor shall participate in Agency and Center level Assessment & Authorization (A&A), and Continuous Monitoring related working group. The Contractor shall disseminate information resulting from such participation. Dissemination efforts shall be closely coordinated with the Government to ensure appropriateness and consistency with program goals and objectives.
The Contractor shall provide a Security Program Review Schedule. (DRD-13, JSC IT Security Operations – Annual)
5.4Identity Management
5.4.1Identity, Credential, and Access Management (ICAM)
The Contractor shall work closely with the ICAM Subject Matter Expert (SME), a Civil Servant, to perform planning, and documentation support in support of the Agency ICAM initiative.
The Contractor shall, as defined by the Government, participate in working group activities, meetings, and teleconferences in support of ICAM. Examples include technical working groups, user forums, Personal Identity Verification (PIV) status and planning discussions, and export control meetings.
The Contractor shall review and disposition NASA Access Management System (NAMS) related Service Requests (SRs) per guidelines provided by the Government.
The Contractor shall respond to questions from Center organizations regarding ICAM policies and procedures.
5 5Authorization Management
5.5.1Traffic Monitoring
The Contractor shall utilize content and traffic monitoring tools at the JSC and WSTF campuses to monitor for malicious cyber activity and inappropriate usage of Government systems using the Government-provided tools listed in Attachment 3, List of Installation Provided Facilities and Services.
The Contractor shall provide a Web Proxy Surveillance and Operations Plan (DRD-16, JSC IT Security Policies, Procedures and Plans) that describes the approach to monitoring the proxy systems.
The Contractor shall utilize the web proxy reporting system to generate reports as directed by the Government. An example of a report requires would be a traffic analysis report. Another would be a report of user activity customized to parameters relating to the particular type of user access.
The Contractor shall utilize the Proxy Anti-Virus scanning system to scan for files infected with Internet based threats (virus, worm, Trojan, or spyware).
The Contractor shall determine the necessary file detection parameters to address specific threats and coordinate any recommended signature changes with the Government prior to implementation.
The Contractor shall monitor the web proxy to detect unusual web access patterns which may indicate unauthorized activity, contact with harmful web sites, or unofficial use of internet services which may be in violation of the acceptable use policy established by NAS (NPD 2540.1, Personal Use of Government Office Equipment Including Information Technology) and JSC restrictions implemented through proxy filers.
The Contractor shall report any violations of the acceptable use policy to the JSC Incident Response Manager (IRM) within three business days of detecting of discovering the activity.
The Contractor shall monitor proxy events for malicious activity. If the activity being monitored indicates that a JSC system is potentially affected with a threat, the Contractor shall open a NASA Security Operations Center (SOC) Incident Management System (IMS) ticket, and categorize the incident based on the United States – Computer Emergency Readiness Team (US-CERT) Federal Agency Reporting Categories.
The Contractor shall request enhancement to the web proxy by making recommendations to the Government for performance and other platform capability changes based upon threats, loading, performance, etc. Approved changes shall be implemented under a plan and schedule approved by the Government.
respond to web application scan requests to request services from the IRD Operations Support Contractor.
The Contractor shall respond to “whitelisting” or “blacklisting” requests. When a web site is required to be whitelisting (meaning access will be granted through the web proxy), the Contractor shall conduct a threat assessment on the web site. The results of the threat assessment should accompany a recommendation to the Government for specific mitigation steps to support the request. All whitelist and blacklist requests shall be approved by the Government prior to implementation. Based upon Government direction, the Contractor shall coordinate the implementation of the whitelist/blacklist request with the relevant IRD or Agency operations support contractor. Examples include the Communications, Outreach, Multi-media & Information (COMIT) and the NASA Integrated Communications Services (NICS) contracts. The Contractor shall also contribute content and expertise to technical discussions relating to the board disposition, implementation, and retirement of the proposed rules.
The Contractor shall, annually, obtain and review the list of proxy user accounts to ensure any inactive or unauthorized users are deleted. If users need to be removed from the system, provide recommendations to the Government, and work with the IRD Operations Support contractor to make the approved changes.
The Contractor shall immediately contact the IRD Help Desk to notify system administrators of any loss of service impacting the JSC or WSTF Proxy.
The Contractor shall provide a JSC Web Proxy Activity Report. (DRD-14 JSC IT Security Operations – Quarterly)
5.6Accountability Management
5.6.1Consolidated Logging System
The Contractor shall use the Government provided Consolidated Logging System (CLS) tool listed in Attachment 3, List of Installation Provided Facilities and Services.
The Contractor shall proactively renew log events from multiple sources to identify threats and to integrate cyber threat indicators, as directed by the Government, to find correlating activity.
The Contractor shall develop, maintain, and support changes to organizational CLS dashboards.
A dashboard typically displays system log information pertinent to a particular organization’s systems.
respond to CLS Custom dashboard requests.
The Contractor shall, annually, obtain and review the list of CLS user accounts to ensure any inactive or unauthorized users are deleted. If users need to be removed from the system, provide recommendations to the Government, and then use the Government provided Enterprise Service Desk ticketing system to request services from the IRD Operations Support contractor to implement approved changes.
The Contractor shall create and maintain custom alerts as directed by the Government.
The Contractor shall coordinate with other organizations to determine the effectiveness of the consolidated logging capability and provide recommendations to the Government for needed changes. An example of such a change is a dashboard enhancement. Another example would be the creation of a new log.
The Contractor shall monitor CLS events for malicious activity. If the activity being monitored indicates that a JSC system is potentially infected with a threat, the Contractor shall open a NASA SOC IMS ticket, ensure the CLS is identified as the primary method used to identify the incident, and categorize the incident based on US-CERT Federal Agency Reporting Categories.
The Contractor shall report any violations of the acceptable use policy to the JSC Incident Response Manager (IRM) within 3 business days of detecting or discovering the activity.
The Contractor shall work closely with the Government to define support requirement for mission critical periods, such as prior to and during vehicle launch operations, on-orbit docking activities, de-orbit and landing. Support requirements for these periods typically includes more aggressive monitoring and reporting for suspicious events. The schedule for this type of support is dynamic and will adapt to mission related scheduling.
The Contractor shall provide a JSC CLS Report. (DRD-14, JSC IT Security Operations – Monthly)
5.6.2Intrusion Detection System
The Contractor shall use the Government provided Intrusion Detection System (IDS) tool listed in Attachment 3, List of Installation Provided Facilities and Services.
The Contractor shall conduct an annual assessment of the IDS implementation and provide recommendations to the Government in order to optimize sensor placement within the network.
The technical configuration information needed for this effort will be maintained by the relevant IRD or Agency Operations Support contractor. Examples include the COMIT and NICS contracts. The Contractor shall deliver any artifacts resulting from these assessments into a Government owned and approved document repository. Examples include SharePoint, the IRD Organizational Master List, and the NASA Online Directives System.
The Contractor shall create and test custom IDS rules intended to address specific threats, recommend implementation changes to the Government, and at the direction of the Government, coordinate the implementation with the relevant IRD or Agency Operations Support contractor.
Examples include the COMIT and NICS contracts.
The Contractor shall monitor the IDS rule-base weekly to ensure that signatures are current, and immediately notify the Government of any exceptions.
The Contractor shall support efforts to integrate JSC IDS with other Agency IDS capabilities as directed by the Government.
The Contractor shall monitor IDS events for malicious activity. If the intrusion event being reviewed indicates that a JSC system is potentially affected, the Contractor shall open a NASA SOC IMS ticket, ensure the IDS is identified as the primary method used to identify the incident, and categorize the incident based on US-CERT Federal Agency Reporting Categories.
The Contractor shall work closely with the Government to define support requirements for mission critical periods, such as prior to and during vehicle launch operations, on-orbit docking activities, de-orbit and landing. Support requirements for these periods typically includes more aggressive monitoring and reporting for suspicious events. The schedule for this type of support is dynamic and will adapt to mission related scheduling.
The Contractor shall report any violations of the acceptable use policy to the Government in writing within 3 business days of the observation.
The Contractor shall recommend baseline thresholds for each threat level (high, medium, low) associated with IDS events.
The Contractor shall ensure the IDS rule-base is updated to eliminate known false-positives. The Contractor shall coordinate the implementation with the relevant IRD or Agency Operations Support contractor. Examples include the COMIT and NICS contracts.
The Contractor shall, annually, obtain and review the list of IDS user accounts to ensure any inactive or unauthorized users are deleted. If users need to be removed from the system, provide recommendations to the Government, and then use the Government provided Enterprise Service Desk ticketing system to respond to request services from eh IRD Operations Support contractor to implement approved changes.
The Contractor shall provide a JSC IDS Report. (DRD-14, JSC IT Security Operations – Quarterly)
5.6.3Cyber Threat Indicator Evaluation
The Contractor shall assess cyber threat indicators provided by Government sources, which include the NASA Security Operations Center (SOC), Third-Party Cyber Intelligence Repositories (CIR), and Non-NASA Government Agencies.
The Contractor shall use multiple Government provided systems to conduct Cyber Threat Analysis.
A complete list of available tools is described in Attachment 3, List of Installation Provided Facilities and Services.
The Contractor shall, within 45 calendar days of task order award, deliver a Cyber Threat Analysis Plan (DRD-16, JSC IT Security Policies, Procedures and Plans) which defines how the Contractor will assess, monitor, and respond to cyber threat indicators.
The Contractor shall work closely with the Government to define support requirements for mission critical periods, such as prior to and during vehicle launch operations, on-orbit docking activities, de-orbit and landing. Support requirements for these periods typically includes up to date monitoring of cyber-threat repositories, and alerting of threat considerations. The schedule for this type of support is dynamic and will adapt to mission related scheduling.
The Contractor shall recommend configuration changes and enhancements to IT Security systems to improve network threat analysis.
The Contractor shall propose recommendations to monitor other CIR not currently being assessed and monitored. Cyber threat indicators may contain Classified National Security Information (CNSI) up to and including the Classification Level SECRET.
The Contractor shall meet all requirements necessary to perform work on CNSI up to and including the Classification Level SECRET. All work involving CNSI shall be performed on NASA Government property within areas designated for the processing and storage of Classified National Security Information up to and including the Classification Level SECRET.
5.6.4Wireless Network Security
The Contractor shall use the Government provided Wireless Intrusion Detection System (WIDS) too listed in Attachment 3, List of Installation Provided Facilities and Services.
The Contractor shall monitor WIDS events for malicious activity. If the intrusion event is being reviewed indicates that a JSC system is potentially affected, the Contractor shall open a NASA SOC IMS ticket and categorize the incident based on US-CERT Federal Agency Reporting Categories.
The Contractor shall plan, conduct, and deliver to the Government the results of Wireless Network Security Assessments. (DRD-15, JSC IT Security Operations – As Directed)
The Contractor shall provide expert knowledge on wireless network threats and vulnerabilities.
5.6.5IT Security Engineering
The Contractor shall provide a flexible, scalable, and responsive engineering capability for the purpose of assessing emerging and new IT Security service concepts and technologies, implementing new or revised capabilities, integrating new and changed systems with other systems and processes within the JSC and NASA information technology environment, performing operations and sustaining engineering for production systems and technical capabilities, and performing studies, developing plans, or resolving problems and concerns of a unique, complex, or specialized character.
The Contractor shall deliver an Engineering Management Plan (DRD-16, JSC IT Security Policies, Procedures and Plans) for the lifecycle management of engineering efforts within 45 days of task order award.
The Contractor shall define formal requirement specifications and develop operations concepts and designs in response to Government provided requirements. The Contractor shall also define performance and availability requirements, maintenance and obsolescence management processes, operations monitoring and incident response requirements and procedures, and disaster recovery and business continuity requirements as directed.
Proposals that result from assessments shall include background, business case justification, concept of operations, side by side options analyses, full lifecycle costs for the proposed capability as well as other affected systems or system elements, decision rationale, recommendation and proposed schedule. Requests for studies shall thoroughly address the topic and include the rationale for any conclusions or recommendations presented.
All project plans and documentation artifacts should conform to IRD project and document management processes (see JSC 66562, IRD Project Management Procedure) and procedures, and shall be provided electronically through approved electronic repositories, except as otherwise directed.
At the direction of the…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .