IT Security Management Plan Fillable Form V9.pdf
PDF 426 KB Posted
- Attached to
- Sounder for Microwave-Based Applications (SMBA) Phase A Study Federal contract opportunity
- Solicitation number
- 80GSFC23R0008
About this file
This document provides details for the Sounder for Microwave-Based Applications (SMBA) Phase A Study federal contract opportunity. The National Aeronautics and Space Administration Goddard Space Flight Center is soliciting proposals for a definition study and design development as part of SMBA formulation activities. The contract will be a firm fixed price award not to exceed $5 million for a one year period of performance. The study is for the SMBA instrument that NASA plans to fly on the National Oceanic and Atmospheric Administration's Near Earth Orbit Network program satellites beginning with a 2031 launch. The solicitation is available under request number 80GSFC23R0008, with proposals due by the anticipated October 20, 2023 contract award date and effective date. The contract will be conducted at the contractor's facilities as a full and open competition under North American Industry Classification System code 541330 and a $25.5 million small business size standard.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFP 80GSFC23R0008 Amendment 2.pdf | ||
| RFP 80GSFC23R0008 SMBA Phase A QA 2 (20230309).pdf | ||
| RFP 80GSFC23R0008 SMBA - Phase A - Cover Letter (Amendment 1).pdf | ||
| Attachment A - SMBA Statement of Work Revision A.pdf | ||
| RFP 80GSFC23R0008 SMBA Phase A QA 1 (20230306).pdf | ||
| RFP 80GSFC23R0008 Amendment 1.pdf | ||
| Attachment I - Contract Data Requirements List.pdf | ||
| Attachment I DRD 2- DEIA Plan.pdf | ||
| Attachment I DRD 1 - OCI Plan.pdf | ||
| RFP 80GSFC23R0008 SMBA - Phase A.pdf | ||
| Attachment C - SMBA Instrument Mission Assurance Requirements.pdf | ||
| RFP 80GSFC23R0008 SMBA - Phase A - Cover Letter.pdf | ||
| Attachment A - SMBA Statement of Work.pdf | ||
| Attachment B - SMBA Performance Specification Document.pdf | ||
| Attachment F - IT Security Applicable Documents List.pdf |
Show all 15
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CUI
VERSION 9 9/2022
Information Technology Security Management Plan
Issue Date:
Effective Date:
**If additional justification is required for any part of the Security Management Plan, please submit a separate word document. Please reference the paragraph number from this document that you are expanding on**
Preface To carry out its wide-ranging responsibilities, the National Aeronautics and Space Administration (NASA), and its employees and managers have access to diverse and complex automated information systems, which include file servers, local and wide area networks running on various platforms, and telecommunications systems to include communications equipment. The offices within NASA depend on the confidentiality, integrity, and availability of these systems and their data in order to accomplish day-to-day activities.
This plan shall describe the processes and procedures that will be followed to ensure appropriate security of IT resources that are developed, processed, or used under this contract. Unlike the IT security plan, which addresses the IT system, the IT Security Management Plan addresses how the contractor will manage personnel and processes associated with IT Security on the instant contract.
The ITSMP is a document required by the NASA FAR to be created and submitted within 30 days of contract award for all contracts, regardless of whether they encompass an information system. The ITSMP should be utilized by all contracts to satisfy the ITSMP FAR clause requirement. Additionally, if the contractor is responsible for an external information system, this document may be leveraged for the completion of an external information system IT Security Plan (reference Information Technology Security Handbook ITS- HBK-AASTEP5.v1.0.0).
Change History Version Date Change Description 1.0
IT Security Management Plan Review and Approval
This Information Technology Security Management Plan (ITSMP) for the was prepared for the exclusive use of NASA and completed on
I have reviewed the contents of this plan, and believe that it presents an accurate representation.
Reviewed by:
ISSO, or equivalent
Date
Concurred by:
COR/Task Monitor
Date
Approved by:
Center CISO
Date
Accepted by:
Contracting Officer
Date
Contents Preface ....................................................................................................................................................................................................... ii
Change History ......................................................................................................................................................................................... iii
IT Security Management Plan Review and Approval ............................................................................................................................... iv
1 Contract Identification
1.1 Contract Name
1.2 Contract Number
1.3 Responsible Organization
1.4 Contact Information
1.4.1 Physical Location
1.4.2 Points of Contact
1.5 General Contract Description
1.5.1 Information System
1.5.2 Contractor Badging
1.5.3 Supply Chain Risk Management (SCRM)
1.5.4 Related Documents
2 Security Control Implementations
2.1 Management Controls
2.2 Operational Controls
2.3 Technical Controls
3 Federal Information Security Management Act (FISMA) Reporting
Appendix A: Acronyms
VERSION 9 9/2022
1 Contract Identification
1.1 Contract Name
Please include the Contract Name.
Contract Name:
Contract Abbreviation:
1.2 Contract Number
Contract Number:
1.3 Responsible Organization
The overarching responsible organization is NASA. The responsible organization can be the associated mission directorate, Center, division, etc to whom the above contract provide support.
National Aeronautics and Space Administration (NASA)
Responsible Organization:
1.4 Contact Information
1.4.1 Physical Location
Include the physical location where NASA data resides and/or where contract with NASA data occurs. Depending on the contract and/or information systems, there may be multiple physical locations. [NOTE: An external information system' is defined as a system that does not reside inside NASA's physical or network (virtual) boundary]
Location Name Street Address City State Zip Code Country
1.4.2 Points of Contact
Title Name Telephone Email Address Contracting Officer (CO)
Contracting Officer Representative (COR)
Contractor Representative
VERSION 9 9/2022
1.5 General Contract Description
Purpose/Function
Include a brief description of the purpose/function of the contract.
1.5.1 Information System
Indicate whether the contract provides or manages an information system to process NASA data. NIST 800-53 R5 definitions: federal information system [OMB A-130]: An information system used or operated by an executive agency, or by another organization on behalf of an executive agency. Information system [USC 3502]: A discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.
☐ The contract provides or manages an external information system to store or process NASA data.
If this box is checked, the system requires an Authorization to Process/Store (ATP/S) NASA information. The contract representative should work with the Center Assessment and Authorization Official to obtain a system unique identifier and the Contracting Officer’s Representative (COR) to initiate the Assessment and Authorization (A&A) process (reference ITS-HBK 2810.02-05A Security Assessment and Authorization: External Information Systems).
☐ The contract does not provide or manage an external information system to store or process NASA data.
If this box is checked, the contract is not responsible for an external information system; therefore, the ITSMP is sufficient to describe the security processes and procedures that will be followed by the contract.
☐ All information technology components used in the performance of the contract are managed under an internal NASA information system.
If this box is checked, the contract is not responsible for an external information system security plan, however, the contractor is responsible for identifying the NASA information system under which the contract is performed. (If multiple systems are being used, please list all systems in separate attachment and note attachment.
NASA Information System Name:
NASA Information System Number:
1.5.2 Contractor Badging
Indicate whether or not contractor personnel will be issued NASA badges.
☐ Contractor personnel will be NASA badged.
If this box is checked, contractors, by virtue of being NASA badged, will automatically fall under many NASA policies and procedures. Consideration of the above should influence the completion of Section 2 of this document.
☐ Contractor personnel will not be NASA badged.
If this box is checked, the contract may not be able to leverage many of NASA’s policies and procedures. If so, provide details in Section 2 that meet the general intent of the control descriptions.
VERSION 9 9/2022
1.5.3 Supply Chain Risk Management (SCRM)
Will IT components be procured/purchased in performance of the contract?
☐Yes ☐No
Are you meeting Federal SCRM requirements documented in the Consolidated Appropriations Act, 2021 (Section 208)?
☐Yes ☐No
1.5.4 Related Documents
5 U.S.C. 552, Freedom of Information Act, 1967 5 U.S.C. 552a, Privacy Act, 1974 FIPS 199, Standards for Security Categorization of Federal Information and Information Systems FIPS 200, Minimum Security Requirements for Federal Information and Information Systems NIST SP 800-18, Guide for Developing Security Plans for Federal Information Systems NIST SP 800-30, Risk Management Guide for Information Technology Systems NIST SP 800-34, Contingency Planning Guide for Information Technology Systems NIST SP 800-37, Guide for the Security Authorization of Federal Information Systems NIST SP 800-42, Guideline on Network Security Testing NIST SP 800-53, Recommended Security Controls for Federal Information Systems NIST SP 800-53A, Techniques and Procedures for Verifying the Effectiveness of Security Controls in Federal Information
Systems NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories NIST SP 800-61, Computer Security Incident Handling Guide NIST SP 800-64, Security Considerations in the Information System Development Life Cycle OMB Circular A-130, Appendix III, Security of Federal Automated Information Systems Public Law (PL) 99-474, The Computer Fraud and Abuse Act of 1986 PL 93-502 -Freedom of Information Act 1974 Presidential Decision Directive (PDD-63), Critical Infrastructure Protection Federal Information Security Management Act of 2002 (FISMA) NPR 2810, Security of Information Technology H.R.133-Consolidated Appropriations Act, 2021 (Section 208)
N/A
VERSION 9 9/2022
2 Security Control Implementations In completing control detail, the author should explain how the contract meets the intent of the control description. In some cases, implementation detail is already included. The author may accept the pre-populated language as is, add to it, modify it, or overwrite
it. Note that if the “Contractor will be NASA-badged” is selected in Section 1.5.2, then the author should explore accepting relevant NASA-provided implementation detail. If the author believes that the control is not applicable to their contract, the “Not Applicable to System/Contract” box should be checked and a short explanation as to why it is not applicable should be included.
2.1 Management Controls
Briefly describe the Justification/Implementation Detail; this description should allow a reviewer to have a basic understanding of the implementation. If contractor personnel will be NASA badged, references to appropriate NASA policies and procedures are sufficient. See Contract Attachment entitled, IT Security Applicable Documents List” for relevant NASA policies and procedures.
Planning relates to the definition and documentation of the key resources and activities used to protect information and information systems. Effective security planning is both comprehensive and flexible.
(ITS-HBK-2810.03-02B)
PL-4: Rules of Behavior Not Applicable to System/Contract Justification/Implementation Detail Control Description NASA IT Rules of Behavior are fully detailed in the SATERN IT Security awareness training module, which covers the appropriate use of government resources, password security, software usage, user responsibilities, and encryption requirement for sensitive data. All employees that handle NASA data are required to take this training annually. As part of the continuous monitoring workbook a signed acknowledgment from users indicating that they understand, and agree to abide by the rules of behavior is provided annually to the Center CISO.
The SATERN IT Security awareness training module will be obtained annually from the Center CISO or the NASA IT Security Awareness & Training Center (ITSATC).
System- or contract-specific detail is provided below:
The organization:
a. Establishes and makes readily available to all information system users, the rules that describe their responsibilities and expected behavior with regard to information and information system usage; and
b. Receives signed acknowledgment from users indicating that they have read, understand, and agree to abide by the rules of behavior, before authorizing access to information and the information system.
2.2 Operational Controls
Briefly describe the justification/Implementation Detail, this description should allow an assessor to have a basic understanding of the implementation.
Security Awareness and Training relates to the information security knowledge requirements for all users of information systems, and the development and delivery of courses and other training resources to enable and validate satisfaction of those requirements. Users are responsible for meeting Agency security training requirements in order to gain and maintain access to any NASA information system resource.
Furthermore, certain roles, including managers and those with significant information security responsibilities, have to comply with additional security training and awareness requirements.
(ITS-HBK-2810.06-2B)
AT-1: Security Awareness and Training Policy and Procedures Not Applicable to System/Contract Justification/Implementation Detail Control Description In accordance with the NASA FAR, external systems are subject to the requirements of NPR 2810 and applicable requirements, regulations, policies, and guidelines are identified in the Applicable Documents List
(ADL).
If applicable, additional organizational or contract-specific policies should be referenced here.
The organization develops, disseminates, and reviews/updates [Assignment:
organization define frequency]:
a. A formal, documented security awareness and training policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
b. Formal, documented procedures to facilitate the implementation of the security awareness and training policy and associated security awareness and training controls.
AT-2: Security Awareness Not Applicable to System/Contract Justification/Implementation Detail Control Description
VERSION 9 9/2022
The organization provides basic security awareness training to all information system users (including managers, senior executives, and contractors) as part of initial training for new users, when required by system changes, and [Assignment: organization-defined frequency] thereafter.
The SATERN IT Security awareness training module, via CD, will be obtained The SATERN IT Security awareness training module will be obtained annually from the Center CISO or the NASA IT Security Awareness & Training Center (ITSATC). All employees that handle NASA data are required to take this training annually.
The SATERN IT Security awareness training module will be obtained annually from the Center CISO or the NASA IT Security Awareness & Training Center (ITSATC).
If applicable, system- or contract-specific detail is provided below.
AT-3: Security Training Not Applicable to System/Contract Justification/Implementation Detail Control Description System- or contract-specific detail is provided below.
The organization provides role-based security-related training: (i) before authorizing access to the system or performing assigned duties; (ii) when required by system changes; and (iii) [Assignment: organization-defined frequency] thereafter.
Incident Response relates to dealing with the potential for and actual damage and disruption to information systems. An “incident” is any adverse event or situation associated with a system that poses a threat to the system’s integrity, availability, or confidentiality. An incident may result in or stem from any one of the following: a failure of security controls; an attempted or actual compromise of information; and/or waste, fraud, abuse, loss, or damage of government property or information.
(ITS-HBK-2810.09-01)
IR-6: Incident Reporting
Not Applicable to System/Contract Justification/Implementation Detail Control Description All breaches will be communicated to the [Center] CISO and the NASA
SOC
within the timeframe appropriate to the category of information involved. If there is PII involved in the breach the SOC will be contacted with one hour.
The SOC may be contacted at 877-NASA SEC (877-627- 2732).
The Center CISO and/or the OIG handles the notification to external authorities.
If applicable, system- or contract-specific detail is provided below.
The organization:
a. Requires personnel to report suspected security incidents to the organizational incident response capability within [Assignment: organization-defined time-period]; and
b. Reports security incident information to designated authorities.
Media Protection relates to the secure use of information storage media. Storage media can take one of two forms – digital or non‐ digital. Non‐digital media typically consists of paper, film, microfilm, microfiche, etc. Digital media is comprised of mobile computing devices, laptops, PDAs, “smart phones,” and removable storage devices such as USB drives, flash drives, writeable CDs and DVDs, memory cards, external hard drives, storage cards, diskettes, magnetic tapes or any electronic device that can be used to copy, save, store and/or move data from one system to another.
(ITS-HBK-2810.11-2C)
MP-1: Media Protection Policy and Procedures Not Applicable to System/Contract Justification/Implementation Detail Control Description In accordance with the NASA FAR, external systems are subject to the requirements of NPR 2810 and applicable requirements, regulations, policies, and guidelines are identified in the Applicable Documents List (ADL).
If applicable, system- or contract-specific policies should be referenced here.
The organization develops, disseminates, and reviews/updates [Assignment:
organization defined frequency]:
a. A formal, documented media protection policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
b. Formal, documented procedures to facilitate the implementation of the media protection policy and associated media protection controls.
MP-3: Media Marking
Control Description System- or contract-specific detail is provided below.
VERSION 9 9/2022
The organization:
a. Marks, in accordance with organizational policies and procedures, removable information system media and information system output indicating the distribution limitations, handling caveats, and applicable security markings (if any) of the information; and
b. Exempts [Assignment: organization-defined list of removable media types] from marking as long as the exempted items remain within [Assignment: organization-defined controlled areas].
MP-4: Media Storage Not Applicable to System/Contract Justification/Implementation Detail Control Description System- or contract-specific detail is provided below.
The organization:
a. Physically controls and securely stores [Assignment: organization-defined types of digital and non-digital media] within [Assignment: organization-defined controlled areas] using [Assignment: organization-defined security measures];
b. Protects information system media until the media are destroyed or sanitized using approved equipment, techniques, and procedures.
MP-5: Media Transport Not Applicable to System/Contract Justification/Implementation Detail Control Description System- or contract-specific detail is provided below.
The organization:
a. Protects and controls [Assignment: organization-defined types of digital and non-digital media] during transport outside of controlled areas using [Assignment: organization-defined security measures];
b. Maintains accountability for information system media during transport outside of controlled areas; and
c. Restricts the activities associated with transport of such media to authorized personnel.
MP-6: Media Sanitization Not Applicable to System/Contract Justification/Implementation Detail Control Description System- or contract-specific detail is provided below.
The organization:
a. Sanitizes information system media, both digital and non-digital, prior to disposal, release out of organizational control, or release for reuse; and
b. Employs sanitization mechanisms with strength and integrity commensurate with the classification or sensitivity of the information.
Configuration Management relates to the organizational aspects of information system baseline configurations, establishing review and validation, and change control. It also manages administrator roles, and the ability of individuals to make changes to the information systems’ configuration.
(ITS-HBK-2810.07-02B)
CM-8: Information System Component Inventory Not Applicable to System/Contract Justification/Implementation Detail Control Description System- or contract-specific detail is provided below.
The organization develops, documents, and maintains an inventory of information system components that:
a. Accurately reflects the current information system;
b. Is consistent with the authorization boundary of the information system;
c. Is at the level of granularity deemed necessary for tracking and reporting;
d. Includes [Assignment: organization-defined information deemed necessary to achieve effective property accountability]; and
e. Is available for review and audit by designated organizational officials.
VERSION 9 9/2022
Physical and Environmental Protection relates to the activities and requirements surrounding the development, implementation, and maintenance of physical access authorizations and controls (e.g., key and security badge distribution, visitor management, and related record keeping), and the protection, proofing, and regulation of facilities. This section also addresses protection of facilities and the essential utilities and infrastructure which support those facilities (e.g., door locks, backup power and lighting, emergency plumbing shutoff switches, and fire suppression systems), and environmental controls for those facilities (e.g., temperature regulation, humidity monitoring), as appropriate.
(ITS-HBK-2810.12-02B)
PE-3: Physical Access Control Not Applicable to System/Contract Justification/Implementation Detail Control Description System- or contract-specific detail is provided below.
The organization:
a. Enforces physical access authorizations for all physical access points (including designated entry/exit points) to the facility where the information system resides (excluding those areas within the facility officially designated as publicly accessible);
b. Verifies individual access authorizations before granting access to the facility;
c. Controls entry to the facility containing the information system using physical access devices and/or guards;Controls access to areas officially designated as publicly accessible in accordance with the organization’s assessment of risk;
a. Secures keys, combinations, and other physical access devices;
b. Inventories physical access devices [Assignment: organization-defined frequency]; and
c. Changes combinations and keys [Assignment: organization-defined frequency] and when keys are lost, combinations are compromised, or individuals are transferred or terminated.
Personnel Security relates to the security activities that surround various facets of the employment life cycle (i.e., initial employee screening, position categorization, authority delegation, sanctioning, transfers, and termination). Personnel Security applies to both direct employees of the Agency as well as contracted personnel, and service bureaus.
(ITS-HBK-2810.13-01B)
PS-2: Position Categorization
Justification/Implementation Detail
The organization:
a. Assigns a risk designation to all positions;
b. Establishes screening criteria for individuals filling those positions; and
c. Reviews and revises position risk designations [Assignment: organization- defined frequency].
System- or contract-specific detail is provided below.
PS-4: Personnel Termination Not Applicable to System/Contract Justification/Implementation Detail Control Description System- or contract-specific detail is provided below.
The organization, upon termination of individual employment:
a. Terminates information system access;
b. Conducts exit interviews;
c. Retrieves all security-related organizational information system-related property; and
d. Retains access to organizational information and information systems formerly controlled by terminated individual.
PS-7: Third-Party Personnel Security
Not Applicable to System/Contract Justification/Implementation Detail Control Description System- or contract-specific detail is provided below.
The organization:
a. Establishes personnel security requirements including security roles and responsibilities for third-party providers;
b. Documents personnel security requirements; and
c. Monitors provider compliance.
PS-3: Personnel Screening Not Applicable to System/Contract Justification/Implementation Detail Control Description System- or contract-specific detail is provided below.
The organization:
a. Screens individuals prior to authorizing access to the information system; and\
b. Rescreens individuals according to [Assignment: organization-defined list of conditions requiring rescreening and, where re-screening is so indicated, the frequency of such rescreening].
Not Applicable to System/Contract Control Description
VERSION 9 9/2022
The organization employs a formal sanctions process for personnel failing to comply with established information security policies and procedures.
2.3 Technical Controls
Briefly describe the Justification/Implementation Detail; this description should allow a reviewer to have a basic understanding of the implementation. If contractor personnel will be NASA badged, references to appropriate NASA policies and procedures are sufficient. See Appendix B: Applicable Documents List for relevant NASA policies and procedures.
Access Control relates to the ability to permit or deny access to computer systems, system locations and system information based on a user’s need to know. It encompasses the management of unique account identifiers (IDs), passwords, physical access, badges and tokens, and user permissions to ensure the proper level of system access.
(ITS-HBK-2810.15-01)
AC-2: Account Management
Not Applicable to System/Contract Justification/Implementation Detail Control Description System- or contract-specific detail is provided below.
The organization manages information system accounts, including:
a. Identifying account types (i.e., individual, group, system, application, guest/anonymous, and temporary);
b. Establishing conditions for group membership;
c. Identifying authorized users of the information system and specifying access privileges;
d. Requiring appropriate approvals for requests to establish accounts;
e. Establishing, activating, modifying, disabling, and removing accounts;
f. Specifically authorizing and monitoring the use of guest/anonymous and temporary accounts;
g. Notifying account managers when temporary accounts are no longer required and when information system users are terminated, transferred, or information system usage or need-to-know/need-to-share changes;
h. Deactivating: (i) temporary accounts that are no longer required; and
(ii) accounts of terminated or transferred users;
i. Granting access to the system based on: (i) a valid access authorization;
(ii) intended system usage; and (iii) other attributes as required by the organization or associated missions/business functions; and
j. Reviewing accounts [Assignment: organization-defined frequency].
AC-5: Separation of Duties Not Applicable to System/Contract Justification/Implementation Detail Control Description System- or contract-specific detail is provided below.
The organization:
a. Separates duties of individuals as necessary, to prevent malevolent activity without collusion;
b. Documents separation of duties; and
c. Implements separation of duties through assigned information system access authorizations.
AC-6: Least Privilege Not Applicable to System/Contract Justification/Implementation Detail Control Description System- or contract-specific detail is provided below.
The organization employs the concept of least privilege, allowing only authorized accesses for users (and processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions.
AC-20: Use of External Information Systems Not Applicable to System/Contract Justification/Implementation Detail Control Description System- or contract-specific detail is provided below.
PS-8: Personnel Sanctions
Control Description System- or contract-specific detail is provided below.
VERSION 9 9/2022
The organization establishes terms and conditions, consistent with any trust relationships established with other organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to:
a. Access the information system from the external information systems; and
b. Process, store, and/or transmit organization-controlled information using the external information systems.
3 Federal Information Security Management Act (FISMA) Reporting The contractor shall adhere to the NASA FISMA reporting requirements and provide inputs upon request. In general this includes:
Security Control Review/Assessment Date Authorization to Process/Store (ATP/S) Date2
Contingency Plan Test Date Contingency Plan Test Type (Tabletop, Simulation or Full)
2 ATP/S is not applicable to contactors who are not operating an external system, rather, components used in the performance of the contract are covered under an internal, NASA information system.
VERSION 9 9/2022
Appendix A: Acronyms
Acronym Definition ADL Applicable Documents List
CISO Chief Information Security Officer
CO Contracting Officer
COR Contracting Officer Representative
FIPS Federal Information Processing Standards
ISSO Information System Security Officer
ITSATC IT Security Awareness & Training Center
NIST-SP National Institute of Standards and Technology – Special Publications
NPR NASA Procedural Requirements
SCRM Supply Chain Risk Management
SOC Security Operations Center
Additional Information: If there is any additional information that you wish to provide, please use the box below.
CUI
Blank Page
| Version: |
| Change Description: |
| 10Row1: |
| Initial Contract Name IT Security Management PlanMMDDYYYY: |
| 10Row2: |
| Initial Contract Name IT Security Management PlanMMDDYYYY_2: |
| 10Row3: |
| Initial Contract Name IT Security Management PlanMMDDYYYY_3: |
| 10Row4: |
| Initial Contract Name IT Security Management PlanMMDDYYYY_4: |
| 10Row5: |
| Initial Contract Name IT Security Management PlanMMDDYYYY_5: |
| 10Row6: |
| Initial Contract Name IT Security Management PlanMMDDYYYY_6: |
| 10Row7: |
| Initial Contract Name IT Security Management PlanMMDDYYYY_7: |
| 10Row8: |
| Initial Contract Name IT Security Management PlanMMDDYYYY_8: |
| 10Row9: |
| Initial Contract Name IT Security Management PlanMMDDYYYY_9: |
| Location NameRow1: |
| Street AddressRow1: |
| CityRow1: |
| StateRow1: |
| Zip CodeRow1: |
| CountryRow1: |
| Location NameRow2: |
| Street AddressRow2: |
| CityRow2: |
| StateRow2: |
| Zip CodeRow2: |
| CountryRow2: |
| NameContracting Officer CO: |
| TelephoneContracting Officer CO: |
| Email AddressContracting Officer CO: |
| NameContracting Officer Representative COR: |
| TelephoneContracting Officer Representative COR: |
| Email AddressContracting Officer Representative COR: |
| NameContractor Representative: |
| TelephoneContractor Representative: |
| Email AddressContractor Representative: |
| PurposeFunction Include a brief description of the purposefunction of the contract: |
| Enter Contract Name: |
| Enter Contract Number: |
| Date Issue: |
| Effective Date: |
| Date: |
| Contract Name: |
| Date Completed: |
| Contract Abbreviation: |
| Contract Number: |
| Responsible Organization: |
| Check Box16: Off |
| Check Box17: Off |
| Check Box18: Off |
| NASA Information System Name: |
| Check Box21: Off |
| Check Box22: Off |
| Check Box23: Off |
| Check Box24: Off |
| Check Box25: Off |
| Check Box26: Off |
| Text70: |
| Check Box2: Off |
| Check Box12: Off |
| Check Box13: Off |
| Check Box14: Off |
| Check Box15: Off |
| Check Box19: Off |
| Check Box20: Off |
| Check Box27: Off |
| Check Box28: Off |
| Check Box29: Off |
| Check Box30: Off |
| Check Box31: Off |
| Check Box32: Off |
| Check Box33: Off |
| Check Box34: Off |
| Check Box35: Off |
| Check Box36: Off |
| Check Box37: Off |
| Check Box38: Off |
| Check Box39: Off |
| Check Box40: Off |
| Check Box41: Off |
| Text42: |
| Text43: |
| Text44: |
| Text45: |
| Text46: |
| Text47: |
| Text48: |
| Text50: |
| Text51: |
| Text52: |
| Text55: |
| Text56: |
| Text57: |
| Text58: |
| Text59: |
| Text60: |
| Text61: |
| Text62: |
| Text63: |
| Initial Contract Name IT Security Management PlanMMDDYYYY_10: |
| MMDDYYYY#1: |
| MMDDYYYY#2: |
| MMDDYYYY#3: |
| MMDDYYYY#4: |
| MMDDYYYY#5: |
| MMDDYYYY#6: |
| MMDDYYYY#7: |
| MMDDYYYY#8: |
| MMDDYYYY#9: |
| MMDDYYYY#10: |
| Text100: |
| Text101: |
| Date Signed 1: |
| Date Signed 2: |
| Date Signed 3: |
| Date Signed 4: |
File details come from the government source that posted it. Updated .