N_PR_2810_001F_.pdf
PDF 904 KB Posted
- Attached to
- Near Space Network (NSN) Services, elibrary Federal contract opportunity
- Solicitation number
- 80GSFC22R0029-elibrary
View the file
Other files for this federal contract opportunity
Show all 46
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
NASA
Procedural Requirements
NPR 2810.1
Effective Date: January 3, 2022
Expiration Date: January 3 2027
COMPLIANCE IS MANDATORY FOR ALL NASA EMPLOYEES
Security of Information and Information Systems
Responsible Office: Office of the Chief Information Officer
Table of Contents Preface
P.1 Purpose P.2 Applicability P.3 Authority P.4 Applicable Documents and Forms P.5 Measurement/Verification P.6 Cancellation
Chapter 1. Introduction
1.1 Introduction
1.2 Roles and Responsibilities
Chapter 2. Identify Function
2.1 Asset Management
2.2 Business Environment
2.3 Governance
2.4 Risk Assessment
2.5 Risk Management Strategy
2.6 Supply Chain Risk Management
Chapter 3. Protect Function
3.1 Identity Management and Access Control
3.2 Awareness and Training
3.3 Data Security
3.4 Information Protection Processes and Procedures
3.5 Maintenance
3.6 Protective Technology
Chapter 4. Detect Function
4.1 Anomalies and Events
4.2 Security Continuous Monitoring
4.3 Detection Processes
Chapter 5. Respond Function
5.1 Response Planning
5.2 Communications
5.3 Analysis
5.4 Mitigation
5.5 Improvements
Chapter 6. Recover Function
6.1 Recovery Planning
6.2 Improvements
6.3 Communications
Appendix A Definitions Appendix B Acronyms Appendix C Requirements Matrices Appendix D References Appendix E Requirements Matrix with respect to system lifecycle
Preface
P.1 Purpose
a. This directive establishes the information security requirements for the NASA Information Security Program. The procedural requirements herein prescribe roles, responsibilities, and conditions that directly or indirectly promote information security throughout the life cycle of all NASA information and information systems, including operational technology systems.
b. This directive identifies information security policies, procedures, and practices that are related to NASA's mission, and consistent with federal laws, executive orders, directives, policies, and regulations.
c. This directive aligns roles and responsibilities of information technology (IT) security personnel to National Institute of Standards and Technology (NIST) Special Publication (SP) 800-37, Risk Management Framework (RMF) for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy and NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations.
d. This directive serves as a reference to the NASA community regarding specific information security roles and responsibilities, and it provides resources where more detailed information may be found.
e. This directive implements cybersecurity policy best practices and guidance, particularly those outlined by the NIST SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Non-Federal Systems and Organizations, NIST SP 800-37, NIST SP 800-46 Rev. 2, Guide to Enterprise Telework, Remote Access, and Bring Your Own Device (BYOD) Security, NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations, NIST SP 800-60 Vol. 1 Rev. 1, Guide for Mapping Types of Information and Information Systems to Security Categories, NIST SP 800-82 Rev. 2, Guide to Industrial Control Systems (ICS) Security, NIST 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations, NIST SP 800-160 Vol. 2, Developing Cyber Resilient Systems – A Systems Security Engineering Approach, and NIST SP 800-161, Supply Chain Risk Management Practices for Federal Information Systems and Organizations, referenced NASA policy documents, specifications, and standards, and mandated by Federal Information Processing Standards (FIPS) across all corporate, project, and mission elements (ground and flight systems).
P.2 Applicability
a. This directive applies to NASA Headquarters and all NASA Centers, including Component Facilities and Technical and Service Support Centers.
(1) For purposes of this directive, NASA Headquarters is treated as a Center. Further, all roles and responsibilities of a Center Chief Information Officer (CIO) apply to NASA Headquarters CIO and all stipulated Center requirements apply to NASA Headquarters.
b. This directive applies to contractors, recipients of grants, cooperative agreements, or other agreements only to the extent specified or referenced in the contracts, grants, or agreements.
c. This directive applies to all unclassified NASA information and NASA information systems, including those that are contracted out, outsourced to, or operated by:
(1) Government owned, contractor operated (GOCO) facilities;
(2) partners under the Space Act;
(3) partners under the Commercial Space Act of 1997;
(4) partners under cooperative agreements; or
(5) commercial or university facilities.
d. This directive does not apply to information systems that do not process NASA information, and are merely incidental to a contract (e.g., a contractor's payroll and personnel management system).
(1) In this directive, all mandatory actions (i.e., requirements) are denoted by statements containing the term “shall.” The terms: “may” or “can” denote discretionary privilege or permission, “should” denotes a good practice and is recommended, but not required, “will” denotes expected outcome, and “are/is” denotes descriptive material.
e. This directive does not apply to Classified National Security Information (CNSI). CNSI is the responsibility of the Office of Protective Services (OPS) and is covered under CNSI policy and requirements contained in NASA Procedural Requirement (NPR) 1600.2, NASA Classified National Security Information (CNSI) and NPR 1600.1, NASA Security Program Procedural Requirements.
f. This directive applies to all NASA users of information systems (e.g., civil servants and contractors) when supporting Agency projects, programs, and missions.
g. In this directive all document citations are assumed to be the latest version unless otherwise noted.
P.3 Authority
a. Freedom of Information Act, 5 U.S.C. § 552, et seq.
b. Privacy Act of 1974, 5 U.S.C. § 552a.
c. Violation of Regulations of National Aeronautics and Space Administration, 18 U.S.C. § 799.
d. Inspector General Act of 1978, 5 U.S.C. App. III.
e. Electronic Communications Privacy Act of 1986, 18 U.S.C. § 2510, et seq.
f. Clinger-Cohen Act of 1996, 40 U.S.C. § 11101 et seq.
g. Federal Information Technology Acquisition Reform Act (FITARA) of 2014, 40 U.S.C. § 11319 et seq.
h. E-Government Act of 2002, 44 U.S.C. § 101.
i. Paperwork Reduction Act of 1995, 44 U.S.C. § 3501, et seq.
j. Federal Information Security Management Act (FISMA) of 2014, 44 U.S.C. § 3541 et seq.
k. Export Control Reform Act of 2018, 50 U.S.C. 4801-4852.
l. National Aeronautics and Space Act, 51 U.S.C. § 20113(e).
m. Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure, E.O. 13800, 82 FR 22391 (2017).
n. Availability of Agency Records to Members of the Public, 14 Code of Federal Regulations (CFR) pt. 1206.
o. Export Administration Regulations, 15 CFR pts. 730-774.
p. International Traffic in Arms Regulations, 22 CFR pts. 120-130.
q. National Telecommunications and Information System Security (NTISS) 1, National Policy on Application of Communications Security to U.S. Civil and Commercial Space Systems, June 17, 1982.
r. NTISS 100, National Policy on Application of Communications Security to Command Destruct Systems, February 17, 1988.
s. Homeland Security Presidential Directive 7 (HSPD-7), Critical Infrastructure Identification, Prioritization, and Protection, December 2003.
t. HSPD-12, Policies for a Common Identification Standard for Federal Employees and Contractors, August 2004.
u. HSPD-20, National Continuity Policy.
v. GAO-09-232G, Federal Information System Controls Audit Manual (FISCAM).
P.4 Applicable Documents and Forms
a. NASA Federal Acquisition Regulations (FAR) Supplement, 48 CFR Chapter 18.
b. NPD 1000.0, NASA Governance and Strategic Management Handbook
c. NPD 1000.3, The NASA Organization
d. NPD 2540.1, Personal Use of Government Office Equipment Including Information Technology.
e. NPD 2810.1, NASA Information Security Policy.
f. NASA Records Retention Schedule No 1441.1 (updated) May 18, 2020.
g. NPR 1600.1, NASA Security Program Procedural Requirements.
h. NPR 1600.2, NASA Classified National Security Information (CNSI).
i. NPR 2841.1, Identity, Credential, and Access Management.
j. NPR 4200.1, NASA Equipment Management Procedural Requirements.
k. NPR 8000.4, Agency Risk Management Procedural Requirements.
l. NASA Advisory Implementing Instruction (NAII) 1050.3, NASA Partnership Guide.
m. NASA-STD-1006, Space System Protection Standard.
n. NASA Cybersecurity Requirements Technical Specification
o. NIST Cybersecurity Framework.
p. NIST Special Publication (SP) 800-37, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy.
q. NIST SP 800-171, Rev 2 Protecting Controlled Unclassified Information in Non-Federal Systems and Organizations.
r. NIST SP 800-46, Guide to Enterprise Telework and Remote Access, and Bring Your Own Device (BYOD) Security.
s. NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations.
t. NIST SP 800-60, Volumes 1 and 2, Guide for Mapping Types of Information and Information Systems to Security Categories: Appendices.
u. NIST SP 800-82, Guide to Industrial Control Systems (ICS) Security and Organizations.
v. NIST SP 800-160 Vol. 2, Developing Cyber Resilient Systems – A Systems Security Engineering Approach.
w. NIST SP 800-161, Supply Chain Risk Management Practices for Federal Information Systems and Organizations.
x. ITS-HBK-2810.11-2B Media Protection and Sanitization.
y. Department of Homeland Security (DHS) Binding Operational Directive (BOD) 18-02 Securing High Value Assets.
P.5 Measurement/Verification
a. Federal regulatory and NASA requirements drive the obligation to measure performance and reduce cost. These measurements will be based upon NASA's goals and objectives and be designed to provide substantive justification for decision-making. The measures will be used to measure the effectiveness of the information security program, policies, and requirements.
b. The NIST Cybersecurity Framework is the fundamental basis of such measurement.
c. The Senior Agency Information Security Officer (SAISO) will provide assessments or audit of the application of this directive. Assessments and audits will consist of reporting from the Centers, including information collected for the satisfaction of Office of Management and Budget (OMB) and FISMA reporting requirements.
d. All covered entities are subject to information security compliance reviews and audits by
NASA.
P.6 Cancellation
a. NPR 2810.1A, Security of Information Technology, dated May 16, 2006.
Chapter 1. Introduction
1.1 Introduction
1.1.1 Structure
1.1.1.1 This directive establishes the information security requirements and responsibilities for NASA, relative to the policy set forth in NPD 2810.1, NASA Information Security Policy. This directive does not negate any existing policies, procedures, memos, handbooks, etc., except where explicitly stated in section P.6 Cancellation. This document is intended to provide a framework for information security and serve as an avenue for the authorization of more in-depth documents (e.g., handbooks, memoranda).
1.1.1.2 This directive is organized into six chapters: (1) Introduction; (2) Identify; (3) Protect; (4) Detect; (5) Respond; and (6) Recover.
a. The chapters in this directive align to the functional areas of version 1.1 of the NIST Cybersecurity Framework (CSF).
b. Each chapter defines the overall intent of the functional area and the roles and responsibilities specific to the area. Each chapter provides references to where more detailed requirements, procedures, and information may be found.
1.1.2 Approach
1.1.2.1 NASA’s SAISO establishes the Agency's Cybersecurity and Privacy Program and its overall objectives and priorities. NASA Headquarters, Centers, satellite facilities, and support service contractor sites have the latitude to use their internal organizational structure to fulfill the roles and responsibilities described herein if the approach is consistent with this directive and more in-depth policy documents authorized by this directive.
1.1.2.2 NASA’s approach to information security is grounded in risk management. Just as a solid understanding of risk management principles is essential to the success of NASA’s space and aeronautics Missions, a solid understanding of these principles is essential to the protection of NASA information and information systems.
1.1.3 Legal Framework
1.1.3.1 Existing laws, regulations, and guidance govern NASA’s implementation of an information security program.
a. The primary statute governing information security is FISMA, which defines information security as the protection of information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction.
b. This directive establishes how NASA implements the requirements of FISMA as they relate to NASA information and information systems.
c. The Clinger-Cohen Act states that the NIST FIPS are “compulsory and binding” 40 U.S.C.
§ 11331(b)(1)(C). FISMA also advocates that information security be based on “periodic assessments of the risk and magnitude of the harm that could result from the unauthorized access, use, disclosure, disruption, modification, or destruction of information and information systems that support the operations and assets of the agency,” Federal Agency Responsibilities, 44 U.S.C. § 3554(b)(1). FISMA provides flexibility regarding the application of information security controls.
1.1.3.2 To implement federal and NASA policies and requirements, FISMA allows for the delegation of responsibilities into various functional roles.
1.2 Roles and Responsibilities
1.2.1 Overview
1.2.1.1 The following are overarching roles and responsibilities related to the NASA Cybersecurity and Privacy Program. Specific roles and responsibilities, as related to information security controls, are referenced throughout the remainder of this directive in their respective chapters. Additional responsibilities may be defined in in-depth policy documents authorized by this directive.
1.2.1.2 Throughout this document roles and responsibilities are generally listed at the highest level possible, with the operating assumption that specific tasks and functions may be delegated as necessary unless explicitly prohibited.
1.2.1.3 For the Jet Propulsion Laboratory (JPL), the Agency CIO will designate the roles allocated for the United States federal government employees.
1.2.2 NASA Management Roles
1.2.2.1 The roles and responsibilities of NASA management are defined in NPD 1000.0, NASA Governance and Strategic Management Handbook, and further outlined in NPD 1000.3, The NASA Organization. The key roles and responsibilities specific to information security are summarized as follows:
1.2.2.2 The NASA Administrator shall:
a. Ensure the security of NASA's information and information systems.
b. Ensure that NASA implements the NIST Cybersecurity Framework.
1.2.2.3 The NASA CIO provides leadership, planning, policy direction, and oversight for the management of NASA information and information systems. The NASA CIO shall:
a. Ensure confidentiality, integrity, and availability of all NASA’s information assets throughout the system life cycle.
b. Ensure all NASA IT is in compliance with federal and NASA Cybersecurity and Privacy Program requirements.
c. Commission suitable governance bodies.
d. Evaluate and approve the designation of Authorizing Officials (AO).
e. Advise senior NASA officials concerning their information security responsibilities.
f. Ensure the NASA enterprise architecture integrates information security considerations into the strategic, capital, and investment planning process.
g. Encourage the maximum reuse and sharing of information security-related information throughout the NASA community.
h. Develop, implement, and maintain a Controlled Unclassified Information (CUI) program which is managed in accordance with Executive Order (E.O.) 13556, Controlled Unclassified Information, and Controlled Unclassified Information, 32 CFR, pt. 2002.
i. Be an employee of the United States Federal Government.
1.2.2.4 Officials in charge of Mission Directorates and Mission Support Offices shall:
a. Appoint an information security point of contact to represent the mission on Agency programmatic strategic cybersecurity initiatives and serve as a voting member of suitable governance bodies.
b. Ensure that resources are allocated to address information and information system security requirements developed under this directive for their information systems.
c. Ensure that their respective organizations, including missions, programs, projects, and institutions under their purview, comply with this directive, ensuring Operational Technology is also compliant.
d. Ensure that secure software development is being practiced for NASA projects per NPR 7150.2, NASA Software Engineering Requirements.
e. Ensure that secure system development is being practiced for NASA projects per NASA specifications and standards, including NASA-STD-1006, and the NASA Cybersecurity Requirements Technical Specification.
1.2.2.5 The Center Directors and the Director for Headquarters Operations shall:
a. With concurrence from the SAISO and the Center’s CIO, designate a Center Chief Information Security Officer (CISO) in writing.
b. Ensure the Center CISO has adequate staff, resources, budget, and authority to implement information security programs at their Center.
1.2.3 Information Security Roles
1.2.3.1 In addition, the following offices and roles support the development and execution of information security policy are listed in the following paragraph.
1.2.3.2 A Center CIO shall:
a. If they apply, execute the responsibilities, comparable to those of the NASA CIO, at the Center level.
b. Execute the responsibilities, comparable to those of the NASA CIO, with respect to NASA facilities and systems not located at a Center as designated by the CIO.
c. If the Center CIO assigns an Organizational Computer Security Official (OCSO) per section 1.2.3.3, designate Center-specific OCSO responsibilities, and any necessary interfaces with the Center CISO, in a Center-level formal policy.
d. Be an employee of the United States Federal Government.
1.2.3.3 A Center CIO may optionally assign OCSOs to facilitate the implementation and oversight of information security within their organization.
1.2.3.4 The SAISO shall:
a. Carry out the responsibilities delegated from the NASA CIO under FISMA (as provided for by 44 U.S.C § 3554(a)(3)(A)), as well as federal and NASA cybersecurity and privacy program requirements.
b. Establish and maintain an office with the mission and resources to ensure compliance with federal and NASA Cybersecurity and Privacy Program requirements.
c. Manage the NASA Cybersecurity and Privacy Program.
d. Keep the NASA Cybersecurity and Privacy Program current with changes in the information security environment and with changes in federal policy and guidelines.
e. Ensure that information security control assessments, authorizations, and OMB and FISMA reporting directives are completed across the Agency in a timely and cost-effective manner.
f. Serve as the NASA CIO's primary liaison with Center CISOs, AOs, Information System Owners (ISOs), and Information System Security Officers (ISSOs).
g. Oversee and arbitrate conflict resolution, relative to information security concerns, for all NASA-wide information systems.
h. Ensure the planning of a framework for the use and adoption of current and new information security technologies implemented throughout the Agency.
i. Maintain a process for planning, implementing, evaluating, and documenting remedial actions to address deficiencies and weaknesses in NASA's Cybersecurity and Privacy Program.
j. Manage the NASA system of Record for all Assessment and Authorization artifacts, including all System Security Plans. The current System of Record is Risk Information Security Compliance System (RISCS).
k. Develop, implement and manage a High Value Asset (HVA) program in accordance with Department of Homeland Security (DHS) Binding Operational Directive (BOD) 18-02 Securing High Value Assets.
l. Develop, implement and manage a threat monitoring and incident response program, to include the NASA Security Operations Center, for NASA HVAs in accordance with DHS BOD 18-02.
m. Be an employee of the United States Federal Government.
1.2.3.5 A Center CISO shall:
a. Execute the Cybersecurity and Privacy Program at the Center level.
b. Assist the SAISO in enforcing NASA information security policies and procedures, and the Federal information security laws, directives, policies, and standards at the Center level.
1.2.3.6 An OCSO (if assigned per section 1.2.3.3) shall:
a. Ensure compliance with information security requirements.
b. Serve as their organization's representative to the Center CISO on information security matters.
c. Report the status of the organization's information security to the Center CISO and senior organization officials.
d. Be an employee of the United States Federal Government.
1.2.3.7 The Center Cybersecurity Risk Manager (CCRM) shall:
a. Support the NASA cybersecurity Risk Executive function, as defined by NIST SP 800-37.
b. Serve as a cybersecurity risk management resource and as a subject matter expert on assessment and authorization for all personnel at their Center.
c. Provide oversight for the cybersecurity risk management activities carried out by Center and mission organizations to help ensure consistent and effective risk-based decisions, in accordance with NASA policies, procedures and organizational risk tolerance.
1.2.3.8 An AO shall:
a. Formally assume the responsibility for the operation of an information system or for the use of a designated set of common controls at an acceptable level of risk to the system, mission, and/or Agency.
b. Allocate sufficient resources to adequately protect information and information systems based on an assessment of organizational risks.
c. Assign Authorizing Official Designated Representatives (AODRs), as necessary. Once designated, an AO may not further delegate their risk acceptance role as AO. However, AOs are encouraged to assign AODRs to support AO visibility into, and management of, their information systems’ cybersecurity posture.
d. Be an employee of the United States Federal Government.
1.2.3.9 An AODR shall:
a. Execute the responsibilities of the AO as delegated.
b. Be an employee of the United States Federal Government.
1.2.3.10 An ISO shall:
a. Acquire, develop, integrate, operate, modify, maintain, and dispose of information systems.
b. Ensure system-level implementation of all Agency and Center requirements.
c. Ensure information systems are categorized in a manner that reflects the criticality of their function, and the sensitivity of the information they generate, collect, process, store, or disseminate.
d. Allocate resources to protect information and information systems based on an assessment of system risks.
e. Ensure that information security controls are implemented according to a thorough risk-based analysis of their information systems' security postures.
f. Provide necessary assessment documentation, as required.
g. Take proper actions to identify, and minimize or eliminate, information system security deficiencies and weaknesses.
h. Communicate feedback to the Center CISO, OCSO (if assigned per section 1.2.3.3), and AO regarding the impact of Agency and Center-wide information security requirements on the operation of their information systems.
i. Ensure funding requests for information security requirements are included in annual budgeting submissions.
j. Utilize, to the extent possible, Agency-provided information system infrastructure.
k. Ensure that custom software developed for use on NASA information systems is implemented securely, in a manner that that reflects the criticality of its function, and the sensitivity of the information it generates, collects, processes, stores, or disseminates.
l. For a given program or project, develop a clear description of the information and system that is protected and evaluate the scope of information security resources that may be required for the project.
m. Appoint an Information Systems Security Officer (ISSO) to carry out provisions listed in 1.2.3.13.
1.2.3.11 Program Managers and Project Managers shall:
a. Allocate resources to protect information and information systems under their control based on an assessment of system risks.
b. Ensure identified cybersecurity risks accepted by AOs are also reflected in the program or project risk database(s)/system(s).
c. Include cybersecurity as part of the program and project plans for projects (e.g., incorporate the requirements of all applicable cybersecurity standards and specifications).
d. Identify and coordinate with ISOs for information systems under their control ensuring greater integration of cybersecurity and mission personnel.
e. Identify and coordinate with ISOs for information systems outside their control that support and impact their mission.
f. Ensure that all information systems under Program Managers’ and Project Managers’ control are fully compliant with the requirements of this directive.
1.2.3.12 An Information Owner (IO) shall:
a. Exercise statutory or operational authority for specified information.
b. Ensure the selection of information security controls is adequate for the protection of information under their authority during generation, collection, processing, dissemination, and disposal.
1.2.3.13 An Information System Security Officer (ISSO) shall:
a. Serve as the principal advisor to the ISO on issues regarding information security.
b. Ensure a proper operational security posture is maintained for their information system.
c. Be responsible for the day-to-day security operations of their information system.
1.2.3.14 Contracting Officers, as defined in Federal Acquisition Regulation 2.101, or Agreement Managers as defined in NAII 1050.3, NASA Partnership Guide, shall ensure that the requirements of this directive are included and in scope for all NASA contracts, Space Act agreements, cooperative agreements, partnership agreements, or other agreements pursuant to which NASA data is being processed and transmitted; IT devices are procured for a purpose that is not incidental to the contract, and/or IT devices are developed or used on a NASA network.
Chapter 2. Identify Function
2.1 Asset Management
2.1.1 Overview
2.1.1.1 Section 2.1 establishes requirements and processes to identify and manage data, devices, systems, and facilities relative to NASA’s information security objectives and risk profile and risk posture.
2.1.2 Asset Management
2.1.2.1 The NASA SAISO shall ensure the maintenance of a NASA-wide information system inventory in the NASA system of record (i.e., RISCS).
2.1.2.2 An ISO shall:
a. Ensure that information system components are identified and documented.
b. Maintain, in the NASA system of record (i.e., RISCS), an accurate, up-to-date inventory of data, devices, systems, and facilities under their ownership monthly.
c. Provide such inventory to the Office of the Chief Information Officer (OCIO) in such manner and format that the SAISO determines.
2.1.3 Physical and Virtual Device and System Inventory
2.1.3.1 The NASA SAISO shall ensure the inventory required by section 2.1.2.1 is accurate and updated with all physical and virtual devices and systems.
2.1.3.2 An ISO shall:
a. Ensure the inventory required by section 2.1.2.1 includes all physical and virtual devices and systems.
b. Provide the NASA SAISO with such inventory.
2.1.4 Software Platform and Application Inventory
2.1.4.1 The NASA SAISO shall ensure the inventory required by section 2.1.2.1 is accurate and updated with all software platforms and applications.
2.1.4.2 The ISO shall:
a. Ensure the inventory required by section 2.1.2.1 includes all software platforms and applications.
b. Provide the NASA SAISO with such inventory.
2.1.5 System Interconnections
2.1.5.1 The NASA SAISO shall maintain the mapping of information system communications and data flows in the NASA system of record.
2.1.5.2 The ISO shall:
a. Maintain and update documentation regarding system interconnections.
b. Provide the NASA SAISO with a mapping of information system communications and data flows.
c. Develop Memoranda of Agreements (MOA), Memoranda of Understandings (MOU), and Interconnection Security Agreements (ISA) for their systems.
d. Review and update such MOAs, MOUs, and ISAs annually.
2.1.6 External Information Systems Catalog
2.1.6.1 The NASA SAISO shall ensure the inventory required by section 2.1.2.1 is accurate and updated with all external information systems.
2.1.6.2 An ISO shall provide the NASA SAISO, in the NASA system of record (i.e., RISCS), with an inventory of external information systems under their supervision.
2.1.7 Resource Prioritization Policy
2.1.7.1 The SAISO shall consider the value of information and information systems to NASA’s mission in the prioritization of information security effort and resources.
2.1.8 Cybersecurity roles and responsibilities for the entire workforce and third-party stakeholders (e.g., suppliers, customers, partners) are established in this section.
2.1.8.1 The NASA CIO shall:
a. Develop and maintain a NASA-wide Cybersecurity and Privacy Program.
b. Designate a SAISO.
2.1.8.2 The SAISO shall:
a. Manage the NASA Cybersecurity and Privacy Program.
b. Maintain and update, as needed to comply with federal and NASA requirements, NPD 2810.1, NPR 2810.1, and all related handbooks.
c. Publish and maintain such policies, procedures, NASA Information Technology Requirements (NITRs), specifications, standards, handbooks, and memoranda as may be necessary to implement the requirements of this directive.
2.2 Business Environment
2.2.1 Overview
2.2.1.1 This section establishes requirements to inform NASA’s information security roles, responsibilities, and risk management decisions.
2.2.2 Supply Chain and Critical Infrastructure Identification
2.2.2.1 The NASA CIO shall:
a. Work with internal and external stakeholders to identify and communicate NASA’s role in the supply chain in order to inform the Supply Chain Risk Management (SCRM) requirements of section 2.6 of this document.
b. Work with internal and external stakeholders to identify and communicate NASA’s role in critical infrastructure.
2.2.3 Contingency Planning
2.2.3.1 The head of Center Protective Services and the Center CIO shall coordinate Center-wide contingency planning efforts that provide for notification, activation, response, recovery, and reconstitution of a Center's information systems as a result of damage or disruption caused by a man-made or natural disaster.
2.2.3.2 The SAISO shall:
a. Develop and maintain Agency-level information system contingency planning policies, procedures, and guidance for NASA, as coordinated through OPS.
b. Develop and test information security contingency plans in place to continue fulfilling the business functions of NASA in support of the Agency's mission essential functions.
c. Ensure that Center CISOs are coordinating a Center-based information system contingency program.
d. Establish recovery metrics and objectives for information systems.
2.2.3.3 The Center CISO, in coordination with OPS, shall:
a. Ensure implementation of those information system contingency planning procedures that provide for notification, activation, response, recovery, and reconstitution.
b. Oversee and arbitrate conflict resolution for all Center-wide information system contingency plans.
c. Ensure and support information system contingency plan tests, training, and exercises.
2.2.3.4 The ISO shall:
a. Develop, test, implement, and maintain information system contingency plans.
b. Document assessment, recovery, and restoration procedures.
c. Ensure that the contingency plan documentation is maintained in a ready state and accurately reflects system requirements, procedures, organizational structure, and policies.
d. Ensure that recovery and restoration procedures outlined in information system contingency plans satisfy a risk-based analysis of the business needs and objectives of the information system and Agency at large.
e. Ensure that information system contingency plan documentation is at a level sufficient to permit a coordinated response at the Center and/or the Agency level.
f. Test, evaluate, and document contingency plans for accuracy, completeness, and effectiveness via a periodic test, training, and exercise program at a frequency in accordance with Agency Defined Values.
2.3 Governance
2.3.1 Overview
2.3.1.1 This section establishes the requirements to develop policies, procedures, and processes to manage and monitor NASA’s regulatory, legal, and risk environment and operations relating to information security.
2.3.1.2 The tenets and framework of NASA's Cybersecurity and Privacy Program are spelled out in this directive and related handbooks, and the Cybersecurity and Privacy Program Plan. The policies, procedures, milestones, metrics, and responsibilities of the Cybersecurity and Privacy Program together make up the Cybersecurity and Privacy Program Plan.
2.3.2 Cybersecurity Policy
2.3.2.1 The SAISO shall:
a. Develop and document a NASA-wide NASA Cybersecurity and Privacy Program that includes an overview and descriptions of measures of performance, enterprise information security architecture, critical infrastructure, risk management strategy, and an information security assessment and authorization process.
b. Provision a NASA-wide repository for information security documentation.
c. Review, update, and augment the NASA Cybersecurity and Privacy Program.
d. Ensure that the NASA Cybersecurity and Privacy Program plan, policy, and requirements are implemented.
e. Update and disseminate Organization Defined Values via a cybersecurity specification updated at least annually.
f. Define a process for the development, documentation, and maintenance of plans of action and milestones (POA&M) and for the acceptance of risk.
g. With respect to unclassified information systems, be responsible for ensuring NASA’s implementation of the NIST RMF.
2.3.2.2 The ISO shall maintain information security documentation in the NASA-wide information security document repository required by section 2.3.2.1b.
2.3.3 Coordination of Information Security
2.3.3.1 The SAISO shall:
2.3.3.2 Coordinate information security compliance with internal and external resources across the Agency.
a. Coordinate information security reviews with the NASA Office of the Inspector General (OIG) and other external entities such as the U.S. Government Accountability Office (GAO).
b. Work with the NASA Office of Procurement to oversee the development and maintenance of an information security clause and coordinate implementation with NASA Office of Procurement as provided in the NASA Federal Acquisition Regulations (FAR), 48 CFR Ch. 18.
2.3.3.3 The Assistant Administrator of Procurement shall:
a. Ensure that contracting officials are aware of requirements related to information security.
b. Ensure the inclusion of information security requirements in all contracts and solicitations.
2.3.3.4 Program Managers and Project Managers shall:
a. Ensure that projects or programs under their control implement the requirements of this directive.
b. Ensure that information security is incorporated into the planning and development of all information systems under their control by following the procedures outlined in NIST SP 800- 160, Systems Security Engineering: Consideration for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems.
2.3.4 Management of legal and regulatory requirements
2.3.4.1 The SAISO shall:
a. Comply with OMB and FISMA reporting requirements.
b. Fulfill OMB and FISMA contingency plan testing requirements.
2.3.5 Governance and Management Processes
2.3.5.1 The NASA CIO shall report to OMB on the status of NASA's Cybersecurity and Privacy Program.
2.3.5.2 The SAISO shall:
a. Report to the NASA Administrator on the effectiveness of NASA's Cybersecurity and Privacy Program, including the progress of remedial actions, as required by FISMA.
b. Include information security resource requirements in programming and budgeting documentation.
2.3.5.3 The ISO shall:
a. Develop and maintain a System Security Plan (SSP) for their information systems.
b. Ensure that all SSPs are developed and tailored to address the threats and associated risks faced by the system.
c. Ensure that required system and services acquisition policy and procedures are implemented for their information systems and documented in the associated SSPs.
d. Establish system-level rules of behavior.
e. Assist in the development of information security requirements for inclusion in solicitations and resulting contracts for acquisitions made in support of their information.
2.3.5.4 The ISSO shall assist in the development of information security requirements for inclusion in solicitations and resulting contracts for acquisitions made in support of their information systems.
2.4 Risk Assessment
2.4.1 Overview
2.4.1.1 This section establishes requirements for the assessment of cybersecurity risk to NASA’s operations, assets, and individuals.
2.4.2 Risk Assessment Policy
2.4.2.1 The SAISO shall:
a. Identify and manage common cybersecurity threats to NASA.
b. Consistent with NPR 8000.4, Agency Risk Management Procedural Requirements, define and make available an RMF that describes a uniform methodology for risk assessment for all Agency internal and external systems.
c. Ensure the assessment, updating, and dissemination of information regarding Agency Common Controls.
d. Ensure the assessment, updating, and dissemination of information regarding those portions of Hybrid Controls that the Agency implements.
e. Manage the NASA-wide information security performance metrics program.
f. Work with the Information Sharing and Analysis Centers (ISACs) and other relevant information sharing fora.
2.4.2.2 The Center CISO shall:
a. Identify and manage common threats to their Center.
b. Understand and communicate, with the AO, the ISO, the OCSO (if assigned), other Centers’ CISOs, and the SAISO any cybersecurity flaws associated with any information system.
c. Verify the correct application of information system categorization criteria and requirements.
2.4.2.3 The OCSO (if assigned per section 1.2.3.3) shall:
a. Verify the correct application of information system categorization criteria and requirements for their organization.
b. Ensure the identification and management of common threats to their organization.
2.4.2.4 The AO shall:
a. Authorize to operate only systems posing an acceptable level of risk to Agency assets, data, and personnel for production operation.
b. Ensure that all systems undergo a complete system security assessment prior to granting an initial Authorization to Operate (ATO).
c. Approve or reject information system categorizations.
d. Grant or deny systems ATO based on an evaluation of risk to the security posture of their information systems.
e. Plan and assign resources for information security assessment and authorization activities.
2.4.2.5 The ISO shall:
a. Assess information systems for risk in accordance with Agency policy and procedures.
b. Create POA&Ms or provide a documented AO acceptance of risk related to any identified system information security deficiencies or weaknesses.
c. Complete POA&M tasks.
d. Apply resources towards the mitigation of identified risks to minimize threats to system performance.
e. Ensure that systems that are identified as posing unacceptable risk to other Agency operations or resources are communicated to the Center CISO and AO and mitigated in a manner that ensures the protection of Agency assets, data, and personnel.
f. Inform key officials of pending assessment and authorization activities.
g. Plan and advocate for the availability of resources for assessment and authorization activities.
h. Perform an information system risk analysis for their systems that can be used to support development of Agency information security baselines.
i. Seek an authorization from the AO prior to the operation of an information system and if changes to the system or its operating environment warrant a reauthorization.
2.4.2.6 The ISSO shall:
a. Perform information system risk analyses in support of security control selection and tailoring, security control implementation including system configuration, and continuous monitoring.
b. In collaboration with the ISO and IO(s), perform the information system security categorization, ensuring that the selected data types reflect all information generated, collected, processed and disseminated by the information system.
2.4.2.7 Program Managers and Project Managers shall:
a. With the support ISOs and ISSOs, understand and communicate to AOs any cybersecurity risks associated with any information system in a program or project under their control so that an assessment can be made of cybersecurity risk to Agency operations and resources.
b. Verify the proper application of information system categorization criteria and requirements for the programs and projects under their control.
2.5 Risk Management Strategy
2.5.1 Overview
2.5.1.1 This section establishes requirements for a cybersecurity risk management strategy to work in conjunction with requirements of NPR 8000.4.
2.5.2 Risk Management Strategy
2.5.2.1 The SAISO shall develop and implement a Cybersecurity Risk Management Strategy, which includes:
a. Definition of NASA’s risk management priorities and constraints for NASA high-value assets, and mission and institutional systems.
b. Documentation criteria as a basis for determination of NASA’s risk tolerances and assumptions.
c. Description of the importance of accurate and timely assessment of the likelihood and consequence severity of threats to NASA’s critical infrastructure within the unique threat environment for NASA operations.
d. Ensure the underlying basis for risk acceptance decisions by AOs across NASA conform to validated practices set forth in NPR 8000.4.
2.6 Supply Chain Risk Management
2.6.1 Overview
2.6.1.1 This section establishes requirements for SCRM.
2.6.2 SCRM Policy
2.6.2.1 The NASA SAISO shall:
a. In awareness of Office of Safety and Mission Assurance roles, develop, manage, and update NASA’s Cyber SCRM process.
b. Identify, prioritize, and assess suppliers and third-party partners of information systems using a cyber supply chain risk assessment process.
c. Work with program and procurement officials in NASA to ensure that:
(1) Contracts with suppliers and third-party partners implement measures designed to meet the objectives of this directive and the Cyber SCRM process required by section 2.6.2.1a.
(2) Suppliers and third-party partners are routinely assessed using audits, test results, or other forms of evaluations to confirm they are meeting their contractual obligations.
(3) Response and recovery planning and testing are conducted with suppliers and third-party providers.
2.6.2.2 The ISO shall:
a. Understand the level of risk to an information system related to the information that is necessarily disclosed to vendors and suppliers during the acquisition process.
b. Establish a process to address weaknesses or deficiencies in supply chain elements identified during independent or organizational assessments of such elements.
Chapter 3. Protect Function
3.1 Identity Management and Access Control
3.1.1 Overview
3.1.1.1 This section establishes requirements for identity management and access control.
3.1.1.2 NPR 2841.1, Identity, Credential, and Access Management (ICAM) establishes requirements for issuance, management, verification, and revocation of identities and credentials.
Such identities and credentials govern both physical and logical access to NASA assets.
3.1.2 Physical Access Policy
3.1.2.1 The Center CIO shall work with the Center Chief of Security, and the Center Facilities organization to ensure physical and environmental controls are met for the information systems at their Centers.
3.1.2.2 The ISO shall:
a. Approve personnel access to secured or restricted physical information system facilities and locations.
b. Establish and maintain a list of all personnel authorized to access secured or restricted physical information system facilities and locations.
c. Validate physical and environmental security controls and monitoring capabilities.
3.1.2.3 The Center Chief of Security, under the policy guidance of Assistant Administrator of the Office of Protective Services shall:
a. Ensure the implementation of physical and environmental security controls.
b. Ensure the capability to monitor physical and environmental security controls.
3.1.3 Remote Access Policy
3.1.3.1 The ISO shall:
a. Ensure only devices that are authorized and approved for remote access to the information system to which they are connecting are granted remote access in a manner consistent with organizational defined values.
b. Ensure that all remote access is routed through NASA CIO-authorized remote access points.
3.1.3.2 Program Managers and Project Managers shall ensure, with respect to any information system in a program or project under their control, that all remote access is routed through authorized NASA access control points.
3.1.3.3 The NASA User shall:
a. Use only NASA authorized and approved devices for remote access to NASA non-public information systems.
b. Take every reasonable effort to ensure the confidentiality, integrity, and availability of information and information systems used remotely and understand the consequences for mishandling.
3.1.4 Access Permissions and Authorization Policy
3.1.4.1 The ISO shall:
a. Administer accounts for their information systems in a way that provides separation of duties, avoids potential conflicts of interest, and grants NASA users the least privilege necessary to perform their respective duties.
b. Manage, in consideration of the IO, access to the information system, and with which privileges users will be authorized.
c. Ensure that any public facing service that requires a login is secured by multi-factor authentication (MFA).
d. Configure all systems and services to permit only authorized connections.
e. Manage all systems and services in a “deny by default, permit by exception” configuration for all ports, protocols, and services.
3.1.4.2 The IO may offer guidance to the ISO regarding management of access to the information system, and with which privileges users will be empowered.
3.1.4.3 The Center Chief of Security or the Assistant Administrator of the Office of Protective Services shall ensure the distribution and management of physical authenticators (i.e., PIV cards).
3.1.4.4 The NASA CIO shall ensure the distribution and management of any other authentication tokens.
3.1.5 Network Integrity Policy
3.1.5.1 The SAISO shall ensure that NASA maintains a Network Access Control Policy to monitor, control, prevent, or regulate device and system access to NASA networks.
3.1.6 Identity Policy
3.1.6.1 The NASA CIO shall provide a NASA-wide framework for identity and authentication management.
3.1.6.2 The ISO shall leverage the Agency identification and authentication framework for applications.
3.1.6.3 The NASA User shall protect identification and authentication information from unauthorized disclosure.
3.1.7 Authentication Policy
3.1.7.1 The SAISO shall:
a. Ensure dissemination of the NASA appropriate use policy statement, based on NPD 2540.1, Personal Use of Government Office Equipment Including Information Technology, and the NASA consent banner.
b. Ensure that the NASA consent disclaimer requirements for internal systems are met through the display of the appropriate use and consent banner statements.
3.1.7.2 The ISO shall:
a. Leverage the Agency identification and authentication framework for applications.
b. Maintain account management capabilities (e.g., account creation, privilege configuration, maintenance, and deletion) for information systems.
c. Ensure the appropriate use and warning banner is displayed by their information system.
d. Establish documented rules for appropriate use and protection of information (e.g., rules of behavior).
3.1.7.3 The NASA User shall comply with all appropriate use policies.
3.2 Awareness and Training
3.2.1 Overview
3.2.1.1 This section establishes requirements for information security awareness and training to ensure that NASA’s personnel and partners are trained to perform their cybersecurity-related duties and responsibilities consistent with NASA policies, procedures, and agreements.
3.2.2 Awareness and Training Policy
3.2.2.1 All NASA officials listed in section 1.2 (relating to Roles and Responsibilities) shall complete any role-based training activities required of their position.
3.2.2.2 The SAISO shall:
a. Develop, maintain, and promote NASA-wide information security awareness and training.
b. Define and make available all Agency information security awareness and training requirements. This includes general knowledge requirements that pertain to all NASA Users as well as role-based requirements targeted at managers, information security professionals, and others.
c. Define educational courses and materials that can be used to satisfy Agency information security awareness and training requirements.
d. Oversee the fulfillment of training requirements across the Agency and for external stakeholders, to include tracking and reporting on the completion of information security awareness and training requirements in the Agency system of record.
e. Maintain the NASA User Rules of Behavior and track user annual acceptance.
3.2.2.3 The ISO shall:
a. Allow access to information systems only to users who comply with all Agency information security awareness and training requirements.
b. Ensure all personnel supporting the information system whose roles include significant information security…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .