SOFIA_Science_Network_SOW_v2.pdf
PDF 30 KB Posted
- Attached to
- Independent Security Assessment of the SOFIA Science Network IT System Federal contract opportunity
- Solicitation number
- NND16588197Q
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| NND16588197Q_Amendment003.pdf | ||
| NND16588197Q_Amendment002.pdf | ||
| NND16588197Q_Amendment001.pdf | ||
| SC9999MARC3504_SOFIA_Science_network_pricing_and_sizing_document..pdf | ||
| ssmo_information_08_Feb_16.docx | DOCX document | |
| ssmo_authorization_boundary_fy16.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
STATEMENT OF WORK
Independent Security Assessment of the SOFIA Science Network IT System
SOFIA Program Office
National Aeronautics and Space Administration Armstrong Flight Research Center Edwards, California
Table of Contents
1.0 Background
2.0 Objectives
3.0 Requirements
4.0 Deliverables
5.0 Period of Performance
6.0 Travel
7.0 Other Special Requirements and Considerations
NND16588197Q SOW SOFIA
4 May 2016 Version 1
1.0 Background
NASA’s SOFIA Science Network Information Technology (IT) System must undergo the process of Assessment and Authorization in order to meet cyber security requirements outlined in the Federal Information Security Management Act (FISMA).
Assessment is the process of assessing the system’s risk level; the assessment process must be performed by an independent Security Control Assessment Team (SCAT).
Authorization is the process of granting the IT system a formal Authorization to Operate (ATO); the ATO is granted by a senior NASA official based on the results of the Assessment.
While NASA typically refers to this process as Assessment and Authorization (A&A), the process is referenced by many Federal agencies as Information Assurance (IA).
The SCAT Vendor will perform an Assessment of the SOFIA Science Network IT System that aligns with the following National Institute of Standards and Technology (NIST) Special Publications (SP):
NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach
NIST SP 800-53 Rev. 4, Security and Privacy Controls for Federal Information Systems and Organizations
NIST SP 800-53 Rev. 4A, Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans
IT components comprising the SOFIA Science Network IT system are located at:
NASA Ames Research Center (ARC) Buildings N232 and N21 Mountain View, California
NASA Armstrong Flight Research Center (AFRC) Building 703 Palmdale, California
2.0 Objectives
The SOFIA Program requires an independent SCAT to perform an Assessment of the SOFIA Science Network IT system, which has been categorized as a MODERATE-impact system. The purpose of the Assessment is to assess the system security controls to determine the extent to which the controls are being implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.
The SCAT Vendor will have a solid understanding of performing these services within the context of NIST’s Risk Management Framework (RMF) architecture. The Assessment findings will be combined with the SCAT Vendor’s expert recommendations to formulate a security remediation plan that seeks to minimize risk exposure of the subject environment.
The SCAT Vendor will provide services based on current guidance from NIST, as well as best-of-breed industry tools. The SCAT Vendor will provide Assessment services that address NIST SP 800-53 Rev. 4 MODERATE-impact security controls. Assessment services will include reviewing existing system security documentation, interviewing key NASA security personnel, testing the system security controls, and delivering findings documents.
Note: A site survey is outside scope of this Statement of Work. The documentation to be provided by the SOFIA team will adequately describe the physical layout of the SOFIA Science Network IT System at the two NASA locations referenced above.
3.0 Requirements
The Assessment process will include three phases:
Phase 1: Planning Phase (Pre-Travel) Project planning, coordination, and scheduling activities will be performed by the SCAT Vendor. The goal of this phase is to minimize operational impact, confirm a common understanding of the process, review the scope of the project, and ensure the availability of resources.
The SCAT Vendor’s Project Manager will participate in planning meetings, kick-off meetings, in-briefing meetings, status meetings, and out-briefing meetings. The Project Manager will be the primary point of contact (POC) for all activities in support of the Assessment effort.
The SCAT Vendor will conduct an Assessment kick-off meeting via conference call, to ensure the congruent understanding of all parties and define the Assessment schedule.
The SCAT Vendor will develop and deliver a Security Assessment Plan and Procedures (SAPP) document that will clearly outline the objectives for the Assessment and provide a detailed roadmap of how the Assessment will be conducted, generic rules of engagement and expectations, actions to be taken by the SCAT Vendor, resources to be applied, tools to be used, travel to be required, personnel required, unanticipated events, issues and recommendations, and post-Assessment actions.
The SCAT Vendor will use MODERATE-impact security controls outlined in NIST SP 800-53 Rev. 4 when performing the Assessment, as well as other applicable Federal regulations and guidance related obtaining a successful ATO decision.
Phase 2: Requirements Gathering During this phase, the SCAT Vendor will acquire and review relevant system documentation and evidence showing that security control objectives are being met for the information system.
Documentation to be collected by the SCAT Vendor from the SOFIA Project include policies, procedures, architectural diagrams, functional specifications, and other relevant system security documents. These documents will assist the SCAT Vendor in determining if:
• Documentation sufficiently addresses stated requirements
• Documentation details the approach to implementing security objectives
• Processes are described in sufficient detail
• Roles and responsibilities are adequately defined and assigned
Also during this phase, the SCAT Vendor will perform interviews and make observations on-site, by telephone, and/or by online conference with appropriate SOFIA personnel to determine if they understand the existing policies and follow appropriate processes.
Also during this phase, vulnerability scans of the system will be performed by NASA personnel or by the SCAT Vendor personnel utilizing approved vulnerability scanning software. All scans will be accomplished using NASA-approved Assessment tools. The following types of tools may be used during the system testing, depending on the specific conditions experienced by the SCAT Vendor:
• Vulnerability Scanning: Assured Compliance Assessment Solution (ACAS)
• Compliance Scanning: Security Content Automation Protocol (SCAP)
• Benchmarking guidelines: USGCB, CIS
• Network Mapping: nmap
Scan data will include information regarding system configuration, control compliance, and system vulnerabilities. Scans performed by the SCAT Vendor will use NASA-approved benchmarking guidelines (USGCB, CIS) for configuration standards. Specifically, the configuration scans will provide the SCAT Vendor with a deeper understanding on how the configuration baseline controls are implemented and if the implementation meets industry best practices. The control compliance scan will validate benchmark compliance, while vulnerability scans will provide additional insight into configuration and patch management. Scan data will also allow the SCAT vendor to identify the required patches and updates that must be implemented on the system in order to reduce the risk of operating the system to a level that will be reasonably acceptable to the Authorizing Official.
Also during this phase, the SCAT Vendor will test the implementation of the MODERATE-level security controls implemented on the system as documented in the system security plan (SSP). Testing methods will include Interview, Examination, and Test of individual security controls. If SCAT Vendor’s test results are incongruent with documented statements in the SSP, the SCAT Vendor will recommend corrections to the SSP document but will not apply edits to the SSP document.
Phase 3: Data Analysis and Reporting Phase The goal of the Data Analysis and Reporting Phase is to complete the project deliverables and provide a clear picture to NASA regarding the security posture of the information system.
In Phase 3, the SCAT Vendor will perform a thorough analysis of the data gathered in Phase 2 to determine if Federal IT security requirements have been met. The results of this analysis will be presented in a Security Assessment Report (SAR). The SAR will enumerate and prioritize system security vulnerabilities and present mitigation recommendations.
The SCAT Vendor will provide a system Plan of Action and Milestones (POA&M) pursuant to NIST and NASA policies and procedures. This POA&M is used to assist the system owner in identifying, assessing, prioritizing, and monitoring security deficiencies associated with the system, documenting progress in correcting those deficiencies, and identifying tasks to be accomplished.
4.0 Deliverables
The Assessment will enumerate and prioritize system vulnerabilities and weaknesses in the implementation of security controls for the system. Deliverables from the SCAT vendor will include:
• Project In-Brief
• Status Reports
• Security Assessment Plan and Procedures (SAPP)
• Security Assessment Report (SAR)
• Plan of Action and Milestones (POA&M)
5.0 Period of Performance
The SCAT Vendor will provide Assessment services within 120 days of contract award.
6.0 Travel
Travel to be billed per government joint travel regulations.
7.0 Other Special Requirements and Considerations
Security requirements; Vendor staff must meet NASA unescorted badging guidelines (Access requirements will be made during the first phase)
Special material requirements;
For the duration of assessment the SOFIA program will provide facilities for SCAT vendor personnel and the following resources be made available for vendor use:
Private meeting space with white board or easel, suitable for conducting interviews and sensitive discussions;
Secure, lockable room for temporary storage of equipment and documents;
Internet access, via either wired or 802.11b/g/n wireless Ethernet network connection;
Access to NASA facilities, administrators, system owner, engineers, and security officers.
File details come from the government source that posted it. Updated .