SOFIA_Science_Network_SOW_v2.pdf

PDF 30 KB Posted

Attached to
Independent Security Assessment of the SOFIA Science Network IT System Federal contract opportunity
Solicitation number
NND16588197Q
Issued by
National Aeronautics and Space Administration Armstrong Flight Research Center

View the file

Other files for this federal contract opportunity

Other files attached to Independent Security Assessment of the SOFIA Science Network IT System, newest first.
File Type Posted
NND16588197Q_Amendment003.pdf PDF
NND16588197Q_Amendment002.pdf PDF
NND16588197Q_Amendment001.pdf PDF
SC9999MARC3504_SOFIA_Science_network_pricing_and_sizing_document..pdf PDF
ssmo_information_08_Feb_16.docx DOCX document
ssmo_authorization_boundary_fy16.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

STATEMENT OF WORK

Independent Security Assessment of the SOFIA Science Network IT System

SOFIA Program Office

National Aeronautics and Space Administration Armstrong Flight Research Center Edwards, California

Table of Contents

1.0 Background

2.0 Objectives

3.0 Requirements

4.0 Deliverables

5.0 Period of Performance

6.0 Travel

7.0 Other Special Requirements and Considerations

NND16588197Q SOW SOFIA

4 May 2016 Version 1

1.0 Background

NASA’s SOFIA Science Network Information Technology (IT) System must undergo the process of Assessment and Authorization in order to meet cyber security requirements outlined in the Federal Information Security Management Act (FISMA).

Assessment is the process of assessing the system’s risk level; the assessment process must be performed by an independent Security Control Assessment Team (SCAT).

Authorization is the process of granting the IT system a formal Authorization to Operate (ATO); the ATO is granted by a senior NASA official based on the results of the Assessment.

While NASA typically refers to this process as Assessment and Authorization (A&A), the process is referenced by many Federal agencies as Information Assurance (IA).

The SCAT Vendor will perform an Assessment of the SOFIA Science Network IT System that aligns with the following National Institute of Standards and Technology (NIST) Special Publications (SP):

NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach

NIST SP 800-53 Rev. 4, Security and Privacy Controls for Federal Information Systems and Organizations

NIST SP 800-53 Rev. 4A, Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans

IT components comprising the SOFIA Science Network IT system are located at:

NASA Ames Research Center (ARC) Buildings N232 and N21 Mountain View, California

NASA Armstrong Flight Research Center (AFRC) Building 703 Palmdale, California

2.0 Objectives

The SOFIA Program requires an independent SCAT to perform an Assessment of the SOFIA Science Network IT system, which has been categorized as a MODERATE-impact system. The purpose of the Assessment is to assess the system security controls to determine the extent to which the controls are being implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system.

The SCAT Vendor will have a solid understanding of performing these services within the context of NIST’s Risk Management Framework (RMF) architecture. The Assessment findings will be combined with the SCAT Vendor’s expert recommendations to formulate a security remediation plan that seeks to minimize risk exposure of the subject environment.

The SCAT Vendor will provide services based on current guidance from NIST, as well as best-of-breed industry tools. The SCAT Vendor will provide Assessment services that address NIST SP 800-53 Rev. 4 MODERATE-impact security controls. Assessment services will include reviewing existing system security documentation, interviewing key NASA security personnel, testing the system security controls, and delivering findings documents.

Note: A site survey is outside scope of this Statement of Work. The documentation to be provided by the SOFIA team will adequately describe the physical layout of the SOFIA Science Network IT System at the two NASA locations referenced above.

3.0 Requirements

The Assessment process will include three phases:

Phase 1: Planning Phase (Pre-Travel) Project planning, coordination, and scheduling activities will be performed by the SCAT Vendor. The goal of this phase is to minimize operational impact, confirm a common understanding of the process, review the scope of the project, and ensure the availability of resources.

The SCAT Vendor’s Project Manager will participate in planning meetings, kick-off meetings, in-briefing meetings, status meetings, and out-briefing meetings. The Project Manager will be the primary point of contact (POC) for all activities in support of the Assessment effort.

The SCAT Vendor will conduct an Assessment kick-off meeting via conference call, to ensure the congruent understanding of all parties and define the Assessment schedule.

The SCAT Vendor will develop and deliver a Security Assessment Plan and Procedures (SAPP) document that will clearly outline the objectives for the Assessment and provide a detailed roadmap of how the Assessment will be conducted, generic rules of engagement and expectations, actions to be taken by the SCAT Vendor, resources to be applied, tools to be used, travel to be required, personnel required, unanticipated events, issues and recommendations, and post-Assessment actions.

The SCAT Vendor will use MODERATE-impact security controls outlined in NIST SP 800-53 Rev. 4 when performing the Assessment, as well as other applicable Federal regulations and guidance related obtaining a successful ATO decision.

Phase 2: Requirements Gathering During this phase, the SCAT Vendor will acquire and review relevant system documentation and evidence showing that security control objectives are being met for the information system.

Documentation to be collected by the SCAT Vendor from the SOFIA Project include policies, procedures, architectural diagrams, functional specifications, and other relevant system security documents. These documents will assist the SCAT Vendor in determining if:

• Documentation sufficiently addresses stated requirements

• Documentation details the approach to implementing security objectives

• Processes are described in sufficient detail

• Roles and responsibilities are adequately defined and assigned

Also during this phase, the SCAT Vendor will perform interviews and make observations on-site, by telephone, and/or by online conference with appropriate SOFIA personnel to determine if they understand the existing policies and follow appropriate processes.

Also during this phase, vulnerability scans of the system will be performed by NASA personnel or by the SCAT Vendor personnel utilizing approved vulnerability scanning software. All scans will be accomplished using NASA-approved Assessment tools. The following types of tools may be used during the system testing, depending on the specific conditions experienced by the SCAT Vendor:

• Vulnerability Scanning: Assured Compliance Assessment Solution (ACAS)

• Compliance Scanning: Security Content Automation Protocol (SCAP)

• Benchmarking guidelines: USGCB, CIS

• Network Mapping: nmap

Scan data will include information regarding system configuration, control compliance, and system vulnerabilities. Scans performed by the SCAT Vendor will use NASA-approved benchmarking guidelines (USGCB, CIS) for configuration standards. Specifically, the configuration scans will provide the SCAT Vendor with a deeper understanding on how the configuration baseline controls are implemented and if the implementation meets industry best practices. The control compliance scan will validate benchmark compliance, while vulnerability scans will provide additional insight into configuration and patch management. Scan data will also allow the SCAT vendor to identify the required patches and updates that must be implemented on the system in order to reduce the risk of operating the system to a level that will be reasonably acceptable to the Authorizing Official.

Also during this phase, the SCAT Vendor will test the implementation of the MODERATE-level security controls implemented on the system as documented in the system security plan (SSP). Testing methods will include Interview, Examination, and Test of individual security controls. If SCAT Vendor’s test results are incongruent with documented statements in the SSP, the SCAT Vendor will recommend corrections to the SSP document but will not apply edits to the SSP document.

Phase 3: Data Analysis and Reporting Phase The goal of the Data Analysis and Reporting Phase is to complete the project deliverables and provide a clear picture to NASA regarding the security posture of the information system.

In Phase 3, the SCAT Vendor will perform a thorough analysis of the data gathered in Phase 2 to determine if Federal IT security requirements have been met. The results of this analysis will be presented in a Security Assessment Report (SAR). The SAR will enumerate and prioritize system security vulnerabilities and present mitigation recommendations.

The SCAT Vendor will provide a system Plan of Action and Milestones (POA&M) pursuant to NIST and NASA policies and procedures. This POA&M is used to assist the system owner in identifying, assessing, prioritizing, and monitoring security deficiencies associated with the system, documenting progress in correcting those deficiencies, and identifying tasks to be accomplished.

4.0 Deliverables

The Assessment will enumerate and prioritize system vulnerabilities and weaknesses in the implementation of security controls for the system. Deliverables from the SCAT vendor will include:

• Project In-Brief

• Status Reports

• Security Assessment Plan and Procedures (SAPP)

• Security Assessment Report (SAR)

• Plan of Action and Milestones (POA&M)

5.0 Period of Performance

The SCAT Vendor will provide Assessment services within 120 days of contract award.

6.0 Travel

Travel to be billed per government joint travel regulations.

7.0 Other Special Requirements and Considerations

Security requirements; Vendor staff must meet NASA unescorted badging guidelines (Access requirements will be made during the first phase)

Special material requirements;

For the duration of assessment the SOFIA program will provide facilities for SCAT vendor personnel and the following resources be made available for vendor use:

Private meeting space with white board or easel, suitable for conducting interviews and sensitive discussions;

Secure, lockable room for temporary storage of equipment and documents;

Internet access, via either wired or 802.11b/g/n wireless Ethernet network connection;

Access to NASA facilities, administrators, system owner, engineers, and security officers.

File details come from the government source that posted it. Updated .