ssmo_information_08_Feb_16.docx
DOCX document 17 KB Posted
- Attached to
- Independent Security Assessment of the SOFIA Science Network IT System Federal contract opportunity
- Solicitation number
- NND16588197Q
About this file
SSMO Information
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| NND16588197Q_Amendment003.pdf | ||
| NND16588197Q_Amendment002.pdf | ||
| NND16588197Q_Amendment001.pdf | ||
| ssmo_authorization_boundary_fy16.pdf | ||
| SOFIA_Science_Network_SOW_v2.pdf | ||
| SC9999MARC3504_SOFIA_Science_network_pricing_and_sizing_document..pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SOFIA Science Network (SSMO) Information The SOFIA Science Network (SSMO), formerly known as the SOFIA Information System for Science Mission Operations (SISSMO), is designed to support all the activities performed by the Science Mission Operations (SMO) staff in support of the NASA SOFIA Program. The primary location of the SSMO is the SOFIA Science Center (SSC) at NASA Ames Research Center (ARC) building N211. A subset of systems are located at the SOFIA Operations Center (SOC) at Armstrong Flight Research Center (AFRC) building 703 in Palmdale, CA, in order to support activities directly related to Data Transfer, Mission Planning, Mission Simulation, Science Instrument testing, and other development and operational activities. This document shall serve to fulfill security requirements: PL-8 Information Security Architecture. This document shall be reviewed annually.
Philosophy The SSMO was conceived, partially, as a standalone entity so that it would not inherit a security design from a parent network or organization with goals that may not be aligned with SOFIA's mission to provide public access to scientific data gathered during its lifetime. Additionally, the SSMO provides the capabilities and flexibility to support guests, foreign nationals, instrument scientists, PIs, GIs, DSI/DLR associates, and other partners needing timely physical and/or logical access for support activities directly related to Data Transfer, Mission Planning, Mission Simulation, Science Instrument testing, and other development and operational activities.
The overall philosophy of the SSMO Information Security Architecture is to protect the confidentiality and integrity of the enterprise information technology architecture in order to support mission operations for the SOFIA project. An additional goal is to ensure availability of the system during key periods (call for proposals, pre-flight mission planning, etc.). Appropriate segmentation of information system components is also necessary when supporting other development and operational activities including: partner collaboration, development and maintenance of science instruments, hosting visiting scientists (including PIs, GIs, and foreign nationals), etc. The Information Security Architecture represents an optimal balance between security (which assures a reasonable level of confidentiality, integrity, and availability) and functionality (which provides enough flexibility to accommodate the functions that are necessary to operate both the SSC and SOC and to enable SOFIA mission objectives).
Enterprise Architecture The overall architecture of the network is segmented into several security zones, where traffic is filtered based on relative risk and function. Each zone is managed by a Cisco ASA firewall that provides both Stateful Packet Inspection (SPI) and highly configurable inbound and outbound Access Control Lists (ACLs). Intrusion Detection System (IDS) capabilities and centralized logging facilities (Splunk) also exist to support higher risk segments of the network. Each firewall device has up to 8 interfaces, permitting the creation of numerous Virtual Local Area Networks (VLANs) which are used to further isolate traffic based on purpose and relative risk. See the supplemental diagrams for additional detail.
The philosophy behind the architecture is that critical systems, such as the Data Cycle System (DCS) (both its Production Environment and its Test/Development Environments), should be isolated from user and developer workstations such that all traffic must pass through at least one filtered firewall interface. The concept of a De-Militarized Zone (DMZ) is implemented such that publicly available systems, which by their nature and more exposed and vulnerable, are isolated from the rest of the information system. Network traffic flow patterns and Access Control Lists (ACLs) are established according to the principle of least privilege, such that all communication is denied by default, and then allowed by exception.
Requirements and Approach As part of managing federal assets within a federal facility, USRA is required to comply with the Federal Information Security Management Act (FISMA) and all other applicable federal regulations. By implementing Federal Information Processing Standard (FIPS) 199 in accordance with Homeland Security Presidential Directive (HSPD) 12, USRA takes a risk-based approach to categorizing the information system, defining appropriate security controls, and continually assessing their effectiveness throughout the lifecycle of the information system.
External Services The SSMO information system depends on several key external factors that are outside the control of USRA. The primary external component is continued financial support. As an annually government funded project, the SSMO cannot fully continue to operate (beyond the limits of specific contract deliverables as defined within prime contract NAS2-97001) without recurring funding. Similarly, the budgetary allocation of resources directly impacts the continued ability to securely operate and maintain the system. The SSMO relies upon an external Internet connection (currently provided by AT&T at the SSC) for providing essential public facing services (DCS, science website, support services, etc.) and establishment of the science datalink between physical sites. The NASA AFRC and NISN networking infrastructure at the SOC are also required external components for establishing and maintaining the science datalink. During deployment of the aircraft to remote locations, an Internet Service Provider (ISP) is necessary to provide a short-term, high capacity science datalink, which facilitates mission operations. The SSC and SOC data centers are both physically managed and maintained externally by their respective NASA centers. All environmental conditioning, power allocation, emergency preparedness, and physical access control are critical for the continued operation of the SSMO.
File details come from the government source that posted it. Updated .