9I.__Attachment_O_-_Information_Technology_Applicable_Documents_List.pdf
PDF 152 KB Posted
- Attached to
- Space Exploration Networks Services and Evolution (SENSE) Federal contract opportunity
- Solicitation number
- NNG17588638R
About this file
Attachment O - Information Technology Applicable Documents List
View the file
Other files for this federal contract opportunity
Show all 50
Space Exploration Networks Services and Evolution (SENSE) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT O
INFORMATION TECHNOLOGY (IT) SECURITY
APPLICABLE DOCUMENTS LIST
June 2016
RFP NNG17588638R
CONTRACT TBD
| Contract | TBD |
| Attachment | O |
(06/2016)
Information Technology (IT) Security Applicable Documents List June 2016
NASA Policy Directives (NPD) and NASA Procedural Requirements (NPR)
Document Subject Effective Date
NPR 1382.1A NASA Privacy Procedural Requirements July 10, 2013
NPD 1382.17H NASA Privacy Policy June 24, 2009
NPD 1440.6I NASA Records Management September 10, 2014
NPR 1441.1E
NASA Records Management Program Requirements January 29, 2015
NPD 2540.1H
Personal Use of Government Office Equipment Including Information Technology February 24, 2016
NPD 2800.1B Managing Information Technology March 21, 2008
NPR 2800.1B Managing Information Technology March 20, 2009
NPD 2810.1E NASA Information Security Policy July 14, 2015
NPR 2810.1A Security of Information Technology w/ Change 1, May 19, 2011) May 16, 2006
NPD 2830.1A NASA Enterprise Architecture November 2, 2011
NPR 2830.1A NASA Enterprise Architecture Procedures December 19, 2013
NPR 2841.1 Identity, Credential, and Access Management January 6, 2011
NASA Interim Directive (NID)
NM2810-64 NASA Interim Directive: Information Technology Security and Efficiency Requirements
May 22, 2008
NID 7120.99 NASA Information Technology and Institutional Infrastructure Program and Project Management Requirements
December 22, 2011
| Contract | TBD |
| Attachment | O |
(06/2016)
NASA Interim Technical Requirements (NITR)
NITR 2800_2 Email Services and Email Forwarding September 18, 2009
NITR 2800_1 NASA Information Technology Waiver Requirements and Procedures
August 13, 2009
IT Security Handbooks (ITS-HBK)
ITS-HBK-1382.02-01 Privacy Goals and Objectives July 27, 2012
ITS-HBK-1382.03-01
Privacy Risk Management and Compliance:
PIAs and SORNs
September 25, 2012
ITS-HBK-1382.03-02
Privacy Risk Management and Compliance:
Annual Reporting Procedures for Reviewing and Reducing PII and Eliminating the Unnecessary Use of SSN
September 7, 2011
ITS-HBK-1382.04-01 Privacy and Information Security: Overview August 28, 2012
ITS-HBK-1382.05-01
Privacy Incident Response and Management:
Breach Response Team Checklist
September 25, 2012
ITS-HBK-1382.06-01
Privacy Notice and Redress: Web Privacy & Written Notice, Complaints, Access and Redress
September 7, 2012
ITS-HBK-1382.07-01 Privacy Awareness and Training: Overview September 7, 2014
ITS-HBK-1382.08-01 Privacy Accountability: Overview August 28, 2012
ITS-HBK-1382.09-01
Privacy Rules of Behavior and Consequences:
Overview
September 7, 2012
ITS-HBK-2810.0001-B
Format and Procedures for an IT Security Policies and Handbooks
June 19, 2014
| Contract | TBD |
| Attachment | O |
(06/2016)
IT Security Handbooks (ITS-HBK)
Document Subject Effective Date
NITR 2810.1
NASA Information Technology Security Disclaimer
Sept 30, 2014
ITS-HBK-1441.01.01 Records Retention and Disposition: Overview Jul 02, 2014
ITS-HBK-1440.01.01 Records Planning & Management: Records Jul 02, 2014
ITS-HBK-2841.001-A Identity, Credential, and Access Management Services
Feb 01, 2011
IT-SOP-2841.001-A Identity and Credential Service Providers Federation Requests
Feb 01, 2011
IT-SOP-2841.002-A Identity, Credential, and Access Management (ICAM): Service Deviation Requests Management & Records Life Cycle-Overview
Feb 01, 2011
IT-STD-1441.1 NASA Records Retention Schedules May 07, 2014
ITS-HBK-2810.02-01 Security Assessment and Authorization May 6, 2011
ITS-HBK-2810.0002-A
Roles and Responsibilities Crosswalk & Definitions
May 2, 2013
ITS-HBK-2810.02-02D
Information System Security Assessment and Authorization Process
February 1, 2015
ITS-HBK-2810.02-04A
Security Assessment and Authorization:
Continuous Monitoring – Annual Security Control Assessments
March 18, 2014
ITS-HBK-2810.02-05 Security Assessment and Authorization:
External Information Systems
October 24, 2012
ITS-HBK-2810.02-06
Security Assessment and Authorization:
Extending and Information Systems Authorization to Operate Process and Templates
October 24, 2012
ITS-HBK-2810.02-08A
Security Assessment and Authorization: Plan of Action and Milestones (POA&M)
December 11, 2013
| Contract | TBD |
| Attachment | O |
(06/2016)
IT Security Handbooks (ITS-HBK)
Document Subject Effective Date
ITS-HBK-2810.03-01 Planning May 6, 2011
ITS-HBK-2810.03-02
Planning: Information System Security Plan Template, Requirements, Guidance and Examples
February 9, 2011
ITS-HBK-2810.04-01A
Risk Assessment: Security Categorization, Risk Assessment, Vulnerability Scanning, Expedited Patching & Organizationally Defined Values
October 12, 2012
ITS-HBK-2810.04-02
Risk Assessment: Procedures for Information System Security Penetration Testing and Rules of Engagement
April 30, 2013
ITS-HBK-2810.04-03
Risk Assessment: Web Application Security Program
April 30, 2013
ITS-HBK-2810.05-01 Systems and Service Acquisition November 21, 2011
ITS-HBK-2810.06a-01 Awareness and Training May 5, 2011
ITS-HBK-2810.07-01 Configuration Management May 6, 2011
ITS-HBK-2810.08-01 Contingency Planning May 06, 2011
ITS-HBK-2810.08-02
Contingency Planning: Guidance and Templates for Plan Development, Maintenance and Test
February 10, 2011
ITS-HBK-2810.09-01A Incident Response and Management December 30, 2014
ITS-HBK-2810.09-02
NASA Information Security Incident Management
August 24, 2011
ITS-HBK-2810.09-03 Targeted Collection of Electronic Data August 24, 2011
ITS-HBK-2810.09-04
Incident Response and Management:
Guidelines for Data Spillage & Sanitization Procedures
February 27, 2014
ITS-HBK-2810.10-01 Maintenance May 6, 2011
| Contract | TBD |
| Attachment | O |
(06/2016)
IT Security Handbooks (ITS-HBK)
Document Subject Effective Date
ITS-HBK-2810.11-01 Media Protection July 13, 2012
ITS-HBK-2810.11-02 Media Protection: Digital Media Sanitization July 13, 2012
ITS-HBK-2810.12-01 Physical and Environmental Protection May 6, 2011
ITS-HBK-2810.13-01 Personnel Security May 6, 2011
ITS-HBK-2810.14-01 System and Information Integrity May 6, 2011
ITS-HBK-2810.15-01 Access Control September 4, 2012
ITS-HBK-2810.15-02A Access Control: Elevated Privileges (EP) September 20, 2012
ITS-HBK-2810.16-01 Audit and Accountability May 6, 2011
ITS-HBK-2810.17-01 Identification and Authentication Jan 17, 2011
ITS-HBK-2810.18-01 System and Communications Protection Apr 6, 2011
Standards
EA-STD 0001.0 Standard for Integrating Applications into the NASA Access Management, Authentication, and Authorization Infrastructure
August 1, 2008
EA-SOP 0003.0 Procedures for Submitting a NASA Agency Forest (NAF) Deviation Request and Transition Plan
August 1, 2008
EA-SOP 0004.0 Procedures for Submitting an Application Integration Deviation Request and Transition Plan
August 1, 2008
NASA-STD-2804-P Minimum Interoperability Software Suite September 22, 2014
NASA-STD-2805-P Minimum Hardware Configurations September 22, 2014
| Contract | TBD |
| Attachment | O |
(06/2016)
Memoranda
From To Subject Effective Date
Posted Date
| Associate | CIO | |
| for | IT | Security, |
Acting
Center Chief Information
| Officers | & |
| Associate | CIO |
| for | Enterprise |
Services
EMET Agent Installation 3/7/2016 3/7/2016
| Associate | CIO | |
| for | IT | Security, |
Acting
Chief Information Officers
| Recruitment | and | Retention | of | a |
| Highly | Qualified | Federal | Workforce |
11/05/2015 11/13/2015
| Associate | CIO | |
| for | IT | Security, |
Acting
Chief Information Officers
Cyber Hygiene Report Actions 11/05/2015 11/13/2015
| Associate | CIO | |
| for | IT | Security, |
Acting
Chief Information Officers & Enterprise Service Executives
Cyber Hygiene Report Actions 10/7/2015 10/7/2015
Associate Chief Information
| Officer | for |
| Capital | Planning |
| and | Governance |
Chief Information Officers
| Information | Technology | Security | |
| Division | Handbook | Expiration | Dates |
9/17/2015 9/17/2015
| Associate | IT |
| Security | Division |
| Director | (Acting) |
Chief Information Officers
Window Server 2003 Waiver Process
8/18/2015 8/19/2015
| Associate | IT |
| Security | Division |
| Director | (Acting) |
Chief Information Officers
| FY15 | IT | Security | and | Privacy |
| Awareness | Training | Reminder |
8/18/2015 8/19/2015
| Contract | TBD |
| Attachment | O |
(06/2016)
Memoranda
From To Subject Effective Date
Posted Date
Office of the Chief Information Security Officer
Senior Agency Information Security Officer
(SASIO)
| Request | the | Cancellation | of | HBK |
| 2810.03-02 | Planning: | Information | ||
| System | Security | Plan | Template, | |
| Requirements, | Guidance, | and |
Examples
7/27/2015 7/27/2015
(Acting) Senior Agency Information Security Officer
Center/Mission Directorate Chief Information Officer (CIO), Chief Information
| Security | Officers |
| (CISO), | and |
Information System Owners
(ISO)
| Vulnerabilities | in | Unsupported | or |
| End | of | Life | Software |
5/28/2015 5/28/2015
(Acting) Senior Agency Information Security Officer
Distribution Naming Pattern Memo 5/28/2015 5/28/2015
Office of the Chief Information Officer
(Acting) Senior Agency Information Security Officer
| Expired | Policy | 2810-02.05 | Security |
| Assessment | and | Authorization: | |
| External | Information | Systems |
11/19/2014 11/19/2014
Senior Agency Information Security Official (Acting)
| Distribution | Interim | Guidance | for | Leveraging |
| Cloud | Services | While | Meeting | |
| Information | Security | Requirements |
1/28/2015 1/28/2015
| Valerie | Burks | Center/Mission |
| Directorate | CIOs |
| Configuration | Guidance | for |
| Computer | Operating | Systems |
12/17/2012 12/17/2012
| Contract | TBD |
| Attachment | O |
(06/2016)
Memoranda
From To Subject Effective Date
Posted Date
(Acting) Senior Agency Information Security Officer
Office of the
CISO
Extension Verification 2810-02.05 11/19/2014 11/19/2014
| NASA | CIO | and |
| Deputy | CIO | for |
| IT | Security |
| Distribution | Updated | Password | Requirements |
| for | AA | Accounts |
7/2/2014 7/2/2014
Chief Information Officer
| Distribution | Establishment | and | Maintenance | of |
| Secure | Communications |
2/28/2014 2/28/2014
Deputy Chief Information Officer for Information Technology Security
| Distribution | Implementation | of | National |
| Institute | of | Standards | and |
| Technology | Special | Publication | 800- |
| 53, | Revision | 4 |
12/19/2013 12/19/2013
Chief Information Officer
| Distribution | Minimum | Security | Requirements |
| for | Personal | Mobile | Devices |
8/27/2013 8/27/2013
Chief Information Officer
| Distribution | Additional | 90-day | extension: | |||
| Blanket | waiver | for | use | of | Filevault | |
| 2.0 | to | meet | Data | at | Rest | (DAR) |
| Encryption | Requirements |
5/7/2013 5/7/2013
Office of the Chief Information Officer
| Distribution | Delegation | of | Authorizing | Official |
| Designation | to | Center | and | Mission |
| Directorate | Chief | Information |
Officers
4/2/2013 4/2/2013
| Contract | TBD |
| Attachment | O |
(06/2016)
Memoranda
From To Subject Effective Date
Posted Date
Deputy CIO for Information Security
| Distribution | NASA | ACES | Secure | Virtual | Team |
| Meeting | (SVTM) | Approved | for | ||
| Secure | Meetings | and | |||
| Communication | of | SBU | Data |
2/5/2013 2/5/2013
Chief Information Officer
| Distribution | Cancellation | of | PDM | 2012-064 | Data |
| At | Rest | (DAR) | Waiver | Process | and |
| issuance | of | a | new | PDM | addressing |
| Alternate | DAR | Encryption | Products |
1/27/2013 1/27/2013
Deputy CIO for Information Technology Security
Center Mission Directorate Chief Information Officers (CIO)
| Configuration | Guidance | for |
| Computer | Operating | Systems |
12/17/2012 12/17/2012
Associate Deputy Administrator
All NASA Employees
| Breach | of | Personally | Identifiable |
| Information | (PII) | [Laptop |
DAR/Encryption]
11/13/2012 11/13/2012
Chief Information Officer
All NASA Center CIO's
| Rescinding | and/or | Archiving |
| Information | Technology | (IT) |
| Security | Memoranda |
9/20/2012 9/20/2012
Deputy CIO for Information Security
All NASA Center CIOs
| FY2012 | FISMA | Awareness | and |
| Training | Reporting | Metrics |
9/12/2012 9/12/2012
| OCIO | Distribution | Acceptance | of | other | Federal | IT |
| Security | Awareness | Training | to | |||
| Satisfy | NASA's | |||||
| FISMA | Requirements |
5/25/2012 5/25/2012
| Charles | F. |
| Bolden, | Jr., |
NASA
Administrator
All NASA Employees
Protection of Sensitive Agency Information
4/3/2012 4/3/2012
| Contract | TBD |
| Attachment | O |
(06/2016)
Memoranda
From To Subject Effective Date
Posted Date
Assistant Administrator for Security and Program Protection, Chief Information Officer (Acting)
NASA Center Directors
| Identity, | Credential, | and | Access |
| Management | Business | Process |
Leads
8/27/2009 8/27/2009
Chief Information Officer (Acting)
Officials-in- Charge of Headquarters, Center CIOs, Mission Directorate CIOs
Security and Support Policy for Smartphones
8/3/2009 8/3/2009
Chief Information Officer (Acting)
| Center | CIOs | Delegation | of | Waiver | Authority | and |
| Responsibility | for | Vulnerability | ||||
| Scanning | Requirements |
5/6/2009 5/6/2009
Chief Information Officer (Acting)
Officials-in- Charge of Headquarters
| Offices, | NASA |
| Center | Directors |
| Roles | and | Responsibilities | for |
| Protecting | NASA | Sensitive | But |
| Unclassified | (SBU) | Information |
4/27/2009 4/27/2009
| Deputy | CIO | for |
| IT | Security |
| Center | CIOs, |
| Center | ITSMs |
| FY | 2009 | Scanning | and | Vulnerability |
| Elimination | or | Mitigation |
2/06/2009 2/06/2009
Chief Information Officer
Officials-in- Charge of Headquarters
| Offices, | NASA |
| Center | Directors |
| Personally | Identifiable | Information |
| (PII) | Incident | Reporting |
1/14/2009 1/14/2009
| Contract | TBD |
| Attachment | O |
(06/2016)
Memoranda
From To Subject Effective Date
Posted Date
Chief Information Officer
| All | NASA | Civil |
| Service | and |
Contractor Employees
| Policy | for | Use | of | Removable | Media, |
| Such | as | USB | Thumb | Drives |
11/21/2008 11/21/2008
Senior Agency Official for Privacy
Official-in- Charge of Headquarters Offices, NASA Center Directors
Personally Identifiable Information (PII) Responsibilities Statement
9/8/2008 9/8/2008
Chief Information Officer
Center CIOs Deployment of the Software Refresh Portal
7/30/2008 7/30/2008
Chief Information Officer
NASA CIOs, Mission Directorate CIOs, Center ITSMs, Center Human Resources Directors, IEMP
Requirement to Log and Verify Sensitive Data Extracts
6/9/2008 6/9/2008
Chief Information Officer
NASA CIOs, Mission Directorate CIOs, Center ITSMs, Center ITSMs, Center Human Resources Directors, IEMP
Remote Access to Personally Identifiable Information (PII)
6/9/2008 6/9/2008
Deputy CIO for IT Security
Center ITSMs Clarification on Requirement for Contractors to Complete NASA Annual IT Security Awareness Training
6/6/2008 6/6/2008
| Contract | TBD |
| Attachment | O |
(06/2016)
Memoranda
From To Subject Effective Date
Posted Date
Deputy CIO for IT Security
Center CIOs, Center ITSMs
System Security Documentation in RMS
2/20/2008 2/20/2008
Chief Information Officer
Center CIOs, Deputy CIOs
Information Discovery 2/4/2008 2/4/2008
Deputy CIO for IT Security
Center CIOs, Center ITSMs
Decision to Cancel Procurement Information Circular (PIC) 04-03 (System Administrator Certification Program)
1/16/2008 1/16/2008
Chief Information Officer
Official-in- Charge of Headquarters Offices, NASA Center Directors
Release of NPD 2200.1A, Management of NASA Scientific and Technical Information
12/18/2007 12/18/2007
Deputy CIO for IT Security
Center CIOs, Mission Directorate CIOs
Agency Security Configuration Standards: Federal Desktop Core Configurations
11/15/2007 11/15/2007
Chief Information Officer
Center Chief Information Officers
Designation of FIPS-199 Impact Level for NASA's OAIT Voice Systems
7/10/2007 7/10/2007
Chief Information Officer
Center Chief Information Officers
Designation of FIPS-199 Impact Level for NASA OAIT Data Center Systems
7/10/2007 7/10/2007
Chief Information Officer
Center Chief Information Officers
Designation of FIPS-199 Impact Level for NASA OAIT LANs
7/10/2007 7/10/2007
| Contract | TBD |
| Attachment | O |
(06/2016)
Memoranda
From To Subject Effective Date
Posted Date
Chief Information Officer (Acting)
Center CIOs, Mission Directorate CIOs
Meeting OMB Memoranda M- 06-015 "Safeguarding Personally Identifiable Information;" M-06-016 "Protection of Sensitive Agency Information," and M-06-019 "Reporting Incidents Involving Personally Identifiable Information and Incorporating the Cost for Security in Agency Information Technology Investments"
10/17/2006 10/17/2006
Deputy Administrator
Administrator/Of ficial-in-Charge of Headquarters Offices, NASA Center Directors
Meeting NASA Information Technology Security Requirements
7/26/2006 7/26/2006
Deputy CIO for IT Security
Center CIOs Designation of FIPS-199 Impact Level for NASA OAIT Desktop Systems
4/16/06 4/16/06
Chief Information Officer, Chief of Strategic Communications
Official-in- Charge of Headquarters Offices, NASA Center Directors, Center CIOs, Mission Directorate CIOs
Policy Governing NASA's Publicly Accessible Web sites
3/16/2006 3/16/2006
Chief Information Officer, Assistant Administrator of Public Affairs
Center CIOs Update of NASA Web site Linking Policy
12/15/2005 12/15/2005
| Contract | TBD |
| Attachment | O |
(06/2016)
Memoranda
From To Subject Effective Date
Posted Date
Chief Information Officer
Center CIOs Update of NASA Web site Privacy Policy
11/28/2005 11/28/2005
Reminder: Within 30 days after contract effective date, the Contractor shall develop and deliver an IT Security Management Plan to the Contracting Officer for approval.
File details come from the government source that posted it. Updated .