JOIST-DRD-06-Information_Technolgy_(IT)_Security_Managment_Plan_and_Reports.docx
DOCX document 37 KB Posted
- Attached to
- Joint Operations and Integrated Systems Technology (JOIST) Federal contract opportunity
- Solicitation number
- NNJ17580323R
About this file
Attachment J-02 DRD-06
View the file
Other files for this federal contract opportunity
Show all 50
Joint Operations and Integrated Systems Technology (JOIST) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
JSC DATA REQUIREMENTS DESCRIPTION (DRD)
(Based on JSC –STD-123. See work page for instructions.)
| 1. DRD Title |
| 2. Date of current version |
| 3. DRL Line Item No. |
| RFP / Contract No. |
| Contractor Information Technology (IT) Security Management Plan and Reports |
| 10/26/2016 |
| 06 |
| NNJ17580323R |
5. Use (Define need for, intended use of, and/or anticipated results of data)
6. DRD Category: (check one)
| To ensure that IT security reporting requirements are met for all IT systems utilized during work associated with this contract. |
| ☒Technical |
☐Administrative
☐S&MA
6. References
7. Interrelationships (e.g., with other DRDs) (Optional)
1. NFS 1852.204-76: Security Requirements for Unclassified IT Resources
1. NPD 2810.1E: NASA Information Security Policy
1. NPR 2810.1A: Security of Information Technology
1. OMB Circular A-130: Management of Federal Information Resources
8. PREPARATION INFORMATION:
The Contractor shall prepare the data delivery as follows:
8a. DATA TYPE:
☒ Type 1 – Written approval ☐Type 2 – Mandatory Submittal ☐Type 3 – Submittal Upon Request
8b. SCOPE:
All contracts that purchase, lease, network to, or otherwise utilize Government-funded IT (as defined by the Clinger-Cohen Act of 1996 and referenced by OMB Circular A-130) must comply with NASA IT Security Requirements.
8c. CONTENT:
IT SECURITY MANAGEMENT PROGRAM PLAN:
The Contractor shall submit an IT Security Management Program Plan for its unclassified technology information resources. This program plan shall describe the policy, processes, and procedures that will be followed to ensure appropriate security of IT resources that are developed, processed, or used under this contact. The Contractor’s IT Security Management Program Plan shall be compliant with the IT security requirements in accordance with Federal and NASA policies as referenced in OMB Circular A-130 and NPR 2810.1.
INFORMATION SYSTEMS SECURITY OFFICER (ISSO):
The Contractor shall have Information Systems Security Officer (ISSO) who is responsible for the Contractor’s system(s) in accordance with the definitions set forth in NPR 2810.1.
IT SECURITY PLAN:
The IT security plan shall be kept up to date as changes to the baseline configuration of the system occur and shall be documented in the IT Security Plan. Note: An IT Security Plan is specific to a system or group of systems, while an IT Security Management Program Plan is defined as the elements a Contractor has outlined to meet the IT Security requirements for interfacing with other Contractors and NASA, training requirements, and meeting the requirements in NPR 2810.1(series). Where authorized by the Government, Government-approved resources may be leveraged in the production of the IT Security plan; however, the Contractor remains fully accountable for its IT Security plan contents. At the Government’s direction, the Contractor’s IT Security plan content may be used to produce a stand-alone IT Security plan, or may be integrated into a consolidated IT Security plan.
IT SECURITY AWARENESS TRAINING:
Employees subject to this contract shall complete the NASA approved IT Security Awareness Training annually. The Contractor shall provide evidence that periodic IT security awareness training has been met for all employees subject on this contract. The Contractor shall submit periodic reports (as required by the CO) detailing the overall status of the annual training program. The annual training program is defined as the period from October 1st through September 30th.
IT SECURITY ROLE-BASED TRAINING:
Employees subject to this contract shall complete NASA-approved IT Security Training annually related to the following Role Based functions:
· IT Systems Security Manager (ISSM)
· Information System Owner (ISO)
· Information Systems Security Officer (ISSO)
· Organizational Computer Security Official – Representative (OCSO-R)
The Contractor shall provide evidence that periodic IT security training has been met for all employees subject on this contract. The Contractor shall submit periodic reports (as required by the CO) detailing the overall status of the annual training program. The annual training program is defined as the period from October 1st through September 30th.
INFORMATION ON EMPLOYEES IN SENSITIVE POSITIONS/ASSIGNMENTS REPORT:
The Information on Employees is Sensitive. IT Security Positions/Assignments Report shall provide information annually for personnel screening as required by NPR 2810.1, and NPR 1600.1 on position risk.
IT POINT OF CONTACT:
The Contractor shall identify a point of contact that NASA may reach in its attempt to address IT and IT Security issues. The point of contact shall have the authority to ensure appropriate actions occur.
8d. FORMAT:
The product shall be in a Microsoft Office compatible format or Government-directed formats compatible with Government IT Security compliance tracking and reporting system(s).
8e. DISTRIBUTION:
Distribution shall be in accordance with Attachment J-01, Data Requirements List (DRL).
8f. SUBMISSION:
Submission shall be in accordance with Attachment J-01, Data Requirements List (DRL).
Revisions are subject to Contracting Officer approval
JSC Form 2341 (Rev October 19, 2011) (MS Word 2007) (Previous editions are obsolete.)
NNJ17580323R Attachment J-02 – DRD-06-1
File details come from the government source that posted it. Updated .