JOIST-DRD-06-Information_Technolgy_(IT)_Security_Managment_Plan_and_Reports.docx

DOCX document 37 KB Posted

Attached to
Joint Operations and Integrated Systems Technology (JOIST) Federal contract opportunity
Solicitation number
NNJ17580323R
Issued by
National Aeronautics and Space Administration Johnson Space Center

About this file

Attachment J-02 DRD-06

View the file

Other files for this federal contract opportunity

Other files attached to Joint Operations and Integrated Systems Technology (JOIST), newest first.
File Type Posted
FRFP_Questions_Round_1.pdf PDF
Attachment_L-07_CF_EPM_Template_Am_1.xlsx XLSX spreadsheet
Section_M_Am_1.docx DOCX document
JOIST-DRD-04_Small_Business_Subcontracting_Plan_and_Reports_Am_1.docx DOCX document
Attachment_L-03_-_Strategic_Projects_TO_Am_1.docx DOCX document
Attachment_L-01_Standard_Labor_Categories.docx DOCX document
JOIST-DRD-02_Total_Compensation_Plan.docx DOCX document
JOIST-DRD-18_Montly_Performance_Report_FFP_IDIQ.docx DOCX document
Section_A.docx DOCX document
Attachment_L-03_-_Strategic_Projects_TO.docx DOCX document
Section_F.docx DOCX document
Section_L.docx DOCX document
Attachment_J-04A_-_GFCS_-_Baseline_A.pdf PDF
Attachment_J-14_-_Government_Property_Management_Plan.docx DOCX document
Attachment_J-07_-_List_of_Applicable_Documents.docx DOCX document
JOIST-DRD-07-Government_Property_Management_Plan_(PMP).docx DOCX document
Attachment_L-07_IDIQ_EPM_Template.xlsx XLSX spreadsheet
JOIST-DRD-14-Equipment_Replacement_(ER)_Plan.docx DOCX document
Attachment_J-17_-_WBS.docx DOCX document
Section_C.docx DOCX document
Document_Change_Log_(DRFP_to_FRFP).pdf PDF
JOIST-DRD-11-Reports_Required_for_Logistics.docx DOCX document
Attachment_L-07_CF_EPM_Template.xlsx XLSX spreadsheet
Attachment_L-09_SF1408.pdf PDF
Attachment_J-03_Standard_Labor_Categories.docx DOCX document
JOIST-DRD-05_Contractor_Organizational_Conflict_of_Interest_(OCI)_Mitigation_Plan.docx DOCX document
Attachment_L-04_Past_Performance_Questionnaire.docx DOCX document
JOIST-DRD-16-Reprocurement_Data_Package.docx DOCX document
JOIST-DRD-17A-Montly_Cost_Reporting_(NF533_and_Supplemental_Requirements)_-_Baseline_A.docx DOCX document
Attachment_J-05_List_of_Government_Property.docx DOCX document
Attachment_J-10_-_Management_and_Staffing_Plan.docx DOCX document
JOIST-DRD-10A-WBS_(Baseline_A).docx DOCX document
Attachment_L-08_Small_Business_Subcontracting_Tables.docx DOCX document
Attachment_L-06_Past_Performance_Consent_Letter.docx DOCX document
Attachment_J-16_-_DRCOP.docx DOCX document
JOIST-DRD-13-Information_Technology_(IT)_Capital_Planning_and_Investment_Control_(CPIC).docx DOCX document
JOIST-DRD-03_Management_and_Staffing_Plan.docx DOCX document
Section_E.docx DOCX document
Attachment_J-08_-_Contract_Phase-In_Plan.docx DOCX document
JOIST-DRD-17B-Montly_Cost_Reporting_(NF533_and_Supplemental_Requirements)_-_Baseline_B.docx DOCX document
Attachment_L-05_Relevant_Past_Performance.xlsx XLSX spreadsheet
Section_H.docx DOCX document
Attachment_J-11_-_Small_Business_Subcontracting_Plan.docx DOCX document
JOIST-DRD-01_Contract_Phase-In_Plan.docx DOCX document
Attachment_J-05A_-_IAGP_-_Baseline_A.pdf PDF
JOIST-DRD-04_Small_Business_Subcontracting_Plan_and_Reports.docx DOCX document
SF33.pdf PDF
Section_K.docx DOCX document
JOIST-DRD-15-Status_Reports_and_Reviews.docx DOCX document
DRFP_Questions_Round_1.pdf PDF
Show all 50

Joint Operations and Integrated Systems Technology (JOIST) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

JSC DATA REQUIREMENTS DESCRIPTION (DRD)

(Based on JSC –STD-123. See work page for instructions.)

1. DRD Title
2. Date of current version
3. DRL Line Item No.
RFP / Contract No.
Contractor Information Technology (IT) Security Management Plan and Reports
10/26/2016
06
NNJ17580323R

5. Use (Define need for, intended use of, and/or anticipated results of data)

6. DRD Category: (check one)

To ensure that IT security reporting requirements are met for all IT systems utilized during work associated with this contract.
☒Technical

☐Administrative

☐S&MA

6. References

7. Interrelationships (e.g., with other DRDs) (Optional)

1. NFS 1852.204-76: Security Requirements for Unclassified IT Resources

1. NPD 2810.1E: NASA Information Security Policy

1. NPR 2810.1A: Security of Information Technology

1. OMB Circular A-130: Management of Federal Information Resources

8. PREPARATION INFORMATION:

The Contractor shall prepare the data delivery as follows:

8a. DATA TYPE:

☒ Type 1 – Written approval ☐Type 2 – Mandatory Submittal ☐Type 3 – Submittal Upon Request

8b. SCOPE:

All contracts that purchase, lease, network to, or otherwise utilize Government-funded IT (as defined by the Clinger-Cohen Act of 1996 and referenced by OMB Circular A-130) must comply with NASA IT Security Requirements.

8c. CONTENT:

IT SECURITY MANAGEMENT PROGRAM PLAN:

The Contractor shall submit an IT Security Management Program Plan for its unclassified technology information resources. This program plan shall describe the policy, processes, and procedures that will be followed to ensure appropriate security of IT resources that are developed, processed, or used under this contact. The Contractor’s IT Security Management Program Plan shall be compliant with the IT security requirements in accordance with Federal and NASA policies as referenced in OMB Circular A-130 and NPR 2810.1.

INFORMATION SYSTEMS SECURITY OFFICER (ISSO):

The Contractor shall have Information Systems Security Officer (ISSO) who is responsible for the Contractor’s system(s) in accordance with the definitions set forth in NPR 2810.1.

IT SECURITY PLAN:

The IT security plan shall be kept up to date as changes to the baseline configuration of the system occur and shall be documented in the IT Security Plan. Note: An IT Security Plan is specific to a system or group of systems, while an IT Security Management Program Plan is defined as the elements a Contractor has outlined to meet the IT Security requirements for interfacing with other Contractors and NASA, training requirements, and meeting the requirements in NPR 2810.1(series). Where authorized by the Government, Government-approved resources may be leveraged in the production of the IT Security plan; however, the Contractor remains fully accountable for its IT Security plan contents. At the Government’s direction, the Contractor’s IT Security plan content may be used to produce a stand-alone IT Security plan, or may be integrated into a consolidated IT Security plan.

IT SECURITY AWARENESS TRAINING:

Employees subject to this contract shall complete the NASA approved IT Security Awareness Training annually. The Contractor shall provide evidence that periodic IT security awareness training has been met for all employees subject on this contract. The Contractor shall submit periodic reports (as required by the CO) detailing the overall status of the annual training program. The annual training program is defined as the period from October 1st through September 30th.

IT SECURITY ROLE-BASED TRAINING:

Employees subject to this contract shall complete NASA-approved IT Security Training annually related to the following Role Based functions:

· IT Systems Security Manager (ISSM)

· Information System Owner (ISO)

· Information Systems Security Officer (ISSO)

· Organizational Computer Security Official – Representative (OCSO-R)

The Contractor shall provide evidence that periodic IT security training has been met for all employees subject on this contract. The Contractor shall submit periodic reports (as required by the CO) detailing the overall status of the annual training program. The annual training program is defined as the period from October 1st through September 30th.

INFORMATION ON EMPLOYEES IN SENSITIVE POSITIONS/ASSIGNMENTS REPORT:

The Information on Employees is Sensitive. IT Security Positions/Assignments Report shall provide information annually for personnel screening as required by NPR 2810.1, and NPR 1600.1 on position risk.

IT POINT OF CONTACT:

The Contractor shall identify a point of contact that NASA may reach in its attempt to address IT and IT Security issues. The point of contact shall have the authority to ensure appropriate actions occur.

8d. FORMAT:

The product shall be in a Microsoft Office compatible format or Government-directed formats compatible with Government IT Security compliance tracking and reporting system(s).

8e. DISTRIBUTION:

Distribution shall be in accordance with Attachment J-01, Data Requirements List (DRL).

8f. SUBMISSION:

Submission shall be in accordance with Attachment J-01, Data Requirements List (DRL).

Revisions are subject to Contracting Officer approval

JSC Form 2341 (Rev October 19, 2011) (MS Word 2007) (Previous editions are obsolete.)

NNJ17580323R Attachment J-02 – DRD-06-1

File details come from the government source that posted it. Updated .