TEAMS3_Software_Info.pdf
PDF 1 MB Posted
- Attached to
- Technology, Engineering, and Aerospace Mission Support 3 (TEAMS 3) Federal contract opportunity
- Solicitation number
- NNL17ZB1001R
About this file
TEAMS 3 Software Information
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| NNL17ZB1001R_Amendment_000002.pdf | ||
| NNL17ZB1001R_Amendment_000001.pdf | ||
| TEAMS3_Final_RFP_QA_dtd_12_19_16.pdf | ||
| TEAMS3_Other_TDNs.pdf | ||
| TEAMS3_Final_RFP.pdf | ||
| TEAMS3_NESC_TDNs.pdf | ||
| TEAMS3_Track_Changes_DRFP_Docs.pdf | ||
| TEAMS3_DRFP_QA_Revised_Answers.doc | DOC document | |
| TEAMS3_DRFP_QA_Second(Final)Set_Final.doc | DOC document | |
| SACD_Overview_Transition_2016.pdf | ||
| TEAMS3_DRFP_QA_FirstSet.doc | DOC document | |
| TEAMS3_Amendment2_DRFP.pdf | ||
| TEAMS3_DRFP.pdf | ||
| TEAMS3_Other_TDNs.pdf | ||
| TEAMS3_NESC_TDNs.pdf | ||
| TEAMS3_Software_Info.pdf |
Show all 16
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
For the best experience, open this PDF portfolio in
Acrobat X or Adobe Reader X, or later.
Get Adobe Reader Now!
http://www.adobe.com/go/reader
Notes
Contents (tabs) of this Workbook
Notes Notes regarding this workbook
MasterNPR Requirements in original NPR order (except SWE-041 moved adjacent to similar requirements)
MasterK Requirements grouped by Project and Contractor
Class ABCDE Compliance matrix for software classes A-E. By hiding or deleting rows/columns, compliance for multiple software classes can be shown.
Class A Compliance matrix for software class A
Class B Compliance matrix for software class B
Class C Compliance matrix for software class C
Class D Compliance matrix for software class D
Class E Compliance matrix for software class E
General
1 On all sheets (tabs) except "MasterK", the Contractor requirements are restated in "Contractor shall" form. In a few cases where the responsibility is "Project and Contractor," the requirements are unchanged.
2 On the "MasterK" sheet, "Project" and "Contractor" requirements are grouped. Requirements in the groups can be hidden or displayed. Where responsibility is "Project and Contractor," the requirements are duplicated in each group. Requirements in the "Contractor" group are restated in "Contractor shall" form, whereas requirements in the "Project" group are unchanged.
MasterNPR
<-- Click on the plus or minus sign to display or hide the NPR7150.2B requirements matrix help information
The rationale for the requirements is contained in the NASA Software Engineering Handbook, NASA-HDBK-2203. Programs/Projects may substitute a matrix that documents their compliance with their particular Center's implementation of NPR 7150.2, if applicable. See NASA-HDBK-2203 for compliance matrices organized by class & safety-criticality, tailoring field for each requirement, tailoring rationale, and approval signature lines. The Compliance Matrix documents the program/project's compliance or intent to comply with the requirements of this NPR or justification for tailoring. The rationale for the requirements is contained in the NASA Software Engineering Handbook, NASA-HDBK-2203. Programs/Projects may substitute a matrix that documents their compliance with their particular Center's implementation of NPR 7150.2, if applicable. See NASA-HDBK-2203 for compliance matrices organized by class & safety-criticality, tailoring field for each requirement, tailoring rationale, and approval signature lines. The Compliance Matrix documents the program/project's compliance or intent to comply with the requirements of this NPR or justification for tailoring.
Tailoring Guidance Tailoring Guidance
X - Indicates an invoked requirement by this NPR consistent with Software Classification (ref. SWE-139). May be tailored with Technical Authority approval (ref. Chapter 2.2). X - Indicates an invoked requirement by this NPR consistent with Software Classification (ref. SWE-139). May be tailored with Technical Authority approval (ref. Chapter 2.2).
Blank - Optional / Not invoked by this NPR for this Software Classification. Blank - Optional / Not invoked by this NPR for this Software Classification.
X *(SC only) - Project is required to meet the requirement to the extent necessary to satisfy safety critical aspects of the software.
X (not OTS) - Does not apply to Off the Shelf (OTS), Commercial Software. X (not OTS) - Does not apply to Off the Shelf (OTS), Commercial Software.
Center Director - Center Director or the Center Director’s designated Engineering Technical Authority or Center Director's designated Safety and Mission Assurance Technical Authority. Center Director - Center Director or the Center Director’s designated Engineering Technical Authority or Center Director's designated Safety and Mission Assurance Technical Authority.
Note 1 - All Safety-critical software has to be classified as Class D or Higher. Note 1 - All Safety-critical software has to be classified as Class D or Higher.
Note 2 - Applies to Class B software except for Class B software on NASA Class D payloads, as defined in NPR 8705.4. For Class B software, in lieu of a CMMI rating by a development organization, the project will conduct an evaluation, performed by a qualified evaluator selected by the Center Engineering Technical Authority, of the seven process areas listed in SWE-032 and mitigate any risk, if deficient. This exception is intended to be used in those cases in which NASA wishes to purchase a product from the "best of class provider," but the best of class provider does not have the required CMMI rating. When this exception is exercised, the Center Engineering Technical Authority should be notified. Note 2 - Applies to Class B software except for Class B software on NASA Class D payloads, as defined in NPR 8705.4. For Class B software, in lieu of a CMMI rating by a development organization, the project will conduct an evaluation, performed by a qualified evaluator selected by the Center Engineering Technical Authority, of the seven process areas listed in SWE-032 and mitigate any risk, if deficient. This exception is intended to be used in those cases in which NASA wishes to purchase a product from the "best of class provider," but the best of class provider does not have the required CMMI rating. When this exception is exercised, the Center Engineering Technical Authority should be notified.
Note 3 - For tailoring of NASA-STD-8739.8 and NASA-STD-8719.13, the Software Assurance Standard and the Software Safety Standard respectively, use the tailoring provided within those documents. They are both risk based and SW Class based tailoring. Note 3 - For tailoring of NASA-STD-8739.8 and NASA-STD-8719.13, the Software Assurance Standard and the Software Safety Standard respectively, use the tailoring provided within those documents. They are both risk based and SW Class based tailoring.
| Note 4 - The Technical Authority implementation responsibilities for Class F software is at the NASA Headquarters Chief Information Officer (CIO) level , the Technical Authority implementation responsibilities for Class G and H is at the Center CIO organization level or at the level defined in the Center Technical Authority implementation plan. All Safety-critical software has to be classified as Class D or higher. | |
| Note 4 - The Technical Authority implementation responsibilities for Class F software is at the NASA Headquarters Chief Information Officer (CIO) level , the Technical Authority implementation responsibilities for Class G and H is at the Center CIO organization level or at the level defined in the Center Technical Authority implementation plan. All Safety-critical software has to be classified as Class D or higher. |
| Section | NPR SWE # | Requirement Text | Technical Authority | Responsibility | A | B | C | D | E | Technical Authority | F | ||
| (Note 4) | Technical Authority | G | |||||||||||
| (Note 4) | H |
(Note 4)
2.2.4 121 Where approved, the project manager shall document and reflect the tailored requirement in the plans or procedures controlling the development, acquisition, and/or deployment of the affected software. Center Level Project X X X X HQ OCIO X Center CIO X X
2.2.5 125 Each project manager with software components shall maintain a compliance matrix or multiple compliance matrices against requirements in this NPR, including those delegated to other parties or accomplished by contract vehicles or Space Act Agreements. Center Level Project X X X X X HQ OCIO X Center CIO X X
2.2.6 139 The projects shall comply with the requirements in this NPR that are marked with a “project” responsibility and an ”X” in Appendix D consistent with their software classification. Center Level Project X X X X X HQ OCIO X Center CIO X X
2.2.10 145 When the compliance matrix is used to waive/deviate from applicable “X” requirement(s), the designated Technical Authorities shall indicate their approval by signature(s) in the compliance matrix itself. Center Level Project X X X X X HQ OCIO X Center CIO X X
3.1.2 13 The Contractor shall develop, maintain, and execute software plans that cover the entire software life cycle and, as a minimum, address the requirements of this directive with approved tailoring. Center Level Contractor X X X X X HQ OCIO X Center CIO X
3.1.3 24 The Contractor shall track the actual results and performance of software activities against the software plans. Center Level Contractor X X X X HQ OCIO X Center CIO X
3.2.1 15 The project manager shall establish, document, and maintain two cost estimates and associated cost parameters for all software Class A and B projects that have an estimated project cost of $2 million or more
-OR -
one software cost estimate and associated cost parameter(s) for other software projects. Center Level Project and Contractor X X X X HQ OCIO Center CIO
3.2.2 151 The software cost estimate(s) shall satisfy the following conditions:
a. Covers the entire software life cycle.
b. Is based on selected project attributes (e.g., assessment of the size, functionality, complexity, criticality, reuse code, modified code, and risk of the software processes and products).
c. Is based on the cost implications of the technology to be used and the required maturation of that technology.
d. Incorporates risk and uncertainty.
e. Includes the cost for software assurance support.
f. Includes other direct costs. Center Level Project and Contractor X X X X HQ OCIO Center CIO
3.3.1 16 The Contractor shall document and maintain a software schedule that satisfies the following conditions:
a. Coordinates with the overall project schedule.
b. Documents the interactions of milestones and deliverables between software, hardware, operations, and the rest of the system.
c. Reflects the critical path for the software development activities.
d. Adhere to the guidance provided in NASA/SP-2010-3403, NASA Scheduling Management Handbook. Center Level Contractor X X X X HQ OCIO X Center CIO X
3.3.2 18 The Contractor shall regularly hold reviews of software activities, status, and results with the project stakeholders and track issues to resolution. Center Level Contractor X X X X HQ OCIO X Center CIO X
3.3.3 19 TheContractor shall select and document a software development life cycle or model that includes phase transition criteria for each life cycle phase. Center Level Contractor X X X X HQ OCIO X (not OTS) Center CIO X (not OTS)
| 3.4.1 | 17 | The Contractor shall plan, track, and ensure project specific software training for project personnel. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X | Center CIO | X |
3.5.1 20 The project manager shall classify each system and subsystem containing software in accordance with the highest applicable software classification definitions for Classes A, B, C, D, E, F, G, and H software in Appendix D. Center Level Project X X X X X HQ OCIO X Center CIO X X
3.5.2 132 The project’s software assurance manager shall perform an independent classification assessment. Center Level Project X X X X X HQ OCIO X Center CIO X X
3.5.3 133 The project manager, in conjunction with the Safety and Mission Assurance organization, shall determine the software safety criticality in accordance with NASA-STD-8719.13. Project and Center SMA Project and Center S&MA X X X X X HQ OCIO X Center CIO X X
3.5.4 21 If a system or subsystem evolves to a higher or lower software classification as defined in Appendix D, or there is a change in the safety criticality of the software, then the project manager shall update the plan to fulfill the applicable requirements per the Requirements Mapping and Compliance Matrix in Appendix C and any approved tailoring. Center Level Project X X X X X HQ OCIO X Center CIO X X
| 3.5.5 | 160 | If a software component is determined to be safety critical software then software component classification shall be Software Class D or higher. | Center Level | Project | X | X | X | X | X | |
| (Note 1) | HQ OCIO | X | Center CIO | X | X |
| 3.6.1 | 22 | The project manager shall plan and implement software assurance per NASA-STD-8739.8. | Center Level | Project, Contractor and Center S&MA | ||||
| (Note 3) | X | X | X | X | HQ OCIO | Center CIO |
3.6.2 141 For projects reaching KDP A after the effective date of this directive’s revision, the program manager shall ensure that software IV&V is performed on the following categories of projects:
a. Category 1 projects as defined in NPR 7120.5.
b. Category 2 projects as defined in NPR 7120.5 that have Class A or Class B payload risk classification per NPR 8705.4.
c. Projects specifically selected by the NASA Chief, Safety and Mission Assurance (SMA) to have software IV&V. HQ OCE and HQ OSMA Project and Center S&MA Per selection criteria defined in the SWE-141 requirement HQ OCIO Center CIO
3.6.3 131 If software IV&V is performed on a project, project manager shall ensure that an IV&V Project Execution Plan (IPEP) is developed. Center and the Center SMA organization Project and Center S&MA X X X HQ OCIO X Center CIO X
| 3.7.1 | 23 | When a project is determined to have safety-critical software, the project manager shall implement the requirements of NASA-STD-8719.13. | Center Level | Project, Contractor and Center S&MA | ||
| (Note 3) | X | X | X | |||
| *(SC only) | X | |||||
| *(SC only) | HQ OCIO | Center CIO |
3.7.2 134 When a project is determined to have safety-critical software, the Contractor shall implement the following items in the software:
a. Safety-critical software is initialized, at first start and at restarts, to a known safe state.
b. Safety-critical software safely transitions between all predefined known states.
c. Termination performed by software of safety critical functions is performed to a known safe state.
d. Operator overrides of safety-critical software functions require at least two independent actions by an operator.
e. Safety-critical software rejects commands received out of sequence, when execution of those commands out of sequence can cause a hazard.
f. Safety-critical software detects inadvertent memory modification and recovers to a known safe state.
g. Safety-critical software performs integrity checks on inputs and outputs to/from the software system.
h. Safety-critical software performs prerequisite checks prior to the execution of safety-critical software commands.
i. No single software event or action is allowed to initiate an identified hazard. Center and the Center SMA organization Contractor
3.7.2 134 (continued)
j. Safety-critical software responds to an off nominal condition within the time needed to prevent a hazardous event.
k. Software provides error handling of safety-critical functions.
l. Safety-critical software has the capability to place the system into a safe state.
m. Safety-critical elements (requirements, design elements, code components, and interfaces) are uniquely identified as safety-critical.
n. Requirements are incorporated in the coding methods, standards, and/or criteria to clearly identify safety-critical code and data within source code comments.
| Center and the Center SMA organization | Contractor | X | X | X | ||
| *(SC only) | X | |||||
| *(SC only) | HQ OCIO | Center CIO |
3.8.1 146 The project manager shall define the approach to the automatic generation of software source code including:
a. Validation and verification of auto-generation tools.
b. Configuration management of the auto-generation tools and associated data.
c. Identification of the allowable scope for the use of auto-generated software.
d. Verification and validation of auto-generated source code.
e. Monitoring the actual use of auto-generated source code compared to the planned use.
f. Policies and procedures for making manual changes to auto-generated source code.
| g. Configuration management of the input to the auto-generation tool, the output of the auto-generation tool, and modifications made to the output of the auto-generation tools. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X | Center CIO | X |
3.9.2 27 The Contractor shall satisfy the following conditions when a COTS, GOTS, MOTS, or reused software component is acquired or used:
a. The requirements to be met by the software component are identified.
b. The software component includes documentation to fulfill its intended purpose (e.g., usage instructions).
c. Proprietary rights, usage rights, ownership, warranty, licensing rights, and transfer rights have been addressed.
d. Future support for the software product is planned and adequate for project needs.
e. The software component is verified and validated to the same level required to accept a similar developed software component for its intended use.
| f. The project has a plan to perform periodic assessments of vendor reported defects to ensure the defects do not impact the selected software components. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X | Center CIO | X |
3.10.2 28 The Contractor shall plan software verification activities, methods, environments, and criteria for the project. Center Level Contractor X X X X HQ OCIO X Center CIO X
3.10.3 29 The Contractor shall plan the software validation activities, methods, environments, and criteria for the project. Center Level Contractor X X X X HQ OCIO X Center CIO X
3.10.4 30 The Contractor shall record, address, and track to closure the results of software verification activities. Center Level Contractor X X X X HQ OCIO X Center CIO X
3.10.5 31 The Contractor shall record, address, and track to closure the results of software validation activities. Center Level Contractor X X X X HQ OCIO X Center CIO X
3.11.3 32 The project manager shall acquire, develop, and maintain software from an organization with a non-expired Capability Maturity Model® Integration for Development (CMMI-DEV) rating as measured by a CMMI Institute authorized or certified lead appraiser as follows:
a. For Class A software: CMMI-DEV Maturity Level 3 Rating or higher for software, or CMMI-DEV Capability Level 3 Rating or higher in all CMMI-DEV Maturity Level 2 and 3 process areas for software.
b. For Class B software on NASA payloads with risk classifications A, B, and C, as defined in NPR 8705.4: CMMI-DEV Maturity Level 2 Rating or higher for software, or CMMI-DEV Capability Level 2 Rating or higher for software in the following process areas:
(1) Requirements Management.
(2) Configuration Management.
(3) Process and Product Quality Assurance.
(4) Measurement and Analysis.
(5) Project Planning.
(6) Project Monitoring and Control.
(7) Supplier Agreement Management (if applicable). HQ OCE and HQ OSMA Project X X (Note 2) HQ OCIO Center CIO
3.12.2 33 The project manager shall assess options for software acquisition versus development. Center Level Project X X X X HQ OCIO X Center CIO X
3.12.3 34 The project manager shall define and document the acceptance criteria and conditions for the software. Center Level Project X X X X HQ OCIO X Center CIO X
| 3.12.4 | 35 | The project manager shall establish a procedure for software supplier selection, including proposal evaluation criteria. | Center Level | Project | X | X | X | X | |
| *(SC only) | HQ OCIO | X | Center CIO |
3.12.5 36 The project manager shall determine which software processes, software documents, electronic products, software activities, and tasks are required for the project and software suppliers. Center Level Project X X X X HQ OCIO X (not OTS) Center CIO X (not OTS)
3.12.6 37 The project manager shall define the milestones at which the software supplier(s) progress will be reviewed and audited as a part of the acquisition activities. Center Level Project X X X X HQ OCIO X (not OTS) Center CIO X (not OTS)
3.12.7 38 The project manager shall document software acquisition planning decisions. Center Level Project X X X X HQ OCIO X (not OTS) Center CIO X (not OTS)
| 3.15.3 | 41 | The (prospective) Contractor(s) shall notify the project, in the response to the solicitation, as to whether or not open source software will be included in code developed for the project. | Center Level | (Prospective) Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X | Center CIO | X |
3.12.8 39 The Contractor shall provide insight into software development and test activities; at a minimum, the Contractor shall to allow the project manager designate to:
a. Monitor product integration.
b. Review the verification activities to ensure adequacy.
c. Review trades studies and source data.
d. Audit the software development process.
e. Participate in software reviews and systems and software technical interchange meetings. Center Level Contractor X X X X HQ OCIO X (not OTS) Center CIO X (not OTS)
| 3.12.9 | 40 | The Contractor shall provide NASA with software products and software process tracking information, in electronic format, including software development and management metrics. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X (not OTS) | Center CIO | X (not OTS) |
| 3.12.10 | 42 | The Contractor shall provide NASA with electronic access to the source code developed for the project in a modifiable format, including MOTS software and non-flight software (e.g., ground test software, simulations, ground analysis software, ground control software, science data processing software, and hardware manufacturing software). | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X (not OTS) | Center CIO | X (not OTS) |
| 3.13.1 | 43 | The Contractor shall track software changes and non-conformances and provide the data for the project's review. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X (not OTS) | Center CIO | X (not OTS) |
| 3.13.2 | 45 | The project manager shall participate in any joint NASA/supplier audits of the software development process and software configuration management process. | Center Level | Project | X | X | X | X | |
| *(SC only) | HQ OCIO | X (not OTS) | Center CIO | X (not OTS) |
3.13.3 46 The Contractor shall provide a software schedule for the project's review and schedule updates as requested. Center Level Contractor X X X X HQ OCIO X (not OTS) Center CIO X (not OTS)
| 3.13.4 | 47 | The Contractor shall make electronically available the software traceability data for the project's review. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X (not OTS) | Center CIO | X (not OTS) |
3.14.2 147 The project manager shall specify reusability requirements that apply to its software development activities to enable future reuse of the software, including models used to generate the software. Center Level Project X X X HQ OCIO X Center CIO X
3.14.3 148 The project manager shall evaluate software for potential reuse by other projects across the Agency and contribute reuse candidates to the Agency Software Catalog. Center Level Project X X X X HQ OCIO X Center CIO X
3.15.2 149 The Contractor shall ensure that when an open source software component is acquired or used, the following conditions are satisfied:
a. The requirements that are to be met by the software component are identified.
b. The software component includes documentation to fulfill its intended purpose (e.g., usage instructions).
c. Proprietary, usage, ownership, warranty, licensing rights, and transfer rights have been addressed.
d. Future support for the software product is planned and adequate for project needs.
| e. The software component is verified and validated to the same level required to accept a similar developed software component for its intended use. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X | Center CIO | X |
3.16.2 154 The project manager shall ensure that security risks in space flight software systems are identified and security risk mitigations are planned for these systems in the Project Protection Plan. Center Level Project X X X HQ OCIO Center CIO
3.16.3 155 The Contractor shall implement the identified software security risk mitigations addressed in the Project Protection Plan. Center Level Contractor X X X HQ OCIO Center CIO
3.16.4 156 The project manager shall ensure and record that all systems including space flight software are evaluated for security risks, including risks posed by the use of COTS, GOTS, MOTS, Open Source, and reused software. Center Level Project X X X HQ OCIO Center CIO
3.16.5 157 The project manager shall ensure that software systems with space communications capabilities are protected against un-authorized access. Center Level Project X X X HQ OCIO Center CIO
3.16.6 158 The project manager shall ensure that the space flight software systems are assessed for possible security vulnerabilities and weaknesses. Center Level Project X X X HQ OCIO Center CIO
3.16.7 159 The Contractor shall verify and validate the required software security risk mitigations to ensure that security objectives identified in the Project Protection Plan for space flight software are satisfied in their implementation. Center Level Contractor X X X HQ OCIO Center CIO
4.1.2.1 50 The Contractor shall establish, capture, record, approve, and maintain software requirements, including the software quality requirements, as part of the technical specification. Center Level Contractor X X X X X HQ OCIO X Center CIO X X
| 4.1.2.2 | 51 | The Contractor shall perform software requirements analysis based on flowed-down and derived requirements from the top-level systems engineering requirements and the hardware specifications and design. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X | Center CIO | X |
| 4.1.2.3 | 52 | The Contractor shall perform, record, and maintain bidirectional traceability between the software requirement and the higher-level requirement. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X | Center CIO | X |
4.1.3.1 53 The Contractor shall track and manage changes to the software requirements. Center Level Contractor X X X X HQ OCIO X Center CIO X
| 4.1.3.2 | 54 | The Contractor shall identify, initiate corrective actions, and track until closure inconsistencies among requirements, project plans, and software products. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X | Center CIO | X |
| 4.1.3.3 | 55 | The Contractor shall perform requirements validation to ensure that the software will perform as intended in the customer environment. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X | Center CIO | X |
4.2.3 57 The Contractor shall develop and record the software architecture. Center Level Contractor X X X HQ OCIO X (not OTS) Center CIO X(not OTS)
4.2.4 143 The project manager shall perform a software architecture review on the following categories of projects:
a. Category 1 Projects as defined in NPR 7120.5.
b. Category 2 Projects as defined in NPR 7120.5 that have Class A or Class B payload risk classification per NPR 8705.4. Center Level Project Per selection criteria defined in the SWE-143 requirement HQ OCIO Center CIO
4.3.2 56 The Contractor shall develop, record, and maintain the software design. Center Level Contractor X X X HQ OCIO X (not OTS) Center CIO X(not OTS)
| 4.3.3 | 58 | The Contractor shall develop, record, and maintain a design based on the software architectural design that describes the lower-level units so that they can be coded, compiled, and tested. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X (not OTS) | Center CIO | X(not OTS) |
4.3.4 59 The Contractor shall perform, record, and maintain bidirectional traceability between the following:
a. Software requirements and software architecture.
b. Software architecture and software design.
| c. Software requirements and software design. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X (not OTS) | Center CIO | X(not OTS) |
4.4.2 60 The Contractor shall implement the software design into software code. Center Level Contractor X X X X HQ OCIO X (not OTS) Center CIO X(not OTS)
| 4.4.3 | 61 | The Contractor shall select, adhere to, and verify software coding methods, standards, and/or criteria. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X (not OTS) | Center CIO | X(not OTS) |
| 4.4.4 | 135 | The Contractor shall verify the software code by using the results from static analysis tool(s). | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | Center CIO |
4.4.5 62 The Contractor shall unit test the software code per the plans for software testing. Center Level Contractor X X X X HQ OCIO X (not OTS) Center CIO X(not OTS)
4.4.6 63 The Contractor shall provide a software version description for each software release. Center Level Contractor X X X X HQ OCIO X (not OTS) Center CIO X(not OTS)
| 4.4.7 | 64 | The Contractor shall perform, record, and maintain bidirectional traceability from software design to the software code. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X (not OTS) | Center CIO | X(not OTS) |
| 4.4.8 | 136 | The Contractor shall validate and accredit software tool(s) required to develop or maintain software. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X | Center CIO | X |
4.5.2 65 The Contractor shall establish and maintain:
a. Software test plan(s).
b. Software test procedure(s).
c. Software test report(s). Center Level Contractor X X X X HQ OCIO X Center CIO X
4.5.3 66 The Contractor shall perform software testing. Center Level Contractor X X X X [X] HQ OCIO X Center CIO X
| 4.5.4 | 67 | The Contractor shall verify the requirement to the implementation of each software requirement. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X | Center CIO | X |
4.5.5 68 The Contractor shall evaluate test results and record the evaluation. Center Level Contractor X X X X HQ OCIO X Center CIO X
4.5.6 69 The Contractor shall record defects identified during testing and track to closure. Center Level Contractor X X X X HQ OCIO Center CIO X
4.5.7 70 The Contractor shall use validated and accredited software models, simulations, and analysis tools required to perform qualification of flight software or flight equipment. Center Level Contractor X X X HQ OCIO Center CIO
4.5.8 71 The Contractor shall update software test plan(s) and software test procedure(s) to be consistent with software requirements. Center Level Contractor X X X X HQ OCIO X Center CIO X
4.5.9 72 The Contractor shall provide and maintain bidirectional traceability from the software test procedures to the software requirements. Center Level Contractor X X X HQ OCIO X Center CIO X
| 4.5.10 | 73 | The Contractor shall validate the software system on the targeted platform or high-fidelity simulation. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X | Center CIO | X |
4.6.2 75 The Contractor shall plan and implement software operations, maintenance, and retirement activities. Center Level Contractor X X X X HQ OCIO X Center CIO X
4.6.3 77 The Contractor shall complete and deliver the software product to the customer with appropriate records, including as-built records, to support the operations and maintenance phase of the software’s life cycle. Center Level Contractor X X X X X HQ OCIO X Center CIO X X
| 5.1.2 | 79 | The project manager shall develop a software configuration management plan that describes the functions, responsibilities, and authority for the implementation of software configuration management for the project. | Center Level | Project and Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X | Center CIO | X |
5.1.3 80 The Contractor shall track and evaluate changes to software products. Center Level Contractor X X X X HQ OCIO X Center CIO X
5.1.4 81 The Contractor shall identify the software configuration items (e.g., software records, code, data, tools, models, scripts) and their versions to be controlled for the project. Center Level Contractor X X X X HQ OCIO X Center CIO X
5.1.5 82 The Contractor shall establish and implement procedures to:
a. Designate the levels of control through which each identified software configuration item is required to pass.
b. Identify the persons or groups with authority to authorize changes.
| c. Identify the persons or groups to make changes at each level. | Center Level | Contractor | X | X | X | X | ||
| *(SC only) | HQ OCIO | X | Center CIO | X | X |
| 5.1.6 | 83 | The Contractor shall prepare and maintain records of the configuration status of software configuration items. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X | Center CIO | X | X |
| 5.1.7 | 84 | The Contractor shall perform software configuration audits to determine the correct version of the software configuration items and verify that they conform to the records that define them. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X | Center CIO | X |
5.1.8 85 The Contractor shall establish and implement procedures for the storage, handling, delivery, release, and maintenance of deliverable software products. Center Level Project and Contractor X X X X HQ OCIO X Center CIO X X
5.2.2 86 The project manager shall identify, analyze, plan, track, control, communicate, and record software risks and mitigation plans in accordance with NPR 8000.4. Center Level Project and Contractor X X X HQ OCIO X Center CIO X
5.3.2 87 The Contractor shall perform and report the results of software peer reviews or software inspections for:
a. Software requirements.
b. Software plans.
c. Any design items that the project identified for software peer review or software inspections according to the software development plans.
d. Software code as defined in the software and or project plans.
| e. Software test procedures. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X (not OTS) | Center CIO | X (not OTS) |
5.3.3 88 The Contractor shall, for each planned software peer review or software inspection:
a. Use a checklist or formal reading technique (e.g., perspective based reading) to evaluate the work products.
b. Use established readiness and completion criteria.
c. Track actions identified in the reviews until they are resolved.
| d. Identify required participants. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X (not OTS) | Center CIO | X (not OTS) |
| 5.3.4 | 89 | The Contractor shall, for each planned software peer review or software inspection, record basic measurements. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X (not OTS) | Center CIO | X (not OTS) |
| 5.4.2 | 90 | The Contractor shall establish, record, maintain, report, and utilize software management and technical measurements. | Center Level | Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X (not OTS) | Center CIO | X (not OTS) |
| 5.4.3 | 93 | The project manager shall analyze software measurement data collected using documented project-specified and/or Center/organizational analysis procedures. | Center Level | Project | X | X | X | X | |
| *(SC only) | HQ OCIO | X (not OTS) | Center CIO | X (not OTS) |
| 5.4.4 | 94 | The project manager shall provide access to the software measurement data, measurement analyses and software development status as requested to the sponsoring Mission Directorate, the NASA Chief Engineer, Center and Headquarters SMA, and Center repositories. | Center Level | Project | X | X | X | X | |
| *(SC only) | HQ OCIO | X (not OTS) | Center CIO | X (not OTS) |
MasterK
<-- Click on the plus or minus sign to display or hide the NPR7150.2B requirements matrix help information
The rationale for the requirements is contained in the NASA Software Engineering Handbook, NASA-HDBK-2203. Programs/Projects may substitute a matrix that documents their compliance with their particular Center's implementation of NPR 7150.2, if applicable. See NASA-HDBK-2203 for compliance matrices organized by class & safety-criticality, tailoring field for each requirement, tailoring rationale, and approval signature lines. The Compliance Matrix documents the program/project's compliance or intent to comply with the requirements of this NPR or justification for tailoring. The rationale for the requirements is contained in the NASA Software Engineering Handbook, NASA-HDBK-2203. Programs/Projects may substitute a matrix that documents their compliance with their particular Center's implementation of NPR 7150.2, if applicable. See NASA-HDBK-2203 for compliance matrices organized by class & safety-criticality, tailoring field for each requirement, tailoring rationale, and approval signature lines. The Compliance Matrix documents the program/project's compliance or intent to comply with the requirements of this NPR or justification for tailoring.
Tailoring Guidance Tailoring Guidance
X - Indicates an invoked requirement by this NPR consistent with Software Classification (ref. SWE-139). May be tailored with Technical Authority approval (ref. Chapter 2.2). X - Indicates an invoked requirement by this NPR consistent with Software Classification (ref. SWE-139). May be tailored with Technical Authority approval (ref. Chapter 2.2).
Blank - Optional / Not invoked by this NPR for this Software Classification. Blank - Optional / Not invoked by this NPR for this Software Classification.
X *(SC only) - Project is required to meet the requirement to the extent necessary to satisfy safety critical aspects of the software.
X (not OTS) - Does not apply to Off the Shelf (OTS), Commercial Software. X (not OTS) - Does not apply to Off the Shelf (OTS), Commercial Software.
Center Director - Center Director or the Center Director’s designated Engineering Technical Authority or Center Director's designated Safety and Mission Assurance Technical Authority. Center Director - Center Director or the Center Director’s designated Engineering Technical Authority or Center Director's designated Safety and Mission Assurance Technical Authority.
Note 1 - All Safety-critical software has to be classified as Class D or Higher. Note 1 - All Safety-critical software has to be classified as Class D or Higher.
Note 2 - Applies to Class B software except for Class B software on NASA Class D payloads, as defined in NPR 8705.4. For Class B software, in lieu of a CMMI rating by a development organization, the project will conduct an evaluation, performed by a qualified evaluator selected by the Center Engineering Technical Authority, of the seven process areas listed in SWE-032 and mitigate any risk, if deficient. This exception is intended to be used in those cases in which NASA wishes to purchase a product from the "best of class provider," but the best of class provider does not have the required CMMI rating. When this exception is exercised, the Center Engineering Technical Authority should be notified. Note 2 - Applies to Class B software except for Class B software on NASA Class D payloads, as defined in NPR 8705.4. For Class B software, in lieu of a CMMI rating by a development organization, the project will conduct an evaluation, performed by a qualified evaluator selected by the Center Engineering Technical Authority, of the seven process areas listed in SWE-032 and mitigate any risk, if deficient. This exception is intended to be used in those cases in which NASA wishes to purchase a product from the "best of class provider," but the best of class provider does not have the required CMMI rating. When this exception is exercised, the Center Engineering Technical Authority should be notified.
Note 3 - For tailoring of NASA-STD-8739.8 and NASA-STD-8719.13, the Software Assurance Standard and the Software Safety Standard respectively, use the tailoring provided within those documents. They are both risk based and SW Class based tailoring. Note 3 - For tailoring of NASA-STD-8739.8 and NASA-STD-8719.13, the Software Assurance Standard and the Software Safety Standard respectively, use the tailoring provided within those documents. They are both risk based and SW Class based tailoring.
| Note 4 - The Technical Authority implementation responsibilities for Class F software is at the NASA Headquarters Chief Information Officer (CIO) level , the Technical Authority implementation responsibilities for Class G and H is at the Center CIO organization level or at the level defined in the Center Technical Authority implementation plan. All Safety-critical software has to be classified as Class D or higher. | |
| Note 4 - The Technical Authority implementation responsibilities for Class F software is at the NASA Headquarters Chief Information Officer (CIO) level , the Technical Authority implementation responsibilities for Class G and H is at the Center CIO organization level or at the level defined in the Center Technical Authority implementation plan. All Safety-critical software has to be classified as Class D or higher. |
<-- Click on the plus or minus sign to display or hide the Project requirements
| Section | NPR SWE # | Requirement Text | Technical Authority | Responsibility | A | B | C | D | E | Technical Authority | F | ||
| (Note 4) | Technical Authority | G | |||||||||||
| (Note 4) | H |
(Note 4)
2.2.4 121 Where approved, the project manager shall document and reflect the tailored requirement in the plans or procedures controlling the development, acquisition, and/or deployment of the affected software. Center Level Project X X X X HQ OCIO X Center CIO X X
2.2.5 125 Each project manager with software components shall maintain a compliance matrix or multiple compliance matrices against requirements in this NPR, including those delegated to other parties or accomplished by contract vehicles or Space Act Agreements. Center Level Project X X X X X HQ OCIO X Center CIO X X
2.2.6 139 The projects shall comply with the requirements in this NPR that are marked with a “project” responsibility and an ”X” in Appendix D consistent with their software classification. Center Level Project X X X X X HQ OCIO X Center CIO X X
2.2.10 145 When the compliance matrix is used to waive/deviate from applicable “X” requirement(s), the designated Technical Authorities shall indicate their approval by signature(s) in the compliance matrix itself. Center Level Project X X X X X HQ OCIO X Center CIO X X
3.2.1 15 The project manager shall establish, document, and maintain two cost estimates and associated cost parameters for all software Class A and B projects that have an estimated project cost of $2 million or more
-OR -
one software cost estimate and associated cost parameter(s) for other software projects. Center Level Project X X X X HQ OCIO Center CIO
3.2.2 151 The software cost estimate(s) shall satisfy the following conditions:
a. Covers the entire software life cycle.
b. Is based on selected project attributes (e.g., assessment of the size, functionality, complexity, criticality, reuse code, modified code, and risk of the software processes and products).
c. Is based on the cost implications of the technology to be used and the required maturation of that technology.
d. Incorporates risk and uncertainty.
e. Includes the cost for software assurance support.
f. Includes other direct costs. Center Level Project and Contractor X X X X HQ OCIO Center CIO
3.5.1 20 The project manager shall classify each system and subsystem containing software in accordance with the highest applicable software classification definitions for Classes A, B, C, D, E, F, G, and H software in Appendix D. Center Level Project X X X X X HQ OCIO X Center CIO X X
3.5.2 132 The project’s software assurance manager shall perform an independent classification assessment. Center Level Project X X X X X HQ OCIO X Center CIO X X
3.5.3 133 The project manager, in conjunction with the Safety and Mission Assurance organization, shall determine the software safety criticality in accordance with NASA-STD-8719.13. Project and Center SMA Project and Center S&MA X X X X X HQ OCIO X Center CIO X X
3.5.4 21 If a system or subsystem evolves to a higher or lower software classification as defined in Appendix D, or there is a change in the safety criticality of the software, then the project manager shall update the plan to fulfill the applicable requirements per the Requirements Mapping and Compliance Matrix in Appendix C and any approved tailoring. Center Level Project X X X X X HQ OCIO X Center CIO X X
| 3.5.5 | 160 | If a software component is determined to be safety critical software then software component classification shall be Software Class D or higher. | Center Level | Project | X | X | X | X | X | |
| (Note 1) | HQ OCIO | X | Center CIO | X | X |
| 3.6.1 | 22 | The project manager shall plan and implement software assurance per NASA-STD-8739.8. | Center Level | Project and Center S&MA | ||||
| (Note 3) | X | X | X | X | HQ OCIO | Center CIO |
3.6.2 141 For projects reaching KDP A after the effective date of this directive’s revision, the program manager shall ensure that software IV&V is performed on the following categories of projects:
a. Category 1 projects as defined in NPR 7120.5.
b. Category 2 projects as defined in NPR 7120.5 that have Class A or Class B payload risk classification per NPR 8705.4.
c. Projects specifically selected by the NASA Chief, Safety and Mission Assurance (SMA) to have software IV&V. HQ OCE and HQ OSMA Project and Center S&MA Per selection criteria defined in the SWE-141 requirement HQ OCIO Center CIO
3.6.3 131 If software IV&V is performed on a project, project manager shall ensure that an IV&V Project Execution Plan (IPEP) is developed. Center and the Center SMA organization Project and Center S&MA X X X HQ OCIO X Center CIO X
| 3.7.1 | 23 | When a project is determined to have safety-critical software, the project manager shall implement the requirements of NASA-STD-8719.13. | Center Level | Project and Center S&MA | ||
| (Note 3) | X | X | X | |||
| *(SC only) | X | |||||
| *(SC only) | HQ OCIO | Center CIO |
3.11.3 32 The project manager shall acquire, develop, and maintain software from an organization with a non-expired Capability Maturity Model® Integration for Development (CMMI-DEV) rating as measured by a CMMI Institute authorized or certified lead appraiser as follows:
a. For Class A software: CMMI-DEV Maturity Level 3 Rating or higher for software, or CMMI-DEV Capability Level 3 Rating or higher in all CMMI-DEV Maturity Level 2 and 3 process areas for software.
b. For Class B software on NASA payloads with risk classifications A, B, and C, as defined in NPR 8705.4: CMMI-DEV Maturity Level 2 Rating or higher for software, or CMMI-DEV Capability Level 2 Rating or higher for software in the following process areas:
(1) Requirements Management.
(2) Configuration Management.
(3) Process and Product Quality Assurance.
(4) Measurement and Analysis.
(5) Project Planning.
(6) Project Monitoring and Control.
(7) Supplier Agreement Management (if applicable). HQ OCE and HQ OSMA Project X X (Note 2) HQ OCIO Center CIO
3.12.2 33 The project manager shall assess options for software acquisition versus development. Center Level Project X X X X HQ OCIO X Center CIO X
3.12.3 34 The project manager shall define and document the acceptance criteria and conditions for the software. Center Level Project X X X X HQ OCIO X Center CIO X
| 3.12.4 | 35 | The project manager shall establish a procedure for software supplier selection, including proposal evaluation criteria. | Center Level | Project | X | X | X | X | |
| *(SC only) | HQ OCIO | X | Center CIO |
3.12.5 36 The project manager shall determine which software processes, software documents, electronic products, software activities, and tasks are required for the project and software suppliers. Center Level Project X X X X HQ OCIO X (not OTS) Center CIO X (not OTS)
3.12.6 37 The project manager shall define the milestones at which the software supplier(s) progress will be reviewed and audited as a part of the acquisition activities. Center Level Project X X X X HQ OCIO X (not OTS) Center CIO X (not OTS)
3.12.7 38 The project manager shall document software acquisition planning decisions. Center Level Project X X X X HQ OCIO X (not OTS) Center CIO X (not OTS)
| 3.13.2 | 45 | The project manager shall participate in any joint NASA/supplier audits of the software development process and software configuration management process. | Center Level | Project | X | X | X | X | |
| *(SC only) | HQ OCIO | X (not OTS) | Center CIO | X (not OTS) |
3.14.2 147 The project manager shall specify reusability requirements that apply to its software development activities to enable future reuse of the software, including models used to generate the software. Center Level Project X X X HQ OCIO X Center CIO X
3.14.3 148 The project manager shall evaluate software for potential reuse by other projects across the Agency and contribute reuse candidates to the Agency Software Catalog. Center Level Project X X X X HQ OCIO X Center CIO X
3.16.2 154 The project manager shall ensure that security risks in space flight software systems are identified and security risk mitigations are planned for these systems in the Project Protection Plan. Center Level Project X X X HQ OCIO Center CIO
3.16.4 156 The project manager shall ensure and record that all systems including space flight software are evaluated for security risks, including risks posed by the use of COTS, GOTS, MOTS, Open Source, and reused software. Center Level Project X X X HQ OCIO Center CIO
3.16.5 157 The project manager shall ensure that software systems with space communications capabilities are protected against un-authorized access. Center Level Project X X X HQ OCIO Center CIO
3.16.6 158 The project manager shall ensure that the space flight software systems are assessed for possible security vulnerabilities and weaknesses. Center Level Project X X X HQ OCIO Center CIO
4.2.4 143 The project manager shall perform a software architecture review on the following categories of projects:
a. Category 1 Projects as defined in NPR 7120.5.
b. Category 2 Projects as defined in NPR 7120.5 that have Class A or Class B payload risk classification per NPR 8705.4. Center Level Project Per selection criteria defined in the SWE-143 requirement HQ OCIO Center CIO
| 5.1.2 | 79 | The project manager shall develop a software configuration management plan that describes the functions, responsibilities, and authority for the implementation of software configuration management for the project. | Center Level | Project and Contractor | X | X | X | X | |
| *(SC only) | HQ OCIO | X | Center CIO | X |
5.1.8 85 The project manager shall establish and implement procedures for the storage, handling, delivery, release, and maintenance of deliverable software products. Center Level Project and Contractor X X X X HQ OCIO X Center CIO X X
5.2.2 86 The project manager shall identify, analyze, plan, track, control, communicate, and record software risks and mitigation plans in accordance with NPR 8000.4. Center Level Project and Contractor X X X HQ OCIO X Center CIO X
| 5.4.3 | 93 | The project manager shall analyze software measurement data collected using documented project-specified and/or Center/organizational analysis procedures. | Center Level | Project | X | X | X | X | |
| *(SC only) | HQ OCIO | X (not OTS) | Center CIO | X (not OTS) |
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .