RFP 80GSFC22R0004 Enclosure 1 - IT Security Management Plan Template.pdf

PDF 2 MB Posted

Attached to
PROTECTIVE SERVICES – EASTERN REGION Federal contract opportunity
Solicitation number
80GSFC22R0004
Issued by
National Aeronautics and Space Administration Goddard Space Center

About this file

This document contains an Information Technology Security Management Plan template for a federal contract. The template outlines requirements for security controls, Federal Information Security Management Act reporting, and acronyms. However, it does not provide specific details on products or services required as it appears to be a generic template for contractors to populate with contract-specific information.

The related federal contract opportunity is a draft Request for Proposal for protective services for multiple NASA centers. Services include communications security, security operations, information security, program security, resource protection, physical security, credentialing, emergency communications and management, and training. The solicitation is a competitive 8(a) small business set-aside with a ceiling of $198 million over five years. Proposals are due approximately 30 days after release of the final RFP, planned for February 5, 2022. The National Aeronautics and Space Administration Goddard Space Flight Center is the contracting agency.

View the file

Other files for this federal contract opportunity

Other files attached to PROTECTIVE SERVICES – EASTERN REGION, newest first.
File Type Posted
RFP 80GSFC22R0004 Enclosure 2 - QASP Fixed Price Contract Template.pdf PDF
Attachment W - Government Seats.pdf PDF
Attachment T - Cover Page.pdf PDF
Attachment G - OCI Avoidance Plan Outline Template.pdf PDF
Attachment B - Baseline Services Price Schedule.pdf PDF
Attachment A.4 - Cover Page.pdf PDF
Attachment A.3 - HQ Annex .pdf PDF
Attachment A.3 - Cover Page.pdf PDF
Attachment A.2 - Cover Page.pdf PDF
Attachment A.1 - Cover Page.pdf PDF
RFP 80GSFC22R0004 Exhibit 2 _80GSFC21R0024 11.30.2021.pdf PDF
Attachment V - In Car Audio Video Body Worn Camera Requirements.pdf PDF
Attachment S - Medical Screening Standards for Armed Personnel.pdf PDF
Attachment S - Cover Page.pdf PDF
Attachment Q - Uniforms.pdf PDF
Attachment A.2 - GSFC Annex.pdf PDF
Attachment A - Cover Page.pdf PDF
Attachment F - Safety And Health Plan.pdf PDF
Attachment V - Cover Page.pdf PDF
Attachment W - Cover Page.pdf PDF
Attachment U - Data Requirements Document.pdf PDF
Attachment U - Cover Page.pdf PDF
Attachment R - Deduction Schedule for Non-Conforming Services.pdf PDF
Attachment R - Cover Page.pdf PDF
Attachment O - Glossary and Acronyms.pdf PDF
Attachment J - DD254 (NPS-ER).pdf PDF
Attachment J - DD 254 Cover Page.pdf PDF
Attachment I - IT Security Management Plan.pdf PDF
Attachment C - IDIQ Fixed Price Rate Matrix 12.2.21.pdf PDF
Attachment A.4 - LaRC Annex .pdf PDF
Attachment A - Performance Work Statement.pdf PDF
Protective Services - DRFP Sections II - VI (12-03-2021).pdf PDF
Protective Services - DRFP Cover Letter (12-3-2021).pdf PDF
RFP 80GSFC22R0004 Exhibit 1 - Past Performance Questionnaire.pdf PDF
Attachment T - Screening Standards for Armed Personnel.pdf PDF
Attachment Q - Cover Page.pdf PDF
Attachment P - Vehicle Standards.pdf PDF
Attachment P - Cover Page.pdf PDF
Attachment O - Cover Page.pdf PDF
Attachment H - IT Security Applicable Documents List.pdf PDF
Attachment D - IAGP List.pdf PDF
Attachment A.1 - GRC Annex .pdf PDF
Show all 42

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Information Technology Security Management Plan

Issue Date Effective Date:

SENSITIVE BUT UNCLASSIFIED

(SBU) Version 7 03/2021

(Insert Contract # Here)

IT Security Management Plan Review and Approval

This Information Technology Security Management Plan (ITSMP) for the was prepared for the exclusive use of NASA and completed on

I have reviewed the contents of this plan, and believe that it presents an accurate representation.

Reviewed by: ________________________________

ISSO, or equivalent Date

Concurred by: ________________________________

COR/Task Monitor Date

Approved by: ________________________________

Center CISO Date

Accepted by: ________________________________

Contracting Officer Date

SENSITIVE BUT UNCLASSIFIED

Contents

Change History .......................................................................................................................................................................................... ii IT Security Management Plan Review and Approval ............................................................................................................................... iii 1 Contract Identification

1.1 Contract Name

1.2 Contract Number

1.3 Responsible Organization

1.4 Contact Information

1.4.1 Physical Location

1.4.2 Points of Contact

1.5 General Contract Description

1.5.1 Information System Categorization

1.5.2 Security Categorization

1.5.3 Information System

1.5.4 Contractor Badging

1.5.5 Supply Chain Risk Management (SCRM)

1.5.6 Related Laws/Regulations/Policies

2 Security Control Implementations 3 Federal Information Security Management Act (FISMA) Reporting Appendix A: Acronyms

1.5.6 Related Laws/Regulations/Policies

• 5 U.S.C. 552, Freedom of Information Act, 1967

• 5 U.S.C. 552a, Privacy Act, 1974

• FIPS 199, Standards for Security Categorization of Federal Information and Information Systems

• FIPS 200, Minimum Security Requirements for Federal Information and Information Systems

• NIST SP 800-18 Rev. 1, Guide for Developing Security Plans for Federal Information Systems

• NIST SP 800-30 Rev. 1, Guide for Conducting Risk Assessments

• NIST SP 800-34 Rev. 1, Contingency Planning Guide for Information Technology Systems

• NIST SP 800-37 Rev. 2, Guide for the Security Authorization of Federal Information Systems

• NIST SP 800-42, Guideline on Network Security Testing

• NIST SP 800-53 Rev. 4, Recommended Security Controls for Federal Information Systems

• NIST SP 800-53A Rev. 4, Techniques and Procedures for Verifying the Effectiveness of Security Controls in Federal

Information Systems

• NIST SP 800-60 v1 Rev. 1, Guide for Mapping Types of Information and Information Systems to Security Categories

• NIST SP 800-61 Rev. 2, Computer Security Incident Handling Guide

• NIST SP 800-64 v1, Security Considerations in the Information System Development Life Cycle

• OMB Circular A-130, Appendix III, Security of Federal Automated Information Systems

• Public Law (PL) 99-474, The Computer Fraud and Abuse Act of 1986

• PL 93-502 -Freedom of Information Act 1974

• Presidential Decision Directive (PDD-63), Critical Infrastructure Protection Federal Information Security Management Act of 2002 (FISMA)

• NPR 2810.1A, Security of Information Technology

Additional Information: If there is any additional information that you wish to provide, please use the box below.

Version 7 03/2021

File details come from the government source that posted it. Updated .