Boeing IR&MS IT Security Function

Work Breakdown Structure

Table of Contents

1. Background
5. Roles and Responsibilities
2. Goal
6. Application Description
3. Scope 7. Acronyms
4. Objectives
PRINT ONE


1. Background

The Information Resources & Management Support Contract (IR&MSC) with NASA HQ requires that the Boeing Team "... implement a comprehensive security program to adequately secure and protect the Government's and Contractor's investment in information technology systems, equipment, software, services, data and information, facilities, and other resources involved in the performance of this contract." [§1.0.1.2]

Sub-task Order 0.6 describes deliverables that the NASA HQ Information Technology (IT) Security Manager (ITSM) has determined to be an integral part of such a program. Sub-task Order 0.6 does not describe how comprehensive IT security should be achieved and maintained - that determination has been left to the Boeing Team.

The IT security posture of NASA HQ is the responsibility of the entire Boeing Team - most everything that Engineering, Operations, Applications and User Services does has a direct impact on IT security. For IT security to work, everyone must understand their role and must meet these additional responsibilities. IT security is therefore a function that must be managed across the Program, and must operate at two levels:
The IT Security Team Lead will launch and direct program-wide activities
The IT Security Team members will provide security deliverables, will conduct security-centric activities, and will assist with program-wide activities

In order to achieve efficiency and effectiveness, the entire Boeing Team must support and follow a plan maintained by the IT Security Team Lead. This Work Breakdown Structure (WBS) represents the foundation of that plan.

Return to the top of the document


2. Goal

The overall goal of the IT Security Function is to continually improve the IT security posture of NASA HQ in the manner deemed most efficient and effective in terms of incident prevention, damage minimization, resource utilization, and law enforcement.

Return to the top of the document


3. Scope

Efforts will focus initially on the tools and processes required for the systematic pursuit of better IT security. These tools and processes will then be directed at NASA HQ systems and services as they are scheduled to migrate behind the firewall - adequate technical security is a prerequisite for migration. It is anticipated that enterprise systems and services will migrate first, followed by Code systems and services. Once all migrating systems and services have been addressed, Boeing will prioritize what remains and will approach Code CI Management for concurrence.

Return to the top of the document


4. Objectives

Pursuit of the following high-level objectives constitutes a comprehensive IT security program for NASA HQ:

  1. Provide ITSM-requested deliverables.
  2. Provide and maintain a comprehensive IT security architecture (i.e. master plan).
  3. Provide and maintain appropriate IT security policies, guidelines and procedures.
  4. Provide centralized IT security management, oversight, review and reporting.
  5. Provide IT security incident and virus response capabilities and coordination.
  6. Provide IT security training and awareness.
  7. Monitor actual system and network activity (i.e. intrusion detection).
  8. Monitor reported system and product vulnerabilities (via CERT, newsgroups, etc.).
  9. Assist NASA HQ in meeting regulatory screening and reporting requirements.
  10. Assess risk and recommend mitigations (e.g. scanning, auditing, analysis).
  11. Respond to security-centric Service Requests (SRs) and Problem Reports (PRs).
  12. Respond to ad hoc requests for analytical or technical security support.

Return to the top of the document


5. Roles and Responsibilities

Boeing Team roles and responsibilities are delineated in the following table using these marks and abbreviations:

SEC = IT Security Group
OPS = Operations
ENG = Engineering
APP = Applications
USR = User Services (other than IT Security Group)
BUS = Business Management

PRINT ONE = Lead and PRINT ONE = Assist
PRI = Priority of Task:
C = Critical for implementation of the IT Security Function
H = High
M = Moderate
L = Low
Shading indicates a deliverable (as opposed to an on-going or recurring activity).

[Bracketed paragraph numbers indicate the mapping to Sub-task Order 0.6 for FY'98]

NOTE: Certain high-level reporting (e.g. financial management, personnel utilization) will continue to be handled by the User Services Department Head. [§1.0.4]

S
E
C
O
P
S
E
N
G
A
P
P
U
S
R
B
U
S
P
R
I
TASK DESCRIPTION (Deliverables are shaded)
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE -- 1. Provide ITSM-requested deliverables. (…others are listed elsewhere in this WBS; these do not fit elsewhere)
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE C a) Update and maintain the IT Security Web page (http://www.hq.nasa.gov/its) as directed.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE C
(i) Provide tools, training and initial design.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE C
(ii)Provide host services for NASA.GOV access.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE C
(iii) Post initial ITS website update.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H (b) Support the NASA IT Security (ITS) Working Group meetings held semi-annually at NASA Centers as directed. [§1.3.2.10]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H (c) Comply with policies and procedures for NASA Headquarters Computer Center (NHCC) physical security. [§1.3.3.1]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H (d) Maintain high quality in all presentations and written products. [Metric 4 "Quality of Documentation"]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE ? (e) Perform other tasks when so directed by the issuance of a competent Sub-task Order or Sub-task Order Amendment.[§1.3.2.1]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE -- 2. Provide and maintain a comprehensive IT security architecture (i.e. master plan).
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE C a)Establish and maintain a NASA HQ-specific IT threat list.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE C
(i)Post HQ Threat List to ITS website.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE C b)Establish and maintain a general-principles-style master architectural plan for NASA HQ IT security. [§1.3.2.8]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE C
(i) Post HQ IT Security Plan to ITS website.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE -- 3.Provide and maintain appropriate IT security policies, guidelines and procedures.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M a)Draft and recommend enhancements for NASA HQ IT security policies as directed. [§1.3]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(i) Update the Virus Prevention and Eradication Policy and Procedures.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(ii) Update the Computer System Password Policy.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(iii)Update the Security Policy for Local Area Networks.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(iv) Update the Procedures for Granting, Changing and Terminating Access to HQ Automated Information Systems.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M b) Establish and maintain platform- and application-specific IT security guidelines. [§1.3.2.8]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(i)Update the UNIX Security Policy and Practices.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(ii) Establish NT Server Security Policy and Practices.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(iii) Establish Mac Server Security Policy and Practices.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(iv) Establish NT, 95 and Mac Workstation Security Policy and Practices.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(v) Establish Sybase Security Policy and Practices.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(vi) Establish Oracle Security Policy and Practices.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(vii)Establish MS SQL Server Security Policy and Practices.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M (c) Establish and maintain procedures for all IT security-significant events and processes. [§1.3.2.5 and 1.3.2.8]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(i) Establish procedure for transitioning existing system in from another NASA Center.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(ii)Establish procedure for responding to alerts issued by another NASA Center.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE -- 4. Provide centralized IT security management, oversight, review and reporting.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H a) Review and coordinate priorities with ITSM; provide up-to-date deliverables schedule and status.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H b) Participate in a half-hour daily status meeting with the Contracting Officer's Technical Representative (COTR) and the Functional Monitors (a.k.a. "NASA HQ Daily Tag Up" typically at 8:30 am). [§1.0.5]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H c) Participate in a one-hour weekly status meeting (typically Wednesday at 11:00 am) with the ITSM and Chief, Support Services Branch.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H d) Contribute to the development and presentation of monthly program management reports to the COTR and Functional Monitors (typically the fourth Thursday "In-depth" at 8:30 am). [§1.0.5]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H e) Monitor and report monthly on the status of ITS at NASA HQ (weekly status reports plus monthly deliverables schedule update and virus statistics; reports also help form the ITS Status section of Data Requirement Descriptions (DRD) 3-C). [§1.0.5 and 1.3.2.6]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H f) Draft and submit the NASA HQ Annual ITS Plan (DRD 6-1) in accordance with NASA Handbook (NHB) 2410.9A. [§1.3.2.9]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE C g)Define IT "security incident", "security activity", "security vulnerability", "security infraction", "security exception", "security review", "security plan" and "risk assessment" relative to NASA HQ, and post to ITS website.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE C h)Establish and maintain a process for IT security incident, activity, vulnerability, infraction and exception reporting.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE C
(i) Establish an IT security reporting process.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(ii)Report irregularities to the IT Security Team.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(iii)Disposition irregularity reports.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(iv) Report all IT security incidents and infractions to the ITS Manager using the Security Incident Report (DRD 69) by close of business the following business day. [§1.3.2.5 and Metric 1 "Security Incident Report"]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(i) Ensure appropriate IT security objectives are established for security-significant projects. [§1.3.2.8]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(i) Propose IT security objectives for the Firewall/ Security Architecture.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(ii) Propose IT security objectives for the Distributed Computing Environment (DCE).
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(iii)Review IT security objectives for the Integrated Financial Management Project (IFMP) as proposed by perspective bidders; provide report.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE C j) Establish IT security review criteria and procedures for hardware systems and include them in the system life cycle and PDR/CDR/DRR/ORR process. [§1.3.2.4]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE C k) Establish IT security review criteria and procedures for applications and include them in the application life cycle and PDR/CDR/DRR/ORR process. [§1.3.2.4 and 1.3.4.1]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M l)Update and maintain the Server matrix (formerly UNIX matrix). [§1.3.2.14]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(i)Provide network map and system listings.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(ii)Verify system details.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(iii) Provide initial update to interested parties.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L m)Update the Boeing IR&MSC Security Management Plan (DRD 66) as needed. [§1.1.1]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L n)Ensure the effectiveness and accuracy of the security measures prescribed by the Boeing IR&MSC Security Management Plan (DRD 66). [§1.1.1.1]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H o)Provide centralized account administration.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(i) Provide security oversight of account administration. [§1.3.2.15]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M p)Cross-connect projects with overlapping IT security aspects.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M q) Participate in Agency-wide IT security-related working groups.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M r)Implement IT security aspects of new Federal mandates and Chief Information Officer (CIO) Executive Notices as they become applicable. [§1.3]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L s) Verify adherence to policy and procedures through periodic, unannounced compliance checks. [§1.3.2.15]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M t)Maintain this WBS, including updates necessitated by changes in policy, technology and organizational structure. [§1.3.1]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE -- 5. Provide IT security incident and virus response capabilities and coordination.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE C a) Generate and maintain an incident response matrix. §1.3.2.5]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE C
(i)Post Incident Response Matrix to ITS website.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE C b)Generate and maintain a virus response matrix. [§1.3.2.5]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE C
(i) Post Virus Response Matrix to ITS website.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M c) Assist the ITSM in better defining the incident response division-of-labor between Code CI, Code W and the NASA Automated System Incident Response Capability (NASIRC).
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H d) Respond to IT security incidents within one business hour of receipt of notification. [Metric 3 "Security Incident Response"]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE -- 6. Provide IT security training and awareness.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H a) Assist the ITSM in the development and delivery of IT security training and awareness as directed. [§1.3.2.13]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L b) Develop, implement and maintain an in-house IT security training and awareness program for Boeing IR&MSC personnel. [§1.1.2]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L
(i)Establish schedule for FY'98 IT security training and awareness activities.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M c) Educate users, Customer Support Representatives (CSRs) and Service Center analysts in proper virus response. [§1.3.2.5]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L
(i)Establish schedule for FY'98 virus response training activities.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M (d) Elevate and maintain IT Security Team proficiency and professionalism.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE -- 7. Monitor actual system and network activity (i.e. intrusion detection).
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M a) Implement automated IT security activity monitors on supported systems. [§1.3.2.8]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M b) Monitor NASA HQ/Internet activities (e.g., NETMON) in support of the Firewall/Security Architecture Project. [§1.3.2.8]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(i)Provide Internet Activity report to Firewall Team.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M c) Audit system and network activity logs.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(i)Provide security oversight of system and network auditing. [§1.3.2.15]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M d)Maintain system and network activity logs in support of incident response.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(i)Provide security oversight of log maintenance. [§1.3.2.15]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE -- 8. Monitor reported system and product vulnerabilities (via CERT, newsgroups, etc.).
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M a) Establish a vulnerability monitoring process.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M b)Monitor vulnerability reports regarding supported hardware and software.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M c)Disposition vulnerability reports.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M d) Test and baseline patches.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M e) Implement patches.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE -- 9. Assist NASA HQ in meeting regulatory screening and reporting requirements.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M a) Monitor changes in applicable regulations.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H b) Collect and submit for screening the Information on Employees in Sensitive ITS Positions/Assignments for appropriate Boeing IR&MSC personnel (DRD 68). [§1.1.3]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H c)Draft a security plan for each of the following general support systems as defined in revised Appendix III of OMB A-130 and in accordance with DRD 6-2. [§1.3.2.8, 1.3.3 and 1.3.3.2]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(i)Establish the requirements and standard format for NASA HQ security plans.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(ii) Draft and submit a security plan for HISS.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H (a) Perform sustaining engineering and maintenance of the existing HISS; and develop and/or acquire, sustain, and maintain enhancements, upgrades, and new capabilities. [§1.3.2.2]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(iii)Draft and submit a security plan for NHCC (administrative, personnel, environmental, physical and support, but not technical security).
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(iv) Draft and submit a security plan for HCN (including the Firewall, Dial-in Server and Border Router). *
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(v) Draft and submit a security plan for NOC. *
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(vi)Draft and submit a security plan for NT Server Farm. *
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(vii) Draft and submit a security plan for NASA HQ Amdahl LPAR (including the intermediary database servers, e.g. AIM1HQ). **
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(viii) Draft and submit a security plan for Alpha. *
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(ix)Draft and submit a security plan for Dedicated Servers (E-mail, MM, Web, News, FTP, DNS, X.500, local database, etc.). *
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H d)Draft a security plan for each of the following category "A" applications as defined in revised Appendix III of OMB A-130 and in accordance with DRD 6-3. [§1.3.4]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(i)Draft and submit a security plan for IRIS.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(ii) Draft and submit a security plan for FPDS.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(iii)Draft and submit a security plan for CAPPS.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(iv)Draft and submit a security plan for NTDS.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(v) Draft and submit a security plan for FAAD.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(vi)Draft and submit a security plan for ERMP.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(vii) Draft and submit a security plan for AMS.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(viii) Draft and submit a security plan for CTDS.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(ix) Draft and submit a security plan for IFMP (unless an adequate plan is provided by the IFMP vendor).
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE -- 10. Assess risk and recommend mitigations (e.g. scanning, auditing, analysis).
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H a) Implement virus protection products for all at-risk NASA HQ IT platforms. [§1.3.2.5]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(i) Select, test and baseline virus protection products and updates.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(ii) Deploy virus protection products on supported platforms.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(iii) Streamline process for distribution of virus protection product updates.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(iv) Obtain and distribute virus protection product updates.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L b)Implement desktop access control products for all at-risk NASA HQ IT platforms.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L
(i) Select, test and baseline desktop access control products.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L
(ii) Deploy desktop access control products.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L
(iii) Administer desktop access control accounts.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H c) Assess and report quarterly the IT security configuration of network-accessible devices (e.g. SATAN scanning of UNIX machines, routers, NT servers, etc.). [§1.3.2.14]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(i) Establish IT security scanning environment. [§1.3.2.8]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(ii) Perform routine scanning of all network-accessible devices.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(iii) Distribute vulnerability reports and manage rectification.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(iv) Provide IT security support for NASA HQ UNIX desktops.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H
(v) Report findings to the ITSM.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M d) Provide/update sensitivity assessments for all NASA HQ applications for inclusion in DRD 31. [§1.3.2.3]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L e) Provide a IT security review for each of the following category "B" applications. [§1.3.4.1 and 1.3.4.2]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L
(i) Draft and submit a IT security review for NPMS.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L
(ii) Draft and submit a IT security review for ACMS.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L
(iii)Draft and submit a IT security review for COBRA.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L
(iv) Draft and submit a IT security review for T&A.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L
(v) Draft and submit a IT security review for WCS.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H f) Provide an IT security review for each new or significantly modified NASA HQ application or hardware system as part of the PDR/CDR/DRR/ORR process. [§1.3.2.4, 1.3.2.8, 1.3.3.2, 1.3.4.1 and 1.3.4.2]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H g) Review all Class 1 SRs through participation in Change Control Board / Service Request Review Team (CCB/SRRT) meetings, and intervene where appropriate.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M h) Certify all non-legacy servers, both production and developmental. [§1.3.3.2]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M i) Identify risks and recommend mitigations for all dial-up, dedicated and virtual communications links originating or terminating at NASA HQ. [§1.2 and 1.3.2.11]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M
(i) Draft and submit Communications Risk Assessment.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L j) Provide appropriate technical, personnel, administrative, environmental and access safeguards for Boeing IR&MSC systems. [§1.1.1.5]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L k) Ensure that all Boeing IR&MSC information technology resources are adequately protected. [§1.1.1.2]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L l) Provide cost-effective assurance of Boeing IR&MSC system availability, integrity and confidentiality. [§1.1.1.4]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L m) Maintain the continuity of Boeing's automated information support for NASA HQ missions, programs and functions. [§1.1.1.3]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L n) Evaluate and recommend architectural and process initiatives, tools and training to improve the IT security environment of NASA HQ with emphasis on the Tactical Plan. [§1.3.2.8]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L o) Assess emerging technologies and risks, raise awareness of potential IT security threats and issues, suggest additional projects and promote the image of the ITS Program. [§1.3, 1.3.1 and 1.3.2.11]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L p) Monitor the general IT security threat situation, the IT security product market and the usage and effectiveness of IT security products and incident response at NASA HQ; analyze impacts, report trends and recommend process improvements. [§1.3.2.5]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L q) Monitor the in-the-wild virus situation, the virus protection market and the usage and effectiveness of virus protection and virus response at NASA HQ; analyze impacts, report trends and recommend process improvements. [§1.3.2.5]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE -- 11. Respond to security-centric Service Requests (SRs) and Problem Reports (PRs).
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M a) Meet due dates for PRs, SRs and Action Items. [§1.3.2.7 and Metric 2 "ITSM-defined Task/products"]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE -- 12. Respond to ad hoc requests for analytical or technical security support.
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H a) Respond to virus incidents. [§1.3.2.5]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE H b) Analyze potential security threats as directed. [§1.3.2.11]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE L c) Obtain penetration testing by outside firm as directed. [§1.3.2.12]
PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE PRINT ONE M d) Respond to NASA HQ ITS problems, issues and questions dealing with NASA HQ IT systems, software and services. [§1.3.2.7]

* Technical security only; refer to NHCC Security Plan for all else.

Return to the table.

** Technical security only; refer to NHCC and MSFC Amdahl Security Plans for all else.

Return to the table.

Return to the top of the document


6. Application Descriptions

ACMS
Administrative Correspondence Management System.
AMS
Acquisition Management System allows the NASA Headquarters and Centers to create, maintain, and generate reports of the acquisition management document information.
CAPPS
Consolidated Agency Personnel/Payroll System is a comprehensive, agency-wide automated information system used to collect and summarize personnel and payroll related information generated at the NASA Centers. CAPPS is a redesign and redevelopment of the Personnel Management Information System (PMIS). The purpose of the system is to fulfill internal and external requests for NASA agency-wide personnel statistical data.
COBRA
Cost/Obligations Budget Resource Application
CTDS
Consolidated Training & Development System provides warehouse consolidation and ad-hoc query capability, for training data.
ERMP
Energy Resources Management Program provides a uniform method of reporting the energy consumption, reduction, and costs for all NASA Centers, and for budgeting energy-related funds.
FAAD
Federal Assistance Award Data System is used to identify, maintain a master file, and report on all NASA contracts which are currently grants and/or cooperative agreements.
FPDS
Federal Procurement Data System collects procurement information to be reported to a central location, GSA, for use by the Congress, the Executive Branch, and the private sector.
IFMP
Integrated Financial Management Project is an integrated agency accounting and financial management system that includes financial reporting and internal controls and complies with applicable accounting principles, standards, and requirements, as well as with pertinent policies prescribed by the Office of Management and Budget (OMB).
IRIS
Incident Reporting Information System is an automated method for collecting mishap information obtained from the NASA Mishap Report Form 1627 and has been designed to meet the mishap reporting requirements defined in NMI8621.1F dated 12/31/91.
NPMS
NASA Procurement Management System.
NTDS
NASA Training and Development System aids in the management of training and development information for NASA.
T&A
Time & Attendance.
WCS
Work Control System.

Return to the top of the document


7. Acronyms (other than applications)

CCB Change Control Board.
CDR Critical Design Review.
CERT Computer Emergency Response Team.
CIO Chief Information Officer
COTR Contracting Officer's Technical Representative.
CSR Customer Support Representative.
DCE Distributed Computing Environment.
DRD Data Requirements Description
DRRDeployment Readiness Review
HCNHeadquarters Computer Network
HISSHeadquarters Integrated Security System
IR&MSCInformation Resources & Management Support Contract
ITInformation Technology
ITSInformation Technology Security
ITSMInformation Technology Security Manager
LPARLogical Partition
NASIRCNASA Automated System Incident Response Capability
NHBNASA Handbook
NHCCNASA Headquarters Computer Center
NOCNetwork Operations Center
NTNew Technology (Microsoft WinNT)
OMBOffice of Management and Budget
ORROperational Readiness Review
PDRPreliminary Design Review
PRProblem Report
SRService Request
SRRTService Request Review Team
UNIXUni-plexed Information and Computing System (UNICS, a.k.a. UNIX)
WBSWork Breakdown Structure

Return to the top of the document