Exhibit 10 - Commercial Architecture Security Questionnaire (QASQ).xlsx
Excel26 KBJun 10, 2026
The document, RFP 80GSFC26R0011, is a COMSATCOM IA Questionnaire outlining comprehensive information assurance and cybersecurity requirements for space systems, specifically focusing on National Institute of Standards and Technology Special Publication 800-53, Revision 5. It details controls across various domains, including Access Control (account management, separation of duties, unsuccessful logon attempts, remote access, system use notification), Awareness and Training (security awareness, role-based security training), Audit and Accountability (audit events, review, reduction, protection), Security Assessment (security assessments, interconnections, plans of action and milestones, continuous monitoring), Configuration Management (baseline configuration, change control, settings, component inventory), Contingency Planning (contingency plan, backup), Identification and Authentication, Incident Response (training, testing, handling, monitoring, reporting), Maintenance, Physical and Environmental Protection (physical access, alternate work site, monitoring), Personnel Security (screening, transfer, termination), Risk Assessment (risk assessment, vulnerability scanning), System and Service Acquisition (security engineering), System and Communications Protection (boundary protection, transmission confidentiality, cryptographic key management, session authenticity), and System and Information Integrity (cryptographic protection, protection of information at rest, flaw remediation, malicious code protection, security alerts). The RFP requires vendors to describe how their proposed solutions address these detailed security concerns for space systems, including ground stations, control links, voice communications, interference identification, spacecraft, operators, and TT&C stations.