NASA Logo

NTRS

NTRS - NASA Technical Reports Server

Back to Results
MAVEN Information Security Governance, Risk Management, and Compliance (GRC): Lessons LearnedAs the first interplanetary mission managed by the NASA Goddard Space Flight Center, the Mars Atmosphere and Volatile EvolutioN (MAVEN) had three IT security goals for its ground system: COMPLIANCE, (IT) RISK REDUCTION, and COST REDUCTION. In a multiorganizational environment in which government, industry and academia work together in support of the ground system and mission operations, information security governance, risk management, and compliance (GRC) becomes a challenge as each component of the ground system has and follows its own set of IT security requirements. These requirements are not necessarily the same or even similar to each other's, making the auditing of the ground system security a challenging feat. A combination of standards-based information security management based on the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF), due diligence by the Mission's leadership, and effective collaboration among all elements of the ground system enabled MAVEN to successfully meet NASA's requirements for IT security, and therefore meet Federal Information Security Management Act (FISMA) mandate on the Agency. Throughout the implementation of GRC on MAVEN during the early stages of the mission development, the Project faced many challenges some of which have been identified in this paper. The purpose of this paper is to document these challenges, and provide a brief analysis of the lessons MAVEN learned. The historical information documented herein, derived from an internal pre-launch lessons learned analysis, can be used by current and future missions and organizations implementing and auditing GRC.
Document ID
20140013251
Acquisition Source
Goddard Space Flight Center
Document Type
Conference Paper
Authors
Takamura, Eduardo
(General Dynamics C4 Systems Greenbelt, MD, United States)
Gomez-Rosa, Carlos A.
(NASA Goddard Space Flight Center Greenbelt, MD United States)
Mangum, Kevin
(General Dynamics C4 Systems Greenbelt, MD, United States)
Wasiak, Fran
(General Dynamics C4 Systems Greenbelt, MD, United States)
Date Acquired
October 29, 2014
Publication Date
March 1, 2014
Subject Category
Ground Support Systems And Facilities (Space)
Computer Programming And Software
Report/Patent Number
GSFC-E-DAA-TN13270
Meeting Information
Meeting: 2015 IEEE Aerospace Conference
Location: Big Sky, MT
Country: United States
Start Date: March 7, 2015
End Date: March 14, 2015
Sponsors: American Inst. of Aeronautics and Astronautics, Institute of Electrical and Electronics Engineers, American Society for Electrical Engineers, PHM Society
Funding Number(s)
CONTRACT_GRANT: NNG11VM00C
Distribution Limits
Public
Copyright
Public Use Permitted.
Keywords
FISMA
Risk Management
Ground Systems
MAVEN Lessons Learned
IT Security
No Preview Available