Effective Date: September 22, 2009
Expiration Date: September 22, 2022
|Update to comply with 1400 Compliance, with administrative changes, updated roles, responsibilities and objectives of continuity of operations as specified by the National Continuity Policy, the NCPIP and the referenced FCDs and other authoritative documents. In addition, this document specifically identifies the Associate Deputy Administrator as the Agency Continuity Coordinator|
|Update to comply with 1400 Compliance, with administrative changes, updated roles, responsibilities and objectives of continuity of operations. Correct citing format. Added other applicability statements in section 2. Added Attachment B. Acronyms.|
It is NASA Policy to:
a. In accordance with the Presidential Policy Directive (PPD), 40, is NASA policy to ensure that the Agency maintains a comprehensive and effective continuity capability composed of programs designed to ensure the continuous performance of essential functions under all conditions.
b. NASA maintains a comprehensive and effective continuity capability by:
(1) Implementing continuity of operations (COOP) plans developed on the four foundations of continuity planning and program management: leadership, staff, communications/technology, and facilities.
(2) Establishing orders of succession and preplanned delegation and devolution of authorities that ensure an orderly predefined transition of leadership and delegation of authority within the Agency.
(3) Identifying and establishing procedures to ensure vital resources, facilities, and records are safeguarded, available, and accessible to support continuity of operations.
(4) Identifying provisions for the acquisition of necessary resources to maintain continuity of operations in an emergency situation.
(5) Identifying and obtaining redundant critical communications capabilities at primary and alternate sites and in transit to ensure the performance of essential functions.
(6) Identifying the components, processes, and requirements for the identification, training, and preparedness of personnel capable of relocating to alternate facilities to support the continuation of essential functions.
(7) Establishing alert and notification procedures for continuity and non-continuity personnel.
(8) Evaluating all NASA Critical Infrastructure (NCI) for mission criticality using a risk management approach to include information technology (IT), communications, and other facilities on which those assets depend (e.g., data, power, water, oil, gas, environmental controls, transportation, safety, and security). These requirements are established in NPR 1040.1 and referenced in national-level documents.
(9) Ensuring that essential management functions of Agency and Center criticaloperations are included under COOP planning.
(10) Developing provisions to attain operational capability at continuity sites within 12 hours of activation of COOP plans and sustain for up to 30 days.
(11) Focusing on reciprocal alternate COOP site operations at other NASA Centers and with international partners with whom NASA shares operational site capabilities.
(12) Reviewing and testing established COOP plans and IT systems contingency plans annually to ensure a viable plan.
(13) Ensuring that adequate resources are made available to maintain a viable and executable COOP capability.
(14) Establishing provisions for reconstitution capabilities that allow for recovery from a catastrophic emergency and resumption of normal operations.
(15) Ensuring that NASA information is protected, handled, and commensurate with the national security classification level, sensitivity, value, and criticality in accordance with NPR 1600.2; NPR 2190.1; and NPR 2810.1.
(16) Ensuring any records created during this process be managed and dispositioned according to NPR 1441.1.
a. This NPD is applicable to NASA Headquarters and NASA Centers, including Component Facilities and Technical and Service Support Centers. This language applies to the Jet Propulsion Laboratory a Federally-Funded Research and Development Center), other contractors, grant recipients, or parties to agreements only to the extent specified or referenced in the appropriate contracts, grants, or agreements.
b. In this directive, all mandatory actions (i.e., requirements) are denoted by statements containing the term "shall." The terms: "may" or "can" denote discretionary privilege or permission, "should" denotes a god practice and is recommended, but not required, "will" denotes expected outcome, and "are/is" denotes descriptive material.
c. In this directive, "Agency-level directives" refers to directives with Agency-wide applicability (e.g., NPDs, NPRs, NIDs).
d. In this directive, "NASA directives' refers to both Agency-level and Center-level directives.
e. In this directive, all document citations are assumed to be the last version unless otherwise noted.
f. This directive is applicable to NASA directives developed or revised after the effective date of the NPD.
a. National Aeronautics and Space Act of 1958, as amended, 51 U.S.C. 2473(c)(1).
b. Telework Enhancement Act of 2010, 5 U.S.C. §§ 6501-6506.
c. Executive Order (EO) 12148, Federal Emergency Management, 3 CFR 412 (1979), as amended by EO 12919, National Defense Industrial Resources Preparedness, 3 CFR 901 (1994).
d. EO 13618, Assignment of National Security and Emergency Preparedness Communications Functions, July 6, 2012.
e. PPD 21, Critical Infrastructure Security and Resilience, February 12, 2013.
f. Federal Continuity Directive (FCD) 1. U.S. Department of Homeland Security Federal Emergency Management Agency, January 17, 2017.
a. NPR 1040.1, NASA Continuity of Operations (COOP) Planning Procedural Requirements.
b. NPR 1441.1, NASA Records Management Program Requirements.
c. NPR 1600.2, NASA Classified National Security Information.
d. NPR 2190.1, NASA Export Control Program.
e. NPR 2810.1, Security of Information Technology.
f. PPD 40, National Continuity Policy, July 15, 2016.
a. As directed by the National Continuity Policy, the NASA Administrator shall ensure that COOP planning is implemented, maintained, and tested throughout the Agency.
b. The Agency Continuity Coordinator (ACC) is responsible for:
(1) Reporting to the Administrator on Agency-wide continuity capabilities and planning.
(2) Ensuring that the NASA Centers (including Component Facilities under their cognizance) implement this policy directive and NPR 1040.1 as appropriate and that appropriate provisions are included in applicable contracting instruments through the contracting officers.
c. The Agency Continuity Manager (ACM) is responsible for:
(1) The functional management of the COOP process and for implementing, managing, and monitoring participation in and compliance with this directive, NPR 1040.1, and national level directives and guidance.
(2)The day-to-day management of the continuity programs and for monitoring the direction, guidance, and best practices of both government and the private sector to ensure the development of the most relevant and robust continuity programs.
d. Center Directors and the Executive Director of Headquarters Operations are responsible for the appropriate implementation of this policy directive and NPR 1040.1 within their respective Centers, including Component Facilities.
e. The Chief Information Officer will ensure the proper evaluation of NASA IT systems needed for the implementation of COOP plans.
f. NASA program managers are responsible for evaluating their program functions, primary or supporting IT communications systems, and other interdependencies for possible COOP implementation.
In assessing whether NASA complies with current regulations, the NASA Office of Protective Services will do the following:
a. Utilize a modified version of the Federal Emergency Management Agency (FEMA) Federal Continuity Evaluation tool to assess continuity plans and readiness at Centers and Component Facilities.
b. Ensure the assessment focuses on evaluating Center continuity programs, plans, and procedures and establish a baseline for demonstrating the extent to which a Center will implement, test, and train personnel under their continuity plans and procedures.
c. Have each Center submit to the ACM each January 30th a certification memo signed by the Center Director or a designee that the Center maintains a continuity plan, the date of plan signature and that the Center participated in an annual exercise that incorporated the deliberate and preplanned movement of continuity personnel to an alternate site and the date of the last exercise.
d. The certification memo shall cover the preceding year from January 1st to December 31st.
NPD 1040.4A, NASA Continuity of Operations (COOP) dated, September 22, 2009.Revalidated on July 26, 2017 original signed by
a. HSPD 7, Critical Infrastructure Identification, Prioritization and Protection (2003).
b. NSPD 46/HSPD 15, Annex II, U.S. Strategy and Policy in the War on Terror (2006).
c. NPD 1000.3, NASA Organization.
d. NPR 1441.1, NASA Records Retention Schedules.
e. NPD 8710.1, Emergency Preparedness Program.
f. NPR 8715.2, NASA Emergency Preparedness Procedural Requirements.
g. DHS FEMA Federal Continuity Directives 1 and 2, Federal Executive Branch Continuity of Operations (2008).ATTACHMENT B. ACRONYMS
AAC Agency Continuity Coordinator
ACM Agency Continuity Manager
EO Executive Order
FCD Federal Continuity Directive
FFRDC Federally Funded Research and Development Center
IT Information technology
COOP NASA Continuity of Operations
NCI NASA Critical Infrastructure
PPD Presidential Policy Directive