47QFLA24R0013_RFP Attachment 10_GREAT Support SCRM Questionaire_2024 10 31.xlsx

XLSX spreadsheet 225 KB Posted

Attached to
Graduate Research, Education and Technology (GREAT) Support Federal contract opportunity
Solicitation number
47QFLA24R0013
Issued by
General Services Administration Federal Acquisition Service Assisted Acquisition Services Region 4

About this file

This file is a Cyber-Supply Chain Risk Management (C-SCRM) Questionnaire template that vendors must complete as part of RFP 47QFLA24R0013 for GREAT Support services at the Air Force Institute of Technology (AFIT). The questionnaire consists of four main sections: Contact Information, Vendor Risk Management Plan, Cybersecurity, and Physical and Personnel Security. Vendors must provide responses about their supply chain security practices, including how they manage key suppliers, verify TAA/MIA compliance, handle cybersecurity threats, conduct background checks, and prevent tampering of ICT equipment.

The questionnaire requires supporting documentation for specific questions, including SCRM contractual requirements with suppliers (2.4), a table of contents for the vendor's SCRM Plan (2.5), and background check policies (4.2). The document specifies that for joint ventures, responses can come from either the JV or the JV managing partner. This is part of a larger solicitation for AFIT educational and research support services, particularly in areas such as high-powered lasers, optics, remote sensing, cyberspace, and other advanced technologies.

View the file

Other files for this federal contract opportunity

Other files attached to Graduate Research, Education and Technology (GREAT) Support, newest first.
File Type Posted
47QFLA24R0013 Amend 6_GREAT Support RFP Appendix 1_Solicitation Sections K-M_2024 12 30.docx DOCX document
47QFLA24R0013 Amend 5_GREAT Support RFP Appendix 1_Solicitation Sections K-M_2024 12 30.docx DOCX document
47QFLA24R0013 Amend 3_RFP Attachment 8_GREAT Support Question Answer_Govt Response_2024 12 13.xlsx XLSX spreadsheet
47QFLA24R0013 Amend 2_GREAT Support RFP Appendix 1_Solicitation Sections K-M_2024 12 09.docx DOCX document
47QFLA24R0013 Amend 2_GREAT Support PWS_Solicitation Sections A-J_2024 12 09.docx DOCX document
47QFLA24R0013_RFP Attachment 8_GREAT Support Questions_Govt Responses_2024 12 09.xlsx XLSX spreadsheet
47QFLA24R0013 Amd 1_RFP Attachment 8_GREAT Support Question_Answer Template_2024 12 03 Govt Responses.xlsx XLSX spreadsheet
47QFLA24R0013_GREAT Support PWS_Solicitation Sections A-J_2024 11 14.docx DOCX document
47QFLA24R0013_RFP Attachment 3_GREAT Support Non-Disclosure Agreement Certification__2024 10 24.docx DOCX document
47QFLA24R0013_RFP Attachment 9_GREAT Support Travel Expense Sheet Template_2024 10 31.xlsx XLSX spreadsheet
47QFLA24R0013_RFP Attachment 2_GREAT Support DRAFT DD254 w SCI Add_2024 09 23.pdf PDF
47QFLA24R0013_GREAT Support RFP Appendix 1_Solicitation Sections K-M_2024 11 14.docx DOCX document
47QFLA24R0013_RFP Attachment 1_GREAT Support Pricing Sheet_2024 10 22.xlsx XLSX spreadsheet
47QFLA24R0013_RFP Attachment 4_GREAT Support Consent to Purchase CTP Template_2024 10 24.xlsx XLSX spreadsheet
47QFLA24R0013_RFP Attachment 5_GREAT Support Key Personnel Qualification Worksheet _ 2024 11 13.docx DOCX document
47QFLA24R0013_RFP Attachment 6_ GREAT Support OCI Statement Template_2024 10 26.docx DOCX document
47QFLA24R0013_RFP Attachment 7_GREAT Support QASP_2024 11 3.docx DOCX document
47QFLA24R0013_RFP Attachment 8_GREAT Support Question_Answer Template_2024 10 31.xlsx XLSX spreadsheet
Show all 18

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Instructions

CYBER-SUPPLY CHAIN RISK MANAGEMENT (C-SCRM) QUESTIONNAIRE
Version 1.10 - 2023-02-15
INSTRUCTIONS
INTRODUCTION:
U.S. adversaries have attacked our nation's supply chains and compromised Federal Government systems, capitalizing on security weaknesses in U.S. companies and third party affiliates. It is incumbent on GSA's industrial base to implement vigilant Supply Chain Risk Management (SCRM) procedures. The Government is requesting that interested parties complete the SCRM Plan Security Posture Questionnaire in the format provided and in accordance with the instructions of the solicitation.

QUESTIONNAIRE COMPLETION INSTRUCTIONS:

● Provide a contact (name, title, offeror name, phone number, and e-mail address) for questions, support, or additional information related to the questionnaire to the respondents.
● GSA recommends designating one primary Point-Of-Contact (POC) from the offeror who will collaborate with the appropriate POCs/teams/vendor/supplier to coordinate and collect and compile responses for each section. The appropriate POCs within each organization will vary and may consist of individuals in information technology, acquisition, procurement, supply chain, or security offices. While related, each section is designed to be relevant to a different aspect of the offeror.
● Provide your responses in the gray shaded lines of the template under Column D, Vendor Response.
● The questions must be answered for the offeror. References to "organization" refer to the offering entity. If proposing as a joint venture (JV), the response can come from either the JV or from the JV managing partner.
● For Questions 2.4, 2.5, and 4.2, the supporting documentation must be submitted in accordance with the instructions in the solicitation and this questionnaire.

Questionnaire

CYBER-SUPPLY CHAIN RISK MANAGEMENT (C-SCRM) QUESTIONNAIRE

Status: Not Started
SECTION 1CONTACT INFORMATIONVENDOR RESPONSEADDITIONAL INFORMATION (IF REQUIRED)
1.1Enter the name of the primary Point-Of-Contact (POC) for the offeror.
1.2Enter the job title of the primary POC for the offeror.
1.3Enter the name of the offeror.
1.4Enter the phone number of the primary POC for the offeror in the following format: (555) 555-5555
1.5Enter the E-mail Address of the primary POC for the offeror.

SECTION 2 VENDOR RISK MANAGEMENT PLAN NIST SP 800-53 Reference FAR Clause

2.1 Does your organization identify key suppliers as related to supply chain threats? IR-8: Incident Response Plan SR-7: Supply Chain Operations Security

2.2Does your organization assess and review supplier risk to include Foreign Ownership, Control and Influence of suppliers and subcontractors prior to entering a contractual relationship?SR-6: Supplier Assessments and Reviews
2.3Does your organization verify that your suppliers meet SCRM requirements through contractual terms and conditions?SR-3: Supply Chain Controls and Processes
2.4Does your organization have written SCRM requirements in contracts with your suppliers?

Special Instruction: Provide supporting documentation containing the SCRM requirements used in contractual terms and conditions with your suppliers. SA-4: Acquisition Process SR-5: Acquisition Strategies, Tools, and Methods

2.5 Will your organization have a SCRM Plan that aligns with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-161, Supply Chain Risk Management Practices for Federal Information Systems and Organizations as required by the RFP?

Special Instruction: Provide supporting documentation containing a table of contents for your SCRM Plan (this can be either extracted separately from the current plan or created for purposes of this submission). SR-1: Policy and Procedures SR-2: Supply Chain Risk Management Plan

2.6 Does your organization confirm 100% of your suppliers of critical Information and Communication Technology (ICT) products and services are TAA/MIA compliant? FAR 52.225-1 Buy American FAR 52.225-5 Trade Agreements

SECTION 3 CYBERSECURITY NIST SP 800-53 Control FAR Clause

3.1 Does your organization have a policy or procedure to identify information consistent with its classification in accordance with applicable legal, regulatory, or internal sensitivity requirements (CUI, classified information, etc)? RA-2: Security Categorization MP-7: Media Use

3.2 Does your organization include contractual obligations to protect information and information systems handled by your suppliers? FAR 52.204-2 Security Requirements FAR 52.204-21 Basic Safeguarding of Covered Contractor Info. Systems

3.3 Does your organization have documented procedures to detect cybersecurity threats and attacks? IR-5: Incident Monitoring RA-5: Vulnerability Monitoring and Scanning

3.4 Does your organization have a documented procedure(s) to respond to and recover from cybersecurity threats and attacks? IR-8: Incident Response Plan RA-7: Risk Response

3.5 Does your organization have personnel designated to respond to cybersecurity incidents? IR-4: Incident Handling

SECTION 4 PHYSICAL AND PERSONNEL SECURITY NIST SP 800-53 Control FAR Clause

4.1 Does your organization have a documented Security Incident Response process covering physical security incidents? (e.g., potential intruder access, missing equipment, etc.)? PE-1: Policy and Procedures PS-1: Policy and Procedures

4.2 Does your organization have policies for conducting background checks of your employees as permitted by the country in which your organization operates?

Special Instruction: Provide supporting documentation containing the policy/policies for conducting background checks. If this is part of a larger document, the specific policy/policies related to background checks may be extracted separately. PE-2: Physical Access Authorizations PE-3: Physical Access Control PS-3: Personnel Screening

4.3 Does your organization have procedures in place to prevent tampering of Information and Communications Technology (ICT) equipment stored as supply chain inventory? SR-9: Tamper Resistance and Detection AC-1: Policy and Procedures

4.4 Does your organization have procedures in place for the prevention and detection of insider threats? PM-12: Insider Threat Program

Data (HIDE)

StatusScoreStatusNot ReviewedYesNoNot ApplicableAlternativeTotal
No Completed0%Counts15000015
Pct100%0%0%0%0%100%

Counts Not Reviewed Yes No Not Applicable Alternative 15 0 0 0 0

DL (HIDE)

GWACSPoolImplementation StatusAnswer
Alliant/ Alliant 2Small Business (SB) PoolSatisfiedYes
Alliant SBHUBZone SB (HUBZone) PoolPartially SatisfiedNo
8(a) STARS IIWomen Owned SB (WOSB) PoolNot Satisfied
VETS/ VETS2OtherNot Applicable
TBD
Not Reviewed

image1.png

File details come from the government source that posted it. Updated .