Attachement 1-C-SCRM Questionnaire.xlsx

XLSX spreadsheet 172 KB Posted

Attached to
UNIFIED PLATFORM FOR DATA ANALYTICS, SECURITY, AND MONITORING Federal contract opportunity
Solicitation number
19AQMM25B0114
Issued by
Department of State Office of Acquisition Management

About this file

This is a Cybersecurity Supply Chain Risk Management (C-SCRM) Questionnaire template that vendors must complete as part of RFI 1019530047 for the Department of State's Unified Platform for Data Analytics, Security, and Monitoring opportunity. The questionnaire consists of three sections: Contact Information, Vendor Risk Management Plan, and Physical and Personnel Security.

The template requires vendors to provide company details and point of contact information in Section 1, answer questions about supply chain threat identification and supplier management in Section 2, and address physical/personnel security measures in Section 3. Specific areas of assessment include background check policies, ICT equipment tampering prevention procedures, and insider threat training. While NIST SP 800-53 references are included, they appear to be for reference only and do not constitute compliance requirements. This is a data collection template that does not itself specify products or services to be delivered.

View the file

Other files for this federal contract opportunity

Other files attached to UNIFIED PLATFORM FOR DATA ANALYTICS, SECURITY, AND MONITORING, newest first.
File Type Posted
Attachment 2-DOS Secure Software Development Attestation Form.pdf PDF
Unified Data Analytics and Security RFI.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

C-SCRM Questionnaire RFI 1019530047 Attachment B

CYBERSECURITY SUPPLY CHAIN RISK MANAGEMENT (C-SCRM) QUESTIONNAIRE

Instructions:

- This worksheet shall be completed by the vendor responsible for submitting the offer. References to "organization" refer to the offering entity. If the offering entity is a joint venture (JV), the response may come from either the JV or from the JV managing partner.

- Provide the requested inputs in the gray shaded lines of the template under column D, Vendor Response, for all Items Numbers for Sections 1-3. Offerors are advised that the Government may request documentation from the Offerors to validate the responses provided.

SECTION 1 - CONTACT INFORMATION
ITEM NO.ITEM DESCRIPTIONVENDOR RESPONSE
1.1Enter the name of your company.
1.2Enter the name of the primary Point-Of-Contact (POC) for your company that the Government may contact to discuss the vendor inputs on this questionnaire.
1.3Enter the job title of the primary POC.
1.4Enter the phone number of the primary POC in the following format: (555) 555-5555
1.5Enter the e-mail address of the primary POC.
SECTION 2 VENDOR RISK MANAGEMENT PLAN
ITEM NO.ITEM DESCRIPTIONVENDOR RESPONSENIST SP 800-53 Reference

tc={AFA5E90D-3D54-4947-81FB-735479B2BB30}: [Threaded comment]

Your version of Excel allows you to read this threaded comment; however, any edits to it will get removed if the file is opened in a newer version of Excel. Learn more: https://go.microsoft.com/fwlink/?linkid=870924

Comment:

Recommend deleting as it confuses vendors as some think they have to comply with these references but that is not the case, they have to comply with the question. Or we need to explain in another column how these relate to the question and what is the expectation of these references.

2.1 Does your organization identify its key supply chain threats? (Note: if you do not have suppliers, answer "Yes") tc={6A5E4123-E4EF-41C5-8FFB-8CC13C11DA22}: [Threaded comment]

Your version of Excel allows you to read this threaded comment; however, any edits to it will get removed if the file is opened in a newer version of Excel. Learn more: https://go.microsoft.com/fwlink/?linkid=870924

Comment:

Red = new addition.IR-8, SR-7
2.2Does your organization map key suppliers to your supply chain threats? (Note: if you do not have suppliers, answer "Yes")IR-8, SR-7
2.3Does your organization have written SCRM requirements in contracts with your key suppliers? (Note: if you do not have suppliers, answer "Yes")SA-4
2.4Does your organization verify that your suppliers meet SCRM requirements through contractual terms and conditions? (Note: if you do not have suppliers, answer "Yes")SR-6
SECTION 3 PHYSICAL AND PERSONNEL SECURITY
ITEM NO.ITEM DESCRIPTIONVENDOR RESPONSENIST SP 800-53 Reference

tc={BFDD9C36-E00E-441A-AFAD-7712E4E33373}: [Threaded comment]

Your version of Excel allows you to read this threaded comment; however, any edits to it will get removed if the file is opened in a newer version of Excel. Learn more: https://go.microsoft.com/fwlink/?linkid=870924

Comment:

Same comment as above.

tc={6A5E4123-E4EF-41C5-8FFB-8CC13C11DA22}: [Threaded comment]

Your version of Excel allows you to read this threaded comment; however, any edits to it will get removed if the file is opened in a newer version of Excel. Learn more: https://go.microsoft.com/fwlink/?linkid=870924

Comment:

Red = new addition.

tc={AFA5E90D-3D54-4947-81FB-735479B2BB30}: [Threaded comment]

Your version of Excel allows you to read this threaded comment; however, any edits to it will get removed if the file is opened in a newer version of Excel. Learn more: https://go.microsoft.com/fwlink/?linkid=870924

Comment:

Recommend deleting as it confuses vendors as some think they have to comply with these references but that is not the case, they have to comply with the question. Or we need to explain in another column how these relate to the question and what is the expectation of these references. 3.1 Does your organization have policies for conducting background checks of your employees as permitted by the country in which your organization operates? No PE-2, PE-3

PS-3

3.2 Does your organization have procedures in place to prevent tampering of Information and Communications Technology (ICT) equipment stored as supply chain inventory? SR-9

AC-1

3.3 Do you provide literacy training on recognizing and reporting potential indicators of insider threat? AT-2(2)

&"Calibri"&11&K000000_x000D_&1#&"Times New Roman"&10&K000000SENSITIVE BUT UNCLASSIFIED

Data (HIDE)

StatusScoreStatusNot ReviewedYesNoNot ApplicableAlternativeTotal
ERROR:#REF!ERROR:#REF!CountsERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!
PctERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!

&"Calibri"&11&K000000_x000D_&1#&"Times New Roman"&10&K000000SENSITIVE BUT UNCLASSIFIED

Counts Not Reviewed Yes No Not Applicable Alternative 0 0 0 0 0

DL (HIDE)

GWACSPoolImplementation StatusAnswer
Alliant/ Alliant 2Small Business (SB) PoolSatisfiedYes
Alliant SBHUBZone SB (HUBZone) PoolPartially SatisfiedNo
8(a) STARS IIWomen Owned SB (WOSB) PoolNot Satisfied
VETS/ VETS2OtherNot Applicable
TBD
Not Reviewed

&"Calibri"&11&K000000_x000D_&1#&"Times New Roman"&10&K000000SENSITIVE BUT UNCLASSIFIED

File details come from the government source that posted it. Updated .