Attachement 1-C-SCRM Questionnaire.xlsx
XLSX spreadsheet 172 KB Posted
- Attached to
- Global Hardware Federal contract opportunity
- Solicitation number
- 19AQMM25B0123
About this file
This is a Cybersecurity Supply Chain Risk Management (C-SCRM) Questionnaire template that vendors must complete as part of RFI 1019530047. The questionnaire consists of three sections: Contact Information, Vendor Risk Management Plan, and Physical and Personnel Security. Section 1 requires basic company information and primary point of contact details. Section 2 focuses on supply chain threat identification, supplier mapping, and SCRM contractual requirements. Section 3 addresses employee background checks, ICT equipment tampering prevention, and insider threat training.
The questionnaire is related to a Department of State RFI (19AQMM25B0123) seeking commercial off-the-shelf hardware solutions for servers and storage to be deployed at hundreds of global sites. Key requirements include transferrable components, efficient RMA process, NIST-certified cryptographic modules, silicon root of trust, and compliance with U.S. government country of origin requirements. Questions were due by February 26 at 3:00 PM Eastern Time, with only complete responses addressing all requirements being considered.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Questions and Responses-Global Hardware-19AQMM25B0123-5 Pages.docx | DOCX document | |
| Attachment 2-DOS Secure Software Development Attestation Form.pdf | ||
| Global Hardware-Request for Information.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
C-SCRM Questionnaire RFI 1019530047 Attachment B
CYBERSECURITY SUPPLY CHAIN RISK MANAGEMENT (C-SCRM) QUESTIONNAIRE
Instructions:
- This worksheet shall be completed by the vendor responsible for submitting the offer. References to "organization" refer to the offering entity. If the offering entity is a joint venture (JV), the response may come from either the JV or from the JV managing partner.
- Provide the requested inputs in the gray shaded lines of the template under column D, Vendor Response, for all Items Numbers for Sections 1-3. Offerors are advised that the Government may request documentation from the Offerors to validate the responses provided.
| SECTION 1 - CONTACT INFORMATION | |||
| ITEM NO. | ITEM DESCRIPTION | VENDOR RESPONSE | |
| 1.1 | Enter the name of your company. | ||
| 1.2 | Enter the name of the primary Point-Of-Contact (POC) for your company that the Government may contact to discuss the vendor inputs on this questionnaire. | ||
| 1.3 | Enter the job title of the primary POC. | ||
| 1.4 | Enter the phone number of the primary POC in the following format: (555) 555-5555 | ||
| 1.5 | Enter the e-mail address of the primary POC. | ||
| SECTION 2 VENDOR RISK MANAGEMENT PLAN | |||
| ITEM NO. | ITEM DESCRIPTION | VENDOR RESPONSE | NIST SP 800-53 Reference |
tc={AFA5E90D-3D54-4947-81FB-735479B2BB30}: [Threaded comment]
Your version of Excel allows you to read this threaded comment; however, any edits to it will get removed if the file is opened in a newer version of Excel. Learn more: https://go.microsoft.com/fwlink/?linkid=870924
Comment:
Recommend deleting as it confuses vendors as some think they have to comply with these references but that is not the case, they have to comply with the question. Or we need to explain in another column how these relate to the question and what is the expectation of these references.
2.1 Does your organization identify its key supply chain threats? (Note: if you do not have suppliers, answer "Yes") tc={6A5E4123-E4EF-41C5-8FFB-8CC13C11DA22}: [Threaded comment]
Your version of Excel allows you to read this threaded comment; however, any edits to it will get removed if the file is opened in a newer version of Excel. Learn more: https://go.microsoft.com/fwlink/?linkid=870924
Comment:
| Red = new addition. | IR-8, SR-7 | |||
| 2.2 | Does your organization map key suppliers to your supply chain threats? (Note: if you do not have suppliers, answer "Yes") | IR-8, SR-7 | ||
| 2.3 | Does your organization have written SCRM requirements in contracts with your key suppliers? (Note: if you do not have suppliers, answer "Yes") | SA-4 | ||
| 2.4 | Does your organization verify that your suppliers meet SCRM requirements through contractual terms and conditions? (Note: if you do not have suppliers, answer "Yes") | SR-6 | ||
| SECTION 3 PHYSICAL AND PERSONNEL SECURITY | ||||
| ITEM NO. | ITEM DESCRIPTION | VENDOR RESPONSE | NIST SP 800-53 Reference |
tc={BFDD9C36-E00E-441A-AFAD-7712E4E33373}: [Threaded comment]
Your version of Excel allows you to read this threaded comment; however, any edits to it will get removed if the file is opened in a newer version of Excel. Learn more: https://go.microsoft.com/fwlink/?linkid=870924
Comment:
Same comment as above.
tc={6A5E4123-E4EF-41C5-8FFB-8CC13C11DA22}: [Threaded comment]
Your version of Excel allows you to read this threaded comment; however, any edits to it will get removed if the file is opened in a newer version of Excel. Learn more: https://go.microsoft.com/fwlink/?linkid=870924
Comment:
Red = new addition.
tc={AFA5E90D-3D54-4947-81FB-735479B2BB30}: [Threaded comment]
Your version of Excel allows you to read this threaded comment; however, any edits to it will get removed if the file is opened in a newer version of Excel. Learn more: https://go.microsoft.com/fwlink/?linkid=870924
Comment:
Recommend deleting as it confuses vendors as some think they have to comply with these references but that is not the case, they have to comply with the question. Or we need to explain in another column how these relate to the question and what is the expectation of these references. 3.1 Does your organization have policies for conducting background checks of your employees as permitted by the country in which your organization operates? No PE-2, PE-3
PS-3
3.2 Does your organization have procedures in place to prevent tampering of Information and Communications Technology (ICT) equipment stored as supply chain inventory? SR-9
AC-1
3.3 Do you provide literacy training on recognizing and reporting potential indicators of insider threat? AT-2(2)
&"Calibri"&11&K000000_x000D_&1#&"Times New Roman"&10&K000000SENSITIVE BUT UNCLASSIFIED
Data (HIDE)
| Status | Score | Status | Not Reviewed | Yes | No | Not Applicable | Alternative | Total |
| ERROR:#REF! | ERROR:#REF! | Counts | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! |
| Pct | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! | ERROR:#REF! |
&"Calibri"&11&K000000_x000D_&1#&"Times New Roman"&10&K000000SENSITIVE BUT UNCLASSIFIED
Counts Not Reviewed Yes No Not Applicable Alternative 0 0 0 0 0
DL (HIDE)
| GWACS | Pool | Implementation Status | Answer |
| Alliant/ Alliant 2 | Small Business (SB) Pool | Satisfied | Yes |
| Alliant SB | HUBZone SB (HUBZone) Pool | Partially Satisfied | No |
| 8(a) STARS II | Women Owned SB (WOSB) Pool | Not Satisfied | |
| VETS/ VETS2 | Other | Not Applicable | |
| TBD | |||
| Not Reviewed |
&"Calibri"&11&K000000_x000D_&1#&"Times New Roman"&10&K000000SENSITIVE BUT UNCLASSIFIED
File details come from the government source that posted it. Updated .