Attachment 12 - C-SCRM Questionnaire (Template).xlsx
XLSX spreadsheet 79 KB Posted
- Attached to
- GSA Global Supply OCONUS Logistics Support Solutions CENTCOM Federal contract opportunity
- Solicitation number
- 47QSCC23R0040
- Issued by
- GSA Federal Acquisition Service
About this file
This document contains a Cyber-Supply Chain Risk Management (C-SCRM) questionnaire template for federal contractors. The questionnaire includes four sections addressing contact information, vendor risk management plans, cybersecurity practices, and physical and personnel security. Contractors are to provide responses to 15 questions within these sections, with supporting documentation required for certain questions related to SCRM plans, SCRM contractual requirements, and background check policies. The questionnaire appears to be part of the solicitation process for opportunity number 47QSCC23R0040, a contract with the GSA Federal Acquisition Service to provide global supply and logistics support solutions for CENTCOM.
View the file
Other files for this federal contract opportunity
Show all 22
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Instructions
| CYBER-SUPPLY CHAIN RISK MANAGEMENT (C-SCRM) QUESTIONNAIRE |
| Version 1.01 - 2022-09-23 |
| INSTRUCTIONS |
| INTRODUCTION: |
| U.S. adversaries have attacked our nation's supply chains and compromised Federal Government systems, capitalizing on security weaknesses in U.S. companies and third party affiliates. It is incumbent on GSA's industrial base to implement vigilant Supply Chain Risk Management (SCRM) procedures. The Government is requesting that interested parties complete the SCRM Plan Security Posture Questionnaire in the format provided and in accordance with the instructions of the solicitation. |
QUESTIONNAIRE COMPLETION INSTRUCTIONS:
| ● Provide a contact (name, title, offeror name, phone number, and e-mail address) for questions, support, or additional information related to the questionnaire to the respondents. |
| ● GSA recommends designating one primary Point-Of-Contact (POC) from the offeror who will collaborate with the appropriate POCs/teams/vendor/supplier to coordinate and collect and compile responses for each section. The appropriate POCs within each organization will vary and may consist of individuals in information technology, acquisition, procurement, supply chain, or security offices. While related, each section is designed to be relevant to a different aspect of the offeror. |
| ● Provide your responses in the gray shaded lines of the template under Column D, Vendor Response. |
| ● The questions must be answered for the offeror. References to "organization" refer to the offering entity. If proposing as a joint venture (JV), the response can come from either the JV or from the JV managing partner. |
| ● For Questions 2.4, 2.5, and 4.2, the supporting documentation must be submitted in accordance with the instructions in the solicitation and this questionnaire. |
Questionnaire
CYBER-SUPPLY CHAIN RISK MANAGEMENT (C-SCRM) QUESTIONNAIRE
| Status: Not Started | |||
| SECTION 1 | CONTACT INFORMATION | VENDOR RESPONSE | ADDITIONAL INFORMATION (IF REQUIRED) |
| 1.1 | Enter the name of the primary Point-Of-Contact (POC) for the offeror. |
| 1.2 | Enter the job title of the primary POC for the offeror. |
| 1.3 | Enter the name of the offeror. |
| 1.4 | Enter the phone number of the primary POC for the offeror in the following format: (555) 555-5555 |
| 1.5 | Enter the E-mail Address of the primary POC for the offeror. |
SECTION 2 VENDOR RISK MANAGEMENT PLAN NIST SP 800-53 Reference FAR Clause
| 2.1 | Does your organization identify key suppliers as related to supply chain threats? | IR-8, SR-7 | |
| 2.2 | Does your organization confirm 100% of your suppliers of critical Information and Communication Technology (ICT) products and services are TAA/MIA compliant? | FAR 52.225-1 |
FAR 52.225-5
| 2.3 | Does your organization assess and review supplier risk to include Foreign Ownership, Control and Influence of suppliers and subcontractors prior to entering a contractual relationship? | SR-6 |
| 2.4 | Will your organization have a SCRM Plan that aligns with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-161, Supply Chain Risk Management Practices for Federal Information Systems and Organizations as required by the RFP? |
| Special Instruction: Provide supporting documentation containing a table of contents for your SCRM Plan (this can be either extracted separately from the current plan or created for purposes of this submission). | SR-1 / SR-2 | |
| 2.5 | Does your organization have written SCRM requirements in contracts with your suppliers? |
| Special Instruction: Provide supporting documentation containing the SCRM requirements used in contractual terms and conditions with your suppliers. | SA-4 | ||
| 2.6 | Does your organization verify that your suppliers meet SCRM requirements through contractual terms and conditions? | SR-3 |
SECTION 3 CYBERSECURITY NIST SP 800-53 Control FAR Clause
| 3.1 | Does your organization have a policy or procedure to identify information consistent with its classification in accordance with applicable legal, regulatory, or internal sensitivity requirements (CUI, classified information, etc)? | NIST SP 800-60 volume 1 and 2, FIPS 199 | |
| 3.2 | Does your organization include contractual obligations to protect information and information systems handled by your suppliers? | FAR 52.204-2 |
FAR 52.204-21
| 3.3 | Does your organization have documented procedures to detect cybersecurity threats and attacks? | RA-5 |
| 3.4 | Does your organization have a documented procedure(s) to respond to and recover from cybersecurity threats and attacks? | IR-1 |
| 3.5 | Does your organization have personnel designated to respond to cybersecurity incidents? | IR-4 |
SECTION 4 PHYSICAL AND PERSONNEL SECURITY NIST SP 800-53 Control FAR Clause
4.1 Does your organization have a documented Security Incident Response process covering physical security incidents? (e.g., potential intruder access, missing equipment, etc.)? PE-1
PS-1
4.2 Does your organization have policies for conducting background checks of your employees as permitted by the country in which your organization operates?
Special Instruction: Provide supporting documentation containing the policy/policies for conducting background checks. If this is part of a larger document, the specific policy/policies related to background checks may be extracted separately. PE-2, PE-3
PS-3
4.3 Does your organization have procedures in place to prevent tampering of Information and Communications Technology (ICT) equipment stored as supply chain inventory? SR-9
AC-1
4.4 Does your organization have procedures in place for the prevention and detection of insider threats? PM-12
Data (HIDE)
| Status | Score | Status | Not Reviewed | Yes | No | Not Applicable | Alternative | Total |
| No Completed | 0% | Counts | 15 | 0 | 0 | 0 | 0 | 15 |
| Pct | 100% | 0% | 0% | 0% | 0% | 100% |
Counts Not Reviewed Yes No Not Applicable Alternative 15 0 0 0 0
DL (HIDE)
| GWACS | Pool | Implementation Status | Answer |
| Alliant/ Alliant 2 | Small Business (SB) Pool | Satisfied | Yes |
| Alliant SB | HUBZone SB (HUBZone) Pool | Partially Satisfied | No |
| 8(a) STARS II | Women Owned SB (WOSB) Pool | Not Satisfied | |
| VETS/ VETS2 | Other | Not Applicable | |
| TBD | |||
| Not Reviewed |
image1.png
File details come from the government source that posted it. Updated .