Attachment 5 - SCRM Basic Safeguarding Questionnaire .pdf
PDF 43 KB Posted
- Attached to
- REQUEST FOR PROPOSAL - Commercial Online Platform Acquisition Federal contract opportunity
- Solicitation number
- 47QSCC23R0002
- Issued by
- GSA Federal Acquisition Service
View the file
Other files for this federal contract opportunity
Show all 18
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment 5
SCRM Basic Safeguarding Questionnaire
1) Enter the name of the primary Point-Of-Contact (POC) for the offeror.
Offeror Response:
2) Enter the job title of the primary POC for the offeror.
3) Enter the name of the offeror.
4) Enter the phone number of the primary POC for the offeror in the following format: (555)
555-5555.
5) Enter the E-mail Address of the primary POC for the offeror.
6) Does your organization identify key suppliers as related to supply chain threats?
7) Does your organization confirm 100% of your suppliers of critical Information and
Communication Technology (ICT) products and services are TAA/MIA compliant?
8) Does your organization assess and review supplier risk factors, such as Foreign
Ownership, Control and Influence of suppliers and subcontractors prior to entering a contractual relationship?
9) Does your organization have a SCRM Plan? (GSA recommends one that aligns with
National Institute of Standards and Technology (NIST) Special Publication (SP) 800-161, Supply Chain Risk Management Practices for Federal Information Systems and
Organizations as required by the RFP) Special Instruction: Provide supporting documentation containing a table of contents for your SCRM Plan (this can be either extracted separately from the current plan or created for purposes of this submission).
10) Does your organization verify that your suppliers meet SCRM requirements through contractual terms and conditions?
11) Does your organization have documented procedures to detect cybersecurity threats and attacks?
12) Does your organization have a documented procedure(s) to respond to and recover from cybersecurity threats and attacks?
13) Does your organization have personnel designated to respond to cybersecurity incidents?
14) Does your organization have a documented Security Incident Response process covering physical security incidents? (e.g., potential intruder access, missing equipment)?
15) Does your organization have policies for conducting background checks of your employees as permitted by the country in which your organization operates? Provide supporting documentation containing the policy/policies for conducting background checks. If this is part of a larger document, the specific policy/policies related to background checks may be extracted separately
16) Does your organization have procedures in place to prevent tampering of Information and
Communications Technology (ICT) equipment stored as supply chain inventory?
17) Does your organization have procedures in place for the prevention and detection of insider threats?
File details come from the government source that posted it. Updated .