Attachment B - C-SCRM Questionnaire.xlsx

XLSX spreadsheet 166 KB Posted

Attached to
NEC - BAS Service Contract for NON-CAA area Federal contract opportunity
Solicitation number
19PM0724Q0063
Issued by
Department of State

About this file

This document is a Cybersecurity Supply Chain Risk Management (C-SCRM) Questionnaire to be completed by a vendor submitting an offer for a federal contract opportunity. It covers three main sections: 1) Contact Information, 2) Vendor Risk Management Plan, and 3) Physical and Personnel Security. The vendor is required to provide responses to questions in each section related to their SCRM practices, such as identifying key supply chain threats, mapping suppliers to threats, having written SCRM requirements in supplier contracts, and conducting background checks and security awareness training for employees. The questionnaire appears to be related to a Request for Quotations (RFQ) for a NEC - BAS Service Contract for Non-CAA area issued by the Department of State, with a due date of September 12th, 2024 at 3:00pm local time. The solicitation requires submission of a Standard Form 1449, the pricing schedule, representations and certifications, and proof of SAM registration in order to be considered for award.

View the file

Other files for this federal contract opportunity

Other files attached to NEC - BAS Service Contract for NON-CAA area, newest first.
File Type Posted
24Q0063 - QA BAS Service Contract for Non-Caa area(Approval Request).docx DOCX document
24Q0063 - Invitation letter.pdf PDF
24Q0063 - SF1449 Cover Page.pdf PDF
24Q0063 - Attachment to SF-1449.pdf PDF
24Q0063 - Invitation letter.pdf PDF
Attachment A - Scope of Works (SOW) Non-CAA.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

C-SCRM Questionnaire

CYBERSECURITY SUPPLY CHAIN RISK MANAGEMENT (C-SCRM) QUESTIONNAIRE
Instructions:

- This worksheet shall be completed by the vendor responsible for submitting the offer. References to "organization" refer to the offering entity. If the offering entity is a joint venture (JV), the response may come from either the JV or from the JV managing partner.

- Provide the requested inputs in the gray shaded lines of the template under column D, Vendor Response, for all Items Numbers for Sections 1-3. Offerors are advised that the Government may request documentation from the Offerors to validate the responses provided.

SECTION 1 - CONTACT INFORMATION
ITEM NO.ITEM DESCRIPTIONVENDOR RESPONSE
1.1Enter the name of your company.
1.2Enter the name of the primary Point-Of-Contact (POC) for your company that the Government may contact to discuss the vendor inputs on this questionnaire.
1.3Enter the job title of the primary POC.
1.4Enter the phone number of the primary POC in the following format: (555) 555-5555
1.5Enter the e-mail address of the primary POC.
SECTION 2 VENDOR RISK MANAGEMENT PLAN
ITEM NO.ITEM DESCRIPTIONVENDOR RESPONSENIST SP 800-53 Reference
2.1Does your organization identify its key supply chain threats?IR-8, SR-7
2.2Does your organization map key suppliers to your supply chain threats?IR-8, SR-7
2.3Does your organization have written SCRM requirements in contracts with your key suppliers?SA-4
2.4Does your organization verify that your suppliers meet SCRM requirements through contractual terms and conditions?SR-6
SECTION 3 PHYSICAL AND PERSONNEL SECURITY
ITEM NO.ITEM DESCRIPTIONVENDOR RESPONSENIST SP 800-53 Reference
3.1Does your organization have policies for conducting background checks of your employees as permitted by the country in which your organization operates?NoPE-2, PE-3

PS-3

3.2 Does your organization have procedures in place to prevent tampering of Information and Communications Technology (ICT) equipment stored as supply chain inventory? SR-9

AC-1

3.3 Do you provide literacy training on recognizing and reporting potential indicators of insider threat? AT-2(2)

&"Calibri"&11&K000000_x000D_&1#&"Times New Roman"&10&K000000SENSITIVE BUT UNCLASSIFIED

Data (HIDE)

StatusScoreStatusNot ReviewedYesNoNot ApplicableAlternativeTotal
ERROR:#REF!ERROR:#REF!CountsERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!
PctERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!

&"Calibri"&11&K000000_x000D_&1#&"Times New Roman"&10&K000000SENSITIVE BUT UNCLASSIFIED

Counts Not Reviewed Yes No Not Applicable Alternative 0 0 0 0 0

DL (HIDE)

GWACSPoolImplementation StatusAnswer
Alliant/ Alliant 2Small Business (SB) PoolSatisfiedYes
Alliant SBHUBZone SB (HUBZone) PoolPartially SatisfiedNo
8(a) STARS IIWomen Owned SB (WOSB) PoolNot Satisfied
VETS/ VETS2OtherNot Applicable
TBD
Not Reviewed

&"Calibri"&11&K000000_x000D_&1#&"Times New Roman"&10&K000000SENSITIVE BUT UNCLASSIFIED

File details come from the government source that posted it. Updated .