Att 10 - Security Risk Review Appendix 2 - Security Program Questionnaire.docx
DOCX document 28 KB Posted
- Attached to
- Resilient Open & Agile Avionics System & Technology Development (ROAASTD) Federal contract opportunity
- Solicitation number
- FA8650-23-S-1031
About this file
This is a security program questionnaire (Appendix 2) for the AFRL Security Risk Review process, associated with solicitation FA8650-23-S-1031 for Resilient Open & Agile Avionics System & Technology Development (ROAASTD). The questionnaire is designed to review security programs and practices of institutions receiving research funding and must be completed by collaborators for review by the S&T Protection Lead.
The questionnaire consists of 13 questions focusing on various security aspects including physical security plans, information security processes, data storage methods, transmission procedures, disposal protocols, reproduction procedures, personnel access safeguards, GFE/GFI protection, cybersecurity measures, operations security, insider threat mitigation, compromise handling procedures, and willingness to provide annual AFRL S&T Protection training. The document is a template requiring completion by applicants and includes fields for basic information such as applicant name, CAGE code/SCL level, position title, and submission date.
View the file
Other files for this federal contract opportunity
Show all 28
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
FA8650-23-S-1031
Security Risk Review, AFRLI 61-113, Appendix 2
SECURITY PROGRAM QUESTIONNAIRE
Objective: This questionnaire is used to review the security program and practices of the institutions receiving research funding.
Intended Audience/User: Completed by collaborators; reviewed by S&T Protection Lead.
Date Submitted: ________________________________________________________________ Applicant Name: _______________________________________________________________ CAGE Code/SCL and level (if applicable): ____________________________________________ Completed by Name: ____________________________________________________________ Position/Title: __________________________________________________________________
1. What are your physical security plans?
2. What information security processes are in place?
3. Where will information for this effort be stored? (examples: computers, cloud, file cabinets, etc.)
4. What procedures are in place for transmission/transportation of information for this effort?
5. What procedures are in place for disposal and destruction of information for this effort?
6. What procedures are in place for reproduction of information for this effort?
7. What safeguards are in place for personnel who can access information for this effort?
8. What is the plan for safeguarding GFE/GFI?
9. What procedures are in place for cybersecurity or network protection?
10. What operations security processes are in place to prevent adversaries’ access to information for this effort or actions that would compromise your projects?
11. What processes are in place to deter, detect, and mitigate actions of insider threat?
12. What procedures are in place to handle if information for this effort is compromised?
13. Are you willing to provide AFRL S&T Protection training to all personnel with access annually?
Additional comments:
File details come from the government source that posted it. Updated .