The file's text, extracted by GovTribe without its formatting.
Supply Chain Risk Management (SCRM) Requirements Solicitation for # HC104718R4004, N4110
This contract is subject to the Federal SCRM policies and regulations including the Defense Federal Acquisition Regulation Supplement (DFARS) 252.239-7017 Notice of Supply Chain Risk, DFARS 252.239-7018 Supply Chain Risk, DoD Instruction 5200.44 Protection of Mission Critical Functions to Achieve Trusted Systems and Networks, Section 806 of theFY2011 NDAA Requirements for Information Relating to Supply Chain Risk, and internal DISA SCRM Processes and Procedures.
The contractor shall submit a SCRM plan as part of its technical proposal that describes how the contractor will reduce and mitigate Supply Chain Risk using the security controls outlined below (further described in CNSSI 1253, Appendix D and NIST SP 800-53), as applicable to your contract. The full text of the selected contractor's SCRM Plan will be included in the resulting contract.
Control Number
| SA-12 |
| Supply Chain Protection |
| x |
| x |
| x |
| SA-12(1) |
| Supply Chain Protection / Acquisition Strategies / Tools / Methods |
| x |
| x |
| x* |
| SA-12(2) |
| Supply Chain Protection / Supplier Reviews |
| x |
| x |
| x* |
| SA-12(5) |
| Supply Chain Protection / Limitation of Harm |
| x |
| x |
| x* |
| SA-12 (7) |
| Supply Chain Protection Assessments Prior to Selection / Acceptance/ Update |
| x |
| x |
| x* |
| SA-12 (8) |
| Supply Chain Protection / Use of All-Source Intelligence |
| x |
| x |
| x* |
| SA-12 (9) |
| Supply Chain Protection / Operations Security |
| x |
| x |
| x |
| SA-12 (10) |
| Supply Chain Protection / Validate as Genuine and Not Altered |
| x |
| x |
| x* |
| SA-12 (11) |
| Supply Chain Protection / Penetration Testing / Analysis of Elements, Processes, and Actors |
| x |
| x |
| x |
| SA-12 (12) |
| Supply Chain Protection / Inter-Organizational System Components |
| x |
| x |
| x |
| SA-12 (13) |
| Supply Chain Protection / Critical Information System Components |
| x |
| x |
| x* |
| SA-12 (14) |
| Supply Chain Protection / Identity and Traceability |
| x |
| x |
| x* |
| SA-12 (15) |
| Supply Chain Protection / Process to Address Weaknesses or Deficiencies |
| x |
| x |
| x |
| IR-4 (10) |
| Incident Handling / Supply Chain Coordination |
| x |
| x |
| x* |
| IR-6 (3) |
| Supply Chain Protection / Incident Reporting / Coordination With Supply Chain |
| x |
| x |
| x* |
| SA-11 |
| Developer Security Testing and Evaluation |
| x |
| x |
| x* |
| SA-14 |
| Criticality Analysis |
| x |
| x |
| x* |
| SA-15 |
| Development Process, Standards, and Tools |
| x |
| x |
| x* |
| SI-7 |
| Software, Firmware, and Information Integrity |
| x |
| x |
| x* |
| CM-4 |
| Security Impact |
| x |
| x |
| x* |
| PM-16 |
| Threat Awareness Program |
| x |
| x |
| x |
*Not required if there will be no procurement of hardware, firmware, or software systems.
DELIVERABLES:
SUPPLY CHAIN RISK MANAGEMENT PLAN UPDATE: The contractor shall provide an updated SCRM Plan to the COR and Program Manager within five (5) business days whenever there is a change that affects one or more security controls as described in the Committee on National Security Systems Instructions (CNSSI) 1253 Appendix D (companion publication to National Institute of Standards and Technology (NIST) Special Publication (SP)). At a minimum, the following events will require a SCRM Update: changes in company ownership, changes in senior company leadership, supplier changes, subcontractor changes, and ICT supply chain compromises.