Attachment_4_-SCRM_Plan.docx

DOCX document 17 KB Posted

Attached to
Advanced Wireless Services-3 (AWS-3) Early Entry Portal (EEP) Development, Operations and Maintenance Support Federal contract opportunity
Solicitation number
HC104718R4004
Issued by
Defense Information Systems Agency

About this file

Attachment 4 - SCRM Plan

View the file

Other files for this federal contract opportunity

Other files attached to Advanced Wireless Services-3 (AWS-3) Early Entry Portal (EEP) Development, Operations and Maintenance Support, newest first.
File Type Posted
non_disclosure_agreement.docx DOCX document
additional_questions.docx DOCX document
9_Federal_EEP Training_Slides 29 June 2017.pdf PDF
Attachment_7_-_Provisions_and_Clauses.docx DOCX document
Attachment_5_-_Evaluation_Tables.docx DOCX document
AWS-3 EEP User's Guide 29 June 2017.pdf PDF
9_Engineering_SMO_DSRMT_EEP Training_Slides 29 June 2017.pdf PDF
6_T3747-1 AWS-3 EEP RTM - T3747-1-PD-17-478.pdf PDF
3_T3747-1-PD-17-467 T3747-1 AWS-3 EEP Software Design Document - v2.3 29 June 2017.pdf PDF
14_DSO-HDBK-15-098-EEP Analysis Capability SOP 11-30-2016 DRAFT_.pdf PDF
HC104718R4004_Request_for_Proposal_AMD02.docx DOCX document
7_ T3747-1 AWS-3 EEP v2.3 Architecture 29 June 2017.pdf PDF
9_Army Tactical Radio Relay PDF
9_Licensee_EEP Training_Slides 29 June 2017.pdf PDF
9_AWS-3 EEP Licensee_EEP Training_Slides 10 NOV 2016.pdf PDF
9_AWS-3 EEP Federal_EEP Training_Slides 10 NOV 2016.pdf PDF
10_T3747-1-OTH-17-479 T3747-1 AWS-3 EEP v2.3 Installation Guide.pdf PDF
AWS-3 EEP v2.3 DSO Form 19 - Software System Certification.pdf PDF
Attachment_6_-_Questions_and_Answers.docx DOCX document
15_Coordination Business Process V1_1.pdf PDF
Attachment_1_-_PWS.docx DOCX document
Attachment_3_-_Cost_Template.xlsx XLSX spreadsheet
1_DSO-SD-16-051 T3747-1 AWS-3 EEP v2.3 System Requirements Specification Rev2 29 June 2017.pdf PDF
Attachment_4_-_SCRM_Plan.docx DOCX document
Attachment_2_-_QASP.docx DOCX document
Attachment_6_-_Questions_Template.docx DOCX document
3_T3747-1-PD-17-467_T3747-1_AWS-3_EEP_Software_Design_Document_-_v2.3_29_June_2017.pdf PDF
Attachment_1_-_PWS.docx DOCX document
Attachment_3_-_CLIN_Pricing_Worksheet.xlsx XLSX spreadsheet
AWS-3_EEP_v2.3_DSO_Form_19_-_Software_System_Certification.pdf PDF
9_AWS-3_EEP_Federal_EEP_Training_Slides_10_NOV_2016.pdf PDF
6_T3747-1_AWS-3_EEP_RTM_-_T3747-1-PD-17-478.pdf PDF
9_AWS-3_EEP_Licensee_EEP_Training_Slides_10_NOV_2016.pdf PDF
14_DSO-HDBK-15-098-EEP_Analysis_Capability_SOP_11-30-2016_DRAFT_.pdf PDF
9_AWS-3_EEP_Engineering_SMO_DSRMT_EEP_Training_Slides_10_NOV_2016.pdf PDF
9_Licensee_EEP_Training_Slides_29_June_2017.pdf PDF
(N4110)_EEP_VDD_Summaries.pdf PDF
1_DSO-SD-16-051_T3747-1_AWS-3_EEP_v2.3_System_Requirements_Specification_Rev2_29_June_2017.pdf PDF
AWS-3_EEP_User's_Guide_29_June_2017.pdf PDF
9_Engineering_SMO_DSRMT_EEP_Training_Slides_29_June_2017.pdf PDF
7__T3747-1_AWS-3_EEP_v2.3_Architecture_29_June_2017.pdf PDF
9_Federal_EEP_Training_Slides_29_June_2017.pdf PDF
Attachment_7_-_Provisions_and_Clauses.docx DOCX document
9_AWS-3_EEP_User's_Guide_29_June_2017.pdf PDF
Attachment_7_-_Provisions_and_Clauses.docx DOCX document
Attachment_5_-_Evaluation_Tables.docx DOCX document
Attachment_3_-_CLIN_Pricing_Worksheet.xlsx XLSX spreadsheet
HC104718R4004_Request_for_Proposal.DOCX DOCX document
Attachment_2_-_QASP.docx DOCX document
Attachment_1_-_PWS.docx DOCX document
Show all 50

Advanced Wireless Services-3 (AWS-3) Early Entry Portal (EEP) Development, Operations and Maintenance Support has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Supply Chain Risk Management (SCRM) Requirements Solicitation for # HC104718R4004, N4110

This contract is subject to the Federal SCRM policies and regulations including the Defense Federal Acquisition Regulation Supplement (DFARS) 252.239-7017 Notice of Supply Chain Risk, DFARS 252.239-7018 Supply Chain Risk, DoD Instruction 5200.44 Protection of Mission Critical Functions to Achieve Trusted Systems and Networks, Section 806 of theFY2011 NDAA Requirements for Information Relating to Supply Chain Risk, and internal DISA SCRM Processes and Procedures.

The contractor shall submit a SCRM plan as part of its technical proposal that describes how the contractor will reduce and mitigate Supply Chain Risk using the security controls outlined below (further described in CNSSI 1253, Appendix D and NIST SP 800-53), as applicable to your contract. The full text of the selected contractor's SCRM Plan will be included in the resulting contract.

Control Number

HW
SW
Srvc
SA-12
Supply Chain Protection
x
x
x
SA-12(1)
Supply Chain Protection / Acquisition Strategies / Tools / Methods
x
x
x*
SA-12(2)
Supply Chain Protection / Supplier Reviews
x
x
x*
SA-12(5)
Supply Chain Protection / Limitation of Harm
x
x
x*
SA-12 (7)
Supply Chain Protection Assessments Prior to Selection / Acceptance/ Update
x
x
x*
SA-12 (8)
Supply Chain Protection / Use of All-Source Intelligence
x
x
x*
SA-12 (9)
Supply Chain Protection / Operations Security
x
x
x
SA-12 (10)
Supply Chain Protection / Validate as Genuine and Not Altered
x
x
x*
SA-12 (11)
Supply Chain Protection / Penetration Testing / Analysis of Elements, Processes, and Actors
x
x
x
SA-12 (12)
Supply Chain Protection / Inter-Organizational System Components
x
x
x
SA-12 (13)
Supply Chain Protection / Critical Information System Components
x
x
x*
SA-12 (14)
Supply Chain Protection / Identity and Traceability
x
x
x*
SA-12 (15)
Supply Chain Protection / Process to Address Weaknesses or Deficiencies
x
x
x
IR-4 (10)
Incident Handling / Supply Chain Coordination
x
x
x*
IR-6 (3)
Supply Chain Protection / Incident Reporting / Coordination With Supply Chain
x
x
x*
SA-11
Developer Security Testing and Evaluation
x
x
x*
SA-14
Criticality Analysis
x
x
x*
SA-15
Development Process, Standards, and Tools
x
x
x*
SI-7
Software, Firmware, and Information Integrity
x
x
x*
CM-4
Security Impact
x
x
x*
PM-16
Threat Awareness Program
x
x
x

*Not required if there will be no procurement of hardware, firmware, or software systems.

DELIVERABLES:

SUPPLY CHAIN RISK MANAGEMENT PLAN UPDATE: The contractor shall provide an updated SCRM Plan to the COR and Program Manager within five (5) business days whenever there is a change that affects one or more security controls as described in the Committee on National Security Systems Instructions (CNSSI) 1253 Appendix D (companion publication to National Institute of Standards and Technology (NIST) Special Publication (SP)). At a minimum, the following events will require a SCRM Update: changes in company ownership, changes in senior company leadership, supplier changes, subcontractor changes, and ICT supply chain compromises.

File details come from the government source that posted it.