J-3 Cybersecurity _ Supply Chain Risk Management (C-SCRM) Deliverables.xlsx
XLSX spreadsheet 133 KB Posted
- Attached to
- One Acquisition Solution for Integrated Services Plus (OASIS+) Women-Owned Small Business (WOSB) Set-Aside - Closed Federal contract opportunity
- Solicitation number
- 47QRCA23R0005
- Issued by
- GSA Federal Acquisition Service
View the file
Other files for this federal contract opportunity
Show all 50
One Acquisition Solution for Integrated Services Plus (OASIS+) Women-Owned Small Business (WOSB) Set-Aside - Closed has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Pre-Award Evaluation Instructio
| Basic Safeguarding of Covered Contractor Information Systems |
| INSTRUCTIONS |
QUESTIONNAIRE COMPLETION INSTRUCTIONS:
| ● Provide a contact (name, title, offeror name, phone number, and e-mail address) for questions, support, or additional information related to the questionnaire to the respondents. |
| ● Provide your responses in the gray shaded lines of the questionnaire. |
| Definitions: |
| Covered contractor information system means an information system that is owned or operated by a contractor that processes, stores, or transmits Federal contract information. |
| Federal contract information means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public (such as on public websites) or simple transactional information, such as necessary to process payments. |
| Information means any communication or representation of knowledge such as facts, data, or opinions, in any medium or form, including textual, numerical, graphic, cartographic, narrative, or audiovisual (Committee on National Security Systems Instruction (CNSSI) 4009). |
| Information system means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information ( 44 U.S.C. 3502). |
| Safeguarding means measures or controls that are prescribed to protect information systems. |
Pre-Award Eval. - Basic Safegua
Basic Safeguarding of Covered Contractor Information Systems Questionnaire
| Status: Not Started | ||
| Section 1: | Contact Information | Vendor Response |
| 1.1 | Enter the name of the offeror. |
| 1.2 | Enter the name of the primary Point-Of-Contact (POC) for the offeror. |
| 1.3 | Enter the E-mail Address of the primary POC for the offeror. |
| 1.4 | Enter the phone number of the primary POC for the offeror in the following format: (555) 555-5555 |
| Section 2: | Access Control | NIST SP 800-53 Control |
| 2.1 | Does your organization limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems)? | AC-2 |
AC-3
AC-17
AC-20
AC-22
| 2.2 | Does your organization limit information system access to the types of transactions and functions that authorized users are permitted to execute? |
| 2.3 | Does your organization verify and control/limit connections to and use of external information systems? |
| 2.4 | Does your organization control information posted or processed on publicly accessible information systems? |
| Section 3: | Identification and Authentication | NIST SP 800-53 Control |
| 3.1 | Does your organization identify information system users, processes acting on behalf of users, or devices? | IA-2 |
IA-3
IA-5
3.2 Does your organization authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems?
| Section 4: | Media Protection | NIST SP 800-53 Control |
| 4.1 | Does your organization sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse? | MP-2 |
MP-4
MP-6
| Section 5: | Physical Protection | NIST SP 800-53 Control |
| 5.1 | Does your organization limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals? | PE-2 |
PE-3
PE-4
PE-5
PE-6
5.2 Does your organization escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices?
| Section 6: | System and Communications Protection | NIST SP 800-53 Control |
| 6.1 | Does your organization monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems? | SC-7 |
| 6.2 | Does your organization implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks? |
| Section 7: | System and Information Integrity | NIST SP 800-53 Control |
| 7.1 | Does your organization identify, report, and correct information and information system flaws in a timely manner? | SI-2 |
SI-3
SI-5
| 7.2 | Does your organization provide protection from malicious code at appropriate locations within organizational information systems? |
| 7.3 | Does your organization update malicious code protection mechanisms when new releases are available? |
| 7.4 | Does your organization perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed? |
Data (HIDE)
| Status | Score | Status | Not Reviewed | Yes | No | Not Applicable | Alternative | Total |
| No Completed | 0% | Counts | 15 | 0 | 0 | 0 | 0 | 15 |
| Pct | 100% | 0% | 0% | 0% | 0% | 100% |
DL (HIDE)
| GWACS | Pool | Implementation Status | Answer |
| Alliant/ Alliant 2 | Small Business (SB) Pool | Satisfied | Yes |
| Alliant SB | HUBZone SB (HUBZone) Pool | Partially Satisfied | No |
| 8(a) STARS II | Women Owned SB (WOSB) Pool | Not Satisfied | |
| VETS/ VETS2 | Other | Not Applicable | |
| TBD | |||
| Not Reviewed |
Post-Award Deliverable Instruct
| CYBER-SUPPLY CHAIN RISK MANAGEMENT PLAN |
| INSTRUCTIONS |
| INTRODUCTION: |
| U.S. adversaries have attacked our nation's supply chains and compromised Federal Government systems, capitalizing on security weaknesses in U.S. companies and third party affiliates. It is incumbent on GSA's industrial base to implement vigilant Supply Chain Risk Management procedures. |
This document is intended to evaluate a contractor's SCRM maturity.
| TEMPLATE COMPLETION INSTRUCTIONS: |
| ● Provide a contact (name, email, and phone number) for questions, support, or additional information related to the questionnaire to the respondents. |
| ● We recommend designating one primary POC from your organization who will collaborate with the appropriate POCs/teams/vendor/supplier to coordinate and collect and compile responses for each section. The appropriate POCs within each organization will vary and may consist of individuals in information technology, acquisition, procurement, supply chain, or security offices. While related, each section is design to be relevant to a different aspect of your organization. This template is intended to gather an initial and consistent baseline and additional follow-up questions from the organization, or other documentation, may be warranted. |
| ● Provide your responses in the gray shaded lines of the template under Column C, Vendor Response. |
| ● Provide a response to each ‘Yes’, ‘No’ question as relevant to the offering. |
| ● Attach supporting documents to the completed SCRM Plan Template by embedding documents in line. You may provide links instead if documentation is available online and accessible. |
| ● Blue text indicates the criteria that a given question is evaluated by and includes references to NIST Special Publications or other resources for further information. |
If the requested supply chain risk management information on the next tab has previously been provided to the requesting organization, provide an updated revision covering material changes.
Critical Component is defined as: A system element that, if compromised, damaged, or failed, could cause a mission or business failure
| Reference links: |
| NIST 800-161 |
| NIST 800-53 |
https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/finalhttps://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final Post-Award Deliverable - C-SCRM
C-SCRM PLAN TEMPLATE
| CONTACT INFORMATION |
| Name of Respondent: |
| Title: |
| Name of Organization: |
| Phone number: |
| Email: |
| SECT. 1 | SUPPLY CHAIN PROVENANCE | VENDOR RESPONSE |
| Identity - including that of each parent and/or subsidiary corporate entities. | ||
| 1.1 | Are suppliers of critical ICT components identified? | |
| Requirement: Attestation |
This standard is met when the prime contractor attests to having identified suppliers of critical components included in ICT supplies and services that will be sold to the government through this contract.
| 1.2 | Is the company ownership of suppliers of critical ICT components verified? |
| Requirement: Attestation |
This standard is met when the prime contractor attests to verifying the company ownership of all suppliers of critical components included in ICT supplies and services that will be sold to the government through this contract.
| 1.3 | Are suppliers of critical ICT components under U.S. ownership? |
| Requirement: Attestation |
This standard is met when the prime contractor attests that all suppliers of critical components included in ICT supplies and services that will be sold to the government through this contract are U.S. owned companies.
| 1.4 | If distributors will be used to provide products/services to the Government, is a threat analysis performed for each distributor? If "yes", provide the process. |
| Requirement: Documentation |
If distributors are not used, this standard is met with a response of "no".
If distributors are used, this standard is met when the prime contractor documents the process to perform a threat analysis for distributors of ICT supplies and services that will be sold to the government through this contract.
Reference NIST 800-161 4.1.4 for Threat Analysis.
| 1.5 | Are any subcontractors and/or suppliers located outside the United States or its territories? If "yes", list company name(s) and foreign country location(s). |
| Requirement: Attestation |
This standard is met when the contractor attests that no subcontractors or suppliers are located outside the of the U.S. If any subcontractors or suppliers are located outside of the U.S., this standard is met when all subcontractors/suppliers are listed, along with the locations of each.
Reference NIST SP 800-53 SR-6, Supplier Assessments and Reviews
| 1.6 | Are controls aligned to the SCRM Baseline as stipulated in NIST SP 800-161, Supply Chain Risk Management Practices for Federal Information Systems and Organization? If yes, demonstrate how in Section 1.7. If "no", mark N/A in Section 1.7 and proceed to Section 2.1. |
| Requirement: Attestation |
This standard is met when the prime contractor attests that the ICT SCRM Security Controls in Chapter 3.5 are followed.
| 1.7 | Provide evidence of control alignment with NIST SP 800-161. |
| Requirement: Documentation |
This standard is met when the prime contractor provides a SCRM or Security plan with well defined operational controls and referenced policies or a third party assessment to demonstrate the alignment.
This question ensures that contractors have policies/procedures that are fully aligned with NIST 800-161.
| SECT. 2 | SUPPLY CHAIN MANAGEMENT AND SUPPLIER GOVERNANCE |
| General | |
| 2.1 | Are policies/processes in place to ensure timely notification of updated risk management information previously provided to the Contracting Officer and Contracting Officer's Representative? If "yes" cite the section where the policy is documented. |
| Requirement: Documentation |
This standard is met when the prime contractor demonstrates the process and policies that ensure timely notification of updated risk management information.
This question ensures that policies are regularly updated and communicated to customers to ensure regular maintenance of established processes/procedures for SCRM.
| Information Communications Technology (ICT) Supply Chain Management | |
| 2.2 | Is there a documented Quality Management System (QMS) based on an industry standard or framework for the prime contractor's Information and Communications Technology (ICT) supply chain operation? If "yes" provide QMS documentation. |
| Requirement: Documentation |
This standard is met when the prime contractor provides the QMS documentation.
This question asks whether the prime contractor has policies and procedures in place to address supply chain risks. If the company is fully compliant with ISO 9001, then we may have more confidence in their implementation, auditing, training, and change management processes. If the company is not fully compliant with ISO 9001, then we may need to dig deeper to understand whether they have effective implementation, audit plans, training, change management processes, etc. This question ensures that the prime contractor is thinking about its supply chain throughout the lifecycle.
Reference ISO 9001:2015; NIST SP 800-161
| Supplier Governance | |
| 2.3 | Do Supply Chain Risk Management (SCRM) requirements exist in contracts with critical ICT suppliers? If "yes", provide the specific contract language which stipulates the SCRM/C-SCRM requirements. |
| Requirement: Documentation |
This standard is met when the prime contractor provides documented C-SCRM/SCRM requirements in contract language.
The Government wants to know that the supplier not only has a comprehensive and robust SCRM program for itself (which helps us to mitigate our own risk and meet customer expectations), but that it also requires the same from its sub-suppliers. We also want to ensure that the supplier ensures that “externally provided processes, products and services” conform to the SCRM requirements expected from the supplier and ensure that the supplier can meet the expectations of its customers. Suppliers must establish incident handling, including preparation, detection analysis, containment and recovery. We want incidents to be addressed with appropriate mitigations. Finally, we want to ensure that we are notified of changes in subcontractors because those changes could impact our ability to appropriately identify our own supply chain risks and our ability to meet the customers’ expectations.
Reference NIST SP 800-53; NIST IR 7622; SIG LITE 2020; ISO 8.4; NIST SP 800-161
| 2.4 | Is there a process to verify that suppliers are meeting SCRM contractual terms and conditions, including, where applicable, requirements to be passed down to sub-suppliers? |
| Requirement: Documentation |
This standard is met when the prime contractor provides documented processes and/or policies that ensure suppliers meet SCRM contractual terms and conditions.
Reference NIST SP 800-53; NIST IR 7622; SIG LITE 2020; ISO 8.4; NIST SP 800-161
| SECT. 3 | INFORMATION SECURITY |
| Identify | |
| 3.1 | Is there a process used to verify that information is categorized according to legal, regulatory, or internal sensitivity requirements? If a process is established by policy, provide the policy. |
| Requirement: Documentation |
This standard is met when the prime contractor documents the processes to verify that information is appropriately categorized.
This question assesses the risk: Breach of confidentiality ISO 27003:2013 sect 7.5.3.
Reference NIST SP 800-53: SI-12 Information Management and Retention, RA-2 Security Categorization
| 3.2 | Are the policies and procedures referenced in 3.1 reviewed and updated annually? When was the most recent review? |
| Requirement: Attestation |
This standard is met when the prime contractor attests that policies and procedures are reviewed and updated annually, and the provides the date of the most recent review.
| Detect | |
| 3.3 | Are incident detection and reporting practices defined and documented which outline the actions that should be taken in the case of an information security or cybersecurity event? If "yes", provide the documented practices. |
| Requirement: Documentation |
This standard is met when the prime contractor provides their incident detection and reporting documentation/practices.
This question assesses the risk of a delay in, or inability to, recover from cybersecurity events.
Reference ISO 27003:2017 sect 16.1.1
| 3.4 | Are cybersecurity events centrally logged, tracked, and continuously monitored? If "yes", provide documentation regarding events are monitored. |
| Requirement: Documentation |
This standard is met when the prime contractor provides documentation regarding how cybersecurity events are logged, tracked, and continuously monitored.
| 3.5 | Is endpoint protection software deployed throughout the prime contractor's environment? If "no", describe the mitigation efforts used instead. |
| Requirement: Attestation |
This standard is met when the prime contractor attests that endpoint protection software is used pervasively in their environment. If not used, additional mitigation efforts must be described.
Reference NIST CSF1.1 PR.IP* Information Protection Processes and Procedures Free endpoint software can be found on this list from CISA: https://www.cisa.gov/free-cybersecurity-services-and-tools
| 3.6 | Is there a documented incident response process and a dedicated incident response team (CSIRT - Computer Security Incident Response Team)? If "no", describe the mitigation efforts used instead. |
| Requirement: Attestation |
This standard is met when the prime contractor attests to having an incident response process and dedicated incident response team. If no process or team exists, mitigation efforts must be described.
This question assesses the risk of the contractor's ability to maintain operational continuity during/after an attack.
Reference CNSSI 4009-2015 under incident handling; NIST SP 800-61.; Shared Assessments Standardized Control Assessment (SCA) sect. K.4
| SECT. 4 | PHYSICAL SECURITY |
| General | |
| 4.1 | Is the entity (organization, operational unit, facility, etc.) currently covered by an unrestricted/unlimited National Industrial Security Program (NISP) Facility Clearance (FCL) or a related U.S. government program such as C- TPAT that certifies the entity as meeting appropriate physical security standards? If "yes", documentation the certification and date of last certification. |
| Requirement: Documentation |
This standard is met when the prime contractor responds yes and provides documentation regarding the certification program and date of certification for the covered entity, or responds no.
Reference DoD 5220.22, Volume 2, August 1, 2018 (National Industrial Security Program: Industrial Security Procedures for Government Activities, Incorporating Change 1, September 30, 2020 (all applicable chapters, section, paragraphs))
| 4.2 | Are security policies and procedures documented which address the control of physical access to cyber assets (network devices, data facilities, patch panels, industrial control systems, programmable logic, etc.)? If "yes", provide documented security policies/procedures. |
| Requirement: Documentation |
This standard is met when the prime contractor documents their security policies and procedures. Reference the specific standard if security policies align to an industry standard.
See NIST SP 800-53 PE-1, PE-2, PE-3.
| 4.3 | Are physical security industry standards/controls adhered to? (e.g., NIST publication, ISO, UL, etc.) If "yes", list the industry standards/controls. |
| Requirement: Documentation |
This standard is met when the contractor lists applicable physical security industry standards/controls that are adhered to.
Controls may align with NIST SP 800-53 Controls PE-1, PE-2 and PE-3.
Reference ONSAT-PSP-14.3, NIST 800-161 AT-3 - Security Training, ISO 27001:2013
| 4.4 | Are the policies and procedures listed in 4.3 reviewed and updated at least annually? When was the most recent review? |
| Requirement: Attestation |
This standard is met when the prime contractor attests that policies are reviewed and updated annually and procedures are reviewed and updated at least every three years, and the provides the date of the most recent review (within the past three years).
| 4.5 | Does a documented Security Incident Response process exist which covers physical security incidents at the prime contractor's owned or operated facilities (e.g., potential intruder access, missing equipment, etc.)? If "no", describe mitigation efforts. |
| Requirement: Attestation |
This standard is met when the prime contractor attests to having a documented security incident response process. If no process exists, mitigation efforts must be described.
| Physical Security In-transit | |
| 4.6 | Are requirements in place to ensure the use of Original Equipment Manufacturer (OEM) or Authorized Distributors for all critical ICT components? |
| Requirement: Documentation |
This standard is met when the prime contractor documents the policies/practices that ensure all critical ICT components are sourced from the OEM or authorized distributors.
Reference IEC:IECEE, IECQ, ISO 28000, ISO 12931, ISO 16678
| 4.7 | Are counterfeit prevention requirements passed on to second and third party suppliers? |
| Requirement: Documentation |
This standard is met when the prime contractor documents a policy that requires third party suppliers to provide authorized critical ICT components.
Reference IEC:IECEE, IECQ, ISO 28000, ISO 12931, ISO 16678
| SECT. 5 | PERSONNEL SECURITY |
| General | |
| 5.1 | Is a personnel security program implemented at the prime contractor's owned or operated facilities? If "yes", list address(es) and, if implemented by a third party, the company(ies) used. If the prime contractor does not own or operate a facility, mark N/A, and skip to question 5.3. |
| Requirement: Attestation |
This standard is met when the prime contractor attests to implementing a personnel security program and lists the address(es) that this program applies to. If a third party is contracted, list the name of the company/companies used.
| 5.2 | Are physical security practices documented or formally governed? If "yes", provide the documentation, or cite the section where the documentation can be found. |
| Requirement: Documentation |
This standard is met when the prime contractor documents the physical security practices in place.
| Onboarding | |
| 5.3 | Are policies documented for conducting background checks of prime contractor employees as permitted by each country in which you operate? If "yes", provide the documented policy or cite where it can be found. |
| Requirement: Documentation |
This standard is met when the prime contractor provides the documented policy for conducting background checks as permitted, or lists the controls used in physical security practices.
This question measures how new employees are introduced to the organization’s security principles and culture during the initial point of entry.
Examples include: NIST SP 800-53 PS-1, PS-2 and PS-3 and:
• NIST CSF: ID.AM-6, ID.GV-2
• SP 800-53: SA-3, SA-8
• SP 800-160: 3.2.1, 3.2.4, 3.3.1
• SP 800-181: K0233
• NIST CSF: PR.AT-*
• SP 800-160: 3.2.4
• SP 800-181: OV-TEA-001, OV-TEA-002; T0030, T0073, T0320; K0204, K0208, K0220, K0226, K0243, K0245, K0252; S0100, S0101; A0004, A0057
• SP 800-181: T0001, T0004
• NIST Cybersecurity Framework (2018) - https://www.nist.gov/cyberframework
| SECT. 6 | SUPPLY CHAIN INTEGRITY |
| General | |
| 6.1 | Are documented processes in place for managing third-party products and component defects throughout their lifecycle? If "yes", provide the documented process or cite where it can be found. |
| Requirement: Documentation |
This standard is met when the prime contractor provides the process documentation for managing third party products and components.
Third-party HW/SW products may not have as stringent quality control and defect analysis and therefore could be at higher risk for non-conformance or being counterfeit.
Reference NIST 800-53 SR-1, SR-2, SR-3, SR-11
| 6.2 | What provisions for auditing are included within supplier contracts? |
| Requirement: Documentation |
This standard is met when the prime contractor documents the processes for auditing in supplier contracts.
Regular audits ensure that processes are being performed and running as desired and offer opportunities for improvements. Passing down audit requirements to suppliers ensures supplier integrity of your suppliers.
Reference NIST 800-53 and NIST 800-161 AU-1, AU-2 and AU-3, and ISO 27036; ONSAT – AIA 4.1
| 6.3 | Are hardware/software products or services integrity and End of Life requirements passed down to second and third party suppliers? If "yes", provide a documented process or policy. |
| Requirement: Documentation |
This standard is met when the prime contractor documents the processes for managing third party supplier integrity requirements.
Reference NIST 800-53 SR-3(3) and ISO 27036; ONSAT – AIA 4.1
| 6.4 | Are processes in place for addressing reuse and/or recycle of hardware products? If "yes", provide the process document. |
| Requirement: Documentation |
This standard is met when the prime contractor provides a process document for managing reuse/recycling of hardware products.
Lack of controlled disposal procedures could increase risks of counterfeiting and unintended uses.
Reference NIST 800-53 MP-6 and R2:2013 - Sustainable Electronics Recycling International, sect 15
| SECT. 7 | SUPPLY CHAIN RESILIENCE |
| General | |
| 7.1 | Is a formal process documented for ensuring supply chain resilience as part of your product offering SCRM practices? If "yes", provide the process document. |
| Requirement: Documentation |
This standard is met when the prime contractor documents the process for ensuring supply chain resilience.
This question is intended to measure the extent to which the company has the ability to withstand and recover from deliberate attacks, accidents, or naturally occurring threats or incidents to its Critical ICT elements and assets.
Reference NIST 800-53 SR-1, SR-2, SR-3, CP-2 and CP-8, and 800-161 supplementary guidance; EO 13873
| Supply Chain Disruption Risk Management (Business Continuity) | |
| 7.2 | Can prime contractor personnel work remotely? If "yes", provide policies, practices, and software allowing remote work. |
| Requirement: Documentation |
This standard is met when the prime contractor documents policies, practices, and software allowing remote work.
This question is intended to address how organizations provide secure access to data and information systems for employees working remotely.
Reference NIST 800-53 PE-17 and NIST 800-161 supplementary guidance
| 7.3 | Is a data backup policy in place that aligns with NIST SP 800-53 CP-9? If "yes", provide the policy. Address if the data backup location is offsite and, additionally, if the backup location is outside the immediate climatic or geographical area (e.g., not in the same floodplain). |
| Requirement: Documentation |
This standard is met when the prime contractor documents a data backup policy that aligns with NIST 800-53 CP-9, or an equivalent standard.
| 7.4 | Has your organization conducted vulnerability assessments, risk assessment, or other calculations to identify what impact physical risks associated with climate related risks (e.g., increases in precipitation-driven flooding, extreme heat events, and inundation due to sea level rise and storm surge) might have on your assets, products, and/or services? |
| Requirement: Attestation |
This standard is met when the prime contractor attests to conducting assessments/calculations to identify risks to assets, products and services associated with climate related risks.
| 7.5 | If the answer to 7.4 is yes, describe the assessment process. If assessment results are reported (CDP, GRI, Sustainability or Corporate Responsibility reports), provide the reporting platform and/or report. |
| Requirement: Documentation |
This standard is met when the prime contractor provides the reporting platform or report from the assessment performed.
| 7.6 | Does your organization have a disaster response plan that includes contingency plans and response protocols for potential short-term acute events (e.g., hurricane, earthquake, flooding, and etc.) and long-term climate related risks impact (e.g.; changes in precipitation, increased average temperature, and sea level rise)? |
| Requirement: Documentation |
This standard is met when the prime contractor provides a disaster response plan that addresses short term and long term impacts from climate related risks.
Reference NIST SP 800-161 R1 Page 241
| 7.7 | Does your organization's disaster response plan include how to manage potential increases in frequency, severity, or duration of weather events? |
| Requirement: Documentation |
This standard is met when the prime contractor's disaster response plan (submitted as part of 7.6) includes management of potential increases in the frequency, severity and/or duration of weather events.
| 7.8 | Does the disaster response plan describe which assets, products, services would most significantly disrupt operations if they experienced short term acute damage (immediate failure, either temporary or catastrophic). |
| Requirement: Documentation |
This standard is met when the prime contractor's disaster response plan includes a list of assets, products, and/or services that would most significantly disrupt operations if they experienced short term acute damage.
| 7.9 | Does the disaster response plan describe which assets, products, services, would most significantly disrupt operations if they experienced gradual long-term cumulative damage (slower degradation; greater wear and tear). |
| Requirement: Documentation |
This standard is met when the prime contractor's disaster response plan includes a list of assets, products, and/or services that would most significantly disrupt operations if they experienced gradual long term cumulative damage.
https://www.cisa.gov/free-cybersecurity-services-and-tools image1.png
File details come from the government source that posted it. Updated .