J-3 Cybersecurity _ Supply Chain Risk Management (C-SCRM) Deliverables.xlsx

XLSX spreadsheet 133 KB Posted

Attached to
One Acquisition Solution for Integrated Services Plus (OASIS+) Women-Owned Small Business (WOSB) Set-Aside - Closed Federal contract opportunity
Solicitation number
47QRCA23R0005
Issued by
GSA Federal Acquisition Service

View the file

Other files for this federal contract opportunity

Other files attached to One Acquisition Solution for Integrated Services Plus (OASIS+) Women-Owned Small Business (WOSB) Set-Aside - Closed, newest first.
File Type Posted
OASIS Plus WOSB Successful Offeror List 10.6.2025.xlsx XLSX spreadsheet
OASIS Plus WOSB Successful Offeror List 09.09.2025.xlsx XLSX spreadsheet
OASIS Plus WOSB Successful Offeror List 06.18.2025.xlsx XLSX spreadsheet
OASIS Plus WOSB Successful Offeror List 4.4.2025.xlsx XLSX spreadsheet
OASIS Plus Proposal Validity Extension Template.pdf PDF
OASIS Plus WOSB Successful Offeror List 9-19-24.xlsx XLSX spreadsheet
OASIS Plus Post-Closing Amendment 0006 Questions and Answers.pdf PDF
OASIS Plus WOSB 47QRCA23R0005 SF30 Continuation Page (Amd 0006).pdf PDF
OASIS Plus WOSB 47QRCA23R0005 SF30 (Amd 0005).pdf PDF
OASIS Plus WOSB 47QRCA23R0005 SF30 Continuation Page (Amd 0005).pdf PDF
OASIS Plus Questions and Answers Group Four Revised 9.15.2023.pdf PDF
OASIS Plus WOSB 47QRCA23R0005 SF30 (Amd 0004).pdf PDF
OASIS Plus Questions and Answers - Group Four.pdf PDF
OASIS Plus Questions and Answers - Group Three Revised 09.07.2023.pdf PDF
OASIS Plus WOSB RFP 47QRCA23R0005 (Conformed Copy) (Amd 0003).pdf PDF
OASIS Plus WOSB 47QRCA23R0005 SF30 Continuation Page (Amd 0003).pdf PDF
J.P-1 OASIS Plus Domain Qualifications Matrix and Scorecards (Amd 0003).xlsx XLSX spreadsheet
J.P-3 Project Verification Form (Amd 0003).pdf PDF
J.P-5 Functional Areas and Sub-Areas (Amd 0003).pdf PDF
OASIS Plus WOSB 47QRCA23R0005 SF30 (Amd 0003).pdf PDF
OASIS Plus Questions and Answers Group Three 09.05.23.pdf PDF
OASIS Plus Questions and Answers - Group Two Revised 08.31.2023.pdf PDF
OASIS Plus Questions and Answers - Group Two.pdf PDF
OASIS Plus Questions and Answers - Group One Revised 08.24.2023.pdf PDF
OSP (Symphony) Demo Webinar Slides (August 16).pdf PDF
OASIS Plus WOSB RFP 47QRCA23R0005 (Conformed Copy) (Amd 0002).pdf PDF
J.P-1 OASIS+ Domain Qualifications Matrix and Scorecards (Amd 0002).xlsx XLSX spreadsheet
J.P-3 Project Verification Form (Amd 0002).pdf PDF
J.P-2 FPDS Sample (Amd 0002).pdf PDF
J.P-8 Direct Labor Hourly Rate Ranges (Amd 0002).xlsx XLSX spreadsheet
J.P-9 Cost-Price Template (Amd 0002).xlsx XLSX spreadsheet
J-3 Cybersecurity _ Supply Chain Risk Management (C-SCRM) Deliverables (Amd 0002).xlsx XLSX spreadsheet
J.P-1 OASIS Plus Domain Qualifications Matrix and Scorecards (Amd 0001).xlsx XLSX spreadsheet
OASIS Plus WOSB 47QRCA23R0005 SF30 (Amd 0001).pdf PDF
OASIS Plus WOSB 47QRCA23R0005 RFP (Conformed Copy) (Amd 0001).pdf PDF
J.P-3 Project Verification Form (Amd 0001).pdf PDF
OASIS Plus Final RFP Cover Letter.pdf PDF
SF33-22_WOSB.pdf PDF
J.P-6 Past Performance Rating Form.pdf PDF
J.P-8 Direct Labor Rate Ranges.pdf PDF
J-1 OASIS Plus Labor Categories and Bureau of Labor Statistics Standard Occupational Classifications.pdf PDF
J.P-1 OASIS Plus Domain Qualifications Matrix and Scorecards.xlsx XLSX spreadsheet
J.P-3 Project Verification Form.pdf PDF
J.P-4 OASIS Plus Domain Auto-Relevant NAICS Codes and PSCs.xlsx XLSX spreadsheet
J.P-9 Cost Price Template.xlsx XLSX spreadsheet
J-4 Department of Defense Required Provisions and Clauses for Task Orders.pdf PDF
Attachment A - Industry FAQs for OASIS Plus.pdf PDF
OASIS Plus WOSB RFP 6.15.2023.pdf PDF
J.P-7 Joint Venture Work _ Qualifications Template.pdf PDF
J.P-10 OASIS Plus Individual Model Subcontracting Plan.pdf PDF
Show all 50

One Acquisition Solution for Integrated Services Plus (OASIS+) Women-Owned Small Business (WOSB) Set-Aside - Closed has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Pre-Award Evaluation Instructio

Basic Safeguarding of Covered Contractor Information Systems
INSTRUCTIONS

QUESTIONNAIRE COMPLETION INSTRUCTIONS:

● Provide a contact (name, title, offeror name, phone number, and e-mail address) for questions, support, or additional information related to the questionnaire to the respondents.
● Provide your responses in the gray shaded lines of the questionnaire.
Definitions:
Covered contractor information system means an information system that is owned or operated by a contractor that processes, stores, or transmits Federal contract information.
Federal contract information means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public (such as on public websites) or simple transactional information, such as necessary to process payments.
Information means any communication or representation of knowledge such as facts, data, or opinions, in any medium or form, including textual, numerical, graphic, cartographic, narrative, or audiovisual (Committee on National Security Systems Instruction (CNSSI) 4009).
Information system means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information ( 44 U.S.C. 3502).
Safeguarding means measures or controls that are prescribed to protect information systems.

Pre-Award Eval. - Basic Safegua

Basic Safeguarding of Covered Contractor Information Systems Questionnaire

Status: Not Started
Section 1:Contact InformationVendor Response
1.1Enter the name of the offeror.
1.2Enter the name of the primary Point-Of-Contact (POC) for the offeror.
1.3Enter the E-mail Address of the primary POC for the offeror.
1.4Enter the phone number of the primary POC for the offeror in the following format: (555) 555-5555
Section 2:Access ControlNIST SP 800-53 Control
2.1Does your organization limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems)?AC-2

AC-3

AC-17

AC-20

AC-22

2.2Does your organization limit information system access to the types of transactions and functions that authorized users are permitted to execute?
2.3Does your organization verify and control/limit connections to and use of external information systems?
2.4Does your organization control information posted or processed on publicly accessible information systems?
Section 3:Identification and AuthenticationNIST SP 800-53 Control
3.1Does your organization identify information system users, processes acting on behalf of users, or devices?IA-2

IA-3

IA-5

3.2 Does your organization authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems?

Section 4:Media ProtectionNIST SP 800-53 Control
4.1Does your organization sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse?MP-2

MP-4

MP-6

Section 5:Physical ProtectionNIST SP 800-53 Control
5.1Does your organization limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals?PE-2

PE-3

PE-4

PE-5

PE-6

5.2 Does your organization escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices?

Section 6:System and Communications ProtectionNIST SP 800-53 Control
6.1Does your organization monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems?SC-7
6.2Does your organization implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks?
Section 7:System and Information IntegrityNIST SP 800-53 Control
7.1Does your organization identify, report, and correct information and information system flaws in a timely manner?SI-2

SI-3

SI-5

7.2Does your organization provide protection from malicious code at appropriate locations within organizational information systems?
7.3Does your organization update malicious code protection mechanisms when new releases are available?
7.4Does your organization perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed?

Data (HIDE)

StatusScoreStatusNot ReviewedYesNoNot ApplicableAlternativeTotal
No Completed0%Counts15000015
Pct100%0%0%0%0%100%

DL (HIDE)

GWACSPoolImplementation StatusAnswer
Alliant/ Alliant 2Small Business (SB) PoolSatisfiedYes
Alliant SBHUBZone SB (HUBZone) PoolPartially SatisfiedNo
8(a) STARS IIWomen Owned SB (WOSB) PoolNot Satisfied
VETS/ VETS2OtherNot Applicable
TBD
Not Reviewed

Post-Award Deliverable Instruct

CYBER-SUPPLY CHAIN RISK MANAGEMENT PLAN
INSTRUCTIONS
INTRODUCTION:
U.S. adversaries have attacked our nation's supply chains and compromised Federal Government systems, capitalizing on security weaknesses in U.S. companies and third party affiliates. It is incumbent on GSA's industrial base to implement vigilant Supply Chain Risk Management procedures.

This document is intended to evaluate a contractor's SCRM maturity.

TEMPLATE COMPLETION INSTRUCTIONS:
● Provide a contact (name, email, and phone number) for questions, support, or additional information related to the questionnaire to the respondents.
● We recommend designating one primary POC from your organization who will collaborate with the appropriate POCs/teams/vendor/supplier to coordinate and collect and compile responses for each section. The appropriate POCs within each organization will vary and may consist of individuals in information technology, acquisition, procurement, supply chain, or security offices. While related, each section is design to be relevant to a different aspect of your organization. This template is intended to gather an initial and consistent baseline and additional follow-up questions from the organization, or other documentation, may be warranted.
● Provide your responses in the gray shaded lines of the template under Column C, Vendor Response.
● Provide a response to each ‘Yes’, ‘No’ question as relevant to the offering.
● Attach supporting documents to the completed SCRM Plan Template by embedding documents in line. You may provide links instead if documentation is available online and accessible.
● Blue text indicates the criteria that a given question is evaluated by and includes references to NIST Special Publications or other resources for further information.

If the requested supply chain risk management information on the next tab has previously been provided to the requesting organization, provide an updated revision covering material changes.

Critical Component is defined as: A system element that, if compromised, damaged, or failed, could cause a mission or business failure

Reference links:
NIST 800-161
NIST 800-53

https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/finalhttps://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final Post-Award Deliverable - C-SCRM

C-SCRM PLAN TEMPLATE

CONTACT INFORMATION
Name of Respondent:
Title:
Name of Organization:
Phone number:
Email:
SECT. 1SUPPLY CHAIN PROVENANCEVENDOR RESPONSE
Identity - including that of each parent and/or subsidiary corporate entities.
1.1Are suppliers of critical ICT components identified?
Requirement: Attestation

This standard is met when the prime contractor attests to having identified suppliers of critical components included in ICT supplies and services that will be sold to the government through this contract.

1.2Is the company ownership of suppliers of critical ICT components verified?
Requirement: Attestation

This standard is met when the prime contractor attests to verifying the company ownership of all suppliers of critical components included in ICT supplies and services that will be sold to the government through this contract.

1.3Are suppliers of critical ICT components under U.S. ownership?
Requirement: Attestation

This standard is met when the prime contractor attests that all suppliers of critical components included in ICT supplies and services that will be sold to the government through this contract are U.S. owned companies.

1.4If distributors will be used to provide products/services to the Government, is a threat analysis performed for each distributor? If "yes", provide the process.
Requirement: Documentation

If distributors are not used, this standard is met with a response of "no".

If distributors are used, this standard is met when the prime contractor documents the process to perform a threat analysis for distributors of ICT supplies and services that will be sold to the government through this contract.

Reference NIST 800-161 4.1.4 for Threat Analysis.

1.5Are any subcontractors and/or suppliers located outside the United States or its territories? If "yes", list company name(s) and foreign country location(s).
Requirement: Attestation

This standard is met when the contractor attests that no subcontractors or suppliers are located outside the of the U.S. If any subcontractors or suppliers are located outside of the U.S., this standard is met when all subcontractors/suppliers are listed, along with the locations of each.

Reference NIST SP 800-53 SR-6, Supplier Assessments and Reviews

1.6Are controls aligned to the SCRM Baseline as stipulated in NIST SP 800-161, Supply Chain Risk Management Practices for Federal Information Systems and Organization? If yes, demonstrate how in Section 1.7. If "no", mark N/A in Section 1.7 and proceed to Section 2.1.
Requirement: Attestation

This standard is met when the prime contractor attests that the ICT SCRM Security Controls in Chapter 3.5 are followed.

1.7Provide evidence of control alignment with NIST SP 800-161.
Requirement: Documentation

This standard is met when the prime contractor provides a SCRM or Security plan with well defined operational controls and referenced policies or a third party assessment to demonstrate the alignment.

This question ensures that contractors have policies/procedures that are fully aligned with NIST 800-161.

SECT. 2SUPPLY CHAIN MANAGEMENT AND SUPPLIER GOVERNANCE
General
2.1Are policies/processes in place to ensure timely notification of updated risk management information previously provided to the Contracting Officer and Contracting Officer's Representative? If "yes" cite the section where the policy is documented.
Requirement: Documentation

This standard is met when the prime contractor demonstrates the process and policies that ensure timely notification of updated risk management information.

This question ensures that policies are regularly updated and communicated to customers to ensure regular maintenance of established processes/procedures for SCRM.

Information Communications Technology (ICT) Supply Chain Management
2.2Is there a documented Quality Management System (QMS) based on an industry standard or framework for the prime contractor's Information and Communications Technology (ICT) supply chain operation? If "yes" provide QMS documentation.
Requirement: Documentation

This standard is met when the prime contractor provides the QMS documentation.

This question asks whether the prime contractor has policies and procedures in place to address supply chain risks. If the company is fully compliant with ISO 9001, then we may have more confidence in their implementation, auditing, training, and change management processes. If the company is not fully compliant with ISO 9001, then we may need to dig deeper to understand whether they have effective implementation, audit plans, training, change management processes, etc. This question ensures that the prime contractor is thinking about its supply chain throughout the lifecycle.

Reference ISO 9001:2015; NIST SP 800-161

Supplier Governance
2.3Do Supply Chain Risk Management (SCRM) requirements exist in contracts with critical ICT suppliers? If "yes", provide the specific contract language which stipulates the SCRM/C-SCRM requirements.
Requirement: Documentation

This standard is met when the prime contractor provides documented C-SCRM/SCRM requirements in contract language.

The Government wants to know that the supplier not only has a comprehensive and robust SCRM program for itself (which helps us to mitigate our own risk and meet customer expectations), but that it also requires the same from its sub-suppliers. We also want to ensure that the supplier ensures that “externally provided processes, products and services” conform to the SCRM requirements expected from the supplier and ensure that the supplier can meet the expectations of its customers. Suppliers must establish incident handling, including preparation, detection analysis, containment and recovery. We want incidents to be addressed with appropriate mitigations. Finally, we want to ensure that we are notified of changes in subcontractors because those changes could impact our ability to appropriately identify our own supply chain risks and our ability to meet the customers’ expectations.

Reference NIST SP 800-53; NIST IR 7622; SIG LITE 2020; ISO 8.4; NIST SP 800-161

2.4Is there a process to verify that suppliers are meeting SCRM contractual terms and conditions, including, where applicable, requirements to be passed down to sub-suppliers?
Requirement: Documentation

This standard is met when the prime contractor provides documented processes and/or policies that ensure suppliers meet SCRM contractual terms and conditions.

Reference NIST SP 800-53; NIST IR 7622; SIG LITE 2020; ISO 8.4; NIST SP 800-161

SECT. 3INFORMATION SECURITY
Identify
3.1Is there a process used to verify that information is categorized according to legal, regulatory, or internal sensitivity requirements? If a process is established by policy, provide the policy.
Requirement: Documentation

This standard is met when the prime contractor documents the processes to verify that information is appropriately categorized.

This question assesses the risk: Breach of confidentiality ISO 27003:2013 sect 7.5.3.

Reference NIST SP 800-53: SI-12 Information Management and Retention, RA-2 Security Categorization

3.2Are the policies and procedures referenced in 3.1 reviewed and updated annually? When was the most recent review?
Requirement: Attestation

This standard is met when the prime contractor attests that policies and procedures are reviewed and updated annually, and the provides the date of the most recent review.

Detect
3.3Are incident detection and reporting practices defined and documented which outline the actions that should be taken in the case of an information security or cybersecurity event? If "yes", provide the documented practices.
Requirement: Documentation

This standard is met when the prime contractor provides their incident detection and reporting documentation/practices.

This question assesses the risk of a delay in, or inability to, recover from cybersecurity events.

Reference ISO 27003:2017 sect 16.1.1

3.4Are cybersecurity events centrally logged, tracked, and continuously monitored? If "yes", provide documentation regarding events are monitored.
Requirement: Documentation

This standard is met when the prime contractor provides documentation regarding how cybersecurity events are logged, tracked, and continuously monitored.

3.5Is endpoint protection software deployed throughout the prime contractor's environment? If "no", describe the mitigation efforts used instead.
Requirement: Attestation

This standard is met when the prime contractor attests that endpoint protection software is used pervasively in their environment. If not used, additional mitigation efforts must be described.

Reference NIST CSF1.1 PR.IP* Information Protection Processes and Procedures Free endpoint software can be found on this list from CISA: https://www.cisa.gov/free-cybersecurity-services-and-tools

3.6Is there a documented incident response process and a dedicated incident response team (CSIRT - Computer Security Incident Response Team)? If "no", describe the mitigation efforts used instead.
Requirement: Attestation

This standard is met when the prime contractor attests to having an incident response process and dedicated incident response team. If no process or team exists, mitigation efforts must be described.

This question assesses the risk of the contractor's ability to maintain operational continuity during/after an attack.

Reference CNSSI 4009-2015 under incident handling; NIST SP 800-61.; Shared Assessments Standardized Control Assessment (SCA) sect. K.4

SECT. 4PHYSICAL SECURITY
General
4.1Is the entity (organization, operational unit, facility, etc.) currently covered by an unrestricted/unlimited National Industrial Security Program (NISP) Facility Clearance (FCL) or a related U.S. government program such as C- TPAT that certifies the entity as meeting appropriate physical security standards? If "yes", documentation the certification and date of last certification.
Requirement: Documentation

This standard is met when the prime contractor responds yes and provides documentation regarding the certification program and date of certification for the covered entity, or responds no.

Reference DoD 5220.22, Volume 2, August 1, 2018 (National Industrial Security Program: Industrial Security Procedures for Government Activities, Incorporating Change 1, September 30, 2020 (all applicable chapters, section, paragraphs))

4.2Are security policies and procedures documented which address the control of physical access to cyber assets (network devices, data facilities, patch panels, industrial control systems, programmable logic, etc.)? If "yes", provide documented security policies/procedures.
Requirement: Documentation

This standard is met when the prime contractor documents their security policies and procedures. Reference the specific standard if security policies align to an industry standard.

See NIST SP 800-53 PE-1, PE-2, PE-3.

4.3Are physical security industry standards/controls adhered to? (e.g., NIST publication, ISO, UL, etc.) If "yes", list the industry standards/controls.
Requirement: Documentation

This standard is met when the contractor lists applicable physical security industry standards/controls that are adhered to.

Controls may align with NIST SP 800-53 Controls PE-1, PE-2 and PE-3.

Reference ONSAT-PSP-14.3, NIST 800-161 AT-3 - Security Training, ISO 27001:2013

4.4Are the policies and procedures listed in 4.3 reviewed and updated at least annually? When was the most recent review?
Requirement: Attestation

This standard is met when the prime contractor attests that policies are reviewed and updated annually and procedures are reviewed and updated at least every three years, and the provides the date of the most recent review (within the past three years).

4.5Does a documented Security Incident Response process exist which covers physical security incidents at the prime contractor's owned or operated facilities (e.g., potential intruder access, missing equipment, etc.)? If "no", describe mitigation efforts.
Requirement: Attestation

This standard is met when the prime contractor attests to having a documented security incident response process. If no process exists, mitigation efforts must be described.

Physical Security In-transit
4.6Are requirements in place to ensure the use of Original Equipment Manufacturer (OEM) or Authorized Distributors for all critical ICT components?
Requirement: Documentation

This standard is met when the prime contractor documents the policies/practices that ensure all critical ICT components are sourced from the OEM or authorized distributors.

Reference IEC:IECEE, IECQ, ISO 28000, ISO 12931, ISO 16678

4.7Are counterfeit prevention requirements passed on to second and third party suppliers?
Requirement: Documentation

This standard is met when the prime contractor documents a policy that requires third party suppliers to provide authorized critical ICT components.

Reference IEC:IECEE, IECQ, ISO 28000, ISO 12931, ISO 16678

SECT. 5PERSONNEL SECURITY
General
5.1Is a personnel security program implemented at the prime contractor's owned or operated facilities? If "yes", list address(es) and, if implemented by a third party, the company(ies) used. If the prime contractor does not own or operate a facility, mark N/A, and skip to question 5.3.
Requirement: Attestation

This standard is met when the prime contractor attests to implementing a personnel security program and lists the address(es) that this program applies to. If a third party is contracted, list the name of the company/companies used.

5.2Are physical security practices documented or formally governed? If "yes", provide the documentation, or cite the section where the documentation can be found.
Requirement: Documentation

This standard is met when the prime contractor documents the physical security practices in place.

Onboarding
5.3Are policies documented for conducting background checks of prime contractor employees as permitted by each country in which you operate? If "yes", provide the documented policy or cite where it can be found.
Requirement: Documentation

This standard is met when the prime contractor provides the documented policy for conducting background checks as permitted, or lists the controls used in physical security practices.

This question measures how new employees are introduced to the organization’s security principles and culture during the initial point of entry.

Examples include: NIST SP 800-53 PS-1, PS-2 and PS-3 and:

• NIST CSF: ID.AM-6, ID.GV-2

• SP 800-53: SA-3, SA-8

• SP 800-160: 3.2.1, 3.2.4, 3.3.1

• SP 800-181: K0233

• NIST CSF: PR.AT-*

• SP 800-160: 3.2.4

• SP 800-181: OV-TEA-001, OV-TEA-002; T0030, T0073, T0320; K0204, K0208, K0220, K0226, K0243, K0245, K0252; S0100, S0101; A0004, A0057

• SP 800-181: T0001, T0004

• NIST Cybersecurity Framework (2018) - https://www.nist.gov/cyberframework

SECT. 6SUPPLY CHAIN INTEGRITY
General
6.1Are documented processes in place for managing third-party products and component defects throughout their lifecycle? If "yes", provide the documented process or cite where it can be found.
Requirement: Documentation

This standard is met when the prime contractor provides the process documentation for managing third party products and components.

Third-party HW/SW products may not have as stringent quality control and defect analysis and therefore could be at higher risk for non-conformance or being counterfeit.

Reference NIST 800-53 SR-1, SR-2, SR-3, SR-11

6.2What provisions for auditing are included within supplier contracts?
Requirement: Documentation

This standard is met when the prime contractor documents the processes for auditing in supplier contracts.

Regular audits ensure that processes are being performed and running as desired and offer opportunities for improvements. Passing down audit requirements to suppliers ensures supplier integrity of your suppliers.

Reference NIST 800-53 and NIST 800-161 AU-1, AU-2 and AU-3, and ISO 27036; ONSAT – AIA 4.1

6.3Are hardware/software products or services integrity and End of Life requirements passed down to second and third party suppliers? If "yes", provide a documented process or policy.
Requirement: Documentation

This standard is met when the prime contractor documents the processes for managing third party supplier integrity requirements.

Reference NIST 800-53 SR-3(3) and ISO 27036; ONSAT – AIA 4.1

6.4Are processes in place for addressing reuse and/or recycle of hardware products? If "yes", provide the process document.
Requirement: Documentation

This standard is met when the prime contractor provides a process document for managing reuse/recycling of hardware products.

Lack of controlled disposal procedures could increase risks of counterfeiting and unintended uses.

Reference NIST 800-53 MP-6 and R2:2013 - Sustainable Electronics Recycling International, sect 15

SECT. 7SUPPLY CHAIN RESILIENCE
General
7.1Is a formal process documented for ensuring supply chain resilience as part of your product offering SCRM practices? If "yes", provide the process document.
Requirement: Documentation

This standard is met when the prime contractor documents the process for ensuring supply chain resilience.

This question is intended to measure the extent to which the company has the ability to withstand and recover from deliberate attacks, accidents, or naturally occurring threats or incidents to its Critical ICT elements and assets.

Reference NIST 800-53 SR-1, SR-2, SR-3, CP-2 and CP-8, and 800-161 supplementary guidance; EO 13873

Supply Chain Disruption Risk Management (Business Continuity)
7.2Can prime contractor personnel work remotely? If "yes", provide policies, practices, and software allowing remote work.
Requirement: Documentation

This standard is met when the prime contractor documents policies, practices, and software allowing remote work.

This question is intended to address how organizations provide secure access to data and information systems for employees working remotely.

Reference NIST 800-53 PE-17 and NIST 800-161 supplementary guidance

7.3Is a data backup policy in place that aligns with NIST SP 800-53 CP-9? If "yes", provide the policy. Address if the data backup location is offsite and, additionally, if the backup location is outside the immediate climatic or geographical area (e.g., not in the same floodplain).
Requirement: Documentation

This standard is met when the prime contractor documents a data backup policy that aligns with NIST 800-53 CP-9, or an equivalent standard.

7.4Has your organization conducted vulnerability assessments, risk assessment, or other calculations to identify what impact physical risks associated with climate related risks (e.g., increases in precipitation-driven flooding, extreme heat events, and inundation due to sea level rise and storm surge) might have on your assets, products, and/or services?
Requirement: Attestation

This standard is met when the prime contractor attests to conducting assessments/calculations to identify risks to assets, products and services associated with climate related risks.

7.5If the answer to 7.4 is yes, describe the assessment process. If assessment results are reported (CDP, GRI, Sustainability or Corporate Responsibility reports), provide the reporting platform and/or report.
Requirement: Documentation

This standard is met when the prime contractor provides the reporting platform or report from the assessment performed.

7.6Does your organization have a disaster response plan that includes contingency plans and response protocols for potential short-term acute events (e.g., hurricane, earthquake, flooding, and etc.) and long-term climate related risks impact (e.g.; changes in precipitation, increased average temperature, and sea level rise)?
Requirement: Documentation

This standard is met when the prime contractor provides a disaster response plan that addresses short term and long term impacts from climate related risks.

Reference NIST SP 800-161 R1 Page 241

7.7Does your organization's disaster response plan include how to manage potential increases in frequency, severity, or duration of weather events?
Requirement: Documentation

This standard is met when the prime contractor's disaster response plan (submitted as part of 7.6) includes management of potential increases in the frequency, severity and/or duration of weather events.

7.8Does the disaster response plan describe which assets, products, services would most significantly disrupt operations if they experienced short term acute damage (immediate failure, either temporary or catastrophic).
Requirement: Documentation

This standard is met when the prime contractor's disaster response plan includes a list of assets, products, and/or services that would most significantly disrupt operations if they experienced short term acute damage.

7.9Does the disaster response plan describe which assets, products, services, would most significantly disrupt operations if they experienced gradual long-term cumulative damage (slower degradation; greater wear and tear).
Requirement: Documentation

This standard is met when the prime contractor's disaster response plan includes a list of assets, products, and/or services that would most significantly disrupt operations if they experienced gradual long term cumulative damage.

https://www.cisa.gov/free-cybersecurity-services-and-tools image1.png

File details come from the government source that posted it. Updated .