J.P-11 A3 Contractor C-SCRM Responsibility Questionnaire.xlsx
XLSX spreadsheet 206 KB Posted
- Attached to
- Alliant 3 GWAC, Request for Proposal (RFP) Federal contract opportunity
- Solicitation number
- 47QTCB24R0009
- Issued by
- GSA Federal Acquisition Service
About this file
This document is a Contractor C-SCRM Responsibility Questionnaire related to the Alliant 3 GWAC solicitation. The questionnaire assesses the offeror's compliance with basic safeguarding requirements for covered contractor information systems as specified in FAR 52.204-21. It covers access control, identification and authentication, media protection, physical protection, system and communications protection, and system and information integrity. The offeror must provide "Yes" or "No" responses to each question and attest that the information provided is accurate. A "No" response to any item would disqualify the offeror from receiving an Alliant 3 GWAC award. The questionnaire also includes a Basic Safeguarding Plan template that the offeror must complete. This questionnaire is one of the attachments to the Alliant 3 GWAC solicitation, which is a request for proposals (RFP) issued by the GSA Federal Acquisition Service for a new government-wide acquisition contract.
View the file
Other files for this federal contract opportunity
Show all 50
Alliant 3 GWAC, Request for Proposal (RFP) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Instructions
Basic Safeguarding of Covered Contractor Information Systems Responsiblity Assessment (FAR 52.204-21) Version 1.00 - 2022-10-13
| QUESTIONNAIRE COMPLETION INSTRUCTIONS: |
| See RFP Section L.5.5.2 |
| ● Provide a contact (name, title, offeror name, phone number, and e-mail address) for questions, support, or additional information related to the questionnaire to the respondents. |
| ● Provide your responses in the gray shaded lines of the questionnaire. All gray shaded areas must be completed andhave a response of "Yes" or "No" an must not be left blank. |
| ● Provide your signature verifying your attestation that all of the information provided is correct. |
| Definitions: |
| Covered contractor information system means an information system that is owned or operated by a contractor that processes, stores, or transmits Federal contract information. |
| Federal contract information means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public (such as on public websites) or simple transactional information, such as necessary to process payments. |
| Information means any communication or representation of knowledge such as facts, data, or opinions, in any medium or form, including textual, numerical, graphic, cartographic, narrative, or audiovisual (Committee on National Security Systems Instruction (CNSSI) 4009). |
| Information system means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information ( 44 U.S.C. 3502). |
| Safeguarding means measures or controls that are prescribed to protect information systems. |
ATTACHMENT J.P-11
Alliant 3 Unrestricted GWAC Solicitation No.: 47QTCB24R0009 ATTACHMENT J.P-11 A3 Contractor C-SCRM Responsbility Questionnaire U.S. General Services Administration Federal Acquisition Service Information Technology Category Office of Acquisition Operations Service Contract Division 2, Branch A (QT2F2BA) 1800 F. Street, N.W, 3rd Floor Washington, DC 20240
Offeror Information Vendor Response
| Enter the name of the offeror (legal entity, company name) | ||
| Enter the name of the primary Point-Of-Contact (POC) for the offeror | ||
| Enter the E-mail Address of the primary POC for the offeror | ||
| Enter the phone number of the primary POC for the offeror in the following format: (555) 555-5555 | ||
| Basic Safeguarding of Covered Contractor Information Systems Responsibility Assessment (FAR 52.204-21) | ||
| Section 1: | Access Control | Answer |
Yes / No (Must Select One) NIST SP 800-53 Control
1.1 Does your organization limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems)? AC-2
AC-3
AC-17
AC-20
AC-22
| 1.2 | Does your organization limit information system access to the types of transactions and functions that authorized users are permitted to execute? |
| 1.3 | Does your organization verify and control/limit connections to and use of external information systems? |
| 1.4 | Does your organization control information posted or processed on publicly accessible information systems? |
Section 2: Identification and Authentication NIST SP 800-53 Control
2.1 Does your organization identify information system users, processes acting on behalf of users, or devices? IA-2
IA-3
IA-5
2.2 Does your organization authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems?
Section 3: Media Protection NIST SP 800-53 Control
3.1 Does your organization sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse? MP-2
MP-4
MP-6
Section 4: Physical Protection NIST SP 800-53 Control
4.1 Does your organization limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals? PE-2
PE-3
PE-4
PE-5
PE-6
4.2 Does your organization escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices?
Section 5: System and Communications Protection NIST SP 800-53 Control
| 5.1 | Does your organization monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems? | SC-7 |
| 5.2 | Does your organization implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks? |
Section 6: System and Information Integrity NIST SP 800-53 Control
6.1 Does your organization identify, report, and correct information and information system flaws in a timely manner? SI-2
SI-3
SI-5
| 6.2 | Does your organization provide protection from malicious code at appropriate locations within organizational information systems? |
| 6.3 | Does your organization update malicious code protection mechanisms when new releases are available? |
| 6.4 | Does your organization perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed? |
| FAR 52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab and Other Covered Entities | ||
| Section 7: | FAR Provision | |
| 7.1 | Does your organization certify it does not utilize hardware, software, and services developed or provided by Kaspersky Lab and other covered entities in accordance with FAR Clause 52.204-23? | FAR 52.204-23 |
| Section 889 Compliance | ||
| Section 8: | FAR Clause/Provision | |
| 8.1 | Does your organization certify that it does not utilize certain telecommunications and video surveillance services or equipment in accordance with FAR Clause 52.204-25 by: |
1) Completing the fill-in provision located at FAR 52.204-26?
2) Including the representation in Section K of your organization's Alliant 3 Proposal?
OR
Does your organization provide representation that it does not utilize certain telecommunications and video surveillance services or equipment in accordance with FAR Provision 52.204-24 by:
1) Completing the fill-in provision located at FAR 52.204-24?
2) Including the representation in Section K of your organization's Alliant 3 Proposal? FAR 52.204-25
FAR 52.204-26
FAR 52.204-24
| Federal Acquisition Supply Chain Security Act Orders | ||
| Section 9: | FAR Clause/Provision | |
| 9.1 | Does your organization ceritify that it complies with the provision at FAR 52.204-29, Prohibition from providing or using as part of the performance of the contract any covered article, or any products or services produced or provided by a source, if the prohibition is set out in an applicable Federal Acquisition Supply Chain Security Act (FASCSA) order, as described in paragraph (b)(1) of FAR 52.204-30, Federal Acquisition Supply Chain Security Act Orders? | FAR 52.204-29 |
| 9.2 | Does your organization certify that complies with the Clause at FAR 52.204-30, Federal Acquisition Supply Chain Security Act Orders—Prohibition, Alt.1 | FAR 52.204-30, Alt. 1 |
Section 10: Certification of Responses Signature/Date (Required)
10.1 I understand that a response of "no" to any of the items above disqualifies my organization from receving an Alliant 3 GWAC Master Contract award. I understand that a separate risk assessment will be conducted by GSA and that an approval is required to be eligible for award. I hereby certify that, to the best of my knowledge, the provided information is true and accurate. (Signature Required)
| Percent Complete | 0% |
| Yes Count | 0 |
| No Count | 0 |
Basic Safeguarding Plan
Basic Safeguarding of Covered Contractor Information Systems Plan
| Status: Not Started | ||
| Section 1: | Contact Information | Vendor Response |
| 1.1 | Enter the name of the offeror. |
| 1.2 | Enter the name of the primary Point-Of-Contact (POC) for the offeror. |
| 1.3 | Enter the E-mail Address of the primary POC for the offeror. |
| 1.4 | Enter the phone number of the primary POC for the offeror in the following format: (555) 555-5555 |
Section 2: Access Control NIST SP 800-53 Control
2.1 Does your organization limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems)? AC-2
AC-3
AC-17
AC-20
AC-22
| 2.2 | Does your organization limit information system access to the types of transactions and functions that authorized users are permitted to execute? |
| 2.3 | Does your organization verify and control/limit connections to and use of external information systems? |
| 2.4 | Does your organization control information posted or processed on publicly accessible information systems? |
Section 3: Identification and Authentication NIST SP 800-53 Control
3.1 Does your organization identify information system users, processes acting on behalf of users, or devices? IA-2
IA-3
IA-5
3.2 Does your organization authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems?
Section 4: Media Protection NIST SP 800-53 Control
4.1 Does your organization sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse? MP-2
MP-4
MP-6
Section 5: Physical Protection NIST SP 800-53 Control
5.1 Does your organization limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals? PE-2
PE-3
PE-4
PE-5
PE-6
5.2 Does your organization escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices?
Section 6: System and Communications Protection NIST SP 800-53 Control
| 6.1 | Does your organization monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems? | SC-7 |
| 6.2 | Does your organization implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks? |
Section 7: System and Information Integrity NIST SP 800-53 Control
7.1 Does your organization identify, report, and correct information and information system flaws in a timely manner? SI-2
SI-3
SI-5
| 7.2 | Does your organization provide protection from malicious code at appropriate locations within organizational information systems? |
| 7.3 | Does your organization update malicious code protection mechanisms when new releases are available? |
| 7.4 | Does your organization perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed? |
Data (HIDE)
| Status | Score | Status | Not Reviewed | Yes | No | Not Applicable | Alternative | Total |
| No Completed | 0% | Counts | 18 | 0 | 0 | 0 | 0 | 18 |
| Pct | 100% | 0% | 0% | 0% | 0% | 100% |
Counts Not Reviewed Yes No Not Applicable Alternative 18 0 0 0 0
DL (HIDE)
| GWACS | Pool | Implementation Status | Answer |
| Alliant/ Alliant 2 | Small Business (SB) Pool | Satisfied | Yes |
| Alliant SB | HUBZone SB (HUBZone) Pool | Partially Satisfied | No |
| 8(a) STARS II | Women Owned SB (WOSB) Pool | Not Satisfied | |
| VETS/ VETS2 | Other | Not Applicable | |
| TBD | |||
| Not Reviewed |
image1.png image2.png
File details come from the government source that posted it. Updated .