J.P-14 A3 C-SCRM Control Selections.xlsx
XLSX spreadsheet 12 KB Posted
- Attached to
- Alliant 3 GWAC, Request for Proposal (RFP) Federal contract opportunity
- Solicitation number
- 47QTCB24R0009
- Issued by
- GSA Federal Acquisition Service
About this file
This document is the J.P-14 A3 C-SCRM Control Selections attachment for the Alliant 3 Governmentwide Acquisition Contract (GWAC) Request for Proposal (RFP) Solicitation No. 47QTCB24R0009. It contains a list of 40 NIST Cybersecurity Supply Chain Risk Management (C-SCRM) controls that offerors must address in their C-SCRM Plan as part of the proposal requirements. The controls cover areas such as access control, audit and accountability, configuration management, personnel security, risk assessment, and supply chain risk management.
The overall Alliant 3 GWAC solicitation is being issued by the General Services Administration (GSA) Federal Acquisition Service. The solicitation has an estimated proposal submission due date of October 28, 2024 and requires offerors to provide information across various templates including contractor teaming arrangements, relevant experience, subcontractor experience, past performance, pricing, and C-SCRM. Offerors must also complete a C-SCRM Responsibility Questionnaire and provide C-SCRM references. The solicitation does not provide details on any specific products or services being procured.
View the file
Other files for this federal contract opportunity
Show all 50
Alliant 3 GWAC, Request for Proposal (RFP) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
40 NIST Controls
| Alliant 3 Unrestricted GWAC | |||
| Solicitation No.: 47QTCB24R0009 | |||
| J.P-14 A3 C-SCRM Control Selections | |||
| (See Section L.5.5.2) | |||
| Cybersecurity Supply Chain Risk Management (C-SCRM) Controls (from NIST Special Publication 800-161 Revision 1) | |||
| Control Family | Control Family Name | Control Identifier | Control (or Control Enhancement) Name |
| AC | Access Control | AC-2 | Account Management |
| AT | Awareness and Training | AT-3 | Role-based Training |
| AU | Audit and Accountability | AU-2 | Event Logging |
| AU | Audit and Accountability | AU-6 | Audit Record Review, Analysis, and Reporting |
| CA | Assessment, Authorization, And Monitoring | CA-5 | Plan of Action and Milestones |
| CM | Configuration Management | CM-2 | Baseline Configuration |
| CM | Configuration Management | CM-4 | Impact Analyses |
| CM | Configuration Management | CM-8 | System Component Inventory |
| CP | Contingency Planning | CP-2 | Contingency Plan |
| IA | Identification and Authentication | IA-2 | Identification and Authentication (Organizational Users) |
| IR | Incident Response | IR-5 | Incident Monitoring |
| IR | Incident Response | IR-8 | Incident Response Plan |
| MA | Maintenance | MA-5 | Maintenance Personnel |
| MP | Media Protection | MP-6 | Media Sanitization |
| PE | Physical and Environmental | PE-3 | Physical Access Control |
| PE | Physical and Environmental | PE-6 | Monitoring Physical Access |
| PL | Planning | PL-8 (M,H) | Security and Privacy Architectures |
| PM | Program Management | PM-31 (NB) | Continuous Monitoring Strategy |
| PS | Personnel Security | PS-3 | Personnel Screening |
| RA | Risk Assessment | RA-3 | Risk Assessment |
| RA | Risk Assessment | RA-7 | Risk Response |
| SA | System And Services Acquisition | SA-1 | Policy and Procedures |
| SA | System And Services Acquisition | SA-2 | Allocation of Resources |
| SA | System And Services Acquisition | SA-3 | System Development Life Cycle |
| SA | System And Services Acquisition | SA-4 | Acquisition Process |
| SA | System And Services Acquisition | SA-5 | System Documentation |
| SA | System And Services Acquisition | SA-8 | Security and Privacy Engineering Principles |
| SA | System And Services Acquisition | SA-22 | Unsupported System Components |
| SC | System And Communications Protection | SC-7 | Boundary Protection |
| SC | System And Communications Protection | SC-8 (M,H) | Transmission Confidentiality and Integrity |
| SI | System and Information Integrity | SI-3 | Malicious Code Protection |
| SI | System and Information Integrity | SI-5 | Security Alerts, Advisories, and Directives |
| SR | Supply Chain Risk Management | SR-1 | Policy and Procedures |
| SR | Supply Chain Risk Management | SR-4 (NB) | Provenance |
| SR | Supply Chain Risk Management | SR-5 | Acquisition Strategies, Tools, and Methods |
| SR | Supply Chain Risk Management | SR-8 | Notification Agreements |
| SR | Supply Chain Risk Management | SR-9 (H) | Tamper Resistance and Detection (note: SI-7(4) and SA-18 was incorporated) |
| SR | Supply Chain Risk Management | SR-10 | Inspection of Systems or Components |
| SR | Supply Chain Risk Management | SR-11 | Component Authenticity |
| SR | Supply Chain Risk Management | SR-12 | Component Disposal |
File details come from the government source that posted it. Updated .