J.P-14 A3 C-SCRM Control Selections.xlsx

XLSX spreadsheet 12 KB Posted

Attached to
Alliant 3 GWAC, Request for Proposal (RFP) Federal contract opportunity
Solicitation number
47QTCB24R0009
Issued by
GSA Federal Acquisition Service

About this file

This document is the J.P-14 A3 C-SCRM Control Selections attachment for the Alliant 3 Governmentwide Acquisition Contract (GWAC) Request for Proposal (RFP) Solicitation No. 47QTCB24R0009. It contains a list of 40 NIST Cybersecurity Supply Chain Risk Management (C-SCRM) controls that offerors must address in their C-SCRM Plan as part of the proposal requirements. The controls cover areas such as access control, audit and accountability, configuration management, personnel security, risk assessment, and supply chain risk management.

The overall Alliant 3 GWAC solicitation is being issued by the General Services Administration (GSA) Federal Acquisition Service. The solicitation has an estimated proposal submission due date of October 28, 2024 and requires offerors to provide information across various templates including contractor teaming arrangements, relevant experience, subcontractor experience, past performance, pricing, and C-SCRM. Offerors must also complete a C-SCRM Responsibility Questionnaire and provide C-SCRM references. The solicitation does not provide details on any specific products or services being procured.

View the file

Other files for this federal contract opportunity

Other files attached to Alliant 3 GWAC, Request for Proposal (RFP), newest first.
File Type Posted
Alliant 3 Phase One Award Notice.pdf PDF
SF30 Amend 0012 Alliant 3.pdf PDF
Alliant 3 RFP A0011 - Version11.pdf PDF
SF30 Amend 0011 Alliant 3.pdf PDF
SF30 Amend 0010 Alliant 3.pdf PDF
Alliant 3 RFP A0010 - Version10.pdf PDF
Alliant 3 RFP A0009 - Version 9.pdf PDF
J.P-16 A3 Self-Scoring Worksheet V.5.xlsx XLSX spreadsheet
J.P-10 A3 GSA Form 527 Contractor Qualification and Financial Information V.4.pdf PDF
SF30 Amend 0007 Alliant 3.pdf PDF
Alliant 3 Pre-proposal Conference.pdf PDF
Alliant 3 RFP A0006 - Version 6.pdf PDF
SF30 Amend 0006 Alliant 3.pdf PDF
J.P-16 A3 Self-Scoring Worksheet V.4.xlsx XLSX spreadsheet
Alliant 3 RFP A0005 - Version 5.pdf PDF
SF30 Amend 0005 Alliant 3.pdf PDF
J.P-10 A3 GSA Form 527 Contractor Qualification and Financial Information V.3.pdf PDF
SF30 Amend 0004 Alliant 3.pdf PDF
Alliant 3 RFP A0004 - Version 4.pdf PDF
SF30 Amend 0003 Alliant 3.pdf PDF
J.P-7 A3 Federal Contract FPDS Crosswalk Sample V2.pdf PDF
J.P-16 A3 Self-Scoring Worksheet V.3.xlsx XLSX spreadsheet
A3 GR Set 02_09.27.24.pdf PDF
J.P-9 A3 Model Individual Subcontracting Plan Template V.3.xlsx XLSX spreadsheet
J.P-11 A3 Contractor C-SCRM Responsibility Questionnaire V.2.pdf PDF
J.P-18 A3 Labor Rate Attestation V.2.pdf PDF
A3 GR Set 01_08.23.24.xlsx XLSX spreadsheet
J.P-9 A3 Model Individual Subcontracting Plan Template V.2.xlsx XLSX spreadsheet
J.P-12 A3 C-SCRM References V.2.pdf PDF
SF30 Amend 0001 Alliant 3.pdf PDF
J.P-10 A3 GSA Form 527 Contractor Qualification and Financial Information V.2.pdf PDF
A3 SF33 47QTCB24R0009.pdf PDF
J.P-1 A3 Contractor Teaming Arrangement (CTA) Template.pdf PDF
J.P-6 A3 Past Performance Rating Template.pdf PDF
J.P-18 A3 Labor Rate Attestation.pdf PDF
J.P-4 A3 Subcontractor Experience Project Template.pdf PDF
J.P-7 A3 Federal Contract FPDS Crosswalk Sample.pdf PDF
J.P-17 A3 C-SCRM Plan Preparation Guide.pdf PDF
J.P-8 A3 Price Template.xlsx XLSX spreadsheet
J.P-10 A3 GSA Form 527 Contractor Qualification and Financial Information.pdf PDF
J.P-13 A3 C-SCRM Plan Template.xlsx XLSX spreadsheet
Alliant 3 RFP 47QTCB24R0009.pdf PDF
J.P-3 A3 Emerging Technology Relevant Experience Project Template.pdf PDF
J.P-5 A3 Small Business Engagement Template.pdf PDF
J.P-9 A3 Model Individual Subcontracting Plan Template.xlsx XLSX spreadsheet
J.P-11 A3 Contractor C-SCRM Responsibility Questionnaire.xlsx XLSX spreadsheet
J.P-12 A3 C-SCRM References.pdf PDF
J.P-15 A3 Climate Change Risk Management Plan Criteria.pdf PDF
J.P-16 A3 Self-Scoring Worksheet.xlsx XLSX spreadsheet
J.P-2 A3 Primary NAICS Code Relevant Experience Project Template.pdf PDF
Show all 50

Alliant 3 GWAC, Request for Proposal (RFP) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

40 NIST Controls

Alliant 3 Unrestricted GWAC
Solicitation No.: 47QTCB24R0009
J.P-14 A3 C-SCRM Control Selections
(See Section L.5.5.2)
Cybersecurity Supply Chain Risk Management (C-SCRM) Controls (from NIST Special Publication 800-161 Revision 1)
Control FamilyControl Family NameControl IdentifierControl (or Control Enhancement) Name
ACAccess ControlAC-2Account Management
ATAwareness and TrainingAT-3Role-based Training
AUAudit and AccountabilityAU-2Event Logging
AUAudit and AccountabilityAU-6Audit Record Review, Analysis, and Reporting
CAAssessment, Authorization, And MonitoringCA-5Plan of Action and Milestones
CMConfiguration ManagementCM-2Baseline Configuration
CMConfiguration ManagementCM-4Impact Analyses
CMConfiguration ManagementCM-8System Component Inventory
CPContingency PlanningCP-2Contingency Plan
IAIdentification and AuthenticationIA-2Identification and Authentication (Organizational Users)
IRIncident ResponseIR-5Incident Monitoring
IRIncident ResponseIR-8Incident Response Plan
MAMaintenanceMA-5Maintenance Personnel
MPMedia ProtectionMP-6Media Sanitization
PEPhysical and EnvironmentalPE-3Physical Access Control
PEPhysical and EnvironmentalPE-6Monitoring Physical Access
PLPlanningPL-8 (M,H)Security and Privacy Architectures
PMProgram ManagementPM-31 (NB)Continuous Monitoring Strategy
PSPersonnel SecurityPS-3Personnel Screening
RARisk AssessmentRA-3Risk Assessment
RARisk AssessmentRA-7Risk Response
SASystem And Services AcquisitionSA-1Policy and Procedures
SASystem And Services AcquisitionSA-2Allocation of Resources
SASystem And Services AcquisitionSA-3System Development Life Cycle
SASystem And Services AcquisitionSA-4Acquisition Process
SASystem And Services AcquisitionSA-5System Documentation
SASystem And Services AcquisitionSA-8Security and Privacy Engineering Principles
SASystem And Services AcquisitionSA-22Unsupported System Components
SCSystem And Communications ProtectionSC-7Boundary Protection
SCSystem And Communications ProtectionSC-8 (M,H)Transmission Confidentiality and Integrity
SISystem and Information IntegritySI-3Malicious Code Protection
SISystem and Information IntegritySI-5Security Alerts, Advisories, and Directives
SRSupply Chain Risk ManagementSR-1Policy and Procedures
SRSupply Chain Risk ManagementSR-4 (NB)Provenance
SRSupply Chain Risk ManagementSR-5Acquisition Strategies, Tools, and Methods
SRSupply Chain Risk ManagementSR-8Notification Agreements
SRSupply Chain Risk ManagementSR-9 (H)Tamper Resistance and Detection (note: SI-7(4) and SA-18 was incorporated)
SRSupply Chain Risk ManagementSR-10Inspection of Systems or Components
SRSupply Chain Risk ManagementSR-11Component Authenticity
SRSupply Chain Risk ManagementSR-12Component Disposal

File details come from the government source that posted it. Updated .