Industry Memo for Supply Chain Risk Management (SCRM) (M-22-18 updated by M-23-16)

From: Federal Government(Federal)
EPA_SCRM_2024_01

Basic Details

started - 10 Jan, 2024 (3 months ago)

Start Date

10 Jan, 2024 (3 months ago)
due - 30 Sep, 2024 (in 5 months)

Due Date

30 Sep, 2024 (in 5 months)
Bid Notification

Type

Bid Notification
EPA_SCRM_2024_01

Identifier

EPA_SCRM_2024_01
ENVIRONMENTAL PROTECTION AGENCY

Customer / Agency

ENVIRONMENTAL PROTECTION AGENCY (3534)ENVIRONMENTAL PROTECTION AGENCY (3534)OFC OF MISSION SUPT (OMS) (FUNDING) (1)

Attachments (1)

unlockUnlock the best of InstantMarkets.

Please Sign In to see more out of InstantMarkets such as history, intelligent business alerts and many more.

Don't have an account yet? Create a free account now.

MESSAGE TO INDUSTRY Background On September 14, 2022, Office of Management and Budget (OMB) issued memorandum M-22-18, Enhancing the Security of the Software Supply Chain through Secure Software Development Practices. The memo requires Federal agencies to comply with the National Institute of Standards and Technology (NIST) Guidance when using third-party software on the agency’s information systems or otherwise affecting the agency’s information. This guidance was updated on June 9, 2023, by OMB M-23-16 which extended the due dates for attestation collection and announced metrics collection for waivers and extensions. Authority Federal Information Security Modernization Act (FISMA) and other provisions of Federal law authorize the Director of OMB to promulgate information security standards for information security systems, including to ensure compliance with standards issued by NIST. Consistent with these authorities and the directives of Executive Order (EO) 14028, the M-22-18
memorandum requires each Federal agency to comply with the NIST Guidance when using third-party software on the agency’s information systems or otherwise affecting the agency’s information. Implementation To comply with Executive Order 14028, and OMB Memorandum M-22-18 (as updated by M-23-16), EPA will update its processes to approve software including requiring vendor attestations. In line with OMB guidance in M-23-16, EPA anticipates collecting attestations for “critical software” 3 months after OMB Paperwork Reduction Act (PRA) approval of the common form; and collection of attestation letters for all other software 6 months after OMB PRA approval of the common form. EPA will begin collecting attestation letters as part of pre-award and post-award contract deliverables once final OMB guidance is received regarding use of the common form for all impacted software. To learn more, see Executive Order 14028, M-22-18, and M-23-16. Communications: This communication is being posted by EPA Office of Acquisition Solutions on behalf of EPA Chief Information Officer. Questions can be submitted at SCRM@epa.gov.

USEPA HEADQUARTERS, W J CLINTON BDG 1200 PENNSYLVANIA AVENUE, N. W.  WASHINGTON , DC 20460  USALocation

Office Address : USEPA HEADQUARTERS, W J CLINTON BDG 1200 PENNSYLVANIA AVENUE, N. W. WASHINGTON , DC 20460 USA

Country : United StatesState : District of ColumbiaCity : Washington

You may also like

SUPPLY CHAIN RISK MANAGEMENT PLATFORM

Due: 12 Feb, 2025 (in 9 months)Agency: VETERANS AFFAIRS, DEPARTMENT OF

INFORMATION AND COMMUNICATIONS TECHNOLOGY SUPPLY CHAIN RISK MANAGEMENT (ICT SCRM) TOOL

Due: 29 Sep, 2028 (in about 4 years)Agency: EDUCATION, DEPARTMENT OF

Insurance Brokerage and Risk Management Services. [Request for Proposals / 23-9934]

Due: 22 Jun, 2028 (in about 4 years)Agency: Harbor (Port of LA, POLA)

Please Sign In to see more like these.

Don't have an account yet? Create a free account now.