14-Vendor Security Questionnaire.xlsx

XLSX spreadsheet 116 KB Posted

Attached to
Lost and Found Management Software State and local contract opportunity
Solicitation number
TCH2132330B1
Issued by
Broward County, Florida

About this file

This is an Enterprise Technology Services Vendor Security Questionnaire (VSQ) document issued by Broward County, Florida for evaluating vendor security practices in connection with a Lost and Found Management Software procurement. The questionnaire applies to vendors providing Software-as-a-Service (SaaS), hosting services, application development services, managed professional services, software installed locally on the County's network, or hardware. The document contains 167 questions organized into three main sections covering SaaS/hosting/application development services, locally-installed software, and hardware, with subsections addressing audit reporting, payment card industry compliance, HIPAA requirements, roles and responsibilities, federated identity management, third-party access, information security policies, risk assessment, regulatory compliance, employee training, background checks, employment terms, physical security, access controls, data security, audit logging, vulnerability assessment, security monitoring, identity and access management, antivirus protection, network defense, media handling, secure disposal, separation of duties, change management, incident management, disaster recovery, product security development lifecycle, cryptographic key management, secure software design and testing, and generative artificial intelligence considerations.

Vendors are required to complete the VSQ with dropdown responses of YES, NO, or N/A for each question, with a Comments section to provide supporting explanations and attach additional documentation as needed. If not provided with initial submittal, vendors must submit the completed questionnaire within three business days of the County's written request. The County will review all VSQ responses, disclose identified security concerns to the Evaluation Committee, and consider any unresolved security concerns as part of final evaluation, which may affect the vendor's overall score. Vendors must attest that all statements made in support of their responses are accurate and true; inaccurate, untruthful, or incorrect statements may result in rejection, contract award rescission, contract termination, or vendor debarment pursuant to Broward County's Procurement Code. The questionnaire was last updated on April 29, 2025.

View the file

Other files for this state and local contract opportunity

Show all 17

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Sheet1

Enterprise Technology Services
Vendor Security Questionnaire (VSQ)
ETS Vendor Security Questionnaire (VSQ): Vendor is required to submit a completed ETS Vendor Security Questionnaire (VSQ) (for applicable solution – services, hardware, and/or software). If a response requires additional information, attach additional pages with the required additional information with the additional pages and information labeled to match the applicable question number. If not provided with the submittal, the Vendor must submit within three business days after the County's written request.

The Vendor Security Questionnaire (VSQ) assesses the Vendor’s security policies and/or system protocol and to identify any potential security vulnerabilities. The County will review the Vendor’s VSQ response; any identified security concerns will be disclosed to the Evaluation Committee. Unresolved security concerns shall be considered by the Evaluation Committee as part of its final evaluation and may affect the Vendor’s evaluation.

As the Vendor's authorized representative, I attest that any and all statements, oral, written or otherwise, made in support of the Vendor's response, are accurate, true and correct. I also acknowledge that inaccurate, untruthful, or incorrect statements made in support of the Vendor's response may be used by the County as a basis for rejection, rescission of the award, or termination of the contract and may also serve as the basis for debarment of Vendor pursuant to PART XI of the Broward County Procurement Code.

Vendor Name:
Vendor Type (Manufacturer, Reseller, Other? If Other, specify.):
Vendor Contact Person's Name / Title /

Email Address:

Product Name / Description:
Solicitation Number and Title

(If applicable):

For each applicable section, complete the matrix by using the dropdown option to select YES or NO. Use "Comments" section to provide as much explanation as possible to clearly support your response. Additional pages may be attached to provide further detail, but any attachments should be referenced in "Comments" section. Select "N/A" if a question within a given section is not applicable.

SECTION 1: SOFTWARE-AS-A-SERVICE (SaaS) / HOSTING / APPLICATION DEVELOPMENT SERVICES /

MANAGED OR PROFESSIONAL SERVICES

No.AreaQuestionVendor Response
YES/NOComments
1REQUIRED RESPONSE: Will your organization provide SOFTWARE-AS-A-SERVICE (SaaS)? (e.g. Software-as-a-service/SaaS, application, website)
2REQUIRED RESPONSE: Will your organization provide HOSTING SERVICES?
3REQUIRED RESPONSE: Will your organization provide APPLICATION DEVELOPMENT SERVICES? (e.g. on-premise, mobile, web, or other custom code)
4REQUIRED RESPONSE: Will your organization provide MANAGED OR PROFESSIONAL SERVICES (UNSUPERVISED BY COUNTY PERSONNEL)?

(Note: "Managed or Professional Services" used herein refers to unsupervised (by County personnel) installation, configuration, consulting, maintenance or monitoring of County systems, applications or infrastructure related to your organization's proposed solution.)

STOP: If you selected NO for Questions 1 through 4 above, PROCEED TO SECTION 2.
5Supporting Documentation
(Upon County's request)Provide the following:

a) Workflow diagram of stored or transmitted information (for SaaS and Hosting Services only)

6b) Security / Network Architecture diagram (for SaaS and Hosting Services only)
7c) Secure Coding standard (for Application Development Services only)
8d) Application Security Program standard (for Application Development Services only)
9Audit Reporting RequirementsDoes your organization have a current System and Organization Controls (SOC) 2, Type II report, inclusive of all five Trust Service Principles (Security, Availability, Processing Integrity, Confidentiality, and Privacy)?

(Note: For any SaaS or hosted application, the SOC report should be for the organization or application specifically, not the datacenter only.)

10Payment Card Industry (PCI) environments - Applicable only if Organization or its proposed subcontractor processes or collects credit card information.Does your organization have a current Payment Card Industry (PCI) certification (e.g., Attestation of Compliance (AOC), Self-Assessment Questionnaire (SAQ))?
11Will the product or solution process or collect credit card information?
12Does your organization maintain a file integrity monitoring program to ensure critical file system changes are monitored and approved with respect to confidential County data?
13Electronic Protected Health Information (ePHI) -
Applicable only if Organization has access to or will be hosting or storing County ePHI.Has your organization had a Risk Assessment performed in the past five years by an external auditor in conjunction with the HIPAA Security rule?
14Does your organization maintain current HIPAA specific policies and procedures in conjunction with the HIPAA Security Rule?
15Does your organization have a designated HIPAA Security and Privacy Officer(s)?
16Does your organization provide HIPAA Security training to your employees at time of hire and at least annually thereafter?
17Roles & ResponsibilitiesHas your organization appointed a central point of contact for security coordination?
18Does your organization have an expected timeframe to respond to initial contact for security related issues? Provide timeframe.
19Does your organization define the priority level of an issue (e.g., minor vs. major, 0-4 scale, etc.)? Describe.
20Does your organization have an expected Service Level Agreement (SLA) to implement changes needed to fix security issues according to priority level? Describe.
21Federated Identity Management and Web Services IntegrationDoes your organization's product have Single Sign-on (SSO) and Federated Identity Enablement integration options (e.g., support for standards like SAML v2 and OAuth 2.0, active directory)? Describe.
22Does your organization use web services and/or data import/export functions (e.g., API, FTP)? Describe.
23External PartiesWill third parties, such as IT service providers have access to the County's data that is stored or transmitted by your organization?
24Does your organization have a Disaster Recovery and Continuity of Operations plan that includes third-party dependencies to ensure critical business functions can continue even during a major disruption?
25Does your organization outsource any aspect of the service to a third party?
26Does your organization utilize any off-shore resources for development? Provide location(s).
27Does your organization build the application in-house?
28Does your organization share customer data with or enable direct access by any third-party?
29Will any proposed subcontractors process, access, transmit or store any County data?
30Do all proposed subcontractors contractually comply with your organization's security standards for data processing?
31Does your organization regularly audit your critical vendors? Describe.
32Information Security Policy & ProceduresDoes your organization have documented standard policies and procedures for security and compliance?
33Risk AssessmentDoes your organization have a process that addresses: (a) the identification and measurement of potential risks with mitigating controls (measures taken to reduce risk), and (b) the acceptance or transfer (e.g. insurance policies, warranties, etc.) of the remaining (residual) risk after mitigation steps have been applied?
34Regulatory ComplianceIs the product or solution currently certified by any security standards? (e.g., PCI-DSS, HIPAA). Provide proof of compliance documentation.
35Does your organization have a documented process to identify new laws and regulations with IT security implications (e.g., FIPA, new state breach notification requirements, monitoring newsletters, webinars, security or regulatory forums, etc.)?
36Has your organization experienced a data breach within the past five years that legally required reporting under applicable law?
37Does your organization have procedures for preservation of electronic records and audit logs in case of litigation hold?
38During Employment – Training, Education & AwarenessHave employees and proposed subcontractors received formal information security awareness training? Provide frequency.
39Have your organization's security policies and procedures been communicated to your employees?
40Are periodic security reminders provided to your organization's employees?
41Background ChecksDoes your organization perform background checks (e.g., credential verification, criminal history, credit history) to examine and assess an employee’s or proposed subcontractor's work and criminal history?
42Are individuals who would have access to the County's data subjected to periodic follow-up background checks?
43Prior to Employment - Terms and Conditions of EmploymentAre employees and proposed subcontractors required to sign a non-disclosure agreement and/or confidentiality form upon initial employment?
44If so, are employees and proposed subcontractors required to sign the non-disclosure agreement annually?
45Termination or Change in EmploymentDoes your organization require that all equipment of any terminated employee or subcontractor is returned and that their user ID is disabled in all systems and badges and/or keys are returned?
46Upon transfer, is existing access reviewed for relevance for employees and subcontractors?
47Secure AreasDoes your organization have effective physical access controls (e.g., door locks, badge /electronic key ID and access controls) in place that prevent unauthorized access to facilities and a facility security plan?
48Is a locked screensaver displayed on unattended workstations?
49Do personnel abide by a clean desk policy to remove and secure sensitive/confidential information from their workspace at the end of the work day?
50Does your organization have a contingency plan in place to handle emergency access to facilities?
51Are physical access controls authorized? Describe who is responsible for managing and ensuring that only appropriate persons have keys or codes to the facility and to locations within the facility with secure data.
52Are there policies and procedures to document repairs and modifications to physical components of the facility that are related to security?
53Are employees or subcontractors permitted access to customer environments from your physical locations only?
54Application and Information Access Control - Confidential System IsolationAre systems and networks that host, process, and/or transfer confidential information "protected" (i.e., isolated, logically or physically separated) from other systems and/or networks?
55Are internal and external networks separated by firewalls with access policies and rules?
56Data SecurityAre development and test environments separate from production environments to protect production applications from inadvertent changes or disruption?
57Does your organization apply database and application logical segregation of customer data?
58Is this a multi-tenant solution?
59Will County’s data be co-mingled with data of any other customer?
60Does your organization provide a means to encrypt data at rest (e.g., AES)?
61Will County’s data be processed, accessed, transmitted or stored through an off shore environment (e.g., outside continental U.S, Alaska, Hawaii)?
62Does your organization provide a means to encrypt County confidential information in transit? Describe controls that are in place to protect confidential information when transferred (e.g., encryption).
63Is there a standard approach for protecting network devices to prevent unauthorized access/network related attacks and data-theft (e.g., firewall between public and private networks, internal VLAN, firewall separation, separate WLAN network, secure portal, multi-tenancy, virtualization, shared storage, etc.)?
64Does your organization use email encryption to protect sensitive/confidential information when communicating with third parties (e.g., IT vendors)?
65Are employees permitted to work remotely from a facility not owned or leased by the organization?
66Are encrypted communications required for all remote connections?
67Does your organization use a secure VPN connection with third parties (e.g., IT vendors)?
68Does your organization have protections in place for ensuring secure remote access (e.g., up-to-date antivirus, posture assessment, VPN enforcement, split tunneling)?
69Is there a formal (documented, approved, published, communicated, and implemented) remote access policy?
70Can your organization restrict access to the solution to and from the County's network in a "deny all, permit by exception" configuration (i.e., whitelist County IP addresses only)?
71Audit LoggingDoes the software or solution perform audit logging? Describe.
72Does the software or solution allow for the configuration of audit log retention for a minimum of 90 days or more?
73Does the software track events for user activity (e.g., failed/successful logins, privileged access)? Describe.
74Vulnerability Assessment and RemediationDoes your organization perform periodic vulnerability scans on your IT systems, networks, and supporting security systems? Provide frequency.
75Are internal or proposed subcontractors vulnerability assessments automated?
76Does your organization have a security patch management cycle in place to address identified vulnerabilities?
77Does your organization provide disclosure of vulnerabilities found in your environment and remediation timelines?
78Does your organization notify customer of applicable patches?
79Security MonitoringAre third party connections to your network monitored and reviewed to confirm only authorized access and appropriate usage (e.g., with VPN logs, server event logs, system, application and data access logging, automated alerts, regular/periodic review of logs or reports)?
80Does your organization monitor your systems and networks for security events? Describe monitoring (e.g., server and networking equipment logs such as servers, routers, switches, wireless APs, monitored regularly).
81Does your organization periodically review system activity? Provide frequency.
82Identity & Access ManagementDoes your organization have a formal access authorization process based on "least privilege" (i.e. employees are granted the least amount of access possible to perform their assigned duties) and "need to know" (e.g., access permissions granted based upon the legitimate business need of the user to access the information, role-based permissions, limited access based on specific responsibilities, network access request form)?
83Are systems and applications configured to restrict access only to authorized individuals (e.g., use of unique IDs and passwords, minimum password length, password complexity, log-in history, lockout, password change, expiration)?
84Is there a list maintained of authorized users with general access and administrative access (e.g., active directory user lists within a confidential application, a spreadsheet of users, a human resources file)?
85Does your organization maintain a list of "accepted mobile devices" (e.g., smart phones, cell phones) and are these devices tracked and managed (e.g., Mobile Device Management)?
86Is a Data Loss Prevention (DLP) in place to prevent the unauthorized distribution of confidential information?
87Is software installation for desktops, laptops, and servers restricted to administrative users only?
88Does software or system have automatic logoff for session inactivity?
89Does your organization control and monitor access to application source code in a secure manner?
90Does your organization deny developers access to production environments, as well as to any environments containing customer data?
91Are user IDs for your system uniquely identifiable?
92Does your organization have any shared accounts? Describe.
93Will your organization allow remote access from proposed subcontractors to the County network, with immediate deactivation after use?
94Can service accounts be configured to run as non-privileged user (i.e., non-Domain Admin)?
95Is Multi-Factor Authentication (MFA) required for employees/contractors for remote access to production systems?
96Is Multi-Factor Authentication (MFA) included as a feature in the proposed system?
97Entitlement ReviewsDoes your organization have a process to review user accounts and related access (e.g., manual process of reviewing system accounts to user accounts in AD for both users and privileged access, such as admins, developers, etc.)?
98AntivirusIs antivirus software installed and running on your computers and supporting systems (e.g., desktops, servers, gateways, etc.)?
99Is this antivirus product centrally managed (e.g., monitored to verify all endpoints have functional agents, agents are up to date with the latest signatures, etc.)? Explain your policies and procedures for management of antivirus software.
100Does your organization have a process for detecting and reporting malicious software?
101Network Defense and Host Intrusion Prevention SystemsDoes your organization have any Intrusion Protection System (IPS) in place for your environment?
102Are employees prevented from using personally owned smart phones or mobile devices to connect to the organization's network?
103Media HandlingDoes your organization have procedures to protect documents and computer media (e.g., tapes, disks, hard drives, etc.) from unauthorized disclosure, modification, removal, and destruction?
104Is confidential data encrypted when stored on laptop, desktop, server hard drive, flash drive, backup tape (i.e., data at rest)?
105Are backup archives stored externally / offsite from your facility?
106Secure DisposalAre there security procedures (e.g., use of secure wiping, NIST 800-88, etc.) for the decommissioning (replacement) of IT equipment and IT storage devices that contain or process confidential information?
107Separation of DutiesAre duties separated (e.g., front desk duties separated from accounting, data analysts access separated from IT support), where appropriate, to reduce the opportunity for unauthorized modification, unintentional modification, or misuse of your IT assets?
108Change ManagementDo formal testing and change management procedures exist for networks, systems, desktops, software releases, deployments, and software vulnerability during patching activities, changes to the system, changes to the workstations and servers with appropriate testing, notification, and approval, etc.?
109Incident ManagementIn the event of a major security incident or data breach, do you provide the County a third-party digital forensics/incident report?
110Does your organization identify, respond to, and mitigate suspected or known security incidents (e.g., incident form completed as a response to each incident)?
111Does your organization have a formal incident response and data breach notification plan and team?
112Is evidence properly collected and maintained during the investigation of a security incident (e.g., employing chain of custody and other computer forensic methodologies that are monitored by internal and/or external parties)?
113Are incidents identified, investigated, and reported according to applicable legal requirements?
114Are incidents escalated and communicated? Describe.
115Do you have a contingency plan in place to handle emergency access to the proposed solution?
116Disaster Recovery Plan & BackupsDoes your organization have a mechanism to back up critical IT systems and County data? Describe.
117Does your organization periodically test your backup/restoration plan by restoring from backup media?
118Does your organization have a disaster recovery plan?
119Are disaster recovery plans updated and tested at least annually?
120Do any single points of failure exist that would disrupt functionality of the proposed product or service?
121Product Security Development LifecycleDoes your organization have any product pre-release security threat modeling in place (e.g., secure coding practice, security architecture review, penetration testing)?
122Does your organization maintain an end-of-life-schedule for the proposed software product or solution?
123Is the product engineered as a multi-tier architecture design?
124Is any proposed product or service within three years of end of life?
125Crypto Materials and Key ManagementDoes your organization have a centralized key management program in place (e.g., any Public Key Infrastructure (PKI), Hardware Security Module (HSM)-based or not, etc.) to issue certificates needed for products and cloud service infrastructure?
126Secure Software Design/TestingIs the software currently certified by any security standards? (e.g., OWASP, NIST). List standards.
127Has the software been developed following secure programming standards like those in the OWASP Developer Guide?
128Does your organization use automated tools for security testing or code reviews to identify security vulnerabilities (e.g., brute force, injection, buffer overflows)?
129Does your organization perform security testing based on industry standards (e.g., OWASP Top 10, SANS Top 25)?
130Does your organization remediate all vulnerabilities identified prior to production deployment?
131Is your organization outsourcing any aspect of the service to a third party?
132Is the product engineered as a multi-tier architecture design?
133Does your organization have capability to respond to and update product for any unforeseen new regulatory requirements?
134Application Development Services -
This section is applicable only if Organization is providing Application Development Services (e.g. on-premise, mobile, web, or other custom code)Does your organization's development and testing teams receive training specific to application security? Describe.
135Does your organization's development team use a development framework? List development languages and framework.
136Does your organization follow secure coding development standards?
137Does your organization have a security methodology for continuous maintenance of the application and applicable components?
138Does your organization review security at each phase of the software development life cycle?
139Does your organization use an industry standard methodology for conducting security testing? Describe.
140Does your organization use automated tools for security testing or code reviews to identify security vulnerabilities (e.g., brute force, injection, buffer overflows)?
141Does your organization perform security testing based on industry standards (e.g., OWASP Top 10, SANS Top 25)?
142Does your organization use an independent third party for periodic security penetration testing?
143Does your organization perform peer code reviews on source code prior to production deployment?
144Does your organization remediate all vulnerabilities identified prior to production deployment?
145Is your organization outsourcing any aspect of the development to a third party?
146Will the County receive a copy of the source code?
147Generative Artificial Intelligence (GenAI) - Refers to artificial intelligence technology that can produce various types of content such as text, images, music, videos, code, etc., based on inputs or prompts to create derived synthetic content beyond analyzing or acting on existing data.Is GenAI used as a component of or in the research, development, or production of this solution or service?
148Is GenAI used in any way to provide ongoing support to this system or solution (e.g., client chatbot for support requests)?
149Does the proposed product or solution use a GenAI model that was developed in house?
150Does the proposed product or solution use a GenAI model that was developed by a third party (e.g., ChatGPT)?
151Does this solution interface with a third-party GenAI product?
152Does this solution interface with any free or open source GenAI components?
153Does your organization have policies and procedures including governance, privacy and security implemented to validate information generated by the GenAI for accuracy?
154Is data labeling used to identify content generated by the GenAI product or solution?
155Are data sources (e.g., social media, news articles, scientific journals) used in the GenAI model verified to ensure content provided is accurate?
156Will County data be used to train or fine tune the GenAI model used in this solution?
157Does your organization have a standard in place to update data used in the GenAI model frequently (e.g., weekly, monthly, quarterly) to ensure data integrity?
158Does your organization have established copyright and authorized use for all data used to develop and operate the GenAI model to prevent copyright violations?
159Is PII information handled or stored by this GenAI solution?
160Will any County data be stored or accessed by the GenAI component?
161Does your organization perform continuous monitoring to detect GenAI model drift (i.e., degradation of model performance due to changes in data, or relationships between input and output variables)?
162Does your organization have security controls implemented to secure the confidentiality of data entered in the GenAI product or solution?
163Will the system continue to function if the GenAI service is not available?
164Does your organization have a procedure implemented to identify, manage, and mitigate GenAI risk?
165Does your organization perform security testing to identify GenAI specific security vulnerabilities (e.g., data poisoning, prompt injection, model exfiltration)?
166Are employees allowed to use GenAI technology from a personal device when conducting company business?
167Has a third party vendor risk assessment been performed on this GenAI solution?
SECTION 2: SOFTWARE INSTALLED IN COUNTY'S NETWORK
No.AreaQuestionVendor Response
YES/NOComments
1REQUIRED RESPONSE: Will your organization provide SOFTWARE INSTALLED LOCALLY IN COUNTY NETWORK?
STOP: If you selected NO for Question 1, PROCEED TO SECTION 3.
2Supporting Documentation
(Upon County's request)Provide the following:

a) Hardware and Software requirements (i.e. Operating System, CPUs, RAM)

3b) Network connectivity requirements
4ResellerWill your organization act as a reseller to provide software to the County? If so, provide manufacturer documentation regarding the security controls of the software and a secure configuration document.
5Software Installation RequirementsCan the application and service accounts used to run the application be configured to run as non-privileged users (e.g., non-Local Administrator rights)?
6Does software require admin rights to be installed? Describe the level of administrative access the software will need on the County domain.
7Is remote access required for installation and support? Describe.
8Can the software be installed on and operated in a virtualized environment?
9Third Party Software RequirementsIs third party software (e.g., Java, Adobe, Log4j) required to be installed or embedded within your software for it to work? Provide software and minimum version.
10Are you using any open source software components (e.g., no paid license) without paid product support? If so, list software components.
11Will the software remain compatible with all updates and new releases of required third party software?
12Secure Software Design/TestingIs the software currently certified by any security standards? (e.g., PCI-DSS). Provide standards.
13Has the software been developed following secure programming standards like those in the OWASP Developer Guide?
14Does your organization use automated tools for security testing or code reviews to identify security vulnerabilities (e.g., brute force, injection, buffer overflows)?
15Does your organization perform security testing based on industry standards (e.g., OWASP Top 10, SANS Top 25)?
16Does your organization remediate all vulnerabilities identified prior to production deployment?
17Is your organization outsourcing any aspect of the service to a third party?
18Is the product engineered as a multi-tier architecture design?
19Does your organization have capability to respond to and update product for any unforeseen new regulatory requirements?
20Audit LoggingDoes software or solution perform audit logging? Describe.
21Does software or solution allow for the configuration of audit log retention for a minimum of 90 days or more?
22Does software have audit reporting capabilities (e.g., user activity, privileged access)? Describe.
23Security Updates/PatchingDoes software have a security patch process? Describe your software security patch process, frequency of security patches and upgrade cycle releases.
24Does your organization support electronic delivery of digitally signed software and upgrades?
25Secure Configuration / Installation
(i.e. PA-DSS configuration)Does software allow for secure configuration and installation (e.g., OS hardening, disabling unnecessary services, antivirus compatibility)?
26Will software or solution process or collect credit card information?
27Confidential DataDoes product or solution process, store or transmit confidential data (e.g., Social Security Number, Date of Birth, Credit Card information)?
28Does software restrict confidential data (e.g., Social Security Number or Date of Birth) from being used as a primary identifier?
29Does software have documentation showing where all confidential data is stored in the application?
30EncryptionDoes software support encryption of data in motion (e.g., SSL)?
31Does software support encryption of data at rest (e.g., column-level encryption, files)? List controls.
32AuthenticationDoes product have Single Sign-on (SSO) and Federated Identity Enablement integration options (e.g., support for standards like SAML v2 and OAuth 2.0, active directory, etc.)? Describe.
33Roles and ResponsibilitiesDoes software provide role-based access control?
34Is a service account required for this software to run?
35If so, does the service account require admin rights?
36Product Security Development LifecycleDoes organization have any product pre-release security threat modeling in place (e.g., secure coding practice, security architecture review, penetration testing, etc.)?
37Does your organization maintain end-of-life-schedule for the software product?
38Is product or service within three years of end of life?
39Regulatory ComplianceIs the software or solution currently certified by any security standards (e.g., PCI-DSS, HIPAA)? Provide proof of compliance documentation.
40Generative Artificial Intelligence (GenAI) - Refers to artificial intelligence technology that can produce various types of content such as text, images, music, videos, code, etc., based on inputs or prompts to create derived synthetic content beyond analyzing or acting on existing dataIs GenAI used as a component of or in the research, development, or production of this solution or service?
41Is GenAI used in any way to provide ongoing support to this system or solution (e.g., client chatbot for support requests)?
42Does the proposed product or solution use a GenAI model that was developed in house?
43Does the proposed product or solution use a GenAI model that was developed by a third party (e.g., ChatGPT)?
44Does this solution interface with a third-party GenAI product?
45Does this solution interface with any free or open source GenAI components?
46Does your organization have policies and procedures including governance, privacy and security implemented to validate information generated by the GenAI for accuracy?
47Is data labeling used to identify content generated by the GenAI product or solution?
48Are data sources (e.g., social media, news articles, scientific journals) used in the GenAI model verified to ensure content provided is accurate?
49Will County data be used to train or fine tune the GenAI model used in this solution?
50Does your organization have a standard in place to update data used in the GenAI model frequently (e.g., weekly, monthly, quarterly) to ensure data integrity?
51Does your organization have established copyright and authorized use for all data used to develop and operate the GenAI model to prevent copyright violations?
52Is PII information handled or stored by this GenAI solution?
53Will any County data be stored or accessed by the GenAI component?
54Does your organization perform continuous monitoring to detect GenAI model drift (i.e., degradation of model performance due to changes in data, or relationships between input and output variables)?
55Does your organization have security controls implemented to secure the confidentiality of data entered in the GenAI product or solution?
56Will the system continue to function if the GenAI service is not available?
57Does your organization have a procedure implemented to identify, manage, and mitigate GenAI risk?
58Does your organization perform security testing to identify GenAI specific security vulnerabilities (e.g., data poisoning, prompt injection, model exfiltration)?
59Are employees allowed to use GenAI technology from a personal device when conducting company business?
60Has a third party vendor risk assessment been performed on this GenAI solution?
SECTION 3: HARDWARE
No.AreaDescriptionVendor Response
YES/NOComments
1REQUIRED RESPONSE: Will your organization provide HARDWARE?
STOP: If you selected NO to Question 1, SKIP THIS SECTION.
2ResellerWill your organization act as a reseller to provide hardware products to the County? If so, provide manufacturer documentation regarding the supply chain security controls around the hardware and a secure configuration document.
3Secure Hardware Design/TestingIs the hardware currently certified by any security standards (e.g., NIST FIPS)?
4Has the software been developed following secure programming standards like those in the OWASP Developer Guide?
5Does your organization use automated tools for security testing or code reviews to identify security vulnerabilities (e.g., brute force, injection, buffer overflows)?
6Does your organization perform security testing based on industry standards (e.g., OWASP Top 10, SANS Top 25)?
7Does your organization remediate all vulnerabilities identified prior to production deployment?
8Is your hardware scanned to detect any vulnerabilities or backdoors within the firmware (i.e, operating system, application code)?
9Is your firmware upgraded to remediate vulnerabilities? Provide frequency.
10If a new vulnerability is identified, is there a documented timeframe for updates/releases? Provide frequency.
11Do you implement security measures during the manufacturing of the hardware? Describe.
12Is your organization outsourcing any aspect of the service to a third party?
13Are there physical security features used to prevent tampering of the hardware? Identify features.
14Security Updates/PatchingDoes the hardware have a security patch process? Describe your hardware security patch process, frequency of security patches and upgrade cycle releases.
15Are there contingencies where key third-party dependencies are concerned?
16Will your organization provide a Software Bill of Materials (SBOM) listing all the open-source and third-party components included in the hardware you will be supplying?
17Identity & Access ManagementAre remote control features embedded for the manufacturer's support or ability to remotely access? Describe.
18Do backdoors exist that can lead to unauthorized access? Describe.
19Do default accounts exist? List all default accounts.
20Can default accounts and passwords be changed by Broward County?
21Can service accounts be configured to run as non-privileged user (i.e., non-Domain Admin)?
22Confidential DataDoes the product or solution collect confidential data (e.g., Social Security Number, Date of Birth, Credit Card information)?
23Roles and ResponsibilitiesIs a service account required for this hardware?
24If so, does the service account require admin rights?
25Product Security Development LifecycleIs an end-of-life schedule maintained for the hardware?
26Is any proposed product or service within three years of end of life?
27Media HandlingDoes your organization have a secure data wipe and data destruction program for proper drive disposal (e.g., Certificate of destruction, electronic media purging)? Describe.
28Regulatory ComplianceIs the hardware currently certified by any security standards? (e.g., PCI-DSS, HIPAA). Provide proof of compliance documentation.
29Will the product or solution process or collect credit card information?
30Does your organization have a process to identify new laws and regulations with IT security implications?
31Generative Artificial Intelligence (GenAI) - Refers to artificial intelligence technology that can produce various types of content such as text, images, music, videos, code, etc., based on inputs or prompts to create derived synthetic content beyond analyzing or acting on existing data.Is GenAI used as a component of or in the research, development, or production of this solution or service?
32Is GenAI used in any way to provide ongoing support to this system or solution (e.g., client chatbot for support requests)?
33Does the proposed product or solution use a GenAI model that was developed in house?
34Does the proposed product or solution use a GenAI model that was developed by a third party (e.g., ChatGPT)?
35Does this solution interface with a third-party GenAI product?
36Does this solution interface with any free or open source GenAI components?
37Does your organization have policies and procedures including governance, privacy and security implemented to validate information generated by the GenAI for accuracy?
38Is data labeling used to identify content generated by the GenAI product or solution?
39Are data sources (e.g., social media, news articles, scientific journals) used in the GenAI model identified to ensure content provided is verifiable?
40Will County data be used to train or fine tune the GenAI model used in this solution?
41Does your organization have a standard in place to update data used in the GenAI model frequently (e.g., weekly, monthly, quarterly) to ensure data integrity?
42Does your organization have established copyright and authorized use for all data used to develop and operate the GenAI model to prevent copyright violations?
43Is PII information handled or stored by this GenAI solution?
44Will any County data be stored or accessed by the GenAI component?
45Does your organization perform continuous monitoring to detect GenAI model drift (i.e., degradation of model performance due to changes in data, or relationships between input and output variables)?
46Does your organization have security controls implemented to secure the confidentiality of data entered in the GenAI product or solution?
47Will the system continue to function if the GenAI service is not available?
48Does your organization have a procedure implemented to identify, manage, and mitigate GenAI risk?
49Does your organization perform security testing to identify GenAI specific security vulnerabilities (e.g., data poisoning, prompt injection, model exfiltration)?
50Are employees allowed to use GenAI technology from a personal device when conducting company business?
51Has a third party vendor risk assessment been performed on this GenAI solution?

Page &P of &N Last Updated: 04/29/2025 image1.png image2.png

File details come from the government source that posted it. Updated .