14-Vendor Security Questionnaire.xlsx
XLSX spreadsheet 116 KB Posted
- Attached to
- Lost and Found Management Software State and local contract opportunity
- Solicitation number
- TCH2132330B1
- Issued by
- Broward County, Florida
About this file
This is an Enterprise Technology Services Vendor Security Questionnaire (VSQ) document issued by Broward County, Florida for evaluating vendor security practices in connection with a Lost and Found Management Software procurement. The questionnaire applies to vendors providing Software-as-a-Service (SaaS), hosting services, application development services, managed professional services, software installed locally on the County's network, or hardware. The document contains 167 questions organized into three main sections covering SaaS/hosting/application development services, locally-installed software, and hardware, with subsections addressing audit reporting, payment card industry compliance, HIPAA requirements, roles and responsibilities, federated identity management, third-party access, information security policies, risk assessment, regulatory compliance, employee training, background checks, employment terms, physical security, access controls, data security, audit logging, vulnerability assessment, security monitoring, identity and access management, antivirus protection, network defense, media handling, secure disposal, separation of duties, change management, incident management, disaster recovery, product security development lifecycle, cryptographic key management, secure software design and testing, and generative artificial intelligence considerations.
Vendors are required to complete the VSQ with dropdown responses of YES, NO, or N/A for each question, with a Comments section to provide supporting explanations and attach additional documentation as needed. If not provided with initial submittal, vendors must submit the completed questionnaire within three business days of the County's written request. The County will review all VSQ responses, disclose identified security concerns to the Evaluation Committee, and consider any unresolved security concerns as part of final evaluation, which may affect the vendor's overall score. Vendors must attest that all statements made in support of their responses are accurate and true; inaccurate, untruthful, or incorrect statements may result in rejection, contract award rescission, contract termination, or vendor debarment pursuant to Broward County's Procurement Code. The questionnaire was last updated on April 29, 2025.
View the file
Other files for this state and local contract opportunity
Show all 17
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Sheet1
| Enterprise Technology Services |
| Vendor Security Questionnaire (VSQ) |
| ETS Vendor Security Questionnaire (VSQ): Vendor is required to submit a completed ETS Vendor Security Questionnaire (VSQ) (for applicable solution – services, hardware, and/or software). If a response requires additional information, attach additional pages with the required additional information with the additional pages and information labeled to match the applicable question number. If not provided with the submittal, the Vendor must submit within three business days after the County's written request. |
The Vendor Security Questionnaire (VSQ) assesses the Vendor’s security policies and/or system protocol and to identify any potential security vulnerabilities. The County will review the Vendor’s VSQ response; any identified security concerns will be disclosed to the Evaluation Committee. Unresolved security concerns shall be considered by the Evaluation Committee as part of its final evaluation and may affect the Vendor’s evaluation.
As the Vendor's authorized representative, I attest that any and all statements, oral, written or otherwise, made in support of the Vendor's response, are accurate, true and correct. I also acknowledge that inaccurate, untruthful, or incorrect statements made in support of the Vendor's response may be used by the County as a basis for rejection, rescission of the award, or termination of the contract and may also serve as the basis for debarment of Vendor pursuant to PART XI of the Broward County Procurement Code.
| Vendor Name: |
| Vendor Type (Manufacturer, Reseller, Other? If Other, specify.): |
| Vendor Contact Person's Name / Title / |
Email Address:
| Product Name / Description: |
| Solicitation Number and Title |
(If applicable):
For each applicable section, complete the matrix by using the dropdown option to select YES or NO. Use "Comments" section to provide as much explanation as possible to clearly support your response. Additional pages may be attached to provide further detail, but any attachments should be referenced in "Comments" section. Select "N/A" if a question within a given section is not applicable.
SECTION 1: SOFTWARE-AS-A-SERVICE (SaaS) / HOSTING / APPLICATION DEVELOPMENT SERVICES /
MANAGED OR PROFESSIONAL SERVICES
| No. | Area | Question | Vendor Response | |
| YES/NO | Comments | |||
| 1 | REQUIRED RESPONSE: Will your organization provide SOFTWARE-AS-A-SERVICE (SaaS)? (e.g. Software-as-a-service/SaaS, application, website) | |||
| 2 | REQUIRED RESPONSE: Will your organization provide HOSTING SERVICES? | |||
| 3 | REQUIRED RESPONSE: Will your organization provide APPLICATION DEVELOPMENT SERVICES? (e.g. on-premise, mobile, web, or other custom code) | |||
| 4 | REQUIRED RESPONSE: Will your organization provide MANAGED OR PROFESSIONAL SERVICES (UNSUPERVISED BY COUNTY PERSONNEL)? |
(Note: "Managed or Professional Services" used herein refers to unsupervised (by County personnel) installation, configuration, consulting, maintenance or monitoring of County systems, applications or infrastructure related to your organization's proposed solution.)
| STOP: If you selected NO for Questions 1 through 4 above, PROCEED TO SECTION 2. | ||
| 5 | Supporting Documentation | |
| (Upon County's request) | Provide the following: |
a) Workflow diagram of stored or transmitted information (for SaaS and Hosting Services only)
| 6 | b) Security / Network Architecture diagram (for SaaS and Hosting Services only) | |
| 7 | c) Secure Coding standard (for Application Development Services only) | |
| 8 | d) Application Security Program standard (for Application Development Services only) | |
| 9 | Audit Reporting Requirements | Does your organization have a current System and Organization Controls (SOC) 2, Type II report, inclusive of all five Trust Service Principles (Security, Availability, Processing Integrity, Confidentiality, and Privacy)? |
(Note: For any SaaS or hosted application, the SOC report should be for the organization or application specifically, not the datacenter only.)
| 10 | Payment Card Industry (PCI) environments - Applicable only if Organization or its proposed subcontractor processes or collects credit card information. | Does your organization have a current Payment Card Industry (PCI) certification (e.g., Attestation of Compliance (AOC), Self-Assessment Questionnaire (SAQ))? | |||
| 11 | Will the product or solution process or collect credit card information? | ||||
| 12 | Does your organization maintain a file integrity monitoring program to ensure critical file system changes are monitored and approved with respect to confidential County data? | ||||
| 13 | Electronic Protected Health Information (ePHI) - | ||||
| Applicable only if Organization has access to or will be hosting or storing County ePHI. | Has your organization had a Risk Assessment performed in the past five years by an external auditor in conjunction with the HIPAA Security rule? | ||||
| 14 | Does your organization maintain current HIPAA specific policies and procedures in conjunction with the HIPAA Security Rule? | ||||
| 15 | Does your organization have a designated HIPAA Security and Privacy Officer(s)? | ||||
| 16 | Does your organization provide HIPAA Security training to your employees at time of hire and at least annually thereafter? | ||||
| 17 | Roles & Responsibilities | Has your organization appointed a central point of contact for security coordination? | |||
| 18 | Does your organization have an expected timeframe to respond to initial contact for security related issues? Provide timeframe. | ||||
| 19 | Does your organization define the priority level of an issue (e.g., minor vs. major, 0-4 scale, etc.)? Describe. | ||||
| 20 | Does your organization have an expected Service Level Agreement (SLA) to implement changes needed to fix security issues according to priority level? Describe. | ||||
| 21 | Federated Identity Management and Web Services Integration | Does your organization's product have Single Sign-on (SSO) and Federated Identity Enablement integration options (e.g., support for standards like SAML v2 and OAuth 2.0, active directory)? Describe. | |||
| 22 | Does your organization use web services and/or data import/export functions (e.g., API, FTP)? Describe. | ||||
| 23 | External Parties | Will third parties, such as IT service providers have access to the County's data that is stored or transmitted by your organization? | |||
| 24 | Does your organization have a Disaster Recovery and Continuity of Operations plan that includes third-party dependencies to ensure critical business functions can continue even during a major disruption? | ||||
| 25 | Does your organization outsource any aspect of the service to a third party? | ||||
| 26 | Does your organization utilize any off-shore resources for development? Provide location(s). | ||||
| 27 | Does your organization build the application in-house? | ||||
| 28 | Does your organization share customer data with or enable direct access by any third-party? | ||||
| 29 | Will any proposed subcontractors process, access, transmit or store any County data? | ||||
| 30 | Do all proposed subcontractors contractually comply with your organization's security standards for data processing? | ||||
| 31 | Does your organization regularly audit your critical vendors? Describe. | ||||
| 32 | Information Security Policy & Procedures | Does your organization have documented standard policies and procedures for security and compliance? | |||
| 33 | Risk Assessment | Does your organization have a process that addresses: (a) the identification and measurement of potential risks with mitigating controls (measures taken to reduce risk), and (b) the acceptance or transfer (e.g. insurance policies, warranties, etc.) of the remaining (residual) risk after mitigation steps have been applied? | |||
| 34 | Regulatory Compliance | Is the product or solution currently certified by any security standards? (e.g., PCI-DSS, HIPAA). Provide proof of compliance documentation. | |||
| 35 | Does your organization have a documented process to identify new laws and regulations with IT security implications (e.g., FIPA, new state breach notification requirements, monitoring newsletters, webinars, security or regulatory forums, etc.)? | ||||
| 36 | Has your organization experienced a data breach within the past five years that legally required reporting under applicable law? | ||||
| 37 | Does your organization have procedures for preservation of electronic records and audit logs in case of litigation hold? | ||||
| 38 | During Employment – Training, Education & Awareness | Have employees and proposed subcontractors received formal information security awareness training? Provide frequency. | |||
| 39 | Have your organization's security policies and procedures been communicated to your employees? | ||||
| 40 | Are periodic security reminders provided to your organization's employees? | ||||
| 41 | Background Checks | Does your organization perform background checks (e.g., credential verification, criminal history, credit history) to examine and assess an employee’s or proposed subcontractor's work and criminal history? | |||
| 42 | Are individuals who would have access to the County's data subjected to periodic follow-up background checks? | ||||
| 43 | Prior to Employment - Terms and Conditions of Employment | Are employees and proposed subcontractors required to sign a non-disclosure agreement and/or confidentiality form upon initial employment? | |||
| 44 | If so, are employees and proposed subcontractors required to sign the non-disclosure agreement annually? | ||||
| 45 | Termination or Change in Employment | Does your organization require that all equipment of any terminated employee or subcontractor is returned and that their user ID is disabled in all systems and badges and/or keys are returned? | |||
| 46 | Upon transfer, is existing access reviewed for relevance for employees and subcontractors? | ||||
| 47 | Secure Areas | Does your organization have effective physical access controls (e.g., door locks, badge /electronic key ID and access controls) in place that prevent unauthorized access to facilities and a facility security plan? | |||
| 48 | Is a locked screensaver displayed on unattended workstations? | ||||
| 49 | Do personnel abide by a clean desk policy to remove and secure sensitive/confidential information from their workspace at the end of the work day? | ||||
| 50 | Does your organization have a contingency plan in place to handle emergency access to facilities? | ||||
| 51 | Are physical access controls authorized? Describe who is responsible for managing and ensuring that only appropriate persons have keys or codes to the facility and to locations within the facility with secure data. | ||||
| 52 | Are there policies and procedures to document repairs and modifications to physical components of the facility that are related to security? | ||||
| 53 | Are employees or subcontractors permitted access to customer environments from your physical locations only? | ||||
| 54 | Application and Information Access Control - Confidential System Isolation | Are systems and networks that host, process, and/or transfer confidential information "protected" (i.e., isolated, logically or physically separated) from other systems and/or networks? | |||
| 55 | Are internal and external networks separated by firewalls with access policies and rules? | ||||
| 56 | Data Security | Are development and test environments separate from production environments to protect production applications from inadvertent changes or disruption? | |||
| 57 | Does your organization apply database and application logical segregation of customer data? | ||||
| 58 | Is this a multi-tenant solution? | ||||
| 59 | Will County’s data be co-mingled with data of any other customer? | ||||
| 60 | Does your organization provide a means to encrypt data at rest (e.g., AES)? | ||||
| 61 | Will County’s data be processed, accessed, transmitted or stored through an off shore environment (e.g., outside continental U.S, Alaska, Hawaii)? | ||||
| 62 | Does your organization provide a means to encrypt County confidential information in transit? Describe controls that are in place to protect confidential information when transferred (e.g., encryption). | ||||
| 63 | Is there a standard approach for protecting network devices to prevent unauthorized access/network related attacks and data-theft (e.g., firewall between public and private networks, internal VLAN, firewall separation, separate WLAN network, secure portal, multi-tenancy, virtualization, shared storage, etc.)? | ||||
| 64 | Does your organization use email encryption to protect sensitive/confidential information when communicating with third parties (e.g., IT vendors)? | ||||
| 65 | Are employees permitted to work remotely from a facility not owned or leased by the organization? | ||||
| 66 | Are encrypted communications required for all remote connections? | ||||
| 67 | Does your organization use a secure VPN connection with third parties (e.g., IT vendors)? | ||||
| 68 | Does your organization have protections in place for ensuring secure remote access (e.g., up-to-date antivirus, posture assessment, VPN enforcement, split tunneling)? | ||||
| 69 | Is there a formal (documented, approved, published, communicated, and implemented) remote access policy? | ||||
| 70 | Can your organization restrict access to the solution to and from the County's network in a "deny all, permit by exception" configuration (i.e., whitelist County IP addresses only)? | ||||
| 71 | Audit Logging | Does the software or solution perform audit logging? Describe. | |||
| 72 | Does the software or solution allow for the configuration of audit log retention for a minimum of 90 days or more? | ||||
| 73 | Does the software track events for user activity (e.g., failed/successful logins, privileged access)? Describe. | ||||
| 74 | Vulnerability Assessment and Remediation | Does your organization perform periodic vulnerability scans on your IT systems, networks, and supporting security systems? Provide frequency. | |||
| 75 | Are internal or proposed subcontractors vulnerability assessments automated? | ||||
| 76 | Does your organization have a security patch management cycle in place to address identified vulnerabilities? | ||||
| 77 | Does your organization provide disclosure of vulnerabilities found in your environment and remediation timelines? | ||||
| 78 | Does your organization notify customer of applicable patches? | ||||
| 79 | Security Monitoring | Are third party connections to your network monitored and reviewed to confirm only authorized access and appropriate usage (e.g., with VPN logs, server event logs, system, application and data access logging, automated alerts, regular/periodic review of logs or reports)? | |||
| 80 | Does your organization monitor your systems and networks for security events? Describe monitoring (e.g., server and networking equipment logs such as servers, routers, switches, wireless APs, monitored regularly). | ||||
| 81 | Does your organization periodically review system activity? Provide frequency. | ||||
| 82 | Identity & Access Management | Does your organization have a formal access authorization process based on "least privilege" (i.e. employees are granted the least amount of access possible to perform their assigned duties) and "need to know" (e.g., access permissions granted based upon the legitimate business need of the user to access the information, role-based permissions, limited access based on specific responsibilities, network access request form)? | |||
| 83 | Are systems and applications configured to restrict access only to authorized individuals (e.g., use of unique IDs and passwords, minimum password length, password complexity, log-in history, lockout, password change, expiration)? | ||||
| 84 | Is there a list maintained of authorized users with general access and administrative access (e.g., active directory user lists within a confidential application, a spreadsheet of users, a human resources file)? | ||||
| 85 | Does your organization maintain a list of "accepted mobile devices" (e.g., smart phones, cell phones) and are these devices tracked and managed (e.g., Mobile Device Management)? | ||||
| 86 | Is a Data Loss Prevention (DLP) in place to prevent the unauthorized distribution of confidential information? | ||||
| 87 | Is software installation for desktops, laptops, and servers restricted to administrative users only? | ||||
| 88 | Does software or system have automatic logoff for session inactivity? | ||||
| 89 | Does your organization control and monitor access to application source code in a secure manner? | ||||
| 90 | Does your organization deny developers access to production environments, as well as to any environments containing customer data? | ||||
| 91 | Are user IDs for your system uniquely identifiable? | ||||
| 92 | Does your organization have any shared accounts? Describe. | ||||
| 93 | Will your organization allow remote access from proposed subcontractors to the County network, with immediate deactivation after use? | ||||
| 94 | Can service accounts be configured to run as non-privileged user (i.e., non-Domain Admin)? | ||||
| 95 | Is Multi-Factor Authentication (MFA) required for employees/contractors for remote access to production systems? | ||||
| 96 | Is Multi-Factor Authentication (MFA) included as a feature in the proposed system? | ||||
| 97 | Entitlement Reviews | Does your organization have a process to review user accounts and related access (e.g., manual process of reviewing system accounts to user accounts in AD for both users and privileged access, such as admins, developers, etc.)? | |||
| 98 | Antivirus | Is antivirus software installed and running on your computers and supporting systems (e.g., desktops, servers, gateways, etc.)? | |||
| 99 | Is this antivirus product centrally managed (e.g., monitored to verify all endpoints have functional agents, agents are up to date with the latest signatures, etc.)? Explain your policies and procedures for management of antivirus software. | ||||
| 100 | Does your organization have a process for detecting and reporting malicious software? | ||||
| 101 | Network Defense and Host Intrusion Prevention Systems | Does your organization have any Intrusion Protection System (IPS) in place for your environment? | |||
| 102 | Are employees prevented from using personally owned smart phones or mobile devices to connect to the organization's network? | ||||
| 103 | Media Handling | Does your organization have procedures to protect documents and computer media (e.g., tapes, disks, hard drives, etc.) from unauthorized disclosure, modification, removal, and destruction? | |||
| 104 | Is confidential data encrypted when stored on laptop, desktop, server hard drive, flash drive, backup tape (i.e., data at rest)? | ||||
| 105 | Are backup archives stored externally / offsite from your facility? | ||||
| 106 | Secure Disposal | Are there security procedures (e.g., use of secure wiping, NIST 800-88, etc.) for the decommissioning (replacement) of IT equipment and IT storage devices that contain or process confidential information? | |||
| 107 | Separation of Duties | Are duties separated (e.g., front desk duties separated from accounting, data analysts access separated from IT support), where appropriate, to reduce the opportunity for unauthorized modification, unintentional modification, or misuse of your IT assets? | |||
| 108 | Change Management | Do formal testing and change management procedures exist for networks, systems, desktops, software releases, deployments, and software vulnerability during patching activities, changes to the system, changes to the workstations and servers with appropriate testing, notification, and approval, etc.? | |||
| 109 | Incident Management | In the event of a major security incident or data breach, do you provide the County a third-party digital forensics/incident report? | |||
| 110 | Does your organization identify, respond to, and mitigate suspected or known security incidents (e.g., incident form completed as a response to each incident)? | ||||
| 111 | Does your organization have a formal incident response and data breach notification plan and team? | ||||
| 112 | Is evidence properly collected and maintained during the investigation of a security incident (e.g., employing chain of custody and other computer forensic methodologies that are monitored by internal and/or external parties)? | ||||
| 113 | Are incidents identified, investigated, and reported according to applicable legal requirements? | ||||
| 114 | Are incidents escalated and communicated? Describe. | ||||
| 115 | Do you have a contingency plan in place to handle emergency access to the proposed solution? | ||||
| 116 | Disaster Recovery Plan & Backups | Does your organization have a mechanism to back up critical IT systems and County data? Describe. | |||
| 117 | Does your organization periodically test your backup/restoration plan by restoring from backup media? | ||||
| 118 | Does your organization have a disaster recovery plan? | ||||
| 119 | Are disaster recovery plans updated and tested at least annually? | ||||
| 120 | Do any single points of failure exist that would disrupt functionality of the proposed product or service? | ||||
| 121 | Product Security Development Lifecycle | Does your organization have any product pre-release security threat modeling in place (e.g., secure coding practice, security architecture review, penetration testing)? | |||
| 122 | Does your organization maintain an end-of-life-schedule for the proposed software product or solution? | ||||
| 123 | Is the product engineered as a multi-tier architecture design? | ||||
| 124 | Is any proposed product or service within three years of end of life? | ||||
| 125 | Crypto Materials and Key Management | Does your organization have a centralized key management program in place (e.g., any Public Key Infrastructure (PKI), Hardware Security Module (HSM)-based or not, etc.) to issue certificates needed for products and cloud service infrastructure? | |||
| 126 | Secure Software Design/Testing | Is the software currently certified by any security standards? (e.g., OWASP, NIST). List standards. | |||
| 127 | Has the software been developed following secure programming standards like those in the OWASP Developer Guide? | ||||
| 128 | Does your organization use automated tools for security testing or code reviews to identify security vulnerabilities (e.g., brute force, injection, buffer overflows)? | ||||
| 129 | Does your organization perform security testing based on industry standards (e.g., OWASP Top 10, SANS Top 25)? | ||||
| 130 | Does your organization remediate all vulnerabilities identified prior to production deployment? | ||||
| 131 | Is your organization outsourcing any aspect of the service to a third party? | ||||
| 132 | Is the product engineered as a multi-tier architecture design? | ||||
| 133 | Does your organization have capability to respond to and update product for any unforeseen new regulatory requirements? | ||||
| 134 | Application Development Services - | ||||
| This section is applicable only if Organization is providing Application Development Services (e.g. on-premise, mobile, web, or other custom code) | Does your organization's development and testing teams receive training specific to application security? Describe. | ||||
| 135 | Does your organization's development team use a development framework? List development languages and framework. | ||||
| 136 | Does your organization follow secure coding development standards? | ||||
| 137 | Does your organization have a security methodology for continuous maintenance of the application and applicable components? | ||||
| 138 | Does your organization review security at each phase of the software development life cycle? | ||||
| 139 | Does your organization use an industry standard methodology for conducting security testing? Describe. | ||||
| 140 | Does your organization use automated tools for security testing or code reviews to identify security vulnerabilities (e.g., brute force, injection, buffer overflows)? | ||||
| 141 | Does your organization perform security testing based on industry standards (e.g., OWASP Top 10, SANS Top 25)? | ||||
| 142 | Does your organization use an independent third party for periodic security penetration testing? | ||||
| 143 | Does your organization perform peer code reviews on source code prior to production deployment? | ||||
| 144 | Does your organization remediate all vulnerabilities identified prior to production deployment? | ||||
| 145 | Is your organization outsourcing any aspect of the development to a third party? | ||||
| 146 | Will the County receive a copy of the source code? | ||||
| 147 | Generative Artificial Intelligence (GenAI) - Refers to artificial intelligence technology that can produce various types of content such as text, images, music, videos, code, etc., based on inputs or prompts to create derived synthetic content beyond analyzing or acting on existing data. | Is GenAI used as a component of or in the research, development, or production of this solution or service? | |||
| 148 | Is GenAI used in any way to provide ongoing support to this system or solution (e.g., client chatbot for support requests)? | ||||
| 149 | Does the proposed product or solution use a GenAI model that was developed in house? | ||||
| 150 | Does the proposed product or solution use a GenAI model that was developed by a third party (e.g., ChatGPT)? | ||||
| 151 | Does this solution interface with a third-party GenAI product? | ||||
| 152 | Does this solution interface with any free or open source GenAI components? | ||||
| 153 | Does your organization have policies and procedures including governance, privacy and security implemented to validate information generated by the GenAI for accuracy? | ||||
| 154 | Is data labeling used to identify content generated by the GenAI product or solution? | ||||
| 155 | Are data sources (e.g., social media, news articles, scientific journals) used in the GenAI model verified to ensure content provided is accurate? | ||||
| 156 | Will County data be used to train or fine tune the GenAI model used in this solution? | ||||
| 157 | Does your organization have a standard in place to update data used in the GenAI model frequently (e.g., weekly, monthly, quarterly) to ensure data integrity? | ||||
| 158 | Does your organization have established copyright and authorized use for all data used to develop and operate the GenAI model to prevent copyright violations? | ||||
| 159 | Is PII information handled or stored by this GenAI solution? | ||||
| 160 | Will any County data be stored or accessed by the GenAI component? | ||||
| 161 | Does your organization perform continuous monitoring to detect GenAI model drift (i.e., degradation of model performance due to changes in data, or relationships between input and output variables)? | ||||
| 162 | Does your organization have security controls implemented to secure the confidentiality of data entered in the GenAI product or solution? | ||||
| 163 | Will the system continue to function if the GenAI service is not available? | ||||
| 164 | Does your organization have a procedure implemented to identify, manage, and mitigate GenAI risk? | ||||
| 165 | Does your organization perform security testing to identify GenAI specific security vulnerabilities (e.g., data poisoning, prompt injection, model exfiltration)? | ||||
| 166 | Are employees allowed to use GenAI technology from a personal device when conducting company business? | ||||
| 167 | Has a third party vendor risk assessment been performed on this GenAI solution? | ||||
| SECTION 2: SOFTWARE INSTALLED IN COUNTY'S NETWORK | |||||
| No. | Area | Question | Vendor Response | ||
| YES/NO | Comments | ||||
| 1 | REQUIRED RESPONSE: Will your organization provide SOFTWARE INSTALLED LOCALLY IN COUNTY NETWORK? | ||||
| STOP: If you selected NO for Question 1, PROCEED TO SECTION 3. | |||||
| 2 | Supporting Documentation | ||||
| (Upon County's request) | Provide the following: |
a) Hardware and Software requirements (i.e. Operating System, CPUs, RAM)
| 3 | b) Network connectivity requirements | ||||
| 4 | Reseller | Will your organization act as a reseller to provide software to the County? If so, provide manufacturer documentation regarding the security controls of the software and a secure configuration document. | |||
| 5 | Software Installation Requirements | Can the application and service accounts used to run the application be configured to run as non-privileged users (e.g., non-Local Administrator rights)? | |||
| 6 | Does software require admin rights to be installed? Describe the level of administrative access the software will need on the County domain. | ||||
| 7 | Is remote access required for installation and support? Describe. | ||||
| 8 | Can the software be installed on and operated in a virtualized environment? | ||||
| 9 | Third Party Software Requirements | Is third party software (e.g., Java, Adobe, Log4j) required to be installed or embedded within your software for it to work? Provide software and minimum version. | |||
| 10 | Are you using any open source software components (e.g., no paid license) without paid product support? If so, list software components. | ||||
| 11 | Will the software remain compatible with all updates and new releases of required third party software? | ||||
| 12 | Secure Software Design/Testing | Is the software currently certified by any security standards? (e.g., PCI-DSS). Provide standards. | |||
| 13 | Has the software been developed following secure programming standards like those in the OWASP Developer Guide? | ||||
| 14 | Does your organization use automated tools for security testing or code reviews to identify security vulnerabilities (e.g., brute force, injection, buffer overflows)? | ||||
| 15 | Does your organization perform security testing based on industry standards (e.g., OWASP Top 10, SANS Top 25)? | ||||
| 16 | Does your organization remediate all vulnerabilities identified prior to production deployment? | ||||
| 17 | Is your organization outsourcing any aspect of the service to a third party? | ||||
| 18 | Is the product engineered as a multi-tier architecture design? | ||||
| 19 | Does your organization have capability to respond to and update product for any unforeseen new regulatory requirements? | ||||
| 20 | Audit Logging | Does software or solution perform audit logging? Describe. | |||
| 21 | Does software or solution allow for the configuration of audit log retention for a minimum of 90 days or more? | ||||
| 22 | Does software have audit reporting capabilities (e.g., user activity, privileged access)? Describe. | ||||
| 23 | Security Updates/Patching | Does software have a security patch process? Describe your software security patch process, frequency of security patches and upgrade cycle releases. | |||
| 24 | Does your organization support electronic delivery of digitally signed software and upgrades? | ||||
| 25 | Secure Configuration / Installation | ||||
| (i.e. PA-DSS configuration) | Does software allow for secure configuration and installation (e.g., OS hardening, disabling unnecessary services, antivirus compatibility)? | ||||
| 26 | Will software or solution process or collect credit card information? | ||||
| 27 | Confidential Data | Does product or solution process, store or transmit confidential data (e.g., Social Security Number, Date of Birth, Credit Card information)? | |||
| 28 | Does software restrict confidential data (e.g., Social Security Number or Date of Birth) from being used as a primary identifier? | ||||
| 29 | Does software have documentation showing where all confidential data is stored in the application? | ||||
| 30 | Encryption | Does software support encryption of data in motion (e.g., SSL)? | |||
| 31 | Does software support encryption of data at rest (e.g., column-level encryption, files)? List controls. | ||||
| 32 | Authentication | Does product have Single Sign-on (SSO) and Federated Identity Enablement integration options (e.g., support for standards like SAML v2 and OAuth 2.0, active directory, etc.)? Describe. | |||
| 33 | Roles and Responsibilities | Does software provide role-based access control? | |||
| 34 | Is a service account required for this software to run? | ||||
| 35 | If so, does the service account require admin rights? | ||||
| 36 | Product Security Development Lifecycle | Does organization have any product pre-release security threat modeling in place (e.g., secure coding practice, security architecture review, penetration testing, etc.)? | |||
| 37 | Does your organization maintain end-of-life-schedule for the software product? | ||||
| 38 | Is product or service within three years of end of life? | ||||
| 39 | Regulatory Compliance | Is the software or solution currently certified by any security standards (e.g., PCI-DSS, HIPAA)? Provide proof of compliance documentation. | |||
| 40 | Generative Artificial Intelligence (GenAI) - Refers to artificial intelligence technology that can produce various types of content such as text, images, music, videos, code, etc., based on inputs or prompts to create derived synthetic content beyond analyzing or acting on existing data | Is GenAI used as a component of or in the research, development, or production of this solution or service? | |||
| 41 | Is GenAI used in any way to provide ongoing support to this system or solution (e.g., client chatbot for support requests)? | ||||
| 42 | Does the proposed product or solution use a GenAI model that was developed in house? | ||||
| 43 | Does the proposed product or solution use a GenAI model that was developed by a third party (e.g., ChatGPT)? | ||||
| 44 | Does this solution interface with a third-party GenAI product? | ||||
| 45 | Does this solution interface with any free or open source GenAI components? | ||||
| 46 | Does your organization have policies and procedures including governance, privacy and security implemented to validate information generated by the GenAI for accuracy? | ||||
| 47 | Is data labeling used to identify content generated by the GenAI product or solution? | ||||
| 48 | Are data sources (e.g., social media, news articles, scientific journals) used in the GenAI model verified to ensure content provided is accurate? | ||||
| 49 | Will County data be used to train or fine tune the GenAI model used in this solution? | ||||
| 50 | Does your organization have a standard in place to update data used in the GenAI model frequently (e.g., weekly, monthly, quarterly) to ensure data integrity? | ||||
| 51 | Does your organization have established copyright and authorized use for all data used to develop and operate the GenAI model to prevent copyright violations? | ||||
| 52 | Is PII information handled or stored by this GenAI solution? | ||||
| 53 | Will any County data be stored or accessed by the GenAI component? | ||||
| 54 | Does your organization perform continuous monitoring to detect GenAI model drift (i.e., degradation of model performance due to changes in data, or relationships between input and output variables)? | ||||
| 55 | Does your organization have security controls implemented to secure the confidentiality of data entered in the GenAI product or solution? | ||||
| 56 | Will the system continue to function if the GenAI service is not available? | ||||
| 57 | Does your organization have a procedure implemented to identify, manage, and mitigate GenAI risk? | ||||
| 58 | Does your organization perform security testing to identify GenAI specific security vulnerabilities (e.g., data poisoning, prompt injection, model exfiltration)? | ||||
| 59 | Are employees allowed to use GenAI technology from a personal device when conducting company business? | ||||
| 60 | Has a third party vendor risk assessment been performed on this GenAI solution? | ||||
| SECTION 3: HARDWARE | |||||
| No. | Area | Description | Vendor Response | ||
| YES/NO | Comments | ||||
| 1 | REQUIRED RESPONSE: Will your organization provide HARDWARE? | ||||
| STOP: If you selected NO to Question 1, SKIP THIS SECTION. | |||||
| 2 | Reseller | Will your organization act as a reseller to provide hardware products to the County? If so, provide manufacturer documentation regarding the supply chain security controls around the hardware and a secure configuration document. | |||
| 3 | Secure Hardware Design/Testing | Is the hardware currently certified by any security standards (e.g., NIST FIPS)? | |||
| 4 | Has the software been developed following secure programming standards like those in the OWASP Developer Guide? | ||||
| 5 | Does your organization use automated tools for security testing or code reviews to identify security vulnerabilities (e.g., brute force, injection, buffer overflows)? | ||||
| 6 | Does your organization perform security testing based on industry standards (e.g., OWASP Top 10, SANS Top 25)? | ||||
| 7 | Does your organization remediate all vulnerabilities identified prior to production deployment? | ||||
| 8 | Is your hardware scanned to detect any vulnerabilities or backdoors within the firmware (i.e, operating system, application code)? | ||||
| 9 | Is your firmware upgraded to remediate vulnerabilities? Provide frequency. | ||||
| 10 | If a new vulnerability is identified, is there a documented timeframe for updates/releases? Provide frequency. | ||||
| 11 | Do you implement security measures during the manufacturing of the hardware? Describe. | ||||
| 12 | Is your organization outsourcing any aspect of the service to a third party? | ||||
| 13 | Are there physical security features used to prevent tampering of the hardware? Identify features. | ||||
| 14 | Security Updates/Patching | Does the hardware have a security patch process? Describe your hardware security patch process, frequency of security patches and upgrade cycle releases. | |||
| 15 | Are there contingencies where key third-party dependencies are concerned? | ||||
| 16 | Will your organization provide a Software Bill of Materials (SBOM) listing all the open-source and third-party components included in the hardware you will be supplying? | ||||
| 17 | Identity & Access Management | Are remote control features embedded for the manufacturer's support or ability to remotely access? Describe. | |||
| 18 | Do backdoors exist that can lead to unauthorized access? Describe. | ||||
| 19 | Do default accounts exist? List all default accounts. | ||||
| 20 | Can default accounts and passwords be changed by Broward County? | ||||
| 21 | Can service accounts be configured to run as non-privileged user (i.e., non-Domain Admin)? | ||||
| 22 | Confidential Data | Does the product or solution collect confidential data (e.g., Social Security Number, Date of Birth, Credit Card information)? | |||
| 23 | Roles and Responsibilities | Is a service account required for this hardware? | |||
| 24 | If so, does the service account require admin rights? | ||||
| 25 | Product Security Development Lifecycle | Is an end-of-life schedule maintained for the hardware? | |||
| 26 | Is any proposed product or service within three years of end of life? | ||||
| 27 | Media Handling | Does your organization have a secure data wipe and data destruction program for proper drive disposal (e.g., Certificate of destruction, electronic media purging)? Describe. | |||
| 28 | Regulatory Compliance | Is the hardware currently certified by any security standards? (e.g., PCI-DSS, HIPAA). Provide proof of compliance documentation. | |||
| 29 | Will the product or solution process or collect credit card information? | ||||
| 30 | Does your organization have a process to identify new laws and regulations with IT security implications? | ||||
| 31 | Generative Artificial Intelligence (GenAI) - Refers to artificial intelligence technology that can produce various types of content such as text, images, music, videos, code, etc., based on inputs or prompts to create derived synthetic content beyond analyzing or acting on existing data. | Is GenAI used as a component of or in the research, development, or production of this solution or service? | |||
| 32 | Is GenAI used in any way to provide ongoing support to this system or solution (e.g., client chatbot for support requests)? | ||||
| 33 | Does the proposed product or solution use a GenAI model that was developed in house? | ||||
| 34 | Does the proposed product or solution use a GenAI model that was developed by a third party (e.g., ChatGPT)? | ||||
| 35 | Does this solution interface with a third-party GenAI product? | ||||
| 36 | Does this solution interface with any free or open source GenAI components? | ||||
| 37 | Does your organization have policies and procedures including governance, privacy and security implemented to validate information generated by the GenAI for accuracy? | ||||
| 38 | Is data labeling used to identify content generated by the GenAI product or solution? | ||||
| 39 | Are data sources (e.g., social media, news articles, scientific journals) used in the GenAI model identified to ensure content provided is verifiable? | ||||
| 40 | Will County data be used to train or fine tune the GenAI model used in this solution? | ||||
| 41 | Does your organization have a standard in place to update data used in the GenAI model frequently (e.g., weekly, monthly, quarterly) to ensure data integrity? | ||||
| 42 | Does your organization have established copyright and authorized use for all data used to develop and operate the GenAI model to prevent copyright violations? | ||||
| 43 | Is PII information handled or stored by this GenAI solution? | ||||
| 44 | Will any County data be stored or accessed by the GenAI component? | ||||
| 45 | Does your organization perform continuous monitoring to detect GenAI model drift (i.e., degradation of model performance due to changes in data, or relationships between input and output variables)? | ||||
| 46 | Does your organization have security controls implemented to secure the confidentiality of data entered in the GenAI product or solution? | ||||
| 47 | Will the system continue to function if the GenAI service is not available? | ||||
| 48 | Does your organization have a procedure implemented to identify, manage, and mitigate GenAI risk? | ||||
| 49 | Does your organization perform security testing to identify GenAI specific security vulnerabilities (e.g., data poisoning, prompt injection, model exfiltration)? | ||||
| 50 | Are employees allowed to use GenAI technology from a personal device when conducting company business? | ||||
| 51 | Has a third party vendor risk assessment been performed on this GenAI solution? |
Page &P of &N Last Updated: 04/29/2025 image1.png image2.png
File details come from the government source that posted it. Updated .