2-A2 Data Security Questionnaire.xlsx

XLSX spreadsheet 21 KB Posted

Attached to
Cyber Security Managed Detection and Response Service State and local contract opportunity
Solicitation number
26-081P
Issued by
Fairbanks North Star Borough, Alaska

About this file

The document is a Data Security Questionnaire for a Cyber Security Managed Detection and Response Service issued by the Matanuska-Susitna Borough in Alaska. The questionnaire is designed to comprehensively assess a vendor's cybersecurity capabilities across seven critical domains: authentication and access control, patch management, security testing and compliance, incident response and data protection, data protection, physical and network security, and additional controls and services.

The questionnaire seeks detailed information from potential vendors, including their capabilities for multi-factor authentication, SIEM log integration, patch management processes, compliance with security standards, incident response plans, data encryption methods, backup policies, physical and network security controls, and supply chain compromise protections. Key areas of inquiry include data ownership, geographic data storage locations, insurance coverage for potential data breaches, email authentication protocols, multi-tenant architecture, and the vendor's approach to maintaining a secure and resilient cybersecurity environment for the Matanuska-Susitna Borough.

View the file

Other files for this state and local contract opportunity

Other files attached to Cyber Security Managed Detection and Response Service, newest first.
File Type Posted
3-26-081P Cyber Security Managed Detection and Response Service.pdf PDF
1-A1 System Requirements Questionnaire.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Data Security Questionnaire 26-081P Cyber Security Managed Detection And Response Service: Vendor Security Questionnaire

Vendor:
Please answer each question thoroughly and provide supporting documentation where requested. If a question does not apply, explain why. Where possible, provide examples, recent reports, or evidence to support your responses.
#Topic/QuestionResponse
1Authentication & Access Control
1.1Do you have Azure/AD Integration?
1.2Do you support Multi-Factor Authentication (MFA) or SSO for accounts and access? Which accounts are covered (e.g., all users, privileged accounts)?
1.3Describe your access control procedures (Identity and Access Management) and provide supporting documentation.
1.4Can logs integrate with SIEM tools?
2Patch Management
2.1What is your policy and process for patching the operating system (OS) and/or application(s)?
2.2Please provide recent examples or reports of patch management activities.
2.3If applicable, does your product allow for mass distribution through tools like SCCM or Intune?
3Security Testing & Compliance
3.1What are your practices regarding penetration testing and vulnerability assessments?
3.2Do you meet any security compliance standards (e.g., NIST, ISO 27001, SOC 2/3)?
3.3Have you received any formal certifications related to your environment? Please specify and attach documentation.
4Incident Response & Data Protection
4.1Do you have a formal incident response plan? Please attach or summarize the plan.
4.2What is your process for Disaster Recovery (DR)?
4.3Has your application or data center ever been compromised? If yes, describe the incident and remediation steps taken.
4.4Do you have an average Mean Time To Recovery (MTTR) or an SLA for MTTR, and what are they?
5Data Protection
5.1Is customer data protected at rest, and what encryption method is used, e.g., AES-256? Where is our data stored (geographic location, data center details)?
5.2How do you manage data backups? Describe your backup policy and frequency.
5.3Who owns the data, and do we have data export capabilities to non-proprietary formats?
5.4Who has access to our data?
5.5What are you insured for if our data (including Personally Identifiable Information - PII) is compromised and revealed? Please provide details of your insurance coverage.
6Physical & Network Security
6.1What is the physical security for your data centers? Describe controls and provide documentation if available. Is Data encrypted during transit, e.g., Transport Layer Security (TLS), and what version?
6.2Provide details for Operations to assess the feasibility of the VPN tunnel if used.
7Additional Controls & Services
7.1What other applications do you incorporate into your services?
7.2Do you have email authentication protocols in place (DKIM, DMARC, and SPF)? Is your platform set up for high availability? Please describe your approach.
7.3Do you employ multi-tenant architecture? If so, how is tenant isolation achieved?
7.4What controls do you have in place for supply chain compromise? Please provide details and examples.

Please ensure that all responses are accurate and provide supporting evidence where applicable. Additional information may be requested based on your responses.

Sheet2

Yes
No

File details come from the government source that posted it. Updated .