22Q0007_Att4Cloud_12092021.docx

DOCX document 26 KB Posted

Attached to
Theater Digital Instructional Resources Federal contract opportunity
Solicitation number
HE1254-22-Q-0007
Issued by
Department of Defense Education Activity

View the file

Other files for this federal contract opportunity

Other files attached to Theater Digital Instructional Resources, newest first.
File Type Posted
22Q007_AMD_122021.pdf PDF
22Q0007 - Att5 Questions and Answers_122021.pdf PDF
HE125422Q0007-Theater RFQ-120921.pdf PDF
22Q0007_Att2GovernmentProductAccessibility_120921.docx DOCX document
22Q0007_Att3Termsof Serv_12092021.docx DOCX document
22Q0007_Att1-Pricing Sheet 120921.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

HE125422Q0007– Attachment 4– DoDEA Cloud Questionnaire

Directions The Department of Defense Education Activity (DoDEA) must review each vendor’s cloud-based solution individually to determine if it is compatible with DoD’s guidelines. Your answers to this questionnaire will enable us to do that evaluaton quickly and effectively. Your assistance is much appreciated. Please provide the following:

· The point(s) of contact should DoDEA have questions about your response.

· Any proprietary or sensitive security information provided in response to this questionnaire will be protected and not shared outside of the U.S. Government.

Client Systems Software and Configuration

1. Is any software required for this service, e.g., software that must be installed on DoDEA computers to include browser extensions and plugins? Has this software been made available for this review?

2. Is this a standalone or networked application? Will DoDEA need to stand up servers to support this application?

3. Are there any configurations or changes that DoDEA must implement to either its computers or browsers to utilize this service?

Privacy Information Data Collection and Distribution

4. What personally identifiable and sensitive information is collected by this service?

5. What, if any, personally identifiable and sensitive information is collected by third parties or by external business partners (e.g., via cookies, plug-ins, ad networks, web beacons etc.)?

6. Is any DoDEA data provided to third parties or external business partners for any purpose? If yes provide a list of all third-party or external business partner recipients

7. Do third parties or external business partner recipients of DoDEA data adhere to the same policies and processes to protect DoDEA data?

8. Describe the process to opt-out of any transfers of DoDEA data to third parties or external business partner recipients.

9. Which, if any, of the following requirements does your cloud service meet:

a. Children's Online Privacy Protection Act (COPPA), per http://www.coppa.org/coppa.htm?

b. Family Educational Rights and Privacy Act (FERPA), per http://www2.ed.gov/policy/gen/guid/fpco/ferpa/index.html?

c. Children's Internet Protection Act (CIPA), per http://www.fcc.gov/guides/childrens-internet-protection-act?

System Management and Security

10. How is system penetration testing, vulnerability management, and intrusion prevention managed?

11. Are software updates and patches routinely or automatically installed on all servers?

12. Are software and hardware lifecycle management procedures in place to replace end-of-life products?

13. Is the system, including its server(s) and network devices, located in secure facilities under controlled circumstances (e.g., authorized personnel access lists, ID cards, entry logs)?

14. Are server(s) and network devices located in an environmentally-controlled facility?

Data Storage, Retention, and Access

15. Where will information be stored? Will any data be stored outside the United States?

16. How is information stored and transmitted?

a. How does the provider protect data at rest, i.e., data in the data center? What data is encrypted: passwords, privacy information, etc.?

b. Is data secured with unique encryption keys for each customer on systems hosting multiple customers?

c. How is data protected in transit, e.g., secure socket layer (SSL), hashing, etc.?

17. Who has access to information stored or processed by the provider?

18. Are background checks completed on personnel with access to servers, applications and customer data?

19. What is the process for authenticating callers and resetting access controls, as well as establishing and deleting accounts?

20. How is school/system data deleted—on a specific schedule or only upon contract termination?

Development and Change Management Process

21. Are there standardized and documented procedures for coding, configuration management, patch installation, and change management for all servers and network devices involved in delivery of contracted services?

22. What is the customer notification process for any changes made to corporate policies for data protection?

23. Audits and Standards

a. What is the process for DoDEA to audit the security and privacy of records?

b. Are the security operations reviewed or audited by an outside group?

c. What security standard is followed, e.g., the International Organization for Standardization (ISO) and Payment Card Industry Data Security Standards (PCI DSS)?

Test and Development Environments

24. Will “live” student/privacy data be used in non-production environment, e.g., in testing, development, or training)?

25. If so, are these environments secure to the same standard as production data?

Data Breach, Incident Investigation and Response

26. What is the process to manage a data breach?

27. Availability

a. Is there a guaranteed service level? If so describe?

b. What is the backup-and-restore process in case of a disaster?

c. What protection is in place against denial-of-service attack?

28. What is the process to perform security incident investigations or e-discovery?

(END OF ATTACHMENT 4)

2 Revised 22 June 2020

File details come from the government source that posted it. Updated .