24Q0002_ATTCH4CloudQ.pdf

PDF 2 MB Posted

Attached to
World Language Instructional Resources Federal contract opportunity
Solicitation number
HE125424Q0002
Issued by
Department of Defense Education Activity

About this file

This document is a cloud services questionnaire for a federal contract opportunity to provide world language instructional resources. The Department of Defense Education Activity is seeking information about a vendor's cloud-based solution and requires responses to questions in four key areas: privacy and data collection details; system management and security practices; data storage, retention, and access controls; and incident response capabilities. The vendor must provide URLs, confirm whether software installations or network changes are necessary, and describe third-party data sharing and student privacy protections. The questionnaire also probes the vendor's system testing, vulnerability management, personnel screening, data encryption, auditing practices, and compliance with standards like the Children's Online Privacy Protection Act, Family Educational Rights and Privacy Act, and International Organization for Standardization.

View the file

Other files for this federal contract opportunity

Other files attached to World Language Instructional Resources, newest first.
File Type Posted
24Q0002_Amend_122023.pdf PDF
24Q0002_Attch9_121623.pdf PDF
24Q0002_ATTCH2TOS.docx DOCX document
24Q0002_ATTCH1_PRICNGWKSHT_120423.xlsx XLSX spreadsheet
24Q0002_ATTCH72930a.pdf PDF
24Q0002_SOL_120523.pdf PDF
24Q0002_PWS_120523.pdf PDF
24Q0002_ATTCH6PrivChklist.pdf PDF
24Q0002_ATTCH8PPQuestionnaire.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DoDEA Cloud Questionnaire 1 Revised 19 July 2022 Changes to this form must go thru DoDEA CyberSecurity

DoDEA Cloud Questionnaire Directions

The Department of Defense Education Activity (DoDEA) must review each vendor’s cloud-based solution individually to determine if it is compatible with DoD and DISA’s guidelines. Your answers to this questionnaire will enable us to do that evaluaton quickly and effectively. Please provide the point(s) of contact should DoDEA have questions about your response.

Please note:

Any proprietary or sensitive security information provided in response to this questionnaire will be protected and not shared outside of the US Government.

Links to web-pages will be considered an unacceptable answer to the question but can be provided as supporting documentation.

Not answering a question will be considered an unacceptable response.

Cloud Resource Website/URL’s

1. Are Cloud Resources URLs provided for this solicitation? (Yes or No)

2. Has access to the Cloud Resource been supplied for this solicitation for review? (Yes or No)

3. Please provide all URLs for this resource.

Client Systems and Software Configuration (3 Questions)

1. Will DoDEA need to stand up servers to support this application? (Yes or No)

2. Is any software required for this service, e.g., software that must be installed on DoDEA computers to include browser extensions and/or plugins? (Yes or No)

a. If Yes, has this software been made available for this review? (Yes or No)

3. Are there any configurations or changes that DoDEA must implement to any of its computers, browsers or firewalls to utilize this service? (Yes or No)

Privacy Information Data Collection and Distribution (6 Questions)

1. Is Personally Identifiable Information (PII) and/or sensitive information collected by this service? (Yes or No) (Some examples of PII: Full name, Home address, Work Address, Email address, Social security number, Passport number, Driver’s license number, Date of birth, Gender, Telephone number)

DoDEA Cloud Questionnaire 2 Revised 19 July 2022

2. Is any, personally identifiable and sensitive information collected by third parties or by external business partners (e.g., via cookies, plug-ins, ad networks, web beacons etc.)? (Yes or No)

3. Is any DoDEA data provided to third parties or external business partners for any purpose? (Yes or No)

a. If yes provide a list of all third-party or external business partner recipients.

4. Do third parties or external business partner recipients of DoDEA data adhere to the same policies and processes to protect DoDEA data? (Yes or No)

5. Is there a process to opt-out of any transfers of DoDEA data to third parties or external business partner recipients? (Yes or No)

6. Are the following requirements for your cloud service meet?

a. Children's Online Privacy Protection Act (COPPA), per https://www.congress.gov/bill/105th-congress/senate-bill/2326/text (Yes or No)

b. Privacy Act of 1974, per https://www.justice.gov/opcl/overview-privacy-act-1974-2020-edition

(Yes or No)

c. Family Educational Rights and Privacy Act (FERPA), per https://www2.ed.gov/policy/gen/guid/fpco/ferpa/index.html (Yes or No)

d. Children's Internet Protection Act (CIPA), per http://www.fcc.gov/guides/childrens-internet-protection-act? (Yes or No)

System Management and Security (7 Questions)

1. Do you perform system penetration testing? (Yes or No)

2. Do you perform application penetration testing? (Yes or No)

3. Is application penetration testing performed after code changes? (Yes or No)

4. Do you perform regular system vulnerability testing? (Yes or No)

5. Do you have system intrusion prevention in place? (Yes or No)

6. Are system software updates and patches provided? (Yes or No)

7. Is the system, including its server(s) and network devices, located in an environmentally controlled and secure facility under controlled circumstances (e.g., authorized personnel access lists, ID cards, entry logs)? (Yes or No) http://www.fcc.gov/guides/childrens-internet-protection-act http://www.fcc.gov/guides/childrens-internet-protection-act

DoDEA Cloud Questionnaire 3 Revised 19 July 2022

Data Storage, Retention, and Access (10 Questions)

1. Is DoDEA’s information and data stored in the United States, to include outlying areas or DoD on-premises? (Yes or No)

2. Are all the Offeror’s employees and/or subcontractors that have or will be accessing DoDEA’s data located within the United States? (Yes or No)

3. Will any Sensitive and/or Confidential data including but not limited to PII data be transferred? (Yes or No)

4. Will DoDEA’s data at rest be encrypted? (Yes or No)

5. Is the system/database hosted on a multi-tenant instance? (Yes or No)

6. Is data secured with unique encryption keys for each customer on systems hosting multiple customers?

(Yes or No)

7. Will DoDEA’s data be protected in transit, e.g., secure socket layer (SSL), hashing, etc.? (Yes or No)

8. Are background checks completed on personnel to include subcontractors with access to servers, applications, and customer data? (Yes or No)

9. Is there a process for authenticating callers and resetting access controls? (Yes or No)

10. Is there a process to delete school/system data? (Yes or No)

Development and Change Management Process (4 Questions)

1. Is there a customer notification process for any changes made to corporate policies for data protection?

(Yes or No)

Audits and Standards

2. Is there a process for DoDEA to audit the security and privacy of records? (Yes or No)

3. Are the security operations reviewed or audited by an outside group? (Yes or No)

4. Are any security standards followed? (Yes or No) (Example: International Organization for Standardization (ISO), National Institute of Standards and Technology (NIST) and Payment Card Industry Data Security Standards (PCI DSS))

DoDEA Cloud Questionnaire 4 Revised 19 July 2022

Test and Development Environments (1 Question)

1. Will “live” student/privacy data be used in a non-production environment, e.g., in testing, development, or training)? (Yes or No)

Data Breach, Incident Investigation and Response (4 Questions)

1. Is there a backup-and-restore process in case of a disaster? (Yes or No)

2. Is there protection in place against denial-of-service attack? (Yes or No)

3. Is there process in managing a data breach? (Yes or No)

4. Is there a process in performing security incident investigations and/or e-discovery (different from a data breach)? (Yes or No)

Please provide any Additional if needed.

URLs:
Dropdown1: [Select Item]
Text3:
Text4:
Text6:
Dropdown2: [Select Item]
Dropdown3: [Select Item]
Dropdown4: [Select Item]
Dropdown5: [Select Item]
Dropdown6: [Select Item]
Dropdown7: [Select Item]
Dropdown8: [Select Item]
Dropdown9: [Select Item]
Dropdown10: [Select Item]
Dropdown11: [Select Item]
Dropdown12: [Select Item]
Dropdown13: [Select Item]
Dropdown14: [Select Item]
Dropdown15: [Select Item]
Dropdown16: [Select Item]
Dropdown17: [Select Item]
Dropdown18: [Select Item]
Dropdown19: [Select Item]
Dropdown20: [Select Item]
Dropdown21: [Select Item]
Dropdown22: [Select Item]
Dropdown23: [Select Item]
Dropdown24: [Select Item]
Dropdown25: [Select Item]
Dropdown26: [Select Item]
Dropdown27: [Select Item]
Dropdown28: [Select Item]
Dropdown29: [Select Item]
Dropdown30: [Select Item]
Dropdown31: [Select Item]
Dropdown32: [Select Item]
Dropdown33: [Select Item]
Dropdown34: [Select Item]
Dropdown35: [Select Item]
Dropdown36: [Select Item]
Dropdown37: [Select Item]
Dropdown38: [Select Item]
Dropdown39: [Select Item]
Dropdown40: [Select Item]
Dropdown41: [Select Item]

File details come from the government source that posted it. Updated .