24Q0015_ATTCH4_CloudQ_021524.pdf

PDF 2 MB Posted

Attached to
Courseware for the Teaching as a Profession Pathway: Education I-III Federal contract opportunity
Solicitation number
HE125424Q0015
Issued by
Department of Defense Education Activity

About this file

This document is a Cloud Questionnaire for the Department of Defense Education Activity (DoDEA) to evaluate a vendor's cloud-based solution. The questionnaire covers several key areas:

  1. Cloud Resource URLs and Access: The vendor must provide all relevant URLs for the cloud resource and confirm if access has been supplied for DoDEA's review.

  2. Client Systems and Software Configuration: The vendor must indicate if DoDEA needs to set up servers or install any software to utilize the service, and if there are any required configurations for DoDEA's computers, browsers, or firewalls.

  3. Privacy Information, Data Collection and Distribution: The vendor must disclose if Personally Identifiable Information (PII) or sensitive data is collected, if any data is shared with third parties, and if the service complies with relevant privacy regulations like COPPA, FERPA, and CIPA.

  4. System Management and Security: The vendor must describe their security practices, including penetration testing, vulnerability scanning, intrusion prevention, and environmental controls for the hosting facility.

  5. Data Storage, Retention, and Access: The vendor must confirm data will be stored in the U.S., accessed only by personnel in the U.S., and that data at rest and in transit will be encrypted.

  6. Development and Change Management, Audits and Standards: The vendor must outline their process for notifying customers of policy changes, enabling DoDEA audits, and adherence to security standards.

  7. Test and Development Environments, Data Breach and Incident Response: The vendor must clarify if live student/PII data is used in non-production environments, and describe their backup, disaster recovery, and incident management capabilities.

This questionnaire is part of the solicitation HE125424Q0015 for digital courseware aligned to the Teaching as a Profession Pathway for the Department of Defense Education Activity.

View the file

Other files for this federal contract opportunity

Other files attached to Courseware for the Teaching as a Profession Pathway: Education I-III, newest first.
File Type Posted
24Q0015_Amend0001_040324.pdf PDF
24Q0015_ATTCH9_QA_040224.pdf PDF
24Q0015_ATTCH1PricingSheet_031424.xlsx XLSX spreadsheet
24Q0015_ATTCH3_ACRVPAT_021524.doc DOC document
24Q0015_ATTCH6_PRCKLST_021524.pdf PDF
24Q0015_ATTCH7_dd2930a_021524.pdf PDF
24Q0015_ATTCH2_TOS_021524.docx DOCX document
24Q0015_ATTCH8_PerformQ_021524.docx DOCX document
24Q0015_SOL_032224.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DoDEA Cloud Questionnaire 1 Revised 19 July 2022 Changes to this form must go thru DoDEA CyberSecurity

DoDEA Cloud Questionnaire Directions

The Department of Defense Education Activity (DoDEA) must review each vendor’s cloud-based solution individually to determine if it is compatible with DoD and DISA’s guidelines. Your answers to this questionnaire will enable us to do that evaluaton quickly and effectively. Please provide the point(s) of contact should DoDEA have questions about your response.

Please note:

Any proprietary or sensitive security information provided in response to this questionnaire will be protected and not shared outside of the US Government.

Links to web-pages will be considered an unacceptable answer to the question but can be provided as supporting documentation.

Not answering a question will be considered an unacceptable response.

Cloud Resource Website/URL’s

1. Are Cloud Resources URLs provided for this solicitation? (Yes or No)

2. Has access to the Cloud Resource been supplied for this solicitation for review? (Yes or No)

3. Please provide all URLs for this resource.

Client Systems and Software Configuration (3 Questions)

1. Will DoDEA need to stand up servers to support this application? (Yes or No)

2. Is any software required for this service, e.g., software that must be installed on DoDEA computers to include browser extensions and/or plugins? (Yes or No)

a. If Yes, has this software been made available for this review? (Yes or No)

3. Are there any configurations or changes that DoDEA must implement to any of its computers, browsers or firewalls to utilize this service? (Yes or No)

Privacy Information Data Collection and Distribution (6 Questions)

1. Is Personally Identifiable Information (PII) and/or sensitive information collected by this service? (Yes or No) (Some examples of PII: Full name, Home address, Work Address, Email address, Social security number, Passport number, Driver’s license number, Date of birth, Gender, Telephone number)

DoDEA Cloud Questionnaire 2 Revised 19 July 2022

2. Is any, personally identifiable and sensitive information collected by third parties or by external business partners (e.g., via cookies, plug-ins, ad networks, web beacons etc.)? (Yes or No)

3. Is any DoDEA data provided to third parties or external business partners for any purpose? (Yes or No)

a. If yes provide a list of all third-party or external business partner recipients.

4. Do third parties or external business partner recipients of DoDEA data adhere to the same policies and processes to protect DoDEA data? (Yes or No)

5. Is there a process to opt-out of any transfers of DoDEA data to third parties or external business partner recipients? (Yes or No)

6. Are the following requirements for your cloud service meet?

a. Children's Online Privacy Protection Act (COPPA), per https://www.congress.gov/bill/105th-congress/senate-bill/2326/text (Yes or No)

b. Privacy Act of 1974, per https://www.justice.gov/opcl/overview-privacy-act-1974-2020-edition

(Yes or No)

c. Family Educational Rights and Privacy Act (FERPA), per https://www2.ed.gov/policy/gen/guid/fpco/ferpa/index.html (Yes or No)

d. Children's Internet Protection Act (CIPA), per http://www.fcc.gov/guides/childrens-internet-protection-act? (Yes or No)

System Management and Security (7 Questions)

1. Do you perform system penetration testing? (Yes or No)

2. Do you perform application penetration testing? (Yes or No)

3. Is application penetration testing performed after code changes? (Yes or No)

4. Do you perform regular system vulnerability testing? (Yes or No)

5. Do you have system intrusion prevention in place? (Yes or No)

6. Are system software updates and patches provided? (Yes or No)

7. Is the system, including its server(s) and network devices, located in an environmentally controlled and secure facility under controlled circumstances (e.g., authorized personnel access lists, ID cards, entry logs)? (Yes or No) http://www.fcc.gov/guides/childrens-internet-protection-act http://www.fcc.gov/guides/childrens-internet-protection-act

DoDEA Cloud Questionnaire 3 Revised 19 July 2022

Data Storage, Retention, and Access (10 Questions)

1. Is DoDEA’s information and data stored in the United States, to include outlying areas or DoD on-premises? (Yes or No)

2. Are all the Offeror’s employees and/or subcontractors that have or will be accessing DoDEA’s data located within the United States? (Yes or No)

3. Will any Sensitive and/or Confidential data including but not limited to PII data be transferred? (Yes or No)

4. Will DoDEA’s data at rest be encrypted? (Yes or No)

5. Is the system/database hosted on a multi-tenant instance? (Yes or No)

6. Is data secured with unique encryption keys for each customer on systems hosting multiple customers?

(Yes or No)

7. Will DoDEA’s data be protected in transit, e.g., secure socket layer (SSL), hashing, etc.? (Yes or No)

8. Are background checks completed on personnel to include subcontractors with access to servers, applications, and customer data? (Yes or No)

9. Is there a process for authenticating callers and resetting access controls? (Yes or No)

10. Is there a process to delete school/system data? (Yes or No)

Development and Change Management Process (4 Questions)

1. Is there a customer notification process for any changes made to corporate policies for data protection?

(Yes or No)

Audits and Standards

2. Is there a process for DoDEA to audit the security and privacy of records? (Yes or No)

3. Are the security operations reviewed or audited by an outside group? (Yes or No)

4. Are any security standards followed? (Yes or No) (Example: International Organization for Standardization (ISO), National Institute of Standards and Technology (NIST) and Payment Card Industry Data Security Standards (PCI DSS))

DoDEA Cloud Questionnaire 4 Revised 19 July 2022

Test and Development Environments (1 Question)

1. Will “live” student/privacy data be used in a non-production environment, e.g., in testing, development, or training)? (Yes or No)

Data Breach, Incident Investigation and Response (4 Questions)

1. Is there a backup-and-restore process in case of a disaster? (Yes or No)

2. Is there protection in place against denial-of-service attack? (Yes or No)

3. Is there process in managing a data breach? (Yes or No)

4. Is there a process in performing security incident investigations and/or e-discovery (different from a data breach)? (Yes or No)

Please provide any Additional if needed.

URLs:
Dropdown1: [Select Item]
Text3:
Text4:
Text6:
Dropdown2: [Select Item]
Dropdown3: [Select Item]
Dropdown4: [Select Item]
Dropdown5: [Select Item]
Dropdown6: [Select Item]
Dropdown7: [Select Item]
Dropdown8: [Select Item]
Dropdown9: [Select Item]
Dropdown10: [Select Item]
Dropdown11: [Select Item]
Dropdown12: [Select Item]
Dropdown13: [Select Item]
Dropdown14: [Select Item]
Dropdown15: [Select Item]
Dropdown16: [Select Item]
Dropdown17: [Select Item]
Dropdown18: [Select Item]
Dropdown19: [Select Item]
Dropdown20: [Select Item]
Dropdown21: [Select Item]
Dropdown22: [Select Item]
Dropdown23: [Select Item]
Dropdown24: [Select Item]
Dropdown25: [Select Item]
Dropdown26: [Select Item]
Dropdown27: [Select Item]
Dropdown28: [Select Item]
Dropdown29: [Select Item]
Dropdown30: [Select Item]
Dropdown31: [Select Item]
Dropdown32: [Select Item]
Dropdown33: [Select Item]
Dropdown34: [Select Item]
Dropdown35: [Select Item]
Dropdown36: [Select Item]
Dropdown37: [Select Item]
Dropdown38: [Select Item]
Dropdown39: [Select Item]
Dropdown40: [Select Item]
Dropdown41: [Select Item]

File details come from the government source that posted it. Updated .