8-Attachment 5 - RFP-2000004237-iso systemSecurityMatrix.pdf

PDF 365 KB Posted

Attached to
Recreation Management System State and local contract opportunity
Solicitation number
RFP 2000004237
Issued by
Fairfax County, Virginia

About this file

This is a Project Proposal Matrix for Meeting Information Technology Security Policy Requirements attachment to Request for Proposal RFP-2000004237 issued by Fairfax County for a cloud-based recreation management system to be used by the Fairfax County Park Authority (FCPA) and the Department of Neighborhood and Community Services (NCS). The matrix serves as a standardized template requiring vendor responses that identify compliance with Fairfax County Information Technology Security Policy requirements. The document is organized into four sections: Section A requests basic information about the proposed solution and its technical components; Section B applies to cloud, hosted, or hybrid services solutions; Section C addresses traditional on-premises solutions; and Section D contains general functional security requirements applicable to both cloud and on-premises solutions. Vendors must complete applicable sections based on whether their proposed recreation management system is cloud-based, on-premises, or hybrid in nature.

The security matrix requires vendors to address comprehensive security standards and controls across multiple domains, including compliance with Payment Card Industry Data Security Standard (PCI-DSS), Health Insurance Portability and Accountability Act (HIPAA), and Personally Identifiable Information (PII) protection requirements. Vendors must provide detailed responses regarding vulnerability management programs, cryptographic protocols, access controls, authentication mechanisms, data encryption at rest and in transit, audit logging, physical security, incident response planning, business continuity and disaster recovery capabilities, employee background investigations, and web application security controls. The template was developed based on standards approved by the North Carolina Healthcare Information and Communications Alliance, Inc. and references the Fairfax County Information Technology Security Policy and HIPAA Security Standards. Completion and certification of this matrix is mandatory for all information technology proposals submitted in response to Fairfax County RFP processes.

View the file

Other files for this state and local contract opportunity

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Fairfax County Project Proposal Matrix for Meeting Information Technology Security Policy Requirements

June 2020

Introduction The Fairfax County Project Proposal Matrix for Meeting Information Technology Security Policy Requirements is required as an attachment for information technology responses to Request for Proposal (RFP) processes initiated by Fairfax County. It is intended to assist Fairfax County with soliciting vendor responses that identify the requirements of the Fairfax County Information Technology Security Policy. The clear identification of each element is required by Fairfax County in order to sustain and ensure a solid foundation for the development and implementation of secure information technology practices within Fairfax County Government.

Vendors with access to Fairfax County information resources are required to abide by all policies and procedures of Fairfax County Government.

The RFP Security Matrix has been divided into four main sections. A response is required depending on the proposed solution/service provided by the vendor.

Section A is to provide basic information regarding the proposed solution

Section B is relevant to Cloud/Hosted services, or hybrid Cloud services, in which solution will be located in non-County datacenters.

Section C is applicable to traditional on-premises solutions which will be located in Fairfax County datacenters under control by Fairfax County personnel.

Section D requires responses regardless if solution is a cloud/hosted solution or traditional on-premises solution. This section covers general functional security capabilities inherent to the solution.

How to Use the Security Template

Each section has multiple columns:

1. Standard This section includes the requirement that needs to be addressed. It can take the form of a question or a statement.

2. Compliance The responder shall provide a high level response to the Standard. The answers can be YES, NO, And N/A. The responder should check one of the three boxes to indicate their solution’s capability. Responders can provide a high level explanation of answers in the “Comments/Additional Information” section.

3. Comments/Additional Information In this section the responder should provide any additional information required to answer the question.

References:

The Fairfax County Information Technology Security Policy and the HIPAA Security Standards. This vendor RFP template was based upon similar work approved for public distribution by the North Carolina Healthcare Information and Communications Alliance, Inc. (NCHICA) in August 2003.

http://www.fairfaxcounty.gov/dit/iso/pm70-05_01.pdf

SECTION A: Please complete the following section for proposed CLOUD, HYBRID SERVICES, and ON-PREMISES SOLUTIONS

DESCRIPTION OF PROPOSED SOLUTION COMMENTS/ADDITIONAL INFORMATION

A.1 Requesting County Agency:

A.2 System Name/Title:

A.3 Vendor/Developer:

A.4 RFP Reference Number (if Applicable):

A.5 Is proposed application or service a cloud-based or on-premises solution?

Vendor-hosted On-Premises BOTH:

A.6 Please identify server application components supported to include software, middleware, authentication and user directory options, and third party supporting software or middleware.

Web application Database Active Directory Integration

3rd-party middleware Other Application Windows Server OS

Unix/Linux

Please provide additional information below:

A.7 Client application Internet Explorer Third-party Plugins

A.8

A.9

Please describe any client application components to include client software, and any third party supporting software or middleware for solution to function.

Please indicate which system development lifecycle and security standards your organization adheres to?

Please specify any database versions that support the application.

Oracle Microsoft SQL Server Other N/A

Please specify supported release versions and other additional information below:

A.10 Please specify any user access directory and external authentication requirements to support the application.

Local application user directory Active Directory Other LDAP N/A

SECTION B: Please complete the following for proposed CLOUD/HOSTED OR HYBRID SERVICES

STANDARDS COMPLIANCE COMMENTS/ADDITIONAL INFORMATION

B.1 Payment Card Industry Data Security Standard (PCI-DSS)

If applicable, is your organization and the proposed solution compliant with PCI-DSS? Provide evidence of industry certification of compliance.

Yes No

Provide additional information below:

B.2 Health Insurance Portability and Accountability Act (HIPAA)

If applicable, is your organization and the proposed solution compliant with HIPAA? Provide evidence of industry certification of compliance or other relevant documentation, if available.

B.3 Personally-Identifiable Information (PII)

If applicable, is your organization and the proposed solution compliant with requirements to secure PII? Provide evidence of compliance, if applicable.

B.4 Does the organization maintain a formal information security program that identifies management, operational, and technical controls to ensure the confidentiality, integrity, and availability of information systems and data and validates those controls?

Provide additional information below:

B.5 Does organization maintain an active vulnerability management program to protect systems from known vulnerabilities?

B.6 Does organization validate and test implemented security controls?

Please describe methods whether through internal or third-party audits, vulnerability assessments, penetration testing, etc.?

B.7 Does the organization’s solution use strong cryptography and security protocols (for example, SSL/TLS, IPSEC, etc.) to safeguard information data during transmission between networks?

B.8 Does the organization’s proposed solution maintain a defense-in-depth security architecture incorporating intrusion detection, firewalls, and other network security monitoring and access control mechanisms?

B.9 Does the organization provide adequate controls to protect against malicious code in hosted environment?

Please describe controls.

B.10 Does the organization protect data by implementing access control mechanisms to limit access to data to personnel whose job requires such access?

ALT

B.11 Does the proposed solution uniquely identify and authenticate all users?

B.12 Does the organization protect data by implementing an auditing and systems monitoring program to identify and alert of unauthorized access or transactions?

B.13 Does the organization restrict physical access to systems housing customer data and is the access audited?

B.14 Will County data be encrypted at rest in the proposed solution?

Yes No

Provide additional information below:

B.15 Has the organization implemented data retention and disposal policies, procedures and processes to limit data storage amount and retention time to that which is required for legal, regulatory, and business requirements?

Provide additional information below:

B.16 Does the organization maintain formal electronic data destruction procedures in the event of customer termination of contract?

B.17 Are the data centers in which County data would reside located only in United States or its territories? If no, please explain.

B.18 Are the organization’s hosted application or resources maintained in a multi-tenant environment or platform in which County data is co-mingled with other entities, or dedicated infrastructure for County-specific resources?

B.19 Does the organization maintain high availability of resources available to customers and document and define specific service availability level agreements?

B.20 Does the organization maintain an incident response plan including strategy for notifying customers in the event of a breach and compromise of customer information? Is this incident response plan regularly tested?

B.21 Does the organization maintain a formal Business Continuity/Disaster Recovery Plan? Does organization perform regular exercises to test the effectiveness of the plan?

Provide additional information below

B.22 Does the organization maintain disaster recovery procedures to assist in preventing interruption of system use?

B.23 Does the organization maintain cyber security risk insurance?

Yes No

Provide additional information below

B.24 Is the organization compliant with legal restrictions on the use of copyright material, ensuring that only software developed by the organization, or licensed or provided by the developer to the organization, is used?

B.25 Do all vendor employees and sub-contractors successfully complete a background investigation upon hire?

SECTION C: Please complete the following for proposed ON-PREMISES SYSTEMS

STANDARDS COMPLIANCE COMMENTS/ADDITIONAL INFORMATION

C.1 Payment Card Industry Data Security Standard (PCI-DSS)

If applicable, is the solution compliant with PCI-DSS? Please provide evidence of industry certification of compliance.

C.2 Health Insurance Portability and Accountability Act (HIPAA)

If applicable, is the solution compliant with HIPAA? Please provide evidence of industry certification of compliance.

C.3 Personally-Identifiable Information (PII)

If applicable, is the solution compliant with requirements to secure PII? Provide evidence of compliance, if applicable.

C.4 Does the organization maintain an active vulnerability management program to identify and remediate vulnerabilities in the system/application which is implicated throughout the product lifecycle?

C.5 Does the organization test and validate security controls implemented within the system/application? Please describe methods whether through internal or third-party audits, vulnerability assessments, penetration testing, etc.?

Provide additional information below:

C.6 Does the organization’s application/system use strong cryptography and security protocols (for example, SSL/TLS, IPSEC, etc.) to safeguard information data during transmission?

C.7 Does the proposed solution uniquely identify and authenticate all users (no anonymous access)?

C.8 Will County data be encrypted at rest in the proposed solution?

Yes

C.9 Does the proposed system/application maintain built-in high-availability features?

C.10 Does organization’s proposed solution include disaster recovery features and recommended practices specific to the solution to allow for the continuation of operations in the event of a disaster?

Provide additional information below:

C.11 Is the organization compliant with legal restrictions on the use of copyright material, ensuring that only software developed by the organization, or licensed or provided by the developer to the organization is used for customer’s systems?

SECTION D: Vendors must complete the following section for both CLOUD and ON-PREMISES SOLUTIONS

GENERAL FUNCTIONAL SECURITY

COMPLIANCE COMMENTS/ADDITIONAL INFORMATION

Password Controls

D.1 Does the system enforce strong passwords to include minimum length and combination of alpha and numeric characters?

Current Minimum: ___ Current Maximum: ___

D.2 Can user passwords be automatically changed or account disabled after a period of inactivity has passed?

Current Change Interval: ___

D.3 Can system force users to change default passwords following the initial set up or resetting of the password?

D.4 Can the system prevent auto logon, application remembering, embedded scripts, and hard-coded passwords in software?

D.5 Does system maintain a history of previously used passwords to prevent reuse?

Current Value: ___

D.6 Does the system allow for users to change their own passwords at their discretion?

D.7 Does the system disable accounts after a specified number of consecutive invalid login attempts?

Current # Attempts: ___

D.8 Does system automatically activate a session termination or lock if user remains idle or inactive for a determined period of time?

Default Auto logoff Time:___

D.9 Are passwords entered in a non-display field to access application/system?

D.10 Are passwords encrypted in storage and transmission? Please identify strategy to secure passwords to include encryption algorithm, key size, and use of salted and password hashing.

Provide additional information below:

D.11 Does system supports multi-factor authentication?

APPLICATION TECHNICAL CONTROLS COMPLIANCE COMMENTS/PLANS FOR MEETING COMPLIANCE

Security Administration

D.12 Does system log unauthorized access attempts by date, time, User ID, device and location?

D.13 Does system maintain an audit trail of all security maintenance performed by date, time, User ID, device and location and information is easily accessible?

D.14 Does system provide security reports of users and access levels?

D.15 Does system maintain role-based group and user access control based on business functional requirements?

D.16 Does system provide the capability to place security controls on each system module and on confidential and critical levels within each module?

D.17 Does system provide capability to restrict access to particular records within the system, based on User ID and groups?

D.18 Is on-site training and sufficient supporting reference materials related to security administration available to provide to County if solution is selected?

D.19 Can system and security logs be archived and recalled as needed?

APPLICATION TECHNICAL CONTROLS COMPLIANCE COMMENTS/ADDITIONAL INFORMATION

Networking

D.20 Has the System configuration/architecture (i.e., hardware, wiring, display, network, and interface) been documented in proposal?

Provide additional information below:

D.21 Does your solution require data transmission between multiple solution provider networks? For example, data transmission requirements between Fairfax County networks and vendor-controlled networks, or vendor and sub-contractor networks?

Describe methodology and requirements

D.22 Is there a requirement for vendor to access system remotely from the internet?

Please describe remote access requirements and any built-in features.

D.23 For management and vendor support, can the system support secure remote access such as multi-factor authentication?

D.24 Is the system compatible with mainstream anti-virus and endpoint protection software?

Please specify compatible products:

D.25 For web application security, has the vendor implemented controls in the proposed solution to protect against SQL injection, cross-site scripting, and other common attacks?

I certify that the above responses are true and accurate.

NAME OF OFFEROR:

Typed Name and Title

Signature Date of Submission

Requesting County Agency:
Requesting County Agency1:
System NameTitle:
System NameTitle1:
VendorDeveloper:
VendorDeveloper1:
RFP Reference Number if Applicable:
Current Minimum Current Maximum:
Current Maximum:
Current Minimum Current Maximum1:
NAME OF OFFEROR:
Hosted or On-Premises Solution: Off
A:
10 Additional Information:
9 Additional Information:
8 Standards:
B:
1 Additional Information:
2 Additional Information:
3 Additional Information:
4 Additional Information:
5 Additional Information:
6 Additional Information:
7 Additional Information:
8 Additional Information:
9 Controls:
10 Additional Information:
11 Additional Information:
12 Additional Information:
13 Additional Information:
14 Additional Information:
16 Additional Information:
17 Additional Information:
18 Additional Information:
19 Additional Information:
20 Additional Information:
21 Additional Information:
22 Additional Information:
15 Additional Information:
23 Additional Information:
24 Additional Information:
25 Additional Information:
User Access/Authentication: Off
Radio Button7: Off
Radio Button8: Off
Radio Button9: Off
Radio Button10: Off
Radio Button12: Off
Radio Button11: Off
Radio Button13: Off
Radio Button14: Off
Radio Button106: Off
Radio Button109: Off
PCI: No
HIPAA: Off
PII: Off
Maintain a Formal InfoSec Program: Off
Active Vulnerability Management Program: Off
Security Controls: Off
Cryptography and Security Protocols: Off
Defense-in-Depth: Off
Controls against malicious code: Off
Access control mechanisms: Off
Access Control Mechanisms: Off
Authenticate Users: Off
Auditing and Systems Monitoring: Off
Restrict Physical Access: Off
County data encrypted at rest: Off
Data retention and disposal policies: Off
Electonic data destruction procedures: Off
County data will reside in US: Off
Is County data co-mingled with others: Off
Organization maintains high availability of resources: Off
Organization maintains incident response plan: Off
Business Continuity/Disaster Recovery Plan: Off
Disaster Recovery Procedures: Off
Cyber Security Risk Insurance: Off
Comply with copyright: Off
CBI for employees and subcontractors: Off
PCI-DSS: Off
HIPAA compliant: Off
PII compliant: Off
Vulnerability management: Off
Test and validate security controls: Off
cryptography and security protocols used: Off
Uniquely identify and authenticate users: Off
Will county data be encrypted at rest: Off
Built-in high-availability: Off
Disaster recovery features: Off
copyright compliance: Off
strong passwords: Off
user passwords automatically changed after inactivity: Off
force users to change default passwords: Off
prevent auto logon: Off
maintain history of used passwords: Off
users can change own passwords: Off
disable accounts after invalid logon attempts: Off
session termination: Off
passwords entered in a non-display field: Off
passwords encrypted: Off
multi-factor authentication: Off
log unauthorized access attempts: Off
audit trail: Off
security reports: Off
role-based group and user acces control: Off
restrict access to particular records: Off
on-site training and supporting reference: Off
archive security logs: Off
system configuration/architecture is documented: Off
data transmission between multiple networks: Off
vendor remote access: Off
support secure remotes access for management and vendor support: Off
compatible with mainstream anti-virus: Off
web application security: Off
C:
1 Additional Information:
2 Additional Information0:
3 Additional Information:
4 Additional Information:
5 Additional Information:
6 Additional Information:
7 Additional Information:
8 Additional Information:
9 Additional Information:
10 Additional Information:
11 Additional Information:
D:
3 Additional Information:
4 Additional Information:
5 Additional Information:
6 Additional Information:
9 Additional Information:
10 Additional Information:
11 Additional Information:
12 Additional Information:
13 Additional Information:
14 Additional Information:
15 Additional Information:
16 Additional Information:
17 Additional Information:
18 Additional Information:
19 Additional Information:
20 Additional Information:
21 Additional Information:
22 Additional Information:
23 Additional Information:
24 Additional Information:
25 Additional Information:
Current # Attempts:
Default Logoff Time:
Name and Title:
Submission Date:
Server Application Components: Off
Client Application Components: Off
Client Application Components0: Off
Client Application Components1: Off
User Access: Off
User Access0: Off
User Access1: Off
User Access2: Off
Server Application Components0: Off
Server Application Components1: Off
Server Application Components2: Off
Server Application Components3: Off
Server Application Components4: Off
Server Application Components5: Off
Database: Off
Database0: Off
Database1: Off
Database2: Off

File details come from the government source that posted it. Updated .