8-Attachment 5 - RFP-2000004237-iso systemSecurityMatrix.pdf
PDF 365 KB Posted
- Attached to
- Recreation Management System State and local contract opportunity
- Solicitation number
- RFP 2000004237
- Issued by
- Fairfax County, Virginia
About this file
This is a Project Proposal Matrix for Meeting Information Technology Security Policy Requirements attachment to Request for Proposal RFP-2000004237 issued by Fairfax County for a cloud-based recreation management system to be used by the Fairfax County Park Authority (FCPA) and the Department of Neighborhood and Community Services (NCS). The matrix serves as a standardized template requiring vendor responses that identify compliance with Fairfax County Information Technology Security Policy requirements. The document is organized into four sections: Section A requests basic information about the proposed solution and its technical components; Section B applies to cloud, hosted, or hybrid services solutions; Section C addresses traditional on-premises solutions; and Section D contains general functional security requirements applicable to both cloud and on-premises solutions. Vendors must complete applicable sections based on whether their proposed recreation management system is cloud-based, on-premises, or hybrid in nature.
The security matrix requires vendors to address comprehensive security standards and controls across multiple domains, including compliance with Payment Card Industry Data Security Standard (PCI-DSS), Health Insurance Portability and Accountability Act (HIPAA), and Personally Identifiable Information (PII) protection requirements. Vendors must provide detailed responses regarding vulnerability management programs, cryptographic protocols, access controls, authentication mechanisms, data encryption at rest and in transit, audit logging, physical security, incident response planning, business continuity and disaster recovery capabilities, employee background investigations, and web application security controls. The template was developed based on standards approved by the North Carolina Healthcare Information and Communications Alliance, Inc. and references the Fairfax County Information Technology Security Policy and HIPAA Security Standards. Completion and certification of this matrix is mandatory for all information technology proposals submitted in response to Fairfax County RFP processes.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| 5-Attachment 3 - Implementation and Training Plan Elements.pdf | ||
| 11-Attachment 1 - Technology Profiles and Additional Requirements.pdf | ||
| 7-Recreation Management RFP 2000004237.pdf | ||
| 6-Attachment 8 -RFP 2000004237- Cost Proposal Template.xlsx | XLSX spreadsheet | |
| 4-DPMM Cover.pdf | ||
| 1-Attachment 6 - AI Questionnaire.pdf | ||
| 9-Attachment 2 - RFP 2000004237- Requirements Workbook.xlsx | XLSX spreadsheet | |
| 2-Attachment 4 - SLA Elements.pdf | ||
| 10-Attachments A1 through A9.pdf | ||
| 3-Attachment 7 -RFP-2000004237- form ITConsultantAgreement.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Fairfax County Project Proposal Matrix for Meeting Information Technology Security Policy Requirements
June 2020
Introduction The Fairfax County Project Proposal Matrix for Meeting Information Technology Security Policy Requirements is required as an attachment for information technology responses to Request for Proposal (RFP) processes initiated by Fairfax County. It is intended to assist Fairfax County with soliciting vendor responses that identify the requirements of the Fairfax County Information Technology Security Policy. The clear identification of each element is required by Fairfax County in order to sustain and ensure a solid foundation for the development and implementation of secure information technology practices within Fairfax County Government.
Vendors with access to Fairfax County information resources are required to abide by all policies and procedures of Fairfax County Government.
The RFP Security Matrix has been divided into four main sections. A response is required depending on the proposed solution/service provided by the vendor.
Section A is to provide basic information regarding the proposed solution
Section B is relevant to Cloud/Hosted services, or hybrid Cloud services, in which solution will be located in non-County datacenters.
Section C is applicable to traditional on-premises solutions which will be located in Fairfax County datacenters under control by Fairfax County personnel.
Section D requires responses regardless if solution is a cloud/hosted solution or traditional on-premises solution. This section covers general functional security capabilities inherent to the solution.
How to Use the Security Template
Each section has multiple columns:
1. Standard This section includes the requirement that needs to be addressed. It can take the form of a question or a statement.
2. Compliance The responder shall provide a high level response to the Standard. The answers can be YES, NO, And N/A. The responder should check one of the three boxes to indicate their solution’s capability. Responders can provide a high level explanation of answers in the “Comments/Additional Information” section.
3. Comments/Additional Information In this section the responder should provide any additional information required to answer the question.
References:
The Fairfax County Information Technology Security Policy and the HIPAA Security Standards. This vendor RFP template was based upon similar work approved for public distribution by the North Carolina Healthcare Information and Communications Alliance, Inc. (NCHICA) in August 2003.
http://www.fairfaxcounty.gov/dit/iso/pm70-05_01.pdf
SECTION A: Please complete the following section for proposed CLOUD, HYBRID SERVICES, and ON-PREMISES SOLUTIONS
DESCRIPTION OF PROPOSED SOLUTION COMMENTS/ADDITIONAL INFORMATION
A.1 Requesting County Agency:
A.2 System Name/Title:
A.3 Vendor/Developer:
A.4 RFP Reference Number (if Applicable):
A.5 Is proposed application or service a cloud-based or on-premises solution?
Vendor-hosted On-Premises BOTH:
A.6 Please identify server application components supported to include software, middleware, authentication and user directory options, and third party supporting software or middleware.
Web application Database Active Directory Integration
3rd-party middleware Other Application Windows Server OS
Unix/Linux
Please provide additional information below:
A.7 Client application Internet Explorer Third-party Plugins
A.8
A.9
Please describe any client application components to include client software, and any third party supporting software or middleware for solution to function.
Please indicate which system development lifecycle and security standards your organization adheres to?
Please specify any database versions that support the application.
Oracle Microsoft SQL Server Other N/A
Please specify supported release versions and other additional information below:
A.10 Please specify any user access directory and external authentication requirements to support the application.
Local application user directory Active Directory Other LDAP N/A
SECTION B: Please complete the following for proposed CLOUD/HOSTED OR HYBRID SERVICES
STANDARDS COMPLIANCE COMMENTS/ADDITIONAL INFORMATION
B.1 Payment Card Industry Data Security Standard (PCI-DSS)
If applicable, is your organization and the proposed solution compliant with PCI-DSS? Provide evidence of industry certification of compliance.
Yes No
Provide additional information below:
B.2 Health Insurance Portability and Accountability Act (HIPAA)
If applicable, is your organization and the proposed solution compliant with HIPAA? Provide evidence of industry certification of compliance or other relevant documentation, if available.
B.3 Personally-Identifiable Information (PII)
If applicable, is your organization and the proposed solution compliant with requirements to secure PII? Provide evidence of compliance, if applicable.
B.4 Does the organization maintain a formal information security program that identifies management, operational, and technical controls to ensure the confidentiality, integrity, and availability of information systems and data and validates those controls?
Provide additional information below:
B.5 Does organization maintain an active vulnerability management program to protect systems from known vulnerabilities?
B.6 Does organization validate and test implemented security controls?
Please describe methods whether through internal or third-party audits, vulnerability assessments, penetration testing, etc.?
B.7 Does the organization’s solution use strong cryptography and security protocols (for example, SSL/TLS, IPSEC, etc.) to safeguard information data during transmission between networks?
B.8 Does the organization’s proposed solution maintain a defense-in-depth security architecture incorporating intrusion detection, firewalls, and other network security monitoring and access control mechanisms?
B.9 Does the organization provide adequate controls to protect against malicious code in hosted environment?
Please describe controls.
B.10 Does the organization protect data by implementing access control mechanisms to limit access to data to personnel whose job requires such access?
ALT
B.11 Does the proposed solution uniquely identify and authenticate all users?
B.12 Does the organization protect data by implementing an auditing and systems monitoring program to identify and alert of unauthorized access or transactions?
B.13 Does the organization restrict physical access to systems housing customer data and is the access audited?
B.14 Will County data be encrypted at rest in the proposed solution?
Yes No
Provide additional information below:
B.15 Has the organization implemented data retention and disposal policies, procedures and processes to limit data storage amount and retention time to that which is required for legal, regulatory, and business requirements?
Provide additional information below:
B.16 Does the organization maintain formal electronic data destruction procedures in the event of customer termination of contract?
B.17 Are the data centers in which County data would reside located only in United States or its territories? If no, please explain.
B.18 Are the organization’s hosted application or resources maintained in a multi-tenant environment or platform in which County data is co-mingled with other entities, or dedicated infrastructure for County-specific resources?
B.19 Does the organization maintain high availability of resources available to customers and document and define specific service availability level agreements?
B.20 Does the organization maintain an incident response plan including strategy for notifying customers in the event of a breach and compromise of customer information? Is this incident response plan regularly tested?
B.21 Does the organization maintain a formal Business Continuity/Disaster Recovery Plan? Does organization perform regular exercises to test the effectiveness of the plan?
Provide additional information below
B.22 Does the organization maintain disaster recovery procedures to assist in preventing interruption of system use?
B.23 Does the organization maintain cyber security risk insurance?
Yes No
Provide additional information below
B.24 Is the organization compliant with legal restrictions on the use of copyright material, ensuring that only software developed by the organization, or licensed or provided by the developer to the organization, is used?
B.25 Do all vendor employees and sub-contractors successfully complete a background investigation upon hire?
SECTION C: Please complete the following for proposed ON-PREMISES SYSTEMS
STANDARDS COMPLIANCE COMMENTS/ADDITIONAL INFORMATION
C.1 Payment Card Industry Data Security Standard (PCI-DSS)
If applicable, is the solution compliant with PCI-DSS? Please provide evidence of industry certification of compliance.
C.2 Health Insurance Portability and Accountability Act (HIPAA)
If applicable, is the solution compliant with HIPAA? Please provide evidence of industry certification of compliance.
C.3 Personally-Identifiable Information (PII)
If applicable, is the solution compliant with requirements to secure PII? Provide evidence of compliance, if applicable.
C.4 Does the organization maintain an active vulnerability management program to identify and remediate vulnerabilities in the system/application which is implicated throughout the product lifecycle?
C.5 Does the organization test and validate security controls implemented within the system/application? Please describe methods whether through internal or third-party audits, vulnerability assessments, penetration testing, etc.?
Provide additional information below:
C.6 Does the organization’s application/system use strong cryptography and security protocols (for example, SSL/TLS, IPSEC, etc.) to safeguard information data during transmission?
C.7 Does the proposed solution uniquely identify and authenticate all users (no anonymous access)?
C.8 Will County data be encrypted at rest in the proposed solution?
Yes
C.9 Does the proposed system/application maintain built-in high-availability features?
C.10 Does organization’s proposed solution include disaster recovery features and recommended practices specific to the solution to allow for the continuation of operations in the event of a disaster?
Provide additional information below:
C.11 Is the organization compliant with legal restrictions on the use of copyright material, ensuring that only software developed by the organization, or licensed or provided by the developer to the organization is used for customer’s systems?
SECTION D: Vendors must complete the following section for both CLOUD and ON-PREMISES SOLUTIONS
GENERAL FUNCTIONAL SECURITY
COMPLIANCE COMMENTS/ADDITIONAL INFORMATION
Password Controls
D.1 Does the system enforce strong passwords to include minimum length and combination of alpha and numeric characters?
Current Minimum: ___ Current Maximum: ___
D.2 Can user passwords be automatically changed or account disabled after a period of inactivity has passed?
Current Change Interval: ___
D.3 Can system force users to change default passwords following the initial set up or resetting of the password?
D.4 Can the system prevent auto logon, application remembering, embedded scripts, and hard-coded passwords in software?
D.5 Does system maintain a history of previously used passwords to prevent reuse?
Current Value: ___
D.6 Does the system allow for users to change their own passwords at their discretion?
D.7 Does the system disable accounts after a specified number of consecutive invalid login attempts?
Current # Attempts: ___
D.8 Does system automatically activate a session termination or lock if user remains idle or inactive for a determined period of time?
Default Auto logoff Time:___
D.9 Are passwords entered in a non-display field to access application/system?
D.10 Are passwords encrypted in storage and transmission? Please identify strategy to secure passwords to include encryption algorithm, key size, and use of salted and password hashing.
Provide additional information below:
D.11 Does system supports multi-factor authentication?
APPLICATION TECHNICAL CONTROLS COMPLIANCE COMMENTS/PLANS FOR MEETING COMPLIANCE
Security Administration
D.12 Does system log unauthorized access attempts by date, time, User ID, device and location?
D.13 Does system maintain an audit trail of all security maintenance performed by date, time, User ID, device and location and information is easily accessible?
D.14 Does system provide security reports of users and access levels?
D.15 Does system maintain role-based group and user access control based on business functional requirements?
D.16 Does system provide the capability to place security controls on each system module and on confidential and critical levels within each module?
D.17 Does system provide capability to restrict access to particular records within the system, based on User ID and groups?
D.18 Is on-site training and sufficient supporting reference materials related to security administration available to provide to County if solution is selected?
D.19 Can system and security logs be archived and recalled as needed?
APPLICATION TECHNICAL CONTROLS COMPLIANCE COMMENTS/ADDITIONAL INFORMATION
Networking
D.20 Has the System configuration/architecture (i.e., hardware, wiring, display, network, and interface) been documented in proposal?
Provide additional information below:
D.21 Does your solution require data transmission between multiple solution provider networks? For example, data transmission requirements between Fairfax County networks and vendor-controlled networks, or vendor and sub-contractor networks?
Describe methodology and requirements
D.22 Is there a requirement for vendor to access system remotely from the internet?
Please describe remote access requirements and any built-in features.
D.23 For management and vendor support, can the system support secure remote access such as multi-factor authentication?
D.24 Is the system compatible with mainstream anti-virus and endpoint protection software?
Please specify compatible products:
D.25 For web application security, has the vendor implemented controls in the proposed solution to protect against SQL injection, cross-site scripting, and other common attacks?
I certify that the above responses are true and accurate.
NAME OF OFFEROR:
Typed Name and Title
Signature Date of Submission
| Requesting County Agency: |
| Requesting County Agency1: |
| System NameTitle: |
| System NameTitle1: |
| VendorDeveloper: |
| VendorDeveloper1: |
| RFP Reference Number if Applicable: |
| Current Minimum Current Maximum: |
| Current Maximum: |
| Current Minimum Current Maximum1: |
| NAME OF OFFEROR: |
| Hosted or On-Premises Solution: Off |
| A: |
| 10 Additional Information: |
| 9 Additional Information: |
| 8 Standards: |
| B: |
| 1 Additional Information: |
| 2 Additional Information: |
| 3 Additional Information: |
| 4 Additional Information: |
| 5 Additional Information: |
| 6 Additional Information: |
| 7 Additional Information: |
| 8 Additional Information: |
| 9 Controls: |
| 10 Additional Information: |
| 11 Additional Information: |
| 12 Additional Information: |
| 13 Additional Information: |
| 14 Additional Information: |
| 16 Additional Information: |
| 17 Additional Information: |
| 18 Additional Information: |
| 19 Additional Information: |
| 20 Additional Information: |
| 21 Additional Information: |
| 22 Additional Information: |
| 15 Additional Information: |
| 23 Additional Information: |
| 24 Additional Information: |
| 25 Additional Information: |
| User Access/Authentication: Off |
| Radio Button7: Off |
| Radio Button8: Off |
| Radio Button9: Off |
| Radio Button10: Off |
| Radio Button12: Off |
| Radio Button11: Off |
| Radio Button13: Off |
| Radio Button14: Off |
| Radio Button106: Off |
| Radio Button109: Off |
| PCI: No |
| HIPAA: Off |
| PII: Off |
| Maintain a Formal InfoSec Program: Off |
| Active Vulnerability Management Program: Off |
| Security Controls: Off |
| Cryptography and Security Protocols: Off |
| Defense-in-Depth: Off |
| Controls against malicious code: Off |
| Access control mechanisms: Off |
| Access Control Mechanisms: Off |
| Authenticate Users: Off |
| Auditing and Systems Monitoring: Off |
| Restrict Physical Access: Off |
| County data encrypted at rest: Off |
| Data retention and disposal policies: Off |
| Electonic data destruction procedures: Off |
| County data will reside in US: Off |
| Is County data co-mingled with others: Off |
| Organization maintains high availability of resources: Off |
| Organization maintains incident response plan: Off |
| Business Continuity/Disaster Recovery Plan: Off |
| Disaster Recovery Procedures: Off |
| Cyber Security Risk Insurance: Off |
| Comply with copyright: Off |
| CBI for employees and subcontractors: Off |
| PCI-DSS: Off |
| HIPAA compliant: Off |
| PII compliant: Off |
| Vulnerability management: Off |
| Test and validate security controls: Off |
| cryptography and security protocols used: Off |
| Uniquely identify and authenticate users: Off |
| Will county data be encrypted at rest: Off |
| Built-in high-availability: Off |
| Disaster recovery features: Off |
| copyright compliance: Off |
| strong passwords: Off |
| user passwords automatically changed after inactivity: Off |
| force users to change default passwords: Off |
| prevent auto logon: Off |
| maintain history of used passwords: Off |
| users can change own passwords: Off |
| disable accounts after invalid logon attempts: Off |
| session termination: Off |
| passwords entered in a non-display field: Off |
| passwords encrypted: Off |
| multi-factor authentication: Off |
| log unauthorized access attempts: Off |
| audit trail: Off |
| security reports: Off |
| role-based group and user acces control: Off |
| restrict access to particular records: Off |
| on-site training and supporting reference: Off |
| archive security logs: Off |
| system configuration/architecture is documented: Off |
| data transmission between multiple networks: Off |
| vendor remote access: Off |
| support secure remotes access for management and vendor support: Off |
| compatible with mainstream anti-virus: Off |
| web application security: Off |
| C: |
| 1 Additional Information: |
| 2 Additional Information0: |
| 3 Additional Information: |
| 4 Additional Information: |
| 5 Additional Information: |
| 6 Additional Information: |
| 7 Additional Information: |
| 8 Additional Information: |
| 9 Additional Information: |
| 10 Additional Information: |
| 11 Additional Information: |
| D: |
| 3 Additional Information: |
| 4 Additional Information: |
| 5 Additional Information: |
| 6 Additional Information: |
| 9 Additional Information: |
| 10 Additional Information: |
| 11 Additional Information: |
| 12 Additional Information: |
| 13 Additional Information: |
| 14 Additional Information: |
| 15 Additional Information: |
| 16 Additional Information: |
| 17 Additional Information: |
| 18 Additional Information: |
| 19 Additional Information: |
| 20 Additional Information: |
| 21 Additional Information: |
| 22 Additional Information: |
| 23 Additional Information: |
| 24 Additional Information: |
| 25 Additional Information: |
| Current # Attempts: |
| Default Logoff Time: |
| Name and Title: |
| Submission Date: |
| Server Application Components: Off |
| Client Application Components: Off |
| Client Application Components0: Off |
| Client Application Components1: Off |
| User Access: Off |
| User Access0: Off |
| User Access1: Off |
| User Access2: Off |
| Server Application Components0: Off |
| Server Application Components1: Off |
| Server Application Components2: Off |
| Server Application Components3: Off |
| Server Application Components4: Off |
| Server Application Components5: Off |
| Database: Off |
| Database0: Off |
| Database1: Off |
| Database2: Off |
File details come from the government source that posted it. Updated .