Appendix A - DoIT Cloud Security.docx

DOCX document 570 KB Posted

Attached to
Museum Collections Software RFP State and local contract opportunity
Solicitation number
25-448DOIT-APP44-B-45570
Issued by
Illinois

About this file

This is a cloud security requirements document (Appendix A) from the Illinois Department of Innovation & Technology (DoIT) outlining mandatory security controls and standards for vendors providing cloud-hosted systems to the State of Illinois. The document details 30 specific security requirements vendors must comply with, including breach notification procedures, security incident policies, data protection measures, logging requirements, and certification standards. The requirements align with NIST 800-53 security controls and cover areas such as access control, audit logging, incident response, data encryption, and disaster recovery.

The document includes detailed appendices covering minimum logging requirements, security controls based on NIST standards, plan of action templates, authority to operate packet requirements, and vulnerability assessment procedures. Vendors must maintain SOC 1 and SOC 2 Type 2 compliance or undergo alternative third-party security assessments. All state data must be stored within the contiguous United States, encrypted at rest and in transit using FIPS 140-compliant encryption, and be readily accessible in non-proprietary formats. The requirements emphasize continuous monitoring, regular security testing, and prompt remediation of vulnerabilities.

View the file

Other files for this state and local contract opportunity

Other files attached to Museum Collections Software RFP, newest first.
File Type Posted
c2d vendor guidance.pdf PDF
vendor disclosure - formerly forms a~4.docx DOCX document
Attachment B - Database Fields Used by Discipline.xlsx XLSX spreadsheet
C2D Vendor Answer Sheet v.24.4~1.docx DOCX document
Museum Collections Software RFP - B45570~1.docx DOCX document
ipg active registered vendor disclosure - formerly forms b.docx DOCX document
DoIT Museum Collections Software RFP - BEP Utilization Plan 25-1.pdf PDF
DoIT Museum Collections Software RFP - Offer to the State of Illinois - B45570.pdf PDF
Vendor Questions Answer 3-6-2025.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Appendix A Cloud Security

Include the following as part of the procurement and contract for systems hosted in a Vendor cloud environment.

State of Illinois Security Requirements:

1. Vendor will notify the State of Illinois’ Chief Information Security Officer within 24 hours of knowledge of any information breach or other security incident which impacts State of Illinois data. Email notification to: DoIT.Security@illinois.gov and Subject Line should state “Breach Notification.”

2. Vendor shall have a documented security incident policy and plan. Vendor must supply a copy at the request of the State of Illinois.

3. Vendor must comply with all United States Federal and State of Illinois laws, rules, and regulations.

4. Vendor must comply with all of the State of Illinois Enterprise Security Policies (https://www2.illinois.gov/sites/doit/support/policies/Pages/default.aspx).

5. Vendor must ensure that all information technology, including electronic information, software, systems and equipment, developed or provided under this contract complies with the applicable requirements of the Illinois Information Technology Accessibility Act Standards as published at (www.dhs.state.il.us/iitaa). 30 ILCS 587. If available, Vendor must provide the State of Illinois their most recent Voluntary Product Accessibility Template (VPAT).

6. Vendor program and project management personnel must ensure coordination of activities with the State of Illinois governance program. Vendor must comply with all policies, standards, and procedures defined by the State of Illinois Department of Innovation and Technology’s Enterprise Portfolio Management Office.

7. Vendor’s system must interface with the State of Illinois’ identity and access management solutions if authentication is required for access to the system.

8. Vendor’s system must log activity within the system and have capacity to forward log information to the State of Illinois’ security incident and event management system (SIEM). Vendor must meet the State of Illinois’ Minimum Logging Requirements for the term of the Contract.

8.1. (See Security Appendix S1)

9. Vendor certifies it has undertaken independent third-party audit Statement on Standards for Attestation Engagements (SSAE-18) certifications and must provide the State of Illinois with a System Operation Controls report (SOC 1) annually and applicable bridge/gap letter when vendor is hosting State of Illinois financial information.

10. Vendor certifies it can comply with at least one of the following requirements listed in order of preference.

10.1 Vendor certifies it has undertaken independent third-party audit Statement on Standards for Attestation Engagements (SSAE-18) certifications and must provide the State of Illinois with a System Operation Controls report (SOC 2 type 2) annually and applicable bridge/gap letter.

10.2 Vendor must provide the State of Illinois with a 3rd party risk assessment of the Vendor’s system conducted within the last year including a 3rd party penetration test.

10.3 Vendor must provide the State of Illinois with a 3rd party risk assessment of the Vendor’s system conducted within the last year.

10.4 Vendor must provide the State of Illinois with a 3rd party penetration test conducted within the last year.

10.5 Vendor must perform an internal security controls assessment to demonstrate compliance with the State of Illinois Vendor Security Controls, based on the current revision of NIST 800-53 security controls for a moderate system. (See Security Appendix S2)

11. Vendor must participate in an annual risk assessment and data classification and system categorization process. The formal risk assessment will be administered by the State of Illinois.

If Vendor cannot provide the SOC 1 and/or 2 report required above and any necessary bridge/gap letter or another appropriate third-party risk assessment as determined by the State of Illinois, then Vendor must perform an internal security controls assessment to demonstrate compliance with the State of Illinois Vendor Security Controls, based on the current revision of NIST 800-53 security controls for a moderate system. Vendor must provide attestation of compliance along with the results of this assessment documented in a Security Assessment Report (SAR) to the State of Illinois. This does not relieve the Vendor of the above requirement to submit a required SOC 1 and/or SOC 2.

11.1. (See Security Appendix S2)

12. Vendor must provide a Plan of Action and Milestones (POA&M) to the State of Illinois that addresses any control deficiencies identified during the State of Illinois’ risk assessment, review of Vendor’s SOC report(s), third-party assessment, and internal security controls assessment. The POA&M should describe the deficiencies in the security controls, address the residual risk, and detail plans for remediation. Vendor must provide the State of Illinois monthly updates regarding progress toward remediation of identified deficiencies.

12.1. (See Security Appendix S3)

13. Vendor must complete and provide the State of Illinois an Authority to Operate (ATO) or Authority to Connect (ATC) packet at the State of Illinois’ request. This packet must be renewed annually.

13.1. (See Security Appendix S4)

14. Vendor must ensure all hosted data pertinent to this contract shall remain located within the contiguous United States.

15. Vendor must ensure encryption of State of Illinois data at rest and in motion. This encryption must comply with encryption security controls as defined in the most current version of the Federal Information Processing Standard (FIPS) 140 using Advanced Encryption Standard (AES) encryption with a minimum key length of 256 bits. Vendor must provide proof of encryption. Vendor must provide the State of Illinois with the capabilities to manage encryption keys for data at rest.

16. Vendor must store data in a non-proprietary, readily accessible format, or Vendor must provide a solution, at no additional cost to the State of Illinois, to extract any State of Illinois data stored in Vendor’s solution.

17. Vendor must only use State of Illinois data, for the purposes stated in this contract.

18. Vendor must maintain a robust and reliable data backup system. Vendor must supply a description of backup methodology, and this methodology must meet defined Maximum Tolerable Downtime (MTD) and Return to Operations (RPO) requirements.

19. Vendor must provide a written disaster recovery mythology and provide proof of annual disaster recovery testing, including issues discovered and remediation plans for the issues discovered.

20. Vendor may not use any State of Illinois data in any non-production system or in any other system outside the application/service procured under this contract.

21. Vendor must provide a copy of all State of Illinois data (in a non-proprietary format) to the State of Illinois without delay upon request by the State of Illinois.

22. Vendor must provide a copy of all State of Illinois data (in a non-proprietary format) to the State of Illinois prior to termination of contract.

23. Vendor must sanitize all media that contains or contained State of Illinois data. Vendor must use the more current revision of NIST Special Publication 800-88; Guidelines for Media Sanitization. Vendor must provide the State of Illinois with a written certification of media sanitization including the method, date and time.

24. Vendor must use a form of “crypto shredding” acceptable to the State of Illinois for rendering all State of Illinois data hosted by the Vendor inaccessible after a copy of all data has been provided to the State of Illinois.

25. Vendor and/or its agents must not resell nor otherwise redistribute information gained from its access to the State of Illinois data.

26. Vendor must not engage in nor permit its agents to push adware, software, or marketing not explicitly authorized by the State of Illinois.

27. Vendor must allow the State of Illinois to perform vulnerability assessments.

27.1. (See Security Appendix S5)

28. Vendor must immediately remediate critical, high, and medium vulnerabilities within the application that are detected during the security assessments and are determined by the State of Illinois to pose an unacceptable risk.

29. Vendor must secure independent third-party penetration testing at regular intervals, in accordance with Cloud Security Alliance (CSA) and Open Web Application Security Project (OWASP) recommendations. Vendor must supply the results of the testing to the State of Illinois upon request.

30. Vendor must supply a list of all non-proprietary/open source software used in their solution. Vendor must also include the version and Open Source Initiative (OSI) approved license type used for any open source software. If Open Source uses non-OSI approved licensing Vendor must include licensing terms and conditions.

Security Appendix S1 – Minimum Logging Requirements

· Input validation failures (e.g., protocol violations, unacceptable encodings, invalid parameter names and values)

· Output validation failures (e.g., database record set mismatch, invalid data encoding)

· Authentication successes and failures

· Authorization (access control) failures

· Session management failures (e.g., cookie session identification value modification)

· Application errors and system events (e.g., syntax and runtime errors, connectivity problems, performance issues, third-party service error messages, file system errors, file upload virus detection, configuration changes)

· Application and related systems start-ups and shut downs, and logging initialization (starting, stopping, or pausing)

· Use of higher-risk functionality (e.g., network connections, addition or deletion of users, changes to privileges, assigning users to tokens, adding or deleting tokens, use of systems administrative privileges, access by application administrators, all actions by users with administrative privileges, access to payment cardholder data, use of data encrypting keys, key changes, creation and deletion of system-level objects, data import and export including screen-based reports, submission of user-generated content - especially file uploads)

· Legal and other opt-ins (e.g., permissions for mobile phone capabilities, terms of use, terms & conditions, personal data usage consent, permission to receive marketing communications)

Security Appendix S2: Security Controls for Vendors Authoritative Document NIST 800-53 v4 – Security and Privacy Controls Access and Control (AC) Organizations must limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems) and to the types of transactions and functions that authorized users are permitted to exercise.

AC Security Controls and Control Enhancements (for Moderate Security Categorization):

Security Control Summary
Control #
Enhancement #’s
· Access Control Policy and Procedures
AC-1
· Account Management
AC-2
(1), (2), (3), (4)
· Access Enforcement
AC-3
· Information Flow Enforcement
AC-4
· Separation of Duties
AC-5
· Least Privilege
AC-6
(1), (2), (5), (9), (10)
· Unsuccessful Logon Attempts
AC-7
· System Use Notification
AC-8
· Session Lock
AC-11
(1)
· Session Termination
AC-12
· Permitted Actions without Identification or Authentication
AC-14
· Remote Access
AC-17
(1), (2), (3), (4)
· Wireless Access
AC-18
(1)
· Access Control for Mobile Devices
AC-19
(5)
· Use of External Information Systems
AC-20
(1), (2)
· Information Sharing
AC-21
· Publicly Accessible Content
AC-22

Authority

CFR
HIPAA 45 CFR - 160, 162, 164
NIST
SP 800-53 Security and Privacy Controls
FIPS
200 Minimum Security Controls
IRS
1075 Tax Information Security Guidelines
DoIT
DoIT Policies and Associated Standards and Guidelines

Awareness and Training (AT) Organizations must (i) ensure that managers and users of organizational information systems are made aware of the security risks associated with their activities and of the applicable laws, executive orders, directives, policies, standards, instructions, regulations, or procedures related to the security of organizational information systems; and (ii) ensure that organizational personnel are adequately trained to carry out their assigned information security-related duties and responsibilities.

AT - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):

Security Control Summary
Control #
Enhancement #’s
· Security Awareness and Training Policy and Procedures
AT-1
· Security Awareness Training
AT-2
(2)
· Role-Based Security Training
AT-3
· Security Training Records
AT-4

Authority

NIST
SP 800-53 Security and Privacy Controls
FIPS
200 Minimum Security Controls
IRS
1075 Tax Information Security Guidelines
DoIT
DoIT Policies and Associated Standards and Guidelines

Audit and Accountability (AU) Organizations must: (i) create, protect, and retain information system audit records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate information system activity; and (ii) ensure that the actions of individual information system users can be uniquely traced to those users, so they can be held accountable for their actions.

AU - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):

Security Control Summary
Control #
Enhancement #’s
· Audit and Accountability Policy and Procedure
AU-1
· Audit Events
AU-2
(3)
· Content of Audit Records
AU-3
(1)
· Audit Storage Capacity
AU-4
· Response to Audit Processing Failures
AU-5
· Audit Review, Analysis, and Reporting
AU-6
(1), (3)
· Audit Reduction and Report Generation
AU-7
(1)
· Time Stamps
AU-8
(1)
· Protection of Audit Information
AU-9
(4)
· Audit Record Retention
AU-11
· Audit Generation
AU-12

Authority

CFR
HIPAA 45 CFR - 160, 162, 164
NIST
SP 800-53 Security and Privacy Controls
FIPS
200 Minimum Security Controls
IRS
1075 Tax Information Security Guidelines
DoIT
DoIT Policies and Associated Standards and Guidelines

Certification, Accreditation, and Security Assessments (CA) Organizations must: (i) periodically assess the security controls in organizational information systems to determine if the controls are effective in their application; (ii) develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organization information systems; (iii) authorize the operation of organizational information systems and any associated information system connections; and (iv) monitor information system security controls on an ongoing basis to ensure the continued effectiveness of the controls.

CA - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):

Security Control Summary
Control #
Enhancement #’s
· Security Assessment and Authorization Policy and Procedures
CA-1
· Security Assessments
CA-2
(1)
· System Interconnections
CA-3
(5)
· Plan of Action and Milestones
CA-5
· Security Authorization
CA-6
· Continuous Monitoring
CA-7
(1)
· Internal System Connections
CA-9

Authority

NIST
SP 800-53 Security and Privacy Controls
NIST
SP 800-53A Assessing Security Controls
FIPS
200 Minimum Security Controls
IRS
1075 Tax Information Security Guidelines
DoIT
DoIT Policies and Associated Standards and Guidelines

Configuration Management (CM) Vendors must: (i) establish and maintain baseline configurations and inventories of organizational information systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; and (ii) establish and enforce security configuration settings for information technology products employed in organizational information systems.

CM - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):

Security Control Summary
Control #
Enhancement #’s
· Configuration Management Policy and Procedures
CM-1
· Baseline Configuration
CM-2
(1), (3), (7)
· Configuration Change Control
CM-3
(2)
· Security Impact Analysis
CM-4
· Access Restrictions for Change
CM-5
· Configuration Settings
CM-6
· Least Functionality
CM-7
(1), (2), (4)
· Information System Component Inventory
CM-8
(1), (3), (5)
· Configuration Management Plan
CM-9
· Software Usage Restrictions
CM-10
· User-Installed Software
CM-11

Authority

NIST
SP 800-53 Security and Privacy Controls
FIPS
200 Minimum Security Controls
IRS
1075 Tax Information Security Guidelines
DoIT
DoIT Policies and Associated Standards and Guidelines

Contingency Planning (CP) Organizations must establish, maintain, and effectively implement plans for emergency response, backup operations, and post-disaster recovery for organizational information systems to ensure the availability of critical information resources and continuity of operations in emergency situations.

CP - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):

Security Control Summary
Control #
Enhancement #’s
· Contingency Planning Policy and Procedures
CP-1
· Contingency Plan
CP-2
(1), (3), (8)
· Contingency Training
CP-3
· Contingency Plan Testing
CP-4
(1)
· Alternate Storage Site
CP-6
(1), (3)
· Alternate Processing Site
CP-7
(1), (2), (3)
· Telecommunications Services
CP-8
(1), (2)
· Information System Backup
CP-9
(1)
· Information System Recovery and Reconstitution
CP-10
(2)

Authority

CFR
HIPAA 45 CFR - 160, 162, 164
NIST
SP 800-53 Security and Privacy Controls
FIPS
200 Minimum Security Controls
IRS
1075 Tax Information Security Guidelines
DoIT
DoIT Policies and Associated Standards and Guidelines

Identification and Authentication (IA) Organizations must identify information system users, processes acting on behalf of users, or devices and authenticate (or verify) the identities of those users, processes, or devices as a prerequisite to allowing access to organizational information systems.

IA - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):

Security Control Summary
Control #
Enhancement #’s
· Identification and Authentication Policy and Procedures
IA-1
· Identification and Authentication (Organizational Users)
IA-2
(1), (2), (3), (8), (11), (12)
· Device Identification and Authentication
IA-3
· Identifier Management
IA-4
· Authentication Management
IA-5
(1), (2), (3), (11)
· Authenticator Feedback
IA-6
· Cryptographic Module Authentication
IA-7
· Identification and Authentication (Non-Organizational Users)
IA-8
(1), (2), (3), (4)

Authority

CFR
HIPAA 45 CFR - 160, 162, 164
NIST
SP 800-53 Security and Privacy Controls
FIPS
200 Minimum Security Controls
IRS
1075 Tax Information Security Guidelines
DoIT
DoIT Policies and Associated Standards and Guidelines

Incident Response (IR) Organizations must: (i) establish an operational incident handling capability for organizational information systems that includes adequate preparation, detection, analysis, containment, recovery, and user response activities; and (ii) track, document, and report incidents to appropriate organizational officials and/or authorities.

IR - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):

Security Control Summary
Control #
Enhancement #’s
· Incident Response Policy and Procedures
IR-1
· Incident Response Training
IR-2
· Incident Response Testing
IR-3
(2)
· Incident Handling
IR-4
(1)
· Incident Monitoring
IR-5
· Incident Reporting
IR-6
(1)
· Incident Response Assistance
IR-7
(1)
· Incident Response Plan
IR-8

Authority

CFR
HIPAA 45 CFR - 160, 162, 164
NIST
SP 800-53 Security and Privacy Controls
FIPS
200 Minimum Security Controls
IRS
1075 Tax Information Security Guidelines
DoIT
DoIT Policies and Associated Standards and Guidelines

Maintenance (MA) Organizations must: (i) perform periodic and timely maintenance on organizational information systems; and (ii) provide effective controls on the tools, techniques, mechanisms, and personnel used to conduct information system maintenance.

MA - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):

Security Control Summary
Control #
Enhancement #’s
· System Maintenance Policy and Procedures
MA-1
· Controlled Maintenance
MA-2
· Maintenance Tools
MA-3
(1), (2)
· Nonlocal Maintenance
MA-4
(2)
· Maintenance Personnel
MA-5
· Timely Maintenance
MA-6

Authority

NIST
SP 800-53 Security and Privacy Controls
FIPS
200 Minimum Security Controls
IRS
1075 Tax Information Security Guidelines
DoIT
DoIT Policies and Associated Standards and Guidelines

Media Protection (MP) Organizations must: (i) protect information system media, both paper and digital; (ii) limit access to information on information system media to authorized users; and (iii) sanitize or destroy information system media before disposal or release for reuse.

MP - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):

Security Control Summary
Control #
Enhancement #’s
· Media Protection Policy and Procedures
MP-1
· Media Access
MP-2
· Media Marking
MP-3
· Media Storage
MP-4
· Media Transport
MP-5
(4)
· Media Sanitization
MP-6
· Media Use
MP-7
(1)

Authority

CFR
HIPAA 45 CFR - 160, 162, 164
NIST
SP 800-53 Security and Privacy Controls
FIPS
200 Minimum Security Controls
IRS
1075 Tax Information Security Guidelines
DoIT
DoIT Policies and Associated Standards and Guidelines

Physical and Environmental Protection (PE) Organizations must: (i) limit physical access to information systems, equipment, and the respective operating environments to authorized individuals; (ii) protect the physical plant and support infrastructure for information systems; (iii) provide supporting utilities for information systems; (iv) protect information systems against environmental hazards; and (v) provide appropriate environmental controls in facilities containing information systems.

PE - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):

Security Control Summary
Control #
Enhancement #’s
· Physical and Environmental Protection Policy and Procedures
PE-1
· Physical Access Authorizations
PE-2
· Physical Access Control
PE-3
· Access Control for Transmission Medium
PE-4
· Access Control for Output Devices
PE-5
· Monitoring Physical Access
PE-6
(1)
· Visitor Access Records
PE-8
· Power Equipment and Cabling
PE-9
· Emergency Shutoff
PE-10
· Emergency Power
PE-11
· Emergency Lighting
PE-12
· Fire Protection
PE-13
(3)
· Temperature and Humidity Controls
PE-14
· Water Damage Protection
PE-15
· Delivery and Removal
PE-16
· Alternate Work Site
PE-17

Authority

NIST
SP 800-53 Security and Privacy Controls
FIPS
200 Minimum Security Controls
IRS
1075 Tax Information Security Guidelines
DoIT
DoIT Policies and Associated Standards and Guidelines

Planning (PL) Organizations must develop, document, periodically update, and implement security plans for organizational information systems that describe the security controls in place or planned for the information systems and the rules of behavior for individuals accessing the information systems.

PL - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):

Security Control Summary
Control #
Enhancement #’s
· Security Planning Policy and Procedures
PL-1
· System Security Plan
PL-2
(3)
· Rules of Behavior
PL-4
(1)
· Information Security Architecture
PL-8

Authority

NIST
SP 800-53 Security and Privacy Controls
FIPS
200 Minimum Security Controls
IRS
1075 Tax Information Security Guidelines
DoIT
DoIT Policies and Associated Standards and Guidelines

Personnel Security (PS) Organizations must: (i) ensure that individuals occupying positions of responsibility within organizations (including third-party service providers) are trustworthy and meet established security criteria for those positions; (ii) ensure that organizational information and information systems are protected during and after personnel actions, such as terminations and transfers; and (iii) employ formal sanctions for personnel failing to comply with organizational security policies and procedures.

PS - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):

Security Control Summary
Control #
Enhancement #’s
· Personnel Security Policy and Procedures
PS-1
· Position Risk Designation
PS-2
· Personnel Screening
PS-3
· Personnel Termination
PS-4
· Personnel Transfer
PS-5
· Access Agreements
PS-6
· Third-Party Personnel Security
PS-7
· Personnel Sanctions
PS-8

Authority

NIST
SP 800-53 Security and Privacy Controls
FIPS
200 Minimum Security Controls
IRS
1075 Tax Information Security Guidelines
DoIT
DoIT Policies and Associated Standards and Guidelines

Risk Assessment (RA) Organizations must periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals resulting from the operation of organizational information systems and the associated processing, storage, or transmission of organizational information.

RA - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):

Security Control Summary
Control #
Enhancement #’s
· Risk Assessment Policy and Procedures
RA-1
· Security Categorization
RA-2
· Risk Assessment
RA-3
· Vulnerability Scanning
RA-5
(1), (2), (5)

Authority

CFR
HIPAA 45 CFR - 160, 162, 164
NIST
SP 800-53 Security and Privacy Controls
FIPS
200 Minimum Security Controls
IRS
1075 Tax Information Security Guidelines
DoIT
DoIT Policies and Associated Standards and Guidelines

System and Services Acquisition (SA) Organizations must: (i) allocate sufficient resources to adequately protect organizational information systems; (ii) employ system development life cycle processes that incorporate information security considerations; (iii) employ software usage and installation restrictions; and (iv) ensure that third-party providers employ adequate security measures to protect information, applications, and or services outsourced from the organizations.

SA - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):

Security Control Summary
Control #
Enhancement #’s
· System and Services Acquisition Policy and Procedures
SA-1
· Allocation of Resources
SA-2
· System Development Life Cycle
SA-3
· Acquisition Process
SA-4
(1), (2), (9), (10)
· Information System Documentation
SA-5
· Security Engineering Principles
SA-8
· External Information System Services
SA-9
(2)
· Developer Configuration Management
SA-10
· Developer Security Testing and Evaluation
SA-11

Authority

NIST
SP 800-53 Security and Privacy Controls
FIPS
200 Minimum Security Controls
IRS
1075 Tax Information Security Guidelines
DoIT
DoIT Policies and Associated Standards and Guidelines

System and Communications Protection (SC) Organizations must: (i) monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries for the information systems; and (ii) employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational information systems.

SC - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):

Security Control Summary
Control #
Enhancement #’s
· System and Communication Protection Policy and Procedures
SC-1
· Application Partitioning
SC-2
· Information in Shared Resources
SC-4
· Denial of Service Protection
SC-5
· Boundary Protection
SC-7
(3), (4), (5), (7)
· Transmission Confidentiality and Integrity
SC-8
(1)
· Network Disconnect
SC-10
· Cryptographic Key Establishment and Management
SC-12
· Cryptographic Protection
SC-13
· Collaborative Computing Devices
SC-15
· Public Key Infrastructure Certificates
SC-17
· Mobile Code
SC-18
· Voice Over Internet Protocol
SC-19
· Secure Name/Address Resolution Service (Authoritative Source)
SC-20
· Secure Name/Address Resolution Service (Recursive or Caching Resolver)
SC-21
· Architecture and Provisioning for Name/Address Resolution Service
SC-22
· Session Authenticity
SC-23
· Protection of Information at Rest
SC-28
· Process Isolation
SC-39

Authority

CFR
HIPAA 45 CFR - 160, 162, 164
NIST
SP 800-53 Security and Privacy Controls
FIPS
200 Minimum Security Controls
IRS
1075 Tax Information Security Guidelines
DoIT
DoIT Policies and Associated Standards and Guidelines

System and Information Integrity (SI) Organizations must: (i) identify, report, and correct information and information systems flaws in a timely manner; (ii) provide protection from malicious code at appropriate locations within organizational information systems, and (iii) monitor information system security alerts and advisories and take appropriate actions in response.

SI - NIST Security Controls and Control Enhancements (for Moderate Security Categorization):

Security Control Summary
Control #
Enhancement #’s
· System and Information Integrity Policy and Procedures
SI-1
· Flaw Remediation
SI-2
(2)
· Malicious Code Protection
SI-3
(1), (2)
· Information System Monitoring
SI-4
(2), (4), (5)
· Security Alerts, Advisories and Directives
SI-5
· Software, Firmware, and Information Integrity
SI-7
(1), (7)
· Spam Protection
SI-8
(1), (2)
· Information Input Validation
SI-10
· Error Handling
SI-11
· Information Handling and Retention
SI-12
· Memory Protection
SI-16

Authority

CFR
HIPAA 45 CFR - 160, 162, 164
NIST
SP 800-53 Security and Privacy Controls
FIPS
200 Minimum Security Controls
IRS
1075 Tax Information Security Guidelines
DoIT
DoIT Policies and Associated Standards and Guidelines

Security Appendix S3 - Plan of Actions and Milestones Template

Identified Deficiency
Residual Risk
Detailed Remediation Plan with Timeline
Expected Completion Date

Security Appendix 4 – Authority to Operate / Authority to Connect Packet

Security Appendix S5 – Authority Packet STATE OF ILLINOIS NIST and FISMA Compliance Document Project Name:

Date:

Duration of Project:

Vendor Name:

Vendor Contact Information:

A. The departments and agencies within all branches of the Federal Government are required by Federal Information Security Modernization Act (FISMA) of 2014 to comply with OMB E-GOV guidance to provide information security for the information and information systems that support the operations and assets under their control. The Federal Office of Management and Budget (OMB) has published guidance for the executive branch in OMB Circulars A-123, Appendix D and A-130.

B. STATE OF ILLINOIS recognizes that FISMA compliance, effective information security management, and continuous monitoring of information systems are paramount to the success of information technology (IT) systems. In order to establish an information security program in accordance with FISMA, Vendor must follow the National Institute for Standards and Technology (NIST) Guidelines of the NIST Risk Management Framework (RMF), as amended.

C. Requirements

(1) Each requirement in the table below is understood to contain the implied prefix, " Vendor shall..."

Area
Requirement ID
Description
NIST and FISMA Compliance
1
Describe in detail how Vendor will meet all NIST and FISMA requirements before the solution or projects approved for production.

VENDOR RESPONSE:

NIST and FISMA Compliance
2
Describe in detail how Vendor will define information system boundaries for authorization.

VENDOR RESPONSE:

NIST and FISMA Compliance
3
Describe in detail how Vendor will assess, review, and evaluate the information systems to be implemented based upon security categorization in accordance with Federal Information Processing Standards (FIPS) Publication 199 Standards for Security Categorization of Federal Information and Information Systems. Additional guidance on defining the information type can be obtained from National Institute Technological Standards (NIST) SP 800-60.

VENDOR RESPONSE:

NIST and FISMA Compliance
4
Describe in detail how Vendor will select the baseline controls described in FIPS 200 and NIST SP 800-53 to develop a System Security Plan (SSP).

VENDOR RESPONSE:

NIST and FISMA Compliance
5
Describe in detail how Vendor will meet security requirements with regard to protecting the confidentiality, integrity, and availability of the system and the information processed, stored, and transmitted by the system.

VENDOR RESPONSE:

NIST and FISMA Compliance
6
Describe in detail how Vendor will perform continuous monitoring of the system in compliance with NIST SP 800-137.

VENDOR RESPONSE:

(2) Vendor shall provide the following System Security Plan (SSP):
The Vendor must develop a SSP using the guidance from NIST Risk Management Framework (RMF) (NIST SP 800-18) to establish an information security program in accordance with the Federal Information Security Management Act (FISMA) and demonstrate compliance.

This SSP must be approved by an authorizing official within the STATE OF ILLINOIS. The SSP must include, but shall not be limited to, the following:

i. Description of how the system is to be compliant with all the United States Federal and State of Illinois laws regarding the security and privacy of medical data and records and of all protected health information (PHI), including:

a) The Code of Federal Regulations (at 45 CFR 95.621), which provides that State of Illinois agencies are responsible for the security of all automated data processing systems involved in the administration of Department of Health and Human Services’ programs, and which includes the establishment of a security plan that outlines how software and data security will be maintained. This section further requires that State of Illinois agencies conduct a review and evaluation of physical and data security operating procedures and personnel practices on a biennial basis.

b) The security and privacy standards contained in Pub. L. 104–191, the Health Insurance Portability and Accountability Act of 1996 (HIPAA), and adopted in 45 CFR Part 164, Subparts C and E, as follows: The security standards require that measures be taken to secure protected heath information that is transmitted or stored in electronic format. The privacy standards apply to protected health information that may be in electronic, oral, and paper form.

c) The requirements in section 1902(a)(7) of the Social Security Act (the Act), as further interpreted in Federal regulations at 42 CFR 431.300 to 307.

ii. Description of measures to secure data and software;

iii. Description of how data is encrypted in transit and in storage;

iv. Description of physical and equipment security measures;

v. Description of personnel security;

vi. Description of software used for security;

vii. Description of the user roles and the access capabilities of each role;

viii. Description of how users are assigned certain roles;

ix. Identification of the staff responsible for controlling the system security;

x. Description of contingency security procedures during a disaster recovery event;

xi. Description of how Vendor works with Office of the Statewide Chief Information Security Officer to conduct annual security review;

xii. Description of how Vendor will ensure password security

xiii. Audit trails for all data access;

xiv. Acknowledgement that Vendor will be responsible for all costs associated with Identify theft, resulting from security breach.

D. Security Risk Assessment. STATE OF ILLINOIS or an independent entity will perform a security control assessment. STATE OF ILLINOIS will provide Vendor a copy of the approved security control assessment. Once Vendor receives the approved assessment, Vendor must then develop a Security Risk Assessment based on the applicable security controls. Guidance on conducting and documenting the Security Risk Assessment can be obtained in NIST SP 800-30.

E. Plan of Action and Milestones (POA&M). After STATE OF ILLINOIS reviews and approves the Security Risk Assessment, Vendor should begin to develop a POA&M. The POA&M should be a living document that is based on the findings and recommendations of the security assessment report. The POA&M should describe the deficiencies in the security controls, address the residual risk, and detail plans for remediation and identify timeline for such remediation.

F. Authorization Approval Package.

(a) After STATE OF ILLINOIS reviews and approves the POA&M, Vendor must prepare a transmittal letter to request approval of the entire authorization package. The authorization package must include at a minimum the following documents:

i. Transmittal Letter

ii. Updated System Security Plan

iii. Security Assessment Plan (include the STATE OF ILLINOIS/independent security assessment)

iv. Security Assessment Report (include the STATE OF ILLINOIS/independent security assessment)

v. Security Risk Assessment

vi. Plan of Action and Milestones

vii. Supporting Documentation including but not limited to design documentation, “As Built” documentation, operational documentation, validation documentation, prior authorization documentation, and other artifacts associated with the implementation and monitoring of the security controls.

(b) The authorizing official will determine the risk to the organizational operation and determine if the system is authorized to proceed. The authorizing official will deliver to Vendor a letter of authorization specifying any limitations or restriction placed on the operation of the system. Additionally, this letter should establish an end date for the security authorization.

(c) If the authorizing official denies the authorization, STATE OF ILLINOIS will continue to work with Vendor until an acceptable level of residual risk for the system is achieved. This work should include the continued remediation listed in the POA&M.

G Life-Cycle Management Vendor shall perform security system reviews and reauthorization of the system at the direction of STATE OF ILLINOIS. Vendor shall be responsible for meeting the following requirements:

(a) Performing continuous monitoring of the security system. Vendor’s continuous monitoring must include periodically selecting a subset of the baseline controls for assessment. Based on assessment of these controls, subsequent remediation actions must be identified and implemented. The ongoing remediation process should include updating key documents such as the SSP, SAR, and POA&M.

(b) Prior to any system or environmental modifications, Vendor must perform a security impact analysis. This must be included as a part of any change management or configuration management process. If the results of the modification indicate changes to the security posture of the system, corrective actions should be initiated and appropriate documents revised and updated. The updating of the documentation and continuous monitoring should provide near real-time risk management.

(c) A monthly Security Status Report must be produced by Vendor for STATE OF ILLINOIS. The Security Status Report should provide essential information regarding the security posture of the system as well as the effectiveness of the controls deployed. Ongoing monitoring activities should be detailed as well as ongoing remediation efforts to address known vulnerabilities. Additional guidance for the monitoring of system security can be obtained in NIST SP 800-137.

Security Appendix S5 – Vulnerability Assessment

· Vendor must obtain approval on behalf of the State of Illinois to perform vulnerability assessments on the cloud-hosting vendor’s website(s).

· Vendor must execute the State of Illinois Vulnerability Scanning Agreement prior to the vulnerability assessment.

(See DoIT Scanning Agreement)

· State of Illinois may, with reasonable notice to Vendor, conduct a security assessment of Vendor’s solution, which may include the following:

· Prior to initial “official” production role out of the application,

· Whitelisted scanning and manual testing of the application only, with application credentials equal to the least privileged role within the application

· Manual verification of scan results with the same credentials

· Manual testing of the application for vulnerabilities

· State of Illinois will not conduct any Denial of Service (DOS) attacks

· State of Illinois will not scan or test any infrastructure devices (servers, switches, routers, intrusion protection system, firewalls, etc.)

· On a quarterly basis for the for the first year after initial production deployment,

· Whitelisted scanning and manual testing of the application only, with application credentials equal to the least privileged role within the application

· Manual verification of scan results with the same credentials

· Manual testing of the application for vulnerabilities

· State of Illinois will not conduct any DOS attacks

· State of Illinois will not scan or test any infrastructure devices (servers, switches, routers, intrusion protection system, firewalls, etc.)

· Prior to any enhancements or upgrades being deployed to production after the initial “official” production role out of the application,

· Whitelisted scanning and manual testing of the application only, with application credentials equal to the least privileged role within the application

· Manual verification of scan results with the same credentials

· Manual testing of the application for vulnerabilities

· State of Illinois will not conduct any DOS attacks

· State of Illinois will not scan or test any infrastructure devices (servers, switches, routers, intrusion protection system, firewalls, etc.)

· Monthly vulnerability scan – no whitelisting, non-credentialed scan (same day every month) DoIT Scanning Agreement DDDDddd State of Illinois IFB Contract: State Supplemental Provisions V.23.3 DoIT Legal – May 2023 image1.jpg

File details come from the government source that posted it. Updated .