Appendix M - ESD-Security-Standard-Brief.pdf
PDF 73 KB Posted
- Attached to
- Wilkeson Pointe Improvements ITB State and local contract opportunity
- Solicitation number
- 2097974
- Issued by
- Erie County, New York
About this file
This document is an Information Security Standard Brief from ESD (Empire State Development) outlining security requirements for all engagements with data or IT components. The brief establishes mandatory security standards and guidelines for safeguarding ESD information and resources. Within 30 days of contract signing, additional deliverables must be identified from ESD's IT Deliverables Standard, documented as project milestones, and delivered according to ESD business requirements.
The standards require compliance with ISO Standards 27001, 27005, and 27035 for network and data protection, GDPR standards for data collection, and NYS and Federal Cyber Security policies. Key requirements include maintaining documented monitoring processes for third-party compliance, providing Identity Access Management with authentication and transaction auditing capabilities, certifying supply chain vendor compliance with ISO standards, documenting all third-party access to ESD systems, and managing information communications security. The brief references relevant resources through links to iso.org and gdpr.eu for detailed compliance information.
View the file
Other files for this state and local contract opportunity
Show all 21
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Version 1
ESD Information Security Standard Brief
All engagements with ESD that have a data or IT component are subject at a minimum, to the following security standards and guidelines as they relate to the safeguarding of ESD information and resources. Additional deliverables that are applicable to the project should be identified from ESD’s IT Deliverables Standard within 30 days of contract signing, documented as milestones in the project plan, and delivered in alignment with ESD business requirements. The IT Deliverables Standard will be provided to prospective vendors prior to contract completion or upon request.
• Security Compliance
• Partners, contractors, vendors, suppliers and all other 3rd parties working with ESD or ESD’s contracted vendors must comply with ISO Standards 27001, 27005 and 27035 as they relate to the protection of ESD’s network, data and information systems. For more information about these and other ISO standards visit https://www.iso.org
• Must have monitoring process in place and documented for 3rd party compliance
• If applicable, must provide Identity Access Management, including authentication and transaction auditing
• Must provide documentation certifying that all 3rd party vendors in the supply chain are complying with ISO standards 27001, 27005 and 27035 as related to their role in the project
• Must comply with GDPR standards for data collection and protection. For more information about GDPR please visit https://gdpr.eu/
• Must adhere to NYS and Federal Cyber Security and Information Security Polices and Laws
• Must document all 3rd party access to ESD data or information systems
• Must manage Information Communications to maintain the security of ESD data https://www.iso.org/ https://gdpr.eu/
File details come from the government source that posted it. Updated .