Att B3 - IOT-SaaS.docx

DOCX document 34 KB Posted

Attached to
ISPHN Centralized Billing OfficeBid Documents State and local contract opportunity
Solicitation number
RFP 26-86529
Issued by
Indiana

About this file

This document is Attachment B.3 of the State of Indiana's Additional Terms and Conditions for Software as a Service (SaaS) engagements. The attachment establishes comprehensive requirements governing data ownership, protection, security, and operational standards for contractors providing SaaS services to the State. The terms define critical concepts including Data (all State-created information in any form), Data Breach (unauthorized access to encrypted data), Encrypted Data (information required to be encrypted under contract), and Security Incident (unauthorized access to contractor systems). The contractor must comply with the Indiana Office of Technology Information Security Framework and maintain all services exclusively within United States data centers, with 24/7 technical support unless otherwise specified in the Service Level Agreement.

Key operational requirements mandate that the State retains all rights and ownership of data, which contractors may access only for normal operations, technical support, or express contractual purposes. Contractors must implement administrative, technical, and organizational security measures to safeguard data confidentiality, integrity, and availability, including encryption of all data at rest and in transit. Contractors must report Security Incidents within two days and Data Breaches within two days or per applicable law, and bear investigation, notification, and remediation costs if breaches result from failure to encrypt data. Additional requirements include Federal Bureau of Investigation background checks for all personnel, annual independent SOC 2 audits of data centers, business continuity and disaster recovery planning with annual testing, two-week advance notice for non-emergency changes and 24-hour notice for emergency changes, and secure data return or destruction upon contract termination using National Institute of Standards and Technology-approved methods with certificates of destruction provided to the State.

View the file

Other files for this state and local contract opportunity

Other files attached to ISPHN Centralized Billing OfficeBid Documents, newest first.
File Type Posted
Att K - Artificial Intelligence.docx DOCX document
Att P - Cost Report SOW.docx DOCX document
RFP 26-86529 Pre-Proposal Conference Slide Deck.pdf PDF
Att O - Centralized Billing Office SOW.docx DOCX document
Att J - Attestation Form.docx DOCX document
Att O - Centralized Billing Office Scope of work.docx DOCX document
Att A1 - IVOSB.docx DOCX document
Att C - Indiana Economic Impact Form.xls XLS spreadsheet
RFP 26-82969 Pre-Proposal Conference Slide Deck.pdf PDF
Att B1 - IOT-IaaS.docx DOCX document
Att P - Cost Report Scope of Work.docx DOCX document
Att A - MWBE.docx DOCX document
Att D - Cost Proposal.xlsx XLSX spreadsheet
Att F - Technical Proposal.docx DOCX document
Att K - Artificial Intelligence Technical Proposal Questions.docx DOCX document
Att G - Q&A Template.xlsx XLSX spreadsheet
Att H - Reference Check Form.docx DOCX document
Att I - Pre-proposal Network Form.docx DOCX document
Att M - Infrastructure Overview.docx DOCX document
Att B2 - IOT-PaaS.docx DOCX document
Att N - Resource Usage Template.xlsx XLSX spreadsheet
Att L - Cloud Questionnaire.xlsx XLSX spreadsheet
Att E - Business Proposal.docx DOCX document
Att B - Sample Contract.docx DOCX document
RFP 26-86529 Main Document.pdf PDF
Show all 25

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment B.3 State of Indiana Additional Terms and Conditions Software as a Service Engagements

DEFINITIONS

Data means all information, whether in oral, written, or electronic form, created by or in any way originating with the State, and all information that is the output of any computer processing, or other electronic manipulation, of any information that was created by or that in any way originated with the State, in the course of using and configuring the Services.

Data Breach means any actual or reasonably suspected unauthorized access to or acquisition of Encrypted Data.

Encrypted Data means Data that that is required to be encrypted under the contract and Statement of Work.

Indiana Office of Technology means the agency established by Ind. Code § 4-13.1-2-1.

Information Security Framework means the State of Indiana’s written policy and standards document governing matters affecting security and available at https://www.in.gov/iot/security/information-security-framework2/.

Security Incident means any actual or reasonably suspected unauthorized access to the contractor’s system, regardless of whether contractor is aware of a Data Breach. A Security Incident may or may not become a Data Breach.

Service(s) means that which is provided to the State by contractor pursuant to this contract and the contractors obligations under the contract.

Service Level Agreement means a written agreement between both the State and the contractor that is subject to the terms and conditions of this contract. Service Level Agreements should include: (1) the technical service level performance promises (i.e. metrics for performance and intervals for measure); (2) description of service quality; (3) identification of roles and responsibilities; (4) remedies, such as credits; and (5) an explanation of how remedies or credits are calculated and issued.

Statement of Work means the written agreement between both the State and contractor attached to and incorporated into this contract.

TERMS

1. Data Ownership: The State owns all rights, title, and interest in the Data. The contractor shall not access State user accounts or Data, except: (1) in the normal course of data center operations; (2) in response to Service or technical issues; (3) as required by the express terms of this contract, applicable Statement of Work, or applicable Service Level Agreement; or (4) at the State’s written request.

Contractor shall not collect, access, or use Data except as strictly necessary to provide Service to the State. No information regarding State’s use of the Service may be disclosed, provided, rented, or sold to any third party for any reason unless required by law or regulation or by an order of a court of competent jurisdiction. This obligation shall survive and extend beyond the term of this contract.

2. Data Protection: Protection of personal privacy and Data shall be an integral part of the business activities of the contractor to ensure there is no inappropriate or unauthorized use of Data at any time. To this end, the contractor shall safeguard the confidentiality, integrity, and availability of Data and shall comply with the following conditions:

a. The contractor shall implement and maintain appropriate administrative, technical, and organizational security measures to safeguard against unauthorized access, disclosure, or theft of Data. Contractor shall implement and maintain heightened security measures with respect to Encrypted Data. Such security measures shall be in accordance with Indiana Office of Technology practice and recognized industry practice, including but not limited to the following:

1. Information Security Framework; and

2. Indiana Office of Technology Cloud Product and Service Agreements, Standard ID: IOT-CS-SEC-010.

b. All Encrypted Data shall be subject to controlled access. Any stipulation of responsibilities shall be included in the Statement of Work and will identify specific roles and responsibilities.

c. The contractor shall encrypt all Data at rest and in transit. The State may, in the Statement of Work, identify Data it deems as that which may be publicly disclosed that is not subject to encryption. Data so designated may be maintained without encryption at rest and in transit. The level of protection and encryption for all Encrypted Data shall meet or exceed that required in the Information Security Framework.

d. At no time shall any Data or processes — that either belong to or are intended for the use of State — be copied, disclosed, or retained by the contractor or any party related to the contractor for subsequent use in any transaction that does not include the State.

e. The contractor shall not use any information collected in connection with the Services for any purpose other than fulfilling its obligations under the contract.

3. Data Location: Storage of Data at rest shall be located solely in data centers in the United States and the contractor shall provide its Services to the State and its end users solely from locations in the United States. The contractor shall not store Data on portable devices, including personal laptop and desktop computers. The contractor shall access Data remotely only as required to provide technical support. The contractor shall provide technical user support on a 24/7 basis unless specified otherwise in the Service Level Agreement.

4. Notice Regarding Security Incident or Data Breach:

a. Incident Response: contractor may need to communicate with outside parties regarding a Security Incident, which may include contacting law enforcement, fielding media inquiries, and seeking external expertise as mutually agreed upon, defined by law, or contained in the contract. Discussing Security Incidents and Data Breaches with the State must be handled on an urgent basis, as part of contractor’s communication and mitigation processes as mutually agreed upon in the Service Level Agreement, contained in the contract, and in accordance with IC 4-1-11 and IC 24-4.9 as they may apply.

b. Security Incident Reporting Requirements: The contractor shall report a Security Incident to the State-identified contact(s) as soon as possible by telephone and email, but in no case later than two (2) days after the Security Incident occurs. Notice requirements may be clarified in the Service Level Agreement and shall be construed in accordance with IC 4-1-11 and IC 24-4.9 as they may apply.

c. Data Breach Reporting Requirements: If a Data Breach occurs, the contractor shall do the following in accordance with IC 4-1-11 and IC 24-4.9 as they may apply: (1) as soon as possible notify the State-identified contact(s) by telephone and email, but in no case later than two (2) days after the Data Breach occurs unless a shorter notice period is required by applicable law; and (2) take commercially-reasonable measures to address the Data Breach in a timely manner. Notice requirements may be clarified in the Service Level Agreement. If the Data involved in the Data Breach involves protected health information, personally identifying information, social security numbers, or otherwise confidential information, other sections of this contract may apply. The requirements discussed in those sections must be met in addition to the requirements of this section.

5. Responsibilities Regarding Data Breach: This section applies when a Data Breach occurs with respect to Encrypted Data within the possession or control of the contractor.

a. The contractor shall: (1) cooperate with the State as reasonably requested by the State to investigate and resolve the Data Breach; (2) promptly implement necessary remedial measures, if necessary; and (3) document and provide to the State responsive actions taken related to the Data Breach, including any post-incident review of events and actions taken to make changes in business practices in providing the Services, if necessary.

b. Unless stipulated otherwise in the Statement of Work, if a Data Breach is a result of the contractor’s breach of its contractual obligation to encrypt Data or otherwise prevent its release as reasonably determined by the State, the contractor shall bear the costs associated with: (1) the investigation and resolution of the Data Breach; (2) notifications to individuals, regulators, or others required by federal and/or state law, or as otherwise agreed to in the Statement of Work; (3) a credit monitoring service required by federal and/or state law, or as otherwise agreed to in the Statement of Work; (4) a website or a toll-free number and call center for affected individuals required by federal and/or state law — all of which shall not amount to less than the average per-record per-person cost calculated for data breaches in the United States (in, for example, the most recent Cost of Data Breach Study: Global Analysis published by the Ponemon Institute at the time of the Data Breach); and (5) complete all corrective actions as reasonably determined by contractor based on root cause and on advice received from the Indiana Office of Technology. If the Data involved in the Data Breach involves protected health information, personally identifying information, social security numbers, or otherwise confidential information, other sections of this contract may apply. The requirements discussed in those sections must be met in addition to the requirements of this section.

6. Notification of Legal Requests: If the contractor is requested or required by deposition or written questions, interrogatories, requests for production of documents, subpoena, investigative demand or similar process to disclose any Data, the contractor will provide prompt written notice to the State and will cooperate with the State’s efforts to obtain an appropriate protective order or other reasonable assurance that such Data will be accorded confidential treatment that the State may deem necessary.

7. Termination and Suspension of Service:

a. In the event of a termination of the contract, the contractor shall implement an orderly return of Data in a mutually agreeable and readable format. The contractor shall provide to the State any information that may be required to determine relationships between data rows or columns. It shall do so at a time agreed to by the parties or shall allow the State to extract its Data. Upon confirmation from the State, the contractor shall securely dispose of the Data.

b. During any period of Service suspension, the contractor shall not take any action that results in the erasure of Data or otherwise dispose of any of the Data.

c. In the event of termination of any Services or contract in its entirety, the contractor shall not take any action that results in the erasure of Data until such time as the State provides notice to contractor of confirmation of successful transmission of all Data to the State or to the State’s chosen vendor.

During this period, the contractor shall make reasonable efforts to facilitate the successful transmission of Data. The contractor shall be reimbursed for all phase-out costs (i.e., costs incurred within the agreed period after contract expiration or termination that result from the transfer of Data or other information to the State). A reimbursement rate shall be agreed upon by the parties during contract negotiation and shall be memorialized in the Statement of Work. After such period, the contractor shall have no obligation to maintain or provide any Data and shall thereafter, unless legally prohibited, delete all Data in its systems or otherwise in its possession or under its control. The State shall be entitled to any post-termination assistance generally made available with respect to the Services, unless a unique data retrieval arrangement has been established as part of a Service Level Agreement.

d. Upon termination of the Services or the contract in its entirety, contractor shall, within 30 days of receipt of the State’s notice given in 7(c) above, securely dispose of all Data in all of its forms, including but not limited to, CD/DVD, backup tape, and paper. Data shall be permanently deleted and shall not be recoverable, according to National Institute of Standards and Technology (NIST)-approved methods. Certificates of destruction shall be provided to the State upon completion.

8. Background Checks: The contractor shall conduct a Federal Bureau of Investigation Identity History Summary Check for each employee involved in provision of Services: (1) upon commencement of the contract; (2) prior to hiring a new employee; and (3) for any employee upon the request of the State. The contractor shall not utilize any staff, including subcontractors, to fulfill the obligations of the contract who have been convicted of any crime of dishonesty, including but not limited to criminal fraud, or otherwise convicted of any felony or misdemeanor offense for which incarceration for up to one (1) year is an authorized penalty. The contractor shall promote and maintain an awareness of the importance of securing the State’s information among the contractor’s employees, subcontractors, and agents. If any individual providing Services under the contract is not acceptable to the State, in its sole opinion, as a result of the background or criminal history investigation, the State, in its sole option shall have the right to either: (1) request immediate replacement of the individual; or (2) immediately terminate the contract, related Statement of Work, and related Service Level Agreement.

9. Access to Security Logs and Reports: The contractor shall provide to the State reports on a schedule and in a format specified in the Service Level Agreement as agreed to by both the contractor and the State. Reports shall include latency statistics, user access, user access IP address, user access history, and security logs for all Data. The State’s audit requirements shall, if applicable, be defined in the Statement of Work.

10. Contract Audit: The contractor shall allow the State to audit conformance to the contract terms. The State may perform this audit or contract with a third party at its discretion and at the State’s expense.

11. Data Center Audit: The contractor shall perform an annual independent audit of its data center(s) where Data, State applications, or other State information is maintained. The contractor shall perform this independent audit at its expense and shall, upon completion, provide an unredacted version of the complete audit report to the State. (The contractor may redact its proprietary information from the unredacted version, however.) A Service Organization Control (SOC) 2 audit report or equivalent approved by the Indiana Office of Technology sets the minimum level of a third-party audit.

The State may perform an annual audit of contractor’s data center(s) where Data, State applications, or other State information is maintained. The audit may take place onsite or remotely, at the State’s discretion. The State shall provide to contractor thirty (30) days’ advance notice prior to the audit. The contractor will make reasonable efforts to facilitate the audit and will make available to the State members of its staff during the audit. The State may contract with a third party to conduct the audit at its discretion and at the State’s expense. If the contractor maintains Data, State applications, or other State information at multiple data centers, the State may perform an annual audit of each data center.

The parties agree that any documents provided to the State under this paragraph shall be deemed a trade secret of contractor and is deemed administrative or technical information that would jeopardize a record keeping or security system, and shall be exempt from disclosure under the Indiana Access to Public Records Act, IC 5-14-3.

12. Change Control and Advance Notice: The contractor shall give notice to the State for change management requests. Contractor shall provide notice to the State regarding change management requests that do not constitute an emergency change management request at least two (2) weeks in advance of implementation. Contractor shall provide notice to the State regarding emergency change management requests no more than twenty-four (24) hours after implementation.

Contractor shall make updates and upgrades available to the State at no additional cost when contractor makes such updates and upgrades generally available to its users. No update, upgrade, or other change to the Service may decrease the Service’s functionality, adversely affect State’s use of or access to the Service, or increase the cost of the Service to the State.

13. Security: The contractor shall, on an annual basis, disclose its non-proprietary system security plans or security processes and technical limitations to the State such that adequate protection and flexibility can be attained between the State and the contractor. For example: virus checking and port sniffing. The State and the contractor shall share information sufficient to understand each other’s roles and responsibilities. The contractor shall take into consideration feedback from the Indiana Office of Technology with respect to the contractor’s system security plans.

The parties agree that any documents provided to the State under this paragraph shall be deemed a trade secret of contractor and is deemed administrative or technical information that would jeopardize a record keeping or security system, and shall be exempt from disclosure under the Indiana Access to Public Records Act, IC 5-14-3.

14. Non-disclosure and Separation of Duties: The contractor shall enforce role-based access control, separation of job duties, require commercially-reasonable nondisclosure agreements, and limit staff knowledge of Data to that which is absolutely necessary to perform job duties. The contractor shall annually provide to the State a list of individuals that have access to the Data and/or the ability to service the systems that maintain the Data.

15. Import and Export of Data: The State shall have the ability to import or export Data in piecemeal or in entirety at its discretion, with reasonable assistance provided by the contractor, at any time during the term of contract. This includes the ability for the State to import or export Data to/from other parties at the State’s sole discretion. Contractor shall specify in the Statement of Work if the State is required to provide its’ own tools for this purpose, including the optional purchase of contractor’s tools if contractor’s applications are not able to provide this functionality directly.

16. Responsibilities and Uptime Guarantee: The contractor shall be responsible for the acquisition and operation of all hardware, software, and network support related to the Services being provided. The technical and professional activities required for establishing, managing, and maintaining the environments are the responsibilities of the contractor. Subject to the Service Level Agreement, the Services shall be available to the State at all times. The contractor shall allow the State to access and use the Service to perform synthetic transaction performance testing.

The contractor shall investigate and provide to the State a detailed incident report regarding any unplanned Service interruptions or outages. The State may terminate the contract for cause if, at its sole discretion, it determines that the frequency of contractor-preventable outages is sufficient to warrant termination.

17. Subcontractor Disclosure: Contractor shall identify all of its strategic business partners related to Services, including but not limited to all subcontractors or other entities or individuals who may be a party to a joint venture or similar agreement with the contractor, and who may be involved in any application development and/or operations.

The contractor shall be responsible for the acts and omissions of its subcontractors, strategic business partners, or other entities or individuals who provide or are involved in the provision of Services.

18. Business Continuity and Disaster Recovery: The State’s recovery time objective shall be defined in the Service Level Agreement. The contractor shall ensure that the State’s recovery time objective has been met and tested as detailed in the Service Level Agreement. The contractor shall annually provide to the State a business continuity and disaster recovery plan which details how the State’s recovery time objective has been met and tested. The parties agree that any documents provided to the State under this paragraph shall be deemed administrative or technical information that would jeopardize a record keeping or security system, and shall be exempt from disclosure under the Indiana Access to Public Records Act, IC 5-14-3. The contractor shall work with the State to perform an annual disaster recovery test and take action to correct any issues detected during the test in a time frame mutually agreed upon between the contractor and the State in the Service Level Agreement.

The State’s Data shall be maintained in accordance with the applicable State records retention requirement, as determined by the State. The contractor shall annually provide to the State a resource utilization assessment detailing the Data maintained by the contractor. This report shall include the volume of Data, the file formats, and other content classifications as determined by the State.

19. Compliance with Accessibility Standards: The contractor shall comply with and adhere to Accessibility Standards of Section 508 Amendment to the Rehabilitation Act of 1973, or any other state laws or administrative regulations identified by the State.

20. State Additional Terms and Conditions Revision Declaration: The clauses in this Exhibit have not been altered, modified, changed, or deleted in any way except for the following clauses which are named below:_____________________________________________

State of Indiana Additional Terms and Conditions Software as a Service Engagements Revised 3/28/2017

File details come from the government source that posted it. Updated .