Att L - Cloud Questionnaire.xlsx

XLSX spreadsheet 51 KB Posted

Attached to
ISPHN Centralized Billing OfficeBid Documents State and local contract opportunity
Solicitation number
RFP 26-86529
Issued by
Indiana

About this file

This document is a Cloud Questionnaire attachment (Attachment L) to RFP 26-86529 for the ISPHN Centralized Billing Office issued by the State of Indiana Office of Technology. The questionnaire is mandatory for all respondents proposing cloud-based solutions and serves as an evaluation tool to assess the alignment of vendor products and services with the State of Indiana's required security controls. The document does not specify response dates, due dates, bidder conferences, site visits, award dates, or contract terms, as it functions as a technical assessment instrument rather than a standalone solicitation notice. Respondents must complete this comprehensive questionnaire to demonstrate their cloud solution's compliance with Indiana's security and operational requirements.

The questionnaire addresses security controls mapped to NIST 800-53 standards and covers critical areas including cloud classification and delivery models, access control policies, account management, audit and accountability capabilities, incident response procedures, encryption methodologies, data protection measures, and system and information integrity requirements. Vendors must provide detailed responses regarding their ability to support government-required security postures, such as data residency within the continental United States, multi-factor authentication, penetration testing, vulnerability management, malware protection, encryption at rest and in transit, and secure data deletion. The assessment also evaluates organizational capabilities in areas such as business continuity planning, physical security controls, identity management, audit reporting, and API interoperability standards. All assessment responses provided by vendors are considered confidential trade secrets and protected from public disclosure under Indiana Code 5-14-3-4, as they are intended solely for the State's evaluation of cloud solution security alignment.

View the file

Other files for this state and local contract opportunity

Other files attached to ISPHN Centralized Billing OfficeBid Documents, newest first.
File Type Posted
RFP 26-86529 Pre-Proposal Conference Slide Deck.pdf PDF
Att O - Centralized Billing Office SOW.docx DOCX document
Att K - Artificial Intelligence.docx DOCX document
Att P - Cost Report SOW.docx DOCX document
Att B2 - IOT-PaaS.docx DOCX document
Att N - Resource Usage Template.xlsx XLSX spreadsheet
Att E - Business Proposal.docx DOCX document
Att B - Sample Contract.docx DOCX document
RFP 26-86529 Main Document.pdf PDF
Att A - MWBE.docx DOCX document
Att D - Cost Proposal.xlsx XLSX spreadsheet
Att F - Technical Proposal.docx DOCX document
Att K - Artificial Intelligence Technical Proposal Questions.docx DOCX document
Att G - Q&A Template.xlsx XLSX spreadsheet
Att H - Reference Check Form.docx DOCX document
Att I - Pre-proposal Network Form.docx DOCX document
Att M - Infrastructure Overview.docx DOCX document
Att J - Attestation Form.docx DOCX document
Att O - Centralized Billing Office Scope of work.docx DOCX document
Att A1 - IVOSB.docx DOCX document
Att C - Indiana Economic Impact Form.xls XLS spreadsheet
Att B3 - IOT-SaaS.docx DOCX document
RFP 26-82969 Pre-Proposal Conference Slide Deck.pdf PDF
Att B1 - IOT-IaaS.docx DOCX document
Att P - Cost Report Scope of Work.docx DOCX document
Show all 25

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Instructions

RFP 26-86529: ISPHN Centralized Billing Office
Attachment L: Cloud Questionnaire
Instructions
I. Respondents with cloud-based solutions will need to complete this questionnaire.

II. CONFIDENTIAL: Any “assessment responses” contained within this questionnaire were provided so that the Indiana Office of Technology would be able to evaluate the extent to which a particular product or service aligns with the State of Indiana’s required security controls. This information is presumed to contain trade secrets whose public disclosure would have the effect of jeopardizing a security system. It is not to be disclosed publicly, under Ind. Code §§ 5-14-3-4(a)(4) and (b)(10), unless disclosure is required by law.

Cloud Questionnaire Cloud Questionnaire

NISTNISTProvider:
IOT Mapping Doc for Cloud SolutionCGIDCID800-53 MappingSecurity ControlControl SpecificationAssessment QuestionAssessment Response
FamilyYesNoN/AExplanation of response
Cloud Classification & ConfigurationCCC-1CCC-1.0EC -1Ensures appropriate information security guards are established.Is the cloud solution you are proposing a Software as a Service, Platform as a Service, or Infrastructure as a Service Delivery Model
Cloud Classification & ConfigurationCCC-2CCC-2EC - 2Establishing, monitoring, and operating IT systems in a manner consistent with IOT Information Security policies and standardsAre you offering Public, Private or government cloud? Please describe the solution support model.
Access Control: Policies & ProceduresACP-1ACP-1.1AC-1TechnicalDevelops, documents, and disseminates to all organization personnel, contractors, and service providers with a responsibility to implement access controls:Does the provider have access control policies and procedures that are reviewed and/or updated at least annually or required due to environmental changes?
Access Control - Account ManagementACP-2ACP-2.1AC-2TechnicalUser access policies and procedures shall be established, and supporting business processes and technical measures implemented, for restricting user access as per defined segregation of duties to address business risks associated with a user-role conflict of interest.Does the solution have the capability to identify and select the following types of accounts: Individual, group, System, Service, Application, Guest/anonymous and temporary?
ACP-2.2TechnicalDoes the provider have the capability to segment and identify administrative accounts by tenant?
ACP-2.3TechnicalAre controls in place to prevent unauthorized access to your application, program or object source code, and assure it is restricted to authorized personnel only?
ACP-2.4TechnicalDoes provider document how access to tenant data is granted and approved?
ACP-2.5TechnicalIs timely deprovisioning, revocation or modification of user access to the organizations systems, information assets and data implemented upon any change in status of employees, contractors, customers, business partners or involved third parties?
ACP-2.6TechnicalDo you provide tenants with documentation on how segregation of duties within proposed cloud service offering are maintained? Please provide copy of procedure(s)
ACP-2.7TechnicalControl Enhancements for Sensitive Systems Removal of Temporary/Emergency Accounts.Does the provider or solution automatically terminate temporary and emergency accounts after a predetermined period which is not to exceed 30-days in accordance with sensitivity and risk? Please provide copy of procedure(s)
Do you provide open encryption methodologies (3.4ES, AES, etc.) to tenants in order for them to protect their data if it is required to move through public networks (e.g., the Internet)?
Do you require at least annual certification of entitlements for all system users and administrators (exclusive of users maintained by your tenants)?
If users are found to have inappropriate entitlements, are all remediation and certification actions recorded/documented?

If different actions are taken for Admin and User Accounts, please provide information on both.

ACP-2.8TechnicalDisable Inactive AccountsDoes the provider or solution automatically disable inactive accounts after 90 consecutive days of non-use?
ACP-2.9TechnicalInactivity logoutDoes the solution logout users automatically when the session inactivity time has exceeded 30 minutes?
Access Control - Access EnforcementACP-3ACP-3.1AC-3TechnicalThe information system enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies.Are policies and procedures established for labeling, handling and the security of data and objects that contain data?
Access Control - Separation of DutiesACP-4ACP-4.1AC-4TechnicalUser access policies and procedures shall be established, and supporting business processes and technical measures implemented, for restricting user access as per defined segregation of duties to address business risks associated with a user-role conflict of interest.Are controls in place to prevent unauthorized access to your application, program or object source code, and assure it is restricted to authorized personnel only? Provide documentation on controls in place to prevent unauthorized access.
Are controls in place to prevent unauthorized access to tenant application, program or object source code, and assure it is restricted to authorized personnel only? Provide documentation on controls in place to prevent unauthorized access.
Access Control - Least PrivilegeACP-5ACP-5.1AC-5TechnicalThe organization employs the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions.Do you document how you grant and approve access to tenant data? Please procedure for doing this.
ACP-5.2TechnicalDo you have a method of aligning provider and tenant data classification methodologies for access control purposes?
ACP-5.3TechnicalWill you share user entitlement remediation and certification reports with your tenants, if inappropriate access may have been allowed to tenant data?
Access Control - Unsuccessful Logon AttemptsACP-6ACP-6.1AC-6TechnicalEnforces a limit of 3 consecutive invalid logon attempts by a user during a 15 minute period;Do you allow tenants/customers to define password and account lockout policies for their accounts? Provide system password requirements and policies.
ACP-6.2TechnicalAutomatically locks the account/node for a minimum of a 30 minute period when the maximum number of unsuccessful attempts is exceeded.Do you support password (minimum length, age, history, complexity) and account lockout (lockout threshold, lockout duration) policy enforcement? Please provide policies for both standard and admin accounts.
ACP-6.3TechnicalPassword Policy must meet or exceed minimum password policies.Do you support tenant defined password complexity policies? Specify your password length and complexity requirements in the notes field
Awareness and Training - Policy and ProceduresATP-1ATP-1.1AT-1

AT-2

AT-3

AT-4OperationalEmployment agreements shall incorporate provisions and/or terms for adherence to established information governance and security policies and must be signed by newly hired or on-boarded workforce personnel (e.g., full or part-time employee or contingent staff) prior to granting workforce personnel user access to corporate facilities, resources, and assets.Do you specifically train your employees regarding their specific role and the information security controls they must fulfill?
ATP-1.2OperationalDo you document employee acknowledgment of training they have completed?
ATP-1.3OperationalAre all personnel required to sign NDA or Confidentiality Agreements as a condition of employment to protect customer/tenant information?
ATP-1.4OperationalIs successful and timely completion of the training program considered a prerequisite for acquiring and maintaining access to sensitive systems?
ATP-1.5OperationalAre personnel trained and provided with customer defined awareness programs at least once a year?
Audit and Control -Audit and AccountabilityAUC-1AUC-1.1AU-1TechnicalAudit plans shall be developed and maintained to address business process disruptions. Auditing plans shall focus on reviewing the effectiveness of the implementation of security operations. All audit activities must be agreed upon prior to executing any audits.Do you produce audit assertions using a structured, industry accepted format (e.g., Cloud Audit/A6 URI Ontology, Cloud Trust, SCAP/CYBEX, GRC XML, ISACA's Cloud Computing Management Audit/Assurance Program, etc.)?
AUC-1.2TechnicalAre your audits performed at least annually? if no, please describe in the comments section.
AUC-1.3TechnicalIndependent reviews and assessments shall be performed at least annually to ensure that the organization addresses nonconformities of established policies, standards, procedures, and compliance obligations.Do you allow tenants to view your SOC2/ISO 27001 or similar third-party audit or certification reports?
AUC-1.4TechnicalDo you conduct network penetration tests of your cloud service infrastructure regularly as prescribed by industry best practices and guidance?
AUC-1.5TechnicalDo you conduct application penetration tests of your cloud infrastructure regularly as prescribed by industry best practices and guidance?
AUC-1.6TechnicalAre the results of the penetration tests available to tenants at their request?
AUC-1.7TechnicalAre the results of internal and external audits available to tenants at their request?
Audit and Control:
Audit EventsAUC-2AUC-2.1AU-2TechnicalAn event is any observable occurrence in an organizational information system. Organizations identify audit events as those events which are significant and relevant to the security of information systems and the environments in which those systems operate in order to meet specific and ongoing audit needs.Is the solution capable of auditing the following events? Successful and unsuccessful account logon events, account management events, object access, policy change, privilege functions, process tracking, and system events.
AUC-2.2TechnicalAudit events on Web ApplicationsIs the solution capable of auditing the following events, for Web applications? All administrator activity, authentication checks, authorization checks, data deletions, data access, data changes, and permission changes.
Audit and Control:
Audit Review, Analysis, and ReportingAUC-3AUC-3.1AU-6TechnicalAudit Review, Analysis, and ReportingIs the solution capable of automated mechanisms to centrally review, analyze and correlate audit and log records from multiple components of the solution to support organizational processes for investigation, alerting and response to suspicious activities? is the information available to your tenants?
Control Assessment and AuthorizationCAA-1CAA-1.1CA-1

CA-3

CA-7 Management Risk assessments associated with data governance requirements shall be conducted at planned intervals and shall consider the following:

• Awareness of where sensitive data is stored and transmitted across applications, databases, servers, and network infrastructure

• Compliance with defined retention periods and end-of-life disposal requirements

• Data classification and protection from unauthorized use, access, loss, destruction, and falsificationDo you provide security control health data in order to allow tenants to implement industry standard Continuous Monitoring (which allows continual tenant validation of your physical and logical control status)?
CAA-1.2ManagementDo you conduct risk assessments associated with data governance requirements at least once a year?
Configuration Management - Policy and ProceduresCMP-1CMP-1.1CM-1OperationalOrganization shall follow a defined quality change control and testing process (e.g., ITIL Service Management) with established baselines, testing, and release standards which focus on system availability, confidentiality, and integrity of systems and servicesDo you provide your tenants with documentation that describes your quality assurance process?
CMP-1.2OperationalIs documentation describing known issues with certain products/services available?
CMP-1.3OperationalAre there policies and procedures in place to triage and remedy reported bugs and security vulnerabilities for product and service offerings? Are tenants provided with documentation on remedied issues?
CMP-1.4OperationalAre mechanisms in place to ensure that all debugging and test code elements are removed from released software versions? Are there technical controls in place to prevent?
CMP-2CMP-1.1CM-2

CM-3

CM-7OperationalThe organization develops, documents, and maintains under configuration control, a current baseline configuration of the information system.Do you have a capability to continuously monitor and report the compliance of your infrastructure against your information security baselines?
CMP-1.2OperationalDo you have controls in place to restrict and monitor the installation of unauthorized software onto your systems?
CMP-1.3OperationalCan you provide evidence that the proposed solution adheres to a security baseline, which is based on least functionality?
CMP-1.4OperationalAre all changes to proposed solution authorized according to change management policies?
Contingency Planning - Information System backupCP-1CP-1.1CP-2

CP4

CP-6

CP-7

CP-9

CP-10 Operational A consistent unified framework for business continuity planning and plan development shall be established, documented, and adopted to ensure all business continuity plans are consistent in addressing priorities for testing, maintenance, and information security requirements. Requirements for business continuity plans include the following:

• Defined purpose and scope, aligned with relevant dependencies

• Accessible to and understood by those who will use them

• Owned by a named person(s) who is responsible for their review, update, and approval

• Defined lines of communication, roles, and responsibilities

• Detailed recovery procedures, manual work-around, and reference information

• Method for plan invocationDo you provide tenants with geographically resilient hosting options?
CP-1.2OperationalDo you provide tenants with infrastructure service failover capability to other providers?
CP-1.3OperationalAre business continuity plans subject to test at planned intervals or upon significant organizational or environmental changes to ensure continuing effectiveness?
CP-1.4OperationalCan the solution provide and maintain a backup of SOI data that can be recovered in an orderly and timely manner within a predefined frequency consistent with recovery time and recovery point objectives?
CP-1.5OperationalCan the solution store a backup of SOI data, at least daily, in an off-site “hardened” facility, located within the continental United States, maintaining the security of SOI data?
CP-1.6OperationalCan the solution partition, in aggregate for this proposal, all SOI data submitted into the solution by the data owner in such a manner that it will not be impacted or forfeited due to E-discovery, search and seizure or other actions by third parties obtaining or attempting to obtain records, information or SOI data for reasons or activities that are not directly related to the business of the data owner?
Identification and Authentication; Organizational UsersIDA-1IDA-1.1IA-1TechnicalVendor should have An identification and authentication policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and complianceDoes your management provision the authorization and restrictions for user access (e.g., employees, contractors, customers (tenants), business partners and/or suppliers) prior to their access to data and any owned or managed (physical and virtual) applications, infrastructure systems and network components?
IDA-1.2Technical
IDA-1.3TechnicalProcedures to facilitate the implementation of the identification and authentication policy and associated identification and authentication controlsDo you require at least annual updates and reviews of your access policies for all system users and administrators (exclusive of users maintained by your tenants)?
Identification and Authentication; Authenticator ManagementIDA-2IDA-1.1IA-2

IA-5

Technical Internal agency or customer (tenant) user account credentials shall be restricted as per the following, ensuring appropriate identity, entitlement, and access management and in accordance with established policies and procedures:

• Identity trust verification and service-to-service application (API) and information processing interoperability (e.g., SSO and Federation)

• Account credential lifecycle management from instantiation through revocation

• Account credential and/or identity store minimization or re-use when feasible

• Adherence to industry acceptable and/or regulatory compliant authentication, authorization, and accounting (AAA) rules (e.g., strong/multi-factor, expireable, non-shared authentication secrets)Do you support use of, or integration with, existing customer-based Single Sign On (SSO) solutions to your service?
IDA-1.2TechnicalDo you support identity federation standards (SAML, SPML, WS-Federation, etc.) as a means of authenticating/authorizing users?
IDA-1.3TechnicalDo you have an identity management system (enabling classification of data for a tenant) in place to enable both role-based and context-based entitlement to data?
IDA-1.4TechnicalDo you provide tenants with strong (multifactor) authentication options (digital certs, tokens, biometrics, etc.) for user access?
IDA-1.5TechnicalDo you allow tenants to use third-party identity assurance services?
IDA-1.6TechnicalDo you support password (minimum length, age, history, complexity) and account lockout (lockout threshold, lockout duration) policy enforcement?
IDA-1.7TechnicalDo you support the ability to force password changes upon first logon?
IDA-1.8TechnicalDo you have mechanisms in place for unlocking accounts that have been locked out (e.g., self-service via email, defined challenge questions, manual unlock)?
Incident ResponseIR-1IR-1.1IR-4

IR-5

IR-6

OperationalIdentify immediate mitigation procedures, including specific instructions, based on information security incident categorization level, on whether or not to shut down or disconnect affected IT systems. Establish procedures for information security incident investigation, preservation of evidence, and forensic analysis.Do you have a documented security incident response plan?
IR-1.2OperationalDo you integrate customized tenant requirements into your security incident response plans?
IR-1.3OperationalDo you publish a roles and responsibilities document specifying what you vs. your tenants are responsible for during security incidents?
IR-1.4OperationalHave you tested your security incident response plans in the last year?
IR-1.5OperationalThe organization tracks and documents information system security incidents.Do you monitor and quantify the types, volumes and impacts on all information security incidents?
IR-1.6OperationalWill you share statistical information for security incident data with your tenants upon request?
IR-1.7OperationalRequires personnel to report suspected security incidents to the organizational incident response capability within 24 hours from when the agency discovered or should have discovered their occurrence; and Reports security incident information to designated authorities.Do you have a defined and documented incident notification process for reporting suspected security incidents within 24 hours?
IR-1.8OperationalDoes your security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting?
IR-1.9OperationalDo you maintain liaisons and points of contact with local authorities in accordance with contracts and appropriate regulations?
IR-1.10OperationalDo you enforce and attest to tenant data separation when producing data in response to legal subpoenas?
Media Protection Policy and Procedures:
Media SanitizationMPP-1MPP1.1MP-6OperationalPolicies and procedures shall be established with supporting business processes and technical measures implemented for the secure disposal and complete removal of data from all storage media, ensuring data is not recoverable by any computer forensic means.Do you support secure deletion (e.g., degaussing/cryptographic wiping) of archived and backed-up data as determined by the tenant?
MPP1.2OperationalDoes the provider distroy all information systems media that cannot be sanitized?
Physical and Environmental Protection: Physical Access AuthorizationsPEP-1PEP-1.1PE-2(1)
PE-2(3)OperationalThe organization authorizes physical access to the facility where the information system resides based on position or role.Can you provide a published procedure for exiting the service arrangement, including assurance to sanitize all computing resources of tenant data once a customer has exited your environment or has vacated a resource?
Physical and Environmental Protection:
Physical Access ControlPEP-2PEP-2.1PE-3OperationalIngress and egress points such as service areas and other points where unauthorized personnel may enter the premises shall be monitored, controlled and, if possible, isolated from data storage and processing facilities to prevent unauthorized data corruption, compromise, and loss.Do you restrict physical access to information assets and functions by users and support personnel?
PEP-2.2OperationalAre ingress and egress points, such as service areas and other points where unauthorized personnel may enter the premises, monitored, controlled and isolated from data storage and process?
Physical and Environmental Protection:
Physical LocationPEP-3PEP-3.1PE-18OperationalAll information system components and services remain within the continental United States.

All physical components associated with an information system or service classified as sensitive with respect to confidentiality or integrity must be housed within the same storage location dedicated for the exclusive use of the organization and are clearly marked.

Each hypervisor can only host one tier of the application architecture and no hypervisor may host the application interface and the data storage component for any information system, even if the components in question do not interact within the same information system.Do you allow tenants to define acceptable geographical locations for data routing or resource instantiation?
PEP-3.2OperationalCan you provide the physical geographical location of the storage in advance for a tenants data?
PEP-3.3OperationalCan you provide the physical geographical location of a tenants data upon request?
PEP-3.4OperationalCan you ensure that data does not migrate beyond a defined geographical residency?
PEP-3.5OperationalDo you have the capability to restrict the storage of customer data to specific countries or geographic locations?
PEP-3.6OperationalDoes the solution have the capability to set affinity on tiered systems, no one hypervisor can host the application and the data storage?
System and Information Integrity:
Vulnerability / Patch Management (Flaw Remediation)SII-1SII-1.1SI-2

RA-5

RA-5-COV

OperationalPolicies and procedures shall be established, and supporting processes and technical measures implemented, for timely detection of vulnerabilities within organizationally-owned or managed applications, infrastructure network and system components (e.g., network vulnerability assessment, penetration testing) to ensure the efficiency of implemented security controls. A risk-based model for prioritizing remediation of identified vulnerabilities shall be used. Changes shall be managed through a change management process for all vendor-supplied patches, configuration changes, or changes to the organization's internally developed software. Upon request, the provider informs customer (tenant) of policies and procedures and identified weaknesses especially if customer (tenant) data is used as part the service and/or customer (tenant) has some shared responsibility over implementation of control.Do you conduct network-layer vulnerability scans regularly as prescribed by industry best practices? Provide the frequency.
IS-20SII-1.2OperationalDo you conduct application-layer vulnerability scans regularly as prescribed by industry best practices? Provide the frequency
IS-20SII-1.3OperationalDo you conduct local operating system-layer vulnerability scans regularly as prescribed by industry best practices? Provide the frequency
IS-20SII-1.4OperationalWill you make the results of vulnerability scans available to tenants at their request?
IS-20SII-1.5OperationalDo you have a capability to rapidly patch vulnerabilities across all of your computing devices, applications and systems?
IS-20SII-1.6OperationalWill you provide your risk-based systems patching time frames to your tenants upon request?
System and Information Integrity:
Malicious Code protectionSII-2SII-2.1SI-3OperationalPolicies and procedures shall be established, and supporting business processes and technical measures implemented, to prevent the execution of malware on organizationally-owned or managed user end-point devices (i.e., issued workstations, laptops, and mobile devices) and IT infrastructure network and systems components.Does the provider ensure that they will utilize industry standard malware protection, incorporating both signature and non-signature-based detection mechanisms, on all systems with access to SOI data?
SII-2.1OperationalDoes the provider ensure that malware protection will be centrally managed and receive regular automatic updates to malicious code protection mechanisms and data files from the software vendor?
System and Communications Protection:
Boundary ProtectionSCP-1SCP-01.1SC-7TechnicalPolicies and procedures shall be established, and supporting business processes and technical measures implemented, for the use of encryption protocols for protection of sensitive data in storage (e.g., databases) and data in transmission (e.g., system interfaces, over public networks, and electronic messaging) as per applicable legal, statutory, and regulatory compliance obligations.Does the provider ensure that the solution will utilize industry standard firewalls regulating all data entering the internal data network from any external source which will enforce secure connections between internal and external systems and will permit only authorized data to pass through?
SCP-01.2TechnicalDoes the provider ensure that external connections incorporated into the solution have appropriate security controls including industry standard intrusion detection and countermeasures that will detect and terminate any unauthorized activity prior to entering the firewall maintained by offeror?
System and Communications Protection;
EncryptionSCP-2SCP-02.1SC-1

SC-8

SC-23

SC-28TechnicalDo you encrypt tenant data at rest (on disk/storage) within your environment?
SCP-02.2TechnicalDo you use encryption for storing and transmitting email attachments?
IS-18SCP-02.3TechnicalDo you leverage encryption to protect data and virtual machine images during transport across and between networks and hypervisor instances?
SCP-02.4TechnicalDo you support tenant-generated encryption keys or permit tenants to encrypt data to an identity without access to a public key certificate (e.g., identity-based encryption)?
SCP-02.5TechnicalDo you have documentation establishing and defining your encryption management policies, procedures and guidelines?
Systems and Communication Protection; Cryptographic Key Establishment and Management
SCP-3SCP-3.1SC-12

SC-13

TechnicalThe organization establishes and manages cryptographic keys for required cryptography employed within the information system in accordance with the organization-defined requirements for key generation, distribution, storage, access, and destruction. Platform and data appropriate encryption (e.g., AES-256) in open/validated formats and standard algorithms shall be required. Keys shall not be stored in the cloud (i.e. at the cloud provider in question), but maintained by the cloud consumer or trusted key management provider. Key management and key usage shall be separated duties.Do you have platform and data appropriate encryption that uses open/validated formats and standard algorithms?
SCP-3.2TechnicalDo you support encryption keys being solely maintained by the cloud consumer or a trusted key management provider?
SCP-3.3TechnicalDo you store encryption keys in the cloud?
SCP-3.4TechnicalDo you have separate key management and key usage duties?
Data Security & Information Lifecycle Management
Nonproduction DataDS-01DS-01.1SA-11ManagementProduction data shall not be replicated or used in non-production environments. Any use of customer data in non-production environments requires explicit, documented approval from all customers whose data is affected, and must comply with all legal and regulatory requirements for scrubbing of sensitive data elements.Do you have procedures in place to ensure production data shall not be replicated or used in non-production environments?
IOT Governance - Portability Requirements
Interoperability & Portability
APIsIPY-01IPY-01The provider shall use open and published APIs to ensure support for interoperability between components and to facilitate migrating applications.Do you publish a list of all APIs available in the service and indicate which are standard and which are customized?
Interoperability & Portability
Data RequestIPY-02IPY-02All structured and unstructured data shall be available to the customer and provided to them upon request in an industry-standard format (e.g., .doc, .xls, .pdf, logs, and flat files).Is customer data (Structured & Unstructured) available on request in an industry-standard format (e.g., .doc, .xls, or .pdf)?
Interoperability & Portability
Policy & LegalIPY-03IPY-03.1Policies, procedures, and mutually-agreed upon provisions and/or terms shall be established to satisfy customer (tenant) requirements for service-to-service application (API) and information processing interoperability, and portability for application development and information exchange, usage, and integrity persistence.Do you provide policies and procedures (i.e. service level agreements) governing the use of APIs for interoperability between your service and third-party applications?
IPY-03.2Do you provide policies and procedures (i.e. service level agreements) governing the migration of application data to and from your service?
Interoperability & Portability
Standardized Network ProtocolsIPY-04IPY-04.1The provider shall use secure (e.g., non-clear text and authenticated) standardized network protocols for the import and export of data and to manage the service, and shall make available a document to consumers (tenants) detailing the relevant interoperability and portability standards that are involved.Can data import, data export and service management be conducted over secure (e.g., non-clear text and authenticated), industry accepted standardized network protocols?
IPY-04.2Do you provide consumers (tenants) with documentation detailing the relevant interoperability and portability network protocol standards that are involved?
Interoperability & Portability
VirtualizationIPY-05IPY-05.1The provider shall use an industry-recognized virtualization platform and standard virtualization formats (e.g., OVF) to help ensure interoperability, and shall have documented custom changes made to any hypervisor in use, and all solution-specific virtualization hooks, available for customer review.Do you use an industry-recognized virtualization platform and standard virtualization formats (e.g.., OVF) to help ensure interoperability?
IPY-05.2Do you have documented custom changes made to any hypervisor in use, and all solution-specific virtualization hooks available for customer review?
Security Framework - Organizational Security FrameworkSF -01SF-01.1Design, acquisition, implementation, configuration, modification, and management of infrastructure and software are consistent with defined processing integrity and related security policies.What Security Framework do you follow (.i.e. NIST, , ISO/IEC 27001, etc…,)?

image1.png

File details come from the government source that posted it. Updated .