Att4_Cloud Questionnaire .pdf

PDF 190 KB Posted

Attached to
Encyclopedia Databases Federal contract opportunity
Solicitation number
HE125425QE003
Issued by
Department of Defense Education Activity

About this file

This document is a DoDEA Cloud Questionnaire that must be completed by vendors offering cloud-based solutions to the Department of Defense Education Activity (DoDEA). The questionnaire addresses various aspects of the vendors' cloud services, including data collection and distribution, system management and security, data storage and retention, and development/change management processes. Key details include:

The questionnaire requires vendors to provide URLs for their cloud resources and indicate if DoDEA needs to configure any software, computers, or firewalls. It also asks about the handling of personally identifiable information (PII) and sensitive data, including whether data is encrypted, transferred to third parties, and protected under relevant federal privacy laws. Vendors must describe their security practices, such as penetration testing, vulnerability scanning, and secure facilities. Other questions cover data retention, access controls, incident response, and use of live data in non-production environments. The questionnaire is part of the evaluation process for the referenced "Encyclopedia Databases" federal contract opportunity (Solicitation Number HE125425QE003) from the Department of Defense Education Activity.

View the file

Other files for this federal contract opportunity

Other files attached to Encyclopedia Databases, newest first.
File Type Posted
Att2_PPQ .docx DOCX document
Att7_52.212-2 Adn .pdf PDF
Att5_Terms of Use.docx DOCX document
25QE003_SOL_311024.pdf PDF
Att1_PWS .pdf PDF
Att6_52.212-1 Adn .pdf PDF
Att3_Pricing .xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DoDEA Cloud Questionnaire 1 Revised 202 Changes to this form must go thru DoDEA CyberSecurity

DoDEA Cloud Questionnaire Directions

The Department of Defense Education Activity (DoDEA) must review each vendor’s cloud-based solution individually to determine if it is compatible with DoD and DISA’s guidelines. Your answers to this questionnaire will enable us to do that evaluaton quickly and effectively. Please provide the point(s) of contact should DoDEA have questions about your response.

Please note:

Any proprietary or sensitive security information provided in response to this questionnaire will be protected and not shared outside of the US Government.

Links to will be considered an unacceptable to the question but can be provided as supporting .

will be considered an unacceptable response.

Cloud Resource Website/URL’s

Are Cloud Resources URLs provided for this solicitation? (Yes or No)

Has access to the Cloud Resource been supplied for this solicitation for review? (Yes or No)

Please provide all URLs for this resource.

Client Systems and Software Configuration (3 Questions)

Will DoDEA need to stand up servers to support this application? (Yes or No)

Is any software required for this service, e.g., software that must be installed on DoDEA computers to include browser extensions and/or plugins? (Yes or No)

If Yes, has this software made available for this review? (Yes or No)

Are there any configurations or changes that DoDEA must implement to any of its computers, browsers or firewalls to utilize this service? (Yes or No)

Privacy Information Data Collection and Distribution (6 Questions)

1. Is Personally Identifiable Information (PII) and/or sensitive information collected by this service? (Yes or No) (Some examples of PII: Full name, Home address, Work Address, Email address, Social security number, Passport number, Driver’s license number, Date of birth, Gender, Telephone number)

Select Item

Select Item

Select Item

Select Item Select Item

Select Item

DoDEA Cloud Questionnaire 2

Is any, personally identifiable and sensitive information collected by third parties or by external business partners (e.g., via cookies, plug-ins, ad networks, web beacons etc.)? (Yes or No)

Is any DoDEA data provided to third parties or external business partners for any purpose? (Yes or No) If yes provide a list of all third-party or external business partner recipients.

Do third parties or external business partner recipients of DoDEA data adhere to the same policies and processes to protect DoDEA data? (Yes or No)

Is there a process to opt-out of any transfers of DoDEA data to third parties or external business partner recipients? (Yes or No)

Are the following requirements for your cloud service meet?

Children's Online Privacy Protection Act (COPPA), per https://www.congress.gov/bill/105th-congress/senate-bill/2326/text (Yes or No) Privacy Act of 1974, per https://www.justice.gov/opcl/overview-privacy-act-1974-2020-edition (Yes or No) Family Educational Rights and Privacy Act (FERPA), per https://www2.ed.gov/policy/gen/guid/fpco/ferpa/index.html (Yes or No) Children's Internet Protection Act (CIPA), per http://www.fcc.gov/guides/childrens-internet-protection-act? (Yes or No)

System Management and Security (7 Questions)

1. Do you perform system penetration testing? (Yes or No)

2. Do you perform application penetration testing? (Yes or No)

3. Is application penetration testing performed after code changes? (Yes or No)

4. Do you perform regular system vulnerability testing? (Yes or No)

5. Do you have system intrusion prevention in place? (Yes or No)

6. Are system software updates and patches provided? (Yes or No)

7. Is the system, including its server(s) and network devices, located in an environmentally controlled and secure facility under controlled circumstances (e.g., authorized personnel access lists, ID cards, entry logs)? (Yes or No)

Select Item

Select Item

Select Item

Select Item

Select Item

Select Item

Select Item

Select Item

Select Item

Select Item

Select Item

Select Item

Select Item

DoDEA Cloud Questionnaire 3

Data Storage, Retention, and Access (10 Questions)

1. Is DoDEA’s information and data stored in the United States, to include outlying areas or DoD on-premises? (Yes or No)

2. Are all the Offeror’s employees and/or subcontractors that have or will be accessing DoDEA’s data located within the United States? (Yes or No)

3. Will any Sensitive and/or Confidential data including but not limited to PII data be transferred? (Yes or No)

4. Will DoDEA’s data at rest be encrypted? (Yes or No)

5. Is the system/database hosted on a multi-tenant instance? (Yes or No)

6. Is data secured with unique encryption keys for each customer on systems hosting multiple customers?

(Yes or No)

7. Will DoDEA’s data be protected in transit, e.g., secure socket layer (SSL), hashing, etc.? (Yes or No)

8. Are background checks completed on personnel to include subcontractors with access to servers, applications, and customer data? (Yes or No)

9. Is there a process for authenticating callers and resetting access controls? (Yes or No)

10. Is there a process to delete school/system data? (Yes or No)

Development and Change Management Process (4 Questions)

1. Is there a customer notification process for any changes made to corporate policies for data protection?

(Yes or No)

Audits and Standards

Is there a process for DoDEA to audit the security and privacy of records? (Yes or No)

Are the security operations reviewed or audited by an outside group? (Yes or No)

Are any security standards followed? (Yes or No) (Example: International Organization for Standardization (ISO), National Institute of Standards and Technology (NIST) and Payment Card Industry Data Security Standards (PCI DSS))

Select Item

Select Item

Select Item

Select Item

Select Item

Select Item

Select Item

Select Item

Select Item

Select Item

Select Item

Select Item

DoDEA Cloud Questionnaire 4

Test and Development Environments (1 Question)

1. Will “live” student/privacy data be used in a non-production environment, e.g., in testing, development, or training)? (Yes or No)

Data Breach, Incident Investigation and Response (4 Questions) backup-and-restore process in case of a disaster? (Yes or No)

Is there protection in place against denial-of-service attack? (Yes or No)

Is there process in managing a data breach? (Yes or No)

Is there a process in performing security incident investigations and/or e-discovery (different from a data breach)? (Yes or No)

Select Item

Select Item

Select Item

File details come from the government source that posted it. Updated .