Attachment_2_-_Security_Questionnaire.xlsx

XLSX spreadsheet 28 KB Posted

Attached to
Enterprise Resource Planning Software Modernization (re-solicitation) State and local contract opportunity
Solicitation number
RFP- 26 - 078
Issued by
Pinellas County, Florida

About this file

This is a Security Questionnaire for the City of St. Petersburg's Enterprise Resource Planning Software Modernization project, a significant technology procurement requiring vendors to provide a fully SaaS cloud-based ERP solution to replace the city's current Oracle E-Business Suite system. The questionnaire serves as Attachment A-4 to the RFP and mandates that vendors provide comprehensive responses to all sections; failure to comply may render proposals non-responsive. Vendors must submit completed questionnaires electronically by February 17, 2026, at 3:00 pm, with a pre-proposal meeting scheduled for January 6, 2026, at 10:00 am via Microsoft Teams and questions due by January 20, 2026, at 12:00 pm.

The Security Questionnaire addresses critical cybersecurity and data protection requirements essential to the City's evaluation of vendor proposals. Key areas of inquiry include third-party security certifications (FedRAMP, SOC II Type II, ISO 27001), Software Development Lifecycle compliance with NIST Special Publication 800-218, data residency guarantees within the continental United States, multi-factor authentication capabilities, and support for Azure AD SSO (SAML). Vendors must document their approach to data separation in multi-tenant environments, network penetration testing procedures, Mobile Device Management support, SIEM log exportation, and data ownership and erasure methodologies. Additional requirements address hardware manufacturing location, system boundary definitions, export control compliance for sensitive information, third-party vendor management, system outages and communication protocols, service level agreements, and integration capabilities within the City's production environment. The City's current infrastructure encompasses 3,201 full-time employees, 603 contingent workers, and 2,727 retirees, with approximately 3.4 terabytes of data requiring migration.

View the file

Other files for this state and local contract opportunity

Other files attached to Enterprise Resource Planning Software Modernization (re-solicitation), newest first.
File Type Posted
Enterprise_Resource_Planning_Software_Modernization_(re-solicitation)_(Addendum_#1_Revision).pdf PDF
Enterprise_Resource_Planning_Software_Modernization_(re-solicitation)_(Addendum_#1_Revision).pdf PDF
Enterprise_Resource_Planning_Software_Modernization_(re-solicitation)_(Addendum_#1_Revision).pdf PDF
Enterprise_Resource_Planning_Software_Modernization_(re-solicitation)_(Addendum_#1_Revision).pdf PDF
Enterprise_Resource_Planning_Software_Modernization_(re-solicitation).pdf PDF
Attachment_3_-_Submittal_Response_Form.docx DOCX document
Attachment_3_-_Submittal_Response_Form.docx DOCX document
Attachment_3_-_Submittal_Response_Form.docx DOCX document
Attachment_3_-_Submittal_Response_Form.docx DOCX document
Attachment_3_-_Submittal_Response_Form.docx DOCX document
Attachment_1_-_EBS_Interfaces.pdf PDF
Attachment_1_to_Appendix_A_-_Pension_Management_System_Requirements.pdf PDF
Attachment_2_-_Security_Questionnaire.xlsx XLSX spreadsheet
Base_Agreement.pdf PDF
Current_Oracle_License_Count.pdf PDF
Attachment_1_-_EBS_Interfaces.pdf PDF
Attachment_1_-_EBS_Interfaces.pdf PDF
Attachment_1_-_EBS_Interfaces.pdf PDF
Attachment_1_to_Appendix_A_-_Pension_Management_System_Requirements.pdf PDF
Current_Oracle_License_Count.pdf PDF
Current_Oracle_License_Count.pdf PDF
Attachment_1_to_Appendix_A_-_Pension_Management_System_Requirements.pdf PDF
Base_Agreement.pdf PDF
Appendix_A_-_Statement_of_Work.pdf PDF
Attachment_2_-_Security_Questionnaire.xlsx XLSX spreadsheet
Base_Agreement.pdf PDF
Attachment_2_-_Security_Questionnaire.xlsx XLSX spreadsheet
Appendix_A_-_Statement_of_Work.pdf PDF
Attachment_1_-_EBS_Interfaces.pdf PDF
Attachment_1_to_Appendix_A_-_Pension_Management_System_Requirements.pdf PDF
Base_Agreement.pdf PDF
Current_Oracle_License_Count.pdf PDF
Attachment_1_to_Appendix_A_-_Pension_Management_System_Requirements.pdf PDF
Current_Oracle_License_Count.pdf PDF
Appendix_A_-_Statement_of_Work.pdf PDF
Appendix_A_-_Statement_of_Work.pdf PDF
Appendix_A_-_Statement_of_Work.pdf PDF
Attachment_2_-_Security_Questionnaire.xlsx XLSX spreadsheet
Base_Agreement.pdf PDF
Show all 39

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Instructions

Attachment A-4 Security Questionnaire Instructions: Review and complete each of the tabs included in this workbook.

INSTRUCTIONS:
Please provide a complete response to all sections in this workbook. Failure to comply may render the proposal non-responsive.
Please follow the instructions in each of the worksheets and attach additional documents to this template where requested.
List of worksheets that require a response:
-Security Questionnaire

Security Questionnaire

City of St. Petersburg SW Selection
A-4 - Security Questionnaire
QuestionResponse
Does the vendor solution have any documentation for cybersecurity assurance? Third-party attestation or certifications are preferred? (Examples: FedRAMP, SOC II Type II, ISO 27001, SOC 2 Type I)
If FedRAMP certified, what is the FedRAMP Package ID#?
Does the Vendor or software/service maker provide an affirmative attestation that the Software Development Lifecycle (SDLC) used in the creation of the software/service is compliant with the federal requirement as detailed in NIST Special Publication 800-218.
Does the vendor or cloud service provider guarantee that all data resides in the continental United States?
Does the data get transmitted out of the continental US?
If yes, where?
Is all technical support for the solution based in the US?
If no, please identify where the technical support is based?
Do employees or employees of the solution in question have credentials to work with data in the US, e.g. Background check, H1B1 for personnel who are entrusted with your information or granted access to your systems?
What are the other external compliance requirements met - applicable only for solutions that will host PII, PCI, FERPA, HIPAA, NERC, SOX, or other regulatory requirements?
Is the proposed solution/system available in public (commercial), private (internally hosted), government (ex. ASW Gov Cloud), or hybrid cloud? Explain all hosted solutions, infrastructure and architecture.
Do separate environments exist for development, testing, and production?
If not, please explain how data is segmented.
Per Executive Order 14028, the City has adopted an agency-wide Multi-Factor Authentication approach. Does the solution have the ability to be MFA compliant?
What are the Multi-Tenant controls for separation of the City's users and data with other customers within the proposed solution.
If not Multi-Tenant, please provide a description of your ability to partition information about the City's users and data within a single tenant of the proposed solution.
Do you support AzureAD SSO (SAML)?
Do you support processes to request and run network penetration tests against the service, or arrange for independent third parties to conduct network penetrations tests on a defined frequency ?
Do you use third-party (e.g., hosted email, email marketing services, etc.) email providers? If so, who?
Does this solution support monitoring via API?
Does the vendor or cloud service provider guarantee that all data resides in the continental United States?
Does the data get transmitted out of the continental US?
The City routinely works with information that is subject to data export control regulations. How can the customer can be assured that export-controlled information remains within the borders of the United States.
Is the City's data erased or completly deleted upon cancellation of this service/application? Please explain erasure methodology.
What are the system boundaries of the proposed solution?
Does the solution support MDM (Mobile Device Management) if applicable?
What level of scanning can the City perform on the system? (Port, Vulnerability)
Can the system be enrolled in a monitoring program?

Can the logs be exported to a SIEM?

Was/Is the hardware manufactured in the Continental United States?
Can you provide a detailed description and or configuration diagram(s) of the hardware, computers, servers, etc.? Include all space, power, air, HVAC, and networking requirements for the equipment
Can you provide a clear description of how the proposed solution will work within the City's current production environment? Clearly identify what modifications (if any) need to be made to support the proposed solution
the City routinely works with information that is subject to data export control regulations. How can the customer can be assured that export-controlled information remains within the borders of the United States.
Does this service/application vendor share client data/personal information with other parties? Please explain
Does the proposed solution / application have robust methods for provisioning and consuming data? Please describe all methods.
Does the proposed system dictate that ownership of any data/content uploaded to the application/service belongs to the subscriber or client? Please describe who owns the data
Does the proposed solution / system allow subscriber or client full ownership of data throughout the entire lifecycle, or does the vendor own client data once uploaded? Please explain
What are the vendor's communication steps regarding system outages ?(patching/unplanned)
Are there any Support Credits/penalties for missing service levels?
Can you please confirm and document web crawler prevention at webroot ?
Please describe how you monitor additional 3rd or 4th party vendors that will have access to the City's data or systems

File details come from the government source that posted it. Updated .