Attachment_2_-_Security_Questionnaire.xlsx

XLSX spreadsheet 28 KB Posted

Attached to
Enterprise Resource Planning Software Modernization (re-solicitation) State and local contract opportunity
Solicitation number
RFP- 26 - 078
Issued by
Pinellas County, Florida

About this file

This Security Questionnaire attachment is a completion requirement for the City of St. Petersburg's Enterprise Resource Planning (ERP) Software Modernization procurement in Florida. The questionnaire serves as a mandatory evaluation document that vendors must complete in full to maintain proposal responsiveness. Vendors are required to provide comprehensive responses across all worksheet tabs, with failure to comply rendering proposals non-responsive. The questionnaire must be submitted electronically by February 17, 2026, at 3:00 pm through the City's online procurement portal, aligned with the overall proposal submission deadline. A pre-proposal meeting is scheduled for January 6, 2026, at 10:00 am via Microsoft Teams, and questions regarding the questionnaire requirements are due by January 20, 2026, at 12:00 pm. The project manager is expected to be onsite at least quarterly for two-day reviews, with mandatory attendance at module kickoff and go-live events throughout the implementation period.

The Security Questionnaire encompasses extensive cybersecurity and data governance requirements designed to protect the City's sensitive information and ensure compliance with federal and state regulations. Vendors must address documentation of cybersecurity assurance including third-party certifications (FedRAMP, SOC II Type II, ISO 27001), Software Development Lifecycle compliance with NIST Special Publication 800-218, and data residency guarantees within the continental United States. Additional requirements include Multi-Factor Authentication capability, Azure AD SSO support, network penetration testing processes, data deletion methodologies, Mobile Device Management support, SIEM log exportation, export-controlled information safeguards, and clear data ownership provisions. Vendors must also detail infrastructure hardware specifications, production environment integration plans, third-party vendor monitoring processes, system monitoring capabilities, and vendor communication protocols for system outages and service level agreements. These comprehensive security and compliance requirements reflect the City's responsibility to protect information belonging to 3,201 full-time employees, 603 contingent workers, and 2,727 retirees, while managing approximately 3.4 terabytes of data migration from the existing Oracle E-Business Suite system.

View the file

Other files for this state and local contract opportunity

Other files attached to Enterprise Resource Planning Software Modernization (re-solicitation), newest first.
File Type Posted
Enterprise_Resource_Planning_Software_Modernization_(re-solicitation)_(Addendum_#1_Revision).pdf PDF
Enterprise_Resource_Planning_Software_Modernization_(re-solicitation)_(Addendum_#1_Revision).pdf PDF
Enterprise_Resource_Planning_Software_Modernization_(re-solicitation)_(Addendum_#1_Revision).pdf PDF
Enterprise_Resource_Planning_Software_Modernization_(re-solicitation)_(Addendum_#1_Revision).pdf PDF
Enterprise_Resource_Planning_Software_Modernization_(re-solicitation).pdf PDF
Attachment_3_-_Submittal_Response_Form.docx DOCX document
Attachment_3_-_Submittal_Response_Form.docx DOCX document
Attachment_3_-_Submittal_Response_Form.docx DOCX document
Attachment_3_-_Submittal_Response_Form.docx DOCX document
Attachment_3_-_Submittal_Response_Form.docx DOCX document
Attachment_1_-_EBS_Interfaces.pdf PDF
Attachment_1_to_Appendix_A_-_Pension_Management_System_Requirements.pdf PDF
Attachment_2_-_Security_Questionnaire.xlsx XLSX spreadsheet
Base_Agreement.pdf PDF
Attachment_2_-_Security_Questionnaire.xlsx XLSX spreadsheet
Current_Oracle_License_Count.pdf PDF
Attachment_1_-_EBS_Interfaces.pdf PDF
Attachment_1_-_EBS_Interfaces.pdf PDF
Attachment_1_-_EBS_Interfaces.pdf PDF
Attachment_1_to_Appendix_A_-_Pension_Management_System_Requirements.pdf PDF
Current_Oracle_License_Count.pdf PDF
Appendix_A_-_Statement_of_Work.pdf PDF
Appendix_A_-_Statement_of_Work.pdf PDF
Attachment_2_-_Security_Questionnaire.xlsx XLSX spreadsheet
Base_Agreement.pdf PDF
Appendix_A_-_Statement_of_Work.pdf PDF
Attachment_1_-_EBS_Interfaces.pdf PDF
Attachment_1_to_Appendix_A_-_Pension_Management_System_Requirements.pdf PDF
Base_Agreement.pdf PDF
Current_Oracle_License_Count.pdf PDF
Attachment_1_to_Appendix_A_-_Pension_Management_System_Requirements.pdf PDF
Current_Oracle_License_Count.pdf PDF
Appendix_A_-_Statement_of_Work.pdf PDF
Current_Oracle_License_Count.pdf PDF
Attachment_1_to_Appendix_A_-_Pension_Management_System_Requirements.pdf PDF
Base_Agreement.pdf PDF
Appendix_A_-_Statement_of_Work.pdf PDF
Attachment_2_-_Security_Questionnaire.xlsx XLSX spreadsheet
Base_Agreement.pdf PDF
Show all 39

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Instructions

Attachment A-4 Security Questionnaire Instructions: Review and complete each of the tabs included in this workbook.

INSTRUCTIONS:
Please provide a complete response to all sections in this workbook. Failure to comply may render the proposal non-responsive.
Please follow the instructions in each of the worksheets and attach additional documents to this template where requested.
List of worksheets that require a response:
-Security Questionnaire

Security Questionnaire

City of St. Petersburg SW Selection
A-4 - Security Questionnaire
QuestionResponse
Does the vendor solution have any documentation for cybersecurity assurance? Third-party attestation or certifications are preferred? (Examples: FedRAMP, SOC II Type II, ISO 27001, SOC 2 Type I)
If FedRAMP certified, what is the FedRAMP Package ID#?
Does the Vendor or software/service maker provide an affirmative attestation that the Software Development Lifecycle (SDLC) used in the creation of the software/service is compliant with the federal requirement as detailed in NIST Special Publication 800-218.
Does the vendor or cloud service provider guarantee that all data resides in the continental United States?
Does the data get transmitted out of the continental US?
If yes, where?
Is all technical support for the solution based in the US?
If no, please identify where the technical support is based?
Do employees or employees of the solution in question have credentials to work with data in the US, e.g. Background check, H1B1 for personnel who are entrusted with your information or granted access to your systems?
What are the other external compliance requirements met - applicable only for solutions that will host PII, PCI, FERPA, HIPAA, NERC, SOX, or other regulatory requirements?
Is the proposed solution/system available in public (commercial), private (internally hosted), government (ex. ASW Gov Cloud), or hybrid cloud? Explain all hosted solutions, infrastructure and architecture.
Do separate environments exist for development, testing, and production?
If not, please explain how data is segmented.
Per Executive Order 14028, the City has adopted an agency-wide Multi-Factor Authentication approach. Does the solution have the ability to be MFA compliant?
What are the Multi-Tenant controls for separation of the City's users and data with other customers within the proposed solution.
If not Multi-Tenant, please provide a description of your ability to partition information about the City's users and data within a single tenant of the proposed solution.
Do you support AzureAD SSO (SAML)?
Do you support processes to request and run network penetration tests against the service, or arrange for independent third parties to conduct network penetrations tests on a defined frequency ?
Do you use third-party (e.g., hosted email, email marketing services, etc.) email providers? If so, who?
Does this solution support monitoring via API?
Does the vendor or cloud service provider guarantee that all data resides in the continental United States?
Does the data get transmitted out of the continental US?
The City routinely works with information that is subject to data export control regulations. How can the customer can be assured that export-controlled information remains within the borders of the United States.
Is the City's data erased or completly deleted upon cancellation of this service/application? Please explain erasure methodology.
What are the system boundaries of the proposed solution?
Does the solution support MDM (Mobile Device Management) if applicable?
What level of scanning can the City perform on the system? (Port, Vulnerability)
Can the system be enrolled in a monitoring program?

Can the logs be exported to a SIEM?

Was/Is the hardware manufactured in the Continental United States?
Can you provide a detailed description and or configuration diagram(s) of the hardware, computers, servers, etc.? Include all space, power, air, HVAC, and networking requirements for the equipment
Can you provide a clear description of how the proposed solution will work within the City's current production environment? Clearly identify what modifications (if any) need to be made to support the proposed solution
the City routinely works with information that is subject to data export control regulations. How can the customer can be assured that export-controlled information remains within the borders of the United States.
Does this service/application vendor share client data/personal information with other parties? Please explain
Does the proposed solution / application have robust methods for provisioning and consuming data? Please describe all methods.
Does the proposed system dictate that ownership of any data/content uploaded to the application/service belongs to the subscriber or client? Please describe who owns the data
Does the proposed solution / system allow subscriber or client full ownership of data throughout the entire lifecycle, or does the vendor own client data once uploaded? Please explain
What are the vendor's communication steps regarding system outages ?(patching/unplanned)
Are there any Support Credits/penalties for missing service levels?
Can you please confirm and document web crawler prevention at webroot ?
Please describe how you monitor additional 3rd or 4th party vendors that will have access to the City's data or systems

File details come from the government source that posted it. Updated .