attachment-3-rfp-2027-nhh-03-patie.xlsx

XLSX spreadsheet 84 KB Posted

Attached to
Patient Identification Software System State and local contract opportunity
Solicitation number
RFP-2027-NHH-02-PATIE
Issued by
Merrimack County, New Hampshire

About this file

Patient Identification Software System - RFP Summary

This document is the Consensus Assessments Initiative Questionnaire (CAIQv4.0.2) from the Cloud Security Alliance, attached as a supporting exhibit to the Request for Proposal issued by the State of New Hampshire Department of Health and Human Services for New Hampshire Hospital. The RFP seeks a comprehensive Patient Identification Software System capable of producing patient identification wristbands in at least six colors with tamper-proof clasps to serve approximately 800 patients annually. The system must be web-based, integrate with existing electronic health records systems, be compatible with handheld scanning devices, and include staff training, software installation, and ongoing support services. The RFP was issued on September 9, 2025, with vendor inquiries accepted until September 16, 2025, and proposals due by October 21, 2025, at 12:00 PM Noon. The anticipated contract will be effective July 1, 2026, with an initial five-year term ending July 1, 2031, and potential extension options for up to five additional years. Proposals will be evaluated using a 1,000-point scoring system, with 700 points allocated to technical capabilities and 300 points to pricing.

The CAIQ questionnaire provided contains 261 questions structured across 17 domains of the Cloud Control Matrix (CCMv4.0.2), establishing detailed security and compliance requirements for cloud service providers. The questionnaire addresses critical areas including audit and assurance, application security, business continuity, change management, cryptography and encryption, data center security, data security and privacy, governance and risk compliance, human resources, identity and access management, infrastructure and virtualization security, logging and monitoring, security incident management, supply chain accountability, threat and vulnerability management, and universal endpoint management. Vendors must demonstrate compliance with HIPAA regulations, NIST Special Publication 800-171 and 800-53 security standards, and provide comprehensive security documentation including Data Protection Impact Assessments, Systems Security Plans, and Disaster Recovery Plans. The RFP mandates vendor accountability through specific performance metrics, including response times for deficiency classes, hosting uptime requirements, and mandatory quarterly reporting, while requiring vendors to demonstrate capabilities across Software as a Service (SaaS), Infrastructure as a Service (IaaS), and Platform as a Service (PaaS) models.

View the file

Other files for this state and local contract opportunity

Other files attached to Patient Identification Software System, newest first.
File Type Posted
attachment_1_RFP-2027-NHH-02-PATIE.xlsx XLSX spreadsheet
attachment_2_RFP-2027-NHH-02-PATIE.pdf PDF
RFP-2027-NHH-02-PATIE.pdf PDF
attachment_3_RFP-2027-NHH-03-PATIE.xlsx XLSX spreadsheet
addendum-2-rfp-2027-nhh-02-patie-0.pdf PDF
addendum-3-rfp-2027-nhh-02-patie-0.pdf PDF
attachment-4-rfp-2027-nhh-02-patie.pdf PDF
rfp-2027-nhh-02-patie.pdf PDF
addendum-1-rfp-2027-nhh-02-patie.pdf PDF
attachment-1-rfp-2027-nhh-02-patie.xlsx XLSX spreadsheet
attachment-2-rfp-2027-nhh-02-patie.pdf PDF
Show all 11

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Introduction

v4.0.2CONSENSUS ASSESSMENTS INITIATIVE QUESTIONNAIRE v4.0.2
Introduction
Consensus Assessments Initiative Questionnaire (CAIQ):
This tab includes the questionnaire associated with the Cloud Control Matrix (CCM) controls, commonly known as the CAIQ.
The Consensus Assessments Initiative Questionnaire version 4 (or CAIQv4.0.2) aligns with the CCMv4.0.2 control specifications. The CAIQv4.0.2’s purpose is to help organizations conduct self-assessments to test their compliance against the CCM V4. It is developed under CSA’s STAR-Level 1 program umbrella, allowing organizations to complete and submit self-assessments to CSA’s STAR Registry.
The CAIQv4.0.2 features 261 questions structured and formulated based on the 17 domains and underlying control specifications of the CCM.
Each question is described using the following attributes:
Question ID
The question identifiers.
Assessment Question
The description of the question.
In addition, this tab includes the following sections (groups of columns).
CSP CAIQ Answer
The Cloud Service Provider (CSP) must respond with “Yes”/ ”No”/ ”NA” next to the corresponding assessment question, and for the portion(s) of the CCM control specification they are responsible and accountable for implementing.
Meaning of possible replies:
• “Yes”: The portion(s) of the CCM control requirement corresponding to the assessment question is met.
• “No”: The portion(s) of the CCM control requirement corresponding to the assessment question is not met.
• “N/A”: The question is not in scope and does not apply to the cloud service under assessment.
NOTES:
A “Yes” answer indicates that the portion of the control in question is implemented. The CSP indicates the responsible and accountable parties (SSRM control ownership), and optionally elaborates on the implementation “how-to” per relevant party CSP and/or CSC.
A “No” answer indicates that the portion of the control in question is not implemented, while in scope of the assessment. The CSP has to assign the implementation responsibility of the control to the relevant party under column “SSRM control ownership”, and optionally elaborate on the “why” (has not been implemented), and “what” has to be done for its implementation by that party.
A “N/A” answer indicates that the portion of the control in question is out of scope of the assessment. The “SSRM control ownership” column is to be left blank (e.g., greyed out), and optionally the CSP may explain why it is the case (“CSP Implementation Description”).
Shared Security Responsibility Model (SSRM) control ownership
The CSP control responses shall identify control applicability and ownership for their specific service.
• CSP-owned: The CSP is entirely responsible and accountable for the CCM control implementation.
• CSC-owned: The Cloud Service Customer (CSC) is entirely responsible and accountable for the CCM control implementation.
• Third-party outsourced: The third-party CSP in the supply chain (e.g., an IaaS provider) is responsible for CCM control implementation, while the CSP is fully accountable.
• Shared CSP and CSC: Both the CSP and CSC share CCM control implementation responsibility and accountability.
• Shared CSP and third party: Any CCM control implementation responsibility is shared between CSP and the third party, but the CSP remains fully accountable.
Note: The CAIQv4 SSRM schema is tailored to CCMv4’s Supply Chain Management, Transparency, and Accountability (STA) domain, controls 1-6, and their corresponding implementation guidelines.
CSP implementation description (optional/recommended)
A description (with references) of how the cloud service provider meets (or does not meet) the portion(s) of the SSRM control they are responsible for. If “NA,” explain why.
CSC responsibilities (optional/recommended)
A summary description of the cloud service customer security responsibilities for the portion(s) of the SSRM control that is responsible for, with corresponding guidance and references.
End of Introduction
© Copyright 2021-2022 Cloud Security Alliance - All rights reserved. You may download, store, display on your computer, view, print, and link to the Cloud Security Alliance “Consensus Assessments Initiative Questionnaire (CAIQ) Version 4.0.2” at http://www.cloudsecurityalliance.org subject to the following: (a) the Consensus Assessments Initiative Questionnaire v4.0.2 may be used solely for your personal, informational, non-commercial use; (b) the Consensus Assessments Initiative Questionnaire v4.0.2 may not be modified or altered in any way; (c) the Consensus Assessments Initiative Questionnaire v4.0.2 may not be redistributed; and (d) the trademark, copyright or other notices may not be removed. You may quote portions of the Consensus Assessments Initiative Questionnaire v4.0.2 as permitted by the Fair Use provisions of the United States Copyright Act, provided that you attribute the portions to the Cloud Security Alliance Consensus Assessments Initiative Questionnaire Version 4.0.2. If you are interested in obtaining a license to this #material for other usages not addresses in the copyright notice, please contact info@cloudsecurityalliance.org.

CAIQv4.0.2

v4.0.2CONSENSUS ASSESSMENTS INITIATIVE QUESTIONNAIRE v4.0.2
Question IDQuestionCSP CAIQ AnswerSSRM Control OwnershipCSP Implementation Description (Optional/Recommended)CSC Responsibilities (Optional/Recommended)CCM Control IDCCM Control SpecificationCCM Control TitleCCM Domain Title
A&A-01.1Are audit and assurance policies, procedures, and standards established, documented,

approved, communicated, applied, evaluated, and maintained?

A&A-01 Establish, document, approve, communicate, apply, evaluate and maintain audit and assurance policies and procedures and standards. Review and update the policies and procedures at least annually.

Audit and Assurance Policy and ProceduresAudit & Assurance
A&A-01.2Are audit and assurance policies, procedures, and standards reviewed and updated

at least annually?

A&A-02.1 Are independent audit and assurance assessments conducted according to relevant standards at least annually?

A&A-02 Conduct independent audit and assurance assessments according to relevant standards at least annually.

Independent Assessments
A&A-03.1Are independent audit and assurance assessments performed according to risk-based

plans and policies?

A&A-03 Perform independent audit and assurance assessments according to risk-based plans and policies.

Risk Based Planning Assessment
A&A-04.1Is compliance verified regarding all relevant standards, regulations, legal/contractual,

and statutory requirements applicable to the audit?

A&A-04 Verify compliance with all relevant standards, regulations, legal/contractual, and statutory requirements applicable to the audit.

Requirements Compliance
A&A-05.1Is an audit management process defined and implemented to support audit planning,

risk analysis, security control assessments, conclusions, remediation schedules, report generation, and reviews of past reports and supporting evidence?

A&A-05 Define and implement an Audit Management process to support audit planning, risk analysis, security control assessment, conclusion, remediation schedules, report generation, and review of past reports and supporting evidence.

Audit Management Process
A&A-06.1Is a risk-based corrective action plan to remediate audit findings established,

documented, approved, communicated, applied, evaluated, and maintained?

A&A-06 Establish, document, approve, communicate, apply, evaluate and maintain a risk-based corrective action plan to remediate audit findings, review and report remediation status to relevant stakeholders.

Remediation
A&A-06.2Is the remediation status of audit findings reviewed and reported to relevant

stakeholders?

AIS-01.1 Are application security policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained to guide appropriate planning, delivery, and support of the organization's application security capabilities?

AIS-01 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for application security to provide guidance to the appropriate planning, delivery and support of the organization's application security capabilities. Review and update the policies and procedures at least annually.

Application and Interface Security Policy and ProceduresApplication & Interface Security
AIS-01.2Are application security policies and procedures reviewed and updated at least

annually?

AIS-02.1 Are baseline requirements to secure different applications established, documented, and maintained?

AIS-02 Establish, document and maintain baseline requirements for securing different applications.

Application Security Baseline Requirements
AIS-03.1Are technical and operational metrics defined and implemented according to

business objectives, security requirements, and compliance obligations?

AIS-03 Define and implement technical and operational metrics in alignment with business objectives, security requirements, and compliance obligations.

Application Security Metrics
AIS-04.1Is an SDLC process defined and implemented for application design, development,

deployment, and operation per organizationally designed security requirements?

AIS-04 Define and implement a SDLC process for application design, development, deployment, and operation in accordance with security requirements defined by the organization.

Secure Application Design and Development
AIS-05.1Does the testing strategy outline criteria to accept new information systems,

upgrades, and new versions while ensuring application security, compliance adherence, and organizational speed of delivery goals?

AIS-05 Implement a testing strategy, including criteria for acceptance of new information systems, upgrades and new versions, which provides application security assurance and maintains compliance while enabling organizational speed of delivery goals. Automate when applicable and possible.

Automated Application Security Testing
AIS-05.2Is testing automated when applicable and possible?

AIS-06.1 Are strategies and capabilities established and implemented to deploy application code in a secure, standardized, and compliant manner?

AIS-06 Establish and implement strategies and capabilities for secure, standardized, and compliant application deployment. Automate where possible.

Automated Secure Application Deployment
AIS-06.2Is the deployment and integration of application code automated where possible?
AIS-07.1Are application security vulnerabilities remediated following defined processes?
AIS-07Define and implement a process to remediate application security

vulnerabilities, automating remediation when possible.

Application Vulnerability Remediation
AIS-07.2Is the remediation of application security vulnerabilities automated when

possible?

BCR-01.1 Are business continuity management and operational resilience policies and procedures established, documented, approved, communicated, applied, evaluated, and maintained?

BCR-01 Establish, document, approve, communicate, apply, evaluate and maintain business continuity management and operational resilience policies and procedures.

Review and update the policies and procedures at least annually.

Business Continuity Management Policy and ProceduresBusiness Continuity Management and Operational Resilience
BCR-01.2Are the policies and procedures reviewed and updated at least annually?

BCR-02.1 Are criteria for developing business continuity and operational resiliency strategies and capabilities established based on business disruption and risk impacts?

BCR-02 Determine the impact of business disruptions and risks to establish criteria for developing business continuity and operational resilience strategies and capabilities.

Risk Assessment and Impact Analysis
BCR-03.1Are strategies developed to reduce the impact of, withstand, and recover from

business disruptions in accordance with risk appetite?

BCR-03 Establish strategies to reduce the impact of, withstand, and recover from business disruptions within risk appetite.

Business Continuity Strategy
BCR-04.1Are operational resilience strategies and capability results incorporated

to establish, document, approve, communicate, apply, evaluate, and maintain a business continuity plan?

BCR-04 Establish, document, approve, communicate, apply, evaluate and maintain a business continuity plan based on the results of the operational resilience strategies and capabilities.

Business Continuity Planning
BCR-05.1Is relevant documentation developed, identified, and acquired to support business

continuity and operational resilience plans?

BCR-05 Develop, identify, and acquire documentation that is relevant to support the business continuity and operational resilience programs. Make the documentation available to authorized stakeholders and review periodically.

Documentation
BCR-05.2Is business continuity and operational resilience documentation available

to authorized stakeholders?

BCR-05.3 Is business continuity and operational resilience documentation reviewed periodically?

BCR-06.1 Are the business continuity and operational resilience plans exercised and tested at least annually and when significant changes occur?

BCR-06 Exercise and test business continuity and operational resilience plans at least annually or upon significant changes.

Business Continuity Exercises
BCR-07.1Do business continuity and resilience procedures establish communication with

stakeholders and participants?

BCR-07 Establish communication with stakeholders and participants in the course of business continuity and resilience procedures.

Communication
BCR-08.1Is cloud data periodically backed up?
BCR-08Periodically backup data stored in the cloud. Ensure the confidentiality,

integrity and availability of the backup, and verify data restoration from backup for resiliency.

Backup
BCR-08.2Is the confidentiality, integrity, and availability of backup data ensured?

BCR-08.3 Can backups be restored appropriately for resiliency?

BCR-09.1 Is a disaster response plan established, documented, approved, applied, evaluated, and maintained to ensure recovery from natural and man-made disasters?

BCR-09 Establish, document, approve, communicate, apply, evaluate and maintain a disaster response plan to recover from natural and man-made disasters. Update the plan at least annually or upon significant changes.

Disaster Response Plan
BCR-09.2Is the disaster response plan updated at least annually, and when significant

changes occur?

BCR-10.1 Is the disaster response plan exercised annually or when significant changes occur?

BCR-10 Exercise the disaster response plan annually or upon significant changes, including if possible local emergency authorities.

Response Plan Exercise
BCR-10.2Are local emergency authorities included, if possible, in the exercise?

BCR-11.1 Is business-critical equipment supplemented with redundant equipment independently located at a reasonable minimum distance in accordance with applicable industry standards?

BCR-11 Supplement business-critical equipment with redundant equipment independently located at a reasonable minimum distance in accordance with applicable industry standards.

Equipment Redundancy
CCC-01.1Are risk management policies and procedures associated with changing organizational

assets including applications, systems, infrastructure, configuration, etc., established, documented, approved, communicated, applied, evaluated and maintained (regardless of whether asset management is internal or external)?

CCC-01 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for managing the risks associated with applying changes to organization assets, including application, systems, infrastructure, configuration, etc., regardless of whether the assets are managed internally or externally (i.e., outsourced). Review and update the policies and procedures at least annually.

Change Management Policy and ProceduresChange Control and Configuration Management
CCC-01.2Are the policies and procedures reviewed and updated at least annually?

CCC-02.1 Is a defined quality change control, approval and testing process (with established baselines, testing, and release standards) followed?

CCC-02 Follow a defined quality change control, approval and testing process with established baselines, testing, and release standards.

Quality Testing
CCC-03.1Are risks associated with changing organizational assets (including applications,

systems, infrastructure, configuration, etc.) managed, regardless of whether asset management occurs internally or externally (i.e., outsourced)?

CCC-03 Manage the risks associated with applying changes to organization assets, including application, systems, infrastructure, configuration, etc., regardless of whether the assets are managed internally or externally (i.e., outsourced).

Change Management Technology
CCC-04.1Is the unauthorized addition, removal, update, and management of organization

assets restricted?

CCC-04 Restrict the unauthorized addition, removal, update, and management of organization assets.

Unauthorized Change Protection
CCC-05.1Are provisions to limit changes that directly impact CSC-owned environments

and require tenants to authorize requests explicitly included within the service level agreements (SLAs) between CSPs and CSCs?

CCC-05 Include provisions limiting changes directly impacting CSCs owned environments/tenants to explicitly authorized requests within service level agreements between CSPs and CSCs.

Change Agreements
CCC-06.1Are change management baselines established for all relevant authorized changes

on organizational assets?

CCC-06 Establish change management baselines for all relevant authorized changes on organization assets.

Change Management Baseline
CCC-07.1Are detection measures implemented with proactive notification if changes

deviate from established baselines?

CCC-07 Implement detection measures with proactive notification in case of changes deviating from the established baseline.

Detection of Baseline Deviation
CCC-08.1Is a procedure implemented to manage exceptions, including emergencies, in

the change and configuration process?

CCC-08 'Implement a procedure for the management of exceptions, including emergencies, in the change and configuration process. Align the procedure with the requirements of GRC-04: Policy Exception Process.'

Exception Management
CCC-08.2'Is the procedure aligned with the requirements of the GRC-04: Policy Exception

Process?'

CCC-09.1 Is a process to proactively roll back changes to a previously known "good state" defined and implemented in case of errors or security concerns?

CCC-09 Define and implement a process to proactively roll back changes to a previous known good state in case of errors or security concerns.

Change Restoration
CEK-01.1Are cryptography, encryption, and key management policies and procedures established,

documented, approved, communicated, applied, evaluated, and maintained?

CEK-01 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for Cryptography, Encryption and Key Management. Review and update the policies and procedures at least annually.

Encryption and Key Management Policy and ProceduresCryptography, Encryption & Key Management
CEK-01.2Are cryptography, encryption, and key management policies and procedures reviewed

and updated at least annually?

CEK-02.1 Are cryptography, encryption, and key management roles and responsibilities defined and implemented?

CEK-02 Define and implement cryptographic, encryption and key management roles and responsibilities.

CEK Roles and Responsibilities
CEK-03.1Are data at-rest and in-transit cryptographically protected using cryptographic

libraries certified to approved standards?

CEK-03 Provide cryptographic protection to data at-rest and in-transit, using cryptographic libraries certified to approved standards.

Data Encryption
CEK-04.1Are appropriate data protection encryption algorithms used that consider data

classification, associated risks, and encryption technology usability?

CEK-04 Use encryption algorithms that are appropriate for data protection, considering the classification of data, associated risks, and usability of the encryption technology.

Encryption Algorithm
CEK-05.1Are standard change management procedures established to review, approve,

implement and communicate cryptography, encryption, and key management technology changes that accommodate internal and external sources?

CEK-05 Establish a standard change management procedure, to accommodate changes from internal and external sources, for review, approval, implementation and communication of cryptographic, encryption and key management technology changes.

Encryption Change Management
CEK-06.1Are changes to cryptography-, encryption- and key management-related systems,

policies, and procedures, managed and adopted in a manner that fully accounts for downstream effects of proposed changes, including residual risk, cost, and benefits analysis?

CEK-06 Manage and adopt changes to cryptography-, encryption-, and key management-related systems (including policies and procedures) that fully account for downstream effects of proposed changes, including residual risk, cost, and benefits analysis.

Encryption Change Cost Benefit Analysis
CEK-07.1Is a cryptography, encryption, and key management risk program established

and maintained that includes risk assessment, risk treatment, risk context, monitoring, and feedback provisions?

CEK-07 Establish and maintain an encryption and key management risk program that includes provisions for risk assessment, risk treatment, risk context, monitoring, and feedback.

Encryption Risk Management
CEK-08.1Are CSPs providing CSCs with the capacity to manage their own data encryption

keys?

CEK-08 CSPs must provide the capability for CSCs to manage their own data encryption keys.

CSC Key Management Capability
CEK-09.1Are encryption and key management systems, policies, and processes audited

with a frequency proportional to the system's risk exposure, and after any security event?

CEK-09 Audit encryption and key management systems, policies, and processes with a frequency that is proportional to the risk exposure of the system with audit occurring preferably continuously but at least annually and after any security event(s).

Encryption and Key Management Audit
CEK-09.2Are encryption and key management systems, policies, and processes audited

(preferably continuously but at least annually)?

CEK-10.1 Are cryptographic keys generated using industry-accepted and approved cryptographic libraries that specify algorithm strength and random number generator specifications?

CEK-10 Generate Cryptographic keys using industry accepted cryptographic libraries specifying the algorithm strength and the random number generator used.

Key Generation
CEK-11.1Are private keys provisioned for a unique purpose managed, and is cryptography

secret?

CEK-11 Manage cryptographic secret and private keys that are provisioned for a unique purpose.

Key Purpose
CEK-12.1Are cryptographic keys rotated based on a cryptoperiod calculated while considering

information disclosure risks and legal and regulatory requirements?

CEK-12 Rotate cryptographic keys in accordance with the calculated cryptoperiod, which includes provisions for considering the risk of information disclosure and legal and regulatory requirements.

Key Rotation
CEK-13.1Are cryptographic keys revoked and removed before the end of the established

cryptoperiod (when a key is compromised, or an entity is no longer part of the organization) per defined, implemented, and evaluated processes, procedures, and technical measures to include legal and regulatory requirement provisions?

CEK-13 Define, implement and evaluate processes, procedures and technical measures to revoke and remove cryptographic keys prior to the end of its established cryptoperiod, when a key is compromised, or an entity is no longer part of the organization, which include provisions for legal and regulatory requirements.

Key Revocation
CEK-14.1Are processes, procedures and technical measures to destroy unneeded keys

defined, implemented and evaluated to address key destruction outside secure environments, revocation of keys stored in hardware security modules (HSMs), and include applicable legal and regulatory requirement provisions?

CEK-14 Define, implement and evaluate processes, procedures and technical measures to destroy keys stored outside a secure environment and revoke keys stored in Hardware Security Modules (HSMs) when they are no longer needed, which include provisions for legal and regulatory requirements.

Key Destruction
CEK-15.1Are processes, procedures, and technical measures to create keys in a pre-activated

state (i.e., when they have been generated but not authorized for use) being defined, implemented, and evaluated to include legal and regulatory requirement provisions?

CEK-15 Define, implement and evaluate processes, procedures and technical measures to create keys in a pre-activated state when they have been generated but not authorized for use, which include provisions for legal and regulatory requirements.

Key Activation
CEK-16.1Are processes, procedures, and technical measures to monitor, review and approve

key transitions (e.g., from any state to/from suspension) being defined, implemented, and evaluated to include legal and regulatory requirement provisions?

CEK-16 Define, implement and evaluate processes, procedures and technical measures to monitor, review and approve key transitions from any state to/from suspension, which include provisions for legal and regulatory requirements.

Key Suspension
CEK-17.1Are processes, procedures, and technical measures to deactivate keys (at the

time of their expiration date) being defined, implemented, and evaluated to include legal and regulatory requirement provisions?

CEK-17 Define, implement and evaluate processes, procedures and technical measures to deactivate keys at the time of their expiration date, which include provisions for legal and regulatory requirements.

Key Deactivation
CEK-18.1Are processes, procedures, and technical measures to manage archived keys

in a secure repository (requiring least privilege access) being defined, implemented, and evaluated to include legal and regulatory requirement provisions?

CEK-18 Define, implement and evaluate processes, procedures and technical measures to manage archived keys in a secure repository requiring least privilege access, which include provisions for legal and regulatory requirements.

Key Archival
CEK-19.1Are processes, procedures, and technical measures to encrypt information in

specific scenarios (e.g., only in controlled circumstances and thereafter only for data decryption and never for encryption) being defined, implemented, and evaluated to include legal and regulatory requirement provisions?

CEK-19 Define, implement and evaluate processes, procedures and technical measures to use compromised keys to encrypt information only in controlled circumstance, and thereafter exclusively for decrypting data and never for encrypting data, which include provisions for legal and regulatory requirements.

Key Compromise
CEK-20.1Are processes, procedures, and technical measures to assess operational continuity

risks (versus the risk of losing control of keying material and exposing protected data) being defined, implemented, and evaluated to include legal and regulatory requirement provisions?

CEK-20 Define, implement and evaluate processes, procedures and technical measures to assess the risk to operational continuity versus the risk of the keying material and the information it protects being exposed if control of the keying material is lost, which include provisions for legal and regulatory requirements.

Key Recovery
CEK-21.1Are key management system processes, procedures, and technical measures being

defined, implemented, and evaluated to track and report all cryptographic materials and status changes that include legal and regulatory requirements provisions?

CEK-21 Define, implement and evaluate processes, procedures and technical measures in order for the key management system to track and report all cryptographic materials and changes in status, which include provisions for legal and regulatory requirements.

Key Inventory Management
DCS-01.1Are policies and procedures for the secure disposal of equipment used outside

the organization's premises established, documented, approved, communicated, enforced, and maintained?

DCS-01 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the secure disposal of equipment used outside the organization's premises. If the equipment is not physically destroyed a data destruction procedure that renders recovery of information impossible must be applied. Review and update the policies and procedures at least annually.

Off-Site Equipment Disposal Policy and ProceduresDatacenter Security
DCS-01.2Is a data destruction procedure applied that renders information recovery

information impossible if equipment is not physically destroyed?

DCS-01.3 Are policies and procedures for the secure disposal of equipment used outside the organization's premises reviewed and updated at least annually?

DCS-02.1 Are policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location established, documented, approved, communicated, implemented, enforced, maintained?

DCS-02 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location. The relocation or transfer request requires the written or cryptographically verifiable authorization.

Review and update the policies and procedures at least annually.

Off-Site Transfer Authorization Policy and Procedures
DCS-02.2Does a relocation or transfer request require written or cryptographically

verifiable authorization?

DCS-02.3 Are policies and procedures for the relocation or transfer of hardware, software, or data/information to an offsite or alternate location reviewed and updated at least annually?

DCS-03.1 Are policies and procedures for maintaining a safe and secure working environment (in offices, rooms, and facilities) established, documented, approved, communicated, enforced, and maintained?

DCS-03 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for maintaining a safe and secure working environment in offices, rooms, and facilities. Review and update the policies and procedures at least annually.

Secure Area Policy and Procedures
DCS-03.2Are policies and procedures for maintaining safe, secure working environments

(e.g., offices, rooms) reviewed and updated at least annually?

DCS-04.1 Are policies and procedures for the secure transportation of physical media established, documented, approved, communicated, enforced, evaluated, and maintained?

DCS-04 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the secure transportation of physical media. Review and update the policies and procedures at least annually.

Secure Media Transportation Policy and Procedures
DCS-04.2Are policies and procedures for the secure transportation of physical media

reviewed and updated at least annually?

DCS-05.1 Is the classification and documentation of physical and logical assets based on the organizational business risk?

DCS-05 Classify and document the physical, and logical assets (e.g., applications) based on the organizational business risk.

Assets Classification
DCS-06.1Are all relevant physical and logical assets at all CSP sites cataloged and

tracked within a secured system?

DCS-06 Catalogue and track all relevant physical and logical assets located at all of the CSP's sites within a secured system.

Assets Cataloguing and Tracking
DCS-07.1Are physical security perimeters implemented to safeguard personnel, data,

and information systems?

DCS-07 Implement physical security perimeters to safeguard personnel, data, and information systems. Establish physical security perimeters between the administrative and business areas and the data storage and processing facilities areas.

Controlled Access Points
DCS-07.2Are physical security perimeters established between administrative and business

areas, data storage, and processing facilities?

DCS-08.1Is equipment identification used as a method for connection authentication?
DCS-08Use equipment identification as a method for connection authentication.
Equipment Identification
DCS-09.1Are solely authorized personnel able to access secure areas, with all ingress

and egress areas restricted, documented, and monitored by physical access control mechanisms?

DCS-09 Allow only authorized personnel access to secure areas, with all ingress and egress points restricted, documented, and monitored by physical access control mechanisms. Retain access control records on a periodic basis as deemed appropriate by the organization.

Secure Area Authorization
DCS-09.2Are access control records retained periodically, as deemed appropriate by

the organization?

DCS-10.1 Are external perimeter datacenter surveillance systems and surveillance systems at all ingress and egress points implemented, maintained, and operated?

DCS-10 Implement, maintain, and operate datacenter surveillance systems at the external perimeter and at all the ingress and egress points to detect unauthorized ingress and egress attempts.

Surveillance System
DCS-11.1Are datacenter personnel trained to respond to unauthorized access or egress

attempts?

DCS-11 Train datacenter personnel to respond to unauthorized ingress or egress attempts.

Unauthorized Access Response Training
DCS-12.1Are processes, procedures, and technical measures defined, implemented, and

evaluated to ensure risk-based protection of power and telecommunication cables from interception, interference, or damage threats at all facilities, offices, and rooms?

DCS-12 Define, implement and evaluate processes, procedures and technical measures that ensure a risk-based protection of power and telecommunication cables from a threat of interception, interference or damage at all facilities, offices and rooms.

Cabling Security
DCS-13.1Are data center environmental control systems designed to monitor, maintain,

and test that on-site temperature and humidity conditions fall within accepted industry standards effectively implemented and maintained?

DCS-13 Implement and maintain data center environmental control systems that monitor, maintain and test for continual effectiveness the temperature and humidity conditions within accepted industry standards.

Environmental Systems
DCS-14.1Are utility services secured, monitored, maintained, and tested at planned

intervals for continual effectiveness?

DCS-14 Secure, monitor, maintain, and test utilities services for continual effectiveness at planned intervals.

Secure Utilities
DCS-15.1Is business-critical equipment segregated from locations subject to a high

probability of environmental risk events?

DCS-15 Keep business-critical equipment away from locations subject to high probability for environmental risk events.

Equipment Location
DSP-01.1Are policies and procedures established, documented, approved, communicated,

enforced, evaluated, and maintained for the classification, protection, and handling of data throughout its lifecycle according to all applicable laws and regulations, standards, and risk level?

DSP-01 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for the classification, protection and handling of data throughout its lifecycle, and according to all applicable laws and regulations, standards, and risk level. Review and update the policies and procedures at least annually.

Security and Privacy Policy and ProceduresData Security and Privacy Lifecycle Management
DSP-01.2Are data security and privacy policies and procedures reviewed and updated

at least annually?

DSP-02.1 Are industry-accepted methods applied for secure data disposal from storage media so information is not recoverable by any forensic means?

DSP-02 Apply industry accepted methods for the secure disposal of data from storage media such that data is not recoverable by any forensic means.

Secure Disposal
DSP-03.1Is a data inventory created and maintained for sensitive and personal information

(at a minimum)?

DSP-03 Create and maintain a data inventory, at least for any sensitive data and personal data.

Data Inventory
DSP-04.1Is data classified according to type and sensitivity levels?
DSP-04Classify data according to its type and sensitivity level.
Data Classification
DSP-05.1Is data flow documentation created to identify what data is processed and

where it is stored and transmitted?

DSP-05 Create data flow documentation to identify what data is processed, stored or transmitted where. Review data flow documentation at defined intervals, at least annually, and after any change.

Data Flow Documentation
DSP-05.2Is data flow documentation reviewed at defined intervals, at least annually,

and after any change?

DSP-06.1 Is the ownership and stewardship of all relevant personal and sensitive data documented?

DSP-06 Document ownership and stewardship of all relevant documented personal and sensitive data. Perform review at least annually.

Data Ownership and Stewardship
DSP-06.2Is data ownership and stewardship documentation reviewed at least annually?

DSP-07.1 Are systems, products, and business practices based on security principles by design and per industry best practices?

DSP-07 Develop systems, products, and business practices based upon a principle of security by design and industry best practices.

Data Protection by Design and Default
DSP-08.1Are systems, products, and business practices based on privacy principles

by design and according to industry best practices?

DSP-08 Develop systems, products, and business practices based upon a principle of privacy by design and industry best practices. Ensure that systems' privacy settings are configured by default, according to all applicable laws and regulations.

Data Privacy by Design and Default
DSP-08.2Are systems' privacy settings configured by default and according to all applicable

laws and regulations?

DSP-09.1 Is a data protection impact assessment (DPIA) conducted when processing personal data and evaluating the origin, nature, particularity, and severity of risks according to any applicable laws, regulations and industry best practices?

DSP-09 Conduct a Data Protection Impact Assessment (DPIA) to evaluate the origin, nature, particularity and severity of the risks upon the processing of personal data, according to any applicable laws, regulations and industry best practices.

Data Protection Impact Assessment
DSP-10.1Are processes, procedures, and technical measures defined, implemented, and

evaluated to ensure any transfer of personal or sensitive data is protected from unauthorized access and only processed within scope (as permitted by respective laws and regulations)?

DSP-10 Define, implement and evaluate processes, procedures and technical measures that ensure any transfer of personal or sensitive data is protected from unauthorized access and only processed within scope as permitted by the respective laws and regulations.

Sensitive Data Transfer
DSP-11.1Are processes, procedures, and technical measures defined, implemented, and

evaluated to enable data subjects to request access to, modify, or delete personal data (per applicable laws and regulations)?

DSP-11 Define and implement, processes, procedures and technical measures to enable data subjects to request access to, modification, or deletion of their personal data, according to any applicable laws and regulations.

Personal Data Access, Reversal, Rectification and Deletion
DSP-12.1Are processes, procedures, and technical measures defined, implemented, and

evaluated to ensure personal data is processed (per applicable laws and regulations and for the purposes declared to the data subject)?

DSP-12 Define, implement and evaluate processes, procedures and technical measures to ensure that personal data is processed according to any applicable laws and regulations and for the purposes declared to the data subject.

Limitation of Purpose in Personal Data Processing
DSP-13.1Are processes, procedures, and technical measures defined, implemented, and

evaluated for the transfer and sub-processing of personal data within the service supply chain (according to any applicable laws and regulations)?

DSP-13 Define, implement and evaluate processes, procedures and technical measures for the transfer and sub-processing of personal data within the service supply chain, according to any applicable laws and regulations.

Personal Data Sub-processing
DSP-14.1Are processes, procedures, and technical measures defined, implemented, and

evaluated to disclose details to the data owner of any personal or sensitive data access by sub-processors before processing initiation?

DSP-14 Define, implement and evaluate processes, procedures and technical measures to disclose the details of any personal or sensitive data access by sub-processors to the data owner prior to initiation of that processing.

Disclosure of Data Sub-processors
DSP-15.1Is authorization from data owners obtained, and the associated risk managed,

before replicating or using production data in non-production environments?

DSP-15 Obtain authorization from data owners, and manage associated risk before replicating or using production data in non-production environments.

Limitation of Production Data Use
DSP-16.1Do data retention, archiving, and deletion practices follow business requirements,

applicable laws, and regulations?

DSP-16 Data retention, archiving and deletion is managed in accordance with business requirements, applicable laws and regulations.

Data Retention and Deletion
DSP-17.1Are processes, procedures, and technical measures defined and implemented

to protect sensitive data throughout its lifecycle?

DSP-17 Define and implement, processes, procedures and technical measures to protect sensitive data throughout it's lifecycle.

Sensitive Data Protection
DSP-18.1Does the CSP have in place, and describe to CSCs, the procedure to manage

and respond to requests for disclosure of Personal Data by Law Enforcement Authorities according to applicable laws and regulations?

DSP-18 The CSP must have in place, and describe to CSCs the procedure to manage and respond to requests for disclosure of Personal Data by Law Enforcement Authorities according to applicable laws and regulations. The CSP must give special attention to the notification procedure to interested CSCs, unless otherwise prohibited, such as a prohibition under criminal law to preserve confidentiality of a law enforcement investigation.

Disclosure Notification
DSP-18.2Does the CSP give special attention to the notification procedure to interested

CSCs, unless otherwise prohibited, such as a prohibition under criminal law to preserve confidentiality of a law enforcement investigation?

DSP-19.1 Are processes, procedures, and technical measures defined and implemented to specify and document physical data locations, including locales where data is processed or backed up?

DSP-19 Define and implement, processes, procedures and technical measures to specify and document the physical locations of data, including any locations in which data is processed or backed up.

Data Location
GRC-01.1Are information governance program policies and procedures sponsored by organizational

leadership established, documented, approved, communicated, applied, evaluated, and maintained?

GRC-01 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for an information governance program, which is sponsored by the leadership of the organization. Review and update the policies and procedures at least annually.

Governance Program Policy and ProceduresGovernance, Risk and Compliance
GRC-01.2Are the policies and procedures reviewed and updated at least annually?

GRC-02.1 Is there an established formal, documented, and leadership-sponsored enterprise risk management (ERM) program that includes policies and procedures for identification, evaluation, ownership, treatment, and acceptance of cloud security and privacy risks?

GRC-02 Establish a formal, documented, and leadership-sponsored Enterprise Risk Management (ERM) program that includes policies and procedures for identification, evaluation, ownership, treatment, and acceptance of cloud security and privacy risks.

Risk Management Program
GRC-03.1Are all relevant organizational policies and associated procedures reviewed

at least annually, or when a substantial organizational change occurs?

GRC-03 Review all relevant organizational policies and associated procedures at least annually or when a substantial change occurs within the organization.

Organizational Policy Reviews
GRC-04.1Is an approved exception process mandated by the governance program established

and followed whenever a deviation from an established policy occurs?

GRC-04 Establish and follow an approved exception process as mandated by the governance program whenever a deviation from an established policy occurs.

Policy Exception Process
GRC-05.1Has an information security program (including programs of all relevant CCM

domains) been developed and implemented?

GRC-05 Develop and implement an Information Security Program, which includes programs for all the relevant domains of the CCM.

Information Security Program
GRC-06.1Are roles and responsibilities for planning, implementing, operating, assessing,

and improving governance programs defined and documented?

GRC-06 Define and document roles and responsibilities for planning, implementing, operating, assessing, and improving governance programs.

Governance Responsibility Model
GRC-07.1Are all relevant standards, regulations, legal/contractual, and statutory

requirements applicable to your organization identified and documented?

GRC-07 Identify and document all relevant standards, regulations, legal/contractual, and statutory requirements, which are applicable to your organization.

Information System Regulatory Mapping
GRC-08.1Is contact established and maintained with cloud-related special interest

groups and other relevant entities?

GRC-08 Establish and maintain contact with cloud-related special interest groups and other relevant entities in line with business context.

Special Interest Groups
HRS-01.1Are background verification policies and procedures of all new employees (including

but not limited to remote employees, contractors, and third parties) established, documented, approved, communicated, applied, evaluated, and maintained?

HRS-01 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for background verification of all new employees (including but not limited to remote employees, contractors, and third parties) according to local laws, regulations, ethics, and contractual constraints and proportional to the data classification to be accessed, the business requirements, and acceptable risk. Review and update the policies and procedures at least annually.

Background Screening Policy and ProceduresHuman Resources
HRS-01.2Are background verification policies and procedures designed according to

local laws, regulations, ethics, and contractual constraints and proportional to the data classification to be accessed, business requirements, and acceptable risk?

HRS-01.3 Are background verification policies and procedures reviewed and updated at least annually?

HRS-02.1 Are policies and procedures for defining allowances and conditions for the acceptable use of organizationally-owned or managed assets established, documented, approved, communicated, applied, evaluated, and maintained?

HRS-02 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures for defining allowances and conditions for the acceptable use of organizationally-owned or managed assets. Review and update the policies and procedures at least annually.

Acceptable Use of Technology Policy and Procedures
HRS-02.2Are the policies and procedures for defining allowances and conditions for

the acceptable use of organizationally-owned or managed assets reviewed and updated at least annually?

HRS-03.1 Are policies and procedures requiring unattended workspaces to conceal confidential data established, documented, approved, communicated, applied, evaluated, and maintained?

HRS-03 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures that require unattended workspaces to not have openly visible confidential data. Review and update the policies and procedures at least annually.

Clean Desk Policy and Procedures
HRS-03.2Are policies and procedures requiring unattended workspaces to conceal confidential

data reviewed and updated at least annually?

HRS-04.1 Are policies and procedures to protect information accessed, processed, or stored at remote sites and locations established, documented, approved, communicated, applied, evaluated, and maintained?

HRS-04 Establish, document, approve, communicate, apply, evaluate and maintain policies and procedures to protect information accessed, processed or stored at remote sites and locations. Review and update the policies and procedures at least annually.

Remote and Home Working Policy and Procedures
HRS-04.2Are policies and procedures to protect information accessed, processed, or

stored at remote sites and locations reviewed and updated at least annually?

HRS-05.1 Are return procedures of organizationally-owned assets by terminated employees established and documented?

HRS-05 Establish and document procedures for the…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .