Attachment 4 - Cloud Questionnaire.docx
DOCX document 23 KB Posted
- Attached to
- Community Profiles for the Non-DoD Program Federal contract opportunity
- Solicitation number
- HE125420Q0026
- Issued by
- Department of Defense Education Activity
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| HE125420Q0026 - QASP revised.docx | DOCX document | |
| Amend 0001.pdf | ||
| Attachment 5-QA.pdf | ||
| HE125420Q0026 - QASP.docx | DOCX document | |
| Attachment 2 - Government Product Accessibility Template (GPAT).docx | DOCX document | |
| HE125420Q0026.docx | DOCX document | |
| Attachment 1 - Pricing Sheet.xlsx | XLSX spreadsheet | |
| Attachment 3 - Terms of Service Addendum.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
HE125420Q0026– Attachment 4 – Cloud Information Questionnaire DoDEA Cloud Questionnaire Directions
· The Department of Defense Education Activity (DoDEA) must review each vendor’s cloud-based solution individually to determine if it is compatible with DoD’s guidelines. The answers you provide to this questionnaire will enable us to do that evaluaton quickly and effectively. Your assistance is much appreciated
· Please provide the point(s) of contact should DoDEA have questions about your response.
· Any proprietary or sensitive security information provided in response to this questionnaire will be protected and not shared outside of the U.S. Government.
Client Systems Software and Configuration
1. Is any software required for this service, e.g., software that must be installed on DoDEA computers, to include browser extensions and plugins? Has this software been made available for this review?
2. Is this a standalone or networked application? Will DoDEA need to stand up servers to support this application?
3. Are there any configurations or changes that DoDEA must implement to either its computers or browsers to utilize this service?
Privacy Information Data Collection and Distribution
1. What personally identifiable and sensitive information is collected by this service?
2. What, if any, personally identifiable and sensitive information is collected by third parties or by external business partners (e.g., via cookies, plug-ins, ad networks, web beacons etc.)?
3. Is any DoDEA data provided to third parties or external business partners for any purpose? If yes provide a list of all third-party or external business partner recipients
4. Do third parties or external business partner recipients of DoDEA data adhere to the same policies and processes to protect DoDEA data?
5. Describe the process to opt-out of any transfers of DoDEA data to third parties or external business partner recipients.
6. Which, if any, of the following requirements does your cloud service meet:
a. Children's Online Privacy Protection Act (COPPA), per http://www.coppa.org/coppa.htm?
b. Family Educational Rights and Privacy Act (FERPA), per http://www2.ed.gov/policy/gen/guid/fpco/ferpa/index.html?
c. Children's Internet Protection Act (CIPA), per http://www.fcc.gov/guides/childrens-internet-protection-act?
System Management and Security
1. How is system penetration testing, vulnerability management, and intrusion prevention managed?
2. Are software updates and patches routinely or automatically installed on all servers?
3. Are software and hardware lifecycle management procedures in place to replace end-of-life products?
4. Is the system, including its server(s) and network devices, located in secure facilities under controlled circumstances (e.g., authorized personnel access lists, ID cards, entry logs)?
5. Are server(s) and network devices located in an environmentally-controlled facility?
Data Storage, Retention, and Access
1. Where will information be stored? Will any data be stored outside the United States?
2. How is information stored and transmitted?
a. How does the provider protect data at rest, i.e., data in the data center? What data is encrypted: passwords, privacy information, etc.?
b. Is data secured with unique encryption keys for each customer on systems hosting multiple customers?
c. How does the provider protect data in transit, e.g., Secure Socket Layer (SSL), hashing, etc.?
1. Who has access to information stored or processed by the provider?
2. Are background checks completed on personnel with access to servers, applications and customer data?
3. What is the process for authenticating callers and resetting access controls, as well as establishing and deleting accounts?
4. How is school/system data deleted? Is it deleted on a specific schedule or only at the termination of the contract?
Development and Change Management Process
1. Are there standardized and documented procedures for coding, configuration management, patch installation, and change management for all servers and network devices involved in delivery of contracted services?
2. What is the customer notification process for any changes made to corporate policies for data protection?
3. Audits and Standards
a. What is the process for DoDEA to audit the security and privacy of records?
b. Are the security operations reviewed or audited by an outside group?
c. What security standard is followed, e.g., the International Organization for Standardization (ISO) and Payment Card Industry Data Security Standards (PCI DSS)?
Test and Development Environments
1. Will “live” student/privacy data be used in non-production (e.g., test or development, training) environment?
2. If so, are these environments secure to the same standard as production data?
Data Breach, Incident Investigation and Response
1. What is the process to manage a data breach?
2. Availability
a. Is there a guaranteed service level? If so describe?
b. What is the backup-and-restore process in case of a disaster?
c. What protection is in place against denial-of-service attack?
3. What is the process to perform security incident investigations or e-discovery?
DoDEA Cloud Questionnaire 3
File details come from the government source that posted it. Updated .