Attachment_4_CloudQuestionnaire.docx
DOCX document 37 KB Posted
- Attached to
- AMD 3: Prekindergarten Instructional Materials Federal contract opportunity
- Solicitation number
- HE125421Q0016
- Issued by
- Department of Defense Education Activity
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| AMD3_21Q0016_RFQ_5-13-21.pdf | ||
| 21Q0016_Attachment5_QA_5_13_21.pdf | ||
| AMD1_21Q0016_RFQ_5-3-21.pdf | ||
| HE125421Q0016_RFQ_4-26-21.pdf | ||
| Attachment_3_Terms of Service Addendum.docx | DOCX document | |
| Attachment 1-Pricing Sheet.xlsx | XLSX spreadsheet | |
| Attachment_2_Government Product Accessibility Template (GPAT).docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DoDEA Cloud Questionnaire Directions
The Department of Defense Education Activity (DoDEA) must review each vendor’s cloud-based solution individually to determine if it is compatible with DoD and DISA’s guidelines. Your answers to this questionnaire will enable us to do that evaluaton quickly and effectively. Please provide the point(s) of contact should DoDEA have questions about your response. Click or tap here to enter text.
Please note:
· Any proprietary or sensitive security information provided in response to this questionnaire will be protected and not shared outside of the US Government.
· Links to webpages will be considered an unacceptable anwer to the question but can be provided as supporting documantion.
· Answering “N/A” or “Not Applicable” alone will be considered an unacceptable response.
Client Systems Software and Configuration
1. Is any software required for this service, e.g., software that must be installed on DoDEA computers to include browser extensions and/or plugins? If so, has this software been made available for this review?
Click or tap here to enter text.
2. Is this a cloud based, standalone or networked solution/application? Will DoDEA need to stand up servers to support this application?
Click or tap here to enter text.
3. Are there any configurations or changes that DoDEA must implement to any of its computers, browsers or firewalls to utilize this service?
Click or tap here to enter text.
Privacy Information Data Collection and Distribution
1. What personally identifiable and sensitive information is collected by this service?
Click or tap here to enter text.
2. What, if any, personally identifiable and sensitive information is collected by third parties or by external business partners (e.g., via cookies, plug-ins, ad networks, web beacons etc.)?
Click or tap here to enter text.
3. Is any DoDEA data provided to third parties or external business partners for any purpose? If yes provide a list of all third-party or external business partner recipients.
Click or tap here to enter text.
4. Do third parties or external business partner recipients of DoDEA data adhere to the same policies and processes to protect DoDEA data?
Click or tap here to enter text.
5. Describe the process to opt-out of any transfers of DoDEA data to third parties or external business partner recipients.
Click or tap here to enter text.
6. Which, if any, of the following requirements does your cloud service meet:
a. Children's Online Privacy Protection Act (COPPA), per https://www.congress.gov/bill/105th-congress/senate-bill/2326/text Click or tap here to enter text.
b. Privacy Act of 1974, per https://www.justice.gov/opcl/overview-privacy-act-1974-2020-edition Click or tap here to enter text.
c. Family Educational Rights and Privacy Act (FERPA), per https://www2.ed.gov/policy/gen/guid/fpco/ferpa/index.html Click or tap here to enter text.
d. Children's Internet Protection Act (CIPA), per http://www.fcc.gov/guides/childrens-internet-protection-act?
Click or tap here to enter text.
System Management and Security
1. How is system penetration testing, vulnerability management, and intrusion prevention managed?
Click or tap here to enter text.
2. How often is penetration testing performed against the application?
Click or tap here to enter text.
3. Are software updates and patches routinely or automatically installed on all servers?
Click or tap here to enter text.
4. Are software and hardware lifecycle management procedures in place to replace end-of-life products?
Click or tap here to enter text.
5. Is the system, including its server(s) and network devices, located in secure facilities under controlled circumstances (e.g., authorized personnel access lists, ID cards, entry logs)?
Click or tap here to enter text.
6. Are server(s) and network devices located in an environmentally controlled facility?
Click or tap here to enter text.
Data Storage, Retention, and Access
1. Where will information be stored? Will any data be stored outside the United States?
Click or tap here to enter text.
2. How will the transfer of any Sensitive, Confidential data including but not limited to PII data be transferred?
Click or tap here to enter text.
3. How is information stored and transmitted?
a. How does the provider protect data at rest, i.e., data in the data center? What data is encrypted: passwords, privacy information, etc.?
Click or tap here to enter text.
b. Is data secured with unique encryption keys for each customer on systems hosting multiple customers? If no unique encryption key is used provide a detailed description/artifact that explains how the database is encrypted and stored and in securing DoDEA's data between tenants.
Click or tap here to enter text.
c. How is data protected in transit, e.g., secure socket layer (SSL), hashing, etc.?
4. Who has access to information stored or processed by the provider?
5. Are background checks completed on personnel with access to servers, applications and customer data? If so, describe type and frequency.
Click or tap here to enter text.
6. What is the process for authenticating callers and resetting access controls, as well as establishing and deleting accounts?
Click or tap here to enter text.
7. How is school/system data deleted—on a specific schedule or only upon contract termination?
Click or tap here to enter text.
Development and Change Management Process
1. Are there standardized and documented procedures for coding, configuration management, patch installation, and change management for all servers and network devices involved in delivery of contracted services?
Click or tap here to enter text.
2. What is the customer notification process for any changes made to corporate policies for data protection?
Click or tap here to enter text.
3. Audits and Standards
a. What is the process for DoDEA to audit the security and privacy of records?
Click or tap here to enter text.
b. Are the security operations reviewed or audited by an outside group? If so, what is the frequency? If not, how are security operations reviewed or audited?
Click or tap here to enter text.
c. What security standard is followed, e.g., the International Organization for Standardization (ISO), National Institute of Standards and Technology (NIST) and Payment Card Industry Data Security Standards (PCI DSS)?
Test and Development Environments
1. Will “live” student/privacy data be used in a non-production environment, e.g., in testing, development, or training)? If so, are these environments secure to the same standard as production data?
Click or tap here to enter text.
Data Breach, Incident Investigation and Response
1. Availability
a. Is there a guaranteed service level? If so describe?
Click or tap here to enter text.
b. What is the backup-and-restore process in case of a disaster?
Click or tap here to enter text.
c. What protection is in place against denial-of-service attack?
Click or tap here to enter text.
2. What is the process in managing a data breach?
Click or tap here to enter text.
3. What is the process to perform security incident investigations or e-discovery?
Click or tap here to enter text.
DoDEA Cloud Questionnaire 3 Revised 27 November 2020 Changes to this form must go thru DoDEA CyberSecurity
File details come from the government source that posted it. Updated .