Attachment_5_Cloud Questionnaire.pdf

PDF 189 KB Posted

Attached to
DoDEA K-12 Digital Learning Focus Requirements Federal contract opportunity
Solicitation number
HE125422Q3000
Issued by
Department of Defense Education Activity

About this file

This document contains a cloud questionnaire and details of a related federal contract opportunity. The cloud questionnaire requests information from vendors on their cloud-based solution, including what software or configurations are required, how privacy and personally identifiable information is collected and protected, how systems are managed and secured, how data is stored, transmitted, accessed and deleted. It also inquires about development and change management processes, use of test environments, and data breach response.

The related federal contract opportunity is a solicitation from the Department of Defense Education Activity seeking proposals for access to enterprise licenses for online digital resources across key subjects for K-12 students and teachers. The digital resources should be age-appropriate, interactive and meet national standards.

View the file

Other files for this federal contract opportunity

Other files attached to DoDEA K-12 Digital Learning Focus Requirements, newest first.
File Type Posted
HE125422Q30000_K-12 Digital Learning Focus_Amendment_0001.pdf PDF
Attachment_6_K-12 Digital Learning Focus_ QASP.pdf PDF
K-12 Digital Learning Focus solicitation.pdf PDF
Attachment_1_PWS_K-12 Digital Learning Resources.pdf PDF
Attachment_2_K-12 Digital Learning Focus_Pricing Sheet.xlsx XLSX spreadsheet
Attachment_3_GPAT_.pdf PDF
Attachment_4_Terms of Service.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

HE1254‐22‐Q‐3000 – Attachment 5– DoDEA Cloud Questionnaire All sections and questions must be addressed on each of the IT compliance forms with a supporting narrative statement. If a question/sections is not applicable to the service/product Vendors offer, it must be marked “Not Applicable.”

DoDEA Cloud Questionnaire Directions

The Department of Defense Education Activity (DoDEA) must review each vendor’s cloud-based solution individually to determine if it is compatible with DoD and DISA’s guidelines. Your answers to this questionnaire will enable us to do that evaluaton quickly and effectively. Please provide the point(s) of contact should DoDEA have questions about your response. Please note:

Any proprietary or sensitive security information provided in response to this questionnaire will be protected and not shared outside of the US Government.

Links to webpages will be considered an unacceptable anwer to the question but can be provided as supporting documantion.

Answering “N/A” or “Not Applicable” alone will be considered an unacceptable response.

Client Systems Software and Configuration

1. Is any software required for this service, e.g., software that must be installed on DoDEA computers to include browser extensions and/or plugins? Has this software been made available for this review?

2. Is this a standalone or networked application? Will DoDEA need to stand up servers to support this application?

3. Are there any configurations or changes that DoDEA must implement to any of its computers, browsers or firewalls to utilize this service?

Privacy Information Data Collection and Distribution

1. What personally identifiable and sensitive information is collected by this service?

2. What, if any, personally identifiable and sensitive information is collected by third parties or by external business partners (e.g., via cookies, plug-ins, ad networks, web beacons etc.)?

3. Is any DoDEA data provided to third parties or external business partners for any purpose? If yes provide a list of all third-party or external business partner recipients.

4. Do third parties or external business partner recipients of DoDEA data adhere to the same policies and processes to protect DoDEA data?

5. Describe the process to opt-out of any transfers of DoDEA data to third parties or external business partner recipients.

6. Which, if any, of the following requirements does your cloud service meet:

All sections and questions must be addressed on each of the IT compliance forms with a supporting narrative statement. If a question/sections is not applicable to the service/product Vendors offer, it must be marked

a. Children's Online Privacy Protection Act (COPPA), per https://www.congress.gov/bill/105th-congress/senate-bill/2326/text

b. Privacy Act of 1974, per https://www.justice.gov/opcl/overview-privacy-act-1974-2020-edition

c. Family Educational Rights and Privacy Act (FERPA), per https://www2.ed.gov/policy/gen/guid/fpco/ferpa/index.html

d. Children's Internet Protection Act (CIPA), per http://www.fcc.gov/guides/childrens-internet-protection-act?

System Management and Security

1. How is system penetration testing, vulnerability management, and intrusion prevention managed?

2. How often is penetration testing performed against the application?

3. Are software updates and patches routinely or automatically installed on all servers?

4. Are software and hardware lifecycle management procedures in place to replace end-of-life products?

5. Is the system, including its server(s) and network devices, located in secure facilities under controlled circumstances (e.g., authorized personnel access lists, ID cards, entry logs)?

6. Are server(s) and network devices located in an environmentally controlled facility?

Data Storage, Retention, and Access

1. Where will information be stored? Will any data be stored outside the United States?

2. How will the transfer of any Sensitive, Confidential data including but not limited to PII data be transferred?

3. How is information stored and transmitted?

a. How does the provider protect data at rest, i.e., data in the data center? What data is encrypted:

passwords, privacy information, etc.?

b. Is data secured with unique encryption keys for each customer on systems hosting multiple customers? If no unique encryption key is used provide a detailed description/artifact that explains how the database is encrypted and stored and in securing DoDEA's data between tenants.

c. How is data protected in transit, e.g., secure socket layer (SSL), hashing, etc.?

4. Who has access to information stored or processed by the provider?

All sections and questions must be addressed on each of the IT compliance forms with a supporting narrative statement. If a question/sections is not applicable to the service/product Vendors offer, it must be marked

5. Are background checks completed on personnel with access to servers, applications and customer data?

If so, describe type and frequency.

6. What is the process for authenticating callers and resetting access controls, as well as establishing and deleting accounts?

7. How is school/system data deleted—on a specific schedule or only upon contract termination?

Development and Change Management Process

1. Are there standardized and documented procedures for coding, configuration management, patch installation, and change management for all servers and network devices involved in delivery of contracted services?

2. What is the customer notification process for any changes made to corporate policies for data protection?

3. Audits and Standards

a. What is the process for DoDEA to audit the security and privacy of records?

b. Are the security operations reviewed or audited by an outside group? If so, what is the frequency? If not, how are security operations reviewed or audited?

c. What security standard is followed, e.g., the International Organization for Standardization (ISO), National Institute of Standards and Technology (NIST) and Payment Card Industry Data Security Standards (PCI DSS)?

Test and Development Environments

1. Will “live” student/privacy data be used in a non-production environment, e.g., in testing, development, or training)? If so, are these environments secure to the same standard as production data?

Data Breach, Incident Investigation and Response

1. Availability

a. Is there a guaranteed service level? If so describe?

b. What is the backup-and-restore process in case of a disaster?

c. What protection is in place against denial-of-service attack?

2. What is the process in managing a data breach?

3. What is the process to perform security incident investigations or e-discovery?

(End of Attachment 5)

File details come from the government source that posted it. Updated .