Attachment A Certificate of Media Santization (002).docx

DOCX document 568 KB Posted

Attached to
Penetration Testing State and local contract opportunity
Solicitation number
25RFP13436
Issued by
Minnehaha County, South Dakota

About this file

This document is a Certificate of Media Sanitization form for a state government data center, specifically related to data management and security protocols. The form provides a structured template for documenting the secure erasure of digital media, with sections for requestor details, data classification, sanitization process, verification, and approvals. The form is designed to comply with the state's Information Technology Security Policy (ITSP-Contractor 230.77) and requires detailed tracking of media sanitization, including the type of media, sanitization method, verification process, and potential reuse of media.

The document emphasizes strict security protocols for handling confidential data, with specific attention to different data classifications (low, moderate) and sensitivity levels such as FTI (Federal Tax Information), ePHI (electronic Protected Health Information), FPLS (Federal Parent Locator Service), and CJIS (Criminal Justice Information Services). The form mandates separate individuals for conducting sanitization and verification, requires comprehensive documentation of the sanitization process, and must be approved by the Data Center Director, in this case Wayne Hayden-Moreland. The certificate must be sent to the state contact and is not intended for public distribution, underscoring the confidential nature of the data management process.

View the file

Other files for this state and local contract opportunity

Other files attached to Penetration Testing, newest first.
File Type Posted
Attachment A Certificate of Media Santization (002).docx DOCX document
Attachment B ITSP.pdf PDF
Attachment C Contractor Security Acknowledgement Form (002).docx DOCX document
RFP Document.pdf PDF
Response to Offeror Questions document.pdf PDF
Attachment C Contractor Security Acknowledgement Form (002).docx DOCX document
RFP Document.pdf PDF
Attachment B ITSP.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Certificate of Media Sanitation for Offsite Data

Instructions

1. Follow State security policy in Information Technology Security Policy- Contractor 230.77, (ITSP- Contractor) the policy can also be found at bit.sd/gov/vendor/default.aspx.

2. Fill out the required section of this form and obtain approvals.

3. Send the completed certificate to the State Contact.

Section 1. Required

Requestor Name Company Email Phone Classification of the confidentiality of the data [Person filling out this form, requesting the sanitization]

[Example- Moderate, see ITSP- Contractor 230.77, Data Classification Table can be found on the Vendor Information webpage.]

Data Owner State Contact [The State agency that is the data owner Current State agency contact]

Person conducting the sanitization Company Email Phone

Database Name

Type of media Model Serial Number [For example- Hard Drive HPE model # 512547-B21 12345]

If there are copies of the data, list the location

Type of sanitization Method used to sanitize Tool used to sanitize [For example- Purged Microsoft SQL Server purge function Microsoft SQL Server 2014]

Was the data one of the following:
☐ FTI ☐ ePHI ☐ FPLS ☐ CJIS

Person who verified the sanitization Date Email Phone [This person should be different then the person doing the sanitization.]

Verification Method

Verification Notes

If the media was reused what are the destination details
[Example- Media was reused by (name) data center. Note only data that is classified low or moderate confidentiality can be reused, see ITSP- Contractor 230.77.]

Section 2. Approvers

Approvers
Signature
Date

[Name of Sanitizer]

[Name of Verifier]

Wayne Hayden-Moreland Data Center Director

This certificate must be sent to the State Contact who will send it to the Data Center Director. Electronic copies are acceptable.

Page | 1 02/22/2019

NOT FOR PUBLIC DISTRIBUTION

image1.jpeg image2.emf image3.png

File details come from the government source that posted it. Updated .