Attachment B ITSP.pdf
PDF 1020 KB Posted
- Attached to
- Penetration Testing State and local contract opportunity
- Solicitation number
- 25RFP13436
- Issued by
- Minnehaha County, South Dakota
About this file
The document is the State of South Dakota's Bureau of Information & Telecommunications (BIT) Information Technology Security Policy (ITSP) Contractor Version 6.0, dated March 2025. This comprehensive policy document establishes cybersecurity guidelines, protocols, and expectations for contractors working with state technology infrastructure and data systems. The policy covers a wide range of security domains including background checks, confidentiality, data protection, mainframe and server security, network access control, authentication methods, application development, and information system management. It applies to all contractors and third-party vendors who interact with state technology resources, mandating strict adherence to security principles of confidentiality, integrity, and availability.
The policy outlines detailed requirements for contractors, including mandatory federal fingerprint-based background checks, multi-factor authentication, data encryption standards, and specific protocols for handling sensitive information such as Federal Tax Information (FTI), Protected Health Information (PHI), and Personally Identifiable Information (PII). Contractors must sign security acknowledgement forms, undergo periodic security assessments, and comply with evolving security standards. The document establishes clear responsibilities for various stakeholders, including the Chief Information Security Officer (CISO), Security Infrastructure Team (SIT), and Security Operations Team (SOT), and provides specific guidelines for managing access, preventing unauthorized activities, and maintaining the security of state technology assets across different network zones and computing environments.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment C Contractor Security Acknowledgement Form (002).docx | DOCX document | |
| RFP Document.pdf | ||
| Response to Offeror Questions document.pdf | ||
| Attachment A Certificate of Media Santization (002).docx | DOCX document | |
| Attachment A Certificate of Media Santization (002).docx | DOCX document | |
| Attachment B ITSP.pdf | ||
| Attachment C Contractor Security Acknowledgement Form (002).docx | DOCX document | |
| RFP Document.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Information Technology
Security Policy Contractor Version 6.0
March 2025
Attachment B
Page | 2
Information Technology Security Policy
CONTRACTOR
NOT FOR PUBLIC DISTRIBUTION 03/2025
General-Information Technology Security Policy-Introduction
1.1.4.1. General
1.1.4.2. Chief Information Security Officer
1.1.4.3. Security Infrastructure Team (SIT)
1.1.4.4. Security Operations Team (SOT)
1.1.4.5. BIT Executive Working Group on Cyber Security
Administrative-I/T Asset Protection-Background Checks
10.1.4.1. Background Checks
10.1.4.2. Disqualifying Criteria
10.1.4.3. Noncriminal Agency Coordinator (NAC)
10.1.4.4. Local Agency Security Officer (LASO)
10.1.4.5. Background Check Interpretation
10.1.4.6. Not Guilty Presumption
10.1.4.7. Background Check Information Challenge
10.1.4.8. Corrective Action
10.1.4.9. Training
10.1.4.10. Emailing Background Check Information
Administrative-I/T Asset Protection-Confidentiality
10.3.4.1. Confidentiality Agreement
10.3.4.2. Security Acknowledgement and Access
Administrative-I/T Asset Protection-Governance of Regulated Data within Information Systems
10.11.4.1. Acquisitions
10.11.4.2. Contracts with Third Parties
10.11.4.3. Third Party Management Requirements (HIPAA, IRS) - DSS
Mainframe-Mainframe Security-Mainframe Accounts
210.3.4.1. Unique Account Requirement
210.3.4.2. Requests for Mainframe User IDs
210.3.4.3. Responsibility for Mainframe User IDs and Passwords
Mainframe-Mainframe Security-Mainframe Accounts
210.4.4.1. Mainframe User ID Revocation
Mainframe-Mainframe Security-Mainframe Access
210.25.4.1. Mainframe Access
Server-Server Security-Server Maintenance and Administration
220.1.4.1. Visibility of Server and Framework Patching Status
Server-Server Security-File Transfer Protocol
220.7.4.1. Use of File Transfer Protocol Server
Server-Server Security-Assurance HIPAA Regulations are Met
220.10.4.1. The Data User is Responsible for Adhering to HIPAA Regulations
Data Center General-Data Center Security-Cloud Based Services and System Information
Page | 3
CONTRACTOR
NOT FOR PUBLIC DISTRIBUTION 03/2025
230.9.4.1. Responsibility for Cloud Based Services and Systems
Data Center General-Data Center Security-Federal Tax Information and Federal Parent Locator Service Information
230.11.4.1. Federal Tax Information Returns and Return Information
230.11.4.2. What is Not Federal Tax Information
230.11.4.3. Safeguarding Federal Tax Information
230.11.4.4. Emailing Federal Tax Information
Data Center General-Procedural-Physical Access - Proximity Cards
230.58.4.1. Proximity Card for Non-BIT Employee Access
230.58.4.2. Physical Access to BIT Offices
Data Center General-Data Center Security-Accounts Access Control and Authorization
230.67.4.1. Individual Access Authorization
230.67.4.2. Least Privilege
230.67.4.3. Password Requirements
230.67.4.4. Individual Access Termination
230.67.4.5. Non-State Accounts
Data Center General-Payment Card Industry Data Security-Payment Card Industry Data Security Standard
230.72.4.1. Payment Card Industry Data Security Standard Requirements
Data Center General-Secure Information Technology Acquisition Policy-Secure Information Technology Acquisition Policy
230.73.4.1. Acquisition of Services Involving HIPAA Data
230.73.4.2. Security Scanning Requirements
230.73.4.3. Hardware Maintenance Agreements
Data Center General-Use of Production Data-Use of Production Data in a Non-Production Environment . 33
230.74.4.1. Use of Production Data in a Non-Production Environment
230.74.4.2. Purging of Data
230.74.4.3. Compliance
Data Center General-Security Impacts-Data Classification
230.75.4.1. Data Classification System
230.75.4.2. Classification of Data Produced under Contract
230.75.4.3. Data Classification Responsibilities
Data Center General-Remote Access to State Information System-Multi-Factor Authentication
230.76.4.1. Usage of Multi-Factor Authentication (MFA)
230.76.4.2. MFA Tokens
Data Center General-Approved Disposal of State Data-Media Sanitization
230.77.4.1. Sanitization of Media in a Contractor's Control
Data Center General-Transfer of Data-Secure Transfer of Data
230.78.4.1. Use of Secure File Transfer Protocol
Development-Application Security-Federal Tax Information
Page | 4
CONTRACTOR
NOT FOR PUBLIC DISTRIBUTION 03/2025
401.1.4.1. Allocation of Resources and Life Cycle Support
401.1.4.2. Information System Security Documentation
401.1.4.3. Software Usage Restrictions and User Installed Software
401.1.4.4. Developer Configuration Management
Development-Application Security-Security Assessments
401.3.4.1. Security Assessments
401.3.4.2. APM Assessment of Risk
401.3.4.3. Security Assessment Report
401.3.4.4. Annual Review
Development-Application Security-Data Encryption
401.5.4.1. Data Encryption
401.5.4.2. Hashing Values
401.5.4.3. Tools
401.5.4.4. Compliance Measurements
401.5.4.5. Exceptions
401.5.4.6. Non-Compliance
Development-Application Security-Authentication and Authorization
401.7.4.1. User Authentication and Authorization
401.7.4.2. Password Requirements
401.7.4.3. Invalid Login Attempts for projects using Federal Tax Information
401.7.4.4. reCAPTCHA
401.7.4.5. Public Key Infrastructure Certificates
401.7.4.6. Tools
401.7.4.7. Compliance Measurements
401.7.4.8. Exceptions
401.7.4.9. Non-Compliance
Development-Application Security-Software Development Life Cycle
401.9.4.1. Software Development Life Cycle
401.9.4.2. Change Management
Network-Service-Access Control
610.1.4.1. System Access Expectations
610.1.4.2. Contractor Access
610.1.4.3. Modems
610.1.4.4. Remote Access
610.1.4.5. Inspection and Review
610.1.4.6. Department of Social Services
Network-Concept-Security Domain Zones
610.3.4.1. Intranet
610.3.4.2. DMZ
Page | 5
CONTRACTOR
NOT FOR PUBLIC DISTRIBUTION 03/2025
610.3.4.3. Extranet
Network-Concept-Network Integrity
610.9.4.1. Responsibilities
610.9.4.2. Management
610.9.4.3. Disabling Critical Components of Network Security Infrastructure
610.9.4.4. Technical Asset or Contractor Connections
610.9.4.5. Local Area Network
610.9.4.6. Wide Area Network
610.9.4.7. Physical Controls
Network-Communication-Internet
610.11.4.1. Multiple Connections
610.11.4.2. Interfaces
610.11.4.3. Security
610.11.4.4. Responsibilities
610.11.4.5. IPv4/IPv6 and Device Names
Security-Network Discovery-Probing-Exploiting
620.1.4.1. Limiting Tool Functionality
620.1.4.2. Exploiting Security Controls of Information Systems
620.1.4.3. Cracking Application or Passwords
620.1.4.4. Exemptions
Security-Content Control-Internet Filtering
620.5.4.1. Exemptions
620.5.4.2. Appropriate Use of Administrator Access
620.5.4.3. DDN Content Filtering
620.5.4.4. DDN Intranet Content Filtering
620.5.4.5. Filter Exemption Requests
Page | 6
CONTRACTOR
NOT FOR PUBLIC DISTRIBUTION 03/2025
ITSP Change Log
Policy Number Policy Title New Revised Deleted
1.1.4.2 Chief Information Security Officer 03/01/2020
10.1 Background Checks 03/01/2020
10.11 Governance of Regulated Data within Information
Systems
03/01/2020
230.10.4.1 Hardware Maintenance Agreements 03/01/2020
230.11 Federal Tax Information and Federal Parent
Locator Service Information
03/01/2020
230.58.4.2 Physical Access to BIT Offices 03/01/2020
230.67.4.5 Non-State Accounts 03/01/2020
230.70.4.1 Authentication for Remote Access to the Data
Center
03/01/2020
230.73.4.10 Banned Hardware 03/01/2020
401.1.4.4 Developer Configuration Management 03/01/2020
401.3.4.2 APM Assessment of Risk 03/01/2020
401.3.4.3 Security Assessment Report 03/01/2020
401.3.4.4 Annual Review 03/01/2020
401.9 Software Development Life Cycle 03/01/2020
410.1 Azure DevOps Server 03/01/2020
Staff Augmentation Contractors must follow the BIT Version of the ITSP.
Page | 7
CONTRACTOR
NOT FOR PUBLIC DISTRIBUTION 03/2025
General-Information Technology Security Policy-Introduction
1.1.1. Overview
This Information Technology (IT) Security Policy has been developed by the Bureau of Information & Telecommunications (BIT) of the State of South Dakota. The Information Technology Security Policy provides guidance regarding cyber security policies of the State relevant to the IT goals, beliefs, ethics, and responsibilities. Specific procedures that State employees and contractors must follow to comply with the security objectives are identified.
The objective of the Information Technology Security Policy is to provide a comprehensive set of cyber security policies detailing the acceptable practices for use of State of South Dakota IT resources. The security policies and procedures set forth are to accomplish the following:
• Assure proper implementation of security controls within the BIT environment.
• Assure government data is protected regardless of hosting location.
• Demonstrate commitment and support to the implementation of security measures by BIT and Executive management.
• Avoid litigation by documenting acceptable use of State IT resources.
• Achieve consistent and complete security across the diverse technology infrastructure of the State and hosted State data.
The Information Technology Security Policy, when combined with individual, specific security procedures, provides a comprehensive approach to security planning and execution to ensure that State managed assets are afforded appropriate levels of protection against destruction; loss; unauthorized access, change, or use; and disruption or denial of service.
BIT is responsible for maintaining and updating this policy. An updated version of the Information Technology Security Policy will be posted to the Intranet annually the first of March. The Commissioner of BIT or the Chief Information Security Officer can authorize an out of cycle or special edition to be released.
Information Technology Security is based on three principles:
• Confidentiality
• Integrity
• Availability Confidentiality - ensuring that only permitted individuals are able to view information pertinent to apply defined responsibilities.
Integrity - the information is accurate because nothing has been changed or altered.
Availability - the technology infrastructure and services built upon that infrastructure are not intentionally disrupted and are available for use by the clientele in a dependable and reliable manner.
Each individual policy defined herein falls within one or more of these guiding principles.
Information Technology security requires on-going vigilance, and employees should understand the importance of cyber security in the protection of State data and technology resources along with the personal/home computing/data assets of every individual. Guardianship of State data, infrastructure, and applications is a critical priority for BIT. The effort is complicated by the balance needed between usability/service and meaningful protection.
BIT Mission Statement
The Bureau of Information and Telecommunications (BIT) strives to partner and collaborate with clients in support of their missions through innovative information technology consulting, systems, and solutions.
Page | 8
CONTRACTOR
NOT FOR PUBLIC DISTRIBUTION 03/2025
Vision Through our highly motivated staff - we will be a Leader and valued partner in providing technology solutions, services, and support that directly contribute to the success of our clients.
Goals:
Provide a Reliable, Secure and Modern Infrastructure.
Provide a well-designed and architected secure computing and communications environment to ensure optimal service delivery to business. Architecture and process will be optimized to support agile and reliable computing and communication services.
Technology assets must be high performing and dependable to ensure services are available whenever needed.
Centralization, standardization, and collaboration are vital to efficiently leverage investments. To maintain public trust, we must secure data and technology assets through leading security tools, policies, and practices.
Deliver Valuable Services at Economical Costs.
Develop innovative and cost-effective solutions through collaboration, cooperation, and in partnership with our clients. The solution sets include developing customized business solutions, efficient project management services, and productive relationships with clients.
Regarding our citizens interacting with their government: "People should be online, not waiting in line."
Build and Retain a Highly Skilled Workforce.
Improve the effectiveness, productivity, and satisfaction of employees in order to attract (and retain) a highly qualified workforce to foster individual innovation and professional growth. Appropriate training and tools will be provided to enhance and improve career skills in the workforce.
Information technology systems are critical, valuable assets. Policies relating to the valuable assets are important to ensure that all entities receive adequate information to enable the department, office, and agency to provide a basic level of protection to the technology systems.
Security is not accomplished at a single point or by a single individual! (Or in a single point in time!)
Instead of relying on one person or a firewall or anti-virus software or some other single piece of hardware or software, a series of assets and entities together build a safe computing environment. Technically, a layered approach is taken to accomplish security within the State which is called the Information Technology (IT) Security Model. A foundation is established; additional layers may build on the previous layer or may also act independently to provide separate security measures. Each point of accessibility into the wired and wireless network creates security concerns. Security is not limited to technology. A critical portion of cyber security is the human aspect.
Information Technology Security Model The different technology layers of the Information Technology Security Model create opportunities for implementing security:
• User Education involves the training of employees to ensure that proper awareness is brought to the topic of security including steps to take when incidents occur that are outside of the scope of the daily work routine.
• Physical Access is taking appropriate steps to physically safeguard technical equipment such as outlining procedures to prevent workstations from being stolen which can include limiting access to a particular room or locking up the device in a cabinet.
• Network Access includes protecting the State Network from unauthorized access via internal methods and from outside our physical offices. Because technology can be manipulated by individuals or workstations to create a detrimental outcome, safeguards must be implemented to prevent, thwart, and repel workstation attacks from inside State Government and the Internet; access protection is not limited to workstations, it includes smartphones, Internet of Thing devices, environmental controls, and network - network connectivity.
Page | 9
CONTRACTOR
NOT FOR PUBLIC DISTRIBUTION 03/2025
• Workstation Platform means taking advantage of the inherent feature sets of workstation platforms. For example, user id and password capabilities must be used as intended within the workstation platform.
• Cyber Strength Evaluation of business software must apply across in-house developed and third party built or supplied software applications. New applications must be tested before being placed into service and existing applications must be re-evaluated on a regular basis.
• Cyber security language is incorporated within all information technology (I/T) requests for proposals and I/T contracts.
• Information System security entails designing the necessary security features and permissions to ensure that only legitimized staff have proper resource access. The design must consider areas such as viewers of departmental data to individuals that can add data or update records.
• Data security is the protection of the asset; often referred to as the "money in the vault". Ensuring that data is only accessible by permitted applications and personnel is the core of the security model. The data could be credit card numbers, social security numbers, health records, or financial information.
Partners The IT Security model goal is to ensure that the hardware, software, and data technology assets of the State are protected in a reasonable and prudent manner. Planning, cooperation, and assistance from many different entities is required to meet the goal. The State has various partners in cyber security efforts. BIT must continue to evolve relationships with:
• State government of South Dakota branches, departments, and constitutional offices
• Internet Service Providers
• Multi-State Information And Sharing Center (MS ISAC)
• Department of Homeland Security
• State Fusion Center
• Federal Bureau of Investigation (FBI) - InfraGard program
• National Association of State Technology Directors (NASTD)
• National Association of Chief Information Officers (NASCIO)
• SysAdmin, Audit, Networking and Security (SANS)
• Microsoft, Inc.
• Symantec, Inc.
• US CERT
• A variety of hardware and software contractors.
All of these organizations contribute to the development of cyber security information sharing, policies, procedures, and metrics. In return, specific reporting is distributed amongst the partners.
Roles and Responsibilities In the application of information technology, BIT is responsible for providing leadership, policy, and technical support to all agencies of the Executive branch of the State of South Dakota. Also, various levels of support are provided to the Judicial branch, constitutional offices of government, K-12 education, and higher education. In addition to data center operations and related end user and customer support services, the broad statement of roles and responsibilities encompasses major information resource functions such as development, delivery, administration of voice, data, and video, applications - to include services, software, hardware selection, installation, and support.
Individual roles and responsibilities are defined herein; the following responsibilities are shared by all:
• Participate in information security awareness program activities.
• Read, understand, and follow the policies defined in the Information Technology Security Policy.
• Report all violations, security incidents, suspected, and/or attempted security incidents to BIT.
BIT Commissioner:
The Commissioner of the Bureau of Information & Telecommunications for the State of South Dakota is responsible for ensuring that:
• Reasonable security measures are taken to protect sensitive files and information.
• Enforceable security rules are created and disseminated.
Page | 10
CONTRACTOR
NOT FOR PUBLIC DISTRIBUTION 03/2025
• System resources are managed and monitored to ensure prudent and legitimate usage.
• Alleged security violations are addressed and problems are investigated.
• Designated individuals are responsible for design, configuration, and support of technology resources.
• Employees and Contractors are responsible for:
• Taking the time to read, understand, and ask questions if necessary to clarify the policies defined herein.
• Fully adhering to these policies defined herein.
• Agreeing that use of State technologies which includes equipment, applications, and resources are for work-related purposes.
• Applying recommended password policies.
• Safeguarding sensitive information whether employee / contractor is in the office or traveling for the State.
• Reporting any unusual requests for information or obvious security incidents to the BIT Service Desk.
• Immediately reporting loss of any State technology devices or data.
• Understanding that everyone is a potential target of nefarious individuals seeking 'social engineering' information to be used for illegally accessing State of South Dakota systems and technologies; Hence, be aware that any information provided to outside entities can be dangerous.
• Protecting information technology assets by following policies and procedures.
• Ensuring each individual is authorized to use a given technical asset.
• Understanding and complying with the policies, procedures, and laws related to conditions of use authorizing access to BIT systems and data.
• Not subverting or attempting to subvert security measures.
• Department, Office, Division, or Group Managers are responsible for:
• Creating, disseminating, and enforcing conditions of use for technology and applications in areas of responsibility.
• Responding to concerns regarding alleged or real violations of this policy.
• Ensuring that their employees understand security responsibilities.
• Monitoring the use of South Dakota technology resources by observing usage.
• Determining the access requirements of staff, and ensuring completion of the appropriate forms, including all required authorizations for the application(s) requested by insuring only legitimate staff have access to the set of functions needed to perform defined tasks.
• Communicating terminations and status changes of individuals immediately to the Bureau of Human Resources (BHR) through BHR-defined procedures so that BIT is notified to ensure proper deletion or revision of user access is performed.
• Ensuring a secure physical environment for the staff use of State equipment, information systems, and data.
• Bureau of Information & Telecommunications (BIT) is responsible for:
• Taking reasonable action to assure the authorized use and security of data, networks, applications, and communications amongst these technologies.
• Promptly responding to client questions on details relating to appropriate use of technical resources.
• Providing advice regarding the development of conditions of use or authorized use and procedures through work order requests.
• Ensuring that investigations into any alleged personal workstation or network security compromises, incidents, or problems are conducted.
• Ensuring that appropriate security controls are enabled and are being followed in coordination with BIT staff that are responsible for security administration.
• Verifying and authorizing individuals for an appropriate level of access to only the resources required to perform one's responsibilities.
• Overseeing that an individual has the necessary security authorizations in order for the person to perform assigned duties or tasks.
• Cooperating with appropriate departments, branches, agencies, and law enforcement officials in the course of investigation of alleged violations of policy or law.
• Overseeing the administration of BIT employee and contractor access to BIT facilities.
• Coordinating disaster recovery and testing exercises.
Page | 11
CONTRACTOR
NOT FOR PUBLIC DISTRIBUTION 03/2025
Data Owners
All data files, information, and applications belong to the State. Authorized users or agents of the data are the State of South Dakota departments, agencies, and offices. Files in central systems belong to the account owner. Data owners are responsible for:
• Tracking the data owned/managed by the agency and agency staff.
• Providing BIT notification within 24 hours of any notices regarding federal/state/or industry audits related to any aspects of an agency data, electronic communications, or data processing.
• Working with BIT to ensure access to the data and application(s) is limited to individuals with a legitimate need for the resource access.
• Ensuring that security measures and standards are implemented and enforced in a method consistent with BIT security policies and procedures.
• Establishing measures to ensure the integrity of the data and applications found within the owner's area of responsibility.
• Authorizing individual's appropriate security access rights for accessing the data and applications that are assigned to the data owner for administration.
• Periodically reviewing access rights to determine that the level is still appropriate for authorized users or the level needs to be changed.
• Assuring a process is in place to retain or purge information according to record retention schedules as set by the Records Management office of the Bureau of Administration or other entities.
• Determining the sensitivity and criticality of the data and application based on established Federal, State, and organizational definitions.
• Compliance with system security and integrity; noncompliance and enforcement; reservation of authority and rights is expected of all employees and contractors.
• All State and contractor personnel utilizing information technology resources shall cooperate fully with the cyber security policies of the State.
• The State reserves the right to take all necessary actions to prevent the State network and computing infrastructure from being used to attack, damage, harm, or improperly exploit any internal or external systems or networks.
• The State reserves the right to take all necessary actions to protect the integrity of the State network, the systems attached to the State network, and the data contained therein.
• Violations of federal, State regulations, or any laws respecting information technology will be considered serious matters that may warrant loss of applicable privileges, fines, or more serious action as necessary, to include but not limited, appropriate disciplinary action.
Individuals with questions concerning the policies described herein should be directed to either an immediate State supervisor or the BIT Service Desk for assignment to the most pertinent BIT Division.
Compliance and Enforcement:
All managers and supervisors are responsible for enforcing the Security Awareness policy.
Any disclosure of regulated data is subject to the Human Resource Polices of BHR.
1.1.2. Purpose
This Information Technology Security Policy contains information technology security policies to ensure that employees and contractors are familiar with the laws and regulations that govern use of IT systems and the data those systems contain.
1.1.3. Scope
The Information Technology Security Policy is intended to address the range of cyber security related topics. Detailed policies are listed and explained throughout the document. Security topics included are workstation, server, network, applications development, mobile, administrative, operational, and other IT areas.
Page | 12
CONTRACTOR
NOT FOR PUBLIC DISTRIBUTION 03/2025
The clientele served by BIT is very diverse. Including the Executive and Judicial branches of State government, local - municipal - county governments, K-12 schools, technical schools, and colleges and universities. Different policies will have a different set of impacted clienteles.
1.1.3.1. Scope Assumptions
The security policies listed within the Information Technology Security Policy apply to State employees and contractors working on or with State of South Dakota IT equipment, data, or services. All are expected to comply with BIT cyber security policies.
1.1.3.2. Scope Constraints
Contractors are not given any special privileges or dispensations regarding policies listed herein. Contractors are expected to follow all policies designated as an employee would follow them. Third party hosting companies also have a set of policies applicable to them. This set of policies is normally a subset of the entire BIT catalog of policies.
1.1.4. Policy
1.1.4.1. General
The policy of BIT is that information is considered a valuable asset and must be appropriately evaluated and protected against all forms of unauthorized access, use, disclosure, modification, or destruction. Security controls must be sufficient to ensure the confidentiality, integrity, availability, and accountability of sensitive and critical information processed and stored on BIT resources and other hosting parties. In addition to implementing the necessary safeguards, each State department, office, and agency is required to determine that the proper levels of protection for the information for that entity exists to include information that is under the control of the department, office, or agency. The security controls that must be applied will be consistent with the classification or value of the information and associated processes that the security controls are designed to protect. Information that is considered by management to be sensitive, critical, or sensitive and critical requires more stringent controls.
1.1.4.2. Chief Information Security Officer
The Commissioner of BIT shall appoint a Chief Information Security Officer (CISO) to implement the information technology security program for the State. The CISO shall seek to assure that information technology is secure at the State and shall be responsible for the following duties:
• Enforcing the provisions of the Information Technology Security Policy.
• Providing for and implementing, in cooperation with the Data Center, Development, and Telecommunications Divisions of BIT, a written process to investigate any violations or potential violations of this policy or any policy regarding system security and integrity, individually or in cooperation with any appropriate State law enforcement or investigative official.
• Implementing training and education programs to ensure government employees are aware of the risks and expected behaviors towards cyber security.
• Keeping a record of system integrity problems and incidents.
• Maintaining and updating the Information Technology Security Policies.
• Taking such emergency action as is reasonably necessary to provide system control where security is deemed to have been lost or jeopardized.
• Performing periodic security surveys.
• Providing for network security by seeking to preclude misuse of the network of the State to gain or attempt to gain unauthorized access to any system.
Page | 13
CONTRACTOR
NOT FOR PUBLIC DISTRIBUTION 03/2025
• Performing checks of information systems to assess system security and integrity, as well as to determine the use or placement of illegal or improper software or equipment.
• Coordinating the cyber security activities across BIT to ensure technology services and IT policies are effective in balancing security requirements vs. client needs.
• Ensuring processes are in place to remove all data before equipment is disposed or redeployed.
• Coordinating and consulting with the BIT Security Infrastructure Team (SIT), Executive Working Group on Cyber Security, other State departments, Board of Regents, K-12 community, federal Department of Homeland Security, and Multi-State Information Sharing and Analysis Center (MS-ISAC).
• Implementing decisions of the State concerning information technology security.
• Providing reports directly to the Office of the Governor where any serious security violation or potential challenge to security occurs.
• Leading the BIT Security Infrastructure Team.
• Leading the Executive Working Group on Cyber Security.
• Coordinating and entering into agreements with organizations on data-sharing.
1.1.4.3. Security Infrastructure Team (SIT)
The SIT shall, in coordination with the CISO, recommend technology solutions, written policies, and procedures necessary for assuring the security and integrity of State information technology. The SIT shall coordinate with the CISO in creating and implementing a written system to investigate any violations or potential violations of this policy or any policy regarding system security and integrity.
• The CISO shall appoint the Security Infrastructure Team members.
• The SIT shall be chaired by the CISO.
• At a minimum, the SIT communicates internally every two weeks, via a scheduled bi-weekly meeting or via email, the current security posture of the State.
• The SIT shall consist of at least one member from each of the BIT information technology divisions.
• The recommendation is that membership include multiple representation from development, systems integration, desktop support, networking.
• K-12, Regental, Judicial, Legislative, and other government entities can be invited at the discretion of the
CISO.
1.1.4.4. Security Operations Team (SOT)
The Security Operations Team (SOT) shall be appointed by the CISO. The SOT meets daily to review any cyber security findings or issues with the State Infrastructure within the previous day. The SOT includes members of the Telecommunications, Data Center, and Development divisions.
• Logs are fed into the State security information and event management system and are monitored by the SOT daily. These logs include firewall, intrusion detection, intrusion prevention, desktop protection, audit logs, etc.
• The SOT meets daily to review any findings or issues.
• Plans of action are established with assignments established based on the deficiencies.
The SOT can make recommendations and suggestions to the SIT for operational considerations.
1.1.4.5. BIT Executive Working Group on Cyber Security
The Executive Working group shall be informed and educated on matters regarding cyber security. They shall offer their perspective and feedback on technology, policies and other important matters.
Page | 14
CONTRACTOR
NOT FOR PUBLIC DISTRIBUTION 03/2025
• At the CISO's discretion, the members of the Working group shall come from the Executive, Judicial, Legislative branches of State government, constitutional offices, K-12 public schools and higher education, and other qualified individuals.
The Group shall meet quarterly at a minimum.
Administrative-I/T Asset Protection-Background Checks
10.1.1. Overview
As a condition of employment, all current and prospective Bureau of Information and Telecommunications (BIT) employees and Information Technology contractors desiring to work for the State shall be screened thoroughly including verification of qualifications. Prospective employees and contractors will be notified that a background check will be done as part of the recruiting and selection process. These verifications must be performed at least once every five years.
10.1.2. Purpose
Ensure that current and prospective BIT employees and Information Technology contractors do not have a criminal history that would raise suspicion as to the integrity of their employment.
10.1.3. Scope
Background checks shall be limited to criminal history available through State and Federal resources.
10.1.3.1. Scope Assumptions
The scope includes BIT employees and prospective BIT employees of the Administration, Data Center, Development, and Telecommunications Divisions, South Dakota Public Broadcasting studio engineers, field engineers, and network operations center staff as well as current and prospective Information Technology contractors desiring to work for the State.
10.1.3.2. Scope Constraints
Background checks are not performed for financial or credit information.
10.1.4. Policy
10.1.4.1. Background Checks
BIT requires all current and prospective BIT employees, State Technology contractors, and the South Dakota Public Broadcasting Engineering group who write or modify State of South Dakota-owned software, alter hardware, configure software of State-owned technology resources, have access to source code and/or protected personally identifiable information or other confidential information or have access to secure areas to undergo Federal fingerprint-based background checks and to have these background checks repeated at least once every five years. Failure to comply with a federal background investigation may result in disciplinary action up to and including termination of employment or the rescinding of a conditional offer of employment. These background checks must be fingerprint-based and performed by the State with support from the State's law enforcement resources. Under provisions set forth in Title 28, Code of Federal Regulations (CFR), Section 50.12, the prospective employees and contractors will be provided written notification that their fingerprints will be used
Page | 15
CONTRACTOR
NOT FOR PUBLIC DISTRIBUTION 03/2025
to check the criminal history records of the State and the Federal Bureau of Investigation (FBI). Identification records obtained from the FBI may be used solely for the purpose requested and may not be disseminated outside the receiving department, related agency, or other authorized entity. BIT will supply the fingerprint cards and the procedure that is to be used to process the fingerprint cards. Individuals should plan on the background check taking two to four weeks. The steps to process the background checks are found in procedures document ITSP 1010.1 Background Checks Procedures.
10.1.4.2. Disqualifying Criteria
SDCL 1-33-63 allows the Commissioner of BIT to require a Federal background investigation be performed on any current or prospective BIT employee or Information Technology contractor that has access to confidential data or information. To implement these provisions, BIT must determine and memorialize its Disqualifying Criteria policy - the specific criminal activity that operates to disqualify a person from having access to the confidential data. For purposes of this Policy, the terms "employee or contractor" means "potential or current BIT employee or Information Technology contractor."
1. An employee or contractor may not have access to confidential data if the individual has been convicted of a felony within 5 years of the date of the most recent criminal background check or any time thereafter.
1. Employees or contractors involved with technology associated with the division of the South Dakota Lottery must meet the qualifications defined in SDCL 42-7A-14. Primarily, this extends the period beyond completing felony sentencing to 10 years, rather than 5 as defined in A. above.
2. If the employee or contractor has been convicted of a crime not included in Paragraph A, the employee or contractor is not automatically disqualified from having access to confidential data. The determination of whether such an employee or contractor may have access to confidential data will be made on an individual basis. The considerations will include but not be limited to:
1. The nature of the conviction, particularly if it is a crime of dishonesty, a financial crime, an identity crime, or a crime involving the misuse of confidential information.
2. The length of time between the offense and the employment decision.
3. The number of offenses.
4. The relatedness of the conviction to the duties and responsibilities of the position.
5. The efforts at maintaining a clean record.
6. The number of crimes committed.
3. The determination required by Paragraph B will be made by the BIT Chief Information Security Officer (CISO) in consultation with the applicable Division Director.
4. Under no circumstances may an employee or contractor have access to confidential data if the individual is disqualified by this policy.
5. If a position within the BIT requires an employee or contractor to have access to confidential data as an essential part of the job function, the individual's failure to undergo or to successfully pass a criminal background check may result in termination of the employee or contractor.
6. After the adoption of this policy, no employee or contractor may be hired by BIT unless the individual undergoes and successfully passes a criminal background check pursuant to this policy.
7. The hiring of support staff positions and promotions within support staff positions may be excluded from this policy.
10.1.4.3. Noncriminal Agency Coordinator (NAC)
The CISO is designated as a Noncriminal Agency Coordinator (NAC) to act as the primary contact person for BIT.
10.1.4.4. Local Agency Security Officer (LASO)
The CISO is appointed as a Local Agency Security Officer (LASO) to act as liaison with the South Dakota Division of Criminal Investigation (SDDCI) to ensure the BIT follows security procedures.
Page | 16
CONTRACTOR
NOT FOR PUBLIC DISTRIBUTION 03/2025
10.1.4.5. Background Check Interpretation
When an explanation of a charge or disposition is needed, the BIT NAC will communicate directly with the agency (SDDCI) that furnished the data to the FBI.
10.1.4.6. Not Guilty Presumption
An individual should be presumed not guilty of any charge/arrest for which there is no final disposition stated on the record or otherwise determined.
10.1.4.7. Background Check Information Challenge
An opportunity to challenge and discuss the disqualification due to information found in the criminal history records of the FBI will be provided to the applicant for five days, if requested. Due to the confidential nature of the criminal history records of the FBI and the restrictions on disclosure of the records, it may be discussed that the applicant was disqualified because of criminal history information; however, the specific FBI results may not be disclosed to the applicant, neither in writing nor verbally. Under provisions set forth in Title 28, CFR, Section 50.12, if the information on the record is used to disqualify an applicant, the official making the determination of suitability for licensing or employment shall provide the applicant the opportunity to complete, or challenge the accuracy of, the information contained in the FBI Identification record. The deciding official should not deny the license or employment based on the information in the record until the applicant has been afforded a reasonable time to correct or complete the information or has declined to do so.
10.1.4.8. Corrective Action
If the applicant wishes to correct the record as it appears in the FBI's Criminal Justice Information Services (CJIS) Division Records System, the applicant should be advised that the procedures to change, correct, or update the record are set forth in Title 28, CFR, Section 16.34.
10.1.4.9. Training
BIT will comply with mandatory training requirements as outlined in the South Dakota Division of Criminal Investigation Guide for Noncriminal Justice Agencies. All personnel directly associated with accessing, maintaining, processing, dissemination, or destruction of Criminal History Record Information (CHRI) shall be trained.
10.1.4.10. Emailing Background Check Information
It is prohibited to mail criminal history background check information either as an email or as an attachment to email. Individuals are prohibited from opening any email that contains background check information. They must report the occurrence to their supervisor and delete the email.
Administrative-I/T Asset Protection-Confidentiality
10.3.1. Overview
All BIT employees and contracted technology professionals shall be granted appropriate access to information, agency documents, records, programs, files, diagrams, and pertinent data resources needed to fulfill the job responsibilities of an individual or a contractual agreement. In return, it is expected that such data is treated as a
Page | 17
CONTRACTOR
NOT FOR PUBLIC DISTRIBUTION 03/2025
trade secret and individuals will not modify data or disclose data to others without proper authorization. Products resulting from employment or custom-built solutions for government agencies are the property of the State.
10.3.2. Purpose
To ensure that employees are familiar with the laws that govern use of information technology systems and the data contained within those systems and that employees and contractor comply with such laws.
10.3.3. Scope
This policy applies to BIT and technology contractors of the State. It includes the protection of sensitive data in addition to the work products built under State guidance. Individuals shall maintain confidentiality and data integrity of documents, records, configurations, programs, and files and understand that work products resulting from such efforts are the property of the State.
10.3.3.1. Scope Assumptions
The confidentiality and data integrity responsibility of BIT employees and contractors extends to, but is not limited to systems, software, data, configurations, architectures / designs, documentation, and infrastructure information developed on its own or acquired from third parties. Customized work products including specific-built software solutions are the property of the State.
10.3.3.2. Scope Constraints
Agencies will have their own data protection and confidentiality agreements. Leased and licensed software is exempt from this policy.
10.3.4. Policy
10.3.4.1. Confidentiality Agreement
The individual must not, at any time, use or disclose any trade secrets or confidential information of the State to anyone, include agencies or contractors that have business with the State, without written permission from the BIT Commissioner, except as required to perform duties for the State. The individual agrees to adhere to all data processing and technology policies governing the use of the technology infrastructure of the State. The individual agrees that all developments made and works created by the individual in connection with the contractual agreement of the State shall be the sole and complete property of the State, and all copyrights and other proprietary interest, therein, shall belong to the State. Upon the request of the State to include the termination of the employment of the person, the individual will leave all reports, messages, programs, diagrams, documentation, code, memoranda, notes, records, drawings, manuals, flow charts, and any other documents whether manual or electronic pertaining to the State, including all copies thereof, with BIT to include all data resources whether manual or electronic involving any trade secrets or confidential information of the State to include agencies or contractors that have business with the State.
Complying with Legal Obligations Employees and contractors are subject to Federal, State and local laws governing the use of information technology systems and the data contained in those systems.
• BIT shall comply with all applicable laws and take measures to protect the information technology systems and the data contained within information systems. Agencies must take the initiative to comply with applicable laws and regulations pertaining to their field of business.
Page | 18
CONTRACTOR
NOT FOR PUBLIC DISTRIBUTION 03/2025
• BIT shall ensure that all BIT employees and technology contractors are aware of legal and regulatory requirements that address the use of information technology systems and the data that reside on those systems.
• Agencies shall ensure that each public employee and other agency authorized users are provided with a summary of the legal obligations that apply to that agency such as HIPAA, etc.
10.3.4.2. Security Acknowledgement and Access
Once chosen, contractors must identify all individual contractors that will be participating in work for the State and begin participating after the work has begun. Contractors working with the State shall be required to sign the Security Acknowledgement form ( http://intranet.bit.sd.gov/forms/ ). All BIT employees and contractors need to have a copy signed and filed. Contractor access to the technology infrastructure of the State is closely managed and limited. Contractors do not have the same degree of access nor privileges given to State employees. At the sole discretion of BIT, access for a contractor to the technology infrastructure of the State can be amended or terminated.
Administrative-I/T Asset Protection-Governance of Regulated Data within Information Systems
10.11.1. Overview
Standards for the governance of regulated data within information systems.
10.11.2. Purpose
This policy states the requirements for acquisitions and contracts with third parties as the contracts include information systems containing regulated data.
10.11.3. Scope
The scope of the policy includes all software or hardware processing, transferring or housing regulated data within
BIT.
10.11.3.1. Scope Assumptions
The State of South Dakota hereby recognizes the status of the State as a carrier of regulated data under the definitions contained in State and federal regulations; "The State of South Dakota must comply with State and federal regulations pertaining to the establishment and management of an appropriate cyber security program in accordance with the regulatory requirements;" Compliance with regulations is mandatory and failure to comply can bring severe sanctions and penalties. BIT recognizes that data stored in BIT data centers is subject to this policy. Contracts and third-party agreements that store regulated data in any non-BIT managed data center must contain language outlined in this policy.
10.11.3.2. Scope Constraints
Business associate agreements referenced herein are the responsibility of the agency. BIT is not a party to those agreements.
10.11.4. Policy
http://intranet.bit.sd.gov/forms/
Page | 19
CONTRACTOR
NOT FOR PUBLIC DISTRIBUTION 03/2025
10.11.4.1. Acquisitions
Whenever the information systems contain regulated data, the agencies must:
• Include the following requirements and specifications, explicitly or by reference, in information system acquisition contracts based on an assessment of risk and in accordance with applicable federal laws, executive orders, directives, policies, regulations, and standards:
o Security functional requirements and specifications o Security-related documentation requirements o Developmental and evaluation-related assurance requirements.
• Ensure third party providers of information systems used to process, store, or transmit the information are secure by designing and implementing the information system using security engineering principles.
• Perform configuration management during information system design, development, implementation, and operation; manage and control changes to the information system. The agency shall implement only organization-approved changes, document approved changes to the information system, and track security flaws and flaw resolution.
• Obtain, protect as required, and make available to authorized personnel adequate documentation for the information system;
• Comply with software usage restrictions enforcing explicit rules governing the installation of software by users.
• Ensure the information system developers create a security test and evaluation plan, implement the plan, and document the results.
• Manage the information system using a system development life cycle methodology that includes information security considerations.
10.11.4.2. Contracts with Third Parties
• For every Business Associate or third party identified, a contract or other written agreement must be in place.
• The agreement must document satisfactory…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .