Attachment C.pdf
PDF 278 KB Posted
- Attached to
- PAVEMENT DATA COLLECTION State and local contract opportunity
- Solicitation number
- 5400025010
- Issued by
- Richland County, South Carolina
About this file
This is an IT Application and System Standards document issued by the South Carolina Department of Transportation (SCDOT) IT Services, effective June 1, 2021. The document establishes mandatory standards for the development, deployment, and security of all applications and information systems within SCDOT's environment, applicable to both internal systems and external vendors providing IT services to the agency. The standards cover desktop infrastructure requirements including Windows 10, Microsoft Office 2016, and approved browsers; server infrastructure specifications such as Windows Server 2012 R2 through 2019 and Microsoft Exchange Server 2016; and application development environments utilizing Microsoft Visual Studio .NET 2017 or greater. All applications must comply with these standards prior to deployment, with non-conforming systems subject to rejection by SCDOT. Vendors are required to submit detailed installation guides, system requirements, data dictionaries, and communication diagrams to the SCDOT IT Systems Manager for approval before deployment. The document emphasizes that SCDOT will not customize its environment to accommodate applications and reserves the right to halt deployment of any system that fails to meet standards or compromises security posture.
Security requirements mandate vulnerability assessments using industry-standard tools such as IBM AppScanner, Tenable Nessus, or OWASP, with all high and medium vulnerabilities requiring remediation before production deployment. Applications must utilize Integrated Windows authentication, comply with Federal Section 508 accessibility standards, and encrypt database connection strings. Cloud-hosted solutions must achieve FedRAMP compliance or equivalent approval from the SCDOT Chief Information Security Officer. Consultants, vendors, and subcontractors with access to SCDOT electronic data must comply with the agency's Acceptable Computer Usage Policy and IT Security Policy, adhere to South Carolina Act 190 of 2008 and related financial security legislation, and implement the National Institute of Standards and Technology Risk Management Framework or comparable cybersecurity frameworks. Exceptions to these standards may only be granted by the SCDOT Chief Information Officer and Chief Information Security Officer. The document references NIST Special Publication 800-53 R5 and NIST Cybersecurity Framework as foundational authorities and is subject to annual review and updates by SCDOT.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment 3.pdf | ||
| Solicitation.pdf | ||
| Attachment G.xlsx | XLSX spreadsheet | |
| Attachment B.pdf | ||
| Attachment D.pdf | ||
| Amendment 1.pdf | ||
| Attachment A.pdf | ||
| Attachment E.pdf | ||
| Attachment F.pdf | ||
| Amendment 2.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SC DOT
IT Application and System Standards for Development, Deployment, and Security v1.2
Effective Date: 06/01/2021
SUMMARY
The purpose of this document is to detail the current standards for the development, deployment and security for applications and information systems. The standards detailed in this document are designed to minimize the risk to SCDOT applications, and information systems by ensuring that applications and systems are developed, deployed, and maintained in a manner in which confidentiality, integrity, and availability are not compromised. It is expected that all applications and systems are developed, deployed, and maintained in line with industry standards, best practices, and federal and state guidelines where applicable.
This document shall be reviewed at least annually and SCDOT reserves the right to update as necessary.
SCOPE
All Information system components including hardware, software, data, services and applications that are located within, maintained, or managed by the SCDOT IT Services unit.
External providers of information systems to the SCDOT are required to comply with this document and any other applicable SCDOT policies, standards, and/or procedures. The vendor/developer is solely responsible for ensuring that the application or system conforms to the environment and standards set by IT Services. Applications/systems that do not conform to our environment will not be deployed. SCDOT will not compromise security for any application or system.
Exceptions to these standards may be granted by the SCDOT CIO and CISO.
ACRONYMS AND DEFINITIONS
Chief Information Officer (CIO) - Oversees SCDOT’s information technology portfolio, including the IT Security Program
Chief Information Security Officer (CISO) – Oversees SCDOT’s security program for all information systems, digital and/or physical.
Compensating Controls - The security and privacy controls employed in lieu of the controls in the baselines described in NIST Special Publication 800-53B that provide equivalent or comparable protection for a system or organization.
FedRAMP - The Federal Risk and Authorization Management Program provides a standardized approach to security authorizations for cloud service offerings.
Internet of Things (IoT) – Computing devices, often called “things”, that integrate physical and/or sensing capabilities with network capabilities. These devices often are embedded with sensors and software for the purpose of connecting and exchanging data with other devices and systems over the Internet. These devices often provide remote interaction with physical systems such as HVAC, lighting, media systems, and camera systems, to list a few.
Information System – A discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.
Information System Owner - Responsible for the overall procurement, development, integration, modification, or operation and maintenance of an Information System. The information system owner also represents the users of the system with subject matter expertise, has deep knowledge of the business processes the system supports, ensures documentation of the system is kept current, and is best positioned to assess the risks to the system based upon proposed system changes.
National Institute for Standards and Technology (NIST) - is a physical sciences laboratory and a non-regulatory agency of the United States Department of Commerce. Its mission is to promote innovation and industrial competitiveness. NIST's activities are organized into laboratory programs that include nanoscale science and technology, engineering, information technology, neutron research, material measurement, and physical measurement.
Operational Technology (OT) – Programmable systems or devices that interact with the physical environment (or manage devices that interact with the physical environment). These systems/devices detect or cause a direct change through thee monitoring and/or control of devices, processes, and events. Examples include industrial control systems, building management systems, fire control systems, and physical access control mechanisms.
Security Control - The safeguards or countermeasures prescribed for an information system or an organization to protect the confidentiality, integrity, and availability of the system and its information.
STANDARDS FOR SYSTEMS
All applications/systems including off-the-shelf and custom must conform to SCDOT’s IT environment as outlined below:
1. SCDOT will not customize, alter or add to our environment to accommodate any application/system.
2. A detailed installation guide, system requirements, data dictionary, and communication diagram must be submitted to and approved by the SCDOT IT Systems Manager before deployment of any and all applications/systems.
3. SCDOT reserves the right to stop deployment of any application/system that fails to conform to these standards or which may compromise the security posture of the SCDOT environment.
4. SCDOT typically provides production environments only. However SCDOT now offers a test environment for vendor supported applications and services. This is for a vendor supported web application and/or web service to be installed in the SCDOT environment is at the discretion of the CIO.
5. SCDOT does not allow remote access to servers or any IT infrastructure resource.
6. Applications shall be developed for the latest supported platform.
7. Before being placed into the production environment, all information systems shall be tested for vulnerabilities using an industry standard testing application such as IBM AppScanner, Tenable Nessus, OWASP, or a comparable tool approved by the SCDOT CISO. All application vulnerabilities identified as high or medium shall be remediated. Vulnerabilities identified as low will be reviewed by the CISO to determine if remediation is required.
DESKTOP INFRASTRUCTURE STANDARDS
Microsoft Windows 10 (2016 LTSB Build 1809).
Microsoft Windows Internet Explorer 11 – not supported
Microsoft Office 2016 (Professional Plus x64).
https://en.wikipedia.org/wiki/United_States_Department_of_Commerce https://en.wikipedia.org/wiki/Information_technology https://en.wikipedia.org/wiki/Information_technology
Microsoft Edge Browser
Microsoft DirectX 9
Microsoft System Center Client
Oracle 12.2.1, 12.2.2 – 32 & 64bit
Google Chrome
Google Earth Pro
Adobe Pro 2017
Adobe SVG Viewer
Cisco VPN
CPC View
FireEye
JAVA 6 updt34
Security Baseline – STIGS Low impact
Microsoft Visio
Microsoft PowerBI
Microsoft Teams
Microsoft Project
Microsoft Office 2013/2016
SERVER INFRASTRUCTURE STANDARDS
Windows Server 2012 R2 64bit
Windows Server 2012 Active Directory native mode
Windows Server 2016
Windows Server 2019
Microsoft Exchange Server 2016 on Premise
Microsoft Office O365
Microsoft ASP.NET Framework Version 4.6.1
STANDARDS FOR APPLICATIONS AND DATABASES
1. Authentication method for applications is Integrated Windows, for databases, the standard is
Oracle or SQL Server authentication.
2. No applications may use local accounts.
3. No applications may be dependent on automatic server login. All such application needs will be deployed as a service.
4. Do not include any Database (SQL or Oracle) configuration in build.
5. If a database connection string is included as part of the applications function, it must be encrypted in the (web.config) file. Encryption on first run is not acceptable.
6. Default document defined in package build.
7. All server reboots will occur after normal business hours.
8. All reports, regardless of database format, can be leveraged with SCDOT’s SQL Server
Reporting Services (SSRS) or Microsoft Power BI reporting tools.
9. Before being placed into the production, all applications shall be tested for vulnerabilities using an industry standard testing application such as IBM AppScanner, Tenable Nessus, OWASP, or a comparable tool approved by the SCDOT CISO.
10. Reasonable effort must be made to ensure that applications comply with Federal Section
508 standards, which makes electronic information accessible to people with disabilities.
APPLICATION/SYSTEM AND DATABASE INFRASTRUCTURE STANDARDS
Microsoft IIS 7.5 running in Windows Server 2008 R2 SP1 64bit
Microsoft IIS 8.5 running on Windows 2012 R2 64bit
Microsoft IIS 10 native running Windows Server 2016
Microsoft SharePoint 2013
Microsoft SQL Server 2014 R2
Microsoft SQL Server 2017
Microsoft SQL Server Reporting Services 2014
Microsoft SQL Server Reporting Services 2017
Oracle 12.2.01
Oracle Application Server 10.1.2.3.0 Internal Server for Internal applications only
Oracle Weblogic Server 12.2.1.3.0. External DMZ Server
Oracle Weblogic Server 12.2.1.4.0 External DMZ Server
APPLICATION/SYSTEM DEVELOPMENT ENVIRONMENT
Microsoft Visual Studio .NET (2017 or greater)
Microsoft InfoPath Designer (2013 or greater)
Microsoft SharePoint Designer (2013 or greater)
DEPLOYMENT METHODS
1. SharePoint application/systems deployed using (.WSP) package.
2. InfoPath forms deployed using (.XSN) package.
3. .NET application/systems deployed using Microsoft Installer (.ZIP) package
APPLICATIONS EMAIL FUNCTIONALITY
All applications that require an email relay shall use SMTP via Sharepoint or Oracle. A relay via
Microsoft exchange is possible but must be approved by the SCDOT Systems Manager before implementation.
IOT/OT DEVICES ON THE SCDOT NETWORK
For nontraditional IT devices (i.e., traffic control devices, weather stations, radars, variable message signs, traffic cameras, security cameras, televisions, video devices, HVAC systems) that connect to the SCDOT network, hardened configurations and vulnerability scans are required.
Providers of these types of devices should refer to NISTIR 8259 Foundational Cybersecurity
Activities for IoT Device Manufacturers for details regarding security considerations and controls.
STANDARDS FOR CLOUD HOSTED SOLUTIONS
Cloud solutions used by the SCDOT are required to abide by the standards in this document whenever possible. When the security controls referenced in this document cannot be implemented, compensating security controls are required. FedRAMP compliance, or a comparable standard approved by the SCDOT CISO, is required for cloud hosted solutions.
ADDITIONAL SECURITY CONTROLS AND CONSIDERATIONS
SCDOT uses the National Institute of Standards and Technology’s Cyber Security Framework as the framework for cyber security. The NIST security controls include, but are not limited to, those controls listed below. As this is only a subset of applicable controls from that framework, please note that other controls not specifically mentioned may be applicable. SCDOT reserves the right to update this list at any time in response to the ever evolving cyber security environment.
Vulnerability Scanning (RA-5)
A vulnerability assessment shall be performed on all information systems undergoing significant changes before the systems are moved into production. A report shall be provided by the vendor to be reviewed by the SCDOT Chief Information Officer and Information Security Officer for approval before the system is moved into production.
System Development Life Cycle (SA-3)
Developers of information systems shall ensure appropriate security controls are implemented at all stages of the information system life cycle.
Security and Privacy Engineering Principles (SA-8)
Developers of information systems shall ensure system security and privacy engineering principles are applied in the specification, design, development, implementation, and modification of information systems.
Developer Security Testing and Evaluation (SA-11)
Developers of information systems shall establish separate development, testing, and production environments. Developers of information systems shall not use production data for testing purposes unless the data has been obfuscated, sanitized, or declassified. If production data must be temporarily used in these environments, appropriate security controls, including approval from the SCDOT CIO and CISO, procedures to remove/delete data after completion of tests, and documentation of activities, shall be implemented.
Development Process, Standards, and Tools (SA-15)
Developers of information systems shall follow a documented development process that explicitly addresses security requirements, identifies the standards and tools used in the development process and documents any specific tools options and configuration used in the development process; Documents, manages, and ensures the integrity of changes to the process and/or tools used in development.
Developers of information systems shall define quality metrics at the beginning of the development process and provide evidence of meeting the quality metrics at predefine milestones.
Developers of information systems shall reduce the attack surface reduction where possible.
Attack surface reduction includes, for example, applying the principle of least privilege, employing layered defenses, applying the principle of least functionality, (i.e., restricting ports, protocols, functions, and services), deprecating unsafe functions, and eliminating application program interfaces that are vulnerable to cyber-attacks. Refer to NIST SP 800-53, CM-7 for additional details on LEAST FUNCTIONALITY.
Developers of information systems shall perform automated vulnerability analysis using and industry standard vulnerability tool approved by the SCDOT CISO.
Separation of System and User Functionality (SC-2)
The information systems separates user functionality (including user interface services) from information system management functionality.
Denial of Service Protection (SC-5)
The information system protects against or limits the effects of various denial of service attacks.
Session Authenticity (SC-23)
Developer shall identify the appropriate controls to ensure session authenticity, protecting message integrity in applications and protecting information transmission to and from information systems.
Flaw Remediation (SI-2)
Developer shall design appropriate controls into information systems, including user developed applications to ensure correct processing. Developer shall ensure that software patches are applied when they function to remove or reduce security weaknesses.
Information Input Validation (SI-10)
Developer shall incorporate controls into information systems to check the validity of information inputs and information outputs.
Developer shall incorporate processing validation checks into information systems to detect processing errors, inadvertent or deliberate processing actions (e.g., accidental deletions).
Supplier Assessments and Reviews (SR-6)
SCDOT shall conduct a supplier review prior to entering in a contractual agreement to acquire the information systems, system component, or information systems services. Supplier reviews include, for example: analysis of supplier processes used to design, develop, test, implement, verify, deliver and support information systems, system components, and information services.
Prior to selection of an information system, system component, or information system service, assessment shall be conducted. Assessments include, for example, testing, evaluations, reviews, and analysis. Self-assessments may be acceptable upon the review of the SCDOT CISO.
Data Transfers
Data transfers/dumps will use only SCDOT encrypted file transfer resources, providers such as
Drop Box and File Genius are not authorized.
LEGAL REQUIREMENTS FOR CONSULTANTS
Below is the cyber security statement included in service provider contracts and is to be used as guidance in terms of recognized standards and frameworks for cybersecurity.
The CONSULTANT and its designated employees, as well as any subcontractors and sub consultants of any tier, having access to SCDOT electronic data, is required to follow
SCDOT’s Acceptable Computer Usage Policy which establishes guidelines for acceptable use and confidentiality of SCDOT’s information technology by the
CONSULTANT and its designated employee for data entry into SCDOT’S computer system; provided that the section of the Policy pertaining to SCDOT’s right to inspect any users email at any time is qualified to reserves unto SCDOT the right to inspect consultant, subcontractor or sub consultant emails that are SCDOT business related, including emails that are related to the services with which consultant is under contract.
The CONSULTANT and its designated employees, as well as any subcontractors and sub consultants of any tier, having access to SCDOT electronic data, is required to also follow
SCDOT’s IT Security Policy which sets forth SCDOT IT Security Policy including Network
Security Policy, Network Access and Authentication Policy, Physical Security Policy, Backup Policy, Incident Response Policy, Corporate Security Policies, VPN Site-to-Site
Policy, Wireless Access Policy, Remote Access Policy, Confidential Data Policy, Guest
Access Policy, Third Party Connection Policy, Outsourcing Policy, and Mobile Device
Policy; the South Carolina Act 190 of 2008; the Financial and Identity Theft Protection Act;
and the Personal Financial Security Act. Prior to access to the SCDOT network, each person designated by the CONSULTANT is required to sign an acknowledgment of the
DD37 policy requirements.
The CONSULTANT’s obligations with respect to the provisions of computer use and data confidentiality shall survive termination or expiration of the contract. Without limiting any rights SCDOT may have, and notwithstanding any other term of this contract, the
CONSULTANT agrees that SCDOT may have no adequate remedy at law for a breach of the CONSULTANT’s obligations under this clause and therefore SCDOT shall be entitled to pursue equitable remedies in the event of a breach.
CONSULTANT is responsible for ensuring that it, as well as any subcontractors and sub consultants of any tier, having access to SCDOT electronic data, is required to manage and reduce risk by employing and using good cyber threat preventative measures. CONSULTANT, subcontractors and sub consultants shall use the National Institute of Standards and Technology’s Risk Management Framework (NIST RMF) as its cybersecurity framework or use other comparable frameworks and standards for cyber security protection. CONSULTANT shall insert a NIST RMF or equivalent framework requirement provision in all subcontract for this Project which require or allow a sub consultant or subcontractor to have access to SCDOT data. CONSULTANT shall provide SCDOT, upon request, third party certifications to verify implementation of an industry recognized cyber security framework during the Project. Other comparable cyber security frameworks include: NIST RMF; NIST CSF; ISO IES 27001/ISO 27002; SOC 2; IASME Governance; CIS Controls version 7; COBIT 5; Fed RAMP; HIPAA; GDPR; FISMA; NERC CIP; HITRUST CSF.
AUTHORITY REFERENCE
SCDOT DD37 SCDOT Acceptable Use Policy
SCDOT DD39 - Establish Guidelines for Content on SCDOT Internet
NIST 800-53 R5 Security and Privacy Controls for Information Systems and Organizations https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final
SCDIS-200 Information Security and Privacy Standards https://admin.sc.gov/technology/policies_procedures
OTHER REFERENCE
NISTIR 8259 Foundational Cybersecurity Activities for IoT Device Manufacturers https://csrc.nist.gov/publications/detail/nistir/8259/final
Version History
Version Date Change Summary
1 09/29/2020 Document creation
1.1 02/25/2021 Managers review and approval
1.2 06/01/2021 Vulnerability assessments detailed
File details come from the government source that posted it. Updated .