Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf
PDF 74 KB Posted
- Attached to
- Corrections Jail Management System State and local contract opportunity
- Solicitation number
- Y25-101-KS
- Issued by
- Orange County, Orlando City, Florida
About this file
This is an Enterprise Security Standards policy document applicable to Orange County Government Board of County Commissioners (OCGBCC) in Florida for external data hosting vendors supporting the Corrections Jail Management System (Y25-101-KS). The policy establishes mandatory security requirements for all vendors, networks, systems, and applications that transmit, process, store, or handle electronic data on behalf of the County. The document outlines comprehensive data protection standards governing data input and processing, storage and handling, transmission, and disposal. Sealed responses for the Corrections Jail Management System are due by 4:00 pm EST on Thursday, January 8, 2026, submitted electronically through the OpenGov e-Procurement Platform only.
The security standards prohibit hosted applications from accessing social security numbers, bank information, Active Directory usernames, or OCGBCC internal or DMZ networks. Field-level encryption is required for sensitive data including usernames, passwords, names, addresses, phone numbers, email addresses, birthdates, document numbers, account numbers, race or religious information, employee identification numbers, and all HIPAA and PCI information both at rest and in transit within encrypted tunnels. Data disposal must utilize sanitization, physical destruction, or purging methods. Vendors must ensure the hosting environment meets information security best practices and pass a yearly penetration test conducted by Orange County ISS personnel or provide results from an external audit by a reputable third-party security company. The document was most recently revised in October 2017 to specify field-level encryption requirements and expand third-party audit options.
View the file
Other files for this state and local contract opportunity
Show all 44
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ENTERPRISE SECURITY STANDARDS, POLICIES, AND GUIDELINES
EXTERNAL DATA HOSTING STANDARD
1.0 Purpose
| The | purpose | of | this | policy | is | to | establish | a | standard | in | order | to | execute | the | proper | retrieval, | storage, |
| transmission, | processing, | and | handling | of | electronic | data. |
2.0 Scope
| This | document | applies | to | all | vendors, | networks, | systems, | and | applications | that | will | transmit, | process, | store, | or |
| handle | electronic | data | provided | by | Orange | County | Government | Board | of | County | Commissioners | (OCGBCC). |
3.0 Audience
| This | document | is | intended | for | distribution | to | those | that | are | involved | in | the | retrieval, | storage, | transmission, |
| processing, | and | handling | of | electronic | data. |
4.0 Policies
4.1 Data Input and Processing
| 4.1.1 Any | use | of | Social | Security | Number | information | shall | adhere | to | and | abide | by | Florida |
| Statutes, | specifically | F.S. | 119.071. |
| 4.1.2 The | hosted | application | shall | not | have | access | to | social | security | information. | |||
| 4.1.3 The | hosted | application | shall | not | have | access | to | data | containing | bank | information. | ||
| 4.1.4 The | hosted | application | shall | not | be | granted | direct | or | indirect | access | to | OCGBCC | Active |
| Directory | usernames. | ||||||||||||
| 4.1.5 The | hosted | application | shall | not | have | access | to | the | OCGCC | internal | or | DMZ | networks. |
| 4.2 Data | Storage | and | Handling | |||||||||
| 4.2.1 Any | data | accessible | from | the | hosted | application | meeting | the | following | criteria | shall | be |
| encrypted | at | a | field-level | and | in | transit: | usernames, | passwords, | names, | addresses, |
| phone | numbers, | addresses, | birthdates, | federal/state/local | document | numbers, | ||||
| account | numbers, | race | or | religious | information, | usernames, | passwords, | employee | ||
| identification | numbers | and | all | HIPAA | and | PCI | information. |
| 4.2.2 Any | data | accessible | from | the | hosted | application | or | directly | accessible | from | it | should | be |
| encrypted | at | a | field | level. |
| 4.3 Transmission | of | Data | ||||||||
| 4.3.1 Any | data | referenced | above | shall | be | transmitted | within | an | encrypted | tunnel. |
| 4.4 Disposal | of | Data | |||||||||||||||
| Once | data | is | no | longer | needed | or | must | be | removed | from | the | system | it | shall | be | sanitized | and |
| disposed | using | one | of | the | methods | below: |
| 4.4.1 Sanitization | - | Overwriting | of | data | previously | stored | on | a | disk | or | drive | with | a | random |
| pattern | of | meaningless | information. |
| 4.4.2 Destruction | - | Physically | damaging | a | medium | so | that | it | is | not | usable | by | any | device | that |
| may | normally | be | used | to | read | information | on | the | media | such | as | a | computer, | tape | |
| reader, | audio | or | video | player. |
| 4.4.3 Purging | data | - | Using | strong | magnetic | devices; | such | as | a | degausser, | it | is | possible | to |
| render | data | unrecoverable. |
| 4.5 External | Audit | |||||||||||
| 4.5.1 The | vendor | must | ensure | that | the | web | hosting | environment | and | the | application | is |
| secured | using | information | security | best | practices. | ||||||
| 4.5.2 The | external | service, | system, | and | application | must | pass | a | yearly | penetration | test |
| performed | by | Orange | County | ISS | personnel. | Alternatively | the | vendor | can | provide | the | |
| results | of | an | external | audit | conducted | by | a | reputable | 3rd | party | security | company. |
5.0 Definitions
| Term | Definition | ||||||||||
| Bank | Information | Checking | account | numbers, | credit | card | numbers, | or | any | unique | number |
| from | a | bank | institution. | ||||||||||||
| Electronic | Media | Physical | objects | on | which | data | can | be | stored, | such | as | hard | drives, | zip | drives, |
| CD-ROMs, | DVDs, | USB | drives, | and | tapes. | |||||||
| Sanitization | To | expunge | data | from | storage | media | so | that | data | recovery | is | impossible. |
| Physical | Destruction | A | sanitization | method | for | optical | media, | such | as | CDs. | ||
| Florida | Statue | 119.071 | Detailed | guidelines | on | usage | of | Social | Security | information |
6.0 Revision History
| October | 2017 Specified | “field-level | encryption” | for | sensitive | data | at | rest | in | 4.2.1 |
| Added | usernames | and | passwords | to | the | list | in | 4.2.1 | ||
| Added | an | option | for | a | 3rd | party | vendor | in | 4.5.2 | |
| Added | definition | for | field-level | encryption |
August 2012 Added “Bank Information” to list of definitions in 5.0
File details come from the government source that posted it. Updated .