Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf

PDF 74 KB Posted

Attached to
Corrections Jail Management System State and local contract opportunity
Solicitation number
Y25-101-KS
Issued by
Orange County, Orlando City, Florida

About this file

This is an Enterprise Security Standards policy document applicable to Orange County Government Board of County Commissioners (OCGBCC) in Florida for external data hosting vendors supporting the Corrections Jail Management System (Y25-101-KS). The policy establishes mandatory security requirements for all vendors, networks, systems, and applications that transmit, process, store, or handle electronic data on behalf of the County. The document outlines comprehensive data protection standards governing data input and processing, storage and handling, transmission, and disposal. Sealed responses for the Corrections Jail Management System are due by 4:00 pm EST on Thursday, January 8, 2026, submitted electronically through the OpenGov e-Procurement Platform only.

The security standards prohibit hosted applications from accessing social security numbers, bank information, Active Directory usernames, or OCGBCC internal or DMZ networks. Field-level encryption is required for sensitive data including usernames, passwords, names, addresses, phone numbers, email addresses, birthdates, document numbers, account numbers, race or religious information, employee identification numbers, and all HIPAA and PCI information both at rest and in transit within encrypted tunnels. Data disposal must utilize sanitization, physical destruction, or purging methods. Vendors must ensure the hosting environment meets information security best practices and pass a yearly penetration test conducted by Orange County ISS personnel or provide results from an external audit by a reputable third-party security company. The document was most recently revised in October 2017 to specify field-level encryption requirements and expand third-party audit options.

View the file

Other files for this state and local contract opportunity

Other files attached to Corrections Jail Management System, newest first.
File Type Posted
Corrections_Jail_Management_System_(Addendum_#6_Revision).pdf PDF
Corrections_Jail_Management_System_(Addendum_#6_Revision).pdf PDF
Corrections_Jail_Management_System_(Addendum_#6_Revision).pdf PDF
Corrections_Jail_Management_System_(Addendum_#4_Revision).pdf PDF
Corrections_Jail_Management_System.pdf PDF
ATTACHMENT_G-_Sample_Critical_Reports.pdf PDF
Attachment_A_-_Final_Mandatory_Features.pdf PDF
Attachment_B_-_EnterpriseSecurityStandards-InternalApplicationsRev4.pdf PDF
ATTACHMENT_F_-_System_Interface_Requirements.pdf PDF
ATTACHMENT_G-_Sample_Critical_Reports.pdf PDF
Attachment_A_-_Final_Mandatory_Features.pdf PDF
Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf PDF
Attachment_E_-_Security_QUESTIONNAIRE.docx DOCX document
ATTACHMENT_F_-_System_Interface_Requirements.pdf PDF
Attachment_B_-_EnterpriseSecurityStandards-InternalApplicationsRev4.pdf PDF
Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf PDF
ATTACHMENT_F_-_System_Interface_Requirements.pdf PDF
Attachment_E_-_Security_QUESTIONNAIRE.docx DOCX document
Attachment_A_-_Final_Mandatory_Features.pdf PDF
Attachment_D_-_Orange_County_IT_Standards.pdf PDF
ATTACHMENT_F_-_System_Interface_Requirements.pdf PDF
Attachment_A_-_Final_Mandatory_Features.pdf PDF
Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf PDF
Attachment_B_-_EnterpriseSecurityStandards-InternalApplicationsRev4.pdf PDF
ATTACHMENT_G-_Sample_Critical_Reports.pdf PDF
Attachment_D_-_Orange_County_IT_Standards.pdf PDF
ATTACHMENT_F_-_System_Interface_Requirements.pdf PDF
Attachment_E_-_Security_QUESTIONNAIRE.docx DOCX document
Y25-101-KS_Corrections_Jail_Management_System.pdf PDF
Attachment_B_-_EnterpriseSecurityStandards-InternalApplicationsRev4.pdf PDF
Attachment_E_-_Security_QUESTIONNAIRE.docx DOCX document
Y25-101-KS_Corrections_Jail_Management_System.pdf PDF
Attachment_A_-_Final_Mandatory_Features.pdf PDF
Attachment_D_-_Orange_County_IT_Standards.pdf PDF
Attachment_E_-_Security_QUESTIONNAIRE.docx DOCX document
Attachment_B_-_EnterpriseSecurityStandards-InternalApplicationsRev4.pdf PDF
Y25-101-KS_Corrections_Jail_Management_System.pdf PDF
ATTACHMENT_G-_Sample_Critical_Reports.pdf PDF
Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf PDF
ATTACHMENT_G-_Sample_Critical_Reports.pdf PDF
Attachment_D_-_Orange_County_IT_Standards.pdf PDF
Attachment_D_-_Orange_County_IT_Standards.pdf PDF
Y25-101-KS_Corrections_Jail_Management_System.pdf PDF
Y25-101-KS_Corrections_Jail_Management_System.pdf PDF
Show all 44

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ENTERPRISE SECURITY STANDARDS, POLICIES, AND GUIDELINES

EXTERNAL DATA HOSTING STANDARD

1.0 Purpose

Thepurposeofthispolicyistoestablishastandardinordertoexecutetheproperretrieval,storage,
transmission,processing,andhandlingofelectronicdata.

2.0 Scope

Thisdocumentappliestoallvendors,networks,systems,andapplicationsthatwilltransmit,process,store,or
handleelectronicdataprovidedbyOrangeCountyGovernmentBoardofCountyCommissioners(OCGBCC).

3.0 Audience

Thisdocumentisintendedfordistributiontothosethatareinvolvedintheretrieval,storage,transmission,
processing,andhandlingofelectronicdata.

4.0 Policies

4.1 Data Input and Processing

4.1.1 AnyuseofSocialSecurityNumberinformationshalladheretoandabidebyFlorida
Statutes,specificallyF.S.119.071.
4.1.2 Thehostedapplicationshallnothaveaccesstosocialsecurityinformation.
4.1.3 Thehostedapplicationshallnothaveaccesstodatacontainingbankinformation.
4.1.4 ThehostedapplicationshallnotbegranteddirectorindirectaccesstoOCGBCCActive
Directoryusernames.
4.1.5 ThehostedapplicationshallnothaveaccesstotheOCGCCinternalorDMZnetworks.
4.2 DataStorageandHandling
4.2.1 Anydataaccessiblefromthehostedapplicationmeetingthefollowingcriteriashallbe
encryptedatafield-levelandintransit:usernames,passwords,names,addresses,
phonenumbers,emailaddresses,birthdates,federal/state/localdocumentnumbers,
accountnumbers,raceorreligiousinformation,usernames,passwords,employee
identificationnumbersandallHIPAAandPCIinformation.
4.2.2 Anydataaccessiblefromthehostedapplicationordirectlyaccessiblefromitshouldbe
encryptedatafieldlevel.
4.3 TransmissionofData
4.3.1 Anydatareferencedaboveshallbetransmittedwithinanencryptedtunnel.
4.4 DisposalofData
Oncedataisnolongerneededormustberemovedfromthesystemitshallbesanitizedand
disposedusingoneofthemethodsbelow:
4.4.1 Sanitization-Overwritingofdatapreviouslystoredonadiskordrivewitharandom
patternofmeaninglessinformation.
4.4.2 Destruction-Physicallydamagingamediumsothatitisnotusablebyanydevicethat
maynormallybeusedtoreadinformationonthemediasuchasacomputer,tape
reader,audioorvideoplayer.
4.4.3 Purgingdata-Usingstrongmagneticdevices;suchasadegausser,itispossibleto
renderdataunrecoverable.
4.5 ExternalAudit
4.5.1 Thevendormustensurethatthewebhostingenvironmentandtheapplicationis
securedusinginformationsecuritybestpractices.
4.5.2 Theexternalservice,system,andapplicationmustpassayearlypenetrationtest
performedbyOrangeCountyISSpersonnel.Alternativelythevendorcanprovidethe
resultsofanexternalauditconductedbyareputable3rdpartysecuritycompany.

5.0 Definitions

TermDefinition
BankInformationCheckingaccountnumbers,creditcardnumbers,oranyuniquenumber
fromabankinstitution.
ElectronicMediaPhysicalobjectsonwhichdatacanbestored,suchasharddrives,zipdrives,
CD-ROMs,DVDs,USBdrives,andtapes.
SanitizationToexpungedatafromstoragemediasothatdatarecoveryisimpossible.
PhysicalDestructionAsanitizationmethodforopticalmedia,suchasCDs.
FloridaStatue119.071DetailedguidelinesonusageofSocialSecurityinformation

6.0 Revision History

October2017 Specified“field-levelencryption”forsensitivedataatrestin4.2.1
Addedusernamesandpasswordstothelistin4.2.1
Addedanoptionfora3rdpartyvendorin4.5.2
Addeddefinitionforfield-levelencryption

August 2012 Added “Bank Information” to list of definitions in 5.0

File details come from the government source that posted it. Updated .