Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf

PDF 74 KB Posted

Attached to
Corrections Jail Management System State and local contract opportunity
Solicitation number
Y25-101-KS
Issued by
Orange County, Orlando City, Florida

About this file

This is an Enterprise Security Standards policy document established by Orange County Government Board of County Commissioners (OCGBCC) governing external data hosting requirements for vendors handling electronic data. The policy establishes mandatory security standards for the retrieval, storage, transmission, processing, and handling of all electronic data provided by the County. The document applies to all vendors, networks, systems, and applications that interact with County data and is intended for distribution to personnel involved in data management operations.

The policy establishes comprehensive security controls across four primary areas: data input and processing restrictions that prohibit hosted applications from accessing Social Security numbers, bank information, Active Directory usernames, or internal networks; data storage and handling requirements mandating field-level encryption and in-transit encryption for sensitive information including usernames, passwords, names, addresses, phone numbers, email addresses, birthdates, document numbers, account numbers, race or religious information, employee identification numbers, and all HIPAA and PCI information; data transmission requirements specifying that all referenced data must be transmitted within encrypted tunnels; and data disposal standards permitting sanitization through data overwriting, physical destruction, or magnetic purging methods. Section 4.5 requires vendors to ensure web hosting environments and applications are secured using information security best practices and mandate that external services, systems, and applications pass yearly penetration testing performed by Orange County ISS personnel or provide results from an external audit conducted by a reputable third-party security company. The policy was last revised in October 2017 with clarifications regarding field-level encryption specifications and the addition of third-party audit options as an alternative to internal penetration testing.

View the file

Other files for this state and local contract opportunity

Other files attached to Corrections Jail Management System, newest first.
File Type Posted
Corrections_Jail_Management_System_(Addendum_#6_Revision).pdf PDF
Corrections_Jail_Management_System_(Addendum_#6_Revision).pdf PDF
Corrections_Jail_Management_System_(Addendum_#6_Revision).pdf PDF
Corrections_Jail_Management_System_(Addendum_#4_Revision).pdf PDF
Corrections_Jail_Management_System.pdf PDF
Attachment_B_-_EnterpriseSecurityStandards-InternalApplicationsRev4.pdf PDF
Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf PDF
Y25-101-KS_Corrections_Jail_Management_System.pdf PDF
ATTACHMENT_G-_Sample_Critical_Reports.pdf PDF
Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf PDF
ATTACHMENT_G-_Sample_Critical_Reports.pdf PDF
Attachment_D_-_Orange_County_IT_Standards.pdf PDF
Attachment_D_-_Orange_County_IT_Standards.pdf PDF
Y25-101-KS_Corrections_Jail_Management_System.pdf PDF
Y25-101-KS_Corrections_Jail_Management_System.pdf PDF
ATTACHMENT_F_-_System_Interface_Requirements.pdf PDF
Attachment_E_-_Security_QUESTIONNAIRE.docx DOCX document
Attachment_A_-_Final_Mandatory_Features.pdf PDF
Attachment_D_-_Orange_County_IT_Standards.pdf PDF
ATTACHMENT_F_-_System_Interface_Requirements.pdf PDF
Attachment_A_-_Final_Mandatory_Features.pdf PDF
Attachment_B_-_EnterpriseSecurityStandards-InternalApplicationsRev4.pdf PDF
ATTACHMENT_G-_Sample_Critical_Reports.pdf PDF
Attachment_D_-_Orange_County_IT_Standards.pdf PDF
ATTACHMENT_F_-_System_Interface_Requirements.pdf PDF
Attachment_E_-_Security_QUESTIONNAIRE.docx DOCX document
Y25-101-KS_Corrections_Jail_Management_System.pdf PDF
Attachment_B_-_EnterpriseSecurityStandards-InternalApplicationsRev4.pdf PDF
Attachment_E_-_Security_QUESTIONNAIRE.docx DOCX document
Y25-101-KS_Corrections_Jail_Management_System.pdf PDF
Attachment_A_-_Final_Mandatory_Features.pdf PDF
Attachment_D_-_Orange_County_IT_Standards.pdf PDF
Attachment_E_-_Security_QUESTIONNAIRE.docx DOCX document
ATTACHMENT_G-_Sample_Critical_Reports.pdf PDF
Attachment_A_-_Final_Mandatory_Features.pdf PDF
Attachment_B_-_EnterpriseSecurityStandards-InternalApplicationsRev4.pdf PDF
ATTACHMENT_F_-_System_Interface_Requirements.pdf PDF
ATTACHMENT_G-_Sample_Critical_Reports.pdf PDF
Attachment_A_-_Final_Mandatory_Features.pdf PDF
Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf PDF
Attachment_E_-_Security_QUESTIONNAIRE.docx DOCX document
ATTACHMENT_F_-_System_Interface_Requirements.pdf PDF
Attachment_B_-_EnterpriseSecurityStandards-InternalApplicationsRev4.pdf PDF
Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf PDF
Show all 44

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ENTERPRISE SECURITY STANDARDS, POLICIES, AND GUIDELINES

EXTERNAL DATA HOSTING STANDARD

1.0 Purpose

Thepurposeofthispolicyistoestablishastandardinordertoexecutetheproperretrieval,storage,
transmission,processing,andhandlingofelectronicdata.

2.0 Scope

Thisdocumentappliestoallvendors,networks,systems,andapplicationsthatwilltransmit,process,store,or
handleelectronicdataprovidedbyOrangeCountyGovernmentBoardofCountyCommissioners(OCGBCC).

3.0 Audience

Thisdocumentisintendedfordistributiontothosethatareinvolvedintheretrieval,storage,transmission,
processing,andhandlingofelectronicdata.

4.0 Policies

4.1 Data Input and Processing

4.1.1 AnyuseofSocialSecurityNumberinformationshalladheretoandabidebyFlorida
Statutes,specificallyF.S.119.071.
4.1.2 Thehostedapplicationshallnothaveaccesstosocialsecurityinformation.
4.1.3 Thehostedapplicationshallnothaveaccesstodatacontainingbankinformation.
4.1.4 ThehostedapplicationshallnotbegranteddirectorindirectaccesstoOCGBCCActive
Directoryusernames.
4.1.5 ThehostedapplicationshallnothaveaccesstotheOCGCCinternalorDMZnetworks.
4.2 DataStorageandHandling
4.2.1 Anydataaccessiblefromthehostedapplicationmeetingthefollowingcriteriashallbe
encryptedatafield-levelandintransit:usernames,passwords,names,addresses,
phonenumbers,emailaddresses,birthdates,federal/state/localdocumentnumbers,
accountnumbers,raceorreligiousinformation,usernames,passwords,employee
identificationnumbersandallHIPAAandPCIinformation.
4.2.2 Anydataaccessiblefromthehostedapplicationordirectlyaccessiblefromitshouldbe
encryptedatafieldlevel.
4.3 TransmissionofData
4.3.1 Anydatareferencedaboveshallbetransmittedwithinanencryptedtunnel.
4.4 DisposalofData
Oncedataisnolongerneededormustberemovedfromthesystemitshallbesanitizedand
disposedusingoneofthemethodsbelow:
4.4.1 Sanitization-Overwritingofdatapreviouslystoredonadiskordrivewitharandom
patternofmeaninglessinformation.
4.4.2 Destruction-Physicallydamagingamediumsothatitisnotusablebyanydevicethat
maynormallybeusedtoreadinformationonthemediasuchasacomputer,tape
reader,audioorvideoplayer.
4.4.3 Purgingdata-Usingstrongmagneticdevices;suchasadegausser,itispossibleto
renderdataunrecoverable.
4.5 ExternalAudit
4.5.1 Thevendormustensurethatthewebhostingenvironmentandtheapplicationis
securedusinginformationsecuritybestpractices.
4.5.2 Theexternalservice,system,andapplicationmustpassayearlypenetrationtest
performedbyOrangeCountyISSpersonnel.Alternativelythevendorcanprovidethe
resultsofanexternalauditconductedbyareputable3rdpartysecuritycompany.

5.0 Definitions

TermDefinition
BankInformationCheckingaccountnumbers,creditcardnumbers,oranyuniquenumber
fromabankinstitution.
ElectronicMediaPhysicalobjectsonwhichdatacanbestored,suchasharddrives,zipdrives,
CD-ROMs,DVDs,USBdrives,andtapes.
SanitizationToexpungedatafromstoragemediasothatdatarecoveryisimpossible.
PhysicalDestructionAsanitizationmethodforopticalmedia,suchasCDs.
FloridaStatue119.071DetailedguidelinesonusageofSocialSecurityinformation

6.0 Revision History

October2017 Specified“field-levelencryption”forsensitivedataatrestin4.2.1
Addedusernamesandpasswordstothelistin4.2.1
Addedanoptionfora3rdpartyvendorin4.5.2
Addeddefinitionforfield-levelencryption

August 2012 Added “Bank Information” to list of definitions in 5.0

File details come from the government source that posted it. Updated .