Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf
PDF 74 KB Posted
- Attached to
- Corrections Jail Management System State and local contract opportunity
- Solicitation number
- Y25-101-KS
- Issued by
- Orange County, Orlando City, Florida
About this file
This document is an Enterprise Security Standards policy established by Orange County Government Board of County Commissioners (OCGBCC) for external data hosting environments. The policy applies to all vendors, networks, systems, and applications that transmit, process, store, or handle electronic data on behalf of the County and establishes comprehensive security requirements governing data input, processing, storage, transmission, and disposal. Key requirements include prohibitions on hosted applications accessing Social Security numbers, bank information, Active Directory usernames, or OCGBCC internal networks; encryption of sensitive data fields at rest and in transit, including usernames, passwords, names, addresses, phone numbers, email addresses, birthdates, document numbers, account numbers, and HIPAA/PCI information; and secure data disposal through sanitization, physical destruction, or purging methods. The policy mandates that external services and applications pass yearly penetration testing conducted by Orange County ISS personnel or alternatively provide results from a reputable third-party security company, with vendors required to ensure web hosting environments and applications are secured using information security best practices.
The document was originally adopted in August 2012 and underwent revision in October 2017 to specify field-level encryption requirements for sensitive data at rest, expand the list of protected data elements to include usernames and passwords, and provide vendors the option to conduct third-party security audits as an alternative to Orange County-administered penetration testing. This policy directly supports the County's Corrections Jail Management System procurement (RFP Y25-101-KS), which requires vendors to comply with extensive security standards including field-level data encryption and yearly penetration testing while managing sensitive inmate and operational data within a correctional facility environment serving approximately 900 concurrent users and 5,175 beds.
View the file
Other files for this state and local contract opportunity
Show all 44
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ENTERPRISE SECURITY STANDARDS, POLICIES, AND GUIDELINES
EXTERNAL DATA HOSTING STANDARD
1.0 Purpose
| The | purpose | of | this | policy | is | to | establish | a | standard | in | order | to | execute | the | proper | retrieval, | storage, |
| transmission, | processing, | and | handling | of | electronic | data. |
2.0 Scope
| This | document | applies | to | all | vendors, | networks, | systems, | and | applications | that | will | transmit, | process, | store, | or |
| handle | electronic | data | provided | by | Orange | County | Government | Board | of | County | Commissioners | (OCGBCC). |
3.0 Audience
| This | document | is | intended | for | distribution | to | those | that | are | involved | in | the | retrieval, | storage, | transmission, |
| processing, | and | handling | of | electronic | data. |
4.0 Policies
4.1 Data Input and Processing
| 4.1.1 Any | use | of | Social | Security | Number | information | shall | adhere | to | and | abide | by | Florida |
| Statutes, | specifically | F.S. | 119.071. |
| 4.1.2 The | hosted | application | shall | not | have | access | to | social | security | information. | |||
| 4.1.3 The | hosted | application | shall | not | have | access | to | data | containing | bank | information. | ||
| 4.1.4 The | hosted | application | shall | not | be | granted | direct | or | indirect | access | to | OCGBCC | Active |
| Directory | usernames. | ||||||||||||
| 4.1.5 The | hosted | application | shall | not | have | access | to | the | OCGCC | internal | or | DMZ | networks. |
| 4.2 Data | Storage | and | Handling | |||||||||
| 4.2.1 Any | data | accessible | from | the | hosted | application | meeting | the | following | criteria | shall | be |
| encrypted | at | a | field-level | and | in | transit: | usernames, | passwords, | names, | addresses, |
| phone | numbers, | addresses, | birthdates, | federal/state/local | document | numbers, | ||||
| account | numbers, | race | or | religious | information, | usernames, | passwords, | employee | ||
| identification | numbers | and | all | HIPAA | and | PCI | information. |
| 4.2.2 Any | data | accessible | from | the | hosted | application | or | directly | accessible | from | it | should | be |
| encrypted | at | a | field | level. |
| 4.3 Transmission | of | Data | ||||||||
| 4.3.1 Any | data | referenced | above | shall | be | transmitted | within | an | encrypted | tunnel. |
| 4.4 Disposal | of | Data | |||||||||||||||
| Once | data | is | no | longer | needed | or | must | be | removed | from | the | system | it | shall | be | sanitized | and |
| disposed | using | one | of | the | methods | below: |
| 4.4.1 Sanitization | - | Overwriting | of | data | previously | stored | on | a | disk | or | drive | with | a | random |
| pattern | of | meaningless | information. |
| 4.4.2 Destruction | - | Physically | damaging | a | medium | so | that | it | is | not | usable | by | any | device | that |
| may | normally | be | used | to | read | information | on | the | media | such | as | a | computer, | tape | |
| reader, | audio | or | video | player. |
| 4.4.3 Purging | data | - | Using | strong | magnetic | devices; | such | as | a | degausser, | it | is | possible | to |
| render | data | unrecoverable. |
| 4.5 External | Audit | |||||||||||
| 4.5.1 The | vendor | must | ensure | that | the | web | hosting | environment | and | the | application | is |
| secured | using | information | security | best | practices. | ||||||
| 4.5.2 The | external | service, | system, | and | application | must | pass | a | yearly | penetration | test |
| performed | by | Orange | County | ISS | personnel. | Alternatively | the | vendor | can | provide | the | |
| results | of | an | external | audit | conducted | by | a | reputable | 3rd | party | security | company. |
5.0 Definitions
| Term | Definition | ||||||||||
| Bank | Information | Checking | account | numbers, | credit | card | numbers, | or | any | unique | number |
| from | a | bank | institution. | ||||||||||||
| Electronic | Media | Physical | objects | on | which | data | can | be | stored, | such | as | hard | drives, | zip | drives, |
| CD-ROMs, | DVDs, | USB | drives, | and | tapes. | |||||||
| Sanitization | To | expunge | data | from | storage | media | so | that | data | recovery | is | impossible. |
| Physical | Destruction | A | sanitization | method | for | optical | media, | such | as | CDs. | ||
| Florida | Statue | 119.071 | Detailed | guidelines | on | usage | of | Social | Security | information |
6.0 Revision History
| October | 2017 Specified | “field-level | encryption” | for | sensitive | data | at | rest | in | 4.2.1 |
| Added | usernames | and | passwords | to | the | list | in | 4.2.1 | ||
| Added | an | option | for | a | 3rd | party | vendor | in | 4.5.2 | |
| Added | definition | for | field-level | encryption |
August 2012 Added “Bank Information” to list of definitions in 5.0
File details come from the government source that posted it. Updated .