Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf

PDF 74 KB Posted

Attached to
Corrections Jail Management System State and local contract opportunity
Solicitation number
Y25-101-KS
Issued by
Orange County, Orlando City, Florida

About this file

This document is an Enterprise Security Standards policy established by Orange County Government Board of County Commissioners (OCGBCC) for external data hosting environments. The policy applies to all vendors, networks, systems, and applications that transmit, process, store, or handle electronic data on behalf of the County and establishes comprehensive security requirements governing data input, processing, storage, transmission, and disposal. Key requirements include prohibitions on hosted applications accessing Social Security numbers, bank information, Active Directory usernames, or OCGBCC internal networks; encryption of sensitive data fields at rest and in transit, including usernames, passwords, names, addresses, phone numbers, email addresses, birthdates, document numbers, account numbers, and HIPAA/PCI information; and secure data disposal through sanitization, physical destruction, or purging methods. The policy mandates that external services and applications pass yearly penetration testing conducted by Orange County ISS personnel or alternatively provide results from a reputable third-party security company, with vendors required to ensure web hosting environments and applications are secured using information security best practices.

The document was originally adopted in August 2012 and underwent revision in October 2017 to specify field-level encryption requirements for sensitive data at rest, expand the list of protected data elements to include usernames and passwords, and provide vendors the option to conduct third-party security audits as an alternative to Orange County-administered penetration testing. This policy directly supports the County's Corrections Jail Management System procurement (RFP Y25-101-KS), which requires vendors to comply with extensive security standards including field-level data encryption and yearly penetration testing while managing sensitive inmate and operational data within a correctional facility environment serving approximately 900 concurrent users and 5,175 beds.

View the file

Other files for this state and local contract opportunity

Other files attached to Corrections Jail Management System, newest first.
File Type Posted
Corrections_Jail_Management_System_(Addendum_#6_Revision).pdf PDF
Corrections_Jail_Management_System_(Addendum_#6_Revision).pdf PDF
Corrections_Jail_Management_System_(Addendum_#6_Revision).pdf PDF
Corrections_Jail_Management_System_(Addendum_#4_Revision).pdf PDF
Corrections_Jail_Management_System.pdf PDF
Attachment_B_-_EnterpriseSecurityStandards-InternalApplicationsRev4.pdf PDF
Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf PDF
Y25-101-KS_Corrections_Jail_Management_System.pdf PDF
ATTACHMENT_G-_Sample_Critical_Reports.pdf PDF
Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf PDF
ATTACHMENT_G-_Sample_Critical_Reports.pdf PDF
Attachment_D_-_Orange_County_IT_Standards.pdf PDF
Attachment_D_-_Orange_County_IT_Standards.pdf PDF
Y25-101-KS_Corrections_Jail_Management_System.pdf PDF
Y25-101-KS_Corrections_Jail_Management_System.pdf PDF
Attachment_D_-_Orange_County_IT_Standards.pdf PDF
ATTACHMENT_F_-_System_Interface_Requirements.pdf PDF
Attachment_E_-_Security_QUESTIONNAIRE.docx DOCX document
Y25-101-KS_Corrections_Jail_Management_System.pdf PDF
Attachment_B_-_EnterpriseSecurityStandards-InternalApplicationsRev4.pdf PDF
Attachment_E_-_Security_QUESTIONNAIRE.docx DOCX document
Y25-101-KS_Corrections_Jail_Management_System.pdf PDF
Attachment_A_-_Final_Mandatory_Features.pdf PDF
Attachment_D_-_Orange_County_IT_Standards.pdf PDF
Attachment_E_-_Security_QUESTIONNAIRE.docx DOCX document
ATTACHMENT_F_-_System_Interface_Requirements.pdf PDF
Attachment_E_-_Security_QUESTIONNAIRE.docx DOCX document
Attachment_A_-_Final_Mandatory_Features.pdf PDF
Attachment_D_-_Orange_County_IT_Standards.pdf PDF
ATTACHMENT_F_-_System_Interface_Requirements.pdf PDF
Attachment_A_-_Final_Mandatory_Features.pdf PDF
Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf PDF
Attachment_B_-_EnterpriseSecurityStandards-InternalApplicationsRev4.pdf PDF
ATTACHMENT_G-_Sample_Critical_Reports.pdf PDF
ATTACHMENT_G-_Sample_Critical_Reports.pdf PDF
Attachment_A_-_Final_Mandatory_Features.pdf PDF
Attachment_B_-_EnterpriseSecurityStandards-InternalApplicationsRev4.pdf PDF
ATTACHMENT_F_-_System_Interface_Requirements.pdf PDF
ATTACHMENT_G-_Sample_Critical_Reports.pdf PDF
Attachment_A_-_Final_Mandatory_Features.pdf PDF
Attachment_E_-_Security_QUESTIONNAIRE.docx DOCX document
ATTACHMENT_F_-_System_Interface_Requirements.pdf PDF
Attachment_B_-_EnterpriseSecurityStandards-InternalApplicationsRev4.pdf PDF
Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf PDF
Show all 44

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ENTERPRISE SECURITY STANDARDS, POLICIES, AND GUIDELINES

EXTERNAL DATA HOSTING STANDARD

1.0 Purpose

Thepurposeofthispolicyistoestablishastandardinordertoexecutetheproperretrieval,storage,
transmission,processing,andhandlingofelectronicdata.

2.0 Scope

Thisdocumentappliestoallvendors,networks,systems,andapplicationsthatwilltransmit,process,store,or
handleelectronicdataprovidedbyOrangeCountyGovernmentBoardofCountyCommissioners(OCGBCC).

3.0 Audience

Thisdocumentisintendedfordistributiontothosethatareinvolvedintheretrieval,storage,transmission,
processing,andhandlingofelectronicdata.

4.0 Policies

4.1 Data Input and Processing

4.1.1 AnyuseofSocialSecurityNumberinformationshalladheretoandabidebyFlorida
Statutes,specificallyF.S.119.071.
4.1.2 Thehostedapplicationshallnothaveaccesstosocialsecurityinformation.
4.1.3 Thehostedapplicationshallnothaveaccesstodatacontainingbankinformation.
4.1.4 ThehostedapplicationshallnotbegranteddirectorindirectaccesstoOCGBCCActive
Directoryusernames.
4.1.5 ThehostedapplicationshallnothaveaccesstotheOCGCCinternalorDMZnetworks.
4.2 DataStorageandHandling
4.2.1 Anydataaccessiblefromthehostedapplicationmeetingthefollowingcriteriashallbe
encryptedatafield-levelandintransit:usernames,passwords,names,addresses,
phonenumbers,emailaddresses,birthdates,federal/state/localdocumentnumbers,
accountnumbers,raceorreligiousinformation,usernames,passwords,employee
identificationnumbersandallHIPAAandPCIinformation.
4.2.2 Anydataaccessiblefromthehostedapplicationordirectlyaccessiblefromitshouldbe
encryptedatafieldlevel.
4.3 TransmissionofData
4.3.1 Anydatareferencedaboveshallbetransmittedwithinanencryptedtunnel.
4.4 DisposalofData
Oncedataisnolongerneededormustberemovedfromthesystemitshallbesanitizedand
disposedusingoneofthemethodsbelow:
4.4.1 Sanitization-Overwritingofdatapreviouslystoredonadiskordrivewitharandom
patternofmeaninglessinformation.
4.4.2 Destruction-Physicallydamagingamediumsothatitisnotusablebyanydevicethat
maynormallybeusedtoreadinformationonthemediasuchasacomputer,tape
reader,audioorvideoplayer.
4.4.3 Purgingdata-Usingstrongmagneticdevices;suchasadegausser,itispossibleto
renderdataunrecoverable.
4.5 ExternalAudit
4.5.1 Thevendormustensurethatthewebhostingenvironmentandtheapplicationis
securedusinginformationsecuritybestpractices.
4.5.2 Theexternalservice,system,andapplicationmustpassayearlypenetrationtest
performedbyOrangeCountyISSpersonnel.Alternativelythevendorcanprovidethe
resultsofanexternalauditconductedbyareputable3rdpartysecuritycompany.

5.0 Definitions

TermDefinition
BankInformationCheckingaccountnumbers,creditcardnumbers,oranyuniquenumber
fromabankinstitution.
ElectronicMediaPhysicalobjectsonwhichdatacanbestored,suchasharddrives,zipdrives,
CD-ROMs,DVDs,USBdrives,andtapes.
SanitizationToexpungedatafromstoragemediasothatdatarecoveryisimpossible.
PhysicalDestructionAsanitizationmethodforopticalmedia,suchasCDs.
FloridaStatue119.071DetailedguidelinesonusageofSocialSecurityinformation

6.0 Revision History

October2017 Specified“field-levelencryption”forsensitivedataatrestin4.2.1
Addedusernamesandpasswordstothelistin4.2.1
Addedanoptionfora3rdpartyvendorin4.5.2
Addeddefinitionforfield-levelencryption

August 2012 Added “Bank Information” to list of definitions in 5.0

File details come from the government source that posted it. Updated .