Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf

PDF 74 KB Posted

Attached to
Corrections Jail Management System State and local contract opportunity
Solicitation number
Y25-101-KS
Issued by
Orange County, Orlando City, Florida

About this file

This is an Enterprise Security Standards policy document issued by Orange County Government Board of County Commissioners (OCGBCC) establishing external data hosting requirements for vendors handling electronic data. The policy applies to all vendors, networks, systems, and applications transmitting, processing, storing, or handling Orange County Government data and establishes mandatory security standards for the Corrections Jail Management System procurement (Y25-101-KS). Sealed electronic responses must be submitted through the OpenGov e-Procurement Platform by January 8, 2026, at 4:00 pm EST, with alternative submission deadlines of March 5, 2026, and March 12, 2026. A non-mandatory pre-bid meeting is scheduled for December 3, 2025, at 11:00 am, with written questions due by December 10, 2025, at 5:00 pm EST. The contract term is five years with optional renewal provisions.

The policy mandates comprehensive security controls including field-level encryption for sensitive data such as usernames, passwords, names, addresses, phone numbers, email addresses, birthdates, document numbers, account numbers, and all HIPAA and PCI information. Vendors are explicitly prohibited from accessing Social Security numbers, bank information, Active Directory credentials, or internal OCGBCC networks. All data transmission must occur within encrypted tunnels, and data disposal must follow sanitization, destruction, or purging methodologies. The vendor must ensure yearly penetration testing either through Orange County ISS personnel or through a reputable third-party security company audit. The County requires comprehensive insurance coverage including $1 million in Commercial General Liability, $1 million in Professional E&O, $5 million in Network Security Liability, and $1 million in Fidelity/Crime Liability. Vendors must demonstrate previous implementation experience in correctional facilities with 1,000 or more beds and comply with FBI CJJIS Security Policy and Americans with Disabilities Act requirements.

View the file

Other files for this state and local contract opportunity

Other files attached to Corrections Jail Management System, newest first.
File Type Posted
Corrections_Jail_Management_System_(Addendum_#6_Revision).pdf PDF
Corrections_Jail_Management_System_(Addendum_#6_Revision).pdf PDF
Corrections_Jail_Management_System_(Addendum_#6_Revision).pdf PDF
Corrections_Jail_Management_System_(Addendum_#4_Revision).pdf PDF
Corrections_Jail_Management_System.pdf PDF
Attachment_B_-_EnterpriseSecurityStandards-InternalApplicationsRev4.pdf PDF
Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf PDF
Y25-101-KS_Corrections_Jail_Management_System.pdf PDF
ATTACHMENT_G-_Sample_Critical_Reports.pdf PDF
Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf PDF
ATTACHMENT_G-_Sample_Critical_Reports.pdf PDF
Attachment_D_-_Orange_County_IT_Standards.pdf PDF
Attachment_D_-_Orange_County_IT_Standards.pdf PDF
Y25-101-KS_Corrections_Jail_Management_System.pdf PDF
Y25-101-KS_Corrections_Jail_Management_System.pdf PDF
ATTACHMENT_G-_Sample_Critical_Reports.pdf PDF
Attachment_A_-_Final_Mandatory_Features.pdf PDF
Attachment_B_-_EnterpriseSecurityStandards-InternalApplicationsRev4.pdf PDF
ATTACHMENT_F_-_System_Interface_Requirements.pdf PDF
ATTACHMENT_G-_Sample_Critical_Reports.pdf PDF
Attachment_A_-_Final_Mandatory_Features.pdf PDF
Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf PDF
Attachment_E_-_Security_QUESTIONNAIRE.docx DOCX document
ATTACHMENT_F_-_System_Interface_Requirements.pdf PDF
Attachment_B_-_EnterpriseSecurityStandards-InternalApplicationsRev4.pdf PDF
Attachment_D_-_Orange_County_IT_Standards.pdf PDF
ATTACHMENT_F_-_System_Interface_Requirements.pdf PDF
Attachment_E_-_Security_QUESTIONNAIRE.docx DOCX document
Y25-101-KS_Corrections_Jail_Management_System.pdf PDF
Attachment_B_-_EnterpriseSecurityStandards-InternalApplicationsRev4.pdf PDF
Attachment_E_-_Security_QUESTIONNAIRE.docx DOCX document
Y25-101-KS_Corrections_Jail_Management_System.pdf PDF
Attachment_A_-_Final_Mandatory_Features.pdf PDF
Attachment_D_-_Orange_County_IT_Standards.pdf PDF
Attachment_E_-_Security_QUESTIONNAIRE.docx DOCX document
ATTACHMENT_F_-_System_Interface_Requirements.pdf PDF
Attachment_E_-_Security_QUESTIONNAIRE.docx DOCX document
Attachment_A_-_Final_Mandatory_Features.pdf PDF
Attachment_D_-_Orange_County_IT_Standards.pdf PDF
ATTACHMENT_F_-_System_Interface_Requirements.pdf PDF
Attachment_A_-_Final_Mandatory_Features.pdf PDF
Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf PDF
Attachment_B_-_EnterpriseSecurityStandards-InternalApplicationsRev4.pdf PDF
ATTACHMENT_G-_Sample_Critical_Reports.pdf PDF
Show all 44

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ENTERPRISE SECURITY STANDARDS, POLICIES, AND GUIDELINES

EXTERNAL DATA HOSTING STANDARD

1.0 Purpose

Thepurposeofthispolicyistoestablishastandardinordertoexecutetheproperretrieval,storage,
transmission,processing,andhandlingofelectronicdata.

2.0 Scope

Thisdocumentappliestoallvendors,networks,systems,andapplicationsthatwilltransmit,process,store,or
handleelectronicdataprovidedbyOrangeCountyGovernmentBoardofCountyCommissioners(OCGBCC).

3.0 Audience

Thisdocumentisintendedfordistributiontothosethatareinvolvedintheretrieval,storage,transmission,
processing,andhandlingofelectronicdata.

4.0 Policies

4.1 Data Input and Processing

4.1.1 AnyuseofSocialSecurityNumberinformationshalladheretoandabidebyFlorida
Statutes,specificallyF.S.119.071.
4.1.2 Thehostedapplicationshallnothaveaccesstosocialsecurityinformation.
4.1.3 Thehostedapplicationshallnothaveaccesstodatacontainingbankinformation.
4.1.4 ThehostedapplicationshallnotbegranteddirectorindirectaccesstoOCGBCCActive
Directoryusernames.
4.1.5 ThehostedapplicationshallnothaveaccesstotheOCGCCinternalorDMZnetworks.
4.2 DataStorageandHandling
4.2.1 Anydataaccessiblefromthehostedapplicationmeetingthefollowingcriteriashallbe
encryptedatafield-levelandintransit:usernames,passwords,names,addresses,
phonenumbers,emailaddresses,birthdates,federal/state/localdocumentnumbers,
accountnumbers,raceorreligiousinformation,usernames,passwords,employee
identificationnumbersandallHIPAAandPCIinformation.
4.2.2 Anydataaccessiblefromthehostedapplicationordirectlyaccessiblefromitshouldbe
encryptedatafieldlevel.
4.3 TransmissionofData
4.3.1 Anydatareferencedaboveshallbetransmittedwithinanencryptedtunnel.
4.4 DisposalofData
Oncedataisnolongerneededormustberemovedfromthesystemitshallbesanitizedand
disposedusingoneofthemethodsbelow:
4.4.1 Sanitization-Overwritingofdatapreviouslystoredonadiskordrivewitharandom
patternofmeaninglessinformation.
4.4.2 Destruction-Physicallydamagingamediumsothatitisnotusablebyanydevicethat
maynormallybeusedtoreadinformationonthemediasuchasacomputer,tape
reader,audioorvideoplayer.
4.4.3 Purgingdata-Usingstrongmagneticdevices;suchasadegausser,itispossibleto
renderdataunrecoverable.
4.5 ExternalAudit
4.5.1 Thevendormustensurethatthewebhostingenvironmentandtheapplicationis
securedusinginformationsecuritybestpractices.
4.5.2 Theexternalservice,system,andapplicationmustpassayearlypenetrationtest
performedbyOrangeCountyISSpersonnel.Alternativelythevendorcanprovidethe
resultsofanexternalauditconductedbyareputable3rdpartysecuritycompany.

5.0 Definitions

TermDefinition
BankInformationCheckingaccountnumbers,creditcardnumbers,oranyuniquenumber
fromabankinstitution.
ElectronicMediaPhysicalobjectsonwhichdatacanbestored,suchasharddrives,zipdrives,
CD-ROMs,DVDs,USBdrives,andtapes.
SanitizationToexpungedatafromstoragemediasothatdatarecoveryisimpossible.
PhysicalDestructionAsanitizationmethodforopticalmedia,suchasCDs.
FloridaStatue119.071DetailedguidelinesonusageofSocialSecurityinformation

6.0 Revision History

October2017 Specified“field-levelencryption”forsensitivedataatrestin4.2.1
Addedusernamesandpasswordstothelistin4.2.1
Addedanoptionfora3rdpartyvendorin4.5.2
Addeddefinitionforfield-levelencryption

August 2012 Added “Bank Information” to list of definitions in 5.0

File details come from the government source that posted it. Updated .