Attachment_C_-_ISS_-_Enterprise_Security_Standards_-_External_Data_Hosting_Rev3.pdf
PDF 74 KB Posted
- Attached to
- Corrections Jail Management System State and local contract opportunity
- Solicitation number
- Y25-101-KS
- Issued by
- Orange County, Orlando City, Florida
About this file
This is an Enterprise Security Standards policy document issued by Orange County Government Board of County Commissioners (OCGBCC) establishing external data hosting requirements for vendors handling electronic data. The policy applies to all vendors, networks, systems, and applications transmitting, processing, storing, or handling Orange County Government data and establishes mandatory security standards for the Corrections Jail Management System procurement (Y25-101-KS). Sealed electronic responses must be submitted through the OpenGov e-Procurement Platform by January 8, 2026, at 4:00 pm EST, with alternative submission deadlines of March 5, 2026, and March 12, 2026. A non-mandatory pre-bid meeting is scheduled for December 3, 2025, at 11:00 am, with written questions due by December 10, 2025, at 5:00 pm EST. The contract term is five years with optional renewal provisions.
The policy mandates comprehensive security controls including field-level encryption for sensitive data such as usernames, passwords, names, addresses, phone numbers, email addresses, birthdates, document numbers, account numbers, and all HIPAA and PCI information. Vendors are explicitly prohibited from accessing Social Security numbers, bank information, Active Directory credentials, or internal OCGBCC networks. All data transmission must occur within encrypted tunnels, and data disposal must follow sanitization, destruction, or purging methodologies. The vendor must ensure yearly penetration testing either through Orange County ISS personnel or through a reputable third-party security company audit. The County requires comprehensive insurance coverage including $1 million in Commercial General Liability, $1 million in Professional E&O, $5 million in Network Security Liability, and $1 million in Fidelity/Crime Liability. Vendors must demonstrate previous implementation experience in correctional facilities with 1,000 or more beds and comply with FBI CJJIS Security Policy and Americans with Disabilities Act requirements.
View the file
Other files for this state and local contract opportunity
Show all 44
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ENTERPRISE SECURITY STANDARDS, POLICIES, AND GUIDELINES
EXTERNAL DATA HOSTING STANDARD
1.0 Purpose
| The | purpose | of | this | policy | is | to | establish | a | standard | in | order | to | execute | the | proper | retrieval, | storage, |
| transmission, | processing, | and | handling | of | electronic | data. |
2.0 Scope
| This | document | applies | to | all | vendors, | networks, | systems, | and | applications | that | will | transmit, | process, | store, | or |
| handle | electronic | data | provided | by | Orange | County | Government | Board | of | County | Commissioners | (OCGBCC). |
3.0 Audience
| This | document | is | intended | for | distribution | to | those | that | are | involved | in | the | retrieval, | storage, | transmission, |
| processing, | and | handling | of | electronic | data. |
4.0 Policies
4.1 Data Input and Processing
| 4.1.1 Any | use | of | Social | Security | Number | information | shall | adhere | to | and | abide | by | Florida |
| Statutes, | specifically | F.S. | 119.071. |
| 4.1.2 The | hosted | application | shall | not | have | access | to | social | security | information. | |||
| 4.1.3 The | hosted | application | shall | not | have | access | to | data | containing | bank | information. | ||
| 4.1.4 The | hosted | application | shall | not | be | granted | direct | or | indirect | access | to | OCGBCC | Active |
| Directory | usernames. | ||||||||||||
| 4.1.5 The | hosted | application | shall | not | have | access | to | the | OCGCC | internal | or | DMZ | networks. |
| 4.2 Data | Storage | and | Handling | |||||||||
| 4.2.1 Any | data | accessible | from | the | hosted | application | meeting | the | following | criteria | shall | be |
| encrypted | at | a | field-level | and | in | transit: | usernames, | passwords, | names, | addresses, |
| phone | numbers, | addresses, | birthdates, | federal/state/local | document | numbers, | ||||
| account | numbers, | race | or | religious | information, | usernames, | passwords, | employee | ||
| identification | numbers | and | all | HIPAA | and | PCI | information. |
| 4.2.2 Any | data | accessible | from | the | hosted | application | or | directly | accessible | from | it | should | be |
| encrypted | at | a | field | level. |
| 4.3 Transmission | of | Data | ||||||||
| 4.3.1 Any | data | referenced | above | shall | be | transmitted | within | an | encrypted | tunnel. |
| 4.4 Disposal | of | Data | |||||||||||||||
| Once | data | is | no | longer | needed | or | must | be | removed | from | the | system | it | shall | be | sanitized | and |
| disposed | using | one | of | the | methods | below: |
| 4.4.1 Sanitization | - | Overwriting | of | data | previously | stored | on | a | disk | or | drive | with | a | random |
| pattern | of | meaningless | information. |
| 4.4.2 Destruction | - | Physically | damaging | a | medium | so | that | it | is | not | usable | by | any | device | that |
| may | normally | be | used | to | read | information | on | the | media | such | as | a | computer, | tape | |
| reader, | audio | or | video | player. |
| 4.4.3 Purging | data | - | Using | strong | magnetic | devices; | such | as | a | degausser, | it | is | possible | to |
| render | data | unrecoverable. |
| 4.5 External | Audit | |||||||||||
| 4.5.1 The | vendor | must | ensure | that | the | web | hosting | environment | and | the | application | is |
| secured | using | information | security | best | practices. | ||||||
| 4.5.2 The | external | service, | system, | and | application | must | pass | a | yearly | penetration | test |
| performed | by | Orange | County | ISS | personnel. | Alternatively | the | vendor | can | provide | the | |
| results | of | an | external | audit | conducted | by | a | reputable | 3rd | party | security | company. |
5.0 Definitions
| Term | Definition | ||||||||||
| Bank | Information | Checking | account | numbers, | credit | card | numbers, | or | any | unique | number |
| from | a | bank | institution. | ||||||||||||
| Electronic | Media | Physical | objects | on | which | data | can | be | stored, | such | as | hard | drives, | zip | drives, |
| CD-ROMs, | DVDs, | USB | drives, | and | tapes. | |||||||
| Sanitization | To | expunge | data | from | storage | media | so | that | data | recovery | is | impossible. |
| Physical | Destruction | A | sanitization | method | for | optical | media, | such | as | CDs. | ||
| Florida | Statue | 119.071 | Detailed | guidelines | on | usage | of | Social | Security | information |
6.0 Revision History
| October | 2017 Specified | “field-level | encryption” | for | sensitive | data | at | rest | in | 4.2.1 |
| Added | usernames | and | passwords | to | the | list | in | 4.2.1 | ||
| Added | an | option | for | a | 3rd | party | vendor | in | 4.5.2 | |
| Added | definition | for | field-level | encryption |
August 2012 Added “Bank Information” to list of definitions in 5.0
File details come from the government source that posted it. Updated .