Attachment E- DSS Data Security Addendum.docx

DOCX document 158 KB Posted

Attached to
ECONOMIC SVCS SYSTEM APP MODERNIZATION State and local contract opportunity
Solicitation number
5400024945
Issued by
Richland County, South Carolina

About this file

This is a Data Security Addendum issued by the South Carolina Department of Social Services (DSS) establishing security and confidentiality standards for service providers handling personal, proprietary, and confidential information in connection with the Economic Services System Application Modernization contract. The addendum outlines comprehensive obligations for service providers regarding the collection, receipt, transmission, storage, disposal, use, and disclosure of DSS data. Service providers must maintain strict confidentiality using appropriate care standards to prevent unauthorized access or disclosure and may only use DSS data for purposes explicitly authorized in the underlying agreement. The document specifies that DSS data remains the confidential information of DSS, not the service provider, and any disclosure to unauthorized third parties requires prior written consent from DSS unless mandated by law.

Service providers must implement administrative, physical, and technical safeguards consistent with industry standards including ISO/IEC 27001:2022, ISO/IEC 27002:2022, and NIST SP 800-53, with specific requirements for encryption of highly-sensitive data, network security, authentication controls, personnel security, and privacy training. Security breach notification must occur within twenty-four hours to designated DSS contacts by phone and email. Service providers must conduct annual vulnerability assessments and site audits, provide audit results upon request, and fully cooperate with DSS investigations and audits. The addendum requires service providers to reimburse DSS for costs incurred in responding to security breaches, maintain a disciplinary process for unauthorized data access, and immediately notify DSS within twenty-four hours when authorized employees depart. Upon contract termination or DSS request, all DSS data must be returned or securely destroyed with written certification. Breach of any provision constitutes material breach permitting immediate contract termination, and service providers must defend and indemnify DSS from third-party claims arising from noncompliance with these security obligations.

View the file

Other files for this state and local contract opportunity

Other files attached to ECONOMIC SVCS SYSTEM APP MODERNIZATION, newest first.
File Type Posted
Attachment R- ESSAM Business Process Analysis Report.pdf PDF
Attachment O-Information for Offerors to Submit Response Table.docx DOCX document
Attachment F- Project Management Plan Template.docx DOCX document
Attachment K- SNAP Eligibility Go Live Reqs.pdf PDF
Attachment I- DSNAP.pdf PDF
Attachment P- Cost Proposal Workbook.xlsx XLSX spreadsheet
Attachment C- Current Technologies & Standards.xlsx XLSX spreadsheet
Attachment B-SNAP System Integrity Review Tool.pdf PDF
Attachment L- Hand Book 901v2.4.pdf PDF
Attachment G- SNAP Manual_rev.pdf PDF
Attachment J- Benefit Integrity Manual.pdf PDF
Attachment T- Answers to Questions from Offerors.xlsx XLSX spreadsheet
Attachment Q- Question Template.docx DOCX document
Attachment H- TANF Policy Manual.pdf PDF
Attachment M- DSS State Office Leadership.pdf PDF
Attachment D-List of Interfaces-UPDATED.xlsx XLSX spreadsheet
Amendment 1.docx DOCX document
Attachment N- Service Provider Security Assessment Questionnaire.docx DOCX document
Attachment S- Federal Clauses.pdf PDF
Solicitation.docx DOCX document
Award Extension Notice.doc DOC document
Attachment A-ESSAM Requirements Definition-UPDATED.xlsx XLSX spreadsheet
Show all 22

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Data Security Addendum

1.0 Standard of Care

(a) Service Provider acknowledges and agrees that, in the course of its engagement by South Carolina Department of Social Services, (“DSS”), Service Provider may receive or have access to Personal, Proprietary, and Confidential Information. Service Provider shall comply with the terms and conditions set forth in this Agreement in its collection, receipt, transmission, storage, disposal, use and disclosure of such Personal, Proprietary and Confidential Information (“DSS Data”) and be responsible for the unauthorized collection, receipt, transmission, access, storage, disposal, use and disclosure of DSS Data under its control or in its possession by all authorized employees/authorized persons. Service Provider shall be responsible for, and remain liable to, DSS for the actions and omissions of all authorized persons that are not authorized employees concerning the treatment of DSS Data as if they were Service Provider’s own actions and omissions.

(b) DSS Data is deemed to be Confidential Information of DSS and is not Confidential Information of Service Provider. In the event of a conflict or inconsistency between this Section and the confidentiality/compliance with laws sections of this Agreement, the terms and conditions set forth in this Section shall govern and control.

(c) In recognition of the foregoing, Service Provider agrees and covenants that it shall:

(i) keep and maintain all DSS Data in strict confidence, using such degree of care as is appropriate to avoid unauthorized access, use or disclosure;

(ii) use and disclose DSS Data solely and exclusively for the purposes for which the DSS Data, or access to it, is provided pursuant to the terms and conditions of this Agreement, and not use, sell, rent, transfer, distribute, or otherwise disclose or make available DSS Data for Service Provider’s own purposes or for the benefit of anyone other than DSS, in each case, without DSS’s prior written consent; and

(iii) not, directly, or indirectly, disclose Personal or Proprietary Information to any person other than its authorized employees/authorized persons, including any, subcontractors, agents, outsourcers, or auditors (an “Unauthorized Third Party”), without express written consent from DSS unless and to the extent required by Government Authorities or as otherwise, to the extent expressly required, by applicable law, in which case, Service Provider shall:

(i) notify DSS before such disclosure or within 48 hours thereafter;

(ii) be responsible for and remain liable to DSS for the actions and omissions of such Unauthorized Third Party concerning the treatment of such DSS Data as if they were Service Provider’s own actions and omissions; and

(iii) require the Unauthorized Third Party that has access to DSS Data to execute a written agreement agreeing to comply with the terms and conditions of this Agreement relating to the treatment of Personal or Proprietary information

2.0 Information Security

(a) Service Provider represents and warrants that its collection, access, use, storage, disposal, and disclosure of DSS Data does and will comply with all applicable federal and state privacy and data protection laws, as well as all other applicable regulations and directives.

(b) Without limiting Service Provider’s obligations under Section [3(a)], Service Provider shall implement administrative, physical and technical safeguards (“Information Security Program”) to protect DSS Data that are no less rigorous than accepted industry practices ([including/specifically] the International Organization for Standardization’s standards: ISO/IEC 27001:2022 – Information Security Management Systems – Requirements and ISO-IEC 27002:2022 – Code of Practice for International Security Management, the National Institute of Standards and Technology (“NIST”) SP800-53, or other applicable industry standards for information security, and shall ensure that all such safeguards, including the manner in which DSS Data is collected, accessed, used, stored, processed, disposed of and disclosed, comply with applicable data protection and privacy laws, as well as the terms and conditions of this Agreement.

(c) If, in the course of its engagement by DSS, Service Provider has access to or will collect, access, use, store, process, dispose of or disclose credit, debit or other payment cardholder information, Service Provider shall at all times remain in compliance with the Payment Card Industry Data Security Standard (“PCI DSS”) requirements, including remaining aware at all times of changes to the PCI DSS and promptly implementing all procedures and practices as may be necessary to remain in compliance with the PCI DSS, in each case, at Service Provider’s sole cost and expense.

(d) At a minimum, Service Provider’s safeguards for the protection of DSS Data shall include:

(i) limiting access of DSS Data to authorized employees/authorized persons;

(ii) securing business facilities, data centers, paper files, servers, back-up systems and computing equipment, including, but not limited to, all mobile devices and other equipment with information storage capability;

(iii) implementing network, device application, database and platform security;

(iv) securing information transmission, storage and disposal;

(v) implementing authentication and access controls within media, applications, operating systems and equipment;

(vi) encrypting Highly-Sensitive DSS Data stored on any mobile media;

(vii) encrypting Highly-Sensitive DSS Data transmitted over public or wireless networks;

(viii) strictly segregating DSS Data from information of Service Provider or its other DSSs so that DSS Data is not commingled with any other types of information;

(ix) implementing appropriate personnel security and integrity procedures and practices, including, but not limited to, conducting background checks consistent with applicable law; and

(x) providing appropriate privacy and information security training to Service Provider’s employees.

(e) During the term of each authorized employee’s employment by Service Provider, Service Provider shall at all times cause such authorized employees to abide strictly by Service Provider’s obligations under this Agreement. Service Provider further agrees that it shall maintain a disciplinary process to address any unauthorized access, use or disclosure of DSS Data by any of Service Provider’s officers, partners, principals, employees, agents, or contractors. Upon DSS’s written request, Service Provider shall promptly identify for DSS, in writing, all authorized employees as of the date of such request.

(f) At the end of each authorized employee’s employment with the Service Provider, Service Provider shall notify DSS within 24 hours of the employee’s departure if individual accounts were created for the former employee within any of DSS’s internal infrastructure, cloud infrastructure, or Service Provider’s tenants so that account can be locked from unauthorized access.

3.0 Security Breach Procedures.

(a) Service Provider shall:

(i) provide DSS with the name and contact information for an employee of Service Provider who shall serve as DSS’s primary security contact and shall be available to assist DSS twenty-four (24) hours per day, seven (7) days per week as a contact in resolving obligations associated with a Security breach;

(ii) notify DSS of a Security Breach as soon as practicable, but no later than twenty-four (24) hours after Service Provider becomes aware of the breach. Service Provider must not wait to conduct an internal investigation to determine if DSS Data was involved. Any internal investigation conducted by the Service Provider should not delay the no later than twenty-four (24) hour reporting requirement of the disclosure or breach; and

(iii) notify DSS of any Security Breaches by telephone at the following number: (phone number to be determined - could be DSS helpdesk or operations team members, or DMS’ phone number), e-mailing DSS with a read receipt at ciso@dss.sc.gov.com and with a copy by e-mail to Service Provider’s primary business contact within DSS.

(b) Immediately following Service Provider’s notification to DSS of a security breach, the parties shall coordinate with each other to investigate the security breach. Service Provider agrees to fully cooperate with DSS in DSS’s handling of the matter, including, without limitation:

(i) assisting with any investigation;

(ii) providing DSS with physical access to the facilities and operations affected;

(iii) facilitating interviews with Service Provider’s employees and others involved in the matter; and

(iv) making available all relevant records, logs, files, data reporting and other materials required to comply with applicable law, regulation, industry standards or as otherwise required by DSS.

(c) Service Provider shall take reasonable steps to immediately remedy any security breach and prevent any further security breach at Service Provider’s expense in accordance with applicable privacy rights, laws, regulations, and standards. Service Provider shall reimburse DSS for actual costs incurred by DSS in responding to, and mitigating damages caused by, any Security Breach, including all costs of notice and/or remediation pursuant to Section 6.

(d) Service Provider agrees that it shall not inform any third party of any security breach involving DSS’s data without first obtaining DSS’s prior written consent, other than to inform a complainant that the matter has been forwarded to DSS’s legal counsel. Further, Service Provider agrees that DSS shall have the sole right to determine:

i. whether notice of the security breach is to be provided to any individuals, regulators, law enforcement agencies, consumer reporting agencies or others as required by law or regulation, or otherwise in DSS’s discretion; and

ii. the contents of such notice, whether any type of remediation may be offered to affected persons, and the nature and extent of any such remediation.

(e) Service Provider agrees to fully cooperate, at its own expense, with DSS in any litigation or other formal action deemed reasonably necessary by DSS to protect its rights relating to the use, disclosure, protection, and maintenance of DSS Data.

(f) In the event of any security breach, Service Provider shall promptly use its reasonable efforts to prevent a recurrence of any such security breach.

4.0 Oversight of Security Compliance

Upon DSS’s written request to confirm Service Provider’s compliance with this Agreement, as well as any applicable laws, regulations and industry standards, Service Provider grants DSS or, upon DSS’s election, a third party on DSS’s behalf, permission to perform an assessment, audit, examination or review of all controls in Service Provider’s physical and/or technical environment in relation to all Personal and proprietary Information being handled and/or services being provided to DSS pursuant to this Agreement. Service Provider shall fully cooperate with such assessment by providing access to knowledgeable personnel, physical premises, documentation, infrastructure, and application software that processes, stores or transports DSS Data for DSS pursuant to this Agreement. In addition, upon DSS’s written request, Service Provider shall provide DSS with the results of any audit by or on behalf of Service Provider performed that assesses the effectiveness of Service Provider’s information security program as relevant to the security and confidentiality of DSS Data shared during the course of this Agreement.

At least once per year, Service Provider shall conduct site audits of the information technology and information security controls for all facilities used in complying with its obligations under this Agreement, including, but not limited to, obtaining a network-level vulnerability assessment performed by a recognized third-party audit firm based on the recognized industry best practices. Upon DSS’s written request, Service Provider shall make available to DSS for review all the following, as applicable: Service Provider’s latest vulnerability scanning results, penetration testing results, Payment Card Industry (PCI) Compliance Report, and Statement on Standards for Attestation Engagements (SSAE-18) SOC audit reports for Reporting on Controls at a Service Organization and any reports relating to its ISO/ICE 27001/27002 certification. DSS shall treat such audit reports as Service Provider’s Confidential Information under this Agreement. Any exceptions noted on the SSAE report or other audit reports will be promptly addressed with the development and implementation of a corrective action plan by service provider’s management.

5.0 Return or Destruction of DSS Data

At any time during the term of this Agreement at the DSS’s written request, or upon the termination or expiration of this Agreement for any reason, Service Provider shall, and shall instruct all authorized persons to, promptly return to DSS all copies, whether in written, electronic or other form or media, of Personal, Proprietary, and Confidential Information in its possession or the possession of such authorized persons, or securely dispose of all such copies, and certify in writing to DSS, that such DSS Data has been returned to DSS or disposed of securely. Service Provider shall comply with all reasonable directions provided by DSS with respect to the return or disposal of Personal, Proprietary, and Confidential Information. Service Provider shall not erase DSS Data, or any copy thereof, without DSS’s prior written consent and shall follow any written instructions from DSS regarding retention and erasure of DSS data.

6.0 Equitable Relief.

Service Provider acknowledges that any breach of its covenants or obligations set forth in Data Security Addendum or the Service Provider’s standard policies and procedures, a copy of which have been provided to DSS may cause DSS irreparable harm for which monetary damages would not be adequate compensation and agrees that, in the event of such breach or threatened breach, DSS is entitled to seek equitable relief, including a restraining order, injunctive relief, specific performance and any other relief that may be available from any court, in addition to any other remedy to which DSS may be entitled at law or in equity. Such remedies shall not be deemed to be exclusive but shall be in addition to all other remedies available at law or in equity, subject to any express exclusions or limitations in this agreement to the contrary.

7.0 Material Breach.

Service Provider’s failure to comply with any of the provisions of Data Security Addendum is a material breach of this Agreement. In such event, DSS may terminate the Agreement effective immediately upon written notice to the Service Provider without further liability or obligation to DSS.

8.0 Indemnification.

Service Provider shall defend, indemnify and hold harmless DSS, and its agencies, affiliates, and its respective directors, employees, agents, successors and permitted assigns (each, a “DSS Indemnitee”) from and against all losses, damages, liabilities, deficiencies, actions, judgments, interest, awards, penalties, fines, costs or expenses of whatever kind, including reasonable attorneys’ fees, the cost of enforcing any right to indemnification hereunder and the cost of pursuing any insurance providers, arising out of or resulting from any third-party claim against any DSS Indemnitee arising out of or resulting from Service Provider’s failure to comply with any of its obligations under this Data Security Addendum

SC Department of Social Services Data Security Addendum Page 1 of 4 Rev 1.0 6/2023 image1.png

File details come from the government source that posted it. Updated .