Attachment_E_-_Security_QUESTIONNAIRE.docx
DOCX document 51 KB Posted
- Attached to
- Corrections Jail Management System State and local contract opportunity
- Solicitation number
- Y25-101-KS
- Issued by
- Orange County, Orlando City, Florida
About this file
This is a Security Questionnaire document used by Orange County Government Board of County Commissioners (OCGBCC) to assess compliance with enterprise security policies for the Corrections Jail Management System project (Y25-101-KS). The questionnaire requires vendors to provide project contact information, compliance documentation, and detailed scope information covering county workstations, databases, servers, internet usage, application data sensitivity levels, mobile applications, APIs, and SSL certificates, preferably accompanied by a complete network diagram. The document establishes a mandatory compliance checklist addressing regulatory requirements such as HIPAA, PCI-DSS, and CJIS standards, with responses due electronically via the OpenGov e-Procurement Platform by 4:00 pm EST on Thursday, January 8, 2026.
The questionnaire contains fourteen survey requirements that vendors must address, including SAML-based single sign-on compatibility, multi-factor authentication support, encryption of data in transit and at rest, antivirus compatibility, adherence to least privilege principles, compliance with Florida Public Records requirements, and generation of exportable audit logs. Vendors must also provide documentation of cybersecurity penetration testing results from either Orange County or a reputable third-party security assessor, or submit a statement committing to such an assessment if none has been completed. The questionnaire does not specify pricing terms, set-asides, funding amounts, or contract renewal options, focusing instead on the vendor's ability to meet security and compliance requirements for the jail management system implementation.
View the file
Other files for this state and local contract opportunity
Show all 44
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
security QUESTIONAIRE Please fill out this questionnaire that will aide in the determination if the following project, product, or application is compliant with the Orange County Government Board of County Commissioners (OCGBCC) enterprise security policies and procedures.
CONTACT INFO:
Project name:
ISS Project Leader:
OCGBCC Business / Department:
Vendor Contact:
COMPLIANCE CHECKLIST:
Attach any relevant documentation / certification / existing waivers for compliance.
| |_| Currently used OCGBCC solution |
| |_| Complies with OCGBCC IT & Security Standards |
Check if the solution is subject to: |_| HIPAA |_| PCI-DSS |_| CJIS |_| Other:
SCOPE:
Please attach a detail of the scope for the project or application. Including the following information: County Workstations, Databases, Servers; Internet and DMZ usage; Application Data (include sensitivity), Mobile Applications, Browser Extensions, Service Accounts, APIs, SSL Certificates, People and Locations. This can include or be represented by a complete network diagram.
SURVEY QUESTIONS:
| |_| Compatible with SAML based Single Sign On (SSO), MFA and auto-provisioning |
| |_| Information is encrypted in transit and at rest (using field-level encryption) |
|_| Solution supports running with antivirus and all latest security patches with no exceptions |_| Does not need a tunnel, VPN, or reverse proxy |_| Service uses unique domains that are not shared with other businesses (such as ocfl.service.com)
|_| Does not contain any sensitive info (emails, names, addresses, SSNs, Driver’s Licenses, passwords, employee identification numbers, ePHI, Banking info, etc.)
|_| Generic accounts are not used and application conforms to least privilege principles.
|_| Will comply with all Florida Public Records requirements |_| DMZ or County hosted internet accessible resources are needed |_| Audit logs are generated for all actions and tasks and can be exported
Date and auditor of last Completed Cybersecurity penetration test:
Please attach the results (without NDA clause). If none have been completed, please include a statement for an assessment to be completed either by Orange County or from a reputable 3rd party security assessor.
Please provide any additional details about the survey questions above:
Security Questionnaire Page 1 of 1 image1.png
File details come from the government source that posted it. Updated .