Attachment_E_-_Security_QUESTIONNAIRE.docx
DOCX document 51 KB Posted
- Attached to
- Corrections Jail Management System State and local contract opportunity
- Solicitation number
- Y25-101-KS
- Issued by
- Orange County, Orlando City, Florida
About this file
This is a Security Questionnaire document prepared by Orange County Government Board of County Commissioners (OCGBCC) for evaluation of the proposed Corrections Jail Management System (RFP Y25-101-KS). The questionnaire serves as a compliance assessment tool to determine whether the vendor's solution meets OCGBCC enterprise security policies and procedures. Vendors must complete detailed sections addressing project contact information, compliance checklist items, regulatory compliance requirements (HIPAA, PCI-DSS, CJIS), and a comprehensive scope description including county workstations, databases, servers, internet and DMZ usage, application data sensitivity levels, mobile applications, browser extensions, service accounts, APIs, SSL certificates, and network diagrams. The survey questions address critical security requirements including SAML-based Single Sign-On compatibility with multi-factor authentication, encryption in transit and at rest using field-level encryption, antivirus and security patch support, tunnel/VPN/reverse proxy requirements, unique domain usage, sensitive data handling, least privilege principles, Florida Public Records Act compliance, DMZ requirements, and comprehensive audit logging capabilities. Vendors must provide documentation of penetration testing results from the most recent cybersecurity assessment completed by Orange County or a reputable third-party security assessor, or commit to completing such an assessment if none has been conducted previously.
The questionnaire requires vendors to attach relevant documentation, certifications, and existing waivers demonstrating compliance with the specified security standards. This assessment tool directly supports the broader RFP evaluation process for a jail management system serving approximately 900 concurrent users with 5,175 facility beds. The security questionnaire must be completed and submitted alongside the vendor's response by the sealed bid deadline through the OpenGov e-Procurement Platform. Vendors must demonstrate capability to meet extensive security requirements including yearly penetration testing, field-level data encryption, antivirus protections, and compliance with FBI CJJIS Security Policy standards as mandated by Orange County's procurement requirements for this five-year contract with optional renewal provisions.
View the file
Other files for this state and local contract opportunity
Show all 44
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
security QUESTIONAIRE Please fill out this questionnaire that will aide in the determination if the following project, product, or application is compliant with the Orange County Government Board of County Commissioners (OCGBCC) enterprise security policies and procedures.
CONTACT INFO:
Project name:
ISS Project Leader:
OCGBCC Business / Department:
Vendor Contact:
COMPLIANCE CHECKLIST:
Attach any relevant documentation / certification / existing waivers for compliance.
| |_| Currently used OCGBCC solution |
| |_| Complies with OCGBCC IT & Security Standards |
Check if the solution is subject to: |_| HIPAA |_| PCI-DSS |_| CJIS |_| Other:
SCOPE:
Please attach a detail of the scope for the project or application. Including the following information: County Workstations, Databases, Servers; Internet and DMZ usage; Application Data (include sensitivity), Mobile Applications, Browser Extensions, Service Accounts, APIs, SSL Certificates, People and Locations. This can include or be represented by a complete network diagram.
SURVEY QUESTIONS:
| |_| Compatible with SAML based Single Sign On (SSO), MFA and auto-provisioning |
| |_| Information is encrypted in transit and at rest (using field-level encryption) |
|_| Solution supports running with antivirus and all latest security patches with no exceptions |_| Does not need a tunnel, VPN, or reverse proxy |_| Service uses unique domains that are not shared with other businesses (such as ocfl.service.com)
|_| Does not contain any sensitive info (emails, names, addresses, SSNs, Driver’s Licenses, passwords, employee identification numbers, ePHI, Banking info, etc.)
|_| Generic accounts are not used and application conforms to least privilege principles.
|_| Will comply with all Florida Public Records requirements |_| DMZ or County hosted internet accessible resources are needed |_| Audit logs are generated for all actions and tasks and can be exported
Date and auditor of last Completed Cybersecurity penetration test:
Please attach the results (without NDA clause). If none have been completed, please include a statement for an assessment to be completed either by Orange County or from a reputable 3rd party security assessor.
Please provide any additional details about the survey questions above:
Security Questionnaire Page 1 of 1 image1.png
File details come from the government source that posted it. Updated .