Attachment_E_-_Security_QUESTIONNAIRE.docx
DOCX document 51 KB Posted
- Attached to
- Corrections Jail Management System State and local contract opportunity
- Solicitation number
- Y25-101-KS
- Issued by
- Orange County, Orlando City, Florida
About this file
This is a Security Questionnaire document for Orange County Government Board of County Commissioners (OCGBCC) related to the Corrections Jail Management System (RFP Y25-101-KS) procurement. The questionnaire is designed to assess vendor compliance with enterprise security policies and procedures for projects, products, or applications. Vendors must provide project contact information, confirm whether the solution is currently used by OCGBCC, verify compliance with OCGBCC IT and Security Standards, and identify if the solution is subject to regulatory requirements including HIPAA, PCI-DSS, and CJIS. The document requires vendors to attach detailed scope documentation including information about county workstations, databases, servers, internet and DMZ usage, application data sensitivity levels, mobile applications, browser extensions, service accounts, APIs, SSL certificates, and network diagrams. Vendors must also provide documentation of any relevant certifications, existing waivers, and compliance evidence.
The questionnaire contains ten mandatory survey questions addressing critical security requirements: SAML-based Single Sign On compatibility with multi-factor authentication and auto-provisioning; encryption of information in transit and at rest using field-level encryption; compatibility with antivirus and security patches; elimination of tunnel, VPN, or reverse proxy requirements; use of unique, non-shared service domains; absence of sensitive information in the system; implementation of least privilege principles without generic accounts; compliance with Florida Public Records requirements; DMZ or county-hosted internet-accessible resources; and generation of exportable audit logs for all actions and tasks. Vendors must provide documentation of cybersecurity penetration testing with dates and auditor information or submit statements committing to assessment completion by either Orange County or a reputable third-party security assessor. The questionnaire allows vendors to provide additional details clarifying responses to survey questions.
View the file
Other files for this state and local contract opportunity
Show all 44
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
security QUESTIONAIRE Please fill out this questionnaire that will aide in the determination if the following project, product, or application is compliant with the Orange County Government Board of County Commissioners (OCGBCC) enterprise security policies and procedures.
CONTACT INFO:
Project name:
ISS Project Leader:
OCGBCC Business / Department:
Vendor Contact:
COMPLIANCE CHECKLIST:
Attach any relevant documentation / certification / existing waivers for compliance.
| |_| Currently used OCGBCC solution |
| |_| Complies with OCGBCC IT & Security Standards |
Check if the solution is subject to: |_| HIPAA |_| PCI-DSS |_| CJIS |_| Other:
SCOPE:
Please attach a detail of the scope for the project or application. Including the following information: County Workstations, Databases, Servers; Internet and DMZ usage; Application Data (include sensitivity), Mobile Applications, Browser Extensions, Service Accounts, APIs, SSL Certificates, People and Locations. This can include or be represented by a complete network diagram.
SURVEY QUESTIONS:
| |_| Compatible with SAML based Single Sign On (SSO), MFA and auto-provisioning |
| |_| Information is encrypted in transit and at rest (using field-level encryption) |
|_| Solution supports running with antivirus and all latest security patches with no exceptions |_| Does not need a tunnel, VPN, or reverse proxy |_| Service uses unique domains that are not shared with other businesses (such as ocfl.service.com)
|_| Does not contain any sensitive info (emails, names, addresses, SSNs, Driver’s Licenses, passwords, employee identification numbers, ePHI, Banking info, etc.)
|_| Generic accounts are not used and application conforms to least privilege principles.
|_| Will comply with all Florida Public Records requirements |_| DMZ or County hosted internet accessible resources are needed |_| Audit logs are generated for all actions and tasks and can be exported
Date and auditor of last Completed Cybersecurity penetration test:
Please attach the results (without NDA clause). If none have been completed, please include a statement for an assessment to be completed either by Orange County or from a reputable 3rd party security assessor.
Please provide any additional details about the survey questions above:
Security Questionnaire Page 1 of 1 image1.png
File details come from the government source that posted it. Updated .