Attachment_E_-_Security_QUESTIONNAIRE.docx
DOCX document 51 KB Posted
- Attached to
- Corrections Jail Management System State and local contract opportunity
- Solicitation number
- Y25-101-KS
- Issued by
- Orange County, Orlando City, Florida
About this file
This is a Security Questionnaire document for Orange County Government Board of County Commissioners (OCGBCC) related to the Corrections Jail Management System (RFP Y25-101-KS) procurement. The questionnaire is designed to assess vendor compliance with OCGBCC enterprise security policies and procedures for the ISS Project. Vendors must complete the comprehensive questionnaire to evaluate whether their proposed solution meets the County's security standards and regulatory requirements. A non-mandatory pre-bid meeting is scheduled for December 3, 2025, at 11:00 am, with questions due by December 10, 2025, at 5:00 pm EST. Sealed electronic responses must be submitted through the OpenGov e-Procurement Platform with multiple submission deadlines: January 8, 2026, March 5, 2026, and March 12, 2026, all at 4:00 pm EST. The contract term is five years with optional renewal options.
The questionnaire requires vendors to provide detailed scope documentation including county workstations, databases, servers, internet and DMZ usage, application data sensitivity levels, mobile applications, browser extensions, service accounts, APIs, and SSL certificates, ideally supported by complete network diagrams. Vendors must address compliance with HIPAA, PCI-DSS, and CJIS standards as applicable. Mandatory security requirements include SAML-based Single Sign-On compatibility, Multi-Factor Authentication, field-level encryption in transit and at rest, antivirus compatibility with latest security patches, unique non-shared domains, least privilege principle adherence, Florida Public Records compliance, audit log generation and exportability, and yearly cybersecurity penetration testing. Vendors must provide evidence of completed penetration tests or commit to assessment by Orange County or a reputable third-party security assessor. The questionnaire also addresses whether DMZ or County-hosted internet-accessible resources are required and mandates that solutions must not contain sensitive information such as emails, names, addresses, SSNs, or employee identification numbers.
View the file
Other files for this state and local contract opportunity
Show all 44
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
security QUESTIONAIRE Please fill out this questionnaire that will aide in the determination if the following project, product, or application is compliant with the Orange County Government Board of County Commissioners (OCGBCC) enterprise security policies and procedures.
CONTACT INFO:
Project name:
ISS Project Leader:
OCGBCC Business / Department:
Vendor Contact:
COMPLIANCE CHECKLIST:
Attach any relevant documentation / certification / existing waivers for compliance.
| |_| Currently used OCGBCC solution |
| |_| Complies with OCGBCC IT & Security Standards |
Check if the solution is subject to: |_| HIPAA |_| PCI-DSS |_| CJIS |_| Other:
SCOPE:
Please attach a detail of the scope for the project or application. Including the following information: County Workstations, Databases, Servers; Internet and DMZ usage; Application Data (include sensitivity), Mobile Applications, Browser Extensions, Service Accounts, APIs, SSL Certificates, People and Locations. This can include or be represented by a complete network diagram.
SURVEY QUESTIONS:
| |_| Compatible with SAML based Single Sign On (SSO), MFA and auto-provisioning |
| |_| Information is encrypted in transit and at rest (using field-level encryption) |
|_| Solution supports running with antivirus and all latest security patches with no exceptions |_| Does not need a tunnel, VPN, or reverse proxy |_| Service uses unique domains that are not shared with other businesses (such as ocfl.service.com)
|_| Does not contain any sensitive info (emails, names, addresses, SSNs, Driver’s Licenses, passwords, employee identification numbers, ePHI, Banking info, etc.)
|_| Generic accounts are not used and application conforms to least privilege principles.
|_| Will comply with all Florida Public Records requirements |_| DMZ or County hosted internet accessible resources are needed |_| Audit logs are generated for all actions and tasks and can be exported
Date and auditor of last Completed Cybersecurity penetration test:
Please attach the results (without NDA clause). If none have been completed, please include a statement for an assessment to be completed either by Orange County or from a reputable 3rd party security assessor.
Please provide any additional details about the survey questions above:
Security Questionnaire Page 1 of 1 image1.png
File details come from the government source that posted it. Updated .