ATTACHMENT G - Security Requirements for Vendor Cloud Hosted Systems V1.3.6 - RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS).pdf
PDF 185 KB Posted
- Attached to
- Kentucky Analytics Platform Solution (KAPS) State and local contract opportunity
- Solicitation number
- RFP-758-2500000171-5
- Issued by
- Kentucky
About this file
This document is Attachment G for the Kentucky Analytics Platform Solution (KAPS) Request for Proposal (RFP 758 2500000171), issued by the Kentucky Cabinet for Health and Family Services (CHFS) Office of Application Technology Services. The attachment details comprehensive security requirements for vendors and cloud-hosted systems that will be used by the Commonwealth of Kentucky. The document outlines stringent security protocols that vendors must follow, including compliance with national standards such as NIST Special Publication 800-53, HIPAA Security and Privacy Rules, and various federal and state regulations.
The security requirements cover a wide range of technical and operational standards, including identity and access management, risk-based security approaches, continuous monitoring, and specific controls for protecting sensitive information like Personally Identifiable Information (PII) and Protected Health Information (PHI). Vendors must implement multi-factor authentication, conduct regular security assessments, maintain detailed system security plans, and undergo independent security reviews. The document also includes significant financial penalties for non-compliance, with potential reductions in compensation up to $30,000 per security requirement failure, emphasizing the critical nature of these security standards for the Kentucky state government's technology infrastructure.
View the file
Other files for this state and local contract opportunity
Show all 19
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment G Security Requirements for Vendor/Cloud-Hosted Systems
KAPS RFP
Kentucky Cabinet for Health and Family Services Version: 1.3.6
Office of Application Technology Services Updated: July 06, 2023
The Solution Provider/Vendor shall ensure compliance with all laws, regulations, and rules. Compliance is required for all applicable Cabinet for Health and Family Services (CHFS) IT Policies, Commonwealth Office of Technology (COT) Enterprise Policies, Internal Revenue Service (IRS) Publication 1075 requirements, and Social Security Administration guidelines and regulations.
The Solution Provider/Vendors shall implement security controls that comply with National Institute of Standards and Technology (NIST) special publication 800-53, rev 4, or later, which provides guidance for moderate baseline controls. The solution shall comply with all relevant Kentucky and local security and privacy regulations, and federal security and privacy standards adopted by the U.S. Department of Health and Human Services (HHS) for Medicaid Systems. The Solution Provider/Vendor shall be required to cooperate with any third-party Vendor that the Commonwealth engages to conduct a Certification and Accreditation audit of the system controls prior to go-live, in accordance with Enterprise Policies and CHFS Policies.
The requested solutions shall be built based upon leading best practices for secure application development, and shall protect the privacy and disclosure of sensitive, protected health information and personally identifiable information in accordance with Health Insurance Portability and Accountability Act (HIPAA) Security and Privacy Rules.
When a covered entity engages the services of a Solution Provider/Vendor/Cloud Service Provider (CSP) to create, receive, maintain, or transmit (electronic Protected Health Information (ePHI) (such as to process and/or store ePHI) on its behalf, the CSP is a business associate under HIPAA. Further, when business associate subcontracts with a CSP to create, receive, maintain, or transmit ePHI on its behalf, the CSP subcontractor itself is a business associate. This is true even if the CSP processes or stores only encrypted ePHI and lacks an encryption key for the data. Lacking an encryption key does not exempt a CSP from business associate status and obligations under the HIPAA Rules. As a result, the covered entity (or business associate) and the CSP shall enter into a HIPAA-compliant business associate agreement (BAA), and the CSP is both contractually liable for meeting the terms of the BAA and directly liable for compliance with the applicable requirements of the HIPAA Rules.
Vendor/Solution Provider/CSP responsibilities shall include, but not be limited to, the following:
1. Implementing a risk-based approach to integrating Security, Identity, and Access management into COT and/or Cabinet-specific initiatives, integration with the Kentucky Online Gateway (KOG) is required for Single Sign-On (SSO) (Active Directory Federation Services (ADFS) or Security Assertion Mark-Up Language (SAML) 2.0), user provisioning, and role-based authentication. The primary Identity store for all Commonwealth of Kentucky staff and Citizens shall only be the Commonwealth’s onsite Active Directory. Please review Attachment R KOG Integration for additional requirements.
RFP 758 2500000171 Kentucky Analytics Platform Solution (KAPS) https://technology.ky.gov/policies-and-procedures/Pages/policies.aspx https://www.chfs.ky.gov/agencies/os/oats/Pages/ITpolicies.aspx
KAPS RFP
Kentucky Cabinet for Health and Family Services Version: 1.3.6
Office of Application Technology Services Updated: July 06, 2023
2. Implementing a role-based, least-privileged approach to controlling access to the business-critical, confidential, protected, private, or otherwise sensitive data.
3. Developing and maintaining documents and artifacts required for state and federal compliance requirements, system security audits, security controls assessment, and distributed testing activities.
4. Documenting procedures for background checks on privileged access to servers, applications, or customer data. Vendor/Solution Provider Staff Background checks for privileged access shall include state and federal database criminal checks.
5. All users with privileged access such as full system and/or administrator level access shall use Commonwealth approved multi-factor authentication methods provided by the vendor.
6. All software and hardware components used to deliver this solution shall be supported by the original equipment manufacturer (OEM) of that particular software or hardware and all other technologies used shall be uncompromised/secure and current versions (example: Transport Layer Security [TLS] 1.2 or higher). The solution/application shall meet Commonwealth of Kentucky Information Technology Standards (such as Browsers, software installed on state computers, etc.).
7. The Vendor/Solution Provider staff shall include well-qualified security experts such as certified security architects, certified penetration testers, compliance resources, incident response resources, and audit personnel on this project throughout the life of the contract and available to Commonwealth of Kentucky security staff at all times.
8. If the proposed solution involves the storage, transmission, or processing of
Personally Identifiable Information (PII), Protected Health Information (PHI), or Federal Tax Information (FTI) of KY Citizens that is associated with the Affordable Care Act (ACA), the Vendor shall include a draft Minimum Accepted Risk Standards for Exchanges (MARS-E) 2.0 or higher System Security Plan (SSP) with complete Control Implementation Descriptions. (Just a template with no implementation descriptions is not acceptable.)
9. Vendor/Solution Provider shall provide a copy of the unaltered and unfiltered vulnerability and penetration test reports to CHFS Information Security as soon as the security assessments are completed. The Vendor/Solution Provider shall conduct the security assessments (i.e., vulnerability scans and penetration tests) regularly. The complete environment (i.e., Network, Storage, Server/Operating System (OS), Database, and Application vulnerability scans) shall occur at least once a month or sooner.
10. Vendor/Solution Provider shall provide a copy of the Statement on Standards for
Attestation (SSAE) 18 or higher SOC2 type 2 report to CHFS Information Security
KAPS RFP
Kentucky Cabinet for Health and Family Services Version: 1.3.6
Office of Application Technology Services Updated: July 06, 2023 at least on annual basis unless the hosting vendor holds current FedRAMP certification.
11. Access to all sensitive information (such as Personally Identifiable Information (PII), Protected Health Information (PHI), etc.) shall be restricted to those vetted through a background check, and may be restricted to U.S. citizen support personnel only based on data type, which will be determined during contract award.
12. All data, including backups and archives, shall be located within the contiguous United States at all times. All sensitive data, as defined by Kentucky Information Technology Standards (KITS), shall be encrypted in-transit and at rest (i.e., on a file system, sever, database, backups, archives, Storage Area Network (SAN), Network Attached Storage (NAS), File Transfer Protocol (FTP, Removable media, etc.) at all times.
13. Vendor/Solution Provider shall provide to CHFS Information Security a copy of the
Implementation plan and Detailed System Architecture (aka. Service Maps, Hardware Architecture, Application and Network Maps), which includes each Infrastructure component such as Servers, Storage, Appliances, Firewalls, IDS/IPS systems, etc., with associated software details as part of the initial deliverables well before the go-live date.
14. Disaster Recovery and Business Continuity testing of the entire system performed at a frequency that is acceptable to Commonwealth of Kentucky, but no later than annually.
15. All databases in new solutions containing sensitive data, such as PII and PHI, shall be monitored continuously for any breaches. The Vendor/Solution Provider shall set up alerts based on triggers that fire when a predetermined threshold on metrics is reached, including, but not limited to, total number of sensitive records read by any user, session origin IP, day and time of the day, program reading the data, etc. The solution shall allow custom thresholds for different user roles for all authorized users. All alerts shall be sent to designated Commonwealth of Kentucky staff including CHFS Information Security.
16. The solution shall enable not only unsuccessful logins, but also successful logins based on predefined criteria acceptable to Commonwealth of Kentucky. The criteria shall include, but not be limited to total number of sensitive records read by any user, session origin Internet Protocol (IP), day and time of the day, program reading the data, etc. All alerts shall be sent to designated Commonwealth of Kentucky staff including CHFS Information Security.
17. The solution shall employ end-to-end application availability and accessibility of the entire system using synthetic transactions, and monitor from an external independent location to guarantee the uptime. All alerts shall be sent to designated Commonwealth of Kentucky staff including CHFS Information Security.
KAPS RFP
Kentucky Cabinet for Health and Family Services Version: 1.3.6
Office of Application Technology Services Updated: July 06, 2023
18. All system components, including modules and sub-components delivered by Vendor/Solution Provider and/or sub-vendors, are subject to the Commonwealth and/or independent security review.
19. The Vendor/Solution Provider shall meet all mandatory security controls listed in
Section 4 of this RFP unless Commonwealth grants an exception.
20. Data Commingling
Commingled data at vendor-hosted or multi-tenant facilities results in security risks that shall be addressed. If the solution includes shared physical or computer facilities with other agencies, departments, or individuals not authorized to have PII, PHI, FTI, or SSA data, strict controls – physical and systemic – shall be maintained to prevent unauthorized disclosure of this information.
All computer equipment cabinets shall be locked in a vendor-hosted or multi-tenant environments, and all access to the cabinet shall be documented.
All access logs and signed visitor logs shall be retained for at least five (5) years in an easily accessible format. Reports of all failed logins shall be followed-up, verified, and documented by the vendor, and reported to CHFS Information Security on daily basis.
The Commonwealth of Kentucky shall report all potential breaches to appropriate federal entities within one (1) hour of discovery; for that reason, solution provider shall notify the Commonwealth within about thirty (30) minutes of discovery of any potential breach. Vendor/Solution Provider shall notify their CHFS point of contact and CHFS Information Security of all Security incidents as noted above.
21. Solution Response Time Response time shall be less than or equal to five (5) seconds for online transactions. The vendor shall continuously monitor the entire solution response time and report all SLA failures to authorized Commonwealth staff.
Exceptions to some of the above requirements may be granted in writing to the solution provided by authorized Commonwealth of Kentucky executives if the hosting facility maintains top-level FedRAMP certification at all times.
KAPS RFP
Kentucky Cabinet for Health and Family Services Version: 1.3.6
Office of Application Technology Services Updated: July 06, 2023
22. Independent Security Review
The Vendor shall perform an infrastructure (i.e., Network, Storage, Server/OS, Database, and Application) security assessments (i.e., vulnerability scans and penetration tests) shall be conducted by the Vendor/Solution Provider prior to implementation(s) and annually with an independent security assessment company that is agreed upon by the Commonwealth. The infrastructure vulnerability assessment shall follow NIST 800-115 guidelines. The Cabinet shall have an unfiltered copy of the application vulnerability assessment as generated by the tools within five (5) working days of its execution. The Solution Provider/Vendor shall provide a remediation plan of action and milestones (POA&M) that meets risk assignment and is in agreement with the Commonwealth.
The Solution Provide/Vendor shall cooperate with any Third-Party Vendor (TPV) that the Commonwealth engages to complete a Certification and Accreditation of the system controls prior to go-live, in accordance with CHFS standards and policies for Certification and Accreditation. Reviews shall be included in the Integrated Work Plan.
All system components, including modules and sub-modules, delivered by the vendor and/or sub-vendors are subject to the independent review.
The Solution Provide/Vendor shall meet the following requirements at a minimum:
1. Maintain an Inventory of Information Systems
The vendor shall have in place an inventory of information systems operated by or under the control of the vendor on behalf of the Commonwealth of Kentucky. The inventory shall include an identification of the interfaces between each system and all other systems or networks, including those not operated by or under the control of the Vendor and/or Commonwealth.
2. Categorize Information and Information Systems According to Risk Level
All information and information systems shall be categorized based on the objectives of providing appropriate levels of information security according to a range of risk levels defined by Federal Information Processing Standard (FIPS) 199 “Standards for Security Categorization of Federal Information and Information Systems.” The guidelines are provided by NIST SP 800-60 “Guide for Mapping Types of Information and Information Systems to Security Categories.”
3. Maintain System Security Plan
Vendor shall develop and maintain a system security plan (SSP) preferably in MARS-E 2.0 or higher template form, which is a living document that requires periodic review, modification, POA&M for implementing security controls. The system security plan is the major input to the security certification and accreditation process for the system.
4. Utilize Security Controls
KAPS RFP
Kentucky Cabinet for Health and Family Services Version: 1.3.6
Office of Application Technology Services Updated: July 06, 2023
Vendor-provided information systems shall meet the minimum-security requirements defined in FIPS 200 “Minimum Security Requirements for Federal Information and Information Systems.” Vendor shall meet minimum-security requirements by selecting the appropriate security controls and assurance requirements as described in NIST Special Publication 800-53, “Recommended Security Controls for Federal Information Systems.” The controls selected or planned shall be documented in the System Security Plan
5. Conduct Risk Assessments
Vendor shall conduct risk assessments to validate its security controls and to determine any additional controls needed to protect the Commonwealth of Kentucky operations (including mission, functions, image, or reputation), agency assets, individuals, other organizations, or the United States. The resulting set of security controls establishes a level of “security due diligence” for the Commonwealth of Kentucky.
6. Certification and Accreditation
Once the system documentation and risk assessment have been completed, the system’s controls shall be reviewed and certified to function appropriately. Based on the results of the review, the information system is accredited. The certification and accreditation process defined in NIST SP 800-37 “Guide for the Security Certification and Accreditation of Federal Information Systems.”
7. Conduct Continuous Monitoring
All accredited systems are required to monitor a selected set of security controls and the system documentation shall be updated to reflect changes and modifications to the system. Continuous monitoring activities include configuration management and control of information system components, security impact analyses of changes to the system, ongoing assessment of security controls, and status reporting.
8. Penalties The Vendor shall create and maintain security controls and services listed under the security requirements section at all times. Failure to deliver the security controls and services, including services as listed under section security requirements, but not limited to, will result in a penalty of $5,000 per occurrence as a result of the Solution provider/Vendor, their tools, or technology.
The Commonwealth shall reduce compensation up to thirty thousand dollars ($30,000.00) per event in which the Solution Provide/Vendor’s solution fails to meet a security requirement, control, or service. The Commonwealth may also pursue consequential or liquidated damages.
KAPS RFP
Kentucky Cabinet for Health and Family Services Version: 1.3.6
Office of Application Technology Services Updated: July 06, 2023
Acronyms
ADFS Active Directory Federation Services
BAA Business Associate Agreement
CHFS Cabinet for Health and Family Services
COT Commonwealth Office of Technology
CSP Cloud Service Provider ePHI electronic Protected Health Information
HHS Department of Health and Human Services
HIPAA Health Insurance Portability and Accountability Act
IP Internet Protocol
IRS Internal Revenue Service
KITS Kentucky Information Technology Standards
KOG Kentucky Online Gateway
MARS-E Minimum Accepted Risk Standards for Exchanges
NAS Network Attached Storage
NIST National Institute of Standards and Technology
OEM Original Equipment Manufacturer
OS Operating System
PHI Protected Health Information
PII Personally Identifiable Information
SAML Security Assertion Mark-Up Language
SAN Storage Area Network
SSAE Statement on Standards for Attestation
SSO Single Sign-On
SSP System Security Plan
TLS Transport Layer Security
File details come from the government source that posted it. Updated .