Attachment L.2 Service Provider Security Assessment Questionnair.docx

DOCX document 41 KB Posted

Attached to
ENTERPRISE RESOURCE PLANNING SYSTEM State and local contract opportunity
Solicitation number
5400023659
Issued by
Spartanburg County, South Carolina

About this file

This is a Service Provider Security Assessment Questionnaire attachment for a competitive negotiations RFP solicitation (No. 5400023659) issued by the State of South Carolina in conjunction with Clemson University for an Enterprise Resource Planning System. The questionnaire serves as a mandatory evaluation tool to assess the security capabilities and compliance posture of service providers bidding on this opportunity. Offerors are required to provide detailed responses addressing twelve key security assessment areas, including access control policies, disaster recovery and business continuity planning, employee and contractor vetting procedures, contractor and sub-contractor security management, third-party security certifications, physical security measures, encryption practices, breach prevention safeguards, incident detection and response capabilities, audit logging procedures, post-contract information management protocols, and identification of any third parties with access to government information. All responses must be signed by an authorized representative of the contractor attesting to the accuracy of the information provided.

The questionnaire establishes mandatory security requirements that bidders must address in their proposals to demonstrate adequate protections for the confidentiality, integrity, and availability of government information throughout the contract term. Specific security certifications such as ISO/IEC 27001 compliance certificates, AICPA SOC 2 (Type 2) reports, or AICPA SOC 3 reports (SysTrust or WebTrust seals) are requested as evidence of third-party validated security controls. Bidders must also describe encryption standards for data at rest, in transit, and during backup operations, along with detailed explanations of audit logging, incident response procedures, and protocols for secure destruction or deletion of government information upon contract termination. The questionnaire requires that offerors maintain these security certifications and provide the state with updated versions throughout the contract period, establishing ongoing security compliance as a contractual obligation.

View the file

Other files for this state and local contract opportunity

Other files attached to ENTERPRISE RESOURCE PLANNING SYSTEM, newest first.
File Type Posted
Attachment E.2 Service Level Agreement.docx DOCX document
Amendment 1.docx DOCX document
Attachment 11 SaaS Environment Services for Offeror's ERP System.docx DOCX document
Attachment B.3 Cost Proposal Workbook.xlsx XLSX spreadsheet
Attachment C.1 Scope of Work (SOW).docx DOCX document
Attachment 1 Background.docx DOCX document
Solicitation 5400023659.docx DOCX document
Attachment C.1 SOW CORRECTED.docx DOCX document
Amendment 2.docx DOCX document
Attachment L.8 Information for Offerors to Submit.docx DOCX document
Attachment 12 REVISED.docx DOCX document
Attachment 10 Rights and Usage Grants.docx DOCX document
Award Extension 23659.doc DOC document
Attachment 7 Clemson Unique Attachment 1.docx DOCX document
Attachment K Representations, certification and other statements.docx DOCX document
Attachment 6 Sample Training Content.docx DOCX document
Notice of Award Posting.docx DOCX document
Attachment H.1 Disengagement Services.docx DOCX document
Attachment 8 External System Interfaces REVISED.xlsx XLSX spreadsheet
Attachment I.2 Proposed Contract Terms.docx DOCX document
Show all 20

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment L.2 – Service Provider Security Assessment Questionnaire

State of South Carolina Clemson University

Competitive Negotiations Attachment L.2 Service Provider Security Assessment Questionnaire

RFP Solicitation No. 5400023659

SERVICE PROVIDER SECURITY ASSESSMENT QUESTIONNAIRE

Instructions: (1) Attach additional pages or documents as appropriate and make sure answers cross reference to the questions below. (2) As used in this Questionnaire, the phrase “government information” shall have the meaning defined in the clause titled “Information Security.” (3) This Questionnaire must be read in conjunction with both of the following two clauses (a) Service Provider Security Assessment Questionnaire – Required, and (b) Service Provider Security Representation.

1. Describe your policies and procedures that ensure access to government information is limited to only those of your employees and contractors who require access to perform your proposed services.

2. Describe your disaster recovery and business continuity plans.

3. What safeguards and practices do you have in place to vet your employees and contractors who will have access to government information?

4. Describe and explain your security policies and procedures as they relate to your use of your contractors and next-tier sub -contractors.

5. List any reports or certifications that you have from properly accredited third-parties that demonstrate that adequate security controls and assurance requirements are in place to adequately provide for the confidentiality, integrity, and availability of the information systems used to process, store, transmit, and access all government information. (For example, an ISO/IEC 27001 compliance certificate, an AICPA SOC 2 (Type 2) report, or perhaps an AICPA SOC 3 report (i.e., a SysTrust or WebTrust seal)). For each certification, describe the scope of the assessment performed. Will these reports / certifications remain in place for the duration of the contract? Will you provide the state with most recent and future versions of the applicable compliance certificate / audit report?

6. Describe the policies, procedures and practices you have in place to provide for the physical security of your data centers and other sites where government information will be hosted, accessed or maintained.

7. Will government information be encrypted at rest? Will government information be encrypted when transmitted? Will government information be encrypted during data backups, and on backup media? Please elaborate.

8. Describe safeguards that are in place to prevent unauthorized use, reuse, distribution, transmission, manipulation, copying, modification, access or disclosure of government information.

9. What controls are in place to detect security breaches? What system and network activity do you log? How long do you maintain these audit logs?

10. How will government information be managed after contract termination? Will government information provided to the Contractor be deleted or destroyed? When will this occur?

Attachment L.2 – Service Provider Security Questionnaire

11. Describe your incident response policies and practices.

12. Identify any third party which will host or have access to government information.

Offeror’s response to this questionnaire includes any other information submitted with its offer regarding information or data security.

SIGNATURE OF PERSON AUTHORIZED TO REPRESENT THE ACCURACY OF THIS INFORMATION ON BEHALF OF CONTRACTOR:

By: (authorized signature)

Its: (printed name of person signing above)

(title of person signing above)

Date:

SPSAQ (JAN 2015) [09-9025-1]

File details come from the government source that posted it. Updated .