Attachment N- Service Provider Security Assessment Questionnaire.docx

DOCX document 36 KB Posted

Attached to
ECONOMIC SVCS SYSTEM APP MODERNIZATION State and local contract opportunity
Solicitation number
5400024945
Issued by
Richland County, South Carolina

About this file

This is a Service Provider Security Assessment Questionnaire attachment for South Carolina's Economic Services System Application Modernization contract opportunity. The questionnaire requires service providers to comprehensively document their information security practices and controls as a condition of contract award. Bidders must provide detailed responses addressing eleven primary areas: access control policies limiting government information to authorized personnel; disaster recovery and business continuity plans; employee and contractor vetting procedures; security policies governing contractor and sub-contractor usage; third-party security certifications such as ISO/IEC 27001, AICPA SOC 2 Type 2, or equivalent with scope descriptions and commitment to maintain certifications throughout contract duration; physical security measures for data centers and information hosting sites; encryption protocols for data at rest, in transit, and during backup operations; safeguards preventing unauthorized access, disclosure, or manipulation of government information; breach detection controls and audit logging procedures with retention timelines; post-contract termination data destruction procedures; and incident response policies. Additionally, service providers must identify all third parties with access to government information.

The questionnaire must be completed by an authorized company representative who certifies the accuracy of all responses through signature, printed name, title, and date. All responses should cross-reference the numbered questions and include supporting documentation or additional pages as necessary. The completed questionnaire must be read in conjunction with the "Service Provider Security Assessment Questionnaire - Required" clause and the "Service Provider Security Representation" clause. This assessment tool ensures that bidders meet the state's stringent information security and data protection requirements before being considered for contract award on this application modernization initiative.

View the file

Other files for this state and local contract opportunity

Other files attached to ECONOMIC SVCS SYSTEM APP MODERNIZATION, newest first.
File Type Posted
Attachment R- ESSAM Business Process Analysis Report.pdf PDF
Attachment O-Information for Offerors to Submit Response Table.docx DOCX document
Attachment F- Project Management Plan Template.docx DOCX document
Attachment K- SNAP Eligibility Go Live Reqs.pdf PDF
Attachment I- DSNAP.pdf PDF
Attachment P- Cost Proposal Workbook.xlsx XLSX spreadsheet
Attachment C- Current Technologies & Standards.xlsx XLSX spreadsheet
Attachment B-SNAP System Integrity Review Tool.pdf PDF
Attachment L- Hand Book 901v2.4.pdf PDF
Attachment G- SNAP Manual_rev.pdf PDF
Attachment J- Benefit Integrity Manual.pdf PDF
Attachment E- DSS Data Security Addendum.docx DOCX document
Attachment T- Answers to Questions from Offerors.xlsx XLSX spreadsheet
Attachment Q- Question Template.docx DOCX document
Attachment H- TANF Policy Manual.pdf PDF
Attachment M- DSS State Office Leadership.pdf PDF
Attachment D-List of Interfaces-UPDATED.xlsx XLSX spreadsheet
Amendment 1.docx DOCX document
Attachment S- Federal Clauses.pdf PDF
Solicitation.docx DOCX document
Award Extension Notice.doc DOC document
Attachment A-ESSAM Requirements Definition-UPDATED.xlsx XLSX spreadsheet
Show all 22

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SAP

ATTACHMENT N

SERVICE PROVIDER SECURITY ASSESSMENT QUESTIONNAIRE

Instructions: (1) Attach additional pages or documents as appropriate and make sure answers cross reference to the questions below. (2) As used in this Questionnaire, the phrase “government information” shall have the meaning defined in the clause titled “Information Security.” (3) This Questionnaire must be read in conjunction with both of the following two clauses (a) Service Provider Security Assessment Questionnaire – Required, and (b) Service Provider Security Representation.

1. Describe your policies and procedures that ensure access to government information is limited to only those of your employees and contractors who require access to perform your proposed services.

2. Describe your disaster recovery and business continuity plans.

3. What safeguards and practices do you have in place to vet your employees and contractors who will have access to government information?

4. Describe and explain your security policies and procedures as they relate to your use of your contractors and next-tier sub -contractors.

5. List any reports or certifications that you have from properly accredited third-parties that demonstrate that adequate security controls and assurance requirements are in place to adequately provide for the confidentiality, integrity, and availability of the information systems used to process, store, transmit, and access all government information. (For example, an ISO/IEC 27001 compliance certificate, an AICPA SOC 2 (Type 2) report, or perhaps an AICPA SOC 3 report (i.e., a SysTrust or WebTrust seal)). For each certification, describe the scope of the assessment performed. Will these reports / certifications remain in place for the duration of the contract? Will you provide the state with most recent and future versions of the applicable compliance certificate / audit report?

6. Describe the policies, procedures and practices you have in place to provide for the physical security of your data centers and other sites where government information will be hosted, accessed or maintained.

7. Will government information be encrypted at rest? Will government information be encrypted when transmitted? Will government information be encrypted during data backups, and on backup media? Please elaborate.

8. Describe safeguards that are in place to prevent unauthorized use, reuse, distribution, transmission, manipulation, copying, modification, access or disclosure of government information.

9. What controls are in place to detect security breaches? What system and network activity do you log? How long do you maintain these audit logs?

10. How will government information be managed after contract termination? Will government information provided to the Contractor be deleted or destroyed? When will this occur?

11. Describe your incident response policies and practices.

12. Identify any third party which will host or have access to government information.

Offeror’s response to this questionnaire includes any other information submitted with its offer regarding information or data security.

SIGNATURE OF PERSON AUTHORIZED TO REPRESENT THE ACCURACY OF THIS INFORMATION ON BEHALF OF CONTRACTOR:

By:____________________________________
(authorized signature)
Its:____________________________________
(printed name of person signing above)
____________________________________
(title of person signing above)

Date: ____________________________________

SPSAQ (JAN 2015) [09-9025-1]

Page Page

File details come from the government source that posted it. Updated .