ATTM 010.docx
DOCX document 23 KB Posted
- Attached to
- WEBSITE REDESIGN SCDHHS State and local contract opportunity
- Solicitation number
- 5400023277
- Issued by
- Richland County, South Carolina
About this file
This is a Service Provider Security Assessment Questionnaire attachment for a website redesign project with the South Carolina Department of Health and Human Services (SCDHHS). The questionnaire is designed to evaluate the security capabilities and practices of potential service providers who will have access to government information during the contract performance. Bidders must provide comprehensive responses addressing 12 specific areas of security assessment, including policies for limiting access to government information, disaster recovery and business continuity planning, employee and contractor vetting procedures, security policies for subcontractors, and relevant third-party certifications such as ISO/IEC 27001 or AICPA SOC 2 compliance reports. Responses must also address physical security measures for data centers, encryption protocols for data at rest and in transit, breach detection controls, audit logging procedures, post-contract data management and destruction, and incident response policies. The questionnaire requires identification of any third parties that will host or access government information.
The questionnaire must be signed by an authorized representative of the contractor attesting to the accuracy of the information provided. Responses should include cross-references to the specific questions and attach additional documentation as appropriate. The completed questionnaire is required in conjunction with two related clauses: the Service Provider Security Assessment Questionnaire - Required clause and the Service Provider Security Representation clause. The questionnaire format is identified as SPSAQ (FEB 2015) [09-9025-1]. No pricing, set-aside information, incumbency status, or specific contract term dates are addressed in this security assessment document.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| Solicitation.pdf | ||
| ATTM 002.pdf | ||
| ATTM 005.docx | DOCX document | |
| Award Extension 2.pdf | ||
| ATTM 009.docx | DOCX document | |
| ATTM 007.xlsx | XLSX spreadsheet | |
| Award Extension.pdf | ||
| ATTM 006.pdf | ||
| ATTM 003.pdf | ||
| ATTM 001.pdf | ||
| Amendment One.pdf | ||
| ATTM 008.docx | DOCX document | |
| ATTM 011.pdf | ||
| ATTM 004.pdf |
Show all 14
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT 010
SERVICE PROVIDER SECURITY ASSESSMENT QUESTIONNAIRE
Instructions: (1) Attach additional pages or documents as appropriate and make sure answers cross reference to the questions below. (2) As used in this Questionnaire, the phrase "government information" shall have the meaning defined in the clause titled "Information Security." (3) This Questionnaire must be read in conjunction with both of the following two clauses (a) Service Provider Security Assessment Questionnaire - Required, and (b) Service Provider Security Representation.
1. Describe your policies and procedures that ensure access to government information is limited to only those of your employees and Contractors who require access to perform your proposed services.
2. Describe your disaster recovery and business continuity plans.
3. What safeguards and practices do you have in place to vet your employees and Contractors who will have access to government information?
4. Describe and explain your security policies and procedures as they relate to your use of your Contractors and next-tier Subcontractors.
5. List any reports or certifications that you have from properly accredited third-parties that demonstrate that adequate security controls and assurance requirements are in place to adequately provide for the confidentiality, integrity, and availability of the information systems used to process, store, transmit, and access all government information. (For example, an ISO/IEC 27001 compliance certificate, an AICPA SOC 2 (Type 2) report, or perhaps an AICPA SOC 3 report (i.e., a SysTrust or WebTrust seal)). For each certification, describe the scope of the assessment performed. Will these reports / certifications remain in place for the duration of the Contract? Will you provide the state with most recent and future versions of the applicable compliance certificate / audit report?
6. Describe the policies, procedures and practices you have in place to provide for the physical security of your data centers and other sites where government information will be hosted, accessed or maintained.
7. Will government information be encrypted at rest? Will government information be encrypted when transmitted? Will government information be encrypted during data backups, and on backup media? Please elaborate.
8. Describe safeguards that are in place to prevent unauthorized use, reuse, distribution, transmission, manipulation, copying, modification, access or disclosure of government information.
9. What controls are in place to detect security breaches? What system and network activity do you log? How long do you maintain these audit logs?
10. How will government information be managed after Contract termination? Will government information provided to the Contractor be deleted or destroyed? When will this occur?
11. Describe your incident response policies and practices.
12. Identify any third party which will host or have access to government information.
Offeror’s response to this questionnaire includes any other information submitted with its offer regarding information or data security.
SIGNATURE OF PERSON AUTHORIZED TO REPRESENT THE ACCURACY OF THIS INFORMATION ON BEHALF OF CONTRACTOR:
By: ____________________________________ (Authorized signature)
Its: ____________________________________ (Printed name of person signing above)
(Title of person signing above)
Date: ____________________________________
SPSAQ (FEB 2015) [09-9025-1]
File details come from the government source that posted it. Updated .