ATTM 011.docx

DOCX document 26 KB Posted

Attached to
BABYNET INTEGRATED CASE MGMT SYSTEM State and local contract opportunity
Solicitation number
5400024726
Issued by
Richland County, South Carolina

About this file

This is a Service Provider Security Assessment Questionnaire (ATTM 011) for the BABYNET Integrated Case Management System contract opportunity in South Carolina. The questionnaire is a required document that service providers must complete to demonstrate their information security capabilities and compliance with government data protection standards. Prospective contractors are required to provide detailed responses addressing twelve key security areas and must have an authorized representative sign the document certifying the accuracy of all submitted information.

The questionnaire requires contractors to describe their access control policies, disaster recovery and business continuity plans, employee and contractor vetting procedures, and security policies governing the use of sub-contractors. Additionally, contractors must disclose any third-party security certifications such as ISO/IEC 27001, AICPA SOC 2 (Type 2), or comparable accreditations, along with detailed scope information for each assessment. Contractors must address encryption standards for data at rest and in transit, physical security measures for data centers, breach detection controls, audit logging practices and retention periods, incident response procedures, and data management protocols following contract termination. The questionnaire also requires contractors to identify any third parties that will have access to or host government information and to commit to maintaining current compliance certifications throughout the contract period.

View the file

Other files for this state and local contract opportunity

Other files attached to BABYNET INTEGRATED CASE MGMT SYSTEM, newest first.
File Type Posted
ATTM 003.pdf PDF
ATTM 009.pdf PDF
ATTM 005.pdf PDF
PL 011.pdf PDF
ATTM 013.xlsx XLSX spreadsheet
ATTM 014.pdf PDF
Award Extension 24726.pdf PDF
ATTM 010.pdf PDF
PL 010.pdf PDF
ATTM 015 Disc Control.docx DOCX document
PL 016.pdf PDF
ATTM 001.pdf PDF
Amendment 2 24726.pdf PDF
Amendment 1.pdf PDF
ATTM 008.xlsx XLSX spreadsheet
ATTM 007.docx DOCX document
PL 015.pdf PDF
ATTM 006.pdf PDF
ATTM 012.pdf PDF
ATTM 004.pdf PDF
BabyNet RFP.pdf PDF
PL 012.pdf PDF
Award Posting Notice.pdf PDF
ATTM 002.pdf PDF
PL 013.pdf PDF
ATTM 007 Q & A.pdf PDF
PL 017.pdf PDF
PL 014.pdf PDF
Show all 28

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ATTM 011 - SERVICE PROVIDER SECURITY ASSESSMENT QUESTIONNAIRE

Instructions: (1) Attach additional pages or documents as appropriate and make sure answers cross reference to the questions below. (2) As used in this Questionnaire, the phrase "government information" shall have the meaning defined in the clause titled "Information Security." (3) This Questionnaire must be read in conjunction with both of the following two clauses (a) Service Provider Security Assessment Questionnaire - Required, and (b) Service Provider Security Representation.

1. Describe your policies and procedures that ensure access to government information is limited to only those of your employees and contractors who require access to perform your proposed services.

2. Describe your disaster recovery and business continuity plans.

3. What safeguards and practices do you have in place to vet your employees and contractors who will have access to government information?

4. Describe and explain your security policies and procedures as they relate to your use of your contractors and next-tier sub -contractors.

5. List any reports or certifications that you have from properly accredited third-parties that demonstrate that adequate security controls and assurance requirements are in place to adequately provide for the confidentiality, integrity, and availability of the information systems used to process, store, transmit, and access all government information. (For example, an ISO/IEC 27001 compliance certificate, an AICPA SOC 2 (Type 2) report, or perhaps an AICPA SOC 3 report (i.e., a SysTrust or WebTrust seal)). For each certification, describe the scope of the assessment performed. Will these reports / certifications remain in place for the duration of the contract? Will you provide the state with most recent and future versions of the applicable compliance certificate / audit report?

6. Describe the policies, procedures and practices you have in place to provide for the physical security of your data centers and other sites where government information will be hosted, accessed or maintained.

7. Will government information be encrypted at rest? Will government information be encrypted when transmitted? Will government information be encrypted during data backups, and on backup media? Please elaborate.

8. Describe safeguards that are in place to prevent unauthorized use, reuse, distribution, transmission, manipulation, copying, modification, access or disclosure of government information.

9. What controls are in place to detect security breaches? What system and network activity do you log? How long do you maintain these audit logs?

10. How will government information be managed after contract termination? Will government information provided to the Contractor be deleted or destroyed? When will this occur?

11. Describe your incident response policies and practices.

12. Identify any third party which will host or have access to government information.

Offeror's response to this questionnaire includes any other information submitted with its offer regarding information or data security.

SIGNATURE OF PERSON AUTHORIZED TO REPRESENT THE ACCURACY OF THIS INFORMATION ON BEHALF OF CONTRACTOR:

By: ____________________________________ (Authorized signature)

Its: ____________________________________ (Printed name of person signing above)

(Title of person signing above)

Date: ____________________________________

SPSAQ (FEB 2015) [09-9025-1]

File details come from the government source that posted it. Updated .