Cloud Hosting Data.pdf
PDF 225 KB Posted
- Attached to
- Traffic Data Services WIM/CCS State and local contract opportunity
- Solicitation number
- 5400029091
- Issued by
- Richland County, South Carolina
About this file
This is a Cloud Hosting Data & Security Compliance Attestation form for the Traffic Data Services WIM/CCS contract opportunity in South Carolina. The attestation document serves as a comprehensive compliance checklist for contractors proposing cloud-hosted or third-party hosted infrastructure solutions, including Software-as-a-Service (SaaS), Platform-as-a-Service (PaaS), Infrastructure-as-a-Service (IaaS), and managed services. The form requires contractors to identify their proposed cloud platform (Microsoft Azure, Amazon Web Services, Google Cloud Platform, or other), confirm data residency exclusively within the continental United States, and attest to data sovereignty requirements prohibiting foreign national access or foreign government control over agency data. Contractors must also confirm support for agency-managed Single Sign-On, integration with industry-standard identity protocols (SAML 2.0, OpenID Connect, OAuth 2.0), role-based access control with separation of duties, and encryption of data at rest using FIPS 140-2 or FIPS 140-3 validated cryptographic modules with secure key management.
The attestation requires contractors to maintain at least one active security certification for each cloud hosting provider, including FedRAMP Moderate or Higher Authorization, GovRAMP Authorization, or SOC 2 Type II Certification. Contractors must disclose all subcontractors and hosting providers, commit to maintaining compliance throughout the contract term, immediately notify the agency of any certification lapses or security incidents within twenty-four hours of detection, and maintain audit logs of all user and administrative activity for a minimum of ninety days in active searchable state and twelve months in secure archive. The form concludes with contractor certification requirements confirming the accuracy and completeness of all statements, signed by an authorized representative with authority to bind the company to these security and compliance requirements.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| Solicitation.pdf | ||
| Camera Information.pdf | ||
| Sites.xlsx | XLSX spreadsheet | |
| Table 3.pdf | ||
| Service Provider Questionnaire.pdf | ||
| Pricing Worksheet.xlsx | XLSX spreadsheet | |
| Accessibility Conformance Report.pdf | ||
| Artifical Intelligence Use.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CLOUD HOSTING DATA & SECURITY COMPLIANCE ATTESTATION
Cloud Hosting Data & Security Compliance Attestation Page 1 of 3
SECTION 1 - GENERAL INFORMATION
Contractor: Date:
Solicitation:
Primary Contact: Title:
Does the proposed solution, in whole or in part, leverage cloud-hosted or is provided using third-party hosted infrastructure (e.g., SaaS, PaaS, IaaS, managed services)? If “No,” skip to Section 11 (Certification) Yes: ⃣ No: ⃣
SECTION 2 - CLOUD PLATFORM
Identify the cloud platform(s) used to host the proposed solution (check all that apply):
⃣ Microsoft Azure ⃣ Amazon Web Services (AWS) ⃣ Google Cloud Platform (GCP) ⃣ Unknown ⃣ Other:
• Is the proposed solution hosted in a U.S. Government-only cloud environment (GovCloud / Government
Cloud)? Yes: ⃣ No: ⃣
SECTION 3 - DATA RESIDENCY (CONUS)
• All Agency data is stored, processed, transmitted, replicated, cached, and backed up exclusively within the continental United States (CONUS). Yes: ⃣ No: ⃣
• All environments (development, test, staging, production, backup, disaster recovery, logging, monitoring, analytics, and support) are located entirely within CONUS. Yes: ⃣ No: ⃣
SECTION 4 - DATA SOVEREIGNTY & FOREIGN ACCESS
• No Agency data is accessed, administered, supported, or maintained by foreign nationals, foreign entities, or personnel located outside CONUS without prior written Agency approval. Yes: ⃣ No: ⃣
• No foreign government or foreign-controlled entity has the ability to access, control, manage, or compel disclosure of Agency data. Yes: ⃣ No: ⃣
• Administrative access is restricted to U.S.-based personnel and enforced using role-based access controls, logging, and monitoring. Yes: ⃣ No: ⃣
SECTION 5 - DATA ENCRYPTION & KEY MANAGEMENT
• Data at rest is encrypted using FIPS 140-2 or FIPS 140-3 validated cryptographic modules Yes: ⃣ No: ⃣
• Encryption keys are securely managed, protected, rotated, and restricted to authorized personnel only Yes: ⃣ No: ⃣
• Agency data is logically isolated from other tenants in multi-tenant environments. Yes: ⃣ No: ⃣
Cloud Hosting Data & Security Compliance Attestation Page 2 of 3
SECTION 6 - IDENTITY & ACCESS MANAGEMENT (IAM)
• Does the proposed solution support Agency-managed Single Sign-On (SSO)? Yes: ⃣ No: ⃣
• Supports integration with Agency identity providers using industry-standard protocols (check all that apply):
⃣ SAML 2.0 ⃣ OpenID Connect (OIDC) ⃣ OAuth 2.0
• Supports Agency-managed identity services (e.g., Active Directory / Entra ID / other Agency IdP). Yes: ⃣ No: ⃣
• Supports enforcement of Agency password, MFA, and conditional access policies through the Agency IdP. Yes: ⃣ No: ⃣
• Does the proposed solution support Agency-managed Role-Based Access Control (RBAC)? Yes: ⃣ No: ⃣
SECTION 6.1 - ROLE-BASED ACCESS CONTROL (RBAC) CAPABILITIES (REQUIRED IF YES)
• Supports configurable, least-privilege role-based access control for all application functions and data. Yes: ⃣ No: ⃣
• Supports separation of duties (e.g., user, administrator, auditor, read-only roles). Yes: ⃣ No: ⃣
• Supports assignment of roles based on user attributes or group membership from the Agency IdP. Yes: ⃣ No: ⃣
• Supports audit logging of authentication events, role assignments, and privilege changes. Yes: ⃣ No: ⃣
SECTION 7 - SECURITY & COMPLIANCE CERTIFICATION
The Offeror certifies that each cloud hosting provider used to store, process, transmit, or access Agency data maintains at least one (1) of the following active, valid security certifications or authorizations:
• FedRAMP Moderate or Higher Authorization Yes: ⃣ No: ⃣ Authorization Level: ☐ Moderate ☐ High FedRAMP ATO or Marketplace Listing Provided
• GovRAMP Authorization Yes: ⃣ No: ⃣ Status: ☐ Authorized ☐ Provisional GovRAMP Documentation Provided
• SOC 2 Type II Certification (or Equivalent) Yes: ⃣ No: ⃣ Scope includes Security and Availability (Confidentiality if applicable) Current SOC 2 Type II Report or Executive Summary Provided
• Other (explain): Yes: ⃣ No: ⃣
Note: At least one above must be selected for each hosting provider disclosed. Documentation must be provided
SECTION 8 - SUBCONTRACTORS & CLOUD PROVIDERS
• All subcontractors, sub-processors, and cloud/hosting providers comply fully with these
Cloud Hosting Security & Data Compliance requirements. Yes: ⃣ No: ⃣
• A complete list of all subcontractors and hosting providers has been disclosed with this submission. Yes: ⃣ No: ⃣
• No changes to hosting locations or sub-processors will occur without prior written Agency approval.
Yes: ⃣ No: ⃣
Cloud Hosting Data & Security Compliance Attestation Page 3 of 3
SECTION 9 - COMPLIANCE & VERIFICATION
• The Offeror agrees to maintain compliance for the full contract term, including renewals. Yes: ⃣ No: ⃣
• The Offeror will immediately notify the Agency of any violation, lapse, downgrade, or revocation of certification or controls. Yes: ⃣ No: ⃣
• The Offeror agrees to provide verification or evidence upon Agency request and supports audit or assessment activities. Yes: ⃣ No: ⃣
SECTION 10 - INCIDENT RESPONSE & AUDITABILITY
• Does the proposed solution maintain a documented incident response plan covering security events involving Agency data or systems? Yes: ⃣ No: ⃣
• The Offeror will notify the Agency of any actual or suspected security incident within twenty-four (24) hours of detection. Yes: ⃣ No: ⃣
• How are security incidents reported to the Agency? (Check all that apply) Yes: ⃣ No: ⃣ ⃣ Email ⃣ Phone ⃣ Incident Ticket / Case Management System ⃣ Other
• Does the proposed solution maintain audit logs of all user, system, and administrative activity? Yes: ⃣ No: ⃣
• Audit logs are retained in an active, searchable state for at least ninety (90) days. Yes: ⃣ No: ⃣
• Audit logs are securely archived for a minimum of twelve (12) months. Yes: ⃣ No: ⃣
• Audit logs are protected against unauthorized access, modification, and deletion. Yes: ⃣ No: ⃣
• Audit logs can be made available to the Agency upon request for security review or investigation. Yes: ⃣ No: ⃣
SECTION 10.1 - EXCEPTIONS OR LIMITATIONS
If No was selected for any question, describe the limitation(s) and any proposed mitigation:
SECTION 11 - CONTRACTOR CERTIFICATION
The undersigned certifies that all statements above are true, accurate, and complete, and that the Offeror has the authority to bind the company to these requirements.
AUTHORIZED REPRESENTATIVE
LEGAL COMPANY NAME:
SIGNATURE:
PRINTED NAME:
TITLE:
DATE:
| SECTION 1 - GENERAL INFORMATION |
| SECTION 2 - CLOUD PLATFORM |
| SECTION 3 - DATA RESIDENCY (CONUS) |
| SECTION 4 - DATA SOVEREIGNTY & FOREIGN ACCESS |
| SECTION 5 - DATA ENCRYPTION & KEY MANAGEMENT |
| SECTION 6 - IDENTITY & ACCESS MANAGEMENT (IAM) |
| SECTION 6.1 - ROLE-BASED ACCESS CONTROL (RBAC) CAPABILITIES (REQUIRED IF YES) |
| SECTION 7 - SECURITY & COMPLIANCE CERTIFICATION |
| SECTION 8 - SUBCONTRACTORS & CLOUD PROVIDERS |
| SECTION 9 - COMPLIANCE & VERIFICATION |
| SECTION 10 - INCIDENT RESPONSE & AUDITABILITY |
| SECTION 10.1 - EXCEPTIONS OR LIMITATIONS |
| SECTION 11 - CONTRACTOR CERTIFICATION |
| AUTHORIZED REPRESENTATIVE |
File details come from the government source that posted it. Updated .