ESBD_432148_1751314819183_13 - 3202500148 Attachment 13 Cybersecurity.pdf
PDF 195 KB Posted
- Attached to
- Mobile Credential Wallet State and local contract opportunity
- Solicitation number
- 3202500148
- Issued by
- Texas
About this file
This document is Attachment 13 - Data Privacy and Cybersecurity for the Texas Workforce Commission (TWC) Mobile Credential Wallet project (Solicitation #3202500148). The attachment outlines comprehensive cybersecurity and data privacy requirements for potential respondents, focusing on cloud-based solutions for a mobile credential wallet system. Key requirements include hosting solutions within the United States, ensuring FedRAMP (Moderate) or TX-RAMP Level 2 certification, maintaining data isolation, encrypting data in transit and at rest, and implementing multi-factor authentication.
The document details an extensive list of cybersecurity requirements that respondents must address, including privacy protocols, information security management, continuous security monitoring, vulnerability assessments, internal data security protocols, fraud detection, personnel security, incident management, disaster recovery, and various technical controls. Respondents are required to provide a detailed description of how they will meet these requirements in a separate document and may gain additional consideration by holding certifications such as SSAE 18 SOC 2, ISO 27001, or FedRAMP/TX-RAMP certifications. The requirements emphasize protecting confidential information, ensuring compliance with standards like HIPAA and FERPA, and maintaining robust security governance throughout the contract term.
View the file
Other files for this state and local contract opportunity
Show all 16
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
3202500148 – Mobile Credential Wallet
Attachment 13 – Data Privacy and Cybersecurity
Respondent’s proposed solution must comply with TWC’s requirement that all data remain in the United States, meet stringent Data Privacy and Cybersecurity requirements, and comply with Texas Government Code Section 2054.391 to host the solution in the DIR DCS.
Regardless of any other provision of this Contract or its incorporated or referenced documents, all of the data for State of Texas Customers identified by the State as requiring their data to remain in the United States shall remain, and be stored, processed, accessed, viewed, transmitted, and received, always and exclusively within the United States which is defined as all 50 states and the District of Columbia.
1.0 Cybersecurity Requirements
Requirements (if applicable) include, but are not limited to:
1. Ensuring solutions that include in whole or in part cloud-based services are hosted by a Cloud Service Provider that has attained Federal Risk and Authorization Management Program (FedRAMP) (Moderate) ready status attested to by a certified third party assessor organization or will have attained FedRAMP (Moderate) ready status prior to Award Date; if a SaaS solution is proposed it must have TX- RAMP Level 2 certification by go live date.
2. Ensuring cloud-based solutions are located within the United States (50 States including the District of Columbia), and all access and support of the solution is performed from the United States.
3. Software, data, and services are isolated within the cloud environment so that other cloud customers sharing physical or virtual space cannot access other customer data or applications.
4. Provide a complete listing of all data centers within the cloud environment where this solution will operate.
5. Ensure data in transit and at rest is encrypted using FIPS 140-2 or FIPS 140-3 compliant algorithms, cyphers, and modules.
6. Ensure any storage devices used in the solution are securely sanitized and/or destroyed prior to disposal using methods acceptable by National Security Agency (NSA) and/or Central Security Service (CSS).
7. Conduct at least an annual assessment of the security controls in place on all information systems used in the solution.
8. Incorporate multi-factor authentication for access to the cloud solution from the internet.
9. Ensure, if using Network Edge Managed Services, that the National Institute of Standards and Technology (NIST)/ISO/IEC 27018:2014 certification has been achieved for the specific services being added to the portfolio.
10. Ensure the protection of TWC confidential information, including Sensitive Personal Identifiable Information (SPII) (See Attachment 1:
Section 2.28) from unauthorized disclosure, unauthorized access, and misuse, at a minimum in accordance with the NIST Special Publication 800-122, Guide to Protecting the Confidentiality of PII through the implementation of controls such as role-based access controls (RBAC), encryption at rest and in transit.
11. Ensure data security and protection for Health Insurance Portability and Accountability Act (HIPAA) compliance and Family Educational Rights and Privacy Act (FERPA) Compliance.
12. Provide for Security Vulnerability Assessments and Controlled Penetration testing by TWC and/or its agent as agreed to for the duration of services of the Successful Respondent.
13. Fully cooperate with the TWC Chief Information Security Officer (CISO) and security team in the detection and remediation of any security vulnerability of the hosting infrastructure and/or the application.
14. Provide a dedicated Hardware Security Module (HSM) appliance for encryption key management.
15. Ensure data protection, Respondent must not use or sell account information, and will provide a written policy to ensure data privacy and security to TWC.
Respondent must affirm their intent to comply with the Requirements as stated in this Section and affirm that they will continue to comply with these Requirements during the term of the Contract issued as a result of this Solicitation, if any.
1.1 Cybersecurity Requirements
In the response to this section, the Respondent must describe how it will address the following requirements in a file entitled ABC_RFO_3202500148_CyberRequirements (.docx or .pdf):
A. Privacy
B. Information Security Management
C. Security Management Plan/System Security Plan
D. Continuous Security Monitoring
E. Security Governance Controls
F. Vulnerability and Security Assessments
G. Internal Data Security Protocols
1). Active Countermeasures
2). Passive Countermeasures
3). User Authentication
4). Security Monitoring Systems
5). Encryption
6). Contracted “Hacking” Services
7). Agent‐Based Monitoring Tools
8). Event Correlation Software
9). Automated Notification
10). Dedicated Security Team
H. Audit and Accountability
I. Fraud Detection and Identity Theft
J. Personnel Security Protocol
K. Data Migration and Conversion Process
L. Data Archiving, Retention, and Retrieval
M. Data Processing Security Systems
N. Data Management Purge
O. Password Policy
P. Facility Safeguards & Security
Q. Physical Security
R. Location of Data
S. Incident Management and Response Plan
T. Disaster Recovery
a. 1). Periodically test data archiving, retention, and retrieval procedures
U. Data Backup and Replication strategy
V. Network Controls including border perimeter controls
W. Application Controls including Web Application Firewall
X. Change management
Y. Release Management Strategy
Z. System Development Life Cycle
AA. Software Configuration Management (SCM) process, controls, and tools
BB. Exceptions process to security policies and IT Security Risk Management.
1.1.1 CyberSecurity Certifications
If Respondent has obtained one, or more, of the cybersecurity certifications listed below, Respondent must include certifications included in Table 3: Response Package 1.
A. Statement on Standards for Attestation Engagements 18 Service and Organization Controls 2 Report (SSAE 18 SOC 2) certification.
B. Information Security Management ISO 27001 certification.
C. Federal Risk and Authorization Management Program (FedRAMP) certification or Texas Risk and Authorization Management Program (TX-RAMP) Level 1 or Level 2 certification, as required per agency contract.
| 1.0 Cybersecurity Requirements |
| 1.1 Cybersecurity Requirements |
| 1.1.1 CyberSecurity Certifications |
File details come from the government source that posted it. Updated .