ESBD_432148_1751314819183_13 - 3202500148 Attachment 13 Cybersecurity.pdf

PDF 195 KB Posted

Attached to
Mobile Credential Wallet State and local contract opportunity
Solicitation number
3202500148
Issued by
Texas

About this file

This document is Attachment 13 - Data Privacy and Cybersecurity for the Texas Workforce Commission (TWC) Mobile Credential Wallet project (Solicitation #3202500148). The attachment outlines comprehensive cybersecurity and data privacy requirements for potential respondents, focusing on cloud-based solutions for a mobile credential wallet system. Key requirements include hosting solutions within the United States, ensuring FedRAMP (Moderate) or TX-RAMP Level 2 certification, maintaining data isolation, encrypting data in transit and at rest, and implementing multi-factor authentication.

The document details an extensive list of cybersecurity requirements that respondents must address, including privacy protocols, information security management, continuous security monitoring, vulnerability assessments, internal data security protocols, fraud detection, personnel security, incident management, disaster recovery, and various technical controls. Respondents are required to provide a detailed description of how they will meet these requirements in a separate document and may gain additional consideration by holding certifications such as SSAE 18 SOC 2, ISO 27001, or FedRAMP/TX-RAMP certifications. The requirements emphasize protecting confidential information, ensuring compliance with standards like HIPAA and FERPA, and maintaining robust security governance throughout the contract term.

View the file

Other files for this state and local contract opportunity

Other files attached to Mobile Credential Wallet, newest first.
File Type Posted
ESBD_432148_1751314632089_07 - 3202500148 Attachment 7 Pricing Assumptions.pdf PDF
ESBD_432148_1751315016961_17 - 3202500148 Appendix A Texas Workforce Board Map.pdf PDF
ESBD_432148_1751314460255_01 - 3202500148 Attachment 1 TWC Vendor T&Cs (02-19-25).pdf PDF
ESBD_432148_1751314488707_02 - 3202500148 Attachment 2 Execution of Offer.pdf PDF
ESBD_432148_1751314507236_03 - 3202500148 Attachment 3 VPAT.pdf PDF
ESBD_432148_1751314547130_04 - 3202500148 Attachment 4 PDAA.xlsx XLSX spreadsheet
ESBD_432148_1751314599261_06 - 3202500148 Attachment 6 Pricing Worksheet.pdf PDF
ESBD_432148_1751314668933_09 - 3202500148 Attachment 9 HSP Form.pdf PDF
ESBD_432148_1751314841110_14 - 3202500148 Attachment 14 Sub W-9 & DD.pdf PDF
ESBD_432148_1751314869681_15 - 3202500148 Attachment 15 - How to fill out the PAR.pdf PDF
ESBD_432148_1751314431120_00 - 3202500148 RFO Mobile Credential Wallet.pdf PDF
ESBD_432148_1751314576317_05 - 3202500148 Attachment 5 SOW.pdf PDF
ESBD_432148_1751314697038_10 - 3202500148 Attachment 10 Evaluation Scoring Matrix.pdf PDF
ESBD_432148_1751314713878_11 - 3202500148 Attachment 11 Questions and Answers.docx DOCX document
ESBD_432148_1751314733411_12 - 3202500148 Attachment 12 Data Center Services.docx DOCX document
ESBD_432148_1751314889004_16 - 3202500148 Attachment 16 Financial Questionnaire.pdf PDF
Show all 16

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

3202500148 – Mobile Credential Wallet

Attachment 13 – Data Privacy and Cybersecurity

Respondent’s proposed solution must comply with TWC’s requirement that all data remain in the United States, meet stringent Data Privacy and Cybersecurity requirements, and comply with Texas Government Code Section 2054.391 to host the solution in the DIR DCS.

Regardless of any other provision of this Contract or its incorporated or referenced documents, all of the data for State of Texas Customers identified by the State as requiring their data to remain in the United States shall remain, and be stored, processed, accessed, viewed, transmitted, and received, always and exclusively within the United States which is defined as all 50 states and the District of Columbia.

1.0 Cybersecurity Requirements

Requirements (if applicable) include, but are not limited to:

1. Ensuring solutions that include in whole or in part cloud-based services are hosted by a Cloud Service Provider that has attained Federal Risk and Authorization Management Program (FedRAMP) (Moderate) ready status attested to by a certified third party assessor organization or will have attained FedRAMP (Moderate) ready status prior to Award Date; if a SaaS solution is proposed it must have TX- RAMP Level 2 certification by go live date.

2. Ensuring cloud-based solutions are located within the United States (50 States including the District of Columbia), and all access and support of the solution is performed from the United States.

3. Software, data, and services are isolated within the cloud environment so that other cloud customers sharing physical or virtual space cannot access other customer data or applications.

4. Provide a complete listing of all data centers within the cloud environment where this solution will operate.

5. Ensure data in transit and at rest is encrypted using FIPS 140-2 or FIPS 140-3 compliant algorithms, cyphers, and modules.

6. Ensure any storage devices used in the solution are securely sanitized and/or destroyed prior to disposal using methods acceptable by National Security Agency (NSA) and/or Central Security Service (CSS).

7. Conduct at least an annual assessment of the security controls in place on all information systems used in the solution.

8. Incorporate multi-factor authentication for access to the cloud solution from the internet.

9. Ensure, if using Network Edge Managed Services, that the National Institute of Standards and Technology (NIST)/ISO/IEC 27018:2014 certification has been achieved for the specific services being added to the portfolio.

10. Ensure the protection of TWC confidential information, including Sensitive Personal Identifiable Information (SPII) (See Attachment 1:

Section 2.28) from unauthorized disclosure, unauthorized access, and misuse, at a minimum in accordance with the NIST Special Publication 800-122, Guide to Protecting the Confidentiality of PII through the implementation of controls such as role-based access controls (RBAC), encryption at rest and in transit.

11. Ensure data security and protection for Health Insurance Portability and Accountability Act (HIPAA) compliance and Family Educational Rights and Privacy Act (FERPA) Compliance.

12. Provide for Security Vulnerability Assessments and Controlled Penetration testing by TWC and/or its agent as agreed to for the duration of services of the Successful Respondent.

13. Fully cooperate with the TWC Chief Information Security Officer (CISO) and security team in the detection and remediation of any security vulnerability of the hosting infrastructure and/or the application.

14. Provide a dedicated Hardware Security Module (HSM) appliance for encryption key management.

15. Ensure data protection, Respondent must not use or sell account information, and will provide a written policy to ensure data privacy and security to TWC.

Respondent must affirm their intent to comply with the Requirements as stated in this Section and affirm that they will continue to comply with these Requirements during the term of the Contract issued as a result of this Solicitation, if any.

1.1 Cybersecurity Requirements

In the response to this section, the Respondent must describe how it will address the following requirements in a file entitled ABC_RFO_3202500148_CyberRequirements (.docx or .pdf):

A. Privacy

B. Information Security Management

C. Security Management Plan/System Security Plan

D. Continuous Security Monitoring

E. Security Governance Controls

F. Vulnerability and Security Assessments

G. Internal Data Security Protocols

1). Active Countermeasures

2). Passive Countermeasures

3). User Authentication

4). Security Monitoring Systems

5). Encryption

6). Contracted “Hacking” Services

7). Agent‐Based Monitoring Tools

8). Event Correlation Software

9). Automated Notification

10). Dedicated Security Team

H. Audit and Accountability

I. Fraud Detection and Identity Theft

J. Personnel Security Protocol

K. Data Migration and Conversion Process

L. Data Archiving, Retention, and Retrieval

M. Data Processing Security Systems

N. Data Management Purge

O. Password Policy

P. Facility Safeguards & Security

Q. Physical Security

R. Location of Data

S. Incident Management and Response Plan

T. Disaster Recovery

a. 1). Periodically test data archiving, retention, and retrieval procedures

U. Data Backup and Replication strategy

V. Network Controls including border perimeter controls

W. Application Controls including Web Application Firewall

X. Change management

Y. Release Management Strategy

Z. System Development Life Cycle

AA. Software Configuration Management (SCM) process, controls, and tools

BB. Exceptions process to security policies and IT Security Risk Management.

1.1.1 CyberSecurity Certifications

If Respondent has obtained one, or more, of the cybersecurity certifications listed below, Respondent must include certifications included in Table 3: Response Package 1.

A. Statement on Standards for Attestation Engagements 18 Service and Organization Controls 2 Report (SSAE 18 SOC 2) certification.

B. Information Security Management ISO 27001 certification.

C. Federal Risk and Authorization Management Program (FedRAMP) certification or Texas Risk and Authorization Management Program (TX-RAMP) Level 1 or Level 2 certification, as required per agency contract.

1.0 Cybersecurity Requirements
1.1 Cybersecurity Requirements
1.1.1 CyberSecurity Certifications

File details come from the government source that posted it. Updated .