Exhibit_1,_Information_Technology_Security_Matrix.pdf

PDF 327 KB Posted

Attached to
Marinas & Campground Management Software Solution State and local contract opportunity
Solicitation number
RFP0000007
Issued by
Miami-Dade County, Florida

About this file

This is an Information Technology Security Matrix exhibit for a Marinas and Campground Management Software Solution procurement by the State of Florida. The document establishes the security requirements and technical standards that the proposed software solution must meet to protect sensitive data and ensure system integrity across the six marinas and campground facilities. The matrix outlines compliance requirements across multiple security domains including access control, encryption, authentication, audit logging, vulnerability management, and incident response protocols that bidders must demonstrate their software can satisfy.

The security matrix serves as a detailed technical specification document that defines mandatory security controls and performance standards rather than pricing, contract terms, or procurement timelines. It establishes the baseline security posture required for the cloud-based management system and ensures that any selected vendor's solution will meet Florida's information technology security standards and regulatory compliance obligations. Bidders must certify that their proposed software architecture, infrastructure, and operational procedures align with each security requirement specified in the matrix as a condition of proposal acceptance.

View the file

Other files for this state and local contract opportunity

Other files attached to Marinas & Campground Management Software Solution, newest first.
File Type Posted
RFP0000007_RFP_Solicitation.pdf PDF
Draft_Form_of_Agreement.pdf PDF
Form_1_-_Price_Proposal_Schedule.docx DOCX document
Exhibit_2,_Functionality_Matrix.xlsx XLSX spreadsheet
RFP_Proposer_Info.pdf PDF
Exhibit_3,_Profile_Groups.pdf PDF
06162026_PR_EVN0055594_1_1_0_06192026_Solicitation_Packet.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Miami-Dade County, FL VENDOR and PRODUCT NAME:

CYBERSECURITY INFORMATION - CONFIDENTIAL AND EXEMPT FROM PUBLIC RECORD DISCLOSURE PURSUANT TO FLORIDA STATUTES s. 282.318 and s. 119.0713

ATTACHMENT A - INFORMATION TECHNOLOGY SECURITY MATRIX

VERSION 112024 REV. A

H.R. 5515

In accordance with US House of Representatives H.R. 5515 “National Defense

Authorization Act for Fiscal Year 2021” House Bill, the Solution shall not utilize products or services from the manufacturers listed therein. DOD Releases List of People's

Republic of China (PRC) Military Companies in Accordance With Section 1260H of the National Defense Authorization Act for Fiscal Year 2021 > U.S. Department of Defense > Releases

Use of Miami-Dade County Data and Systems:

1. Access Control: Miami-Dade County (MDC) employees, system users, contractors or those operating on their behalf are prohibited from incorporating or using AI-enabled services in such a way that Miami-Dade County data is uploaded or made available for data mining or usage. Uploading, copying, sharing, or transmitting any sensitive Miami-Dade created or managed data via methods or software not explicitly allowed are prohibited. This includes any PCI, PII, HIPAA, CJIS or other data that is created or managed by or on behalf of Miami-Dade County. Access controls are to be guided by the Miami-Dade County Enterprise Security Policy. The MDC Enterprise Security Policy is available to responsive bidders or upon request approved by the MDC Enterprise Security Office.

2. Data Protection: All data processed by Cloud-based or AI-enabled technologies must be protected from unauthorized access, theft, and misuse. Data must be encrypted in transit and at rest, and access controls should be in place to ensure that only authorized users can access the data. Data should be stored securely, and backups must be kept in a secure location. Usage of said data by the Cloud or AI provider must be communicated and agreed to, with consideration to transparency and with human oversight of use and potential abuse or misuse.

3. Monitoring: Any Cloud-based or AI-enabled technologies must be monitored for unusual activity or unauthorized access. Logs and alerts should be reviewed regularly, and security analytics should be used to identify potential threats or hallucinations.

4. Vulnerability Management: Any Cloud-based or AI-enabled technologies must be regularly assessed for vulnerabilities and weaknesses. Regular vulnerability scans and penetration testing must be conducted, and security assessments must be performed to identify areas of improvement.

5. Incident Response: Abuse or misuse to the extent that it endangers the security or privacy of Miami-Dade County citizens, users, data, personnel, or facilities must be reported according to the Miami-Dade County Enterprise Security Office Incident Response Plan.

6. Training and Awareness: All employees must receive training on the secure use of any Cloud-based or AI-enabled technologies. This should include best practices for data protection, access controls, and incident response.

7. Compliance: Any Cloud-based or AI-enabled technologies must be compliant with relevant laws and regulations, such as GDPR, HIPAA, and CCPA as well as compliant with Miami-Dade County Security Policy and the overall policies and procedures of Miami-Dade County. Regular audits should be conducted to ensure compliance.

8. Risk Management: A risk management program should be in place to identify and mitigate risks associated with the use of any Cloud-based or AI-enabled technologies. Risks should be regularly assessed, and appropriate controls should be put in place to mitigate those risks.

9. Coordinated Vulnerability Disclosure: Miami-Dade County follows a vulnerability disclosure model in which a vulnerability or an issue is disclosed to the public only after the responsible parties have been allowed sufficient time to patch or remedy the vulnerability or issue.

https://www.defense.gov/News/Releases/Article/3661985/ https://www.defense.gov/News/Releases/Article/3661985/ https://www.defense.gov/News/Releases/Article/3661985/

Instructions

• Purpose: This security matrix is designed to assess the security controls implemented by external vendors and contractors.

• Instructions: This form should be completed by someone who is familiar with the proposed system and can answer technical security questions such as a Product Manager, CISO, CTO, CIO. Please save the completed file to include the name of the product and return the completed matrix in a machine-readable format (e.g., Word or PDF).

• For each functionality listed below, please select the code that best corresponds to your response and enter it in the 'Meet (Y/C/M/N)' column. Provide detailed explanations or comments in the 'Detailed Explanation' column to clarify how the functionality is addressed. Provide diagrams and additional documentation when you return the completed security matrix.

• Response Codes:

o Y – Fully met without configuration or modification.

o C – Met via configuration (without changing base source code).

o M – Met via modification of the base source code.

o N – Not met. If an alternative compensating control is being proposed, please provide a detailed explanation. A blank or "N/A" response will be interpreted as "N".

Vendor Information

• Vendor Name:

• Contact Person:

• Title:

• Email:

• Phone Number:

Security Matrix

A. Data Classification and Protection

Functionality

Number Functionality

Meet

(Y/C/M/N)

Detailed

Explanation References

Type of Data Processed: Indicate all types of data your solution processes. Remove any that do not apply:

- PII (Personally Identifiable Information)

- PCI (Payment Card Industry)

- PHI (Protected Health Information)

- Critical Infrastructure - SCADA / ICS / OT

- HR (Human Resources)

- CJIS (Criminal Justice Information Services)

- HIPAA

- Financial Records - Other (please specify)

NIST CSF

ID.AM-5; ISO

27001 A.8

Compliance and Risk Assessments: Has a SOC 2

Type II or other risk assessment been performed within the last 12 months? Please provide the most recent report.

ID.GV-1; SOC

2, ISO 27001

B. Risk Assessments and Compliance

Functionality

Number Functionality

Meet

(Y/C/M/N) Detailed Explanation References

Compliance Certifications: Does the solution comply with any of the following standards?

Please check all that apply and provide supporting documentation.

- ISO/IEC 27001

- PCI DSS v4.0.1

- HIPAA

- StateRAMP / FedRAMP

- Other (please specify)

ID.GV-2; ISO

27001;

StateRAMP;

FedRAMP, PCI 4.0.1 https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors

C. Identity and Access Management

Number Functionality

Meet

(Y/C/M/N) Detailed Explanation References

Unique User Identification: The solution uniquely identifies each user.

PR.AC-1;

CIS Control

6.2

Integration with Directory Services: The solution integrates with Microsoft Active

Directory or Azure Active Directory

(EntraID) for user authentication of internal users using protocols such as

SAML, OAuth 2.0, or OpenID Connect.

CIS Control

6.1

Principle of Least Privilege (Operating

Systems): The solution can be installed and maintained in accordance with the principle of least privilege for operating systems.

PR.AC-6;

CIS Control

Principle of Least Privilege (Database

Systems): The solution can be installed and maintained in accordance with the principle of least privilege for database systems.

PR.AC-6;

CIS Control

Unique Process Identification: The solution uniquely identifies each process (system, service, Managed

Service Accounts).

PR.AC-4;

CIS Control

Scheduled Password Rotation: The solution supports scheduled password rotation of process accounts.

PR.AC-5;

CIS Control

6.1

Disable or Rename Default Accounts:

Default system accounts can be disabled or renamed (e.g., administrator/admin, guest).

CIS Control

Number Functionality

Meet

(Y/C/M/N) Detailed Explanation References

Inactive Account Management:

Accounts are automatically disabled after a configurable period of inactivity

(e.g., 90 days).

CIS Control

16.11

Password Authentication: The solution utilizes account passwords for authentication and supports passphrase best practices.

CIS Control

Password Complexity Requirements:

User password complexity is configurable to allow for a minimum of

14 characters comprised of upper and lower-case letters, numbers, and special characters. System Accounts require complex passwords with a minimum of 25 characters and must be changed every 180 days. Use of Group

Managed Service Accounts (gMSA) is strongly recommended.

CIS Control

6.3

Password Suppression: Passwords are suppressed (not echoed back) when entered by users.

CIS Control

6.5

Multi-Factor Authentication (MFA): The solution supports MFA for user authentication. Phishing Resistant

Authentication is strongly recommended.

PR.AC-7;

CIS Control

6.8

Encryption of Credentials in Transit:

User login credentials are encrypted during transmission with a minimum of

AES 256-bit encryption.

PR.DS-2;

CIS Control

3.1

17 Password History and Reuse: The solution supports password history

Functionality

Meet

(Y/C/M/N) Detailed Explanation References functionality to prevent reuse of a configurable number of prior passwords

(minimum of 10).

CIS Control

6.4

Administrative Password Aging: The solution supports administrative password aging of 30 days.

CIS Control

6.3

Password Reset Capability:

Administrative accounts have the capability of resetting passwords.

CIS Control

Self-Service Password Reset with

Challenge Questions: The solution provides user self-service password reset functionality utilizing challenge-response authentication.

CIS Control

6.6

Challenge Question Security: Self-service challenge responses are comprised of at least 8 questions, with responses stored securely using AES

256-bit encryption.

CIS Control

6.6

Configurable Login Attempt Limits: The solution supports limiting unsuccessful login attempts to 5 before locking out or disabling the account.

CIS Control

16.7

Concurrent Session Control: The solution supports limiting concurrent user sessions to 1 by default;

administrators can configure the number.

CIS Control

16.9

Account Lockout/Disable Capability:

Administrators can lock or disable accounts whenever necessary.

Functionality

Meet

(Y/C/M/N) Detailed Explanation References

CIS Control

16.4

Pre-Login Banner: The solution can display a customizable pre-login warning banner stating that unauthorized access is prohibited.

PR.PT-2;

CIS Control

16.1

Role-Based Access Control (RBAC):

The solution supports managing users based on group membership and assigning/revoking specific privileges.

CIS Control

User Rights and Privileges Reporting:

Tools and reports are available to enumerate user rights, group membership, access permissions, or user profiles.

PR.DS-6;

CIS Control

4.4

Account Password Encryption in

Storage: System Accounts, Passwords, Certificates, Keys, and other secrets are stored hashed and salted using strong cryptographic algorithms (e.g., SHA-256 with salt).

PR.DS-1;

CIS Control

14.4

D. Audit Logging and Monitoring

Number Functionality

Meet

(Y/C/M/N) Detailed Explanation References

Audit Logging Capability: The solution captures audit logs of successful and unsuccessful logins, records viewed, printed, added, deleted, or modified, and retains logs for at least 5 years plus current.

DE.AE-3; CIS

Control 8

Audit Log Details: Logs capture date and time, user account, source IP address, event details, and success or failure of the event.

DE.AE-3; CIS

Control 8

Audit Mechanism Protection:

Administrators cannot disable the audit mechanism.

PR.PT-1; CIS

Control 8.8

Audit Log Integrity: Audit logs are protected from unauthorized access and alteration (e.g., sent to a SIEM in addition to local storage).

Control 8.5

Audit Log Tamper Prevention: Users and administrators are prevented from modifying, deleting, or adding log entries.

Control 8.5

Intrusion Detection and Prevention:

The solution is protected using

Intrusion Detection and Prevention

Systems (IDS/IPS).

DE.CM-1; CIS

Control 9

Protection Against DDoS Attacks: The solution is protected against Distributed

Denial of Service (DDoS) attacks.

PR.DS-5; CIS

Control 9

Security Event Notifications: The solution generates outbound alerts and notifications. Explain the data contained in these messages (e.g., DE.DP-5; CIS

Control 8.7

Functionality

Meet

(Y/C/M/N) Detailed Explanation References email alerts, automated reports, SNMP v.3 traps).

E. Software and Configuration Management

Number Functionality

Meet

(Y/C/M/N) Detailed Explanation References

Microsoft Enterprise Access

Model Compliance: The solution can be installed and maintained according to the Microsoft

Enterprise Access Model.

PR.IP-1; CIS

Control 4

Software Version Control: The solution prevents outdated software versions from accessing the Database Management

System (DBMS).

PR.IP-1; CIS

Control 2.3

Patch Management: The solution is regularly patched with appropriate security patches within specified timeframes:

- Critical patches: within 14 days of release

- High patches: within 30 days

- Medium and Low patches: within

90 days

PR.IP-12; CIS

Control 7

Vulnerability Management:

Regular vulnerability scans are performed (e.g., monthly) using tools like Nessus or Qualys.

Reports are shared upon request.

Control 7

Application Security Testing:

Regular application vulnerability scans are conducted using tools like WebInspect, Veracode, or

AppScan. Dynamic and Static

Application scans are preferred.

Control 18

Change Control Processes:

Application vulnerability scanning

(e.g., PCI DSS, OWASP Top 10)

PR.IP-3; CIS

Control 6.1 https://docs.microsoft.com/en-us/windows-server/identity/securing-privileged-access/securing-privileged-access-reference-material https://docs.microsoft.com/en-us/windows-server/identity/securing-privileged-access/securing-privileged-access-reference-material

Functionality

Meet

(Y/C/M/N) Detailed Explanation References is performed prior to production migration of changes. Medium, High, and Critical vulnerabilities are remediated before migration.

Reports are shared upon request.

F. Data Encryption and Transmission

Number Functionality

Meet

(Y/C/M/N) Detailed Explanation References

Data Encryption in Transit: Sensitive data is encrypted during transmission over the network using a minimum of TLS 1.2 with AES

PR.DS-2; CIS

Control 3.11

Data Encryption at Rest: Sensitive information is encrypted while in storage using a minimum of AES

PR.DS-1; CIS

Control 14

Encryption over External Networks:

Sensitive information is encrypted for transmission over external networks using a minimum of AES

Control 3.11

G. Cloud Hosting and Infrastructure Security

Number Functionality

Meet

(Y/C/M/N) Detailed Explanation References

Data Center Compliance: If cloud-hosted, the solution is hosted in an audited data center complying with

ISO/IEC 27001, SOC 2 Type II, StateRAMP, or FedRAMP standards.

Provide the latest audit report.

PR.AC-5;

StateRAMP;

FedRAMP

Employee Access Controls: Controls prohibit hosting employees or third-party personnel from accessing, viewing, or modifying customer confidential data. Describe controls used, including encryption and key storage mechanisms.

PR.AC-5; CIS

Control 14

Functionality

Meet

(Y/C/M/N) Detailed Explanation References

High Availability and Failover: The solution is highly available with active-active or active-passive failover between geographically diverse data centers.

PR.DS-4; CIS

Control 12

Data Residency: System and data are physically located within the

Continental United States.

PR.DS-5

Network Accessibility: System is accessible from the County's network and proxy infrastructure.

PR.AC-3

Session Encryption: All sessions are encrypted from initiation to termination using validated encryption ciphers (TLS 1.2 or higher).

Control 3.11

Regular Vulnerability Scanning:

Monthly vulnerability scans are performed using tools like Nessus, Tenable, or Qualys. Reports will be shared with the County if requested.

Control 7

API Security: APIs use API key security (X-API-Key) or demonstrate alternate security controls.

PR.AC-1; CIS

Control 14.8

H. Software Integrity and Secure Development

Number Functionality

Meet

(Y/C/M/N) Detailed Explanation References

Prevent Changes to Records:

Users, developers, DBAs, or administrators cannot alter posted, NIST CSF PR.IP-

4; CIS Control 5

Functionality

Meet

(Y/C/M/N) Detailed Explanation References completed, or closed transaction records.

Rollback Processes: Rollback processes are incorporated into the database for all critical transactions.

4; CIS Control

10.5

Outdated Software Access

Prevention: The solution prevents outdated software versions from accessing the DBMS.

1; CIS Control 2.3

I. Artificial Intelligence (AI) and Machine Learning (ML) Controls

• Note: This section addresses security controls specific to systems utilizing Artificial Intelligence (AI) and Machine Learning (ML). These controls ensure the trustworthy, secure, and ethical use of AI/ML technologies. Please refer to NIST.AI.600-1.pdf for detailed guidance.

Functionality

Number Functionality

Meet

(Y/C/M/N) Detailed Explanation References

AI Governance and Oversight: The organization has established governance structures and policies for

AI/ML system development and deployment, including defined roles and responsibilities.

NIST.AI.600-

1.pdf; NIST AI

RMF GOV

AI Risk Management Framework

Application: The organization applies a risk management framework specific to

AI/ML systems to identify, assess, and mitigate risks throughout the AI lifecycle.

RMF MAP

Data Quality and Integrity for AI/ML:

Data used for training and testing AI/ML models is assessed for quality, relevance, and potential biases.

Processes ensure data integrity and accuracy.

RMF MEASURE

Model Transparency and Explainability:

AI/ML models are designed to be interpretable, with mechanisms to explain model decisions to stakeholders as appropriate.

RMF MANAGE

Security of AI/ML Systems: The AI/ML systems are protected against adversarial attacks (e.g., data poisoning, model inversion). Security controls safeguard AI assets and processes.

RMF SECURE

Functionality

Meet

(Y/C/M/N) Detailed Explanation References

Privacy Protection in AI/ML: Measures protect personal and sensitive information used in AI/ML systems, including compliance with data protection regulations and techniques like differential privacy.

RMF PROTECT

Fairness and Bias Mitigation: The organization identifies and mitigates biases in AI/ML models to promote fairness and prevent discrimination against any group.

RMF MEASURE

Monitoring and Maintenance of AI/ML

Systems: Continuous monitoring detects performance degradation, biases, or security incidents in AI/ML systems, with processes for model updates.

RMF MANAGE

Ethical Considerations and Compliance:

The organization adheres to ethical guidelines and legal requirements related to AI/ML, including transparency and accountability.

RMF GOV

Third-Party AI Components

Management: If using third-party AI/ML components or services, the organization ensures they meet the same security and ethical standards, including due diligence.

RMF GOV

Incident Response for AI/ML Systems:

The organization has incident response plans that include scenarios specific to

AI/ML systems, such as model failures or adversarial attacks.

RMF RESPOND

Functionality

Meet

(Y/C/M/N) Detailed Explanation References

Documentation and Reporting of AI/ML

Models: Comprehensive documentation of AI/ML models, including design decisions, training data, and testing results, is maintained and available for review.

RMF GOV

J. Software Bill of Materials (SBOM)

• AGPL POLICY WARNING: Code licensed under the GNU Affero General Public License (AGPL)

MUST NOT be used at Miami-Dade County.

Functionality

Number Functionality

Meet

(Y/C/M/N) Detailed Explanation References

SBOM Creation and Maintenance:

An SBOM must be created and maintained for all software projects, listing all third-party libraries and their associated metadata.

NIST SP 800-

161; CIS

Control 2.3

SBOM Submission Formats:

SBOMs must be submitted in

CycloneDX or SPDX formats. If these formats are unavailable, a fillable form template must be used to capture the required information.

At a minimum, the following details must be documented for each third-party library: Software Component or Library Name, Author, Version, Last Updated Date, Website, and

License.

Control 2.3

Regular SBOM Updates and

Reviews: The SBOM must be updated and reviewed regularly to ensure accuracy and completeness.

Control 2.3

Licensing Compliance Review: A licensing compliance review must be conducted, and the results must be signed by the developer's management before any third-party library is used in production.

ID.SC-3; ISO

27001

A.18.1.3

General Comments

• Please provide any additional information or clarifications below:

Notes:

• Applicability of Sections: Ensure you complete all sections relevant to your solution, including the new

Software Bill of Materials (SBOM) section.

• AGPL Policy Compliance: Under no circumstances should code licensed under the GNU Affero

General Public License (AGPL) be used in solutions provided to Miami-Dade County.

• Compensating Controls: For any "N" responses, please provide detailed explanations of compensating controls or alternative solutions in the 'Detailed Explanation' column.

• Evidence and Documentation: Please provide supporting documents where applicable, such as SBOM files, policy documents, certificates, audit reports, or AI/ML governance frameworks.

• Priority Levels: Some functionalities may be marked as High Priority. These are critical requirements that must be met for compliance.

• Data Protection Regulations: Ensure compliance with relevant data protection laws such as GDPR, CCPA, or other applicable regulations.

• Ethical AI Practices: Adherence to ethical guidelines in AI development and deployment is crucial for maintaining trust and compliance.

• SBOM Importance: Maintaining an accurate and up-to-date SBOM is essential for supply chain security and vulnerability management.

Glossary of Terms and Acronyms

• 2FA: Two-Factor Authentication

• ADFS: Active Directory Federation Services

• AES: Advanced Encryption Standard

• AGPL: GNU Affero General Public License

• AI: Artificial Intelligence

• AI RMF: Artificial Intelligence Risk Management Framework

• API: Application Programming Interface

• CJIS: Criminal Justice Information Services

• CIS Controls: Center for Internet Security Controls

• CISO: Chief Information Security Officer

• CycloneDX: A software bill of materials (SBOM) standard designed for use in application security contexts and supply chain component analysis

• DDoS: Distributed Denial of Service

• DBA: Database Administrator

• DBMS: Database Management System

• EDR: Endpoint Detection and Response

• EOL: End of Life

• FedRAMP: Federal Risk and Authorization Management Program

• FIDO2: Fast IDentity Online 2, an authentication standard that enables phishing-resistant authentication methods

• FIM: Federated Identity Management

• gMSA: Group Managed Service Accounts

• Group Managed Service Accounts (gMSA): A feature in Microsoft Windows Server that provides automatic password management and simplified Service Principal Name (SPN) management for service accounts running on multiple servers. gMSAs allow services to share a common identity across multiple servers or instances, enhancing security and ease of management.

• HIPAA: Health Insurance Portability and Accountability Act

• HR: Human Resources

• IDS/IPS: Intrusion Detection System/Intrusion Prevention System

• ISO/IEC 27001: International Organization for Standardization/International Electrotechnical Commission

27001

• MFA: Multi-Factor Authentication

• ML: Machine Learning

• NIST: National Institute of Standards and Technology

• NIST CSF: NIST Cybersecurity Framework

• OWASP: Open Web Application Security Project

• PCI DSS: Payment Card Industry Data Security Standard.

• PHI: Protected Health Information

• PII: Personally Identifiable Information

• Phishing Resistant Authentication: Authentication methods designed to prevent phishing attacks by eliminating reliance on shared secrets (like passwords) that can be stolen or intercepted. This typically involves using cryptographic authentication techniques, such as hardware security keys compliant with

FIDO2/WebAuthn standards, certificate-based authentication, or biometric factors.

• RBAC: Role-Based Access Control

• RDBMS: Relational Database Management System

• SAML: Security Assertion Markup Language

• SBOM: Software Bill of Materials

• SIEM: Security Information and Event Management

• SHA: Secure Hash Algorithm SHA-256 or better is required.

• SNMP: Simple Network Management Protocol. SNMP v.3 or better is required.

• SOC 2: System and Organization Controls 2

• SOX: Sarbanes-Oxley Act

• SPDX: Software Package Data Exchange, an open standard for communicating software bill of material information

• SSAE 16: Statement on Standards for Attestation Engagements No. 16

• SSO: Single Sign-On

• StateRAMP: State Risk and Authorization Management Program

• TLS: Transport Layer Security

References

• NIST SP 800-161: Supply Chain Risk Management Practices for Federal Information Systems and

Organizations o Provides guidance on identifying, assessing, and mitigating risks throughout the supply chain at all levels of the organization.

o Link to NIST SP 800-161

• CIS Controls v8: Center for Internet Security Critical Security Controls Version 8 o Control 2.3: Addressing software inventory and control.

• ISO/IEC 27001 A.18.1.3: Protection of records o Ensures records are protected from loss, destruction, falsification, and unauthorized access or release.

• NIST.AI.600-1.pdf: NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0) o Provides guidelines for managing risks associated with AI systems to promote trustworthy and responsible AI.

o Link to NIST AI RMF 1.0 https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/final https://www.nist.gov/itl/ai-risk-management-framework

Submission Guidelines

• Deadline for Submission: [Insert Deadline]

• Preferred Format: Please return the completed matrix in a machine-readable format (e.g., Word or

PDF).

• Contact for Queries: [Insert Contact Name and Email]

• Confidentiality Assurance: Your responses will be treated confidentially and used solely for the purpose of assessing the security controls for the proposed system.

Vendor Declaration

• I hereby attest that the information provided in this security matrix is accurate and complete to the best of my knowledge.

• Authorized Signature:

• Name:

• Title:

• Date:

attachment A - information technology security matrix
version 112024 rev. A

File details come from the government source that posted it. Updated .