Exhibit_1,_Information_Technology_Security_Matrix.pdf
PDF 327 KB Posted
- Attached to
- Marinas & Campground Management Software Solution State and local contract opportunity
- Solicitation number
- RFP0000007
- Issued by
- Miami-Dade County, Florida
About this file
This is an Information Technology Security Matrix exhibit for a Marinas and Campground Management Software Solution procurement by the State of Florida. The document establishes the security requirements and technical standards that the proposed software solution must meet to protect sensitive data and ensure system integrity across the six marinas and campground facilities. The matrix outlines compliance requirements across multiple security domains including access control, encryption, authentication, audit logging, vulnerability management, and incident response protocols that bidders must demonstrate their software can satisfy.
The security matrix serves as a detailed technical specification document that defines mandatory security controls and performance standards rather than pricing, contract terms, or procurement timelines. It establishes the baseline security posture required for the cloud-based management system and ensures that any selected vendor's solution will meet Florida's information technology security standards and regulatory compliance obligations. Bidders must certify that their proposed software architecture, infrastructure, and operational procedures align with each security requirement specified in the matrix as a condition of proposal acceptance.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| RFP0000007_RFP_Solicitation.pdf | ||
| Draft_Form_of_Agreement.pdf | ||
| Form_1_-_Price_Proposal_Schedule.docx | DOCX document | |
| Exhibit_2,_Functionality_Matrix.xlsx | XLSX spreadsheet | |
| RFP_Proposer_Info.pdf | ||
| Exhibit_3,_Profile_Groups.pdf | ||
| 06162026_PR_EVN0055594_1_1_0_06192026_Solicitation_Packet.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Miami-Dade County, FL VENDOR and PRODUCT NAME:
CYBERSECURITY INFORMATION - CONFIDENTIAL AND EXEMPT FROM PUBLIC RECORD DISCLOSURE PURSUANT TO FLORIDA STATUTES s. 282.318 and s. 119.0713
ATTACHMENT A - INFORMATION TECHNOLOGY SECURITY MATRIX
VERSION 112024 REV. A
H.R. 5515
In accordance with US House of Representatives H.R. 5515 “National Defense
Authorization Act for Fiscal Year 2021” House Bill, the Solution shall not utilize products or services from the manufacturers listed therein. DOD Releases List of People's
Republic of China (PRC) Military Companies in Accordance With Section 1260H of the National Defense Authorization Act for Fiscal Year 2021 > U.S. Department of Defense > Releases
Use of Miami-Dade County Data and Systems:
1. Access Control: Miami-Dade County (MDC) employees, system users, contractors or those operating on their behalf are prohibited from incorporating or using AI-enabled services in such a way that Miami-Dade County data is uploaded or made available for data mining or usage. Uploading, copying, sharing, or transmitting any sensitive Miami-Dade created or managed data via methods or software not explicitly allowed are prohibited. This includes any PCI, PII, HIPAA, CJIS or other data that is created or managed by or on behalf of Miami-Dade County. Access controls are to be guided by the Miami-Dade County Enterprise Security Policy. The MDC Enterprise Security Policy is available to responsive bidders or upon request approved by the MDC Enterprise Security Office.
2. Data Protection: All data processed by Cloud-based or AI-enabled technologies must be protected from unauthorized access, theft, and misuse. Data must be encrypted in transit and at rest, and access controls should be in place to ensure that only authorized users can access the data. Data should be stored securely, and backups must be kept in a secure location. Usage of said data by the Cloud or AI provider must be communicated and agreed to, with consideration to transparency and with human oversight of use and potential abuse or misuse.
3. Monitoring: Any Cloud-based or AI-enabled technologies must be monitored for unusual activity or unauthorized access. Logs and alerts should be reviewed regularly, and security analytics should be used to identify potential threats or hallucinations.
4. Vulnerability Management: Any Cloud-based or AI-enabled technologies must be regularly assessed for vulnerabilities and weaknesses. Regular vulnerability scans and penetration testing must be conducted, and security assessments must be performed to identify areas of improvement.
5. Incident Response: Abuse or misuse to the extent that it endangers the security or privacy of Miami-Dade County citizens, users, data, personnel, or facilities must be reported according to the Miami-Dade County Enterprise Security Office Incident Response Plan.
6. Training and Awareness: All employees must receive training on the secure use of any Cloud-based or AI-enabled technologies. This should include best practices for data protection, access controls, and incident response.
7. Compliance: Any Cloud-based or AI-enabled technologies must be compliant with relevant laws and regulations, such as GDPR, HIPAA, and CCPA as well as compliant with Miami-Dade County Security Policy and the overall policies and procedures of Miami-Dade County. Regular audits should be conducted to ensure compliance.
8. Risk Management: A risk management program should be in place to identify and mitigate risks associated with the use of any Cloud-based or AI-enabled technologies. Risks should be regularly assessed, and appropriate controls should be put in place to mitigate those risks.
9. Coordinated Vulnerability Disclosure: Miami-Dade County follows a vulnerability disclosure model in which a vulnerability or an issue is disclosed to the public only after the responsible parties have been allowed sufficient time to patch or remedy the vulnerability or issue.
https://www.defense.gov/News/Releases/Article/3661985/ https://www.defense.gov/News/Releases/Article/3661985/ https://www.defense.gov/News/Releases/Article/3661985/
Instructions
• Purpose: This security matrix is designed to assess the security controls implemented by external vendors and contractors.
• Instructions: This form should be completed by someone who is familiar with the proposed system and can answer technical security questions such as a Product Manager, CISO, CTO, CIO. Please save the completed file to include the name of the product and return the completed matrix in a machine-readable format (e.g., Word or PDF).
• For each functionality listed below, please select the code that best corresponds to your response and enter it in the 'Meet (Y/C/M/N)' column. Provide detailed explanations or comments in the 'Detailed Explanation' column to clarify how the functionality is addressed. Provide diagrams and additional documentation when you return the completed security matrix.
• Response Codes:
o Y – Fully met without configuration or modification.
o C – Met via configuration (without changing base source code).
o M – Met via modification of the base source code.
o N – Not met. If an alternative compensating control is being proposed, please provide a detailed explanation. A blank or "N/A" response will be interpreted as "N".
Vendor Information
• Vendor Name:
• Contact Person:
• Title:
• Email:
• Phone Number:
Security Matrix
A. Data Classification and Protection
Functionality
Number Functionality
Meet
(Y/C/M/N)
Detailed
Explanation References
Type of Data Processed: Indicate all types of data your solution processes. Remove any that do not apply:
- PII (Personally Identifiable Information)
- PCI (Payment Card Industry)
- PHI (Protected Health Information)
- Critical Infrastructure - SCADA / ICS / OT
- HR (Human Resources)
- CJIS (Criminal Justice Information Services)
- HIPAA
- Financial Records - Other (please specify)
NIST CSF
ID.AM-5; ISO
27001 A.8
Compliance and Risk Assessments: Has a SOC 2
Type II or other risk assessment been performed within the last 12 months? Please provide the most recent report.
ID.GV-1; SOC
2, ISO 27001
B. Risk Assessments and Compliance
Functionality
Number Functionality
Meet
(Y/C/M/N) Detailed Explanation References
Compliance Certifications: Does the solution comply with any of the following standards?
Please check all that apply and provide supporting documentation.
- ISO/IEC 27001
- PCI DSS v4.0.1
- HIPAA
- StateRAMP / FedRAMP
- Other (please specify)
ID.GV-2; ISO
27001;
StateRAMP;
FedRAMP, PCI 4.0.1 https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors
C. Identity and Access Management
Number Functionality
Meet
(Y/C/M/N) Detailed Explanation References
Unique User Identification: The solution uniquely identifies each user.
PR.AC-1;
CIS Control
6.2
Integration with Directory Services: The solution integrates with Microsoft Active
Directory or Azure Active Directory
(EntraID) for user authentication of internal users using protocols such as
SAML, OAuth 2.0, or OpenID Connect.
CIS Control
6.1
Principle of Least Privilege (Operating
Systems): The solution can be installed and maintained in accordance with the principle of least privilege for operating systems.
PR.AC-6;
CIS Control
Principle of Least Privilege (Database
Systems): The solution can be installed and maintained in accordance with the principle of least privilege for database systems.
PR.AC-6;
CIS Control
Unique Process Identification: The solution uniquely identifies each process (system, service, Managed
Service Accounts).
PR.AC-4;
CIS Control
Scheduled Password Rotation: The solution supports scheduled password rotation of process accounts.
PR.AC-5;
CIS Control
6.1
Disable or Rename Default Accounts:
Default system accounts can be disabled or renamed (e.g., administrator/admin, guest).
CIS Control
Number Functionality
Meet
(Y/C/M/N) Detailed Explanation References
Inactive Account Management:
Accounts are automatically disabled after a configurable period of inactivity
(e.g., 90 days).
CIS Control
16.11
Password Authentication: The solution utilizes account passwords for authentication and supports passphrase best practices.
CIS Control
Password Complexity Requirements:
User password complexity is configurable to allow for a minimum of
14 characters comprised of upper and lower-case letters, numbers, and special characters. System Accounts require complex passwords with a minimum of 25 characters and must be changed every 180 days. Use of Group
Managed Service Accounts (gMSA) is strongly recommended.
CIS Control
6.3
Password Suppression: Passwords are suppressed (not echoed back) when entered by users.
CIS Control
6.5
Multi-Factor Authentication (MFA): The solution supports MFA for user authentication. Phishing Resistant
Authentication is strongly recommended.
PR.AC-7;
CIS Control
6.8
Encryption of Credentials in Transit:
User login credentials are encrypted during transmission with a minimum of
AES 256-bit encryption.
PR.DS-2;
CIS Control
3.1
17 Password History and Reuse: The solution supports password history
Functionality
Meet
(Y/C/M/N) Detailed Explanation References functionality to prevent reuse of a configurable number of prior passwords
(minimum of 10).
CIS Control
6.4
Administrative Password Aging: The solution supports administrative password aging of 30 days.
CIS Control
6.3
Password Reset Capability:
Administrative accounts have the capability of resetting passwords.
CIS Control
Self-Service Password Reset with
Challenge Questions: The solution provides user self-service password reset functionality utilizing challenge-response authentication.
CIS Control
6.6
Challenge Question Security: Self-service challenge responses are comprised of at least 8 questions, with responses stored securely using AES
256-bit encryption.
CIS Control
6.6
Configurable Login Attempt Limits: The solution supports limiting unsuccessful login attempts to 5 before locking out or disabling the account.
CIS Control
16.7
Concurrent Session Control: The solution supports limiting concurrent user sessions to 1 by default;
administrators can configure the number.
CIS Control
16.9
Account Lockout/Disable Capability:
Administrators can lock or disable accounts whenever necessary.
Functionality
Meet
(Y/C/M/N) Detailed Explanation References
CIS Control
16.4
Pre-Login Banner: The solution can display a customizable pre-login warning banner stating that unauthorized access is prohibited.
PR.PT-2;
CIS Control
16.1
Role-Based Access Control (RBAC):
The solution supports managing users based on group membership and assigning/revoking specific privileges.
CIS Control
User Rights and Privileges Reporting:
Tools and reports are available to enumerate user rights, group membership, access permissions, or user profiles.
PR.DS-6;
CIS Control
4.4
Account Password Encryption in
Storage: System Accounts, Passwords, Certificates, Keys, and other secrets are stored hashed and salted using strong cryptographic algorithms (e.g., SHA-256 with salt).
PR.DS-1;
CIS Control
14.4
D. Audit Logging and Monitoring
Number Functionality
Meet
(Y/C/M/N) Detailed Explanation References
Audit Logging Capability: The solution captures audit logs of successful and unsuccessful logins, records viewed, printed, added, deleted, or modified, and retains logs for at least 5 years plus current.
DE.AE-3; CIS
Control 8
Audit Log Details: Logs capture date and time, user account, source IP address, event details, and success or failure of the event.
DE.AE-3; CIS
Control 8
Audit Mechanism Protection:
Administrators cannot disable the audit mechanism.
PR.PT-1; CIS
Control 8.8
Audit Log Integrity: Audit logs are protected from unauthorized access and alteration (e.g., sent to a SIEM in addition to local storage).
Control 8.5
Audit Log Tamper Prevention: Users and administrators are prevented from modifying, deleting, or adding log entries.
Control 8.5
Intrusion Detection and Prevention:
The solution is protected using
Intrusion Detection and Prevention
Systems (IDS/IPS).
DE.CM-1; CIS
Control 9
Protection Against DDoS Attacks: The solution is protected against Distributed
Denial of Service (DDoS) attacks.
PR.DS-5; CIS
Control 9
Security Event Notifications: The solution generates outbound alerts and notifications. Explain the data contained in these messages (e.g., DE.DP-5; CIS
Control 8.7
Functionality
Meet
(Y/C/M/N) Detailed Explanation References email alerts, automated reports, SNMP v.3 traps).
E. Software and Configuration Management
Number Functionality
Meet
(Y/C/M/N) Detailed Explanation References
Microsoft Enterprise Access
Model Compliance: The solution can be installed and maintained according to the Microsoft
Enterprise Access Model.
PR.IP-1; CIS
Control 4
Software Version Control: The solution prevents outdated software versions from accessing the Database Management
System (DBMS).
PR.IP-1; CIS
Control 2.3
Patch Management: The solution is regularly patched with appropriate security patches within specified timeframes:
- Critical patches: within 14 days of release
- High patches: within 30 days
- Medium and Low patches: within
90 days
PR.IP-12; CIS
Control 7
Vulnerability Management:
Regular vulnerability scans are performed (e.g., monthly) using tools like Nessus or Qualys.
Reports are shared upon request.
Control 7
Application Security Testing:
Regular application vulnerability scans are conducted using tools like WebInspect, Veracode, or
AppScan. Dynamic and Static
Application scans are preferred.
Control 18
Change Control Processes:
Application vulnerability scanning
(e.g., PCI DSS, OWASP Top 10)
PR.IP-3; CIS
Control 6.1 https://docs.microsoft.com/en-us/windows-server/identity/securing-privileged-access/securing-privileged-access-reference-material https://docs.microsoft.com/en-us/windows-server/identity/securing-privileged-access/securing-privileged-access-reference-material
Functionality
Meet
(Y/C/M/N) Detailed Explanation References is performed prior to production migration of changes. Medium, High, and Critical vulnerabilities are remediated before migration.
Reports are shared upon request.
F. Data Encryption and Transmission
Number Functionality
Meet
(Y/C/M/N) Detailed Explanation References
Data Encryption in Transit: Sensitive data is encrypted during transmission over the network using a minimum of TLS 1.2 with AES
PR.DS-2; CIS
Control 3.11
Data Encryption at Rest: Sensitive information is encrypted while in storage using a minimum of AES
PR.DS-1; CIS
Control 14
Encryption over External Networks:
Sensitive information is encrypted for transmission over external networks using a minimum of AES
Control 3.11
G. Cloud Hosting and Infrastructure Security
Number Functionality
Meet
(Y/C/M/N) Detailed Explanation References
Data Center Compliance: If cloud-hosted, the solution is hosted in an audited data center complying with
ISO/IEC 27001, SOC 2 Type II, StateRAMP, or FedRAMP standards.
Provide the latest audit report.
PR.AC-5;
StateRAMP;
FedRAMP
Employee Access Controls: Controls prohibit hosting employees or third-party personnel from accessing, viewing, or modifying customer confidential data. Describe controls used, including encryption and key storage mechanisms.
PR.AC-5; CIS
Control 14
Functionality
Meet
(Y/C/M/N) Detailed Explanation References
High Availability and Failover: The solution is highly available with active-active or active-passive failover between geographically diverse data centers.
PR.DS-4; CIS
Control 12
Data Residency: System and data are physically located within the
Continental United States.
PR.DS-5
Network Accessibility: System is accessible from the County's network and proxy infrastructure.
PR.AC-3
Session Encryption: All sessions are encrypted from initiation to termination using validated encryption ciphers (TLS 1.2 or higher).
Control 3.11
Regular Vulnerability Scanning:
Monthly vulnerability scans are performed using tools like Nessus, Tenable, or Qualys. Reports will be shared with the County if requested.
Control 7
API Security: APIs use API key security (X-API-Key) or demonstrate alternate security controls.
PR.AC-1; CIS
Control 14.8
H. Software Integrity and Secure Development
Number Functionality
Meet
(Y/C/M/N) Detailed Explanation References
Prevent Changes to Records:
Users, developers, DBAs, or administrators cannot alter posted, NIST CSF PR.IP-
4; CIS Control 5
Functionality
Meet
(Y/C/M/N) Detailed Explanation References completed, or closed transaction records.
Rollback Processes: Rollback processes are incorporated into the database for all critical transactions.
4; CIS Control
10.5
Outdated Software Access
Prevention: The solution prevents outdated software versions from accessing the DBMS.
1; CIS Control 2.3
I. Artificial Intelligence (AI) and Machine Learning (ML) Controls
• Note: This section addresses security controls specific to systems utilizing Artificial Intelligence (AI) and Machine Learning (ML). These controls ensure the trustworthy, secure, and ethical use of AI/ML technologies. Please refer to NIST.AI.600-1.pdf for detailed guidance.
Functionality
Number Functionality
Meet
(Y/C/M/N) Detailed Explanation References
AI Governance and Oversight: The organization has established governance structures and policies for
AI/ML system development and deployment, including defined roles and responsibilities.
NIST.AI.600-
1.pdf; NIST AI
RMF GOV
AI Risk Management Framework
Application: The organization applies a risk management framework specific to
AI/ML systems to identify, assess, and mitigate risks throughout the AI lifecycle.
RMF MAP
Data Quality and Integrity for AI/ML:
Data used for training and testing AI/ML models is assessed for quality, relevance, and potential biases.
Processes ensure data integrity and accuracy.
RMF MEASURE
Model Transparency and Explainability:
AI/ML models are designed to be interpretable, with mechanisms to explain model decisions to stakeholders as appropriate.
RMF MANAGE
Security of AI/ML Systems: The AI/ML systems are protected against adversarial attacks (e.g., data poisoning, model inversion). Security controls safeguard AI assets and processes.
RMF SECURE
Functionality
Meet
(Y/C/M/N) Detailed Explanation References
Privacy Protection in AI/ML: Measures protect personal and sensitive information used in AI/ML systems, including compliance with data protection regulations and techniques like differential privacy.
RMF PROTECT
Fairness and Bias Mitigation: The organization identifies and mitigates biases in AI/ML models to promote fairness and prevent discrimination against any group.
RMF MEASURE
Monitoring and Maintenance of AI/ML
Systems: Continuous monitoring detects performance degradation, biases, or security incidents in AI/ML systems, with processes for model updates.
RMF MANAGE
Ethical Considerations and Compliance:
The organization adheres to ethical guidelines and legal requirements related to AI/ML, including transparency and accountability.
RMF GOV
Third-Party AI Components
Management: If using third-party AI/ML components or services, the organization ensures they meet the same security and ethical standards, including due diligence.
RMF GOV
Incident Response for AI/ML Systems:
The organization has incident response plans that include scenarios specific to
AI/ML systems, such as model failures or adversarial attacks.
RMF RESPOND
Functionality
Meet
(Y/C/M/N) Detailed Explanation References
Documentation and Reporting of AI/ML
Models: Comprehensive documentation of AI/ML models, including design decisions, training data, and testing results, is maintained and available for review.
RMF GOV
J. Software Bill of Materials (SBOM)
• AGPL POLICY WARNING: Code licensed under the GNU Affero General Public License (AGPL)
MUST NOT be used at Miami-Dade County.
Functionality
Number Functionality
Meet
(Y/C/M/N) Detailed Explanation References
SBOM Creation and Maintenance:
An SBOM must be created and maintained for all software projects, listing all third-party libraries and their associated metadata.
NIST SP 800-
161; CIS
Control 2.3
SBOM Submission Formats:
SBOMs must be submitted in
CycloneDX or SPDX formats. If these formats are unavailable, a fillable form template must be used to capture the required information.
At a minimum, the following details must be documented for each third-party library: Software Component or Library Name, Author, Version, Last Updated Date, Website, and
License.
Control 2.3
Regular SBOM Updates and
Reviews: The SBOM must be updated and reviewed regularly to ensure accuracy and completeness.
Control 2.3
Licensing Compliance Review: A licensing compliance review must be conducted, and the results must be signed by the developer's management before any third-party library is used in production.
ID.SC-3; ISO
27001
A.18.1.3
General Comments
• Please provide any additional information or clarifications below:
Notes:
• Applicability of Sections: Ensure you complete all sections relevant to your solution, including the new
Software Bill of Materials (SBOM) section.
• AGPL Policy Compliance: Under no circumstances should code licensed under the GNU Affero
General Public License (AGPL) be used in solutions provided to Miami-Dade County.
• Compensating Controls: For any "N" responses, please provide detailed explanations of compensating controls or alternative solutions in the 'Detailed Explanation' column.
• Evidence and Documentation: Please provide supporting documents where applicable, such as SBOM files, policy documents, certificates, audit reports, or AI/ML governance frameworks.
• Priority Levels: Some functionalities may be marked as High Priority. These are critical requirements that must be met for compliance.
• Data Protection Regulations: Ensure compliance with relevant data protection laws such as GDPR, CCPA, or other applicable regulations.
• Ethical AI Practices: Adherence to ethical guidelines in AI development and deployment is crucial for maintaining trust and compliance.
• SBOM Importance: Maintaining an accurate and up-to-date SBOM is essential for supply chain security and vulnerability management.
Glossary of Terms and Acronyms
• 2FA: Two-Factor Authentication
• ADFS: Active Directory Federation Services
• AES: Advanced Encryption Standard
• AGPL: GNU Affero General Public License
• AI: Artificial Intelligence
• AI RMF: Artificial Intelligence Risk Management Framework
• API: Application Programming Interface
• CJIS: Criminal Justice Information Services
• CIS Controls: Center for Internet Security Controls
• CISO: Chief Information Security Officer
• CycloneDX: A software bill of materials (SBOM) standard designed for use in application security contexts and supply chain component analysis
• DDoS: Distributed Denial of Service
• DBA: Database Administrator
• DBMS: Database Management System
• EDR: Endpoint Detection and Response
• EOL: End of Life
• FedRAMP: Federal Risk and Authorization Management Program
• FIDO2: Fast IDentity Online 2, an authentication standard that enables phishing-resistant authentication methods
• FIM: Federated Identity Management
• gMSA: Group Managed Service Accounts
• Group Managed Service Accounts (gMSA): A feature in Microsoft Windows Server that provides automatic password management and simplified Service Principal Name (SPN) management for service accounts running on multiple servers. gMSAs allow services to share a common identity across multiple servers or instances, enhancing security and ease of management.
• HIPAA: Health Insurance Portability and Accountability Act
• HR: Human Resources
• IDS/IPS: Intrusion Detection System/Intrusion Prevention System
• ISO/IEC 27001: International Organization for Standardization/International Electrotechnical Commission
27001
• MFA: Multi-Factor Authentication
• ML: Machine Learning
• NIST: National Institute of Standards and Technology
• NIST CSF: NIST Cybersecurity Framework
• OWASP: Open Web Application Security Project
• PCI DSS: Payment Card Industry Data Security Standard.
• PHI: Protected Health Information
• PII: Personally Identifiable Information
• Phishing Resistant Authentication: Authentication methods designed to prevent phishing attacks by eliminating reliance on shared secrets (like passwords) that can be stolen or intercepted. This typically involves using cryptographic authentication techniques, such as hardware security keys compliant with
FIDO2/WebAuthn standards, certificate-based authentication, or biometric factors.
• RBAC: Role-Based Access Control
• RDBMS: Relational Database Management System
• SAML: Security Assertion Markup Language
• SBOM: Software Bill of Materials
• SIEM: Security Information and Event Management
• SHA: Secure Hash Algorithm SHA-256 or better is required.
• SNMP: Simple Network Management Protocol. SNMP v.3 or better is required.
• SOC 2: System and Organization Controls 2
• SOX: Sarbanes-Oxley Act
• SPDX: Software Package Data Exchange, an open standard for communicating software bill of material information
• SSAE 16: Statement on Standards for Attestation Engagements No. 16
• SSO: Single Sign-On
• StateRAMP: State Risk and Authorization Management Program
• TLS: Transport Layer Security
References
• NIST SP 800-161: Supply Chain Risk Management Practices for Federal Information Systems and
Organizations o Provides guidance on identifying, assessing, and mitigating risks throughout the supply chain at all levels of the organization.
o Link to NIST SP 800-161
• CIS Controls v8: Center for Internet Security Critical Security Controls Version 8 o Control 2.3: Addressing software inventory and control.
• ISO/IEC 27001 A.18.1.3: Protection of records o Ensures records are protected from loss, destruction, falsification, and unauthorized access or release.
• NIST.AI.600-1.pdf: NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0) o Provides guidelines for managing risks associated with AI systems to promote trustworthy and responsible AI.
o Link to NIST AI RMF 1.0 https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/final https://www.nist.gov/itl/ai-risk-management-framework
Submission Guidelines
• Deadline for Submission: [Insert Deadline]
• Preferred Format: Please return the completed matrix in a machine-readable format (e.g., Word or
PDF).
• Contact for Queries: [Insert Contact Name and Email]
• Confidentiality Assurance: Your responses will be treated confidentially and used solely for the purpose of assessing the security controls for the proposed system.
Vendor Declaration
• I hereby attest that the information provided in this security matrix is accurate and complete to the best of my knowledge.
• Authorized Signature:
• Name:
• Title:
• Date:
| attachment A - information technology security matrix |
| version 112024 rev. A |
File details come from the government source that posted it. Updated .