GSS25942-PENSION_IVV-appB1.pdf

PDF 641 KB Posted

Attached to
Independent Verification and Validation - Pension Modernization State and local contract opportunity
Solicitation number
GSS25942-PENSION_IVV
Issued by
Kent County, Delaware

About this file

This document is an enterprise policy and terms and conditions agreement from the State of Delaware's Department of Technology and Information (DTI) governing cloud services and data usage. The policy, identified as document SE-CLD-001 Revision 7, establishes comprehensive guidelines for state organizations utilizing offsite or cloud facilities and services, including Infrastructure-, Platform-, and Software-as-a-Service (XaaS). It applies to all users of the State of Delaware's communications and computing resources, with specific requirements for new contracts and amendments involving cloud services and data sharing.

The policy mandates stringent data protection measures, including encryption of non-public data in transit and at rest, using validated cryptography standards. Service providers must maintain cyber security liability insurance with coverage levels ranging from $2 million to $100 million, depending on the number of Personally Identifiable Information (PII) records involved. The document outlines detailed requirements for data ownership, usage, location, breach notification, background checks, and contract audits. Providers must ensure data security, limit unauthorized access, and have protocols for secure data disposal upon contract termination. The policy was last reviewed on 4/14/2023 and is designed to mitigate risks associated with entrusting the state's computing operations and sensitive data to third-party service providers.

View the file

Other files for this state and local contract opportunity

Other files attached to Independent Verification and Validation - Pension Modernization, newest first.
File Type Posted
GSS25942-PENSION_IVV-appC.pdf PDF
GSS25942-PENSION_IVV-rfp.pdf PDF
GSS25942-PENSION_IVV-appE.xlsx XLSX spreadsheet
GSS25942-PENSION_IVV-appD.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Doc Ref Number: SE-CLD-001 Revision Number: 7

Document Type: Enterprise Policy Page: 1 of 6

Policy Title: Terms and Conditions Governing Cloud Services and Data Usage

Delivering Technology that Innovates

STATE OF DELAWARE

DEPARTMENT OF TECHNOLOGY AND INFORMATION

801 Silver Lake Blvd.

Dover, Delaware 19904

Synopsis: This policy provides guidance for State of Delaware organizations to utilize offsite or cloud facilities and services, including hosting and computing (XaaS: e.g, Software-, Infrastructure-, Platform-, etc., as-a-Service). Additionally, it addresses situations when State data is used by an entity for audit, research, or other purposes.

Authority: Title 29 Chapter 90C Delaware Code, §9004C General Powers, statewide and agency technology solutions, policies, standards and guidelines, including as recommended by the Technology Investment

Applicability: This policy is applicable to all users of the State of Delaware communications and computing resources. DTI is an Executive Branch Agency and has no authority over the customers in Legislative and Judicial Branches, as well as Local Education Agencies, and other Federal and Local Government entities that use these resources.

However, all users, including these entities, must agree to abide by all policies, standards promulgated by DTI as a condition of access and continued use of these resources.

Effective: 5/15/2013 Reviewed: 4/14/2023

Approved By: Chief Information Officer Sponsor: Chief Security Officer

TABLE OF CONTENTS

Section Page

I. Policy 2

II. Definitions 4

III. Development and Revision History 5

IV. Approval Signature Block 6

V. Listing of Appendices 6

Document Type: Enterprise Policy Page: 2 of 6

Policy Title: Terms and Conditions Governing Cloud Services and Data Usage

Delivering Technology that Innovates

STATE OF DELAWARE

DEPARTMENT OF TECHNOLOGY AND INFORMATION

801 Silver Lake Blvd.

Dover, Delaware 19904

I. Policy

EXECUTIVE SUMMARY

Cloud and offsite hosting and services (contracted Xaas: Infrastructure-, Platform-, Software-as-a-Service) offer credible alternatives to traditional IT delivery models.

Contracted XaaS can provide benefits such as rapid delivery, enhanced scalability, development agility and new funding models.

PURPOSE

This policy establishes the terms and conditions for contracted XaaS and establishes terms and conditions for data usage. All IT-related RFPs, Contracts, etc. and data sharing engagements that may involve offsite hosting must abide by this policy. The terms and conditions set forth in this policy will help to organizations by mitigating computing operations and data to a third party.

POLICY STATEMENT

New contracts and amendments to contracts with service providers, as well as agreements regarding others (including but not limited to audit, research, etc.), are expected to include a cloud services and data usage signed agreement, as applicable, approved by DTI. When it applies, the Terms and Conditions Governing Cloud Services and Data Usage policy requires a signed Terms and Conditions Governing Cloud Services and Data Usage Agreement. Contracts or other agreements already in force will be expected to include the applicable signed agreements approved by DTI at the next renewal or revision date. The following standard agreement is available:

Terms and Conditions Governing Cloud Services and Data Usage Agreement (PDF)

Nothing in this policy statement or its related agreement precludes state agencies from imposing their own industry-specific terms and conditions as their business might require, above and beyond those promulgated by DTI.

Document Type: Enterprise Policy Page: 3 of 6

Policy Title: Terms and Conditions Governing Cloud Services and Data Usage

Delivering Technology that Innovates

STATE OF DELAWARE

DEPARTMENT OF TECHNOLOGY AND INFORMATION

801 Silver Lake Blvd.

Dover, Delaware 19904

IMPLEMENTATION RESPONSIBILITY

DTI and/or the technical staff will implement this policy during the course of normal business activities, including project execution and the design, development, or support of systems.

Service providers should be familiar with, and adhere to, security guidelines closely aligned with standardized industry approaches to assessment, documentation, monitoring, and controls for cloud products and services, such as those promulgated by the Federal Risk and Authorization Management Program (FedRAMP), Cloud Security Alliance (CSA), the National Institute of Standards and Technology (NIST), and other accreditation authorities as these become recognized by the industry.

ENFORCEMENT and WAIVER

DTI will enforce this policy during the course of normal business activities, including review of proposed projects and during the design, development, or support of systems. This policy may also be enforced by others during the course of their normal business activities, including contract execution, review or amendment, audits, and design reviews.

Cyber Security Liability Insurance

The State of Delaware places paramount importance on protection of sensitive Personally Identifiable Information (PII) or otherwise confidential information as defined by 6 Del. C. §1202C (15) and §12B-101(7)a, and as noted below under Section II Definitions.

In accordance with Terms and Conditions Governing Cloud Services and Data Usage Agreement Item 5, non-public state data shall be encrypted in transit and, for PII data, at rest. A service provider will employ validated cryptography standards as specified in National Institute of Standards and Technology FIPS140-2 Security Requirements. When the Service Provider cannot offer encryption at rest, they must maintain, for the duration of the contract, cyber security liability insurance coverage for any loss resulting from a data breach. Such a liability protection policy shall comply with the requirements, incorporated by addendum to this policy (see Addendum 1: Cyber Security Liability Insurance Requirement).

Document Type: Enterprise Policy Page: 4 of 6

Policy Title: Terms and Conditions Governing Cloud Services and Data Usage

Delivering Technology that Innovates

STATE OF DELAWARE

DEPARTMENT OF TECHNOLOGY AND INFORMATION

801 Silver Lake Blvd.

Dover, Delaware 19904

In the event a service provider fails to keep in effect at all times the insurance coverage required by this provision, the State may, in addition to pursuing any other remedies available, terminate the contract upon the occurrence of such event, subject to the provisions of the contract.

If there is ambiguity or confusion regarding any part of this policy, seek clarification from the point of contact defined in the header of this policy.

II. Definitions

Personally Identifiable Information (PII)

1. Information or data, alone or in combination, that identifies or authenticates a particular individual. Such information or data may include, without limitation, Name, Date of birth, Full address (e.g. house number, city, state, and/or zip code), Phone Number, Passwords, PINs, Federal or state tax information, Biometric data, Unique identification numbers (e.g. driver's license number, social security number, credit or debit account numbers, medical records numbers), Criminal history, Citizenship status, Medical information, Financial Information, Usernames, Answers to security questions or other personal identifiers.

2.

under Delaware Code Title 6 § 12B-101 Title 6, §1202C, and

Title 29 §9017C or any other applicable State of Delaware or Federal law.

Document Type: Enterprise Policy Page: 5 of 6

Policy Title: Terms and Conditions Governing Cloud Services and Data Usage

Delivering Technology that Innovates

STATE OF DELAWARE

DEPARTMENT OF TECHNOLOGY AND INFORMATION

801 Silver Lake Blvd.

Dover, Delaware 19904

III.Development and Revision History

Date Revision 5/15/2013 Rev 0 Initial version 8/27/2014 Rev 1 Updated version 11/17/2014 Rev 2 Updated version 11/23/2015 Rev 3 -insured list.

3/1/2016 Rev 4 - Added Tiered Coverage Schedule. Added PII definition. Adjusted

Ponemon value. Updated link for The Center for Digital Government 2014 study of Cloud Security Procurements.

10/10/2016 Rev 5 - Added language and references to State standards in the Implementation Responsibility section.

2/1/2018 Rev 5 - Added language and references to State standards in the Implementation Responsibility section.

6/18/2018 Rev 6 - Revised policy titles and agreement references. Added language and references to new Data Usage Terms and Conditions Policy, as well as to State standards in the Implementation Responsibility section;

revised DelCode references with respect to definitions of Personally Identifiable Information (PII); moved information regarding Cyber Liability Insurance Requirement to be incorporated by Addendum 1.

4/14/2023 Rev 7 Revised the wording to reflect the consolidated policy and agreement documents.

IV. Approval Signature Block

V.

Name & Title:

State Chief Information Officer

Date

Document Type: Enterprise Policy Page: 6 of 6

Policy Title: Terms and Conditions Governing Cloud Services and Data Usage

Delivering Technology that Innovates

STATE OF DELAWARE

DEPARTMENT OF TECHNOLOGY AND INFORMATION

801 Silver Lake Blvd.

Dover, Delaware 19904

Listing of Appendices

APPENDIX 1 - CYBER SECURITY LIABILITY INSURANCE REQUIREMENTS

Issued by an insurance company acceptable to the State of Delaware and valid for the entire term of the contract, inclusive of any term extension(s).

Liability limits will be calculated based on the maximum system record count over the life of the contract and the Ponemon Institute average Public Sector Breach cost per record as published in the most recent Cost of Breach Study (e.g., 2017, $141). Refer to the Tiered Coverage Schedule below.

Tiered Coverage Schedule

Level Number of PII records Level of cyber liability insurance required

(occurrence = data breach) 1 1-10,000 $2,000,000 per occurrence 2 10,001 50,000 $3,000,000 per occurrence 3 50,001 100,000 $4,000,000 per occurrence 4 100,001 500,000 $15,000,000 per occurrence 5 500,001 1,000,000 $30,000,000 per occurrence 6 1,000,001 10,000,000 $100,000,000 per occurrence

Shall include, but not be limited to, coverage for liabilities arising out of premises, operations, independent contractors, products, completed operations, and liability assumed under an insured contract.

At a minimum, the policy must include third party coverage for credit monitoring; notification costs to data breach victims; and regulatory penalties and fines.

Shall apply separately to each insured against whom claim is made or suit is

Shall include a provision requiring that the policy cannot be cancelled without thirty days written notice to the State Chief Information Officer.

The Service Provider shall be responsible for any deductible or self-insured retention contained in the insurance policy.

The coverage under the policy shall be primary, and not excess, to any other insurance carried by the Service Provider.

The State of Delaware shall not be a named or additional insured under the policy.

PUBLIC AND NON-PUBLIC DATA OWNED BY THE STATE OF DELAWARE

State of Delaware Terms and Conditions Governing Cloud Services and Data Usage Agreement

Contract/Agreement # ______________________________________________________________________, Appendix ____ between State of Delaware and _______________________________________________________ dated __________

This document shall become part of the final contract.

Form Revision Date: 8/21/23

STATE OF DELAWARE

DEPARTMENT OF TECHNOLOGY AND INFORMATION

801 Silver Lake Blvd., Dover, Delaware 19904

Public Data

Non Public Data

1 Data Ownership: The State of Delaware shall own all right, title and interest in its data that is related to the services provided by this contract. The PROVIDER shall not access State of Delaware user accounts, or State of Delaware data, except (i) in the course of data center operations, (ii) in response to service or technical information obtained or generated by the PROVIDER under this contract shall become and remain property of the State of Delaware.

2 Data Usage: The PROVIDER shall comply with the following conditions. At no time will any information, belonging to or intended for the State of Delaware, be copied, disclosed, or retained by PROVIDER or any party related to PROVIDER for subsequent use in any transaction. The PROVIDER will take reasonable steps to limit the use of, or disclosure of, and requests for, confidential State data to the minimum necessary to accomplish the intended purpose under this agreement. PROVIDER may not use any information collected in connection with the service issued from this proposal for any purpose other than fulfilling the service.

Terms and Conditions Governing Cloud Services and Data Usage Policy), privacy, and sensitive data shall be an integral part of the business activities of the PROVIDER to ensure that there is no inappropriate or unauthorized use of State of Delaware information at any time. The PROVIDER shall safeguard the confidentiality, integrity, and availability of State information. No party related to the PROVIDER or contracted by the PROVIDER may retain any data for subsequent use in any transaction that has not been expressly authorized by the State of Delaware.

3 Termination and Suspension of Service: In the event of termination of the contract, PROVIDER shall implement an orderly return of State of Delaware data in CSV, XML, or another mutually agreeable format.

The PROVIDER shall guarantee the subsequent secure disposal of State of Delaware data.

a) Suspension of services: During any period of suspension, contract negotiation, or disputes, the

PROVIDER shall not take any action to intentionally erase any State of Delaware data.

b) Termination of any services or agreement in entirety: In the event of termination of any services or agreement in entirety, the PROVIDER shall not take any action to intentionally erase any State of Delaware data for a period of ninety (90) days after the effective date of the termination. All obligations for protection of State data remain in place and enforceable during this 90-day period. After such 90-day period has expired, the PROVIDER shall have no obligation to maintain or provide any State of Delaware data and shall thereafter, unless legally or contractually prohibited, dispose of all State of Delaware data in its systems or otherwise in its possession. Within this 90-day timeframe, the PROVIDER will continue to secure and back up State of Delaware data covered under the contract.

c) Post-Termination Assistance: The State of Delaware shall be entitled to any post-termination assistance generally made available with respect to the Services unless a unique data retrieval arrangement has been established as part of the Service Level Agreement.

d) Secure Data Disposal: When non-public data is provided by the State of Delaware, the PROVIDER shall destroy all requested data in all of its forms (e.g., disk, CD/DVD, backup tape, paper). Data shall be permanently deleted, and shall not be recoverable, in accordance with National Institute of Standards and Technology (NIST) approved methods after ninety (90) days of the contract termination. The PROVIDER shall provide written certificates of destruction to the State of Delaware.

Contract/Agreement # ______________________________________________________________________, Appendix ____ between State of Delaware and _______________________________________________________ dated __________

This document shall become part of the final contract.

Form Revision Date: 8/21/23

STATE OF DELAWARE

DEPARTMENT OF TECHNOLOGY AND INFORMATION

801 Silver Lake Blvd., Dover, Delaware 19904

Public Data

Non Public Data

4 Data Location: The PROVIDER shall not store, process, or transfer any non-public State of Delaware data outside of the United States, including for back-up and disaster recovery purposes. The PROVIDER will permit its personnel and subcontractors to access State of Delaware data remotely only as required to provide technical or call center support.

5 Encryption: The PROVIDER shall encrypt all non-public data in transit regardless of the transit mechanism.

For engagements where the PROVIDER stores sensitive personally identifiable or otherwise confidential information, this data shall be encrypted at rest. The encryption shall be consistent with validated cryptography standards as specified in National Institute of Standards and Technology FIPS140-2, Security Requirements. The key location and other key management details will be discussed and negotiated by both parties. When the PROVIDER cannot offer encryption at rest, they must maintain, for the duration of the contract, cyber security liability insurance coverage for any loss resulting from a data breach in accordance with the Terms and Conditions Governing Cloud Services and Data Usage Policy.

6 Breach Notification and Recovery: The PROVIDER must notify the State of Delaware at eSecurity@delaware.gov immediately or within 24 hours of any determination of the breach of security as defined in 6 Del. C. §12B-101(2) resulting in the destruction, loss, unauthorized disclosure, or alteration of State of Delaware data. The PROVIDER shall send a preliminary written report detailing the nature, extent, and root cause of any such data breach no later than two (2) business days following notice of such a breach. The PROVIDER will continue to send any and all reports subsequent to the preliminary written report. The PROVIDER shall meet and confer with representatives of DTI regarding required remedial action in relation to any such data breach without unreasonable delay. If data is not encrypted (see CS3, below), Delaware Code (6 Del. C. §12B-100 et seq.) requires public breach notification of any incident resulting in the loss or unauthorized dis

Terms and Conditions Governing Cloud Services and Data Usage Policy) by PROVIDER or its subcontractors. The PROVIDER will assist and be responsible for all costs to provide notification to persons whose information was breached without unreasonable delay but not later than sixty (60) days after determination of the breach, except 1) when a shorter time is required under federal law; 2) when law enforcement requests a delay; or 3) reasonable diligence did not identify certain residents, in which case notice will be delivered as soon as practicable. All such communication shall be coordinated with the State of Delaware. Should the PROVIDER or its contractors be liable for the breach, the PROVIDER shall bear all costs associated with investigation, response, and recovery from the breach. This includes, but is not limited to, credit monitoring services with a term of at least three (3) years, mailing costs, website, and toll-free telephone call center services. The State will retain all determining authority for breach accountability and responsibility. The State of Delaware shall not agree to any limitation on liability that relieves the PROVIDER or its subcontractors from its own negligence, or to the extent that it creates an obligation on the part of the State to hold a PROVIDER harmless. The PROVIDER shall not issue a media notice without the approval of the State.

7 Background Checks: The PROVIDER must warrant that they will only assign employees and subcontractors who have passed a federally compliant (IRS Pub 1075 2.C.3) criminal background check. The background checks must demonstrate that staff, including subcontractors, utilized to fulfill the obligations of the contract, Contract/Agreement # ______________________________________________________________________, Appendix ____ between State of Delaware and _______________________________________________________ dated __________

This document shall become part of the final contract.

Form Revision Date: 8/21/23

STATE OF DELAWARE

DEPARTMENT OF TECHNOLOGY AND INFORMATION

801 Silver Lake Blvd., Dover, Delaware 19904

Public Data

Non Public Data have no convictions, pending criminal charges, or civil suits related to any crimes of dishonesty. This includes but is not limited to criminal fraud, or any conviction for any felony or misdemeanor offense for which incarceration for a minimum of one (1) year is an authorized penalty. The PROVIDER shall promote and maintain an awareness of the importance of securing the State's information among the employees and agents. Failure to obtain and maintain all required criminal history may be deemed a material breach of the contract and grounds for immediate termination and denial of further work with the State of Delaware.

8 Security Logs and Reports: The PROVIDER shall allow the State of Delaware access to system security logs that affect this engagement, its data, and or processes. This includes the ability for the State of Delaware to request a report of the records that a specific user accessed over a specified period of time.

9 Sub-contractor Flowdown: The PROVIDER shall with the security requirements stated herein.

10 Contract Audit: The PROVIDER shall allow the State of Delaware to audit conformance including contract terms, system security, and data centers, as appropriate. The State of Delaware may perform this audit or least thirty (30) days advance written notice and shall not unreasonably interfere with the business. In lieu of performing its own audit, the State may request the results of a third party audit from the PROVIDER or an attestation of compliance.

11 Cyber Liability Insurance: An awarded vendor unable to meet the Terms and Conditions Governing Cloud Services and Data Usage Policy requirement of encrypting PII at rest shall, prior to execution of a contract, present a valid certificate of cyber liability insurance at the levels indicated below. Further, the awarded vendor shall ensure the insurance remains valid for the entire term of the contract, inclusive of any term extension(s). Levels of cyber liability insurance required are based on the number of PII records anticipated to be housed within the solution at any given point in the term of the contract. Should the actual number of coverage is obtained (see table below). In the event that vendor fails to obtain sufficient coverage, vendor shall be liable to cover damages up to the required coverage amount.

Level Number of PII records Level of cyber liability insurance required

(occurrence = data breach) 1 1-10,000 $2,000,000 per occurrence 2 10,001 50,000 $3,000,000 per occurrence 3 50,001 100,000 $4,000,000 per occurrence 4 100,001 500,000 $15,000,000 per occurrence 5 500,001 1,000,000 $30,000,000 per occurrence 6 1,000,001 10,000,000 $100,000,000 per occurrence

Contract/Agreement # ______________________________________________________________________, Appendix ____ between State of Delaware and _______________________________________________________ dated __________

This document shall become part of the final contract.

Form Revision Date: 8/21/23

STATE OF DELAWARE

DEPARTMENT OF TECHNOLOGY AND INFORMATION

801 Silver Lake Blvd., Dover, Delaware 19904

The terms of this Agreement shall be incorporated into the aforementioned contract. Any conflict between this Agreement and the aforementioned contract shall be resolved by giving priority to this Agreement. By signing this Agreement, the PROVIDER agrees to abide by the following applicable Terms and Conditions [check one]:

FOR OFFICIAL 1-3 (Public Data) USE ONLY 1-11 (Non-Public Data)

Provider Name/Address (print):

Provider Authorizing Official Name (print):

Provider Authorizing Official Signature:

Date:

File details come from the government source that posted it. Updated .