HE1254-21-R-0002 Attachment 4 DoDEA Cloud Questionnaire.docx

DOCX document 25 KB Posted

Attached to
K-5 Social Studies Curriculum Resources Federal contract opportunity
Solicitation number
HE1254-21-R-0002
Issued by
Department of Defense Education Activity

View the file

Other files for this federal contract opportunity

Other files attached to K-5 Social Studies Curriculum Resources, newest first.
File Type Posted
HE1254-21-R-0002 Amend 02.pdf PDF
HE1254-21-R-0002 Attachment 5 QA 12.14.2020.pdf PDF
HE1254-21-R-0002 Amend 01.pdf PDF
HE1254-21-R-0002 Attachment 1 Pricing Sheet Amend 01.xlsx XLSX spreadsheet
HE1254-21-R-0002 Attachment 5 QA.pdf PDF
HE1254-21-R-0002 K-5 Social Studies Curriculum Resources.pdf PDF
HE1254-21-R-0002 Attachment 3 Terms of Service Addendum.docx DOCX document
HE1254-21-R-0002 Attachment 2 GPAT.docx DOCX document
HE1254-21-R-0001 Attachment 1 - Pricing Sheet.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

HE1254-21-R-0002 – Attachment 4 – DoDEA Cloud Questionnaire DoDEA Cloud Questionnaire Directions

The Department of Defense Education Activity (DoDEA) must review each vendor’s cloud-based solution individually to determine if it is compatible with DoD and DISA’s guidelines. Your answers to this questionnaire will enable us to do that evaluaton quickly and effectively. Please provide the point(s) of contact should DoDEA have questions about your response. Please note:

· Any proprietary or sensitive security information provided in response to this questionnaire will be protected and not shared outside of the US Government.

· Links to webpages will be considered an unacceptable anwer to the question but can be provided as supporting documantion.

· Answering “N/A” or “Not Applicable” alone will be considered an unacceptable response.

Client Systems Software and Configuration

1. Is any software required for this service, e.g., software that must be installed on DoDEA computers to include browser extensions and/or plugins? Has this software been made available for this review?

2. Is this a standalone or networked application? Will DoDEA need to stand up servers to support this application?

3. Are there any configurations or changes that DoDEA must implement to any of its computers, browsers or firewalls to utilize this service?

Privacy Information Data Collection and Distribution

1. What personally identifiable and sensitive information is collected by this service?

2. What, if any, personally identifiable and sensitive information is collected by third parties or by external business partners (e.g., via cookies, plug-ins, ad networks, web beacons etc.)?

3. Is any DoDEA data provided to third parties or external business partners for any purpose? If yes provide a list of all third-party or external business partner recipients.

4. Do third parties or external business partner recipients of DoDEA data adhere to the same policies and processes to protect DoDEA data?

5. Describe the process to opt-out of any transfers of DoDEA data to third parties or external business partner recipients.

6. Which, if any, of the following requirements does your cloud service meet:

a. Children's Online Privacy Protection Act (COPPA), per https://www.congress.gov/bill/105th-congress/senate-bill/2326/text

b. Privacy Act of 1974, per https://www.justice.gov/opcl/overview-privacy-act-1974-2020-edition

c. Children's Internet Protection Act (CIPA), per http://www.fcc.gov/guides/childrens-internet-protection-act?

System Management and Security

1. How is system penetration testing, vulnerability management, and intrusion prevention managed?

2. How often is penetration testing performed against the application?

3. Are software updates and patches routinely or automatically installed on all servers?

4. Are software and hardware lifecycle management procedures in place to replace end-of-life products?

5. Is the system, including its server(s) and network devices, located in secure facilities under controlled circumstances (e.g., authorized personnel access lists, ID cards, entry logs)?

6. Are server(s) and network devices located in an environmentally controlled facility?

Data Storage, Retention, and Access

1. Where will information be stored? Will any data be stored outside the United States?

2. How will the transfer of any Sensitive, Confidential data including but not limited to PII data be transferred?

3. How is information stored and transmitted?

a. How does the provider protect data at rest, i.e., data in the data center? What data is encrypted: passwords, privacy information, etc.?

b. Is data secured with unique encryption keys for each customer on systems hosting multiple customers? If no unique encryption key is used provide a detailed description/artifact that explains how the database is encrypted and stored and in securing DoDEA's data between tenants.

c. How is data protected in transit, e.g., secure socket layer (SSL), hashing, etc.?

4. Who has access to information stored or processed by the provider?

5. Are background checks completed on personnel with access to servers, applications and customer data? If so, describe type and frequency.

6. What is the process for authenticating callers and resetting access controls, as well as establishing and deleting accounts?

7. How is school/system data deleted—on a specific schedule or only upon contract termination?

Development and Change Management Process

1. Are there standardized and documented procedures for coding, configuration management, patch installation, and change management for all servers and network devices involved in delivery of contracted services?

2. What is the customer notification process for any changes made to corporate policies for data protection?

3. Audits and Standards

a. What is the process for DoDEA to audit the security and privacy of records?

b. Are the security operations reviewed or audited by an outside group? If so, what is the frequency? If not, how are security operations reviewed or audited?

c. What security standard is followed, e.g., the International Organization for Standardization (ISO), National Institute of Standards and Technology (NIST) and Payment Card Industry Data Security Standards (PCI DSS)?

Test and Development Environments

1. Will “live” student/privacy data be used in a non-production environment, e.g., in testing, development, or training)? If so, are these environments secure to the same standard as production data?

Data Breach, Incident Investigation and Response

1. Availability

a. Is there a guaranteed service level? If so describe?

b. What is the backup-and-restore process in case of a disaster?

c. What protection is in place against denial-of-service attack?

2. What is the process in managing a data breach?

3. What is the process to perform security incident investigations or e-discovery?

DoDEA Cloud Questionnaire 2 Revised 31 July 2020

File details come from the government source that posted it. Updated .