ATTACHMENT_4_CLOUD_INFO.pdf
PDF 31 KB Posted
- Attached to
- Grades K-5 Science Curriculum Materials for DoDEA Schools Worldwide Federal contract opportunity
- Solicitation number
- HE1254-17-R-0001
- Issued by
- Department of Defense Education Activity
About this file
Attachment 4: DoDEA Cloud Vendor Information Collection
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment_0004.pdf | ||
| Amendment_0003.pdf | ||
| Amendment_02.pdf | ||
| Att_7-_Amended_Pricing_Schedule.xlsx | XLSX spreadsheet | |
| Attachment_6_Quantico_Base_map.pdf | ||
| Amendment_0001_K-5_Science_HE1254-17-R-0001.pdf | ||
| RFP_HE1254-17-R-0001_K-5_Science.pdf | ||
| ATTACHMENT_2_PP_Part_1.pdf | ||
| ATTACHMENT_5_GPAT.pdf | ||
| Att_1_-_Pricing_Schedule_K-5_Science_2-1-17.xlsx | XLSX spreadsheet | |
| ATTACHMENT_3_PP_Part_2.pdf |
Show all 11
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT 4: DoDEA CLOUD VENDOR INFORMATION COLLECTION
Data Collection and Distribution
1. Does the vendor use the Privacy Impact Assessment to identify all data that the system provides the ability to collect, whether or not collection is required, per http://www.dodea.edu/upload/pia_DPS.pdf?
2. What, if any, data is collected by third parties (e.g., via cookies, plug-ins, ad networks, web beacons etc.)?
3. Does the vendor service meet the requirements for any of the following?
a. Children's Online Privacy Protection Act (COPPA), per http://www.coppa.org/coppa.htm
b. Family Educational Rights and Privacy Act (FERPA), per http://www2.ed.gov/policy/gen/guid/fpco/ferpa/index.html
c. Children's Internet Protection Act (CIPA), per http://www.fcc.gov/guides/childrens-internet-protection-act
System Management and Security
1. How is system penetration testing, vulnerability management, and intrusion prevention managed?
2. Are software updates and patches routinely or automatically on all servers?
3. Are software and hardware lifecycle management procedures in place to replace end-of-life products?
4. Is the system, including server(s) and network devices located in secure facilities under controlled circumstances (e.g., authorized personnel access lists, ID cards, entry logs)?
5. Are server(s) and network devices located in an environmentally controlled facility?
6. Are backups performed and tested regularly and stored off-site?
7. How are these backups secured? Disposed of?
Data Storage and Data Access
1. Where will information be stored and how is data “at rest” protected (i.e., data in the data center)?
a. Will any data be stored outside the United States?
b. Is all or some data at rest encrypted (e.g. just passwords, passwords and sensitive data, all data) and what encryption method is used?
2. How will the information be stored and transmitted?
a. How is data and access separated from other customers?
b. How does the provider protect data in transit, e.g., Secure Socket Layer (SSL), hashing, etc.?
3. Who has access to information stored or processed by the provider?
a. What process is in place to ensure vendor access to school records is limited to when necessary to provide the service to the school?
b. Are background checks completed on personnel with administrative access to servers, applications and customer data?
c. Does the vendor subcontract any functions, such as analytics?
d. What is the process for authenticating callers and resetting access controls, as well as establishing and deleting accounts?
e. How are third party government or law enforcement data requests managed?
Data and Metadata Retention
1. How does the vendor assure the proper management and disposal of data?
2. How is data deleted?
a. Is data deleted on a specific schedule or only on termination of contract?
b. What is the process to request the deletion of school data?
3. What is the process to request school data?
Development and Change Management Process
1. Are there standardized and documented procedures for coding, configuration management, patch installation, and change management for all servers and network devices involved in delivery of contracted services?
2. Are practices regularly audited?
3. What is the customer notification process for changes that will affect the security, storage, usage, or disposal of any information received or collected directly from the school?
4. Availability
a. Is there a guaranteed service level? If so describe?
b. What is the backup-and-restore process in case of a disaster?
c. What protection is in place against denial-of-service attack?
5. Audits and Standards
a. What is the process for the school to audit the security and privacy of records?
b. Are the security operations reviewed or audited by an outside group?
c. What security standard such as the International Organization for Standardization (ISO) and Payment Card
Industry Data Security Standards (PCI DSS)?
Test and Development Environments
1. Will “live” student data be used in non-production (e.g., test or development, training) environment?
2. Are these environments secure to the same standard as production data?
Data Breach, Incident Investigation and Response
1. What is the process to manage a data breach in vendor systems?
2. What is the process to perform security incident investigations or e-discovery?
3. Regarding incident investigation, what is the process to request log data for end user, administrative and maintenance activity?
(End of Attachment 4)
File details come from the government source that posted it. Updated .