Attachment_4_-_Cloud_Questionnaire.docx
DOCX document 24 KB Posted
- Attached to
- Interactive Technology and Professional Learning Federal contract opportunity
- Solicitation number
- HE1254-19-R-0009
- Issued by
- Department of Defense Education Activity
About this file
Attachment 4 - Cloud Questionnaire
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| HE1254-19-R-0009_-_0001_31Jul19_(SF_30).pdf | ||
| Attachment_4-Cloud_Questionnaire_(Rev1).docx | DOCX document | |
| Attachment_1-Pricing_Worksheet_(Rev1).xlsx | XLSX spreadsheet | |
| CONFOR~1.PDF | ||
| Attachment_3_-_Terms_of_Use.docx | DOCX document | |
| Attachment_1_-_Pricing_Worksheet.xlsx | XLSX spreadsheet | |
| Attachment_6_-_QASP.docx | DOCX document | |
| Attachment_2_-_GPAT.docx | DOCX document | |
| Attachment_5_-_Q&As_from_Synopsis.xlsx | XLSX spreadsheet | |
| HE1254-19-R-0009_ASD.pdf | ||
| Draft_PWS.pdf | ||
| Synopsis_29May2019.pdf |
Show all 12
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
HE1254-19-R-0009
Attachment 4
DoDEA Cloud Questionnaire Directions
· The Department of Defense Education Activity (DoDEA) must review each vendor’s cloud-based solution individually to determine if it is compatible with DoD’s guidelines. The answers you provide to this questionnaire will enable us to do that evaluaton quickly and effectively. Your assistance is much appreciated
· Please provide the point(s) of contact should DoDEA have questions about your response.
· Any proprietary or sensitive security information provided in response to this questionnaire will be protected and not shared outside of the U.S. Government.
Client Systems Software and Configuration Is any software required for this service, e.g., software that must be installed on DoDEA computers, to include browser extensions and plugins? Has this software been made available for this review?
To help ensure a consistent testing experience for students it is recommended that on devices that will be used for testing the HMH Data Manager secure browser is installed. Supported platforms include Windows, Mac, iPad and Chromebooks.
1. Is this a standalone or networked application? Will DoDEA need to stand up servers to support this application? This is a networked application. The DoDEA does not need to stand up servers to support the application.
1. Are there any configurations or changes that DoDEA must implement to either its computers or browsers to utilize this service? The IP addresses / URLs on the Data Manager IP Address and Port Listing document must not be blocked by firewall settings.
Privacy Information Data Collection and Distribution (Provided by Ray & Gene Mainen)
1. What personally identifiable and sensitive information is collected by this service? Students:
- Student name, school/building, demographics information and assessment scores are collected Administration:
- Administrators name, email address and school/building they are associated with are collected.
1. What, if any, personally identifiable and sensitive information is collected by third parties or external business partners (e.g., via cookies, plug-ins, ad networks, web beacons etc.)?
Internet Testing Solutions (ITS) ITS is used for the online testing of students. The following information is shared with ITS
· Student first name
· Student last name
· Assessment administered to student
· Internal ids representing the student, school and assessment
· Unscored student response
1. Is any DoDEA provided to third parties or external business partners for any purpose? If yes provide a list of all third-party or external business partner recipients Google
· Google Analytics is used to track user sessions. Data Manager adheres to Google’s privacy policy https://www.google.com/analytics/terms/us.html You will not and will not assist or permit any third party to, pass information to Google that Google could use or recognize as personally identifiable information.
· Internet Testing Solutions (ITS)- This site is equipped with a program that monitors traffic by automatically recording every visitor's host, browser type and/or IP address. This program tracks the number of times the site is hit, how many visitors come to the site, which parts of the site they frequent, and the length of time of each visit. This information does not contain personal information and is used to evaluate areas of interest and to improve the site and may be provided to third parties by this site or its affiliates.
· CTS – provides data management for Contractor. In the normal course of events, CTS does not access the DoDEA data. There is the possible situation in an emergency that CTS may access DODEA data to solve a problem.
1. Do third parties or external business partner recipients of DoDEA data adhere to the same policies and processes to protect DoDEA data? The third-party vendor is contractually obligated to essentially the same confidentiality standards as the Contractor
1. Describe the process to opt-out of any transfers of DoDEA data to third parties or external business partner recipients.
Based on the model offer for this product and the primarily management function of the third-party business partners, opt out of transfer to the specified third parties is not an option.
1. Which, if any, of the following requirements does your cloud service meet:
Contractor agrees to abide by federal, state, and local laws, regulations, and ordinances applicable to this project. They include but are not limited to the Information Assurance requirements defined by: The Family Educational Rights and Privacy Act ("FERPA…), 20 U.S.C. § 1232g, and its implementing regulations (34 C.F.R. part 99), the Children's Online Privacy Protection Act ("COPPA"), 15 U.S.C. § 6501-6505, and its implementing regulations (16 C.F.R. § 312, et seq.), the Protection of Pupil Rights Amendment, ("PPRA”) 20 U.S.C, § 1232(h) and its implementing regulations (34 C.F.R. § 98.1 et seq.). In the event of a conflict between FERPA and all other previously cited confidentiality laws, FERPA will control authority on controlling law.
System Management and Security
1. How is system penetration testing, vulnerability management, and intrusion prevention managed?
Penetration, vulnerability management and Intrusion prevention for AWS is described in the ISO 27001 Certification of AWS valid until 2019
1. Penetration / Static testing is conducted by the Contractor on Internet Testing Solutions on a regular basis.
1. Are software updates and patches routinely or automatically installed on all servers?
All updates and patches are routinely installed on all servers by CTS as data manager.
1. Are software and hardware lifecycle management procedures in place to replace end-of-life products? AWS manages the lifecycle in the Data Storage facility. Software that is approaching end of life is scheduled for updating as needed. Hardware is maintained by a 3rd party service provider who is contractually obligated to provide up to date equipment.
1. Is the system, including its server(s) and network devices, located in secure facilities under controlled circumstances (e.g., authorized personnel access lists, ID cards, entry logs)? Both AWS and ITS have servers and network devices in secure facilities
1. Are server(s) and network devices located in an environmentally-controlled facility?
Yes, all l AWS and ITS servers and network devices are in environmentally controlled facilities.
Data Storage, Retention, and Access
1. Where will information be stored? Will any data be stored outside the United States?
All data will be stored in the United States at AWS, in Virginia, USA and an undefined backup facility in the USA.
1. How is information stored and transmitted?
1. How does the provider protect data at rest, i.e., data in the data center? What data is encrypted: passwords, privacy information, etc.?
Password information is stored in a hashed and salted format using <SHA 256> hashing algorithm Customer data is encrypted at the database level using <AES 256> algorithm.
1. Is data secured with unique encryption keys for each customer on systems hosting multiple customers? Each customer is identified with a unique id which is not hashed but it is encrypted at rest just like any other data.
The platforms ensure that each customer can view only their specific data. Customer role based authentication is used to isolate customer accounts and ensure that users can view only their specific data e.g., Teachers can only see their assigned student data, Administrators at a school level can only access data pertaining to their school.
1. How does the provider protect data in transit, e.g., Secure Socket Layer (SSL), hashing, etc.?
All data sent via the open World Wide Web is sent using TLS or SFTP. Passwords are hashed as part of the process.
1. Who has access to information stored or processed by the provider? ITS, CTS
1. Are background checks completed on personnel with access to servers, applications and customer data? Yes
1. What is the process for authenticating callers and resetting access controls, as well as establishing and deleting accounts?
· Password resets and other administrative functions on users can only be executed by users within the same structure. That is, District Admins can administer users in their district, School Admins within their school, and Teachers within their class.
· Passwords are stored using an approved hashing algorithms, key length, and iterations as defined in the Cryptography and Encryption Standard. Note that encryption (as opposed to hashing) of passwords should be avoided, since the decryption key must be available at runtime, and does not typically present a strong control against the compromise of the plain-text password.
· When contacting the helpdesk to reset a password, the user must be authenticated
1. How is school/system data deleted? Is it deleted on a specific schedule or only at the termination of the contract?
At the termination of the contract, Contractor requires a written letter from DoDEA with instruction prior to transferring the data in a mutually agreeable format or to deleting the data. Deletion of data is done in compliance with NIST 800-88.
Development and Change Management Process Are there standardized and documented procedures for coding, configuration management, patch installation, and change management for all servers and network devices involved in delivery of contracted services? Yes
1. What is the customer notification process for any changes made corporate policies for data protection?
Substantive changes to HMH policies that impact our customers are communicated via advance notifications/banners on impacted platforms at the time of login. HMH will work in good faith with our customers to address any concerns that may arise because of such changes
1. Audits and Standards
1. What is the process for the school/system to audit the security and privacy of records? The DODEA customer must request such an audit through their designated HMH representative who will coordinate audit activities with the appropriate teams within HMH. Such audits are generally limited to no more than two business days in duration and may not occur more often than annually. Some data requested may need to be redacted/sanitized before being provided to protect the privacy of other Contractor customers.
1. Are the security operations reviewed or audited by an outside group? AWS ISO 27001- certified to 2019
1. What security standard is followed, such as the International Organization for Standardization (ISO) and Payment Card Industry Data Security Standards (PCI DSS)?
AWS certified to ISO 27001 Test and Development Environments
1. Will “live” student/privacy data be used in non-production (e.g., test or development, training) environment?
No De-identified data is used by HMH for research on product improvement.
1. If so, are these environments secure to the same standard as production data? N/A Data Breach, Incident Investigation and Response
1. What is the process to manage a data breach in vendor systems?
If unusual behavior of the network is observed, HMH has an Security Incident Process in place which defines all participant’s initial and ongoing responsibilities. The Process is led by the VP of Information Security or his/her designee. When an alert is escalated to Information Security Department an initial assessment is conducted. Based on the results of that assessment, a decision to conduct a broader investigation may be made. In such a case, the Information Security Department has at its disposal any corporate or external required identify, assess, contain, and remediate a breach or potential breach per the HMH Security Incident Response Policy and Process, key stakeholders such as the Legal Department, Corporate Communications, and senior executives are involved throughout the response to ensure that customer and corporate concerns are properly addressed.
1. Availability
1. Is there a guaranteed service level? If so describe? 99.5% up time
1. What is the backup-and-restore process in case of a disaster?
1. Data manager Backup-And-Restore Process at AWS (Amazon Web Services).
The Data Manager server architecture is evenly distributed across 2 AWS Availability Zones. These Availability Zones are geographically separated. The database cluster consists of 2 database servers, one in each Availability Zone. Every time Data Manager updates or creates a database record, both database servers are updated simultaneously.
In the event the servers in one Availability Zone no longer function, Data Manager will continue to be available while we restore the servers.
Cloud Protection Manager is used for server backups. Backups of each server are performed daily at 3:00 am Eastern. Servers are restored using these images.
1. What protection is in place against denial-of-service attack?
Denial of service vulnerabilities are addressed as part of our ongoing vulnerability management program. Weaknesses are identified, prioritized, and remediated on an ongoing basis.
1. What is the process to perform security incident investigations or e-discovery?
As noted in section 1 above, once a potential breach has been identified, HMH follows a predefined process as documented in our Security Incident Response Policy. Our priorities are:
· Compliance with all applicable laws
· The protection of our customers’, employees’, and business partners’ information
· Compliance with all applicable industry regulations
· Adherence to Contractor’s contractual obligations
· The protection of Contractor’s customer good will
· Cooperation with law enforcement and regulatory authorities
The process includes the following broad steps, which may overlap:
· Detection and Analysis
· Containment, Eradication, and Recovery,
· Post-Incident Activity
File details come from the government source that posted it.