HE125420R3001_ DoDEA Cloud Questionnaire_SIS (Attachement 1).docx

DOCX document 17 KB Posted

Attached to
DoDEA Student Information System (SIS) Federal contract opportunity
Solicitation number
HE125420R3001
Issued by
Department of Defense Education Activity

View the file

Other files for this federal contract opportunity

Other files attached to DoDEA Student Information System (SIS), newest first.
File Type Posted
HE125420R3001_Past Performance Questionnaire (Attachment 3).docx DOCX document
DODEA SIS RFP HE125420R3001.pdf PDF
HE125420R3001 Price Template (Attachment 2).xlsx XLSX spreadsheet
DRAFT SIS-PWS-18Dec2019.docx DOCX document
SIS NOTICE.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

RFP HE125420R3001

ATTACHMENT 1

DoDEA Cloud Questionnaire – Student Information System Directions

· The Department of Defense Education Activity (DoDEA) must review each vendor’s cloud-based solution individually to determine if it is compatible with DoD’s guidelines. Any proprietary or sensitive security information provided in response to this questionnaire will be protected and not shared outside of the U.S. Government.

· Instructions: Offerors shall closely read the questions below and ensure their responses are complete. Failture to do so may result in the Offeror being found unacceptable Client Systems Software and Configuration

1. Is any software required for this service, e.g., software that must be installed on DoDEA computers, to include browser extensions and plugins? If so please provide a list of the software and all applicable security documentation.

2. Are there any configurations or changes that DoDEA must implement to either its computers or browsers to utilize this service? If so please provide those configurations and any related security documentation.

Privacy Information Data Collection and Distribution

3. What personally identifiable and sensitive information (PII) is collected and used? How is that information protected? Please provide information pertaining to the data protection. See references within Section 7 of the PWS.

4. What, if any, personally identifiable and sensitive information is collected by third parties or by external business partners (e.g., via cookies, plug-ins, ad networks, web beacons etc.)? See references within Section 7 of the PWS.

5. Is any DoDEA data provided to third parties or external business partners for any purpose? If yes, please provide a list of all third-party or external business partner recipients.

6. Which, if any, of the following requirements does your cloud service meet:

0. Children's Online Privacy Protection Act (COPPA), per http://www.coppa.org/coppa.htm?

0. Family Educational Rights and Privacy Act (FERPA), per http://www2.ed.gov/policy/gen/guid/fpco/ferpa/index.html?

0. Children's Internet Protection Act (CIPA), per http://www.fcc.gov/guides/childrens-internet-protection-act?

System Management and Security

7. Where is the application hosted? What Security Controls are inherited from the hosting provider? Please provide information identifying the security controls.

8. Please provide an overview of the systems defense in depth environment including what security practices are in place to protect the application.

9. How are the following security practices implemented and managed: system penetration testing, vulnerability management, and intrusion prevention? Please provide documentation (audits, results etc.) showing that these security practices are being followed.

10. Are software updates and patches routinely or automatically installed on all servers? Please provide information showing that the hosted environment and the application(s) are receiving the necessary security updates within the identified timeframe.

11. Is the system, including its server(s) and network devices, located in secure facilities under controlled circumstances (e.g., authorized personnel access lists, ID cards, entry logs)? Please provide information on how access is restricted.

Data Storage, Retention, and Access

12. Where will information be stored? Will any data be stored outside the United States? If so, in what nation(s) will it be stored?

13. How is information stored and transmitted?

0. How does the provider protect data at rest, i.e., data in the data center? What data is encrypted: passwords, privacy information, etc.? Please provide information explaining how the data is protected and any documentation referencing this area.

0. On systems that host multiple customers is data secured with unique encryption keys for each customer? Please provide information on if data is secured and how the data is secured between customers environments.

0. How does the provider protect data in transit, e.g., Secure Socket Layer (SSL), hashing, etc.?

14. Who has access to information stored or processed by the provider? Please provide information or examples as to how this process is executed.

15. Are background checks completed on personnel with access to servers, applications and customer data? Please provide an example of this process.

16. What is the process for authenticating callers and resetting access controls, as well as establishing and deleting accounts? Please provide information and/or examples as to how these processes are executed.

17. How is school/system data deleted? Is it deleted on a specific schedule or only at the termination of the contract?

Development and Change Management Process

18. Are there standardized and documented procedures for coding, configuration management, patch installation, and change management for all servers and network devices involved in delivery of contracted services? Please provide information or examples as to how these processes are executed.

19. What is the customer notification process for any changes made to corporate policies for data protection? Please provide information or examples as to how this process is executed.

20. Audits and Standards

0. What is the process for DoDEA to audit the security and privacy of records?

0. Are the security operations reviewed or audited by an outside group? If so please provide that group and the frequency of the security audit.

0. What security standard is followed, e.g., the International Organization for Standardization (ISO) and Payment Card Industry Data Security Standards (PCI DSS)? Please provide information on what standard is followed and how that standard is applied and enforced.

Test and Development Environments

21. Will “live” student/privacy data be used in a non-production environment (e.g., test or development, training)? If so, are these environments secure to the same standard as production data?

Data Breach, Incident Investigation and Response

22. What is the process to manage a data breach? Please provide information or examples as to how this process is executed.

23. Availability

0. What is the backup-and-restore process in case of a disaster? Please provide information on how availability will be maintained in the event of an internal or external event that affects the production system.

0. What protection is in place against denial-of-service attacks?

0. Has your system been previously compromised, if so please provide an overview of the event and the action that was taken to remediate the effects of the incident.

24. What is the process to perform security incident investigations or e-discovery?

File details come from the government source that posted it. Updated .