IT_Supplemental_.pdf

PDF 169 KB Posted

Attached to
Five9 Call Center Services State and local contract opportunity
Solicitation number
BPM048459
Issued by
Baltimore County, Maryland

About this file

This document is an IT Supplemental requirements file for the State of Maryland that outlines technical specifications and requirements for IT contracts, effective August 2024. The document details deliverable submission and acceptance processes, requiring contractors to submit deliverables through an Agency Deliverable Product Acceptance Form (DPAF) and ensure compatibility with Microsoft Office products within two versions of current releases. Draft deliverables must be submitted two weeks before final deliverables are due, and all deliverables must undergo a standard review cycle agreed upon between the State and Contractor.

The document specifies extensive security requirements including SOC 2 Type 2 audit requirements, data protection controls, disaster recovery provisions requiring a DR site at least 100 miles from primary operations, and incident response procedures. Contractors must comply with PCI DSS requirements, maintain data within continental U.S. boundaries, and provide security logs and reports. The document prohibits auto-renewal of services and requires contractors to bear costs for security audits and breach remediation. There are specific requirements for hardware/software procurement with no markup allowed on materials passed through to the State, and contractors must maintain separate production, test and training environments. While a HIPAA Business Associate Agreement is not required, contractors must complete a Location of Performance Services Disclosure.

View the file

Other files for this state and local contract opportunity

Other files attached to Five9 Call Center Services, newest first.
File Type Posted
MSDE_Supplemental_Information_Technology_Requirements_10.2024__5_.pdf PDF
R00B5600109_Call_Center_Services.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Information Technology (IT) Supplemental

IT Supplemental Effective Date: August 2024

1.1 Deliverables

1.1.1 Deliverable Submission

A. For every deliverable, the Contractor shall request the Contract Monitor confirm receipt of that deliverable by sending an e-mail identifying the deliverable name and date of receipt.

B. For every deliverable, the Contractor shall submit to the Contract Monitor, by email, an Agency Deliverable Product Acceptance Form (DPAF), an example of which is provided on the DoIT web page here:

https://doit.maryland.gov/contracts/Documents/_procurementForms/Deliverabl eProductAcceptanceForm-DPAFsample.pdf

C. Unless specified otherwise, written deliverables shall be compatible with

Microsoft Office, Microsoft Project or Microsoft Visio within two (2) versions of the current version. At the Contract Monitor’s discretion, the Contract

Monitor may request one hard copy of a written deliverable.

D. A standard deliverable review cycle will be elaborated and agreed-upon between the State and the Contractor. This review process is entered into when the Contractor completes a deliverable.

A. For any written deliverable, the Contract Monitor may request a draft version of the deliverable, to comply with the minimum deliverable quality criteria listed in Section 2.4.3 Minimum Deliverable Quality. Drafts of each final deliverable, except status reports, are required at least two weeks in advance of when the final deliverables are due (with the exception of deliverables due at the beginning of the project where this lead time is not possible, or where draft delivery date is explicitly specified). Draft versions of a deliverable shall comply with the minimum deliverable quality criteria listed in Section 2.4.3

Minimum Deliverable Quality.

1.1.2 Deliverable Acceptance

A. A final deliverable shall satisfy the scope and requirements of this RFP for that deliverable, including the quality and acceptance criteria for a final deliverable as defined in Section 2.4.4 Deliverable Descriptions/Acceptance Criteria.

B. The Contract Monitor shall review a final deliverable to determine compliance with the acceptance criteria as defined for that deliverable. The Contract

Monitor is responsible for coordinating comments and input from various team members and stakeholders. The Contract Monitor is responsible for providing clear guidance and direction to the Contractor in the event of divergent feedback from various team members.

C. The Contract Monitor will issue to the Contractor a notice of acceptance or rejection of the deliverable in the DPAF (see online sample). Following the return of the DPAF indicating “Accepted” and signed by the Contract Monitor, the Contractor shall submit a proper invoice in accordance with the procedures https://doit.maryland.gov/contracts/Documents/_procurementForms/DeliverableProductAcceptanceForm-DPAFsample.pdf https://doit.maryland.gov/contracts/Documents/_procurementForms/DeliverableProductAcceptanceForm-DPAFsample.pdf in Section 3.3. The invoice must be accompanied by a copy of the executed

DPAF or payment may be withheld.

B. In the event of rejection, the Contract Monitor will formally communicate in writing any deliverable deficiencies or non-conformities to the Contractor, describing in those deficiencies what shall be corrected prior to acceptance of the deliverable in sufficient detail for the Contractor to address the deficiencies.

The Contractor shall correct deficiencies and resubmit the corrected deliverable for acceptance within the agreed-upon time period for correction.

1.1.3 Minimum Deliverable Quality

The Contractor shall subject each deliverable to its internal quality-control process prior to submitting the deliverable to the State.

Each deliverable shall meet the following minimum acceptance criteria:

A. Be presented in a format appropriate for the subject matter and depth of discussion.

B. Be organized in a manner that presents a logical flow of the deliverable’s content.

C. Represent factual information reasonably expected to have been known at the time of submittal.

D. In each section of the deliverable, include only information relevant to that section of the deliverable.

E. Contain content and presentation consistent with industry best practices in terms of deliverable completeness, clarity, and quality.

F. Meets the acceptance criteria applicable to that deliverable, including any State policies, functional or non-functional requirements, or industry standards.

G. Contains no structural errors such as poor grammar, misspellings or incorrect punctuation.

H. Must contain the date, author, and page numbers. When applicable for a deliverable, a revision table must be included.

C. A draft written deliverable may contain limited structural errors such as incorrect punctuation, and shall represent a significant level of completeness toward the associated final written deliverable. The draft written deliverable shall otherwise comply with minimum deliverable quality criteria above.

1.1.4 Deliverable Descriptions/Acceptance Criteria

In addition to the items identified in the table below, the Contractor may suggest other subtasks, artifacts, or deliverables to improve the quality and success of the assigned tasks.

1.3 Contractor-Supplied Hardware, Software, and Materials

A. The Contractor is responsible for the acquisition and operation of all hardware, software and network support related to the services being provided. However, the State has the right to purchase hardware, software, and hosting services from a source other than the Contractor if it is determined to be in the best interest of the State based on value and price.

B. Cloud based applications shall be accessible from various client devices through a thin client interface such as a Web browser or a program interface.

C. For projects that require Contractor supplied materials, the costs for the materials shall be passed through to the State with no mark-up by the Contractor.

D. The Contractor shall prepare software releases and stage each release in the system testing environment at the State for validation. The State will have the ability to manage the distribution of these releases to the appropriate sites. (Note: To support this requirement, the Offeror shall propose, provide and fully describe their solution for updating all sites with any new software releases.)

E. The Contractor may operate in the production environment upon authorization to operate (ATO) from the State.

F. The State shall receive the manufacturer or provider’s standard warranty for hardware and software provided under the Contract, the details for which must be described in the Offeror’s Technical

Proposal. Any warranty period for goods and services will not commence until acceptance of the products or services by the State of Maryland. Notwithstanding anything to the contrary, all defective items must be replaced at no additional cost to the State.

1.4 Product Requirements

A. Open source software may be proposed; however, operational support for the proposed software must also be proposed. Operational support shall include maintenance and updating of code to address software dependencies, software updates and security vulnerabilities.

B. Bidders/Offerors proposing to resell services of another entity must be authorized by such other entity.

C. No international storage or processing for State Data: As described in Section 1.6.5.B 15) Data

Protection and Controls, Bidders/Offerors are advised that any processing or storage of data outside of the continental U.S. is strictly prohibited.

D. Consistent expiration dates: Licenses/services purchased under the Contract shall expire coterminously with the earliest licenses/services delivered. As appropriate, charges shall be prorated.

E. Any terms of use or other agreement applicable to the Bidder’s/Offeror's proposed services must be contained in the Bidder’s/Offeror’s Technical Proposal. The State is not subject to any terms of use or other agreement applicable to the Bidder’s/Offeror’s proposed services unless the same are explicitly agreed to by the State during the Proposal evaluation process.

F. The State does not recognize and is not subject to any auto-renewal of services provision that may be contained or provided for in any Contractor agreements.

1.5 Maintenance

Maintenance and support, and Contractor’s ongoing maintenance and support obligations, are defined as follows:

A. Maintenance commences at the initial startup activities.

B. Software maintenance includes all software changes, modifications, updates, patching, bug fixes, vulnerability fixes, and enhancements applicable to all system modules licensed without further charge to all licensed users maintaining a renewable software support contract.

C. Maintenance shall be provided for superseded releases and back releases still in use by the State.

D. For the first year and all subsequent Contract years, the following services shall be provided for the current version and one previous version of any Software provided with the Deliverables, commencing upon

1) Error Correction. Upon notice by the State of a problem with the Software (which problem can be verified), reasonable efforts to correct or provide a working solution for the problem.

2) Material Defects. Contractor shall notify the State of any material errors or defects in the

Deliverables known, or made known to Contractor from any source during the life of the Contract that could cause the production of inaccurate or otherwise materially incorrect results. The Contractor shall initiate actions as may be commercially necessary or proper to effect corrections of any such errors or defects.

3) Vulnerabilities. Contractor shall notify the State of any vulnerabilities of which it is or becomes aware, that could allow unauthorized access, disclosure, or modification of data, applications, or systems. The Contractor shall fix all vulnerabilities in accordance with the State’s IT Security Manual in Reference B of the Table in Section 1.2.

4) Updates. Contractor will provide to the State at no additional charge all new releases and bug fixes

(collectively referred to as “Updates”) for any software Deliverable developed or published by the

Contractor and made available to its other customers.

E. Activity reporting

1.5.1 Technical Support

A. “Technical Support” means Contractor-provided assistance for the services or Solution furnished under the Contract, after initial end-user support confirms a technical issue that requires additional troubleshooting capabilities; sometimes referenced as Tier II – IV support.

B. Technical Support shall be available during Normal State Business Hours.

C. The State shall be able to contact a Technical Support team member 24 hours per day, 7 days per week, 365 days per year, based on the Tier defined in the Service Level Agreement.

D. Contractor Personnel providing technical support shall be familiar with the State’s account (i.e., calls shall not be sent to a general queue).

E. Contractor shall return calls for service of emergency system issues within one (1) hour or per the

Service Level Agreement.

F. Calls for non-emergency IT service requests will be returned within three (3) hours or immediately the following day if after Normal State Business Hours.

G. The State shall be provided with information on software problems encountered at other locations, along with the solution to those problems, when relevant to State software.

3) Contractor shall utilize a help desk ticketing system to record and track all help desk calls.

The ticketing system shall record with a date and timestamp when the ticket was opened and when the ticket was closed as well as which personnel at the organization handled and resolved the ticket with a full audit trail of activity as well as which personnel at the organization handled and resolved the ticket with a full audit trail of activity.

The Contractor shall:

A. Perform backups of the web, application, and database servers on a regular basis. This shall include daily incremental backups and full weekly backups of all volumes of servers;

B. Retain daily backups for one (1) month and weekly backups shall be retained for two (2) years;

C. Store daily backups off-site.

1.6 Service Level Agreement (SLA)

THIS SECTION IS INAPPLICABLE TO THIS RFP.

1.7 Required Project Policies, Guidelines and Methodologies

The Contractor must comply with all applicable laws, regulations, policies, standards and guidelines affecting Information Technology projects, which may be created or changed periodically. These include, but are not limited to:

Reference Regulations, Policies, Guidelines and Methodologies

A The State of Maryland System Development Life Cycle (SDLC) methodology https://doit.maryland.gov/SDLC/Pages/agile-sdlc.aspx

B The State of Maryland Information Technology Security Policy and Standards at:

https://doit.maryland.gov/policies/Pages/ContractPolicies.aspx

C The State of Maryland Information Technology Non-Visual Standards at:

https://doit.maryland.gov/policies/Pages/nva.asp

D The State of Maryland Information Technology Project Oversight at:

https://doit.maryland.gov/epmo/Pages/ProjectOversight.aspx

E

The Contractor shall follow project management methodologies consistent with the most recent edition of the Project Management Institute’s Project Management

Body of Knowledge Guide.

F

Hardware and Software hardening procedures by Center for Internet Security

(CIS) guides https://www.cisecurity.org/ or Security Requirements Guides (SRG) http://www.nist.gov

G

Federal Information Processing Standards (FIPS), “Security Requirements for

Cryptographic Modules”, FIPS PUB 140-3:

https://csrc.nist.gov/publications/detail/fips/140/3/final https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips-140-

3-standards

H Purchasing and Recycling Electronic Products https://dgs.maryland.gov/Pages/GreenPurchasing/Resources/Electronics.aspx

1.8 Disaster Recovery and Data

1.8.1 Redundancy, Data Backup and Disaster Recovery

a) Unless specified otherwise, throughout the Contract term, the Contractor shall maintain or cause to be maintained disaster avoidance procedures designed to safeguard State data and other confidential information, Contractor’s processing capability and the availability of http://doit.maryland.gov/SDLC/Pages/agile-sdlc.aspx http://doit.maryland.gov/policies/Pages/ContractPolicies.aspx https://doit.maryland.gov/policies/Pages/nva.asp http://doit.maryland.gov/epmo/Pages/ProjectOversight.aspx https://www.cisecurity.org/ http://www.nist.gov/ https://csrc.nist.gov/publications/detail/fips/140/3/final https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips-140-3-standards https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips-140-3-standards https://dgs.maryland.gov/Pages/GreenPurchasing/Resources/Electronics.aspx hosted services. Any force majeure provisions of the Contract do not limit the Contractor’s obligations under this provision.

b) The Contractor shall have robust contingency and disaster recovery (DR) plans in place to ensure that the services provided under the Contract will be maintained in the event of disruption to the Contractor/subcontractor’s operations (including, but not limited to, disruption to information technology systems), however caused.

1) The Contractor shall furnish a DR site.

2) The DR site shall be at least 100 miles from the primary operations site, and have the capacity to take over complete production volume in case the primary site becomes unresponsive.

c) The contingency and DR plans must be designed to ensure that services under the Contract are restored after a disruption within 24 hours from notification, with a recovery point objective of one hour or less prior to the outage in order to avoid unacceptable consequences due to the unavailability of services.

d) The Contractor shall test the contingency/DR plans at least twice annually to identify any changes that need to be made to the plan(s) to ensure a minimum interruption of service.

Coordination shall be made with the State to ensure limited system downtime when testing is conducted. At least one annual test shall include backup media restoration and failover/fallback operations at the DR location. The Contractor shall send the Contract

Monitor a notice of completion following completion of DR testing.

e) Such contingency and DR plans shall be available for the State to inspect and practically test at any reasonable time, and subject to regular updating, revising, and testing throughout the term of the Contract.

1.8.2 Data Export/Import

a) The Contractor shall, at no additional cost or charge to the State, in an industry standard/non-proprietary format:

1) perform a full or partial import/export of State data within 24 hours of a request; or

2) provide to the State the ability to import/export data at will and provide the State with any access and instructions which are needed for the State to import or export data.

b) Any import or export shall be in a secure format per the Security Requirements.

1.8.3 Data Ownership and Access

As set forth in the Contract, data, databases and derived data products created, collected, manipulated, or directly purchased as part of the solicitation are the property of the State. The purchasing State agency is considered the custodian of all State data. The use, access, and distribution of all data shall comply with the requirements of the Data Use Agreement (Attachment Y).

The Contractor may not access State data other than as necessary to perform the services under this

Contract.

The Contractor shall limit access to and use of State data to Contractor Personnel whose responsibilities require such access or use and shall train such Contractor Personnel on the confidentiality obligations set forth herein.

At no time shall any data or processes – that either belong to or are intended for the use of the State or its officers, agents or employees – be copied, disclosed or retained by the Contractor or any party related to the Contractor for subsequent use in any transaction that does not include the State.

The Contractor shall not use any information collected in connection with the services furnished under the Contract for any purpose other than fulfilling such services.

Provisions in Sections 1.8.1 - 1.8.3 shall survive expiration or termination of the Contract.

Additionally, the Contractor shall flow down the provisions of Sections 1.8.1 - 1.8.3 (or the substance thereof) in all subcontracts.

1.9 Security Requirements

The following requirements are applicable to the Contract:

1. Employee Identification

a) Contractor Personnel shall display his or her company ID badge in a visible location at all times while on State premises. Upon request of authorized State personnel, each

Contractor Personnel shall provide additional photo identification.

b) Contractor Personnel shall cooperate with State site requirements, including but not limited to, being prepared to be escorted at all times, and providing information for State badge issuance.

c) Contractor shall remove any Contractor Personnel from working on the Contract where the

State determines, in its sole discretion, that Contractor Personnel has not adhered to the

Security requirements specified herein.

d) The State reserves the right to request that the Contractor submit proof of employment authorization of non-United States Citizens, prior to commencement of work under the

Contract.

2. Security Clearance / Criminal Background Check

The State reserves the right to refuse any individual Contractor Personnel to work on State premises, based upon certain specified criminal convictions, as specified by the State.

A criminal background check is not required for Contractor Personnel.

A. The Contractor shall obtain criminal background checks on candidates it sends for employment under the Contract. At a minimum, these checks must contain convictions and probation before judgment (PBJ) pleadings within the State of Maryland. This check may be performed by a public or private entity.

The Contractor shall provide the Contract Monitor with certification of completion of the required criminal background check described in this IFB for each required Contractor

Personnel prior to assignment, and that the Contractor Personnel have successfully passed this check.

B. Persons with a criminal record may not perform services under the Contract unless prior written approval is obtained from the Contract Monitor. The Contract Monitor reserves the right to reject any individual based upon the results of the background check. Decisions of the Contract Monitor as to acceptability of a candidate are final.

C. The CJIS criminal record check of each Contractor Personnel who will work on State premises shall be reviewed and documented by the Contractor for convictions of any of the following crimes described in the Annotated Code of Maryland, Criminal Law Article:

1) §§ 6-101 through 6-104, 6-201 through 6-205, 6-409 (various crimes against property);

2) any crime within Title 7, Subtitle 1 (various crimes involving theft);

3) §§ 7-301 through 7-303, 7-313 through 7-317 (various crimes involving telecommunications and electronics);

4) §§ 8-201 through 8-302, 8-501 through 8-523 (various crimes involving fraud);

5) §§9-101 through 9-417, 9-601 through 9-604, 9-701 through 9-706.1 (various crimes against public administration); or

6) a crime of violence as defined in CL § 14-101(a).

D. Contractor Personnel that would have access to systems supporting the State or to State data who have been convicted of a felony or convicted of a crime involving telecommunications and electronics or convicted within the past five (5) years of a misdemeanor from the above list of crimes shall not be permitted to work on the

Contract.

E. A particular on-site location covered by the Contract may require more restrictive conditions regarding the nature of prior criminal convictions that would result in

Contractor Personnel not being permitted to work on those premises. Upon receipt of a location’s more restrictive conditions regarding criminal convictions, the Contractor shall provide an updated certification regarding the Contractor Personnel working at or assigned to those premises.

3. On-Site Security Requirement(s)

THIS SECTION IS INAPPLICABLE TO THIS IFB.

1.9.4 Information Technology Security

A. Contractors shall comply with and adhere to the State IT Security Manual, Policies and

Standards. These policies may be revised from time to time and the Contractor shall comply with all such revisions. Updated and revised versions of the State IT Policy and

Standards are available online at: Policies, Standards, and Guidelines.

B. The Contractor shall not connect any of its own equipment to a State LAN/WAN without prior written approval by the State as directed and coordinated with the Contract

Monitor.

The Contractor shall:

https://doit.maryland.gov/cybersecurity/Pages/policies-and-guidance.aspx

1) For IT Security Policies and Standards that are no covered by the State IT

Security Manual, the Contract shall Implement administrative, physical, and technical safeguards to protect State data that are no less rigorous than accepted industry best practices for information security such as those listed below (see Section 1.6.5)

2) Ensure that all such safeguards, including the manner in which State data is collected, accessed, used, stored, processed, disposed of and disclosed, comply with applicable data protection and privacy laws as well as the terms and conditions of the

Contract; and

3) Ensure compliance with all applicable federal, State, and local laws, rules and regulations concerning security of Information Systems and Information Technology.

1.9.5. Data Protection and Controls

A. Contractor shall ensure a secure environment for all State data and any hardware and software (including but not limited to servers, network and data components) provided or used in connection with the performance of the Contract according to a written security policy (“Security Plan”) no less rigorous than that of the State and using best practices that comply with an accepted industry standard, such as the NIST cybersecurity framework.

1) The Security Plan shall detail the steps and processes employed by the Contractor as well as the features and characteristics which will ensure compliance with the security requirements of the Contract. Such Security Plan shall be provided to the

State for its review with solicitation response. If awarded a contract, the Security

Plan shall be provided on an annual basis or whenever updates are made.

2) The Contractor shall supply a copy of such policy to the State for validation, with any appropriate updates, on an annual basis.

3) If any Security Plan information, including procedures, are different based on a

Task Order, Contractor shall furnish such differences to the respective TO

Manager.

B. To ensure appropriate data protection safeguards are in place, the Contractor shall implement and maintain the following controls during the Contract Term (the Contractor may augment this list with additional controls):

1) Establish separate production, test, and training environments for systems supporting the services provided under the Contract and ensure that production data is not utilized in test or training environment(s).

2) Apply hardware and software hardening procedures as recommended by Center for Internet Security (CIS) guides, Security Technical Implementation Guides

(STIG), or similar industry best practices to reduce the systems’ surface of vulnerability, eliminating as many security risks as possible and documenting what is not feasible or not performed according to best practices. Any hardening practices not implemented shall be documented with a plan of action and milestones including any compensating control. These procedures may include but are not limited to removal of unnecessary software, disabling or removing unnecessary services, removal of unnecessary usernames or logins, and the deactivation of unneeded features in the Contractor’s system configuration files.

3) Ensure that State data is not commingled with non-State data through the proper application of compartmentalization Security Measures.

4) Apply data encryption to protect Sensitive Data at all times, including in transit, at rest, and also when archived for backup purposes. Unless otherwise directed, the Contractor is responsible for the encryption of all Sensitive Data.

5) Apply data encryption to all Contractor managed or controlled State data when the data is in transit over untrusted network segments.

6) Utilize encryption algorithms for encrypting data that comply with current

Federal Information Processing Standards (FIPS), “Security Requirements for

Cryptographic Modules.”

7) Enable appropriate logging parameters to monitor user access activities, authorized and failed access attempts, system exceptions, and critical information security events as recommended by the operating system and application manufacturers and information security standards, including the

Maryland Department of Information Technology’s Information Security

Manual.

8) Retain the aforementioned logs and review them at least daily to identify suspicious or questionable activity for investigation and documentation as to their cause and remediation, if required. The State shall have the right to inspect the logs and the Contractor or subcontractor’s performance to confirm the effectiveness of these measures for the services being provided under the

Contract.

9) Ensure system and network environments are separated by properly configured and updated layer seven firewalls.

10) Restrict network connections between trusted and untrusted networks by physically or logically isolating systems from unsolicited and unauthenticated network traffic.

11) By default “deny all” and only allow access by exception.

12) Review, at least annually and after changes, the aforementioned network connections, documenting and confirming the business justification for the use of all service, protocols, and ports allowed, including the rationale or compensating controls implemented for those protocols considered insecure but necessary.

13) Perform regular internal and external vulnerability testing of operating system, applications, and all network devices utilized in this Contract. Such testing is expected to identify outdated software versions; missing software patches;

device or software misconfigurations; and to validate compliance with or deviations from the security policies applicable to the Contract. Contractor shall evaluate all identified vulnerabilities for potential adverse effect on security and integrity and remediate the vulnerability no later than 30 days following the earlier of vulnerability’s identification or public disclosure, or document why remediation action is unnecessary or unsuitable. The State shall have the right to conduct vulnerability testing and inspect the results of similar Contractor performed vulnerability testing to confirm the effectiveness of these measures for the services being provided under the Contract.

14) Enforce strong user authentication and password control measures to minimize the opportunity for unauthorized access through compromise of the user access controls. At a minimum, the implemented measures should be consistent with the most current Maryland Department of Information Technology’s Information

Security Policies, including specific requirements for password length, complexity, history, and account lockout.

15) Ensure State data is not processed, transferred, or stored outside of the continental United States (“U.S.”). The Contractor shall provide its services to the State and the State’s end users solely from data centers in the U.S. Unless granted an exception in writing by the State, the Contractor shall not allow

Contractor Personnel to store State data on portable devices, including personal computers, except for devices that are used and kept only at its U.S. data centers.

Contractor Personnel may access State data remotely only as required to provide technical support and with the prior approval of the State.

16) Ensure Contractor Personnel shall not connect any of their own equipment to

State IT assets without prior written approval by the State. Any such approval may be revoked, rescinded, or curtailed at any time for any reason. The

Contractor shall coordinate requests for approval with the Contract Monitor and is subject to all State approval processes as they may be revised from time to time.

17) Ensure that anti-virus and anti-malware software is installed and maintained on all systems and end points supporting the services provided under the Contract;

that the anti-virus and anti-malware software is automatically updated; and that the software is configured to actively scan and detect threats to the system for remediation. The Contractor shall perform routine monthly vulnerability scans and take corrective actions for any findings.

18) Conduct regular external vulnerability testing designed to examine the service provider’s security profile from the Internet without benefit of access to internal systems and networks behind the external security perimeter. Evaluate all identified vulnerabilities on Internet-facing devices for potential adverse effect on the service’s security and integrity and remediate the vulnerability promptly or document why remediation action is unnecessary or unsuitable. The State shall have the right to inspect the Contractor’s processes and the performance of vulnerability testing to confirm the effectiveness of these measures for the services being provided under the Contract.

1.9.6 Security Logs and Reports Access

a) For any cloud hosted, or Contractor, or third party hosted solution, the Contractor shall provide security logs and reports to the State in a mutually agreeable format.

b) Reports shall include latency statistics, user access, user access IP address, user access history and security logs for all State data, systems, and software data, systems, and software related to the Contract.

1.9.7 Payment Card Industry Compliance

A. Contractor shall at all times comply, and ensure compliance with, all applicable Payment

Card Industry ("PCI") Data Security Standards (“DSS”), including any and all changes thereto. Contractor shall provide the Contract Monitor with documented evidence of current compliance to PCI DSS within 30 days of request.

B. The Contractor shall annually furnish to the Contract Monitor evidence of the PCI

Security Standards Council’s (SSC) acceptance or attestation of the Contractor’s conformance to the relevant PCI DSS requirements by a third party certified to perform compliance assessments.

C. The Contractor shall ensure that the scope of the annual SOC 2 Type II Audit Report specified under Section 1.7 includes testing to confirm the PCI assessment results.

1.9.8 Security Incident Response

A. The Contractor shall notify the State when any Contractor system that may access, process, or store State data or State systems experiences a Security Incident or a Data

Breach as follows:

1) notify the State within twenty-four (24) hours of the discovery of a Security

Incident by providing notice via written or electronic correspondence to the

Contract Monitor, State Chief Information Security Officer and Maryland

Security Operations Center (MD-SOC);

2) notify the State within seventy-two (72) hours if there is a threat to Contractor’s solution as it pertains to the use, disclosure, and security of State data; and

3) provide written notice to the State within one (1) Business Day after Contractor’s discovery of unauthorized use or disclosure of State data and thereafter all information the State requests concerning such unauthorized use or disclosure.

B. Contractor’s notice shall identify:

1) the nature of the unauthorized use or disclosure;

2) the State data used or disclosed,

3) who made the unauthorized use or received the unauthorized disclosure;

4) what the Contractor has done or shall do to mitigate any deleterious effect of the unauthorized use or disclosure; and

5) what corrective action the Contractor has taken or shall take to prevent future similar unauthorized use or disclosure.

6) The Contractor shall provide such other information, including a written report, as reasonably requested by the State.

C. Discussing Security Incidents with the State should be handled on an urgent as-needed basis, as part of Contractor communication and mitigation processes as mutually agreed upon, defined by law or contained in the Contract. The Contractor shall obtain approval from the State prior to communicating with outside parties regarding a Security Incident, which may include contacting law enforcement, fielding media inquiries and seeking external expertise.

D. The Contractor shall comply with all applicable system security breach laws.

1.9.9 Data Breach Responsibilities

A. If the Contractor reasonably believes or has actual knowledge of a Data Breach, the

Contractor shall, unless otherwise directed:

1) Notify the appropriate State-identified contact within 24 hours by telephone and email to the Maryland Security Operations Center (MD-SOC) in accordance with the agreed upon security plan or security procedures unless a shorter time is required by applicable law;

2) Cooperate with the State to investigate and resolve the data breach;

3) Promptly implement commercially reasonable remedial measures to remedy the

Data Breach; and

4) Document responsive actions taken related to the Data Breach, including any post-incident review of events and actions taken to make changes in business practices in providing the services.

B. With respect to State data within the possession or control of the Contractor, the

Contractor shall bear the costs associated with (1) the investigation and resolution of the data breach; (2) notifications to individuals, regulators or others required by State law; (3) a credit monitoring service required by State or federal law; (4) a website or a toll-free number and call center for affected individuals required by State law; and (5) complete all corrective actions as reasonably determined by Contractor based on root cause; all [(1) through (5)] subject to the Contract’s limitation of liability.

C. The public disclosure of a cybersecurity incident shall be pursuant to Guidelines for the Public Disclosure of Cybersecurity Incidents or any successor thereto..

1.9.11 The State shall, at its discretion, have the right to review and assess the Contractor’s compliance to the security requirements and standards defined in the Contract.

1.10 SOC 2 Type 2 Audit Report

A SOC 2 Type 2 Audit Report applies to the Contract. The applicable trust services criteria are

a) The Contractor shall provide to the Contract Monitor, within thirty (30) calendar days of the issuance of the final SOC 2 Type 2 Audit Report, the audit results and a documented https://doit.maryland.gov/cybersecurity/Documents/Cybersecurity-Guidelines-PDCI.pdf https://doit.maryland.gov/cybersecurity/Documents/Cybersecurity-Guidelines-PDCI.pdf https://doit.maryland.gov/cybersecurity/Documents/Cybersecurity-Guidelines-PDCI.pdf corrective action plan that addresses each audit finding or exception contained in the

SOC 2 Type 2 Audit Report, identifying in detail the remedial action to be taken by the

Contractor along with the date(s) when each remedial action is to be implemented. The scope of the SOC 2 Type 2 Audit Report shall include work performed by any subcontractors that handles, store or process Sensitive Data or are responsible for security controls and provide essential support to the TO Contractor for or essential support to the

Information Functions and Processes for the services provided to the State under the

Contract. The Contractor shall ensure the audit includes all such subcontractors operating in performance of the Contract or, in the case the subcontractor’s services are covered by a separate SOC 2 Type 2 Audit, that separate SOC 2 Type 2 Audit reports are obtained from all subcontractors and submitted to the Contract Monitor via the

Contractor’s primary point of contact.

b) All SOC 2 Type 2 Audit Reports shall be submitted to the Contract Monitor as specified in Section a above. The initial SOC 2 Type 2 Audit shall be completed within a timeframe to be specified by the State. The audit period covered by the initial SOC 2

Type 2 Audit shall start with the Contract Effective Date unless otherwise agreed to in writing by the Contract Monitor. All subsequent SOC 2 Type 2 Audits after this initial audit shall be performed at a minimum on an annual basis throughout the Term of the

Contract, and shall cover a 12-month audit period or such portion of the year that the

Contractor furnished services.

c) The SOC 2 Type 2 Audit shall report on the suitability of the design and operating effectiveness of controls over the Information Functions and Processes to meet the requirements of the Contract, including the Security Requirements identified in Section

1.6, relevant to the trust services criteria identified in Section 1.7.1: as defined in the aforementioned Guidance.

d) The audit scope of each year’s SOC 2 Type 2 Audit Report may need to be adjusted

(including the inclusion or omission of the relevant trust services criteria of Security, Availability, Processing Integrity, Confidentiality, and Privacy) to accommodate any changes to the environment since the last SOC 2 Type 2 Audit Report. Such changes may include but are not limited to the addition of Information Functions and/or Processes through modifications to the Contract or due to changes in Information Technology or the operational infrastructure. The Contractor shall ensure that the audit scope of each year’s

SOC 2 Type 2 Audit Report engagement shall accommodate these changes by including in the SOC 2 Type 2 Audit Report all appropriate controls related to the current environment supporting the Information Functions and/or Processes, including those controls required by the Contract.

e) The scope of the SOC 2 Type 2 Audit Report shall include work performed by any subcontractors that handle, store or process Sensitive Data and provide essential support to the TO Contractor for or essential support to the Information Functions and Processes for the services provided to the State under the Contract. The Contractor shall ensure the audit includes all such subcontractors operating in performance of the Contract or shall ensure their subcontractors obtain a SOC 2 Type 2 Audit Report as described in this

Section.

f) All SOC 2 Type 2 Audits shall be completed at the Contractor’s expense, including those of the Contractor, shall be performed at no additional expense to the State.

g) If the Contractor fails during the Contract term to obtain an annual SOC 2 Type 2 Audit

Report by the date specified in Section 1.7.2.A, the State shall have the right to retain an independent audit firm to perform an audit engagement to issue of a SOC 2 Type 2 Audit

Report of the Information Functions and/or Processes utilized or provided by the

Contractor and under the Contract. The Contractor agrees to allow the independent audit firm to access its facility/ies for purposes of conducting this audit engagement(s), and will provide the necessary support and cooperation to the independent audit firm in the performance of the engagement.that is required to perform the audit engagement of the

SOC 2 Type 2 Audit Report. The State, at its option, will invoice the Contractor for the expense of the SOC 2 Type 2 Audit Report(s), or deduct the cost from future payments to the Contractor.

h) Provisions in Section 1.7.1-2 shall survive expiration or termination of the Contract.

Additionally, the Contractor shall flow down the provisions of Section 1.7.1-2 (or the substance thereof) in all subcontracts.

1.13 Location of the Performance of Services Disclosure

The Bidder/Offeror is required to complete and submit with the Bid/ Proposal the Location of the

Performance of Services Disclosure. A copy of this Disclosure is included as Attachment K.

1.14 HIPAA - Business Associate Agreement

A HIPAA Business Associate Agreement is not required for this procurement.

File details come from the government source that posted it. Updated .