ITSData Sec Govnce.pdf
PDF 240 KB Posted
- Attached to
- STUDENT ECOMMERCE SOLUTION State and local contract opportunity
- Solicitation number
- 5400019220
- Issued by
- Horry County, South Carolina
About this file
This is an Information Security and Data Governance questionnaire issued by Coastal Carolina University (CCU) Office of ITS/CIO for a Student eCommerce Solution procurement in South Carolina. The document outlines comprehensive technical and security requirements that vendors must address in their proposals, covering data protection, user authentication, software security, information security policies, and third-party partner assessments. The questionnaire does not specify response dates, due dates, site visits, bidder meetings, or award dates within the provided document. The contract term and any renewal options are not detailed in this file.
The document establishes mandatory compliance standards including federal and state regulations (FERPA, HIPAA, GDPR, Graham-Bliley Act), PCI-DSS standards, and CCU's internal IT policies. Vendors must address specific requirements such as Azure-ADFS compatible single sign-on, data encryption in transit and at rest, servers located within the Continental United States, integration with FirstData/SunTrust payment gateway, P2PE certified point-of-sale devices with EMV capability, and seamless integration with Ellucian Colleague ERP systems. The questionnaire requires vendors to detail encryption methods, role-based access controls, audit trail capabilities, business continuity and disaster recovery plans, data sanitization procedures, accessibility compliance (Section 508 and WCAG 2.0), mobile capabilities, and secure data transfer methods (HTTPS, SSH/SFTP). Vendors must also provide documentation including attestations of PCI-DSS compliance, VPAT assessments, service level agreements, and detailed cost breakdowns for any modifications, customizations, or additional resources required to meet stated requirements.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| AMENDMENT 1.doc | DOC document | |
| AWARD EXTENSION.doc | DOC document | |
| CANCEL SOLICITATION.doc | DOC document | |
| SOLICITATION-CCU.doc | DOC document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Questions directed to the Office of ITS/CIO
Data Security and Governance - Information Security and Access Control CCU-Office of ITS/CIO
The proposed solution must adhere to federal and state regulations (FERPA, HIPAA, GDPR, Graham-Bliley Act, etc.) as well as to CCU’s Information Technology Service (ITS) policies and procedures with regards to data protection and privacy, firewalls, email and access policies and procedures including, but not limited to:
https://www.coastal.edu/policies/pdf/univ-its%20450%20general%20usage- %20may%202018.pdf https://www.coastal.edu/policies/pdf/univ-its%20483%20data%20privacy,%20classification,%20and%20protection,%20january%20201 7.pdf
Information Security Questions If modifications or additional costs are needed for the solution to meet any referenced requirement, detailed costs of services, products and components must be listed or attached to the proposal.
1. Data Protection (e.g., unauthorized access or disclosure):
a. What type of encryption is used for the transmission and storage of data?
b. What measures are used to separate CCU’s data from other clients’ data, if any?
c. Describe the manner throughout which data inputs and outputs is conducted.
d. What is the offerors’ position on data sharing?
2. Users’ Authentication and Access:
a. How are user accounts created and administered?
b. How does the solution provide levels of role-based security?
c. How does the solution handle single sign on capabilities, if implemented?
d. How does the solution handle logging/auditing capabilities (internally and externally)?
e. Does the solution maintain a signed audit trail of user(s) performance including actions taken and when? If so, how is this accomplished?
f. What are the supported browsers?
3. Software and system security and integrity:
a. How are software modifications tested?
b. How is programming/source code reviewed and when was it last modified?
c. What measures are in place to protect against web security flaws such as SQL injection, XSS, broken authentication and session management?
4. Information security policies and practices:
a. What measures (e.g., training, processes, background checks, etc.) does the offeror provide to ensure employees will safeguard data?
b. Does the offeror have an established information security program (that adheres to applicable Federal, and State regulations and Information Security standards, guidelines, and best practices) to fully address confidentiality, integrity and availability of data? Can a copy of the IS https://www.coastal.edu/policies/pdf/univ-its%20450%20general%20usage-%20may%202018.pdf https://www.coastal.edu/policies/pdf/univ-its%20450%20general%20usage-%20may%202018.pdf https://www.coastal.edu/policies/pdf/univ-its%20483%20data%20privacy,%20classification,%20and%20protection,%20january%202017.pdf https://www.coastal.edu/policies/pdf/univ-its%20483%20data%20privacy,%20classification,%20and%20protection,%20january%202017.pdf https://www.coastal.edu/policies/pdf/univ-its%20483%20data%20privacy,%20classification,%20and%20protection,%20january%202017.pdf
Program be provided to CCU, including auditing by an independent entity?
5. Third party partners:
a. Are there third-party technology partners used for the solution to work?
b. What protection measures are in place or utilized?
c. Has any external auditing been conducted?
Can it be verified?
Other Requirements:
a. Describe offeror’s business continuity and disaster recovery plans.
b. If implemented, single sign-on must be Azure-ADFS compatible.
c. Data encryption must be accommodated in transit and “at rest”.
d. The equipment hosting the solution for the University must be located in a physically secure facility and within the boundary of the Continental United States of America.
e. Describe Offeror’s data and physical security practices for hosted or cloud-based solutions.
f. Provide offeror’s procedures for data and system access, data retention, disposal and replacement of hard drives and disposal of backup tapes.
g. Is Offeror’s system in a shared environment? Will CCU have a dedicated system or instance of Offeror’s solution? What are offeror’s firewall port requirements for cloud-based solutions?
h. Does offeror have specific IP’s that can be matched to firewall rules?
i. If the system to be integrated with CCU systems (e.g., Ellucian Colleague, SSO, etc.), what are the required IT resources and hours during the initial implementation and thereafter? Please describe and state in details the types of IT resources required, initial and ongoing required hours to implement and support the solution.
j. Describer Offeror’s termination or exit process for ensuring successful transition to an alternative solution.
k. Must adhere to the University’s Information Technology Service (ITS) policies and procedures with regards to firewalls, email, domain and access policies and procedures as well as industry best standards.
l. The solution must natively handle email capabilities and adhere to industry best practices.
m. The solution must be PCI-DSS (latest industry acceptable version) Compliant with P2P encryption devices.
n. The solution must use SC State contract merchant services processor and compatible payment gateway: First Data/SunTrust.
o. The solution must have the ability to securely export monthly credit card payment details into an Excel worksheet from the solution.
p. The solution must be P2PE certified POS (point-of-sale) devices for in-person credit/debit card transactions with EMV capability.
q. SRED keypads or secure device to process telephone payments without inputting credit/debit card numbers into CCU computer keyboards.
r. Provide Attestation of Compliance to PCI-DSS Standards to the university on an annual basis.
s. Possible future integration with solutions such as TouchNet, NelNet, etc.
Data Governance and Security - Information Security Data Elements Checklist
CCU Office of ITS/CIO
CCU requires that third-party contractors and partners protect and safeguard University information or information that’s entrusted to the University. All contractors who transmit, access, process or store compliant data are required to agree to federal, state regulations as well as industry standards/best practices and CCU’s standards and policies.
2. Will the offeror as a third party be:
(Please Check all that apply) ☐Transmitting
☐ Accessing
☐ Processing
☐ Storing University Data
3. How many records will be involved?
☐ 250
☐ 251-500
☐ 501-1000
☐ 1000+
4. Data elements to be transmitted, accessed, processed or stored by the Offeror.
☐ Social Security Numbers
☐ Driver’s License Number or State
☐ Identification Card Number
☐ Personal Financial Information:
Account #, Account Password, ☐ Personal Identification Number (PIN)
☐ DOD classified data, or special Sensitive
Data
☐ Protected Health Information (PHI)
☐ Covered by insurance.
☐ Payment card data (credit or debit card)
☐ We will be using a third-party merchant account.
☐ Unsure what merchants will be used.
☐ Student information FERPA data or directory information that students have opted not to have released.
☐ Academic evaluations such as tests, scores, and transcripts.
☐ General counseling/advising records.
☐ Disciplinary records.
☐ Financial aid records, including loan collection records.
☐ Disability status/medical issues.
☐ Which SAQ does the offeror fill for PCI-
DSS compliance?
☐ Any other University non-public data
(Compliant or Business Sensitive) not shown above. Please Provide Examples:
Accessibility Requirements:
Since the solution would have end-user human interface (e.g., end-user device software component, web pages or sites, video or audio playback, file upload system, mobile device components, etc.), the offeror must submit one or both of the following assessments that users, instructors, system administrators, etc., are expected to interact with.
1. A current and accurate "Voluntary Product Accessibility Template", or VPAT, (see http://www.itic.org/public-policy/accessibility), to document products and/or services' conformance and deviations from Section 508 of the Rehabilitation Act of 1973.
2. A detailed description of the accessibility features that shows and explains compliance with and deviations from the guidelines of the "Web Content Accessibility Guidelines (WCAG) 2.0” published by www.w3.org.
General Information Technology Questionnaires:
The system requirements should reflect delivered/“out-of-the-box” functionality. Offerors must indicate if modifications, additional product costs or if any other accommodations would be necessary to meet any of the requirements. Additional costs, customizations or upgrades must be provided, detailing the costs and item descriptions. Costs will include any one-time/initial costs as well as ongoing annual support costs.
1. Onsite solutions a. Please describe in detail the hardware, core product software, storage and database requirements.
b. Please describe server requirements and specifications (e.g., operating systems, web server software, etc.)
c. Please describe the minimum desktop workstation hardware and software requirements required by the solution.
d. Please describe details of network communications required between the web server, app server, database server, and any other required servers.
2. SaaS/hosted/cloud solutions a. Please list normal scheduled downtime frequency, uptime percentage, standard day/time openings, etc.
b. Please describe the minimum desktop workstation hardware and software requirements required by the solution.
c. Please describe details of network communications required between the solution and other solution including University systems.
d. Please describe deployment instances of the environment (e.g., test, development and production). Are all of the instances available to CCU? If yes, detail the types of instances and how access would be provided.
e. Please reference the vendor SLA (Service http://www.itic.org/public-policy/accessibility http://www.w3.org/
Level Agreement) support requests.
3. Solution components that are provided by third-party partners, including OEM software, hosting, internal application network, etc.
a. Please describe the main technologies for the components.
b. Please provide third-party technology partner(s) name(s), address(es) and contact(s).
c. Please explain additional costs or fees associated with the referenced components.
4. Practices and policies related to data stored by this solution
a. Please describe how data will be “completely erased” upon the contract termination.
b. Please clarify data ownership rights and responsibilities of the parties and provisions for CCU obtaining the data as needed.
c. Please indicate types of data stored especially if any data is protected (e.g., HIPAA, FERPA, etc.).
d. Please indicate how long data is stored or archived.
e. Please describe the technology, practices and policies you have in place that would protect CCU data from unauthorized access and use.
f. Does company provide full data sanitization to ensure the integrity of imported data.
5. Business continuity and disaster recovery management practices
a. If the software is deployed in multiple data centers, how often is data synchronized between the data centers?
b. Please describe the strategies to minimize downtime in the event of a catastrophic failure of the hosting environment(s) or components.
c. Would CCU experience any loss of data as a result of downtime, system problems or catastrophic failure? If yes, describe the situations that could result in loss of CCU data.
d. How much downtime should CCU expect for a catastrophic failure?
6. Change management practices for all hardware and software components
a. How often is the software updated and releases made available?
b. How is CCU notified of new updates or upgrades?
c. Are updates and upgrades mandatory?
d. What provisions are there for managing customization requested by CCU?
e. How are the updates accomplished?
f. How are the system functionality is appropriately tested before changes go into production?
g. Will CCU play a role in reviewing and approving changes?
h. Are there any dashboards to display system performance and health in real time?
7. Provide detailed information regarding browser requirements for the proposed solution to meet the functionality and system requirements, including any specific required versions and/or add-ins.
8. Describe the mobile capabilities available a. Please indicate supported mobile platforms.
with the proposed solution b. Please describe implementation of mobile capabilities (i.e. mobile-enabled, apps, etc.)
c. Please explain how and when mobile updates provided.
d. Please explain how you ensure that all mobile interfaces to your solution comply with disability accessibility requirements such as Section 508 and/or WCAG2.0.
9. Does the solution provide data exports for upload to CCU systems? If so, please describe the types of information exported and the process employed.
10. Does the solution have the ability to automate data importing and exporting?
11. Does the solution come with a comprehensive data dictionary of the database?
12. Identity Management System a. If the solution integrates with identity management systems, please describe the delivery mechanism of this component.
b. Does the solution offer capabilities to use Azure ADFS. If not, then what do you offer?
c. Please describe the SSO implementation requirements.
d. Does the solution deliver an API that would allow for the remote management of user authorization data? If yes, please describe how.
13. Please describe the ongoing functions to be performed by CCU system and application administrators? Does the solution need a full-time staff member to be administered?
14. What is the maximum number of logged in concurrent users can the solution support? How does the system define concurrent users?
Data Governance and Security - Interface Data Exchange Requirements CCU Office of ITS/CIO
Transfer of data will must be accomplished only via using secure methods such as, but not limited to HTTPS and SSH/SFTP. Offerors must provide secure file transfer solutions and may recommend alternative processes if they would be beneficial to CCU. Alternatives must be described in detail and are subject to CCU's approval. For all proposed transmission methods, the offerors must provide the technical requirements, processing transactions, a detailed description of security and authorization processes and requirements, forms, encryption or authentication requirements, and devices or digital certificates, alternatives available if the standard transmission method fails, plus a disclosure on any software limitations on file sizes or numbers of records in a batch.
Requirements should reflect delivered/”out-of-the-box” functionality. Offerors must indicate if system modifications, additional product or costs or if any other accommodations would be necessary to meet any requirement. Additional costs customizations or upgrades must be provided in details.
Technical Interface Data Exchange
1. Please indicate the offeror’s acceptance and compliance with the high-level Interface Data Exchange requirements outlined above, including the understanding that the Interface Data Exchange may require additional requirements and that the proposed solution considers this task and the resulting work in-scope. Indicate any areas of noncompliance or other concerns with these requirements.
2. Please provide details on security protections for the Interface Data Exchange that are afforded by the solution proposed?
3. Does your solution support the needs for sharing and linking data with other applications and databases?
4. Does the system seamlessly integrate with One Card Systems, specifically CBORD? If not, what are the associated costs (e.g., technology and staff resources) to ensure integration with
CBORD?
5. The proposed solution must interface with an online payment processing gateway for eCommerce services such as online payments. The proposed solution must be able to interface seamlessly with the University’s payment card processor “FirstData/SunTrust Payment Gateway”.
The solution should utilize the University’s login as referenced in Appendix M Question 15 and TouchNet payment systems.
a. Is the proposed solution an existing FirstData/SunTrust partner?
b. If not an existing FirstData/SunTrust Ready Partner:
i. Can the solution integrate with the FirstData/SunTrust platform at the Offeror’s expense? A time frame for accomplishing this integration must be provided.
ii. Does the solution currently have an existing website for accepting payments?
If so, please provide that URL and assurances that it is PCI-DSS compliant.
iii. Does this solution use a third-party application for accepting payments? If so, who is the third-party service provider of the application, and provide assurance that the application is PA-DSS compliant.
c. What other Payment Gateways does the Offeror partner with (e.g. TouchNet, NelNet, etc.)
6. If integration with University ERP (Ellucian Colleague – Unidata database-based) is requested, is there an existing/”out-of-the-box interface with the ERP, or would a custom interface need to be developed? Please provide details of any additional costs for seamless integration.
7. Does the solution allow easy secure integration with other applications including desktop tools (i.e. Microsoft Office Professional Suite (Word, Excel, PowerPoint, Access Dataset)?
8. Does the solution provide for auto/mass load of new and existing records (including ID records), matching on IDs where necessary (non-ID records) to obtain data from external sources? Users MUST be able to perform the load, preview it online, and set additional rules before committing it to the database. It is preferable that a wizard or other user aid be available for this purpose. Some "uploads" may be updating existing records.
File details come from the government source that posted it. Updated .