OCHCA_Vendor_Questionnaire-_SAAS-Cloud-No_PHI.xlsx

XLSX spreadsheet 214 KB Posted

Attached to
Sanction Screening Services State and local contract opportunity
Solicitation number
IFB NO. 042-2921902-VC
Issued by
Orange County, San Diego City, California

About this file

The document is an IT Cyber Security Questionnaire from the Orange County Health Care Agency (OCHCA) for a Sanction Screening Services procurement. The solicitation seeks a web-based platform for comprehensive screenings against federal and state exclusion lists, requiring electronic screening of employees, physicians, and vendors through monthly and single-name checks. Electronic proposals are due by November 7, 2025, at 4:00 pm, with bids remaining valid for 365 days. All questions must be submitted by October 31, 2025, before 4:00 pm, and the procurement allows for multiple awards or rejection of submissions.

The procurement offers preferences for Local Small Businesses (OCLSB) and Disabled Veteran Business Enterprises (DVBE), potentially providing a 5% bid price reduction for certified businesses. Bidders must be registered with the California Secretary of State, possess a valid DUNS number and Unique Entity Identifier (UEI), and comply with various certification requirements. The detailed IT Cyber Security Questionnaire requires extensive information about data handling, encryption, access management, and security protocols, indicating a rigorous technological evaluation process. While specific budget ranges are not explicitly stated, the solicitation includes a pricing structure with an annual portal access fee covering unlimited user accounts, training sessions, and customer support, along with additional fees for various screening services.

View the file

Other files for this state and local contract opportunity

Other files attached to Sanction Screening Services, newest first.
File Type Posted
Sanction_Screening_Services.pdf PDF
Sanction_Screening_Services.pdf PDF
Model_Contract_-_Sanction_Screening_-_IFB-042-2921902.pdf PDF
Model_Contract_-_Sanction_Screening_-_IFB-042-2921902.pdf PDF
OCHCA_Vendor_Questionnaire-_SAAS-Cloud-No_PHI.xlsx XLSX spreadsheet
Performance_Bond.pdf PDF
Performance_Bond.pdf PDF
Labor_and_Material_Payment_Bond.pdf PDF
Labor_and_Material_Payment_Bond.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Sheet1 VENDOR: Complete all items on this sheet unless instructed otherwise. Instructions are provided via comments at the top of each column.

ORANGE COUNTY HEALTH CARE AGENCY

IT CYBER SECURITY QUESTIONNAIRE

DATE COMPLETED:
COMPLETED BY:
1. Vendor Company Info
IDInformation RequestedVendor's ResponseComments/Additional Information
VCI.1.0Company Name
VCI.1.1Company Headquarters Location
VCI.1.2Website URL
VCI.1.3Application name
VCI.1.4Version Number
VCI.1.5Release date
VCI.1.6Please describe in detail the business functions your application supports/provides
VCI.1.7Vendor Contact Name
VCI.1.8Vendor Contact Title
VCI.1.9Vendor Contact Department
VCI.1.10Vendor Contact Office Phone
VCI.1.11Vendor Contact Cell Phone
VCI.1.12Vendor Contact Email
VCI.1.13Vendor IT Contact Name
VCI.1.14Vendor IT Contact Office Phone
VCI.1.15Vendor IT Contact Cell Phone
VCI.1.16Vendor IT Contact Email
VCI.1.17Vendor Emergency Contact Name
VCI.1.18Vendor Emergency Contact Office Phone
VCI.1.19Vendor Emergency Contact Cell Phone
VCI.1.20Vendor Emergency Contact Email
VCI.1.21Vendor Support Number
VCI.1.22Vendor Support Email
VCI.1.23Vendor certifications/Accreditations/Reports (These pertain to certifications, accreditations, reports that you, as the vendor holds, not one of your providers such as AWS, or Azure, etc.)
VCI.1.24Does your application use a data center in the cloud? (e.g. AWS Data Center, MS Azure Data Center, etc.)
VCI.1.25List the regions your cloud storage resides, that will be housing HCA data. (Western U.S., Eastern U.S., Canada, Europe, Asia, etc…)
VCI.1.26Will vendor staff, that have access to HCA data, be located in the U.S.?
VCI.1.27Have you implemented a DLP, (Data Loss Prevention), system on your network?
VCI.1.28Is Gen AI utilized for any aspects of the work performed for the County of Orange?
2. General Security Requirements
IDRequirements/GuidelinesInformation RequestedVendor's ResponseComments/Additional Information
GSR.1.0ISO/IEC 27002 is an international standard that provides guidance for organizations looking to establish, implement, and improve an Information Security Management System (ISMS) focused on cybersecurity. While ISO/IEC 27001 outlines the requirements for an ISMS, ISO/IEC 27002 offers best practices and control objectives related to key cybersecurity aspects including access control, cryptography, human resource security, and incident response. The standard serves as a practical blueprint for organizations aiming to effectively safeguard their information assets against cyber threats. By following ISO/IEC 27002 guidelines, companies can take a proactive approach to cybersecurity risk management and protect critical information from unauthorized access and loss.Does your application system meet the general security standards based upon ISO/IEC 27002?
GSR.1.1Select the frameworks used specific to your application(s)
GSR.1.2Will the vendor process, transmit, store or have access to any of OCHCA's data?
GSR.1.3What type of data are you handling for OCHCA? Select all that apply.
GSR.1.4Does your application run on an operating system that is consistently and currently supported by the operating systems vendor? [Applications under maintenace are expected to always be current in regards to the current version of the relevant operating system.]
GSR.1.5Applications hosted by OCHCA routinely apply patches to both the operating system and subsystems as updated releases are available from the operating system vendor and/or any third party vendors. Do you keep your software current and compatible with such updated releases in order for the application to operate in this environment?
GSR.1.6Do you provide timely updates to address any applicable security vulnerabilities found in the application? Please describe using the Comments/Additional Information column.
GSR.1.7OCHCA uses a variety of monitoring tools to assess and manage the health and performance of our application server, network connectivity, power, etc. Does your application function appropriately while monitoring tools are actively running?
GSR.1.8All application services must run as a true service and not require a user to be logged into the application for these services to continue to be active.

If you require an application service, is this true for your application?

[OCHCA will provide an account with the appropriate security level to log on as a service, and an account with the appropriate administrative rights to administer the application. The account password must periodically expire per OCHCA IT Security Services Policy & Procedures.]

GSR.1.9If Applicable, you will need to embed/Submit your SDLC (Software Development Life Cycle) Policy/Process within this document, or send separately.If software is developed in-house, do you have a formal SDLC process?
3. Information Security
IDRequirements/GuidelinesInformation RequestedVendor's ResponseComments/Additional Information
IS.1.32Do you encrypt confidential information on removable media?

Please select all forms of removable media where confidential information is always encrypted.

Always Encrypted:

IS.1.33 How long will your organization retain our confidential information? Less than:

4. Access Management
IDRequirements/GuidelinesInformation RequestedVendor's ResponseComments/Additional Information
AM.1.0Identity and access management (IAM) is a framework of business processes, policies and technologies that facilitates the management of electronic or digital identities. With an IAM framework in place, information technology (IT) managers can control user access to critical information within their organizations. Least privilege, RBAC, zero trust networks, regular account audits/reviews, usage logging/reporting.Do you have an Identity and Access Management (IAM) control process?
AM.1.1Is the user authenticated to the application?
AM.1.2Does the application support integration with enterprise identity management systems? If yes, indicate the compatible systems.
AM.1.3If there is no integration with enterprise identy management systems, please describe the access account creation and requirements (Username and password, minimum length, and complexity requirements).
AM.1.4Is the application compatible with alternative authentication mechanisms (e.g. certificates, token, biometric, MFA, etc.?)
AM.1.5Can access be defined based on the user’s job role, (Role-based Access Controls)?
AM.1.6Can the Application generate a report of all users and their roles?
AM.1.7Does the application have the option to force new users to change their password upon first login?
AM.1.8Can the user change their password at any time?
AM.1.9Can the system administrator enforce password policy and/or complexity such as minimum length, numbers and alphabet requirements, and upper and lower case letters, etc.?
AM.2.0Can the application be set to automatically lock a user’s account after a predetermined number of consecutive unsuccessful logon attempts?
AM.2.1Can the application be set to automatically log a user off the application after a predefined period of inactivity?
AM.2.2Can the application support the removal of user’s access privileges without requiring the deletion of the user account?
AM.2.3Are there default vendor test logins and/or system administrator passwords in the product?
5. Audit Capabilities
IDRequirements/GuidelinesInformation RequestedVendor's ResponseComments/Additional Information
AC.1.1Does this application have the ability to generate audit logs?
AC.1.2Does this application capture user access activity such as successful logon, logoff, and unsuccessful logon attempts? If yes, list the data elements contained in the audit log in the comments section to the right.
AC.1.3Does this application capture data entries, changes, and deletions? If yes, list the data elements contained in the audit log in the comments section to the right
AC.1.4Does the application time stamp for audit log entries synchronize with other applications and systems using NTP/SNTP?
AC.1.5Can the audit log “data” be exported from the application for further processing (e.g. storage, analysis)?
AC.1.6Are the audit log files protected from unauthorized alteration? If yes, please describe the protections in the comment section to the right.
AC.1.7Does the application allow a system administrator to set the inclusion or exclusion of audited events based on organizational policy and operating requirements or limits?
AC.1.8Can the application continue normal operation even when the security audit capability is non-functional? (For example, if the audit log reaches capacity, the application should continue to operate and should suspend logging, start a new log, or begin overwriting the existing log)
6. Other Capabilities
IDRequirements/GuidelinesInformation RequestedVendor's ResponseComments/Additional Information
OC.1.1Does the application maintain a journal of transactions or snapshots of data between backup intervals?
OC.1.2Does the application have the ability to run a backup concurrently with the operation of the application?
OC.1.3Does the application include documentation that explains error messages to users and system administrators and the actions that are required?
OC.1.4Does the application’s client software operate without requiring the user to have local administrator level rights in order to run the application?
OC.1.5Describe how updates to the application are typically handled and how the application is certified to perform as intended with updates to the operating system and other helper applications (such as service packs and hot fixes and how the customer is notified)
OC.1.6Does your application come with a Service Level Agreement (SLA)? If yes, please describe any guaranteed response times associated with the SLA in the comments section to the right.
OC.1.7Does your application undergo third-party application security testing? If yes, please describe the frequency, (Once a year, after a major version release, etc.). ALSO, SUBMIT THE LATEST PEN TEST RESULTS AND ANY CORRECTIVE ACTIONS TAKEN.
7. Support Functionality
IDRequirements/GuidelinesInformation RequestedVendor's ResponseComments/Additional Information
SF.1.1How are you supporting this Application? (Use Comments section to describe in more detail)
SF.1.2Is remote access a functionality that is built into the application itself? If yes, please describe the security related with the remote access in the comment section to the right.
SF.1.3If requested, can the application associate remote support activities with an individual employee of the vendor?
SF.1.4If applicable, do vendor support personnel have specific roles and accesses that control access to sensitive data within the application?
SF.1.5Does the application audit remote support connection attempts and remote support actions such as application or configuration modifications?
SF.1.6Does the application require remote access by the vendor for any routine maintenance? Explain in comments to the right, the type of remote access needed.
PLEASE READ-If your company has a SOC 2 Type 2, HITRUST CSF, or FedRAMP certification, STOP here. Questionnaire is COMPLETE. (Certifications from your 3rd Party vendors do not count)You must provide a current copy of the certification for verification.Comments/Additional Information
Information Security Audit
ISA.1.2Does your organization have a policy or process for conducting risk assessments?
ISA.1.3Please attach/embed the Information Security policy in the Comment column.Does your organization have a documented information security policy?
ISA.1.5Does your organization use computers and/or computer networks in conjunction with the delivery of the contracted services?
ISA.1.6Does your organization ever use encryption technology to protect client confidential information in storage or transit?
ISA.1.8Does your organization have a formal change management policy or process for the management of changes to the production environment?
ISA.1.9Does your organization have an incident response policy or process?
ISA.1.10Does your organization have a formal business continuity plan?
ISA.1.11Does the scope of the Risk Assessment include the people, processes, and technology responsible for the products and services you provide under your contract with us?
ISA.1.12What was the date of completion of your organization's most recent risk assessment?mm/dd/yyyy
ISA.1.13Please attach/embed control development and risk acceptance documentation.Has management addressed all unmitigated and under-mitigated risks identified during the Risk Assessment by developing and implementing controls and/or documenting risk-acceptance decisions?
ISA.1.15Does your organization follow and enforce compliance with its policies?
ISA.1.16Are policies reviewed, updated if necessary, and approved annually?

If you respond "No," please use the Comment column to explain and put the frequency/conditions under which they are reviewed and approved.

ISA.1.17 Who approves the Information Security policies?

If you select "Other," please put the title in the Comment column.

ISA.1.18Are policies communicated to all applicable staff? Please select all conditions under which policies are communicated.
ISA.1.23Please attach/embed the respective P&P.Does your organization engage one or more qualified, independent parties to audit and or assess its information security program? Please list the parties in the Comment column.
ISA.1.34Please attach/embed the respective Policy & Procedure in the Comment column.Are all workers, including employees, contractors, and consultants, who have access to our confidential information, bound by a confidentiality agreement that requires them to keep the information confidential?
ISA.1.35Please attach/embed the respective Policy & Procedure in the Comment column.Do your workers' employment agreements or contracts obligate them to adhere to your organization's policies, including information security policies?
ISA.1.36Do all workers attest that they have read, understand, and will abide by the security policies?
ISA.1.37Please attach/embed the respective Policy and Procedures in the Comment column.Does your organization run comprehensive background checks including criminal (local, county, State, Province, National), work verification, social security number verification, credit check, address verification, professional licensing, Sex Offender Registry checks, and Terrorist Watch List Checks? Use the Comment column to list any of the above-listed checks that are NOT performed.
ISA.1.38Please attach/embed the respective Policy and Procedures in the Comment column.Does your organization require all new hires to undergo drug testing?
ISA.1.39Please attach/embed the respective Policy and Procedures in the Comment column.Are all workers trained on the security policies that apply to their role within the organization?
ISA.1.40Please attach/embed the respective Policy and Procedures in the Comment column.Do you provide information security awareness training to help promote responsible information handling, proper selection and use of passwords, safe Internet browsing habits, and ethical e-mail practices?
ISA.1.41Please attach/embed the respective Policy and Procedures in the Comment column.Do you train workers on the security responsibilities specific to their roles?
ISA.1.42Please attach/embed the respective Policy and Procedures in the Comment column.Do you provide training specific to applicable regulatory obligations?
ISA.1.43Please attach/embed the respective Policy and Procedures in the Comment column.Do workers undergo all applicable training upon hire and at least annually thereafter?
ISA.1.59Please attach/embed a copy of your network diagram in the Comment column.Does your organization maintain a computer network diagram?
ISA.1.60Is your network diagram accurate and complete?
ISA.1.69Please attach/embed the respective Policy and Procedures in the Comment column.What types of checks are performed on systems that connect to your network to ensure that they comply with your policies?
ISA.1.70Please select the responses that best reflects your use of network-based Intrusion Detection (IDS) and/or Intrusion Prevention (IPS) solutions.
ISA.1.71Please select, by category, the network services your organization exposes over the Internet or untrusted networks FOR THE PURPOSES OF EXCHANGING CONFIDENTIAL INFORMATION or PERFORMING APPLICATIONS, SYSTEMS OR NETWORK ADMINISTRATION. Select all that apply.
ISA.1.73Please select the response or responses that best describe the ways workers can connect to the computing environment remotely. Select all that apply.
ISA.1.74Does your remote access solution support split tunneling?
ISA.1.75Is two factor authentication required for remote access?
ISA.1.76Are all systems configured to use the same, synchronized time, for example NTP?
ISA.1.77Please attach/embed the respective Policy and Procedures in the Comment column.Does your organization have a repeatable system build process?
ISA.1.78Are your systems security hardened in accordance with industry standards or other publications on system hardening?
ISA.1.79Please attach/embed the respective Policy and Procedures in the Comment column.How soon does your organization apply security patches following their publication?
ISA.1.80Please attach/embed the respective Policy and Procedures in the Comment column.How quickly after publication does your organization apply antivirus updates?
ISA.1.81Please attach/embed the respective Policy and Procedures in the Comment column.Is encryption always used to protect client confidential information at rest.
ISA.1.82Please attach/embed the respective Policy and Procedures in the Comment column.Is client confidential information always encrypted in transit over the Internet and untrusted networks?
ISA.1.83Please attach/embed the respective Policy and Procedures in the Comment column.What SSL/TLS Versions are in use by your organization? Select all that apply.
ISA.1.84What versions of SSH are in use by your organization? Select all that apply.
ISA.1.85All accounts must follow a formal activation and deactivation policy and procedure. An established and adhered to timeline and process must exist for provisioning and deprovisioning accounts.Are there procedures for provisioning and deprovision of accounts?
ISA.1.86All user accounts must have the ability to log activity and be audited to identify out of scope operations. Privileged accounts must have a higher degree of insight and logging/reporting/reviews.Are user accounts audited on a regular basis?
ISA.1.87Policies, procedures, and monitoring regarding the use of GenAI need to be in place to ensure the Confidentiality, Integrity and Availability of County operations, data, and security.If Gen AI is utilized for any aspects of the work performed for the County of Orange, then embed/submit your policy.
ISA.1.88Please provide a Yes or No answer, a narrative, and policy. The classification and lifecycle of County data must be commensurate with County standards (access, data protection, management, etc.). No unauthorized access or exfiltration is permitted.Do you have Data Classification Handling policy & procedures in place?
ISA.1.89Please provide a Yes or No answer, a narrative, and policy. System data is retained only for as long as is required by contract. Data will be destroyed or returned at the end of the retention period. Data will be rendered unreadable through a verified data removal/destruction process (physical drive destruction/degaussing).Do you have Data Retention and destruction policies in place?
ISA.1.90Please provide a Yes or No answer, a narrative, and policy. All external connectivity to the network and environment that houses County data and functionality must be protected (MFA, encryption, VPN-IPsec, etc.).Are remote connections to your network granted via a formal request/approval policy and utilize a secure/encrypted communication pathway (VPN, RDP, etc.)?

ISO27001

HITRUST CSF

FedRamp Other - List in next column

SOC 2 TYPE 2 REPORT

AWS Data Center Azure Data Center Iron Mountain Data Center Other - List in next column

NIST 800-53 R4/5

NIST SP 800-66 R1

COBIT 4/5

PCI

OTHER - list in next column

OWASP

ePHI

PII

PCI

PUBLIC

PHI (Paper) Backup Tapes/Devices Writable CD-ROM Disks USB Storage Devices Other Removable Media We do not encrypt removable media 30 days from receipt 90 days from receipt One year from receipt More than one year from receipt Until termination of agreement Until termination of agreement plus 1 year Until termination of agreemnt plus 7 years Returned upon client request Disposed of upon client request Confidential information is retained in perpetuity (forever) Confidential information is not retained Other Per contract terms

CEO

CISO

ISO

Compliance Officer Other Upon hire Upon policy change Annually Every other year Never Host MAC address authenticated Host cryptographically authenticated as under the management of your organization (for example, 802.1x) Current anti-virus verification Current patch-level verification Local firewall configuration verification Other We do not utilize a NAC solution We have an IDS solution that detects but cannot prevent intrusion attempts We have an IPS solution that detects and attempts to prevent instrusion attempts Our IDS or IPS is deployed at our network perimeter Our IDS or IPS is deployed within our DMZs and other Internet-facing and untrusted network-facing sub-nets Our IDS or IPS is deployed on all network segments, including internal network segments Other We do not use an IDS or IPS Encrypted end-user services (HTTPS, IP-SEC, SFTP, FTPS) Expected clear-text services (DNS, SMTP, NTP, HTTP) Encrypted management services (SSH, RDP) Clear-text management services (telnet, SNMP, SMB, RPC) Others N/A - confidential information is not transmitted electronically

IP-SEC VPN

SSL-VPN

Terminal Services (RDP)

SSH

Other remote desktop control applications Other None - remote access is never allowed 7 days or less 21 - 28 days Less quickly than 28 days from publication Within an hour Within a day Within a week Less quickly than one week Other Never - our organization does not update its antivirus definitions SSLv2 SSLv310 TLSv1.0 TLSv1.1 TLSv1.2 N/A - SSL/TLS not in use SSHv1 SSHv2 N/A - SSH not in use

LDAP

Directory Services Kerberos

SSO

Others (Use comments section to list) Certificates Token Biometric

MFA\2FA

Other (List in comments section) Onsite Support Remote access (Explain in detail in comments) Email/Phone Support Non-Sensitive None Other (Use Comment section for details) Google Drive OneDrive List regions in Comments section Yes NO (Use Comments section to list location(s) Yes No Yes No Yes No Yes No Yes No Yes No Yes (Submit or embed policy) No (Use comments section to explain) Yes No Yes No YES (Describe process in Comments section) No Yes No N/A Yes (Submit or embed policy. Or, use comments for details) No (Use comments section to explain) Yes No Yes No N/A See comments section Yes If yes, select type:

No Yes (List roles in comments) No Yes No Yes Yes No N/A due to AD integration or SSO No Yes No Yes No Yes No N/A due to AD integration or SSO N/A due to AD integration or SSO Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes (List the data elements in the comments section) No Yes (List the data elements in the comments section) No Yes (Describe the protections in the comments section) No Yes No Yes No Yes No Yes No Yes (Details in the comments section) No Yes (SLA response times listed in the comments section) No Yes No N/A Yes No N/A Yes No N/A Yes No N/A Yes (Explain in comments) No Yes (Describe security controls in the comments section) No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No N/A Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes (embed or submit policy) No Yes (embed or submit policy) No Yes (embed or submit policy) No Yes (embed or submit policy) No Yes (embed or submit policy) No We do not use Gen AI for any aspects of support in this contract Policy embeded or submitted Group Box 805 TLSv1.3 Metadata De-identified PHI/PII None

Sheet2 image1.jpeg

File details come from the government source that posted it. Updated .