OCHCA_Vendor_Questionnaire-_SAAS-Cloud-No_PHI.xlsx
XLSX spreadsheet 214 KB Posted
- Attached to
- Sanction Screening Services State and local contract opportunity
- Solicitation number
- IFB NO. 042-2921902-VC
- Issued by
- Orange County, San Diego City, California
About this file
The document is an IT Cyber Security Questionnaire from the Orange County Health Care Agency (OCHCA) for a Sanction Screening Services procurement. The solicitation seeks a web-based platform for comprehensive screenings against federal and state exclusion lists, requiring electronic screening of employees, physicians, and vendors through monthly and single-name checks. Electronic proposals are due by November 7, 2025, at 4:00 pm, with bids remaining valid for 365 days. All questions must be submitted by October 31, 2025, before 4:00 pm, and the procurement allows for multiple awards or rejection of submissions.
The procurement offers preferences for Local Small Businesses (OCLSB) and Disabled Veteran Business Enterprises (DVBE), potentially providing a 5% bid price reduction for certified businesses. Bidders must be registered with the California Secretary of State, possess a valid DUNS number and Unique Entity Identifier (UEI), and comply with various certification requirements. The detailed IT Cyber Security Questionnaire requires extensive information about data handling, encryption, access management, and security protocols, indicating a rigorous technological evaluation process. While specific budget ranges are not explicitly stated, the solicitation includes a pricing structure with an annual portal access fee covering unlimited user accounts, training sessions, and customer support, along with additional fees for various screening services.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| Sanction_Screening_Services.pdf | ||
| Sanction_Screening_Services.pdf | ||
| Model_Contract_-_Sanction_Screening_-_IFB-042-2921902.pdf | ||
| Model_Contract_-_Sanction_Screening_-_IFB-042-2921902.pdf | ||
| OCHCA_Vendor_Questionnaire-_SAAS-Cloud-No_PHI.xlsx | XLSX spreadsheet | |
| Performance_Bond.pdf | ||
| Performance_Bond.pdf | ||
| Labor_and_Material_Payment_Bond.pdf | ||
| Labor_and_Material_Payment_Bond.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Sheet1 VENDOR: Complete all items on this sheet unless instructed otherwise. Instructions are provided via comments at the top of each column.
ORANGE COUNTY HEALTH CARE AGENCY
IT CYBER SECURITY QUESTIONNAIRE
| DATE COMPLETED: | |||
| COMPLETED BY: | |||
| 1. Vendor Company Info | |||
| ID | Information Requested | Vendor's Response | Comments/Additional Information |
| VCI.1.0 | Company Name | ||
| VCI.1.1 | Company Headquarters Location | ||
| VCI.1.2 | Website URL | ||
| VCI.1.3 | Application name | ||
| VCI.1.4 | Version Number | ||
| VCI.1.5 | Release date | ||
| VCI.1.6 | Please describe in detail the business functions your application supports/provides | ||
| VCI.1.7 | Vendor Contact Name | ||
| VCI.1.8 | Vendor Contact Title | ||
| VCI.1.9 | Vendor Contact Department | ||
| VCI.1.10 | Vendor Contact Office Phone | ||
| VCI.1.11 | Vendor Contact Cell Phone | ||
| VCI.1.12 | Vendor Contact Email | ||
| VCI.1.13 | Vendor IT Contact Name | ||
| VCI.1.14 | Vendor IT Contact Office Phone | ||
| VCI.1.15 | Vendor IT Contact Cell Phone | ||
| VCI.1.16 | Vendor IT Contact Email | ||
| VCI.1.17 | Vendor Emergency Contact Name | ||
| VCI.1.18 | Vendor Emergency Contact Office Phone | ||
| VCI.1.19 | Vendor Emergency Contact Cell Phone | ||
| VCI.1.20 | Vendor Emergency Contact Email | ||
| VCI.1.21 | Vendor Support Number | ||
| VCI.1.22 | Vendor Support Email | ||
| VCI.1.23 | Vendor certifications/Accreditations/Reports (These pertain to certifications, accreditations, reports that you, as the vendor holds, not one of your providers such as AWS, or Azure, etc.) |
| VCI.1.24 | Does your application use a data center in the cloud? (e.g. AWS Data Center, MS Azure Data Center, etc.) | |||
| VCI.1.25 | List the regions your cloud storage resides, that will be housing HCA data. (Western U.S., Eastern U.S., Canada, Europe, Asia, etc…) | |||
| VCI.1.26 | Will vendor staff, that have access to HCA data, be located in the U.S.? | |||
| VCI.1.27 | Have you implemented a DLP, (Data Loss Prevention), system on your network? | |||
| VCI.1.28 | Is Gen AI utilized for any aspects of the work performed for the County of Orange? | |||
| 2. General Security Requirements | ||||
| ID | Requirements/Guidelines | Information Requested | Vendor's Response | Comments/Additional Information |
| GSR.1.0 | ISO/IEC 27002 is an international standard that provides guidance for organizations looking to establish, implement, and improve an Information Security Management System (ISMS) focused on cybersecurity. While ISO/IEC 27001 outlines the requirements for an ISMS, ISO/IEC 27002 offers best practices and control objectives related to key cybersecurity aspects including access control, cryptography, human resource security, and incident response. The standard serves as a practical blueprint for organizations aiming to effectively safeguard their information assets against cyber threats. By following ISO/IEC 27002 guidelines, companies can take a proactive approach to cybersecurity risk management and protect critical information from unauthorized access and loss. | Does your application system meet the general security standards based upon ISO/IEC 27002? | ||
| GSR.1.1 | Select the frameworks used specific to your application(s) | |||
| GSR.1.2 | Will the vendor process, transmit, store or have access to any of OCHCA's data? | |||
| GSR.1.3 | What type of data are you handling for OCHCA? Select all that apply. | |||
| GSR.1.4 | Does your application run on an operating system that is consistently and currently supported by the operating systems vendor? [Applications under maintenace are expected to always be current in regards to the current version of the relevant operating system.] | |||
| GSR.1.5 | Applications hosted by OCHCA routinely apply patches to both the operating system and subsystems as updated releases are available from the operating system vendor and/or any third party vendors. Do you keep your software current and compatible with such updated releases in order for the application to operate in this environment? | |||
| GSR.1.6 | Do you provide timely updates to address any applicable security vulnerabilities found in the application? Please describe using the Comments/Additional Information column. | |||
| GSR.1.7 | OCHCA uses a variety of monitoring tools to assess and manage the health and performance of our application server, network connectivity, power, etc. Does your application function appropriately while monitoring tools are actively running? | |||
| GSR.1.8 | All application services must run as a true service and not require a user to be logged into the application for these services to continue to be active. |
If you require an application service, is this true for your application?
[OCHCA will provide an account with the appropriate security level to log on as a service, and an account with the appropriate administrative rights to administer the application. The account password must periodically expire per OCHCA IT Security Services Policy & Procedures.]
| GSR.1.9 | If Applicable, you will need to embed/Submit your SDLC (Software Development Life Cycle) Policy/Process within this document, or send separately. | If software is developed in-house, do you have a formal SDLC process? | ||
| 3. Information Security | ||||
| ID | Requirements/Guidelines | Information Requested | Vendor's Response | Comments/Additional Information |
| IS.1.32 | Do you encrypt confidential information on removable media? |
Please select all forms of removable media where confidential information is always encrypted.
Always Encrypted:
IS.1.33 How long will your organization retain our confidential information? Less than:
| 4. Access Management | ||||
| ID | Requirements/Guidelines | Information Requested | Vendor's Response | Comments/Additional Information |
| AM.1.0 | Identity and access management (IAM) is a framework of business processes, policies and technologies that facilitates the management of electronic or digital identities. With an IAM framework in place, information technology (IT) managers can control user access to critical information within their organizations. Least privilege, RBAC, zero trust networks, regular account audits/reviews, usage logging/reporting. | Do you have an Identity and Access Management (IAM) control process? | ||
| AM.1.1 | Is the user authenticated to the application? | |||
| AM.1.2 | Does the application support integration with enterprise identity management systems? If yes, indicate the compatible systems. | |||
| AM.1.3 | If there is no integration with enterprise identy management systems, please describe the access account creation and requirements (Username and password, minimum length, and complexity requirements). | |||
| AM.1.4 | Is the application compatible with alternative authentication mechanisms (e.g. certificates, token, biometric, MFA, etc.?) | |||
| AM.1.5 | Can access be defined based on the user’s job role, (Role-based Access Controls)? | |||
| AM.1.6 | Can the Application generate a report of all users and their roles? | |||
| AM.1.7 | Does the application have the option to force new users to change their password upon first login? | |||
| AM.1.8 | Can the user change their password at any time? | |||
| AM.1.9 | Can the system administrator enforce password policy and/or complexity such as minimum length, numbers and alphabet requirements, and upper and lower case letters, etc.? | |||
| AM.2.0 | Can the application be set to automatically lock a user’s account after a predetermined number of consecutive unsuccessful logon attempts? | |||
| AM.2.1 | Can the application be set to automatically log a user off the application after a predefined period of inactivity? | |||
| AM.2.2 | Can the application support the removal of user’s access privileges without requiring the deletion of the user account? | |||
| AM.2.3 | Are there default vendor test logins and/or system administrator passwords in the product? | |||
| 5. Audit Capabilities | ||||
| ID | Requirements/Guidelines | Information Requested | Vendor's Response | Comments/Additional Information |
| AC.1.1 | Does this application have the ability to generate audit logs? | |||
| AC.1.2 | Does this application capture user access activity such as successful logon, logoff, and unsuccessful logon attempts? If yes, list the data elements contained in the audit log in the comments section to the right. | |||
| AC.1.3 | Does this application capture data entries, changes, and deletions? If yes, list the data elements contained in the audit log in the comments section to the right | |||
| AC.1.4 | Does the application time stamp for audit log entries synchronize with other applications and systems using NTP/SNTP? | |||
| AC.1.5 | Can the audit log “data” be exported from the application for further processing (e.g. storage, analysis)? | |||
| AC.1.6 | Are the audit log files protected from unauthorized alteration? If yes, please describe the protections in the comment section to the right. | |||
| AC.1.7 | Does the application allow a system administrator to set the inclusion or exclusion of audited events based on organizational policy and operating requirements or limits? | |||
| AC.1.8 | Can the application continue normal operation even when the security audit capability is non-functional? (For example, if the audit log reaches capacity, the application should continue to operate and should suspend logging, start a new log, or begin overwriting the existing log) | |||
| 6. Other Capabilities | ||||
| ID | Requirements/Guidelines | Information Requested | Vendor's Response | Comments/Additional Information |
| OC.1.1 | Does the application maintain a journal of transactions or snapshots of data between backup intervals? | |||
| OC.1.2 | Does the application have the ability to run a backup concurrently with the operation of the application? | |||
| OC.1.3 | Does the application include documentation that explains error messages to users and system administrators and the actions that are required? | |||
| OC.1.4 | Does the application’s client software operate without requiring the user to have local administrator level rights in order to run the application? | |||
| OC.1.5 | Describe how updates to the application are typically handled and how the application is certified to perform as intended with updates to the operating system and other helper applications (such as service packs and hot fixes and how the customer is notified) | |||
| OC.1.6 | Does your application come with a Service Level Agreement (SLA)? If yes, please describe any guaranteed response times associated with the SLA in the comments section to the right. | |||
| OC.1.7 | Does your application undergo third-party application security testing? If yes, please describe the frequency, (Once a year, after a major version release, etc.). ALSO, SUBMIT THE LATEST PEN TEST RESULTS AND ANY CORRECTIVE ACTIONS TAKEN. | |||
| 7. Support Functionality | ||||
| ID | Requirements/Guidelines | Information Requested | Vendor's Response | Comments/Additional Information |
| SF.1.1 | How are you supporting this Application? (Use Comments section to describe in more detail) | |||
| SF.1.2 | Is remote access a functionality that is built into the application itself? If yes, please describe the security related with the remote access in the comment section to the right. | |||
| SF.1.3 | If requested, can the application associate remote support activities with an individual employee of the vendor? | |||
| SF.1.4 | If applicable, do vendor support personnel have specific roles and accesses that control access to sensitive data within the application? | |||
| SF.1.5 | Does the application audit remote support connection attempts and remote support actions such as application or configuration modifications? | |||
| SF.1.6 | Does the application require remote access by the vendor for any routine maintenance? Explain in comments to the right, the type of remote access needed. | |||
| PLEASE READ-If your company has a SOC 2 Type 2, HITRUST CSF, or FedRAMP certification, STOP here. Questionnaire is COMPLETE. (Certifications from your 3rd Party vendors do not count) | You must provide a current copy of the certification for verification. | Comments/Additional Information | ||
| Information Security Audit | ||||
| ISA.1.2 | Does your organization have a policy or process for conducting risk assessments? | |||
| ISA.1.3 | Please attach/embed the Information Security policy in the Comment column. | Does your organization have a documented information security policy? | ||
| ISA.1.5 | Does your organization use computers and/or computer networks in conjunction with the delivery of the contracted services? | |||
| ISA.1.6 | Does your organization ever use encryption technology to protect client confidential information in storage or transit? | |||
| ISA.1.8 | Does your organization have a formal change management policy or process for the management of changes to the production environment? | |||
| ISA.1.9 | Does your organization have an incident response policy or process? | |||
| ISA.1.10 | Does your organization have a formal business continuity plan? | |||
| ISA.1.11 | Does the scope of the Risk Assessment include the people, processes, and technology responsible for the products and services you provide under your contract with us? | |||
| ISA.1.12 | What was the date of completion of your organization's most recent risk assessment? | mm/dd/yyyy | ||
| ISA.1.13 | Please attach/embed control development and risk acceptance documentation. | Has management addressed all unmitigated and under-mitigated risks identified during the Risk Assessment by developing and implementing controls and/or documenting risk-acceptance decisions? |
| ISA.1.15 | Does your organization follow and enforce compliance with its policies? |
| ISA.1.16 | Are policies reviewed, updated if necessary, and approved annually? |
If you respond "No," please use the Comment column to explain and put the frequency/conditions under which they are reviewed and approved.
ISA.1.17 Who approves the Information Security policies?
If you select "Other," please put the title in the Comment column.
| ISA.1.18 | Are policies communicated to all applicable staff? Please select all conditions under which policies are communicated. | |
| ISA.1.23 | Please attach/embed the respective P&P. | Does your organization engage one or more qualified, independent parties to audit and or assess its information security program? Please list the parties in the Comment column. |
| ISA.1.34 | Please attach/embed the respective Policy & Procedure in the Comment column. | Are all workers, including employees, contractors, and consultants, who have access to our confidential information, bound by a confidentiality agreement that requires them to keep the information confidential? |
| ISA.1.35 | Please attach/embed the respective Policy & Procedure in the Comment column. | Do your workers' employment agreements or contracts obligate them to adhere to your organization's policies, including information security policies? |
| ISA.1.36 | Do all workers attest that they have read, understand, and will abide by the security policies? | |
| ISA.1.37 | Please attach/embed the respective Policy and Procedures in the Comment column. | Does your organization run comprehensive background checks including criminal (local, county, State, Province, National), work verification, social security number verification, credit check, address verification, professional licensing, Sex Offender Registry checks, and Terrorist Watch List Checks? Use the Comment column to list any of the above-listed checks that are NOT performed. |
| ISA.1.38 | Please attach/embed the respective Policy and Procedures in the Comment column. | Does your organization require all new hires to undergo drug testing? |
| ISA.1.39 | Please attach/embed the respective Policy and Procedures in the Comment column. | Are all workers trained on the security policies that apply to their role within the organization? |
| ISA.1.40 | Please attach/embed the respective Policy and Procedures in the Comment column. | Do you provide information security awareness training to help promote responsible information handling, proper selection and use of passwords, safe Internet browsing habits, and ethical e-mail practices? |
| ISA.1.41 | Please attach/embed the respective Policy and Procedures in the Comment column. | Do you train workers on the security responsibilities specific to their roles? |
| ISA.1.42 | Please attach/embed the respective Policy and Procedures in the Comment column. | Do you provide training specific to applicable regulatory obligations? |
| ISA.1.43 | Please attach/embed the respective Policy and Procedures in the Comment column. | Do workers undergo all applicable training upon hire and at least annually thereafter? |
| ISA.1.59 | Please attach/embed a copy of your network diagram in the Comment column. | Does your organization maintain a computer network diagram? |
| ISA.1.60 | Is your network diagram accurate and complete? | |
| ISA.1.69 | Please attach/embed the respective Policy and Procedures in the Comment column. | What types of checks are performed on systems that connect to your network to ensure that they comply with your policies? |
| ISA.1.70 | Please select the responses that best reflects your use of network-based Intrusion Detection (IDS) and/or Intrusion Prevention (IPS) solutions. | |
| ISA.1.71 | Please select, by category, the network services your organization exposes over the Internet or untrusted networks FOR THE PURPOSES OF EXCHANGING CONFIDENTIAL INFORMATION or PERFORMING APPLICATIONS, SYSTEMS OR NETWORK ADMINISTRATION. Select all that apply. | |
| ISA.1.73 | Please select the response or responses that best describe the ways workers can connect to the computing environment remotely. Select all that apply. | |
| ISA.1.74 | Does your remote access solution support split tunneling? | |
| ISA.1.75 | Is two factor authentication required for remote access? | |
| ISA.1.76 | Are all systems configured to use the same, synchronized time, for example NTP? | |
| ISA.1.77 | Please attach/embed the respective Policy and Procedures in the Comment column. | Does your organization have a repeatable system build process? |
| ISA.1.78 | Are your systems security hardened in accordance with industry standards or other publications on system hardening? | |
| ISA.1.79 | Please attach/embed the respective Policy and Procedures in the Comment column. | How soon does your organization apply security patches following their publication? |
| ISA.1.80 | Please attach/embed the respective Policy and Procedures in the Comment column. | How quickly after publication does your organization apply antivirus updates? |
| ISA.1.81 | Please attach/embed the respective Policy and Procedures in the Comment column. | Is encryption always used to protect client confidential information at rest. |
| ISA.1.82 | Please attach/embed the respective Policy and Procedures in the Comment column. | Is client confidential information always encrypted in transit over the Internet and untrusted networks? |
| ISA.1.83 | Please attach/embed the respective Policy and Procedures in the Comment column. | What SSL/TLS Versions are in use by your organization? Select all that apply. |
| ISA.1.84 | What versions of SSH are in use by your organization? Select all that apply. | |
| ISA.1.85 | All accounts must follow a formal activation and deactivation policy and procedure. An established and adhered to timeline and process must exist for provisioning and deprovisioning accounts. | Are there procedures for provisioning and deprovision of accounts? |
| ISA.1.86 | All user accounts must have the ability to log activity and be audited to identify out of scope operations. Privileged accounts must have a higher degree of insight and logging/reporting/reviews. | Are user accounts audited on a regular basis? |
| ISA.1.87 | Policies, procedures, and monitoring regarding the use of GenAI need to be in place to ensure the Confidentiality, Integrity and Availability of County operations, data, and security. | If Gen AI is utilized for any aspects of the work performed for the County of Orange, then embed/submit your policy. |
| ISA.1.88 | Please provide a Yes or No answer, a narrative, and policy. The classification and lifecycle of County data must be commensurate with County standards (access, data protection, management, etc.). No unauthorized access or exfiltration is permitted. | Do you have Data Classification Handling policy & procedures in place? |
| ISA.1.89 | Please provide a Yes or No answer, a narrative, and policy. System data is retained only for as long as is required by contract. Data will be destroyed or returned at the end of the retention period. Data will be rendered unreadable through a verified data removal/destruction process (physical drive destruction/degaussing). | Do you have Data Retention and destruction policies in place? |
| ISA.1.90 | Please provide a Yes or No answer, a narrative, and policy. All external connectivity to the network and environment that houses County data and functionality must be protected (MFA, encryption, VPN-IPsec, etc.). | Are remote connections to your network granted via a formal request/approval policy and utilize a secure/encrypted communication pathway (VPN, RDP, etc.)? |
ISO27001
HITRUST CSF
FedRamp Other - List in next column
SOC 2 TYPE 2 REPORT
AWS Data Center Azure Data Center Iron Mountain Data Center Other - List in next column
NIST 800-53 R4/5
NIST SP 800-66 R1
COBIT 4/5
PCI
OTHER - list in next column
OWASP
ePHI
PII
PCI
PUBLIC
PHI (Paper) Backup Tapes/Devices Writable CD-ROM Disks USB Storage Devices Other Removable Media We do not encrypt removable media 30 days from receipt 90 days from receipt One year from receipt More than one year from receipt Until termination of agreement Until termination of agreement plus 1 year Until termination of agreemnt plus 7 years Returned upon client request Disposed of upon client request Confidential information is retained in perpetuity (forever) Confidential information is not retained Other Per contract terms
CEO
CISO
ISO
Compliance Officer Other Upon hire Upon policy change Annually Every other year Never Host MAC address authenticated Host cryptographically authenticated as under the management of your organization (for example, 802.1x) Current anti-virus verification Current patch-level verification Local firewall configuration verification Other We do not utilize a NAC solution We have an IDS solution that detects but cannot prevent intrusion attempts We have an IPS solution that detects and attempts to prevent instrusion attempts Our IDS or IPS is deployed at our network perimeter Our IDS or IPS is deployed within our DMZs and other Internet-facing and untrusted network-facing sub-nets Our IDS or IPS is deployed on all network segments, including internal network segments Other We do not use an IDS or IPS Encrypted end-user services (HTTPS, IP-SEC, SFTP, FTPS) Expected clear-text services (DNS, SMTP, NTP, HTTP) Encrypted management services (SSH, RDP) Clear-text management services (telnet, SNMP, SMB, RPC) Others N/A - confidential information is not transmitted electronically
IP-SEC VPN
SSL-VPN
Terminal Services (RDP)
SSH
Other remote desktop control applications Other None - remote access is never allowed 7 days or less 21 - 28 days Less quickly than 28 days from publication Within an hour Within a day Within a week Less quickly than one week Other Never - our organization does not update its antivirus definitions SSLv2 SSLv310 TLSv1.0 TLSv1.1 TLSv1.2 N/A - SSL/TLS not in use SSHv1 SSHv2 N/A - SSH not in use
LDAP
Directory Services Kerberos
SSO
Others (Use comments section to list) Certificates Token Biometric
MFA\2FA
Other (List in comments section) Onsite Support Remote access (Explain in detail in comments) Email/Phone Support Non-Sensitive None Other (Use Comment section for details) Google Drive OneDrive List regions in Comments section Yes NO (Use Comments section to list location(s) Yes No Yes No Yes No Yes No Yes No Yes No Yes (Submit or embed policy) No (Use comments section to explain) Yes No Yes No YES (Describe process in Comments section) No Yes No N/A Yes (Submit or embed policy. Or, use comments for details) No (Use comments section to explain) Yes No Yes No N/A See comments section Yes If yes, select type:
No Yes (List roles in comments) No Yes No Yes Yes No N/A due to AD integration or SSO No Yes No Yes No Yes No N/A due to AD integration or SSO N/A due to AD integration or SSO Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes (List the data elements in the comments section) No Yes (List the data elements in the comments section) No Yes (Describe the protections in the comments section) No Yes No Yes No Yes No Yes No Yes (Details in the comments section) No Yes (SLA response times listed in the comments section) No Yes No N/A Yes No N/A Yes No N/A Yes No N/A Yes (Explain in comments) No Yes (Describe security controls in the comments section) No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No N/A Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes No Yes (embed or submit policy) No Yes (embed or submit policy) No Yes (embed or submit policy) No Yes (embed or submit policy) No Yes (embed or submit policy) No We do not use Gen AI for any aspects of support in this contract Policy embeded or submitted Group Box 805 TLSv1.3 Metadata De-identified PHI/PII None
Sheet2 image1.jpeg
File details come from the government source that posted it. Updated .