RFP Document.pdf
PDF 382 KB Posted
- Attached to
- Penetration Testing State and local contract opportunity
- Solicitation number
- 25RFP13436
- Issued by
- Minnehaha County, South Dakota
About this file
This is a Request for Proposal (RFP) issued by the State of South Dakota's Bureau of Information & Technology (BIT) for penetration testing services to enhance the state's cybersecurity capabilities. The RFP seeks separate proposals for red team and purple team exercises to assess the cybersecurity posture of the Executive Branch, covering web applications, networks, and computer systems. Proposals are due by June 30, 2025, with an anticipated contract award on September 30, 2025. The contract will have an initial two-year term with options for up to three one-year extensions. The assessment will include both remote and on-site components, with a purple team exercise requiring at least one contractor to be on-site in Sioux Falls, SD. The final deliverables will include an executive summary with a security posture rating and a detailed technical report documenting attack simulations and recommendations.
The RFP does not specify a fixed budget but allows offerors to submit multiple cost proposals for red and purple team exercises. Contractors must include all costs, including third-party software licenses, and comply with extensive security protocols such as background investigations, multi-factor authentication, and data protection standards. The state will own all data generated during the assessment, and contractors must sign a Security Acknowledgement Form. The assessment explicitly excludes certain state entities including the Board of Regents, Office of the Attorney General, Unified Judicial System, and K-12 Networks. Contractors must demonstrate expertise in cybersecurity, provide comprehensive documentation of attack methodologies, and adhere to industry-recognized frameworks such as CIS, EPSS, CVSS, and MITRE ATT&CK™/D3FEND™.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| Response to Offeror Questions document.pdf | ||
| Attachment C Contractor Security Acknowledgement Form (002).docx | DOCX document | |
| Attachment A Certificate of Media Santization (002).docx | DOCX document | |
| Attachment B ITSP.pdf | ||
| Attachment B ITSP.pdf | ||
| Attachment A Certificate of Media Santization (002).docx | DOCX document | |
| Attachment C Contractor Security Acknowledgement Form (002).docx | DOCX document | |
| RFP Document.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
UPDATED MARCH 31, 2025 V5.0 1
STATE OF SOUTH DAKOTA
INFORMATION TECHNOLOGY (IT) RFP
Bureau of Information & Technology 700 Governors Drive
Pierre, SD 57501
Penetration Testing
PROPOSALS ARE DUE NO LATER THAN 11:59 p.m. CDT, June 30, 2025
RFP #: 25RFP13436
STATE POC: Security Operations Center, Technology Operations & Communications EMAIL: BIT.RFPSECURITYREVIEW@state.sd.us
READ CAREFULLY
FIRM NAME: AUTHORIZED SIGNATURE:
ADDRESS: TYPE OR PRINT NAME:
CITY/STATE: TELEPHONE NO:
ZIP (9 DIGITS): FAX NO:
E-MAIL:
PRIMARY CONTACT INFORMATION
CONTACT NAME:
TELEPHONE NO:
FAX NO: E-MAIL:
UPDATED MARCH 31, 2025 V5.0 2
1 General Information
1.1 Purpose of Request for Proposal (RFP)
1.1.1 Background:
The Bureau of Information & Technology (BIT) will conduct penetration testing as part of an initiative to enhance the cybersecurity poster of the State of South Dakota.
1.1.2 Goals and Objectives:
The goal is to assess our capabilities in preventing, detecting, and responding to cyber-attacks targeting the Executive Branch of the State of South Dakota.This assessment will enable BIT to engage in real-time attacks and utilize incident response playbooks, providing analysts with practical experience and identifying areas for improvement in the state's cybersecurity posture.
Benefits include:
• Evaluating the effectiveness of the State of South Dakota’s security posture.
• Enhancing BIT’s security readiness.
• Assessing the performance of security defenses.
• Improving defender training.
• Gaining objective insights into high-risk areas within the State of South
Dakota’s environment (both external and internal).
BIT is seeking separate proposals and associated costs for both a red team exercise and a purple team exercise. Offerors may be selected for one or both exercises, and different offerors may be chosen for each exercise.
1.1.3 Description of Components or Phases:
BIT is requesting proposals for a penetration testing exercise:
• A red team exercise can be conducted remotely.
• A purple team exercise will require at least one person to be on-site during the exercise.
Upon project completion, the State has the option to renew the contract with the offeror for follow-up exercises.
1.1.4 Scope of Components or Phases:
The assessment will cover any combination of web applications, networks, and computer systems within the Executive Branch.
Note: Physical penetration testing is not included in the scope.
Exclusions:
1.2 Issuing Office and RFP Reference Number
The Bureau of Information & Technology (“Agency”) is the issuing office for this document and all subsequent addenda relating to it, on behalf of the State of South Dakota (“State”).
UPDATED MARCH 31, 2025 V5.0 3
The reference number for this transaction is RFP#25RFP13436. This reference number must be referred to on all proposals, correspondence, and documentation relating to this RFP. For purposes of this RFP, the State’s centralized IT agency, the Bureau of Information and Technology (“BIT”), must approve all IT related purchases.
1.3 Schedule of Activities (Subject to Change)
All deadlines in the Schedule of Activities are due by 11:59 p.m. Central Time. The Schedule of Activities for this RFP is as follows:
RFP Publication May 16, 2025 Deadline for Submission of Written Inquiries June 6, 2025 Deadline for Responses to offeror Questions June 13, 2025 Deadline for Proposal Submission June 30, 2025 Evaluation of Proposals to Determine Short List (If required) July 31, 2025 Demonstrations and presentations (if required) August 15, 2025 Anticipated Award Decision/Contract Negotiation September 30, 2025
1.4 Submitting a Proposal
All proposals must be completed and received by the Agency by the date and time indicated in Section 1.3 Schedule of Activities.
Proposals received after the Deadline for Proposal Submission will be late and ineligible for consideration.
All proposals must be signed, in ink or electronically, by a representative of the offeror who is legally authorized to bind the offeror to the proposal. Proposals that are not properly signed may be rejected. The offeror’s proposal must be prepared pursuant to the requirements of Section 6 Proposal Submission Requirements of this RFP.
The State will only accept electronic proposals via email.
Each offeror must provide an electronic version of the proposal. The electronic version should be provided in MS Word or in PDF format to BIT.RFPSECURITYREVIEW@state.sd.us. The email, including attachments, must be limited to 20MB in size.
No proposal will be accepted from, or no contract or purchase order will be awarded to, any person, firm, or corporation that is in arrears upon any obligations to the State of South Dakota, or that otherwise may be deemed irresponsible or unreliable by the State of South Dakota.
1.5 Certification Regarding Debarment, Suspension, Ineligibility, and Voluntary
Exclusion – Lower Tier Covered Transactions
By signing and submitting this proposal, the offeror certifies that neither it nor its principals is presently debarred, suspended, proposed for debarment, declared ineligible, or voluntarily excluded from participation, by any Federal department or agency, from transactions involving the use of Federal funds. Where the offeror is unable to certify to any of the statements in this certification, the offeror shall attach an
UPDATED MARCH 31, 2025 V5.0 4
explanation to its offer.
1.6 Non-Discrimination Statement
The State of South Dakota requires that all contractors, vendors, and suppliers doing business with any State agency, department, or institution, provide a statement of non-discrimination. By signing and submitting their proposal, the offeror certifies they do not discriminate in their employment practices with regard to race, color, creed, religion, age, sex, ancestry, national origin, or disability.
1.7 Restriction of Boycott of Israel
For contractors, vendors, suppliers, or subcontractors with five (5) or more employees who enter into a contract with the State of South Dakota that involves the expenditure of one hundred thousand dollars ($100,000) or more, by submitting a response to this solicitation or agreeing to contract with the State, the bidder or offeror certifies and agrees that the following information is correct:
The bidder or offeror, in preparing its response or offer or in considering proposals submitted from qualified, potential vendors, suppliers, and subcontractors, or in the solicitation, selection, or commercial treatment of any vendor, supplier, or subcontractor, has not refused to transact business activities, has not terminated business activities, and has not taken other similar actions intended to limit its commercial relations, related to the subject matter of the bid or offer, with a person or entity on the basis of Israeli national origin, or residence or incorporation in Israel or its territories, with the specific intent to accomplish a boycott or divestment of Israel in a discriminatory manner. It is understood and agreed that, if this certification is false, such false certification will constitute grounds for the State to reject the bid or response submitted by the bidder or offeror on this project and terminate any contract awarded based on the bid or response. The successful bidder or offeror further agrees to provide immediate written notice to the contracting executive branch agency if during the term of the contract it no longer complies with this certification and agrees such noncompliance may be grounds for contract termination.
1.8 Certification Relating to Prohibited Entity
For contractors, vendors, suppliers, or subcontractors who enter into a contract with the State of South Dakota by submitting a response to this solicitation or agreeing to contract with the State, the bidder or offeror certifies and agrees that the following information is correct:
The bidder or offeror, in preparing its response or offer or in considering proposals submitted from qualified, potential vendors, suppliers, and subcontractors, or in the solicitation, selection, or commercial treatment of any vendor, supplier, or subcontractor, is not a prohibited entity, regardless of its principal place of business, that is ultimately owned or controlled, directly or indirectly, by a foreign national, a foreign parent entity, or foreign government from China, Iran, North Korea, Russia, Cuba, or Venezuela, as defined by South Dakota Codified Law § 5-18A. It is understood and agreed that, if this certification is false, such false certification will constitute grounds for the State to reject the bid or response submitted by the bidder or offeror on this project and terminate any
UPDATED MARCH 31, 2025 V5.0 5
contract awarded based on the bid or response. The successful bidder or offeror further agrees to provide immediate written notice to the contracting executive branch agency if during the term of the contract it no longer complies with this certification and agrees such noncompliance may be grounds for contract termination and would be cause to suspend and debar a business under SDCL § 5-18D-12.
1.9 Certification of No State Legislature Interest
The bidder or offeror (i) understands neither a state legislator nor a business in which a state legislator has an ownership interest may be directly or indirectly interested in any contract with the State that was authorized by any law passed during the term for which that legislator was elected, or within one year thereafter, and (ii) has read South Dakota Constitution Article 3, Section 12 and has had the opportunity to seek independent legal advice on the applicability of that provision to any agreement entered into as a result of this RFP. By signing an agreement pursuant to this RFP, the bidder or offeror certifies that the Agreement is not made in violation of the South Dakota Constitution Article 3, Section 12.
1.10 Modification or Withdrawal of Proposals
Proposals may be modified or withdrawn by the offeror prior to the established due date and time.
No oral, telephonic, telegraphic or facsimile responses or modifications to informal, formal bids, or Request for Proposals will be considered.
1.11 Questions Regarding RFP
All written questions should be sent to:
BIT.RFPSECURITYREVIEW@state.sd.us , only emailed questions will be accepted.
Each offeror may submit questions via email concerning this RFP to obtain clarification of requirements. No questions will be accepted after the date and time indicated in the above schedule of activities. Email questions to the email address listed above with the subject line “RFP#25RFP13436”. The questions and their answers will be sent to all offerors that submitted Letters of Intent, submitted questions, or requested the questions and answers via email before the proposal submittal date and will be sent by the date and time indicated in the above calendar of events. Offeror may not rely on any other statements, either of a written or oral nature, that alter any specification or other term or condition of this RFP that have not originated from the SD RFP Project Contact. Offerors will be notified in the same manner as indicated above regarding any modifications to this RFP. Offerors and their agents may not contact any state employee other than the buyer of record regarding any of these matters during the solicitation and evaluation process.
Inappropriate contacts are grounds for suspension and exclusion from specific procurements.
1.12 Proprietary Information
The proposal of the successful offeror(s) becomes public information. Proprietary information can be protected under limited circumstances such as client lists and non-public financial statements. An entire proposal may not be marked as proprietary.
UPDATED MARCH 31, 2025 V5.0 6
Offerors must clearly identify in the Executive Summary and mark in the body of the proposal any specific proprietary information they are requesting to be protected. The Executive Summary must contain specific justification explaining why the information is to be protected. Proposals may be reviewed and evaluated by any person at the discretion of the State. All materials submitted become the property of the State of South Dakota and may be returned only at the State's option.
1.13 Length of Contract
The length of the contract will be for a term of two year(s). The State will have the opportunity to renew the contract annually for up to three one-year time extensions. The extension(s) will not be automatic.
1.14 Governing Law
This RFP will be governed by and construed in accordance with the laws of the State of South Dakota. Any lawsuit pertaining to or affecting this RFP will be venued in Circuit Court, Sixth Judicial Circuit, Hughes County, South Dakota.
1.15 Presentations/Demonstrations
At the State’s discretion, the State may require a presentation or demonstration by an offeror to clarify a proposal. However, the State may award a contract based on the initial proposals received without a presentation or demonstration by the offeror. If presentations or demonstrations are required, they will be scheduled after the submission of proposals. Presentations and demonstrations will be made at the offeror’s expense.
1.16 Discussions
At the State’s discretion, the offeror may or may not be invited to have discussions with the State. The discussions can be before or after the RFP has been submitted.
Discussions will be made at the offeror’s expense.
1.17 Negotiations
This process is a Request for Proposal/Competitive Negotiation process. Each proposal will be evaluated, and each respondent will be available for negotiation meetings at the State’s request. The State reserves the right to negotiate on any component of every proposal submitted. From the time the proposals are submitted until the formal award of a contract, each proposal is considered a working document and as such, will be kept confidential. The negotiation discussions will also be held as confidential until such time as the award is completed.
2 Standard Contract Terms and Conditions
Any contract or agreement resulting from this RFP will include the State’s standard terms and conditions as listed below, the State’s standard Information Technology (“IT”) contract terms, and any additional terms and conditions as negotiated by the parties. The offeror must indicate in its response any issues it has with specific contract terms. If the offeror does not indicate
UPDATED MARCH 31, 2025 V5.0 7
that there is an issue with a specific contract term, then the offeror will be deemed to have accepted the contract terms as written.
2.1 The Contractor will perform those services described in the Scope of Work, attached hereto as Section 3 of the RFP and by this reference incorporated herein.
2.2 The Contractor’s services under this Agreement will start on , and end on
, unless terminated sooner pursuant to the terms of the Agreement.
2.3 The Contractor will not use State equipment, supplies, or facilities. The Contractor will provide the State with its Employer Identification Number, Federal Tax Identification Number, or Social Security Number upon execution of this Agreement.
2.4 The State will make payment for services upon satisfactory completion of the services.
The TOTAL CONTRACT AMOUNT is an amount not to exceed $ . The State will not pay Contractor's expenses as a separate item. Payment will be made pursuant to itemized invoices submitted with a signed state voucher. Payment will be made consistent with SDCL chapter 5-26.
2.5 The Contractor agrees to indemnify the State of South Dakota, its officers, agents, and employees, from and against all claims or proceedings for actions, suits, damages, liabilities, other losses or equitable relief that may arise at least in part as a result of an act or omission in performing services under this Agreement. The Contractor will defend the State of South Dakota, its officers, agents, and employees against any claim, including any claim, action, suit, or other proceeding related to the claim. The Contractor’s obligation to indemnify includes the payment of attorney fees and other costs of defense.
In defending the State of South Dakota, its officers, agents, and employees, the Contractor will engage other professionals, subject to the written approval of the State which will not be unreasonably withheld. Notwithstanding the foregoing, the State may, in its sole discretion and at the expense of the Contractor, engage attorneys and other professionals to defend the State of South Dakota, its officers, agents, and employees, or to assist the Contractor in the defense. This section does not require the Contractor to be responsible for or defend against claims or proceedings for damages, liabilities, losses, or equitable relief arising solely from errors or omissions of the State, its officers, agents, or employees.
2.6 During the term of this Agreement, the Contractor will obtain and maintain in force insurance coverage of the types and with the limits as follows:
2.6.1 Commercial General Liability Insurance:
The Contractor will maintain occurrence based commercial general liability insurance or equivalent form with a limit of not less than $1 million for each occurrence. If such insurance contains a general aggregate limit it will apply separately to this Agreement or be no less than two times the occurrence limit.
The insurance policy will name the State of South Dakota, its officers and employees, as additional insureds, but liability coverage is limited to claims not barred by sovereign immunity. The State of South Dakota, its officers and employees do not hereby waive sovereign immunity for discretionary conduct as provided by law.
2.6.2 Professional Liability Insurance or Miscellaneous Professional Liability Insurance:
UPDATED MARCH 31, 2025 V5.0 8
The Contractor will procure and maintain professional liability insurance or miscellaneous professional liability insurance with a limit not less than $1 million.
2.6.3 Business Automobile Liability Insurance:
The Contractor will maintain business automobile liability insurance or equivalent form with a limit of not less than $1 million for each accident. Such insurance will include coverage for owned, hired, and non-owned vehicles.
2.6.4 Workers’ Compensation Insurance:
The Contractor will procure and maintain workers’ compensation and employers’ liability insurance as required by South Dakota or federal law.
Before beginning work under this Agreement, Contractor will furnish the State with properly executed Certificates of Insurance which will clearly evidence all insurance required in this Agreement. In the event a substantial change in insurance, issuance of a new policy, cancellation, or nonrenewal of the policy, the Contractor agrees to provide immediate notice to the State and provide a new certificate of insurance showing continuous coverage in the amounts required. Contractor will furnish copies of insurance policies if requested by the State.
2.7 While performing services under this Agreement, the Contractor is an independent contractor and not an officer, agent, or employee of the State of South Dakota.
2.8 The Contractor agrees to report to the State any event encountered in the course of performance of this Agreement which results in injury to the person or property of third parties, or which may otherwise subject Contractor or the State to liability. The Contractor will report any such event to the State immediately upon discovery.
The Contractor's obligation under this section will only be to report the occurrence of any event to the State and to make any other report provided for by their duties or applicable law. The Contractor’s obligation to report will not require disclosure of any information subject to privilege or confidentiality under law (e.g., attorney-client communications).
Reporting to the State under this section will not excuse or satisfy any obligation of the Contractor to report any event to law enforcement or other entities under the requirements of any applicable law.
2.9 This Agreement may be terminated by either party hereto upon thirty (30) days’ written notice. In the event the Contractor breaches any of the terms or conditions of this Agreement, this Agreement may be terminated by the State at any time with or without notice. If termination for a breach is affected by the State, any payments due to the Contractor at the time of termination may be adjusted to cover any additional costs to the State because of the Contractor's breach. Upon termination the State may take over the work and may award another party an agreement to complete the work under this Agreement. If after the State terminates for a breach by the Contractor it is determined that the Contractor was not at fault, then the Contractor will be paid for eligible services rendered and expenses incurred up to the date of termination.
2.10 This Agreement depends upon the continued availability of appropriated funds and expenditure authority from the Legislature for this purpose. If for any reason the Legislature fails to appropriate funds or grant expenditure authority, or funds become unavailable by operation of law or federal funds reductions, this Agreement will be terminated by the State upon five (5) business days’ written notice. The Contractor agrees
UPDATED MARCH 31, 2025 V5.0 9
that termination for any of these reasons is not a default by the State nor does it give rise to a claim against the State or any officer, agent, or employee of the State, and the Contractor waives any claim against the same.
2.11 This Agreement may not be assigned without the express prior written consent of the
State. This Agreement may not be amended except in writing, which writing will be expressly identified as a part of this Agreement and be signed by an authorized representative of each of the parties to this Agreement.
2.12 This Agreement will be governed by and construed in accordance with the laws of the
State of South Dakota, without regard to any conflicts of law principles, decisional law, or statutory provision which would require or permit the application of another jurisdiction’s substantive law. Venue for any lawsuit pertaining to or affecting this Agreement will be in Circuit Court, Sixth Judicial Circuit, Hughes County, South Dakota.
2.13 The Contractor will comply with all federal, tribal, state, and local laws, regulations, ordinances, guidelines, permits, requirements, and other standards applicable to providing services pursuant to this Agreement and will be solely responsible for obtaining current information on such requirements. Nothing herein will constitute a waiver by the State to any defense to jurisdiction nor will anything under this Agreement constitute an acknowledgement by the State that any tribe has or exercises any jurisdiction over this Agreement or the parties.
2.14 The Contractor may not use subcontractors to perform the services described in this
Agreement without the express prior written consent of the State. The Contractor will include provisions in its subcontracts requiring its subcontractors to comply with the applicable provisions of this Agreement, to indemnify the State, and to provide insurance coverage for the benefit of the State in a manner consistent with this Agreement. The Contractor will cause its subcontractors, agents, and employees to comply with applicable federal, tribal, state, and local laws, regulations, ordinances, guidelines, permits, and other standards and will adopt such review and inspection procedures as are necessary to assure such compliance. The State, at its option, may require the vetting of any subcontractors. The Contractor will assist in the vetting process.
2.15 The State reserves the right to reject any person from performing services under this Agreement who the State believes would be detrimental to the services, presents insufficient skills, presents inappropriate behavior, or is considered by the State to be a security risk.
2.16 The Contractor hereby acknowledges and agrees that all reports, plans, specifications, technical data, miscellaneous drawings, software system programs and documentation, procedures, or files, operating instructions and procedures, source code(s) and documentation, including those necessary to upgrade and maintain the software program, and all information contained therein provided to the State by the Contractor in connection with its performance of services under this Agreement will belong to and is the property of the State and will not be used in any way by the Contractor without the written consent of the State. Papers, reports, forms, software programs, source code(s), and other material which are a part of the work under this Agreement will not be copyrighted without written approval of the State.
UPDATED MARCH 31, 2025 V5.0 10
2.17 The Contractor certifies that neither Contractor nor its principals are presently debarred, suspended, proposed for debarment or suspension, or declared ineligible from participating in transactions by the federal government or any state or local government department or agency. Contractor further agrees that it will immediately notify the State if during the term of this Agreement Contractor or its principals become subject to debarment, suspension, or ineligibility from participating in transactions by the federal government, or by any state or local government department or agency.
2.18 By signing this Agreement, the Contractor certifies and agrees that is has not refused to transact business activities, have not terminated business activities, and have not taken other similar actions intended to limit its commercial relations, related to the subject matter of this Agreement, with a person or entity that is either the State of Israel, or a company doing business in or with Israel or authorized by, licensed by, or organized under the laws of the State of Israel to do business, or doing business in the State of Israel, with the specific intent to accomplish a boycott or divestment of Israel in a discriminatory manner. It is understood and agreed that, if this certification is false, such false certification will constitute grounds for the State to terminate this Agreement. During the term of this Agreement, if the Contractor no longer complies with this certification, the Contractor agrees to provide immediate written notice to the State and agrees such noncompliance may be grounds for termination of this Agreement.
2.19 Pursuant to South Dakota Codified Law § 5-18A, by entering into this Agreement with the
State of South Dakota, the Contractor certifies and warrants that the Contractor is not a prohibited entity, regardless of its principal place of business, that is ultimately owned or controlled, directly or indirectly, by a foreign national, a foreign parent entity, or foreign government from China, Iran, North Korea, Russia, Cuba, or Venezuela, as defined by South Dakota Codified Law § 5-18A.
The Contractor agrees that if this certification is false, the State may terminate this Agreement with no further liability to the State. The Contractor further agrees to provide immediate written notice to the State if during the term of the contract it no longer complies with this certification, and the Contractor agrees such noncompliance may be grounds for contract termination and would be cause to suspend and debar a business under SDCL § 5-18D-12.
2.20 The Contractor (i) understands neither a state legislator nor a business in which a state legislator has an ownership interest may be directly or indirectly interested in any contract with the State that was authorized by any law passed during the term for which that legislator was elected, or within one year thereafter, and (ii) has read South Dakota Constitution Article 3, Section 12 and has had the opportunity to seek independent legal advice on the applicability of that provision to this Agreement. By signing this Agreement, the Contractor certifies that this Agreement is not made in violation of the South Dakota Constitution Article 3, Section 12.
2.21 Any notice or other communication required under this Agreement will be in writing and sent to the address set forth above. Notices will be given by and to on behalf of the State, and by and to , on behalf of the Contractor, or such authorized designees as either party may from time to time designate in writing. Notices or communications to or between the parties will be deemed to have been delivered when mailed by first class mail, provided that notice of default or termination will be sent by registered or certified mail, or, if personally delivered, when received by such party.
UPDATED MARCH 31, 2025 V5.0 11
2.22 In the event that any court of competent jurisdiction will hold any provision of this
Agreement unenforceable or invalid, such holding will not invalidate or render unenforceable any other provision of this Agreement.
2.23 All other prior discussions, communications, and representations concerning the subject matter of this Agreement are superseded by the terms of this Agreement, and except as specifically provided in this Agreement, this Agreement constitutes the entire agreement with respect to the subject matter.
2.24 The waiver by either party of a breach or violation of any provisions of this Agreement will not operate as, or be construed to be, a waiver of any subsequent breach of the same or other provision of this Agreement.
2.25 Nothing in this Agreement is intended to constitute a waiver of sovereign immunity by or on behalf of the State of South Dakota, its agencies, officers, or employees.
2.26 Neither party will disclose the contents of the Agreement except as required by applicable law or as necessary to carry out the terms of the Agreement or to enforce that party’s rights under this Agreement. The Contractor acknowledges that the State of South Dakota and its agencies are public entities and thus are bound by South Dakota open meetings and open records laws. It is therefore not a breach of this Agreement for the State to take any action that the State reasonably believes is necessary to comply with the South Dakota open records or open meetings laws, including, without limitation, posting this Agreement on the website pursuant to SDCL § 1-27-46.
2.27 Professional Services Quality and Originality Warranties
The Contractor represents and warrants that all professional services provided pursuant to this Agreement will be performed in a professional and workmanlike manner. The Contractor further represents and warrants that the deliverables under this Agreement will be its own original work, without incorporation of software, text, images, or other assets created by third parties, except to the extent that the State consents to such incorporation in writing.
2.28 Remedies for Breach of Professional Services Warranties
In the event of a breach of the warranty granted in Section 2.27 of this Agreement, the Contractor, at its own expense, will promptly re-perform the professional services in question. The preceding sentence, in conjunction with the State’s right to terminate this Agreement for breach where applicable, states the State’s sole remedy and the Contractor’s entire liability for breach of the warrant granted in Section 2.27.
2.29 Confidentiality of Information
A. Definition: “Confidential Information” includes all information disclosed by the State to the Contractor, including but not limited to, names, social security numbers, employee numbers, addresses, other data about applicants, employees, and clients to whom the State provides services of any kind, and any other nonpublic, sensitive information disclosed by the State. Notwithstanding the foregoing, Confidential Information does not include information that:
UPDATED MARCH 31, 2025 V5.0 12
1. was in the public domain at the time it was disclosure;
2. was known to the Contractor without restriction at the time of disclosure by the
State;
3. The Contractor received written approval by the State to disclose;
4. was independently developed by the Contractor without the benefit or influence of the State’s information; or
5. becomes known to the Contractor without restrictions from a source not connected to the State.
B. Nondisclosure: The Contractor will not use Confidential Information for any purpose other than to facilitate the transactions contemplated by this Agreement (“Purpose”).
The Contractor will not disclose Confidential Information to:
1. any employee or contractor of the Contractor unless such person needs access in order to facilitate the Purpose and executes a nondisclosure agreement with the employee or contractor with terms no less restrictive than those of this Agreement; and
2. any other third party without the State’s prior written consent.
Without limiting the generality of the foregoing, the Contractor must protect Confidential Information with the same degree of care it uses to protect its own confidential information of similar nature and importance, but with no less than reasonable care. The Contractor must promptly notify the State of any misuse or misappropriation of Confidential Information that comes to the Contractor’s attention.
Notwithstanding the foregoing, the Contractor may disclose Confidential Information as required by applicable law or by proper legal or governmental authority. The Contractor must give the State prompt notice of any such legal or governmental demand and reasonably cooperate with the State in any effort to seek a protective order or otherwise to contest such required disclosure, at the State’s expense.
C. Injunction, Termination, and Retention of Rights:
1. Injunction. The Contractor agrees that breach of this Section 2.29 would cause the State irreparable injury, for which monetary damages would not provide adequate compensation, and that in addition to any other remedy, the State will be entitled to injunctive relief against such breach or threatened breach, without proving actual damage or posting a bond or other security.
2. Return upon Termination. Upon termination of this Agreement, the Contractor will return all copies of Confidential Information to the State or certify, in writing, the destruction thereof.
3. Retention of Rights. This Agreement does not transfer ownership of Confidential Information or grant a license thereto. Except to the extent that another section of this Agreement specifically provides to the contract, the State will retain all right, title, and interest in and to all Confidential Information.
2.30 State Data
A. Definition: “State Data” is any data produced or provided by the State as well as any data produced or provided for the State by the Contractor or a third party.
B. Data Location and Offshore Services: The Contractor must provide its services to the State as well as access and storage of State Data, Confidential Information, or reconnaissance information regarding the State’s systems solely from data centers located in the continental United States. The Contractor will not provide access to State Data, Confidential Information, or reconnaissance information regarding the State’s systems to any entity or person(s) located outside the continental United States that are not named in this Agreement without prior written permission from the
UPDATED MARCH 31, 2025 V5.0 13
State. This restriction also applies to disaster recovery; any disaster recovery plan must provide for data storage entirely within the continental United States.
C. Use of Portable Devices: The Contractor must prohibit its employees, agents, affiliates, and subcontractors from storing State Data on portable devices, including personal computers, except for devices that are used and kept only at the Contractor’s data center(s). All portable devices used for storing State Data must be password protected and encrypted.
D. Remote Access: The Contractor will prohibit its employees, agents, affiliates, and subcontractors from accessing State Data, Confidential Information, or reconnaissance information regarding the State’s systems remotely except as necessary to provide the services under this Agreement and consistent with all contractual and legal requirements. The accounts used for remote access cannot be shared accounts and must include multifactor authentication. If the State Data, Confidential Information, or reconnaissance information regarding the State’s systems that is being remotely accessed is legally protected data or considered sensitive by the State, then:
1. the device must be password protected;
2. the data or information is not put onto mobile media (such as flash drives);
3. no non-electronic copies are made of the data or information;
4. the Contractor must maintain a log detailing the data or information which was accessed, when it was accessed, and by whom it was accessed.
E. Non-Disclosure and Separation of Duties: The Contractor will enforce separation of job duties and require non-disclosure agreements of all staff that have or can have access to State Data or the hardware that State Data resides on. The Contractor will limit staff knowledge to those staff whose duties require them to have access to State Data or the hardware State Data resides on.
F. Securing of Data: All hardware used to access, store, and process State Data, Confidential Information, or reconnaissance information regarding the State’s systems will employ industry best practices, including appropriate administrative, physical, and technical safeguards to secure such data or information from unauthorized access, disclosure, alteration, and use. Such measures will be no less protective than those used to secure the Contractor’s own data of a similar type, and in no event less than commercially reasonable in view of the type and nature of the data involved.
G. Data Encryption: If State Data, Confidential Information, or reconnaissance information regarding the State’s systems will be remotely accessed or stored outside the State’s IT Infrastructure, the Contractor warrants that the State Data, Confidential Information, or reconnaissance information regarding the State’s systems will be encrypted in transit (including via any web interface) and at rest at no less than AES256 level of encryption with at least SHA256 hashing and that the Contractor will comply with all other technical specifications of the State as incorporated by reference.
H. Lost or Damaged Data Liability: If State Data is lost or damaged as a result of any failure by the Contractor, its employees, or its agents to exercise reasonable care to prevent such loss or damage, then the Contractor’s liability will not exceed the reasonable cost of reproducing the lost or damaged data. The Parties agree this limitation of liability will trump any limitation of liability as it relates to lost or damaged State Data.
I. Rights, Use, and License of and to State Data: The parties agree that all rights, including all intellectual property rights, in and to State Data will remain the exclusive property of the State. The State grants the Contractor a limited, nonexclusive license
UPDATED MARCH 31, 2025 V5.0 14
to use the State Data solely for the purpose of performing its obligations under this Agreement. This Agreement does not give a party any rights, implied or otherwise, to the other’s data, content, or intellectual property, except as expressly stated in the Agreement.
Protection of personal privacy and State Data must be an integral part of the business activities of the Contractor to ensure there is no inappropriate or unauthorized use of State Data at any time. To this end, the Contractor must safeguard the confidentiality, integrity, and availability of State Data and comply with the following conditions:
1. The Contractor will implement and maintain appropriate administrative, technical, and organizational security measures to safeguard against unauthorized access, disclosure, use, or theft of Personally Identifiable Information (PII), data protected under the Family Educational Rights and Privacy Act (FERPA), Protected Health Information (PHI), Federal Tax Information (FTI), or any information that is confidential under applicable federal, state, or international law, rule, regulation, or ordinance. Such security measures will be in accordance with recognized industry practice and not less protective than the measures the Contractor applies to its own non-public data.
2. The Contractor will not copy, disclose, retain, or use State Data for any purpose other than to fulfill its obligations under this Agreement.
3. The Contractor will not use State Data for the Contractor’s own benefit and will not engage in data mining of State Data or communications, whether through automated or manual means, except as specifically and expressly required by law or authorized in writing by the State through a State employee or officer specifically authorized to grant such use of State Data.
J. Continued Access to State Data: The Contractor agrees it will not hinder the State’s access to State Data if there is a contract dispute between the Parties, if there is a billing dispute between the Parties, or if the Contractor merges with or is acquired by another entity. In addition, the Contractor must maintain all security requirements and disaster recovery commitments of this Agreement during such incidents.
K. Legal Requests for State Data: Except as otherwise expressly prohibited by law, the Contractor will:
1. immediately notify the State of any subpoenas, warrants, or other legal order, demand, or request received by the Contractor seeking State Data, Confidential Information, or reconnaissance information regarding the State’s systems maintained by the Contractor;
2. consult with the State regarding the Contractor’s response;
3. cooperate with the State’s requests in connection with efforts by the State to intervene and quash or modify the order, demand, or request; and
4. Upon the State’s request, provide the State with a copy of both the order, demand, or request and the Contractor’s proposed or actual response to the order, demand, or request.
L. eDiscovery: The Contractor will contact the State upon receipt of any electronic discovery, litigation holds, discovery searches, and expert testimonies related to, or which in any way might reasonably require access to State Data, Confidential Information, or reconnaissance information regarding the State’s systems. The Contractor will not respond to service of process and other legal requests related to the State without first notifying the State unless prohibited by law from providing such notice.
M. Audit Requirements: The Contractor warrants and agrees it is aware of and complies with all audit requirements relating to the classification of State Data the Contractor stores, processes, and accesses. Depending on the data classification, UPDATED MARCH 31, 2025 V5.0 15 this may require the Contractor to grant physical access to the data hosting facilities to the State or a federal agency. The Contractor will notify the State of any request for physical access to a facility that hosts or processes State Data by any entity other than the State.
N. Data Sanitization: At the end of a project covered by this Agreement, the Contractor will return all State Data to the State or securely dispose of all State Data in all forms, this can include State Data on media such as paper, punched cards, magnetic tape, magnetic disks, solid state devices, or optical discs. This State Data must be permanently deleted by either purging the data or destroying the medium on which the State Data is found according to the methods given in the most current version of National Institute of Standards and Technology (NIST) Special Publication 800-88.
The Contractor must complete and provide to the State point of contact a completed Certificates of Sanitization for Offsite Data, attached to this Agreement as Attachment A. The State will review the completed Certificates of Sanitization for Offsite Data. If the State is not satisfied by the data sanitization, then the Contractor will use a method that does satisfy the State. This contract clause remains in effect for as long as the Contractor, and the Contractor’s subcontractors, agents, assigns, and affiliated entities have the State Data, even after the Agreement is terminated or the project is completed.
2.31 Security Processes
The Contractor will disclose its non-proprietary security processes and technical limitations to the State so adequate protection and flexibility can be attained between the State and the Contractor, e.g. virus checking and port sniffing.
2.32 Password Policies
Password policies for the Contractor’s employees will be documented annually and provided to the State to ensure adequate password protections are in place. Logs and administrative settings will be provided to the State upon request to demonstrate such policies are actively enforced. The process used to reset a password must include security questions or Multi-factor Authentication.
2.33 Adverse Event
The Contractor must notify the State contact within two days if the Contractor becomes aware that an Adverse Event has occurred. An Adverse Event is the unauthorized use of system privileges, unauthorized access to State Data, execution of malware, physical intrusions and electronic intrusions that may include network, applications, servers, workstations, and social engineering of staff. If the Adverse Event was the result of the Contractor’s actions or inactions, the State can require a risk assessment of the Contractor the State mandating the methodology to be used as well as the scope. At the State’s discretion a risk assessment may be performed by a third party at the Contractor’s expense. State Data is any data produced or provided by the State as well as any data produced or provided for the State by a third-party.
2.34 Threat Notification
A credible security threat consists of the discovery of an exploit that a person considered
UPDATED MARCH 31, 2025 V5.0 16
an expert on Information Technology security believes could be used to breach any aspect of a system that is holding State Data or a product provided by the Contractor.
Upon becoming aware of a credible security threat with the Contractor’s product(s) and or service(s) being used by the State, the Contractor or any subcontractor supplying product(s) or service(s) to the Contractor needed to fulfill the terms of this Agreement will notify the State within two business days of any such threat. If the State requests, the Contractor will provide the State with information on the threat.
2.35 Access Attempts
The Contractor will log all access attempts, whether failed or successful, to any system connected to the hosted system which can access, read, alter, intercept, or otherwise impact the hosted system or its data or data integrity. For all systems, the log must include at least: login page used, username used, time and date stamp, incoming IP for each authentication attempt, and the authentication status, whether successful or not. Logs must be maintained not less than 7 years in a searchable database in an electronic format that is un-modifiable. At the request of the State, the Contractor agrees to grant the State access to those logs to demonstrate compliance with the terms of this Agreement and all audit requirements related to the hosted system.
2.36 Access to Protected Data
For the purposes of this Agreement, “Protected Data” means data protected by any law, regulation, industry standard, or has been designated as sensitive by the federal or a state government. The Parties agree that if this Agreement provides the Contractor access to the State’s Protected Data, then the following contract clauses apply:
A. Security Incident Notification: For purposes of this Agreement, “Security Incident” is a violation of any Bureau of Information and Technology (BIT) security or privacy policy or contract agreement involving Protected Data or the imminent threat of a violation. The BIT security and privacy policies can be found in the Information Technology Security Policy (ITSP), attached to this Agreement and fully incorporated in this Agreement as Attachment B. The Contractor will implement, maintain, and update Security Incident procedures that comply with all state standards and federal and state requirements. The Contractor agrees to notify the State of a Security Incident. To the extent probes and reconnaissance scans common to the industry constitute Security Incidents, the Parties agree that this Agreement constitutes notice by the Contractor of the ongoing existence and occurrence of such Security Incidents for which no additional notice to the State is required. Probes and reconnaissance scans include, but are not limited to, pings and other broadcast attacks on the Contractor’s firewall, port scans, and unsuccessful log-on attempts if such probes and reconnaissance scans do not result in a Security Incident as defined above. Except as required by a legal requirement, the Contractor will provide notice of the Security Incident to only the State. The State will determine if notification to the public will be made by the State or by the Contractor. The method and content of the notification of the affected parties will be coordinated with, and is subject to approval by the State, unless required otherwise by legal requirements. If the State decides that the Contractor will be distributing, broadcasting to, or otherwise releasing information on the Security Incident to the news media, the State will decide to whom the information will be sent and must approve the content of the information. The Contractor must reimburse the State for any costs associated with the notification, distributing, UPDATED MARCH 31, 2025 V5.0 17 broadcasting, or otherwise releasing information on the Security Incident.
1. The Vender must notify the State point of contact within 12 hours of the Contractor becoming aware that a Security Incident has occurred.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .