RFP Security Asses Quest.docx

DOCX document 79 KB Posted

Attached to
STC Managed Cloud Services State and local contract opportunity
Solicitation number
5400028075
Issued by
South Carolina

About this file

This document is a Security Assessment Questionnaire for a Managed Cloud Services solicitation (No. 5400026039) issued by the State Fiscal Accountability Authority. The questionnaire is designed to comprehensively evaluate a service provider's information security practices, with 18 detailed questions covering access controls, disaster recovery, employee vetting, third-party contractor management, security certifications, data encryption, incident response, and system architecture.

The questionnaire requires potential contractors to provide extensive details about their information security protocols, including physical and digital safeguards, compliance with Federal Information Processing Standards, cryptographic module conformance, data breach history, and post-contract data management procedures. Respondents must also disclose third-party hosting arrangements, provide system architecture diagrams, and sign an authorization certifying the accuracy of their submitted information. The document serves as a critical due diligence tool for assessing a service provider's capability to securely handle government information across various dimensions of cybersecurity and data protection.

View the file

Other files for this state and local contract opportunity

Other files attached to STC Managed Cloud Services, newest first.
File Type Posted
Canceled Contracts.docx DOCX document
Financial Resp Matrix.xlsx XLSX spreadsheet
Form of Invoice Data Feed.xlsx XLSX spreadsheet
Form of Parent Guaranty.docx DOCX document
General Provisions.docx DOCX document
MCS SOW OGE.docx DOCX document
NDA.docx DOCX document
Non Disclosure Form.docx DOCX document
Definitions.docx DOCX document
MCS SOL Com Serv.docx DOCX document
Negotiated T&C.docx DOCX document
RFP Offer Qual.docx DOCX document
Service Level & Deliver.xlsx XLSX spreadsheet
Source Code Escrow.docx DOCX document
Business Model.docx DOCX document
Key Personnel.docx DOCX document
MCS Solicitation.pdf PDF
MCS Solution State Agencies.docx DOCX document
Pricing Structure.xlsx XLSX spreadsheet
RFP Offeror Reference.docx DOCX document
Reports.xlsx XLSX spreadsheet
Service Model.docx DOCX document
Form of Work Order.docx DOCX document
Goverance Model.docx DOCX document
InFlight Projects.docx DOCX document
MCS SOW State Agencies.docx DOCX document
MCS Solution OGE.docx DOCX document
Performance Model.docx DOCX document
RFP Exceptions.xlsx XLSX spreadsheet
RFP Offeror Experience.docx DOCX document
Rep, Cert & Other.docx DOCX document
Service Level Definitions.docx DOCX document
Service Management Manual.docx DOCX document
Show all 33

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Exhibit J.2.7 (Security Assessment Questionnaire) Solicitation No. 5400026039

Managed Cloud Services

Exhibit J.2.7 Service Provider Security Assessment Questionnaire

Solicitation No. 5400026039

Service Provider Security Assessment QuestionnaireInstructions:

(a) Attach additional pages or documents as appropriate and make sure answers cross reference to the questions below.

(b) As used in this Questionnaire, the phrase “government information” shall have the meaning defined in the clause titled “Information Security.”

(c) This Questionnaire must be read in conjunction with both of the following two clauses (i) Service Provider Security Assessment Questionnaire – Required, and (ii) Service Provider Security Representation.

1. Describe your policies and procedures that ensure access to government information is limited to only those of your employees and contractors who require access to perform your proposed services.

2. Describe your disaster recovery and business continuity plans.

3. What safeguards and practices do you have in place to vet your employees and contractors who will have access to government information?

4. Describe and explain your security policies and procedures as they relate to your use of your contractors and next-tier sub-contractors.

5. List any reports or certifications that you have from properly accredited third-parties that demonstrate that adequate security controls and assurance requirements are in place to adequately provide for the confidentiality, integrity, and availability of the information systems used to process, store, transmit, and access all government information. (For example, an ISO/IEC 27001 compliance certificate, an AICPA SOC 2 (Type 2) report, or perhaps an AICPA SOC 3 report (i.e., a SysTrust or WebTrust). For each certification, describe the scope of the assessment performed. Will these reports / certifications remain in place for the duration of the contract? Will you provide the state with most recent and future versions of the applicable compliance certificate / audit report?

6. Do you have contractual language in place with third parties governing access to government data?

7. Do the contracts in place with these third parties address liability in the event of a data breach?

8. Do all cryptographic modules in use in your solutions conform to the Federal Information Processing Standards (FIPS PUB 140-2 or 140-3)?

9. Have you had a personal data breach in the past three years that involved reporting to a governmental agency, notice to individuals (including voluntary notice), or notice to another organization or institution?

10. Describe the policies, procedures, and practices you have in place to provide for the physical security of your data centers and other sites where government information will be hosted, accessed, or maintained.

11. Will government information be encrypted at rest? Will government information be encrypted when transmitted? Will government information be encrypted during data backups, and on backup media? Please elaborate.

12. Describe safeguards that are in place to prevent unauthorized use, reuse, distribution, transmission, manipulation, copying, modification, access, or disclosure of government information.

13. What controls are in place to detect security breaches? What system and network activity do you log? How long do you maintain these audit logs?

14. How will government information be managed after contract termination? Will government information provided to the Contractor be deleted or destroyed? When will this occur?

15. Describe your incident response policies and practices.

16. Please describe your incident notification procedures.

17. Identify any third party which will host or have access to government information.

18. Can you provide overall system and/or application architecture diagrams, including a full description of the data flow for all components of the system and solutions?

Offeror’s response to this questionnaire includes any other information submitted with its offer regarding information or data security.

SIGNATURE OF PERSON AUTHORIZED TO REPRESENT THE ACCURACY OF THIS INFORMATION ON BEHALF OF CONTRACTOR:

By:____________________________________
(authorized signature)
Its:____________________________________
(printed name of person signing above)
____________________________________
(title of person signing above)

Date: ____________________________________

SPSAQ (JAN 2015) [09-9025-1]

State Fiscal Accountability Authority Page 1 image1.png

File details come from the government source that posted it. Updated .