Security Assessment Questionnaire.docx

DOCX document 19 KB Posted

Attached to
SCC Student Payment Services State and local contract opportunity
Solicitation number
5400029535
Issued by
Spartanburg County, South Carolina

About this file

This is a Security Assessment Questionnaire for the SCC Student Payment Services contract opportunity in South Carolina. The questionnaire requires service providers to document their security practices and capabilities related to hosting and managing the college's sensitive information. Respondents must address compliance with applicable legislation such as FERPA and the Gramm-Leach-Bliley Act, specify hosting locations for solutions and databases, identify all employees and third parties with access to college data, and disclose whether any personnel accessing data reside outside the continental United States. The questionnaire must be completed and signed by an authorized contractor representative to certify the accuracy of all responses provided.

The questionnaire establishes comprehensive security requirements covering employee vetting procedures, contractor management policies, physical data center security, encryption standards for data at rest and in transit, backup and restoration protocols, disaster recovery capabilities with defined recovery point and time objectives, breach notification procedures, and post-contract data destruction processes. Respondents must provide supporting documentation demonstrating relevant IT security certifications and detailed descriptions of their data backup, disaster recovery, and breach reporting procedures. The questionnaire emphasizes the protection of personally identifiable information and government information, requiring contractors to outline specific safeguards against unauthorized access, use, distribution, or disclosure and to clarify liability determinations for any data breaches that occur during the contract term.

View the file

Other files for this state and local contract opportunity

Other files attached to SCC Student Payment Services, newest first.
File Type Posted
Functional Requirements.xlsx XLSX spreadsheet
Demo Outline.docx DOCX document
Solicitation.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SERVICE PROVIDER SECURITY ASSESSMENT QUESTIONNAIRE Instructions: (1) Attach additional pages or documents as appropriate and make sure answers cross reference to the questions below. (2) As used in this Questionnaire, the phrase “government information” shall have the meaning defined in the clause titled “Information Security.” (3) This Questionnaire must be read in conjunction with both of the following two clauses (a) Service Provider Security Assessment Questionnaire – Required, and (b) Service Provider Security Representation.

1. Does this solution conform to applicable legislation (such as FERPA and Gramm Leach Bliley Act [GLBA])?

2. Is this solution hosted at the Contractor’s location? If so, where?

3. Is this solutions database hosted at a third party? If so, who and where?

4. What employees of the solution provider has access to the College’s data and under what circumstances?

5. Are there any employees with access to the college’s data who reside outside the continental USA? If so, explain.

6. Are there any third party partnered/connected to the vendor who have access to the college’s data? If yes, explain.

7. Are there any third-party vendors employees outside the continental USA that have access to the college’s data? If yes, explain.

8. What safeguards and practices do you have in place to vet your employees and contractors who will have access to the College’s information?

9. What security policies and procedures as they relate to your use of your contractors and next-tier subcontractors can you provide?

10. What policies, procedures and practices do you have in place to provide for the physical security of the data center(s) and other sites where the College’s information will be hosted, accessed or maintained?

11. Will the College information be encrypted at rest? Please elaborate.

12. Will the College information be encrypted when transmitted? Please elaborate.

13. Will the College information be encrypted during data backups, and on backup media? Please elaborate.

14. What safeguards are in place to prevent unauthorized use, reuse, distribution, transmission, manipulation, copying, modification, access or disclosure of PII information?

15. What is the process for notification of customers of an unauthorized use or breach of data? Describe procedure.

16. Can you provide a document that describes the process to report data breaches and determination on liability to protect those whose data was breached? If yes, please provide.

17. What relevant IT security certifications demonstrating the level of security for the hosted environment can you provide?

18. Can you provide documentation identifying the data back-up and restore capabilities that will be used to support the hosted service?

19. Are backups stored at the same Data Center as the database or are they stored at a separate facility?

20. Can you provide documentation describing your disaster recovery capabilities, including recovery point objective (RPO) and recovery time objective (RTO) for the hosted environment?

21. How will the college’s information be managed after contract termination? Will government information provided to the Contractor be deleted or destroyed? When will this occur?

Offeror’s response to this questionnaire includes any other information submitted with its offer regarding information or data security. SIGNATURE OF PERSON AUTHORIZED TO REPRESENT THE ACCURACY OF THIS INFORMATION ON BEHALF OF CONTRACTOR:

By:____________________________________ (authorized signature)

Its:____________________________________ (printed name of person signing above)

(title of person signing above)

Date: ____________________________________

File details come from the government source that posted it. Updated .