Service Provider Questionnaire.pdf
PDF 140 KB Posted
- Attached to
- Traffic Data Services WIM/CCS State and local contract opportunity
- Solicitation number
- 5400029091
- Issued by
- Richland County, South Carolina
About this file
This is a Service Provider Security Assessment Questionnaire (version 12/2025) required by South Carolina for the Traffic Data Services WIM/CCS contract opportunity. The questionnaire is a mandatory security compliance document that prospective service providers must complete and submit with their proposals. The form consists of twelve questions designed to comprehensively evaluate a contractor's information security capabilities, policies, and procedures. Bidders must provide detailed responses addressing access controls, disaster recovery and business continuity plans, employee and contractor vetting processes, subcontractor security protocols, relevant certifications (such as FedRAMP, GovRAMP, ISO/IEC 27001, AICPA SOC 2 Type 2, or CMMC), physical security measures, encryption practices, breach detection controls, audit logging procedures, incident response protocols, and post-contract data management and destruction procedures.
The questionnaire requires responses addressing how government information will be protected throughout the contract lifecycle, including encryption standards for data at rest, in transit, and during backups. Contractors must identify any third parties that will have access to government information and commit to maintaining current security certifications throughout the contract term, with provisions to supply the state with recent and future audit reports. All responses must be signed by an authorized company representative certifying the accuracy of the information provided. Submission of this completed questionnaire is a prerequisite for contract award, and failure to adequately address the security requirements may disqualify a bidder from consideration for the Traffic Data Services WIM/CCS opportunity.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| Solicitation.pdf | ||
| Pricing Worksheet.xlsx | XLSX spreadsheet | |
| Accessibility Conformance Report.pdf | ||
| Cloud Hosting Data.pdf | ||
| Artifical Intelligence Use.pdf | ||
| Table 3.pdf | ||
| Camera Information.pdf | ||
| Sites.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SERVICE PROVIDER SECURITY ASSESSMENT QUESTIONNAIRE
SERVICE PROVIDER SECURITY ASSESSMENT QUESTIONNAIRE (v12/2025) Page 1 of 2
Instructions: I. Attach additional pages or documents as appropriate. II. As used in this Questionnaire, government information shall have the meaning defined in the clause titled “Information Security.”.
1. Describe your policies and procedures that ensure access to government information is limited to only those employees and contractors who require access to perform the proposed services.
2. Describe your disaster recovery and business continuity plans to include agency notification of incident and pre-prepared communications plan for notifying individuals affected by the incident and the timeframes within all of these items are addressed.
3. What safeguards and practices do you have in place to vet employees and Contractors who have access to government information?
4. Describe and explain your security policies and procedures related to use of Contractors/subcontractors.
5. List any certifications that you have that demonstrate that adequate security controls are in place to properly store, manage and process government information (e.g., FedRAMP Authorization, GovRAMP Authorization, ISO/IEC 27001 certification, AICPA SOC 2 (Type 2) report, or Cybersecurity Maturity Model Certification (CMMC)). Will these certifications be in place for the duration of the contract? Will you provide the state with most recent and future audit reports related to these certifications?
6. Describe the policies, procedures and practices you have in place to provide for the physical security of your data centers and other sites where government information will be hosted, accessed or maintained.
7. Will government information be encrypted at rest? Will government information be encrypted when transmitted? Will government information be encrypted during data backups?
8. Describe safeguards that are in place to prevent unauthorized use, reuse, distribution, transmission, manipulation, copying, modification, access or disclosure of government information.
SERVICE PROVIDER SECURITY ASSESSMENT QUESTIONNAIRE
SERVICE PROVIDER SECURITY ASSESSMENT QUESTIONNAIRE (v12/2025) Page 2 of 2
9. What controls are in place to detect security breaches? Do you log transactions and network activity? How long do you maintain these audit logs??
10. How will government information be managed after contract termination? Will government information, provided to the Contractor, be deleted or destroyed? When will this occur?
11. Describe your incident response policies and practices to include agency notification of incident and pre-prepared communications plan for notifying individuals affected by the incident and the timeframes within all of these items are addressed.
12. Identify any third party which will host or have access to government information.
Offeror’s response to this questionnaire includes any other information submitted with its offer regarding information or data security.
SIGNATURE OF PERSON AUTHORIZED TO REPRESENT THE ACCURACY OF THIS INFORMATION
ON BEHALF OF CONTRACTOR:
By: ____________________________________ (Authorized Signature)
Its: ____________________________________ (Printed Name of person signing above)
Title: ____________________________________ (Title of person signing above)
Date: ____________________________________
File details come from the government source that posted it. Updated .