Third_Party_Questionnaire.xlsx
XLSX spreadsheet 1 MB Posted
- Attached to
- Advanced Traffic Management System Design Continuing Services State and local contract opportunity
- Solicitation number
- 26-18SS
- Issued by
- Sarasota County, Siesta Key CDP, Florida
About this file
This Third Party Questionnaire document supports a Request for Qualifications issued by the City of Sarasota, Florida for Advanced Traffic Management System (ATMS) Design Continuing Services. The City seeks to establish a qualified pool of registered professional engineers to provide ongoing engineering services on an as-needed basis for the Regional ATMS project serving Sarasota and Sarasota County. Services required include attendance at project conferences, consultation, preliminary studies, working drawings and specifications preparation, scale and detail drawings, cost estimates, proposal development, space planning assistance, and analysis services. The project encompasses design and construction support for the existing, fully functional ATMS system with additional fiber communication installation coordinated across multiple City departments, Sarasota County, and potentially Manatee County. The solicitation follows Florida Statute 287.055 (Consultant's Competitive Negotiation Act) and applicable federal requirements under 2 CFR Part 200, as this is a FEMA-funded project. The City intends to make multiple awards establishing a library of qualified engineering firms for contract performance.
The questionnaire functions as a qualification screening tool to evaluate prospective consultants prior to final contract award. Selected firms will be responsible for providing all personnel, travel, software, equipment, and supplies necessary to deliver signalization and engineering design services. Pricing terms and specific contract duration details are to be negotiated following the qualification-based selection process. The continuing services contract structure allows the City flexibility to engage qualified consultants from the established pool as project needs arise, with potential for extended performance based on demonstrated capability and project requirements.
View the file
Other files for this state and local contract opportunity
Show all 50
Advanced Traffic Management System Design Continuing Services has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Questionnaire
| City of Sarasota – Vendor Software Security Questionnaire (Version 1.0) | |
| The City of Sarasota requires all IT vendors to complete this questionnaire to ensure compliance with cybersecurity, privacy, and public sector standards. | |
| This includes alignment with CJIS, HIPAA, PCI DSS, and the Florida Sunshine Law. | |
| Please complete all questions and attach supporting documentation where requested. | |
| Use dropdowns for consistency. If a question is not applicable, explain why. | |
| For document requests, attach files directly or provide secure links in the comments. | |
| ERROR:#VALUE! | |
| Vendor Name | |
| Vendor Contact | |
| Vendor Email | |
| Vendor Phone | |
| Project Name | |
| Hosting Type | |
| Date Completed |
| # | Question | Risk Level | Response | Comments | Document Attached | Risk Score | Auto-Fail Reason |
| 1. Authentication & Access Control | |||||||
| 1.1 | Does your software integrate with a clients' Entra IdP for SSO | High | Yes | 0 | |||
| 1.2 | Does the solution integrate with Active Directory (on-prem or Azure AD)? | Medium | 0 | ||||
| 1.4 | Does the solution enforce least privilege and role-based access control (RBAC)? | High | 0 | ||||
| 1.5 | Are default passwords changed during installation and are complex or long (15+ characters) passwords enforced? | High | 0 | ||||
| 2. Data Protection & Encryption | |||||||
| 2.1 | What encryption protocols are used to protect data in transit and at rest? | High | 0 | ||||
| 2.2 | Is encryption at rest implemented using AES-256 or better? | High | 0 | ||||
| 2.3 | Is TLS 1.2 or higher used for data in transit? | High | 0 | ||||
| 2.4 | Are encryption keys securely managed (e.g., HSM, KMS)? | High | 0 | ||||
| 3. Security Testing & Vulnerability Management | |||||||
| 3.1 | Can you provide documentation of recent security testing or vulnerability assessments? | High | 0 | ||||
| 3.2 | Do you conduct regular vulnerability scans and penetration tests? | High | 0 | ||||
| 3.3 | Do you have a documented patch management process? | Medium | 0 | ||||
| 4. Incident Response & Breach Notification | |||||||
| 4.1 | Do you have a documented incident response and disaster recovery plan? | High | 0 | ||||
| 4.2 | Will you notify the City of Sarasota within 72 hours of a confirmed data breach? | High | 0 | ||||
| 4.3 | Are forensic investigations conducted as part of incident response? | Medium | 0 | ||||
| 5. Compliance & Certifications | |||||||
| 5.1 | What certifications or compliance standards has your software achieved (e.g., ISO, HIPAA, PCI DSS, CJIS)? | High | 0 | ||||
| 5.2 | Do you maintain cyber liability and professional liability insurance? | Medium | 0 | ||||
| 5.3 | Is your solution compliant with Florida Sunshine Law requirements for public records? | High | 0 | ||||
| 6. Privacy & Data Handling | |||||||
| 6.1 | How do you manage and store user data, and what privacy protections are in place? | Medium | 0 | ||||
| 6.2 | Is any data stored or processed outside the continental United States? | High | 0 | ||||
| 6.3 | Do you have a data retention and secure deletion policy? | Medium | 0 | ||||
| 7. Logging & Monitoring | |||||||
| 7.1 | Are security logs retained, protected from tampering, and reviewed regularly? | Medium | 0 | ||||
| 7.2 | Do you monitor privileged user activity for anomalies? | High | 0 | ||||
| 8. Business Continuity & Backup | |||||||
| 8.1 | Do you have a tested disaster recovery and business continuity plan? | High | 0 | ||||
| 8.2 | Are backups encrypted and stored in geographically redundant locations? | Medium | 0 | ||||
| 8.3 | What is you backup policy, RTO and RPO? | High | 0 | ||||
| 8.4 | Can the client data be exported if the client discontinues using your service? | High | 0 | ||||
| 9. Third-Party Risk | |||||||
| 9.1 | Do you assess the security posture of your subcontractors or third-party service providers? | High | 0 | ||||
| 10. Endpoint & Application Security | |||||||
| 10.1 | Are any antivirus exceptions required for your software? | Medium | 0 | ||||
| 10.2 | What types of information does your application store (e.g., PII, PHI, CJIS)? | High | 0 | ||||
| Total Risk Score | 0 | ||||||
| Low Risk |
Instructions 📋 City of Sarasota – Vendor Software Security Questionnaire Instructions
| Purpose |
| This questionnaire is used to evaluate the security posture of vendors providing software or cloud-based services to the City of Sarasota. It ensures compliance with cybersecurity, privacy, and public sector standards. |
| Instructions |
| If you answer anything other than "Yes" on 1.1, the application Auto Fails |
| Complete all questions in the Questionnaire tab. |
| Use dropdowns for consistency. |
| If a question is not applicable, select “N/A” and provide an explanation in the Vendor Comments column. |
| If you answer “No” or “Partial”, you must explain why in the Vendor Comments column. |
| Attach supporting documentation where requested. You may: |
| Embed documents directly in the Vendor Comments cell, or |
| Provide a secure link to the document. |
| Use the Document Attached column to indicate whether documentation is included. |
| Florida Public Sector Compliance |
| Vendors must comply with the following: |
| CJIS Security Policy if Criminal Justice Information (CJI) is processed or stored. |
| HIPAA if Protected Health Information (PHI) is involved. |
| PCI DSS if payment card data is processed. |
| Florida Sunshine Law: Vendors must be aware that all records related to City business may be subject to public disclosure. |
| Data Residency: All data must be stored within the continental United States unless explicitly approved by the City. |
| Scoring |
| Each question is assigned a risk level (Low, Medium, High). |
| Responses are scored as follows: |
| Yes = 0 points |
| Partial = 1 point |
| No = 2 points |
| N/A = 0 points |
| The score is multiplied by the risk level weight: |
| Low = 1 |
| Medium = 2 |
| High = 3 |
| A Total Risk Score is calculated at the bottom of the questionnaire. |
| Risk Categories |
| Score Range Risk Level |
| 0–20 Low Risk |
| 21–40 Medium Risk |
| 41+ High Risk |
Lists
| Response Options | Risk Levels | Hosting Types | Documents |
| Yes | Low | On-prem | Attached |
| No (Please Explain) | Medium | SaaS | Not Attached (Please Explain) |
| N/A (Please Explain) | High | IaaS | Not Applicable |
| Partial (Please Explain) | PaaS |
File details come from the government source that posted it. Updated .