Third_Party_Questionnaire.xlsx
XLSX spreadsheet 1 MB Posted
- Attached to
- Advanced Traffic Management System Design Continuing Services State and local contract opportunity
- Solicitation number
- 26-18SS
- Issued by
- Sarasota County, Siesta Key CDP, Florida
About this file
This is a Third-Party Questionnaire file submitted as part of the City of Sarasota, Florida's Consultant's Competitive Negotiation Act (CCNA) procurement for Advanced Traffic Management System (ATMS) Design Continuing Services. The City seeks to establish a library of qualified professional engineers to provide design and engineering support services for the Regional ATMS serving Sarasota City and County, with potential coordination involving Sarasota County, Manatee County, the City of Bradenton, the Florida Department of Transportation, and other regional entities. Services include design and engineering support for the existing ATMS system, preparation of preliminary studies, working drawings, specifications, cost estimates, fiber optic communication infrastructure design, project conference attendance, and construction engineering and inspection services. The solicitation was posted on January 29, 2026, with proposals due by March 24, 2026, at 2:30 p.m. The contract will have a default term of one year with two optional one-year renewal periods for a maximum three-year duration. The City intends to make multiple awards to establish a qualified contractor pool.
Contractors must meet specified qualifications including a minimum of five continuous years of experience in signalization services, active Florida professional engineer registration, proof of drug-free workplace certification, and submission of four references with at least three confirmed. Evaluation criteria consist of four equally weighted categories at 25 points each: Company Qualifications, Personnel Qualifications, Relevant Project Experience and References, and Approach and Methodology, with pricing evaluated proportionally. The project is federally funded through the Federal Emergency Management Agency (FEMA), requiring compliance with Davis-Bacon prevailing wage provisions, equal employment opportunity standards, and other federal mandates. Construction costs are restricted to projects not exceeding $7,500,000 and planning activities to $500,000, with annual adjustments by the Consumer Price Index beginning July 1, 2025. Professional liability insurance of no less than one million dollars is required, and contractors must perform at least 51 percent of work with their own organization. Liquidated damages for project delays range from $12 per day for small projects to $1,000 plus incremental charges for projects exceeding $700,000. Proposals are limited to 150 single-sided pages in PDF format and must be submitted electronically through the City's online system.
View the file
Other files for this state and local contract opportunity
Show all 50
Advanced Traffic Management System Design Continuing Services has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Questionnaire
| City of Sarasota – Vendor Software Security Questionnaire (Version 1.0) | |
| The City of Sarasota requires all IT vendors to complete this questionnaire to ensure compliance with cybersecurity, privacy, and public sector standards. | |
| This includes alignment with CJIS, HIPAA, PCI DSS, and the Florida Sunshine Law. | |
| Please complete all questions and attach supporting documentation where requested. | |
| Use dropdowns for consistency. If a question is not applicable, explain why. | |
| For document requests, attach files directly or provide secure links in the comments. | |
| ERROR:#VALUE! | |
| Vendor Name | |
| Vendor Contact | |
| Vendor Email | |
| Vendor Phone | |
| Project Name | |
| Hosting Type | |
| Date Completed |
| # | Question | Risk Level | Response | Comments | Document Attached | Risk Score | Auto-Fail Reason |
| 1. Authentication & Access Control | |||||||
| 1.1 | Does your software integrate with a clients' Entra IdP for SSO | High | Yes | 0 | |||
| 1.2 | Does the solution integrate with Active Directory (on-prem or Azure AD)? | Medium | 0 | ||||
| 1.4 | Does the solution enforce least privilege and role-based access control (RBAC)? | High | 0 | ||||
| 1.5 | Are default passwords changed during installation and are complex or long (15+ characters) passwords enforced? | High | 0 | ||||
| 2. Data Protection & Encryption | |||||||
| 2.1 | What encryption protocols are used to protect data in transit and at rest? | High | 0 | ||||
| 2.2 | Is encryption at rest implemented using AES-256 or better? | High | 0 | ||||
| 2.3 | Is TLS 1.2 or higher used for data in transit? | High | 0 | ||||
| 2.4 | Are encryption keys securely managed (e.g., HSM, KMS)? | High | 0 | ||||
| 3. Security Testing & Vulnerability Management | |||||||
| 3.1 | Can you provide documentation of recent security testing or vulnerability assessments? | High | 0 | ||||
| 3.2 | Do you conduct regular vulnerability scans and penetration tests? | High | 0 | ||||
| 3.3 | Do you have a documented patch management process? | Medium | 0 | ||||
| 4. Incident Response & Breach Notification | |||||||
| 4.1 | Do you have a documented incident response and disaster recovery plan? | High | 0 | ||||
| 4.2 | Will you notify the City of Sarasota within 72 hours of a confirmed data breach? | High | 0 | ||||
| 4.3 | Are forensic investigations conducted as part of incident response? | Medium | 0 | ||||
| 5. Compliance & Certifications | |||||||
| 5.1 | What certifications or compliance standards has your software achieved (e.g., ISO, HIPAA, PCI DSS, CJIS)? | High | 0 | ||||
| 5.2 | Do you maintain cyber liability and professional liability insurance? | Medium | 0 | ||||
| 5.3 | Is your solution compliant with Florida Sunshine Law requirements for public records? | High | 0 | ||||
| 6. Privacy & Data Handling | |||||||
| 6.1 | How do you manage and store user data, and what privacy protections are in place? | Medium | 0 | ||||
| 6.2 | Is any data stored or processed outside the continental United States? | High | 0 | ||||
| 6.3 | Do you have a data retention and secure deletion policy? | Medium | 0 | ||||
| 7. Logging & Monitoring | |||||||
| 7.1 | Are security logs retained, protected from tampering, and reviewed regularly? | Medium | 0 | ||||
| 7.2 | Do you monitor privileged user activity for anomalies? | High | 0 | ||||
| 8. Business Continuity & Backup | |||||||
| 8.1 | Do you have a tested disaster recovery and business continuity plan? | High | 0 | ||||
| 8.2 | Are backups encrypted and stored in geographically redundant locations? | Medium | 0 | ||||
| 8.3 | What is you backup policy, RTO and RPO? | High | 0 | ||||
| 8.4 | Can the client data be exported if the client discontinues using your service? | High | 0 | ||||
| 9. Third-Party Risk | |||||||
| 9.1 | Do you assess the security posture of your subcontractors or third-party service providers? | High | 0 | ||||
| 10. Endpoint & Application Security | |||||||
| 10.1 | Are any antivirus exceptions required for your software? | Medium | 0 | ||||
| 10.2 | What types of information does your application store (e.g., PII, PHI, CJIS)? | High | 0 | ||||
| Total Risk Score | 0 | ||||||
| Low Risk |
Instructions 📋 City of Sarasota – Vendor Software Security Questionnaire Instructions
| Purpose |
| This questionnaire is used to evaluate the security posture of vendors providing software or cloud-based services to the City of Sarasota. It ensures compliance with cybersecurity, privacy, and public sector standards. |
| Instructions |
| If you answer anything other than "Yes" on 1.1, the application Auto Fails |
| Complete all questions in the Questionnaire tab. |
| Use dropdowns for consistency. |
| If a question is not applicable, select “N/A” and provide an explanation in the Vendor Comments column. |
| If you answer “No” or “Partial”, you must explain why in the Vendor Comments column. |
| Attach supporting documentation where requested. You may: |
| Embed documents directly in the Vendor Comments cell, or |
| Provide a secure link to the document. |
| Use the Document Attached column to indicate whether documentation is included. |
| Florida Public Sector Compliance |
| Vendors must comply with the following: |
| CJIS Security Policy if Criminal Justice Information (CJI) is processed or stored. |
| HIPAA if Protected Health Information (PHI) is involved. |
| PCI DSS if payment card data is processed. |
| Florida Sunshine Law: Vendors must be aware that all records related to City business may be subject to public disclosure. |
| Data Residency: All data must be stored within the continental United States unless explicitly approved by the City. |
| Scoring |
| Each question is assigned a risk level (Low, Medium, High). |
| Responses are scored as follows: |
| Yes = 0 points |
| Partial = 1 point |
| No = 2 points |
| N/A = 0 points |
| The score is multiplied by the risk level weight: |
| Low = 1 |
| Medium = 2 |
| High = 3 |
| A Total Risk Score is calculated at the bottom of the questionnaire. |
| Risk Categories |
| Score Range Risk Level |
| 0–20 Low Risk |
| 21–40 Medium Risk |
| 41+ High Risk |
Lists
| Response Options | Risk Levels | Hosting Types | Documents |
| Yes | Low | On-prem | Attached |
| No (Please Explain) | Medium | SaaS | Not Attached (Please Explain) |
| N/A (Please Explain) | High | IaaS | Not Applicable |
| Partial (Please Explain) | PaaS |
File details come from the government source that posted it. Updated .