Third_Party_Questionnaire.xlsx
XLSX spreadsheet 1 MB Posted
- Attached to
- Advanced Traffic Management System Design Continuing Services State and local contract opportunity
- Solicitation number
- 26-18SS
- Issued by
- Sarasota County, Siesta Key CDP, Florida
About this file
This is a Third-Party Questionnaire file for the City of Sarasota, Florida's Advanced Traffic Management System (ATMS) Design Continuing Services procurement. The City is seeking multiple registered professional engineers to provide engineering services for the Regional ATMS on an as-needed basis under Florida's Consultant's Competitive Negotiation Act (CCNA). The procurement encompasses design and engineering support for the existing ATMS system serving Sarasota and Sarasota County, including preparation of preliminary studies, working drawings, specifications, cost estimates, and construction engineering and inspection services. The solicitation was posted on January 29, 2026, with proposals due by March 24, 2026, at 2:30 p.m., submitted electronically in PDF format and limited to 150 single-sided pages. The resulting contract will establish a pool of qualified engineering firms with a default one-year term and two optional one-year renewal periods, allowing for a total potential duration of three years. Consultants must maintain monthly coordination meetings and submit progress reports with draft invoices for approval prior to final invoicing.
Required qualifications include a minimum of five continuous years of experience providing signalization services for similar projects, active Florida professional engineer registration, and submission of four contractor references with a minimum of three confirmed references required. Evaluation criteria consist of four equally weighted categories: Qualifications of Company, Personnel qualifications, Relevant Project Experience and References, and Approach and Methodology, each worth 25 points, with pricing evaluated proportionally. Consultants must perform at least 51 percent of total contract work with their own organization, and professional liability insurance of no less than one million dollars is required. The project is federally funded through the Federal Emergency Management Agency (FEMA) and requires compliance with Davis-Bacon prevailing wage provisions, equal employment opportunity standards, and other federal contract requirements. Construction costs are restricted to projects not exceeding $7,500,000 and planning and study activities capped at $500,000, adjusted annually by the Bureau of Labor Statistics Consumer Price Index beginning July 1, 2025. Liquidated damages for project delays range from $12 per day for projects under $5,000 to $1,000 plus incremental charges for projects exceeding $700,000. No specific set-asides for disadvantaged or minority enterprises appear to be included in this solicitation.
View the file
Other files for this state and local contract opportunity
Show all 50
Advanced Traffic Management System Design Continuing Services has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Questionnaire
| City of Sarasota – Vendor Software Security Questionnaire (Version 1.0) | |
| The City of Sarasota requires all IT vendors to complete this questionnaire to ensure compliance with cybersecurity, privacy, and public sector standards. | |
| This includes alignment with CJIS, HIPAA, PCI DSS, and the Florida Sunshine Law. | |
| Please complete all questions and attach supporting documentation where requested. | |
| Use dropdowns for consistency. If a question is not applicable, explain why. | |
| For document requests, attach files directly or provide secure links in the comments. | |
| ERROR:#VALUE! | |
| Vendor Name | |
| Vendor Contact | |
| Vendor Email | |
| Vendor Phone | |
| Project Name | |
| Hosting Type | |
| Date Completed |
| # | Question | Risk Level | Response | Comments | Document Attached | Risk Score | Auto-Fail Reason |
| 1. Authentication & Access Control | |||||||
| 1.1 | Does your software integrate with a clients' Entra IdP for SSO | High | Yes | 0 | |||
| 1.2 | Does the solution integrate with Active Directory (on-prem or Azure AD)? | Medium | 0 | ||||
| 1.4 | Does the solution enforce least privilege and role-based access control (RBAC)? | High | 0 | ||||
| 1.5 | Are default passwords changed during installation and are complex or long (15+ characters) passwords enforced? | High | 0 | ||||
| 2. Data Protection & Encryption | |||||||
| 2.1 | What encryption protocols are used to protect data in transit and at rest? | High | 0 | ||||
| 2.2 | Is encryption at rest implemented using AES-256 or better? | High | 0 | ||||
| 2.3 | Is TLS 1.2 or higher used for data in transit? | High | 0 | ||||
| 2.4 | Are encryption keys securely managed (e.g., HSM, KMS)? | High | 0 | ||||
| 3. Security Testing & Vulnerability Management | |||||||
| 3.1 | Can you provide documentation of recent security testing or vulnerability assessments? | High | 0 | ||||
| 3.2 | Do you conduct regular vulnerability scans and penetration tests? | High | 0 | ||||
| 3.3 | Do you have a documented patch management process? | Medium | 0 | ||||
| 4. Incident Response & Breach Notification | |||||||
| 4.1 | Do you have a documented incident response and disaster recovery plan? | High | 0 | ||||
| 4.2 | Will you notify the City of Sarasota within 72 hours of a confirmed data breach? | High | 0 | ||||
| 4.3 | Are forensic investigations conducted as part of incident response? | Medium | 0 | ||||
| 5. Compliance & Certifications | |||||||
| 5.1 | What certifications or compliance standards has your software achieved (e.g., ISO, HIPAA, PCI DSS, CJIS)? | High | 0 | ||||
| 5.2 | Do you maintain cyber liability and professional liability insurance? | Medium | 0 | ||||
| 5.3 | Is your solution compliant with Florida Sunshine Law requirements for public records? | High | 0 | ||||
| 6. Privacy & Data Handling | |||||||
| 6.1 | How do you manage and store user data, and what privacy protections are in place? | Medium | 0 | ||||
| 6.2 | Is any data stored or processed outside the continental United States? | High | 0 | ||||
| 6.3 | Do you have a data retention and secure deletion policy? | Medium | 0 | ||||
| 7. Logging & Monitoring | |||||||
| 7.1 | Are security logs retained, protected from tampering, and reviewed regularly? | Medium | 0 | ||||
| 7.2 | Do you monitor privileged user activity for anomalies? | High | 0 | ||||
| 8. Business Continuity & Backup | |||||||
| 8.1 | Do you have a tested disaster recovery and business continuity plan? | High | 0 | ||||
| 8.2 | Are backups encrypted and stored in geographically redundant locations? | Medium | 0 | ||||
| 8.3 | What is you backup policy, RTO and RPO? | High | 0 | ||||
| 8.4 | Can the client data be exported if the client discontinues using your service? | High | 0 | ||||
| 9. Third-Party Risk | |||||||
| 9.1 | Do you assess the security posture of your subcontractors or third-party service providers? | High | 0 | ||||
| 10. Endpoint & Application Security | |||||||
| 10.1 | Are any antivirus exceptions required for your software? | Medium | 0 | ||||
| 10.2 | What types of information does your application store (e.g., PII, PHI, CJIS)? | High | 0 | ||||
| Total Risk Score | 0 | ||||||
| Low Risk |
Instructions 📋 City of Sarasota – Vendor Software Security Questionnaire Instructions
| Purpose |
| This questionnaire is used to evaluate the security posture of vendors providing software or cloud-based services to the City of Sarasota. It ensures compliance with cybersecurity, privacy, and public sector standards. |
| Instructions |
| If you answer anything other than "Yes" on 1.1, the application Auto Fails |
| Complete all questions in the Questionnaire tab. |
| Use dropdowns for consistency. |
| If a question is not applicable, select “N/A” and provide an explanation in the Vendor Comments column. |
| If you answer “No” or “Partial”, you must explain why in the Vendor Comments column. |
| Attach supporting documentation where requested. You may: |
| Embed documents directly in the Vendor Comments cell, or |
| Provide a secure link to the document. |
| Use the Document Attached column to indicate whether documentation is included. |
| Florida Public Sector Compliance |
| Vendors must comply with the following: |
| CJIS Security Policy if Criminal Justice Information (CJI) is processed or stored. |
| HIPAA if Protected Health Information (PHI) is involved. |
| PCI DSS if payment card data is processed. |
| Florida Sunshine Law: Vendors must be aware that all records related to City business may be subject to public disclosure. |
| Data Residency: All data must be stored within the continental United States unless explicitly approved by the City. |
| Scoring |
| Each question is assigned a risk level (Low, Medium, High). |
| Responses are scored as follows: |
| Yes = 0 points |
| Partial = 1 point |
| No = 2 points |
| N/A = 0 points |
| The score is multiplied by the risk level weight: |
| Low = 1 |
| Medium = 2 |
| High = 3 |
| A Total Risk Score is calculated at the bottom of the questionnaire. |
| Risk Categories |
| Score Range Risk Level |
| 0–20 Low Risk |
| 21–40 Medium Risk |
| 41+ High Risk |
Lists
| Response Options | Risk Levels | Hosting Types | Documents |
| Yes | Low | On-prem | Attached |
| No (Please Explain) | Medium | SaaS | Not Attached (Please Explain) |
| N/A (Please Explain) | High | IaaS | Not Applicable |
| Partial (Please Explain) | PaaS |
File details come from the government source that posted it. Updated .