UPDATED ATTACHMENT B: DATA SECURITY AND GOVERNANCE - INFORMATION.pdf
PDF 310 KB Posted
- Attached to
- COMPUTERIZED MAINTENANCE MANAGEMENT State and local contract opportunity
- Solicitation number
- 5400027309
- Issued by
- Horry County, South Carolina
About this file
This is a Data Security and Governance Requirements document issued by Coastal Carolina University's Office of Information Technology Services/Chief Information Officer for a computerized maintenance management system procurement in South Carolina. The document establishes comprehensive information security and compliance standards that vendors must address in their proposals, including adherence to federal and state regulations such as FERPA, HIPAA, GDPR, and the Graham-Bliley Act, as well as CCU's internal IT policies. Vendors are required to address data protection measures, user authentication and access controls, software and system security integrity, information security policies and practices, third-party partner involvement, business continuity and disaster recovery plans, and accessibility requirements including VPAT certification or WCAG 2.0 compliance documentation. The document requires detailed responses regarding system architecture for both onsite and SaaS/cloud-based solutions, including hardware requirements, network communications specifications, data governance practices, change management procedures, and integration capabilities with existing university systems.
The requirements specify that vendors must demonstrate PCI-DSS compliance with annual attestation if processing financial transactions, implement encryption both in transit and at rest with Continental United States-based hosting facilities, and ensure seamless integration with specific university systems including Ellucian Colleague ERP, One Card Systems/CBORD, and state-approved payment processing gateways. Vendors must provide detailed cost breakdowns for any modifications, customizations, or additional services required to meet stated requirements, including one-time implementation costs and ongoing annual support expenses. The document mandates that all data transfer utilize secure methods such as SSL, that single sign-on implementation be Azure or SAML compatible, and that email communications employ DKIM, SPF, and DMARC protection. Additionally, vendors must describe their procedures for data retention, disposal, system access controls, termination and exit processes, and provide evidence of information security program compliance through independent auditing where applicable.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment 1.docx | DOCX document | |
| ATTACHMENT C: PRICE PROPOSAL WORKBOOK.xlsx | XLSX spreadsheet | |
| Amendment 2.docx | DOCX document | |
| Solicitation 5400027309.rtf | RTF text file | |
| Award Posting Notice.doc | DOC document | |
| Amendment 3.docx | DOCX document | |
| Award Extension.doc | DOC document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Questions directed to the Office of ITS/CIO
Data Security and Governance - Information Security and Access Control CCU-Office of ITS/CIO
The proposed solution must adhere to federal and state regulations (FERPA, HIPAA, GDPR, Graham-Bliley Act, etc.) as well as to CCU’s Information Technology Service (ITS) policies and procedures with regards to data protection and privacy, firewalls, email and access policies and procedures including, but not limited to:
General Usage – Network and Computing Policy Data Privacy, Classification, and Protection Policy
Access ITS Policies here: https://www.coastal.edu/cito/policies/
Information Security Questions If modifications or additional costs are needed for the solution to meet any referenced requirement, detailed costs of services, products and components must be listed or attached to the proposal.
1. Data Protection (e.g., unauthorized access or disclosure):
a. What measures are used to separate CCU’s data from other clients’ data, if any?
2. Users’ Authentication and Access: a. How does the solution handle single sign on capabilities, if implemented?
b. How does the solution handle logging/auditing capabilities (internally and externally)?
c. Does the solution maintain a signed audit trail of user(s) performance including actions taken and when? If so, how is this accomplished?
d. What are the supported browsers?
3. Software and system security and integrity:
a. What measures are in place to protect against web security flaws such as SQL injection, XSS, broken authentication and session management?
4. Information security policies and practices:
a. What measures (e.g., training, processes, background checks, etc.) does the offeror provide to ensure employees will safeguard data?
b. Does the offeror have an established information security program (that adheres to applicable Federal, and State regulations and Information Security standards, guidelines, and best practices) to fully address confidentiality, integrity and availability of data? Can a copy of the IS https://www.coastal.edu/policies/policyDetails.php?x=214 https://www.coastal.edu/policies/policyDetails.php?x=238 https://www.coastal.edu/cito/policies/
Program be provided to CCU, including auditing by an independent entity?
5. Third party partners: a. Are there third-party technology partners used for the solution to work?
b. Has any external auditing been conducted?
Can it be verified?
Other Requirements:
a. Describe the offeror’s business continuity and disaster recovery plans.
b. If implemented, single sign-on must be Azure or SAML compatible.
c. Any email communications generated by the offeror must employ a combination of DKIM, SPF, DMARC to ensure domain protection and to increase deliverability.
d. Data encryption must be accommodated in transit and “at rest”.
e. The equipment hosting the solution for the University must be located in a physically secure facility and within the boundary of the Continental United States of America.
f. Describe Offeror’s data and physical security practices for hosted or cloud-based solutions.
g. Provide offeror’s procedures for data and system access, data retention, disposal and replacement of hard drives and disposal of backup tapes.
h. Is Offeror’s system in a shared environment? Will CCU have a dedicated system or instance of Offeror’s solution? What are the offeror’s firewall port requirements for cloud- based solutions?
i. Does the offeror have specific IP’s that can be matched to firewall rules?
i. If the system to be integrated with CCU systems (e.g., Ellucian Colleague, SSO, etc.), what are the required IT resources and hours during the initial implementation and thereafter? Please describe and state in detail the types of IT resources required, initial and ongoing required hours to implement and support the solution.
j. Describer Offeror’s termination or exit process for ensuring successful transition to an alternative solution.
k. Must adhere to the University’s Information Technology Service (ITS) policies and procedures with regards to firewalls, email, domain and access policies and procedures as well as industry best standards.
l. The solution must natively handle email capabilities and adhere to industry best practices.
m. The solution must be PCI-DSS (latest industry acceptable version) Compliant with eP2P encryption devices if processing financial transactions.
n. The solution must use SC State contract merchant services processor and compatible payment gateway based on the current SC state requirements.
o. The solution must have the ability to securely export monthly credit card payment details into an Excel worksheet from the solution.
p. SRED keypads or secure device to process telephone payments without inputting credit/ debit card numbers into CCU computer keyboards.
Provide Attestation of Compliance to PCI-DSS Standards to the university on an annual basis.
Possible future integration with solutions such as TouchNet, etc.
m.
n.
akshell Cross-Out akshell Cross-Out akshell Cross-Out
Data Governance and Security - Information Security Data Elements Checklist CCU Office of ITS/CIO
CCU requires that third-party contractors and partners protect and safeguard University information or information that’s entrusted to the University. All contractors who transmit, access, process or store compliant data are required to agree to federal, state regulations as well as industry standards/best practices and CCU’s standards and policies.
1. Will the offeror as a third party be:
(Please Check all that apply)
☐ Transmitting ☐ Accessing ☐ Processing ☐ Storing University Data
2. How many records will be involved? ☐ 250 ☐ 251-500 ☐ 501-1000 ☐ 1000+
3. Data elements to be transmitted, accessed, processed or stored by the Offeror.
☐ Social Security Numbers ☐ Driver’s License Number or State ☐ Identification Card Number ☐ Personal Financial Information:
Account #, Account Password, ☐ Personal Identification Number (PIN) ☐ DOD classified data, or special Sensitive
Data ☐ Protected Health Information (PHI) ☐ Covered by insurance.
☐ Payment card data (credit or debit card) ☐ We will be using a third-party merchant account.
☐ Unsure what merchants will be used.
☐ Student information FERPA data or directory information that students have opted not to have released.
☐ Academic evaluations such as tests, scores, and transcripts.
☐ General counseling/advising records.
☐ Disciplinary records.
☐ Financial aid records, including loan collection records.
☐ Disability status/medical issues.
☐ Which SAQ does the offeror fill for PCI-
DSS compliance?
☐ Any other University non-public data
(Compliant or Business Sensitive) not shown above. Please Provide Examples:
Accessibility Requirements:
Since the solution would have end-user human interface (e.g., end-user device software component, web pages or sites, video or audio playback, file upload system, mobile device components, etc.), the offeror must submit one or both of the following assessments that users, instructors, system administrators, etc., are expected to interact with.
1. A current and accurate "Voluntary Product Accessibility Template", or VPAT, (see http://www.itic.org/public-policy/accessibility), to document products and/or services' conformance and deviations from Section 508 of the Rehabilitation Act of 1973.
2. A detailed description of the accessibility features that shows and explains compliance with and deviations from the guidelines of the "Web Content Accessibility Guidelines (WCAG) 2.0” published by www.w3.org.
General Information Technology Questionnaires:
The system requirements should reflect delivered/“out-of-the-box” functionality. Offerors must indicate if modifications, additional product costs or if any other accommodation would be necessary to meet any of the requirements. Additional costs, customizations or upgrades must be provided, detailing the costs and item descriptions. Costs will include any one-time/initial costs as well as ongoing annual support costs.
1. Onsite solutions a. Please describe in detail the hardware, core product software, storage and database requirements.
b. Please describe the minimum desktop workstation hardware and software requirements required by the solution.
c. Please describe details of required network communications (e.g., port numbers, protocol, etc.).
2. SaaS/hosted/cloud solutions a. Please list normal scheduled downtime frequency, uptime percentage, etc.
b. Please describe the minimum desktop workstation hardware and software requirements required by the solution.
c. Please describe details of network communications required between the solution and other solutions including University systems.
d. Please describe deployment instances of the environment (e.g., test, development, and production). Are all of the instances available to CCU? If yes, detail the types of instances and how access would be provided.
e. Please reference the vendor SLA (Service http://www.itic.org/public-policy/accessibility http://www.w3.org/
Level Agreement) support requests.
3. Solution components that are provided by third-party partners, including OEM software, hosting, internal application network, etc.
a. Please describe the third-party components.
b. Please provide third-party technology partner(s) name(s), address(es) and contact(s).
c. Please explain additional costs or fees associated with the referenced components.
4. Practices and policies related to data stored by this solution
a. Please describe how data will be “completely erased” upon the contract termination.
b. Please clarify data ownership rights and responsibilities of the parties and provisions for CCU obtaining the data as needed.
c. Please indicate types of data stored especially if any data is protected (e.g., HIPAA, FERPA, etc.).
d. Please indicate how long data is stored or archived.
e. Please describe the technology, practices and policies you have in place that would protect CCU data from unauthorized access and use.
f. Does company provide full data sanitization to ensure the integrity of imported data.
5. Business continuity and disaster recovery management practices
a. If the software is deployed in multiple data centers, how often is data synchronized between the data centers?
b. Please describe the strategies to minimize downtime in the event of a catastrophic failure of the hosting environment(s) or components.
c. Would CCU experience any loss of data as a result of downtime, system problems or catastrophic failure? If yes, describe the situations that could result in loss of CCU data.
d. How much downtime should CCU expect for a catastrophic failure?
6. Change management practices for all hardware and software components
a. How often is the software updated and releases made available?
b. How is CCU notified of new updates or upgrades?
c. Are updates and upgrades mandatory?
d. What provisions are there for managing customization requested by CCU?
e. How are the system functionality is appropriately tested before changes go into production?
f. Will CCU play a role in reviewing and approving changes?
g. Are there any dashboards to display system performance and health in real time?
7. Provide detailed information regarding browser requirements for the proposed solution to meet the functionality and system requirements, including any specific required versions and/or add-ins.
8. Describe the mobile capabilities available a. Please indicate supported mobile platforms.
with the proposed solution b. Please describe the limitations of mobile application implementation.
c. Please explain how and when mobile updates are provided.
d. Please explain how you ensure that all mobile interfaces to your solution comply with disability accessibility requirements such as Section 508 and/or WCAG.
9. Does the solution provide data exports for upload to CCU systems? If so, please describe the types of information exported and the process employed.
10. Does the solution have the ability to automate data importing and exporting?
11. Does the solution come with a comprehensive data dictionary of the database?
12. Identity Management System a. If the solution integrates with identity management systems, please describe the delivery mechanism of this component.
b. Please describe the SSO implementation requirements.
c. Does the solution deliver an API that would allow for the remote management of user authorization data? If yes, please describe how.
13. Please describe the ongoing functions to be performed by CCU system and application administrators? Does the solution need a full-time staff member to be administered?
14. What is the maximum number of logged in concurrent users can the solution support? How does the system define concurrent users?
Data Governance and Security - Interface Data Exchange Requirements CCU Office of ITS/CIO Transfer of data must be accomplished only via using secure methods such as, but not limited to SSL. Offerors must provide secure file transfer solutions and may recommend alternative processes if they would be beneficial to CCU. Alternatives must be described in detail and are subject to CCU's approval. For all proposed transmission methods, the offerors must provide the technical requirements, processing transactions, a detailed description of security and authorization processes and requirements, forms, encryption or authentication requirements, and devices or digital certificates, alternatives available if the standard transmission method fails, plus a disclosure on any software limitations on file sizes or numbers of records in a batch.
Requirements should reflect delivered/”out-of-the-box” functionality. Offerors must indicate if system modifications, additional product or costs or if any other accommodation would be necessary to meet any requirement. Additional costs customizations or upgrades must be provided in detail.
Technical Interface Data Exchange
1. Please provide details on security protections for the Interface Data Exchange that are afforded by the solution proposed?
2. Does your solution support the needs for sharing and linking data with other applications and databases?
3. If integration is required, does the system seamlessly integrate with One Card Systems, specifically CBORD? What are the associated costs (e.g., technology and staff resources) to ensure integration with CBORD?
4. The proposed solution must interface with an online payment processing gateway for eCommerce services such as online payments. The proposed solution must be able to interface seamlessly with the University’s state-approved payment card processor “Payment Gateway”. The solution should utilize the University’s login as referenced in Appendix M Question 15 and TouchNet payment systems.
a. Is the proposed solution an existing FirstData partner?
b. If not an existing FirstData Ready Partner:
i. Can the solution integrate with the
FirstData platform at the Offeror’s expense? A time frame for accomplishing this integration must be provided.
ii. Does the solution currently have an existing website for accepting payments?
If so, please provide that URL and assurances that it is PCI-DSS compliant.
iii. Does this solution use a third-party application for accepting payments? If so, who is the third-party service provider of the application, and provide assurance that the application is PA-DSS compliant.
c. What other Payment Gateways does the Offeror partner with (e.g. TouchNet, etc.)
6. If integration with University ERP (Ellucian Colleague – Unidata database-based) is requested, is there an existing/”out-of-the-box" interface with the ERP, or would a custom interface need to be developed? Please provide details of any additional costs for seamless ethos integration.
7. Does the solution allow easy secure integration with other applications including desktop tools (i.e. Microsoft Office Professional Suite)?
8. Does the solution provide for auto/mass load of new and existing records (including ID records), matching on IDs where necessary (non-ID records) to obtain data from external sources? Users MUST be able to perform the load, preview it online, and set additional rules before committing it to the database. It is preferable that a wizard or other user aid be available for this purpose. Some "uploads" may be updating existing records.
9. Does the solution utilize email communication? (if yes, please answer the following)
a. Will email communication be uni-directional (i.e. notifications only (noreply)) or bi-directional capable?
b. Describe the way the emails will be generated, regarding headers and the measures taken to ensure they pass authorization checks and deliverability success.
c. Do you supply the email services directly or does the solution utilize a hosted email service (e.g. amazonses, etc.))
File details come from the government source that posted it. Updated .