VendorSecurityAssessment.xlsx

XLSX spreadsheet 990 KB Posted

Attached to
Integrated Data Dashboard State and local contract opportunity
Solicitation number
EV00000677
Issued by
Oklahoma

About this file

The document is a Vendor Security Assessment spreadsheet created by the State of Oklahoma's Office of Management and Enterprise Services (OMES) IS Cybercommand, designed to assess and manage cybersecurity risks from potential IT service and product vendors. The purpose of the assessment is to comprehensively evaluate a vendor's internal security posture, ensuring their environment and security protocols meet the state's minimum security requirements before issuing an Authority to Operate (AOO). The assessment covers 21 distinct security domains, including demographics, service-specific details, governance, device management, software management, secure configuration, log monitoring, identity and access management, account management, protection capabilities, training, incident response, recovery, business continuity, vendor management, event history, and specialized areas like HIPAA compliance, biometrics, and payment card industry standards.

The assessment is structured as a maturity rating questionnaire, with vendors required to self-assess their cybersecurity capabilities across multiple dimensions, ranging from "Nonexistent" to "Optimized" levels. Each section includes detailed questions about the organization's security practices, tools, policies, and historical performance, with specific focus on areas such as encryption, data protection, incident response, backup procedures, third-party risk management, and compliance with various regulatory standards. The document includes a risk matrix that allows the state to evaluate potential security risks based on the vendor's responses, with risk levels ranging from LOW to EXTREME, helping OMES make informed decisions about vendor security and potential vulnerabilities in their information technology ecosystem.

View the file

Other files for this state and local contract opportunity

Other files attached to Integrated Data Dashboard, newest first.
File Type Posted
Attachment_B_-_State_Full_Terms_.pdf PDF
OMESFormCP004.pdf PDF
Attachment_A_-_Agency-purpose.pdf PDF
Attachment_D_-_IT_Terms.pdf PDF
Exhibit_01_-_Proposal_Requirements.pdf PDF
Exhibit_02_-_Technical_Requirements.pdf PDF
Exhibit_04_-ThirdPartySupplierInfo_.xlsx XLSX spreadsheet
EV00000677_Agency_Non-negotiable_Bid_instructions.pdf PDF
Exhibit_03_-_Project_Timeline.pdf PDF
Exhibit_05_-_Cost_Proposal_.xlsx XLSX spreadsheet
Fillable_OMESFormCP076.pdf PDF
Attachment_G_-_Federal_Funding_Terms.pdf PDF
Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Instruction

Assessment NameSecurity Assessment
Organization NameState of Oklahome - OMES IS Cybercommand
PurposeThe purpose of the assessment is for the State of Oklahoma to Identify and manage any risk stemming from our business partnerships. All suppliers offering IT related services and/or products are required to complete this assessment prior to issuance of an Authority to Operate (AOO). This assessment is designed to allow us to gain a better understanding of our supplier’s internal security posture, along with the product, service, and/or solution being offered. Our tools, platforms, and procedures should have no bearing on the enterprise security controls of the suppliers. The State wants to ensure the vendor's overall environment and security protocols will meet the State's minimum-security requirements.
Maturity level

1 - Demographics

Organization Answering Questionnaire
System Name or Service for which this applies
State of Oklahoma Security Policy
https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf
Demographics
#QuestionAnswer
D-1Company's Legal Name
D-2Primary Website URL
D-3Primary Contact Name
D-4Primary Contact Email
D-5Primary Contact Phone
D-6Alternate Contact Name
D-7Alternate Contact Email
D-8Alternate Contact Phone
D-9Please describe the product or service your organization will be providing the State of Oklahoma.
D-10Please describe the type of service or product being provided the State of Oklahoma. (i.e. SaaS, PaaS, IaaS, Hardware, Staffing, etc.)

2 - Service Specific

Organization Answering Questionnaire
System Name or Service for which this applies
State of Oklahoma Security Policy
https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdfEnter a Value in the corresponding Maturity Rating Box
Service SpecificStatusMaturity RatingExplanation / Comments
#Question(Y/N)NonexistentInitial / Ad HocRepeatable but intuitiveDefinedManaged & MeasureableOptimized
SS-1This section is strictly regarding the service or product being provided to the State of Oklahoma. All other sections in this assessment will be in regards to your organziations internal security posture, processes, and procedures.
SS-2Does the system store, host, transmit or process any sensitive data?
SS-3Sensitive defined as any data that may contain information protected by state statutes or federal regulations.
SS-4Sensitive defined as not protected, however contains information that must be secured for the continuity or security of state government or individuals. That if such data were disclosed likely harm would occur to the state, the security posture of the state or individuals.
SS-5Does your organization have resources outside the U.S that will host, store, transmit, process or access State of Oklahoma data?
SS-6Will your organization host, store, transmit, process, or access and regulated sensitive or non-regulated sensitive data? (i.e. PHI/HIPAA, PII, CJI, FTI FERPA, etc.)
SS-7Will a non-resident individual or corporation of the U.S. have physical or logical access to State of Oklahoma Data?
SS-8Will any support contacts of the solution provider for hardware, software, or other technical support allow for the physical or logical access of a non US resident or corporation?
SS-9Does the solution provider have a Help Desk function that allows for the support intake and handling of IT and /or security related services?
SS-10Does the solution provider engage in E-Commerce activity on behalf of the State of Oklahoma?
SS-11Does the solution provider outsource or subcontract any portion of the services that are being contracted on the behalf of the State of Oklahoma?

3 - Governance

Organization Answering Questionnaire
System Name or Service for which this applies
State of Oklahoma Security Policy
https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdfEnter a Value in the corresponding Maturity Rating Box
GovernanceStatusMaturity RatingExplanation / Comments
#Question(Y/N)NonexistentInitial / Ad HocRepeatable but intuitiveDefinedManaged & MeasureableOptimized
G-1Does your organization have a Chief Information Security Officer (CISO), Chief Security Officer (CIO) or functional equivalent?
G-2Does this individual periodically brief the CEO, Board of Directors, or equivalent on the security posture and maturity levels of the organization?
G-3Are any of the following IT services outsourced by your organization to a third party vendor? (Please describe in the comments section to the right.)
G-4Does your organization have a cyber / information security policy?
G-5Does your organization have an Acceptable Use Policy (AUP) that defines the ranges of permitted use of company-provided technologies, and contains consequences for noncompliance/violations of the AUP?
G-6Does your organization have an Insider Threat Program in order to deter, detect, and mitigate insider threats?
G-7Does your organization follow a specific cybersecurity standard, framework, or set of best practices? If yes, please decribe in the comments section to the right.
G-8Does your organization currently have documented enterprise or company-wide privacy policies in place? If no, please clarify in the comments seciton to the right.
G-9Does your organization have a physical security program in place with risk-based protections (CCTV, visitor access controls, alarms, etc.) to secure offices and/or data centers?
G-10Does your organization perform background checks on all new/temporary employees, and contractors? If yes, please describe what your bcakground check consists of in the comment section to the right.
G-11Does your organization conduct security assessments and periodic re-assessments on third party partners/vendors and other service providers with access to information assets?
G-12Does your organization engage with third party auditors to assess your information/cybersecurity program and associated controls? If so, please specify in the comments section to the right.

4 - Device Management

Organization Answering Questionnaire
System Name or Service for which this applies
State of Oklahoma Security Policy
https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdfEnter a Value in the corresponding Maturity Rating Box
Device ManagementStatusMaturity RatingExplanation / Comments
#Question(Y/N)NonexistentInitial / Ad HocRepeatable but intuitiveDefinedManaged & MeasureableOptimized
DM-1Does your organization have an inventory management program for all hardware assets?
DM-2Are inventories conducted on a regular basis? (i.e. Quarterly, Annually, etc.)
DM-3Is the hardware inventory documented?
DM-4Does your organization maintain an inventory of the percentage of third party or vendor managed assets residing outside of the organizations network and not under your organizations control that has access to or processes your information assets (Cloud, SaaS, etc.)?

5 - Software Management

Organization Answering Questionnaire
System Name or Service for which this applies
State of Oklahoma Security Policy
https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdfEnter a Value in the corresponding Maturity Rating Box
Software ManagementStatusMaturity RatingExplanation / Comments
#Requirement(Y/N)NonexistentInitial / Ad HocRepeatable but intuitiveDefinedManaged & MeasureableOptimized
SM-1Does your organization maintain an inventory of all software in use?
SM-2How often is this inventory updated?
SM-3Does this inventory include operating systems and versions currently in use?
SM-4Does your organization currently whitelist software, in conjunction with the software inventory to ensure only approved software is on organizational assets?

6 - Secure Configuration

Organization Answering Questionnaire
System Name or Service for which this applies
State of Oklahoma Security Policy
https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdfEnter a Value in the corresponding Maturity Rating Box
Secure ConfigurationStatusMaturity RatingExplanation / Comments
#Question(Y/N)NonexistentInitial / Ad HocRepeatable but intuitiveDefinedManaged & MeasureableOptimized
SC-1Does your organization maintain standard secure configuration images for operating systems and software applications?
SC-2Do these standard configurations incorporate industry recognized security hardening techniques?
SC-3Does your organization employ a system configuration management tool (Active Directory Group Policy, etc.) that enforce and re-deploy configuration settings to systems?
SC-4In your organization, are the software development, testing, and production environments separated?

7 - Log Monitoring

Organization Answering Questionnaire
System Name or Service for which this applies
State of Oklahoma Security Policy
https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdfEnter a Value in the corresponding Maturity Rating Box
Log MonitoringStatusMaturity RatingExplanation / Comments
#Question(Y/N)NonexistentInitial / Ad HocRepeatable but intuitiveDefinedManaged & MeasureableOptimized
LM-1Has your organization implemented standard audit logging policies for hardware and software?
LM-2Does this policy require a timestamp, source address, destination address, and other useful data sets?
LM-3Are these logs kept in a standardized format, such as syslog or Common Event Expression?
LM-4Do these logs include access and/or changes to sensitive data?
LM-5How long are these audit logs kept?
LM-6Are network boundary devices (firewalls, network-based Intrusion Prevention Systems/Intrusion Detection Systems, and/or inbound & outbound proxies) logging traffic both allowed and blocked?
LM-7Does your organizaiton utilize a SIEM, Dedicated Security Personnel, or Third-Party service to analyze audit logs, reports, and alerts on a regular basis to identify unusual activity?
LM-8Does your organization have security personnel/system administrators that review anomalies to identify unauthorized activity and resolve per an incident response plan?
LM-9Does your organization have a SIEM(Security Information and Event Management) tool, or other similar logging tool for unified aggregation, consolidation, correlation, analysis, and alerting?
LM-10Is this log tool updated regularly to minimize false positives and insignificant alerts?

8 - IAM

Organization Answering Questionnaire
System Name or Service for which this applies
State of Oklahoma Security Policy
https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdfEnter a Value in the corresponding Maturity Rating Box
Identity & Access ManagementStatusMaturity RatingExplanation / Comments
#Question(Y/N)NonexistentInitial / Ad HocRepeatable but intuitiveDefinedManaged & MeasureableOptimized
IAM-1Does your organization utilize a service for directory services, identity providers (IdP), Federation and/or rights privileges management? (i.e. Microsoft Active Directory, Azure Active Directory, Okta, Ping, Active Directory Federation Services, Google Workspaces, etc.)
IAM-2Does your organiation have controls in place to protect user accounts with administrator privileges? (Please describe in the comments section to the right)
IAM-3Do you have controls in place for privileged service accounts? (i.e. Inventories on accounts conducted at least quarterly, password lengths of at least 25 characters, passwords rotated at least annually, etc.)

9 - Account Management

Organization Answering Questionnaire
System Name or Service for which this applies
State of Oklahoma Security Policy
https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdfEnter a Value in the corresponding Maturity Rating Box
Account ManagementStatusMaturity RatingExplanation / Comments
#Question(Y/N)NonexistentInitial / Ad HocRepeatable but intuitiveDefinedManaged & MeasureableOptimized
AM-1Does your organization review user accounts regulary to confirm they are still valid? If yes, please describe how often these reviews are conducted in the comments section to the right.
AM-2Do user accounts have an expiration date that is enforced, or is there a documented process to disable accounts immediately upon termination of employment?
AM-3Are user accounts disabled after at least 60 days of inactivity?
AM-4Does your organization have a formalized process to disable accounts upon termination of an employee, contractor/consultant, or third-party user?
AM-5Does your system automatically engage a screensaver lockout after a set period of time to limit access to unattended computers?
AM-6In your organization, are accounts automatically locked after a set number of failed login attempts? If yes, please describe how locked accounts are unlocked by end-users in the comments section to the right.
AM-7Does your organization have controls in place that enforces minimum password requirements?
AM-8Does your organization utilize MFA (Multi-Factor Authentication) for user, administrative, and/or privileged accounts?
AM-9Does your organization require multi-factor authentication for remote login access to your corporate network?
AM-10Does your organization utilize remote access protocols, such as Remote Desktop Protocol (RDP), VPN, SSH, SFTP or other similar protocols to securely access your internal corporate network remotely? If yes, please describe the protocol utilized.

10 - Protection Capabilities

Organization Answering Questionnaire
System Name or Service for which this applies
State of Oklahoma Security Policy
https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdfEnter a Value in the corresponding Maturity Rating Box
Protection CapabilitiesStatusMaturity RatingExplanation / Comments
#Question(Y/N)NonexistentInitial / Ad HocRepeatable but intuitiveDefinedManaged & MeasureableOptimized
PC-1Does your organization encrypt Data-at-Rest? If yes, please describe the encryption utilized.
PC-2Does your organization encrypt Data-in-Transit? If yes, please describe the encryption utilized.
PC-3Does your organization maintain data disposal/sanitation policies and procedures that define media sanitization requirements and techniques?
PC-4In addition to policies and procedures, do you have contracts with service providers to sanitize items or media with sensitive/confidential information prior to reuse or disposal?
PC-5In addition to policies and procedures, do you or a service provider retain an audit trail/chain of custody process and proof of media destruction/disposal?
PC-6Does your organization employ anti-malware solutions (e.g., anti-virus, anti-spyware, advanced endpoint security) on workstations, servers, and mobile devices?
PC-7Are updates for anti-malware solutions regularly installed on all devices where anti-malware is employed?
PC-8Are vulnerability scans performed on a regular basis?
PC-9Are operating systems, software/applications, and other application software or firmware updated on a regular basis either manually or through an automated patch management process?
PC-10How often are patches/updates installed?
PC-11Is penetration testing conducted regularly on your network and critical systems?
PC-12Does your organization rely on operating systems, software, or hardware that is no longer supported or is considered "end-of-life"(EOL) by the manufacturer? If yes, please summarize EOL cases in the commetns section
PC-13For the following line items, please answer if your organization utilizes these Information Technology (IT) and Information/Cybersecurity tools and capabilities:
PC-13.1Network Intrusion Detection/Prevention Systems (NIDS/NIPS)
PC-13.2Unified Threat Management (UTM) / Threat Prevention/Protection Systems (TPS)
PC-13.3Network Data Loss Prevention (DLP) solution
PC-13.4Protective Domain Name Service (PDNS)
PC-13.5Security Information and Event Management (SIEM)
PC-13.6Email DLP solution
PC-13.7Enforce Sender Policy Framework (SPF)
PC-13.8DomainKeys Identified Mail (DKIM)
PC-13.9Domain-based Message Authentication, Reporting and Conformance (DMARC)
PC-13.10Block malicious and phishing URLs
PC-13.11Host Intrusion Detection/Prevention System (HIDS/HIPS)
PC-13.12Multi-Factor Authentication to on-site/cloud backups
PC-13.13File Integrity Tools (Whitelisting)
PC-13.14Endpoint detection and Response (EDR) solutions
PC-13.15Advanced Endpoint Security
PC-13.16Endpoint DLP solution
PC-13.17Identity and Access Management solutions
PC-13.18Network Detection and Response (NDR) solutions
PC-13.19Bring Your Own Device (BYOD) security solutions
PC-13.20Password management software
PC-13.21Wireless Network Security solutions
PC-13.22DDOS mitigation solutions
PC-13.23Please describe in the comments section any other tools or capabilities that support the organizations cyber/information security.

11 - Training

Organization Answering Questionnaire
System Name or Service for which this applies
State of Oklahoma Security Policy
https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdfEnter a Value in the corresponding Maturity Rating Box
TrainingStatusMaturity RatingExplanation / Comments
#Question(Y/N)NonexistentInitial / Ad HocRepeatable but intuitiveDefinedManaged & MeasureableOptimized
T-1Does your organization have an established cybersecurity/information security awareness training program? (If no, please clarify below)
T-2Is the training mandatory for all employees, contractors, temporary hires and/or interns upon hire and at least annually?
T-3Do you perform regular analysis to identify gaps in the training, and update the training as needed?
T-4Does this training cover how to avoid common cyber risks and threats, such as social engineering?

12 - Incident Response

Organization Answering Questionnaire
System Name or Service for which this applies
State of Oklahoma Security Policy
https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdfEnter a Value in the corresponding Maturity Rating Box
Incident ResponseStatusMaturity RatingExplanation / Comments
#Question(Y/N)NonexistentInitial / Ad HocRepeatable but intuitiveDefinedManaged & MeasureableOptimized
IR-1Does your organization have a formally documented Incident Response Plan?
IR-2Are tabletop exercises performed at least annually to ensure the Incident response Plan is still accurate and employees are familiar with their roles and responsibilities?
IR-3Is there a review of your Incident Response Plan regularly to ensure it is up-to-date with current threats, along with local, state and federal laws?

13 - Recovery

Organization Answering Questionnaire
System Name or Service for which this applies
State of Oklahoma Security Policy
https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdfEnter a Value in the corresponding Maturity Rating Box
RecoveryStatusMaturity RatingExplanation / Comments
#Question(Y/N)NonexistentInitial / Ad HocRepeatable but intuitiveDefinedManaged & MeasureableOptimized
R-1Does your organization perform back-ups on critical information a regular basis?
R-2Does your organization test restoration capabilities by performing a full restoration from a sample set of backup data at least annually?
R-3Are recovery plans reviewed and revised at least annually?

14 - Business Continuity

Organization Answering Questionnaire
System Name or Service for which this applies
State of Oklahoma Security Policy
https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdfEnter a Value in the corresponding Maturity Rating Box
Business ContinuityStatusMaturity RatingExplanation / Comments
#Question(Y/N)NonexistentInitial / Ad HocRepeatable but intuitiveDefinedManaged & MeasureableOptimized
BC-1Does your organization maintain a business continuity/disaster recovery plan?
BC-2Is your Business Continuity and/or Disaster Recovery Plan tested/reviewed at least annually? If not, please describe how often in the comments section.
BC-3Does your organization have the capability to immediately failover to redundant or standby information systems?
BC-4Does your organization maintain an alternate backup IT facility such as a cold/warm/hot site?

15 - Vendor Management

Organization Answering Questionnaire
System Name or Service for which this applies
State of Oklahoma Security Policy
https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdfEnter a Value in the corresponding Maturity Rating Box
Vendor ManagementStatusMaturity RatingExplanation / Comments
#Question(Y/N)NonexistentInitial / Ad HocRepeatable but intuitiveDefinedManaged & MeasureableOptimized
VM-1Does your organization employ a Third-Party Risk Management program to vet all third-party vendors?
VM-2Does your organization audit vendors with access to your organization's computer systems and confidential data to ensure they are compliant with required security standards?
VM-3Does your organization utilize cloud computing? (i.e. Public, Hybrid, or Private Cloud)
VM-4Does your organization require confirmation from cloud vendors that they are in compliant with any applicable laws related to data storage and data transfer?

16 - Event History

Organization Answering Questionnaire
System Name or Service for which this applies
State of Oklahoma Security Policy
https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdfEnter a Value in the corresponding Maturity Rating Box
Event HistoryStatusMaturity RatingExplanation / Comments
#Question(Y/N)NonexistentInitial / Ad HocRepeatable but intuitiveDefinedManaged & MeasureableOptimized
EH-1Has your organization sustained any network security incidents or data incidents that resulted in a material financial loss in the last 5 years?
EH-2In the last 5 years, has your organization been required to notify any individuals or entities because of a breach of information security?
EH-3In the last 5 years, has your organization received any demands or claims relating to allegations of theft of information or breach of information security?
EH-4In the last 5 years, has your organization beene the subject of any government action, regulatory investigation or subpoena regarding any alleged violation of any privacy/data security law or regulation?
EH-5In the last 5 years, has your organization experienced a network outage, or substantial loss of IT functionality for more than 6 hours?
EH-6Within the last 5 years, has your organization sustained any network security incidents, or outages as the result of actions of a 3rd party vendor (e.g. cloud vendors, IT consultants, payroll, data processing)?

17 - HIPAA

Organization Answering Questionnaire
System Name or Service for which this applies
State of Oklahoma Security Policy
https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdfEnter a Value in the corresponding Maturity Rating Box
HIPAAStatusMaturity RatingExplanation / Comments
#Question(Y/N)NonexistentInitial / Ad HocRepeatable but intuitiveDefinedManaged & MeasureableOptimized
H-1Is your organization considered a covered entity under the Health Portability and Accountability Act (HIPAA) and/or the Health Information Technology for Economic and Clinical Health Act (HITECH)?
H-2Is your organization considered a Business Associate under the HIPAA/HITECH Acts?
H-3Is your organization HIPAA compliant and conducts yearly compliance reviews?
H-4Are all Business Associate agreements are reviewed to ensure they are HIPAA compliant?

18 - Biometrics

Organization Answering Questionnaire
System Name or Service for which this applies
State of Oklahoma Security Policy
https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdfEnter a Value in the corresponding Maturity Rating Box
BiometricsStatusMaturity RatingExplanation / Comments
#Question(Y/N)NonexistentInitial / Ad HocRepeatable but intuitiveDefinedManaged & MeasureableOptimized
B-1Does your organization use or provide technology that scans biometric identifiers (e.g. fingerprints, voice, hands, faces, eyes, signature, etc.)?Yes
B-2Does your organization manage and disclose use of biometric information?
B-3Does your organization follow data retention and destruction procedures for biometric information?
B-4Is equipment or technology provided by a third party used to collect, receive, or retain biometric data from internal employees or customers/clients?
B-5Does your organization follow storage and protection procedures for biometric information?

19 - PCI-DSS

Organization Answering Questionnaire
System Name or Service for which this applies
State of Oklahoma Security Policy
https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdfEnter a Value in the corresponding Maturity Rating Box
PCI-DSSStatusMaturity RatingExplanation / Comments
#Question(Y/N)NonexistentInitial / Ad HocRepeatable but intuitiveDefinedManaged & MeasureableOptimized
PCI-1Is your organization required to be compliant with Payment Card DSS Standards (PCI-DSS)?
PCI-2Is your organization currently compliant with PCI-DSS Validation Requirements as required by your merchant level (i.e. Level 1 - 4)?
PCI-3Does your organization utilize a payment processor that provides regular evidence of PCI-DSS compliance?
PCI-4Is all PCI data encrypted at-rest?
PCI-5Is malware protection implemented on POS terminals?
PCI-6Is Intrusion Detection Systems (IDS) and Data Loss Prevention (DLP) implemented within your POS network and any other PCI systems?
PCI-7Is IDS and DLP monitored 24 hours a day either internally or by a third-party service?
PCI-8Is all PCI data either encrypted or tokenized while in-transit?
PCI-9Does your organization utilize PCI Validated P2PE?
PCI-10Is your organization compliant with the Song Beverly Act and/or other similar laws/regulations?
PCI-11Is your organization compliant with the credit card display provisions of the Fair and Accurate Credit Transaction Act (FACTA)?

20 - Trending Topics

Organization Answering Questionnaire
System Name or Service for which this applies
State of Oklahoma Security Policy
https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdfEnter a Value in the corresponding Maturity Rating Box
Trending TopicsStatusMaturity RatingExplanation / Comments
#Question(Y/N)NonexistentInitial / Ad HocRepeatable but intuitiveDefinedManaged & MeasureableOptimized
TT-1Does your organization run a version of SolarWinds Orion that is vulnerable to the SUNBURST or SUPERNOVA backdoors?
TT-2Does your organization run a version of Microsoft Exchange Server 2010 through to 2019 that are vulnerable to the zero-day exploits being targeted?
TT-3Does your organization currently use Pulse Connect Secure VPN products?
TT-4Does your organization currently utilize Accellion FTA products?
TT-5Has your organization identified vulnerable versions of Log4j in your enterprise systems, including but not limited to: applications, on-premise software components, cloud software components, in-house software development, and third-party technology providers?
TT-6Did your organization conduct an investigation to ensure, and/or remediate any potential Log4j vulnerabilities/malicious activity caused by Log4j?
TT-7Has your organization developed any software affected by the Log4j vulnerability?

21 - Systems

Organization Answering Questionnaire
System Name or Service for which this applies
State of Oklahoma Security Policy
https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdfEnter a Value in the corresponding Maturity Rating Box
SystemsStatusMaturity RatingExplanation / Comments
#Question(Y/N)NonexistentInitial / Ad HocRepeatable but intuitiveDefinedManaged & MeasureableOptimized
S-1Does your organization currently have a Cyber Insurance Provider?
S-2Does your organization utilize a third-party service/application for data security (i.e. Druva, Token Ex, Bid ID, Digital Guardian, etc.)?
S-3Does your organization utilize a third-party service/application for endpoint security (i.e. Absolute Software, VMware Carbon Black, FireEye, Crowdstrike, etc.)?
S-4Does your organization utilize a third-party service/application for Network & Information Security (i.e. IronNet Cybersecurity, Trend Micro, Aruba, Gigamon, etc.)?
S-5Does your organization utilize a third-party service/application for Risk and Compliance (i.e. Security Scorecard, Xm Cyber, KnowBe4, Crowdstrike, etc.)?
S-6Does your organization have a third-party service/application for email/messaging security (i.e. Darktrace, FireEye, Mimecast, etc.)?
S-7Does your organization have a third-party service/application that handles Identity and Access Management (i.e. Aruba, CyberArk, RSA, etc.)?

Risk Matrix

Questions answered "No" without a reasonable justification, or other mitigation methods described, and answer pertains to organization = 1 Risk.Risk to State =
LOWLOWLOWMEDIUMMEDIUM
12345
LOWMEDIUMMEDIUMHIGHHIGH
246810
LOWMEDIUMHIGHHIGHEXTREME
3691215
MEDIUMHIGHHIGHHIGHEXTREME
48121620
MEDIUMHIGHEXTREMEEXTREMEEXTREME
510152025

Data Source

Yes0
No1
2
3
4
5

image1.png image2.png image3.png image4.png image5.png image6.png image7.png image8.png image9.png image10.png

File details come from the government source that posted it. Updated .