VendorSecurityAssessment.xlsx
XLSX spreadsheet 990 KB Posted
- Attached to
- Integrated Data Dashboard State and local contract opportunity
- Solicitation number
- EV00000677
- Issued by
- Oklahoma
About this file
The document is a Vendor Security Assessment spreadsheet created by the State of Oklahoma's Office of Management and Enterprise Services (OMES) IS Cybercommand, designed to assess and manage cybersecurity risks from potential IT service and product vendors. The purpose of the assessment is to comprehensively evaluate a vendor's internal security posture, ensuring their environment and security protocols meet the state's minimum security requirements before issuing an Authority to Operate (AOO). The assessment covers 21 distinct security domains, including demographics, service-specific details, governance, device management, software management, secure configuration, log monitoring, identity and access management, account management, protection capabilities, training, incident response, recovery, business continuity, vendor management, event history, and specialized areas like HIPAA compliance, biometrics, and payment card industry standards.
The assessment is structured as a maturity rating questionnaire, with vendors required to self-assess their cybersecurity capabilities across multiple dimensions, ranging from "Nonexistent" to "Optimized" levels. Each section includes detailed questions about the organization's security practices, tools, policies, and historical performance, with specific focus on areas such as encryption, data protection, incident response, backup procedures, third-party risk management, and compliance with various regulatory standards. The document includes a risk matrix that allows the state to evaluate potential security risks based on the vendor's responses, with risk levels ranging from LOW to EXTREME, helping OMES make informed decisions about vendor security and potential vulnerabilities in their information technology ecosystem.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment_B_-_State_Full_Terms_.pdf | ||
| OMESFormCP004.pdf | ||
| Attachment_A_-_Agency-purpose.pdf | ||
| Attachment_D_-_IT_Terms.pdf | ||
| Exhibit_01_-_Proposal_Requirements.pdf | ||
| Exhibit_02_-_Technical_Requirements.pdf | ||
| Exhibit_04_-ThirdPartySupplierInfo_.xlsx | XLSX spreadsheet | |
| EV00000677_Agency_Non-negotiable_Bid_instructions.pdf | ||
| Exhibit_03_-_Project_Timeline.pdf | ||
| Exhibit_05_-_Cost_Proposal_.xlsx | XLSX spreadsheet | |
| Fillable_OMESFormCP076.pdf | ||
| Attachment_G_-_Federal_Funding_Terms.pdf |
Show all 12
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Instruction
| Assessment Name | Security Assessment |
| Organization Name | State of Oklahome - OMES IS Cybercommand |
| Purpose | The purpose of the assessment is for the State of Oklahoma to Identify and manage any risk stemming from our business partnerships. All suppliers offering IT related services and/or products are required to complete this assessment prior to issuance of an Authority to Operate (AOO). This assessment is designed to allow us to gain a better understanding of our supplier’s internal security posture, along with the product, service, and/or solution being offered. Our tools, platforms, and procedures should have no bearing on the enterprise security controls of the suppliers. The State wants to ensure the vendor's overall environment and security protocols will meet the State's minimum-security requirements. |
| Maturity level |
1 - Demographics
| Organization Answering Questionnaire | |
| System Name or Service for which this applies | |
| State of Oklahoma Security Policy | |
| https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf |
| Demographics | ||
| # | Question | Answer |
| D-1 | Company's Legal Name | |
| D-2 | Primary Website URL | |
| D-3 | Primary Contact Name | |
| D-4 | Primary Contact Email | |
| D-5 | Primary Contact Phone | |
| D-6 | Alternate Contact Name | |
| D-7 | Alternate Contact Email | |
| D-8 | Alternate Contact Phone | |
| D-9 | Please describe the product or service your organization will be providing the State of Oklahoma. | |
| D-10 | Please describe the type of service or product being provided the State of Oklahoma. (i.e. SaaS, PaaS, IaaS, Hardware, Staffing, etc.) |
2 - Service Specific
| Organization Answering Questionnaire | ||
| System Name or Service for which this applies | ||
| State of Oklahoma Security Policy | ||
| https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf | Enter a Value in the corresponding Maturity Rating Box |
| Service Specific | Status | Maturity Rating | Explanation / Comments | ||||||
| # | Question | (Y/N) | Nonexistent | Initial / Ad Hoc | Repeatable but intuitive | Defined | Managed & Measureable | Optimized | |
| SS-1 | This section is strictly regarding the service or product being provided to the State of Oklahoma. All other sections in this assessment will be in regards to your organziations internal security posture, processes, and procedures. | ||||||||
| SS-2 | Does the system store, host, transmit or process any sensitive data? | ||||||||
| SS-3 | Sensitive defined as any data that may contain information protected by state statutes or federal regulations. | ||||||||
| SS-4 | Sensitive defined as not protected, however contains information that must be secured for the continuity or security of state government or individuals. That if such data were disclosed likely harm would occur to the state, the security posture of the state or individuals. | ||||||||
| SS-5 | Does your organization have resources outside the U.S that will host, store, transmit, process or access State of Oklahoma data? | ||||||||
| SS-6 | Will your organization host, store, transmit, process, or access and regulated sensitive or non-regulated sensitive data? (i.e. PHI/HIPAA, PII, CJI, FTI FERPA, etc.) | ||||||||
| SS-7 | Will a non-resident individual or corporation of the U.S. have physical or logical access to State of Oklahoma Data? | ||||||||
| SS-8 | Will any support contacts of the solution provider for hardware, software, or other technical support allow for the physical or logical access of a non US resident or corporation? | ||||||||
| SS-9 | Does the solution provider have a Help Desk function that allows for the support intake and handling of IT and /or security related services? | ||||||||
| SS-10 | Does the solution provider engage in E-Commerce activity on behalf of the State of Oklahoma? | ||||||||
| SS-11 | Does the solution provider outsource or subcontract any portion of the services that are being contracted on the behalf of the State of Oklahoma? |
3 - Governance
| Organization Answering Questionnaire | ||
| System Name or Service for which this applies | ||
| State of Oklahoma Security Policy | ||
| https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf | Enter a Value in the corresponding Maturity Rating Box |
| Governance | Status | Maturity Rating | Explanation / Comments | ||||||
| # | Question | (Y/N) | Nonexistent | Initial / Ad Hoc | Repeatable but intuitive | Defined | Managed & Measureable | Optimized | |
| G-1 | Does your organization have a Chief Information Security Officer (CISO), Chief Security Officer (CIO) or functional equivalent? | ||||||||
| G-2 | Does this individual periodically brief the CEO, Board of Directors, or equivalent on the security posture and maturity levels of the organization? | ||||||||
| G-3 | Are any of the following IT services outsourced by your organization to a third party vendor? (Please describe in the comments section to the right.) | ||||||||
| G-4 | Does your organization have a cyber / information security policy? | ||||||||
| G-5 | Does your organization have an Acceptable Use Policy (AUP) that defines the ranges of permitted use of company-provided technologies, and contains consequences for noncompliance/violations of the AUP? | ||||||||
| G-6 | Does your organization have an Insider Threat Program in order to deter, detect, and mitigate insider threats? | ||||||||
| G-7 | Does your organization follow a specific cybersecurity standard, framework, or set of best practices? If yes, please decribe in the comments section to the right. | ||||||||
| G-8 | Does your organization currently have documented enterprise or company-wide privacy policies in place? If no, please clarify in the comments seciton to the right. | ||||||||
| G-9 | Does your organization have a physical security program in place with risk-based protections (CCTV, visitor access controls, alarms, etc.) to secure offices and/or data centers? | ||||||||
| G-10 | Does your organization perform background checks on all new/temporary employees, and contractors? If yes, please describe what your bcakground check consists of in the comment section to the right. | ||||||||
| G-11 | Does your organization conduct security assessments and periodic re-assessments on third party partners/vendors and other service providers with access to information assets? | ||||||||
| G-12 | Does your organization engage with third party auditors to assess your information/cybersecurity program and associated controls? If so, please specify in the comments section to the right. |
4 - Device Management
| Organization Answering Questionnaire | ||
| System Name or Service for which this applies | ||
| State of Oklahoma Security Policy | ||
| https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf | Enter a Value in the corresponding Maturity Rating Box |
| Device Management | Status | Maturity Rating | Explanation / Comments | ||||||
| # | Question | (Y/N) | Nonexistent | Initial / Ad Hoc | Repeatable but intuitive | Defined | Managed & Measureable | Optimized | |
| DM-1 | Does your organization have an inventory management program for all hardware assets? | ||||||||
| DM-2 | Are inventories conducted on a regular basis? (i.e. Quarterly, Annually, etc.) | ||||||||
| DM-3 | Is the hardware inventory documented? | ||||||||
| DM-4 | Does your organization maintain an inventory of the percentage of third party or vendor managed assets residing outside of the organizations network and not under your organizations control that has access to or processes your information assets (Cloud, SaaS, etc.)? |
5 - Software Management
| Organization Answering Questionnaire | ||
| System Name or Service for which this applies | ||
| State of Oklahoma Security Policy | ||
| https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf | Enter a Value in the corresponding Maturity Rating Box |
| Software Management | Status | Maturity Rating | Explanation / Comments | ||||||
| # | Requirement | (Y/N) | Nonexistent | Initial / Ad Hoc | Repeatable but intuitive | Defined | Managed & Measureable | Optimized | |
| SM-1 | Does your organization maintain an inventory of all software in use? | ||||||||
| SM-2 | How often is this inventory updated? | ||||||||
| SM-3 | Does this inventory include operating systems and versions currently in use? | ||||||||
| SM-4 | Does your organization currently whitelist software, in conjunction with the software inventory to ensure only approved software is on organizational assets? |
6 - Secure Configuration
| Organization Answering Questionnaire | ||
| System Name or Service for which this applies | ||
| State of Oklahoma Security Policy | ||
| https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf | Enter a Value in the corresponding Maturity Rating Box |
| Secure Configuration | Status | Maturity Rating | Explanation / Comments | ||||||
| # | Question | (Y/N) | Nonexistent | Initial / Ad Hoc | Repeatable but intuitive | Defined | Managed & Measureable | Optimized | |
| SC-1 | Does your organization maintain standard secure configuration images for operating systems and software applications? | ||||||||
| SC-2 | Do these standard configurations incorporate industry recognized security hardening techniques? | ||||||||
| SC-3 | Does your organization employ a system configuration management tool (Active Directory Group Policy, etc.) that enforce and re-deploy configuration settings to systems? | ||||||||
| SC-4 | In your organization, are the software development, testing, and production environments separated? |
7 - Log Monitoring
| Organization Answering Questionnaire | ||
| System Name or Service for which this applies | ||
| State of Oklahoma Security Policy | ||
| https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf | Enter a Value in the corresponding Maturity Rating Box |
| Log Monitoring | Status | Maturity Rating | Explanation / Comments | ||||||
| # | Question | (Y/N) | Nonexistent | Initial / Ad Hoc | Repeatable but intuitive | Defined | Managed & Measureable | Optimized | |
| LM-1 | Has your organization implemented standard audit logging policies for hardware and software? | ||||||||
| LM-2 | Does this policy require a timestamp, source address, destination address, and other useful data sets? | ||||||||
| LM-3 | Are these logs kept in a standardized format, such as syslog or Common Event Expression? | ||||||||
| LM-4 | Do these logs include access and/or changes to sensitive data? | ||||||||
| LM-5 | How long are these audit logs kept? | ||||||||
| LM-6 | Are network boundary devices (firewalls, network-based Intrusion Prevention Systems/Intrusion Detection Systems, and/or inbound & outbound proxies) logging traffic both allowed and blocked? | ||||||||
| LM-7 | Does your organizaiton utilize a SIEM, Dedicated Security Personnel, or Third-Party service to analyze audit logs, reports, and alerts on a regular basis to identify unusual activity? | ||||||||
| LM-8 | Does your organization have security personnel/system administrators that review anomalies to identify unauthorized activity and resolve per an incident response plan? | ||||||||
| LM-9 | Does your organization have a SIEM(Security Information and Event Management) tool, or other similar logging tool for unified aggregation, consolidation, correlation, analysis, and alerting? | ||||||||
| LM-10 | Is this log tool updated regularly to minimize false positives and insignificant alerts? |
8 - IAM
| Organization Answering Questionnaire | ||
| System Name or Service for which this applies | ||
| State of Oklahoma Security Policy | ||
| https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf | Enter a Value in the corresponding Maturity Rating Box |
| Identity & Access Management | Status | Maturity Rating | Explanation / Comments | ||||||
| # | Question | (Y/N) | Nonexistent | Initial / Ad Hoc | Repeatable but intuitive | Defined | Managed & Measureable | Optimized | |
| IAM-1 | Does your organization utilize a service for directory services, identity providers (IdP), Federation and/or rights privileges management? (i.e. Microsoft Active Directory, Azure Active Directory, Okta, Ping, Active Directory Federation Services, Google Workspaces, etc.) | ||||||||
| IAM-2 | Does your organiation have controls in place to protect user accounts with administrator privileges? (Please describe in the comments section to the right) | ||||||||
| IAM-3 | Do you have controls in place for privileged service accounts? (i.e. Inventories on accounts conducted at least quarterly, password lengths of at least 25 characters, passwords rotated at least annually, etc.) |
9 - Account Management
| Organization Answering Questionnaire | ||
| System Name or Service for which this applies | ||
| State of Oklahoma Security Policy | ||
| https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf | Enter a Value in the corresponding Maturity Rating Box |
| Account Management | Status | Maturity Rating | Explanation / Comments | ||||||
| # | Question | (Y/N) | Nonexistent | Initial / Ad Hoc | Repeatable but intuitive | Defined | Managed & Measureable | Optimized | |
| AM-1 | Does your organization review user accounts regulary to confirm they are still valid? If yes, please describe how often these reviews are conducted in the comments section to the right. | ||||||||
| AM-2 | Do user accounts have an expiration date that is enforced, or is there a documented process to disable accounts immediately upon termination of employment? | ||||||||
| AM-3 | Are user accounts disabled after at least 60 days of inactivity? | ||||||||
| AM-4 | Does your organization have a formalized process to disable accounts upon termination of an employee, contractor/consultant, or third-party user? | ||||||||
| AM-5 | Does your system automatically engage a screensaver lockout after a set period of time to limit access to unattended computers? | ||||||||
| AM-6 | In your organization, are accounts automatically locked after a set number of failed login attempts? If yes, please describe how locked accounts are unlocked by end-users in the comments section to the right. | ||||||||
| AM-7 | Does your organization have controls in place that enforces minimum password requirements? | ||||||||
| AM-8 | Does your organization utilize MFA (Multi-Factor Authentication) for user, administrative, and/or privileged accounts? | ||||||||
| AM-9 | Does your organization require multi-factor authentication for remote login access to your corporate network? | ||||||||
| AM-10 | Does your organization utilize remote access protocols, such as Remote Desktop Protocol (RDP), VPN, SSH, SFTP or other similar protocols to securely access your internal corporate network remotely? If yes, please describe the protocol utilized. |
10 - Protection Capabilities
| Organization Answering Questionnaire | ||
| System Name or Service for which this applies | ||
| State of Oklahoma Security Policy | ||
| https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf | Enter a Value in the corresponding Maturity Rating Box |
| Protection Capabilities | Status | Maturity Rating | Explanation / Comments | ||||||
| # | Question | (Y/N) | Nonexistent | Initial / Ad Hoc | Repeatable but intuitive | Defined | Managed & Measureable | Optimized | |
| PC-1 | Does your organization encrypt Data-at-Rest? If yes, please describe the encryption utilized. | ||||||||
| PC-2 | Does your organization encrypt Data-in-Transit? If yes, please describe the encryption utilized. | ||||||||
| PC-3 | Does your organization maintain data disposal/sanitation policies and procedures that define media sanitization requirements and techniques? | ||||||||
| PC-4 | In addition to policies and procedures, do you have contracts with service providers to sanitize items or media with sensitive/confidential information prior to reuse or disposal? | ||||||||
| PC-5 | In addition to policies and procedures, do you or a service provider retain an audit trail/chain of custody process and proof of media destruction/disposal? | ||||||||
| PC-6 | Does your organization employ anti-malware solutions (e.g., anti-virus, anti-spyware, advanced endpoint security) on workstations, servers, and mobile devices? | ||||||||
| PC-7 | Are updates for anti-malware solutions regularly installed on all devices where anti-malware is employed? | ||||||||
| PC-8 | Are vulnerability scans performed on a regular basis? | ||||||||
| PC-9 | Are operating systems, software/applications, and other application software or firmware updated on a regular basis either manually or through an automated patch management process? | ||||||||
| PC-10 | How often are patches/updates installed? | ||||||||
| PC-11 | Is penetration testing conducted regularly on your network and critical systems? | ||||||||
| PC-12 | Does your organization rely on operating systems, software, or hardware that is no longer supported or is considered "end-of-life"(EOL) by the manufacturer? If yes, please summarize EOL cases in the commetns section | ||||||||
| PC-13 | For the following line items, please answer if your organization utilizes these Information Technology (IT) and Information/Cybersecurity tools and capabilities: | ||||||||
| PC-13.1 | Network Intrusion Detection/Prevention Systems (NIDS/NIPS) | ||||||||
| PC-13.2 | Unified Threat Management (UTM) / Threat Prevention/Protection Systems (TPS) | ||||||||
| PC-13.3 | Network Data Loss Prevention (DLP) solution | ||||||||
| PC-13.4 | Protective Domain Name Service (PDNS) | ||||||||
| PC-13.5 | Security Information and Event Management (SIEM) | ||||||||
| PC-13.6 | Email DLP solution | ||||||||
| PC-13.7 | Enforce Sender Policy Framework (SPF) | ||||||||
| PC-13.8 | DomainKeys Identified Mail (DKIM) | ||||||||
| PC-13.9 | Domain-based Message Authentication, Reporting and Conformance (DMARC) | ||||||||
| PC-13.10 | Block malicious and phishing URLs | ||||||||
| PC-13.11 | Host Intrusion Detection/Prevention System (HIDS/HIPS) | ||||||||
| PC-13.12 | Multi-Factor Authentication to on-site/cloud backups | ||||||||
| PC-13.13 | File Integrity Tools (Whitelisting) | ||||||||
| PC-13.14 | Endpoint detection and Response (EDR) solutions | ||||||||
| PC-13.15 | Advanced Endpoint Security | ||||||||
| PC-13.16 | Endpoint DLP solution | ||||||||
| PC-13.17 | Identity and Access Management solutions | ||||||||
| PC-13.18 | Network Detection and Response (NDR) solutions | ||||||||
| PC-13.19 | Bring Your Own Device (BYOD) security solutions | ||||||||
| PC-13.20 | Password management software | ||||||||
| PC-13.21 | Wireless Network Security solutions | ||||||||
| PC-13.22 | DDOS mitigation solutions | ||||||||
| PC-13.23 | Please describe in the comments section any other tools or capabilities that support the organizations cyber/information security. |
11 - Training
| Organization Answering Questionnaire | ||
| System Name or Service for which this applies | ||
| State of Oklahoma Security Policy | ||
| https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf | Enter a Value in the corresponding Maturity Rating Box |
| Training | Status | Maturity Rating | Explanation / Comments | ||||||
| # | Question | (Y/N) | Nonexistent | Initial / Ad Hoc | Repeatable but intuitive | Defined | Managed & Measureable | Optimized | |
| T-1 | Does your organization have an established cybersecurity/information security awareness training program? (If no, please clarify below) | ||||||||
| T-2 | Is the training mandatory for all employees, contractors, temporary hires and/or interns upon hire and at least annually? | ||||||||
| T-3 | Do you perform regular analysis to identify gaps in the training, and update the training as needed? | ||||||||
| T-4 | Does this training cover how to avoid common cyber risks and threats, such as social engineering? |
12 - Incident Response
| Organization Answering Questionnaire | ||
| System Name or Service for which this applies | ||
| State of Oklahoma Security Policy | ||
| https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf | Enter a Value in the corresponding Maturity Rating Box |
| Incident Response | Status | Maturity Rating | Explanation / Comments | ||||||
| # | Question | (Y/N) | Nonexistent | Initial / Ad Hoc | Repeatable but intuitive | Defined | Managed & Measureable | Optimized | |
| IR-1 | Does your organization have a formally documented Incident Response Plan? | ||||||||
| IR-2 | Are tabletop exercises performed at least annually to ensure the Incident response Plan is still accurate and employees are familiar with their roles and responsibilities? | ||||||||
| IR-3 | Is there a review of your Incident Response Plan regularly to ensure it is up-to-date with current threats, along with local, state and federal laws? |
13 - Recovery
| Organization Answering Questionnaire | ||
| System Name or Service for which this applies | ||
| State of Oklahoma Security Policy | ||
| https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf | Enter a Value in the corresponding Maturity Rating Box |
| Recovery | Status | Maturity Rating | Explanation / Comments | ||||||
| # | Question | (Y/N) | Nonexistent | Initial / Ad Hoc | Repeatable but intuitive | Defined | Managed & Measureable | Optimized | |
| R-1 | Does your organization perform back-ups on critical information a regular basis? | ||||||||
| R-2 | Does your organization test restoration capabilities by performing a full restoration from a sample set of backup data at least annually? | ||||||||
| R-3 | Are recovery plans reviewed and revised at least annually? |
14 - Business Continuity
| Organization Answering Questionnaire | ||
| System Name or Service for which this applies | ||
| State of Oklahoma Security Policy | ||
| https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf | Enter a Value in the corresponding Maturity Rating Box |
| Business Continuity | Status | Maturity Rating | Explanation / Comments | ||||||
| # | Question | (Y/N) | Nonexistent | Initial / Ad Hoc | Repeatable but intuitive | Defined | Managed & Measureable | Optimized | |
| BC-1 | Does your organization maintain a business continuity/disaster recovery plan? | ||||||||
| BC-2 | Is your Business Continuity and/or Disaster Recovery Plan tested/reviewed at least annually? If not, please describe how often in the comments section. | ||||||||
| BC-3 | Does your organization have the capability to immediately failover to redundant or standby information systems? | ||||||||
| BC-4 | Does your organization maintain an alternate backup IT facility such as a cold/warm/hot site? |
15 - Vendor Management
| Organization Answering Questionnaire | ||
| System Name or Service for which this applies | ||
| State of Oklahoma Security Policy | ||
| https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf | Enter a Value in the corresponding Maturity Rating Box |
| Vendor Management | Status | Maturity Rating | Explanation / Comments | ||||||
| # | Question | (Y/N) | Nonexistent | Initial / Ad Hoc | Repeatable but intuitive | Defined | Managed & Measureable | Optimized | |
| VM-1 | Does your organization employ a Third-Party Risk Management program to vet all third-party vendors? | ||||||||
| VM-2 | Does your organization audit vendors with access to your organization's computer systems and confidential data to ensure they are compliant with required security standards? | ||||||||
| VM-3 | Does your organization utilize cloud computing? (i.e. Public, Hybrid, or Private Cloud) | ||||||||
| VM-4 | Does your organization require confirmation from cloud vendors that they are in compliant with any applicable laws related to data storage and data transfer? |
16 - Event History
| Organization Answering Questionnaire | ||
| System Name or Service for which this applies | ||
| State of Oklahoma Security Policy | ||
| https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf | Enter a Value in the corresponding Maturity Rating Box |
| Event History | Status | Maturity Rating | Explanation / Comments | ||||||
| # | Question | (Y/N) | Nonexistent | Initial / Ad Hoc | Repeatable but intuitive | Defined | Managed & Measureable | Optimized | |
| EH-1 | Has your organization sustained any network security incidents or data incidents that resulted in a material financial loss in the last 5 years? | ||||||||
| EH-2 | In the last 5 years, has your organization been required to notify any individuals or entities because of a breach of information security? | ||||||||
| EH-3 | In the last 5 years, has your organization received any demands or claims relating to allegations of theft of information or breach of information security? | ||||||||
| EH-4 | In the last 5 years, has your organization beene the subject of any government action, regulatory investigation or subpoena regarding any alleged violation of any privacy/data security law or regulation? | ||||||||
| EH-5 | In the last 5 years, has your organization experienced a network outage, or substantial loss of IT functionality for more than 6 hours? | ||||||||
| EH-6 | Within the last 5 years, has your organization sustained any network security incidents, or outages as the result of actions of a 3rd party vendor (e.g. cloud vendors, IT consultants, payroll, data processing)? |
17 - HIPAA
| Organization Answering Questionnaire | ||
| System Name or Service for which this applies | ||
| State of Oklahoma Security Policy | ||
| https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf | Enter a Value in the corresponding Maturity Rating Box |
| HIPAA | Status | Maturity Rating | Explanation / Comments | ||||||
| # | Question | (Y/N) | Nonexistent | Initial / Ad Hoc | Repeatable but intuitive | Defined | Managed & Measureable | Optimized | |
| H-1 | Is your organization considered a covered entity under the Health Portability and Accountability Act (HIPAA) and/or the Health Information Technology for Economic and Clinical Health Act (HITECH)? | ||||||||
| H-2 | Is your organization considered a Business Associate under the HIPAA/HITECH Acts? | ||||||||
| H-3 | Is your organization HIPAA compliant and conducts yearly compliance reviews? | ||||||||
| H-4 | Are all Business Associate agreements are reviewed to ensure they are HIPAA compliant? |
18 - Biometrics
| Organization Answering Questionnaire | ||
| System Name or Service for which this applies | ||
| State of Oklahoma Security Policy | ||
| https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf | Enter a Value in the corresponding Maturity Rating Box |
| Biometrics | Status | Maturity Rating | Explanation / Comments | ||||||
| # | Question | (Y/N) | Nonexistent | Initial / Ad Hoc | Repeatable but intuitive | Defined | Managed & Measureable | Optimized | |
| B-1 | Does your organization use or provide technology that scans biometric identifiers (e.g. fingerprints, voice, hands, faces, eyes, signature, etc.)? | Yes | |||||||
| B-2 | Does your organization manage and disclose use of biometric information? | ||||||||
| B-3 | Does your organization follow data retention and destruction procedures for biometric information? | ||||||||
| B-4 | Is equipment or technology provided by a third party used to collect, receive, or retain biometric data from internal employees or customers/clients? | ||||||||
| B-5 | Does your organization follow storage and protection procedures for biometric information? |
19 - PCI-DSS
| Organization Answering Questionnaire | ||
| System Name or Service for which this applies | ||
| State of Oklahoma Security Policy | ||
| https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf | Enter a Value in the corresponding Maturity Rating Box |
| PCI-DSS | Status | Maturity Rating | Explanation / Comments | ||||||
| # | Question | (Y/N) | Nonexistent | Initial / Ad Hoc | Repeatable but intuitive | Defined | Managed & Measureable | Optimized | |
| PCI-1 | Is your organization required to be compliant with Payment Card DSS Standards (PCI-DSS)? | ||||||||
| PCI-2 | Is your organization currently compliant with PCI-DSS Validation Requirements as required by your merchant level (i.e. Level 1 - 4)? | ||||||||
| PCI-3 | Does your organization utilize a payment processor that provides regular evidence of PCI-DSS compliance? | ||||||||
| PCI-4 | Is all PCI data encrypted at-rest? | ||||||||
| PCI-5 | Is malware protection implemented on POS terminals? | ||||||||
| PCI-6 | Is Intrusion Detection Systems (IDS) and Data Loss Prevention (DLP) implemented within your POS network and any other PCI systems? | ||||||||
| PCI-7 | Is IDS and DLP monitored 24 hours a day either internally or by a third-party service? | ||||||||
| PCI-8 | Is all PCI data either encrypted or tokenized while in-transit? | ||||||||
| PCI-9 | Does your organization utilize PCI Validated P2PE? | ||||||||
| PCI-10 | Is your organization compliant with the Song Beverly Act and/or other similar laws/regulations? | ||||||||
| PCI-11 | Is your organization compliant with the credit card display provisions of the Fair and Accurate Credit Transaction Act (FACTA)? |
20 - Trending Topics
| Organization Answering Questionnaire | ||
| System Name or Service for which this applies | ||
| State of Oklahoma Security Policy | ||
| https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf | Enter a Value in the corresponding Maturity Rating Box |
| Trending Topics | Status | Maturity Rating | Explanation / Comments | ||||||
| # | Question | (Y/N) | Nonexistent | Initial / Ad Hoc | Repeatable but intuitive | Defined | Managed & Measureable | Optimized | |
| TT-1 | Does your organization run a version of SolarWinds Orion that is vulnerable to the SUNBURST or SUPERNOVA backdoors? | ||||||||
| TT-2 | Does your organization run a version of Microsoft Exchange Server 2010 through to 2019 that are vulnerable to the zero-day exploits being targeted? | ||||||||
| TT-3 | Does your organization currently use Pulse Connect Secure VPN products? | ||||||||
| TT-4 | Does your organization currently utilize Accellion FTA products? | ||||||||
| TT-5 | Has your organization identified vulnerable versions of Log4j in your enterprise systems, including but not limited to: applications, on-premise software components, cloud software components, in-house software development, and third-party technology providers? | ||||||||
| TT-6 | Did your organization conduct an investigation to ensure, and/or remediate any potential Log4j vulnerabilities/malicious activity caused by Log4j? | ||||||||
| TT-7 | Has your organization developed any software affected by the Log4j vulnerability? |
21 - Systems
| Organization Answering Questionnaire | ||
| System Name or Service for which this applies | ||
| State of Oklahoma Security Policy | ||
| https://oklahoma.gov/content/dam/ok/en/omes/documents/InfoSecPPG.pdf | Enter a Value in the corresponding Maturity Rating Box |
| Systems | Status | Maturity Rating | Explanation / Comments | ||||||
| # | Question | (Y/N) | Nonexistent | Initial / Ad Hoc | Repeatable but intuitive | Defined | Managed & Measureable | Optimized | |
| S-1 | Does your organization currently have a Cyber Insurance Provider? | ||||||||
| S-2 | Does your organization utilize a third-party service/application for data security (i.e. Druva, Token Ex, Bid ID, Digital Guardian, etc.)? | ||||||||
| S-3 | Does your organization utilize a third-party service/application for endpoint security (i.e. Absolute Software, VMware Carbon Black, FireEye, Crowdstrike, etc.)? | ||||||||
| S-4 | Does your organization utilize a third-party service/application for Network & Information Security (i.e. IronNet Cybersecurity, Trend Micro, Aruba, Gigamon, etc.)? | ||||||||
| S-5 | Does your organization utilize a third-party service/application for Risk and Compliance (i.e. Security Scorecard, Xm Cyber, KnowBe4, Crowdstrike, etc.)? | ||||||||
| S-6 | Does your organization have a third-party service/application for email/messaging security (i.e. Darktrace, FireEye, Mimecast, etc.)? | ||||||||
| S-7 | Does your organization have a third-party service/application that handles Identity and Access Management (i.e. Aruba, CyberArk, RSA, etc.)? |
Risk Matrix
| Questions answered "No" without a reasonable justification, or other mitigation methods described, and answer pertains to organization = 1 Risk. | Risk to State = | ||||
| LOW | LOW | LOW | MEDIUM | MEDIUM | |
| 1 | 2 | 3 | 4 | 5 | |
| LOW | MEDIUM | MEDIUM | HIGH | HIGH | |
| 2 | 4 | 6 | 8 | 10 | |
| LOW | MEDIUM | HIGH | HIGH | EXTREME | |
| 3 | 6 | 9 | 12 | 15 | |
| MEDIUM | HIGH | HIGH | HIGH | EXTREME | |
| 4 | 8 | 12 | 16 | 20 | |
| MEDIUM | HIGH | EXTREME | EXTREME | EXTREME | |
| 5 | 10 | 15 | 20 | 25 |
Data Source
| Yes | 0 |
| No | 1 |
| 2 | |
| 3 | |
| 4 | |
| 5 |
image1.png image2.png image3.png image4.png image5.png image6.png image7.png image8.png image9.png image10.png
File details come from the government source that posted it. Updated .