Supporting Documentation · Jan 6, 2015
11-15 Exhibits to Resolution Awarding Contract for 911 System Maintenance and Repair.pdf
c64ab1e2bb206146c4660bc566c5f1e4fca8ca686497d1305ceee0ffc4e0b340Indexed text · page 55
Show all pagesstatistical, personnel, customer and/or technical data supplied by the State that is deemed confidential. Any use, sale, or offering of this data in any form by the contractor, or any individual or entity in the contractor’s charge or employ, will be considered a violation of this contract and may result in contract termination and the contractor’s suspension or debarment from State contracting. In addition, such conduct may be reported to the State Attorney General for possible criminal prosecution. The contractor shall assume total financial liability incurred by the contractor associated with any breach of confidentiality. The contractor and all project staff including its subcontractor(s) must complete and sign confidentiality and non-disclosure agreements provided by the State and require all staff to view yearly security awareness and confidentiality training modules provided by the contractor. It shall be the contractor’s responsibility to ensure that any new staff sign the confidentiality agreement and complete the security awareness and confidentiality training modules within one month of the employees’ start date. Security clearance/background check for all contractors and project staff must be obtained and provided to the State (to protect the State of New Jersey from losses resulting from contractor employee theft, fraud or dishonesty) upon request. Refer to the National Institute of Standards and Technology (NIST) Special Publication (SP) 300-12, An Introduction to Computer Security: The NIST Handbook, Section 10.1.3, Filling the Position – Screening and Selecting. 5.9.2 SECURITY STANDARDS 1. Network Security: The contractor shall maintain the contractor’s network security that – at a minimum – includes: network firewall provisioning, intrusion detection and prevention, vulnerability assessments and regular independent third party penetration testing. The contractor shall maintain network security that conforms to one of the following: A. Those standards that the State of New Jersey applies to its own network, as found in the State of New Jersey Shared IT Architecture document: http://www.state.nj.us/it/ps/it_architecture.pdf. B. Current standards set forth and maintained by the National Institute of Standards and Technology (NIST), including:
http://www.state.nj.us/it/ps/it_architecture.pdf. B. Current standards set forth and maintained by the National Institute of Standards and Technology (NIST), including: http://csrc.nist.gov/publications/PubsSPs.html http://csrc.nist.gov/publications/nistpubs/800-113/SP800-113.pdf http://csrc.nist.gov/publications/nistpubs/800-66-Rev1/SP-800-66-Revision1.pdf http://csrc.nist.gov/publications/drafts/800-125/Draft-SP800-125.pdf http://csrc.nist.gov/publications/nistpubs/800-122/sp800-122.pdf https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml. C. Any generally recognized comparable standard that the contractor then applies to its own network that is approved by the NJ Statewide Office of Information Security. • The contractor shall be subject to the same security and infrastructure review processes that are required by NJOIT and its partner Departments and Agencies. The contractor shall submit relevant documentation and participate in the System Architecture Review (SAR) process. • For “outsourced hosting services”, the contractor must demonstrate the ability to not only secure the physical application infrastructure utilizing the above mentioned security requirements, but also control and secure physical access to the application hosting facilities, the racks supporting network infrastructure and processing server equipment, web, application and database servers. 49
File revisions (1)
- Sep 29, 2026
c64ab1e2bb201,211,121 bytes