Town CrierWest Orange, New Jersey
← Back to search

Supporting Documentation · Jan 6, 2015

11-15 Exhibits to Resolution Awarding Contract for 911 System Maintenance and Repair.pdf

Preserved file SHA-256c64ab1e2bb206146c4660bc566c5f1e4fca8ca686497d1305ceee0ffc4e0b340

Indexed text · page 56

Show all pages
Page 56

• If the contractor is not supplying “dedicated” hardware resources to host State of New Jersey applications and data, the contractor must demonstrate its strategy to maintain application and/or stack isolation using commercially available security devices to maintain security zones, routing isolation and access control to infrastructure devices and access/security logging (AAA) within its infrastructure. • The contractor must supply “cleansed” but detailed network infrastructure diagrams of the application hosting environment for review by NJ OIT Network Infrastructure and Enterprise Security Office. 2. Application Security: The contractor at a minimum shall run application vulnerability assessment scans during development and system testing. Vulnerabilities shall be remediated prior to production release. 1. All systems and applications shall be subject to Vulnerability Assessment scans on a regular basis. 3. Data Security: The contractor at a minimum shall protect and maintain the security of data in accordance with generally accepted industry practices and to the standards and practices required by NJOIT. • Any Personally Identifiable Information must be protected. All data must be classified in accordance with the State’s Asset Classification and Control policy, 08-04-NJOIT (www.nj.gov/it/ps). Additionally, data must be disposed of in accordance with the State’s Information Disposal and Media Sanitation policy, 09-10-NJOIT (www.nj.gov/it/ps). • Data usage, storage, and protection is subject to any applicable regulatory requirements, including those for HIPAA (Health Insurance Portability and Accountability Act), and PII (Personally Identifiable Information), Tax Information Security Guidelines for Federal, State, and Local Agencies (IRS Publication 1075) and the New Jersey State tax confidentiality statute, as amended, N.J.S.A. 54:50-8, Payment Card Industry (PCI) Data Security Standard, State of New Jersey Identity Theft Prevention Act, June 2005, State of New Jersey Drivers’ Privacy Protection Act of 1994, Pub.L.103-322 4. Data Transmission: The contractor shall only transmit or exchange State of New Jersey data with other parties when expressly requested in writing and permitted

Page 56

Act of 1994, Pub.L.103-322 4. Data Transmission: The contractor shall only transmit or exchange State of New Jersey data with other parties when expressly requested in writing and permitted by and in accordance with requirements of the State of New Jersey. The contractor shall only transmit or exchange data with the State of New Jersey or other parties through secure means supported by current technologies. The contractor shall encrypt all data defined as personally identifiable or confidential by the State of New Jersey or applicable law, regulation or standard during any transmission or exchange of that data. 5. Data Storage: All data provided by the State of New Jersey or gathered by the contractor on behalf of the State of New Jersey must be stored, processed, and maintained solely in accordance with a project plan and system topology approved by the State Contract Manager. No State data shall be processed on or transferred to any device or storage medium including portable media, smart devices and/or USB devices, unless that device or storage medium has been approved in advance in writing by the State Project Manager. 50

File revisions (1)