Town CrierWest Orange, New Jersey
← Back to search

Supporting Documentation · Jan 6, 2015

11-15 Exhibits to Resolution Awarding Contract for 911 System Maintenance and Repair.pdf

Preserved file SHA-256c64ab1e2bb206146c4660bc566c5f1e4fca8ca686497d1305ceee0ffc4e0b340

Indexed text · page 58

Show all pages
Page 58

In addition, the security plan shall identify and define: • Regulations and security requirements – how the contractor will address security requirements such as PCI, HIPAA, FISMA and etc. • System, Administrative and Personnel Security - the security responsibilities of and supervision required for information owned and / or operated by the contractor. Security responsibilities include responsibilities for administration of the infrastructure, implementing or maintaining security and the protection of the confidentiality, integrity, and availability of information systems or processes. • Workforce Security - the control process for hiring and terminating of contractor’s employees, and method used for granting and denying access to the contractor’s network, systems and applications. Identify and define audit controls when employment of the employee terminates. • Role based security access – the products and methods for role based security and access to the contractor’s infrastructure and access to the State’s infrastructure. • Password Management – the appropriate password management controls to meet defined regulation or security requirements. • Logging / Auditing controls – the contractor’s audit control methods and requirements. • Incident Management – the methods for detecting, reporting and responding to an incident, vulnerabilities and threats. • Vulnerability / Security Assessment – the products and methods used for scanning contractor’s infrastructure for vulnerabilities and remediation of the vulnerabilities. Identify and define methods used for initiating and completing security assessments. • Anti-virus / malware controls – the products and methods for anti-virus and malware controls that meet industry standards. It shall include policy statements that require periodic anti-viral software checks of the system to preclude infections and set forth its commitment to periodically upgrade its capability to maintain maximum effectiveness

Page 58

odic anti-viral software checks of the system to preclude infections and set forth its commitment to periodically upgrade its capability to maintain maximum effectiveness against new strains of software viruses. • Firewall – the products and methods for firewall control process and intrusion detection methodology. • Database – the products and methods for safeguarding the database(s). • Server and infrastructure – the products and methods for "hardening" of the hardware’ operating systems. • Transmission - the products and methods on how its system addresses security measures regarding communication transmission, access and message validation. • Data Integrity – the products and methods on the integrity of all stored data and the electronic images, and the security of all files from unauthorized access. The contractor must be able to provide reports on an as-needed basis on the access or change for any file within the system. 5.10 NEWS RELEASES The contractor is not permitted to issue news releases pertaining to any aspect of the services being provided under this contract without the prior written consent of the Director. 5.11 ADVERTISING The contractor shall not use the State’s name, logos, images, or any data or results arising from this contract as a part of any commercial advertising without first obtaining the prior written consent of the Director. 52

File revisions (1)