28.1 VITA Information security policies, standards and guidelines (Security PSGs) required in all IT solicitations and contracts

28.1.2 Application of VITA enterprise cloud oversight services (ECOS) policy and procedures to all SaaS solicitations and contracts

While agencies are required to comply with all Security PSGs as described in section 28.1.1, Security Standard SEC525-02 provides agency compliance requirements for non-CESC hosted cloud solutions.

In addition to Security Standard SEC525-02, for any procurements for third-party (supplier-hosted) cloud services (i.e., Software as a Service), agencies must use this process obtaining VITA approval to procure.  Refer to the Third Party Use Policy at this link: Third Party Use Policy.

Your agency's Information ISO or AITR can assist you in understanding this process and in obtaining the required documentation to include in your solicitation or contract. There are specially required Cloud Services terms and conditions that must be included in your solicitation and contract, and a questionnaire that must be included in the solicitation for bidders to complete and submit with their proposals. You may also contact: enterpriseservices@vita.virginia.gov

More guidelines for application of ECOS is available here: Cloud and Oversight Services

Supply Chain Management Division (SCM) and other VITA divisions participate in various oversight and governance capacities to assist CSRM in fulfilling VITA's statutory security obligations.