25.7 VITA contractual requirements
25.7.4 VITA security and cloud contractual requirements
Section 2.2-2009 of the Code of Virginia mandates that the Chief Information Officer (CIO) is responsible for the development of policies, standards, and guidelines for assessing security risks, determining the appropriate security measures and performing security audits of government electronic information. Such policies, standards, and guidelines shall apply to the Commonwealth's executive, legislative, and judicial branches and independent agencies.
While agencies are required to comply with all security policies, standards and guidelines (PSGs), Security Standard SEC530 provides agency compliance requirements for non- CESC hosted cloud solutions. These PSGs are located at this URL: https://www.vita.virginia.gov/it-governance/itrm-policies-standards/
In addition to Security Standard SEC530, for any procurements for third-party (supplier- hosted) cloud services (i.e., Software as a Service), since agencies have $0 delegated authority to procure these types of solutions, there is a distinct process for obtaining VITA approval to procure. At the link above, refer to the Third Party Use Policy. Your agency’s Information Security Officer or AITR can assist you in understanding this process and in obtaining the required documentation to include in your solicitation or contract. There are specially required Cloud Services terms and conditions that must be included in your solicitation and contract, and a questionnaire that must be included in the solicitation for bidders to complete and submit with their proposals. You may also contact: enterpriseservices@vita.virginia.gov
Search the manual by key words or common terms.