While agencies are required to comply with all Security PSGs as described in section 28.1.1, Security Standard SEC525provides agency compliance requirements for non-CESC hosted cloud solutions.
In addition to Security Standard SEC525, for any procurements for third-party (supplier- hosted) cloud services (i.e., Software as a Service), agencies must use this process obtaining VITA approval to procure. Refer to the Third Party Use Policy at this link: https://www.vita.virginia.gov/media/vitavirginiagov/it-governance/psgs/pdf/ThirdPartyUsePolicy.pdf.
Your agency’s ISO or AITR can assist you in understanding this process and in obtaining the required documentation to include in your solicitation or contract. There are specially required Cloud Services terms and conditions that must be included in your solicitation and contract, and a questionnaire that must be included in the solicitation for bidders to complete and submit with their proposals. You may also contact: firstname.lastname@example.org
More guidelines for application of ECOS is available here:
Commonwealth Security and Cloud Requirements for Solicitations and Contracts: https://www.vita.virginia.gov/media/vitavirginiagov/supply-chain/pdf/Commonwealth-Security-and-Cloud-Requriements-2018-07-01.pdf
ECOS Procedure Checklist for Cloud Solution Solicitations and Contracts: https://www.vita.virginia.gov/media/vitavirginiagov/supply-chain/docs/ECOSProcedureChecklistforCloudSolutionSolicitationsandContracts20200724-(8).docx