The Vendor is required to provide comprehensive security risk assessment services include:
• Security Assessment: conduct a comprehensive assessment of the county’s it infrastructure, systems, and applications to identify security vulnerabilities and weaknesses.
• Vulnerability assessment: perform a thorough vulnerability scanning of all systems, networks, and applications to identify and prioritize vulnerabilities.
• penetration testing: conduct simulated attacks to identify exploitable vulnerabilities and assess the effectiveness of security controls and to measure the feasibility of systems compromise beyond identifying and documenting discrete vulnerabilities; this includes external, internal, wireless, remote access, application and web.
• Cloud security assessment: evaluate the security posture of cloud environments (AWS and azure) used by the county.
• Application assessments: review the security of critical applications, including web applications, database systems, and custom applications.
• Information security program review: evaluate the effectiveness of the county’s information security program, including its adherence to industry standards and regulatory requirements such as HIPAA, PCI DSS, CJIS, and other applicable regulations.
• Security architecture analysis: review the county’s security architecture and identify potential design flaws and weaknesses.
• Data loss prevention (DLP) services: assess the county’s DLP capabilities and recommend improvements to protect sensitive data.
• Inventory of data assets and impact analysis: identify and classify sensitive data assets and assess the potential impact of a data breach.
• Ransomware defense and incident readiness analysis: assess the county’s ransomware defense capabilities, incident response plans, and business continuity plans.
• Security policy review and modernization: assess the county's enterprise and agency security policies for modernization and compliance with state and regulatory requirements such as NIST 2.0, HIPPA, PCI and CJIS.
- Contract Period/Term: 3 years