Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
Build your evaluation
no account needed
Match on your requirements
no account needed
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
1. Weight what matters
100 criteria
baselineWhich compliance frameworks and control catalogs (SOC 2, ISO 27001, NIST CSF/800-53, PCI DSS, HIPAA, GDPR) ship with pre-built control mappings, and how are cross-framework control overlaps deduplicated so one piece of evidence satisfies multiple frameworks?
baselineDescribe how evidence collection is automated (API integrations to cloud/IT systems versus manual upload) for a defined control set, and quantify the reduction in manual evidence-gathering hours with a customer reference.
baselineHow does the platform handle continuous control monitoring versus point-in-time audit snapshots — can a control show as 'failing' between audits, and how is that surfaced to control owners?
baselineWhat risk register and risk-scoring methodology is used (qualitative, quantitative, FAIR-based), and can custom risk models or scoring weights be configured, or is it a fixed vendor methodology?
baselineDetail the vendor/third-party risk management capability — questionnaire automation, evidence review workflow, and continuous vendor risk monitoring — and how it integrates with the core control framework.
baselineHow are policy documents versioned, attested to by employees, and linked to specific controls, and what happens to attestation records when a policy is updated mid-cycle?
baselineProvide detail on audit-readiness workflows: can an auditor be given direct, scoped, read-only access to evidence and control status, and what is the typical time reduction for SOC 2 Type II audit prep with a named reference?
baselineWhat is the integration depth with ticketing/remediation workflows (Jira, ServiceNow) for control failures and audit findings — bidirectional sync or one-way export?
baselineExplain multi-entity/multi-framework support for organizations managing several subsidiaries or business units with different compliance obligations — is this native multi-tenancy or a workaround using tags/labels?
baselineBriefly describe how your firm will meet the minimum qualifications.
baselineInclude a project organizational chart that identifies key personnel and outlines the role of any subcontractors.
baselineDoes the platform support AI-governance frameworks specifically (ISO/IEC 42001, NIST AI RMF) alongside traditional compliance frameworks, or is AI governance a separate, unmapped module?
baselineDescribe the incident/breach management workflow and how a security incident automatically ties back to affected controls and triggers required regulatory notification timelines (e.g., 72-hour GDPR).
baselineWhat regulatory-change monitoring is provided — does the platform proactively flag when a framework's requirements change and identify which existing controls are now out of date?
baselineWhere is compliance evidence data itself hosted, and what data-residency/sovereignty options exist for customers in regulated jurisdictions (EU, government) who can't have their compliance evidence leave-region?
baselineDetail board- and executive-level reporting: can a non-technical board member get a real-time compliance posture summary, and how is trend-over-time (not just current snapshot) presented?
baselineHow frequently are automated controls actually re-tested (continuous, daily, weekly), versus how frequently is that claimed in marketing — and can the customer configure test frequency per control criticality?
baselineExplain the pricing model — per framework, per control, per user/seat, or flat platform fee — and what happens to cost when a customer adds a second or third framework to an existing subscription.
baselineWhat is the typical time-to-first-value — from contract signature to the first control showing live automated evidence — and what implementation resources (customer-side FTEs, vendor professional services) does that require?
baselineVendor must provide Internal Control Management capability: document controls linked to risk analysis and develop verification/testing processes.
baselineVendor must be an onshore U.S.-based organization, with work performed offsite at the vendor's own location; proposed contract term is five years.
baselineIdentify the amount, type of coverage, deductible, and any coinsurance.
baselineProvide the last 2 years of SOC 1 and SOC 2 type II reports or respond with N/A if you do not have such reports.
baselineSpecify the location of the office responsible for servicing the airport authority, describing how long this specific office has been operating and the number of employees it has.
baselineProvide a thorough review of the port authority's Cybersecurity Program using the NIST Cybersecurity Framework (CSF) version 2.0 or future versions; document assessment results on a spreadsheet for each CSF control with risk findings rated high, medium, and low.
baselinePlan and prepare for a virtual meeting with the port authority's Information Security Officer (ISO) and Chief Information Officer (CIO) to review the results of the NIST audit.
baselinePrepare, within 30 days, an executive summary in PowerPoint of the NIST audit results.
baselineBe prepared for a 20-30 minute briefing of the executive summary to the port authority's Cybersecurity Oversight Committee and IT Steering Committee.
baselineDescribe any claim submitted by any client against the prime firm within the past two (2) years related to the professional services provided by the firm or its key personnel (claim = sum in dispute exceeding 10% of firm's fee).
baselineDisclose any real or perceived conflicts of interest for team members, inclusive of the prime, sub-consultants and key team members.
baselineIdentify the proposed team (working titles, degrees, certificates, and licenses), demonstrate the team's experience in performing the requested services, and describe how the team meets or exceeds the required qualifications.
baselineProvide an organizational chart demonstrating the relationships and hierarchy of the team and availability to support the port authority's projects; identify individuals by name, position, discipline and firm, including key back-up personnel.
baselineInclude a list of recent contracts/projects in the last three (3) years, with point of contact, contact information, and brief description, for services relevant to the Scope of Services, performed by key personnel.
baselineClearly describe the approaches and methods that will be used to accomplish the tasks required in the scope of services, including a summary of innovative ideas and suggestions for enhancing the scope of services.
baselineOutline the team's experience providing similar services and describe how the team is able to respond to the port authority's request for services (schedule).
baselineProvide a plan for communications and coordination between the project team, the port authority's project manager, and various stakeholders.
baselinePresent detailed information on the firm's proposed fee structure for all resources for the services proposed.
baselineComplete the Vendor Cybersecurity Self-Evaluation (Attachment E), submitted as a separately labeled PDF document.
baselineDescribe firm profile and history: types of services offered, duration of experience providing services related to this RFP, year established, form of organization, number/size/locations of offices, and total number of employees.
baselineWithin the last five (5) years, have you ever been terminated from a contract? If so, please describe the facts and circumstances surrounding the termination.
baselineTo validate prior experience, provide at least three references: each reference's name, company name, contact information, project scope, description of services, relationship length, and name/contact information of the principal contact, covering relevant experience within the last two years.
baselineComplete the Vendor Capacity information (TVE Sheet 6) and specify the estimated number of professional personnel, consultants, and technicians who will be engaged in the work, describing each individual's experience level and responsibilities.
baselineVendor must provide Reporting & Analytics capability with real-time dashboards, described as supporting HTML or other features designed to provide an at-a-glance view of current risk status.
baselineProvide references including a description of similar work performed, agency name/location, contract amount, agency contact information, and duration of service.
baselineIdentify all proposed subcontractors, including a description of the work each will perform and an estimate of the percentage of work assigned to each subcontractor.
baselineIdentify key personnel proposed for specific tasks, including name, current location, proposed position, current assignment, level of commitment, availability, and duration of employment with the firm.
baselineProvide a project organization chart delineating communication and reporting relationships among staff.
baselineProvide a narrative addressing the Scope of Work and demonstrating a clear understanding of the project's needs, including approach/methodologies and a project timeline (work plan).
baselineComplete the Cost Proposal (Attachment B) detailing fees for requested services, including unit costs, total labor hours, and/or average hourly rates broken down by task.
baselineConfirm ability to comply with the insurance provisions in Agreement Attachment 1; if unable, identify any written exceptions or deviations to the insurance requirements.
baselineConfirm authorization to do business in the applicable state.
baselineConfirm no prior or current engagement that would present a conflict of interest with the municipality.
baselineDescribe firm qualifications and profile, including number of employees, office locations, and ownership.
baselineSubmit at least three references with contact information for clients currently or previously served.
baselineProvide a proposed fee structure including a fixed fee for the engagement, itemized out-of-pocket expenses, hourly rates by role for out-of-scope work, and pricing for additional optional services.
baselineConfirm the firm has the legal authority and technical capability to perform network penetration testing services and shall comply with applicable laws, including the Computer Fraud and Abuse Act, applicable state computer crime statutes, and the FBI CJIS Security Policy where applicable.
baselineSupport compliance and auditing requirements aligned with standards such as NIST CSF, CJIS, ISO 27001, HIPAA, and PCI-DSS.
baselineAlign with NIST CSF, CJIS, HIPAA, and PCI-DSS requirements.
baselineConfirm all vendor personnel with potential access to CJIS data possess or can obtain CJIS-level clearance or equivalent background checks prior to access.
baselineDetail the firm's experience in the same or similar areas of expertise, stability, and adaptability to providing the required services; describe what sets the company apart and what value it brings.
baselineProvide a list of projects the company has completed of similar size, type, and complexity to this project.
baselineProvide at least three (3) references for similar services, including point of contact, telephone number, and brief description of services provided.
baselineDescribe how long the organization has been in business and under the same management providing similar services.
baselineProvide detailed information on the qualifications and experience of the Project Manager, including project reference contacts.
baselineIdentify key project staff and subconsultants, provide resumes, and demonstrate experience on projects of similar size and complexity.
baselineAssess alignment to NIST CSF and applicable requirements/frameworks (e.g., NIST SP 800-53, CJIS, and other applicable regulations/standards) (Compliance & Standards Alignment).
baselineProvide Compliance Mapping to NIST CSF, NIST SP 800-53, and CJIS, with all risk ratings mapped to the housing authority's internal risk register.
baselineParticipate in quarterly security review with the agency.
baselineProvide a letter of interest including firm history, principals, office locations, years in business, relevant licenses/certifications, and managerial capacity and financial viability to deliver the proposed services.
baselineProvide five (5) or more former or current clients, including Public Housing Authorities, for whom the proposer has performed similar services, with contact name, phone, email, scope of service, and dates.
baselineComplete Form HUD-5369-C, Certifications and Representations of Offerors — Non-Construction Contract.
baselineComplete the Profile and Certification Form disclosing ownership structure, diversity status (MBE/WBE/RBE/veteran-owned), debarment history, conflicts of interest with the housing authority's Commissioners/Officers, and indemnification certification.
baselineIdentify all proposed subcontractors, including classification, dollar amount, location, and MBE/WBE/SBE ownership status.
baselineEnsure all vendor personnel assigned to the engagement pass a background check consistent with the agency's cybersecurity and personnel policies, even though CJIS/PCI/PII/PHI access is not anticipated.
baselineDemonstrate strong familiarity with and operational alignment to NIST SP 800-61 Rev. 2, CIS Controls (v8+), and applicable regulatory frameworks including HIPAA, PCI DSS, and CJIS Security Policy.
baselineProvide documentation and proof of FedRAMP Authorization (at moderate risk) for any contractor cloud service offering that accesses, stores, or processes the organization's data/PII before use.
baselineDemonstrate that contractor systems are compliant with FISMA and NIST SP 800-53 Rev. 5 and have received an Authority to Operate, providing evidence per the NIST risk management framework, prior to delivering services.
baselineComplete security questionnaires, IT rules of behavior, certifications, assessments, or workforce training reasonably requested by the organization in a timely manner.
baselineEstablish and maintain internal policies/procedures for security of services and Contractor IT systems, and provide copies of information privacy and IT security policies to the organization upon request.
baselineSupport annual FISMA compliance assessments, including third-party assessments for ATO, continuous monitoring, and security penetration testing to identify vulnerabilities, and document/track findings via a Plan of Action and Milestones (POA&M).
baselineNotify the organization within 24 hours if Contractor IT services lose FedRAMP Authorization, discontinue use, and identify/implement a replacement solution within 10 business days.
baselineRespond within 10 business days to new or supplemental information security questionnaires that the organization may require during contract performance.
baselineMaintain administrative, technical, physical, and procedural information security controls compliant with ISO 27001, and provide ISO 27001 compliance certification within 10 calendar days of contract effective date.
baselineMaintain SOC 2 Type II controls and provide the most current SOC 2 Type II report within 10 calendar days of contract effective date.
baselineAnnually provide, upon written request, current security policies, Standard Information Gathering (SIG) Lite documentation, SOC 2 Type II report, system ATO(s)/ISCM evidence, and ISO 27001 certifications.
baselineExplain in detail how Offeror will establish and maintain safeguards to protect the confidentiality and integrity of the organization's Confidential Information in its possession.
baselineProvide a statement regarding any known conflicts of interest, and propose specific and detailed measures to avoid, neutralize, or mitigate actual/potential/apparent conflicts.
baselineProvide a list of any monitoring issues, audit findings, or findings of contract nonperformance related to the work within the last five years.
baselineProvide an explanation of the methodology, strategy, and workflow to be utilized, together with procedures to ensure compliance with federal/State requirements.
baselineAre there parts of your solution that can be carved out for MWBE and SDVOB subcontracting opportunities? If so, which part(s)? If not, explain why.
baselineRespond affirmatively that Proposer and subcontractors will have, prior to commencement of work, all necessary licenses, certifications, approvals, and other credentials to perform the Scope of Work.
baselineProvide the last two years of the company's most recent tax returns or, if available, audited financial statements.
baselineProvide vendor company introduction: company name, address, Federal EIN or SSN, Tax ID/DUNS, and the name, title, phone, email, and signature of the vendor's responsible contact person, plus any other persons authorized to represent the company regarding this RFP.
baselineIn the Management Summary, reflect the Vendor's understanding of the services desired and its ability to meet the RFP's requirements, describe the Vendor's approach to the proposal, and clearly indicate any options or alternatives.
baselineComplete the Vendor Qualifications and Prior Experience information (TVE Sheet 4), including a Company Profile, SAM.gov registration status, prior experience, project management approach, data management approach, and cost management approach.
baselineParse the Vendor's standard contracts and agreements terms and conditions against the Terms and Conditions requirements (TVE Sheet 8), and provide all applicable contracts and agreements in electronic format, to support development of standardized lightweight contracts.
baselineComplete the Pricing information (TVE Sheet 9) and the Payments information (TVE Sheet 10), proposing standardized, streamlined, easy-to-use pricing and payment models adaptable to the association's method.
baselineInclude any additional information pertinent to the Vendor's capabilities and experience in the proposal.
baselineDescribe the Vendor's flexibility with respect to lightweight contracts and simple invoice/payment options intended to facilitate speedy deployments of OT cybersecurity technologies across the utility sector, and the ease of use and simplicity of the Vendor's proposed Deployment Execution Strategies and Methods.
baselineConfirm the Vendor's fee structure or costs and describe how it is streamlined, standardized, and easy-to-use to facilitate speedy deployments across the utility sector.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Platform baseline
neutral · staff-reviewed
RFIWhich compliance frameworks and control catalogs (SOC 2, ISO 27001, NIST CSF/800-53, PCI DSS, HIPAA, GDPR) ship with pre-built control mappings, and how are cross-framework control overlaps deduplicated so one piece of evidence satisfies multiple frameworks?Answer key — what a strong answer shows
Strong answers name specific frameworks with maintained mappings, show cross-mapping/overlap logic (one control satisfies many frameworks), and disclose which frameworks are shallow templates versus deeply maintained.
RFPDescribe how evidence collection is automated (API integrations to cloud/IT systems versus manual upload) for a defined control set, and quantify the reduction in manual evidence-gathering hours with a customer reference.Answer key — what a strong answer shows
Look for named system integrations (not generic 'we integrate with everything'), a specific hours-saved figure tied to a real customer, and honesty about which evidence still requires manual upload.
RFIHow does the platform handle continuous control monitoring versus point-in-time audit snapshots — can a control show as 'failing' between audits, and how is that surfaced to control owners?Answer key — what a strong answer shows
Strong answers describe real-time or near-real-time control status with owner notification, not just a dashboard that updates at audit time.
RFIWhat risk register and risk-scoring methodology is used (qualitative, quantitative, FAIR-based), and can custom risk models or scoring weights be configured, or is it a fixed vendor methodology?Answer key — what a strong answer shows
Look for explicit naming of the methodology and configurability; be skeptical of vendors who can't describe their scoring math beyond 'high/medium/low'.
RFPDetail the vendor/third-party risk management capability — questionnaire automation, evidence review workflow, and continuous vendor risk monitoring — and how it integrates with the core control framework.
From other buyers
crowdsourced · anonymized
💬
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Answer key — what a strong answer shows
Strong answers show TPRM as a first-class module tied to the same control/evidence engine, not a bolted-on separate product with duplicate data entry.
RFIHow are policy documents versioned, attested to by employees, and linked to specific controls, and what happens to attestation records when a policy is updated mid-cycle?Answer key — what a strong answer shows
Look for versioned attestation history that survives policy updates (old attestations don't silently vanish or get miscounted as current).
RFPProvide detail on audit-readiness workflows: can an auditor be given direct, scoped, read-only access to evidence and control status, and what is the typical time reduction for SOC 2 Type II audit prep with a named reference?Answer key — what a strong answer shows
Strong answers describe a dedicated auditor portal/role with scoped access and a concrete time-saved figure backed by a named customer, not a generic percentage.
RFIWhat is the integration depth with ticketing/remediation workflows (Jira, ServiceNow) for control failures and audit findings — bidirectional sync or one-way export?Answer key — what a strong answer shows
Bidirectional sync (ticket status flows back to close the control finding automatically) is materially stronger than one-way export requiring manual reconciliation.
RFPExplain multi-entity/multi-framework support for organizations managing several subsidiaries or business units with different compliance obligations — is this native multi-tenancy or a workaround using tags/labels?Answer key — what a strong answer shows
Native multi-entity support (separate scoping, separate evidence, shared control library) is stronger than a single flat workspace with tags simulating separation.
RFPBriefly describe how your firm will meet the minimum qualifications.
RFPInclude a project organizational chart that identifies key personnel and outlines the role of any subcontractors.
RFIDoes the platform support AI-governance frameworks specifically (ISO/IEC 42001, NIST AI RMF) alongside traditional compliance frameworks, or is AI governance a separate, unmapped module?Answer key — what a strong answer shows
Strong answers show AI governance controls mapped into the same evidence/control engine as everything else, not a bolted-on standalone checklist.
RFPDescribe the incident/breach management workflow and how a security incident automatically ties back to affected controls and triggers required regulatory notification timelines (e.g., 72-hour GDPR).Answer key — what a strong answer shows
Look for automatic control-linkage and notification-deadline tracking, not a generic incident ticket with no compliance-clock awareness.
RFIWhat regulatory-change monitoring is provided — does the platform proactively flag when a framework's requirements change and identify which existing controls are now out of date?Answer key — what a strong answer shows
Strong answers describe active monitoring with control-level impact flagging; a vendor requiring the customer to manually track framework updates is materially weaker.
RFIWhere is compliance evidence data itself hosted, and what data-residency/sovereignty options exist for customers in regulated jurisdictions (EU, government) who can't have their compliance evidence leave-region?Answer key — what a strong answer shows
Look for concrete regional hosting options; be skeptical of vendors offering only a single-region SaaS with no residency control for evidence data.
RFPDetail board- and executive-level reporting: can a non-technical board member get a real-time compliance posture summary, and how is trend-over-time (not just current snapshot) presented?Answer key — what a strong answer shows
Strong answers show a dedicated executive view with trend lines, not just a raw control-count dashboard built for practitioners.
RFIHow frequently are automated controls actually re-tested (continuous, daily, weekly), versus how frequently is that claimed in marketing — and can the customer configure test frequency per control criticality?Answer key — what a strong answer shows
Ask for the real technical re-test cadence per control type, not the headline 'continuous monitoring' claim, and confirm criticality-based configurability.
RFPExplain the pricing model — per framework, per control, per user/seat, or flat platform fee — and what happens to cost when a customer adds a second or third framework to an existing subscription.Answer key — what a strong answer shows
Look for transparent incremental-framework pricing; vendors who won't disclose how multi-framework cost scales are a red flag for budget planning.
RFIWhat is the typical time-to-first-value — from contract signature to the first control showing live automated evidence — and what implementation resources (customer-side FTEs, vendor professional services) does that require?Answer key — what a strong answer shows
Strong answers give a specific week/month figure backed by a customer reference and are honest about the customer-side effort required, not just vendor-side setup time.
RFPVendor must provide Internal Control Management capability: document controls linked to risk analysis and develop verification/testing processes.
RFPVendor must be an onshore U.S.-based organization, with work performed offsite at the vendor's own location; proposed contract term is five years.
RFPIdentify the amount, type of coverage, deductible, and any coinsurance.
RFPProvide the last 2 years of SOC 1 and SOC 2 type II reports or respond with N/A if you do not have such reports.
RFPSpecify the location of the office responsible for servicing the airport authority, describing how long this specific office has been operating and the number of employees it has.
RFPProvide a thorough review of the port authority's Cybersecurity Program using the NIST Cybersecurity Framework (CSF) version 2.0 or future versions; document assessment results on a spreadsheet for each CSF control with risk findings rated high, medium, and low.
RFPPlan and prepare for a virtual meeting with the port authority's Information Security Officer (ISO) and Chief Information Officer (CIO) to review the results of the NIST audit.
RFPPrepare, within 30 days, an executive summary in PowerPoint of the NIST audit results.
RFPBe prepared for a 20-30 minute briefing of the executive summary to the port authority's Cybersecurity Oversight Committee and IT Steering Committee.
RFPDescribe any claim submitted by any client against the prime firm within the past two (2) years related to the professional services provided by the firm or its key personnel (claim = sum in dispute exceeding 10% of firm's fee).
RFPDisclose any real or perceived conflicts of interest for team members, inclusive of the prime, sub-consultants and key team members.
RFPIdentify the proposed team (working titles, degrees, certificates, and licenses), demonstrate the team's experience in performing the requested services, and describe how the team meets or exceeds the required qualifications.
RFPProvide an organizational chart demonstrating the relationships and hierarchy of the team and availability to support the port authority's projects; identify individuals by name, position, discipline and firm, including key back-up personnel.
RFPInclude a list of recent contracts/projects in the last three (3) years, with point of contact, contact information, and brief description, for services relevant to the Scope of Services, performed by key personnel.
RFPClearly describe the approaches and methods that will be used to accomplish the tasks required in the scope of services, including a summary of innovative ideas and suggestions for enhancing the scope of services.
RFPOutline the team's experience providing similar services and describe how the team is able to respond to the port authority's request for services (schedule).
RFPProvide a plan for communications and coordination between the project team, the port authority's project manager, and various stakeholders.
RFPPresent detailed information on the firm's proposed fee structure for all resources for the services proposed.
RFPComplete the Vendor Cybersecurity Self-Evaluation (Attachment E), submitted as a separately labeled PDF document.
RFPDescribe firm profile and history: types of services offered, duration of experience providing services related to this RFP, year established, form of organization, number/size/locations of offices, and total number of employees.
RFPWithin the last five (5) years, have you ever been terminated from a contract? If so, please describe the facts and circumstances surrounding the termination.
RFPTo validate prior experience, provide at least three references: each reference's name, company name, contact information, project scope, description of services, relationship length, and name/contact information of the principal contact, covering relevant experience within the last two years.
RFPComplete the Vendor Capacity information (TVE Sheet 6) and specify the estimated number of professional personnel, consultants, and technicians who will be engaged in the work, describing each individual's experience level and responsibilities.
RFPVendor must provide Reporting & Analytics capability with real-time dashboards, described as supporting HTML or other features designed to provide an at-a-glance view of current risk status.
RFPProvide references including a description of similar work performed, agency name/location, contract amount, agency contact information, and duration of service.
RFPIdentify all proposed subcontractors, including a description of the work each will perform and an estimate of the percentage of work assigned to each subcontractor.
RFPIdentify key personnel proposed for specific tasks, including name, current location, proposed position, current assignment, level of commitment, availability, and duration of employment with the firm.
RFPProvide a project organization chart delineating communication and reporting relationships among staff.
RFPProvide a narrative addressing the Scope of Work and demonstrating a clear understanding of the project's needs, including approach/methodologies and a project timeline (work plan).
RFPComplete the Cost Proposal (Attachment B) detailing fees for requested services, including unit costs, total labor hours, and/or average hourly rates broken down by task.
RFPConfirm ability to comply with the insurance provisions in Agreement Attachment 1; if unable, identify any written exceptions or deviations to the insurance requirements.
RFPConfirm authorization to do business in the applicable state.
RFPConfirm no prior or current engagement that would present a conflict of interest with the municipality.
RFPDescribe firm qualifications and profile, including number of employees, office locations, and ownership.
RFPSubmit at least three references with contact information for clients currently or previously served.
RFPProvide a proposed fee structure including a fixed fee for the engagement, itemized out-of-pocket expenses, hourly rates by role for out-of-scope work, and pricing for additional optional services.
RFPConfirm the firm has the legal authority and technical capability to perform network penetration testing services and shall comply with applicable laws, including the Computer Fraud and Abuse Act, applicable state computer crime statutes, and the FBI CJIS Security Policy where applicable.
RFPSupport compliance and auditing requirements aligned with standards such as NIST CSF, CJIS, ISO 27001, HIPAA, and PCI-DSS.
RFPAlign with NIST CSF, CJIS, HIPAA, and PCI-DSS requirements.
RFPConfirm all vendor personnel with potential access to CJIS data possess or can obtain CJIS-level clearance or equivalent background checks prior to access.
RFPDetail the firm's experience in the same or similar areas of expertise, stability, and adaptability to providing the required services; describe what sets the company apart and what value it brings.
RFPProvide a list of projects the company has completed of similar size, type, and complexity to this project.
RFPProvide at least three (3) references for similar services, including point of contact, telephone number, and brief description of services provided.
RFPDescribe how long the organization has been in business and under the same management providing similar services.
RFPProvide detailed information on the qualifications and experience of the Project Manager, including project reference contacts.
RFPIdentify key project staff and subconsultants, provide resumes, and demonstrate experience on projects of similar size and complexity.
RFPAssess alignment to NIST CSF and applicable requirements/frameworks (e.g., NIST SP 800-53, CJIS, and other applicable regulations/standards) (Compliance & Standards Alignment).
RFPProvide Compliance Mapping to NIST CSF, NIST SP 800-53, and CJIS, with all risk ratings mapped to the housing authority's internal risk register.
RFPParticipate in quarterly security review with the agency.
RFPProvide a letter of interest including firm history, principals, office locations, years in business, relevant licenses/certifications, and managerial capacity and financial viability to deliver the proposed services.
RFPProvide five (5) or more former or current clients, including Public Housing Authorities, for whom the proposer has performed similar services, with contact name, phone, email, scope of service, and dates.
RFPComplete Form HUD-5369-C, Certifications and Representations of Offerors — Non-Construction Contract.
RFPComplete the Profile and Certification Form disclosing ownership structure, diversity status (MBE/WBE/RBE/veteran-owned), debarment history, conflicts of interest with the housing authority's Commissioners/Officers, and indemnification certification.
RFPIdentify all proposed subcontractors, including classification, dollar amount, location, and MBE/WBE/SBE ownership status.
RFPEnsure all vendor personnel assigned to the engagement pass a background check consistent with the agency's cybersecurity and personnel policies, even though CJIS/PCI/PII/PHI access is not anticipated.
RFPDemonstrate strong familiarity with and operational alignment to NIST SP 800-61 Rev. 2, CIS Controls (v8+), and applicable regulatory frameworks including HIPAA, PCI DSS, and CJIS Security Policy.
RFPProvide documentation and proof of FedRAMP Authorization (at moderate risk) for any contractor cloud service offering that accesses, stores, or processes the organization's data/PII before use.
RFPDemonstrate that contractor systems are compliant with FISMA and NIST SP 800-53 Rev. 5 and have received an Authority to Operate, providing evidence per the NIST risk management framework, prior to delivering services.
RFPComplete security questionnaires, IT rules of behavior, certifications, assessments, or workforce training reasonably requested by the organization in a timely manner.
RFPEstablish and maintain internal policies/procedures for security of services and Contractor IT systems, and provide copies of information privacy and IT security policies to the organization upon request.
RFPSupport annual FISMA compliance assessments, including third-party assessments for ATO, continuous monitoring, and security penetration testing to identify vulnerabilities, and document/track findings via a Plan of Action and Milestones (POA&M).
RFPNotify the organization within 24 hours if Contractor IT services lose FedRAMP Authorization, discontinue use, and identify/implement a replacement solution within 10 business days.
RFPRespond within 10 business days to new or supplemental information security questionnaires that the organization may require during contract performance.
RFPMaintain administrative, technical, physical, and procedural information security controls compliant with ISO 27001, and provide ISO 27001 compliance certification within 10 calendar days of contract effective date.
RFPMaintain SOC 2 Type II controls and provide the most current SOC 2 Type II report within 10 calendar days of contract effective date.
RFPAnnually provide, upon written request, current security policies, Standard Information Gathering (SIG) Lite documentation, SOC 2 Type II report, system ATO(s)/ISCM evidence, and ISO 27001 certifications.
RFPExplain in detail how Offeror will establish and maintain safeguards to protect the confidentiality and integrity of the organization's Confidential Information in its possession.
RFPProvide a statement regarding any known conflicts of interest, and propose specific and detailed measures to avoid, neutralize, or mitigate actual/potential/apparent conflicts.
RFPProvide a list of any monitoring issues, audit findings, or findings of contract nonperformance related to the work within the last five years.
RFPProvide an explanation of the methodology, strategy, and workflow to be utilized, together with procedures to ensure compliance with federal/State requirements.
RFPAre there parts of your solution that can be carved out for MWBE and SDVOB subcontracting opportunities? If so, which part(s)? If not, explain why.
RFPRespond affirmatively that Proposer and subcontractors will have, prior to commencement of work, all necessary licenses, certifications, approvals, and other credentials to perform the Scope of Work.
RFPProvide the last two years of the company's most recent tax returns or, if available, audited financial statements.
RFPProvide vendor company introduction: company name, address, Federal EIN or SSN, Tax ID/DUNS, and the name, title, phone, email, and signature of the vendor's responsible contact person, plus any other persons authorized to represent the company regarding this RFP.
RFPIn the Management Summary, reflect the Vendor's understanding of the services desired and its ability to meet the RFP's requirements, describe the Vendor's approach to the proposal, and clearly indicate any options or alternatives.
RFPComplete the Vendor Qualifications and Prior Experience information (TVE Sheet 4), including a Company Profile, SAM.gov registration status, prior experience, project management approach, data management approach, and cost management approach.
RFPParse the Vendor's standard contracts and agreements terms and conditions against the Terms and Conditions requirements (TVE Sheet 8), and provide all applicable contracts and agreements in electronic format, to support development of standardized lightweight contracts.
RFPComplete the Pricing information (TVE Sheet 9) and the Payments information (TVE Sheet 10), proposing standardized, streamlined, easy-to-use pricing and payment models adaptable to the association's method.
RFPInclude any additional information pertinent to the Vendor's capabilities and experience in the proposal.
RFPDescribe the Vendor's flexibility with respect to lightweight contracts and simple invoice/payment options intended to facilitate speedy deployments of OT cybersecurity technologies across the utility sector, and the ease of use and simplicity of the Vendor's proposed Deployment Execution Strategies and Methods.
RFPConfirm the Vendor's fee structure or costs and describe how it is streamlined, standardized, and easy-to-use to facilitate speedy deployments across the utility sector.
RFPProvide Information Security Policy and Procedure Development or Review.
RFPProvide a summary of your organization's qualifications (not to exceed 5 pages), covering expertise in software development, support, implementation, and training pertaining to the proposed software, including any third-party systems included in the proposal; submission of industry-analyst reports (e.g., Gartner, Meta Group) is encouraged.
RFPInclude at least three references (at least three public-sector references from cities that have installed and fully implemented the solution, similar in scope to this RFP, and preferably within the applicable state) where your organization provided similar services using the same software, including contact names, phone numbers, addresses, and the year/timeframe of engagement; one reference form per reference.
RFPProvide a detailed description of your project management approach and implementation methodology (not to exceed 10 pages), describing your implementation plan including training, data conversion, systems integration, and testing processes, your approach/philosophy, and options (internal, subcontractor, or implementation vendor).
RFPProvide a high-level project plan with expected deliverables and estimated timelines, including typical expectations of agency staff commitment and what staff the agency can anticipate needing to backfill during implementation.
RFPProvide costs using the Pricing Worksheet (Appendix C) for all project deliverables, identifying any third-party software and customization estimates.
RFPIf at any time in the past 5 years your firm has had a contract terminated for convenience, non-performance, or any other reason, or has entered into legal action with a customer, describe the situation(s), including the name and address of the contracting party and the circumstances.
RFPMust include pre-built and customizable reporting for compliance and security analytics, and should provide compliance-specific reports.
RFPMust be compliant with relevant federal and state regulations applicable to educational institutions.
RFPOfferors must include a statement of work (SOW).
RFPVendors are to describe their process for amending the contract to accommodate site/service substitutions during the contract term, given that the school district may add, move, or close locations during the life of the contract.
RFPBidders must clearly separate E-Rate eligible costs from ineligible costs in the pricing schedule.
RFPService Providers are responsible for providing a valid Service Provider Identification Number (SPIN), a valid FCC Registration Number, and evidence of FCC Green Light Status at the time the proposal is submitted; if in Red Light Status, must explain remediation steps and expected timeframe.
RFPComplete the Vendor Execution information (TVE Sheet 7): identify what technologies, services, and agreements are being offered and the contributions from the Vendor itself versus its partners, and identify any major requirements that cannot be met by the Vendor.
RFPDemonstrate a solid customer base utilizing the proposed solution, including cities similar in size and service delivery to the agency, and successful experience implementing the proposed software in the applicable state to fully comply with record tracking and reporting requirements.
RFPIn the Letter of Transmittal, state your organization's understanding of the work to be accomplished; commit to performing the implementation work within the scheduled time period upon award; summarize service fee costs and state whether fees are fixed, complete, inclusive, or negotiable; confirm the proposal remains valid for 180 days; and name the individuals authorized to make representations for your organization, with titles, addresses, emails, and phone numbers.
RFPProvide a Company Profile including organizational size, how long in business, public or private entity status, whether local/regional/national/international in scope, and a listing of other similar governmental customers using the proposed solution.
RFPVendor must submit a minimum of four (4) references, preferably from school districts located in the same state, with name, contact name, email, phone, and address for each.
RFPBidder must clearly define contract terms for all pricing submitted; the contract must be able to begin providing goods/services on July 1, 2025 and remain valid for a three-year term expiring June 30, 2028.
RFPVendor should provide different dashboards/screens for different roles (Top Management, IS Team, Auditors) for viewing real-time incidents, events, alerts and status of actions taken; the offered cyber security product shall assist compliance with SEBI guidelines on cyber security for financial intermediaries.
RFPContractor shall serve as primary technical support for all internal and external audits (e.g., an annual federal OIG FISMA audit), driving artifact collection, providing liaison/interview support, and performing evidence validation for completeness/accuracy/quality.
RFPContractor shall manage the Information Security Continuous Monitoring (ISCM) program and perform internal controls testing, maintaining A&A packages (SSPs, CMPs, Contingency Plans) per NIST SP 800-18 and the organization's internal standards, conducting annual policy/procedure gap analyses, routine reviews of audit logs/patching/access lists/IR testing, and executing internal Security Control Assessments (SCA) per NIST SP 800-53A for minor systems, interim authorizations, or FedRAMP SaaS offerings.
RFPTask Area 5: Contractor shall provide program management (planning, coordination, staffing oversight, quality control, risk/issue management), recurring reports/briefings/dashboards/metrics per established cadence, and performance management tracking SLAs/KPIs, identifying performance issues and recommending corrective action.
RFPContractor shall deliver a Transition-In Plan no later than 7 days after contract award, and a Transition-In Support Package (documentation, licensing, asset inventories, SOPs) no later than 45 days after award; deliver a Transition-Out Plan no later than 90 days before contract expiration and a Transition-Out Support Package no later than 60 days before expiration, including shadowing/knowledge-transfer sessions.
RFPContractor shall provide Key Personnel in the following roles: Program Manager (PMP/CISSP/CCSP), Security Architect (CISSP/CISM/SSCP), SOC/NOC Operations Manager (CISSP + IR/SecOps cert), ISSO Lead (CISSP or equivalent), Lead Cybersecurity Engineer (CISSP/ISSEP/ITIL), Automation/SOAR Engineer, Lead PAM Engineer, and Vulnerability Management Lead — Key Personnel shall remain in their positions throughout the Contract Term absent the organization's prior written approval for changes.
RFPContractor shall conduct background checks on Contractor Staff and provide evidence of the background checks to the organization upon request; Contractor Staff working on the organization's premises must sign a Visitor Form, and Contractor is responsible for all actions of Contractor Staff including violations of law or negligence.
RFPThe SOC should be able to integrate various log types and logging options into SIEM, ticketing/workflow/case management, unstructured/big data, reporting/dashboard, and customized use cases/rule design based on risk and compliance requirements, in adherence to RBI cyber security circular RBI/2015-16/418; the SOC setup should meet ISO27001, PCI-DSS and OWASP requirements and the Bank should be able to obtain certification from an independent entity.
RFPVendor must provide Audit Management capability: managing all auditing activities including planning, execution and reporting, with tracking capabilities for findings and remediation.
RFPVendor must provide Compliance Management capability: ability to execute policy compliance audits and identify same or similar policy requirements to reduce redundancies.
RFPVendor must provide Risk Management capability: evaluate risk levels across data storage, collection, and transmission with impact analysis and mitigation recommendations.
RFPSubmit a compliance certificate certifying compliance with the SEBI Cyber Security and Cyber Resilience Framework (dated 20 Aug 2024) before onboarding and every year until contract expiration, and submit SOC efficacy testing results on a half-yearly basis per SEBI CSCRF format.
RFPTask Area 1: Contractor shall provide integrated security compliance, vulnerability management, and risk support services, including ISSO support for security authorization activities, development/maintenance of security documentation, and support for RMF, Assessment and Authorization (A&A), and continued authorization lifecycle activities.
RFPContractor shall support management, tracking, analysis, and reporting of Plans of Action and Milestones (POA&Ms), risk acceptances, and related remediation activities, including status reporting on open, overdue, closed, and risk-accepted items, and identify trends/recurring issues.
RFPContractor shall lead, maintain, and track enterprise-wide configuration management as a dedicated, non-collateral security function: develop/maintain security configuration baselines (updated at least annually), perform automated configuration compliance scanning, analyze failed settings for security risk/technical conflict/formal deviation, integrate configuration data into the authorization boundary (e.g., Xacta/GRC tool), manage deviation/risk decisions via Security Impact Analyses (SIA) with annual re-review, and implement a continuous tuning maintenance cycle.
RFPVendor must complete and submit Attachment C (Minimum Qualifications Checklist), Attachment D (References Template), Attachment E (Technology Security Assessment), and Attachment G (Functional Response Template) as part of the proposal package, along with a Price Proposal per Attachment B and acceptance of the County Standard Contract Template (Attachment F).
RFPThe Supplier shall provide the best pricing for this RFP in Goods and/or Services.
RFPManage full lifecycle of vendor IT risk management – onboarding, assessment, off boarding.
RFPManage IT risk assessments based on common cyber security frameworks (NIST CSF & 800 series, ISO 27001, GLBA and others).
RFPProvide a scalable solution to meet the needs of a geographically distributed, federated organization.
RFPEasily configure templates and workflows and quickly share with other locations.
RFPShare results of vendor assessments and risk ratings with other locations.
RFPStandardize vendor and IT risk assessments, workflows, templates and reports.
RFPProvide a secure storage location for sensitive cybersecurity documentation that allows the university system to comply with vendor requirements for handling their data.
RFPBuild configurable, automated workflows and risk analysis, leveraging Artificial Intelligence as applicable.
RFPEmpower localized teams to tailor assessments based on their requirements.
RFPInclude interconnectivity – send and receive data – from a variety of external systems such as ticketing, asset management (e.g. ServiceNow, Jira); contract lifecycle management (CLM) and other GRC platforms (e.g. OneTrust, etc.).
RFPProvide integration with continuous monitoring solutions for third party (e.g. Security Scorecard, Black Kite, etc.) and internal (BitSight, ServiceNow, etc.) risk data.
RFPFacilitate data downloading to common, non-proprietary file types without requiring help from customer support.
RFPReduce time and redundant effort to evaluate vendor risk using customizable analysis tools.
RFPImprove risk visibility for multiple layers of leadership through customizable reporting dashboards and rollup reporting.
RFPDown-selected Suppliers will be required to present and provide a sandbox environment demonstration of the proposed solution.
RFPSuppliers are required to respond to all questionnaires: Supplier Information, Supplier Capabilities, GRC Technical, GRC Functional, Environmental and ECI, Accessibility, Data Security, and Pricing. Responses should not rely on generic AI-generated templates and must clearly demonstrate how the proposed solution specifically addresses each question.
RFPSupplier must certify under penalty of perjury that the services will be performed solely with workers within the United States, including any services provided using a sub-supplier; or describe in its proposal any parts of the services that will be performed by workers outside of the United States.
RFPIn documenting an Exception to the RFP specifications, Supplier must provide a detailed itemization and explanation for each deviation from the RFP specifications, clearly describing any alternate goods and/or services that could be provided to satisfy those requirements.
RFPContractor shall provide a GRC tool that includes support for: process automation features to streamline workflows and manual tasks.
RFPIntegrated content management supporting internal and external collaboration, document sharing, storage, and archiving.
RFPCase management features for core GRC functions (audits, assessments, risks, investigations, etc.).
RFPForms management and template configuration solutions with no-code capability to easily modify field types/names and associated data validations.
RFPAd-hoc & scheduled reporting and analytics; enterprise and project-specific dashboards with drill down capability.
RFPWhat is the organization's policy on confidentiality during and after the engagement?
RFPSupport enterprise risk management: collection, analysis and communication of high impact/high likelihood programmatic or operational risks across the enterprise.
RFPSupport compliance, internal control testing, & policy management features.
RFPSupport case management with tight, role-based security permissions limiting access to confidential fraud investigations to authorized personnel only.
RFPOffer a no-code, highly configurable integrated GRC COTS solution with an intuitive, user-friendly UI connecting the organization's GRC functions (audit, risk, compliance, etc.) within a single integrated platform.
RFPSupport access to both internal and select external users (external contractors with restricted/limited access), supporting a user population of approximately 200 once fully scaled.
RFPProvide privacy security features to store sensitive/confidential/PII GRC documents and associated data (e.g. Fraud Risk investigations).
RFPEnable unique role-based permissions controlling access/authorization to both content and tool functionality.
RFPSupport open APIs to enable bi-directional data flow or similar connection/integration with other systems or applications of the organization (e.g. SharePoint, Enterprise Data Warehouse).
RFPIntegrate with the organization's OKTA Identity and Access Management/MFA software for user authentication and provisioning, and provide MFA capabilities.
RFPSupport Single Sign On (SSO) capability through OKTA by using SAML based authentication, and provide create, update, and deactivate capabilities.
RFPSupport ability to perform bulk file uploads (e.g. csv, xls) for populating GRC internal data and downloadable data exports of all internal records and data.
RFPEnable automated and manual bulk migration of data and artifacts from existing legacy systems to the GRC tool as part of implementation.
RFPInterface with Outlook/Exchange for outbound and inbound email delivery to support email notifications, email-triggering workflows, bulk-email delivery, and automated entity data collection via templatized forms or file attachment uploads.
RFPThe solution shall provide full and incremental data back-up capabilities on a scheduled and ad-hoc basis, and must allow system administrators to perform restoration of content at all levels, from full database restoration to partial restoration of selected content.
RFPThe system shall flexibly allow growth of data and transaction volume without any degradation of response time or other system processing performance criteria when at full capacity (>80%).
RFPThe organization requires 24/7 access to the GRC solution with a system uptime of >99%. The vendor shall provide SLAs for scheduled system maintenance and response times for addressing system failures.
RFPThe system shall not exceed >500ms response time for user interactions and support transaction volumes and data transfers with minimal workload processing delays.
RFPFor cloud-based solutions, the system shall support the ability to configure encryption at rest and/or in transit for the organization's sensitive data, as determined by the organization's policy and use cases.
RFPThe organization requires the ability to perform configuration changes and user acceptance testing in separate technology environments isolated from the GRC live production application. The vendor shall propose a solution that includes multiple, lower environments to meet product development life cycle for deploying features via automated continuous integration.
RFPThe organization requires support of SDLC artifacts during implementation including architecture/integration diagrams, high-level technical design (TDD), test documentation, and security assessment procedures and certification.
RFPDesired but not required: provide a built-in Microsoft 365 connector or ability to build API to archive documents in OneDrive; support UX using the organization's branding and 508 compliance.
RFPThe vendor shall provide a detailed strategy/plan illustrating the vendor's approach and methodology to the configuration, implementation and roll out of the GRC tool, including key phases, milestones, timeline, and resources specifying roles and responsibilities.
RFPThe vendor shall work with the organization's Identity Access Manager (and identity management engineers) for configuration of OKTA and MFA with the GRC environment, and ensure that GRC functions properly over user VPN.
RFPThe vendor shall incorporate backup protocols and guidance for how GRC will interact with current backup hardware and software for both file structure and work drives as well as disaster recovery systems.
RFPThe vendor shall provide strategy to migrate legacy data to the new GRC tool, including data mapping, migration tasks, dependencies, assumptions, constraints and risks, and provide a decommissioning strategy for legacy tools.
RFPThe vendor shall provide support, for 90 days post-deployment, for any GRC Administration related questions or issues, plus telephone support for technical questions.
RFPThe vendor shall provide customized materials and recommendations for enterprise-wide training for admin, core team users, business/general, leadership users as well as for external contractors and new hires using the tool, and develop a communications and training plan based on GRC best practices.
RFPVendor requirement: US based vendor; 5+ years of experience implementing GRC tools; for cloud-based tools, hosting services must reside in the Continental United States.
RFPVendor shall assign a Project Manager whose primary duties will be the implementation and oversight of the project, and shall schedule, prepare an agenda for, and coordinate a Project Kick-Off Meeting within ten business days of contract execution.
RFPCapabilities Matrix: Identify the tool(s) and services that satisfy the technical requirements. Provide a brief explanation of how your company would mitigate those tool and service requirements that your solution does not currently satisfy. Provide a roadmap and a tentative timeline to implement the tools and services requested in the RFP.
RFPComplete Attachment 3 (Vendor GRC Functional Fit Gap) provided by the organization, filling in the information on the different tabs; and respond to Attachment 4 (Informational Request).
RFPDescribe your firm's experience with providing the tools and related services as detailed in Section 6 of this RFP. Provide a minimum of three examples of projects and personnel, including an overview of the engagement, description of scope of work performed, its relevance to this effort, and the results achieved.
RFPInclude 3 professional references with Company Name, POC name and title, and POC email and phone number.
RFPOfferor's proposal shall clearly and conspicuously identify information contained in the proposal that Contractor contends is confidential information.
RFPProvide completed pricing information in the format of Attachment 1 (Bid Sheet); the proposed price should be fully burdened and must include wages, overhead, general and administrative expenses, travel, taxes and profit.
RFPUpon written request by the organization, Contractor shall provide a Continuity of Operations Plan (COOP) including business continuity plans, disaster recovery plans, emergency operations plan and procedures.
RFPContractor shall provide resources with a working and holistic understanding and knowledge of the Risk Management Framework (RMF) as defined by NIST SP 800-53 and NIST SP 800-53A, and serve as the source of technical expertise with regard to maintaining and improving the organization's RMF implementation.
RFPContractor shall provide Assessment & Authorization (A&A) support for approximately 15 moderate baseline systems consisting of the organization's Enterprise Common Controls, organization-hosted systems, systems hosted on FedRAMP-authorized cloud platforms, and systems hosted on non-FedRAMP-authorized cloud services.
RFPContractor shall develop and maintain a plan for the organization's ISSM and CISO approval to maintain authorization or risk acceptance for all relevant systems, including achievement of Authorization to Operate (ATO) for new or significantly changed systems, in accordance with OMB, NIST, and FISMA guidance/regulations.
RFPContractor shall prepare A&A packages, including a System Security Plan (SSP) for each of the organization's systems; strategically advise on the restructuring/reordering of system boundaries for compliance packages; prepare risk management recommendations; and track POA&Ms internally and with system owners.
RFPContractor shall conduct internal risk assessments to ensure controls and countermeasures are identified to compensate for weaknesses to reduce risk to the organization's operations, assets, individuals, or stakeholders, and prepare risk determination statements outlining potential risk with planned or completed corrective actions.
RFPContractor shall provide quarterly reports on A&A activities for Executive Briefing to the CIO and/or the organization's Enterprise Risk Management Council, including SCAs completed, penetration tests completed, and relevant POA&M updates.
RFPNo later than 18 months after award, Contractor shall develop a comprehensive plan to migrate systems from legacy A&A practices to Ongoing Security Authorization (OSA), leveraging NIST SP 800-37 (Risk Management), NIST SP 800-53 (Control Guidance), and NIST SP 800-137 (Continuous Monitoring), and recommend innovative ways to automate OSA activities such as automated control testing and results reporting.
RFPContractor shall be responsible for managing the organization's information security policies, procedures, and standards based on FISMA, NIST, OMB, DHS directives, updating A&A policies and the Information Security and Privacy Control Policy at least annually, and identifying policy gaps with quarterly reporting and mitigation recommendations.
RFPContractor shall be responsible for administration and maintenance of the organization's IT Security GRC Tool (currently Telos Xacta 360), including capturing, organizing, and maintaining draft/final security artifacts, and supporting independent third-party assessors' use of the tool for artifact collection and SRTM preparation.
RFPContractor shall ensure audit logs are reviewed and regular audits conducted for security and accountability, and work with IT Security Operations to integrate audit logging into the organization's SIEM tool, if possible.
RFPContractor shall develop and maintain a Plans of Action and Milestones (POA&M) Management Program Plan and Procedure, manage POA&M creation from findings arising from A&A assessments, audits, incidents, and penetration test findings, and use the organization-designated software (currently JIRA) for tracking all POA&Ms.
RFPContractor shall be responsible for establishing and managing an IT Risk Management Program per OMB Circular A-123/A-130, including developing an IT Risk Management Program Charter and Plan, defining risk appetite and governance methodology, recommending an automated mechanism for capturing and tracking IT risks, and providing quarterly trending/metrics reports to the CIO and/or Enterprise Risk Management Council.
RFPAs tasked, Contractor shall facilitate transition of contracted activities and services to the organization's personnel or a follow-on contractor, providing current system/user documentation, licensing and renewal information, asset management records, current inventory of the organization's assets, and knowledge-transfer/shadowing opportunities.
RFPContractor shall designate a Program Manager (CISSP or equivalent) with at least 10 years of relevant cybersecurity program management experience to oversee the project and act as senior technical advisor to CISO/OCISO staff.
RFPContractor shall designate an ISSO Lead (CISSP, CIPT or equivalent) to lead A&A support activities and develop/implement information security standards and procedures; a POA&M Management Lead (CISSP or equivalent); a Vulnerability Management Lead (CISSP or equivalent); a Risk Management Lead (PMP, PMI-RMP, CRISC, or equivalent); and a Supply Chain Risk Management Lead (PMP, PMI-RMP, CRISC, or equivalent).
RFPDescribe Offeror's capabilities for performing the Contract, including personnel resources and management capabilities. If applicable, describe how subcontractors or partners are used and how rates are determined when using subcontractors. Provide a list of firms, if any, that will be used.
RFPOfferors shall describe in detail their process for conducting activities to manage the organization's Information Security Program, including how the Offeror intends to staff and complete these activities, and describe in detail their plan for completing the digital government consulting identified in the RFP within the time allotted.
RFPOfferor shall provide an Information Security Program Plan Framework that highlights their expertise in conducting these types of consulting services.
RFPDescribe your firm's experience with consultation and support of an organization's information security program of similar size and scope. Provide examples of the projects and personnel, including types of positions and length of assignments.
RFPIdentify by name all key personnel. Describe the technical knowledge and experience of proposed personnel in the requested services, including depth of knowledge, expertise and number of years. Indicate any other personnel that will be assigned to the organization and his/her role on the contract. Provide a brief summary of each professional staff member's qualifications including education and relevant experience; submit resumes for all key personnel (no longer than two pages each).
RFPProvide a list of up to three current or recently completed contracts similar in scope, each including client name, project title, period of performance, contract number, contract value, and primary/back-up points of contact; for each, provide an overview of the engagement, scope of work performed, relevance to this effort, and results achieved.
RFPOfferors must identify any actual or potential conflicts of interest, including current vendors of the organization involving the Offeror or any proposed subcontractor, and the means by which it proposes to avoid, neutralize, or mitigate such conflicts.
RFPProvide a summary detailing Offeror's FISMA and NIST security framework and organization information security support, and a clear statement of whether Offeror's performance of the Contract will comply with all requirements stated in the RFP and the organization's Terms and Conditions.
RFPShould be a Government Organization/PSU/PSE/partnership firm or a limited Company under Indian Laws or/and an autonomous Institution approved by GOI/RBI, in existence in India for three years as of 31-07-2019.
RFPShould have a minimum average annual turnover of Rs. 20 crores during the last three financial years (2016-17, 2017-18, 2018-19), with net profits in each of those years, evidenced by abridged audited Balance Sheet and P&L statements.
RFPBidder should have at least 3 years' experience offering Information Security Services (security assessment, defining security policies/procedures/baselines, risk assessment, security consulting) to public sector Banks in India, evidenced by copy of purchase order.
RFPThe Bidder must have experience providing ISO27001 consultancy to at least 2 BFSI institutions in India leading to successful ISO27001 certification/recertification, of which at least 1 must be a Bank in India with a minimum of 500 branches, evidenced by purchase order and certification copies.
RFPThe Bidder must have at least 5 consultants qualified as ISO27001 Lead Auditors and at least 12 CISA/CISSP/CEH certified professionals as employees, and must not be an existing System Integrator maintaining IT infrastructure at the Bank's Data Centre or DR site; subcontracting of any RFP-scope work is not allowed.
RFPSelected Bidder shall perform detailed scoping of DC/DR operations, review the Bank's IT Security Policy, ISMS Framework, and Risk Assessment Framework against ISO27001 standards/international best practices/RBI guidelines, and update policy/procedure/framework documents based on that review.
RFPConduct awareness training sessions (classroom and on-the-job) on IT Risk assessment and ISO27001 standard for DC and DR staff on a yearly basis, to enable Bank personnel to carry out such assignments independently in future.
RFPPerform a comprehensive Risk Assessment of DC/DR operations (and third-party relationships) on a yearly basis per a defined Risk Assessment methodology, hold periodic meetings with the Bank, and submit a granular, deficiency-specific Risk Mitigation Plan (generic recommendations to be avoided) based on industry best practices; actual risk remediation is out of scope but the Bidder must coordinate with the Bank's system integrator and provide handholding support until risks are remediated.
RFPPerform pre-surveillance/recertification internal audit to ensure comprehensive compliance with ISO27001, prepare/modify all required documentation (e.g. Statement of Applicability), enable the Bank for external surveillance/recertification audits, and assist in closure of internal and external audit findings.
RFPIn the event of any change in the ISO standard, the selected Bidder will be required to migrate documentation (policies/procedures) and assist the Bank in migrating to the new standard to maintain certification, at Bank's discretion on timeline, at no additional cost.
RFPKey project personnel must have in-depth knowledge of IT and Banking processes with a minimum of 3 years' work experience in IT Security, in-depth knowledge of RBI guidelines, be a certified ISO27001 Lead Auditor, have worked on at least 2 ISO27001 consultancy/certification assignments (1 for a Bank), and possess CISA/CISSP/CEH certification.
RFPDeliverables: high-level and detailed project plans, description of approach/methodology, detailed scope for ISO27001 certification, modified IT Security Policy/ISMS Framework/Risk Assessment Framework, classroom training materials, Risk Assessment report and Risk Mitigation plan, executive summary and detailed reports for management review, Internal Audit Report, and all ISO27001 certification documentation.
RFPSubstitution of key project team members during the assignment is not allowed except with prior written Bank concurrence and equivalent-qualification replacement staff; unsatisfactory substitution entitles the Bank to terminate the contract and recover payments plus liquidated damages equal to the contract value.
RFPPlease describe the levels of your professional liability insurance coverage for client security breaches (cyber risk) and any fiduciary or professional liability insurance your Firm carries. Is the coverage on a per client basis or applied to the Firm as a whole? List the insurance carriers.
RFPWhat limitation on liability, if any, do you impose through your contract? The Firm must not seek to unreasonably limit their liability for negligence.
RFPDoes coverage for liability, due to your negligence, continue for a period following termination of the contract? If so, for how long?
RFPHas your Firm ever been involved in a lawsuit in the last ten (10) years involving any services provided by the Firm? If so, provide details, including description of the lawsuit, dates, and outcomes, including any filed claims settled without litigation.
RFPHas your Firm, related entities, affiliates, principals, and/or officers been a party in any material civil or criminal litigation, or subject to investigation, disciplinary action, or regulatory review? Describe any anticipated litigation in which your Firm may be involved.
RFPMust carry cybersecurity insurance and liability coverage to mitigate risks associated with testing (proof required with submission).
RFPVendors must be willing to enter into a Business Associate Agreement (BAA) in compliance with HIPAA regulations, as required.
RFPProvide a list and description of any legal actions, lawsuits, arbitrations or formal protests in which bidder has been involved in the last twenty-four (24) months that would have an impact on the bidder's ability to provide the requested services.
RFPProvide a written acknowledgement of the acceptance of the Contracting Requirements set forth in Section IV of the RFP, or an explanation of specific bidder concerns or requested changes.
RFPThe organization will require that the Respondent performing this service sign a non-disclosure agreement prior to beginning work due to the highly proprietary or sensitive nature of the information that may be disclosed during the project.
RFPDescribe the dollar levels of coverage for errors and omissions coverage and any other liability coverage which the Firm carries.
RFPDescribe any contractual legal liability threshold amounts related to professional errors and omissions offered as a condition for entering into a potential contract.
RFPProvide an affirmation that no conflicts of interest exist between the Firm and the organization, its Board of Trustees, members, or management. If a conflict of interest does exist, describe the conflict.
RFPProvide a description of the Firm's internal control structure, design, and security to protect the organization's data from unauthorized use or access.
RFPList and describe any professional relationship the Firm or any of its consulting group staff have with any member of the organization's Board of Trustees, and state the number of client relationships key personnel are currently involved with and type of service request.
RFPProvide a copy of your company's standard professional services contract and indicate if there are any terms in the contract that are not negotiable.
RFPComplete and submit the Third Party Cybersecurity Questionnaire.
RFPUpon request, promptly provide copies of information security policies covering data classification, security training/awareness, systems administration/patching/configuration, application development/code review, incident response, disaster recovery/business continuity, data/system backup, and compliance with information security/privacy laws, regulations, or standards.
RFPAre there any indemnity provisions (in the contract) that protect the university from any liability arising from a loss of sensitive information?
RFPIs your secure gateway environment certified by an authoritative third party, and if so, who?
RFPHas a security audit been performed to any of the following standards: PCI-DSS, CIS Security Benchmarks, ISO 27001/2, NIST 800-12, AICPA SOC 2 Type II, or other? What are the results of the audit? Please include a copy of the external attestation.
RFPWhat were the findings of your most recent security audit? Date performed?
RFPComplete answers to the HECVAT (Higher Education Community Vendor Assessment Toolkit).
RFPVendor will complete one of the following audits at least annually and immediately after any actual or reasonably suspected Security Incident: SOC 2 Type II, SOC for Cybersecurity, or an accepted Higher Education Community Vendor Assessment Toolkit (HECVAT); evidence must be provided to the University prior to the Agreement and at least annually thereafter.
RFPVendor's Technology Professional Liability Errors & Omissions policy must include Cyber Risk coverage and Computer Security and Privacy Liability coverage with a limit of no less than $2,000,000 per occurrence and $4,000,000 in the aggregate.
RFPIf Vendor is processing credit/debit card transactions on behalf of University, comply with PCI DSS, PA-DSS, and PCI PTS at all times, providing annual attestation of compliance (Attestation of Compliance for Onsite Assessments – Service Providers, and PCI Report on Compliance cover letter).
RFIDoes the vendor have a current Cyber Security SOC2 certification? If not, please explain why.
RFIDoes the vendor maintain Cyber Security insurance? What are those liability thresholds for each deployed solution?
RFIWhat industry standard frameworks does the vendor use to maintain solution security?
RFIVendor shall operate an information security program designed to meet confidentiality, integrity, and availability (CIA) requirements, including a documented Information Security Policy communicated to employees, an accountable named point of contact for the program, and a formal risk assessment process to identify and mitigate security risks.