10207 Appendix A - Requirements.xlsx
XLSX spreadsheet 29 KB Posted
- Attached to
- Transit Passenger Counting System State and local contract opportunity
- Solicitation number
- 10207
- Issued by
- Larimer County, Colorado
About this file
This document is an Excel-based Requirements Appendix for the City of Fort Collins Transfort Bus Division, seeking a replacement passenger counting system for their 60-bus fleet before their current system sunsets in Summer 2026. The procurement involves a comprehensive request for a new Automatic Passenger Counting (APC) system with detailed functional and non-functional requirements across multiple categories including data processing, manual data entry, reporting, vehicle compatibility, statistical adjustment, and cybersecurity compliance. The requirements document provides vendors with specific instructions for responding, including guidelines for indicating conformance levels for each requirement and opportunities to explain how their solution meets the specified criteria.
The requirements emphasize critical capabilities such as NTD reporting compliance, data access and ownership, vehicle compatibility with three-door articulated buses, and robust security protocols. Key technical and administrative requirements include the ability to quantify APC performance, support existing APC hardware, provide automated passenger counts at the stop level, and meet stringent data protection standards. The document includes extensive cybersecurity questionnaire sections covering data ownership, protection, location, breach responsibilities, background checks, encryption standards, and requires potential vendors to demonstrate comprehensive security practices, including potential submission of a Cloud Security Alliance CONSENSUS ASSESSMENTS INITIATIVE QUESTIONNAIRE (CAIQ) and possessing certifications like SOC 2 Type 2 and ISO standards.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| Appendix C - Total Cost of Ownership Schedule.xltx | XLTX file | |
| RFP 10207 Transit Passenger Counting System Final.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Instructions Vendor Instructions:
Please complete the tab labeled "Requirements." Select a response in Column E titled "Conformance" based on your platform's ability to meet each of the requirements. In Columns F and G, provide additional information about how your product meets each requirement. Vendors are encouraged to provide a comprehensive response for each requirement in order to provide the evaluators with adequate information to evaluate the solution.
If meeting a requirement will entail modifications that require additional costs, please indicate those in your Vendor Response Comments. If no cost is indicated, the contract will indicate that the vendor will provide this modification for free.
| Please do not change any values in columns other than E, F, and G. | Requirement Conformance | Description | |
| Out-of-the-Box | The solution meets the requirement as is, “out-of-the-box” functionality with no configuration or custom programming/coding. | ||
| With Configuration | The solution can meet the requirement by arranging the functional parameters that are already inherent in the product – and not by changing the product’s source code – so that it functions in a way that meets the City’s specific business needs. | ||
| Planned Release | The current version of the solution cannot meet the requirement “Out of the Box” or “With Configuration,” but will be able to with a release that's on your current roadmap for release within one year. | ||
| With Custom Programming | The solution can meet the requirement only by modifying the product’s source code (changing or adding new code) to enable it to do what it was not originally able to do. | ||
| Cannot Meet | The product cannot meet the requirement Out-of-the-box, with configuration, with a planned release, or with custom programming. |
| Priority | Description |
| Must have | An essential component of the solution we seek |
| Should have | An important component of the solution we seek |
| Could have | Feature we would find helpful but not necessary |
Requirements
| ATTACHMENT A | ||||||
| ID | Priority | Criterion | Description | Conformance | Product/Module | Vendor Response Comments |
| Functional Requirements |
<Please use this space to note what product/module of the solution is required to address the requirement.> <Please use this space to expand on your response and/or reference supporting documentation (e.g. file attachments, online information, etc.) on how your solution meets the requirement. Please clearly indicate whether your solution would entail additional costs.>
<Note: If your solution only partially meets the requirement, please indicate clearly and specifically the elements of the requirement it does not meet.>
| Operation | |||
| Must have | Access and permissions | Easy assignment of users to roles and groups and delegation of permissions/access to those roles or groups - describe | |
| Could have | Capability | Live passenger count to be available in current CAD system. | |
| Must have | Capability | Must support currently installed APC hardware. | |
| Must have | Data Processing | Ability to identify and articulate business rules for data processing (eg discard when trip has more timepoints than in pattern, load balancing) | |
| Should have | Data Processing | Ability to customize business rules for data processing and preview what impact changes might have to ridership | |
| Must have | Manual Data Entry | Ability to enter ridership data from manual tally on the road (preferably via mobile device and not paper) when APC unavailable | |
| Must have | Manual Data Entry | Abillity to enter ridership data from manually tally from the office when APC unavailble for a given trip | |
| Must have | APC Testing | Ability to quanitfy APC performance via comparison to manual ridecheckers | |
| Should have | NTD Reporting | Clear analog to NTD required ridership reports for S10 | |
| Must have | APC Certification | Ability to satisfy criteria for NTD APC Certification in a timely and accurate manner | |
| Must have | Reporting | Automatic and accurate passenger counts for fixed route services, attributing boarding and alignhting at the stop level | |
| Must have | Vehicle Compatibility | Compatability with all vehicles in fleet, including three door articulated buses | |
| Must have | Statistical Adjustment | Ability to adjust ridership data via stastical rules in the case of missing data | |
| Must have | Data Access | Ability to query both unadjusted, adjusted and statistically factored data to understand differences in reporting modes | |
| Must have | Data Access | Ability to bring data in to city owned servers in order to integrate into our reporting stacks, speicifcally Microsoft environment and tools | |
| Must have | Data Quality and Troubleshooting | Means of detecting and monitoring errors within the system, both in hardware and software | |
| Should have | Warnings | Automated warnings for errors/failures within the system to be sent to relevant parties for troubleshooting | |
| Administration | |||
| Should have | Access and permissions | Capability to maintain visitor profiles and registration information | |
| SaaS Cyber Questionnaire | Visitor Responsiveness | ||
| Must Answer | Data Ownership | The City of Fort Collins will own all rights, title and interest in its data that is related to the services provided. All data obtained by the vendor regarding the performance of these services shall become and remain the property of the City. The vendor will not share or distribute any City data to any other entity without the City's written consent. Can you comply with this? | |
| Must Answer | Data Protection | Describe how you safeguard the confidentiality, integrity, and availability of City information, including encryption of personal data in transit and at rest, and access control. Do you have a privacy and security policy, and does the policy apply to customers’ private data including personal identifiable information? | |
| Must Answer | Data destruction | What procedures and safeguards does the vendor have in place for sanitizing and disposing of City data according to prescribed retention schedules or following the conclusion of a project or termination of a contract to render it unrecoverable and prevent accidental and/or unauthorized access to City data? | |
| Must Answer | Data Location | Are the data centers where City data may be stored or processed located exclusively in the United States? Do you allow your personnel or contractors to store City data on portable devices? Do your personnel and contractors access City data remotely? | |
| Must Answer | Security Incidents or Data Breaches | Describe your data breach and incident response communication plans. Has the company experienced any security breaches? If yes, explain. | |
| Must Answer | Breach Responsibilities | In addition to data breach communication, what additional responsibilities do you have to your customers in the event of a data breach involving private data that is in your control, or in the control of your contractors/subsidiaries, at the time of breach? Do you have cybersecurity insurance? If yes, provide an overview of the coverage. | |
| Must Answer | Background Checks | Do you conduct criminal background checks on all staff, including subcontractors? Do you employ people convicted of any crime of dishonesty? | |
| Must Answer | Access to Security Logs and Reports | The vendor shall provide reports to the City in a format specified in the SLA agreed to by the vendor and the City. Reports shall include latency statistics, user access, user access IP address, user access history and security logs for all City files related to this contract. Can you comply with this? | |
| Must Answer | Risk Assessments and Audits | Do you conduct periodic risk assessments to identify cybersecurity threats, vulnerabilities, and potential business consequences? Do you have regular independent assessments of your cybersecurity processes? Do you perform independent audits of your data center? How often? What level of audit is performed (e.g., SOC2)? Would you be willing to share redacted versions of your most recent risk assessment and audit report with the City? | |
| Must Answer | Change Control and Advance Notice | How do you communicate upgrades (e.g., major upgrades, minor upgrades, system changes) that may impact service availability and performance to your customers? | |
| Must Answer | Upgrades | Are technology systems (e.g., servers, network devices, operating systems, applications, malware definitions) regularly updated/patched? Do you have any systems in production that are past end of life or that can no longer be patched? | |
| Must Answer | Non-disclosure and Separation of Duties | Describe how you enforce separation of job duties and limit staff knowledge of City data to that which is necessary to perform job duties. | |
| Must Answer | Import and Export of Data | Describe the data import and export processes from the customer’s perspective. | |
| Must Answer | Subcontractor Disclosure | Identify all your strategic business partners related to services provided under this arrangement, including but not limited to all subcontractors or other entities or individuals who may be a party to a joint venture or similar agreement with the you, and who shall be involved in any application development and/or operations. | |
| Must Answer | Right to Remove Individuals | The City shall have the right at any time to require that the vendor remove from interaction with the City any vendor representative who the City believes is detrimental to its working relationship with the vendor. Can you comply with this? | |
| Must Answer | Encryption of Data at Rest | Can you ensure hard drive encryption consistent with validated cryptography standards as referenced in FIPS 140-2, Security Requirements for Cryptographic Modules for all personal data? | |
| Must Answer | Internet-Facing Security | We may use BitSight (like a credit report for cyber security) to assess your internet-facing security. Do you subscribe to BitSight or a similar service, and if so, are you willing to provide a sanitized report? | |
| Must Answer | Service Interruption | In the event of an interruption of your service, what is your process for notifying customer operations of the circumstances of the interruption or outage and the expected recovery time? | |
| Must Answer | Backup and Recovery | What is your backup & recovery SLA? What are the actual results/metrics vs. the SLA for the last 12 months? Is your backup data encrypted and, if so, to what standard? | |
| Must Answer | Authentication | Do you have an internal password policy? Do you have complexity or length requirements for passwords? Can employees/contractors remotely connect to your production systems? (i.e., VPN. Is multi-factor authentication available? Do you require MFA for administration of your service (local or remote)? Do you support SSO/SAML ADFS for customer access? | |
| Must Answer | Cyber Insurance | Does your firm carry cyber insurance? If so, what are your insurance levels? | |
| Must Answer | CAIQ Questionnaire | Lack of security control transparency is a leading inhibitor to the adoption of cloud services. As part of the City of Fort Collin’s Information Security program we are requesting that all our Cloud Service Providers complete and submit the Cloud Security Alliance (CSA) CONSENSUS ASSESSMENTS INITIATIVE QUESTIONNAIRE (CAIQ). This will enable Utilities to have greater confidence that the information is being appropriately protected, and that processes are in place for appropriate action to be taken where any areas of concern emerge. |
The City will request that the Vendor of Choice complete the CAIQ to assess the maturity of policies, systems and controls that are in place related to services you provide. The questionnaire is available here or www.cloudsecurityalliance.org. The question set was developed by CSA in partnership with industry groups to provide an agreed question set that can be used across the supply chain and is focused on providing industry-accepted ways to document what security controls exist in IaaS, PaaS, and SaaS offerings, providing greater security control transparency. Describe Vendor familiarity with the CAIQ questionnaire.
Answer: Samsara has a SOC 2 type 2 report alongside ISO 27001, 27017, 27018, and 27701 certifications. See security.samsara.com to access attestation documents and certifications.
| Nonfunctional requirements | |||
| Usability | |||
| Should have | Additional features | Straightforward user interface that can be leveraged by multiple kinds of users in the organization | |
| Should have | Record Retention | Ability to retain records for a minimum of 3 years, preferably longer | |
| Security | |||
| Must have | Audit capabilities | Ability to provide an audit/audit-trail capture capabilities for transactional logging, including login and unique user credentials | |
| Performance | |||
| Must have | Availability | Describe any platform uptime guarantees and your ability to perform required system maintenance in a timely fashion | |
| Must have | Responsiveness | Describe any service-level agreement (SLA) guarantees | |
| Training and Support | |||
| Must have | Documentation | Detailed documentation provided, included all documentation necessary to use and maintain the new solution |
File details come from the government source that posted it. Updated .