10207 Appendix A - Requirements.xlsx

XLSX spreadsheet 29 KB Posted

Attached to
Transit Passenger Counting System State and local contract opportunity
Solicitation number
10207
Issued by
Larimer County, Colorado

About this file

This document is an Excel-based Requirements Appendix for the City of Fort Collins Transfort Bus Division, seeking a replacement passenger counting system for their 60-bus fleet before their current system sunsets in Summer 2026. The procurement involves a comprehensive request for a new Automatic Passenger Counting (APC) system with detailed functional and non-functional requirements across multiple categories including data processing, manual data entry, reporting, vehicle compatibility, statistical adjustment, and cybersecurity compliance. The requirements document provides vendors with specific instructions for responding, including guidelines for indicating conformance levels for each requirement and opportunities to explain how their solution meets the specified criteria.

The requirements emphasize critical capabilities such as NTD reporting compliance, data access and ownership, vehicle compatibility with three-door articulated buses, and robust security protocols. Key technical and administrative requirements include the ability to quantify APC performance, support existing APC hardware, provide automated passenger counts at the stop level, and meet stringent data protection standards. The document includes extensive cybersecurity questionnaire sections covering data ownership, protection, location, breach responsibilities, background checks, encryption standards, and requires potential vendors to demonstrate comprehensive security practices, including potential submission of a Cloud Security Alliance CONSENSUS ASSESSMENTS INITIATIVE QUESTIONNAIRE (CAIQ) and possessing certifications like SOC 2 Type 2 and ISO standards.

View the file

Other files for this state and local contract opportunity

Other files attached to Transit Passenger Counting System, newest first.
File Type Posted
Appendix C - Total Cost of Ownership Schedule.xltx XLTX file
RFP 10207 Transit Passenger Counting System Final.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Instructions Vendor Instructions:

Please complete the tab labeled "Requirements." Select a response in Column E titled "Conformance" based on your platform's ability to meet each of the requirements. In Columns F and G, provide additional information about how your product meets each requirement. Vendors are encouraged to provide a comprehensive response for each requirement in order to provide the evaluators with adequate information to evaluate the solution.

If meeting a requirement will entail modifications that require additional costs, please indicate those in your Vendor Response Comments. If no cost is indicated, the contract will indicate that the vendor will provide this modification for free.

Please do not change any values in columns other than E, F, and G.Requirement ConformanceDescription
Out-of-the-BoxThe solution meets the requirement as is, “out-of-the-box” functionality with no configuration or custom programming/coding.
With ConfigurationThe solution can meet the requirement by arranging the functional parameters that are already inherent in the product – and not by changing the product’s source code – so that it functions in a way that meets the City’s specific business needs.
Planned ReleaseThe current version of the solution cannot meet the requirement “Out of the Box” or “With Configuration,” but will be able to with a release that's on your current roadmap for release within one year.
With Custom ProgrammingThe solution can meet the requirement only by modifying the product’s source code (changing or adding new code) to enable it to do what it was not originally able to do.
Cannot MeetThe product cannot meet the requirement Out-of-the-box, with configuration, with a planned release, or with custom programming.
PriorityDescription
Must haveAn essential component of the solution we seek
Should haveAn important component of the solution we seek
Could haveFeature we would find helpful but not necessary

Requirements

ATTACHMENT A
IDPriorityCriterionDescriptionConformanceProduct/ModuleVendor Response Comments
Functional Requirements

<Please use this space to note what product/module of the solution is required to address the requirement.> <Please use this space to expand on your response and/or reference supporting documentation (e.g. file attachments, online information, etc.) on how your solution meets the requirement. Please clearly indicate whether your solution would entail additional costs.>

<Note: If your solution only partially meets the requirement, please indicate clearly and specifically the elements of the requirement it does not meet.>

Operation
Must haveAccess and permissionsEasy assignment of users to roles and groups and delegation of permissions/access to those roles or groups - describe
Could haveCapabilityLive passenger count to be available in current CAD system.
Must haveCapabilityMust support currently installed APC hardware.
Must haveData ProcessingAbility to identify and articulate business rules for data processing (eg discard when trip has more timepoints than in pattern, load balancing)
Should haveData ProcessingAbility to customize business rules for data processing and preview what impact changes might have to ridership
Must haveManual Data EntryAbility to enter ridership data from manual tally on the road (preferably via mobile device and not paper) when APC unavailable
Must haveManual Data EntryAbillity to enter ridership data from manually tally from the office when APC unavailble for a given trip
Must haveAPC TestingAbility to quanitfy APC performance via comparison to manual ridecheckers
Should haveNTD ReportingClear analog to NTD required ridership reports for S10
Must haveAPC CertificationAbility to satisfy criteria for NTD APC Certification in a timely and accurate manner
Must haveReportingAutomatic and accurate passenger counts for fixed route services, attributing boarding and alignhting at the stop level
Must haveVehicle CompatibilityCompatability with all vehicles in fleet, including three door articulated buses
Must haveStatistical AdjustmentAbility to adjust ridership data via stastical rules in the case of missing data
Must haveData AccessAbility to query both unadjusted, adjusted and statistically factored data to understand differences in reporting modes
Must haveData AccessAbility to bring data in to city owned servers in order to integrate into our reporting stacks, speicifcally Microsoft environment and tools
Must haveData Quality and TroubleshootingMeans of detecting and monitoring errors within the system, both in hardware and software
Should haveWarningsAutomated warnings for errors/failures within the system to be sent to relevant parties for troubleshooting
Administration
Should haveAccess and permissionsCapability to maintain visitor profiles and registration information
SaaS Cyber QuestionnaireVisitor Responsiveness
Must AnswerData OwnershipThe City of Fort Collins will own all rights, title and interest in its data that is related to the services provided. All data obtained by the vendor regarding the performance of these services shall become and remain the property of the City. The vendor will not share or distribute any City data to any other entity without the City's written consent. Can you comply with this?
Must AnswerData ProtectionDescribe how you safeguard the confidentiality, integrity, and availability of City information, including encryption of personal data in transit and at rest, and access control. Do you have a privacy and security policy, and does the policy apply to customers’ private data including personal identifiable information?
Must AnswerData destructionWhat procedures and safeguards does the vendor have in place for sanitizing and disposing of City data according to prescribed retention schedules or following the conclusion of a project or termination of a contract to render it unrecoverable and prevent accidental and/or unauthorized access to City data?
Must AnswerData LocationAre the data centers where City data may be stored or processed located exclusively in the United States? Do you allow your personnel or contractors to store City data on portable devices? Do your personnel and contractors access City data remotely?
Must AnswerSecurity Incidents or Data BreachesDescribe your data breach and incident response communication plans. Has the company experienced any security breaches? If yes, explain.
Must AnswerBreach ResponsibilitiesIn addition to data breach communication, what additional responsibilities do you have to your customers in the event of a data breach involving private data that is in your control, or in the control of your contractors/subsidiaries, at the time of breach? Do you have cybersecurity insurance? If yes, provide an overview of the coverage.
Must AnswerBackground ChecksDo you conduct criminal background checks on all staff, including subcontractors? Do you employ people convicted of any crime of dishonesty?
Must AnswerAccess to Security Logs and ReportsThe vendor shall provide reports to the City in a format specified in the SLA agreed to by the vendor and the City. Reports shall include latency statistics, user access, user access IP address, user access history and security logs for all City files related to this contract. Can you comply with this?
Must AnswerRisk Assessments and AuditsDo you conduct periodic risk assessments to identify cybersecurity threats, vulnerabilities, and potential business consequences? Do you have regular independent assessments of your cybersecurity processes? Do you perform independent audits of your data center? How often? What level of audit is performed (e.g., SOC2)? Would you be willing to share redacted versions of your most recent risk assessment and audit report with the City?
Must AnswerChange Control and Advance NoticeHow do you communicate upgrades (e.g., major upgrades, minor upgrades, system changes) that may impact service availability and performance to your customers?
Must AnswerUpgradesAre technology systems (e.g., servers, network devices, operating systems, applications, malware definitions) regularly updated/patched? Do you have any systems in production that are past end of life or that can no longer be patched?
Must AnswerNon-disclosure and Separation of DutiesDescribe how you enforce separation of job duties and limit staff knowledge of City data to that which is necessary to perform job duties.
Must AnswerImport and Export of DataDescribe the data import and export processes from the customer’s perspective.
Must AnswerSubcontractor DisclosureIdentify all your strategic business partners related to services provided under this arrangement, including but not limited to all subcontractors or other entities or individuals who may be a party to a joint venture or similar agreement with the you, and who shall be involved in any application development and/or operations.
Must AnswerRight to Remove IndividualsThe City shall have the right at any time to require that the vendor remove from interaction with the City any vendor representative who the City believes is detrimental to its working relationship with the vendor. Can you comply with this?
Must AnswerEncryption of Data at RestCan you ensure hard drive encryption consistent with validated cryptography standards as referenced in FIPS 140-2, Security Requirements for Cryptographic Modules for all personal data?
Must AnswerInternet-Facing SecurityWe may use BitSight (like a credit report for cyber security) to assess your internet-facing security. Do you subscribe to BitSight or a similar service, and if so, are you willing to provide a sanitized report?
Must AnswerService InterruptionIn the event of an interruption of your service, what is your process for notifying customer operations of the circumstances of the interruption or outage and the expected recovery time?
Must AnswerBackup and RecoveryWhat is your backup & recovery SLA? What are the actual results/metrics vs. the SLA for the last 12 months? Is your backup data encrypted and, if so, to what standard?
Must AnswerAuthenticationDo you have an internal password policy? Do you have complexity or length requirements for passwords? Can employees/contractors remotely connect to your production systems? (i.e., VPN. Is multi-factor authentication available? Do you require MFA for administration of your service (local or remote)? Do you support SSO/SAML ADFS for customer access?
Must AnswerCyber InsuranceDoes your firm carry cyber insurance? If so, what are your insurance levels?
Must AnswerCAIQ QuestionnaireLack of security control transparency is a leading inhibitor to the adoption of cloud services. As part of the City of Fort Collin’s Information Security program we are requesting that all our Cloud Service Providers complete and submit the Cloud Security Alliance (CSA) CONSENSUS ASSESSMENTS INITIATIVE QUESTIONNAIRE (CAIQ). This will enable Utilities to have greater confidence that the information is being appropriately protected, and that processes are in place for appropriate action to be taken where any areas of concern emerge.

The City will request that the Vendor of Choice complete the CAIQ to assess the maturity of policies, systems and controls that are in place related to services you provide. The questionnaire is available here or www.cloudsecurityalliance.org. The question set was developed by CSA in partnership with industry groups to provide an agreed question set that can be used across the supply chain and is focused on providing industry-accepted ways to document what security controls exist in IaaS, PaaS, and SaaS offerings, providing greater security control transparency. Describe Vendor familiarity with the CAIQ questionnaire.

Answer: Samsara has a SOC 2 type 2 report alongside ISO 27001, 27017, 27018, and 27701 certifications. See security.samsara.com to access attestation documents and certifications.

Nonfunctional requirements
Usability
Should haveAdditional featuresStraightforward user interface that can be leveraged by multiple kinds of users in the organization
Should haveRecord RetentionAbility to retain records for a minimum of 3 years, preferably longer
Security
Must haveAudit capabilitiesAbility to provide an audit/audit-trail capture capabilities for transactional logging, including login and unique user credentials
Performance
Must haveAvailabilityDescribe any platform uptime guarantees and your ability to perform required system maintenance in a timely fashion
Must haveResponsivenessDescribe any service-level agreement (SLA) guarantees
Training and Support
Must haveDocumentationDetailed documentation provided, included all documentation necessary to use and maintain the new solution

File details come from the government source that posted it. Updated .