11-Attachment 1 - Technology Profiles and Additional Requirements.pdf
PDF 198 KB Posted
- Attached to
- Recreation Management System State and local contract opportunity
- Solicitation number
- RFP 2000004237
- Issued by
- Fairfax County, Virginia
About this file
This is a Technology Profiles and Additional Requirements attachment for RFP 2000004237 issued by Fairfax County, Virginia, for a recreation management system to be utilized by the Fairfax County Park Authority (FCPA) and the Department of Neighborhood and Community Services (NCS). The proposed solution must be delivered as a complete enterprise system encompassing core software, database, bolt-ons, interfaces, and reporting tools, with the contractor responsible for all integration between proposed products. The solution must operate as a modern web-based application accessible on any mobile device operating system, interface with the County's Geographic Information System (GIS), public website, and SAP-based enterprise resource planning system (FOCUS), and be capable of 24/7/365 availability with scalability and appropriate maintenance windows. The County's Department of Information Technology (DIT) will direct methodology and design for all required interfaces, with the DIT Director serving as the Chief Technology Officer and maintaining authority over strategic technology investments and county-wide deployment. The Architecture Review Board (ARB) will provide technical review and sign-off of solution designs, and all offerors must specifically disclose any deviations from documented standards and desired architectures and provide approaches for integrating non-standard components.
The County anticipates the solution will be implemented across six separate computing environments (sandbox, development, testing, training, acceptance, and production) with duplicate servers and workstations unless virtual machine technology is preferred. All proposed solutions must comply with Fairfax County Information Technology Security Policy, federal and Virginia laws regarding Personally Identifiable Information (PII), Payment Card Industry (PCI) compliance, and Americans with Disabilities Act (ADA) requirements. Contractor personnel are subject to monitoring by the County IT Security Office, and any personnel breaching IT Security Policy are subject to automatic removal. All County data remains the sole property of the County, with full access to tools and capabilities required; source code reverts to the County in cases of contractor bankruptcy, merger, or acquisition. If the solution is hosted outside the County's network, the County requires 24/7 access to all data and business records, and the contractor must develop and maintain an approved Business Continuity and Disaster Recovery plan capable of seamless failover and active-active functionality, with the County maintaining direct access to inspect host and co-location sites.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| 8-Attachment 5 - RFP-2000004237-iso systemSecurityMatrix.pdf | ||
| 5-Attachment 3 - Implementation and Training Plan Elements.pdf | ||
| 7-Recreation Management RFP 2000004237.pdf | ||
| 6-Attachment 8 -RFP 2000004237- Cost Proposal Template.xlsx | XLSX spreadsheet | |
| 4-DPMM Cover.pdf | ||
| 1-Attachment 6 - AI Questionnaire.pdf | ||
| 9-Attachment 2 - RFP 2000004237- Requirements Workbook.xlsx | XLSX spreadsheet | |
| 2-Attachment 4 - SLA Elements.pdf | ||
| 10-Attachments A1 through A9.pdf | ||
| 3-Attachment 7 -RFP-2000004237- form ITConsultantAgreement.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
RFP 2000004237
Attachment-1
1. TECHNOLOGY PROFILES AND ADDITIONAL REQUIREMENTS
1.1. Fairfax County Information Technology Profile and Requirements:
1.1.1. The Solution proposed for meeting the requirements of this solicitation must be proposed in entirety to include core software, database, bolt-ons, interfaces and reporting tool. The Offeror will be responsible for any integration between its proposed products. The County will direct methodology and design for interfaces required to existing County applications associated with the functional and technical requirements of this project. It is anticipated that the Solution will use a modern web-based application architecture, be operational out of the box on any mobile device OS, produce reports and data analytics as required in the functional specifications, and be capable of interface with the County’s GIS, public website and SAP-based enterprise resource planning (ERP) system referred to as the Fairfax County Unified System (FOCUS). Information about Fairfax County IT Projects, Standards, environments and platforms can be found in the Information Technology Plan, https://www.fairfaxcounty.gov/informationtechnology/it-plan
1.1.2. Fairfax County IT Management Overview – The Department of Information
Technology (DIT) is the County’s central IT agency that establishes standards and architecture for information and communication systems for all County agencies. DIT provides leadership, process, governance, resources, and expertise in deploying information technology, and provides technology infrastructure, and designs, develops, implements and maintains enterprise-wide and agencies’ specific applications. The Director of DIT is also the County's Chief Technology Officer (CTO) and has authority for strategic leadership for technology investments, and direction in deployment of technology county-wide, and oversees implementation of policy and IT projects. DIT has a Project Management Office that works with all agencies’ Project Managers (PM) in reviewing project plans for performance and scope, and approving project expenditures. DIT assigns a technical PM who is responsible for working with project System Integrators (SI) on the technical implementation processes.
1.1.3. The County prefers that IT solutions use industry standards out-of-the-box, including contemporary best practices for solution architecture, configurability, integration, user access and data security; be available 24x7x365; are scalable and meet reasonable performance requirements; and allow for appropriate maintenance windows.
1.1.4. If the solution will be a custom build by an SI, then DIT will specify the standard for the build and the solution underlying infrastructure.
1.1.5. If the solution is a commercial licensed software product, it is expected that the solution delivered is based on its manufacture specifications and not manipulated outside its developed architecture and development standards. The solution design should recommend the hardware and database environment that ensures optimal performance, supportability and reliability.
1.1.6. If the Solution is hosted outside the County’s IT environment, such as a subscription service, the provider must adhere to County IT Security standards for data security and privacy and user access from the county’s local and remote network. DIT will specify remote access specifications.
1.2. County Networking Environment:
1.2.1. The County’s technology architecture is a tactical asset that defines technology components necessary to support business operations and the infrastructure required for implementation of technologies in response to the changing needs of government business and industry evolution. It is a multi-layered architecture that includes:
• Application and Data Architectures,
• Platform Architecture,
• Network Architecture,
• Internet Architecture, and
• Security Architecture.
1.2.2. More information about the County’s enterprise architecture is available in the Information Technology Plan, published by the County DIT, at
1.3. Information System Requirements:
1.3.1. Information systems delivery and management is governed by the Architecture Review
Board ( A R B ) and other program specific committees that are chartered to manage scope and functionality delivery issues, and advise and/or direct development efforts and promote conformance to a variety of standards, including but not limited, to those in the Information Technology Plan, https://www.fairfaxcounty.gov/informationtechnology/it-plan. The DIT ARB provides technical review and sign-off of Solution designs.
1.3.2. In general, solutions that are installed on premises at Fairfax County use industry standards and must meet the following requirements, which are described in the Information Technology Plan, https://www.fairfaxcounty.gov/informationtechnology/it-plan:
• Enterprise Architecture and Standards,
• Application Platforms and Architecture, and
• Database and Operating Systems.
1.3.3. Deviations: Deviations from the architecture and standards may become a barrier to the sustainability of the County’s integration and interoperability posture and may be subject to further review. All Offerors must specifically disclose all aspects of the proposed solution which deviate from the documented standards and desired architectures, and provide approaches for consideration about the manner in which non-standard components may be integrated.
1.3.4. Graphical User Interfaces: The County has standard templates that are required for its websites to have maximum consistency across applications and content.
Any hosted applications and some COTS applications should be able to present through the County template or simulation for County brand and identity.
Alternatives to using these templates must be arranged through the County DIT.
1.4. IT/Cyber Security:
1.4.1. All solution components must meet Information Security practices as described in the Fairfax County Information Technology Security Policy:
https://www.fairfaxcounty.gov/informationtechnology/sites/informationtechnology/file s/assets/security/pm70-05_01.pdf.
https://www.fairfaxcounty.gov/informationtechnology/it-plan https://www.fairfaxcounty.gov/informationtechnology/it-plan https://www.fairfaxcounty.gov/informationtechnology/it-plan https://www.fairfaxcounty.gov/informationtechnology/it-plan https://www.fairfaxcounty.gov/informationtechnology/sites/informationtechnology/files/assets/security/pm70-05_01.pdf https://www.fairfaxcounty.gov/informationtechnology/sites/informationtechnology/files/assets/security/pm70-05_01.pdf
1.4.2. Offerors must include in their proposals a complete Fairfax County Project Proposal Matrix for Meeting Information Technology Security Policy Requirements (Attachment H).
1.4.3. The solution as implemented must be compliant with all federal and Virginia laws and regulations governing the access, use and management of Personally Identifiable Information (PII), Payment Card Industry (PCI) compliant and meet Americans with Disabilities Act (ADA) requirements.
1.4.4. Offerors must include in their proposals the completed Attachment J: Fairfax County IT Services Provider Consultant/Contractor Agreement, for the firm and its personnel that have roles in the implementation and management of the solution implementation and post implementation maintenance and support, as applicable.
This requirement is non-negotiable.
1.4.5. Contractor personnel are subject to monitoring by the County IT Security Office (ISO), and any person of the Contractor or its subcontractors or representatives that breach IT Security Policy and/or ethics are automatically removed from the engagement.
1.4.6. Sensitive and Confidential Information: Sensitive or Confidential information may not be removed from Fairfax County premises unless the information’s owner has approved such removal in advance. This includes, but is not limited to, portable computer hard disks, portable memory devices (including USB drives), tape cartridges, and paper documents containing sensitive or confidential information.
This paragraph does not apply to authorized off-site backups which are in encrypted form.
1.4.7. Authorized Tools and Programs: Except as otherwise expressly authorized by DIT/ISO, users shall not download, install or run security programs or utilities that reveal weaknesses in the security of a system. For example, Fairfax County users shall not run password cracking programs, network reconnaissance/discovery software/applications, key loggers, packet sniffers, network mapping tools, port scanners or any other non-approved programs while connected in any manner to the Fairfax County network infrastructure.
1.4.8. Remote Access: Authorized users accessing the County’s network remotely shall abide by security policies and procedures to protect the County's equipment, data, and network access as if they were working on premises.
1.4.8.1. Remote access is a service provided by the County and shall be used for authorized business purposes only. To this end, management shall approve every request for remote access.
1.4.8.2. Remote access to the Fairfax County network shall be done using the DIT provided or supported services that are approved by the Information Security Office.
1.4.8.3. Agencies or individuals who wish to implement non-standard Remote Access solutions to the Fairfax County production network shall obtain prior approval from DIT and the Information Security Office.
1.4.8.4. Secure remote access shall be strictly controlled. Control will be enforced via remote access authentication using security tokens that provide one-time password authentication or public/private keys with strong pass-phrases. Furthermore, users may not share passwords or access devices to permit others onto the County network.
1.4.8.5. Remote Access control will be enforced via network and system level auditing. This information will be readily available for monitoring and review by appropriate personnel.
1.4.8.6. External access to and from information systems shall meet Fairfax County remote access standards and guidelines.
1.4.8.7. Fairfax County employees and Contractors with remote access privileges shall ensure that their County-owned or personal computer or workstation, which is remotely connected to Fairfax County’s network, is not connected to any other network at the same time, with the exception of personal networks that are under the complete control of the user.
1.4.8.8. Reconfiguration of a home user’s equipment for the purpose of split-tunneling or dual homing is not permitted.
1.4.8.9. All hosts that are connected to Fairfax County internal networks via remote access technologies shall use the most up-to-date anti-virus software.
1.4.8.10. By using remote access technology with personal equipment, users shall understand that their machines are a de facto extension of Fairfax County’s network, and as such are subject to the same standards that apply to County-owned equipment; therefore, their machines shall be configured to comply with Fairfax County policies and DIT standards for anti-virus software and patch management.
1.4.8.11. Employees and Contractors with remote access shall provide their IP address (if using cable or DSL) to the Information Security Office and implement DIT defined security standards on their home systems, which include, but are not limited to, anti- virus software and firewalls.
Periodic scans will be made against these addresses to ensure proper security measures are in place. Violators will have their remote access privileges revoked.
1.4.8.12. The County monitors its networks and systems for security violations.
Users agree to this monitoring when they use the service.
1.4.8.13. The link shall be encrypted whenever a computer network connection is established between a County computer and another computer at a location outside an official Fairfax County office, and whenever this connection transmits, or is likely to transmit sensitive information.
12.5 Ownership of and Access to Data, Source Code:
12.5.1 All County data is and must remain the sole property of the County. Therefore, all tools and capabilities native to the Offeror’s solution should be available to the County to allow for full access to that data. All tables, layouts, queries, stored procedures, XML schema and other content developed to support the operation of a database and/or County applications in the Fairfax environment become the property of the County, and shall be available to the appropriate County personnel as needed and upon request.
12.5.2 Source code shall revert to the County if the Contractor files for bankruptcy or protection from creditors in a court of law. The County shall have full rights to use source code for any purposes other than resale. The same applies if the Contractor is merged or acquired and the software is no longer supported. Software source code will be updated to reflect the most current version of the software source code materials including all adjustments and configuration made for Fairfax County.
12.5.3 Once contract is awarded, Contractor must provide documentation about schemas or database table organization at a level of detail that enables report writers to navigate and extract all information necessary to produce ad hoc reports.
12.5.4 All source code developed under a given task order must remain the sole property of the County. Contractor may request permission to re-use portions of the code written by their staff, however, this request must be made in writing to the Fairfax County Department of Procurement and Material Management for review and approval.
12.5.5 The above is not meant to include proprietary programs, tools or other intellectual property. However, such claim to proprietary content cannot intrude on the County’s right to access its data without undue interference or additional cost.
12.5.6 Data owned by Fairfax County may not be used by the Contractor for any purposes without the express written consent of the appropriate County representative. Data covered under specific federal, state and local privacy laws are confidential. Any breach of privacy is cause for termination of contract.
12.5.7 Data Access (Off-Premise): If the solution is hosted outside the County’s network the
County requires 24/7 access to all data and all communications, transactions, and all other records of business concerning the software in relation to the agencies that utilize and/or access HCSIS.
12.6 Standard County Data:
12.6.1 Certain elements are standardized in format and content to enable enterprise-wide data usability, coordination of services, analysis, and public safety. New systems that use any of these elements are required to meet these requirements and any deviation from the standard must be documented and approved by the CTO.
12.7 Interoperability:
12.7.1 The County is pursuing each of these three types of interoperability in the venues where most suited:
12.7.1.1 Application Level Interoperability: Agencies or organizations use the same application to perform the same business functions. Shared applications are useful if the application is built specifically with that purpose in mind.
12.7.1.2 Data Level Interoperability: Agencies or organizations use standards-based technologies to share specific data elements in specific ways.
12.7.1.3 Portal Level Interoperability: Portals enable communities of interest (both citizen constituents and business development community) to share data that is of relevance to each through a common interface or portal.
Portal level interoperability provides the option to offer several services via a single intuitive and customer-centric portal and to address multiple communities of interest. Portals bring streams of data to particular communities of interest and enable filtering, chat functions and other tools and capabilities to be used against the data stream.
Portal level interoperability relies on standards-based data level interoperability. There will also be a robust portal for County staff to access and utilize the solution.
12.8 Hardware Requirements:
12.8.1 If the proposed solution will be implemented and hosted at the County, all hardware must be specified. If components of the proposed solution deviate from this requirement, please specify in the technical proposal for consideration.
12.8.2 The County may require up to six separate computing environments, with the ability to run concurrently, for sandbox, development, testing, training, acceptance, and production. To ensure that each environment is technically equivalent, duplicate servers and workstations as specified below shall be utilized except where virtual machine technology is preferred by the County. The County will work with the Contractor to duplicate or approximate other relevant environmental considerations such as the network and system loading to ensure realistic testing scenarios are facilitated.
12.8.3 System hardware requirements should be listed in detail to include make and model required for the full implementation of the application. All hardware components must be sized appropriately to ensure that the performance requirements of the Contractor’s application will be met. Equipment specifications provided by the County within this RFP shall be considered as minimal requirements. Deviations for hardware proposed will be finalized during final design stages of the project.
12.8.4 The County maintains a four-year replacement program for workstations and a four-year replacement program for servers and associated ancillary equipment. The Contractor shall prepare technology refreshment specifications and costs for installed hardware currently under maintenance agreement every four years or when requested. If the proposed refresh is accepted in whole or part, the Contractor shall install and support the identified equipment through the warranty and subsequent maintenance periods.
12.9 Disaster Recovery/Continuity of Operations:
12.9.1 Regardless of the architecture of its systems, the Contractor shall have developed and be continually ready to invoke a Business Continuity and Disaster Recovery (“BC-DR”) plan that at a minimum addresses the following scenarios: (i) The central computer installation and resident software are destroyed or damaged, (ii) System interruption or failure resulting from network, operating hardware, software, or operational errors that compromises the integrity of transactions that are active in a live system at the time of the outage, (iii) System interruption or failure resulting from network, operating hardware, software or operational errors that compromises the integrity of data maintained in a live or archival system, (iv) System interruption or failure resulting from network, operating hardware, software or operational errors that does not compromise the integrity of transactions or data maintained in a live or archival system but does prevent access to the system, i.e., causes unscheduled system unavailability. The BC-DR plan shall account for and be in effect during the entire period beginning with project kickoff and ending with the end of any turnover period. This BC-DR plan must be prior approved by the County.
12.9.2 Fairfax County operates a contemporary near real-time co-location site for county applications and data off-site. The solution proposed must be able to seamlessly fail-over and be active-active. If components of the solution proposed are a subscription service hosted by the Offeror or third-party data-center, the Offeror must include provision and description of its DR site and procedures. Fairfax County must have direct access to inspect the host and co-location sites.
12.9.3 The Contractor’s Disaster Recovery plan should document the processes necessary to respond to system disruption or a disaster that would affect the system.
12.9.4 The Contractor’s Disaster Recovery plan shall identify the activities, resources, and procedures needed to carry out processing requirements for a prolonged period of time.
File details come from the government source that posted it. Updated .