4-6594 RFP - Attachment 3 - Rated Criteria.xlsx

XLSX spreadsheet 64 KB Posted

Attached to
Modern Intranet Packaged Solution State and local contract opportunity
Solicitation number
PEIG-6594
Issued by
Puerto Rico

About this file

This document is a detailed Request for Proposals (RFP) from the Province of Prince Edward Island (PEI) for a Modern Intranet Packaged Solution. The RFP seeks a comprehensive intranet system that will serve as a work hub supporting various human resource arrangements and workplace productivity tools. The solution must provide robust content management, workflow capabilities, employee communication features, and integration with existing government systems. The proposal requires extensive technical documentation covering areas such as system architecture, security protocols, data migration, backup and recovery strategies, and compliance with Canadian data residency and privacy regulations.

The RFP outlines stringent technical requirements including mandatory criteria such as data remaining in Canadian data centers, anti-spam controls, responsive design, customizable access controls, and multi-factor authentication. Vendors must provide detailed responses across multiple evaluation categories including performance metrics, security certifications, physical and information security controls, disaster recovery plans, and exit strategies. The comprehensive evaluation will assess not just technical capabilities, but also vendor expertise, project implementation approach, operational support plans, and added value propositions. While specific budget details are not explicitly stated, the RFP suggests a multi-year contract with potential for ongoing support and system evolution, emphasizing the government's commitment to a robust, adaptable intranet solution.

View the file

Other files for this state and local contract opportunity

Other files attached to Modern Intranet Packaged Solution, newest first.
File Type Posted
1-6594 RFP - Modern Intranet Packaged Solution.pdf PDF
2-6594 RFP - Attachment 1 - Privacy, Security and Confidentiality Agreement (PSCA).pdf PDF
3-6594 RFP - Attachment 2 - Submission Form.xlsx XLSX spreadsheet
5-6594 RFP - Attachment 4 - Financial Response.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Summary

On-PremCloudBDO (Cloud)New Rocket (Cloud)GoldNET (On-Prem)Solutions Metrix (Cloud)Solutions Metrix (On-Prem)
D.3.2 Technical Questions (Schedule B)15.015.0ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!
1. Proponent information10.91.00.7ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!
2. Solution Information10.91.00.7ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!
3. Exit Strategy00.03.02.2ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!
4. Backup & Recovery21.72.01.5ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!
5. Maintenance & Updates32.63.02.2ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!
6. Data migration & Integration21.72.01.5ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!
7. Security32.63.02.2ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!
8. Contract & Support21.72.01.5ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!
9. Information / Data21.72.01.5ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!
10. Network10.91.00.7ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!
11. Implementation0.10.10.10.1ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!
12. Pricing0.10.10.10.1ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!ERROR:#REF!

Mandatory Requirements

E.3.1 Mandatory Requirements
Refer to Appendix E - Section E.3.1 Mandatory Requirements of the RFP for instructions.StatusVendor Comments
Mandatory Solution Requirements
RequirementFully/Partially/Non -CompliantProvide details supporting your compliancy status
Can each business unit have ownership and control over content within their area, but with a workflow to review and approve new pages for quality? If yes, please describe the process.-
Does the product integrate with common workplace productivity tools? If yes, please list.-
Does the product provide tools for usability optimization and monitoring?

- how staff access the site

- frequency posts are viewed

- frequency content is viewed

- frequency forms are accessed and submitted

- frequency search terms

- time spent on site-
Does the product include a content life cycle mechanism to identify content owners, identify stale content, and notify content owners when updates or removal is recommended?-
Does the product support in-office, remote, and hybrid employees? If yes, provide details on how this is achieved.-

Mandatory Technical Requirements

ItemMandatory CriteriaFully/Partially/Non -CompliantProvide details supporting your compliancy status
1Data collected by the proposed solution must remain in Canada for the duration of contract.

Provide the name(s) of the data center(s) being proposed for this solution.

In your supporting details, provide the name of the data center and its location.-
2The proposed solution is a fully-hosted cloud-based solution that offers on-demand, self-service-
3All data collected through the proposed solutions is owned and controlled by the Government of PEI.-
4The proposed solution must provide Anti-spam controls that meet Canadian Anti-Spam Legislation (CASL).-
5The Solution must have a responsive design approach that can address a range of devices and device sizes and enable automatic adaptation to the screen, whether the content is viewed on a tablet or phone.-
6The proposed solution must support customizable auto logoff functionality for inactive and idle users.-
7If the solution includes a database, the proposed tool must have a process to identify all sensitive data in the production database and to mask/randomize that data in all non-production databases.-
8The proposed solution must provide direct access to reporting data sets that are required by the Government of PEI for direct data consumption using in-house reporting software tools. Reference the Confidential Standards and Technical Information document for additional details.-
9The Solution must have the ability to capture an audit log of all accesses and changes to the system including data changes.-
10The proposed solution must be compatible with the following Government of PEI's standards.

Confidential Standards and Technical Information will be provided to vendors upon signing a Non-Disclosure Agreement.

Access Control-
Active Directory-
Anti-Virus Software-
Browsers-
Databases-
Data Destruction-
Desktop Operating System-
Encryption-
Passwords-
Mobile Phone Devices-
Desktops, Laptops, Tablets-
API Integration-
Migration Details-
System Integration Details-
Productivity & Communication Tools-

Technical Requirements E.3.2 Technical Requirements Refer to Appendix E Section E.3.2 Technical Requirements of the RFP for instructions.

1. Contract & Support

On-PremCloudCategoryVendor QuestionVendor Response
1.01√√Performance Metrics and BenchmarkingDescribe the performance benchmarks your system is monitored for and the reports that are available to us to review.

Performance metrics can include but is not limited to the following:

- System availability guarantees. (e.g. 24x7, 99.9%)

- Application response times

- Speed of individual transactions

- Speed of mass transactions

- Speed of data imports and data exports

- Data storage limits

Describe reports available for monitoring system performance metrics

- A description of the performance reports provided. If no regular report is automatically provided, can a regular report be requested as part of the contract obligations?

- Frequency of reports.

- Remedies and/or penalties in place for failure to meet the performance standards.

1.02 √ √ Responsibilities Describe the roles and responsibilities for your solution through all layers of technology.

(e.g. Data Center, Networking, Storage, Infrastructure (servers, processors, RAM), Hypervisors, Virtual Network Infrastructure, Operating System, Solution Stack, Application, Database, Interfaces (APIs, GUIs), Data)

Include a table containing a list of roles and who is responsible for that role (e.g. vendor, third-party vendor, GPEI)

2. General Technical Information

On-PremCloudCategoryVendor QuestionVendor Response
2.01√System ArchitectureDescribe the architecture of the proposed cloud solution.

Cloud/Hybrid Platform Deployment Model: Public, Private, Community, On-Premise Service Model: SaaS, PaaS, IaaS, XaaS

2.02 √ √ System Architecture Must provide a diagram of the technical layout of the proposed environments (production and non-production).

Including

- Recommendations for environments: production and non-production

- Any limitations of access to and usage of the environments

- How secondary environments are synched with production environments (repopulating test databases) and any additional fees associated with the task

- How service is connected to government network

- SaaS architecture diagram and description: User interface, Application, Data, Integration, Security, Network

- High availability architecture diagram and description: Redundancy, Failover

- Disaster recovery architecture diagram and description: Network, Replication, Failover

- Data Centre and Backup Storage Facilities description: Physical Sites, Physical Security, Infrastructure Connectivity, Servers, Offsite Storage Data Center Backup Tapes and Other Storage Media, Business Continuity Plans

2.03 √ √ Non-Production Databases Describe your process to ensure all sensitive data is protected in non-production databases, if your solution includes a database.

- Describe your process to identify all sensitive data in your production database.

- Describe your process to populate all non-production databases and how you will ensure all sensitive data is masked and/or randomized in those databases.

2.04 √ √ Desktop Software Provide details on desktop software requirements. Include at a minimum CPU, RAM, and Storage requirements)

- Specify plug-in or add-on requirements for browsers. (e.g. IIS, Flash, Java, .NET, etc.)

- Provide a list of any other desktop software that will be required for this system but is not included in the "Technical Standards" tab.

2.05 √ √ Server Software Provide details on server software requirements.

1. Server Operating System

- State the recommended operating system(s) used for this solution.

2. Database Management System

- State the recommended database management system(s) used with this solution, if applicable.

3.Other Software - Provide a detailed list of all other software components, including versions, required to implement the proposed solution.

Include all 3rd party software not part of the application. (e.g. Weblogic, WebSphere, Java, Apache, IIS, MS Word, Excel, Adobe Viewers)

** NOTE ** This question is to be answered regardless of platform. For cloud/hosted proposals, the question is for information purposes only but is still required.

2.06 √ √ Other Devices Provide a list of other supported devices and system versions.

- Include details on the ability for the application to operate on hand-held and mobile devices. (e.g. Blackberry, iPhone, Android, Tablets)

- Include details on printers compatibility.

2.07 √ √ Subscription/Licensing Describe the proposed solution's licensing model.

- Include all license requirements for the entire system (e.g. OS, DB, 3rd party software).

- Subscription; Processor Based; User Based

- Include details of licensing information for all components of the proposed solution

- Is the solution an annual support & maintenance or a subscription model?

- Include any licensing restrictions (e.g. Oracle in a virtual environment).

2.08 √ Captcha Does your system support CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart)?

If yes, which brand is supported?

2.09 √ √ Multi-Factor Authentication Does your system support multi-factor authentication?

If yes, what methods of authentication are supported, including which authenticator apps are supported.

2.10 √ √ Languages What languages are supported by your system?

3. Security

On-PremCloudCategoryVendor QuestionVendor Response
General
3.01√√Security CertificationsProvide details of security certifications, such as NIST 800-53, FIPS 140-3, ISO 27001, SAS70, SSAE16, CSA-STAR, SOC1, and SOC2, for all entities involved in the delivery of the proposed system.

Data Center certification is mandatory.

Vendor certification is an asset.

Include

- Proof of certification

- Frequency of the audits

Note: The vendor submitting the proposal MUST submit proof of certification for itself and all sub-contractors, including data centers.

Failure to submit mandatory proof of certification may result in failure to pass RFP evaluation.

3.02 √ Data Residency

Provide details on all data centers where the proposed solution can/will store information.

Data Residency applies to all forms of data including backups.

Include

- Who owns the data center(s) and where are they physically located?

- Can you guarantee that the data will remain in the same data center? If not, include when this would occur, the data that would be impacted, client notification procedures, and locations where the data could be moved

3.03 √ √ Anti-Virus Scanner Provide details on anti-virus

- Provide a list of anti-virus software that is compatible with this system.

- Provide a list of any required file exclusions.

- Describe any restrictions on software that can be installed to manage the solution such as Anti-virus agents, monitoring tools, or remote control tools?

3.04 √ √ Penetration/ Vulnerability Testing Provide a description of the penetration/vulnerability testing performed by the organization.

Include

- Tests performed, results of tests, frequency of tests.

3.05 √ Encryption Describe various encryption protocols or techniques available in your system to protect data in-transit, data at-rest and in use.

Encryption for data in use (the data being shared, processed, and viewed), does the solution utilize a digital rights management solution (DRM/ILM) or is the solution hosted on a cloud service provider that has data in use encryption policies in place?

Are redundant sites and data backups encrypted as well?

Include

- Who is responsible to maintain the encryption keys?

- List all parties that have access to the encryption keys.

- Are all copies of data, including backups, encrypted.

- How is key management process handled?

3.06 √ √ Auditing Describe the auditing functions available within the proponent's solution.

Explain how the solution can track, alert on, and report inappropriate access and usage of the system.

Provide details on any canned auditing reports that you can provide on a regular basis.

The description MUST include:

- Configuration options available for logging end-user and administrator actions

- Provide details on the types of events that can be logged (or not logged)

- Options available for setting formatting and logging levels

- Options available for setting retention policies and purging

- Whether or not GPEI get direct access to logs if required

- Whether or not specific log events can be captured and sent as a notification to GPEI employees

3.07 √ √ Password Controls Describe password functionality.

Include

- Ability for users to manage/change their own passwords

- Process for forgotten passwords

- Password controls: e.g expiration functionality, maximum failed attempts, minimum and maximum length and the use of letters, symbols and numbers

- Ability to modify the password control parameters

- Description of how passwords are passed through the application and stored (e.g. encryption)

Security & Risk Management
Physical Security is the protection of personnel, hardware, software, networks and data from physical actions and events that could cause serious loss or damage to an enterprise, agency or institution. This includes protection from fire, flood, natural disasters, burglary, theft, vandalism and terrorism.

Personnel Security is the discipline of assessing the conduct, integrity, judgment, loyalty, reliability, and stability of individuals for duties and responsibilities requiring trustworthiness.

Security and risk management is the process of identifying, prioritizing, managing, and monitoring risks to an organization or a system. It involves assessing the threats, the existing controls, the consequences, the likelihood, and the impact of the risks. It also involves selecting and implementing appropriate risk responses or strategies. Security and risk management can be applied to different domains, such as cybersecurity.

A Security Incident is an occurrence that actually or ptotentially jeopardizes the confidentiality, integrity, or availability of an information system or the information the system processes, stores, or transmits or that constitutes a violation or imminent threat of violation of security policies, secuirty procedures, or acceptable use policies.

3.08 √ √ Physical Security Provide a description of existing security controls such as policies, procedures, or guidelines that protect an organizations information assets against unauthorized access to physical areas, systems, and/or assets.

Include

- Physical, Technical, and/or Administrative controls such as policies, procedures, techniques, methods, solutions, plans, actions, or devices designed to provide physical security such as, but not limited to backup power, cooling, and environmental monitoring.

- Are the controls preventative, detective, or corrective.

- Security process in place for access by visitors, whether clients can tour the facilities, process to request a tour of the facilities.

3.09 √ √ Information Security Provide a description of existing security controls such as policies, procedures, or guidelines that protect an organizations information assets.

Include

* Physical, Technical, and/or Administrative controls such as policies, procedures, techniques, methods, solutions, plans, actions, or devices designed to provide information security.

* Are the controls preventative, detective, or corrective.

* Would the solution incorporate any risk management life cycle approach e.g.. risk transfer, risk matrix/analysis

* Describe risk management approach for software and/or supply chain risks"

3.10 √ √ Personnel Security Provide a description of existing security controls such as policies, procedures, or guidelines that define personnel or business practices that ensures employes, including sub-contractors, are appropriately vetted.

Include

- Physical, Technical, and/or Administrative controls such as policies, procedures, techniques, methods, solutions, plans, actions, or devices designed to provide personnel security.

- Employee hiring and termination practices (background checks, physical access to facilities)

- Equipment and Internet usage

- Separation of duties

- Auditing

- Do you provide ongoing security training to staff

NOTE: This applies to both the vendor and the data center/cloud provider.

3.11 √ √ Incident Management & Response Describe processes in place to identify and respond to incidents.

Include

- Do you have processes in place to detect and alert on breaches, security issues, and other performance/availability issues?

- Has your company ever experienced a security breach and if you have, describe how was the breached handled?

- In the event of a security breach, will you commit to provide notification to PEI within twelve hours of the breach being discover? If no, please describe your response plan.

Identity and Access Management (IAM)
Identity and access management (IAM) is a set of processes, policies, and tools for defining and managing the roles and access privileges of individual network entities (users and devices) to a variety of cloud and on-premises applications. IAM is a centralized and consistent way to manage user identities, automate access controls, and meet compliance requirements across traditional and containerized environments.
3.12√√ApproachDescribe your approach on how the solution leverages identity or service providers.

For example

- Microsoft for security services including, authentication, authorization, access control, and

- In relation to Mobile, Api, apps(Web), other third party apps

Include : - Provide an explanation on any approach you implement for using protocols that integrate through Directory Services OpenID, Oauth2.0, SAML, SSO etc.

- Does the solution use Role based access control( RBAC) or MAC or other methods for access controls, logging and auditing. If yes, provide details.

3.13 √ √ User Access Control Describe how the proposed solution limits or expands a user’s scope of work within the application, based on role or responsibility.

Include

- Protections and policies/processes in place for authentication to the application

- Process to grant or limit access for users to specific information through customizing security rights to various screens based on user or user group (creating, modifying and deleting users and user groups; configuring, changing or resetting passwords; configuring accounts and/or screens; account lockouts, etc..).

- Customizing security rights to various screens based on user or user group, etc..

- Describe details concerning the configurability of the auto logoff parameter.

- Describe ability to provide access through role-based profiles

- Provide details on non-identity provider integration relating to user access management including use of suspension, creation, registration etc.

Data Privacy / Information Privacy
Data Privacy or Information Privacy is a branch of data security concerned with the proper handling of data – consent, notice, and regulatory obligations. More specifically, practical data privacy concerns often revolve around: Whether or how data is shared with third parties, how data is legally collected or stored, and regulatory restrictions such as GDPR and HIPAA.

Data protection is focused on protecting assets from unauthorized use, while data privacy defines who has authorized access.

The General Data Protection Regulation (GDPR) is a legal framework that sets guidelines for the collection and processing of personal information from individuals who live and outside of the European Union(EU).

3.14√Data PrivacyDescribe any event where the company would restrict GPEI access to its data.
3.15√Data ProtectionIf you have a multi-tenant architecture that extends to the database level, describe the controls currently in place that will ensure the separation of data and the security of information between different customers.
3.16√√General Data Protection Regulation (GDPR)Is your solution GDPR compliant?

If yes, provide detail on:

- How the system is impacted by the GDPR?

- The processes to remain compliant with the GDPR.

3.17 √ √ Artificial Intelligence Does the proposed solution offer machine learning and/or artificial intelligence capabilities?

If yes,

- Describe how PEI's data would be used, protected and who would have access to that data?

Describe the capabilities or the approach used?

- Describe if models are tunable by the customer, if there is a framework for plugging in customers own models, and describe how often models are updated by the Proponent."

4. Exit Strategy

On-PremCloudCategoryVendor QuestionVendor Response
Please use the following definitions when answering the questions in this section.

A cloud exit strategy, commonly referred to as a reverse migration, is the process of developing a plan to ensure that a business can effectively switch from one cloud provider to another or back on-premise without a larger disruption.

Data destruction is the process of destroying data stored on various forms of electronic media so that it is completely unreadable and irrecoverable. The purpose of data destruction is to prevent unauthorized access or use of sensitive information. Data destruction is different from data deletion, which does not guarantee that the data is permanently erased.

4.01 √ Exit Strategy Provide details on the exit strategy for clients that terminate their services.

Include

- The process to initiate an exit

- The fees for data export/transfer, deletion of data, early contract termination.

- The processes to transfer data back to GPEI

- The formats are available for the data export

- Identify the vendor and client responsibilities during process.

- Identify any fees associated with terminating services (Include fees for data export/transfer, deletion of data, early contract termination.

4.02 √ Data Destruction Provide details on the process to destroy data if services are terminated.

Preferred method of destruction should adhere to CSE IT Media Sanitization ITSP 40.006 V2 or NIST SP 800-88 Guidelines for Media Sanitization in the U.S.

If you can't adhere to the above standards, provide details on why you can't and the processes and policies in place to destroy data.

Destruction of data must include backup versions and disaster recovery versions as well as all production and non-production databases.

- Include information on backup versions and any other copy of the database/files

- What verification do you provide to the client that data has been destroyed

4.03 √ Data Protection In reference to an exit strategy, describe the processes your company has in place to protect our data if your company goes out of business, is sold to another company, or if the servers are legally seized.

Include

- Do you use an escrow service? If you do, provide details on the service.

- How will you ensure data is transferred back to the client under these circumstances?

5. Backup & Recovery

On-PremCloudCategoryVendor QuestionVendor Response
Please use the following definitions when answering the questions in this section.

A database backup is an extra physical or virtual copy of data on another storage device. If you lose a piece of data, you can use its backup to restore the original file.

Database restore is a process of recovering a database from a backup file.

Disaster recovery (DR) is a step-by-step plan for responding to a major incident by switching to a secondary IT infrastructure.

While having a backup strategy is important, it is not the same as a disaster recovery strategy. A backup is a copy of your data; a disaster recovery plan is insurance that guarantees its recovery.

5.01 √ √ Backup Strategy Provide details on your backup strategy for the proposed system.

Include:

- The backup Schedule (Daily full and/or incremental)

- The retention schedule

- The maximum potential data loss

- Backup file format

- Transaction logging capabilities

- Custom/on-request backup capabilities

- Where your backups are located

** Note ** On-premise proposals should include any recommendations related to backup and recovery.

5.02 √ Disaster Recovery Describe your Disaster Recovery Plan.

Include details of the disaster recovery plan in place for recovering data center operations and network connectivity in the event of a local or regional disaster and the frequency of disaster recovery plan reviews/updates.

5.03 √ Backup Copy for GPEI Can your company provide a copy of the backup upon request.

- If yes, provide in detail the process to request and receive a copy of the data and any restrictions in place for such a request as well as available file formats.

- What formats can you provide the data in?

- If no, provide explanation why it is not possible.

5.04 √ Restore Process Describe the process your company uses when a data restore is needed.

Include

- The Recovery Point Objective (RPO) and Recovery Time Objective (RTO)

- The process in place to regularly test restore procedures

- The frequency of testing, and how the tests are validated.

5.05 √ Risk Analysis Describe any Risk Analysis plans in place.

Include

- Approach/Process for Risk Analysis

- Risk Categories

- Risk Likelihood and Risk Severity

- Risk Response Plan

- Risk Priority and Analysys Process

- Risk Ownership

- Risk Trigger

5.06 √ Redundancy / High Availability Describe applicable redundancy, high availability, and business continuity strategies.

Include whether data clustering, mirroring, or duplicating processes are implemented, and the role of each data center involved. (e.g. primary data center).

6. Data Migration & Integration

On-PremCloudCategoryVendor QuestionVendor Response
Please use the following definitions when answering the questions in this section.

Data Migration is the process of transferring data between different data storage types, formats, or IT systems.

Data Integration is the process of combining data residing at different sources so as to provide users with a unified view of all the data.

Data Export refers to our ability to receive an export of the database or a portion of the database in a format that is readable by us.

6.01 √ √ Data Migration If applicable, describe in detail the process to migrate data from GPEI to the proposed solution.

Details of the data integration requirements will be provided to vendors upon signing a Privacy, Security, and Confidentiality Agreement (PSCA).

Must Include:

- details on additional charges applied to complete a migration of the data.

6.02 √ √ Data Integration If applicable, describe in detail the integration process from existing GPEI systems to the proposed solution.

Details of the data integration requirements will be provided to vendors upon signing a Privacy, Security, and Confidentiality Agreement (PSCA).

- Are integration services provided?

- Details of additional fees for integration services.

- If REST APIs are compatible for integration development by GPEI.

- Provide a list of other software that this system can integrate with (e.g. Microsoft products.)

6.03 √ Data Export Describe the process to receive an export of our data if requested.

Must Include

- What data can be exported?

- What file formats available?

- What is the process to follow to get an export?

- Are there additional fees for this type of request?

7. Information/Data

On-PremCloudCategoryVendor QuestionVendor Response
Please use the following definitions when answering the questions in this section.

Records Management involves creating a level of efficient and systematic control over the creation, use, and disposition of records throughout its lifecycle, and includes setting policies for maintaining different types of records.

Data Retention refers to the practice of storing data for a specific period of time. This can be done for a variety of reasons, including legal compliance, business continuity, and data analytics.

Reporting Capacity requirements deal with the amount of information or services that can be handled by the component or system. These are important since they establish the way that the system can be used.

7.01 √ √ Records Management Describe the records management capabilities and any processes in place for records management purposes available in the proposed system.

Details of the data migration requirements will be provided to vendors upon signing a Non-Disclosure Agreement.

If specific records management requirements have been included, state whether or not your company can provide the records management services that meet those requirements and list all file formats available for archived records.

If there are no specific records management requirements included, state the capabilities your system has to perform general records managment services.

7.02 √ √ Data Retention Describe the data retention capabilities of the solution.

Include if the functionality customizable.

7.03 √ √ Reporting The vendors are required to provide direct access to reporting data sets that are required by Government of PEI for direct data consumption using in house reporting software tools, if the solution includes a database.

Direct access is a more secure way to grant access as it limits and governs users and groups that are explicitly granted permission, without extracting or replicating the data from the source system.

Example Approaches:

• Providing direct access to reporting database views, providing a reporting database server mirror, or exposing reportable data sets via a data warehousing platform;

• Direct API (Application Programing Interface) access to reporting data sets is an acceptable solution as long as it provides all required data elements outlined by the client / department/ project. Sample protocols: OData (Open Data Protocol), SOAP web services, REST API/JSON, FHIR ( for health projects), etc. Vendor is required to provide detailed API specification documentation.

7.04 √ √ Capacity Describe the capacity requirements for the application.

- Is the system scalable to handle data growth. Provide some details on scalability.

- Confirm that all storage related to this system is hosted by the Cloud Service Provider.

- Outline all costs related to storage on a per-TB basis.

- Describe the mechanisms to either expand or contract the purchased amount ??

- Based on the provided scope, provide an estimate of the amount of storage required based on other enterprise customers of similar scale.

8. Network

On-PremCloudCategoryVendor QuestionVendor Response
8.01√√BandwidthProvide details on bandwidth requirements necessary to provide acceptable service delivery.

- What network bandwidth is required by Gov't of PEI to ensure acceptable performance.

- What network bandwidth is provided by the vendor's data center? Is it shared or dedicated?

8.02 √ Cloud Access Is the service open to the public, or restricted to specific users? If so how?

This should cover IP white listing, VPNs, or web pages restricted by password.

8.03 √ √ IP Addresses Does this service require government provision of IP numbers? If so, how many and for what purpose?

Solution Requirements E.3.3 Solution Requirements Refer to Appendix E - Section E.3.3 Solution Requirements of the RFP for instructions.

Content and Workflow
#Vendor QuestionVendor Response
1.01Does the product support the provision and presentation of organizational charts (with reporting structure) and contact information for employees? This information should be able to be updated/maintained by each organizational unit manually and preferably through an integration/API with the human resource management system. If yes, please describe how this is achieved.
1.02Does the product allow the user to search for employees by role and business unit, as well as name? If yes, please outline the options.
1.03Does the product support a 'home page' view for each user that would show dashboard content specific to their department such as:

department banner/branding

- links to department specific applications

- links to internal and external websites

- notification of upcoming events

- news feeds

- department notifications (new hires / retirements)

- forms

- instructional documentation / knowledge resources

1.04 Does the product support an 'organization wide' view for each user that would show content that is important for all users (links to organization applications and links to important internal and external websites and content such as:

- government banner/branding

- links to enterprise applications

- links to internal and external websites

- notification of upcoming events

- news feeds

- government wide notifications

- forms

- instructional documentation / knowledge resources

1.05Does your product integrate with workflow tools / systems? If yes, please provide the workflow tools / systems that are supported.
1.06Does your product contain workflow functionality? If yes, please describe.
1.07Does your product contain electronic signature functionality for forms and approvals? If yes, please describe.
1.08Does the product integrate with electronic signature products for forms and approvals? If yes, please provide the electronic signature products that are supported.
1.09Is the product able to support the broadcasting of "All Staff" communications as well as communications that are specific to a subset of staff such as:

specific roles / job titles specific location Does the system have content management capability that allows for advanced date scheduling, posting, and removal of notices, newsletters etc. ?

1.10Is the product able to embed videos and photos in newsfeed, communications, etc.? If yes please provide details.
1.11Is the product able to provide a mechanism for campaigns and surveys that could be for a specific department or for all staff, including

- creation

- targeting groups

- monitoring level of response

- sending reminders

- consolidating and exporting results

1.12How is the product able to track viewing statistics on a communication or content? What level of detail is available?
1.13Is your product able to require that a user confirm/acknowledge that a message or content was viewed? If yes, please provide detail.
1.14Does the product have a search feature that allows users to search for specific communications by keyword, topic, or date, relevance ranking, ability to search within the documents, suggest popular searched items.? If yes please provide a summary of the features.
1.15Does the product support Communities of Practice pages/groups that could include staff from multiple departments? Can staff easily see all the Communities of Practice they are part of?
1.16Does the product provide features geared for employee communications, including:

targeted delivery alerts and reminders chat, Q&A and forums suggestion 'box' feature peer recognition feature town halls / presentations with Q&A recognition for participation on intranet (badges, star contributor).

If yes, please indicate which features are available.

1.17Does the product integrate with any enterprise business applications that would be beneficial to a Canadian government environment? If yes, provide examples.
1.18Can the product integrate with external training applications / platforms? If yes, can you provide examples?
General
2.01Does your product enable the turning on and off of commenting on posts? If yes, please provide detail.
2.02Does the product include an app store that includes additional widgets / features that staff can add?
2.03Do you have clients in Canada? Do you have clients of a similar size and/or organization as ours?
2.04What support mechanisms are available for your product? Do you provide training?
2.05Does your product support the creation of chatbots? What types of chatbots are supported?
2.06Does your product support the creation / maintenance of Frequency Asked Questions (FAQs)?
2.07Does your product include AI features? If so, please include details.
2.08Does the product support a ‘work queue’, where work activities can be aggregated and prioritized?
2.09Does the product support search and graph technologies? If yes, please describe what is available.
2.10Does the product support business-user oriented authoring and publishing, without the need to depend on IT resources?
2.11Does the product have a 'wiki' or repository to contain templates, logos, content guidelines and governance processes?
2.12As part of an implementation solution, can your organization provide recommendations of user interface/design for key pages (departments/ABC, Forms, Publications, home page)?
2.13As part of an implementation solution, can your organization assist with the development of a Roadmap / Strategy for a large organization's implementation of intranet ?
2.14Does your product support the creation of custom fields that can be used to link data in integrated applications (for example employee id)
2.15Application responsiveness is very important. What mechanisms does your application employ to ensure quick, responsive interactions (low latency)?
2.16Is your product able to be configured during or after installation, if the Province chooses to 'turn off' or 'turn on' features? For example, would the Province be able to turn off AI and then implement it at a later phase? Please describe how this would be done (if your product does not include AI, use another feature as an example.
User Access
3.01Is the product able to be delivered through a web destination site, employee portal, and/or mobile app?
3.02Can the product work on users' personal devices (not maintained/controlled by the organization)?
3.03How does the product accommodate external users, who are not in our organization? If yes, provide details on how this is achieved.
3.04Does the product support accessibility (screen readers, alt text to images, transcripts/captions for videos etc..)? Does the product support multilingual translation?
3.05Does the product have strong navigation features such as:

multiple levels of menus quick links suggestions for similar content content includes contact information for more information AI suggestions 'did you mean to search…?' ability to favorite, bookmark, etc. content and files ability to create personalized dashboards to display most relevant info/tools for their role If yes, please provide detail on the navigation features available.

Project Plan & Summary E.3.4 Project Plan & Summary Refer to Appendix E - Section E.3.4 Project Plan & Summary of the RFP for instructions.

No.CategoryProponent QuestionProponent Response
E.3.4.1Executive Summary
Provide a 1-2 page summary of your technical response, highlighting the key features of your proposal. It should allow the evaluation team to quickly gain an overall perspective of your proposal, prior to reviewing it in detail
Provide answer in PDF format as an attachment to your proposal.
E.3.4.2Understanding of Service RequirementsProvide a 1-2 page summary of your understanding of the RFP requirements defined in this RFP. This content should be expressed in your own words and not simply recite the requirements as defined in this RFP.Provide answer in PDF format as an attachment to your proposal.
E.3.4.3Proposed Approach, Process and Project PlanProvide a 3-4 page summary Describe the approach and/or process proposed to address the RFP requirements. Include any notable methodologies, tools and techniques, and their respective suitability to this project.

Provide a project plan that reflects your proposed approach/process and demonstrates your ability to meet the milestones. Describe the plan to implement both non-production and production environments.

Refer to Appendix E - E.3.4.3 Proposed Approach/Process and Project Plan in the RFP for more details.

Include

- List of high-level tasks

- Time estimates for high-level tasks

- Resource requirements

- Migration

- Testing requirements/use cases

- Process to populate non-production databases

- Transition plans for implementing the solution

- Communication plans

- Change Request

- Go Live Plan

- Training Plan

- Integration StrategyProvide answer in PDF format as an attachment to your proposal.
E.3.4.4Operational PlanProponents are to provide a 2-3 page summary describing their proposed operational plan for ongoing support.

Proponents are to include the following in their plan:

- Items such as warranty period, coverage hours, additional costs, support office location, manuals/documentation provided

- The process to request support

- Support levels (Critical, urgent, medium, low), thresholds, response time guarantees

- Escalation process

- Contact information for submitting issues (phone, online, etc.)

- Regular operating hours support

- After-hours support

- Issue response times

- Describe escalation procedures

- Reporting (Service Level, Quaterly/Annual, etc)

- Content mgmt processes/procedure

- Change Requests

- Downtime Procedures

- Provide a RACI chart outlining the roles and responsibilities for the proposed support planProvide answer in PDF format as an attachment to your proposal.
E.3.4.5Added ValueProvide a 1-2 page summary describing the added value of this system.

‘Added value’ is the realization of additional benefits beyond the inherent worth of a good or service. Some examples for services include approach, expertise, references, resources, management, tools and/or methodologies, etc., or a combination of these.

Describe the aspect(s) of your proposal believed to result in notable added value for this project and/or Government as a whole. Provide answer in PDF format as an attachment to your proposal.

Expertise & References E.3.5 Expertise & References Refer to Appendix E - Section E.3.5 Expertise & References of the RFP for instructions.

Proponent: 0

All Proponents must demonstrate that they have the level of experience to provide high quality services of a similar type to those sought in this RFP. Proponents must provide the following documentation to demonstrate this qualification criterion:

E.3.5.1 Project References with Demonstrated Expertise

Provide three project references for any work done by you in the past three years that is similar in nature to the requirements defined in this RFP. Select references that are similar to Government, and provide a contact name, along with his/her phone number, fax number and email address. The reference information provided should identify the size of the projects conducted for the reference as well as demonstrate the extent of your previous experience, the reference’s overall satisfaction with your services and the results achieved, including your adherence to interim and final deadlines.

All information must be provided for each reference.

Client Name is the organization that worked on the project.

Duration should include start and end date.

Reference information is the person that will provide the reference information.

Proponent Role is a short description of the role the contracted organization played in the project.

Reference #1

Client Name Reference Name

Project Name Reference Title

Project Duration Reference Phone #

Proponent Role Reference Email

What were the highlights of your solution and what innovations did you bring in your approach?

Reference #2

Client Name Reference Name

Project Name Reference Title

Project Duration Reference Phone #

Proponent Role Reference Email

What were the highlights of your solution and what innovations did you bring in your approach?

Reference #3

Client Name Reference Name

Project Name Reference Title

Project Duration Reference Phone #

Proponent Role Reference Email

What were the highlights of your solution and what innovations did you bring in your approach?

E.3.5.2 Management
a. Team Formation
Describe your approach to overall team formation and coordination of team members. Include an organizational chart for the Project specifically, focusing on Key Personnel assigned to the Project.
b. Sustainability
What is your organization’s approach to sustainability and corporate social responsibility? Describe what steps your organization takes to reduce the environmental footprint resulting from your operations.
c. Changes in Project Manager
Describe how changes in the project manager in particular would be handled, if this becomes necessary.
d. New Service Requirements
If new service requirements emerge during the project, Government will make every effort to provide the successful Proponent with as much advance notice as possible. Describe the process and typical timelines involved in making additional resources available to this project.
e. Managing Risk
Please describe the potential risks to the Province that may impact achievement and timely completion of expected results as well as their quality. Describe measures that will be put in place to mitigate these risks
Add new rows as needed.
E.3.5.3 Team Qualifications and Experience

The Proponent should be able to demonstrate that its proposed team as a whole meets or exceeds the RFP requirements. Prepare the table below to identify all personnel who will be assigned to the project and contribute to (i) the routine management and/or (ii) the performance of the required services. As shown, provide each person’s name, title, role on this project, experience in this role and his/her respective employment status.

Name Title Project Role Role Experience # Months Employment Status (E=employee, C=contractor, P=partner)

<Project Manager>
<Resource #1>
<Resource #2>

The Province encourages innovation and competition in the Proponent community through arrangements such as partnerships and consortiums. If sub-contractors or partners of a Proponent are permitted for this project, they must be identified in your table. If so, describe the general range of services that the respective contractors (companies or individuals) provided and how this benefits your company. If no contractors or partners are identified, this will be interpreted to mean that only a Proponent’s ‘own resources’ will be used.

Submit the individual resumes for each proposed resource with a copy of a completed Section E - Account Team Submission Form for the individual. The resumes should be structured to emphasize their relevant qualifications and experience in successfully completed projects of a similar size and scope to that required by this RFP.

E.3.5.4 Government Human Resource Requirements

The Proponent should provide a list of resources that GPEI will need to provide for the implementation as well as on-going support. This list will be used to estimate the cost of internal resources and will be added to the 5 year Total Cost of Ownership.

Project Role Estimated Annual FTE Description of Duties

<Project Manager>
<DBA>
<System Administrator>

File details come from the government source that posted it. Updated .