Appendix 13 - Revision 1.pdf
PDF 1 MB Posted
- Attached to
- IT SYSTEM MODERNIZATION State and local contract opportunity
- Solicitation number
- 5400027020
- Issued by
- Richland County, South Carolina
About this file
Technical Requirements Appendix for SCDMV IT System Modernization
This is a technical requirements appendix for the South Carolina Department of Motor Vehicles' (SCDMV) IT system modernization initiative. The document establishes comprehensive technical specifications across ten primary areas: user interface requirements, hosting environment options, security controls, backup and disaster recovery capabilities, system management functions, performance standards, interface specifications, general technical requirements, geographic locations, and device specifications. The modernized system must support multiple concurrent user communities including 872 branch users across 65 locations, 604 headquarters users, 2,682 active motor vehicle dealerships, 16,179 other users (law enforcement, businesses, courts, lending institutions), and 4,562 electronic lienholders. The system must process annual transaction volumes exceeding 38 million law enforcement inquiries, 3.3 million vehicle registration services, 1.9 million driver's license services, and 5.2 million miscellaneous customer services. Current infrastructure includes approximately 1,461 branch workstations and 1,438 headquarters workstations running Dell platforms, with peripherals including document scanners, barcode scanners, thermal printers, credit card readers, and credential printers. The system must manage approximately 220 million documents requiring 27.8 terabytes of storage with projected growth of 8-10 gigabytes daily.
The technical solution must be hosted in either a contractor-provided cloud environment (mandatory option) or a state-provided Azure cloud with contractor-provided engineering and support (optional). Both hosting options must achieve FedRAMP moderate certification with support provided exclusively within the contiguous United States. The system requires a primary data center located within 500 miles of South Carolina's border and a secondary disaster recovery site separated by at least 100 miles and located outside South Carolina, with network latency not exceeding five milliseconds from either location to SCDMV headquarters. Recovery objectives mandate a maximum recovery point objective (RPO) of 120 minutes and recovery time objectives (RTO) of two hours for all system access levels. The contractor must provide all hardware, systems software, supporting software, cloud engineering, configuration, backup, recovery, disaster recovery support, and maintenance through the warranty period at no additional cost. Security compliance requires FedRAMP moderate certification, encryption of all data at rest and in transit using FIPS 140-3 standards, multifactor authentication for all user access, comprehensive audit logging with three-year retention for audit logs, annual independent FedRAMP audits at contractor expense, and immediate breach notification procedures to designated SCDMV contacts. The contractor must perform semi-annual backup restoration testing, maintain immutable document storage for operational records, achieve specified user interface response times (0.1 seconds for same-screen interactions, 2 seconds for record retrieval and customer searches), and provide compatibility with Microsoft Active Directory, Azure AD, Microsoft 365 email integration, Power BI business intelligence tools, and existing SCDMV security monitoring and malware detection solutions.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment 1.pdf | ||
| Solicitation.pdf | ||
| Appendix 2 - Revision 1.pdf | ||
| Appendix 14 - Revision 1.pdf | ||
| Appendix 7 - Revision 1.pdf | ||
| Appendix 04.pdf | ||
| Amendment 2.pdf | ||
| Appendix 08.pdf | ||
| Appendix 11 - Revision 1.pdf | ||
| Attachment C - Revision 2.xlsx | XLSX spreadsheet | |
| Attachment B - Revision 1.pdf | ||
| Appendix 12.pdf | ||
| Appendix 09.pdf | ||
| Attachment 4.pdf | ||
| Appendix 15.pdf | ||
| Attachment A - Revision 2.pdf | ||
| Appendix 3 - Revision 1.pdf | ||
| Appendix 01.pdf | ||
| Appendix 06.pdf | ||
| Appendix 5 - Revision 2.pdf | ||
| Appendix 10 - Revision 1.pdf |
Show all 21
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Technical Requirements
Appendix
Subject:
Technical Requirements
Appendix 13 - Technical Requirements Revision 1 Page 1 of 44
1. Overview
2. Introduction
3. Technical Requirements
See Appendix 15 for a complete list of all abbreviations and acronyms.
Appendix 13 - Technical Requirements Revision 1 Page 2 of 44
1. Overview These Technical Requirements are desired to be met by the Contractor’s proposed solution. The SCDMV requires a state-of-the-art solution that adheres to industry best practices and employs generally accepted industry frameworks, approaches, and designs. The proposed solution should balance the requirements presented in this appendix to provide a secure, reliable, flexible, enterprise-level solution that is cost-effective and realistic.
Appendix 13 - Technical Requirements Revision 1 Page 3 of 44
2. Introduction The technical requirements address the following areas:
1. User Interface (UI) Requirements
2. Hosting Environment
3. Security
4. Backup/Recovery and Disaster Recovery
5. System Management
6. Performance
7. Interfaces
8. General
9. Locations
10. Devices
Appendix 13 - Technical Requirements Revision 1 Page 4 of 44
3. Technical Requirements This document details the technical requirements for the modernized system. These requirements cover aspects of the modernized system outside of the requirements for the specific business areas.
3.1 User Interface (UI) Requirements
1. Multiple Browser Support – The modernized system UI shall support all major browsers including:
a. Edge
b. Chrome
c. Safari
d. Firefox
2. Browser Independence – All modernized system public-facing web applications shall be browser-independent.
3. Mobile GUI Support – The modernized system UI shall:
a. provide a single responsive graphical user interface (GUI) that runs on mobile devices and desktop devices.
b. support touch screen monitor interactions for desktops, laptops, mobile devices, and kiosks.
c. automatically resize the screen for optimal viewing based on the device.
4. Consistent Layout – The modernized system UI shall:
a. have a consistent layout across modules, including warnings, alerts, and other prompts.
b. have consistent controls and buttons across modules.
c. have consistent behavior across modules.
5. Internal and External Users – The modernized system UI shall:
a. address differences between internal users (staff) and external users
(customers, third-party authorized users).
b. provide a readily identifiable visible difference for internal-facing and customer-facing applications.
c. provide a readily identifiable visible difference between the production environment and non-production environments.
6. Branding – The modernized system UI shall
a. comply with SCDMV branding standards as defined by the SCDMV.
7. ADA Compliant – The modernized system UI:
a. shall comply with the Americans with Disabilities Act of 1990 (ADA).
b. should preferably allow ADA features to be toggled on and off by the user.
Appendix 13 - Technical Requirements Revision 1 Page 5 of 44
c. shall ensure compatibility with all Federal Government disability and UI standards.
d. Shall comply with the Web Content Accessibility Guidelines (WCAG), latest version. The SCDMV requires Level AA for ADA/WCAG compliance.
8. Guided Design – The modernized system UI shall provide a:
a. simple, clean design, that is intuitive and guides the user through the process.
b. wizard-like interface for applicable customer transactions that are on more than one screen.
9. Required Fields – The modernized system UI shall:
a. visually identify the mandatory input fields (i.e. requiring user input).
b. consider dynamic mandatory input fields.
c. be sufficiently intuitive to only ask for needed information.
10. Field Format Masking – The modernized system UI shall support a format mask that will enforce mandatory formatting for data entry of all sensitive and/or protected data, such as PII, PHI, and similar data types.
11. Masked Passwords and Other Sensitive Data– The modernized system UI shall automatically mask passwords and other sensitive data (e.g., SSN and DOB) on typing and provide a toggle to be able temporarily to see the unmasked passwords and other sensitive data as permissible. The toggle removing the mask shall not be a permanent on/off but shall automatically revert to off after a short period of time, usually less than fifteen seconds for passwords.
12. Data Validations – The modernized system UI shall validate the:
a. presence of data (e.g., validate in mandatory fields) - when a user attempts to save information, ignore a space character as valid, and verify the data type is correct.
b. correctness of data (e.g., validate in mandatory fields) - when a user attempts to save information or leaves a field, including automatically performing any mandatory checks that can be made and performing actions like left justification before saving into a database.
13. Real-Time Error Messaging – The modernized system UI shall interactively inform the user of errors based on real-time validations performed as the user enters data or as soon as the remote system check is completed.
14. Breadcrumb Navigation Displays – The modernized system UI shall display breadcrumbs and allow users to move forward and back to prior screens to adjust data before submission and guide user navigation to required screens.
15. User Save Prompts – The modernized system UI shall prompt the user to save data before exiting screens as needed.
16. PII Security – The modernized system UI shall adhere to the security measures/specifications identified in Section 3.3, Item 1, to prevent individual and
Appendix 13 - Technical Requirements Revision 1 Page 6 of 44 bulk PII loss, as approved by the SCDMV and without interfering with the day-to-day requirements for performing work.
17. Navigation – The modernized system UI shall provide tabbing/typing through fields.
18. Navigation Focus – The modernized system UI shall provide a focus that goes to the next logical field.
19. Dynamic Dropdowns – The modernized system UI shall provide dynamic dropdowns that can be filtered/narrowed down by typing.
20. Current Version of Windows – The modernized system must be compatible and maintain capability with Microsoft’s current supported versions of Windows. Note:
The modernized system software is expected to be able to operate on the latest version of Microsoft Windows. If and when the modernized system is deployed to any specific version of Microsoft Windows will be at the discretion of the SCDMV.
21. More Option – The modernized system UI shall display a minimal amount of information to the user while also enabling the user to immediately expand the amount of information displayed. (E.g., click the “More” button.)
22. Navigate Forward and Backwards – The modernized system UI shall allow the ability:
a. to go back to prior screens (e.g., during the processing of a transaction) to adjust data and information and continue processing without canceling the transaction.
b. to cancel a transaction and have the system undo the work that has been done. (E.g., uncommitting saved data.)
c. to undo data provided on prior screens.
d. to reverse decisions made on prior screens.
e. to undo data provided on prior screens when the screens are resumed at a later time.
f. to move backward and forward without re-entering previously entered data.
g. to save work-in-progress and come back to it later without loss of data.
h. to clean up work in progress that is no longer viable. (i.e. Exchanging a license plate after the vehicle has been sold.)
23. Saving Transactions – The modernized system UI shall:
a. allow the automatic saving of information as users enter data without clicking a save button.
b. allow setting the interval when entered data is automatically saved.
c. allow saving a transaction that is in progress.
d. allow resuming a transaction that is in progress.
e. allow returning to an in-process transaction after abnormal interruption (e.g., power failure at the workstation).
Appendix 13 - Technical Requirements Revision 1 Page 7 of 44
f. alert other users that a saved transaction is pending for a user.
g. allow a user to pick up and complete or cancel work in progress started by a different user.
h. allow a user to pick up and complete or cancel work in progress.
i. ensure automatically saved transactions do not become part of the official record until the transaction is completed.
24. Notes – The modernized system shall:
a. provide simple (e.g., bold, italics, underscore, highlighting, font color) formatting in a manner that does not conflict with ADA requirements.
b. provide bulleted list functionality.
c. provide cut-and-paste functionality.
d. allow including/pasting images where appropriate.
e. provide spelling and grammar checking.
f. provide a character count limit.
g. support all character sets used by Federal interface partners.
25. Cut and Paste – The modernized system shall support cut and paste, along with all standard Windows shortcut keys:
a. within the system.
b. to and from other Windows applications.
c. within word processing functions within the modernized system.
26. Help – The modernized system shall:
a. provide context-sensitive help for transactions.
b. provide context-sensitive help for codes, abbreviations, and acronyms.
c. provide hover help.
27. Reviewing Information Before Committing – The modernized system UI shall allow both staff and customers to review and update all entered information before final submission.
28. UI Layout – The modernized system UI shall not require code changes for the following changes to the UI:
a. text and field positioning.
b. field, text, and font size.
c. field tab order.
d. adding/removing logos and images.
e. hiding and revealing hidden fields.
f. adding, updating, and removing text.
29. Partial SSNs – The modernized system UI shall allow entry of partial SSNs as part of the search function.
Appendix 13 - Technical Requirements Revision 1 Page 8 of 44
30. Static Content – Changes to static content shall not require code changes or other programming effort to the modernized system UI when referentially accessed.
3.2 Hosting Environment
The Offeror shall propose a system that is:
1. hosted in a Contractor-Provider Cloud Environment; or
2. optionally hosted in a State-Provided Azure Cloud with Contractor-Provided
Engineering and Support.
The inclusion of the Contractor-Provided Cloud Environment is considered mandatory.
The inclusion of an environment for a system that is hosted in the State-Provided Azure Cloud with Contractor-Provided Engineering and Support is optional but desirable. For Offerors that provide both cloud environments, the SCDMV will decide which will be used at the time of the award.
3.2.1 State-Provided Azure Cloud with Contractor-Provided Engineering and Support
For Contractors proposing a solution hosted in a State-Provided Azure cloud environment, the Contractor shall also include cloud engineering and cloud support as part of their proposal. The requirements in this section (3.2.1) only apply if the Contractor is proposing to use a State-Provided Azure Cloud.
1. Cloud – The Contractor solution shall be hosted in an Azure government cloud provided by the State.
a. FedRAMP – The modernized system shall be hosted on a FedRAMP moderate certified hosting platform.
b. CONUS Support – The Contractor shall provide all support from within the Contiguous United States.
2. Cloud Specifications – The Offeror shall provide the SCDMV with the specifications for all environments required to meet the requirements in this RFP.
3. Cloud Engineering Specifications – The Contractor shall provide all cloud engineering for establishing the environments (e.g., development, training, test, production) by specifying the:
a. Operating environment (e.g., Windows Is preferred)
b. Type (e.g., general purpose, storage optimized)
c. Azure cloud storage access tiers (e.g., "Hot", "Cool", or "Archive")
d. Servers (number and purpose of each server)
e. Sizing (CPUs, memory, storage, network bandwidth)
f. Azure Site Recovery service
g. Other relevant metrics.
Appendix 13 - Technical Requirements Revision 1 Page 9 of 44
4. Cloud Engineering Environment Acquisition – The Contractor shall support the SCDMV in specifying the necessary configuration of the Azure cloud environments and the timing for avoiding the premature ordering of the environments.
5. Cloud Engineering Environment Setup – The Contractor shall provide all of the required cloud engineering for establishing and configuring the environments (e.g., operating system and database installation and configuration).
6. Using State Licenses Where Possible – The Contractor shall work with the State to utilize State software licenses (e.g., Microsoft operating system, Microsoft databases, programming languages, anti-malware, and network software) where possible.
7. Supporting Software Components – The Contractor shall provide all software components and associated licenses excluding the licenses provided by the State (e.g., operating system, database, anti-malware, and network software) necessary for the system to fully function.
8. Systems Software Components – The State will provide licenses for the operating system, database, anti-malware, and network software necessary to manage and maintain the cloud-based system.
9. Cloud Engineering Environment Support – The Contractor shall provide all of the support for the cloud environments through the warranty period and support periods, including all software, configuration, backup and recovery, disaster recovery, and other support needs, unless specifically agreed to in writing by the State.
10. Primary & Secondary Sites – The modernized system shall operate on the State-provided, cloud-hosted, primary and secondary sites that run redundantly serving both as a fail-over and a Disaster Recovery site.
a. The primary and secondary sites shall support all environments (e.g., development, test, training, production).
b. The primary site shall be located within 500 miles of the South Carolina physical border.
a. The secondary site shall be separated from the primary site location and shall not be within one hundred (100) miles of the primary site.
c. The secondary site shall not reside within South Carolina.
d. The primary and secondary sites shall be in separate cloud regions with cross-region replication to ensure data integrity and data availability.
e. The primary and secondary sites shall meet the Recovery Point Objectives
(RPO) and Recovery Time Objectives (RTO) requirements stated in Section
3.4.2 Disaster Recovery.
11. Compliance – The modernized system hosting platform shall meet State and Federal compliance requirements.
Appendix 13 - Technical Requirements Revision 1 Page 10 of 44
12. Connectivity – The Contractor shall provide high availability of connectivity between the primary and secondary sites to keep the systems in sync and able to meet all disaster recovery and failover requirements.
13. Storage – The Contractor shall specify sufficient storage and processing capacity to support all requirements of the SCDMV.
14. Usage – The Contractor shall work with the State cloud provider to provide a detailed itemization of cloud usage for all cloud services, including network usage, memory usage, disk usage, processor usage, software licenses, and other services.
3.2.2 Contractor-Provided Cloud Environment
The modernized system shall be deployed in a Contractor-provided cloud environment.
At present, the State prefers Azure and AWS cloud environments but is open to considering Contractor-provided cloud environments that are procured and provided by the Contractor if these cloud environments meet the following requirements.
1. Cloud – The State strongly prefers that the Contractor solution be hosted in either an Azure or AWS cloud.
2. FedRAMP – The modernized system shall be hosted on a FedRAMP moderate, certified hosting platform.
3. CONUS Support – The Contractor shall provide all support from within the Contiguous United States.
4. All Inclusive Hardware and Systems Software– The Contractor-provided cloud environment shall be all inclusive to the extent no additional hardware and systems software will need to be procured from the commencement of the project through the end of the warranty period or completion of the contract, whichever is later.
5. All Inclusive Management, Support, and Maintenance– The Contractor-provided cloud environment shall be all inclusive to the extent no additional services and staff will need to be procured for management, support, and maintenance of the Contractor-provided cloud environments from the commencement of the project through the end of warranty period or completion of the contract, whichever is later.
6. Primary & Secondary Sites – Contractor solution shall operate on a Contractor-provided, cloud-hosted, primary and secondary site that runs redundantly serving both as a fail-over and a Disaster Recovery site. The Disaster Recovery location shall be separated from the primary data center location and shall not be within the same cloud region as the primary location. The primary and secondary sites shall support all development and production environments. The primary and secondary sites shall meet the RPO and RTO requirements stated in Section 3.4.2 Disaster Recovery.
7. Primary Site Location – The Contractor-provided cloud environment’s primary site shall be located within 500 miles of the South Carolina physical border.
Appendix 13 - Technical Requirements Revision 1 Page 11 of 44
8. Secondary Site Location – The Contractor-provided cloud environment’s secondary site shall not reside within South Carolina.
9. Primary Site Network Latency – Network latency from the primary site to the SCDMV headquarters site shall not be greater than five milliseconds (5ms) at all times.
10. Secondary Site Network Latency – Network latency from the secondary site to the SCDMV headquarters site shall not be greater than five milliseconds (5ms) at all times.
11. Compliance – The modernized system hosting platform shall meet State and Federal compliance requirements.
12. Connectivity – The Contractor shall advise the SCDMV of all network requirements for maintaining and sustaining connectivity between the primary and secondary cloud sites to keep the systems in sync and able to meet all disaster recovery and failover requirements.
13. Storage and Processing – The Contractor-provided cloud shall include all storage and processing capacity to support all of SCDMV’s modernized system requirements.
14. Bandwidth – The Contractor-provided cloud shall include all required bandwidth capacity to support all of SCDMVs modernized system requirements.
15. System Software Components – The Contractor shall provide all system software components and associated licenses including the operating system, database, and network software necessary for the system to fully function.
16. Supporting Software Components – The Contractor shall provide all software components and associated licenses excluding the operating system, database, and network software necessary for the system to fully function.
17. Usage – The Contractor shall provide the SCDMV with a detailed itemization of cloud usages for all cloud services, including network usage, memory usage, disk usage, processor usage, software licenses, and other supplied services. SCDMV prefers the detailed itemization of cloud usage for all cloud services to be available in real time.
18. Cloud Experience – The Contractor shall provide evidence that the cloud vendor they are proposing has experience on the development, testing, deployment, and support of the proposed product in the proposed cloud environment.
19. CONUS-Based Cloud Company – The cloud vendor proposed by the Contractor shall be a company with headquarters in the United States, not primarily owned by foreign entities, and cannot be banned by the U.S. government (including the Pentagon) from being used by federal agencies.
a. The contractor shall ensure that data never leaves the CONUS.
Appendix 13 - Technical Requirements Revision 1 Page 12 of 44
b. The contractor shall ensure that the SCDMV modernized system shall never be accessed by resources outside the CONUS for any purpose including support and maintenance.
c. The contractor shall ensure that the SCDMV modernized system can never be accessed by resources outside the CONUS for any purpose including support and maintenance.
20. Migration to the State Cloud – If requested by the SCDMV, the Contractor shall agree to work with SCDMV to migrate the modernized system (software, data, support, etc.) from the Contractor-provided cloud proposed by the Contractor to the State’s cloud platform at a time in the future.
3.3 General Requirements
The modernized system shall meet all physical and logical security requirements including the following:
1. Law & SCDMV Policy – The modernized system shall comply with and continue to comply with the latest versions of the State and federal laws and regulations, and SCDMV policies including:
a. SC Family Privacy Protection Act of 2002 (for the protection of citizen PII).
b. FedRAMP (Federal Risk and Authorization Management Program
[FedRAMP®]) moderate.
c. AD-551 Information Security – SCDMV specific.
d. AD-552 Information Security Incident Response Plan.
e. The Federal Driver Privacy Protection Act of 1994 (for the protection of citizen PII).
f. SC FOIA (Particularly Sections 30-4-160 and 30-4-165 of Title 30 of the South
Carolina Code of Laws.
g. SSA Technical System Security Requirements
h. SCDIS-200 Information Security and Privacy Standards
2. Security Requirements – Complying with State and SCDMV security requirements, industry standards, and existing security tools and services including but not limited to:
a. FedRAMP (Federal Risk and Authorization Management Program) moderate
b. Incident Reporting and Breach of Security Protocols, including
c. Record Disposition/Destruction Security Controls/Standards, including SCDIS-
501 Information Media Disposal Procedure and South Carolina Department of Archives and History (SCDAH) General Records Retention Schedule.
3. Events that Need to be Logged – The events identified in the latest version of the SCDMV's Audit and Accountability Policy.
Appendix 13 - Technical Requirements Revision 1 Page 13 of 44
4. Fail Secure – The modernized system shall adhere to the principle of ‘Fail Secure’ to ensure that a system in a failed state does not reveal any sensitive information or leave any access controls open for attacks.
5. Secure System Boundaries – The modernized system shall be architected and constructed to monitor and control communications at key internal boundaries (for example: web servers, application servers, and database servers).
6. Secure Logs – Secure logs shall meet the requirements of SCDMV’s Audit and Accountability Policy. The Contractor shall ensure:
a. sensitive data stored in logs shall be encrypted.
b. access to sensitive data shall be restricted specifically to those with job duties requiring this access.
a. the details about who, when, what, and how the information was accessed logs are accessed.
c. the SCDMV prefers not to record the failed password in logs.
7. Protect Data – The Contractor shall ensure the modernized system is, designed, built, maintained, and managed to prevent corruption or loss of data already accepted into the modernized system in the event of a system failure.
8. Secure Components – The Contractor shall not deploy any application or code to production that contains known security vulnerabilities.
9. Scanning – The modernized system shall be subject to security and vulnerability scanning and the Contractor shall remediate any non-compliant results in an agreed-upon timeframe based on level of severity.
10. Accessing System Logs – The Contractor shall provide a mechanism for third parties to be able to evaluate the system’s security posture by accessing system logs, an API hook, and other mechanisms. This access will allow an authorized third- party or SCDMV to assess the system ensuring that it meets security requirements. (For example, allow the third-party to have a hook into the system to run scans in the environment.)
11. Encryption – The Contractor shall:
a. ensure encryption is applied to all data at rest. The SCDMV is currently using appliance-level encryption, database field encryption, and database encryption.
b. work with the SCDMV to adopt FIPS-140-3 or higher for the modernized system for data at rest.
c. ensure encryption is applied to all data in transit.
d. ensure the SCDMV’s modernized system supports the latest Transport Layer
Security (TLS) standard. Work with the SCDMV to adopt FIPS-140-3 or higher for the SCDMV modernized system for data in transit/flight.
Appendix 13 - Technical Requirements Revision 1 Page 14 of 44
e. ensure that all data communicated via an external interface (i.e., outside of the SCDMV) is encrypted, regardless of whether the information is flowing out of the SCDMV or into the SCDMV.
12. Trusted Networks and Nodes – The modernized system shall be, designed, built, maintained, and managed to restrict network connections between trusted and untrusted networks by physically and/or logically isolating systems supporting the modernized system from unsolicited and unauthenticated network traffic.
a. The SCDMV prefers physical segmentation.
13. Configuration Reviews – The Contractor shall review:
a. Every 6 months the Contractor shall review the network connections, documenting and confirming the business justification for the use of all services, protocols, and ports allowed, including the rationale or compensating controls implemented for those protocols not meeting current standards and provide a report to the SCDMV for review and approval.
14. Organized & Well Managed Hosting – The Contractor shall:
a. Implement administrative, physical, and technical safeguards to protect
SCDMV data that are no less rigorous than:
SCDIS-200 Information Security and Privacy Standards.
Accepted industry practices, such as the current Control Objectives for
Information and Related Technology (COBIT) framework or similar applicable industry standards.
b. Ensure that all such safeguards, including how SCDMV data is collected, accessed, used, stored, processed, disposed of, and disclosed comply with applicable data protection and privacy laws as well as the terms and conditions stated elsewhere for the modernized system.
c. Ensure compliance with FedRAMP moderate certification.
d. Ensure compliance with SCDMV’s contiguous US-based support requirement.
15. Hardening Procedures – The Contractor shall:
a. Apply hardware and software hardening procedures, which may include, but are not limited to, the removal of unnecessary software, disabling or removing of unnecessary services, the removal of unnecessary usernames or logins, and the deactivation of unneeded features in the System configuration files, as recommended by the manufacturer/developer to reduce the System’s surface of vulnerability.
b. Ensure compliance with SCDMV’s contiguous US-based support requirement.
16. Data Isolation – The Contractor shall ensure, for all environments including back-up and disaster recovery, whether cloud or otherwise hosted:
a. No SCDMV data appears in any non-SCDMV system unless expressly authorized by the SCDMV.
Appendix 13 - Technical Requirements Revision 1 Page 15 of 44
b. SCDMV data cannot be commingled with any other data and must be logically separated from non-SCDMV data unless expressly authorized by
SCDMV.
a. Separate, dedicated, and segmented environments, including all instances, for SCDMV systems, data, interfaces, and other components.
b. The aforementioned Data Isolation requirements do not apply to customers downloading their own personal data for which they are authorized to access on their personal devices.
17. Security for All Environments –
a. All modernized system environments (e.g., production, testing, training, and development) are required to have the same security controls that are available in the production environment.
b. Unless instructed to do so in writing, the Contractor shall follow the same security precautions for all non-production environments that are followed for the production environments.
3.3.1 Breach and Data Breach
The Contractor shall comply with Breach of Security of State Agency Data S.C. Code Ann Section 1-11-490.
The Contractor shall assist the State in meeting the requirements stated in Proviso
117.97 of the 2025-2026 Appropriations Act.
For purposes of the requirements in this section, notification is considered to have taken place when a phone call is made to a person (not voicemail) and details are communicated to the SCDMV designated email address. The SCDMV will provide the following phone numbers and email addresses to be used for notifying the SCDMV in the event of a breach or data breach:
1. ISO Cell Phone
2. CIO Cell Phone
3. Security Team on-call Phone Number
4. Required email addresses for contacting the SCDMV
For purposes of the requirements in this section, “under Contractor control” shall be interpreted to apply to any elements the Contractor has access to, responsibility for, or authority over. Elements include system-related components, primary and secondary sites, networks, storage, data, content, applications, workstations, peripherals, interfaces, accounts and passwords, biometric authentication mechanisms such as fingerprints and facial images, authentication mechanisms such as fobs and badges, backup and recovery media and applications, policies, procedures, documentation, and items related to these.
Appendix 13 - Technical Requirements Revision 1 Page 16 of 44
In the event of a breach or data breach:
1. Notify SCDMV – The Contractor shall immediately notify SCDMV with information regarding the breach (e.g., time, customers affected, data compromised) regarding the breach for elements under Contractor control. If SCDMV becomes aware of a breach that affects the elements under Contractor control, SCDMV will communicate this information to the Contractor. The Contractor shall also immediately notify the SCDMV with information regarding any potential breach.
2. Isolate Systems – The Contractor shall immediately isolate all systems under Contractor control that were accessed by the attacker to prevent further access to data or lateral movement within the network.
3. Separate User, System, and Other Accounts – The Contractor shall work with SCDMV immediately to separate or disable the breached user, system, and other accounts that are under Contractor control.
4. Separate System Accounts – The Contractor shall immediately separate or disable the breached system accounts.
5. Assess Damage – The Contractor shall immediately begin to assess the damage and provide periodic (not less than hourly) communications to SCDMV on the assessment.
6. Damage Assessment – The Contractor shall include in the breach damage assessment the:
a. data accessed.
b. how attackers gained access to systems.
c. impact on operations.
d. Contractor’s approach to containing the breach.
e. Contractor’s actions for preventing a further breach.
f. plans for restoring the system elements under Contractor control or recommendations for restoring those elements that are not under Contractor control.
g. plans for returning to normal operation.
7. Identify and Close Breach Points – The Contractor shall:
a. immediately identify and close all breach points for the system elements under Contractor control.
b. work with SCDMV to immediately identify and close all breach points for the system elements not under Contractor control.
8. Notify Impacted Parties – The Contractor shall provide the capability to notify impacted parties in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the computerized data system.
Appendix 13 - Technical Requirements Revision 1 Page 17 of 44
a. The Contractor acknowledges that there may be delays in notification if a law enforcement agency determines in writing that the notification may seriously impede a criminal investigation.
b. The SCDMV will coordinate all communications to the public.
9. Safely Restore Data – The Contractor shall:
a. Not perform a restore place until due diligence is performed to include an attestation report approved by the SCDMV.
b. Identify and implement an approach to safely restore data for the system elements under Contractor control.
c. Work with the SCDMV to identify and implement an approach to safely restore data for the system elements that are not under Contractor control.
d. Execute the predefined approach for safely restoring data when directed to do so by the SCDMV.
e. The SCDMV will decide what to do if data is lost or some data cannot be safely restored, and the Contractor shall accommodate these business decisions.
10. Penetration Testing – The Contractor shall conduct penetration testing on all affected environments under Contractor control after every breach and data breach unless directed not to do so in writing by the SCDMV. The Contractor shall work with the SCDMV to conduct penetration testing on all affected environments that are not under Contractor control after every breach and data breach. (Also see 3.3.3 System Security, item 6. Regular Vulnerability Testing.)
a. The Contractor shall consult the SCDMV when determining which environments require penetration testing.
b. The Contractor shall support third-party assessments of the environments.
c. The Contractor shall provide a FedRAMP moderate certification to the
SCDMV after each penetration test following a breach or data breach.
d. The penetration test requirements after a breach or data breach are in addition to the annual penetration tests performed by the SCDMV.
e. The Contractor shall update the system recovery and disaster recovery plans after any breach or data breach.
11. Updating System Recovery and Disaster Recovery Plans – Unless instructed by the
SCDMV otherwise, after every breach and data breach the Contractor shall review, update, and submit for State review and approval, the system recovery and disaster recovery plans.
a. The Contractor shall include lessons learned from the breach or data breach when updating the recovery plans.
b. The Contractor shall include what is being done differently or is now being done.
Appendix 13 - Technical Requirements Revision 1 Page 18 of 44
c. The Contractor shall identify the steps being taken to ensure the breach or data breach does not happen again.
d. The updating of system recovery, disaster recovery, and business continuity plans shall be in addition to the updates that take place as part of periodic reviews.
12. Complying with State Policies, Procedures, and Standards – The Contractor shall comply with all State policies, procedures, and standards regarding breaches
3.3.2 Access Security
1. Active Directory – The modernized system shall utilize SSO based on either
Microsoft Active Directory or Azure AD to maintain an up-to-date directory of all personnel who currently use or access the SCDMV modernized system and/or databases by user’s role.
2. Multiple Role Types – The modernized system shall accommodate access for customers and provide SCDMV employees multiple user roles: DL holder, SCDMV employee, etc. Conditional Access should be configured to limit public and admin access.
3. PII – The modernized system shall protect the security of any user access to personally identifiable information (PII), collected pursuant to the REAL ID Act, in accordance with 6 CFR § 37.41(b)(2).
4. Secure Access and Multifactor Authentication for the Install Base – The modernized system shall allow the Install Base (SCDMV employees on-premises or remote) to log into the modernized system using multifactor authentication (MFA).
On successful entry of the ID and Password, the modernized system shall require additional authentication credentials (the defaults for the Install Base are RFID and fingerprints [primary], tokens and passphrase [secondary]) and on entry of additional authentication credentials, provide access to the modernized system through multi-factor authentication. The specific logon and multifactor authentication methods allowed will be determined by the DMV during the initial project scoping calls.
5. Secure Customer and Partner Access and Multifactor Authentication – The modernized system shall allow Customers and Partners to log into a Web-Based Transaction Center (see functional requirements, Web-Based Transaction Center) using a secure ID and password. As required by the modernized system for some or all access, the system shall implement multifactor authentication. On successful entry of the ID and Password, the modernized system shall send a secondary authentication credential to the client’s preferred communication method (e.g., phone text, email) and on entry of the authentication code, provide access to the modernized system through multifactor authentication. The Contractor shall recommend an option for off-premises users, businesses, partners, customers, and
Appendix 13 - Technical Requirements Revision 1 Page 19 of 44 others that are not in the Install Base. The SCDMV reserves the right to require the Contractor to integrate with the SCDMV’s MFA solution.
6. Access to Functionality Before Authentication – The modernized system shall allow read-only access to static-only content available on the Website.
7. Failed Login Attempt Lockout – The modernized system shall enforce a configurable limit of consecutive invalid access attempts by a user and implement appropriate protections to protect against further, possibly malicious, user authentication attempts using an appropriate mechanism (e.g., locks the account/node until released by an administrator, locks the account/node for a configurable period, or delays the next login prompt according to a configurable delay algorithm) and support defined State and SCDMV policies. In addition to account lockout thresholds, rate limiting should be used where possible to counter brute force attacks.
8. Warning Banner – The modernized system shall display a configurable pre-login banner or warning (e.g., “System shall only be accessed by authorized users”) before accessing any PII. If the modernized system does not support pre-login capabilities, the modernized system shall display the banner immediately following authorization. The user shall be required to acknowledge acceptance of the terms and conditions in the configurable banner before any PII is accessed.
9. Anti-Malware Compatibility – The modernized system shall be compatible with and operate on workstations configured with anti-malware software per State and SCDMV standards.
10. Compatibility With Security Monitoring Solutions – The modernized system shall be compatible with and operate on workstations configured with security monitoring software per and SCDMV standards.
11. Access Logging – The modernized system shall have appropriate logging parameters enabled to automatically monitor and record:
a. authorized and failed access attempts, including failed access related to information systems, and enforcing multi-factor authentication.
b. password changes, privilege escalation.
c. use of administrative privileges and third-party credential usage.
d. critical information security events as recommended by the operating system and application manufacturers.
e. user access activities.
f. system exceptions.
12. Inactive User Session – The modernized system upon detection of user inactivity shall prevent further viewing and access to the modernized system by that user/session and terminate the session or initiate a session lock that remains in effect until the user reestablishes access using appropriate identification and authentication procedures. The length of inactivity shall be configurable.
Appendix 13 - Technical Requirements Revision 1 Page 20 of 44
13. Passphrase Rules and Access Configuration – The modernized system shall be configurable to enforce the following rules regarding personal access:
a. Configurable minimum passphrase length
b. Configurable failed login lockout threshold
c. Configurable not reusable passphrase history
d. Configurable passphrase complexity
e. Configurable lockout duration
f. Configurable lockout tiers (e.g., increasing lockout durations and then permanent lockout).
14. Passphrase and Password Encryption – The modernized system shall encrypt all passwords and passphrases using FIPS 140-3.
15. Single Sign-On – The modernized system shall provide the ability to integrate with:
a. Microsoft Active Directory for Install-Base users.
b. Azure-AD for non-Install-Base users.
16. Compatibility – The modernized system shall work with and be compatible with these additional products used in the SCDMV environment:
a. Virtual Private Networks (VPN)
b. Session Shadowing
c. Remote Desktop Access
d. Recording user workstation sessions and associated phone calls
3.3.3 System Security
1. FedRAMP Moderate – The modernized system shall comply with FedRAMP (Federal
Risk and Authorization Management Program [FedRAMP®]) moderate and provide proof of continuous compliance with FedRAMP moderate.
2. Full Stack Compliance – All components of the modernized system shall meet the FedRAMP moderate requirement and shall be certified as a complete system.
a. Ensure that all components of the modernized system and data are physically located within the contiguous US. Ensure that support personnel for the modernized system support personnel are U.S. Citizens or meet USCIS Form I-9 requirements.
b. Ensure all system support personnel for the modernized system are physically located within the contiguous US.
3. SSA Security – The modernized system shall maintain compliance with all SSA controls per the latest version of TSSR (Technical System Security Requirements).
4. Certifications – The Contractor shall maintain the FedRAMP moderate certification for the fully implemented modernized system and routinely provide the certification(s) on an annual basis to the SCDMV.
Appendix 13 - Technical Requirements Revision 1 Page 21 of 44
5. System Audit – The Contractor shall submit the modernized system to a security audit annually, cooperate in State and SCDMV audits, and provide audit results available for evaluation purposes. The State and SCDMV will determine the scope of the audit. Audits shall be based on the requirements of the FedRAMP Moderate certification.
a. The modernized system shall work with the State and SCDMV tools, scans, and monitoring mechanisms.
b. The Contractor shall propose to the SCDMV, subject to State review and approval procedures, best practices that use third-party tools and APIs that allow third parties to perform risk assessments on data in the cloud.
c. The Contractor shall provide a mechanism for third parties to be able to evaluate the system’s security posture by accessing system logs, an API hook, or other mechanisms. This access will allow an authorized third-party or the SCDMV to assess the system ensuring that it meets security requirements.
d. System logs should be compatible with the State SIEM, Security should have access to raw logs. Logs should be in UTF8 format where possible and set for UTC -5 or UTC-4 during daylight saving hours.
e. The modernized system must work with all SCDMV designated third-party security tools such as network scanners, network monitors, and Cloud Access Security Broker (CASB) services.
f. The modernized system shall be designed and built to allow a third- party to evaluate and assess the system using secure APIs.
g. The Contractor shall have an independent audit firm perform a FedRAMP Moderate Compliance Assessment.
h. The Contractor shall work with an independent third-party selected by the SCDMV to perform an annual security assessment and penetration test.
i. The Contractor shall support the SCDMV with any information and access necessary for any other audits or assessments.
6. Vulnerability Testing – Prior to beginning any activity involving SCDMV data, information, identities, or systems, the Contractor shall have established policies and procedures to implement and maintain mechanisms for regularly performing vulnerability testing of the operating system, application, databases, content storage, payment systems, and network devices. All policies and procedures established by the Contractor shall be submitted to the SCDMV for review and approval. The Contractor shall follow the approved policies and procedures, working with an independent third-party selected by the SCDMV to perform an annual security assessment and penetration test.
7. Vulnerability Testing Identifies – In addition to supporting SCDMV vulnerability testing, the Contractor shall ensure their regular vulnerability testing identifies:
a. device or software misconfigurations
Appendix 13 - Technical Requirements Revision 1 Page 22 of 44
b. missing software patches
c. outdated software versions
d. validate compliance with or deviations from the software provider’s security policy.
8. Regular Patching – The Contractor shall:
a. have at least industry minimum acceptable standard policies and procedures for patching and then scanning.
b. follow the patching and scanning policies and procedures.
c. address updating all environments as part of the patching and scanning policies and procedures.
9. Vulnerability Analysis – The Contractor shall develop a vulnerability mitigation strategy.
a. evaluate all identified vulnerabilities for potential adverse effects on the system’s security and integrity and remediate the vulnerability promptly or document why the remediation action is unnecessary or unsuitable.
b. unless otherwise specified by other agency requirements and standards, vulnerability testing shall be conducted: (1) at least once monthly for a high-level general assessment of the internal and external environment; and (2) at least annually for a comprehensive assessment.
c. provide details of all assessments to be proposed by the Contractor in the RFP response.
3.3.4 Security Log/Audits/Reports
1. Capturing All Activity – The modernized system shall log all activities, including user access activities, authorized and failed access attempts, system exceptions, and critical information security events necessary to implement and achieve security, business operation monitoring, system performance, and other standards.
2. Capturing Events for DMV Policy Compliance – The following events shall be captured for activities that involve accessing or modifying customer PII, based on DMV policies that align with SSA controls:
a. Name changes
b. Date of birth changes
c. Social security verifications
d. Social Security Number changes
e. Social Security Number unmasking
f. Viewing Social Security verification results
g. Viewing the unmasking report
h. Those events identified in the latest version of the SCDMV's Audit and
Accountability Policy.
Appendix 13 - Technical Requirements Revision 1 Page 23 of 44
3. Capturing Events for DMV Security Policy Compliance – The following events shall be captured for activities that involve accessing or modifying customer PII, based on DMV Policy:
a. Address changes
b. Height and weight changes
c. Those events identified in the latest version of the SCDMV's Audit and
Accountability Policy
d. In the future, information such as preferred payment information, email address, telephone number, and biometric information
4. PII Logging – The modernized system shall capture (at the application level) activities that involve accessing or modifying customer PII:
a. Name changes
b. Date of birth changes
c. Social Security verifications
d. Social Security Number changes
e. Social Security Number unmasking
f. Viewing social security verification results
g. Viewing the unmasking report
h. Those events identified in the latest version of the SCDMV's Audit and
Accountability Policy
5. Configurable Logging – The modernized system shall be configurable to allow the
SCDMV to specify the transactions that are logged and the information that is logged.
6. Activity Log Data – The modernized system shall support activity logging based on selectable event criteria and producing audit reports that include, at a minimum, the following:
a. date and time the activity occurred
b. software/hardware component of the information system where the activity occurred
c. the type of activity that occurred
d. subject identity (e.g., user, device, process context) users include DMV worker identification, self-service user identities, power-of-attorney identities, and the identity of service providers under contract to work for others third parties (e.g., pickups), with authorized paperwork, that pick-up artifacts on behalf of others third-party testers dealer licensing
Appendix 13 - Technical Requirements Revision 1 Page 24 of 44
e. the source and outcome (i.e., success or failure) of the activity
f. IP address
g. dollar amount (if applicable)
h. Payment card information (if applicable) including Billing Name, Address 1, Address 2, City/State/Zip, Phone, Email, Pay Type, Card Type, Truncated Account No, Expiration Date, Order ID, Session No, FTrans No, RTrans No, Receipt Date, Receipt Time, DMV Amount, Credit/Debit Card Use Convenience Fees, and Total Charged, subject to all PCI Compliance requirements and NACHA rules. Adherence to these rules must be strictly enforced.
i. payment type (e.g., cash, check, payment card, Apple Pay)
j. signature (signature pad, e-signature, digital signature)
k. That data identified in the latest version of the SCDMV's Audit and
Accountability Policy
7. Event Log Data – The modernized system shall support event logging based on selectable event criteria and produce audit reports that include, at a minimum, the following:
a. Date and time of the event
b. Identity/logon ID of the user associated with the event
c. Source of the event
d. Success or failure of the event
e. Type of event
f. IP address
g. That data identified in the latest version of the SCDMV's Audit and
Accountability Policy.
8.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .