Att D - Infrastructure Overview.docx

DOCX document 44 KB Posted

Attached to
Payment Processing ServicesBid Documents State and local contract opportunity
Solicitation number
26-86377
Issued by
Marion County, Indiana

About this file

Infrastructure Overview - State of Indiana RFP

This is an Infrastructure Overview document outlining hosting requirements and solutions for a State of Indiana Request for Proposal managed by the Indiana Office of Technology. The document specifies mandatory infrastructure and support requirements for vendors proposing solutions where solution hosting is in scope. Vendors must select from four hosting solution categories: State-Owned Cloud Tenant (preferred), Vendor-Hosted Cloud Tenant (exception-based), On-Premises with Vendor-Provided Hardware (preferred), or On-Premises with State-Owned Hardware (exception-based). All proposed cloud-based solutions must comply with the Risk and Assurance Management Program (RAMP) policy aligned with NIST 800-53 Revision 5 standards, which is expected to be finalized by October 14, 2025. The State strongly prefers cloud-based service offerings deployed within state-owned cloud tenants provisioned through Microsoft Azure or Amazon Web Services under Indiana's enterprise agreements.

For State-Owned Cloud Tenant deployments, the State retains full ownership and administrative control with all data residing within the state-owned environment, while vendors are responsible for installation, updates, management, security implementation, and Day 2 support and maintenance operations. Vendors proposing alternative hosting solutions must provide compelling justification and demonstrate independently verified compliance with NIST 800-53 Revision 5 or a detailed compliance roadmap. On-premises solutions require vendors to either procure and maintain hardware within Indiana datacenters or manage solutions on state-owned infrastructure, with full responsibility for lifecycle management, documentation, performance reporting, and service levels as outlined in the IOT-Services-Catalog. Vendors must identify all assumptions in their proposals and provide detailed explanations; if solution hosting is not in scope, vendors should respond with "N/A" to the technical proposal questions.

View the file

Other files for this state and local contract opportunity

Other files attached to Payment Processing ServicesBid Documents, newest first.
File Type Posted
Att B - Q&A Template.xlsx XLSX spreadsheet
RFI 26-86377 Main Document.pdf PDF
Att C - AI - Technical Questions.docx DOCX document
Att A - Response Template.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment D - Infrastructure Overview NOTE: The following Infrastructure Overview language applies if solution hosting is in scope for your response to this RFP.

The State strongly prefers a cloud-based service offering. Cloud-based service offerings are required to be within a state-owned cloud tenant. However alternative solutions may be considered if they demonstrate significant value. This section provides details on infrastructure and support requirements, outlining the State’s minimum requirements.

Please note that any proposed cloud-based service offerings submitted in response to this RFP will need to comply at the time of solution implementation with the Risk and Assurance Management Program (RAMP) policy that is currently being developed in order to comply with a recent executive order that was handed down by Governor Mike Braun, EO 25-19. The new policy will be based on commonly accepted industry practices and standards like NIST 800-53 Revision 5 and is expected to have tiered levels of security requirements which will depend on the type of data involved, its sensitivity, and how the solution interfaces with State resources. The program and subsequent continuous monitoring requirements outlined in the policy are expected to align closely with StateRAMP dba GovRAMP best practice and is expected to be finalized and implemented by October 14, 2025. Prospective vendors should keep all the foregoing in mind as they prepare their proposals and be confident that any proposals they ultimately choose to submit are flexible enough to accommodate commonly accepted industry practices and standards in the typical state government-required RAMP. Please visit the RAMP Cybersecurity Frequently Asked Questions page for additional information.

Solution Categories If solution hosting is within scope, the vendor must propose one of the following hosting solutions:

1) State-Owned Cloud Tenant (Preferred Cloud Solution) Definition: A vendor hosted solution deployed within a cloud environment owned and managed by the State. This environment is provisioned in either Microsoft Azure or Amazon Web Services (AWS) under the State’s enterprise agreements. The Indiana Office of Technology will set up a cloud tenant that the vendor will use to support all aspects of the solution with oversight and minimal support from the Indiana Office of Technology.

Minimum Requirements

· Tenant Ownership and Access:

· The State retains full ownership and administrative control over the tenant.

· The vendor shall be granted access only to the resources necessary for the deployment, configuration, and maintenance of the solution, as explicitly authorized by the State.

· The State owns the financial consumption charges within the State-Owned cloud tenant.

· Data Residency and Compliance:

· All data associated with the solution must reside within the State-owned tenant.

· The vendor must ensure compliance with all applicable State and federal regulations, including but not limited to data security, privacy, and sovereignty requirements.

· Deployment and Management:

· The vendor is expected to install, update, and manage the application and other unique aspects of the solution during the project to meet the requirements and as part of Day 2 support / Maintenance and Operations.

· https://www.in.gov/iot/iot-vendor-engagement/htThe vendor must utilize state approved tenant specific native tools and services for monitoring, backup, and disaster recovery, as specified by the State.

· Security and Access Controls:

· The vendor shall implement robust security measures, including role-based access control, encryption, and multi-factor authentication, in alignment with Information Security Framework (https://www.in.gov/iot/iot-vendor-engagement/).

· Security documentation and audit logs must be provided to the State regularly.

· Security assessments, including vulnerability scans, must be conducted and reported to the State.

· Exit Strategy:

· Upon contract expiration or termination, the vendor shall ensure a seamless transition of all resources, configurations, and data back to the State, without disruption to ongoing operations.

· A detailed exit plan must be submitted within 120 days of contract expiration or termination, including but not limited to timelines and responsibilities, to facilitate this transition.

2) Vendor Hosted Cloud Tenant (Exception Based Cloud Solution) Definition: A vendor managed cloud environment outside of the State’s enterprise agreements.

Justification and Minimum Requirements:

Exceptions to the requirement of utilizing a state-owned cloud tenant will only be considered if there are compelling reasons and justifications as to why hosting in a State-owned cloud tenant is not feasible. The State will evaluate these justifications but is not obligated to agree with any external cloud hosting options and the associated scoring will reflect that.

If proposing a hosted solution that does not use a State-owned cloud tenant, your company is required to, at a minimum:

· Provide a clear justification for why hosting within a state-owned cloud tenant is not feasible.

· Demonstrate independently verified compliance with NIST 800-53, Revision 5 (or the most current version at the time of proposed solution go-live).

· Alternatively, provide a detailed plan that includes independent verification of your company's path toward achieving compliance with NIST 800-53, Revision 5 (or the current version at the time of proposed solution go-live).

· Adhere to the applicable security standards, policies and requirements as outlined by the IOT Cloud Provider Questionnaire, Software as a Service (SaaS), Platform as a Service (PaaS), and Infrastructure as a Service (IaaS) Terms outlined within this procurement.

3) On-Premises Solutions - Vendor Provided Hardware (Preferred On-Premises Solution) Definition: A vendor provided hardware solution deployed within the States data center.

Minimum Requirements

· The vendor is responsible for procuring, deploying, and maintaining hardware hosted within the State of Indiana datacenters.

· Ensuring that all hardware aligns with the State’s standards and specifications, as outlined the State’s established policies and enterprise standards that collectively constitute the Information Security Framework (https://www.in.gov/iot/iot-vendor-engagement/).

· Meeting the service levels, security protocols, and cost expectations detailed in the "Hosting" section of the IOT-Services-Catalog.pdf.

· Providing full documentation of hardware lifecycle management, including installation, updates, maintenance, and upgrades as needed.

· Ensuring compatibility with existing state systems and providing any necessary adjustments for seamless integration.

· Delivering comprehensive reporting on hardware usage, performance metrics, and any troubleshooting activities during the contract period.

4) On-Premises Solutions – State Owned Hardware (Exception Based On-Premises Solution) Definition: A vendor managed solution operating on state owned infrastructure.

Minimum Requirements:

· Collaborating with the State to ensure a seamless initial setup, including installation, configuration, and integration with the State’s systems.

· Adhering to the service levels, security requirements, and cost structures outlined in the "Hosting" section of the IOT-Services-Catalog.pdf and as outlined within the Information Security Framework (https://www.in.gov/iot/iot-vendor-engagement/).

· Provide ongoing monitoring, performance optimization, data backup, and disaster recovery services to ensure system reliability and availability.

· Coordinating with the State on any necessary warranty claims or hardware replacements, including detailed reporting and documentation of hardware issues and resolutions.

· Transferring knowledge, if applicable, to the State to facilitate collaboration and long-term operational continuity.

TECHNICAL PROPOSAL QUESTIONS

NOTE: The following Infrastructure Overview language applies if solution hosting is in scope for your response to this RFP. If solution hosting is not in scope, respond with “N/A” in both response areas below.

The State strongly prefers a cloud-based service offering. Cloud-based service offerings are required to be within a state-owned cloud tenant. However alternative solutions may be considered if they demonstrate significant value. Please see the Infrastructure Overview section in the RFP document for detailed requirements information.

Cloud-Based Service Offering Any cloud-based solution recommended by vendors should use a State of Indiana-owned cloud tenant. The State of Indiana will establish an appropriate cloud tenant for the solution as part of the design activities early in the project. The vendor is expected to install, update, and manage the application and other unique aspects of the solution during the project to meet State of Indiana requirements and as part of Day 2 support / Maintenance and Operations. The State of Indiana requires the receipt of the 1) financial consumption charges as part of the usage within the State of Indiana owned cloud tenant and 2) visibility into the security results throughout the life of the solution on the State of Indiana owned cloud tenant.

If your company is recommending an exception to using a State of Indiana owned cloud tenant as described in the Infrastructure Overview section of the RFP, provide a clear justification for why hosting within a state-owned cloud tenant is not feasible and describe your company's status and readiness for compliance with NIST 800-53, Revision 5 (or the current version at the time of proposed solution go-live).

Outline, in detail, your company's overall cloud-based service strategy, specifying:

· the hosting location

· your company’s agreement with the financial consumption and security visibility expectations if your company is recommending a solution hosted in a State of Indiana owned cloud tenant

· your company’s NIST 800-53, Revision 5 readiness if recommending a solution that is not hosted in a State of Indiana owned cloud tenant.

· all tools and software and their purpose as part of your company’s cloud solution during both project implementation and Maintenance and Operations throughout the life of solution.

Identify any assumptions made in your company’s response and provide a detailed explanation for each assumption to ensure a clear and mutual understanding of the proposed solution.

If not proposing a cloud service offering, respond with “N/A” in the response area below.

[Cloud-Based Service Offering Response Area]

On-Premises Service Offering If proposing an on-premises service offering, please describe your approach to delivering on-premises-based services for the two scenarios outlined in the Infrastructure Overview section of the RFP. Include details on how your solution will address the scope of services, service levels, and costs as defined in the “Hosting” section of the IOT-Services-Catalog.pdf. Additionally, provide examples of similar projects your company has successfully implemented to demonstrate your capability.

Identify any assumptions made in your company’s response and provide a detailed explanation for each assumption to ensure a clear and mutual understanding of the proposed solution.

If not proposing a on-premises service offering, respond with “N/A” in the response area below.

[On-Premises Service Offering Response Area]

File details come from the government source that posted it. Updated .