Attach 1_ICDE Working Group Minimum Requirements.pdf
PDF 346 KB Posted
- Attached to
- DEA Investigative Case and Data Ecosystem (ICDE) Federal contract opportunity
- Solicitation number
- DEA-ICDE-2026
About this file
This document is a detailed Requirements document for an Integrated Case Management System (ICDE) for the Drug Enforcement Administration (DEA), dated September 29, 2025. The comprehensive requirements span multiple functional areas including case management, reporting, evidence tracking, analytics, cloud infrastructure, security, system configuration, data migration, and support. The system must provide robust capabilities for managing case lifecycles, tracking evidence, generating reports, supporting investigations, and maintaining strict security protocols with features like two-factor authentication, role-based access controls, and compliance with federal security standards like FedRAMP High.
Key technical requirements include the ability to integrate with multiple existing DEA systems, support dynamic reporting and data visualization, enable advanced analytics with geospatial mapping and trend analysis, provide cloud-based infrastructure with scalability and geographic redundancy, and ensure comprehensive data migration from legacy systems. The document outlines extensive requirements for system administrators, including configurable user roles, code table management, and the ability to modify system parameters without disrupting operations. Additional critical features include 24/7/365 support, multiple training environments, government ownership of training materials, and ongoing documentation and product update support.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFI-Investigative Case Mgmt Data Ecosystem_UPDATE.pdf | ||
| RFI-Investigative Case Mgmt Data Ecosystem_UPDATE.pdf | ||
| ICDE RFI Question Matrix.xlsx | XLSX spreadsheet | |
| RFI - Investigative Case Management Ecosystem_Final.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Contents Case Management
Case Mgt. System - Reporting Case Mgt. System - Supplemental Reports Case Mgt. System - Task Management Case Mgt. System - Case Management General Case Management System ...................................................................................... Error! Bookmark not defined.
Case Management System Investigation Assignment Case Monitoring Criminal Organization Management Case Mgt. System - Drug and Nondrug Evidence Case Mgt. System Case Mgt. System - Data Sharing Case Mgt. System - UCR/NIBRS ........................................................................................... Error! Bookmark not defined.
Case Mgt. System - System Administration Case Mgt. System - Technology Operational Plan Requirements Case Mgt. System - Diversion Control Requirements
Analytics
Analytics (Detailed examination of events) Do they belong in CMS- inside or outside of this system?
ICDE Requirements Minimum System Requirements
Updated September 29, 2025
Ability to analyze activity using the following options, including, but not limited to:
Ability to present statistics visually, including, but not limited to the following:
Data Aggregation Visualization (map-data collection) map overview (case orientation) Dashboards and Alerts
Cloud
Security
System Security
System Configuration
System Admin Configuration Capabilities Data Migration
Support
SUPPORT
TRAINING
Feature Description Tier 1 Requirement
Tier 2 Requirement
Case Mgt. System – Reporting CMS has the ability to manage case life cycle: open, active, pending, closed etc.
1. Case Mgt. System supports ability to populate all reports and Case Mgt. System supports ability to populate all reports. already in the system-enterprise data warehouse (EDW) Y
2. Case Mgt. System supports ability to standardize information in the field reporting application according to parameters established in the Case Mgt. System (names, addresses, dates, phone numbers etc., EDW)
Y
3. Case Mgt. System supports standardizing name data and customization to include associates, criminal organizations, weapons, etc. and configure drop-down menus. Y
4. Case Mgt. System reports dynamically update as information is changed in system fields Y
5. Case Mgt. System supports ability to provide a calendar date select (e.g. to enter a date, user opens a calendar and clicks on the appropriate date) when entering dates in the report writing application.
Y
6. Case Mgt. System provides the ability to redact and/or expunge specific information or documents. Y
7. Case Mgt. System supports limited edits to reports after supervisor approval (e.g. spelling, grammar, UCR & NIBRS code corrections). Y
8. Case Mgt. System provides in-app, basic word processing functionality to include spell-check, bold text, bullets, and font adjustments. Y
9. Case Mgt. System allows for text from MS Word documents to be pasted into the Case Mgt. System, maintaining original formatting. Y
10. Case Mgt. System attachments of media files and documents allow for descriptive metadata to be input & searchable. Y
11. Case Mgt. System provides easy-to-read reporting on system user activity including timestamps. Y
Case Management
Tier 2 Requirement
12. Case Mgt. System launches additional queries from a record or list of records (drill down).
For example, a search on a person's name in Case Mgt. System would return multiple possible matches with each name offering a hyperlink to additional information.
Y
13. Case Mgt. System provides a mechanism that helps reduce possibility of users in adding new minimum number of individuals to the system. (related to #14) Y
14. Case Mgt. System supports single and secondary approval process. Y
15. Case Mgt. System supports Supervisor review of incomplete reports in progress from assigned personnel/users Y
16. Case Mgt. System includes a tool to electronically redact text from records. Y
17. Case Mgt. System supports ability to create pick lists/drop-down menus, edit pick lists in existing reports, Case Mgt. System, or modules Ad Hoc; fields must be able to capture data for analytical use.
Y
18. Case Mgt. System enables users to switch from writing a report to searching the system without having to log out or switch applications/systems Y
19. Case Mgt. System search functionality supports ability to query narrative field for all reports or any module or any module that contains free-form text. Y
20. Case Mgt. System supports ability to add/generate a supplemental report and linked to the primary incident report after the initial case report has been submitted and approved) Y
21. Case Mgt. System supports a day/night mode. Y
22. System administrators can configure report narrative templates (tier 1) that prompt (drop down menu-tier 2) users to enter report-required information in the narrative. Y
Case Mgt. System - Supplemental Reports
23. Case Mgt. System ability when writing a supplemental report to view the original report. Y
24. Case Mgt. System supports ability to restrict the number of reports in draft status and configure existing fields and/or add fields as needed. Y
Case Mgt. System - Task Management
Tier 2 Requirement
25. Allow users to assign other users tasks, e.g. perform polygraph, contact victim(s), etc., trigger in-app and email alert(s) to assigned user. Y
Case Mgt. System - Case Management
26. Case Management System ability to add users to cases at any time regardless of report status; remove or add multiple users. Y
27. Case Management System ability to create tasks. Y
28. The ability to cross-reference reports-transmit reports enterprise-wide from within the Case Management System. Y
29. Case Management System ability for users to electronically send reports to a supervisor. Y
30. Case Management System ability for reports to be automatically sent to a supervisor based on built-in Agency business logic (e.g. crime type.) Y
31. Case Management System ability to link all associated reports (e.g. case report, supplemental reports, investigation reports.) Y
32. Case Management System ability to update and notify an agency-defined user when a supplemental report is added to an assigned case. Y
33. Case Management System ability to provide narrative fields associated with each case. Y
34. Case Management System ability to provide an audit trail of all case-related activity. Y
35. Case Management System ability to categorize case types (i.e., Crimes Against People, Crimes Against evidence. Y
36. Case Management System ability to create folders and subfolders with standardized naming conventions within cases for attachments and notes for ease of management. Y
37. Case Management System ability to save select contents of working file as final case file. N
38. Case Management System ability for a user to place an alert (define type) on any data point or element in the EDW for open cases (e.g. person, location, vehicle. Y
39. Case Management System ability to create an alert to determine when additional action is due per policy (e.g. supplement report is due within 30 days of assignment.) Y
Tier 2 Requirement
40. Case Management System ability to provide dedicated fields to track case disposition. Y
41. Case Management System ability to systematically inform evidence and evidence of agency-defined changes to evidence dispositions. Y
42. Case Management System ability to link external links/URLS (e.g. YouTube, social media sites) Y
43. Case Management System ability to protect cases (unrestricted, restricted, prohibited) Y
44. Case Management System ability to track workload activity of each specialty unit. Y-Tier 2
45. Vendor shall utilize Human Centered Design (HCD), agile methodologies, and Ux and Cx tools to understand, refine, and implement an effective case management system. Y
Case Management System Investigation Assignment
46. Case Management System ability for supervisors to review and reassign cases to other users and groups Y
47. Case Management System ability to link multiple reports based on single case number or multiple case numbers. Y
48. Case Management System ability to assign a case sent for informational purposes. (e.g., OCDETF) Y
49. Case Management System ability to Grant/Restrict Access to Cases Y
50. Case Management System ability for a supervisor to electronically assign case responsibility to a user Y
51. Case Management System ability to assign multiple users to a case. Y
52. Case Management System ability to distinguish roles for users (e.g. primary, secondary.) Y
53. Case Management System ability to assign review dates with an investigation assignment (e.g. upon assignment, user has ten days to contact complainant.) Y
54. Case Management System ability to query case activity based on expired policy reporting requirements scheduled to expire within a date range (e.g., 5 days to generate a DEA6). Y
Tier 2 Requirement
55. Case Management System ability for users to receive electronic notifications that they have been assigned a case. Y
Case Monitoring
56. Case Management System ability to track agency-defined system activities. Y
57. Case Management System ability for first and second-line supervisors to monitor users' workloads. Y
58. Case Management System ability for supervisors to view all activities, documents and attachments regarding a specific case. Y
SOD Added Requirements
59. Key word search within a DEA 6, 7, 7a Y
60. BIU specific need -to incorporate SARC process and tracking of SARC Y
61. Access entire case file -interface, refer to line 28, conceptualize the folder within a folder, access multiple files/documents(subfolders) within the case (ability to query and parce specific information)
Y
62. A drop down for FTO linkages (more than one cartel) export DEA 6’s with FTO connection with redaction capability (refer to line 17)
Y
63. Systems to incorporate: SOD app located currently on concord, funding for wires, many of the apps in concord now taken out of DARTS
Y
64. Standard queries, e.g., FINCN and SW Border queries, Subpoenas Y
65. Ability to fill a field where target activity is happening-where activity is actually taking place
(analytics) Y
66. Tracking of case types and investigative tools utilized with date stamp and query type Y
67. Incorporate the SOD case system investigative assistance (i.e./similar to the Nemesis of
DC) Drop down menus allowing for the selection of specific tools or assistance Y
68. System availability (for agents) to request external (DoD CTF) analytic support as part of the drop-down box functionality
Y
SARC/AGEO Added Requirements
Tier 2 Requirement
69. AGEO application (API-linked) to the ICDE Y
70. Ability to integrate with SARC/AGEO application Y
71. Drop downs for money flows (e.g., financial institutions) Y
72. (FO) Financial Operation drop down box Y
73. Standardization of inputs (target), deconfliction with Y
NADDIS Y
74. Current money laundering needs updates Y
Criminal Organization Management
75. Case Mgt. System provides ability to flag criminal organization records in the Master Name
Index such as confirmed, suspected or affiliated criminal organization member. (NADDIS) Y
76. Case Mgt. System provides ability to set or remove a flag on confirmed or suspected criminal organization records in Master Name Index. Y
77. Case Mgt. System provides ability to retrieve criminal organization information when query returns a name flagged with a criminal organization record. Y
78. Case Mgt. System provides ability to label individual as a criminal organization member, associate or affiliate. Y
79. Case Mgt. System provides dedicated fields to capture criminal organization-related data such as member name, criminal organization affiliation/classification, ethnicity, moniker, PII, vehicles, etc.
Y
80. Case Mgt. System supports ability to provide dedicated fields to add safety cautions/threats. Y
Case Mgt. System - Drug and Nondrug Evidence
81. Case Mgt. System Drug and Nondrug Evidence module must be fully integrated to allow for the tracking of chain of custody from seizure to final disposition. Y
82. All evidence entered in the Case Mgt. System must only be entered once with a unique serial identifier and carried through to all other Case Mgt. System modules that utilize the information (including Case Mgt. System Evidence and Evidence module.
Tier 2 Requirement
83. Evidence information entered within other Case Mgt. System modules (e.g. Offense and Supplemental Reports, Arrest, Field Reporting, etc.) must flow seamlessly to appropriate fields within Case Mgt. System Evidence module without requiring the re-entry of any information.
Y
84. Case Mgt. System Evidence module allows for the entry and submission of articles prior to report approval or closure. Y
85. Case Mgt. System Evidence module allows multiple personnel to enter articles concurrently from different workstations (both networked and mobile.) Y
86. Case Mgt. System must provide data entry screens that allow the user to enter vehicle information for vessels, cars, motorcycles. For each vehicle, the system must capture the identifying information appropriate for the vehicle type (e.g. vessels, cars, motorcycles).
Y
87. Case Mgt. System Evidence provides ability for a user to indicate the type of processing requested (e.g. DNA, ballistics testing, fingerprinting.) Y
88. Case Mgt. System Evidence module enables a user to request evidence lab processing (ability to request an expedited analysis) upon submitting evidence. Y
89. Case Mgt. System includes safeguards to ensure that procedures and laws governing the proper disposition are followed. Y
90. Case Mgt. System supports automated messaging for specific evidence/evidence-related events that require notification (for release, destruction, adjudication.) Y
91. Case Mgt. System Evidence module provides a means to store digital images of the item prior to the disposition. Y
92. Case Mgt. System Evidence module must store, display, and enable the editing of information pertaining to evidence items including, at a minimum: date, time, location of the event; agents(s) involved; description of the evidence; the quantity and value (estimated or known) of the evidence; serial numbers and other identification information (including owner-applied numbers); associated case numbers and case offense/crime type; item number; owner's name and contact information; release to owner date; evidence type and category or article codes; number of days held; destruction/disposal date; brand names;
manufacturer; models; and colors.
Tier 2 Requirement
93. Case Mgt. System Evidence module must support the upload, storage, and display of a (practically) unlimited number of photographs/images of evidence items. Y
94. Case Mgt. System Evidence module must be able to enter, modify, track and, provide data entry fields for all of Case Mgt. System Evidence data elements tracked by NCIC, and other reporting systems as required.
Y
95. Case Mgt. System Evidence module must support the association of a single evidence item to multiple cases and reports. Y
96. Case Mgt. System Administrators must be able to modify the validation codes used to validate evidence items entered into Case Mgt. System Evidence module without requiring any assistance from the Case Mgt. System vendor.
Y
97. Case Mgt. System evidence and Evidence module must be able to use bar coding technologies and radio frequency identification (RFID) to identify and track evidence and evidence items maintained in the Case Mgt. System. Y
Y
98. Case Mgt. System Evidence module must support a standard iOS or Android device to manage evidence and perform inventories. Y
99. Case Mgt. System Evidence module must support the scanning of a storage location in order to automatically enter the evidence item's location. Y
100. Authorized Case Mgt. System users (e.g. users) completing initial offense, supplemental, arrest and other Case Mgt. System reports that contain evidence must be able to print evidence tags/barcodes directly from their reports and affix the tags to the entered evidence items prior to their storage in a evidence room.
Y
101. Authorized Case Mgt. System users (e.g. evidence room custodians and clerks) checking evidence items into a evidence room must be able to print and affix evidence tags/barcodes to the checked-in evidence items prior to their storage in the evidence room.
Y
102. Case Mgt. System Evidence module must automatically fill in previously entered information that is known to the Case Mgt. System but allow authorized Case Mgt. System users to update any previously entered information. For example, it must not be necessary to indicate the person completing the last transaction if the Case Mgt. System already knows the name and ID of the person completing the transaction.
Tier 2 Requirement
103. Case Mgt. System users must be able to query Case Mgt. System evidence and evidence module database by case number, bar code ID, item ID, invoice number, current disposition, next action type, next action date, partial and full serial number, partial and full owner applied number, all EDW, people involved, evidence description, date and time range, and various combinations of all of these search criteria.
Y
104. Case Mgt. System users must be able to determine the evidence room status and location of evidence items associated with a case directly from the various reports comprising the case.
Y
105. Case Mgt. System users must be able to determine the evidence room status and location of evidence items associated with a case directly from query results listing reports and cases that have evidence that was entered into the Evidence module database.
Y
106. Case Mgt. System Evidence module must be able to automatically alert appropriate system users and groups of users prior to the time that the statute of limitations is exceeded for disposal of the evidence.
Y
107. Case Mgt. System evidence and Evidence module must support automatic disposition notification of certain evidence by notifying specific Case Mgt. System users or groups of users when evidence is eligible for disposition based upon the type of item, the type of associated case and the statute of limitations associated with the charges in the case, and elapsed time since the case was adjudicated.
Y
108. Case Mgt. System evidence and Evidence module must be able to create lists of evidence to be disposed of. Y
109. Provides the ability to process items for disposal in bulk with a single disposition that will apply to all impacted articles (e.g. all eligible narcotics can be processed for destruction at once.)
Y
110. Case Mgt. System evidence and Evidence module must be able to capture electronic signatures from individuals picking up evidence for various reasons including disposal, claimed by owner, and transfer to a different facility.
Y
111. Case Mgt. System evidence and Evidence module must provide tools to expedite completing evidence room and storage facility inventories. Y
Tier 2 Requirement
112. Authorized Case Mgt. System users must be able to display and print evidence room inventory lists that identify all items stored in the entire area or a user-specified subarea of an evidence room along with user-specified information about each of the items contained in the specified area.
Y
113. Case Mgt. System Evidence module provides support and documents whenever an article is scanned/recorded, the system depicts all prior scans and locations, along with associated article(s.)
Y
114. Case Mgt. System automatically updates historic location information when rooms, bins, or shelf numbers are changed. When users view the scan audit, the system will depict the original scan location.
Y
115. Case Mgt. System Evidence module must maintain "chain-of-custody" information for all evidence and evidence stored in the Case Mgt. System as evidence moves between the evidence room and various other locations such as labs, prosecutor's office, courts, etc.
When an article is moved, the system captures the date, time, ID of the person who moved it, and the purpose of the movement.
Y
116. Case Mgt. System Evidence module provides a complete audit trail for all item movements generated on demand or automatically at user-defined intervals. Y
117. Case Mgt. System Evidence module automatically generates random article numbers (on-demand or automatically at user-defined intervals) within a user-defined evidence/evidence article type (e.g. guns) for the purpose of conducting randomized and routine audits.
Y
118. Case Mgt. System Evidence module must be relationally cross-referenced to the NADDIS, EDW and other modules. Y
119. Case Mgt. System Evidence displays all evidence articles associated with NADDIS. Y
120. For multiple pieces of the same evidence category, the system will allow the user to enter an unlimited number of evidence records, choose to duplicate the entered record if needed, then update additional data elements that may be unique.
Y
121. Case Mgt. System Evidence module provides a check-in/check-out log to allow evidence movement to be tracked. Y
Tier 2 Requirement
122. Case Mgt. System will use automated messaging inside the system for specific evidence-related events and dispositions that require notification (e.g. release, destruction, adjudication.)
Y
Evidence Control Processes-added requirements
123. Incorporation of CERTS and IMPACT into 1 system Y
124. Automated Request: select multiple exhibit numbers for specific dispositions, from requestor to first line supervisor over to the evidence custodian with the ability to track the final disposition with witness acknowledgement.
Y
125. Automated request: request multiple exhibits to be submitted to evidence at one time request from the agent/ TFO through the first line supervisor to the evidence custodian with tracking of receipts and witnesses. (103)
Y
126. Create/digitize a printable label (e.g., case file #, seizing agent, witnessing agent, exhibit number, location of seizure, date, etc.,) with bar code, to be affixed on the bag
Y
127. Ability to print labels that reflect the re-opening and sealing of an evidence container with opened by, witnessed the opening, the date of opening, the date of sealing, by whom and witnessed by whom. The original bar code number will be placed on the label.
Y
128. Upon submission and receipt of the evidence custodian, if the evidence is submitted (or removed for purpose) outside of policy (e.g., 72 hr. policy), the system will send a notification so the first line supervisor and submitter request for justification of late submission. Remark notes and associated with that exhibit.
Y
129. Compatibility with evidence scanners (MSS software, DEA specific Android USB communicator app)
Y
130. Ability to assign locations to evidence in the vault (specific shelf location) Y
131. Ability to import DEA lab reports Y
132. Allowing attachments after approval through first line supervisor and ability to add and cross file can occur at any point in the submission Y
133. All new forms under one drop down or tab for forms (customization) Y
134. Ability to send overdue notifications for checked out exhibits/ prominent “past due” alerts early in the system Y
User friendly search criteria Y IN-added requirements
135. GS Alerts and red flags as to discrepancies -crosswalk with checklist for case file reviews Y
Tier 2 Requirement
136. Approvals, flags, notifications, audits Y
137. Build-in standardized reasons, justifications in a drop-down menu that can’t be defaulted Y
138. Standardized naming conventions for files Y
139. Agents and TFOs (lead Co-case agent) case coming due, close to 90 days or per policy Y
140. Record past due reports (90-day) ability to identify reviews, past dues, address red flags and notifications to supervisor Y
141. Visualization of trends and indicators, compiled in an audit feature, customize at each level; supervisor, programmatic, user Y
142. SAC dashboard visibility based on key elements inspected, customizable Y
143. Migrating current data, archiving cases Y
144. Communication between systems e.g. CERTS, UFMS (easier communication between platforms) Y
145. “Single pane of glass” solutions (integration) Y
146. Tracking external communications with external partners Y Case Mgt. System
147. Historical log with timestamps displaying when report was started, approved/denied.
Access reports in all states of existence, e.g. prior to revisions, supervisor approval, etc. Y
Case Mgt. System - Data Sharing
148. Forward individual and bulk documents and digital files to other agencies with first line supervisor approval (e.g., other law enforcement agencies, state attorney, etc.) and include an audit trail.
Y
Case Mgt. System - System Administration
149. Case Mgt. System Administrator-levels (e.g. account management and group access) to allow more than one person to serve as a system administrator. Y
150. Case Mgt. System Administration supports ability to add drop-down menu items, fields or check boxes to appear on designated reports, without incurring additional costs. Y
151. Case Mgt. System Administrator can configure report narrative templates that prompt users to enter report-required information in the narrative. Y
Tier 2 Requirement
152. Case Mgt. System Administration provides functionality to modify pick lists, drop-down menus, create rules, labels (e.g. Case Management System- names of criminal organizations, case types, pre-assign case related tasks by case type.) System Administrative functionality to modify pick lists, drop-down menus, rules, labels (e.g. Case Management System- names of criminal organizations, case types, pre-assign case related tasks by case type.)
Y
153. Case Mgt. System provides administrative functionality to add checkboxes ad-hoc for users to easily track things within reports, such as new initiatives (e.g., operational priorities, community events, related incidents, etc.)
Y
154. Case Mgt. System provides system administrative capability to add new evidence & evidence drop-off locations, configure barcode field requirements, and manage disposition types and time periods.
Y
155. Case Mgt. System Administration enables authorized administrators to define certain data entry fields as “mandatory" (to prevent users from submitting incomplete reports, evidence and evidence items, etc.)
Y
156. Case Mgt. System Administrator can add, modify existing, delete offense codes within the system, in advance of go-live/active date, without vendor involvement. Y
Case Mgt. System - Technology
157. Interconnect ability to other systems as needed via API Connection to ODBC and other communication methods; Open Database Connectivity (ODBC) and ability to extract to local machine or server on demand. (API with connection to ODBC, EDW)
Y
158. The Case Mgt. System can maintain records for a period of ten (10) years without noticeable performance decline. Y
159. The system is able to download system updates without requiring user intervention or degrading application performance. Y
160. The Case Mgt. System must be accessible with a standard web browser, such as Microsoft Edge or Google Chrome. Y
Operational Plan Requirements
Tier 2 Requirement
161. The Case Mgt. System has the ability for deconfliction and connectivity to internal and external system Y
162. The Case Mgt. System has the ability to build and document the threat assessment. Y
163. The Case Mgt. System has the ability to conduct mapping and deconflictions among multiple locations resulting in a map.(e.g., hospital, trauma center) Y
164. The Case Mgt. System has the allows users to configure maps with multiple pins and geo-fences around significant locations. Y
165. The Case Mgt. System has the ability to prepopulate target subject, photos and mugshots of people, names and associated data; phone numbers. Y
166. The Case Mgt. System has the ability to pre-identify operational team members Y
167. The Case Mgt. System has the ability to identify types of operation/ops plan Y
168. The Case Mgt. System has the ability identify safety and investigative tools used in Ops plan Y
169. The Case Mgt. System requires first and second line approval Y
170. The Case Mgt. System will restrict a specified number of draft plans per case file at one time. Y
171. The Case Mgt. System will have the ability to update the date of execution of an already approved Ops Plan with first line supervisor approval. Y
Case Mgt. System - Diversion Control Requirements
172. The data housed in the case management systems are accessed by internal users (DEA employees) through several Oracle and Java-based web applications, including: RICS, CSOS, ARCOS
Y
173. The Case Mgt. System shall have data integration-functionality with RICS (e.g., similar to pre-population of NADDIS Number and other core details) Y
174. The Case Mgt. System shall Integrate a separate tab (diversion landing page) for diversion users, all these systems linked inside the new case mgt. system (hyperlinked) Y
Tier 2 Requirement
175. The Case Mgt. System shall be linked and accessible to multiple diversion applications and modules (e.g., case support requests) Y
176. The Case Mgt. System shall link to the National Provider Index (NPI) identifier for physicians included on diversion-specific user landing page. Y
177.a. The Case Mgt. System shall have the ability to add tables and graphs inside the report.
Make it more than just a text editor Y
178.b. The Case Mgt. System shall Integrate with DARTS for deconfliction. The integration shall support data exchange and deconfliction process to ensure accuracy and safety in operations.
Y
RICS, ARCOS,
Suspicious Orders Reporting System (SORS and SORS II), Theft Loss Reporting (TLR), Chemical Transaction Analysis System (CTRANS), Quota Management System (QMS), Combat Methamphetamine Epidemic Act
(CMEA),
Toxicology Reporting (TOX), Unlawful Medical Products Internet Reporting Effort
(UMPIRE), RX
Abuse Online Reporting
Tier 2 Requirement
(RXAOR),
Industry Tip Report (TIP), and others such as
IRADD.
Controlled Substance Ordering System
(CSOS),
Manufacturer distributor Briefing Report (MDBR), Diversion Admin Case Tracker (DACT), Synthetic Drug Online Reporting (SDRS), Industry Tip Reporting (ITR), Diversion Control Intranet/ebster (DC), User Manuals
Tier 2 Requirement
Analytics (Detailed examination of events) Do they belong in CMS- inside or outside of this system?
179. Integrated function based on a template aggregating all data captured by the system into a statistical report e.g. reports). Y
Analytics
Tier 2 Requirement
180. Allow analysts to aggregate data and perform analysis on reports in all status e.g. draft, not submitted, not approved, approved etc. Y
181. Analytical functionality provides ability for all data stored in the system to be available for analysis through an analytical tool. Y
182. Ability for the user to select those modules and fields from which data is pulled for analysis. Y
183. Users can search for, and within, reports which are not yet complete or not yet approved so that draft or incomplete reports are searchable. Y
184. Ability to analyze data contained within user-generated reports via database query. Y
Ability to analyze activity using the following options, including, but not limited to:
185. Basic trend analysis (e.g. simple drug trends, simple arrest trends) Y
186. Basic frequency (e.g. frequency of arrests FTOs) Y
187. Basic geospatial analysis (e.g., analysis by user-defined geographical area). Y
188. Time analysis (e.g., by time, date, date range, etc.) Y
189. Comparative analysis (e.g., changes over time) Y
190. Simple relational analysis (e.g., seeking relationships between two data fields) Y
191. Complex relational analysis (e.g., seeking relationships among three or more data fields).
Y-Tier 2
Ability to present statistics visually, including, but not limited to the following:
192. Pin maps Y
193. Bar graphs Y
194. Pie charts Y
195. Density maps Y
196. Line graphs Y
197. Ability to save the output of an analysis. Y
Tier 2 Requirement
198. Ability to export the output of an analysis to printer, common file types: PDF or CSV/Excel file Y
Data Aggregation
199. Ability to aggregate data. For example, by date, range, time of day, day of week, geographic area, group, personnel, crime type. Y
200. Ability to correlate any data element from the EDW. Y
Visualization (map-data collection) map overview (case orientation)
201. Ability to plot case data on a map. Y
202. Ability to plot data from the EDW on the map. Y
203. Ability to drill down for incident details from any case plotted on the map. Y
204. Ability to drill down to retrieve information from the EDW from the map. Y
205. Ability to drill down to retrieve supplemental information (e.g., ops plan, hazards, case history) associated with a location. Y
206. Ability to drill down to retrieve supplemental information associated with an agency-defined parameter around the location (address, building, block, etc.). Y
207. Ability to produce animation of case types occurring over a user-defined period of time. Y-Tier 2
208. Ability for case animation to display on the map. Y
Dashboards and Alerts
209. Ability to have unique dashboards and templates by user profile. Y
210. Ability for users to save dashboards for future use by users or shared library. Y
211. Ability to incorporate the following features by bar graphs, geographic areas, summary totals, and changes over time/comparisons. Y
212. Ability for dashboards to update in real-time. Y
213. Analytical users with the associated permissions can set up analytical reports to be sent to users on a scheduled or ad-hoc basis. Y
Tier 2 Requirement
214. Ability to export statistical reports in multiple file formats (PDF, .CSV, Excel) and make available on the user's local machine. Y
215. Allow user selection of file format for exported reports. Y
216. Allow users option to export static files (i.e. PDF's) that contain all visual representations of underlying data displayed within dashboards. Y
Feature Description
Tier 1 Requirement
Tier 2 Requirement
217. System is able to operate in a cloud or hybrid cloud environment, able to be vendor-agnostic. Y
218. System supports ability to share records with other agencies by creating a link that will require credentials and share privilege-based system access rights with other agencies. Y
219. System includes cloud security and threat detection implemented and/or the ability to onboard with DEA. Y
220. Supports data sharing and separation management within a multi-tenancy environment. Y
221. System offers dynamic scalability. Y-Tier 2
222. System supports horizontal scaling in response to an anticipation of changes in usage. Y-Tier 2
223. System supports vertical scaling in response to or anticipation of resource intensive temporary processes. Y-Tier 2
224. System can be securely hosted on cloud infrastructure designated for Government within the Continental Unites States. Y
Cloud
225. System offers industry standard, cloud-native platform that provides reliability and operational efficiency. Y
226. Provides on-demand user audit functionality. Y
227. System is accessible from a modern browser and requires no vendor-specific client-side software. Y
228. System is accessible from multiple devices, (e.g. desktop, laptop, mobile device, tablet, etc.) Y
229. System is developed, owned, hosted and maintained within the continental United States. Y
230. System meets FISMA/FIPS/DOJ compliance requirements. Y
231. System provides automated backup services. Y
232. System provides data restoration services in the event of an outage. Y
233. System provides for disaster recovery/failover in the event of hardware or communication failure at the data center. Y
234. System provides the ability for agencies to have multiple tenants configured, e.g., production, training, test, etc. Y
235. System supports simultaneous application window use. For example, user can have multiple queues or records open for viewing and editing at the same time. Y
236. System uses data encryption in transit, at rest, and between applications and databases. Y
237. System will auto-scale up or down as needed to meet the needs of the agency. Y
238. System provides the ability for unlimited storage and configuration of reports, records management and retention, document attachments, media files such as video, audio, images, etc.
Y
239. Cloud solution is deployed to multiple server locations that are geographically separated.
Tier 2 Requirement
System Security
240. System supports Active Directory and Okta authentication. Y
241. FedRAMP High Y
242. Ability for users who are not authorized to access sensitive information to see that the information exists but not view the actual information. Y
243. Ability to assign users to security groups, including multiple security groups.
244. System meets all applicable security policy requirements. Y
245. System supports single user credential access across System application. Y
246. System supports two-factor authentication. Y
247. Ability to create multiple security groups. Y
248. Ability to create temporary security profiles. Y
249. System provides IP Address control options. Y
250. Ability to lock down reports to specific users or roles Y
251. Ability to restrict user's permission to drill-down into query returns and hyperlinks. Y
252. After unsuccessful logon attempts, System automatically locks out the user per DEA policy. Y
253. Authenticated system users are able to initiate all system modules and externally interfaced systems they are authorized to access through a single login process. Y
254. In the event that there is a failure in the transaction auditing process, system has a method generating error logs, that there is a problem. Y
255. System is compatible with antivirus software. Y
Security
Tier 2 Requirement
256. System ATT and ATO system documentation as required Y
257. Provides a complete set of system documentation to include but not limited to: general design documents, data dictionary, system architecture, network architecture, file/table layouts, API's, and API documentation, and operational manuals). Y
258. System Accessibility: Authorized users must be able to perform any system task from any authorized workstation. Y
259. System is designed to backup data automatically to permit operational and application continuity should the system experience a single point of failure. Y
260. System Administrators are able to immediately disable a user account, a user group, or all users (except system admins) such that the user(s) is not able to log on to System. Y
261. System administrators can manage user roles from a central location. Y
262. System employs data encryption that meets all security policy standards for any exchange or transmittal of data Y
263. System accepts user profile updates from firebird and will maintain or merge historical data associated with the previous name appropriately. Y
264. System has a configurable user-security profile to control individual user access to the various modules, applications, functions, features, and data available within System. Y
265. System has management functionality to automate deployment of updates to all application clients (e.g., workstations and MDC's) and manage configuration settings. This includes application upgrades, releases and configuration settings. Y
266. System is able to track and maintain user sign-on and sign off times indefinitely. Y
267. System is compatible with utilities used for applying operating systems and third-party software testing/updates (e.g., Microsoft Windows updates.) Y
Tier 2 Requirement
268. System maintains a history of de-activated user IDs. Y
269. System must allow for adjustment, if required, of System time to change for Daylight Savings Time (DST) on all system components. Y
270. System will maintain audit logs of system activity. Y
271. The inactivation of user profiles does not delete records from system thereby enabling historical analysis of the activities completed by those individuals and profiles in system. Y
272. Ability to ensure all data and data transmissions are encrypted through approved standards. Y
273. Ability to manage data privacy, especially for information involving security clearances, polygraphs, and medical examinations/records Y
274.
Multifactor authentication
Encryption at rest and encryption in transit Data Minimization and protection of PHI and PII RBAC and ABAC Cybersecurity Auditing
275. Ability to integrate common cybersecurity tools (e.g., SIEM, EDR, vulnerability scanners)
276. Ability for Specific partner integrations (e.g., ServiceNow, Jira), if any Y
277. Ability for Integration with 3rd party AI vendors Y
278. Compliance with Privacy Documentation and proper protection of PII.
279. Ability to integrate with Trusted Internet Connection Architecture Y
Tier 2
Ability to Confirm FedRAMP and/or Impact Level (IL) authorization level.
Provide FedRAMP number Provide name of IL hosting agencies (if able)
280. Ability to provide non-proprietary security documentation to demonstrate compliance with FISMA, DOJ/DEA policies, HIPAA, and Section 508.
281. Ability to provide evidence of uptime SLAs, audit logs, data rights protections and incident history (if applicable).
282. Ability to integrate with Zero Trust Architecture Principles.
Y
283. Ability to manage vulnerability and patch management processes, focusing on the CISA BOD 22-01 and exploitable vulnerabilities.
284. Ability to provide continuous Monitoring Requirements.
Y
285. Ability to manage supply Chain Risk Management (SCRM).
System Configuration
Tier 2 Requirement
System Admin Configuration Capabilities
286. Ability for code table updates to propagate throughout the system (e.g. the ability to update program code and reference data) Y
287. Ability for the agency to define codes for drop-down-down menus. (e.g., attachment types) Y
288. Ability for the agency to maintain code tables without contacting the vendor. Y
289. Ability for the base system configuration to include all NCIC codes. Y
290. Ability for users who are not authorized to access sensitive information to see that the information exists, but not view the actual information Y
291. Ability to add to and/or edit reference tables as needed. (general) Y
292. Ability to add to and/or edit connect to existing database tables (e.g., oracle and SQL) Y
293. Ability to assign user group access permissions. Y
294. Ability to track previous and or new values to maintain historical data values and associated time periods (e.g., an offense from five years ago displays codes from five years ago). (provide use case scenarios)
Y
295. Ability to configure report approval workflows. Y
296. Ability to configure report review and approval queues/workflows. Y
297. Ability to create a new code and merge/link historical records to a new code. Y
298. Ability to designate code table values as obsolete and unavailable for current use, preventing further entry of that value, yet retain the value in the table for inquiries on historical data.
Y
299. Ability to make changes and additions to the code tables without modification to or recompilation of the application software. Y
300. Ability to prevent display of obsolete code table values on drop-down lists on entry. (on the front end) Y
Tier 2 Requirement
301. Ability to require users to enter values from a code table (e.g., prevent user from bypassing option.) Y
302. Ability to select obsolete code table values on drop-down lists when a historic record upon retrieval. (on the back end). Y
303. Ability to share code tables among application components. Y
304. Ability to store the date and code table value becomes effective. Y
305. Ability to support dependent code logic (e.g., if a Ford is selected, only Ford models are listed in associated data fields). Y
306. Add additional or remove if needed, report approval levels Y
307. Add contact information to the EDW including phone, address, email, and emergency contact information. Y
308. Adding, updating and removing or inactivating users Y
309. Administrators can lock down customizations of configurations. Y
310. Create user groups and can assign users to each group. Y
311. Data fields throughout the system can be made mandatory or optional. Y
312. If access is granted via role-based configuration, agency system administrators will have configuration control over roles, names, and access levels to include mobile. Y
313. System administrator can configure report narrative templates that prompt users to enter report-required information in the narrative Y
314. System Administrators will have the ability to edit group assignments for users within the current system and link to an outside system (concord admin), duty stations, as well as all associated workflow, routing, forms, etc. customization needed for configuration.
Y
315. System allows for agency-configurable abilities for assignment to roles that allow a system administrator to assign different levels of security and functions to a user based on that user's role
Tier 2 Requirement
316. System allows for agency-configurable roles that allow to system administrator configure different user types Y
317. System configuration/administration changes can be made when system is live without having to shut it down or restart it. Y
318. System data fields are conditionally required based on the type of record being created. Y
319. System shall allow login configuration such that users default to a particular duty station, but can access records from other duty stations to which they have been granted permissions.
Y
320. Table changes become immediately effective and do not affect overall system availability. Y
321. The system allows for modifications to system configuration parameters when the system is active without having to shut the entire system down or restart it. Y
322. The system can be accessed without requiring on-prem installation(s) Y
323. The system can be configured to auto-generate and route statistic reports on a daily, weekly, and/or monthly basis within the system Y
324. The system has an online and in-application help feature that lists available options for system configuration. Y
325. The system includes canned reporting capabilities for monitoring system performance and or degradation. Y
326. The system includes on-line help/guides that list available options for attribute/table configuration parameters, and a description of the impacts resulting from changing the parameter to each of its available options.
Y
327. The system is capable of continuous operation without degradation while files are being backed up. Y
328. The system provides textual descriptions of how each system administration feature operates and will display to the user how changing settings will impact the system and users.
Tier 2 Requirement
329. System provides safeguards and application design patterns used in order to ensure that a single request does not consume a disproportionate level of server-side resources. Y
330. System supports agency administrators to create/manage user accounts. Y
331. System user-security profiles can be assigned to individual user roles or user groups based on personnel classifications (e.g. system administrator, supervisor.) Y
Data Migration
332. The vendor maps legacy data to new system fields and is responsible for migration of legacy data Y
333. The vendor tests the scripts to ensure migration Y
334. The vendor transforms legacy data into new system Y
335. The vendor ensures new data and other sources are connected to the EDW. Y
336. The vendor ensures that migrated legacy data, previously not system-required, do not create errors in the new system where fields may have new constraints Y
337. The vendor is responsible for cleaning data to ensure the data is accurate, accessible, and aligned with updated requirements.
338. The system ensures data quality control between migrated data and new system Y
339. The new system has ability to retrieve archived data on-demand Y
Tier 2 requirement
SUPPORT
340. Access to a 24/7/365 online knowledge portal for current product support. Y
Support
Tier 2 requirement
341. 24/7/365 support for system administrators is included and provided, post implementation. Y
342. Dedicated account management support included and provided pre/post-implementation. Y
TRAINING
343. Documentation is provided for product updates. Y
344. Ongoing product and training documentation is provided by the vendor after go-live Y
345. Product and training documentation is provided by the vendor during the implementation process. Y
346. The vendor provides multiple environments that do not impact or update the production system. (e.g., Beta Test System, Enterprise-wide Training). Y
347. The system's testing and training environment is as extensive as the system's production environment in order to enable new system configurations and system updates to be tested. Y
348. Training through multiple environments; onsite, virtual and train the trainer, etc. Y
349. Government ownership of the training materials to support sustainability Y
| Case Management |
| Case Mgt. System – Reporting CMS has the ability to manage case life cycle: open, active, pending, closed etc. |
| Case Mgt. System - Supplemental Reports |
| Case Mgt. System - Task Management |
| Case Mgt. System - Case Management |
| Case Management System Investigation Assignment |
| Case Monitoring |
| SOD Added Requirements |
| Y |
| Y |
| Y |
| Y |
| Y |
| Y |
| Y |
| Y |
| Y |
| Y |
| Criminal Organization Management |
| Case Mgt. System - Drug and Nondrug Evidence |
| Case Mgt. System |
| Case Mgt. System - Data Sharing |
| Case Mgt. System - System Administration |
| Case Mgt. System - Technology |
| Operational Plan Requirements |
| Case Mgt. System - Diversion Control Requirements |
| Analytics |
| Analytics (Detailed examination of events) Do they belong in CMS- inside or outside of this system? |
| Ability to analyze activity using the following options, including, but not limited to: |
| Ability to present statistics visually, including, but not limited to the following: |
| Data Aggregation |
| Visualization (map-data collection) map overview (case orientation) |
| Dashboards and Alerts |
| Cloud |
| Security |
| System Security |
| System Configuration |
| System Admin Configuration Capabilities |
| Data Migration |
| Support |
| SUPPORT |
| TRAINING |
File details come from the government source that posted it. Updated .