EINF90325_Exhibits.pdf

PDF 1 MB Posted

Attached to
EINF90325 RFQ-ITS Physical Security Assessment Services State and local contract opportunity
Solicitation number
EINF90325
Issued by
Sacramento County, California

About this file

This Scope of Work document outlines consulting services for the State Controller's Office (SCO) in California to provide physical security systems assessment and recommendations. SCO seeks a contractor to evaluate existing physical security controls, systems, and applications across seven facilities (four in the Sacramento area, one in San Francisco, and two in the Los Angeles area) and provide comprehensive findings aligned with NIST 800-53 standards. The agreement has a one-year term with SCO retaining the right to amend the contract to modify locations, equipment, software, scope, and quantities at its exclusive discretion. The contractor must supply at least one key staff member with minimum three years of IT physical security assessment experience for government entities and current industry-recognized certifications. Services will be performed both remotely and onsite during standard business hours (8:00 a.m. to 5:00 p.m. Pacific Time, Monday through Friday, excluding state holidays). Three deliverables are required: an Initial Review due at 30 days, an Analysis due at 60 days, and a Final Report with one, three, and five-year remediation plans due at 90 days. All deliverables must be in Microsoft Office Suite format, free of errors, professionally formatted, and delivered to an SCO-designated repository as the exclusive property of SCO.

The contractor must maintain multiple insurance policies including $1 million commercial general liability, statutory workers' compensation with $1 million employer's liability, $1 million automobile liability, $1 million professional liability, and $15 million cyber liability coverage. Compensation is based on actual expenditures incurred at rates specified in Exhibit B, with invoices submitted monthly in arrears requiring approved Deliverable Expectation Documents and Deliverable Acceptance Documents. The contractor bears all costs including labor, supplies, equipment, travel, per diem, parking, vehicles, taxes, insurance, and licenses, with no additional costs reimbursed beyond the maximum agreement amount without a fully executed amendment. The contractor must utilize SCO-supplied laptops with SCO Security Software Suite and comply with extensive data security and confidentiality requirements, including NIST SP 800-53 compliance, encryption of sensitive data, role-based access controls, and incident notification within 24 hours of any security breach. SCO will withhold $10,000 from final payment pending receipt of a Prime Contractor's Certification—DVBE Subcontractor Report within 60 days of agreement expiration, and the contractor must submit a biannual Prime Contractor's Certification—Small Business Subcontractor Report documenting small business utilization.

View the file

Other files for this state and local contract opportunity

Other files attached to EINF90325 RFQ-ITS Physical Security Assessment Services, newest first.
File Type Posted
IFB_Solicitation_08A3992.pdf PDF
EINF90325_RFQ-ITS.pdf PDF
C25651009_BID_FORMS_CSCR.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

State Controller’s Office RFQ-ITS Number EINF90325

Exhibit A

SCOPE OF WORK

A. Description of Services

The Contractor shall provide physical security systems and program consulting services related to the State Controller’s Office (SCO) physical security controls, systems, and applications, including the supporting infrastructure required to operate them (e.g. access control, video surveillance, and intrusion detection systems). All services provided shall support a physical security assessment aligned with applicable industry standards, such as the National Institute of Standards and Technology (NIST) 800-53 Physical and Environmental Protection (PE) family controls where relevant. In doing so the Contractor shall evaluate SCO’s existing physical security controls and provide findings and recommendations.to improve alignment with industry best practices to strengthen SCO’s physical security program, including governance and retention practices.

Services will be completed both remotely and onsite. Onsite services shall be performed at SCO facilities:

four (4) located in the greater Sacramento area, one (1) in San Francisco, and two (2) in the greater Los Angeles area). All remote services must be performed within the continental United States.

SCO Facility Locations:

300 Capitol Mall, Sacramento, CA 95814 621 Capitol Mall, Sacramento, CA 95814 3301 C Street, Sacramento, CA 95816 10600 White Rock Road, Rancho Cordova, CA 95670 888 S. Figueroa Street, Los Angeles, CA 90017 901 Corporate Center Drive, Suite 200, Monterey Park, CA 91754 455 Golden Gate Avenue, Suite 10500, San Francisco, CA, 94102

Agreement Term

The term of this agreement will be for one (1) year with SCO reserving the sole right to amend the agreement to add time, funds, modify locations, equipment, software, and/or adjust the quantity or scope of services, at its exclusive discretion. The rates in Exhibit B, Attachment 1, Cost Worksheet will not change as a result of any amendment to this agreement. This agreement may be terminated by SCO with 30 days’ written notice to the Contractor or immediately for cause, including but not limited to Contractor breach, failure to meet deliverables, or security incidents.

Contractors are cautioned that no work will begin until the Agreement has been fully executed. If work is performed prior to the Agreement approval, and the Agreement for any reason is not approved, all previous work performed by the Contractor is considered donated to SCO and no payment shall be made for that work.

Agreement Amount

The Contractor and SCO Information Security Office (ISO) Contract Manager (CM) are responsible for monitoring the Agreement cost to ensure it does not exceed the maximum amount of the Agreement without an executed amendment. The Contractor and SCO ISO CM are jointly responsible for continuous monitoring of agreement expenditures. Under no circumstances shall costs exceed the maximum agreement amount without a fully executed written amendment. Any unauthorized expenditures are the sole responsibility of the Contractor and will not be reimbursed by SCO.

B. Contractor Responsibilities

The Contractor shall:

1. Maintain and provide, upon request, key staff’s current industry-recognized certifications relevant to IT physical security within five (5) business days of SCO request.

2. Supply at least one (1) key staff fully trained in IT physical security assessment services. Key staff must be with the current company for at least one year and possess a minimum of three years’ experience within the last five years in IT physical security assessments for government entities.

3. Perform all services during the business hours of 8:00 a.m. to 5:00 p.m. Pacific Time (PT) Monday through Friday, except State holidays. For a list of State holidays which SCO observes, go to the following link: http://www.calhr.ca.gov/employees/pages/state-holidays.aspx.

4. Coordinate services with the SCO ISO CM.

5. Work closely with SCO staff to complete all tasks/deliverables as defined in Section E, Contractor Deliverables and as defined in the Deliverable Expectation Document (DED) and/or Work Authorization Form (if applicable).

6. Adhere to all SCO requirements detailed in the DED and/or Work Authorization Form related to the identified deliverables.

7. Perform all services as agreed, with diligence, and in a professional manner in accordance with the description of services in the Agreement and to SCO satisfaction.

8. Attend remote and in-person meetings as required.

9. Communicate all issues and/or concerns through the documented process agreed upon in writing by the Contractor and SCO during kickoff meeting.

10. Coordinate with SCO ISO CM to ensure adherence to all SCO policies, procedures, and standards.

11. Immediately notify the SCO ISO CM of events or proposed changes that could affect the scope, budget, or work schedule under this agreement.

12. Utilize SCO-supplied laptops, including SCO Security Software Suite, for all services performed under in this agreement. Such laptops shall be picked up from an SCO location in the greater Sacramento area at a mutually agreed upon time and location.

a. Remote access of SCO network will be available only over Virtual Private Network (VPN) using

SCO-supplied credentials.

b. SCO-supplied laptops shall not utilize any third-party VPN.

c. SCO will track laptop per SCO policy.

d. SCO-supplied laptops shall be used solely for documentation and process review. Any changes or configurations must be completed by the SCO ISO CM or their designee.

e. All SCO-related documentation shall be labeled as Controlled Unclassified Information (CUI)- Restricted.

f. Traffic Light Protocol (TLP): All SCO-related documentation will be evaluated independently and labeled TLP:Red, TLP:Amber+Strict or TLP:Amber.

13. Shall not attach any non-SCO personal computers, phones, tablets, laptops, thumb drives, etc., or any electronic device to a SCO server or workstation without prior SCO written approval from the SCO Chief Information Security Officer (CISO) or designated representative. Should this be necessary, SCO reserves the right to inspect, scan, and retain any device for any malware that could pose a threat to server devices or the network.

14. Ensure all staff performing services during the term of this agreement understand that they are subject to SCO security clearance requirements and must successfully complete and pass a SCO background check and security awareness training prior to performing any services.

15. Ensure key staff shall utilize a SCO provided security badge to access work areas when onsite.

16. Ensure staff read and/or complete standard SCO documents (i.e., Policy Acknowledgement, Technology Resources, Zero Tolerance for Discrimination, etc.), during the term of the Agreement.

17. Ensure all contractor staff sign the SCO Contractor/Consultant Confidentiality Statement and Non-Disclosure Acknowledgement form (ISO-004b).

18. Ensure cost includes all labor, supplies, equipment, travel, per diem, parking fees, vehicle, taxes, insurance, licenses, permit fees, additional fees, and any other associated cost necessary to provide the services in accordance with Exhibit A, Scope of Work. SCO will not pay for any costs not included in the Total Agreement Amount.

19. Complete a Prime Contractor’s Certification - DVBE Subcontractor Report (STD 817) and submit to SCO if the Contractor committed to subcontract with a Disabled Veteran Business Enterprise (DVBE).

To certify that the DVBE commitment was met, the Contractor must submit the STD 817 within 60 days of expiration of the Agreement.

20. Complete and submit Exhibit A, Attachment 6, the biannual Prime Contractor’s Certification – Small

Business Subcontractor Report on SB subcontractor utilization to the Contract Analyst in the SCO Contracts and Procurement Office. At a minimum, the report includes:

a. Amount paid to each SB Subcontractor for the reporting period.

C. Physical Security Assessment Objectives

1. Conduct a comprehensive evaluation of the effectiveness of existing physical security controls, including the handling, review, monitoring, and retention of surveillance video footage systems including staff roles and responsibilities applications and supporting infrastructure used to operate those technologies, and architecture specific to physical security, as defined in the detailed list provided by SCO after agreement award.

2. Schedule and conduct comprehensive onsite inspections of all SCO locations with the SCO ISO CM.

Provide hardware, infrastructure, and security architecture recommendations.

3. Identify weaknesses, vulnerabilities, and deficiencies in the implemented physical security controls within the target system, network, or applications.

4. Determine the remaining risk exposure and identify areas where additional controls or mitigations may be required.

5. Provide Plan of Action and Milestones (POA&Ms) detailing recommendations for improvement which may include remediation actions, enhancements to existing controls, or the implementation of additional controls to address identified weaknesses.

6. Provide a prioritized risk assessment and actionable, measurable recommendations for mitigation, including specific timelines and responsible parties for each recommended action.

7. Provide written recommendations:

a. Of industry best practices for video retention governance, archive, and backup of camera footage for standard business operations and high security operations.

b. For business continuity and disaster recovery for physical security systems and applications.

c. For the use of live and recorded camera footage, that include identifying roles and responsibilities for managers, supervisors, and security professionals to conduct monitoring both in real time and in response to an incident. Recommendations should address the frequency of monitoring and protocols for addressing issues identified during these monitoring reviews.

8. SCO shall discuss components with the Contractor upon execution of the Agreement that includes the following:

a. Systems to be included in assessment (e.g. servers, workstations, laptops, and mobile devices, including both internal and external systems, as well as any cloud-based systems).

b. Applications to be included in assessment include CCure, ExacqVision, and Bosch Alarms.

c. Network components to be included in the assessment (e.g. routers, switches, firewalls, and other network devices, including both internal and external network components, as well as any cloud-based network components that SCO uses).

D. Reporting Requirements for Deliverables

The Contractor shall include the following in all reports:

Contractor’s Name Key Staff’s Name Summary of the work that was performed during the service Signature of the SCO ISO CM or designated representative

1. The reports shall:

a. Provide an Executive Summary of the assessment summarizing the objectives, scope, key findings, and recommendations and highlight critical issues, risks and recommendations in a format suitable for executive leadership.

b. Include an introduction that provides background information about the assessment, including the purpose, scope, methodology, and any relevant assumptions or limitations.

c. Provide the assessment methodology describing the approach and methodology used during the assessment. The assessment should include the techniques, tools, and procedures employed to evaluate the security controls and assess the system's overall security posture.

d. Provide the assessment findings, presenting the detailed findings and observations from the assessment. It should include a comprehensive analysis of the physical security controls, vulnerabilities, weaknesses, and deficiencies identified during the assessment process. Each finding should be clearly documented, including relevant evidence and supporting information.

e. Provide a risk analysis based on the identified findings. The risk analysis shall assess the potential impact and likelihood of exploitation for each finding and determine the associated risk level.

f. Provide clear and actionable remediation recommendations that outline specific actions and measures to address the identified findings and mitigate the identified risks. Remediation recommendations must be practical, actionable, and tailored to SCO’s context. Remediation recommendations must also include an estimate of potential cost for the remediation. The recommendations for remediation may include remediation steps, control enhancements, process improvements, or additional security measures. Recommendations must be specific, feasible, and include estimated resource requirements, implementation timelines, and responsible roles.

g. Provide appendices that may include supporting documentation, such as detailed technical findings, network diagrams, assessment logs, or compliance matrices. These supplementary materials shall provide additional context and evidence to support the assessment report.

h. Provide technical training recommendations for SCO staff.

E. Contractor Deliverables

All documentation, data, and work products generated as part of this agreement are the exclusive property of SCO and may not be used, disclosed, or reproduced by the Contractor for any purpose outside the scope of this agreement without prior written consent from SCO. All deliverables must address the assessment objectives itemized in Section C. IT Physical Security Assessment Objectives and follow Section D. Reporting Requirements for Deliverables.

1. Deliverable Format

a. Deliverable documents must be comprehensive in level of detail and quality, professional in presentation, and consistent in style.

b. All deliverables must adhere to the following and be:

1) Provided in a format compatible with Microsoft Office Suite 2016 or later standard applications.

2) Delivered in a malware free media compatible with SCO storage devices that are Microsoft

Windows based.

Deliverable # Description Due Date

Initial Review of controls, systems, applications, network infrastructure, and architecture specific to physical security.

30 Days

Analysis of controls, systems, applications, network infrastructure, and architecture specific to physical security.

60 Days

Final Report with Recommendations including 1 year, 3 year, and 5-year plans to address weaknesses and strengthen controls, systems, applications, network infrastructure, and architecture specific to physical security.

90 Days

3) Stored in a SCO designated central repository.

4) Remain the sole property of SCO.

5) All deliverables must be free of errors, professionally formatted, and meet the quality standards defined by SCO. Deliverables not meeting these standards will be rejected.

c. The Microsoft Office Suite standard applications include Word, Excel, Visio, Microsoft Project, PowerPoint etc. In all cases, the Contractor must verify application compatibility with SCO prior to creation or delivery of any electronic documentation. SCO must provide advance written approval for delivery in any other format or tool used by the Contractor.

2. Deliverable Expectation Document (DED)

a. The SCO ISO CM will provide a DED to the Contractor as the first step for every Deliverable. A sample DED form is provided as Exhibit A, Attachment 1, Deliverable Expectation Document (Sample).

b. For each deliverable, the Contractor and SCO ISO CM will agree in advance, through meetings and/or planning sessions, on the deliverable expectations. SCO will document the expectations, completion date, and acceptance criteria in writing on the DED.

c. The DED will address all tasks, activities, and deliverables required by the Agreement including any additional items agreed upon during subsequently meetings and planning sessions.

d. The DED will be signed by the SCO ISO CM and the Contractor to confirm mutual agreement of the expectations and acceptance criteria.

e. The Contractor must provide deliverables to SCO by the specified due date unless SCO has granted written permission on the DED to deviate from the schedule.

3. Deliverables Submission Criteria

a. The Contractor shall provide the SCO ISO CM a Deliverable Acceptance Document (DAD) with the submission of final deliverables. A sample DAD form is provided as Exhibit A, Attachment 2, Deliverable Acceptance Document (Sample).

b. The SCO ISO CM will acknowledge receipt of the DAD within two (2) business days via encrypted email.

c. The SCO ISO CM will approve or reject the deliverable in writing, based on the DED using the

DAD.

d. The SCO ISO CM will notify the Contractor in writing within 10 business days after Contractor submission of each final deliverable of any acceptance problems by identifying the specific inadequacies and/or failures in services performed and/or documents produced by the Contractor, unless the Contractor and the SCO ISO CM have mutually agreed in writing to a different review period for the DAD.

e. Failure to meet deliverable deadlines without prior written approval from SCO may result in liquidated damages or termination for cause.

4. Review of Deliverables

a. SCO’s review of deliverables will be in accordance with the time frames set forth in the Project Schedule and/or DEDs.

b. SCO review period will vary with the complexity and volume of the task and/or deliverable.

c. SCO shall make every effort to review deliverables within 10 business days of written acknowledgment of receipt of the DAD. If the SCO ISO CM determines the submitted deliverables require more than 10 business days to review, SCO will coordinate with the Contractor to determine an alternative turnaround period and memorialize the collaborative decision in writing, based on the size and number of deliverables currently in review.

d. A formal walkthrough session shall be conducted to review all submitted deliverables. SCO will identify the reviewers that will attend these walkthrough sessions. The walkthrough sessions will be organized and scheduled by the Contractor and SCO ISO CM. The walkthrough provides SCO with the opportunity to verify details of the work completed.

5. Deliverable Rejection

a. It is the sole determination of SCO as to whether a deliverable has been successfully completed and is acceptable to SCO.

b. If a deliverable is not accepted, the SCO ISO CM will indicate the reason for no acceptance on the DAD and attach the rationale for the rejection in their response to the Contractor.

c. The Contractor shall acknowledge receipt via encrypted email of the returned DAD document and written denial within two (2) business days.

6. Escalation Process

a. The Contractor may request a meeting with the SCO ISO CM, and other stakeholders to discuss and/or clarify comments on the returned DAD.

b. Contractor must immediately notify SCO ISO CM, in writing, of any events, incidents, or proposed changes that could impact the scope, budget, schedule, or security posture under this agreement.

c. The Contractor shall make appropriate corrections to the deliverable and resubmit, with a new DAD, to the SCO ISO CM for acceptance review within five (5) business days of acknowledging receipt of non-acceptance.

d. The Contractor shall ensure SCO comments, both written and those made as a result of a meeting to clarify comments, are included in the resubmitted deliverable.

e. The Contractor may request an extension for up to an additional five (5) business days to resubmit corrected or modified deliverables. The request must be in writing, and written approval must be obtained from SCO prior to the resubmission due date.

7. Deliverable Acceptance

a. Acceptance will be determined when the Contractor has identified all vulnerabilities within the scope of the IT security assessment and provided remediation recommendations and all reports.

b. Upon acceptance of the submitted/re-submitted DAD, the SCO ISO CM shall sign the DAD and check the appropriate box indicating that the deliverable has been approved and accepted by SCO.

c. SCO shall provide via encrypted email, the approved DAD and supporting documentation to the

Contractor.

d. The Contractor shall submit the signed DAD, and the encrypted email approval with the deliverable invoice when submitting an invoice for payment.

G. Unanticipated Tasks

1. In the event that additional work must be performed that was wholly unanticipated and is not specified in this Scope of Work (SOW), but that is, in the opinion of both parties, necessary to the successful accomplishment of the general SOW outlined, and the estimated cost of that work does not exceed 10 percent of the base agreement, the procedures outlined in this section will be employed. No work outside the original SOW may commence without a fully executed Work Authorization Form signed by both parties. Any work performed without such authorization is at the Contractor’s sole risk and expense.

2. For each item of unanticipated work not specified in the SOW, a Work Authorization Form will be prepared in accordance with the sample attached as Exhibit A, Attachment 3, Work Authorization Form (Sample).

3. It is understood and agreed upon by both parties to this agreement that all of the terms and conditions of this agreement shall remain in force with the inclusion of any such Work Authorization Form. Such Work Authorization shall in no way constitute an agreement other than as provided pursuant to this agreement nor in any way amend or supersede any of the other provisions of this agreement.

4. Each Work Authorization Form shall consist of the following:

a. A detailed statement of the purpose, objective, or goals to be undertaken by the Contractor

b. The name, job classification(s) or approximate skill level(s) of the key staff to be made available by the Contractor

c. An identification of all significant material to be developed by the Contractor and delivered to SCO

d. An identification of all significant materials to be delivered by SCO to the Contractor

e. An estimated time schedule for the provisions of these services by the Contractor

f. Completion criteria for the work to be performed

g. The Contractor's estimated work hours for each key staff assigned required to accomplish the purpose, objective or goals

h. The Contractor's billing rates as identified in Exhibit B, Attachment 1, per work hour

i. The Contractor's estimated total cost of the Work Authorization.

5. SCO shall not pay the Contractor for any cost related to the development of Work Authorization Forms.

6. All Work Authorization Forms must be in writing and signed by the Contractor and SCO ISO CM prior to beginning work.

7. SCO has the right to require the Contractor to stop or suspend work on any Work Authorization pursuant to the “Stop Work” provision of the Exhibit C, Information Technology - General Provisions- Non-Cloud Goods & Services DGS PD 403-ITGP (Non-Cloud).

8. The Contractor must follow the SCO Work Authorization Form procedure outlined below in order to expend key staff resources on task accomplishment in excess of the previously estimated work hours.

a. If, in the performance of the work, the Contractor determines that a Work Authorization to be performed under this agreement cannot be accomplished within the estimated work hours, the Contractor will immediately notify the SCO ISO CM in writing of the Contractor's estimate of the work hours required to complete the Work Authorization in full.

b. The SCO ISO CM will notify the Contractor in writing of its election within seven (7) calendar days after receipt of the Contractor's notification.

c. Upon receipt of such notification, SCO may:

1) Authorize the Contractor to expend the estimated additional work hours or service in excess of the original estimate necessary to accomplish the Work Authorization (such an authorization not unreasonably to be withheld), or

2) Terminate the Work Authorization, or

3) Alter the scope of the Work Authorization in order to define tasks that can be accomplished within the remaining estimated work hours.

d. If notice of the election is given to proceed, the Contractor may expend the estimated additional work hours or services. SCO agrees to reimburse the Contractor for such additional work hours.

H. Contractor Key Staff Changes

1. Key Staff Continuity

a. Contractor must provide at least 14 business days’ advance written notice and receive written approval from SCO prior to any removal, reassignment, or substitution of key staff, except in cases of emergency.

b. SCO recognizes that the Contractor’s key staff may be unavailable due to circumstances beyond the Contractor’s control such as illness, an extended leave of absence, death, termination, or resignation. However, the Contractor shall ensure key staff continuity throughout the term of the Agreement.

2. Key Staff Misconduct

a. The Contractor shall remove any key staff or subcontractors who, in the opinion of SCO, have engaged in improper conduct.

b. SCO will document the misconduct and notify the Contractor, in writing, within two (2) business days of becoming aware of the misconduct.

c. Within two (2) days of receiving notice of key staff misconduct, the Contractor must remove the identified key staff or subcontractor.

d. Within 14 business days of receiving written notification of the misconduct, the Contractor shall provide SCO with replacement key staff with equivalent knowledge, skill set, and experience of removed key staff.

e. The key staff shall be replaced subject to the key staff replacement process in Section H.5, Key Staff Change Procedures.

3. Key Staff Performance Issues

a. In the event either party identifies a performance issue with key staff, the identifying party must contact the other party within two (2) business days.

b. The identifying party must document the performance issues, discuss the issues with the other party, and together, they should determine the best approach for resolving the issues.

c. The Contractor shall document the agreed upon resolution and provide written notice to the SCO

ISO CM.

d. If the parties agree that the key staff should be removed, the key staff shall be replaced subject to Section H.5, Key Staff Change Procedures.

e. SCO reserves the right to require immediate removal of any key staff for performance or conduct issues, at its sole discretion.

4. Key Staff Replacement/Substitution

a. In the event Contractor key staff are unable to perform their duties due to illness, resignation, or other factors beyond the Contractor’s control, the Contractor shall make every effort to provide suitable substitute personnel with equivalent knowledge, skill set, and experience.

b. The replacement/substitute key staff must meet all requirements as stated in RFQ-ITS EINF90325 and must be approved by SCO in writing prior to starting work.

c. When the unplanned or early departure of key staff or a subcontractor from the Agreement is unavoidable, the Contractor shall immediately notify SCO in writing and document the activities and timelines to transition and train new or reassigned replacement key staff. Reference Section H. 5, Key Staff Change Procedures for additional information.

5. Key Staff Change Procedures

a. The Contractor must obtain written approval from SCO prior to making key staff changes.

b. SCO reserves the right to approve or deny all of the Contractor’s proposed replacement key staff designated to fill any key staff roles.

c. The Contractor shall provide a replacement key staff within seven (7) business days who meets the key requirements identified in RFQ-ITS EINF90325 and who has equivalent knowledge, skill set, and experience of the key staff member previously approved. The Contractor shall provide Exhibit A, Attachment 4, Personnel Change Order Request Form (Sample) and Exhibit A, Attachment 5, Key Staff Reference Form (Sample) with the replacement key staff’s resume and any related documents (e.g. certifications, degrees, etc.) to SCO.

d. Within 14 business days of SCO receiving the replacement staff’s personnel change order request form, references, resume, and related documents (i.e., certifications, degree, etc.) SCO will review and provide written approval or rejection of the Contractor’s offered personnel change.

e. The Contractor’s proposed replacement key staff will be required to successfully complete and pass an SCO background check prior to starting work.

f. SCO reserves the right to request a statement from the replaced key staff to confirm the reason for replacement.

g. SCO shall not compensate the Contractor for any time or effort required to prepare new key staff member(s) for work on the Agreement.

h. All Contractor key staff names must be identified within the Agreement and may be updated during the agreement term upon SCO approval. Any approved changes will be reflected should an amendment be completed.

6. Replacement/Substitute Key Staff Rejection

a. If SCO rejects the proposed replacement/substitute key staff, within 10 business days, the

Contractor shall provide SCO with another viable key staff that meets the key requirements identified in RFQ-ITS EINF90325 and who has equivalent knowledge, skill set, and experience of the key staff member previously approved.

b. If a qualified replacement is not identified within 10 business days of rejection, the Contractor shall be in material breach of the Agreement unless the Contractor submits a written request for an extension and SCO provides written approval before the deadline.

I. Kickoff Meeting

Within 10 business days of agreement execution, the Contractor shall conduct a kickoff meeting with the SCO team to:

1. Review the details of the SOW to ensure a clear understanding of the Agreement goals and expectations.

2. Review the roles and responsibilities of the Contractor and SCO staff.

3. Review the deliverables, the schedule, and coordinate a high-level project review.

4. Discuss critical factors that may impact this agreement.

5. Review administrative and reporting requirements.

6. Discuss and agree upon the process for communicating issues, risks, status, etc. on this agreement.

7. Discuss and agree upon the approach to tracking and managing performance.

8. Identify the CMs and other key staff.

9. Reviews threats and vulnerabilities experienced in the last 12 months.

10. All decisions, processes, and action items agreed upon during the kickoff meeting must be documented and distributed to all parties within two (2) business days.

J. SCO Responsibilities

SCO shall:

1. Provide the Contractor with an SCO ISO CM to manage the Deliverable Schedule and oversee the

Agreement and SCO ISO representatives who shall monitor the services provided.

2. Provide the Contractor key staff, no more than one (1) , with a laptop including SCO Security Software Suite for all services in this agreement upon successful completion of the background check.

3. Provide the Contractor key staff, no more than one (1) , with SCO Credentials and a badge upon successful completion of the background check.

4. Provide the Contractor access to its facilities and staff as necessary to complete services and deliverables identified in this SOW.

5. Provide scheduled access to Subject Matter Experts (SMEs) as needed for completion of agreement tasks and activities.

6. Review required status reports to ensure efficiency and effectiveness.

7. Review and approve tasks and deliverables as identified in this SOW.

8. Coordinate deliverable tasks and activities to the overall schedule.

9. Coordinate onboarding and exiting/closing activities.

10. Communicate all issues and/or concerns through the process agreed upon by the Contractor and SCO ISO CM during kickoff meeting.

11. Conduct the SCO background check on Contractor’s key staff.

12. Provide the Contractor’s key staff standard SCO documents (i.e. SCO Background Check, Policy Acknowledgement, Technology Resources, COVID-19 protocol, Zero Tolerance for Discrimination, etc.), to read and/or complete during the term of the Agreement.

13. SCO reserves the right to request verification of key staff qualifications.

14. SCO reserves the right to ask for the replacement of any key staff based solely on its own judgment and the Contractor shall replace with the same qualified key staff, or better. All replacement key staff are subject to approval by SCO.

K. Contacts

1. The Contract Manager for technical service inquiries will be:

State Controller’s Office Contractor TBD

Name: Name:

Address:

Address:

Phone: Phone:

E-mail: E-mail:

2. The contact for Agreement inquiries will be:

State Controller’s Office Contractor TBD

Name: Name:

Address: Address:

Phone: Phone:

E-mail: E-mail:

3. Contacts may be changed upon written notice to either party without an agreement amendment. Any changes to contact information must be communicated in writing and acknowledged by both parties prior to taking effect.

Exhibit A, Attachment 1

DELIVERABLE EXPECTATION DOCUMENT (DED) (SAMPLE)

I. Agreement Information

1. Contractor Name: 2. Agreement Number: CINF90325

3. Deliverable Number: 4. Deliverable Name:

5. Task and Deliverable Description from Scope of Work (SOW):

II. Deliverable Expectations

6. Delivery Timeline:

Start Date – End Date –

7. Update Schedule:

8. Specific Component(s) of Tasks and Deliverables:

9. Acceptance Criteria:

III. Required Signatures

This DED was completed according to agreement requirements of Agreement Number CINF90325.

10. SCO Information Security Office (ISO) Contract Manager (CM):

Name Signature Date

11. Contractor Contract Manager:

Exhibit A, Attachment 1

DELIVERABLE EXPECTATION DOCUMENT (DED) INSTRUCTIONS

INSTRUCTIONS FOR COMPLETING THE DED:

Section I. Agreement Information

1. Contractor Name: Enter the full legal name of the Contractor.

2. Agreement Number: Enter the number of the Agreement that corresponds to the work conducted.

3. Deliverable Number: Enter the number of the deliverable.

4. Deliverable Name: Enter the name of the deliverable.

5. Task and Deliverable Description: Provide the task/deliverable description direct from Exhibit A. If paraphrasing is needed, cite the section in Exhibit A and provide as much detail as possible.

Section II: Deliverable Expectations

6. Delivery Timeline: Enter the date that the deliverable is required per the approved DED work plan.

7. Update Schedule: Enter the trigger and/or time frame that the deliverable is required to be updated.

8. Specific Component(s) of Deliverable: Enter the specific measurable component for the overall deliverable. Please use one space per component.

9. Acceptance Criteria: Enter the specific criteria that the component will be deemed acceptable or unacceptable.

Section III: Required Signatures

10. SCO Information Security Office (ISO) Contract Manager (CM): Type or print the full name of the SCO Contract Manager or their designated appointee, sign, and date.

11. Contractor Contract Manager: Type or print the full name of the Contractor’s Contract Manager or their designated appointee, sign, and date.

Exhibit A, Attachment 2

DELIVERABLE ACCEPTANCE DOCUMENT (DAD) (SAMPLE)

I. Agreement Information

1. Contractor Name: 2. Agreement Number: CINF90325

3. Deliverable Number: 4. Deliverable Name:

5. Date Submitted:

II. Deliverable Acceptance Document (DAD) Information

6. Date Approved: 7. SCO Approver:

III. Deliverable Acceptance Status

☐ 8. Accepts that the deliverable is in conformance with the approved DED

☐ 9. Accepts deliverable with changes noted below in “Comments/Changes”

☐ 10. Rejects deliverable, see explanation below as applicable

11. Date Deliverable Accepted/Rejected:

12. Reason for Rejection of Deliverable, if applicable:

13. Comments/Changes:

IV. Required Signatures

The deliverables associated with this DAD have been approved and have been completed according to agreement requirements of Agreement Number CINF90325

14. SCO Information Security Office (ISO) Contract Manager (CM):

15. Contractor Contract Manager:

Exhibit A, Attachment 2

DELIVERABLE ACCEPTANCE DOCUMENT INSTRUCTIONS

INSTRUCTIONS FOR COMPLETING THE DAD:

Section I. Agreement Information

1. Contractor Name: Enter the full legal name of the Contractor.

2. Agreement Number: Enter the number of the Agreement that corresponds to the work conducted.

3. Deliverable Number: Enter the number of the deliverable.

4. Deliverable Name: Enter the name of the deliverable.

5. Date Submitted: Enter the date the DAD was submitted to SCO.

Section II: Deliverable Acceptance Document (DAD) Information

6. Date Approved: Enter the date the DAD was approved by SCO.

7. SCO Approver: Enter the full name of the SCO staff that approved the DAD.

Section III: Deliverable Acceptance Status

8. Accepts that the Deliverable is in conformance with the approved DED: Check box number 8 if the deliverable is in conformance with the approved DED.

9. Accepts Deliverable with changes noted below in “Comments/Changes”: Check box number 9 if the deliverable is acceptable with comments. Enter comments in box 13.

10. Rejects Deliverable, see explanation below as applicable: Check box number 10 if the deliverable is unacceptable. Enter explanation in box 12.

11. Date Deliverable Accepted/Rejected: Enter the date the deliverable was found to be accepted or unacceptable, and rejected by SCO.

12. Reason for Rejection of Deliverable: If box 10 is checked, provide the reason for the rejected deliverable.

13. Comments/Changes: Provide sufficient detail for the Contractor to make corrections to the deliverable and resubmit to SCO.

Section IV: Required Approval Signatures

14. SCO Information Security Office (ISO) Contract Manager (CM): Type or print the full name of the SCO Contract Manager or their designated appointee, sign, and date.

15. Contractor Contract Manager: Type or print the full name of the Contractor’s Contract Manager or their designated appointee, sign, and date.

Exhibit A, Attachment 3

WORK AUTHORIZATION FORM (SAMPLE)

Title

Work Authorization Number

Task Summary

Schedule Dates Start Date: Completion Date:

Contractor Key Staff to Be Assigned Job Classification / Skill Level

Labor Hours Hourly Labor Rate Total Estimated Cost

Completion Criteria

This task will be performed in accordance with this Work Authorization and the provisions of Agreement Number CINF90325.

Approved By:

State Controller's Office Contractor – TBD

(Name/Title –Type or Print)

Signature

Date

(Name/Title –Type or Print)

Exhibit A, Attachment 3

WORK AUTHORIZATION FORM INSTRUCTIONS

Form field titles and expected entry criteria

Field Titles Description of Entry

Title Enter the title of the work authorization being requested.

Work Authorization Number

Enter the assigned work authorization number.

Task Summary Enter a detailed statement of the purpose, objective, or goals for the work authorization. Include an identification of all significant materials to be developed by the Contractor and delivered to SCO, an identification of all significant materials to be delivered by SCO to the Contractor, and an estimated time schedule for the provisions of these services by the Contractor.

Schedule Dates Enter the estimated Start Date and Completion Date for the work to be performed.

Contractor Key Staff Enter the name or identification of the proposed Key Staff to complete the work as detailed in the work authorization.

Job Classification/Skill Level

Enter the job classification or approximate skill level(s) of the key staff to be made available by the Contractor.

Labor Hours Enter the Contractor's estimated work hours required to accomplish the purpose, objective, or goals of the work authorization.

Hourly Rate Enter the Contractor’s hourly rate.

Total Estimated Cost Enter the Contractor’s estimated total cost to complete the work as outlined in the work authorization.

Completion Criteria Enter the Contractor’s completion criteria for the work to be performed.

Contractor Name Enter the name and title of the Contractor or an individual who is authorized to bind the Contractor’s firm contractually.

Exhibit A, Attachment 4

PERSONNEL CHANGE ORDER REQUEST FORM (SAMPLE)

PERSONNEL CHANGE ORDER NO.

Contractor Name: Agreement Number: CINF90325

Proposed Start Date (or upon approval by SCO, whichever occurs later):

Reason for Change:

Description of Change:

To swap out the following Personnel.

Current Personnel: (Name, classification and hourly rate) Proposed Personnel: (Name including phone number and email address)

Proposed Personnel Classification:

(qualifications must be equal or better than current identified staff)

Proposed Hourly Rate:

(must be less than or equal to current rate)

Attach Resume, Certifications, Degrees and References

(Exhibit A, Attachment 5, Personnel Change Key Staff Reference Form must be included)

Exhibit A, Attachment 4

Approved By:

State Controller's Office Contractor Name - TBD

(Name / Title –Type or Print)

(Name / Title –Type or Print)

Approval:

Changes identified above are in accordance with the terms and conditions of the Agreement.

By signing below, the Contractor Official and SCO ISO CM confirm that the proposed staff meets the key requirements identified in RFQ-ITS EINF90325and has the equivalent knowledge, skill set, and experience of the key staff member previously approved.

Exhibit A, Attachment 5

PERSONNEL CHANGE KEY STAFF REFERENCE FORM (SAMPLE)

Exhibit A, Attachment 5, Personnel Key Staff Reference Form, must be completed for the proposed staff.

References must support the intent of the Agreement and be able to provide an objective assessment of the Proposed Key Staff performance. The references cannot be current employees of the Contractor’s company.

No reference, project, or contact name may be used more than once per identified Key Staff.

Proposed Key Staff Name:

Proposed Key Staff Classification:

Reference Client Name:

Reference Contact Name and Title:

Telephone: Email:

Project Description:

Key Staff involvement on this project:

Approximate Value or Cost of Agreement: $

Key Staff Begin/End Dates (MM/DD/YYYY) From: To:

Report Field Report Field Description Responsible Party

Reporting Period

Identifies the current 6-month reporting period that will be either July - December (due by January 31) or January - June (due by July 31) Prime Contractor

Prime Contractor Information Name Full Legal Name Prime Contractor Agreement Number Executed agreement number SCO Contracts & Procurement Office Agreement Amount Total agreement amount for the agreement term SCO Contracts & Procurement Office Amount Invoiced During Current

6-Month Reporting Period Dollar amount invoiced during the current reporting period. Prime Contractor

Amount Invoiced During Contract Term

Cumulative dollar amount invoiced by the Prime Contractor during the agreement term Prime Contractor

List of CA certified SB

A) SB Subcontractor's Name

DGS certified SB identified on the Bidder Declaration submitted with the bid response and/or approved by SCO during the term of the Agreement SCO Contracts & Procurement Office

B) SB Certification Number DGS assigned SB certification number SCO Contracts & Procurement Office

C) Commitment Percentage

Percentage commitment to the SB for the agreement term as identified on the Bidder Declaration submitted with the bid response and/or approved by SCO during the term of the Agreement SCO Contracts & Procurement Office

D) Commitment Amount Dollar amount spend committed to the SB for the agreement term SCO Contracts & Procurement Office

E) Amount Paid to SB During Current 6-Month Reporting Period Amount paid to SB during the current reporting period Prime Contractor

Instructions on how to complete Exhibit A, Attachment 3

State Controller's Office RFQ-ITS Number EINF90325

Exhibit A, Attachment 6

PRIME CONTRACTOR'S CERTIFICATION-

SMALL BUSINESS SUBCONTRACTOR REPORT

F) Percentage Paid to SB during Current 6-Month Reporting Period

Percentage of agreement spend paid to the SB during the current reporting period

Auto-Calculates based on the Prime Contractor's total amount invoiced during the reporting period.

G) Total Paid to SB During Agreement Term Cumulative amount paid to SB for all reporting periods during the agreement term Prime Contractor

H) Percentage Paid to SB During Agreement Term

Total percentage of agreement spend paid to the SB during the agreement term

Auto-Calculates based on the Prime Contractor's total amount invoiced during the Agreement term.

I) Variance Actual % vs. Commitment % Comparison of the percentage of agreement spend committed to with the actual spend Auto-Calculates

J) Comments/Explanations Section for Contractor to provide any clarifying or important information Prime Contractor

State Controller's Office RFQ-ITS Number EINF90325

Exhibit A, Attachment 6

Begin through End

(B)

SB

Certification Number

(C) Commitment

Percentage

(D) Commitment

Amount

(I) Variance

Comitment Percentage vs.

Actual

Percentage

1 -$ #DIV/0!

2 #DIV/0!

3 #DIV/0!

4 #DIV/0!

5 #DIV/0!

6 #DIV/0!

7 #DIV/0!

8 #DIV/0!

14 -$ -$

Amount Invoiced During Contract

Term

Agreement Payment Information

Name

Reporting Period

Prime Contractor Information

Payment Information

State Controller's Office

Grand Total #DIV/0!

List all California certified Small Business (SB) firms performing services as a subcontractor for this agreement.

#DIV/0!-$

#DIV/0!

(G) Total Paid to SB

During Agreement Term

(E) Amount Paid to SB During Current 6- Month Reporting

Period

(H) Percentage Paid to SB

During Agreement

Term

(A) SB Subcontractor(s) Name

SB Information Commitment Information (F)

Percentage Paid to SB During Current 6-

Month Reporting Period

Agreement Amount Invoiced During Current 6- Month Reporting

Period

Number

Amount

-$ #DIV/0!

Prime Contractor's Certification - Small Business Subcontractor Report

State Controller's Office RFQ-ITS Number EINF90325

Attach copies of this page for additional lines

(J) Comments/Explanations

Title:

Prime Contractor Contract Manager Print Name:

Signature:

I certify under penalty of perjury under the laws of the State of California that all information submitted is true and correct.

Date Signed:

State Controller's Office RFQ-ITS Number EINF90325

Exhibit B

BUDGET DETAIL AND PAYMENT PROVISIONS

A. Invoicing and Payment

1. For services satisfactorily rendered, and upon receipt and approval of the invoices, SCO agrees to compensate the Contractor for actual expenditures incurred in accordance with the rates specified in Exhibit B, Attachment 1, Cost Worksheet.

2. Itemized invoices shall be submitted on Contractor’s letterhead, not more frequently than monthly, in arrears and must include:

Contractor’s Name Agreement Number – CINF90325 Key Staff’s Name Approved Deliverable Expectation Document (DED) Approved Deliverable Acceptance Document (DAD) Approved Work Authorization, as applicable Total number of hours worked Invoices must be submitted with all required supporting documentation. Incomplete or incorrect invoices will be rejected and returned for correction.

If submitting electronically, send one (1) PDF copy to: ADMAP@sco.ca.gov

If invoices cannot be submitted electronically, please mail one (1) copy to:

Departmental Accounting Office P.O. Box 942850

Sacramento, CA 94250

Invoice inquiries: ADMAP@sco.ca.gov

B. Budget and Contingency Clause

1. It is mutually agreed that if the Budget Act of the current year and/or any subsequent years covered under this agreement does not appropriate sufficient funds for the program, this agreement shall be of no further force and effect. In this event, SCO shall have no liability to pay any funds whatsoever to contractor or to furnish any other considerations under this agreement and contractor shall not be obligated to perform any provisions of this agreement.

2. If funding for any fiscal year is reduced or deleted by the Budget Act for purposes of this program, SCO shall have the option to either cancel this agreement with no liability occurring to SCO or offer an agreement amendment to contractor to reflect the reduced amount.

C. Prompt Payment Clause

Payment will be made in accordance with, and within the time specified in, Government Code Chapter 4.5, commencing with Section 927.

E. DVBE Subcontractor Authorization to Withhold $10,000

Exhibit B

SCO will withhold $10,000, or full payment if less than $10,000, from a prime contractor’s final payment pending receipt of a complete and accurate Prime Contractor’s Certification – DVBE Subcontracting Report STD 817. The report must be received within 60 days of the Agreement expiration date.

Exhibit B, Attachment 1

COST WORKSHEET

To be inserted upon award of agreement.

Exhibit C

INFORMATION TECHNOLOGY GENERAL PROVISIONS NON-CLOUD

GOODS & SERVICES DGS PD 403-ITGP (Non-Cloud)

Exhibit C, Information Technology General Provisions Non-Cloud Goods & Services DGS PD 403-ITGP Non- Cloud (Revised 02/2025), shall be incorporated by reference only and made part of the Agreement as if attached hereto.

Information Technology General Provisions Non-Cloud Goods & Services DGS PD 403-ITGP Non-Cloud (Revised 02/2025) may be viewed and downloaded at Internet site https://www.dgs.ca.gov/- /media/Divisions/PD/Acquisitions/Solicitation-Document-Attachments/IT-General-Provisions-NonCloud-DGS- PD-403ITGP-Revised-02202025.pdf.

If you do not have Internet access, a hard copy can be provided.

Exhibit D

SPECIAL TERMS AND CONDITIONS

A. Insurance Requirements

The Contractor shall display evidence of the following coverage on an Acord certificate:

1. Commercial General Liability Insurance – The Contractor shall maintain general liability on an occurrence form with limits not less than $1 million per occurrence for bodily injury and property damage liability combined with a $2 million annual policy aggregate. The policy shall include coverage for liabilities arising out of premises, operations, independent contractors, products, completed operations, personal and advertising injury, and liability assumed under an insured agreement. This insurance shall apply separately to each insured against whom claim is made, or suit is brought subject to the Contractor's limit of liability. The policy shall include the State of California, its officers, agents, employees, AKT, The Evergreen Company (TEC), and CFT NV Developments LLC c/o LPC West, Inc. as additional insured’s. The additional insured endorsement must be provided.

2. Workers’ Compensation and Employer’s Liability – The Contractor shall maintain statutory workers’ compensation insurance issued and shall furnish to State Controller's Office (SCO) a certificate of insurance evidencing workers’…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .