R25-038DS Privileged Access Management RFI.pdf

PDF 372 KB Posted

Attached to
Privileged Access Management State and local contract opportunity
Solicitation number
R25-038DS
Issued by
El Paso County, Colorado

About this file

This is a Request for Information (RFI) issued by the City of Colorado Springs Procurement Services for a Privileged Access Management (PAM) solution to enhance the city's cybersecurity capabilities. The RFI is designed to gather information from potential vendors about available PAM technologies in the marketplace, with the goal of determining the number of qualified sources and understanding budgetary requirements. The RFI was issued on April 4, 2025, with responses due by May 2, 2025, at 4:30 pm MST through the Rocky Mountain E-Purchasing System. The city is specifically seeking PAM solutions that provide detailed control, monitoring, and logging of privileged accounts while ensuring users do not have direct access to privileged credentials.

The RFI includes a comprehensive set of cybersecurity vendor questions covering topics such as data rider agreements, single sign-on/multi-factor authentication support, SOC2 certification, cyber security insurance, breach communication processes, vulnerability testing, and industry security frameworks. Vendors are required to provide detailed company information, background, municipal experience, and estimated cost quotes. The document emphasizes that this RFI is non-binding and is primarily used for information gathering and potential future competitive procurement. If the RFI determines there are sufficient interested and qualified vendors with favorable monetary estimates, the city may subsequently issue a formal Request for Proposal (RFP) for PAM services.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

REQUEST FOR INFORMATION

Privileged Access Management

Dylan Smith City of Colorado Springs Procurement Services

107 N. Nevada Ave Suite 125 Colorado Springs, CO 80903

TEL: (719) 385-5240

E-Mail: Dylan.Smith2@coloradosprings.gov.

Issue date: April 4, 2025 mailto:Dylan.Smith2@coloradosprings.gov

1.1 PURPOSE

The City of Colorado Springs is requesting information from organizations interested in providing privileged access management (PAM) solutions to enhance the City’s cybersecurity posture.

It is the City's intent to issue this Request for Information (RFI) to determine whether there are a sufficient number of interested and qualified sources that can provide the requested software system and to understand budgetary needs.

1.2 REQUESTS FOR INFORMATION DEFINITION

Responses to this RFI are considered non-binding and are only used to gather information to be used for budgetary and specification preparation purposes. It will also be used to determine the number of companies that exist in the industry for a possible future competitive procurement.

It is not the intent of the City to award a contract as a result of this RFI. If this RFI determines that there are sufficient interested and qualified vendors/contractors and favorable monetary estimates, the City may issue a formal RFP (Request for Proposal) for these services. If an RFP is issued, then all firms that responded to this RFI will be added to our source list and will be formally invited to propose.

1.3 BACKGROUND

The City of Colorado Springs would like information on available PAM technologies in the marketplace that provide detailed control, monitoring, and logging of privileged accounts, while ensuring users do not have direct access to privileged credentials. Privileged accounts or the escalation of account permissions represent a significant cybersecurity risk and a potential threat to IT service availability. To mitigate these risks, The City’s Cybersecurity team requires a robust PAM solution.

1.4 CITY OF COLORADO SPRINGS CYBER SECURITY VENDOR QUESTIONS

Please answer the following questions for the City Information Technology Office:

1. Will the vendor sign or request changes to the City Information Technology Data Rider, included in Exhibit 1 of this RFI?

2. Does the vendor solution support the uses of SSO/MFA?

3. Does the vendor have a current Cyber Security SOC2 certification? If not, please explain why.

4. Does the vendor maintain Cyber Security insurance? What are those liability thresholds for each deployed solution?

5. What is the vendor process for communicating a security breach or incident to its customers?

6. Does the vendor conduct any recurring vulnerability or penetration testing?

7. What industry standard frameworks does the vendor use to maintain solution security?

1.5 PROCEDURAL INFORMATION

A. Inquiries

Questions about the RFP must be submitted electronically with BidNet. A written response to any inquiry may be provided in the form of an Amendment to the solicitation. Questions are due by 4:30 PM April 18, 2025

Request for information or support shall be addressed to:

Dylan Smith Dylan.Smith2@coloradosprings.gov.

Amendments to this RFI may be issued at any time prior to the time set for receipt of submittals. The City will post all addenda using the Rocky Mountain E-Purchasing System (www.bidnetdirect.com) It is the respondent’s responsibility to check the website for posted addenda.

1.6 RESPONSE SUBMISSION

Responses should be prepared simply and economically while still providing pertinent details of the vendor's ability to meet the requirements specified in this document (or portions thereof) and as stated below. At a minimum they should include the following information:

1. Company name, owner, address, phone #, e-mail, website if applicable.

2. Company background and previous successful relevant experience in PAM solutions

3. Experience working with municipalities

4. Quote providing the estimated cost to be used to help develop a budget.

5. Answers to the Cybersecurity questions in Section 1.4

6. Any additional relevant information.

Responses will be accepted electronically through the Rocky Mountain E-Purchasing System (www.bidnetdirect.com) and must be submitted by May 2, 2025, 4:30 pm MST.

1.7 COST OF RESPONSES

The City of Colorado Springs is not liable for any cost incurred by vendors in preparing their response. Respondents may be asked to clarify or expand upon information provided.

1.8 PROPRIETARY INFORMATION

If a response contains information that the respondent does not want disclosed to the public, or used for any purpose other than the evaluation of this response, all such information must be indicated with the following or similar statement: “The information contained on pages _____, _____, and _____ shall not be duplicated or used in whole or in part for any purpose other than to evaluate the response provided. If a contract is awarded to this firm as a result of the submission of such information, the City of Colorado Springs shall have the right to duplicate, use, or disclose this information to the extent provided in the contract. This restriction does not limit the City of Colorado Springs’ right to use the information herein if obtained from another source.”

All such nondisclosure items specified in the response shall be subject to disclosure as mailto:Dylan.Smith2@coloradosprings.gov http://www.bidnetdirect.com/ http://www.bidnetdirect.com/ provided in the Colorado Open Records Act (CORA) or as otherwise provided by law.

1.9 RESPONSE MATERIAL OWNERSHIP

All material submitted in response to this RFI becomes the property of the City of Colorado Springs except for software products that are made available for demonstration purposes and proprietary material.

EXHIBIT 1 – IT TECHNOLOGY RIDER

FOLLOWS THIS PAGE

City of Colorado Springs Innovation and Technology (IT) Department Technology Rider

City of Colorado Springs Information Technology Department-Cybersecurity

City Technology Rider (Contract Rider) Release v5_DRAFT

Introduction The IT Technology Rider was created to ensure good and proper cyber hygiene is implemented and practiced on technology that is installed on vendor technology systems, services used by the City to execute City operations, or within the City’s on-premises (on-prem) network. Vendor cloud-based technology systems and services are most often consumed as Software-as-a-Service (SaaS), Platform-as-a-Service (PaaS), or Infrastructure-as-a- Service (IaaS). By ensuring good and proper cyber hygiene, due diligence is applied to vendor engagements to prevent and/or minimize the likelihood of cyber incidents negatively impacting public safety and municipal operations through loss of availability or capability, unauthorized use, destruction, or modification of technology or data.

Binding Intentions of this Technology Rider This rider applies directly to the actual Service Provider (operator or original equipment operator (OEM)) and the vendor (together, jointly and severally, the “Vendor”) of the service being consumed by the City. If the service is purchased through a value-added reseller (VAR), the VAR hereby certifies and guarantees it will obtain signature of this Technology Rider by the Service Provider and return proof of said signature approval with the VAR’s final signed contract.

Scope This IT Technology Rider is applicable to all City contracts and other vendor engagements where vendors provide one or more of the following:

- Storage and/or transmission of City sensitive and/or restricted data;

- Storage and/or transmission of City data that is the source of record with any City data classification level;

- Computation and analytic capabilities required as part of the delivery of a City service or capability;

- Technology installed directly onto the City on-prem network or cloud-based network infrastructure, Infrastructure as a Service (IaaS), and/or Platform as a Service (PaaS);

- Application integrations that allow data sharing between a City technology asset and a third-party technology asset;

- The technology or Service directly underpins a business process with a Business Impact Analysis (BIA) tier classification of 0-2;

- Primary and secondary internet service provider (ISP) contracts;

- Managed service provider (MSP) or Managed security service provider (MSSP) contracts, to include any vendor engagement requiring access to any type of City asset in order to perform any support, design, or maintenance activities;

- When Artificial Intelligence (AI) or Machine Learning (ML) are included in a technology or service and the output will require business action, will drive business spending, or is automated to a business process;

or

- If City Data will be ingested or consumed by an AI/ML platform and may be shared with third parties or leveraged in the learning data set.

After departmental request and approval from City IT, the following do not require the IT Technology Rider:

- Hardware only purchases with no third-party software installed;

- Subscriptions to web-based research and analysis services that do not include any of the above configurations;

- Software technology purchased and installed on City network infrastructure by City IT personnel;

- Some transport/circuit only contracts;

- Vendor training engagements/workshops where vendor does not have access to City sensitive and/or restricted data on their corporate systems;

- If the only scope element that requires this technology rider is the sole source of data and the business element procuring/using this service determines it does not pose any impact to necessary services, without the possibility of loss or discontinuation of service; or

City Technology Rider (Contract Rider) Release v5_DRAFT

- If City IT Cyber staff can articulate an appropriate reason and the business unit procuring or consuming the service agree this rider may be excepted.

Minimum Requirements The following minimum requirements will be applied to Vendor’s staff, technology, information systems, services, and applications. At any time during the term of service, the IT Department may request a written attestation from the Vendor for any of the following minimum requirements. The Vendor shall provide the written attestation within fifteen (15) business days of City’s request. Minimum requirements will be noted and applied when providing direct support to City on-premises or cloud-based information systems (IaaS/PaaS)).

City and Vendor Governance

1) Vendor Governance: During the term of service, the Vendor shall operate an information security program designed to meet the confidentiality, integrity, and availability (CIA) requirements of the service or product being supplied. Vendor shall ensure all of its partners and sub-contractors meet or exceed the same requirements.

a) Information Security Policy: Vendor shall develop, implement, and maintain an information security policy and shall communicate the policy to all of Vendor’s employees, agents, representatives, and contractors.

b) Information Security Accountability: Vendor shall appoint and identify to the City an employee who shall be accountable for Vendor’s information security program. Minimum contact information shall include said employee’s name, primary phone number, and email address. The City shall be updated regarding changes in this point of contact within thirty (30) days of a change.

c) Risk Management: Vendor shall employ a formal risk assessment process to identify security risks that may impact the products or services being supplied and to mitigate risks in a timely manner commensurate with the risk.

2) City Governance: (NOTE: Only applies when providing direct support to City on-premises or cloud-based information systems (IaaS/PaaS))

a) Vendor shall comply with applicable City technology policies and governance, such as, but not limited to, the City’s Acceptable Use Policy, Privileged Account Acceptable Use Policy, Password Policy, Colorado Privacy Law (C.R.S. § 6-1-713 et seq.), Purchase Card Industry Data Security Standards (PCI DSS), and the Criminal Justice Information System Security Policy (CJIS) (external) during the life cycle of the service.

Asset Management

3) Asset Inventory: Vendor shall maintain an inventory of all Vendor hardware and software assets used to provide service to the City.

4) Data Classification: Vendor shall develop, implement, and maintain a data classification scheme and process designed to ensure that Vendor data used to provide service to the City is protected according to its confidentiality requirements.

Supply Chain Risk Management

5) Supplier Security Assessments: Vendor shall engage in appropriate due diligence assessments of potential suppliers that may impact the security of the services or products being supplied to the City.

6) Security in Supplier Agreements: Vendor shall ensure that agreements with suppliers who may impact the security of the services or products being supplied to the City contain appropriate security requirements.

City Technology Rider (Contract Rider) Release v5_DRAFT

Human Resource Security

7) Information Security Awareness: Vendor shall develop and implement an information security awareness program designed to ensure that all Vendor employees and contractors receive security education as relevant to their job function.

8) Background Checks: Vendor shall conduct an appropriate background review on all new employees, based on the sensitivity of the role that they are being hired for within the Vendor’s organization.

Vendor Identity Management, Authentication, and Access Control

9) Authentication: Vendor shall ensure that all access by Vendor’s employees, agents, representatives, and contractors to City or Vendor systems used to provide services or supply products, require appropriate authentication controls that, at a minimum, include:

a) Strong passwords/passphrases, or multi-factor authentication for users; and

b) Multi-factor authentication for all remote access.

10) Authorization: Vendor shall ensure that all access to the Vendor’s information systems, used to provide services or supply products to the City, is authorized by a Vendor approved identity and access management process.

11) Privileged Account Management: Vendor shall appropriately manage and control privileged accounts on the Vendor’s information systems that, at a minimum, includes:

a) Use of dedicated accounts for privileged activity; and

b) Maintaining an inventory of privileged accounts.

12) Access Termination: Vendor shall develop and maintain a process designed to ensure that user access to the Vendor’s information system, and/or network is revoked upon termination of employment, or revoked upon termination or expiration of a contractor’s contract, as applicable.

City Network Access and Vendor Remote Access System

13) City Network Access Request: (NOTE: Only applies when providing direct support to City on-premises or cloud-based information systems (IaaS/PaaS))

a) Staff augmentation services (where one or more of Vendor’s employees is augmenting City IT staff): Each Vendor employee must (i) complete City Cybersecurity Awareness Training; (ii) read, sign, and comply with City Acceptable Use Policy; and, (iii) if required, complete the City Privileged Account Acceptable Use Policy/Vendor Access Policy.

b) Managed Services (where a full service is provided by Vendor): Vendor shall identify a company officer or program manager that can read and sign the Acceptable Use Policy and, if required, the City Privileged Account Acceptable Use Policy/Vendor Access Policy, and ensure all Vendor employees comply with same.

c) Access Termination: The City reserves the right to limit or terminate any City network account at any time, in its sole discretion, to protect City information systems and data.

14) Vendor Remote Access System: Vendor shall ensure that all access, by employees or contractors, to the Vendor’s information systems, used to provide services or supply products to the City, require appropriate authentication controls, that, at a minimum, include:

a) Strong passwords/passphrases or multi-factor authentication for users;

b) Multi-factor authentication for all remote access; and

c) Maintaining an inventory of privileged accounts.

City Technology Rider (Contract Rider) Release v5_DRAFT

Data Custodian, Access, Ownership, and Security

15) Data Access: Vendor will provide access to receive and store raw data via City approved interfaces during the subscription or license period.

a) Data should include both structured and unstructured data.

b) These interfaces are typically Application Programing Interface (API) (i.e., REST), direct database access, or delimited files per Secure File Transfer Protocol (SFTP) transfer. Other mechanisms may be accepted at the written discretion of the City.

c) Access to data shall not be throttled or disabled without prior written approval and agreement from the City.

d) Data should always (24x7x365) be available at download speeds acceptable to the City.

16) Data Ownership: Data generated by the City (i.e. data entry), as well as unique data derived from City data, is owned solely by the City at all times. As such, Vendor shall not mine or share data, aggregated, itemized, or otherwise, with third party entities, without the prior written consent of City.

17) Encryption: Vendor shall ensure all Vendor laptops, mobile devices, and removable media owned by Vendor and Vendor’s employees, agents, representatives, and contractors that are used to store, process, or transport City identified restricted or sensitive organizational data are encrypted at all times. Encryption shall meet or exceed current industry standards and best practices.

18) Secure Disposal: Vendor shall ensure all Vendor media and technology that is used to store, process, or transport City data is disposed of in compliance with industry recognized disposal methods approved by City

System Acquisition, Development, and Maintenance

19) Security Requirements: Vendor shall ensure that information security requirements are defined for all new

Vendor information systems, whether acquired or developed.

20) Separation of Environments: Vendor shall ensure that Vendor development and testing environments are separate from its production environments.

21) Data Anonymization: Vendor shall not use City data in the development or testing of new systems unless the data is appropriately anonymized and prior written approval from the City is obtained.

22) Secure Coding: Vendor shall ensure that all Vendor applications are developed with secure coding best practices, such as the OWASP Top 10 Most Critical Web Application Security Risks.

Physical and Environmental Security

23) Risk Assessment: Vendor shall use a formal risk assessment methodology to identify physical and environmental threats to Vendor and implement controls to minimize the risks.

Information Protection Processes and Procedure

24) Hardening: Vendor shall develop and implement security configuration baselines for all Vendor endpoint and network device types.

25) Network Segregation: Vendor shall segregate the Vendor network into zones based on trust levels and control the flow of traffic between said zones.

26) Anti-Malware: Vendor shall ensure that all Vendor information systems that are susceptible to malware are protected by up-to-date anti-malware software.

27) Wireless Access Control: Vendor shall ensure that the Vendor’s wireless network access is protected, including, at a minimum:

City Technology Rider (Contract Rider) Release v5_DRAFT

a) All wireless network access should be encrypted;

b) All wireless network access to the production network should be authenticated using multi-factor authentication, such as machine certificates; and

c) Wireless network access for personal devices and guest access should be segregated from the production network.

28) Patching: Vendor shall evaluate, test, and apply patches to Vendor information systems in a timely fashion, according to their risk.

29) Disaster Recovery: Vendor shall create, maintain, and exercise tools, techniques, and procedures to enable the recovery and/or continuation of service in the event of an unexpected disaster (environmental, man-made, cyber-attack, or other). This includes, but is not limited to, a backup and recovery process designed to ensure that the Vendor’s data and City’s data can be promptly recovered within documented recovery point objectives (RPO) in the event of an unexpected loss.

Protective Technology

30) Logging: Vendor shall ensure that security event logging requirements have been defined and that all of

Vendor’s information systems are configured to meet logging requirements.

31) Intrusion Detection: Vendor shall deploy intrusion detection or prevention systems at the Vendor’s network perimeter.

32) Denial of Service Protection: Vendor shall deploy a control to detect and mitigate denial of service attacks against Vendor networks and information systems used to provide services to the City.

Security Continuous Monitoring

33) Security Monitoring: Vendor shall deploy automated tools to collect, correlate, and analyze security event logs from multiple sources, and monitor them for suspected security incidents on Vendor networks and information systems used to provide services to the City.

34) Vulnerability Assessments: Vendor shall conduct vulnerability assessments against all Vendor internet-facing information systems on a regular basis.

35) Penetration Testing: Vendor shall perform penetration tests on all vendor web applications and services used to provide services to the City, in accordance with standard penetration testing methodologies, on a regular basis, no less often than annually.

Artificial Intelligence (AI) or Machine Learning (ML)

36) Security Features: Vendor shall ensure security controls are enabled to prevent City data leakage to AI or

ML systems. The Vendor shall also ensure prevention measures are in place to minimize impacts from adversarial machine learning.

37) Vendor shall ensure that there are proper technical and human security controls in place that prevent AI/ML misuse.

38) Management of AI/ML platform: Vendor staff must undergo annual training to protect the AI/ML platform.

The Vendor must establish and maintain procedures to enhance the quality of AI/ML platform outputs, including appropriate human oversight to minimize errors and bias.

39) The Vendor shall adhere to a framework, such as ISO/IEC 42001:2023 or NIST AI Risk Management Framework (RMF), to ensure trustworthiness is integrated into the design, development, deployment, management, and utilization of AI systems.

Cyber Insurance

City Technology Rider (Contract Rider) Release v5_DRAFT

40) A Technical Errors & Omissions policy is required. For details on policy requirements see Section 4 of the City contract.

Information Security Incident Management

41) A Cybersecurity Incident is defined as: An event that, without lawful authority, jeopardizes, disrupts, or otherwise impacts, or is reasonably likely to jeopardize, disrupt, or otherwise impact, the integrity, confidentiality, or availability of computers, information, or communications systems or networks, physical or virtual infrastructure controlled by computers or information systems, or information residing on the system.

42) Incident Response: Vendor shall develop, implement, and maintain an information security incident response process and will test the process on a regular basis, no less often than annually.

43) Data Breaches: Vendor shall provide written notice to the City of any unauthorized access, acquisition, or disclosure of City data or information systems. Additionally, the Vendor shall provide written notice to the City of any unauthorized access or acquisition of Vendor information systems that could negatively impact CIA of City data or operations.

44) Vendor acknowledges and understands that it will have access to City’s confidential information (“Confidential Information”) under this Contract, including, but not limited to, personally identifiable information (PII), employee health information, financial information, and other sensitive and restricted information. Vendor agrees, warrants, and guarantees that it will protect all Confidential Information and shall not disclose the Confidential Information to any party other than City. All Confidential Information shall be kept strictly confidential by Vendor. Vendor shall not directly or indirectly disclose, publish, communicate, or make available Confidential Information, or allow it to be disclosed, published, communicated, or made available, in whole or part, to any third-party entity or person, except with the prior written consent of City. Vendor, its employees, agents, and contractors shall not access or use any Confidential Information, and shall not copy or remove any documents, records, files, media, or other resources containing any Confidential Information, in a manner inconsistent with this Contract. Nothing in this Contract shall be construed to prevent disclosure of Confidential Information as may be required by applicable law or regulation, or pursuant to the valid order of a court of competent jurisdiction or an authorized government agency. Vendor understands and acknowledges that its obligations under this Contract with regards to any Confidential Information shall commence immediately upon Vendor first having access to such Confidential Information and shall continue until such time as such Confidential Information has become public knowledge.

45) All City owned data and Confidential Information shall be secured by Vendor in a manner at least as stringent as that used by City. All City owned data and Confidential information shall be maintained and secured by Vendor in accordance with all federal, state, and local laws, including, but not limited to, the Health Insurance Portability and Accountability Act (HIPAA) and Criminal Justice Information Services (CJIS) regulations. Upon termination or expiration of this Contract, at City’s option,

46) Vendor shall protect all City Confidential Information from unauthorized access, use, modification, disclosure, or destruction. In accordance with C.R.S. § 24-73-102 and C.R.S. § 6-1-713.5, Vendor shall implement and maintain reasonable security procedures and practices that are: (a) appropriate to the nature of the personal identifying information disclosed to Vendor; and (b) reasonably designed to help protect the personal identifying information from unauthorized access, use, modification, disclosure, or destruction. Vendor shall have primary responsibility for implementing and maintaining said security procedures and practices. Vendor shall be solely liable for any security breach and will comply with all provisions of C.R.S. § 6-1-716 and C.R.S.

§ 24-73-103 and provide all required notices.

47) Cybersecurity Incident and Data Breach Reporting:

a) The Vendor shall provide notice, in accordance with Subsection (b) of this section, to the City within eighteen (18) hours of becoming aware of any security breach that has or may negatively impact City

City Technology Rider (Contract Rider) Release v5_DRAFT data and/or information systems in order to allow the City to meet required Federal and State reporting requirements.

b) Reporting delivery shall be made verbally and in writing to the City’s Chief Information Security Officer (CISO). The following reporting methods must both be executed:

i) Encrypted electronic mail with a Subject line of “COCS Breach Notification” sent to:

ITCyberSecurity@ColoradoSprings.gov; and

ii) Voice call to the IT Service Desk: 719-385-5831.

c) In the initial report, the following minimum data shall be provided:

i) Details that caused the incident/breach;

ii) Whether the incident/breach involved City data exposure, scanning, exfiltration, destruction/modification, or other misuse or misappropriation of City data of any classification;

iii) The amount and nature of the City data involved in the incident/breach;

iv) The entity, if known, that gained access to City data or information systems; and

v) The initial plan to contain and eradicate incident/breach.

d) In Follow-up and Closure reports, the following minimum data shall be provided:

i) Any updated details to the information provided in the initial report;

ii) Validation that the incident/breach has been confirmed actual, false positive, or benign;

iii) Updated containment, eradication, and resolution plans; and

iv) Final root cause analysis (RCA) and documented impact to the City.

Payment Card Industry (PCI) Data Security Standard (DSS) Compliance:

(NOTE: Only applies when vendor is to provide financial transactions services for or on behalf of the City in the execution of activities during the term of service.)

48) Vendor solutions shall be fully compliant with the PCI DSS, with no requirement for the City to implement any PCI DSS controls. If installed on City networks or infrastructure, the Vendor solution shall be PCI DSS Point-to-Point Encryption (P2PE) compliant.

49) Report of Compliance (RoC): For all solutions that are consumed without any City responsibility to implement PCI DSS controls, Vendor shall provide City Finance with a RoC. The RoC shall be sent to:

a) City Finance at: accountants@coloradosprings.gov.

b) Questions or follow-up delivery confirmation can be called into 719-385-5224.

50) Self-Assessment Questionnaire (SAQ): In the event the City is required to provide any PCI DSS required SAQ in relation to Vendor’s solution, the Vendor shall support the completion of the SAQ where applicable.

Vulnerability and Audit Mitigation

51) The City reserves the right to request audit results or the attestation that specific audits have been conducted and mitigation actions have been completed. For open findings, the City reserves the right to request attestation that the findings have proper mitigation controls in place or a resolution roadmap.

52) For applicable vulnerabilities released as a common vulnerabilities and exposures (CVE) 10, an emergency directive from the DHS Cybersecurity and Infrastructure Agency (CISA), or product vendor “Patch Now” recommendation, Vendor shall provide a statement of resolution or an executable mitigation plan within thirty

(30) calendar days of the CVE or CISA release.

mailto:ITCyberSecurity@ColoradoSprings.gov mailto:accountants@coloradosprings.gov

City Technology Rider (Contract Rider) Release v5_DRAFT

Contract completion or termination

53) Within thirty (30) calendar days of contract expiration or termination, the Vendor shall deliver to the City, a signed attestation that the following actions were completed:

a) Vendor shall return all City data to the City in a structured and secured digital format compatible with City information systems and technology standards.

b) Vendor shall delete all City technology credentials retained in or stored in any Vendor-owned systems upon expiration or termination of City contract.

c) All connections made to the City network or information systems shall be terminated upon expiration or termination of City contract.

d) All City data residing on any Vendor owned system is fully and completely removed and returned to the City or destroyed beyond restoration with industry standard destruction practices.

Exception Requests

- Depending on Vendor provided justification, some requirements herein may be reserved by City.

- Vendor may provide a written request for City review and submit a change request to City Procurement to start the review and exception process. If approved, changes will be made and accepted by incorporating approved changes into the final signed and executed contract.

R25-038DS Privileged Access Management RFI
1.1 PURPOSE
1.2 REQUESTS FOR INFORMATION DEFINITION
A. Inquiries

City_IT_TechnologyRider_Ver_5 1

File details come from the government source that posted it. Updated .