HomeMy WebLinkAboutRFP - 9046 AUTOMATED CUSTOMER CONSENT MANAGEMENTRFP 9406 Automated Customer Consent Tracking Page 1 of 28
REQUEST FOR PROPOSAL
9046 AUTOMATED CUSTOMER CONSENT MANAGEMENT
The City of Fort Collins is requesting proposals from qualified Vendors for a solution to formalize
and manage the automation and verification of customer data exchange.
As part of the City’s commitment to Sustainable Purchasing, proposals submission via
email is preferred. Proposals shall be submitted in a single Microsoft Word or PDF file
under 20MB and e-mailed to: purchasing@fcgov.com. If electing to submit a hard copy
proposal we require one (1) hard copy and one (1) electronic copy on a jump drive to be
received at the City of Fort Collins' Purchasing Division, 215 North Mason St., 2nd floor, Fort
Collins, Colorado 80524. Proposals must be received before 3:00 p.m. (our clock) on
November 1, 2019 and referenced as Proposal No. 9046 Customer Consent Management.
If delivered, they are to be sent to 215 North Mason Street, 2nd Floor, Fort Collins, Colorado
80524. If mailed, the address is P.O. Box 580, Fort Collins, 80522-0580. Please note,
additional time is required for bids mailed to the PO Box to be received at the Purchasing Office.
The City encourages all Disadvantaged Business Enterprises (DBEs) to submit proposals in
response to all requests for proposals. No individual or business will be discriminated against
on the grounds of race, color, sex, or national origin. It is the City’s policy to create a level
playing field on which DBEs can compete fairly and to ensure nondiscrimination in the award
and administration of all contracts.
All questions should be submitted, in writing via email, to Marisa Donegon, Buyer at
mdonegon@fcgov.com, no later than 5:00 PM MST (our clock) on October 23, 2019. Please
format your e-mail to include: RFP 9046 Customer Consent Management in the subject line.
Questions received after this deadline may not be answered. Responses to all questions
submitted before the deadline will be addressed in an addendum and posted on the Rocky
Mountain E-Purchasing System webpage.
Rocky Mountain E-Purchasing System hosted by Bidnet
A copy of the RFP may be obtained at http://www.bidnetdirect.com/colorado/city-of-fort-collins.
This RFP has been posted utilizing the following Commodity Code(s):
20832 Customer Relationship Management Software (CRM)
20880 Software, Microcomputer (Not Otherwise Classified)
20890 Utilities: Back-up, Batch File, Firewall, Menus, Operating System, Network
Operating System, Network Management, Recovery, Screen, Security, Virus
Protection, etc.
91829 Computer Software Consulting
91897 Utilities: Gas, water, Electric Consulting
Public Viewing Copy: The City is a governmental entity subject to the Colorado Open Records
Act, C.R.S. §§ 24-72-200.1 et seq. (“CORA”). Any proposals submitted hereunder are subject
to public disclosure by the City pursuant to CORA and City ordinances. Vendors may submit
one (1) additional complete proposal clearly marked “FOR PUBLIC VIEWING.” In this version
RFP 9406 Automated Customer Consent Tracking Page 2 of 28
of the proposal, the Vendor may redact text and/or data that it deems confidential or proprietary
pursuant to CORA. Such statement does not necessarily exempt such documentation from
public disclosure if required by CORA, by order of a court of appropriate jurisdiction, or other
applicable law. Generally, under CORA trade secrets, confidential commercial and financial
data information is not required to be disclosed by the City. Proposals may not be marked
“Confidential” or ‘Proprietary’ in their entirety. All provisions of any contract resulting from
this request for proposal will be public information.
New Vendors: The City requires new Vendors receiving awards from the City to fill out and
submit an IRS form W-9 and to register for Direct Deposit (Electronic) payment. If needed, the
W-9 form and the Vendor Direct Deposit Authorization Form can be found on the City’s
Purchasing website at www.fcgov.com/purchasing under Vendor Reference Documents. Please
do not submit with your proposal.
Sales Prohibited/Conflict of Interest: No officer, employee, or member of City Council, shall
have a financial interest in the sale to the City of any real or personal property, equipment,
material, supplies or services where such officer or employee exercises directly or indirectly any
decision-making authority concerning such sale or any supervisory authority over the services to
be rendered. This rule also applies to subcontracts with the City. Soliciting or accepting any gift,
gratuity favor, entertainment, kickback or any items of monetary value from any person who has
or is seeking to do business with the City of Fort Collins is prohibited.
Collusive or Sham Proposals: Any proposal deemed to be collusive or a sham proposal will
be rejected and reported to authorities as such. Your authorized signature of this proposal
assures that such proposal is genuine and is not a collusive or sham proposal.
The City of Fort Collins reserves the right to reject any and all proposals and to waive any
irregularities or informalities.
Utilization of Award by Other Agencies: The City of Fort Collins reserves the right to allow
other state and local governmental agencies, political subdivisions, and/or school districts to
utilize the resulting award under all terms and conditions specified and upon agreement by all
parties. Usage by any other entity shall not have a negative impact on the City of Fort Collins in
the current term or in any future terms.
The selected Vendor shall be expected to sign the City’s standard Agreement prior to
commencing Services (see sample attached to this Proposal).
Sincerely,
Gerry Paul
Purchasing Director
RFP 9406 Automated Customer Consent Tracking Page 3 of 28
I. BACKGROUND & OBJECTIVE / OVERVIEW
A. Objective
The City of Fort Collins is requesting proposals from qualified Vendors for a solution to
formalize and manage the automation and verification of customer data exchange.
B. Background
City of Fort Collins Utilities (Utilities) serves more than 65,000 (both single family and
multi-family) electric customers with total annual sales of approximately 1,500 gigawatt-
hours. Utilities also provides water, wastewater, stormwater and financing services.
More information about Utilities can be found at fcgov.com/utilities.
As required by the passage of the City of Fort Collins Building Energy and Water Scoring
amendments to the Municipal Code (Ordinance 2018-144, the “Building Energy and
Water Scoring Ordinance”), building owners are required to enter data into the EPA
ENERGY STAR Portfolio Manager tool including on-site solar generation, natural gas,
electric and water usage data. Owners of approximately 1,600 commercial properties
and approximately 350 multifamily properties are required to comply with this regulation.
Currently, these processes are manual and include a request by the customer to a
Utilities Staff member for usage data or a Staff member request to the customer for
behind-the-meter data. Customers and Staff are burdened by the manual processes and
frequently are unable to fully meet the needs for data requests in a timely manner.
Additionally, Utilities’ Residential Solar Rebate Program supports rebates for more than
300 residential solar photovoltaic (PV) projects per year. More than two dozen
Participating Solar Contractors supporting the Rebate Program consistently seek
customer usage history records in order to develop accurate system sizing analyses and
economic impacts for customer proposals. Utilities Customer Care support team typically
satisfies these requests via phone with rudimentary monthly consumption data.
Improved support systems for these requests would ideally relieve that team load and
offer monthly records for both on-peak and off-peak energy consumption for the previous
24 months. Aligning customer and trade ally data needs for efficiency projects, solar and
battery storage systems, Utilities seeks to support Participating Solar Contractors and
other trade allies with detailed customer load data in order to accurately model the
economic benefit of proposed projects. Utilities also seeks the solar production data that
comes from a solar array in order to support customers in monitoring their solar array’s
performance.
RFP 9406 Automated Customer Consent Tracking Page 4 of 28
II. SCOPE OF PROPOSAL
A. Scope of Work
The overall objectives of the Automated Customer Consent Management program include:
a) Maintain a web-based and user-friendly customer interface that allows customers to
grant or deny various partner contractors access to their Utility data; and
b) Facilitate data transfer and consent management between Utilities and designated third-
party providers/software (EPA Portfolio Manager, solar inverter data, etc.) using RESTful
web APIs; and
c) Allow scalability to support other City of Fort Collins data requests (beyond Utilities).
There are two tasks associated with this program:
Task 1: Automated Customer Consent Tracking and Verification.
Utilities is seeking a Vendor to create a standardized business process for verifying
customer requests for data, connecting usage data to third-party webservices, and collecting
Utility usage information required by the Building Energy and Water Scoring ordinance and
Solar Rebate Program. Tasks shall include the following deliverables:
a) Provide a business process and automate customer consent to release data
following the Colorado Open Records Act for the Release of Customer data that
uses best practices and industry standards; and
b) Manage requestor identity verification control for the consent process, including
verification methods currently used by industry experts and the tradeoffs between
customer ease-of-use and verification rigor; and
c) Manage record retention in a searchable and accessible repository that meets or
exceeds the Colorado Municipal Records Retention Manual.
Task 2: Web Services and Application Program Interface Development.
Utilities Resource Conservation team is seeking a Vendor to provide support in planning,
designing, developing, and implementing a business process and web service within the
Utilities Customer Connections setting (including the Fort Collins Utility’s Customer
Information System). This service will:
a) Provide a web-based user interface from which the user can grant or deny
contractors access to their Utility data as well as initiate data transfer processes; and
b) Connect data via various third-party systems required by Utilities for participation in
Utility program activities. It is preferred that the awarded Vendor meet the
Department of Energy Dataguard principles described in:
https://www.dataguardprivacyprogram.org/downloads/DataGuard_VCC_Concepts_a
nd_Principles_2015_01_08_FINAL.pdf
c) The project will prioritize in year one the following Third Party systems:
RFP 9406 Automated Customer Consent Tracking Page 5 of 28
(1) The Environmental Protection Agency web services for ENERGY STAR Portfolio
Manager. The automation process developed by the Vendor will push Utilities
water and electric data needed to benchmark community buildings using an
Energy Star Score generated by the EPA Portfolio Manager.
(2) Firms participating in Utilities’ Solar Rebate Program. The automation process
developed by the Vendor will push load data to contractors requesting data in
order to accurately model the economic benefit of proposed projects.
d) Tasks shall include connecting Web Services and creating new application program
interfaces (API), including the following key development activities:
(1) Requirements analysis
(2) Programming
(3) Unit testing
(4) Quality assurance for integration testing
(5) Preparing documentation
(6) User training
e) The Vendor shall work with the City’s Project Manager to develop a comprehensive
project plan (roadmap) that identifies the tasks, defines project staff
roles/responsibilities, and provides a timeline for completion of tasks.
f) The Vendor shall work with the City’s Project Manager to develop a communication
plan for project information sharing and comments on a routine basis as well as
quarterly briefings for senior management.
g) The Vendor shall provide ongoing support with identifying problems and providing
solutions for both technical and other project-related issues. The Vendor will be
responsible for providing on-going evaluation of project work, quality, and timeliness
for completion of projects.
B. Deliverables/Milestones
The City intends for the first customers to use the web portal in quarter 2 of 2020. In order
for the portal to qualify for customer use, the following milestones must be met:
• Milestone 1: All customer consent documentation must be recorded and available
for audit as specified in Task 1.
• Milestone 2: Applicable APIs (data connections to the Utility, ENERGY STAR
Portfolio Manager, and any mutually-agreed-upon firms participating in the Solar
Rebate Program) must be available for internal sandbox testing by the Utility.
C. Minimum Qualifications
Experience with a small municipal or co-op utility (20,000 – 70,000 customer system) is
preferred.
RFP 9406 Automated Customer Consent Tracking Page 6 of 28
D. Anticipated Schedule
The following represents the City’s target schedule for the RFP. The City reserves the
right to amend the target schedule at any time.
• RFP issuance: October 14, 2019
• Question deadline: 5:00 PM MST on October 23, 2019
• Proposal due date: 3:00 MST (our clock) on November 1, 2019
• Interviews (tentative): Week of November 18, 2019
• Award of Contract (tentative): December 6, 2019
E. Budget
The budget for this project is not to exceed $100,000 for year 1 costs. Vendors are invited
to submit proposals with the tasks prioritized to aid the City in working together with the
awarded Vendor to identify and implement core tasks within the budget available for this
project.
F. Interviews
In addition to submitting a written proposal, the top-rated Vendors may be interviewed by
the RFP assessment team and asked to participate in an oral presentation to provide an
overview of the company, approach to the project and to address questions. The
evaluation criteria for the oral interviews will be the same as the criteria for the written
evaluations and is included in Section IV.
G. Subcontractors
Vendors will be responsible for identifying any subcontractors in their proposal. Please
note that the City will contract solely with the awarded Vendor; therefore, subcontractors
will be the responsibility of the Vendor.
H. Proposal Format
Please limit the total length of your proposal to a maximum of twenty-five (25) double sided
or fifty (50) single sided 8 ½ x 11” pages (excluding cover pages, table of contents,
dividers and Vendor Statement form). Font shall be a minimum of 10 Arial and margins
are limited to no less than .5” for sides and top/bottom. Extended page sizes, such as 11”
x 17”, count as a single page. Please, no embedded documents. Proposals that do not
conform to these requirements may be rejected.
I. Fees, Licenses, Permits
The successful Vendor shall be responsible for obtaining any necessary licenses, fees or
permits without additional expense to the City. All equipment shall be properly licensed
and insured, carry the appropriate permits and be placarded as required by law.
J. Laws and Regulations
The Vendor agrees to comply fully with all applicable local, State of Colorado and Federal
laws and regulations and municipal ordinances.
RFP 9406 Automated Customer Consent Tracking Page 7 of 28
K. Invoicing and Payment
Invoices should be emailed monthly to invoices@fcgov.com with a copy to the Project
Manager. The cost of the work completed shall be paid to the Vendor each month following
the submittal of a correct invoice by the Vendor indicating the project name, Purchase
Order number, task description, hours worked, personnel/work type category, hourly rate
for each employee/work type category, date of the work performed specific to the task,
percentage of that work that has been completed by task, 3rd party supporting
documentation with the same detail and a brief progress report.
Payments will be made using the prices listed on the agreed-to Price Schedule. In the
event a service is requested which is not listed on the Price Schedule, the Vendor and the
City will negotiate an appropriate unit price for the service prior to Consultant initiating
such work.
The City pays invoices on Net 30 terms.
III. PROPOSAL SUBMITTAL
For this section, Vendors are required to provide detailed written responses to the following
items in the order outlined below. The responses shall be considered technical offers of what
Vendors propose to provide and shall be incorporated in the contract award as deemed
appropriate by the City. A proposal that does not include all the information required may be
deemed non-responsive and subject to rejection.
Responses must include all the items in the order listed below. It is suggested that the Vendors
include each of the City’s questions with their response immediately following the question.
The City of Fort Collins shall not reimburse any firm for costs incurred in the preparation and
presentation of their proposal.
A. Cover Letter / Executive Summary
The Executive Summary should highlight the content of the proposal and features of the
program offered, including a general description of the program and any unique aspects
or benefits provided by your firm.
Indicate your availability to participate in the interviews/demonstrations on the proposed
dates as stated in the Schedule section.
B. Vendor Information
1. Describe the Vendor’s business and background
2. Number of years in the business
3. Details about ownership
4. An overview of services offered and qualifications
5. Size of the firm
6. Location(s) of offices. If multiple, please identify which will be the primary for our
account.
7. Primary contact information for the company including contact name(s) and title(s),
mailing address(s), phone number(s), and email address(s). Complete Section V,
Vendor Statement.
RFP 9406 Automated Customer Consent Tracking Page 8 of 28
C. Scope of Proposal
1. Provide a detailed narrative of the services proposed if awarded the contract per the
scope above. The narrative should include any options that may be beneficial for the
City to consider.
2. Describe how the project would be managed and who would have primary
responsibility for its timely and professional completion. Include a description
regarding how the analysis will be performed for the various identified areas
identified, the methods and assumptions used, and the limitations of the analysis.
3. Describe the methods and timeline of communication your firm will use with the
City’s Project Manager and other parties.
4. Describe your firm’s customer service and technical support standards.
5. Include a description of the software and other analysis tools to be used.
6. Include support and maintenance plan details.
7. Describe your firm’s data integrity and security standards, particularly around
transferring between third-parties.
8. Give examples of third-party partnership(s) in the state of Colorado your firm has
experience with, similar to what is described in this Scope of Work.
9. Describe the methods and timeframe for storing data. Describe whether your firm
destroys data, and if so, how frequently.
10. Describe the format that data will be delivered. Describe if the data will be formatted
prior to delivery.
11. Describe single-sign on capabilities.
12. Identify what portion of work, if any, may be subcontracted.
D. Firm Capability
Provide relevant information regarding previous experience related to this or similar
Projects, to include the following:
1. Provide an Organization Chart/Proposed Project Team: An organization chart
containing the names of all key personnel and sub consultants with titles and their
specific task assignment for this Agreement shall be provided in this section.
2. A list of qualifications for your firm and qualifications and experience of the specific
staff members proposed to perform the consulting services described above.
3. Provide an example of a similar project in the last 5 years that have involved the staff
proposed to work on this project. Include the owner’s name, title of project, beginning
price, ending price, contact name, email and phone number, sub-consultants on the
team and a brief description of the work and any change orders.
4. Provide examples of at least two projects where you’ve worked with your sub-
consultants. List the sub-consultant firm(s) for this Agreement, their area(s) of
expertise, and include all other applicable information herein requested for each sub-
consultant. Identify what portion of work, if any, may be sub-contracted.
5. References (current contact name, current telephone number and email address)
from at least three similar projects with similar requirements that have been
RFP 9406 Automated Customer Consent Tracking Page 9 of 28
completed within the past five (5) years and that have involved the staff proposed to
work on this project. Provide a description of the work performed. The Vendor
authorizes the City to verify any and all information contained in the Vendor’s
submittal from references contained herein and hereby releases all those concerned
providing information as a reference from any liability in connection with any
information they give.
E. Assigned Personnel
1. List of Project Personnel: This list should include the identification of the contact
person with primary responsibility for this Agreement, the personnel proposed for this
Agreement, and any supervisory personnel, including partners and/or sub
consultants, and their individual areas of responsibility.
2. A resume for each professional and technical person assigned to the Agreement,
including partners and/or sub consultants, shall be submitted. The résumés shall
include at least three individual references from previous assignments. Please limit
resumes to one page.
3. Some functions of this project may require the use of sub-consultants. If you intend
to utilize sub-consultants you must list each and provide resumes for their key
personnel.
4. Describe the availability of project personnel to participate in this project in the
context of the firm’s other commitments.
5. Provide a list of similar projects completed in the last five (5) years by the key
members of the proposed team.
F. Availability
1. Can the work be completed in the necessary timeframe, with target start and
completion dates met? If the proposed schedule is not feasible, please propose a
realistic schedule.
2. Are other qualified personnel available to assist in meeting the project schedule if
required?
3. Is the project team available to attend meetings as required to complete the Scope of
Work?
4. Provide an outline of the schedule for completing tasks.
5. Describe the methods and timeline of communication your firm will use with the
City’s Project Manager and other parties.
G. Sustainability/TBL Methodology
In concise terms (no more than two pages), please describe how your organization strives
to be sustainable. Address how your firm incorporates Triple Bottom Line (TBL) into the
workplace. See Section IV: Review and Assessment for additional information.
If possible, please highlight areas of opportunity in the project where sustainability could
be applied and/or improved.
RFP 9406 Automated Customer Consent Tracking Page 10 of 28
H. Cost and Work Hours
In your response to this proposal, please provide the following:
1. Detailed cost proposals for implementation, recurring, and variable costs for
proposed program administration in the pricing table located in the solicitation
posting on www.bidnetdirect.com.
Please include any specific assumptions for costs. Include any applicable costs for
support & maintenance for 5 years.
I. SaaS Cyber Vendor Questionnaire
Provide responses to the questions in Exhibit A, SaaS Cyber Vendor Questionnaire,
consisting of two (2) pages.
J. Additional Information
Provide any information that distinguishes Vendor from its competition and any additional
information applicable to this RFP that might be valuable in assessing Vendor’s proposal.
Explain any concerns Vendor may have in maintaining objectivity in recommending the
best solution. All potential conflicts of interest must be disclosed.
Exceptions to the Scope of Services and City Agreement (a sample of which is
attached in Section VI) shall be documented.
IV. REVIEW AND ASSESSMENT CRITERIA
A. Proposal and Interview Criteria
Vendors will be evaluated on the following criteria. These criteria will be the basis for
review and assessment of the written proposals and optional interview session. At the
discretion of the City, interviews of the top-rated Vendors may be conducted.
The rating scale shall be from 1 to 5, with 1 being a poor rating, 3 being an average rating,
and 5 being an outstanding rating.
WEIGHTING
FACTOR QUALIFICATION STANDARD
2.0 Scope of Proposal
Does the proposal address all elements of the
RFP? Does the proposal show an
understanding of the project objectives,
methodology to be used and results/outcomes
required by the project? Are there any
exceptions to the specifications, Scope of Work,
or agreement?
2.0 Firm Capability
Does the firm have the resources, financial
strength, capacity and support capabilities
required to successfully complete the project on-
time and in-budget? Has the firm successfully
completed previous projects of this type and
scope?
RFP 9406 Automated Customer Consent Tracking Page 11 of 28
2.0 Assigned Personnel
Do the persons who will be working on the
project have the necessary skills and
qualifications? Are sufficient people of the
requisite skills and qualifications assigned to the
project?
1.0 Availability
Can the work be completed in the necessary
time? Can the target start and completion dates
be met? Are other qualified personnel available
to assist in meeting the project schedule if
required? Is the project team available to attend
meetings as required by the Scope of Work?
1.0 Sustainability/TBL
Methodology
Does the firm demonstrate a commitment to
Sustainability and incorporate Triple Bottom Line
methodology in both their Scope of Work for the
project, and their day-to-day business operating
processes and procedures?
2.0 Cost & Work Hours
Does the proposal included detailed cost break-
down for each cost element as applicable and
are the line-item costs competitive? Do the
proposed cost and work hours compare
favorably with the Project Manager's estimate?
Are the work hours presented reasonable for the
effort required by each project task or phase?
Definitions
Sustainable Purchasing is a process for selecting products or services that have a lesser
or reduced negative effect on human health and the environment when compared with
competing products or services that serve the same purpose. This process is also known
as “Environmentally Preferable Purchasing” (EPP), or “Green Purchasing”.
The Triple Bottom Line (TBL) is an accounting framework that incorporates three
dimensions of performance: economic, or financial; environmental, and social. The
generally accepted definition for TBL is that it “captures the essence of sustainability by
measuring the impact of an organization’s activities on the world…including both its
profitability and shareholders values and its social, human, and environmental capital.”
B. Reference Evaluation Criteria
Prior to award, the Project Manager will check references using the following criteria.
Negative responses from references may impact the award determination.
CRITERIA STANDARD QUESTIONS
Overall Performance Would you hire this Vendor again? Did they show
the skills required by this project?
Timetable
Was the original Scope of Work completed within the
specified time? Were interim deadlines met in a
timely manner?
RFP 9406 Automated Customer Consent Tracking Page 12 of 28
Completeness
Was the Vendor responsive to client needs; did the
Vendor anticipate problems? Were problems solved
quickly and effectively?
Budget Was the original Scope of Work completed within the
project budget?
Job Knowledge
If a study, did it meet the Scope of Work?
If Vendor administered a construction contract, was
the project functional upon completion and did it
operate properly? Were problems corrected quickly
and effectively?
RFP 9406 Automated Customer Consent Tracking Page 13 of 28
V. VENDOR STATEMENT
Vendor hereby acknowledges receipt of the City of Fort Collins Request for Proposal and
acknowledges that it has read and agrees to be fully bound by all of the terms, conditions and
other provisions set forth in the RFP. Additionally, Vendor hereby makes the following
representations to City:
a. All of the statements and representations made in this proposal are true to the best of the
Vendor’s knowledge and belief.
b. Vendor commits that it is able to meet the terms provided in this proposal.
c. This proposal is a firm and binding offer, for a period of 90 days from the date hereof.
d. Vendor further agrees that the method of award is acceptable.
e. Vendor also agrees to complete the proposed Agreement with the City of Fort Collins
within 30 days of notice of award. If contract is not completed and signed within 30 days,
City reserves the right to cancel and award to the next highest rated firm.
f. Vendor acknowledge receipt of addenda.
Legal Firm Name:
Physical Address:
Remit to Address:
Phone:
Name of Authorized Agent of Firm:
Signature of Authorized Agent:
Primary Contact for Project:
Title: Email Address:
Phone: Cell Phone:
NOTE: VENDOR STATEMENT IS TO BE SIGNED & RETURNED WITH YOUR PROPOSAL.
Professional Services Agreement
Page 14 of 28
VI. SAMPLE AGREEMENT (FOR REFERENCE ONLY – DO NOT SIGN )
PROFESSIONAL SERVICES AGREEMENT
THIS AGREEMENT made and entered into the day and year set forth below, by and
between THE CITY OF FORT COLLINS, COLORADO, a Municipal Corporation, hereinafter
referred to as the "City" and , hereinafter referred to as the "Professional".
WITNESSETH:
In consideration of the mutual covenants and obligations herein expressed, it is agreed by
and between the parties hereto as follows:
1. Scope of Services. The Professional agrees to provide services in accordance with the
scope of services attached hereto as Exhibit A, consisting of ( ) page(s), and
incorporated herein by this reference. Irrespective of references in Exhibit A to certain
named third parties, the Professional shall be solely responsible for performance of all duties
hereunder.
2. The Work Schedule. [Optional] The services to be performed pursuant to this Agreement
shall be performed in accordance with the Work Schedule attached hereto as Exhibit B,
consisting of ( ) page(s), and incorporated herein by this reference.
3. Contract Period. This Agreement shall commence , 20 , and shall continue in
full force and effect until , 20 , unless sooner terminated as herein provided. In
addition, at the option of the City, the Agreement may be extended for additional one year
periods not to exceed four (4) additional one year periods. Renewals and pricing changes
shall be negotiated by and agreed to by both parties. Written notice of renewal shall be
provided to the Professional and mailed no later than thirty (30) days prior to contract end.
4. Early Termination by City. Notwithstanding the time periods contained herein, the City may
terminate this Agreement at any time without cause by providing written notice of termination
to the Professional. Such notice shall be delivered at least fifteen (15) days prior to the
termination date contained in said notice unless otherwise agreed in writing by the parties.
All notices provided under this Agreement shall be effective when mailed, postage prepaid
and sent to the following addresses:
Professional: City: Copy to:
Attn:
City of Fort Collins
Attn:
PO Box 580
Fort Collins, CO 80522
City of Fort Collins
Attn: Purchasing Dept.
PO Box 580
Fort Collins, CO 80522
In the event of any such early termination by the City, the Professional shall be paid for
services rendered prior to the date of termination, subject only to the satisfactory
Professional Services Agreement
Page 15 of 28
performance of the Professional's obligations under this Agreement. Such payment shall be
the Professional's sole right and remedy for such termination.
5. Design, Project Indemnity and Insurance Responsibility. The Professional shall be
responsible for the professional quality, technical accuracy, timely completion and the
coordination of all services rendered by the Professional, including but not limited to designs,
plans, reports, specifications, and drawings and shall, without additional compensation,
promptly remedy and correct any errors, omissions, or other deficiencies. The Professional
shall indemnify, save and hold harmless the City, its officers and employees in accordance
with Colorado law, from all damages whatsoever claimed by third parties against the City;
and for the City's costs and reasonable attorney’s fees, arising directly or indirectly out of
the Professional's negligent performance of any of the services furnished under this
Agreement. The Professional shall maintain insurance in accordance with Exhibit ,
consisting of one (1) page, attached hereto and incorporated herein.
6. Compensation. [Use this paragraph or Option 1 below.] In consideration of the services
to be performed pursuant to this Agreement, the City agrees to pay the Professional a fixed
fee in the amount of ($ ) plus reimbursable direct costs. All such fees and costs
shall not exceed ($ ) in accordance with Exhibit , consisting of
( ) page(s), attached hereto and incorporated herein. Monthly partial payments based
upon the Professional's billings and itemized statements are permissible. The amounts of
all such partial payments shall be based upon the Professional's City-verified progress in
completing the services to be performed pursuant hereto and upon the City's approval of
the Professional's actual reimbursable expenses. Final payment shall be made following
acceptance of the Work by the City. Upon final payment, all designs, plans, reports,
specifications, drawings, and other services rendered by the Professional shall become the
sole property of the City.
7. Compensation. [Option 1] In consideration of the services to be performed pursuant to this
Agreement, the City agrees to pay the Professional on a time and reimbursable direct cost
basis in accordance with Exhibit , consisting of ( ) page(s), attached
hereto and incorporated herein, with maximum compensation (for both Professional's time
and reimbursable direct costs) not to exceed ($ ). Monthly partial payments
based upon the Professional's billings and itemized statements of reimbursable direct costs
are permissible. The amounts of all such partial payments shall be based upon the
Professional's City-verified progress in completing the services to be performed pursuant
hereto and upon the City's approval of the Professional's reimbursable direct costs. Final
payment shall be made following acceptance of the Work by the City. Upon final payment,
all designs, plans, reports, specifications, drawings and other services rendered by the
Professional shall become the sole property of the City.
8. License. Upon execution of this Agreement, the Professional grants to the City an
irrevocable license to use any and all sketches, drawings, specifications, designs,
blueprints, data files, calculations, studies, analysis, renderings, models and other Work
Order deliverables (the “Instruments of Service”), in any form whatsoever and in any
Professional Services Agreement
Page 16 of 28
medium expressed, for purposes of constructing, using, maintaining, altering and adding to
the project, provided that the City substantially performs its obligations under the
Agreement. The license granted hereunder permits the City and third parties reasonably
authorized by the City to reproduce applicable portions of the Instruments of Service for use
in performing services or construction for the project. In addition, the license granted
hereunder shall permit the City and third parties reasonably authorized by the City to
reproduce and utilize the Instruments of Service for similar projects, provided however, in
such event the Professional shall not be held responsible for the design to the extent the
City deviates from the Instruments of Service. This license shall survive termination of the
Agreement by default or otherwise.
9. City Representative. The City will designate, prior to commencement of work, its project
representative who shall make, within the scope of his or her authority, all necessary and
proper decisions with reference to the project. All requests for contract interpretations,
change orders, and other clarification or instruction shall be directed to the City
Representative.
10. Project Drawings. Upon request and before final payment, the Professional shall provide
the City with reproducible drawings of the project containing accurate information on the
project as constructed. Drawings shall be of archival quality, prepared on stable mylar base
material using a non-fading process to provide for long storage and high quality
reproduction. "CD" disc of the as-built drawings shall also be submitted to the owner in and
AutoCAD version no older then the established City standard. The Professional
acknowledges the City is a governmental entity subject to the Colorado Open Records Act,
C.R.S. §§ 24-72-200.1, et seq. (the “CORA”), and documents in the City’s possession may
be considered public records subject to disclosure under the CORA.
11. Monthly Report. Commencing thirty (30) days after the date of execution of this Agreement
and every thirty (30) days thereafter, Professional is required to provide the City
Representative with a written report of the status of the work with respect to the Scope of
Services, Work Schedule, and other material information. Failure to provide any required
monthly report may, at the option of the City, suspend the processing of any partial payment
request.
12. Independent Contractor. The services to be performed by Professional are those of an
independent contractor and not of an employee of the City of Fort Collins. The City shall
not be responsible for withholding any portion of Professional's compensation hereunder for
the payment of FICA, Workers' Compensation, other taxes or benefits or for any other
purpose.
13. Subcontractors. The Professional may not subcontract any of the Work set forth in the
Exhibit A, Statement of Work without the prior written consent of the city, which shall not be
unreasonably withheld. If any of the Work is subcontracted hereunder (with the consent of
the City), then the following provisions shall apply: (a) the subcontractor must be a reputable,
qualified firm with an established record of successful performance in its respective trade
Professional Services Agreement
Page 17 of 28
performing identical or substantially similar work, (b) the subcontractor will be required to
comply with all applicable terms of this Agreement, (c) the subcontract will not create any
contractual relationship between any such subcontractor and the City, nor will it obligate the
City to pay or see to the payment of any subcontractor, and (d) the Work of the subcontractor
will be subject to inspection by the City to the same extent as the Work of the Professional.
The Professional shall require all subcontractors performing Work hereunder to maintain
insurance coverage naming the City as an additional insured under this Agreement of the
type and with the limits specified within Exhibit “C”, consisting of one (1) page attached
hereto and incorporated herein by this reference. The Professional shall maintain a copy of
each subcontract’s certificate evidencing the required insurance. Upon request, the
Professional shall promptly provide the City with a copy of such certificate(s).
14. Personal Services. It is understood that the City enters into the Agreement based on the
special abilities of the Professional and that this Agreement shall be considered as an
agreement for personal services. Accordingly, the Professional shall neither assign any
responsibilities nor delegate any duties arising under the Agreement without the prior written
consent of the City.
15. Acceptance Not Waiver. The City's approval of drawings, designs, plans, specifications,
reports, and incidental work or materials furnished hereunder shall not in any way relieve
the Professional of responsibility for the quality or technical accuracy of the Work. The City's
approval or acceptance of, or payment for, any of the services shall not be construed to
operate as a waiver of any rights or benefits provided to the City under this Agreement.
16. Default. Each and every term and condition hereof shall be deemed to be a material element
of this Agreement. In the event either party should fail or refuse to perform according to the
terms of this agreement, such party may be declared in default.
17. Remedies. In the event a party has been declared in default, such defaulting party shall be
allowed a period of ten (10) days within which to cure said default. In the event the default
remains uncorrected, the party declaring default may elect to (a) terminate the Agreement
and seek damages; (b) treat the Agreement as continuing and require specific performance;
or (c) avail himself of any other remedy at law or equity. If the non-defaulting party
commences legal or equitable actions against the defaulting party, the defaulting party shall
be liable to the non-defaulting party for the non-defaulting party's reasonable attorney fees
and costs incurred because of the default.
18. Binding Effect. This writing, together with the exhibits hereto, constitutes the entire
agreement between the parties and shall be binding upon said parties, their officers,
employees, agents and assigns and shall inure to the benefit of the respective survivors,
heirs, personal representatives, successors and assigns of said parties.
19. Law/Severability. The laws of the State of Colorado shall govern the construction,
interpretation, execution and enforcement of this Agreement. In the event any provision of
Professional Services Agreement
Page 18 of 28
this Agreement shall be held invalid or unenforceable by any court of competent jurisdiction,
such holding shall not invalidate or render unenforceable any other provision of this
Agreement.
20. Prohibition Against Employing Illegal Aliens. Pursuant to Section 8-17.5-101, C.R.S., et.
seq., the Professional represents and agrees that:
a. As of the date of this Agreement:
1. The Professional does not knowingly employ or contract with an illegal alien who will
perform work under this Agreement; and
2. The Professional will participate in either the e-Verify program created in Public Law
208, 104th Congress, as amended, and expanded in Public Law 156, 108th
Congress, as amended, administered by the United States Department of Homeland
Security (the “e-Verify Program”) or the Department Program (the “Department
Program”), an employment verification program established pursuant to Section 8-
17.5-102(5)(c) C.R.S. in order to confirm the employment eligibility of all newly hired
employees to perform work under this Agreement.
b. The Professional shall not knowingly employ or contract with an illegal alien to perform
work under this Agreement or knowingly enter into a contract with a subcontractor that
knowingly employs or contracts with an illegal alien to perform work under this
Agreement.
c. The Professional is prohibited from using the e-Verify Program or Department Program
procedures to undertake pre-employment screening of job applicants while this
Agreement is being performed.
d. If the Professional obtains actual knowledge that a subcontractor performing work
under this Agreement knowingly employs or contracts with an illegal alien, the
Professional shall:
1. Notify such subcontractor and the City within three days that the Professional has
actual knowledge that the subcontractor is employing or contracting with an illegal
alien; and
2. Terminate the subcontract with the subcontractor if within three days of receiving the
notice required pursuant to this section the subcontractor does not cease employing
or contracting with the illegal alien; except that the Professional shall not terminate
the contract with the subcontractor if during such three days the subcontractor
provides information to establish that the subcontractor has not knowingly employed
or contracted with an illegal alien.
e. The Professional shall comply with any reasonable request by the Colorado
Department of Labor and Employment (the “Department”) made in the course of an
investigation that the Department undertakes or is undertaking pursuant to the
authority established in Subsection 8-17.5-102 (5), C.R.S.
Professional Services Agreement
Page 19 of 28
f. If the Professional violates any provision of this Agreement pertaining to the duties
imposed by Subsection 8-17.5-102, C.R.S. the City may terminate this Agreement. If
this Agreement is so terminated, the Professional shall be liable for actual and
consequential damages to the City arising out of the Professional’s violation of
Subsection 8-17.5-102, C.R.S.
g. The City will notify the Office of the Secretary of State if the Professional violates this
provision of this Agreement and the City terminates the Agreement for such breach.
21. Special Provisions. Special provisions or conditions relating to the services to be performed
pursuant to this Agreement are set forth in Exhibit - Confidentiality, consisting of three
(3) pagea, attached hereto and incorporated herein by this reference.
Professional Services Agreement
Page 20 of 28
THE CITY OF FORT COLLINS, COLORADO
By:
Gerry Paul
Purchasing Director
DATE:
ATTEST:
APPROVED AS TO FORM:
PROFESSIONAL'S NAME
By:
Printed:
Title:
CORPORATE PRESIDENT OR VICE PRESIDENT
Date:
Professional Services Agreement
Page 21 of 28
EXHIBIT A
SCOPE OF SERVICES
Official Purchasing Document
Last updated 10/2017
Professional Services Agreement
Page 22 of 28
EXHIBIT
(BID SCHEDULE/COMPENSATION)
Official Purchasing Document
Last updated 10/2017
Professional Services Agreement
Page 23 of 28
EXHIBIT
INSURANCE REQUIREMENTS
1. The Professional will provide, from insurance companies acceptable to the City, the
insurance coverage designated hereinafter and pay all costs. Before commencing Work
under this bid, the Professional shall furnish the City with certificates of insurance
showing the type, amount, class of operations covered, effective dates and date of
expiration of policies, and containing substantially the following statement:
“The insurance evidenced by this Certificate will not reduce coverage or limits and
will not be cancelled, except after thirty (30) days written notice has been received
by the City of Fort Collins.”
In case of the breach of any provision of the Insurance Requirements, the City, at its
option, may take out and maintain, at the expense of the Professional, such insurance
as the City may deem proper and may deduct the cost of such insurance from any
monies which may be due or become due the Professional under this Agreement. The
City, its officers, agents and employees shall be named as additional insureds on the
Professional 's general liability and automobile liability insurance policies for any claims
arising out of Work performed under this Agreement.
2. Insurance coverages shall be as follows:
A. Workers' Compensation & Employer's Liability. The Professional shall maintain
during the life of this Agreement for all of the Professional's employees engaged in
Work performed under this agreement:
1. Workers' Compensation insurance with statutory limits as required by
Colorado law.
2. Employer's Liability insurance with limits of $100,000 per accident,
$500,000 disease aggregate, and $100,000 disease each employee.
B. Commercial General & Vehicle Liability. The Professional shall maintain during the
life of this Agreement such commercial general liability and automobile liability
insurance as will provide coverage for damage claims of personal injury, including
accidental death, as well as for claims for property damage, which may arise
directly or indirectly from the performance of Work under this Agreement.
Coverage for property damage shall be on a "broad form" basis. The amount of
insurance for each coverage, Commercial General and Vehicle, shall not be less
than $1,000,000 combined single limits for bodily injury and property damage.
In the event any Work is performed by a subcontractor, the Professional shall be
responsible for any liability directly or indirectly arising out of the Work performed
under this Agreement by a subcontractor, which liability is not covered by the
subcontractor's insurance.
C. Errors & Omissions. The Professional shall maintain errors and omissions
insurance in the amount of $1,000,000.
Official Purchasing Document
Last updated 10/2017
Professional Services Agreement
Page 24 of 28
EXHIBIT
CONFIDENTIALITY
IN CONNECTION WITH THE SERVICES to be provided by Professional under this
Agreement, the parties agree to comply with reasonable policies and procedures with regard to
the exchange and handling of confidential information and other sensitive materials between the
parties, as set forth below.
1. Definitions.
For purposes of this Agreement, the party who owns the confidential information and is
disclosing same shall be referenced as the “Disclosing Party.” The party receiving the
Disclosing Party’s confidential information shall be referenced as the “Receiving Party.”
2. Confidential Information.
Confidential Information controlled by this Agreement refers to information which is not
public and/or is proprietary and includes by way of example, but without limitation, City
customer information, utility data, service billing records, customer equipment information,
location information, network security system, business plans, formulae, processes,
intellectual property, trade secrets, designs, photographs, plans, drawings, schematics,
methods, specifications, samples, reports, mechanical and electronic design drawings,
customer lists, financial information, studies, findings, inventions, and ideas.
To the extent practical, Confidential Information shall be marked “Confidential” or
“Proprietary.” Nevertheless, Professional shall treat as Confidential Information all customer
identifiable information in any form, whether or not bearing a mark of confidentiality or
otherwise requested by the City, including but not limited to account, address, billing,
consumption, contact and other customer data. In the case of disclosure in non-
documentary form of non-customer identifiable information, made orally or by visual
inspection, the Disclosing Party shall have the right, or, if requested by the Receiving Party,
the obligation to confirm in writing the fact and general nature of each disclosure within a
reasonable time after it is made in order that it is treated as Confidential Information. Any
information disclosed to the other party prior to the execution of this Agreement and related
to the services for which Professional has been engaged shall be considered in the same
manner and be subject to the same treatment as the information disclosed after the
execution of this Agreement with regard to protecting it as Confidential Information.
3. Use of Confidential Information.
Receiving Party hereby agrees that it shall use the Confidential Information solely for the
purpose of performing its obligations under this Agreement and not in any way detrimental
to Disclosing Party. Receiving Party agrees to use the same degree of care Receiving Party
uses with respect to its own proprietary or confidential information, which in any event shall
result in a reasonable standard of care to prevent unauthorized use or disclosure of the
Confidential Information. Except as otherwise provided herein, Receiving Party shall keep
confidential and not disclose the Confidential Information. The City and Professional shall
cause each of their directors, officers, employees, agents, representatives, and
subcontractors to become familiar with, and abide by, the terms of this section, which shall
survive this Agreement as an on-going obligation of the Parties.
Professional shall not use such information to obtain any economic or other benefit for itself,
or any third party, other than in the performance of obligations under this Agreement.
Official Purchasing Document
Last updated 10/2017
Professional Services Agreement
Page 25 of 28
4. Exclusions from Definition.
The term “Confidential Information” as used herein does not include any data or information
which is already known to the Receiving Party or which before being divulged by the
Disclosing Party (1) was generally known to the public through no wrongful act of the
Receiving Party; (2) has been rightfully received by the Receiving Party from a third party
without restriction on disclosure and without, to the knowledge of the Receiving Party, a
breach of an obligation of confidentiality; (3) has been approved for release by a written
authorization by the other party hereto; or (4) has been disclosed pursuant to a requirement
of a governmental agency or by operation of law.
5. Required Disclosure.
If the Receiving Party is required (by interrogatories, requests for information or documents,
subpoena, civil investigative demand or similar process, or by federal, state, or local law,
including without limitation, the Colorado Open Records Act) to disclose any Confidential
Information, the Parties agree the Receiving Party will provide the Disclosing Party with
prompt notice of such request, so the Disclosing Party may seek an appropriate protective
order or waive the Receiving Party’s compliance with this Agreement.
The Receiving Party shall furnish a copy of this Agreement with any disclosure.
6. Notwithstanding paragraph 5, Professional shall not disclose Confidential Information to any
person, directly or indirectly, nor use it in any way, except as required or authorized in
writing by the City.
7. Red Flags Rules.
Professional must implement reasonable policies and procedures to detect, prevent and
mitigate the risk of identity theft in compliance with the Identity Theft Red Flags Rules found
at 16 Code of Federal Regulations part 681. Further, Professional must take appropriate
steps to mitigate identity theft if it occurs with one or more of the City’s covered accounts
and must as expeditiously as possible notify the City in writing of significant breeches of
security or Red Flags to the City.
8. Data Protection and Data Security.
In addition to the requirements of paragraph 7, Professional shall have in place information
security safeguards designed to conform to or exceed industry best practices regarding the
protection of the confidentiality, integrity and availability of utility and customer information
and shall have written agreements requiring any subcontractor to meet those standards.
These information security safeguards (the “Information Security Program”) shall be
materially consistent with, or more stringent than, the safeguards described in this Exhibit.
a) Professional’s information security safeguards shall address the following elements:
• Data Storage, Backups and Disposal
• Logical Access Control (e.g., Role-Based)
• Information Classification and Handling
• Secure Data Transfer (SFTP and Data Transfer Specification)
• Secure Web Communications
• Network and Security Monitoring
• Application Development Security
Official Purchasing Document
Last updated 10/2017
Professional Services Agreement
Page 26 of 28
• Application Security Controls and Procedures (User Authentication, Security
Controls, and Security Procedures, Policies and Logging)
• Incident Response
• Vulnerability Assessments
• Hosted Services
• Personnel Security
b) Subcontractors. Professional may use subcontractors, though such activity shall not
release or absolve Professional from the obligation to satisfy all conditions of this
Agreement, including the data security measures described in this Exhibit, and to require
a substantially similar level of data security, appropriate to the types of services provided
and Customer Data received, for any subcontractor Professional may use. Accordingly,
any release of data, confidential information, or failure to protect information under this
Agreement by a subcontractor or affiliated party shall be attributed to Professional and
may be considered to be a material breach of this Agreement.
9. Confidential Information is not to be stored on any local workstation, laptop, or media such
as CD/DVD, USB drives, external hard drives or other similar portable devices unless the
Professional can ensure security for the Confidential Information so stored. Work stations or
laptops to be used in the Work will be required to have personal firewalls on each, as well as
have current, active anti-virus definitions.
10. The Agreement not to disclose Confidential Information as set forth in this Exhibit shall apply
during the term of the Work and at any time thereafter unless specifically authorized by the
City in writing.
11. If Professional breaches this Agreement, in the City’s sole discretion, the City may
immediately terminate this Agreement and withdraw Professional’s right to access
Confidential Information.
12. Notwithstanding any other provision of this Agreement, all material, i.e., various physical
forms of media in which Confidential Information is contained, including but not limited to
writings, drawings, tapes, diskettes, prototypes or products, shall remain the sole property of
the Disclosing Party and, upon request, shall be promptly returned, together with all copies
thereof to the Disclosing Party. Upon such return of physical records, all digital and
electronic data shall also be deleted in a non-restorable way by which it is no longer
available to the Receiving Party. Written verification of the deletion (including date of
deletion) is to be provided to the Disclosing Party within ten (10) days after completion of
engagement, whether it be via termination, completion or otherwise.
13. Professional acknowledges that the City may, based upon the representations made in this
Agreement, disclose security information that is critical to the continued success of the City’s
business. Accordingly, Professional agrees that the City does not have an adequate remedy
at law for breach of this Agreement and therefore, the City shall be entitled, as a non-
exclusive remedy, and in addition to an action for damages, to seek and obtain an injunction
or decree of specific performance or any other remedy, from a court of competent
jurisdiction to enjoin or remedy any violation of this Agreement.
Official Purchasing Document
Last updated 10/2017
Professional Services Agreement
Page 27 of 28
EXHIBIT A
SAAS CYBER VENDOR QUESITONNAIRE
1. Data Ownership: The City of Fort Collins will own all right, title and interest in its data
that is related to the services provided. All data obtained by the vendor in the
performance of this services shall become and remain the property of the City. The
vendor will not share or distribute any City data to any other entity without the express
written consent of the City. Can you comply with this?
2. Data Protection: Describe how you safeguard the confidentiality, integrity and
availability of City information, including encryption of personal data in transit and at rest,
and access control. Do you have a privacy and security policy, and does the policy apply
to customers’ private data including personal identifiable information?
3. Data destruction: What procedures and safeguards does the vendor have in place for
sanitizing and disposing of City data according to prescribed retention schedules or
following the conclusion of a project or termination of a contract to render it
unrecoverable and prevent accidental and/or unauthorized access to City data?
4. Data Location: Are the data centers where City data may be stored or processed
located exclusively in the United States? Do you allow your personnel or contractors to
store City data on portable devices? Do your personnel and contractors access City data
remotely?
5. Security Incidents or Data Breaches: Describe your data breach and incident
response communication plans. Has the company experienced any security breaches? If
yes, explain.
6. Breach Responsibilities: In addition to data breach communication, what additional
responsibilities do you have to your customers in the event of a data breach involving
private data that is in your control, or in the control of your contractors/subsidiaries, at
the time of breach? Do you have cybersecurity insurance? If yes, provide an overview of
the coverage.
7. Background Checks: Do you conduct criminal background checks on all staff, including
subcontractors? Do you employ people convicted of any crime of dishonesty?
8. Access to Security Logs and Reports: The vendor shall provide reports to the City in
a format as specified in the SLA agreed to by both the vendor and the City. Reports shall
include latency statistics, user access, user access IP address, user access history and
security logs for all City files related to this contract. Can you comply with this?
9. Risk Assessments and Audits: Do you conduct periodic risk assessments to identify
cybersecurity threats, vulnerabilities, and potential business consequences? Do you
have regular independent assessments of your cybersecurity processes? Do you
perform independent audits of your data center? How often? What level of audit is
performed (e.g., SOC2)? Would you be willing to share redacted versions of your most
recent risk assessment and audit report with the City?
10. Change Control and Advance Notice: How do you communicate upgrades (e.g., major
upgrades, minor upgrades, system changes) that may impact service availability and
performance to your customers?
Official Purchasing Document
Last updated 10/2017
Professional Services Agreement
Page 28 of 28
11. Upgrades: Are technology systems (e.g., servers, network devices, operating systems,
applications, malware definitions) regularly updated/patched? Do you have any systems
in production that are past end of life or that can no longer be patched?
12. Non-disclosure and Separation of Duties: Describe how you enforce separation of job
duties and limit staff knowledge of City data to that which is necessary to perform job
duties.
13. Import and Export of Data: Describe the data import and export processes from the
customer’s perspective.
14. Subcontractor Disclosure: Identify all your strategic business partners related to
services provided under this arrangement, including but not limited to all subcontractors
or other entities or individuals who may be a party to a joint venture or similar agreement
with the you, and who shall be involved in any application development and/or
operations.
15. Right to Remove Individuals: The City shall have the right at any time to require that
the vendor remove from interaction with City any vendor representative who the City
believes is detrimental to its working relationship with the vendor. Can you comply with
this?
16. Encryption of Data at Rest: Can you ensure hard drive encryption consistent with
validated cryptography standards as referenced in FIPS 140-2, Security Requirements
for Cryptographic Modules for all personal data?
17. Internet-Facing Security: We may use BitSight (like a credit report for cyber security) to
assess your internet-facing security. Do you subscribe to BitSight or a similar service,
and if so are you willing to provide a sanitized report?
18. Service Interruption: In the event of an interruption of your service, what is your
process for notifying customer operations of the circumstances of the interruption or
outage and the expected recovery time?
19. Backup and Recovery: What is your backup & recovery SLA? What are the actual
results/metrics vs. the SLA for the last 12 months? Is your backup data encrypted and, if
so, to what standard?
20. Authentication: Do you have an internal password policy? Do you have complexity or
length requirements for passwords? Do employees/contractors have ability to remotely
connect to your production systems? (i.e. VPN. Is multi-factor authentication available?
Do you require MFA for administration of your service (local or remote)? Do you support
SSO/SAML ADFS for customer access?
21. Cyber Insurance: Does your firm carry cyber insurance? If so, what are your insurance
levels?