Town CrierWest Orange, New Jersey
← Back to search

Supporting Documentation · Jan 6, 2015

11-15 Exhibits to Resolution Awarding Contract for 911 System Maintenance and Repair.pdf

Preserved file SHA-256c64ab1e2bb206146c4660bc566c5f1e4fca8ca686497d1305ceee0ffc4e0b340

Indexed text

Page 55

http://www.state.nj.us/it/ps/it_architecture.pdf. B. Current standards set forth and maintained by the National Institute of Standards and Technology (NIST), including: http://csrc.nist.gov/publications/PubsSPs.html http://csrc.nist.gov/publications/nistpubs/800-113/SP800-113.pdf http://csrc.nist.gov/publications/nistpubs/800-66-Rev1/SP-800-66-Revision1.pdf http://csrc.nist.gov/publications/drafts/800-125/Draft-SP800-125.pdf http://csrc.nist.gov/publications/nistpubs/800-122/sp800-122.pdf https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml. C. Any generally recognized comparable standard that the contractor then applies to its own network that is approved by the NJ Statewide Office of Information Security. • The contractor shall be subject to the same security and infrastructure review processes that are required by NJOIT and its partner Departments and Agencies. The contractor shall submit relevant documentation and participate in the System Architecture Review (SAR) process. • For “outsourced hosting services”, the contractor must demonstrate the ability to not only secure the physical application infrastructure utilizing the above mentioned security requirements, but also control and secure physical access to the application hosting facilities, the racks supporting network infrastructure and processing server equipment, web, application and database servers. 49

Page 56

• If the contractor is not supplying “dedicated” hardware resources to host State of New Jersey applications and data, the contractor must demonstrate its strategy to maintain application and/or stack isolation using commercially available security devices to maintain security zones, routing isolation and access control to infrastructure devices and access/security logging (AAA) within its infrastructure. • The contractor must supply “cleansed” but detailed network infrastructure diagrams of the application hosting environment for review by NJ OIT Network Infrastructure and Enterprise Security Office. 2. Application Security: The contractor at a minimum shall run application vulnerability assessment scans during development and system testing. Vulnerabilities shall be remediated prior to production release. 1. All systems and applications shall be subject to Vulnerability Assessment scans on a regular basis. 3. Data Security: The contractor at a minimum shall protect and maintain the security of data in accordance with generally accepted industry practices and to the standards and practices required by NJOIT. • Any Personally Identifiable Information must be protected. All data must be classified in accordance with the State’s Asset Classification and Control policy, 08-04-NJOIT (www.nj.gov/it/ps). Additionally, data must be disposed of in accordance with the State’s Information Disposal and Media Sanitation policy, 09-10-NJOIT (www.nj.gov/it/ps). • Data usage, storage, and protection is subject to any applicable regulatory requirements, including those for HIPAA (Health Insurance Portability and Accountability Act), and PII (Personally Identifiable Information), Tax Information Security Guidelines for Federal, State, and Local Agencies (IRS Publication 1075) and the New Jersey State tax confidentiality statute, as amended, N.J.S.A. 54:50-8, Payment Card Industry (PCI) Data Security Standard, State of New Jersey Identity Theft Prevention Act, June 2005, State of New Jersey Drivers’ Privacy Protection Act of 1994, Pub.L.103-322 4. Data Transmission: The contractor shall only transmit or exchange State of New Jersey data with other parties when expressly requested in writing and permitted

Page 56

Act of 1994, Pub.L.103-322 4. Data Transmission: The contractor shall only transmit or exchange State of New Jersey data with other parties when expressly requested in writing and permitted by and in accordance with requirements of the State of New Jersey. The contractor shall only transmit or exchange data with the State of New Jersey or other parties through secure means supported by current technologies. The contractor shall encrypt all data defined as personally identifiable or confidential by the State of New Jersey or applicable law, regulation or standard during any transmission or exchange of that data. 5. Data Storage: All data provided by the State of New Jersey or gathered by the contractor on behalf of the State of New Jersey must be stored, processed, and maintained solely in accordance with a project plan and system topology approved by the State Contract Manager. No State data shall be processed on or transferred to any device or storage medium including portable media, smart devices and/or USB devices, unless that device or storage medium has been approved in advance in writing by the State Project Manager. 50

Page 57

6. Data Scope: All provisions applicable to data include data in any form of transmission or storage, including but not limited to: database files, text files, backup files, log files, XML files, and printed copies of the data. 7. Data Re-Use: All State provided data shall be used expressly and solely for the purposes enumerated in the contract. Data shall not be distributed, repurposed or shared across other applications, environments, or business units of the contractor. No State data of any kind shall be transmitted, exchanged or otherwise passed to other contractors or interested parties except on a case-by-case basis as specifically agreed to in writing by the State Contract Manager. 8. Data Breach: Unauthorized Release Notification: The contractor shall comply with all applicable State and Federal laws that require the notification of individuals in the event of unauthorized release of personally-identifiable information or other event requiring notification. In the event of a breach of any of the contractor’s security obligations or other event requiring notification under applicable law (“Notification Event”), the contractor shall assume responsibility for informing the State Contract Manager and all such individuals in accordance with applicable law and to indemnify, hold harmless and defend the State of New Jersey, its officials, and employees from and against any claims, damages, or other harm related to such Notification Event. 9. End of Contract Data Handling: Upon termination of this Contract the contractor shall erase, destroy, and render unreadable all contractor copies of State data according to the standards enumerated in accordance with the State’s Information Disposal and Media Sanitation policy, 09-10-NJOIT (www.nj.gov/it/ps) and certify in writing that these actions have been complete within thirty (30) days of the termination of this Contract or within seven (7) days of the request of an agent of the State whichever shall come first. 10. Security Audit: The contractor must allow State assigned staff full access to all operations for security inspections and audits which may include reviews of all issues addressed in description of the security approach and

Page 57

low State assigned staff full access to all operations for security inspections and audits which may include reviews of all issues addressed in description of the security approach and willingness to enter into good faith discussions to implement any changes. 5.9.3 SECURITY PLAN The contractor must provide a security plan. The document shall describe the administrative, physical, technical and systems controls to be used by the system and/or services. The contractor's security plan must, at a minimum, provide security measures for the following areas: - Facilities Physical Security - System Security - System Data Security - Administrative and Personnel Security The security plan shall provide for review of the contractor's operations and control system. The contractor shall have the capability to detect and report attempted unauthorized entries into the facility and system. All security requirements for the contractor apply to development, testing, production and backup systems. The contractor shall provide a summary overview of the security document and describe how it has been incorporated into a larger security program for automated data processing. In the plan, the contractor shall highlight security features of the system. 51

Page 58

In addition, the security plan shall identify and define: • Regulations and security requirements – how the contractor will address security requirements such as PCI, HIPAA, FISMA and etc. • System, Administrative and Personnel Security - the security responsibilities of and supervision required for information owned and / or operated by the contractor. Security responsibilities include responsibilities for administration of the infrastructure, implementing or maintaining security and the protection of the confidentiality, integrity, and availability of information systems or processes. • Workforce Security - the control process for hiring and terminating of contractor’s employees, and method used for granting and denying access to the contractor’s network, systems and applications. Identify and define audit controls when employment of the employee terminates. • Role based security access – the products and methods for role based security and access to the contractor’s infrastructure and access to the State’s infrastructure. • Password Management – the appropriate password management controls to meet defined regulation or security requirements. • Logging / Auditing controls – the contractor’s audit control methods and requirements. • Incident Management – the methods for detecting, reporting and responding to an incident, vulnerabilities and threats. • Vulnerability / Security Assessment – the products and methods used for scanning contractor’s infrastructure for vulnerabilities and remediation of the vulnerabilities. Identify and define methods used for initiating and completing security assessments. • Anti-virus / malware controls – the products and methods for anti-virus and malware controls that meet industry standards. It shall include policy statements that require periodic anti-viral software checks of the system to preclude infections and set forth its commitment to periodically upgrade its capability to maintain maximum effectiveness

Page 58

odic anti-viral software checks of the system to preclude infections and set forth its commitment to periodically upgrade its capability to maintain maximum effectiveness against new strains of software viruses. • Firewall – the products and methods for firewall control process and intrusion detection methodology. • Database – the products and methods for safeguarding the database(s). • Server and infrastructure – the products and methods for "hardening" of the hardware’ operating systems. • Transmission - the products and methods on how its system addresses security measures regarding communication transmission, access and message validation. • Data Integrity – the products and methods on the integrity of all stored data and the electronic images, and the security of all files from unauthorized access. The contractor must be able to provide reports on an as-needed basis on the access or change for any file within the system. 5.10 NEWS RELEASES The contractor is not permitted to issue news releases pertaining to any aspect of the services being provided under this contract without the prior written consent of the Director. 5.11 ADVERTISING The contractor shall not use the State’s name, logos, images, or any data or results arising from this contract as a part of any commercial advertising without first obtaining the prior written consent of the Director. 52

Page 59

5.12 LICENSES AND PERMITS The contractor shall obtain and maintain in full force and effect all required licenses, permits, and authorizations necessary to perform this contract. The contractor shall supply the State Contract Manager with evidence of all such licenses, permits and authorizations. This evidence shall be submitted subsequent to the contract award. All costs associated with any such licenses, permits and authorizations must be considered by the bidder in its proposal. 5.13 CLAIMS AND REMEDIES 5.13.1 CLAIMS All claims asserted against the State by the contractor shall be subject to the New Jersey Tort Claims Act, N.J.S.A. 59:1-1, et seq., and/or the New Jersey Contractual Liability Act, N.J.S.A. 59:13-1, et seq. 5.13.2 REMEDIES Nothing in the contract shall be construed to be a waiver by the State of any warranty, expressed or implied, of any remedy at law or equity, except as specifically and expressly stated in a writing executed by the Director. 5.13.3 REMEDIES FOR FAILURE TO COMPLY WITH MATERIAL CONTRACT REQUIREMENTS In the event that the contractor fails to comply with any material contract requirements, the Director may take steps to terminate the contract in accordance with the State of NJ Standard Terms and Conditions, authorize the delivery of contract items by any available means, with the difference between the price paid and the defaulting contractor's price either being deducted from any monies due the defaulting contractor or being an obligation owed the State by the defaulting contractor as provided for in the State administrative code, or take any other action or seek any other remedies available at law or in equity. 5.14 LATE DELIVERY The contractor must immediately advise the State Contract Manager in writing, of any circumstance or event that could result in late completion of any task or subtask called for to be completed on a date certain. If the contractor cannot meet the contract completion date for any task or subtask required to be completed by a date certain, the contractor shall provide written explanation to the contract manager with an estimated delivery and/or completion date for the task or subtask. The Contractor shall assume all responsibility for its subcontractors, authorized dealers and resellers. 5.15 RETAINAGE The amount of retainage is noted on the RFP signatory page accompanying this RFP. The

Page 59

tractor shall assume all responsibility for its subcontractors, authorized dealers and resellers. 5.15 RETAINAGE The amount of retainage is noted on the RFP signatory page accompanying this RFP. The using agency shall retain the stated percentage of each invoice submitted. At the end of each three (3) month period, the using agency shall review the contractor's performance. If performance has been satisfactory, the Using Agency shall release 90% of the retainage for the preceding three (3) month period. Following certification by the State Contract Manager that all services have been satisfactorily performed the balance of the retainage shall be released to the contractor. 53

Page 60

5.16 ADDITIONAL WORK AND/OR SPECIAL PRODUCTS The contractor shall not begin performing any additional work or special projects without first obtaining written approval from both the State Contract Manager and the Director. In the event of additional work and/or special projects, the contractor must present a written proposal to perform the additional work to the State Contract Manager. The proposal should provide justification for the necessity of the additional work. The relationship between the additional work and the base contract work must be clearly established by the contractor in its proposal. The contractor’s written proposal must provide a detailed description of the work to be performed broken down by task and subtask. The proposal should also contain details on the level of effort, including hours, labor categories, etc., necessary to complete the additional work. The written proposal must detail the cost necessary to complete the additional work in a manner consistent with the contract. The written price schedule must be based upon the hourly rates, unit costs or other cost elements submitted by the contractor in the contractor’s original proposal submitted in response to this RFP. Whenever possible, the price schedule should be a firm, fixed price to perform the required work. The firm fixed price should specifically reference and be tied directly to costs submitted by the contractor in its original proposal. A payment schedule, tied to successful completion of tasks and subtasks, must be included. Upon receipt and approval of the contractor’s written proposal, the State Contract Manager shall forward same to the Director for the Director’s written approval. Complete documentation from the Using Agency, confirming the need for the additional work, must be submitted. Documentation forwarded by the State Contract Manager to the Director must include all other required State approvals, such as those that may be required from the State of New Jersey’s Office of Management and Budget and NJOIT. No additional work and/or special project may commence without the Director’s written approval. In the event the contractor proceeds with additional work and/or special projects without the Director’s written approval, it shall be at the contractor’s sole risk. The State shall be under no obligation to pay for work performed without the Director’s

File revisions (1)