Criminal Justice Information Exchange

Location: Vermont
Posted: Apr 8, 2026
Due: Jun 26, 2026
Agency: State of Vermont
Type of Government: State & Local
Category:
  • D - Automatic Data Processing and Telecommunication Services
Publication URL: To access bid details, please log in.
TITLE QUESTIONS DUE ANSWERS POSTED DUE DATE NO POSTING AFTER
Criminal Justice Information Exchange
Bidder Response Form
CJIS_Requirements_Companion_Document
Additional_CJIS_RFP_Contract_Requirements

05/20/2026 04:30PM


06/26/2026 04:30PM

Attachment Preview

State of Vermont Bidder Response Form

Request for Proposal Name: Criminal Justice Information Exchange

Vendor Instructions:

Provide the information requested in this form and submit it to the State of Vermont as part of your Request for Proposal (RFP) response. All answers must be provided within the form unless otherwise specified.

Important: This form must be completed and submitted in response to this RFP for your proposal to be considered valid. The submission must also include the eight (8) additional artifacts requested within this form (denoted by underlined green font).

See the RFP for full instructions for submitting a bid. Bids must be received by the due date and at the location specified on the cover page of the RFP.

Direct any questions you have concerning this form or the RFP to:

STATE CONTACT

State of Vermont

Office of Purchasing & Contracting

E-mail Address:

Part 1: VENDOR PROFILE

Complete the table below.

Provide a brief overview of your company including number of years in business, number of employees, nature of business, and description of clients. Identify any parent corporation and/or subsidiaries.

Is your organization currently or has it previously provided solutions and/or services to any agency or entity of the Vermont State government within the past five years? If so, include a complete list of the State entities, the solutions and/or services provided, and the dates your organization provided the State with these services in the last five years.

Provide a Financial Statement* for your company and label it Attachment #1. This requirement can be filled by:

A current Dun and Bradstreet Report that includes a financial analysis of the firm;

An Annual Report if it contains (at a minimum) a Compiled Income Statement and Balance Sheet verified by a Certified Public Accounting firm; or

Tax returns and financial statements including income statements and balance sheets for the most recent 3 years, and any available credit reports.

A confidentiality statement may be included if this financial information is considered non-public information

*Some types of procurements may require bidders to provide additional or specific financial information. Any such additional requirements will be clearly identified and explained within the RFP and may include supplemental forms in addition to this Bidder Response Form.

Disclose any judgments, pending or expected litigation, or other real potential financial reversals, which might materially affect the viability or stability of your company or indicate below that no such condition is known to exist. A confidentiality statement may be included if this information is considered non-public information

Provide a list of three references similar in size and industry (preferably another governmental entity). References shall be clients, other than the State of Vermont, who have implemented your Solution within the past 48 months.

Part 2: Vendor Proposal/Solution

Provide a description of the technology solution you are proposing.

Provide a description of the capabilities of the technology solution you are proposing.

If specific software is being proposed, provide a description of the:

Standard features and functions of the software:

The software licensing requirements for the solution:

Maximum number of concurrent users:

Give a brief description of the evolution of the system/software solution you are proposing. Include the date of the first installed site and major developments which have occurred (e.g. new versions, new modules, specific features).

List the total number of installations in the last 3 years by the year of installation.

Provide the total number of current users for the proposed system and indicate what version they are using.

Have you implemented the proposed solution for other government entities? If so, tell us who, when, and how that implementation went?

Provide a Road Map that outlines the company's short term and long term goals for the proposed solution/software and label it Attachment #2. (A confidentiality statement may be included if this information is considered non-public information)

Provide a PowerPoint (minimum of 1 slide and maximum of 10 slides) that provides an Executive level summary of your proposal to the State. Label it Attachment #3.

Describe any infrastructure, equipment, network or hardware required to implement and/or run the solution.

What is your recommended way to host this solution?

Describe how your solution can be integrated to other applications and if you offer a standard-based interface to enable integrations.

Respond to the following questions about the solution being proposed:

Part 3: Functional Requirements

The table below lists the State's Functional Requirements. Indicate the "Availability" for each requirement for your proposed solution. Use the "Vendor Comments" column to provide any additional information or explanations.

A - Feature is available in the core ("out-of-the-box") solution.

D - Feature is currently under development (indicate anticipated date of availability in the Vendor comments column).

C - Feature is not available in the core solution but can provided with customization.

N - Feature is not available.

Part 4: Non- Functional Requirements

The tables below list the State's Non-Functional Requirements. Indicate if your proposed solution complies in the "Comply" column.

Yes = the solution complies with the stated requirement.

No = the solution does not comply with the stated requirement.

N/A = Not applicable to this offering.

Describe how the requirement is met in the "Vendor Description of Compliance" column.

4.1 Hosting

4.2 Application Solution

Security

As a solution vendor, you must have documented and implemented security practices for the following and have a process to audit/monitor for adherence. Indicate "Yes" or "No" in the "Comply" column or "N/A" if the requirement is not applicable to this offering. Use the "Vendor Description of Applicable Security Processes" column to describe how you meet the requirement and the "Audit/Monitor" column to indicate how you monitor for compliance. (A confidentiality statement may be included if this information is considered non-public information)

4.4 Other Non-Functional Requirements

For each requirement listed, indicate if and how you comply or type "N/A" if it is not applicable to your offering.

4.5 Data Compliance

Vendors and their solutions must adhere to applicable State and Federal standards, policies, and laws based on the type of data that will be stored, accessed, transmitted and/or controlled by the solution. If the "Type of Data" column is checked below, respond "Yes" or "No" in the "Comply" column and provide an explanation on how you comply in the "Vendor's Description of Compliance" column.

4.6 State of Vermont Cybersecurity Standard Update

Bidder shall certify by checking the box below the Solution shall not include, incorporate, rely on, utilize or be supported by any products or services subject to the limitations provided under State of Vermont Cybersecurity Standard Update, which Bidder acknowledges has been provided to it, and is available on-line at the following URL:

Bidder hereby certifies that in connection with the Request for Proposal, none of the applicable products or services will be included in or used to support State systems in a manner prohibited under the Standard.

4.7 CJIS SECURITY POLICY REQUIREMENTS

The CJIS Security Policy attachment lists the State's CJIS Non-Functional Requirements. Indicate the ability to "Comply" for each requirement for your proposed solution. Use the "Vendor Comments" column to provide any additional information or explanations.

Part 5: IMPLEMENTATION/Project Management Approach

[Add, modify or delete information in this section to be specific to your RFP.]

Describe the approach you would recommend for project managing this engagement.

Provide a list of the standard project management deliverables that you would normally produce for this type of engagement.

Provide a proposed list of project phases, major milestones, and an implementation time-line. Label this Attachment #4.

What types of difficulties have other clients experienced with implementation of the proposed solution?

Describe the experience and qualifications of the Project Manager you would offer as the resource for this engagement. Provide a copy of their resume and label it Attachment #5.

Part 6: TECHNICAL Services

[Add, modify or delete information in this section to be specific to your RFP.]

Describe the technical services included in your proposal (e.g., business analysis, configuration, testing, implementation, etc.).

Provide a list of the standard deliverables for the technical services described above.

Describe your business analysis approach for the implementation of CJIX. Describe your requirements elicitation and documentation processes and deliverables.

Describe how you document and manage other requirements related artifacts like acceptance criteria and business rules.

Provide a description of the roles/services/tasks the State will be expected to cover as part of this engagement. Describe any additional roles/services/tasks that are optional, but would be beneficial for the State to provide.

Describe your typical conversion plan to convert data from existing systems to your proposed solution (if applicable).

Describe and attach your typical Implementation Plan (label it Attachment #6), which shall include planning for the transition to maintenance and operations.

Describe the experience and qualifications of the technical resources proposed for this engagement. Provide their resume(s) and label them Attachment #7.

Describe the training that is included in your proposal.

Describe the system, administrator, and/or user documentation that is included in your proposal.

PART 7: Oral Demonstrations, Interviews and Trial Evaluation Period:

The State reserves the right to require a Vendor to present an Oral Demonstration of their proposed solution, preferably by the Vendor's Solution Experts and Information Technology staff that will be implementing the solution and respond to interview questions during the demonstration. The demonstration will be stand alone and should include a high-level overview of how the proposed solution meets the State's needs and will be limited to 90 minutes, then 30 minutes available for the State to ask questions about the proposed solution.

Request and be provided a Trial Evaluation (Hands-On Evaluation) Period of the proposed solution by State Evaluators. State Evaluators will have access to Vendor's Sandbox version of the proposed solution for Hands-On Evaluation which will include:

Hands-On Evaluation Setup Meeting prior to beginning of the Evaluation period with Vendor Representative, and State Representatives to review such items as

Account setup and types of roles.

Confirmation of Hands-On Evaluation duration dates.

Vendor Support contact during Hands-On Evaluation.

Setup of Kick-Off meeting with Vendor Representatives and State Evaluators.

Check-In meetings; setup of a minimum of two (2) meetings during Evaluation period.

How Vendor will respond to State questions and evaluation scripts findings (issues).

Pre-Hands-On Evaluation Support to ensure that all Evaluators have successfully logged into the Vendor's Sandbox.

Hands-On Evaluation Duration of Fifteen 15 Business Days.

First day of the Evaluation period, or prior to, a Kick-Off Meeting with Vendor Representatives, and State Evaluators for orientation of Vendor's Sandbox version of the solution.

Minimum of fourteen (14) business days of Hands-On Evaluation of Vendors proposed solution in Vendor's Sandbox.

Minimum of two (2) Check-In Meetings during Evaluation period with State Evaluators and Vendor Representatives to review any issues, blocks, features, and functionality discovered. It is preferred by the State that the first Check-In Meeting be in the first week of the Evaluation period.

All costs associated with oral demonstration, interviews, and Sandbox setup and usage for Hands-On Evaluation will be borne entirely by the Vendor.

Describe how you will make these items possible and what Vendor support will be provided during Hands-On Evaluation period.

Part 8: Maintenance and Support Services

Provide answers to the questions below regarding your company's Maintenance and Support Services:

Describe how adherence to your service levels is measured and what remedies you would provide the State when performance doesn't meet the standard?

Part 8: PRICING

Submit pricing for your proposed solution in the table below. Fill in only the lines that are applicable to your proposal. Insert lines for additional costs, but do not delete or rename any lines in the Table. Total each column and provide a total of all columns in the "Total Implementation, plus 5 Year Costs" box on the next page.

Describe any assumptions you have made in relation to the above cost and pricing information.

Provide pricing information for any volume discounts that are available based on the number of software licenses purchased or support years purchased.

Provide pricing for any Functional Requirements marked as "C" (feature is not available in the core solution, but can be provided with customization).

Part 9: Terms and Conditions

Exceptions to the States standard terms, conditions, and templates is strongly discouraged. Accordingly, exceptions may result in a determination that a bidders proposal is not in the best interest of the State. However, if a bidder does wish to take exception to the State's terms, conditions, or templates they must indicate those objections in the table below. Add lines to the table below as needed. The State considers contractor documents the bidder wishes to append to the contract as exceptions.

Part 10: CERTIFICATE OF COMPLIANCE/Authorized Company Signature

NON COLLUSION: Bidder hereby certifies that the prices quoted have been arrived at without collusion and that no prior information concerning these prices has been received from or given to a competitive company. If there is sufficient evidence to warrant investigation of the bid/contract process by the Office of the Attorney General, bidder understands that this paragraph might be used as a basis for litigation.

CONTRACT TERMS: Bidder hereby acknowledges that is has read, understands and agrees to the terms of this RFP, including Attachment C: Standard State Contract Provisions, and any other contract attachments included with this RFP.

Worker Classification Compliance Requirement: In accordance with Section 32 of The Vermont Recovery and Reinvestment Act of 2009 (Act No. 54), the following provisions and requirements apply to Bidder when the amount of its bid exceeds $250,000.00.

Self-Reporting. Bidder hereby self-reports the following information relating to past violations, convictions, suspensions, and any other information related to past performance relative to coding and classification of workers, that occurred in the previous 12 months.

Subcontractor Reporting. Bidder hereby acknowledges and agrees that if it is a successful bidder, prior to execution of any contract resulting from this RFP, Bidder will provide to the State a list of all proposed subcontractors and subcontractors' subcontractors, together with the identity of those subcontractors' workers compensation insurance providers, and additional required or requested information, as applicable, in accordance with Section 32 of The Vermont Recovery and Reinvestment Act of 2009 (Act No. 54), and Bidder will provide any update of such list to the State as additional subcontractors are hired. Bidder further acknowledges and agrees that the failure to submit subcontractor reporting in accordance with Section 32 of The Vermont Recovery and Reinvestment Act of 2009 (Act No. 54) will constitute non-compliance and may result in cancellation of contract and/or restriction from bidding on future state contracts.

Executive Order 05 - 16: Climate Change Considerations in State Procurements Certification

Bidder certifies to the following (Bidder may attach any desired explanation or substantiation. Please also note that Bidder may be asked to provide documentation for any applicable claims):

Bidder owns, leases or utilizes, for business purposes, space that has received:

Energy Star(R) Certification

LEED(R), Green Globes(R), or Living Buildings ChallengeSM Certification

Other internationally recognized building certification:

____________________________________________________________________________

2. Bidder has received incentives or rebates from an Energy Efficiency Utility or Energy Efficiency Program in the last five years for energy efficient improvements made at bidder's place of business. Please explain:

_____________________________________________________________________________

3. Please Check all that apply:

Bidder can claim on-site renewable power or anaerobic-digester power ("cow-power"). Or bidder consumes renewable electricity through voluntary purchase or offset, provided no such claimed power can be double-claimed by another party.

Bidder uses renewable biomass or bio-fuel for the purposes of thermal (heat) energy at its place of business.

Bidder's heating system has modern, high-efficiency units (boilers, furnaces, stoves, etc.), having reduced emissions of particulate matter and other air pollutants.

Bidder tracks its energy consumption and harmful greenhouse gas emissions. What tool is used to do this? _____________________

Bidder promotes the use of plug-in electric vehicles by providing electric vehicle charging, electric fleet vehicles, preferred parking, designated parking, purchase or lease incentives, etc..

Bidder offers employees an option for a fossil fuel divestment retirement account.

Bidder offers products or services that reduce waste, conserve water, or promote energy efficiency and conservation. Please explain:

____________________________________________________________________________

____________________________________________________________________________

Please list any additional practices that promote clean energy and take action to address climate change:

_____________________________________________________________________________

____________________________________________________________________________

_____________________________________________________________________________

Executive Order 02 - 22: Solidarity with the Ukrainian People

By checking this box, Bidder certifies that none of the goods, products, or materials offered in response to this solicitation are Russian-sourced goods or produced by Russian entities. If Bidder is unable to check the box, it shall indicate in the table below which of the applicable offerings are Russian-sourced goods and/or which are produced by Russian entities. An additional column is provided for any note or comment that you may have.

Certification Regarding Use of Contract Funds for Lobbying. The following provision is applicable to the Contractor for contracts over $100,000.00, and Contractor shall include this clause in all its subcontracts over $100,000.00.

1. The prospective contractor certifies, to the best of his or her knowledge and belief, under the penalties of perjury under the laws of the State of Vermont and the United States that on behalf of the person, firm, association, or corporation he or she represents, that:

a. No Federal appropriated funds have been paid or will be paid, by or on behalf of the undersigned, to any person for influencing or attempting to influence an officer or employee of any Federal agency, a Member of Congress, an officer or employee of Congress, or an employee of a Member of Congress in connection with the awarding of any Federal contract, the making of any Federal grant, the making of any Federal loan, the entering into of any cooperative agreement, and the extension, continuation, renewal, amendment, or modification of any Federal contract, grant, loan, or cooperative agreement.

b. If any funds other than Federal appropriated funds have been paid or will be paid to any person for influencing or attempting to influence an officer or employee of any Federal agency, a Member of Congress, an officer or employee of Congress, or an employee of a Member of Congress in connection with this Federal contract, grant, loan, or cooperative agreement, the undersigned shall complete and submit Standard Form-LLL, "Disclosure Form to Report Lobbying," in accordance with its instructions.

2. This certification is a material representation of fact upon which reliance was placed when this transaction was made or entered into. Submission of this certification is a prerequisite for making or entering into this transaction imposed by 31 U.S.C. 1352. Any person who fails to file the required certification shall be subject to a civil penalty of not less than $10,000 and not more than $100,000 for each such failure.

3. The prospective contractor also agrees that they shall require that the language of this certification be included in all lower tier subcontracts, which exceed $100,000 and that all such recipients shall certify and disclose accordingly.

For your bid to be considered valid, this Bidder Response Form must be signed by a duly authorized representative of the bidder, and submitted as part of the response to the proposal.

I am authorized to submit a proposal to the State of Vermont in response to this RFP on behalf of my organization. The information provided as part of my organization's response is a true and accurate representation of my organization's ability to meet the State of Vermont's business needs as expressed in this RFP.

Item Detail
Company Name: [insert the name that you do business under]
Physical Address: [if more than one office - put the address of your head office]
Postal Address: [e.g. P.O Box address]
Business Website: [url address]
Type of Entity (Legal Status): [sole trader/partnership/limited liability company or specify other]
Primary Contact: [name of the person responsible for communicating with the Buyer]
Title: [job title or position]
Email Address: [email]
Phone Number: [landline]
Fax Number: [fax]
Reference 1 Detail Detail
Reference Company Name: [insert the name that you do business under] [insert the name that you do business under]
Company Address: [address] [address]
Type of Industry: [industry type: e.g., government, telecommunications, etc.] [industry type: e.g., government, telecommunications, etc.]
Contact Name: [if applicable] [if applicable]
Contact Phone Number: [phone] [phone]
Contact Email Address: [email] [email]
Description of system(s) implemented: [description] [description]
Date of Implementation: [date] [date]
Reference 2 Reference 2 Detail
Reference Company Name: Reference Company Name: [insert the name that you do business under]
Company Address: Company Address: [address]
Type of Industry: Type of Industry: [industry type: e.g., government, telecommunications, etc.]
Contact Name: Contact Name: [if applicable]
Contact Phone Number: Contact Phone Number: [phone]
Contact Email Address: Contact Email Address: [email]
Description of system(s) implemented: Description of system(s) implemented: [description]
Date of Implementation: Date of Implementation: [date]
Reference 3 Detail
Reference Company Name: [insert the name that you do business under]
Company Address: [address]
Type of Industry: [industry type: e.g., government, telecommunications, etc.]
Contact Name: [if applicable]
Contact Phone Number: [phone]
Contact Email Address: [email]
Description of system(s) implemented: [description]
Date of Implementation: [date]
Vendor Response/Explanation Vendor Response/Explanation
Question Yes or No
Does the solution use Service Oriented Architecture for integration?
Does the solution use a Rules Engine for business rules?
Does the solution use any Master Data Management?
Does the solution use any Enterprise Content Management software?
Does the solution use any Case Management software?
Does the solution use any Business Intelligence software?
Does the solution use any Database software?
Does the solution use any Business Process Management software?
Is this a browser based solution and if so what browsers do you support?
Does the solution include an API for integration?
ID # Functional Requirement Description Availability Vendor Comments
1 Consolidated Dispatch Centers 1 Consolidated Dispatch Centers 1 Consolidated Dispatch Centers 1 Consolidated Dispatch Centers
A01 As a dispatch center supervisor with workstations that simultaneously dispatch for multiple agencies, I want both: all of my workstations and/or a sub-set of my workstations to receive inbound messages for all agencies that the dispatch center supports so that my employees are informed.
A02 As a State Police Dispatcher and Admin with the necessary role permissions, I want a mobile command post station that can travel with me to an emergency within any agency across the state which will allow me to utilize any ORI that I need to so that I can respond efficiently and effectively to the emergency.
A03 As an employee who dispatches/works at a consolidated dispatch center supporting multiple agencies, I want to receive messages for all agencies we support, with the option to filter messages to a specific agency or agencies, so that I can effectively dispatch for multiple agencies simultaneously or focus on a specific agency as needed by the dispatch center.
2 Multi-Agency Employees 2 Multi-Agency Employees 2 Multi-Agency Employees 2 Multi-Agency Employees
A04 As an employee who dispatches/works for multiple agencies, I want different permissions for each agency (within a single user account) that I work with so that I can securely perform my job duties for each agency that I am supporting per shift. (ex: As a TAC for Middlesex, and a less-than-full-service user for Montpelier, I cannot perform full TAC functions at the Montpelier agency).
A05 As an employee who dispatches/works for multiple agencies, I want to receive messages only for the agency (or consolidated dispatch center) that I am actively working for during that shift so that I stay focused on the current job and don't miss important messages. I also want to filter the messages that I receive based on agency and/or role so I can keep the messages organized for efficient workflows. (I should not have to manage multiple user accounts for my multiple roles and/or agencies)
A06 As an employee who dispatches/works for multiple agencies, I want to choose which agency ORI to use for each message that I send so that I can accurately represent the agency that I am sending the message on behalf of (shift-based).
A07 As a user who has permissions to utilize multiple ORIs, I may only do so at specific workstations so that security standards can be maintained. Workstations should have a configurable list of ORIs they can utilize, and users may only use an ORI if their user account AND the workstation are both authorized to use the ORI.
3 Record Holding Agreements 3 Record Holding Agreements 3 Record Holding Agreements 3 Record Holding Agreements
A08 As a State Police Admin Clerk or another part-time center employee, I want to assign a 24/7 Dispatch/PSAP center as my "holding agency" so that they can verify data when I am not available.
A09 As an agency with a Holder of Records Agreement with another agency, I want all of my configurations migrated to and/or maintained to the 24/7 agency so that non-terminal or non-24/7 agencies are able to maintain 24-hour dispatch services of NCIC/NLETS/VLETS/NCIC/III record information. (ex: so that a user can create a record within NCIC, on behalf of another agency's Originating Identifier "ORI").
A10 As a "holder of records" agency for another agency, I want to receive messages that are sent to the originating agency, so that I have all context for situations, should they arise.
A11 As a "holder of records" agency for another agency, I want to use the originating agency's ORI for NCIC transactions so that I can represent the originating agency accurately.
A12 As a "holder of records" agency for another agency, I want to receive a copy of any unsolicited traffic to the originating agency so that I can be kept informed.
A13 As an internal state developer, I want an instant way to adjust ORI access, in case of emergency ("mutual aid") and for multiple users and agencies at once so that for one-off situations such as a mass-incident, an agency can accept administrative assistance from other agency's' staff.
A14 As an operator sending messages using an Agency ORI, the platform should ensure that I have permission to use the ORI prior to processing the transaction.
A15 As a user (and agency, and station) who has permissions to enter or query a record on behalf of another ORI, I want a drop-down option available to me so that I can determine or change my ORI selection for a specific transaction.
A16 As the NCIC Auditor, I want to set up and configure agency settings so that, for example, an agency can allow another agency to pick up messages for them after hours.
4 Auditing and Accountability 4 Auditing and Accountability 4 Auditing and Accountability 4 Auditing and Accountability
AA01 As an Integration Developer, I want to assist specific and authorized users with investigating system use so that they can identify any misuse of the system.
AA02 As an Integration Developer, I want to investigate and re-construct timelines from message history so that I can help users investigate unexpected system behavior or so that I can investigate unusual user behavior.
AA03 As the NCIC Auditor, I want to assess how other agencies are entering/modifying/canceling records and how other users run reports so that I can comply with FBI, CJIS, and Vermont Statute Security Standards.
AA04 As the NCIC Auditor, I want to assist the FBI during their tri-annual state audit of VCIC sections so that I can help them validate that users' data access was compliant and based on criminal justice operations and so that Vermont can maintain access to FBI data.
AA05 As the NCIC Auditor, I want to visually monitor message traffic utilizing a dashboard so that I can find errors and so that I can intervene and help users with their encountered errors.
AA06 As the NCIC Auditor, I want to research cases and records that may have been accessed or disseminated improperly for auditing purposes.
AA07 As the NCIC Auditor, I want to access basic user account data such as when a user account was created for auditing purposes.
AA08 As the NCIC Auditor, I want to access basic message data such as "which user account conducted a transaction" or "what variations/errors did a message encounter" or "what steps did a user take to encounter an error message" for auditing purposes.
AA09 As the NCIC Auditor, I want the ability to visually graph report data so that, for example, I could show an agency the occurrence of data they query, how their users utilize the system, their users' success or error rates.
AA10 As the NCIC Auditor, I want to utilize an archive and retrieval function so that I can search for and audit records utilizing robust search and filter functionality so that I can comply with tri and bi-annual audits (ex: list of all wanted persons within a specific ORI from the past 3 years and with MRI) - I also want to save my search history and parameters.
AA11 As a Vermont State Police Dispatcher, I want to run audit queries (for example, view all missing people within a certain agency/agencies) so that I compile the data that I need to keep Vermonters safe and secure.
AA12 As a Vermont State Police Dispatcher Supervisor, I want to review prior queries and responses to/from my dispatch center (according to CJIS policy's access privileges: the principal of least privilege should be maintained) so that I can establish timelines for messages previously sent or received.
AA13 As an Integration Developer, I want to quantify user and workstation activity so that I can re-assign licenses, if need be.
AA14 As the NCIC Auditor, I want to review (and filter) message data such as where the message was from, where it was sent, what database(s) the message has found a hit within so that I can be informed of message data.
AA15 As the NCIC Auditor, I want to maintain a log of all users and agencies that access Criminal History Record based on ORI, so that I can provide the FBI with this data monthly and so that Vermont can comply with the FBI CJIS Security Policy without having to perform manual work. (FBI requires 1 year retain of Criminal History access logs) (example: X record accessed on X date for X reason).
AA16 As the NCIC Auditor, I want to access a single message by utilizing search functionality for auditing purposes.
5 CCH Database: CCH Admin 5 CCH Database: CCH Admin 5 CCH Database: CCH Admin 5 CCH Database: CCH Admin
CCH01 As a VT CCH administrator, I want to perform administrative functions such as managing agency, event, disposition and charge codes so that the system will support all codes used by the judiciary.
CCH02 As a VT CCH administrator, I want to search for and unseal a criminal history record that has been ordered "unsealed" by the judiciary.
6 CCH Database: CCH Integrations 6 CCH Database: CCH Integrations 6 CCH Database: CCH Integrations 6 CCH Database: CCH Integrations
CCH03 As the Fingerprint Section Supervisor, I want to validate that each fingerprint submission (including livescan data) populates arrest data from AFIS into the solution so that I can review the fingerprint submission for quality.
CCH04 As the Fingerprint Section Supervisor, I want to send data from the solution to AFIS Scanner, so that I don't need to manually enter data into both solutions.
CCH05 As the Fingerprint Section Supervisor, I want to send data from the solution to the FBI so that I can get an FBI number created.
CCH06 As a VT CCH team member, I want to review (quality check) and import a disposition file (PDF) that I receive from the courts into the solution so that charge outcomes (such as new cycles added, existing cycle updated (ex: prints), and rejected (ex: new names/DOBs to the solution or not on file, case numbers that match but docket number does not match or vice versa)) do not need to be manually entered.
CCH07 As a VT CCH team member, I want to enter (automatically) weekly, a court file of violations of probations (csv) into the solution so that we can monitor any probation violations that have occurred.
CCH08 As a VT CCH team member, I want to review and import (automatically) a monthly death report (txt) into the solution (that I receive from the Department of Health) so that any dead person that is within the database can receive a "dead" flag on their record, and so that their date of death can be logged.
CCH09 As a VT CCH team member, I want to automatically import the events from a Parole Board Report (pdf) into the solution so that individuals that have been released from their parole, have violated their parole, or are no longer on parole can be accurately documented and updated within the solution.
CCH10 As a VT CCH team member, I want to automatically import the Failure to Appear Report into the solution so that "failure to appears" can be documented and updated per criminal dockets.
CCH11 As a VT CCH team member, I want to automatically import/ingest reports so that I don't need to open every single docket that is impacted/affected by the report when I do my quality control work.
CCH12 As a VT CCH team member, I want to export cancellations from the solution so that I can upload the cancellations (Brady disqualifications or modifications) into the FBI-Maintained Law Exchange Portal (LEEP) (NICS Indices) (LEEP allows LE direct access to NCIC).
7 CCH Database: CCH Record Management 7 CCH Database: CCH Record Management 7 CCH Database: CCH Record Management 7 CCH Database: CCH Record Management
CCH13 As a VT CCH team member, I want to remove records from the Triple III (Interstate Identification Index) so that the records can be disqualified/expunged.
CCH14 As a VT CCH team member, I want to perform quality control on imported court charges (from disposition file), so that I can validate data (ex: manually match/link hits, fix spelling errors to match hits, create new entries in CCH if new).
CCH15 As a VT CCH team member, I want to automatically expunge and/or seal a record (approximately 1000 orders a month) from the Triple III (when it is expunged/sealed from our state CH database) so that the record can be deleted or hidden (respectively) from certain user permissions (excluding Law Enforcement).
CCH16 As a VT CCH team member, I want to search for data and filter and fine-tune my searches so that I can find exactly what I need. (ex: search by docket number, search by 2nd docket within a specific set of cycle counts, search by statutes/whether individual was convicted/group by dates, query by case number or fingerprint tracking number)
CCH17 As a DOC Staff Member, I want to see the full evolution and history of a criminal history case (including original sentences, probation violations, suspensions) so that I can be truly informed of an individual's history and current status.
CCH18 As a VT CCH team member, I want to pull a report based on varying data points (such as docket number or incidents during a specific time period) in an abstractable fashion so that I can compile, print, and/or export data that I need in any format that I need such as XLS and CSV (ex: run a report based on data fields for export to meet the needs of an FBI audit).
CCH19 As the Fingerprint Section Supervisor, I want to run a daily Triple III (Interstate Identification Index) query (report) so that FBI data changes get automatically updated within the VTCCH database to reflect the accurate current state (such as when an FBI/UNC number, SID, Flag have been expunged and removed).
CCH20 As the Fingerprint Section Supervisor, I want to review incoming criminal and civil (non-criminal) fingerprint and mugshot submissions so that I can validate the quality (accurate, up to date, comprehensive) of the arrest submission.
8 Data Migration & Historical Records 8 Data Migration & Historical Records 8 Data Migration & Historical Records 8 Data Migration & Historical Records
DM01 As an IT administrator, I want all data from the current system (that we are required by statute or CJIS Security Policy to maintain for a period of time) to be migrated to the new solution by the vendor so that we maintain compliance with the law and policy.
DM02 As an IT administrator, I want the existing system configuration (Users, ORIs, Stations, Agencies, MKEs, etc.) to be migrated to the new solution so that I don't have to spend time recreating the existing system configuration.
9 Digital Line-Ups 9 Digital Line-Ups 9 Digital Line-Ups 9 Digital Line-Ups
DLU01 As a State Police Admin, I want to create a digital line-up of mugshot photos to present to a witness so that I can determine whether the witness can identify a subject.
10 Imports, Exports & Reports 10 Imports, Exports & Reports 10 Imports, Exports & Reports 10 Imports, Exports & Reports
IER01 As an Integration Developer, I want to build a custom query for searching data (with custom keys for the queries) so that I can assist users when necessary.
IER02 As an Integration Developer, I want to the solution to query data that I can trust so that I don't have to export into other platforms such as SQL for further investigation.
IER03 As an Integration Developer, I want to report on and query data within the system such as "Number of messages that a user or agency handled" or "Station name that a certain ORI delivers to" so that I can make informed decisions.
IER04 As a local law enforcement dispatcher, I want to print any screen/form/returns that I am viewing within the solution and any query/report that I have populated within the solution so that, for instance, I can disseminate the data to an incarcerated or supervised individual's case worker(s). *must be in printable format and fall within standard paper margins
IER05 As a local law enforcement dispatcher, I want to save/download any screen/form/return and any query/report that I am viewing so that that, for instance, I can further manipulate the data in another solution (CSV, PDF, xml, JSON, etc.).
11 Message Terminal/Inbox: Admin Messages 11 Message Terminal/Inbox: Admin Messages 11 Message Terminal/Inbox: Admin Messages 11 Message Terminal/Inbox: Admin Messages
M01 As a law enforcement dispatcher or admin, I want to send and receive both templated and un-templated hit conformation requests and/or responses (in plain English) so that I can request a known record from another state or agency (ex: trooper asking if an individual is still wanted) or validate a request from another state or agency (such as validating a licensed professional's charges or identity or confirming that indeed, the individual is still wanted) within a set time period (urgent = 10 mins, non-urgent = 1 hour).
M02 As a local law enforcement dispatcher or admin, I want to send and receive both templated and un-templated admin messages such as a "Be on the Lookout" (BOL) to other agencies within the state, region, and nation so that they can be informed of recent events and current activity.
12 Message Terminal/Inbox: Printing 12 Message Terminal/Inbox: Printing 12 Message Terminal/Inbox: Printing 12 Message Terminal/Inbox: Printing
M03 As an agency who would like to print messages, I want to print all messages that come into my dispatcher's terminal (automatic and on demand) so that I can have a physical copy of messages.
13 Message Terminal/Inbox: Send & Receive User Experience 13 Message Terminal/Inbox: Send & Receive User Experience 13 Message Terminal/Inbox: Send & Receive User Experience 13 Message Terminal/Inbox: Send & Receive User Experience
M04 As a DOC Full-Service Terminal Operator, I want to query and track warrants by various fields (such as by every warrant that I am responsible for) so that I can clearly visualize my workload.
M05 As a law enforcement dispatcher or admin, I want my Hit Confirmations to auto-populate data based on the data in the associated message so that I do not need to duplicate entry.
M06 As a user, I want to view the message return data in multiple formats with custom filters (presentation view, xml, raw data, hex view) so that I can export it if need be.
M07 As a user, I want to search within my own inbox so that I can locate specific messages.
M08 As a user, I want to specify the subject line of my message so that I can clarify the purpose for my recipients and to improve efficiency.
M09 As a user, I want relevant data (to my search/query) to be highlighted within a return so that I don't have to scroll/search for the important data that I need.
M10 As a user, I want all messages to be date and time stamped and with a unique MRI and message number so that I can locate the message in the future.
M11 As a user, I want all message returns to be filtered and listed, for example, by type of form: MKE, by source (NCIC/HFS/User), by date so that I can sort my returns by those field values if need be (for example, I want to sort by source so that I can validate that there are no instate, national, or DMV warrants out for a specific person).
M12 As a State Police Dispatcher, I want the data returned from my queries to be clear, concise (glance-able), up-to-date, pertinent, relevant, and with a single source of truth (ex: suspension indicators) without having to scroll through outdated or repetitive information so that I can provide timely and accurate information to a trooper so that I can keep both the requesting trooper and the public safe.
M13 As a State Police Dispatcher, when running a query, I want returned information instantly summarized in plain text English with key data in a highly visible location (at the top of the return screen) so that time is not wasted when supplying troopers with crucial information (such as if a vehicle in their traffic stop is currently stolen or if an individual in their traffic stop is currently wanted for a violent crime).
M14 As a user, I want a pull-back method so that I can edit or remove a previously sent message (ex: after sending an admin message, I need to pull it back to edit a typo).
M15 As a user, I want to mark a message as unread so that I can have a visual reminder to return to the message when needed.
M16 As a user, I want to specify the destination of my message and receive only the messages that are pertinent to my work (driven by my role and message type) so that I am not distracted by messages that do not pertain to me. (ex: dispatch should receive every admin message, but troopers should receive messages only on need-to-know basis (based on CJIS rules for FBI). I want to clearly identify which messages are relevant and important to me (1k messages a day) so that I can respond to my specific message-load.
M17 As a user sending standardized messages, I want to be prevented from submitting invalid/non-conformant messages (the system should validate messages before they are sent) so that messages can remain consistently formatted.
M18 As a DOC Full-Service Terminal Operator, I want to enter both single and multiple warrants for a single wanted person so that all relevant data is collected on an individual.
M19 As a local law enforcement dispatcher, I want to locate data such as name, dob, vehicle, driver's license, offense, so that I can document an incident or report to support local first responders during their incidents.
M20 As a State Police Admin, I want to run a Criminal History request, License check, or License plate check, so that I can provide the returned data to the requesting State Trooper. Acceptance Criteria: Given that I am a VSP Admin, when a newly incarcerated or supervised individual is taken into custody, and at least once a year following, and when determining status and classification of custody, then I can run a criminal history on the individual.
M21 As a State Police Admin, I want to utilize F-keys (short cut keys) when querying so that I can more quickly and efficiently access the data that I need.
M22 As a law enforcement dispatcher, I want to monitor messages (such as a request for warrant message) so that I can keep local police informed and ultimately, keep Vermonters safe.
M23 As a law enforcement dispatcher, I want to be notified (by sound, alert banner, pop-up, highlight, work queue, or other means) of urgent messages (such as an urgent Hit Confirmation Request) so they are handled promptly and never missed.
M24 As a law enforcement dispatcher, I want to run name query with phonetic or approximate name-matching functionality so that I can provide information to first responders even if I don't have accurate spelling of an individual's name.
M25 As a State Police Dispatcher, I want to perform a Meta or Super Query (such as a super name or super license plate query) by inputting data once to simultaneously query VT DMV, NCIC, and NLETS partners' databases so that I do not need to individually query each source when providing pertinent information (such as name, vehicle & registration, driver, license plates, license photos, criminal history information (previous offenses)) to the requesting troopers so that they have up-to-date information during their arrest and when documenting court records and so that I can investigate a licensed professional.
M26 As an Integration Developer, I want to ensure the conditional logic that drives message spawning can be configured so that modifications can be made when needed.
14 Security: Access Control & Enforcement 14 Security: Access Control & Enforcement 14 Security: Access Control & Enforcement 14 Security: Access Control & Enforcement
S01 As an Integration Developer, I want to access user, station, agency and other configuration data via an API, direct database query, or another tool so that I can have direct access to look at attributes such as which agencies a user works for and whether the user is full or limited service, what permissions are granted to a station and which agencies it can represent when interacting with NCIC/NLETs, and other operational details.
S02 As an Integration Developer, I want to ensure all users have access to the interface(s) they need and ensure that the system is reliable, secure so that public safety is able to be prioritized across the state.
S03 As an Integration Developer, I want to set up security roles and configure users and user-groups so that the state can implement role-based access control to sensitive data and features.
S04 As the NCIC Auditor, I want to ensure the solution integrates with NexTest so that I can continue to adjust user settings, assign user to specific roles, add/disable/change profile information, assign test results (for certification) and assign/adjust test dates.
S05 As the NCIC Auditor, I want to access my unique security role so that I can access the FT Query (file transfer between VT and NCIC) and the SPRQ Query (any VT record in NCIC).
S06 As an investigator with the Office of Professional Regulation (OPR) or another user with less-frequent usage of the solution, I want access to only the forms that I need and none of the forms that I don't utilize, so that I can efficiently work within the solution.
S07 As an internal state developer, I want to ad-hoc create and modify security role(s) based on arising needs.
S08 As the NCIC Auditor, I want to set up both full-service and less-than-full-service user accounts for new and returning certified staff so that they can have access to the solution (once they have passed their NexTest certifications). I want the ability to configure/modify existing accounts so that I can, for example, de-activate accounts upon exit or lock-down accounts when VCIC has determined a user should no longer have access.
15 Security: User Account/Session Management 15 Security: User Account/Session Management 15 Security: User Account/Session Management 15 Security: User Account/Session Management
S10 As an Integration Developer or Helpdesk Staff Member, I want to perform user management functions such as resetting passwords and updating account names so that I can keep the data safe and users up to date.
S11 As a user, when my password has expired, I want to self-reset my password on my own initiation so that I don't have to contact a helpdesk or admin to get me reset (all security settings must follow CJIS Security Policy).
S12 As a Platform Administrator, I want to review current license assignments and usage so that I can determine whether our supply is adequate and find free licenses to assign to new users.
S13 As a Platform Administrator, I want to immediately terminate or disconnect a user's active session after determining the session is operated by a bad actor or someone without valid clearance so that I can protect the integrity of the system and limit the damage an attacker could cause.
16 System Integration & Data Exchange: Admin Configurations 16 System Integration & Data Exchange: Admin Configurations 16 System Integration & Data Exchange: Admin Configurations 16 System Integration & Data Exchange: Admin Configurations
SIDE01 As a Platform Administrator, I want to configure delivery paths to specific and customized agency settings (ex: all messages are printed, or all messages delivered to the first dispatch position, dispatch outsourced to another set agency) so that each individual agency can keep their preferred settings in a future system. I want to be able to adjust these settings for the agencies at any time post-implementation
SIDE02 As a Platform Administrator, I want a dashboard representing data such as user-encountered error messages, messages that were unable to be delivered (message queue), invalid parameters (to identify downstream vendors route breaking), Platform Status Screen (ex: disc space) and code-processing issues so that I can visually monitor indicators of issues.
17 System Integration & Data Exchange: Integration with Internal Info Systems 17 System Integration & Data Exchange: Integration with Internal Info Systems 17 System Integration & Data Exchange: Integration with Internal Info Systems 17 System Integration & Data Exchange: Integration with Internal Info Systems
SIDE03 As a State Police Admin, I want to utilize standardized VT CCH message keys so that I can efficiently query records residing in VT CCH.
SIDE04 As a State Police Admin, I want to utilize standardized VT DMV message keys so that I can retrieve individual's state ID data such as Identification, driving history, vehicle registration information, handicap placard statuses.
18 System Integration & Data Exchange: Integration Major CJI Exchange Systems 18 System Integration & Data Exchange: Integration Major CJI Exchange Systems 18 System Integration & Data Exchange: Integration Major CJI Exchange Systems 18 System Integration & Data Exchange: Integration Major CJI Exchange Systems
SIDE05 As an Integration Developer, I want to ensure compliance with and interpret system behavior based on CJIS Security Requirements, NCIC Operators Manual, and the NLETS Standard so that Vermont remains within federal compliance.
SIDE06 As the NCIC Auditor, I want to enter records, modify records, and clear/cancel records so that I can keep Vermont's criminal justice data up to date.
SIDE07 As a DOC Full Service Terminal Operator, I want to manage warrants (Temporary and Permanent) in accordance with the FBI operating manual so that I can keep them up to date with a single source of truth (all warrants issued to a single individual) to increase clarity for users and keep law enforcement and the DOC community safe. Acceptance Criteria: The following field examples must be included: Name, DOB, LE Agency/Keeper of warrant, Date of Issuance, Offense.
SIDE08 As a DOC Full-Service Terminal Operator, I want to run criminal history record queries against NCIC/VT CCH/FBI/III/NLETS databases on an Incarcerated or Supervised Individual (or staff/contractors/volunteers) - so that I can manage their case (ex: to inform programming, release eligibility).
SIDE09 As a local law enforcement dispatcher, I want to query NCIC data (view/enter/clear/cancel/modify records) such as stolen vehicles, wanted persons, missing persons, protection orders, stolen articles, firearms, gang activity, warrants, violent persons, sex offenders so that I can provide the information to local police to keep them informed and safe during incidents.
SIDE10 As a State Police Admin, I want to utilize standardized NICS message keys (defined in the NICS Manual - such as add/modify/delete/unseal/audit) so that I can efficiently query and make changes (query/enter/modify/cancel) to records residing in NICS. (ex: when performing a fire-arm return (currently: QN/QNP) I want to query data to ensure the person in question is legally able to have their firearm returned to them).
SIDE11 As the Fingerprint Section Supervisor, I want to gather information on specific offenders/fingerprints by interacting with the "Triple III" (Interstate Identification Index/NFF) according to the (National Fingerprint File Operational and Technical Manual NGI-DOC-09034-2.0) using standard message keys (ex: MRS, DRS, DEC, TQ, EHN, XHN, QH, QR, ZRS) so that, for example, I can see if a licensed professional has a fingerprint supported arrest from another state.
SIDE12 As a State Police Admin with TAC (Terminal Access Coordinator) permissions, I want to run NCIC Validations (review and then modify a record) so that the solution accurately reflects current (last-validated) data on records such as active wanted persons, protection orders, stolen property and people with restraining orders.
SIDE13 As a State Police Admin, I want to utilize standardized NCIC message keys (defined in the NCIC Operator's Manual - such as: add/modify/delete/cancel/clear) so that I can efficiently query and make changes (query/enter/modify/cancel) to records residing in NCIC to keep law enforcement and DOC communities safe.
SIDE14 As a State Police Admin, I want to utilize standardized NLETS message keys (defined in the NLETS user guide) so that I can query NLETS and NLETS partner data.
SIDE15 As a State Police Dispatcher, I want to make updates and modifications to records in NCIC so that I can keep them up to date.
19 System Integration & Data Exchange: Integration with Other Systems 19 System Integration & Data Exchange: Integration with Other Systems 19 System Integration & Data Exchange: Integration with Other Systems 19 System Integration & Data Exchange: Integration with Other Systems
SIDE16 As an Integration Developer, I want to perform connectivity troubleshooting such as CAD RMS (user authentication) and NexTest (re-certifications) so that I can help users interpret error messages. (Integrations: CAD RMS, MugShot WebApp, VCCRIS, VTCourts, Idemia, NexTest, Offender Watch)
SIDE17 As a user (such as a dispatcher or admin), I want to "pack" records with information from other systems, such as DMV, Valcour, Spilman, so that NCIC records can have full and robust data with all available information.
SIDE18 As a DOC Terminal Operator, I want to review Sex Offender Registry Information when I am performing a super/meta name query so that I can review if anyone is on the registry (both in and out of state) for a registerable offense.
20 System Integration & Data Exchange: System Configuration Management & Retention 20 System Integration & Data Exchange: System Configuration Management & Retention 20 System Integration & Data Exchange: System Configuration Management & Retention 20 System Integration & Data Exchange: System Configuration Management & Retention
SIDE19 As a Platform Administrator, I want change control capabilities so that I can roll back changes in case of any issues.
21 Support 21 Support 21 Support 21 Support
TS01 As a Platform Administrator, I want to ensure that the vendor documents any conditional logic that is hard coded in the system so that I can refer to the documentation when needed.
TS03 As an Integration Developer, I want an open line of communication with the vendor of the solution so that helpdesk tickets can get resolved and so that I can be a liaison between the users and the vendor.
22 UX/UI Configuration & Customization: Administrator Configurations 22 UX/UI Configuration & Customization: Administrator Configurations 22 UX/UI Configuration & Customization: Administrator Configurations 22 UX/UI Configuration & Customization: Administrator Configurations
CC01 As an infrequent user of the system, I want to view the name and acronym of the forms (rather than solely an acronym so that I can be reminded of the form names.
CC02 As a law enforcement dispatcher or admin, I want to tailor the notification behavior to my role so that I'm notified of things I can address and not interrupted by things that I cannot.
CC03 As an Integration Developer, I want to modify the XML stylesheets used to present XML messages to end users, adding fields that are displayed, displaying descriptive alternatives for CANDLE standard codes, removing fields not needed or re-arranging their appearance on the screen so that I can better organize information for users.
CC04 As an Integration Developer, I want to modify fields on a message input form such as changing the required setting on a field or setting conditional logic for a form and/or fields so that I can configure the solution as needed.
23 UX/UI Configuration & Customization: User Customizations 23 UX/UI Configuration & Customization: User Customizations 23 UX/UI Configuration & Customization: User Customizations 23 UX/UI Configuration & Customization: User Customizations
CC05 As a user, I want to personalize my frequented forms by building a "quick-access" or "favorites" list (which will remain configured every time I log into the system, regardless of machine). I also want to rename my forms and list categories so that I can easily and quickly find the forms that I need.
CC06 As a user, I want to share my preferences (such as favorited forms) with another user so that they can utilize my recommended and preferred settings.
CC07 As a user, I want to customize my layout so that I can make the solution fit my specific needs. (ex: incoming messages can be on top, left, or right of return screen)
CC08 As a user, I want multiple options to view and open forms including but not limited to: by dropdown list, by searching by form name (ex: VIN or NLETS standard names), by searching via command line/search field by actual data (ex: VIN Number) so that I can choose the form-finding option that works best for me.
CC09 As a user, I want to store my forms within a folder structure so that I can keep the forms I need organized.
CC10 As a user, I want to save and "lock" a query search so that if I accidentally click out of the screen, I don't lose my search-returned forms or data.
24 UX/UI Configuration & Customization: User Experience 24 UX/UI Configuration & Customization: User Experience 24 UX/UI Configuration & Customization: User Experience 24 UX/UI Configuration & Customization: User Experience
CC12 As a State Police Admin, I want quick and easy access to any forms that I need such as the VIN Assist/Decoder tool so that I can keep troopers safe and get them the information that they need immediately.
CC13 As a local law enforcement dispatcher, I want to support local first responders by performing administrative functions such as responding to phone calls, documenting reports, providing hit confirmations, monitoring incoming messages, running criminal history/background checks and fulfilling various requests so that I can keep responders safe.
CC14 As a State Police Dispatcher, I want to perform multiple searches at once so that I can investigate both multiple aspects of both a single trooper's inquiry, and/or multiple trooper's inquiries at one time.
CC15 As a State Police Dispatcher, I want to perform data queries within templated forms and custom-made forms, and by free query (utilizing keys in a command line to type in any data point needed) so that I have multiple options for getting the information that I need.
CC16 As a State Police Dispatcher, I want to utilize a VIN decoder or VIN assist tool so that vehicle data (such as make, model) will auto-populate when I enter the VIN and so that my time can be saved when identifying a vehicle.
CC17 As a State Police Dispatcher, I want every form and screen clearly labeled in plain text English so that I don't need to memorize, for example, DMV or National codes to understand the form or fields.
CC18 As a State Police Dispatcher, I want to save drafts of my NCIC Entries as "universal templates" so that I can come back to them to utilize at a later date (in any free-text, and across all consoles/terminals/users within the PSAP). (ex: free text form on form "EPO" would populate pre-written prompts such as: "TEMP0RARY 0RDER ISSUED, C0NTACT 0RI F0R C0NDITI0NS / REMAINS IN EFFECT UNTIL THE C0URT DISMISSES THE CASE, ISSUES A FINAL 0RDER OR DENIES A FINAL ORDER AFTER A HEARING / HEARING SCHEDULED FOR"
CC19 As a VT CCH team member, I want to see the court and docket number on every record within the system so that I can communicate with clarity when working with other agencies (ex: same charge on two separate dockets can get confusing).
CC20 As a VT CCH team member, I want to enter and view more than one DOB field so that I can enter and view all DOBs when performing a record check.
CC21 As a VT CCH team member or Fingerprint Section Supervisor, I want to remove/seal mugshot photos efficiently when a record has been indicated to be sealed or expunged (ex: when there is a non-conviction) so that I don't have to manually sort/toggle through all artifacts before finding the specific item I need to remove/seal.
CC22 As a VT CCH team member, when importing events (such as a parole violation) that are on multiple dockets (or other files), I want to enter the event code on all corresponding dockets (or other files) at the same time so that I do not need to duplicate (or worse) manual entry.
CC23 As a user, I want an un-do button so that I can remove actions that I have taken by mistake (ex: accidentally closing a window or deleting a message).
ID # Mapped NFR Title Non-Functional Requirement Description Comply Vendor's Description of Compliance
H1 Hosting/Infrastructure Any technical solution must be hosted in a data center.
H2 Reliability/DR Any hosting provider must provide for back-up and disaster recovery models and plans as needed for the solution.
H3 Operations/Service Management Any hosting provider will abide by ITIL best practices for change requests, incident management, problem management and service desk.
GR-00073 Operations/Infrastructure Management As a State technical operations lead, I want the Contractor to manage hosting, environments, and infrastructure performance so that systems operate reliably and meet service level agreements.
GR-00074 Infrastructure Management The Contractor must implement, host (or arrange for third-party hosting), operate, maintain, and manage all infrastructure, including all hardware, software, middleware, and licenses necessary for successful operation of all systems and services under the Contract.
GR-00075 Service Reliability/ SLA Management The Contractor must be solely responsible for the endtoend oversight and management of all environments during implementation and transition, such that performance metrics and service level agreements are met.
GR-00076 Network/Connectivity The Contractor must retain the responsibility and costs for providing network connectivity and access to all systems and data under their scope to all Stateauthorized stakeholders.
GR-00077 Operations/Maintenance The Contractor must retain all responsibility and costs for all software, hardware, and infrastructure Maintenance and Operations necessary to fulfill their obligations of this Contract.
GR-00078 Asset Management The Contractor must collaborate with the State to provide, as a subsidiary plan to the Business Design/System Design Document, an Asset Management Plan that describes the process the Contractor must use to manage applicable technology assets for the duration of the Contract within a multi-Contractor, integrated system-wide enterprise solution. This plan must include: (a) Hardware/software inventory (including location) (b) Procurement information (c) Contract information (d) License management.
GR-00079 Performance Efficiency The Contractor must provide the base infrastructure and optimization of all systems under the scope of this Contract to meet required application-specific uptime/response time requirements related to performance requirements, deliverable due dates, and Service Level Agreements.
GR-00080 Performance Monitoring The Contractor must provide reporting of all infrastructure optimizations annually, or after any major system change, to meet or exceed performance requirements or as requested by the State.
GR-00081 Performance Management The Contractor must document and maintain Stateapproved applicationspecific response time requirements, measurements, and reporting.
GR-00082 Capacity Management/Scalability The Contractor must continuously monitor, track, and report monthly to the State infrastructure space and storage trends over the term of the Contract.
GR-00083 Change Management The Contractor must notify the State and present the upgrade/replacement plan within 20 business days of awareness of a software or infrastructure upgrade notice received from a software/infrastructure contractor, unless the change is categorized as an Emergency Upgrade, in which case notification must be given five days prior to the upgrade date.
GR-00084 Change/Release Management The Contractor must implement each approved upgrade/replacement plan for all software and infrastructure upgrades in accordance with a Stateapproved schedule.
GR-00085 Access Management/Infrastructure The Contractor must provide the tools and infrastructure to support required access to all systems and data under their scope to all Stateauthorized stakeholders.
ID # Mapped NFR Title Non-Functional Requirement Description Comply Vendor's Description of Compliance
A1 Reliability/Disaster Recovery Any solutions vendor must provide for the backup/recover, data retention and disaster recovery of a contracted/hosted application solution.
A2 Maintainability/Environment Management Any solutions vendor must provide for application management and design standard of all technology platforms and environments for the application solution (Development, Staging, Productions, DR, etc.)
A3 Service Level Management Any solutions vendor must engage the State of Vermont using Service Level Agreements for system and application performance, incident reporting and maintenance.
A4 Data Governance/Data Ownership The State owns any data they enter, migrate, or transmit into the solution and the vendor shall allow the State to pull or copy this data at any time free of charge.
A5 Data Management/Metadata Management As a contract deliverable, the vendor shall supply an up-to-date data dictionary that represents all data respective of the solution it will provide. The data dictionary must contain the following attributes: The technology (RDBMS platform) that hosts the data source, i.e. Oracle, SQL Server, MySQL, DB2, etc. The location where the data source is hosted Thorough descriptions of each table in the data source Thorough descriptions of each column within each table in the data source. In addition to business definitions, column descriptions must include the following detail: schema names; file group names (if applicable); data types; lengths; primary and foreign key constrains; applied formatting; applied calculations; applied aggregations; NULL-ability; default values.
ID # Mapped NFR Title Non-Functional Requirements Description Comply Vendor's Description of Compliance
001 Security Hosting service provider personnel will use SOV internal network to connect to servers at the State of Vermont's (SOV's) data center. SOV is responsible for access control into its data center.
002 Agility The solution must provide clear and accurate documentation and guidance for the customers and users on how to use the service effectively and efficiently.
003 Compatibility Solutions will have a mechanism to share specific data, e.g., limited data sets, detailed data at the level of the individual, but with the data anonymous and completely de-identified in a controllable fashion with other State of Vermont (SOV) and local agencies.
004 Security Least Privilege and Separation of Duties (SOD) principles will be applied to all solutions, ensuring user permissions and system functionality align with specific roles based on access needs.
005 Security Solution administrators can create, manage, and assign user accounts with role-based access, including user groups, locations, and organizational hierarchy.
006 Transferability Integration security needs such as encryption at message and transport layer, should be defined and built per business needs and standards defined by the Vermont Agency of Digital Services Security Office.
007 Usability Solutions will enable central workflow alerts and transactional status. Solutions will centralize pending work items for the user as in a work queue.
008 Security Contractor shall make the application session length configurable and set in accordance with agency requirements.
009 Usability The solution should support table-driven variables instead of hardcoded values, enabling users with appropriate role-based permissions to add, delete, update, or view values and rows. The system must be able to immediately access these values based on the effective date ranges of the modified or added records.
010 Performance Efficiency The solution must scale up or down automatically based on the demand and traffic patterns.
011 Security Authentication of external users will be handled with a SAML or OIDC connection with the State's tenants in DEV, TEST and PROD environments. Internal users shall be authenticated with a SAML or OIDC connection to Entra. The State's preference is to have separate URLs for internal and external authentication. If the application can only facilitate a single auth provider but requires access for both internal and external users, Okta shall be established as the auth provider and will route internal users to Entra. If app functionality depends on internal or external status, the application must have a means to discern such states from OIDC claims, SAML attributes or other reliable method approved by the State.
012 Maintainability Develop profiles and permission sets to account for users accessing multiple apps.
013 Maintainability Provides out-of-the-box, pre-built visual components to easily create apps through a declarative drag and drop framework
014 Maintainability Solutions Provider will assist the State in preparing the detailed infrastructure requirements.
015 Maintainability Provide access to event log files to track system usage trends and user behavior such as who is logging in and from where, what pages users are viewing, and what reports users are running and exporting.
016 Security Network controls will protect and control SOV data during transmission, ensuring all connected devices comply with security standards and policies.
017 Maintainability The system will provide auditing and internal capabilities to generate audit logs.
018 Maintainability The solution must support monitoring and logging of system events and errors to facilitate root cause analysis and troubleshooting. so SOV admins can make configuration changes when needed
019 Maintainability The solution architecture will allow for transaction tracking and review throughout the system for auditing, error diagnosis, and performance management purposes.
020 Security Audit records will be protected from modifications and require approval for any changes.
021 Maintainability Develop profiles and permission sets to account for users accessing multiple app
022 Compatibility Solutions will have the ability to support varying message payloads, ranging from individual transactions to large files (more than 1GB) containing multiple transactions. The SOA solution will be configured to appropriately manage these varying types of message construction and size through a common set of components. Where possible, solutions will error on the side of individual transactions per message to simplify the message management, routing, and database recovery needs.
023 Compatibility Provide standard and custom configurable reports and dashboards in real time to analyze quality, effectiveness, satisfaction, issues, and overall performance. Reports and Dashboards can roll up from individuals to full management hierarchy, with drill-down capability.
024 Compatibility Database data exports will contain all data from the State of Vermont (SOV)'s production database(s) or the subset of data specified in the data export request.
025 Transferability The ability to easily transfer data from one system to another without being required to re-enter data
026 Compatibility The solution must enable the sharing of particular data with other SOV and local agencies while ensuring the anonymity and complete de-identification of the data. The data must be shared in a controlled manner to ensure that only authorized personnel have access to it. The solution must enable the sharing of particular data with other SOV and local agencies while ensuring the anonymity and complete de-identification of the data. The data must be shared in a controlled manner to ensure that only authorized personnel have access to it.
027 Compatibility The solution database will have data replication capabilities to external file formats or other RDBM Systems.
028 Compatibility The solution database will provide standard data extraction API to allow import and export of data.
029 Maintainability Solutions will include a workflow tool to support the records management process.
030 Maintainability Custom fields, create new fields that are immediately searchable and reportable in the application.
031 Usability Solutions will provide support for full text search.
032 Maintainability Ability to track open activities and activity history, from the portal
033 Compatibility Solutions will support authoring and management of solution data. Solutions will provide a flexible and comprehensive workflow-based capability that can be used to create and maintain workflows supporting solution data maintenance across the multiple source solutions.
034 Transferability Solutions will have a defined data migration strategy or process.
035 Compatibility Solutions will provide the ability for on-line access by any site connected to the State of Vermont's Network.
036 Compatibility The solution will provide standard data extraction API to allow import and export of data at rest
037 Maintainability Solutions Provider will perform Refreshes based on a submitted and approved change request from the State.
038 Security Use of digital signatures or secure mechanisms to authenticate senders of messages or transactions.
039 Maintainability Duplicate Management: The solution must provide a duplicate management capability to help maintain clean and accurate data.
040 Usability Solutions will roll-up (summarize data) and drill-down (view details) in reports online.
041 Compatibility The software shall support easy data migration from the current version to future versions of the software, ensuring that users can upgrade without losing any important data or functionality
042 Security Solutions will maintain records of all data additions, changes, and deletions, searchable by user/client ID, date/time, location, and other details.
043 Maintainability Provide ability to track the changes that users make to field values in the system.
044 Maintainability The Solution must be documented with clear and concise comments, diagrams, and user manuals that explain the functionality, architecture, and dependencies of each component.
045 Usability The Solution should be able to generate the plain text nesting of rules automatically, using a clear and readable format that can be easily understood by both technical and non-technical users. The plain text nesting should also be able to display the hierarchy of rules and the conditions under which they are applied, providing a comprehensive view of the rule set. This capability will support effective rule management and maintenance, ensuring that the system can continue to enforce business rules effectively over time.
046 Compatibility Solutions will support the industry standards for messaging, receiving and sharing data and interfaces relevant to health and human services organizations including, but not limited to: FHIR Version 4.0 and Electronic Data Interchange (EDI) X12 healthcare format. The versioning for these products must be maintained to meet the evolving requirements of the State of Vermont 's (SOV's) CMS and ONC and any other bodies that dictate these standards.
047 Agility The solution must learn from the feedback and data collected from the customers and users by analyzing, interpreting, reporting, etc. them.
048 Performance Efficiency The solution must have a user interface with a clear and consistent navigation and layout that is easy for users to understand and use. The navigation and layout should be designed in a way that aligns with the user's expectations and mental model, meaning it should be intuitive and follow common design patterns.
049 Usability Solutions will support reporting requirements either natively or integrate with other reporting tools to provide reporting.
050 Performance Efficiency Solutions will provide the ability to optimize individual queries and support parallelizing a query to run on multiple CPUs at the same time to increase performance
051 Agility The solution must monitor and measure the usage, performance, quality, and satisfaction of the service using analytics and feedback mechanisms.
052 Maintainability Must have flexible customer portal user access and identity management
053 Security The hosting service provider will manage access control to its data centers and the environment, limiting access to State of Vermont's (SOV's) network connections.
054 Usability Solutions will provide the ability to store electronic forms (solution generated or 3rd-party generated forms).
055 Compatibility Solution will integrate with the State of Vermont Master Person Index (MPI) using the State's Integration Platform and adhere to the State rules for MPI determinations and processing. MPI covers all customer, provider and other human references.
056 Security Access provisioning is centralized and based on job roles, requiring management approval.
057 Maintainability For document management functions, Solutions will use a centralized, shared document management/content management solution.
058 Security All Hosting Service Provider personnel will use a software VPN client to connect to the HPISN. Upon initiating a VPN session, employees will authenticate with a username and password. Once authenticated, each employee will be assigned a static IP address specific to that VPN concentrator. This method reduces security risks like IP spoofing, as the client software enforces the assigned IP based on user identity rather than device MAC address.
059 Reliability Solution provider will monitor critical performance parameters: these can included: CPU usage: the percentage of CPU resources consumed by the software. High CPU usage can affect the responsiveness and speed of the solution. Memory usage: the amount of memory allocated by the software. High memory usage can indicate high resource consumption and affect the performance of the solution Requests per minute and bytes per request: the number of requests received by the software's API per minute and the amount of data handled by each request. Latency and uptime: the delay between a user's action on the software and the response of the software to that action, and the availability of the software to serve requests. Security exposure: the degree to which the software is vulnerable to unauthorized access, modification, or damage. Execution time: the time taken by the software to complete a certain function or task. Throughput: the rate at which the software can process data or transactions.
060 Security Contractor shall ensure that all logout triggers, which are to be provided to all authenticated external users, are effective at terminating both the app session and the Okta SSO session.
061 Compatibility If necessary and required for the solution, electronic data exchange refers to the standardized, machine-readable exchange of data between systems or applied Electronic data exchange refers to the standardized, machine-readable exchange of data between systems or applications. Standards for electronic data exchange vary by industry, with examples including HL7 and FHIR for healthcare, and SWIFT and FIX for finance.
062 Agility The solution must support multiple languages, currencies, time zones, and regional settings for different markets and users.
063 Maintainability Solutions Provider will leverage State of Vermont's Enterprise Data/Object Model to facilitate standardized reporting, ad hoc queries, list views and dashboards.
064 Compatibility If necessary and required for the solution, electronic data exchange refers to the standardized, machine-readable exchange of data between systems or applications. Electronic data exchange refers to the standardized, machine-readable exchange of data between systems or applications. Standards for electronic data exchange vary by industry, with examples including HL7 and FHIR for healthcare, and SWIFT and FIX for finance.
065 Compatibility Solutions will include the following types of transformation: Simple transformations, e.g., data-type conversions, string manipulations and simple calculations. Moderate-complexity transformations, e.g., lookup and replace operations, aggregations, summarizations, deterministic matching and management of slowly changing dimensions. Higher-order transformations, e.g., sophisticated parsing operations on free-form text and rich media. Facilities for developing custom transformations and extending packaged transformations.
066 Usability Solutions will permit all users (dependent on role-based security and access rights) to have current and up-to-date information regarding a client's information when connected to solutions, given the operational and technical constraints of the data source(s). The data displayed will be time-stamped to reflect the currency of the data.
067 Compatibility Solution will define the requirement for all software to support data integration with other systems
068 Maintainability Applications shall be meta-data driven and allow for common meta-data use across differing lines of business and different instance/orgs.
069 Maintainability Solutions Providers will provide version control management capability. All changes to Solutions will be reported and approved by the State, and will be maintained in the Solutions Provider's version control management solution, which will be available to the State for review and audit.
070 Maintainability Solutions Providers will provide the required system permissions, documentation and training that describes the procedures for Solution administrators to add, update or inactivate user IDs and passwords.
071 Usability Service Providers will develop a user guide that can be accessed online and printed on demand.
072 Maintainability The solution must support automated testing, with clear and well-defined test cases and test data.
073 Transferability Vendor will work in a Development and Test environment prior to promoting the code to production
074 Security The hosting provider will evaluate and respond to incidents of unauthorized access or handling of SOV data, working with relevant teams and law enforcement to restore confidentiality, integrity, and availability of SOV's environment.
075 Usability The solution will support dynamic rule change, enabling users to modify rules on the fly without requiring system downtime. The solution should also separate rules from the engine, making it easier to update rules without affecting the underlying engine.
076 Transferability The system may adapt its user interface according to the user's preferred language and locale
077 Usability Solutions will enable indexing and searching of documents.
078 Reliability For PaaS and IaaS solution providers, backup and Recovery Services will include operating system images, configuration files, database, code tree, hardware configurations and virtualization configurations. (PaaS, IaaS)
079 Maintainability The solution must support version control and rollback capabilities to facilitate quick and easy reversions in case of errors or issues with new updates.
080 Security When user requests to log in, or requests an authenticated page, they shall be redirected to the State's central login widget (currently at my.vermont.gov) in order to ensure that the user is challenged with state approved authenticators in a state approved user experience.
081 Transferability Solutions will support access from multiple channels and devices.
082 Usability Mobile Applications shall support offline capabilities, limited to essential business process for field work. i.e. fillable form fields which sync-up with cloud platform when device is back online.
083 Maintainability Applications shall support configurable field level security controls
084 Usability Solutions will provide the capability to allow the user to manually remove, rescan and replace a previously scanned image or document(s).
085 Maintainability Solutions Provider will use DNS instead of host files.
086 Compatibility The solution provider will meet requirements as identified in the corresponding HL7 FHIR Implementation Guides (IG) for Blue Button, PDEX and others as apropos and these Blue Button IGs will be considered the standards needed for 3rd parties to access the data.
087 Accessibility The State of Vermont (SOV) will access applications through a URL entered in a web browser.
088 Accessibility If a survey engine is required for the solution, the survey engine must provide robust configuration options to create, distribute, and analyze surveys effectively.
089 Accessibility Solutions will provide support for a web content management solution that is robust, scalable, and provides workflow management.
090 Accessibility The solution should be designed to provide secure, scalable, accessible storage and retrieval of policy and procedure content, allowing users to quickly find and access information, with robust search capabilities, version control, and collaboration among multiple stakeholders.
091 Accessibility Information will be provided to applicants and enrollees in plain language, consistent with Section 504 and Section 508 of the Rehabilitation Act, including accessible web sites and the provision of auxiliary aids and services at no cost to individuals with disabilities, and language access services for individuals with limited English proficiency such as interpretation, translations, and non-English taglines indicating the availability of language services.
092 Accessibility Solutions will provide speech and hearing impaired persons with the ability to communicate using a Teletypewriter (TTY) or Telecommunications Display Device (TDD), as applicable to the solution's communication channels.
Accessibility The solution shall conform to applicable digital accessibility standards, including at minimum WCAG 2.1 Level AA for all web and mobile user interfaces, Section 508 requirements for electronic and information technology, and any applicable provisions of the DOJ Web and Mobile App Accessibility Final Rules for public services.The system shall accommodate a wide range of assistive technologies and shall be tested to ensure compliance with accessibility guidelines.
093 Accessibility Accessibility requirements shall apply to all user facing components of the solution, including portals, mobile applications, administrative interfaces used by staff, generated documents, forms, and embedded widgets or third party components that affect the user experience.
094 Accessibility The contractor shall provide a current Accessibility Conformance Report, using the appropriate VPAT template, for each product or major module with a user interface prior to contract award or prior to solution going live, and shall provide an updated report within 14 business days of any major release that affects the user interface.
095 Accessibility The contractor shall document all known accessibility limitations of the solution, their impact on users with disabilities, and planned remediation timelines, and shall provide this documentation with the Accessibility Conformance Report and upon request by the State.
096 Accessibility The solution shall support effective use with common assistive technologies on supported platforms and browsers, including screen readers, screen magnifiers, and speech input tools, without loss of functionality compared to non assisted use.
097 Accessibility All interactive elements in the solution shall be fully usable with keyboard only input, with visible focus indicators and a logical tab order, and the solution shall expose a meaningful semantic structure, including headings, landmarks, labels, and status messages, to allow efficient navigation by users of assistive technologies.
098 Accessibility The contractor shall conduct accessibility testing using automated tools, manual expert review, and assistive technologies, and shall provide test plans and results to the State. The contractor shall review the accessibility testing results to determine severity of issues.
099 Accessibility No release shall be promoted to production until critical and high severity accessibility defects identified by the State have been remediated or are covered by an approved exception and interim alternate access method.
100 Accessibility For solutions identified by the State as high impact, usability and accessibility testing shall include participation by users with disabilities and assistive technologies, and findings from this testing shall be documented and incorporated into design and implementation decisions.
101 Accessibility Accessibility defects shall be classified and remediated according to provisions in the agreed service levels such as the minimum as follows: critical defects that block users with disabilities from completing primary tasks shall be mitigated within five (5) business days and fully remediated within thirty (30) calendar days; high severity defects that significantly degrade usability shall be mitigated within ten (10) business days and fully remediated within sixty (60) calendar days.
102 Accessibility The contractor shall participate in periodic accessibility reviews with the State at least annually and after any major release affecting the user interface, and shall provide updated accessibility test results and Accessibility Conformance Reports as part of these reviews.
103 Accessibility The contractor shall designate an accessibility lead responsible for coordinating accessibility activities and responding to State inquiries, and shall ensure that personnel involved in design, development, testing, and support receive role appropriate training on digital accessibility standards and assistive technologies.
104 Accessibility The solution and associated support processes shall provide a clearly identified mechanism for users to report accessibility issues and request accommodations, and such reports shall be captured, tracked, and remediated within the same service levels that apply to other critical defects.
105 Security Any user/station limitations will be equally and universally imposed by the solution. Examples include passwords changed via downstream CAD/Integration will meet the same password complexity requirements. Limitations surrounding which stations a user can logon to will be enforced regardless of station classification or access method.
106 Security The solution will configure the system to allow users to log in with a Single Sign On (SSO) experience using a federated Identity Provider. The system should support SSO via SAML and support AD FS as an Identity Provider.
107 Security The solution shall require users to use multifactor authentication to log in order to meet CJIS Security Policy requirements. ADS IT should be able to help users configure MFA and revoke lost MFA devices without needing vendor support.
108 Accessibility The solution shall be able to unlock accounts and reset passwords for users in agencies I support as a TAC so that I can get my staff back online quickly when they have a password/account issue
109 Usability The contractor shall designate an accessibility lead responsible for coordinating accessibility activities and responding to State inquiries, and shall ensure that personnel involved in design, development, testing, and support receive role appropriate training on digital accessibility standards and assistive technologies.
110 Usability The solution and associated support processes shall provide a clearly identified mechanism for users to report accessibility issues and request accommodations, and such reports shall be captured, tracked, and remediated within the same service levels that apply to other critical defects.
111 Usability Facilitate development of a governance model for the solution, recognizing the breadth of user groups and decentralized decision-making hierarchy.
112 Compatibility Facilitate development of templates for data sharing agreements across the user community and across vendors currently, and in the future, in the technical ecosystem that interacts with the solution.
113 Maintainability Facilitate Business Architecture re-design for future use of the solution, optimizing processes for efficiency and data integrity. Document processes in the form of job aids and on-boarding materials for new employees.
114 Usability Following PROSCi's ADKAR model, facilitate solution adoption by generating awareness, interest and engagement, process and solution training, and support during go-live and during the hypercare period.
ID # Non-Functional Requirement Description Comply Vendor's Description of Applicable Security Processes Audit/Monitor Process
S1 Input validation
S2 Output encoding
S3 Authentication and password management
S4 Session management
S5 Access control
S6 Cryptographic practices
S7 Error handling and logging
S8 Data protection from unauthorized use, modification, disclosure or destruction (accidental or intentional).
S9 Communication security
S10 System configuration
S11 Database security
S12 File management
S13 Memory management
S14 Fraud detection
S15 General coding practices
S16 POA&M management
S17 Risk Assessment Practices including but not limited to vulnerability assessment and pen testing
S18 Incident response planning and testing
S19 System Security Plan delivery
S20 As a State security and privacy lead I want compliant security controls, assessments, and protected environments so that systems meet Federal and State privacy, audit, and cybersecurity standards.
S21 The Contractor must develop and keep current a State-approved System Security Plan.
S22 The Contractor must meet the applicable State and Federal privacy and security standards in the hosting and support of all infrastructure.
S23 The Contractor must provide secure access as applicable and appropriate to the development and test environments to a subset of authorized users. Authorization must be by each environment and conform to the security protocols used by the State.
S24 The Contractor must ensure development and test environments have sufficient security controls in place to prevent unauthorized access.
S25 The Contractor must ensure that test environments, aligned with State standards and approval, mask critical and sensitive data as required for distribution. This includes data classified as Protected Health Information (PHI) and Personally Identifiable Information (PII).
S26 The Contractor must ensure that test environments must adhere to the same level of security compliance for such data as required in a production environment, unless authorized otherwise in writing by the State.
S27 The Contractor must provide appropriate system access and/or a walk-through of any Contractor facilities and operations as directed by the State to facilitate external and internal audits.
S28 The Contractor must, throughout all phases of this Contract, adhere to 42 CFR 434.6(a)(5), which allows evaluation by Federal Partners through inspection or other means, of the quality, appropriateness, and timeliness of services performed under this Contract.
S29 The Contractor must provide an independent, third-party security and privacy controls assessment report that covers compliance with NIST SP 800-171 and/or NIST SP 800-53 standards and all relevant controls in the Health Insurance Portability and Accountability Act (HIPAA); aligning Health Care Industry Security Approaches pursuant to Cybersecurity Act of 2015, Section 405(d); and the Open Web Application Security Project Top 10.
ID # Non-Functional Requirement Description Comply Vendor's Description of Compliance
TESTING AND QUALITY MANAGEMENT
GR-0008 As a State quality lead, I want quality and testing activities managed under approved standards and plans so that the system meets performance, compliance, and operational expectations.
GR-00094 The Contractor must develop and keep current a State-approved Quality Management Plan that is consistent with ISO 9001:2015, Quality Management System (QMS), Total Quality Management (TQM), SSAE18 SOC 2 Type 2, and Continuous Quality Improvement principles and standards.
GR-00095 The Contractor must collaborate with the State and all State-identified Contractors/partners to achieve and maintain quality system and operational services in accordance with Stateapproved performance metrics and benchmarks.
GR-00096 The Contractor must implement Stateapproved performance improvements, in a method and manner that is consistent with ISO, QMS, TQM, SSAE16, and Continuous Quality Improvement principles and standards.
GR-00097 The Contractor must lead, coordinate, and be responsible for all project quality assurance management, documentation quality assurance, and quality assurance testing meetings as requested and required under the Quality Management Plan and/or by the State.
GR-00098 The Contractor must assign a dedicated resource to lead the quality assurance staff during the design, development, and implementation phases. This resource will ensure that process improvements are executed in alignment with Lean Six Sigma principles or other standards such as ISO, QMS, TQM, SSAE16, and Continuous Quality Improvement.
GR-00099 The Contractor must provide adequate and dedicated staff to implement, monitor, and address all quality assurance and improvement activities required under the Quality Management Plan.
GR-00100 The Contractor must take a proactive role in identifying and addressing quality control issues within the solution in the effort to meet or exceed performance benchmarks/metrics for the State.
GR-00101 The Contractor must develop and keep current a State-approved Test Management Plan.
GR-00102 The Contractor must collaborate with other project Contractors to ensure the Test Management Plan establishes test frameworks and test objectives, supporting all Contractors and partners involved in the solution.
GR-00103 The Test Management Plan must comply with ISO/IEC/IEEE 29119-3:2021 standards.
GR-00104 The solution must enable State-approved users to load data into development, testing, training, and other non-production environments.
GR-00105 The Contractor must provide secure access as applicable and appropriate to the development and test environments to a subset of authorized users.
GR-00106 The Contractor must ensure development and test environments enable access to appropriate devices and resources required to connect to the State environment.
GR-00107 The Contractor must implement a User Acceptance Test (UAT) environment so there is a dedicated environment for user acceptance testing activities.
GR-00108 The solution must adhere to established and mutually agreed-upon standards, procedures, and protocols for data loading into non-production environments.
GR-00109 The Contractor must develop, for each system change, a State-approved suite of test cases that includes the test scope, approach, and tools, and is used to complete testing and provide the documented test results to the State.
GR-00110 The Contractor must provide resources to assist, complete, and submit results, in a State-approved format, of all comprehensive system(s) tests as documented in the State-approved Test Management Plan.
GR-00111 The Contractor must provide sufficient time and resources for all testing performed by the Contractor, and to support testing done by entities other than the Contractor.
GR-00112 The Contractor must ensure that all draft deliverables meet the State's minimum expectations for grammar, spelling, formatting, and overall quality, with revisions made at no additional cost and without impacting the project schedule.
TRAINING & SUPPORT
GR-0009 As a user support administrator, I want training, user guides, and help desk services delivered using State standard so that users are supported and enabled throughout system adoption.
GR-00113 The Contractor must develop and keep current a State-approved User Training Plan.
GR-00114 The Contractor must develop and keep current a searchable, web-based, interactive, State-approved User Guide. The User Guide should have smart documentation (linked issues, typeahead, suggestions based on problem statements, workflow documentation).
GR-00115 The User Guide must be used as part of the basis for user training, unless otherwise specified by the State.
GR-00116 The Contractor must develop and keep current training materials in compliance with Americans with Disabilities Act of 1990 (ADA) standards. Any identified changes to training materials to comply with this requirement must be addressed at no cost to the State.
GR-00117 The Contractor must provide training to the State, its agents, and Successor Contractor(s).
GR-00118 The Contractor must develop and keep current a State-approved Help Desk Plan.
GR-00119 The Contractor must maintain a State-approved help desk support function that enables users to submit requests through a web portal during State business days, 7 a.m. ET to 7 p.m. ET.
GR-00120 The Contractor must maintain a State-approved help desk support function that enables users to submit requests by phone during State business days, 7 a.m. ET to 7 p.m. ET.
GR-00121 The Contractor must provide technical assistance as needed to assist users in researching problems, reviewing production outputs, and understanding report formats.
GENERAL TRANSITION REQUIREMENTS
GR-EPIC-01 As a State program executive and governance lead, I want the Contractor to establish, maintain, and operate comprehensive administrative, technical, and operational management frameworks across all project disciplines-including project management, staffing, financial management, communications, documentation, technical design, infrastructure, security, quality assurance, training, operations, business continuity, and transition activities-in full alignment with State-approved standards, tools, plans, and governance processes, so that the solution is delivered and sustained with consistent quality, accountability, transparency, security, and compliance throughout all phases of the contract lifecycle, while minimizing risk and ensuring seamless coordination across all stakeholders and technical components.
GR-FEA-01 As a State project manager, I want the Contractor to plan, manage, and report project activities using State-approved tools and plans so that the project is executed consistently, collaboratively, and in alignment with State governance standards.
GR-00001 The Contractor must follow project management methodologies as directed by the State that are consistent with the Project Management Institute's (PMI) Project Management Body of Knowledge (PMBOK) Guide v7 and Agile project management.
GR-00002 The Contractor must use the State-managed SharePoint Online Project Management Repository in accordance with State standards and expectations.
GR-00003 The Contractor must complete the activities specified in the Enterprise Project Management Office (EPMO) Project Lifecycle as published on the EPMO public-facing website.
GR-00004 The Contractor must provide, on a weekly basis, a current project schedule in Microsoft Project format (v2013 or later).
GR-00005 The Contractor must maintain a decision log, risk log, and issue log (in State-approved tools), updated at least weekly, with clear owners and due dates.
GR-00006 The Contractor must actively collaborate with all State-approved Contractors and Subcontractors, sharing information, designs, and schedules necessary to achieve an integrated solution.
GR-00007 The Contractor must participate in State-facilitated cross-vendor forums, and align to shared standards, environments, calendars, and schedules as directed by the State.
GR-00008 If an inter-vendor conflict cannot be resolved collaboratively within five business days, the Contractor must escalate the issue to the State no later than one business day thereafter.
GR-00009 The Contractor must review, provide feedback on, signoff, and conform to the project's State-authored Business Analysis Plan.
GR-00010 The Contractor must follow business analysis methodologies that are consistent with the International Institute for Business Analysis (IIBA) Guide to Business Analysis Body of Knowledge (BABOK) v3.
GR-00011 The Contractor must collaborate with the State to elicit user stories and requirements at sufficient detail to ensure the solution meets the needs of the State.
GR-00012 The Contractor must maintain and manage all requirements, user stories, and business rules in the State's Azure DevOps (ADO) tenant per the direction of the State.
GR-00013 The Contractor must develop and keep current a State-approved Risk Management Plan.
GR-00014 The Contractor must develop and keep current a State-approved Implementation Plan that outlines the approach for the design, development, and implementation of all technology and services in accordance with the solution scope.
GR-00015 The Contractor must, upon Contract execution, participate in the project Steering Committee, which will govern and steer the project.
GR-00016 The Contractor must review, provide feedback on, signoff, and conform to the project's State-authored Change Management Plan.
GR-00017 The Contractor must collaborate with all State-approved Contractors and Subcontractors under the direction of the State Change Control Board to manage change within a multi-Contractor, integrated systems solution as it relates to any system- or non-system-based changes, modifications, or maintenance activities, efforts, tasks, or projects
GR-00018 The Contractor must identify the impact of data source changes to all solution components and capabilities, so that the changes may be verified to be in accordance with the approved Change Management Plan.
GR-00019 The Contractor must monitor and inform the State of industry changes that may have an impact on business processes or on systems covered by the Contract, so that the State can prepare for and implement any necessary updates and stay aligned with industry changes and best practices.
GR-00020 The Contractor must review, provide feedback on, signoff, and conform to the project's State-authored Scope Management Plan.
GR-00021 The Contractor must develop a State-approved Project Kickoff Deck.
GR-00022 The Contractor must review, provide feedback on, signoff, and conform to the project's State-authored Schedule Management Plan.
GR-00023 The Contractor must review, provide feedback on, signoff, and conform to the project's State-authored Deliverables Matrix.
Human Resources & Staffing Management
FEA-GF-02 As a State contract manager I want visibility and oversight of Contractor staffing and personnel so that the project maintains qualified, available, and accountable resources.
GR-00024 The Contractor must keep current, on the State's SharePoint site, a Personnel Table of all Contractor staff and Subcontractor staff associated with the project. The Personnel Table must provide: (a) Full name (b) Business phone number (c) Business email address (d) Project role (e) Project responsibilities.
GR-00025 The Contractor must develop and keep current a State-approved Organizational Chart of all Contractor and Subcontractor personnel working on the project.
GR-00026 The Contractor must provide the State with resumes for Contractor and Subcontractor staff working on the project.
GR-00027 The Contractor must ensure vacant positions supporting this Contract are filled within 60 calendar days of date of vacancy or obtain written approval by the State for extended vacancies.
GR-00028 The Contractor must provide the State 20 business days or more advance notice of any plans to change, hire, or reassign personnel supporting this Contract.
GR-00029 The Contractor must notify the State within one business day of the replacement, reassignment, resignation, or termination of any personnel directly supporting this Contract.
GR-00030 The Contractor must replace or reassign personnel supporting this Contract for cause (i.e., where the State can demonstrate a reason) at the State's request. The State shall report to Contractor any concerns regarding Contractor Personnel that may lead the State to make such a request with sufficient detail and time for Contractor to take corrective measures.
GR-00031 The Contractor must conduct an initial criminal background check/investigation on all new hires supporting this Contract as well as conduct follow-up criminal investigations every two years, if requested, for all staff supporting this Contract. The costs for the initial criminal background check must be the responsibility of the Contractor.
GR-00032 The Contractor's staffing solution may include staff located both within the United States as well as outside the United States.
GR-00033 The Contractor must ensure that all licensed Contractor staff maintain current licensure required for their role on the project, with no State or Federal sanctions.
GR-00034 The Contractor must cross train its staff to prevent loss of knowledge and expertise when staff leave, as well as to minimize negative impacts to project timelines due to resource availability.
GR-00035 The Contractor must keep current a State-approved process for immediate removal, with just cause or reason, physical and remote access to systems and facilities for Contractor or Subcontractor employees deemed unfit to continue employment.
GR-00036 The Contractor must develop and keep current a State-approved Resource Management Plan.
GR-00037 The Contractor must bear the costs of changes, hires, or reassignment of Contractor personnel.
GR-00038 The Contractor must develop and apply onboarding and training processes for new staff and turnover in staff.
Contract & Financial Management
FEA-GF-03 As a State financial administrator, I want Contractor invoicing, subcontractor oversight, and legal responses managed consistently so that financial compliance, accountability, and transparency are maintained.
GR-00039 The Contractor must develop and keep current a State-approved process for all invoicing activities.
GR-00040 The Contractor must correct and reissue invoices within 10 business days of State notification.
GR-00041 The Contractor must make all Subcontractor agreements available to the State upon request.
GR-00042 The Contractor must be responsible/accountable for all subcontracted work assigned, including responsibility for enforcement and oversight of subcontractors and their compliance with all State and Federal contractual terms/provisions as included within this Contract.
GR-00043 For any Subcontract, the Contractor must identify a designated Subcontractor contact who is accessible to the State.
GR-00044 The Contractor must provide, at no cost to the State, information and data as requested by the State to fulfill requests for litigation, subpoenas, open record requests, or other legal actions.
GR-00045 Upon State request, the Contractor must provide staff and resources to assist the State with preparing and reviewing materials planned to be shared at forum(s), such as national organizations and conferences, on efforts related to this Contract.
Communications and Document Management
FEA-GF-04 As a State project manager, I want project documentation and communications managed using State standards so that information is accurate, compliant, and accessible.
GR-00046 The Contractor must review, provide feedback on, signoff, and conform to the project's State-authored Communication Management Plan.
GR-00047 The Contractor must notify the State of all legislative, executive level, and media inquiries with respect to this project and forward any such inquiries to the State within one business day of the Contractor's awareness of said inquiry.
GR-00048 The Contractor must not respond to legislative, executive level, or media inquiries regarding the project unless directed by the State, except where required by law.
GR-00049 The Contractor must ensure all communications conform to State of Vermont brand standards as issued by the Chief Marketing Office.
GR-00050 The Contractor must ensure that the Contractor's own name, logo, or any reference to the Contractor are not included in any public-facing communications with respect to this project, unless approved by the State.
GR-00051 The Contractor must develop and keep current a State-approved Deliverables Management Plan.
GR-00052 The Contractor must update and maintain all Project Deliverables on a mutually agreed upon cadence as approved by the State.
GR-00053 The Contractor must prepare, update, revise, and submit to the State for approval all operational, systems, or reportingbased documentation (in all original forms/media) as they relate to system changes, maintenance, or modification work requests.
GR-00054 The Contractor must create and maintain all system and technical documentation for the solution.
GR-00055 System and technical documentation must utilize Stateapproved language, diagrams, and structure.
GR-00056 The Contractor must utilize the State-approved Project Management Repository as well as any other State-required document repository to maintain systemrelated business, technical, and operational documentation.
GR-00057 The Contractor must ensure all documentation is readily available online and electronically maintained, retained, archived, and restored as required by all document and data retention laws, including any applicable litigation hold.
GR-00058 The Contractor must ensure all documentation is prepared and accessible using current State standard/approved software packages.
GR-00059 All project documentation must be reviewed and approved by the State prior to publication.
GR-00060 The Contractor must provide new, routinely maintained, and updated documentation for all contracted functions in accordance with the Stateapproved documentation development, maintenance, and quality review process.
GR-00061 The Contractor must maintain a documentation standard that aligns with the standards and templates set forth by the State and other contracted Contractors and utilize the approved standard throughout the life of the Contract.
GR-00062 The Contractor must revise any required documentation deliverable if requested to do so by the State.
GR-00063 The Contractor must maintain complete and detailed records of all Contractor-facilitated meetings with the State related to the Contract, software development lifecycle documents, presentations, project artifacts, and any other interaction and post and maintain these artifacts in the Project Management Repository within five business days of the meeting or interaction.
GR-00064 The Contractor must secure State approval prior to any representation or presentation of documentation related to this project, including any local, State, national conferences, or other public or private forums.
TECHNICAL DESIGN & IMPLEMENTATION
FEA-GF-04 As a State enterprise architect I want system, interface, and data design documentation maintained and approved so that technical components are traceable, consistent, and support integrated operations.
GR-00065 The Contractor must develop and keep current a State-approved Business Design/System Design Document.
GR-00066 The Contractor must create and keep current documentation of all operational, system, and technical processes as they relate to the solution.
GR-00067 The Contractor must develop and keep current a State-approved Interface Control Document that documents all data elements, processes, methodologies, mechanisms, protocols, and other related information for each data source.
GR-00068 The Contractor must document and keep current all conceptual, logical, and physical models for all database service layers and supporting data stores and make the models available online to the State.
GR-00069 The Contractor must store all conceptual, logical, and physical models in a State-approved repository.
GR-00070 The Contractor must complete all conceptual, logical, and physical models to reflect the most current updates or changes based on approval by the State 10 business days prior to implementation of the planned change. Updates must be published to users at the time of implementation.
GR-00071 The Contractor must provide documentation that describes the contents, format, and structure of all databases and the relationships among all database objects.
GR-00072 All user interfaces must comply with the most recent version of Section 508 Standards and WCAG Level A and AA Success Criteria.
Operations and Maintenance Management
FEA-GF10 As a State operations manager, I want maintenance, defect management, release control, and performance monitoring so that system stability and operational continuity are sustained.
GR-00122 The Contractor must develop and keep current a State-approved System Maintenance Support Plan.
GR-00123 The Contractor must provide Maintenance Support activities during certification and transition to the maintenance and operations vendor(s). This includes making changes to existing functionality and features that are necessary to continue proper system and/or operational services.
GR-00124 The Contractor must perform and complete all work necessary to correct and resolve each defect identified in the solution.
GR-00125 The Contractor must utilize Microsoft Azure DevOps, the State-approved online Defect Management tool, for the identification, impact assessment, definition, traceability, verification, and reporting of all defects and resolutions.
GR-00126 The Contractor must conduct development walk-throughs as appropriate to demonstrate to the State that all functions have been completely and accurately planned, developed, and unit tested.
GR-00127 The Contractor must, in coordination with the State, maintain a comprehensive lessons-learned repository in the State's Azure DevOps tenant that is a knowledge base of all lessons learned.
GR-00128 The Contractor must detect, log, notify, and respond appropriately to errors and exceptions in both system and data processing.
GR-00129 The Contractor must collaborate with the source system Contractor to resolve bad or otherwise corrupt data in accordance with the data quality review process timelines.
GR-00130 The Contractor must maintain a data quality review process for the identification and resolution of corrupt or bad data.
GR-00131 The Contractor must develop and keep current a State-approved Release Management Plan.
GR-00132 The Contractor must have the ability to selectively move modifications on a release schedule with State approval, with the flexibility to selectively back out system changes prior to a release (last minute) without significant resources or impact (point in time restore).
GR-00133 The Contractor must implement improvements, changes, or enhancements following a State-approved approach that must enable all other environments to update and mirror the "new" production functionality.
GR-00134 The Contractor must provide, as part of the Release Management Plan, a Network Design and Monitoring Plan for an optimally performing computing and data transporting environment.
GR-00135 The Contractor must implement a configuration management process with established promotion and version control procedures for the implementation of a multi-Contractor, integrated system-wide enterprise.
GR-00136 The Contractor must maintain, as part of the Release Management Plan, change management metadata regarding all system application release and operational performance and behavior.
GR-00137 The Contractor must provide a quarterly Configuration Management Summary report providing a high-level overview of any changes to the system baseline configuration and operational usage.
GR-00138 The Contractor must document and maintain State-approved standard maintenance windows for system maintenance and downtime that are coordinated across solutions and minimize stakeholder disruption.
GR-00139 The Contractor must obtain State approval before initiating scheduled and emergency maintenance windows and system outages.
GR-00140 The Contractor must document all incidents in accordance with the State standard Incident Reporting Form template.
GR-00141 The Contractor must notify affected State stakeholders of scheduled and emergency maintenance windows and system outages.
GR-00142 The Contractor must develop and keep current a State-approved Performance Management Plan.
GR-00143 The Contractor must allow a State representative to participate in any Contractor-facilitated user group that is associated with any part of the solution.
GR-00144 The Contractor must develop and keep current a State-approved Operating Procedures Guide.
GR-00145 The solution must include exception handling mechanisms to facilitate error correction and/or auditing across all components of the solution without impacting concurrent, overall operations, as well as reporting of exceptions to the State.
GR-00146 The Contractor must transcribe the lessons-learned repository to a lessons-learned report within 60 business days after the project is completed.
Business Continuity and Disaster Recovery
FEA-GF11 As a State continuity and risk program owner I want reliable BC/DR/CIR planning, exercises, and recovery capabilities so that critical operations can resume during incidents or outages.
GR-00147 The Contractor must develop and keep current a State-approved Business Continuity, Cyber Incident Response, and Disaster Recovery (BC/DR/CIR) Plan.
GR-00148 The Contractor must ensure the Business Continuity/Disaster Recovery/Cyber Incident Response Plan: (a) provides a framework for reconstructing vital operations to ensure the safety of employees (b) provides for the resumption of time sensitive operations and services in the event of an emergency (c) provides for initial and ongoing notification procedures (d) complies with all NIST CP-2, NIST 800-61, and IR-8, NIST-800-53 standards (e) complies with the latest version of ARC-AMPE standards.
GR-00149 The Contractor must ensure the Business Continuity/Disaster Recovery/Cyber Incident Response Plan's operational and system functions, including systems and operations under the scope of Subcontractors, adhere to Health Insurance Portability and Accountability Act and National Institute of Standards and Technology standards.
GR-00150 The Contractor must provide an up-to-date copy of the Business Continuity/Disaster Recovery/Cyber Incident Response Plan in a secure, highly accessible, centralized online location and at an offsite location approved by the State.
GR-00151 The Contractor must submit the Business Continuity, Cyber Incident Response, and Disaster Recovery Plan annually or more frequently as directed by the State, such as after a major system change that materially affects the plan.
GR-00152 The Contractor must perform annual Business Continuity, Disaster Recovery, and Cyber Incident Response exercises, including pre-go-live activities.
GR-00153 Business Continuity (BC), Disaster Recovery (DR), and Cyber Incident Response (CIR) exercises must include activities selected from the BC/DR/CIR Plans to verify the viability of each plan in accordance with NIST CP-4 and IR-8 standards.
GR-00154 The Contractor must perform Business Continuity, Disaster Recovery, and Cyber Incident Response exercises after major system changes as required by the State.
GR-00155 The Contractor must document all Business Continuity, Disaster Recovery, and Cyber Incident Response activities and report to the State instances where appropriately trained personnel were unable to complete the necessary recovery procedures.
GR-00156 The Contractor must adjust contingency and training plans to correct deficiencies identified through Business Continuity, Disaster Recovery, and Cyber Incident Response exercises and present updates to the State for approval.
GR-00157 The Contractor must provide annual test reports to the State within 10 business days of exercise, Business Continuity (BC)/Disaster Recovery (DR) and Cyber Incident Response (CIR) Plan reports within one business day of incident, and BC/DR/CIR Plan updates within one business day of identified deficiency.
GR-00158 The Contractor must evaluate systems and business processes in collaboration with the State for criticality and necessity to determine appropriate return to operations time frames during development of both the initial and ongoing Business Continuity/Disaster Recovery/Cyber Incident Response Plans.
GR-00159 The Contractor must update key personnel contact information as it relates to the Business Continuity/Disaster Recovery/Cyber Incident Response Plans within one business day of notification of the change.
GR-00160 The Contractor must implement a State-approved alert process to handle system-related issues, including notifying State-identified contacts in accordance with the Business Continuity/Disaster Recovery/Cyber Incident Response Plans.
GR-00161 In coordination with the State, the Contractor must provide training to Contractor staff and State-identified stakeholders on the execution of the Business Continuity/Disaster Recovery/Cyber Incident Response Plans a minimum of 20 business days prior to implementation of the Contractor's module components, with the implementation of major changes, and annually thereafter.
GR-00162 The Contractor must review any new applicable Contractor provided business processes, including systems and operations under the scope of Subcontractors, for impact on mission critical functionality and update Business Continuity/Disaster Recovery/Cyber Incident Response Plans prior to new business process implementation.
GR-00163 The Contractor must ensure that personnel who are responsible for systems recovery and cyber incident response are trained in accordance with NIST Publication 800-53 current revision and latest version of ARC-AMPE standards and tested in their ability to execute the contingency and incident response procedures.
GR-00164 The Contractor must provide for backup capabilities at a geographically separate remote site(s) from the Contractor's primary site(s) in accordance with the standards set forth in the Business Continuity/Disaster Recovery/Cyber Incident Response Plans. System and data backup and recovery points must be mutually agreed upon between the Contractor and the State.
GR-00165 The Contractor must provide a backup and recovery/failover system(s) in compliance with State and Federal rules and regulations to ensure full backup.
GR-00166 Backup and Recovery Services must be in place for Production Environment and Non-Production Environments.
GR-00167 The solution must ensure that all backups are immutable (unchangeable).
GR-00168 The solution must employ backup strategies that include air gap measures.
Transition and Closeout Management
FEA-GF12 As a State program lead I want an orderly turnover and transfer of knowledge, assets, and responsibilities so that future providers can assume services without disruption.
GR-00169 The Contractor must develop a State-approved Turnover and Closeout Plan that includes the process, details, and cadence the Contractor uses to assess the eligibility of any other organization pursuing an optional extension of Attachment H licensing terms, after the initial 42-month contract term, with the Contractor on behalf of the State.
GR-00170 The Contractor must transition and train, as requested and negotiated, any or all infrastructure responsibilities necessary to fulfill the Contractor's contractual obligations to the State or another party upon notification from the State. This includes but is not limited to transference of: The Cloud Service Provider's (CSP) member accounts using the appropriate mechanisms; Complete system inventory for all Contractor services; Contractor cloud boundary access control policies; Network ACLs; Security Groups; Roles; Users; 2FA/Multi-Factor Authentication tooling; Infrastructure as Code programs and scripts; Security and compliance monitoring tools and processes; Audit logs; System monitoring; SIEM tooling and logs; Vulnerability Management; Plan of Action and Milestones; Compliance scans; Data backups; Configuration Management Database items; Disaster Recovery fail-over and recovery routines.
Type of Data Applicable State & Federal Standards, Policies, and Laws Comply Vendor's Description of Compliance
Publicly available information NIST 800-171
Confidential Personally Identifiable Information (PII) State law on Notification of Security Breaches State Law on Social Security Number Protection State law on the Protection of Personal Information National Institute of Standards & Technology: NIST SP 800-53 Revision 4 "Moderate" risk controls Privacy Act of 1974, 5 U.S.C. 552a.
Personal Health Information (PHI) Health Insurance Portability and Accountability Act of 1996: HIPAA The Health Information Technology for Economic and Clinical Health Act HITECH Code of Federal Regulations 45 CFR 95.621
Type of Data Applicable State & Federal Standards, Policies, and Laws Comply Vendor's Description of Compliance
Affordable Care Act Personally Identifiable Information (PII) Internal Revenue Service Tax Information Security Guidelines for Federal, State and Local Agencies IRS Pub 1075 Minimum Acceptable Risk Standards for Exchanges MARS-E 2.0 (Scroll down the page)
Personal Information from Motor Vehicle Records Driver's Privacy Protection Act (Title XXX) ("DPPA") 18 U.S.C. Chapter 123, 2721 - 2725
Criminal Records Criminal Justice Information Security Policy: CJIS
How do you manage the process of gathering our business and technical requirements?
What methodology (e.g., workshops, interviews, document analysis) do you use to map our requirements to the COTS product's standard features?
How do you handle requirements that fall outside the COTS application's standard capabilities? What is the formal process for identifying a gap?
What is your standard deliverable/artifact that formally documents the agreed-upon scope (e.g., Requirements Traceability Matrix, Statement of Work)?
What is your formal Gap Analysis process? Who from your team is responsible for leading this activity?
For each identified gap, what is the decision framework used to determine whether it will be solved by:
Configuration (using built-in flexibility)?
Customization (developing new code)?
A process change on the State's end?
What is your policy and process for customizations? Are there limitations (e.g., only via APIs, no changes to core code)? How are these customizations supported and maintained during future product upgrades?
How is the impact of a customization on the overall system performance and stability measured and documented?
How do you ensure that the system, as implemented, meets the agreed-upon requirements? How do you associate or link business rules and acceptance criteria to requirements?
What is your approach to User Acceptance Testing (UAT) in relation to the requirements? Do you provide pre-built test cases linked to the requirements?
How do you demonstrate that a custom development or configuration has not negatively impacted other core system functions (regression testing)?
Questions Vendor Response
Service: Customer Phone &/or Email Support Service: Customer Phone &/or Email Support
What is the method for contacting technical support?
What are the hours of operation for support?
What is the turnaround time for responses?
What is the escalation process for support issues?
Who comprises the support team and what are their qualifications?
Define your response resolution metrics and how you capture and report them.
Service: Incident/Security Breach Notification and Process Service: Incident/Security Breach Notification and Process
Describe your identification and notification process for security breaches.
Service: Data Management Service: Data Management
Describe how data is stored, retained and backed-up (including frequency).
Service: Hosting Service: Hosting
Describe the hosting service and associated service levels.
Questions Vendor Response
Service: Scheduled Maintenance/Downtime Service: Scheduled Maintenance/Downtime
What is the frequency of scheduled maintenance and downtime?
What is the notification process for scheduled maintenance and downtime?
Describe how "maintenance" updates are tested with customers prior to installing them in their live environments.
Service: System Upgrades Service: System Upgrades
Are software upgrades provided as part of the software support contract?
Describe your software upgrade process.
How often are new versions released?
Is documentation and training provided for system upgrades?
Are there additional costs for upgrades and/or new releases?
Describe how and when the State will have an opportunity to test system upgrades/releases prior to live installation.
Describe how the State will validate post installation and how changes will be backed out in the event that a problem is encountered.
Questions Vendor Response
Service: Bug Fixes and Minor Enhancements Service: Bug Fixes and Minor Enhancements
Describe the frequency and process for providing, testing, and installing bug fixes and minor enhancements.
Service: Disaster Recovery Service: Disaster Recovery
Describe the disaster recovery services included in this proposal for any non-state hosted services.
What is your standard RPO and RTO?
Describe the plan your company has in place for its own disaster recovery of any sites that may be involved in support of this proposal.
Cost Type One Time (Implementation) Year 1 Year 2 Year 3 Year 4 Year 5
Software
Enterprise Application: License Fees $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Maintenance &/or License Fee Add-Ons $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Subscription cost $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Storage Limitations and/or Additional Fees $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Database Software: License Fees $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Middleware Tools: License Fees $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Operating System Software: License Fees $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Upgrade Costs for Later Years $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Support and Maintenance Fees $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
$0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Implementation Services
Project Management $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Requirements $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Design (Architect Solution) $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Development (Build, Configure or Aggregate)/Testing $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
System Testing $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Defect Removal $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Implement/Deploy or Integrate $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Quality Management $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Cost Type One Time (Implementation) Year 1 Year 2 Year 3 Year 4 Year 5
Implementation Services Continued
Training $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
$0.00 $0.00 $0.00 $0.00 $0.00 $0.00
$0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Telecom $0.00
Bandwidth $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
$0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Hardware $0.00
Computing Hardware $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Storage and Backup Hardware $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Network Hardware $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Facilities/Data Center $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
$0.00 $0.00 $0.00 $0.00 $0.00 $0.00
$0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Hosting $0.00
Hosting Fees $0.00 $0.00 $0.00 $0.00 $0.00 $0.00
$0.00 $0.00 $0.00 $0.00 $0.00 $0.00
Total Base Costs $0.00
Total Implementation plus Five Year Costs $ 0.00
Clause Location Exception Proposed Verbiage
[indicate RFP, exhibit, attachment or addendum, section & page number] [briefly describe your concern about this clause] [describe your suggested alternative wording for the clause or your solution]
[indicate RFP, exhibit, attachment or addendum, section & page number] [briefly describe your concern about this clause] [describe your suggested alternative wording for the clause or your solution]
[indicate RFP, exhibit, attachment or addendum, section & page number] [briefly describe your concern about this clause] [describe your suggested alternative wording for the clause or your solution]
Summary of Detailed Information Date of Notification Outcome
Provided Equipment or Product Note or Comment
Signature:
Full name:
Title:
Company:
Date:
This is the opportunity summary page. It provides an overview of this opportunity and a preview of the attached documentation.
Daily notification on new contract opportunities

With GovernmentContracts, you can:

  • Find more opportunities and win more business
  • Receive daily alerts for all new bid opportunities
  • Get contract opportunities matched to your business
ONE WEEK FREE TRIAL

See also

Reading ER P23-1 (404) Request Date: 7/29/2026 1:05:25 PM Open Date: Closing Date:

State Government of Vermont

Bid Due: 8/21/2026

Williston Road Stormwater Structures Request Date: 7/29/2026 8:42:48 AM Open Date: Closing Date:

State Government of Vermont

Bid Due: 8/27/2026

Follow Dental and Audiology Coordinator for the Vermont Army National Guard Active Contract

DEPT OF DEFENSE

Bid Due: 8/23/2026

Roadway Line Striping and Markings Request Date: 7/24/2026 2:23:32 PM Open Date: Closing

State Government of Vermont

Bid Due: 8/19/2026

* Disclaimer: Information regarding bids, requests for proposals (RFPs), or requests for qualifications (RFQs) is provided on this website only for convenience and does not constitute official public notice. Persons wishing to respond to or inquire about bids, RFPs, or RFQs should contact the appropriate government department.