| Location: | Vermont |
|---|---|
| Posted: | Apr 8, 2026 |
| Due: | Jun 26, 2026 |
| Agency: | State of Vermont |
| Type of Government: | State & Local |
| Category: |
|
| Publication URL: | To access bid details, please log in. |
| TITLE | QUESTIONS DUE | ANSWERS POSTED | DUE DATE | NO POSTING AFTER |
|
Criminal Justice Information Exchange
Bidder Response Form CJIS_Requirements_Companion_Document Additional_CJIS_RFP_Contract_Requirements |
05/20/2026 04:30PM |
|
06/26/2026 04:30PM |
|
State of Vermont Bidder Response Form
Request for Proposal Name: Criminal Justice Information Exchange
Vendor Instructions:
Provide the information requested in this form and submit it to the State of Vermont as part of your Request for Proposal (RFP) response. All answers must be provided within the form unless otherwise specified.
Important: This form must be completed and submitted in response to this RFP for your proposal to be considered valid. The submission must also include the eight (8) additional artifacts requested within this form (denoted by underlined green font).
See the RFP for full instructions for submitting a bid. Bids must be received by the due date and at the location specified on the cover page of the RFP.
Direct any questions you have concerning this form or the RFP to:
STATE CONTACT
State of Vermont
Office of Purchasing & Contracting
E-mail Address:
Part 1: VENDOR PROFILE
Complete the table below.
Provide a brief overview of your company including number of years in business, number of employees, nature of business, and description of clients. Identify any parent corporation and/or subsidiaries.
Is your organization currently or has it previously provided solutions and/or services to any agency or entity of the Vermont State government within the past five years? If so, include a complete list of the State entities, the solutions and/or services provided, and the dates your organization provided the State with these services in the last five years.
Provide a Financial Statement* for your company and label it Attachment #1. This requirement can be filled by:
A current Dun and Bradstreet Report that includes a financial analysis of the firm;
An Annual Report if it contains (at a minimum) a Compiled Income Statement and Balance Sheet verified by a Certified Public Accounting firm; or
Tax returns and financial statements including income statements and balance sheets for the most recent 3 years, and any available credit reports.
A confidentiality statement may be included if this financial information is considered non-public information
*Some types of procurements may require bidders to provide additional or specific financial information. Any such additional requirements will be clearly identified and explained within the RFP and may include supplemental forms in addition to this Bidder Response Form.
Disclose any judgments, pending or expected litigation, or other real potential financial reversals, which might materially affect the viability or stability of your company or indicate below that no such condition is known to exist. A confidentiality statement may be included if this information is considered non-public information
Provide a list of three references similar in size and industry (preferably another governmental entity). References shall be clients, other than the State of Vermont, who have implemented your Solution within the past 48 months.
Part 2: Vendor Proposal/Solution
Provide a description of the technology solution you are proposing.
Provide a description of the capabilities of the technology solution you are proposing.
If specific software is being proposed, provide a description of the:
Standard features and functions of the software:
The software licensing requirements for the solution:
Maximum number of concurrent users:
Give a brief description of the evolution of the system/software solution you are proposing. Include the date of the first installed site and major developments which have occurred (e.g. new versions, new modules, specific features).
List the total number of installations in the last 3 years by the year of installation.
Provide the total number of current users for the proposed system and indicate what version they are using.
Have you implemented the proposed solution for other government entities? If so, tell us who, when, and how that implementation went?
Provide a Road Map that outlines the company's short term and long term goals for the proposed solution/software and label it Attachment #2. (A confidentiality statement may be included if this information is considered non-public information)
Provide a PowerPoint (minimum of 1 slide and maximum of 10 slides) that provides an Executive level summary of your proposal to the State. Label it Attachment #3.
Describe any infrastructure, equipment, network or hardware required to implement and/or run the solution.
What is your recommended way to host this solution?
Describe how your solution can be integrated to other applications and if you offer a standard-based interface to enable integrations.
Respond to the following questions about the solution being proposed:
Part 3: Functional Requirements
The table below lists the State's Functional Requirements. Indicate the "Availability" for each requirement for your proposed solution. Use the "Vendor Comments" column to provide any additional information or explanations.
A - Feature is available in the core ("out-of-the-box") solution.
D - Feature is currently under development (indicate anticipated date of availability in the Vendor comments column).
C - Feature is not available in the core solution but can provided with customization.
N - Feature is not available.
Part 4: Non- Functional Requirements
The tables below list the State's Non-Functional Requirements. Indicate if your proposed solution complies in the "Comply" column.
Yes = the solution complies with the stated requirement.
No = the solution does not comply with the stated requirement.
N/A = Not applicable to this offering.
Describe how the requirement is met in the "Vendor Description of Compliance" column.
4.1 Hosting
4.2 Application Solution
Security
As a solution vendor, you must have documented and implemented security practices for the following and have a process to audit/monitor for adherence. Indicate "Yes" or "No" in the "Comply" column or "N/A" if the requirement is not applicable to this offering. Use the "Vendor Description of Applicable Security Processes" column to describe how you meet the requirement and the "Audit/Monitor" column to indicate how you monitor for compliance. (A confidentiality statement may be included if this information is considered non-public information)
4.4 Other Non-Functional Requirements
For each requirement listed, indicate if and how you comply or type "N/A" if it is not applicable to your offering.
4.5 Data Compliance
Vendors and their solutions must adhere to applicable State and Federal standards, policies, and laws based on the type of data that will be stored, accessed, transmitted and/or controlled by the solution. If the "Type of Data" column is checked below, respond "Yes" or "No" in the "Comply" column and provide an explanation on how you comply in the "Vendor's Description of Compliance" column.
4.6 State of Vermont Cybersecurity Standard Update
Bidder shall certify by checking the box below the Solution shall not include, incorporate, rely on, utilize or be supported by any products or services subject to the limitations provided under State of Vermont Cybersecurity Standard Update, which Bidder acknowledges has been provided to it, and is available on-line at the following URL:
Bidder hereby certifies that in connection with the Request for Proposal, none of the applicable products or services will be included in or used to support State systems in a manner prohibited under the Standard.
4.7 CJIS SECURITY POLICY REQUIREMENTS
The CJIS Security Policy attachment lists the State's CJIS Non-Functional Requirements. Indicate the ability to "Comply" for each requirement for your proposed solution. Use the "Vendor Comments" column to provide any additional information or explanations.
Part 5: IMPLEMENTATION/Project Management Approach
[Add, modify or delete information in this section to be specific to your RFP.]
Describe the approach you would recommend for project managing this engagement.
Provide a list of the standard project management deliverables that you would normally produce for this type of engagement.
Provide a proposed list of project phases, major milestones, and an implementation time-line. Label this Attachment #4.
What types of difficulties have other clients experienced with implementation of the proposed solution?
Describe the experience and qualifications of the Project Manager you would offer as the resource for this engagement. Provide a copy of their resume and label it Attachment #5.
Part 6: TECHNICAL Services
[Add, modify or delete information in this section to be specific to your RFP.]
Describe the technical services included in your proposal (e.g., business analysis, configuration, testing, implementation, etc.).
Provide a list of the standard deliverables for the technical services described above.
Describe your business analysis approach for the implementation of CJIX. Describe your requirements elicitation and documentation processes and deliverables.
Describe how you document and manage other requirements related artifacts like acceptance criteria and business rules.
Provide a description of the roles/services/tasks the State will be expected to cover as part of this engagement. Describe any additional roles/services/tasks that are optional, but would be beneficial for the State to provide.
Describe your typical conversion plan to convert data from existing systems to your proposed solution (if applicable).
Describe and attach your typical Implementation Plan (label it Attachment #6), which shall include planning for the transition to maintenance and operations.
Describe the experience and qualifications of the technical resources proposed for this engagement. Provide their resume(s) and label them Attachment #7.
Describe the training that is included in your proposal.
Describe the system, administrator, and/or user documentation that is included in your proposal.
PART 7: Oral Demonstrations, Interviews and Trial Evaluation Period:
The State reserves the right to require a Vendor to present an Oral Demonstration of their proposed solution, preferably by the Vendor's Solution Experts and Information Technology staff that will be implementing the solution and respond to interview questions during the demonstration. The demonstration will be stand alone and should include a high-level overview of how the proposed solution meets the State's needs and will be limited to 90 minutes, then 30 minutes available for the State to ask questions about the proposed solution.
Request and be provided a Trial Evaluation (Hands-On Evaluation) Period of the proposed solution by State Evaluators. State Evaluators will have access to Vendor's Sandbox version of the proposed solution for Hands-On Evaluation which will include:
Hands-On Evaluation Setup Meeting prior to beginning of the Evaluation period with Vendor Representative, and State Representatives to review such items as
Account setup and types of roles.
Confirmation of Hands-On Evaluation duration dates.
Vendor Support contact during Hands-On Evaluation.
Setup of Kick-Off meeting with Vendor Representatives and State Evaluators.
Check-In meetings; setup of a minimum of two (2) meetings during Evaluation period.
How Vendor will respond to State questions and evaluation scripts findings (issues).
Pre-Hands-On Evaluation Support to ensure that all Evaluators have successfully logged into the Vendor's Sandbox.
Hands-On Evaluation Duration of Fifteen 15 Business Days.
First day of the Evaluation period, or prior to, a Kick-Off Meeting with Vendor Representatives, and State Evaluators for orientation of Vendor's Sandbox version of the solution.
Minimum of fourteen (14) business days of Hands-On Evaluation of Vendors proposed solution in Vendor's Sandbox.
Minimum of two (2) Check-In Meetings during Evaluation period with State Evaluators and Vendor Representatives to review any issues, blocks, features, and functionality discovered. It is preferred by the State that the first Check-In Meeting be in the first week of the Evaluation period.
All costs associated with oral demonstration, interviews, and Sandbox setup and usage for Hands-On Evaluation will be borne entirely by the Vendor.
Describe how you will make these items possible and what Vendor support will be provided during Hands-On Evaluation period.
Part 8: Maintenance and Support Services
Provide answers to the questions below regarding your company's Maintenance and Support Services:
Describe how adherence to your service levels is measured and what remedies you would provide the State when performance doesn't meet the standard?
Part 8: PRICING
Submit pricing for your proposed solution in the table below. Fill in only the lines that are applicable to your proposal. Insert lines for additional costs, but do not delete or rename any lines in the Table. Total each column and provide a total of all columns in the "Total Implementation, plus 5 Year Costs" box on the next page.
Describe any assumptions you have made in relation to the above cost and pricing information.
Provide pricing information for any volume discounts that are available based on the number of software licenses purchased or support years purchased.
Provide pricing for any Functional Requirements marked as "C" (feature is not available in the core solution, but can be provided with customization).
Part 9: Terms and Conditions
Exceptions to the States standard terms, conditions, and templates is strongly discouraged. Accordingly, exceptions may result in a determination that a bidders proposal is not in the best interest of the State. However, if a bidder does wish to take exception to the State's terms, conditions, or templates they must indicate those objections in the table below. Add lines to the table below as needed. The State considers contractor documents the bidder wishes to append to the contract as exceptions.
Part 10: CERTIFICATE OF COMPLIANCE/Authorized Company Signature
NON COLLUSION: Bidder hereby certifies that the prices quoted have been arrived at without collusion and that no prior information concerning these prices has been received from or given to a competitive company. If there is sufficient evidence to warrant investigation of the bid/contract process by the Office of the Attorney General, bidder understands that this paragraph might be used as a basis for litigation.
CONTRACT TERMS: Bidder hereby acknowledges that is has read, understands and agrees to the terms of this RFP, including Attachment C: Standard State Contract Provisions, and any other contract attachments included with this RFP.
Worker Classification Compliance Requirement: In accordance with Section 32 of The Vermont Recovery and Reinvestment Act of 2009 (Act No. 54), the following provisions and requirements apply to Bidder when the amount of its bid exceeds $250,000.00.
Self-Reporting. Bidder hereby self-reports the following information relating to past violations, convictions, suspensions, and any other information related to past performance relative to coding and classification of workers, that occurred in the previous 12 months.
Subcontractor Reporting. Bidder hereby acknowledges and agrees that if it is a successful bidder, prior to execution of any contract resulting from this RFP, Bidder will provide to the State a list of all proposed subcontractors and subcontractors' subcontractors, together with the identity of those subcontractors' workers compensation insurance providers, and additional required or requested information, as applicable, in accordance with Section 32 of The Vermont Recovery and Reinvestment Act of 2009 (Act No. 54), and Bidder will provide any update of such list to the State as additional subcontractors are hired. Bidder further acknowledges and agrees that the failure to submit subcontractor reporting in accordance with Section 32 of The Vermont Recovery and Reinvestment Act of 2009 (Act No. 54) will constitute non-compliance and may result in cancellation of contract and/or restriction from bidding on future state contracts.
Executive Order 05 - 16: Climate Change Considerations in State Procurements Certification
Bidder certifies to the following (Bidder may attach any desired explanation or substantiation. Please also note that Bidder may be asked to provide documentation for any applicable claims):
Bidder owns, leases or utilizes, for business purposes, space that has received:
Energy Star(R) Certification
LEED(R), Green Globes(R), or Living Buildings ChallengeSM Certification
Other internationally recognized building certification:
____________________________________________________________________________
2. Bidder has received incentives or rebates from an Energy Efficiency Utility or Energy Efficiency Program in the last five years for energy efficient improvements made at bidder's place of business. Please explain:
_____________________________________________________________________________
3. Please Check all that apply:
Bidder can claim on-site renewable power or anaerobic-digester power ("cow-power"). Or bidder consumes renewable electricity through voluntary purchase or offset, provided no such claimed power can be double-claimed by another party.
Bidder uses renewable biomass or bio-fuel for the purposes of thermal (heat) energy at its place of business.
Bidder's heating system has modern, high-efficiency units (boilers, furnaces, stoves, etc.), having reduced emissions of particulate matter and other air pollutants.
Bidder tracks its energy consumption and harmful greenhouse gas emissions. What tool is used to do this? _____________________
Bidder promotes the use of plug-in electric vehicles by providing electric vehicle charging, electric fleet vehicles, preferred parking, designated parking, purchase or lease incentives, etc..
Bidder offers employees an option for a fossil fuel divestment retirement account.
Bidder offers products or services that reduce waste, conserve water, or promote energy efficiency and conservation. Please explain:
____________________________________________________________________________
____________________________________________________________________________
Please list any additional practices that promote clean energy and take action to address climate change:
_____________________________________________________________________________
____________________________________________________________________________
_____________________________________________________________________________
Executive Order 02 - 22: Solidarity with the Ukrainian People
By checking this box, Bidder certifies that none of the goods, products, or materials offered in response to this solicitation are Russian-sourced goods or produced by Russian entities. If Bidder is unable to check the box, it shall indicate in the table below which of the applicable offerings are Russian-sourced goods and/or which are produced by Russian entities. An additional column is provided for any note or comment that you may have.
Certification Regarding Use of Contract Funds for Lobbying. The following provision is applicable to the Contractor for contracts over $100,000.00, and Contractor shall include this clause in all its subcontracts over $100,000.00.
1. The prospective contractor certifies, to the best of his or her knowledge and belief, under the penalties of perjury under the laws of the State of Vermont and the United States that on behalf of the person, firm, association, or corporation he or she represents, that:
a. No Federal appropriated funds have been paid or will be paid, by or on behalf of the undersigned, to any person for influencing or attempting to influence an officer or employee of any Federal agency, a Member of Congress, an officer or employee of Congress, or an employee of a Member of Congress in connection with the awarding of any Federal contract, the making of any Federal grant, the making of any Federal loan, the entering into of any cooperative agreement, and the extension, continuation, renewal, amendment, or modification of any Federal contract, grant, loan, or cooperative agreement.
b. If any funds other than Federal appropriated funds have been paid or will be paid to any person for influencing or attempting to influence an officer or employee of any Federal agency, a Member of Congress, an officer or employee of Congress, or an employee of a Member of Congress in connection with this Federal contract, grant, loan, or cooperative agreement, the undersigned shall complete and submit Standard Form-LLL, "Disclosure Form to Report Lobbying," in accordance with its instructions.
2. This certification is a material representation of fact upon which reliance was placed when this transaction was made or entered into. Submission of this certification is a prerequisite for making or entering into this transaction imposed by 31 U.S.C. 1352. Any person who fails to file the required certification shall be subject to a civil penalty of not less than $10,000 and not more than $100,000 for each such failure.
3. The prospective contractor also agrees that they shall require that the language of this certification be included in all lower tier subcontracts, which exceed $100,000 and that all such recipients shall certify and disclose accordingly.
For your bid to be considered valid, this Bidder Response Form must be signed by a duly authorized representative of the bidder, and submitted as part of the response to the proposal.
I am authorized to submit a proposal to the State of Vermont in response to this RFP on behalf of my organization. The information provided as part of my organization's response is a true and accurate representation of my organization's ability to meet the State of Vermont's business needs as expressed in this RFP.
| Item | Detail |
|---|---|
| Company Name: | [insert the name that you do business under] |
| Physical Address: | [if more than one office - put the address of your head office] |
| Postal Address: | [e.g. P.O Box address] |
| Business Website: | [url address] |
| Type of Entity (Legal Status): | [sole trader/partnership/limited liability company or specify other] |
| Primary Contact: | [name of the person responsible for communicating with the Buyer] |
| Title: | [job title or position] |
| Email Address: | [email] |
| Phone Number: | [landline] |
| Fax Number: | [fax] |
| Reference 1 | Detail | Detail |
|---|---|---|
| Reference Company Name: | [insert the name that you do business under] | [insert the name that you do business under] |
| Company Address: | [address] | [address] |
| Type of Industry: | [industry type: e.g., government, telecommunications, etc.] | [industry type: e.g., government, telecommunications, etc.] |
| Contact Name: | [if applicable] | [if applicable] |
| Contact Phone Number: | [phone] | [phone] |
| Contact Email Address: | [email] | [email] |
| Description of system(s) implemented: | [description] | [description] |
| Date of Implementation: | [date] | [date] |
| Reference 2 | Reference 2 | Detail |
| Reference Company Name: | Reference Company Name: | [insert the name that you do business under] |
| Company Address: | Company Address: | [address] |
| Type of Industry: | Type of Industry: | [industry type: e.g., government, telecommunications, etc.] |
| Contact Name: | Contact Name: | [if applicable] |
| Contact Phone Number: | Contact Phone Number: | [phone] |
| Contact Email Address: | Contact Email Address: | [email] |
| Description of system(s) implemented: | Description of system(s) implemented: | [description] |
| Date of Implementation: | Date of Implementation: | [date] |
| Reference 3 | Detail |
|---|---|
| Reference Company Name: | [insert the name that you do business under] |
| Company Address: | [address] |
| Type of Industry: | [industry type: e.g., government, telecommunications, etc.] |
| Contact Name: | [if applicable] |
| Contact Phone Number: | [phone] |
| Contact Email Address: | [email] |
| Description of system(s) implemented: | [description] |
| Date of Implementation: | [date] |
| Vendor Response/Explanation | Vendor Response/Explanation | |
|---|---|---|
| Question | Yes or No | |
| Does the solution use Service Oriented Architecture for integration? | ||
| Does the solution use a Rules Engine for business rules? | ||
| Does the solution use any Master Data Management? | ||
| Does the solution use any Enterprise Content Management software? | ||
| Does the solution use any Case Management software? | ||
| Does the solution use any Business Intelligence software? | ||
| Does the solution use any Database software? | ||
| Does the solution use any Business Process Management software? | ||
| Is this a browser based solution and if so what browsers do you support? | ||
| Does the solution include an API for integration? |
| ID # | Functional Requirement Description | Availability | Vendor Comments |
|---|---|---|---|
| 1 Consolidated Dispatch Centers | 1 Consolidated Dispatch Centers | 1 Consolidated Dispatch Centers | 1 Consolidated Dispatch Centers |
| A01 | As a dispatch center supervisor with workstations that simultaneously dispatch for multiple agencies, I want both: all of my workstations and/or a sub-set of my workstations to receive inbound messages for all agencies that the dispatch center supports so that my employees are informed. | ||
| A02 | As a State Police Dispatcher and Admin with the necessary role permissions, I want a mobile command post station that can travel with me to an emergency within any agency across the state which will allow me to utilize any ORI that I need to so that I can respond efficiently and effectively to the emergency. | ||
| A03 | As an employee who dispatches/works at a consolidated dispatch center supporting multiple agencies, I want to receive messages for all agencies we support, with the option to filter messages to a specific agency or agencies, so that I can effectively dispatch for multiple agencies simultaneously or focus on a specific agency as needed by the dispatch center. | ||
| 2 Multi-Agency Employees | 2 Multi-Agency Employees | 2 Multi-Agency Employees | 2 Multi-Agency Employees |
| A04 | As an employee who dispatches/works for multiple agencies, I want different permissions for each agency (within a single user account) that I work with so that I can securely perform my job duties for each agency that I am supporting per shift. (ex: As a TAC for Middlesex, and a less-than-full-service user for Montpelier, I cannot perform full TAC functions at the Montpelier agency). | ||
| A05 | As an employee who dispatches/works for multiple agencies, I want to receive messages only for the agency (or consolidated dispatch center) that I am actively working for during that shift so that I stay focused on the current job and don't miss important messages. I also want to filter the messages that I receive based on agency and/or role so I can keep the messages organized for efficient workflows. (I should not have to manage multiple user accounts for my multiple roles and/or agencies) | ||
| A06 | As an employee who dispatches/works for multiple agencies, I want to choose which agency ORI to use for each message that I send so that I can accurately represent the agency that I am sending the message on behalf of (shift-based). | ||
| A07 | As a user who has permissions to utilize multiple ORIs, I may only do so at specific workstations so that security standards can be maintained. Workstations should have a configurable list of ORIs they can utilize, and users may only use an ORI if their user account AND the workstation are both authorized to use the ORI. | ||
| 3 Record Holding Agreements | 3 Record Holding Agreements | 3 Record Holding Agreements | 3 Record Holding Agreements |
| A08 | As a State Police Admin Clerk or another part-time center employee, I want to assign a 24/7 Dispatch/PSAP center as my "holding agency" so that they can verify data when I am not available. | ||
| A09 | As an agency with a Holder of Records Agreement with another agency, I want all of my configurations migrated to and/or maintained to the 24/7 agency so that non-terminal or non-24/7 agencies are able to maintain 24-hour dispatch services of NCIC/NLETS/VLETS/NCIC/III record information. (ex: so that a user can create a record within NCIC, on behalf of another agency's Originating Identifier "ORI"). | ||
| A10 | As a "holder of records" agency for another agency, I want to receive messages that are sent to the originating agency, so that I have all context for situations, should they arise. | ||
| A11 | As a "holder of records" agency for another agency, I want to use the originating agency's ORI for NCIC transactions so that I can represent the originating agency accurately. | ||
| A12 | As a "holder of records" agency for another agency, I want to receive a copy of any unsolicited traffic to the originating agency so that I can be kept informed. | ||
| A13 | As an internal state developer, I want an instant way to adjust ORI access, in case of emergency ("mutual aid") and for multiple users and agencies at once so that for one-off situations such as a mass-incident, an agency can accept administrative assistance from other agency's' staff. | ||
| A14 | As an operator sending messages using an Agency ORI, the platform should ensure that I have permission to use the ORI prior to processing the transaction. | ||
| A15 | As a user (and agency, and station) who has permissions to enter or query a record on behalf of another ORI, I want a drop-down option available to me so that I can determine or change my ORI selection for a specific transaction. | ||
| A16 | As the NCIC Auditor, I want to set up and configure agency settings so that, for example, an agency can allow another agency to pick up messages for them after hours. | ||
| 4 Auditing and Accountability | 4 Auditing and Accountability | 4 Auditing and Accountability | 4 Auditing and Accountability |
| AA01 | As an Integration Developer, I want to assist specific and authorized users with investigating system use so that they can identify any misuse of the system. | ||
| AA02 | As an Integration Developer, I want to investigate and re-construct timelines from message history so that I can help users investigate unexpected system behavior or so that I can investigate unusual user behavior. | ||
| AA03 | As the NCIC Auditor, I want to assess how other agencies are entering/modifying/canceling records and how other users run reports so that I can comply with FBI, CJIS, and Vermont Statute Security Standards. | ||
| AA04 | As the NCIC Auditor, I want to assist the FBI during their tri-annual state audit of VCIC sections so that I can help them validate that users' data access was compliant and based on criminal justice operations and so that Vermont can maintain access to FBI data. | ||
| AA05 | As the NCIC Auditor, I want to visually monitor message traffic utilizing a dashboard so that I can find errors and so that I can intervene and help users with their encountered errors. | ||
| AA06 | As the NCIC Auditor, I want to research cases and records that may have been accessed or disseminated improperly for auditing purposes. | ||
| AA07 | As the NCIC Auditor, I want to access basic user account data such as when a user account was created for auditing purposes. | ||
| AA08 | As the NCIC Auditor, I want to access basic message data such as "which user account conducted a transaction" or "what variations/errors did a message encounter" or "what steps did a user take to encounter an error message" for auditing purposes. | ||
| AA09 | As the NCIC Auditor, I want the ability to visually graph report data so that, for example, I could show an agency the occurrence of data they query, how their users utilize the system, their users' success or error rates. | ||
| AA10 | As the NCIC Auditor, I want to utilize an archive and retrieval function so that I can search for and audit records utilizing robust search and filter functionality so that I can comply with tri and bi-annual audits (ex: list of all wanted persons within a specific ORI from the past 3 years and with MRI) - I also want to save my search history and parameters. | ||
| AA11 | As a Vermont State Police Dispatcher, I want to run audit queries (for example, view all missing people within a certain agency/agencies) so that I compile the data that I need to keep Vermonters safe and secure. | ||
| AA12 | As a Vermont State Police Dispatcher Supervisor, I want to review prior queries and responses to/from my dispatch center (according to CJIS policy's access privileges: the principal of least privilege should be maintained) so that I can establish timelines for messages previously sent or received. | ||
| AA13 | As an Integration Developer, I want to quantify user and workstation activity so that I can re-assign licenses, if need be. | ||
| AA14 | As the NCIC Auditor, I want to review (and filter) message data such as where the message was from, where it was sent, what database(s) the message has found a hit within so that I can be informed of message data. | ||
| AA15 | As the NCIC Auditor, I want to maintain a log of all users and agencies that access Criminal History Record based on ORI, so that I can provide the FBI with this data monthly and so that Vermont can comply with the FBI CJIS Security Policy without having to perform manual work. (FBI requires 1 year retain of Criminal History access logs) (example: X record accessed on X date for X reason). | ||
| AA16 | As the NCIC Auditor, I want to access a single message by utilizing search functionality for auditing purposes. | ||
| 5 CCH Database: CCH Admin | 5 CCH Database: CCH Admin | 5 CCH Database: CCH Admin | 5 CCH Database: CCH Admin |
| CCH01 | As a VT CCH administrator, I want to perform administrative functions such as managing agency, event, disposition and charge codes so that the system will support all codes used by the judiciary. | ||
| CCH02 | As a VT CCH administrator, I want to search for and unseal a criminal history record that has been ordered "unsealed" by the judiciary. | ||
| 6 CCH Database: CCH Integrations | 6 CCH Database: CCH Integrations | 6 CCH Database: CCH Integrations | 6 CCH Database: CCH Integrations |
| CCH03 | As the Fingerprint Section Supervisor, I want to validate that each fingerprint submission (including livescan data) populates arrest data from AFIS into the solution so that I can review the fingerprint submission for quality. | ||
| CCH04 | As the Fingerprint Section Supervisor, I want to send data from the solution to AFIS Scanner, so that I don't need to manually enter data into both solutions. | ||
| CCH05 | As the Fingerprint Section Supervisor, I want to send data from the solution to the FBI so that I can get an FBI number created. | ||
| CCH06 | As a VT CCH team member, I want to review (quality check) and import a disposition file (PDF) that I receive from the courts into the solution so that charge outcomes (such as new cycles added, existing cycle updated (ex: prints), and rejected (ex: new names/DOBs to the solution or not on file, case numbers that match but docket number does not match or vice versa)) do not need to be manually entered. | ||
| CCH07 | As a VT CCH team member, I want to enter (automatically) weekly, a court file of violations of probations (csv) into the solution so that we can monitor any probation violations that have occurred. | ||
| CCH08 | As a VT CCH team member, I want to review and import (automatically) a monthly death report (txt) into the solution (that I receive from the Department of Health) so that any dead person that is within the database can receive a "dead" flag on their record, and so that their date of death can be logged. | ||
| CCH09 | As a VT CCH team member, I want to automatically import the events from a Parole Board Report (pdf) into the solution so that individuals that have been released from their parole, have violated their parole, or are no longer on parole can be accurately documented and updated within the solution. | ||
| CCH10 | As a VT CCH team member, I want to automatically import the Failure to Appear Report into the solution so that "failure to appears" can be documented and updated per criminal dockets. | ||
| CCH11 | As a VT CCH team member, I want to automatically import/ingest reports so that I don't need to open every single docket that is impacted/affected by the report when I do my quality control work. | ||
| CCH12 | As a VT CCH team member, I want to export cancellations from the solution so that I can upload the cancellations (Brady disqualifications or modifications) into the FBI-Maintained Law Exchange Portal (LEEP) (NICS Indices) (LEEP allows LE direct access to NCIC). | ||
| 7 CCH Database: CCH Record Management | 7 CCH Database: CCH Record Management | 7 CCH Database: CCH Record Management | 7 CCH Database: CCH Record Management |
| CCH13 | As a VT CCH team member, I want to remove records from the Triple III (Interstate Identification Index) so that the records can be disqualified/expunged. | ||
| CCH14 | As a VT CCH team member, I want to perform quality control on imported court charges (from disposition file), so that I can validate data (ex: manually match/link hits, fix spelling errors to match hits, create new entries in CCH if new). | ||
| CCH15 | As a VT CCH team member, I want to automatically expunge and/or seal a record (approximately 1000 orders a month) from the Triple III (when it is expunged/sealed from our state CH database) so that the record can be deleted or hidden (respectively) from certain user permissions (excluding Law Enforcement). | ||
| CCH16 | As a VT CCH team member, I want to search for data and filter and fine-tune my searches so that I can find exactly what I need. (ex: search by docket number, search by 2nd docket within a specific set of cycle counts, search by statutes/whether individual was convicted/group by dates, query by case number or fingerprint tracking number) | ||
| CCH17 | As a DOC Staff Member, I want to see the full evolution and history of a criminal history case (including original sentences, probation violations, suspensions) so that I can be truly informed of an individual's history and current status. | ||
| CCH18 | As a VT CCH team member, I want to pull a report based on varying data points (such as docket number or incidents during a specific time period) in an abstractable fashion so that I can compile, print, and/or export data that I need in any format that I need such as XLS and CSV (ex: run a report based on data fields for export to meet the needs of an FBI audit). | ||
| CCH19 | As the Fingerprint Section Supervisor, I want to run a daily Triple III (Interstate Identification Index) query (report) so that FBI data changes get automatically updated within the VTCCH database to reflect the accurate current state (such as when an FBI/UNC number, SID, Flag have been expunged and removed). | ||
| CCH20 | As the Fingerprint Section Supervisor, I want to review incoming criminal and civil (non-criminal) fingerprint and mugshot submissions so that I can validate the quality (accurate, up to date, comprehensive) of the arrest submission. | ||
| 8 Data Migration & Historical Records | 8 Data Migration & Historical Records | 8 Data Migration & Historical Records | 8 Data Migration & Historical Records |
| DM01 | As an IT administrator, I want all data from the current system (that we are required by statute or CJIS Security Policy to maintain for a period of time) to be migrated to the new solution by the vendor so that we maintain compliance with the law and policy. | ||
| DM02 | As an IT administrator, I want the existing system configuration (Users, ORIs, Stations, Agencies, MKEs, etc.) to be migrated to the new solution so that I don't have to spend time recreating the existing system configuration. | ||
| 9 Digital Line-Ups | 9 Digital Line-Ups | 9 Digital Line-Ups | 9 Digital Line-Ups |
| DLU01 | As a State Police Admin, I want to create a digital line-up of mugshot photos to present to a witness so that I can determine whether the witness can identify a subject. | ||
| 10 Imports, Exports & Reports | 10 Imports, Exports & Reports | 10 Imports, Exports & Reports | 10 Imports, Exports & Reports |
| IER01 | As an Integration Developer, I want to build a custom query for searching data (with custom keys for the queries) so that I can assist users when necessary. | ||
| IER02 | As an Integration Developer, I want to the solution to query data that I can trust so that I don't have to export into other platforms such as SQL for further investigation. | ||
| IER03 | As an Integration Developer, I want to report on and query data within the system such as "Number of messages that a user or agency handled" or "Station name that a certain ORI delivers to" so that I can make informed decisions. | ||
| IER04 | As a local law enforcement dispatcher, I want to print any screen/form/returns that I am viewing within the solution and any query/report that I have populated within the solution so that, for instance, I can disseminate the data to an incarcerated or supervised individual's case worker(s). *must be in printable format and fall within standard paper margins | ||
| IER05 | As a local law enforcement dispatcher, I want to save/download any screen/form/return and any query/report that I am viewing so that that, for instance, I can further manipulate the data in another solution (CSV, PDF, xml, JSON, etc.). | ||
| 11 Message Terminal/Inbox: Admin Messages | 11 Message Terminal/Inbox: Admin Messages | 11 Message Terminal/Inbox: Admin Messages | 11 Message Terminal/Inbox: Admin Messages |
| M01 | As a law enforcement dispatcher or admin, I want to send and receive both templated and un-templated hit conformation requests and/or responses (in plain English) so that I can request a known record from another state or agency (ex: trooper asking if an individual is still wanted) or validate a request from another state or agency (such as validating a licensed professional's charges or identity or confirming that indeed, the individual is still wanted) within a set time period (urgent = 10 mins, non-urgent = 1 hour). | ||
| M02 | As a local law enforcement dispatcher or admin, I want to send and receive both templated and un-templated admin messages such as a "Be on the Lookout" (BOL) to other agencies within the state, region, and nation so that they can be informed of recent events and current activity. | ||
| 12 Message Terminal/Inbox: Printing | 12 Message Terminal/Inbox: Printing | 12 Message Terminal/Inbox: Printing | 12 Message Terminal/Inbox: Printing |
| M03 | As an agency who would like to print messages, I want to print all messages that come into my dispatcher's terminal (automatic and on demand) so that I can have a physical copy of messages. | ||
| 13 Message Terminal/Inbox: Send & Receive User Experience | 13 Message Terminal/Inbox: Send & Receive User Experience | 13 Message Terminal/Inbox: Send & Receive User Experience | 13 Message Terminal/Inbox: Send & Receive User Experience |
| M04 | As a DOC Full-Service Terminal Operator, I want to query and track warrants by various fields (such as by every warrant that I am responsible for) so that I can clearly visualize my workload. | ||
| M05 | As a law enforcement dispatcher or admin, I want my Hit Confirmations to auto-populate data based on the data in the associated message so that I do not need to duplicate entry. | ||
| M06 | As a user, I want to view the message return data in multiple formats with custom filters (presentation view, xml, raw data, hex view) so that I can export it if need be. | ||
| M07 | As a user, I want to search within my own inbox so that I can locate specific messages. | ||
| M08 | As a user, I want to specify the subject line of my message so that I can clarify the purpose for my recipients and to improve efficiency. | ||
| M09 | As a user, I want relevant data (to my search/query) to be highlighted within a return so that I don't have to scroll/search for the important data that I need. | ||
| M10 | As a user, I want all messages to be date and time stamped and with a unique MRI and message number so that I can locate the message in the future. | ||
| M11 | As a user, I want all message returns to be filtered and listed, for example, by type of form: MKE, by source (NCIC/HFS/User), by date so that I can sort my returns by those field values if need be (for example, I want to sort by source so that I can validate that there are no instate, national, or DMV warrants out for a specific person). | ||
| M12 | As a State Police Dispatcher, I want the data returned from my queries to be clear, concise (glance-able), up-to-date, pertinent, relevant, and with a single source of truth (ex: suspension indicators) without having to scroll through outdated or repetitive information so that I can provide timely and accurate information to a trooper so that I can keep both the requesting trooper and the public safe. | ||
| M13 | As a State Police Dispatcher, when running a query, I want returned information instantly summarized in plain text English with key data in a highly visible location (at the top of the return screen) so that time is not wasted when supplying troopers with crucial information (such as if a vehicle in their traffic stop is currently stolen or if an individual in their traffic stop is currently wanted for a violent crime). | ||
| M14 | As a user, I want a pull-back method so that I can edit or remove a previously sent message (ex: after sending an admin message, I need to pull it back to edit a typo). | ||
| M15 | As a user, I want to mark a message as unread so that I can have a visual reminder to return to the message when needed. | ||
| M16 | As a user, I want to specify the destination of my message and receive only the messages that are pertinent to my work (driven by my role and message type) so that I am not distracted by messages that do not pertain to me. (ex: dispatch should receive every admin message, but troopers should receive messages only on need-to-know basis (based on CJIS rules for FBI). I want to clearly identify which messages are relevant and important to me (1k messages a day) so that I can respond to my specific message-load. | ||
| M17 | As a user sending standardized messages, I want to be prevented from submitting invalid/non-conformant messages (the system should validate messages before they are sent) so that messages can remain consistently formatted. | ||
| M18 | As a DOC Full-Service Terminal Operator, I want to enter both single and multiple warrants for a single wanted person so that all relevant data is collected on an individual. | ||
| M19 | As a local law enforcement dispatcher, I want to locate data such as name, dob, vehicle, driver's license, offense, so that I can document an incident or report to support local first responders during their incidents. | ||
| M20 | As a State Police Admin, I want to run a Criminal History request, License check, or License plate check, so that I can provide the returned data to the requesting State Trooper. Acceptance Criteria: Given that I am a VSP Admin, when a newly incarcerated or supervised individual is taken into custody, and at least once a year following, and when determining status and classification of custody, then I can run a criminal history on the individual. | ||
| M21 | As a State Police Admin, I want to utilize F-keys (short cut keys) when querying so that I can more quickly and efficiently access the data that I need. | ||
| M22 | As a law enforcement dispatcher, I want to monitor messages (such as a request for warrant message) so that I can keep local police informed and ultimately, keep Vermonters safe. | ||
| M23 | As a law enforcement dispatcher, I want to be notified (by sound, alert banner, pop-up, highlight, work queue, or other means) of urgent messages (such as an urgent Hit Confirmation Request) so they are handled promptly and never missed. | ||
| M24 | As a law enforcement dispatcher, I want to run name query with phonetic or approximate name-matching functionality so that I can provide information to first responders even if I don't have accurate spelling of an individual's name. | ||
| M25 | As a State Police Dispatcher, I want to perform a Meta or Super Query (such as a super name or super license plate query) by inputting data once to simultaneously query VT DMV, NCIC, and NLETS partners' databases so that I do not need to individually query each source when providing pertinent information (such as name, vehicle & registration, driver, license plates, license photos, criminal history information (previous offenses)) to the requesting troopers so that they have up-to-date information during their arrest and when documenting court records and so that I can investigate a licensed professional. | ||
| M26 | As an Integration Developer, I want to ensure the conditional logic that drives message spawning can be configured so that modifications can be made when needed. | ||
| 14 Security: Access Control & Enforcement | 14 Security: Access Control & Enforcement | 14 Security: Access Control & Enforcement | 14 Security: Access Control & Enforcement |
| S01 | As an Integration Developer, I want to access user, station, agency and other configuration data via an API, direct database query, or another tool so that I can have direct access to look at attributes such as which agencies a user works for and whether the user is full or limited service, what permissions are granted to a station and which agencies it can represent when interacting with NCIC/NLETs, and other operational details. | ||
| S02 | As an Integration Developer, I want to ensure all users have access to the interface(s) they need and ensure that the system is reliable, secure so that public safety is able to be prioritized across the state. | ||
| S03 | As an Integration Developer, I want to set up security roles and configure users and user-groups so that the state can implement role-based access control to sensitive data and features. | ||
| S04 | As the NCIC Auditor, I want to ensure the solution integrates with NexTest so that I can continue to adjust user settings, assign user to specific roles, add/disable/change profile information, assign test results (for certification) and assign/adjust test dates. | ||
| S05 | As the NCIC Auditor, I want to access my unique security role so that I can access the FT Query (file transfer between VT and NCIC) and the SPRQ Query (any VT record in NCIC). | ||
| S06 | As an investigator with the Office of Professional Regulation (OPR) or another user with less-frequent usage of the solution, I want access to only the forms that I need and none of the forms that I don't utilize, so that I can efficiently work within the solution. | ||
| S07 | As an internal state developer, I want to ad-hoc create and modify security role(s) based on arising needs. | ||
| S08 | As the NCIC Auditor, I want to set up both full-service and less-than-full-service user accounts for new and returning certified staff so that they can have access to the solution (once they have passed their NexTest certifications). I want the ability to configure/modify existing accounts so that I can, for example, de-activate accounts upon exit or lock-down accounts when VCIC has determined a user should no longer have access. | ||
| 15 Security: User Account/Session Management | 15 Security: User Account/Session Management | 15 Security: User Account/Session Management | 15 Security: User Account/Session Management |
| S10 | As an Integration Developer or Helpdesk Staff Member, I want to perform user management functions such as resetting passwords and updating account names so that I can keep the data safe and users up to date. | ||
| S11 | As a user, when my password has expired, I want to self-reset my password on my own initiation so that I don't have to contact a helpdesk or admin to get me reset (all security settings must follow CJIS Security Policy). | ||
| S12 | As a Platform Administrator, I want to review current license assignments and usage so that I can determine whether our supply is adequate and find free licenses to assign to new users. | ||
| S13 | As a Platform Administrator, I want to immediately terminate or disconnect a user's active session after determining the session is operated by a bad actor or someone without valid clearance so that I can protect the integrity of the system and limit the damage an attacker could cause. | ||
| 16 System Integration & Data Exchange: Admin Configurations | 16 System Integration & Data Exchange: Admin Configurations | 16 System Integration & Data Exchange: Admin Configurations | 16 System Integration & Data Exchange: Admin Configurations |
| SIDE01 | As a Platform Administrator, I want to configure delivery paths to specific and customized agency settings (ex: all messages are printed, or all messages delivered to the first dispatch position, dispatch outsourced to another set agency) so that each individual agency can keep their preferred settings in a future system. I want to be able to adjust these settings for the agencies at any time post-implementation | ||
| SIDE02 | As a Platform Administrator, I want a dashboard representing data such as user-encountered error messages, messages that were unable to be delivered (message queue), invalid parameters (to identify downstream vendors route breaking), Platform Status Screen (ex: disc space) and code-processing issues so that I can visually monitor indicators of issues. | ||
| 17 System Integration & Data Exchange: Integration with Internal Info Systems | 17 System Integration & Data Exchange: Integration with Internal Info Systems | 17 System Integration & Data Exchange: Integration with Internal Info Systems | 17 System Integration & Data Exchange: Integration with Internal Info Systems |
| SIDE03 | As a State Police Admin, I want to utilize standardized VT CCH message keys so that I can efficiently query records residing in VT CCH. | ||
| SIDE04 | As a State Police Admin, I want to utilize standardized VT DMV message keys so that I can retrieve individual's state ID data such as Identification, driving history, vehicle registration information, handicap placard statuses. | ||
| 18 System Integration & Data Exchange: Integration Major CJI Exchange Systems | 18 System Integration & Data Exchange: Integration Major CJI Exchange Systems | 18 System Integration & Data Exchange: Integration Major CJI Exchange Systems | 18 System Integration & Data Exchange: Integration Major CJI Exchange Systems |
| SIDE05 | As an Integration Developer, I want to ensure compliance with and interpret system behavior based on CJIS Security Requirements, NCIC Operators Manual, and the NLETS Standard so that Vermont remains within federal compliance. | ||
| SIDE06 | As the NCIC Auditor, I want to enter records, modify records, and clear/cancel records so that I can keep Vermont's criminal justice data up to date. | ||
| SIDE07 | As a DOC Full Service Terminal Operator, I want to manage warrants (Temporary and Permanent) in accordance with the FBI operating manual so that I can keep them up to date with a single source of truth (all warrants issued to a single individual) to increase clarity for users and keep law enforcement and the DOC community safe. Acceptance Criteria: The following field examples must be included: Name, DOB, LE Agency/Keeper of warrant, Date of Issuance, Offense. | ||
| SIDE08 | As a DOC Full-Service Terminal Operator, I want to run criminal history record queries against NCIC/VT CCH/FBI/III/NLETS databases on an Incarcerated or Supervised Individual (or staff/contractors/volunteers) - so that I can manage their case (ex: to inform programming, release eligibility). | ||
| SIDE09 | As a local law enforcement dispatcher, I want to query NCIC data (view/enter/clear/cancel/modify records) such as stolen vehicles, wanted persons, missing persons, protection orders, stolen articles, firearms, gang activity, warrants, violent persons, sex offenders so that I can provide the information to local police to keep them informed and safe during incidents. | ||
| SIDE10 | As a State Police Admin, I want to utilize standardized NICS message keys (defined in the NICS Manual - such as add/modify/delete/unseal/audit) so that I can efficiently query and make changes (query/enter/modify/cancel) to records residing in NICS. (ex: when performing a fire-arm return (currently: QN/QNP) I want to query data to ensure the person in question is legally able to have their firearm returned to them). | ||
| SIDE11 | As the Fingerprint Section Supervisor, I want to gather information on specific offenders/fingerprints by interacting with the "Triple III" (Interstate Identification Index/NFF) according to the (National Fingerprint File Operational and Technical Manual NGI-DOC-09034-2.0) using standard message keys (ex: MRS, DRS, DEC, TQ, EHN, XHN, QH, QR, ZRS) so that, for example, I can see if a licensed professional has a fingerprint supported arrest from another state. | ||
| SIDE12 | As a State Police Admin with TAC (Terminal Access Coordinator) permissions, I want to run NCIC Validations (review and then modify a record) so that the solution accurately reflects current (last-validated) data on records such as active wanted persons, protection orders, stolen property and people with restraining orders. | ||
| SIDE13 | As a State Police Admin, I want to utilize standardized NCIC message keys (defined in the NCIC Operator's Manual - such as: add/modify/delete/cancel/clear) so that I can efficiently query and make changes (query/enter/modify/cancel) to records residing in NCIC to keep law enforcement and DOC communities safe. | ||
| SIDE14 | As a State Police Admin, I want to utilize standardized NLETS message keys (defined in the NLETS user guide) so that I can query NLETS and NLETS partner data. | ||
| SIDE15 | As a State Police Dispatcher, I want to make updates and modifications to records in NCIC so that I can keep them up to date. | ||
| 19 System Integration & Data Exchange: Integration with Other Systems | 19 System Integration & Data Exchange: Integration with Other Systems | 19 System Integration & Data Exchange: Integration with Other Systems | 19 System Integration & Data Exchange: Integration with Other Systems |
| SIDE16 | As an Integration Developer, I want to perform connectivity troubleshooting such as CAD RMS (user authentication) and NexTest (re-certifications) so that I can help users interpret error messages. (Integrations: CAD RMS, MugShot WebApp, VCCRIS, VTCourts, Idemia, NexTest, Offender Watch) | ||
| SIDE17 | As a user (such as a dispatcher or admin), I want to "pack" records with information from other systems, such as DMV, Valcour, Spilman, so that NCIC records can have full and robust data with all available information. | ||
| SIDE18 | As a DOC Terminal Operator, I want to review Sex Offender Registry Information when I am performing a super/meta name query so that I can review if anyone is on the registry (both in and out of state) for a registerable offense. | ||
| 20 System Integration & Data Exchange: System Configuration Management & Retention | 20 System Integration & Data Exchange: System Configuration Management & Retention | 20 System Integration & Data Exchange: System Configuration Management & Retention | 20 System Integration & Data Exchange: System Configuration Management & Retention |
| SIDE19 | As a Platform Administrator, I want change control capabilities so that I can roll back changes in case of any issues. | ||
| 21 Support | 21 Support | 21 Support | 21 Support |
| TS01 | As a Platform Administrator, I want to ensure that the vendor documents any conditional logic that is hard coded in the system so that I can refer to the documentation when needed. | ||
| TS03 | As an Integration Developer, I want an open line of communication with the vendor of the solution so that helpdesk tickets can get resolved and so that I can be a liaison between the users and the vendor. | ||
| 22 UX/UI Configuration & Customization: Administrator Configurations | 22 UX/UI Configuration & Customization: Administrator Configurations | 22 UX/UI Configuration & Customization: Administrator Configurations | 22 UX/UI Configuration & Customization: Administrator Configurations |
| CC01 | As an infrequent user of the system, I want to view the name and acronym of the forms (rather than solely an acronym so that I can be reminded of the form names. | ||
| CC02 | As a law enforcement dispatcher or admin, I want to tailor the notification behavior to my role so that I'm notified of things I can address and not interrupted by things that I cannot. | ||
| CC03 | As an Integration Developer, I want to modify the XML stylesheets used to present XML messages to end users, adding fields that are displayed, displaying descriptive alternatives for CANDLE standard codes, removing fields not needed or re-arranging their appearance on the screen so that I can better organize information for users. | ||
| CC04 | As an Integration Developer, I want to modify fields on a message input form such as changing the required setting on a field or setting conditional logic for a form and/or fields so that I can configure the solution as needed. | ||
| 23 UX/UI Configuration & Customization: User Customizations | 23 UX/UI Configuration & Customization: User Customizations | 23 UX/UI Configuration & Customization: User Customizations | 23 UX/UI Configuration & Customization: User Customizations |
| CC05 | As a user, I want to personalize my frequented forms by building a "quick-access" or "favorites" list (which will remain configured every time I log into the system, regardless of machine). I also want to rename my forms and list categories so that I can easily and quickly find the forms that I need. | ||
| CC06 | As a user, I want to share my preferences (such as favorited forms) with another user so that they can utilize my recommended and preferred settings. | ||
| CC07 | As a user, I want to customize my layout so that I can make the solution fit my specific needs. (ex: incoming messages can be on top, left, or right of return screen) | ||
| CC08 | As a user, I want multiple options to view and open forms including but not limited to: by dropdown list, by searching by form name (ex: VIN or NLETS standard names), by searching via command line/search field by actual data (ex: VIN Number) so that I can choose the form-finding option that works best for me. | ||
| CC09 | As a user, I want to store my forms within a folder structure so that I can keep the forms I need organized. | ||
| CC10 | As a user, I want to save and "lock" a query search so that if I accidentally click out of the screen, I don't lose my search-returned forms or data. | ||
| 24 UX/UI Configuration & Customization: User Experience | 24 UX/UI Configuration & Customization: User Experience | 24 UX/UI Configuration & Customization: User Experience | 24 UX/UI Configuration & Customization: User Experience |
| CC12 | As a State Police Admin, I want quick and easy access to any forms that I need such as the VIN Assist/Decoder tool so that I can keep troopers safe and get them the information that they need immediately. | ||
| CC13 | As a local law enforcement dispatcher, I want to support local first responders by performing administrative functions such as responding to phone calls, documenting reports, providing hit confirmations, monitoring incoming messages, running criminal history/background checks and fulfilling various requests so that I can keep responders safe. | ||
| CC14 | As a State Police Dispatcher, I want to perform multiple searches at once so that I can investigate both multiple aspects of both a single trooper's inquiry, and/or multiple trooper's inquiries at one time. | ||
| CC15 | As a State Police Dispatcher, I want to perform data queries within templated forms and custom-made forms, and by free query (utilizing keys in a command line to type in any data point needed) so that I have multiple options for getting the information that I need. | ||
| CC16 | As a State Police Dispatcher, I want to utilize a VIN decoder or VIN assist tool so that vehicle data (such as make, model) will auto-populate when I enter the VIN and so that my time can be saved when identifying a vehicle. | ||
| CC17 | As a State Police Dispatcher, I want every form and screen clearly labeled in plain text English so that I don't need to memorize, for example, DMV or National codes to understand the form or fields. | ||
| CC18 | As a State Police Dispatcher, I want to save drafts of my NCIC Entries as "universal templates" so that I can come back to them to utilize at a later date (in any free-text, and across all consoles/terminals/users within the PSAP). (ex: free text form on form "EPO" would populate pre-written prompts such as: "TEMP0RARY 0RDER ISSUED, C0NTACT 0RI F0R C0NDITI0NS / REMAINS IN EFFECT UNTIL THE C0URT DISMISSES THE CASE, ISSUES A FINAL 0RDER OR DENIES A FINAL ORDER AFTER A HEARING / HEARING SCHEDULED FOR" | ||
| CC19 | As a VT CCH team member, I want to see the court and docket number on every record within the system so that I can communicate with clarity when working with other agencies (ex: same charge on two separate dockets can get confusing). | ||
| CC20 | As a VT CCH team member, I want to enter and view more than one DOB field so that I can enter and view all DOBs when performing a record check. | ||
| CC21 | As a VT CCH team member or Fingerprint Section Supervisor, I want to remove/seal mugshot photos efficiently when a record has been indicated to be sealed or expunged (ex: when there is a non-conviction) so that I don't have to manually sort/toggle through all artifacts before finding the specific item I need to remove/seal. | ||
| CC22 | As a VT CCH team member, when importing events (such as a parole violation) that are on multiple dockets (or other files), I want to enter the event code on all corresponding dockets (or other files) at the same time so that I do not need to duplicate (or worse) manual entry. | ||
| CC23 | As a user, I want an un-do button so that I can remove actions that I have taken by mistake (ex: accidentally closing a window or deleting a message). |
| ID # | Mapped NFR Title | Non-Functional Requirement Description | Comply | Vendor's Description of Compliance |
|---|---|---|---|---|
| H1 | Hosting/Infrastructure | Any technical solution must be hosted in a data center. | ||
| H2 | Reliability/DR | Any hosting provider must provide for back-up and disaster recovery models and plans as needed for the solution. | ||
| H3 | Operations/Service Management | Any hosting provider will abide by ITIL best practices for change requests, incident management, problem management and service desk. | ||
| GR-00073 | Operations/Infrastructure Management | As a State technical operations lead, I want the Contractor to manage hosting, environments, and infrastructure performance so that systems operate reliably and meet service level agreements. | ||
| GR-00074 | Infrastructure Management | The Contractor must implement, host (or arrange for third-party hosting), operate, maintain, and manage all infrastructure, including all hardware, software, middleware, and licenses necessary for successful operation of all systems and services under the Contract. | ||
| GR-00075 | Service Reliability/ SLA Management | The Contractor must be solely responsible for the endtoend oversight and management of all environments during implementation and transition, such that performance metrics and service level agreements are met. | ||
| GR-00076 | Network/Connectivity | The Contractor must retain the responsibility and costs for providing network connectivity and access to all systems and data under their scope to all Stateauthorized stakeholders. | ||
| GR-00077 | Operations/Maintenance | The Contractor must retain all responsibility and costs for all software, hardware, and infrastructure Maintenance and Operations necessary to fulfill their obligations of this Contract. | ||
| GR-00078 | Asset Management | The Contractor must collaborate with the State to provide, as a subsidiary plan to the Business Design/System Design Document, an Asset Management Plan that describes the process the Contractor must use to manage applicable technology assets for the duration of the Contract within a multi-Contractor, integrated system-wide enterprise solution. This plan must include: (a) Hardware/software inventory (including location) (b) Procurement information (c) Contract information (d) License management. | ||
| GR-00079 | Performance Efficiency | The Contractor must provide the base infrastructure and optimization of all systems under the scope of this Contract to meet required application-specific uptime/response time requirements related to performance requirements, deliverable due dates, and Service Level Agreements. | ||
| GR-00080 | Performance Monitoring | The Contractor must provide reporting of all infrastructure optimizations annually, or after any major system change, to meet or exceed performance requirements or as requested by the State. | ||
| GR-00081 | Performance Management | The Contractor must document and maintain Stateapproved applicationspecific response time requirements, measurements, and reporting. | ||
| GR-00082 | Capacity Management/Scalability | The Contractor must continuously monitor, track, and report monthly to the State infrastructure space and storage trends over the term of the Contract. | ||
| GR-00083 | Change Management | The Contractor must notify the State and present the upgrade/replacement plan within 20 business days of awareness of a software or infrastructure upgrade notice received from a software/infrastructure contractor, unless the change is categorized as an Emergency Upgrade, in which case notification must be given five days prior to the upgrade date. | ||
| GR-00084 | Change/Release Management | The Contractor must implement each approved upgrade/replacement plan for all software and infrastructure upgrades in accordance with a Stateapproved schedule. | ||
| GR-00085 | Access Management/Infrastructure | The Contractor must provide the tools and infrastructure to support required access to all systems and data under their scope to all Stateauthorized stakeholders. |
| ID # | Mapped NFR Title | Non-Functional Requirement Description | Comply | Vendor's Description of Compliance |
|---|---|---|---|---|
| A1 | Reliability/Disaster Recovery | Any solutions vendor must provide for the backup/recover, data retention and disaster recovery of a contracted/hosted application solution. | ||
| A2 | Maintainability/Environment Management | Any solutions vendor must provide for application management and design standard of all technology platforms and environments for the application solution (Development, Staging, Productions, DR, etc.) | ||
| A3 | Service Level Management | Any solutions vendor must engage the State of Vermont using Service Level Agreements for system and application performance, incident reporting and maintenance. | ||
| A4 | Data Governance/Data Ownership | The State owns any data they enter, migrate, or transmit into the solution and the vendor shall allow the State to pull or copy this data at any time free of charge. | ||
| A5 | Data Management/Metadata Management | As a contract deliverable, the vendor shall supply an up-to-date data dictionary that represents all data respective of the solution it will provide. The data dictionary must contain the following attributes: The technology (RDBMS platform) that hosts the data source, i.e. Oracle, SQL Server, MySQL, DB2, etc. The location where the data source is hosted Thorough descriptions of each table in the data source Thorough descriptions of each column within each table in the data source. In addition to business definitions, column descriptions must include the following detail: schema names; file group names (if applicable); data types; lengths; primary and foreign key constrains; applied formatting; applied calculations; applied aggregations; NULL-ability; default values. |
| ID # | Mapped NFR Title | Non-Functional Requirements Description | Comply | Vendor's Description of Compliance |
|---|---|---|---|---|
| 001 | Security | Hosting service provider personnel will use SOV internal network to connect to servers at the State of Vermont's (SOV's) data center. SOV is responsible for access control into its data center. | ||
| 002 | Agility | The solution must provide clear and accurate documentation and guidance for the customers and users on how to use the service effectively and efficiently. | ||
| 003 | Compatibility | Solutions will have a mechanism to share specific data, e.g., limited data sets, detailed data at the level of the individual, but with the data anonymous and completely de-identified in a controllable fashion with other State of Vermont (SOV) and local agencies. | ||
| 004 | Security | Least Privilege and Separation of Duties (SOD) principles will be applied to all solutions, ensuring user permissions and system functionality align with specific roles based on access needs. | ||
| 005 | Security | Solution administrators can create, manage, and assign user accounts with role-based access, including user groups, locations, and organizational hierarchy. | ||
| 006 | Transferability | Integration security needs such as encryption at message and transport layer, should be defined and built per business needs and standards defined by the Vermont Agency of Digital Services Security Office. | ||
| 007 | Usability | Solutions will enable central workflow alerts and transactional status. Solutions will centralize pending work items for the user as in a work queue. | ||
| 008 | Security | Contractor shall make the application session length configurable and set in accordance with agency requirements. | ||
| 009 | Usability | The solution should support table-driven variables instead of hardcoded values, enabling users with appropriate role-based permissions to add, delete, update, or view values and rows. The system must be able to immediately access these values based on the effective date ranges of the modified or added records. | ||
| 010 | Performance Efficiency | The solution must scale up or down automatically based on the demand and traffic patterns. | ||
| 011 | Security | Authentication of external users will be handled with a SAML or OIDC connection with the State's tenants in DEV, TEST and PROD environments. Internal users shall be authenticated with a SAML or OIDC connection to Entra. The State's preference is to have separate URLs for internal and external authentication. If the application can only facilitate a single auth provider but requires access for both internal and external users, Okta shall be established as the auth provider and will route internal users to Entra. If app functionality depends on internal or external status, the application must have a means to discern such states from OIDC claims, SAML attributes or other reliable method approved by the State. | ||
| 012 | Maintainability | Develop profiles and permission sets to account for users accessing multiple apps. | ||
| 013 | Maintainability | Provides out-of-the-box, pre-built visual components to easily create apps through a declarative drag and drop framework | ||
| 014 | Maintainability | Solutions Provider will assist the State in preparing the detailed infrastructure requirements. | ||
| 015 | Maintainability | Provide access to event log files to track system usage trends and user behavior such as who is logging in and from where, what pages users are viewing, and what reports users are running and exporting. | ||
| 016 | Security | Network controls will protect and control SOV data during transmission, ensuring all connected devices comply with security standards and policies. | ||
| 017 | Maintainability | The system will provide auditing and internal capabilities to generate audit logs. | ||
| 018 | Maintainability | The solution must support monitoring and logging of system events and errors to facilitate root cause analysis and troubleshooting. so SOV admins can make configuration changes when needed | ||
| 019 | Maintainability | The solution architecture will allow for transaction tracking and review throughout the system for auditing, error diagnosis, and performance management purposes. | ||
| 020 | Security | Audit records will be protected from modifications and require approval for any changes. | ||
| 021 | Maintainability | Develop profiles and permission sets to account for users accessing multiple app | ||
| 022 | Compatibility | Solutions will have the ability to support varying message payloads, ranging from individual transactions to large files (more than 1GB) containing multiple transactions. The SOA solution will be configured to appropriately manage these varying types of message construction and size through a common set of components. Where possible, solutions will error on the side of individual transactions per message to simplify the message management, routing, and database recovery needs. | ||
| 023 | Compatibility | Provide standard and custom configurable reports and dashboards in real time to analyze quality, effectiveness, satisfaction, issues, and overall performance. Reports and Dashboards can roll up from individuals to full management hierarchy, with drill-down capability. | ||
| 024 | Compatibility | Database data exports will contain all data from the State of Vermont (SOV)'s production database(s) or the subset of data specified in the data export request. | ||
| 025 | Transferability | The ability to easily transfer data from one system to another without being required to re-enter data | ||
| 026 | Compatibility | The solution must enable the sharing of particular data with other SOV and local agencies while ensuring the anonymity and complete de-identification of the data. The data must be shared in a controlled manner to ensure that only authorized personnel have access to it. The solution must enable the sharing of particular data with other SOV and local agencies while ensuring the anonymity and complete de-identification of the data. The data must be shared in a controlled manner to ensure that only authorized personnel have access to it. | ||
| 027 | Compatibility | The solution database will have data replication capabilities to external file formats or other RDBM Systems. | ||
| 028 | Compatibility | The solution database will provide standard data extraction API to allow import and export of data. | ||
| 029 | Maintainability | Solutions will include a workflow tool to support the records management process. | ||
| 030 | Maintainability | Custom fields, create new fields that are immediately searchable and reportable in the application. | ||
| 031 | Usability | Solutions will provide support for full text search. | ||
| 032 | Maintainability | Ability to track open activities and activity history, from the portal | ||
| 033 | Compatibility | Solutions will support authoring and management of solution data. Solutions will provide a flexible and comprehensive workflow-based capability that can be used to create and maintain workflows supporting solution data maintenance across the multiple source solutions. | ||
| 034 | Transferability | Solutions will have a defined data migration strategy or process. | ||
| 035 | Compatibility | Solutions will provide the ability for on-line access by any site connected to the State of Vermont's Network. | ||
| 036 | Compatibility | The solution will provide standard data extraction API to allow import and export of data at rest | ||
| 037 | Maintainability | Solutions Provider will perform Refreshes based on a submitted and approved change request from the State. | ||
| 038 | Security | Use of digital signatures or secure mechanisms to authenticate senders of messages or transactions. | ||
| 039 | Maintainability | Duplicate Management: The solution must provide a duplicate management capability to help maintain clean and accurate data. | ||
| 040 | Usability | Solutions will roll-up (summarize data) and drill-down (view details) in reports online. | ||
| 041 | Compatibility | The software shall support easy data migration from the current version to future versions of the software, ensuring that users can upgrade without losing any important data or functionality | ||
| 042 | Security | Solutions will maintain records of all data additions, changes, and deletions, searchable by user/client ID, date/time, location, and other details. | ||
| 043 | Maintainability | Provide ability to track the changes that users make to field values in the system. | ||
| 044 | Maintainability | The Solution must be documented with clear and concise comments, diagrams, and user manuals that explain the functionality, architecture, and dependencies of each component. | ||
| 045 | Usability | The Solution should be able to generate the plain text nesting of rules automatically, using a clear and readable format that can be easily understood by both technical and non-technical users. The plain text nesting should also be able to display the hierarchy of rules and the conditions under which they are applied, providing a comprehensive view of the rule set. This capability will support effective rule management and maintenance, ensuring that the system can continue to enforce business rules effectively over time. | ||
| 046 | Compatibility | Solutions will support the industry standards for messaging, receiving and sharing data and interfaces relevant to health and human services organizations including, but not limited to: FHIR Version 4.0 and Electronic Data Interchange (EDI) X12 healthcare format. The versioning for these products must be maintained to meet the evolving requirements of the State of Vermont 's (SOV's) CMS and ONC and any other bodies that dictate these standards. | ||
| 047 | Agility | The solution must learn from the feedback and data collected from the customers and users by analyzing, interpreting, reporting, etc. them. | ||
| 048 | Performance Efficiency | The solution must have a user interface with a clear and consistent navigation and layout that is easy for users to understand and use. The navigation and layout should be designed in a way that aligns with the user's expectations and mental model, meaning it should be intuitive and follow common design patterns. | ||
| 049 | Usability | Solutions will support reporting requirements either natively or integrate with other reporting tools to provide reporting. | ||
| 050 | Performance Efficiency | Solutions will provide the ability to optimize individual queries and support parallelizing a query to run on multiple CPUs at the same time to increase performance | ||
| 051 | Agility | The solution must monitor and measure the usage, performance, quality, and satisfaction of the service using analytics and feedback mechanisms. | ||
| 052 | Maintainability | Must have flexible customer portal user access and identity management | ||
| 053 | Security | The hosting service provider will manage access control to its data centers and the environment, limiting access to State of Vermont's (SOV's) network connections. | ||
| 054 | Usability | Solutions will provide the ability to store electronic forms (solution generated or 3rd-party generated forms). | ||
| 055 | Compatibility | Solution will integrate with the State of Vermont Master Person Index (MPI) using the State's Integration Platform and adhere to the State rules for MPI determinations and processing. MPI covers all customer, provider and other human references. | ||
| 056 | Security | Access provisioning is centralized and based on job roles, requiring management approval. | ||
| 057 | Maintainability | For document management functions, Solutions will use a centralized, shared document management/content management solution. | ||
| 058 | Security | All Hosting Service Provider personnel will use a software VPN client to connect to the HPISN. Upon initiating a VPN session, employees will authenticate with a username and password. Once authenticated, each employee will be assigned a static IP address specific to that VPN concentrator. This method reduces security risks like IP spoofing, as the client software enforces the assigned IP based on user identity rather than device MAC address. | ||
| 059 | Reliability | Solution provider will monitor critical performance parameters: these can included: CPU usage: the percentage of CPU resources consumed by the software. High CPU usage can affect the responsiveness and speed of the solution. Memory usage: the amount of memory allocated by the software. High memory usage can indicate high resource consumption and affect the performance of the solution Requests per minute and bytes per request: the number of requests received by the software's API per minute and the amount of data handled by each request. Latency and uptime: the delay between a user's action on the software and the response of the software to that action, and the availability of the software to serve requests. Security exposure: the degree to which the software is vulnerable to unauthorized access, modification, or damage. Execution time: the time taken by the software to complete a certain function or task. Throughput: the rate at which the software can process data or transactions. | ||
| 060 | Security | Contractor shall ensure that all logout triggers, which are to be provided to all authenticated external users, are effective at terminating both the app session and the Okta SSO session. | ||
| 061 | Compatibility | If necessary and required for the solution, electronic data exchange refers to the standardized, machine-readable exchange of data between systems or applied Electronic data exchange refers to the standardized, machine-readable exchange of data between systems or applications. Standards for electronic data exchange vary by industry, with examples including HL7 and FHIR for healthcare, and SWIFT and FIX for finance. | ||
| 062 | Agility | The solution must support multiple languages, currencies, time zones, and regional settings for different markets and users. | ||
| 063 | Maintainability | Solutions Provider will leverage State of Vermont's Enterprise Data/Object Model to facilitate standardized reporting, ad hoc queries, list views and dashboards. | ||
| 064 | Compatibility | If necessary and required for the solution, electronic data exchange refers to the standardized, machine-readable exchange of data between systems or applications. Electronic data exchange refers to the standardized, machine-readable exchange of data between systems or applications. Standards for electronic data exchange vary by industry, with examples including HL7 and FHIR for healthcare, and SWIFT and FIX for finance. | ||
| 065 | Compatibility | Solutions will include the following types of transformation: Simple transformations, e.g., data-type conversions, string manipulations and simple calculations. Moderate-complexity transformations, e.g., lookup and replace operations, aggregations, summarizations, deterministic matching and management of slowly changing dimensions. Higher-order transformations, e.g., sophisticated parsing operations on free-form text and rich media. Facilities for developing custom transformations and extending packaged transformations. | ||
| 066 | Usability | Solutions will permit all users (dependent on role-based security and access rights) to have current and up-to-date information regarding a client's information when connected to solutions, given the operational and technical constraints of the data source(s). The data displayed will be time-stamped to reflect the currency of the data. | ||
| 067 | Compatibility | Solution will define the requirement for all software to support data integration with other systems | ||
| 068 | Maintainability | Applications shall be meta-data driven and allow for common meta-data use across differing lines of business and different instance/orgs. | ||
| 069 | Maintainability | Solutions Providers will provide version control management capability. All changes to Solutions will be reported and approved by the State, and will be maintained in the Solutions Provider's version control management solution, which will be available to the State for review and audit. | ||
| 070 | Maintainability | Solutions Providers will provide the required system permissions, documentation and training that describes the procedures for Solution administrators to add, update or inactivate user IDs and passwords. | ||
| 071 | Usability | Service Providers will develop a user guide that can be accessed online and printed on demand. | ||
| 072 | Maintainability | The solution must support automated testing, with clear and well-defined test cases and test data. | ||
| 073 | Transferability | Vendor will work in a Development and Test environment prior to promoting the code to production | ||
| 074 | Security | The hosting provider will evaluate and respond to incidents of unauthorized access or handling of SOV data, working with relevant teams and law enforcement to restore confidentiality, integrity, and availability of SOV's environment. | ||
| 075 | Usability | The solution will support dynamic rule change, enabling users to modify rules on the fly without requiring system downtime. The solution should also separate rules from the engine, making it easier to update rules without affecting the underlying engine. | ||
| 076 | Transferability | The system may adapt its user interface according to the user's preferred language and locale | ||
| 077 | Usability | Solutions will enable indexing and searching of documents. | ||
| 078 | Reliability | For PaaS and IaaS solution providers, backup and Recovery Services will include operating system images, configuration files, database, code tree, hardware configurations and virtualization configurations. (PaaS, IaaS) | ||
| 079 | Maintainability | The solution must support version control and rollback capabilities to facilitate quick and easy reversions in case of errors or issues with new updates. | ||
| 080 | Security | When user requests to log in, or requests an authenticated page, they shall be redirected to the State's central login widget (currently at my.vermont.gov) in order to ensure that the user is challenged with state approved authenticators in a state approved user experience. | ||
| 081 | Transferability | Solutions will support access from multiple channels and devices. | ||
| 082 | Usability | Mobile Applications shall support offline capabilities, limited to essential business process for field work. i.e. fillable form fields which sync-up with cloud platform when device is back online. | ||
| 083 | Maintainability | Applications shall support configurable field level security controls | ||
| 084 | Usability | Solutions will provide the capability to allow the user to manually remove, rescan and replace a previously scanned image or document(s). | ||
| 085 | Maintainability | Solutions Provider will use DNS instead of host files. | ||
| 086 | Compatibility | The solution provider will meet requirements as identified in the corresponding HL7 FHIR Implementation Guides (IG) for Blue Button, PDEX and others as apropos and these Blue Button IGs will be considered the standards needed for 3rd parties to access the data. | ||
| 087 | Accessibility | The State of Vermont (SOV) will access applications through a URL entered in a web browser. | ||
| 088 | Accessibility | If a survey engine is required for the solution, the survey engine must provide robust configuration options to create, distribute, and analyze surveys effectively. | ||
| 089 | Accessibility | Solutions will provide support for a web content management solution that is robust, scalable, and provides workflow management. | ||
| 090 | Accessibility | The solution should be designed to provide secure, scalable, accessible storage and retrieval of policy and procedure content, allowing users to quickly find and access information, with robust search capabilities, version control, and collaboration among multiple stakeholders. | ||
| 091 | Accessibility | Information will be provided to applicants and enrollees in plain language, consistent with Section 504 and Section 508 of the Rehabilitation Act, including accessible web sites and the provision of auxiliary aids and services at no cost to individuals with disabilities, and language access services for individuals with limited English proficiency such as interpretation, translations, and non-English taglines indicating the availability of language services. | ||
| 092 | Accessibility | Solutions will provide speech and hearing impaired persons with the ability to communicate using a Teletypewriter (TTY) or Telecommunications Display Device (TDD), as applicable to the solution's communication channels. | ||
| Accessibility | The solution shall conform to applicable digital accessibility standards, including at minimum WCAG 2.1 Level AA for all web and mobile user interfaces, Section 508 requirements for electronic and information technology, and any applicable provisions of the DOJ Web and Mobile App Accessibility Final Rules for public services.The system shall accommodate a wide range of assistive technologies and shall be tested to ensure compliance with accessibility guidelines. | |||
| 093 | Accessibility | Accessibility requirements shall apply to all user facing components of the solution, including portals, mobile applications, administrative interfaces used by staff, generated documents, forms, and embedded widgets or third party components that affect the user experience. | ||
| 094 | Accessibility | The contractor shall provide a current Accessibility Conformance Report, using the appropriate VPAT template, for each product or major module with a user interface prior to contract award or prior to solution going live, and shall provide an updated report within 14 business days of any major release that affects the user interface. | ||
| 095 | Accessibility | The contractor shall document all known accessibility limitations of the solution, their impact on users with disabilities, and planned remediation timelines, and shall provide this documentation with the Accessibility Conformance Report and upon request by the State. | ||
| 096 | Accessibility | The solution shall support effective use with common assistive technologies on supported platforms and browsers, including screen readers, screen magnifiers, and speech input tools, without loss of functionality compared to non assisted use. | ||
| 097 | Accessibility | All interactive elements in the solution shall be fully usable with keyboard only input, with visible focus indicators and a logical tab order, and the solution shall expose a meaningful semantic structure, including headings, landmarks, labels, and status messages, to allow efficient navigation by users of assistive technologies. | ||
| 098 | Accessibility | The contractor shall conduct accessibility testing using automated tools, manual expert review, and assistive technologies, and shall provide test plans and results to the State. The contractor shall review the accessibility testing results to determine severity of issues. | ||
| 099 | Accessibility | No release shall be promoted to production until critical and high severity accessibility defects identified by the State have been remediated or are covered by an approved exception and interim alternate access method. | ||
| 100 | Accessibility | For solutions identified by the State as high impact, usability and accessibility testing shall include participation by users with disabilities and assistive technologies, and findings from this testing shall be documented and incorporated into design and implementation decisions. | ||
| 101 | Accessibility | Accessibility defects shall be classified and remediated according to provisions in the agreed service levels such as the minimum as follows: critical defects that block users with disabilities from completing primary tasks shall be mitigated within five (5) business days and fully remediated within thirty (30) calendar days; high severity defects that significantly degrade usability shall be mitigated within ten (10) business days and fully remediated within sixty (60) calendar days. | ||
| 102 | Accessibility | The contractor shall participate in periodic accessibility reviews with the State at least annually and after any major release affecting the user interface, and shall provide updated accessibility test results and Accessibility Conformance Reports as part of these reviews. | ||
| 103 | Accessibility | The contractor shall designate an accessibility lead responsible for coordinating accessibility activities and responding to State inquiries, and shall ensure that personnel involved in design, development, testing, and support receive role appropriate training on digital accessibility standards and assistive technologies. | ||
| 104 | Accessibility | The solution and associated support processes shall provide a clearly identified mechanism for users to report accessibility issues and request accommodations, and such reports shall be captured, tracked, and remediated within the same service levels that apply to other critical defects. | ||
| 105 | Security | Any user/station limitations will be equally and universally imposed by the solution. Examples include passwords changed via downstream CAD/Integration will meet the same password complexity requirements. Limitations surrounding which stations a user can logon to will be enforced regardless of station classification or access method. | ||
| 106 | Security | The solution will configure the system to allow users to log in with a Single Sign On (SSO) experience using a federated Identity Provider. The system should support SSO via SAML and support AD FS as an Identity Provider. | ||
| 107 | Security | The solution shall require users to use multifactor authentication to log in order to meet CJIS Security Policy requirements. ADS IT should be able to help users configure MFA and revoke lost MFA devices without needing vendor support. | ||
| 108 | Accessibility | The solution shall be able to unlock accounts and reset passwords for users in agencies I support as a TAC so that I can get my staff back online quickly when they have a password/account issue | ||
| 109 | Usability | The contractor shall designate an accessibility lead responsible for coordinating accessibility activities and responding to State inquiries, and shall ensure that personnel involved in design, development, testing, and support receive role appropriate training on digital accessibility standards and assistive technologies. | ||
| 110 | Usability | The solution and associated support processes shall provide a clearly identified mechanism for users to report accessibility issues and request accommodations, and such reports shall be captured, tracked, and remediated within the same service levels that apply to other critical defects. | ||
| 111 | Usability | Facilitate development of a governance model for the solution, recognizing the breadth of user groups and decentralized decision-making hierarchy. | ||
| 112 | Compatibility | Facilitate development of templates for data sharing agreements across the user community and across vendors currently, and in the future, in the technical ecosystem that interacts with the solution. | ||
| 113 | Maintainability | Facilitate Business Architecture re-design for future use of the solution, optimizing processes for efficiency and data integrity. Document processes in the form of job aids and on-boarding materials for new employees. | ||
| 114 | Usability | Following PROSCi's ADKAR model, facilitate solution adoption by generating awareness, interest and engagement, process and solution training, and support during go-live and during the hypercare period. | ||
| ID # | Non-Functional Requirement Description | Comply | Vendor's Description of Applicable Security Processes | Audit/Monitor Process |
|---|---|---|---|---|
| S1 | Input validation | |||
| S2 | Output encoding | |||
| S3 | Authentication and password management | |||
| S4 | Session management | |||
| S5 | Access control | |||
| S6 | Cryptographic practices | |||
| S7 | Error handling and logging | |||
| S8 | Data protection from unauthorized use, modification, disclosure or destruction (accidental or intentional). | |||
| S9 | Communication security | |||
| S10 | System configuration | |||
| S11 | Database security | |||
| S12 | File management | |||
| S13 | Memory management | |||
| S14 | Fraud detection | |||
| S15 | General coding practices | |||
| S16 | POA&M management | |||
| S17 | Risk Assessment Practices including but not limited to vulnerability assessment and pen testing | |||
| S18 | Incident response planning and testing | |||
| S19 | System Security Plan delivery | |||
| S20 | As a State security and privacy lead I want compliant security controls, assessments, and protected environments so that systems meet Federal and State privacy, audit, and cybersecurity standards. | |||
| S21 | The Contractor must develop and keep current a State-approved System Security Plan. | |||
| S22 | The Contractor must meet the applicable State and Federal privacy and security standards in the hosting and support of all infrastructure. | |||
| S23 | The Contractor must provide secure access as applicable and appropriate to the development and test environments to a subset of authorized users. Authorization must be by each environment and conform to the security protocols used by the State. | |||
| S24 | The Contractor must ensure development and test environments have sufficient security controls in place to prevent unauthorized access. | |||
| S25 | The Contractor must ensure that test environments, aligned with State standards and approval, mask critical and sensitive data as required for distribution. This includes data classified as Protected Health Information (PHI) and Personally Identifiable Information (PII). | |||
| S26 | The Contractor must ensure that test environments must adhere to the same level of security compliance for such data as required in a production environment, unless authorized otherwise in writing by the State. | |||
| S27 | The Contractor must provide appropriate system access and/or a walk-through of any Contractor facilities and operations as directed by the State to facilitate external and internal audits. | |||
| S28 | The Contractor must, throughout all phases of this Contract, adhere to 42 CFR 434.6(a)(5), which allows evaluation by Federal Partners through inspection or other means, of the quality, appropriateness, and timeliness of services performed under this Contract. | |||
| S29 | The Contractor must provide an independent, third-party security and privacy controls assessment report that covers compliance with NIST SP 800-171 and/or NIST SP 800-53 standards and all relevant controls in the Health Insurance Portability and Accountability Act (HIPAA); aligning Health Care Industry Security Approaches pursuant to Cybersecurity Act of 2015, Section 405(d); and the Open Web Application Security Project Top 10. |
| ID # | Non-Functional Requirement Description | Comply | Vendor's Description of Compliance |
|---|---|---|---|
| TESTING AND QUALITY MANAGEMENT | |||
| GR-0008 | As a State quality lead, I want quality and testing activities managed under approved standards and plans so that the system meets performance, compliance, and operational expectations. | ||
| GR-00094 | The Contractor must develop and keep current a State-approved Quality Management Plan that is consistent with ISO 9001:2015, Quality Management System (QMS), Total Quality Management (TQM), SSAE18 SOC 2 Type 2, and Continuous Quality Improvement principles and standards. | ||
| GR-00095 | The Contractor must collaborate with the State and all State-identified Contractors/partners to achieve and maintain quality system and operational services in accordance with Stateapproved performance metrics and benchmarks. | ||
| GR-00096 | The Contractor must implement Stateapproved performance improvements, in a method and manner that is consistent with ISO, QMS, TQM, SSAE16, and Continuous Quality Improvement principles and standards. | ||
| GR-00097 | The Contractor must lead, coordinate, and be responsible for all project quality assurance management, documentation quality assurance, and quality assurance testing meetings as requested and required under the Quality Management Plan and/or by the State. | ||
| GR-00098 | The Contractor must assign a dedicated resource to lead the quality assurance staff during the design, development, and implementation phases. This resource will ensure that process improvements are executed in alignment with Lean Six Sigma principles or other standards such as ISO, QMS, TQM, SSAE16, and Continuous Quality Improvement. | ||
| GR-00099 | The Contractor must provide adequate and dedicated staff to implement, monitor, and address all quality assurance and improvement activities required under the Quality Management Plan. | ||
| GR-00100 | The Contractor must take a proactive role in identifying and addressing quality control issues within the solution in the effort to meet or exceed performance benchmarks/metrics for the State. | ||
| GR-00101 | The Contractor must develop and keep current a State-approved Test Management Plan. | ||
| GR-00102 | The Contractor must collaborate with other project Contractors to ensure the Test Management Plan establishes test frameworks and test objectives, supporting all Contractors and partners involved in the solution. | ||
| GR-00103 | The Test Management Plan must comply with ISO/IEC/IEEE 29119-3:2021 standards. | ||
| GR-00104 | The solution must enable State-approved users to load data into development, testing, training, and other non-production environments. | ||
| GR-00105 | The Contractor must provide secure access as applicable and appropriate to the development and test environments to a subset of authorized users. | ||
| GR-00106 | The Contractor must ensure development and test environments enable access to appropriate devices and resources required to connect to the State environment. | ||
| GR-00107 | The Contractor must implement a User Acceptance Test (UAT) environment so there is a dedicated environment for user acceptance testing activities. | ||
| GR-00108 | The solution must adhere to established and mutually agreed-upon standards, procedures, and protocols for data loading into non-production environments. | ||
| GR-00109 | The Contractor must develop, for each system change, a State-approved suite of test cases that includes the test scope, approach, and tools, and is used to complete testing and provide the documented test results to the State. | ||
| GR-00110 | The Contractor must provide resources to assist, complete, and submit results, in a State-approved format, of all comprehensive system(s) tests as documented in the State-approved Test Management Plan. | ||
| GR-00111 | The Contractor must provide sufficient time and resources for all testing performed by the Contractor, and to support testing done by entities other than the Contractor. | ||
| GR-00112 | The Contractor must ensure that all draft deliverables meet the State's minimum expectations for grammar, spelling, formatting, and overall quality, with revisions made at no additional cost and without impacting the project schedule. | ||
| TRAINING & SUPPORT | |||
| GR-0009 | As a user support administrator, I want training, user guides, and help desk services delivered using State standard so that users are supported and enabled throughout system adoption. | ||
| GR-00113 | The Contractor must develop and keep current a State-approved User Training Plan. | ||
| GR-00114 | The Contractor must develop and keep current a searchable, web-based, interactive, State-approved User Guide. The User Guide should have smart documentation (linked issues, typeahead, suggestions based on problem statements, workflow documentation). | ||
| GR-00115 | The User Guide must be used as part of the basis for user training, unless otherwise specified by the State. | ||
| GR-00116 | The Contractor must develop and keep current training materials in compliance with Americans with Disabilities Act of 1990 (ADA) standards. Any identified changes to training materials to comply with this requirement must be addressed at no cost to the State. | ||
| GR-00117 | The Contractor must provide training to the State, its agents, and Successor Contractor(s). | ||
| GR-00118 | The Contractor must develop and keep current a State-approved Help Desk Plan. | ||
| GR-00119 | The Contractor must maintain a State-approved help desk support function that enables users to submit requests through a web portal during State business days, 7 a.m. ET to 7 p.m. ET. | ||
| GR-00120 | The Contractor must maintain a State-approved help desk support function that enables users to submit requests by phone during State business days, 7 a.m. ET to 7 p.m. ET. | ||
| GR-00121 | The Contractor must provide technical assistance as needed to assist users in researching problems, reviewing production outputs, and understanding report formats. | ||
| GENERAL TRANSITION REQUIREMENTS | |||
| GR-EPIC-01 | As a State program executive and governance lead, I want the Contractor to establish, maintain, and operate comprehensive administrative, technical, and operational management frameworks across all project disciplines-including project management, staffing, financial management, communications, documentation, technical design, infrastructure, security, quality assurance, training, operations, business continuity, and transition activities-in full alignment with State-approved standards, tools, plans, and governance processes, so that the solution is delivered and sustained with consistent quality, accountability, transparency, security, and compliance throughout all phases of the contract lifecycle, while minimizing risk and ensuring seamless coordination across all stakeholders and technical components. | ||
| GR-FEA-01 | As a State project manager, I want the Contractor to plan, manage, and report project activities using State-approved tools and plans so that the project is executed consistently, collaboratively, and in alignment with State governance standards. | ||
| GR-00001 | The Contractor must follow project management methodologies as directed by the State that are consistent with the Project Management Institute's (PMI) Project Management Body of Knowledge (PMBOK) Guide v7 and Agile project management. | ||
| GR-00002 | The Contractor must use the State-managed SharePoint Online Project Management Repository in accordance with State standards and expectations. | ||
| GR-00003 | The Contractor must complete the activities specified in the Enterprise Project Management Office (EPMO) Project Lifecycle as published on the EPMO public-facing website. | ||
| GR-00004 | The Contractor must provide, on a weekly basis, a current project schedule in Microsoft Project format (v2013 or later). | ||
| GR-00005 | The Contractor must maintain a decision log, risk log, and issue log (in State-approved tools), updated at least weekly, with clear owners and due dates. | ||
| GR-00006 | The Contractor must actively collaborate with all State-approved Contractors and Subcontractors, sharing information, designs, and schedules necessary to achieve an integrated solution. | ||
| GR-00007 | The Contractor must participate in State-facilitated cross-vendor forums, and align to shared standards, environments, calendars, and schedules as directed by the State. | ||
| GR-00008 | If an inter-vendor conflict cannot be resolved collaboratively within five business days, the Contractor must escalate the issue to the State no later than one business day thereafter. | ||
| GR-00009 | The Contractor must review, provide feedback on, signoff, and conform to the project's State-authored Business Analysis Plan. | ||
| GR-00010 | The Contractor must follow business analysis methodologies that are consistent with the International Institute for Business Analysis (IIBA) Guide to Business Analysis Body of Knowledge (BABOK) v3. | ||
| GR-00011 | The Contractor must collaborate with the State to elicit user stories and requirements at sufficient detail to ensure the solution meets the needs of the State. | ||
| GR-00012 | The Contractor must maintain and manage all requirements, user stories, and business rules in the State's Azure DevOps (ADO) tenant per the direction of the State. | ||
| GR-00013 | The Contractor must develop and keep current a State-approved Risk Management Plan. | ||
| GR-00014 | The Contractor must develop and keep current a State-approved Implementation Plan that outlines the approach for the design, development, and implementation of all technology and services in accordance with the solution scope. | ||
| GR-00015 | The Contractor must, upon Contract execution, participate in the project Steering Committee, which will govern and steer the project. | ||
| GR-00016 | The Contractor must review, provide feedback on, signoff, and conform to the project's State-authored Change Management Plan. | ||
| GR-00017 | The Contractor must collaborate with all State-approved Contractors and Subcontractors under the direction of the State Change Control Board to manage change within a multi-Contractor, integrated systems solution as it relates to any system- or non-system-based changes, modifications, or maintenance activities, efforts, tasks, or projects | ||
| GR-00018 | The Contractor must identify the impact of data source changes to all solution components and capabilities, so that the changes may be verified to be in accordance with the approved Change Management Plan. | ||
| GR-00019 | The Contractor must monitor and inform the State of industry changes that may have an impact on business processes or on systems covered by the Contract, so that the State can prepare for and implement any necessary updates and stay aligned with industry changes and best practices. | ||
| GR-00020 | The Contractor must review, provide feedback on, signoff, and conform to the project's State-authored Scope Management Plan. | ||
| GR-00021 | The Contractor must develop a State-approved Project Kickoff Deck. | ||
| GR-00022 | The Contractor must review, provide feedback on, signoff, and conform to the project's State-authored Schedule Management Plan. | ||
| GR-00023 | The Contractor must review, provide feedback on, signoff, and conform to the project's State-authored Deliverables Matrix. | ||
| Human Resources & Staffing Management | |||
| FEA-GF-02 | As a State contract manager I want visibility and oversight of Contractor staffing and personnel so that the project maintains qualified, available, and accountable resources. | ||
| GR-00024 | The Contractor must keep current, on the State's SharePoint site, a Personnel Table of all Contractor staff and Subcontractor staff associated with the project. The Personnel Table must provide: (a) Full name (b) Business phone number (c) Business email address (d) Project role (e) Project responsibilities. | ||
| GR-00025 | The Contractor must develop and keep current a State-approved Organizational Chart of all Contractor and Subcontractor personnel working on the project. | ||
| GR-00026 | The Contractor must provide the State with resumes for Contractor and Subcontractor staff working on the project. | ||
| GR-00027 | The Contractor must ensure vacant positions supporting this Contract are filled within 60 calendar days of date of vacancy or obtain written approval by the State for extended vacancies. | ||
| GR-00028 | The Contractor must provide the State 20 business days or more advance notice of any plans to change, hire, or reassign personnel supporting this Contract. | ||
| GR-00029 | The Contractor must notify the State within one business day of the replacement, reassignment, resignation, or termination of any personnel directly supporting this Contract. | ||
| GR-00030 | The Contractor must replace or reassign personnel supporting this Contract for cause (i.e., where the State can demonstrate a reason) at the State's request. The State shall report to Contractor any concerns regarding Contractor Personnel that may lead the State to make such a request with sufficient detail and time for Contractor to take corrective measures. | ||
| GR-00031 | The Contractor must conduct an initial criminal background check/investigation on all new hires supporting this Contract as well as conduct follow-up criminal investigations every two years, if requested, for all staff supporting this Contract. The costs for the initial criminal background check must be the responsibility of the Contractor. | ||
| GR-00032 | The Contractor's staffing solution may include staff located both within the United States as well as outside the United States. | ||
| GR-00033 | The Contractor must ensure that all licensed Contractor staff maintain current licensure required for their role on the project, with no State or Federal sanctions. | ||
| GR-00034 | The Contractor must cross train its staff to prevent loss of knowledge and expertise when staff leave, as well as to minimize negative impacts to project timelines due to resource availability. | ||
| GR-00035 | The Contractor must keep current a State-approved process for immediate removal, with just cause or reason, physical and remote access to systems and facilities for Contractor or Subcontractor employees deemed unfit to continue employment. | ||
| GR-00036 | The Contractor must develop and keep current a State-approved Resource Management Plan. | ||
| GR-00037 | The Contractor must bear the costs of changes, hires, or reassignment of Contractor personnel. | ||
| GR-00038 | The Contractor must develop and apply onboarding and training processes for new staff and turnover in staff. | ||
| Contract & Financial Management | |||
| FEA-GF-03 | As a State financial administrator, I want Contractor invoicing, subcontractor oversight, and legal responses managed consistently so that financial compliance, accountability, and transparency are maintained. | ||
| GR-00039 | The Contractor must develop and keep current a State-approved process for all invoicing activities. | ||
| GR-00040 | The Contractor must correct and reissue invoices within 10 business days of State notification. | ||
| GR-00041 | The Contractor must make all Subcontractor agreements available to the State upon request. | ||
| GR-00042 | The Contractor must be responsible/accountable for all subcontracted work assigned, including responsibility for enforcement and oversight of subcontractors and their compliance with all State and Federal contractual terms/provisions as included within this Contract. | ||
| GR-00043 | For any Subcontract, the Contractor must identify a designated Subcontractor contact who is accessible to the State. | ||
| GR-00044 | The Contractor must provide, at no cost to the State, information and data as requested by the State to fulfill requests for litigation, subpoenas, open record requests, or other legal actions. | ||
| GR-00045 | Upon State request, the Contractor must provide staff and resources to assist the State with preparing and reviewing materials planned to be shared at forum(s), such as national organizations and conferences, on efforts related to this Contract. | ||
| Communications and Document Management | |||
| FEA-GF-04 | As a State project manager, I want project documentation and communications managed using State standards so that information is accurate, compliant, and accessible. | ||
| GR-00046 | The Contractor must review, provide feedback on, signoff, and conform to the project's State-authored Communication Management Plan. | ||
| GR-00047 | The Contractor must notify the State of all legislative, executive level, and media inquiries with respect to this project and forward any such inquiries to the State within one business day of the Contractor's awareness of said inquiry. | ||
| GR-00048 | The Contractor must not respond to legislative, executive level, or media inquiries regarding the project unless directed by the State, except where required by law. | ||
| GR-00049 | The Contractor must ensure all communications conform to State of Vermont brand standards as issued by the Chief Marketing Office. | ||
| GR-00050 | The Contractor must ensure that the Contractor's own name, logo, or any reference to the Contractor are not included in any public-facing communications with respect to this project, unless approved by the State. | ||
| GR-00051 | The Contractor must develop and keep current a State-approved Deliverables Management Plan. | ||
| GR-00052 | The Contractor must update and maintain all Project Deliverables on a mutually agreed upon cadence as approved by the State. | ||
| GR-00053 | The Contractor must prepare, update, revise, and submit to the State for approval all operational, systems, or reportingbased documentation (in all original forms/media) as they relate to system changes, maintenance, or modification work requests. | ||
| GR-00054 | The Contractor must create and maintain all system and technical documentation for the solution. | ||
| GR-00055 | System and technical documentation must utilize Stateapproved language, diagrams, and structure. | ||
| GR-00056 | The Contractor must utilize the State-approved Project Management Repository as well as any other State-required document repository to maintain systemrelated business, technical, and operational documentation. | ||
| GR-00057 | The Contractor must ensure all documentation is readily available online and electronically maintained, retained, archived, and restored as required by all document and data retention laws, including any applicable litigation hold. | ||
| GR-00058 | The Contractor must ensure all documentation is prepared and accessible using current State standard/approved software packages. | ||
| GR-00059 | All project documentation must be reviewed and approved by the State prior to publication. | ||
| GR-00060 | The Contractor must provide new, routinely maintained, and updated documentation for all contracted functions in accordance with the Stateapproved documentation development, maintenance, and quality review process. | ||
| GR-00061 | The Contractor must maintain a documentation standard that aligns with the standards and templates set forth by the State and other contracted Contractors and utilize the approved standard throughout the life of the Contract. | ||
| GR-00062 | The Contractor must revise any required documentation deliverable if requested to do so by the State. | ||
| GR-00063 | The Contractor must maintain complete and detailed records of all Contractor-facilitated meetings with the State related to the Contract, software development lifecycle documents, presentations, project artifacts, and any other interaction and post and maintain these artifacts in the Project Management Repository within five business days of the meeting or interaction. | ||
| GR-00064 | The Contractor must secure State approval prior to any representation or presentation of documentation related to this project, including any local, State, national conferences, or other public or private forums. | ||
| TECHNICAL DESIGN & IMPLEMENTATION | |||
| FEA-GF-04 | As a State enterprise architect I want system, interface, and data design documentation maintained and approved so that technical components are traceable, consistent, and support integrated operations. | ||
| GR-00065 | The Contractor must develop and keep current a State-approved Business Design/System Design Document. | ||
| GR-00066 | The Contractor must create and keep current documentation of all operational, system, and technical processes as they relate to the solution. | ||
| GR-00067 | The Contractor must develop and keep current a State-approved Interface Control Document that documents all data elements, processes, methodologies, mechanisms, protocols, and other related information for each data source. | ||
| GR-00068 | The Contractor must document and keep current all conceptual, logical, and physical models for all database service layers and supporting data stores and make the models available online to the State. | ||
| GR-00069 | The Contractor must store all conceptual, logical, and physical models in a State-approved repository. | ||
| GR-00070 | The Contractor must complete all conceptual, logical, and physical models to reflect the most current updates or changes based on approval by the State 10 business days prior to implementation of the planned change. Updates must be published to users at the time of implementation. | ||
| GR-00071 | The Contractor must provide documentation that describes the contents, format, and structure of all databases and the relationships among all database objects. | ||
| GR-00072 | All user interfaces must comply with the most recent version of Section 508 Standards and WCAG Level A and AA Success Criteria. | ||
| Operations and Maintenance Management | |||
| FEA-GF10 | As a State operations manager, I want maintenance, defect management, release control, and performance monitoring so that system stability and operational continuity are sustained. | ||
| GR-00122 | The Contractor must develop and keep current a State-approved System Maintenance Support Plan. | ||
| GR-00123 | The Contractor must provide Maintenance Support activities during certification and transition to the maintenance and operations vendor(s). This includes making changes to existing functionality and features that are necessary to continue proper system and/or operational services. | ||
| GR-00124 | The Contractor must perform and complete all work necessary to correct and resolve each defect identified in the solution. | ||
| GR-00125 | The Contractor must utilize Microsoft Azure DevOps, the State-approved online Defect Management tool, for the identification, impact assessment, definition, traceability, verification, and reporting of all defects and resolutions. | ||
| GR-00126 | The Contractor must conduct development walk-throughs as appropriate to demonstrate to the State that all functions have been completely and accurately planned, developed, and unit tested. | ||
| GR-00127 | The Contractor must, in coordination with the State, maintain a comprehensive lessons-learned repository in the State's Azure DevOps tenant that is a knowledge base of all lessons learned. | ||
| GR-00128 | The Contractor must detect, log, notify, and respond appropriately to errors and exceptions in both system and data processing. | ||
| GR-00129 | The Contractor must collaborate with the source system Contractor to resolve bad or otherwise corrupt data in accordance with the data quality review process timelines. | ||
| GR-00130 | The Contractor must maintain a data quality review process for the identification and resolution of corrupt or bad data. | ||
| GR-00131 | The Contractor must develop and keep current a State-approved Release Management Plan. | ||
| GR-00132 | The Contractor must have the ability to selectively move modifications on a release schedule with State approval, with the flexibility to selectively back out system changes prior to a release (last minute) without significant resources or impact (point in time restore). | ||
| GR-00133 | The Contractor must implement improvements, changes, or enhancements following a State-approved approach that must enable all other environments to update and mirror the "new" production functionality. | ||
| GR-00134 | The Contractor must provide, as part of the Release Management Plan, a Network Design and Monitoring Plan for an optimally performing computing and data transporting environment. | ||
| GR-00135 | The Contractor must implement a configuration management process with established promotion and version control procedures for the implementation of a multi-Contractor, integrated system-wide enterprise. | ||
| GR-00136 | The Contractor must maintain, as part of the Release Management Plan, change management metadata regarding all system application release and operational performance and behavior. | ||
| GR-00137 | The Contractor must provide a quarterly Configuration Management Summary report providing a high-level overview of any changes to the system baseline configuration and operational usage. | ||
| GR-00138 | The Contractor must document and maintain State-approved standard maintenance windows for system maintenance and downtime that are coordinated across solutions and minimize stakeholder disruption. | ||
| GR-00139 | The Contractor must obtain State approval before initiating scheduled and emergency maintenance windows and system outages. | ||
| GR-00140 | The Contractor must document all incidents in accordance with the State standard Incident Reporting Form template. | ||
| GR-00141 | The Contractor must notify affected State stakeholders of scheduled and emergency maintenance windows and system outages. | ||
| GR-00142 | The Contractor must develop and keep current a State-approved Performance Management Plan. | ||
| GR-00143 | The Contractor must allow a State representative to participate in any Contractor-facilitated user group that is associated with any part of the solution. | ||
| GR-00144 | The Contractor must develop and keep current a State-approved Operating Procedures Guide. | ||
| GR-00145 | The solution must include exception handling mechanisms to facilitate error correction and/or auditing across all components of the solution without impacting concurrent, overall operations, as well as reporting of exceptions to the State. | ||
| GR-00146 | The Contractor must transcribe the lessons-learned repository to a lessons-learned report within 60 business days after the project is completed. | ||
| Business Continuity and Disaster Recovery | |||
| FEA-GF11 | As a State continuity and risk program owner I want reliable BC/DR/CIR planning, exercises, and recovery capabilities so that critical operations can resume during incidents or outages. | ||
| GR-00147 | The Contractor must develop and keep current a State-approved Business Continuity, Cyber Incident Response, and Disaster Recovery (BC/DR/CIR) Plan. | ||
| GR-00148 | The Contractor must ensure the Business Continuity/Disaster Recovery/Cyber Incident Response Plan: (a) provides a framework for reconstructing vital operations to ensure the safety of employees (b) provides for the resumption of time sensitive operations and services in the event of an emergency (c) provides for initial and ongoing notification procedures (d) complies with all NIST CP-2, NIST 800-61, and IR-8, NIST-800-53 standards (e) complies with the latest version of ARC-AMPE standards. | ||
| GR-00149 | The Contractor must ensure the Business Continuity/Disaster Recovery/Cyber Incident Response Plan's operational and system functions, including systems and operations under the scope of Subcontractors, adhere to Health Insurance Portability and Accountability Act and National Institute of Standards and Technology standards. | ||
| GR-00150 | The Contractor must provide an up-to-date copy of the Business Continuity/Disaster Recovery/Cyber Incident Response Plan in a secure, highly accessible, centralized online location and at an offsite location approved by the State. | ||
| GR-00151 | The Contractor must submit the Business Continuity, Cyber Incident Response, and Disaster Recovery Plan annually or more frequently as directed by the State, such as after a major system change that materially affects the plan. | ||
| GR-00152 | The Contractor must perform annual Business Continuity, Disaster Recovery, and Cyber Incident Response exercises, including pre-go-live activities. | ||
| GR-00153 | Business Continuity (BC), Disaster Recovery (DR), and Cyber Incident Response (CIR) exercises must include activities selected from the BC/DR/CIR Plans to verify the viability of each plan in accordance with NIST CP-4 and IR-8 standards. | ||
| GR-00154 | The Contractor must perform Business Continuity, Disaster Recovery, and Cyber Incident Response exercises after major system changes as required by the State. | ||
| GR-00155 | The Contractor must document all Business Continuity, Disaster Recovery, and Cyber Incident Response activities and report to the State instances where appropriately trained personnel were unable to complete the necessary recovery procedures. | ||
| GR-00156 | The Contractor must adjust contingency and training plans to correct deficiencies identified through Business Continuity, Disaster Recovery, and Cyber Incident Response exercises and present updates to the State for approval. | ||
| GR-00157 | The Contractor must provide annual test reports to the State within 10 business days of exercise, Business Continuity (BC)/Disaster Recovery (DR) and Cyber Incident Response (CIR) Plan reports within one business day of incident, and BC/DR/CIR Plan updates within one business day of identified deficiency. | ||
| GR-00158 | The Contractor must evaluate systems and business processes in collaboration with the State for criticality and necessity to determine appropriate return to operations time frames during development of both the initial and ongoing Business Continuity/Disaster Recovery/Cyber Incident Response Plans. | ||
| GR-00159 | The Contractor must update key personnel contact information as it relates to the Business Continuity/Disaster Recovery/Cyber Incident Response Plans within one business day of notification of the change. | ||
| GR-00160 | The Contractor must implement a State-approved alert process to handle system-related issues, including notifying State-identified contacts in accordance with the Business Continuity/Disaster Recovery/Cyber Incident Response Plans. | ||
| GR-00161 | In coordination with the State, the Contractor must provide training to Contractor staff and State-identified stakeholders on the execution of the Business Continuity/Disaster Recovery/Cyber Incident Response Plans a minimum of 20 business days prior to implementation of the Contractor's module components, with the implementation of major changes, and annually thereafter. | ||
| GR-00162 | The Contractor must review any new applicable Contractor provided business processes, including systems and operations under the scope of Subcontractors, for impact on mission critical functionality and update Business Continuity/Disaster Recovery/Cyber Incident Response Plans prior to new business process implementation. | ||
| GR-00163 | The Contractor must ensure that personnel who are responsible for systems recovery and cyber incident response are trained in accordance with NIST Publication 800-53 current revision and latest version of ARC-AMPE standards and tested in their ability to execute the contingency and incident response procedures. | ||
| GR-00164 | The Contractor must provide for backup capabilities at a geographically separate remote site(s) from the Contractor's primary site(s) in accordance with the standards set forth in the Business Continuity/Disaster Recovery/Cyber Incident Response Plans. System and data backup and recovery points must be mutually agreed upon between the Contractor and the State. | ||
| GR-00165 | The Contractor must provide a backup and recovery/failover system(s) in compliance with State and Federal rules and regulations to ensure full backup. | ||
| GR-00166 | Backup and Recovery Services must be in place for Production Environment and Non-Production Environments. | ||
| GR-00167 | The solution must ensure that all backups are immutable (unchangeable). | ||
| GR-00168 | The solution must employ backup strategies that include air gap measures. | ||
| Transition and Closeout Management | |||
| FEA-GF12 | As a State program lead I want an orderly turnover and transfer of knowledge, assets, and responsibilities so that future providers can assume services without disruption. | ||
| GR-00169 | The Contractor must develop a State-approved Turnover and Closeout Plan that includes the process, details, and cadence the Contractor uses to assess the eligibility of any other organization pursuing an optional extension of Attachment H licensing terms, after the initial 42-month contract term, with the Contractor on behalf of the State. | ||
| GR-00170 | The Contractor must transition and train, as requested and negotiated, any or all infrastructure responsibilities necessary to fulfill the Contractor's contractual obligations to the State or another party upon notification from the State. This includes but is not limited to transference of: The Cloud Service Provider's (CSP) member accounts using the appropriate mechanisms; Complete system inventory for all Contractor services; Contractor cloud boundary access control policies; Network ACLs; Security Groups; Roles; Users; 2FA/Multi-Factor Authentication tooling; Infrastructure as Code programs and scripts; Security and compliance monitoring tools and processes; Audit logs; System monitoring; SIEM tooling and logs; Vulnerability Management; Plan of Action and Milestones; Compliance scans; Data backups; Configuration Management Database items; Disaster Recovery fail-over and recovery routines. |
| Type of Data | Applicable State & Federal Standards, Policies, and Laws | Comply | Vendor's Description of Compliance |
|---|---|---|---|
| Publicly available information | NIST 800-171 | ||
| Confidential Personally Identifiable Information (PII) | State law on Notification of Security Breaches State Law on Social Security Number Protection State law on the Protection of Personal Information National Institute of Standards & Technology: NIST SP 800-53 Revision 4 "Moderate" risk controls Privacy Act of 1974, 5 U.S.C. 552a. | ||
| Personal Health Information (PHI) | Health Insurance Portability and Accountability Act of 1996: HIPAA The Health Information Technology for Economic and Clinical Health Act HITECH Code of Federal Regulations 45 CFR 95.621 |
| Type of Data | Applicable State & Federal Standards, Policies, and Laws | Comply | Vendor's Description of Compliance |
|---|---|---|---|
| Affordable Care Act Personally Identifiable Information (PII) | Internal Revenue Service Tax Information Security Guidelines for Federal, State and Local Agencies IRS Pub 1075 Minimum Acceptable Risk Standards for Exchanges MARS-E 2.0 (Scroll down the page) | ||
| Personal Information from Motor Vehicle Records | Driver's Privacy Protection Act (Title XXX) ("DPPA") 18 U.S.C. Chapter 123, 2721 - 2725 | ||
| Criminal Records | Criminal Justice Information Security Policy: CJIS |
| How do you manage the process of gathering our business and technical requirements? |
|---|
| What methodology (e.g., workshops, interviews, document analysis) do you use to map our requirements to the COTS product's standard features? |
| How do you handle requirements that fall outside the COTS application's standard capabilities? What is the formal process for identifying a gap? |
| What is your standard deliverable/artifact that formally documents the agreed-upon scope (e.g., Requirements Traceability Matrix, Statement of Work)? |
| What is your formal Gap Analysis process? Who from your team is responsible for leading this activity? |
| For each identified gap, what is the decision framework used to determine whether it will be solved by: |
| Configuration (using built-in flexibility)? |
| Customization (developing new code)? |
| A process change on the State's end? |
| What is your policy and process for customizations? Are there limitations (e.g., only via APIs, no changes to core code)? How are these customizations supported and maintained during future product upgrades? |
| How is the impact of a customization on the overall system performance and stability measured and documented? |
| How do you ensure that the system, as implemented, meets the agreed-upon requirements? How do you associate or link business rules and acceptance criteria to requirements? |
|---|
| What is your approach to User Acceptance Testing (UAT) in relation to the requirements? Do you provide pre-built test cases linked to the requirements? |
| How do you demonstrate that a custom development or configuration has not negatively impacted other core system functions (regression testing)? |
| Questions | Vendor Response |
|---|---|
| Service: Customer Phone &/or Email Support | Service: Customer Phone &/or Email Support |
| What is the method for contacting technical support? | |
| What are the hours of operation for support? | |
| What is the turnaround time for responses? | |
| What is the escalation process for support issues? | |
| Who comprises the support team and what are their qualifications? | |
| Define your response resolution metrics and how you capture and report them. | |
| Service: Incident/Security Breach Notification and Process | Service: Incident/Security Breach Notification and Process |
| Describe your identification and notification process for security breaches. | |
| Service: Data Management | Service: Data Management |
| Describe how data is stored, retained and backed-up (including frequency). | |
| Service: Hosting | Service: Hosting |
| Describe the hosting service and associated service levels. |
| Questions | Vendor Response |
|---|---|
| Service: Scheduled Maintenance/Downtime | Service: Scheduled Maintenance/Downtime |
| What is the frequency of scheduled maintenance and downtime? | |
| What is the notification process for scheduled maintenance and downtime? | |
| Describe how "maintenance" updates are tested with customers prior to installing them in their live environments. | |
| Service: System Upgrades | Service: System Upgrades |
| Are software upgrades provided as part of the software support contract? | |
| Describe your software upgrade process. | |
| How often are new versions released? | |
| Is documentation and training provided for system upgrades? | |
| Are there additional costs for upgrades and/or new releases? | |
| Describe how and when the State will have an opportunity to test system upgrades/releases prior to live installation. | |
| Describe how the State will validate post installation and how changes will be backed out in the event that a problem is encountered. |
| Questions | Vendor Response |
|---|---|
| Service: Bug Fixes and Minor Enhancements | Service: Bug Fixes and Minor Enhancements |
| Describe the frequency and process for providing, testing, and installing bug fixes and minor enhancements. | |
| Service: Disaster Recovery | Service: Disaster Recovery |
| Describe the disaster recovery services included in this proposal for any non-state hosted services. | |
| What is your standard RPO and RTO? | |
| Describe the plan your company has in place for its own disaster recovery of any sites that may be involved in support of this proposal. |
| Cost Type | One Time (Implementation) | Year 1 | Year 2 | Year 3 | Year 4 | Year 5 |
|---|---|---|---|---|---|---|
| Software | ||||||
| Enterprise Application: License Fees | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| Maintenance &/or License Fee Add-Ons | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| Subscription cost | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| Storage Limitations and/or Additional Fees | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| Database Software: License Fees | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| Middleware Tools: License Fees | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| Operating System Software: License Fees | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| Upgrade Costs for Later Years | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| Support and Maintenance Fees | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | |
| Implementation Services | ||||||
| Project Management | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| Requirements | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| Design (Architect Solution) | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| Development (Build, Configure or Aggregate)/Testing | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| System Testing | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| Defect Removal | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| Implement/Deploy or Integrate | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| Quality Management | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| Cost Type | One Time (Implementation) | Year 1 | Year 2 | Year 3 | Year 4 | Year 5 |
| Implementation Services Continued | ||||||
| Training | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | |
| $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | |
| Telecom | $0.00 | |||||
| Bandwidth | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | |
| Hardware | $0.00 | |||||
| Computing Hardware | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| Storage and Backup Hardware | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| Network Hardware | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| Facilities/Data Center | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | |
| $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | |
| Hosting | $0.00 | |||||
| Hosting Fees | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 |
| $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | |
| Total Base Costs | $0.00 |
| Total Implementation plus Five Year Costs | $ 0.00 |
|---|
| Clause Location | Exception | Proposed Verbiage |
|---|---|---|
| [indicate RFP, exhibit, attachment or addendum, section & page number] | [briefly describe your concern about this clause] | [describe your suggested alternative wording for the clause or your solution] |
| [indicate RFP, exhibit, attachment or addendum, section & page number] | [briefly describe your concern about this clause] | [describe your suggested alternative wording for the clause or your solution] |
| [indicate RFP, exhibit, attachment or addendum, section & page number] | [briefly describe your concern about this clause] | [describe your suggested alternative wording for the clause or your solution] |
| Summary of Detailed Information | Date of Notification | Outcome |
|---|---|---|
| Provided Equipment or Product | Note or Comment |
|---|---|
| Signature: | |
|---|---|
| Full name: | |
| Title: | |
| Company: | |
| Date: |

With GovernmentContracts, you can:
Reading ER P23-1 (404) Request Date: 7/29/2026 1:05:25 PM Open Date: Closing Date:
State Government of Vermont
Bid Due: 8/21/2026
Williston Road Stormwater Structures Request Date: 7/29/2026 8:42:48 AM Open Date: Closing Date:
State Government of Vermont
Bid Due: 8/27/2026
Follow Dental and Audiology Coordinator for the Vermont Army National Guard Active Contract
DEPT OF DEFENSE
Bid Due: 8/23/2026
Roadway Line Striping and Markings Request Date: 7/24/2026 2:23:32 PM Open Date: Closing
State Government of Vermont
Bid Due: 8/19/2026