The vendor is required to provide the overall solution or methodology for the grant management database.
- The summary should describe the following:
• Key differentiators in service offerings, account management, and value-added services proposed by your company.
• Your understanding of the scope of requirements and the level to which your proposal has met the requirements.
• High-level project execution plan and timeline for completion, outlining any equipment delays that could impact availability.
• Risk management considerations.
• Value and outcomes delivered to agency
- Secure access and audit controls:
• Implement role-based access control (RBAC) with a minimum of admin, editor, viewer, and grantee roles.
• The system should ensure only appropriate users see only data relevant to their work.
• For example, roles such as:
i. Program officers (agency staff managing the grant awards).
ii. Auditors.
iii. Finance staff.
iv. Others.
o Support single sign-on (SSO) and multi-factor authentication (MFA).
o Maintain comprehensive audit logs to accurately and consistently report on user access, change, and deletion of all data.
o Logging of access and change history, considering potential requirements from auditors or other bodies and investigation of specific user activity.
2. Data protection standards:
• Provide data encryption at-rest and in-transit for sensitive data.
• Enforce data retention policies with automated archiving based on agency practices.
• Supports disaster recovery and daily data backup plans to ensure data security and availability.
• Service level agreement (SLA) and uptime expectations during business hours 6 am - 6 pm Monday thru Friday.
• Implement secure data destruction procedures for data that is no longer required.
• Any other information on how the system will ensure an appropriate level of detail to verify the agency stewardship of the data regarding storage, retention, and destruction.
3. Compliance with security standards:
• Proposer should describe how the system complies with applicable security standards including but not limited to FERPA, SOC2, HIPAA, NIST, FEDRAMP.
- Not-Mandatory Pre-Proposal Meeting Date: May 27, 2025
- Questions/Inquires Deadline: May 29, 2025