USA(Massachusetts)
SYS-1244

RFP Description

The vendor is required to provide for a FedRAMP certified enterprise password management and privileged access management solution and to ensure our applications, data and operations are more secure.
- Enterprise password management requirements:
1. Security and compliance requirements
• Must integrate with the commonwealth’s solution for SSO (microsoft Entra id).
• Should support SCIM user lifecycle management to automate user provisioning and deprovisioning.
• Must support aes-256 encryption for data at rest and in transit.
• Must support MFA methods like TOTP, biometric, and hardware tokens.
• Role-based access control (RBAC): should allow granular permission settings.
• Must be compliant with regulations (e.g., soc 2, iso 27001).
• Must maintain detailed logs of user activity, accessible only to authorized admins.
2. Usability and accessibility requirements
• Platform compatibility: available on major OS platforms (windows, mac, Linux) and mobile (iOS, android).
• Browser integration: supports extensions for popular browsers (chrome, Firefox, safari, edge).
• Simple and intuitive UI for both end-users and administrators.
• Automatically fills and captures login details across applications and browsers.
• Ability to create shared vaults to organize and distribute credentials to specific individuals or groups.
3. Performance and scalability requirements
• High availability: minimal downtime with load balancing and failover support.
• Scalability: supports growth from a small team to a large enterprise without performance degradation.
• Data synchronization: real-time password sync across all devices.
4. Training and support requirements
• User training: comprehensive training materials and live sessions for end-users and admins.
• Technical support: 24/7 support via chat, email, or phone.
• Documentation: detailed technical and user documentation.
5. Privileged access management requirements:
• Solution will provide API access to the enterprise vault.
• Assist with certificate rotation and management.
• Ability to customize password settings in the vault including expiration dates for secrets.
- Contract Period/Term: 1 year

Timeline

RFP Posted Date: Saturday, 24 May, 2025
Proposal Meeting/
Conference Date:
NA
NA
Deadline for
Questions/inquiries:
NA
Proposal Due Date: Wednesday, 28 May, 2025
Authority: Government
Acceptable: Only for USA Organization
Work of Performance: Offsite
Download Documents

Similar RFPs
CANADA(Alberta)