The vendor is required to provide enterprise password management and privileged access management solution and to ensure our applications, data and operations are more secure.
1. Security and compliance requirements
• Must integrate with the commonwealth’s solution for SSO (microsoft ENTRA id).
• Should support SCIM user lifecycle management to automate user provisioning and deprovisioning.
• Must support aes-256 encryption for data at rest and in transit.
• Must support MFA methods like TOTP, biometric, and hardware tokens.
• Role-based access control (RBAC): should allow granular permission settings.
• Must be compliant with regulations (e.g., soc 2, iso 27001).
• Must maintain detailed logs of user activity, accessible only to authorized admins.
2. Usability and accessibility requirements
• Platform compatibility: available on major OS platforms (windows, mac, Linux) and mobile (iOS, android).
• Browser integration: supports extensions for popular browsers (chrome, Firefox, safari, edge).
• Simple and intuitive UI for both end-users and administrators.
• Automatically fills and captures login details across applications and browsers.
• Ability to create shared vaults to organize and distribute credentials to specific individuals or groups.
3. Performance and scalability requirements
• High availability: minimal downtime with load balancing and failover support.
• Scalability: supports growth from a small team to a large enterprise without performance degradation.
• Data synchronization: real-time password sync across all devices.
4. Training and support requirements
• User training: comprehensive training materials and live sessions for end-users and admins.
• Technical support: 24/7 support via chat, email, or phone.
• Documentation: detailed technical and user documentation.
5. Privileged access management requirements:
• Solution will provide API access to the enterprise vault.
• Assist with certificate rotation and management.
• Ability to customize password settings in the vault including expiration dates for secrets.
- Contract Period/Term: 1 year