The vendor is required to provide innovates investments matching platform for co-design, implement, manage and refine this connection platform, which will be built on air table infrastructure.
- The mission of AI is to advance the economy of the province by promoting technology development and application, performing applied research, and providing expert advice, technical information and scientific infrastructure that is responsive to the needs of the private sector and supports activities in the public sector.
- Includes to the following:
• Co-design the database for each stakeholder module
• Co-design the matching, searching and reporting functions of the database
• Test and refine the database
• Support adoption of the database
• Build additional modules that support the goal of the platform, as needed
• Update the platform to accommodate additional stakeholder groups as identified by state innovates
• Build an extensive data analytics and reporting dashboard
• Provide contextual information on processes upon request
• Provide associated product documentation relevant to the product life cycle
• Be available for weekly and mutually agreed upon ad hoc project meetings
- The contractor shall use appropriate air table functions and features, in addition to third-party integrations that support the full realization of the project, while also addressing any cybersecurity concerns.
- Cybersecurity requirements:
- Data security and protection
• All data must be encrypted both at rest and in transit using industry-standard encryption methods (e.g., AES-256, TLS 1.2+).
• The contractor must implement robust access controls, ensuring least privilege principles for users and administrators.
• Data residency must be in country, and any transfer of data outside of agreed-upon jurisdictions must be pre-approved by state innovates.
- Identity and access management
• Multi-factor authentication (MFA) shall be required for all accounts accessing the platform.
• Role-based access control (RBAC) must be implemented, ensuring only authorized personnel have access to sensitive data and systems.
• Periodic user access reviews must be conducted to minimize security risks.
- Supply chain security
• The contractor must disclose all third-party services, integrations, and dependencies used within the platform and ensure compliance with the same cybersecurity standards.
• The contractor shall assess supply chain risks and provide an overview of vendor security measures.
- Secure development practices
• The platform shall be developed following secure coding guidelines, including the protocol top 10 and CWE/sans top 25 vulnerabilities.
• Regular security testing, including penetration testing and vulnerability assessments, must be conducted.
• Security patches and updates must be applied within industry-accepted timelines.
- Incident response and monitoring
• The contractor shall have a documented incident response plan in place, including timelines for incident reporting and escalation.
• The contractor must provide real-time security monitoring for unauthorized access attempts and potential security threats.
• The contractor shall conduct periodic security audits and compliance checks.
- Incident response and monitoring
• The contractor shall have a documented incident response plan in place, including timelines for incident reporting and escalation.
• The contractor must provide real-time security monitoring for unauthorized access attempts and potential security threats.
• The contractor shall conduct periodic security audits and compliance checks.
- Cloud security and cybersecurity regulations
• Cyber security guidance for critical infrastructure– ensures risk management and cybersecurity best practices, relevant if the platform becomes a critical business tool.
• Directive on service and digital (if integrating with government systems or cloud services) – defines cloud security, encryption, and compliance standards.
- Contract Period/Term: 1 year
- Questions/Inquires Deadline: February 24, 2025
Set up free email alerts and get notified when new government bids, tenders and procurement opportunities match your industry and location. Choose daily or weekly delivery.