The Vendor is required to provide a vast and intricate educational system, there is a pressing need for a cutting-edge, user-friendly, and highly secure identity and access management (IAM) and administration solution.
- IAM Solution that aligns with modern administration standards to empower our students, our educators, and our support staff to interact with our digital ecosystem securely and seamlessly.
- The IAM Solution will be at the forefront of technological innovation, providing a foundation of trust, accessibility, and compliance that underpins our digital endeavors.
- IAM Solution should to:
β’ Establish robust identity governance across all digital assets.
β’ Centralize and automate user provisioning, access requests, and de provisioning workflows.
β’ Strengthen security protocols and mitigate potential risks associated with unauthorized access.
β’ Enhance user experience through seamless, yet secure, access to resources.
β’ Ensure adherence to industry-specific compliance regulations (specify if applicable, e.g., PII, HIPAA, SOPPA, GDPR FERPA and ISSRA etc.).
β’ Provide a single/configurable (configurable by cps) SSO portal for admins, leadership, help desk, and to the end users, which is compatible with platform SSO on ChromeOS, windows, macOS, iOS & iPadOS, android devices.
- Servers/Appliance:
β’ Virtualization standards:
β Use of hypervisors like VMware, Hyper-V, KVM or virtual/physical appliances.
β must support the latest Microsoft (minimum windows server 2019) or red hat enterprise Linux operating systems for any on-premises servers, and must include ongoing support for the Microsoft / red hat operating system product lifecycle; must include streamlined migration steps for OS upgrade scenarios.
β Support for containerization (e.g., Docker, kubernetes).
β’ Compute capacity:
β Scalability options (vertical and horizontal scaling).
β provisioning speed for new instances.
β’ Resource allocation and management:
β Static (minimum), dynamic and on-demand CPU, memory, and storage allocation mechanisms.
β Monitoring tools for server health and performance.
- Storage:
β’ Data Redundancy and Durability:
β Implementation of RAID or erasure coding for data protection.
β Multiple data replication across USA dispersed locations (As per CPS data sharing policy, data cannot be stored outside of USA boundaries).
β’ Scalable Storage Solutions:
β Ability to scale storage capacity based on demand.
β Support for various storage types (block, file, and object).
β’ Data Encryption and Access Control:
β Encryption at rest and in transit.
β Access controls and permission mechanisms for data storage.
- Network:
β’ Security and Firewall Standards:
β Implementation of firewalls and network security groups.
β Network segmentation and isolation.
β’ Load Balancing and Traffic Distribution:
β Load balancers for distributing incoming traffic.
β Redundancy and failover mechanisms for network components.
β’ Network Monitoring and Management:
β Tools for monitoring network performance and traffic.
β Automated scaling of network resources based on demand.
Compliance and Standards:
β’ Compliance with Industry Regulations and Security Measures:
β Adherence to industry-specific regulations (HIPAA, SOPA, GDPR, etc.).
β Compliance and Adherence to NIST Privacy Framework and Cybersecurity
- Framework
β Encryption protocols, e.g., TLS 1.2+.
β Data backup and disaster recovery plans.
β Regular audits and compliance checks.
- Service Level Agreements (SLAs):
β Minimum uptime percentage (e.g., 99.999%).
β Response time for support requests within one (1) hour.
β Bandwidth and latency expectations.
β Response time for different types of support tickets.
β Escalation process for critical issues.
β Measures for penalties or compensation in case of SLA breaches.
- Support/Communication Channels:
β Availability of support channels (email, phone, live chat, etc.).
β 24/7 support availability.
- Performance Metrics and Reporting:
β Required weekly and monthly Metrics report to measure support performance.
β Regular reporting on support activities and issue resolution.
- Interoperability and Compatibility:
β Compatibility with various operating systems and software.
β Open standards for APIs and interoperability with third-party services.
- Integrations Standards:
β’ Compatibility:
β Compatibility with existing systems/software.
β API availability and documentation.
β’ Data Exchange Protocols:
β Standard formats for data exchange (JSON, XML, etc.).
β Handling of data transformation and synchronization.
β’ Testing and Deployment Procedures:
β Procedures for testing integrations.
β Guidelines for deployment and rollback.
- Solution must include:
β’ Empower secure digital interactions: we aim to create an environment where our students, our educators, and our support staff can access our systems and data securely from anywhere, at any time.
β’ We envision a future where identities are the keys to our digital world, offering a frictionless yet highly secure experience.
β’ User self-service: we want to empower our students, educators and support staff to take control of their identities and access privileges, reducing administrative burdens and fostering a sense of ownership.
β’ Multi-factor authentication (MFA): security is paramount. The IAM solution should incorporate robust MFA options, enhancing security by requiring multiple forms of identity verification for critical systems and data access.
β’ Evolving threat detection: the IAM solution should enhance our cyberattack preparedness through identity threat detection and response (ITDR).
β’ It is crucial in safeguarding our organization against evolving cyber threats; investing in cutting-edge technologies and fostering a culture of proactive cybersecurity measures, we envision incorporating cutting-edge threat detection mechanisms, including AI and machine learning, to detect and respond to security incidents in real-time.
β’ Adaptability and scalability: we envision a solution that can grow with our district's needs.
β’ Whether we expand our students/workforce, adopt new technologies, or collaborate with new partners, the IAM solution should be flexible and scalable to accommodate these changes seamlessly.
β’ Integration and collaboration: the IAM solution should seamlessly integrate with our existing and future technology stack, enabling interoperability and collaboration with external partners and services.
β’ Granular access control: we want to implement fine-grained access control mechanisms, ensuring that users have the right level of access to resources based on their roles and responsibilities.
β’ This not only enhances security but also streamlines workflows.
β’ Seamless user experience: the IAM solution should provide a user-friendly experience.
β’ We want a unified and intuitive interface for our students, our educators, and our support staff to manage their identities, access privileges, and preferences easily.
β’ Compliance and governance: the IAM solution provider should commit to adhering to industry regulations and internal policies.
β’ The IAM solution should facilitate audit trails, reporting, and compliance management, making it easier to ensure that we meet all regulatory requirements and internal standards.
β’ Identity lifecycle management: comprehensive management of user identities throughout their lifecycle - from onboarding to off boarding - ensuring efficient provisioning and de provisioning processes in as near to real-time as feasible.
β’ Compliance and auditability: robust audit trails, compliance reporting capabilities, and support for regulatory standards, enabling comprehensive oversight and adherence to compliance mandates.
β’ Availability/uptime: ensure continuous service availability with a 99.99% uptime, incorporating inherent disaster recovery capabilities.
β’ Single sign-on/SSO portal: the IAM solution should provide a portal for all SSO integrated applications.
β’ The solution should provide a centralized authentication and access control system that enables users to access multiple applications and services using a single set of login credentials.
β’ Automated and near real-time management of identity lifecycles.
β’ automated and near real-time management of identity lifecycles revolutionizes the efficiency and security of organizational systems.
β’ Streamlines the entire spectrum of identity management, from user onboarding to off boarding.
β’ Automated workflows ensure swift provisioning of access rights aligned with roles and responsibilities, minimizing manual errors and enhancing operational agility.
β’ Provisioning of accounts for active directory and google workspace.
β’ Automated provisioning of accounts within five minutes in agency on-prem active directory and google workspace infrastructures ensures near real-time access setup.
β’ Role-based and policy-driven access control.
β’ Comprehensive and configurable reporting on all IAM processes.
β’ An intuitive and user-friendly interface with self-service capabilities for end-users.
β’ Strong privileged access management (pam) to restrict elevated privileges in an automated / governed manner, and to audit and report on any and all access elevations.
β’ Integration with major board applications, including the student information system and other board applications/databases.
- Contract Period/Term: 3 years
- A Pre-Submittal Conference Date: April 14, 2025
- Questions/Inquires Deadline: April 07, 2025
Set up free email alerts and get notified when new government bids, tenders and procurement opportunities match your industry and location. Choose daily or weekly delivery.