Company Name: This RFI response has been submitted by: Address: (Street, Su. # City, State, Zip) Request for Information RFI #15/16-300 for Enterprise Password Management Software Contact Name: Telephone #: Fax #: E-mail address: Schedule of Events: EVENT DATE Post RFI July 14, 2015 Questions Due July 27, 2015 by 3:00 pm Addendum Issued July 28, 2015 RFI Response Due Date August 6, 2015 (The City reserves the right to change schedule of events without prior notice or responsibility to Vendor.) Submit Request for Information response to: Ruth Cain, CPPB, Purchasing Manager City of Rancho Cucamonga 10500 Civic Center Drive, Rancho Cucamonga, CA 91730 Vendor submittals shall be delivered in sealed packaging, clearly marked with the RFI title and number on the outside packaging. Direct Questions to: Debbie Grimes, Buyer I E-mail: debbie.grimes@cityofrc.us Phone: (909) 477-2700 ext. 2504 NOTICE From the issuance date of this Request for Information until a Vendor is awarded, Vendors are not permitted to communicate with any City staff or officials regarding this procurement, other than during interviews, demonstrations, and/or site visits, except at the direction of Ruth Cain, CPPB, Purchasing Manager or Debbie Grimes, Buyer I, the designated representatives of the City of Rancho Cucamonga.
1. GENERAL INFORMATION RFI # 15/16-300 Enterprise Password Management Software 1.1 PURPOSE OF THE REQUEST FOR INFORMATION The City of Rancho Cucamonga intends to conduct a formal procurement process for the purchase of Enterprise Password Management Software to allow the City to control and manage privileged account passwords on a temporary and delegated basis with the goal of preventing unauthorized access to City systems. The City wishes this password management solution to control various types of accounts including, but not limited to, Super-User Accounts that control all administrative accounts, service accounts that require privileged logons/passwords to operate a Windows service account or application-to-application passwords that allow applications to connect to each other. One of the overall goals of the password management tool is to eliminate all shared credentials, prevent back door accounts, and allow the ability to automatically change all privileged and Windows service account passwords on-demand. The purpose of this RFI is to gather information that may assist the City in its preparation of the formal process to be conducted at a later date. The RFI should not be construed as a formal solicitation. Response to this RFI is not a prerequisite to participation in any subsequent procurement action related to this project. A vendor may choose to respond to selected parts of this RFI only. Complete responses, however, are strongly preferred and encouraged. Vendors are encouraged to provide creative and innovative ideas for cost savings, new concepts, functionality, technical advances, and economic solutions beyond the confines of this RFI. Responders should indicate any value added arrangements, special services, discounts or terms and conditions, or combinations of such that might suggest creative options for the City to consider when preparing a formal Request for Proposal. The City s intent is to consider all manufactures that provide Enterprise Password Management Software applicable to the City s needs. Vendors may be contacted to discuss their responses. Any information collected through this RFI process may or may not be used in the future to develop a solicitation for proposals. Providing a response to the City does not in any way give an advantage to any vendor. Acknowledgement of receipt of responses will not be made nor will respondents be notified of the City s view of the information received. Please be advised that this is a Request for Information (RFI) and is not a Request for Proposal, Quote or Bid. This request is for information and planning purposes only and shall not be construed as a solicitation or as an obligation on the part of the City. Because this not a formal solicitation, copies will not be made available for request. The City will not award a contract on the basis of responses nor otherwise pay for the preparation of any information submitted or the City s use of such information. The purpose of this RFI is purely to gain input from the vendor community on the published specifications. Responses will be separated from and have no bearing on subsequent evaluations of proposals submitted in response to any future formal RFP process. The City will not evaluate the responses, and the RFI should not be used by interested parties to market their products/services. Proprietary information is not being solicited. Responses will be reviewed only by City personnel and authorized third parties. Therefore, do not send any material that requires a non-disclosure agreement or that may be business sensitive. Responses received that include a non-disclosure agreement or identify 2
RFI # 15/16-300 Enterprise Password Management Software information that is business sensitive will not be accepted. Responses to this notice will not be returned. 1.2 QUESTIONS AND CLARIFICATIONS All questions or clarification requests must be submitted in writing to Debbie Grimes, Buyer I, in any one of the following manners, directly through the Bid system or via email at debbie.grimes@cityofrc.us, on or before July 22, 2015, by 3:00 PM. Answers and/or clarifications will be provided in the form of an Addendum and will be posted for download from the City s bid system in accordance with the above Schedule of Events. The named Contact for this RFI is the sole point of contact for this process. Vendors are not permitted to communicate with other City staff or officials about this RFI, except during mandatory presentation and/or interviews, unless otherwise directed by the Contact. 1.3 SPECIFICATIONS The intent of this RFI is to reach out to the Enterprise Password Management Software manufacturer, supplier, and contractor market to solicit their expertise in developing specifications based on the City s performance requirements. The specifications published in this RFI are for the sole purpose of review and feedback from the vendor community and are subject to vendor scrutiny. The City is looking for input and recommendations that will assist in selecting and purchasing Enterprise Password Management Software. 1.4 RESPONSE FORMAT TO THE RFI 1.4.1 COVER LETTER / INTRODUCTION The Cover Letter should include a synopsis of your organization, type and size of organization with a brief description of the organization s business structure. Provide your company name, mailing address and telephone number of the Vendor point of contact for this RFI response. The letter should be signed by an authorized representative of the company. 1.4.2 CAPABILITIES AND TECHNICAL EXPERIENCE Provide a capability statement that details the company s technical ability to provide Enterprise Password Management Software as described herein. 1.4.3 PAST EXPERIENCE A statement providing past experience on projects for this type or similar types of Enterprise Password Management Software. 1.4.4 COMMENTS Please provide any information that may be relevant. Include any literature or technical specifications. The intent of the City is to complete this RFI and conduct the formal procurement process in this fiscal year. At this time, the City is not looking for budgetary numbers; please do not include them in this RFI. 3
Exhibit A Scope of Work For your RFI, please assume the following estimates of node counts: RFI # 15/16-300 Enterprise Password Management Software Privileged user accounts: 30 Privileged Windows service accounts: 150 Companywide staff accounts: 600 Windows servers: 200 Windows desktops: 600 ESXi Servers:20 vsphere vcenter: 4 Cisco devices: 100 Backup Exec servers: 3 Backup exec remote credentials: 75 It is anticipated that key requirements for the enterprise password management would include the following - please advise if you have any additions, changes or deletions. Give authorized users automated access to managed systems and/or applications through random password checkout. All passwords must be encrypted in non-open-source database. Preferably Microsoft SQL 2014 or later. Allow access to all stored or managed info to be accessed by authorized staff while either on-premises or offsite. Software ability to manage passwords for Windows local and domain accounts, and automatically update every associated account credential including Windows tasks, COM/DCOM objects, and services. We also want a solution the can manage accounts credentials on embedded passwords in web application, business applications, Microsoft SQL, Linix and VMware ESXi platforms, Cisco networking devices, Dell DRAC, Backup Exec stored credentials for remote servers, and control over numerous other systems/infrastructure components for a comprehensive solution that can scale as we add new technology or features. Provide a mechanism to manage staff permitted access to info and passwords stored in the enterprise password management software at a granular per-user level, giving each user access to only the individual account they have been granted permission. System must have high availability and redundant capabilities. The loss of any one system should not cause any passwords to be lost. No limitations exist as to how many times or functions are run against a registered node of user account. Granted access staff is not limited to how many times they can access the software in any given time period. Allow real-time monitoring and in-depth administrative reporting for all actions and password access activity in the entire environment. Provide alerting features on key actions such as password changes, password failures, etc. 4
RFI # 15/16-300 Enterprise Password Management Software Ability to propagate password chances anywhere accounts are referenced such as Windows service accounts. Provide a dashboard with key data to monitor logons and activity. Support for two-factor authentication providers. Ability to deploy out-of-band time based one-time password. Support hardware-based encryption to securely store credentials to FIPS 140-2 levels 2 and 3 Ability to provide authoritative audit trails of all privileged access, all protected systems and accounts to prove regulatory compliance. Ability to use SSH keys to access physical and virtual hardware and applications. Provide a continuous auto-discovery for new identities on new and existing hardware and software including Windows machines, Linux servers, Cisco devices and databases. Provide tools to make the initial implementation manageable. Ability to discover and change all default privileged passwords on each existing, new and changed hardware and software asset. The solution must support user password access via mobile devices and tablets. Continuous automated account discovery to see where privileged credentials reside and how they are being used. Automatically detect changes in the environment and immediately update itself. Limit the time and scope of access to sensitive credentials with the ability to automatically change these credentials after the access period expires and distribute the new credentials to all places where they are being used. The proposed solution must be able to integrate with the City s Microsoft Active Directory (2008 R2, or soon to be 2012) and VMWare vsphere (5.5 and 6). Supporting operating systems should be 2012 R2 and later and support VMware s virtualization. 5
RFI # 15/16-300 Enterprise Password Management Software EXHIBIT B SIGNATURE OF AUTHORITY The undersigned firm declares that he has carefully examined the specifications and read the above terms and conditions, and hereby proposes and agrees, if this RFI response is accepted, to furnish all material in accordance with the specifications and instructions, in the time and manner therein prescribed for the unit cost amounts set forth in the following RFI response. THE VENDOR IN SUBMITTING THIS RFI RESPONSE MUST FILL IN THE FOLLOWING INFORMATION. FAILURE TO DO SO MAY DEEM YOUR RFI RESPONSE AS NON-RESPONSIVE. Company Name: Telephone #: Address: (Street, Su. # City, State, Zip) Fax #: E-mail address: Authorized Representative: (print) Signature: Web Address: Title: Date: 6