Comprehensive IT Assessment Questions & Answers



Similar documents
SENIOR SYSTEMS ANALYST

itg CloudBase is a suite of fully managed Hybrid & Private Cloud Services ready to support your business onwards and upwards into the future.

REQUEST FOR PROPOSAL (RFP) # HIPAA SECURITY ASSESSMENT VENDOR QUESTIONS & ANSWERS ~ MAY 29, 2014

611 Tradewind Dr. Suite 100, Ancaster ON, L9G 4V5 (905) ext 244

City of Coral Gables

Infrastructure solution Options for

Audit Report. Effectiveness of IT Controls at the Global Fund Follow-up report. GF-OIG-15-20b 26 November 2015 Geneva, Switzerland

6. Responsible for installing, configuring and administering VMware vsphere for test and production environments.

COMLINK Cloud Technical Specification Guide DEDICATED SERVER

CITY OF SAN MATEO, CALIFORNIA

Enterprise Information Technology Security Assessment RFP Answers to Questions

City of University City. Request for Proposal (RFP)

Enterprise SM VOLUME 1, SECTION 5.1: MANAGED TIERED SECURITY SERVICES

Cloud for Credit Unions Leveraging New Solutions to Increase Efficiency & Reduce Costs Presented by: Hugh Smallwood, Chief Technology Officer

Ashley Clarke Hosted Desktop. Business Name

CounselorMax and ORS Managed Hosting RFP 15-NW-0016

CONNECTICUT HOUSING FINANCE AUTHORITY REQUEST FOR PROPOSAL FOR Development of Strategic Information Technology Plan

RFQ IT Services. Questions and Answers

REQUEST FOR INFORMATION FOR HOSTED SERVER AND STORAGE ENVIRONMENT

JOB DESCRIPTION. *-- Assist with the administration of the Exchange Servers and Client Installations, including smart phones.

UMHLABUYALINGANA MUNICIPALITY IT PERFORMANCE AND CAPACITY MANAGEMENT POLICY

Department Description. Department Mission

The Elephant in the Room: What s the Buzz Around Cloud Computing?

Credit Unions and The Cloud. By: Chris Sachse

Client Security Risk Assessment Questionnaire

PROPOSALS REQUESTED THE TOWN OF OLD ORCHARD BEACH POLICE DEPARTMENT FOR IP-BASED VOICE COMMUNICATION SYSTEM

CLOUD SERVICES FOR EMS

I. EXECUTIVE SUMMARY. Date: June 30, Sabina Sitaru, Chief Innovation Officer, Metro Hartford Innovation Services

Response to Bidder Questions and Amendment 2 to Request for Proposal Disaster Recovery Services

TASK TDSP Web Portal Project Cyber Security Standards Best Practices

Request for Proposal to

Disaster Recovery Checklist Disaster Recovery Plan for <System One>

INFRASTRUCTURE SOLUTIONS OVERVIEW

iseries Server Cloud Migration Frequently Asked Questions

Audit of System Backup and Recovery Controls for the City of Milwaukee Datacenters MARTIN MATSON City Comptroller

THE COALFIELDS REGENERATION TRUST

Q&A ADDENDUM FOR INFORMATION SECURITY VULNERABILITY ASSESSMENT PUBLISHED 10/20/2015

ICT budget and staffing trends in the UK

Web Drive Limited TERMS AND CONDITIONS FOR THE SUPPLY OF SERVER HOSTING

A2: If the above list did not provide enough detail, please describe, in your own words, your enterprise s primary industry.

ADDENDUM #1 REQUEST FOR PROPOSALS

Server Virtualization Cloud Partner Training Series

Bridged Apps: specialise in the deployment of many well known apps, as well as building customer made apps, websites, and SEO.

Guardian365. Managed IT Support Services Suite

GETTING THE MOST FROM THE CLOUD. A White Paper presented by

Response to Questions CML Managed Information Security

North Florida Community College

Diagram Cloud Computing

EXECUTIVE SUMMARY 1.1 PROJECT OBJECTIVES

Service Descriptions

REQUEST FOR PROPOSAL. # Storage Solution RFP

Service Availability Metrics

Information Services and Technology FY Performance Plan

Managed IT Services. Maintain, manage and report

Computing: Public, Private, and Hybrid. You ve heard a lot lately about Cloud Computing even that there are different kinds of Clouds.

How To Run A Hosted Physical Server On A Server At Redcentric

MANAGED FIREWALL SERVICE. Service definition

GIS Support RFP Questions and Answers

Hosting Services VITA Contract VA AISN (Statewide contract available to any public entity in the Commonwealth)

Request for Resume (RFR) CATS II Master Contract. Section 1 General Information R00B

Hosted SharePoint: Questions every provider should answer

Retention & Destruction

Request for Expressions of Interest On a contract to perform: Renewal of Information Technology Strategic Plan

OFFICE OF THE STATE AUDITOR General Controls Review Questionnaire

Check Point and Security Best Practices. December 2013 Presented by David Rawle

Self-Hosted Applications

Keyfort Cloud Services (KCS)

IT General Controls Domain COBIT Domain Control Objective Control Activity Test Plan Test of Controls Results

Validating Cloud. June 2012 Merry Danley

Public or Private Cloud: The Choice is Yours

Supplier Security Assessment Questionnaire

Overview of Cloud Computing and Cloud Computing s Use in Government Justin Heyman CGCIO, Information Technology Specialist, Township of Franklin

2014 HIMSS Analytics Cloud Survey

ICT budget and staffing trends in Healthcare

Transcription:

Comprehensive IT Assessment Questions & Answers 1) Does the City have an approved budget for this project, range, or a not-to-exceed amount? IT Assessments vary widely in scope, comprehensiveness, and actual deliverables, which means costs vary widely as well. Our objective is to scale the project and deliverables that provide the greatest value and probability of successful implementation to meet your budget. A) The budget will be dependent on the overall analysis of the RFP proposals and the selection process for a vendor(s). 2) Is the City looking at a strategic roadmap in accordance with local governments best practices or some other best practices? The City uses the word industry standards and is it fair to assume the City is referring to local government standards or similarly sized organizations? A) Yes, in accordance with local government best practices and other regulatory requirements. 3) The City refers to Current State Analysis. Does the City intend to have the contractor perform a State Analysis of all departments the information technology is currently servicing to identify the current gaps? If so, approximately how many departments is the information technology servicing? A) Yes, there are 8 departments. The Police Department has their own IT. 4) Does the City provide IT services to any other municipalities or not-for-profit organizations, etc.? If so, will they be included in this study? 5) Has the City ever documented its IT strategic plan in the past? 6) Does the City have an up to date IT policies and procedures manual? 7) Does the City intend to have the contractor perform only a risk-based IT Assessment or is the City interested in having the contractor perform both internal and external penetration testing of the current IT infrastructure? A) The City would like to have the contractor perform both internal and external penetration testing of the current IT infrastructure. 8) Does the City have a preference on which framework the contractor should utilize to conduct its gap analysis and risk assessment? A) The City has no preference.

9) Was the pre-proposal meeting mandatory? If not, can you provide an attendee list and any relevant meeting minutes? A) The pre-proposal meeting was not mandatory and was just an opportunity for the vendors to get a firsthand look at our IT environment. The vendors were given a guided tour of the City s IT department and some of its local network switch closets. The following vendors were at the pre-proposal meeting: US ProTech Business Technology Solutions Axxera Consulting Services mgo CPA DTC Schafer Consulting Netixs McGladrey Accent Computer Solutions Sigmanet Client First Scientia 10) We see a reference to Windows Server 2003. Has the City purchased extended support through Microsoft since this operating system has reached its end of life? 11) What technology infrastructure is supported by the vendor on a monthly basis? A) VmWare, Data Backup, Microsoft Exchange, Firewall, Antivirus (Server Level) 12) Are the daycare centers and senior center City-owned properties staffed by City employees? A) Yes 13) Within IT Strategy, there is a reference to major initiatives and the technology plan. Can you provide a) details on what these major initiatives are and b) a copy of the technology plan? A) The major initiative is for an outside company to come in and evaluate our current IT environment and provide us with a strategic roadmap for the City s future operations. We do not have a current technology plan. 14) Does the City anticipate that any external shareholders (specifically citizens) would be engaged for development of the strategic plan?

15) Regarding the reference to an IT Risk Assessment, can you elaborate on the level of detail the City anticipates? This could include everything from a high-level review to a very detailed assessment (penetration testing, PCI compliance, etc.) A) The IT Risk Assessment should be detailed enough to meet the requirements of industry standards for local governments. 16) Are any of the IT employees to be assessed covered by a union/association and to what extent does the City anticipate their involvement in the Personnel deliverable? A) Yes, all city employees are covered by a union/ association. We do not anticipate the union will have any involvement in the Personnel deliverable. 17) What is the City s desired schedule for this project? A) First quarter of 2016. 18) Can the city provide an updated network/component diagram to show/indicate all technology equipment, the connectivity methodology used and the date of the last time each component was updated hardware/firmware/software. A) The city cannot provide this information because no record was kept and we don t have the resources to get an updated diagram at this time. 19) Related to the RFP documentation Item #6 Personnel: When appropriate please provide a CV/Resume for each of the three members of the current I.T. staff for the purpose of skills analysis/abilities to determine any gap/training opportunities A) When the time is appropriate; that information will be acquired through personal interviews of each of the three IT members. 20) Is there a list of managers from each department who are available to meet to obtain feedback and concerns can be uncovered regarding current technology platforms and future demands/objectives. A) We currently don't have a list of managers that are designated for this purpose. However, one can be arranged when the time come. 21) Does the city have any network analyzers/traffic data tools in place with reports/statistics on network traffic, bandwidth utilization, processor and memory utilization per device on the network?

22) What long-term contracts are in place for software applications and hardware platforms? List software packages, the usage and department utilizing the software and the length term of the contract. In addition, list hardware contracts, how many devices are under warranty and the terms of the warranty per device? A) Software / Hardware Usage Department Contract length Vision Internet City Website hosting all yearly Eden Finance/HR System all yearly Quadrant Cashiering system Finance yearly HDL Business License Finance yearly Barracuda 410 Web Filter IT 3 years Watch Guard Firewall IT Lease Sire Agenda and minutes City Clerk yearly TaskForce Fleet Management Public Works yearly System Fuel Force Fleet Fuel Public Works yearly Management system iworq Work order Public Works yearly management (webbase) GovClarity GIS system All yearly Accela Permits Plus Permit system Public Work, yearly Planning, Fire Dept. FireHouse Fire Record Fire Department yearly management system Telestaff Fire staff scheduling Fire Department yearly Class Class registration system Community services yearly 23) What percentage of the city s workforce are mobile today? How many mobile workers does the city anticipate over the next year, three years? What software applications are utilized in the mobile environment? A) A very small percent of the workforce are mobile. We do not anticipate more than 10 mobile worker within the next three years. They mainly use VPN and RDP to their desktops in their office. 24) What work is performed by the contractor on a monthly basis to help maintain the network? A) Firewall management, Data backup and restore, offsite data storage, monitor virtual servers, email recovery and hosted antivirus software on servers.

25) Does the city have any current plans/proposals underway to upgrade/purchase hardware or software applications to meet business needs of various entities supported by the city I.T. A) The City is planning to upgrade the IT infrastructure with new network switches, new Host for more virtual servers and new SAN. After that the City needs to plan on software upgrades throughout the City. 26) What current vendor provided network connectivity solutions are being utilized? What bandwidth is available, the configuration of current bandwidth, termination points and management options, term of contract and costs. A) We are using Charter Communications for internet and phone services. The speed is 25Mbps. It s a five year contract that expires in April of 2018 and costs $757/month. 27) When was the City s Technology Plan developed? Did the City utilize a third party to assist with development of the plan? A) We do not currently have a Technology Plan. 28) Does the City have an existing risk assessment process that has defined threats and vulnerabilities that the City monitors ongoing? 29) Does the City conduct any regular customer surveys to gauge the service delivery capabilities of the existing technology organizational mix of in-house and outsourced personnel? 30) What are the core enterprise applications utilized by the City (financial management, HR/Payroll, Billing, Operations)? A) Finance/HR/Payroll Eden by Tyler Technologies, HDL for business license, Quadrant for cashiering, Permits Plus, Sire for Agendas and Document Imaging, Firehouse for Fire record management, Telestaff for Fire department staff scheduling and IWorQ for work orders in public works. 31) Has the City identified the Public and non-public entities that would be used in comparing IT Costs? 32) Do you have a 3-5 year business plan, and supporting technology strategic plan?

33) Do you have an enterprise risk management program, and risk framework for controls and Security management? 34) Do you have a governance structure (executive steering committee) for investment approvals and progress reviews? A) The Finance Department and City Manager s Office. 35) Do you measure and manage their environment by any IT KPIs? 36) Top 3 business challenges? A) 1. Accomplishing more with less 2. Moving over to the cloud 3. Software compatibility 37) Infrastructure platform on-prem, outsourced or cloud-based? A) On premise Windows 38) Types of references required? A) The Consultant/Contractor shall submit with his/her proposal a list of at least three (3) clients using the same service being proposed, with names, addresses, and telephone numbers. A survey of references will be made to determine, among other things, the vendor s success in meeting the needs of the contracting agency in a timely manner.