Extracted text (via pymupdf)
90434 characters
CONTRACT MANAGED SECURITY SERVICES PROVIDER (MSSP) 240094-RFP This contract is entered into this 26th day of June, 2024 by and between Maricopa County (County), a political subdivision of the State of Arizona, and Transource Services Corp dba Transource Computers, an Arizona corporation (Contractor) for the purchase of a Managed Security Services Provider (MSSP) that provides security operation center services. 1.0 CONTRACT TERM This contract is for a term of three years, beginning on the 1st day of July, 2024 and ending the 30th day of June, 2027. 2.0 OPTION TO RENEW The County may, at its option and with the concurrence of the Contractor, renew the term of this contract up to a maximum of three additional years, (or at the County’s sole discretion, extend the contract on a month-to-month basis for a maximum of six months after expiration). The Contractor shall be notified in writing by the Office of Procurement Services of the County’s intention to renew the contract term at least 60 calendar days prior to the expiration of the original contract term. 3.0 CONTRACT COMPLETION In preparation for contract completion, the Contractor shall make all reasonable efforts for an orderly transition of its duties and responsibilities to another provider and/or to the County. This may include, but is not limited to, preparation of a transition plan and cooperation with the County or other providers in the transition. The transition includes the transfer of all records and other data in the possession, custody, or control of the Contractor that are required to be provided to the County either by the terms of this agreement or as a matter of law. The provisions of this clause shall survive the expiration or termination of this agreement. 4.0 PRICE ADJUSTMENTS Any requests for reasonable price adjustments must be submitted 60 calendar days prior to contract expiration. Requests for adjustment in cost of labor and/or materials must be supported by appropriate documentation. The reasonableness of the request will be determined by comparing the request with the Consumer Price Index or by performing a market survey. If County agrees to the adjusted price terms, County shall issue written approval of the change and provide an updated version of the contract. The new change shall not be in effect until the date stipulated on the updated version of the contract. 5.0 PAYMENTS 5.1 As consideration for performance of the duties described herein, County shall pay Contractor the sum(s) stated in Exhibit A – Vendor Information and Pricing. 5.2 Payment shall be made upon the County’s receipt of a properly completed invoice. SERIAL 240094-RFP 5.3 INVOICES 5.3.1 The Contractor shall submit one legible copy of their detailed invoice before payment(s) will be made. Incomplete invoices will not be processed. At a minimum, the invoice must provide the following information: • Company name, address, and contact information • County bill-to name and contact information • Contract serial number • County purchase order number • Project name and/or number • Invoice number and date • Payment terms • Date of service or delivery • Quantity • Contract item number(s) • Description of purchase (product or services) • Pricing per unit of purchase • Extended price • Total amount due 5.3.2 Problems regarding billing or invoicing shall be directed to the department as listed on the purchase order. 5.3.3 Payment shall only be made to the Contractor by Accounts Payable through the Maricopa County Vendor Express Payment Program. This is an Electronic Funds Transfer (EFT) process. After Contract Award the Contractor shall complete the Vendor Registration Form located on the County Department of Finance Vendor Registration Web Site (https://www.maricopa.gov/5169/Vendor-Information). 5.3.4 Discounts offered in the contract shall be calculated based on the date a properly completed invoice is received by the County. 5.3.5 EFT payments to the routing and account numbers designated by the Contractor shall include the details on the specific invoices that the payment covers. The Contractor is required to discuss remittance delivery capabilities with their designated financial institution for access to those details. 5.4 CRITERIA FOR DELIVERY AND ACCEPTANCE OF DELIVERABLES 5.4.1 The Contractor shall submit all Deliverables to the County Representative. Each Deliverable will be in the requisite format specified in the SOW and contain the content required by the SOW prior to the Deliverable being submitted. Documentation shall be delivered in one electronic version with accompanying transmittal letters. 5.4.1.1 County Representative shall review and validate Contractor’s Deliverables product prior to Acceptance. Acceptance criteria for Deliverables shall consist of the following: 5.4.1.1.1 Specific Deliverables are completed as specified in this Contract and the final Deliverable has been rendered. 5.4.1.1.2 Plans, schedules, designs, documentation, and reports are approved and completed as specified in this Contract. 5.4.1.1.3 All supporting Documentation is provided and completed. SERIAL 240094-RFP 5.4.1.1.4 All Deliverables are presented to County in the approved format (or if no such format is approved, in an industry- standard format). 5.4.1.1.5 All Deliverables are at the agreed upon acceptable level of quality as defined in this Contract. 5.5 APPLICABLE TAXES 5.5.1 It is the responsibility of the Contractor to determine any and all applicable taxes and include those taxes in their proposal. The legal liability to remit the tax is on the entity conducting business in Arizona. Tax is not a determining factor in contract award. 5.5.2 The County will look at the price or offer submitted and will not deduct, add, or alter pricing based on speculation or application of any taxes, nor will the County provide Contractor any advice or guidance regarding taxes. If you have questions regarding your tax liability, seek advice from a tax professional prior to submitting your bid. You may also find information at https://www.azdor.gov/Business.aspx. Once your bid is submitted, the offer is valid for the time specified in this solicitation, regardless of mistake or omission of tax liability. If the County finds overpayment of a project due to tax consideration that was not due, the Contractor will be liable to the County for that amount, and by contracting with the County agrees to remit any overpayments back to the County for miscalculations on taxes included in a bid price. 5.5.3 Tax Indemnification: Contractor and all subcontractors shall pay all Federal, State, and local taxes applicable to their operation and any persons employed by the Contractor. Contractor shall, and require all subcontractors to, hold Maricopa County harmless from any responsibility for taxes, damages, and interest, if applicable, contributions required under Federal and/or State and local laws and regulations, and any other costs including: transaction privilege taxes, unemployment compensation insurance, Social Security, and workers’ compensation. Contractor may be required to establish, to the satisfaction of County, that any and all fees and taxes due to municipality or the State of Arizona for any license or transaction privilege taxes, use taxes, or similar excise taxes are currently paid (except for matters under legal protest). 6.0 AVAILABILITY OF FUNDS 6.1 The provisions of this contract relating to payment for services shall become effective when funds assigned for the purpose of compensating the Contractor as herein provided are actually available to County for disbursement. The County shall be the sole judge and authority in determining the availability of funds under this contract. County shall keep the Contractor fully informed as to the availability of funds. 6.2 If any action is taken by, any State agency, Federal department, or any other agency or instrumentality to suspend, decrease, or terminate its fiscal obligations under, or in connection with, this contract, County may amend, suspend, decrease, or terminate its obligations under, or in connection with, this contract. In the event of termination, County shall be liable for payment only for services rendered prior to the effective date of the termination, provided that such services are performed in accordance with the provisions of this contract. County shall give written notice of the effective date of any suspension, amendment, or termination under this section, at least 10 days in advance. 7.0 STRATEGIC ALLIANCE for VOLUME EXPENDITURES (SAVE) The County is a member of the SAVE cooperative purchasing group. SAVE includes the State of Arizona, many Phoenix metropolitan area municipalities, and many K-12 unified school districts. Under the SAVE Cooperative Purchasing Agreement, and with the concurrence of the successful respondent under this solicitation, a member of SAVE may access a contract resulting from a solicitation issued by the County. If contractor does not want to grant such access to a member of SAVE, state so in contractor’s bid. In the absence of a statement to the contrary, the County will assume that contractor does wish to grant access to any contract that may result from this bid. The County assumes no responsibility for any purchases by using entities. 8.0 INTERGOVERNMENTAL COOPERATIVE PURCHASING AGREEMENTS (ICPAs) County currently holds ICPAs with numerous governmental entities. These agreements allow those entities, with the approval of the Contractor, to purchase their requirements under the terms and conditions of the County contract. It is the responsibility of the non-County government entity to perform its own due diligence on the acceptability of the contract under its applicable procurement rules, processes, and procedures. Certain governmental agencies may not require an ICPA and may utilize this contract if it meets their individual requirements. Other governmental agencies may enter into a separate Statement of Work with the Contractor to meet their own requirements. The County is not a party to any uses of this contract by other governmental entities. 9.0 DUTIES 9.1 The Contractor shall perform all duties stated in Exhibit B – Scope of Work, or as otherwise directed in writing by the procurement officer. 9.2 During the contract term, County may provide Contractor’s personnel with adequate workspace for consultants and such other related facilities as may be required by Contractor to carry out its contractual obligations. 10.0 TERMS AND CONDITIONS 10.1 INDEMNIFICATION 10.1.1 To the fullest extent permitted by law, and to the extent that claims, damages, losses, or expenses are not covered and paid by insurance purchased by the contractor, the contractor shall defend, indemnify, and hold harmless the County (as Owner), its agents, representatives, officers, directors, officials, and employees from and against all claims, damages, losses, and expenses (including, but not limited to attorneys' fees, court costs, expert witness fees, and the costs and attorneys' fees for appellate proceedings) arising out of, or alleged to have resulted from, the negligent acts, errors, omissions, or mistakes of the contractor, a subcontractor, anyone directly or indirectly employed by them, or anyone for whose acts they may be liable relating to the performance of this contract. 10.1.2 Contractor's duty to defend, indemnify, and hold harmless the County, its agents, representatives, officers, directors, officials, and employees shall arise in connection with any claim, damage, loss, or expense that is attributable to bodily injury, sickness, disease, death, or injury to, impairment of, or destruction of tangible property, including loss of use resulting therefrom, caused by negligent acts, errors, omissions, or mistakes in the performance of this contract, but only to the extent caused by the negligent acts or omissions of the contractor, a subcontractor, anyone directly or indirectly employed by them, or anyone for whose acts they may be liable, regardless of whether or not such claim, damage, loss, or expense is caused in part by a party indemnified hereunder. 10.1.3 The amount and type of insurance coverage requirements set forth herein will in no way be construed as limiting the scope of the indemnity in this section. SERIAL 240094-RFP 10.1.4 The scope of this indemnification does not extend to the sole negligence of County. 10.2 INSURANCE 10.2.1 Contractor, at Contractor’s own expense, shall purchase and maintain, at a minimum, the herein stipulated insurance from a company or companies duly licensed by the State of Arizona and possessing an AM Best, Inc. category rating of B++. In lieu of State of Arizona licensing, the stipulated insurance may be purchased from a company or companies, which are authorized to do business in the State of Arizona, provided that said insurance companies meet the approval of County. The form of any insurance policies and forms must be acceptable to County. 10.2.2 All insurance required herein shall be maintained in full force and effect until all work or service required to be performed under the terms of the contract is satisfactorily completed and formally accepted. Failure to do so may, at the sole discretion of County, constitute a material breach of this contract. 10.2.3 In the event that the insurance required is written on a claims-made basis, Contractor warrants that any retroactive date under the policy shall precede the effective date of this contract and either continuous coverage will be maintained, or an extended discovery period will be exercised for a period of two years beginning at the time work under this contract is completed. 10.2.4 Contractor’s insurance shall be primary insurance as respects County, and any insurance or self-insurance maintained by County shall not contribute to it. 10.2.5 Any failure to comply with the claim reporting provisions of the insurance policies or any breach of an insurance policy warranty shall not affect the County’s right to coverage afforded under the insurance policies. 10.2.6 The insurance policies may provide coverage that contains deductibles or self- insured retentions. Such deductible and/or self-insured retentions shall not be applicable with respect to the coverage provided to County under such policies. Contractor shall be solely responsible for the deductible and/or self-insured retention and County, at its option, may require Contractor to secure payment of such deductibles or self-insured retentions by a surety bond or an irrevocable and unconditional letter of credit. 10.2.7 The insurance policies required by this contract, except Workers’ Compensation and Errors and Omissions, shall name County, its agents, representatives, officers, directors, officials, and employees as additional insureds. 10.2.8 The policies required hereunder, except Workers’ Compensation and Errors and Omissions, shall contain a waiver of transfer of rights of recovery (subrogation) against County, its agents, representatives, officers, directors, officials, and employees for any claims arising out of Contractor’s work or service. 10.2.9 If available, the insurance policies required by this contract may be combined with Commercial Umbrella Insurance policies to meet the minimum limit requirements. If a Commercial Umbrella insurance policy is utilized to meet insurance requirements, the Certificate of Insurance shall indicate which lines the Commercial Umbrella Insurance covers. SERIAL 240094-RFP 10.2.9.1 Commercial General Liability Commercial General Liability (CGL) insurance and, if necessary, Commercial Umbrella insurance with a limit of not less than $2,000,000 for each occurrence, $4,000,000 Products/Completed Operations Aggregate, and $4,000,000 General Aggregate Limit. The policy shall include coverage for premises liability, bodily injury, broad form property damage, personal injury, products and completed operations and blanket contractual coverage, and shall not contain any provisions which would serve to limit third party action over claims. There shall be no endorsement or modifications of the CGL limiting the scope of coverage for liability arising from explosion, collapse, or underground property damage. 10.2.9.2 Workers’ Compensation 10.2.9.2.1 Workers’ compensation insurance to cover obligations imposed by Federal and State statutes having jurisdiction of Contractor’s employees engaged in the performance of the work or services under this contract; and Employer’s Liability insurance of not less than $1,000,000 for each accident, $1,000,000 disease for each employee, and $1,000,000 disease policy limit. 10.2.9.2.2 Contractor, its subcontractors, and sub-subcontractors waive all rights against this contract and its agents, officers, directors, and employees for recovery of damages to the extent these damages are covered by the workers’ compensation and Employer’s Liability or Commercial Umbrella Liability insurance obtained by Contractor, its subcontractors, and its sub-subcontractors pursuant to this contract. 10.2.9.3 Errors and Omissions/Professional Liability Insurance Technology Errors & Omission insurance: Such insurance shall cover any and all errors, omissions, or negligent acts in the delivery of products, services, and/or licensed programs under this contract. • Each claim $5,000,000 In the event that the Technology Errors & Omission insurance required by this contract is written on a claims-made basis, contractor warrants that any retroactive date under the policy shall precede the effective date of this contract and, either continuous coverage will be maintained, or an extended discovery period will be exercised for a period of two years, beginning at the time work under this contract is completed. Cyber, Network Security, and Privacy Liability Cyber, Network Security and Privacy Liability Insurance with a limit of not less than $5,000,000 per occurrence. The policy shall include, but not be limited to; coverage for all directors, officers, agents and employees of the Contractor, losses with respect to network risks (such as data breaches, unauthorized access or use, and ID theft of data), invasion of privacy (regardless of the type of media involved in the loss of private information), crisis management, identity theft response costs, breach notification costs, credit remediation, and credit monitoring, defense, and claims expenses, regulatory defense costs plus fines and SERIAL 240094-RFP penalties, cyber extortion, electronic data restoration expenses (data asset protection), network business interruption, computer fraud coverage, funds transfer loss, third-party fidelity, theft, no requirement for arrest and conviction, and loss outside the premises of the named insured. 10.2.10 Certificates of Insurance 10.2.10.1 Prior to contract award, Contractor shall furnish the County with valid and complete Certificates of Insurance, or formal endorsements as required by the contract in the form provided by the County, issued by Contractor’s insurer(s), as evidence that policies providing the required coverage, conditions and limits required by this contract are in full force and effect. Such certificates shall identify this contract number and title. 10.2.10.2 In the event any insurance policy(ies) required by this contract is (are) written on a claims-made basis, coverage shall extend for two years past completion and acceptance of Contractor’s work or services and as evidenced by annual certificates of insurance. 10.2.10.3 If a policy does expire during the life of the Contract, a renewal certificate must be sent to County 15 calendar days prior to the expiration date. 10.2.10.4 Certificates of Insurance shall identify Maricopa County as the certificate holder as follows: Maricopa County c/o Risk Management 301 W Jefferson St, Suite 910 Phoenix, AZ 85003 10.2.11 Cancellation and Expiration Notice Applicable to all insurance policies required within the insurance requirements of this contract, Contractor’s insurance shall not be permitted to expire, be suspended, be canceled, or be materially changed for any reason without 30 days prior written notice to Maricopa County. Contractor must provide to Maricopa County, within two business days of receipt, if they receive notice of a policy that has been or will be suspended, canceled, materially changed for any reason, has expired, or will be expiring. Such notice shall be sent directly to Maricopa County Office of Procurement Services and shall be mailed, or hand delivered to 301 W. Jefferson, Suite 700, Phoenix, AZ 85003, or emailed to the procurement officer noted in the solicitation. 10.3 FORCE MAJEURE 10.3.1 Neither party shall be liable for failure of performance, nor incur any liability to the other party on account of any loss or damage resulting from any delay or failure to perform all or any part of this contract, if such delay or failure is caused by events, occurrences, or causes beyond the reasonable control and without negligence of the parties. Such events, occurrences, or causes include, but are not limited to, acts of God/nature (including fire, flood, earthquake, storm, hurricane, or other natural disaster), war, invasion, act of foreign enemies, hostilities (whether war is declared or not), civil war, riots, rebellion, revolution, insurrection, military or usurped power or confiscation, terrorist activities, nationalization, government sanction, lockout, blockage, embargo, labor dispute, strike, and interruption or failure of electricity or telecommunication service, and pandemic. SERIAL 240094-RFP 10.3.2 Each party, as applicable, shall give the other party notice of its inability to perform and particulars in reasonable detail of the cause of the inability. Each party must use best efforts to remedy the situation and remove, as soon as practicable, the cause of its inability to perform or comply. 10.3.3 The party asserting Force Majeure as a cause for non-performance shall have the burden of proving that reasonable steps were taken to minimize delay or damages caused by foreseeable events, that all non-excused obligations were substantially fulfilled, and that the other party was timely notified of the likelihood or actual occurrence which would justify such an assertion, so that other prudent precautions could be contemplated. 10.4 ORDERING AUTHORITY Any request for purchase shall be accompanied by a valid purchase order issued by a County department or directed by a Certified Agency Procurement Aid (CAPA) with a purchase card for payment. 10.5 PROCUREMENT CARD ORDERING CAPABILITY County may opt to use a procurement card (Visa or Master Card) to make payment for orders under this contract. 10.6 NO MINIMUM OR MAXIMUM PURCHASE OBLIGATION This contract does not guarantee any minimum or maximum purchases will be made. Orders will only be placed under this contract when the County identifies a need and proper authorization and documentation have been approved. 10.7 PURCHASE ORDERS 10.7.1 County reserves the right to cancel purchase orders within a reasonable period of time after issuance. Should a purchase order be canceled, the County agrees to reimburse the Contractor for actual and documentable costs incurred by the Contractor in response to the purchase order. The County will not reimburse the Contractor for any costs incurred after receipt of County notice of cancellation, or for lost profits, or for shipment of product prior to issuance of purchase order. 10.7.2 Contractor agrees to accept verbal notification of cancellation of purchase orders from the County procurement officer with written notification to follow. Contractor specifically acknowledges to be bound by this cancellation policy. 10.8 BACKGROUND CHECK Respondents may be required to pass multiple background checks (e.g., Sheriff’s Office, County Attorney's Office, Courts, as well as Maricopa County general government) to determine if the respondent is acceptable to do business with the County. This applies to, but is not limited to, the company, subcontractors, and employees, and the failure to pass these checks shall deem the respondent non-responsible. 10.9 SUSPENSION OF WORK The procurement officer may order the Contractor, in writing, to suspend, delay, or interrupt all or any part of the work of this contract for the period of time that the procurement officer determines appropriate for the convenience of the County. No adjustment shall be made under this clause for any suspension, delay, or interruption to the extent that performance would have been so suspended, delayed, or interrupted by any other cause, including the fault or negligence of the Contractor. No request for adjustment under this clause shall be granted unless the claim, in an amount stated, is asserted in writing as soon as practicable SERIAL 240094-RFP after the termination of the suspension, delay, or interruption, but not later than the date of final payment under the contract. 10.10 STOP WORK ORDER 10.10.1 The procurement officer may, at any time, by written order to the Contractor, require the Contractor to stop all, or any part, of the work called for by this contract for a period of 90 calendar days after the order is delivered to the Contractor, and for any further period to which the parties may agree. The order shall be specifically identified as a stop work order issued under this clause. Upon receipt of the order, the Contractor shall immediately comply with its terms and take all reasonable steps to minimize the incurrence of costs allocable to the work covered by the order during the period of work stoppage. Within a period of 90 calendar days after a stop work order is delivered to the Contractor, or within any extension of that period to which the parties shall have agreed, the procurement officer shall either: 10.10.1.1 cancel the stop work order; or 10.10.1.2 terminate the work covered by the order as provided in the Termination for Default or the Termination for Convenience clause of this contract. 10.10.1.3 The procurement officer may make an equitable adjustment in the delivery schedule and/or contract price, and the contract shall be modified, in writing, accordingly, if the Contractor demonstrates that the stop work order resulted in an increase in costs to the Contractor. 10.11 TERMINATION FOR CONVENIENCE Maricopa County may terminate the resultant contract for convenience by providing 60 calendar days advance notice to the Contractor. 10.12 TERMINATION FOR DEFAULT 10.12.1 The County may, by written Notice of Default to the Contractor, terminate this contract in whole or in part if the Contractor fails to: 10.12.1.1 deliver the supplies or to perform the services within the time specified in this contract or any extension; 10.12.1.2 make progress, so as to endanger performance of this contract; or 10.12.1.3 perform any of the other provisions of this contract. 10.12.2 The County’s right to terminate this contract under these subparagraphs may be exercised if the Contractor does not cure such failure within 10 business days (or more if authorized in writing by the County) after receipt of a Notice to Cure from the procurement officer specifying the failure. 10.13 PERFORMANCE It shall be the Contractor’s responsibility to meet the proposed performance requirements. Maricopa County reserves the right to obtain services on the open market in the event the Contractor fails to perform, and any price differential will be charged against the Contractor. 10.14 CONTRACTOR EMPLOYEE MANAGEMENT 10.14.1 Contractor shall endeavor to maintain the personnel proposed in their proposal throughout the performance of this contract. SERIAL 240094-RFP 10.14.2 If Contractor personnel’s employment status changes, Contractor shall provide County a list of proposed replacements with equivalent or greater experience. 10.14.3 Under no circumstances shall the implementation schedule to be impacted by a personnel change on the part of the Contractor. 10.14.4 Contractor shall not reassign any key personnel identified in their proposal without the express consent of the County. 10.14.5 County reserves the right to immediately remove from its premises any Contractor personnel it determines to be a risk to County operations. 10.14.6 County reserves the right to request the replacement of any Contractor personnel at any time, for any reason. 10.15 WARRANTY OF SERVICES 10.15.1 The Contractor warrants that all services provided hereunder will conform to the requirements of the contract, including all descriptions, specifications, and attachments made a part of this contract. County’s acceptance of services or goods provided by the Contractor shall not relieve the Contractor from its obligations under this warranty. 10.15.2 In addition to its other remedies, County may, at the Contractor's expense, require prompt correction of any services failing to meet the Contractor's warranty herein. Services corrected by the Contractor shall be subject to all the provisions of this contract in the manner and to the same extent as services originally furnished hereunder. 10.16 INSPECTION OF SERVICES 10.16.1 The Contractor shall provide and maintain an inspection system acceptable to County covering the services under this contract. Complete records of all inspection work performed by the Contractor shall be maintained and made available to County during contract performance and for as long afterwards as the contract requires. 10.16.2 County has the right to inspect and test all services called for by the contract, to the extent practicable at all times and places during the term of the contract. County shall perform inspections and tests in a manner that will not unduly delay the work. 10.16.3 If any of the services do not conform to contract requirements, County may require the Contractor to perform the services again in conformity with contract requirements, at no cost to the County. When the defects in services cannot be corrected by re-performance, County may: 10.16.3.1 require the Contractor to take necessary action to ensure that future performance conforms to contract requirements; and 10.16.3.2 reduce the contract price to reflect the reduced value of the services performed. 10.16.4 If the Contractor fails to promptly perform the services again or to take the necessary action to ensure future performance in conformity with contract requirements, County may: SERIAL 240094-RFP 10.16.4.1 by contract or otherwise, perform the services and charge to the Contractor, through direct billing or through payment reduction, any cost incurred by County that is directly related to the performance of such service; or 10.16.4.2 terminate the contract for default. 10.17 USAGE REPORT The Contractor shall furnish the County a usage report, upon request, delineating the acquisition activity governed by the contract. The format of the report shall be approved by the County and shall disclose the quantity and dollar value of each contract item by individual unit of measure. 10.18 STATUTORY RIGHT OF CANCELLATION FOR CONFLICT OF INTEREST Notice is given that, pursuant to A.R.S. § 38-511, the County may cancel any contract without penalty or further obligation within three years after execution of the contract, if any person significantly involved in initiating, negotiating, securing, drafting, or creating the contract on behalf of the County is at any time, while the contract or any extension of the contract is in effect, an employee or agent of any other party to the contract in any capacity or consultant to any other party of the contract with respect to the subject matter of the contract. Additionally, pursuant to A.R.S. § 38-511, the County may recoup any fee or commission paid or due to any person significantly involved in initiating, negotiating, securing, drafting, or creating the contract on behalf of the County from any other party to the contract arising as the result of the contract. 10.19 OFFSET FOR DAMAGES In addition to all other remedies at Law or Equity, the County may offset from any money due to the Contractor any amounts Contractor owes to the County for damages resulting from breach or deficiencies in performance of the contract. 10.20 SUBCONTRACTING 10.20.1 The Contractor may not assign to another Contractor or subcontract to another party for performance of the terms and conditions hereof without the written consent of the County. All correspondence authorizing subcontracting must reference the bid serial number and identify the job or project. 10.20.2 The subcontractor’s rate for the job shall not exceed that of the prime Contractor’s rate, as bid in the pricing section, unless the prime Contractor is willing to absorb any higher rates. The subcontractor’s invoice shall be invoiced directly to the prime Contractor, who in turn shall pass-through the costs to the County, without mark- up. A copy of the subcontractor’s invoice must accompany the prime Contractor’s invoice. 10.21 AMENDMENTS All amendments to this contract shall be in writing and approved/signed by both parties. Maricopa County Office of Procurement Services shall be responsible for approving all amendments for Maricopa County. 10.22 ADDITIONS/DELETIONS OF REQUIREMENTS The County reserves the right to add and/or delete materials and services to a contract. If a service requirement is deleted, payment to the Contractor will be reduced proportionately, to the amount of service reduced in accordance with the bid price. If additional materials SERIAL 240094-RFP or services are required from a contract, prices for such additions will be negotiated between the Contractor and the County. 10.23 RIGHTS IN DATA 10.23.1 The County shall have the use of data and reports resulting from a contract without additional cost or other restriction except as may be established by law or applicable regulation. Each party shall supply to the other party, upon request, any available information that is relevant to a contract and to the performance thereunder. 10.23.2 Data, records, reports, and all other information generated for the County by a third party as the result of a contract are the property of the County and shall be provided in a format designated by the County or shall be and remain accessible to the County into perpetuity. 10.24 ACCESS TO AND RETENTION OF RECORDS FOR THE PURPOSE OF AUDIT AND/OR OTHER REVIEW 10.24.1 In accordance with Section MC1-372 of the Maricopa County Procurement Code, the Contractor agrees to retain (physical or digital copies of) all books, records, accounts, statements, reports, files, and other records and back-up documentation relevant to this contract for six years after final payment or until after the resolution of any audit questions, which could be more than six years, whichever is longest. The County, Federal or State auditors and any other persons duly authorized by the department shall have full access to and the right to examine, copy, and make use of, any and all said materials. 10.24.2 If the Contractor’s books, records, accounts, statements, reports, files, and other records and back-up documentation relevant to this contract are not sufficient to support and document that requested services were provided, the Contractor shall reimburse Maricopa County for the services not so adequately supported and documented. 10.25 AUDIT DISALLOWANCES If at any time it is determined by the County that a cost for which payment has been made is a disallowed cost, the County shall notify the Contractor in writing of the disallowance. The course of action to address the disallowance shall be at sole discretion of the County, and may include either an adjustment to future invoices, request for credit, request for a check, or a deduction from current invoices submitted by the Contractor equal to the amount of the disallowance, or to require reimbursement forthwith of the disallowed amount by the Contractor by issuing a check payable to Maricopa County. 10.26 STRICT COMPLIANCE Acceptance by County of a performance that is not in strict compliance with the terms of the contract shall not be deemed to be a waiver of strict compliance with respect to all other terms of the contract. 10.27 VALIDITY The invalidity, in whole or in part, of any provision of this contract shall not void or affect the validity of any other provision of the contract. 10.28 SEVERABILITY The removal, in whole or in part, of any provision of this contract shall not void or affect the validity of any other provision of this contract. SERIAL 240094-RFP 10.29 RELATIONSHIPS 10.29.1 In the performance of the services described herein, the Contractor shall act solely as an independent Contractor, and nothing herein or implied herein shall at any time be construed as to create the relationship of employer and employee, co- employee, partnership, principal and agent, or joint venture between the County and the Contractor. 10.29.2 The County reserves the right of final approval on proposed staff. Also, upon request by the County, the Contractor will be required to remove any employees working on County projects and substitute personnel based on the discretion of the County within two business days, unless a different time period was previously approved by the County. 10.30 NON-DISCRIMINATION Contractor agrees to comply with all provisions and requirements of Arizona Executive Order 2009-09, including flow down of all provisions and requirements to any subcontractors. Executive Order 2009-09 supersedes Executive Order 99-4 and amends Executive Order 75-5 and is hereby incorporated into this contract as if set forth in full herein. During the performance of this contract, contractor shall not discriminate against any employee, client, or any other individual in any way because of that person’s age, race, creed, color, religion, sex, disability, or national origin. (Arizona Executive Order 2009-09 can be viewed at https://apps.azsos.gov/public_services/register/2009/46/governor.pdf). 10.31 WRITTEN CERTIFICATION PURSUANT to A.R.S. § 35-393.01 If vendor engages in for-profit activity and has 10 or more employees, and if this agreement has a value of $100,000 or more, vendor certifies it is not currently engaged in, and agrees for the duration of this agreement to not engage in, a boycott of goods or services from Israel. This certification does not apply to a boycott prohibited by 50 U.S.C. § 4842 or a regulation issued pursuant to 50 U.S.C. § 4842. 10.32 CERTIFICATION REGARDING DEBARMENT AND SUSPENSION 10.32.1 The undersigned (authorized official signing on behalf of the Contractor) certifies to the best of his or her knowledge and belief that the Contractor, its current officers, and directors: 10.32.1.1 are not presently debarred, suspended, proposed for debarment, declared ineligible, or voluntarily excluded from being awarded any contract or grant by any United States department or agency or any state, or local jurisdiction; 10.32.1.2 have not within a three-year period preceding this contract: 10.32.1.2.1 been convicted of fraud or any criminal offense in connection with obtaining, attempting to obtain, or as the result of performing a government entity (Federal, State or local) transaction or contract; or 10.32.1.2.2 been convicted of violation of any Federal or State antitrust statutes or conviction for embezzlement, theft, forgery, bribery, falsification or destruction of records, making false statements, or receiving stolen property regarding a government entity transaction or contract; SERIAL 240094-RFP 10.32.1.3 are not presently indicted or criminally charged by a government entity (Federal, State or local) with commission of any criminal offenses in connection with obtaining, attempting to obtain, or as the result of performing a government entity public (Federal, State or local) transaction or contract; 10.32.1.4 are not presently facing any civil charges from any governmental entity regarding obtaining, attempting to obtain, or from performing any governmental entity contract or other transaction; and 10.32.1.5 have not within a three-year period preceding this contract had any public transaction (Federal, State or local) terminated for cause or default. 10.32.2 If any of the above circumstances described in the paragraph are applicable to the entity submitting a bid for this requirement, include with your bid an explanation of the matter including any final resolution. 10.32.3 The Contractor shall include, without modification, this clause in all lower tier covered transactions (i.e., transactions with subcontractors or sub-subcontractors) and in all solicitations for lower tier covered transactions related to this contract. If this clause is applicable to a subcontractor or sub-subcontractor, the Contractor shall include the information required by this clause with their bid. 10.33 VERIFICATION REGARDING COMPLIANCE WITH A.R.S. § 41-4401 AND FEDERAL IMMIGRATION LAWS AND REGULATIONS 10.33.1 By entering into the contract, the Contractor warrants compliance with the Immigration and Nationality Act (INA using E-Verify) and all other Federal immigration laws and regulations related to the immigration status of its employees and A.R.S. § 23-214(A). The Contractor shall obtain statements from its subcontractors certifying compliance and shall furnish the statements to the procurement officer upon request. These warranties shall remain in effect through the term of the contract. The Contractor and its subcontractors shall also maintain Employment Eligibility Verification forms (I-9) as required by the Immigration Reform and Control Act of 1986, as amended from time to time, for all employees performing work under the contract and verify employee compliance using the E-Verify system and shall keep a record of the verification for the duration of the employee’s employment or at least three years, whichever is longer. I-9 forms are available for download at www.uscis.gov. 10.33.2 The County retains the legal right to inspect documents of Contractor and subcontractor employees performing work under this contract to verify compliance with paragraph 10.33.1 of this section. Contractor and subcontractor shall be given reasonable notice of the County’s intent to inspect and shall make the documents available at the time and date specified. Should the County suspect or find that the Contractor or any of its subcontractors are not in compliance, the County will consider this a material breach of the contract and may pursue any and all remedies allowed by law, including, but not limited to: suspension of work, termination of the contract for default, and suspension and/or debarment of the Contractor. All costs necessary to verify compliance are the responsibility of the Contractor. 10.34 CONTRACTOR LICENSE REQUIREMENT 10.34.1 The Contractor shall procure all permits, insurance, and licenses, and pay the charges and fees necessary and incidental to the lawful conduct of his/her business, and as necessary complete any requirements, by any and all governmental or non-governmental entities as mandated to maintain compliance with and remain in good standing. The Contractor shall keep fully informed of SERIAL 240094-RFP existing and future trade or industry requirements, and Federal, State, and local laws, ordinances, and regulations which in any manner affect the fulfillment of a contract and shall comply with the same. Contractor shall immediately notify both the Office of Procurement Services and the department of any and all changes concerning permits, insurance, or licenses. 10.35 INFLUENCE 10.35.1 As prescribed in MC1-1203 of the Maricopa County Procurement Code, any effort to influence an employee or agent to breach the Maricopa County Ethical Code of Conduct or any ethical conduct, may be grounds for disbarment or suspension under MC1-902. 10.35.2 An attempt to influence includes, but is not limited to: 10.35.2.1 A person offering or providing a gratuity, gift, tip, present, donation, money, entertainment or educational passes or tickets, or any type of valuable contribution or subsidy that is offered or given with the intent to influence a decision, obtain a contract, garner favorable treatment, or gain favorable consideration of any kind. 10.35.3 If a person attempts to influence any employee or agent of Maricopa County, the chief procurement officer, or his designee, reserves the right to seek any remedy provided by the Maricopa County Procurement Code, any remedy in equity or in the law, or any remedy provided by this contract. 10.35.4 ABSOLUTELY NO CONTACT BETWEEN THE RESPONDENT AND ANY COUNTY PERSONNEL, OTHER THAN THE OFFICE OF PROCUREMENT SERVICES, IS ALLOWED DURING THE SOLICITATION PROCESS UNLESS THE COMMUNICATION IS IN REGARD TO PRE-EXISTING BUSINESS WITH THE COUNTY. ANY COMMUNICATIONS REGARDING THE SOLICITATION, ITS PARTICIPANTS, OR ANY DOCUMENTATION PRIOR TO THE CONTRACT AWARD MAY BE GROUNDS FOR DISMISSAL OF THE RESPONDENT FROM THE EVALUATION PROCESS. 10.36 CONFIDENTIAL INFORMATION 10.36.1 Any information obtained in the course of performing this contract may include information that is proprietary or confidential to the County. This provision establishes the Contractor’s obligation regarding such information. 10.36.2 The Contractor shall establish and maintain procedures and controls that are adequate to assure that no information contained in its records and/or obtained from the County or from others in carrying out its functions (services) under the contract shall be used by or disclosed by it, its agents, officers, or employees, except as required to efficiently perform duties under the contract. The Contractor’s procedures and controls, at a minimum, must be the same procedures and controls it uses to protect its own proprietary or confidential information. If, at any time during the duration of the contract, the County determines that the procedures and controls in place are not adequate, the Contractor shall institute any new and/or additional measures requested by the County within 15 business days of the written request to do so. 10.36.3 Any requests to the Contractor for County proprietary or confidential information shall be referred to the County for review and approval, prior to any dissemination. SERIAL 240094-RFP 10.37 PUBLIC RECORDS Under Arizona law, all offers submitted and opened are public records and must be retained by the County at the Maricopa County Office of Procurement Services. Offers shall be open to public inspection and copying after contract award and execution, except for such offers or sections thereof determined to contain proprietary or confidential information by the Office of Procurement Services. If an offeror believes that information in its offer or any resulting contract should not be released in response to a public record request, under Arizona law, the offeror shall indicate the specific information deemed confidential or proprietary and submit a statement with its offer detailing the reasons that the information should not be disclosed. Such reasons shall include the specific harm or prejudice which may arise from disclosure. The records manager of the Office of Procurement Services shall determine whether the identified information is confidential pursuant to the Maricopa County Procurement Code. 10.38 INTEGRATION This contract represents the entire and integrated agreement between the parties and supersedes all prior negotiations, proposals, communications, understandings, representations, or agreements, whether oral or written, expressed, or implied. 10.39 UNIFORM ADMINISTRATIVE REQUIREMENTS By entering into this contract, the Contractor agrees to comply with all applicable provisions of Title 2, Subtitle A, Chapter II, Part 200—UNIFORM ADMINISTRATIVE REQUIREMENTS, COST PRINCIPLES, AND AUDIT REQUIREMENTS FOR FEDERAL AWARDS contained in Title 2 C.F.R. § 200 et seq. 10.40 GOVERNING LAW This contract shall be governed by the laws of the State of Arizona. Venue for any actions or lawsuits involving this contract will be in Maricopa County Superior Court, Phoenix, Arizona. 10.41 FORCED LABOR 10.41.1 By submitting a bid for this solicitation and/or entering into a contract as a result of this solicitation, contractor agrees to comply with all applicable portions of Arizona Revised Statutes Section 35-394. Contracting; procurement; prohibition; written certification; remedy; termination; exception; definitions. 10.41.2 Contractor certifies that it does not currently, and agrees for the duration of the contract, that it will not use: 10.41.2.1 The forced labor of ethnic Uyghurs in the People’s Republic of China. 10.41.2.2 Any goods or services produced by the forced labor of ethnic Uyghurs in the People’s Republic of China. 10.41.2.3 Any contractors, subcontractors or suppliers that use the forced labor or any good or services produced by the forced labor of ethnic Uyghurs in the People’s Republic of China. 10.41.3 If contractor becomes aware during the term of the agreement that contractor is not in compliance with this paragraph, the contractor shall notify the County within five business days after becoming aware of the noncompliance. If the contractor fails to provide a written certification to the County that the contractor has remedied the noncompliance within 180 days after notifying the County of its noncompliance, then the agreement terminates, except that if the agreement termination date SERIAL 240094-RFP occurs before the end the 180-day period, the agreement terminates on the agreement termination date. 10.42 PRICES Contractor warrants that prices extended to County under this contract are no higher than those paid by any other customer for these or similar services. 10.43 ORDER OF PRECEDENCE In the event of a conflict in the provisions of this contract and Contractor’s license agreement, if applicable, the terms of this contract shall prevail. 10.44 UNIQUE ENTITY IDENTIFIER (UEI) AND SYSTEM FOR AWARD MANAGEMENT REGISTRATION All contractors that receive funding must have a UEI number through https://sam.gov/content/entity-registration. Contractor must also remain current with the System for Award Management www.sam.gov throughout the term of the contract. 10.45 RELIGIOUS ACTIVITIES The contractor agrees that costs, planned or claimed, including costs incurred, shall not include any expense for any religious activity. 10.46 POLITICAL ACTIVITY PROHIBITED None of the funds, materials, property, or services contributed by the County or the contractor under the agreement shall be used in the performance of this agreement for any partisan political activity, or to further the election or defeat of any candidate for public office. 10.47 EQUAL EMPLOYMENT OPPORTUNITY 10.47.1 The contractor shall not discriminate against any employee or applicant for employment because of race, age, disability, color, religion, sex, or national origin. The contractor shall take affirmative action to ensure applicants are employed and that employees are treated during employment without regard to their race, age, disability, color, religion, sex, or national origin. Such action shall include but is not limited to the following: employment, upgrading, demotion or transfer, recruitment, or recruitment advertising, lay-off or termination, rates of pay or other forms of compensation, and selection for training, including apprenticeship. 10.47.2 Contractor shall comply with the following provisions: 10.47.2.1 Title VI and VII of the Civil Rights Act of 1964, as amended (42 U.S.C. §§ 2000a, et seq.); 10.47.2.2 The Rehabilitation Act of 1973, as amended (29 U.S.C. §§ 701, et seq.); 10.47.2.3 The Age Discrimination in Employment Act of 1967, as amended (29U.S.C. §§ 621, et seq.); 10.47.2.4 The Americans With Disabilities Act of 1990 (42 U.S.C. §§ 12101, et seq.); and Arizona Executive Order 2009-09, as amended, et seq. which mandates that all persons shall have equal access to employment opportunities. SERIAL 240094-RFP 10.47.2.5 Contractor understands that the United States has the right to seek judicial enforcement of this assurance. 10.48 CERTIFICATION REGARDING LOBBYING 10.48.1 Contractor certifies, to the best of their knowledge and belief, that: 10.48.1.1 No federal appropriated funds have been paid or will be paid, by or on behalf of the contractor, to any person for influencing or attempting to influence an officer or employee of any agency. This applies to a Member of Congress, an officer or employee of Congress, or an employee of a Member of Congress in connection with the awarding of any federal contract, the making of any federal grant. Including the making of any federal, loan the entering into of any cooperative agreement, and the extension, continuation, renewal, amendment, or modification of any federal contract, grant, loan, or cooperative agreement. 10.48.2 If any funds other than federal appropriated funds, have been paid or will be paid to any person for influencing or attempting to influence an officer or employee of any agency, member of Congress, an officer or employee of Congress, or an employee of a member of Congress in connection with this federal contract, grant, loan, or cooperative agreement, the undersigned shall complete and submit Standard Form-LLL, “Disclosure Form to Report Lobbying,” in accordance with its instructions. 10.48.3 Contractor shall include Lobbying Certification language in the award documents for all subcontractors (including sub-grants, and contract under grants, loans, and cooperative agreements) and that all sub-recipients shall certify and disclose accordingly. 10.48.3.1 The Lobbying Certification is a material representation of fact upon which reliance was placed when this transaction is made or entered into. Submission of this certification is prerequisite for making or entering into this transaction imposed by section 1352, Title 31, U.S. Code. Any successful proposer(s) who fail to file the required certification shall be subject to a civil penalty of not less than $10,000.00 and not more than $100,000.00 for each such failure. 10.49 CLEAN AIR ACT & CLEAN WATER ACT Contractor must comply with all applicable standards, orders, or requirements issued under section 306 of the Clean Air Act (42 U.S.C. 1857(h), section 508 of the Clean Water Act (33 U.S.C. 1368) Executive Order 11738, and Environmental Protection Agency regulations (40 CFR part 15). 10.50 ENERGY POLICY AND CONSERVATION ACT Contractor must adhere to the standards and policies relating to energy efficiency, which are contained in the State energy conservation plan issued in compliance with the Energy Policy and Conservation Act (Pub. L. 94-163, 89 Stat.871). 10.51 INCORPORATION OF DOCUMENTS 10.51.1 The following are to be attached to and made part of this Contract: 10.51.1.1 Exhibit A – Vendor Information and Pricing 10.51.1.2 Exhibit B – Scope of Work SERIAL 240094-RFP 10.51.1.3 Exhibit C – Service Level Agreement 10.51.1.4 Exhibit D – Information Technology Supplemental Terms and Conditions 10.51.1.5 Exhibit E – Office of Procurement Services Contractor Travel and Per Diem Policy 10.52 NOTICES All notices given pursuant to the terms of this contract shall be addressed to: For County: Maricopa County Office of Procurement Services 301 W. Jefferson St. Suite 700 Phoenix, Arizona 85003-1647 For Contractor: Transource Services Corp dba Transource Computers 2405 W Utopia Rd Phoenix, AZ 85027 SERIAL 240094-RFP IN WITNESS WHEREOF, this contract is executed on the date set forth above. CONTRACTOR AUTHORIZED SIGNATURE PRINTED NAME AND TITLE ADDRESS DATE MARICOPA COUNTY CHAIRMAN, BOARD OF SUPERVISORS DATE ATTESTED: CLERK OF THE BOARD DATE APPROVED AS TO FORM: DEPUTY COUNTY ATTORNEY DATE Curtis Wescott / Government Sales and Contract Manager 2405 W. Utopia Rd Phoenix, AZ 85027 06/12/2024 SERIAL 240094-RFP EXHIBIT A: VENDOR INFORMATION AND PRICING COMPANY NAME: Transource Services Corp DOING BUSINESS AS (dba): Transource Computers MAILING ADDRESS: 2405 W Utopia Rd Phoenix, AZ 85027 REMIT TO ADDRESS: 2405 W Utopia Rd Phoenix, AZ 85027 TELEPHONE NUMBER: 623-215-4407 FAX NUMBER: 623-879-8887 WWW ADDRESS: www.transource.com REPRESENTATIVE NAME: Curtis Wescott REPRESENTATIVE TELEPHONE NUMBER: 623-215-4407 REPRESENTATIVE EMAIL ADDRESS curtisw@transource.com YES NO REBATE WILL ALLOW OTHER GOVERNMENTAL ENTITIES TO PURCHASE FROM THIS CONTRACT: ☒ ☐ WILL ACCEPT PROCUREMENT CARD FOR PAYMENT: ☒ ☐ Payment Terms: *Net 30 Days *After ‘Go-Live’ in Year 1 and on the anniversary date thereafter for Years 2 and 3. Pricing: Pricing: Title Year 1 Year 2 Year 3 Total Managed Security Services Provider (MSSP) $545,000.00 $545,000.00 $545,000.00 $1,635,000.00 Other Costs $0.00 $0.00 $0.00 Total Costs $545,000.00 $545,000.00 $545,000.00 $1,635,000.00 Optional Services: Title Year 1 Year 2 Year 3 Total Digital Forensics and Incident Response $450/hr $450/hr $450/hr N/A Incident Response Retainer Services $400/hr $400/hr $400/hr N/A *minimum 100 hours Advanced Threat Hunting $150K/yr $150K/yr $150K/yr $450,000.00 Tabletop Exercises as a Service (TTXaaS) $95K/yr $95K/yr $95K/yr $285,000.00 *$95,000/year, max of 4/year or $35K per exercise SERIAL 240094-RFP EXHIBIT B: SCOPE OF WORK 1.0 INTENT The Contractor shall provide to the County a Managed Security Services Provider (MSSP) for 24x7x365 security operations center (SOC) services for the applicable County enterprise network as outlined in this scope of work. The County intends to continue this level of service by taking advantage of existing security controls as well as new technology to identify threats to the County. The Contractor shall partner with Accelerynt as the provider of 24x7x365 monitoring services out of its Plano, Texas facility. 2.0 SCOPE OF WORK 2.1.1 This monitoring shall include escalation to Tier 2 and 3 the County security analysts and management as needed, as specified in documented playbooks. Accelerynt will escalate validated security incidents to responsible parties as outlined in the communications plan and the incident response process. Accelerynt supports multiple notification methods including email, PagerDuty, Slack, Teams, OpsGenie and many others. 2.1.2 MSSP shall provide, at discretion of County and individual departments, incident response services to address and mitigate security incidents when they occur. Accelerynt has a fully staffed incident response team, led by Michael McAndrews. 2.1.3 MSSP shall provide a dedicated account manager to the County for the length of the contract. Accelerynt confirms it will provide a dedicated project manager for the implementation phase and a dedicated account manager for the duration of the contract. 2.2 THREAT DETECTION 2.2.1 MSSP shall provide cyber threat detection services to identify potential security threats and vulnerabilities. Accelerynt utilizes a combination of passive analytics and active threat hunting. Passive analytics rules are processed against all inbound logs and provide alerting and incident generation capability. Accelerynt also conducts active threat hunts via the Sentinel hunting blade, passive external reconnaissance with commercially available tools such as Censys and Shodan and has multiple “vouched” accounts on various dark web marketplaces and telegram. Threat Hunts are highly focused on detecting adversaries living off the land and provides insight into realistic adversary techniques. External reconnaissance provides Maricopa County value by detecting services that are internet accessible and often a common avenue of attack for adversaries. By keeping MCC appraised of any new additional threat vectors, MCC can mitigate these before they become security concerns. Finally, Accelerynt has access into multiple Tor marketplaces and Telegram channels to evaluate if any potential data exfiltration is for sale and/or accessible to malicious users. 2.3 INTEGRATIONS 2.3.1 MSSP shall ingest/integrate with the County’s existing portfolio of tools including but not limited to: security information and event management (SIEM), security orchestration, automation and response (SOAR), endpoint security protection, mobile device security controls, data loss prevention (DLP) tools, vulnerability management suite, and others. Accelerynt utilizes Microsoft Sentinel which has hundreds of out-of-the-box connectors (https://learn.microsoft.com/en-us/azure/sentinel/data-connectors-reference) in addition to being able to capture the majority of data sources that utilize either syslog or have a restful API. Accelerynt has the largest Microsoft Sentinel automation repository (https://github.com/Accelerynt-Security) including numerous playbooks to respond to commodity threats such as user compromise, machine compromise, email compromise and network security compromise. SERIAL 240094-RFP 2.3.2 The County’s ideal state is to refrain from installing an additional proprietary agent on all endpoints that must be managed, rather, the MSSP should be able to ingest alert data from us to generate initial alerts. 2.3.2.1 Secured access to log data will be provided as needed to MSSP. 2.3.3 We shall accept proposals that do require installation of a proprietary agent. Accelerynt can utilize data ingestion from Splunk only or utilize Microsoft log collection infrastructure as necessary. Certain data sources such as Active Directory logs from Domain Controllers generally should utilize the Microsoft logging agent to ensure no delay in critical log ingestion. 2.3.4 MSSP data should be consumable via secure Application Programming Interface ( API). Accelerynt utilizes the Sentinel platform which has a robust API to query data (https://learn.microsoft.com/en-us/rest/api/securityinsights/operation-groups?view=rest-securityinsights- 2023-11-01) 2.4 REPORTING AND ANALYTICS 2.4.1 MSSP should integrate with our SIEM for purposes of visualizing/reporting findings. Accelerynt utilizes Sentinel for security monitoring which has native Splunk data integration (https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/how-to-export-data-from-splunk-to-azure- sentinel/ba-p/1891237) 2.4.2 Data generated by the MSSP providing services to the County should be made available via API or similar method, as stated above. Accelerynt utilizes the Sentinel platform which has a robust API to query data (https://learn.microsoft.com/en-us/rest/api/securityinsights/operation-groups?view=rest-securityinsights- 2023-11-01) 2.4.3 MSSP should have documented processes/run books in place for reporting credible incidents/threats to the County. Accelerynt has response procedures for commoditized threats in addition to having procedural guidance on extraordinary security alerts/incidents. Accelerynt also has the largest repository of approved playbooks for Azure Sentinel (https://github.com/Accelerynt-Security) for automated security response. 2.5 SECURITY ANALYTICS 2.5.1 MSSP should demonstrate use of data analytics and machine learning, etc. (as appropriate) to detect anomalies and patterns in network traffic, user behavior, and other activities to help detect potential security threats. Accelerynt utilizes Azure Sentinel which supports a built-in security machine learning model and also supports bring your own machine learning (https://learn.microsoft.com/en-us/azure/sentinel/bring-your- own-ml) models. Machine learning is primarily focused on detecting anomalies with User Behavior Entity Analytics, network based anomalies such as abnormally large data transfers or callbacks and cloud based anomalies such as large volume of API calls, resource generation and exfiltration. 2.6 OPTIONAL SERVICES 2.6.1 We encourage vendors who provide network operations center (NOC) and/or other IT operations monitoring services to include this information in their responses to the Request for Proposals (RFP) as optional, including cost, as well as how these services may integrate with the required MSSP offering. Accelerynt does not offer these optional services but confirms it will integrate with the County’s NOC solution or other ITOPS platforms. SERIAL 240094-RFP EXHIBIT C: SERVICE LEVEL AGREEMENT When malicious activity is detected, Accelerynt will perform an Investigation, provide an analysis, and notify the Client if Accelerynt cannot resolve the issue. Over time, our goal is to handle 100% of the verified events without escalating. This can be engineered to meet the Client’s requirements. Accelerynt will notify the Client electronically which may include using email or supported integrations. Other notifications can be incorporated as desired. Subsequent related activity identified as part of the ongoing Investigation of the incident or monitoring will be appended to an existing Investigation. Time from Investigation-created timestamp to County-notified timestamp as measured by Accelerynt is less than 60 minutes. SERIAL 240094-RFP EXHIBIT D: INFORMATION TECHNOLOGY SUPPLEMENTAL TERMS AND CONDITIONS 1. DEFINITIONS 1.1 “Authorized Persons” means the service provider’s employees, contractors, subcontractors or other agents who need to access the County’s personal data to enable the service provider to perform the services required. 1.2 “Data Breach” means the unauthorized access by a non-authorized person/s that results in the use, disclosure or theft of a County’s unencrypted personal data. 1.3 “Individually Identifiable Health Information” means information that is a subset of health information, including demographic information collected from an individual, and (1) is created or received by a health care provider, health plan, employer or health care clearinghouse; and (2) relates to the past, present or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present or future payment for the provision of health care to an individual; and (a) that identifies the individual; or (b) with respect to which there is a reasonable basis to believe the information can be used to identify the individual.12 1.4 “Non-Public Data” means data, other than personal data, that is not subject to distribution to the public as public information. It is deemed to be sensitive and confidential by the County because it contains information that is exempt by statute, ordinance or administrative rule from access by the general public as public information. 1.5 “Personal Data” means data that includes information relating to a person that identifies the person by name and has any of the following personally identifiable information (PII): government-issued identification numbers (e.g., Social Security, driver’s license, passport); financial account information, including account number, credit or debit card numbers; or protected health information (PHI) relating to a person. 1.6 “Protected Health Information” (PHI) means individually identifiable health information transmitted by electronic media, maintained in electronic media, or transmitted or maintained in any other form or medium. PHI excludes education records covered by the Family Educational Rights and Privacy Act (FERPA), as amended, 20 U.S.C. 1232g, records described at 20 U.S.C. 1232g(a)(4)(B)(iv) and employment records held by a covered entity in its role as employer.13 1.7 “Public Jurisdiction” means any government or government agency that uses these terms and conditions. The term is a placeholder for the government or government agency. 1.8 “County Data” means all data created or in any way originating with the County, and all data that is the output of computer processing of or other electronic manipulation of any data that was created by or in any way originated with the County, whether such data or output is stored on the County’s hardware, the service provider’s hardware or exists in any system owned, maintained or otherwise controlled by the County or by the service provider. 1.9 “County Identified I.T. Security Contact” means the person or persons designated in writing by the County to receive security incident or breach notification. 1.10 “Security Incident” means the potentially unauthorized access by non-authorized persons to personal data or non-public data the service provider believes could reasonably result in the use, disclosure or theft of a County’s unencrypted personal data or non-public data within the possession or control of the service provider. A security incident may or may not turn into a data breach. SERIAL 240094-RFP 1.11 “Service Level Agreement” (SLA) means that part of the written agreement between both the County and the service provider that is subject to the terms and conditions in this document and that unless otherwise agreed to includes (1) the technical service level performance promises, (i.e. metrics for performance and intervals for measure), (2) the amount of time required for notice by the provider to the County for notification of upcoming changes, (3) security notice requirements, (4) timeframes for response to operational problems and failures, and (5) any remedies for performance failures. 1.12 “Service Provider” means the contractor and its employees, subcontractors, agents and affiliates who are providing the services agreed to under the contract. 1.13 “Software-as-a-Service” (SaaS) means the capability provided to the consumer to use the provider’s applications running on a cloud infrastructure. The applications are accessible from various client devices through a thin-client interface such as a Web browser (e.g., Web-based email) or a program interface. The consumer does not manage or control the underlying cloud infrastructure including network, servers, operating systems, storage or even individual application capabilities, with the possible exception of limited user specific application configuration settings. 1.14 “Statement of Work/Scope of Work” means a written statement in a solicitation document or contract that describes the County’s service needs and expectations. 2. SUPPORT OVERVIEW 2.1 Support hours (accommodate our time zone) - vendor will maintain customer service hours that coincide with our 8AM- 5PM M-Fri (MST) office schedule. They will also provide afterhours support at a level commensurate with the nature of the service provided. 2.2 Updates/upgrades - vendor will follow a timely and consistent schedule in applying updates to their solution and the underlying infrastructure needed to support it. Zero day/emergency updates will be done expeditiously by vendor, with proper communication to customers affected 2.3 Entity will comply with all applicable provisions of the Americans with Disabilities Act, the Rehabilitation Act of 1973, and all applicable federal regulations, as amended from time to time (ADA Laws). All electronic and information technology and products and services to be used must be compliant with the ADA Laws. 2.3.1 Compliance means that a disabled person can acquire the same information, engage in the same interactions, and enjoy the same services as a nondisabled person, in an equally effective and integrated manner, with substantially equivalent ease of use. 3. DATA OVERVIEW: 3.1 Data liberation - vendor is required to provide the means to pull all user data from vendor solution any time as desired, in a machine-readable format. 3.2 System shall be capable of encrypting data both at rest and in transit as needed/determined by the customer. 3.3 Data Ownership: The County will own all right, title and interest in its data that is related to the services provided by this contract. The service provider shall not access County user accounts or County data, except (1) in the course of data center operations, (2) in response to service or technical issues, (3) as required by the express terms of this contract or (4) at the County’s written request. SERIAL 240094-RFP 3.4 Data Protection: Protection of personal privacy and data shall be an integral part of the business activities of the service provider to ensure there is no inappropriate or unauthorized use of County information at any time. To this end, the service provider shall safeguard the confidentiality, integrity and availability of County information and comply with the following conditions: 3.4.1 The service provider shall implement and maintain appropriate administrative, technical and organizational security measures to safeguard against unauthorized access, disclosure or theft of personal data and non-public data. Such security measures shall be in accordance with recognized industry practice and not less stringent than the measures the service provider applies to its own personal data and non-public data of similar kind. 3.4.2 All data obtained by the service provider in the performance of this contract shall become and remain the property of the County. Vendor usage of customer data for non-County purposes requires written approval from the County. 3.4.3 All personal data shall be encrypted at rest and in transit with controlled access. The County shall identify data it deems as non-public data to the service provider. The level of protection and encryption for all non-public data shall be identified and made a part of this contract. Any stipulation of responsibilities will identify specific roles and responsibilities and shall be included in the statement of work (SOW), or otherwise made a part of this contract. 3.5 At no time shall any data or processes — that either belong to or are intended for the use of a County or its officers, agents or employees — be copied, disclosed or retained by the service provider or any party related to the service provider for subsequent use in any transaction that does not include the County. 3.6 Hosted applications must have the ability to support encrypted protocols for sensitive data in flight and in rest. Encryption ciphers must use at least a 128-bit key length. Hashing algorithms used must be of the Secure Hash Algorithm (SHA) or Advanced Encryption Standard (AES) family. The minimum acceptable algorithm shall be SHA-2 or AES128. 3.7 Data Location: The service provider shall provide its services to the County and its end users solely from data centers in the U.S. Storage of County data at rest shall be located solely in data centers in the U.S. The service provider shall not allow its personnel or contractors to store County data on portable devices, including personal computers, except for devices that are used and kept only at its U.S. data centers. The service provider shall permit its personnel and contractors to access County data remotely only as required to provide technical support. The service provider may provide technical user support on a 24/7 basis using a Follow the Sun model, unless otherwise prohibited in the SLA. 3.8 The vendor shall destroy all offline copies of County data at the time they cease to be useful. Destruction procedures must be made available to the County upon request. 3.9 At the conclusion of the contract, all County data and working papers must be returned to the County and all vendor copies destroyed. The vendor must confirm in writing to the County that all data was destroyed in accordance with this agreement and state the methodology used. 4. BACKUP AND DISASTER RECOVERY OVERVIEW 4.1 County has the right to, with 72 hours’ notice, request a test of customer-centric backup and Disaster Recovery functionality, as defined in the contract. 4.2 Backups to removable media must be encrypted using the Advanced Encryption Standard (AES) with a minimum of a 128-bit key. Industry recognized key handling procedures must be utilized. At no time shall the key be stored on the backup media in clear text, including SERIAL 240094-RFP but not limited to table labels. The vendor must make key handling procedures and logs available upon request. 5. Unless otherwise stated, hosting providers will complete incremental backups daily and be able to successfully generate full backups within 24 hours unless otherwise agreed upon. 6. INTEGRATION AND INTERFACES OVERVIEW 6.1 All customer integrations and interfaces are fully documented and updated when changes are made by vendor at no cost to the County. 7. TESTING OVERVIEW: 7.1 A documented strategy for testing and QA of development and configuration shall be provided to the Maricopa County project team for approval prior to commencement of system build upon request. 7.2 Issues identified in vendor testing shall be cataloged, updated upon closure with final disposition, and provided to the project team prior to UAT testing. 7.3 Vendor will allow Maricopa County a reasonable timeframe to execute the test plan and retest items with issues. 7.4 Vendor will work directly with Maricopa County, and external vendors to integration test all interfaces and transmissions of data. To eliminate constraints and delays in external vendor testing and validation, a separate mirror environment for testing is advised. 7.5 Vendor will enable automation and file transmission during UAT and parallel testing. 7.6 Vendor will allow Maricopa County to execute performance and load testing as prior to the start of UAT. 7.7 The Vendor shall provide County with a UAT test catalog to aid in development of test scripts. 7.8 Testing variances will be documented, categorized, and assigned priority through a mutually agreed upon format. 7.9 Unit testing of the application shall be performed and documented by the vendor. 7.10 Vendor will provide documented results of testing including negative and positive testing results. 8. CONNECTIVITY OVERVIEW: 8.1 Vendor will proactively communicate any proposed networking change made against connections between vendor and County a minimum of 5 business days prior to the change. 8.2 Client applications installed on user workstations that must contact the off-site hosting environment must be able to do so through a secured HTTP proxy. Workstations must not be required to directly connect over the Internet for any reason. 8.3 Any connection between the County and vendor needs to be secured using industry accepted standards. SERIAL 240094-RFP 9. SYSTEM SECURITY OVERVIEW: 9.1 Security Incident or Breach Notification and Responsibilities: The service provider shall inform the County of any security incident or data breach. 9.2 Breach notification requirements shall be determined by all applicable laws and contracts including, but not limited to, Arizona Revised Statutes 44-7501 and 18-552, California SB 1386, the Health Insurance Portability and Accountability Act (HIPAA), Criminal Justice Information Services (CJIS) and Payment Card Industry (PCI). 9.3 Incident Response: The service provider may need to communicate with outside parties regarding a security incident, which may include contacting law enforcement, fielding media inquiries and seeking external expertise as mutually agreed upon, defined by law or contained in the contract. Discussing security incidents with the County should be handled on an urgent as-needed basis, as part of service provider communication and mitigation processes as mutually agreed upon, defined by law or contained in the contract. 9.4 Unless otherwise stipulated, if a data breach is a direct result of the service provider’s breach of its contract obligation to encrypt personal data or otherwise prevent its release, the service provider shall bear the costs associated with the following: 9.4.1 the investigation and resolution of the data breach; 9.4.2 notifications to individuals, regulators or others required by state law; 9.4.3 a credit monitoring service required by state (or federal) law; 9.4.4 a website or a toll-free number and call center for affected individuals required by state law — all not to exceed the average per record per person cost calculated for data breaches in the United States in the most recent Cost of Data Breach Study: Global Analysis published by the Ponemon Institute at the time of the data breach; and 9.4.5 complete all corrective actions as reasonably determined by service provider based on root cause; all [(1) through (5)] subject to this contract’s limitation of liability. 9.5 Breach Reporting Requirements: If the service provider has actual knowledge of a confirmed data breach that affects the security of any County content that is subject to applicable data breach notification law, the service provider shall 9.5.1 promptly notify the appropriate County identified contact within 24 hours or sooner, unless shorter time is required by applicable law, and 9.5.2 take commercially reasonable measures to address the data breach in a timely manner. 9.6 The vendor shall make the information security incident response policy and procedure available to the County at any time upon request. 9.7 Access to Security Logs and Reports: The service provider shall provide reports to the County in a format as specified in the SLA agreed to by both the service provider and the County. Reports shall include latency statistics, user access, user access IP address, user access history and security logs for all County files related to this contract. County may, at their discretion, use separate SIEM tool to analyze and manage provided log and report data. SERIAL 240094-RFP 10. AUDITING AND COMPLIANCE OVERVIEW 10.1 The system must log all material user actions, including but not limited to, logon and log off. 10.2 The system must log all material administrator actions, including but not limited to, user creation, user deleting, password resets, and privilege level changes. 10.3 The system must log failed login attempts. 10.4 Logs must be made available to the County at any time, preferably though API, web service or some other automated fashion 10.5 The vendor must comply with all applicable laws, regulations, and contracts including (but not limited to) Criminal Justice Information Services (CJIS), Health Insurance Portability and Accountability Act, and Payment Card Industry (PCI). 10.6 Vendors that host applications containing HIPAA protected data must enter into a Business Associate agreement (as defined by HIPPA) with the County. The Business Associate agreement must be maintained for the life of the contract. 10.7 Audit of 3rd Party systems - in order to determine that SLAs or other agreements between Maricopa County and the 3rd party entity are being adhered to, we reserve the right to audit systems being used to provide the service and supporting services (such as internal work order/ITSM systems, log files, etc.) used to support the services being provide to the county. 10.8 The vendor must make SOC2 compliance reports, or other comparable security report, audit findings, and third-party attestations available at the time of award, and at any time to the County upon request. Updated compliance reports shall be provided to the County Identified I.T. Security Contact annually. 10.9 For SOC 2 reports, this must be of the solution and not of the hosting service the vendor may be using (i.e., do not share Amazon’s or Microsoft’s SOC2 report instead of one specific to the solution in question). 10.10 The vendor must immediately notify the County, in writing, upon a confirmed violation of the compliance requirement. The notification must include any information provided by the regulatory body. SERIAL 240094-RFP EXHIBIT E: OFFICE OF PROCUREMENT SERVICES CONTRACTOR TRAVEL AND PER DIEM POLICY 1.0 All contract-related travel plans and arrangements shall be prior-approved by the County contract administrator. 2.0 Lodging, per diem, and incidental expenses incurred in performance of Maricopa County/Special District (County) contracts shall be reimbursed based on current U.S. General Services Administration (GSA) domestic per diem rates for Phoenix, Arizona. Contractors must access the following internet site to determine rates (no exceptions): www.gsa.gov. 2.1 Additional incidental expenses (i.e., telephone, fax, internet, and copying charges) shall not be reimbursed. They should be included in the contractor’s hourly rate as an overhead charge. 2.2 The County will not (under any circumstances) reimburse for contractor guest lodging, per diem, or incidentals. 3.0 Commercial air travel shall be reimbursed as follows: 3.1 Coach airfare will be reimbursed by the County. Business class airfare may be allowed only when preapproved in writing by the County contract administrator as a result of the business needs of the County when there is no lower fare available. 3.2 The lowest direct flight airfare rate from the contractor’s assigned duty post (pre-defined at the time of contract signing) will be reimbursed. Under no circumstances will the County reimburse for airfares related to transportation to or from an alternate site. 3.3 The County will not (under any circumstances) reimburse for contractor guest commercial air travel. 4.0 Rental vehicles may only be used if such use would result in an overall reduction in the total cost of the trip, not for the personal convenience of the traveler. Multiple vehicles for the same set of travelers for the same travel period will not be permitted without prior written approval by the County contract administrator. 4.1 Purchase of comprehensive and collision liability insurance shall be at the expense of the contractor. The County will not reimburse a contractor if the contractor chooses to purchase this coverage. 4.2 Rental vehicles are restricted to sub-compact, compact, or mid-size sedans unless a larger vehicle is necessary for cost efficiency due to the number of travelers. (NOTE: Contractors shall obtain pre-approval in writing from the County contract administrator prior to rental of a larger vehicle.) 4.3 County will reimburse for parking expenses if free, public parking is not available within a reasonable distance of the place of County business. All opportunities must be exhausted prior to securing parking that incurs costs for the County. Opportunities to be reviewed are the DASH, shuttles, etc. that can transport the contractor to and from County buildings with minimal costs. 4.4 County will reimburse for the lowest rate, long-term, uncovered (covered or enclosed parking will not be reimbursed) airport parking only if it is less expensive than shuttle service to and from the airport. 4.5 The County will not (under any circumstances) reimburse the contractor for guest vehicle rental(s) or other any transportation costs. SERIAL 240094-RFP 5.0 Contractor is responsible for all costs not directly related to the travel except those that have been pre-approved by the County contract administrator. These costs include, but are not limited to, the following: in-room movies, valet service, valet parking, laundry service, costs associated with storing luggage at a hotel, fuel costs associated with non-County activities, tips that exceed the per diem allowance, health club fees, and entertainment costs. Claims for unauthorized travel expenses will not be honored and are not reimbursable. 6.0 Travel and per diem expenses shall be capped at 15 percent of project price unless otherwise specified and approved by the County in individual contracts. 7.0 Contractor shall provide, (upon request) with their invoice(s), copies of receipts supporting travel and per diem expenses, and, if applicable, with a copy of the written consent issued by the County contract administrator. No travel and per diem expenses shall be paid by County without copies of the written consent as described in this policy and copies of all receipts.