Extracted text (via pymupdf)
167141 characters
ERIAL 230142-RFP REAL ESTATE PROPERTY AND RIGHT-OF-WAY MANAGEMENT SYSTEM DATE OF LAST REVISION: June 12, 2024 CONTRACT END DATE: June 30, 2029 CONTRACT PERIOD THROUGH JUNE 30, 2029 TO: All Departments FROM: Office of Procurement Services SUBJECT: Contract for REAL ESTATE PROPERTY AND RIGHT-OF-WAY MANAGEMENT SYSTEM Attached to this letter is published an effective purchasing contract for products and/or services to be supplied to Maricopa County activities as awarded by Maricopa County on June 12, 2024 (Eff. 06/01/24). All purchases of products and/or services listed on the attached pages of this letter are to be obtained from the vendor holding the contract. Individuals are responsible to the vendor for purchases made outside of contracts. The contract period is indicated above. RN/mm Attach Copy to: Office of Procurement Services Shallana Edwards, Real Estate Department CONTRACT REAL ESTATE PROPERTY AND RIGHT-OF-WAY MANAGEMENT SYSTEM 230142-RFP This contract is entered into this 12th day of June 2024 by and between Maricopa County (County), a political subdivision of the State of Arizona, and ENKON Information Systems (USU), Inc, a Washington State business corporation (Contractor) for the purchase of Real Estate Property and Right- of-Way Management System. 1.0 CONTRACT TERM 1.1 This contract is for a term of five years, beginning on the 1st day of July 2024 and ending the 30th day of June 2029. 2.0 OPTION TO RENEW The County may, at its option and with the concurrence of the Contractor, renew the term of this contract up to a maximum of 2-5 Yr. terms, (or at the County’s sole discretion, extend the contract on a month-to-month basis for a maximum of six months after expiration). The Contractor shall be notified in writing by the Office of Procurement Services of the County’s intention to renew the contract term at least 60 calendar days prior to the expiration of the original contract term. 3.0 CONTRACT COMPLETION In preparation for contract completion, the Contractor shall make all reasonable efforts for an orderly transition of its duties and responsibilities to another provider and/or to the County. This may include, but is not limited to, preparation of a transition plan and cooperation with the County or other providers in the transition. The transition includes the transfer of all records and other data in the possession, custody, or control of the Contractor that are required to be provided to the County either by the terms of this agreement or as a matter of law. The provisions of this clause shall survive the expiration or termination of this agreement. 4.0 PRICE ADJUSTMENTS Any requests for reasonable price adjustments must be submitted 60 calendar days prior to contract expiration. Requests for adjustment in cost of labor and/or materials must be supported by appropriate documentation. The reasonableness of the request will be determined by comparing the request with the Consumer Price Index or by performing a market survey. If County agrees to the adjusted price terms, County shall issue written approval of the change and provide an updated version of the contract. The new change shall not be in effect until the date stipulated on the updated version of the contract. 5.0 PAYMENTS 5.1 As consideration for performance of the duties described herein, County shall pay Contractor the sum(s) stated in Exhibit D – Pricing Sheet. 5.2 Payment shall be made upon the County’s receipt of a properly completed invoice. SERIAL 230142-RFP 5.3 INVOICES 5.3.1 Upon mutually agreed upon milestones/deliverables outlined in the implementation plan, the respondent shall submit two legible copies of their detailed invoice before payment(s) can be made. At a minimum, the invoice must provide the following information: • Company name, address, and contact information • County bill-to name and contact information • Contract serial number • County purchase order number • Project name and/or number • Invoice number and date • Payment terms • Date of milestone/deliverable • Quantity • Contract item number(s) • Arrival and completion time • Description of purchase (product or services) • Pricing per unit of purchase • Extended price • Total amount due 5.3.2 Labor, services, and maintenance must be billed as a separate line item. 5.3.3 Problems regarding billing or invoicing shall be directed to the department as listed on the purchase order. 5.3.4 Payment shall only be made to the Contractor by Accounts Payable through the Maricopa County Vendor Express Payment Program. This is an electronic funds transfer (EFT) process. After contract award, the Contractor shall complete the Vendor Registration Form accessible from the County Department of Finance Vendor Registration Web Site https://www.maricopa.gov/5169/Vendor- Information. 5.3.5 Discounts offered in the contract shall be calculated based on the date a properly completed invoice is received by the County. 5.3.6 EFT payments to the routing and account numbers designated by the Contractor shall include the details on the specific invoices that the payment covers. The Contractor is required to discuss remittance delivery capabilities with their designated financial institution for access to those details. 5.4 APPLICABLE TAXES 5.4.1 It is the responsibility of the Contractor to determine any and all applicable taxes and include those taxes in their proposal. The legal liability to remit the tax is on the entity conducting business in Arizona. Tax is not a determining factor in contract award. 5.4.2 The County will look at the price or offer submitted and will not deduct, add, or alter pricing based on speculation or application of any taxes, nor will the County provide Contractor any advice or guidance regarding taxes. If you have questions regarding your tax liability, seek advice from a tax professional prior to submitting your bid. You may also find information at https://www.azdor.gov/Business.aspx. Once your bid is submitted, the offer is valid for the time specified in this solicitation, regardless of mistake or omission of tax liability. If the County finds overpayment of a project due to tax consideration that was not due, the Contractor will be liable to the County for that amount, and by contracting with the County agrees to remit SERIAL 230142-RFP any overpayments back to the County for miscalculations on taxes included in a bid price. 5.4.3 Tax Indemnification: Contractor and all subcontractors shall pay all Federal, State, and local taxes applicable to their operation and any persons employed by the Contractor. Contractor shall, and require all subcontractors to, hold Maricopa County harmless from any responsibility for taxes, damages, and interest, if applicable, contributions required under Federal and/or State and local laws and regulations, and any other costs including: transaction privilege taxes, unemployment compensation insurance, Social Security, and workers’ compensation. Contractor may be required to establish, to the satisfaction of County, that any and all fees and taxes due to the City or the State of Arizona for any license or transaction privilege taxes, use taxes, or similar excise taxes are currently paid (except for matters under legal protest). 6.0 AVAILABILITY OF FUNDS 6.1 The provisions of this contract relating to payment for services shall become effective when funds assigned for the purpose of compensating the Contractor as herein provided are actually available to County for disbursement. The County shall be the sole judge and authority in determining the availability of funds under this contract. County shall keep the Contractor fully informed as to the availability of funds. 6.2 If any action is taken by, any State agency, Federal department, or any other agency or instrumentality to suspend, decrease, or terminate its fiscal obligations under, or in connection with, this contract, County may amend, suspend, decrease, or terminate its obligations under, or in connection with, this contract. In the event of termination, County shall be liable for payment only for services rendered prior to the effective date of the termination, provided that such services are performed in accordance with the provisions of this contract. County shall give written notice of the effective date of any suspension, amendment, or termination under this section, at least 10 days in advance. 7.0 DUTIES 7.1 The Contractor shall perform all duties stated in Exhibit B – Scope of Work, or as otherwise directed in writing by the procurement officer. 7.2 During the contract term, County may provide Contractor’s personnel with adequate workspace for consultants and such other related facilities as may be required by Contractor to carry out its contractual obligations. 8.0 TERMS AND CONDITIONS 8.1 INDEMNIFICATION 8.1.1 To the fullest extent permitted by law, and to the extent that claims, damages, losses, or expenses are not covered and paid by insurance purchased by the contractor, the contractor shall defend, indemnify, and hold harmless the County (as Owner), its agents, representatives, officers, directors, officials, and employees from and against all claims, damages, losses, and expenses (including, but not limited to attorneys' fees, court costs, expert witness fees, and the costs and attorneys' fees for appellate proceedings) arising out of, or alleged to have resulted from, the negligent acts, errors, omissions, or mistakes relating to the performance of this contract. 8.1.2 Contractor's duty to defend, indemnify, and hold harmless the County, its agents, representatives, officers, directors, officials, and employees shall arise in connection with any claim, damage, loss, or expense that is attributable to bodily injury, sickness, disease, death, or injury to, impairment of, or destruction of SERIAL 230142-RFP tangible property, including loss of use resulting therefrom, caused by negligent acts, errors, omissions, or mistakes in the performance of this contract, but only to the extent caused by the negligent acts or omissions of the contractor, a subcontractor, anyone directly or indirectly employed by them, or anyone for whose acts they may be liable, regardless of whether or not such claim, damage, loss, or expense is caused in part by a party indemnified hereunder. 8.1.3 The amount and type of insurance coverage requirements set forth herein will in no way be construed as limiting the scope of the indemnity in this section. 8.1.4 The scope of this indemnification does not extend to the sole negligence of County. 8.2 INFRINGEMENT DEFENSE AND INDEMNIFICATION 8.2.1 Definitions For purposes of this section: 8.2.1.1 “Claim” means any cause of action in a third-party action, suit, or proceeding against County alleging that Contractor software, or its upgrades, modifications, or revisions, as of its delivery date under this agreement, infringes a valid U.S. patent, copyright, or trademark. 8.2.1.2 “Participate and Share in the Costs” means Contractor will assist the County in the defense of the Claim, to the extent agreed to by the parties, except that Contractor shall be solely responsible for any and all costs adjudged in a successful Claim against the County. 8.2.1.3 “Third-Party Products” means any products made by a party other than Contractor, and may include, without limitation, products ordered by County from third parties. However, components of Contractor branded products are not Third-Party Products if they are both: 8.2.1.3.1 embedded in Third-Party Products (i.e., not recognizable as standalone items); and 8.2.1.3.2 not identified as separate items on Contractor’s price list, quotes, order specifications forms, or documentation. 8.2.2 Defense and Indemnity Contractor shall defend, and Participate and Share in the Cost, in the full defense of the County against any Claim, and will indemnify and hold harmless the County, as provided for in this section, for any judgments, settlements, and court awarded attorney’s fees resulting from a Claim where the claimant is adjudged the successful party in the Claim. Contractor’s obligations under this section are conditioned on the following: 8.2.2.1 County promptly notifies Contractor of the Claim, in writing, upon being made aware of the Claim; 8.2.2.2 County gives Contractor lead authority control of the defense and (if applicable) settlement of the Claim, provided that County’s legal counsel may participate in such defense and settlement, at County’s expense; and 8.2.2.3 County provides all information and assistance reasonably requested by Contractor to handle the defense or settlement of the Claim. SERIAL 230142-RFP 8.2.3 Remedial Measures If software becomes, or Contractor reasonably believes use of software may become, the subject of a Claim, Contractor may, at its own expense and option: 8.2.3.1 procure for County the right to continue use of the product; 8.2.3.2 replace or modify the software; or 8.2.3.3 to the extent that neither 8.2.3.1 nor 8.2.3.2 are deemed commercially practicable, refund to County a pro-rated portion of the applicable fees for software based on a linear depreciation monthly over a 10-year useful life, in which case County will cease all use of software and return it to Contractor. 8.2.4 Exceptions Contractor will have no defense or indemnity obligation for any Claim based on: 8.2.4.1 modifications by someone other than Contractor; 8.2.4.2 software has been modified by Contractor in accordance with County- provided specifications or instructions; 8.2.4.3 use or combination by the County of software with Third-Party Products, open source, or freeware technology; 8.2.4.4 Third-Party Products, open source, or freeware technology; 8.2.4.5 a product that is used or located by County in a country other than the country in which or for which it was supplied by Contractor; 8.2.4.6 possession or use of a product after Contractor has informed County of modifications or changes required to avoid such Claim and offered to implement those modifications or changes, if such Claim would have been avoided by implementation of Contractor's suggestions and to the extent County did not provide Contractor with a reasonable opportunity to implement Contractor's suggestions; or 8.2.4.7 the amount of revenue or profits earned, or other value obtained by the use of products, or the amount of use of the products. 8.2.5 The foregoing states Contractor’s entire liability, and County’s sole and exclusive remedy, except as provided by law or equity, with respect to any infringement or misappropriation of any intellectual property rights of another party. 8.3 SOURCE CODE ESCROW REQUIREMENT 8.3.1 Contractor shall provide all proprietary technology and materials covered under this agreement that Maricopa County has purchased from Contractor for safekeeping with a mutually acceptable software escrow service provider (escrow agent) within 30 days of award, to include, but is not limited to, all source code, any updates or fixes, and related materials and documents for commercial off-the- shelf software (COTS), etc. (“deposit material”). The deposit material deposited with the escrow agent shall be a snapshot of all source code and related material maintained by Contractor. In this way, as beneficiary of the escrow agreement between Contractor and escrow agent, Maricopa County will have access to all source code of the products that they license for all versions of the software. Furthermore, the escrowed code shall include all code specifically developed for Maricopa County including, but not limited to, interfaces, Extraction- SERIAL 230142-RFP Transformation-Loading (ETL) routines for data conversion, and all custom code. Upon taking possession of the source code, Maricopa County will have the right to use the source for products that they license in the versions currently installed on the system or any subsequent versions archived with the escrow agent. Contractor will make a deposit of the deposit material with the escrow agent upon any version release or once every six months, whichever occurs first. 8.3.2 Maricopa County hereby agrees to pay the yearly standard fee for a beneficiary of the source code. 8.3.3 Maricopa County shall have access to the source code in the event of any of the following circumstances: 8.3.3.1 the sale, assignment, or transfer to any third party of any of Contractor’s rights in the licensed product (or any portion thereof) if such sale, assignment, or transfer would prevent Contractor from fully performing any of its obligations under any agreement with Maricopa County; 8.3.3.2 Contractor becomes insolvent or commits any affirmative act of insolvency, or generally fails to pay, or admits in writing its inability to pay, debts as they become due, makes a general assignment for the benefit of creditors, files a voluntary petition of bankruptcy, suffers or permits the appointment of a receiver for its business or assets, becomes subject to any proceeding under, or case in, any bankruptcy or insolvency law, or Contractor takes any action to authorize, or in the furtherance of, any of the following: 8.3.3.2.1 Contractor discontinues providing full support and maintenance services for the licensed product in accordance with its obligations pursuant to any agreement with Maricopa County; 8.3.3.2.2 Contractor has ceased to do business or improperly refuses to provide any services pursuant to any agreement with Maricopa County; 8.3.3.2.3 Contractor has breached (and if subject to a cure period, has not cured such breach within such period) any material term or condition of any agreement with Maricopa County; 8.3.3.2.4 any change of control of Contractor or Contractor’s parent company, where such party is acquired, directly or indirectly, in a single transaction or series of related transactions, or all or substantially all of the assets of such party are acquired by any entity, or such party is merged with or into another entity to form a new entity; or 8.3.3.2.5 any other circumstance in which Maricopa County is entitled to access or use the applicable deposit materials (including, but not limited to, the source code) under the express terms of any agreement between Contractor and Maricopa County. 8.3.4 Upon Maricopa County taking possession of the source code, Maricopa County hereby agrees as follows: 8.3.4.1 Maricopa County accepts full and total responsibility for the safekeeping of the source code. Maricopa County agrees that such source code shall be subject to the restrictions of transfer, sale, and reproduction placed SERIAL 230142-RFP on the software itself as stated in the software license signed by all parties. 8.3.4.2 Maricopa County agrees to only use source code related to applications for which they own a license. 8.3.4.3 Maricopa County agrees, if so ordered by a court of competent jurisdiction, to compensate Contractor for any and all damages Contractor suffers, to include reasonable attorney’s fees, resulting directly or indirectly from, but not limited to, the mishandling, misuse, or theft of the source code, regardless of intent, or the absence thereof, by Maricopa County, its employees, agents, and third-party Contractors. 8.3.4.4 No license under any trademark, patent, copyright, or any other intellectual property right, is either granted or implied by the disclosure of the source code to Maricopa County. The Contractor’s disclosure of the source code to Maricopa County shall not constitute any representation, warranty, assurance, guarantee, or inducement by the Contractor to Maricopa County of any kind, and, in particular, with respect to the non-infringement of trademarks, patents, copyrights, or any other intellectual property rights, or other rights of third persons or of Contractor. 8.3.5 Contractor will not be responsible for maintaining the source code. Furthermore, Contractor will not be liable for any consequences related to the use of source code modified by Maricopa County. 8.4 INSURANCE 8.4.1 Contractor, at Contractor’s own expense, shall purchase and maintain, at a minimum, the herein stipulated insurance from a company or companies duly licensed by the State of Arizona and possessing an AM Best, Inc. category rating of B++. In lieu of State of Arizona licensing, the stipulated insurance may be purchased from a company or companies, which are authorized to do business in the State of Arizona, provided that said insurance companies meet the approval of County. The form of any insurance policies and forms must be acceptable to County. 8.4.2 All insurance required herein shall be maintained in full force and effect until all work or service required to be performed under the terms of the contract is satisfactorily completed and formally accepted. Failure to do so may, at the sole discretion of County, constitute a material breach of this contract. 8.4.3 In the event that the insurance required is written on a claims-made basis, Contractor warrants that any retroactive date under the policy shall precede the effective date of this contract and either continuous coverage will be maintained, or an extended discovery period will be exercised for a period of two years beginning at the time work under this contract is completed. 8.4.4 Contractor’s insurance shall be primary insurance as respects County, and any insurance or self-insurance maintained by County shall not contribute to it. 8.4.5 Any failure to comply with the claim reporting provisions of the insurance policies or any breach of an insurance policy warranty shall not affect the County’s right to coverage afforded under the insurance policies. SERIAL 230142-RFP 8.4.6 The insurance policies may provide coverage that contains deductibles or self- insured retentions. Such deductible and/or self-insured retentions shall not be applicable with respect to the coverage provided to County under such policies. Contractor shall be solely responsible for the deductible and/or self-insured retention and County, at its option, may require Contractor to secure payment of such deductibles or self-insured retentions by a surety bond or an irrevocable and unconditional letter of credit. 8.4.7 The insurance policies required by this contract, except Workers’ Compensation and Errors and Omissions, shall name County, its agents, representatives, officers, directors, officials, and employees as additional insureds. 8.4.8 The policies required hereunder, except Workers’ Compensation and Errors and Omissions, shall contain a waiver of transfer of rights of recovery (subrogation) against County, its agents, representatives, officers, directors, officials, and employees for any claims arising out of Contractor’s work or service. 8.4.9 If available, the insurance policies required by this contract may be combined with Commercial Umbrella Insurance policies to meet the minimum limit requirements. If a Commercial Umbrella insurance policy is utilized to meet insurance requirements, the Certificate of Insurance shall indicate which lines the Commercial Umbrella Insurance covers. 8.4.9.1 Commercial General Liability Commercial General Liability (CGL) insurance and, if necessary, Commercial Umbrella insurance with a limit of not less than $2,000,000 for each occurrence, $4,000,000 Products/Completed Operations Aggregate, and $4,000,000 General Aggregate Limit. The policy shall include coverage for premises liability, bodily injury, broad form property damage, personal injury, products and completed operations and blanket contractual coverage, and shall not contain any provisions which would serve to limit third party action over claims. There shall be no endorsement or modifications of the CGL limiting the scope of coverage for liability arising from explosion, collapse, or underground property damage. 8.4.9.2 Automobile Liability Commercial/Business Automobile Liability insurance with a combined single limit for bodily injury and property damage of not less than $2,000,000 each occurrence with respect to any of the Contractor’s owned, hired, and non-owned vehicles assigned to or used in performance of the Contractor’s work or services or use or maintenance of the premises under this contract. 8.4.9.3 Workers’ Compensation 8.4.9.3.1 Workers’ compensation insurance to cover obligations imposed by Federal and State statutes having jurisdiction of Contractor’s employees engaged in the performance of the work or services under this contract; and Employer’s Liability insurance of not less than $1,000,000 for each accident, $1,000,000 disease for each employee, and $1,000,000 disease policy limit. SERIAL 230142-RFP 8.4.9.3.2 Contractor, its subcontractors, and sub-subcontractors waive all rights against this contract and its agents, officers, directors, and employees for recovery of damages to the extent these damages are covered by the workers’ compensation and Employer’s Liability or Commercial Umbrella Liability insurance obtained by Contractor, its subcontractors, and its sub-subcontractors pursuant to this contract. 8.4.9.4 Errors and Omissions/Professional Liability Insurance Technology Errors & Omission insurance: Such insurance shall cover any and all errors, omissions, or negligent acts in the delivery of products, services, and/or licensed programs under this contract. • Each claim $5,000,000 In the event that the Technology Errors & Omission insurance required by this contract is written on a claims-made basis, contractor warrants that any retroactive date under the policy shall precede the effective date of this contract and, either continuous coverage will be maintained or an extended discovery period will be exercised for a period of two years, beginning at the time work under this contract is completed. 8.4.9.5 Cyber, Network Security, and Privacy Liability Cyber, Network Security and Privacy Liability Insurance with a limit of not less than $5,000,000 per occurrence. The policy shall include, but not be limited to; coverage for all directors, officers, agents and employees of the Contractor, losses with respect to network risks (such as data breaches, unauthorized access or use, and ID theft of data), invasion of privacy (regardless of the type of media involved in the loss of private information), crisis management, identity theft response costs, breach notification costs, credit remediation, and credit monitoring, defense, and claims expenses, regulatory defense costs plus fines and penalties, cyber extortion, electronic data restoration expenses (data asset protection), network business interruption, computer fraud coverage, funds transfer loss, third-party fidelity, theft, no requirement for arrest and conviction, and loss outside the premises of the named insured. 8.4.10 Certificates of Insurance 8.4.10.1 Prior to contract award, Contractor shall furnish the County with valid and complete Certificates of Insurance, or formal endorsements as required by the contract in the form provided by the County, issued by Contractor’s insurer(s), as evidence that policies providing the required coverage, conditions and limits required by this contract are in full force and effect. Such certificates shall identify this contract number and title. 8.4.10.2 In the event any insurance policy(ies) required by this contract is (are) written on a claims-made basis, coverage shall extend for two years past completion and acceptance of Contractor’s work or services and as evidenced by annual certificates of insurance. 8.4.10.3 If a policy does expire during the life of the Contract, a renewal certificate must be sent to County 15 calendar days prior to the expiration date. SERIAL 230142-RFP 8.4.11 Cancellation and Expiration Notice Applicable to all insurance policies required within the insurance requirements of this contract, Contractor’s insurance shall not be permitted to expire, be suspended, be canceled, or be materially changed for any reason without 30 days prior written notice to Maricopa County. Contractor must provide to Maricopa County, within two business days of receipt, if they receive notice of a policy that has been or will be suspended, canceled, materially changed for any reason, has expired, or will be expiring. Such notice shall be sent directly to Maricopa County Office of Procurement Services and shall be mailed, or hand delivered to 301 W. Jefferson St. Suite 700, Phoenix, AZ 85003, or emailed to the procurement officer noted in the solicitation. 8.5 FORCE MAJEURE 8.5.1 Neither party shall be liable for failure of performance, nor incur any liability to the other party on account of any loss or damage resulting from any delay or failure to perform all or any part of this contract, if such delay or failure is caused by events, occurrences, or causes beyond the reasonable control and without negligence of the parties. Such events, occurrences, or causes include, but are not limited to, acts of God/nature (including fire, flood, earthquake, storm, hurricane, or other natural disaster), war, invasion, act of foreign enemies, hostilities (whether war is declared or not), civil war, riots, rebellion, revolution, insurrection, military or usurped power or confiscation, terrorist activities, nationalization, government sanction, lockout, blockage, embargo, labor dispute, strike, and interruption or failure of electricity or telecommunication service, and pandemic. 8.5.2 Each party, as applicable, shall give the other party notice of its inability to perform and particulars in reasonable detail of the cause of the inability. Each party must use best efforts to remedy the situation and remove, as soon as practicable, the cause of its inability to perform or comply. 8.5.3 The party asserting Force Majeure as a cause for non-performance shall have the burden of proving that reasonable steps were taken to minimize delay or damages caused by foreseeable events, that all non-excused obligations were substantially fulfilled, and that the other party was timely notified of the likelihood or actual occurrence which would justify such an assertion, so that other prudent precautions could be contemplated. 8.6 ORDERING AUTHORITY Any request for purchase shall be accompanied by a valid purchase order issued by a County department or directed by a Certified Agency Procurement Aid (CAPA) with a purchase card for payment. 8.7 PROCUREMENT CARD ORDERING CAPABILITY County may opt to use a procurement card (Visa or Master Card) to make payment for orders under this contract. 8.8 NO MINIMUM OR MAXIMUM PURCHASE OBLIGATION This contract does not guarantee any minimum or maximum purchases will be made. Orders will only be placed under this contract when the County identifies a need and proper authorization and documentation have been approved. SERIAL 230142-RFP 8.9 PURCHASE ORDERS 8.9.1 County reserves the right to cancel purchase orders within a reasonable period of time after issuance. Should a purchase order be canceled, the County agrees to reimburse the Contractor for actual and documentable costs incurred by the Contractor in response to the purchase order. The County will not reimburse the Contractor for any costs incurred after receipt of County notice of cancellation, or for lost profits, or for shipment of product prior to issuance of purchase order. 8.9.2 Contractor agrees to accept verbal notification of cancellation of purchase orders from the County procurement officer with written notification to follow. Contractor specifically acknowledges to be bound by this cancellation policy. 8.10 BACKGROUND CHECK Respondents may be required to pass multiple background checks (e.g., Sheriff’s Office, County Attorney's Office, Courts, as well as Maricopa County general government) to determine if the respondent is acceptable to do business with the County. This applies to, but is not limited to, the company, subcontractors, and employees, and the failure to pass these checks shall deem the respondent non-responsible. 8.11 SUSPENSION OF WORK The procurement officer may order the Contractor, in writing, to suspend, delay, or interrupt all or any part of the work of this contract for the period of time that the procurement officer determines appropriate for the convenience of the County. No adjustment shall be made under this clause for any suspension, delay, or interruption to the extent that performance would have been so suspended, delayed, or interrupted by any other cause, including the fault or negligence of the Contractor. No request for adjustment under this clause shall be granted unless the claim, in an amount stated, is asserted in writing as soon as practicable after the termination of the suspension, delay, or interruption, but not later than the date of final payment under the contract. 8.12 STOP WORK ORDER 8.12.1 The procurement officer may, at any time, by written order to the Contractor, require the Contractor to stop all, or any part, of the work called for by this contract for a period of 90 calendar days after the order is delivered to the Contractor, and for any further period to which the parties may agree. The order shall be specifically identified as a stop work order issued under this clause. Upon receipt of the order, the Contractor shall immediately comply with its terms and take all reasonable steps to minimize the incurrence of costs allocable to the work covered by the order during the period of work stoppage. Within a period of 90 calendar days after a stop work order is delivered to the Contractor, or within any extension of that period to which the parties shall have agreed, the procurement officer shall either: 8.12.1.1 cancel the stop work order; or 8.12.1.2 terminate the work covered by the order as provided in the Termination for Default or the Termination for Convenience clause of this contract. 8.12.1.3 The procurement officer may make an equitable adjustment in the delivery schedule and/or contract price, and the contract shall be modified, in writing, accordingly, if the Contractor demonstrates that the stop work order resulted in an increase in costs to the Contractor SERIAL 230142-RFP 8.13 TERMINATION FOR CONVENIENCE Maricopa County may terminate the resultant contract for convenience by providing 60 calendar days advance notice to the Contractor. 8.14 TERMINATION FOR DEFAULT 8.14.1 The County may, by written Notice of Default to the Contractor, terminate this contract in whole or in part if the Contractor fails to: 8.14.1.1 deliver the supplies or to perform the services within the time specified in this contract or any extension; 8.14.1.2 make progress, so as to endanger performance of this contract; or 8.14.1.3 perform any of the other provisions of this contract. 8.14.2 The County’s right to terminate this contract under these subparagraphs may be exercised if the Contractor does not cure such failure within 10 business days (or more if authorized in writing by the County) after receipt of a Notice to Cure from the procurement officer specifying the failure. 8.15 PERFORMANCE It shall be the Contractor’s responsibility to meet the proposed performance requirements. Maricopa County reserves the right to obtain services on the open market in the event the Contractor fails to perform, and any price differential will be charged against the Contractor. 8.16 CONTRACTOR EMPLOYEE MANAGEMENT 8.16.1 Contractor shall endeavor to maintain the personnel proposed in their proposal throughout the performance of this contract. 8.16.2 If Contractor personnel’s employment status changes, Contractor shall provide County a list of proposed replacements with equivalent or greater experience. 8.16.3 Under no circumstances shall the implementation schedule to be impacted by a personnel change on the part of the Contractor. 8.16.4 Contractor shall not reassign any key personnel identified in their proposal without the express consent of the County. 8.16.5 County reserves the right to immediately remove from its premises any Contractor personnel it determines to be a risk to County operations. 8.16.6 County reserves the right to request the replacement of any Contractor personnel at any time, for any reason. 8.17 TRAINING 8.17.1 The contractor shall provide live in-classroom and/or online training that can be accessed for County staff members including but not limited to the following: 8.17.2 Administrator Training/As-Built Review 8.17.2.1 Configuration training where applicable for County resources will be performed prior to closure. 8.17.2.2 End User Hands-On Training SERIAL 230142-RFP 8.17.2.3 Post Deployment Training – train the trainer 8.17.3 Contractor shall provide online, in-application help and/or training materials for users to access while working within the system. Material shall be printable. 8.17.4 Contractor shall provide to the County options that include training materials which address County specific system configuration. 8.17.5 The contractor shall provide training services to completely train County personnel in the use and care of the equipment. All training shall take place on-site unless otherwise negotiated with County. 8.18 WARRANTY OF SERVICES 8.18.1 The Contractor warrants that all services provided hereunder will conform to the requirements of the contract, including all descriptions, specifications, and attachments made a part of this contract. County’s acceptance of services or goods provided by the Contractor shall not relieve the Contractor from its obligations under this warranty. 8.18.2 In addition to its other remedies, County may, at the Contractor's expense, require prompt correction of any services failing to meet the Contractor's warranty herein. Services corrected by the Contractor shall be subject to all the provisions of this contract in the manner and to the same extent as services originally furnished hereunder. 8.19 INSPECTION OF SERVICES 8.19.1 The Contractor shall provide and maintain an inspection system acceptable to County covering the services under this contract. Complete records of all inspection work performed by the Contractor shall be maintained and made available to County during contract performance and for as long afterwards as the contract requires. 8.19.2 County has the right to inspect and test all services called for by the contract, to the extent practicable at all times and places during the term of the contract. County shall perform inspections and tests in a manner that will not unduly delay the work. 8.19.3 If any of the services do not conform to contract requirements, County may require the Contractor to perform the services again in conformity with contract requirements, at no cost to the County. When the defects in services cannot be corrected by re-performance, County may: 8.19.3.1 require the Contractor to take necessary action to ensure that future performance conforms to contract requirements; and 8.19.3.2 reduce the contract price to reflect the reduced value of the services performed. 8.19.4 If the Contractor fails to promptly perform the services again or to take the necessary action to ensure future performance in conformity with contract requirements, County may: 8.19.4.1 by contract or otherwise, perform the services and charge to the Contractor, through direct billing or through payment reduction, any cost incurred by County that is directly related to the performance of such service; or SERIAL 230142-RFP 8.19.4.2 terminate the contract for default. 8.20 STATUTORY RIGHT OF CANCELLATION FOR CONFLICT OF INTEREST Notice is given that, pursuant to A.R.S. § 38-511, the County may cancel any contract without penalty or further obligation within three years after execution of the contract, if any person significantly involved in initiating, negotiating, securing, drafting, or creating the contract on behalf of the County is at any time, while the contract or any extension of the contract is in effect, an employee or agent of any other party to the contract in any capacity or consultant to any other party of the contract with respect to the subject matter of the contract. Additionally, pursuant to A.R.S. § 38-511, the County may recoup any fee or commission paid or due to any person significantly involved in initiating, negotiating, securing, drafting, or creating the contract on behalf of the County from any other party to the contract arising as the result of the contract. 8.21 OFFSET FOR DAMAGES In addition to all other remedies at Law or Equity, the County may offset from any money due to the Contractor any amounts Contractor owes to the County for damages resulting from breach or deficiencies in performance of the contract. 8.22 SUBCONTRACTING 8.22.1 The Contractor may not assign to another Contractor or subcontract to another party for performance of the terms and conditions hereof without the written consent of the County. All correspondence authorizing subcontracting must reference the bid serial number and identify the job or project. 8.22.2 The subcontractor’s rate for the job shall not exceed that of the prime Contractor’s rate, as bid in the pricing section, unless the prime Contractor is willing to absorb any higher rates. The subcontractor’s invoice shall be invoiced directly to the prime Contractor, who in turn shall pass-through the costs to the County, without mark- up. A copy of the subcontractor’s invoice must accompany the prime Contractor’s invoice. 8.23 AMENDMENTS All amendments to this contract shall be in writing and approved/signed by both parties. Maricopa County Office of Procurement Services shall be responsible for approving all amendments for Maricopa County. 8.24 ADDITIONS/DELETIONS OF REQUIREMENTS The County reserves the right to add and/or delete materials and services to a contract. If a service requirement is deleted, payment to the Contractor will be reduced proportionately to the amount of service reduced in accordance with the bid price. If additional materials or services are required from a contract, prices for such additions will be negotiated between the Contractor and the County. 8.25 RIGHTS IN DATA 8.25.1 The County shall have the use of data and reports resulting from a contract without additional cost or other restriction except as may be established by law or applicable regulation. Each party shall supply to the other party, upon request, any available information that is relevant to a contract and to the performance thereunder. SERIAL 230142-RFP 8.25.2 Data, records, reports, and all other information generated for the County by a third party as the result of a contract are the property of the County and shall be provided in a format designated by the County or shall be and remain accessible to the County into perpetuity. 8.26 ACCESS TO AND RETENTION OF RECORDS FOR THE PURPOSE OF AUDIT AND/OR OTHER REVIEW 8.26.1 In accordance with Section MC1-372 of the Maricopa County Procurement Code, the Contractor agrees to retain (physical or digital copies of) all books, records, accounts, statements, reports, files, and other records and back-up documentation relevant to this contract for six years after final payment or until after the resolution of any audit questions, which could be more than six years, whichever is longest. The County, Federal or State auditors and any other persons duly authorized by the department shall have full access to and the right to examine, copy, and make use of, any and all said materials. 8.26.2 If the Contractor’s books, records, accounts, statements, reports, files, and other records and back-up documentation relevant to this contract are not sufficient to support and document that requested services were provided, the Contractor shall reimburse Maricopa County for the services not so adequately supported and documented. 8.27 AUDIT DISALLOWANCES If at any time it is determined by the County that a cost for which payment has been made is a disallowed cost, the County shall notify the Contractor in writing of the disallowance. The course of action to address the disallowance shall be at sole discretion of the County, and may include either an adjustment to future invoices, request for credit, request for a check, or a deduction from current invoices submitted by the Contractor equal to the amount of the disallowance, or to require reimbursement forthwith of the disallowed amount by the Contractor by issuing a check payable to Maricopa County. 8.28 STRICT COMPLIANCE Acceptance by County of a performance that is not in strict compliance with the terms of the contract shall not be deemed to be a waiver of strict compliance with respect to all other terms of the contract. 8.29 VALIDITY The invalidity, in whole or in part, of any provision of this contract shall not void or affect the validity of any other provision of the contract. 8.30 SEVERABILITY The removal, in whole or in part, of any provision of this contract shall not void or affect the validity of any other provision of this contract. 8.31 RELATIONSHIPS 8.31.1 In the performance of the services described herein, the Contractor shall act solely as an independent Contractor, and nothing herein or implied herein shall at any time be construed as to create the relationship of employer and employee, co- employee, partnership, principal and agent, or joint venture between the County and the Contractor. SERIAL 230142-RFP 8.31.2 The County reserves the right of final approval on proposed staff. Also, upon request by the County, the Contractor will be required to remove any employees working on County projects and substitute personnel based on the discretion of the County within two business days, unless previously approved by the County. 8.32 NON-DISCRIMINATION Contractor agrees to comply with all provisions and requirements of Arizona Executive Order 2009-09, including flow down of all provisions and requirements to any subcontractors. Executive Order 2009-09 supersedes Executive Order 99-4 and amends Executive Order 75-5 and is hereby incorporated into this contract as if set forth in full herein. During the performance of this contract, Contractor shall not discriminate against any employee, client, or any other individual in any way because of that person’s age, race, creed, color, religion, sex, disability, or national origin. (Arizona Executive Order 2009-09 can be viewed at https://apps.azsos.gov/public_services/register/2009/46/governor.pdf). 8.33 WRITTEN CERTIFICATION PURSUANT to A.R.S. § 35-393.01 If vendor engages in for-profit activity and has 10 or more employees, and if this agreement has a value of $100,000 or more, vendor certifies it is not currently engaged in, and agrees for the duration of this agreement to not engage in, a boycott of goods or services from Israel. This certification does not apply to a boycott prohibited by 50 U.S.C. § 4842 or a regulation issued pursuant to 50 U.S.C. § 4842. 8.34 CERTIFICATION REGARDING DEBARMENT AND SUSPENSION 8.34.1 The undersigned (authorized official signing on behalf of the Contractor) certifies to the best of his or her knowledge and belief that the Contractor, its current officers, and directors: 8.34.1.1 are not presently debarred, suspended, proposed for debarment, declared ineligible, or voluntarily excluded from being awarded any contract or grant by any United States department or agency or any state, or local jurisdiction; 8.34.1.2 have not within a three-year period preceding this contract: 8.34.1.2.1 been convicted of fraud or any criminal offense in connection with obtaining, attempting to obtain, or as the result of performing a government entity (Federal, State or local) transaction or contract; or 8.34.1.2.2 been convicted of violation of any Federal or State antitrust statutes or conviction for embezzlement, theft, forgery, bribery, falsification or destruction of records, making false statements, or receiving stolen property regarding a government entity transaction or contract; 8.34.1.3 are not presently indicted or criminally charged by a government entity (Federal, State or local) with commission of any criminal offenses in connection with obtaining, attempting to obtain, or as the result of performing a government entity public (Federal, State or local) transaction or contract; 8.34.1.4 are not presently facing any civil charges from any governmental entity regarding obtaining, attempting to obtain, or from performing any governmental entity contract or other transaction; and SERIAL 230142-RFP 8.34.1.5 have not within a three-year period preceding this contract had any public transaction (Federal, State or local) terminated for cause or default. 8.34.2 If any of the above circumstances described in the paragraph are applicable to the entity submitting a bid for this requirement, include with your bid an explanation of the matter including any final resolution. 8.34.3 The Contractor shall include, without modification, this clause in all lower tier covered transactions (i.e., transactions with subcontractors or sub-subcontractors) and in all solicitations for lower tier covered transactions related to this contract. If this clause is applicable to a subcontractor or sub-subcontractor, the Contractor shall include the information required by this clause with their bid. 8.35 VERIFICATION REGARDING COMPLIANCE WITH A.R.S. § 41-4401 AND FEDERAL IMMIGRATION LAWS AND REGULATIONS 8.35.1 By entering into the contract, the Contractor warrants compliance with the Immigration and Nationality Act (INA using E-Verify) and all other Federal immigration laws and regulations related to the immigration status of its employees and A.R.S. § 23-214(A). The Contractor shall obtain statements from its subcontractors certifying compliance and shall furnish the statements to the procurement officer upon request. These warranties shall remain in effect through the term of the contract. The Contractor and its subcontractors shall also maintain Employment Eligibility Verification forms (I-9) as required by the Immigration Reform and Control Act of 1986, as amended from time to time, for all employees performing work under the contract and verify employee compliance using the E-Verify system and shall keep a record of the verification for the duration of the employee’s employment or at least three years, whichever is longer. I-9 forms are available for download at www.uscis.gov. 8.35.2 The County retains the legal right to inspect documents of Contractor and subcontractor employees performing work under this contract to verify compliance with paragraph 8.35.1 of this section. Contractor and subcontractor shall be given reasonable notice of the County’s intent to inspect and shall make the documents available at the time and date specified. Should the County suspect or find that the Contractor or any of its subcontractors are not in compliance, the County will consider this a material breach of the contract and may pursue any and all remedies allowed by law, including, but not limited to: suspension of work, termination of the contract for default, and suspension and/or debarment of the Contractor. All costs necessary to verify compliance are the responsibility of the Contractor. 8.36 CONTRACTOR LICENSE REQUIREMENT 8.36.1 The Contractor shall procure all permits, insurance, and licenses, and pay the charges and fees necessary and incidental to the lawful conduct of his/her business, and as necessary complete any requirements, by any and all governmental or non-governmental entities as mandated to maintain compliance with and remain in good standing. The Contractor shall keep fully informed of existing and future trade or industry requirements, and Federal, State, and local laws, ordinances, and regulations which in any manner affect the fulfillment of a contract and shall comply with the same. Contractor shall immediately notify both Office of Procurement Services and the department of any and all changes concerning permits, insurance, or licenses. SERIAL 230142-RFP 8.37 INFLUENCE 8.37.1 As prescribed in MC1-1203 of the Maricopa County Procurement Code, any effort to influence an employee or agent to breach the Maricopa County Ethical Code of Conduct or any ethical conduct, may be grounds for disbarment or suspension under MC1-902. 8.37.2 An attempt to influence includes, but is not limited to: 8.37.2.1 A person offering or providing a gratuity, gift, tip, present, donation, money, entertainment or educational passes or tickets, or any type of valuable contribution or subsidy that is offered or given with the intent to influence a decision, obtain a contract, garner favorable treatment, or gain favorable consideration of any kind. 8.37.3 If a person attempts to influence any employee or agent of Maricopa County, the chief procurement officer, or his designee, reserves the right to seek any remedy provided by the Maricopa County Procurement Code, any remedy in equity or in the law, or any remedy provided by this contract. 8.37.4 ABSOLUTELY NO CONTACT BETWEEN THE RESPONDENT AND ANY COUNTY PERSONNEL, OTHER THAN THE OFFICE OF PROCUREMENT SERVICES, IS ALLOWED DURING THE SOLICITATION PROCESS UNLESS THE COMMUNICATION IS IN REGARD TO PRE-EXISTING BUSINESS WITH THE COUNTY. ANY COMMUNICATIONS REGARDING THE SOLICITATION, ITS PARTICIPANTS, OR ANY DOCUMENTATION PRIOR TO THE CONTRACT AWARD MAY BE GROUNDS FOR DISMISSAL OF THE RESPONDENT FROM THE EVALUATION PROCESS. 8.38 CONFIDENTIAL INFORMATION 8.38.1 Any information obtained in the course of performing this contract may include information that is proprietary or confidential to the County. This provision establishes the Contractor’s obligation regarding such information. 8.38.2 The Contractor shall establish and maintain procedures and controls that are adequate to assure that no information contained in its records and/or obtained from the County or from others in carrying out its functions (services) under the contract shall be used by or disclosed by it, its agents, officers, or employees, except as required to efficiently perform duties under the contract. The Contractor’s procedures and controls, at a minimum, must be the same procedures and controls it uses to protect its own proprietary or confidential information. If, at any time during the duration of the contract, the County determines that the procedures and controls in place are not adequate, the Contractor shall institute any new and/or additional measures requested by the County within 15 business days of the written request to do so. 8.38.3 Any requests to the Contractor for County proprietary or confidential information shall be referred to the County for review and approval, prior to any dissemination. 8.39 PUBLIC RECORDS Under Arizona law, all offers submitted and opened are public records and must be retained by the County at the Maricopa County Office of Procurement Services. Offers shall be open to public inspection and copying after contract award and execution, except for such offers or sections thereof determined to contain proprietary or confidential information by the Office of Procurement Services. If an offeror believes that information in its offer or any resulting contract should not be released in response to a public record request, under Arizona law, the offeror shall indicate the specific information deemed confidential or SERIAL 230142-RFP proprietary and submit a statement with its offer detailing the reasons that the information should not be disclosed. Such reasons shall include the specific harm or prejudice which may arise from disclosure. The records manager of the Office of Procurement Services shall determine whether the identified information is confidential pursuant to the Maricopa County Procurement Code. 8.40 INTEGRATION This contract represents the entire and integrated agreement between the parties and supersedes all prior negotiations, proposals, communications, understandings, representations, or agreements, whether oral or written, expressed, or implied. 8.41 UNIFORM ADMINISTRATIVE REQUIREMENTS By entering into this contract, the Contractor agrees to comply with all applicable provisions of Title 2, Subtitle A, Chapter II, Part 200—UNIFORM ADMINISTRATIVE REQUIREMENTS, COST PRINCIPLES, AND AUDIT REQUIREMENTS FOR FEDERAL AWARDS contained in Title 2 C.F.R. § 200 et seq. 8.42 GOVERNING LAW This contract shall be governed by the laws of the State of Arizona. Venue for any actions or lawsuits involving this contract will be in Maricopa County Superior Court, Phoenix, Arizona. 8.43 FORCED LABOR 8.43.1 By submitting a bid for this solicitation and/or entering into a contract as a result of this solicitation, contractor agrees to comply with all applicable portions of Arizona Revised Statutes Section 35-394. Contracting; procurement; prohibition; written certification; remedy; termination; exception; definitions. 8.43.2 Contractor certifies that it does not currently, and agrees for the duration of the contract, that it will not use: 8.43.2.1 The forced labor of ethnic Uyghurs in the People’s Republic of China. 8.43.2.2 Any goods or services produced by the forced labor of ethnic Uyghurs in the People’s Republic of China. 8.43.2.3 Any contractors, subcontractors or suppliers that use the forced labor or any good or services produced by the forced labor of ethnic Uyghurs in the People’s Republic of China. 8.43.3 If contractor becomes aware during the term of the agreement that contractor is not in compliance with this paragraph, the contractor shall notify the County within five business days after becoming aware of the noncompliance. If the contractor fails to provide a written certification to the County that the contractor has remedied the noncompliance within 180 days after notifying the County of its noncompliance, then the agreement terminates, except that if the agreement termination date occurs before the end the 180-day period, the agreement terminates on the agreement termination date. 8.44 PRICES Contractor warrants that prices extended to County under this contract are no higher than those paid by any other customer for these or similar services. SERIAL 230142-RFP 8.45 CERTIFICATION REGARDING LOBBYING 8.45.1 Contractor certifies, to the best of their knowledge and belief, that: 8.45.1.1 No federal appropriated funds have been paid or will be paid, by or on behalf of the contractor, to any person for influencing or attempting to influence an officer or employee of any agency. This applies to a Member of Congress, an officer or employee of Congress, or an employee of a Member of Congress in connection with the awarding of any federal contract, the making of any federal grant. Including the making of any federal, loan the entering into of any cooperative agreement, and the extension, continuation, renewal, amendment, or modification of any federal contract, grant, loan, or cooperative agreement. 8.45.2 If any funds other than federal appropriated funds, have been paid or will be paid to any person for influencing or attempting to influence an officer or employee of any agency, member of Congress, an officer or employee of Congress, or an employee of a member of Congress in connection with this federal contract, grant, loan, or cooperative agreement, the undersigned shall complete and submit Standard Form-LLL, “Disclosure Form to Report Lobbying,” in accordance with its instructions. 8.45.3 Contractor shall include Lobbying Certification language in the award documents for all subcontractors (including sub-grants, and contract under grants, loans, and cooperative agreements) and that all sub-recipients shall certify and disclose accordingly. 8.45.3.1 The Lobbying Certification is a material representation of fact upon which reliance was placed when this transaction is made or entered into. Submission of this certification is prerequisite for making or entering into this transaction imposed by section 1352, Title 31, U.S. Code. Any successful proposer(s) who fail to file the required certification shall be subject to a civil penalty of not less than $10,000.00 and not more than $100,000.00 for each such failure. 8.46 CLEAN AIR ACT & CLEAN WATER ACT Contractor must comply with all applicable standards, orders, or requirements issued under section 306 of the Clean Air Act (42 U.S.C. 1857(h), section 508 of the Clean Water Act (33 U.S.C. 1368) Executive Order 11738, and Environmental Protection Agency regulations (40 CFR part 15). 8.47 ENERGY POLICY AND CONSERVATION ACT Contractor must adhere to the standards and policies relating to energy efficiency, which are contained in the State energy conservation plan issued in compliance with the Energy Policy and Conservation Act (Pub. L. 94-163, 89 Stat.871). 8.48 ORDER OF PRECEDENCE In the event of a conflict in the provisions of this contract and Contractor’s license agreement, if applicable, the terms of this contract shall prevail. SERIAL 230142-RFP 8.49 INCORPORATION OF DOCUMENTS 8.49.1 The following are to be attached to and made part of this Contract: 8.49.1.1 Exhibit A – Vendor Information and Pricing 8.49.1.2 Exhibit B – Scope of Work 8.49.1.3 Exhibit C – Standard Software Maintenance Agreement 8.49.1.4 Exhibit D – Office of Procurement Services Contractor Travel and Per Diem Policy 8.49.1.5 Attachment E - Requirements Traceability Matrix 8.49.1.6 Attachment G – IT Supplement Terms and Conditions 8.50 NOTICES All notices given pursuant to the terms of this contract shall be addressed to: For County: Maricopa County Office of Procurement Services 301 W. Jefferson St., Suite 700 Phoenix, Arizona 85003-1647 For Contractor: ENKON Information Systems (USA) Inc 1700 Westlake Ave. N. Suite 200 Seattle, WA 98109 8.51 INQUIRIES 8.51.1 Inquiries concerning information herein must be submitted prior to the question deadline date/time posted in the e-procurement platform, Periscope S2G, using the link in the “Q&A” tab. 8.51.2 Administrative telephone/email inquiries shall be addressed to: LOUIS NICOLOSI, PROCUREMENT OFFICER TELEPHONE: (602) 506-2761 Louis.nicolosi@maricopa.gov 8.51.3 Inquiries may be submitted by telephone but must be followed up in writing. No oral communication is binding on Maricopa County. SERIAL 230142-RFP SERIAL 230142-RFP EXHIBIT A – VENDOR INFORMATION AND PRICING COMPANY NAME: ENKON Information Systems (USA) Inc DOING BUSINESS AS (dba): ENKON Information Systems (USA) Inc MAILING ADDRESS: 1700 Westlake Ave. N. Suite 200 Seattle WA 9 REMIT TO ADDRESS: 1700 Westlake Ave. N. Suite 200 Seattle WA 9 TELEPHONE NUMBER: 1-800-374-5291 FAX NUMBER: 250-480-7141 WWW ADDRESS: www.enkon.com REPRESENTATIVE NAME: Douglas Thorsteinson REPRESENTATIVE TELEPHONE NUMBER: 250-480-7103 REPRESENTATIVE EMAIL ADDRESS dthorsteinson@enkon.com YES NO REBATE WILL ALLOW OTHER GOVERNMENTAL ENTITIES TO PURCHASE FROM THIS CONTRACT: WILL ACCEPT PROCUREMENT CARD FOR PAYMENT: NET 30 DAYS SERIAL 230142-RFP 230142-RFP Pricing Sheet NIGP Codes-20876 & 20977 Pricing (Year 6 - 10 Optional Renewal) Vendor Submitting: ENKON One Time Costs: Real Estate Cost Description Year 1 Year 2 Year 3 Year 4 Year 5 Year 6 Year 7 Year 8 Year 9 Year 10 Vendor Explanation of Costs Traveling Costs (Per Exhibit 2) $20,000.00 $ $ $ $ $ $ $ $ $ Planning and Analysis Costs $175,000.00 $ $ $ $ $ $ $ $ $ Configuration Costs $90,000.00 $ $ $ $ $ $ $ $ $ Development Costs $75,000.00 $ $ $ $ $ $ $ $ $ Conversion and Migration Costs $160,000.00 $ $ $ $ $ $ $ $ $ Estimate at this time as we do not fully understand the extent of the data sets. Training Costs $75,000.00 $ $ $ $ $ $ $ $ $ Customization Costs $90,000.00 $ $ $ $ $ $ $ $ $ Monthly Hosting Costs $ $ $ $ $ $ $ $ $ $ Monthly Processing Costs $ $ $ $ $ $ $ $ $ $ Monthly Service Fees $12,000.00 $ $ $ $ $ $ $ $ $ Other One Time Fees $ $ $ $ $ $ $ $ $ $ Maintenance fee $12,000.00 $ $ $ $ $ $ $ $ $ License Fees $ 7,500.00 $ $ $ $ $ $ $ $ $ All Third Party Costs (If applicable) $ $ $ $ $ $ $ $ $ $ Add Additional lines if necessary $ $ $ $ $ $ $ $ $ $ Total: $716,500.00 $- $ - $- $- $ - $- $- $- $- Operational Costs: Cost Description Year 1 Year 2 Year 3 Year 4 Year 5 Year 6 Year 7 Year 8 Year 9 Year 10 Vendor Explanation of Costs Traveling Costs (Per Exhibit 2) $ $ $ $ $ $ $ $ $ $ Planning and Analysis Costs $ $ $ $ $ $ $ $ $ $ Configuration Costs $ $ $ $ $ $ $ $ $ $ Development Costs $ $ $ $ $ $ $ $ $ $ SERIAL 230142-RFP Conversion and Migration Costs $ $ $ $ $ $ $ $ $ $ Training Costs $ $20,000.00 $ $ $ $ $ $ $ $ Customization Costs $ $ $ $ $ $ $ $ $ $ Monthly Hosting Costs $ $ $ $ $ $ $ $ $ $ Monthly Processing Costs $ $ $ $ $ $ $ $ $ $ Monthly Service Fees $ $ $ $ $ $ $ $ $ $ Other One Time Fees $ $ $ $ $ $ $ $ $ $ Maintenance fee $ $11,400.00 $11,400.00 $ 11,400.00 $ 11,400.00 $12,540.00 $12,540.00 $12,540.00 $12,540.00 $12,540.00 License Fees $ $51,300.00 $51,300.00 $ 51,300.00 $ 51,300.00 $56,430.00 $56,430.00 $56,430.00 $56,430.00 $56,430.00 All Third Party Costs (If applicable) $ $ $ $ $ $ $ $ $ $ After Hours Support Rate $ $ $ $ $ $ $ $ $ $ Add Additional lines if necessary $ $ $ $ $ $ $ $ $ $ Total $ - $82,700.00 $62,700.00 $ 62,700.00 $ 62,700.00 $68,970.00 $68,970.00 $68,970.00 $68,970.00 $68,970.00 Year 1 Year 2 Year 3 Year 4 Year 5 Year 6 Year 7 Year 8 Year 9 Year 10 Total Total One Time Costs $716,500.00 $- $ - $- $- $ - $- $- $- $- $ 716,500.00 Total Operational Costs $ - $82,700.00 $62,700.00 $ 62,700.00 $ 62,700.00 $68,970.00 $68,970.00 $68,970.00 $68,970.00 $68,970.00 $ 615,650.00 Note: Pricing to be based on 25 up to 50 concurrent users with service support between the hours of 8:00 a.m. - 5:00 p.m. MST M-F. ENKON Note: Pricing is based on 100 named users. 230142-RFP Pricing Sheet NIGP Codes-20876 & 20977 Pricing (Year 6 - 10 Optional Renewal) Vendor Submitting:ENKON One Time Costs: Flood Control Cost Description Year 1 Year 2 Year 3 Year 4 Year 5 Year 6 Year 7 Year 8 Year 9 Year 10 Vendor Explanation of Costs Traveling Costs (Per Exhibit 2) $ $ $ $ $ $ $ $ $ Planning and Analysis Costs $ $ $ $ $ $ $ $ $ Configuration Costs $15,000.00 $ $ $ $ $ $ $ $ $ Asset Management Module Development Costs $ 7,500.00 $ $ $ $ $ $ $ $ $ SERIAL 230142-RFP Conversion and Migration Costs $ $ $ $ $ $ $ $ $ Estimate at this time as we do not fully understand the extent of the data sets. Training Costs $ 5,000.00 $ $ $ $ $ $ $ $ $ Customization Costs $ $ $ $ $ $ $ $ $ Monthly Hosting Costs $ $ $ $ $ $ $ $ $ Monthly Processing Costs $ $ $ $ $ $ $ $ $ Monthly Service Fees $ $ $ $ $ $ $ $ $ Other One Time Fees $ $ $ $ $ $ $ $ $ Maintenance fee $ $ $ $ $ $ $ $ $ License Fees $ $ $ $ $ $ $ $ $ All Third Party Costs (If applicable) $ $ $ $ $ $ $ $ $ Add Additional lines if necessary $ $ $ $ $ $ $ $ $ Total: $27,500.00 $- $ - $ - $- $ - $- $- $- $ - Operational Costs: Cost Description Year 1 Year 2 Year 3 Year 4 Year 5 Year 6 Year 7 Year 8 Year 9 Year 10 Vendor Explanation of Costs Traveling Costs (Per Exhibit 2) $ $ $ $ $ $ $ $ $ $ Planning and Analysis Costs $ $ $ $ $ $ $ $ $ $ Configuration Costs $ $ $ $ $ $ $ $ $ $ Development Costs $ $ $ $ $ $ $ $ $ $ Conversion and Migration Costs $ $ $ $ $ $ $ $ $ $ Training Costs $ Customization Costs $ Monthly Hosting Costs $ Monthly Processing Costs $ Monthly Service Fees $ Other One Time Fees $ Maintenance fee $ $3,000.00 $ 3,000.00 $ 3,000.00 $3,000.00 $3,300.00 $ 3,300.00 $ 3,300.00 $3,300.00 $3,300.00 License Fees $ $10,800.00 $10,800.00 $ 10,800.00 $ 10,800.00 $11,880.00 $11,880.00 $11,880.00 $11,880.00 $11,880.00 All Third Party Costs (If applicable) $ After Hours Support Rate $ Add Additional lines if necessary $ Total $ - $13,800.00 $13,800.00 $ 13,800.00 $ 13,800.00 $15,180.00 $15,180.00 $15,180.00 $15,180.00 $15,180.00 SERIAL 230142-RFP Year 1 Total One Time Costs $27,500.00 Total Operational Costs $ - $13,800.00 $13,800.00 $ 13,800.00 $ 13,800.00 $15,180.00 $15,180.00 $15,180.00 $15,180.00 $15,180.00 Note: Pricing to be based on 25 up to 50 concurrent users with service support between the hours of 8:00 a.m. - 5:00 p.m. MST M-F. ENKON Note: Pricing is based on 100 named users. SERIAL 230142-RFP EXHIBIT B-SCOPE OF WORK The proposal submitted by the vendor will include project management, needs assessment, configuration, installation, testing, training, documentation and implementation of the software solution and software licensing. Implementation must include the validation and migration of existing data into the new application and any required materials. Contractor shall provide a software solution that will support automation of all necessary functions related to permitting, plan review, inspections, licensing process, and code enforcement of the current system in place, and possibly offer expansion or integration of services not used at present The selected vendor must bring the range of necessary capabilities and experience to implement and provide support for the Real Property Management System. The County will consider proposals submitted by a contractor that proposes to work in conjunction with subcontractors. However, the bidding vendor must assume responsibility for all work and services performed under the executed contract. The County will choose a solution that most closely meets its requirements for flexibility and configurability, the functional requirements defined in this RFP, and that provides an open system architecture that allows integration with other internal enterprise systems. The solution selected will be implemented using a phased approach as recommended by the selected vendor and approved by the County. The County expects process improvement through implementation of new systems, and it is the County’s intent to adopt industry best practices and standards wherever feasible to minimize the configuration that is required to implement and maintain the various components of the proposed solution. 1.1. TECHNICAL AND FUNCTIONAL REQUIREMENTS Technical and Functional Requirements are listed in Attachment E - Requirements Traceability Matrix. Respondents are to complete the table to the best of their ability. Failure to submit a completed Attachment E - Requirements Traceability Matrix will result in non-responsive submittal and will immediately disqualify the vendor and software implementation services for a minimum of five years. Software Brokers are not permitted to submit an RFP on behalf of another Software Vendor. The Software Vendor submitting the RFP must be the Software Implementor. 1.1.1. Versioning 1.1.1.1. Major version of software being proposed has been in production for a minimum of one year. 1.1.1.2. Major version of software being proposed must be operating to provide a full range of functions in at least two comparable North American jurisdictions. Both implementations have been operational for at least six months. 1.1.2. System Integration 1.1.2.1. The proposed system integration has been implemented for at least two large government jurisdictions. Both implementations have been operational for at least six months. 1.1.2.2. At least one of the implementations above included mapping and conversion of records from multiple data sources. 1.1.3. Project Manager 1.1.3.1. Proposed project manager has managed at least three software implementation projects of similar scope and complexity within the last 10 years. SERIAL 230142-RFP 1.1.3.2. Proposed project manager has managed at least one implementation project that involved the proposed software major version (e.g., 5.XX) within the last five years. 1.1.3.3. Proposed project manager has experience with PMI Project Management Implementation methods. 1.1.4. Project Management 1.1.4.1. The contractor shall provide professional project management that works closely and effectively with all County team members. The contractor will provide a project leadership resource or team to work with the County stakeholders and project manager. A steering committee comprised of contractor and County resources will meet at regular intervals to track project progress and review escalations or scope changes as needed. 1.1.4.2. Contractor will provide complete project management services that will provide the project management or implementation methodology following PMI standards (waterfall, agile, etc.) that they plan to use during the process. 1.1.4.3. The contractor will plan and facilitate business process realignment, conducting facilitated workshops to align Maricopa County Real Estate Department existing business processes with industry standards, to increase efficiency while taking advantage of the solution’s best/effective practices. The contractor will be responsible for identifying and documenting needed changes and demonstrating clearly how the proposed software will be implemented with these new processes. In addition, the contractor will identify and document processes that can’t be aligned with application functionality and provide alternative solutions. Any process changes or re-alignment must be approved by the County. 1.1.4.4. The contractor will conduct a fit/gap analysis to compare the stated requirements against the application functionality as specified in Attachment E - Requirements Traceability Matrix. Based on this analysis, contractor will provide recommendations for closing the gaps. These recommendations may include business process or configuration changes. Customizations may be recommended for critical business needs (prioritized, risk assessed) but should be avoided as much as possible. 1.1.4.5. Contractor shall dedicate staffing resources who will be expected to understand the County business requirements and practices before configuration.. The system shall be configured in a manner that is easily supported using normal effective business practices while considering the needs of the County. Differences between current business practices and configuration recommendations will be documented by the contractor and approved by the County prior to any change in configuration. 1.1.4.6. The contractor shall develop an organizational change management strategy including outlining the organizational changes that the initiative will bring, developing specific transition and communication strategies for the various stakeholder groups, and developing strategies for mitigating and managing major barriers for implementation. The contractor will align with County counterpart(s) and communication support staff. The communications strategies should build throughout the project to create a thorough awareness and understanding of the project to all staff. This will include contractor crafted language and branding material specific for the project within the County. 1.1.4.7. The contractor must propose a methodology and tools for maintaining multiple environments (including data refresh and migration capabilities) on an ongoing basis during and after project completion (provide testing tool software SERIAL 230142-RFP information). At least three separate environments are expected for issues management, development, testing, and training for the term of the contract. The contractor must also propose and provide appropriate documentation, end-user training, and operations procedures to enable departments to effectively maintain and utilize all environments 1.2. SYSTEM REQUIREMENTS Contractors shall complete Attachment E - Requirements Traceability Matrix for each business process based on current functionality. 1.3. GENERAL REQUIREMENTS Application functionality shall include and not be limited to the following: 1.3.1. Acquisitions: The application shall allow County Users to submit a request for Acquisition of Property for County Projects. Application shall allow internal RED users to manage the acquisition process including budget, parcels to be acquired, correspondence with parcel owners, negotiations, offer letters, final offers and condemnation. 1.3.2. County Owned Property: The application shall allow County Users to maintain current county owned properties and provide the ability to view historical property information that includes acquisition, excess land sales, parcel splits, easements, annexations, and abandonment. 1.3.3. Right of Way and Easements: Application shall allow County Users to designate County Right of Way for maintenance and Easement in-grants and out-grants. 1.3.4. Annexations and Abandonments: The application shall allow County Users to apply annexations or abandonments against County Owned property and store recorded information related to the property. 1.3.5. Leases/Licenses: The application shall allow County Users to track Leases and Licenses where the County is either the lessor or the lessee and provide the ability to generate lease agreements and track monthly and annual rents due for the agreement period as well as provide tracking of any license agreements. 1.3.6. Other Agreements: The application shall provide the ability to track other agreements (Inter-Governmental Agreements, Memorandums of Understanding) with external jurisdictions or property owners. 1.3.7. Excess Land Sales: The application shall allow the ability to split and designate county owned property as excess land available for sale and provide a workflow from designation to receipt of payment and closing documents. 1.3.8. OnBase Integration: The proposed solution shall provide integration with the County’s Enterprise Document Management System, OnBase for document storage. 1.3.9. DocuSign Integration: The proposed solution shall allow integration with DocuSign to allow for electronic signatures for agreements, contracts, leases, and other items that may require signature. 1.3.10. GIS Integration: Provide bi-directional integration with GIS that includes the ability to drill down from spatial maps into the revolutions per minutes (RPMS) for views of county owned property, easements, current acquisitions, annexations, as well as historical activities pertaining to an individual parcel or group of parcels within a project. The County would like to initiate actions from the GIS map such as initiating a request for an acquisition or a request for other information pertaining to a specific parcel to include (but not limited to), SERIAL 230142-RFP ownership, related department, county facilities, easements, leases or agreements and excess land. 1.3.11. Configurable and flexible workflow management tool to automate business processes including configurable automatic email notification to internal and external users, routing of system tasks based upon the application of established business rules, tracking and escalation of tasks, and the ability to perform ad hoc tasks as necessary. 1.3.12. Intuitive graphical user interface that is simple to use and provides robust functionality for internal and external stakeholders. This shall include logical menus, intuitive navigation, and consistent visual cues (pull downs, checklists, check boxes, etc.). The Graphical User Interface (GUI) will support a consistent user experience across all major browsers, i.e., Internet Explorer, Edge, Firefox, Chrome, and Safari. The implemented system will provide a navigation that conforms to industry best practices, across all modules including consistent use of good keyboard shortcuts, keyboard form navigation, standardized form validation, and standardized use of lookup/search screens, dropdowns, and pop-ups, tooltip text, icons, etc. 1.3.13. Legacy Data Accessibility. The ability to use vendor provided template to migrate or import legacy data from existing sources (Excel, SQL, Access) into the system so that data historical (up to five years) is available in the new application. 1.3.14. Ability to integrate or interface with existing line of business applications including but not limited to ESRI, DocuSign, OnBase, or legacy data via Application Programming Interface (API’s), queries, etc. System must have a data structure that allows for integration with other systems with open databases, points of integration include, but are not limited to GIS data, OnBase, Advantage., must also include a well-documented data dictionary and any ongoing updates 1.3.15. Standard reporting capability as well as ad hoc report creation allowing user to select from standard reporting as well as creation of customized reports based on indexed values. Easy output of query data to text, Adobe, MS Word, MS Excel, or Portable Document Format (PDF) is required. 1.3.16. The solution must be searchable by multiple data fields including, but not limited to, Department, Property Type, Real Estate Parcel Number, Project Number, Road Name (On/From/To), Assessor Parcel Number, Township/Range/Section (Public Land Survey System (PLSS)), Recording Number 1.3.17. Data backup and archiving including purging of data at regular intervals based on county defined records retention policies. 1.3.18. Configurable Automated Notifications. Automatic email notification to users when assigned activities have been updated or new tasks have been assigned to them. Automatic email notification to supervisors and staff when a task is overdue. 1.3.19. Roles based security and workflow capabilities with County administrators who can perform user administration, configuration changes, and other administrator tasks without intervention by the contractor. Authentication via OKTA (preferred), Active Directory, or single sign on. All user sessions should be always encrypted, supporting Security Assertion markup Language (SAML)-based authentication in conjunction with Multi Factor Authentication (MFA). 1.3.20. Current Security diagrams and other documentation such as architecture, policies, procedures, and compliance with laws, National Institute of Standards and Technology (NIST) critical success factor (CSF), Statement of Standards for Attestation Engagements No. 16 (SSAE-16), Health Insurance Portability and Accountability (HIPAA), Sarbanes- Oxley Act (SOX), Federal Risk and Authorization Management Program (FedRAMP), etc. Security patches and software upgrades should be current, and backup procedures for SERIAL 230142-RFP remote files and databases should be put in place. Third party software integration should be verified. 1.3.21. The vendor must make Systems and Organizations Controls 2 (SOC2) compliance reports, audit findings, and third-party attestations available at any time to the County upon request. 1.3.22. Personal Identifiable Information: The proposed solution shall not monitor or track Personal Identifiable Information (PII). 1.4. CONTRACTOR REQUIREMENTS Contractor services shall include and not be limited to the following: 1.4.1. Experienced-based expertise and consultation on topics such as suggested changes in process flows, communication, industry best practices, etc. 1.4.2. Facilitation of business process analysis and potential reengineering of business processes impacted by solution as necessary to increase efficiency while taking advantage of the solution’s best/effective practices. 1.4.3. System configuration and delivery of software to meet business and functionality requirements. 1.4.4. Full implementation of the new solution (including as-built documentation of system design, system configurations). 1.4.5. Delivery of browser-based access to the solution for administration staff to facilitate ease of application system deployment and maintenance. 1.4.6. Integration of imaging, print-on-demand, and workflow management, collectively also known as Enterprise Content Management (ECM), within the solution – to include both “tight” workflow (i.e., enabling a transaction/function as part of a defined workflow path), as well as the ability to perform a transaction/function such as a parcel type or other attribute change “directly” (i.e., ‘outside’ of the defined workflow path). 1.4.7. Testing of the solution to confirm that it meets the functionality, reliability, or performance needs of the County’s integrated enterprise-wide application environment. The testing will be conducted for both the install for performance testing and during the configuration stage for functional testing. 1.4.8. Process/workflow analysis, including comparison of current process versus new process of all impacted workflows and procedures. 1.4.9. Training, including County specific manuals and documentation for system users, including employees and administrators, in addition to all baseline functionalities. All such documentation must reflect the as-built status of the solution; standard documentation reflecting only the contractor’s un-configured base solution will not be accepted. 1.4.10. Ongoing maintenance and support including system updates, patching, hot fixes, and other actions necessary to provide 24/7 access for internal and external users. 1.4.11. Integration services using common integration technologies for the communication of data from other County systems. 1.4.12. Administration and delivery of training for system administrators in application navigation and the use of screens and windows and the use of the new solution to perform all various job functions, processes, and sub-processes in the new environment. SERIAL 230142-RFP 1.5. DISASTER RECOVERY 1.5.1. For Hosted Solutions, contractor shall provide an automated/self-service ability to retrieve all county data as desired, preferably through an API or other service. 1.5.2. For Hosted Solutions, contractor shall provide a detailed disaster recovery plan that will outline the Recovery Time Objective (RTO) and Recovery Point Objective (RPO). 1.5.2.1. RTO — the maximal time your organization can tolerate for recovering normal operations in case of a disaster (for example, recovery within 30 minutes, 2 hours, 12 hours) 1.5.2.2. RPO — the maximal amount of data your organization can afford to lose (for example, an hour of data, three hours of data, one day of data) 1.6. IMPLEMENTATION PLAN The contractor must provide a detailed implementation plan that models a standard practice implementation including migration of existing data and includes the following: 1.6.1. Implementation methodology: The plan must include flexible implementation methods that will allow for increased communication, testing, and progress tracking on a recurring basis. 1.6.2. Task Level Information: The plan must include all activities necessary for a successful project at multiple levels - primary activity, task level, and subtasks levels as needed. 1.6.3. Identification of All Resources: The plan must clearly identify the contractor (including subcontractors), and other resources required, including County resources, to successfully complete the project. The vendor must provide job descriptions and the number of personnel to be assigned for all Implementation activities. 1.6.4. Plan Progress Charts: The plan must include appropriate progress/Gantt chart-style project schedule including all phases, activities, resources (by job title) as well as any County resources required as part of the vendor’s implementation. Include estimated durations for the activities, deliverable milestones, and dependencies. 1.7. TRAINING 1.7.1. The county shall provide live in-classroom and/or online training that can be accessed for County staff members including but not limited to the following: 1.7.1.1. Administrator Training/As-built review 1.7.1.1.1. Configuration training where applicable for County resources will be performed prior to closure. 1.7.1.2. End User Hands-On Training 1.7.1.3. Post Deployment Training – train the trainer 1.7.2. Contractor shall provide online, in-application help and/or training materials for users to access while working within the system. Material shall be printable. 1.7.3. Contractor shall provide to the County options that include training materials which address County specific system configuration. 1.7.4. The contractor shall provide training services to completely train County personnel in the use and care of the equipment. SERIAL 230142-RFP 1.8. TESTING REQUIREMENTS 1.8.1. A documented strategy for testing and quality assurance of configuration by analysis and implementation consultants shall be provided to the County project team for approval prior to commencement of system build.+ 1.8.2. Unit testing of the functionality of the system shall be performed and documented by the contractor. Samples and results of tests may be requested by the project team to ensure thorough testing is performed prior to client turnover. Issues identified in testing shall be cataloged, updated upon closure with final disposition, and provided to the project team prior to user acceptance testing (UAT) testing. Items identified as issues will not be closed unless written approval to do so is provided by the County. 1.8.3. Contractor will work directly with County, and external vendors to integration test all interfaces and transmissions of data. To eliminate constraints and delays in external testing and validation, a separate mirror environment for SIT testing is required. 1.8.4. Contractor will work with the County to perform migrations to new environment via move or copy, not reconfiguration. This is to test the migration process in preparation for go-live. 1.8.5. The contractor shall provide County with a UAT test catalog to aid in development of test scripts. Contractor will allow the County a reasonable timeframe to execute the test plan and retest items with issues. Contractor will enable automation and file transmission during UAT and parallel testing. Contractor will allow County to execute performance and load testing prior to the start of UAT. 1.8.6. County is responsible for executing test scripts for UAT and parallel testing. Contractor will work with County to identify gaps in testing plan where possible. 1.8.7. Testing variances will be documented, categorized, and assigned impact through a mutually agreed upon format. If significant issues are found in data conversion, the project leadership team may request additional conversions. 1.8.8. If significant issues are found in UAT testing, a refresh and restore with an additional cycle of UAT may be requested by the project leadership team. If an environment becomes stale due to long testing timeframes, the project leadership team may request a refresh or restore. 1.8.9. Contractor shall allow software to be scanned for security vulnerabilities prior to execution of a final contract. Any high or critical findings will need to be remediated before the County will enter into a contractual agreement with the vendor. 1.9. PRODUCTION SUPPORT AND PRODUCT MANAGEMENT The following items shall be delivered to County in advance of the go-no-go decision for migration to production. 1.9.1. Provide a tool for reporting, tracking issues and resolution that provides status and is accessible by County team as needed. 1.9.2. Upon successful delivery of the application, the contractor shall provide an implementation strategy and proposed timeline for future product enhancements. 1.10. POST GO LIVE SUPPORT 1.10.1. Contractor shall be expected to provide post go live support to County end users. Contractor shall provide details of post go live support in their response to this RFP including issue resolution. SERIAL 230142-RFP 1.11. PROJECT DELIVERABLES The following project deliverables are provided as an example. Actual deliverables will be determined prior to contract award. Milestone Milestone Description Suggested Deliverables Project Initiation and Planning Complete contract, begin project, finalize requirements and finalize plan • Project Kickoff Meeting • Project Schedule • Implementation Plan/Milestone Deliverables • Communication Plan • Security Risk Assessment • Requirement Traceability Matrix • Quality Assurance Plan Business Process Analysis and Re- alignment Optimize its underlying processes to achieve more efficient results with the new software Initiative 1 • Project Schedule/Work Plan • Business Process Alignment Workshops • Actionable Plan from Alignment Workshops • Business Process Alignment Presentation • Gap Analysis Documentation Initiative 2 • Change Readiness Assessment • Stakeholder Engagement Workshops • Organizational Alignment Strategy & Communication Plan • Impact Analysis of Business Process Redesign • Lessons Learned Workshop Initiative 3 • Document of Current Integrations • Data History Options Document • Data Cleanup Best Practices Guideline Organizational Change Management Create a framework, prepare, adopt, and implement organizational changes, including its culture, policies, procedures, and physical environment, as well as employee roles, skills, and responsibilities in how it relates to the software delivery. • Change Control Register • Stakeholder analysis • Communication Planning • Measurements for new change performance to redesign organizational strategies, ensuring business continuity • Value Realization Design Create design for how the system will be configured and data migrated for the County • Functional Specification Document • Technical Specification Document • Architecture Diagram (review/signoff) • Architecture/design documentation • Data Migration design documentation • Database Entity Relationship Diagram (ERD) for Reporting • Technical Requirements Documentation • Updated business and functional requirements documentation (if applicable) SERIAL 230142-RFP • Reporting Requirements Build and configure Build and Configure system. Complete conversion of historical data • Historical Data Analysis and Mapping • Data conversion plan and approach • Converted historical data • Interface Development Sign-Off • Configured Test and QA environments • Weekly Status Reports • Configuration Guide/Functional Workbook • Test Plan • Unit/System Testing Scripts • Unit/System Testing Sign-Off • Integration Testing Scripts • Integration Testing Sign-Off • Development of Reporting Specifications • Report Development Sign-Off • Detailed Cutover Plan • Support Plan Delivered Testing Vendor validates solution. User Acceptance Testing starts after to validate solution • User Acceptance Testing • User Acceptance Testing Scripts/Sign-Off Training Training of users. Documentation of solution electronically delivered to the County • On-Site Training • Training Guide and Job Aides • User Guide • Train the Trainer Sign-Off • Documentation on online help tools Deployment Move to production go-live and support • Configured production system • Post-Deployment Support • Metric reports and/or documentation • Transition to Service Operation/Maintenance • Populate all environments (DEV & UAT) with production Data Acceptance and Close Out Final project closure • Lessons Learned Participation • Invoices Finalized • Future Enhancement Implementation Strategy SERIAL 230142-RFP EXHIBIT C - CONTRACTOR STANDARD SOFTWARE TERMS SOFTWARE AND SERVICES TERMS 1. TERMS 1.1 These Terms and the schedules referenced in Section 1.2 are subject to the all of the other terms of the contract entered into the 27th day of March 2024 by and between County and Contractor (“Serial 230142-RFP”), to which these Terms are attached as this Exhibit C. In the event there is a conflict between these terms and all of the other terms of Serial 230142-RFP, all of the other terms of Serial 230142-RFP shall govern. These Terms will govern the purchase of licenses to access and use the Contractor software identified in Section 2.3, and the Services set out in Section 3. From time to time during the term of Serial 230142-RFP County may purchase additional software licenses and services, which additional licenses and services will be subject to these Terms. 1.2 County has read and understands the following schedule(s) to these Terms, which govern County’s use and Contractor’s delivery of the software and services: Schedule A – Terms and Conditions (SaaS) Schedule B – Support and Service Levels (SaaS) Schedule C – Professional Services Schedule D – Integral-LIS Licensed Components 2. LICENSE DETAILS 2.1 Authorized Users. County will be initially licensed for [100#] Authorized Users. Additional Authorized Users may be added at any time, subject to the rates set out in Exhibit A. 2.2 Authorized Area. County is authorized to use the Contractor software and services solely within the geographical limits of [] (the “Maricopa County, AZ-Authorized Area”). 2.3 Software Description and Subscription License Fees 2.3.1 Software. [[select: Integral-LIS package, Integral-BI package and Integral-Spatial package]. During the term of Serial 230142-RFP, County may order additional software packages through the issuance of a written purchase order. 2.3.2 Configuration and Implementation. The one-time fee for the configuration and implementation of the software is per Exhibit A. 2.3.3 Monthly Subscription and Annual Maintenance Fees. The monthly subscription and annual maintenance fees for the Software are set out in Exhibit A. SERIAL 230142-RFP See Exhibit A Description One-Time Setup Fee (USD) Monthly Fee (USD) Annual Maintenance Fee (USD) Core Components 1. Integral-LIS – Land Information System 2. Help Desk (Silver Package – ten (10) tickets a month) 3. Integral-BI – Report Manager, Designer and Dashboards 4. Core User Licenses – five (5) Additional User Licenses • 6-50 users $25/user/month • 51-100 users$20/user/month • 101-200 users $20/user/month Optional Items 5. Integral-Spatial – Map Viewer and Map Server (GeoServer version) 6. Tax Package 7. Reserves Package 8. Analytical Data Management 9. Help Desk (Platinum Package – unlimited tickets) TOTAL 3. PROFESSIONAL SERVICES 3.1 Professional Services will be subject to the additional terms agreed to between county and contractor. 3.1.1 Training and Support. Training and support options offered by Contractor, and associated costs will be negotiated between county and contractor Costs do not include travel, accommodation, and general disbursements, all of which will invoiced at cost, and which are in addition to professional fees. Table 2 Item Description TOTAL (USD) Webinars Webinars (up to 20 attendees for a 1.5 hour session) per Webinar (Price to be determined on quantity requested) Classroom Training Session (at County’s premises) (2 days for one trainer) – In North America Training at County’s premises per session plus travel and accommodation expenses1 Administrative Training (up to five participants) Administrator Training in Contractor’s office in Victoria, BC, Canada. per session (2 day event) 3.1.2 Related Professional Services. Contractor shall provide the Professional Services set out in Exhibit A. From time to time during the term of Serial 230142-RFP, and subject to the execution of an agreed statement of work, County may request and Contractor shall provide certain additional Professional Services related to the licensed software. Unless otherwise agreed in the applicable SOW, Professional Services will be billed at Contractor’s then-standard time and materials rates. SERIAL 230142-RFP Table 3. Additional Professional Services Professional Services Description Data Migration Contractor can assist in migrating legacy data into the Integral-LIS Web Application. Quotes will be provided after a review of each of the available data sets. Integration Contractor can integrate the Integral-LIS with County systems. Map Creation Contractor has complete GIS Services that can assist the County in maintaining the mapping environment, including the creation of Map Services, editing services, etc. for the Integral-Spatial package. Map Server Maintenance Contractor can maintain the GeoServer on behalf of County if requested for the Integral-Spatial package. Reports Contractor can create custom reports that are provided by the County. Customization Contractor has created the Integral-LIS Web Application to allow easy customization and new business flows to be added into the application. 4. INVOICING Fees will be invoiced as follows, unless otherwise agreed in an applicable statement of work: • One time set-up, installation and configuration fees for the Integral-LIS Web Application: 50% within one week of the effective date of Serial 230142-RFP, and the remaining 50% will be invoiced when the application is deployed on the production server and available for use by County. • Installation fees for the Integral Spatial Package and the Integral BI – Reporting and Dashboard: 50% within one week of the effective date of Serial 230142-RFP, and the remaining 50% will be invoiced when the application is deployed on the production server and available for use by County. • Monthly/Yearly License Fees: Invoiced monthly in advance commencing on anniversary date of contract. Alternatively, license fees may be paid yearly in advance commencing on contract anniversary date at a discount of 1%, in which case Contractor will invoice County not less than forty-five (45) days prior to the commencement of each annual term. • Annual Maintenance Fees: Payable annually in advance, commencing on contract anniversary date. Contractor will invoice County not less than forty-five (45) days prior to the commencement of each annual term. • Training Fees and Expenses: Invoiced upon completion of the training services. • Professional Services: Invoiced monthly in arrears. SERIAL 230142-RFP 5. TERM These Terms will continue in effect for the term of Serial 230142-RFP. 6. RESERVED 7. RESERVED SERIAL 230142-RFP EXHIBIT D – OFFICE OF PROCUREMENT SERVICES CONTRACTOR TRAVEL AND PER DIEM POLICY 1.0 All contract-related travel plans and arrangements shall be prior-approved by the County contract administrator. 2.0 Lodging, per diem, and incidental expenses incurred in performance of Maricopa County/Special District (County) contracts shall be reimbursed based on current U.S. General Services Administration (GSA) domestic per diem rates for Phoenix, Arizona. Contractors must access the following internet site to determine rates (no exceptions): www.gsa.gov. 2.1 Additional incidental expenses (i.e., telephone, fax, internet, and copying charges) shall not be reimbursed. They should be included in the contractor’s hourly rate as an overhead charge. 2.2 The County will not (under any circumstances) reimburse for contractor guest lodging, per diem, or incidentals. 3.0 Commercial air travel shall be reimbursed as follows: 3.1 Coach airfare will be reimbursed by the County. Business class airfare may be allowed only when preapproved in writing by the County contract administrator as a result of the business needs of the County when there is no lower fare available. 3.2 The lowest direct flight airfare rate from the contractor’s assigned duty post (pre-defined at the time of contract signing) will be reimbursed. Under no circumstances will the County reimburse for airfares related to transportation to or from an alternate site. 3.3 The County will not (under any circumstances) reimburse for contractor guest commercial air travel. 4.0 Rental vehicles may only be used if such use would result in an overall reduction in the total cost of the trip, not for the personal convenience of the traveler. Multiple vehicles for the same set of travelers for the same travel period will not be permitted without prior written approval by the County contract administrator. 4.1 Purchase of comprehensive and collision liability insurance shall be at the expense of the contractor. The County will not reimburse a contractor if the contractor chooses to purchase this coverage. 4.2 Rental vehicles are restricted to sub-compact, compact, or mid-size sedans unless a larger vehicle is necessary for cost efficiency due to the number of travelers. (NOTE: Contractors shall obtain pre-approval in writing from the County contract administrator prior to rental of a larger vehicle.) 4.3 County will reimburse for parking expenses if free, public parking is not available within a reasonable distance of the place of County business. All opportunities must be exhausted prior to securing parking that incurs costs for the County. Opportunities to be reviewed are the DASH, shuttles, etc. that can transport the contractor to and from County buildings with minimal costs. 4.4 County will reimburse for the lowest rate, long-term, uncovered (covered or enclosed parking will not be reimbursed) airport parking only if it is less expensive than shuttle service to and from the airport. 4.5 The County will not (under any circumstances) reimburse the contractor for guest vehicle rental(s) or other any transportation costs. SERIAL 230142-RFP 5.0 Contractor is responsible for all costs not directly related to the travel except those that have been pre-approved by the County contract administrator. These costs include, but are not limited to, the following: in-room movies, valet service, valet parking, laundry service, costs associated with storing luggage at a hotel, fuel costs associated with non-County activities, tips that exceed the per diem allowance, health club fees, and entertainment costs. Claims for unauthorized travel expenses will not be honored and are not reimbursable. 6.0 Travel and per diem expenses shall be capped at 15 percent of project price unless otherwise specified and approved by the County in individual contracts. 7.0 Contractor shall provide, (upon request) with their invoice(s), copies of receipts supporting travel and per diem expenses, and, if applicable, with a copy of the written consent issued by the County contract administrator. No travel and per diem expenses shall be paid by County without copies of the written consent as described in this policy and copies of all receipts. SERIAL 230142-RFP ATTACHMENT E - REQUIREMENTS TRACEABILITY MATRIX 230142-RFP Exhibit E-REQUIREMENTS TRACEABILITY MATRIX Vendor Responses Requirement ID Requirement Category Requirement Sub- Category Requirement Description Mandatory, Preferred, Optional Module Please place an "X" in the applicable category below. Explanation Out of the Box With Configuration With Programming Future Release With Third Party Vendor Cannot Meet (e.g. what functionality is available out of the box; what configuration is needed to meet the requirement; what programming is needed to meet the requirement; or when and what functionality will be released to meet the requirement.) Security and Access Control (Users) SAC001 Security and Access Control (Users) User Accounts The application shall provide role-based security that allows the system administrator to add users to roles based on defined groups. Mandatory Administration X The Integral-LIS application includes role based security. View, edit, delete, and archive functions can be controlled for users and user groups. Role based security can also be setup for an organizations business units. SAC002 Security and Access Control (Users) User Accounts The application shall allow authorized users to manage group/role security that will apply to all users in a specific group/role. Mandatory Administration X Group security is included in our Administration package. SAC003 Security and Access Control (Users) User Accounts The system shall integrate with Active Directory for application user account creation. Mandatory Administration X The Integral-LIS application integrates with Active Directory to provide Single Sign-on capability. SAC004 Security and Access Control (Users) User Accounts The system shall deactivate an account based on the termination of an Active Directory Account. Mandatory Administration X With integration with Active Directory, a user is deactivated and cannot login is their Active Directory Account is terminated SERIAL 230142-RFP SAC005 Security and Access Control (Users) User Accounts The system should allow a user to be assigned to multiple security groups/roles. Mandatory Administration X Any number of groups can be setup for security purposes and a user can be added to one or more groups. SAC006 Security and Access Control (Users) User Accounts The system shall integrate with Active Directory for user account maintenance. Mandatory Administration X Our system integrates with Active Directory. SAC007 Security and Access Control (Users) User Accounts The system shall allow for the archival and removal of records that are past a retention period. Preferred Administration X The system has Archival capability. The administration can set the timeframe for deletion of archive records. Architecture and Integration Administration AAI001 Architecture and Integration Integration - API The vendor shall provide full documentation on all vendor supported APIs and interfaces. Mandatory Administration X Integral-LIS includes a Help system that provides full documentation of all the functionality of the system including the APIs. AAI002 Architecture and Integration Integration - API The system shall provide multiple APIs connections to be able to integrate with other systems. Mandatory Administration X As many API connections as needed can be established. AAI003 Architecture and Integration Integration - API The application shall provide integration with the County EDMS (OnBase) through API or other configurable framework. Mandatory Administration X Integral-LIS will seamlessly integrate with OnBase. AAI004 Architecture and Integration Integration The system should have the ability to link to reporting tools and dashboarding tools. (examples: Power BI/Tableau). Preferred Administration X Linking to third party reporting tools is done through our APIs. AAI005 Architecture and Integration Integration The application shall provide the ability to migrate existing verified data from existing sources (SQL, ESRI Geodatabases, Excel) Mandatory Administration X Migration is done in a number of ways. We have specialized spreadsheets that can be used for this purpose. There are APIs and we have tools for migration of ESRI geodatabases. SERIAL 230142-RFP AAI006 Architecture and Integration Integration The application shall provide integration capabilities with current (Bentley and Autodesk) and future Computed Aided Design and Drafting systems used by Real Estate Preferred Administration X This must be done through the Integral- LIS APIs. AAI007 Architecture and Integration Integration The application shall provide a configurable framework that provides the county the ability to import/export data with other county enterprise systems Preferred Administration X This can be done through the Integral- LIS APIs. AAI008 Architecture and Integration Integration The system should integrate with DocuSign to allow document routing for approvals Preferred Administration X Integral-LIS can be integrated with DocuSign. AAI009 Architecture and Integration Integration The application shall be compatible with ESRI ArcGIS and allow synching of records between the application and geodatabases Preferred Administration X Integral-Spatial has a connector for ESRI ArcGIS and it allows synhing of records between the integral- LIS database and geodatabases. This is done with Map and Feature Services published by ArcGiS Server. AAI010 Architecture and Integration Architecture The system shall have a multiple environment solution including production, test, dev, training. Mandatory Administration X ENKON typically with have development, quality assurance, user acceptance and production servers for any of our deployments. We have also setup training servers but often the UA server is used for this purpose. AAI011 Architecture and Integration Architecture The system testing environment shall allow for the testing of test scenarios, reconfigurations, new reports, hot fixes, patches, upgrades etc. Mandatory Administration X The testing environment is a complete duplicate of the Production system and any type of testing can be completed on this site. Vendor Architecture and Security Questions SERIAL 230142-RFP VQ001 Vendor Architecture and Security Questions Vendor Architecture and Security Questions The vendor shall provide a full data dictionary along with table descriptions and linkages, and Entity Relationship Diagram for each database (main system and data warehouse). Mandatory X ENKON will provide this information provided a NDA is signed by both parties. VQ002 Vendor Architecture and Security Questions Vendor Architecture and Security Questions The vendor shall provide the county with their redundancy capabilities for the system. Mandatory X ENKON can provide a number of options for redundancy from warm sites to hot sites. Pricing is different for each scenario. VQ003 Vendor Architecture and Security Questions Vendor Architecture and Security Questions The system application server should be a Windows based solution. Preferred X The application is Windows based. VQ004 Vendor Architecture and Security Questions Vendor Architecture and Security Questions The system should be a SQL server based solution. Preferred X The database is Microsoft SQL Server 2019 or higher. VQ005 Vendor Architecture and Security Questions Vendor Architecture and Security Questions The vendor shall reveal during the RFP process if they are a single-tenant or multi-tenant architecture/infrastructure. Mandatory X Our systems are single tenant. We give each client three VMs: a web server; a database server and a map server. VQ006 Vendor Architecture and Security Questions Vendor Architecture and Security Questions The vendor shall reveal during the RFP process their service level agreement. (e.g. outages, incidents, customer service, updates, etc.) Mandatory X The County and ENKON will need to sign a subscription agreement. This agreement defines our SLAs and penalities. VQ007 Vendor Architecture and Security Questions Vendor Architecture and Security Questions The system shall be single sign on (SSO) ready or compatible with multifactor identification and the vendor shall describe this functionality during the RFP process. Mandatory X The system is single sign on ready. We have done Active Directory and federated services such as OKTA as examples. VQ008 Vendor Architecture and Security Questions Vendor Architecture and Security Questions The vendor shall reveal during the RFP process what enhancements they have planned for the future (i.e. additional functionality, features, etc. ). Mandatory X ENKON has a very clear development plan that is shared with our clients. This plan can be provided to the County. VQ009 Vendor Architecture and Security Questions Vendor Architecture and Security Questions The vendor shall reveal during the RFP process how closely customer feedback is considered in their upgrade/enhancement plans. Mandatory X ENKON holds roadmap sessions with our client about each 6 months. The items that were brough forward from the previous session is reviewed in the current session. SERIAL 230142-RFP VQ010 Vendor Architecture and Security Questions Vendor Architecture and Security Questions The vendor shall reveal during the RFP process if the support SLA, what the hours of operation are, qualifications of support staff and escalation procedures are? Mandatory X Our Help desk process is briefly discussed in the proposal. A detailed description of our system can be provided at any time. VQ011 Vendor Architecture and Security Questions Vendor Architecture and Security Questions The vendor shall reveal if their system website is ADA compliant, WCAG compliant A and AA. Mandatory X The Integral-LIS application has been reviewed and WCAG compliant except for a few components of our system. VQ012 Vendor Architecture and Security Questions Vendor Architecture and Security Questions The vendor shall reveal during the RFP process the licensing model for the system. Mandatory X Licensing is by packages/modules selected and the number of named users. VQ013 Vendor Architecture and Security Questions Vendor Architecture and Security Questions The vendor shall reveal during the RFP process how change requests are handled after implementation, their time period and costs. Mandatory X ENKON has a well defined Change Management process. Requirements are gathered from the client and a pricing proposal is given to be approved before any work is completed. VQ014 Vendor Architecture and Security Questions Vendor Architecture and Security Questions The vendor shall reveal during the RFP process how long their warranty period is after implementation. Mandatory X ENKON has a HyperCare program for 30 days after deployment and regular care after that period. We wll provide a full description of our care program upon request. VQ015 Vendor Architecture and Security Questions Vendor Architecture and Security Questions The vendor shall reveal during the RFP process the desktop software requirements and browser requirements. Mandatory X Chrome and Edge are the preferred browsers and any operating system using these browsers. Vendor Architecture and Security Questions - Hosted Option VQ001 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process their data center certifications: FEDRAMP, SOX, SAS-70, SSAE-16 certified Mandatory X ENKON is SOC 2 Type 2 certified. SERIAL 230142-RFP VQ002 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process their firewall and web access firewall (WAF) protection and describe their layered security. Mandatory X ENKON utilizes Sophos XGS firewalls deployed in Active/Passive pairs in each data ceter. Theses firewalls include the IDS/IPS and WAF modules. These firewalls prodide the first layer of defense between the internet and the servers which host the Integral-LIS applications we have deployed for our clients. Web servers are deployed in a DMZ with the supporting infrastructure being deployed in and Internal network zoned. The firewalls restrict traffic initiated from the Internet to the DMZ and these systems in the DMZ will connect to the internal infrastructure through the firewall. Each Integral-LIS system is isolated to a sperate VLAN dedicated to the client it is hosted for. Access to client data is restricted the Integral-LIS system for that client and an internet maintenance network for the purpose of data management and backup. VQ003 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process how they defend against security breaches and issues such as SQL injections, cross-site- scripting, man-in-the- middle attacks, brute force attacks, etc.. Mandatory X ENKON utilizes a combination of the IDS/IPS and WAF functionallity of the firewalls along with running regular vulnerability scanning and annual penetration testing. ENKON's technical staff are trained on secure coding and address any issue found in penetration testing into Intergal_LIS in a timely fashion. SERIAL 230142-RFP VQ004 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process how their defense against security breaches is maintained. Mandatory X ENKON maintains their defense against security breaches by monitoring the logs of the IDS/IPS and WAF systems as well as regular reports to management of the status of those reports as well as the results of Vulnerability scanning. ENKON technical staff monitor a variety of sources that report newly discovered vulnerabilities. ENKON regularly patches operating systems and applications to address vulnerabilities that have been discovered and remediated. VQ005 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process how they monitor for security breaches. Mandatory X ENKON utilizes a combination of manual log review and automated systems to scan logs for anomalies. VQ006 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process their connection security parameters (SSL, AES, hash and other algorithms used to protect data transmissions). Mandatory X ENKON uses the results of their vulnerability and ventration testing results as will as reported vulnerabilities to inform configuration of appropriate TLS versions to have enalbed and the allowed HASH algorithms. VQ007 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process how they handle network intrusion protection (DDOS, Brute Force, Port Scanning, Switch Router Attacks etc.) Mandatory X ENKON utilizes Sophos XGS firewalls which include network intrusion prevention. SERIAL 230142-RFP VQ008 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process how they handle software updates, network patches, hotfixes, rollups and other updates. Mandatory X ENKON IT staff monthly review updates and patched released to evaluate the effect on systems hosted for clients. After they have been applied in a testing environment without issue they are then applied to production during the next maintenance window. If the patch is deemed to be of a more urgent nature during the review then ENKON will schedule an emergency outage to have the patch applied as soon as it has been tested. Non critical patches and updates are reviewed for impact and effect on supportability to ensure the stability and maintainability of the system. VQ009 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process how they protect their personnel, clientele and system environment from viral attacks, malware and phishing. Mandatory X ENKON utilizes Trend Micro AV solutions installed on all server and workstations. The Sophos firewalls also provide malware scanning functionallity. ENKON's email is delivered though Office365 and using Microsofts anti malware and anti- phishing filters. Staff are also trained in recognizing phishing email using KnowBe4's phishing simulation training. SERIAL 230142-RFP VQ010 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process how the data is staged at their colocations. Mandatory X When ENKON is initially importing client data into their Integral-LIS system it will be imported into a dedicated SQL instance in the UA environment and made available for client acceptance. After the Integral-LIS system is deployed dta is directly entered into the application via user input or API integration. VQ011 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process how their data is encrypted (in-transit and/or at rest). Mandatory X Integral-LIS encrypts data in transit via TLS and data at rest is stored on an encrypted SAN volume. VQ012 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process how much data storage is available through the host, how much is included in the system fees, and how much per GB is extra space. Mandatory X ENKON allows up to 2 terabytes of storage in our current fee structure. If additional storage is needed ENKON will provide pricing on a per terrabyte basis. VQ013 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process their data portability options and availability. Mandatory X All data is owned by the client at all times. This data can be exported from the system through the reporting system or through the APIs. VQ014 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process their data backup and data recovery procedures and options. Mandatory X ENKON Logships the SQL data to the secondary data center every 30 minutes and performs a full backup of the database each evening. The virtual machines which contain the Intergal_LIS system are backed up each evening. Backups are copied offsite and written to tapes which are sent offsite twice a week. These tapes are vaulted for 6 months and yearly archives of the tape backups are vaulted for 5 years. In the event of data loss ENKON staff can SERIAL 230142-RFP recall the tapes and restore the affected data. VQ015 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process the data backup frequency and if any additional costs are charged for data backups. Mandatory X ENKON Logships the SQL data to the secondary data center every 15 minutes and performs a full backup of the database each evening. The virtual machines which contain the Intergal_LIS system are backed up each evening. This is part of the standard maintenance and is performed at no additional charge. VQ016 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process if they do offsite backups of the system and data. Mandatory X ENKON Logships the SQL data to the secondary data center every 15 minutes. SQL amd VM backups copied off-site and written to tapes that are vaulted for 6 months. Yearly archives of the tape backups are vaulted for 5 years. VQ017 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process the system login credential security and expiry Mandatory X The Integral-LIS login credential policy is maintained by designated systems administrators at the client organization. VQ018 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process what their uptime is for the system. Mandatory X 99.90% VQ019 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall allow the county to retrieve their data from the system at any time without a fee. Mandatory X This can be done through the Reporting system or through the APIs. VQ020 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP who maintains system data for legal or compliance purposes. Mandatory X The data in the system is always owned by the client. SERIAL 230142-RFP VQ021 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process what type of remote connections are available to their cloud resources. Mandatory X ENKON has remote access via VPN to the resources they maintain at their data centers. The only other access to the resources would be to the application and its API via HTTPS. VQ022 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process who does updates, hotfixes, security patches and when they are done. Mandatory X ENKON has remote access via VPN to the resources they maintain at their data centers. The only other access to the resources would be to the application and its API via HTTPS. VQ023 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process how notifications for updates, hotfixes, and security patches are given and the timeframe they are given prior to releasing the fix. Mandatory X ENKON maintains the application and applies update, hotfixes and security patches to it as scheduled with the client. VQ024 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process how outage notifications are given to the county and whether or not they have an system status site for outage alerts or downtime. Mandatory X Planned system outages are arranged with the client's Integral-LIS administrator. The Integral-LIS system is monitored for availability with an anomalies reported to ENKON IT staff. Any incidents that would affect availability of the system would be reported to the project manager for the client at ENKON who would communicate the outage and planned resolution with the client's administrator for Integral-LIS. There is no system status page. VQ025 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process the connectivity options for the system and associated redundant paths. Mandatory X The Integral-LIS application is available at the primary URL and if a warm site is required it would be available at a secondary URL. SERIAL 230142-RFP VQ026 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal what the storage limit is for the system and if additional storage is necessary how much it will cost. Mandatory X Two Terabytes is included in the pricing. Each terabyte after that is $100 per month. VQ027 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal if there is a guaranteed uptime for the system, what that guaranteed uptime is and what happens if the guaranteed uptime is not maintained. Mandatory X ENKON will enter into a Subscription Agreement with Maricopa County. This document provides the SLAs and penalities and will be provided upon request. VQ028 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall provide during the RFP process the latest copy of their SOC 2 report for their own infrastructure system. Mandatory X This will be provided if ENKON is selected. VQ029 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process how they do vulnerability testing of the system and how often. Mandatory X ENKON utilizes Qualysguard to scan for vulnerabilities weekly. Reports from these scan are reviewed with IT management, their risk is ranked and appropriate mitigation actions are performed. VQ030 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process how they conduct system penetration testing and how often. Mandatory X ENKON uses third party companies with expertise in penetration testing to undertake our tests VQ031 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process if uptime/outage alerting is available, if they have a status page, rss feeds, email alerts etc. Mandatory X ENKON monitors the uptime of all of systems throughout monitoring software. This has email alerts and much more. Reports can be provided to the County on a specific schedule if required. VQ032 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process if their data centers are owned and maintained by their company or if they are a tenant. Mandatory X ENKON leases space from Data Centers. ENKON owns all the racks, servers and supporting equipment used in the data center. SERIAL 230142-RFP VQ033 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall provide during the RFP process the geographical location of their data centers. Mandatory X Our Data Centers are located in Seattle Washington and Kelwna BC. VQ034 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process their fail over capacity (active/passive, load- balanced etc.) and the time to fail over and back Mandatory X Our failover is to a second data center and can be set as active or passive depending on client requirement. The costs are different for each option. VQ035 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal what their anticipated maintenance windows are and the frequency. Mandatory X We request a monthly maintenance window, usually a few hours on Saturday evening. SERIAL 230142-RFP VQ036 Vendor Architecture and Security Questions Vendor Architecture and Security Questions - Hosted Option The vendor shall reveal during the RFP process how communication is handled if a system breach occurs (i.e. who do they notify, timeframe people are notified etc.). Mandatory X If a system breach were to occur ENKON staff being notified of the breach would follow the Incident Response procedure which can be summarized as: Classify incident based on business impact; Low, Medium, or High per the Risk Management Plan document found in the Appendices section of this manual. If staff reported the violation, acknowledge the receipt of the issue. On Medium or High impact incidents, immediately inform the President, Controller, and Professional Services manager. Contain the incident dangers/ramifications as tightly as possible to prevent an expanding problem. Take corrective action to mitigate damages. This can also include staff training. Recover system to original and functional state. On the Medium or High impact incidents, inform the President, Controller, and Professional Services manager of the status of the incident and its resolution. Follow up on the problem resolution, forensic services, and lessons learned and report on those findings in the weekly IT meeting. Interfaces and Reporting X SERIAL 230142-RFP INT1 GIS & Mapping General The application shall integrate with ESRI ArcGIS Mandatory X Integral-Spatial includes a connector to ArcGIS Server. Any maps published on ArcGIS Server can be shown in our Map Viewer. INT2 GIS & Mapping General The application shall allow synching of records between the application and ESRI geodatabase Preferred X Integral-Spatial allows pushing and pulling data from ESRI geobases using the Feature Service of ArcGIS Server. INT3 Document Attachments General The application shall allow for integration with the County EDMS (OnBase) for Document Attachments Mandatory X Integral-LIS can seamlessly be integrated with OnBase. We are currently working on this integration for another client. INT4 Document Attachments Submit and Retrieve The application shall provide the ability to submit/store documents using appropriate document types and keywords in OnBase either through configurable API or through available OnBase API. Mandatory X Submitting of documents through the Integral-LIS OnBase will be possible including the document type and keywords. The communication between the two systems will be a web service. INT5 Document Attachments Submit and Retrieve The application shall provide the ability to retrieve documents in OnBase through configurable API or through OnBase APIs or configurable URLS. Preferred X A web service will be used to communicate between Integral-LIS and OnBase. The web service will be using both Integral- LIS's and OnBase's APIs. INT6 Document Attachments Keywords The application shall allow for OnBase keyword updates when necessary Preferred X We believe that this will be possible. INT7 Document Attachments Document Retention The application shall allow for record retention that is in coordination with documents stored in OnBase based on Document Type and Arizona State Library, Archives, & Public Records Retention Schedules. Mandatory X The Integral-LIS allows an administrator to set an record retention policy. SERIAL 230142-RFP INT8 Reporting General The application shall provide a number of pre- designed reports that are accessible to users based on security role and area of responsibility. Preferred X Integral-LIS comes with over 50 pre- designed reports. When running these reports security is applied so only data that a users is authorized to see will be available in the report. INT9 Reporting General The application shall provide the ability for authorized users to created save reports within the application Mandatory X Integral-BI includes a Report Designer that allows a user to create ad-hoc reports and save these reports as templates so they can be used at any time. INT10 Reporting General The application shall allow authorized admin level users the ability to upload customized SSRS reports and make them available as part of the application reports. Preferred X These reports should be able to be uploaded into the system but ENKON will need to review the content of the report. INT11 Reporting Acquisitions The application shall allow authorized users to create and run offer letters for acquisitions based on pre-defined templates. Preferred X Pre-defined reports such as Offer Letters are designed in our Report Designer and saved as templates. INT12 Reporting Acquisitions The application shall allow authorized users to run budget, offer amounts and actual expenditure reports for acquisitions related to a project to include high level amounts and parcel specific details. Preferred X Such reports are designed in the Report Designer. Any field from any form can be included on the report. This can link agreement data to parcel specific details for example. INT13 Reporting Excess Land Sales The application shall allow authorized users to generate excess land sales auction packets. Preferred X Such Auction packets could be created by the County in the Report Designer or initially ENKON could create these packets. INT14 Reporting Other Agreements The application shall allow authorized users to print agreements created for IGA's, MOU/MOA. Preferred X Any report can be printed from the Integral-LIS application. SERIAL 230142-RFP ATTACHMENT G – IT SUPPLEMENT TERMS AND CONDITIONS INFORMATION TECHNOLOGY SUPPLEMENTAL TERMS AND CONDITIONS 1. DEFINITIONS 1.1. “Authorized Persons” means the service provider’s employees, contractors, subcontractors or other agents who need to access the County’s personal data to enable the service provider to perform the services required. 1.2. “Data Breach” means the unauthorized access by a non-authorized person/s that results in the use, disclosure or theft of a County’s unencrypted personal data. 1.3. “Individually Identifiable Health Information” means information that is a subset of health information, including demographic information collected from an individual, and (1) is created or received by a health care provider, health plan, employer or health care clearinghouse; and (2) relates to the past, present or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present or future payment for the provision of health care to an individual; and (a) that identifies the individual; or (b) with respect to which there is a reasonable basis to believe the information can be used to identify the individual.12 1.4. “Non-Public Data” means data, other than personal data, that is not subject to distribution to the public as public information. It is deemed to be sensitive and confidential by the County because it contains information that is exempt by statute, ordinance or administrative rule from access by the general public as public information. 1.5. “Personal Data” means data that includes information relating to a person that identifies the person by name and has any of the following personally identifiable information (PII): government-issued identification numbers (e.g., Social Security, driver’s license, passport); financial account information, including account number, credit or debit card numbers; or protected health information (PHI) relating to a person. 1.6. “Protected Health Information” (PHI) means individually identifiable health information transmitted by electronic media, maintained in electronic media, or transmitted or maintained in any other form or medium. PHI excludes education records covered by the Family Educational Rights and Privacy Act (FERPA), as amended, 20 U.S.C. 1232g, records described at 20 U.S.C. 1232g(a)(4)(B)(iv) and employment records held by a covered entity in its role as employer.13 1.7. “Public Jurisdiction” means any government or government agency that uses these terms and conditions. The term is a placeholder for the government or government agency. 1.8. “County Data” means all data created or in any way originating with the County, and all data that is the output of computer processing of or other electronic manipulation of any data that was created by or in any way originated with the County, whether such data or output is stored on the County’s hardware, the service provider’s hardware or exists in any system owned, maintained or otherwise controlled by the County or by the service provider. 1.9. “County Identified I.T. Security Contact” means the person or persons designated in writing by the County to receive security incident or breach notification. SERIAL 230142-RFP 1.10. “Security Incident” means the potentially unauthorized access by non-authorized persons to personal data or non-public data the service provider believes could reasonably result in the use, disclosure or theft of a County’s unencrypted personal data or non-public data within the possession or control of the service provider. A security incident may or may not turn into a data breach. 1.11. “Service Level Agreement” (SLA) means that part of the written agreement between both the County and the service provider that is subject to the terms and conditions in this document and that unless otherwise agreed to includes (1) the technical service level performance promises, (i.e. metrics for performance and intervals for measure), (2) the amount of time required for notice by the provider to the County for notification of upcoming changes, (3) security notice requirements, (4) timeframes for response to operational problems and failures, and (5) any remedies for performance failures. 1.12. “Service Provider” means the contractor and its employees, subcontractors, agents and affiliates who are providing the services agreed to under the contract. 1.13. “Software-as-a-Service” (SaaS) means the capability provided to the consumer to use the provider’s applications running on a cloud infrastructure. The applications are accessible from various client devices through a thin-client interface such as a Web browser (e.g., Web-based email) or a program interface. The consumer does not manage or control the underlying cloud infrastructure including network, servers, operating systems, storage or even individual application capabilities, with the possible exception of limited user specific application configuration settings. 1.14. “Statement of Work/Scope of Work” means a written statement in a solicitation document or contract that describes the County’s service needs and expectations. 2. SUPPORT OVERVIEW 2.1. Support hours (accommodate our time zone) - vendor will maintain customer service hours that coincide with our 8AM- 5PM M-Fri (MST) office schedule. They will also provide afterhours support at a level commensurate with the nature of the service provided. 2.2. Updates/upgrades - vendor will follow a timely and consistent schedule in applying updates to their solution and the underlying infrastructure needed to support it. Zero day/emergency updates will be done expeditiously by vendor, with proper communication to customers affected 2.3. Entity will comply with all applicable provisions of the Americans with Disabilities Act, the Rehabilitation Act of 1973, and all applicable federal regulations, as amended from time to time (ADA Laws). All electronic and information technology and products and services to be used must be compliant with the ADA Laws. 2.3.1. Compliance means that a disabled person can acquire the same information, engage in the same interactions, and enjoy the same services as a nondisabled person, in an equally effective and integrated manner, with substantially equivalent ease of use. 3. DATA OVERVIEW: 3.1. Data liberation - vendor is required to provide the means to pull all user data from vendor solution any time as desired, in a machine-readable format. 3.2. System shall be capable of encrypting data both at rest and in transit as needed/determined by the customer. 3.3. Data Ownership: The County will own all right, title and interest in its data that is related to the services provided by this contract. The service provider shall not access County user accounts or County data, except (1) in the course of data center operations, (2) in response to service or technical issues, (3) as required by the express terms of this contract or (4) at the County’s written request. SERIAL 230142-RFP 3.4. Data Protection: Protection of personal privacy and data shall be an integral part of the business activities of the service provider to ensure there is no inappropriate or unauthorized use of County information at any time. To this end, the service provider shall safeguard the confidentiality, integrity and availability of County information and comply with the following conditions: 3.4.1. The service provider shall implement and maintain appropriate administrative, technical and organizational security measures to safeguard against unauthorized access, disclosure or theft of personal data and non-public data. Such security measures shall be in accordance with recognized industry practice and not less stringent than the measures the service provider applies to its own personal data and non-public data of similar kind. 3.4.2. All data obtained by the service provider in the performance of this contract shall become and remain the property of the County. Vendor usage of customer data for non-County purposes requires written approval from the County. 3.4.3. All personal data shall be encrypted at rest and in transit with controlled access. The County shall identify data it deems as non-public data to the service provider. The level of protection and encryption for all non-public data shall be identified and made a part of this contract. Any stipulation of responsibilities will identify specific roles and responsibilities and shall be included in the statement of work (SOW), or otherwise made a part of this contract. 3.5. At no time shall any data or processes — that either belong to or are intended for the use of a County or its officers, agents or employees — be copied, disclosed or retained by the service provider or any party related to the service provider for subsequent use in any transaction that does not include the County. 3.6. Hosted applications must have the ability to support encrypted protocols for sensitive data in flight and in rest. Encryption ciphers must use at least a 128-bit key length. Hashing algorithms used must be of the Secure Hash Algorithm (SHA) or Advanced Encryption Standard (AES) family. The minimum acceptable algorithm shall be SHA-2 or AES128. 3.7. Data Location: The service provider shall provide its services to the County and its end users solely from data centers in the U.S. Storage of County data at rest shall be located solely in data centers in the U.S. The service provider shall not allow its personnel or contractors to store County data on portable devices, including personal computers, except for devices that are used and kept only at its U.S. data centers. The service provider shall permit its personnel and contractors to access County data remotely only as required to provide technical support. The service provider may provide technical user support on a 24/7 basis using a Follow the Sun model, unless otherwise prohibited in the SLA. 3.8. The vendor shall destroy all offline copies of County data at the time they cease to be useful. Destruction procedures must be made available to the County upon request. 3.9. At the conclusion of the contract, all County data and working papers must be returned to the County and all vendor copies destroyed. The vendor must confirm in writing to the County that all data was destroyed in accordance with this agreement and state the methodology used. 4. BACKUP AND DISASTER RECOVERY OVERVIEW 4.1. County has the right to, with 72 hours’ notice, request a test of customer-centric backup and Disaster Recovery functionality, as defined in the contract. 4.2. Backups to removable media must be encrypted using the Advanced Encryption Standard (AES) with a minimum of a 128-bit key. Industry recognized key handling procedures must be utilized. At no time shall the key be stored on the backup media in clear text, including but not SERIAL 230142-RFP limited to table labels. The vendor must make key handling procedures and logs available upon request. 5. Unless otherwise stated, hosting providers will complete incremental backups daily and be able to successfully generate full backups within 24 hours unless otherwise agreed upon. 6. INTEGRATION AND INTERFACES OVERVIEW 6.1. All customer integrations and interfaces are fully documented and updated when changes are made by vendor at no cost to the County. 7. TESTING OVERVIEW: 7.1. A documented strategy for testing and QA of development and configuration shall be provided to the Maricopa County project team for approval prior to commencement of system build upon request. 7.2. Issues identified in vendor testing shall be cataloged, updated upon closure with final disposition, and provided to the project team prior to UAT testing. 7.3. Vendor will allow Maricopa County a reasonable timeframe to execute the test plan and retest items with issues. 7.4. Vendor will work directly with Maricopa County, and external vendors to integration test all interfaces and transmissions of data. To eliminate constraints and delays in external vendor testing and validation, a separate mirror environment for testing is advised. 7.5. Vendor will enable automation and file transmission during UAT and parallel testing. 7.6. Vendor will allow Maricopa County to execute performance and load testing as prior to the start of UAT. 7.7. The Vendor shall provide County with a UAT test catalog to aid in development of test scripts. 7.8. Testing variances will be documented, categorized, and assigned priority through a mutually agreed upon format. 7.9. Unit testing of the application shall be performed and documented by the vendor. 7.10. Vendor will provide documented results of testing including negative and positive testing results. 8. CONNECTIVITY OVERVIEW: 8.1. Vendor will proactively communicate any proposed networking change made against connections between vendor and County a minimum of 5 business days prior to the change. 8.2. Client applications installed on user workstations that must contact the off-site hosting environment must be able to do so through a secured HTTP proxy. Workstations must not be required to directly connect over the Internet for any reason. 8.3. Any connection between the County and vendor needs to be secured using industry accepted standards. 9. SYSTEM SECURITY OVERVIEW: 9.1. Security Incident or Breach Notification and Responsibilities: The service provider shall inform the County of any security incident or data breach. SERIAL 230142-RFP 9.2. Breach notification requirements shall be determined by all applicable laws and contracts including, but not limited to, Arizona Revised Statutes 44-7501 and 18-552, California SB 1386, the Health Insurance Portability and Accountability Act (HIPAA), Criminal Justice Information Services (CJIS) and Payment Card Industry (PCI). 9.3. Incident Response: The service provider may need to communicate with outside parties regarding a security incident, which may include contacting law enforcement, fielding media inquiries and seeking external expertise as mutually agreed upon, defined by law or contained in the contract. Discussing security incidents with the County should be handled on an urgent as-needed basis, as part of service provider communication and mitigation processes as mutually agreed upon, defined by law or contained in the contract. 9.4. Unless otherwise stipulated, if a data breach is a direct result of the service provider’s breach of its contract obligation to encrypt personal data or otherwise prevent its release, the service provider shall bear the costs associated with the following: 9.4.1. the investigation and resolution of the data breach; 9.4.2. notifications to individuals, regulators or others required by state law; 9.4.3. a credit monitoring service required by state (or federal) law; 9.4.4. a website or a toll-free number and call center for affected individuals required by state law — all not to exceed the average per record per person cost calculated for data breaches in the United States in the most recent Cost of Data Breach Study: Global Analysis published by the Ponemon Institute at the time of the data breach; and 9.4.5. complete all corrective actions as reasonably determined by service provider based on root cause; all [(1) through (5)] subject to this contract’s limitation of liability. 9.5. Breach Reporting Requirements: If the service provider has actual knowledge of a confirmed data breach that affects the security of any County content that is subject to applicable data breach notification law, the service provider shall 9.5.1. promptly notify the appropriate County identified contact within 24 hours or sooner, unless shorter time is required by applicable law, and 9.5.2. take commercially reasonable measures to address the data breach in a timely manner. 9.6. The vendor shall make the information security incident response policy and procedure available to the County at any time upon request. 9.7. Access to Security Logs and Reports: The service provider shall provide reports to the County in a format as specified in the SLA agreed to by both the service provider and the County. Reports shall include latency statistics, user access, user access IP address, user access history and security logs for all County files related to this contract. County may, at their discretion, use separate SIEM tool to analyze and manage provided log and report data. 10. AUDITING AND COMPLIANCE OVERVIEW 10.1. The system must log all material user actions, including but not limited to, logon and log off. 10.2. The system must log all material administrator actions, including but not limited to, user creation, user deleting, password resets, and privilege level changes. 10.3. The system must log failed login attempts. SERIAL 230142-RFP 10.4. Logs must be made available to the County at any time, preferably though API, web service or some other automated fashion 10.5. The vendor must comply with all applicable laws, regulations, and contracts including (but not limited to) Criminal Justice Information Services (CJIS), Health Insurance Portability and Accountability Act, and Payment Card Industry (PCI). 10.6. Vendors that host applications containing HIPAA protected data must enter into a Business Associate agreement (as defined by HIPPA) with the County. The Business Associate agreement must be maintained for the life of the contract. 10.7. Audit of 3rd Party systems - in order to determine that SLAs or other agreements between Maricopa County and the 3rd party entity are being adhered to, we reserve the right to audit systems being used to provide the service and supporting services (such as internal work order/ITSM systems, log files, etc.) used to support the services being provide to the county. 10.8. The vendor must make SOC2 compliance reports, or other comparable security report, audit findings, and third-party attestations available at the time of award, and at any time to the County upon request. Updated compliance reports shall be provided to the County Identified I.T. Security Contact annually. 10.9. For SOC 2 reports, this must be of the solution and not of the hosting service the vendor may be using (i.e., do not share Amazon’s or Microsoft’s SOC2 report instead of one specific to the solution in question). 10.10. The vendor must immediately notify the County, in writing, upon a confirmed violation of the compliance requirement. The notification must include any information provided by the regulatory body. SERIAL 230142-RFP ENKON INFORMATION SYSTEMS, 1700 WESTLAKE AVE. N. SUITE 200, SEATTLE, WA 98109 PRICING SHEET: NIGP CODE 20876 Terms: NET 30 DAYS Vendor Number VS0000009781 Certificates of Insurance Required Contract Period: To cover the period ending June 30, 2029.