Miss. Admin. Code Title 36 — Technology

title-36Miss. Admin. Code tit. 36Regulation

CYBER SECURITY REVIEW BOARD CYBER SECURITY REVIEW BOARD

Part 301 General Provisions

36 Miss. Admin. Code Pt. 301 General Provisions

1

Title 36: Technology: Cyber Security Review Board Part 301: General Provisions Chapter 1: Purpose and Applicability and Relation to Other Law Rule 1.1. History and Purpose. Per 2024 Regular Session Mississippi Senate Bill 2698 (Mississippi Code Sections 25-53-231, et seq.) the "Cyber Security Review Board" (“CSRB”) shall be responsible for ensuring a collaborative effort is made to address the cybersecurity threat posed to the State of Mississippi. Responsibilities of the board include creating a system of reporting cybersecurity attacks within the state, researching and implementing best practices to mitigate cybersecurity risks, and connecting individuals and entities with federal and industry partners.

Source: Miss. Code Ann. § 25-53-231, et seq.

Rule 1.2. Statutory Conflict. Specific statutory provisions which govern CSRB’s rules or related proceedings which conflict with any of these rules shall remain in full force and effect, only to the extent of such conflict.

Source: Miss. Code Ann. § 25-53-231, et seq.

Rule 1.3. Conflict of Law. These rules and the statutes from which they are promulgated shall not be construed to amend, repeal, or supersede the provisions of any other law; and, to the extent that the provisions of any other law conflict or are inconsistent with the provisions of these rules and the statutes from which they are promulgated, the provisions of such other law shall govern and control.

Source: Miss. Code Ann. § 25-53-231, et seq.

Rule 1.4. Effect. These rules and the statutes from which they are promulgated do not relieve an agency or individual from compliance with any provision of law.

Source: Miss. Code Ann. § 25-53-231, et seq. Chapter 2: Officers and Personnel Rule 2.1. Chairperson. The Executive Director of the Mississippi Office of Homeland Security, or his or her designee will be designated as Chairperson. The Chairperson shall preside at all meetings of the CSRB; co-sign all contracts, deeds and other instruments made by the CSRB when required by federal or state regulations; and perform all duties incident to the office of Chairperson and such other duties as may be prescribed by the CSRB from time to time. Source: Miss. Code Ann. §§ 25-53-233, 25-53-235, 25-53-237. Rule 2.2. Vice Chairperson. The Executive Director of the Mississippi Department of Information Technology Services, or his or her designee will be designated as the Vice Chairperson. The Vice

2

Chairperson shall perform the duties of the Chairperson in the absence, incapacity, or inability of the Chairperson to act.

Source: Miss. Code Ann. §§ 25-53-233, 25-53-235, 25-53-237.

Rule 2.3. Secretary. The Mississippi Cyber Initiative Program Manager, or his or her designee will serve as Secretary. The Secretary shall prepare and provide the agenda for meetings of the CSRB and shall prepare the minutes of the CSRB in accordance with state law.

Source: Miss. Code Ann. §§ 25-53-235, 25-53-237.

Rule 2.4. Board Members.

  1. The Commissioner of the DPS, or designee,
  2. The Executive Director of the MEMA, or designee,
  3. The Adjutant General of the MSNG, or designee
  4. The State Superintendent of Education, or designee, and
  5. The Attorney General of Mississippi, or designee.

Source: Miss. Code Ann. § 25-53-233, 25-53-237.

Rule 2.5. Ex Officio Nonvoting Members.

  1. The President of the Mississippi Municipal League, or designee,
  2. The Executive Director of the Mississippi Association of Supervisors staff, or

designee,

g. The Chairmen of the Technology Committee of the Mississippi Senate, or designee,

h. The Chairmen of the Technology Committee of the Mississippi House of

Representatives, or designee, and

i. The Mississippi Cyber Initiative Program Manager, or designee.

Source: Miss. Code Ann. § 25-53-235, 25-53-237.

Chapter 3: Meetings

Rule 3.1. Regular Meetings. Regular meetings shall be conducted on the first Thursday of each month beginning at 9:30 a.m., or at such day and time as may be selected and announced in advance by the Chairperson as required by state law and shall be held at the Mississippi Office of Homeland Security, or such other location as may be selected and announced in advance by the Chairperson. Public notice shall be provided for each meeting as required by state law and the meeting shall be open to the public. Any member of the CSRB may participate in an official meeting by teleconference or videoconference means.

Source: Miss. Code Ann. §§ 25-53-237, 25-41-1, 25-41-3, 25-41-5, 25-41-13.

3

Rule 3.2. Agenda. A CSRB member may request that any item which the member desires to be considered by the full CSRB be placed on the agenda. All other requests for items to be placed on the agenda shall be submitted in writing to the Secretary/Chairperson, with sufficient detail to explain the nature of the request and be received no less than ten (“10”) calendar days prior to the scheduled monthly meeting.

The Secretary/Chairperson of the CSRB shall provide the proposed agenda to each CSRB member not later than seven (“7”) calendar days prior to a regularly scheduled meeting.

Source: Miss. Code Ann. § 25-41-5, 25-53-237.

Rule 3.3. Executive Session. The CSRB may enter executive session for the transaction of public business; however, an executive session shall be limited to matters exempted from open meetings as provided in Miss. Code Ann. § 25-41-7 and shall follow the procedure required in Miss. Code Ann. § 25-41-7.

The CSRB and the Chairperson shall designate who is permitted to remain in executive session.

Source: Miss. Code Ann. § 25-41-7, 25-53-237.

Rule 3.4. Quorum. A majority of the members of the CSRB shall constitute a quorum for the transaction of business, but a smaller number may recess from time to time until a quorum is obtained.

Source: Miss. Code Ann. § 25-53-237.

Rule 3.5. Voting. Voting on all matters shall be by voice vote or by roll call, and the ayes and nays shall be entered in the minutes of the meeting. All actions shall require a majority vote of the members present provided a quorum is present. The Chairperson will have a vote on any measure before the CSRB. The Chairperson may not make or second motions.

Source: Miss. Code Ann. §§ 25-53-233, 25-53-235, 25-53-237, 25-41-5.

Rule 3.6. Minutes. The minutes of the CSRB shall be kept in accordance with Miss. Code Ann. § 25-41-11. The minutes shall be prepared by the Secretary; however, the Secretary may secure such assistance as is necessary for the preparation of the minutes. All proposed minutes shall be provided with the agenda to each CSRB member within seven (“7”) calendar days prior to any CSRB meeting. All proposed minutes shall become the official minutes after adoption by the CSRB.

Source: Miss. Code Ann. §§ 25-53-237, 25-41-11.

4

Rule 3.7. Designee. If a member of the CSRB opts to send a designee in his/her place, in accordance with Miss. Code Ann. § 25-53-233, said member shall use the designee form to notify the Chairperson of his/her designee via his/her agency letterhead ten (“10”) days prior to the meeting. Such letter of designation shall remain on file and considered the official appointment of his/her designee as long as that board member remains a member of the CSRB.

Source: Miss. Code Ann. §§ 25-41-9, 25-53-233, 25-53-235, 25-53-237.

Rule 3.8. Rules and Order. The CSRB will adhere to parliamentary procedures for conducting business and will seek guidance from Robert's Rules of Order to the extent such procedures are not inconsistent with the CSRB Rules and Regulations, enabling statutes, or other Mississippi law.

Source: Miss. Code Ann. §§ 25-53-231, et seq.

Chapter 4: Public Records

Rule 4.1. Public Records. In accordance with Miss. Code Ann. § 25-61-3(b), Proposals, books, records, papers, or other documentary materials, regardless of physical form or characteristics, in use, prepared, possessed or retained by the CSRB for use in the conduct of its business are public records under Mississippi law and are subject to disclosure to any person making a request thereof, according to the procedures documented below.

Source: Miss. Code Ann. §§ 25-41-1, et seq., 25-53-231, et seq., 25-61-1, et seq.

Rule 4.2. Submission Requests. Any person wishing to request access to public records of the Mississippi Department of Public Safety, or seeking assistance in making such a request, must make the official request in writing by email, fax, or letter addressed to the Legal Division of the Mississippi Department of Public Safety:

Legal Division P.O. Box 958 Jackson, Mississippi 39205

Office: (601)-987-1332 Fax: (601) 987-1345 Email: records@dps.ms.gov

Information is also available at the Mississippi Department of Public Safety’s website (http://www.dps.ms.gov).

Source: Miss. Code Ann. §§ 25-41-1, et seq., 25-53-231, et seq., 25-61-1, et seq.

5

Rule 4.3. Contents of Request. Any person requesting to inspect, copy, mechanically reproduce or obtain a reproduction of public records of CSRB must include the following information:

  1. Name of requestor,
  2. Mailing address of requestor,
  3. Telephone number of requestor,
  4. Email address of requestor,
  5. Identification of the requested public records, by individual item or category with

reasonable particularity, sufficient particularity that the public records officer or

designee may locate the public records, and

f. Date of request.

Source: Miss. Code Ann. §§ 25-41-1, et seq., 25-53-231, et seq., 25-61-1, et seq.

Rule 4.4. Timetable for Processing. Within seven (7) Working Days of receipt of the request, the CSRB will do one or more of the following:

  1. Make the records available for inspection or copying.
  2. If Standard Documents are requested and full payment is received in accordance

with the attached Schedule of Fees, send the copies to the requestor.

c. Acknowledge the receipt of the Special Request and accompanying Special

Request fee of $60, and provide a reasonable estimate of the time and cost that will be

required to make the records available; for records that do not fall under the provisions

of Mississippi Code Annotated Section 25-61-9 regarding Third Party Information

notification requirements, the CSRB will provide a written explanation if the records

cannot be produced within the seven (“7”) Working Day period.

d. Provide notice of missing or incomplete payment to the requestor. Requests not

accompanied by the appropriate payment will be closed within ten (“10”) Working

Days of the date of the CSRB’s notification to the requestor, if payment is not received.

e. If the request is unclear or does not sufficiently identify the requested records,

request clarification from the requestor. Such clarification may be requested and

provided by telephone, with written follow-up. The CSRB may revise the estimate of

when records will be available.

f. Deny the request, with documentation to the requestor as to the reason for denial.

Source: Miss. Code Ann. §§ 25-41-1, et seq., 25-53-231, et seq., 25-61-1, et seq.

Rule 4.5. Third Party Information. The CSRB receives certain information from Third Parties that may be exempt from the Public Records Act and/or otherwise protected by disclosure by law. Records furnished to CSRB which may otherwise be protected from disclosure by law shall not be released until notice to the third party has been given in accordance with Miss. Code Ann. § 25- 61-9.

6

a.When the CSRB receives a request to release Third Party Information, the owner of this information is notified of the name and address of the party requesting the information and the nature of the information requested, starting the twenty-one (“21”) day period under Section 25-61-9. The requestor also receives a copy of this notification. b.The Third Party must provide the CSRB and/or its legal representation, through the Mississippi Attorney General’s Office, a copy of a court order or petition seeking a protective order within the twenty-one (“21”) day period under Section 25-61-9. Failure of the Third Party to timely comply with the requirements of Section 25-61-9 shall result in disclosure. Upon the filing of a petition and notifying CSRB as required under Section 25-61-9 do not negate the Third Party’s duty to comply with the applicable Mississippi Rules of Civil Procedure. c.If CSRB receives notice of an order or petition by the twenty-one (“21”) day deadline, the CSRB will notify the requestor that the information is protected and cannot be furnished until the legal proceedings have concluded. d.If CSRB is not notified of the applicable court order or petition for protective order prior to the expiration of the twenty-one (“21”) day period, then CSRB shall release all information, not protected, to the requestor once payment for the information has been received from the requestor.

Source: Miss. Code Ann. §§ 25-41-1, et seq., 25-53-231, et seq., 25-61-1, et seq.

Rule 4.6. Assessment of Costs to Requestor. By statute, charges for records are made on a cost- recovery basis. Payment for records requested shall be made in advance and shall be sufficient to cover the actual costs for the CSRB and/or the customer agency/institution to furnish the records. Such costs include, but are not limited to, staff and/or counsel time to evaluate and research the request, to retrieve any relevant files, to organize the information, to notify any Third Parties, to develop a cost estimate and schedule, to reproduce the material, and to deliver the information requested.

Payment shall be in the form of a certified check, money order, or corporate check made payable to the CSRB for the amount specified. No cash or personal checks will be accepted. Should the actual cost of producing the requested information exceed the estimate provided, the requestor will be notified of the additional amount due before the CSRB provides the information.

Source: Miss. Code Ann. §§ 25-41-1, et seq., 25-53-231, et seq., 25-61-1, et seq.

Chapter 5. Declaratory Opinions.

Rule 5.1. Applicability of Chapter. This chapter sets forth the CSRB’s rules governing the form, content, and filing of requests for declaratory opinions, the procedural rights of persons in relation to the written requests, and the CSRB’s procedures regarding the disposition of requests as required by Miss. Code Ann. § 25-43-2.103.

7

Source: Miss. Code Ann. § 25-43-2.105.

Rule 5.2. Scope of Declaratory Opinions. The CSRB will issue declaratory opinions regarding the applicability to specified facts of:

  1. A statute administered or enforced by the CSRB,
  2. A rule promulgated by the CSRB, or
  3. An order issued by the CSRB.

Source: Miss. Code Ann. § 25-43-2.105.

Rule 5.3. Scope of Declaratory Opinion Request. A request must be limited to a single transaction

or occurrence.

Source: Miss. Code Ann. § 25-43-2.105.

Rule 5.4. Procedure to Submit Request. When a person with substantial interest, as required by Section 25-43-2.103, requests a declaratory opinion, the requestor must submit a printed, typewritten, or legibly handwritten request.

  1. Each request must be submitted on 8-1/2” x 11” white paper.
  2. Each request may be in the form of a letter addressed to or in the form of a pleading

as if filed with court.

c. The submission must comply with all requirements of this chapter, including but

not limited to Rules 5.5-5.6.

Source: Miss. Code Ann. § 25-43-2.105.

Rule 5.5. Contents of Request. Each request must contain the following:

  1. Each request must include the date of the request.
  2. Each request must include the full name, telephone numbers, and mailing address

of the requestor(s).

c. Each request must be signed by the person filing the request, unless represented by

an attorney, in which case the attorney may sign the request.

d. Each request must clearly state that it is a request for a declaratory opinion.

e. Each request must clearly identify the statute or rule at issue.

f. Each request must include a clear and concise statement of all facts relevant to the

question presented.

g. Each request must identify all other known persons involved in or impacted by the

facts giving rise to the request including their relationship to the facts, and their name,

mailing address, and telephone number.

8

h. Each request must include a statement sufficient to show that the requestor has a substantial interest in the subject matter of the request.

Source: Miss. Code Ann. § 25-43-2.105.

Rule 5.6. Signature of Attestation. Any party who signs the request shall attest that the request complies with the requirements set forth in these rules, including but not limited to a full, complete, and accurate statement of relevant facts and that there are no related proceedings pending before any agency, board, administrative, or judicial tribunal. Source: Miss. Code Ann. § 25-43-2.105. Rule 5.7. Reasons for Refusal of Declaratory Opinion Request. The CCSRB may, for good cause, refuse to issue a declaratory opinion. The circumstances in which declaratory opinions will not be issued include, but are not necessarily limited to:

  1. The matter is outside the primary jurisdiction of the CSRB,
  2. Lack of clarity concerning the question presented,
  3. There is pending or anticipated litigation, administrative, or other adjudicative

action which may either answer the question presented by the request or otherwise

make an answer unnecessary,

d. The statute, rule, or order on which a declaratory opinion is sought is clear and not

in need of interpretation to answer the question presented by the request,

e. The facts presented in the request are insufficient to answer the question presented,

f. The request fails to comply with any requirements under this chapter,

g. The request seeks to resolve issues which are moot, abstract, or hypothetical such

that the requestor is not substantially affected by the rule, statute, or order on which a

declaratory opinion is sought,

h. No controversy exists or is certain to arise which raises a question concerning the

application of the statute, rule, or order,

i. The question presented by the request concerns the legal validity of a statute, rule,

or order,

j. The request is not based upon facts calculated to aid in the planning of future

conduct, but is, instead, based on past conduct in an effort to establish the effect of that

conduct,

k. No clear answer is determinable,

l. The question presented by the request involves the application of a criminal statute

or sets forth facts which may constitute a crime,

m. The answer to the question presented would require the disclosure of information

which is privileged or otherwise protected by law from disclosure,

n. The question is currently the subject of an Attorney General’s Opinion request,

o. The question has been answered by an Attorney General’s Opinion,

p. One or more requestors have standing to seek an Attorney General’s Opinion on

the proffered question,

9

q. A similar request is pending before the CSRB, any other agency, or proceeding is pending on the same subject matter before any agency, administrative or judicial tribunal, or where such an opinion would constitute the unauthorized practice of law, r. The question involves eligibility for a license, permit, certificate, or other approval by the CSRB or some other agency and there is a statutory or regulatory application process by which eligibility for said license, permit, or certificate, or other approval may be determined.

Source: Miss. Code Ann. § 25-43-2.105.

Rule 5.8. Agency Response. Within forty-five (“45”) working days after the receipt of a request for a declaratory opinion which complies with the requirements of this chapter, the CSRB shall, in writing: a. Issue an opinion declaring the applicability of the statute, rule, or order to the specified circumstances, b. Agree to issue a declaratory opinion by a specified time but no later than ninety (“90”) days after receipt of the written request, or c. Decline to issue a declaratory opinion, stating the reasons for its actions. The forty-five (“45”) day period shall begin on the first business day after which the request is received by CSRB. If the forty-five (“45”) day period ends on a weekend or holiday, the CSRB response will be provided on the first business day thereafter. Source: Miss. Code Ann. § 25-43-2.105. Rule 5.9. Availability of Declaratory Opinions and Requests for Opinions. Declaratory opinions and requests for declaratory opinions shall be available for public inspection and copying at the expense of the viewer during normal business hours. All declaratory opinions and requests shall be indexed by name, subject, and date of issue. Declaratory opinions and requests which contain information which is confidential or exempt from disclosure under the Mississippi 16 Public Records Act or other laws shall be exempt from this requirement and shall remain confidential. Source: Miss. Code Ann. § 25-43-2.105. Chapter 6: Rulemaking Oral Proceedings Rule 6.1. Application of Chapter. This chapter applies to all oral proceedings held for the purpose of providing the public with an opportunity to make oral presentations or written input on proposed new rules, amendments to rules, and proposed repeal of existing rules before the CSRB pursuant to the Administrative Procedures Act. Source: Miss. Code Ann.§ 25-43-2.105. Rule 6.2. Request for Oral Proceeding. When a political subdivision, an agency, or a citizen requests an oral proceeding in regards to a proposed rule adoption, the requestor must submit a printed, typewritten, or legibly handwritten request.

10

  1. Each request must be submitted on 8-1/2” x 11” white paper.
  2. The request may be in the form of a letter addressed to the [Agency] or in the form

of a pleading as if filed with a court.

c. Each request must include the full name, telephone numbers, and mailing address

of the requestor(s).

d. All requests shall be signed by the person filing the request, unless represented by

an attorney, in which case the attorney may sign the request.

Source: Miss. Code Ann.§ 25-43-2.105.

Rule 6.3. Notice of Oral Proceeding. Notice of the date, time, and place of all oral proceedings

shall be filed with the Secretary of State’s Office for publication in the Administrative Bulletin.

The CSRB providing the notice shall provide notice of oral proceedings to each requestor. The

oral proceedings will be scheduled no earlier than twenty (“20”) days from the filing of the notice

with the Secretary of State. The Agency Head, or designee who is familiar with the substance of

the proposed rule, shall preside at the oral proceeding on a proposed rule.

Source: Miss. Code Ann.§ 25-43-2.105.

Rule 6.4. Public Participation Guidelines. Public participation shall be permitted at oral

proceedings in accordance with the following:

a. At an oral proceeding on a proposed rule, persons may make statements and present documentary and physical submissions concerning the proposed rule. b. Persons wishing to make oral presentations at such a proceeding shall notify the CSRB at least three business days prior to the proceeding and indicate the general subject of their presentations. The presiding officer in his or her discretion may allow individuals to participate that have not contacted the CSRB prior to the proceeding. c. At the proceeding, those who participate shall indicate their names and addresses, identify any persons or organizations they may represent, and provide any other information relating to their participation deemed appropriate by the presiding officer. d. The presiding officer may place time limitations on individual presentations when necessary to assure the orderly and expeditious conduct of the oral proceeding. To encourage joint presentations and to avoid repetition, additional time may be provided for persons whose presentations represent the views of other individuals as well as their own views. e. Persons making presentations are encouraged to avoid restating matters that have already been submitted in writing. Written materials may, however, be submitted at the oral proceeding. f. Where time permits and to facilitate the exchange of information, the presiding officer may open the floor to questions or general discussion. The presiding officer may question participants and permit the questioning of participants by other participants about any matter relating to that rule-making proceeding, including any

11

prior written submissions made by those participants in that proceeding. No participant shall be required to answer any question. Source: Miss. Code Ann.§ 25-43-2.105. Rule 6.5. Submissions and Records. Physical and Documentary Submissions presented by participants in an oral proceeding shall be submitted to the presiding officer. Such submissions become the property of the CSRB, part of the rulemaking record, and are subject to the CSRB’s public records request procedure. The CSRB may record oral proceedings by stenographic or electronic means. Source: Miss. Code Ann.§ 25-43-2.105.

MISSISSIPPI ELECTRONIC RECORDING COMMISSION MISSISSIPPI ELECTRONIC RECORDING COMMISSION

Part 201 Rules and Standards Concerning Electronic Recording of Real Property Records in the Offices of Chancery Clerks

Chapter 1 General Rules and Standards to Implement Electronic Recording

36 Miss. Admin. Code Pt. 201, R. 1.1 Purpose

The purpose of this chapter is to establish uniform recording standards and practices, provide for integrity and security of transmissions of such records, and promote efficiencies and improved service for electronic recording of real property records in the offices of Chancery Clerks.

History

  • Source: Section 5 (a), HB 599, 2011 Regular Session of the Mississippi Legislature, as approved by the Governor.
36 Miss. Admin. Code Pt. 201, R. 1.2 Definitions

The following definitions govern the use of terms in these Rules:

(A) “Electronic Signature” means an electronic sound, symbol or process attached to or logically associated with a document and executed or adopted by a person with the intent to sign the document;

(B) "Electronic Recording" or "eRecording" means the process of the office of a Chancery Clerk accepting, recording and indexing a document in an electronic form instead of by paper submission.

(C) “PDF” (Portable Document Format) means the file format originally created by Adobe Systems for document exchange allowing documents to be viewed as they were intended to appear. PDFs are a common format for image exchange or Web presentation.

(D) “TIFF” (Tagged Image File Format) means the variable-resolution bitmapped image format originally developed by the Aldus Corporation (now part of Adobe Systems) and published as ISO 12639:2004, Graphic technology-Prepress digital data exchange-Tag image file

format for image technology (TIFF/IT). TIFF is a common format for high-quality black and white, gray-scaled, or color graphics of any resolution and is made up of individual dots or pixels.

(E) “XML” (Extensible Markup Language) means an extensible document language for specifying document content. XML is not a predefined markup language but a metalanguage – a language for describing other languages – allowing the user to specify a document type definition (DTD) and design customized markup languages for different classes of documents.

(F) “Trusted Submitter” means a party that has a Trusted Submitter Agreement signed, approved by, and on file with an individual Chancery Clerk as provided in these Rules in order to record documents electronically with that Chancery Clerk.

(G) “Trusted Submitter Agreement” means the agreement to be signed by any party who wishes to become a Trusted Submitter as defined in these Rules and which is in a form which substantially conforms to that appended to these Rules as Exhibit A.

(H) “Electronic Document” and “Electronic Record” both mean a document that is received by the office of a Chancery Clerk in an electronic form meeting the standards set forth in this Chapter.

(I) “Electronic Acceptance" or “Acceptance” means the act of a Chancery Clerk accepting a submitted document for recording through electronic means.

(J) "System of Electronic Recording" means a computer program, and the hardware and software components that comprise it, which allows for the receipt and processing of Electronic Documents for recording and indexing.

(K) “Delivery Agent” means a third party or entity other than the Trusted Submitter and the Chancery Clerk through whom Electronic Documents and/or recording fees are delivered to the office of a Chancery Clerk.

History

  • Source: Section 5 (a) and (c), HB 599, 2011 Regular Session of the Mississippi Legislature, as approved by the Governor .
36 Miss. Admin. Code Pt. 201, R. 1.3 Optional Participation

The implementation of, use of, establishment of, and/or participation in, a System of Electronic Recording is optional with each Chancery Clerk of each county in the state of Mississippi.

History

  • Source: Section 4,HB 599, 2011 Regular Session of the Mississippi Legislature, as approved by the Governor.
36 Miss. Admin. Code Pt. 201, R. 1.4 Standards

The following standards are applicable to eRecording in the office of any Chancery Clerk who elects to implement, use, establish and/or participate in a System of

Electronic Recording in the State of Mississippi:

(A) Electronic recording under this Chapter shall conform to the technical standards set forth in the following documents adopted by the Property Records Industry Association (PRIA): (1) PRIA eRecording XML Standard Version 2.4, which includes PRIA Request Version 2.4.2 (August 2007); (2) PRIA Response Version 2.4.2 (August 2007); (3) Document Version 2.4.1 (October 2007); and (4) Notary Version 2.4.1 (October 2007).

(B) The PRIA eRecording XML Implementation Guide for Version 2.4.1, Revision 2 (March 2007), as amended from time to time, should be consulted for reference. Copies of these standards and the Implementation Guide are available:

(1) from the Property Records Industry Association (PRIA), 2501 Aerial Center Parkway, Ste. 103, Morrisville, NC 27560; telephone: (919) 459 2081; website: http://www.pria.us; and

(2) from the Office of the Secretary of State of the State of Mississippi, 700 North Street, Jackson, Mississippi 39202; telephone: 800-256-3494 or 601-359-1633; website www.sos.state.ms.us .

(C) Electronic Documents shall be transmitted and stored as either TIFF or PDF files with a minimum of 200 dpi.

(D) The Commission shall annually review these standards and guidelines and, when deemed appropriate, adopt necessary amendments thereto.

History

  • Source: Section 5 (a) and (c), HB 599, 2011 Regular Session of the Mississippi Legislature, as approved by the Governor.
36 Miss. Admin. Code Pt. 201, R. 1.5 Subsequent Changes

Any subsequent changes to, amendments to, or versions of, the standards referenced and established in Rule 1.4 which may hereafter be adopted by PRIA or any successor organization shall be subject to approval by the Mississippi Electronic Recording Commission before becoming effective in the State of Mississippi.

History

  • Source: Section 5 (a) and (c), HB 599, 2011 Regular Session of the Mississippi Legislature, as approved by the Governor.
36 Miss. Admin. Code Pt. 201, R. 1.6 Models of eRecording

Electronic Documents shall conform to the following models:

(A) Model 1: Trusted Submitters will transmit scanned images of original ink-signed documents to the office of the C hancery Clerk. The office of the Chancery Clerk completes the recording process in the same way as paper using the imaged copy as the source document. Once the Chancery Clerk accepts the documents for recording, the scanned image is "burned" with the recording information, including recording date and time as well as the unique recording

reference number, such as instrument number. Indexing is performed by the indexing staff of the Chancery Clerk's office, as with paper documents. A copy of the recorded images is returned to the Trusted Submitter, together with the recording endorsement data.

(B) Model 2: Trusted Submitters will transmit scanned images of ink-signed documents or an Electronic Document electronically signed and notarized, along with data necessary for processing, indexing, and returning the document, to the office of the C hancery Clerk. The office of the Chancery Clerk performs an electronic examination of the imaged document and indexing data, and then completes the recording process using the imaged copy and electronic indexing information. The electronic version of the recorded document is returned to the Trusted Submitter, together with the recording endorsement data.

(C) Model 3: Trusted Submitters will transmit documents which have been created, signed and notarized electronically containing the electronic indexing information, or SMART™ documents which are a single object containing the electronic version of the document in such a way that enables the electronic extraction of data from the object. SMART™ documents are required to be signed and notarized electronically. Electronic Signatures must comply with the Uniform Electronic Transaction Act (UETA). The office of the Chancery Clerk performs an electronic examination of the Electronic Documents and indexing information, then completes the recording process using the Electronic Documents. Images of electronic and SMART™ documents are made and returned to the Trusted Submitter along with recording endorsement data.

(D) However, Model 3 documents are acceptable only to the extent that they have been electronically notarized within a state which has enacted laws governing electronic notarizations and has promulgated rules effectuating the same.

History

  • Source: Section 5 (a) and (c), HB 599, 2011 Regular Session of the Mississippi Legislature, as approved by the Governor.
36 Miss. Admin. Code Pt. 201, R. 1.7 Trusted Submitter Agreements

Every Trusted Submitter and every Delivery Agent transmitting electronic records shall complete and sign a Trusted Submitter Agreement application in a form which substantially conforms to that appended to this Rule as Exhibit A. Each Chancery Clerk electing to implement, use, establish and/or participate in a System of Electronic Recording must record a true and correct copy of each such Trusted Submitter Agreement in and among the county land records in his or her Miscellaneous Book or other, similar record series. Thereupon, the Trusted Submitter shall be authorized to record documents electronically.

History

  • Source: Section 5 (a) and (c), HB 599, 2011 Regular Session of the Mississippi Legislature, as approved by the Governor.
36 Miss. Admin. Code Pt. 201, R. 1.8 Who may Submit Trusted Submitter Agreements

Each Chancery Clerk shall determine who may submit real property documents for electronic recording and who may enter into Trusted Submitter Agreements as set forth in these Rules.

History

  • Source: Section 5 (a) and (c), HB 599, 2011 Regular Session of the Mississippi Legislature, as approved by the Governor .
36 Miss. Admin. Code Pt. 201, R. 1.9 Business Rules

Each Chancery Clerk electing to implement, use, establish and/or participate in a System of Electronic Recording must adopt, establish and publish a set of Business Rules that govern how electronic recording will be conducted. At a minimum, such rules must:

(A) provide for a reasonable period of time exclusive of weekends, holidays, and any day on which the Chancery Clerk’s office is closed: (1) for acceptance or rejection of a document submitted for recording electronically; and (2) for notification thereof to the Trusted Submitter;

(B) establish a procedure for assigning an order of processing electronic submissions in conjunction with documents transmitted to the Chancery Clerk’s office by other, traditional means;

(C) describe document rejection practices and standards and provide for a means of informing Trusted Submitters of the reason(s) for rejection.

History

  • Source: Section 5 (a) and (c), HB 599, 2011 Regular Session of the Mississippi Legislature, as approved by the Governor.
36 Miss. Admin. Code Pt. 201, R. 1.10 Payment of Fees

Each Chancery Clerk electing to implement, use, establish and/or participate in a System of Electronic Recording shall allow for the electronic payment of recording fees. Such fees may be paid and collected through a Delivery Agent using a third party account, provided full recording fees are paid by the close of the following business day provided such funds are available to the office of the Chancery Clerk within two business days of the transaction and sufficient documentation is generated to satisfy county audit requirements. Electronic payment may be accomplished by ACH debit, direct deposit, escrow account payment, federal reserve wire transfer, credit cards, or such other means as the individual Chancery Clerk may designate. However, no transaction or merchant fee may be paid by the office of the Chancery Clerk.

History

  • Source: Section 4 (b)(7), HB 599, 2011 Regular Session of the Mississippi Legislature, as approved by the Governor.
36 Miss. Admin. Code Pt. 201, R. 1.11 Document Formatting

Any document submitted for electronic recording shall, where applicable, conform to the formatting requirements set forth in Miss. Code Ann. § 89-5- 24 (Supp. 2012).

History

  • Source: Section 5 (a) and (c), HB 599, 2011 Regular Session of the Mississippi Legislature, as approved by the Governor .
36 Miss. Admin. Code Pt. 201, R. 1.12 Amendments

The Rules set forth in this Part 201 may be amended at any time by a majority vote of the Mississippi Electronic Recording Commission in accordance with the Mississippi Administrative Procedures Act.

History

  • Source: Section 5 (a) and (c), HB 599, 2011 Regular Session of the Mississippi Legislature, as approved by the Governor.

Chapter 2 Rule-making Oral Proceedings.

36 Miss. Admin. Code Pt. 201, R. 2.1 Application of Chapter

This Chapter applies to all oral proceedings held for the purpose of providing the public with an opportunity to make oral presentations or written input on proposed new rules, amendments to rules, and proposed repeal of existing rules before the Mississippi Electronic Recording Commission pursuant to the Administrative Procedures Act.

History

  • Source: Miss. Code Ann.§ 25-43-2.105 (Rev. 2006).
36 Miss. Admin. Code Pt. 201, R. 2.2 Request for Oral Proceeding

When a political subdivision, an agency, or a citizen requests an oral proceeding in regards to a proposed rule adoption, the requestor must submit a printed, typewritten, or legibly handwritten request.

(A) Each request must be submitted on 8-1/2" x 11" white paper.

(B) The request may be in the form of a letter addressed to the Mississippi Electronic Recording Commission or in the form of a pleading as if filed with a court.

(C) Each request must include the full name, telephone numbers, and mailing address of the requestor(s).

(D) All requests shall be signed by the person filing the request, unless represented by an attorney, in which case the attorney may sign the request.

History

  • Source: Miss. Code Ann.§ 25-43-2.105 (Rev. 2006).
36 Miss. Admin. Code Pt. 201, R. 2.3 Notice of Oral Proceeding

Notice of the date, time, and place of all oral proceedings shall be filed with the Secretary of State's Office for publication in the Administrative Bulletin. The agency providing the notice shall provide notice of oral proceedings to each requestor. The oral proceedings will be scheduled no earlier than twenty (20) days from the filing of the notice with the Secretary of State. The Chairman of the Mississippi Electronic Recording Commission, or a designee who is familiar with the substance of the proposed rule, shall preside at the oral proceeding on a proposed rule.

History

  • Source: Miss. Code Ann.§ 25-43-2.105 (Rev. 2006).
36 Miss. Admin. Code Pt. 201, R. 2.4 Public Participation Guidelines

Public participation shall be permitted at oral

proceedings in accordance with the following:

(A) At an oral proceeding on a proposed rule, persons may make statements and present documentary and physical submissions concerning the proposed rule.

(B) Persons wishing to make oral presentations at such a proceeding shall notify the Mississippi Electronic Recording Commission at least three business days prior to the proceeding and indicate the general subject of their presentations. The presiding officer in his or her discretion may allow individuals to participate that have not contacted the Commission prior to the proceeding.

(C) At the proceeding, those who participate shall indicate their names and addresses, indentify any persons or organizations they may represent, and provide any other information relating to their participation deemed appropriate by the presiding officer.

(D) The presiding officer may place time limitations on individual presentations when necessary to assure the orderly and expeditious conduct of the oral proceeding. To encourage joint presentations and to avoid repetition, additional time may be provided for persons whose presentations represent the views of other individuals as well as their own views.

(E) Persons making presentations are encouraged to avoid restating matters that have already been submitted in writing. Written materials may, however, be submitted at the oral proceeding.

(F) Where time permits and to facilitate the exchange of information, the presiding officer may open the floor to questions or general discussion. The presiding officer may question participants and permit the questioning of participants by other participants about any matter relating to that rule-making proceeding, including any prior written submissions made by those participants in that proceeding. No participant shall be required to answer any question.

History

  • Source: Miss. Code Ann.§ 25-43-2.105 (Rev. 2006).
36 Miss. Admin. Code Pt. 201, R. 2.5 Submissions and Records

Physical and Documentary Submissions presented by participants in an oral proceeding shall be submitted to the presiding officer. Such submissions become the property of the Mississippi Electronic Recording Commission, part of the rulemaking record, and are subject to the Mississippi Electronic Recording Commission's public records request procedure. The Mississippi Electronic Recording Commission may record oral proceedings by stenographic or electronic means.

History

  • Source: Miss. Code Ann.§ 25-43-2.105 (Rev. 2006).

Chapter 3 Declaratory Opinions.

36 Miss. Admin. Code Pt. 201, R. 3.1 Application of Chapter

This Chapter sets forth the Mississippi Electronic Recording

Commission’s rules governing the form, content, and filing of requests for declaratory opinions, the procedural rights of persons in relation to the written requests, and the Mississippi Electronic Recording Commission’s procedures regarding the disposition of requests as required by Mississippi Code § 25-43-2.103.

History

  • Source: Miss. Code Ann.§ 25-43-2.105 (Rev. 2006).
36 Miss. Admin. Code Pt. 201, R. 3.2 Scope of Declaratory Opinions

The Mississippi Electronic Recording Commission will issue declaratory opinions regarding the applicability to specified facts of:

(A) a statute administered or enforceable by the Mississippi Electronic Recording Commission;

(B) a rule promulgated by the Mississippi Electronic Recording Commission;

History

  • Source: Miss. Code Ann.§ 25-43-2.105 (Rev. 2006).
36 Miss. Admin. Code Pt. 201, R. 3.3 Scope of Declaratory Opinion Request

A request must be limited to a single transaction or occurrence.

History

  • Source: Miss. Code Ann.§ 25-43-2.105 (Rev. 2006).
36 Miss. Admin. Code Pt. 201, R. 3.4 How to Submit Requests

When a person with substantial interest, as required by Section 25-43-2.103 of the Administrative Procedures Act, requests a declaratory opinion, the requestor must submit a printed, typewritten, or legibly handwritten request, consistent with the following:

(A) Each request must be submitted on 8-1/2" x 11" white paper.

(B) The request may be in the form of a letter addressed to the Mississippi Electronic Recording Commission or in the form of a pleading as if filed with a court.

(C) Each request must include the full name, telephone numbers, and mailing address of the requestor(s).

(D) All requests shall be signed by the person filing the request, unless represented by an attorney, in which case the attorney may sign the request.

(E) Each request must clearly state that it is a request for a declaratory opinion.

History

  • Source: Miss. Code Ann.§ 25-43-2.105 (Rev. 2006).
36 Miss. Admin. Code Pt. 201, R. 3.5 Signature Attestation

Any party who signs the request shall attest that the request complies with the requirements set forth in these rules, including but not limited to a full,

complete, and accurate statement of relevant facts and that there are no related proceedings pending before any agency, administrative, or judicial tribunal.

History

  • Source: Miss. Code Ann.§ 25-43-2.105 (Rev. 2006).
36 Miss. Admin. Code Pt. 201, R. 3.6 Request Content Requirement

Each request must contain the following:

(A) A clear identification of the statute, rule, or order at issue;

(B) The question for the declaratory opinion;

(C) A clear and concise statement of all facts relevant to the question presented;

(D) The identity of all other known persons involved in or impacted by the facts giving rise to the request including their relationship to the facts, and their name, mailing address, and telephone number; and

(E) A statement sufficient to show that the requestor has a substantial interest in the subject matter of the request.

History

  • Source: Miss. Code Ann.§ 25-43-2.105 (Rev. 2006).
36 Miss. Admin. Code Pt. 201, R. 3.7 Reasons for Refusal of Declaratory Opinion Request

The Mississippi Electronic Recording Commission may, for good cause, refuse to issue a declaratory opinion. The circumstances in which declaratory opinions will not be issued include, but are not necessarily limited to:

(A) The matter is outside the primary jurisdiction of the Mississippi Electronic Recording Commission;

(B) Lack of clarity concerning the question presented;

(C) There is pending or anticipated litigation, administrative action or anticipated administrative action, or other adjudication which may either answer the question presented by the request or otherwise make an answer unnecessary;

(D) The statute, rule, or order on which a declaratory opinion is sought is clear and not in need of interpretation to answer the question presented by the request;

(E) The facts presented in the request are not sufficient to answer the question presented;

(F) The request fails to contain information required by these rules or the requestor failed to follow the procedure set forth in these rules;

(G) The request seeks to resolve issues which have become moot or are abstract or hypothetical such that the requestor is not substantially affected by the rule, statute, or order on which a declaratory opinion is sought;

(H) No controversy exists or is certain to arise which raises a question concerning the application of the statute, rule, or order;

(I) The question presented by the request concerns the legal validity of a statute, rule, or order;

(J) The request is not based upon facts calculated to aid in the planning of future conduct, but is, instead, based on past conduct in an effort to establish the effect of that conduct;

(K) No clear answer is determinable;

(L) The question presented by the request involves the application of a criminal statute or sets forth facts which may constitute a crime;

(M) The answer to the question presented would require the disclosure of information which is privileged or otherwise protected by law from disclosure;

(N) The question is currently the subject of an Attorney General's opinion request;

(O) The question has been answered by an Attorney General's opinion;

(P) One or more requestors have standing to seek an Attorney General's opinion on the proffered question;

(Q) A similar request is pending before this agency, or any other agency, or a proceeding is pending on the same subject matter before any agency, administrative or judicial tribunal, or where such an opinion would constitute the unauthorized practice of law; or

(R) The question involves eligibility for a license, permit, certificate or other approval by the Mississippi Electronic Recording Commission or some other agency and there is a statutory or regulatory application process by which eligibility for said license, permit, or certificate or other approval may be determined.

History

  • Source: Miss. Code Ann.§ 25-43-2.105 (Rev. 2006).
36 Miss. Admin. Code Pt. 201, R. 3.8 Agency Response

Within ninety (90) days after the receipt of a request for a declaratory opinion which complies with the requirements of these rules, the Mississippi Electronic Recording Commission shall, in writing:

(A) Issue an opinion declaring the applicability of the statute, rule, or order to the

specified circumstances;

(B) Agree to issue a declaratory opinion by a specified time but no later than ninety (90) days after receipt of the written request; or

(C) Decline to issue a declaratory opinion, stating the reasons for its action. The ninety (90) day period shall begin on the first business day after which the request is received by the Mississippi Electronic Recording Commission.

History

  • Source: Miss. Code Ann.§ 25-43-2.105 (Rev. 2006).
36 Miss. Admin. Code Pt. 201, R. 3.9 Availability of Declaratory Opinions and Requests for Opinions

Declaratory opinions and requests for declaratory opinions shall be available for public inspection and copying at the expense of the viewer during normal business hours. All declaratory opinions and requests shall be indexed by name, subject, and date of issue. Declaratory opinions and requests which contain information which is confidential or exempt from disclosure under the Mississippi Public Records Act or other laws shall be exempt from this requirement and shall remain confidential.

EXHIBIT A

ELECTRONIC RECORDING TRUSTED SUBMITTER AGREEMENT

This Trusted Submitter Agreement (the "Agreement") is entered into by and between the ________ County Chancery Clerk and Submitter, whose name and address is set forth below. By this Application and Agreement, Submitter seeks to become a Trusted Submitter of real estate documents and other recordable documents through an electronic portal.

  1. Electronic Recording (eRecording):

eRecording is defined based on the level of automation and structure of the transaction. The Chancery Clerk's Office accepts ____________________ transmissions, as defined in Attachment A.

  1. Program Eligibility:

As provided by Rule 1.8, Attorneys, banks, mortgage bankers, title closing companies, title insurance companies, title underwriters, governmental entities, and other trusted entities may submit real property documents for eRecording. eRecording requires a business relationship as well as mutual trust between the Chancery Clerk's Office, the Submitter, and a third party vendor transmitting electronic records. All parties to the eRecording transaction desire to operate and maintain a secure recording system that safeguards parties to recordation from deceit, fraud, and forgery. This Application and Agreement outlines the procedures and practices for the trusted relationship between the Chancery Clerk's Office and all Submitters. Participation in the eRecording program is voluntary and the decision to do so is a business judgment. The Chancery Clerk's Office will continue to receive paper documents to be recorded into the Official Records.

The Chancery Clerk's Office is currently eRecording with the following vendor(s): _____________________

  1. County Requirements:

The eRecording Program of the Chancery Clerk's Office is defined by the requirements included in this Application and the Attachments referenced herein, as may be amended (the "eRecording Rules").

Attachment A – Technical Specifications: provides the technical specifications including the format, models of eRecording supported, transmission protocols, and security requirements of the electronic records. All eRecording participants must agree to provide transmissions following the specifications outlined.

Attachment B – Documents and Indexing Specifications: contains the document and indexing specifications for the eRecording Program. For each document type, the expected document code is provided, along with the expected indexing information. Attachment C – Service Offering and eRecording Reasons for Rejections: contains the processing schedules, hours of operation for the eRecording Program, and reasons for rejection of an eRecorded document.

Attachment D – Payment Options: provides the method(s) of payment which will be accepted by the Chancery Clerk's Office.

These eRecording Rules will stay in effect until notice is given of a pending change. The Chancery Clerk's Office will post the details of any changes on its website and use its best efforts to provide at least fifteen (15) business days advance notice of any changes.

  1. eRecording Submitter Responsibilities:

Submitters are expected to abide by Mississippi law. eRecording allows Submitters to prepare, sign, and/or transmit documents and business records in electronic formats. The electronically transmitted documents will be considered the “original” record of the transaction, in substitution for, and with the same intended effect as, paper documents and, in the case that such documents bear a digital or electronic signature, paper documents bearing handwritten signatures.

Submitters are expected to be diligent in ensuring that documents submitted for eRecording have been checked before submission for errors, omissions, scanning defects, illegible areas, and other deficiencies that would affect the ability of the Chancery Clerk's Office to record the document and the public notice to be created thereby.

Submitters are required to attest to the accuracy and completeness of the electronic records and acknowledge responsibility for the content of the documents. Should a dispute or legal action arise concerning an electronic transaction, the Chancery Clerk's Office will be held harmless and will not be liable for any damages.

Submitters are responsible for the costs of the system or services provided by a third party that enables them to meet the requirements of this eRecording Program.

Submitters will immediately notify the Chancery Clerk's Office of any security incident, including, but not limited to, attempts to and/or actual unauthorized access to its pathway which would compromise or otherwise adversely affect the Chancery Clerk's Office data systems.

Submitters will work to ensure that all security measures and credentials implemented are protected. Documents are to be authenticated and transmitted without modification. Submitters are expected to maintain an audit trial of all activity, available to the Chancery Clerk's Office, at its request, to resolve issues or investigate potential fraudulent activity. The audit trail must

contain, at a minimum, the following: submitter ID, submitted content at point of receipt from Submitter, submitted content at point of delivery to the Chancery Clerk's Office, dates and times submitted, size, and total fee(s) due.

Submitters are responsible for coordinating all technical problems and issues through the Chancery Clerk's Office.

  1. Chancery Clerk's Responsibilities:

The Chancery Clerk's Office will attempt to protect the integrity of the recording process through ongoing monitoring of documents received and recorded through eRecording means.

eRecording is one method of transmitting documents to be recorded in the Official Records of the Chancery Clerk. The Chancery Clerk's Office will test and maintain eRecording software and hardware required to operate the eRecording capability. The Chancery Clerk's Office, however, shall be held harmless and will not be held liable for any damages resulting from software or equipment failure and assumes no contractual liability for any damages that may result from such failure.

The Chancery Clerk's Office will apply the same level of diligence in handling documents submitted electronically as those submitted through the traditional manual paper process.

  1. General Understandings:

The Chancery Clerk's Office will not incur any liability for the information electronically transmitted by Submitters, including, but not limited to, any breach of security, fraud, or deceit.

The Chancery Clerk's Office and Submitters will attempt, in good faith, to resolve any controversy or claim arising out of or relating to eRecording through negotiation prior to initiating litigation.

The Chancery Clerk's Office may terminate any Submitter’s authorization to eRecord documents for any reason.

Documents may be rejected in accordance with Mississippi law, including, but not limited to, the following reasons: document errors, failure to pay the filing or other fees due, the document is not a type the Chancery Clerk's Office is authorized to accept for recording, or the document fails to meet any other applicable legal requirement.

  1. Termination:

The Chancery Clerk may cease eRecording at any time for any reason as long as fifteen (15) business days notice is provided.

SUBMITTER INFORMATION

Name of Individual or Entity:

Street Address:

City, State, Zip:

Phone Number:

Person Responsible for administration of electronic recording by Applicant:

Phone Number: Email:

Short Description of nature of business:

By signing below, the Submitter hereby acknowledges that the Submitter understands and will abide by the terms of this Application and Agreement, including Attachments, as may be amended.

Date Signature of Applicant

By: Its:

Date __________County Chancery Clerk

__________________ By: Its: _________________________

Attachment A

Technical Specifications

  1. Accepted Models for Electronic Recording

The three models of automation are as follows:

Level 1: Submitting organizations transmit scanned images of original ink signed documents to the office of the Chancery Clerk. The office of the Chancery Clerk completes the recording process in the same way as paper using the imaged copy as the source document. Once the office of the Chancery Clerk accepts the documents for recording, the scanned image is “burned” with the recording information, including recording date and time as well as the unique recording reference number, such as instrument number. Indexing is performed by the indexing staff of the Chancery Clerk’s office, as with paper documents. A copy of the recorded images is returned to the submitter, together with the recording endorsement data.

Level 2: Submitting organizations transmit scanned images of ink signed documents or an electronic document electronically signed and notarized, along with data necessary for processing, indexing, and returning the document, to the office of the Chancery Clerk. The office of the Chancery Clerk performs an electronic examination of the imaged document and indexing data, and then completes the recording process using the imaged copy and electronic indexing information. The electronic version of the recorded document is returned to the submitter, together with the recording endorsement data.

Level 3: Submitting organizations transmit documents which have been created, signed and notarized electronically containing the electronic indexing information, or SMART™ documents which are a single object containing the electronic version of the document in such a way that enables the electronic extraction of data from the object. SMART™ documents are required to be signed and notarized electronically. Electronic signatures must comply with the Uniform Electronic Transaction Act (UETA). The office of the Chancery Clerk performs an electronic examination of the electronic documents and indexing information, then completes the recording process using the electronic documents. Images of electronic and SMART™ documents are made, and returned to the submitting organization, along with recording endorsement data.

  1. Format of the Transmitted File

Property Records Industry Association (PRIA)/Mortgage Industry Standards Maintenance Organization (MISMO) file format standards will be used. The file format shall be TIFF or PDF, and must be so specified.

  1. Communications Protocol and Options

Transmission Control Protocol/Internet Protocol (TCP/IP), HTTP and HTTPS will be used.

  1. Security Framework Encryption will be a minimum 128 bit file and image encryption. Secure Socket Layer (SSL) and user login/password will be employed. User passwords are controlled by the Submitter and should be monitored/or changed periodically to ensure security. Computers on which documents originate must have all critical operating system patches applied, must have a firewall (hardware or software) installed, and must have up to date virus scan software.

  2. Returned File Format

Property Records Industry Association (PRIA)/Mortgage Industry Standards Maintenance Organization (MISMO) file format standard will be used. Documents will be returned in the file format (TIFF or PDF) specified by the submitter.

  1. Electronic Signatures and Use of Digital Certificates

The use of Electronic Signatures and Digital Certificates will need to adhere to the guidelines set out in any applicable Mississippi Statutes and Mississippi Secretary of State administrative rules.

  1. Imaging Standards

Documents will be scanned at a minimum of 200 dpi. Documents will be scanned in portrait mode. Document images will be captured in single page [or specify multi page] storage format. Scanned documents will be legible and reproducible – including signatures and notary seals. Document details, such as margins, font size, and other similar requirements, must meet all applicable state or local standards. Documents must be scanned to original size.

Attachment B

Documents and Indexing Specifications

  1. Eligible Document Types

All document types recorded in a paper-based world are acceptable for eRecording. [Be sure to name any exceptions. Further, it may be helpful to attach a table to show document types and anticipated indexing data.]

  1. County Specific Document Type Coding

Please refer to PRIA Web site (www.pria.us) for the Logical Data Dictionary, which lists all the “Document Types.” It is the Chancery Clerk's intention to not reject documents based on “incorrect or non-County specific” document types. The Chancery Clerk's Office will correct the document type as part of the acceptance process.

  1. Indexing Fields for each Document Code

See the attached table. [Be sure to indicate your intentions regarding incomplete or inaccurate indexing data. Will your staff correct/change the indexing data or reject the document?]

  1. Document Imaging Quality Control Standards

The xhtml document must display in W3C (World Wide Web Consortium) Standards.

  1. Notary Requirements per Document

It is the responsibility of the Submitter to confirm that notary signatures and seals are present on all documents that require them. Inked notary seals are strongly recommended, in place of emobssed notary seals which require "darkening" by the Submitter prior to submittal.

  1. Eligible Document Batches

Document batches will be submitted by a standard naming convention as specified by the Chancery Clerk. The maximum size of electronic document batches will be determined by the Chancery Clerk.

Attachment C

Service Offering

  1. Hours of Operation

Documents may be submitted at any time during the week. Documents will only be processed between 8:00 a.m. and 5:00 p.m. on those days that the Chancery Clerk's Office is open to the public for business. Documents will not be processed on county holidays, weekends, declared emergencies, etc. or in the event of network or equipment failure. The Chancery Clerk's Office will attempt to notify Submitters of any disruption in service.

  1. Processing Schedules

Documents must be received by [specify a time] local time to be recorded or rejected on the date received. Documents received after [specify a time] local time will be recorded or rejected on the next business day.

  1. Alternative Delivery Options

There are no other electronic delivery options at this time.

  1. Return Options

Submitted documents that are accepted for recording will be made available to the Submitter in electronic format after recording. Notice of Acceptance will be provided to Submitter within 24 hours (excluding weekends, holidays, and any other time in which the Chancery Clerk's Office is closed) of submission. The document image and indexing data shall either be included in the notice of Acceptance, or provided subsequently.

Submitted documents that are rejected will be made available to the Submitter in electronic format after rejection, along with a description of the reason(s) for rejection. Notice of Rejection will be provided within 24 hours (excluding weekends, holidays, and any other time in which the Chancery Clerk's Office is closed) of submission.

  1. Service Help Contact Information

The following Chancery Clerk staff members [minimum of two] are identified as the primary points of contact for the Submitter:

Name: Email: Phone number:

Name: Email: Phone number:

Attachment D

Payment Options

[Be sure to state what payment options you will accept, and provide any necessary authorization forms.]

Sample language for ACH Debit

Automated Clearing House (ACH) Debit transactions will be accepted as the payment method for an eRecording transaction. The Submitter must sign an authorization form, allowing Automated Clearing House (ACH) transactions against the account being used to process fees for documents submitted. It is the Submitter’s responsibility to inform the Chancery Clerk of any changes that may effect an ACH transaction at least 10 days before the change. The Chancery Clerk may terminate the Submitter’s authorization for failure to report changes in ACH, or for unavailability of funds. The Submitter will not be able to access the eRecording system if applications have been accepted and the fees have not been collected.

Sample language for Escrow Payments

Escrow payments will be accepted as the payment method for an eRecording transaction. Towards that end, a Submitter must keep a minimum of $100 on account in the Chancery Clerk's office in order to proceed with eRecording.

History

  • Source: Miss. Code Ann.§ 25-43-2.105 (Rev. 2006).

MISSISSIPPI INFORMATION TECHNOLOGY SERVICES MISSISSIPPI INFORMATION TECHNOLOGY SERVICES

Part 1 Enterprise Security Policy

Chapter 1 Security Program Policies Rule 1.1 Authority To fulfill the statutory requirements for cybersecurity, the State of Mississippi will have a comprehensive cybersecurity program (the Enterprise Security Program) to provide coordinated oversight of the cybersecurity efforts across all state agencies, including cybersecurity systems, services, and the development of policies, standards and guidelines.

36 Miss. Admin. Code Pt. 1, R. 1.2 Rule 1.2

Purpose The goal of this policy is to improve the cybersecurity posture of the State by establishing requirements for preserving the confidentiality, integrity, and availability of State of Mississippi information and information technology (IT) systems (hereafter referred to collectively as “SOM Assets”) from unauthorized use, access, disclosure, modification, or destruction.

Confidentiality ensures that information is accessible only to those authorized to have access. Integrity ensures the accuracy and completeness of the data is safeguarded. Availability ensures that authorized users have access to the information.

This policy establishes minimum security requirements that all agencies will adhere to, using them as minimum standards with which to develop, implement, and maintain their individual agency IT security policies, plans, and procedures as well as the standards and policies for all state data and information technology resources that state agencies shall implement to the extent

that they apply including defined enterprise security minimum requirements for procuring data and information technology systems and services.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 1, R. 1.3 Rule 1.3

Scope This policy applies to all state agencies; State of Mississippi employees; ITS trusted partners (e.g., subcontractors, vendors, third-parties, temporary workers, etc.); or any entity, as provided by law, authorized to operate, manage, or use SOM Assets. Agency is defined as and includes all the various state agencies, officers, departments, boards, commissions, offices, and institutions of the state. A. This policy includes a subset of technical requirements that are only applicable to agencies participating in the Enterprise State Network. Agencies that do not participate in the Enterprise State Network, and thus do not have the benefit of the technical controls in place, must develop agency-specific security policies that are: 1. Appropriate to their respective environments and information, and 2. Consistent with the intent of this policy. B. This policy addresses information regardless of what form it takes (i.e., electronic, printed, etc.), what technology is used to handle it, the location of the data or resources, or what purpose(s) it serves. C. This policy encompasses all data and information technology resources (i.e., data and information technology systems (automated and manual), services, products, etc.) for which the agencies have administrative responsibility, including data and information technology resources managed, provided, and/or hosted by third parties on behalf of the agencies. D. Beyond the requirements of this policy, state agencies must also comply with other applicable security standards and policies for state data and IT resources established by ITS. This includes, but is not limited to, the State of Mississippi Enterprise Cloud and Offsite Security Policy, which outlines additional security requirements for cloud and offsite hosting services. Additional policies, requirements, and/or recommendations for state agencies can be found on the ITS website.

History

  • Source: Miss. Code Ann. §§ 25-53-3 (2)(e) and 25-53-201.
36 Miss. Admin. Code Pt. 1, R. 1.4 ITS Chief Information Officer The ITS Chief Information Officer is also the ITS Executive Director

The ITS CIO (or any currently designated acting CIO) oversees all agency activities and ensures that an organizational structure is in place for overseeing security risk management.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 1, R. 1.5 Rule 1.5

Enterprise Security Program The Enterprise Security Program is focused on providing the resources, guidance, and oversight needed for improving the cybersecurity posture of the enterprise network for state government. ITS has designated a Chief Information Security Officer (CISO) to manage the program and

develop, maintain, and communicate the State of Mississippi Enterprise Security Policy and State of Mississippi Enterprise Security Standards. The ITS CISO and ITS cybersecurity professionals will execute the Program mission by: A. Administering the Enterprise Security Program to execute the statutory duties and responsibilities of ITS. B. Researching and selecting enterprise technology solutions capable of improving the cybersecurity posture in the function of any agency, institution, or function of state government as a whole. C. Establishing and maintaining the security standards and policies for all state data and IT resources that state agencies shall implement, to the extent that they apply. D. Coordinating and promoting efficiency and security with all applicable laws and regulations in the acquisition, operation, and maintenance of state data, cybersecurity systems, and services used by agencies of the State. E. Managing, planning, and coordinating all enterprise cybersecurity systems under the jurisdiction of the state. F. Developing, in coordination with state agencies, enterprise cybersecurity systems and services for all governmental organizations within the purview of ITS. G. Providing ongoing analysis of enterprise cybersecurity systems and services costs, facilities, and systems within state government. H. Organizing an advisory council of Information Security Officers from each state agency and coordinating the activities of the advisory council to provide education and awareness, identify cybersecurity-related issues, set future direction for cybersecurity plans and policy, and provide a forum for inter-agency communications regarding cybersecurity. I. Requiring a cooperative effort for the utilization of enterprise cybersecurity systems and services among MS state agencies.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 1, R. 1.6 Rule 1.6

Agency Heads The Executive Director and/or Agency Head of each state agency is solely responsible for the security of all data and IT resources under said agency’s purview, irrespective of the location of the data or resources. Locations include data residing at agency sites, on agency real property and tangible and intangible assets; in the State Data Centers; in transit between locations; or at a third-party location on behalf of the agency. The Executive Director/Agency Head will ensure that an organizational structure is in place for overseeing security risk management, but is ultimately accountable for: A. Ensuring that an agency-wide cybersecurity program is in place. B. Designating an information security officer to administer the agency’s security program.

C. Ensuring the agency adheres to the requirements established by the Enterprise Security Program, to the extent that they apply. D. Participating in all Enterprise Security Program initiatives and services in lieu of deploying duplicate services specific to the agency. E. Developing, implementing, and maintaining written agency policies and procedures to ensure the security of data and IT resources. 1. The agency policies and procedures are confidential information and exempt from public inspection, except that the information must be available to the Mississippi’s Office of the State Auditor and/or ITS in performing auditing duties. F. Implementing policies and standards to ensure that all of the agency’s data and IT resources are maintained in compliance with state and federal laws and regulations, to the extent that they apply. G. Implementing appropriate cost-effective safeguards to reduce, eliminate, or recover from identified threats to data and IT resources. H. Ensuring that internal assessments of the security program are conducted. 1. The results of the internal assessments are confidential and exempt from public inspection, except that the information must be available to the Mississippi’s Office of the State Auditor and/or ITS in performing auditing duties. I. Including all appropriate cybersecurity requirements in the specifications for the agency's solicitation of state contracts for procuring data and information technology systems and services. J. Including a general description of the security program and future plans for ensuring security of data in the agency long-range information technology plan. K. Participating in annual information security training designed specifically for the agency head to ensure that the agency head has an understanding of: the information and information systems that support the operations and assets of the agency; the potential impact of common types of cyber-attacks and data breaches on the agency’s operations and assets; how cyber-attacks and data breaches on the agency’s operations and assets could impact the operations and assets of other state agencies on the Enterprise State Network; how cyber-attacks and data breaches occur; steps the executive director or agency head and agency employees should take to protect their information and information systems; and the annual reporting requirements required of the executive director or agency head.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 1, R. 1.7 Rule 1.7

Agency Cybersecurity Programs Agencies must develop and maintain an agency-wide cybersecurity program to address security for information and information systems that support the operations and assets of the agency, including those provided or managed by another organization, contractor, or other source. Agency controls in the management of the cybersecurity program include:

A. Ensuring that an agency-wide cybersecurity program plan is developed, disseminated, and maintained. B. Ensuring the resources needed to implement the cybersecurity program are documented and available. C. Developing, monitoring, and reporting on the results of security measures of performance. D. Ensuring the information technology architecture is designed with consideration for information security and the resulting risk to agency operations, agency assets, individuals, other organizations, and the State. E. Providing insider threat awareness training to detect and prevent malicious insider activity. F. Establishing an information security workforce development and improvement program. G. Developing and maintaining a process for conducting security testing, training, and monitoring activities. H. Ensuring participation with the Enterprise Security Program to assist the agency with 1. Facilitating ongoing security education and training for agency employees. 2. Maintaining knowledge of recommended security practices, techniques, and technologies. 3. Sharing current security-related information including threats, vulnerabilities, and incidents with appropriate stakeholders.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 1, R. 1.8 Rule 1.8

Agency Information Security Officer Each agency must designate an Information Security Officer (ISO) that will manage information security tasks and activities within the agency. The ISO responsibilities include: A. Providing oversight of the agency-wide cybersecurity program within their agency. B. Collaborating with agency staff on the development, implementation, and maintenance of agency-specific security plans, policies, and procedures. C. Ensuring that their agency is adhering to the State of Mississippi enterprise security policies and standards; agency-specific policies; and any other security policies, guidelines, regulations, or laws (Federal, State, and Local) their agency is required to comply with. D. Ensuring that regular assessments and evaluations of the agency’s security posture are performed. E. Recommending a course of action where security risks are not adequately addressed. F. Reporting security compliance status and advising the agency head and the agency Chief Information Officer (CIO) on the completeness and adequacy of agency security measures.

G. Monitoring and reporting the performance of security measures within their agency. H. Ensuring all information as required in State of Mississippi enterprise policies and standards are developed and submitted. I. Ensuring agency participation in the Enterprise Security Program activities, Security Council meetings hosted by ITS, and other security-related activities organized by ITS.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 1, R. 1.9 Agency Staff Roles and Responsibilities All agency staff are personally responsible for information security

The roles and responsibilities of staff must be defined in local policies and procedures and incorporated into the staff orientation process. A. Agency staff must comply with this State of Mississippi enterprise and agency- specific security policies, standards, and procedures to maintain the confidentiality, integrity, and availability of SOM assets. B. Agency staff designated as an owner of an agency information system are responsible for the overall procurement, development, integration, modification, or operation and maintenance of information systems including: 1. Advising the agency on system security categorization. 2. Ensuring the creation of required system security plans. 3. Ensuring the implementation of all required security controls for the system.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 1, R. 1.10 Rule 1.10

Policy Framework This policy is designed to be in alignment with security requirements recommended by the National Institute of Standards and Technology (NIST), the National Cybersecurity and Infrastructure Security Agency (CISA), and the Center for Internet Security (CIS). This policy addresses the five core functions listed below. A. Identify – Development of an organizational understanding to manage cybersecurity risk to systems, assets, data, and capabilities. B. Protect – Development and implementation of the appropriate safeguards to ensure the security of SOM assets. C. Detect – Development and implementation of the appropriate activities to identify the occurrence of a cybersecurity event. D. Respond – Develop and implement the appropriate activities to take action regarding a detected cybersecurity event. E. Recover - Develop and implement the appropriate activities to maintain plans to mitigate and to restore critical infrastructure services that were impaired due to a cybersecurity event.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 1, R. 1.11 Policy Compliance and Auditing A

Each agency shall adhere to the more restrictive policy when conflicts exist between this policy and agency policies. B. Each agency shall regularly review the level of compliance with this policy, document where compliance with the requirements of this policy is not met and develop a plan for addressing the deficiencies. C. The following information is provided to clarify the role of the Mississippi Office of the State Auditor (OSA) and the Mississippi Department of Information Technology Services (ITS) in auditing compliance: 1. The State Auditor will review how well agencies comply with security policies as part of their normal agency information systems auditing activities. 2. As a component of their standard Information Systems audit process, the State Auditor will consider the State of Mississippi Enterprise Security Policy in the review of the systems, processes, and procedures that they will examine. 3. The State Auditor may determine a special audit of an agency’s information system processing is warranted; in which case they will proceed under their existing authority. Each agency must maintain documentation showing the results of its review or audit and the plan for correcting identified deficiencies. To the extent that the audit documentation includes valuable formulae, designs, drawings, computer source code, object codes or research data, or that disclosure of the audit documentation would be contrary to the public interest and would irreparably damage vital government functions, such audit documentation is exempt from public disclosure. 4. The State Auditor may request the assistance of ITS in the performance of this normal audit function. 5. The State Auditor may request and review copies of an agency’s IT Security Risk Assessment separately or in conjunction with the normal agency audit process. 6. The State Auditor may request and review the agency’s compliance document that identifies the agency’s current compliance level with the State of Mississippi Enterprise Security Policy. 7. Upon determination of any non-compliance, the State Auditor may instruct the agency and/or ITS to take necessary steps to become compliant. 8. Agencies should understand that failure to comply with this policy could result in a finding in the agency’s audit report from the State Auditor. D. In addition to complying with this policy, it is the responsibility of each agency to determine whether there are any guidelines, regulations, or laws (Federal, State, and Local) outside this policy they are required to meet. These guidelines, regulations, or laws may include, but are not limited to: 1. Health Insurance Portability and Accountability Act of 1996 (HIPAA) 2. The Privacy Act of 1974, 5 U.S.C. § 552 a, Public Law No. 93-579 3. Family Educational Rights and Privacy Act (FERPA) (20 U.S.C. § 1232g; 34 CFR Part 99) 4. Payment Card Industry Data Security Standard (PCI/DSS)

  1. Internal Revenue Service (IRS) Publication 1075 6. Criminal Justice Information Services (CJIS) 7. Miss. Code Ann. § 75-24-29 Breach of Security; Require Notice 8. Children’s Internet Protection Act (CIPA) 9. Federal Information Security Management Act of 2002 (FISMA) 10. Miss. Code Ann. § 25-1-111 Prevention of Disclosure by State Agencies of Social Security Numbers 11. Driver’s Privacy Protection Act (DPPA) 12. The Fair Credit Reporting Act (FCRA) 13. The Gramm-Leach-Bliley Act (GLBA) 14. Miss. Code Ann. § 25-53-193 National Security on State Devices and Networks Act 15. Children’s Online Privacy Protection Act (COPPA)

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 1, R. 1.12 Rule 1.12

Maintenance of State of Mississippi Enterprise Security Policies, Standards, Guidelines and Recommendations The revision date for this policy is Month/Day/Year. A. ITS is responsible for routine maintenance and review of this policy. Routine maintenance and review is required to ensure that this policy is up-to-date with respect to the technological advances and changes in the business requirements of state agencies, potential threats, applicable legislation and other changes that impact information security policies, standards, guidelines and recommendations.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 1, R. 1.13 Exceptions to the State of Mississippi Enterprise Security Policies, Standards, Guidelines, and Recommendations A

The only permitted exceptions to the State of Mississippi Enterprise Security Policy are those that are approved in writing by ITS for an agency’s specific purpose and are only applicable to that agency’s operations for the duration of time defined by the exception. B. Each agency must inquire with the agency partner (e.g., subcontractor, vendor, third- party, etc.) and appropriate agency staff to ascertain if design alternatives, configuration changes, or additional products, systems, or services are available to attain compliance prior to submitting a request for an exception. C. Prior to selecting, acquiring, and/or procuring data and information technology resources (i.e., data and information technology systems, services, products, etc.) and/or renewing existing agreements for data and information technology resources, each agency must consider all applicable enterprise policies and standards and is responsible for ensuring the data and information technology resource allows the agency to be in compliance with all applicable enterprise policies and standards when specifying, scoping, evaluating, and/or renewing solutions and that all appropriate

cybersecurity requirements are included in the acquisition/procurement of data and information technology solutions.

History

  • Source: Miss. Code Ann. § 25-53-201.

Chapter 2 Asset Management

36 Miss. Admin. Code Pt. 1, R. 2.1 System and Physical Device Inventory A

Each agency must maintain an accurate and up-to-date inventory of all technology assets with the potential to store or process information. This should include all assets with an IP address. 1. Implement a process that requires approval before new assets are installed or deployed. This process shall include the designation of a person, or persons authorized to make such approvals, and documentation describing how these approvals are recorded. 2. The inventory shall include all hardware assets, whether connected to the agency’s network or not. This includes agency assets owned, operated, or managed by a third party. 3. The inventory shall be maintained and updated throughout the asset’s lifecycle (installations, removals, updates, etc.). i. Unsupported assets/hardware that can no longer receive security patches must be removed from the network. 4. The inventory information for each asset should include the network address (if static), hardware address, machine name, data asset owner, and department for each asset and whether the hardware asset has been approved to connect to the network. For assets with dynamic addresses provided by DHCP, refer to ITS’s recommendation on utilizing DHCP. i. ITS recommends utilizing dynamic host configuration protocol (DHCP) logging on all DHCP servers or IP address management tools to update the agency’s hardware asset inventory. Agencies might consider creating DHCP reservations for all systems with dynamic addresses in order to keep addresses from changing frequently. 5. ITS recommends maintaining active ports, services, and protocols to the hardware assets in the asset inventory. Agencies might utilize port scanning on a regular basis to review all open ports, identify any unauthorized ports, and develop this portion of the inventory. B. Each agency must ensure that unauthorized assets are either removed from the network or receives a documented exception. 1. Employing MAC-based ACL’s or other methods are highly encouraged to prevent an unauthorized host from connecting to the network. If this can be employed, reviews should be performed regularly to ensure that it is working as intended. If such technical controls cannot be implemented, network scans should be executed on a frequent basis to identify unauthorized hosts. C. ITS recommends utilizing an active discovery tool, such as a network port scanner, for updating the hardware asset inventory.

D. ITS recommends utilizing dynamic host configuration protocol (DHCP) logging on all DHCP servers or IP address management tools to update the agency’s hardware asset inventory. Agencies might consider creating DHCP reservations for all systems with dynamic addresses in order to keep addresses from changing frequently. E. ITS recommends deploying automated mechanisms to support tracking and recovery of physical devices and systems.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 1, R. 2.2 Software Inventory A

Each agency must maintain an up-to-date list of all authorized software that is required for any agency purpose on any agency system. 1. Implement a process that requires approval before new software is installed or deployed. 2. Software platform and application inventory shall be maintained and updated throughout the asset’s lifecycle (installations, removals, updates, etc.). B. Each agency must ensure that software, applications, or operating systems that have reached EOL and are no longer supported are replaced with alternatives which are supported by its respective vendor. This does not apply to in-house software development unless third-party tools or components are included within its design or functionality. 1. Unsupported software should be removed from the authorized software inventory system or at least "No longer authorized for use on agency systems". C. Each agency must ensure that unauthorized software is either removed from use on enterprise assets or receives a documented exception. This should be reviewed on a regular basis, or at least monthly. D. ITS recommends utilizing software inventory tools throughout the agency to automate the documentation of all software on agency systems. 1. The software inventory system should track the name, version, publisher, and install date for all software, including operating systems authorized by the agency. E. ITS recommends utilizing technical controls, such as application allowlisting (application control), to ensure that only authorized software can execute or be accessed. The functionality of these controls should be reviewed bi-annually, at minimum. F. ITS recommends utilizing technical controls to ensure that only authorized software libraries (such as .dell,, .ocx,, .so files) are allowed to load into a system process. Block unauthorized libraries from loading into a system process. The functionality of these controls should be reviewed bi-annually, at minimum.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 1, R. 2.3 Classification of Information Assets A

Each agency must establish a framework for classifying information

based on its sensitivity and criticality to the agency. 1. The framework applies to all data created, collected, accessed, owned, processed, maintained, stored, or transmitted by the agency and covers all employees, contractors, and third-party users who have access to this data. B. Each agency shall serve as a classification authority for its information and information assets irrespective of location, resource, or form. This includes information and/or information assets managed or hosted by third parties. 1. Data classifications are a prerequisite to establishing agency policies and guidance regarding the collection, generation, access, processing, storage, maintenance, transmission, archiving, and disposal of state data. i. In addition to the data classification requirement, ITS recommends all data have a designated data owner responsible for the identification and classification of the information they have been designated as well as establishing rules for data governance and that appropriate requirements are incorporated into agreements relating to the agency’s classified data. C. Each agency must classify data based on potential impact to the agency’s ability to accomplish its assigned mission, fulfill its legal responsibility, maintain its day-to-day functions, and protect individuals that would be caused by a loss of confidentiality, integrity, or availability of the data. 1. Confidentiality i. Preserving authorized restrictions on information access and disclosure, including means for protecting person privacy and proprietary information. A loss of confidentiality is the unauthorized disclosure of information. 2. Integrity i. Guarding against improper information modification or destruction and includes ensuring information nonrepudiation and authenticity. A loss of integrity is the unauthorized modification or destruction of information. 3. Availability i. Ensuring timely and reliable access to and use of information. A loss of availability is a disruption of access to or use of information or an information system. D. Each agency must classify data into one of three categories: Low, Moderate, and High. These categories are based on the potential impact on the agency should the data be compromised in terms of confidentiality, integrity, or availability. 1. Low

The use of the words “information” and “data” are interchangeable.

i. The loss of confidentiality, integrity, or availability could be expected to have a limited adverse effect on agency operations, agency assets or individuals. 2. Moderate i. The loss of confidentiality, integrity, or availability could be expected to have a serious adverse effect on agency operations, agency assets or individuals. 3. High i. The loss of confidentiality, integrity, or availability could be expected to have a severe or catastrophic adverse effect on agency operations, agency assets or individuals. E. Each agency must maintain an inventory of all data created, collected, accessed, stored, processed, or transmitted by agency assets, including those located on-site or at a remote service provider, classified as Moderate or High. 1. ITS recommends agencies also maintain data mapping of on-premise and off- premise systems, servers, applications, etc. that have data classified as Moderate or High. F. Each agency must determine if their information and information systems are subject to state or federal legal requirements and categorize them as required by law (i.e. HIPAA, PCI, IRS, CJIS, etc.). G. Each agency must establish a process to regularly review and adjust the appropriateness of assigned classifications throughout the lifecycle of the data. H. Each agency must ensure that data classified as Moderate or High is secured in accordance with applicable agency requirements, federal or state regulations/guidelines, and the enterprise security policy. I. Each agency must ensure that data shared, as permitted by applicable legal requirements, with any other public or private entity is classified and protected in accordance with agency and applicable legal requirements and in accordance with a document agreement detailing, at minimum, data treatment and protection requirements. J. All reproductions of information in its entirety must carry the same information classification as the original. Partial reproductions of information need to be evaluated to determine if new classifications are warranted. K. If an agency is unable to determine the classification of specific data sets, the data should be assigned a classification that is equivalent to the highest classified data in the set. L. ITS recommends all personally identifiable information (PII) be classified, at minimum, as “Moderate”. M. Agencies must adhere to all applicable privacy laws, regulations, policies, and procedures regarding the creation, collection, use, processing, storage, maintenance, dissemination, disclosure, and disposal of PII.

N. Additionally, agencies must establish administrative, technical, and physical safeguards to protect PII from unauthorized access, use, modification, loss, destruction, dissemination, or disclosure. O. ITS recommends agencies consider implementing the below recommendations as it relates to PII. 1. Agencies should only create, collect, use, process, store, maintain, disseminate, and/or disclose PII if they have legal authority to do so. i. Additionally, agencies should, to the extent practicable, seek individual consent for the creation, collection, use, processing, storage, maintenance, dissemination, or disclosure of PII.

  1. Agencies should only create, collect, use, process, store, maintain, disseminate, and/or disclose the minimum amount of PII that is relevant and necessary to accomplish its assigned mission, legally authorized purpose, maintain its day-to-day functions, and fulfill its legal responsibility. 3. In addition to establishing safeguards to protect PII as required in Rule 2.3(M), agencies that create, collect, use, access, process, maintain, share, disseminate, disclose, and/or store PII should also develop policies, procedures, and processes aligned with applicable legal requirements and privacy principles and best practices that address the preceding as well as purpose, retention, and disposal of PII. 4. Agencies should be transparent and provide notice to individuals regarding the creation, collection, use purpose, processing, storage, maintenance, dissemination, disposal, and disclosure of PII. i. Agencies should only use PII for the purpose(s) specified in the notice.

  2. Agencies should ensure PII is accurate, relevant, timely, and complete. 6. Agencies should only maintain PII for as long as legally required and/or necessary to accomplish its purpose and/or mission. 7. Training should be provided to all parties with access to and/or who use/process PII. 8. Agencies should consider the Fair Information Practice Principles (FIPPs) and/or NIST Privacy Framework when evaluating products, systems, services, solutions, processes, programs, risks, and activities involving PII and/or affecting individual privacy.

History

  • Source: Miss. Code Ann. § 25-53-201.

Chapter 3 Governance Rule 3.1 Security Policies A. Each agency must develop, implement, and maintain their individual agency IT security policies.

36 Miss. Admin. Code Pt. 1, R. 3.2 Cybersecurity Program A

Each agency must develop and implement an agency-wide cybersecurity program plan. All agency personnel should have an understanding of the cybersecurity program; however, the level of detail may vary depending on the employee's role and the sensitivity of the information. 1. The plan shall describe the agency’s current security posture, include an assessment of current risk, and a plan of action and milestones that describe current gaps in the security program and summarize the goals of the agency to address those gaps. 2. The plan shall include the assignment of roles and responsibilities, including the contact information for the designated agency Information Security Officer. 3. Each agency must provide a letter of compliance as a component of its cybersecurity program plan which describes applicable State, Federal, and Local regulations, laws, and standards it is required to satisfy. This includes compliance with the State of MS Enterprise Security Program. i. Letters of compliance must be signed by the agency head, who is responsible for the oversight of IT security. Letters of compliance must indicate that the agency head has observed, reviewed, and approved agency security processes, procedures, and practices. 4. Each agency must annually review and revise (as needed) its cybersecurity program plan to reflect relevant changes that impact the plan. B. Each agency must have a security program maturity assessment performed at least once every two (2) years. This assessment will determine the current level of compliance with the State of MS Enterprise Security Policy, identify security threats to their environment, and learn about remediation opportunities that may help to strengthen their ability to protect SOM assets from cyberthreats. 1. The program assessment must utilize an ITS-defined set of criteria to evaluate the effectiveness of the agency security program and the controls that protect the assets that support the agency. 2. The results of the assessment must be provided to ITS. 3. The cybersecurity program maturity assessment must be performed by an ITS- approved third-party cybersecurity assessment provider and can be included as part of the required comprehensive cybersecurity assessment as defined in the cybersecurity assessment chapter of this policy.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 1, R. 3.3 Legal and Regulatory Requirements A

Each agency must ensure that all applicable State and Federal legal and regulatory requirements regarding cybersecurity and information privacy and security are understood, addressed, and satisfied.

History

  • Source: Miss. Code Ann. § 25-53-201.

Chapter 4 Access Control

36 Miss. Admin. Code Pt. 1, R. 4.1 Access Management A

Each agency must limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems). For implementation, ensure that each asset has strong user authentication as well as network and local access control lists necessary to implement "need-to-know" and "least privilege". 1. Establish and follow a process, preferably automated, for granting access to enterprise assets upon new hire, modifying access, or role change of a user. i. All access to enterprise assets must be authenticated and adhere to guidance that follows; and ii. All granting of account access (assignment of privileges) must follow a strict and defined process (i.e. using account request forms and approvals thereof by the appropriate personnel). This process is preferably automated (such as the use of Privileged Access Management (PAM) systems) but can also be manual. 2. Configure data access control lists based on a user’s need to know. Apply data access control lists, also known as access permissions, to local and remote file systems, databases, and applications. 3. Establish and maintain an inventory of all accounts managed in the enterprise. The inventory must include both user and administrator accounts. The inventory, at a minimum, should contain the person’s name, username, start/stop dates, and department. Validate that all active accounts are authorized, on a recurring schedule at a minimum quarterly, or more frequently. i. For implementation, consider having respective department heads or other appropriate persons review user accounts lists provided by system administrators for each asset within the Enterprise. Any noted necessary changes should be provided to the system administrator and another account listing should be generated for subsequent review and confirmation the actions were taken. 4. Require users to authenticate to enterprise-managed VPN prior to accessing enterprise resources on end-user devices. 5. ITS recommends deploying port-level access control. Port-level access control utilizes 802.1x, or similar network access control protocols, such as certificates, and may incorporate user and/or device authentication.

i. 802.1x is preferred as it gives the greatest level of security and flexibility. However, if this is not possible, ITS recommends configuring "sticky MAC" or simply limiting the MAC address that can be used for a particular network port, especially in areas where the connected network devices do not change frequently. B. Each agency must limit system access to the types of transactions and functions that authorized users are permitted to execute. 1. Establish and follow a process, preferably automated, for revoking access to SOM assets, through disabling accounts immediately upon termination, rights revocation, or role change of a user. Disabling accounts, instead of deleting accounts, may be necessary to preserve audit trails. If an automated system cannot be implemented, ITS recommends documenting a manual checklist that is part of the HR process. 2. Establish and maintain an inventory of service accounts. The inventory, at a minimum, must contain department owner, review date, and purpose. Perform service account reviews to validate that all active accounts are authorized, on a recurring schedule at a minimum quarterly, or more frequently. i. ITS recommends that this review be conducted in conjunction with the review described in Part 1, Chapter 4, Section A.3. 3. Centralize access control for all enterprise assets through a directory service or SSO provider, where supported. 4. Manage access control for assets remotely connecting to enterprise resources. Determine amount of access to enterprise resources based on: up-to-date anti- malware software installed, configuration compliance with the enterprise’s secure configuration process, and ensuring the operating system and applications are up-to-date. 5. ITS recommends defining and maintaining role-based access control, through determining and documenting the access rights necessary for each role within the agency to successfully carry out its assigned duties. Perform access control reviews of SOM assets to validate that all privileges are authorized, on a recurring schedule at a minimum annually, or more frequently. i. Note that if the agency is utilizing the ITS-managed Enterprise VPN solution, this control will be implemented as part of that service. C. Each agency must control the flow of sensitive data in accordance with approved authorizations. 1. Document data flows. Data flow documentation includes service provider data flows into and out of the organization and should be based on the organization's data management process. Within that diagram, the organization should include mechanisms (such as firewalls) that filter the flow of data, encryption devices that protect the data, and intrusion detection systems that analyze the data. i. Review and update documentation annually, or when significant enterprise changes occur that could impact this safeguard. 2. An authoritative figure should be designated to review and approve changes to data flow prior to their implementation.

D. Each agency must separate the duties of individuals to reduce the risk of malicious activity without collusion. 1. ITS recommends defining and maintaining system access authorizations, such as roles or user groups with differing permissions, to support separation of duties. Perform authorization reviews, on a recurring schedule at a minimum annually, or more frequently. E. Each agency must employ the principle of least privilege, including for specific security functions and privileged accounts. 1. Establish and maintain a secure network architecture. A secure network architecture must address segmentation (using implementation methods such as VLAN access controls and/or firewalls to segment and protect systems), least privilege (ensuring users only have access to the systems and data required for their job), and availability (using redundant systems and data paths), at a minimum. F. Each agency must use non-privileged accounts or roles when accessing non-security functions or roles for general computing activities, such as Internet browsing. 1. ITS recommends administrator privileges to dedicated administrator accounts on SOM assets. Conduct general computing activities, such as internet browsing, email, and productivity suite use, from the user’s primary, non- privileged account. G. Each agency must prevent non-privileged users from executing privileged functions and audit the execution of such functions. 1. ITS recommends logging sensitive data access, including modification and disposal. H. Each agency must limit unsuccessful logon attempts. 1. Enforce automatic account lockout following a predetermined threshold of local failed authentication attempts. 2. The account should be locked until released by an administrator or until a specified period of time has passed. The decision for release of an account after exceeding the threshold of failed authentication attempts should be based on capabilities of the account. I. Each agency must ensure that systems have screen locks or password protected screen savers which are activated after a defined period of inactivity. 1. Configure automatic session locking on SOM assets after a defined period of inactivity. For general purpose operating systems, the period must not exceed 15 minutes. For mobile end-user devices, the period must not exceed 2 minutes. J. Each agency must terminate (automatically) a user session after an agency-defined condition or trigger events requiring session disconnect. 1. Examples of conditions or trigger events requiring automatic session termination could include defined periods of user inactivity, targeted responses to certain types of incidents, time-of-day restrictions on information system use.

K. Each agency shall display a system use notification message or banner to users before granting access to the system that provides privacy and security notices consistent with applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 1, R. 4.2 Remote Access Management A

Each agency must terminate all VPNs in the Enterprise VPN Solution managed by ITS. 1. Agencies can request an exception to this requirement for the following: i. Terminating one or more VPNs using another method other than the Enterprise VPN Solution. ii. Accessing a Virtual Desktop Infrastructure from the Internet without a VPN. 2. Agencies are required to provide documentation that justifies that the exception is required for meeting applicable security compliance requirements. 3. In any case where ITS approves an exception, the exception only applies to a singular VPN, unless otherwise specified, and said VPN must be built to meet or exceed all controls specified within the Enterprise Security Policy. B. All connections from any entities (state or third party) that reside on the outside of the Enterprise State Network must be made via a virtual private network (VPN) connection (using industry-standard IPSec or SSL protocols) or via a third-party circuit that terminates at the ITS data centers in a DMZ on the Enterprise Perimeter Firewall. 1. Determine amount of access to enterprise resources based on: up-to-date anti- malware software installed, configuration compliance with the agency’s secure configuration process, and ensuring the operating system and applications are up-to-date. 2. Require multi-factor authentication for remote network access. 3. Require users to authenticate to enterprise-managed VPN and authentication services prior to accessing enterprise resources on end-user devices. C. All connections from any entities (state or third party) that reside on the outside of the state network must be made via a virtual private network (VPN) connection using industry-standard IPSec or SSL protocols. D. VPNs may be client-based or LAN-to-LAN based. 1. Client-based VPNs are VPNs in which software (client) is installed on a remote user’s computer and a secure connection is made between that VPN client and a VPN-capable terminating device (i.e. VPN concentrator, firewall, router, server). i. All client-based VPNs must require multi-factor authentication. 2. LAN-to-LAN VPNs are VPNs that are created between a VPN-capable device on a third-party network and a VPN-capable device on the state network.

E. For client-based VPNs, split-tunneling must be disabled on any device (firewall, VPN Concentrator, etc.) used to terminate VPNs inside the state network. 1. Split tunneling is defined as having the ability to participate in a LAN while connected to the state Network via VPN. To meet the requirement of disabling split tunneling, it is required that all network activity for the client PC be redirected down the tunnel. Both listening services and browsing services must be redirected to the VPN so that no LAN activity can take place, regardless of whether it is initiated by the client PC or by another device on the LAN. 2. Any device (including SSL VPN appliances) that cannot fully disable split tunneling as it is defined above does not meet the requirements or intent of this security policy. F. All remote access across any network, internal or external to the agency environment, must employ cryptographic mechanisms to protect sensitive data. G. For both client-based and LAN-to-LAN VPNs, tunnels must be limited with access- restrictions that are granular enough to restrict all inbound traffic to both IP addresses and specific TCP/UDP ports. The list of addresses and ports allowed must only include what is necessary for the applications used by the remote users. H. Authorization for remote execution of privileged commands and remote access to security-relevant information must be limited to agency-defined needs. A privileged command is a human-initiated (interactively or via a process operating on behalf of the human) command executed on a system involving the control, monitoring, or administration of the system including security functions and associated security- relevant information. Security-relevant information is any information within the system that can potentially impact the operation of security functions or the provision of security services in a manner that could result in failure to enforce the system security policy or maintain isolation of code and data. 1. To understand and comply with this requirement, each agency should: i. Identify privileged commands (or activity) authorized for remote execution. ii. Identify security-relevant information that can be accessed remotely. iii. With these identified, it is recommended that firewall rules governing remote access be used to enforce these restrictions. Further, users with privileged access should be trained and aware of this policy. I. All remote access to the Enterprise State Network must be revoked immediately upon the retirement, resignation, dismissal, end of contract, or all other actions that signal that the requirements for having a connection are no longer valid. J. At no time should any employee, vendor or account holder provide their remote access credentials (user information or password) to anyone. Employees, vendors, or account holders must be assigned individual accounts. K. All remote access (VPN and other remote access types) must require multi-factor authentication.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 1, R. 4.3 Wireless Access A

Each agency must ensure that all Wireless Local Area Networks (WLANS) are configured securely. 1. Authorize each type of wireless access prior to allowing such connections by establishing and maintaining a secure configuration process for network devices such as the access point and switches supporting the wireless access. 2. Protect wireless access using secure network management (TLS, SSH) and communication protocols (WPA2 and WPA3). 3. Utilize the Advanced Encryption Standard (AES) for wireless access. 4. Each agency must ensure that their wireless deployment encryption keys are rotated regularly and frequently (at least every 6 months). Further, all encryption keys should be changed if wireless access must be revoked (such as after termination or transfer of an employee). 5. ITS recommends disabling wireless access on devices that do not have a business purpose for wireless access. 6. ITS recommends disabling peer-to-peer wireless network capabilities on wireless clients. 7. ITS recommends configuring wireless access on client machines that do have an essential wireless business purpose, to allow access only to authorized wireless networks and to restrict access to other wireless networks. 8. ITS recommends ensuring that wireless networks use authentication protocols such as Extensible Authentication Protocol-Transport Layer Security (EAP/TLS) to provide credential protection and mutual authentication. 9. ITS recommends disabling wireless peripheral access of devices (such as Bluetooth), unless such access is required for a documented business need. B. Each agency must ensure that guest/public users are not permitted access to the state network resources. 1. Agencies wishing to provide Internet access to a guest user must utilize one of the following approved methods: i. Installing separate equipment and a separate circuit for guest users. Contact ITS for more information on this method of connectivity. ii. Tunneling guest user traffic to an ITS DMZ via a wireless controller solution implemented by ITS. Contact ITS for more information on this method of connectivity. 2. Both methods require: i. No ports opened inbound to guest users. ii. All guest user traffic must be filtered.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 1, R. 4.4 Portable and Mobile Device Access A

Each agency must ensure that all portable and mobile devices are controlled and configured securely. Portable and mobile devices are computing devices that have a small form factor such that it can easily be carried by a single individual; is designed

to operate without a physical connection; possesses local, non-removable or removable data storage; and includes a self-contained power source. Portable and mobile device functionality may also include voice communication capabilities, on- board sensors that allow the device to capture information, and/or built-in features for synchronizing local data with remote locations. Examples include smart phones, laptops, and tablets. These devices are typically associated with a single individual. 1. Where possible, require multi-factor access for portable and mobile devices. B. Each agency must ensure that all confidential information stored or processed on portable and mobile devices is encrypted (whole-disk encryption, full-device encryption, container-based encryption, etc.). 1. Utilize technology that can remotely wipe portable and mobile devices when deemed appropriate such as lost or stolen devices, or when an individual no longer supports the enterprise. 2. ITS recommends using a management platform that allows central administration of the appropriate security policy to all devices supported by the agency. C. Each agency must enforce automatic device lockout following a predetermined threshold of local failed authentication attempts on all portable and mobile devices. 1. For laptops, do not allow more than 20 failed authentication attempts: for tablets and smartphones, no more than 10 failed authentication attempts. D. Each agency must ensure that any device connected to the Enterprise State Network has only one active connected network interface at any time. For example, if plugged into Ethernet, Wi-Fi is disabled.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 1, R. 4.5 External Information Systems A

Each agency must establish and maintain an inventory of all known service providers approved to access SOM assets or approved to process, store, or transmit SOM data. 1. The inventory includes classification(s), and the designated enterprise contract(s) for each service provider. 2. Classification consideration may include one or more characteristics, such as data sensitivity, data volume, availability requirements, applicable regulations, inherent risk, and mitigated risk. 3. Review and update the inventory annually, or when significant enterprise changes occur that could impact this safeguard. B. Each agency must ensure service provider contracts include appropriate security requirements. More details about security requirements for cloud and offsite hosting services are included in the Enterprise Cloud and Offsite Hosting Security Policy on the ITS website. C. Each agency must control sensitive information that is posted or processed on publicly accessible systems.

History

  • Source: Miss. Code Ann. § 25-53-201.

Chapter 5 Awareness and Training

36 Miss. Admin. Code Pt. 1, R. 5.1 User Awareness Education and Training A

Each agency must ensure all employees, associates, business partners, and others using SOM systems and data are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures related to the security of those systems and data. B. Each agency must implement and maintain a security awareness training program for all agency users (including managers, senior executives, and contractors) to educate them on how to interact with SOM systems and data in a secure manner. 1. Conduct training at hire and, at a minimum, annually. 2. Train agency users to recognize social engineering attacks, such as phishing, pre-texting, and tailgating. 3. Train workforce members on authentication best practices. Example topics include MFA, password composition, and credential management. 4. Train workforce members on how to identify and properly store, transfer, archive, and destroy sensitive data. This also includes training workforce members on clear screen and desk best practices, such as locking their screen when they step away from their enterprise asset, erasing physical and virtual whiteboards at the end of meetings, and storing data and assets securely. 5. Train workforce members to be able to recognize a potential incident and be able to report such an incident. 6. Train workforce to understand how to verify and report out-of-date software patches or any failures in automated processes and tools. Part of this training should include notifying IT personnel of any failures in automated processes and tools. 7. Train workforce members on the dangers of connecting to, and transmitting data over, insecure networks for enterprise activities. If the enterprise has remote workers, training must include guidance to ensure that all users securely configure their home network infrastructure. 8. Ensure that the security awareness program and related content is updated frequently (at least annually) to address new technologies, threats, standards and business requirements. 9. Train workforce members to be aware of causes for unintentional data exposure. Example topics include mis-delivery of sensitive data, losing a portable end-user device, exposing sensitive data in artificial intelligence models, or publishing data to unintended audiences. 10. Each agency must determine the method of training, weighing the convenience of computer-based training against the value of live classroom training. i. Agencies electing to use computer-based training must adhere to the enterprise standard for security awareness and education training. More information about enterprise standards can be found on ITS’s website.

C. Each agency must ensure that users are trained to carry out their assigned cybersecurity-related duties and responsibilities. 1. Conduct role-specific security awareness and skills training. Example implementations include secure system administration courses for IT professionals, OWASP® Top 10 vulnerability awareness and prevention training for web application developers, advanced social engineering awareness training for high-profile roles, and specific training for personnel who maintain or secure operational technology (OT) as part of their regular duties. OT encompasses the hardware and machines responsible for the physical security processes. 2. ITS recommends each agency train personnel responsible for IT and OT assets on how to effectively respond to OT cyber incidents. D. Each agency must provide security awareness training on recognizing and reporting potential indicators of insider threats.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 1, R. 5.2 Senior Executives Roles and Responsibilities A

Each agency head must clearly communicate to senior executives their roles, as well as the responsibilities that accompany those roles. B. Each agency head must participate in annual information security training designed specifically for the agency head to ensure that the agency head has an understanding of: 1. The information and information systems that support the operations and assets of the agency. 2. The potential impact of common types of cyber-attacks and data breaches on the agency’s operations and assets. 3. How cyber-attacks and data breaches on the agency’s operations and assets could impact the operations and assets of other state agencies on the Enterprise State Network. 4. How cyber-attacks and data breaches occur. 5. Steps the agency head and agency employees should take to protect their information and information systems. 6. The annual reporting requirements required of the agency head.

History

  • Source: Miss. Code Ann. § 25-53-201.

Chapter 6 Audit and Accountability

36 Miss. Admin. Code Pt. 1, R. 6.1 Audit and Accountability A

Each agency must create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity. 1. Establish and maintain a process for managing audit logs. This process should include documented policy which addresses the sensitivity of the agency’s

audit logs, personnel who will retain ownership of audit logs, log handling procedures, and log disposal requirements. Review and update documentation annually, or when significant agency changes occur that could impact this safeguard. 2. Ensure the audit log management process defines the agency’s logging requirements. At a minimum, address the collection, review, and retention of audit logs for agency assets. 3. Collect audit logs for all agency assets (especially those processing, storing, or transmitting sensitive data) as defined in the collection requirements of the audit log management process. 4. Ensure that all audit logs, if applicable, include event source, date, username, timestamp, source addresses, destination addresses, and other useful elements that could assist in a forensic investigation. 5. Ensure that logging destinations maintain adequate storage to comply with the agency’s audit log management process. 6. Collect DNS query audit logs on agency assets, where appropriate and supported. 7. Collect URL request audit logs on agency assets, where appropriate and supported. 8. Collect command-line audit logs, where appropriate and supported. Example implementations include collecting audit logs from PowerShell®, BASH™, and remote administrative terminals. 9. Centralize, to the extent possible, audit log collection and retention across agency assets. This ensures security event alerting for all agency assets can be easily correlated and analyzed. An example of this would be a central log server or SIEM that collects and stores all agency asset logs. 10. Ensure that audit logs are maintained based on agency audit log management processes and include a minimum retention of at least 90 days and a maximum retention timeline. 11. ITS recommends logging access to sensitive audit log data, including modification and disposal, to include both the account accessing log data as well as timestamps. 12. ITS recommends collecting service provider logs, where supported. Examples include collecting authentication and authorization events, data creation and disposal events, and user management events. B. Each agency's use of audit logs must ensure that the actions of individual system users can be uniquely traced to those users, so they can be held accountable for their actions. C. Each agency must conduct reviews of audit logs to detect anomalies or abnormal events that could indicate a potential threat. Conduct reviews on a weekly, or more frequent, basis. D. Each agency must define processes for alerting in the event of an audit logging failure. These processes should include defined actions to be taken when an alert is received. Examples of audit log failures includes events such as log disks becoming

full or corrupted. Examples of alerts could be automated emails to be sent to log management personnel. E. Each agency must implement a process to review, analyze, and report correlated audit logs for investigation and response to indications of unlawful, unauthorized, suspicious, or unusual activity. F. Each agency must centralize security event alerting across agency assets for log correlation and analysis. 1. ITS recommends the use of a SIEM, which includes vendor-defined event correlation alerts. A log analytics platform configured with security-relevant correlation alerts also satisfies this safeguard. G. Each agency must configure logging to utilize internal system clocks within each agency asset to generate time stamps for audit logs. 1. Standardize time synchronization across all agency assets. At least two synchronized and authoritative time sources should be used in each agency asset, where supported. Examples of time sources are network time protocol (NTP) time servers. Agencies on the State network have the option of using the ITS time servers (tick.its.ms.gov and tock.its.ms.gov). 2. ITS recommends implementing a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records. Examples of time synchronization services and assets include Windows Time Service (W32Time) and separate, internal Network Time Protocol (NTP) servers. H. Each agency must protect audit information and audit logging tools from unauthorized access, modification, and deletion. 1. ITS recommends encrypting logs for maintaining integrity and confidentiality of sensitive data. I. Each agency must limit management of audit logging functionality to a subset of privileged users. This includes the ability to view, edit, and delete logs, as well as permissions necessary to change logging configurations. 1. ITS recommends defining and maintaining role-based access control, through determining and documenting the access rights necessary for management of audit logging functionality within the agency. Perform access control reviews of agency assets to validate that all privileges are authorized, on a recurring schedule at a minimum annually, or more frequently.

History

  • Source: Miss. Code Ann. § 25-53-201.

Chapter 7 Configuration Management

36 Miss. Admin. Code Pt. 1, R. 7.1 Configuration Management A

Each agency must establish and maintain baseline configurations of agency systems (including hardware, software, and firmware) throughout the respective system development life cycles.

B. Each agency must establish and maintain a secure configuration process for agency assets. Review and update documentation annually, or when significant enterprise changes occur. 1. Securely manage network infrastructure. Example implementations include version-controlled-infrastructure-as-code, and the use of secure network protocols, such as SSH and HTTPS as opposed to Telnet and HTTP. 2. Use standard, industry-recommended hardening configuration templates for application infrastructure components. This includes underlying servers, databases, and web servers, and applies to cloud containers, Platform as a Service (PaaS) components, and SaaS components. Do not allow in-house developed software to weaken configuration hardening. C. Each agency must track, review, approve or disapprove, and log meaningful changes to agency systems. 1. This can be accomplished through a number of ways provided they are fully implemented and utilized for all changes. For example, specialized software packages can be licensed for this purpose or for smaller environments, adequately designed spreadsheets could be utilized. Ultimately, as long as all meaningful changes are tracked, reviewed, and approved, the solution to do this is irrelevant. 2. Less meaningful changes that the agency determines doesn’t need to be reviewed and approved should be logged for historical reference. D. Each agency must analyze the security impact of changes prior to implementation and ensure documentation is updated. 1. Any configuration change which is identified as resulting in a meaningful impact to the agency’s functionality (i.e. installation of new software or hardware, implementation of new methods for granting or removing access, etc.) should be reviewed, its impact considered, and the change documented prior to its rollout. E. Each agency must review, approve or disapprove, and enforce physical and logical access restrictions associated with changes to agency systems. 1. These access appointments should be documented or otherwise logged via either logical or physical mediums, such as permission delegation via Active Directory or physical sign-in sheets placed at entry points. F. Each agency must employ the principle of least functionality by configuring agency systems to provide only essential capabilities. G. Each agency must uninstall or disable unnecessary services on enterprise assets and software, such as an unused file sharing service, web application module, or service function. H. Each agency must use technical controls (when possible), such as application allowlisting, to ensure that only authorized software can execute or be accessed. Reassess this allowlist bi-annually at minimum, or more often if significant change to software inventory necessitates.

I. ITS recommends using software inventory tools, when possible, throughout the enterprise to automate the discovery and documentation of installed software.

History

  • Source: Miss. Code Ann. § 25-53-201.

Chapter 8 Identification and Authentication

36 Miss. Admin. Code Pt. 1, R. 8.1 Identification and Authentication Management A

Each agency must identify system users, processes acting on behalf of users, and devices. Typically, individual identifiers are the usernames associated with the system accounts assigned to those individuals. Additionally, common device identifiers can include: media access control (MAC), Internet protocol (IP) addresses, device-unique token identifiers. B. Each agency must establish and follow an authentication process, preferably automated, for granting access to enterprise assets upon new hire, rights grant, or role change of a user. 1. All access to enterprise assets must be authenticated and adhere to guidance that follows; and 2. All granting of account access (assignment of privileges) must follow a strict and defined process (i.e. using account request forms and approvals thereof by the appropriate personnel). This process is preferably automated (such as the use of Privileged Access Management (PAM) systems) but can also be manual. C. Each agency must use multifactor authentication (MFA) for local (console or other direct access) and network access (any access that occurs over a network of any type) to privileged accounts and for network access to non-privileged accounts. For network access, this includes such protocols as RDP, SSH, and VDI. Multifactor authentication requires the use of two or more different factors to authenticate. The factors are defined as something you know (e.g., password, personal identification number [PIN]); something you have (e.g., cryptographic identification device, token); or something you are (e.g., biometric). 1. Require MFA for all administrative access accounts, where supported, on all enterprise assets, whether managed on-site or through a third-party provider. 2. Require all externally exposed agency or third-party applications (such as Box, 365, etc.) to enforce MFA, where supported. Enforcing MFA through a directory service or single sign on (SSO) provider is a satisfactory implementation of this requirement. This includes public access to state licensure sites. 3. Where MFA authentication is not supported (such as local administrator, root, or service accounts), accounts must use passwords that contain at least fourteen (14) characters and are unique to that system. The passwords should be changed when the account is believed to have been breached or otherwise compromised in any way.

D. Each agency must implement replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts. 1. Authentication processes resist replay attacks if it is impractical to successfully authenticate by recording or replaying previous authentication messages. For example, Windows systems not in a domain rely on NTLM and NTLMv2 authentication. These protocols are vulnerable to replay attacks. Join workstations to a domain to ensure Kerberos is used as an authentication protocol (which is not vulnerable to replay attacks). As an alternative, use a one-time password authentication mechanism (such as an RSA token) for logging into systems. E. Each agency must prevent reuse of identifiers for an agency-defined period. For example, when a user leaves an agency, the username assigned to that user should not be re-used for a specified period (such as 6 months). F. Each agency must disable identifiers after an agency-defined period of inactivity (such as 45 days). G. Each agency must enforce minimum password requirements for all non-administrator accounts. At minimum, the guidelines must adhere to the detailed guidance in NIST 800-63B section 5.1, 5.1.1.1, 5.1.1.2 and the additional requirements below. 1. Passwords must be unique per unique account. If one username/account is used across multiple assets, it must employ a unique password on each. 2. Passwords must contain at least 8 characters for accounts using MFA and 14 characters for accounts not using MFA. 3. Passwords must not be disclosed to anyone except in emergency circumstances or when there is an overriding operational necessity. 4. Usernames must be unique per user. Further, “group” or shared accounts should not be utilized. 5. Default passwords must adhere to the requirements of this section and must be changed upon initial authentication by the user. During account creation or password resets, unique passwords should be set for each account as opposed to using a common, default password for multiple users. 6. Passwords must be required on all user accounts. 7. Each agency must prohibit automated/scripted password input. H. Each agency must use industry-standard encryption standards to encrypt passwords when stored or in transit. At a minimum, encryption shall meet or exceed AES 128- bit and TLS 1.3.

History

  • Source: Miss. Code Ann. § 25-53-201.

Chapter 9 Incident Response

36 Miss. Admin. Code Pt. 1, R. 9.1 Incident Response Management A

Each agency must establish and maintain an incident response process that addresses roles and responsibilities, compliance requirements, and a communication plan.

  1. Each agency must ensure that their incident response process is appropriately aligned with the State of MS’s Enterprise Cybersecurity Incident Response Plan. The enterprise plan can be found on the ITS website (www.its.ms.gov). 2. Review the incident response process annually, or when significant agency changes occur that could impact this safeguard. This may include changes to network architecture which may affect business continuity, perceived or realized security events, or other modifications to an agency's infrastructure which alter business flow. 3. In addition to maintaining an electronic version of the incident response plan, all agencies must prepare a hard copy which is maintained and accessible to appropriate staff. B. Each agency must designate one key person, and at least one backup, who will manage the agency’s incident handling process. 1. Management personnel are responsible for the coordination and documentation of incident response and recovery efforts and can consist of employees internal to the enterprise, third-party vendors, or a hybrid approach. If using a third-party vendor, designate at least one person internal to the agency to oversee any third-party work. All agencies must document whether incident response is handled internally or via a third-party vendor and shall retain any documentation describing agreements made with external service providers. 2. Review the management personnel designations annually, or when significant agency changes occur that could impact this safeguard. C. Each agency must assign key roles and responsibilities for incident response, including staff from legal, IT, information security, facilities, public relations, human resources, incident responders, and analysts, as applicable. All assignments must be documented as a component of the agency Incident Response plan. 1. Review key roles and responsibilities annually, or when significant agency changes occur that could impact this safeguard. D. Each agency must determine which primary and secondary mechanisms will be used to communicate and report during a security incident. Mechanisms can include phone calls, emails, or letters. Keep in mind that certain mechanisms, such as emails, can be affected during a security incident. 1. Review communication mechanisms annually, or when significant agency changes occur that could impact this safeguard. E. Each agency must track, document, and report incidents to designated officials and/or authorities both internal and external to the agency. 1. Establish and maintain contact information for parties that need to be informed of security incidents. Contacts may include internal staff, third-party vendors, law enforcement, cyber insurance providers, relevant government agencies, or other stakeholders. Verify contacts annually to ensure that information is up to date. 2. Establish and maintain an agency process for the workforce to report security incidents. The process includes reporting timeframe, personnel to report to, mechanism for reporting, and the minimum information to be reported. Ensure

the process is publicly available to all of the workforce. Review annually, or when significant agency changes occur that could impact this safeguard. 3. Each agency must report all cybersecurity incidents to ITS involving their information and information systems, whether managed by the state agency, contractor, or other source. Please refer to the State of MS’s Enterprise Cybersecurity Incident Reporting Guidelines document for more detailed information on reporting cybersecurity incidents and timelines. The document can be found on the ITS website (www.its.ms.gov). F. Each agency must test the agency incident response capability. 1. Plan and conduct routine incident response exercises and scenarios for key personnel involved in the incident response process to prepare for responding to real-world incidents. Exercises need to test communication channels, decision making, and workflows. Conduct testing on an annual basis, at a minimum. G. Each agency must conduct post-incident reviews. Post-incident reviews help prevent incident recurrence through identifying lessons learned and follow-up action. 1. Document the way the incident was identified, actions taken in response to the incident, and any impact to agency resources or functionality incurred as a result of the incident. 2. Lessons learned from post-incident reviews must be documented and deficiencies must be addressed in a timely fashion. Actions taken to remediate known identified deficiencies must be documented. H. ITS recommends that each agency establish and maintain security incident thresholds, including, at a minimum, differentiating between an incident and an event. A security event is an observed change to the normal behavior of a system, environment, process, workflow, or person. Examples of events may include router ACLs were updated; firewall policy was pushed. An incident is an event that negatively affects the confidentiality, integrity, and/or availability in a way that impacts the agency. Examples: attacker posts company credentials online, attacker steals customer credit card database, worm spreads through network. 1. Review the post-incident process annually, or when significant agency changes occur that could impact this safeguard.

History

  • Source: Miss. Code Ann. § 25-53-201.

Chapter 10 Maintenance

36 Miss. Admin. Code Pt. 1, R. 10.1 Maintenance Management A

Each agency must establish and maintain procedures and processes for performing maintenance on agency IT systems. 1. Ensure all potentially impacted security controls are still functioning properly following maintenance, repair, or replacement actions.

  1. Approve and monitor all maintenance activities, whether performed on site or remotely and whether the system or system components are serviced on site or removed to another location. B. Each agency must approve, control, and monitor the use of system maintenance tools. C. Each agency must ensure equipment removed for off-site maintenance is sanitized of any sensitive or confidential information. D. Each agency must assess media containing diagnostic and test programs for malicious code before the media are used in agency IT systems. E. Each agency must require multifactor authentication to establish maintenance sessions via external (nonlocal) network connections and terminate such connections when maintenance session is complete. F. Each agency must supervise the maintenance activities of maintenance personnel without required access authorization.

History

  • Source: Miss. Code Ann. § 25-53-201.

Chapter 11 Media Protection

36 Miss. Admin. Code Pt. 1, R. 11.1 Media Protection A

Each agency must protect (i.e., physically control and securely store) all sensitive stored data, both hard copy and digital media, on all systems (agency-managed and hosted). All sensitive data on digital media must be protected using an encryption protocol. 1. Media is defined as any medium in which data can be stored, recorded, or printed. This includes both digital and non-digital media. i. Digital media is a form of content that is stored in a digital format, which can be easily accessed and manipulated using electronic devices. Examples of electronic devices include but are not limited to computers, smartphones, tablets, flash storage, diskettes, magnetic tapes, external or removable hard disk drives (e.g., solid state, magnetic), compact discs, and digital versatile discs. Digital media encompasses a wide range of multimedia content, including text, images, audio, video, and interactive elements, and it is often distributed through the internet and various digital communication channels. 2. Non-digital media includes all data storage and records which are not stored within an electronic device. This includes but is not limited to paper and microfilm. 3. Securely storing sensitive digital data includes implementing industry approved encryption protocols. All media storage devices that store sensitive data should employ a hardware-level encryption solution, such as Windows BitLocker or Linux dm-crypt. All portable media must employ an encryption methodology that requires a password, token, or other means of authentication to decrypt.

  1. All devices which store sensitive information must be included in an automated or manually maintained inventory. Each agency must employ a procedure for documenting access requests and the return of both digital and non-digital storage media. Digital media storage devices should be cataloged with a make, model, and other identifying information, as well as the responsible party. 5. Media storage solutions must be appropriate for the data which it will contain. For example, backups of sensitive data should be stored via encrypted hard drives or tapes as opposed to flash drives. All media storage devices and records should be classified according to the sensitivity of the data stored within. 6. Storage media may not be subject to the above security standards if it only contains data that has been determined to be in the public domain, publicly releasable, or have limited adverse impacts if accessed by other than authorized personnel. Each agency must employ a process classifying sensitive and non-sensitive data that includes approval by key stakeholders. B. Each agency must limit access to sensitive data on digital and non-digital media to only authorized users based on a user’s need to know. 1. Apply data access control lists, also known as access permissions, to local and remote file systems, databases, and applications. C. Each agency must sanitize or destroy digital and non-digital system media containing sensitive data before disposal or release for reuse. 1. Establish a data retention policy that defines when sensitive data must be destroyed. 2. Ensure the disposal process and method are commensurate with the data sensitivity. 3. Examples of the types of digital media include scanners, copiers, printers, notebook computers, workstations, network components, mobile devices. 4. Examples of the types of non-digital media include paper and microfilm. 5. Sanitize or destroy digital and non-digital system media containing sensitive data before disposal or release for reuse. i. The sanitization process removes information from system media such that the information cannot be retrieved or reconstructed. ii. Acceptable sanitization techniques may include clearing, purging, cryptographic erasure of digital media, de-identification of personally identifiable information, and destruction. Non-digital media should be thoroughly scrubbed to remove all sensitive data prior to release or rendered irrecoverable via cross-cut shredding or incineration. Digital media should be destroyed via methods such as low-level wiping, degaussing, or physical destruction. 6. Ensure that all sensitive data stored and/or hosted by third parties is sanitized or destroyed. The agency should require that the third-party provide certificates of destruction or sanitization when the process is complete. 7. Ensure that appropriate confidentiality agreements are in place for all sensitive agency data stored and/or hosted by third parties.

D. Each agency must review sensitive data and determine if the media should be marked with necessary confidentiality markings and distribution limitations. 1. Examples of where data may not need to be marked include publicly releasable data or data that remains in secure areas controlled by the agency. E. Each agency must control access to media containing sensitive data when outside of controlled areas via hardware-level encryption or password authentication on all digital media. 1. All media, both digital and non-digital must be assigned to a responsible party prior to its departure from a controlled area via a documented process. This may be satisfied through a log sheet that denotes the responsible party and a timestamp of the media’s departure and return or an automated inventory system. F. Each agency must encrypt sensitive data stored on digital media. G. Each agency must control the use of removable media on system components. 1. Limit the use of portable storage devices to only approved devices, including devices provided by the agency, devices provided by other approved entities, and devices that are not personally owned. 2. Portable storage devices must be restricted to functionality only necessary for their intended purpose. Devices which do not require the ability to be written to should be configured as “Read Only”. 3. Disable autorun and autoplay functionality for removable media. 4. Configure antimalware software to automatically scan removable media. H. Each agency must prohibit the use of portable storage devices when such devices have no identifiable owner. I. Each agency must protect recovery/backup data with equivalent controls to the original data. This includes encryption and data separation, based on requirements.

History

  • Source: Miss. Code Ann. § 25-53-201.

Chapter 12 Personnel Security

36 Miss. Admin. Code Pt. 1, R. 12.1 Personnel Security Protection A

Each agency must screen individuals prior to authorizing access to any non-public agency systems or data. Screening activities include but are not limited to the evaluation/assessment of an individual’s conduct, integrity, judgment, loyalty, reliability, and stability (i.e., the trustworthiness of the individual). 1. Ensure that all staff which are provided access to non-public data are subject to, at a minimum, background checks in accordance with applicable laws. B. Each agency must ensure that access to agency systems and data are protected during and after personnel actions such as terminations and transfers. 1. Establish a documented process for disabling user access within a predefined time upon employee departures. This may include disabling or deleting user accounts, VPN access, and the return or disablement of access tokens and

keys. 2. Consider timely execution of termination actions for individuals terminated for cause. In certain situations, agencies must consider disabling the system accounts of individuals that are being terminated prior to the individuals being notified. 3. Ensure that all security-related agency system-related property is retrieved and retain access to all agency information and systems formerly controlled by the terminated individual.

History

  • Source: Miss. Code Ann. § 25-53-201.

Chapter 13 Physical Protection

36 Miss. Admin. Code Pt. 1, R. 13.1 Physical Protection A

Each agency must limit physical access to agency systems, equipment, and the respective operating environments to authorized individuals. Limiting physical access requires the implementation of physical security controls to restrict an individual’s ability to interface with a given device. 1. Limiting physical access should be applied to all individuals who enter its facility or perimeter. This includes, but is not limited to staff, visitors, and other third parties which retain access credentials. 2. Develop and maintain documented processes which describe the methods in which they restrict access and enforce physical access authorizations, to include the location of mission critical devices and systems, their applicable physical security control, and how access is delegated and removed from users. i. Limiting physical access to equipment may include placing equipment in locked rooms or other secured areas and allowing access to authorized individuals only; and placing equipment in locations that can be monitored by organizational personnel. Computing devices, external disk drives, networking devices, monitors, printers, copiers, scanners, facsimile machines, and audio devices are examples of equipment. B. Each agency must protect and monitor the physical facility and support infrastructure for agency systems. Known or observed vulnerabilities or gaps in the physical security of an organization’s perimeter or facility must be addressed immediately. C. Each agency must escort visitors and monitor and control visitor activity. 1. Individuals with permanent physical access authorization credentials are not considered visitors. Audit logs can be used to monitor visitor activity. D. Each agency must maintain and audit logs of physical access. 1. Audit logs can be procedural (e.g., a written log of individuals accessing the facility), automated (e.g., capturing ID provided by an access card/badge), or some combination thereof. Physical access points can include facility access points, interior access points to systems or system components requiring

supplemental access controls, or both. System components (e.g., workstations, notebook computers) may be in areas designated as publicly accessible with organizations safeguarding access to such devices. 2. ITS recommends that agencies review physical access logs monthly and upon occurrence of detected and/or suspected physical security incidents/violations. E. Each agency must control and manage physical access devices. 1. Physical access devices include but are not limited to keys, locks, combinations, biometric readers, and card readers. These devices must be secured when not in use. 2. Document the location in which access devices and keys are stored as well as individuals which are granted access to them. 3. Inventory physical access devices at least annually. 4. Change physical access devices (e.g., combinations and keys) at minimum yearly and/or when keys are lost, combinations compromised, or when individuals possessing the keys or combinations retire, leave, and/or are transferred or terminated and/or access is no longer needed. F. Each agency must ensure protections for agency systems are in place for alternate work sites. 1. Alternate work sites may include government facilities or the private residences of employees.

History

  • Source: Miss. Code Ann. § 25-53-201.

Chapter 14 Risk Assessment

36 Miss. Admin. Code Pt. 1, R. 14.1 Risk Assessments A

Each agency must periodically assess the risk to agency operations resulting from the operation of agency systems and the associated processing, storage, or transmission of data. B. Each agency must conduct a risk assessment that considers threats, vulnerabilities, likelihood, and impact to agency operations and assets, individuals, other organizations, and state government. 1. Identify threats and vulnerabilities to agency systems. i. An inventory of all hardware, software, and user access must be established and maintained as an agency experiences any substantive change. Please refer to Part 1, Chapter 2, 2.1 System and Physical Device Inventory. 2. Identify threats and vulnerabilities from third parties, including, but not limited to, third parties who operate systems on behalf of the agency and/or process, store, or transmit information on behalf of the agency. i. Identify all third parties which provide functionality to the organization via either hardware or software. Agencies will inventory and document the data and network resource access that all third parties are provided access.

ii. Determine the sensitivity of data that each third party is provided access to and incorporate said access into its risk assessment. iii. Define the legal and regulatory standards that the data accessible to the third party is subject to and establish contracts or other Service Level Agreements to describe the ability and expectation of the vendor to satisfy the applicable standard. iv. Monitor and ensure (to the extent possible) that the third party meets the expectations of any agreement or contractual obligation regarding information security and/or privacy. 3. Determine the likelihood and magnitude of harm from unauthorized access, use, disclosure, disruption, modification, loss, or destruction of/to the system and/or the information it processes, stores, or transmits, and any related information. 4. Determine the likelihood and impact of adverse effects on individuals arising from the collection and/or processing of personally identifiable information (PII). i. ITS recommends agencies conduct privacy impact and/or privacy risk assessments to help determine the likelihood and impact of adverse effects for PII. A privacy risk and/or privacy impact assessment evaluates the risks, controls, and consequences associated with collecting, maintaining, using, and/or disclosing personally identifiable information (within and outside of the agency) so that the agency can make informed decisions regarding risk mitigation, protection of the data, and compliance with applicable legal requirements and best practices.

  1. Integrate risk assessment results and risk management decisions from the agency and mission or business process perspectives with system-level risk assessments. 6. Document risk assessment results in appropriate agency security and privacy plans. 7. Respond to findings from security and privacy assessments, monitoring, and audits in accordance with agency risk tolerance and update the risk assessment as needed. 8. Review and update the risk assessment, as needed, in accordance with agency risk tolerance based on security and privacy assessments, monitoring, and audits; supply chain issues; security incidents or breaches; changes in law, executive orders, directives, regulations, policies, standards, or guidelines; and changes to and/or availability of new technologies, individuals, external parties, and assets in accordance with agency risk tolerance. C. Each agency must perform automated vulnerability scans for vulnerabilities in agency systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified. 1. Perform automated vulnerability scans of internal agency assets on a monthly, or more frequent, basis. Conduct both authenticated and unauthenticated

scans, using a SCAP-compliant vulnerability scanning tool. The agency must maintain the results of vulnerability scans for a period of at least one year. 2. Perform automated vulnerability scans of externally exposed agency assets using a SCAP-compliant vulnerability scanning tool. Perform scans on a monthly, or more frequent, basis. The agency must maintain the results of vulnerability scans for a period of at least one year. D. Each agency must remediate detected vulnerabilities on a monthly, or more frequent, basis, based on the remediation process.

History

  • Source: Miss. Code Ann. § 25-53-201.

Chapter 15 Cybersecurity Assessments

36 Miss. Admin. Code Pt. 1, R. 15.1 Cybersecurity Assessments A

Each agency must conduct a comprehensive cybersecurity assessment at least once every two years to evaluate the security controls in agency systems to determine if the controls are effective in their application and to identify the current security posture of its information systems and the agency. Cybersecurity assessments must also include external parties, including, but not limited to, service providers, contractors/third parties, etc. who operate systems on behalf of the agency and/or process, store, or transmit information on behalf of the agency. 1. Each agency must employ an ITS-approved independent, impartial third-party provider to conduct the comprehensive cybersecurity assessment. Comprehensive cybersecurity assessments must include at minimum the below and should be modeled from all guidelines specified in the Comprehensive Cybersecurity Assessment Guidelines document that can be found on the ITS website. i. Perform an assessment of the security controls in the information systems and their environment of operation to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting established security requirements. ii. Incorporate results from other types of assessment activities such as vulnerability scanning and system monitoring, to maintain the security and privacy posture of systems during the system life cycle. iii. Perform external and internal penetration tests to identify vulnerabilities and attack vectors that can be used to exploit agency systems. a. Penetration testing must be appropriate to the size, complexity, and maturity of the agency environment. Penetration testing activities include scope, such as network, web application, Application Programming Interface (API), hosted services, and physical premise control. 1. Cloud-based services which are identified as a

component of agency business functionality must be included in Security Assessments. This includes cloud- based backup solutions, user access control platforms (e.g. Microsoft 365), file-sharing and storage platforms (e.g. SharePoint, Box), and other Content Management Systems (e.g. AWS, Akamai). b. Penetration testing must occur from outside the agency’s network perimeter (i.e., outside the agency's firewall but inside the Enterprise State Network’s security border) as well as from within the agency’s boundaries (i.e., on the internal agency network) to simulate both outsider and insider attacks. Penetration testing helps determine the minimum set of controls required to reduce and maintain risk at an acceptable level. c. Control and monitor any user or system accounts that are used to simulate both outsider and insider attacks to ensure they are only being used for legitimate purposes and are removed or restored to normal function after testing is completed. d. Validate security measures after each penetration test. If deemed necessary, modify rulesets and capabilities to detect the techniques used during testing. e. Validated vulnerabilities discovered during the penetration tests must be documented and mitigated in a timely manner. 1. Vulnerabilities should be prioritized based on the criticality of both the vulnerability and the system/application. f. Penetration tests should include a full scope of blended attacks, such as wireless, client-based, and web application attacks. g. Agencies which develop in-house applications that have a defined development cycle will create a test bed that mimics a production environment for specific penetration tests attacks against elements that are not typically tested in production, such as attacks against supervisory control and data acquisition and other control systems. iv. Perform social engineering training campaigns and simulated threats to assess the security posture and employee adherence to established security policies and practices. This may include either email phishing, voice vishing, or a combination of both attacks. Testing should not be designed to target a specific person, but rather target the corporate culture, to include all agency staff. v. Cybersecurity assessments must include applications to ensure key security and privacy requirements are met. Code in the application and supporting infrastructure must be tested for common errors that can compromise the integrity of the production environment when the application is deployed. a. ITS recommends that all new applications have a

comprehensive assessment performed by a third-party prior to its release into a production environment. vi. ITS recommends performing advanced persistent threat (APT) assessments to identify weaknesses that could be used in a targeted and/or advanced attack. The goal of an APT is to gain access, escalate privileges, and remain hidden so as to exfiltrate sensitive data. This type of assessment includes a higher level of agency reconnaissance, a more prolonged period of engagement to facilitate a deeper understanding of more complicated attack possibilities, and many times utilizes social engineering. Further, ITS recommends periodically assessing the current environment for indications of an incident such a breach. vii. ITS recommends including tests for the presence of overly permissive network resources which are used to share data. This includes assessment of Access Control Lists and the storage of data in network shares which is identified as sensitive. This may include information and artifacts that would be useful to attackers, including network diagrams, configuration files, older penetration test reports, and backups of emails or documents containing passwords or other information critical to system operation. B. Each agency must develop and implement a plan of action and milestones to document the planned remedial actions to correct weaknesses or deficiencies and reduce or eliminate known vulnerabilities in agency systems. 1. Update plan of action and milestones based on findings from ongoing assessments, audits or reviews, and continuous monitoring activities. C. Each agency must submit all cybersecurity assessment reporting deliverables to ITS. Reporting requirements are included in the Cybersecurity Assessment Reporting Guidelines which can be found on the ITS website. All reporting deliverables from the cybersecurity assessment must be submitted within 90 days of its completion. D. Each agency must monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls. 1. Continuous monitoring efforts facilitate ongoing awareness of threats, vulnerabilities, and information security to support agency risk management decisions. 2. Additional cybersecurity assessments should be performed when there are significant changes to information systems and their environment of operation, new threats and vulnerabilities are identified, or other conditions occur that may impact the security state of the system or its environment. E. Each agency must develop, document, and periodically update system security plans that describe system boundaries, system environments of operation, how security requirements are implemented, and the relationships with or connections to other systems.

History

  • Source: Miss. Code Ann. § 25-53-201.

Chapter 16 System and Communication Protection

36 Miss. Admin. Code Pt. 1, R. 16.1 System and Communications Protection A

Each agency must monitor, control, and protect communications (i.e., information transmitted or received by agency systems) at the external boundaries and key internal boundaries of agency systems. 1. Use secure network management and communication protocols (e.g., 802.1X, Wi-Fi Protected Access 2 (WPA2) Enterprise or greater). i. ITS recommends not using WPA2 Personal (standard wireless network keys) as opposed to WPA2 Enterprise (username and password wireless authentication). 2. Perform traffic filtering between network segments, where appropriate. 3. Collect and store all network traffic flow logs and/or network traffic in a centralized server. All traffic logs must be retained for a predetermined period defined by the agency. Logs shall be reviewed at consistent intervals, or in response to a perceived or realized security event. B. Each agency which develops in-house software must employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems. 1. Establish and maintain a secure network architecture. A secure network architecture must address the following, at a minimum: i. Network segmentation: Development and production environments should be separated logically from one another. Further, network segmentation should exist between areas of differing data sensitivity levels. ii. Least privilege: Software and systems shall be designed in a way users are only afforded permissions to necessary functionality and information. iii. Availability: Software shall be designed in a manner that does not negatively impact the availability of other agency resources. 2. Establish and maintain a secure application development process. In the process, address such items as: secure application design standards, secure coding practices, developer training, vulnerability management, security of third-party code, and application security testing procedures. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard. C. Each agency must separate user functionality from system management functionality. 1. Agencies can implement separation of system management functionality from user functionality by using: i. Different computers, different instances of operating systems, or different network addresses, virtualization techniques, or combinations of these or other methods, as appropriate. ii. This type of separation includes, for example, web administrative interfaces that use separate authentication methods for users of any other system resources.

iii. Separation of system and user functionality may include isolating administrative interfaces on different domains and with additional access controls. 2. Establish and maintain dedicated computing resources, either physically or logically separated, for all administrative tasks or tasks requiring administrative access. The computing resources should be segmented from the agency's primary network and not be allowed internet access. D. Each agency must prevent unauthorized and unintended information transfer via shared system resources. It is recommended that only Common Criteria (CC) approved systems (such as Windows, Apple, Linux) are used. The CC evaluated systems have been certified to protect against misuse of shared resources. E. Each agency must implement DMZ subnetworks for publicly accessible system components that are physically or logically separated from internal networks. F. Each agency must deny network inbound communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception). 1. Use technical controls, such as application allowlisting, to ensure that only authorized software can execute or be accessed. The agency should reassess this bi-annually, or more frequently. 2. ITS recommends deploying port-level access control. Port-level access control utilizes 802.1x, or similar network access control protocols, such as certificates, and may incorporate user and/or device authentication. G. Each agency must prevent remote devices from simultaneously establishing non- remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling). H. Each agency must implement cryptographic mechanisms to prevent unauthorized disclosure of sensitive information during transmission unless otherwise protected by alternative physical safeguards. 1. Encrypt sensitive data in transit. Example implementations can include Transport Layer Security (TLS) and Open Secure Shell (OpenSSH). I. Each agency must terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity. For example, this includes inactivity timeouts on management sessions to network devices and servers in addition to inactivity timeouts on user network sessions such as VPN connections and other network sessions. J. Each agency must establish and manage cryptographic keys for cryptography employed in organizational systems. For example, agencies should determine what cryptographic keys (TLS certificates, VPN keys, etc.) are in use. Document how these keys are managed and protected. K. Each agency must employ federal information processing standards (FIPS)-validated cryptography when used to protect the confidentiality of sensitive information.

L. Each agency must prohibit remote activation of collaborative computing devices such as microphones, webcams, and screensharing applications. Users must be prompted with an indication that these devices are “in use” after activation. M. Each agency must control and monitor the use of mobile code. 1. Mobile code includes software programs or part of a program obtained from remote systems, transmitted across a network, and executed on a local system without explicit installation or execution by the recipient. Mobile code technologies include, but are not limited to Java, JavaScript, ActiveX, Postscript, PDF, VBScript. N. Each agency must control and monitor the use of Voice over Internet Protocol (VoIP) technologies. This includes delegation of access to administrative and end users, monitoring traffic flows, and review of any logging and alerts. O. Each agency must protect the authenticity of communications sessions. This requires authentication and encryption of traffic using FIPS-approved algorithms. P. Each agency must protect the confidentiality of sensitive data at rest. 1. Encrypt sensitive data at rest on servers, applications, and databases containing sensitive data. Storage-layer encryption, also known as server-side encryption, meets the minimum requirement of this Safeguard. Additional encryption methods may include application-layer encryption, also known as client-side encryption, where access to the data storage device(s) does not permit access to the plain-text data.

History

  • Source: Miss. Code Ann. § 25-53-201.

Part 2 Procurement Handbook

36 Miss. Admin. Code Pt. 2 Procurement Handbook

1

Mississippi Department of Information Technology Services (ITS) Procurement Handbook

Title 36: Technology

Part 2: Information Systems Services

Part 2 Chapter 1: ITS Roles in IT Procurement

Rule 201.1: 001-010 Introduction to ITS and Technology Procurement

Introduction: The Mississippi Department of Information Technology Services (ITS) was created by the legislature to maximize the use and benefit of information technology in state government by promoting full cooperation, coordination, cohesive planning, and maximum compatibility among all state agencies and institutions of higher learning. State statute establishing ITS and outlining the duties and responsibilities of the agency is found in Mississippi Code Section 25-53- 1, et seq. Lexis Publishing is the official publisher of the Mississippi Code, which can be accessed through the Secretary of State’s website:

Search the Mississippi Code at Michie’s Legal Resources powered by LexisNexis Publishing

A summary of ITS statute is found in this handbook under 001-050 Summary of ITS Statute.

The acquisition of information technology for all state agencies and institutions of higher learning (IHLs) is within the scope of the ITS law and the policies and procedures established in accordance with this statute. ITS law and policy cover the procurement of all information technology hardware, software, and services by state agencies and IHLs.

The responsibilities of ITS in the procurement of technology for the state of Mississippi include: • Furnishing customers with technical guidance and assistance in complying with the legal requirements of state purchasing laws for information technology • Maximizing competition, to the fullest extent practicable, among technology manufacturers and service providers • Maximizing the compatibility of the State's information resources • Acquiring complete information technology solutions that provide the best combination of functionality and cost • Leveraging the State's combined purchasing power to provide the best possible discounts

State agencies and institutions of higher learning are required by law to follow ITS procedures in information technology procurements. The only statutory exception is for acquisitions by institutions of higher learning made wholly with federal funds. Note that there is no exception for state agency projects that are federally funded, use grant money, or paid for via other nontraditional funding models.

2

For many acquisitions, agencies and IHLs must obtain ITS approval prior to initiating a purchase. For other acquisitions, ITS has delegated responsibility for technology purchases to the agencies and institutions according to specific guidelines.

Governing authorities (e.g. community/junior colleges, county boards of supervisors, school districts, and municipalities) are not required to use ITS procurement procedures but may choose to do so as one way of meeting public purchasing requirements.

Public Purchasing Law, Mississippi Code Title 31, Chapter 7, governs the purchase of commodities, non-IT equipment, and travel for the state of Mississippi. This law is administered by the Mississippi Department of Finance and Administration (DFA), Office of Purchasing, Travel, and Fleet Management (OPTFM) and can be accessed through the Secretary of State’s website:

Search the Mississippi Code at Michie’s Legal Resources powered by LexisNexis Publishing

ITS utilizes the provisions of Public Purchasing Law and DFA/OPTFM purchasing guidelines for Sole Source and Emergency procurements of information technology. ITS also works closely with DFA to assist customers and vendors in interpreting and complying with the provisions of ITS and Public Purchasing statutes. To the extent possible, the staffs of these two organizations keep rules and procedures synchronized for IT and non-IT procurements.

The Public Procurement Review Board (PPRB) Office of Personal Service Contract Review (OPSCR) Rules and Regulations governs the solicitation and selection of personal and professional services that do not involve information technology. Note that IT professional services provided by contract workers, as opposed to independent contractors, are outside the scope of ITS law and policy and therefore fall under the guidelines of the PPRB. OPSCR Rules and Regulations can be found on the OPSCR website. Source: 25-53-1, et seq; 31-7-1 et seq; 25-9-120; 27-104-7

3

Part 2 Chapter 1: ITS Roles in IT Procurement Rule 201.2: 001-020 Acquisitions within ITS Purview

  1. Information Technology Equipment, Software, and Services: Section 25-53-3 of the Mississippi Code of 1972 defines ITS' authority over the acquisition of any information technology, computer or telecommunications equipment, electronic word processing and office systems, or services utilized in connection therewith, including, but not limited to, all phases of computer software and consulting services and insurance on all state- owned computer equipment. Acquisition of computer or telecommunications equipment or services means the purchase, lease, rental, or acquisition in any other manner of any such computer or telecommunications equipment or services. Telecommunications equipment, systems, and related services are defined as the equipment and means to provide telecommunications transmission facilities; telephone systems, including voice processing systems; facsimile systems; radio paging services; satellite radio, telephone, and dispatch services; mobile telephone services, including cellular mobile telephone services; intercom and paging systems; video teleconferencing systems; personal communications networks and services; and any and all systems based on emerging and future telecommunications technologies related to any of these devices or services.

Note that, unlike public purchasing law, the statute that defines ITS' purview over technology acquisitions includes services. All technology services, whether for direct, hands-on skills such as application development and network support, or for such technology consulting services as technology training (both classroom and on-the-job), technology studies, project management, technology advisory roles, quality assurance support, and facilities management, are within ITS purview.

  1. Global Positioning System (GPS) and Navigation devices The Global Positioning System (GPS) is a U.S. space-based radio-navigation system that provides reliable positioning, navigation, and timing services to civilian users. For anyone with a GPS receiver, the system provides location and time.

ITS wants to emphasize the fact that it does have purchasing purview over GPS and navigation devices under the following conditions:

• When the GPS and navigation capability is integrated into a PocketPC or WinCE product • When the GPS and navigation capability is integrated into a Palm OS device • When the GPS and navigation capability is integrated into a Linux PDA device • When the GPS and navigation capability is integrated into a Blackberry • When the GPS and navigation capability is integrated into a smart mobile device running on the Symbian OS

  1. Electronic Government: Private companies offer partnerships with all levels of government to provide the tools and resources to implement internet-based services and business solutions (“E-Government”) with little or no up-front investment of money by the government entities. These companies use various funding mechanisms to recoup their expenses and to realize a profit from these

4

services. Per an Attorney General Official Opinion dated August 25, 2000, the Attorney General’s office affirmed that pursuant state statute, ITS has the authority to establish a procedure requiring the definition of requirements and a competitive contract award for the procurement of E-government services, regardless of the funds actually paid up-front by a state entity.

For purchases in which (1) the value of the goods and services exceed the dollar amount established in Section 31-7-13(c), (2) there is a competitive market, and (3) there is potential for vendor profit from the project, contracts must be awarded based on an open and competitive process that allows the state to compare offerings to obtain the best product, service, and value, regardless of monies paid directly to the vendor by the state entity. The competitive process ensures the state’s requirements are well-defined, project contracts are negotiated to protect the state’s interest, and the vendor selected is the one with the most advantageous combination of cost and services.

The same Attorney General’s Opinion also affirmed that state statute gives ITS the authority and responsibility to establish infrastructure standards for E-Government that must be utilized and conformed to by all state agencies. These standards must be incorporated into any specifications for the procurement of E-Government products and services. In addition, E- Government implementations that involve payments of any type require the review and approval of the Department of Finance and Administration.

For any procurement related to E-Government, the purchaser should follow the approval process detailed in 001-025 Approvals for Internet-based Applications and Services.

  1. Internet and Application Service Providers ITS wants to emphasize the fact that services offered through Internet Service Providers and Application Service Providers are subject to ITS oversight. These services include but, as technology evolves, are not limited to the following examples: • Internet access and related services packaging • Applications and database hosting/processing, including Application Service Provider (ASP) and Software as a Service (SaaS) models • Website development, content management and hosting • Email hosting; equipment co-location services • Data back-up and recovery services • Disaster recovery services • Business continuation services • Network operations center services • Electronic payment processing • Systems and security administration • Line of business outsourcing such as electronic reservations management, help desk and/or license sales related outsourced IT services

  2. Printers/Copiers: ITS has jurisdiction over the procurement of stand-alone and networked printers, while the Department of Finance and Administration (DFA), Office of Purchasing, Travel, and Fleet

5

Management (OPTFM) is responsible for the purchase of copiers. When multifunction devices become available, the line between equipment under ITS purview and equipment under OPTFM purview became distinct. ITS and DFA continue to monitor this technology convergence and its impact on the ITS and DFA customers and procurement approach.

Customers may purchase devices whose primary function is copying from DFA state contracts. If the device purchased from the DFA contract will be networked and the total purchase price is over $250,000 (or if the total cost for the term of a lease is over $250,000), the customer must submit an Exemption Request for ITS approval. This process ensures that ITS is aware of large network print device purchases. When the total term of the rental agreement from the DFA contract exceeds $500,000, approval shall be required from the Public Procurement Review Board (PPRB) prior to entering into the rental agreement. Additional information can be found at the link below.

Department of Finance and Administration (DFA), Office of Purchasing, Travel, and Fleet Management (OPTFM)

Devices that are purchased to function primarily as network or stand-alone printers may be procured through the ITS Express Products List (EPL) or through a procurement request to ITS.

  1. Document Imaging and Management: Document imaging and management systems scan, store, index, and retrieve documents and other business data electronically. Documents are converted to digitized images, typically via a document scanner. Standard components of document management systems include document capture, document storage and archiving, document indexing and retrieval, document exporting capability, and security to protect documents from unauthorized access. Document imaging and document management, including hardware, software, imaging services, and/or any other related consulting services, are within the purview of ITS. Equipment and services for analog methods of data imaging and retrieval, such as microfilm, are not within ITS purview.

  2. Management Consulting Contracts: Procurements of consulting services for a study that is the initial phase of an application development project, for functional or conceptual systems design, data modeling, network design, network security, and technology infrastructure recommendations are examples of consulting contracts that require ITS approval. Other consulting studies, such as business process reengineering, process analysis, and general management studies, may fall under the purview of ITS or of the PPRB, depending on the specific project deliverables. If the study's primary focus is technology, the services should be procured through ITS. If the primary deliverable from a management consulting contract is a report in which recommendations of technology are included but are not the primary component, the services may be procured through ITS or the PPRB, at the customer's discretion. If the customer is uncertain whether ITS approval is required for a specific project, the customer may contact the ITS Procurement Help Desk at isshelp@its.ms.gov or (601) 432-8166 and/or may submit an Exemption Request to ITS for written documentation that the specific project does not require ITS approval.

6

Regardless of the procurement mechanism used for a management consulting contract, once the customer is ready to proceed with technology purchases based on recommendations from a consulting study, including the study report with the technology procurement request is beneficial to both the customer and to ITS and helps expedite the purchasing process.

  1. Donations and Gifts of Information Technology: Recipients of donations and gifts of older information technology near or at the end of their lifecycle should assess the cost of the items received in terms of usefulness relative to newer technology. Many older technology items are more costly to uninstall, relocate, reinstall, operate, and maintain than new equipment of the same type.

A donation or gift requires ITS approval if the costs of installing, operating, and supporting the equipment exceed amounts delegated to the recipient under the Delegation of Approval Procedure. ITS will be glad to assist in assessing the value of donations and gifts of information technology on request.

  1. Other Examples of Procurements Under ITS Purview: Equipment or services for a specialized application whose primary function or purpose is other than information technology and for which any computer chip or telecommunications component is secondary or incidental to the equipment’s primary function are outside the purview of ITS.

See 001-030 Exceptions to ITS Purview for a list of some specific items that do not require ITS approval and for instructions on obtaining confirmation regarding ITS purview for a specific procurement.

Source: 25-53-3; 25-53-151

7

Part 2 Chapter 1: ITS Roles in IT Procurement Rule 201.3: 001-025 Approvals for Internet-based Applications and Services (State Agencies) E-government applications and services require additional review and approval by ITS and by DFA (in contrast to traditional software applications.) Because of the multiple costing models used by vendors for e-government applications, as well as the necessity for ensuring appropriate security for all public-facing applications, the normal ITS procurement delegations to agencies do not apply for these types of acquisitions. In addition, DFA must approve and schedule any implementations that involve payments.

Agencies planning to acquire e-government software or services should follow the checklist shown below during the planning process. Preparing and submitting the information packet outlined in the checklist will ensure the acquisition has received required DFA and ITS reviews and approvals and help prevent delays in the implementation of the needed services. Submit the following information to both ITS and DFA at least 90 days prior to the procurement of the products or services. Additional time (120-180+ days) will be required for more complex projects or applications. Requests that are not submitted within the prescribed timeframes are subject to expedited processing charges from both ITS and DFA.

NOTE: All ITS and DFA approvals are specific to the project, scope, and contract term outlined in the request. Revisions to scope, extension of contract or hosting terms, addition of functionality (including adding or changing payment services), additional expenditures, and other changes to the project or to the vendor agreement require submission of an additional approval request. Approval of a specific application by DFA and ITS does not imply approval of future applications within the same application or across application models. Additionally, all approvals by DFA and ITS of waivers from the State’s enterprise requirements are time-limited and may be revoked at any time if required to protect the substantial interests of the State.

8

√

Steps:

  1. Define and document functional requirements.
  2. Determine and document all payment methods that will be accepted: (Visa debit/credit; MasterCard debit/credit; Amex; e-check; other).
  3. Determine and document all payment services needed (online; in person: counter; point- of-sale, ACH).
  4. Complete the following checklist to determine if additional documentation and justification are required: (provide complete explanation, justification, and proposed technology and environment related to any question in a-d below that cannot be answered “yes.”). a. Hosted at the State Data Center? If not, provide a copy of the hosting company’s security policy, disaster recovery plan, and 3 rd party financial audit if vendor is known. [Alternately, this requirement will be incorporated into the competitive procurement process.] b. If hosted at State Data Center: Verification that application utilizes software products and versions supported at the State Data Center? Attach verification form signed by State Data Center representative to this request. c. Payments made via State’s Enterprise Payment Engine? If a waiver is to be requested, this request as documented in the DFA Administrative Rule, Payment by Credit Card or Other Forms of Electronic Payment to State Agencies, should be included in the submittal. d. Application will use the State’s Enterprise Payment Interface Component (EPIC) for payment processor interface?
  5. If not hosted at State Data Center using State’s enterprise payment system and processor, determine PCI DSS compliance requirements tier and responsibility. Provide a copy of most recent PCI audit from the proposed hosting and/or payment vendor if known. [Alternately, this requirement will be incorporated into the competitive procurement process.] (Note: If hosted at State Data Center, using State’s Enterprise Payment Processor and Enterprise Payment Interface Component, ITS will certify PCI compliance.)
  6. Document anticipated fee structure, including EOC fee. If requesting waiver of the EOC fee or if requesting to absorb EOC fee on customer’s behalf, include letter from agency executive outlining that request.
  7. Determine and document procurement approach:
    1. Document anticipated lifecycle cost to agency.
    2. Document anticipated lifecycle cost to consumer.
    3. If total of a+b above is above quote threshold but less than bid threshold, obtain 2
    written quotes and provide copies to ITS (Or request that ITS obtain the quotes as part of the procurement approval process). d. If total of a+b above is above bid threshold, complete ITS competitive procurement form, exemption request form, or sole source form.
  8. Submit all documentation to both ITS and DFA. Source: 25-53-151

9

Part 2 Chapter 1: ITS Roles in IT Procurement Rule 201.4: 001-030 Exceptions to ITS Purview State statute governing ITS provides for some specific exemptions from ITS purview and also allows ITS to establish policies and procedures for delegating bidding and contracting responsibilities for IT procurement to the purchasing agency. However, ITS is not authorized to exempt any purchase from applicable state statute, including but not limited to the competitive bid requirement.

Section 25-53-25 (3) excludes the following acquisitions from ITS jurisdiction: "Acquisitions of computer equipment and services by institutions of higher learning or junior colleges wholly with federal funds and not with state general funds...." This code section specifically states, however, that these acquisitions are NOT exempt from public purchasing laws. Note that neither of these code sections exempts acquisitions made by state agencies with federal funds from ITS purview.

Section 25-53-25 (2) of the Mississippi Code gives ITS the authority to delegate purchasing responsibility and is the basis for the Exemption, Delegation of Approval, and Planned Purchases Procedures.

Equipment, software, or services for a specialized application whose primary function or purpose is other than information technology and for which any IT functionality or component is secondary or incidental to the equipment’s primary function are outside the purview of ITS.

ITS maintains a partial list of items and services about which frequent questions are asked regarding ITS purview. The list is not exhaustive and is updated as new situations arise.

The following procurements do not require ITS approval. Because of potential impact on technology infrastructure, notification to ITS is required in some cases, as noted below:

10

Product: Examples: Specialized medical or scientific products whose primary purpose is other than information technology Spectrophotometers/spectrometers CT and other medical scanners Equipment for performing lab tests or analyses Automated weather stations and monitoring devices Intelligent Medication Dispensers Computer supplies Laser and magnetic media Printer toner cartridges Computer paper Computer accessories Printer paper trays Envelope feeders Power strips Surge protectors Computer furniture Computer desks Computer cabinets Technology Reference Manuals: hardcopy or electronic User manuals Technical manuals Electronic or online publication of state- published documents (static, without functionality) Annual reports Policy manuals State's "Blue Book" Online Research or Educational Material (standard "off the shelf" delivery of static information without customized or interactive functionality) Electronic magazines Electronic databases: Lexis/Nexis, Westlaw, Solinet Electronic textbooks or reference material Radio/TV broadcast or reception equipment (i.e. one-way transmission) Equipment needed to create, edit, and/or broadcast audio/video programming Cable television Satellite dishes for receipt of television broadcast programming (Note: Satellite transmission and reception systems for providing communication facilities DO fall within ITS purview.) Microfilm and other analog image storage media Microfilm/microfiche viewing and duplicating equipment Microfilm cameras Digital indexing systems for analog storage media Digital cameras and self-contained surveillance equipment NOTE: Surveillance systems for which devices have assigned IP addresses or have a network connection DO fall within ITS purview Surveillance cameras Video monitors

11

Services: Examples: Vendor-independent Advisory/Research Subscription Services: (Prior approval not required. Supply ITS with a copy of any supplement to an ITS Master Agreement) Gartner "seats" Subscription Giga Advisory Service Subscription Technology products or services provided by one Mississippi agency or institution for another. These types of acquisitions are specifically exempted from the bid requirement per Mississippi Code Section 31-7-13 (m) (vi).

Notify ITS during the planning phase for any acquisitions having market value above the current Delegation of Approval Limits. In addition, provide ITS with a copy of any contracts or agreements executed for agency- to-agency acquisitions immediately upon execution.

Note: If the acquisition commits the state entity to expenditures with any private company in an amount above the current Delegation of Approval limits, the acquisition is NOT exempt from ITS purview. The Mississippi EDNET Institute Mississippi's public universities State agencies The John C. Stennis Institute of Government Technology products or services furnished to state entities by other governmental entities or instruments or by peer or affiliated organizations. These types of acquisitions are specifically exempted from the bid requirement per Mississippi Code Section 31-7-13 (m) (vi). Notify ITS during the planning phase for any acquisitions having market value above the current Delegation of Approval Limits. In addition, provide ITS with a copy of any contracts or agreements executed for agency- to-agency acquisitions immediately upon execution. Note: If the acquisition commits the state entity to expenditures with any private company in an amount above the current Delegation of Approval limits, the acquisition is NOT exempt from ITS purview. Federal agencies: EPA, USDA AASHTO (American Association of State Highway and Transportation Officials) Public universities Counterpart agency from another state

12

Services: Examples: Technology services provided by contract employees, designated according to the agency’s determination under the guidelines of the Internal Revenue Service (IRS) Questionnaire for Classification of Contractual Personnel. (Note: IT services provided by independent contractors DO fall under the purview of ITS).

ITS customers should procure the items or services listed above in compliance with the regulations of the Department of Finance and Administration Office of Purchasing, Travel, and Fleet Management or the regulations of the Office of Personal Service Contract Review, or local purchasing requirements, if applicable. However, if it is appropriate and desirable to procure an item from the above list in conjunction with turnkey information technology procurement, the item may be included with that acquisition under ITS purchasing statute and procedures.

Even if the item being purchased is not listed above, ITS approval may not be required if the equipment or service is for a special purpose other than information technology.

When uncertain about a specific procurement, contact the ITS Help Desk at isshelp@its.ms.gov or (601) 432-8166 to determine whether ITS involvement is required. To obtain written verification from ITS of whether ITS approval is required for a specific acquisition, submit a letter or e-mail to: Information Technology Services - ISS, 3771 Eastwood Drive, Jackson, MS 39211, projects@its.ms.gov. Upon ITS staff review of the exemption request, if the ITS staff concurs that the procurement is not within the scope of ITS law/policy/procedure, the ITS Executive Director will write a letter or memo to the requesting agency/public university specifying that the acquisition does not fall within ITS purview. No CP-1 Acquisition Approval is issued or required. The agency/public university may proceed with the procurement in compliance with applicable laws.

Source: 25-53-25; 31-7-13

13

Part 2 Chapter 1: ITS Roles in IT Procurement Rule 201.5: 001-050 Summary of ITS Statute Sections 25-53-1 through 25-53-191

Category/Code Section Purpose of ITS:

25-53-1 To maximize the use and benefit of information technology by promoting full cooperation, coordination, cohesive planning, and maximum compatibility among all state agencies and institutions of higher learning; Purview of ITS: State Agencies Institutions of Higher Learning (Public University) Other political subdivisions on request

Authority, Duties, & Responsibilities

  1. Procurement Business Area: Information Systems Services (ISS) Scope: All information technology (including telecommunications) hardware, software, and services

Category/Code Section Responsibilities: 25-53-5 (d) Maximize competition, to the fullest extent practicable, among manufacturers; Maximize compatibility among information systems; 25-53-21 (f) Serve as purchasing and contracting agent for the state for all IT hardware, software, and services; Receive and review all requests for the acquisition of IT hardware, software, and services; Approve or disapprove all requests for the acquisition of IT hardware, software, and services; 25-53-5 (o) Award contracts to the lowest and best bidder, after determining the lowest and best of the proposals submitted; 25-53-5 (k); 25-53-21 (f) Approve all contracts for technology hardware, software, and services; 25-53-21 (f) Execute all contracts for technology hardware, software, and services; 25-53-29 (1) Publish written planning guides, policies and procedures for use by agencies and institutions in planning for IT;

14

Authority: 25-53-5 (d) Require the use of common computer languages; 25-53-21 (e) Require the renegotiation, termination, amendment, or execution in proper form and according to established policies, rules, and regulations, of all contracts for the acquisition of IT hardware, software, or services; 25-53-25 (2) Develop policies for delegating bidding and contracting responsibilities to the purchasing agency; 25-53-21 (d) Report to the ITS Board any failure on the part of any agency to cooperate with the planning for efficient IT operation;

1a. Procurement: Telecommunications- Specific Scope: All requests by state agencies for the purchase or lease of telecommunications systems or services including telecommunication proposals, studies and consultation contracts, and intra- LATA and inter-LATA transmission channels

Category/Code Section Responsibilities: 25-53-111 (h) Establish and define telecommunications systems and services specifications and designs so as to assure compatibility of telecommunications systems and services within state government and governing authorities; 25-53-111 (l) Develop policies, procedures and long-range plans for the acquisition of telecommunications systems; Authority: 25-53-111 (g) Review, coordinate, approve or disapprove all requests for procurement, through purchase or lease, of telecommunications systems or services, including telecommunication proposals, studies and consulting contracts and intra-LATA and inter-LATA transmission channels; 25-53-111 (l) Require all state agencies to submit a long-range plan for the use of telecommunications equipment, systems and services; 25-53-109 (c) (iv) Manage specification writing, bid letting, proposal evaluation, and contract negotiations for telecommunications systems and services;

15

  1. Technology Oversight, Standardization, and Operations Business Areas: Telecom Services, Data Services, Information Security Scope: Cooperation between state agencies for the purpose of efficient IT operation

Category/Code Section Responsibilities: 25-53-5 (l) Acquire and operate technology to provide services to state agencies when, in ITS’ opinion, such operation will provide maximum efficiency and economy in the function of any agency or state government as a whole; 25-53-21 (a) Conduct continuing studies of all information technology activities carried out by all agencies; Develop a long range plan for the efficient and economical performance of all information technology activities in state government; 25-53-21 (a), (d) Implement the long range technology plan as it applies to ITS and ensure that the over-all technology direction outlined in the plan is implemented by all state agencies; Authority: 25-53-5 (g) Provide for the development and require the adoption of standardized computer programs; 25-53-5 (i) Specify organizational structures within state agencies relating to information technology operations; 25-53-21 (c) Inspect the IT operations of any agency as necessary; 25-53-21 (d)

Decide all questions of the division of the cost of information technology operations among the agencies; 25-53-21 (g) Shall suggest and cause to be brought about cooperation between the agencies and institutions in order that work and/or equipment in one agency may be made available to another agency; Effect any improvements necessary for the purpose of joint or cooperative IT operations; 25-53-29 (1) (c) Inspect agency facilities and equipment, interview agency employees, and review records at any time deemed necessary for the purpose of identifying cost-effective applications of technology; 25-53-29 (c) Issue management letters to agency heads following IT inspections, with cost estimates and recommendations concerning staff reductions, other monetary savings, and improved delivery of services;

2a. Technology Oversight and Standardization: Telecommunications- Specific Scope: All telecommunications systems and networks used by state agencies

Category/Code Section Responsibilities: 25-53-105 Coordinate and promote efficiency in the acquisition, operation and maintenance of all telecommunications systems and networks used by agencies of the state; 25-53-105 Coordinate the compatibility of systems and networks of the state with those of governing authorities to promote a uniform, compatible telecommunications system for agencies and governing authorities;

16

Category/Code Section Responsibilities: 25-53-109 (b) Provide more effective management of state telecommunications resources and implement long-range plans and procurement; 25-53-109 (c)

Manage, plan, and coordinate all telecommunications systems under the jurisdiction of the state; 25-53-111 (a) Establish and coordinate through state ownership or commercial leasing all telecommunications systems and services affecting the management and operations of the state; 25-53-111 (b) Act as sole centralized customer for the acquisition, billing, and record keeping of all telecommunications systems or services provided to state agencies through lease or purchase; 25-53-111 (d)

Offer or provide transmission, switch and network services on a reimbursable basis to agencies financed by federal funds, to governing authorities, and to other governmental agencies 25-53-111 (e) Approve or provide state telephone services on a reimbursable basis to full-time students at state institutions of higher learning and junior colleges; 25-53-111 (f)

Develop coordinated telecommunications systems or services for all state agencies; 25-53-111 (i)

Provide a continuous, comprehensive analysis and inventory of telecommunications costs, facilities and systems within state government; 25-53-111 (j)

Promote, coordinate or assist in the design and engineering of emergency telecommunications systems, including but not limited to 911 service, emergency medical services and other emergency telecommunications services; 25-53-111 (k) Advise and provide consultation to agencies and governing authorities with respect to telecommunications management planning; 25-53-111 (l) Develop policies, procedures and long-range plans for the use of telecommunications systems; Authority: 25-53-109 (a)

Form an advisory council of persons with expertise and experience in telecommunications for the purpose of setting goals, establishing long- range plans and policies, and overseeing and assisting in the procurement of telecommunications equipment and services; 25-53-109 (c) (i)

Administer telecommunications systems, including coordination of activities, vendors, service orders, and billing/record-keeping functions; 25-53-109 (c) (ii) Plan new systems or services; 25-53-109 (c) (iii) Design replacement systems; 25-53-109 (c) (v)

Supervise the implementation of new systems and ongoing support; 25-53-109 (c) (vi) Implement long-term state plans; 25-53-109 (c) (vii) Manage intra-LATA and inter-LATA networking;

17

Category/Code Section Responsibilities: 25-53-111 (c) Charge respective user agencies for their proportionate cost of the installation, maintenance and operation of the telecommunications systems and services, including the operation of ITS; 25-53-111 (f)

Require cooperative utilization of telecommunications equipment and services by aggregating users;

25-53-119

Sole authority and responsibility, within the constraints of this statute, for defining the specific telecommunication equipment, systems and services to which this statute is applicable.

  1. Training Business Area: Education Services Scope: Training programs for employees in information technology positions and end-users of technology

Category/Code Section Responsibilities: 25-53-5 (g) Establish training programs for state agency personnel; 25-53-29 (d) Conduct classroom and onsite training for end-users of applications and systems and for IT professionals; 25-53-111 (k) Provide training to users within state government in telecommunications technology and system use;

  1. Consulting Business Area: Information Systems Services; Telecom Services; Data Services Scope: Planning, consulting, project management, systems and performance review, system definition, design, application programming, training, development and documentation, implementation, maintenance and other tasks within the resources of ITS, for agencies, institutions, political subdivisions, and other governmental entities, on a fee basis

Category/Code Section Responsibilities: 25-53-29 (2) Provide a high level of technical expertise for government entities; 25-53-29 (1) (e) Provide consulting services to agencies and institutions or governmental subdivisions requesting technical assistance; Authority: 25-53-29 (1) (e)

Submit proposals and enter into contracts to provide services to agencies, institutions, or governmental subdivisions; 25-53-29 (4) Charge fees to agencies and institutions for services rendered to them; 25-53-29 (6) Contract with firms or individuals to augment the consulting staff to ensure timely completion of tasks;

  1. Additional Requirements of State Agencies:

18

Category/Code Section Responsibilities: 25-53-113 Give full cooperation to ITS in furnishing all information of any kind as it pertains to telecommunications; 25-53-115 No agency shall rent, lease, lease/purchase, purchase, or in any way own or pay for the operation of any telecommunications system out of any funds available for use by that agency without the written approval of ITS. 25-53-117

No agency shall obligate the state to any vendor for a telecommunications system of any kind. All transactions dealing with a telecommunications system shall be conducted through ITS and any vendor found in violation of this policy may be prohibited for bidding for up to 24 months.

Source: 25-53-1, et seq

19

Part 2 Chapter 1: ITS Roles in IT Procurement Rule 201.6: 001-060 Index to ITS Statute Index to ITS Statute: Sections 25-53-1 through 25-53-191

20

Where is it in ITS Statute? Advertising: 14 day minimum 25-53-5 (o) Advisory Committee (IRC) 25-53-5 (p) Annual Report 25-53-5 (o) 25-53-29 (3) Bid: Definition: includes RFPs, other instruments 25-53-3 (g) Bid Limit: Link to 31-7-13 (c) in public purchasing 25-53-5 (o) Board: Bond 25-53-7 (2) Board: Duties & Responsibilities 25-53-5 Board: Membership 25-53-7 (1) Board: Monthly Meetings 25-53-11 Board: Minutes 25-53-17 Board: Per Diem 25-53-9 Board: Quorum 25-53-13 Board: Votes: liability for 25-53-15 Bond: Executive Director 25-53-19 Cellular: See Wireless Communication Devices Charges: See "Fees" Chief Confidentiality Officer 25-53-21 (h) Community Colleges: Federal funds exempted 25-53-25 (3) Community Colleges: Special needs 25-53-5 (b) Compatibility: Maximizing 25-53-5 (d) Competition: Maximizing 25-53-5 (d) Consulting Services 25-53-29 (1) (a) 25-53-29 (1) (e)

Consulting Services: Highly qualified staff 25-53-29 (5) Consulting Services: Contracting for staff augmentation 25-53-29 (6) Consulting Services: Escalate positions 25-53-29 (5) Consulting Services: Fees 25-53-29 (4) Contracting Agent: Executive Director as 25-53-21 (f) Contracts: Approving 25-53-5 (k) Cooperation between state agencies 25-53-21 (d) 25-53-21 (g) Definitions 25-53-3 Delegating Contract Approval to Executive Director up to $ Limit 25-53-5 (k) Delegating Procurement Responsibility to Agencies 25-53-25 (2) Disposal of Equipment 25-53-5 (c) Documentation of IT Procedures of an Agency 25-53-5 (i) E-Government 25-53-151 Escalated Positions 25-53-107 (2) 25-53-29 (5) Executive Director: Bond 25-53-19 Executive Director: Duties 25-53-21 Executive Director: Hiring staff 25-53-19 Executive Director: Selection and qualifications 25-53-19

21

Fees: ITS Revolving Fund 25-53-5 (r) Fees: RFPs and other documents 25-53-5 (d) Fees: Vendors 25-53-5 (r) Financial Disclosure: Board and Executive Director 25-53-7 (3) GIS: Delivery system infrastructure 25-53-5 (s) GIS: Warehouse 25-53-5 (s) GIS: Coordinating Council for GIS/Remote Sensing Established 25-53-201 IHL/Community Colleges: Federal funds exempted 25-53-25 (3) IHL/Community Colleges: Special needs 25-53-5 (b) Information Confidentiality Officers 25-53-51--59 Legislative Advisors 25-53-7 (4) Limitation of Liability 25-53-21 (e) Local Governments: Assist with IT Plans 25-53-5 (m) Lowest and Best 25-53-5 (o) Negotiating within Terms of Specifications 25-53-5 (o) Open and Competitive Specifications 25-53-5 (o) Operate Computer Equipment: Maximum efficiency & economy 25-53-5 (l) Organizational Structures 25-53-5 (i) Pilot Projects 25-53-5 (q) Plan: Issue 3-year master plan annually 25-53-29 (2) Planning Guides and Policies 25-53-29 (1) (b)

Private Sector: Services to nonstate entities 25-53-5 (e) Procurement: $ limit for bid 25-53-5 (o) Procurement: General rules 25-53-5 (o) Protests 25-53-5 (n) Public Purchasing Law 25-53-5 (p) Reject All Bids 25-53-5 (o) Reporting by Agencies to ITS 25-53-5 (h) Rules and Regulations: Establishing and publishing 25-53-5 (j) Rules and Regulations: Reporting 25-53-5 (h) Sole Source (General Reference: 25-53; Specific: 31- 7) 25-53-5 (p) 31-7-13 (m) (viii)

Specifications 25-53-5(d) 25-53-5(o) 31-7- 13(c)(iv)(1) Staff: Hired by Executive Director 25-53-19 Standardized Computer Programs: Requiring 25-53-5 (g) Telecommunications 25-53-101-- 125

Telecommunications: Charge user agencies proportionate cost 25-53-111 (c) Telecommunications: Equipment support contracts 25-53-121

22

Telecommunications: ITS as sole centralized customer 25-53-111 (b) 25-53-115 25-53-117 Telecommunications: Procurement scope 25-53-111 (g) 25-53-115 Telecommunications: Escalate positions 25-53-107 (2) Telecommunications: Procurement 25-53-123 25-53-113 (g) Title of Equipment 25-53-5 (c) Training 25-53-29 (1) (a) and (d) 25-53-5 (g) 25-53-111 (k) Wireless Communication Commission 25-53-171 Wireless Communication Devices 25-53-191

Source: 25-53-1, et seq

23

Part 2 Chapter 1: ITS Roles in IT Procurement Rule 201.7: 001-070 Index to Attorney General Opinions

Opinion Date AG DOC Number Requestor, if other than ITS Subject Opinion February 9, 2011 2011-00001

September 9, 1980 1980-00001802 Federal law takes precedent over State Law 2/9/11: The court concluded that, if a conflict exists between a federal regulation and a provision of state law, then the conflict must be resolved in favor of the federal regulation.

9/9/80: The court concluded that where a state participates in federal programs, it is bound by those regulations even though state law, with regard to a particular matter, may be to the contrary. August 20, 2010 2010- ITS Responsibilities in purchase of GIS by local governments ITS' role under 25-58-1 (4) is NOT formal proposal evaluation and recommendation of lowest & best proposal. ITS is responsible for reviewing proposed solutions with the view of leveraging previous expenditures. May 15, 2009 2009- Local zoning ordinances and Towers for MSWIN Government entities are subject to municipal and/or county zoning ordinances aimed at public safety; A municipality or county may not enact an ordinance that would prohibit the WCC from fulfilling its statutory obligations; A municipality or county has an obligation to grant such exceptions to their ordinances as necessary to permit the WCC to fulfill its statutory obligation of implementing a statewide wireless communication system. September 22, 2006 2006-0457 Cooperative Purchasing Agreements ITS may adopt rules and procedures for submitting cooperative purchasing agreements for approval by DFA to be utilized by ITS on behalf of agencies and institutions of the state. May 5, 2006 2006-00159 DFA Cooperative Purchasing Agreements DFA may adopt as its own purchase agreements the cooperative agreements developed by other states and local governments April 14, 2006 2006-00125 ITS Board: Holdover in office ITS code does not provide any authority for an ITS board member to hold over in office until a successor is appointed. (Note: ITS Statute

24

Opinion Date AG DOC Number Requestor, if other than ITS Subject Opinion amended to allow a Board member to continue to serve until a successor has been appointed.) January 25, 2006 2006-0030 DFA Contract Clauses: Indemnity and related matters Absent express or implied authority, an agency cannot indemnify or hold harmless a contractor for liability arising from the contractor's performance or negligence; State may affirmatively acknowledge its potential liability under the Tort Claims Act; Limitation of liability provisions are unenforceable except in one instance in which Legislature has provided express authority to ITS Executive Director. November 30, 2004 2004-0572

Cooperative Purchasing Agreements ITS has the authority to establish reasonable rules, regulations, and procedures to effect the utilization of cooperative purchasing agreements as provided in Section 31-7-13 (m) (xxix) for information technology purchases. August 22, 2003 2003-0411 Tunica County School District Unsealed Bids and Other Irregularities or Technical Deficiencies

Irregularities that can be waved generally have the following characteristics:

  1. Mandatory statutory provisions are not violated.
  2. Irregularity does not in any way destroy the competitive character of the bid.
  3. Irregularity has no effect as to the amount of the bid.
  4. Irregularity does not give one bidder an advantage or benefit over other bidders. Sealed bid requirement is statutory and cannot be waived. A domestic corporation must be duly incorporated and in good standing with the Secretary of State’s office to be awarded a bid. May 16, 2003 2003-0203 Purchase of MS EdNet Services by State Agencies

ITS can include EdNet services in the category "“technology services furnished to state entities by other governmental entities," thus exempting these acquisitions from the requirement for competitive bids (MS Code Section 31-7-13(m)(vi)) and from ITS approval (ITS Procurement Handbook)

25

Opinion Date AG DOC Number Requestor, if other than ITS Subject Opinion October 4, 2002 2002-0534

April 12, 2002 2002-0153

March 16, 2001 2001-0139 ITS Purview over Community Colleges

10/4/02: Only IT equipment purchased by Community Colleges using funds from local tax levies are under ITS purview; 4/12/02: Expenditures of tax proceeds by Community Colleges for IT purchases are under ITS purview; 3/16/01: Community Colleges, as agencies of local government, are not under ITS purview. December 15, 2000 2000-0684 Insurance Requirement for Public Works Contracts

$1 million insurance requirement does not apply generically to IT projects, but could apply to specific contracts, such as outside cabling plants August 25, 2000 2000-0442 E-Government Business Models and Bid Requirements

  1. ITS can establish infrastructure standards that must be utilized by all agencies.
  2. ITS can require competitive award for e-government services, regardless of the dollar amount.
  3. The selling of advertising on the state’s websites is not permitted without specific statutory authority; ITS can approve contracts funded by commercial ads on a vendor’s web site.
  4. ITS cannot approve fee-added internet services as the ONLY way in which citizens can conduct business with a state agency.
  5. An agency cannot sell its records for a profit; an agency cannot authorize any entity to be the exclusive recipient or provider of public data. June 20, 2000 2000-0270 Hinds County Online Services for County Governments

The AG’s office strongly encourages competitive bids for acquisition of web-based e-government services by counties, although advertising for bids is not required; Counties are authorized to charge consumers a user fee for e-government services; September 3, 2010 2010-00123 IT Services for Governing Authorities The AG’s office recommends soliciting competitive bids or proposals for the

26

Opinion Date AG DOC Number Requestor, if other than ITS Subject Opinion acquisition of IT services by governing authorities, even though there are no competitive requirements in law. December 10, 1999 1999-0573 Library Commission Grants of Obsolete Computer Equipment to Nonprofit Organizations

Library Commission cannot loan or assign computer equipment except to governmental entities but may loan or assign equipment to such nonprofit community centers as may qualify as libraries. Commission can define as a library any Mississippi organization providing a service to the public that is being provided by a significant number of recognized libraries in the US, including providing computers for public access for research and Internet access. June 12, 1998 1998-0342 Dollar Threshold for Competitive, Advertised Bids Narrow interpretation of MS Code Section 25-53-5(p), ITS use of law/regulations governing DFA- OPTFM (public purchasing); ITS cannot use DFA-OPTFM bid limit of $10,000; (Note: ITS statute amended in 1999 Legislative Session to tie bid limit directly to limit in public purchasing law.) May 29, 1998 1998-0288 Disclaimer of Implied Warranties Vendors can limit or disclaim implied warranties in offering computer hardware and software to the State through ITS; ITS can, however, require implied warranties of merchantability and fitness for a particular purpose in any RFP. June 20, 1997 1997-0362 ITS and State Board of Community and Junior Colleges Use of State Information Technology Services by Private Entity Is it legal for a non-public entity to connect to the compressed video backbone network and deliver educational and training services to their constituents? Opinion reiterates 5/10/96 opinion below. May 10, 1996 (not online) Access to State-Provided Technology Resources (Internet access via an IHL’s frame relay connection) by Parochial School State owned technology services can be used by a private entity only when (1) such services are not readily available otherwise in the state; and (2) the nonstate entity pays a charge not less than the prevailing rate for similar services charged by private enterprise. September 13, 1994 1994-0588 State Agency’s Right to Transfer Ownership of Sale is permissible in exchange for fair value. Contract must determine ownership of the

27

Opinion Date AG DOC Number Requestor, if other than ITS Subject Opinion Developed Software to Vendor software. Software belongs to the developer in the absence of contract language to the contrary. June 6, 1994 1994-0305 Certificate of Responsibility Requirement for Vendors Installing or Maintaining Telecommunications and Computer Equipment and Cabling A contract primarily focused on the purchase of telecommunications or computer equipment that will merely be installed or subjected to routine maintenance probably does not fall within the public projects category necessitating a Certificate of Responsibility. June 6, 1994 1994-0281 Management and Distribution of Pay Telephone Commissions by ITS ITS is the sole centralized customer for the acquisition, billing, and record keeping of all telecommunications systems or services provided to state agencies. The law does not mandate that payment of telephone commissions for the Department of Corrections be made directly to the Inmate Welfare Fund, rather than be distributed by ITS to the Department of Corrections, less ITS’ costs. July 2, 1993 1993-0440 Sole-Source Acquisitions Sole source acquisitions of software can be made under ITS’ statutory authority to defer to state purchasing laws for telecommunications acquisitions. (Note: ITS statute later amended to add language re access to public purchasing laws in the “data processing” portion of ITS code.) March 24, 1993 1993-0229 Community College Purchase Using Federal Funds The purchase of computer equipment by community colleges using federal funds administered through the State Vocational Education Board are exempt from ITS purview under Section 25-53-25 (3). The administration of the funds by a state board does not negate this exemption. March 3, 1993 1992-1023 Municipal Energy Agency of MS Limitation of Liability Limitation of liability clauses in contracts (prior to ITS statute allowing limitation) April 3, 1992 1991-0922 Software Developed by the State as Public Record Software is not data but a tool to collect information. Programs developed by the State are its intellectual property. To the extent that software contains confidential file access

28

Opinion Date AG DOC Number Requestor, if other than ITS Subject Opinion information, software is not subject to disclosure under public records statute. July 5, 1990 1990-0485 Mississippi Gulf Coast Community College Telephone Service in Student Dorms Community College cannot allow vendor to contract directly with and supply services to students in dorms on college-owned lines. Per MS Code, ITS must approve or provide telephone services to students at state community colleges on a reimbursable basis. There is no requirement that ITS approve or provide telephone services to college employees, who can contract directly with vendor for telephone service in college-owned housing. March 30, 1990 1990-0187 Purchase of software from a state employee by a state entity via an ITS RFP Allows a state employee to contract with any entity other than the one at which he is employed, as long as proposal is lowest and best. March 7, 1989 1989-076 Bids as Public Records To the extent proposals contain trade secrets or confidential commercial or financial information, they are protected and are not subject to release until the provisions of the Public Records Act requiring notice to 3rd parties and opportunity for a protective court order are complied with. Otherwise, nothing prohibits access to bid information, either during the evaluation process or after the award. November 11, 1988 In re Miss. Jud. Information Sys., 533 So. 2d 1110, 1111 (Miss. 1988) Supreme Court Declared Not Under ITS Purview “The judicial department of the government of this state is not subject to the authority or regulations of [ITS].” Source: 25-53-1, et seq

29

Part 2 Chapter 2: FAQs Rule 202.1: 002-010 FAQs for Customers Customer FAQs

What governmental units are subject to ITS Procurement Law and Policies? Who can buy through ITS? Which acquisitions are under ITS purview? What procurement tools are available? Do I have to go through the competitive bid process to buy IT hardware, software and/or services? How do I know if a purchase will qualify for E-Rate? Who do I contact to initiate an IT Procurement request? Can I initiate an IT Procurement request on-line? Is it possible for an agency to handle procurement themselves? How do I purchase new phones/phone system? Can I lease IT equipment? How may an agency acquire an item that is Sole Source? What is an Express Product List (EPL)? Who can use the EPL? What if I need a product or service that is not on an EPL? Do IT services have to be bid?

Who can buy through ITS? What Governmental units are subject to ITS Procurement Law and Policies? State agencies and institutions of higher learning (IHLs) or public universities are required by law to follow ITS procedures in information technology procurements for hardware, software and services. The only statutory exception is for acquisitions by institutions of higher learning or public universities made wholly with federal funds. Note that there is no exception for state agency projects that are federally funded, use grant money, or paid for via other nontraditional funding models.

For many acquisitions, agencies and IHLs must obtain ITS approval prior to initiating a purchase. For other acquisitions, ITS has delegated responsibility for technology purchases to the agencies and public universities according to specific guidelines.

Governing authorities (e.g. community/junior colleges, county boards of supervisors, school districts, and municipalities) are not required to use ITS procurement procedures but may choose to do so as one way of meeting public purchasing requirements.

Refer to section 001-010 Introduction to ITS and Technology Procurement for more information.

Which acquisitions are under ITS purview? Information Technology Equipment, Software, and Services Electronic Government Internet and Application Service Providers Printers/Copiers Document Imaging and Management

30

Management Consulting Services Donations and Gifts of Information Technology Refer to section 001-020 Acquisitions within ITS Purview for more explanation.

What procurement tools are available? There are several procurement options available depending on the nature of the project. Refer to the associated link for a detailed description of each.

Request for Proposal (RFP) Express Products List (EPL) General RFPs Special RFPs Telecommunications Contracts & Services for State Agencies Telecommunications Contracts & Services for IHLs Sole Source Procurements

Do I have to go through the competitive bid process to buy IT hardware, software and/or services? According to ITS Law, competitive bids or proposals must be solicited for all acquisitions of information technology (IT) equipment/hardware, software, and services involving the expenditure of funds in excess of the dollar amount established in Section 31-7-13(c). The list below summarizes bid requirements for IT acquisitions:

Not over $5,000 – May purchase without advertising or otherwise requesting competitive bids, unless the purchasing agency or entity has established more stringent procedures.

$5,000.01 up to but not over the dollar amount established in Section 31-7-13(c) – May purchase without advertisement for bids, provided at least two competitive written bids have been obtained. Please note that you must select the lowest quote. (Note an Express Products List cannot be used as one of these bids.)

In excess of the dollar amount established in Section 31-7-13(c) – Submit a Competitive Procurement Request form for ITS to advertise, issue written specifications and receive sealed bids or proposals.

How do I know if a purchase will qualify for E-Rate? Refer to the Eligible Services List. Agencies may also contact Gary Rawson at (601) 432-8113 or Gary.Rawson@its.ms.gov for more information.

Who do I contact to initiate an IT Procurement request? Requests for the procurement of information technology hardware, software or services should be submitted to ITS using the Competitive Procurement Request form and appropriate attachments. Refer to 009-005 Procurement Process: Submitting a Request for a more detailed description. Procurement requests should be sent to ITS via e-mail (Projects@its.ms.gov), fax (601-713-6380), or mail at ITS, 3771 Eastwood Drive, Jackson, MS 39211. Can I initiate an IT Procurement on-line?

31

Yes, via ITS’ online procurement request system.

Is it possible for an agency to handle procurement themselves? ITS has an exemption procedure in place to allow agencies in special situations and institutions of higher learning or public universities to handle a procurement in-house. The Exemption procedure allows agencies and public universities to request exemption from ITS to handle specific information technology procurement projects which, by law, require solicitation of bids or proposals, without the involvement of ITS.

The exemption procedure is designed for projects involving traditional information technology equipment, software, or services which the agency/public university has the in-house resources and expertise to procure without ITS involvement. The procedure exempts projects from ITS involvement in the procurement. It does not exempt the agency or public university from following public purchasing requirements. The exemption should be approved by ITS before an advertisement is issued for the procurement. A request for exemption should be submitted on an Exemption Request form. A copy of the Exemption Request form is available in Word or PDF format on the ITS website at Procurement Request Forms.

How do I purchase new phones/phone system? Contact the Procurement Help Desk at 601-432-8166 prior to formulating and submitting any requests for procurement of telecommunications equipment. See 011-080 ITS Telecommunications Contracts and Services for State Agencies and 011-085 ITS Telecommunications Contracts and Services for Institutions of Higher Learning (IHLs) for more detailed information.

Can I lease IT equipment? Yes. Agencies and IHLs are able to consider multiple funding models for each procurement project, and need to specify models of interest, including a leasing alternative within the Competitive Procurement request.

How may an agency acquire an item that is Sole Source? Mississippi Public Purchasing Law (Section 31-7-13) specifies that noncompetitive items available from one source only be exempted from bid requirements (sole-sourced). ITS statute, in Section 25-53-5 (p), permits ITS to utilize provisions in Public Purchasing law or regulations, when applicable. In certain limited situations, with appropriate written documentation and proper approval, information technology acquisitions may be sole-sourced. ITS applies a strict interpretation of the single source definition and is a strong advocate for conducting a competitive procurement unless the reasons for not competing are overwhelming and incontrovertible.

Per Public Purchasing law, acquisitions must meet the following criteria to be authorized as sole source:

  1. The product or services being purchased must perform a function for which no other product or source of services exists,
  2. The purchaser must be able to show specific business objectives that can be met only through the unique product or services, AND

32

  1. The product or services must be available only from the manufacturer and NOT through resellers who could submit competitive pricing for the product or services.

Additionally, acquisitions of IT services must include the following information to be authorized as sole source:

  1. An explanation about why the amount to be expended is reasonable, and
  2. An explanation regarding the efforts by the purchaser to obtain the best possible price.

Customers should reference 013-030 Procurement Types: Sole Source for more detailed information.

What is an Express Product List (EPL)? Who can use the EPL? Express Products Lists (EPLs) are compilations of proposals competitively solicited by ITS. Categories are added, changed and dropped based upon purchasing demand. Agencies, public universities, community/junior colleges, and other governing authorities may use the lists to make information technology purchases in accordance with ITS procedures and guidelines. Refer to 011-030 Procurement Instruments: Express Products List (EPLs) for more information.

What if I need a product or service that is not on an EPL? The agency or IHL may either fill out a Competitive Procurement Request form or ask for an Exemption to bid the products or services themselves. Reference 015-010 ITS Procurement Limits Policies: State Agencies or 015-020 ITS Procurement Limits Policies: IHLs for information regarding procurement guidelines based on the type of procurement and total lifecycle cost.

Do IT services have to be bid? Yes, Section 25-53-3 of the Mississippi Code of 1972 defines ITS' authority over the acquisition of any information technology, computer or telecommunications equipment, electronic word processing and office systems, or services utilized in connection therewith, including, but not limited to, all phases of computer software and consulting services and insurance on all state- owned computer equipment. Note that, unlike public purchasing law, the statute that defines ITS' purview over technology acquisitions includes services. All technology services, whether for direct, hands-on skills such as application development and network support, or for such technology consulting services as technology studies, project management, technology advisory roles, quality assurance support, and facilities management, are within ITS purview. Reference 001-020 Acquisitions within ITS Purview in the Procurement Handbook for more information.

Source: 25-53-1, et seq

33

Part 2 Chapter 2: FAQs Rule 202.2: 002-020 FAQs for Vendors Vendor FAQs

How do I do business with the State of Mississippi? How do I get on the State “vendor lists”? How do I receive notification of RFPs and Sole Sources? How do I check the notification of award for an RFP? How do I obtain information related to a particular project or proposal (Public Records Request)? How do I obtain a MAGIC vendor code? How do I check the status of a PO? How do I add hardware, software or services to my EPL listing? How do I get added to an EPL if the EPL RFP due date has passed? How do I obtain a state government contact list? How do I verify that ITS is tax exempt?

How do I do business with the State of Mississippi? Refer to the information located in 021-010 How to Do Business with the State of Mississippi.

How do I get on the State “vendor lists”? Your company does not have to be on a state “bid” list to do business with the State of Mississippi. We suggest that you review the information on the ITS website to determine how best your company could provide products or services to the State of Mississippi.

From the home page, select "Procurement" on the top of the screen. The link is Vendor Information. The ITS Vendor Information page provides information concerning how to do business with the state of Mississippi and includes links to other vendor-related resources. You would particularly need to note the link to RFPs and Sole Sources Advertised. By choosing this link you will access a list of Current Requests for Proposals. If an RFP requests products or services that your company can supply, you may respond to the RFP.

There is another link on the Vendor Information Page called General RFPs. General RFPs are solicited yearly in January for use through the following January to acquire products and services for more routine projects that do not require an individual Request for Proposal document just for that project. The General RFPs for the calendar year are advertised in late fall for receipt in January. Vendors may respond to General RFPs after the initial proposal due date at any time during the year until November 30th.

How do I receive notification of RFPs and Sole Sources? ITS doesn’t notify vendors directly when solicitations for RFPs and Sole Sources are published. We publish all of our RFPs and sole source advertisements on the ITS website. Select “Procurement” on the top of the home page. The link is RFPs and Sole Sources Advertised. (Note: There is also a quick link to this information on the right hand side of the home page).

34

We also publish all RFPs and Sole Sources in the Clarion-Ledger, typically on Tuesdays, the Mississippi State Government Transparency site located at https://www.ms.gov/dfa/contract_bid_search/, and ITS maintains a bulletin board of current technology solicitations near the reception area on the first floor or ITS administrative offices, 3771 Eastwood Drive, Jackson, MS 39211.

How do I check the notification of award for an RFP? Check the ITS Website, by selecting "Procurement" on the top of the home page. The link is RFPs Closed. (Note: There is also a quick link to this information on the right hand side of the home page).

How do I obtain information related to a particular project or proposal (Public Records Request)? All requests for information under the Public Records Act must be submitted in writing to: Executive Director Department of Information Technology Services 3771 Eastwood Drive Jackson, MS 39211 RE: PUBLIC RECORDS REQUEST Refer to 019-010 ITS Public Records Procedures for more information.

How do I obtain a MAGIC vendor code? In order to receive payment from state agencies, vendors must be set up in Mississippi’s Accountability System for Government Information and Collaboration (MAGIC). Each ITS RFP will require the vendor to supply their MAGIC vendor code. To determine whether a vendor is a registered supplier in MAGIC, go to the MAGIC Vendor Information page and follow the steps below:

  1. Enter the first five characters of the Vendor Name or the vendor’s 11 digit SAAS Vendor Number.
  2. Click Submit. If the vendor conducted business with the state prior to July 2014, the vendor’s information will include a MAGIC Vendor Number, SAAS Vendor Number, Vendor Name, City, State, and Zip displayed. If vendor information does not exist in MAGIC, “The query you submitted returned no records." will be displayed.

Converted vendors need to submit an email via mash@dfa.ms.gov to request a MAGIC User ID and Password. Enter "Vendor ID Request" as the email Subject, and include the following information: • MAGIC Vendor Number • Vendor Name • Contact Name • Contact Email Address • Contact Phone Number If the vendor is not a registered supplier and wishes to do business with the State of Mississippi, the vendor needs to visit the following link to register: State of Mississippi Supplier Registration. If the vendor attempts to complete the registration process and is already a

35

converted vendor in MAGIC, they will receive a duplicate error message and will need to call the MMRS Call Center at 601-359-1343, Option 2 for assistance in locating vendor information. If the vendor does not wish to use the State of Mississippi Supplier Self Registration process, the vendor will need to complete the Supplier Registration Form and contact the State of Mississippi agency that they desire to do business with to complete the registration process. How do I check the status of a PO? The Vendor should contact the Agency for whom ITS conducted the procurement. That agency will issue the PO.

How do I add hardware, software or services to my EPL listing? Depending on the EPL, products may or may not be able to be added. Some EPLs do not allow for changes until the mid-cycle update or the new EPL cycle. Other EPLs may be changed with the mutual consent of ITS and the vendor. To understand more about adding products or services to a specific EPL, review the RFP by checking the ITS website under “Procurement” on the top of the home page. The link is Vendor Information. Scroll down to EPL RFP Cycle Dates and New Vendor Opportunities.

How do I get added to an EPL if the EPL RFP due date has passed? If the EPL has its mid-cycle update, which usually occurs six months after the original RFP due date, submit a proposal at that time. To understand more about when to respond to a specific EPL, review the RFP by checking the ITS website under “Procurement” on the top of the home page. The link is Vendor Information. Scroll down to EPL RFP Cycle Dates and New Vendor Opportunities.

How do I obtain a state government contact list? The list may be requested via the ITS website, using the Contact Tab on the right side of the page. The list is sent via e-mail, usually within 2 business days.

How do I verify that ITS is tax exempt? There is a tax exempt letter on file in the ITS Business Office from the Mississippi Department of Revenue that exempts ITS from sales tax under Section 27-65-105A of Mississippi Code. If more information is needed, contact the project manager. The project manager’s contact information is included on the cover page of the RFP. Source: 25-53-1, et seq

36

Part 2 Chapter 3: Glossary of Terms Rule 203.1: 005-125 Competitive Written Bid IT purchases over $5,000.00 but not over the dollar amount established in Section 31-7-13(c) have been delegated by ITS to the purchasing entity. Purchases in this price range do not require advertisement of bids but do require at least two competitive written bids. "Competitive written bid," often referred to as a "written quote," is defined as follows: a bid submitted on a bid form furnished by the buying agency or governing authority and signed by authorized personnel representing the vendor, or a bid submitted on a vendor's letterhead or identifiable bid form and signed by authorized personnel representing the vendor. You must select the lowest quote.

"Competitive" means the bids are developed based upon comparable identification of the needs and are developed independently and without knowledge of other bids.

Source: 25-53-5 (o); 31-7-13 (c)

37

Part 2 Chapter 3: Glossary of Terms Rule 203.2: 005-150 Consensus Scoring ITS utilizes a Consensus Scoring methodology for proposal evaluation. ITS has found that a consensus rating arrived at by the evaluation team after consideration and discussion of all information provided by a vendor represents a more accurate assessment of the vendor's offering than does a mathematical averaging of individual evaluators' scores.

In a consensus scoring approach, individual evaluators read the assigned proposals, or sections of proposals, prior to evaluation work sessions and make notes of proposed scoring, observations of strengths and weaknesses, and questions regarding the vendor's proposal.

During consensus scoring sessions, the evaluation facilitator directs the team's attention to each item in the specifications. The evaluation team considers one proposal at a time, comparing the vendor's proposed offering against the specifications in the underlying RFP or LOC. Consensus scoring sessions encourage open discussions and questions among members of the evaluation team. Evaluators discuss the relative strengths and weaknesses of a vendor's proposal in each area. Open debate about a vendor's statement or response is encouraged to help ensure nothing proposed by a vendor in response to a requirement is overlooked. This discussion may provide additional insight into the vendor's offering and/or correct misperceptions of individual evaluators, so that the consensus score arrived at by the team may differ from the initial score of the majority of evaluators and from the mathematical average of the individual scores. The most important factor in assigning a final consensus score to any item is that the score accurately reflect the merits and value of the vendor's proposal for that item.

Once the team has arrived at a consensus score for an item in the proposal, the evaluation facilitator captures the consensus score along with documentation of the team's observations of noted strengths and weaknesses of the vendor's proposal for that item. Narrative documentation is required for items that either exceed the specification or do not meet the specification in some manner. Only the consensus score sheet and comments are official and become part of the project file. Individual team member evaluation worksheets and notes are collected and destroyed once the consensus scoring is completed.

If an item or area in a vendor's proposal is not clear or cannot be scored due to ambiguity or missing information, the evaluation team may decide a written clarification from the vendor is appropriate for a given item. In this case, a written request for clarification will be generated and sent to the vendor. The area or item under review may be suspended from scoring until the response is received from the vendor or a temporary score may be assigned. When the clarification is received, the evaluation team once again addresses the item and determines a final consensus score. Source: 25-53-3 (g); 25-53-5 (o)

38

Part 2 Chapter 3: Glossary of Terms Rule 203.3: 005-200 Delegation of Approval Mississippi Code Section 25-53-21 (f) specifies that the ITS Executive Director shall receive, review, and promptly approve or disapprove all requests of agencies of the state for the acquisition of computer equipment or services, which are submitted in accordance with rules and regulations of the authority.

Section 25-53-25 (2) allows ITS to delegate approval for certain acquisitions as follows:

The authority [i.e. ITS Board] may establish policies and procedures for the purpose of

delegating the bidding and contracting responsibilities related to the procurement of computer

equipment or services to the purchasing agency. Such policies and procedures must address

the following issues:

  1. Establish categories of equipment or services affected;
  2. Establish maximum unit and/or ceiling prices of such procurements;
  3. Establish reporting, monitoring and control of such procurements; and
  4. Establish other such rules and regulations as necessary to fully implement the

purposes of this section. Nothing in this subsection shall be construed to imply

exemption from the public purchases law, being Section 31-7-1 et seq.

Delegation of Approval is the term for ITS' delegation of the responsibility and approval for certain routine information technology acquisitions to the agencies and public universities under ITS purview. Purchases may be made under these delegation procedures without prior ITS approval. Examples include certain categories of procurements below the bid threshold, purchases made from the ITS Express Products Lists, and delegation of the procurement process to state institutions of higher learning (public university) up to a defined dollar limit, in accordance with Mississippi Code Section 25-53-5 (b) to give consideration to the special needs of such institutions due to their teaching and research functions.

For specific delegation dollar amounts and categories, refer to 015-010 Procurement Limits Policies: State Agencies and 015-020 Procurement Limits Policies: IHLs. The delegation amounts are different for state agencies and for public universities. For public universities, the approval of technology purchases below the cost threshold requiring ITS involvement is specifically delegated to the public university’s CIO, who must approve all such acquisitions, whether acquired competitively or through sole source certification.

Because ITS has delegated the procurement process to IHLs for certain dollar amounts above the threshold for competitive bidding and sole source certification, this delegation also includes giving the IHL the authority to advertise and issue an RFB, ITB, RFP, or other competitive instrument, evaluate responses, make an award, and negotiate and execute a contract. The advertisement for competitive procurements issued by IHLs must be made in accordance with ITS Statute 25-53-5 (o) (in a newspaper of general circulation in the State). Note that, for any delegation or exemption, ITS requires that the state agency or public university follow ITS Statute 25-53, along with IT Procurement policy and procedures, as documented in this Handbook. For example, all ads and procurement instruments must be published on the Internet in a location that is readily searchable

39

by and available to the general public, and published on the Mississippi State Government Transparency site located at https://www.ms.gov/dfa/contract_bid_search. Source: 25-53-25 (2)

40

Part 2 Chapter 3: Glossary of Terms Rule 203.4: 005-400 Lifecycle Cost The lifecycle cost of an information technology project means the total committed costs of the project, not just the initial or up-front costs. Lifecycle cost includes all costs associated with obtaining the item and maintaining and operating it for its projected lifecycle. Initial or one-time costs might include purchase price, freight, installation, and training. Ongoing costs include such expenses as post-warranty maintenance; support, including help desk charges, upgrade charges, and on-site vendor personnel; and any recurring usage charges. Examples: (1) An acquisition of equipment with a projected lifecycle of five years, a purchase cost of $100,000, monthly hardware maintenance of $250, and related annual software fees of $10,000 has a lifecycle cost of $165,000 (($100,000 + ($250 x 60 months) + ($10,000 x 5 years)). (2) An acquisition of software from the Microsoft Enterprise Agreement is a three-year purchase commitment. The lifecycle cost is the cost per seat times the number of seats times 3 years. (3) For a turn-key acquisition of hardware, system software, and consulting services for the development of an application system, the lifecycle costs consist of: (a) all initial fees for hardware and software, (b) hardware and software maintenance and support costs over the projected life of the hardware and system software, (c) all consulting fees, including initial development, implementation, training, data conversion, and other requested services, and (d) any applicable ongoing costs for support of the resulting application system. As part of the procurement request to ITS, the customer is asked to provide an estimate of the useful life of the acquisition prior to replacement. This estimate is used as the lifecycle term over which the lifecycle cost is computed.

See the definition of "Project”, Section 005-600, for an explanation of the implications of project lifecycle costs. Source: 25-53-5 (o)

41

Part 2 Chapter 3: Glossary of Terms Rule 203.5: 005-600 Project Why define a project? (1) Each ITS Express Products List (EPL) specifies a maximum spending limit per project. For projects costing up to the designated amount, ITS has delegated to the purchasing entity the authority and responsibility for selecting the lowest and best vendor for the specific project from among the offerings on the EPL. Projects with total project lifecycle costs above the EPL limit are beyond the scope of this delegated process and are subject to full ITS review and authorization. See Handbook Section 005-400 for the definition of lifecycle cost. [Note: with ITS participation and approval, EPLs can be utilized as the procurement instrument for projects above the EPL spending limit via the Planned Purchases process (Handbook Section 013-080) or by submitting a Competitive Procurement Request for ITS to issue a Letter of Configuration based on the appropriate EPL.

(2) For information technology projects involving the expenditure of funds above a specified limit, state law generally requires: (a) that the acquisition be based upon competitive specifications; (b) that the acquisition be publicly advertised; and (c) that sealed proposals be received and evaluated to determine the lowest and best respondent [Mississippi Code Annotated, Section 25-53-5 (o)]. State law further specifies that it is unlawful to split purchases in order to circumvent the requirements for advertising [Mississippi Code Annotated, Section 31-7-13 (o)]. ITS policies and procedures use the total project lifecycle cost to determine whether a given acquisition is above the bid threshold and to further determine the procurement mechanisms that can legally be used for that acquisition. See Handbook Section 005-400 for the definition of total project lifecycle cost and ITS Procurement Limits Policies in Section 015-010 (State Agencies) and Section 015- 020 (IHLs) for an overview of procurement mechanisms by lifecycle cost range. Note: The current bid threshold is the expenditure of funds in excess of the dollar amount established in Section 31- 7-13(c).

(3) Mississippi Code Annotated, Section 25-53-5 (k) requires that contracts for information technology purchases be approved by the ITS Board. The Board is authorized to delegate this approval to the ITS Executive Director for projects costing less than a specified amount. See Handbook Section 018-030 for current Executive Director thresholds and Board Approval requirements. The total project lifecycle cost is used to determine whether a contract can be approved by the ITS Executive Director or must be submitted to the ITS Board for approval.

(4) Mississippi Code Annotated, Section 31-3-21 requires that any contractor submitting a bid for a public project that (a) involves erection, building, construction, reconstruction, repair, maintenance or related work and (b) will cost in excess of $50,000, possess a Certificate of Responsibility issued by the Mississippi Board of Contractors. This section of the code also requires that all bids submitted for such projects contain, on the exterior of the bid envelope, contractor’s current certificate number. Projects involving inside or outside cabling fall within this category and are under the purview of ITS. The total project lifecycle cost is used to determine whether the project requires a certificate of responsibility, which in turn determines who can bid on the project and whether the bid must have the certificate number on the exterior of the bid envelope to be accepted.

42

Guidelines for defining a project: A project has a specific objective or desired accomplishment and defined starting and ending dates (even if these are rather flexible!). A project is not “business as usual,” but a process that is outside the normal flow of work. Projects have a defined scope and a predefined budget and are often executed by contractors or by staff members who are acting outside their everyday work roles.

ITS gives our customers some flexibility in defining a “project,” based on the customer’s procurement process and guidelines from their auditors. ITS does not make a final ruling but has developed the guidelines below for determining whether expenditures should be considered a single project. The primary “rule of thumb” is that the purchaser document and consistently apply a valid and defensible methodology for defining a project and that the purchaser look at each project separately in regards to vendor selection. ITS suggests the following factors that may determine the definition of an information technology project:

  1. A project might be defined by the time frame of the purchases (e.g. all agency workstation procurements for a fiscal year might be a single project; a technology training class would typically be a single project). Note: The 2-way radio EPL specifically defines a "project" for the purpose of the EPL purchase limit as the total expenditures for equipment and services made by an agency from this EPL per fiscal year.
  2. Funding source might define a project (e.g. if the funding sources place different requirements on the purchasing entity, separate projects might be needed to accommodate these requirements).
  3. In some cases, location of equipment might determine a project (e.g. if each district office can consider a different vendor and/or a different technical solution, these acquisitions could be considered separate projects.)
  4. Technical requirements can define a project (e.g. acquisition of several variations of desktop workstations for an agency might be a single project, while the acquisition of desktop workstations for the central office and of ruggedized laptops for the same agency’s mobile units might be separate projects).
  5. Potential for volume discount can define a project (i.e. Will aggregating requirements for hardware, software, or services across time, locations, or funding sources potentially result in significant cost savings to the state? Will using a competitive process potentially result in better pricing? Note that the instructions for EPLs specify that published prices are not-to- exceed amounts based on a quantity of one. Customers are encouraged to aggregate purchases in order to negotiate for volume discounts from EPL vendors where applicable.)
  6. Business functionality and proposed utilization of hardware, software, and services can define a project. (e.g. multiple scanners purchased for general use across an agency might be a stand- alone project; a scanner purchase for a specific application system for which other hardware, software, and services are also being procured should probably be considered a part of the larger project.)

Source: 25-53-5 (o); 31-7-13 (o); 25-53-5 (k); 31-3-21

43

Part 2 Chapter 3: Glossary of Terms Rule 203.6: 005-800 Silent Period The Silent Period is a period of time during procurement in which any state employee directly or indirectly involved in any step in the procurement process, including but not limited to procurement management, development of specifications, evaluation of proposals, and contract negotiations, should not communicate with prospective vendors. The silent period typically applies to all employees of the customer agency. All communications with potential vendors during the silent period should be directed to the individual who is the contact person for the procurement or should occur only as authorized by the contact person in conjunction with the procurement process.

ITS recommends that customers begin the silent period at the time they begin formal development of requirements and specifications. Prior to that time, customers can and should communicate with vendors about the marketplace and technologies as they formulate their project scope and approach. At the point in time when a customer has done adequate research and begins to formulate the specific requirements, the customer agency should cease their communications with vendors in that marketplace to avoid any appearance of impropriety or favoritism.

If a customer desires a more formal approach to marketplace research, a Request for Information may be published. The RFI process is not covered by the Silent Period. Customers that desire ITS assistance with the RFI process should submit a Competitive Procurement Request form to ITS. Customers that wish to conduct the RFI process without ITS involvement should submit an Exemption Request form to ITS.

ITS also recognizes that incumbent vendors may be performing work for the customer and that the work may or may not be related to the scope of an active procurement. In those cases, the customer agency will naturally continue to have contact with the vendor in the course of doing business. This contact is not an issue. Customers should, however, take extra precaution to avoid a perception of misconduct by (1) meeting in groups and avoiding extensive one-on-one time with a vendor who provides the products and services being acquired in the active procurement; and (2) not discussing the active procurement.

Source: 25-53-5 (o)

44

Part 2 Chapter 4: Procurement Contacts Rule 204.1: 007-010 Procurement Contacts: by Role The responsibility for technology procurements lies with the Information Systems Services (ISS) Division of the Mississippi Department of Information Technology Services (ITS). The following individuals can assist you with various aspects of technology procurement, whether you are a customer, a vendor, or an interested party. Additional contact information for specific procurements is published with the Request for Proposals or Letter of Configuration.

If you reach voice mail and need to speak with someone immediately, press "0," stay on the line, and explain to the ITS Receptionist the type assistance needed.

Type Assistance: Name Telephone E-mail Procurement Help Desk (Rotates) 601-432-8166 Procurement Help Desk ISS Division Director Lynn Ainsworth 601-432-8150 lynn.ainsworth@its.ms.gov Procurement Process Specialist Tina Wilkins 601-432-8161 tina.wilkins@its.ms.gov Procurement Team Leaders: Renée Murray 601-432-8146 renee.murray@its.ms.gov Tangela Harrion 601-432-8112 tangela.harrion@its.ms.gov Anthony Hardaway 601-432-8110 anthony.hardaway@its.ms.gov EPL Questions Contact the Procurement Help Desk Public Record Requests Jeanette Crawford 601-432-8179 open.records@its.ms.gov Customer Invoices Lynn Ainsworth 601-432-8150 lynn.ainsworth@its.ms.gov ITS Switchboard Receptionist 601-432-8000

Source: 25-53-5; 25-53-21; 25-53-25

45

Part 2 Chapter 5: Procurement Process Rule 205.1: 009-001 ITS Procurement Process Flows Diagrams of the ITS procurement process are provided below

Table of Contents: • ITS Procurement Process • Customer Purchase Process (after ITS approval is received) • Details of Process by Procurement Type o Competitive Procurement: RFP o Competitive Procurement: LOC o Revision to Previous Approval o Sole Source Certification o Exemption o Planned Purchase o Protest Process o Quality Assurance Review

46

47

48

49

50

51

52

53

54

55

56

Part 2 Chapter 5: Procurement Process Rule 205.2: 009-005 Procurement Process: Submitting a Request Instructions for Preparing and Submitting a Procurement Request Overview Requested Information: General/Competitive Procurement Additional Information: Cooperative Purchasing Supplement Additional Information: Sole Source Certifications Additional Information: Emergency Purchases Additional Information: Exemption Requests Additional Information: Revision Requests Additional Information: Planned Purchase Requests OVERVIEW Requests for the procurement of information technology hardware, equipment, systems, software or services by agencies or public universities under the purview of ITS may be submitted to ITS via the On-line Procurement Requests System or by faxing, mailing, or emailing the applicable request form. The On-line Procurement Requests system is accessed from the ITS website under the "Procurement" link on the top of the home page, selecting “On-line Procurement Requests.” State employees should use their ACE user id and password to log in. Staff at IHLs, local governments, or other entities that do not use the ACE applications should contact the ITS Procurement Help Desk at (601) 432-8166 to obtain a user id. Customers who do not use the On-line Procurement Requests System will find the forms needed for submitting a request under the "Procurement" link on the top of the ITS home page, by selecting Procurement Request Forms. All forms are available in PDF or Word format. Note: The ITS procurement function occasionally has a queue of projects that have been submitted and are waiting assignment to the ITS Technology Consultant who will conduct or process the procurement request. ITS encourages customers to send in requests as early as possible to help ensure the products or services being procured are available when needed. Customers do not have to complete every item on the procurement request form prior to submitting a procurement. It is preferable to submit partial information than to hold the request for additional research and jeopardize the procurement schedule. Customers are encouraged to include the Agency IT Planning Project Name and Number that contains documentation related to the procurement request.

57

Each Procurement Request form consolidates the basic information ITS needs to manage and track your request through the ITS procurement process and allows detailed information concerning the procurement to be attached. Include all the information about your agency or public university requested on the form, including project contact name, phone, hand mail or mailing address, fax number, and email address. It is also important that you assign a Project Title to each request that ITS can use to reference your project in our communications with you. Most other fields on the form are not required for initial submission of a request. The more information you provide, however, the more quickly and easily your request can be processed once assigned. ITS will need detailed background information about the needs to be met by this acquisition. ITS procurement personnel must fully comprehend what you are trying to accomplish with this acquisition to determine the best way to meet your needs. Detail as much as you know at the time of submitting the request. Your assigned Technology Consultant will work with you during the procurement process to obtain any additional information required. The request form asks for information concerning alternative solutions and functional specifications for the acquisition. If you have researched and documented alternatives and specifications, include these details in your request. ITS can expedite procurement requests that are submitted with complete, correct, and specific background, alternatives, and specification information. However, as with other information requested on the forms, ITS staff will be glad to work with you to research alternatives and develop functional specifications for items to most appropriately meet your needs. Agencies presenting to the ITS Board for approval of procurements must have the following: • A current IT Security Risk Assessment from a third-party security consultant. For more information, please visit the Information Security page of the ITS Website at http://www.its.ms.gov/Services/Pages/services_security.aspx. • A completed Business Case on the project detailing the scope, lifecycle cost, and return on investment of the procurement. To assist agencies in preparing a Business Case, documentation and forms are located on the Agency Planning Page of the ITS website at http://www.its.ms.gov/Services/Pages/Agency-IT-Planning.aspx.

The information listed below further defines the information to be provided on the various request forms. Call the ITS Help Desk at (601) 432-8166 if you have additional questions when filling out the forms. REQUESTED INFORMATION: GENERAL The following items are generally applicable across multiple request types. Project Title - The project name used by the customer agency when referencing the project (up to 40 characters) that uniquely identifies a procurement request for the customer. Stimulus (ARRA) Funds? - Mark “Yes” or “No” as to whether or not the project is ARRA- funded.

58

Customer Contact Information: Agency/Institution - The full name of the agency or institution submitting the request. Address - The complete address for the contact person listed below as the project contact. This may be a HANDMAIL address or a U.S. postal address. Contact Person - The name and title of the individual whom ITS can contact should additional information be needed. This person should be involved in the preparation of the request and completely familiar with the background, requirements, project schedule, etc. Phone - The telephone number of the contact person. Fax - The fax number of the contact person. E-mail address - The e-mail address of the of the contact person MAGIC Customer Number Code (state agencies only) – to make sure that invoices for ITS procurement services are addressed and routed correctly to your agency Division/Department - The department(s) and subdepartment(s) that will use the requested equipment or services. Handmail - Mark “Yes” if the address listed in item is a handmail address for delivery by DFA's Office of Capitol Facilities. Mark “No” if the address listed is a postal address. Project Summary: Narrative Description of Project - Provide an overview of the project: • What is being procured • What business needs the product or services will meet • Any applicable statutory mandates • Is this a new function, replacement of current automation, automation of a manual function ITS Acquisition Approval (CP-1) should be effective through this date - Date through which the requesting agency will need to pay vendor invoices. For example, if you anticipate that a software system will be implemented by December 31, 2013, and you will pay monthly hosting fees for three years beginning with implementation, the CP-1 must be in effect long enough after December 31, 2016 to allow payment of the final vendor invoice. Forty-five to sixty days after the anticipated completion of a project is a good rule-of-thumb in assigning this date. Cost Estimates - This section of the request form is designed to capture your best estimates of one-time and recurring costs for the lifecycle of the project. Costs should be broken out by state fiscal year, for the lifecycle of the project. Note: These estimates should include total project costs to be paid to outside vendors for new hardware, software, and services, and do not include internal agency costs such as staff, floor space, and existing hardware.

59

Time Constraints: Item Needed by - Date by which you need the requested equipment or software delivered or services to begin. Funds Expire - Date funds expire, for state or federal funding year, grant end date, or other time- related funding constraints. Discuss Funding - • How much of total anticipated funding needed for the project is actually available at this time? • What is your total project budget (external and internal)? • What is the percent of federal matching funds, if applicable? • Are there other funds that are not general fund monies? • From what fund number will the payments be made? Anticipated Lifecycle of Products/System (i.e. estimate years effective use) - • How long do you anticipate using the product to be acquired before replacing? • What types of upgrade options are needed? • How long do you plan to pay maintenance/support? • What do you anticipate the term of the initial contract will be • What renewal options are desirable (i.e. number of renewals and length of each optional renewal term) Acquisition Details: Items Requested - Depending on what is being requested, you may either (1) detail the requested items on the form or (2) attach specifications. If detailing the items on the form, list the name, quantity, description, and building location(s) of the items being requested. Include the estimated dollar amount of each item or service. If more space is needed, you may include an itemized attachment. If you itemize on an attachment, be sure to summarize the acquisition in the space provided and reference the attachment. If attaching specifications, furnish as much of the information outlined below as practical and applicable. Remember: ITS statutes generally require that procurements of information technology be open and competitive. Unless valid justification of a compelling business need is presented and approved by ITS, ITS will not issue specifications that limit competition when there are multiple sources available to meet your business needs. We are committed to working with you to develop the best possible specifications both to ensure your objectives are achieved and to protect you via a legal and defensible procurement. • Initial minimum functional specifications - Based upon your agency or public university's initial needs, define in as much detail as possible what your minimum requirements are for the item(s) you are requesting. Outline those requirements you consider mandatory. Do not simply list specifications from a vendor's technical sheet. Instead, define those functions that correlate with your business needs. Where specifications are restrictive, be particularly specific as to why the requirements are necessary to meet your needs. If the item(s) requested must be compatible with existing

60

equipment or interface with current applications, describe the equipment and applications currently in place. For application software, are you seeking a COTS solution or custom development? How much customization of an existing package is acceptable? Note: The preferred format for detailed requirements is bulleted or paragraph form in a Word document. Do not insert the specifications into an ITS RFP or LOC template or develop an RFP or LOC document, as our templates change frequently and this step will create extra work for you as our customer. • Training, documentation, implementation, and related services - In addition to the functional requirements for equipment or software, what services will be needed for the vendor during implementation? What are training requirements (number of staff, level of training, location of training, classroom versus online, etc.)? • Maintenance and support requirements - Selection of lowest and best proposal in many instances is determined by the maintenance and support a vendor can offer on the item(s) he sells. Define what maintenance arrangement you deem most acceptable for the item(s) requested. Describe platform and infrastructure - Provide relevant information depending on what is being procured: • What voice/data/video network connectivity will be needed • Provide information on transaction size, volume • Describe utilization of State Data Center resources: o Mainframe o eGovernment portal o Payment engine o Document management o Hosting • Describe security requirements based on classification of data and how these requirements will be met • What database and programming language will be used • Will any additional hardware, software, personnel be required at your agency (beyond what is included on this request) ITS Statute and the ITS Board require that systems for state agencies be hosted at the State Data Center by default. If requesting approval for equipment to be located outside the State Data Center, provide justification. If requesting approval for hosting to be provided by other than the State Data Center, provide justification. Progress to date - What has been done related to this project, including any communication with ITS staff (data/voice/procurement/other)? Your assigned project manager can process your request most effectively if he/she is aware of any decisions that have been made or information that has been obtained to date. If applicable, provide names and phone numbers of contacts within ITS or within the requesting organization who can provide additional information. Vendors Contacted: Attach written estimates or other information received from vendors - Provide the names, addresses and telephone numbers of vendors whom you have talked with

61

regarding the procurement. Provide copies of any vendor proposals, configurations, recommendations, or literature you have received on the item(s) being requested. Critical Factor(s) (in the selection of a vendor/brand/solution for this acquisition) - Section 25-53-5 of the ITS law specifies that acquisitions be made from the lowest and best proposal. Many factors can be considered in determining the lowest and best proposal. If selection of the proposal and products to meet your agency/public university’s needs should be based on criteria in addition to price, you should furnish a listing of criteria upon which your agency/ public university believes the selection of "lowest and best" proposal should be based and the priority of each criterion. What are the most critical functional or technical requirements from your agency's perspective? Discuss budget/cost constraints. Acknowledgement of procurement costs - Since ITS does not receive funding for the procurement function, we must bill for the time spent performing procurement-related tasks. This billing is done on a monthly basis for hours expended during the prior month and continues until the procurement project is closed. For larger procurement projects or for smaller projects that span more than one month, you will receive multiple bills for services for a given procurement. When proposals must be solicited for an acquisition, the requesting agency/ public university is responsible for the costs of the required advertisements in The Clarion Ledger. Advertising charges and procurement services will be billed to the customer on the same invoice. When submitting a procurement form via mail, fax, or email, enter the name and title of the agency head, public university CIO, or designee on the line to the bottom left of the form. This person must then sign and date the request. By signing the request, the authorized individual acknowledges understanding of the procurement charges and commits the agency/public university to paying all costs incurred. In the On-Line Procurement Requests System, the acknowledgement of charges is required when the request is submitted to ITS. Note: ITS must assume that persons submitting procurement requests under their signature or via the on-line request system have been authorized to do so by their agency or public university. The customer agency must establish its own internal procedures regarding signature and procurement request authority. ADDITIONAL INFORMATION: COOPERATIVE PURCHASING SUPPLEMENT See 011-070 Procurement Instruments: Cooperative Purchasing Agreements for additional information on cooperative purchasing. Governmental Entity Establishing the Cooperative Agreement - Name of the specific governing body (level of government: state, local, federal; name of entity and department) or consortium (membership; type consortium) that initially established the cooperative agreement. Name of Cooperative Agreement - Specific contract/purchase instrument reference name. Examples: GSA Schedule 70; WSCA Wireless Communication & Equipment Contract. Contact at Sponsoring Governmental Entity - Name of person who can answer questions and provide any additional information required regarding the initial establishment and permissible use of the cooperative agreement.

62

Phone - Of contact Fax - Of contract Email Address - Of contact Certification this cooperative agreement is available for use by the state - Requestor should obtain certification from the entity establishing the cooperative agreement, stating that the State of Mississippi may use the pricing and terms and conditions as a procurement vehicle and that the contract was awarded in an open and competitive manner. Optionally, the requestor may ask ITS to obtain this certification from the contact listed above as part of the procurement process. Other Requirements for use of agreement - Requirements the purchaser must meet in order to use the cooperative agreement, including any necessary organizational memberships or other prerequisites. Attach printout and/or Internet link for requested products or services, with contract pricing

  • Attach a printout of the page from the contract, attachment, or Internet that shows the specific products or services being procured and the associated pricing of those items. Attach printout and/or Internet link for terms and conditions - Attach a copy of the contract, including any processes or procedures for negotiating state-specific terms and conditions as a modification or addition to the base contract. Provide a contact for contract questions and issues, if known and if different from the contact above. Cost Benefit Justification - Discuss and quantify research regarding the pricing and terms of the cooperative agreement demonstrating that the use of this agreement for the requested products and services is in the best interest of the State. ADDITIONAL INFORMATION: SOLE SOURCE CERTIFICATIONS Note: Certification must be renewed for revisions to previous Sole Source Acquisitions. The marketplace may have changed since the original sole source acquisition. After an initial contract term, a competition may be required. See 013-030 Procurement Types: Sole Source for additional information on Sole Source Certification. Specific business requirements to be met by the requested products or services - The purchasing agency or institution is responsible for documenting its business needs in the sole source request. What are the business requirements, based on your agency's mission, enabling legislation, or external mandate, that are to be met via the sole source acquisition? Include both an overview of the business requirements and details on the specific features of the requested product or service provider on which the sole source certification will be based. Other products/vendors researched or evaluated - Before a product or service can be certified as single source, the market must be researched to identify alternate sources or products.

63

Describe the competitive market and document the specific reasons why other products or service providers in this market cannot substantially meet your business needs. If similar products or services exist in the marketplace, the business case for the unique functionality or characteristics of the sole-sourced item must be compelling for the procurement to be sole- sourced under state statute. Unique features (i.e. special functionality) of the requested product(s) or vendor - Document in detail the unique capabilities of the product or service to be sole-sourced. These features should be based on business requirements described above. As the requestor, you are responsible for demonstrating that only one product or supplier is capable of satisfying these requirements. The uniqueness must be based on functionality. The following are not acceptable as sole source determinants: • Patented methodologies • low cost • special incentives • largest user base • other comparative features

Is the expenditure reasonable? Explain why or why not: Per Mississippi Code Annotated Section 27-104-7(2)(o), purchasers requesting sole source approval of services must provide an explanation of why the amount to be expended for the service is reasonable. Section 27- 104-7 directs the efforts of the Public Procurement Review Board, and by policy and procedure, ITS follows similar documentation requirements.

Negotiation Efforts: Per Mississippi Code Annotated Section 27-104-7(2)(o), purchasers requesting sole source approval of services must provide an explanation of the efforts to obtain the best possible price for the service. Section 27-104-7 directs the efforts of the Public Procurement Review Board, and by policy and procedure, ITS follows similar documentation requirements. Vendor's Certification of Sole Source attached - In addition to the requestor's certification of need and uniqueness of the requested product, a statement is required from the vendor, on the company's letterhead. This statement should certify both that (1) the product is unique in the specific ways documented by the customer above and (2) the product is available only through the manufacturer and not via resellers. Requestors should provide instructions to vendors on the type of certification that is required by Mississippi's sole source statute. Vendors should not include adjectival justification (best, largest, fastest) but should clearly describe unique functionality. If there are resellers but the product itself is certified as single source, a product- specific competition must be conducted among resellers to obtain competitive pricing. Vendor's proposal attached - If the vendor has provided pricing and/or terms and conditions for a contract, attach these. Because the State is at a contractual disadvantage in an acquisition not based upon a competition with detailed specifications, it is especially important that the contract be based on the State's contract templates that meet Mississippi's statutory requirements. The proposal and vendor contracts provide a starting point for incorporating the specifics of the purchase into the State's paperwork as a solid contractual foundation that protects the purchaser for the life of the product.

64

MAGIC Vendor Code(s) - Vendor must be in MAGIC before a CP-1 can be issued - Because the vendor has already been determined in a Sole Source request, providing the following information in parallel with the documentation required for sole source certification may speed up the acquisition process. Place order to: Vendor name and address Remit to: Vendor name and address - Provide if different from "Place order to" information. Signature of agency head or IHL CIO (or designee) - In addition to acknowledging procurement charges, as described in “REQUESTED INFORMATION - GENERAL”, this signature, for a sole source request, is the requesting entity's certification that the request is in fact a sole source as defined in Mississippi Code and explained in Chapter 013-010 of the Procurement Handbook. ADDITIONAL INFORMATION: EMERGENCY PURCHASES See 013-060 Emergency Purchases for information on emergency purchases and requests. ADDITIONAL INFORMATION: EXEMPTION REQUESTS See 013-040 Procurement Types: Exemption for additional information on exemption requests. Planned Acquisition Method: Describe the manner in which this procurement will be conducted in fulfillment of state law - An exemption request is used by a purchasing entity to request that ITS delegate the procurement process for an acquisition that falls within ITS purview and has not been delegated to the agencies and institutions via a global delegation (See 015-010 Procurement Limits Policies: State Agencies and 015-020 Procurement Limits Policies: IHLs for information on global delegations) ITS cannot exempt a procurement from the competitive process required by state law. This section should be used to describe the competitive instrument that will be used for the acquisition (RFP, Request for Quotes, Bid), including a high-level description of the scope and content of that document, and a description of how the procurement will be handled by the requesting agency in accordance with such statutory requirements as advertisement in a newspaper with statewide circulation, receipt of sealed proposals, and fair and equitable determination of lowest and best response. Signature of agency head or IHL CIO - In addition to acknowledging procurement charges, as described in “REQUESTED INFORMATION - GENERAL”, this signature, for an exemption request, is the requesting entity's certification of the following: • The agency/institution will follow all applicable laws for public purchasing in the acquisition, including the following: o Developing open specifications o Advertising according to IT Procurement law, and ITS policy and procedure as documented in this Handbook o Ensuring a thorough and equitable evaluation of all responses o Responding in a timely manner to all public records and post-procurement review requests

65

• The agency/institution will negotiate any and all applicable contracts and contract amendments arising from the procurement, with signature authority for the State delegated by the ITS Executive Director to the agency/institution • Any protests resulting from the procurement will be heard by the ITS Executive Director and/or ITS Board, in accordance with the ITS Protest Procedure and Policy. The signature also acknowledges that the authority of the ITS Executive Director to negotiate limitation of liability cannot be delegated and does not apply to an exemption. ADDITIONAL INFORMATION: REVISION REQUESTS See 013-020 Procurement Types: Revision for additional information on revision requests. Project History and Accounting: CP-1 Number to be Revised - Full CP-1 number of current CP-1(s) (YYYYnnnn, where YYYY=Fiscal Year issued; nnnn = sequence number) Total Amount Authorized on CP-1 to be Revised - Total dollar amount originally approved on the current CP-1(s) (Dollar amount labeled "Lifecycle" on last page of CP-1) Reason(s) Revision Required - Check all that apply. For "Other," enter explanation as described below. Project Accounting - Summarize expenditures to date from the original CP-1, to show the remaining balance, if any, from the initial approval. Note: Provide invoice details for at least the previous 12 months. Payments older than 12 months may be summarized by Fiscal Year. This information is intended to help the customer and ITS reconcile the change request with previous approvals and to ensure the new CP-1 is issued for the correct amount, bringing forward any remaining dollars from the previous CP-1 if appropriate. Include any invoiced or encumbered amounts in the payment history and subtract the total amount spent or encumbered from the original approval amount to represent the current remaining balance as accurately as possible. Dollar Amount: Complete this section if the revision includes an increase in the dollar amount. Original Amount Approved - Total dollar amount originally approved on the CP-1 Current Balance - Amount remaining, per Project Accounting above. Amount of Increase - Total dollar amount of requested increase in project cost. Explain the reason for the increased cost in the section "Project Scope," as described below. New Balance - Current Balance + Amount of Increase; New CP-1 will be issued for this amount. Expiration Date: Complete this section if the revision includes an extension to the CP-1 expiration date.

66

Original - Provide the expiration date of the CP-1 that is being revised. New - Provide the desired expiration date for the new CP-1. Allow time to process final invoices after project completion. Vendor Information: Vendor Name - Complete this section if the revision includes a vendor name change. If the name change is due to an acquisition or assignment, provide all relevant information and explanation. Original - Vendor name as shown on current CP-1 New - Vendor name for new CP-1. If vendor is not in MAGIC under the new name, or if the project has been assigned to a vendor not in MAGIC, ITS will work with you and the vendor to acquire the W-9 form and any other documentation needed. Vendor Address - Complete this section if the revision includes an address change for the vendor. Note whether the change applies to “Notice”, “Remit To”, and/or “Place Order To” addresses. If the address change impacts the vendor file record in MAGIC, ITS will work with you and the vendor to acquire the needed documentation and submit the update to DFA. Original - Address as shown on current CP-1 New - Provide both physical and mailing addresses, if different. Project Scope - Complete this section if the revision includes any change in project scope from the scope defined in the original CP-1 and supporting contract documents. All revision requests that include an increase in dollar amount should include an explanation of that increase in this section. Scope changes with no cost impact or that reduce the total cost should also be clearly documented in this section. Examples of requested scope changes include: • More or fewer of specific items than originally planned • Alternate products or services in lieu of those originally planned • Additional consulting hours to provide additional services or services over a longer period of time. Provide quantitative information and unit costs, such as • Number of additional hours and hourly rates • Model of equipment • Unit cost • Quantity required • Description of new deliverable(s) and deliverable costs with vendor's methodology for determining that cost Other - Complete this section if the reason for revision included "Other." Provide an explanation of the change needed and the circumstances that led to the change request. This section can also be used to provide additional supporting details that would be required to issue a revised CP-1.

67

ADDITIONAL INFORMATION: PLANNED PURCHASES See 013-080 Procurement Types: EPL Planned Purchase for additional information on planned purchases. Project Title - Planned Purchases for FY20__: This standard project title is used for an agency's planned purchases for a fiscal year. ITS Project # (IT Plan) – From the Planning System Vendors Contacted - Specific instructions are included on the form for Planned Purchases regarding attaching written quotes from EPL vendors. Note: A minimum of two quotes are required for total FY purchases up to $1,000,000 and a minimum of three quotes are required above $1,000,000 total FY purchases. Selection and Justification: - Indicate the selected vendor(s) from the quotation received. See additional documentation on the Planned Purchases form. If the quote selected is not low cost, the requestor must supply substantial justification to support the selection. Name and official title of agency head to whom Planned Procurement authorization letter will be addressed - The authorization to exceed the EPL purchasing limits using the planned purchases procedure is issued in the form of a letter from the ITS Executive Director to the requesting agency's executive director or officer. Provide the full name and title of the agency's executive. This letter should be maintained in the purchasing file for audit purposes. Source: 25-53-5; 31-7-7; 31-7-13; 25-53-25 (2)

68

Part 2 Chapter 5: Procurement Process Rule 205.3: 009-010 Procurement Process: Multi-Year Prepayment Approvals In accordance with the authority granted under Section 7-7-27 Mississippi Code Annotated, the Department of Finance and Administration (DFA), by letter dated June 18, 2010, attached below, granted ITS the authorization to approve contracts for multi-year prepayment of information technology services and software licensing for ITS customer agencies. You may view this letter on page 74.

This authorization is specifically applicable to projects requiring ITS approval and does NOT apply to projects made under ITS' purchasing delegations to agencies.

Prior to granting any approval for a multi-year prepayment, ITS must carefully review the licensing or services to be provided to ensure prepayment is both a standard business model for the licenses or services being purchased and is advantageous to the State. If approved, ITS will ensure that contracts for these purchases contain appropriate protective language to reduce the risk of prepayment.

Once the prepayment has been approved, ITS will issue a project-specific approval letter to the customer agency, in addition to the usual CP-1 Acquisition Approval Document. The approval letter will cite the authorization granted to ITS by DFA.

Agencies must attach a copy of the ITS approval letter to the payment voucher (PV).

ITS Process for Approval of Prepayment for Technology Under a Blanket Waiver from DFA

  1. ITS receives a request from a customer for technology services or software licensing that could potentially include a multi-year prepayment. The most common situations for consideration of prepayment are warranty extensions, prepaid hardware support or software licensing, and prepaid hosting when the vendor must make a significant up-front investment in infrastructure.
  2. ITS includes language in the Request for Proposals (RFP), Letter of Configuration (LOC), Request for Quotations (RFQ), or Invitation to Bid (ITB) specifying that vendors must: a) provide pricing for one year as well as multi-year prepayment options that provide significant savings for the State so that the risks and benefits of prepayment can be evaluated; and/or b) define and justify any prepayment requirements in vendor’s business model for these services or software
  3. ITS evaluates proposals, including assessment of any significant cost benefits or vendor requirements for prepayment. If prepayment is required, ITS evaluates vendor’s justification to ensure this is a standard business model supported by the industry and by the vendor’s up- front investments. If prepayment is an option, ITS evaluates the cost savings to ensure the benefit of prepayment outweighs the risks.
  4. ITS discusses the evaluation of prepayment options with the customer. If customer requests acceptance of a prepayment proposal, customer documents that decision in writing to ITS.
  5. If a prepayment proposal is accepted, ITS includes language in the resulting project contract concerning the state’s ability to terminate based on non-appropriation of funds and a

69

requirement for a pro-rated refund of prepayment to the state upon any allowable termination of the contract. 6. ITS issues and uploads to MAGIC a CP-1 Acquisition Approval Document for the acquisition, documenting the services or licenses, amount and timeframe covered by the prepayment. 7. ITS sends a letter to the customer documenting the specifics of the prepayment authority, citing DFA’s authorization for ITS to approve such contracts. 8. ITS sends a copy of the executed contract to the customer for upload to the Merlin Award/Contract Interface. 9. Customer proceeds with the purchase, using the information uploaded to MAGIC by the ITS CP-1 process to encumber funds and make payment. Customer will attach a copy of the project-specific prepayment approval letter from ITS to the payment voucher.

70

AUTHORIZATION LETTER FROM DFA: Waiver for ITS to approve multi-year payments

Source: 7-7-27

71

Part 2 Chapter 5: Procurement Process Rule 205.4: 009-025 Procurement Process: CP-1 Approval Documents and MAGIC ITS CP-1 Acquisition Approval Form The ITS CP-1 Acquisition Approval form is used to notify agencies and institutions that ITS has approved the agency or institution’s request for the acquisition of information technology equipment, software, or service or has approved the exemption of a procurement from ITS. Upon approval, ITS prepares the form and emails (default), mails, or faxes the CP-1 to the designated contact at the customer agency or institution. This form specifically identifies the name of the vendor, a list of the products approved, associated costs, and any additional pertinent information for acquisitions made through ITS, and specifies the nature of the purchase and the maximum expenditure amount for exempted procurements.

For acquisitions made through ITS, the form is the agency/institution’s authorization to issue a purchase order and/or to make ongoing payments to the specified vendor for the products or services identified on the form and at the prices itemized. The agency/institution should promptly issue a purchase order upon receipt of the CP-1 as the CP-1 is based upon proposal pricing the vendor is bound to honor for a specified time period.

For acquisitions that involve recurring payments, the CP-1 form specifies an effective date and expiration date, authorizing payments throughout that time period. The frequency of payment, payment amount, and total number of payments to be made are also indicated on the CP-1.

The CP-1 form should be kept with related financial records to provide an audit trail of ITS approval. The CP-1 number must be referenced on each related purchase order(s). If a CP-1 approves payment of recurring costs, the dates covered by the payment should be specified on the purchase order.

CP-1 Form and MAGIC For state agencies, ITS loads a contract into MAGIC that contains the CP-1 approval information. Customers reference the MAGIC contract for payment processing.

72

CP-1 Revisions (Replacement CP-1s) It is necessary to contact ITS for revised or extended approval if any of the following occur: (1) Major changes to the configuration; (2) The vendor or vendor name changes; (3) The CP-1 has expired and payments still need to be made; (4) The cost exceeds the lifecycle cost authorized on the CP-1.

ITS approves a revision or extension by issuing a replacement CP-1. The replacement CP-1 has a different CP-1 number than the original CP-1 and voids the CP-1 being replaced. Once you have received a replacement CP-1, discontinue use of the CP-1 which was replaced.

It is not necessary to acquire revised ITS approval for price decreases or minor configuration changes.

Lifecycle Cost Authorization on the CP-1 The CP-1 contains a total lifecycle cost and details to show how the lifecycle was derived. The agency/institution is authorized to make payments to the vendor specified on the CP-1 up to this amount.

CP-1 Lifecycle Limit: (1) Base Price: • For ongoing CP-1s authorizing monthly, quarterly, semi-annual, or annual licensing, hosting, maintenance, support, rental, or lease purchase payments, the base price is calculated as follows: base price = number of payments (determined by predicted lifecycle) x payment amount • For purchase or one-time CP-1s, the base price is calculated as follows: base price = the purchase or one-time price • For not-to-exceed CP-1s (for instance, a CP-1 authorizing a maximum number of hours for programming services charged by the hour, payable as incurred in varying amounts and/or at non-cyclic times) the base price is calculated as follows: base price = sum of all payments (if applicable, calculated as hourly rate or average hourly rate x the maximum number of hours of service)

(2) Cost increases allowed per the RFP and/or the contract: For CP-1s (typically only ongoing CP-1s) based upon an RFP and/or contract that allows a periodic percentage increase in hourly rates, annual maintenance, or other ongoing cost, this increase is included in the amount authorized on the CP-1.

Source: 25-53-5 (o)

73

Part 2 Chapter 5: Procurement Process Rule 205.5: 009-070 Procurement Process: Deadlines for Submitting Requests Each year, ITS sends a reminder to our customers of approximate turnaround times required to conduct IT procurements, as well as the corresponding deadlines for submitting projects that must be completed during the current state and federal fiscal years. These timelines are intended to help ensure procurement requests are submitted to ITS in time for completion within the customer's desired time frames and in time to receive approval for any expenditure with a funding deadline or other external time constraints.

This handbook shows an estimate of projected time required for processing each procurement type and dollar amount (Procurement Limits Policies: Section 015-010 and 015-020). Unless you have already had specific discussions with ITS procurement staff regarding a project schedule, the high end of each range should be used as a guideline for when requests should be submitted to ITS to ensure the procurement is completed in time to meet your needs.

In addition, the associated deadlines for State and Federal Fiscal Year acquisitions are listed in the table below. Note that requests for personnel services and maintenance contracts under the purview of ITS that are to be paid from either the old or new fiscal year funds and that begin on or near the beginning of the state or federal fiscal year should also be submitted by the fiscal year deadline. (e.g. maintenance that should be renewed effective July 1)

Continually review your state and federal funding and your information systems needs and submit all procurement requests to ITS according to the deadlines and timeframes shown. Some complex requests, such as those requiring extensive systems analysis or engineering surveys prior to RFP development, take more time than indicated on the schedules below. ITS will work with you to develop a project plan and timetable to address these types of requests. ITS will work with you to have all other requests submitted by the deadline dates completed within the timeframes shown and by the June 30 and September 30 funding deadlines when applicable.

We believe the schedules shown below give you and our staff sufficient time to ensure each project receives adequate attention for the size and complexity of the acquisition. Each June and September, procurement requests are at risk of not meeting the funding deadlines because they were not submitted in time to complete the purchase in compliance with state and federal laws. When the procurement timeline is too compressed, ITS staff cannot complete procurements that (a) meet all legal requirements for competitive proposals; (b) provide a thorough and legally defensible evaluation of vendor proposals; and (c) develop project contracts that adequately protect the customer’s interests. Also, ITS develops staffing plans based on the requests we have received and may not have adequate staff resources available to process requests received after these deadlines.

ITS understands that our customers sometimes don’t have information concerning the availability of funds for technology acquisitions until after these deadlines. ITS is committed to assisting you at any time, to the best of our ability. The options (we are aware of) for helping you to complete your purchases with tighter timeframes and/or those submitted after these deadlines are: (1) you can use your own staff and/or contract staff for more of the preliminary research and preparation

74

of the request and to assist available ITS staff throughout the procurement; or (2) you may request an exemption on a Procurement Request Form and, with ITS’ approval, make the purchase yourself, assuming the responsibility for following all purchasing laws. ITS assistance for projects requiring a tighter timeframe or received after the deadlines may be charged at a higher hourly rate to cover our additional expenses.

If you are unable to have the formal request prepared by the scheduled submission date but are aware of upcoming purchases that have a funding deadline, call Lynn Ainsworth at 601- 432-8150 or Tina Wilkins at 601-432-8161 on or before these deadline dates. We will work to help you meet your objectives in the required time frame.

Category Time Required for Procurement Process: Submission Deadline for June 30 Funds: Submission Deadline for September 30 Funds: Requests requiring Board approval and an RFP 3 - 8 months January 1 April 1 Requests not requiring Board approval but requiring an RFP 2 - 5 months February 1 May 1 Exemption requests requiring ITS Board approval; Requests for sole source certification; Competitive procurements not requiring Board approval and using existing procurement instruments 1 - 3 months April 1 July 1 All other procurement requests 1 month +/- June 1 September 1

75

Notes: (a) The lifecycle cost includes all costs associated with obtaining the item or service and with maintaining and operating it for its projected lifecycle. Examples of costs in each category include: (1) Initial and/or one-time costs: purchase price, freight, installation, and cost to exercise purchase option; (2) Ongoing costs: maintenance, lease, rental, associated personnel costs, and telephone line charges. Lifecycle costs are computed over a three to five year period, unless factors relevant to a specific project dictate a different time period.

(b) Contact ITS to see if there is an existing procurement instrument that can be used for your acquisition. Source: 25-53-5 (o)

76

Part 2 Chapter 5: Procurement Process Rule 205.6: 009-080 Procurement Process: Public Records Requests The diagrams below detail the ITS Public Records Request Process.

Table of Contents: Request for Standard Documents Custom Request without 3rd party notification Custom Request with 3rd party Notification

Public Records Process Flow: You may download a PDF version of the ITS Public Records Process diagrams from the ITS website by clicking the following link: Public Records Process.pdf

77

Request for Standard Documents

78

Custom Request Without 3rd Party Notification

79

Custom Request With 3rd Party Notification

Source: 25-61-1, et seq

80

Part 2 Chapter 5: Procurement Process Rule 205.7: 009-090 Procurement Process: Vendor Protests The ITS Protest Procedure and Policy outlines the process by which any party who is aggrieved in a procurement process may file a formal protest. ITS makes every effort to conduct fair and open procurements and to be proactive in responding to any vendor concerns throughout the process. Vendors are urged to contact the designated ITS project manager for the procurement as soon as an issue or concern is noted. ITS will make every effort to evaluate the concern and to respond appropriately without requiring the vendor to file a formal protest.

Before filing a protest, vendors are strongly encouraged to meet with ITS staff to review ITS process documentation for the relevant procurement. Per the ITS Protest Procedure and Policy, vendors are required to attend a Post Procurement Review before filing a formal protest of any contract award.

Refer to 009-001 ITS Procurement Process Flows for additional information, specifically the flow labeled Protest Process.

Source: 25-53-5 (n)

81

Part 2 Chapter 5: Procurement Process Rule 205.8: 009-100 Procurement Process: Disposals Disposals of Information Technology Equipment

Agencies and institutions should dispose of computer and telecommunications equipment in accordance with guidelines published by the State Auditor’s Office in the Property Officers Manual. Procedures for the disposal of state property are further detailed in the Department of Finance and Administration’s Office of Purchasing, Travel, and Fleet Management Procurement Manual, Chapter 8.

The Department of Environmental Quality also provides Computer Recycling Guidelines on its website, including information on environmental issues related to the disposal of computer equipment.

Agencies and institutions need to consider the following when disposing of or canceling leases for computer and telecommunications equipment:

(1) Cancellation of Insurance and/or Maintenance Coverage

• If you dispose of or transfer equipment covered by insurance, be sure to coordinate cancellation/transfer of insurance as well so that you will not be liable to pay insurance coverage on equipment that has been disposed of or transferred. • If you dispose of or transfer equipment covered by vendor maintenance, be sure to cancel this maintenance so that you will not be liable to pay for maintenance on equipment you no longer have.

(2) Disposal of Equipment with Accruals

If your agency/institution has been renting or leasing equipment that is still of value and has accruals that can be applied toward a purchase, you should attempt to locate another state agency or institution that would like to take advantage of those accruals.

(3) Disposal of Equipment With Value

If your agency/institution is disposing of equipment that is still working or that could be of some value, you should attempt to locate another state agency or institution that would like to have the equipment. The recipient should be aware, however, of any costs associated with operating or maintaining the equipment that might result in more expense to the recipient than newer technology. The recipient should also be aware that these associated costs may require ITS approval.

82

(4) Disposal of Equipment as Salvage

Training centers such as those at state community colleges and high schools can often use broken or old equipment for spare parts or to train students on equipment assembly and repair.

Regardless of the disposal method used, each agency or institution must ensure that all proprietary computer programs and all data have been completely erased from storage devices prior to disposal or transfer of the equipment, using industry best practices to ensure the information cannot be reconstructed. Source: 25-53-5 (c)

83

Part 2 Chapter 6: Procurement Instruments Rule 206.1: 011-010 Procurement Instruments: Requests for Proposals (RFPs) ITS law generally requires that all acquisitions of computer equipment and services involving a lifecycle cost in excess of the dollar amount established in Section 31-7-13(c)be awarded based on competitive and open specifications. Statute also requires that the procurement be advertised in a newspaper having a general circulation in the state (i.e. The Clarion Ledger) at least fourteen calendar days prior to receiving vendor bids and proposals.

ITS uses the Request for Proposals (RFP) as the instrument of choice for obtaining competitive pricing and offerings in compliance with this state statute. The RFP outlines the functional requirements for the equipment, software, and services needed, and vendors respond by proposing solutions and pricing that satisfy these requirements. Proposals and vendors are evaluated in terms of the ability of the solution to satisfy the stated requirements and best meet the needs of the purchasing agency over the expected life of the equipment or system. The evaluation is based on predefined evaluation criteria in which price is not the only factor. Some of the criteria for assessing the proposals received are necessarily subjective. It is the responsibility of ITS and the purchasing entity to ensure the evaluation process is fair and defensible.

Custom RFPs may be developed for the procurement of high-dollar, complex, unique acquisitions by a single agency. The ITS staff and the requesting agency or institution develop an RFP detailing the specific equipment, system, software, and/or service requirements. General RFPs, Special RFPs, and RFPs issued for Express Products Lists (EPLs) are prepared by ITS to meet the needs of multiple customers. See the Multi-Use RFP Index (MURI) for a list of current general, special, and EPL RFPs. While some smaller project may require custom RFPs, ITS makes every effort to use the instruments on the MURI for purchases of products and services within the scope of these instruments, to lower the procurement costs for both customer and vendor.

Solicitations of proposals are published in The Clarion Ledger and on the ITS website. Any vendor may request a printed copy of the RFP (usually with an associated fee) or download the contents from the Internet at no cost in either MS Word or Adobe format. The link is RFPs and Sole Sources Advertised. (Note: This is also a Quick Link on the right hand side of the homepage.)

Some RFPs include a mandatory or optional pre-proposal vendor's conference. The date and location of the conference will be published in the newspaper and Internet ads and will also be printed on the front page of the RFP. For mandatory conferences, only companies who had representatives sign in at the vendor's conference will be allowed to submit proposals as the primary contractor.

Proposals are due at 3:00 p.m. on the specified date and are submitted to the ITS administrative office at 3771 Eastwood Drive, Jackson, Mississippi 39211, per instructions on the cover sheet of the RFP. ITS opens, logs in, and performs a preliminary validation of proposals received. A Register of Proposals is posted on the Internet following the proposal due date.

ITS and the procuring agency jointly evaluate the proposals received, obtain ITS Board approval if required, and negotiate a contract with the awarded vendor.

84

Although most RFPs developed for specific customer agency projects are used for a single purchase, the ITS RFP template contains language allowing the reuse of any award at the discretion of the State and with the concurrence of the vendor.

Refer to 009-001 ITS Procurement Process Flows for additional information, specifically the flow labeled Competitive Procurements: RFPs.

Source: 25-53-3 (g)

85

Part 2 Chapter 6: Procurement Instruments Rule 206.2: 011-030 Procurement Instruments: Express Products Lists (EPLs) Express Products Lists (EPLs) are compilations of proposals competitively solicited by ITS, evaluated, and awarded, usually to multiple vendors, for the purchase of IT commodity products. These lists, when used in accordance with ITS instructions, meet all requirements of Mississippi law for legal competitive procurement of technology products.

EPL categories are added, changed and dropped based upon purchasing demand. Agencies, public universities, community/junior colleges, K-12 schools, and other governing authorities may, but are not required to, use the lists to make information technology purchases in accordance with ITS procedures and guidelines.

Note: When an ITS customer uses an EPL as their procurement authority, that customer is accepting, by their use of the instrument, the requirements as described in the published EPL, the underlying Request for Proposal, and, when applicable, the EPL Purchase Agreement or contract executed by the EPL vendor and ITS on the customer’s behalf.

EPL Distribution

ITS publishes selected Express Products Lists on the ITS website.

ITS will distribute single copies of some EPLs upon request to the individual designated by the agency/institution to receive EPLs (typically the purchasing agent). Distribute additional copies to interested persons in your agency/institution.

Procedures for Using Express Products Lists

Agencies may make purchases from an EPL up to the dollar limit specified in that EPL without advance approval from ITS. For further information regarding dollar limits and use of EPLs, see the following sections of this handbook: (1) Procurement Limits Policies: State Agencies, Section 015-010 (2) Procurement Request Types: Planned Purchase, Section 013-080 (3) ITS Telecommunications Contracts and Services for State Agencies, Section 011-080.

Public universities may make purchases from an EPL up to the dollar limit specified in the EPL without advance approval from ITS. For further information see the following sections of this handbook: (1) Procurement Limits Policies: IHLs, Section 015-020 (2) ITS Telecommunications Contracts and Services for IHLs, Section 011-085.

Governing authorities may make acquisitions from an EPL up to the dollar limit specified in the EPL.

Purchase orders using an EPL must be coded with the EPL Number (RFP Number) and a copy of the applicable EPL pages should be retained with the purchasing documentation to provide an

86

audit trail. Each EPL has its own “Instructions for Use”. Within this document are sections addressing “best practices” and “what goes in your purchase/audit file”.

Items included on ITS EPLs are based upon customer buying demands. ITS does not necessarily endorse or support products appearing on an EPL.

Responsible Use of EPLs EPLs are excellent tools for making routine purchases. They are, however, general purpose in nature and must be used responsibly and in good faith. The larger the dollar amount purchased from an EPL, the more evaluation and documentation is recommended. The following are guidelines for responsible use of an EPL:

• Always consider the alternative of bidding the purchase, especially large purchases, if you reasonably expect that you would get better pricing or contractual terms and conditions that obligate the vendor to meet your specific requirements. Document for the purchasing file the rationale for using the EPL versus bidding the purchase.

• ITS encourages purchasers to aggressively seek the best possible value from an EPL based upon established EPL specifications and proposals. Pricing is one major factor in selecting vendors for the EPL. However, because pricing for information technology hardware generally tends to decrease, ITS strongly encourages purchasers to check with the vendor before placing an order. Vendors are required by the terms of the EPL to pass price decreases to the State. If purchasing multiple items from the list, check with the vendor about quantity pricing. Many vendors price their proposals based upon "quantity of one" purchases and may be able to provide a better price based upon quantity purchases. Purchasers should be aware that it is often appropriate to negotiate with EPL vendors for better pricing, especially when multiple units are being acquired or the EPL is approaching the end of its cycle.

• EPL customers are encouraged to secure these “best possible value” scenarios in writing from all EPL vendors meeting their specifications within a given class. Award the purchase to the lowest and best bidder and maintain all documentation with the purchasing file as an audit trail.

• To maintain the integrity of the EPL process, EPL customers and vendors must adhere to all requirements of the RFP and the Instructions for Use memo issued for each EPL. If you have questions, Contact the ITS Procurement Help Desk at 601-432-8166.

Tips for Making a Successful EPL Purchase

Compatibility can be a major issue in configuring information technology. ITS strongly advises you to contact the vendor to make sure components you purchase from any EPL will be compatible with each other or with your existing equipment.

Technical specifications may not all be represented on the EPL printout. ITS strongly advises that you contact the vendor to verify all critical specifications about the product you intend to purchase.

87

Vendors are required by the terms of their EPL proposals to provide timely delivery of items on the list. There are occasionally circumstances that prevent a vendor from making timely delivery. Report problems with timely delivery to ITS. Vendors who have chronic difficulties delivering will be excluded from future EPLs. However, to mitigate any delivery problems, ITS strongly encourages you to check with the vendor before you place an order, especially near the end of the fiscal year or when you have other critical delivery requirements.

If there is a problem with item availability, the vendor is expected, within reason, to offer you an equivalent or better substitute at or below the original price. It is your responsibility to make sure that the substitution is equivalent to or better than the original offering.

If you have difficulties using or suggestions regarding an EPL let ITS know. Our address is:

Information Technology Services ATTN: EPL 3771 Eastwood Drive Jackson, MS 39211 FAX: (601) 713-6380 You may also contact the ITS Procurement Help Desk at 601 432-8166 or isshelp@its.ms.gov.

Source: 25-53-5 (o)

88

Part 2 Chapter 6: Procurement Instruments Rule 206.3: 011-050 Procurement Instruments: General RFPs and Letters of Configuration ITS uses general RFPs for multiple routine acquisitions by agencies of such items as LAN/UNIX hardware and software, cabling, telephone equipment, mainframe/midrange components, and IT consulting services. To avoid the time and expense involved in soliciting individual proposals for each such acquisition, ITS advertises periodically to receive proposals on these high-volume categories of information technology.

Proposals received in response to a General RFP are used for a specified period of time, usually one year, to establish a pool of vendors that can provide a certain scope of product categories and expertise. There is no sole winning vendor. Product and pricing are not included in a vendor’s response to a General RFP. Therefore, ITS validates the proposal but does not perform an evaluation or selection at the time proposals are submitted.

ITS uses General RFPs in conjunction with Competitive Procurement Requests received from customer agencies and institutions. ITS works with the customer to define the specifications. Once the specifications are defined, an abbreviated solicitation, called a Letter of Configuration (LOC), is sent to the vendor pool, and each vendor has the opportunity to submit a proposal with pricing and other requested information. Selection of the lowest and best alternative submitted in response to the LOC is based upon the requestor’s unique project requirements detailed in the LOC.

General RFPs are for use by the ITS staff on behalf of the procuring agency or institution. General RFPs are NOT for use by agencies, institutions, and governing authorities without ITS involvement.

Refer to 009-001 ITS Procurement Process Flows for additional information, specifically the flow labeled Competitive Procurements: LOCs.

Source: 25-53-3 (g)

89

Part 2 Chapter 6: Procurement Instruments Rule 206.4: 011-060 Procurement Instruments: Special RFPs and Requests for Information (RFIs) ITS issues RFPs on request of a customer or customers to establish a multi-use award for a single agency or group of agencies or institutions. The terms and intended users and uses of special RFPs are spelled out in the specifications within the RFP. Special RFPs are administered by ITS or by the requesting agency. A list of current Special RFPs is contained in the Multi-Use RFP index on the ITS website. ITS issues Requests for Information (RFIs) upon request from customers when the customer believes less formal marketplace research will not provide the information necessary to collect quality information prior to a competitive procurement process. When a customer desires a more formal approach to marketplace research, an RFI process may be used. Customers that desire ITS assistance with the RFI process should submit a Competitive Procurement Request form to ITS. Customers that wish to conduct the RFI process without ITS involvement should submit an Exemption Request form to ITS. An RFI is for information gathering purposes only and cannot be used as a procurement award for the purchase of IT hardware, software or services. Source: 25-53-3 (g)

90

Part 2 Chapter 6: Procurement Instruments Rule 205.6: 011-070 Procurement Instruments: Cooperative Purchasing Agreements ITS statutes generally require that acquisitions of technology hardware, software, and services involving the expenditure of funds in excess of the dollar amount established in Section 31-7-13(c) be based upon competitive and open specifications. This statute further requires that contracts for these acquisitions be entered into only after advertisements of proposal solicitations are published in one or more daily newspapers having a general circulation in the State not less than fourteen days prior to receiving proposals. This section of the Mississippi Code, with its requirement for advertisement in a local newspaper, has limited the ability of Mississippi agencies to use cooperative purchasing agreements established by other local, state, and federal entities for technology purchases.

Mississippi public purchasing code and subsequent interpretation statute by the Mississippi Attorney General have provided two avenues for the utilization of cooperative purchasing agreements for the acquisition of information technology products and services: (1) Certified Purchasing Offices: Senate Bill 2344, 2003 Regular Legislative Session, added Section 31-7-13 (m) (xxix) to Mississippi Code, exempting from bid requirements purchases made by certified purchasing offices of state agencies pursuant to qualifying cooperative purchasing agreements. Attorney General Opinion No. 2004-0572 affirmed that ITS has the authority to establish rules and procedures for the utilization of cooperative purchasing agreements by certified purchasing offices for information technology purchases. See Certified Purchasing Office Guidelines on the DFA website for the requirements for certification and for a list of certified purchasing offices in the state. (2) Cooperative Purchasing Agreements approved by DFA: Mississippi Code Section 31-7-7 (b), charges the Department of Finance and Administration (DFA) with arranging purchasing agreements for the acquisition of commodities by Mississippi public entities. Once these agreements are established, purchases may be made through the provisions of Mississippi Code Section 31-7-13 (m) (i), which provides an exemption from bid requirements for acquisitions made from such agreements. Attorney General Opinion No. 2006-0159 states that DFA may adopt as its own approved purchase agreements the cooperative agreements that have been developed by other states and local governments. Attorney General Opinion No. 2006-0457 provides that ITS has the authority to adopt procedures for submitting purchasing agreements to DFA for approval to be utilized by ITS on behalf of agencies and institutions of the state.

To initiate a technology purchase from any cooperative purchasing agreement utilizing either of the two approaches outlined above, submit a procurement request to ITS.

Procedure for making technology acquisitions from cooperative purchasing agreements: • Submit a Competitive Procurement Request form, including the Cooperative Purchasing Agreement Supplement to the request form. • Indicate whether your agency or institution is a Certified Purchasing Office. • ITS will evaluate the request, including the agency's justification that use of the cooperative agreement is "in the best interest of the government entity" (a statutory requirement in

91

Mississippi Code Section 31-7-13 (m) (xxix)). Considerations will include an evaluation of comparable market pricing; comparisons with any existing ITS purchase instruments that cover the same products; the uniqueness of the product or service in the marketplace; contract terms and conditions; and cost and time requirements for acquiring the product or services in another manner. • If the requesting agency or institution is not a Certified Purchasing Office and the cooperative agreement has not been previously approved by DFA, ITS will submit the cooperative purchasing agreement to DFA for approval as a DFA purchase agreement. • If this is the first time this cooperative agreement has been used for a technology procurement through ITS, ITS will research the requirements for use, including any necessary organizational memberships or other prerequisites. The requestor should provide any known information concerning these requirements on the Cooperative Purchasing Agreement Supplement form submitted to ITS. • ITS will issue a CP-1 with special "cooperative purchasing" language included. (NOTE: ITS approvals for using a cooperative purchasing agreement are project-specific and on a project- by-project basis.) • ITS will work with the customer on any contract supplement required. • ITS will work with the vendor to register in MAGIC, if the vendor is not in MAGIC, and to provide the vendor with information on the State's requirement for receiving payment through PayMode. Source: 31-7-13 (m); 31-7-7 (b)

92

Part 2 Chapter 6: Procurement Instruments Rule 206.6: 011-080 ITS Telecommunications Contracts and Services for State Agencies Per state statute, all telecommunications systems and services affecting the management and operations of the State must be acquired through ITS. The following table lists the major voice and data telecommunications services provided to state agencies through ITS and/or through ITS contracts.

Note that the standard procurement delegations do not apply to telecommunications services and systems. See Acquisition of Telecommunications Services by State Agencies for details.

Senate Bill 2514, 2005 Regular Session [codified as Mississippi Code § 25-53-171], established the Mississippi Wireless Communication Commission and tasked the Commission with the responsibility for approving all wireless communication purchases within State Government and for setting forth rules and regulations governing these purchases. See Purchasing Rules, Guidelines, and Procedures on the WCC website for additional information regarding wireless communication purchases.

For price or other information for Service Areas 1-5 or 7, contact TelecomRequest@its.ms.gov. See ITS EPLs for products and pricing in Service Area 6. For any telecommunications services or systems not listed, contact TelecomRequest@its.ms.gov.

93

Product/Service Area: Includes: ITS Approval Process: (1) Local Area Access: Line charges for traditional voice communication services (any voice communication line other than radio circuits) Business Lines ("dial tone") Trunking (DID, ISDN-PRI, OGO, or any combination) Centrex Lines Basic telephone installation: Greater Jackson Area only Basic data cable Installation: Greater Jackson Area only Voice Mail services No delegation. ITS has conducted these procurements on behalf of the State and has contracts in place for these services. Contact ITS directly as outlined above for additional details and to arrange for these services. (2) Long Distance Toll Services Intra-LATA calls Inter-LATA calls Interstate calls International calls Toll-free service (i.e. "800" type service) Calling cards No delegation. ITS has conducted these procurements on behalf of the State and has contracts in place for these services. Contact ITS directly as outlined above for additional details and to arrange for these services. (3) Audio and Web Conferencing Operator Assisted Reservationless Document Sharing Streaming video No delegation. ITS has conducted these procurements on behalf of the State and has contracts in place for these services. Contact ITS directly as outlined above for additional details and to arrange for these services. (4) Data Communication Services Inter-LATA circuits Intra-LATA circuits MPLS circuits State backbone Internet access DSL No delegation. ITS has conducted these procurements on behalf of the State and has contracts in place for these services. Contact ITS directly as outlined above for additional details and to arrange for these services. (5) Data Communication Equipment Routers providing connection to the statewide backbone network Submit Procurement Request to ITS for any router that is a direct connection to the statewide backbone. NOTE: If not a State backbone network border device, purchase using standard delegation limits and procurement procedures.

94

Product/Service Area: Includes: ITS Approval Process: (6) Telecommunication Express Products Lists

Two-way radios Delegation to purchase outside EPL up to but not over the dollar amount established in Section 31-7-13(c) . You must select the lowest quotation. Submit standard procurement request or use EPL above the dollar amount established in Section 31-7- 13(c); Requires WCC approval above $100,000 per project or per fiscal year; May use MSWIN Contract as EPL for equipment on Mobile, Portable, and Dispatch Console Equipment List; Submit standard procurement request above EPL fiscal year spending limit ($200,000). Cellular and other wireless devices and services Agencies and IHLs must purchase cellular devices and services from the Master Cellular Agreement; No dollar limit to purchases from Master Cellular Agreement by any government entity; All exceptions to Master Cellular Agreement by agencies and IHLs require ITS approval; Competitive procurement required for any exception with a cost that exceeds the amount established in Section 31-7-13(c) Pager equipment and services Delegation to purchase up to but not over the dollar amount established in Section 31-7-13(c) without ITS involvement if obtaining 2 written quotations; You must select the lowest quotation. Submit standard procurement request above the dollar amount established in Section 31-7-13(c) or for sole-source acquisitions above $5,000.

95

Product/Service Area: Includes: ITS Approval Process: E-911equipment and services Delegation to purchase outside EPL up to but not over the dollar amount established in Section 31-7-13(c). Submit standard procurement request or use EPL above the dollar amount established in Section 31-7- 13(c); You must select the lowest quotation. Submit standard procurement request above EPL spending limit. Wireless communication purchases from E-911 EPL require WCC approval above $100,000. (7) Telephone Equipment, Systems, and Maintenance Telephone sets (single and multi-line) Delegation to purchase using standard delegation limits and procurement procedures. Key Systems Delegation to purchase using standard delegation limits and procurement procedures. PBXs Delegation to purchase using standard delegation limits and procurement procedures. Hybrid Systems Delegation to purchase using standard delegation limits and procurement procedures. Phone system maintenance Delegation to purchase using standard delegation limits and procurement procedures. Pay Phones Delegation to purchase using standard delegation limits and procurement procedures.

Source: 25-53-101 through 125; 25-53-171

96

Part 2 Chapter 6: Procurement Instruments Rule 206.7: 011-085 ITS Telecommunications Contracts and Services for Institutions of Higher Learning (IHLs) Per state statute, all telecommunications systems and services affecting the management and operations of the state must be acquired through ITS. The following table lists the major voice and data telecommunications services that can be provided to state institutions of higher learning through ITS and/or through ITS contracts.

Note that, for the acquisition of telecommunications services and systems, the normal delegation of procurement authority by ITS to the institution of higher learning does not apply. See Acquisition of telecommunications Services by IHLs for details.

For certain telecommunication products and services, ITS has compiled and published Express Products Lists (EPLs) that can be used by IHLs in these acquisitions.

Senate Bill 2514, 2005 Regular Session [codified as Mississippi Code § 25-53-171], established the Mississippi Wireless Communication Commission and tasked the Commission with the responsibility for approving all wireless communication purchases within the state and for setting forth rules and regulations governing these purchases. See Purchasing Rules, Guidelines, and Procedures on the WCC website for additional information regarding wireless communication purchases.

For price or other information for Service Areas 1-5 or 7, contact TelecomRequest@its.ms.gov. See ITS EPLs for products and pricing in Service Area 6. For any telecommunications services or systems not listed, contact TelecomRequest@its.ms.gov.

97

Service Area: Includes: ITS Approval Process: (1) Local Area Access: Line charges for traditional voice communication services (any voice communication line other than radio circuits) Business Lines ("dial tone") Trunking (DID, ISDN-PRI, OGO, or any combination) Centrex Lines No delegation. ITS has conducted these procurements on behalf of the State and has contracts in place for these services. Contact ITS directly as outlined above for additional details and to arrange for these services. (2) Long Distance Toll Services Intra-LATA calls Inter-LATA calls Interstate calls International calls Toll-free service (i.e. "800" type service) Calling cards No delegation. ITS has conducted these procurements on behalf of the State and has contracts in place for these services. Contact ITS directly as outlined above for additional details and to arrange for these services. (3) Audio and Web Conferencing Operator Assisted Reservationless Document Sharing Streaming video

No delegation. ITS has conducted these procurements on behalf of the State and has contracts in place for these services. Contact ITS directly as outlined above for additional details and to arrange for these services. (4) Data Communication Services Inter-LATA circuits Intra-LATA circuits MPLS Circuits State backbone Internet access DSL No delegation. ITS has conducted these procurements on behalf of the State and has contracts in place for these services. Contact ITS directly as outlined above for additional details and to arrange for these services.

98

Service Area: Includes: ITS Approval Process: (5) Data Communication Equipment Routers providing connection to the statewide backbone network For any router that is a direct connection to the statewide backbone: (a) Delegation to purchase, following applicable procurement laws, up to $250,000 without ITS involvement. MUST name Cisco as manufacturer. OR (b) Submit procurement request to ITS. NOTE: If not a border device, purchase using standard delegation limits and procurement procedures. (6) Telecommunications Express Products Lists Two-way radios Delegation to purchase outside EPL following applicable procurement laws up to $250,000 without ITS involvement. Submit standard procurement request above $250,000; Requires WCC approval above $100,000 per project or per fiscal year; May use MSWIN Contract as EPL for equipment on Mobile, Portable, and Dispatch Console Equipment List; Submit procurement request to buy from EPL above EPL spending limit ($200,000).

99

Service Area: Includes: ITS Approval Process: Cellular equipment and services

Agencies and IHLs must purchase cellular devices and services from the Master Cellular Agreement; No dollar limit to purchases from Master Cellular Agreement by any government entity; All exceptions to Master Cellular Agreement by agencies and IHLs require ITS approval; Competitive procurement required for any exception with a cost that exceeds the amount established in Section 31-7- 13(c); Pager equipment and services

Delegation to purchase following applicable procurement laws, up to $250,000 without ITS involvement E-911 Delegation to purchase outside EPL, following applicable procurement laws, up to $250,000 without ITS involvement (7) Telephone Equipment and Systems Telephone sets (single and multi-line) Delegation to purchase using standard delegation limits and procurement procedures Key Systems Delegation to purchase using standard delegation limits and procurement procedures PBXs Delegation to purchase using standard delegation limits and procurement procedures Hybrid Systems Delegation to purchase using standard delegation limits and procurement procedures Phone system maintenance Delegation to purchase using standard delegation limits and procurement procedures Pay Phones Delegation to purchase using standard delegation limits and procurement procedures

100

Service Area: Includes: ITS Approval Process: Voice Mail services Delegation to purchase using standard delegation limits and procurement procedures

Source: 25-53-101 through 125; 25-53-171

101

Part 2 Chapter 7: Procurement Types Rule 207.1: 013-020 Procurement Types: Revision Request for Revised or Extended Approval

Agencies and institutions should complete and send a completed Request for Revision to Previous Approval and appropriate attachments as listed on the form to ITS to request changes to a previously issued CP-1. A copy of the revision request form is available in PDF and Word formats on the ITS website. Customers may also submit revision requests via ITS' online procurement request system.

ITS approves a revision or extension by issuing a new CP-1. The new CP-1 will have the same Contract Number as the original CP-1 and any other revision CP-1s previously issued for the same project. For state agencies, the new CP-1 updates the information in MAGIC for that contract record. Customers should continue to reference the same contract number when making payments related to the project.

When to Request Revised ITS Approval

It is necessary to request revised ITS approval and obtain a replacement CP-1 in the following instances:

• Expired Purchase CP-1 that you still need to use. Attach a letter from the vendor stating that equipment can still be delivered at (or below) the pricing on the CP-1. Try to issue purchase orders promptly upon receipt of a CP-1 to avoid the problem of expired CP-1s. Vendors submit pricing that they will honor for only a limited amount of time. Also, equipment may not be available after long periods of time. If the vendor can no longer deliver the equipment at or below the price approved on the original CP-1, it may be appropriate to handle your revision request as a new procurement.

• Expired Ongoing CP-1 for hardware or software maintenance, software licensing fees, etc. The CP-1 from which you make ongoing payments has expired but you still need the coverage. In this instance, ITS will confer with the agency or institution and reference the terms of the original proposal solicitation and contract to assess whether it is appropriate to extend the current contract with the existing vendor or to initiate a new procurement.

• Vendor Change. Whether for a purchase CP-1 or for an ongoing CP-1, you need to acquire revised ITS approval to change vendors. A change of vendors will typically require that ITS handle the request as a new procurement unless it is a name or address change only.

• Price Increase. It is necessary to seek revised ITS approval for price increases over the lifecycle amount authorized on the CP-1. See Terms: Lifecycle Cost and Procurement Process: CP-1 Approval Documents and MAGIC for an explanation of the lifecycle amount authorized on the CP-1.

• Major Configuration Change. It is necessary to acquire revised ITS approval for major configuration changes.

102

It is not necessary to acquire revised ITS approval for price decreases or minor configuration changes.

Minor Configuration Changes

On Purchase CP-1s and CP-1s for a maximum amount, ITS itemizes the configuration, typically submitted in a proposal by the vendor and requested by the agency or institution. It is not necessary to request that ITS issue a replacement CP-1 to reflect minor changes made to the configuration. Minor configuration changes must generally meet the following criteria:

• Does not exceed the total lifecycle cost specified on the CP-1, • In line with the proposal solicitation, the vendor’s proposal and the resulting contract, • More or better capability at or below the original price, • In the best interest of the state, and • Acceptable to the agency.

An example of such a minor configuration change would be an offer by a vendor to substitute newly available microcomputers of the same brand with a faster processing speed and/or with a larger hard drive than those proposed within the lifecycle cost authorized by the CP-1.

On CP-1s of an ongoing nature, typically those for maintenance, it is not necessary to request a replacement CP-1 to reflect minor additions/deletions within the lifecycle amount authorized by the CP-1.

An example of such a minor configuration change would be an agency’s addition of several new PCs which have recently rolled off of warranty along with the deletion of several old printers which have been disposed of by the agency.

The agency should document and keep in its file for audit trail purposes the reason for all such minor configuration changes and document that the changes are in line and are in the best interest of the state. The agency will need to furnish this documentation to ITS if a replacement CP-1 should later become necessary.

Major Configuration Changes

Major configuration changes do require ITS approval.

An example of a major configuration change on a purchase would be one where the agency has decided to considerably change workstation and server configurations.

An example of a major configuration change on a maintenance CP-1 would be the need to add 25 microcomputers that have recently rolled off warranty to an existing contract with a maintenance vendor.

103

A New Procurement is Required

It is appropriate for ITS to revise or extend approval and to issue a replacement CP-1 only where the revision or extension is within the scope of the original procurement. There may be situations where you request a replacement CP-1 but the situation merits a new procurement. ITS will work with you to solicit the additional information needed if it is determined that your request should be processed as a competitive procurement.

Refer to 009-001 ITS Procurement Process Flows for additional information, specifically the flow labeled Revisions to Previous Approvals.

Source: 25-53-5 (o)

104

Part 2 Chapter 7: Procurement Types Rule 207.2: 013-030 Procurement Types: Sole Source ITS enabling legislation requires that information technology equipment and services be acquired in a manner that insures the maximum of competition among all manufacturers and suppliers of such equipment and services. Accordingly, ITS promotes full and open competition through the issuance of open specifications, unless valid justification is presented and approved by ITS, and the objective evaluation of vendor proposals to determine the lowest and best offering to meet an agency's or public university’s business requirements. True competition protects the integrity and credibility of purchasing in the public sector and is essential in providing best value and adequate contractual protection for the purchasing entity.

Mississippi Public Purchasing Law (Section 31-7-13) specifies that noncompetitive items available only from one source may be exempted from bid requirements (sole-sourced). ITS statute, in Section 25-53-5 (p), permits ITS to utilize provisions in Public Purchasing law or regulations, when applicable. In certain limited situations, with appropriate written documentation and proper approval, information technology acquisitions may be sole-sourced.

A Sole Source Certification Request is an agency's or public university’s statement, with accompanying documentation, that there is no competition in the marketplace for the requested product or service. Single source acquisitions awarded without competition are exceptions that can only be certified after thorough marketplace research. ITS applies a strict interpretation of the single source definition and is a strong advocate for conducting a competitive process unless the reasons for not competing are overwhelming and incontrovertible.

ITS Sole Source Procedure The ITS Sole Source procedure is designed to allow agencies and public universities to submit requests to ITS instead of to DFA when approval of sole source information technology acquisitions is required per Section 31-7-13 of the Mississippi Code. The ITS Sole Source Procurement Request Form, in conjunction with the Sole Source Certification signed by the agency head or public university CIO, has been designed to collect the necessary justification and certification for an information technology sole source acquisition. A Sole Source Certification Request Form should be completed for all information technology sole source acquisition requests other than those delegated to the agency or institution (See Section 015-010: State Agencies, and Section 015-020: IHLs for specific dollar limits for the delegation of Sole Source approval to Agencies and Institutions of Higher Learning, as applicable).

Submit the Sole Source Certification Request to ITS rather than to DFA. It is not necessary to submit duplicate paperwork to the DFA Office of Purchasing, Travel, and Fleet Management (OPTFM) for approval of sole source acquisitions. A copy of the Sole Source Certification Request Form is available in PDF or Word format on the ITS website. Customers may also submit sole source requests via ITS' online procurement request system. All sole source certifications must be signed by the Executive Director of the agency or the CIO of the public university, or that person’s designee. Designees must be identified by the agency or public university through formal written correspondence to the ITS Executive Director.

105

ITS thoroughly reviews Sole Source Certification Requests, determining if competing products and/or services exist. If so, ITS will conduct a competitive procurement. If ITS’ review confirms the sole source, then a Sole Source advertisement will be issued, giving interested parties, like other vendors, an opportunity to identify competing products and/or services. Based upon the results of the Sole Source advertisement, ITS will either certify the request as a sole source or conduct a competitive procurement.

A CP-1 Acquisition Approval Document issued by ITS for the amount of the sole source acquisition. Agencies that issue purchase orders through DFA should note that this CP-1 is uploaded by ITS into MAGIC to authorize payment of the sole source purchase.

Sole Source Criteria and Required Documentation Sole source acquisitions must meet certain criteria. Per Public Purchasing Law, the following criteria must be met for a procurement to be authorized as sole source:

  1. The product or services being purchased must perform a function for which no other product or source of services exists,
  2. The purchaser must be able to show specific business objectives that can be met only through the unique product or services, AND
  3. The product or services must be available only from the manufacturer and NOT through resellers who could submit competitive pricing for the product or services.

The purchasing agency or public university is responsible for documenting its business needs in the sole source request, as well as the ways in which the requested product or services meets those needs. In addition, the purchaser should document why other products or services cannot substantially meet the documented needs. If similar products or services exist in the marketplace, the business case for the unique functionality or characteristics of the sole-sourced item must be compelling for the procurement to be sole-sourced under state statute.

The purchasing agency/public university should obtain and submit to ITS a written proposal from the sole source provider. This proposal should clearly document the exact product and services to be provided, timeframes for delivery or service provision, and all associated pricing information, including retail price, discount structure, volume-related tiered pricing structures, ongoing support costs, and price escalation caps. If the purchasing agency/public university prefers, the ITS staff assigned to the sole source request can work with the vendor to obtain this information.

In addition to the above documentation from the purchaser, certification from the manufacturer should accompany the Sole Source Certification Request. This documentation supplements the sole source justification but does not replace the purchaser’s documentation of business need. The manufacturer must certify, on company letterhead, the unique features of the product or service within the marketplace and must also certify that the product or service is available only through the manufacturer or from a single specified distributor or reseller.

Additionally, acquisitions of IT services must include the following information to be authorized as sole source:

106

  1. An explanation about why the amount to be expended is reasonable, and
  2. An explanation regarding the efforts by the purchaser to obtain the best possible price.

Per Mississippi Code Annotated Section 27-104-7(2)(o), purchasers requesting sole source approval of services must provide an explanation of why the amount to be expended for the service is reasonable, and an explanation of the efforts to obtain the best possible price for the service. Section 27-104-7 directs the efforts of the Personal Services Contract Review Board and by policy and procedure, ITS follows similar documentation requirements.

The following factors do NOT constitute valid criteria for sole source designations: • Quality of the product or services: The competitive process has been established to determine the lowest and best offering. • Price of the product or services: The competitive process has been established to determine the lowest and best offering. • Product that performs in a unique way but does not provide unique functionality: A unique algorithm or patented search process is not a sole source unless there is significant functionality that is only available through the requested product. • Project timetable or other scheduling constraints: The emergency purchase statute was established for situations meeting the statutory definition of "emergency". See 013-060 Emergency Purchases. • Incumbent products or service providers: An award from a competitive process for the acquisition of products or services does not constitute a permanent purchasing mechanism. All products and services are re-evaluated from time to time to determine when a full competition and potential replacement are warranted. For service providers, this competition may include a reasonable learning curve for time required by non-incumbents to become acclimated to the particular customer, product, and/or environment. • Sole source designation by other states: Mississippi's sole source requirements are more stringent than those in many other states.

Remember: The law says single source, not best source. Competition is used to determine best source.

Benefits of Soliciting Proposals It is always acceptable, and usually preferable, to solicit bids or proposals for an acquisition even if the product or services requested are believed to be unique in the marketplace. The benefits of soliciting proposals for a sole source item include: • The purchaser develops a written statement of requirements against which to evaluate the sole source offering • The vendor submits a written statement of commitments and pricing for both initial and ongoing costs, against which the purchaser can evaluate vendor and product performance and which can be incorporated into a negotiated contract • The solicitation of written proposals increases the potential of reduced price offerings and/or written guarantees against excessive price escalation for a set contract period

Agency/Public University Responsibility

107

The purchasing agency/public university is responsible for providing all necessary documentation and justification required to support a sole source acquisition, as described above. If adequate documentation is not provided with the request, ITS staff will work with the requestor’s staff to obtain sufficient information to certify the sole source. Note that ITS must charge an hourly rate for the time required to obtain this additional documentation.

The purchasing agency/public university is responsible for making the sole source procurement within the amount and from the vendor specified on the CP-1 Acquisition Approval Document.

Delegation of Sole Source Certification State Agencies: For state agencies, approval of all technology purchases with a lifecycle cost of $5,000 or less, including sole source purchases, has been delegated to the agency. The ITS Procurement Limits Policies for Agencies require a minimum of two competitive written bids or proposals for technology purchases with a lifecycle cost over $5,000 but not over the dollar amount established in Section 31-7-13(c). Since, for single source items, the procuring agency will be unable to obtain two written bids, ITS must approve all sole source acquisitions of information technology with a lifecycle cost greater than $5,000.

IHLs: Institutions of Higher Learning (IHLs) or public universities have been delegated the authority to certify sole source procurements up to $250,000 lifecycle cost under the ITS Procurement Limits Policies for IHLs using the sole source procedures outlined in this Handbook. For the certification of sole source procurements delegated to the CIOs at public universities, the public university must follow ITS’ Sole Source Procedure, including advertisement of the intent to award as sole source, as outlined in this chapter. Institutions certifying a sole source purchase must ensure the criteria listed above are met and documented in writing by the institution and the vendor prior to certifying a product or service as sole source. Sole source documentation must be reviewed and approved by the IHL's CIO for any sole-source certification above $5,000. The ITS sole source procedure requires that sole sources be advertised in a newspaper of statewide circulation for 2 consecutive weeks prior to award. Additionally, Registers of Objectors and Notifications of Award must be posted, and a post-purchase comparison of the award to the purchase documents must be conducted by the IHL CIO. All sole source documentation should be retained in the public university’s procurement file. Sole source requests above $250,000 lifecycle cost require ITS approval. For purposes of periodic recertification of sole sources, the delegated limit of $250,000 is for each certification period, as opposed to a cumulative total.

Other than the delegations outlined above, all sole source technology procurements must be certified by ITS. ITS cannot exempt a sole source request--the ITS Exemption Request and ITS Sole Source Request are mutually exclusive.

Refer to 009-001 ITS Procurement Process Flows for additional information, specifically the flow labeled Sole Source Certifications.

Source: 25-53-5 (p); 31-7-13; 24-104-7

108

Part 2 Chapter 7: Procurement Types Rule 207.3: 013-040 Procurement Types: Exemption The Exemption procedure allows agencies and institutions to request exemption from ITS to handle specific information technology procurement projects that, by law, require solicitation of bids or proposals, without the involvement of ITS. The exemption procedure is designed for projects involving traditional information technology equipment, software, or services which the agency/institution has the in-house resources and expertise to procure without ITS involvement. The exemption should be approved by ITS before an advertisement is issued for the procurement. A request for exemption should be submitted on an Exemption Request form. A copy of the exemption request form is available in PDF and Word formats on the ITS website. Customers may also submit exemption requests via ITS' online procurement request system.

All exemption requests must be signed by the Executive Director of the agency or the CIO of the institution of higher learning, or that person’s designee. The name and title of the agency head, institution CIO, or designee should be entered on the line to the bottom left of the request form and the form should be signed and dated on the bottom right.

ITS staff reviews the information submitted on the exemption request form concerning the acquisition, including the procurement approach that will be used and the estimated total lifecycle cost. The exemption request will be approved by the ITS Executive Director, or will be presented to the ITS Board for approval if the total lifecycle cost exceeds the Director Approval threshold.

A CP-1 Acquisition Approval Document is issued for the amount of the exemption, based on the agency's estimate of the total lifecycle cost. Agencies that issue purchase orders through DFA should be aware that this CP-1 is uploaded by ITS into MAGIC to authorize processing payment for an exempted procurement. This approval is not vendor specific, as it is issued prior to the procurement process. When exempting a procurement, ITS will specify the maximum amount exempted on the CP-1 Acquisition Approval Document. The agency/institution must submit a request for approval of the additional dollar amount if the procurement results in a cost greater than the estimated total used in the original exemption.

When approval is received, the agency/institution may proceed with the procurement without further involvement from ITS, as outlined under "Agency/Public University Responsibilities" below.

An exemption cannot be used in conjunction with a sole source acquisition. Sole source acquisitions should be submitted to ITS on a Sole Source Certification Request form.

The requirement of soliciting bids or proposals for services that can be competitively provided is NOT waived by an ITS exemption. All applicable statutes for competitive procurements must still be followed by the purchasing entity.

An exemption should also be requested if an agency desires to issue a Request for Information (RFI) without ITS involvement. Note that an RFI is for information gathering purposes only and cannot be used as a procurement award for the purchase of IT hardware, software or services.

109

110

Agency/Public University Responsibilities

For exempted acquisitions, the purchasing agency/institution is responsible for making the purchase within the dollar amount authorized by ITS on the CP-1 Acquisition Approval Document and for following all applicable statutory requirements throughout the procurement process, including but not limited to those outlined in Title 25, Chapter 53 of Mississippi Code. These requirements include: (1) development of competitive and open specifications; (2) issuing an advertisement to solicit bids or proposals according to Section 25-53-5 (o) of the Mississippi Code; (3) conducting a thorough and equitable evaluation of all proposals received; (4) responding in a timely manner to all public records and post-procurement review requests; and (5) negotiating and signing a contract, if applicable, within the scope and intent of the specifications. ITS does not participate in any of these steps for exempted procurements.

In the negotiation of contracts for the products and services being obtained, agencies and public universities should be aware that, per a 1993 Attorney General Opinion, state agencies do not have the authority to allow a vendor to limit its liability. Pursuant to Section 25-53-21(e) of the 1972 Mississippi Code Annotated, as amended, the Executive Director of ITS may negotiate a limitation on the liability to the State of prospective contractors provided such limitation affords the State reasonable protection. This authority to negotiate a limitation of liability applies ONLY to contracts negotiated by ITS for execution by the ITS Executive Director and does not apply to contracts negotiated for exempted procurements.

If a vendor protest results from the exempted procurement, however, the rules and guidelines of the ITS Protest Procedure and Policy apply, with the ITS Executive Director receiving and responding to the protest.

Refer to 009-001 ITS Procurement Process Flows for additional information, specifically the flow labeled Exemption Approvals.

Source: 25-53-25 (2)

111

Part 2 Chapter 7: Procurement Types Rule 207.4: 013-050 Acquisition of Telecommunications Services by State Agencies ITS statute, Mississippi Code Section 25-53-111, requires that ITS: • Establish and coordinate through either state ownership or commercial leasing, all telecommunications systems and services affecting the management and operations of the state • Act as the sole centralized customer for the acquisition, billing and record keeping of all telecommunications systems or services provided to state agencies whether obtained through lease or purchase • Charge the respective user agencies for their proportional cost of the installation, maintenance and operation of the telecommunications systems and services

To fulfill this statutory mandate, ITS issues Requests for Proposals to obtain the lowest and best provider of local and long distance voice access services and of data communications services. The resulting contracts are for the use of ITS in furnishing these services to all state agencies. The contracts aggregate all telecommunications traffic into one account with ITS as the sole customer on behalf of the state, as required in the above statute. This aggregation allows ITS to get the best possible pricing for the state as a whole; to better manage telecommunications facilities within the state; and to have an accurate inventory of all telecommunications services within state government.

There is no delegation of procurement authority for telecommunications services for state agencies. All such services must be obtained through the Telecom Services and Data Services Divisions of ITS. See ITS Telecommunications Contracts and Services for State Agencies for a list of products and services within the scope of this policy and for links to the associated pricing.

In addition to the line and access services provided via vendor contracts, ITS is the direct provider of basic telephone installation services and basic data cable installation services for customers in the Capitol Complex and greater Jackson area. Note that neither agency staff nor third-party vendors are to provide any cabling or telephone installation or update services unless prior written approval has been obtained from ITS on a case-by-case basis.

As an ITS telecommunications customer, a state agency receives the following "value-add" services: • Contractual terms and conditions negotiated and enforced by ITS on behalf of the state • Renegotiation for lower pricing at set intervals throughout the life of each contract • Uniform service and cost to all areas of the state • Facility reviews on request to evaluate opportunities for cost savings (voice and data) • Statewide authorization codes for long distance • Customized telephone billing to accommodate the accounting requirements of the individual agency, including electronic billing options • State government telephone operator services • Trouble/Help Desk support (voice and data) • Customer service support (voice and data) • Telecommunications training on request • Voice communications needs analysis on request

112

• On-line state telephone directory listings and service • Network Operations Center • Core security administration (IDS and VPN) • Domain name services • System design and configuration (voice and data) • 24x7x365 operations (voice and data) • Problem determination (voice and data) • Disaster recovery (voice and data) • Capacity planning • Telecommunications Express Products Lists (2-way radios, E-911) • Master Cellular Contract

To request additional information or to order services, contact TelecomRequest@its.ms.gov. Source: 25-53-111

113

Part 2 Chapter 7: Procurement Types Rule 207.5: 013-055 Acquisition of Telecommunications Services by IHLs ITS statute, Mississippi Code Section 25-53-111, requires that ITS: • Establish and coordinate through either state ownership or commercial leasing, all telecommunications systems and services affecting the management and operations of the state • Act as the sole centralized customer for the acquisition, billing and record keeping of all telecommunications systems or services provided to state institutions whether obtained through lease or purchase • Charge the respective user institutions for their proportional cost of the installation, maintenance and operation of the telecommunications systems and services • Approve or provide state telephone services on a reimbursable basis to full-time students at state institutions of higher learning, including where such services are provided by the state or the institution

To fulfill this statutory mandate, ITS issues Requests for Proposals to obtain the lowest and best provider of local and long distance voice access services and of data communications services. The resulting contracts are for the use of ITS in furnishing these services to all state agencies and institutions of higher learning. The contracts aggregate all telecommunications traffic into one account with ITS as the sole customer on behalf of the state, as required in the above statute. This aggregation allows ITS to get the best possible pricing for the state as a whole; to better manage telecommunications facilities within the state; and to have an accurate inventory of all telecommunications services within state government. See ITS Telecommunications Contracts and Services for IHLs for a list of products and services within the scope of this policy.

As an ITS telecommunications customer, an IHL receives the following "value-add" services: • Contractual terms and conditions negotiated and enforced by ITS on behalf of the state • Renegotiation for lower pricing at set intervals throughout the life of each contract • Uniform service and cost to all areas of the state • Statewide authorization codes for long distance • Capacity planning • Telecommunications Express Products Lists (2-way radios, E-911) • Master Cellular Contract

To request additional information or to order services, contact TelecomRequest@its.ms.gov. Source: 25-53-111

114

Part 2 Chapter 7: Procurement Types Rule 207.6: 013-060 Procurement Types: Emergency Purchases ITS utilizes the provisions of the Mississippi Public Purchasing Law and DFA/OPTFM purchasing guidelines in conjunction with ITS procedures for emergency purchases of information technology. Section 31-7-13(j) of the Mississippi Code, outlines the emergency purchase procedures, and Section 31-7-1(f) defines “emergency” as follows:

(f) "Emergency" shall mean any circumstances caused by fire, flood, explosion, storm, earthquake, epidemic, riot, insurrection or caused by any inherent defect due to defective construction, or when the immediate preservation of order or of public health is necessary by reason of unforeseen emergency, or when the immediate restoration of a condition of usefulness of any public building, equipment, road or bridge appears advisable, or in the case of a public utility when there is a failure of any machine or other thing used and useful in the generation, production or distribution of electricity, water or natural gas, or in the transportation or treatment of sewage; or when the delay incident to obtaining competitive bids could cause adverse impact upon the governing authorities or agency, its employees or its citizens; or in the case of a public airport, when the delay incident to publishing an advertisement for competitive bids would endanger public safety in a specific (not general) manner, result in or perpetuate a specific breach of airport security, or prevent the airport from providing specific air transportation services.

Note that the definition applies only to events that could not reasonably have been anticipated.

The need to purchase technology products or services under the emergency purchase procedures and determination as to whether an emergency exists is a decision made by the governing board or the executive head/president, or his designees, of any agency or public university.

Consistent with Section 31-7-13(j), the governing board or the executive head/president, or his designees, of any agency/public university of the State must first determine if an emergency exists in regard to the purchase of technology products or services so that the delay incident to giving opportunity for competitive bidding would either (1) threaten the health or safety of any person or the preservation or protection of property or (2) be detrimental to the interests of the State.

If the governing board or the executive head/president, or his designees, of any agency/public university determines that an emergency exists, the agency/public university shall follow the procedures that correspond with each specific emergency type declaration as identified below and shall file the appropriate documentation with ITS as required by statute, the ITS procedures, and as requested by ITS.

Please note the following applies to all emergency purchases: Total purchases made under Section 31-713(j) shall only be for the purpose of meeting the needs created by the emergency. ITS anticipates an emergency may include multiple purchases including purchases that fall under different types of emergencies. The agency or public university must submit documentation for each declared emergency purchase separately and pay careful attention to the requirements under

115

each emergency type including, but not limited to, purchases that require ITS approval as well as the specific documentation required under each type of emergency. Emergency purchases shall be made with as much competition as is practicable under the circumstances and limited in time and scope to those products/services necessary to meet the emergency. Any contract awarded pursuant to an emergency purchase shall not exceed a term of one (1) year.

(1) Emergencies Threatening Health or Safety of Any Person or Preservation or Protection of Property (Does Not Require ITS Approval)

Whether an emergency exists which threatens the health or safety of any person or the preservation or protection of property is an agency/public university decision. ITS does not approve emergency purchases of this type nor determine the validity of the agency/public university emergency declaration. However, the corresponding ITS Emergency Purchase Form and post-purchase documentation are required to be filed with ITS as soon as practicable AFTER the emergency purchase.

If the governing board or the executive head/president, or his designees, of an agency or public university determines that an emergency exists so that the delay incident to giving opportunity for competitive bidding would threaten the health or safety of any person or the preservation or protection of property, the provisions of competitive bidding shall not apply, and the agency/public university shall submit the completed and signed “ITS Emergency Purchase Form (Where Delay Would Threaten Health, Safety, or Property)” available on the ITS website to ITS as soon as practicable AFTER the emergency purchase as well as post-purchase documentation required by Section 31-7-13(j).

See “Additional Information: Emergency Purchase Form and Post-Purchase Documentation” for information that must be provided on the form, including any attachments, and the post-purchase documentation requirements.

(2) Emergencies Where Delay Would Be Detrimental to the Interests of the State (Requires ITS Approval)

All other situations meeting the definition of “emergency” set forth in Section 31-7-1(f) are an agency/public university decision and require approval from ITS BEFORE the emergency purchase.

If the governing board or the executive head/president, or his designees, of an agency or public university determines that an emergency exists so that the delay incident to giving opportunity for competitive bidding would be detrimental to the interests of the state, then the agency/public university must seek prior approval from ITS to make the purchase without having to comply with the competitive bid requirements.

The agency/public university must submit the completed and signed “ITS Emergency Purchase Request Form (Where Delay Would Be Detrimental to the Interests of the State)” available on the ITS website to ITS with a certified copy of the minutes of the board of such agency/public

116

university documenting the emergency purchase request, if applicable, PRIOR to the emergency purchase for ITS review and approval.

If the request is approved by ITS, the agency/public university must also submit post-purchase documentation as required by Section 31-7-13(j) after the emergency purchase.

See “Additional Information: Emergency Purchase Form and Post-Purchase Documentation” for information that must be provided on the form, including any attachments, and the post-purchase documentation requirements.

Additional Information: Emergency Purchase Form and Post-Purchase Documentation

Agencies/public universities shall provide sufficient detail on the appropriate emergency purchase form so that a person not familiar with the situation could be expected to understand the need to forego the normal purchasing procedure including the type/nature of the emergency, the specific emergency component that applies to the current emergency situation, and from whom the purchase was made. The form shall be signed by the agency executive head or public university president unless a request for a designee signature is approved by ITS.

Submission of the completed form, along with the necessary documentation, is required to ensure compliance with Section 31-7-13(j). And when applicable, gives ITS the necessary information to review the emergency purchase request.

Please note: • For emergency purchases that do not require prior ITS approval, ITS will issue a CP-1 Acquisition Approval Document to facilitate payment processing upon receipt of the Emergency Purchase Form and required documentation. • For emergency purchase requests that do require prior ITS approval, upon approval, ITS issues a CP-1 Acquisition Approval Document to facilitate payment processing. For state agencies, these approvals are uploaded into MAGIC.

Failure to provide required and sufficient information may result in delay in issuing the CP-1 and/or approval of the emergency request, if required.

Emergency Purchase Form

Agencies/public universities shall address the following on the corresponding Emergency Purchase Form:

• Does the situation fall under the definition of an emergency set forth in Section 31-7-1(f)? o The response to this item shall outline the specific component of the definition that applies in the current emergency situation. • Does the emergency threaten the health or safety of any person or the preservation or protection of property?

117

o If yes, ITS approval is not required, and the agency/public university may proceed with the emergency purchase and submit the corresponding Emergency Purchase form and post purchase documentation as soon as practicable to ITS AFTER the emergency purchase. o If no, ITS approval is required, and the agency/public university must submit the corresponding Emergency Purchase form and documentation to ITS PRIOR to the emergency purchase. • What happened to cause the emergency? o This explanation is an expansion on the events surrounding the specific emergency that is cited in response to the above question. • What would be the negative consequences of following normal purchasing procedures? o This includes an explanation of the expected turnaround time for following a normal purchasing process contrasted with the timeframe in which the products or services are required in order to perform the mission of the agency. • Basis of selection of vendor(s)to be used o In response to this question, agencies/public universities should describe the research and selection process used for the requested emergency purchase. Agencies/public universities should use reasonable efforts to: ▪ Compare vendor offerings ▪ Ensure the selected product or service provided meets the needs of the agency/public university ▪ Obtain favorable pricing and contract terms using the following: • Written quotations • Use of state contract templates • Internet research • Reference checking • Other information means that can be used within the time constraints imposed by the emergency • Vendor’s contract • PO/Invoice • MAGIC Vendor Codes • If applicable, for emergencies where delay would be detrimental to the interests of the State, a copy of the certified minutes of the agency/public university’s board meeting regarding the request for an emergency purchase must be attached to the corresponding emergency form. o The agency head/university president or their designee must ensure each emergency purchase request is documented in the minutes of the board meeting prior to the emergency purchase. The minutes must include a description of the information technology to be purchased, the cost, the vendor from whom the purchase will be made, and the nature of the emergency. A copy of these minutes must be provided to ITS with the emergency purchase request. • Signature of agency head or public university president o The signature, for an emergency purchase, is the requesting entity’s certification that an emergency exists as outlined in Section 31-7-13(j). o Only the agency head or public university president shall sign the form unless a request for a designee signature is approved by ITS.

118

Post-Purchase Documentation Agencies/public universities shall also provide ITS with post-purchase documentation. In addition to submission of the signed and completed corresponding ITS Emergency Purchase Form, in compliance with Section 31-7-13(j), following the emergency purchase, the agency or public university shall also provide documentation of the purchase, including a description of the product/service purchased, the purchase price thereof, and the nature of the emergency which shall be filed with ITS.

Source: 31-7-1(f); 31-7-13(j)

119

Part 2 Chapter 7: Procurement Types Rule 207.7: 013-080 Procurement Types: EPL Planned Purchase The EPL Planned Purchase Procedure allows an agency to make purchases that exceed the cost limit of an Express Products List (EPL). As the coordinator of the information technology planning effort for state government agencies, ITS works with agencies during the planning process to determine procurements that can be appropriately made using EPLs. The EPL planned purchases procedure is limited to: (1) Projects in the agency's current technology plan (2) Equipment or software appearing on a current EPL

An agency using the EPL Planned Purchase Procedure is given authorization, up to a specified dollar amount, to make the identified procurements from the EPLs without further ITS involvement. The approval is issued in the form of a letter from the ITS Executive Director and a CP-1 Acquisition Approval Document. The purchasing agency should retain the approval letter in its purchasing documentation.

Since agencies often make their purchases under the EPL Planned Purchase approval over the course of the fiscal year and to multiple vendors, ITS also sends a Planned Purchases Tracking Form with the approval letter and CP-1. This form should be used to record the date, purchase order number, and dollar amount of each expenditure made under the EPL Planned Purchases approval. This form serves as a tracking tool for the agency, and the agency is required to retain the completed form in its purchasing documentation for audit purposes.

The purchasing agency should also document that an effort was made to obtain a lower price than the published EPL price, since the volume purchased under an EPL Planned Purchase approval is higher than the typical EPL amount. Each EPL has instructions relevant to negotiating volume discounts with vendors. EPL Planned Purchase requests must be accompanied by a minimum of two vendor quotes for purchases up to $1,000,000 and three quotes for purchases over $1,000,000. Additional instructions for submitting EPL Planned Purchase requests are contained on the EPL Planned Purchase procurement form. EPL Planned Purchases with a lifecycle cost above the Director Approval thresholds defined in Section 018-030 require ITS Board approval.

During review of your agency’s IT plan, it may be determined that a project might benefit from a Planned Purchase Procurement. If so, an IT Planning Coordinator will contact your agency. To initiate an EPL Planned Purchase prior to being contacted, call Debra Brown, IT Planning Coordinator, at 601-432-8128; contact the ITS Procurement Help Desk at 601-432-8166; or submit a Planned Purchase Procurement Request to ITS Procurement. Additional information and contact information for agency planning is located on the ITS website.

Although the Planned Purchase Procedure was primarily established for state agencies who submit technology plans to ITS annually, IHLs, community colleges, local governments, K-12 schools, and other government entities who have shown due diligence in technology planning and who want to use the ITS EPLs above the default spending thresholds may be eligible for planned purchases. These public entities may submit a request for a planned purchase to ITS along with a copy of their current technology plan in the format required by their regulatory agent. The request

120

should also include detailed information regarding the items to be purchased and the EPL quotations received. ITS will review the plan information and the specific procurement details to see if a planned purchase is appropriate.

Refer to 009-001 ITS Procurement Process Flows for additional information, specifically the flow labeled Planned Purchases.

Source: 25-53-25 (2)

121

Part 2 Chapter 8: Procurement Limits Policies Rule 208.1: 015-010 Procurement Limits Policies: State Agencies Procedures for the Acquisition of Information Technology Equipment, Software, and Services by Procurement Type and Total Lifecycle Cost for State Agencies

By law, all acquisitions of information technology must be approved by ITS. ITS has delegated this responsibility to agencies for certain types of purchases and lifecycle cost limits. Note that these thresholds are based upon total lifecycle costs and that there are situations in which actual monies paid is not the sole determinant of the requirement for a competitive procurement process. For purchases in which (1) the value of the goods and services exceeds bid limit, (2) there is a competitive market, and (3) there is potential for vendor profit from the project, contracts must be awarded based on an open and competitive process that allows the state to compare offerings to obtain the best product, service, and value, regardless of monies paid directly to the vendor by the state entity. The competitive process ensures the state’s requirements are well- defined, project contracts are negotiated to protect the state’s interest, and the vendor selected is the one with the most advantageous combination of cost and services.

The table below defines the procedures and the required approvals for each category and project lifecycle cost range. For current Director Approval thresholds, see Section 018-030.

122

Procurement Type/Lifecycle Cost $.01 - $5,000.00 $5,000.01 - up to but not over the dollar amount established in Section 31-7-13(c) In excess of the dollar amount established in Section 31-7-13(c), up to Director Approval Threshold Above Director Approval Threshold Regular Competitive Procurement • Delegated to Agency • May purchase without advertising or otherwise requesting competitive bids • Delegated to Agency • May purchase without advertisement for bids, provided at least two competitive written bids have been obtained • You must select the lowest quote

• Requires ITS approval: CP-1 in MAGIC • Advertisement & receipt of competitive bids required by law

• Requires ITS Board approval • Requires ITS approval: CP-1 in MAGIC • Advertisement & receipt of competitive bids required by law • Requires Business Case • Requires IT Security Risk Assessment Cooperative Purchasing Agreement No delegation. Regardless of lifecycle cost, ITS statute and policy require ITS review and approval of all cooperative purchases of technology.

No delegation. Regardless of lifecycle cost, ITS statute and policy require ITS review and approval of all cooperative purchases of technology.

No delegation. Regardless of lifecycle cost, ITS statute and policy require ITS review and approval of all cooperative purchases of technology.

No delegation. Regardless of lifecycle cost, ITS statute and policy require ITS review and approval of all cooperative purchases of technology.

123

Procurement Type/Lifecycle Cost $.01 - $5,000.00 $5,000.01 - up to but not over the dollar amount established in Section 31-7-13(c) In excess of the dollar amount established in Section 31-7-13(c), up to Director Approval Threshold Above Director Approval Threshold Telecommunications Systems and Services (See Acquisition of Telecommunications Services by State Agencies for more information)

No delegation. ITS has conducted these procurements on behalf of the state and has contracts in place that must be used by agencies for telecommunications systems and services (voice and data). See ITS Telecommunications Contracts for State Agencies for details. No delegation. ITS has conducted these procurements on behalf of the state and has contracts in place that must be used by agencies for telecommunications systems and services (voice and data). See ITS Telecommunications Contracts for State Agencies for details. No delegation. ITS has conducted these procurements on behalf of the state and has contracts in place that must be used by agencies for telecommunications systems and services (voice and data). See ITS Telecommunications Contracts for State Agencies for details. No delegation. ITS has conducted these procurements on behalf of the state and has contracts in place that must be used by agencies for telecommunications systems and services (voice and data). See ITS Telecommunications Contracts for State Agencies for details. Note: ITS contracts have already received Board approval. Agency acquisitions of services from these contracts do not require additional Board action.

124

Procurement Type/Lifecycle Cost $.01 - $5,000.00 $5,000.01 - up to but not over the dollar amount established in Section 31-7-13(c) In excess of the dollar amount established in Section 31-7-13(c), up to Director Approval Threshold Above Director Approval Threshold Sole Source Procurement • Delegated to Agency • May purchase without advertising or otherwise requesting competitive bids • Requires ITS approval: CP-1 in MAGIC • Submit Sole Source Certification Request with vendor and agency documentation to ITS 3-5 weeks before purchase (Note: Agency Head or Designee must sign the sole source request) • Requires ITS approval: CP-1 in MAGIC • Submit Sole Source Certification Request with vendor and agency documentation to ITS 3-5 weeks before purchase (Note: Agency Head or Designee must sign the sole source request) • Requires ITS Board approval • Requires ITS approval: CP-1 in MAGIC • Submit Sole Source Certification Request with vendor and agency documentation to ITS 2-4 months before purchase • Requires Business Case • Requires IT Security Risk Assessment (Note: Agency Head or Designee must sign the sole source request)

125

Procurement Type/Lifecycle Cost $.01 - $5,000.00 $5,000.01 - up to but not over the dollar amount established in Section 31-7-13(c) In excess of the dollar amount established in Section 31-7-13(c), up to Director Approval Threshold Above Director Approval Threshold Exemption from ITS Not applicable: Already delegated to agency Not applicable: Already delegated to agency (Note: ITS cannot exempt a sole source procurement > $5,000) • Requires ITS approval: CP-1 in MAGIC • Advertisement & receipt of competitive bids required by law (conducted by the Agency after exemption is approved by ITS) • Submit Exemption Request to ITS 2-4 weeks prior to advertising the procurement • Requires ITS Board approval • Requires ITS approval: CP-1 in MAGIC • Advertisement & receipt of competitive bids required by law (conducted by the Agency after exemption is approved by ITS) • Submit Exemption Request to ITS 4-6 weeks prior to advertising the procurement • Requires Business Case • Requires IT Security Risk Assessment Express Products Lists (EPLs) • Delegated to Agency • Access EPL on ITS website • Follow instructions on specific EPL • Delegated to Agency • Access EPL on ITS website • Follow instructions on specific EPL • Delegated to Agency up to EPL limit • Access EPL on ITS website • Follow instructions on specific EPL • See EPL Planned Purchase

126

Procurement Type/Lifecycle Cost $.01 - $5,000.00 $5,000.01 - up to but not over the dollar amount established in Section 31-7-13(c) In excess of the dollar amount established in Section 31-7-13(c), up to Director Approval Threshold Above Director Approval Threshold EPL Planned Purchase Not applicable Not applicable Purchase above EPL limit: • Requires approval letter from ITS Executive Director and CP-1 • Requires that project be in current IT Plan submitted by agency to ITS & equipment /software needed must appear on a current EPL • ITS planner contacts agency concerning Planned Purchases during review of agency's plan. Call your planner or submit an EPL Planned Purchase Request to ITS to initiate a Planned Purchase prior to being contacted. Requires ITS Board approval • Requires approval letter from ITS Executive Director and CP-1 • Requires that project be in current IT Plan submitted by agency to ITS & equipment /software needed must appear on a current EPL • ITS planner contacts agency concerning Planned Purchases during review of agency's plan. Call your planner or submit an EPL Planned Purchase Request to initiate a Planned Purchase prior to being contacted (at least 2 weeks prior to ITS Board Meeting). • Requires Business Case

127

Procurement Type/Lifecycle Cost $.01 - $5,000.00 $5,000.01 - up to but not over the dollar amount established in Section 31-7-13(c) In excess of the dollar amount established in Section 31-7-13(c), up to Director Approval Threshold Above Director Approval Threshold Emergency Procurement (where delay is detrimental to the interests of the State) Not applicable • Requires ITS approval: CP-1 in MAGIC • Submit Emergency Purchase Request Form with vendor and agency documentation to ITS before purchase • (Note: Agency Head or Designee, if approved by ITS, must sign the Emergency Purchase Request Form) • If request approved, submit post-purchase documentation following the purchase • Requires ITS approval: CP-1 in MAGIC • Submit Emergency Purchase Request Form with vendor and agency documentation to ITS before purchase • (Note: Agency Head or Designee, if approved by ITS, must sign the Emergency Purchase Request Form) • If request approved, submit post-purchase documentation following the purchase • Requires ITS Board approval • Requires ITS approval: CP-1 in MAGIC • Submit Emergency Purchase Request Form with vendor and agency documentation to ITS before purchase • (Note: Agency Head or Designee, if approved by ITS, must sign the Emergency Purchase Request Form) • Requires Business Case • Requires IT Security Risk Assessment • If request approved, submit post-purchase documentation following the purchase

128

Procurement Type/Lifecycle Cost $.01 - $5,000.00 $5,000.01 - up to but not over the dollar amount established in Section 31-7-13(c) In excess of the dollar amount established in Section 31-7-13(c), up to Director Approval Threshold Above Director Approval Threshold Emergency Procurement (where delay threatens health or safety of any person or preservation or protection of property) Not applicable • Submit to ITS the Emergency Purchase Form signed by the Agency Head or Designee, if approved by ITS, along with the post-purchase documentation as soon as practicable after the emergency purchase • Submit to ITS the Emergency Purchase Form signed by the Agency Head or Designee, if approved by ITS, along with the post-purchase documentation as soon as practicable after the emergency purchase • ITS loads a CP-1 to MAGIC so the vendor payment can be processed • Submit to ITS the Emergency Purchase Form signed by the Agency Head or Designee, if approved by ITS, along with the post-purchase documentation as soon as practicable after the emergency purchase • ITS loads a CP-1 to MAGIC so the vendor payment can be processed • ITS Board informed of emergency

129

Procurement Type/Lifecycle Cost $.01 - $5,000.00 $5,000.01 - up to but not over the dollar amount established in Section 31-7-13(c) In excess of the dollar amount established in Section 31-7-13(c), up to Director Approval Threshold Above Director Approval Threshold E-Government Procurement NOTE: Due to the different vendor business models for E-Government services and products, the procurement approach is not governed by the total expenditure but by the true market value, as determined by the complexity and size of the project. See Sections 001-020 and 001-025 of this handbook for additional information on Electronic Government procurements. • Cost category must be based on true market value, not funds paid to vendor by agency • Requires DFA approval for any payment functionality • Follow process outlined in 001- 025 Approvals for Internet-based Applications and Services • Cost category must be based on true market value, not funds paid to vendor by agency • Requires DFA approval for any payment functionality • Follow process outlined in 001- 025 Approvals for Internet-based Applications and Services • Cost category must be based on true market value, not funds paid to vendor by agency • Requires DFA approval for any payment functionality • Follow process outlined in 001- 025 Approvals for Internet-based Applications and Services • Cost category must be based on true market value, not funds paid to vendor by agency • Requires DFA approval for any payment functionality • Requires ITS Board approval if true market value exceeds Director Approval Threshold • Follow process outlined in 001- 025 Approvals for Internet-based Applications and Services • Requires Business Case • Requires IT Security Risk Assessment

Source: 25-53-5; 25-53-25 (2); 25-53-151; 31-7-13 (c)

130

Part 2 Chapter 8: Procurement Limits Policies Rule 208.2: 015-020 Procurement Limits Policies: IHLs Procedures for the Acquisition of Information Technology Equipment, Software, and Services by Procurement Type and Total Lifecycle Cost for Institutions of Higher Learning

By law, all acquisitions of information technology products or services by IHLs must be approved by ITS. ITS has delegated this responsibility to the Chief Information Officers (CIOs) of the State's Institutions of Higher Learning for certain types of purchases and lifecycle cost limits. Note that these thresholds are based upon total lifecycle costs and that there are situations in which actual monies paid is not the sole determinant of the requirement for a competitive procurement process.

For purchases in which (1) the value of the goods and services exceeds bid limit, (2) there is a competitive market, and (3) there is potential for vendor profit from the project, contracts must be awarded based on an open and competitive process that allows the state to compare offerings to obtain the best product, service, and value, regardless of monies paid directly to the vendor by the state entity. The competitive process ensures the state’s requirements are well-defined, project contracts are negotiated to protect the state’s interest, and the vendor selected is the one with the most advantageous combination of cost and services.

For the certification of sole source procurements delegated to the CIOs at public universities, the public university must follow ITS’ Sole Source Procedure, including advertisement of the intent to award as sole source, as outlined in Chapter 7, 013-030.

The only statutory exception to the requirement for ITS approval is for acquisitions of computer equipment and services made by IHLs wholly with federal funds. These acquisitions do NOT fall within ITS' purview. In addition, Mississippi Code Section 25-53-5 (b) directs ITS, in establishing procedures and carrying out its statutory charges in relation to IHLs, to take into consideration the special needs of these institutions in relation to the fields of teaching and scientific research. In accordance with this directive, ITS has delegated procurement oversight for IT purchases to IHLs at a higher level of delegation for state agencies. These delegation thresholds and associated oversight requirements are outlined in the table that follows.

The table below defines the procedures and the required approvals for each category and project lifecycle cost range. For current Director Approval thresholds, see Section 018-030. Note that all Procurement Requests submitted to ITS must be signed by the Institution's CIO or that person's designee.

131

Procurement Type/Lifecycle Cost $.01 - $5,000.00 $5,000.01 - up to but not over the dollar amount established in Section 31-7- 13(c) In excess of the dollar amount established in Section 31-7- 13(c) - $250,000.00

$250,000.01 but below Director Approval Threshold Above Director Approval Threshold Regular Competitive Procurement • Delegated to Institution's CIO • May purchase without advertising or otherwise requesting competitive bids • Delegated to Institution's CIO • May purchase without advertisement for bids, provided at least two competitive written bids have been obtained • You must select the lowest quote

• Delegated to Institution's CIO • Advertisement & receipt of competitive bids required by law

• Requires ITS approval: CP-1 • Advertisement & receipt of competitive bids required by law • • Requires ITS Board approval and CP-1 • Advertisement & receipt of competitive bids required by law • Requires Business Case • Requires IT Security Risk Assessment Cooperative Purchasing Agreement No delegation. Regardless of lifecycle cost, ITS statute and policy require ITS review and approval of all cooperative purchases of technology.

No delegation. Regardless of lifecycle cost, ITS statute and policy require ITS review and approval of all cooperative purchases of technology. No delegation. Regardless of lifecycle cost, ITS statute and policy require ITS review and approval of all cooperative purchases of technology.

No delegation. Regardless of lifecycle cost, ITS statute and policy require ITS review and approval of all cooperative purchases of technology.

No delegation. Regardless of lifecycle cost, ITS statute and policy require ITS review and approval of all cooperative purchases of technology.

132

Telecommunica- tions Systems and Services (See Acquisition of Telecommunica- tions Services by IHLs for more information)

No delegation. ITS has conducted these procurements on behalf of the state and has contracts in place that can be used by IHLs for telecommunica- tions systems and services (voice and data). See ITS Telecommunica- tions Contracts for IHLs for details.

To acquire these services other than via an ITS contract, submit an exemption request to ITS prior to acquiring the service.

No delegation. ITS has conducted these procurements on behalf of the state and has contracts in place that can be used by IHLs for telecommunica- tions systems and services (voice and data). See ITS Telecommunica- tions Contracts for IHLs for details.

To acquire these services other than via an ITS contract, submit an exemption request to ITS prior to acquiring the service. No delegation. ITS has conducted these procurements on behalf of the state and has contracts in place that can be used by IHLs for telecommunica- tions systems and services (voice and data). See ITS Telecommunica- tions Contracts for IHLs for details.

To acquire these services other than via an ITS contract, submit an exemption request to ITS prior to advertising for the service. No delegation. ITS has conducted these procurements on behalf of the state and has contracts in place that can be used by IHLs for telecommunica- tions systems and services (voice and data). See ITS Telecommunica- tions Contracts for IHLs for details. No delegation. ITS has conducted these procurements on behalf of the state and has contracts in place that can be used by IHLs for telecommunica- tions systems and services (voice and data). See ITS Telecommunica- tions Contracts for IHLs for details. Note: ITS contracts have already received Board approval. IHL acquisitions of services from these contracts do not require additional Board action. Exemptions to acquire these services other than via ITS contracts require Board approval. Submit an exemption request to ITS 6- 8 weeks prior to advertising for the service. • Requires Business Case

133

Procurement Type/Lifecycle Cost $.01 - $5,000.00 $5,000.01 - up to but not over the dollar amount established in Section 31-7- 13(c) In excess of the dollar amount established in Section 31-7- 13(c) - $250,000.00

$250,000.01 but below Director Approval Threshold Above Director Approval Threshold • Requires IT Security Risk Assessment Sole Source Procurement • Delegated to Public University's CIO • May purchase without advertising or otherwise requesting competitive bids Sole Source Certification Delegated to Public University's CIO • Must follow ITS Sole Source Procedure as outlined in Chapter 7, 013-030 of this Handbook

Sole Source Certification Delegated to Public University's CIO • Must follow ITS Sole Source Procedure as outlined in Chapter 7, 013-030 of this Handbook

• Requires ITS approval: CP-1 • Submit Sole Source Certification Request with vendor and institution documentation to ITS 3-5 weeks before purchase (Note: Public University's CIO or Designee must sign the sole source request) • Requires ITS Board approval and CP-1 • Submit Sole Source Certification Request with vendor and Public University's documentation to ITS 2-4 months before purchase • Requires Business Case (Note: Public University's CIO or Designee must sign the sole source request)

134

Procurement Type/Lifecycle Cost $.01 - $5,000.00 $5,000.01 - up to but not over the dollar amount established in Section 31-7- 13(c) In excess of the dollar amount established in Section 31-7- 13(c) - $250,000.00

$250,000.01 but below Director Approval Threshold Above Director Approval Threshold Exemption from ITS Not applicable: Already Delegated to Institution's CIO Not applicable: Already Delegated to Institution's CIO Not applicable: Already Delegated to Institution's CIO • Requires ITS approval: CP-1 • Advertisement & receipt of competitive bids required by law (conducted by the Institution after the exemption is approved) • Submit Exemption Request to ITS 2-4 weeks prior to advertising the procurement (Note: ITS cannot exempt a sole source procurement > $250,000) • Requires ITS Board approval and CP-1 • Requires Business Case • Requires Security Risk Assessment • Advertisement & receipt of competitive bids required by law (conducted by the Institution after the exemption is approved) • Submit Exemption Request to ITS 4 - 6 weeks prior to advertising the procurement Express Products Lists (EPLs) • Delegated to Institution's CIO • Access EPL on ITS website • Follow instructions on specific EPL • Delegated to Institution's CIO • Access EPL on ITS website • Follow instructions on specific EPL • Delegated to Institution's CIO up to EPL limit • Access EPL on ITS website • Follow instructions on specific EPL • Delegated to Institution’s CIO up to EPL limit • Access EPL on ITS website • Follow instructions on specific EPL • See EPL Planned Purchase

135

Procurement Type/Lifecycle Cost $.01 - $5,000.00 $5,000.01 - up to but not over the dollar amount established in Section 31-7- 13(c) In excess of the dollar amount established in Section 31-7- 13(c) - $250,000.00

$250,000.01 but below Director Approval Threshold Above Director Approval Threshold EPL Planned Purchase Not applicable Not applicable Purchase above EPL limit: • Requires ITS approval: Letter from ITS Executive Director • Requires submitting IT Plan to ITS for review; equipment /software needed must appear on a current EPL • ITS planners and procurement analysts assess the plan and the procurement request • See EPL Planned Purchase for further details. • Requires ITS approval: Letter from ITS Executive Director • Requires submitting IT Plan to ITS for review; equipment/softw are needed must appear on a current EPL • ITS planners and procurement analysts assess the plan and the procurement request • See EPL Planned Purchase for further details. • Requires ITS Board approval • Requires Business Case • Requires IT Security Risk Assessment • Requires approval letter from ITS Executive Director • Requires submitting IT Plan to ITS for review; equipment /software needed must appear on a current EPL • ITS planners and procurement analysts assess the plan and the procurement request • See EPL Planned Purchase for further details.

136

Procurement Type/Lifecycle Cost $.01 - $5,000.00 $5,000.01 - up to but not over the dollar amount established in Section 31-7- 13(c) In excess of the dollar amount established in Section 31-7- 13(c) - $250,000.00

$250,000.01 but below Director Approval Threshold Above Director Approval Threshold Emergency Procurement (where delay is detrimental to the interests of the State) Not applicable • Requires ITS approval: CP-1 • Submit Emergency Purchase Request Form with documentation to ITS before purchase (Note: IHL President or Designee, if approved by ITS, must sign the Emergency Purchase Request Form) If request approved, submit post-purchase documentation following the purchase • Requires ITS approval: CP-1 • Submit Emergency Purchase Request Form with documentation to ITS before purchase (Note: IHL President or Designee, if approved by ITS, must sign the Emergency Purchase Request Form) If request approved, submit post-purchase documentation following the purchase • Requires ITS approval: CP-1 • Submit Emergency Purchase Request Form with documentation to ITS before purchase (Note: IHL President or Designee, if approved by ITS, must sign the Emergency Purchase Request Form) If request approved, submit post-purchase documentation following the purchase • Requires ITS Board approval and CP-1 • Submit Emergency Purchase Request Form with documentation to ITS before purchase • (Note: IHL President or Designee, if approved by ITS, must sign the Emergency Purchase Request Form) • Requires Business Case • Requires IT Security Risk Assessment • If request approved, submit post- purchase documentation following the purchase

137

Procurement Type/Lifecycle Cost $.01 - $5,000.00 $5,000.01 - up to but not over the dollar amount established in Section 31-7- 13(c) In excess of the dollar amount established in Section 31-7- 13(c) - $250,000.00

$250,000.01 but below Director Approval Threshold Above Director Approval Threshold Emergency Procurement (where delay threatens health or safety of any person or preservation or protection of property) Not applicable • Submit to ITS the Emergency Purchase Form signed by the IHL President or Designee, if approved by ITS, along with the post- purchase documentation as soon as practicable after the emergency purchase • Submit to ITS the Emergency Purchase Form signed by the IHL President or Designee, if approved by ITS, along with the post- purchase documentation as soon as practicable after the emergency purchase

• Submit to ITS the Emergency Purchase Form signed by the IHL President or Designee, if approved by ITS, along with the post-purchase documentation as soon as practicable after the emergency purchase • ITS issues a CP- 1 so the vendor payment can be processed

• Submit to ITS the Emergency Purchase Form, signed by the IHL President or Designee, if approved by ITS, along with the post- purchase documentation as soon as practicable after the emergency purchase • ITS issues a CP-1 so the vendor payment can be processed • ITS Board informed of emergency procurement and surrounding circumstances

138

Procurement Type/Lifecycle Cost $.01 - $5,000.00 $5,000.01 - up to but not over the dollar amount established in Section 31-7- 13(c) In excess of the dollar amount established in Section 31-7- 13(c) - $250,000.00

$250,000.01 but below Director Approval Threshold Above Director Approval Threshold E-Government Procurement NOTE: Due to the different vendor business models for E-Government services and products, the procurement approach is not governed by the total expenditure but by the true market value, as determined by the complexity and size of the project. See Section 001- 020 of this handbook for additional information on Electronic Government procurements. • Delegated to Institution's CIO • Advertisement & receipt of competitive bids required if true market value of services exceeds the dollar amount established in Section 31-7- 13(c) regardless of funds expended • Delegated to Institution's CIO • Advertisement & receipt of competitive bids required if true market value of services exceeds the dollar amount established in Section 31-7- 13(c), regardless of funds expended • Delegated to Institution's CIO • Advertisement & receipt of competitive bids required • Requires ITS approval: CP-1 • Advertisement & receipt of competitive bids required by law • Submit Procurement Request to ITS 2-5 months before purchase • Requires ITS Board approval and CP-1 • Advertisement & receipt of competitive bids required by law • Submit Procurement Request to ITS 3-8 months before purchase • Requires Business Case • Requires IT Security Risk Assessment

Source: 25-53-5; 25-53-25 (2); 25-53-151; 31-7-13 (c)

139

Part 2 Chapter 9: Awards and Contracts Rule 209.1: 018-010 Proposal Evaluation Process Each Request for Proposals (RFP) and Letter of Configuration (LOC) issued by ITS contains a summary-level description of the criteria and process that will be used in the evaluation of submitted proposals to determine the winning proposal. The details of the evaluation process and scoring methodology for each RFP are developed prior to the receipt of proposals, and the summary point allocation by category is posted on the ITS website when proposals are received. The LOC evaluation process and scoring methodology are documented to the project file prior to receipt of proposals and posted on the LOC database for access by General RFP vendors.

While the evaluation process used for a specific RFP or LOC will be customized to fit the particular procurement, ITS generally applies the evaluation practices outlined below for proposal evaluation. Steps may be combined, added, or eliminated at the sole discretion of the State based on attributes of the specific procurement project. Once the evaluation process has been defined for a given RFP or LOC, each proposal received is evaluated in a consistent and defensible manner according to that evaluation process.

The intent of the evaluation process is to establish a ranking of proposals based on the requirements of the RFP or LOC. See 018-020 Proposal Evaluation Criteria and Scoring Formula for details on the numerical scoring of proposals.

Proposal Evaluation Practices:

  1. The ITS Technology Consultant assigned to the procurement project leads the evaluation process and ensures that the evaluation process and scoring methodology are consistently followed and documented.
  2. The ITS Technology Consultant has primary responsibility for validating each proposal to ensure that all essential elements are present: e. g. number of copies, proposal bond, signatures. Such validation should occur on the day the proposals are received. Vendors may, at the State's sole discretion, be allowed to remedy some procedural deficiencies by immediate delivery of additional copies, valid bonds, or signed cover sheets within the timeframe established by the State, typically within twenty-four hours or less of proposal due date. In no case, however, will a vendor be allowed to submit additional price information that cannot be derived from the original proposal, nor will unsolicited clarifications be accepted outside the process defined in the RFP or LOC. Proposals that are non-responsive due to missing components or failure to follow critical instructions are eliminated from further consideration. If costs are required to be submitted and sealed separately, proposals that include any cost information in the unsealed portion of the technical proposal will be eliminated from further consideration
  3. The ITS Technology Consultant, in conjunction with the customer, names an evaluation team prior to the receipt of proposals. Members of the evaluation team may be asked to participate in the scoring of entire proposals or in the scoring of only portion(s) of proposals that correspond with the member's particular knowledge and expertise.

140

  1. If appropriate, the ITS Technology Consultant conducts an evaluation orientation session, explaining the evaluation process and scoring methodology and distributing copies of the proposals to the team members.
  2. Proposal confidentiality statements are obtained from each team member before distribution of the proposals.
  3. Each evaluator individually reviews the proposals, or portions of proposals assigned, prior to the evaluation scoring work sessions. Evaluators review, take notes, and prepare questions for discussion.
  4. The evaluation team may determine from their initial review that some proposals are non- responsive and will not be included in the evaluation. Proposals may be deemed non- responsive by the following ways: • The vendor did not follow the instructions in the RFP in preparing the proposal • Required information or critical components are omitted • Total cost cannot be determined • The proposal is clearly outside the scope of the RFP or LOC and/or proposes an alternate approach unacceptable to the State • The proposal offers only a partial solution to the State's requirements • The overall quality of the response is too poor to be evaluated with reasonable effort • Other significant shortfalls determined by the evaluation team. If a proposal is determined to be non-responsive, the evaluation team documents the reasons the proposal is eliminated from consideration and does not proceed further with the evaluation and scoring of the proposal.
  5. For RFPs that do not have sealed costs, the ITS Technology Consultant and evaluation team may determine that a proposal’s costs that are outside the project budget and/or out of the competitive range may not be included in the initial round of scoring.
  6. For RFPs that contain Mandatory Provisions, as identified on the cover page and detailed in the Technical Specifications section of the RFP, proposals that do not meet one or more of the Mandatory Provisions are subject to immediate disqualification and elimination from further consideration, at the sole discretion of the State.
  7. The ITS Technology Consultant facilitates consensus scoring sessions for the technical components of each proposal. During the technical evaluation, the evaluation team discusses each item to be scored and arrives at an overall consensus score for the technical portion of the RFP. The ITS Technology Consultant records the scores assigned by the team and documents specific ways in which any item exceeds or does not meet specifications. Proposals may be scored based only on criteria and specifications outlined in the RFP or LOC.
  8. The ITS Technology Consultant, in conjunction with the evaluation team, determines the clarifications required for each proposal and solicits these clarifications from the vendor(s) in writing. The information in clarifications is then reviewed to determine whether the

141

scoring is impacted by the additional information. All written clarifications become part of the vendor's proposal. 12. If references are to be verified, the ITS Technology Consultant, in conjunction with the evaluation team, develops a reference questionnaire. References are checked by telephone or email. Records of each vendor reference contacted are retained for the evaluation file. 13. Scores from the consensus scoring sessions are tallied by the ITS Technology Consultant. The ITS Technology Consultant reviews the consensus findings with the designated Quality Assurance (QA) Coordinator to ensure the process was followed and scores were assigned consistently. If there is a required threshold ("gate"), typically expressed as a minimum percentage of the technical requirements that must be met or of the non-cost points that must be obtained to proceed to vendor presentations and/or the cost evaluation phase, the proposals not reaching that threshold are eliminated from further consideration. 14. For proposals within the competitive range, the evaluation team reviews each proposal's exception summary and determines which exceptions are acceptable to the State, which cannot be accepted, and which can be negotiated after contract award. Proposals with a substantial number of material exceptions and/or with exceptions that are not acceptable to the State may, at the sole discretion of the evaluation team, be eliminated from further consideration at any point in the evaluation process. 15. The ITS Technology Consultant, in conjunction with the customer and other scoring team members, schedules vendor presentations, if required. If there is a possibility that vendor presentations will be required during the evaluation process, this possibility will be stated in the underlying RFP or LOC. All vendors who have submitted responsive proposals in the competitive range will be asked to schedule a presentation. Oral presentations are typically recorded and become part of the vendors' proposals. Following all presentations, the evaluation team reviews the scoring of each proposal to see if information from the presentation impacted the consensus score for any item. 16. The ITS Technology Consultant, with assistance as needed from the evaluation team, compiles the cost information, ensuring that all applicable costs are included in the price evaluation of each proposal, verifying quantities and calculations, and ensuring the cost proposal is consistent with the functional/technical proposal. The evaluation team may request vendor clarifications on inconsistencies or on what is included or not included in a particular cost item. No new pricing can be accepted after the proposal due date, except as defined in the underlying RFP or LOC. Any proposal for which the cost cannot be precisely determined will be eliminated from further consideration. See 018-020 Proposal Evaluation Criteria and Scoring Formula for details on cost calculation and scoring formula. 17. The evaluation team determines whether a Best and Final Offer (BAFO) will be requested. The State reserves the right to request a BAFO on any procurement. The decision of whether to request a BAFO is solely the decision of the State. If a BAFO is to be required from the vendors, the ITS Technology Consultant and the evaluation team develop a written request that outlines the information to be provided and the deadline for submitting the BAFO. This document is provided to all vendors who have submitted responsive proposals in the

142

competitive range and who could be reasonably expectant of award. BAFOs are evaluated in the same manner as the original proposals. 18. The ITS Technology Consultant compiles and verifies all scores (technical and cost) and determines the apparent winning proposal. After this information has been verified by the Technology Consultant's QA Coordinator, it is sent to the evaluation team for verification. 19. Once the scoring has been reviewed and accepted by the evaluation team, the ITS Technology Consultant formally requests customer concurrence with the award recommendation, posts a notification of the award to the ITS website, and emails participating vendors a notice of intent to award pending ITS Board approval and/or successful contract negotiations. 20. Depending on the project cost, either the ITS Executive Director or the ITS Board must approve the award. This approval is independent of any approvals required by the customer agency or other regulatory or oversight entities. See 018-030 ITS Director Approval & ITS Board Approval of Procurements for additional information. 21. The ITS Technology Consultant, the Special Assistant Attorney General assigned to ITS, and the designated customer representatives begin contract negotiations with the awarded vendor. Should negotiations not be successful within a reasonable amount of time, the State may discontinue negotiations and begin negotiations with the vendor that provided the next most competitive proposal.

Source: 25-53-5 (o)

143

Part 2 Chapter 9: Awards and Contracts Rule 209.2: 018-020 Proposal Evaluation Criteria and Scoring Formula Section 25-53-5 (o) of the Mississippi Code specifies that any contract for a technology acquisition be awarded to the vendor submitting the "lowest and best" proposal. This requirement means the evaluation criteria and scoring formula for evaluating vendor proposals include both quantitative and qualitative measures. For each Request for Proposals (RFP) and Letter of Configuration (LOC) issued, ITS works with the customer agency/public university to develop a scoring formula, based on 100 points.

The initial determination in any scoring formula is the division of the 100 points between cost and non-cost components. Cost identifies the "lowest" proposal, but many other components applicable to determining the quality of the proposal are also considered in determining which proposal is both "lowest and best." The number of points allocated to cost is typically between 25 and 90 (i.e. 25% to 90% of the basis for determining the winning proposal). The cost points assigned for a particular procurement depend upon the nature of the products or services being acquired. This allocation is a business decision made by ITS and the customer agency or public university.

For a small number of LOCs or Invitations to Bid, the specifications consist of a list of specific hardware or software components and cost is the only determinant. A cost-only evaluation methodology is the exception for procurements under the purview of ITS. The higher the service component, the larger and more complex the project, and the greater the risk to the State, the higher the percentage of points allocated to the non-cost portion of the scoring formula.

Examples of factors other than cost that are considered for inclusion in the scoring formula are: • Quality and responsiveness of the proposal • Technical merit of the proposed solution • References • Company information • Quality of the project plan • Qualifications of proposed staff

Once the relevant non-cost evaluation criteria for the given RFP or LOC are selected, each criterion is assigned a weight. For some procurements, the evaluation criteria are applied in steps. In these evaluations, each step may designate a threshold or pass/fail criteria that must be met for the proposal to be considered further.

ITS reserves the ability to add up to five "value-add" points for features of significant value to the State that are over-and-above the requirements of the RFP or LOC and are offered at no additional cost to the State. The scoring criteria developed for each procurement will specify whether value- add points are available and how they will be assigned. Value-add points are in addition to the 100 base points. In practice, Value-add points are rarely used. Other procurements have optional evaluation steps, such as an onsite interview or oral presentation, built in as contingencies. These steps are exercised or bypassed at the State's sole

144

discretion, based on an assessment by the evaluation team as to whether the extra information is needed for an adequate evaluation and determination of the award.

Scoring of the non-cost components in the evaluation criteria is always somewhat more subjective than the quantitative scoring of proposal cost information. Each valid proposal is evaluated against the requirements of the RFP. Proposals are not compared with each other. Unless otherwise justified by the nature of the project, ITS uses a consensus scoring approach to assign points to non-cost criteria. See 018-010 Proposal Evaluation Process for a description of consensus scoring.

Cost scores are computed using lifecycle costs (See 005-400 Terms: Lifecycle cost). The cost score is computed as a ratio of the difference between a given proposal's lifecycle cost and the lifecycle cost of the lowest valid proposal. The following cost scoring formula is used for every proposal evaluation:

Points awarded for cost = (1-((B-A)/A))*n Where: A = Total lifecycle cost of lowest valid proposal B = Total lifecycle cost of proposal being scored n = number of points allocated to cost for this procurement

In simpler terms, lowest price gets a perfect score. A proposal that is 20% more expensive than the lowest priced offering gets 20% fewer points.

When the above formula would result in a negative cost score (i.e. the lifecycle cost of the proposal being scored is more than twice that of the lowest valid proposal), the cost score is set to zero, rather than deducting points from the vendor's score.

Source: 25-53-5 (o)

145

Part 2 Chapter 9: Awards and Contracts Rule 209.3: 018-030 ITS Director Approval & ITS Board Approval of Procurements Mississippi Code Annotated, Section 25-53-5 (k), requires that contracts for information technology purchases be approved by the ITS Board. The Board is authorized to delegate this approval to the ITS Executive Director for projects costing less than a specified amount. The ITS Board is charged in state statute with the responsibility for maximizing the use and benefit of information technology by the agencies, boards, commissions, and public universities of the state. To address this directive, the ITS Board, during state fiscal year 2004, outlined a plan to redirect its focus to place more attention on strategic technology initiatives and to be more involved in the planning stages of mission-critical projects. The ITS Board expressed its intent to increase its ability to impact the responsible use of scarce technology dollars for more effective solutions that leverage state infrastructure investments and promote technical compatibility and coordination among agencies and public universities. As an important component of this redirection of its role, the ITS Board revised the content and format of board meetings. As the Board shifted its focus from the approval of contract awards at the end of a procurement process to the review, analysis, and approval of strategic technology initiatives, the Board set new thresholds for approval of procurement projects by the ITS Executive Director. With fewer procurement project presentations, the Board will have time to work with ITS and ITS customers on strategic planning, best practices, and leveraging the state’s investment in enterprise technology resources.

Prior to presenting a project to the ITS Board for approval, agencies must be incompliance with the Enterprise Security Policy and have obtained an IT Security Risk Assessment within three years of the date of the procurement presentation to the ITS Board. For more information on the IT Security Risk Assessment and the State of Mississippi Enterprise Security Policy, please visit the Information Security page of the ITS website at

http://www.its.ms.gov/Services/Pages/services_security.aspx.

A business case must be completed on all IT projects requiring ITS Board Approval. ITS has developed an IT Project Business Case Workbook to assist agencies in preparing the business case. Other advanced planning documentation such as a grant application might be substituted for the Business Case if it provides the necessary justification for the technology project. Please work with the IT Planning Coordinator at ITS to determine if the documentation may be substituted.

Business case documentation may be found on the ITS website at http://www.its.ms.gov/Services/Pages/Agency-IT-Planning.aspx. For more information or assistance, please contact the IT Planning Coordinator at ITS.

Due to the importance the Board places on technology planning, the new Director Approval thresholds do not apply to agencies without approved technology plans.

146

ITS Board Approval and Reporting Requirements/ Director Approval Thresholds Effective July 2004

Board Approval Requirements for Agencies with approved IT plans and for IHLs Director Approval Thresholds Procurement Category Board Approval Required if Total Project Lifecycle Cost is Greater Than: Default $1,000,000* Manufacturer Maintenance No limit: Board approval not required Bureau of Buildings Projects No limit: Board approval not required Consulting Services: Includes all projects that include either 'body shop' or deliverable-based technology consulting, other than incidental services provided in conjunction with another acquisition. $500,000* Projects identified by Board, ITS Director, ITS staff, and/or customer agency staff for special consideration: These projects will be identified at the direction of the ITS Board. The ITS Board may determine focus areas based on Enterprise Architecture initiatives, analysis of agency IT plans, and continued assessment of emerging technologies and opportunities for interoperability and leveraging state IT infrastructure investments. Board input and/or approval required Board Approval Requirements: for Agencies without approved IT plans

Default $250,000 Board Reporting Requirements Consulting Services Semi annually: Total consulting services approved, by agency, with list of individual CP-1s Annually: IT PINS by agency: filled and vacant, with salaries

IT PINS by position across all state agencies

*Note: The ITS Executive Director only approves state agency projects with a lifecycle cost above $250,000 if those projects are in the current technology plan on file with ITS. Approvals by the ITS Executive Director of projects costing more than $250,000 are designated "Director Approved

147

Planned Purchases." The CP-1 Acquisition Approval Documents for these procurements contain the project number from the agency's IT plan and have special language documenting that the acquisition was authorized under the Director Approval Planned Purchases Procedure.

The total project lifecycle cost is used to determine whether a contract can be approved by the ITS Executive Director ('Director Approval') or must be submitted to the ITS Board for approval (see 005-400 Terms: Lifecycle cost).

Because there are many types of projects and associated payment models and because contracts are frequently modified over the life of a project, the table below has been developed to describe situations in which ITS Board approval would be required. The table is not exhaustive. A customer who is uncertain whether ITS Board approval is required for a specific procurement is encouraged to discuss the procurement details with the ITS Technology Consultant assigned to the project after the request has been submitted. Type Contract: Board Approval Required if: (1) Initial: Single Phase The total initial and ongoing costs (maintenance, support, annual license fees, etc.) to be paid to vendor(s) for the projected lifecycle of the technology exceed the Director Approval threshold. (2) Initial: Multi-Phase The total cost of the initial phase is less than the Director Approval threshold, but the RFP/LOC included an option for the contract to continue for subsequent phases at the State’s discretion, with the vendor providing a cost proposal for the next phase as a deliverable in Phase I; the total cost of the initial phase and subsequent phases can reasonably be expected to exceed the Director Approval threshold (3) Modification/continuation: Amendment or change order to ongoing project a. Cost increase for the amendment or change order is above the Director Approval threshold; or b. Cost increase for the amendment or change order is less than the Director Approval threshold, but the new project total is above the Director Approval threshold, and there has been no previous Board approval for the project; or c. Cost increase for the amendment or change order is less than the Director Approval threshold; the project was approved by the Board; the sum of changes since the last Board approval exceeds the Director Approval threshold Source: 25-53-5 (k)

148

Part 2 Chapter 10: Procurement Policies Rule 210.1: 019-001 ITS Procurement Ethics

Principles and Standards

Procurement Code of Ethics

Procurement Code of Conduct

Principles and Standards for Ethical Procurement

ITS has adopted the following overriding principles and standards to guide individual and group decisions and actions related to technology procurements. These principles and standards are established to (1) encourage adherence to uncompromising ethical behavior, (2) increase awareness and acceptance of ethical conduct, and (3) emphasize the role of ethics when formulating decisions.

These standards are guidelines for everyone involved in technology procurements, whether they represent ITS, an ITS customer, or a technology vendor.

These principles and standards, along with the attached Code of Ethics and Code of Conduct, should be applied with good judgment, management support, and personal conscience when making decisions concerning actions that affect or influence public procurement.

Principles and Standards: Perceived Impropriety: Prevent the intent and appearance of unethical or compromising conduct in relationships, actions, and communications. Interactions among ITS, customers, and vendors must be honest and fair-minded. Avoid actions that appear to, or actually, diminish ethical conduct. Consequences of a perceived impropriety can be the same as consequences of an actual impropriety.

Conflicts of Interest: Ensure that any personal, business, or other activity does not conflict with the interests of the State or your role in technology procurement. Persons responsible for technology procurements must not use their positions to induce another person to provide inappropriate benefits to themselves or others. This standard applies to family, business, personal, or financial relationships. Even the appearance of a conflict must be avoided.

Issues of Influence: Avoid behaviors or actions that may negatively influence, or appear to influence, procurement decisions. Avoid any activity that reduces the objectivity of the decision- making process.

Responsibilities to the State: Uphold your responsibilities using reasonable care and granted authority to deliver value to the State. As employees of the State and public servants, technology procurement professionals serve the interests of the State of Mississippi to the exclusion of personal gain.

149

Vendor and Customer Relationships: Promote positive vendor and customer relationships. ITS procurement staff members are responsible for developing and maintaining effective business relationships with vendors and ITS customers. Impartiality across all business interactions enhances the reputation of ITS and of the public procurement process.

Confidential and Proprietary Information: Protect confidential and proprietary information and share it with others only when needed. ITS procurement staff members should ensure that recipients of confidential and proprietary information know that they have an obligation to protect it.

Applicable Laws and Procedures: Know and follow the letter and spirit of Mississippi public procurement statutes, as well as the processes, procedures, rules, and guidelines applicable to technology procurement. ITS procurement staff members should develop and maintain an understanding of the statutory requirements for technology procurement for the State of Mississippi. Customers and vendors should seek to understand the basic guidelines and legal constraints inherent to public procurement in Mississippi.

(Source: Principles and Standards of Ethical Supply Management Conduct with Guidelines, Institute for Supply Management, Inc. TM , ©2008. Used by permission.)

ITS Procurement Code of Ethics

Section 1: Background and Purpose

1.1 Section 25-4-101, Mississippi Code of 1972, as amended states, “The legislature declares that elective and public office and employment is a public trust and any effort to realize personal gain through official conduct, other than as provided by law, or as a natural consequence of the employment or position, is a violation of that trust. Therefore, public servants shall endeavor to pursue a course of conduct which will not raise suspicion among the public that they are likely to be engaged in acts that are in violation of this trust and which will not reflect unfavorably upon the state and local governments.”

1.2 ITS expects and promotes full compliance with the statutory directives in Mississippi Code Sections 25-4-101 through 25-4-119, by all ITS staff members, ITS customers, and members of the vendor community who do business with ITS. This Code of Ethics and associated Code of Conduct are provided as a reminder to each of these groups of the high ethical standards to which they and their actions are held by the members of the public; the legislative, executive, and judicial branches of Mississippi government; and the executive management and board of ITS. This policy is intended to be applied in conjunction with and shall not be considered as superseding any laws or regulations administered and enforced by the Mississippi Ethics Commission.

150

Section 2: Expectations of ITS Procurement Staff

2.1 ITS considers public employment to be a public trust and expects each ITS employee, including but not limited to those involved in the procurement process, to exhibit the highest standards of honesty, integrity, impartiality, courtesy and ethical conduct in all actions and decisions.

2.2 ITS procurement staff will work professionally, cooperatively, and respectfully with ITS customers and with prospective and incumbent vendors.

2.3 ITS procurement staff will manage procurements fairly and in a transparent manner, adhering to all statutes, policies, and rules.

2.4 ITS management will promote and foster the highest standards of professional competence and knowledge for all personnel involved in the procurement process.

2.5 ITS procurement staff will seek to work as efficiently as possible while producing a quality product that meets the objectives of the State of Mississippi, minimizing delays and costs for both vendors and customers.

2.6 ITS procurement staff will work with the customer and, if applicable, the vendor community, to develop responsible and realistic project schedules and then to ensure commitments are fulfilled in a timely manner to meet published procurement schedules.

2.7 ITS procurement staff will protect confidential and proprietary information throughout the procurement process.

2.8 ITS procurement staff will not solicit or accept gifts, gratuities, loans, offers of employment, or anything else of monetary value from a vendor.

2.9 ITS procurement staff will identify any procurement situation which creates a potential conflict of interest or appearance of such conflict for the staff member. ITS management will take measures to appropriately mitigate the conflict. Conflict of interest is defined as any personal interest, directly or indirectly, through business, family, friend, or other associations, that may influence or may reasonably appear to others to influence a person’s judgment and impartiality, in any matter relevant to that person’s duties.

Section 3: Expectations of ITS Customers

3.1 ITS expects customers, as public servants, to exhibit the highest standards of integrity and ethical conduct in all aspects of the procurement process.

3.2 ITS expects customer staff to work professionally, cooperatively, and respectfully with ITS and with vendors.

151

3.3 ITS expects customers to be fully open and forthcoming with all information related to an acquisition, including but not limited to customer executive’s objectives, direction and support; budget and funding; business and technical issues and objectives; vendor contacts; and all other influences, drivers, expectations, schedules, and other potential influences on the procurement process or outcome.

3.4 ITS expects customer entities to provide requested information in a complete and accurate form and in a timely manner.

3.5 ITS expects customers to maintain the confidentiality of information acquired during the procurement process as appropriate.

3.6 ITS expects customers to accurately represent their true business requirements and to work with ITS to ensure specifications are open and competitive (unless valid justification is presented and approved by ITS).

3.7 ITS expects customers to uphold the public trust by procuring solutions that meet their business needs without paying for features that exceed the procuring entity’s true requirements.

3.8 ITS expects customers to initiate only procurements the customer has a clear intent to award.

3.9 ITS expects customers to responsibly and proactively manage vendors and project contracts to ensure all provisions are upheld and to protect the interests of the State.

3.10 ITS expects customers to identify any situation with a potential conflict of interest or appearance of such conflict related to the procurement process. Conflict of interest is defined as any personal interest, directly or indirectly, through business, family, friend, or other associations, that may influence or may reasonably appear to others to influence a person’s judgment and impartiality, in any matter relevant to that person’s duties.

Section 4: Expectations of Prospective and Incumbent Vendors

4.1 Vendors are expected to promote the highest standards of ethical behavior in all business dealings and in every phase and aspect of the procurement process.

4.2 Vendors are expected to fully respect the need for public sector procurement to be conducted in a structured, consistent, fair, open, and transparent manner.

4.3 Vendor representatives are expected to work professionally, cooperatively, and respectfully with ITS and ITS’ customers, providing information in the form requested and in a timely manner.

4.4 Vendors are expected to raise valid issues or concerns regarding a procurement vehicle or process as soon as they become aware of the issue and to work with the State’s representatives to resolve issues in a constructive manner.

152

4.5 Vendors are expected to present complete and accurate information concerning their experience, products, and capabilities and to propose only solutions they can successfully deliver for the cost and within the timeframe proposed.

4.6 Vendors are expected to read, understand, and comply with ITS’ procurement policies and procedures, as well as all instructions and requirements in the specific procurement vehicle to which the vendor is responding.

4.7 Vendors are expected to negotiate project contracts in good faith and to uphold all commitments made in a project proposal, including but not limited to project timeframes, costs, and staffing, and to ensure projects are resourced and supported to a successful outcome.

4.8 Vendors must not attempt to unduly influence any part of the procurement process or content in a manner that violates generally accepted business ethics.

4.9 Vendors must not work in concert with any competing vendor when preparing a bid or proposal.

4.10 Vendors must not distribute marketing or sales-related information related to an ITS procurement instrument, contract, project, or award without the prior review and written permission of ITS. Vendors who violate this provision, especially if the information distributed is fraudulent or misleading, are subject to disqualification or other penalties.

4.11 Vendors must not offer, give or agree to give a gratuity, gift, or anything of monetary value, including any offer of employment, to anyone involved in the procurement process within one year of the conclusion of the procurement process. ITS will consider any such offer a breach of process, and the offering vendor will be subject to disqualification and other penalties.

Section 5: Expectations for the Procurement Process

5.1 Every procurement overseen by ITS will be conducted in accordance with all applicable statutes and with the policies and procedures of ITS.

5.2 Procurements will be conducted using a competitive process. Exceptions will require substantial and compelling documentation.

5.3 Specifications developed for technology procurements will be open and competitive (unless valid justification is presented and approved by ITS) and will represent the actual business requirements of the customer entity. The process will not favor or exclude qualified vendors other than by criteria that are true requirements of or value to the State.

5.4 The procurement process will be transparent, with appropriate information shared with stakeholders in a timely manner.

153

5.5 The selection in a procurement process will be based on the best combination of cost and value to the State and will be determined based on the criteria defined in the underlying procurement vehicle.

5.6 All potential vendors will be treated fairly and equitably and will have equal access to information throughout the procurement process.

5.7 Contractual terms will be clear and fair, taking into account the interests of the vendor while protecting the substantial interests of the State.

5.8 The procurement process will offer and encourage opportunities for both successful and unsuccessful candidate vendors to receive feedback that is specific and relevant to the vendor’s offering and the procurement process, with the objective of improving future offerings by that vendor and of incorporating applicable vendor feedback into the procurement process.

Source: Sections 25-4-101 through 25-4-119

ITS Procurement Code of Conduct

Section 1: ITS Statutory Responsibilities and Charge

1.1 ITS is dedicated to providing the best possible service to government customers. ITS strives to balance the following aspects of our role in government: • The need to develop strong partnerships with vendors who provide IT hardware, software, and services to government • The need to deliver quality IT hardware, software, and services for the lowest possible cost to the State as a whole • The requirement to manage open and competitive procurement efforts for IT hardware, software, and services.

1.2 ITS employees conduct themselves in a manner to instill public confidence in the integrity of state government employees. It is impossible to anticipate every example of ethics decisions that may be presented to ITS employees. It is the responsibility of the employee to exercise good judgment and to be sensitive to any possible appearance of impropriety when conducting business with customers and vendors.

1.3 ITS employees are encouraged to err on the side of excess diligence regarding any business situation to avoid even the appearance of a violation of the public trust.

154

Section 2: Gifts and Gratuities

2.1 ITS recognizes there is a cost for vendors to provide IT hardware, software, and services to government. ITS also recognizes that as the cost for a vendor to do business increases, the cost for government to do business increases. ITS employees strive to lower the cost of doing business wherever possible.

2.2 Acceptance of anything of tangible value from a vendor contributes to the vendor’s expenses and unnecessarily presents an opportunity for misinterpretation of the relationship between the vendor and the employee. Therefore, ITS procurement staff members do not accept any offer of a product, service, or favor of tangible value from a vendor.

2.3 ITS procurement staff members refuse gifts and gratuities, including but not limited to, money, credit, loans, discounts not generally available, and entertainment. Some examples of unacceptable gifts and offerings are listed below: • Free tickets to the theater, sports events, or other entertainment venues. • Paid travel costs or accommodations. • Gift cards or gift certificates.

2.4 ITS procurement staff members do not accept offers of employment from any awarded vendor within one year of the conclusion of a procurement process in which that vendor and staff member mutually participated.

2.5 ITS procurement staff members do not solicit anything from vendors for any reason. Examples include, but are not limited to: • Purchases by vendors from side businesses in which the staff member is involved • Donations by vendors for charitable and/or civic events or organizations in which the ITS employee and/or his/her immediate family is involved • Purchases by vendors from fund raisers in which ITS employees and/or their families are involved

2.6 ITS procurement staff may accept items of nominal value offered by suppliers to a substantial number of their customers for public relations purposes when there could be no perception of monetary value, inappropriate influence, or other ethical breach. Examples might include a t-shirt, pen, notepad, or other inexpensive trinket.

2.7 ITS procurement staff members may sometimes be required to conduct business during meals or to participate in modest hospitality as a courtesy in a business relationship. Staff members will avoid frequent meals with the same vendor and avoid any situation in which he/she might be perceived to have been influenced as a result of accepting or participating in a particular vendor’s hospitality. However, any and all vendor contacts with ITS procurement staff and ITS customer staff must be discontinued during any active procurement process in which the vendor is a potential proposer for the customer’s project and/or the ITS procurement staff member is involved in the procurement project.

155

2.8 ITS procurement staff may participate in lunch-and-learn and similar meetings sponsored by vendors.

2.9 ITS procurement staff members may participate in raffles or drawings held by vendors in public forums but will not encourage or initiate a vendor raffle.

Section 3: Confidential Information

3.1 The assigned ITS project manager is responsible for ensuring that all ITS and customer employees involved in the procurement process execute the appropriate confidentiality agreements in a timely manner and that these agreements are maintained in the project file.

3.2 The assigned ITS project manager is responsible for protecting and controlling the distribution of all proprietary or confidential materials throughout the procurement process, including physical security of printed documents, security of electronic documents, and accounting for all copies of the same.

3.3 The assigned ITS project manager is responsible for instructing each team member regarding the need to protect and secure proprietary and confidential information.

3.4 The assigned ITS project manager is responsible for ensuring any external requests for project information are directed to and processed by the ITS Public Records Officer in accordance with the ITS Public Records Policy.

Section 4: Conflict of Interest

4.1 ITS procurement staff members strive to collectively and individually maintain an open and competitive environment for awarding and conducting government business. An ITS procurement staff member with a perceived or actual conflict of interest in a certain procurement effort will make a formal declaration of disqualification and promptly withdraw from further participation in the procurement.

4.2 ITS procurement staff members avoid engaging in personal business with a vendor who provides IT hardware, software, or services to government in Mississippi.

4.3 ITS procurement staff members do not lend money to or borrow money from any vendor.

4.4 ITS procurement staff members avoid outside employment or other activities that might create demands incompatible with their procurement assignments, cast doubt on their ability to perform these assignments objectively, or otherwise create a conflict of interest.

4.5 Conflicts of interest for members of the procurement staff include but are not limited to:

156

• The ITS procurement staff member or any member of that person’s immediate family has a financial interest pertaining to the procurement and/or an association with any potential vendors • A business or organization with which the ITS procurement staff member or any member of that person’s immediate family is associated has a financial interest pertaining to the procurement and/or is a potential vendor • Any other person, business, or organization with whom the ITS procurement staff member or any member of that person’s immediate family is negotiating or has an arrangement concerning prospective employment is involved in the procurement Source: Sections 25-4-101 through 25-4-119

157

Part 2 Chapter 10: Procurement Policies Rule 210.2: 019-010 ITS Public Records Policy and Procedures Public Records Policy

Public Records Procedures

Public Records Request Form

ITS Public Records Policy

  1. Statutory Authority and Purpose (a) Introduction The Mississippi Department of Information Technology Services (ITS) is the state agency created by Section 25-53-1 et seq., Mississippi Code of 1972, to maximize the use and benefit of information technology by promoting full cooperation, coordination, cohesive planning, and maximum compatibility of technology among all state agencies and institutions of higher learning. ITS' central office is located at 3771 Eastwood Drive, Jackson, Mississippi 39211. These public records procedures are promulgated by ITS in compliance with the Mississippi Public Records Act of 1983, Mississippi Code Section 25-61-1, et seq. “It is the policy of the Legislature that public records must be available for inspection by any person unless otherwise provided by this act. Furthermore, providing access to public records is a duty of each public body and automation of public records must not erode the right of access to those records.” Section 25-61-1, Miss. Code of 1972. “[A]ll public records are hereby declared to be public property, and any person shall have the right to inspect, copy or mechanically reproduce or obtain a reproduction of any public record of a public body in accordance with reasonable written procedures adopted by the public body concerning the cost, time, place and method of access, and public notice of the procedures shall be given by the public body.” Section 25-61-5, Miss. Code of 1972. The act defines "public record" to include "all books, records, papers, accounts, letters, maps, photographs, films, cards, tapes, recordings or reproductions thereof, and any other documentary materials, regardless of physical form or characteristics, having been used, being in use, or prepared, possessed or retained for use in the conduct, transaction or performance of any business, transaction, work, duty or function of any public body, or required to be maintained by any public body.” Section 25-61-3(b), Miss. Code of 1972. The purpose of these rules is to establish the guidelines and procedures ITS will follow in order to provide full access to public records. These rules provide information to persons wishing to request access to public records of ITS and establish processes for both requestors and ITS staff that are designed to best assist members of the public in obtaining such access.

158

The purpose of the act is to provide the public full access to information concerning the conduct of government, mindful of individuals' privacy rights and the desirability of the efficient administration of government. Because the purpose of the act is to allow people to be informed about governmental decisions (and therefore help keep government accountable) while at the same time recognizing certain exemptions, it should not be used to obtain records containing purely personal information that has no bearing on the conduct of government. The act and these rules will be interpreted in favor of disclosure. In carrying out its responsibilities under the act, ITS will be guided by the provisions of the act describing its purposes and interpretation. (b) Definitions (i) "Custom Request" means any public records request for information other than what is contained in the list of Standard Documents as specified in the ITS Public Records Request Procedures Attachment to this document. (ii) "Exempt Record" means a record held by a public body that may contain information that impacts the rights of others and has been excluded from disclosure under the Mississippi Public Records Act. (iii)"Initial Fee" means the evaluation and research payment in the amount specified in the ITS Public Records Request Procedures Attachment to this document. This fee is due with the submission of Public Records Requests for Custom Requests and is applied toward the actual cost of filling the Public Records Request. (iv) "Standard Document" means any public record listed in the ITS Public Records Request Procedures Attachment to this document and available for immediate release at either no cost or a fixed charge. (v) "Standard Document Fee" means the fixed cost for a particular Standard Document, as shown in the ITS Public Records Request Procedures Attachment to this document. (vi) "Working Days" means Monday through Friday but excludes State recognized holidays mandated by Mississippi Code Annotated, Section 3-3-7 (1972), other holidays identified in holiday proclamations published or distributed by the Mississippi Secretary of State, and any other day the offices of state agencies are officially closed for business. 2. ITS Public Records Officer and Contact Information (a) Any person wishing to request access to public records of ITS, or seeking assistance in making such a request should contact the Public Records Officer of ITS in one of two ways – via the Public Records On-Line Application or in writing to: Public Records Officer Mississippi Department of Information Technology Services 3771 Eastwood Drive, Jackson, MS 39211 Phone: 601-432-8000 Fax: 601-713-6380 Email: open.records@its.ms.gov

159

Information is also available at the ITS website. (b) The ITS Public Records Officer will oversee compliance with the act but other ITS staff members may process the request. Therefore, these rules will refer to the Public Records Officer "or designee." The Public Records Officer or designee and ITS will provide the "fullest assistance" to requestors; ensure that public records are protected from damage or disorganization; and prevent the fulfilling of public records requests from causing excessive interference with essential functions of ITS. All references in this policy to "Public Records Officer" should be construed as "Public Records Officer or designee." 3. Availability of public records (a) Records available through ITS website. Many public records maintained by ITS are available for access and/or download at no charge via the ITS website. Requestors are encouraged to view the documents available on the website prior to submitting a public records request. Requestors without access to the internet may request to use a computer at the ITS offices for this purpose. (b) Hours for inspection of records: With prior written notice to the Public Records Officer, public records are available for inspection and copying during normal business hours of ITS, Monday through Friday, 8:00 a.m. to 5:00 p.m., excluding state holidays. Records must be inspected at the offices of ITS with an ITS employee present. (c) Organization of records: ITS will maintain its records in a reasonably organized manner. ITS will take reasonable actions to protect records from damage and disorganization. A requestor shall not take ITS records from ITS offices. (d) Making a request for public records (i) Any person wishing to inspect or copy any public records maintained by ITS, or to request copies of such information from ITS, should make the request via the Public Records On-Line Application, in writing using the ITS Public Records Request Form, or by letter addressed to the ITS Public Records Officer and include the following information: • Name of requestor • Address of requestor • Other contact information, including telephone number and e-mail address • Identification of the public records adequate for the Public Records Officer to locate the records • The date of the request • A certified or corporate check for the appropriate amount, as specified in the ITS Public Records Request Procedures Attachment to this document

(ii) If the requestor wishes to have copies of the records made instead of simply inspecting them, he or she should so indicate and make arrangements to pay for copies of the records at the time they are copied. Standard photocopies will be provided at the per page cost specified in the ITS Public Records Request Procedures Attachment to this document.

160

(iii) A Public Records Request Form is available for use by requestors at the office of the Public Records Officer. Word and pdf versions of this document are attached to this policy. Because an Initial Payment must accompany the request, verbal, telephone, email, and fax requests cannot be accepted. (iv) Public Records On-Line Application – The on-line application allows requestors to make requests and payments electronically through a secure payment processor. (e) Obligations of ITS (i) ITS has a duty to promptly provide access to all nonexempt public records. ITS will treat all requestors similarly, regardless of the purpose of the request or the identity of the requestor. (ii) Public records used or created by ITS will be retained according to retention schedules approved by the Mississippi Department of Archives and History. These schedules are specific to ITS and to the type and contents of the public record. The destruction of ITS public records is governed by the retention schedules. (iii) ITS will not destroy any public record, even if it is eligible to be lawfully destroyed under a retention schedule, if a public records request has been made for that record. ITS will retain the record until the Public Records Request has been resolved. (iv) ITS will use technology to provide public records in electronic form where possible. (v) ITS will conduct an objectively reasonable search for responsive records. (vi) ITS is not obligated to create a new record to satisfy a public records request. (f) Obligations of Requestor (i) A requestor must request an identifiable record or class of records. An "identifiable records" is one the ITS staff can reasonably locate. The Public Records Act does not allow the requestor to search through ITS files for records that cannot be reasonably identified or described to ITS. (ii) A requestor must be as specific as possible in making the request. Requests using inexact and comprehensive phrases such as "all records relating to" a topic, requests requiring legal research, or requests asking for information rather than records will be clarified or denied by ITS.

161

  1. Processing of Public Records Requests (a) Providing access: ITS acknowledges that “providing access to public records is a duty” and that “any person shall have the right to inspect, copy or mechanically reproduce or obtain a reproduction of any public record” in accordance with these policies (Mississippi Code Sections 25-61-1 and 25-61-5). The Public Records Officer will process requests in the order allowing the most requests to be processed in the most efficient manner. (b) Acknowledging receipt of request: Within seven (7) Working Days of receipt of the request, the Public Records Officer will do one or more of the following: (i) Make the records available for inspection or copying. (ii) If copies are requested and full payment is received in accordance with the ITS Public Records Request Procedures Attachment to this document, send the copies to the requestor. (iii) Acknowledge the receipt of the request and provide a reasonable estimate of the time and cost that will be required to make the records available; for records that do not fall under the provisions of Mississippi Code Section 25-61-9 regarding third party notification requirements, ITS will provide a written explanation if the records cannot be produced within the seven Working Day period. (iv) If the request is unclear or does not sufficiently identify the requested records, request clarification from the requestor. Such clarification may be requested and provided by telephone, with written follow-up. The Public Records Officer may revise the estimate of when records will be available. (v) Deny the request, with documentation to the requestor as to the reason for denial. (c) Consequences of failure to respond: If ITS does not respond in writing within seven (7) Working Days of receipt of the request for disclosure, the requestor should contact the Public Records Officer to determine the reason for the failure to respond. (d) Protecting rights of others: In the event the requested records contain information that may affect rights of others and may be exempt from disclosure, the Public Records Officer will, prior to providing the records, give notice to such others whose rights may be affected by the disclosure ("Third Party Notice"). Such notice will be given so as to make it possible for those other persons to contact the requestor and ask him or her to revise the request, or, if necessary, seek an order from a court to prevent or limit the disclosure. The notice to the affected persons will include a copy of the request. See Section 7 of this policy for additional information on Third Party Information. (e) Denial of Request: ITS may deny or delay a Public Records Request for the following reasons: (i) Records exempt from disclosure: Some records are exempt from disclosure, in whole or in part. If ITS believes that a record is exempt from disclosure and should be withheld,

162

the Public Records Officer will state the specific exemption and provide a brief explanation of why the record or a portion of the record is being withheld. If only a portion of a record is exempt from disclosure, but the remainder is not exempt, the Public Records Officer will redact the exempt portions, provide the nonexempt portions, and indicate to the requestor why portions of the record are being redacted. See Section 6 of this policy for additional information on exemptions. (ii) Record does not exist or ITS does not have the record: ITS must only provide access to public records in existence at the time of the request. If a public record is created or comes into the possession of ITS after the request is received by ITS, that record will not be provided. The requestor must make a new request to obtain subsequently created public records. Sometimes more than one public body holds the same record. When more than one public body holds a record and a requestor makes a request to ITS, ITS will provide access to the record it holds regardless of its availability from another public body. (iii) Record is part of ongoing negotiations: If the record(s) is part of ongoing negotiations related to a request for competitive sealed proposals, production of the record(s) shall not be made until after the notice of intent to award is issued. Such production shall be made within seven (7) days such notice to award is issued. (f) Inspection of records (i) Consistent with other demands and with prior written notice by the requestor to the Public Records Officer, ITS shall promptly provide space to inspect nonexempt public records with an ITS employee present. No member of the public may remove a document from the viewing area or disassemble or alter any document. The requestor shall indicate which documents he or she wishes ITS to copy and must provide payment for copies at the time copies are made. (ii) The requestor must claim or review the assembled records within ten (10) Working Days of ITS' notification to him or her that the records are available for inspection or copying. ITS will notify the requestor in writing of this requirement and inform the requestor that he or she should contact ITS to make arrangements to claim or review the records. If the requestor or a representative of the requestor fails to claim or review the records within the ten (10) Working Day period or make other arrangements, ITS may close the request and refile the assembled records. Other public records requests can be processed ahead of a subsequent request by the same person for the same or almost identical records, which can be processed as a new request. (iii) Providing copies of records: After inspection is complete, the Public Records Officer shall make the requested copies or arrange for copying. The requestor must provide payment for copies at the time copies are made. Alternately, the requestor may ask that ITS provide the requested information directly to the requestor, in printed or electronic form, without prior inspection of the information by the requestor. (iv) Providing records in installments: When the request is for a large number of records, the Public Records Officer will provide access for inspection and/or copying in

163

installments, if he or she reasonably determines that it would be practical to provide the records in that way. If, within ten (10) Working Days, the requestor fails to inspect the entire set of records or one or more of the installments or fails to make payment as required, the Public Records Officer may stop searching for the remaining records and close the request. (v) Completion of inspection: When the inspection of the requested records is complete and/or all requested copies are provided to the requestor, the Public Records Officer will indicate that ITS has completed a diligent search for the requested records and made any located nonexempt records available for inspection. (vi) Closing withdrawn or abandoned request: When the requestor either withdraws the request or fails to fulfill his or her obligations to inspect the records or to make payment as required, the Public Records Officer will close the request and indicate to the requestor that ITS has closed the request. (vii) Later discovered documents: If, after ITS has informed the requestor that it has provided all available records, ITS becomes aware of additional responsive documents existing at the time of the request, it will promptly inform the requestor of the additional documents and provide them on an expedited basis. 5. Processing of public records requests: Electronic records (a) Requesting electronic records: The process for requesting electronic public records is the same as for requesting paper public records (Section 4 of this policy, Processing of Public Records Requests). (b) Providing electronic records: When a requestor requests records in an electronic format, the Public Records Officer will provide the nonexempt records or portions of such records that are reasonably locatable in an electronic format that is used by ITS and is generally commercially available, or in a format that is reasonably translatable from the format in which ITS keeps the record. Costs for providing electronic records are governed by the ITS Public Records Request Procedures Attachment to this document. ITS will produce records that can be located based on a description provided by the requestor, using standard search features in ITS' current software. (c) Customized access to databases: With the consent of the requestor, ITS may provide customized access if the record is not reasonably locatable or not reasonably translatable into the format requested. ITS may charge the actual cost for such customized access. 6. Exemptions (a) The Mississippi Public Records Act, as well as other statues and court decisions, provides that a number of types of documents are exempt from public inspection and copying. In addition, other statutes or rules of law, such as various privacy restrictions, may prohibit disclosure. Requestors should be aware of the following exemptions, outside the Public Records Act, that restrict the availability of some documents held by ITS for inspection and copying. This list is provided for informational purposes only and may not be all-inclusive:

164

• Academic records exempt from public access, see § 37-11-51 • Appraisal records exempt from access, see § 31-1-27 • Archaeological records exempt from public access, see § 39-7-41 • Attorney work product, examination, exemption, see § 25-1-102 • Birth Defects Registry, see § 41-21-205 • Bureau of vital statistics, access to records, see § 41-57-2 • Charitable organizations, registration information, exemption from public access, see § 79- 11-527 • Concealed pistols or revolvers, licenses to carry, records, exemption, see § 45-9-101 • Confidentiality, ambulatory surgical facilities, see § 41-75-19 • Defendants likely to flee or physically harm themselves or others, see § 41- 32-7 • Environmental self-evaluation reports, public records act, exemption, see § 49-2-71 • Hospital records, Mississippi Public Records Act exemption, see § 41-9-68 • Individual tax records in possession of public body, exemption from public access requirements, see § 27-3-77 • Insurance and insurance companies, risk based capital level requirements, reports, see § 83-5-415 • Judicial records, public access, exemption, see § 9-1-38 • Jury records exempt from public records provisions, see § 13-5-97 • Licensure application and examination records, exemption from Public Records Act, see § 73-52-1 • Medical examiner, records and reports, see § 41-61-63 • Personnel files exempt from examination, see § 25-1-100 • Public records and trade secrets, proprietary commercial and financial information, exemption from public access, see § 79-23-1 • Workers' compensation, access to records, see § 71-3-66

(b) ITS will describe why each withheld record or redacted portion of a record is exempt from disclosure.

  1. Third Party Information

(a) Documents submitted to ITS by commercial entities in conjunction with the procurement process and with enterprise technology initiatives often contain trade secrets or confidential commercial or financial information subject to the protection of the Public Records Act (Mississippi Code Section 25-61-9). Upon request to inspect or copy any third-party document, ITS shall notify the person who filed the document ("Third Party"). Twenty-one (21) days after such notice, the document will be made available for public inspection and/or copying unless the Third Party shall have filed in Chancery Court a petition seeking a protective order on or before the expiration of the twenty-one day time period. Any party seeking a protective order for a procurement contract awarded by ITS shall give notice to and provide the reasons for the protective order to the party requesting the information in accordance with the Mississippi Rules of Civil Procedure. The Third Party must also provide notice to ITS at least 14 days prior to the time of filing. ITS must post the notice and reasons for the protective order on the Mississippi procurement portal for a minimum of seven (7) days before the Party may file the petition seeking the protective

165

order in Chancery Court. Any party seeking a protective order in violation of this subsection may be barred by a state agency from submitting bids, proposals or qualifications for procurement for a period not to exceed five (5) years. (Mississippi Code Section 25-61-9(7)) (b) The Third Party must prove to the court's satisfaction that the record or portion of the record is exempt from disclosure and must deliver the court order preventing the release of all or part of the information to ITS prior to the deadline to prevent disclosure of the information. The Third Party must name the requestor as a party to any action to enjoin disclosure. (c) ITS will not make a determination as to whether a requested record provided by a Third Party contains trade secrets or confidential commercial or financial information. ITS will provide Third Party Notice as outlined above and allow the court to determine if a protective order should be issued. (d) Documents are frequently produced by ITS that contain specific information obtained directly from a Third Party and, as such, may be subject to Third Party Notice as described above. Examples include, but are not limited to, detailed proposal evaluation documentation; line-item pricing spreadsheets; and some contracts and/or contract exhibits containing proprietary vendor information and marked "confidential." Contracts executed prior to November 26, 2007 are subject to Third Party Notice; exhibits in contracts executed between November 27, 2007 and June 30, 2015, that are marked “confidential” will be subject to Third Party Notice; contracts executed on or after July 1, 2015 are not subject to Third Party Notice. From the Spring of 2010 forward, executed contracts are available via the state’s Transparency website, located at http://www.transparency.ms.gov/contracts/contracts.aspx. In no event, however, will ITS be obligated to provide Third Party Notice prior to the release of ITS-generated documents containing summary-level information or other information as may be required to be made public record as part of the fulfillment of ITS' statutory mission. (e) All ITS employees are Confidentiality Officers, as defined in Section 25-53-51 of Mississippi Code, and have been duly sworn in accordance with the oath contained therein. Information and data owned by another agency or institution and residing at ITS must not be disclosed by ITS employees, as mandated in the oath taken as Confidentiality Officers. Requests for such data must be made to the originating agency or institution. 8. Costs of providing public records (a) Costs for fulfilling a request: Section 25-61-7(1), Miss. Code of 1972, reads in part as follows: “Except as provided in subsection (2) of this section, each public body may establish and collect fees reasonably calculated to reimburse it for, and in no case to exceed, the actual cost of searching, reviewing and/or duplicating and, if applicable, mailing copies of public records.” Billing rates are established in compliance with federal cost allocation guidelines. The current range of billing rates for ITS staff is shown in the ITS Public Records Request Procedures Attachment to this document. ITS commits to providing standard information on the ITS website at no cost to the requestor and to fulfilling Custom Requests as expeditiously and efficiently as possible. ITS will provide a cost estimate to the requestor prior to the requestor's incurring any charges above those of the initial research fee discussed below.

166

(b) Initial Evaluation and Research Fee: ITS charges an initial fee, in the amount specified in the ITS Public Records Request Procedures Attachment to this document, for every customized public records request. This fee covers the cost of coordinating with the applicable project team to ascertain documents that are available within the scope of the request; reviewing the requested records; determining based on the content of the records whether Third Party Notification must be provided; providing required notifications; and developing a cost estimate and timetable for fulfilling the request. A Custom Public Records Request cannot be processed until this initial fee is received. The initial fee is non-refundable. (c) Charges for staff services: The actual cost of searching for and reviewing the information, providing Third Party Notice if required, copying or scanning, redacting exempt information from public records, and other services required to fulfill the Custom Request, shall be based upon the applicable hourly rate, as described in 8.a. above, which shall be multiplied by the actual time to complete the tasks. If a request requires legal analysis and advice to determine possible exemptions, ITS will include the actual cost of the attorney's time in the cost of fulfilling the request. (d) Costs for paper copies: A requestor may obtain standard black and white photocopies for the amount specified in the ITS Public Records Request Procedures Attachment to this document. Before copies can be made and/or provided to the requestor, the requestor must pre-pay all reasonably estimated costs of copying all the records selected by the requestor. ITS will not charge sales tax when it makes copies of public records. (e) Costs for electronic records: The cost of electronic copies of records and/or scanned copies of non-electronic records shall be the amount specified as the media cost for a CD in the ITS Public Records Request Procedures Attachment to this document. The cost of the scanning process will be calculated at the hourly service rate. There will be no charge for e-mailing electronic records to a requestor, unless another cost applies, such as research and scanning fees. (f) Costs of mailing: ITS will charge actual costs of mailing, including the cost of the shipping container. (g) Payment: Payment may be in the form of an electronic payment via the Public Records On- Line Application, a certified check, money order, or corporate check made payable to ITS for the amount specified. No cash or personal checks can be accepted. 9. Review of denials of public records (a) Petition for internal administrative review of denial of access: Any person who objects to the initial denial or partial denial of a records request may petition in writing (including e-mail) to the Public Records Officer for a review of that decision. The petition must include a copy of or reasonably identify the written statement by the Public Records Officer or designee denying the request. (b) Consideration of petition for review: The Public Records Officer must promptly provide the petition and any other relevant information to the ITS Executive Director. That person will immediately consider the petition and either affirm or reverse the denial within two (2) Working

167

Days following ITS' receipt of the petition, or within such other time as ITS and the requestor mutually agree to. (c) Review by the Ethics Commission: Pursuant to Section 25-61-13, Miss. Code of 1972, if ITS denies a requestor access to public records, the requestor may ask the Ethics Commission to review the matter. The Ethics Commission has adopted rules on such requests. They may be found at http://www.ethics.state.ms.us/ethics/ethics.nsf. (d) Judicial review: Any person whose request for public records was denied may institute a suit in the Chancery Court of Hinds County, seeking to reverse the denial, as set forth in Section 25- 61-13, Miss. Code of 1972.

168

Attachment: ITS Public Records Request Procedures

NOTE: Refer to "ITS Public Records Policy" above for the rules and guidelines under which these procedures were developed and are administered.

STEP 1a: Requestor submits a written request for the information and includes payment:

  1. Use the ITS Public Records Request Form [attached below] or your own format.
  2. Include the information requested on the ITS Public Records Request form: Name of

requestor; address of requestor; other contact information, including telephone number and

e-mail address; identification of the public records adequate for the Public Records Officer

to locate the records; and date of the request;

c. Address the request to: ITS Public Records Officer, Mississippi Department of

Information Technology Services, 3771 Eastwood Drive, Jackson, MS 39211.

d. For documents listed on the attached Schedule of Fees under "Standard Documents," each

request must be accompanied by payment in the amount specified on the payment schedule.

e. For any Custom Request (i.e. any request for information not included in the list of

Standard Documents), the request must be accompanied by payment in the amount of $70

to cover the first hour of staff time involved in evaluation and research of the request. This

payment is non-refundable and is applied toward the total actual cost of filling the Public

Records Request.

f. Payment must be in the form of a certified check, money order, or corporate check made

payable to ITS for the amount specified. No cash or personal checks can be accepted.

g. Note that, because payment must be submitted with the request, no verbal, telephone,

email, or fax requests can be accepted for either standard documents or custom requests.

h. Requests not accompanied by payment in the amount specified for Standard Documents or

in the amount of $70 for Custom Requests will be closed within ten (10) Working Days of

the date of notification to the requestor, if payment is not received.

i. Frequently requested information, including current Express Products Lists, current and

recent RFPs, procurement status and award information, the Procurement Handbook, and

vendor information on how to do business with the State, is available free of charge on the

ITS website. Refer to “Vendor Information” within the “PROCUREMENT” tab.

Requestors are urged to review the website prior to submitting a request. For assistance in

locating information on the website, call the Procurement Help Desk, (601) 432-8166.

STEP 1b: Requestor submits an on-line request for the information via the Public Records On-Line Application (including payment) at the link below.

https://www.ms.gov/its/public_record_request

STEP 2: ITS evaluates and researches the request:

a. The ITS Public Records Officer determines whether the request is for a Standard Document or is a Custom Request. For Standard Documents, skip to Step 3.

169

b. For Custom Requests, the ITS Public Records Officer evaluates the request; coordinates with the ITS project manager for the applicable project to ensure all relevant information is reviewed; researches the project file and other sources to see what information is available and in what format the information is stored; and estimates the effort that will be required to reproduce the information. This research may require the retrieval of files that have been archived or the search of electronic records. c. The ITS Public Records Officer prepares a schedule and estimated cost for the Public Records Request, based upon the volume of information, the format in which the information is stored, and whether Third Party information has been requested. The Initial Payment covers the first hour of ITS staff time involved in researching the request, retrieving files, preparing the estimate, and providing Third Party Notice. The Initial Payment is non-refundable if the requestor decides not to proceed with the request after receiving the schedule and estimated cost.

STEP 3: ITS provides Requested Documents or Feedback to Requestor:

a. For a request for Standard Documents accompanied by the appropriate payment, ITS will provide the requested Standard Document within seven (7) Working Days of ITS’ receipt of the request. b. For a Custom Request not accompanied by the appropriate initial payment as described above, ITS will notify the requestor and request payment before proceeding. c. For a Custom Request that does NOT require Third Party notice: • If the request is accompanied by the appropriate initial payment and the initial payment covers the full cost of producing the records, ITS will furnish the records to the requestor within seven (7) Working Days of receipt of the request. If ITS cannot produce the records within seven (7) Working Days of ITS’ receipt of the request, ITS will provide a written explanation for the delay. • If the initial payment does not cover the cost of producing the records, ITS will furnish the requestor an acknowledgement of receipt of the request, with the cost and schedule for providing the requested information. When payment in the amount of the remaining balance is received from the requestor, ITS will provide the requested information according to the schedule provided. ITS will provide a written explanation if the records cannot be produced within seven (7) Working Days of receipt of payment. d. For a Custom Request requiring Third Party notification, ITS will furnish the requestor an acknowledgement of receipt of the request and a copy of the Third Party Notice (under separate cover). The cost and schedule for providing the information will be provided to the requestor once the deadline has passed for the Third Party to obtain a court order and ITS knows what portion of the material can be released. See additional information in Step 4 below. e. ITS staff will make a good faith effort to provide the requested information within seven (7) Working Days of receipt of a request. Note, however, that if Third Party Information is requested, ITS is required to notify the Third Party and to provide this party the opportunity to protect any confidential information. ITS cannot accept payment for the

170

balance of the request until the deadline for obtaining a court order to block release of Third Party Information has passed. (See discussion of Third Party Information in Step 4 below).

STEP 4: ITS provides Third Party Notice as needed:

a. All information and documents produced or received by ITS, including those associated with competitive procurements, may be requested by any business or individual under the ITS Public Records Policy in accordance with these Public Records Procedures. Proposals and information extracted directly from proposals during the evaluation process, as well as certain other documents prepared by vendors and submitted to ITS, will be considered Third Party information and will not be released until notice has been given to the party submitting the information, as described below. b. When ITS receives a request to release information provided by a Third Party, which may contain trade secrets or confidential commercial or financial information, the owner of this information is notified of the name and address of the party requesting the information and provided a copy of the request. c. The owner of the information ("Third Party") is given ten (10) Working Days to obtain a court order protecting the information, or portions of the information, as confidential. d. If the owner of the information seeks a court order, the party seeking the court order must name the requestor as a party to any action to enjoin disclosure. e. If a court order is delivered to ITS by the deadline protecting all requested information, ITS will notify the requestor that the information is protected and cannot be furnished. If the Third Party is unable to obtain a final protective order by the deadline, ITS will accept a copy of the filed petition for a protective order in lieu of the final order, providing the petition was filed timely upon Third Party’s receipt of notification from ITS regarding the request for information and providing the final order is furnished to ITS as soon as the court acts on the request. f. If no court order is received by the deadline, or if portions of the requested information are excluded from the court order, ITS will send the requestor an invoice with the cost and schedule for providing any unprotected information. ITS will release the unprotected information to the requestor as soon as payment has been received from the requestor.

STEP 5: Requestor submits payment of remaining balance for Custom Requests:

a. For a Custom Request, ITS will have provided the requestor, as outlined in Steps 2 through 4 above, cost and schedule information for producing and delivering the records requested. Such costs include, but are not limited to, staff time to evaluate and research the request, retrieve any relevant files, organize the information, notify any Third Parties, and produce the information in final form for delivery. The Initial Fee is deducted from the total estimated cost for a net balance due, if any. b. Requestor remits payment for the remaining balance, if any. Payment must be in the form of a certified check, money order, or corporate check made payable to ITS for the amount specified. No cash or personal checks can be accepted.

STEP 6: ITS provides the information for Custom Requests to the requestor:

171

a. ITS sends the requested information via U.S. mail, unless the requestor has specified another form of delivery. b. ITS provides the requested information in pdf format on CD-ROM, unless another format has been specified by the requestor. c. Once the information has been provided, ITS closes the request.

SUGGESTIONS FOR MINIMIZING COSTS FOR PUBLIC RECORDS REQUESTS:

  1. Make the request as specific as possible. The less defined and/or more inclusive the scope of the Public Records Request, the more documents and files that have to be searched and evaluated by the ITS staff. For example, wording in requests asking for "all records, papers, documents, messages, correspondence, notes, etc. related to this or similar projects" is extremely open-ended and requires staff to interpret what time-frame, sources of information, and project files are reasonable to research and evaluate. The wider the "net," the greater the effort required, and, thus, the greater the cost to the requestor.
  2. Provide information and payment timely. Sometimes the requestor will submit a written Public Records Request and then not respond with payment during the required time frame once the schedule and estimate are provided. If the requestor later decides to proceed with the request, ITS staff must again locate the information and develop a new schedule and cost estimate. The requestor must submit a new request with the $70 initial payment.
  3. Request information as soon as possible after ITS creates or receives the information. Project files are archived off-site after a reasonable time period. Requests for information on projects for which a contract has been signed for several months are typically more expensive to respond to than requests for information on projects that have been recently awarded.

172

Schedule of Fees Standard Documents: Vendor information packet No Charge Paper copy of an Express Products List (EPL) where applicable $25 EPL Marketing Report $25 Paper copy of ITS master mailing list in mailing label format: Includes IT directors, agency heads, and purchasing agents of state agencies, public universities, and community colleges No Charge Printed Copy of RFPs $25, plus actual cost of reproducing any oversized diagrams or other special attachments Copy of RFPs on CD in Microsoft Word format $25 for Word document; any oversized diagrams or other special attachments will be reproduced on paper or electronically at actual cost ITS Monthly Board Meeting Packet No Charge Paper copy of Procurement Handbook $50 Custom Requests and Variable Costs: Evaluation & research payment ("Initial Fee"): Due with the submission of Public Records Requests for Custom Requests and is applied toward the actual cost of filling the Public Records Request $70 Fees for fulfilling Custom Requests, based on the expense categories below: Quoted individually upon receipt of written request and $70 evaluation and research payment (above). In-house standard black & white photocopies $0.15 per page (paper/copier fee) CD (with .doc, .xls, or .pdf files of requested information) $5.00 per CD (media fee) Postage, UPS, Federal Express 1 Actual cost Staff time Actual staff time required to provide all services to fulfill the Public Records Request, including but not limited to researching; providing notifications; and compiling, copying, scanning, and delivering requested information, at staff members’ hourly rates ($70 - $80 per hour) Computer processing Actual Cost Temporary agency personnel 1,2 Actual Cost Reproduction cost by outside print facility 1 Actual Cost 1 ITS may request that payments for outside services be made by the requestor directly to the company providing the services. 2 ITS reserves the right to use temporary personnel and services, the cost of which will be passed on to the requestor, if sufficient in-house personnel are not available to respond to the request in a timely manner.

173

PUBLIC RECORDS REQUEST FORM: You may download a PDF version of this form from the ITS website by clicking the following link, Public Records Request Form.pdf

A blank form is shown on the following page.

174

Source: 25-61-1, et seq

175

Part 2 Chapter 10: Procurement Policies Rule 210.3: 019-020 ITS Protest Policy and Procedures A. Purpose of Policy - The policies and procedures set forth herein and issued by the Department of Information Technology Services (hereinafter referred to as "ITS"), establish the guidelines relating to the filing, hearing, decision and appeal of protests by any actual or prospective participant in the procurement process who is aggrieved in connection with the solicitation or award of a contract. B. Definitions - When used in reference to this policy:

  1. "Attorney General" means the individual assigned by the Attorney General of the State of Mississippi to provide legal assistance to ITS.
  2. "Award of Contract" means
    1. approval of the lowest and best proposal by the ITS Executive Director via
    2. written notification to proposers on ITS letterhead or
    ii) published notification of intent to award or iii) the execution of a CP-1 for the project, whichever of (i), (ii) or (iii) occurs first, OR b) the ITS Board's approval of same during an open session of the Board. c) ITS statute specifies whether (a) or (b) is applicable for a given project, depending on the total lifecycle cost of the contract.
  3. "Customer" means the procuring state agency, institution, or governmental entity.
  4. "Disclosure of Information" means the inadvertent or intentional divulgement of information in a vendor's proposal that is clearly marked "confidential" to any individual or group outside the proposal evaluation team, comprised of ITS and Customer staff who participate directly or indirectly in the assessment and scoring of the proposals.
  5. "General RFP" means a Request for Proposal issued by ITS to be used in satisfying routine recurring requests for acquisitions of information technology hardware, software, or services. Each proposal received in response to a General RFP is subject to technical and financial evaluation on a project by project basis, and awards may be made multiple times from each proposal. For procurements using a General RFP with multiple configuration alternatives, a Letter of Configuration is sent to suppliers with valid proposals to obtain the best system configuration and pricing.
  6. "Interested Party" means any party who has documented in writing to the Executive Director of ITS that he/she has a sufficient personal interest in the subject matter of the protest. If the contract has been awarded, as defined herein, the awarded vendor automatically becomes an Interested Party without having to provide this written documentation.
  7. "ITS Board" means the membership of the ITS Board as specified in Section 25-53-7 of the Mississippi Code of 1972.
  8. "Letter of Configuration" or “LOC” means a request to suppliers to provide a cost proposal for a specific configuration of equipment, software, and/or services required by a Customer for a particular project. A Letter of Configuration is sent to all suppliers who have a current valid proposal for the relevant General RFP and who have proposed products and/or services that most closely match the requirements for the specific project.
  9. "Official Release of the RFP" means the date the RFP was posted on the ITS website, "www.its.ms.gov,"or the date the most recent clarification to the RFP was posted on the ITS website, whichever date is later.

176

  1. "Post-Procurement Review" means a business meeting conducted by ITS staff at the request of any participant in the procurement process to exchange information on the procurement process and on the evaluation and scoring of the proposal submitted by the participant requesting the review.
  2. "Proposal Solicitation" means the process of advertising/requesting and receiving vendors' proposals submitted in response to an RFP or Letter of Configuration.
  3. "Protestor" means any actual or prospective participant in the procurement process who is aggrieved in connection with the technology procurement and who files a protest.
  4. "Request for Proposal" or "RFP" means a formal invitation from the State, advertised according to state statute, asking suppliers to submit an offer as a solution to a problem or need that the State has identified.
  5. "State" means ITS and/or the procuring state agency, institution, or governmental entity.
  6. "Working Days" means Monday through Friday but excludes State-recognized holidays mandated by Mississippi Code Annotated, Section 3-3-7 (1972), other holidays identified in holiday proclamations published or distributed by the Mississippi Secretary of State, and any other day the offices of the state agencies are officially closed for business. C. Roles and Responsibilities During Protest
  7. Role of ITS a. ITS' enabling legislation requires that ITS ensure that information technology procurements for state government agencies and institutions follow all applicable state statutes. Therefore, ITS will provide as much guidance in a protest situation as wanted and needed by the Customer. ITS has the responsibility for all decisions related to procurement process and procedures, while all business decisions related to the procurement are the sole responsibility of the Customer. b. The specific responsibilities of ITS during the protest are listed below: i) All correspondence related to the protest will be mailed or delivered by ITS under the signature of either the ITS Executive Director or the chairperson of the ITS Board, whichever is appropriate. ITS will work with the Customer on the content of any correspondence. ITS is responsible for ensuring that all parties to the protest receive copies of any correspondence. ii) ITS will maintain the official protest file, including copies of all documents related to the protest. iii) ITS will work with all parties to schedule any protest conferences or meetings, including distributing official notification of all such conferences or meetings. iv) ITS will hire independent legal counsel at ITS' expense if ITS deems such independent counsel necessary and advisable in a given protest situation. v) ITS will administer, research, and respond to any public records requests received in conjunction with a protest, working with the Customer to locate and organize pertinent information. The individual or company making the public records request is responsible for any costs incurred in filling the request. See 019-010 Public Records Policy and Procedures for additional information. vi) ITS will provide the official record of any conference related to the protest. This record may be either an audio tape, with or without transcription, or a court reporter's record, at the discretion of ITS. ITS will pay any expense incurred to produce this official record in the format selected by ITS.
  8. Role of the Customer

177

a. The Customer will work with ITS to research and organize any project information required for the protest or any associated public records request(s). b. The Customer can hire independent legal counsel at the Customer's expense if the Customer deems such independent counsel necessary and advisable in a given protest situation. c. The Customer is responsible for all costs incurred by the State during the protest other than the ITS internal costs outlined in Item C. above. d. The Customer is responsible for all business decisions associated with the protest and with the underlying procurement. 3. Role of the Protestor a. The Protestor is responsible for responding promptly to any requests for information made by ITS related to the protest. b. The Protestor is responsible for filing all applicable bonds. c. The Protestor is responsible for working with ITS to schedule any conferences and/or meetings related to the protest in a timely manner. d. The Protestor is responsible for adhering to the schedules identified in this policy. e. If the Protestor needs or requires any record of a protest-related conference other than the official record produced at ITS' expense, the Protestor is responsible for producing that record at the Protestor's expense. 4. Role of the Interested Party a. The Interested Party is responsible for responding promptly to any requests for information made by ITS related to the protest. b. If the Interested Party needs or requires any record of a protest-related conference other than the official record produced at ITS' expense, the Interested Party is responsible for producing that record at the Interested Party's expense. D. Right to Protest - Any actual or prospective participant in the procurement process who is aggrieved in connection with the solicitation or Award of a Contract and has posted the applicable protest bond as defined in Item E. below, and who has, if the protest is of an Award of Contract, participated in a Post-Procurement Review with ITS staff, may file a protest. E. Protest Bond

  1. As a condition precedent to filing a protest, the Protestor must provide a Protest Bond as herein described. The Protestor shall procure, submit to the State with its written protest, and maintain in effect at all times during the course of this protest or appeal thereof, a Protest Bond in the amount specified in the underlying RFP or Letter of Configuration, or in the default amount specified by the ITS Board when no such amount is specified in the RFP or Letter of Configuration. The default bond amount established by the ITS Board is $250,000 or the estimated total project cost, whichever is less. The estimated total project cost shall be determined by the state.
  2. The bond shall be accompanied by a duly authenticated or certified document evidencing that the person executing the bond is a licensed Mississippi agent for the bonding company. This certified document shall identify the name and address of the person or entity holding the Protest Bond, and shall identify a contact person to be notified in the event the state is required to take action against the bond. The Protest Bond shall not be released to the Protestor until the protest is finally resolved and the time for appealing said protest has expired or until the

178

protest is finally resolved and the Protestor furnishes ITS with written notification that no appeal will be pursued. 3. The Protest Bond shall be procured at the Protestor's expense and be payable to the State of Mississippi. Prior to approval of the Protest Bond, the State reserves the right to review the bond and require the Protestor to substitute an acceptable bond in such form as the State may reasonably require. The premiums on such bond shall be paid by the Protestor. 4. The bond shall bind the surety to all of the terms and conditions of this protest policy. The State may claim against the Protest Bond as specified in Section 25-53-5 (n) of the Mississippi Code Annotated, as amended, in addition to all other rights and remedies the State may have at law or in equity. F. Subject of Protest

  1. Protestors may file a protest during the following phases or events of the procurement process. Grounds for protest of each milestone are limited to specific criteria. Each written protest should specifically identify which of the following grounds is the reason for the protest. Only protests at the following milestones and citing the following grounds shall be considered: a. Milestone: Specification preparation Specifications were unjustifiably restrictive and failed to promote fair and open competition b. Milestone: Proposal Solicitation State failed to follow procedures established in the RFP or Letter of Configuration, ITS procurement policy and procedures, or ITS governing law c. Milestone: Disclosure of Information marked as confidential in the proposal State failed to follow procedures established in the RFP or Letter of Configuration, ITS procurement policy and procedures, or ITS governing law d. Milestone: Award of Contract i) Errors were made in computing scores upon which an award was based ii) Bias, discrimination, or conflict of interest exists on the part of an evaluator iii) State failed to follow procedures established in the RFP or Letter of Configuration, ITS procurement policy and procedures, or ITS governing law e. Milestone: Execution of the contract Scope and intent of the project as specified in the executed contract differ materially from the scope and intent of the RFP or Letter of Configuration
  2. Disallowed Issues: Protests not based on the above criteria shall not be considered. Protests not based on procedural matters will not be considered. Protests will be rejected as without merit if they attack such issues as:
    1. An evaluator's professional judgment on the quality of a response
    2. The Customer's assessment of their agency's own needs or requirements
    3. Authority to Resolve Protests - The Executive Director of ITS or his/her designee shall have
    the authority to settle and resolve a protest. H. Filing of Protest
  3. Time for Filing: Protests must be filed according to the milestone schedule below. If no protest is filed within the time limit specific to a milestone then the time for protesting any activity leading up to that milestone shall be deemed waived. a) Milestone: Specification preparation:

179

• Within five (5) Working Days after the date of the Official Release of the RFP; or • Within two (2) Working Days before the Letter of Configuration response is due. b) Milestone: Proposal Solicitation: • Withinfive (5) Working Days after the Protestor knows or should have known of the failure to follow procedure, but in no event later than ten (10) Working Days after the Award of Contract. c) Milestone: Disclosure of Information: • Within five (5) Working Days after the Protestor knows or should have known of the Disclosure of Information, but in no event later than ten (10) Working Days after the Award of Contract. d) Milestone: Award of Contract: • All protests filed during this period must be preceded by a Post Procurement Review. (See Section 212.4: 021-0402(2) – Post Procurement Review – As Condition Precedent to Protest.) • In order to preserve Protestor’s right to protest, Protestor must request, in writing, a Post Procurement Review within five (5) Working Days of ITS’s Notice of the Award of Contract. • All protests must be filed within five (5) Working Days after Post Procurement Review. (For exceptions to this rule see Miss. Code Ann. Section 25-61-5(1)(b)). e) Milestone: Execution of contract: • Within five (5) Working Days of the execution of the contract by the last signatory.

  1. Notice. Protests shall be made in writing and submitted in an envelope labeled “Protest” to the Executive Director of ITS by personal delivery or by certified United States Mail, postage prepaid, return receipt requested, or by overnight courier with signed receipt. If a protest is not filed within the time limits set forth herein, it will be considered waived. A protest is deemed filed when it is received by the Executive Director of ITS and contains the items detailed in Section I below, including but not limited to a Protest Bond in the correct amount, as described in Section E above. I. Content of Protest - The written protest shall contain the following:
  2. The name, mailing address, telephone number, and fax number of the Protestor
  3. Appropriate identification of the procurement or contract protested
  4. A statement, in sufficient detail, of the facts upon which the protest is based, including the effective date of any alleged grievable action, and why such action is believed to be in error and any actions taken prior to the protest in an attempt to resolve the grievance
  5. Supporting exhibits, evidence, or documents to substantiate any claims. If such exhibits, evidence, or documents are not available within the filing time, Protestor should provide the expected date the information will be available. In no case will delay in the delivery of supporting documents be justification for extending the time for filing the protest
  6. A statement of the relief requested
  7. The Protest Bond and accompanying certification, as described in Section E above a. A protest that is incomplete, or not submitted within the prescribed time limits as described in Section H above, will be summarily dismissed. b. All correspondence related to a protest should be addressed to the ITS Executive Director. The outside of the envelope should be clearly marked "Protest" and should contain the

180

name and RFP number or Letter of Configuration subject for the procurement that is the object of the protest. J. Notification - Upon receipt of a written protest, the Executive Director of ITS shall submit a copy of the protest to the Attorney General, to the Customer involved in the procurement under protest, and to all other Interested Parties. The same parties will also receive copies of any other written documents generated during the protest proceedings without the requirement of a public records request being submitted. K. Stay of Procurements - In the event of a timely protest, the State shall not proceed further with the proposal solicitation or Award of the Contract until the resolution of the protest, unless the Executive Director of ITS, after conferring with the director of the procuring state agency, institution, or governmental entity, makes a written determination that in order to protect the substantial interests of the State, it is necessary to go forward with the proposal solicitation or Award of the Contract. L. Additional Information -- Time for Filing - Any additional information requested from the Protestor or Interested Parties by the Executive Director of ITS should be submitted within the reasonable time period established by the Executive Director in order to expedite consideration of the protest. Failure of any party to comply expeditiously with a request for information by the Executive Director of ITS may result in the protest being resolved without the additional information being considered. M. Initial Review of Protest

  1. When a protest is filed, the Executive Director of ITS shall perform a review of the protest. The review shall be based on the written protest material submitted by the Protestor and all other facts known to the Executive Director. The Executive Director shall determine as a result of the initial review if sufficient information has been submitted to render a decision. The Executive Director may either render a decision at that time based on the information in his/her possession or schedule a protest conference as specified in Section N below.
  2. ITS may refuse to hear or consider, or may cease to consider, a protest on the grounds that the protest is trivial, frivolous, vexatious, or not made in good faith. N. Scheduling of Protest Conference - When the Executive Director of ITS determines that a protest conference is required to acquire sufficient information to render a decision, the Executive Director shall, mutually with the Protestor, schedule a date, time, and place for the protest conference and send a notice of same to the Protestor, the Customer, and any Interested Party. O. Rescheduling of Protest Conference - Continuances requested by any party to the protest shall be granted within the discretion of the Executive Director of ITS only for good cause shown. P. Failure to Appear at Protest Conference - If a Protestor, without good cause, fails to appear at the protest conference, such failure will be deemed a withdrawal of the protest and the Executive Director shall dismiss the protest and such dismissal shall be final and conclusive. Q. Conduct of Protest Conference

181

  1. The protest conference is a business meeting during which time the issues relevant to the specific procurement being protested are presented. ITS expects the issues to be presented from a business perspective by the protesting vendor's account representative directly overseeing this project. ITS will not allow the protest conference to evolve into an adversarial proceeding.
  2. So as to encourage the amicable resolution of a protest, the protest conference is informal and no witnesses are examined. However, if there is anyone that a party believes could provide pertinent input, the party may have that person present to be interviewed, at the discretion of the ITS Executive Director, at the conclusion of the conference and before a decision is made.
  3. The Protestor has the burden of proving that the protest merits the relief requested.
  4. The Executive Director of ITS shall have the authority to maintain the decorum of the conference and shall take reasonable steps to do so when necessary, including clearing the conference room of any person who is disruptive. R. Decision of ITS Executive Director
  5. The Executive Director of ITS shall, within a reasonable time, prepare a written decision. The final determination shall either:
    1. Find the protest lacking in merit and uphold the State's action
    2. Find only technical or harmless errors in the State's acquisition process, determine the State
    to be in substantial compliance, and reject the protest c. Find merit in the protest and provide options which may include: i.) Correct errors and re-evaluate all proposals ii.) Reissue the RFP or Letter of Configuration iii.) Make other findings and determine other courses of action as appropriate d. Find that it is in the best interest of the State to reissue the RFP or Letter of Configuration, with no determination of fault or error.
  6. A copy of such decision shall be sent by personal delivery or sent by electronic means to the Protestor; any Interested Party, and the executive head of the procuring state agency, institution, or governmental entity, provided that a printed copy of the decision is sent to the Protestor by courier or other delivery option with signed receipt. The decision of the Executive Director of ITS shall be final and conclusive unless fraudulent or unless a timely request for a review by the ITS Board is filed. S. Effect of Judicial Proceedings - ITS shall refuse to decide a protest if an action concerning the protest has been filed in court. T. Review by the ITS Board
  7. Right to Review - Any Protestor, Interested Party, or Customer aggrieved by the final decision of the Executive Director of ITS, may file a written request for review by the ITS Board.
  8. Time for Filing a. Requests for review by the ITS Board shall be filed with the Board with copies of same being sent to the Executive Director of ITS, the Customer, and any Interested Party, by personal delivery or by certified United States Mail, postage prepaid, return receipt requested, or by overnight courier with signed receipt, within three (3) Working Days after receipt of the decision by the Executive Director of ITS.

182

b. If a request for review by the ITS Board is not filed within the specified time limit, it will be considered waived and the decision of the Executive Director of ITS shall be final and conclusive. 3. Content of Review Request - The written request for review by the ITS Board shall contain, at minimum, the following: a. the name and mailing address of the person filing the request for review; b. a copy of the written protest originally filed; c. copies of all documents which have been produced thus far in the protest proceeding; d. copy of the decision of the Executive Director of ITS; e. a statement, in sufficient detail, of the facts relied upon to substantiate a claim that the decision of the Executive Director of ITS is in error; f. a statement of the relief requested; and g. the Protest Bond and accompanying certification, as described in Section E above. 4. Initial Review by ITS Board - When a Request for Review is filed, the ITS Board shall perform an objective review of the request. The review shall be based on the written material submitted by the Protestor and all other facts known to the Board. The Board shall determine as a result of the initial review if sufficient information has been submitted to render a decision. The Board may either render a decision based upon the information in its possession or schedule a review conference as specified below. 5. Scheduling of Review Conference a. When the ITS Board determines that a conference is required to acquire sufficient information to render a decision, the ITS Board shall mutually with the Protestor schedule a date, time, and place for the review conference and send a notice of same to the Protestor, the Customer, and any Interested Party. b. Continuances requested by any party to the protest shall be granted within the discretion of the ITS Board only for good cause shown. c. If a Protestor, without good cause, fails to appear at the review conference, such failure will be deemed a withdrawal of the protest and the ITS Board shall dismiss the protest and such dismissal shall be final and conclusive. 6. Conduct of Review Conference a. The review conference is a business meeting during which time the issues relevant to the specific procurement being protested are presented. ITS expects the issues to be presented from a business perspective by the protesting vendor's account representative directly overseeing this project. ITS will not allow the review conference to evolve into an adversarial proceeding. b. So as to encourage the amicable resolution of a protest, the review conference is informal and no witnesses are examined. However, if there is anyone that a party believes could provide pertinent input, the party may have that person present to be interviewed, at the discretion of the ITS Board, at the conclusion of the conference and before a decision is made. c. The Protestor has the burden of proving that the protest merits the relief requested. 7. The ITS Board shall have the authority to maintain the decorum of the conference and shall take reasonable steps to do so when necessary, including clearing the conference room of any person who is disruptive.

183

  1. Decision on Review - The ITS Board shall issue a final written decision within a reasonable time after the final date for filing all documents to be considered on review. The final determination shall either:
    1. Uphold the Executive Director's decision; or
    2. Determine that the Executive Director's decision was in error and render a new decision
    which shall either: i. Find the protest lacking in merit and uphold the State's action; or ii. Find only technical or harmless errors in the State's acquisition process, determine the State to be in substantial compliance, and reject the protest; or iii. Find merit in the protest and provide options which may include: • Correct errors and re-evaluate all proposals; or • Reissue the RFP or Letter of Configuration; or • Make other findings and determine other courses of action as appropriate; or iv. Find that it is in the best interest of the State to reissue the RFP or Letter of Configuration, with no determination of fault or error. A copy of such decision shall be sent by personal delivery or sent by electronic means to the party filing the request for review; the Executive Director of ITS; the executive head of the procuring state agency, institution, or governmental entity; and any Interested Party, provided that a printed copy of the decision is sent to the party filing the request for review by courier or other delivery option with signed receipt. A determination of an issue or fact by a quorum of the ITS Board shall be final and conclusive unless arbitrary, capricious, fraudulent or clearly erroneous. U. Exhaustion of Remedies - Except as may be authorized under federal law, no Protestor may file a petition for judicial review with a court of competent jurisdiction, until a final written decision has been issued by the ITS Board. Any such petition for judicial review shall be filed in accordance with the court of competent jurisdiction’s rules/procedures after entry of ITS Board's final written decision. Protestor must notify ITS, within thirty (30) calendar days of entry of ITS Board's final written decision, concerning Protestor's intent to file a petition for judicial review. ITS will return the Protest Bond only on receipt of written notification from Protestor that Protestor will not file a petition for judicial review. Upon the court's determination following any petition for review that the protest was filed without substantial basis or reasonable expectation to believe that the protest was meritorious, ITS will issue a payment demand against the Protest Bond to cover the expense or loss incurred by the State as a result of the protest. V. Amendment of Rules, Etc.
  2. The ITS Board may, from time to time, amend these rules or promulgate new rules.
  3. If any one or more of these rules is found to be invalid by a court of competent jurisdiction, such finding shall not affect the validity of any other of these rules. Source: 25-53-7; 3-3-7; 25-53-5 (n)

184

Part 2 Chapter 10: Procurement Policies Rule 210.4: 019-030 Issuing Brand Specifications

While Sections 25-53-5(o) and 25-53-123(1) of the Mississippi Code of 1972 generally provide that all acquisitions of computer equipment and services as well as telecommunications equipment, systems, and related services involving the expenditure of funds in excess of the dollar amount established in Section 31-7-13(c) be based upon competitive and open specifications, Section 25- 53-5(d) specifically directs and authorizes the adoptions of rules, regulations, and procedures governing the acquisition of computer and telecommunications equipment and services which shall, to the fullest extent practicable, ensure maximum competition between all manufacturers of supplies or equipment or services, and that in the writing of the specifications, in the making of contracts relating to the acquisitions of such equipment and services, and in the performance of its other duties the authority shall provide for the maximum compatibility of all information systems hereafter installed or utilized by all state agencies and may require the use of common computer languages where necessary to accomplish the purposes of the ITS Chapter of the Mississippi Code of 1972. Furthermore, under Section 25-53-5(b), a paramount consideration in the execution of its functions, which includes the adoption of reasonable rules and regulations as outlined in Section 25-53-5(j), is the successful internal organization and operation of agencies so that efficiency existing therein shall not be adversely affected or impaired and that the special needs of public universities in relation to the fields of teaching and scientific research shall also be taken into consideration.

Section 25-53-5(p) also provides ITS with statutory authority to procure equipment, systems, software, and related services in accordance with the law or regulations, or both, which govern DFA, or ITS, and Section 31-7-13(c)(iv)(1) of the public purchasing law authorizes DFA or the board of a governing authority, upon presentation of valid justification, to approve requests for specific equipment necessary to perform a specific job, and further permits such justification, when placed on the minutes of the board of the governing authority, to serve as authority for a governing authority to write specifications to require a specific item of equipment needed to perform a specific job.

ITS makes every effort to work with customers to ensure the statutory requirements as well as the customer's business needs are met through the procurement process. To the fullest extent practicable, ITS strongly encourages the use of open and competitive specifications to ensure maximized competition between all manufacturers when there are other technology sources available that would meet the customer’s business needs; however, in certain situations, the most advantageous, efficient, and cost-effective approach may be to identify the brand in the specifications. And ITS recognizes that customers must determine how to fulfill their business needs and the features which are indispensable to fulfilling those needs, and a customer may determine there is a compelling business need to identify a brand in the specifications.

Accordingly, as permitted by ITS statutes and consistent with Section 31-7-13(c)(iv)(1), upon presentation of valid justification of a customer’s compelling business need, ITS may approve requests to issue brand specifications when deemed in the best interest of the State so as long as

185

there are multiple vendors or resellers available to provide the requested acquisition to ensure maximum competition to the fullest extent practicable.

Requests to issue brand specifications must be well documented by the customer and reviewed and approved by ITS prior to customer purchase. Presentation of valid justification for requests to issue brand specifications shall be provided on the corresponding “Justification for Brand Specification” request form available on the ITS website and should address the customer’s compelling business needs and practical benefits, including, but not limited to, the following:

• Compatibility; • Cost-effectiveness • Efficiency; • Interoperability/Consistency; • Staff expertise/Institutional knowledge; • Maintenance/Support requirements; • Volume discounts over a product lifecycle; • Synchronization with peer governmental, educational, or research entities • Other factors for consideration

The customer must acknowledge on the form that the customer has determined it has a compelling business need to issue brand specifications, that multiple vendors or resellers are available that can provide the specified brand, and that issuing the brand specification is in the best interest of the State.

Requests to issue brand specifications are limited to purchase made from the Express Product List (EPL) and/or other procurements listed on the ITS Express Product List webpage where the instructions for use permit the issuance of brand specifications based on the specific procurement. Customers are responsible for reviewing the individual instructions for use to determine whether the procurement permits the issuance of brand specifications.

A customer may also present a valid justification of a compelling business need to issue brand specifications for ITS review and approval for acquisitions outside the Express Product List. ITS will review and approve requests to issue brand specifications for acquisitions outside the EPL webpage on a case-by-case basis, and this option may only be used if the manufacturer/brand is available from multiple vendors or resellers and issuing the brand specification is determined to be in the best interest of the State.

ITS reserves the right at any time and at its discretion to review and request additional information to assess a customer’s request to issue brand specifications.

Please note: The following criteria are NOT appropriate in requesting brand specifications:

(1) Brand specifications must be at the manufacturer level. Requiring a specific reseller is not permitted.

186

(2) Single/sole source items. If only one source can provide the requested brand item, and the item is not competitively available from multiple vendors or resellers, the Sole Source process should be used. (See 013-030 Sole Source)

(3) Personal/professional services unless approved at the discretion of ITS.

Source: 25-53-5(b); 25-53-5(d); 25-53-5(j); 25-53-5(o); 25-53-5(p); 25-53-123(1); 31-7- 13(c)(iv)(1)

187

Part 2 Chapter 10 Procurement Policies Rule 210.5: 019-050 Proposal Confidentiality Procedure RFP and Proposal Confidentiality Procedure The Mississippi Public Records Act of 1983, Mississippi Code Section 25-61 states: (1) Records furnished to public bodies by third parties which contain trade secret or confidential commercial or financial information shall not be subject to inspection, examination, copying or reproduction under this chapter until notice to said third parties has been given. ITS treats all vendor proposals submitted in response to Request for Proposals (RFPs) as confidential and only discloses proposal information in accordance with the ITS Public Records Procedures (Section 019-010 of the ITS Procurement Handbook). The utmost care must be taken by all parties involved in the evaluation of proposals and subsequent project implementation activities to maintain that confidentiality. In addition, the integrity of the procurement process requires that ITS maintain confidentiality regarding the content of an RFP at all times prior to the RFP's official release. This confidentiality is to ensure no vendor has an unfair advantage due to having advance knowledge of specific RFP content and requirements. The following procedures should be followed to protect the integrity of the procurement process and to secure the resulting vendor proposals throughout the lifecycle of the information technology procurement project. During RFP Development: Participants in the RFP development process are bound by public procurement policy to maintain confidentiality of the specific content and requirements of the RFP at all times prior to the RFP's official publication on the ITS website ("RFP Release"). In many cases, the understanding and verbal commitment of the participants afford adequate protection for the integrity of the RFP and procurement process. The ITS Technology Consultant (TC) serving as Project Manager should determine whether a specific RFP requires the execution of formal, written RFP Confidentiality Agreements. Factors that would indicate a written RFP Confidentiality Agreement is needed include: (1) multiple entities involved in the development and review of the RFP (e.g. oversight committees and commissions, interagency procurements, participation of multiple functional areas within a single agency); (2) highly competitive or litigious vendor market; (3) RFP development process spanning multiple months; and/or (4) high-dollar, complex projects. If it is determined that RFP Confidentiality Agreements are required, the agreements should be executed by everyone who has access to the RFP document before it is publically released, including procurement project team members at ITS and the customer agency, customer executives, and the ITS Board, if applicable. The executed confidentiality agreements must be maintained in the ITS project file. Prior to Proposal Due Date: The ITS TC serving as Project Manager and the Customer Agency contact on the project should determine the composition of the evaluation team. ITS customers may utilize the services of third party contractors for proposal evaluation, quality assurance of vendor deliverables and/or implementation project management. These contractors must be subject to the same

188

confidentiality requirements as the state team members. Generally, all members of the team evaluate the vendor’s entire proposal. In some instances, team members may only evaluate specific portions of a vendor’s proposal where they have expertise. In either case, all team members should execute an Evaluation Confidentiality Agreement prior to receiving a copy of proposals. The executed confidentiality agreements must be maintained in the ITS project file. The TC should stress the importance of maintaining proposal confidentiality in initial meetings with the evaluation team. Proposal Due Date: Vendors and other parties that have not executed confidentiality agreements relative to this procurement may attend the proposal opening. The TC and/or proposal opening witness must ensure that the opened proposals are not left unattended at any time. The TC should secure a master copy of each proposal to eventually archive with the project file. The TC should distribute the remaining copies of the proposals to only those members of the evaluation team who have executed the confidentiality agreement. Proposal Evaluation: The TC should instruct the team members to take all reasonable precautions to prevent unauthorized access to vendor proposals. Additionally, the team members should be reminded not to discuss proposal content with anyone other than evaluation team members. Team members operating in a cubicle environment should utilize enclosed cabinets, boxes or some other means to avoid leaving proposals exposed to passers-by. As most office environments now share printers, caution must be taken in printing any proposal comparisons or summaries that contain technical and/or financial data about the proposals so that the printouts are not viewed by unauthorized individuals. During the evaluation period, the team may request clarifications from the vendor on specific areas of his proposal. The clarifications submitted by the vendor must be held to the same level of confidentiality as the original proposal. If during the evaluation, it is determined that additional people need to evaluate the proposals in whole or in part, the TC must require them to execute a confidentiality agreement and instruct them on precautionary measures of safeguarding the proposals. Post Evaluation: When the evaluation is complete, the TC must collect all copies of the losing vendors’ proposals. The TC and the customer agency contact must determine the number of winning vendor proposals that will be required by the customer for use in project implementation. Typically, one copy is required for contract administration. Frequently additional copies are needed for the Project Manager and Quality Assurance provider. The TC must be certain that a Confidentiality Agreement for Awarded Vendor Proposal has been executed by the Customer Agency Executive Director or Information Systems Officer before releasing copies of the winning proposals. The TC will secure one copy of each proposal for the ITS permanent project file and distribute the requested copies of the winning proposal to the customer agency. After expiration of the period in which a protest of award may be filed, all remaining copies of the winning and losing proposals must be destroyed. All copies must be shredded or otherwise destroyed by the TC or the ITS/ISS Administrative Team.

189

Damage Control: If at any point during the evaluation or implementation process it is known that the contents of a proposal have been exposed to a third party, the TC should first ascertain the extent of the exposure. If exposure was to an internal party to the project, the TC should immediately have them execute a Confidentiality Agreement and instruct them on proposal confidentiality. If exposure was to an outside party, the TC should notify ITS ISS Division management, who will provide appropriate notification to the affected Vendor.

Source: 25-61-1, et seq

190

Part 2 Chapter 10: Procurement Policies Rule 210.6: 019-070 Timely Receipt of Bids and Proposals All responses to ITS Requests for Proposals (RFPs) and Letters of Configuration (LOCs) are due at 3:00 p.m. Central Time on the date published in the RFP or LOC. The proposal must be time stamped by the ITS receptionist by the specified date and time. (Note: For LOCs only, proposals may be submitted electronically IF SO SPECIFIED IN THE INDIVIDUAL LOC. The email or fax receipt date and time become the official "time stamp" for electronic proposals.)

Any proposal received after the time of the proposal due date will be returned unopened. ITS is not responsible for any delays in delivery or expenses for the development or delivery of proposals. It is solely the responsibility of the proposing vendor to ensure proposals reach ITS by the required time and to confirm the arrival of the submitted proposal as needed.

Source: 25-53-5 (o)

191

Part 2 Chapter 11: ITS Board Rule 211.1: 020-005 ITS Board Meetings: Overview Meeting Schedule and Location The ITS Board meets monthly, and at such other times and places called upon to convene by either the Board Chairman or the majority of its members. The Board’s meetings are open, public meetings. Notice of these meetings is published on the ITS website as well as posted outside the reception area at the ITS administrative office, 3771 Eastwood Drive, Jackson, Mississippi.

Board meetings are the official venues in which ITS statutory policy-making, strategic planning, procurement and other project-related business are conducted. The Board must have a quorum of at least three (3) members present in order to conduct an official meeting. These meetings follow an agenda of business items that have been compiled and forwarded to the Board by ITS staff, one week prior to the time of the actual meeting. This lead-time assists the Board in reviewing and preparing for each project on the agenda.

Board meetings are currently scheduled to occur on the third Thursday of each month. As a rule, meetings begin promptly at 11:00 a.m. There are exceptions to this schedule that occur randomly during peak periods of project activity. Meetings will be arranged in advance to convene earlier in the day and/or to extend to accommodate much fuller agendas. See 020-010 Board Meeting Schedule, Called Meetings, and Notice for the official policies and procedures regarding scheduling of meetings as adopted by the ITS Board.

Boardroom Facilities The ITS Boardroom is located in the ITS Board Room on the first floor of the ITS administrative office. This room is the site for most meetings unless the Board accepts an invitation from another agency or institution to host a meeting offsite. Seating is available in the back of the room for attendees from the vendor community and from state agencies and institutions, as well as any other interested party.

All meeting attendees other than ITS employees are required to sign in upon entering the meeting room. Their attendance is recorded as a part of the Board’s minutes. Copies of the Board’s agenda for the current meeting are available at the sign-in table. The agenda is also posted on the ITS website during the week of the meeting.

Those presenters that desire to use the boardroom presentation facilities will find connections for both power and local/wide area networking, as well as provision of an overhead projector capable of hosting programmed presentations from portable computers. Presenters must give advance notice to the ITS staff if the presenters want to use these facilities. Further, they should arrive sufficiently early to set-up, test and ensure that their presentations and all facilities are working together.

Prior arrangements must similarly be made for any attendee or media group desiring to set up and use audio or video equipment to record any Board meeting.

192

Board Meeting Protocol and Decorum The ITS Board conducts its business in a formal, official setting. The Board Chairman moderates each meeting observing Robert’s Rules of Order. All participants are expected to observe appropriate dress and conduct in keeping with the official protocol and decorum of the Board meetings. All discourse with the Board should be done from the speaker’s podium or, upon being recognized by the Chairman, from the gallery. Participants should stand and state their names prior to speaking. For formal rules of conduct adopted by the Board in 1989, see 020-015 Rules and Regulations Governing the Conduct of Persons at ITS Board Meetings.

To preserve the order of the meeting, all participants are required to disengage any cellular phones, pagers or other electronic devices and refrain from using them while the Board meeting is underway.

The Chairman begins each meeting with a call to order, then an invitation for guests to introduce themselves. All attendees who are not ITS employees should state their name, title, and employer. The Chairman next requests that the Board review and vote on the minutes of the previous meeting. The Board’s subsequent order of business is to take up the current month’s agenda, generally in the order in which it was prepared by the ITS staff. The Chairman will invite the particular internal and/or guest staff to present a synopsis of each agenda item together with the official recommendation. The Chairman will entertain discussion of the agenda item among the Board and presenters. The Chairman next requests a motion from the Board members on the disposition of each agenda item. The Board then votes on the agenda item. The Board secretary records all proceedings into the minutes of each meeting. The minutes become official once approved by the Board and signed at a subsequent meeting. Upon conclusion of all scheduled and ad hoc agenda items, the Chairman calls for a motion to adjourn the meeting.

Conclusion The ITS Board and staff have organized the Board meeting process in the manner described so that the business of State and its citizens, as it pertains to ITS statutory responsibilities, may be conducted in an open, efficient manner, allowing each agenda item and its interested parties to be given the fullest respect and consideration. Source: 25-53-11

193

Part 2 Chapter 11: ITS Board Rule 211.2: 020-010 Board Meeting Schedule, Called Meetings, and Notice At its October 19, 2006 meeting, the ITS Board approved the following policies and procedures related to scheduling and providing notice of ITS Board Meetings:

Regular Meetings • The ITS Board will hold its regularly scheduled monthly meetings on the third Thursday of each month, beginning at 11:00 a.m., in the ITS Board Room, 3771 Eastwood Drive, Jackson, Mississippi 39211. • The Board may cancel its regular meeting in any month in which there is no official business to come before the Board, a quorum of members cannot be present, or the Board Chairman determines there are other compelling reasons for doing so. • The Board may reschedule its regular meeting to an alternate date, time, and/or location as needed, provided notice is given as outlined below.

Special or Called Meetings • Upon call of the ITS Board Chairman or a majority of the members of the Board, the ITS Board may additionally meet at other such times and locations as may be set, provided notice is given as outlined below.

Notice • Notice of the date, time, and location of all meetings of the ITS Board will be posted in the ITS administrative building at 3771 Eastwood Drive, Jackson, Mississippi and on the ITS website, ITS Board Meetings. • Notice of changes to the date, time, or location of any regular meeting, and notice of the date, time, and location of any special or called meeting will be posted in the ITS administrative building at 3771 Eastwood Drive, Jackson, Mississippi and on the ITS website one hour after the change to the date, time, or location of the regular meeting or within one hour after such special or called meeting is set.

Source: 25-53-11

194

Part 2 Chapter 11: ITS Board Rule 211.3: 020-015 Rules and Regulations Governing the Conduct of Persons at ITS Board Meetings (Adopted by ITS Board July 1989)

  1. General Conduct

A. Public Attendance: Any person desiring to attend meetings of the ITS Board may do so to the extent that space is available.

B. Demeanor: During the course of all meetings attendees should limit their exits and entrances and other movements or private conversations within the meeting room.

C. Interruptions: No unsolicited interjections by attendees will be allowed unless the Chairman grants approval.

D. Disruptions: Disruptive conduct of any kind-is not allowed and will result in exclusion from the meeting,

  1. Recording or Transmission Devices

A. Prohibitions: No visual recording or transmission of Board meetings will be permitted. The taking of photographs is likewise not allowed.

B. Provisionally Permitted Methods: There are no proscriptions against non-intrusive, mechanical or manual methods of transcription such as note-taking or silent court reporting machines, provided space permits.

C. Rescinding of Permission: The Chairman reserves the right to rescind permission regarding the transcription of any proceeding and require the discontinuance of any mode of transcription which in the Chairman's opinion demonstrates a disrupting effect on the conduct of the meeting.

  1. Oral Presentations

A. Authorization: Any person obtaining prior permission from the Chairman of the Board may make a single oral presentation before the Board members at a regularly-scheduled meeting.

195

B. Denial: The Chairman reserves the right to deny any such request if it is not received in time to reasonably allow for adjustments in the agenda or if, in the Chairman's opinion, the presentation is unnecessary or will be unduly burdensome.

C. Time Allotted: Any person obtaining such permission will be allotted a reasonable amount of time not to exceed fifteen (15) minutes to address the members of the Board. Any additional time allotted will be discretionary with the Chairman. No Question and Answer session will be permitted unless the members of the Board grant approval.

D. Rebuttal or Corroboration: Persons wishing to have equal time before the Board for the purpose of rebutting or corroborating any oral presentation must adhere to the procedure set out above. Source: 25-53-11

196

Part 2 Chapter 12: Information for Vendors Rule 212.1: 021-010 How to Do Business with the State of Mississippi

Question: How do I sell technology products and services to state entities? Answer: It depends upon:

(1) The type of products or services you are selling to the State The Department of Information Technology Services (ITS) is the Mississippi state agency established by law to oversee the State's information technology. The procurement of information technology equipment, software, and services for all state agencies and institutions of higher learning is under the jurisdiction of ITS. There are two Mississippi agencies involved in the statewide purchasing function. Purchasing of items NOT related to information technology equipment and software is coordinated through the Department of Finance and Administration (DFA) Office of Purchasing, Travel, and Fleet Management (OPTFM). Purchasing of computer supplies falls within DFA oversight. The Public Procurement Review Board (PPRB) Office of Personal Service Contract Review (OPSCR) Rules and Regulations governs the solicitation and selection of personal and professional services that do not involve information technology. (2) What type of government entity you are selling to State agencies and institutions of higher learning are required to follow ITS procedures to make information technology procurements. Governing Authorities (such as county boards of supervisors, community/junior colleges, K-12 school districts, or cities) are not required to use ITS procurement procedures when making information technology purchases, but are allowed to use certain ITS procedures if they choose to do so. When not using ITS procurement procedures, Governing Authorities must use general purpose State Purchasing Laws and procedures coordinated through DFA-OPTFM. Procurement procedures for agencies and institutions of higher learning to follow when making information technology purchases are contained in the ITS Procurement Handbook. Purchases of information technology are coordinated by ITS in compliance with 25-53 of the Mississippi Code. This law requires the solicitation of proposals for the majority of information technology purchases. The Mississippi Code is online. (3) The dollar amounts of the purchase and what type of proposals might be in place to handle the purchase Agencies, institutions of higher learning and governing authorities (K-12 schools, community/junior colleges, city and county government, etc.) may make purchases in accordance with ITS Law and Public Purchasing Law as follows.

• Up to $5,000 - May purchase without advertising or otherwise requesting competitive bids, unless the purchasing agency or entity has established more stringent procedures.

197

• $5,000.01 – up to but not over the dollar amount established in Section 31-7-13(c). - May purchase without advertisement for bids, provided at least two competitive written bids have been obtained. You must select the lowest quote. (Note an Express Products List cannot be used as one of these bids.) • In excess of the dollar amount established in Section 31-7-13(c) - Advertise, issue written specifications and receive sealed bids or proposals.

Some agencies have established additional procurement procedures; check with the individual agency or institution to determine if there are other requirements.

Question: What types of proposals does ITS use? Answer: ITS does NOT set up "state contracts" for routine purchases of information technology purchases. ITS does not maintain a "bidder's list". All ITS RFPs are advertised on the ITS website. RFPs typically fall into one of the following categories: • Individual Requests for Proposals are typically for the procurement of large dollar, complex, and/or unique acquisitions, usually for a single acquisition by a single agency or institution. • Special RFPs typically are used by a specific group of agencies/institutions. The terms and intended users and uses are spelled out in the RFP document. Often these proposals are for repetitive or longer term use, as opposed to a more limited time use in an Individual RFP. • General RFPs are used by ITS for the routine acquisitions by multiple entities of items such as microcomputer equipment and software, printers, cabling, telephone equipment, mainframe/midrange components, small UNIX/Internet servers, and IT consulting services. ITS advertises these RFPs and updates them periodically mid-cycle. General RFPs can only be used by ITS staff. They are not published. ITS uses General RFPs in conjunction with procurement requests received from agencies/institutions to acquire information technology products and services in accordance with state law. • Express Products Lists (EPLs) are evaluated proposals covering routine configurations of such items as microcomputers, servers and LAN components, printers, software, and two-way radios. Agencies, institutions and governing authorities may use an EPL in compliance with ITS procedures to make purchases that fall within the scope of the EPL. The most popular EPL is the IT Hardware EPL. ITS publicly advertises each time proposals for EPLs are solicited. See Procurement Instruments: EPLs, Section 011-030 of the ITS Procurement Handbook, for procedures the agencies and institutions are required to use when purchasing from Express Products Lists. The complete list of EPLs is found on the ITS website.

More details for information technology vendors interested in doing business with the State of Mississippi are available in the Procurement Information for Vendors, Section 021-020 of the ITS Procurement Handbook. Topics covered in this section include: • More details on ITS RFP advertising procedures • Suggestions for marketing to state agencies • Procurements of information technology that state agencies and institutions may make without prior coordination through ITS • Legal and funding issues when submitting proposals to the state • IT purchases by governing authorities using ITS procedures Source: 25-53-5 (o)

198

Part 2 Chapter 12: Information for Vendors Rule 212.2: 021-020 Procurement Information for Vendors The following information is intended for use by vendors interested in doing business with the State of Mississippi Department of Information Technology Services.

Introduction This information is provided for vendors regarding the Department of Information Technology Services (ITS) and the process of selling information systems equipment, software and related services to the State of Mississippi. This information explains ITS procurement procedures and addresses questions most frequently asked by vendors.

It is the goal of ITS to promote and maximize competition in the purchasing of information technology hardware, equipment, systems, software, and services for the State within Mississippi's information systems architecture. If you have not worked with ITS or sold to the State of Mississippi before, we welcome you to do so. If you have worked with us in the past, we thank you for your previous participation and encourage your participation in the future.

ITS Website ITS maintains an Internet website with information of interest to ITS customers and vendors. Separate channels for Vendors and Customers help organize the information and focus your search. We invite you to visit our website at http://www.its.ms.gov. Use the contact information available on the website if you have additional questions or need answers concerning a specific situation or project.

Who is ITS? ITS is a state agency established by law to oversee the State’s acquisition and use of information technology. ITS coordinates the procurement of information technology for Mississippi agencies, public universities, and, optionally, governing authorities such as community/junior colleges, local governments, and K-12 schools and school districts. The procurement of information technology hardware, equipment, systems, software, and services for all state agencies and institutions of higher learning is under the jurisdiction of ITS.

ITS is governed by a five-member Board. The ITS Board plays a strong role in the procurement process. All procurements are made in compliance with 25-53 of the Mississippi Code and policies set by the Board. Procurements in excess of the Director Approval threshold, as defined in Section 018-030, must be approved by the Board. The Board has delegated to the Executive Director of ITS the discretion of approving procurements under these thresholds.

For many acquisitions it is necessary for state agencies and institutions of higher learning to acquire ITS approval prior to procurement of information technology hardware, equipment, systems, software, and services. Responsibility for some acquisitions has been delegated to the agencies and institutions under the Exemption, Delegation of Approval, or Planned Purchases Procedures. Explanation of which procurements require ITS' prior approval and which may be handled by the agency/institution without ITS' prior approval is detailed later in this document.

199

The acquisition of information technology by Mississippi agencies and institutions of higher learning are governed by the following laws: • Computer/Data Processing (DP) procurements: Section 25-53-1, et seq. of the Mississippi Code. • Telecommunications (TC) Procurements: Section 25-53-101, et seq. of the Mississippi Code. Both types of procurements are governed by the same policies and procedures.

Department of Finance & Administration Office of Purchasing, Travel, and Fleet Management There are two different Mississippi agencies involved in the statewide purchasing function. ITS coordinates information technology purchases. Purchasing of items not related to information technology equipment, software and services is coordinated per Section 31-7 of the Mississippi Code through the Department of Finance and Administration (DFA) Office of Purchasing, Travel, and Fleet Management. Purchasing of computer supplies falls within DFA oversight.

Groups to Whom ITS Procurement Procedures Apply ITS Procurement procedures apply to the following groups: • State Agencies • State Institutions of Higher Learning (Public Universities) • Governing Authorities (such as county boards of supervisors, State Community/Junior Colleges, school districts or municipalities.) State agencies and institutions of higher learning (public universities) are required to follow ITS procedures in information technology procurements. Governing Authorities (such as county boards of supervisors, community and junior colleges, school districts, or cities) are not required to use ITS procurement procedures, but are allowed to use certain ITS procedures if they choose to do so. Governing Authority procurement procedures are described later in this document.

How ITS Publicizes Upcoming Acquisitions ITS posts current solicitations for Request for Proposals and Sole Source Certifications on the ITS website. ITS does not maintain a bidder's list and vendors do not have to pre-qualify to respond to ITS RFPs. RFPs for upcoming acquisitions and Sole Source Certifications are also advertised in The Clarion-Ledger newspaper, the Mississippi State Government Transparency site located at https://www.ms.gov/dfa/contract_bid_search/, and ITS maintains a bulletin board of current technology solicitations near the reception area on the first floor or ITS administrative offices, 3771 Eastwood Drive, Jackson, MS 39211.

Watch for ITS advertisements in the newspaper or check the Internet listing. Newspaper ads and new listings on the website typically appear on Tuesdays. You may respond to any ITS solicitation for which your company has the requisite expertise. If you would like to submit a proposal to any ITS solicitation and are unable to download the solicitation from the Internet, you may contact the ITS Procurement Help Desk at 601-432-8166 or isshelp@its.ms.gov.)

Charges for Requests for Proposals The vast majority of RFPs issued by ITS are available for download from the ITS website in Adobe and Word format at no cost.

200

ITS charges for printed copies of RFPs. See ITS Public Records Procedures for the current cost of a printed RFP. The vendor is required to deliver one of the following forms of payment before the vendor is given a copy of the RFP.

  1. Corporate check
  2. Personal check (only if the individual is known and has an ongoing business relationship with ITS)
  3. Certified check
  4. Money order
  5. Credit Card via Public Records On-Line Payment Application

No cash will be accepted.

Overview of Procurement Procedures Used by ITS To ensure full compliance with legal requirements, ITS handles procurements in the following ways:

  1. Individual Requests for Proposals (RFPs)
  2. Special RFPs
  3. General RFPs
  4. Express Products Lists (EPLs)

Individual RFPs ITS uses the RFP process for the procurement of high dollar, complex, and/or unique acquisitions, typically for a single acquisition by a single agency or institution. The ITS staff and the requesting agency or institution develop an RFP detailing the specific equipment, system, software and/or service requirements. Solicitations of proposals are published as detailed above. Any vendor may obtain a Word or PDF copy of the RFP from the Internet or request a copy of the RFP as specified above.

Vendors should carefully review the RFP project schedule for key dates. ITS and the procuring agency/institution may host a vendor’s conference with attendance specified as either optional or mandatory. The RFP schedule will show the date and time of the vendor's conference, as well as the deadline for submission of written questions concerning the RFP. While vendors may receive verbal input from the State project team during the vendor's conference or from the designated State Contact Person for the RFP, vendors should be aware that only questions answered officially by the State in writing and posted to the ITS website at the RFP link are binding. Vendors should check the RFP link regularly for official addenda to the RFP, including posted questions and answers.

If a vendor elects to submit a proposal for consideration, the proposal must be submitted to ITS in accordance with all requirements outlined in the RFP by the date and time specified. No Late Proposals Will Be Accepted.

At the date and time the proposals are due, ITS opens, logs, and performs a preliminary validation of proposals received. Vendors are welcome to be present at the ITS offices at the date and time the proposals are due to observe this process.

201

ITS typically assists the procuring agency/institution in the evaluation of the proposals received. This evaluation process may require from a few hours to multiple weeks, depending on the complexity and scope of the RFP and the number and size of the proposals received. During the evaluation process, ITS may request clarifications of vendor proposal information. Because time is always of the essence in the procurement process, ITS requests that you provide prompt responses and accurate answers to all clarification requests. The ITS staff can satisfy our clients’ needs most effectively with vendors who, in addition to providing good pricing, provide us with timely and accurate responses during the evaluation process. See Procurement Instruments: Requests for Proposals (RFPs) for additional information.

Special RFPs ITS issues RFPs to establish a special proposal or proposals for use by a single or group of agencies/institutions. The terms and intended users and uses of special RFPs are spelled out in the specifications. See Procurement Instruments: Special RFPs for additional information.

General RFPs ITS uses General RFPs for routine acquisitions by multiple agencies of items such as microcomputer equipment and software, printers, cabling, telephone equipment, mainframe/midrange components, small UNIX/Internet servers, and IT consulting services. To avoid the time and expense involved in soliciting individual proposals for each such acquisition, ITS advertises periodically to receive proposals on these high-volume categories of information technology.

Proposals received in response to a General RFP are used for a specified period of time (usually one year). There is no sole winning vendor. ITS validates each response but does not perform a preliminary selection from the proposals submitted. When a need arises during the year for equipment, software, or services in a General RFP category, all vendors proposing the products or services that meet the requestor’s unique project requirements are sent a Letter of Configuration (LOC) by ITS. The LOC describes the exact needs of the customer and requests a proposal with pricing.

ISS staff issues LOCs to vendors with valid General RFP proposals who meet the qualifications for the specific project. For vendors meeting the criteria for a given project, the LOC is emailed to the vendor contacts listed in the General RFP response. In addition, vendors with valid General RFP proposals are given an unpublished URL to check for all LOCs. Valid General RFP vendors may respond to any LOC for that General RFP, even if they did not receive the LOC in the email distribution.

Unlike RFP responses, which require delivery of sealed, hard-copy proposals, LOC response may typically be submitted in hard-copy or by fax or email. Vendors should follow the Delivery Instructions in the individual LOC. All submitted proposals are evaluated and the lowest and best solution selected.

General RFPs are for use by the ITS staff on behalf of the procuring agency or institution. General RFPs are NOT for use by agencies, institutions and governing authorities without ITS involvement.

202

Vendors may submit or update General RFP responses throughout the year as detailed in the specifications. Details of RFP procedures are contained in the specifications provided to the vendor.

For a current list of categories of General RFPs, see the Multi-Use RFP Index. General RFP categories will be added and dropped as the demands change.

The ITS staff cannot overemphasize to the vendor the importance of the General RFP process and the importance of vendors' submitting and maintaining accurate and complete General RFP responses. Complete and accurate proposals provide the ITS staff with information about your products and/or services to determine whether they are a fit for a particular project. Your response to the General RFP is one of your best marketing tools for technology in state government.

Express Products Lists ITS has established the Express Products Lists (EPLs) to offer agencies and institutions an expedited procurement procedure for routine acquisitions of microcomputers, servers and LAN components, printers, cellular telephone equipment, and software. ITS does an evaluation of EPL proposals upon receipt to select and publish the lowest and best offerings for each EPL in compliance with the law. EPLs may be used by state agencies, public universities, and governing authorities in the state to make purchases up to the specified dollar limits without ITS involvement.

Details regarding the EPLs may be found in the specifications for the RFPs soliciting Express Products Lists proposals and in the published EPL. See Procurement Instruments: Express Products Lists for additional information.

MAGIC Information To receive payment from state agencies, Vendors must be set up in Mississippi’s Accountability System for Government Information and Collaboration (MAGIC). Each ITS RFP will require the vendor to supply their MAGIC vendor code. If the vendor has not previously done business with the State, the registration can be completed at the link below.

https://sus.magic.ms.gov/sap/bc/webdynpro/sapsrm/wda_e_suco_sreg?sap-client=100

Marketing Activities to the State of Mississippi Vendors are welcome to market products to the state agencies and institutions providing the marketing efforts are conducted in an open and ethical manner and are coordinated with ITS. In fact, ITS recognizes that the vendor is the best source of information regarding his product and appreciates the vendor's willingness and cooperation in working with ITS and the agencies and institutions to publicize how the capabilities of these products can enhance the State's information technology needs.

Vendors can most successfully market to the State by understanding and working within Mississippi's information technology planning, budgeting, and procurement framework. The points below outline this framework.

203

  1. Marketing to the State from the "Enterprise Perspective" within the State's strategic direction for information technology: In support of state agencies and institutions information technology infrastructure, ITS takes an enterprise perspective regarding the State's information systems. A procurement of information systems technology should be made from the viewpoint of the State as a whole. This enterprise perspective is essential for ITS and the agencies and institutions we serve to carry out the mission and the intent of the law effectively.

If you find where your product corresponds with the State's information technology strategic direction, and the agency or institution’s needs, and market from that angle, you should be more successful in marketing to the State.

  1. Procurement is at least a two-year process which is front-ended by the planning and budgeting functions. The client agency begins the procurement process at least two years prior to the actual issuance of a purchase order to the vendor when the agency develops its information technology plan. For instance, an agency must plan in January-April 2004 for purchases to be procured NO SOONER than July 2005. The agency must then budget for the planned acquisition in the August 2004 time frame and the Legislature must appropriate the funds during the legislative session in the January- April 2005 time frame. The resulting acquisition takes place between July 2005 and June 2006.

You, the vendor, will be most successful if you begin your marketing effort with ITS and the agency/institution during the planning process.

Procurements Which Require ITS Approval Prior to Acquisition ITS is the purchasing and contracting agent for all acquisitions of information technology equipment, software, and services that fall within the scope of ITS authority. Contracts without the signature of the Executive Director of ITS are not valid except those delegated to the agency/institution.

ITS approval before the purchase in the form of a CP-1 Acquisition Approval Document is required for acquisitions of information technology equipment, software, and services by state agencies/institutions unless the purchase is handled under the Exemption, Delegation of Approval, or Planned Purchases Procedures described below.

204

Exemptions Procedure ITS may delegate individual procurement projects to the agency/institution under the ITS Exemption Procedure. State agencies and institutions of higher learning may request to make specific procurements of information systems technology without further ITS involvement. ITS' exemption of the procurement gives the agency/institution the responsibility and accountability of making the procurement, including competitive proposal solicitation and contracting, in good faith compliance with the ITS laws. See Procurement Types: Exemptions for additional information.

Delegation of Approval ITS also has delegated certain routine information technology acquisitions to the agencies/institutions. Purchases may be made under these procedures without prior ITS approval. See Procurement Limits Policies, Section 015 of the Procurement Handbook, for specific delegation dollar amounts and categories (Section 015-010 for agencies and Section 015-020 for institutions of higher learning).

Planned Purchases Procedure As the coordinator of the long range planning effort of information technology in the State, the ITS Strategic Services Division works with agencies during the planning process to determine procurements that could be most appropriately acquired from the EPLs. Under the Planned Purchases Procedure, a participating agency is given authorization up to a specified dollar amount to make the identified procurements from the EPLs without further ITS involvement. See Procurement Request Types: Planned Purchases for additional information.

Necessary Components of a Legal Acquisition Procurements of information technology equipment, software and services involve at minimum the agency/institution for whom the purchase is being made, ITS, and the vendor. It is important that the vendor understand its role, that of ITS, and that of the agency/institution.

The following components are necessary for a legal sale to a state agency or institution of higher learning:

  1. ITS Approval An ITS CP-1 Acquisition Approval Document must be issued to the agency/institution for any information technology acquisition unless the procurement has been made under the Exemption Procedure. An order from an agency/institution that was not made in accordance with ITS procedures DOES NOT constitute a valid purchase order. ITS strongly recommends that the vendor verify that the agency/institution has followed a legal ITS procurement procedure for any order from a state agency or institution. Typically, the purchase order should reference an ITS CP-1 Acquisition Approval Document reference number, should be from a valid Express Products List, or should be below the cost thresholds requiring ITS oversight. See Procurement Limits Policies, Section 015 of the Procurement Handbook, for specific delegation dollar amounts and categories (Section 015-010 for agencies and Section 015-020 for institutions of higher learning).

205

  1. Contracts The Executive Director of ITS is, by state statute, the purchasing and contracting agent for information technology hardware, equipment, systems, software, and services made by agencies and institutions of higher learning in the State of Mississippi. All contracts (other than those related to procurements delegated to agencies and institutions as described above) MUST be signed by the Executive Director of ITS to be legally binding. Successful vendors must agree to basic contractual terms and conditions required by the State of Mississippi.
  2. Funding Verification and Agency/Institution Purchase Order The agency/institution is responsible for paying for and receiving the products/services purchased. Funding and payment issues are not within ITS control. ITS CP-1 approval and execution of the contract do NOT constitute a certification that funding is available for the acquisition. The agency/institution is ultimately responsible for verifying availability of funding and issuing a purchase order to the vendor to complete the order. Vendor is responsible for all risks involved in illegal sales to the State and may be required to take back without payment items illegally sold to the State. When in doubt, call ITS for clarification.

NOTE: Billing must be directed to the purchasing agency/institution as specified on the purchase order. Do not send agency/institution billing to ITS unless explicitly directed on the purchase order to do so.

Purchases by Governing Authorities Acquisitions of information technology hardware, equipment, systems, software, and services made by governing authorities DO NOT require ITS approval. Governing authorities are not required to get ITS approval or to have a CP-1 Acquisition Approval Document for making information technology purchases. Governing authorities are not required to use the ITS Express Products Lists (EPLs) to make information technology purchases but can do so if they choose as a mechanism for meeting the requirements of public purchasing laws. The Public Purchasing Law defines governing authorities in section 31-7-1(b). Permission is granted within the Public Purchasing Law for governing authorities to use ITS' proposals, by exempting from bid requirements those items covered by purchase agreements arranged by ITS (Section 31-7- 13(m)(xi)).

Reference Information Regarding State Purchasing Laws The data processing procurement laws are contained in Section 25-53-1 et seq of the Mississippi Code of 1972. The telecommunications procurement laws are contained in Section 25-53-101 through 25-53-125 of the Mississippi Code of 1972. The Public Purchasing Law is contained in Section 31-7-1 et seq of the Mississippi Code.

Section 25-53-25 of the Mississippi Code excludes the following acquisitions from ITS jurisdiction: "...Acquisitions of computer equipment and services by institutions of higher learning or junior colleges wholly with federal funds and not with state general funds...."

Section 25-53-25 of the Mississippi Code gives ITS the authority to delegate purchasing responsibility and is the basis for the Exemption, Delegation of Approval, or Planned Purchases Procedure.

206

Part 2 Chapter 12: Information for Vendors Rule 212. 3: 021-030 Suggestions for Responding to ITS RFPs

• Read and follow all instructions in the Request for Proposal (RFP). The proposal becomes part of the contract with the awarded vendor and a non-responsive proposal will be removed from further consideration. • Work from the Microsoft Word version of the RFP, inserting direct, clear answers below each item in the Technical Requirements section, as instructed in Item 1 of that section, with a clear delineation (through color/font/vertical bars in the margins, e.g.) to show vendor's response versus original RFP text. • If you take exception to an item, it's best to clearly outline an alternative, what you CAN do or offer, because the option might be acceptable to the State or at least allow the State to identify the level of risk. • Tab the response and insert a table of contents, showing where the signed cover sheet, proposal bond, exception summary, response to technical specifications, cost proposal, response to exhibits, etc. are found. • Don't include "brochure" type language -- vendors sometimes make the mistake of marketing themselves rather than just responding to the requirements directly. • Another issue for some proposals is providing the right level of information in response to technical requirements--enough information versus not enough or too much. For most items, the evaluators want to see how the vendor will meet the requirement, not just "will comply." But too much information, especially when it doesn't directly respond to the requirement, is also negative, because the answer gets lost in all the excess verbiage. • When the RFP requires an Experience Information & Reference Workbook, follow all instructions carefully in completing the Microsoft Excel spreadsheet. Experience must be quantified in months. Do not submit candidates without the required amount of experience in each area--they cannot be considered.

207

Part 2 Chapter 12: Information for Vendors Rule 212.4: 021-040 Post-Procurement Reviews

  1. Post-Procurement Reviews – General

A Post-Procurement Review is a business meeting conducted by ITS at a vendor’s request after an Award of Contract for a Request for Proposal (RFP) or Letter of Configuration (LOC). Post- Procurement Reviews are attended by the ITS staff members responsible for the given procurement, ITS management staff responsible for the procurement process, members of the vendor’s staff involved in the proposal process, and, optionally, staff members from the customer agency on whose behalf ITS conducted the procurement. A Post-Procurement Review is a non- confrontational business meeting in which parties exchange information on the procurement process, the results, and any concerns. No vendor preparation is necessary, other than general familiarity with the procurement process that was followed and the contents of that vendor's proposal.

A Post-Procurement Review is available to any vendor who responded to a Request for Proposal (RFP) or Letter of Configuration (LOC), regardless of whether they were awarded the resulting contract. Vendors are encouraged to request Post-Procurement Reviews to both receive information on the scoring of their proposals and to provide ITS with feedback on the procurement process. ITS actively solicits feedback from the vendor regarding any wording in procurement documents or any procurement procedures that were unclear, difficult to follow, or unduly complicated the procurement process. ITS uses this information as input to improve the procurement process. The purpose of the Post-Procurement Review is to strengthen the business relationships and communications between proposing vendors and the State, to provide ITS with information to facilitate improvements to the procurement process, and to provide vendors with specific information that allows them to have insight into the procurement and proposal evaluation process and to compete most effectively. The Post-Procurement Review should also provide a vendor the information needed to determine whether that vendor is aggrieved relative to the specific procurement. For a Post-Procurement Review conducted after the protest period for a given procurement has passed, the full objective of all discussion and information exchange is to assist all parties in identifying ways to improve the procurement products and processes and to help the State increase competition.

Post-Procurement Reviews should be requested in a timely manner, typically no later than five working days after the Award of Contract (for Post-Procurement Reviews related to Protests see section below, Post-Procurement Review – As Condition Precedent for Protests). Requests for a Post-Procurement Review should be made to the ITS staff member who was the contact for the procurement process or to the Director of the Division of Information Systems Services (ISS). Requests must be made in writing. Post-Procurement Reviews can be conducted at the ITS administrative office, 3771 Eastwood Drive, Jackson, Mississippi 39211, or can be conducted via telephone conference call, at the vendor's option. Post-Procurement Reviews normally last between thirty minutes and an hour.

208

Any information in a proposal that was deemed pertinent to the defined evaluation criteria may be summarized for the proposal scoring and included in the project file and/or in a written ITS Board write-up to document the evaluation results. This summary-level information includes (a) total points awarded to each vendor’s proposal in each major scoring category (e.g. technical merit, company resources, value-add, references, cost); (b) the total lifecycle cost computed from each vendor’s cost proposal; and (c) the overall ranking of all proposals. This information is part of the public record and may be reproduced or distributed by ITS without prior notification to proposing vendors. The summary-level cost and scoring information described above is provided at the time of the meeting to vendors requesting a Post-Procurement Review for a given procurement.

ITS requests that vendors understand and conform to the following guidelines for Post- Procurement Reviews: A. ITS will provide detailed information on the evaluation and scoring of the proposal submitted by the participant requesting the review and summary-level evaluation, scoring, and cost information on all other proposals. Note that, while scores for other proposals are public record, the details of any other proposal cannot be revealed without third-party notification; therefore, any specific discussion of scoring or proposal content will be confined to the requesting vendor’s proposal. To ensure consistency and to enable the state to maintain a record of the information we provide under public records, ITS follows a published public records policy for the release of all information other than what can be disclosed in a Post-Procurement Review. A Post-Procurement Review can be conducted prior to or in parallel with fulfillment of public records requests. See Section 019-010 ITS Public Records Procedures for additional information. B. As Post-Procurement Reviews are business meetings, ITS will not have legal staff present. Should a vendor choose to have an attorney present, the vendor must immediately identify that individual as an attorney, whether the attorney is participating via telephone or is present at an in-house meeting. ITS will stop the meeting until a representative of the Mississippi Attorney General's Office can be in attendance.

ITS strongly encourages vendors to schedule Post-Procurement Reviews when they have any questions following contract award. As described above, the meetings can be conducted face-to- face in the ITS offices or via conference call, according to the vendor’s preference. ITS believes these meetings are extremely valuable opportunities for the vendor and the State to exchange information. Among other benefits to vendors, the Post-Procurement Review provides the only mechanism outside the Public Records Procedure for receiving information on the specifics of the evaluation process, including a complimentary copy of the ITS Board written recommendation or similar written information for projects that were not presented to the ITS Board.

ITS has found that these meetings usually clear up any concerns regarding the process and evaluation. If the vendor is not satisfied on these matters during the Review, the vendor then has adequate information to determine if a protest is warranted. Note that the ITS Protest Procedure and Policy requires that a vendor may not file a protest of an Award of Contract without first participating in a Post-Procurement Review with ITS staff.

  1. Post-Procurement Review – As Condition Precedent to Protest

209

ITS Protest Procedure and Policy requires that a vendor may not file a protest of an Award of Contract without first participating in a Post-Procurement Review. See Section 019-020(H) – Filing of Protest. All Post Procurement Reviews held as a condition precedent to a protest will be conducted for the same purposes and in the same spirit and manner as described above.

210

Part 2 Chapter 13: State Holidays Rule 213.1: 023-010 State Holidays

Link for Official State Holidays in Mississippi: Secretary of State: State Holidays

State Offices are typically closed for: • New Year's Day • National Memorial Day • Independence Day • Labor Day • Thanksgiving Day and the following Friday • Christmas Day and the day before or after

ITS offices are usually open, with a reduced staff, on the following holidays: • Martin Luther King's and Robert E. Lee's Birthdays • George Washington's Birthday • Confederate Memorial Day • Veteran's Day Source: 3-3-7

Part 3 Part 3: Enterprise Cloud and Offsite Hosting Security Policy

Chapter 1 General Policy

36 Miss. Admin. Code Pt. 3, R. 1.1 Purpose This document formally promulgates the State of Mississippi Enterprise Cloud and Offsite Hosting Security Policy

The goal of this policy is to improve the security posture of the State by establishing minimum security requirements that all agencies will adhere to, for the utilization of offsite hosting facilities including cloud computing.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 3, R. 1.2 Rule 1.2

Authority To fulfill the statutory requirements for cybersecurity, the State of Mississippi will have a comprehensive cybersecurity program (the Enterprise Security Program) to provide coordinated oversight of the cybersecurity efforts across all state agencies, including cybersecurity systems, services and development of policies, standards and guidelines.

The Mississippi Department of Information Technology Services (ITS) administers the Enterprise Security Program to execute the duties and responsibilities of the cybersecurity program.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 3, R. 1.3 Rule 1.3

Scope This policy applies to all state agencies; State of Mississippi employees; trusted partners; or any entity, as provided by law, authorized to operate, manage, or use State of Mississippi information and information technology (IT) systems (hereafter referred to collectively as “SOM Assets”). Agency is defined as and includes all the various state agencies, officers, departments, boards, commissions, offices, and institutions of the state (§ 25-53-3 (2)(e)). A. This policy includes a subset of technical requirements that are only applicable to agencies participating in the Enterprise State Network. Agencies that do not

participate in the Enterprise State Network, and thus do not have the benefit of the technical controls in place, must develop agency-specific security policies that are: 1. Appropriate to their respective environments, and 2. Consistent with the intent of this policy.

B. This policy addresses information regardless of what form it takes (i.e., electronic, printed, etc.), what technology is used to handle it, or what purpose(s) it serves. C. This policy encompasses systems, automated and manual for which the agencies have administrative responsibility, including systems managed or hosted by third parties on behalf of the agencies.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 3, R. 1.4 Rule 1.4

Cloud and Offsite Hosting Contracts and Amendments Each agency must ensure that new contracts and amendments include the terms and conditions approved by ITS. A. Contracts already in force will be expected to include the terms and conditions approved by ITS at the time of next renewal, modification, or renegotiation. B. The terms and conditions clauses are mandatory for every engagement and exceptions will be considered non-compliant. Agencies can view the mandatory terms and conditions on the ITS website.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 3, R. 1.5 Rule 1.5

Cloud and Offsite Hosting Security Each agency must ensure the implementation of reasonable measures to preserve the confidentiality, integrity, and availability of State of Mississippi information and information technology (IT) systems (hereafter referred to collectively as “SOM Assets”) from unauthorized use, access, disclosure, modification, or destruction. For any measure that the agency cannot directly implement due to the SOM Asset being managed by another organization, contractor, or other source, the agency must implement periodic verification/audit to ensure that the measure is properly implemented. A. Each agency must ensure adherence to all applicable security requirements established by the State of Mississippi Enterprise Security Policy. 1. Each agency must ensure adherence to the baseline security controls for Cloud and Offsite Hosting implementations. The baseline security controls can be found on the ITS website.

B. Each agency must adhere to the following for all assets encrypted at rest. 1. Evaluate the risks with available key location and key management implementations and select the implementation that adequately protects the data; 2. Implement security controls to reduce and mitigate risks when encryption of data at rest is not possible; and 3. Secure and maintain adequate liability coverage when encryption of data at rest is not possible.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 3, R. 1.6 Policy Application Each agency must adhere to all requirements in this policy

A. Each agency shall adhere to the more restrictive policy when conflicts exist between this policy and agency policies. B. Each agency shall determine the level of compliance with this policy and confirm in writing their compliance level in accordance with compliance reporting requirements of the State of Mississippi Enterprise Security Policy. 1. Documentation must include details of where compliance with the requirements of this policy is not met and plans for mitigating the deficiencies.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 3, R. 1.7 Rule 1.7

Maintenance of the State of Mississippi Cloud and Offsite Hosting Security Policy The revision date for this policy is July 1, 2018. A. ITS is responsible for routine maintenance and review of this policy. Routine maintenance and review is required to ensure that this policy is up-to-date with respect to the technological advances and changes in the business requirements of state agencies, potential threats, applicable legislation and other changes that impact information security policies, standards, guidelines and recommendations. A detailed description of the policy and standards review process is included in the Enterprise Security Program document. The Program document is available on the ITS website.

History

  • Source: Miss. Code Ann. § 25-53-201.
36 Miss. Admin. Code Pt. 3, R. 1.8 Rule 1.8

Exceptions to the State of Mississippi Cloud and Offsite Hosting Security Policy, Standards, Guidelines and Recommendations A. The only permitted exceptions to the State of Mississippi Cloud and Offsite Hosting Security Policy are those that are approved in writing by ITS for an agency’s specific purpose and are only applicable to that agency’s operations for the duration of time defined by the exception. A detailed description of the policy and standards exception process is included in the Enterprise Security Program document. The Program document is available on the ITS website. B. Each agency must inquire with the vendor and appropriate agency staff to ascertain if design alternatives, configuration changes, or additional products or services are available to attain compliance prior to submitting a request for an exception. C. Prior to selecting and procuring information technology products and services, each agency must consider all enterprise policies and standards when specifying, scoping, and evaluating solutions to meet current and planned requirements.

History

  • Source: Miss. Code Ann. § 25-53-201.

WIRELESS COMMUNICATION COMMISSION WIRELESS COMMUNICATION COMMISSION

Part 101 Wireless Communication Commission (WCC)

Chapter 1 PURCHASING GUIDELINES AND PROCEDURES

36 Miss. Admin. Code Pt. 101, R. 1.1 Rule 1.1

WCC Purview The following products and services fall within the purview of the WCC and the scope of these purchasing guidelines and procedures:

Technology Examples Radio Frequency Voice: 2-way radio products and services Data: Public safety and emergency services data Cellular Voice: Standard cell phone products and services Data: Blackberry and other PDA devices, including GIS applications (AVL); high speed EVDO Satellite Voice: Primary voice system for MEMA, Wildlife; emergency voice for DEQ, Health, Transportation, Public Safety Data: Mobile units’ use of satellites for Internet connectivity. Traditional point-to-point high-speed data communication across physical locations using wireless access points Data: Wireless communication among physical locations; multi-campus wireless point- to-point; Wi-Fi NOTE: Wireless networks within a building or contained to a single campus are NOT included in WCC purview. IP/RF Dispatch and other hybrid systems

History

  • Source: Mississippi Code Ann. 25-53-171(4)
36 Miss. Admin. Code Pt. 101, R. 1.2 Rule 1.2

Statewide Wireless Contracts In June 2007, the Commission executed a turnkey agreement with Motorola for the implementation of a statewide digital trunked land mobile radio system to be known as the Mississippi Wireless Information Network (MSWIN). The Commission also sponsored and facilitated the establishment of a Master Cellular Agreement with Cellular South, executed in June 2007, for the procurement of cellular products and services.

These statewide contracts may be used by any state or local governmental entity, agency or department within the State of Mississippi for the purchase of wireless products and services as outlined below:

  1. Use of the MSWIN Agreement The MSWIN Agreement may be used as a purchase instrument by governmental entities as follows: a. Any public entity may purchase subscriber and console equipment from the Mobile, Portable, and Dispatch Console Units list under the same rules and regulations as those outlined for the ITS 2-Way Radio EPL. b. Public entities desiring to join MSWIN: To join MSWIN, the public entity must, in conjunction with the Wireless Communication Commission Governance Committee, develop and submit a Wireless Communication Plan (See Attachment A) to the Commission and receive the Commission’s approval for that plan. The WCC will negotiate any necessary change orders required to the MSWIN contract to bring additional entities onto the system.

  2. Use of the Master Cellular Agreement Both ITS and the WCC have approved state agencies, institutions, and governing authorities to purchase products and services from the Master Cellular Agreement with Cellular South without additional oversight by either body and without any dollar limit. State law requires state agencies and IHLs to procure cellular products and services from the Master Cellular Agreement. The Commission strongly encourages other public entities to utilize this contract.

History

  • Source: Mississippi Code Ann. 25-53-171(4)
36 Miss. Admin. Code Pt. 101, R. 1.3 Rule 1.3

Purchases Outside the MSWIN and Master Cellular Agreements To help achieve its legislated goal of effective wireless communication interoperability throughout the state, the Commission has set price thresholds for the review of wireless initiatives outside these statewide contracts prior to any procurement commitment by the purchasing entity.

The Commission encourages all entities to look for opportunities for interoperability with the MSWIN system when considering wireless communication procurements. The MSWIN system is designed to allow the use of any vendor’s P25-compatible radio equipment. The Commission will work with any government body in the state considering radio system purchases to help ensure an appropriate level of interoperability, whether the entity chooses to purchase equipment from the MSWIN Agreement or to purchase P-25 compliant equipment from other vendors and manufacturers.

Purchasing thresholds for WCC review and approval of wireless communication purchases are outlined below.

History

  • Source: Mississippi Code Ann. 25-53-171(4)
36 Miss. Admin. Code Pt. 101, R. 1.4 Rule 1.4

Purchasing Thresholds and Required Approvals The Commission has delegated certain wireless procurements below defined cost thresholds to the purchasing entity and has also established a Wireless Communication Commission Procurement Review Committee (“Committee”) to review purchases prior to or in lieu of full Commission review. The dollar thresholds and approval requirements for all wireless purchases, including those under and those outside the statewide wireless contracts, are set forth below.

Please note that cost ranges are lifecycle costs and should include both initial purchase costs and ongoing expenditures for a reasonable product lifecycle. Both equipment and service charges are included. Maintenance charges for existing equipment do not require WCC approval.

Also note that all approvals by the Committee or Commission are in addition to all requirements of public purchasing law and/or any required ITS approvals.

Radio: Cellular: Other Wireless Purchases: To join the MSWIN system [voice and/or data]: Work with the appropriate WCC Committee(s) to develop Wireless Communication Plan.

Radio Purchases (including use of ITS 2-Way Radio EPL and Mobile, Portable, and Dispatch Console Equipment List from MSWIN contract): • No Committee or Commission approval or review required up to Purchases from Master Cellular Agreement: • No Committee or Commission approval or review required. • No dollar limit.

Purchases OUTSIDE Master Cellular Agreement: • Must have ITS approval prior to presenting to WCC for ANY agency or IHL purchases outside the Master Agreement; • Committee approval required for any purchase • No Committee or Commission approval or review required up to $100,000 per project or fiscal year; • Between $100,001 and $250,000 per project or per fiscal year requires review and approval of Committee; • Greater than $250,000 per project or fiscal year requires preliminary review by Committee and approval of Commission.

$100,000 per project or fiscal year; • Between $100,001 and $250,000 per project or per fiscal year requires review and approval of Committee; • Greater than $250,000 per project or fiscal year requires preliminary review by Committee and approval of Commission.

$75,000 per fiscal year; • Committee review and Commission approval required for any purchase > $150,000 per fiscal year.

Purchases for subsequent radio purchases for projects which have previously been approved by the Committee or Commission may be reviewed for approval as follows:

  1. Subsequent radio purchases up to $100,000 per project or fiscal year may be reviewed for approval by the Executive Officer. 2. Subsequent radio purchases greater than $100,000 per project or fiscal year may be reviewed for approval by the Committee.

History

  • Source: Mississippi Code Ann. 25-53-171(4)
36 Miss. Admin. Code Pt. 101, R. 1.5 Rule 1.5

Submission of Information for Approval For wireless purchases requiring review and approval by the Committee or the full Commission, agencies and institutions under ITS purview should complete the applicable ITS Procurement Request Form. Local governments and other governing authorities not under ITS purview should complete the attached form for wireless purchases requiring Committee or Commission action.

Submit the appropriate form to: Wireless Communication Request, c/o ITS, 3771 Eastwood Drive, Jackson, MS 39211. Requests must be received no later than thirty (30) days prior to the date of the regularly scheduled WCC meeting, the first Thursday of each month, to be considered by the Commission and/or the Committee at that month’s meeting. Requests for subsequent radio purchases for projects that have previously been approved by the Committee or Commission may be submitted to the Commission at any time during the month.

The WCC will return the form to the requesting entity after review, with the Commission’s action noted. Where applicable, approved requests will be forwarded to ITS after Committee and/or Commission action.

History

  • Source: Mississippi Code Ann. 25-53-171(4)
36 Miss. Admin. Code Pt. 101, R. 1.6 Emergency Procurements of Wireless Products and Services A "state of emergency" or "local emergency" as defined in Miss

Code Ann. § 33-15-5 (f) and (g), must exist for such a procurement to be considered an emergency purchase by the Commission. In accordance with Miss. Code Ann. § 33-15-17(b) (1972), as interpreted by the Mississippi Attorney General (Op. No. 2002-0393, August 9, 2002), when any disaster occurs and has been declared in accordance with law, local governments have the power to enter into contracts and incur obligations "necessary to combat such disaster, protecting the health and safety of persons and property, and providing emergency assistance to the victims of such disaster." This power extends to the purchase and rental of equipment as well as the purchase of supplies and materials "without regard to time-consuming procedures and formalities prescribed by law" pertaining to such procurement.

  1. Emergency Procurements by Local Governments: The Commission recognizes that the emergency management law, Miss. Code Ann. § 33-15-17(b) (1972), is the controlling authority and governs wireless communication purchases by local governments during declared emergencies under § 33-15-1 et seq. so long as emergency conditions giving rise to the need for the purchase (combat of the disaster, protection of health and safety of persons and property, and providing emergency assistance to disaster victims) remain in place. When such emergency needs for wireless communication procurement no longer exist, the emergency authority to procure such equipment without compliance with other applicable state law ends as well.

  2. Emergency Procurements by State Agencies: With regard to state agency emergency procurement, the Emergency Management Law, Miss. Code Ann. Section 33- 15-11(b)(17)(1) (1972), requires that the Governor suspend provisions of state laws, rules or regulations prescribing procedures for the conduct of state business before such procedures may be dispensed with. He may do this if strict compliance with the provisions of such procurement statutes, orders, rules or regulation would “in any way” prevent, hinder or delay necessary action in coping with a disaster. When the Governor exercises this authority to suspend public procurement laws for state agencies, the Commission recognizes that the Governor’s Order regarding such suspension is the controlling authority and governs wireless communication purchases for the duration of his order. When the Governor lifts the suspension of these rules, the emergency authority to procure such equipment without compliance with other applicable state law ends as well.

  3. Reporting Requirements for Emergency Procurements: The Commission requires that any state agency or local government procuring wireless communication technology, as defined herein, under the authority of Miss. Code Ann. § 33-15-17(b) or the exercise of the Governor’s authority under 33-15-11(b)(17)(1) (1972), follow the state and federal laws otherwise applicable. The Commission directs the purchasing entity to strongly consider a temporary solution to the emergency need for wireless communication, to be followed by a competitive process for the selection of a permanent solution in accordance with all applicable statutes and the Commission’s rules. For emergency purchases of wireless technology costing more than $100,000, the purchasing entity also shall, within thirty days of the acquisition, inform the Commission of such emergency purchase or

rental, the precise nature of the emergency necessitating the purchase or rental, the exact equipment purchased or rented and its cost.

History

  • Source: Mississippi Code Ann. 25-53-171(4)
36 Miss. Admin. Code Pt. 101, R. 1.7 Rule 1.7

For Assistance For assistance with a wireless procurement, contact the ITS Procurement Help Desk at 601-576- HELP (576-4357).

Attachment A Wireless Communication Plan

[NOTE: Content and format to be developed by QA Consultant and Governance Committee]

History

  • Source: Mississippi Code Ann. 25-53-171(4)

Chapter 2 PUBLIC RECORDS Rule 2.1 Public Records Proposals, books, records, papers, or other documentary materials, regardless of physical form or characteristics, in use, prepared, possessed or retained by the WCC for use in the conduct of its business are public records under Mississippi law and are subject to disclosure to any person making a request thereof, according to the procedures documented below.

36 Miss. Admin. Code Pt. 101, R. 2.2 Rule 2.2

Submission of Requests All requests for information under the Public Records Act and other submissions must be submitted in writing to:

Executive Officer Mississippi Wireless Communication Commission 412 East Woodrow Wilson Avenue, Mail Stop 6601 Jackson, MS 39216-1405 RE: PUBLIC RECORDS REQUEST Please Note: No verbal or telephone requests can be accepted. Because payment must be submitted with the request, email requests cannot be accepted. Requests for Standard Documents, as identified on the Schedule of Fees in Section 5, must be accompanied by payment in the amount specified on the Schedule of Fees. For any Special Request (i.e. any request for information not included in the list of Standard Documents), the request must be accompanied by payment in the amount of $60 to cover the first hour of staff time involved in evaluation and research of the request. This payment is non- refundable and is applied toward the total actual cost of filling the public records request.

History

  • Source: Mississippi Code Ann. 25-53-171(4)
36 Miss. Admin. Code Pt. 101, R. 2.3 Rule 2.3

Timetable for Processing “Working Days” as used herein means Monday through Friday but excludes State recognized holidays mandated by Mississippi Code Annotated, Section 3-3-7,other holidays identified in holiday proclamations published or distributed by the Mississippi Secretary of State, and any other day the offices of state agencies are officially closed for business. Within seven (7) Working Days of receipt of the request, the WCC will do one or more of the following: i. Make the records available for inspection or copying.

ii. If Standard Documents are requested and full payment is received in accordance with the attached Schedule of Fees, send the copies to the requestor.

iii. Acknowledge the receipt of the Special Request and accompanying Special Request fee of $60, and provide a reasonable estimate of the time and cost that will be required to make the records available; for records that do not fall under the provisions of Mississippi Code Annotated Section 25-61-9 regarding Third Party Information notification requirements, the WCC will provide a written explanation if the records cannot be produced within the seven Working Day period.

iv. Provide notice of missing or incomplete payment to the requestor. Requests not accompanied by the appropriate payment will be closed within ten (10) Working Days of the date of the WCC’s notification to the requestor, if payment is not received.

v. If the request is unclear or does not sufficiently identify the requested records, request clarification from the requestor. Such clarification may be requested and provided by telephone, with written follow-up. The WCC may revise the estimate of when records will be available.

vi. Deny the request, with documentation to the requestor as to the reason for denial.

History

  • Source: Mississippi Code Ann. 25-53-171(4)
36 Miss. Admin. Code Pt. 101, R. 2.4 Third Party Information The WCC receives certain information from Third Parties that may be confidential

In compliance with Mississippi Code Annotated Section 25-61-9(1), trade secrets or confidential commercial or financial information is not released until notice has been given to the party submitting the information. When the WCC receives a request to release Third Party Information, the owner of this information is notified of the name and address of the party requesting the information and the nature of the information requested. The requestor also receives a copy of this notification. The Third Party is given twenty-one (21) days from the date the Third Party is given notice by the WCC to either obtain a court order protecting the information as confidential or submit to the WCC a copy of the chancery court filed petition seeking protective order. If a court order or filed petition is delivered to the WCC by this deadline, the WCC will notify the requestor that the information is protected and cannot be furnished. If a court order is not obtained nor a filed petition for protective order submitted, then WCC shall release all

information not protected to the requestor once the deadline has passed and payment for the information has been received from the requestor.

History

  • Source: Mississippi Code Ann. 25-53-171(4)
36 Miss. Admin. Code Pt. 101, R. 2.5 Rule 2.5

Assessment of Costs to Requestor Payment for information requested must be made in advance and must be sufficient to cover the actual costs for the WCC and/or the customer agency/institution to furnish the information. Such costs include, but are not limited to, staff and/or counsel time to evaluate and research the request, to retrieve any relevant files, to organize the information, to notify any Third Parties, to develop a cost estimate and schedule, to reproduce the material, and to deliver the information requested. Payment must be in the form of a certified check, money order, or corporate check made payable to the WCC for the amount specified. No cash or personal checks can be accepted. Should the actual cost of producing the requested information exceed the estimate provided, the requestor will be notified of the additional amount due before the WCC provides the information.

History

  • Source: Mississippi Code Ann. 25-53-171(4)
36 Miss. Admin. Code Pt. 101, R. 2.6 Schedule of Fees Standard Documents:

Printed Copy of RFPs $25, plus actual cost of reproducing any oversized diagrams or other special attachments Copy of RFPs on CD in Microsoft Word format $25 for Word document; any oversized diagrams or other special attachments will be reproduced on paper or electronically at actual cost Paper copy of a project contract, excluding confidential exhibits $25 Special Requests and Variable Costs:

Evaluation & research payment (Due with the submission of Public Records requests for special requests and is applied toward the actual cost of filling the Public Records request) $60 Fees for fulfilling Special Requests, based on the expense categories below: Quoted individually upon receipt of written request and $60 evaluation and research payment (above). In-house photocopies $0.20 per page (paper/copier fee); actual cost for color copies CD (with .doc, .xls, or .pdf files of requested information) $5.00 per CD (media fee) Postage, UPS, Federal Express* Actual Cost Staff time Actual staff time required to provide all services to fulfill the Public Records request, including but not limited to researching; providing notifications; and compiling, copying, scanning, and delivering requested information, at staff members' hourly rates ($60 - $75 per hour) Computer processing Actual Cost Temporary agency personnel* Actual Cost

Reproduction cost by outside print facility* Actual Cost Attorney time Actual Cost *The WCC may request that payments for outside services be made by the requestor directly to the company or person providing the services.

History

  • Source: Mississippi Code Ann. 25-53-171(4) 44820268.v1

Chapter 3 MSWIN PTT USER FEE

36 Miss. Admin. Code Pt. 101, R. 3.1 Purpose:

REPEALED Effective 07/13/2012

Chapter 4 ENCRYPTION

36 Miss. Admin. Code Pt. 101, R. 4.1 Purpose:

The purpose of this policy is to establish guidelines for encryption of PTT devices and talk groups.

History

  • Source: Mississippi Code Ann. 25-53-171(4)
36 Miss. Admin. Code Pt. 101, R. 4.2 Background:
  1. The Mississippi Wireless Communication Commission (WCC) is implementing a statewide survivable, reliable, interoperable wireless communication system known as the Mississippi Wireless Information Network (MSWIN).

  2. The MSWIN is equipped with over-the-air rekeying (OTAR) capabilities allowing authorized encrypted PTT devices (subscriber units) to be rekeyed over the air without physically touching the device. Encryption keys must initially be loaded locally with ‘Key Loader’.

  3. Vendors may offer proprietary encryption software in their equipment as a no- cost option. The proprietary nature of the software will not allow the use of the over the air re-keying feature or interoperability with other vendor’s devices in the encryption mode.

  4. The use of vendor specific proprietary encryption software limits users’ choices for PTT devices and other equipment to that vendor.

  5. The WCC has adopted the AES encryption software as the preferred system encryption software and discourages the use of vender proprietary encryption software.

History

  • Source: Mississippi Code Ann. 25-53-171(4)
36 Miss. Admin. Code Pt. 101, R. 4.3 Procedure:
  1. The user must notify the MSWIN Liaison of the user’s desire to encrypt the operation of PTT devices.

A. The notification will include the number of talk groups, the type of encryption, and the device identification. B. The user must state if encryption will be operator selected or the talk groups will be in encrypted mode full-time. C. Non-AES encrypted devices must be programmed for operator selection only.

  1. Special event talk groups will not be encrypted.

History

  • Source: Mississippi Code Ann. 25-53-171(4)

Chapter 5 NARROW BAND – TDMA SUBSCRIBER DEVICES

36 Miss. Admin. Code Pt. 101, R. 5.1 Purpose:

The purpose of this policy is to establish guidelines for use of FDMA and TDMA subscriber devices on MSWIN.

History

  • Source: Mississippi Code Ann. 25-53-171(4)
36 Miss. Admin. Code Pt. 101, R. 5.2 Background:
  1. The Mississippi Wireless Communication Commission (WCC) is implementing a statewide survivable, reliable, interoperable wireless communication system known as the Mississippi Wireless Information Network (MSWIN).

  2. The WCC adopted the P-25 Phase 2 TDMA narrow banding technology and will retro-fit existing equipment or install TDMA equipment upon availability, anticipated to be June 2012.

  3. TDMA will increase the capacity for existing tower equipment two fold with minimal expense.

  4. Multiple Vendors offer P-25 Phase 2 ready subscriber equipment as well as P-25 Phase 2 capable (up-gradable) subscriber units.

5.3 Procedure:

  1. New subscriber or other equipment purchased for operation on the MSWIN must be TDMA capable or equipped.

  2. Users operating TDMA capable devices, on MSWIN, must upgrade the devices within 90 days of notification that MSWIN has initialized TDMA.

  3. Users operating non-TDMA capable devices, on MSWIN, must contact the MSWIN Liaison and cooperate in the development of a migration or usage plan to minimize the capacity impact of the continued use of the non-TDMA devices on the MSWIN system.

  4. Users operating non-TDMA capable devices, with MSWIN special event talk groups, for emergency or short term event interoperability, must contact the MSWIN Liaison and agree to specific use guidelines.

History

  • Source: Mississippi Code Ann. 25-53-171(4)
  • Source: Mississippi Code Ann. 25-53-171(4)

Chapter 6 MSWIN INTEROPERABILITY PATCH

36 Miss. Admin. Code Pt. 101, R. 6.1 Purpose:

The purpose of this policy is to define a Mississippi Wireless Information Network (MSWIN) Interoperability Patch and establish operational procedures.

History

  • Source: Mississippi Code ANN. 25-53-171(4)
36 Miss. Admin. Code Pt. 101, R. 6.2 Background:

Patching the MSWIN system for normal operations creates a high risk of degrading the availability of both the MSWIN and agency’s resources. Patching to MSWIN will be strictly monitored and controlled. The implementation and operation of the patch hardware, interface, radio, labor, etc. is the responsibility of the requesting agency. The MSWIN network manager will assign talk groups during large events, including training sessions, requiring more talk group resources than is available from the regional special event talk groups, including the state-wide special event talk group.

  1. A MSWIN Patch is defined as an interface between the MSWIN system and any non- MSWIN radio or audio source to provide audio communications between disparate systems, or connecting two or more MSWIN talk groups.

A. Patching can interconnect the MSWIN to a PBX or other telephone system, cell systems, the internet, satellite phones or another agency’s communication system.

B. In most cases network patches can be accomplished through dispatch consoles or external gateway devices.

  1. Approved MSWIN Patches

A. Temporarily Established Patches

a. A patch for a specific event and disconnected at the conclusion of that event.

i. Example 1: Patching a channel from an agency responding from out of state to a MSWIN agency talkgroup. ii. Example 2: A high speed pursuit crossing jurisdictional line requiring talkgroups from different law enforcement agencies to be patched to MSWIN.

B. Permanently Established Patch

a. Patch is set up without regard to an event, designed to remain in place with no time frame for disconnecting.

History

  • Source: Mississippi Code Ann. 25-53-171(4)
36 Miss. Admin. Code Pt. 101, R. 6.3 Procedure:
  1. Any agency or private sector emergency response organization desiring to operate on MSWIN or having access to Special Event talk groups, will, through an authorized representative, execute the Mississippi Interoperability Channel Plan (MICP) Memorandum of Understanding prior to the issuance of system identification numbers.

  2. The MSWIN network manager will be notified prior to the use of the state-wide special event talk groups. In the event of an emergency the network manager will be notified as soon as possible.

  3. Depending on the event regional MSWIN special event talk groups should be utilized prior to state-wide MSWIN special event talk groups.

  4. Temporarily Established Patches

A. No prior approval is required for MSWIN member agencies establishing temporary patches to their own talk groups.

B. The MSWIN network manager will be notified of any temporary patch in place for more than twelve hours.

C. The patch must function in a technically and operationally consistent manner.

a. The release time between messages should be less than 4 seconds. b. The audio quality should be a close representation of the original audio as heard on a typical subscriber radio. c. The audio shall be free of hum, clicks, or other extraneous noise. d. There shall be no clipping of the first syllables or loss of audio through the patch.

D. The agency will continuously monitor and respond to calls on the patch.

E. Although necessary, patches have the ability to degrade the performance of the MSWIN system, as such; agencies are requested to disconnect temporary patches as soon as possible.

  1. Permanent Patches

A. The MSWIN network manager must approve permanent patches prior to implementation. The possible impact on the MSWIN Grade of Service (GOS) and other users will be considered prior to the approval.

B. Permanent patches are to remain active at all times on the talk groups specified within the MOU. This requirement is to provide the users with a consistent and functioning communications path.

C. When utilizing external patching devices or bridging equipment such as an ACR 1000, only one talk patch will be programmed into a permanently patched MSWIN interface radio.

D. The patch must function in a technically and operationally and consistent manner. Guidelines in section 4A – 4C.d are applicable for permanent patches.

  1. Network Patch Communications Request

A. When an agency needs to perform a temporary/permanent patch lasting more than twelve hours to MSWIN, requiring no MSWIN assistance, the agency must provide the MSWIN manager the following:

• Agency requesting network patch. • Contact information for the requesting agency. • Reason for request/event type description. • Details of the patch including the types of systems. Frequencies, or talk groups. • All involved agencies requiring interoperability. • Expected duration of event. • Bridging equipment physical locations.

B. Agency to MSWIN requiring MSWIN assistance

a. Agencies may request use of the technical resources from MSWIN by providing the information as required in Section 6A.

C. The National Incident Management System (NIMS) procedures should be followed by the Incident Commander and MSWIN personnel.

a. Avoid using an agency’s primary dispatch channel. b. Require participating agencies to check in at the command post and provide portable radios and frequency/talk group channels for use during the incident to the Communication Unit Leader (COML). c. Assign radio call sign/designator information to connected agencies. d. Instruct MSWIN on where to setup and operate the tactical equipment if assigned.

e. Inform MSWIN personnel which agencies are participating. f. Provide MSWIN with agency provided radios and an Incident Command Structure (ICS). g. Confer with MSWIN personnel concerning what command level or other specific talk groups should be patched.

History

  • Source: Mississippi Code Ann. 25-53-171(4)
36 Miss. Admin. Code Pt. 101, R. 6.4 Network Patch Deactivation
  1. When interoperable communications are no longer required, agencies should follow these guidelines:

A. The Incident Commander or designee shall:

a. Make an announcement on the command channel to all, advising them that the network patch is being deactivated. b. Contact the MSWIN or console operator to shut down the network patch.

  1. Individual agencies are responsible for retrieving the portable radios and associated equipment provided during the operation.

History

  • Source: Mississippi Code Ann. 25-53-171(4)
36 Miss. Admin. Code Pt. 101, R. 6.5 Problem ID and Resolution
  1. If an issue or problem is identified during the network patch, the MSWIN network manager will determine who will take corrective action. If the issue or problem cannot be identified, the network manager shall contact the appropriate technical personnel.

History

  • Source: Mississippi Code Ann. 25-53-171(4)
36 Miss. Admin. Code Pt. 101, R. 6.6 Network Patch Test Procedures
  1. To ensure that equipment components of the network patch operate properly, each agency will test their resources according to their agency’s individual policies and procedures. Below are recommended procedures: A. Representatives from each agency should meet on a regular basis to test communications.

B. Testing should include deployment, setup, operation, and deactivation of the network patch. C. Agency representatives should arrive at the test location to test their ability to communicate with other agencies utilizing the patch.

History

  • Source: Mississippi Code Ann. 25-53-171(4)
36 Miss. Admin. Code Pt. 101, R. 6.7 Grade of Service
  1. If a patch negatively impacts the MSWIN GOS, MSWIN may remotely disable a patch after attempting to rectify the problem and in the case of a permanent patch only after 30 days written notice. 2. In the event of an emergency, as determined by the MSWIN network manager, the patch radios will be immediately disabled. The MSWIN network manager will make a good faith effort to notify the agency.

History

  • Source: Mississippi Code Ann. 25-53-171(4)

Chapter 7 MSWIN BROADBAND PTT INTERFACE POLICY

36 Miss. Admin. Code Pt. 101, R. 7.1 Rule 7.1

Purpose The Wireless Communications Commission (WCC) understands the benefits of a broadband push-to-talk (PTT) interface to the Mississippi Wireless Information Network (MSWIN), and desires to provide that interface in a way that preserves the integrity of the mission critical nature of the Land Mobile Radio (LMR) functionality of the system. PTT over Public Safety Broadband interfaced devices shall not be used as replacement for, or in lieu of P25 radios for mission-critical public safety communications.

History

  • Source: Mississippi Code Ann. 25-53-171(4)
36 Miss. Admin. Code Pt. 101, R. 7.2 Proper Use The WCC considers broadband PTT operation as secondary to traditional LMR operation on the MSWIN system

As such, it should not be used for mission critical communications. If broadband PTT traffic compromises or interferes with LMR traffic, the WCC reserves the right to break the connection to the broadband PTT system without prior notice or guarantee of restoration timeline. Problems with broadband PTT system operation should be reported first to the carrier or provider of that service, and only if that investigation points to the MSWIN interface should the issue be escalated to WCC staff. Broadband PTT issues, being secondary in nature, will be addressed only during normal business hours.

History

  • Source: Mississippi Code Ann. 25-53-171(4)
36 Miss. Admin. Code Pt. 101, R. 7.3 Rule 7.3

Methodology The Wireless Communications Commission has procured a broadband PTT interface to the MSWIN system that gives the WCC centralized control over all connections, and this interface is the only approved method for connecting broadband PTT into MSWIN. This system, called Critical Connect and provided by Motorola Solutions, is a cloud-based arbiter of external system connections, and provides a portal for control and management of individual LMR talkgroup to broadband PTT talkgroup patches. This centralized, managed interface gives the WCC the granular control needed to assure proper use of broadband PTT connections.

History

  • Source: Mississippi Code Ann. 25-53-171(4)
36 Miss. Admin. Code Pt. 101, R. 7.4 Rule 7.4

Existing User Considerations The WCC understands that some local users of the MSWIN system have procured broadband PTT solutions that interface with MSWIN via donor radios. This type of solution is not allowed under the terms of this policy. However, in order to allow for the graceful transition of users of donor radio based broadband PTT interface systems to the centralized interface system described in this policy, existing users of these systems will be given a five-year grace period to transition to a system with a Critical Connect interface. This exception only applies to donor radio-based systems already in use at the time of publication of this policy.

History

  • Source: Mississippi Code Ann. 25-53-171(4)

Poursuivez vos recherches dans ChatGPT ou Claude

Connectez Omnilex pour rechercher dans le corpus juridique depuis votre assistant IA.