Laserfiche WebLink
Page 11 of 26 <br />2.5 RISK ASSESSMENTS <br />At a minimum, Everett Transit expects that the consultant will conduct multiple risk assessments for the <br />five areas listed in2.4, project scope that will include the following sections. <br />1. Identification of: <br />a. Critical assets <br />b. Threats <br />c. Vulnerabilities <br />d. Likelihood of an attack or incident <br />e. Consequences and impacts of an attack or incident. <br />f. Identifying potential mitigation measures/countermeasures <br />2. Assigning the initial risk index to determine the basis for risk decision criteria. <br />3. Determining residual risk acceptability <br />2.6 DELIVERABLES <br />The expectation is that the comprehensive Threat and Vulnerability Assessment (TVA) will include at a <br />minimum the following information: <br />1. Comprehensive Threat and Vulnerability Assessment for Everett Transit’s system and assets and <br />master plan for prioritized implementation of findings from the assessment. <br />a. Comprehensive security report that addresses each site’s specific threat vulnerabilities and <br />countermeasure recommendations. <br />b. Policy recommendations. <br />2. Detailed estimate of costs to implement the findings. <br />2.7 MEETINGS <br />The Supplier will conduct a variety of meetings that fall into the following categories: <br />1. Meetings with internal and external stakeholders to gather input. <br />2. Monthly status updates with the project manager <br />2.8 SUPPLIER RESPONSIBILITIES <br />The supplier will report to the Project Manager. The Supplier will provide internal communications and <br />messages in the form of oral and written memos to the Project Manager as needed. <br />2.9 CITY OF EVERETT RESPONSIBILITIES <br />City staff will be responsible for the following: <br />• Providing a primary contact for the Supplier. <br />• Provide background and requirements. <br />• Provide existing available data and reports to support analysis. <br />• Provide existing background data. <br />• Coordinate review of consultant deliverables. RFP