Title
Information Technologies Department recommending the Board approve and authorize the Chair to execute Amendment I to Agreement 6418 with Foresite MSP, Inc. to continue providing cyber security monitoring and risk assessment services for an additional three-years from March 16, 2023, through March 15, 2026, with an increase to total compensation in the amount of $142,500, making the new not-to-exceed amount of $239,000 and lowering the Security Operation Center services rate.
FUNDING: General Fund.
Body
DISCUSSION / BACKGROUND
On March 15, 2022, the Board approved item 22-0336 authorizing the Chair to execute Agreement 6418 with Foresite MSP, Inc.to provide cyber security monitoring and risk assessment services for the term of March 16, 2022, through March 15, 2023 for a not-to-exceed amount of $96,500.
Foresite provides cost-effective and advanced cyber defense services for U.S. counties, states, and small business organizations, such as security monitoring, threat detection and analysis, log retention and management, incident alerting and response, mitigation recommendations, and on-call technical support. Foresite’s Integrated Risk Management Features (FIRM) also provides solutions such as risk assessments, automated policy scoring and reviews mitigation plans aligned to compliance framework, technology gap assessments, and safebreach attack simulations and environment testing. Foresite provides El Dorado County with advanced security operations through 24/7/365 Security Monitoring and Support Services (SMSS) protecting the County against complex threats via the managed IT Security Operation Center (SOC). Foresite also provides Security Information and Event Management (SIEM) offering real-time analysis of our infrastructure and continuous monitoring of cyber threats. Foresite will also provide a one-time high-risk assessment of our security environment, including a gap assessment, action plans, and consulting services.
The proposed Amendment to the Agreement will continue these services for an additional three years for the period of March 16, 2023, through March 15, 2026, with an increase to the not-to-exceed in the amount of $142,500, making the new not-to-exceed $239,000. Extending the SOC services for an additional three-years will provide stability for Countywide network security and lock-in pricing at a low-rate. The original agreement allowed for a one-year extension of our SOC services at $50,000 for the second year. The proposed amendment allows for a three-year extension of our SOC services at $47,500 per year, which is a reduced rate.
ALTERNATIVES
The Board could refuse to sign this amendment, which would terminate our countywide cyber security monitoring services, and the County would need to determine an alternative way to provide 24x7 security monitoring and oversight.
PRIOR BOARD ACTION
22-0336 - March 15, 2022
OTHER DEPARTMENT / AGENCY INVOLVEMENT
Reviewed by County Counsel and Risk Management.
CAO RECOMMENDATION / COMMENTS
Approve as recommended.
FINANCIAL IMPACT
Appropriations are included in the Information Technologies FY 2022-23 Budget for ongoing security monitoring services.
CLERK OF THE BOARD FOLLOW UP ACTIONS
Clerk of the Board to obtain the Board Chair's signature on one copy of Amendment I to Agreement 6418 with Foresite MSP, Inc. and return to the Chief Administrative Office, Central Fiscal Unit, Attention: Kelley Lawrie.
STRATEGIC PLAN COMPONENT
Good Governance.
CONTACT
Tonya Digiorno, Director of Information Technologies