City of Calgary / RFP 25-1667 / Independent response QA
Security incident response checklist
A bidder-side control list for the Corporate Security Incident Management System procurement.
Public scope
Show how one secure platform controls the full incident lifecycle.
Intake to closure
Trace intake, triage, investigation, resolution, closure, ownership, exceptions, and escalation evidence.
Dispatch and field work
Map dispatch, scheduling, mobile access, field updates, advisory services, and task accountability.
Hybrid integrations
Show the integration approach for Azure, OneDrive, Exchange Online and on-premises, and NetApp MetroCluster.
Govern and improve
Connect role-based access, audit logs, retention, reporting, analytics, intelligence, and AI claims to specific evidence.
Evidence map
Turn every capability claim into something an evaluator can verify.
Use one matrix to connect the buyer's requirement, your response location, the evidence source, its owner, and the final QA state.
The official notice, procurement documents, and any buyer-issued amendments control. Verify them before submission.
| Control area | Evidence to map | Final check |
|---|---|---|
| Security and accessHybrid controls | Architecture, roles, logging, retention, privacy, and security documents | Claims match the cited source |
| Incident lifecycleIntake through closure | Configuration examples, forms, routing, dispatch, exceptions, and reports | Every step has an owner and outcome |
| IntegrationNamed systems | Azure, OneDrive, Exchange, NetApp, APIs, monitoring, and failure handling | Dependencies and assumptions are explicit |
| DeliveryImplementation and support | Plan, roles, milestones, training, handoff, and service model | Dates, attachments, and pricing reconcile |
Response control
Three passes before the package is locked.
- 1
Trace requirements
Assign each requirement to a response location, evidence source, owner, and status.
- 2
Challenge gaps
Find unsupported claims, missing dependencies, contradictory statements, weak proof, and unclear responsibilities.
- 3
Lock submission controls
Reconcile forms, attachments, pricing, approvals, file names, amendments, and portal timing.
Independent review
Bidder-side QA, not buyer guidance.
TinyOps Studio is not affiliated with or endorsed by the City of Calgary or CanadaBuys. The buyer's official documents and amendments control.
The bidder owns eligibility, solution design, claims, pricing, legal review, signatures, approvals, and final submission. TinyOps does not need sensitive incident data or production-system access.
Fixed-scope response support
Turn the solicitation into a controlled response package.
Buy the one-business-day RFP Compliance Gap Scan for $149, or reserve the $2,500 Proposal Response Accelerator for a requirements matrix, response outline, evidence map, red-team gap review, and final submission QA.