Sample
RFP
Outline
Seeking
a
Mobile
Consumer
Application
Platform
Provider
1. Introduction
1.1 Purpose
1.2 Proposal
Evaluation
Process
1.3 Scheduled
Timetable
&
Coordination
1.4
RFP
Instructions
2. Company
Background
(to
be
filled
out
by
issuing
company)
Company
Overview:
Business
Objectives:
Objectives
for
the
mobile
initiative
include:
Scope
of
Project:
RFP
Services
Requested
Overview
Timing
of
Project:
Expected
Usage:
ie,
Global,
Region,
Local
3. Company’s
Technology
Environment
Overview
of
company’s
technology
environment
and
existing
mobile
infrastructure
(if
any).
4. Business
Functionality
Requirements
4.1 Overview
The
goal
of
the
mobility
solution
is
to
enable
an
integrated
online
and
mobile
experience
that
provides
mobile
users
with
access
to
a
substantial
subset
of
capabilities
currently
available
to
online
users.
The
mobility
solution
must
deliver
two
key
capabilities:
• The
ability
to
mobile
enable
existing
websites:
o View
Products
o E-‐commerce
o User
Registration
o Sign-‐in
• The
ability
to
develop
native
mobile
phone
applications
that
integrate
with:
o View
Products
o E-‐commerce
o Push
Notification/Support
of
Marketing
Initiatives
4.2 Mobile
Web
Requirements
Solution
needs
to
support
various
mobile
browsers
and
more
than
8,000
device
types
including
iPod
Touch,
iPad,
etc.
4.3 Native
Application
Development
Requirements
State
OS/devices/apps
the
company
wants
to
support,
i.e.
(iPhone,
Android,
BlackBerry,
Symbian,
Palm,
Windows
Mobile,
etc.)
The
native
application
must
have
the
ability
to
integrate
with
existing
web
sites
and
well
as
with
back-‐end
systems
or
third-‐party
systems.
4.4 Technical
requirements
The
vendor
platform
must
also:
• Enable
the
look
and
feel
of
the
mobile
web
application
to
be
modified
• Enable
the
look
and
feel
of
the
native
mobile
application
to
be
modified
• Enable
changes
to
the
user
interface
• Enable
the
integration
with
third
party
APIs
• Support
multiple
languages
and
character
sets
• Enable
the
creation
of
a
framework
to
which
new
mobile
features
can
be
added
while
providing
users
with
a
consolidated,
seamless
user
experience
5. Mobile
Platform
Technology
Environment
Please
provide
an
overview
of
the
solution
and
the
associated
architecture.
Describe
in
detail
each
component
in
the
application
architecture,
the
integration
between
components
and
the
technical
environment
that
supports
this.
5.1 Mobile
Application
Platform
5.1.1 Core
Product
Technologies
1. How
does
the
product
architecture
support
performance
and
scalability?
Please
provide
benchmarking
information.
2. What
mobile
technologies
are
supported
by
the
core
product?
Please
provide
a
complete
list
of
technologies
supported
to
date
and
technologies
in
the
product
roadmap
(WAP,
SMS,
Rich
Clients-‐
iPhone,
Android,
J2ME).
3. How
large
is
the
device
database
maintained
for
the
core
product,
how
is
it
updated?
What
level
of
detail
is
included?
How
is
device
detection
performed?
4. What
mobile
browsers
are
supported
by
the
product?
5. What
media
types,
MIME
types
are
supported
by
the
core
product?
How
does
the
product
handle
resizing
images
to
fit
mobile
devices.
6. What are the SLAs around supporting device OS changes (Blackberry 5.0 to 5.1, for example)?
7. What are the SLA’s around new device OS versions (iPhone 3.0 to 4.0 for example)?
8. What are the SLA’s around new device types?
9. How does the platform support moving the existing application/web site to new devices and/or
new OS versions?
10. Assuming that the initial implementation will be mobile web, what additional effort will be
required to build fully native application upon completion of the mobile website? (not “wrapper”
type applications, but full downloadable native applications). Address specifically:
a. iPhone
b. Android
c. BlackBerry
d. Symbian (for global markets)
e. Support for non-mobile channels? Ex: Social Media integration, etc.
f. Mention any other device types that may be of interest, and that the company supports, or
plans to support in the future.
11. As a follow-on to question 8), is your system capable of taking advantage of the entire suite of
native capabilities of the device (both for mobile web, as well as native rich apps)? What about
your graphics capabilities? GPS? Please explain.
12. Is your system capable of supporting multiple applications, mobile web sites, and other channels
from a single application definition? Please explain.
13. How many mobile systems do you support and optimize for, addressing specifically the device
Fatypes, device form factors, browser types, and operating systems that you support? Please
explain. In addition, please explain your real time optimization capabilities.
14. Production level support – are you staffed for 365/24/7 production level support? Explain.
15. What type of real time communication systems do you support for mobile devices, including:
a. SMS/MMS (one way and two way)
b. Alerts
c. Advertising
16. Is your system a commercial software system, or will your proposed application be built as a
custom system?
17. Although the initial implementation will be English, what other languages do you support?
What will the process and level of effort be to support a new language.
18. What are your capabilities with regards to making secure transactions over mobile web,
especially with regards mobile commerce?
19. Are you able to do both Hosting and on-premise deployments? Please explain your approach to
both.
20. What are the back end data systems that your system depends on? (e.g., web servers, database,
etc). Which of your systems are based on open system standards?
21. Are your production systems part of a single platform?
22. Please explain the redundancy, failover and other mission critical elements of your architecture to
prevent downtime.
23. Do you license your development tools, so that the company can develop or enhance the mobile
systems built using your technology?
24. What are the data integration capabilities of your solution? How do you accomplish data
integration? Specifically, what experience do you have in:
a. Scraping all data sources in a commercial web site?
b. Integrating with web services?
c. Integrating with proprietary data repositories behind a firewall?
d. Mix and match multiple data sources using any one or all of a, b, and c above?
5.1.2 Security
1. How
does
the
core
product
enable
secure
transactions
on
mobile
devices?
2. What
approaches,
from
a
security
standpoint,
does
the
core
product
support
for
integrating
with
existing
e-‐Commerce
platforms?
(credit
card
security,
SSL,
etc)
3. How
does
the
core
produce
deal
with
session
management?
(e.g.
does
the
middleware
piece
emulate
a
client
browser
and
keeps
session
state)
5.1.3 APIs
1. What
types
of
APIs/Web
Services
are
supported
by
your
product
when
connecting
to
existing
applications?
(REST,
SOAP,
etc).
2. How
does
the
product
enable
integration
with
native
phone
capabilities?
(e.g.
GPS,
camera,
accelerometer,
voice
services).
Can
users
make
calls
from
web
based
applications
or
native
applications?
(e.g.
click
on
phone
number
to
make
call)
5.1.4 Integration
Capabilities
1. How
is
the
look
and
feel
customized
(does
this
require
development)?
2. In
case
the
core
product
support
native
applications
on
rich
clients
such
as
iPhone
and
Android,
how
does
the
product
allows
for
integration
with
existing
web
sites
and/or
services?
(screen
scraping,
using
existing
web
service
APIs,
etc)
5.1.5 Analytics/Reporting
1. Do you support out of the box reporting/analytics? If so, what types of information is used for
the reports? Do the reports show the mobile device used? Are you able to track Mobile web vs.
Native on–device apps usage?
5.1.6 Scalability
1. How
can
the
hosting
infrastructure
be
scaled?
2. How
does
scaling
impact
licensing?
3. Does
the
core
product
support
load
balancing?
If
so,
what
kind
of
load
balancing?
(software,
hardware)
5.1.7 High
Availability
1. How
does
the
core
product
achieve
a
highly
available
environment
(>
99.9%)
2. Does
the
core
product
support
clustering?
If
so
what
clustering
technologies?
5.1.8 Internationalization
1. How
does
the
core
product
support
internationalization?
5.1.9 Monitoring,
Notification
and
Troubleshooting
1. What
components
can
be
monitored
within
the
product?
2. What
events
can
generate
a
notification
within
the
product?
5.1.10 Accessibility
1. What
accessibility
guidelines
and
standards
does
the
core
product
complies
with?
6. Implementation
Services
Please
describe
the
implementations
services
provided
to
implement
the
functionality
described
in
previous
sections.
The
implementation
services
include
§ Deployment
and
configuration
of
the
mobile
web
platform
§ Customization
of
the
mobile
website
forms
§ Custom
software
development
to
develop
items
such
as
native
mobile
phone
applications
for
various
mobile
operating
platforms,
integration
interfaces,
reports,
and
security
Based
on
the
technical
requirements
defined
in
the
sections
above
please
provide
in
detail
the
methodology,
the
effort,
and
the
resources
required
to
deploy
the
solution.
For
all
of
the
development
work,
please
describe
the
type
of
development
work
expected
and
the
associated
quantity.
6.1 Implementation
1. What
is
the
implementation
methodology
used?
Please
describe
the
specific
phases,
steps,
and
artifacts.
2. Provide
a
high
level
project
plan
for
implementing
the
solution
showing
all
phases
of
the
SDLC
(e.g.
planning,
design,
development/build,
test,
deploy).
Include
the
effort
showing
high-‐level
milestones,
work
packages,
and
dependencies.
Please
use
Microsoft
Project
to
detail
the
plan
to
the
week
level.
Provide
staffing
levels
on
a
per
week
basis.
3. What
would
be
the
project
organization?
Describe
the
different
types
of
roles
and
the
number
of
resources
needed
for
each
role?
Please
provide
a
staffing
model
for
the
duration
of
the
project
and
an
organization
chart.
4. List
any
other
parties
that
will
participate
in
the
deployment
and
describe
in
detail
their
roles.
5. What
type
of
post
implementation
support
does
the
Vendor
provide
as
a
warranty
for
the
solution?
How
long
is
this
provided
and
what
is
the
team
that
would
provide
the
support?
6. What
testing/QA
capabilities
does
the
vendor
provide?
(e.g.
unit
testing,
functional
testing,
performance/load/stress
testing).
What
environments
are
provided
by
the
vendor
and
what
environments
are
needed
from
the
company?
(DEV,
QA,
etc).
7. What
tools
does
the
vendor
use
to
test
mobile
applications
on
the
different
devices
supported
in
their
device
database?
(e.g.
device
emulators)
7. Hosting
Services
Please
describe
how
the
solution
is
hosted
(if
required),
including
management,
administration,
and
maintenance
of
the
technology
environment
that
supports
all
aspects
of
the
solution.
7.1 Hosting
Capabilities
1. Describe
the
services
provided
(complete
set
of
services,
specific
services
to
support
our
solution,
experience
with
providing
services)
2. Describe
the
operating
Model
(organization,
processes,
and
tools)
3. Confirm
the
service
levels
can
be
achieved
(availability,
performance)
4. How
does
the
technical
environment
support
the
service
levels?
Describe
the
environment
in
detail.
Please
include
metrics
for
the
previous
year
showing
availability
(planned
and
unplanned)
and
performance.
5. Describe
in
detail
the
security
aspects
of
the
hosted
environment
and
the
independent
audit/security
certifications
of
the
environment.
6. Are
the
hardware
components
dedicated
or
shared?
If
it
is
shared
how
do
ensure
the
security,
service
levels,
and
scalability
requirements?
8. INFORMATION
SECURITY
REQUIREMENTS
Please
respond
with
your
capabilities
to
comply
with
the
following
requirements:
Requirement
Response
Control
access
to
Confidential
Information
Vendor
shall:
v
Maintain
appropriate
barriers
between
untrusted
networks
such
as
the
Internet
and
systems
containing
Confidential
Information,
including:
Establishing
a
Demilitarized
Zone
(DMZ)
between
the
untrusted
Internet
and
the
Business
Partner
internal
network
where
a
where
the
data
resides.
This
three-‐tire
architecture
will
provide
another
layer
of
protection
to
confidential
information
by
placing
that
information
behind
a
second
firewall
Installing,
configuring
and
monitoring
system
configuration,
firewall
(intrusion
prevention)
and
intrusion
detection
software
protecting
systems
where
Confidential
Information
is
stored
or
processed.
Maintaining
a
written
network
diagram
showing
all
equipment,
tools
and
media
where
Confidential
Information
is
processed
or
stored.
Adhere
to
a
comprehensive
policy
and
procedure
to
audit
logs
of
all
monitoring
tools
and
to
resolve
any
unauthorized
access
attempts.
Ensure
physical
security
of
facilities
where
Confidential
Information
is
stored
Vendor
shall:
Create
the
appropriate
number
of
layers
of
physical
security
between
unauthorized
people
and
systems
which
store
or
process
Confidential
Information
(e.g.
for
most
purposes,
the
appropriate
number
of
layers
will
be
three).
Maintain
at
least
one
monitoring
layer.
Protect
and
ensure
secure
treatment
of
each
Party’s
systems
The
information
security
standards
for
the
internal
operations
of
the
party,
whose
systems
will
be
accessed
by
the
other
party
to
perform
its
obligations
under
the
Agreement
will
apply.
9. SERVICE
LEVEL
REQUIREMENTS
Please
respond
as
to
your
capabilities
to
comply
with
the
following
requirements:
Requirement
Response
Service
Desk
Call
Procedures:
In
the
event
of
a
service
interruption
or
problem
reporting.
Escalation
Procedures:
In
the
event
of
an
outage,
both
at
a
Management
and
Technical
levels
System
Support
Hours
of
Operation:
Please
provide
all
locations
involved
in
the
support
of
the
application
Standard
Maintenance
Window:
(example:30th
of
each
month
3
hour
duration)
Unscheduled
Maintenance
Window:
Please
provide
communication
vehicle
and
how
much
lead
time
to
the
client.
Disaster
Recovery:
Please
provide
your
DR
site
location,
annual
DR
testing
schedule,
recovery
time
of
the
system/application.
Change
Control
Procedures.
The
company
requires
a
7
day
notice
on
any
changes
to
the
environment.
This
includes,
program
code,
parameter
settings,
circuit,
hardware,
software,
but
excludes
any/all
content
changes.
requires
the
vendor
to
coordinate
all
activities
with
the
Business
Solution
Manager.
Vendor
Holiday
Schedule
Service
Reporting
and
Review
procedures:
Please
provide
goals
and
measurements
of
the
system/application
and
when
you
will
report
to
the
client.