My WebLink
|
Help
|
About
|
Sign Out
Home
Browse
Search
Kittitas County SOW Microsoft Purview Data Security Strategy PSA v4 20260929
>
Meetings
>
2026
>
10. October
>
2026-10-06 10:00 AM - Commissioners' Agenda
>
Kittitas County SOW Microsoft Purview Data Security Strategy PSA v4 20260929
Metadata
Thumbnails
Annotations
Entry Properties
Last modified
10/1/2026 12:16:19 PM
Creation date
10/1/2026 12:16:12 PM
Metadata
Fields
Template:
Meeting
Date
10/6/2026
Meeting title
Commissioners' Agenda
Location
Commissioners' Auditorium
Address
205 West 5th Room 109 - Ellensburg
Meeting type
Regular
Meeting document type
Supporting documentation
Supplemental fields
Item
Request to Approve Microsoft Purview Data Security Strategy SOW under Existing MSA with Trace3, LLC
Order
2
Placement
Consent Agenda
Row ID
149866
Type
Agreement
There are no annotations on this page.
Document management portal powered by Laserfiche WebLink 9 © 1998-2015
Laserfiche.
All rights reserved.
/
14
PDF
Print
Pages to print
Enter page numbers and/or page ranges separated by commas. For example, 1,3,5-12.
After downloading, print the document using a PDF reader (e.g. Adobe Reader).
View images
View plain text
<br /> Statement of Work <br /> <br />September 29, 2026 - Version 4.0 Microsoft Purview Data Security Strategy Page 4 <br />Design Phase <br />• Design the compliance boundary architecture, including the RBAC role -group model that restricts each <br />department's data handlers to their own agency's mailboxes and SharePoint sites (e.g., a "Sheriff – eDiscovery <br />Managers" role group) <br />• Define the Compliance Security Filter logic and naming standard for up to twenty-four (24) departmental filters <br />keyed to the standardized Entra ID attributes and mapped SharePoint URLs <br />• Design the Preservation in Place hold model to replace verbal and email litigation holds <br />• Design the export configuration for deduplication and decryption to support cleaner legal review hand -off <br />• Produce an as-built design specification for County review and approval before implementation <br />Execute Phase <br />• Remediate Entra ID department attributes for In-Scope users in accordance with the approved Discovery <br />recommendations <br />• Create and configure the RBAC role groups and assign departmental data handlers <br />• Implement up to twenty-four (24) Compliance Security Filters and validate that each filter correctly scopes search <br />results to the owning department's mailboxes and SharePoint sites only <br />• Configure Preservation in Place holds and validate that content is preserved even when deleted or when a <br />custodian departs <br />• Enable the PRO to generate search result statistics and estimates; <br />• Configure deduplication and decryption at export and validate output against a representative review set <br />• Conduct end-to-end validation of the five (5) operational use cases (scoped PRA search, litigation hold, designee <br />self-service, cleaner review hand-off, and audit defensibility) <br />Closure Phase <br />• Deliver as-built documentation of the implemented boundary architecture, Compliance Security Filters, hold <br />model, and export configuration <br />• Deliver up to two (2) ninety (90)-minute administrator enablement sessions for Central IT covering the boundary <br />architecture and ongoing administration <br />• Deliver up to two (2) ninety (90)-minute working sessions for departmental designees covering query <br />construction, search statistics, and exports <br />• Conduct a project closure review and confirm acceptance criteria are met <br />• Provide recommendations for optional downstream phases (e.g., Premium eDiscovery review sets and predictive <br />coding) should the County's needs grow beyond G3 <br />• Provide Project lessons learned documentation <br />• Complete Project closure meeting with Project team <br />• Conduct Knowledge Transfer: <br />o Provide an informal overview of administrative and operational functions on or before the Services <br />completion with the necessary and identified staff available for the session <br />• Deliver Completion Certificate and attain Client sign off <br /> <br />*Please note: Knowledge Transfer does not replace formal system training. Knowledge transfer is delivered as part of <br />the Services and will be four (4) sessions lasting up to ninety (90) minutes each. Client must identify necessary staff <br />required/needed for the Knowledge Transfer session and do everything they can to have the identified resources <br />available for the session. This transfer of knowledge will be conducted in an informal and informative way, not <br />prepared in advance, and without creating any knowledge artifacts such as documents, diagrams or videos. A <br />recording of the session may be done at Client’s request. If recorded, it will be distributed to the Client within three <br />(3) business days of the completion of the Knowledge Transfer session.
The URL can be used to link to this page
Your browser does not support the video tag.