FROM: Joe Michael, Chief Information Officer
SUBJECT: Data Classification and Microsoft 365 Information Governance Implementation
RECOMMENDATION:
title
Recommend that the Board approve a contract with Presidio to provide consulting and implementation services for the Data Classification and Microsoft 365 Information Governance Implementation Project in an amount not to exceed $224,500.00 and authorize the Chief Executive Officer to execute the agreement.
body
BACKGROUND:
At the July Board meeting, the Board approved a comprehensive expansion of SBCERA's cybersecurity program centered on Palo Alto security services. That approval directly supported the remediation of recent audit findings by adding capabilities SBCERA either did not have or could not previously integrate at the level required to address current security risks.
The proposed item addresses related audit findings from a different, but complementary, direction. Rather than acquiring another perimeter-security platform, this project focuses on the configuration, governance, and secure use of systems and services already within SBCERA's Microsoft environment. Staff is requesting authorization to obtain specialized consulting services to design and configure that environment in alignment with applicable National Institute of Standards and Technology (NIST) guidance, SBCERA's operational requirements, and the security controls appropriate for the information SBCERA creates, receives, stores, and transmits.
Data Classification and Governance
The foundation of the project is the creation of an enterprise data-classification framework and supporting data dictionary. Data classification is the process of identifying information by its business purpose, sensitivity, legal or regulatory requirements, and the potential impact of unauthorized access, disclosure, alteration, or loss. The framework will establish a manageable set of classification levels and clear handling requirements for each level. The data dictionary will document the principal categories of information maintained by SBCERA, their business owners, locations, sensitivity, handling considerations, and the classification and controls that apply.
A classification framework is necessary because security technology cannot consistently protect information unless the organization first defines what the information is, how sensitive it is, who is responsible for it, and how it may be used or shared. Without those definitions, individual departments and employees may make inconsistent decisions, while automated controls may be either too permissive or so restrictive that they interfere with legitimate business operations. A common classification model provides the policy foundation for consistent access, sharing, monitoring, and data-loss-prevention decisions across SBCERA.
Microsoft Purview will translate this governance framework into enforceable technical controls. Purview can use sensitivity labels, data-loss-prevention policies, retention controls, trainable classifiers, and sensitive-information types to identify and protect data. Depending on the classification and the capabilities of each service, those controls can require markings or encryption, restrict external sharing, limit copying or downloading, apply retention requirements, generate alerts, support investigations, and block or warn on activities that present an unacceptable risk.
The same classification and labeling structure will be used across supported Microsoft 365 applications and services, including SharePoint, OneDrive, Teams, Office applications, and Microsoft 365 Copilot. This common policy layer is particularly important as information moves between services. For example, a document stored in SharePoint may be accessed through Teams, synchronized through OneDrive, opened in an Office application, or used by Copilot to generate a response. Properly configured permissions, labels, and Purview controls help ensure that the protections follow the information and that Copilot operates within the user's existing access rights and organizational policies. The project will also address oversharing and permissions governance so that introducing new collaboration and AI capabilities does not unintentionally broaden access to sensitive information.
The completed classification framework and data dictionary will also be provided to the Palo Alto cybersecurity project. This will allow the Microsoft and Palo Alto controls to be mapped to the same definitions of sensitive data and acceptable handling. Microsoft Purview will provide governance and protection within the Microsoft 365 environment, while Palo Alto data-loss-prevention capabilities can provide complementary inspection and enforcement across applicable network, cloud, and endpoint channels. Using a shared classification model will reduce conflicting policies, improve incident context, and help SBCERA apply consistent controls regardless of where information is stored or how it is transmitted. The specific exchange of labels, metadata, sensitive-data definitions, and policy signals will be finalized during design and implementation based on the supported integration methods.
Project Scope
The selected consultant will work with SBCERA staff and business stakeholders to complete the governance, configuration, implementation, and migration activities necessary to operationalize the classification framework. The anticipated scope includes:
• Developing an enterprise data-classification framework, data dictionary, ownership model, handling standards, and governance process;
• Assessing and configuring Microsoft Purview, including appropriate sensitivity labels, data-loss-prevention policies, retention controls, monitoring, alerting, and related compliance capabilities;
• Implementing and governing Microsoft Teams, OneDrive, and Microsoft 365 Copilot, including access, sharing, lifecycle, and security controls appropriate to each classification;
• Assessing the existing on-premises file-server environment; preparing, remediating, and mapping content and permissions; and migrating approved content to SharePoint Online;
• Applying the necessary Purview and Microsoft 365 controls to SharePoint and migrated information, including protections intended to reduce oversharing and inappropriate external access;
• Coordinating the classification definitions and data-loss-prevention requirements with the Palo Alto cybersecurity initiative; and
• Providing documentation, knowledge transfer, testing support, and implementation guidance so SBCERA can sustain the environment after project completion.
Consultant Outreach and Proposal Process
SBCERA worked with Forrester and its independent auditor to identify the core requirements for a data-classification initiative. Both emphasized the need to establish governance and correctly configure the Microsoft environment. Based on that guidance, staff contacted SBCERA's Microsoft account representatives and engineering specialists and requested assistance identifying qualified consultants.
Microsoft does not recommend or endorse a specific consulting firm. Microsoft does, however, maintain partner designations and specializations that indicate demonstrated experience in particular solution areas. Using that information, Microsoft identified multiple firms whose capabilities appeared to align with SBCERA's organization and anticipated needs.
Staff then conducted a formal and consistent outreach process. Each firm received the same project information, questions, responses, and opportunity to submit a proposal. SBCERA held multiple meetings with the firms to clarify the objectives and expected scope. Of the six firms contacted, SBCERA received four final proposals. The two remaining firms continued to request additional time or meetings beyond the schedule met by the other participants.
Auditor Independence
SBCERA's independent auditor also submitted a proposal for this work. Following internal review, staff determined that the auditor's proposal should not be included in the final evaluation. Although the auditor may appropriately assist with limited advisory matters, this project would make significant and far-reaching changes to SBCERA's governance and technology environment. Excluding the auditor from implementation preserves the auditor's independence and avoids placing the firm in the position of evaluating controls it designed or implemented. Staff believes that separation will provide the Board and SBCERA with a more objective assessment of the completed work.
Proposal Review and Cost Comparison
The proposals varied in their implementation approaches, estimated labor hours, staffing models, and total cost. CDW-G submitted an updated proposal that includes engineering review and reflects a more complete level of effort for the requested scope. The table below summarizes the final proposals received and identifies the firms that did not submit a proposal.
|
Consultant |
Estimated Hours |
Estimated Cost |
|
CDW-G |
1,280 |
$192,000.00 |
|
Presidio |
890 |
$224,500.00 |
|
Kopius Tech |
1,760* |
$406,500.00 |
|
Go-Planet |
2,100 |
$475,000.00 |
|
Quisitive |
Did Not Submit by Deadline |
|
IBM |
Did Not Submit by Deadline |
* Kopius Tech indicated that it could actively work on multiple project objectives concurrently.
Evaluation and Recommendation
A ranking matrix is included with this item and reflects staff's evaluation of each firm's proposal and proposed approach to SBCERA's objectives. The evaluation considered the completeness and clarity of the proposed solution, demonstrated understanding of the required outcomes, implementation approach, staffing and level of effort, relevant qualifications and experience, project risk, and cost.
Presidio was the only firm to clearly define a complete implementation approach and directly align its proposed work with each of SBCERA's stated objectives. The other proposals either did not address all requested objectives or left material elements ambiguous. Those gaps create a risk that necessary work could later be treated as outside the original scope, resulting in change requests, schedule delays, or a request for additional funding.
Presidio's proposal is within the anticipated budget and is among the more cost-effective proposals received. More importantly, its scope provides the clearest path to delivering the governance framework, Microsoft 365 configuration, Purview controls, SharePoint migration, Copilot readiness, and Palo Alto DLP coordination required by the project. Based on the ranking matrix and staff's review of the proposals, staff recommends that SBCERA award the data-classification and Microsoft information-governance project to Presidio for an amount not to exceed $224,500.00 and authorize the Chief Executive Officer to execute the agreement and any necessary administrative amendments consistent with the Board's approval and SBCERA's contracting policies.
Upon approval, staff will finalize the statement of work, confirm implementation phases and acceptance criteria, and establish project governance with the selected consultant. Material changes to the approved scope or funding will be returned to the appropriate approving authority in accordance with SBCERA policy.
BUDGET IMPACT:
Costs for this item are included in the current year administrative and/or non-administrative budget.
STRATEGIC PLANNING GOAL/OBJECTIVE:
Operational Excellence & Efficiency
STAFF CONTACT:
Joe Michael
ATTACHMENTS:
Exhibit A: Presidio Data Classification Proposal
Exhibit B: Scoring Matrix