Closed tender

Home Office Security Architecture & Assurance Service

Details

Value
GBP 5,000,000
Published
4 May 2017
Submission
18 May 2017

Tender description

Why the Work is Being Done Home Office DDaT has a requirement for specialist security architecture capabilities to shape and lead the overall security architecture for HODDaT portfolios, programmes and projects using open standards (such as TOGAF) Problem to Be Solved HODDaT would like to grow and augment its current Security Architecture capability. In order to do this, it needs to engage a partner to work with the current team on several programmes. Who Are the Users Users include the public applying for entry to or the right to remain in the UK and police, security and enforcement teams controlling immigration and securing UK borders and detecting criminal behaviour within the Home Office and wider Government Agencies. Early Market Engagement No market engagement has taken place Work Already Done There are currently resources in place, where the current contract with an incumbent supplier is coming to an end Existing Team There is an existing team in place working within the Immigration Platform Technology (IPT) and Digital Services at the Border Programmes (DSAB). The new supplier will need to work collaboratively with other areas of the Programmes and other suppliers. Current Phase Not applicable Work Location Metro Point, Croydon and Marsham Street, London, as well as other Home Office locations on request. Working Arrangments The security architects need to be able to operate within a hub and spoke governance model and with other 3rd parties if required. The team is expected to work across the multiple sites, the main site is expected to be Croydon and be available during standard HO working hours. Expenses will conform to HO internal policies and will not be payable within the M25. Security Clearance Service Provider personnel need to be compliant with BPSS as a minimum, and CTC clearance if working in Home Office buildings. Depending on the nature of the role, if escalated and/or privileged access is necessary then there may be a requirement for SC clearance, and in certain circumstances, DV clearance. Additional T&Cs Individual Statements of Work (SoW) will be agreed periodically and subject to satisfactory performance of the supplier and HO needs. This contract is non-exclusive. The intention of this contract is the provision of a service with defined outcomes where the supplier is responsible for deliverables, risk, and provision of individuals. This contract would probably be deemed outside the intermediaries legislation (IR35) but could be affected by factors outside HO control. HO assumes no liability and will grant no guarantee of status. IPR in any developed technology will rest with HO. Skills & Experience Provide evidence of significant experience (5 years preferred) and deep experitise across a broad spectrum of security disciplines:Leadership & governance,Security Architecture,Risk management,Accreditor support, Delivery of IDAM solution and Operational Security Provide evidence of significant experience (3 years preferred) in providing security governance within an agile delivery lifecycle,ensuring gating processes are followed,design&code reviews are performed and security issues/risks are appropriately addressed Provide evidence of capability to shape and lead the overall security architecture using open standards (such as TOGAF) Provide evidence of capability to develop,implement and maintain a security architecture roadmap and the supporting implementation plan based upon agile delivery for programmes&projects, plus gap analysis between current&target states Provide evidence of capability to develop and implement an end-to-end risk management lifecycle Provide evidence of capability to manage the end-to-end security accreditation process and provision of lifecycle support Provide evidence of capability to impart operational security advice to HODDaT projects(eg. coordinating application security testing,providing detailed SOWs to external IT HC providers,working with development teams on key risks) Provide evidence of capability to build and support a role based identity & access management system (IDAM), authorising access to applications Provide evidence of capability to lead on innovation and performance engineering for the IDAM solution, and be accountable for the availability, scalability and performance of the IDAM solution Provide evidence of capability to architect and maintain security solutions in AWS cloud environments, with knowledge of AWS security services (IAM Policies, Security Groups and Access Control Lists) Provide evidence of capability to architect and maintain secuirty monitoring solutions in AWS cloud environments, with knowledge of AWS monitoring services (such as Cloud Trail and Net Flow Logs) Provide evidence of experience implementing NCSC (CESG) security guidelines, standards, and policies Nice to Haves Have successfully established Intelligent Client Functions to direct and assure deliverables from internal and external suppliers Provide demonstrable experience of assuring projects and find out where they are going wrong and what is required to remediate Provide demonstrable evidence of staff with experience of managing expectations and reporting to a wide range of internal departmental and cross-Government stakeholders, including those at senior level Experience in Border security and Immigration requirements and business processes, issues, and solutions No. of Suppliers to Evaluate 5 Proposal Criteria All essential and nice to have requirements will be evaluated further as part of the overall proposal criteria below There will be 6 Evaluation criteria weighted: Specific Competencies 65%, Methodology 10%, Plan for initial phase 10%, Ability to scale capability 10%, Performance Management 5%, Risk Management 5% Specific Competencies: Includes all essential and nice to have technology criteria Methodology: Knowledge and application of Agile, Government Digital Service, and NCSC standards Plan: Quality of delivery plan for first phase of engagement and statement of work Scale Capability: Capability of increasing delivery or service capability in the medium to long term Performance: Delivery and Service management reliability and repeatability - Client reporting and Quality management Risk Management: Provide evidence of maintaining quality and consistency over the medium term and approach to assumption, dependency, risk, and issue management Cultural Fit Criteria Approach to service readiness Approach to stakeholder management Approach to developing a One Team approach Approach to the development of client capability Approach to people development Approach to innovation and value for money Payment Approach Capped time and materials Assessment Method Written proposal Work history Presentation Evaluation Weighting Technical competence 65% Cultural fit 5% Price 30% Questions from Suppliers Budget range the budget range is between £3m to £5m (excluding vat) for a period of up to 2 years. separate day rates for each role will be required, and the following types of roles are required (but not limited to) as part of the service: security lead, information assurance and operational security leads, idam architects and idam developers. the initial team is anticipated to be between approximately 5 - 10 resources. statements of works will be agreed periodically with the supplier on a capped, fixed or t&m basis with agreed outcomes and deliverables.

Timeline

  1. Completed: Tender published4 May 2017
    Current notice
  2. Completed: Submission date18 May 2017

About the buyer

Home Office is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.

AI insights

  • Is there a preferred supplier?
  • What are the buyers pain points?
  • What has the buyer previously procured?
  • What are the key requirements?
Sign-up to enrich

Decision makers

Connect with the people behind this procurement.

Contact nameJob titlePhone numberWork email
Head of Procurement+44 •••• ••••••
Commercial Director+44 •••• ••••••
Procurement Manager+44 •••• ••••••
Category Lead+44 •••• ••••••
Senior Buyer+44 •••• ••••••
Contracts Manager+44 •••• ••••••

Related topics

Topics related to Home Office Security Architecture & Assurance Service, ranked by notice volume.

View all topics
TopicCountValue
  1. 1,485
    £14.9bn
  2. 681
    £1.7bn
  3. 3,366
    £105.8bn
  4. 4,088
    £269.5bn

Win more public sector contracts

Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.