Closed tender

Home Office Security Architecture & Assurance Service

Details

Value
GBP 4,000,000
Published
4 May 2017
Submission
18 May 2017

Tender description

Summary of the work Develop, implement and maintain security architecture and delivery capability for HODDaT portfolios, programmes & projects, in relation to the following areas of Security: Leadership and governance, Security Architecture, Risk management, Accreditor support, Delivery of an IDAM solution and Operational Security. Expected Contract Length Up to a maximum of 2 years Latest start date Monday 31 July 2017 Budget Range The Budget range is between £3m to £5m (excluding VAT) for a period of up to 2 years. Separate day rates for each role will be required, and the following types of roles are required (but not limited to) as part of the service: Security Lead, Information Assurance and Operational Security Leads, IDAM Architects and IDAM Developers. The initial team is anticipated to be between approximately 5 - 10 resources. Statements of works will be agreed periodically with the supplier on a capped, fixed or T&M basis with agreed outcomes and deliverables. Why the Work is Being Done Home Office DDaT has a requirement for specialist security architecture capabilities to shape and lead the overall security architecture for HODDaT portfolios, programmes and projects using open standards (such as TOGAF) Problem to Be Solved HODDaT would like to grow and augment its current Security Architecture capability. In order to do this, it needs to engage a partner to work with the current team on several programmes. Who Are the Users Users include the public applying for entry to or the right to remain in the UK and police, security and enforcement teams controlling immigration and securing UK borders and detecting criminal behaviour within the Home Office and wider Government Agencies. Early Market Engagement No market engagement has taken place Work Already Done There are currently resources in place, where the current contract with an incumbent supplier is coming to an end Existing Team There is an existing team in place working within the Immigration Platform Technology (IPT) and Digital Services at the Border Programmes (DSAB). The new supplier will need to work collaboratively with other areas of the Programmes and other suppliers. Current Phase Not applicable Skills & Experience • Provide evidence of significant experience (5 years preferred) and deep experitise across a broad spectrum of security disciplines:Leadership & governance,Security Architecture,Risk management,Accreditor support, Delivery of IDAM solution and Operational Security • Provide evidence of significant experience (3 years preferred) in providing security governance within an agile delivery lifecycle,ensuring gating processes are followed,design&code reviews are performed and security issues/risks are appropriately addressed • Provide evidence of capability to shape and lead the overall security architecture using open standards (such as TOGAF) • Provide evidence of capability to develop,implement and maintain a security architecture roadmap and the supporting implementation plan based upon agile delivery for programmes&projects, plus gap analysis between current&target states • Provide evidence of capability to develop and implement an end-to-end risk management lifecycle • Provide evidence of capability to manage the end-to-end security accreditation process and provision of lifecycle support • Provide evidence of capability to impart operational security advice to HODDaT projects(eg. coordinating application security testing,providing detailed SOWs to external IT HC providers,working with development teams on key risks) • Provide evidence of capability to build and support a role based identity & access management system (IDAM), authorising access to applications • Provide evidence of capability to lead on innovation and performance engineering for the IDAM solution, and be accountable for the availability, scalability and performance of the IDAM solution • Provide evidence of capability to architect and maintain security solutions in AWS cloud environments, with knowledge of AWS security services (IAM Policies, Security Groups and Access Control Lists) • Provide evidence of capability to architect and maintain secuirty monitoring solutions in AWS cloud environments, with knowledge of AWS monitoring services (such as Cloud Trail and Net Flow Logs) • Provide evidence of experience implementing NCSC (CESG) security guidelines, standards, and policies Nice to Haves • Have successfully established Intelligent Client Functions to direct and assure deliverables from internal and external suppliers • Provide demonstrable experience of assuring projects and find out where they are going wrong and what is required to remediate • Provide demonstrable evidence of staff with experience of managing expectations and reporting to a wide range of internal departmental and cross-Government stakeholders, including those at senior level • Experience in Border security and Immigration requirements and business processes, issues, and solutions Work Location Metro Point, Croydon and Marsham Street, London, as well as other Home Office locations on request. Working Arrangments The security architects need to be able to operate within a hub and spoke governance model and with other 3rd parties if required. The team is expected to work across the multiple sites, the main site is expected to be Croydon and be available during standard HO working hours. Expenses will conform to HO internal policies and will not be payable within the M25. Security Clearance Service Provider personnel need to be compliant with BPSS as a minimum, and CTC clearance if working in Home Office buildings. Depending on the nature of the role, if escalated and/or privileged access is necessary then there may be a requirement for SC clearance, and in certain circumstances, DV clearance. Additional T&Cs Individual Statements of Work (SoW) will be agreed periodically and subject to satisfactory performance of the supplier and HO needs. This contract is non-exclusive. The intention of this contract is the provision of a service with defined outcomes where the supplier is responsible for deliverables, risk, and provision of individuals. This contract would probably be deemed outside the intermediaries legislation (IR35) but could be affected by factors outside HO control. HO assumes no liability and will grant no guarantee of status. IPR in any developed technology will rest with HO. No. of Suppliers to Evaluate 5 Proposal Criteria • All essential and nice to have requirements will be evaluated further as part of the overall proposal criteria below • There will be 6 Evaluation criteria weighted: Specific Competencies 65%, Methodology 10%, Plan for initial phase 10%, Ability to scale capability 10%, Performance Management 5%, Risk Management 5% • Specific Competencies: Includes all essential and nice to have technology criteria • Methodology: Knowledge and application of Agile, Government Digital Service, and NCSC standards • Plan: Quality of delivery plan for first phase of engagement and statement of work • Scale Capability: Capability of increasing delivery or service capability in the medium to long term • Performance: Delivery and Service management reliability and repeatability - Client reporting and Quality management • Risk Management: Provide evidence of maintaining quality and consistency over the medium term and approach to assumption, dependency, risk, and issue management Cultural Fit Criteria • Approach to service readiness • Approach to stakeholder management • Approach to developing a One Team approach • Approach to the development of client capability • Approach to people development • Approach to innovation and value for money Payment Approach Capped time and materials Evaluation Weighting Technical competence 65% Cultural fit 5% Price 30% Questions from Suppliers 1. The guidance for the initial response says "You should only provide one example for each essential or nice-to-have requirement (unless the buyer specifies otherwise)". Please provide guidance on exactly what you would expect to see in the 100 word responses for questions which specify a number of years experience - multiple projects or a "yes" and a single example? Please list the questions you expect to see more than one example for so we are clear on your evaluation approach. Where a number of years experience is asked for suppliers should detail the nature and duration of that experience along with a specific example. If there is a further example that is relevant to the question, provides additional insight to the suppliers experience and is possible to outline in sufficient detail within the 100 word limit then it may be provided. This applies to all questions. 2. From the description of the task it appears that there may be an IDAM solution being developed/used. If this is the case, is this going to be used for future development under this contract? If so, what technology is it based on? Development of the current IdAM solution is ongoing. It is currently a Forgerock Identity and Access Management solution that authenticates business users, internal development users and system users who use the Immigration IT applications. There may be some development to maintain and uplift the existing solution, which will be agreed via SOWs. We want to centralise this solution so that we share the IdAM solution across other HO departments, and part of a SOW under this contract may include assisting with the move to a centralised solution. This may mean migrating to a different technology over time, such as Keycloak. 3. Is there capacity to apply for the various lead roles stated in 'budget range'? No. The requirement is for a Security Architecture & Assurance Service and therefore we expect the supplier to provide teams consisting of (but not limited to) those roles outlined in the budget range section. The service will have clearly defined outcomes and deliverables and, as such, it will be up to the supplier to shape the teams to meet the requirements set out in the statements of work. 4. Can you clarify the deadline time for submitting the responses on Thursday the 18 May, please? The deadline for responses to be submitted on to the system is 23:59 on Thursday 18th May 2017 5. Within the Essential Experience the following bullet point outlines the necessary IDAM experience: • Provide evidence of capability to build and support a role based identity & access management system (IDAM), authorising access to applications. Have the Home Office team already selected an IDAM vendor that will be used as the underpinning technology? It is currently a Forgerock Identity and Access Management solution that authenticates business users, internal development users and system users who use the Immigration IT applications. We want to centralise this solution so that we share the IdAM solution across other HO departments, and part of a SOW under this contract may include assisting with the move to a centralised solution. This may mean migrating to a different technology over time, such as Keycloak. We would look to the supplier to design and implement this solution. 6. What is the indicative phasing (with durations) that the statement of work is likely to follow? An approximate answer will suffice with a time-base of one month. The initial Statement of Work will likely be for a mobilisation phase. The exact duration of this will be confirmed at contract award but is likely to be for 1 month. Following that Statements of Works will be agreed periodically based on the requirements of the portfolio. 7. What is the client’s ideal team composition, ie how many of resources are to be supplied within each role discipline and seniority (across leads, architects and developers)? The team composition will depend on the Statements of Work, Outcomes and Deliverables that are agreed between the Home Office and the Supplier. For fixed price pieces of work it will be for the Supplier to decide on the optimum team structure based on the requirements for that Statement of Work. 8. What is the ideal onboarding schedule for the proposed team, ie which roles must be fulfilled at contract start and what tolerance is there for phased onboarding (ideally specified by role)? The initial Statement of Work will likely be for a mobilisation phase. The exact duration will be confirmed at contract award but is likely to be for 1 month and the majority of the roles outlined in the ‘Budget Range’ section. The full team will then be expected to be deployed following this phase, which will be agreed during the mobilisation phase. 9. As the proposed contract is to be non-exclusive, is there a scenario where the client may appoint resources from multiple suppliers to work as a composite team? No, it is not intended that there will be a composite team. We expect a service to be delivered and the Supplier to take responsibility for delivering the outcomes as agreed in the Statements of Work. 10. With regards to the question ‘Provide evidence of capability to lead on innovation and performance engineering for the IDAM solution, and be accountable for the availability, scalability and performance of the IDAM solution’ Could you please clarify whether you are referring to a service solution or the Design approach? We are primarily referring to a service solution. We are looking for the supplier to design and implement the solution. As we already have a solution in place that controls fine grained access to applications and data, the initial SoW will include the creation of a roadmap for enhancement of the existing solution and the implementation of any associated changes. The roadmap is also likely to include design changes to move towards a more centralised solution. 11. Could you please clarify what you are referring to with regard to the following statement – ‘Evidence of successfully established Client Functions to direct and assure deliverable from Internal and External Suppliers’? Intelligent Client Function is an in house capability within a host organisation which has responsibility for the ownership, management and delivery of a defined service or range of services on behalf of part or all of the organization, to that organisation. We are looking for suppliers who have performed that function in the past and have experience in defining deliverables, as well as assuring deliverables once they have been produced by internal suppliers (ie. Home Office employees) and external suppliers (suppliers delivering services to the Home Office). 12. Can you please clarify whether the Contract will support appropriate offsite working (ie within a suitable facility) or whether the roles are to be based firmly within the Home Office locations specified? At the ITT stage we will ask for a rate card for both onsite and offsite working and it will be agreed in advance of each Statement of Work where the appropriate location will be. The location will very much depend on the type of work being performed but Suppliers can assume the majority will take place in Home Office locations. 13. Your questions refer to ‘role based’ IdAM capability, we were of the understanding that the movement across Government and MOD was towards attribute based identity management, could you please clarify your approach? We already have a solution in place that controls fine grained access to applications and data. The initial SoW will include the creation of a roadmap for enhancement of the existing solution and the implementation of any associated changes. The roadmap is also likely to include design changes to move towards a more centralised solution.

Timeline

  1. Completed: Tender published4 May 2017
    Current notice
  2. Completed: Submission date18 May 2017

About the buyer

Home Office is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.

AI insights

  • Is there a preferred supplier?
  • What are the buyers pain points?
  • What has the buyer previously procured?
  • What are the key requirements?
Sign-up to enrich

Decision makers

Connect with the people behind this procurement.

Contact nameJob titlePhone numberWork email
Head of Procurement+44 •••• ••••••
Commercial Director+44 •••• ••••••
Procurement Manager+44 •••• ••••••
Category Lead+44 •••• ••••••
Senior Buyer+44 •••• ••••••
Contracts Manager+44 •••• ••••••

Related topics

Topics related to Home Office Security Architecture & Assurance Service, ranked by notice volume.

View all topics
TopicCountValue
  1. 1,485
    £14.9bn
  2. 1,283
    £16.9bn
  3. 681
    £1.7bn
  4. 1,745
    £636.1bn
  5. 3,366
    £105.8bn
  6. 854
    £19.1bn
  7. 4,088
    £269.5bn

Win more public sector contracts

Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.