Home Office Border Force Security Architecture & Assurance Service
Details
- Buyer
- Home Office
- Value
- GBP 5,000,000
- Published
- 29 June 2017
- Submission
- 13 July 2017
- Source
- uk:digital_marketplace
Tender description
Summary of the work Develop/implement/maintain Information Assurance/Design capability for Border-Force/other HO portfolios, programmes & projects related to following Security areas: Leadership/governance, Security-Architecture, Risk-management, Accreditor-support, Operational-Security. Also involves creating RMADS-style documentation to assess threats/risks/mitigations/residual risk for each project; making recommendation to business/technology and influence architecture-design. Supplier to contribute to/support building of best practice across HO. Expected Contract Length 24 months maximum. Latest start date Monday 2 October 2017 Budget Range £4 - £5 million across the lifetime of the contract. Why the Work is Being Done Border Force has a requirement for Technical Security Information Assurance and Design capabilities to shape and lead the overall security architecture for Border Force portfolios, programmes and projects using open standards (such as TOGAF). Other Home Office programmes may also make use of this arrangement. Problem to Be Solved Border Force would like to grow and augment its current Technical Security Information Assurance and Design capability. In order to do this, it needs to engage a partner to work with the current team on several programmes. Who Are the Users Users include the public applying for entry to or the right to remain in the UK and police, security and enforcement teams controlling immigration and securing UK borders and detecting criminal behaviour within the Home Office and wider Government Agencies. Early Market Engagement No market engagement has taken place. Work Already Done There are currently resources in place, where the current contract with an incumbent supplier is coming to an end. Existing Team There is an existing team in place working within Border Force. The new supplier will need to work collaboratively with other areas of the Programme and other suppliers. Current Phase Not applicable Skills & Experience • Demonstrable evidence of significant experience (5 years preferred) and deep expertise across a broad spectrum of Information Assurance methodologies. • Significant experience (3 years+) providing Information-Assurance Services for solutions built within Agile-delivery lifecycles/continuous delivery to production, ensuring gating processes followed, design/code reviews performed and security issues/risks appropriately addressed. • Demonstrable evidence of capability to shape and lead the overall security architecture using open standards (such as TOGAF). • Capability to develop/implement/maintain an Information Assurance roadmap and the supporting implementation plan based upon Agile delivery for programmes & projects, plus gap analysis between current & target states. • Demonstrable evidence of experience of assuring IaaS, SaaS, PaaS solution in hyper scale cloud providers. • Demonstrable evidence of capability to manage the end-to-end Information Assurance process and provision of lifecycle support including end-to-end risk management. • Capability to impart operational security advice to Border-Force projects (e.g. coordinating application security testing, providing detailed SOWs to external ITHC providers and working with development teams on key risks). • Demonstrable experience with commercial risk assessment methodology e.g. ISF and IRAM. • Demonstrable experience with ISO27001:2013 and risk assessment methodology. • Demonstrable evidence of experience implementing NCSC (CESG) security guidelines, standards, and policies. • Demonstrable experience of technical governance within projects delivered to the GDS service standards and production of appropriate artefacts as projects move through delivery, alpha, beta and into live service. Nice to Haves • Have successfully established Intelligent Client Functions to direct and assure deliverables from internal and external suppliers. • Demonstrable experience of assuring projects and find out where they are going wrong and what is required to remediate. • Demonstrable evidence of strong stakeholder management showing staff with experience of managing expectations and reporting to a wide range of internal departmental and cross-Government stakeholders, including those at senior level. • Demonstrable experience in Border security and Immigration requirements and business processes, issues, and solutions. • Demonstrable experience of working on digital by default service standard compliant government website. • Demonstrable experience of writing of specific operations guidelines e.g. decommissioning of Laptops etc. Guidance will be stipulated by the security architects. • Demonstrable experience of writing of specific operations guidelines e.g. decommissioning of Laptops etc. Guidance will be stipulated by the security architects. • Demonstrable experience of establishing & running Key operations functions e.g. running vulnerability scanning tools & write up results; Installing specific security tools e.g. password safes. • Demonstrable experience of establishing/running Key operations functions e.g. Decommissioning servers/laptops/end point user devices; Installing/running open-source security tools e.g. clamAV,NGINX WAF, pfSense firewall; Managing PKI infrastructure e.g. issuing CA. • Demonstrable experience of Incident Management reporting including defining processes. • Demonstrable experience of supporting Dev Ops in respect to delivery of specific security controls, particular in respect of using cloud providers. • Demonstrable experience of assuring and securing solutions built at Official and Secret data classifications. • Demonstrable evidence of designing technical controls for solutions in hyper scale cloud providers. • Demonstrable evidence of designing technical controls for solutions in hyper scale cloud providers. • Demonstrable evidence of designing technical controls for solutions in hyper scale cloud providers. • Demonstrable evidence of chairing Security Working Groups and Information Assurance Boards • Demonstrable evidence of strong understanding of GPDR legislation. • Demonstrable evidence of defining and implementing automated security tests. • Demonstrable evidence of building an in-house PEN test capability. • Demonstrable evidence of providing a business concentric view on information risks. Work Location Lunar House, Croydon and Marsham Street, London, as well as other Home Office locations on request. Working Arrangments The team need to be able to operate within a hub and spoke governance model and with other third parties if required. The team is expected to work across the multiple sites, the main site is expected to be Croydon and be available during standard HO working hours. Expenses will conform to HO internal policies and will not be payable within the M25. Security Clearance Service Provider personnel need to be compliant with SC clearance, and in certain circumstances, DV clearance. Additional T&Cs Individual Statements of Work agreed periodically subject to satisfactory performance and HO needs. Contract is non-exclusive. Intention is service provision with defined outcomes; supplier is responsible for deliverables, risk, and provision of individuals. If this was to be executed in this manner then it would probably be deemed outside the intermediaries’ legislation but could be affected by factors outside HO control. HO assumes no liability; will grant no guarantee of status. Supply-continuity, resource-stability, and management part of assessment criteria; excessive dependence on independent contractors may be detrimental to bid evaluation unless within managed supply-chains. HO will own developed technology IPR. No. of Suppliers to Evaluate 5 Proposal Criteria • All essential and nice to have requirements will be evaluated further as part of the overall proposal criteria below • There will be 6 Evaluation criteria weighted: Specific Competencies 65%, Methodology 10%, Plan for initial phase 10%, Ability to scale capability 10%, Performance Management 5%, Risk Management 5% • Specific Competencies: Includes all essential and nice to have technology criteria • Methodology: Knowledge and application of Agile, Government Digital Service, and NCSC standards. • Plan: Quality of delivery plan for first phase of engagement and statement of work • Scale Capability: Capability of increasing delivery or service capability in the medium to long term • Performance: Delivery and Service management reliability and repeatability - Client reporting and Quality management. • Risk Management: Provide evidence of maintaining quality and consistency over the medium term and approach to assumption, dependency, risk, and issue management Cultural Fit Criteria • Approach to service readiness. • Approach to stakeholder management. • Approach to developing a One Team approach. • Approach to the development of client capability. • Approach to people development. • Approach to innovation and value for money. Payment Approach Capped time and materials Evaluation Weighting Technical competence 65% Cultural fit 5% Price 30% Questions from Suppliers 1. Could you please let us know why the model is capped time and material. For project of such magnitude, would it not be better to have T&M? Capped time and materials allows the Authority to control budgets against clearly defined workpackages. 2. Can I ask why the Authority is not using the Cyber Security Services 2 procurement framework, which includes Security Architecture and Assurance Services? The Cyber Security Services 2 procurement framework was considered for this exercise and for a previous unrelated exercise. However the breadth of the supplier community was not as good as that for DOS2; hence a more competitive response can be gained by using DOS2. 3. Does the Authority have a preference for Commercial Risk Assessment methodologies, if so, which is preferred: IRAM, RA2, ISO27005, CRAMM, ALE, NIST, OCTAVE, IS1&2 or can the Providers use other Government or NCSC/GSS approved Risk Assessment/Management methodologies? The Authority has no preference for a particular risk assessment methodology. What is important is that the approach is robust and supports the business making informed decisions, at the pace demanded for the Authority's delivery pipline. 4. Does the Authority have a preference for Commercial Risk Assessment methodologies, if so, which is preferred: IRAM, RA2, ISO27005, CRAMM, ALE, NIST, OCTAVE, IS1&2 or can the Providers use other Government or NCSC/GSS approved Risk Assessment/Management methodologies? The Authority has no preference for a particular risk assessment methodology. What is important is that the approach is robust and supports the business making informed decisions, at the pace demanded for the Authority's delivery pipline. 5. In terms of Scale Capability i.e. Capability of increasing delivery or service capability in the medium to long term, is the buyer open to receiving architecture as a service from our pool of cyber security architects to provide very specific and focussed service based on tech and specialism, or is the requirement for specific dedicated architects? The Authority is acceptable towards the use of ‘other’ cyber security architects, provided the following is made clear and presented as a business case :• The skill set of the individuals and (the reasoning) why this individual is necessary (i.e. what is the real benefit of using this individual)• The duration of the work package for this individual. 6. Does the Authority require the Provider to build or run an in-house Pen testing service, or to conduct internal vulnerability assessments as part of the service? The Authority does not govern the approach of use of the Service Providers management of resources, however we would require the Service Provider to implement a risk based approach towards the building of the solution and to demonstrate an approach whereby vulnerability scans have been integrated into the continuous integration process. 7. Does the Authority require the Provider to provide full Application Security services on top of the Architecture and Assurance services, including: the implementation, installation and management of application and infrastructure security components and services, e.g.: Web Firewalls, PKI and encryption services, Certificate Authorities, Anti-virus software, DLP and NIDS, etc. Or will these services be provided/delivered by the solution/application/infrastructure/platform providers? The Authority requires the Service Provider to deployed a completed solution which demonstrates compliance to all standards and regulations; expectation would be for the solution to be deployed into the cloud, therefore certain activities may be passed onto the cloud service provider but with major fundamental security related functions managed within (based on risk tolerance, etc). 8. Given the role of the desired capability to is to lead on the security architecture of Programmes across the Border force, and potentially other parts of the Home Office, to what extent will the advisory capability need to be able to extend beyond traditional IA borders. We feel it is vitally important that compute/ server, and even ITIL information processes are designed in such a way as to minimise the need for security add-ons to address failings elsewhere in architecture designs. It is our experience that cloud services are rarely configured correctly and this is an at inception flaw. Gap analysis is fundamental to Information Assurance; whereby risks exists, there is expectation that these are clearly documented against risks utilising the 4T process: Transference, Tolerance, Treatment, Termination of Risk.Flaws and untreatable risks are expected – hence, Authority would expect such risks to be clearly defined for purpose of acceptance/“tolerating the risk”. Processes and security architecture utilised must be sufficient towards the treatment of lowering or terminating risks; it's expected that mitigations must cover the minimum, i.e. not compromise the Privacy by Design/Default concepts, but take into consideration possible future requirements (e.g. change in regulations – GDPR, etc). 9. Are there specific skills sets/knowledge (governance, project management, technical expertise ) that is lacking and currently not provided for, by the incumbent service provider? The current contract is coming to a natural end; whether there are any skill sets or knowledge gaps is not relevant to this procurement exercise. 10. There are a number of requirements that have been duplicated – can you confirm these are simply duplications and there are not other requirements which have been over-written. Further there are two requirements regarding ‘establishing & running key operations functions’ but with different ‘e.g.’s – can you confirm whether these are two separate requirements or simply different example scopes of one requirement. The two "Nice to Haves" starting "Demonstrable experience of establishing & running Key operations functions...." are two parts of the same requirement; wording limitation entailed listing separately.The "Nice to Have" duplicates "Demonstrable evidence of designing technical controls for solutions in hyper scale cloud providers." Please replace with:-• Demonstrable evidence of creating and maintaining Privacy Impact Assessments• Demonstrable evidence of creating and maintaining policy documentsPlease indicate in your response if you are unable to answer these two questions in the time set. 11. Please can you clarify how many 'cases' you expect to recorded in Year 1, 2 & 3 etc. in the CBA. Also is there a sense of the volume of data that would need held in CBA? Currently there are approximately 5000 alarms per month which under current legislation would generate a case. The Authority expect this number to reduce. The future system will include alarm data, vehicle and person data and manifest data for example. Capacity planning will need to be undertaken as part of Discovery.
Timeline
- Completed: Tender published29 June 2017Current notice
- Completed: Submission date13 July 2017
About the buyer
Home Office is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.
Decision makers
Connect with the people behind this procurement.
| Contact name | Job title | Phone number | Work email |
|---|---|---|---|
| Head of Procurement | +44 •••• •••••• | ••••••••@home-office.gov | |
| Commercial Director | +44 •••• •••••• | ••••••••@home-office.gov | |
| Procurement Manager | +44 •••• •••••• | ••••••••@home-office.gov | |
| Category Lead | +44 •••• •••••• | ••••••••@home-office.gov | |
| Senior Buyer | +44 •••• •••••• | ••••••••@home-office.gov | |
| Contracts Manager | +44 •••• •••••• | ••••••••@home-office.gov |
Related topics
Topics related to Home Office Border Force Security Architecture & Assurance Service, ranked by notice volume.
- 1,484£14.9bn
- 5,684£136.4bn
- 5,183£735.8bn
- 343£2.3bn
- 2,074£309.9bn
- 3,366£105.8bn
- 1,497£10.1bn
- 26,969£1.7tn
- 2,507£313.9bn
- 1,417£20.1bn
- 4,088£269.5bn
- 4,068£249.4bn
Related buyers
Buyers similar to Home Office.
- 1,531£58.3bn
- 750£1.3bn
- 692£133.2bn
- 641£160.0bn
- 338£7.4bn
- 326£1.3bn
- 280£1.1bn
- 263£902.6m
- 228£550.1m
- 184£222.3bn
Win more public sector contracts
Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.
