Closed tender

Threat Intelligence for Department of Health and NHS Blood and Transplant

Details

Published
30 October 2017
Submission
13 November 2017

Tender description

Why the Work is Being Done Government Departments must remain resilient to cyber-attacks. To help these departments achieve this goal, the Cabinet Office launched a pilot GBEST security assessment framework. The pilot scheme promotes intelligence-led penetration testing that seeks to mimic the actions of cyber attackers intent on compromising an organisation’s Critical Functions and the technology assets and people supporting those functions. The provision of Threat Intelligence will provide insight into the most secure way to manage two critical NHS Blood and Transplant systems. Problem to Be Solved The key functions that would lead to compromise of confidentiality and integrity relate primarily to the blood services (Hematos and Pulse systems) and the organ transplant services (ODT system). These systems contain highly confidential data where, if compromised could result in severe clinical harm to many patients/donors. The provider is expected to supply a summary of key threats to the functioning of these core functions, detailing the highest scoring threats to be prioritised by the Penetration Testers. Reports are expected to be the standard of CBEST, prioritising risks to address in Phase 3 Penetration Test. Who Are the Users Government Departments need to ensure that they remain resilient to cyber attacks to ensure the safety of UK citizens. They need to be aware of any potential weaknesses and key threats so that these can be addressed and rectified. Early Market Engagement Work Already Done Existing Team Suppliers will be working with representatives from the Department of Health, NHS Digital, NHS Blood and Transplant, Cabinet Office and National Cyber Security Centre. Current Phase Not applicable Work Location Expected to be flexible and occasionally travel to NHS Blood and Transplant sites in England. Most work will be remote. Working Arrangments To be agreed at contract award but will include 3 weeks of Threat Intelligence to be done ahead of a Penetration Testing period conducted by a separate service provider. 1 week overlap of work with Penetration Test service providers. Some availability required during Penetration testing phase that will last 6 weeks to answer any relevant questions from the Penetration Tester. Security Clearance SC preferable with all those working on the project to have CTC as a minimum. Further details on security clearance can be found here: http://intranet.cabinetoffice.gov.uk/task/security-vetting/ Content is of a highly sensitive nature. Additional T&Cs The provider must share information as laid out in the GBEST Implementation Guide and abide by the GBEST Principles. Any non-disclosure agreements must not hinder the delivery of the scheme, specifically, relevant information should be readily shared between the Threat Intelligence provider, the Penetration Tester and GDS. All expenses must be pre-agreed between the parties and must comply with the Cabinet Office Travel and Subsistence Policy. All vendors are obliged to provide sufficient guarantees to implement appropriate technical and organisational measures so that the processing meets the requirements of GDPR and ensures the protection of the rights of data subjects. Skills & Experience Be CBEST approved, CREST certified Threat Intelligence Manager successfully assessed against CBEST criteria to supply CBEST Threat Intelligence Services Have experience of assisting customers with Threat Modelling Nice to Haves Previous experience of CBEST TI development. Previous experience of CBEST application. No. of Suppliers to Evaluate 4 Proposal Criteria Project plan. Previous experience. Teams structure and CV's. Value for Money. Cultural Fit Criteria Describe their approach for working with the Buyer (and alongside other suppliers) as part of an integrated, co-located effective and efficient delivery team. Describe their experience of working with an organisation with the following characteristics: • Critical 24x7 Services • Healthcare Sector • Secure services Payment Approach Fixed price Assessment Method Written proposal Evaluation Weighting Technical competence 65% Cultural fit 15% Price 20% Questions from Suppliers No questions have been answered yet Budget range

Timeline

  1. Completed: Tender published30 October 2017
    Current notice
  2. Completed: Submission date13 November 2017

About the buyer

NHS Blood and Transplant is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.

AI insights

  • Is there a preferred supplier?
  • What are the buyers pain points?
  • What has the buyer previously procured?
  • What are the key requirements?
Sign-up to enrich

Decision makers

Connect with the people behind this procurement.

Contact nameJob titlePhone numberWork email
Head of Procurement+44 •••• ••••••
Commercial Director+44 •••• ••••••
Procurement Manager+44 •••• ••••••
Category Lead+44 •••• ••••••
Senior Buyer+44 •••• ••••••
Contracts Manager+44 •••• ••••••

Related topics

Topics related to Threat Intelligence for Department of Health and NHS Blood and Transplant, ranked by notice volume.

View all topics
TopicCountValue
  1. 5,186
    £736.1bn
  2. 1,418
    £20.1bn

Win more public sector contracts

Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.