Cyber Security Governance Risk and Compliance (GRC) Implementation Partner
Details
- Buyer
- Home Office
- Value
- GBP 4,000,000
- Published
- 8 December 2017
- Submission
- 22 December 2017
- Source
- DigitalMarketplace
Tender description
Why the Work is Being Done The Home Office is growing its digital presence and becoming more data driven. A review of the cyber security for Home Office systems and data identified a number of actions required to securely enable this transformation, these include: • Improving Home Office cyber security assurance processes by ensuring a risk-based approach, with the right level of technical rigour. • Upgrading the security controls around core Home Office infrastructure. • Building a central Cyber Security Operations Centre (CSOC) capability to monitor Home Office. • Testing incident response processes, including simulating the impact of a major cyber incident on the department. Problem to Be Solved Building on existing resources, establish a new central cyber security governance team, specifically: 1. Provide an interim BAU team for up to 12 months. 2. Establish Team processes and reporting cycle, integrate with wider Home Office governance and embed in BAU. 3. Produce/provide baseline Home Office Cyber Security Policies and Standards. 4. Determine and pilot a methodology to measure business risk appetite and reporting. 5. Determine and pilot a ‘Secure by Design’ process. 6. Support ServiceNow GRC module integration by defining requirements / workflow and conducting acceptance testing. 7. Support enduring Team recruitment and embed the team, including knowledge transfer Who Are the Users The GRC team will report to the Head of Cyber Security, and will work across all Business Units within the Home Office, working with Asset owners to allow them to determine and measure the exact nature of their cyber risk and tolerances, that security resources are prioritised in accordance with our risk appetite and deliver return on investment, and with technical teams to ensure new systems are designed and maintained to a set of approved HO wide Security policies and standards. Early Market Engagement Work Already Done A Discovery phase has delivered a GRC Strategy setting out the approach and activities to establish a GRC team and a Target Operating Model defining the team’s high level processes, organisation and governance. A set of draft Cyber Security Policies have been started, aligned to Cabinet Office objectives, and an initial list of required Cyber Security Standards has been created. Activities to define the Cyber demand model and KPIs, are planned to complete before this work commences. A limited number of existing cyber security resources (security architects, accreditors, policy managers) will need to be incorporated into the new structure. Existing Team The GRC Implementation Partner will build upon the limited resources described above and will work with a range of internal and external stakeholders, within a complex ecosystem of suppliers. To illustrate, the GRC Implementation Partner will need to collaborate with the overarching programme delivery partner(s), and with multiple other service providers within the cyber and infrastructure programmes. Current Phase Not applicable Work Location The team will be delivering output and outcomes primarily with a team located in Croydon and Central London. It is envisaged that travel to other Departmental locations in the UK may be required. Working Arrangments The supplier’s team will be required to be located on site for five days-per-week, whether alongside the programme team in Croydon or London, or at other Departmental locations around the UK. It is envisaged that the GRC Implementation team will consist of 8-10 Consultants, including an overall Delivery Manager, and a TDA. The interim GRC BAU team will number 3x FTE consisting of Policy Consultants and Risk Analysts. Day rates will be inclusive of travel and subsistence within M25. Travel and subsistence outside of M25 will be reimbursed in line with the Departmental policy, after approval from the HO-service manager. Security Clearance Individuals in the supplier’s team will require SC clearance, or be willing to undergo SC clearance checks. SC clearance needs to have been achieved before work can commence. Additional T&Cs The payment approach is Fixed Price, but specific elements will be capped T&M, to be explained further in the pricing schedule Skills & Experience Outline experience of designing and delivering Governance Risk and Compliance function within cyber security programmes in the last 3 years Outline experience in implementing Governance Risk and Compliance function methodologies, tools and resources Outline experience of implementing a suite of Governance Risk and Compliance policies and standards within cyber security programmes in the last 3 years Outline experience in running successful communications campaigns around cyber security awareness in the last 3 years Outline experience of setting up a BAU team including conducting organisational design and training needs analysis, supporting recruitment, training newly appointed staff and knowledge transfer to the enduring team Outline experience of mobilising an experienced GRC Operating model implementation and transformation team within the timescales and to managing its performance over the entire contract duration Outline experience of collaborating and working alongside external delivery partners to enable the delivery of the wider Cyber Security Programme Nice to Haves Outline experience of collaboration and functioning within complex ecosystems of suppliers and internal stakeholders, and ensuring that the end customer needs are represented and met Proven thought leadership in implementing cyber risk assessment methodologies in complex governmental organisations. Relevant professional qualifications, memberships and contributions to cyber security knowledge, corporately or by proposed team members No. of Suppliers to Evaluate 4 Proposal Criteria Approach and methodology in planning and managing the delivery of the various work packages. Solution design methodology and governance Proposed team structure including CVs and relevant experience of named team members Mobilisation plan, including capacity to be flexible with requirements and ability to quickly draw on/source other skills sets as required. Supplier Exit Strategy, including knowledge transfer to HO BAU teams. Risks identified with approach suggested and the solution to manage those risks. Ensuring consistency of staff within the GRC implementation team Value added activities which further improve delivery confidence Cultural Fit Criteria Approach to functioning effectively and collaboratively in a complex multi-supplier environment. Approach to proactive issue management, problem resolution and improving ways of working Approach to leading by example to keep data secure. Approach to leveraging existing supplier knowledge and experience to the benefit of the wider programme Strategy for leaving a sustainable legacy by providing learning opportunities / knowledge transfer events for the wider HO team. Payment Approach Fixed price Assessment Method Written proposal Work history Presentation Evaluation Weighting Technical competence 50% Cultural fit 20% Price 30% Questions from Suppliers Budget range £2.5m - £4m
Timeline
- Completed: Tender published8 December 2017Current notice
- Completed: Submission date22 December 2017
About the buyer
Home Office is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.
Decision makers
Connect with the people behind this procurement.
| Contact name | Job title | Phone number | Work email |
|---|---|---|---|
| Head of Procurement | +44 •••• •••••• | ••••••••@home-office.gov | |
| Commercial Director | +44 •••• •••••• | ••••••••@home-office.gov | |
| Procurement Manager | +44 •••• •••••• | ••••••••@home-office.gov | |
| Category Lead | +44 •••• •••••• | ••••••••@home-office.gov | |
| Senior Buyer | +44 •••• •••••• | ••••••••@home-office.gov | |
| Contracts Manager | +44 •••• •••••• | ••••••••@home-office.gov |
Related topics
Topics related to Cyber Security Governance Risk and Compliance (GRC) Implementation Partner, ranked by notice volume.
- 1,485£14.9bn
- 2,200£16.7bn
- 407£6.4bn
- 5,185£735.9bn
- 165£2.7bn
- 3,366£105.8bn
- 4,088£269.5bn
- 1,114£12.3bn
Related buyers
Buyers similar to Home Office.
- 1,531£58.3bn
- 750£1.3bn
- 692£133.2bn
- 641£160.0bn
- 338£7.4bn
- 326£1.3bn
- 280£1.1bn
- 263£902.6m
- 228£550.1m
- 184£222.3bn
Win more public sector contracts
Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.
