Security Testing Engagement Partner
Details
- Buyer
- Met Office
- Supplier(s)
- NCC Group Security Services Limited
- Value
- GBP 120,000
- Published
- 10 February 2017
- Source
- uk:digital_marketplace
Tender description
Summary of the work An ongoing project to provide IT health checks and penetration testing; knowledge transfer and other security-related services. Expected Contract Length 18 months, plus a possible 6 month extension Latest start date 14/11/2016 Budget Range £60,000 to £100,000 per annum. Why the Work is Being Done As an organisation, we need to regularly carry out IT health checks/penetration testing and accreditation of new projects and also our existing systems and services. Rather than procure these on an ad-hoc basis, we are seeking to partner with an established provider of these services over a longer-term period. Problem to Be Solved Agile and consistent IT health checks and penetration testing of our newly developed and existing products and services. Who Are the Users As the Met Office Security Testing Team and Accreditation team, we need to identify and work with an established IT Security testing partner, so that we can assure and test our products and services. Work Already Done The Met Office has a standard, established process for engaging external security testing (see also Working Arrangements below). Existing Team The Met Office has an internal Security Testing team who will be co-ordinating all partner engagements. Current Phase Live Skills & Experience • An established and recognised provider of penetration testing services • Web Application testing (CHECK and CREST Accredited) • Infrastructure testing (CHECK and CREST Accredited) • Build reviews (CHECK and CREST Accredited) • Code reviews (CHECK and CREST Accredited) • Firewall and networking audits (CHECK and CREST Accredited) • Wireless and networking audits (CHECK and CREST Accredited) • Security Training • Knowledge Transfer Nice to Haves • Mobile device and application testing • Incident response • Social engineering • Physical security Work Location The Met Office has its headquarters in Exeter, where the majority of engagements will take place if an on-site visit is required. Remote working is an option where this is appropriate and possible. The Met Office has a number of outstations around the UK, where some engagements may be required to take place, although this will be a minority, if any. Working Arrangments In general, for each engagement, a Target of Evaluation (ToE) will be provided and should be mutually agreed with a proposal/test plan. Once agreed, this engagement will be arranged and scheduled with initiation and conclusion meetings taking place. A detailed test exit report with recommendations must be provided as per CHECK practices. Security Clearance SC clearance is required for this engagement. Some limited engagements may require DV clearance. Please consider when responding, the necessity for some individuals to be willing and able to pass DV clearance. This is expected to be a low number of engagements. No. of Suppliers to Evaluate 5 Proposal Criteria • The experience and professionalism of the provider • The thoroughness and efficiency of the test plan/proposal • The lead time to complete an engagement • The value for money of the proposal Cultural Fit Criteria • Timeliness and effectiveness of communication • Willingness to engage as a partner • Openness and approach to knowledge transfer/training Payment Approach Time and materials Evaluation Weighting Technical competence 60% Cultural fit 20% Price 20% Questions from Suppliers 1. Hello, Can you please clarify the submission requirements for this procurement exercise? It is mentioned in the contract notice that bidders will be evaluated based on •Written proposal •Case study •Work history •Presentation However when we tried to access the application, it is just a questionnaire for us to complete. Can you please clarify if you want the additional info sent to you by separate email ( as there is no space for additional attachments) or do we need to fill just the questionnaire for this stage? Many thanks At this stage, we only require you to complete the questionnaire. The DOS process is a two-stage process. If shortlisted for the evaluation stage we would then require the Written proposal, case study, work history and presentations to be completed. 2. Is CREST accreditation alone sufficient to be eligible for this opportunity? If not, what does CHECK give the Met Office that CREST does not? We may stipulate CHECK for some formal IT Health Checks, in part due to the security clearance and official sensitive information handling requirements of this accreditation. Without CHECK a more limited amount of work may be available through this opportunity, but we would nevertheless encourage you to apply. 3. We would love to work with you on this opportunity, however we currently not CHECK accredited, however we have CREST accreditation and obviously are held in high regard for our Security practise across the world. Would this preclude us from applying? Until earlier this year we were CHECK accredited but this has lapsed due to customers not requesting this accreditation over the last year. We may stipulate CHECK for some formal IT Health Checks in part due to the security clearance and official sensitive information handling requirements of this accreditation. Without CHECK a more limited amount of work may be available through this opportunity, but we would nevertheless encourage you to apply. If you have held CHECK accreditation, then we would obviously encourage you to mention that where possible, and we may encourage you to re-accredit yourselves. 4. 1. Approximately how many days testing is required per annum? 2. How much notice can you provide prior to a test being conducted? We are anticipating 60-80 days worth of testing in a given year. Notice is flexible, we would expect to arrange dates 2-4 weeks in advance, but would be able to communicate our intention to test earlier.
Timeline
- Completed: Award published10 February 2017Current notice
- Completed: Award date10 February 2017
About the buyer
Met Office is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.
Decision makers
Connect with the people behind this procurement.
| Contact name | Job title | Phone number | Work email |
|---|---|---|---|
| Head of Procurement | +44 •••• •••••• | ••••••••@met-office.gov | |
| Commercial Director | +44 •••• •••••• | ••••••••@met-office.gov | |
| Procurement Manager | +44 •••• •••••• | ••••••••@met-office.gov | |
| Category Lead | +44 •••• •••••• | ••••••••@met-office.gov | |
| Senior Buyer | +44 •••• •••••• | ••••••••@met-office.gov | |
| Contracts Manager | +44 •••• •••••• | ••••••••@met-office.gov |
Related topics
Topics related to Security Testing Engagement Partner, ranked by notice volume.
- 2,074£309.9bn
- 2,507£313.9bn
- 1,417£20.1bn
Related buyers
Buyers similar to Met Office.
- 2,657£1.7bn
- 900£19.4bn
- 688£8.8bn
- 472£15.4bn
- 433£3.8bn
- 350£20.5m
- 301£368.1m
- 252£578.5m
- 240£10.1bn
- 171£48.3m
Win more public sector contracts
Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.
