Awarded contract

Security Testing

Details

Supplier(s)
CGI IT UK Ltd
Value
GBP 182,000
Published
30 May 2018

Tender description

Summary of the work We have a requirement for penetration testing on a complex bespoke network and it's component systems. We will require approximately 2-3 tests per year over the next two years by CHECK accredited, DV cleared testing team. Expected Contract Length 2 years Latest start date Monday 28 May 2018 Budget Range Each penetration Test task will consist of a capped time and materials value of 35 man/days with a maximum day rate of £1100 Ex VAT and inclusive of T&S. We estimate approximately 2-3 tests per year with a minimum of 2 months notice before each test. Why the Work is Being Done The Authority has a requirement for several penetration tests in order to provide evidence for the ongoing accreditation of a bespoke computer network, approximately 2 tests per calender year. The first the first of these is currently scheduled to happen in June of this year. Subsequent tests would be at dates mutually agreed between the parties with a minimum of 2 months notice. The second test is estimated to be required towards the end of 2018. Problem to Be Solved Penetration testing a fundamental requirement of ongoing system accreditation. Who Are the Users So that the System Design Authority are able to continue to develop and operate the network there is an ongoing requirement for penetration testing. Early Market Engagement N/A Work Already Done The systems development is ongoing and there have been 2 previous penetration tests. These have been illustrative in determining the scale of this requirement and the estimated number of days for each penetration testing task. Existing Team The supplier will be performing security tests in support of the system design authority, this a multi-disciplinary team dedicated to the delivery and support of system capability; the team is comprised of system engineers, QA, network engineers, Security and delivery / project managers. Current Phase Beta Skills & Experience • CHECK Accredited • Microsoft System Centre ‘Suite’ 2012 • Active Directory • Windows 10 (inc Kiosk Mode) • Windows Orchestrator • Out of Band Management • Reference Management LAN • Must complete the Supplier Assurance Questionnaire at: http://supplier-cyber-protection.service.gov.uk/ using assesment reference: RAR-24BBRHGS Risk profile: Moderate Nice to Haves • WSUS • Hyper-V • App-V • WEF • RBAC Work Location Exact address to be provided on contract award. Working Arrangments The work will be required to be completed on-site during normal working hours, this will include face-to-face interaction and presence at a stand-up and wash-up session. Security Clearance This contract will require every member of the test team is DV cleared and a UK national. This is a fundamental and essential requirement of this competition. Due to the time scales involved proposed staff for the initial test must hold DV clearance to apply at time of application. Additional T&Cs The following conditions will apply to this contract, full text can be found here: https://www.gov.uk/guidance/acquisition-operating-framework DEFCON 5J (Edn 18/11/16) DEFCON 76 (Edn 12/06) DEFCON 501 (Edn 11/17) DEFCON 502 (Edn 05/17) DEFCON 513 (Edn 11/16) DEFCON 522 (Edn 11/17) DEFCON 658 (Edn 10/17) please see technical competence criteria. DEFCON 659A (Edn 02/17) DEFCON 660 (Edn 12/15) DEFCON 703 (Edn 08/13) No. of Suppliers to Evaluate 5 Proposal Criteria • Evidence of previous security testing activities • Work history and experience of the proposed testing team • Approach and methodology to penetration testing task • Value for Money Cultural Fit Criteria • Work with our team including other contractors. • Share knowledge and experience freely across the team. • Be comfortable standing up for this discipline and behind their recommendations. Payment Approach Capped time and materials Evaluation Weighting Technical competence 65% Cultural fit 5% Price 30% Questions from Suppliers 1. Please can you confirm whether the requirement of CHECK Accreditation applies to the organization generally or, specifically to the DV cleared personal or team carrying out the required works? The supplier must hold CHECK Accreditation, however in order to operate under the CHECK scheme at least one individual from the test team must be CHECK Accredited to CHECK Team Leader status. This gives the company 'Green Light' status from the National Cyber Security Centre which we require. 2. Does a supplier have to be a "Green Light" organisation or can a CHECK Team Leader with DV Clearance, if they are able to complete a Penetration test within 35 days, meet the criteria? The supplier must be a 'Green Light' organisation. The requirement is for a ‘CHECK Accredited Test Team’ as per the definition on the NCSC website (https://www.ncsc.gov.uk/scheme/penetration-testing). An individual CHECK team leader does not satisfy the requirement for a 'Test Team'.

Timeline

  1. Completed: Award published30 May 2018
    Current notice
  2. Completed: Award date30 May 2018

About the buyer

Defence Equipment and Support : Ministry of Defence is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.

AI insights

  • Is there a preferred supplier?
  • What are the buyers pain points?
  • What has the buyer previously procured?
  • What are the key requirements?
Sign-up to enrich

Decision makers

Connect with the people behind this procurement.

Contact nameJob titlePhone numberWork email
Head of Procurement+44 •••• ••••••
Commercial Director+44 •••• ••••••
Procurement Manager+44 •••• ••••••
Category Lead+44 •••• ••••••
Senior Buyer+44 •••• ••••••
Contracts Manager+44 •••• ••••••

Win more public sector contracts

Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.