MOJ Cybersecurity scanning and open data intelligence platform
Details
- Buyer
- Ministry of Justice
- Published
- 16 January 2019
- Submission
- 30 January 2019
- Source
- DigitalMarketplace
Tender description
Why the Work is Being Done The Ministry of Justice (MOJ) has a diverse and sizeable technology estate which presents challenges for vertical and horizontal analysis for cybersecurity purposes such as technical security configuration, upstream supply chain analysis and other metrics. The MOJ wish to create an platform that will gather technical indicators from a series of sources (Amazon Web Services Route53, Microsoft Azure DNS and so on) utilise scanning techniques (create localised scripts but also leverage urlscan.io and beyond) and import the data into an analytical toolset (for example, Elasticsearch/Logstash/Kibana) and provide the capability for searching, alerting (triggers) and otherwise analysis. Problem to Be Solved "The Ministry of Justice (MOJ) is currently limited in its capability to understand the size of it's web operations presence and ascertain the cybersecurity posture of that estate - for example: how many public websites are based on *.justice.gov.uk and how many of those are configured with modern Transport Layer Security (TLS). The MOJ through this work will be able to analyse technical security indicators across its known web presence in order to advise the wider MOJ on problematic areas that require, or may soon require, mitigation efforts and otherwise investment." Who Are the Users As the MOJ Chief Information Security Officer and/or MOJ Senior Security Advisor, I need to know the size of MOJ's public technology estate and have a data-led approach to advise the MOJ Permanent Secretary and MOJ Executive Committee on where cybersecurity investment is required. As a MOJ Cybersecurity analyst, I need to be able to analyse technical security and create alerts and reports. Early Market Engagement None conducted. Work Already Done The MOJ Security & Privacy - 'Red team' has created a discardable Elasticsearch/Logstash/Kibana (ELK) environment in a Public Cloud provider, and has manually imported some data sources for experimental analysis. (This environment can be enhanced and used, or discarded). Existing Team MOJ Digital & Technology - Security & Privacy Team Current Phase Alpha Work Location Supplier location(s) and 102 Petty France, London, SW1H 9AJ Working Arrangments "On site for an initial onboarding and discussion period (as mutually agreed) with the vast majority of delivery being completed from Supplier location(s) Use agile working methods Weekly progress reports Use of on line collaboration tools such as Slack and Skype for remote working. The Security & Privacy Team Project Manager to provide reviews, direction and clarification on progress on a required (but at least weekly) basis" Security Clearance Baseline Personnel Security Check (BPSS) as a minimum. See https://www.gov.uk/government/publications/government-baseline-personnel-security-standard for further guidance. Additional T&Cs Standard Digital Outcomes and Specialist contract and MoJ's Travel and Subsistence policy. Please see: https://www.gov.uk/government/publications/digital-outcomes-and-specialists-2-call-off-contract Skills & Experience Provide recent and demonstrable experience in advising on technical security scanning solutions for large and diverse IT estates conducted in the last three years Outline recent and demonstrable experience in implementation of technical security data analytical toolsets and platforms conducted in the last three years Outline recent and demonstrable experience in open source intelligence and vulnerability information gathering (for public domains) conducted in the last three years Outline recent and demonstrable experience in building modular scalable technical data analytical platforms conducted in the last three years Provide recent and demonstrable experience in authoring code that performs analytical correlation functions conducted in the last three years Provide recent and demonstrable experience in building modular scalable platforms using infrastructure as code principles in AWS conducted in the last three years Nice to Haves Provide recent and demonstrable experience of Amazon Web Services' Kinesis Data Firehose conducted in the last three years Provide recent and demonstrable experience of Amazon Web Services' Athena and/or ElasticSearch conducted in the last three years Provide recent and demonstrable experience of Amazon Web Services' QuickSight conducted in the last three years Provide recent and demonstrable experience of Amazon Web Services' Lambda & Lambda Layers conducted in the last three years Provide recent and demonstrable experience of Python development Provide recent and demonstrable experience of open source development (in particular, well-made and robust code development) and accompanying solution & code documentation conducted in the last three years Provide recent and demonstrable experience of open source intelligence platforms and tools for the analysis of publicly accessible IP addresses, servers, domains and websites conducted in the last three years No. of Suppliers to Evaluate 5 Proposal Criteria Describe the method you would propose to use, referencing your experience, on how you would architect a scanning and data analysis platform Describe the method you would propose to use, referencing your experience, which data sources a cybersecurity analysis tool should be used Describe the method you would propose to use, referencing your experience, how data should be analysed and metrics be created from underlying datasets Describe the method you would propose to use, referencing your experience, how trigger levels should be created in a cybersecurity technical data system should be created Describe how you will ensure a high quality 'production ready' repeatable platform will be provided through your approach and methodology. Describe how you will ensure that the a developed platform will be flexible to ensure future expansion by any maintainer with sufficient capability Cultural Fit Criteria Recent and demonstrable experience of working in public sector or highly regulated environment conducted in the last three years Explain how you’ll ensure collaboration at all levels of the project and programme delivery between users, team members and management. Give examples of where you have taken this approach. Explain internal development team planning and quality assurance processes Payment Approach Time and materials Assessment Method Written proposal Evaluation Weighting Technical competence 65% Cultural fit 10% Price 25% Questions from Suppliers Budget range
Timeline
- Completed: Tender published16 January 2019Current notice
- Completed: Submission date30 January 2019
About the buyer
Ministry of Justice is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.
Decision makers
Connect with the people behind this procurement.
| Contact name | Job title | Phone number | Work email |
|---|---|---|---|
| Head of Procurement | +44 •••• •••••• | ••••••••@ministry-of-justice.gov | |
| Commercial Director | +44 •••• •••••• | ••••••••@ministry-of-justice.gov | |
| Procurement Manager | +44 •••• •••••• | ••••••••@ministry-of-justice.gov | |
| Category Lead | +44 •••• •••••• | ••••••••@ministry-of-justice.gov | |
| Senior Buyer | +44 •••• •••••• | ••••••••@ministry-of-justice.gov | |
| Contracts Manager | +44 •••• •••••• | ••••••••@ministry-of-justice.gov |
Related buyers
Buyers similar to Ministry of Justice.
- 1,538£58.4bn
- 751£1.3bn
- 641£160.0bn
- 463£8.5bn
- 338£7.4bn
- 327£1.3bn
- 281£1.1bn
- 265£902.8m
- 228£550.1m
- 186£223.2bn
Win more public sector contracts
Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.
