MoJ Cyber Security Policy/Guidance Review & Refresh
Details
- Buyer
- Ministry of Justice
- Value
- GBP 250,000
- Published
- 12 August 2019
- Submission
- 26 August 2019
- Source
- DigitalMarketplace
Tender description
Why the Work is Being Done The Ministry of Justice (MoJ) has been working on improving it's IT security policies and guidance to update them into modern, pragmatic, user-centric content. Our goal is to have an updated portfolio that enables digital and technology delivery teams, and all of our suppliers, to easily understand their responsibilities with regards to security and privacy matters, and provide clear guidance on good ways to acheive good security outcomes. This will enable our security specialists to focus on the more complex and challenge security problems we face. Problem to Be Solved The MoJ doesn't have a totally modern security 'stack' (policies, standards, guidelines and procedures) in relation to technology. The MoJ wants to undertake a comprehensive review across the central MoJ, its executive-agencies, non-departmental public-bodies and other related/funded organisations in order to modernise. The outcomes should be revised documentation with keenly modernised positions. The work should provide internal staff, contractors, supply chain and external partners with a coherent risk-balanced 'stack' which supports the safe and secure function of the MoJ. The MoJ has been working on policy and standards improvements and is now seeking an external partner to complete this work. Who Are the Users As a designer/implementer of MoJ technology solutions, I need a clearly policies, standards and guidance so that I can build secure systems to enable the MoJ to deliver its functions. As a technology supplier to the MoJ, I need a clearly articulated and understandable set of requirements, so that my service provision to the MoJ meets the MoJ's information security requirements. As an MoJ risk owner, I need to be assured that each role involved in the design, provision, management, maintenance and support of technology within the MoJ is aware of their roles andresponsibilties in a way they can understand. Early Market Engagement None conducted. Work Already Done The MoJ Security & Privacy team previously retained technical writers to review existing MoJ technology-related information security policies and guidances. Some policies/standards were revised (such as passwords and password management) but due to the extent of the task and limited resource some policies were identified as deprecated have not yet been revised. The public work in progress MoJ policy repository can be found here: https://github.com/ministryofjustice/itpolicycontent/ The MoJ Cyber Security team has created and maintains https://ministryofjustice.github.io/security-guidance/ (source code: https://github.com/ministryofjustice/security-guidance) to provide guidance on different security topics. Existing Team MOJ Digital & Technology - Security & Privacy Team Current Phase Alpha Work Location Supplier location(s) and Petty France, London, SW1H 9AJ Working Arrangments - On-site for an-initial discovery period (as mutually agreed), as-per interviewee preferences, and the majority of analytical and drafting delivery being completed from Supplier location(s) - Use agile working-methods - At least bi-weekly progress-reports (no-less than once every 2 weeks) - Use of digital collaboration tools such as Slack and Skype for remote working where possible - Use of MoJ digital work planning tools (Jira, Confluence and Trello) where mutually agreeable - Change/source control platform Github.com - The Security & Privacy Team Project Manager to provide reviews, direction and clarification on progress on a required (but at least bi-weekly) basis Security Clearance Baseline Personnel Security Check (BPSS, https://www.gov.uk/government/publications/government-baseline-personnel-security-standard) as a minimum for any persons entering MOJ buildings and/or viewing unpublished MOJ documents Additional T&Cs - Standard Digital Outcomes and Specialist framework & call-off contract - MoJ's Travel and Subsistence policy (**no T&S payable inside M25**) Skills & Experience Outline recent experience (within the last 3 years) in advising public sector (or clients from other highly regulated environments) on information security governance Outline recent experience (within the last 3 years) in conducting user research interviews for the purposes of policy, guidance and/or procedural design Outline recent experience (within the last 3 years) in user-focused content design Outline recent experience (within the last 3 years) in user-focused technical writing Outline recent experience (within the last 3 years) in authoring content with markup languages based on plain text formatting syntax (for example, Markdown) Outline recent experience (within last 3 years) delivering HMG security policies and guidance Nice to Haves Outline recent experience (within the last 3 years) around analysing technology standards from organisations (for example, BritishStandardsInstitute or InternationalOrganizationForStandardization) in-order to inform organisational policy/guidance/standards reviews Outline recent experience (within the last 3-years) around analysing technology security standards from organisations (for example, CenterForInternetSecurity or the NationalCyberSecurityCentre) in order to inform organisational security policy/guidance/standards reviews Outline how you would-use recent public sector / highly regulated sector experience (within last 5 years) to inform content and direction, to achieve expert efficiency through this programme of work No. of Suppliers to Evaluate 5 Proposal Criteria Describe how you would approach understanding the existing MOJ technology-related information security policies, standards, guidance, procedures (etc) scope, landscape and documentation sets Describe how you would create a governance framework to allow policies, standards, guidance and procedures to be inherited between MoJ organisations Describe how you would prioritise which policies (etc) should be reviewed in which order Describe how you would approach stakeholder engagement over a diverse organisation (including independent arms-length organisations) Describe how you would approach end-user engagement over a diverse organisation to conduct user-focused interviews to establish their requirements Describe how you would ensure all documentation outputs (for example, a policy document) could be maintained by a future suitably skilled policy reviewer Cultural Fit Criteria Describe recent (within the last 3 years) experience working in the public sector or other highly regulated sector Explain how you’ll ensure collaboration at all-levels of the project and programme delivery between users, team members and management. Give examples of where you have taken this approach. Explain how you’ll ensure collaboration at all-levels of the project and programme delivery between users, team members and management. Give examples of where you have taken this approach. Payment Approach Capped time and materials Assessment Method Written proposal Presentation Evaluation Weighting Technical competence 65% Cultural fit 10% Price 25% Questions from Suppliers Budget range bidders to estimate total cost based on requirements up to a total of £250,000 (exc vat)
Timeline
- Completed: Tender published12 August 2019Current notice
- Completed: Submission date26 August 2019
About the buyer
Ministry of Justice is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.
Decision makers
Connect with the people behind this procurement.
| Contact name | Job title | Phone number | Work email |
|---|---|---|---|
| Head of Procurement | +44 •••• •••••• | ••••••••@ministry-of-justice.gov | |
| Commercial Director | +44 •••• •••••• | ••••••••@ministry-of-justice.gov | |
| Procurement Manager | +44 •••• •••••• | ••••••••@ministry-of-justice.gov | |
| Category Lead | +44 •••• •••••• | ••••••••@ministry-of-justice.gov | |
| Senior Buyer | +44 •••• •••••• | ••••••••@ministry-of-justice.gov | |
| Contracts Manager | +44 •••• •••••• | ••••••••@ministry-of-justice.gov |
Related topics
Topics related to MoJ Cyber Security Policy/Guidance Review & Refresh, ranked by notice volume.
- 5,186£736.1bn
- 4,088£269.5bn
- 4,672£63.7bn
- 5,635£560.2bn
- 4,815£66.2bn
Related buyers
Buyers similar to Ministry of Justice.
- 1,496£58.1bn
- 731£1.3bn
- 637£160.0bn
- 446£8.1bn
- 334£7.4bn
- 324£1.3bn
- 272£1.1bn
- 252£892.4m
- 224£483.9m
- 178£221.9bn
Win more public sector contracts
Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.
