MOJ Cybersecurity Log Collection and Aggregation Platform
Details
- Buyer
- Ministry of Justice
- Value
- GBP 280,000
- Published
- 18 November 2019
- Submission
- 2 December 2019
- Source
- DigitalMarketplace
Tender description
Why the Work is Being Done The Ministry of Justice (MOJ) has a diverse estate with a variety of suppliers and technical systems. We need a platform to enable log collection, aggregation, storage, analysis and targeted forwarding capabilities. Problem to Be Solved The Ministry of Justice is currently constrained in its ability to understand the cybersecurity posture of its current estates due to security logs being held in multiple systems. In many cases these systems are hard to query. The team lacks a single, centralised store of logs that can be queried to help correlate cross-system attacks and track adversarial actors' behaviours. Who Are the Users As a Cybersecurity analyst, I need to be able to easily create, edit and execute queries on logs in a variety of formats across a varied estate to convert individual events into actionable security alerts. This will allow me to monitor the estate effectively. As a member of an operational team, I need to be able to easily create, edit and execute queries across my relevant log sources to identity suspicious events and translate them into actionable security alerts. Early Market Engagement None conducted. Work Already Done The MOJ Security & Privacy team has created a proposed architecture based on the MOJ's Kubernetes cloud hosting environment (on AWS) and commonly used logging tooling (the Elasticsearch, Logstash and Kibana, or Elastic stack). This has been approved by the technical authorities, and is the recommended basis of your implementation. Existing Team MOJ Digital & Technology - Security & Privacy Team Current Phase Alpha Work Location Supplier location(s) and Petty France, London, SW1H 9AJ Working Arrangments - on-site for an initial onboarding ramp-up period (as mutually agreed) with the vast majority of delivery being completed from supplier location(s) - use agile working methods - weekly progress reports - use of MOJ online collaboration tools such as Slack and Skype for remote working - use of MOJ productivity tools such as Google G-Suite, Trello, Atlassian Jira for work planning/activity - the Security & Privacy Team Project Manager to provide reviews, direction and clarification on progress on a required (but at least weekly) basis Security Clearance Baseline Personnel Security Check (BPSS) as a minimum. See https://www.gov.uk/government/publications/government-baseline-personnel-security-standard for further guidance. Additional T&Cs Any agreed Travel or Subsistence costs would be under MoJ's Travel and Subsistence policy Skills & Experience Provide recent and demonstrable experience of implementing log collection and storage conducted in the last three years Outline recent and demonstrable experience of using the Elasticsearch, Logstash and Kibana (ELK) stack (or directly comparable substitutions) for analyzing logs conducted in the last three years Outline recent and demonstrable experience in building modular scalable technical data analytical platforms conducted in the last three years Provide recent and demonstrable experience in building modular scalable platforms using infrastructure as code principles in Kubernetes/AWS conducted in the last three years Provide recent and demonstrable experience in operating a technical platform, including patching and maintenance conducted in the last three years Provide recent and demonstrable experience of transitioning a technical system to an operations team, explaining how you transferred knowledge to the team, conducted in the last three years Nice to Haves Provide recent and demonstrable experience of Amazon Web Services' Athena and/or Elasticsearch service conducted in the last three years Provide recent and demonstrable experience of using configuration as code to build and operate systems in a cloud-native manner Provide recent and demonstrable experience of Amazon Web Services' Cloudformation conducted in the last three years Provide recent and demonstrable experience of open source development (in particular, well-made and robust code development) and accompanying solution & code documentation conducted in the last three years No. of Suppliers to Evaluate 5 Proposal Criteria Describe the method you would propose to use, referencing your experience, on how you would build a multi-tenant log aggregation platform based on the ELK (or directly comparable) stackset Describe the method you would propose to use, referencing your experience, on how you would onboard the logs from target systems Describe the method you would propose to use, referencing your experience, to build dashboards for cybersecurity analysts and how you would ensure that they had ownership of the dashboards Describe how you will ensure that the a developed platform will be flexible to ensure future expansion by any maintainer with sufficient capability Describe how you will ensure a high quality 'production ready' repeatable platform will be provided through your approach and methodology. Cultural Fit Criteria Recent and demonstrable experience of working in public sector or highly regulated environment conducted in the last three years Explain how you’ll ensure collaboration at all levels of the project and programme delivery between users, team members and management. Give examples of where you have taken this approach. Explain internal development team planning and quality assurance processes Explain how you provide knowledge sharing and handover at the end of an engagement Payment Approach Capped time and materials Assessment Method Evaluation Weighting Technical competence 60% Cultural fit 10% Price 30% Questions from Suppliers Budget range bidders to suggest total cost based on requirements up to a total of £280,000 (exc vat) including the 12 week extension.
Timeline
- Completed: Tender published18 November 2019Current notice
- Completed: Submission date2 December 2019
About the buyer
Ministry of Justice is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.
Decision makers
Connect with the people behind this procurement.
| Contact name | Job title | Phone number | Work email |
|---|---|---|---|
| Head of Procurement | +44 •••• •••••• | ••••••••@ministry-of-justice.gov | |
| Commercial Director | +44 •••• •••••• | ••••••••@ministry-of-justice.gov | |
| Procurement Manager | +44 •••• •••••• | ••••••••@ministry-of-justice.gov | |
| Category Lead | +44 •••• •••••• | ••••••••@ministry-of-justice.gov | |
| Senior Buyer | +44 •••• •••••• | ••••••••@ministry-of-justice.gov | |
| Contracts Manager | +44 •••• •••••• | ••••••••@ministry-of-justice.gov |
Related topics
Topics related to MOJ Cybersecurity Log Collection and Aggregation Platform, ranked by notice volume.
- 681£1.7bn
- 26,969£1.7tn
- 4,088£269.5bn
Related buyers
Buyers similar to Ministry of Justice.
- 1,531£58.3bn
- 750£1.3bn
- 641£160.0bn
- 458£8.1bn
- 338£7.4bn
- 326£1.3bn
- 280£1.1bn
- 263£902.6m
- 228£550.1m
- 184£222.3bn
Win more public sector contracts
Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.
