RHUL-19053 Cyber Security Discovery and Design Project
Details
- Published
- 26 February 2019
- Submission
- 12 March 2019
- Source
- DigitalMarketplace
Tender description
Why the Work is Being Done The goal of the College is to work with a Supplier to assist in this phased approach project with the initial phase of work being discovery and to assist in identifying program of works required in order to build on the substantial changes already made by the College to key business systems and their migration to the cloud. These migrations have enhanced the Colleges security posture and brought next generation security practices and tools to the forefront of IT operations The design and discovery work for this project must commence Thursday 02nd of May for a 8 week period (approx.) Problem to Be Solved The problem to be solved is for the Supplier to assist, support and work with the College through provision of expertise and knowledge of databases, networks, hardware, firewalls and encryption in order to provide the Identification of a strategic cyber security roadmap and a coherent security architecture as part of a high level design in order to support future phases of the project Who Are the Users With cyber attacks increasing against the UK education sector and as a University, RHUL want to be able to confidently work with a Supplier that will use their knowledge and expertise to help support and assist the College through their cyber security project in whatever phases their assistance is required. Early Market Engagement Early market engagement that had taken place, in summary, found that there is the requirement is for a strategy and design document to be put in place that will clarify, elaborate on and sequence a large programme of works that are expected to fall into seven different categories as described below for potential delivery: • Managing user access control • Home and mobile working • Malware prevention • Network Security • Secure configuration • Monitoring • Removable media control Work Already Done Existing Team The internal Royal Holloway University London team will comprise of; -System network specialists -Application Specialists -System Network and Application Specialists -Project Manager -Team Stakeholders, in order to provide guidance on requirements and approvals of proposals -Business Owners Current Phase Discovery Work Location Royal Holloway University London Egham Hill, Egham TW20 0EX Working Arrangments As outlined about working arrangements will be with the University's internal team. This will ensure complete transparency in works being completed and communication achieved. Work will be done on-site, daily, unless otherwise agreed and where required face to face team meetings Expenses to be in line with the University's expense policy, once we have site of rate card and expenses this can be reviewed Security Clearance It will be a requirement that whom ever has been awarded the contract signs the University NDA agreement Additional T&Cs Skills & Experience Experience establishing status & suitability of patching across server and endpoint estates, including managed devices, capabilities of configuration / patch management tools currently deployed and supporting policies and processes. Experience selecting, implementing & deploying tool(s) for performing configuration and patch management across managed devices with Windows, Mac OS X, Linux operating systems, common products including Java and Adobe products Experience selecting, implementing & deploying tool(s) for multifactor authentication (MFA) services and ensure that industry best practice and compatibility with a broad range of systems / applications is supported. Outline experience in the provision of, or the selection/ recommendation of, a Security Operations Centre (SOC) for 24/7 monitoring of networks and attached devices with appropriate alerting and response measures. Ensure solutions, processes and tools designed for specific security threats remain compatible with other related tools and services such as Log Aggregation and out sourcing to a Security Operations Centre. highlight services for the tuning of monitoring tool(s), including the existing LogRhythm tool, and the training in such tools to RHUL IT resources to enable automatic analysis, reporting, alert generation review Intrusion Prevention capabilities and configuration of existing Palo Alto firewalls with recommendation and implementation of other intrusion prevention tools confirming suitability for meeting present threats ensure application systems only have the network access they need and defining new rules where required. Approach in providing services for IT network re-design according to current best practices and to support, but not limited to, the following: Segregation of managed and unmanaged devices; review the current Sophos end point security products (one for Cloud, one for on-premise) confirm their on-going suitability as the tool of choice for both Windows and wider estate security Following review, can you advise, if necessary, of further configuration optimisation or replacement with a different security product. Ability to select, recommend & implement tools to manage DNS queries, protect the wider IT estate in addition to filtering / blocking those associated with malware & ransomware threats. Provide services for network tuning to meet required performance and quality of service criteria. Experience in analysis and design of DNS posture, external visibility and DNS, IPAM & DHCP architecture. Ability provide services for analysis and review of existing account/password sync between on-premise AD and Cloud O365 and design of a quicker, fully supported and more robust solution Outline experience in selection, recommendation and implementation of a scalable web VPN upgrade, or other appropriate mechanisms/solutions for delvering remote acccess Outline experience in above with NAC (Network Access Control) with support for user role-based access, posture checking and easy on-going maintenance with compatibility with MFA and SSO solutions. Nice to Haves Outline approach in providing services to select, implement & deploy tool(s), and define & help produce policies and processes, safeguarding against non-managed devices which access the College's networks Help establish the status of, and define procedures for, vulnerability scanning across server, endpoint estates, a range of managed devices, and the capabilities of the vulnerability scanning tools currently deployed Able to provide services for review and subsequent improvement of the student on-boarding process using existing, and, if necessary, recommended new tools. Able to provide services for the analysis and review of O365 email accounts, given to alumni with no additional tools for management or security, and recommendation of potential self-service solutions. Able to provide services for the identification, recommendation and implementation of tool(s) for new account / password creation & communication and subsequent password management. Could you evidence where you have done such a project before and how it was phased No. of Suppliers to Evaluate 7 Proposal Criteria Approach in providing for the definition and updating of security policies for server and desktop estates / Approach to a policy definition and implementation of management of network devices (e.g. firewalls, switches, etc.) to block threats and to stop the spread of malicious infections. Outline recommendation for implementation & configuration of appropriate network monitoring tools to: Better understand traffic on the University network and detect security issues; Provide network behaviour modelling; Approach to Detecting unusual behaviour of traffic on network raising / log alerts; Support sFlow monitoring (sampling approach); Support NetFlow monitoring. review Intrusion Prevention capabilities and configuration of existing Palo Alto firewalls with recommendation and implementation of other intrusion prevention tools. review Intrusion Prevention capabilities and configuration of existing Palo Alto firewalls with recommendation and implementation of other intrusion prevention tools confirming suitability for meeting present threats whilst ... …ensuring application systems only have the network access they need and defining new rules where required. Approach to providing services for analysis and design of DNS posture, external visibility and DNS, IPAM & DHCP architecture. Able to provide services for consultation, policy proposals, solution design and implementation on removable media controls and DLP (Data Loss Protection). provide analysis and review of existing, varied log on processes (ADFS, SSO, Open Athens, system specific logins) designing a more coherent end user experience for logging into student facing services Selection approach , recommendation and implementation of Cloud based tools for protection against phishing, spoofing, malware, ransomware threats by the inspection of inbound and outbound email traffic and appropriate filtering, Approach and Methodology to consultation for policy proposals, solution design and implementation on mobile working. Approach to identifying, recommending and implementing of tool(s) for new account / password creation & communication and subsequent password management. Highlight approach to Able to provide services for review and subsequent improvement of the student on-boarding process using existing, and, if necessary, recommended new tools. Output Requirement: Knowledge Transfer (RHUL to Partner), Infrastructure Estate Discovery, Detailed Requirements Analysis & Review, High Level Design, Strategic Road Map Iterations, Review & Approval Knowledge transfer workshops to facilitate completion of the ‘As Is’ Cyber Security picture. Document the ‘As Is’ picture Analysis, discussion and documentation of risk management strategies & potential solutions to inform the strategic road map, security architecture and high level design Document & present to Project Board the strategic high level Project Plan supported by the following, Work Breakdown Structure, Activity Plan, Cost Plan, Quality Plan, Communication Plan, Risk Management Plan Document the ‘As Is’ picture Document & present to the Project Board the Cyber Security strategy road map Cultural Fit Criteria •Work as a team with our organisation and other suppliers •Be transparent and collaborative when making decisions •Be transparent and collaborative when making decisions Payment Approach Fixed price Assessment Method Written proposal Case study Work history Reference Evaluation Weighting Technical competence 60% Cultural fit 20% Price 20% Questions from Suppliers Budget range
Timeline
- Completed: Tender published26 February 2019Current notice
- Completed: Submission date12 March 2019
About the buyer
Royal Holloway, University of London is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.
Decision makers
Connect with the people behind this procurement.
| Contact name | Job title | Phone number | Work email |
|---|---|---|---|
| Head of Procurement | +44 •••• •••••• | ••••••••@royal-holloway-university-of-london.gov | |
| Commercial Director | +44 •••• •••••• | ••••••••@royal-holloway-university-of-london.gov | |
| Procurement Manager | +44 •••• •••••• | ••••••••@royal-holloway-university-of-london.gov | |
| Category Lead | +44 •••• •••••• | ••••••••@royal-holloway-university-of-london.gov | |
| Senior Buyer | +44 •••• •••••• | ••••••••@royal-holloway-university-of-london.gov | |
| Contracts Manager | +44 •••• •••••• | ••••••••@royal-holloway-university-of-london.gov |
Related topics
Topics related to RHUL-19053 Cyber Security Discovery and Design Project, ranked by notice volume.
- 1,485£14.9bn
- 5,185£735.9bn
- 2,074£309.9bn
- 11,175£1.0tn
- 182£2.7bn
- 26,970£1.7tn
- 2,507£313.9bn
Related buyers
Buyers similar to Royal Holloway, University of London.
- 337£19.0m
- 270£317.1m
- 132£196.2m
- 124£173.5m
- 114£48.2m
- 112£11.7m
- 101£60.1m
- 97£55.7m
- 85£83.4m
- 84£16.0m
Win more public sector contracts
Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.
