Proc 585 - Specialist Client-side Security Architecture
Details
- Buyer
- Home Office
- Published
- 29 July 2020
- Submission
- 12 August 2020
- Source
- DigitalMarketplace
Tender description
Why the Work is Being Done The Home Office is enhancing its Cyber risk management and architecture functions within portfolios to ensure that the world class services delivered to internal and external Home Office customers have a robust security framework to support them. This starts with Secure by design by embedding security architects within one or more delivery programmes to ensure security is at the forefront of developers minds. This is then backed up by security assurance to identify and help mitigate any residual risk and an Operational Security team to maintain a robust monitoring, reporting and support incident response. The security architecture function will work with internal Home Office delivery programmes and external 3rd party suppliers to ensure that the Home Office has a secure supply chain. Problem to Be Solved Supporting the Principal Security Architect by providing specialist security advice, leadership and governance for HO DDaT portfolios, programmes and projects and: • Identify, manage and address security concerns of key stakeholders • Manage and develop the security architecture team and its capabilities • Maintain the security architecture plan, and ensure it is communicated to the appropriate personnel • Provide assurance of security-related technology selection, product evaluation and proof of concepts • Ensure conformance with the target security architecture by implementation projects • Ensure gating process is followed, design and code reviews are performed, and security issues / risks are appropriately addressed • Ensure that the security architecture lifecycle is maintained & governance framework is executed • Ensure that the security architecture meets the non-functional qualities as defined by HO DDaT • Ensure that agreed security principles and standards are consistently applied and clearly communicated across HO portfolios • Ensure that dependencies are appropriately managed between HO DDaT portfolios, programmes and projects • Ensure that HO DDaT joined-up agenda is supported at portfolio, programme and project level and opportunities for re-use across HO DDaT are maximised Who Are the Users The end customers are the build, infrastructure and security operations within portfolios and the wider Home Office. The business services that are delivered by the Home Office are to a mix of other Home Office staff and public customers. Early Market Engagement Work Already Done There is an existing Security Architecture team that currently undertake all the activities required within this contract. The successful supplier will work in conjunction with the existing supplier to ensure there is a full knowledge handover. The successful bidder is expected to continue with bot the in train work and new requests from the front line business areas. Existing Team The incumbent team compromises 1 permanent Civil Servant who heads up the BICS Security Function, supported by 17 full time contractors provided by the incumbent supplier. The incumbent uses a mix of grades within its team, which is headed up by a Lead Architect. The skillset of the incumbent includes: Security Architecture, Assurance and Risk Management, Scrum Master, Ethical Hacking, security DevOps and Operational Security. Current Phase Live Work Location The principal Home Office locations where the services are expected to be performed are: o Croydon/London/Sheffield o Alternate/Offsite working locations as applicable Working Arrangments Working arrangements are a mix of onsite and remote working, depending on the prevailing business need. The onsite working location is Croydon; however, under the current Covid-19 restrictions, all work is undertaken remotely. It is expected that when the situation allows, staff will be expected to travel to the office for face-to-face meetings when required. Security Clearance Service Provider personnel need to be compliant with SC clearance. Depending on the nature of the role, if escalated and/or privileged access is necessary then there may be a requirement for DV clearance. Additional T&Cs Bid pricing will be subject to a DDaT rate card, which details the Target Rates (i.e. the rates which the Authority believes are acceptable) and the Maximum Rates (i.e. the rates in excess of which the bid will be considered non-compliant). Skills & Experience Provide details of recently (within the last 2 years): Supporting a Principal Security Architect by providing specialist security advice, leadership and governance for portfolios, programmes and projects Supporting a Principal Security Architect in shaping and leading the overall security architecture for portfolios, programmes and projects using open standards (such as TOGAF) Supporting a Principal Security Architect in developing and implementing the end-to-end risk management lifecycle for portfolios, programmes and projects Supporting a Principal Security Architect to deliver successful security accreditation for portfolio, programme and project releases Providing operational security advice to portfolios, programmes and projects Providing leadership and governance within both the central hub and a spoke of a spoke governance model Using Amazon Web Services (e.g. Lambda; EC2; KMS; Cloud* RDS databases); CI/CD Pipeline tools (e.g. Jenkins; Bitbucket; Packer); Containerisation (e.g. Kubernetes and EKS); programming capability to produce scripts (e.g. Python) Providing a searchable, collaborative capability for capturing and maintaining key security architecture knowledge Nice to Haves Provide evidence of resources that have existing SC clearance that will support the speeding up of on-boarding teams Demonstrate experience of handing over products to another team, including service transition No. of Suppliers to Evaluate 5 Proposal Criteria T1(a) - How will you manage the work and maintain quality? - 5% T1(b) - How will you quickly identify resources and on-board them on site and on the start date? - 5% T1(c) - What is your approach to transition and handover from the incumbent? - 7% T1(d) - How will you adopt the approach/solution, allowing for ongoing support and further development? - 5% T1(e) - How will you enhance the methodology and offer opportunities for improvement? - 5% T2 - Give a detailed example of where you have successfully deployed a cyber security team that undertook Architecture, Assurance and Operational security functions - 12% T3(a) - Identify the key team roles and proposed team members - 3% T3(b) - Describe your proposed team structure - 3% T4 - Describe how you would add value to individual project teams and the wider Home Office (do not discuss pricing) - 10% T5 - Presentation (shortlisted bidders only) - 10% P1 - Whole life cost (broken down by year) - 25% P2(a) - Overall Average Day Rate (total cost divided by number of staff days required) - 5% P2(b) - Rate card (not evaluated) P2(c) - Breakdown of staff days by SFIA Level and daily rate (not evaluated) C1 - Cultural fit - 5% Cultural Fit Criteria Work as a team with our organisation and other suppliers Transparent and collaborative when making decisions Have a no-blame culture and encourage people to learn from their mistakes Application of Agile Principles Ability to add value Payment Approach Capped time and materials Assessment Method Evaluation Weighting Technical competence 65% Cultural fit 5% Price 30% Questions from Suppliers No questions have been answered yet Budget range this competition includes a price-based element, so no indicative budget will be given.
Timeline
- Completed: Tender published29 July 2020Current notice
- Completed: Submission date12 August 2020
About the buyer
Home Office is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.
Decision makers
Connect with the people behind this procurement.
| Contact name | Job title | Phone number | Work email |
|---|---|---|---|
| Head of Procurement | +44 •••• •••••• | ••••••••@home-office.gov | |
| Commercial Director | +44 •••• •••••• | ••••••••@home-office.gov | |
| Procurement Manager | +44 •••• •••••• | ••••••••@home-office.gov | |
| Category Lead | +44 •••• •••••• | ••••••••@home-office.gov | |
| Senior Buyer | +44 •••• •••••• | ••••••••@home-office.gov | |
| Contracts Manager | +44 •••• •••••• | ••••••••@home-office.gov |
Related topics
Topics related to Proc 585 - Specialist Client-side Security Architecture, ranked by notice volume.
- 1,485£14.9bn
- 681£1.7bn
- 5,185£735.9bn
- 1,997£39.8bn
- 3,366£105.8bn
- 11,175£1.0tn
- 26,970£1.7tn
- 1,418£20.1bn
- 4,088£269.5bn
Related buyers
Buyers similar to Home Office.
- 1,531£58.3bn
- 750£1.3bn
- 692£133.2bn
- 641£160.0bn
- 338£7.4bn
- 326£1.3bn
- 280£1.1bn
- 263£902.6m
- 228£550.1m
- 184£222.3bn
Win more public sector contracts
Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.
