Microsoft Sentinel Deployment and a Sentinel Managed Detect and Respond (MDR) Service
Details
- Value
- GBP 220,000
- Published
- 18 March 2021
- Submission
- 1 April 2021
- Source
- uk:digital_marketplace
Tender description
Summary of the work MS Sentinel Professional Services for Deployment and a Sentinel SOC Managed Detect and Respond (MDR) Service. Expected Contract Length 12 months minimum term with an option to extend quarterly upto 24 months Latest start date Friday 30 April 2021 Budget Range It is expected / budgeted to cost no more than approximately £40k per Sentinel implementation and £400k for 12months service Why the Work is Being Done The NDA is three years into a Cyber Security and Resilience Programme, which is implementing change across all of its businesses. A key component of CSRP is the establishment of a Cyber Security Operations Capability (GSOC), which will: • Provide security operations capability across the NDA businesses using Sentinel as its core technology. • Provide a 24/7/365 Managed Detect and Respond service to the NDA businesses. • Provide Management Information reporting for the MDR service levels covering: Time to Detect and Time to Respond. Produce Daily Updates, Weekly Summary, Detailed Monthly Report and a monthly Service review call. Problem to Be Solved Provide the NDA with the ability to provision the GSOC capability, within 12 weeks of project start up. To then support the initial 12 month period of the GSOC capability deployment and its operation by supplying suitably skilled staff. Suitably skilled means, staff with relevant experience and certifications. including. Azure certified CISSP certified SANS certified Who Are the Users The lead for this work within the NDA is the CSRP Programme Manager. The users of the SOC will be the Operating Companies, Information security and IT teams. Work Already Done A successful proof of Concept based on Azure Sentinel has been completed for one of the NDA Operating Companies which is now moving into deployment. The NDA are looking for a second supplier to run the deployment across other operating Companies out at pace and also learn additional best practise ideas. Existing Team The supplier will work as part of the CSRP team, which is made up of a combination of NDA staff, contractors and other suppliers that are responsible for CSRP related services (such as Incident Response, Threat Intelligence and Assurance/Testing). The supplier may encounter other suppliers as they engage with NDA businesses, who have their own support teams and security services in place. It is not envisaged they will work with the supplier that has delivered the current pilot. Current Phase Live Skills & Experience • Have technical capability to implement Azure Sentinel and onboard logs from both on-prem and cloud based sources • Experience of deployment of appropriate data connections both IT and OT data sources • Minimum of SC clearance for staff engaged with the project • Minimum of 2 reference sentinel deployments + lighthouse implementations across multiple operating companies in a group environment • Technical capability to deploy Defender suite of products integrated into Azure Sentinel • Technical capability to deploy automated detection and response handling, e.g. on identification of crypto/malware • Threat modelling aligned to MITTRE ATT&CK framework • The ability to tune Sentinel alerts in a complex environment • Ability to on-board additional operating companies Sentinel into the managed SOC service as they come online with 2 months notice Nice to Haves • Have experience in Government and regulated environments • Hold the following security industry certifications across company employees ( next 11 entries) • Microsoft Certified Azure Security Engineer (AZ500) • Microsoft Certified 365 Security Administrator (MS500) • GIAC Certified Intrusion Analyst (GCIA) • GIAC Certified Intrusion Handler (GCIH) • GIAC Certified Enterprise Defender (GCED) • Offensive Security Certified Professional (OSCP) • CREST Registered Penetration Tester (CREST CRT) • CREST Practitioner Security Analyst (CREST CPSA) • Certified Ethical Hacker (EC|CEH) • Certified Information System Security Professional (CISSP) • Qualified Security Assessor (QSA) Work Location Delivered all through remote working but some meetings may take place in Whitehaven, Cumbria; Workington, Cumbria; and Warrington, Cheshire once Covid restrictions are lifted Working Arrangments The supplier PM, Service Manager and key personnel will be expected to be routinely available with daily stand-ups by conference call. Online communication is inevitable given the geographic spread of NDA sites Security Clearance SC minimum (or equivalent) and personnel may need to go through NDA clearance checks No. of Suppliers to Evaluate 5 Proposal Criteria • Ability to meet timeframe • Maturity and suitability of technical solution • Experience in relation to IT/OT topologies • Examples of similar, successful projects • Approach to project and task management • Value for money (including transparency of costs) Cultural Fit Criteria • Ability to work as part of CSRP team • Agility in approach and management of tasks • Focus on the outcome of the work, not the specifics of their technical capability • Willingness to share wider knowledge and experience of supplier • Willingness to take risk and responsibility Payment Approach Fixed price Assessment Method • Case study • Work history • Reference • Presentation Evaluation Weighting Technical competence 60% Cultural fit 20% Price 20% Questions from Suppliers 1. Can you please provide the rationale behind the many different qualifications needed within the supplier organisation? Seems a bit excessive for deploying Microsoft Sentinel. Our requirement is to both deploy Sentinel and provide an ongoing Managed Detect and Respond Service. We believe that an organisation that has the capability to deliver these services should ideally hold these types of qualifications. Noting that these are desirable not mandatory. Please detail any qualifications that your company many not have. 2. Can we get an idea of the Team size of the CSRP team? The CSRP team is circa 20 people 3. Does the defender suite of products include IoT defender? No this is not currently in scope. 4. Is there a list of deliverables/activities that the Supplier team is expected to do or achieve? Planning• Develop Use Cases• Costing Estimations:o data ingestiono data retention• High level design• SecOps proceduresDeployment• Low level designs• Build/deploy Azure instance• Deploy agents from on-premise and cloud infrastructure• Log data generation, collection/management• Investigation/visualisation of incidents using best practice (MITRE ATT&CK) • Azure production environment integrated Microsoft&third party solutionsSOC deliverables/activities:• 24/7 network&endpoint monitoring.• Proactive threat hunting• Actionable threat mitigation guidance• Behavioural Analytics• Develop Playbooks&automation of response• Purple teaming/continuous improvement• Scenario testing• SLA for detection&response.• RT reporting • Monthly ServReviews 5. How many log sources, device types are expected to be part of the solution? This will be determined with the operating company at the planning stages based on their needs. 6. Will you require detailed pricing at this stage of the RFP? No though estimated costs will be part of the evaluation criteria at this stage of the RFP so ball park should be shared with expected tweaks as further questions / scope come to light. 7. Does each NDA Operating Company require its own Sentinel implementation, or are they expected to share one environment? Each operating company will have it’s own sentinel instance with Azure Lighthouse deployed for central visibility. 8. Please clarify the number of Operating Companies. 2 Operating Companies 9. Please provide an assets and sources list for monitoring for each environment (e.g. Operating Company) to be monitored This will be determined with the operating company at the planning stages based on their needs. 10. Please provide a user count for each environment (e.g. Operating Company) to be monitored, along with relevant licensing levels (F1, E3) All operating companies hold E5 licencing, user numbers below:NTS – 1000 usersLLWR – 400 11. Please provide details of the IT and OT data sources in-scope for this service. IT data sources include Microsoft server/desktop and cloud technologies with some Linux variations. Networking and infrastructure is an assorted mix from major brands, including Cisco, HP, Juniper, Fortigate, Checkpoint and Palo Alto. OT sources will be discussed during onboarding process. 12. Can you clarify if you require the ability to incorporate events/logs of the additional Defender components (Defender for Identity, Defender for O365, etc) you require support to deploy and manage the Defender for Endpoint to the NDA EUC environment? Yes we require the ability to ingest defender components logs as well as the deployment. 13. Do you have specific MITRE ATT&CK Techniques in-scope for this service (Top 10, etc?) Yes, these will be shared during the engagement as they vary between operating company. 14. Do you have a roadmap for the additional operating companies to be onboarded to the service? Do you anticipate multiple companies being onboarded simultaneously or sequentially? A roadmap is in place for onboarding operating companies which will be 2 per quarter. There will be some simultaneity in each quarter for onboarding. 15. Can any details be shared of the PoC that has already been conducted? Success criteria, results, PoC build etc. The PoC implementation was focussed on the cloud services in use at the PoC operating company. 16. The ability to provision a GSOC capability within 12 weeks of project start-up – is this for a single operating company Yes this is for a single operating company. 17. How many operating companies are there? There are 7 Operating Companies currently, 2 of which will be required to be onboarded as part of this engagement. 18. The operating company that has already conducted a PoC is out of scope for this requirement? Yes the PoC operating company is out of scope for onboarding but in-scope for the managed SOC service offering. 19. Can examples of the IT and OT data sources be provided? IT data sources include Microsoft server/desktop and cloud technologies with some Linux variations. Networking and infrastructure is an assorted mix from major brands, including Cisco, HP, Juniper, Fortigate, Checkpoint and Palo Alto. OT sources will be discussed during onboarding process. 20. Regarding the Security Clearance requirement for SC minimum (or equivalent), please can you advise what equivalent clearances are acceptable. For example are any US clearances acceptable in place of SC? A UK National Security Vetting (SC) is preferred but we can accept foreign clearances such as (US) through a recognised partner. The issue is having them validated though so the Supplier would need to be able to provide all the information on the PCSIS form. Once that information is received our ONR inspector would then need to go to the Cabinet Office to have the clearances validated. This may not be a quick process and the majority of the related approvals will be outside our control.
Timeline
- Completed: Tender published18 March 2021Current notice
- Completed: Submission date1 April 2021
About the buyer
Nuclear Decommissioning Authority (NDA) is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.
Decision makers
Connect with the people behind this procurement.
| Contact name | Job title | Phone number | Work email |
|---|---|---|---|
| Head of Procurement | +44 •••• •••••• | ••••••••@nuclear-decommissioning-authority-nda.gov | |
| Commercial Director | +44 •••• •••••• | ••••••••@nuclear-decommissioning-authority-nda.gov | |
| Procurement Manager | +44 •••• •••••• | ••••••••@nuclear-decommissioning-authority-nda.gov | |
| Category Lead | +44 •••• •••••• | ••••••••@nuclear-decommissioning-authority-nda.gov | |
| Senior Buyer | +44 •••• •••••• | ••••••••@nuclear-decommissioning-authority-nda.gov | |
| Contracts Manager | +44 •••• •••••• | ••••••••@nuclear-decommissioning-authority-nda.gov |
Related topics
Topics related to Microsoft Sentinel Deployment and a Sentinel Managed Detect and Respond (MDR) Service, ranked by notice volume.
- 878£163.5bn
- 5,186£736.1bn
- 1,745£636.1bn
- 11,175£1.0tn
- 26,970£1.7tn
Related buyers
Buyers similar to Nuclear Decommissioning Authority (NDA).
- 1,661£204.4bn
- 441£232.8m
- 358£99.4m
- 349£15.0bn
- 288£2.8bn
- 255£16.6bn
- 240£507.0m
- 201£1.0bn
- 113£59.4m
- 96£936.8m
Win more public sector contracts
Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.
