Closed tender

Linux/Unix Server Environment Discovery, Patch Recommendation and Implementation

Details

Value
GBP 18,540
Published
11 May 2021
Submission
25 May 2021

Tender description

Summary of the work The MCA seeks technical support to evaluate its existing Linux Unix Server estate and provide the MCA with Operating System / AntiVirus patch status to bring the environment up to latest possible versioning and provide documented deliverables in each case. Expected Contract Length Approx 2 Months Latest start date Monday 2 August 2021 Budget Range Maximum of £18,540 inclusive of VAT Why the Work is Being Done Investment in Technology - Simplify our corporate technical infrastructure, remove all legacy services, and build resilient services. Ideally the project should deliver in 6 - 8 weeks from project start up (Summer 2021). Problem to Be Solved The MCA has a requirement for a supplier to complete a full review of the existing Linux/Unix Server environment infrastructure and to develop a plan to rationalise and provide a current patch and recommended final patch version of the Linux/Unix server estate. Who Are the Users The MCA's Linux/Unix environment estate consists of approximately 100 servers. The requirement is to complete a discovery and audit exercise to validate all server devices, their current versions and patch requirements. Validate the outputs of the discovery works against that of the MCA's existing capture of Linux/Unix Server environments and provide additional input where necessary to add value and act as single version of the truth. Work with MCA resources to determine what Linux/Unix Server environments are in scope and provide the MCA with Operating System/AntiVirus patch status to bring the environment up to latest possible version. Early Market Engagement N/A Work Already Done N/A Existing Team The successful supplier will need to work with various personnel from the MCA Information Technology team and with the MCA's partner organisations to deliver the project's outcomes. Current Phase Not started Skills & Experience • Provide evidence to show that they have a proven track record of working in a Linux Unix Server environment with extensive administrative knowledge on a Linux Unix server platform. • Provide evidence to show that they are familiar with various flavours of Linux operating systems and a working knowledge of Windows Server operating systems • Provide evidence to show that they have experience of maintenance of Linux Unix systems enhancing performance through system monitoring, analysis and patch application • Provide evidence to show that they have of experience of auditing and producing reporting outputs on Linux based systems. • Provide evidence to show that they are familiar with virtualisation and enterprise network platforms. Nice to Haves • hold Linux Unix Practitioner Qualification(s). • hold ITIL V4 Foundation Certificate. • have awareness of monitoring and patching platforms. • have familiarity with Linux Standards and Best Practice. Work Location Remote Working is acceptable. Visits to Southampton, MCA HQ for Project Start Up/Closedown meetings. Working Arrangments It is anticipated that the successful supplier will largely work remotely but some days onsite at Southampton and Fareham could be advantageous at project start up certainly. Expenses must be included within the supplier's bid. Security Clearance Resources would need to be Security Check (SC) cleared to be able to have administrative access to MCA systems. Resource will additionally be escorted whilst onsite by appropriate MCA Information Technology staff. Additional T&Cs In addition to the Standard contract terms and conditions the MCA stipulates that, as per the requirements, resources need to have Security Check (SC) clearance in place to be able to have administrative access to MCA systems for the duration of this project. Additionally, the MCA will hold the Intellectual Property Rights of all project materials and documented deliverables produced and which will not be reproduced without first acquiring the MCA's written consent. No. of Suppliers to Evaluate 3 Proposal Criteria • Technical solution • Approach and methodology - Including toolsets and initial environment requirements to be able to complete the discovery • How the approach or solution meets user needs • How the approach or solution meets your organisation's policy or goal • Estimated timeframes for the work • Identification of risks and dependencies and offered approaches to manage them • Resourcing structure • Most economically advantageous tender Cultural Fit Criteria be able to work as a team with our organisation and other suppliers to be able to achieve the project's outcomes Payment Approach Fixed price Assessment Method • Case study • Work history • Reference Evaluation Weighting Technical competence 75% Cultural fit 5% Price 20% Questions from Suppliers 1. A supplier has asked a question about ‘Linux/Unix Server Environment Discovery, Patch Recommendation and Implementation’.They asked:Is it the MCA’s aim to use paid for or free Open Source tools? In line with Government Digital Service guidelines the MCA are initially to look at open source, where it is the best fit, but not to exclude paid for tools where there is no alternative. Looking for recommendations from the selected supplier during completion of this work. 2. Does the MCA have a historical audit to work against or just a system scan?If the MCA only have a scan, what scan is it e.g. NMAP?Does the MCA have a record of all Linux/Unix devices or will their be “rogue” devices?How many departments/3rd parties have administration/jurisdiction over these systems?Does the MCA use one flavour of Anti-Virus and if so what is it?Is the exercise solely an Audit/Discovery or does it involve the patching & bringing systems up to date as well?Does the MCA have a existing Linux Management Systems(e.g. SaltStack, Ansible, Uyuni?) Collated list using various toolsets currently in .csv format.This exercise is to discover the Linux Unix server environments. There may be devices that appear as running Linux OS.The number of departments are internally one (MCA IT) and one 3rd party IT Support Provider.The MCA does not use a single Anti-Virus product. Look to standardise as part of the patching and updating service. The exercise involves patching recommendation and implementation to bring environments up to date.The MCA does not use a single Linux Management System product. Looking to standardise this as part of the patching/updating service. 3. A supplier has asked a question about ‘Linux/Unix Server Environment Discovery, Patch Recommendation and Implementation’. They asked: What Unix (Not Linux) systems do you have? The MCA currently only uses Sun Solaris Unix systems. 4. Which versions of Unix & Linux are deployed within the MCA currently? Or is that part of the discovery required by the supplier? The MCA have completed our own preliminary Linux/Unix server environment exercise within the last 6 months, but we are expecting the supplier's own discovery exercise to validate, and potentially even build upon, our own findings. 5. What virtualisation technology are you using? We currently use both VMWare and Hyper-V 6. Are all the servers accessible via ssh? Not currently, we are inviting respondents to recommend a toolset and requirements to complete the assessment, if SSH access is an essential requirement to complete the discovery, please add this to your response. 7. Please confirm the scope of this work – Is the output of this engagement a reliable inventory with a report showing current OS patch levels against a desired target state and a recommendation / plan for remediation or does the scope of this work also include the application of all OS Patches to bring the estate to the desired level? The scope of this is to complete the inventory, together with the report against the desired state and a recommendation plan including the application of as many software patches as is possible within the given timescale. 8. Are you able to give an idea of the quantity and the version / deployment type of the Solaris instances you have deployed? (Assuming the answer to the previous question about MCA only using Solaris stands) – i.e – What versions of Solaris, how many of each? Are these physical machines or virtuals? x86 or SPARC? If SPARC does the scope include patching OBP/EEPROM? The bulk of this inventory will be based upon Linux servers (approximately 95). There are no more than five physical Sun Solaris servers in our environment which are in the scope of this piece of work. We are hopeful that current versions will be ascertained as part of the discovery element of this work. However, no OBP/EEPROM patching will be required as part of the scope of these works. 9. Is the scope of this work to include consideration of valid rollback method for patching of each server? Do all servers have working consoles and use of centralised ‘admin’ server for execution of tasks as a privileged user? Are these servers running live systems and subject to change control, managed downtime, multiple stakeholders etc? 1) All change control procedures will be followed before any work is undertaken. A valid method of rollback should always be considered when patching servers, although we appreciate this is not always achievable.2) All servers will be manageable from the console screen, we do not currently utilise a central administration product or server.3) Yes, all servers are currently in use and running live systems. Change Control process will need to be followed in order to complete any patching or upgrading. This task will be sponsored by an MCA staff member. 10. What determines the target state for patched servers? – Internal guidance? Vendors/external governing bodies/audit? CIS benchmarks?Is the plan to patch servers as-is or is there any interest in consolidation/migration etc where there are advantages in doing so? 4) Target state could be determined by a number of factors, the current product running in the environment, the current supported highest version in conjunction with the installed software etc. We will always strive to install the latest security and operating system patches and updates wherever possible.5) Looking for recommendations in this area, if there are opportunities to consolidate/migrate then they will be considered. 11. Can you confirm whether the exercise includes remediation of the failed patching or just discovery/recommendation? The scope of this is to complete the inventory, together with the report against the desired state and a recommendation plan including the application of as many software patches as is possible within the given timescale. 12. What Linux Distributions & what versions do you have?Is there any patch stage servers used? Are any servers air-gapped? How many clusters?What is the percentage of vm’s?Are all servers in support? Are there any bespoke systems or are they all Standard OperatingEnvironments? The purpose of this piece of work is to produce an inventory of our Linux estate, the versions installed and the services running upon them with a view to recommendations being made and implement method for patching. 13. Is there a defined server security policy?How many environments are run?Any docker/puppet/ostree patch types?Are all systems backed up regularly and on time?Do all systems have a console/Lights out management card?Have all systems been firmware patched?Are there any software or applications that would prevent particularpatches from being deployed? Although no single policy is defined, server security is always part of each service design.We do not believe this question is relevant to our requirement. There are approximately 100 Linux/Unix server environments.There are no docker/puppet/ostree patch types.Any changes made to the server or service will be duly considered as part of the change process.All systems have console access.Most systems are virtual. For the physical servers they will be dealt with on a case by case basis as per requirements.The discovery exercise should outline any software/applications that would prevent particular patches from being deployed.

Timeline

  1. Completed: Tender published11 May 2021
    Current notice
  2. Completed: Submission date25 May 2021

About the buyer

Maritime and Coastguard Agency is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.

AI insights

  • Is there a preferred supplier?
  • What are the buyers pain points?
  • What has the buyer previously procured?
  • What are the key requirements?
Sign-up to enrich

Decision makers

Connect with the people behind this procurement.

Contact nameJob titlePhone numberWork email
Head of Procurement+44 •••• ••••••
Commercial Director+44 •••• ••••••
Procurement Manager+44 •••• ••••••
Category Lead+44 •••• ••••••
Senior Buyer+44 •••• ••••••
Contracts Manager+44 •••• ••••••

Related topics

Topics related to Linux/Unix Server Environment Discovery, Patch Recommendation and Implementation, ranked by notice volume.

View all topics

Related buyers

Buyers similar to Maritime and Coastguard Agency.

View all buyers

Win more public sector contracts

Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.