NDA Group Security Architecture Resource
Details
- Value
- GBP 3,000,000
- Published
- 24 August 2021
- Submission
- 7 September 2021
- Source
- uk:digital_marketplace
Tender description
Summary of the work The NDA is looking for a supplier to provide resource with the necessary knowledge, skills and experience to help meet the demands for Security Architecture expertise across the NDA estate, on a range of projects and BAU activities. Example work packages: Network Segregation Expansion, Azure IaaS workload migration, PAW/Red Forest. Expected Contract Length 2 years Latest start date Monday 1 November 2021 Budget Range £2- £3 million over 2 years Why the Work is Being Done The NDA is 3 years into a Cyber Security and Resilience Programme, which is implementing change across all of its 8 operating companies. A key component of CSRP is the establishment of a Security Architecture resource contract, which will provide operating companies with access to contract Security Architecture resources aligned to CIISec roles. Contract Security Architecture roles will be used for BAU as well as project activity to support operating companies in the delivery of their objectives. Problem to Be Solved Support the Cyber Security teams at NDA operating companies by providing architectural security advice, leadership and governance to programmes, projects and BAU activity and:- • Advise on security architecture designs for proposed systems and changes • Development of Security Architecture Polices, Principles, Patterns and Standards • Making and guiding effective decisions for highly complex architectures both on premise and in cloud environments • Articulating the impact of vulnerabilities on existing and future designs and systems to senior stakeholders • Advising on security concepts at a technical level across multiple projects, working with security tools, network security infrastructure technologies, and information security management frameworks Who Are the Users As the lead for this work within the NDA , the CSRP Programme Manager will coordinate this activity and work but the work itself will be conducted for one of the 7 NDA operating companies. Existing Team The supplier will work as part of the CSRP team, which is made up of a combination of NDA staff, contractors and other suppliers that are responsible for CSRP related services. The supplier may encounter other suppliers as they engage with NDA businesses, who have their own support teams and security services in place. Current Phase Discovery Skills & Experience • Recent experience (within the last 2 years) of placing Technical Security Architects/Senior Security Architects into delivery teams in government or Critical National Infrastructure • Evidence of supporting architecture functions in shaping the overall security architecture for portfolios, programmes and projects using open standards (such as TOGAF) • Evidence of providing architectural security advice to portfolios, programmes and projects for both OT and IT environments • Evidence of developing, documenting and maintaining security-architecture, policies and procedures, Security risk assessments. Conduct internal security-audits/remediation. Manage external security-audit. Ongoing skills-transfer and documentation. • Designing, delivering, securing cloud based security architecture. Ensuring security controls are appropriate to mitigate, minimise, treat discovered risks. Technical assurance to ensure compliance with security architecture, covering new/legacy systems • Ability to deliver an Agile project, using relevant programme tools • Ability to work with CSRP and operating companies to track and plan out forward work load across the NDA group. Nice to Haves • Experience in NDA/ONR environment • Already SC Cleared Personnel Work Location Predominantly home based with some travel likely to the following locations: Herdus House, Westlakes Science & Technology Park, Moor Row, Cumbria, CA24 3HU Hinton House, Birchwood Park Avenue, Risley, Warrington, WA36GR Dounreay Site Restoration Ltd, Dounreay, Thurso, Caithness, KW14 7TZ Sellafield Site, Sellafield, Seascale, Cumbria, CA20 1PG Nuclear Transport Solutions, Regents Court, Baron Way, Carlisle, Cumbria, CA64SJ RWM, Building 329, Thompson Avenue, Harwell Campus, Didcot, Oxfordshire, OX11 0GD Magnox Ltd, Oldbury Technical Centre, Oldbury Naite, Thornbury, South Glos, BS35 1RQ Pelham House, Pelham Drive, Calderbridge, Cumbria, CA201DB Working Arrangments Predominantly Home based working in the short term with on-site work at the discretion of the operating company. The supplier PM and key personnel will be expected to be routinely available with CSRP daily stand-ups by conference call. Online communication is inevitable given the geographic spread of NDA sites Security Clearance SC minimum (or equivalent) and personnel may need to go through NDA clearance checks Additional T&Cs Current forward demand for Security Architecture resource is in some cases indicative, any potential supplier is expected to provide flexibility within the contract to allow for periods of high and low demand No. of Suppliers to Evaluate 5 Proposal Criteria • Essential Skills and experience • Ability to meet project start and ongoing timeframes • Value for Money • How the proposal and approach meets NDA objectives and needs Cultural Fit Criteria • Work as a team with our organisation and other suppliers • Be transparent and collaborative when making decisions • Willingness to share wider knowledge and experience Payment Approach Capped time and materials Assessment Method • Reference • Presentation Evaluation Weighting Technical competence 60% Cultural fit 20% Price 20% Questions from Suppliers 1. Can the Authority please confirm the expected team size that the winning tenderer will need to provide? Role Group Magnox NDA CC SL DSRL NTS LLWR RWM Senior Sec Arch 4 44 2 44 10 4 4 4 total 116 days average per month Minimum Number of Resources0.2 2 0.2 2 1 0.2 0.2 0.2 Total is 6 people 2. Is there an incumbent on this service? No there isnt an incumbent 3. Can the Authority please confirm the architecture disciplines required? i.e. Security, Network etc? Predominantly Security Architecture with possibly a small amount of some other disciplines depending on the activity or project, but mainly focus on security. 4. Can the Authority please confirm whether the opportunity is assessed as inside or outside of IR35? IR 35 not applicable 5. Can the Authority please confirm whether the stated budget includes VAT? Ex VAT 6. Can the Authority please confirm the expenses policy, and whether the stated budget includes a provision for expenses? Budget includes travel and expenses. Limited travel required but would work to NDA employee travel policy. Can share policy once get to next stage of procurement 7. Can the Authority please confirm how much travel is expected to the locations listed in the advert? No expected travel for the first 6 – 9 months, a review will be taken after this time by the project manager to determine if onsite work will be required moving forward. 8. Can the Authority please confirm the size of the existing team? This depends on which operating company the work will be done for, some operating companies have 4 security architects while others have none. 9. Can the Authority please confirm the expected team size that the winning tenderer will need to provide? Based on indicative demand over the next 6 months the tender could be resourced by between 6 – 10 resources. The range in resources is due to internal scheduling, with some activities/projects running concurrently and others running consecutively. The table in my other response tries to show that but apologise for the formatting 10. Do you have more information on what needs to be delivered? The supplied consultants will need to provide advice and guidance (including the creation of documentation and designs) to operating companies over a range of projects to ensure that new systems or changes to existing ones are secure and in line with company policy and best practice guidance. Some example projects are: Deployment of Azure Virtual Desktop, Implementation of Privileged Access Workstations (PAW) and WAN replacement. 11. Will the resource be expected to be on-site fulltime in 6-9 months? No, a review will be undertaken on what activity can be delivered while working remotely, the preference is for all work to be delivered remotely if at all possible. 12. In order to have 6 people ready, is it acceptable to rotate them out at a later date, once we have backfilled their position with long term resource? Yes, we would like to keep a core team of people moving around the estate but we do accept that this isn’t always possible. 13. And just for clarity, is there any TUPE involved? No TUPE involved. 14. Could we please know how many consultants would be required to start in November A minimum of 4 consultants would be required for start in November 15. Could we please know which cloud providers are are being used within NDA and their operating companies. Predominantly Azure with some AWS. 16. Will the Authority accept a consortium approach? Nov this is not our preferred approach 17. Will the Authority accept a consortium approach? No this is not our preferred approach 18. Would it be possible for the authority to grant a one week extension, taking the application deadline to the 14th September? The dates are set by the portal and all suppliers are working to the same end date so I am afraid I am unable to extend the deadline 19. Please can the Authority explain the acronym ONR used here “Experience in NDA/ONR environment”. Thank you Nuclear Decommissioning Authority / Office for Nuclear Regulation 20. Do you have a more detailed job description of required skills sets? Please see the link to the GOV.UK site in relation to security architecture skill sets. Security architect - GOV.UK (www.gov.uk) 21. Could we please know the underlying application stack technologies used within the operating companies There is a varied mixture of IT & OT across the NDA estate. Technologies which will require Security Architecture input include: Network Infrastructure (SD WAN,Firewalls, Routers, Switches), Compute Infrastructure, IaaS, SaaS, on-prem applications and business systems. Vendors include: Microsoft, Amazon, HP Aruba, Paolo Alto, McAfee, Blackberry, Juniper, Cisco, VMWare, Dell. 22. Could we please know if NDA already has a cloud deployment and integration models defined. Could we know if the controls controls framework for the defined models has been established? This will depend on the operating company, assume Cloud Deployment and Integration models are yet to be defined.
Timeline
- Completed: Tender published24 August 2021Current notice
- Completed: Submission date7 September 2021
About the buyer
Nuclear Decommissioning Authority (NDA) is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.
Decision makers
Connect with the people behind this procurement.
| Contact name | Job title | Phone number | Work email |
|---|---|---|---|
| Head of Procurement | +44 •••• •••••• | ••••••••@nuclear-decommissioning-authority-nda.gov | |
| Commercial Director | +44 •••• •••••• | ••••••••@nuclear-decommissioning-authority-nda.gov | |
| Procurement Manager | +44 •••• •••••• | ••••••••@nuclear-decommissioning-authority-nda.gov | |
| Category Lead | +44 •••• •••••• | ••••••••@nuclear-decommissioning-authority-nda.gov | |
| Senior Buyer | +44 •••• •••••• | ••••••••@nuclear-decommissioning-authority-nda.gov | |
| Contracts Manager | +44 •••• •••••• | ••••••••@nuclear-decommissioning-authority-nda.gov |
Related topics
Topics related to NDA Group Security Architecture Resource, ranked by notice volume.
- 1,484£14.9bn
- 5,183£735.8bn
- 2,074£309.9bn
- 2,507£313.9bn
- 4,112£205.5bn
- 4,088£269.5bn
- 4,068£249.4bn
Related buyers
Buyers similar to Nuclear Decommissioning Authority (NDA).
- 1,713£205.5bn
- 461£2.1bn
- 372£250.0m
- 362£15.0bn
- 294£2.8bn
- 267£19.9bn
- 250£511.2m
- 203£1.0bn
- 122£59.9m
- 101£945.6m
Win more public sector contracts
Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.
