Cyber Risk Programme (CRP) Client Side Support - Enterprise Patching
Details
- Buyer
- Ministry of Defence
- Value
- GBP 3,084,000
- Published
- 13 April 2022
- Submission
- 27 April 2022
- Source
- uk:digital_marketplace
Tender description
Summary of the work The successful supplier will deliver enterprise level changes to support the transformation of the Authorities ICT patching processes. They will Co-ordinate multiple workstreams to meet Enterprise patching strategy and objectives. the supplier will deliver against the defined outcomes to support the Programme Expected Contract Length 15 months Latest start date Monday 20 June 2022 Budget Range Not to exceed £3.084m Ex VAT Why the Work is Being Done The Enterprise Patching Project looks to fill the capability gap by providing a secure Patch Acquisition and Distribution Service (PADS) that meets the evolving needs of the MOD Enterprise. Ensuring it is designed, to assist and support the system owners to implement required patches in a timely fashion. Furthermore, the project will update existing and introduce new processes, investigate technical solutions, and update policies that provide the governance for remediation and reporting of patch management across the enterprise. Note: This advert is a rerun of the previously unfilled advert ref: 16550 Problem to Be Solved The successful supplier will support the CRP Programme in achieving the following: Objective 1. Investigate, understand, and remediate where possible, technical and process issues that delay timely software patches in accordance with Defence policy requirements. Objective 2. Drive and increase the patch compliance rate by examining patch failures and providing recommendations to remediate. Objective 3. Deliver technical capability that provides secure patch acquisition and distribution services to meet the evolving needs of the MOD Enterprise. Who Are the Users The CRP programme within Strategic Command are the users. Specialist support is required to sustain the current project delivery and expected increased outputs which lay predominantly at the implementation of the Enterprise Patching Strategy, providing a stable base from which Modernising Patching Project via Alpha & Beta development partners can plan and implement its scope of work Work Already Done Over FY20/21 the Project received initial approval to commence. The client-side support provided has since developed the definition of the project, ran a supplier tender process, designed a high-level architecture for PADS, created target infrastructure for a patching tool in MOD Cloud ICE S01 and is currently completing the final sprints within an Alpha Development phase, the outcomes of which are forming the Statement of Requirement for the Beta phase. Existing Team The existing team consists of project managers, technical service architects, client-side technical Dev & DevOps resources, Cloud Architects, product owners, security specialists and a Security Assurance Controller. Existing governance structures are mature within CRP with the Programme Manager acting as primary delivery sponsor. Current Phase Alpha Skills & Experience • Extensive understanding of MOD / Major industry defensive cyber capabilities at strategic and operational levels and the interactions between them to enable a proactive cyber posture. (5%) • Experience of delivering complex projects / programmes in-line with GDS service design principles (5%) • Demonstrable experience of providing client-side support within transformation programmes. (5%) • Proven track record of working with distributed stakeholders to implement transformation across organisational structures, operational governance and information flows for large-scale complex projects. (5%) • Proven experience of running a workstream of activity, related to delivering an enterprise-level Cyber Security Operations Capability. (2.5%) • Experience of managing service integration utilising the ITIL 4 model (2.5%) Nice to Haves • Experience of working within Defence organisations on agile project delivery. (5%) • Have ability to think creatively and can articulate innovative ideas to solving complex business and ICT problem (5%) • Understanding of MOD Investment Approvals (JSP 655) and the creation of business cases from refined requirements. (5%) Work Location The work can generally be carried out by remote working but will entail travel to the main site at MoD Corsham. Working Arrangments The majority of the work will be carried out by remote working and will entail travel as required to deliver the project at: a. Main site - MoD Corsham, Westwells Road, Corsham, Wiltshire, SN13 9NR b. Additional Locations - MOD Abbey wood, Bristol, MOD Main Building, London Where resources require access to a SECRET workstation, work will be carried out on site, at the following location: a. MoD Corsham, Westwells Road, Corsham, Wiltshire, SN13 9NR. Security Clearance To proceed to Stage 2, suppliers must clearly demonstrate ability to receive OFFICIAL SENSITIVE materials. Proposed supplier staff must already hold SC, or be sponsored by the supplier to achieve SC. The supplier must have capability to offer staff that are DV cleared for short periods Additional T&Cs Bid Responses to be submitted on the templates provided and in Microsoft Office Word format only. Suppliers must use the Authorities Purchase to Payment Tool called CP&F or be prepared to sign up to the tool No. of Suppliers to Evaluate 7 Proposal Criteria • Documented proposed approach against Statement of Requirement (SoR) , including delivery methodology, breakdown of tasks, transfer of knowledge approach, how the supplier will integrate and work collaboratively (20%) • Case study of previous experience of embedded client-side support (10%) • Onboarding and Implementation Plan, (10%) • Team structure, Including proposed FTE / Month to support delivery demand peaks and ramp down to (10%) • Evidence/confirmation that the proposed team have or can be sponsored by the supplier to achieve the relevant Security Clearances (5%) • Risk mitigation approach (5%) Cultural Fit Criteria • Demonstrate action to identify and manage cyber security risks in the delivery of the contract including in the supply chain.(2.5%) • Support in-work progression to help people, including those from disadvantaged or minority groups, to move into higher paid work by developing new skills relevant to the contract.(2.5%) • Working as a team with our organisation and its stakeholders sharing knowledge in a no blame culture to enable learning From Experience.(2.5%) • Working collborativley and take responsibility for the tasks in hand and adapt quickly, in an ever changing environment to enable completion of tasks in an agile manner.(2.5%) Payment Approach Fixed price Evaluation Weighting Technical competence 60% Cultural fit 10% Price 30% Questions from Suppliers 1. There are a number of roles listed under ‘Existing Team’. Can the Authority please confirm whether these are roles that the winning tenderer is expected to provide, or whether these roles form part of the existing team already within the programme (i.e. who the winning supplier would be working with once engaged) The roles describe the existing project team role skillset, of which the supplier will need to provision if successful. Further details of the role requirements are to be released within Stage 2. The winning supplier will be accountable for the successful delivery of the Enterprise Patching Project, direct to the Authority programme team. 2. Can the Authority please confirm – Is there an incumbent supplier? The Authority can confirm that there is an incumbent supplier.
Timeline
- Completed: Tender published13 April 2022Current notice
- Completed: Submission date27 April 2022
About the buyer
Ministry of Defence is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.
Decision makers
Connect with the people behind this procurement.
| Contact name | Job title | Phone number | Work email |
|---|---|---|---|
| Head of Procurement | +44 •••• •••••• | ••••••••@ministry-of-defence.gov | |
| Commercial Director | +44 •••• •••••• | ••••••••@ministry-of-defence.gov | |
| Procurement Manager | +44 •••• •••••• | ••••••••@ministry-of-defence.gov | |
| Category Lead | +44 •••• •••••• | ••••••••@ministry-of-defence.gov | |
| Senior Buyer | +44 •••• •••••• | ••••••••@ministry-of-defence.gov | |
| Contracts Manager | +44 •••• •••••• | ••••••••@ministry-of-defence.gov |
Related topics
Topics related to Cyber Risk Programme (CRP) Client Side Support - Enterprise Patching, ranked by notice volume.
- 1,485£14.9bn
- 6,447£32.8bn
- 5,186£736.1bn
- 1,997£39.8bn
- 1,745£636.1bn
- 11,175£1.0tn
- 1,497£10.1bn
- 26,970£1.7tn
- 3,863£605.8bn
Related buyers
Buyers similar to Ministry of Defence.
- 731£1.3bn
- 675£133.0bn
- 637£160.0bn
- 446£8.1bn
- 334£7.4bn
- 324£1.3bn
- 272£1.1bn
- 252£892.4m
- 224£483.9m
- 178£221.9bn
Win more public sector contracts
Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.
