Closed tender

RM1043.7 - Digital Forensic Examination

Details

Published
9 November 2022
Submission
23 November 2022

Tender description

Summary of the work The ICO requires a forensic capability in order to facilitate the criminal and civil investigations into offences and regulatory breaches. The product received from the Digital Forensic Providers will meet evidential standards for use in criminal and civil proceedings, and to support any ICO regulatory action. Expected Contract Length 2 Years + 25% Latest start date Monday 30 January 2023 Why the Work is Being Done The ICO is looking to appoint two forensic provider's to assist in the investigation of criminal and civil breaches. The current contract is due to expire in January 2023 and this would replace that contract. This would be a 2 year contract with the option to extend for a further 25%. Problem to Be Solved Current contract is due to expire. Who Are the Users Part of the ICO Investigations Directorate is the Department who deal with a variety of Freedom of Information and Data Protection cases with the overriding aim to take purposeful risk-based regulatory action where obligations are ignored, examples need to be set or issues need to be clarified, based on the ICO’s Regulatory Action Policy. Within the Department are the Criminal Investigations, Civil Investigations and Privacy and Digital Marketing Investigations Team responsible for investigating criminal and civil breaches of the Data Protection Act, the Freedom of Information Act, Privacy and Electronic Communication Regulations (PECR) and Environmental Information Regulations (EIR). These pieces of legislation all rely on schedule 15 of the Data Protection Act 2018 as a gateway to the powers to apply for a search warrant and to secure electronic evidence. Existing Team Part of the ICO Investigations Directorate is the Department who deal with a variety of Freedom of Information and Data Protection cases with the overriding aim to take purposeful risk-based regulatory action where obligations are ignored, examples need to be set or issues need to be clarified, based on the ICO’s Regulatory Action Policy. There is the potential that you may need to engage with another supplier. Current Phase Not applicable Skills & Experience • have extensive experience of Digital Forensic Examination • have the appropriate levels of Security Clearance • be able to mobilise by 30th January 2023 • have relevant ISO accreditations • have experience of working to agreed timescales of the Criminal Justice system Nice to Haves • include a Single Point of Contact • deliver evidence, reports and information via a secure client / web portal Work Location At your own premises, with collections from the Wilmslow Office (SK9) and meetings in person (where necessary) and via Teams Working Arrangments Collaborative working with the ICO Teams Face to Face and via Teams, to be arranged and co-ordinated in agreement between the parties. Additional T&Cs Crown Commercial Services Standard Contract No. of Suppliers to Evaluate 3 Proposal Criteria • approach and methodology • technical solution • how they’ve identified risks and dependencies and offered approaches to manage them • have sufficient resource capability or would require a recruitment drive for workload and what that would look like Cultural Fit Criteria • work as a team with our organisation and other suppliers • resilience, a general ability to handle stress and continue to work effectively • Respect, equality, diversity and inclusivity - embrace inclusive ways of working. Demonstrate respect each other and our stakeholders, customers and colleagues and treat all with dignity. • be transparent and collaborative when making decisions • Collaborative – Working towards achieving our goals, seeking and sharing information and expertise and working effectively with a range of partners to achieve objectives. Payment Approach Time and materials Evaluation Weighting Technical competence 50% Cultural fit 20% Price 30% Questions from Suppliers 1. What are the appropriate levels of security clearance? https://www.gov.uk/government/publications/united-kingdom-security-vetting-clearance-levels/national-security-vetting-clearance-levels 2. Just for clarity, is this seeking people to perform the actual investigations or provision of a system/tool to support a team in these investigations? The ICO is looking for both of those services and may need one or both depending on the nature of the investigation. 3. What are the appropriate levels of security clearance? All suppliers must be vetted to SC level. 4. Good morning,We are a newly established digital forensics lab but with very experienced digital forensics technicians who have experience working to ISO 17025 guidelines.All of our processes and procedures in our lab follow ISO 17025 guidelines. We have also applied and are currently working through the accreditation process to obtain ISO 17025. We have all other relevant ISO’s required to process information securely.Are we able to apply for this opportunity? Our requirement is to have companies ISO accredited and in the interests of fairness and impartiality we advise that they should not apply on this occasion. 5. What levels of Security Clearance are appropriate to this work i.e. NPPV Levels 1-3, SC or DV. Minimum level of Security Clearance required is SC 6. If a specific ISO accreditation is not held, but the supplier is in the process of obtaining that accreditation, will this be considered acceptable? ISO Accreditation would need to be in place by Contract Award, if working towards. Otherwise this would not be acceptable. 7. Which specific ISO accreditations are deemed relevant? ISO9001, ISO27001, ISO17025 8. Will suppliers be required to present evidence of the examinations at court? Yes 9. Is there any requirement for ancillary services to support investigations at scale, such as document review platforms which can greatly assist by expediting searches across multiple data sources from related cases? The requirement for this is unlikely as most of our investigations are stand-alone. There may however be occasions where nominals may be duplicated over separate investigations, this therefore would be advantagous but not mandatory. 10. Is there an existing Case Management System which the supplier will be required to adopt and use? The Criminal Investigation Team use Crimson as a case management system, there is no requirement for our supplier to use this. Knowledge of it would be advantageous. 11. Are there any existing technologies or specific tooling requirements that the supplier will be required to use or embed in its processes? Nothing specific from the ICO however we expect any supplier to have access to latest technology. 12. In order for us to scale the necessary resources to comply with any SLA, what volume of work is anticipated i.e. number of devices per week? This is difficult to quantify as not all our investigations require examination of electronic devices, if it assists, we sent 11 devices off last month after executing search warrants, prior to that our last submission was some months ago with a similar number of devices. 13. • What ISO accreditations do you require?• Your “Nice-to-have skills and experience” includes “deliver evidence, reports and information”. Does reports in this context refer to expert witness reports or witness of fact reports? And do you expect to need suppliers’ teams to give evidence in court? ISO9001, ISO27001, ISO17025 . We require our forensic supplier to provide witness reports and statements and attend court to give evidence as necessary. 14. • In answer to question 2 you stated that investigations may be required as part of this framework. Does “perform the investigation” in this context mean only the IT Forensics investigation relating to hardware/devices/data and policies and procedures? Or does it extend to support though the broader ICO investigation lifecycle – i.e. from receipt of allegation/notice, through evidence collection, investigation process including review of documentary evidence, formal interviews and the like? We require our forensic provider to examine hardware and devices as part of the ICO investigation, we do not require further support. 15. • Does “Digital Forensic Examination” in the context of this Framework mean only the forensic capture and interrogation of IT hardware/data or does it also include a review of IT/data policies and procedures, and consideration of whether those IT/data policies and procedures were followed? Do you expect that any other disciplines of Digital Forensic Examination will be required in addition to these? Yes, this means the forensic interrogation of IT hardware and not examination of policies.

Timeline

  1. Completed: Tender published9 November 2022
    Current notice
  2. Completed: Submission date23 November 2022

About the buyer

Information Commissioner's Office is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.

AI insights

  • Is there a preferred supplier?
  • What are the buyers pain points?
  • What has the buyer previously procured?
  • What are the key requirements?
Sign-up to enrich

Decision makers

Connect with the people behind this procurement.

Contact nameJob titlePhone numberWork email
Head of Procurement+44 •••• ••••••
Commercial Director+44 •••• ••••••
Procurement Manager+44 •••• ••••••
Category Lead+44 •••• ••••••
Senior Buyer+44 •••• ••••••
Contracts Manager+44 •••• ••••••

Related topics

Topics related to RM1043.7 - Digital Forensic Examination, ranked by notice volume.

View all topics
TopicCountValue
  1. 5,040
    £145.9bn

Related buyers

Buyers similar to Information Commissioner's Office.

View all buyers

Win more public sector contracts

Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.