HSENI - Online Forms Security Health Check
Details
- Value
- GBP 2,500
- Published
- 22 November 2022
- Submission
- 3 February 2012
- Source
- uk:bravosolution
Tender description
The objective of this document is to invite CESG approved companies, who have CHECK Scheme approved consultants (i.e. classified as Green) with web application security experience, to tender for the provision of web application security testing services. 2. BACKGROUND The Health and Safety Executive for Northern Ireland (hereafter abbreviated to HSENI) are currently reviewing the information assurance security applied to all public facing online forms. All public facing online forms are to be subject to an application level security health check (or penetration test). The Executive’s online forms are a key channel for communicating with its stakeholders and the general public and it has also increasingly become a key means of providing transactional and interactive services to the public. The desired outcome of this exercise is to provide assurance that the Executive’s online forms are protected from penetration and compromise from intruders. The Departmental Security Officer for the Department of Enterprise, Trade & Investment (DETI) wishes to have any security vulnerabilities within online forms identified, quantified in terms of risk/impact and advice provided on remedial action. It is envisaged that securing vulnerabilities and reducing risks will lead to a reduction in the likelihood of: • Phishing attacks that can exploit vulnerabilities, particularly cross-site scripting, and weak or non-existent authentication or authorisation checks; • Privacy violations from poor validation, business rule and weak authorisation checks; • Identity theft through poor or non-existent cryptographic controls, remote file include and authentication, business rule, and authorisation checks; • Systems compromise, data alteration, or data destruction attacks via Injections and remote file include; • Financial loss through unauthorised transactions and Cross Site Request Forgery attacks; • Reputation loss through exploitation of any of the above vuln
Timeline
- Completed: Submission date3 February 2012
- Completed: Tender published22 November 2022Current notice
About the buyer
Department of Finance is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.
Decision makers
Connect with the people behind this procurement.
| Contact name | Job title | Phone number | Work email |
|---|---|---|---|
| Head of Procurement | +44 •••• •••••• | ••••••••@department-of-finance.gov | |
| Commercial Director | +44 •••• •••••• | ••••••••@department-of-finance.gov | |
| Procurement Manager | +44 •••• •••••• | ••••••••@department-of-finance.gov | |
| Category Lead | +44 •••• •••••• | ••••••••@department-of-finance.gov | |
| Senior Buyer | +44 •••• •••••• | ••••••••@department-of-finance.gov | |
| Contracts Manager | +44 •••• •••••• | ••••••••@department-of-finance.gov |
Related topics
Topics related to HSENI - Online Forms Security Health Check, ranked by notice volume.
- 1,745£636.1bn
- 4,607£326.7bn
Related buyers
Buyers similar to Department of Finance.
- 59£121.9m
- 43£1.7bn
- 11£46.1m
- 6£88.1m
- 6£7.5m
- 4£10.6m
- 3£1.5m
- 1£454.0k
- 635£2.6bn
- 386£3.6bn
Win more public sector contracts
Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.
