Closed tender

Identity Access Management Service (IAMS) Development Team 1

Details

Value
GBP 9,700,000
Published
2 December 2022
Submission
16 December 2022

Tender description

Summary of the work Support MOD to build and configure the technology changes needed to establish the Official and internet facing capabilities for the IAMS. These capabilities will be delivered via a number of work packages, defined in the IAMS backlog. Produce design and policy documentation, support Close Client Side Support team with assurance. Expected Contract Length 18 months Latest start date Monday 27 February 2023 Budget Range Up to 9.7M to deliver IOC inclusive of T&S. Why the Work is Being Done The MOD’s Identity and Access Management Service (IAMS) Programme is now moving into the Delivery Phase, to establish an Initial Operating Capability (IOC) by February 2024 (building on existing identity and AAD services) with a start date of Jan 23. This will provide new Identity and Access Management services for the Official domain . MOD Defence Digital currently has insufficient suitably qualified and experienced staff to provide in-house technical delivery teams to configure the technical platform nor the capacity / experience to manage the change programme. Development Teams made up from contractor resources are therefore required to design, build, configure produce policy, and manage the core, internet connected, Identity and Access Management Service at Official / Official Sensitive. This will serve the majority of the current 250,000 users and act as a pattern for delivery of similar capabilities at Full Operating Capability in the deployed arena and at higher classifications. Problem to Be Solved The MoD had several disparate and ageing identity services, the Identity Access Management (IdAM) and Directories programme created a centralised identity service taken significant steps to improve and refine the identity data. The IAMS programme goal is to build upon this and modernise and establish a centrally managed and assured single identity for use across the wider MoD estate. The IAMS solution will support the modernisation the identity and authentication services, Multi-Factor Authentication (MFA), Single Sign On (SSO), application and resources access and control mechanisms and enable the progression to a Zero Trust Architecture within the MoD estate. The technical delivery team (Development Team) will design, build, configure, and manage the MOD.GOV.UK Azure Active Directory (AAD) instance in conjunction with the other stakeholders identified to deliver the core Official IdAM Service. The delivery team will also be responsible for further supporting the development of policy and standards and reviewing this as part of a lifecycle process. Who Are the Users Groups require secure controlled access (not limited to): 1. Military Services Personnel – to MOD services and resources for operational, planning and communications. Required MOD administration and training. Access to comms, data capture, geo data, decision support, land environment consumer apps and more. 2. MOD Civil Servants – to support MOD programs and projects. Access collaboration, comms, productivity, finance and more. 3. Reserves and Cadets - required learning and relevant information. Access eLearning, planning and corporate apps. 4. Civilians Contractors and Consultants - require controlled access to support MOD programs, projects and collaboration. Access Productivity Comms, Collaboration and other defined applications. 5. Non-Person entities – service accounts and APIs. Support IOT and technology, exchange data/enable automation. Access defined IOT and technology. 6. Other Government Department Personnel - collaboration and support MoD services/operations. Access Comms, Collaboration, Productivity and professional community. 7. Veterans – resettlement and support, other relevant services. Access veteran services. 8. Allied Military and Civilian Personnel – collaboration allied activities and information sharing. Access Collaboration, Comms and professional community. Locally engaged civilians' provision of local services. Access Corporate. 9. Families of MOD Personnel – resettlement, advice and support, benefits, and community. Access veteran services, pay, vouchers and benefits apps. Work Already Done The IAMS architecture has been agreed, including existing identity lifecycle management and MOD.GOV.UK AAD. Design and governance stakeholders have been identified and documentation produced to provide direction for the delivery teams. High-level Designs have been prepared, requirements gathered, and user functions established for the Identity Service. Governance bodies are in-place supporting all activities to achieve final approval to operate. The AAD and mature identity store is in place. However, there is currently no enterprise level service management to maintain and innovate this technology. The Operational Service Management capability acts as a front door for other defence capabilities and onboarding services. Existing Team The service owner for AAD manages the whole of the M365 domain, other technology suppliers configure and manage neighbouring technologies. There is no current incumbent with responsibility for an identity and access management service in AAD. The development teams will work to the IAMS Close Client Side Support Partner on behalf of the Senior Responsible Owner. They will also need to work closely with existing delivery teams and service owners within MOD. Finally, the contractor will need to work closely with Technical and Service Design authority and teams managing existing services to be transitioned. Current Phase Discovery Skills & Experience • Demonstrate capability to create High-level, Low-level Design documentation and technical configuration/assurance documents such as Implementation Guide and produce scripts to support the implementation, for complex environments - 15 points • Demonstrate Business Analysis (BA) capability that has been applied to develop business, user and technical policies in conjunction with other teams - 5 points • Experience of Azure Active Directory (AAD) implementation and maintenance in complex hybrid cloud environment - 12 points • Experience of implementation and maintenance of AAD services such as: 1. MFA; 2. SSO; 3. Conditional Access; 4. Role Base and Policy Based access management - 10 points • Experience of Identity and Access Management capabilities for implementation and maintenance of such services in complex and secure environments - 10 points • Experience of Integration of Identity and Access Management services and AAD with protective monitoring tools, including those external to Azure - 7 points • Experience of Integration of AAD to externally hosted modern and legacy applications - 8 points • Testing & Accreditation – Experience of developing scope of testing and accreditation, management testing and accreditation, proving the service you delivered meets functional and security requirements - 6 points • Experience of rapidly employing appropriate mitigation/fix process for requirement and functional, gaps and/or threats and vulnerabilities from testing phases - 7 points • Experience of Development Lifecycle capabilities aligned with first delivering and then managing complex hybrid cloud architectures - 6 points • Demonstrable experience of configuring and implementing approved designs to meet operational and security requirements - 6 points • Experience of managing the configuration and maintenance of an enterprise scale instance of AAD including evidence of identity lifecycle management - 8 points Nice to Haves • MoD or other secure customer delivery and/or service management capabilities - 8 points • Understanding and delivery capability for Zero Trust Architecture - 3 points • Understanding and experience of implementation aligned with NCSC guidance and principles - 7 points • Experience in Policy Enforcement Point and application gateway services implementation - 5 points • Experience working in complex dynamic programmes - 7 points Work Location Remotely & at MoD sites, primarily MoD Corsham, Westwells Road | Corsham | Wiltshire | SN13 9NR Working Arrangments Development teams will be expected to attend meetings within standard office hours. The vast majority of which will be held virtually. A hybrid arrangement will be in place with onsite and remote working. As the central Identity and Access Management Service is developed and transitioned into live production, there will be a requirement to provide 24/7 service management. This is subject to the development and agreement of appropriate Service Level Agreements (SLA). Security Clearance The Supplier shall provide all staff with a minimum of Security Check clearance for anyone actively engaged in the delivery of services within the contract from the contract start date. The Authority will not hold or sponsor clearances. Additional T&Cs DEFCONS 5J, 76, 129J, 522, 602B, 609, 627, 642, 658, 660 In accordance with DEFCON 658 a Cyber risk assessment has been undertaken Cyber risk profile: Moderate All expenses must be pre-agreed between the parties and must comply with the authority Travel and Subsistence (T&S) Policy. Options to call-off sub-services Conflict of Interest No. of Suppliers to Evaluate 5 Proposal Criteria • Describe how you would deliver the technical solution as described in the SOR - 17 points • Outline your approach and methodology to delivery and service management - 12 points • Demonstrate how the approach or solution meets user needs, and how is this evidenced (UAT, delivery review, other) - 8 points • Provide estimated timeframes for the work, including provision of a plan of work to deliver services outlined in SOR - 16 points • Explain how you will identify risks and dependencies and approaches to manage/mitigate them - 12 points • Provide your team structure and staffing approach including how options will be staffed - 5 points • Demonstrate how your proposal ensures value for money - 6 points • A model of how you will manage quality and governance both in delivery and lifecycle management - 10 points • Detail your proposed approach for knowledge transfer to technical and business teams throughout the life of the contract - 14 points Cultural Fit Criteria • Work collaboratively as a team with our organisation and other suppliers, adapting quickly to changing environments, enabling completion of tasks in an agile manner – 1 point • Take responsibility for their work – 1 point • Share knowledge and experience with other team members, the Authority and customers – 1 point • Challenge the status quo – 1 point • Can work with stakeholders with a range of technical expertise – 1 point • Social Value – Tackling economic inequality MAC3.5 Demonstrate action to identify and manage cyber security risks in the delivery of the contract including the supply chain – 5 points • Social Value – Fighting climate change MAC4.2. Influence staff, suppliers, customers and communities through the delivery of the contract to support environmental protection and improvement – 2.5 points • Social Value – Equal opportunity MAC6.1. Demonstrate action to identify and tackle inequality in employment, skills and pay in the contract workforce – 2.5 points Payment Approach Fixed price Assessment Method • Case study • Work history Evaluation Weighting Technical competence 65% Cultural fit 15% Price 20% Questions from Suppliers 1. Could we request a copy of the SOR please? A copy of the SOR will not be made available until the first stage of the competition is completed. Only suppliers who are successful at stage 1 will have access to the SOR. 2. The requirement title “IAMS Development Teams 1” implies that there will be competitions for subsequent teams. Can the Authority clarify whether it is the case that there will be competitions for future teams and, if so, whether the scope be comparable? Yes - It is anticipated that there will be further competitions to bring in teams to activate various sub-services. These are also included as options within this requirement to ensure that the Authority does not run the risk of delaying the IAMS IOC date. For instance, if the MFA design work is complete and appropriate skilled resources are in place, then Team 1 could begin implementation. 3. Can the Authority clarify what outcome(s) you are looking to achieve? Enablement of AAD subservices (e.g. designing and potentially implementing MFA, Single sign-on, Role Based Access Control) and management through run and support to achieve the strategic goal of more centralised identity management and one identity for MOD users. 4. Can you confirm if onboarding of users – notably through document and identity verification – is in scope of this work package? "Onboarding - Yes the selected supplier will be involved at the end of an already designed and automated process to onboard users. The supplier will also be involved in the user testing ahead of service enablement (proof of concept)Identity verification - No, we already have a function delivering this which sits within the designed process mentioned above. 5. 1. Are Security Services in scope2. Could you provide an indication (without commitment) of the size of team required on day 1 and potential ramp up?3. Will the supplier be responsible for processing any personally identifiable data?4. Safety critical services in scope? If so could you indicate the types of services?5. Will TUPE apply? 1. The solution will work with MODs accreditation and security wrapper e.g. MODs Secure Operations Centre capability2. With the provision of the budget (which includes options) bidders are expected to determine a suitable team size once they have access to the SOR.3. At this stage, this is not clear but will be made clearer once tender is issued at stage 2 of procurement.4. Not entirely clear what is meant by safety critical services. All services at Official will be impacted by the complete roll-out of IAMS into production.5. TUPE is not considered applicable to this procurement. 6. 6. Will any of this be governed by ITAR regulations7. Will any aspects of the delivery be Above Secret?8. Will any aspects of this delivery deal with Airworthiness9. What is the anticipated timing of Stage 2 of the procurement 6. It is not considered that there is any ITAR related equipment or information.7. For this stage of the programme there are no aspects of delivery above Secret.8. The requirement does not cover airworthiness.9. Given the Christmas period, the evaluation of stage 1 is unlikely to be completed until the 2nd week of January. Therefore, we anticipate inviting the specified number of suppliers to stage 2 mid-late January. The anticipation is that suppliers will have 2 weeks to return tender documentation and the Authority a further 2 weeks for evaluation. 7. How many forests and domains in the AD estate? 1 forest and domain 8. Do you have any current AAD deployments? Yes, there is a live tenant that the supplier will be working with. 9. Are certificate services included in the scope? Integration with certificate services is in scope. 10. Are any 3rd party tools being used to provide PIM in an AD environment? Yes 11. Does the stated user count accurately reflect all user groups stated, e.g. veterans and families? For the IOC delivery, the user count is accurate but does not include all of the user groups stated in the advert e.g. Veterans and families. 12. Is the supplier delivery team also responsible for requirements, programme management and business change? The Development Team will do elements of requirements and business change, details of which will be included in the SOR. 13. Are there any requirements or expectations regarding the development and deployment platforms for the IAM service? Given the stated requirements, NET is heavily implied No development expected. The IAMS service will be operated on a commercial off the shelf product (AAD) with a high level design of supporting capabilities which will be managed and configured in a manner recommended by the Development Team.

Timeline

  1. Completed: Tender published2 December 2022
    Current notice
  2. Completed: Submission date16 December 2022

About the buyer

Ministry of Defence is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.

AI insights

  • Is there a preferred supplier?
  • What are the buyers pain points?
  • What has the buyer previously procured?
  • What are the key requirements?
Sign-up to enrich

Decision makers

Connect with the people behind this procurement.

Contact nameJob titlePhone numberWork email
Head of Procurement+44 •••• ••••••
Commercial Director+44 •••• ••••••
Procurement Manager+44 •••• ••••••
Category Lead+44 •••• ••••••
Senior Buyer+44 •••• ••••••
Contracts Manager+44 •••• ••••••

Related topics

Topics related to Identity Access Management Service (IAMS) Development Team 1, ranked by notice volume.

View all topics

Win more public sector contracts

Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.