Closed tender

Government Security Extranet - Alpha

Details

Value
GBP 120,000
Published
2 February 2022
Submission
16 February 2022

Tender description

Summary of the work The Government Security Function is looking for a supplier to design and build a secure alpha extranet to be used by authorised individuals to access ‘OFFICIAL-SENSITIVE’ information. The site should also have a 'public facing' section for users who have not registered for an account. Expected Contract Length up to 24 months (Alpha to be completed within 6 months) Latest start date Friday 11 March 2022 Budget Range Up to £120,000 Why the Work is Being Done The Government Security Function is made up of civil servants from across all Government departments and ALBs. Our users are based in different departments and primarily use the IT provided by their home department. We currently do not have a suitable place to publish guidance and information for our community of security professionals to access. In addition to this we are unable to provide guidance and information suitable for industry professionals or public sector organisations. We are looking for a solution that will replace www.security.gov.uk with a solution that provides content to external audiences (such as public sector organisations looking for guidance issued by the security function) and a secured section/site for authorised users who can access information once they have successfully logged into the platform. Problem to Be Solved Following an in-house discovery we have found that our community of security professionals would like to access news, guidance and documents from a central source. At the moment, security guidance is shared internally through emails with a risk of not reaching the entire intended audience across our security community, Government departments and key public sector partners. Our users want to have access to up to date information when they need it and have the confidence the information hosted on the solution is appropriately secured and available to those who have the correct permissions to view the resources. The solution needs to be intuitive and familiar. The site must also allow for some content to be made 'public' without impacting the integrity of the site. Who Are the Users As an authorised user I need to securely log into the platform and access a range of material such as guidance, news, upcoming events and download files so that I have the most up to date information for my role. As an authorised user I need to have the ability to opt-in to have my contact details listed in a directory for other authorised users to search for me by name or job title. As an authorised publisher I have the ability to publish content and set appropriate permissions so that authorised users can access the information. As an administrator I have the ability to run reports and view logs so that I can see how often a specific page or resource is accessed and by who so that I can ensure a clear audit log is kept. As a public sector user with no credentials I can view guidance so that I can apply the best practices to my public sector organisation. Work Already Done Discovery phase has been completed internally and the discovery report will be shared with the successful supplier. Existing Team A non-technical team is in place to support the project and facilitate conversations with relevant departments. Current Phase Alpha Skills & Experience • Experience of building secure solutions ensuring the best industry standards to protect the solution and the information it contains • The ability to develop prototypes, design and building services which meet both user needs and the GOV.UK guidelines for content design, service design and accessibility • Ability of running user research in line with the GOV.UK service manual • Well-rounded technical understanding to collaborate on technical specifications • Potential Bidders must confirm they are already or will sign up to the CCS e-Sourcing Suite for the Evaluation Stage before the Shortlisting Stage submission deadline • Potential Bidders must agree to abide by Crown Commercial Service’s Process for the Evaluation Stage Nice to Haves • Demonstrable evidence of transforming websites through good UX design and coaching best practices across organisations at all levels • Strong experience of UK Government Design Principles, Service Standard and Service Manual • Experience of planning, documenting and communicating the design process and concepts in a clear, concise manner • Demonstrate experience in provisioning, configuring, deploying and managing the hosting platform on the GOV.UK PaaS platform • Have experience with responsive web design • Hold Cyber Essentials certifications • Experience delivering a service that has passed a GDS Service Assessment Work Location The supplier can work remotely in the UK. Government Security is based in the Cabinet Office (70 Whitehall, London). Working Arrangments The supplier and their staff working on the project must be based in the UK and be able to either travel to London or attend virtual meetings. Security Clearance Due to the nature of our work suppliers should be willing to nominate individuals to undergo security clearance if required. https://www.gov.uk/government/publications/vetting-explained-and-our-vetting-charter Additional T&Cs All expenses must be pre-agreed between the parties and must comply with the Cabinet Office (CO) Travel and Subsistence (T&S) Policy. All vendors are obliged to provide sufficient guarantees to implement appropriate technical and organisational measures so that the processing meets the requirements of GDPR and ensures the protection of the rights of data subjects. For further information please see the Information Commissioner's Office website https://ico.org.uk/for-organisations/data-protection-reform/overview-of-the-gdpr/ The solution must implement the Cloud Security Principles - https://www.ncsc.gov.uk/collection/cloud-security/implementing-the-cloud-security-principles No. of Suppliers to Evaluate 5 Proposal Criteria • Proposed technical solution (40%) • Approach and methodology (40%) • Knowledge transfer (10%) • Social Value (10%) Cultural Fit Criteria Cultural fit (100%) Payment Approach Capped time and materials Assessment Method Case study Evaluation Weighting Technical competence 50% Cultural fit 20% Price 30% Questions from Suppliers 1. Does the intranet need to integrate with any existing systems and tooling, such as authentication, cyber security, protective monitoring, service monitoring etc? The extranet will not integrate with any other systems at this time. 2. who did the discovery? The discovery phase was carried out by an in-house team within Government Security. 3. Regarding- Hold Cyber Essentials certifications.Are you happy to.produce this at the selection stage..? As part of the shortlisting stage, please indicate whether you hold/do not hold the Cyber Essentials certifications. Additional evidence may be required at the further evaluation stage. 4. Is there a list of authorised users and if so roughly how many users are expected to authorise to the system?There appears to be 3 levels of users, public (anyone can access), public sector (only users from the public sector) and authorised users (users with credentials and access to non-public data) – is there to be a seperate access level for public sector users who can access different data to the general public? If so, how does the system identify public sector users? Or are there only two levels of user access; public (including public sector) and authorised users? The solution should be scalable and grow as more users sign up. A product we are currently using (to be decommissioned once this solution is in place) has 2,000 registered users. In the first two years we don't expect to exceed 5,000 registered users.Early user research has indicated that there's a desire for information only being released to specific communities, but we'd expect everyone in a community to be an authorised user (with credentials and access to non-public data). So there will be two levels of user access, the public (including unauthenticated public sector users) and authorised users.

Timeline

  1. Completed: Tender published2 February 2022
    Current notice
  2. Completed: Submission date16 February 2022

About the buyer

Cabinet Office is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.

AI insights

  • Is there a preferred supplier?
  • What are the buyers pain points?
  • What has the buyer previously procured?
  • What are the key requirements?
Sign-up to enrich

Decision makers

Connect with the people behind this procurement.

Contact nameJob titlePhone numberWork email
Head of Procurement+44 •••• ••••••
Commercial Director+44 •••• ••••••
Procurement Manager+44 •••• ••••••
Category Lead+44 •••• ••••••
Senior Buyer+44 •••• ••••••
Contracts Manager+44 •••• ••••••

Related topics

Topics related to Government Security Extranet - Alpha, ranked by notice volume.

View all topics
TopicCountValue
  1. 5,185
    £735.9bn
  2. 4,088
    £269.5bn
  3. 4,672
    £63.7bn
  4. 4,815
    £66.2bn
  5. 2,886
    £97.0bn

Win more public sector contracts

Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.