RM1043.8-1-UKHSA Security Architecture
Details
- Value
- GBP 2,800,000
- Published
- 26 April 2023
- Submission
- 12 May 2023
Tender description
About adding context and requirements test Work done so far There are approximately 100 ongoing projects and pieces of work being undertaken at the moment in various stages, the supplier will take over some of the more complex pieces and we will deprecate the remainder using the newly formed PMO. Which phase the project is in Not started Existing team Cyber Security Operations Cyber Security Operations G6 Head of Security Operations Cyber Security Operations G7 Cyber Contract / Testing Lead Cyber Security Operations G7 Cyber Security Business Lead Cyber Security Operations SEO SECOPS Analyst Cyber Security Operations SEO SECOPS Analyst Cyber Security Delivery Cyber Security Delivery G6 Security Architect Lead Cyber Security Delivery G7 Security Architect Cyber Security Delivery SEO Security Architect Cyber Security Delivery SEO Security Architect Cyber Compliance Risk and Assurance Cyber Compliance Risk and Assurance G6 Cyber Risk and and Assurance Lead Cyber Compliance Risk and Assurance G7 Cyber Governance and Risk Lead Cyber Compliance Risk and Assurance SEO Jnr Cyber Risk and Assurance Specialist Cyber Compliance Risk and Assurance HEO Cyber Governance and Risk Cyber Compliance Risk and Assurance G7 Compliance Lead Cyber Compliance Risk and Assurance HEO Compliance Officer Cyber Compliance Risk and Assurance EO Compliance Support Cyber Compliance Risk and Assurance SEO Standards and Policy Officer Cyber Compliance Risk and Assurance G7 Product and Supply Chain Lead Cyber Compliance Risk and Assurance SEO Product and Supply Chain Officer Cyber Compliance Risk and Assurance HEO Product and Supply Chain Support Programme Management and Operations Programme Management and Operations G6 Cyber Programme and Operational Lead Programme Management and Operations G7 Cyber Strategy Specialist Programme Management and Operations SEO Admin Support Programme Management and Operations HEO Admin Support Programme Management and Operations G7 PMO Project Lead Programme Management and Operations SEO Project Manager Programme Management and Operations SEO Project Manager Programme Management and Operations G7 Business Engagement Lead Programme Management and Operations SEO Business Engagement Officer Culture and Awareness G7 Cyber Culture Lead Culture and Awareness SEO Cyber Training Address where the work will be done Remote and various UKHSA locations as required Working arrangements Remote or UKHSA head office, with occasional travel to other UKHSA sites. Expenses to be approved in advance by contract manager Provide more information about your security requirements: Baseline Personnel Security Standard (BPSS) Provide more information about your security requirements: Counter Terrorist Check (CTC) Provide more information about your security requirements: Security Check (SC) Provide more information about your security requirements (optional): SOME STAFF MAY NEED SC or DV clearance for specific projects Latest start date 2023-07-01 Enter the expected contract length: 2 years Extension period: 1 year Write the term or acronym: Security Architecture Write the term or acronym: TOGAF Write the term or acronym: SABSA Write the term or acronym: OSA Write the term or acronym: Zero-Knowledge Write the term or acronym: SSO Write the term or acronym: BYOD Write the term or acronym: Defence in Depth Write the term or acronym: Air-Gapped Write the term or acronym: PCI-DSS Write the term or acronym: ISO Write the term or acronym: NCSC Write the term or acronym: NIS Directive Write the term or acronym: CNI Write the term or acronym: UK GDPR Write the term or acronym: TOGAF Methodology Write the term or acronym: SABSA Methodology Write the term or acronym: OSA Methodology Explain the term or acronym: The practice of designing computer systems to achieve security goals Explain the term or acronym: The Open Group Architecture Framework Explain the term or acronym: Sherwood Applied Business Security Architecture Explain the term or acronym: Open Security Architecture Explain the term or acronym: Design school of thought revolving around removing the inherent trust in your internal network Explain the term or acronym: Single Sign-On Explain the term or acronym: Bring Your Own Device Explain the term or acronym: Defence in Depth is a strategy that leverages multiple security measures to protect an organisation’s assets. Explain the term or acronym: An air-gapped device has no direct connection to the internet or any other device connected to the internet Explain the term or acronym: The Payment Card Industry Data Security Standard Explain the term or acronym: International Organisation for Standardisation Explain the term or acronym: National Institute of Standards and Technology (US Explain the term or acronym: Network and Information Systems Regulations (2018) Explain the term or acronym: Critical National Infrastructure Explain the term or acronym: The United Kingdom General Data Protection Regulation, as part of the Data Protection Act (2018) Explain the term or acronym: TOGAF focuses on the preliminary phases of Security Architecture through setting the organisation’s scope and goal and aids in determining what problems the organisation wants to solve with Security Architecture. Explain the term or acronym: SABSA is a policy-driven framework that aims to answer the critical questions asked by the security architect: who, what, when, and why. The end goal is to ensure that security services within an organisation are an integral part of its IT management. Explain the term or acronym: OSA is a framework that offers an overview of critical security issues, principles, components and concepts underlying architectural decisions involved when designing effective security architectures. Unlike the previous two, which focus on the reasons for the project, OSA focuses on the actual security controls and their implementation. Are you prepared to show your budget details?: Yes Indicative maximum: 4000000 Indicative minimum: 1600000 Confirm if you require a contracted out service or supply of resource Contracted out service: the off-payroll rules do not apply Summary of work • The ability to lead and support Threat Modelling workshops Utilising the following frameworks, 1. Microsoft STRIDE; 2. MITRE ATT&CK; 3. OWSAP Top 10 • The ability to lead and support Risk Assessment workshops Utilising the following frameworks, 1. Center for Internet Security Critical Security Controls; 2. NCSC Cyber Assessment Framework; 3. NHS Data Security and Protection Toolkit • The ability to review and critique both high and low level designs • To create & update technical standards to support organisation policies Understanding of UK HMG Functional Standards, including GovS • To create & update architectural cloud blueprints/design patterns Aligned with Microsoft Azure and AWS Well-Architected Frameworks • To create & update security requirements for projects and tenders • To be able to articulate technical cyber risk & issues to none-technical stakeholders in plain English Also, the the following shall be part of the key elements of the service requirements: Security Engagement: - • Security Risk & Assurance: - Development and delivery of processes including: Risk assessment and analysis, Risk Reporting, 3rd Party Assurance, Security Control Assessment, Control Framework Compliance. • ISMS Delivery: - Development and delivery of processes including: ISMS Definition, Security Policy, Security Control Definition, Audit Liaison. • Application Security & Cloud Security Engineering: - Development and delivery of processes including: Continuous Controls Monitoring, Documenting Systems security plans, Completing Security control assessments, Implementing Identity and Access Management, Implementing Security baseline Configuration, Operating CI / CD integrated tests, Delivering Specialist awareness training • Security Behaviour and Culture: - Development and delivery of processes including: Programme user security awareness training, Supplier staff engagement / training, Citizen risky behaviours, Intranet Site and Policy Publication, Phishing programs, Exec/Board Education, Skills assessment Following internal conversations with DAS strategic finance lead, this function is to be delivered in house with effect from the 1st of November 2022. • Penetration Testing Coordination: - Development of processes required to scope, engage and manage multiple concurrent penetration testing engagements. Engagement with business to define scope of penetration tests, engage penetration testing service providers, assess results of penetration tests, develop action plans • Project Management and Co-ordination: - These services should cover a wide range of security outcomes and co-ordination activities to support the Cyber Security team including: Authoring of business cases for technology and security resources, management of Commercial and financial processes to ensure procurements are compliant and appropriate for the business, providing Cybersecurity strategic capabilities as and when required by the business. This service is currently provided by a 3rd party and uses up to 15 staff on who are provided on an as and when needed basis. The requirement is for the equivalent of 150 hours of in-house resource per week to be available at all times and up to a further 500 hours per week to be available too. Therefore, the successful supplier shall have the capacity to provide up to 650 hours of in-house resource per week without relying on a 3rd party contract staff. Where the supplied staff will work London Where the supplied staff will work No specific location (for example they can work remotely) Who the organisation using the products or services is UK Health Security Agency Why the work is being done Below is a non-exhaustive list of UKHSA motivation and organisational benefits of a secure architecture: ● increase resilience to cyber attacks ● allows for a greater understanding of your organisation’s IT estate ● proactive security controls allow for cost savings ● helps to ensure the secure storage of sensitive data/information ● reduces the risk associated with a cyber incident ● increases the organisations’ resilience ● reduces the attack surface of the organisation ● allows for increased operational efficiency ● allows security measures to support rather than hinder the business ● acts as assurance for entering into agreements with third parties The business problem you need to solve Security Engagement: - • Security Risk & Assurance: - Development and delivery of processes including: Risk assessment and analysis, Risk Reporting, 3rd Party Assurance, Security Control Assessment, Control Framework Compliance. • ISMS Delivery: - Development and delivery of processes including: ISMS Definition, Security Policy, Security Control Definition, Audit Liaison. • Application Security & Cloud Security Engineering: - Development and delivery of processes including: Continuous Controls Monitoring, Documenting Systems security plans, Completing Security control assessments, Implementing Identity and Access Management, Implementing Security baseline Configuration, Operating CI / CD integrated tests, Delivering Specialist awareness training • Security Behaviour and Culture: - Development and delivery of processes including: Programme user security awareness training, Supplier staff engagement / training, Citizen risky behaviours, Intranet Site and Policy Publication, Phishing programs, Exec/Board Education, Skills assessment Following internal conversations with DAS strategic finance lead, this function is to be delivered in house with effect from the 1st of November 2022. • Penetration Testing Coordination: - Development of processes required to scope, engage and manage multiple concurrent penetration testing engagements. Engagement with business to define scope of penetration tests, engage penetration testing service providers, assess results of penetration tests, develop action plans • Project Management and Co-ordination: - These services should cover a wide range of security outcomes and co-ordination activities to support the Cyber Security team including: Authoring of business cases for technology and security resources, management of Commercial and financial processes to ensure procurements are compliant and appropriate for the business, providing Cybersecurity strategic capabilities as and when required by the business. First user type: N/A Enter more details about this user type: N/A
Timeline
- Completed: Tender published26 April 2023Current notice
- Completed: Submission date12 May 2023
About the buyer
UK Health Security Agency is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.
Decision makers
Connect with the people behind this procurement.
| Contact name | Job title | Phone number | Work email |
|---|---|---|---|
| Head of Procurement | +44 •••• •••••• | ••••••••@uk-health-security-agency.gov | |
| Commercial Director | +44 •••• •••••• | ••••••••@uk-health-security-agency.gov | |
| Procurement Manager | +44 •••• •••••• | ••••••••@uk-health-security-agency.gov | |
| Category Lead | +44 •••• •••••• | ••••••••@uk-health-security-agency.gov | |
| Senior Buyer | +44 •••• •••••• | ••••••••@uk-health-security-agency.gov | |
| Contracts Manager | +44 •••• •••••• | ••••••••@uk-health-security-agency.gov |
Related topics
Topics related to RM1043.8-1-UKHSA Security Architecture, ranked by notice volume.
- 1,485£14.9bn
- 1,283£16.9bn
- 1,415£4.4bn
- 5,185£735.9bn
- 165£2.7bn
- 182£2.7bn
- 1,418£20.1bn
- 4,088£269.5bn
- 5,030£73.7bn
Related buyers
Buyers similar to UK Health Security Agency.
- 2,657£1.7bn
- 900£19.4bn
- 688£8.8bn
- 433£3.8bn
- 350£20.5m
- 301£368.1m
- 261£233.9m
- 252£578.5m
- 240£10.1bn
- 171£48.3m
Win more public sector contracts
Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.
