RM1043.8-1-MINISTRY OF DEFENCE - Defence Digital - 713225450 - CARP Testing
Details
- Buyer
- Ministry of Defence
- Published
- 11 November 2024
- Submission
- 25 November 2024
Tender description
Work done so far Similar work is ongoing to deliver workshops that help systems begin the process of creating cyber attack recovery plans. Some of these systems will almost certainly undergo Testing and Exercising workshops to validate the outputs. Which phase the project is in Alpha Existing team At present there is a permanent PM on CARP, supported by a technical assurance lead, and a MOD theme lead overseeing suppliers delivering pre-mortem workshops and the creation of CARP tools. Address where the work will be done The project’s centre of gravity will be at MOD Corsham SN14 9NR, but workshops will be delivered across the MOD estate, taking place at the site most convenient for the system – travel will therefore be required. Non-workshop work can largely be delivered remotely. Working arrangements Contractors employed under contract will generally not be required to work specific hours but will need to meet agreed milestones, provide agreed reporting, and attend agreed meetings. The exception to this is when delivering workshops when contractors will typically be working 8-hour days within Civil Service core hours. Contractors should be prepared to work onsite when it is requested by Authority. For a small number of cases in SECRET there may be a requirement to work exclusively onsite. Onsite work delivering workshops will attract entitlement to T&S expenses in accordance with MOD Travel Guide rates, providing it is approved in advance. Provide more information about your security requirements: Security Check (SC) Provide more information about your security requirements: Developed Vetting (DV) Provide more information about your security requirements (optional): All roles must hold SC as a minimum. Supplier must also be able to provide some DV cleared individuals for select roles, to be dictated within Statements of Work. Latest start date 2025-03-03 Enter the expected contract length: 1 year Special terms and conditions Security requirements of a minority of select roles may dictate that only MOD provided laptops may be appropriate to perform role. Special terms and conditions Security Aspects Letter ref “20241111-CARP SAL V1.0-UKO”. The Supplier shall comply with the Security Aspects Letter for this Contract. Special terms and conditions No specific Quality Management System requirements are defined. This does not relieve the Supplier of providing conforming products under this contract. Special terms and conditions No Deliverable Quality Plan is required reference DEFCON 602B Special terms and conditions Concessions shall be managed in accordance with Def Stan. 05-061 Part 1, Issue 7 – Quality Assurance Procedural Requirements – Concessions. Special terms and conditions Any contractor working parties shall be provided in accordance with Def Stan. 05-061 Part 4, Issue 4 – Quality Assurance Procedural Requirements – Contractor Working Parties Special terms and conditions Supply of a contracted out service: the off-payroll rules do not apply. Are you prepared to show your budget details?: Yes Indicative maximum: £ 1,657,500 (Ex VAT). This is inclusive of £30,000 ex VAT Travel & Subsistence. Confirm if you require a contracted out service or supply of resource Contracted out service: the off-payroll rules do not apply Summary of work The CARP project aims to develop recovery planning processes and procedures for impacted systems and services and by providing a framework upon which future recovery efforts can be based. The Testing and Exercising workstream will deliver a cyber recovery plan test and exercise process and reporting, that will improve the maturity of MoD’s digital resilience. This process shall prepare the organisation to perform more sophisticated testing exercises in the long term and be based on best practice and discovery activity within MoD. It should be sensitive to the varied needs across the business not only in classification but in terms of the cost benefit in the selection of testing methods. It will then deliver 20 Cyber Attack Recovery Plan Testing and Exercising workshops (along with follow up reports) to a prioritised list of critical communication, information, and operational systems with the aim of: - Increasing the maturity of cyber capability through exercising recovery plans to achieve a material improvement in cyber recovery resilience and a reduction in cyber risk. - Gaining end-to-end insight on the strengths and weaknesses of cyber-attack recovery delivery in relation to people, process, and technology. The supplier shall review and refine the cyber recovery plan test and exercising process following each workshop. This process must have the ability to be scaled and implemented further across MOD to enable ongoing test and exercising. This must be developed in such a way as to support CARP Testing and Exercising to transition into a service model forming part of a wider programme service catalogue. Where the supplied staff will work No specific location (for example they can work remotely) Who the organisation using the products or services is MOD StratCom - Defence Digital Why the work is being done The MOD faces an increasing threat of cyber-attacks, some of which will not be prevented through NIST Cybersecurity framework preventative elements alone (Identify, Protect, Detect and Respond). Therefore, MOD requires the capability to recover from the effects of such an attack. The CARP project is meeting this requirement by developing recovery planning processes and procedures for impacted systems and services and by providing a framework upon which future recovery efforts can be based. Alongside the tools to produce recovery plans, proven methodologies and processes to test and exercise these plans are critical to ensuring these systems not only better prevent attacks occurring but ensure business continuity in the event of an incident, and the rapid recovery of full service as soon as possible. This project will enable the creation of suitable methodologies and tools to test and exercise recovery plans as well as the delivery of twenty workshops to not only validate the plans of selected critical systems, but also ensure the tools developed incorporate user feedback and are suitable going forward. The business problem you need to solve The MOD requires not only a framework and tools to guide how systems plan for cyber attack recovery but also methodologies and processes to validate the suitability of their recovery plans. In order to achieve the necessary business change across MOD it is critical these policies and processes are developed through active user engagement with systems and systems are supported in their recovery plan development. First user type: Users of the service will be twenty systems. These are critical systems that have developed a cyber attack recovery plan but require it to be exercised and validated to ensure to is fit for purpose.
Timeline
- Completed: Tender published11 November 2024Current notice
- Completed: Submission date25 November 2024
About the buyer
Ministry of Defence is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.
Decision makers
Connect with the people behind this procurement.
| Contact name | Job title | Phone number | Work email |
|---|---|---|---|
| Head of Procurement | +44 •••• •••••• | ••••••••@ministry-of-defence.gov | |
| Commercial Director | +44 •••• •••••• | ••••••••@ministry-of-defence.gov | |
| Procurement Manager | +44 •••• •••••• | ••••••••@ministry-of-defence.gov | |
| Category Lead | +44 •••• •••••• | ••••••••@ministry-of-defence.gov | |
| Senior Buyer | +44 •••• •••••• | ••••••••@ministry-of-defence.gov | |
| Contracts Manager | +44 •••• •••••• | ••••••••@ministry-of-defence.gov |
Related topics
Topics related to RM1043.8-1-MINISTRY OF DEFENCE - Defence Digital - 713225450 - CARP Testing, ranked by notice volume.
- 5,684£136.4bn
- 11,699£1.1tn
- 11,175£1.0tn
- 26,970£1.7tn
- 4,068£249.4bn
Related buyers
Buyers similar to Ministry of Defence.
- 731£1.3bn
- 675£133.0bn
- 637£160.0bn
- 446£8.1bn
- 334£7.4bn
- 324£1.3bn
- 272£1.1bn
- 252£892.4m
- 224£483.9m
- 178£221.9bn
Win more public sector contracts
Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.
