gvtcx

Detection and Response Security Solution

Genomics England Published 12 Aug 2020 Contracts Finder
The value below is a framework or dynamic market ceiling: the maximum that could be spent across all call-offs, not the value of a single contract. Aggregate figures on this site exclude these to avoid double counting.

key details

Value£300,000
Statusactive
Category (CPV) 48730000
RegionLondon
Deadline4 Sept 2020
Contract start1 Oct 2020
Contract end30 Sept 2021
Procedureselective
SME suitableYes
OCIDocds-b5fd17-ac66eb60-da48-4e6e-b8ac-8f418099a70a

description

NB: This is a further competition under an existing procurement framework and isnt open to the wider market. This notice is for information only.

Genomics England has a Cyber Security Strategy that commits to improving the cyber security capabilities of our information systems. A detection, response and management solution would provide a significant capability in line with the Cyber Security Strategy.

It is envisaged that a detection and response capability would provide three significant benefits:

  1. The ability to detect malicious, suspicious, or anomalous events and behaviours across the whole of the GEL enterprise
  2. The ability to review and interpret findings quickly and easily
  3. The capability to quickly respond to malicious events with the option to automate standard response to common events

The solution for developing a detection and response capability is expected have the following characteristics. This is not an exhaustive list and should support the required outcome, it is not intended to preclude or favour any specific technology.

  1. Information Entities for Analysis

The solution must be able to analyse data that gives an insight into user and device behaviour within the Genomics England Enterprise Systems (Cloud, On Prem, SAAS, IAAS, PAAS etc.)

  1. User Behaviour Profiling Models

The solution must be able to model data and detect suspicious or 'out of character' behaviour. The solution must not rely solely on being able to recognise 'known bad' events (i.e. signature or rules-based detection).

  1. Reports and Dashboards

The solution must be able to present information that is easy to understand and interpret. The solution must be able to cater for a diverse set of users e.g. analysts, senior management etc.

  1. Deployment options

The solution must be able to cater for the whole Genomics England Enterprise (Cloud, On Prem, SAAS, IAAS, PAAS etc.).

  1. Integrations with Identity Management (e.g. Azure AD, Okta, etc)
  1. Response Capabilities

The solution must enable Genomics England staff to respond to possible security incidents in order to prevent or contain a security breach. As well enabling staff the solution should also have the capability to follow defined 'playbooks' and take automated action when triggered by certain events. This is often referred to as SOAR (Security Orchestration and Response). The key is reducing Genomics England's MTTR (Mean Time to Respond) in managing security incidents.

Additional information:

NB: This is a closed further competition under an existing framework therefore isnt open to opportunity to the wider market. The eSourcing Portal link will not provide an open tender to register interest.

documents

Documents are linked, not mirrored. They are served by the publishing authority and may require registration.

notice history

1 notice published against this procurement.

PublishedTypeRegimeNotice
13 Aug 2020 Tender (tender) · c202a135-50c2-4e2a-bdac-948d00f4f811-375697

more from Genomics England

all contracts from this buyer →

similar contracts awarded

Other awarded contracts in the same category. Useful for seeing who normally wins this kind of work, and at what value.

source

Published on Contracts Finder. Contact details for named individuals are not reproduced on this site.