gvtcx

TRN 1052/07/2105 - Supply of Cyber Security Technical Benchmarking

DEPARTMENT OF ENERGY AND CLIMATE CHANGE Published 18 Nov 2016 Contracts Finder

key details

Value£27,000
Statuscomplete
Category (CPV) 09000000 +2 more
RegionLondon
Deadline25 May 2015
Contract start3 Aug 2015
Contract end1 Mar 2016
SME suitableYes
OCIDocds-b5fd17-c3c5f979-adc8-11e6-9901-0019b9f3037b

Award

SupplierValueDateStatus
CSO Confidential £27,000 28 Jul 2015 active

description

The E3CC High-level Risks and Control Assessment across the downstream gas and electricity sectors identified the following priority areas of shared risk on which industry have requested HMG support. This work will look at the best practices and maturity of management across members in both Operational Technology (OT) and Information Technology (IT) environments of their companies for:

  • Access control and identity management
  • Communications management, including remote access
  • Management of end point security and data leakage prevention

For each of the topic areas, the following process will be followed:

Background research will be carried out to look at existing standards, general best practices and any specific standards and practices relevant to the electricity and gas sectors. From these, and initial conversations with the E3CC members as well as reference back to the E3CC cyber security risk assessment, a series of themes, sub-topics and key questions will be developed. The aim is to identify levels of maturity as well as lessons learnt/key best practices.

The key questions will then be used to survey the E3CC membership, usually in the form of a telephone interview. (Participation is voluntary, but past benchmarks have gained the involvement of 80-100% of all 16 members; we expect the contractor to work with us at the earliest opportunity, if involvement looks to be significantly less than this, i.e. <50% of the members). Anonymity will be assured by the contractor, although members may volunteer to be attributed on sub-topics if they wish.

The data collected from the completed questionnaires and interviews will then be collated and analysed and may have additional literature research added to help explain any findings, where required

The results will be collated into a report which is then presented to the following E3CC meeting and retained on the private E3CC section of the CPNI Extranet.

The final reports will include:

-A definition of good cyber security practices against each of these three topics;
-An assessment of cyber maturity within the downstream gas and electricity sectors against each of the three topic areas, against good-practice. This will be a baseline for future assessments.
-An assessment of cyber security practices compared to other CNI sectors, where appropriate.
-Any Recommendations on how to improve cyber security practices within the downstream gas and electricity sectors based on the analysis of the findings.

notice history

1 notice published against this procurement.

PublishedTypeRegimeNotice
11 Sept 2015 Award (award) · ocds-b5fd17-c3c5f979-adc8-11e6-9901-0019b9f3037b-73945-trn-1052-07-2015

more from DEPARTMENT OF ENERGY AND CLIMATE CHANGE

all contracts from this buyer →

similar contracts awarded

Other awarded contracts in the same category. Useful for seeing who normally wins this kind of work, and at what value.

source

Published on Contracts Finder. Contact details for named individuals are not reproduced on this site.