II.1)
Scope of the procurement
Cyber Security Testing Services (CSTS)
Reference number:
ENQEIR653
72222300
-
Information technology services
Services
II.1.4)
Short description
Driven by the ongoing development of our information security framework and business transformation programmes, EirGrid’s Information Security function has established a security testing and a security risk assessments reporting regime. The aim of the reporting regime is to provide EirGrid with the following:
1. Vulnerability assessment with the associated exposures inherent within their current infrastructure.
2. Comprehensive risk analysis and recommendations, including a remediation plan.
3. Security audit, security reviews and test details, including applied methodology.
In keeping with its position in the industry EirGrid maintains a modern IT infrastructure comprising the following technologies:
• Servers: Physical and Virtual. Linux, Unix, Windows.
• Desktop: Workstation and Laptop. Windows.
• Databases: Oracle and MSQL.
• Network: Routers, Switches, Firewalls, Load Balancers and Gateways.
• Cloud Services.
II.1.5)
Estimated total value
Value excluding VAT: 640000.00
EUR
II.1.6)
Information about lots
This contract is divided into lots:
no
II.2.2)
Additional CPV code(s)
72222300
-
Information technology services
II.2.3)
Place of performance
Main site or place of performance:
Dublin, Belfast
II.2.4)
Description of the procurement
EirGrid intends to establish a single supplier framework. The Framework Agreement period will be for an initial duration of three (3) years with the option to extend yearly for up to five (5) years, subject always to the satisfactory performance of the member.
EirGrid require a security partner to provide the scope of services below. The scope of services is expected to include, but is not limited to:
• Provision of Cyber Security Testing Services (CSTS) across EirGrid’s IT Infrastructure to ensure security, confidentiality and integrity.
• Security testing will be primarily targeted at the externally visible infrastructure but some may be required to be internal.
• Security testing may be targeted at production and pre-production environments.
• Some CSTS may require re-testing to confirm the implementation of the remediation plan.
• Each security testing will be subject to individual scoping determined by EirGrid and agreed with the successful supplier, including “rules of engagement” such as:
Type of security testing.
Targets.
Objectives (what can and cannot be done).
Scope (processes, website options, infrastructure, services that are off limits).
Progress reporting.
Entry points.
Price is not the only award criterion and all criteria are stated only in the procurement documents
Value excluding VAT: 640000.00
EUR
II.2.7)
Duration of the contract, framework agreement or dynamic purchasing system
Duration in months:
36
This contract is subject to renewal:
no
II.2.9)
Information about the limits on the number of candidates to be invited
Envisaged number of candidates:
5
Objective criteria for choosing the limited number of candidates:
Please see Information Memorandum and Pre-Qualification Questionnaire attached to this notice
II.2.10)
Information about variants
Variants will be accepted:
no
II.2.11)
Information about options
Options:
yes
Description of options:
The initial contract period envisaged is three years with the possibility to extend annually up to a further five years, subject always to the satisfactory performance of the supplier.
The estimated spend of 640,000 EUR is taking into account the full duration of the contract including the possible extensions.
II.2.13)
Information about European Union funds
The procurement is related to a project and/or programme financed by European Union funds:
no