Welcome, visitor!   Login

Menu Post an Ad

Information Security and Architecture Services

Global-Fund-logo2

Item Details:

  • Organisation: The Global Fund to Fight AIDS, Tuberculosis and Malaria
  • Reference Number: TGF-20-011
  • Published: 12th February 2020
  • Deadline: 26th February 2020 at 5 pm
  • Time zone: Geneva Time
  • Street: Chemin du Pommier 40
  • City: Geneva
  • Country: Switzerland
  • Zip/Postal Code: 1218
  • Expires: This ad has expired

Email to a friend

← Go Back
  • Item listed by: on 2020-02-14

    Item Description:

    The Global Fund to Fight AIDS, Tuberculosis and Malaria (“the Global Fund”) was established in January 2002 as a financial instrument, complementary to existing programs addressing HIV/AIDS, tuberculosis and malaria. It is a 21st century organisation designed to accelerate the end of AIDS, tuberculosis and malaria as epidemics. As partnership between government, civil society, the private sector, and people affected by the disease, the Global Fund mobilizes and invests nearly USD 4 billion a year to support programs run by local experts in more than 110 countries. The Global Fund operates with three core principles: partnership, country ownership and performance-based funding. By challenging barriers and embracing innovative approaches, the Global Fund strives for maximum impact.

    Objectives of the Consultancy

    The Global Fund would like to engage organizations specializing in Microsoft technologies, security & information risk assessments (penetration testing), enterprise and security architecture, change management, communications, information security training and implementing specialist security tools and technologies. The objective is to build out a security foundation of new security capabilities across Global Fund to ensure the continued protection for Global Fund information assets.

    Scope of Work

    The scope of work broadly covers the following technological and functional areas:

    1. Microsoft Technologies, Azure and Office365 architecture, design, security, development, implementation and optimization
    2. SharePoint & Business integration
    3. Security and IT assessments, penetration testing & 3rd party audits

    The detailed scope of this service will include but not be limited to:

    a) Microsofttechnologies,AzureandOffice365architecture,design,security, development, implementation and optimisation

    • Microsoft, Azure and 0365 Azure architecture and service configuration & integration.
    • Configure, optimize, tune and implement security best practices for Microsoft Azure and 0365 and configure and implement security tools and technologies. Including but not limited to azure information protection, Cloud App, 0365 data protection (GDPR), auditing logging , security and compliance centre and advanced emerging security features
    • Microsoft Workbench and Artificial intelligence expertise.
    • Knowledge sharing best practices for Azure in and around CI and sustainability of ML workflows for both exploratory and production use (with a key chain of continuity between the two).
    • Microsoft, Azure and 0365 security optimization and implementing best practices and tuning. Designing and implementing auditing and logging and alerting of security related incidents and unauthorized admin activity and access.
    • Identity and access management using solutions such as MIM 2016, Azure AD, Privileged Access Management and Privileged Identity Management and other related security new features.
    • Evaluating and architecting and implementing 3rd party security capabilities and tools to be used with Microsoft e.g. Varonis
    • Data loss prevention and Azure information protection. Evaluating and implementing data leak protection. Azure Information Protection, digital rights management and encryption. Labelling and classification of information and change management required to adopt technologies.
    • Cloud Access Security Brokers. Cloud compliance technologies. e.g. Netscope etc. Advanced security tools.
    • Assistance with preparation of solution design and functional specification and operational documentation. Support the Global Fund with elements of infrastructure deployments and implementation of proof-of-concepts for testing related scenarios.
    • Business process analysis and recommendations of industry best practices in the area of security, identity and role management, including streamlining and automating on and off-boarding processes.

    b)  SharePointBusinessIntegration

    • Interact with the business and gather requirement and prepare integration of in- house project, plan
    • Sharepoint management, setup best practices and implement new features and optimization.
    • Knowledge, training and awareness to IT and business teams.
    • Documentation and processes, procedures
    • Integration of 3rd party products for monitoring alerting and security enhancements e.g. Varonis

    c)  Security and IT assessments, Penetration testing & 3rd party audits

    • Internal and external penetration testing, security assessments.
    • Penetration testing will include the use of automated and manual tools and techniques to analyze information systems and business logic for potential vulnerabilities resulting from poor or improper system configuration, both known and unknown hardware or software flaws, and operational weaknesses in process or technical countermeasures.
    • Provide security and IT assessments against international standards and best practices.
    • Provide senior management with prioritized action plans and technical reports.
    • Develop baseline secure configurations and build configuration assessments.
    • Develop and support remediation efforts when required. Assess (and remediate) security configuration of information assets including platforms, network, and applications to identify vulnerabilities to industry benchmarks and Global Fund regulations and standards.
    • Develop secure development life cycle process review and policies. Conduct code reviews and remediation. Review source code to verify the existence of security controls, ensuring that they work as intended, that they have been invoked through secure channels and at appropriate times, and to ensure the code is free of backdoors and malware.
    • Develop audit plans against international standards such as ISO-27001/2 and specific Global Fund criteria.
    • Conduct 3rd party audits on suppliers when required for assurance.

    Engagement

    Global Fund cannot guarantee the exact number of project hours that the selected suppliers will be awarded.

    Global Fund recognizes that personnel changes within the bidder’s organization may affect the availability of personnel. Bidders should strive to retain the same personnel for Global Fund to ensure continuity and build knowledge of the environment and provide consistent services. Bidders should also cater for additional resources in case of multiple security services are being awarded to the same firm.

    Global Fund reserves the right to accept or reject the use of specific personnel on an individual project basis.

    Periodic performance reviews will be conducted to review KPI’s related to quality of service provided, availability of qualified personnel, adherence to SLAs for lead time, review of feedback including issues and challenges received from Global Fund stakeholders.

    Each selected firm should propose a Program Manager who would be the focal point of engagement with Global Fund.

    Download Request for Proposals (RFP) in English

    No Tags

      

    Listing ID: 5795e473768b977f

    Report problem

    Processing your request, Please wait....

    Verified user

    Sponsored Links

    Related Ads

    Some other ads that you might be interested in...

    IFAD

    Provision of Claim Handling Services For Employer’s Liability Insuran...

    The purpose of this request for proposal (RFP) is to select a qualified and experienced Third Party Administrators for handling, administering and settling claims related […]

    2018-09-14

    itu-logo2

    Development, Implementation, and Maintenance of a “Information Mediator Bui...

    The International Telecommunication Union (ITU) is pleased to invite your company to submit a Proposal for the Development, implementation, and maintenance of a “Information Mediator […]

    2022-06-21

    afdb-logo2

    Acquisition, implementation, maintenance and training of SAP lease administ...

    The African Development Bank (hereafter referred to as “The Bank”) intent to select a company for the supply, installation, configuration, maintenance and training for SAP […]

    2018-10-09

    Leave a Reply

    You must be logged in to post a comment.

    Listing Opportunities

    Featured Tender

    Innovative Solutions

    error: Content is protected !!