19CPU255 - Penetration Testing
Tender ID: 405891
Tender Details
Tender Description
This Tender is invited by the Issuer.
1. The vendor must be a Council of Registered Ethical Security Testers (CREST) approved company.
2. The URL’s will be pen tested, in addition to the URL’s, the vendor must allow for the testing of up to two additional services which will be identified and agreed to during the contract period.
3. The Vendor will engage with Comcare to develop a test plan and seek approval prior to commencement.
4. The Vendor will provide provision of feedback on findings during the testing to support the management of risks.
5. After testing the vendor will provide a report of the findings of the test plan to Comcare within the agreed time frames detailed in the test plan.
6. The report will provide risk assessed findings and recommendations to address any vulnerabilities discovered during the assessment.
7. The risk assessment should be in line with Comcare’s Risk Management Framework (framework information will be provided by Comcare).
8. All testing is to be undertaken passively. The vendor must not actively exploit vulnerabilities discovered during the testing.
9. The vendor will provide their IP addresses which will be used during the testing. Comcare will pass these IP addresses to stakeholders to facilitate the testing.
Location
Similar Tenders
Active opportunities matching this tender's categories and regions.