ICT Certification and Accreditation documents creation, review and update
Tender ID: 536249
Tender Details
Tender Description
This Tender is invited by the Issuer.
Deliver Professional and technical ICT services to the Commonwealth
The supplier must provide professional and qualified security consultants that are able to understand the requirements and produce highly technical documentation based on the complexity of each facility MOSSPO manages.
The deliverables must be fit for the following purpose(s):
- Assist in the Certification and Accreditation of the following ranges MOSSPO manages:
- Multi-Influence Range (MIR)
- Jervis Bay Telemetry Range (JBTR)
- Mobile Missile Telemetry Range (MMTR)
- Align with the Information Security Manual (ISM).
- Align with the Defence Security Principal Framework (DSPF)
To achieve Cyberworthiness certification and accreditation, ICTSB requires specific documentation that needs to be produced for each facility we mange that has been listed above. The list of documentation that will form each deliverable includes:
- Australian Cyber Security Centre Essentials 8 (ASCS 8) Statement of Applicability (SoA) System Security Plan (SSP) System Overview Document (SOD) Incident Response Plan (IRP) Security Risk Management Plan (SRMP) Detailed Design Document Risk Register Business Impact Level (BIL) Standard Operating Procedures (SOP) as required
- Australian Cyber Security Centre Essentials 8 (ASCS 8)
- Statement of Applicability (SoA)
- System Security Plan (SSP)
- System Overview Document (SOD)
- Incident Response Plan (IRP)
- Security Risk Management Plan (SRMP)
- Detailed Design Document
- Risk Register
- Business Impact Level (BIL)
- Standard Operating Procedures (SOP) as required
Depending on the complexity of each facility, the supplier will have to determine how many documents will be required for each facility. Some basic facilities might only require 2-3 documents whilst other complex facilities may require all the documents to achieve certification depending on the classification of information held on their respective ICT Systems.
Recommended Qualifications
The following skill sets and or qualifications are highly desirable:
- Endorsed IRAP Assessor
- Two or more of the following certifications:
- Certified Industry System Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- ISO 27001 Lead Auditor
- Global Information Assurance Certification (GIAC)
- Global Information Assurance Certification Forensic Analyst (GCFA)
- Certified Information Systems Auditor (CISA)
- Recent experience in security assessments of ICT Systems.
As part of any outsourcing arrangement, the Director IRM is required to validate the skills/qualifications and suitability of the proposed Industry Security Professional (ISP) prior to any individual being engaged.