Support Environment Audit and Uplift Activities
Tender ID: 583975
Tender Details
Tender Description
This Tender is invited by the Issuer.
Australian Submarine Agency’s (ASA) Information Control Branch (ICB) has developed a system utilising VMware by Broadcom technologies. VMware by Broadcom released a significant set of uplift and security patches to the software base that underpins the system.
The system uses customised code templates and extensions to provide the functionality and security controls, such customised code is particularly susceptible to changes resulting from patching.
- Perform audit and regression testing of the system
- Environment Assessment
- Security and Compliance Assessment
- Documentation uplift
- Required documentation for the system. Specifically, Uplift of the existing document suite to ensure the IT environment is well-documented, secure, and aligned with best practices by assessing platform health, refining architecture documentation, and supporting security documentation development in preparation for Accreditation.
- Ensure the IT infrastructure is operating at optimal performance, security, and reliability by assessing system health, identifying lifecycle management gaps, and implementing necessary updates and configuration changes.
- Ensure the IT infrastructure remains secure, stable, and optimised by assessing system health, identifying lifecycle gaps, and applying necessary updates to maintain compliance and performance.
- Support relevant project governance forums, e.g. Project Board / Project Team slide packs.
- Support ICB to ensure project delivery is meeting timelines and user requirements effectively.
- All applicable documents and artefacts required by ICB, ASA and Defence policies at the appropriate stages. These documents are to be drafted and consulted to relevant representatives.
- Provide specialist advice to representatives, to ensure solution options will be designed for user’s needs, and to realise whole system capability benefits for ASA.
- Ensure compliance of the system against the Australian Cyber Security Centre (ACSC) Information Security Manual (ISM) and Defence Security Policy Framework (DSPF)
- Ensure all software and hardware security advisories are advised. Certify patches are compatible with the system and remediated accordingly.
- Provide input and draft the documentation and activities that are conducted by the ICB for system delivery, including:
- Security and architecture documentation: provide analysis of the system and development of a System Security Plan (SSP), Solution Engineering Description (SED), As Built As Configured (ABAC), and other required security documentation as directed in line with the ISM and the DSPF.
- Participate in briefings to senior officials as required.
- Respond to any planning or documentation changes which may arise
- Other tasks arising out of project governance and stakeholder engagement at the discretion of the CoA Task Manager.
Title
| Skill set
| AGSVA Security Clearance Level
|
Project Manager | Project Management Services and Support | NV1 |
Senior ICT Architect | -Virtualisation (VMware Cloud Foundation Technologies)
| NV1 |
Multiple ICT Consultants
| -Virtualisation (VMware Cloud Foundation Technologies)
-Private Cloud Technologies -HPE rack mount hardware -Cisco hardware and software -Microsoft Software -Linux Software | NV1 |
Evaluation Criteria:
ICB will evaluate the Panel Member response against the following criteria:
1. Panel Member’s proposed approach to the delivery of the Services.
2. Panel Member’s knowledge of the critical requirements of the Services to be provided.
3. Panel Member’s demonstrated previous or similar experience and qualifications of proposed personnel.
4. Panel Member’s costing estimates and pricing structure.
Respondents should provide details of ICT architectural and documentation services previously provided, together with names and contact details of referees.
An understanding of the ISM and DPSF is required. Where applicable, and with the direction of a CoA Task Manager, ICB is to engage with relevant Defence and external stakeholders for completing the task.