منافسة عامة قيد التنفيذ

مشروع تشغيل وصيانة أنظمة الحماية من المخاطر السيبرانية

وزارة العدل - الديوان العام

رقم المنافسة

210539361357

المعرّف

#225320

رقم المنافسة
210539361357
رقم المنافسة الداخلي
2021/59
الجهة الحكومية
وزارة العدل - الديوان العام
الفرع / الإدارة
إدارة المشتريات والعقود
نوع المنافسة
منافسة عامة
حالة المنافسة
طريقة تقديم العروض
رسوم الاشتراك
500 ر.س
سعر كراسة الاشتراط
2,000 ر.س
تكلفة الدعوة
200 ر.س
تكلفة الشراء
500 ر.س
الضمان الإبتدائي
الضمان النهائي
مدة العقد
التأمين مطلوب
مدة الوقفة (أيام)
داخل المملكة
التاريخ ميلادي هجري
تاريخ النشر 2021/06/24 01:05
آخر موعد للاستفسارات 2021/07/07 1442-11-27
آخر موعد تقديم العروض 2021/08/03 09:30 1442-12-24
موعد فتح العروض 2021/08/03 10:00 1442-12-24
موعد فحص العروض
التاريخ المتوقع للترسية
تاريخ بدء الأعمال
تاريخ خطاب تأكيد المشاركة
بداية إرسال الأسئلة

موقع التنفيذ

منطقة التنفيذ
مدن التنفيذ

مجال التصنيف

يشمل مواد توريد
لا

جدول 1 الخدمات والمخرجات - تقنية معلومات

البند الفئة الكمية وصف البند المواصفات وحدة القياس الرقم التسلسلي منتج من القائمة الإلزامية
1 التراخيص 4 تجديد رخص نظام لفحص التطبيقات من الثغرات الامنية • مراقبة الكود بشكل آلي • دعم عدد لامحدود للنطاقات • التوافقية والتكاملية مع أنظمة الوزارة مثل أنظمة الفحص والمراقبة الأخرى وأنظمة متابعة التذاكر بحيث يمكن دفع النتائج على هيئة تذاكر يمكن متابعتها وإدارة تدفقها. • يوفر الحل اختبار امن التطبيقات بشكل ديناميكي – دوري • يوفر الحل اختبار امن التطبيقات بشكل ثابت • يوفر الحل اختبار امن تطبيقات الجوال والأجهزة اللوحية وعميل المتصفحات • يوفر الحل اختبار امن التطبيقات بشكل ثابت اثناء تطويره في السحابة وبالتكامل مع مسار التكامل المستمر والتسليم المستمر (DevOps/DevSecOps CI/CD Pipeline ) المستخدمة في الوزارة • يوفر الحل اختبار امن واجهة برمجة التطبيقات بشكل ديناميكي وثابت بشكل فعال عبر معرفة هيكلة البيانات للطلبات والردود واجراء الاختبارات اللازمة لواجهة برمجة التطبيقات بمختلف تعريفاتها (Rest API, OpenAPI[OAS]/Swagger, RAML, SOAP, WSDL, WADL,API Blueprint ) • يوفر الحل التكامل مع دورة حياة تطوير التطبيقات • يوفر الحل السرعة والكفاءة والدقة في الفحص واستخراج النتائج • يوفر الحل تحليل تكوين البرمجيات Software Composition Analysis • يحتوي الحل على واجهة تطبيق ويب • واجهة الويب مبنية من عدة طبقات (العرض التقديمي والتطبيقات و قاعدة البيانات) • يقدم الحل تقرير مفصل يتضمن شرح متعمق للنتائج و طرق تنفيذها وتوصيات المعالجة بعدة امتدادات: .pdf, .cvs, .xsls • مرونة الحل عن طريق توفير عمل تقارير بالشكل المفصل والملائم للوزارة • يوفر الحل مستويات مختلفة من التقارير المناسبة، على سبيل المثال، تقارير خاصة بالمطورين، تقارير خاصة بالإداريين والتنفيذيين، ..الخ. • يوفر الحل عرض التقارير باستخدام المعايير الأمنية المعترف بها عالمياً مثل: CWE OWASP Top 10, SANS Top 25, • يوفر الحل عرض تجميعي للنتائج وتحليلي وتفصيلي لأكثر التطبيقات خطورة وأكثر الثغرات تكراراً مع توفير رسوم بيانية لتحليلات النتائج • قدرة الحل على ربط النتائج الخاصة باختبار امن التطبيقات بمختلف مصادرها التي تم ذكرها بعاليه بنوعيها (الديناميكي الدوري والثابت) في لوحة تحكم واحدة • قدرة الحل على توفير خادم مركزي واحد يجمع كل القوانين، والسياسات، والنتائج وحلولها الخاصة بأمن التطبيقات • قدرة الحل على تحديد التطبيقات المتوافقة مع سياسات الوزارة ومعايير الأمن العالمية • إمكانية تصنيف النتائج حسب الأولوية ومعدل الخطورة • إمكانية ربط كل من النتائج الخاصة باختبار امن التطبيقات الديناميكي الدوري والثابت • لوحة التحكم المركزية الخاصة بالحل قادرة على استيعاب النتائج والثغرات الأمنية من حلول أخرى وربطها مع التطبيقات ذات العلاقة • يدعم الحل أنواع التوثيق و المصادقة المعقدة التالية: Basic NTLM, Form-Based, Kerberos, Client-side Certificate, Captcha, Single-Sign-On, OAuth(ALL), Tokens, Multi-Factor-Authentication • قدرة الحل على تخطي أنواع المصادقة المعقدة التالية عند فحص التطبيقات: Basic NTLM, Form-Based, Kerberos, Client-side Certificate, Captcha, Single-Sign-On, OAuth(ALL), Tokens, Multi-Factor-Authentication • قدرة الحل على فحص التطبيقات ذات الصفحة الواحدة Single Page • قدرة الحل على فحص تطبيقات الجوال والأجهزة اللوحية ديناميكياً و بشكل ثابت للأندرويد وال iOS • قدرة الحل على اكتشاف البرامج الضارة والفيروسات في نفس التطبيق • استمرار الزحف داخل الموقع او التطبيق لتحديد التغيرات ثم اجراء تحليل كامل • مرونة الحل بحيث يمكن للوزارة من تحديد وتطبيق سياسات البرمجة الآمنة الخاصة بها • قدرة الحل على تكرار الهجمات لاعادة الاختبار لاثبات النتيجة • قدرة الحل لاجراء الاختبار ضد المعايير الأمنية المعترف بها مثل OWASP • توفير الحل القدرة على إيقاف عملية الفحص، وتعديل الفحص واستئناف الاختبار في الوضع التفاعلي • توفير الحل القدرة على انشاء تنبيهات وتذاكر للثغرات المكتشفة وارسالها عبر البريد الالكتروني لملاك التطبيق • يدعم الحل تعريف مستويات لمعالجة الثغرات وآليات التصعيد للثغرات الغير معالجة إلى المسؤولين • يدعم الحل العمل المؤتمت بتحديد الوقت والتاريخ والمستهدفات ومتغيرات الفحص ويدعم الارسال المؤتمت للنتائج • يوفر الحل نتائج دقيقة تصل إلى 98% من الصحة ويقلل نسبة النتائج الموجبة الخاطئة (False positive) • يدعم الحل إعادة الفحص الآلي والمؤتمت للتأكد من إغلاق ومعالجة الثغرات عبر استشعار حالة التذاكر التي تم دفعها (أي عند اغلاق التذكرة من قبل المسؤول تقوم الأداة بعمل إعادة فحص آلي للتأكد من الإغلاق بشكل صحيح وارسال النتيجة للمسؤول واغلاق التذكرة). • يدعم الحل الاحتفاظ بالنتائج لمدة سنة بشكل تجميعي بحيث يمكن الرجوع لأي نتيجة فحص في أي وقت من العام دون الحاجة لاستخراج التقارير والاحتفاظ بها يدوياً. • الحل يدعم كل اللغات التالية: C/C++/C#, COBOL,ColdFusion, Java(including support for Android APIs), JavaServer Pages (JSP), JavaScript, Perl, PHP, PL/SQL, T-SQL, .NET(C#, ASP.NET, VB.NET)- Microsoft .NET Framework, ASP (JavaScript/VBScript), Visual Basic, Objective-C in Xcode projects and workspaces, Apache Struts1 and 2, Spring MVC 2.5 and 3, ASP.NET MVC (Windows only), Enterprise JavaBeans (EJB), ASP.NET (Windows only), Jax- RS(v1.0 and higher), Jax- ws(v2.2 and higher) • يجب ان يكون النظام مترجم شامل قادر على ترجمة التكنولوجيا الجديدة، مثل أجاكس، و HTML5، و JSON و التي يتم استخدامها في الويب والموبايل الحالية • يدعم الحل تحديث قاعدة بيانات الثغرات بشكل تلقائي بأحدث الثغرات الجديدة ودرجات خطورتها. • يجب أن يدعم الحل التطبيقات غير محدودة الهدف مع تضمنه رخصة الاشتراك وتوفير الدعم الفوري والتفاعلي والصيانة والتدريب لمدة ثلاث سنوات مستخدم 1 0
2 التراخيص 10000 تجديد رخص نظام لإدارة مواطن الضعف والكشف عن الثغرات الأمنية بالشبكة تجديد الرخص لنظام Tenable.sc لعدد ١٠٠٠٠ (عشرة آلاف هدف) لمدة ثلاث سنوات نهاية طرفية 2 0
3 التراخيص 10000 تجديد رخص نظام تقييم ومراجعة التهيئة والإعدادات تجديد الرخص لنظام Tenable.sc لعدد ١٠٠٠٠ (عشرة آلاف هدف) لمدة ثلاث سنوات نهاية طرفية 3 0
4 التراخيص 200 تجديد رخص نظام لفحص التطبيقات من الثغرات الامنية Acunetix تجديد الرخص لنظام فحص التطبيقات Acunetix Premium لعدد ٢٠٠ هدف لمدة ثلاث سنوات نهاية طرفية 4 0
1 الضمانات والدعم 1 تجديد عقد الضمانات والدعم الفني لنظام لفحص التطبيقات من الثغرات الامنية تجديد عقد الضمانات والدعم الفني لنظام لفحص التطبيقات من الثغرات الامنية عقد ضمان 6 0
2 الضمانات والدعم 1 تجديد عقد الضمانات والدعم الفني لنظام لإدارة مواطن الضعف والكشف عن الثغرات الأمنية بالشبكة تجديد عقد الضمانات والدعم الفني لنظام لإدارة مواطن الضعف والكشف عن الثغرات الأمنية بالشبكة عقد ضمان 7 0
3 الضمانات والدعم 1 تجديد عقد الضمانات والدعم الفني لنظام تقييم ومراجعة التهيئة والإعدادات تجديد عقد الضمانات والدعم الفني لنظام تقييم ومراجعة التهيئة والإعدادات عقد ضمان 8 0
4 الضمانات والدعم 1 تجديد عقد الضمانات والدعم الفني نظام لفحص التطبيقات من الثغرات الامنية Acunetix تجديد عقد الضمانات والدعم الفني نظام لفحص التطبيقات من الثغرات الامنية Acunetix عقد ضمان 9 0
5 الضمانات والدعم 1 تجديد عقد الضمانات والدعم الفني لنظام المتقدم للكشف وتحليل المخاطر الأمنية تجديد عقد الضمانات والدعم الفني لنظام المتقدم للكشف وتحليل المخاطر الأمنية عقد ضمان 10 0
1 الخدمات 30000 خدمة توثيق أسماء نطاق البريد الالكتروني تسعى وزارة العدل إلى حماية نطاق البريد الالكتروني الخاص بها من الاحتيال ومراقبة مراسلات البريد الالكتروني والحصول على معلومات استخباراتية. وذلك لاستقبال تقارير التحقيق المفصلة والتقارير اليومية وتخزينها وتحليلها. نطاق العمل: مراقبة وحماية نطاقة البريد الالكتروني وذلك بتفعيل بروتوكول DMARC و SPFو DKIM من أجل الحد من انتحال النطاقات الخاصة بالوزارة وذلك عبر خدمة مدارة تعمل من خلال مزود خدمة داخل المملكة. المواصفات الفنية للخدمة: - DMARC Monitoring and Protection for 1 Active Domain which is involved in sending emails through an automated platform. - DMARC Monitoring and Protection for Unlimited Subdomains. - DMARC Monitoring and Protection for unlimited inactive domains (parked, defensive, and any domain that is not involved in sending emails). - Automatic detection of subdomains. - Establishing a DMARC policy of p=reject - Setting up SPF/DKIM DNS records and ensuring the optimization of the same - Aligning Email Sending sources to send SPF, DKIM and DMARC compliant emails. - Dashboards that display: - DMARC trend charts – The platform should depict Day-on-Day / Month-on-Month DMARC alignment effectiveness graphs. - SPF/DKIM compliance statistics - DMARC compliance status for each monitored domain - Overview of malicious IPs sending emails on behalf of the domain. - Overview of top IPs sending emails on behalf of a domain. - Detailed DMARC reporting views with the following filters (pass, not aligned pass, fail): - Sender-wise view - Results-wise view - Host-wise view - Reporter-wise view - Country-wise view - DMARC forensic reports with PGP encryption support - Browsable DMARC forensic report email headers (if any) along with CSV export capability - Geo-map visualization of failing sending sources. - Sending IP details that includes at a minimum: - Geographical location of the IP (locality, City and Country of the mail sender IP address) - IP blacklisting information - Whois, Abuse, ASN information - FCRDNS - Export as PDF capability - The platform should allow reports and IP information to be exported out of the portal as a formatted PDF. - Automated mail based daily, weekly & monthly compliance & failure PDF reports. - Role based user management functionality: - The platform should allow the organization to self-enroll users with role-based access restrictions (View / super user) - Domain management functionality - The platform should allow the organization to self-enroll mail domains for monitoring. - DNS record setup assistance: - The platform should provide self-guided tools for assisting error-free creation of SPF / DKIM / DMARC records - DNS query tools: The platform should provide tools for querying the current SPF / DKIM / DMARC records - The platform should provide real time email alerts for Forensics (RUF), DNS Errors and set different thresholds by email. - The Platform should support Hosted MTA-STS / TLS-RPT Aggregation Reports - The Platform should provide Hosted BIMI Authentication Service - The Platform should be hosted in local cloud within the kingdom. مدة المشروع: 3 سنوات Objectives: 1. The purpose of this RFP is to obtain a Domain-Based Message Authentication, Reporting and Conformance (DMARC) service. 2. 2.1.2. Detect any other email sending services from said domains and subdomains and report them to each respective organization. 2.1.3. Define with each organization the criteria for authentic emails and their sources. 2.1.4. Define with each organization a White-List of IP addresses for email sending services prior to implementation. 2.2. Implementation 2.2.1. Set up email addresses with each organization to receive DMARC reports. 2.2.2. Provide DMARC portal access to nominated organization personnel and train them. 2.2.3. Work with each organization to achieve automatic rejection of emails that do not comply with items. 2.2.5. Assist organization personnel in the development of necessary PGP Keys to ensure privacy of forensic mail. 2.2.6. Sharing of Email headers to be potentially used for Forensic Analysis. 2.3. Post Implementation 2.3.1. Provide alerts on abusive IPs & domains and recommend actions to be performed by organization personnel. 2.3.2. Monitoring and update of DMARC policy to clear false positives and false negatives. 2.4. Administration 2.4.1. Update DMARC policy to add/remove domains/subdomains. 2.4.3. Work with respective organization personnel to move DMARC Policy from MONITOR to QUARANTINE to REJECT. 2.4.4. Perform forensic analysis of reported/marked emails by organization personnel. 2.5. Reporting 2.5.1. Configure reports to be sent to email addresses identified in on daily and weekly basis. 2.5.2. Weekly, monthly, quarterly and yearly organization reports that can be generated on demand basis. 2.6. Standard SLA 2.6.1. Standard 8x5 email support مستخدم 11 0
2 الخدمات 36 خدمة استقصاء التهديدات الالكترونية 36 شهر يجب أن يقوم المورد بتقديم خدمات استباقية للتنبيه بالمخاطر السيبرانية بشكل مباشر وفوري وذلك لرفع كفاءة ومستوى الأمن السيبراني في الوزارة. كما يجب الاستعانة بمركز بالمصادر السيبرانية المفتوحة وغيرها وتقدم من خلال فريق بحثي متخصص ومتعمق في مجال الأمان والمكافحة الذكية للتهديدات السيبرانية على أن يقدم ما يلي: - فهم عميق للمصادر التهديدات السيبرانية وتحليلها ودمج المصادر السيبرانية . - إجراء التحقيقات والتحليلات للتهديدات السيبرانية من خلال منصة خاصة بالمورد متوافقة مع تشريعات ومتطلبات الهيئة الوطنية للأمن السيبرانية - إعدادا التقارير المعلومات الاستباقية على عدة مستويات (استراتيجية، تخطيطه، تشغيلية، تقنية) بشكل دوري - إقامة دورات تدريبية وورش العمل لفريق الوزارة لعدد 6 موظفين وذلك في فهم المعلومات الاستباقية وطريقة تحليلها. Machine to Machine Intelligence Ingestion • The platform should support various structured and unstructured Threat Intelligence feed formats gathered from a combination of Commercial, Open source, User-led, and Community-driven Intel sharing sources and also provide complete advisory of threats to enable the organization to plan countermeasures for taking proactive actions. • The platform should be capable of integrating with existing internal security/network devices such as SIEM, IDS, IPS, Anti-APT solution, Firewall, UEBA, etc., to gather internal Intelligence. • The platform should support all the STIX 2.0 objects out of the box and any feed ingested should be converted to STIX objects • The platform should have capabilities to add custom STIX objects compliant with STIX 2.0 and STIX 1.x. • The platform should have capabilities to perform automated IOC extraction from imported attachments like PDF, Excel, Word, PDF, etc. • The platform should have capabilities to perform automated IOC extraction from external URL inputed by TI analyst. • The platform should have capabilities to perform automated IOC extraction and parsing from external RSS feeds. • The platform should support STIX inbox capabilities to receive TI in Realtime from other TAXII servers of private community or ISAC's • The platform should support configuration of multiple mailboxes to fetch the TI in real-time as well as on-demand • The platform should have capabilities to perform Email deep search for IOC • The platform should support data types like STIX Objects, JSON, card data, IBANS, contacts, emails, etc. • The platform should support automated IOC ingestion from Email boxes. • The platform should have capabilities to harness Intel data from internal tools like SIEM, honeypot, etc. • Feeds and IOC • The platform should support open standard formats like CyboX, OpenIOC, Yara, STIX 1.0, STIX 2.0, MISP, XML, CSV, JSON, MAEC, IODEF etc. • The platform should support advisories from partners like Visa, Swift, and other payment platforms. • The platform should support custom indicators like IBAN, Credit cards, Mobile numbers, and national ID numbers. • The platform should also be capable of supporting unstructured formats such as email, news, RSS Feeds, blogs, Free text etc. and should be capable of automatically normalizing it. • The platform should be able to support reliable, actionable feeds for: a. IP Addresses b. Domain Names c. Hashes d. E-Mails e. File Names f. Blacklists g. Malware Indicators h. ASN i. Mutex j. Win Registry Key k. Port l. HTTP Session Object m. User-Agent • The platform should have custom indicator attributes which can be shared with subsidiaries. • The platform must ensure that apart from other relevant elements, the following elements are included in the IOC: i. Source information (IP, Domain, URL etc.) ii. File formats (.exe, .doc, .pdf, .xml etc.) iii. Geo Location iv. File hash values v. Vulnerability details • The platform should have the ability to import and export Intel feeds in popular consumable formats such as XML, JSON, CSV, etc. • The platform should present the imported feeds in a graphical, searchable, sortable and reportable format in the platform itself. • The platform should be able to consume the Strategic Threat Intel feeds from other platforms. • The platform should have capabilities to create custom strategic unstructured Threat Intel and have option to share it with private community. • The platform should allow to create custom watchlist for any data ingested within the platform and trigger alerts on match • The platform should support managing the Threat actor data and also allow comparing the threat actos with each other • The platform should support automated relations between the TI data reported as well as option to manually create relations Enrichment and Normalization • The platform should be able to perform Normalization - Consolidating data across different sources formats. • The platform should be able to do De-Duplication - Removal of duplicate information. • The platform should perform enrichment - removal of false positives, scoring of indicators, and the addition of context when multiple feeds are fed into it. • The platform must provide additional information on IOCs, wherever requested, by integrating with WHOIS, Virus total, Shodan, Hybrid Analysis etc. • The platform should support scoring of feeds or IOC to ensure only relevant feeds are worked upon by the analyst. • The platform should have tight integration with MITRE ATT&CK navigator for Tactical Threat Intelligence harnessing and analysis. It should further facilitate custom technique creation option, custom threat actor creation option etc. • The platform should be able to provide latest threat advisories in a searchable manner based on geography, threat actors, IoC etc., to obtain the information about Tactics, Techniques and Procedures (TTPs). • The platform should be capable of doing contextual analysis of Intelligence wherein it helps in highlighting organization relevant Threat Intel based on custom parameters like location, industry etc. • The platform should include complete threat visibility i.e. End-to-end details of threats such as attack surface vulnerabilities, malware, IOCs, actors behind the attacks, tools, tactics and procedures used, motivation etc. • The platform should be capable of mapping the ingested IOC to the TTP. • The platform should be capable of mapping the TTP to APT Groups to zero down the APT groups targeting the organization. • The platform should have advanced automation rules to support analysts in mundane tasks such as filtering IOC, relevant feeds, blocking of IPs on the firewall etc. • The platform should support ML-based automated correlation between various objects of the received Threat Intel. • The platform must be capable of identifying new, potential typo squatting domains. • The platform should have the capability to set expiration for TLP: RED STIX packages for secure transfer and handling of valuable tactical threat information. • The platform should support automated indicator deprecation, in which the indicator gets expired after the decided time-span. The platform should also have an option to auto unblock IOC on deprecation. • The platform should allow the analyst to mark the severity and risk, track and add comment/notes for the indicators. • The platform should support interactive analysis with help of notes/ comments which can be shared with other analysts. • The platform should have capabilities to automatically harness the critical IOC and map it back to MITRE ATT&CK navigator relevant TTP. • The platform should have capabilities to perform Custom scoring based on parameters like source weightage, source score, etc. • The platform should be able to weed out False positives. • The platform should have an unde review option for analyst convenience. • The platform should have analysts task tracking feature. • The Platform should support whitelisting of internal IOCs such as IP, URLs to ensure that they are not flagged as malicious. Reporting and Governance • It should provide capability to create articles and export advisories/articles in PDF with auto mail notification. • The platform should have a feature to auto generate Executive Reports for higher management. • The reports should provide Adversary Intelligence with info on threat actors, TTPs, incidents and campaigns. • The reports generated in the platform should provide Technical Intelligence on Vulnerabilities, Network, Security Risk/ Malware Files etc. • The platform should support Multi-level Intel view from actioning perspective for different roles in the organization such as Analysts, SOC/IR Teams, Steering Committees and CISO. • The platform should have advanced auditable logs which show each and every individual’s log such as users, subscriber, polled sources with the data received etc., and a tab of all the input and output data flow. • The platform should provide features to measure ROI of Threat Intel operations such as the amount of data ingested, acted upon, and disseminated. It should make it possible for the executives to measure the entire ROI of the procedure. Threat Intelligence Sharing/ Collaboration • The platform must support Threat Intelligence sharing format/protocols such as STIX/TAXII. • The platform should allow sharing and receiving of Strategic Threat Intelligence. • The platform should allow sharing and receiving of Tactical Threat Intelligence. • The platform should allow sharing and receiving of Technical Threat Intelligence. • The platform should support sharing real-time enriched and analyzed Threat Intel with peers, subsidiaries, third parties, regulators etc. • The platform should facilitate two-way Intelligence transmission with organizations like ISACs, CERTs etc. Access Control and Authentication • The platform should support two-factor authentication. • The platform should have Role-based Access Control to support different level of roles. • The roles should be customizable with customizable permissions and access. Support for Multi Tenancy • The platform should be able to support smooth multi-geography implementation ensuring multi-tenancy is achieved without hassle. • The platform must preferably have a light version for multi-tenancy use cases for operations across different countries. • The platform must have stringent Access Control to ensure different tenants can be managed individually. خدمة 12 0
3 الخدمات 400 خدمات اختبار الاختراق ( لمدة سريان المشروع 36 شهراً) نطاق عمل المشروع نظرا لتزايد الهجمات السيبرانية في الأونة الأخيرة والتي تستهدف بشكل كبير القطاع الحكومي، فإن وزارة العدل تسعى إلي إجراء تقييم للبنية التحتية للوزارة عن طريق إجراء استشارة في اختبار اختراق تفصيلي بهدف اكتشاف الثغرات ونقاط الضعف والعمل على حلها مما سيساعد في ضمان امان وتوافر ونزاهة بنية تكنولوجيا المعلومات. وخلق بيئة معلوماتية آمنة تعالج وتتصدى للتحديات الأمنية. • ان تكون الشركة لها أكثر 3 سنوات خبره في مجال تقديم هذا النوع من الاستشارات • فريق عمل الشركة قام باكتشاف عدد لا يقل عن 50 عن Vulnerability Day Zero • ويفضل ان تكون قامت باكتشاف أكثر من 100 مع تقديم الأدلة • فريق عمل المنفذ الاستشارات حاصل على الشهادة التالية على الأقل OSCP, OSCE, OSWP, SANS GREM, CISSP, CCSP • يجب أن تكون الشركة حاصلة على شهادة ISO 27001 تقييم الثغرات واختبار الاختراق يجب على مقدم خدمات الاستشارة تحديد نقاط الضعف والتهديدات على الشبكة من الخارج والداخل وفق منهجية واضحة ذات مقاييس عالمية. كما يجب على مقدم الاستشارة أن يقوم بإخضاع جميع الخوادم وأجهزة ومعدات الشبكات التي يمكن الوصول إليها خارجيا إلى اختبار الصندوق الأسود والأبيض Black and white box penetration testing بشكل دقيق، وذلك باستخدام عدد من الأدوات وكذلك الاختبارات اليدوية لإمكانية استغلال الثغرات باستخدام منهجيات مختلفة. على افتراض أن هوية المهاجم الخارجي غير موثق بها وليس له صلاحيات للدخول الأنظمة. ومن ثم تقوم المقاول المنفذ للمشروع بتقديم تقرير مفصل عن تحليل الفجوات والثغرات وكذلك تقديم الاقتراحات لتفادي المشاكل الحالية إن وجدت والمشاكل المتوقعة. ويجب أن يتم إجراء اختبار الاختراق مع الحفاظ على مستوى مقبول من المخاطر على الأنظمة والشبكات داخل الوزارة ويجب أن يسلط الضوء على النقاط التالية: • معرفة الأجزاء الهامة من الأنظمة التي يجب تفحصها واختبارهاsurface Attack. • الجهد والوقت الذي سيبذله المهاجم لتدمير الخدمات العامة How easy it is break into public services. • مستوى التطور التقني لدى المهاجم للنجاح في عملية الاختراق • مدى قدرة أنظمة الحماية الموجودة في الوزارة على اكتشاف ومواجهة الاختراق. وعليه فإن اختبار الاختراق يجب أن يشمل – ولا يقتصر على -النقاط التالية: • الاستعلام عن DNS ، WHOIS ،وغيرها من المعلومات المتاحة للعامة. • سرد مكونات الأنظمة: فحص عناوين البريد الإلكتروني، رسائل البريد الإلكتروني. وكذلك التحقق من الاستفسارات والردود للبروتوكولات UDP،TCP ، ICMP . • اكتشاف الأجهزة النشطة وتحدد مسارات الربط الشبكي وتحديد بنية الشبكة. • تحديد المنافذ والخدمات التي تعمل عليها. • إجراء مسح شامل لنقاط الضعف على كافة الأجهزة التي تخدم في طبقة الشبكات 3 و4 (Layer 3, 4). • محاولة اجتياز أجهزة جدران الحماية. • محاولة اجتياز أنظمة حماية البريد الإلكتروني يشمل محاكات الفيروسات إلى وحفظها في أجهزة داخل الوزارة. • محاولة الحصول على كلمات المرور الخاصة بمدراء النظام من خلال اجتياز النظام او عمل تصيد الكتروني لمدراء الأنظمة. • تقييم نقاط الضعف على الخوادم. • محاولة الحصول لأنظمة التحكم بمركز البيانات الرئيسي على سبيل المثال نظام التحكم بالأبواب، ونظام التكييف، والكمرات، وأجهزة مراقبة الحرارة. • عمل محاكاة اختراق من خلال استخدام جهاز داخل الوزارة: -كسر حماية الجهاز وتحميل برامج. - اجتياز مكافح الفيروسات. -الحصول على كلمة المرور الخاصة بمسؤول النظام. - محاولة الوصول للأنظمة داخلياً. - محاولة الوصول لملف المشاركة والوصول لملفات بطريقة غير مخولة. - محاولة الحصول على مخطط الشبكة الإلكتروني. • محاولة الدخول من أجهزة خارجية إلى داخل الوزارة والوصل للأنظمة والخدمات الداخلية من خلال الشبكة السلكية واللاسلكية. • إجراء اختبار أمني على مستوى الخوادم يتضمن ولا يقتصر على : - Application and service configuration - Authentication - Access Control and System Hardening • البحث عن كلمات المرور الضعيفة باستخدام الأدوات المخصصة لذلك. • الحصول على دلائل لكلمة المرور (hashes )من الأجهزة التي يمكن أن تستخدم للوصول إلى أنظمة أخرى. • عمل تصعيد لصلاحيات الحسابات التي تم الحصول عليها للوصول إلى أنظمة تشغيل الخادم. • تصعيد مستوى authorization من الحسابات التي يتم الوصول إليها للوصول إلى حسابات المدراء. • استخدام الأساليب الغير مشروعه المتبعة من قبل المهاجمين لجمع المعلومات مثل الهندسة الاجتماعية Social Engineering وغيرها في عمليات الاختبارات. • محاولة الحصول على كلمات المرور الخاصة بحسابات التواصل الاجتماعي الخاصة بالوزارة تويتر، وإنستغرام، وفيس بوك، ويوتيوب، ولينكدن. على الجهة الاستشارية تقديم تقرير مفصل في والأدلة والبراهين على كل جزء من نطاق الخدمة الاستشارية في تقييم الثغرات واختبارات الاختراق كل مرة كما تحتوي على سبيل المثال لا الحصر: • تقرير مفصل على عملية الحصول على كلمة مرور مسؤول النظام مع الإثباتات. • تقرير مفصل لجميع الثغرات والأنظمة وآلية معالجتها. • تقرير مفصل محاكاة اختراق جهاز داخل الوزارة مع الإثباتات. • تقرير مفصل عن تصعيد مستوى الصلاحيات مع الإثباتات. • تقرير مفصل عن الحصول على انظمة التحكم بمركز المعلومات. • تقرير مفصل عن الحصول على دلائل لكلمات المرور. • تقرير عن كلمات المرور الضعيفة ساعة / خلال مدة المشروع 13 0

12 بند

كراسة الشروط الرئيسية

كراسة الشروط والمواصفات وملاحق المنافسة

2.0 MB تم التحميل

2021/225320/main_booklet_كراسة_الشروط.html

فتح

المستندات الداعمة (1 ملف)

الحماية من المخاطر السيبرانية.zip

3.5 MB تم التحميل

2021/225320/idd_F1C0C4A8-EBEF-C2EC-8507-79C679100000_الحماية_من_المخاطر_السيبرانية.zip

فتح

لم يتم ترسية هذه المنافسة بعد

لا توجد بيانات للمحتوى المحلي

معايير التقييم

لا توجد معايير تقييم

أخبار المنافسة

لا توجد أخبار