منافسة عامة
✓ مرسّى
تجديد رخص نظام مضاد الفيروسات ونظام الكشف والاستجابة للتهديدات الأمنية وحماية خوادم البريد الإلكتروني لديوان المظالم 2021 م
ديوان المظالم
رقم المنافسة
210639371752
المعرّف
#234738
عنوان الضمان الإبتدائى
6565 طريق الملك خالد حي جامعة الملك سعود الرياض 12371 2999
الغرض من المنافسة
تجديد رخص نظام مضاد الفيروسات ونظام الكشف والاستجابة للتهديدات الأمنية وحماية خوادم البريد الإلكتروني لديوان المظالم على النظام الحالي.
| التاريخ | ميلادي | هجري |
|---|---|---|
| تاريخ النشر | 2021/06/14 11:54 | — |
| آخر موعد للاستفسارات | 2021/06/25 | 1442-11-15 |
| آخر موعد تقديم العروض | 2021/06/30 10:00 | 1442-11-20 |
| موعد فتح العروض | 2021/06/30 11:00 | 1442-11-20 |
| موعد فحص العروض | — | — |
| التاريخ المتوقع للترسية | 2021/09/27 | 1443-02-20 |
| تاريخ بدء الأعمال | 2021/10/04 | 1443-02-27 |
| تاريخ خطاب تأكيد المشاركة | — | — |
| بداية إرسال الأسئلة | 2021/06/29 | 1442-11-19 |
| أقصى مدة للإجابة | 5 يوم | |
| مكان فتح العروض | منصة اعتماد | |
| مدة الوقفة | 5 يوم |
موقع التنفيذ
مجال التصنيف
الأنشطة
- • تقنية المعلومات
وصف المنافسة
تجديد رخص نظام مضاد الفيروسات ونظام الكشف والاستجابة للتهديدات الأمنية وحماية خوادم البريد الإلكتروني لديوان المظالم على النظام الحالي.
جدول 1 المواد - تقنية معلومات
| البند | الكمية | وصف البند | المواصفات | وحدة القياس | الرقم التسلسلي | منتج من القائمة الإلزامية |
|---|---|---|---|---|---|---|
| توريد وتركيب رخص نظام مضاد الفيروسات لجميع الأجهزة والخوادم المرتبطة بشبكة الديوان وتقديم الدعم الفني لمدة سنة واحدة | 3800 | توريد وتركيب رخص نظام مضاد الفيروسات لجميع الأجهزة والخوادم المرتبطة بشبكة الديوان وتقديم الدعم الفني لمدة سنة واحدة | The solution must provide a single management console for deployment of the antivirus protection systems, configuration of group and individual parameters for applications, timely database updates, continuous monitoring of system status and quick response to emergencies. -The solution must support high availability and clustering. -The solution must come with Arabic/English user Interface . -The solution must support secure communication between management server and endpoints. -The solution must support Role Based Access Control to the management server and the ability to assign different access levels to different users like administrator, operator, and view. -solution Vendor must be in the “leaders” quadrant of Gartner’s latest magic quadrant report. -The solution must support notification via SNMP, Email and SMS. -The solution must support authentication to allow access to central management console. -The solution must provide a single management console to manage all below products/functions: -Antimalware components, -Control components ( Application, Web and Device ) control, -Firewall and HIPS, -Server protection, -MDM and Mobile Security components, -Virtual machines protection (VMware, Hyper-V and Citrix). -The deployment of the Endpoint solution must support the following: -Remote installation from the central management server, -Remote installation from a web portal, -Deployment based on active directory, -Deployment via third party software deployment solutions, -Local installation using pre-configured package. -solution must support signature update through: -The central management server, -Network shares and portable media, -Intermediate update sources. -Solution must provide a facility to save/minimize utilization of WAN and slow network connections by allowing updates to be downloaded once to an intermediate update source in the remote location and then distribute updates locally. -The “intermediate” update source should be fully manageable from the central management server and doesn’t necessary require to be installed on Windows Server. -Solution must support below client operating systems: -Windows XP, Vista,7, 8 and 8.1,10, -Red Hat Enterprise 5.8 & 6.2 , 7 Desktop, -Fedora 16, -CentOS-6.2, -SUSE Linux Enterprise Desktop 10 SP4, -OpenSUSE Linux 12.1, -Ubuntu 10.04 & 12.04 LTS , -Mac OS X 10.10 (Yosemite), -Mac OS X 10.9 (Mavericks), -Mac OS X 10.8 (Mountain Lion). -Solution must support below Server operating systems: -Windows Srv 2003, 2008, 2008 R2, 2012, 2012 R2 , 2016including standard, enterprise, core & datacenter editions, -Windows storage server 2012, -Windows hyper-v server 2012, -Windows Server 2003, 2008, 2012, 2012 R2 Terminal Server, -Citrix Presentation Server 4.0,4.5, -Citrix XenApp 4.5, 5.0, 6.0, 6.5, -Citrix XenDesktop 7.0, 7.1, 7.5. -Solution must be able to manage all mentioned operating systems and their protection components using single management console, -solution must be able to detect following type of threats: -Viruses (including polymorphic), Worms, Trojans, Backdoors, Rootkits, Spyware, Adware Pornware, Keyloggers, Crimeware, Phishing sites and links, Zero-day vulnerabilities and other malicious and unwanted software . -Solution must support automatic detection and deployment of antivirus protection on new connected/discovered workstations. -solution must include following components in a single agent installed on the endpoint: -Antimalware, -Application, Web and Device control, -HIPS and Firewall. -Solution should support seamless migration from existing antivirus solution and should remove existing Antivirus agent while upgrading. -Comprehensive endpoint visibility which includes graphical reporting, centralized logging, and threshold alerting. -Solution should support adding/removing protection components to endpoints without full reinstallation of the agent, -Solution should support installation endpoint protection on Servers without restart. -Solution should integrate with Active Directory in terms of pulling existing structure and computers/users and apply the same on the management server. -endpoint solution must allow the following : -Manual scanning, On access scanning, On demand scanning, Compressed File Scanning, Scan Individual file , Folder and drive, Script blocking and scanning, Auto clean, Quarantine infected files, Registry guard, Buffer Overflow Protection, Instant messages (IM) scanning. -Endpoint solution should be protected with a password to prevent stopping/killing the AV process and for self-protection regardless of user authorization level on the system. -Scans both HTTP and FTP traffic against viruses and spyware or any other malware. -Solution should provide facility for external computers to connect to internal management server for policies updates and status reporting. -Solution must include a personal firewall capable of, but not limited to: -Block network activates of applications based on their categorization, Block/allow certain packets, protocol, IP addresses, Ports and traffic direction, Automatic and manual addition of network subnets and modify network activity permissions. -Solution must be able to block network attacks and report source of infection, -Solution must have a proactive approach to prevent malwares from exploiting existing vulnerabilities, -Solution must support signature based detection in addition to cloud-assisted and heuristics/behavioral detection. -The solution should have the ability to alert , clean, delete , quarantine the detected threats. -Solution should have the ability to accelerate scanning tasks skipping those objects that have not changed since the previous scan. -Can exclude specified files / folders from being scanned either in the on-access scan (real-time protection) or during on-demand scans. -Isolate infected computers in case no action has been taken against a new threat in terms of applying more strict settings, initiate full system scan, DB update and even cutting off network communication if necessary. -All detected threats (cleaned or active) must be backed up in a central location where all samples can be re-examined or restored. -Automatically scans removable drives for malware upon insertion to any endpoint. Scan should be controlled based on drive size. -Solution must be able to block the usage of USB storage devices or only allow access to whitelisted devices and allow read/write access by domain users to reduce data theft and enforce lock policies. -solution must be able to differentiate among USB storage devices, printers, mobiles and other peripherals. -Ability to block access to certain websites based on content, user and time of day User-based policies for device, web and application control. -solution should allow blocking following devices: -Bluetooth, Mobile devices, -External modems, CD/DVDs, Transferring data to mobile devise, -Solution should contains cloud integration for most up to date updates on malware and potential threats. -Solution must support blocking blacklisted applications from being launched on endpoints. Also it must. -Support blocking all applications except “whitelisted” ones. -Solution must have cloud-integrated application control component to get latest updates on applications’ rating and categories. -Solution must provide a facility to check applications listed in each cloud-based category. -Solution must have the ability to block unsigned applications and to automatically categorizes unknown applications . -Solution should have a centralized , detailed, customized, and Multiple Format Reports (on screen and on paper). -Solution must be optimized for Desktop Virtualization by: -Automatically recognizes whether an agent is on a physical or virtual machine to better target protection. -Prevents network, CPU, and storage conflicts by serializing scan and update operations per virtual server. -Ability to control and prevent scan-storming. -solution must provide real time dashboard that enables rapid troubleshooting of errors, security events and security issues; graphs and numbers enabling steps required to alert resolution. -Ability to schedule report generation and distribution via emails or save at particular location in HTML, excel and PDF formats. Report customization and filter criteria such as date and time range, specific type of attack, and end point type (server or desktop). -solution should be able to protect and manage mobile devices including, but not limited to, iOS, BlackBerry and Android. -Solution must support protection deployment via the central management server, respective market and locally. -Solution must be able to scan mobile devices for malware and other unwanted objects on-demand and on-schedule with automatic action. -Solution must be able to manage and monitor mobile devices from same console used to manage computers and servers. -Solution must provide “anti-theft” function, where lost and/or displaced devices can be located, locked and wiped remotely. -Solution must provide facility to block blacklisted applications from being launched on the mobile device. -Solution must be able to separate personal and corporate data/applications with different controls and security settings and to require a password to access corporate data. -Solution should detect and report jail breaking and rooting on mobile devices. -Solution must be able to remotely install and remove applications from iOS devices. -Solution must be able to enforce security settings on mobile devices, like password restrictions and encryption. | رخصة | 1 | 0 |
| توريد وتركيب رخص نظام الكشف والاستجابة للتهديدات الأمنية المتقدمة على أجهزة المستخدمين والخوادم مع الدعم الفني لمدة سنة واحدة | 3800 | توريد وتركيب رخص نظام الكشف والاستجابة للتهديدات الأمنية المتقدمة على أجهزة المستخدمين والخوادم مع الدعم الفني لمدة سنة واحدة | Access Control - This product shall support multitenancy with role-based access and delegated administration control - This product shall support the access of many Admin Roles and multiple Admin sessions - Policy Enforcement and Malware Control - This product shall support a cloud based intelligence platform that provides reputation feeds on files and bad hashes to make decisions - This Product shall support a single agent for both EPP & EDR - This Product shall support both preventive Static AI and Behavioral AI engines that protects from (unknown) malicious files and malicious activities in real time whether that endpoint is online or offline - This product shall detect a wide range of malware carriers such as BOT networks, Command & Control, TOR networks, etc - This product shall protect against wide classes of malicious software such as viruses, Trojans, spyware, APTs, etc. and shall categorize detected attacks - This product shall support detection of zero-day malicious file/file less attacks, ransomware attacks and adopt behavioral analysis/intelligence in carrying out detection. Remediation and or reversal to known good state of an endpoint in the event of a ransomware infection/attack - Unique ability to provide rollback & remediation of any potentially infected machines (saves our customers time) - This Product shall provide protection from Lateral Movement attacks using Behavioral AI engine that detects attacks initiated by remote devices - This product shall support a wide range of endpoints (Workstations, Servers, VDI) and across OS platforms. (Windows, Linux, Oracle, Mac OS etc.) - This product shall support the ability to build file policy filtering based on manually inputted IOC hashes and automated hash feeds from third party solutions or Open Source feeds solutions such as Virus Total, Looking glass, etc - This Product shall provide full EDR capabilities that collects and re-linked of IOCs and support a powerful interface to query, pivot, hunt with advanced query language - This Product shall provide Full response capabilities: mitigation, remediation, rollback, network quarantine, get logs, get files, device control (USB ports), FW control, Secure Remote Shell (full PowerShell on Windows, full Bash on MacOS), orchestration of 3rd party security products using APIs - Monitoring - This product shall provide customized, group-specific and predefined suspicious user activity monitoring and reporting for event and audit logs - This product shall have mechanisms/rules to detect shared administrative privileges - This Product shall provide the Visibility into SSL traffic for use in hunting operations - This Product provides Device control (USB port, and more…) - This Product provides Application and version inventory + Vulnerability/Risk assessment - Compliance - This product shall support compliance standards (ISO 27001) and shall document controls Within these standards where their products satisfactorily meets its requirement. This brief documentation should either be written in the comment section of this item or attached should it be reasonably large - High Availability - This product shall support high tolerance and resiliency during failures - This product shall detect and alert early enough, failures in either event sources (the main appliances) or its management box in which case shall not lead to temporal loss of logs - Integration - This product shall provide easy integration with Security Incidents and Events Management systems (SIEM) for real-time incident management, and shall also integrate well with network management tools - This product shall support Complete API support/interface that can integrate in both ways into other security tools with receive remote instructions from other appliances such as SIEM to take specific decisions on its behalf - This product shall support configuration at both the GUI and CLI - Performance - This product shall ensure high performance during peak hours of network transactions ensuring that endpoint performance are not impacted in any form - This product shall support collection and analysis of endpoint telemetry, such as file I/O, network connections, process execution, log-on events, or registry changes and on-demand access to current-state data from all systems - This product shall support enterprise wide for any type of file “at rest” by name or hash on demand and historical - This product shall support combined, complete but simple search queries using a combination of methods such as regular expression, fully unstructured text search, etc. simultaneously without impacting search performance - This product shall provide a very good reporting interface for viewing real-time logs and ability to generate recurring customized reports - This product shall support exporting of reports in different formats including PDF and CSV and with pre-built report templates customizable to organization's need - Scalability - This Product shall support on- premise infrastructure deployment of the Management server(s) - This product shall architecturally "scale" in larger deployments - This product shall support multi-tenancy environment with an MSSP model. - This product shall support centralizing dashboards from different tenants without breaking the multi-tenancy concept - This product shall support multi-tenancy for administration console - This product shall support distributed appliance-engine model with an appliance-based centralized log storage for distributed events - This product shall provide storage system that support segregation of log databased on tenant - This product shall have capacity to store massive amounts of both real-time and historical events long-term (say six months minimum) - This product shall support centralized administration in a geographically dispersed deployment - Virtualization - This solution shall support a virtual representation of this product in VM environment, which will enhance the daily customization test needs of customer's security research team - | رخصة | 2 | 0 |
| توريد وتفعيل رخص نظام حماية خوادم البريد الإلكتروني لمدة سنتين | 3500 | توريد وتفعيل رخص نظام حماية خوادم البريد الإلكتروني لمدة سنتين. | Antivirus scan of Exchange mail stores in background without performance impact on Exchange server - Ability to cure infected archives - Ability to protect against BEC (business email compromise) attacks by using sender authentication mechanisms such as SPF / DKIM / DMARC - Ability to detect and delete suspicious/unwonted objects: ads, information collectors, auto dialers, etc - Detection of malicious and phishing links in mail bodies - Ability to detect malware sprawl that allows to take timely measures for mail server protection hardening: ability to inform administrator via email about malware sprawl based on defined malware activity threshold - Ability to backup scanned object in reserved storage and restore it back after curing or deletion in case of false positives. Broad range of search criteria available in reserved storage - Additional protection layer through cloud based reputation services - Anomalies analyser for detection and blocking of unknown (0day) malware in packed mime parts - Scan of all email parts, including message headers (sender address, recipient addresses, etc.), mime parts and message size - Mail filtering and filter exclusions of messages based on sender address (as well as its IP address) presence in own white and black lists - Check sender IP address in DNS-based real-time blackhole list (DNSBL) - Check addresses and links via SPAM URI Real-time Block lists (SURBL) presented in email body - Content filtering of all message headers and mime parts - Check of graphical attachments through well-known spam signatures - Program reports and their auto delivery to administrators by schedule - Ability to update application modules and antivirus bases from different sources and by various means, including network and local data sources - Ability to scan mailboxes and public folders with Exchange Web Services enabled in background - Detailed HTML reports. - Ability to send reports to defined mail recipients - Active Directory integration - Centralized management of all protection components available via single MMC console - Antispam agent should be able to detect SPAM and Probable SPAM Emails - Solution should be able to add blacklisting for sender emails - Solution should be able to whitelisting for sender IP addresses - Solution should be able to check sender IP for presence in DNS - Solution should be able to check if sender’s IP address is dynamic - Solution should be able to use Single Database for all instance - Administrator must be able to find detected email from all instance in one single console - Solution should be able to add blacklisting for sender IP addresses - Solution should be able to whitelisting for recipient emails - Solution should be able to blacklisting for recipient emails - Administrator must be release detected email from all instance in one single console - Ability to add of labels to message headers ([!!Infected object], [!!Protected object], [!!Corrupted object], etc.) - Ability to specify individual actions for different security risks (viruses, worms, spyware, etc.) or for damaged or password-protected attachments - Ability to find and remove all macros from office/document files - Special response when mass-mailing behaviour is detected - Ability to support ‘Cloud’ protection for Antimalware - Ability to send Notifications about any detected threats - Ability to customizable templates for Notifications from administration console - Language-based spam detection (reacts to languages with a high spam rating) - Ability to add of addition customizable labels to processed messages (‘[!!Spam]’, ‘[!!Probable Spam]’, etc.) - Ability to assign SCL (spam confidence level) values to messages - Ability to increasing spam rating for specified conditions (sender address contains numbers, 'To' field is empty, 'Subject field longer than 250 chars, etc.') - maximum scanning time for a message, in seconds - Ability to scan DOC files for spam - Ability to scan RTF files for spam - Ability to use ‘Potential Spam’ (or ‘Suspected Spam’) status - Ability to use image analysis techniques to detect spam - Ability to skip spam checking for the Postmaster address - Ability to send notifications about Web Reputation support events (to Admin, Sender, Recipient) - Ability to specify messages to be blocked by scanning for strings in a subject, body or attachment file name - + Ability to add role-based administration - Support for Clusterization - Ability to export/import all server configuration settings to an external XML-file - Ability to send Notifications about any detected threats - Ability to manual update databases - Ability to monitor application's operations via Microsoft System Centre Operations Manager - Ability to on-demand scan for selected mailboxes and public folders - Ability to scan exclusions per recipient basis - Ability to scan exclusions by file masks - Ability to scan limit of compound objects by nesting levels | رخصة | 3 | 0 |
3 بند
كراسة الشروط الرئيسية
| اسم المورد | قيمة العرض (ر.س) | قيمة الترسية (ر.س) | النتيجة الفنية | الحالة |
|---|---|---|---|---|
| شركة رموز التقنيات للأمن السيبراني | 849,620.00 | — | مطابق | مشارك |
| شركة الجريسي لخدمات الكمبيوتر واجهزه الاتصالات شركة مجموعه الجريسي | 896,505.50 | — | مطابق | مشارك |
| الشركة العليا السعودية لانظمه الحاسب الالي | 917,700.00 | — | مطابق | مشارك |
| شركة التقنيات العالمية للتجارة والمقاولات | 881,705.00 | — | مطابق | مشارك |
| شركة رموز التقنيات للأمن السيبراني | 849,620.00 | 849,620.00 | — | مرسّى |
الآليات
القائمة الإلزامية
آلية التفضيل السعري للمنتج الوطني
وثائق المحتوى المحلي
معايير التقييم
معايير التقييم الفني
| المستوى الاول | المستوى الثاني | المستوى الثالث | الوزن النهائي |
|---|---|---|---|
| التقييم الفني |
معايير التقييم المالي
| المستوى الاول | المستوى الثاني | المستوى الثالث | الوزن النهائي |
|---|---|---|---|
| التقييم المالي | السعر | التكلفة الكلية | 100% |
أخبار المنافسة
title
تاريخ الإنشاء
value
04/11/42 10:41:03 ص
title
تاريخ فتح العروض
value
20/11/42 11:00:00 ص
title
تاريخ الترسيه
value
01/02/1443