منافسة عامة
✓ مرسّى
تجديد رخص نظام رصد الأحداث الأمنية لديوان المظالم 2021 م
ديوان المظالم
رقم المنافسة
210839410005
المعرّف
#277609
عنوان الضمان الإبتدائى
6565 طريق الملك خالد حي جامعة الملك سعود الرياض 12371 2999
الغرض من المنافسة
تجديد رخص نظام رصد ومراقبة الأحداث والتهديدات الأمنية بشبكة ديوان المظالم وتقديم التقارير والتنبيهات الاستباقية المساعدة لتجنب الوقوع في المخاطر مع تقديم الدعم الفني لمدة سنة واحدة.
| التاريخ | ميلادي | هجري |
|---|---|---|
| تاريخ النشر | 2021/09/01 10:17 | — |
| آخر موعد للاستفسارات | 2021/09/14 | 1443-02-07 |
| آخر موعد تقديم العروض | 2021/09/19 10:00 | 1443-02-12 |
| موعد فتح العروض | 2021/09/19 11:00 | 1443-02-12 |
| موعد فحص العروض | — | — |
| التاريخ المتوقع للترسية | 2021/12/13 | 1443-05-09 |
| تاريخ بدء الأعمال | 2021/12/19 | 1443-05-15 |
| تاريخ خطاب تأكيد المشاركة | — | — |
| بداية إرسال الأسئلة | 2021/09/12 | 1443-02-05 |
| أقصى مدة للإجابة | 5 يوم | |
| مكان فتح العروض | منصة اعتماد | |
| مدة الوقفة | 5 يوم |
موقع التنفيذ
مجال التصنيف
الأنشطة
- • تقنية المعلومات
وصف المنافسة
تجديد رخص نظام رصد ومراقبة الأحداث والتهديدات الأمنية بشبكة ديوان المظالم وتقديم التقارير والتنبيهات الاستباقية المساعدة لتجنب الوقوع في المخاطر مع تقديم الدعم الفني لمدة سنة واحدة.
جدول 1 المواد - تقنية معلومات
| البند | الكمية | وصف البند | المواصفات | وحدة القياس | الرقم التسلسلي | منتج من القائمة الإلزامية |
|---|---|---|---|---|---|---|
| نظام رصد الأحداث الأمنية لديوان المظالم 2021 م | 1 | نظام رصد الأحداث الأمنية لديوان المظالم 2021 م | جب أن يتوفر في المنتج ما يلي من خلال السجلات رخصة النظام بمعدل حفظ للسجلات 50 جيجابايت / يومياً - حالة الحدث - مكان الحدث أو النظام الذي تم تنفيذ الحدث فيه - ي- نوع الحدث - مكان الحدث او النظام الذي تم تنفيذ الحدث فيه - وقت الحدث وتاريخه - الاحداث المراد تسجليها - الأحداث الخاصة بالأمن السيبراني على جميع الاحداث التقنية والتأكد من توافقية المنتج من جميع الموردين أو ) Vendors) - الأحداث الخاصة بالحسابات والتحليل لها (UEBA ) - الأحداث الخاصة بالتصفح والشبكات اللاسلكية - نقل المعلومات عبر وسائط التخزين - اجراء التغييرات غير المشروكة على السجلات وملفات الأنظمة الحساسة (fim) - تغيرات إعدادات النظام أو الشبكة أو الخدمات بما في ذلك تنزيل حزم البيانات والإصلاحات - الأنشطة المشبوهة التي يكتشفها نظام منع التسلل مثل (IPS )- ان تكون مدة الاحتفاظ بالسجلات الخاصة بالأحداث السيبرانية لا تقل عن 12 شهراً- مقدرة المنتج على معالجة البيانات بشكل عالي وعلى الأقل الاحتفاظ بالبيانات ONLIINE لمدة - القدر على تحليل البيانات باستخدام تقنية (SOAR ) - قدرة المنتج على مساعدة (FORINSICS) في عملهم (COLLECT DATA FOR (FORINSICS) (- وجود منصة المشاركة (APT مع SIEM)- وجود سهولة إدارة PLAT FORM وتحديد الواجهات - . Performance on ingestion and query should grow linearly with the infrastructure (with double resources, we should be able to have twice the capacity with the same performance) - . The solution shall have the capacity to manage many concurrent queries (counting both realtime and historic queries, both interactive and job queries), in this case more than 100 concurrent queries - . Unlimited number of concurrent users on the platform - . The bidder should state the supported protocols. In particular are desired: http/https, syslog, ssh, ftp, netflow) - . Geographical distributed solution: should be able to have the ingestion and data storage in several locations/countries, and to keep having ingestion and query in real-time -. The solution must be multi-tenant in all the features and logical layers - . Multiple deployment models: the solution shall be able to be deployed in cloud, in on-premises, on in hybrid models - . Keep the data in the original format ("raw" format) -. To avoid "lock-in" on a provider, the solution shall be able to export the data in the original raw format - . Shall be able to keep all data (including those arriving in real time) compressed, in order to save resources - . Shall be able to query the compressed data with the performance requested -. Same engine and infrastructure for query real-time data and historical data (in order to reduce complexity and maintenance/operation costs) - Support for oData, oAuth, and SAML - . Shall be able to add new data sources without stopping operations ("hot ") and in real time - . Detect loss and lack of data by volume, data type and element in each one of the data sources - . Build and execution of alerts in real time. Real-time refers to a granularity of 5 minutes and the information corresponding to 5-minutes data must be viewed 2 minutes after the end of the period - End-to-end security: data must be secure from sending to query. Ciphered data in transit. Encrypted data in the storage. Data authenticated in transits with cross-cryptographic authentication with digital certificates - . Digital signature of the data by blocks, to protect against tampering with the data -. Secure reception of data from devices over public networks - Login with strong 2-factor authentication - . Full audit of the platform and the user’s activities: Access, query execution, activity, volumes used, etc… at user, department and account levels, per data source and table -. All the interface capacities shall be managed by role-based access models. - Control access, based on roles, to data at table, row and column levels - . The solution should be "schema less", and should support several "schemas" over the same data, applying them "on the fly" (during the query or the closest)-. "Data virtualization": Shall support multiples models, schemas, and unions of data over a single copy of the original data - . Query over open temporal periods ("from xxx to forever") in strict real time (not emulating with micro-batching). Real-time refers to a granularity of 5 minutes and the information corresponding to 5-minutes data must be viewed 2 minutes after the end of the period. - Anonymization of data at table, row and column. Managed by roles. - Mask of data at table, row and column. Managed by roles.- . Advanced correlation of events in real time. Real-time refers to a granularity of 5 minutes and the information corresponding to 5-minutes data must be viewed 2 minutes after the end of the period. - Data aggregation: KPI's calculated on real time over the raw data. Materialization of the aggregated results on real time. Real-time refers to a granularity of 5 minutes and the information corresponding to 5-minutes data must be viewed 2 minutes after the end of the period. - Integrated geolocation mechanisms - . The solution can build abstraction layer over data from different manufacturers to create a common information model - . Consume machine learning models in real time - All the below capacities shall be able to execute by the end-user using the interface, fully audited, and managed by roles - . User should be able to create queries (even complex ones) without code: that implies to have a graphical interface to build queries - . Create alerts and notifications - . Should be capable to create data unions using only events that fulfill a group of conditions (including conditions on enriched columns) -. Capacity to search tokens of information in all data, both on raw data and after applying any model - . Capacity to create complex graphical queries - . Native support of advance operations over each column, and available from the user interface (network functions, statistical operations, …) - . Should be able to enrich the data, dynamically and statically, both on real-time data and on historic data - . Statistic functions – Solution shall provide statistic functions to present information. As a minimum: time evolution, histogram, cumulative distributions, average calculations, percentile calculations. -. The solution shall support different chart types within the same graph (e.g. KPI 1 = bar, KPI 2 = line). - . The solution shall include functionalities such as: maximum, minimum and average to analyze the indicators. - . The platform should allow the creation of multiple user profiles managed by an administrator profile. That is, a user or group of users may only have access to one or several cases of use / applications / services within the tool, even numbers ranges. - . The solution shall distinguish between different user roles. For example, monitoring engineers, maintenance engineers and Customer Services agents shall have different interfaces. -. The creation and management of the different user roles need to be done through a graphical interface (GUI) | رخصة | 1 | 0 |
1 بند
كراسة الشروط الرئيسية
| اسم المورد | قيمة العرض (ر.س) | قيمة الترسية (ر.س) | النتيجة الفنية | الحالة |
|---|---|---|---|---|
| شركة ديتكون السعودية ديتاساد المحدودة | 599,437.50 | — | مطابق | مشارك |
| شركة ديتكون السعودية ديتاساد المحدودة | 599,437.50 | 599,437.50 | — | مرسّى |
الآليات
القائمة الإلزامية
آلية التفضيل السعري للمنتج الوطني
وثائق المحتوى المحلي
معايير التقييم
معايير التقييم الفني
| المستوى الاول | المستوى الثاني | المستوى الثالث | الوزن النهائي |
|---|---|---|---|
| التقييم الفني |
معايير التقييم المالي
| المستوى الاول | المستوى الثاني | المستوى الثالث | الوزن النهائي |
|---|---|---|---|
| التقييم المالي | السعر | التكلفة الكلية | 100% |
أخبار المنافسة
title
تاريخ الإنشاء
value
23/01/43 10:47:30 ص
title
تاريخ فتح العروض
value
12/02/43 11:00:00 ص
title
تاريخ الترسيه
value
16/04/1443