منافسة عامة
قيد التنفيذ
عملية توريد وتركيب وتشغيل أنظمة ورخص أمن وتشفير قواعد البيانات بالمديرية العامة لمكافحة المخدرات
المديرية العامة لمكافحة المخدرات
رقم المنافسة
220339524888
المعرّف
#378792
| التاريخ | ميلادي | هجري |
|---|---|---|
| تاريخ النشر | 2022/03/27 12:05 | — |
| آخر موعد للاستفسارات | 2022/03/28 | 1443-08-25 |
| آخر موعد تقديم العروض | 2022/04/19 14:00 | 1443-09-18 |
| موعد فتح العروض | 2022/04/20 11:00 | 1443-09-19 |
| موعد فحص العروض | — | — |
| التاريخ المتوقع للترسية | — | — |
| تاريخ بدء الأعمال | — | — |
| تاريخ خطاب تأكيد المشاركة | — | — |
| بداية إرسال الأسئلة | — | — |
موقع التنفيذ
مجال التصنيف
جدول 1 القوى العاملة - تقنية معلومات
| العدد | وصف البند | الرقم التسلسلي | المسمى الوظيفي | الحد الأدني لسنوات الخبرة | عدد ساعات العمل الاساسي المتوقعة | عدد ساعات العمل الاضافي المتوقعة |
|---|---|---|---|---|---|---|
| 1 | بكالوريوس في هندسة الحاسب الالي | 1 | مدير المشروع )مهندس( | 10 | 8 | 1 |
| 1 | بكالوريوس في هندسة الحاسب الالي | 2 | تنفيذ المشروع ) مهندس ( | 6 | 8 | 1 |
| 1 | دبلوم حاسب الي | 3 | فني حاسب الي | 3 | 7 | 1 |
3 بند
جدول 2 المواد - تقنية معلومات
| البند | الكمية | المواصفات | وحدة القياس | الرقم التسلسلي | منتج من القائمة الإلزامية |
|---|---|---|---|---|---|
| نظام مراقبة قواعد البيانات و اكتشاف الثغرات مع الرخص لثلاثة سنوات | 1 | أولا : نظام مرا رقبة قواعد البيانات و اكتشاف الثغ ا رت مع الرخص لثلاثة سنوات: DB using one of the best tools available in the market today, this tool must be from the same SEIM Vendor to ensure seamless integration and must be at least with the below features: - Discovery & Classification The solution should offer automatic discovery of new users, databases or database objects on the network The solution should provide sensitive data discovery options together with predefined data classification rules for various sensitive data types including PCI, and PII data and offers the ability for customization The solution should support user entitlement reviews on database accounts Assess & Harden The solution should provide support for database vulnerability management for both software and configuration including asset prioritization, risk scoring, customizable reporting and workflow options. The solution should provide support for virtual vulnerability patching Encryption Requirements The solution should The solution support real-time auditing and alerting The solution should detect excessive, unnecessary, unauthorized, suspicious or high-risk activity in real-time for both internal and external users (including privileged users) The solution should provide granular policy management by separate audit and security policies be created and managed at different granularity levels The solution should be able to block excessive, unnecessary, unauthorized, suspicious or high-risk activity in real-time for both internal and external users (including privileged users). The solution must be able to facilitate ODBC/JDBC connections over SSL without requiring additional SSL certificates to be deployed The solution should audit accesses with elevated privileges, such as an administrator or system administrator account The solution should provide ongoing, continuous monitoring for the usage and flow of sensitive data The solution should have the ability to monitor data that is passed through encrypted transmissions (SSL, SFTP, etc.) The solution should have the ability to define rules and alerts The solution must identify down to the user level who is accessing which data The solution should have the ability to implement user defined monitoring rules The solution should be able to monitor structured and unstructured data through File Activity Monitoring Audit & Report Audit records should contain all information required for understanding of the event including: Source and destination IP, DB and OS user name, source application, number of affected rows, and database instance name The solution should provide easy to use custom reporting and alerting options in addition to preconfigured reports and policies The solution should provide means to profile data activity behavior together with tools to filter noise or known false positives The solution should not store sensitive data in logs generated by the application (e.g. passwords) Logs and audit-trail generated by the solution should not be editable by users and should be read-only Alerting should be available via email, SNMP and Syslog The solution should provide an internal workflow capability that allows users to raise issues and assign them to other users Reports should be exportable via both PDF and Excel solution should be stored in a secure manner and all alterations to the report generation and to the reports themselves should be auditable Performance & Scalability The solution should support distributed infrastructure (Data Centers in different locations) Performance impact introduced on the database and file servers should be minimal Network traffic introduced by the solution should have minimal impact on network capacity The solution must be scalable to accommodate future growth in number or size of servers The solution should not materially impact any other monitoring tools already in use in the systems. Management & Security The solution should provide one centralized management UI for all user / administrator interaction The solution should provide centralized automated configuration and policy pushes, patch, content and vulnerability tests’ updates for all components of the solution. The solution should provide tamper proof audit trail (including from privileged users) The solution should provide Role Based Access Control Workflow, Alerting, Reporting, Incident Triage/Ticketing and other features for security, database, audit and risk teams enforcing separation of duties principles The solution should provide self-health monitoring features The solution should provide secure connections for user interface and communication within different modules and components of the solution including Strong Authentication capability The solution should enforce a password policy by which users of the solution have to set up strong passwords with a password expiration The solution should have built-in Audit Data MGMT - back-up, purge, and archive capabilities The solution should have Centralized, relational data store for correlation, drill-down, and analysis The solution should have Hardening, Discovery, Classification, Entitlement Reporting, Vulnerability Assessment capabilities The solution should have Entitlement Reporting, Collect and aggregate entitlements across data platforms; identify dormant entitlements The solution should have VA Analyze DB configuration, identify vulnerabilities, recommend remediation Deployment The solution should support high availability deployment options The solution should support virtual appliance format deployment local agent monitoring The solution must ensure integrity, continuity and avoid any loss of audit log data in the event of failure for both agents and central systems Agent deployment should not require any DB intervention, native logs/triggers to be created and maintained in order for it to function The solution should provide an archiving strategy for logs greater than a specified time and all archive logs must be retained for a time period as specified by the Information Lifecycle Management policies The solution should be entirely configurable from the front end and have a user-friendly user interface The solution should ensure that agent-based tooling supports an alert being raised to Security Operations team in the event of an agent being switched off or changed Explain the system and infrastructure requirements to support the solution The solution should be able to integrate with our ticketing system to map assets with owners Solution Support The solution should have in place a process that identifies security patches and fixes The vendor should provide support for the solution, including the application of security patches and fixes, the implementation of known vulnerability remediation actions, and the troubleshooting and resolution of incidents | رخص | 1 | 0 |
1 بند
كراسة الشروط الرئيسية
كراسة الشروط والمواصفات وملاحق المنافسة
353 KB
تم التحميل
2022/378792/main_booklet_كراسة_الشروط.html
المستندات الداعمة (4 ملف)
ملحق خطاب العرض.pdf
30 KB
تم التحميل
2022/378792/idd_39A4C0AA-D0A7-C5E6-8536-7FABE7000000_ملحق_خطاب_العرض.pdf
ملحق الاسئلة والاستفسارات.pdf
13 KB
تم التحميل
2022/378792/idd_4D1DE860-6E42-CD9C-8C1A-7FABE7100000_ملحق_الاسئلة_والاستفسارات.pdf
نموذج عقد تقنية المعلومات.pdf
566 KB
تم التحميل
2022/378792/idd_58DB1D7E-0BD8-C92F-846B-7FABE6E00000_نموذج_عقد_تقنية_المعلومات.pdf
الية التفضيل السعري للمنتج الوطني.pdf
74 KB
تم التحميل
2022/378792/idd_A3601687-9128-C81E-843B-7FABE7300000_الية_التفضيل_السعري_للمنتج_الوطني.pdf
لم يتم ترسية هذه المنافسة بعد
لا توجد بيانات للمحتوى المحلي
معايير التقييم
لا توجد معايير تقييم
أخبار المنافسة
لا توجد أخبار