منافسة عامة قيد التنفيذ

عملية توريد وتركيب وتشغيل أنظمة ورخص أمن وتشفير قواعد البيانات بالمديرية العامة لمكافحة المخدرات

المديرية العامة لمكافحة المخدرات

رقم المنافسة

220339524888

المعرّف

#378792

رقم المنافسة
220339524888
رقم المنافسة الداخلي
19/1443-1444
الجهة الحكومية
المديرية العامة لمكافحة المخدرات
الفرع / الإدارة
إدارة المنافسات
نوع المنافسة
منافسة عامة
حالة المنافسة
طريقة تقديم العروض
رسوم الاشتراك
500 ر.س
سعر كراسة الاشتراط
500 ر.س
تكلفة الدعوة
200 ر.س
تكلفة الشراء
500 ر.س
الضمان الإبتدائي
الضمان النهائي
مدة العقد
التأمين مطلوب
مدة الوقفة (أيام)
داخل المملكة
التاريخ ميلادي هجري
تاريخ النشر 2022/03/27 12:05
آخر موعد للاستفسارات 2022/03/28 1443-08-25
آخر موعد تقديم العروض 2022/04/19 14:00 1443-09-18
موعد فتح العروض 2022/04/20 11:00 1443-09-19
موعد فحص العروض
التاريخ المتوقع للترسية
تاريخ بدء الأعمال
تاريخ خطاب تأكيد المشاركة
بداية إرسال الأسئلة

موقع التنفيذ

منطقة التنفيذ
مدن التنفيذ

مجال التصنيف

يشمل مواد توريد
لا

جدول 1 القوى العاملة - تقنية معلومات

العدد وصف البند الرقم التسلسلي المسمى الوظيفي الحد الأدني لسنوات الخبرة عدد ساعات العمل الاساسي المتوقعة عدد ساعات العمل الاضافي المتوقعة
1 بكالوريوس في هندسة الحاسب الالي 1 مدير المشروع )مهندس( 10 8 1
1 بكالوريوس في هندسة الحاسب الالي 2 تنفيذ المشروع ) مهندس ( 6 8 1
1 دبلوم حاسب الي 3 فني حاسب الي 3 7 1

3 بند

جدول 2 المواد - تقنية معلومات

البند الكمية المواصفات وحدة القياس الرقم التسلسلي منتج من القائمة الإلزامية
نظام مراقبة قواعد البيانات و اكتشاف الثغرات مع الرخص لثلاثة سنوات 1 أولا : نظام مرا رقبة قواعد البيانات و اكتشاف الثغ ا رت مع الرخص لثلاثة سنوات: DB using one of the best tools available in the market today, this tool must be from the same SEIM Vendor to ensure seamless integration and must be at least with the below features: - Discovery & Classification  The solution should offer automatic discovery of new users, databases or database objects on the network  The solution should provide sensitive data discovery options together with predefined data classification rules for various sensitive data types including PCI, and PII data and offers the ability for customization  The solution should support user entitlement reviews on database accounts Assess & Harden  The solution should provide support for database vulnerability management for both software and configuration including asset prioritization, risk scoring, customizable reporting and workflow options.  The solution should provide support for virtual vulnerability patching Encryption Requirements The solution should The solution support real-time auditing and alerting  The solution should detect excessive, unnecessary, unauthorized, suspicious or high-risk activity in real-time for both internal and external users (including privileged users)  The solution should provide granular policy management by separate audit and security policies be created and managed at different granularity levels  The solution should be able to block excessive, unnecessary, unauthorized, suspicious or high-risk activity in real-time for both internal and external users (including privileged users).  The solution must be able to facilitate ODBC/JDBC connections over SSL without requiring additional SSL certificates to be deployed  The solution should audit accesses with elevated privileges, such as an administrator or system administrator account  The solution should provide ongoing, continuous monitoring for the usage and flow of sensitive data  The solution should have the ability to monitor data that is passed through encrypted transmissions (SSL, SFTP, etc.)  The solution should have the ability to define rules and alerts  The solution must identify down to the user level who is accessing which data  The solution should have the ability to implement user defined monitoring rules  The solution should be able to monitor structured and unstructured data through File Activity Monitoring Audit & Report  Audit records should contain all information required for understanding of the event including: Source and destination IP, DB and OS user name, source application, number of affected rows, and database instance name  The solution should provide easy to use custom reporting and alerting options in addition to preconfigured reports and policies  The solution should provide means to profile data activity behavior together with tools to filter noise or known false positives  The solution should not store sensitive data in logs generated by the application (e.g. passwords)  Logs and audit-trail generated by the solution should not be editable by users and should be read-only  Alerting should be available via email, SNMP and Syslog  The solution should provide an internal workflow capability that allows users to raise issues and assign them to other users  Reports should be exportable via both PDF and Excel solution should be stored in a secure manner and all alterations to the report generation and to the reports themselves should be auditable Performance & Scalability  The solution should support distributed infrastructure (Data Centers in different locations)  Performance impact introduced on the database and file servers should be minimal  Network traffic introduced by the solution should have minimal impact on network capacity  The solution must be scalable to accommodate future growth in number or size of servers  The solution should not materially impact any other monitoring tools already in use in the systems. Management & Security The solution should provide one centralized management UI for all user / administrator interaction The solution should provide centralized automated configuration and policy pushes, patch, content and vulnerability tests’ updates for all components of the solution. The solution should provide tamper proof audit trail (including from privileged users) The solution should provide Role Based Access Control Workflow, Alerting, Reporting, Incident Triage/Ticketing and other features for security, database, audit and risk teams enforcing separation of duties principles The solution should provide self-health monitoring features The solution should provide secure connections for user interface and communication within different modules and components of the solution including Strong Authentication capability The solution should enforce a password policy by which users of the solution have to set up strong passwords with a password expiration The solution should have built-in Audit Data MGMT - back-up, purge, and archive capabilities The solution should have Centralized, relational data store for correlation, drill-down, and analysis The solution should have Hardening, Discovery, Classification, Entitlement Reporting, Vulnerability Assessment capabilities The solution should have Entitlement Reporting, Collect and aggregate entitlements across data platforms; identify dormant entitlements The solution should have VA Analyze DB configuration, identify vulnerabilities, recommend remediation Deployment  The solution should support high availability deployment options  The solution should support virtual appliance format deployment local agent monitoring  The solution must ensure integrity, continuity and avoid any loss of audit log data in the event of failure for both agents and central systems  Agent deployment should not require any DB intervention, native logs/triggers to be created and maintained in order for it to function  The solution should provide an archiving strategy for logs greater than a specified time and all archive logs must be retained for a time period as specified by the Information Lifecycle Management policies  The solution should be entirely configurable from the front end and have a user-friendly user interface  The solution should ensure that agent-based tooling supports an alert being raised to Security Operations team in the event of an agent being switched off or changed  Explain the system and infrastructure requirements to support the solution  The solution should be able to integrate with our ticketing system to map assets with owners Solution Support  The solution should have in place a process that identifies security patches and fixes  The vendor should provide support for the solution, including the application of security patches and fixes, the implementation of known vulnerability remediation actions, and the troubleshooting and resolution of incidents رخص 1 0

1 بند

كراسة الشروط الرئيسية

كراسة الشروط والمواصفات وملاحق المنافسة

353 KB تم التحميل

2022/378792/main_booklet_كراسة_الشروط.html

فتح

المستندات الداعمة (4 ملف)

ملحق خطاب العرض.pdf

30 KB تم التحميل

2022/378792/idd_39A4C0AA-D0A7-C5E6-8536-7FABE7000000_ملحق_خطاب_العرض.pdf

فتح

ملحق الاسئلة والاستفسارات.pdf

13 KB تم التحميل

2022/378792/idd_4D1DE860-6E42-CD9C-8C1A-7FABE7100000_ملحق_الاسئلة_والاستفسارات.pdf

فتح

نموذج عقد تقنية المعلومات.pdf

566 KB تم التحميل

2022/378792/idd_58DB1D7E-0BD8-C92F-846B-7FABE6E00000_نموذج_عقد_تقنية_المعلومات.pdf

فتح

الية التفضيل السعري للمنتج الوطني.pdf

74 KB تم التحميل

2022/378792/idd_A3601687-9128-C81E-843B-7FABE7300000_الية_التفضيل_السعري_للمنتج_الوطني.pdf

فتح

لم يتم ترسية هذه المنافسة بعد

لا توجد بيانات للمحتوى المحلي

معايير التقييم

لا توجد معايير تقييم

أخبار المنافسة

لا توجد أخبار