منافسة عامة قيد التنفيذ

مشروع تجديد رخص نظام مضاد الفيروسات ونظام الكشف والاستجابة للتهديدات الأمنية لديوان المظالم لعام 2022م

ديوان المظالم

رقم المنافسة

220339532429

المعرّف

#383811

رقم المنافسة
220339532429
رقم المنافسة الداخلي
2022/17
الجهة الحكومية
ديوان المظالم
الفرع / الإدارة
ادارة العقود والمشتريات
نوع المنافسة
منافسة عامة
حالة المنافسة
طريقة تقديم العروض
رسوم الاشتراك
500 ر.س
سعر كراسة الاشتراط
200 ر.س
تكلفة الدعوة
200 ر.س
تكلفة الشراء
500 ر.س
الضمان الإبتدائي
الضمان النهائي
مدة العقد
التأمين مطلوب
مدة الوقفة (أيام)
داخل المملكة
التاريخ ميلادي هجري
تاريخ النشر 2022/03/30 13:04
آخر موعد للاستفسارات 2022/04/12 1443-09-11
آخر موعد تقديم العروض 2022/04/20 13:00 1443-09-19
موعد فتح العروض 2022/04/20 14:00 1443-09-19
موعد فحص العروض
التاريخ المتوقع للترسية
تاريخ بدء الأعمال
تاريخ خطاب تأكيد المشاركة
بداية إرسال الأسئلة

موقع التنفيذ

منطقة التنفيذ
مدن التنفيذ

مجال التصنيف

يشمل مواد توريد
لا

جدول 1 المواد - تقنية معلومات

البند الفئة الكمية وصف البند المواصفات وحدة القياس الرقم التسلسلي منتج من القائمة الإلزامية
توريد وتركيب رخص نظام الكشف والاستجابة للتهديدات الأمنية المتقدمة لجميع الأجهزة والخوادم المرتبطة بشبكة الديوان مع الدعم الفني لمدة سنة واحدة 1 3800 توريد وتركيب رخص نظام الكشف والاستجابة للتهديدات الأمنية المتقدمة لجميع الأجهزة والخوادم المرتبطة بشبكة الديوان مع الدعم الفني لمدة سنة واحدة "Access Control - This product shall support multitenancy with role-based access and delegated administration control - This product shall support the access of many Admin Roles and multiple Admin sessions - Policy Enforcement and Malware Control - This product shall support a cloud based intelligence platform that provides reputation feeds on files and bad hashes to make decisions - This Product shall support a single agent for both EPP & EDR - This Product shall support both preventive Static AI and Behavioral AI engines that protects from (unknown) malicious files and malicious activities in real time whether that endpoint is online or offline - This product shall detect a wide range of malware carriers such as BOT networks, Command & Control, TOR networks, etc - This product shall protect against wide classes of malicious software such as viruses, Trojans, spyware, APTs, etc. and shall categorize detected attacks - This product shall support detection of zero-day malicious file/file less attacks, ransomware attacks and adopt behavioral analysis/intelligence in carrying out detection. Remediation and or reversal to known good state of an endpoint in the event of a ransomware infection/attack - Unique ability to provide rollback & remediation of any potentially infected machines (saves our customers time) - This Product shall provide protection from Lateral Movement attacks using Behavioral AI engine that detects attacks initiated by remote devices - This product shall support a wide range of endpoints (Workstations, Servers, VDI) and across OS platforms. (Windows, Linux, Oracle, Mac OS etc.) - This product shall support the ability to build file policy filtering based on manually inputted IOC hashes and automated hash feeds from third party solutions or Open Source feeds solutions such as Virus Total, Looking glass, etc - This Product shall provide full EDR capabilities that collects and re-linked of IOCs and support a powerful interface to query, pivot, hunt with advanced query language - This Product shall provide Full response capabilities: mitigation, remediation, rollback, network quarantine, get logs, get files, device control (USB ports), FW control, Secure Remote Shell (full PowerShell on Windows, full Bash on MacOS), orchestration of 3rd party security products using APIs - Monitoring - This product shall provide customized, group-specific and predefined suspicious user activity monitoring and reporting for event and audit logs - This product shall have mechanisms/rules to detect shared administrative privileges - This Product shall provide the Visibility into SSL traffic for use in hunting operations - This Product provides Device control (USB port, and more…) - This Product provides Application and version inventory + Vulnerability/Risk assessment - Compliance - This product shall support compliance standards (ISO 27001) and shall document controls Within these standards where their products satisfactorily meets its requirement. This brief documentation should either be written in the comment section of this item or attached should it be reasonably large - High Availability - This product shall support high tolerance and resiliency during failures - This product shall detect and alert early enough, failures in either event sources (the main appliances) or its management box in which case shall not lead to temporal loss of logs - Integration - This product shall provide easy integration with Security Incidents and Events Management systems (SIEM) for real-time incident management, and shall also integrate well with network management tools - This product shall support Complete API support/interface that can integrate in both ways into other security tools with receive remote instructions from other appliances such as SIEM to take specific decisions on its behalf - This product shall support configuration at both the GUI and CLI - Performance - This product shall ensure high performance during peak hours of network transactions ensuring that endpoint performance are not impacted in any form - This product shall support collection and analysis of endpoint telemetry, such as file I/O, network connections, process execution, log-on events, or registry changes and on-demand access to current-state data from all systems - This product shall support enterprise wide for any type of file “at rest” by name or hash on demand and historical - This product shall support combined, complete but simple search queries using a combination of methods such as regular expression, fully unstructured text search, etc. simultaneously without impacting search performance - This product shall provide a very good reporting interface for viewing real-time logs and ability to generate recurring customized reports - This product shall support exporting of reports in different formats including PDF and CSV and with pre-built report templates customizable to organization's need - Scalability - This Product shall support on- premise infrastructure deployment of the Management server(s) - This product shall architecturally ""scale"" in larger deployments - This product shall support multi-tenancy environment with an MSSP model. - This product shall support centralizing dashboards from different tenants without breaking the multi-tenancy concept - This product shall support multi-tenancy for administration console - This product shall support distributed appliance-engine model with an appliance-based centralized log storage for distributed events - This product shall provide storage system that support segregation of log databased on tenant - This product shall have capacity to store massive amounts of both real-time and historical events long-term (say six months minimum) - This product shall support centralized administration in a geographically dispersed deployment - Virtualization - This solution shall support a virtual representation of this product in VM environment, which will enhance the daily customization test needs of customer's security research team - " رخصة 1 0
توريد وتركيب رخص نظام مضاد الفيروسات لجميع الأجهزة والخوادم المرتبطة بشبكة الديوان وتقديم الدعم الفني لمدة سنة واحدة 2 3800 توريد وتركيب رخص نظام مضاد الفيروسات لجميع الأجهزة والخوادم المرتبطة بشبكة الديوان وتقديم الدعم الفني لمدة سنة واحدة The solution must provide a single management console for deployment of the antivirus protection systems, configuration of group and individual parameters for applications, timely database updates, continuous monitoring of system status and quick response to emergencies. -The solution must support high availability and clustering. -The solution must come with Arabic/English user Interface . -The solution must support secure communication between management server and endpoints. -The solution must support Role Based Access Control to the management server and the ability to assign different access levels to different users like administrator, operator, and view. -solution Vendor must be in the “leaders” quadrant of Gartner’s latest magic quadrant report. -The solution must support notification via SNMP, Email and SMS. -The solution must support authentication to allow access to central management console. -The solution must provide a single management console to manage all below products/functions: -Antimalware components, -Control components ( Application, Web and Device ) control, -Firewall and HIPS, -Server protection, -MDM and Mobile Security components, -Virtual machines protection (VMware, Hyper-V and Citrix). -The deployment of the Endpoint solution must support the following: -Remote installation from the central management server, -Remote installation from a web portal, -Deployment based on active directory, -Deployment via third party software deployment solutions, -Local installation using pre-configured package. -solution must support signature update through: -The central management server, -Network shares and portable media, -Intermediate update sources. -Solution must provide a facility to save/minimize utilization of WAN and slow network connections by allowing updates to be downloaded once to an intermediate update source in the remote location and then distribute updates locally. -The “intermediate” update source should be fully manageable from the central management server and doesn’t necessary require to be installed on Windows Server. -Solution must support below client operating systems: -Windows XP, Vista,7, 8 and 8.1,10, -Red Hat Enterprise 5.8 & 6.2 , 7 Desktop, -Fedora 16, -CentOS-6.2, -SUSE Linux Enterprise Desktop 10 SP4, -OpenSUSE Linux 12.1, -Ubuntu 10.04 & 12.04 LTS , -Mac OS X 10.10 (Yosemite), -Mac OS X 10.9 (Mavericks), -Mac OS X 10.8 (Mountain Lion). -Solution must support below Server operating systems: -Windows Srv 2003, 2008, 2008 R2, 2012, 2012 R2 , 2016including standard, enterprise, core & datacenter editions, -Windows storage server 2012, -Windows hyper-v server 2012, -Windows Server 2003, 2008, 2012, 2012 R2 Terminal Server, -Citrix Presentation Server 4.0,4.5, -Citrix XenApp 4.5, 5.0, 6.0, 6.5, -Citrix XenDesktop 7.0, 7.1, 7.5. -Solution must be able to manage all mentioned operating systems and their protection components using single management console, -solution must be able to detect following type of threats: -Viruses (including polymorphic), Worms, Trojans, Backdoors, Rootkits, Spyware, Adware Pornware, Keyloggers, Crimeware, Phishing sites and links, Zero-day vulnerabilities and other malicious and unwanted software . -Solution must support automatic detection and deployment of antivirus protection on new connected/discovered workstations. -solution must include following components in a single agent installed on the endpoint: -Antimalware, -Application, Web and Device control, -HIPS and Firewall. -Solution should support seamless migration from existing antivirus solution and should remove existing Antivirus agent while upgrading. -Comprehensive endpoint visibility which includes graphical reporting, centralized logging, and threshold alerting. -Solution should support adding/removing protection components to endpoints without full reinstallation of the agent, -Solution should support installation endpoint protection on Servers without restart. -Solution should integrate with Active Directory in terms of pulling existing structure and computers/users and apply the same on the management server. -endpoint solution must allow the following : -Manual scanning, On access scanning, On demand scanning, Compressed File Scanning, Scan Individual file , Folder and drive, Script blocking and scanning, Auto clean, Quarantine infected files, Registry guard, Buffer Overflow Protection, Instant messages (IM) scanning. -Endpoint solution should be protected with a password to prevent stopping/killing the AV process and for self-protection regardless of user authorization level on the system. -Scans both HTTP and FTP traffic against viruses and spyware or any other malware. -Solution should provide facility for external computers to connect to internal management server for policies updates and status reporting. -Solution must include a personal firewall capable of, but not limited to: -Block network activates of applications based on their categorization, Block/allow certain packets, protocol, IP addresses, Ports and traffic direction, Automatic and manual addition of network subnets and modify network activity permissions. -Solution must be able to block network attacks and report source of infection, -Solution must have a proactive approach to prevent malwares from exploiting existing vulnerabilities, -Solution must support signature based detection in addition to cloud-assisted and heuristics/behavioral detection. -The solution should have the ability to alert , clean, delete , quarantine the detected threats. -Solution should have the ability to accelerate scanning tasks skipping those objects that have not changed since the previous scan. -Can exclude specified files / folders from being scanned either in the on-access scan (real-time protection) or during on-demand scans. -Isolate infected computers in case no action has been taken against a new threat in terms of applying more strict settings, initiate full system scan, DB update and even cutting off network communication if necessary. -All detected threats (cleaned or active) must be backed up in a central location where all samples can be re-examined or restored. -Automatically scans removable drives for malware upon insertion to any endpoint. Scan should be controlled based on drive size. -Solution must be able to block the usage of USB storage devices or only allow access to whitelisted devices and allow read/write access by domain users to reduce data theft and enforce lock policies. -solution must be able to differentiate among USB storage devices, printers, mobiles and other peripherals. -Ability to block access to certain websites based on content, user and time of day User-based policies for device, web and application control. -solution should allow blocking following devices: -Bluetooth, Mobile devices, -External modems, CD/DVDs, Transferring data to mobile devise, -Solution should contains cloud integration for most up to date updates on malware and potential threats. -Solution must support blocking blacklisted applications from being launched on endpoints. Also it must. -Support blocking all applications except “whitelisted” ones. -Solution must have cloud-integrated application control component to get latest updates on applications’ rating and categories. -Solution must provide a facility to check applications listed in each cloud-based category. -Solution must have the ability to block unsigned applications and to automatically categorizes unknown applications . -Solution should have a centralized , detailed, customized, and Multiple Format Reports (on screen and on paper). -Solution must be optimized for Desktop Virtualization by: -Automatically recognizes whether an agent is on a physical or virtual machine to better target protection. -Prevents network, CPU, and storage conflicts by serializing scan and update operations per virtual server. -Ability to control and prevent scan-storming. -solution must provide real time dashboard that enables rapid troubleshooting of errors, security events and security issues; graphs and numbers enabling steps required to alert resolution. -Ability to schedule report generation and distribution via emails or save at particular location in HTML, excel and PDF formats. Report customization and filter criteria such as date and time range, specific type of attack, and end point type (server or desktop). -solution should be able to protect and manage mobile devices including, but not limited to, iOS, BlackBerry and Android. -Solution must support protection deployment via the central management server, respective market and locally. -Solution must be able to scan mobile devices for malware and other unwanted objects on-demand and on-schedule with automatic action. -Solution must be able to manage and monitor mobile devices from same console used to manage computers and servers. -Solution must provide “anti-theft” function, where lost and/or displaced devices can be located, locked and wiped remotely. -Solution must provide facility to block blacklisted applications from being launched on the mobile device. -Solution must be able to separate personal and corporate data/applications with different controls and security settings and to require a password to access corporate data. -Solution should detect and report jail breaking and rooting on mobile devices. -Solution must be able to remotely install and remove applications from iOS devices. -Solution must be able to enforce security settings on mobile devices, like password restrictions and encryption. رخصة 2 0

2 بند

كراسة الشروط الرئيسية

كراسة الشروط والمواصفات وملاحق المنافسة

312 KB تم التحميل

2022/383811/main_booklet_كراسة_الشروط.html

فتح

المستندات الداعمة (4 ملف)

الشروط والأحكام لآلية التفضيل السعري للمنتج الوطني.pdf

567 KB تم التحميل

2022/383811/idd_49BD322A-E0CE-CED8-86BC-7FD4AEF00000_الشروط_والأحكام_لآلية_التفضيل_السعري_للمنتج_الوطني.pdf

فتح

متطلبات المحتوى المحلي.pdf

19 KB تم التحميل

2022/383811/idd_49EBD718-EF33-C162-8419-7FD4AEF00000_متطلبات_المحتوى_المحلي.pdf

فتح

خطاب تقديم العرض.pdf

123 KB تم التحميل

2022/383811/idd_6621AD0B-711D-CFAB-873E-7FD4AEF00000_خطاب_تقديم_العرض.pdf

فتح

نموذج العقد.pdf

434 KB تم التحميل

2022/383811/idd_8DD33B1D-D0EC-C428-8535-7FD4AEF00000_نموذج_العقد.pdf

فتح

لم يتم ترسية هذه المنافسة بعد

لا توجد بيانات للمحتوى المحلي

معايير التقييم

لا توجد معايير تقييم

أخبار المنافسة

لا توجد أخبار