Enterprise Security Operations Managed Service

Ervia

Provision of a Security Incident and Event Management System (SIEM) and a Managed SOC Service operating 24x7x365 and capable of meeting Erviaโ€™s needs and include the following capabilities: 24*7*365 Monitoring and Alerting Service, Event and Data Collection, Dashboard and Reporting, Event Correlation, User and Entity Analytics, High Volume Log Management, User Monitoring, Application Monitoring, Real Time Data Collection, Incident Management, Threat Intelligence, OT and Telemetry capability, Forensic Investigation Scope of contract: includes: Provision, implementation and support of a scalable solution for initially up to 6 000 events per second (EPS) and or equivalent IP / Volume based licensing model with potential to grow significantly over subsequent number of years and incorporating additional systems (through inclusion of existing or future new systems). (As per PQQ Document).

Deadline

The time limit for receipt of tenders was 2018-10-02. The procurement was published on 2018-08-30.

Who? What? Where?
Procurement history
Date Document
2018-08-30 Contract notice
2018-10-02 Additional information
2020-01-30 Contract award notice
Contract notice (2018-08-30)
Object
Scope of the procurement
Title: Security software package
Reference number: 18/021
Short description:
Provision of a Security Incident and Event Management System (SIEM) and a Managed SOC Service operating 24x7x365 and capable of meeting Erviaโ€™s needs and include the following capabilities: 24*7*365 Monitoring and Alerting Service, Event and Data Collection, Dashboard and Reporting, Event Correlation, User and Entity Analytics, High Volume Log Management, User Monitoring, Application Monitoring, Real Time Data Collection, Incident Management, Threat Intelligence, OT and Telemetry capability, Forensic Investigation Scope of contract: includes: Provision, implementation and support of a scalable solution for initially up to 6 000 events per second (EPS) and or equivalent IP / Volume based licensing model with potential to grow significantly over subsequent number of years and incorporating additional systems (through inclusion of existing or future new systems). (As per PQQ Document).
Show more
Notice metadata
Original language: English ๐Ÿ—ฃ๏ธ
Document type: Contract notice
Nature of contract: Services
Regulation: European Union, with participation of GPA countries
Common procurement vocabulary (CPV)
Code: Security software package ๐Ÿ“ฆ
Additional CPV: Electronic intelligence system ๐Ÿ“ฆ
Place of performance
NUTS region: ร‰ire/Ireland ๐Ÿ™๏ธ

Procedure
Procedure type: Negotiated procedure
Type of bid: Submission for all lots
Award criteria
The most economic tender

Contracting authority
Identity
Country: Ireland ๐Ÿ‡ฎ๐Ÿ‡ช
Awarding authority type: Utilities entity
Awarding authority name: Ervia
Postal address: P.O.Box 900, Webworks, Eglinton Street
Postal town: Cork
Contact
Internet address: http://www.ervia.ie ๐ŸŒ
E-mail: tenders@ervia.ie ๐Ÿ“ง
Phone: +353 214239506 ๐Ÿ“ž
URL for documents: http://www.etenders.gov.ie ๐ŸŒ
URL for participation: http://www.etenders.gov.ie ๐ŸŒ

Reference
Dates
Date dispatched: 2018-08-30 ๐Ÿ“…
Submission deadline: 2018-10-02 ๐Ÿ“…
Publication date: 2018-09-04 ๐Ÿ“…
Identifiers
Notice number: 2018/S 169-385773
OJ-S issue: 169
Additional information
You must submit through the Etenders system before the deadline. The submission deadline is strict and no submissions will be possible after the date and time specified in the PQQ documents. Please note that all tenders are electronic, as such NO paper copies will be accepted or read. Please submit via the Etenders system not later than 12:00 hrs (local time) Tuesday 2.10.2018.
Show more

Object
Scope of the procurement
Short description:
Provision of a Security Incident and Event Management System (SIEM) and a Managed SOC Service operating 24x7x365 and capable of meeting Erviaโ€™s needs and include the following capabilities:
โ€” 24*7*365 Monitoring and Alerting Service,
โ€” Event and Data Collection,
โ€” Dashboard and Reporting,
โ€” Event Correlation,
โ€” User and Entity Analytics,
โ€” High Volume Log Management,
โ€” User Monitoring,
โ€” Application Monitoring,
โ€” Real Time Data Collection,
โ€” Incident Management,
โ€” Threat Intelligence,
โ€” OT and Telemetry capability,
โ€” Forensic Investigation.
Scope of contract includes:
โ€” Provision, implementation and support of a scalable solution for initially up to 6 000 events per second (EPS) and / or equivalent IP / Volume based licensing model with potential to grow significantly over subsequent number of years and incorporating additional systems (through inclusion of existing or future new systems),
Show more
โ€” The SIEM solution must be capable of providing a secure means of integration with the relevant Ervia, Irish Water and Gas Networks Ireland systems (IT and OT Systems).Real-time collection and analysis of events from host systems, security devices and network devices. The solution must use global energy sector threat intelligence to identify existing and emerging threats,
Show more
โ€” Ervia have a requirement for a Siem technology implementation to be co located between Ervia and Supplier premises. In addition to the SIEM solution Ervia wishes to engage with the supplier to provide a managed SOC service for which the operating model should be a hybrid approach which leverages global knowledge and skilled persons for augmenting the in house Security Operations team and help to drive the maturing of Ervia security threat intelligence capability and incident response / resolutionโ€™,
Show more
โ€” It must be fully compatible with existing Ervia IT and OT systems and technologies, and be fully scalable (for future expansion if necessary),
โ€” Provision of a managed SOC service to configure, tune, and respond to relevant severity events, this response will include an initial SIEM based investigation and alerting of events,
โ€” The provider must have a dedicated Security Operations Centre staffed 24/7/365 by appropriately qualified personnel,
โ€” Provide predefined functions that can be lightly customized to meet Erviaโ€™s specific requirements,
โ€” Comply with all Irish and EU regulations, including GDPR and recommendations on how the vendor will help Ervia comply with the EU NIS Directive,
โ€” Provision of advanced security intelligence relating to Erviaโ€™s business,
โ€” Professional services to establish document and mobilise target operating model with Erviaโ€™s Security Operations team, including training where applicable,
โ€” Capability to provide auxiliary resources and services to manage security devices where necessary and to react to security incidents.
Duration: 36 months
Description of renewals: Option to renew for periods up to 24 months.
Description of options: Option to extend for additional periods up to 1 + 1 years.
Additional information:
You must submit through the Etenders system before the deadline. The submission deadline is strict and no submissions will be possible after the date and time specified in the PQQ documents. Please note that all tenders are electronic, as such NO paper copies will be accepted or read. Please submit via the Etenders system not later than 12:00 hrs (local time) Tuesday 2.10.2018.
Show more
Place of performance
Main site or place of performance: Cork, South West

Legal, economic, financial and technical information
Conditions for participation
Suitability to pursue the professional activity:
Please refer to tender documents available to download from www.etenders.gov.ie only.
Information about a particular profession: Services
Reference to relevant legislative or regulatory provisions:
If applicable, please refer to tender documents available to download from www.etenders.gov.ie only.
Contract execution
Legal form to be taken by the group of economic operators to whom the contract is to be awarded:
Requests to participate may be submitted by single entities or by groups of service providers. A group will not be required to convert into a specific legal form in order to submit a request to participate, but may if the Contracting Entity considers it necessary to ensure that the contract is carried out to its satisfaction, be required to do so prior to award of the contract. The Contracting Entity also reserves the right to contract with each member of the group on the basis of joint and several liability, or with one member of the group as a main contractor with a number of sub-contractors or on any other basis as the Contracting Entity considers appropriate.
Show more

Procedure
Legal basis: 32014L0025
Envisaged number of candidates: 5
Time of receipt of tenders: 12:00
Languages in which tenders or requests to participate may be submitted: English ๐Ÿ—ฃ๏ธ
Irish ๐Ÿ—ฃ๏ธ
Tender validity period: 6 months

Contracting authority
Identity
National registration number: N/a
Contact
Contact point: Ervia Tenders
Address of the buyer profile: https://irl.eu-supply.com/ctm/Company/CompanyInformation/Index/376 ๐ŸŒ
Documents URL: www.etenders.gov.ie ๐ŸŒ
URL for participation: www.etenders.gov.ie ๐ŸŒ
URL for documents: www.etenders.gov.ie ๐ŸŒ

Complementary information
Review body
Name: The High Court
Postal address: The Four Courts
Postal town: Dublin
Postal code: 7
Country: Ireland ๐Ÿ‡ฎ๐Ÿ‡ช
Phone: +353 18886000 ๐Ÿ“ž
E-mail: highcourtcentraloffice@courts.ie ๐Ÿ“ง
Internet address: http://www.courts.ie ๐ŸŒ
Information about review deadlines:
Precise information on deadline(s) for review procedures:
Please refer to Statutory Instrument 131 of 2010, European Communities (Award of Contracts by Utility Undertaking) (Review Procedures) Regulations 2010 (and in particular Regulation 7 and 10(2)).
Source: OJS 2018/S 169-385773 (2018-08-30)
Additional information (2018-10-02)
Object
Scope of the procurement
Short description:
Provision of a Security Incident and Event Management System (SIEM) and a Managed SOC Service operating 24x7x365 and capable of meeting Erviaโ€™s needs and include the following capabilities: โ€” 24*7*365 monitoring and alerting service, โ€” event and data collection, โ€” dashboard and reporting, โ€” event correlation, โ€” user and entity analytics, โ€” high volume log management, โ€” user monitoring, โ€” application monitoring, โ€” real time data collection, โ€” incident management, โ€” threat intelligence, โ€” OT and telemetry capability. Forensic Investigation Scope of contract includes: โ€” provision, โ€” implementation and support of a scalable solution for initially up to 6000 events per second (EPS) and/or equivalent IP/Volume based licensing model with potential to grow significantly over subsequent number of years and incorporating additional systems (through inclusion of existing or future new systems). (As per PQQ Document).
Show more
Notice metadata
Document type: Additional information
Common procurement vocabulary (CPV)
Code: Investigation and security services ๐Ÿ“ฆ

Contracting authority
Identity
Postal address: PO Box 900, Webworks, Eglinton Street
Postal code: Cork

Reference
Dates
Date dispatched: 2018-10-02 ๐Ÿ“…
Submission deadline: 2018-10-09 ๐Ÿ“…
Publication date: 2018-10-06 ๐Ÿ“…
Identifiers
Notice number: 2018/S 193-437601
Refers to notice: 2018/S 169-385773
OJ-S issue: 193

Object
Scope of the procurement
Short description:
โ€” 24*7*365 monitoring and alerting service,
โ€” event and data collection,
โ€” dashboard and reporting,
โ€” event correlation,
โ€” user and entity analytics,
โ€” high volume log management,
โ€” user monitoring,
โ€” application monitoring,
โ€” real time data collection,
โ€” incident management,
โ€” threat intelligence,
โ€” OT and telemetry capability.
Forensic Investigation Scope of contract includes:
โ€” provision,
โ€” implementation and support of a scalable solution for initially up to 6000 events per second (EPS) and/or equivalent IP/Volume based licensing model with potential to grow significantly over subsequent number of years and incorporating additional systems (through inclusion of existing or future new systems). (As per PQQ Document).
Show more
Source: OJS 2018/S 193-437601 (2018-10-02)
Contract award notice (2020-01-30)
Object
Scope of the procurement
Short description:
Provision of a Security Incident and Event Management System (SIEM) and a managed SOC service operating 24x7x365 and capable of meeting Erviaโ€™s needs and include the following capabilities: 24x7x365 monitoring and alerting service, event and data collection, dashboard and reporting, event correlation, user and entity analytics, high volume log management, user monitoring, application monitoring, real time data collection, incident management, threat intelligence, OT and telemetry capability, forensic investigation scope of contract: includes: provision, implementation and support of a scalable solution for initially up to 6 000 events per second (EPS) and/or equivalent IP/volume based licensing model with potential to grow significantly over subsequent number of years and incorporating additional systems (through inclusion of existing or future new systems). (As per PQQ Document).
Show more
Notice metadata
Document type: Contract award notice
Nature of contract: Supplies

Procedure
Type of bid: Not applicable
Award criteria
Lowest price

Reference
Dates
Date dispatched: 2020-01-30 ๐Ÿ“…
Publication date: 2020-02-04 ๐Ÿ“…
Identifiers
Notice number: 2020/S 024-054921
OJ-S issue: 24
Additional information
You must submit through the eTenders system before the deadline. The submission deadline is strict and no submissions will be possible after the date and time specified in the PQQ documents. Please note that all tenders are electronic, as such no paper copies will be accepted or read. Please submit via the eTenders system not later than 12.00 (local Time) 2.10.2018.
Show more

Object
Scope of the procurement
Short description:
Provision of a Security Incident and Event Management System (SIEM) and a managed SOC service operating 24x7x365 and capable of meeting Erviaโ€™s needs and include the following capabilities:
โ€” OT and telemetry capability,
โ€” forensic investigation.
Scope of contract includes
โ€” provision, implementation and support of a scalable solution for initially up to 6 000 events per second (EPS) and/or equivalent IP/volume based licensing model with potential to grow significantly over subsequent number of years and incorporating additional systems (through inclusion of existing or future new systems),
Show more
โ€” the SIEM solution must be capable of providing a secure means of integration with the relevant Ervia, Irish Water and Gas Networks Ireland systems (IT and OT systems). Real-time collection and analysis of events from host systems, security devices and network devices. The solution must use global energy sector threat intelligence to identify existing and emerging threats,
Show more
โ€” Ervia have a requirement for a SIEM technology implementation to be co-located between Ervia and supplier premises. In addition to the SIEM solution Ervia wishes to engage with the supplier to provide a managed SOC service for which the operating model should be a hybrid approach which leverages global knowledge and skilled persons for augmenting the in house security operations team and help to drive the maturing of Ervia security threat intelligence capability and incident response/resolution,
Show more
โ€” it must be fully compatible with existing Ervia IT and OT systems and technologies, and be fully scalable (for future expansion if necessary),
โ€” provision of a managed SOC service to configure, tune, and respond to relevant severity events, this response will include an initial SIEM based investigation and alerting of events,
โ€” the provider must have a dedicated security operations centre staffed 24/7/365 by appropriately qualified personnel,
โ€” provide predefined functions that can be lightly customized to meet Erviaโ€™s specific requirements,
โ€” comply with all Irish and EU regulations, including GDPR and recommendations on how the vendor will help Ervia comply with the EU NIS Directive,
โ€” provision of advanced security intelligence relating to Erviaโ€™s business,
โ€” professional services to establish document and mobilise target operating model with Erviaโ€™s Security Operations team, including training where applicable,
โ€” capability to provide auxiliary resources and services to manage security devices where necessary and to react to security incidents.
Additional information:
You must submit through the eTenders system before the deadline. The submission deadline is strict and no submissions will be possible after the date and time specified in the PQQ documents. Please note that all tenders are electronic, as such no paper copies will be accepted or read. Please submit via the eTenders system not later than 12.00 (local Time) 2.10.2018.
Show more
Place of performance
Main site or place of performance: Cork, South West.

Reference
Additional information
You must submit through the eTenders system before the deadline. The submission deadline is strict and no submissions will be possible after the date and time specified in the PQQ documents. Please note that all tenders are electronic, as such no paper copies will be accepted or read. Please submit via the eTenders system not later than 12.00 hrs (local time) 2.10.2018.
Show more
Source: OJS 2020/S 024-054921 (2020-01-30)