← Back to search results

plannedFind a Tender · planning

Provision of Security Incident Event Management Tool

Buyer: Crown Prosecution Service →

BuyerCrown Prosecution Service
Statusplanned
DeadlineNot published
ValueValue not published
Published14 Aug 2023

What is being bought

Provision of a Security Incident Event Management Tool: The Crown Prosecution Service (CPS) is issuing a Prior Information Notice (PIN) to inform prospective suppliers of its intention to procure a Security Information and Event Management (SIEM) tool. CPS will go to market for a new SIEM system as part of its overall cybersecurity strategy.

Delivery location

UKI3

Categories

System and support services 72250000For security system 72250000-FB09System and support services 72250000

Lot details

Lot 1

The Crown Prosecution Service (CPS) is issuing a Prior Information Notice (PIN) to inform prospective suppliers of its intention to procure a Security Information and Event Management (SIEM) tool. CPS will go to market for a new SIEM system as part of its overall cybersecurity strategy. As a minimum, the tool should provide the following functionality: 1. Log Collection and Aggregation: The SIEM should be capable of collecting and aggregating logs and data from various sources across the CPS, such as network devices, servers, applications, cloud infrastructure, and endpoints/end-user-devices. 2. Integration and Compatibility: The SIEM should integrate seamlessly with existing security tools and technologies, such as intrusion detection/prevention systems (IDS/IPS), firewalls, antivirus solutions, and threat intelligence feeds. 3. Real-time Monitoring: The SIEM should provide real-time monitoring capabilities to detect and alert on suspicious or malicious activities as they occur. This involves continuous analysis of incoming log data to identify anomalies and patterns indicative of security threats. 4. Event Correlation and Analysis: The system should be able to correlate and analyse events from multiple sources to identify complex attack patterns that may go unnoticed when analysing individual events in isolation. 5. Threat Detection and Alerts: The SIEM should have threat detection mechanisms that can identify known threats based on signatures and behaviours, as well as emerging threats using advanced analytics and machine learning techniques. It should generate timely and actionable alerts for security teams. 6. Incident Response: The SIEM should facilitate efficient incident response by providing workflow and case management capabilities. This allows security teams to track, investigate, and remediate security incidents effectively. 7. Automated Remediation: The SIEM should be capable of integrating with network services and infrastructure to automatically mitigate significant threats in real time. 8. Data Retention and Storage: A SIEM system must be capable of storing and managing large volumes of log data over extended periods to support historical analysis, compliance requirements, and forensic investigations. An indicative estimate is 50TB of data over a rolling year. 9. Scalability: The SIEM should be scalable to accommodate growing data volumes and an expanding IT infrastructure. It should be able to handle the increasing demands of log collection, analysis, and storage. 10. User and Entity Behaviour Analytics (UEBA): Advanced SIEM systems incorporate UEBA capabilities to establish baselines of normal behaviour for users and entities. Deviations from these baselines can trigger alerts for potential insider threats or compromised accounts. 11. Compliance and Reporting: The SIEM should assist organisations in meeting regulatory compliance requirements by offering predefined compliance reports and helping to demonstrate adherence to industry standards and regulations. 12. Advanced Analytics and Machine Learning: Employing machine learning and advanced analytics can enhance threat detection by identifying subtle patterns and anomalies that may indicate novel or sophisticated attacks. At this stage, the CPS is seeking to engage with the supply market as part of an information-gathering exercise to understand how suppliers might approach the provision of the services outline above, particularly with regards to any developments in service delivery and innovation. Suppliers who wish to express their interest in this potential opportunity should do so via the contact details contained within the notice and shall subsequently be invited to attend a virtual engagement session in which they may present their observations on how the requirements within this Prior Information Notice could be fulfilled. This presentation may take any format and should cover the following areas: • the latest developments / capabilities in SIEM technology • a cost estimation - provide a comprehensive breakdown of potential cost associated with the service provision to the CPS. This should include: setup costs, ongoing service costs, any cost related to customisation, support, or upgrades as well as any other incidental costs that may be incurred during the service.

Statusplanned

What is included

ItemCategoryQuantity
1System and support services, For security systemNot published

Comparable-procurement analytics

Benchmarked against retained Find a Tender procedures with CPV division 72. The category anchor is System and support services (72250000); this is a deliberately broad market comparator. The comparison is shown at several levels rather than pretending one company or region is always the best benchmark.

Comparison setProceduresReported bids per procedureNamed award suppliersPrice evidence
Market: CPV division 7210,5392 median · 15.4 average (4,162 of 10,539 with a bid count)2 average (5,054 of 10,539 with named award suppliers)Not published
Same buyer1Not publishedNot publishedNot published
Delivery region: UKI3108 median · 7 average (3 of 10 with a bid count)1 average (3 of 10 with named award suppliers)Not published

“Reported bids” is an official aggregate, sometimes reported per lot; it is the closest available competition measure. “Named award suppliers” are winners, not all applicants.

Price-outcome signal

Not enough comparable procedures currently publish both a GBP tender value and a usable lowest-valid-bid value to calculate a responsible price-reduction benchmark. Tenderline deliberately does not infer a saving from named award suppliers or from missing award values.

Procurement strategy & market signals

Framework agreementNot published
Dynamic purchasing systemNot published
Competitive procurementNot published
Recurring requirementNot published
Procurement method rationaleNot published
Rationale classificationsNot published
Special regimeNot published
Covered byNot published
Submission policyNot published
Selection criteriaNot published
Risk detailsNot published

Planning & early market engagement

BudgetNot published
No-engagement rationaleNot published
Planning documents0
Planning milestones0

No planning milestones published.

Related procurements

No linked framework, prior procurement or reprocurement published.

Documents & submission route

No documents are published in the current source record.

Source data inventory

Diagnostic view. “Not published” means this current release does not provide a value.

OCIDocds-h6vhtk-03efa9
Latest release ID023781-2023
Latest release timestampMon Aug 14 2023 15:42:21 GMT+0000 (Coordinated Universal Time)
Sourcefind-a-tender
Official notice URLNot published
Tender statusplanned
Procurement methodNot published
Procurement method detailsNot published
Main procurement categoryservices
Above thresholdNot published
Legal basis32014L0024
Tender period: startNot published
Tender period: endNot published
Expression of interest deadlineNot published
Enquiry deadlineNot published
Award period: startNot published
Award period: endNot published
Submission method detailsNot published
Submission languagesNot published
Electronic catalogue policyNot published
Total tender valueNot published
Tender lots in source1
Tender items in source1
Tender documents in source0
Awards in latest release0
Contracts in latest release0
Parties in latest release1

Notice history

DateEventReference
14 Aug 2023planning023781-2023

All source data

Unmodified official OCDS data retained by Tenderline for this procurement process.

Complete current OCDS release JSON
{
  "id": "023781-2023",
  "tag": [
    "planning"
  ],
  "date": "2023-08-14T16:42:21+01:00",
  "ocid": "ocds-h6vhtk-03efa9",
  "buyer": {
    "id": "GB-FTS-90184",
    "name": "Crown Prosecution Service"
  },
  "tender": {
    "id": "ocds-h6vhtk-03efa9",
    "lots": [
      {
        "id": "1",
        "status": "planned",
        "description": "The Crown Prosecution Service (CPS) is issuing a Prior Information Notice (PIN) to inform prospective suppliers of its intention to procure a Security Information and Event Management (SIEM) tool.\nCPS will go to market for a new SIEM system as part of its overall cybersecurity strategy.\nAs a minimum, the tool should provide the following functionality:\n1. Log Collection and Aggregation: The SIEM should be capable of collecting and aggregating logs and data from various sources across the CPS, such as network devices, servers, applications, cloud infrastructure, and endpoints/end-user-devices.\n2. Integration and Compatibility: The SIEM should integrate seamlessly with existing security tools and technologies, such as intrusion detection/prevention systems (IDS/IPS), firewalls, antivirus solutions, and threat intelligence feeds.\n3. Real-time Monitoring: The SIEM should provide real-time monitoring capabilities to detect and alert on suspicious or malicious activities as they occur. This involves continuous analysis of incoming log data to identify anomalies and patterns indicative of security threats.\n4. Event Correlation and Analysis: The system should be able to correlate and analyse events from multiple sources to identify complex attack patterns that may go unnoticed when analysing individual events in isolation.\n5. Threat Detection and Alerts: The SIEM should have threat detection mechanisms that can identify known threats based on signatures and behaviours, as well as emerging threats using advanced analytics and machine learning techniques. It should generate timely and actionable alerts for security teams.\n6. Incident Response: The SIEM should facilitate efficient incident response by providing workflow and case management capabilities. This allows security teams to track, investigate, and remediate security incidents effectively.\n7. Automated Remediation: The SIEM should be capable of integrating with network services and infrastructure to automatically mitigate significant threats in real time.\n8. Data Retention and Storage: A SIEM system must be capable of storing and managing large volumes of log data over extended periods to support historical analysis, compliance requirements, and forensic investigations. An indicative estimate is 50TB of data over a rolling year.\n9. Scalability: The SIEM should be scalable to accommodate growing data volumes and an expanding IT infrastructure. It should be able to handle the increasing demands of log collection, analysis, and storage.\n10. User and Entity Behaviour Analytics (UEBA): Advanced SIEM systems incorporate UEBA capabilities to establish baselines of normal behaviour for users and entities. Deviations from these baselines can trigger alerts for potential insider threats or compromised accounts.\n11. Compliance and Reporting: The SIEM should assist organisations in meeting regulatory compliance requirements by offering predefined compliance reports and helping to demonstrate adherence to industry standards and regulations.\n12. Advanced Analytics and Machine Learning: Employing machine learning and advanced analytics can enhance threat detection by identifying subtle patterns and anomalies that may indicate novel or sophisticated attacks.\nAt this stage, the CPS is seeking to engage with the supply market as part of an information-gathering exercise to understand how suppliers might approach the provision of the services outline above, particularly with regards to any developments in service delivery and innovation.\nSuppliers who wish to express their interest in this potential opportunity should do so via the contact details contained within the notice and shall subsequently be invited to attend a virtual engagement session in which they may present their observations on how the requirements within this Prior Information Notice could be fulfilled.\nThis presentation may take any format and should cover the following areas:\n• the latest developments / capabilities in SIEM technology\n• a cost estimation - provide a comprehensive breakdown of potential cost associated with the service provision to the CPS. This should include: setup costs, ongoing service costs, any cost related to customisation, support, or upgrades as well as any other incidental costs that may be incurred during the service."
      }
    ],
    "items": [
      {
        "id": "1",
        "relatedLot": "1",
        "deliveryAddresses": [
          {
            "region": "UKI3"
          }
        ],
        "additionalClassifications": [
          {
            "id": "72250000",
            "scheme": "CPV",
            "description": "System and support services"
          },
          {
            "id": "72250000-FB09",
            "scheme": "CPVS",
            "description": "For security system"
          }
        ]
      }
    ],
    "title": "Provision of Security Incident Event Management Tool",
    "status": "planned",
    "legalBasis": {
      "id": "32014L0024",
      "scheme": "CELEX"
    },
    "description": "Provision of a Security Incident Event Management Tool:\nThe Crown Prosecution Service (CPS) is issuing a Prior Information Notice (PIN) to inform prospective suppliers of its intention to procure a Security Information and Event Management (SIEM) tool.\nCPS will go to market for a new SIEM system as part of its overall cybersecurity strategy.",
    "communication": {
      "futureNoticeDate": "2024-01-31T00:00:00Z"
    },
    "classification": {
      "id": "72250000",
      "scheme": "CPV",
      "description": "System and support services"
    },
    "mainProcurementCategory": "services"
  },
  "parties": [
    {
      "id": "GB-FTS-90184",
      "name": "Crown Prosecution Service",
      "roles": [
        "buyer"
      ],
      "address": {
        "region": "UKI3",
        "locality": "LONDON",
        "postalCode": "SW1H 9EA",
        "countryName": "United Kingdom",
        "streetAddress": "102 Petty France"
      },
      "details": {
        "url": "https://www.cps.gov.uk",
        "classifications": [
          {
            "id": "MINISTRY",
            "scheme": "TED_CA_TYPE",
            "description": "Ministry or any other national or federal authority, including their regional or local subdivisions"
          },
          {
            "scheme": "COFOG",
            "description": "Provision of a Security Incident Event Management Tool"
          }
        ]
      },
      "identifier": {
        "legalName": "Crown Prosecution Service",
        "noIdentifierRationale": "notOnAnyRegister"
      },
      "contactPoint": {
        "name": "Patience Arinaitwe",
        "email": "patience.arinaitwe@cps.gov.uk"
      }
    }
  ],
  "language": "en",
  "initiationType": "tender"
}
Complete JSON history (1 releases)
14 Aug 2023 · 023781-2023 · planning
{
  "id": "023781-2023",
  "tag": [
    "planning"
  ],
  "date": "2023-08-14T16:42:21+01:00",
  "ocid": "ocds-h6vhtk-03efa9",
  "buyer": {
    "id": "GB-FTS-90184",
    "name": "Crown Prosecution Service"
  },
  "tender": {
    "id": "ocds-h6vhtk-03efa9",
    "lots": [
      {
        "id": "1",
        "status": "planned",
        "description": "The Crown Prosecution Service (CPS) is issuing a Prior Information Notice (PIN) to inform prospective suppliers of its intention to procure a Security Information and Event Management (SIEM) tool.\nCPS will go to market for a new SIEM system as part of its overall cybersecurity strategy.\nAs a minimum, the tool should provide the following functionality:\n1. Log Collection and Aggregation: The SIEM should be capable of collecting and aggregating logs and data from various sources across the CPS, such as network devices, servers, applications, cloud infrastructure, and endpoints/end-user-devices.\n2. Integration and Compatibility: The SIEM should integrate seamlessly with existing security tools and technologies, such as intrusion detection/prevention systems (IDS/IPS), firewalls, antivirus solutions, and threat intelligence feeds.\n3. Real-time Monitoring: The SIEM should provide real-time monitoring capabilities to detect and alert on suspicious or malicious activities as they occur. This involves continuous analysis of incoming log data to identify anomalies and patterns indicative of security threats.\n4. Event Correlation and Analysis: The system should be able to correlate and analyse events from multiple sources to identify complex attack patterns that may go unnoticed when analysing individual events in isolation.\n5. Threat Detection and Alerts: The SIEM should have threat detection mechanisms that can identify known threats based on signatures and behaviours, as well as emerging threats using advanced analytics and machine learning techniques. It should generate timely and actionable alerts for security teams.\n6. Incident Response: The SIEM should facilitate efficient incident response by providing workflow and case management capabilities. This allows security teams to track, investigate, and remediate security incidents effectively.\n7. Automated Remediation: The SIEM should be capable of integrating with network services and infrastructure to automatically mitigate significant threats in real time.\n8. Data Retention and Storage: A SIEM system must be capable of storing and managing large volumes of log data over extended periods to support historical analysis, compliance requirements, and forensic investigations. An indicative estimate is 50TB of data over a rolling year.\n9. Scalability: The SIEM should be scalable to accommodate growing data volumes and an expanding IT infrastructure. It should be able to handle the increasing demands of log collection, analysis, and storage.\n10. User and Entity Behaviour Analytics (UEBA): Advanced SIEM systems incorporate UEBA capabilities to establish baselines of normal behaviour for users and entities. Deviations from these baselines can trigger alerts for potential insider threats or compromised accounts.\n11. Compliance and Reporting: The SIEM should assist organisations in meeting regulatory compliance requirements by offering predefined compliance reports and helping to demonstrate adherence to industry standards and regulations.\n12. Advanced Analytics and Machine Learning: Employing machine learning and advanced analytics can enhance threat detection by identifying subtle patterns and anomalies that may indicate novel or sophisticated attacks.\nAt this stage, the CPS is seeking to engage with the supply market as part of an information-gathering exercise to understand how suppliers might approach the provision of the services outline above, particularly with regards to any developments in service delivery and innovation.\nSuppliers who wish to express their interest in this potential opportunity should do so via the contact details contained within the notice and shall subsequently be invited to attend a virtual engagement session in which they may present their observations on how the requirements within this Prior Information Notice could be fulfilled.\nThis presentation may take any format and should cover the following areas:\n• the latest developments / capabilities in SIEM technology\n• a cost estimation - provide a comprehensive breakdown of potential cost associated with the service provision to the CPS. This should include: setup costs, ongoing service costs, any cost related to customisation, support, or upgrades as well as any other incidental costs that may be incurred during the service."
      }
    ],
    "items": [
      {
        "id": "1",
        "relatedLot": "1",
        "deliveryAddresses": [
          {
            "region": "UKI3"
          }
        ],
        "additionalClassifications": [
          {
            "id": "72250000",
            "scheme": "CPV",
            "description": "System and support services"
          },
          {
            "id": "72250000-FB09",
            "scheme": "CPVS",
            "description": "For security system"
          }
        ]
      }
    ],
    "title": "Provision of Security Incident Event Management Tool",
    "status": "planned",
    "legalBasis": {
      "id": "32014L0024",
      "scheme": "CELEX"
    },
    "description": "Provision of a Security Incident Event Management Tool:\nThe Crown Prosecution Service (CPS) is issuing a Prior Information Notice (PIN) to inform prospective suppliers of its intention to procure a Security Information and Event Management (SIEM) tool.\nCPS will go to market for a new SIEM system as part of its overall cybersecurity strategy.",
    "communication": {
      "futureNoticeDate": "2024-01-31T00:00:00Z"
    },
    "classification": {
      "id": "72250000",
      "scheme": "CPV",
      "description": "System and support services"
    },
    "mainProcurementCategory": "services"
  },
  "parties": [
    {
      "id": "GB-FTS-90184",
      "name": "Crown Prosecution Service",
      "roles": [
        "buyer"
      ],
      "address": {
        "region": "UKI3",
        "locality": "LONDON",
        "postalCode": "SW1H 9EA",
        "countryName": "United Kingdom",
        "streetAddress": "102 Petty France"
      },
      "details": {
        "url": "https://www.cps.gov.uk",
        "classifications": [
          {
            "id": "MINISTRY",
            "scheme": "TED_CA_TYPE",
            "description": "Ministry or any other national or federal authority, including their regional or local subdivisions"
          },
          {
            "scheme": "COFOG",
            "description": "Provision of a Security Incident Event Management Tool"
          }
        ]
      },
      "identifier": {
        "legalName": "Crown Prosecution Service",
        "noIdentifierRationale": "notOnAnyRegister"
      },
      "contactPoint": {
        "name": "Patience Arinaitwe",
        "email": "patience.arinaitwe@cps.gov.uk"
      }
    }
  ],
  "language": "en",
  "initiationType": "tender"
}