Provision of Third Party Assurance Under the Gov Assure Scheme
Value
£25,000
Suppliers
Classifications
- Computer audit consultancy and hardware consultancy services
Tags
- award
Submission Deadline
2 months ago
Published
1 month ago
Description
GovAssure is the new cyber security assurance approach for government that has replaced the cyber security element of the Departmental Security Health Check (DSHC) from April 2023. The GovAssure assurance approach meets the requirements for and objective understanding of government cyber security. Organisations will assess critical systems against one of two target CAF profiles for government, the Baseline or the Enhanced Profile. This will provide organisations and the Security Function with a more effective mechanism to understand the level of cyber resilience across government. GovAssure is designed for OFFICIAL systems and does not currently apply to systems processing data classified as SECRET or above. Higher classification systems will be considered at a later date. GovAssure will apply to government sector Critical National Infrastructure (CNI), bringing them under a common assurance process for cyber. DVLA's Cyber Security team are required to carry out a self-assessment on three of the systems used within DVLA the NCSC Cyber Assurance Framework (CAF). Once the reports have been completed these are required to be uploaded into a Cabinet Office Portal. The DVLA requires a supplier to provide the following service: • Have access to the Cabinet Office Portal. • Carry out an assessment for each of the system reports. • Provide a written report for each system to be uploaded to the portal providing their findings and make recommendations for improvements. • Essential that all supplier staff have engaged in undertaking the work under this contract must be security vetted to at least SC. The supplier will have no access to DVLA systems or personal data, the supplier will follow Cabinet Office direction on assessment and report formats. Only the successful supplier will have access to the DVLA reports within the Cabinet Office Portal. DVLA will provide DVLA-issued laptops with user accounts for undertaking the work under this contract. Remote working will be permitted using the secure remote working solution provided by DVLA, but the successful company will need to arrange to securely collect the devices and to securely return them on completion of the contract. The devices will be provided only to undertake the work under this contract and must not be used to connect to any other network or undertake any other activity without authorisation from DVLA. The supplier must be able to carry out this service and provide the relevant reports by Mid-October. On completion of the reports DVLA are required to sign off/accept the contents of the report by Mid-November. All reports will be assessed by Cabinet Office and an improvement plan will be provided. It is envisaged that Vehicles CASP and Tachos are of high complexity with the Payment Broker being within the mid-tier range. These systems will be assessed using the BASELINE Profile
Similar Contracts
Open
London Borough of Waltham Forest
Published 4 months ago
Open
Manchester Metropolitan University
Published 1 year ago
Open
Manchester Metropolitan University
Published 1 year ago
AI Bid Assistant
Our AI-powered tool to help you create winning bids is coming soon!
Organisation
Timeline complete
Complete