خدمات الأمن السيبراني لدعم الاستراتيجيات التقنية لمركز الذكاء الاصطناعي NCAI-HPCCYB
الهيئة السعودية للبيانات والذكاء الاصطناعي
رقم المنافسة
240539018821
المعرّف
#792074
عنوان الضمان الإبتدائى
الهيئة السعودية للبيانات والذكاء الاصطناعي
الغرض من المنافسة
تعتبر المنافسة داعمة لقطاع التمكين الرقمي وذلك لتسريع اعمال تطوير الذكاء الاصطناعي لمبادرات المركز الوطني للذكاء الاصطناعي المتعددة ورفع مستوى الامتثال لمعايير الأمن السيبراني التنظيمية و تحقيق الأهداف الاستراتيجية للأمن السيبراني بمركز المعلومات الوطني و الحد من المخاطر السيبرانية عبر تطبيق الضوابط الأمنية اللازمة ودعم أصحاب المصلحة وتوفير الحوسبة اللازمة لتسهيل إنجاز الأعمال حسب المتطلبات خلال أعمال مبادرات المركز الوطني للذكاء الاصطناعي المتعددة
| التاريخ | ميلادي | هجري |
|---|---|---|
| تاريخ النشر | 2024/08/22 13:34 | — |
| آخر موعد للاستفسارات | 2024/10/10 | 1446-04-07 |
| آخر موعد تقديم العروض | 2024/10/17 10:00 | 1446-04-14 |
| موعد فتح العروض | 2024/10/17 10:00 | 1446-04-14 |
| موعد فحص العروض | — | — |
| التاريخ المتوقع للترسية | 2024/09/30 | 1446-03-27 |
| تاريخ بدء الأعمال | 2024/11/24 | 1446-05-22 |
| تاريخ خطاب تأكيد المشاركة | — | — |
| بداية إرسال الأسئلة | 2024/10/10 | 1446-04-07 |
| أقصى مدة للإجابة | 7 يوم | |
| مكان فتح العروض | الخدمات المشتركة - لجنة فتح العروض | |
| مدة الوقفة | 5 يوم |
موقع التنفيذ
مجال التصنيف
الأنشطة
- • تقنية المعلومات
وصف المنافسة
مقرات الهيئة السعودية للبيانات والذكاء الاصطناعي في مدينة الرياض
جدول 1 المواد - تقنية معلومات
| البند | الفئة | الكمية | وصف البند | المواصفات | وحدة القياس | الرقم التسلسلي | الرمز الإنشائي | منتج من القائمة الإلزامية |
|---|---|---|---|---|---|---|---|---|
| خدمات مدارة لادارة وتشغيل الانظمة Managed Security Services | خدمة | 36 | تركيب وتشغيل البرامج والأجهزة الأمنية المستخدمة وتقديم الدعم اللازم من قبل مزود الخدمة المتعاقد معه حسب المشار اليه في جدول الكميات على ان تكون مدة كل خدمة شهر في مقر الهيئة السعودية للبيانات والذكاء الاصطناعي | يجب على مقدمي خدمات الأمن المُدارة توفير خدمات الكشف والاستجابة المُدارة وخدمات الاستشارة بشأن التهديدات. يجب على مقدمي خدمات الأمن المُدارة توفير حلول مجمعة تشمل الحوسبة والتخزين والشبكة. يجب على مقدمي خدمات الأمن المُدارة توفير الكشف المستمر للثغرات باستخدام أدوات الضعف والتكامل مع حلول منصة الكشف والاستجابة المُدارة. يجب على مقدمي خدمات الأمن المُدارة تقديم تقارير أسبوعية أو شهرية للمنظمة بشأن الخدمات المشتركة مع مقدمي خدمات الأمن المُدارة. يجب على مقدمي خدمات الأمن المُدارة توفير ثلاثة مهندسين في الأمن السيبراني لإدارة الضوابط الأمنية المقترحة في الطلب. يجب على مقدمي الخدمات الأمنية المُدارة إجراء تحقيقات عميقة واستجابة للحوادث. | شهر | 1 | 0 | |
| تركيب وضبط اعدادات أمن الحاويات containers security | جهاز | 1 | تركيب وضبط اعدادات أمن الحاويات containers security لتأمينها على البيئة السحابية الخاصة بالمركز | Bidder should do the configuration and installation | عدد | 2 | 0 | |
| أمن الحاويات containers security | خدمة | 1 | لاضافة طبقة الحماية السيبرانية للحاويات | General . • Must be a cloud native platform architecture capable of being deployed on different architectures i.e. container, serverless or public cloud. • Must support a non-intrusive deployment i.e. No appliances or Agents. • Supports automated deployments tools and can leverage APIs for onboarding. • "Supports RBAC model for separation of duties and data - Read Only. - Role for adding cloud accounts.. - Limit access to specific accounts or account groups. Support integration of SSO and Federation providers via industry standard protocols i.e. SAML. • "Capability to feed alerts to 3rd party workflow tools in addition to visualising in the Prisma dashboard • Capability to tune alerts generated and customise the type of alerts that are sent to the relevant workflow tools and teams. • Solution provides an industry standard RESTFUL API. . • Containers (K8 - Managed/Unmanaged) Docker + others. • "Deploy out as a cloud native solution without requiring any agents or additional layers being added to container images or underlying cluster.. . • Support deployment on multiple container platforms including:. . - Kubernetes (Cloud hosted EKS, AKS and GKE). - Other variants (Openshift, Pivotal etc). - Docker (stand alone and Swarm). - ECS". • Management platform flexibility to allows hosted SaaS or customer hosted container based management console. • "Kubernetes Deployment options:. . - Scripted. - Deployment manifest YAML. - Helm charts". . . . • Provide protection for cloud functions, deploy into the function.. • Discover cloud functions and vulnerabilities via cloud provider APIs. . • Hosts (Linux, Windows). . • "Deploy out as a cloud native solution that supports a deployment on multiple host platforms including:. . - Windows. - Linux". • Management platform flexibility to allows hosted SaaS or customers self hosted management console. . . Vulnerability Assessment Requirement. General . . • Provides high level visualisation on any vulnerabilities that exist . • Filter based on severity of vulnerability. • Capability to export vulnerability assessment information via API, CSV or integration with other platforms . • Allows filtering of vulnerabilities based on specific criteria i.e. CVE number. • Automatic updating of vulnerability feeds without operational overhead. • Where possible, provide mappings against well known vulnerability standards bodies and metrics i.e CVE and leverage common scoring mechanisms i.e. CVSS. . IAC. . • Capability to scan in the CI phase prior to deployment of instances i.e. Terraform , Cloud Formation . . • Containers (K8 - Managed/Unmanaged) Docker + others. . • Ensure that any vulnerability scanning doesn't require changes to be made to the container image via insertion of agents or similar mechanism. • Capability to scan all container images for vulnerabilities irrespective of whether they are deployed in Public Cloud , On-Premise, Hybrid or air gapped environments. • "Perform Vulnerability assessment at the CI (Continuous Integration) phase of the DevOps build pipeline by plugging into well known build platforms i.e.. . - Jenkins. - CircleCi. - Azure DevOps , AWS codepipeline and others. . • Perform integration capability for other lesser known build platforms.. . • Where possible, provide vulnerability metrics directly within the build platform and the option to fail the build if vulnerabilities of a given severity are discovered". • Allow developers to scan a stand alone container image prior to checking into a registry, build pipeline or running. • "Capability to scan container registries to ensure ongoing health of container image, examples include:. . - Azure Container Registry. - Docker Hub. - Google Container Registry. - AWS EC2 container registry. - Nexus Sonar. - JFrog . . • Many more providing they are Docker Registry 2.0 compliance". • Capability to discover vulnerabilities in running container images within the environment. • Platform provides the capability to concisely visualise vulnerabilities at the Build, Deploy and Run. • Capability to drill down on each container image and visualise the exact layer(s) where vulnerabilities exist, enable fast feedback via integration with DevOps workflows. • "Capability to understand each vulnerability in-depth and threat vectors that may raise the risk profile in the environment.. . - Ease of attack. - Threat Vectors i.e. Network based. - If a fix is available and how long has the vulnerability existed.. - Traits of running containers that elevate risk. - Detailed CVE information and remediation details.. - Understand which containers and hosts the vulnerability exist on.. - Impacted packages/ frameworks.. - Percentage of environment impacted". • The capability to define your own custom vulnerability checks. • "Configure proactive policies to alert on or prevent deployment of vulnerable images into a production environment.. . • Policies should be tunable based on the severity level, labels, images and other factors". • In high security environments that are air-gapped, provide a mechanism to update vulnerability signatures. • Vulnerability managemnt should cover Git Repo including Java , Python & ode repositories on git. . • Serverless - Lambda, Azure, GCP Functions. . • Automatically discover vulnerabilities for Serverless functions including any vulnerabilities in function libraries. • """Capability to understand each vulnerability in-depth and threat vectors that may raise the risk profile in the environment.. . - Ease of attack. - Threat Vectors i.e. Network based. - If a fix is available and how long has the vulnerability existed.. - Detailed CVE information and remediation details.. - Impacted packages/ frameworks.. • Hosts (Linux, Windows). . • Capability to scan all supported hosts for vulnerabilities irrespective of whether they are deployed in Public Cloud , On-Premise, Hybrid or air gapped environments. • Capability to discover vulnerabilities in running hosts within the environment as well as AWS AMI. • "Capability to understand each vulnerability in-depth and threat vectors that may raise the risk profile in the environment.. . - Ease of attack. - Threat Vectors i.e. Network based. - If a fix is available and how long has the vulnerability existed. - Detailed CVE information and remediation details. - Understand which containers and hosts the vulnerability exist on. - Impacted packages/ frameworks.. - Percentage of environment impacted". • The capability to define your own custom vulnerability checks. • "Configure proactive policies to alert on or prevent deployment of vulnerable hosts into a production environment (Linux hosts only).. . • Policies should be tunable based on the severity level, labels, images and other factors". • In high security environments that are air-gapped, provide a mechanism to update vulnerability signatures. • Have the ability to apply vulnerability rules when when vendor fixes are available. . • Customer specific use cases. . . Compliance Requirement. General . . • Provides high level visualisation on any compliance violations across the environment for the different architectures i.e. Public Cloud, Container or Serverless. • Filter based on severity of compliance failure. • Capability to export compliance violation events via API, CSV or integration with other platforms i.e Slack, SOAR (Demisto), Jira, Email. • Allows for filtering and searching for specific compliance checks via name, resource impacted or severity plus other metrics i.e. cloud accounts, labels.. • Automatic updating of vulnerability feeds without operational overhead. • Where possible leverage well known compliance standards and regulatory frameworks i.e. NIST, CIS, GDPR PCI, ISO. • Ensure continuous and automatic scanning for compliance without the operators having to manually set and schedule scans. . . • Containers (K8 - Managed/Unmanaged) Docker + others. . • Ensure that any compliance scanning doesn't require changes to be made to the container image via insertion of agents or similar mechanism. • Capability to scan all container images for compliance violations irrespective of whether they are deployed in Public Cloud , On-Premise, Hybrid or air gapped environments. • "Provide out of the box baselining against well know standards and frameworks for container images, runtime and kubernetes configuration. - CIS (Docker & Kubernetes). - NIST 800-190. - PCI. - GDPR". • "Perform compliance audit at the CI (Continuous Integration) phase of the DevOps build pipeline by plugging into well known build platforms i.e.. . - Jenkins. - CircleCi. - Azure DevOps and others. . • Perform integration capability for other lessor know build platforms.. . • Where possible, provide vulnerability metrics directly within the build platform with the option to fail the build if compliance violations of a given severity are discovered". • Allow developers to scan a stand alone container image prior to checking into a registry, build pipeline or running. • "Capability to scan container registries to ensure ongoing compliance of images, examples include:. . - EC2 container registry. - Nexus Sonar. - JFrog . . • Many more providing they are Docker Registry 2.0 compliance". • Capability to discover compliance violations in existing running containers within the environment. • Platform provides the capability to concisely visualise compliance violations at the Build, Deploy and Run. • The capability to define your own custom compliance checks. • "Configure proactive policies to alert on or prevent deployment of non-compliant images into a production environment.. . • Policies should be tunable based on the severity level, labels, images and other factors". • In high security environments that are air-gapped, provide a mechanism to update compliance signatures. • Capability to only allows the use of "Trusted images". • "Understand what images are running in the enviroment and allow only ""Trusted Images"" to run.. . - Control via registry. - Repo. - Individual Image. - Base layers of image". . • Serverless - Lambda, Azure, GCP Functions. . • "Automatically discover compliance violations for Serverless functions including:. . - Embedded Private keys and passwords. - Overly permissive access. - Broad resource access. - Unused services that the function can access. - Suspicious function actions". • """Capability to understand each compliance failure.. . - Ease of attack. - Threat Vectors i.e. Network based. - If a fix is available and how long has the violation existed.. - Impacted functions. • ". • Hosts (Linux, Windows). . • Capability to scan all container images for compliance violations irrespective of whether they are deployed in Public Cloud , On-Premise, Hybrid or air gapped environments. • "Provide out of the box baselining against well know standards and frameworks for hosts including Windows, Lunix, Docker host/ daemon/ security ops, Kubernetes master/worker/ federation:. . - CIS (Docker & Kubernetes). - NIST 800-190. - PCI. - GDPR". • Capability to discover compliance violations in existing running hosts within the environment. • The capability to define your own custom compliance checks. • In high security environments that are air-gapped, provide a mechanism to update compliance signatures. • Perform checks look at the Windows host’s configuration of the Windows Firewall, Windows Defender / anti-malware, and Windows Update configuration. • Ability to implement security around files and directories in your monitoring profile for changes - File Integrity Monitoring (FIM). . • Customer specific use cases. . Incident Response and Protection Requirement. General . . • Provide dashboarding detailing any incidents or anomalies along with criticality. • Support different types of threat detection capabilities including static signature, learning and behavioural analysis. • Capability to export compliance violation events via API, CSV or integration with other platforms • Allows for filtering and searching for specific incidents via name, resource impacted or severity plus other metrics i.e. cloud accounts, labels. • Automatic updating of threat intelligence feeds. • Behavioural and learning based models must be automatic without requiring the operator to manually setup thresholds etc. . . • Containers (K8 - Managed/Unmanaged) Docker + others. . • "The platform can baseline container images and their expected behaviours via a combination of static analysis of dockerfiles and deployment manifest combined with dynamic analysis of a running container, this should include:. . - Network activity. - Processes. - File System. . • Container capabilities i.e. Does it have elevate access". • Capability to relearn baseline . • "Capability to report when there is a deviation or abnormal activity compared to the baseline i.e. . . - New process spawned. - Network comms that differs from the baseline. - Exec access to containers". • "Leverages threat intelligence to spot malicious or abnormal behaviour i.e. . . - Crypto Mining. - Malware. - Communication with high risk domains/destinations. - Lateral Movement". • Capability to drill down on incidents and perform forensic investigation and capture/export information related to the incident. • Allows proactive protection against certain incidents including the capability to prevent rogue processes and network activity or in extreme cases to terminate a running container, this should be possible through a flexible policy that can be tailored based on container images, namespace or labels. • The platform automatically maps and learns network activity between the container images in the environment. • Provide a zero trust architecture by implementing microsegmentation to limit lateral movement . • "Provide layer 7 Web application protection for containers hosting web apps, protection should include, protections should include:. . - CSRF Protection. - XSS Protection. - Clickjacking protection. - SQL Injection protection. - Attack Tool protection . - Malformed request protection. . • ". . . . • Serverless - Lambda, Azure, GCP Functions. . • "Automatically discover compliance violations for Serverless functions which could lead to incidents including:. . - Embedded Private keys and passwords. - Overly permissive access. - Broad resource access. - Unused services that the function can access. - Suspicious function actions". • "Capability to protect functions including:. . - Network. - Process. • ". • Hosts (Linux, Windows). . • "The platform can baseline hosts and their expected behaviours, this should include:. . - Network activity. - Processes". • Capability to relearn baseline learned behaviours. • "Capability to report when there is a deviation or abnormal activity compared to the baseline i.e. . . - New process spawned. - Network comms that differs from the baseline. - Exec access to containers". • "Capability to report when there is a deviation or abnormal activity compared to the baseline i.e. . . - Network comms that differs from the baseline. - App Capabilites. - Application Control / Whitelisting. - Log Inspection. - User, Application and Application Activites. - File Integrity Monitoring". • Capability to drill down on incidents and perform forensic investigation and capture/export information related to the incident. • Allows proactive protection against certain incidents including the capability to alert on rogue applications on hosts, this should be possible through a flexible policy. • The platform automatically maps and learns network activity between hosts in the environment. • Provide a zero trust architecture by implementing microsegmentation to limit lateral movement . • "Provide layer 7 Web application protection for hosts withweb apps, protection should include, protections should include:. . - CSRF Protection. - XSS Protection. - Clickjacking protection. - SQL Injection protection. - Attack Tool protection . - Malformed request protection. • Customer specific use cases | عدد | 3 | 0 | |
| Encryption Key Management | خدمة | 100 | Encryption Key Management - Hardware Security Modules . Certificate-Based Authentication for outside developers | Encryption Key Management - Hardware Security Modules . Certificate-Based Authentication for outside developers | عدد | 4 | 0 | |
| خدمات تقييم و اختبارات امنية لانظمة البيئة السحابية | خدمة | 36 | خدمة تشغيلية واحترافية لمتطلبات اختبارات الأمن السيبراني لأنظمة البيئة السحابية | • يتطلب من مقدم العطاء استخدام الأدوات والخبرات التقنية للبيئات السحابية من خلال خبراء ذات خبرة عملية في هذا المجال ويشمل نطاق العمل عمل تقييم ومراجعة الإعدادات للأنظمة السحابية بما يشمل:. - مراجعة الاعدادات الأمنية لأنظمة البيئة السحابية المختلفة مع التدقيق على قياس مدى الالتزام بالمعايير والضوابط الامنية. - يلتزم مقدم الخدمة بالتأكد من تطبيق افضل ممارسات الامنية المعتمدة من الشركات الأم بالإضافة الى . - الكشف عن الثغرات الأمنية بشكل اوتوماتيكي باستخدام أدوات الاختبارات الأمنية لمكونات البيئة السحابية مثل المنصات السحابية والخوادم وأجهزة الشبكة. - مراجعة التصاميم التقنية للمكونات السحابية والأنظمة المستضافة بالإضافة الى فحص الاعدادات والقواعد المطبقة. - انشاء وتطوير المراجع الأمنية المعتمدة لجميع المكونات السحابية Minimum Security Baseline-Standards وتعزيز المتطلبات الأمنية بتطوير الخدمات السحابية والتطبيقات المقدمة من خلال منصات الاتمتة السحابية Cloud Management Platform. - التطوير وتعزيز المعايير الأمنية لنظم إدارة الحاويات السحابية (Kubernetes & Containers) بما يدعم أنشطة التطوير ونشر الحاويات على الخوادم المتعددة | شهر | 5 | 0 | |
| جهاز المبدل للانترنت Internet Switch | اجهزة | 2 | لربط الشبكة والأجهزة الداخلية | . • 48 x RJ45 10/100/10000Mb auto- sensing ports, SFP+ ports, 2 x stacking ports, 1x PSU included. . • 24 x RJ45 10/100/10000Mb auto- sensing ports, SFP+ ports, 1x PSU included. . • 8 x RJ45 10/100/1000Mb auto- sensing ports, 2 x SFP ports, 1 x PSU included. . • Support for minimum of 8 switches per stack for 24 port and 48 port switches . • Must support Comprehensive enterprise-class Layer 2/3 feature set on 24/48 port switches . • The switch (24/48) must support Layer 3 routing and must be offered with its highest available licensing model . • Switch must be compliant . • Switch should be SDN Open Flow ready . • Standards Support . • 802.3 – 10 Base-T . • 802.3u – 100 Base-T . • 802.3ab – 1000 Base-T . • 802.3ac – VLAN Tagging . • 802.3ad – Link Aggregation . • 802.3ae – 10 GigE . • 802.1D – Spanning Tree, GARP and GVRP . • 802.1S – Multiple Spanning Tree . • 802.1W – Rapid Spanning Tree . • 802.1Q – Virtual LANs with Port-based VLANs . • 802.1v – Protocol-based VLANs . • 802.1p – Ethernet Priority with User Provisioning and Mapping . • 802.1X – Port-based Authentication . • 802.2 . • 802.3x – Flow Control . • 802.1AB – LLDP . • 802.1p . • SNMP v1/v2/v3 . • IGMP snooping v1/v2V3 . • IGMP Snooping Querier . • For 24 and 48 port switches, should support routing static capabilities.. • The proposed switch must have 3 years vendor support with 7x24 service. . • The Quantity for the 48 port switches must be 1. • The Quantity for the 24 port switches must be 2. • The Quantity for the 8 port switches must be 1 | عدد | 6 | 0 | |
| جهاز المبدل للمنطقة المحايدة DMZ Switch | اجهزة | 2 | لربط الشبكة والأجهزة الداخلية | . • 48 x RJ45 10/100/10000Mb auto- sensing ports, SFP+ ports, 2 x stacking ports, 1x PSU included. . • 24 x RJ45 10/100/10000Mb auto- sensing ports, SFP+ ports, 1x PSU included. . • 8 x RJ45 10/100/1000Mb auto- sensing ports, 2 x SFP ports, 1 x PSU included. . • Support for minimum of 8 switches per stack for 24 port and 48 port switches . • Must support Comprehensive enterprise-class Layer 2/3 feature set on 24/48 port switches . • The switch (24/48) must support Layer 3 routing and must be offered with its highest available licensing model . • Switch must be FreshAir compliant . • Switch should be SDN Open Flow ready . • Standards Support . • 802.3 – 10 Base-T . • 802.3u – 100 Base-T . • 802.3ab – 1000 Base-T . • 802.3ac – VLAN Tagging . • 802.3ad – Link Aggregation . • 802.3ae – 10 GigE . • 802.1D – Spanning Tree, GARP and GVRP . • 802.1S – Multiple Spanning Tree . • 802.1W – Rapid Spanning Tree . • 802.1Q – Virtual LANs with Port-based VLANs . • 802.1v – Protocol-based VLANs . • 802.1p – Ethernet Priority with User Provisioning and Mapping . • 802.1X – Port-based Authentication . • 802.2 . • 802.3x – Flow Control . • 802.1AB – LLDP . • 802.1p . • SNMP v1/v2/v3 . • IGMP snooping v1/v2V3 . • IGMP Snooping Querier . • For 24 and 48 port switches, should support routing static capabilities.. • The proposed switch must have 3 years vendor support with 7x24 service. . • The Quantity for the 48 port switches must be 1. • The Quantity for the 24 port switches must be 2. • The Quantity for the 8 port switches must be 1 | عدد | 7 | 0 | |
| FC Cables LC LC LC MC | اجهزة | 100 | Cables | FC Cables LC-LC, LC-MC• Fiber Optic SFP Single mode 1Gig/10Gig• Length 3 mtr• Single mode, 8 core - Fiber Optic Cable.• Fiber Optic Patch Panel: Single Mode Duplex LC Fully Loaded 8/16 port.• Fiber Optic LC Duplex Patch chords 3mtrs• Heat Shrink Sleeves, Pigtails, Alcohol Pads, Labelling and all other required accessories for splicing. | عدد | 8 | 2114 | 1 |
| UTP Cables Cat 7 | اجهزة | 100 | Cables | • UTP Cat7 Patch Chords 3mtrs | عدد | 9 | 0 | |
| جهاز المبدل للأدارة MGMT Switch | اجهزة | 2 | . • 48 x RJ45 10/100/1000Mb auto- sensing ports, SFP+ ports, 2 x stacking ports, 1x PSU included. . • 24 x RJ45 10/100/1000Mb auto- sensing ports, SFP+ ports, 1x PSU included. . • 8 x RJ45 10/100/1000Mb auto- sensing ports, 2 x SFP ports, 1 x PSU included. . • Support for minimum of 8 switches per stack for 24 port and 48 port switches . • Must support Comprehensive enterprise-class Layer 2/3 feature set on 24/48 port switches . • The switch (24/48) must support Layer 3 routing and must be offered with its highest available licensing model . • Switch must be FreshAir compliant . • Switch should be SDN Open Flow ready . • Standards Support . • 802.3 – 10 Base-T . • 802.3u – 100 Base-T . • 802.3ab – 1000 Base-T . • 802.3ac – VLAN Tagging . • 802.3ad – Link Aggregation . • 802.3ae – 10 GigE . • 802.1D – Spanning Tree, GARP and GVRP . • 802.1S – Multiple Spanning Tree . • 802.1W – Rapid Spanning Tree . • 802.1Q – Virtual LANs with Port-based VLANs . • 802.1v – Protocol-based VLANs . • 802.1p – Ethernet Priority with User Provisioning and Mapping . • 802.1X – Port-based Authentication . • 802.2 . • 802.3x – Flow Control . • 802.1AB – LLDP . • 802.1p . • SNMP v1/v2/v3 . • IGMP snooping v1/v2V3 . • IGMP Snooping Querier . • For 24 and 48 port switches, should support routing static capabilities.. • The proposed switch must have 3 years vendor support with 7x24 service. . • The Quantity for the 48 port switches must be 1. • The Quantity for the 24 port switches must be 2. • The Quantity for the 8 port switches must be 1 | عدد | 10 | 0 | ||
| تقنية الوسيط proxy | نظام | 2 | يعمل على توفير الحماية للمستخدمين من كشف العنوان الخاص بهم وفحص الترافيك الداخل / الخارج من/الى الانترنت وتطبيق بعض السياسات الخاصة بتصفح الانترنت | System information. License Capacity . • 500–4,000 users. . Hardware Specifications. • 8 GB. Management. • HTTP/S, SSH, CLI, SNMP, Console RJ45. . Network Interfaces . • 4x GE RJ45. Storage. • 4 TB (2 TB x2) Hard Disk. Power Supply . • Single (Optional Dual). Form Factor. • 1U Appliance. Input Voltage . • 100–240V, AC 60–50 Hz. Power Consumption . (Average / Maximum) 120 W / 151 W. Maximum Current. • 100V/5A, 240V/3A. Heat Dissipation. • 550 BTU/h. Operating Temperature . • 32–104°F (0–40°C). Storage Temperature. • -13–158°F (-25–70°C). Humidity. • 5–95% non-condensing. FEATURES SUMMARY. . System. . • Wide range of deployment options:. • Inline, Forward Proxy, Explicit proxy, WCCP/PBR. • Hardware or virtual appliance. • IPv4 and IPv6 address support. • Application Support including HTTP/S. • HA available as active-active and active-backup with. • session synchronization . . Authentication. . • Support for various authentication modes including Radius,. • SAML, LDAP, NTLM, Kerberos. • Password. • In-built authentication requiring no additional device. . . Threat Protection. . • Integration with threat intelligence services for real-time threat updates. • Integration with cloud sandbox to detect advanced threats. • In-built security services requiring no additional appliance. • DNS and Web-Filtering. • Dynamic categorization of websites. • Blocking of malicious and suspicious domains and URLs. • Static blacklists and whitelists. • Application Control. • Granular web application control for social websites. • Support for 3000+ applications. • Antivirus, bonet and DLP. • Content Analysis. • Multiple ICAP servers support. • IPS signature and filters. • Web Rating Override. • SSL/SSH Inspection. • Custom Application Signature. . . Advanced Caching. . • Web and video caching. • Reverse web cache. • Traffic Shaping and QoS policies to prioritize Apps. • Dynamic adaptive streaming over HTTP. • Dynamic adaptive streaming over RTP and RTMPT. . . WAN Optimization. . • Protocol Optimization – support HTTP, MAPI, CIFS, FTP,. • and TCP. • Secure tunneling over across WAN. • Wan Optimization peers. . Management and Reporting. . • Support Syslog server. • Granular role based access. • Reporting and Logging. • Policy tests for ease of deployment | عدد | 11 | 0 | |
| جهاز المبدل الداخلي Core DC Switch | اجهزة | 2 | لربط الشبكة والأجهزة الداخلية | . Up to 6.4 Tbps switching capacity with up to 2 Bpps of forwarding performance.. . ● Up to 36 MB of unified buffer per ASIC.. . ● Intel 2.4-GHz x86 CPU with up to 120 GB of USB 3.0 or up to 960 GB of SATA SSD storage for container-based application hosting.. . ● Up to 32 nonblocking 100 Gigabit Ethernet QSFP28 ports.. . ● Up to 32 nonblocking 40 Gigabit Ethernet QSFP+ ports.. . ● Up to 48 nonblocking 25 Gigabit Ethernet SFP28 ports.. . ● Up to 48 nonblocking 10 Gigabit Ethernet SFP+ ports.. . ● Scalable Layer 3 routing (IPv4, IPv6, and multicast) tables and Layer 2 switching tables.. . ● Hardware support for Application Hosting (e.g. with Cisco ThousandEyes Enterprise Agent).. . ● 802.1ba AV Bridging (AVB) built in to provide a better AV experience through improved time synchronization and QoS.. . ● Precision Time Protocol (PTP; 1588v2) provides accurate clock synchronization with sub-microsecond accuracy, making it suitable for distribution and synchronization of time and frequency over the network.. . ● Support for both static and dynamic NAT and Port Address Translation (PAT). | عدد | 12 | 0 | |
| جهاز جدار الحماية لمراكز البيانات Data Center Firewall | اجهزة | 2 | لحماية الشبكة وفحص حزم البيانات حزم البيانات الداخلة والخارجة من/الى البنية التحتية واضافة طبقة حماية اضافية على جدار الحماية الخاص بالانترنت | . . General Specification . • Should be provided with Next Generation Firewall licenses for IPS, Advanced Malware Protection and Application Control Service, URL and DNS filtering. • The device should support both Explicit Proxy and Transparent Proxy along with all NGFW features simultaneously on the same appliance without any compromise.. • The solution should support advanced SDWAN features to aggregate multiple WAN interfaces, measure application performance among the links and selecting best exit interface for traffic using measured SLAs without additional license. • The SDWAN feature shall fully support IPv4 as well as IPv6. • The SDWAN feature should support both passive WAN health measurement through synthetic transactions and active WAN health measurement through monitoring application session information. • Should support both SSL certificate inspection and full SSL inspection. Solution should support TLS 1.1, 1.2 and 1.3 deep inspection. • The solution must support native integration with similar products to form a fabric to share visibility, share threat intelligence and automate response.. • The device must have APIs.. • It should have inbuilt feature of Two-Factor Authentication (2FA) for SSL-VPN and for Admin login, without needing a separate software/hardware to deploy the solution.. • The system must have the ability to integrate with external threat feeds and IP reputation sources from both public and private sources . • The proposed system shall provide robust visibility GUI panels and dashboards. Should support HTML5 based Web UI. The Web UI should not have any Java, Flash or ActiveX components as these components can pose considerable security threats due to frequent-vulnerabilities and end-of-support notices.. • The proposed system shall provide administrators ability to assign arbitrary score given based on the perceived risk of certain events such as visit to malicious websites and malware detection. . • Should be able to send logs simultaneously to existing Centralized logging appliance, multiple Syslog servers and SIEM solutions. • The proposed solution should be leader in last Gartner Network Firewall.. • The proposed solution should be leader in last Gartner WAN Edge Infrastructure.. • The proposed solution should be integrated with any authentication and identification platform and support at minimum; Active Directory, LDAP, RADIUS, TACACS+.. • 8x 100GE/40GE QSFP28 slots and 18x 25GE/10GE SFP28 slots, 2 x GE RJ45 Management Ports, SPU NP7 and CP9 hardware accelerated, 2x 2TB storage and 2 AC power supplies. • 3 Year Advanced Threat Protection (IPS, Advanced Malware Protection Service, Application Control). • 3 Year Secure RMA Service. . . . . . | عدد | 13 | 0 | |
| جهاز المبدل المتوسط Intermediate Switches | اجهزة | 2 | لربط الشبكة والأجهزة الداخلية | . • 48 x RJ45 10/100/10000Mb auto- sensing ports, SFP+ ports, 2 x stacking ports, 1x PSU included. . • 24 x RJ45 10/100/10000Mb auto- sensing ports, SFP+ ports, 1x PSU included. . • 8 x RJ45 10/100/1000Mb auto- sensing ports, 2 x SFP ports, 1 x PSU included. . • Support for minimum of 8 switches per stack for 24 port and 48 port switches . • Must support Comprehensive enterprise-class Layer 2/3 feature set on 24/48 port switches . • The switch (24/48) must support Layer 3 routing and must be offered with its highest available licensing model . • Switch must be FreshAir compliant . • Switch should be SDN Open Flow ready . • Standards Support . • 802.3 – 10 Base-T . • 802.3u – 100 Base-T . • 802.3ab – 1000 Base-T . • 802.3ac – VLAN Tagging . • 802.3ad – Link Aggregation . • 802.3ae – 10 GigE . • 802.1D – Spanning Tree, GARP and GVRP . • 802.1S – Multiple Spanning Tree . • 802.1W – Rapid Spanning Tree . • 802.1Q – Virtual LANs with Port-based VLANs . • 802.1v – Protocol-based VLANs . • 802.1p – Ethernet Priority with User Provisioning and Mapping . • 802.1X – Port-based Authentication . • 802.2 . • 802.3x – Flow Control . • 802.1AB – LLDP . • 802.1p . • SNMP v1/v2/v3 . • IGMP snooping v1/v2V3 . • IGMP Snooping Querier . • For 24 and 48 port switches, should support routing static capabilities.. • The proposed switch must have 3 years vendor support with 7x24 service. . • The Quantity for the 48 port switches must be 1. • The Quantity for the 24 port switches must be 2. • The Quantity for the 8 port switches must be 1 | عدد | 14 | 0 | |
| حماية نظام أسماء النطاقات DNS Security | نظام | 1 | خدمة مهمة تقوم بالتأكد من أمرين مهمين هما: صحة مصدر المعلومة ومن صحة المعلومة نفسها (لم يتم تغييرها أو العبث بها) وتستخدم بين النطاقات التي تخدم نفس اسم النطاق لتبادل الملفات بينها | . • The bidder should propose a solution which contain dedicated secure internal DNS and DHCP physical/virtual servers across one datacentre with an overall optimal capacity of 45K DNS QPS and 300 DHCP LPS. • The proposed solution should contain dedicated secure caching DNS with an overall optimal capacity of 23K DNS QPS. • The proposed DNS security solution should contain a dedicated hardware /virtual reporting & analytics server in the main datacentre with total indexing daily capacity of 500MB. • The proposed solution must for 1 and 3 yrs.. • The bidder should propose the below for the SDAIA cloud datacentre. . • The proposed solution should contain dedicated secure internal DNS and DHCP virtual servers across one datacenter with an overall optimal capacity of 75K DNS QPS and 450 DHCP LPS . • The proposed solution should contain dedicated secure caching DNS with an overall optimal capacity of 45K DNS QPS. • The proposed solution should contain dedicated external DNS with an overall optimal capacity of 23K DNS QPS. • The proposed DNS security solution should contain a dedicated virtual reporting & analytics server in the main datacentre with total indexing daily capacity of 5GB. • The proposed solution must for 1 and 3 yrs.. • The proposed solution DNS Firewall solution should leverage on-premises DDI platforms to run the DNS Firewall service.. • The proposed solution should offer internal authoritative DNS, DHCP and hybrid DNS firewalling . • The proposed solution should contain on-premises VM based platforms and should cover 1x datacenters capable of running the DNS Firewall service.. • The proposed DNS Firewall license should be used as a hybrid DNS FW that can support cloud-based DNS Firewalling and on-premises DNS Firewalling at the same time. The on-premises DDI solution and Hybrid DNS FW should both be provided from the same technology vendor. . • The proposed DDI solution should offer flexible licenses that can be moved to/from HW platforms to/from virtual based platforms and vice versa.. • The proposed solution should be capable of integrating thru DNS over TLS with on-premises DDI solution deployed in the network. The DDI solution should be available and produced from the same DNS Firewall vendor.. • The proposed solution should be offered from a technology vendor/manufacturer who is able to offer cloud-based DNS FW for protection against Data Exfiltration over DNS.. • The proposed DNS FW solution should offer support for DNSSEC validation.. • The proposed solution must offer DNS Context-aware Security.. • The proposed solution should be offered from a technology vendor/manufacturer that can support Threat Intelligence from same vendor for DNS based Firewalling.. • The proposed solution should be offered from a technology vendor/manufacturer that should support Threat Intelligence data/IoCs sharing with SIEM and NGFWs thru WAPI calls.. • The proposed solution should be offered from a technology vendor/manufacturer that can offer DNS Firewalling to provide protection against DNS based tunneling, DGA, fast-flux and data exfiltration and infiltration threats.. • The proposed solution should be offered from a technology vendor/manufacturer that can offer DNS Firewalling that should support Behavioral based analytics and detection for DNS based threats.. • The proposed solution should be able to offer DNS Firewalling without any change on the setup leveraging threat intelligence and streamlined behavioral analytics thru machine learning.. • The proposed solution should be capable of integrating with 3rd party security eco-systems from NGFWs and SIEM solutions.. • The proposed solution should be capable of protecting users on-premise behind the network and roaming users or users located in branches that don’t have direct connectivity to the datacenter(s).. • The proposed cloud DNS firewall solution should support DNS caching for better application performance.. • All provided components of the solution including internal DNS, DHCP and hybrid DNS FW should be provided from the same technology vendor.. • The proposed solution must offer cloud based and on-premise based protection against Data Exfiltration over DNS.. • The proposed solution should offer DNS FW leveraging threat intelligence and streamlined behavioral analytics thru machine learning.. • The proposed DNS FW solution should offer support for DNSSEC validation.. • The proposed solution must offer DNS Context-aware Security.. • The proposed solution should support Threat Intelligence based DNS Firewalling.. • The proposed solution should offer Threat Intelligence Data Exchange (TIDE) platform support Threat Intelligence data/IoCs sharing with SIEM and NGFWs thru RESFul WAPI.. • The proposed solution should support cloud based and on-premises based Behavioral based analytics and detection for DNS based threats.. • The proposed solution should be capable of integrating with 3rd party security eco-systems including NGFWs (PaloAlto & Fortinet), Vulnerability Management Systems (Tenable/Qualys/FortiGate/PaloAlto/ServiceNow/Rapid7) and SIEM solutions.. • The secure DDI solution should offer the ability to leverage security eco-system and orchestration using outbound restful API calls and notifications to enable triggering actions and automation across 3rd party systems. . • The secure DNS caching solution should offer the ability to leverage outbound restful API calls and notifications upon DNS security events. Solutions that don’t support outbound API calls will be discarded.. • The proposed solution should be capable of protecting users on-premise behind the network and roaming users or users located in branches that don’t have direct connectivity to the DCs.. • The proposed cloud DNS firewall solution should support DNS caching for better application performance.. • The secure DDI solution should offer DNS firewalling leveraging DNS RPZ threat intelligence that should contain multiple categories of RPZ security feeds. Solutions with single security RPZ feed will be discarded. . • The secure DDI solution should offer be able to offer DNS firewalling with threat intelligence from the same technology vendor that should contain as minimum all below RPZ security feeds:. • Base hostnames: The base hostnames RPZ feed is required to enable protection against known hostnames that are dangerous as destinations and are sources of threats, such as APTs, bots, compromised host/domains, exploit kits, malicious name servers and sinkholes.. • Anti-malware: This RPZ feed enables protection against hostnames containing known malicious threats, such as malware command and control (C&C), malware download and active phishing site.. • Ransomware: This RPZ feed enables protection against hostnames containing malware that restricts access to the computer system it infects and demands a ransom for the removal of the restriction. • Bogon: This RPZ feed enables should contain the source addresses of DDoS attacks and is an informal name for an IP packet on the public Internet that claims to be from an area of the IP address space reserved, but not yet allocated or delegated by an Internet Authority or Registry. Bogons are usually the result of accidental or malicious misconfiguration.. • DHS AIS_IP and DHS AIS_Hostname (2 feeds): AIS is a part of the Department of Homeland Security’s (DHS’s) effort to create an ecosystem in which, as soon as a company or federal agency observes an attempted compromise, the indicator is shared with AIS program partners.. • DHS AIS NCCIC Watch list Hostnames and Domains and DHS AIS NCCIC Watch list IPs (2 feeds): Indicators contained in these feeds appear on the watch list from the National Cybersecurity and Communications Integration Center (NCCIC). | عدد | 15 | 0 | |
| خوادم الداخلية internal server | اجهزة | 3 | خوادم لاستضافة البرامج للأمن السيبراني | • Chassis Chassis with up to 16x2.5" Drives. • Trusted Platform Module Trusted Platform Module 2.0 V3. • Chassis 2.5" Chassis with up to 16 SAS/SATA Drives, 2 CPU. • CPU Gold 6330 2G, 28C/56T, 11.2GT/s, 42M Cache, Turbo, HT (205W) DDR4-2933. • CPU Gold 6330 2G, 28C/56T, 11.2GT/s, 42M Cache, Turbo, HT (205W) DDR4-2933. • Memory Type 3200MT/s RDIMMs. • Memory Type 32GB RDIMM, 3200MT/s, Dual Rank, 16Gb BASE x8. • HDD 2.4TB 10K RPM SAS ISE 12Gbps 512e 2.5in Hot-Plug Hard Drive. • Power Supply Dual, Hot-Plug,Power Supply Fault Tolerant Redundant (1+1), 800W, Mixed Mode. • Rack Power Cord Rack Power Cord 2M (C13/C14 10A). • NIC Motherboard with Broadcom 5720 Dual Port 1Gb On-Board LOM. • NIC Ethernet X710 Quad Port 10GbE SFP+, OCP NIC 3.0. • BOSS-S2 controller card BOSS-S2 controller card + with 2 M.2 240GB (RAID 1). • SFP SFP+ SR Optic, 10GbE, for all SFP+ ports except high temp validation warning cards. • OS VMware ESXi 7.0 U3 Embedded Image (License Not Included). • OS Licenses VMware vSphere 7 Standard for 1 CPU, up to 32 cores, 1YR VMware SNS. • Warranty Warranty 12Months, 12 Month(s). • Support Support and Next Business Day Onsite Service, 12 Month(s). . • Chassis Chassis with up to 16x2.5" Drives. • Trusted Platform Module Trusted Platform Module 2.0 V3. • Chassis 2.5" Chassis with up to 16 SAS/SATA Drives, 2 CPU. • CPU Gold 6330 2G, 28C/56T, 11.2GT/s, 42M Cache, Turbo, HT (205W) DDR4-2933. • CPU Gold 6330 2G, 28C/56T, 11.2GT/s, 42M Cache, Turbo, HT (205W) DDR4-2933. • Memory Type 3200MT/s RDIMMs. • Memory Type 32GB RDIMM, 3200MT/s, Dual Rank, 16Gb BASE x8. • HDD 2.4TB 10K RPM SAS ISE 12Gbps 512e 2.5in Hot-Plug Hard Drive. • Power Supply Dual, Hot-Plug,Power Supply Fault Tolerant Redundant (1+1), 800W, Mixed Mode. • Rack Power Cord Rack Power Cord 2M (C13/C14 10A). • NIC Motherboard with Broadcom 5720 Dual Port 1Gb On-Board LOM. • NIC Ethernet X710 Quad Port 10GbE SFP+, OCP NIC 3.0. • BOSS-S2 controller card BOSS-S2 controller card + with 2 M.2 240GB (RAID 1). • SFP SFP+ SR Optic, 10GbE, for all SFP+ ports except high temp validation warning cards. • OS VMware ESXi 7.0 U3 Embedded Image (License Not Included). • OS Licenses VMware vSphere 7 Standard for 1 CPU, up to 32 cores, 1YR VMware SNS. • Warranty Warranty 12Months, 12 Month(s). • Support Support and Next Business Day Onsite Service, 12 Month(s). . | عدد | 16 | 0 | |
| نظام التدقيق الامني للدليل النشط | نظام | 1 | توريد وتركيب نظام الحماية و التدقيق للدليل النشط | - On-Premise solution that is compliance with all local laws and regulations in Saudi Arabia - Integrated Active Directory, Exchange and Office 365 management - One-click AD, O365, and Exchange user creation - Bulk management of AD objects via CSV import - 200+ pre-packaged, actionable reports - Automation for routine tasks such as AD cleanup - OU-based help desk delegation - Template-based user provisioning - Protect against data loss disasters with AD backup and recovery - Integration with popular SIEM, HR management, and helpdesk software - iOS and Android mobile apps, and much more - Create users in AD, Exchange, Office 365, Google Apps, and Skype for Business (Lync) in a single step - Create or modify AD objects (users, groups, contacts, OUs, and computers) in bulk via CSV import - Perform AD tasks such as password reset, account unlock, clean up, and more - Streamline the management of AD objects such as users and OUs with customizable templates - Assign, replace, or revoke Office 365 licenses in bulk. Manage shared, remote, room, and equipment mailboxes - Create backups of AD objects and restore all attributes of an object or only specific attributes - Generate and schedule more than 200 preconfigured, granular reports on AD, Exchange, Office 365, and Google Apps - View inactive users, locked out users, disabled computers, and more in just few clicks - Create custom AD reports to obtain the exact data that you require - Export to a number of formats including HTML, PDF, XLS, XLSX, CSV, and CSVDE - Mention specific users or computers in a CSV file for generating their important details - Generate compliance reports to meet regulatory standards such as SOX, HIPAA, and more - Granularly delegate AD, Office 365, and G-Suite tasks to help desk technicians for specific Ous - Delegate tasks such as resetting passwords, creating users, and more - Delegate without elevating technicians' privileges in Active Directory - Automate routine Active Directory tasks such as AD clean up - Configure a review-approval workflow to execute AD tasks with a structured flo - Exercise control over automated tasks by using workflow with automation - Manage users from anywhere- Reset passwords; unlock, enable, disable and delete accounts - View reports on locked out, disabled, password, expired and inactive users - View, manage, and execute AD workflow requests - Audit Windows file servers, failover clusters, NetApp, and EMC storage to document changes to files and folders - Track changes across Windows servers, printers, and USB devices with a summary of events - Leverage advanced statistical analysis and machine learning techniques to detect anomalous behavior and defend against cyber attacks - Monitor, report, and alert on domain controllers in real time - Utilize over 200 detailed, event-specific GUI reports - Track changes to Group Policy and all AD objects - Track logons and logoffs to workstations - View and schedule graphical reports - Report on employee attendance, total active and idle time - Monitor activity on terminal services - Track file creation, modification, and deletion - Get forensics on security and permission changes - Monitor network shares AD45 Utilize file integrity monitoring (FIM) - Also monitor, alert and report on AD FS, AD LDS, LAPS, DNS, NAS devices, scheduled tasks and processes, Windows security log and other system events - Track all changes to Windows AD objects including users, groups, computers, GPOs, and OUs. - Achieve AD monitoring with a single, correlated view of all the activities - Monitor every user's logon and logoff activity, including every successful and failed logon attempt across network workstations - Audit Windows file servers, failover clusters, NetApp, and EMC storage to document changes to files and folders - Audit file access - Monitor system configurations, program files, and folder changes to ensure file integrity - Audit removable storage devices. Audit print servers - Monitor RADIUS logons | عدد | 17 | 0 | |
| خادم server | اجهزة | 1 | خوادم لحفظ وتوفير التقارير دورية وللمراقبة بشكل عام | • M640 Chassis - 2.5". • 2 x Gold 5220 -2.2Ghz - 16 Core. • 8x 16GB DDR4 2666Mhz RDIMM. • 16 x 900 GB 15K SAS drives. • PERC H330 Mini Blade Controller (RAID 0/1/5/10/50). • 2 x Pass Through Mezz Adapter - VRTX. • Intel X520 10GbE DP KR NDC. • IDSDM with 2 x 16GB SC cards. • Dell iDRAC9 License Enterprise. . | عدد | 18 | 0 | |
| نظام ادارة صلاحيات دخول مسؤول الانظمة PAM | اجهزة | 50 | توريد وتركيب نظام ادارة صلاحيات دخول مسؤول النظام | "يجب توريد وتركيب نظام ادارة صلاحيات دخول مسؤول النظام PAM الحلول مع كامل مستلزماتها. . توفير الحلول الازمة مع الرخص التشغيلية لمدة 3 سنوات. يجب الالتزام بالمواصفات المطلوبة حسب الآتي:. The product should be deployed in a variety of footprints including a physical appliance, a VMware virtual appliance, , and provide equivalent capabilities in each.. The product provides a bastion-host gateway to broker - as proxy - user access to managed target devices (*NIX, Windows, etc.) with a zero-trust posture.. The solution must be based on a fully featured Appliance, with at least Open Authentication, Zero-Trust model, Password DB, Discovery, Access Control policies, Session Recording, VMware management, Cloud Applications Management, Command Broker hosted on the same Appliance without the need of additional modules or components. The Solution must provide Load Balancing (VIP configuration, algorithms and management) and High Availability (Clustering and Disaster Recovery) capabilities within the Appliance, without the need of any 3rd party software or licenses.. The High Availability Architecture must be able to support One or Multiple Datacenters installation (WAN) without the need of 3rd party software or licenses.. The preferred PAM High Availability is Active-Active, and the Internal Password Database must natively provide a complete Replication Architecture without the need of 3rd party software or licenses. . The High Availability Architecture must be able to support Active-Active and Active-Passive Disaster Recovery installations without the need of 3rd party software or licenses. In case of Multiple Datacenter (WAN) installation, the High Availability Architecture must be able to provide the capability to use any of the PAM Sites to recover (for DR or any other unavailability scenarios) the main Production Site, without the need of 3rd party software or licenses.. The PAM Solution supports an upgrade process in-place, using the provided GUI and based on patch/payload files.. The product's Appliance is highly scalable, supporting (for example) 3000 concurrent SSH sessions, 1500 concurrent RDP sessions, or 2000 concurrent connections of mixed SSH and RDP regardless of which form factor (physical or virtual) is used and with Session Recording active. The product adds scale by simply adding new appliance to a cluster.. The PAM solution must be accessed via a dedicated “PAM Client” to be installed on the Users’ Desktops/Laptops. The Session Recording capability must provide a Primary Storage and a Failover Storage, with the possibility to disable completely the Access to the managed devices when the Session Recording storage is not available/mounted. The product supports a variety of authentication methods including LDAP v3 compliant directories including AD, OpenLDAP, RHDS, Novell eDirectory, etc., RADIUS and MFA solutions that integrate with RADIUS, x.509 certificate (browser or Smartcard-based), RSA SecurID, SAML 2.0 as a Relying Party, as well as combined authentication such as LDAP + RADIUS.. The product includes an internal user store for maintaining product administrator’s identities, to ensure independence from an external directory for protecting privileged operations.. The product logs all activity including administrative operations and user activity. User Activity attributes actions to the named user.. The PAM Solution must provide proof of compliance with the following Certifications: 23 NYCRR 500, FISMA, HIPAA, NERC, NRC, PCI/DSS, GDPR. The PAM Solution must provide proof of compliance with the Common Criteria certification with a NIAP approved Enterprise Security Management Protection Profile (NIAP- Preferred Protection Profile). The Solution must provide a Target Connector Framework, enabling to easily build custom Connectors for remote targets that are not supported with out-of-the-box Connectors.. The PAM Solution can provide an add-on for reporting any suspicious behavior with privileged access and proactive remediation actions.. This Behavioral Analysis add-on must be based on an Appliance and specifically designed, configured and specialized for collecting and elaborating the PAM data.. 2FA Solution - 2nd Factor Authentication Credentials (i.e. Mobile OTP, Soft Token, etc.) should be generated on a Mobile App and without the need of any connection or network access for the mobile device.. 2FA Solution - 2nd Factor Authentication Credentials (i.e. Mobile OTP, Soft Token, etc.) must support also Push Notification and SMS as alternative methods to receive/consume the second factor credential.. 2FA Solution - 2nd Factor Authentication Credentials technology must be patented by the vendor and must not require any kind of user password being in transit on the network . The PAM Solution controls access to many different endpoint types such as UNIX/Linux via SSH or Telnet, Windows and RDP Published Apps, Databases, Mainframes via TN3270 or TN5250, Network devices via SSH or telnet, web-based apps via http/https/SAML, etc.. The product controls user access to managed systems through the appliance using a "Zero Trust" model that prevents access that is not explicitly granted.. Provides in-line command filtering using white lists/black lists for SSH, network devices and Mainframe command line operations. No endpoint agent needed.. Can detect when violations of the white list/black list rules occur and can automate action as a result including warning the user, logging off the session, or disabling the user's account within the product as well as alerting when the event occurs.. The product provides highly efficient integrated video session recording with low storage requirements. Videos are fingerprinted to ensure they have not been tampered with. Violations of policies are highlighted in the videos. Video Session Recording is supported for RDP, Telnet, SSH (via CA PAM applet and Windows Putty client), HTTP, HTTPS, TN3270 and TN5250 sessions.. The product allows administrators to terminate active sessions from within the product's Web interface.. Provides a socket filtering capability to prevent unauthorized outbound TCP/IP connections on managed systems including *NIX and Windows.. The product supports using RDP to published applications in which the user can be confined, rather than requiring RDP to a full desktop.. The product allows local/desktop applications to be invoked for connecting to the managed devices via the appliance.. The product supports logging in to the managed applications using SAML 2.0, with the product as the IdP.. The product provides fine-grained control over AWS console features so that administration of AWS can be secured, delegated and managed. The product uses AWS APIs to manage all access to AWS. New instances of AWS servers are automatically detected and managed.. The product controls and audits access to privileged accounts in VMware vCenter. New Virtual systems are automatically detected and managed.. The product provides fine-grained control over VMware NSX so that administration of NSX can be secured, delegated and managed.. The product Controls and Audits administrative access to MS Office 365.. The product can be deployed as an MS Azure instance and can Control and Audit administrative access to MS Azure. Kerberos Authentication for RDP sessions when users are logged in with PIV/CAC smart cards (PIV pass-thru).. The product controls access to high-privileged accounts such as *NIX root and Windows Administrator, sa, etc.. The product provides automated login to managed endpoints using privileged credentials, without revealing the credentials to the user.. The product supports password management for privileged accounts, to rotate passwords after it has been used or viewed, and/or at scheduled intervals. Password composition and view policies can be customized.. The product supports SSH Key management for managed endpoints across the hybrid enterprise, including on-prem, private or hybrid cloud, and IaaS-based devices for authentication of privileged accounts and rotation of SSH keys.. The product allows secondary authentication (such as to sudo, databases or other targets that require a second authentication) to be invoked by authorized users and optionally supplies the privileged account credential when it is required.. The product allows "Learn Mode" to build transparent login configurations to acquire credentials when using RDP published applications.. The product uses a simple "Learn Mode" to acquire credentials of web-based apps by allowing users to map the applications credentials to the fields of the product.. The product can require an approval by designated users as a condition of accessing the credentials for managed accounts.. The product can validate that a Ticket exists as a condition of granting access to a privileged credential using the customers help desk including CA Service Desk Manager, BMC Remedy, HP Service Manager, ServiceNow, and Salesforce Service Cloud.. This integration must be provided out-of-the-box. The product provides tools/APIs for enabling applications that require access to privileged accounts to access credentials programmatically, eliminating the need to "hard code" credentials into the script or application. Password can be rotated automatically.. The product should be able to manage passwords stored in plain, hardcoded in system files or user-defined files, JDBC definitions, etc. including within application configuration files, code or scripts.. In addition the solution must provide a JDBC driver wrapper for addressing the J2EE applications use case.. The A2A capability must support at least the following languages: Java, Perl, C, C++, C#, Korn Shell, C Shell, PHP, Python, PowerShell, Visual Basic, Visual C++, VB Script, and JavaScript.. The product should have capabilities to provide credentials for authenticating applications/scripts at run-time and using batch processes.. The A2A capability must operate with a full secured process, as follows:. · The Account must be classified as A2A. · The Account must have an “alias” so the programmers don’t need to know the credential. · PAM must verify the agent/client who’s asking the credentials. · PAM must verify the name of the alias. · PAM must verify the script or program invoking the request. · PAM must verify the user ID invoking the request. · PAM must verify the path of the calling program. · PAM must verify the hash of the calling program. • توفير الدعم الفني والرخص االلازمة لمدة 3 سنوات من تاريخ التشغيل. . الدعم الفني لايندرج تحت ضمان الوكيل المنصوص عليه في نظام وزارة التجارة ( يبدأ مع انتهاء مرحلة تركيب النظام) .. توفير ورشة عمل وتدريب للحلول والبرامج المقترحة . | عدد | 19 | 0 | |
| خوادم المنطقة المحايدة DMZ Server | اجهزة | 3 | خوادم لاستضافة البرامج للأمن السيبراني | • Chassis 8x2.5 Front Storage. • Trusted Platform Module Trusted Platform Module 2.0 V3. • Chassis 2.5" Chassis with up to 8 Hard Drives (SAS/SATA), 3 PCIe Slots, 2 CPU. • CPU Gold 5317 3G, 12C/24T, 11.2GT/s, 18M Cache, Turbo, HT (150W) DDR4-2933. • CPU Gold 5317 3G, 12C/24T, 11.2GT/s, 18M Cache, Turbo, HT (150W) DDR4-2933. • Memory Type 3200MT/s RDIMMs. • Memory Type 32GB RDIMM, 3200MT/s, Dual Rank, 16Gb BASE x8. • HDD 960GB SSD SAS ISE Read Intensive 12Gbps 512 2.5in Hot-plug AG Drive, 1 DWPD,. • HDD 1.92TB SSD vSAS Read Intensive 12Gbps 512e 2.5in Hot-Plug ,AG Drive SED, 1DWPD,. • Power Supply Dual, Hot-plug, Power Supply Fault Tolerant Redundant (1+1), 800W, Mixed Mode. • Rack Power Cord Rack Power Cord 2M (C13/C14 10A). • NIC Ethernet X710 Quad Port 10GbE SFP+, OCP NIC 3.0. • OS VMware ESXi 7.0 U3 Embedded Image (License Not Included). • OS VMware vSphere 7 Standard for 1 CPU, up to 32 cores, 1YR VMware SNS. • Warranty Parts Only Warranty 12Months, 12 Month(s). • Support ProSupport and Next Business Day Onsite Service, 12 Month(s) | عدد | 20 | 0 | |
| نظام الكشف و الاستجابة لأنظمة الشبكة NDR | نظام | 2 | توريد وتركيب نظام الكشف و الاستجابة لأنظمة الشبكة NDR | "يجب توريد وتركيب نظام الكشف و الاستجابة لأنظمة الشبكة NDR الحلول مع كامل مستلزماتها. . توفير الحلول الازمة مع الرخص التشغيلية لمدة 3 سنوات. يجب الالتزام بالمواصفات المطلوبة حسب الآتي:. The solution should be available as hardware appliance or virtual appliance or as a software . The solution should provide all the required functionalities in one box only that consumes a maximum of 2U Rack Space without the need to add more boxes Support out-of-band management. Built in GUI for system management. Management interface must be accessible from any standard browser and work on any standard OS. (Windows, MacOSX, Linux, Firefox, Safari, Chrome, Internet Explorer). Solution should not require the installation of any client (thick or thin) . Support up to 200 individual users accounts for management. Support at least 10 unique users logged in simultaneously. Support LDAP based authentication for management access. Support separate management roles for administration and users. Support encrypted session for all management functions (SSL, SSH). Support an integrated database and reporting engine that does not require user-configuration, maintenance, or tuning. . Support an audit log of management activities. Support safe downloading of reconstructed artifacts, either individually or as an archived collection. Support sending system alerts and events to an external syslog and log aggregators. Support SNMP v2 & v3 queries for system health and status. Support sending SNMP traps for system alerts and events. Support sending Email notifications for system alerts and events. Support an API for extended attribute extraction and protocol classification. Ability to revoke a user’s access. Support central management for at least 35 remote capture devices. Support encrypted communications between the central manager and all remote capture devices. Support interacting with and configuring all remote capture devices simultaneously from the central manager. Support federated queries to all devices under management from the central manager.. The communication between the central manager and the remote devices should not utilize more than 3% of a 1 Gbps link. Support out-of-band passive deployments. Support a VM based deployment. Support a VM deployment that can regenerate intra-guest VM traffic from a virtual switch to a physical network segment. Support a bare metal install on approved provided hardware. Support cluster mode deployments for enhanced throughput and processing. Support Direct Attached Storage to increase forensic retention beyond internal storage. Support capturing and retaining regenerated traffic from, aggregation TAPs, SPAN ports, and mirror ports. Support efficient capture on multiple interfaces simultaneously. Support both optical and copper connections for capture. Support a minimum of 4x 10 Gbps copper connections for capture. Support capturing inbound and outbound data concurrently. Support full Berkley Packet Filter (BPF) functionality for inclusive/exclusive packet capture per capture interface. Support processing, capturing, and recording packets at a sustained 5 Gbps for 6 hours with 99.999% data capture rate.. Support network links that can burst up to 10 Gbps. Support capture and processing of traffic that is 802.1Q tagged. Support data storage solutions and scale yup to 800TB per appliance . Support capture and query of both IPv4 and IPv6 traffic. Support exporting RAW PCAP data from query results. Support real-time regeneration of traffic flows to secondary capture or analysis solution.. Support playback of historical traffic based on specific time frames to secondary capture or analysis solution. Support the following classes of reputation services: virus scanner, domain reputation, URL reputation, hash reputation, and file analysis integration.. Solution should provide automated workflows and instant reports deliver complete forensic details, contextual awareness and actionable intelligence about breaches—including root-cause exploration and reconstruction of breach activity for fast time-to-resolution.. Support extracting files/artifacts from flows in common network protocols (HTTP, SMRTP, SMB, IM, etc.). Support an integrated solution to preview artifacts/files that have been extracted from flows.. Support interpreting JavaScript to discover obscured content or exploits. Support geo location for identifying the sources of communications by country. Support storing meta-data for 3x longer than capture data. Support efficient DPI inspection regardless of the number of protocol classifiers instantiated. Support alerts for any indexed metadata. Support real-time alerting for reconstructed files . Support a hashing mechanism for extracted file types.. Support near real-time verdict tracking via automated threat intelligence, reputation services AND malware detonation platforms.. Support user configurable dashboards. Support reporting on any and all flows for a predetermined time frame. Support alerting on any single or combination of metadata attribute(s) in near real-time. Support reconstruction of multiple platform file types, including Windows executables and archives (zip, exe, dll, PE, etc.), Mac .pkg and .dmg files, Android .ap files, etc.. Support extraction of large files, i.e. there should be no restriction on the file size of the artifacts being extracted.. Ability to save reports for later use.. Easy configuration of reporting tools.. Support classification and indexing of traffic within nested (tunneled, encapsulated) protocols at least 10 layers deep.. Support Active Directory Integration so it can perform mapping between users and all related attributes such as IP addresses. Support report caching for consecutive queries of the same data. Support integration with other network tools via REST or other API.. Support integration with external firewalls. Support integration with external IPS solutions. Support integration with external SIEM solutions. Support integration with external malware analysis solutions . Support integration with external endpoint forensics solutions. Support session flow . Support to discard the row data and keep only meta data . • توفير الدعم الفني والرخص االلازمة لمدة 3 سنوات من تاريخ التشغيل. . الدعم الفني لايندرج تحت ضمان الوكيل المنصوص عليه في نظام وزارة التجارة ( يبدأ مع انتهاء مرحلة تركيب النظام) .. توفير ورشة عمل وتدريب للحلول والبرامج المقترحة . | عدد | 21 | 0 | |
| نظام حفظ وسائط الحزم عبر الشبكة TAP Network packet brocker | نظام | 1 | توريد وتركيب نظام حفظ وسائط الحزم عبر الشبكة | "يجب توريد وتركيب نظام حفظ وسائط الحزم عبر الشبكة TAP الحلول مع كامل مستلزماتها. . توفير الحلول الازمة مع الرخص التشغيلية لمدة 3 سنوات. يجب الالتزام بالمواصفات المطلوبة حسب الآتي:. Support tap the links set up with TAPs (and/or SPANs), even if the traffic is not under continuous monitoring.. -Network packet broker with 40 GBE tap feature or more based on the network infra. -Must support captures, aggregates, and distributes network traffic for monitoring nd analysis purposes . port configuration multiple 40GbE ports for connecting to network links, switches, or routes, . -Support packet filtering, load balancing, packet slicing and protocol decapitation. • توفير الدعم الفني والرخص االلازمة لمدة 3 سنوات من تاريخ التشغيل. . الدعم الفني لايندرج تحت ضمان الوكيل المنصوص عليه في نظام وزارة التجارة ( يبدأ مع انتهاء مرحلة تركيب النظام) .. توفير ورشة عمل وتدريب للحلول والبرامج المقترحة . | عدد | 22 | 0 | |
| نظام فك التشفير عبر الشبكة | نظام | 2 | توريد وتركيب نظام فك التشفير عبر الشبكة | "يجب توريد وتركيب أجهزة فك التشفير عبر الشبكة SSL Broker الحلول مع كامل مستلزماتها. . توفير الحلول الازمة مع الرخص التشغيلية لمدة 3 سنوات. يجب الالتزام بالمواصفات المطلوبة حسب الآتي:. SSL/TLS visibility. Provides SSL/TLS decryption and encryption, strong cipher support, and flexible deployment.. Dynamic service chaining. Provides service insertion, service resiliency, service monitoring, and load balancing.. Context-based intelligence. Scales with high availability. Granular control. • توفير الدعم الفني والرخص االلازمة لمدة 3 سنوات من تاريخ التشغيل. . الدعم الفني لايندرج تحت ضمان الوكيل المنصوص عليه في نظام وزارة التجارة ( يبدأ مع انتهاء مرحلة تركيب النظام) .. توفير ورشة عمل وتدريب للحلول والبرامج المقترحة | عدد | 23 | 0 | |
| نظام حماية تسريب البيانات DLP | رخصة | 500 | توريد وتركيب نظام حماية تسريب البيانات | "يجب توريد وتركيب نظام حماية تسريب البيانات Data loss prevention الحلول مع كامل مستلزماتها. . توفير الحلول الازمة مع الرخص التشغيلية لمدة 3 سنوات. يجب الالتزام بالمواصفات المطلوبة حسب الآتي:. • Detect sensitive corporate operations documents (Governance, Procedures) . • Detect sensitive corporate business documents (Legal, M&A, Marketing). • Detect sensitive design documents (Drawings, Project Plans). • Management console supports two-factor authentication for user authentication.. • All communications from different modules with the management console must be encrypted. • Supporting security logging and auditing of administrative actions.. • The solution must support policy tuning workflow and automation, centralized policy, system events, and incidents from management console . • All DLP modules (email, web, network, servers, storage, Cloud, and endpoints) must be managed by a single management console.. • The solution must have one unified policy applied on all DLP modules (email, web, network, servers, storage, Cloud, and endpoints).. • Supporting multiple concurrent administrators.. • Measure risk reduction and demonstrate compliance by using the reports generated from the management console. • Ability to integrate with classification tool. • Accommodating the following content-aware detection techniques: partial and exact document matching, images, structured data fingerprinting, statistical analysis, extended regular expression matching, and conceptual and lexicon analysis using the following detection technologies: vector machine learning, indexed document matching, remote EDM indexer, and exact data matching. • Includes predefined policies or templates to cover standard regulations and best practices. • Policies can be created using user authentication directory services (LDAP), utilizing user group and username information. • Policies can be created based on IP, email address or domain (both as source and destination). • Policies can be created based on method of data transfer (protocol, USB devices, etc.). • Policies can be created based on port. • Policies can be created using combinations of data elements of structured or unstructured data. • Exceptions can be built into rules to minimize false positives. • New rules can be created by copying an existing rule. • All incidents (gateway, endpoint and discovery) report to a central management console. • All policies (gateway, endpoint and discovery) can be managed from a central management console. • Incident details retain source IP address, destination IP address, protocol, and port. • Incident details retain sender e-mail address, recipient e-mail address, and SMTP headers. • Incident details retain all content in the transaction, not just the content that violated policy. • The solution should be capable of defining DLP Policy based on user risk score and response based on user risk score.. • The solution should be capable of protecting and building policies based on Zero trust users regardless of whether the user is authorized or non-authorized to use the data.. • Incident details retain all attachments in the transaction, not just the attachment that violated policy. • Provides for pre-registration (fingerprinting) of known sensitive data . • Provides pre-registration in the form of fingerprinting both structured and unstructured data . • Structured data fingerprinting method provides for specifying which combination of data fields constitute a match on a per-policy basis . • Database fingerprinting process allows for direct connection via ODBC (name each supported database) . • Supports detection based on document type, even if file extension has been changed . • Supports sensitive content in file types of any kind . • Supports recursive review of archived files . • Supports inspection and detection of files of any format (note how many file formats). • . • Incidents can be assigned automatically to reviewers . • Incidents can be sorted by severity level . • Incidents can be sorted by sender, recipient, source, destination, protocol, and content type . • Incidents can display and highlight a summary content that violated the policy . • Incident views can be customized based on content pertinent to the reviewer's role and preferences . • Incidents can be grouped by sender, recipient, source, destination, etc., for easy management . • Incident views can be created and saved for easy recall . • Incident reporting can be shared with SYSLOG compatible systems . • Multiple incidents can be assigned to a case for further investigation and remediation . • Cases can be reassigned to different owners after creation . • Case content can be exported with full content and attachments for review by an external reviewer . • . • Interfaces with MTAs to provide for SMTP blocking . • Interfaces with web proxies using ICAP standard for HTTP/FTP blocking . • Supports analyzing SSL traffic using compatible ICAP proxies . • Supports blocking of SSL traffic using compatible ICAP proxies . • Supports notification of policy violation to end user (violator) for email violations . • Supports notification of policy violation to end user (violator) for violations using protocols other than email (HTTP, FTP, etc.) . • Supports notification of policy violation to management . • End user notification is customizable . • End user notification is customizable based on type or severity of violation . • Event reporting includes an explanation of which policy was violated and which portion of the content caused the violation . • Supports "coach mode," notifying user of pending infraction and allowing them to correct or provide justification to proceed. . • Restrict access to specific policy violations based on company role (Compliance, HR, Legal, Finance, etc.) . • Restrict access to policy violations on a per user and per group basis . • Restrict access to actionable functions within polices based on role (Reviewer, Policy Writer, Investigator) . • Limit access to incident details and attachments based on role . • Mask PII or PCI information contained in match summary display based on role . • Restrict access to after-the-fact search capabilities based on role . • Restrict access to case creation, reviewing, modification, or deletion based on role . • Integrate with LDAP for unified user authentication . • Integrate with LDAP groups for unified role definition . • Audit and securely store all user transactions . • Granular access controls to separate system maintenance functions from sensitive information access . • Secure access to the management console using HTTPS . • Secure remote maintenance access to the console using SSH . • Secure storage of local account passwords . • Security hardening measures to remove unnecessary services and network protocols to the DLP systems . • All access to device is logged for an audit trail . • All changes to device configuration or policies are logged . • Audit log is protected from access and manipulation (even via command line or accessing the backend of the device). • Supports centralized reporting for multiple network devices in a single reporting console . • Supports reporting on gateway, endpoint and discovery in a single reporting console . • Provides executive dashboard . • Allows for custom report creation . • Custom reports can be saved (memorized) and re-run . • Reports can run automatically on daily, weekly or monthly basis . • Generate reports in PDF or CSV format . • Develop reports built around stakeholder requirements . • Develop reports based on top (X) policy violations, senders, content type, protocol, etc. . • Build reports from GUI based on current view attributes (columns, content filters, view, etc.) . • Build detailed reports based on historical traffic/content analyzed . • Export historical records for archiving or external review/analysis . • Purpose built appliance . • Turn-key installation and deployment . • DLP system, databases, and assets can be managed by a single department in an enterprise environment . • Single data-at-rest inspection device can analyze and index all sensitive content for data stores up to xxx TB . • Supports sustained bandwidth of up to xxx Mbps with bursts to xxx Mbps . • Supports high availability . • Supports fail over . • Supports network attached storage . • Supports offline archiving of data (in what format) . • Supports encryption of sensitive data fields within the database for PCI compliance . • Supports encryption of entire database . • Provides backup and restore capability of event log data, policies and profiles and system configuration . • Supports load balancing of multiple inspection devices without third-party load balancing devices . • Multiple inspection devices can be managed from a central console (single interface) . • Settings, policies and configurations are automatically replicated across multiple inspection devices . • Capable of monitoring both inbound and outbound connections . • Manages event expiration log as storage limits are met . . • توفير الدعم الفني والرخص االلازمة لمدة 3 سنوات من تاريخ التشغيل. . الدعم الفني لايندرج تحت ضمان الوكيل المنصوص عليه في نظام وزارة التجارة ( يبدأ مع انتهاء مرحلة تركيب النظام) .. توفير ورشة عمل وتدريب للحلول والبرامج المقترحة . | عدد | 24 | 0 | |
| نظام حماية وامن دخول الشبكة | نظام | 2 | توريد وتركيب نظام حماية وامن دخول الشبكة NAC | "يجب توريد وتركيب نظام حماية وامن دخول الشبكة Network access control الحلول مع كامل مستلزماتها. . توفير الحلول الازمة مع الرخص التشغيلية لمدة 3 سنوات. يجب الالتزام بالمواصفات المطلوبة حسب الآتي:. • Monitor endpoint status on the network in real-time.. 4 medium network appliances . • Enforce granular policies for access control and endpoint compliance. • Address security operations with automated network security remediation. • Act as an integration hub to share data with other cybersecurity tools. . Solution Must support Centralized Management with a Centralized License. The proposed solution must support Enterprise management via Virtual Machine or Appliance to manage all the appliances from a single admin console when multiple Appliances/Virtual Machines are used to cover the solution. Solution Must support High Availability for the Enterprise Management. Solution Must Support Interactive Dashboard for the Visibility and the Compliance Status. Solution Must support Asset inventory Dashboard. Solution Must support up to 10 Endpoint Appliances Configuration management. Proposed Solution must have two appliances in the main DC with the following Specs to manage the solution and for centralized license.. Proposed solution should be capable of supporting 10,000 endpoints and managing up to 200 Layer-2/Layer-3 network devices.. Proposed Solution should provide Visibility & Control into (Campus Network, Data Center, Cloud, OT and IoT).. Proposed Solution must be scalable for Future expansion without requiring major Architecture changes.. Proposed Solution must support continuous monitoring and assessment for the endpoints while connected to the Network Infrastructure (Periodic reassessment). Proposed Solution must support Windows, Linux, and Mac OS Operating systems, and must support legacy Windows Operating Systems.. Proposed Solution should be capable to block the access of endpoints which are connected on unmanaged network (I.e Unmanaged Switch).. Proposed solution should be capable of identifying IOT devices such as: IP Cameras, VOIP, Projectors, HVAC devices, etc.. Proposed solution must support IoT credential assessment (Default Credentials, Default SNMP Communities, Default Factory Credentials ..Etc.). Proposed Solution must support passive and active check for well known Vulnerabilities and IOC’s. Proposed Solution must support open ports and map it to the devices.. Proposed Solution must support IP to MAC Mapping on wired connected devices based on Switch IP and Switch port.. Proposed Solution must support Data Center Visibility including and not limited to VMware, ACI and all components related to it.. Proposed Solution should have the capabilities to check if VMware Tools are installed on a virtual machine. Such as: . • Tools installed and up to date . • Tools installed but upgrade recommended . • Tools installed but need to be updated . • Tools installed but VM is not managed . • Tools not installed . Proposed Solution should have the capabilities to check if the ESXi host profile is compliant, non-compliant or unknown.. Proposed Solution should have the capabilities to classify different types of VMware virtual machines and servers, such as: . • Virtual Machines . • ESXi Servers . • vCenter Server. Proposed Solution should have the capabilities classifying virtual machines based on VMWare NSX security groups or based on NSX security tags. . Domain, Domain User, Domain Member, OS-Class, IP of the connected switch, Switch Port, Switch Port VLAN, Switch Port Status, Switch Vendor, Access status.. Proposed Solution must support Passive discovery with DPI for IT and IoT protocols.. Proposed Solution must support Passive discovery with SPAN port traffics analysis. .. Proposed Solution should support Access Restriction Based on encryption. Proposed Solution should support Access Restriction Based on patches . Proposed Solution should support Access Restriction Based on AV . Proposed Solution should support Access Restriction Based on Managed Device . Proposed Solution should support Access Restriction Based on AD/LDAP account . Proposed solution should be capable of support/integrating with wide variety of Network switching vendors such as Cisco, Juniper, Arista, Huawei, Brocade / Foundry, etc. without making any change on the existing setup or requiring upgrade to this infrastructure elements.. Solution provided shall provide unrestricted number of Virtual Appliances Licenses to cover our requested total IP Endpoints.. Proposed Solution appliance should support (centralized, distributed and hybrid) architecture.. Proposed Solution should not require any network architecture change . Proposed solution should be deployed without requiring 802.1X for Access Control features. Proposed Solution must integrate with infrastructure devices by using SNMP, CLI. Proposed Solution should support visibility to all the IP enabled devices connected in the network (agentless using Passive and Active Fingerprinting techniques) for both Traditional Endpoints and Industrial IoT Devices. . Proposed solution should not require an agent to perform endpoint profiling, posture Assessment & baselining for full NAC solution features (for managed devices). Agent can be used for managed AD-member Windows endpoints. . Proposed solution should provide information regarding the endpoint connected to the network, such as IP Address, MAC Address, NetBIOS Name, NetBIOS . Proposed solution should support Device tracking (What, Where, Who, When and how). Proposed solution should be capable to provide Post-connect monitoring in an agentless manner. . Proposed Solution Should capable to achieve all feature & functionality with agentless, Agent based & Dissolvable agent mode deployment.. Proposed Solution should provide Visibility & Control into Data Center virtual-machines and its virtualized infrastructure. Proposed solution must support hardware-based and virtual appliance.. Proposed solution should be scalable of supporting 1M+ IP endpoints and managing Layer 2 / Layer 3 devices in non-dot1x mode.. Proposed Solution should support high-availability and clustering.. Proposed solution should allow administrators to review events, do searches, and run reports from a Web UI. . Proposed solution must support the following reporting capability:. 1- Automatically generate reports on scheduled basis.. 2- Administrators should update or define custom reports.. 3- Ability to run certain reports based on security role. 4- Support scheduled reports be delivered via e-mail. Proposed solution should support event logging via severity. For forensic and faster network troubleshooting, the solution should log each & every session/ all important events that pass through and provide simple graphical and statistical reports. & Logs should be exportable to external log server.. The solution should provide real time alerts via eMail.. Proposed solution should support Role Based Access Control for management. Proposed support alert notification. Proposed solution should support report generation in csv, xls or pdf. Proposed Solution should support creation of custom reports. Proposed Solution should support helpdesk notification. Proposed solution must support non-disruptive, out-of-band model (with all feature & functionality) to ensure network keeps functioning even if the solution goes down for whatever reason.. Proposed solution must support built-in configuration wizards and customizable policy templates for rapid time-to-value.. Discuss how can the proposed solution prevent end-stations failing to meet policy from accessing the network and the alternatives for quarantining and/or fixing computers out of compliance.. Proposed solution quarantine method should not rely on specialized hardware or software.. Proposed solution should support VLAN restriction, Switch port block, Dynamic ACL, Endpoint ACL, Port based ACLs and virtual firewalling.. Proposed solution should support performing Pre and Post admission check, policy recheck. Proposed solution should support Compliance and Remediation abilities. Proposed solution should support Guest Management without requiring additional license.. Describe proposed solution policy configuration options: those configured out of the box (best practices) and the flexibility for the state to customize the solution (status checking methods, breadth of status checking options).. Proposed solution should support automatically detecting new endpoint connected to the network. Please describe how this can be done with proposed solution.. Proposed solution should be cable of identifying virtual versus physical hosts. The solution should be able to identify the vendor of the NIC of endpoints. The solution should be able to identify the switch name and the port on the switch to which and endpoint is connected. Proposed solution should be able to identify the user, email address and IP address of managed devices without requiring an agent through integration with existing LDAP server.. Proposed solution should be able to identify on managed the presence/absence of (without requiring an agent):. Windows Services. Windows process. Open ports. External devices. Dual Home. P2P application.. IM application.. Proposed solution should provide IOC scanning to discover and mitigate threats from infected endpoints.. The Solution should be able to identify and classify the Operating System and patch levels installed on managed devices without requiring an agent.. Proposed Solution should support the following User Directory Servers:. • Active Directory. • eDirectory.. • Sun Directory Server.. • Notes.. • Open LDAP Server.. • Radius Protocol Server.. Proposed solution should support the following Widows OS:. • Windows10. • Windows 8. • Windows 7. • Windows vista. • Windows 2000. • Windows XP. • Windows Server 2016 Technical Preview. • Windows Server 2012. • Windows Server 2008. • Windows Server 2003 . Proposed solution should support the following MAC OS:. • OS X 10.6 (Snow Leopard). • OS X 10.7 (Lion). • OS X 10.8 (Mountain Lion). • OS X 10.9 (Mavericks). • OS X 10.10 (Yosemite). • OS X 10.11 (El Capitan). • Mac OS 10.12 (Sierra). • Mac OS 10.13.x (High Sierra). • Mac OS 10.14.x (Mojave). • Mac OS 10.15.x (Catalina). Proposed solution should support the following Linux OS:. • CentOS. • Debian . • Fedora . • Kali. • Mint. • Red Hat Enterprise Linux. • Red Hat Enterprise Desktop. • Red Hat. • Open Suse. • Suse Enterprise. • Ubuntu. • IGEL. Proposed Solution should support posture assessment of Mac and Linux endpoints while providing an inventory of applications, processes and open ports on an endpoint. In addition, solution should include remediation actions such as kill processes, run scripts, set registry keys or disable dual-homed device adaptors. . Proposed solution should Integrate with LDAP/AD. Proposed Solution should provide built-in method to identify IoT (SNMP / SSH / Telnet) weak and default credentials with ability to add custom credentials to the posture assessment engine. Proposed solution should support Integration with SCCM without requiring creation of any SQL queries (integration should be simple, and out of the box). Proposed solution should support both copper and fiber interfaces (1G/10G).. The solution should support bi-directional information sharing and workflow automation with security technologies such as Advanced Threat Detection (ATD), Vulnerability Assessment (VA), Enterprise Mobility Management (EMM), Next-Gen Firewalls, Endpoint Protection Platforms (EPP) and Security Information and Event Management (SIEM) tools help accelerate system-wide response and achieve operational efficiencies. The OEM should provide a list of all the currently supported integrations.. The Configuration of the solution must be from the vendor by a certified professional service engineer.. • توفير الدعم الفني والرخص االلازمة لمدة 3 سنوات من تاريخ التشغيل. . الدعم الفني لايندرج تحت ضمان الوكيل المنصوص عليه في نظام وزارة التجارة ( يبدأ مع انتهاء مرحلة تركيب النظام) .. توفير ورشة عمل وتدريب للحلول والبرامج المقترحة . | عدد | 25 | 0 | |
| نظام مكافحة الملفات الخبيثه | رخصة | 500 | توريد وتركيب نظام مكافحة الملفات الخبيثه Antivirus | توريد وتركيب الحلول مع كامل مستلزماتها. . توفير الحلول الازمة مع الرخص التشغيلية لمدة 3 سنوات. توريد وتركيب الرخص اللازمة للخوادم (350خادم). توريد وتركيب الرخص اللازمة للأجهزة الطرفية (150 جهاز ). The technology shall support the application whitelisting and advance threat protection . The techonolgy shall support host firewall . Desktop firewall to control network traffic and protect against attacks. Central management console to monitor and manage endpoints. Antivirus and spyware to scan and remove malicious software. Intrusion prevention to prevent unauthorized access and exploits. Suggested solution must support below client operating systems:. • Android, Apple IOS.. • Windows on Arm devices, Windows in S Mode.. • Windows Vista (32-bit, 64-bit) . • Windows 7 (32-bit, 64-bit; RTM and SP1) . • Windows Embedded 7 Standard, POSReady, and Enterprise (32-bit, 64-bit) . • Windows 8 (32-bit, 64-bit) . • Windows Embedded 8 Standard (32-bit and 64-bit) . • Windows 8.1 (32-bit, 64-bit), including Windows To Go . • Windows 8.1 update for April 2014 (32-bit, 64-bit) . • Windows 8.1 update for August 2014 (32-bit, 64-bit) . • Windows Embedded 8.1 Pro, Industry Pro, and Industry Enterprise (32-bit, 64-bit) . • Windows 10 (32-bit, 64-bit) . • Windows 10 Fall Creators Update (version 1709) (32-bit, 64-bit) . • Windows 10 April 2018 Update (version 1803) (32-bit, 64-bit). • Windows 10 Oct 2018 Update (Version 1809) (32-bit, 64-bit). • Windows 10 June 2019 Update (Version 1903) (32-bit, 64-bit). • Windows 10 Des 2019 Update (Version 1909) (32-bit, 64-bit). • Windows 10 May 2020 Update (Version 2004) (32-bit, 64-bit). • Windows Server 2008 R2 (32-bit, 64-bit; R2, SP1, and SP2) . • Windows Small Business Server 2011 (64-bit) . • Windows Server 2012 . • Windows Server 2012 R2 . • Windows Server 2012 R2 update for April 2014 . • Windows Server 2012 R2 update for August 2014 . • Windows Server 2016. • Windows Server 2019. • Mac OS X 10.10, 10.11, 10.12, 10.13, 10.14 (including 10.14.5), 10.15. • Amazon Linux 1, 2.. • CentOS 6.X, 7.x, 8.x ; 32-bit and 64-bit. • Debian 6.0.5 Squeeze, Debian 8 Jessie; 32-bit and 64-bit . • Fedora 16, 17; 32-bit and 64-bit . • Oracle Linux (OEL) 6U2, 6U4, 6U5, 7, 7.1, 7.2, 7.3 . • Red Hat Enterprise Linux Server (RHEL) 6U2 - 6U9, 7 - 7U4 , 8. • SUSE Linux Enterprise Server (SLES) 11 SP1 - 11 SP4, 32-bit and 64-bit; 12, 12 SP1 - 12 SP3, 15 64-bit . • SUSE Linux Enterprise Desktop (SLED) 11 SP1 - 11 SP4, 32-bit and 64-bit; 12 SP3, 64-bit . • Ubuntu 12.04, 14.04, 16.04, 18.04; 32-bit and 64-bit". "Suggested solution must support below Virtual Environments:. • Microsoft Azure . • Amazon Workspaces . • VMware WS 5.0, GSX 3.2 or later, ESX 2.5 or later . • VMware ESXi 5.5 – 6.7. • Microsoft Windows Server 2008 R2, 2012, 2012 R2, 2016 Hyper-V, 2019. • Citrix XenServer 5.6 or later . • Virtual Box by Oracle". Solution should able to Detects and blocks malicious software in real time, including viruses, worms, Trojan horses, spyware, Adware, and RootKit.. Endpoint solution technology should include a behavioral based technology apart from providing the signatures for known threats, vulnerability add heuristic based approach. It should be able to score both good and bad behaviors of unknown applications, enhancing detection and reducing false positives without the need to create rule-based configurations to provide protection from unseen threats i.e. zero-day threats.. Solution firewall engine should have option to allow or block support of network protocols, including Ethernet, Token Ring, IPX/SPX, AppleTalk, and NetBEUI. Can block protocol drivers (example: VMware, WinPcap) and should have Adapter specific rules – e.g. Ethernet, Wireless, VPN. Proposed IPS solution should allow customer to edit and create the IPS signature using snort-based format if required.. Solution should able to block devices based on Windows Class ID and should include USB, Infrared, Bluetooth, Serial, Parallel, fire wire, SCSI and PCMCIA.. Solution should also be able to block and give read/write/execute permission for mentioned devices.. Solution should provide application analysis, process control, file and registry access control, and module and DLL control.. "Proposed Solution should be able to deploy flexible and different security policies depending upon the AND/OR relationship of following network triggers:. • IP address (range or mask). • DNS Server. • DHCP Server. • WINS Server. • Gateway Address. • TMP Token Exists (hardware token). • DNS Name Resolves to IP. • Policy Manager Connected. • Network Connection (wireless, VPN, Ethernet, dialup)". Proposed IPS solution should combines NIPS (network) and HIPS (host) both with Generic Exploit Blocking (GEB) for one signature to proactively protect against all variants, Granular application access control and behavior-based technology mentioned above.. Proposed Anti Spyware solution should be able to bypass Windows File System and should have Direct Access to NTFS Volume to provide raw Disk Scan for superior RootKit protection.. System Lock Down - it should be able to “Locks down” the system by fingerprinting every executable file on the system. It can then monitor all running applications and terminate any application for which the agent does not have a matching fingerprint.. Denial of service detection and protection - Should Protects the system from multiple forms of anomalous network behavior that is designed to disrupt system availability and/or stability.. Anti-spoofing - Should Protects the transmission of data from being sent to a hacker system who has spoofed their IP or Mac Address. Agent has the ability to detect and block process execution chains. It is able to detect when a malicious application tries to execute a trusted application, and then use the trust privileges of that application to access the network.. Anti-application hijacking - Should prevent hackers and web sites from identifying the operating system and browser of individual computers.. Code insertion attack prevention - Prevent malicious applications from inserting code into trusted application to bypass outbound application fire walling.. Protocol adapter attack prevention - Prevent malicious applications from using their own protocol adapter to bypass outbound fire walling.. Anti-Virus Solution proposed should not have failed Virus Bulletin 100 award ever and should have won the same more than 41 times continuously.. Proposed Personal firewall solution should be on the top on Gartner magic quadrant.. Antivirus and Antispyware policy can have options by default to choose High Security and High performance to have a right balance while deployment in the production network.. Antivirus schedules scans should get delayed/rescheduled while laptops are running on batteries.. Antivirus should have behavior-based technology to scan for Trojans, worms and key stroke loggers to protect from zero-day threats. Sensitivity level of this should get adjusted with customized scanning frequency.. Antivirus Solution should have internet browser protection and home page should be configurable if security risk changes that.. The proposed solution should have email plugin scans attachments, including zip files, removing malware before it reaches the inbox and able to Scan POP 3 email traffic including email clients Microsoft outlook, lotus notes and outlook express.. Desktop Firewall rules should be configurable depending upon the adapters including Ethernet, wireless, Dialup, VPN (Microsoft PPTP, Nortel, Cisco.. Desktop Firewall rules should be configurable depending upon the state of screen saver "ON" & "Off".. Desktop Firewall Policies should be configurable depending upon the time and day.. Product should have readymade policies including -To Make all removable drives read only, to block program from running from removable drives, protect clients files and registry keys, log files written to USB drives, block modifications to host files. Management server should have the capabilities to add multiple domains if required for the different locations to assign the different administrators for other locations. Each domain should share the same management server and database & This separation prevents administrators in one domain from viewing data in other domains. These administrators can view and manage the contents of their own domain, but they cannot view and manage the content of other domains.. To conserve the network bandwidth clients should be configurable to upload the maximum records of logs to the management server.. Product should have a security setting to block all traffic until the firewall starts and after the firewall stops except initial DHCP & NetBIOS Traffic.. The proposed AV solution should have the capability to detect the files through number of users using that file across the globe.. Browser intrusion prevention: AV should be capable enough to block the malicious downloads thorough browsers.. The proposed AV solution should rank the files based on the digital signature, age of the file, prevalence like attributes. The proposed AV client should have a visible indication whenever it connected to the AV console.. AV console should have a threat con which indicates the virus status on the Public network. The Proposed solution should have the deception feature as part of the Endpoint Agent. The Proposed Solution should have Memory exploit mitigation as a part of the same agent. The proposed solution should have EDR feature using same agent. The proposed solution should be a part of Gartner leader quadrant. The proposed solution should have endpoint deception as a part of the single agent. The proposed solution should have Host Integrity identifies and remediates non-compliant or out-of-date endpoints.. The proposed solution should have effective Advance machine learning in file analysis and behavioral analysis.. The proposed solution should have Host IPS can block and detect internal or outbound network attacks and communications and threats at the browser and network level before they make it to the disk and are executed.. Endpoint agent protected from tampering or disabling.. The proposed solution should have a cloud management console as optional. "Endpoint Detection and Response should Detect, hunt, isolate, and eliminate intrusions across all endpoints using AI-driven analytics, investigation playbooks, and unequaled threat intelligence, and it should be integrated with Endpoint Protection as a single agent. EDR Should have the below features:. Detect and Expose – Reduce time to breach discovery and quickly expose scope . • Apply Machine Learning and Behavioral Analytics to expose suspicious activity, detect and prioritize incidents . • Automatically identify and create incidents for suspicious scripts and memory exploits . • Expose memory-based attacks with analysis of process memory . Investigate and Contain – Increase incident responder productivity and ensure threat containment . • Ensure complete incident playback with continuous recording of endpoint activity, view specific endpoint processes . • Hunt for threats by searching for indicators of compromise across all endpoints in real-time . • Contain potentially compromised endpoints during investigation with endpoint quarantine . Resolve – Rapidly fix endpoints and ensure the threat does not return . • Delete malicious files and associated artifacts on all impacted endpoints . • Blacklist and whitelist files at the endpoint . • Enhanced reporting allows any table to be exported for incident resolution reports . Integrate and Automate – Unify investigator views, orchestrate data and work flows . • Easily integrate incident data and actions into existing SOC infrastructure including Splunk and ServiceNow. • Replicate the best practices and analysis of skilled investigators with automated incident playbook rules. • Gain in-depth visibility into endpoint activity with automated artifact collection ". Respondent should have as part of the platform an End Point solution that allows for detection, validation, and quarantine. All functionality must work on or off of the corporate network and without a requirement for VPN back to the corporate network. The proposed platform must be able to support multiple detection and protection technologies within their solution and should include a signature base engine that leverage on database of known files and their behavior to determine if the file is malicious, without additional payload on file detonation to detect zero day and unknown threats. The solution must have a 2-stage process for quarantine and remediation. The solution must be able to push out new upgrade versions of the endpoint agent. Endpoint agents must be able to be controlled on and off the corporate network for the purposes of detection, triage, and quarantine.. Endpoint Detection and Response solution must be able to learn about zero-day threats from other security devices doing virtual execution. Endpoint Detection and Response solution must be able to take inputs for custom indicators of compromise. Endpoint agent must have capability to protect against threats like Adware, Viruses and software vulnerabilities that exists on the endpoint solution. "Ability to fully forensically analyze identified malware and provide the following information to enterprise staff:. • Comprehensive Host Modification Report. • Copy of malware binary(s). • Full URL trails identifying all of the locations to which the malware attempts to communicate.. • Summary reports of enterprise malware events breaking down malware by type, host, and activity.. • Immediate analysis as to whether the malware maps to a previously KNOWN or UNKNOWN threat. • Severity information, illustrating how effective your other defenses would have worked against this threat.". The proposed solution should dynamically generate the required rules/policies to block/blacklist the malicious file on all endpoint clients without the need to deploy/integration with additional agents. The solution must be able to automatically quanrantine convicted bad files to a different network location.. The solution must be able to pass Indicators of Compromise (IOCs) such as file hash, to the endpoint solution so that the endpoint solution could block current and future detection of similar files. Solution should be able to detect Kernel level rootkits. Solution should be able to handle reflective DLL injection. The solution should be able to identify across endpoints if the malicious file presents with different names . The solution must provide a single view of suspicious or malicious files across the endpoints . The solution must provide file reputation based on Intelligence information gathered across the globe to aid remediation and investigation processes. The solution must provide the administrator the ability to submit files for Dynamic Malware analysis. . The solution must provide the ability to whitelist or blacklist files across endpoints . The endpoint agent must support file reputation lookup to EDR servers. The endpoint agent must support blocking, deletion and quarantine of threats. The endpoint agent must not impact the performance of the agent.. The endpoint agent must provide host-based intrusion prevention capabilities to protect against network threats targeting endpoints. The endpoint agent shall provide browser-based intrusion prevention capabilities to the endpoints. The endpoint solution must support a deep environment search for IOCs from all endpoints for files and registry keys as well as domains and URLs. The endpoint solution must be able to blacklist and erase malicious files from a single control plane. The solution must be able to quarantine endpoints from a single control plane to prevent further infection . The endpoint solution must correlate threat and malware information with the existing anti-malware solution and prioritize or de-prioritize EDR incidents based on protection status by the anti-malware solution. The proposed APT solution must also have support for current Endpoint protection as part of the platform that allows for detection, validation, containment and remediation of the Endpoint.. The endpoint agent should integrate with the endpoint protection and not require any new agent to be installed on the endpoint. . The endpoint EDR Solution should be able to remediate the endpoint using the existing Endpoint protection or its own tools.. The endpoint EDR solution should be able to detect the unknown malicious malware and should be able to submit the malware for virtual execution from endpoints independent of the Network EDR solution. . The endpoint EDR solution should be able to detect, validate, contain and remediate the endpoints when the user is on or off of the corporate network and without a requirement for VPN back to the corporate network.. The proposed solution should support containment of the endpoints and containment operations should support role-based Administrators.. The endpoint EDR solution should be able to accept IOC's and threat intelligence dynamically from the devices performing Virtual execution analysis on the network (e.g. Integration with Network and Email based EDR solution). The proposed solution should have IoC and Threat Hunt queries on clients directly at scale. The endpoint EDR solution must be able to integrate with SIEM.. The endpoint EDR solution must be able to detect the presence of files that have been written to a system but have not been executed.. The endpoint EDR solution may not interfere with normal user and business operations on the endpoint no matter how busy the system becomes.. The endpoint EDR solution must provide regular updates of threat intelligence to include indicators involving highly advanced threat groups in state-sponsored targeted attacks.. The endpoint EDR solution upgrades must be supported by standard enterprise software deployment mechanisms as well as the ability to perform upgrades to endpoints within the solution itself.. The Solution provider should allow the submission of suspicious sample for analysis at the click of a button from the solution to avoid Potential False positive . The solution should support the bare-metal and virtual execution sandbox to detect the virtual aware new gen threats.. The implementation of the solution should not add any new agent and should be part of the endpoint protection to the endpoint machine.. The Proposed solution should support flight data recorder . The proposed solution should comprehensive App discovery and inventory to scan and inventories all the apps and files collected from all the endpoints in the environment and provides detailed information about each app and file, including the name, risk score, vulnerability score, publisher, reputation, number of devices it is seen on, and so on.. The proposed solution should comprehensive application control policy and easy Policy Creation with Logical View to add any application from discovered App to white or black list.. Endpoint App Control enables trust in apps, based on a variety of app attributes, allowing or blocking apps based on one or a combination of any number of static (e.g. hash, path, publisher and certificate) and dynamic (e.g. risk and reputation score) attributes.. The App Control policy should enable rule creation on a broad range of parameters that include app name, path, and hash, reputation, publisher, user, user group, and command-line parameters.. The App Control policy should have an option to enforced in “monitor only” mode.. The proposed solution should analyze the difference between what the applications allowed in the environment and what applications run in the environment. . The proposed solution should enable to define trusted updaters which can be from discovered apps or new apps, publisher, directory, files, users, and user groups, that can install or update the software on the endpoints.. The proposed solution should prevent trusted apps from being exploited and prevent untrusted apps from infecting systems.. "The proposed solution should have application behavior Isolation rules capabilities to protect our devices and these rules allow or block certain application behavior, as the following isolation types. . • Browser isolation (Google Chrome, Firefox, Internet Explorer, Microsoft Edge). • Office isolation. • PDF Renderer isolation. • Platform isolation policy, which includes the following:. o OS settings. o Generic jail settings (high, medium, and low isolation). . The isolation provides rules to protect the following:. • Registry protection. • File protection. • Process interaction protection. • Process execution protection. • Network access protection. • System call protection". The proposed solution should detects any suspicious files in our network based on the intensity levels and enable us to add the detected files to whitelist or blacklist and enable us to isolate a suspicious application with a Platform Isolation policy.. The proposed solution should have ability to discover, inventory and isolate portable applications based on risk rating.. The proposed solution should have deception feature with deploying a wide variety of ‘bait’ - fake files, credentials, network shares, cache entries, and endpoints – throughout your environment.. The proposed solution should have endpoint deception as a part of the single agent. The proposed solution should have utilize deception techniques to monitor and notify of malicious application behavior.. The proposed solution should be supporting IOS and Android Devices. The proposed solution should prevent attacks on mobile devices running iOS and Android.. The proposed solution should proactively protecting the mobile devices from malware, network threats, and app/OS vulnerability exploits, with or without an Internet connection.. The proposed solution should have capability to enable us to take faster reaction and constant protection, even when devices are disconnected from the Internet.. The proposed solution should Proactively thwart attacks, immediately and automatically when a threat is detected.. The proposed solution should target the exact threat without impacting other resources or processes, and kick in on-demand.. The proposed solution should have protection action against risky apps threats including but not limited to (blocking communication, preventing installation, blocking communication with malicious command-and-control (c&c) servers, and blocking access to sensitive resources). The proposed solution should have protection action against network threats including but not limited to (network automatic launch of VPN tunnel when network threat is detected, blocking access to sensitive corporate resources, and blocking access to fake corporate wi-fi hotspots).. The proposed solution should have protection action against content threats including but not limited to (tunnelling all traffic through a secure web gateway, blocking access to unwanted content, and blocking SMS phishing messages).. The proposed solution should have protection action to automatically disconnect malicious VPNs. The proposed solution should have VPN technology can be implemented in always-on or on-demand mode.. "The VPN technology in the proposed solution should have the capability to operate in two ways: . 1. as an encrypted tunnel through which traffic passes securely between the device and a network.. 2. as a selective traffic blocker. (specific traffic passing through the VPN is dropped and never leaves the device).. Each of these implementations can be always-on or on-demand.". The proposed solution should have Multi-layered mobile defence against known, and zero-day attacks across every mobile threat vector.. The proposed solution should have protection from suspicious networks, apps and behaviors before they can do harm.. The proposed solution should protect privacy and productivity without negatively impacting mobile experience or battery life.. The proposed solution should have automated IT policy enforcement and built-in integrations with all major existing enterprise EMM/ MDM, SIEM, email servers and VPNs.. The proposed solution should have capabilities to integrate with many security solution including but not limited to WSS, CASB, DLP and Endpoint protection. The proposed solution should easy to deploy, adopt, maintain and update.. The proposed solution should zero impact on productivity, experience, privacy and deep analysis of suspicious apps.. The proposed solution should have real-time response and protection against various known, unknown and targeted malware attacks from any suspicious apps and networks.. The proposed solution should have automated corporate asset protection when under attack.. The proposed solution should have a reputation check capability with machine learning for apps, networks and OS.. The proposed solution should have comprehensive activity logs for integration with any SIEM solution.. The proposed solution should have app analysis capability based on signature, static/dynamic analysis, behavior, structure, permissions, source and more.. The proposed solution should have detection, blocking and remediation of malicious IOS profiles.. The proposed solution should have capability to identify Man-in-the-Middle, SSL downgrading and content manipulation attacks without violating privacy.. The proposed solution should have capability to monitoring devices for unpatched known vulnerabilities and uncovering zero-day vulnerabilities in apps and operating systems.. The proposed solution should provides mobile threat defense for modern operating systems without relying on a 3rd party. The proposed solution should addressing stealthy attacks or APTs with effective Active Directory defense from the endpoint to provide autonomous breach containment, incident response, and domain security assessment.. The proposed solution should autonomously capability to learn the organization’s Active Directory structure in its entirety (servers, endpoints, applications, users, branches, naming conventions, configurations, attributes etc.). The proposed solution should able to create an authentic and unlimited obfuscation.. The proposed solution should able runtime evaluation of processes, context and Active Directory activity is evaluated.. The proposed solution should have a high-fidelity alert and the capability to is automatic to blocking the attack.. The proposed solution should provide a real-time forensics reporting that captures actual reconnaissance, credential theft, and lateral movement phases that were performed by the attacker and documenting the attacks chain.. The proposed solution should able to automatic mitigation stops the malicious process on the endpoint to contain the breach in real-time, removing its ability to spawn another process, overwrite another part of memory, run reconnaissance commands, or communicate out to the network.. The proposed solution should have the capability to continuously probes for domain misconfigurations, vulnerabilities, and persistence, and present the domain from the attacker’s perspective, and allowing for immediate risk mitigation.. The proposed solution should prevent lateral movement with AD protection and ML based deception technology. The proposed solution should have an automated assessment process uses attack simulations to gather in-depth information about the configuration of the domain, privileged accounts, security settings, GPO, endpoints, domain controller, and Kerberos.. The proposed solution should have autonomously analyzes every component of the domain and Active Directory structure for misconfigurations and backdoors in AD and the entire domain environment.. Solution should be deployed, administered and updated in a single agent package and update mechanism. There should not be any need for multiple deployment of agent & to get the updates to achieve the all product functionality required above. . The proposed solution should have cabapilty to deployment in Cloud, On-Prem, and Hybrid options. Find unmanaged endpoints and deploy single lightweight agent for complete protection.. Security and compliance check both should be managed by a single administration management server and console.. Solution should provide integration with RSA for management console authentication addition to the user credential authentication if required and also should get integrated with LDAP, Syslog, and Active Directory.. The Management servers installed at different locations should have the ability to replicate data, logs and content at defined interval in Multi-Server Architecture with Policy and Log Replication.. The agent should be able to password protect uninstall, password for disabling service and password to open the client GUI so that users will not be able to uninstall the agent.. Agent should have the ability to protect the service from being stopped, even if an administrator logs on.. Update mechanism should include client content updates from management server, internal update servers, external vendor update servers, also from the client that acts as a proxy between a management server and clients in the group and using Third-party tools like Microsoft SMS.. Proposed AV solution should have a single and the same agent for physical and Virtual clients. . . الدعم الفني لايندرج تحت ضمان الوكيل المنصوص عليه في نظام وزارة التجارة ( يبدأ مع انتهاء مرحلة تركيب النظام) .. • توفير ورش عمل لنقل ومشاركة المعرفة لتشغيل وتركيب النظام.. | عدد | 26 | 0 | |
| نظام جدار حماية التطبيقات application firewall | نظام | 2 | توريد وتركيب نظام حماية تطبيقات الويب WAF | "يجب توريد وتركيب أجهزة حماية تطبيقات الويب WAF الحلول مع كامل مستلزماتها. . توفير الحلول الازمة مع الرخص التشغيلية لمدة 3 سنوات. يجب الالتزام بالمواصفات المطلوبة حسب الآتي:. 9. Solution must provide analytics capability for device groups in synchronization with improvement in management and visibility with stats notification.. 10. Solution must be able to define and control how traffic is distributed across links, based on real-time traffic flows and throughput.. 11. Solution must be able to automatically build different policies for different applications and rapid deployment based on detected traffic with combined detection and prevention techniques.. 12. Solution must be able to update all signatures and protection mechanisms and licensing in totally isolated environment. 13. Solution must provide automatic self-learning and creation of security polices with versioning capability of the configured policies and rollback.. 14. Solution must provide SSL offloading capability with storing private keys in secure mechanism with capability for tuning SSL parameters.. 15. Solution must provide session tracking mechanisms that enhanced enforcement and reporting capabilities that take into account user sessions and application user names within the application.. 16. Solution must provide request and response logging that support profile by enabling configuration log entries to be reported when requests/responses are received.. 17. Solution must provide protection of AJAX-enabled applications including those that use JSON for data transfer between the client and the server. 18. Solution must provide virus checking on HTTP file uploads and SOAP attachments. Support to Anti-Virus via ICAP communication channel.. 19. Solution must provide XML Web Services access restriction methods defined via Web Services Description Language (WSDL) or XML Schema format (XSD). 20. Solution must provide XML Parser Protection, limit recursions to thwart DoS conditions, limit the numbers of elements, lengths of elements, attack signatures enforcement.. 21. Solution must be able to perform information display masking/scrubbing on requests and responses.. 22. Solution must be able to perform restrictions and filtering based on values and lengths of URL, filetype, parameters, methods, encoding in headers and response, cookies, and body content for all type of HTTP protocols.. 23. Solution must be able to monitor latency of Layer 7 (application layer) traffic to detect the spikes and anomalies in the typical traffic pattern.. 24. Solution must be able to integrate with vulnerability management tools and provide virtual patching capability.. 25. Solution must be able to provide protection based on all OWASP defined vulnerabilities. • توفير الدعم الفني والرخص االلازمة لمدة 3 سنوات من تاريخ التشغيل. . الدعم الفني لايندرج تحت ضمان الوكيل المنصوص عليه في نظام وزارة التجارة ( يبدأ مع انتهاء مرحلة تركيب النظام) .. توفير ورشة عمل وتدريب للحلول والبرامج المقترحة | عدد | 27 | 0 | |
| نظام فحص الملفات file protection sandbox | نظام | 2 | توريد وتركيب اجهزة نظام فحص الملفات File Protection Sandbox | "يجب توريد وتركيب نظام كشف الملفات المتقدم عبر الشبكة Host Sandboxing الحلول مع كامل مستلزماتها. . توفير الحلول الازمة مع الرخص التشغيلية لمدة 3 سنوات. يجب الالتزام بالمواصفات المطلوبة حسب الآتي:. يجب ان يكون للجهاز القدرة على الوصول الى الملفات و فحصها من خلال البرتوكولات التالية:. - CIFS. - NFS. - WebDAV. - Secure WebDAV . • يجب ان يكون الجهاز بالمواصفات التالية. - 2RU rack mount. - Hard Disk 4 x 2 TB HDD, 3.5” RAID 10. - Network Interface Ports:2 x Gigabit Ethernet ports. - Up to 50,000 files per day. •توفير الاشتراك في way-1. including license for scanning content on file servers and sharepoint servers. • الاشتراك في الدعم (Support Platinum Plus. • توفير الدعم الفني والرخص االلازمة لمدة 3 سنوات من تاريخ التشغيل. . الدعم الفني لايندرج تحت ضمان الوكيل المنصوص عليه في نظام وزارة التجارة ( يبدأ مع انتهاء مرحلة تركيب النظام) .. توفير ورشة عمل وتدريب للحلول والبرامج المقترحة | عدد | 28 | 0 | |
| نظام كشف الملفات المتقدم عبر الشبكة | نظام | 2 | توريد وتركيب نظام كشف و فحص الملفات المتقدم عبر الشبكة NX | "يجب توريد وتركيب نظام كشف الملفات المتقدم عبر الشبكة Network Sandboxing الحلول مع كامل مستلزماتها. . توفير الحلول الازمة مع الرخص التشغيلية لمدة 3 سنوات. يجب الالتزام بالمواصفات المطلوبة حسب الآتي:. · . يجب ان يكون للجهاز القدرة على العمل • . Network • توريد وتركيب عدد 4 نظام حماية الشبكات. Signature-less Detection Capability using Virtual Machine Based Dynamic Analysis. · The. proposed solution should have IPS capabilities. · The proposed solution should have Riskware. detection capabilities. · The solution must detect Zero-Day and APT attacks.. · The solution. should support IPMI. · It should support two management ports. · The proposed solutions should. be certified by the US Department of Homeland Security SAFETY Act Certification. · The. solution must utilize custom Virtual Machine (on-premise) technology to positively identify. malware, including zero-hour vulnerability exploits, polymorphic payloads, and obfuscated javascript.. The virtualization solution must not be detectable by malware in order to avoid evasion.. They Hypervisor must not be an OEM solution such as from VMWare or others. · The solution. has to be capable of automatically downloading threat intel from an intelligence cloud. · all static. analysis will occur in the appliance including: IPS, custom signature, Riskware, CnC rule. matching and others. · The solution should support inline monitoring and blocking (not only TCP. Reset). · The solution OS software must but capable of being automatically updated from the. Web management GUI. · The solution must be able to run multiple Micro Tasks in a single VM. (e.g. run sample across multiple versions of Adobe Acrobat in a Single VM Execution). · The. solution must be administered through a web-based console that doesn’t require the installation of. additional software.. · The solution must allow the creation of accounts with different roles used. to administer the solution, or just monitor the alerts.. · The solution must allow the authentication. to the console by using authentication services like RADIUS, TACACS+, LDAP and LDAPS.. ·. The solution should support remote administration using CLI and GUI (Web Console). · The. solution must be able to detect and report web exploits by using multiple versions of web. browsers and plug-ins.. · The analysis must be performed runtime in order to detect all the. malware actions, even the ones that fail in the virtual environment but might be successful on a. client workstation. Before and after differential Comparison or VM state is not acceptable.. · For. the list of applications supported in the VM's the Vendor must have a method for pushing updates. to the list of applications dynamical to the appliance without requiring a full OS or solution. upgrade.. · The solution must allow the configuration of an ACL to control access to the. management interface. · The solution must be able to utilize NetBIOS and DNS for hostname. resolution when generating alerts.. · IPS Detection of Reconnaissance Activity. · IPS Detection of. Brute Force Attacks. · IPS Uses Dynamic Analysis Engine (VM) for IPS alert validation and. correlation. · The solution should support remote administration using ssh and https. · The. solution must be able to detect and report malware downloaded by users, or downloaded in the. context of a web exploit by using multiple client operating systems with multiple service pack. levels running on both x64 and x86 architectures.. · completely unknown vulnerabilities across. protocols and applications.. · The solution must be able to detect all three stages of the modern. malware’s attack lifecycle, while highlighting every stage of the attack: Exploit, Dropper & Data. Exfiltration. · Solution should use customized hypervisor and should include instrumentation. running within itself for run-time detection analysis. · Solution should be able to handle reflective. DLL injection. · Solution should be able to detect Kernel level rootkits. · Solution should be able. to handle packed payloads. · Solution should be able to deal with VM evasion techniques. ·. Solution should have the ability to remain fully effective when configured to share no data,. events, nor any information with vendor or the vendors network.. · Solution should have the. ability to detect client-side EXPLOITS prior to any complex malware being downloaded to the. systems; complex malware is defined as malware with complex abilities such as key-logging,. data-stealing, encrypting, migrating, and installing additional complex malware.. · The solution. must be capable of blocking reliably outgoing communications to CnC servers in order to. conserve data integrity on hosts including out of band infections. · The solution must be able to. automatically generate a network communication profile if the malware tries to contact network. resources during the analysis. This profile must be used to determine if systems on the network. are compromised.. · Should provide information such as:. i. Host Modification Report. ii. Copy of. malware binary. iii. PCAP of Malware to Command & Control servers. iv. Meta Format of. Malware to Command & Control servers. v. Full URL trail identifying all of the locations from. • توفير الدعم الفني والرخص االلازمة لمدة 3 سنوات من تاريخ التشغيل. . الدعم الفني لايندرج تحت ضمان الوكيل المنصوص عليه في نظام وزارة التجارة ( يبدأ مع انتهاء مرحلة تركيب النظام) .. توفير ورشة عمل وتدريب للحلول والبرامج المقترحة | عدد | 29 | 0 | |
| تقييم مستوى نضج معمارية الامن السيبراني | خدمة | 1 | خدمات استشارية | تقييم مستوى نضج الامن السيبراني اعتمادا على مرجهية هيكلية الامن السيبراني للذكاء الاصطناعي متوافق مع متطلبات العمل الاتية: . a.Conduct gap and maturity level assessment (CMMI Maturity Levels) and define the As-Is and To-Be states on the AI Cybersecurity Architecture covering each building block.. b.Provide recommendations on how to fill the gap between current and target state and ensure flexibility and robustness for all new technologies. | عدد | 30 | 0 | |
| نظام التحقق من نزاهة الملفات والالتزام | نظام | 1 | توريد وتركيب نظام التحقق من نزاهة الملفات والالتزام (FILE INTEGRITY MONITOR&Security Compliance Check) | يجب توريد وتركيب الحلول مع كامل مستلزماتها. . توفير الحلول الازمة مع الرخص التشغيلية لمدة 3 سنوات. • توريد نظام (FILE INTEGRITY MONITOR&Security Compliance Check&Security Compliance Check&Security Compliance Check ) . • تركيب نظام (FILE INTEGRITY MONITOR&Security Compliance Check&Security Compliance Check). • توفير خدمات احترافية لنظام (FILE INTEGRITY MONITOR&Security Compliance Check&Security Compliance Check). توريد وتركيب الرخص اللازمة للخوادم (500 خادم). توريد وتركيب الرخص اللازمة لأجهزة الشبكة (50). توريد وتركيب الرخص اللازمة للتكامل مع الانظمة الامنية (2). توريد وتركيب الرخص اللازمة للامتثال واللالتزام (2). توريد و تركيب الرخص اللازمة ESXI (2) . الدعم الفني لايندرج تحت ضمان الوكيل المنصوص عليه في نظام وزارة التجارة ( يبدأ مع انتهاء مرحلة تركيب النظام) .. • توفير ورش عمل لنقل ومشاركة المعرفة لتشغيل وتركيب النظام.(8 موظفين). | عدد | 31 | 0 | |
| خدمات احترافية استشارية | خدمة | 36 | خدمات احترافية استشارية للامن السيبراني | توفير خدمات لمراجعة الاعدادات للتقنيات الرقمية لمدة 200 يوم عمل . توفير خدمات تقييم فجوات امنية لتقييم البنية التقنية والانظمة مع تقيمم المخاطر السيبرانية . توفير خدمات امنية لتقييم اختبار الاختراق لعدد 50 نظام او تطبيق و 300 عنوان شبكي و . تطوير خطة معالجة تقنية و وتشغيلية | شهر | 32 | 0 | |
| تطوير وتصميم مرجعية لمعمارية الامن السيبراني | خدمة | 1 | خدمات استشارية | تطوير اطار لمرجعة هيكلية الامن السيبراني متوافق مع متطلبات العمل حسب المتطلبات الفنية الاتية: . Develop the AI Reference Cybersecurity Architecture based on the AI UCF (defined in the previous activity), Threat Catalog, and business needs. The vendor shall:. a.Develop Threat Catalog including threats, actors (adversaries), motives, methods, risks and scenarios for each Use Case defined in Activity. b. Develop AI Reference Cybersecurity Architecture (AI RSA) following SABSA framework up to level three (logical level). The AI RSA shall comprise cybersecurity capabilities (Security Ser+F10vices in SABSA terminology), security drivers, potential threats, the existing related security solutions for each capability, and integration patterns for each domain.. develop cybersecurity rules and standards for each capability (up to 10 security rules for each capability).. d. Map the capabilities to the controls in the AI UCF defined and unified Reference security architecture . . E. The vendor must doining the required assessment with developing the required toolkit with take approval from the Cybersecurity and relevant dept. | عدد | 33 | 0 | |
| خدمة احترافية واستشارية | خدمة | 8 | خدمات احترافية لتطوير وتحسين انظمة الادارة والتحكم بالوصول | توفير خدمات احترافية استشارية لتطوير وتحسين الخدمات الاتية :. Identity access Managment Gap Assessment Report . Roadmap and Implementation Plan including all Recommendations . User Data Requirements Analysis Report for IAG . Document detailing Roles and Responsibilities and RACI for IAG . Processes, procedures, and guidelines . Workflows and Forms . IAM Use Cases 30 . PAM use cases 30. . | شهر | 34 | 0 | |
| أنظمة أمن وحماية الشبكة المتقدمة | اجهزة | 1 | توريد وتركيب انظمة أمن وحماية الشبكة المتقدمة (Network Multi-engine malware portection) | يجب توريد وتركيب الحلول مع كامل مستلزماتها. . توفير الحلول الازمة مع الرخص التشغيلية لمدة 3 سنوات. :يجب الالتزام بالمواصفات المطلوبة حسب الآتي:. Solution must be at least 4 ICAP servers distributed in two datacenters. - Solution must be at - least with 20 Engines scanning capability through 6 different dedicated servers distributed in two datacenters. - Solution must support - Solution must support Core technology enablement (CDR, DLP, multi-scanning, etc.). - 24x7x365Maintenance & Support for 3 years. - solution component to be implemented in two different datacenter sites.. The solution should support both Windows Client and Server versions. The solution should support Chrome, Firefox, Safari, Internet Explorer and Microsoft Edge for the management console. Web access to the platform should be via https protocol. The solution should support RBAC . The solution should be able to integrate with SIEM or syslog servers. The solution should provide auditable record of files and emails that has been scanned. The solution should be able to run in air gapped environments. The solution should be able to work in a network connected mode. The solution should expose APIs for integration purposes. The exposed APIs have to be officilaly documented. The solution should connect to only one URL to download the new signature definitions. The solution should support signature definition upload previously downloaded from an internet connected machine. The engine and virus definition update mechanism should support internet, manual and folder mode. The solution must provide a single pane of glass for central configuration. The solution should integrate with syslog/SIEM systems. The solution must allow the creation of accounts with different roles used to administer the solution, or for auditing purposes. The solution should provide Active Directory and LDAP group-based administrative roles. Solution should have its logs archived locally, and they should be downloadable via the GUI. The solution should support remote administration using RDP and https. The solution should provide built in database. The built in database management should be done from the product user interface. The solution should allow configuration export and backup. The solution should be able to provide 30+ different AV engines . The solution should use signature based detection. The solution should use heuristic based detection. The solution should use machine learning based detection. The multiple AV engines should be able to run in a multithreaded way. The solution should be able to support complex archive processing and extration. The solution should support over 30 different archive types. The solution should allow configuration of the archive handling process. The solution should be able to process password protected archived/files. The detection should run fully on premise with no cloud connection. There should only be 1 licensing component for all the multiple AV engines. The different AV engines have to run in an airgapped environment. The frequency of the signature definition updates has to be configurable. The signature definitions have to all come from one single point. The solution should be able to detect known vulnerabilities in binary data. The solution should be able to integrate inline with 3rd party security controls. The solution should be able to qurantine malicious sample for further analysis. The solution must allow disabling AV engines to exclude them from scanning. The solution should provide a false positive configurable threshold . The solution should be able to provide a known vulnerabilty assessment technology. The solution should detect Vulnerable Installers. The solution should detect IoT Software and Firmware Vulnerabilities. The solution should provide a file type detection technology. The solution should provide a YARA module. The solution has to be able to integrate via REST API. The REST API has to be JSON based. The solution should detect spoofing of over 4,500 file types and block spoofed files. The solution should support extraction for the follwing archive types: Zip, 7z, Jar, rar, rar5, tar, ISO, Gzip, CAB, ARJ, LZH, RPM, DEB, LZMA, WIM, SFX, XZ, VDI, VHD, MBR, CPIO, HFS, .apk .gz .msi .tgz .tbz, bz2. The archive extraction mechanism should be configurable. The solution should process Microsoft Office Documents as archives. The following self extracting archives should be supported: 7zip, WinRAR, PKZIP, IExpress. The solution should be able to blacklist/whitelist by hash, filename, filetype or mime type. The solution should be able to quarantine blocked files. The quarantine should have the option to integrate with MetaDefender Cloud for Threat Intelligence. The solution should allow different workflow rule configuration to customize the order and process in which files are handled. The solution should provide the option to integrate inline with a 3rd party security control (external scanner). The solution has to be able to integrate with SMB compatible storage. • االشتراك في الدعم (Plus Platinum Support (الصيانة والدعم غير مندرجة تحت الضمان حسب متطلبات وزارة التجارة. | عدد | 35 | 0 | |
| نظام لادارة التقنيات الامنية بالشبكة | نظام | 1 | توفير وتركيب نظام لادارة التقنيات الامنية NETWORK SECURITY POLICY ORCHESTRATION AND ASSURANCE | . يجب توريد وتركيب الحل التقني لأتمتة التقنيات الامنية بالشبكة وغيرها NETWORK POLIY ORCHESTRATION AND ASSURANCE مع كامل مستلزماتها. . توفير الحلول الازمة لمدة 3 سنوات. توفير ورشة عمل وتدريب للحلول والبرامج المقترحة (8 موظفين). يجب الالتزام بالمواصفات المطلوبة حسب الآتي:. Network Policy Orchestration & Assurance Integration with Firewall for 20 and 50 network devices. يجب الالتزام بالمواصفات المطلوبة حسب الآتي: . The proposed system should be deployed in two data centers. Also, it should be deployed by the Professional Service team from the mother company.. Bidder should provide HLD , LLD , Operation Guides for End-user and Admins , Minimum Baseline Security Standards , and test uses cases in SDAIA template documents.. The proposed system should be virtual based.. The proposed solution should be able to integrate with SIEM tool and forward all the logs and events to the SIEM solution.. The proposed solution should support multi tiers architecture. . The proposed solution should support Single Sing On.. The proposed solution should support integration with Active Directory (AD), Network Time Protocol (NTP) and Domain Name System (DNS).. Bidder should provide all the required commu ation matrix for the proposed solution.. Bidder should provide the data flow of the proposed solution.. The data should be encrypted in transit.. The data should be encrypted at rest.. The proposed solution should support RBAC model for separation of duties and data.. The proposed solution should be able to integrate with Multi Factor authentication solution (MFA).. The proposed solution should be highly available. The solution should support automatic replication between the solutions in two data centers.. The proposed solution should support integration and not limited to Palo Alto, Cisco, Fortinet, Juniper firewalls (VM, VSYS and Appliances) ,Load Balancers , and WAF . All functionality of the proposed solution’s platform should be tightly integrated and operated from a single pane of glass. . The proposed solution should support user customizable query language, which allows the user to perform a variety of tasks . The proposed solution should store unlimited versions of firewall configurations with all changes detected and stored in encrypted database. . The proposed Solution should support continues real-time monitoring and detection of all changes.. The proposed solution should provide a Device Dashboard where information on Rule Usage is displayed and the top used rules should be listed based on percentages in descending order. . Used and Unused Rules:. In addition to the detailed rule usage and object analysis information, the proposed solution should provide information to help optimize the operation of a policy. . The proposed solution should also highlight which rules have seen no activity at all, to help chart a remediation path for the removal of unused rules and reduce policy complexity while increasing security posture. . Redundant / Shadowed Rules:. The proposed solution should provide a standard report for identifying redundant and shadowed rules with details that indicate the portion of the rules that causes the redundancy. Users can configure the varying level of redundancy and overlap.. Rule Consolidation:. The proposed solution should provide a standard report that displays security rules on the firewall that may be safely consolidated without changing the behavior of the policy.. The proposed solution should Support Real-Time change analysis and reporting for the monitored Firewalls.. The proposed solution should provide security compliance reports utilizing built-in and customized security controls. . The proposed solution should include extensive policy rule search capabilities and global search functions across multiple policies. Additionally, reporting and compliance checks provide the ability to customize a report to see if a specific object is allowed. This can include IPs, networks, groups, zones, or services. The proposed solution should support real-time compliance custom and assessment dashboard.. The proposed solution operating system should be hardened. . The proposed solution should have ability to Identify any unused rules, unused network objects and unused service objects in existing policies to prevent gaps and reduce unnecessary complexity.. The proposed solution should provide reports for rule consolidation.. The proposed solution should provide Object usage like ports and IPs within the Rule for Clean-up.. The proposed solution should support Creation of custom controls and assessments to identify automatically rules for clean-up and recertification.. The proposed solution should provide comprehensive network mapping for managed devices. . The proposed solution should store the data on encrypted disk.. The proposed solution should provide Rule usage in time query capabilities and visualization on histogram.. The proposed solution should have the ability to normalize firewall rulesets for single consistent view across multiple vendors.. The proposed solution should have the ability to generate custom reports and queries.. The proposed solution should provide built-in security policies and baselines based on security best practices. . The proposed solution should support multi-vendor next generation firewalls. . The proposed solution should be able to read and analyze existing policies for managed devices upon deployment. . The proposed solution should support Custom assessments can be run for specific device group or all devices if required.. The proposed solution should provide out of the box compliance reports like ISO 27001, NCA ,CSA etc compliance report generated for individual Firewall and Groups of Firewalls. The proposed solution should provide full audit logs for any system changes. . The proposed solution should support Policy and Rule Documentation for all integrated Firewalls & network devices.. The proposed solution should support Role base access with Granular privileges definition limiting user group access to specific system functions/interface (i.e. dashboard, configuration, change management) as well as functions within particular systems limited to selected device groups or all devices.. The proposed solution should be able to automate and generate reports via email. . The proposed solution should provide user-friendly web interface based on HTML 5. . The proposed solution should support multi-user roles/privileges. . The proposed solution should support authentication of users using RADIUS, AD, LDAP. . The proposed solution should provide web user interface that is compatible with modern web browsers (Internet Explorer, Firefox, and Chrome). . The proposed solution should support single and distributed environment for deployment. . The proposed solution should support Fully customizable Web-based dashboard with customizable metrics, defined using security information query language, including NAT rules. The proposed solution reports and notifications are to be available in a minimum of the following formats HTML, PDF.. The proposed solution should support all functionality through REST-API.. The proposed solution should provide recommendations to fix overly permissive rules. . The proposed solution should allow admins to develop customized controls for security analysis. . The proposed solution should have the ability to graphical mapping and simulating traffic path flow. . The proposed solution should support full-fledged Workflow based Firewall Rule Change Management.. The proposed solution should provide Firewall policies management, Audit and Compliance management as well as automated change management and recertification process and workflow.. The proposed solution should have the ability to push the configuration directly on the firewalls without needs to firewall management station.. The proposed solution should have the ability to connect read/write with and without centralized firewall managers including Panorama, Cisco FTD, Fortinet Manager. The proposed solution should have the ability to manually and automatically remove deactivated rules. . The proposed solution should provide Firewall policies management, Audit and Compliance management as well as automated change management and recertification process and workflow. . The proposed solution reports and notifications are to be available in a minimum of the following formats HTML, PDF.. • توفير الدعم الفني والرخص االلازمة لمدة 3 سنوات من تاريخ التشغيل. . الدعم الفني لايندرج تحت ضمان الوكيل المنصوص عليه في نظام وزارة التجارة ( يبدأ مع انتهاء مرحلة تركيب النظام) .. | عدد | 36 | 0 | |
| أجهزة حماية الشبكة جدار ناري Next Gen Firewall | اجهزة | 5 | توريد وتركيب أجهزة جدار ناري Next-Gen Firewall | يجب توريد وتركيب الحلول مع كامل مستلزماتها. . توفير الحلول الازمة مع الرخص التشغيلية لمدة 3 سنوات. يجب الالتزام بالمواصفات المطلوبة حسب الآتي:. NGFW should cover interconnectivity for the chosen zones.. NGFW should have capability to interconnect through 40Gbps and QSFP interfaces with at least 4 interfaces on each firewall .. NGFW should able at least to handle 50 Gbps throughput as stateful without applying SSL/IPS inspection and 25 Gbps with IPS inspection.. NGFW should able to integrate with environment and be integrated with proposed network security orchestration solution.. NGFW should including the all hardward parts and passive components such as cables,SFP,Stand, etc.. the linceses should be provided for 3 years including the all security function IPS, SSL, Threat feeds, and advanced support. 7. Redundant FANs and Power supply . توفير الدعم الفني والرخص االلازمة لمدة 3 سنوات من تاريخ التشغيل. . الدعم الفني لايندرج تحت ضمان الوكيل المنصوص عليه في نظام وزارة التجارة ( يبدأ مع انتهاء مرحلة تركيب النظام) .. توفير ورشة عمل وتدريب للحلول والبرامج المقترحة (8 موظفين) | عدد | 37 | 0 | |
| نظام الكشف والاستجابة للأجهزة الطرفية | رخصة | 500 | توريد وتركيب رخص لنظام الكشف والاستجابة للأجهزة الطرفية(Endpoint Detection and Response) . | Three-years EDR software subscription expansion for 500 endpoints with . - solution component to be implemented in two different datacenter sites.. - 24x7x365Maintenance & Support for 3 years. On premise EDR solution with capability to work as mutitenancy to improve security operations productivity and enhance detection and response capabilities by including more security components into a unified whole that offers multiple streams of telemetry, presenting options for multiple forms of detection and concurrently enabling multiple methods of response. . Centralization of normalized data, Correlation of security data and alerts into incidents. A centralized incident response capability . · Allows deep visibility into all endpoint activity – in real time and retrospectively.. · Simplifies threat hunting and detection.. · Prevents threats through your preferred AV engine and process blocking.. · Automates response with pre-built scripts and playbooks.. · See all endpoint activity across Windows, Mac, and Linux systems and gain unmatched insight through the collection of all executable files and scripts that are analyzed against the latest threat intelligence. . · Detect threats in real time or hunt retrospectively through recorded events. . · Monitor a full software inventory and identify vulnerabilities with links to MITRE CVEs or Microsoft KB Reports.. · View all process data, user activity, registry events, file system activity, and memory data and more.. · Review full software inventory and known CVE and KB vulnerabilities. · Collect executable files and scripts for analysis and threat hunting.. · Create and save advanced queries using Boolean logic.. · Monitor endpoints in real-time and retrospectively, on and off the network. · Monitor key events with playback analysis to automatically deliver an incident timeline, along with prioritized alerts.. · The solution must be able to automate response with scripts and playbooks, including the ability to isolate endpoints, terminate processes, remove files, and deploy custom scripts. . · The ability to start investigations with memory analysis, vulnerability scans, and system inventory. The ability to capture data and memory and full disk images, as well as the ability to remotely access endpoints to view and take action on files and processes.. · The ability to take action and automate response with a customizable library of scripts and playbooks. · Collect forensically sound data in real time for deeper investigations.. · Remotely access and control endpoint file systems and processes. · Integrate with SIEMs, NGFWs, etc., to execute response actions.. · Maintain full control of endpoints with full remote shell capabilities.. · Endpoint threats must be mapped to MITRE ATT&CK™ to allow SDAIA analysts to see the TTPs in use and to determine the proper response. Untrusted executables are automatically sent to SDAIA sandbox and can be integrated into process blocking (IOC, hash, and YARA rules).. · The solution must support Windows, Linux and MacOS for agents installations. · The solution must automatically collect executables and script file at the first time executed in the environment. · The solution must automatically and dynamically collect installed software on all endpoints and alert against any identified CVE. · The solution must record process activities (process start, image load, process access, service and process exit) in real time. · The solution must record when a process creates a remote thread in another process, or when a thread is created in the current process by another process. · The solution must be able to ingest open source IoCs and YARA rules and use it to run scans on target endpoint(s). · The solution must allow users the ability to query across collected endpoint behaviors and must support saving search queries. · The solution must have Advanced Query Builder to allows for users to craft queries that include Boolean logic, targeting of endpoint groups for inclusion/exclusion, and assists users in creating these advanced queries that are useful for investigation, behavior rule creation, and threat hunting. · The solution must record connected endpoint(s) information including but not limited to: host name, IP Address, processor, memory, OS, OS version and last connected time. · The solution must be able to dynamically update recorded connected endpoint(s) information. · The solution must support endpoint grouping (static groups, dynamic groups and imported groups). · The solution must be able to show endpoint related task results, alerts, USB activities, login history and installed software as part of the endpoint record.. · The soluation must support Multitenant architecture. The solution be compliant with CSDC EDR technologies . Share knowleged must be provided. • الاشتراك في الدعم (Support Platinum Plus) الصيانة والدعم غير مندرجة تحت الضمان حسب متطلبات وزارة التجارة | عدد | 38 | 0 | |
| الامن المدار لمركز عمليات الامن السيبراني | خدمة | 36 | خدمة تشغيلية واحترافية لمتطلبات الأمن السيبراني التشغيلية المدارة | خدمات SOC الأمنية • يجب على مقدمي خدمات الأمن المُدارة توفير خدمات الكشف والاستجابة المُدارة (مراقبة التهديدات في الوقت الحقيقي) لمدار 24 ساعة يوميًا، طوال السنة، باشتراك سنوي يشمل تراخيص تصل إلى 70 جيجابايت. • يجب تحديد وموافقة الوصول إلى خدمات الأمن المُدارة من قبل قسم الأمن السيبراني. • يجب استضافة جميع الأصول الأمنية في المنظمة مع وضع خطة محددة لتسليمها إلى الفريق ذي الصلة بناءً على توجيهات مالك المشروع، مع تضمين جميع الوثائق وليس اقتصارًا على: LLD، HLD، حالات الاستخدام، التراخيص، مصفوفة الاتصال، قائمة الوصول للمستخدم، إلخ. • يجب أن تشمل الأصول الأمنية المذكورة، ولكن لا تقتصر عليها: أجهزة الشبكة، Active Directory مايكروسوفت، أجهزة مكتبية بنظام مايكروسوفت، خوادم بنظام مايكروسوفت، خوادم لينكس، جدران الحماية الحدودية، جدران الحماية لمركز البيانات، EDR، جدار حماية تطبيقات الويب • يجب على مقدمي خدمات الأمن المُدارة توفير جمع السجلات، تحليل السجلات، تقارب السجلات وتحليل البيانات، ويجب أن تتمثل البيانات في مقر المنظمة وفقًا للتوافق. • يجب على مقدمي خدمات الأمن المُدارة توفير رؤية على مدار الساعة في التهديدات والثغرات والهجمات، بالإضافة إلى استجابة الحوادث مع خدمات التصحيح. • يجب على مقدمي خدمات الأمن المُدارة توفير خدمة الكشف والاستجابة وتوفير الرؤية والخبرة التي تسمح لهم بالتعرف عندما تكون هناك حاجة إلى إجراءات استجابة، وتقييم المخاطر. • يجب أن يلتزم مقدمي خدمات الأمن المُدارة بجميع اللوائح ذات الصلة بالأمن السيبراني. • يجب أن توفر خدمات الأمن المُدارة إجراءات التشغيل القياسية (SOPs) بما في ذلك النموذج التشغيلي، وعمليات SOC، وسير العمل مع الأدوار والمسؤوليات بين المزود والمنظمة، والتفاعل مع أمان المعلومات، واتفاقات مستوى الخدمة والكتب العمل، وإجراءات التصعيد. • يجب على مقدمي خدمات الأمن المُدارة توفير خدمات استخبارات التهديد المُدارة باستخدام مصادر مفتوحة بهدف فهم أحدث التهديدات السيبرانية، في أقرب وقت ممكن بناءً على المخاطر والوضع الأمني. • يجب على مقدمي الخدمات المُدارة توفيرالدعم لجميع السجلات بناءً على سياسة الاحتفاظ، وبإمكانية تصدير السجلات المحفوظة عند الحاجة. • يجب على مقدمي الخدمات المُدارة محو جميع البيانات/المعلومات التاريخية ذات الصلة بسادايا بما في ذلك جميع الأنشطة والسجلات والحوادث والتكاملات بعد تأكيد تسليم المشروع. • يجب على مقدمي الخدمات المُدارة دعم جميع متطلبات التقارير اللازمة لتلبية جميع متطلبات التنظيم الداخلية والخارجية. • يجب على مقدمي الخدمات المُدارة دعم تبادل المعلومات الاستخبارية مع SOC سادايا بناءً على المعايير المحددة من قبل فريق CTI في سادايا. • يجب على مقدمي الخدمات المُدارة أن يأخذوا في الاعتبار الEDR المقترح للعملية ونطاق متطلبات الكشف والاستجابة. • يجب على خدمات الأمن المُدارة أخذ الموافقة من الإدارة ذات الصلة في الأمن السيبراني لحالات الاستخدام وطلبات التغيير وإنشاء المستخدمين. • يجب الموافقة على أي تصميم أو تغيير من قبل أعضاء فريق الأمن السيبراني وأي قسم ذي صلة من جانب السدايا. • يجب تقديم نقل المعرفة كل 6 أشهر مع أعضاء فريق الأمن السيبراني (SOC) لجميع المستويات مثل: تحليل L1، L2، L3، والهندسة والإدارة. • يجب على المقاولين الامتثال لمتطلبات التكنولوجيا التالية: 1. يجب أن تكون الحلول المقترحة قادرة على توفير وظائف SIEM الجيل القادم. 2. يجب أن تكون حلول SIEM مبنية على تكنولوجيا البيانات الكبيرة مع القدرة على استيعاب تخزين غير محدود. 3. يجب تثبيت تراخيص حلول SIEM دون الاتصال بالإنترنت ويجب أن تبرز الخيارات والقيود الدائمة والاشتراكية للتراخيص. 4. يجب أن تكون حلول SIEM قابلة للتوسيع والانتشار في بيئات متعددة مختلفة. 5. يجب أن تأخذ حلول SIEM قدرات العميل المتعددة في جمع البيانات وإثرائها والبحث فيها والاحتفاظ بها بعين الاعتبار. 6. يجب أن تكون فترة الاحتفاظ على الأقل 6 أشهر من السجلات التي يمكن البحث فيها عبر الإنترنت، و 12 شهرًا من السجلات التي يمكن البحث فيها، وثلاث سنوات من السجلات المؤرشفة التي يمكن البحث فيها. 7. يجب على حلول SIEM أن تتمكن من التعامل مع زيادة مرة واحدة في السعة السائلة (EPS) بمعدل أربع مرات خلال ساعة واحدة دون أي تخزين مؤقت أو تدهور في أداء الحل. 8. يجب أن تكون حلول SIEM قادرة على تحقيق التوافر العالي بين ثلاثة مراكز بيانات مختلفة لطبقات الجمع والترابط والفهرسة والأرشفة. 9. يجب تشفير جميع التواصلات بين جميع مكونات حلول SIEM. 10. يجب أن لا تفرض حلول SIEM أي قيود على عدد الحقول التي يمكنها فهرستها. 11. يجب أن تسمح التصميمات والبيانات المقترحة لحلول SIEM بالوصول السريع إلى تيرابايتات الأرشفة والبيانات التاريخية. يجب أن تكون قادرة على توفير البحث السريع جدًا والموزع. | شهر | 39 | 0 |
39 بند
كراسة الشروط الرئيسية
المستندات الداعمة (11 ملف)
لم يتم ترسية هذه المنافسة بعد
الآليات
القائمة الإلزامية
آلية وزن المحتوى المحلي في التقييم المالي
معايير التقييم
معايير التقييم الفني
| المستوى الاول | المستوى الثاني | المستوى الثالث | الوزن النهائي |
|---|---|---|---|
| التقييم الفني |
معايير التقييم المالي
| المستوى الاول | المستوى الثاني | المستوى الثالث | الوزن النهائي |
|---|---|---|---|
| التقييم المالي | السعر | التكلفة الكلية | 100% |