منافسة عامة
✓ مرسّى
مشروع صيانة وتشغيل ودعم الامن السبراني لإمارة منطقة تبوك
أمارة منطقة تبوك
رقم المنافسة
250239002487
المعرّف
#899794
عنوان الضمان الإبتدائى
إمارةمنطقة تبوك
الغرض من المنافسة
مشروع صيانة وتشغيل ودعم الامن السبراني لإمارة منطقة تبوك
| التاريخ | ميلادي | هجري |
|---|---|---|
| تاريخ النشر | 2025/02/10 14:43 | — |
| آخر موعد للاستفسارات | 2025/03/10 | 1446-09-10 |
| آخر موعد تقديم العروض | 2025/03/22 14:00 | 1446-09-22 |
| موعد فتح العروض | 2025/03/23 10:00 | 1446-09-23 |
| موعد فحص العروض | — | — |
| التاريخ المتوقع للترسية | 2025/03/16 | 1446-09-16 |
| تاريخ بدء الأعمال | 2025/03/23 | 1446-09-23 |
| تاريخ خطاب تأكيد المشاركة | — | — |
| بداية إرسال الأسئلة | 2025/03/20 | 1446-09-20 |
| أقصى مدة للإجابة | 7 يوم | |
| مكان فتح العروض | مبنى الامارة | |
| مدة الوقفة | 5 يوم |
موقع التنفيذ
مجال التصنيف
الأنشطة
- • تقنية المعلومات
جدول 1 جدول العماله
| العدد | وصف البند | السنة الاولى | السنة الثالثة | السنة الثانية | الرقم التسلسلي | المسمى الوظيفي | أقل مؤهل للقبول | الحد الأدني لسنوات الخبرة | عدد ساعات العمل الاساسي المتوقعة | عدد ساعات العمل الاضافي المتوقعة |
|---|---|---|---|---|---|---|---|---|---|---|
| 1 | "- خبرة لا تقل عن خمس سنوت في مجال الأمن السيبراني ومخاطر الأمن السيبراني -حاصل على شهادات في مجال الأمن السيبراني بالمهام المقدمة:D3 GREM, CISA, CISM, CCNP SECURITY, CEH, CHFI, CCSP, CASP+ -المتابعة والإشراف على أعمال الإدارة فريق الأمن السيبراني بشكل كامل -إدارة التقييم والصيانة الدورية لسياسات الأمن السيبراني في الإمارة بشكل كامل -متابعة مراحل الإنجاز والتواصل الفعال مع أصحاب الشأن وفريق العمل فيما يخص ذلك -تقديم الرأي والمشورة للإدارة وفرق الأمن السيبراني في مواضيع الأمن السيبراني -مراجعة فعالية ضوابط الأمن السيبراني للغمارة ومواءمتها للأهداف الاستراتيجية وخطط العمل -متابعة حالة التطوير للإدارة وتطوير أو تعديل برنامج الأمن السيبراني -متابعة الالتزام بضوابط الهيئة الوطنية للأمن السيبراني بشكل دوري والإشراف على فرق العمل لتحقيق الامتثال للضوابط وتحديث سجل المخاطر بشكل دوري لمضمان معرفة جوانب القصور -تزويد الإدارة بموجز عن التطورات والتوجهات والضوابط السيبرانية اللازمة لحماية الإمارة. - العمل على تطوير مهارات كوادر الأمن السيبراني - العمل والإشراف على التدريب ونقل المعرفة ومتابعة التحسين المستمر للكوادر السيبرانية ويشمل: -وضع خطط تدريب مخصصة للكوادر -المتابعة المستمرة لنقل المعرفة -متابعة التحسين المستمر وتقديم وتطوير برامج التدريب طيلة مرحلة المشروع -التواصل بفاعلية وبأولوية تامة مع المتطلبات سواء من وزارة الداخلية أو من الهيئة الوطنية للأمن السيبراني أو أي جهة ذات علاقة سواء داخلية أو خارجية وتشمل: -التنبيهات الأمنية-التحديثات المطلوبة -الاستفسارات وتعبئة النماذج الخاصة به إن وجدت -التواصل بفاعلية مع الأطراف الخارجية عند وقوع حادث سيبراني | 1 | 0 | 2880 | 1 | استشاري مخاطر أمن سيبراني | بكالوريوس حاسب آلي أو ما يعادله | 5 | 2880 | 0 |
| 1 | خبرة لا تقل عن خمس سنوت في مجال الأمن السيبراني ومخاطر الأمن السيبراني -حاصل على شهادات في مجال الأمن السيبراني بالمهام المقدمة: GRCP, CCEP, CGEIT, CISSP, CRMA, CISM, CISAG, CRISC, CGRC -حوكمة الأمن السيبراني -ضمان تلبية متطلبات ضوابط الأمن الهيئة الوطنية للأمن السيبراني -تنفيذ وتصميم الملفات ذات الصلة -تطوير سياسات الأمن السيبراني للإدارة وتحديثها -تحليل ضوابط الأمن السيبراني وتقييم فاعليتها ضمان الالتزام بمتطلبات إدارة مخاطر الأمن السيبراني للإدارة والمتطلبات القانونية ذات الصلة -التواصل بفاعلية وبأولوية تامة مع المتطلبات سواء من وزارة الداخلية أو الهيئة الوطنية للأمن السيبراني أو أي جهة ذات علاقة سواء داخلية أو خارجية ويشمل: -التنبيهات الأمنية -التحديثات المطلوبة -الاستفسارات وتعبئة النماذج الخاصة إن وجدت المرونة في القيام بمهمات أخرى خاصة بإدارة الامن السيبراني حسب الحاجة ورؤية الإدارة -تطوير وتحديث سياسات وضوابط ومعايير الأمن السيبراني للإمارة -التواصل الفعال مع الإدارة العليا أو الإدارات ذات العلاقة بشأن حوكمة الأمن السيبراني -التأكد من وضع خطط رفع الوعي بسياسات ومعايير وضوابط الأمن السيبراني ومتابعة فعالية تطبيقها. -تقييم سياسات وضوابط ومعايير الأمن السيبراني -المشاركة في وضع الإجراءات ومتابعة وتدقيق الالتزام معرفة بمتطلبات سياسات وضوابط ومعايير الأمن السيبراني وحماية البيانات المعمول بها -معرفة عميقة بالامن السيبراني وحماية البيانات -معرفة بسياسات واستراتيجيات الأمن السيبراني المعمول بها -مهارة تطوير وتحديث السياسات التي تعكس متطلبات الأمن السيبراني وأعمال الإمارة -معرفة بمنهجيات وطرق وحكومة الأمن السيبراني | 1 | 0 | 2880 | 2 | استشاري حوكمة الأمن السيبراني | بكالوريوس حاسب آلي أو ما يعادله | 5 | 2880 | 0 |
| 1 | "- سعودي - خبرة لا تقل عن سنة في مجال الامن السيبراني ومخاطر الأمن السيبراني - حاصل على شهادات في مجال الامن السبراني بالمهام المقدمة مثل: - Security*, CCNA Security, ISC, CEH, GRC - التواصل الفعال مع الإدارة العليا أو الإدارات ذات العلاقة بشأن مخاطر الأمن السيبراني - التأكد من وضع الخطط والتدابير اللازمة للتعامل مع مخاطر الأمن السيبراني وفق السياسات والضوابط المعمول بها - تحديد مخاطر الأمن السبيبراني - تحديد وتحليل وتقييم المخاطر بشكل دوري وكلما خضع أي برنامج أو نظام لتغيير جوهري - تقديم التوصيات بشأن قبول المخاطر وتحملها - معرفة بتهديدات الأمن السيبراني ومخاطره والقضايا التي تثيرها كل من التقنيات الجديدة ومصادر التهديدات - معرفة بمبادئ الأمن السيبراني وحماية البيانات - معرفة بمنهجيات وطرق إدارة مخاطر الأمن السيبراني - معرفة بأصول الإمارة ومهارة تطبيق منهجيات تقييم المخاطر. - المرونة بالقيام بأعمال أخرى خاصة بالأمن السيبراني حسب الحاجة ورؤية الإدارة | 1 | 0 | 2880 | 3 | أخصائي مخاطر أمن سيبراني | بكالوريوس حاسب آلي أو ما يعادله | 1 | 2880 | 0 |
| 1 | "- سعودي - خبرة لا تقل عن سنة في مجال الامن السيبراني ومخاطر الأمن السيبراني - حاصل على شهادات في مجال الامن السبراني بالمهام المقدمة مثل: - Security*, CCNA Security, ISC, GRC - التواصل الفعال مع الإدارة العليا أو الإدارات ذات العلاقة بشأن مخاطر الأمن السيبراني - متابعة والتأكد من تطبيق سياسات وضوابط ومعايير الأمن السيبراني المعمول بها - تطوير وتطبيق آليات فعالية لتوكيد الالتزام بسياسات وضوابط ومعايير الأمن السيبراني المعمول بها - إعداد نماذج وتقارير الالتزام ورفعه للإدارة العليا - تقديم التوصيات حول تطوير سياسات وضوابط ومعايير الأمن السيبراني وطرق التدقيق والمتابعة الخاصة بها - معرفة بمتطلبات سياسات وضوابط ومعايير الأمن السيبراني وحماية البيانات المعمول بها - كعرفة بمبادئ الأمنا لسيبراني وحماية البيانات - معرفة بمنهجية توكيد التزام الأمن السيبراني وأفضل الممارسات لذلك - مهارة تطبيق سياسات ومعايير وضوابط الأمن السيبراني داخل الإمارة - معرفة بالمستجدات في مجال الأمن السيبراني وخاصة ما يتعلق بالسياسات والضوابط والمعايير ذات العلاقة - المرونة بالقيام بأعمال أخرى خاصة بالأمن السيبراني حسب الحاجة ورؤية الإدارة | 1 | 0 | 2880 | 4 | أخصائي الالتزام بالأمن السيبراني | بكالوريوس حاسب آلي أو ما يعادله | 1 | 2880 | 0 |
| 1 | "- سعودي - خبرة لا تقل عن سنة في مجال الامن السيبراني ومخاطر الأمن السيبراني - حاصل على شهادات في مجال الامن السبراني بالمهام المقدمة مثل: - Security*, CCNA Security, ISC, GRC - تطوير وتحديث سياسات وضوابط الأمن السيبراني للإمارة - التواصل الفعال مع الإدارة العليا أو الإدارات ذات العلاقة بشأن مخاطر الأمن السيبراني - التأكد من وضع خطط لرفع الوعي بسياسات ومعايير وضوابط الأمن السيبراني ومتابعة تطبيقها - تقييم سياسات وضوابط ومعايير الأمن السيبراني وفعالية تطبيقها - المشاركة في وضع إجراءات توكيد ومتابعة ودقيق الالتزام بسياسات الأمن السيبراني - معرفة بمتطلبات سياسات وضوابط ومعايير الأمن السيبراني وحماية البيانات المعمول بها - معرفة بمبادئ الأمن السيبراني وحماية البيانات - معرفة بسياسات واستراتيجيات الأمن السيبراني المعمول بها. - مهارة تطوير وتحديث السياسات التي تعكس متطلبات الأمن السيبراني وأعمال الإمارة - معرفة بمنهجيات وطرق حوكمة الأمن السيبراني - المرونة بالقيام بأعمال أخرى خاصة بالأمن السيبراني حسب الحاجة ورؤية الإدارة | 1 | 0 | 2880 | 5 | أخصائي حوكمة الأمن السيبراني | بكالوريوس حاسب آلي أو ما يعادله | 1 | 2880 | 0 |
| 2 | "- سعودي - خبرة لا تقل عن سنة في مجال الامن السيبراني ومخاطر الأمن السيبراني - حاصل على شهادات في مجال الامن السببراني بالمهام المقدمة مثل: - Security*, CCNA Security, ISC, GRC, CEH - تحليل تنبيهات الأنظمة والشبكات التي يتم الحصول عليها من مصادر مختلفة لتحديد الأسباب المحتملة لأي أحداث يتم اكتشافها - توثيق الحوادث السيبرانية المشتبه بها التي من شانها أن تؤدي إلى أثر فوري أو مستمر وفقا لخطة الإمارة للاستجابة للحوادث السيبرانية وتصعيداه والإبلاغ عنه - تقديم تقارير لأحداث الشبكات والأنشطة الأخرى ذات الصلة بالأمن السيبراني - الكشف عن الهجمات والأنشطة المشبوهة وحالات إساءة الاستخدام والتعرف عليها والتنبيه بشأنها في الوقت المناسب وتمييزها عن الأنشطة الاعتيادية - معرفة بمنهجيات وأساليب تحليل البيانات لاكتشاف الأحداث السيبرانية في النظم والشبكات - معرفة بمفاهيم نظم وشبكات الحاسب الآلي ومنهجيات تشغيلها وإدارتها - معرفة بالتهديديات والثغرات في نظم وشبكات الحاسب الآلي - مهارة استخدام أدوات الدفاع السيبراني وإدارة الشبكات لجمع البيانات وتحليل أنماط حركة مرور البيانات عبر الشبكات - معرفة بأفضل الممارسات لمنهجيات تحليل حركة المرور عبر الشبكات - المرونة بالقيام بأعمال أخرى خاصة بالأمن السيبراني حسب الحاجة ورؤية الإدارة | 2 | 0 | 5760 | 6 | محلل دفاع أمن سيبراني | بكالوريوس حاسب آلي أو ما يعادله | 1 | 5760 | 0 |
6 بند
جدول 2 تجديد التراخيص والدعم الفني لأنظمة الأمن السيبراني لمدة 3 سنوات
| البند | الفئة | وصف البند | المواصفات | وحدة القياس | السنة الاولى | السنة الثالثة | السنة الثانية | الرقم التسلسلي |
|---|---|---|---|---|---|---|---|---|
| تجديد ترخيص نظام مركز مراقبة عمليات الأمن السيبراني | تراخيص | تجديد ترخيص نظام مركز مراقبة عمليات الأمن السيبراني SOC / SIEM | نظام مركز مراقبة عمليات الأمن السيبراني SOC / SIEM • On Premise 4 Elastic Enterprise subscription - 64GB - 3 years • Professional Service & Support for 50 Offline Days (8 Hours Per Day) | رخصة | 4 | 0 | 0 | 1 |
| تجديد تراخيص نظام إدارة التحكم بالأجهزة والهواتف المحمولة | تراخيص | تجديد تراخيص نظام إدارة التحكم بالأجهزة والهواتف المحمولة MDM | نظام إدارة التحكم بالأجهزة والهواتف المحمولة MDM • On Premise 200 Licenses | رخصة | 200 | 0 | 0 | 2 |
| تجديد تراخيص وضمان جهاز إتلاف البيانات الرقمية | تراخيص | تجديد تراخيص وضمان جهاز إتلاف البيانات الرقمية Data Destroy | إتلاف البيانات الرقمية Data Destroy • On Premise 1 Device | دعم ورخص | 1 | 0 | 0 | 3 |
| تجديد تراخيص نظام مسح البيانات الرقمية | تراخيص | تجديد تراخيص نظام مسح البيانات الرقمية Data Eraser | مسح البيانات الرقمية Data Eraser • On Premise 100 Licenses | رخصة | 100 | 0 | 0 | 4 |
| تجديد تراخيص نظام إدارة الأصول | تراخيص | تجديد تراخيص نظام إدارة الأصول Asset Management | نظام إدارة الأصول Asset Management • On Premise Standard Licenses • L2 & L3 Support | رخصة | 1 | 0 | 0 | 5 |
| تجديد تراخيص نظام التحكم بالوصول للشبكة الداخلية | تراخيص | تجديد تراخيص نظام التحكم بالوصول للشبكة الداخلية NAC | نظام التحكم بالوصول للشبكة الداخلية NAC • On Premise 2500 Endpoint | رخصة | 2500 | 0 | 0 | 6 |
| تجديد تراخيص نظام إدارة الصلاحيات ومراقبة الدخول للأنظمة الحساسة | تراخيص | تجديد تراخيص نظام إدارة الصلاحيات ومراقبة الدخول للأنظمة الحساسة PAM | 7 نظام إدارة الصلاحيات ومراقبة الدخول للأنظمة الحساسة PAM • On Premise Secret Server w/Connection manager – 50 users • On Premise Secret server business users 700 business users • On-site professional services • Professional service 1 year | رخصة | 750 | 0 | 0 | 7 |
| تجديد رخص نظام فحص الثغرات | تراخيص | تجديد رخص نظام فحص الثغرات Vulnerability Management | 8 نظام فحص الثغرات Vulnerability Management • On Premise Standard Licenses Network & System | رخصة | 1 | 0 | 0 | 8 |
| تجديد رخص نظام منع تسريب البيانات | تراخيص | تجديد رخص نظام منع تسريب البيانات DLP | نظام منع تسريب البيانات DLP تجديد رخص نظام منع تسريب البيانات DLP | رخصة | 1 | 0 | 0 | 9 |
9 بند
جدول 3 تراخيص استخدام منصة التوعية بالأمن السيبراني مع الدعم الفني لمدة 3 سنوات
| البند | الفئة | وصف البند | المواصفات | وحدة القياس | السنة الاولى | السنة الثالثة | السنة الثانية | الرقم التسلسلي | ملف البند |
|---|---|---|---|---|---|---|---|---|---|
| رخص منصة التوعية بالامن السيبراني | التوعية | رخص منصة التوعية بالامن السيبراني | - يجب أن يكون للجهة المزودة للمنصة خبرة سابقة في التعامل مع جهات حكومية. - القدرة على تعديل الكود المصدري للمنصة لتلبية متطلبات التخصيص. - توفير الدعم الفني للبرنامج ويشمل المنصة التعليمية وأداة المحاكاة طول مدة العقد ويكون المنفذ مسؤول عن: - إصلاح الأخطاء في المنصة التعليمية وأداة التصيد الالكتروني. - الإجابة على التساؤلات المختصة بسير العمل. - عمل التحديثات في حال وجود نسخ جديدة. - مرفق ملف داعم | رخص | 1 | 0 | 0 | 1 | تراخيص استخدام منصة التوعية بالأمن السيبراني مع الدعم الفني لمدة 3 سنوات.pdf |
1 بند
جدول 4 تجديد التراخيص والدعم الفني لأنظمة الأمن السيبراني لمدة 3 سنوات
| البند | الفئة | وصف البند | المواصفات | وحدة القياس | السنة الاولى | السنة الثالثة | السنة الثانية | الرقم التسلسلي | ملف البند |
|---|---|---|---|---|---|---|---|---|---|
| توريد وتركيب وتشغيل نظام تشفير البيانات | أنظمة | توريد وتركيب وتشغيل نظام تشفير البيانات Data Encryption Solution | نظام تشفير البيانات Data Encryption Solution سهولة التشغيلية: أن يضمن الحل إدارة السياسات المركزية ومفتاح التشفير التحكم في بياناتك عبر كل خادم فعلي وافتراضي داخل وخارج الإمارة. تقليل المخاطر: وذلك من خلال تحقيق متطلبات الامتثال وأفضل الممارسات لحماية البيانات من التهديدات الخارجية أو المتسللين من الداخل باستخدام تشفير بيانات مثبت وعالي الأداء وقابل للتطوير. المرونة: التعامل بسرعة مع متطلبات أمان البيانات الجديدة ومتطلبات الامتثال من خلال وجود حل جاهز وقادر على حماية جميع البيانات الحساسة. Capabilities: • Centralized management console • Monitoring and reporting • Data discovery and classification - Risk analysis with data visualization • Data discovery and classification can be combined with transparent encryption to automatically encrypt sensitive data at the file level. • Ransomware protection - Actively watches for malicious behavior - Behavior monitoring and data analytics enable: - Protection against zero-day attacks - Protection when the system is disconnected from the internet - Protection when installed after the existence of ransomware on the endpoint. • Secrets management - Centralized management for all types of secrets - Built for ease of use in DevOps integrations, automations, and orchestrations. - Manage secrets for hybrid, multi-cloud (all clouds), multi- tenants, on-prem and legacy systems and with human or machine access. • Data protection techniques - Transparent encryption for files, databases and big data - Application-layer data protection - Format-preserving encryption - Tokenization with dynamic data masking - Static data masking - Privileged user access controls • Centralized enterprise key management - FIPS 140-2 compliant enterprise key management - Unparalleled partner ecosystem of KMIP integrations - Multi-cloud key management - Transparent Data Encryption (TDE) key management Environments. • Clouds: Amazon Web Services, Google Cloud Platform, IBM Cloud, Microsoft Azure, Oracle Cloud Infrastructure, Salesforce, SAP, and more. • Supported OSs: Linux, Windows and Unix • Big Data: Hadoop, SAP HANA • Database: IBM DB2, Microsoft SQL Server, MongoDB, MySQL, Oracle, Sybase, Teradata and others. • Any storage environment Platform advantages. • Discover, protect and control Emirate of Tabuk's sensitive data anywhere with next-generation unified data protection. • Consistent security and compliance across physical, virtual, and cloud environments. • Identify and secure data across structured, unstructured and big data platforms. • Reduce time-to-value. Rapidly enable platform capabilities as Needed. • Hardware Security Modules as the secure root of trust for the platform include FIPS 140-2 Level 3 certification. | نظام | 1 | 0 | 0 | 1 | — |
| انشاء مناطق امنة باستخدام التجزئة الدقيقة | خدمات | إنشاء مناطق امنة باستخدام التجزئة الدقيقة Micro-Segmentations | إنشاء مناطق امنة باستخدام التجزئة الدقيقة Micro-Segmentations تطبيق وتفعيل التجزئة الدقيقة بنهج الأمن السيبراني الذي يتضمن تقسيم الشبكة إلى أجزاء وتطبيق عناصر تحكم أمنية على كل جزء بناءً على متطلبات الجزء. وأن يتم استخدام برامج التجزئة الدقيقة مع تقنية المحاكاة الافتراضية للشبكة، وتعمل هذه المناطق الآمنة الدقيقة على عزل أحمال العمل وتأمينها بشكل فردي باستخدام سياسات مخصصة ومحددة لأحمال العمل. وعلى سبيل المثال، يمكن حماية كل جهاز افتراضي (VM) في الشبكة، حتى مستوى التطبيق، باستخدام عناصر تحكم أمنية دقيقة. - Container Segmentation: Container segmentation involves isolating containers from each other and the host system to improve security and reduce the attack surface. Containerization is a widely used technology that allows multiple applications or services to run in separate containers on a single host system. Without proper segmentation, though, containers can potentially access each other's data and configuration files, which can result in security vulnerabilities. r Apply Container Segmentation Best Practices: • Container isolation: Each container should be isolated from other containers running on the same host system to prevent unauthorized access. This can be achieved using container technologies like Docker and Kubernetes, which provide built-in isolation mechanisms. • Network segmentation: Containers can be segmented from each other using network segmentation techniques. This involves creating separate networks for each container and configuring firewall rules to allow or deny traffic between containers. • Role-based access control: Role-based access control (RBAC) can be used to define access policies for different containers based on user roles and permissions. This can help to ensure that containers are accessed only by authorized users and processes. • Image signing: Container images can be digitally signed to ensure that only trusted images are deployed in production. This can help to prevent container images from being tampered with or altered, reducing the risk of security vulnerabilities. • Runtime protection: Runtime protection tools can be used to monitor container activity and detect anomalies that may indicate a security breach. These tools can help to detect and prevent attacks in real-time, improving the security posture of containerized environments. Container segmentation should help to ensure the security of containerized applications and services. By isolating containers and applying access control policies, the Emirate of Tabuk can reduce the attack surface and prevent unauthorized access to sensitive data and resources. Container segmentation should be implemented as part of an overall security strategy that includes network security, access control, and runtime protection. | خدمة | 1 | 0 | 0 | 2 | — |
| نظام فحص النصوص البرمجية | أنظمة | نظام فحص النصوص البرمجية Code Scanner | نظام فحص النصوص البرمجية Code Scanner توجد فروق بين البحث عن الثغرات الأمنية في تطبيقات الويب والبحث عن الثغرات الأمنية التقليدية باستخدام الأدوات التقليدية العامة، لذلك، يتطلب تقديم حل ينهج نهجًا مختلفًا لتقييم الثغرات الأمنية في تطبيقات الويب وإدارتها. ويجب أن يوفر الحل المقدم لفحص تطبيقات الويب تحسينات كبيرة على سياسة فحص تطبيقات الويب القديمة. يجب أن يوفر الحل المقدم مسحًا شاملاً للثغرات لتطبيقات الويب الحديثة، ويقلل تغطيته الدقيقة للثغرات من الإيجابيات الخاطئة والسلبيات الخاطئة لضمان فهم فرق الأمان للمخاطر الأمنية الحقيقية في تطبيقات الويب. ويجب أن يوفر مسحًا خارجيًا آمنًا حتى لا تواجه تطبيقات الويب الإنتاجية انقطاعات أو تأخيرات. يجب أن يدعم أنواع برامج فحص تطبيقات الويب القابلة للتطبيق، استناداً إلى تقنية اختبار أمان التطبيقات الديناميكية dynamic application security testing (DAST). Scan: The complete set of available checks which includes all other pre-built templates, except for the API scan. Overview: A simplified version of the “Scan” template without several active tests to lower its impact and speed up the scan. PCI: A special template used as part of the attestation offering that provides for the payment card industry (PCI) security standard. Only submissions to attestation consume PCI licenses: otherwise, this template is a simplified version of the "Scan" template. SSL/TLS: A health check scan focused on the current state of the web server encryption settings and certificate state (for example, the remaining time on the certificate). Config Audit: A compliance audit that detects externally viewable web server settings that External audit providers commonly review to evaluate the health of a security program. API Scan: A special template requiring more configuration to describe the application programming interface (API), so that the scanner can successfully detect relevant vulnerabilities This includes some similar tests in the “Scan” template but adds others unique to API endpoints. | نظام | 1 | 0 | 0 | 3 | — |
| توريد وتركيب جهاز ونظام خداع المهاجمين | خدمات | توريد وتركيب جهاز ونظام خداع المهاجمين Threat Deception | توريد وتركيب جهاز ونظام خداع المهاجمين Threat Deception يجب أن يقدم الحل منصة خداع غير تدخلية بدون برنامج وسيط للكشف عن الهجمات النشطة داخل الشبكة وإيقافها. مع القدرة على خداع المهاجمين للانخراط في أصول وهمية وفي النهاية الكشف عن أنفسهم. أن يجمع الحل بين مفهوم مصيدة العسل وتحليلات التهديدات وقدرات التخفيف من التهديدات، ويتم تحقيق ذلك من خلال توزيع طبقة من أصول الخداع عبر الشبكة - أدوات التضليل والرموز، مثل المفاتيح والملفات المزيفة على نقاط النهاية والخوادم - وإنشاء نظام من الفخاخ التي تبدو وتعمل مثل أي أصل حقيقي آخر عبر شبكات تقنية المعلومات والتشغيل وإنترنت الأشياء، والتي تهدف إلى خداع وكشف وعزل الهجمات البشرية والآلية المعروفة وغير المعروفة، فبدلاً من انتظار ارتكاب الجهة المسؤولة عن التهديد لخطأ ثم اكتشاف وجودها، يمكن تبني نهج دفاعي نشط حيث تصبح أي خطوة يتخذها المهاجم - سواء حاولوا تصعيد الامتيازات أو تشغيل البرامج الضارة - فرصة لك لاكتشافهم. Accurate, Early Detection and Fast Response • Reduces dwell time and false positives • Detects early reconnaissance and lateral movements • Built-in, automated attack quarantine capabilities stop attacks before they spread • Automatically scales as risk level rises • Helps mitigate ransomware by leading malware to encrypt fake files, triggering automatic blocking of the infected endpoint. • Automatically deploys vulnerable decoys based on best Labs latest outbreak alerts • Integrates with the Fortinet Security Fabric and third-party security controls Enrich Actionable Insights, Increase SOC Effectiveness • Generates high-fidelity, actionable alerts based on real-time interactions with adversaries • Correlates malicious activities using eight different forensic engines to help analysts investigate, gather forensic evidence, monitor, and automatically stop attacks in progress. • Closes visibility gaps with in-progress attack intel and detailed forensics • Provides attack replays and attack visualizations • Low-friction deployment and maintenance via automation Extend Support to Challenging Areas • Optimized OT, IoT, and IoMT decoys are designed to expose and block threats to industrial systems, IoT, and IoMT devices. • Agentless and non-intrusive, with zero impact on mission-critical operations • Ease of installation (one-day operation) and use; does not require any network topology changes • Detects threats to assets that cannot provide their own telemetry • Available across every attack surface, including on-premises, cloud, and IT, OT, IoT, and IoMT environments. • Operates in both online and air-gapped modes - RAM Size: DDR4-2400 48 GB ECC RDIMM (16 GB*3) - VM Support: Windows 7 / 10 / 11, Win 10 / 11 (customizable, BYOL), Win Server 2016/2019/2022 (customizable, BYOL), Ubuntu 16.04 / 18.04, Redhat (customizable, BYOL), CentOS 7.9, SSL-VPN, ESXI Decoy, FortiGate, IoT (Routers, Switch, Printers and IP-Camera), Medical devices, (PACS, Infusion pump), SWIFT, SCADA, ERP, POS, SAP, Elastic Search, Tomcat, MySql MariaDB, SIP, XMPP, MQTT, 4G/5G 3GPP, MacOS, Webmin, Citrix, Nginx, EV-CPO. - Services: ARP, BACNET, B.BRAUN (port 8080), CAN Bus Protocol, CDP, CoAP, CWMP, DICOM Server, DNP3, Elastic Search, ENIP, ERP-WEB, FTP, GIT, GTP-U, Guardian-AST, HoneyDoc, HTTP, HTTP (APACHE), HTTPS, ICMP, IEC104, IIS (HTTP), IIS (HTTPS), Infusion Pump (FTP), Infusion Pump (Telnet), IP Camera-WEB, IPMI, Jetdirect, KAMSTRUP, Lantronix Discovery Protocol, LOGON, MariaDB, MODBUS, MOXA, MQTT WEB, MSSQL, MYSQL, NBNSSpoofSpotter, NextEPC WEB, PACS, PACS-WEB, POS-WEB, Printer-WEB, PROFINET, RADIUS, RARP, RDP, RTSP, S7COMM, SAMBA, SAP DISPATCHER, SAP ROUTER, SAP WEB, SAP WEB HTTPS, ScadaBR, SCTP and GTP-C, SIP, SMB, SMTP, SNMP, SRTP, SSH, SSLVPN, SWIFT Lite2, TCPListener, Telnet, TFTP, TOMCAT (HTTP), TOMCAT (HTTPS), TP-LINK WEB, TRICONEX, UPnP, vnc, XMPP, XMPP WEB. Deception VMs Shipped: Deceptor Bundle Contract included license for Deception Decoys, Deception Lure plus FortiGuard Services Subscriptions (AREA, AV, IPS, and Web Filtering).1 VLAN unit price, minimum order of 2 VLANs. Interfaces: 4 x GE (RJ45), 4 x GE (SFP). Storage Capacity: 2 TB (2 x 1 TB HDD). | خدمات | 1 | 0 | 0 | 4 | — |
| زيادة مساحة التخزين و الذاكرة العشوائية لخوادم | توريد | زيادة مساحة التخزين و الذاكرة العشوائية لخوادم سجلات المراقبة والحوادث السيبرانية | 16 HPE 3.84TB SAS 12G Read Intensive SFF SC Multi Vendor SSD4 HPE 1.6TB SAS 12G Mixed Use SFF SC Multi Vendor SSD48 HPE 32GB (1x32GB) Dual Rank x4 DDR4-2933 CAS-21-21-21 Registered Smart Memory Kit1 HPE Synergy D3940 12Gb SAS CTO Drive Enclosure with 40 SFF (2.5in) Drive Bays1 HPE Synergy D3940 Redundant I/O Adapter Installation1 HPE Installation Service68 HPE Add On Options Install SVC1 HPE Synergy Node Installation Service1 HPE Technical Installation Startup SVC1 HPE After Hours HW Startup 24x7 CTR SVC Support1 HPE 3Y Tech Care Essential with Defective Media Retention Service68 For HPE Internal Entitlement Purposes1 HPE Synergy DS3940 Storage Module Support Services1 HPE ProLiant Door/dock Small Logistic Service | سعة تخزينية | 1 | 0 | 0 | 5 | — |
| جهاز مكتبة النسخ الاحتياطي | توريد | جهاز مكتبة النسخ الاحتياطي Tape Library | جهاز مكتبة النسخ الاحتياطي Tape Library يجب أن يكون الحل المقدم قابل لتلبية متطلبات الاحتفاظ بالبيانات على المدى الطويل، فضلاً عن توفير حماية البيانات من التهديدات المتزايدة التي تشكلها برامج الفدية. وأن يوفر أداة التحميل التلقائي ومكتبة الأشرطة سهولة إدارة أشرطة النسخ الاحتياطي من أي مكان، لتخفيف الحاجة إلى تقنية المعلومات ومركز البيانات للتواجد في مقر الإمارة. إمكانية حماية البيانات من الوصول غير المصرح به باستخدام تشفير البيانات. إمكانية زيادة السعة و/أو الأداء بسرعة باستخدام ترقيات محرك الأقراص بدون أدوات أخرى. يدعم سعة تخزين حتى 300 تيرابايت. أن يقدم الحل واجهة استخدام تسهل لموظفي تقنية المعلومات ومركز البيانات إدارة النسخ الاحتياطي. أن يدعم الحل المقدم معظم أنظمة النسخ الاحتياطي المعتمدة. أرشفة البيانات طويلة المدى مع عمر تخزين محدد للوسائط يبلغ 30 عامًا في ظل الظروف المحيطة الطبيعية. | جهاز | 1 | 0 | 0 | 6 | — |
| جهاز مكتبة النسخ الاحتياطي الافتراضية | توريد | جهاز مكتبة النسخ الاحتياطي الافتراضية Virtual Tape Library | جهاز مكتبة النسخ الاحتياطي الافتراضية Virtual Tape Library جهاز نسخ احتياطية افتراضية بالمواصفات التالية: - Max Throughput: Up to 4.2 TB/hr - Max Throughput (DD Boost): Up to 7.0 TB/hr - Logical Capacity: Up to 1.6 PB - Logical Capacity with Cloud Tier: Up to 4.8 PB - Usable Capacity: 4 TB – 32 TB - sable Capacity with Cloud Tier: Up to 96 TB - Built-In Networking: 1x Mgm't port - Required Networking (rNDC or OCP): 4x 10G Base-T Optional Networking with I/O Cards: 10GBase-T card can auto- negotiate down to support 1GbE Up to single dual- port 10GbE SLICs: Optical Single quad-port 16Gbps FC HBA Software features: Global Compression, Data Invulnerability Architecture, including inline verification and integrated dual disk parity RAID 6, snapshots, telnet, FTP, SSH, email alerts, scheduled capacity reclamation, Ethernet failover and aggregation, Link Aggregation Control Protocol (LACP), VLAN tagging, IP aliasing, DD Boost, DD Encryption, DD Extended Retention, DD Retention Lock, DD Virtual Tape Library (VTL) (for open systems and IBMi operating environments). Available add-ons include DD Boost, Cloud Tier for long-term retention, Cloud Disaster Recovery, and DD Replicator. System management Web Interface Management, SNMP, and command line management interface. Data management NFS v3 over TCP, CIFS and DD Boost over 1GbE or 10GbE or Fibre Channel, tape library emulation (VTL) over Fiber Channel, and NDMP Tape Server. | جهاز | 1 | 0 | 0 | 7 | — |
| خزينة حفظ أشرطة النسخ الاحتياطي المادية والمستندات الهامة والحساسة | توريد | خزينة حفظ أشرطة النسخ الاحتياطي المادية والمستندات الهامة والحساسة | خزينة حفظ أشرطة النسخ الاحتياطي المادية والمستندات الهامة والحساسةخزنة آمنة مقاومة للحريق ومضادة للماء وخزانة رقمية آمنة، خزنة آمنة مقاومة للحريق ومضادة للسرقة، خزانة أمان كبيرة السعة للتخزين، ارتفاع 60 سم/70 سم/80 سم.قفل رمز ميكانيكي معدني بالكامل: قفل الرمز مصنوع من الفولاذ بالكامل، والسطح مطلي بالكهرباء.ثلاث مجموعات من كلمات المرور المكونة من 6 أرقام، مما يقلل من احتمالية فك التشفير، وعامل أمان عالي.. ميزات الخزنة: تتميز الخزنة بوظائف مقاومة للحريق ومقاومة للماء ومضادة للعبث.تتمتع بمقاومة جيدة لدرجات الحرارة العالية ويمكن أن يصل وقت مقاومة الحريق إلى ساعتين.المادة: الخزنة مصنوعة من الفولاذ عالي الكثافة، ومضادة للعبث، ومضادة للحفر، وعامل أمان عالي. لوحة ميكانيكية من الفولاذ المقاوم للصدأ: اللوحة مصنوعة من الفولاذ المقاوم للصدأ 304، بصلابة 120HPB، ومقاومة للخدش ومقاومة عالية للتآكل. | خزينة | 1 | 0 | 0 | 8 | — |
| نظام اكتشاف البيانات وتصنيفها | أنظمة | نظام اكتشاف البيانات وتصنيفها Data Discovery & Classification | نظام اكتشاف البيانات وتصنيفها Data Discovery & Classification أن يدعم نظام اكتشاف وتصنيف البيانات المقدم الاستفادة من الذكاء الاصطناعي للحصول على نظرة شاملة على كافة البيانات بالإمارة لتحسين دقة تصنيف البيانات وأتمتة عملية الاكتشاف والتصنيف. أن يقوم النظام باستخدام برامج إنشاء نماذج الذكاء الاصطناعي التوليدي، وبناء محرك تصنيف تنبؤي وذاتي التعلم، ويعمل مع اللغة الطبيعية لاقتراح التصنيفات، ومن خلال التعلم المستمر، يتم تقديم اقتراحات عالية الدقة. أن يتم تصنيف كافة الملفات ورسائل البريد الإلكتروني التي تم إنشاؤها حديثًا، ويتم تحويل كل ملف إلى متجه رياضي مع تسمية تصنيف مجهولة وغير قابلة للهندسة العكسية بحيث يمكن تخزين المعلومات بأمان. أثناء إنشاء الملف، يجب أن يتيح تصنيف البيانات إضافة تسميات مرئية وبيانات وصفية، مما يتيح خيار تحديد التصنيف الخاص بالإمارة أو استخدام التوصية التي تم إنشاؤها بواسطة الذكاء الاصطناعي. يتم تسليم كل توصية بمستوى ثقة يعتمد على البيانات الموجودة داخل الملف مقارنة بنموذج الذكاء الاصطناعي للمساعدة في اتخاذ قرارات تصنيف دقيقة للغاية. إضافة تسميات مرئية وبيانات وصفية لتسهيل فرض السياسات والامتثال للضوابط. تتضمن خيارات التصنيف ما يلي: - الامتثال - التصنيف - قواعد التنفيذ - التسمية المرئية - قواعد مشاركة البريد الإلكتروني - الاستثناءات A. Data Classification Requirement Requirement Compliance (Fully Compliant / Partially Compliant) Comments Overview An AI-based classification engine must power the solution The Solution should be self learning powered by a machine learning system The Solution should integrate automatically with DLP Solutions The solution must Automatically support compliance standards such as ECC-2018, DCC-1:2022,GDPR, PII, ISO 27001, PCI, CMMC, SAMA ,NCA,PDPL … etc. The solution should not require additional licenses for Databases – The solution should be an all in one package The solution will recommend compliance and classification levels to the user using Artificial Intelligence , Machine Learning and log attempts to expose or declassify The solution should work on premise and have an option to work in the cloud The solution can generate, schedule automated reports The Vendor shall have local presence in Saudi Arabia. Applying Classification Ability to choose more than one classification value (multiple selections) Users can be prompted to classify by a pop-up dialogue box Assisted labelling guiding the user through classification choices to ensure valid selections Dynamically tagged classification options for advanced schemes (such as ITAR, CUI, SAMA, PII etc) Ability to have a default classification or suggested classification User prompted to classify when saving, printing, or sending an email Tag images and video support via the explorer right-click Tag CAD files via the explorer right-click Tag MS Visio and Project via the explorer right-click Ability to create custom patterns (regexes) for classification suggestions on the product’s dashboard Default (auto) labelling rules for Agent (all new or modified files and emails are classified by default, i.e. Internal or Confidential) Ability to configure default (auto) labeling rules individually per plugin Word, Excel, PP, Outlook Agent can seamlessly auto update LDAP authentication for the end-user agents Bulk Classification of files with a right-click in Windows Explorer MAC Agent Exclusive and non-exclusive tags for classification labels, compliance labels, attribute labels and any other custom labels Ability to add multiple floating headers to the same document (i.e. a Header for Internal and a header for PCI, but headers will be added individually through a floating text boxes) Ability to configure the visual appearance behavior for each header/footer individually Ability to configure the visual appearance behavior for each FLOATING header/footer individually Each individual FLOATING header/footer should stack in each own column General Compliance Requirements The solution should support automated, suggested, and user-driven classification. The solution should evaluate the content, context, identity and other attributes of unstructured data to make classification and policy decisions. The solution should have a simple and flexible policy engine to support the creation of rules. For example, upon an event where the user clicks 'Send' on an email, under the condition one of the email recipients had a particular specific email domain, to take any action to block the email from being sent. The solution should trigger policy and classification actions based on different events, such as Open, Save, Print, Forward, Close, Send, or Classification Change. The solution should enable administrators to define policies with or without classification as part of the policy. The solution should enable administrators to combine policies to provide more fine-grained control. The solution should support policy nesting/hierarchy to control the flow of policy execution, making it easier to keep more advanced use cases for classification and policy enforcement. The solution should provide context-sensitive help throughout the user interface to support security training and help users select the correct classification and policy remediation options. Data Classification and Identification Requirements The solution should support the classification of messages and tasks from within Microsoft Outlook 2013/ 2016/ 2019 (or higher version) or Exchange online. The solution should enable the classification of Word, Excel and PowerPoint documents of all versions of Microsoft Office from Office 2013 to current O365 The solution should provide a consistent classification schema across applications. The solution should support the ability to enforce the classification of email (M.S. Outlook/OWA/O365) and documents irrespective of file extensions and types. The solution should support the ability to classify on Send, Save/Save As, Print, New Email, Close/Open Document, and other email and document events. The solution should support data retention and disposition tags, including data fields for retention periods The solution should prominently display classification values (easily Visible) in the Microsoft Office/Outlook /O365. The solution should recognise the classification of received emails and display the classification in Outlook. The solution should support different classification values for various applications. This can be combined with user targeting to present detailed classification options based on application and user identity. The solution should enable users to assign classification values via a one-click classification user interface. The solution should enable users to assign classification values while using the Outlook2013/2016/2019 (or higher) in-line reply feature. The solution should enable users to assign classification values to any file type by right-clicking in File Explorer and selecting one or more files. The solution should support the dynamic population of classification fields from sources other than the pre-configured classification schema by inserting multiple Metadata attributes. For example, metadata values can come from document attributes (e.g. author), environmental variables, and Active Directory (e.g. group, department). The solution should support asking users to confirm an automated classification value (also called "suggested classification"). The solution should support the ability to prompt users to change the default classification(s)if the default is inappropriate for the content, context, or other attributes of the email or document. The solution should support the ability to prompt users to classify in some cases and use automated classification in others. For example, a default classification may be used for internal email, but users are prompted to classify for external email. Or users may be prompted to classify email only when there is an attachment. The solution should support the ability to scan certain keywords and regular expressions and set the classification accordingly. The solution should generate metadata for all file types, including persistent, embedded metadata for many non-office files, i.e., other extensions/formats, including PDF, Visio, Project, images, and video files The solution should support the creation of unlimited custom metadata for interoperability (Department, PII type, Document category, PII count etc.), including custom X-headers. The solution should support customizable visual markings in email and documents (e.g., font(name/size/features), size, color, and content). The solution should support customizable visual markings in M.S. Outlook. The solution should support adding visual markings to the top and bottom of an email. The solution should support the ability to add watermarks in supported Microsoft office applications. The solution should support the use of variables in visual markings, making it easier for administrators to support multiple use cases in one policy. The solution should support different visual markings for the same classification, depending on context. For example, a "Confidential" document with a specific keyword may have different markings than a "Confidential" document with PII. Auditing and Reporting Requirements The solution should log user activity while users are handling email, documents, and files. The solution should provide built-in reports. The solution should provide a pre-built starter set of reports for the reporting database (in tab-separated values/ Excel or Database format). The classification values on email should be consistent irrespective of the user accessing emails from platforms desktop, laptop The solution should have the ability to retain existing classifications in emails threads. Configuration and Deployment Requirements The solution should provide a centralized, web-based Administration Console for classification configuration and policy management. The Solution should support deploying configuration from a Central Server. The centralized solution should work based on with a single agent in the client. The solution should enable clients to retrieve their configuration from a central management server over a secure connection (SSL / TLS). The solution should enable administrators to push client configurations to user desktops via the Central Server The solution should cache configurations locally for offline use. The solution should enable clients to leverage policy updates without restarting Microsoft Outlook and Office applications. The solution should provide the ability to deploy in silent mode so that software can be deployed and enabled in different phases. The solution should enable administrators to customize all user interface text strings to support different languages and terminology. This includes classification fields and values and policy warning messages. The solution should be able to identify information like I.D., Passport numbers, and credit card information for automated classification through either inbuilt capability or should have the ability to define regular expressions. The solution should work with Microsoft Office 2013 (32-bit and 64-bit), 2016, 2019 or later. The solution should work on Windows 7, 8, 1, and 10 or Higher. Integration and Interoperability Requirements The solution supports DLP or DRM solutions The solution should provide the ability to attach metadata to information objects, leveraged by e-discovery solutions. The solution should provide the ability to attach metadata to information objects, which can be leveraged by third-party data loss prevention (DLP) solutions and should work even when emails and documents are protected. The solution should provide the ability to write tags that the DLP solution can read. The solution should provide the ability to trigger encryption based on metadata. Printing can be controlled based on classification and context User can apply bulk classification across multiple selected files in Windows file explorer views Applying Classification Markings to A File Apply a marking to the header of a file Apply a marking to the footer of a file Apply a watermark to a file Apply persistent metadata to a file Visible markings can be customized, so they don't affect templates, existing content, structure or branding Classification Integration with Email Classification can be applied in M.S. Outlook When an email is classified, the recipients and originator are checked automatically on sending to ensure they are appropriate - e.g. to prevent an email marked 'internal' going to an external domain The classification level of an email is automatically updated to match the level of any attachment (or match the highest level of classification if more than one attachment) Attachments can be checked to ensure they are classified and the classification hasn't expired Classification can check how many recipients are on the email The classification of an email can be retained on the reply from an external recipient Apply markings in the first line of text Apply markings in the last line of text Apply markings in the subject of an email as either prefix or appended Apply markings in the x-header of an email Apply Rights Management (e.g. Azure RMS, Seclore, Sealpath) Automatic email classification for inbound email based on last email classification sent by the internal user Intelligent Actions Classification Can Take Stop user saving or printing without classifying Stop accidental email dissemination to users without an appropriate clearance level Suggest or mandate a default classification based on company position, department, location, file contents Mandate classification of a file created externally when it is opened, shared or printed Detect files nested in a file, or the body of an email Detect content in files and suggest or mandate classification Detect content in nested files and suggest or mandate classification Protecting the Metadata from User Modification Metadata is persistent - any removed metadata is re-applied when the file is saved, printed or emailed Users can be prevented from changing the classification Details of the user who classified the file are logged If a user is allowed to change classification, this change will be logged Policy Management There is a simple management tool where policies can be created and modified Policy rules can be built and edited with a simple wizard Policies can be tailored with an extensive range of attributes - for example, Active Directory attributes No limit to the number of policies that can be created Unlimited classification levels to enable a policy to evolve Classification can be amended over time, as business needs develop Functionality Policies can align with a company's internal marking and enforcement policies A range of classification elements can be applied - e.g. single selectors, multiple selectors Policies can be easily tested (test mode) before deployment Classification can be mandated Policy Flexibility and Customization Classification buttons can be wrapped (stacked) into columns (so they don't take up too much space in the ribbon) Translation and Localization of language is supported Language support is automated based on the user's location Management & Reporting All classification actions are logged Solution should provide file activity reports Solution should provide agent activity reports B. Data Security Posture Management (DSPM) requirements Requirement Compliance (Fully Compliant / Partially Compliant) Comments 1.1 Data Discovery & Intelligence. Does the data security platform provide these elements and functions? Context around the data Actionable Insights Ability to Tag / Label Data Classification Identify Duplicate Data Metadata Capture Confidence Scoring Deep Learning Dark Data Discovery Risk Scoring Rule Management Sensitive Data Identification and Discovery Overexposed Access 1.2 Classification: does the data security platform perform the following classification? Regular Expressions Pattern matching Keyword matching Customizable AI/ML trained models to identify organization specific data Automated Tagging & Labeling End user Tagging & Labeling categorize by sensitivity type Classify sensitive and critical business data Common regulatory classifiers (PCI, PHI, PII, Financial information, PIFI, etc.) Identify BU data assets e.g. Financial: contracts, bank statements, budgets, investment, supply chain, etc. Detect and categorize based on keywords, positive and negative terms, phrases, or patterns to identify specific topics. Identify and classify based on location and file extensions for cataloging and data management purposes. NLP text analysis techniques e.g. bag-of-word and fuzzy text to detect topics and approximate data matching Ability to define custom attributes e.g. critical and sensitive business data to meet organizational needs. Identify based on sentiment analysis e.g. HR data, Finance data, Legal data, etc. Evaluate the complexity of text, sentiment analysis, readability scores, and keyword extraction Identify and track unclassified data Identify data for legal hold Identify ROT data 1.3 Data Coverage: Can your data security platform connect to and scan each of these data sources and types? Structured Databases Unstructured Data Sources Data Lakes & Data Warehouses Applications Email & Messaging Cloud SaaS Cloud IaaS Dev Tools Endpoints (Windows and Mac) GenAI - Workspaces, Invite only, Private chats, AnyoneWithLink (companywide or public internet) 1.4 Access Governance Identify overprivileged users Identify overexposed data by sensitivity / criticality / business unit e.g. Finance, HR, etc. Visibility on internal and external access based on data sensitivity Customize access type Flag and investigate high risk issues Identify stale data to move, archive, or delete Identify data geolocation to satisfy data soveirgnity obligations 1.5 Data Governance Access Governance Compliance standards and regulatory frameworks Customizable data classification taxonomy Integrate with Microsoft MIP/PIP to extend consistent enforcement Data ownership management Data Asset Register Security Posture Policies Automated activity triggers based on policy violations Data flow management Data lifecycle management Data audit trails and reporting for compliance purposes 1.6 Data Remediation Remediate high risk data with workflow orchestration Priorities findings by sensitivity and risk Assign remediation activity to data sets Implement data remediation actions on datasets Delegate remediation by role, scope, and user Revoke excessive permissions Apply/update classification/tag/label Ability to move, delete, and archive data 1.7 Data Retention Customizable data retention policies Automated activity triggers based on policy violations Review files and data in violation Remediation options - move, delete, and archive data Audit trail and reporting (1 year minimum) 1.8 Extensibility across the Org Data risk and controls management capabilities Data retention workflows Data Governance capabilities Data scientist solutions Records management capabilities Compliance capabilities Security Operations capabilities Legal eDiscovery capabilities 1.9 Integrations, Ops, & Ecosystem Integrate with DSLP, SIEM, ITSM, email REST API available CI/CD integration On-prem / private cloud deployment option SaaS deployment option Extensible reporting capabilities Customizable RBAC 1.10 Documentation & Support Customizable reporting dashboards Quick Start Guide that can provide a Streamlined Onboarding, Regulation Awareness and Prebuilt Configurations. Audit trails and reporting Solution and Training Documentation Architecture Documentation (system architecture, elements, and deployment information) The Vendor shall have local presence in Saudi Arabia – Educational training and certification | نظام | 1 | 0 | 0 | 9 | — |
| نظام التعافي من الكوارث | أنظمة | نظام التعافي من الكوارث Disaster Recovery System | نظام التعافي من الكوارث Disaster Recovery System أن يعمل الحل المقدم على تقليل مخاطر الكوارث من خلال أتمتة عمليات استعادة الأنظمة والخدمات الإلكترونية في مركز البيانات الرئيسي والرديف، بحيث تكون نقطة الاسترداد قريبة من الصفر للأنظمة الهامة والحساسة حسب ما تراه إمارة منطقة تبوك.أن يقدم الحل خطط التعافي من الكوارث المولدة أوتوماتيكياً والتي يمكنها إثبات الامتثال.اختبارات التعافي من الكوارث المؤتمتة بالكامل والتي تؤكد إمكانية تحقيق أهداف الاستعادة الخاصة بالإمارة.أن يدعم الحل الاستعادة من الكوارث بنقرة واحدة للحفاظ على سير العمليات بسرعة وسهولة.أن يحتوي النظام على شاشة توضح مؤشرات هدف نقطة الاسترداد وهدف وقت الاسترداد (RPO وRTO) حسب اتفاقية مستوى الخدمة (SLA).الاسترداد السليم: أن يقوم النظام باستعادة البيانات النظيفة من خلال تكرار عمليات الفحص بحثًا عن البرامج الضارة للعثور على أحدث نقطة استعادة آمنة وسليمة.الوصول الآمن بناءً على الأدوار والصلاحيات: يدعم التفويض والتحكم في الوصول الآمن للمسؤولين عن الأنظمة والتطبيقات وقواعد البيانات.الاختبار الآلي: إمكانية إجراء اختبارات الاستعادة من الكوارث بدون تأثير، سواء كانت مجدولة أو عند الطلب، للتأكد من إمكانية تلبية متطلبات RTOs وRPOs..بيئة التجربة والاختبار الفوري: استخدام موارد الاسترداد بعد الكوارث لإجراء اختبارات التصحيح دون التأثير على البيئة الحقيقية.التحقق من نجاح التعافي من الكوارث: إمكانية التحقق من أن أنظمة وخدمات الإمارة تعمل كما هو متوقع بعد التعافي من الكوارث.الاستعادة بنقرة واحدة: إمكانية استعادة أنظمة أو تطبيقات فردية أو موقع كامل من أي مكان بنقرة واحدة فقط من خلال واجهة الويب.التوثيق التلقائي: إنشاء وتوليد وثائق التعافي من الكوارث تلقائيًا لإثبات الجاهزية والامتثال.أن يدعم العمل مع أنظمة تشغيل مايكروسوفت ولينوكس، وقواعد بيانات مايكروسوفت وأوراكل.أن يعمل النظام داخل شبك وخوادم إمارة منطقة تبوك.Availability Features & Technical Overviewo Multi-platform Support.Availability support both Windows and Linux platform.o Continuous, asynchronous byte-level replication over any distance.Availability monitors changes to all protected files or virtual machines and replicates only the bytes that change to a disaster recovery site as far away as you would like, over standard IP networks, for maximum protection against data loss. Open-file mirroring and replication. Availability processes and replicates open files without taking them offline; applications remain online and users stay productive.o Data Integrity and Write-Order Consistency.On Windows Server hosts or within Windows-based virtual machines, Availability uses its patented STAR (Sequential Transfer Asynchronous Replication) technology to ensure the integrity of replicated data, which is especially important in the case of transactional databases such as Microsoft SQL or Microsoft Exchange. When replicating vSphere VMs, Availability uses VMware APIs for virtual machine snapshot functionality, ensuring that VMs are in a known and consistent state, ready for recovery at any time.o Flexible bandwidth scheduling.Impose higher or lower network usage limits during those times when most appropriate for your business. Limit network use of Availability during busy work hours and increase or remove these limits during non-peak times for efficient replication with the least amount of impact on production resources.o Protects Exchange, SQL Server, Oracle, SharePoint, and more.Availability is hardware and application independent, allowing you to use the hardware and software that suit your business.o Continuous, full-server replication.There’s more to protecting your systems than just protecting the data. Availability hardware independent full-server protection protects the OS, applications and data for easy recovery to another physical or virtual machine regardless of make, model or configuration.o Point-In-Time RecoveryAvailability integrates with Microsoft Volume Shadow Copy Service to allow you to schedule and recover from up to 64 point-in-time copies of data on your Availability target when running on a physical server or within a virtual machine.o No shared storage; no single point of failure for Windows clustering.Maintain a separate, continuously updated copy of clustered data resources on each cluster member for seamless recovery from any node, application or storage failure. Plus, with Availability you’re not limited to Windows Server Failover Clustering – certified storage – you can use any storage hardware, regardless of vendor, model, or interconnect.o Supports clustered deployments on Windows servers.Protect up to eight nodes in a single cluster; replicate to or from MSCS clusters of up to 16 nodes, and automatically respond as cluster resources move from node to node.o Exclusive resource planning tool.Using the Availability TDU (Throughput Diagnostics Utility), it is possible to simulate the amount of replication traffic generated by data changes in your environment and estimate the bandwidth you’ll need to go live.o High availability and failover.Choose between application- or virtual machine-level or full-server failover to configure an alternate system to take over for your production server in the event of an outage. The Full-Server Failover feature of Availability provides files and folders protection and failover, providing hardware-independent system state protection with monitoring and failover for critical systems. For vSphere and Hyper-V machines, replicating entire VMs ensures that you can recover quickly with one-click failover and restore. Fast, simple configuration.The Application Manager feature configures and manages protection for Microsoft Exchange, SQL Server, Blackberry Enterprise Server, SharePoint Services and Windows File Services running on a physical server or in a virtual machine. It automates the setup and configuration of real-time protection and availability management for these business-critical applications.o Failover testing.The Target Data Verification feature allows you to test replica data (as long as the target server is running Windows Server 2003 SP1 or later). Testing is performed against the replicated copy of data without the need to stop tracking changes on the source server or re-mirror the dataset. At the end of the test, changes to the replicated data are reverted using a snapshot performed at the beginning of the test and application of the replicated data in the replication queue is resumed.On Hyper-V and vSphere platforms, the Availability “undo failover” feature allows you to re-start the source virtual machine in the state it was in at the point of failover and discard any data changes that may have taken place on the target. The “test failover” feature allows you to start the target machine with no network connectivity in order to verify data integrity on the target while keeping the source machine available.o Single-screen monitoring.The Availability Console provides the ability to sort, filter and monitor the health of your protected servers, the mirror status and event logs on one screen.Centralized reporting and analysis. The Availability Reporting Center offers detailed, custom analysis and reports of your entire Availability environment. The rich reporting and dashboard views of the reporting center make it easy to manage even the largest deployments.o Integrated management for clusters.The GeoCluster™ feature of Availability integrates seamlessly with Microsoft Server Failover Clustering, providing the administrators with one step management of both data replication and cluster configuration/failover settings for multi-site clusters.o Email notification.Availability can provide email event notifications that can be configured with different recipients for each server, with each having its own event notification level.Availability supports all following failover methods:• Data-Level FailoverProtection of Specific Files, Folder, or Drives; without the inclusion of any services or System Data.Supported for Standalone to StandaloneCluster to Standalone• Application FailoverProtection of specific applications like SQL Server, Oracle DB, SWIFT. | نظام | 1 | 0 | 0 | 10 | نظام التعافي من الكوارث Disaster Recovery System 2.pdf |
10 بند
المستندات الداعمة (12 ملف)
| اسم المورد | قيمة العرض (ر.س) | قيمة الترسية (ر.س) | النتيجة الفنية | الحالة |
|---|---|---|---|---|
| شركة القرار الآمن لتقنية المعلومات مساهمة غير مدرجة | 20,817,139.00 | — | غير مطابق | مشارك |
| شركة ام دي اس لانظمه الحاسب الالي شركة شخص واحد | 14,423,024.00 | — | مطابق | مشارك |
| شركة امداد الرقميه للتقنية | 14,927,207.56 | — | غير مطابق | مشارك |
| شركة سور لتقنية المعلومات | 13,986,689.85 | — | غير مطابق | مشارك |
| شركة الضوابط المتقدمة لتقنية المعلومات | 13,961,940.93 | — | مطابق | مشارك |
| شركة حزام المعلومات شركة مساهمة سعودية مقفلة | 12,488,218.46 | — | غير مطابق | مشارك |
| شركة اليم الدولي للأمن السيبراني | 11,777,885.00 | — | غير مطابق | مشارك |
| شركة درع الأمان الرقمي للاتصالات و تقنية المعلومات | 10,500,000.00 | — | مطابق | مشارك |
| شركة درع الأمان الرقمي للاتصالات و تقنية المعلومات | 10,500,000.00 | 10,500,000.00 | — | مرسّى |
الآليات
تفضيل المنشآت الصغيرة والمتوسطة
معايير التقييم
معايير التقييم الفني
| المستوى الاول | المستوى الثاني | المستوى الثالث | الوزن النهائي |
|---|---|---|---|
| التقييم الفني |
معايير التقييم المالي
| المستوى الاول | المستوى الثاني | المستوى الثالث | الوزن النهائي |
|---|---|---|---|
| التقييم المالي | السعر | التكلفة الكلية | 100% |
أخبار المنافسة
title
تاريخ الإنشاء
value
05/08/46 12:52:33 م
title
تاريخ فتح العروض
value
23/09/46 10:00:00 ص
title
تمديد تواريخ المنافسة
value
تاريخ فتح العروض23/09/46 10:00:00 صآخر موعد لتقديم العروض22/09/46 02:00:00 مآخر موعد لإستلام الإستفسارات10/09/46 12:00:00 ص
title
تاريخ الترسيه
value
30/03/1447