USA(New York)
CAM-0156

RFP Description

The Vendor is required to provide to provide comprehensive cybersecurity event monitoring, threat detection, and IT infrastructure event monitoring services.
- Cybersecurity Event Monitoring (24x7x365)
1. Service Requirements
• Provide continuous (24 hours/day, 7 days/week, 365 days/year) monitoring of security events across agency entire it infrastructure: including, but not limited to Microsoft 365, AWS, and azure resources
• Utilize agency existing security monitoring systems, tools, and platforms while ensuring seamless integration with future enhancements.
• Detect, analyze, and respond to cybersecurity incidents according to defined severity levels and SLAS.
• Perform initial triage and assessment of security alerts to determine severity and impact.
• Escalate critical security incidents to appropriate agency personnel according to established procedures.
• Document all security events, including actions taken, in a centralized incident management system.
• Conduct preliminary forensic analysis for security incidents and provide post-incident reports with root cause analysis.
• Provide recommendations for remediation activities. 2. Reporting requirements
• Create real-time alerts for critical security events.
• Furnish monthly comprehensive security reports including metrics, trends analysis, and recommendations.
• Conduct quarterly reviews of monitoring effectiveness and suggest improvements. - IT production infrastructure event monitoring (24x7x365)
1. Service requirements
• Continuously monitor production it infrastructure events (24 hours/day, 7 days/week,
365 days/year), approximately 100 assets.
• Monitor server performance, network devices, applications, and other critical it systems.
• Respond to system alerts according to predefined SLAS.
• Execute predefined response actions on affected systems per agency operational procedures.
• Escalate unresolved issues to appropriate agency personnel when necessary.
• Document all infrastructure events and actions taken in agency ticketing system.
2. Reporting requirements
• Generate real-time alerts for critical infrastructure events.
• Deliver weekly summaries of off-hours infrastructure events.
• Furnish monthly reports detailing infrastructure incidents, trends, and recurring issues with recommendations for improvement.
- Vulnerability management services
1. Service requirements
• Monitor configuration changes and policy violations in cloud environments.
• Conduct regular vulnerability scans of agency network, systems, and applications using industry-leading scanning tools.
• Perform quarterly external and internal penetration tests.
• Correlate identified vulnerabilities with threat intelligence to prioritize remediation efforts.
• Integrate vulnerability data with security monitoring to enhance detection capabilities.
• Provide detailed remediation recommendations with specific action items.
• Track vulnerability remediation progress and validate fixes.
2. Reporting requirements
• Deliver comprehensive vulnerability reports within 3 business days of scan completion
• Include executive summaries with risk ratings and prioritized remediation guidance
• Provide trend analysis showing vulnerability remediation progress over time
• Conduct quarterly review meetings to discuss findings and remediation strategies and validate remediation actions.
- Threat intelligence integration
1. Service requirements
• Provide access to commercial and proprietary threat intelligence feeds relevant to the financial sector with real-time enrichment.
• Correlate threat intelligence with agency environment to identify specific risks and emerging attack patterns.
• Develop custom detection rules based on emerging threats
• Provide early warning of threats specifically targeting retirement systems and financial institutions
• Update detection capabilities in response to new threat actor tactics, techniques, and procedures (TTPS)
2. Reporting requirements
• Provide immediate advisories for critical threats targeting agency environment
• Include actionable intelligence with specific detection and mitigation recommendations.
• Conduct monthly threat landscape reviews with agency security personnel.
- Contract Period/Term: 1 year
- Questions/Inquires Deadline: May 01, 2025

Timeline

RFP Posted Date: Friday, 25 Apr, 2025
Proposal Meeting/
Conference Date:
NA
NA
Deadline for
Questions/inquiries:
Thursday, 01 May, 2025
Proposal Due Date: Friday, 30 May, 2025
Authority: Government
Acceptable: Only for USA Organization
Work of Performance: Offsite
Download Documents

Similar RFPs




USA(South Carolina)