The Vendor is required to provide for the overall planning, design, implementation, migration, testing, and operational transition of agency cloud-based web application firewall (WAF) solution.
1. Solution selection and procurement
• Evaluation and demonstration of one or more cloud-based web application firewall solutions that meet defined business and security requirements.
• Procurement of a single, enterprise-approved, cloud-based WAF platform to replace existing disparate WAF implementations.
2. Security baseline and policy configuration
• Establishing a standardized security baseline for the new WAF platform prior to onboarding applications.
• Implementation of consistent security policies across all protected services to eliminate gaps caused by multiple legacy WAF solutions.
3. Cloud-based WAF platform implementation
• Deployment and configuration of a consolidated cloud-based WAF solution aligned with agency cloud-first strategy.
• Configuration of core WAF capabilities, including traffic inspection, threat detection, and policy enforcement for externally facing services.
4. Protection against web-based threats
• Enablement of protections against common and emerging web-based threats, including open web application security project (OWASP) top 10 vulnerabilities.
• Configuration of traffic filtering, rate limiting, and application-specific security rules where required.
5. DDOS mitigation capability
• Enablement of built-in layer 7 distributed denial of service (DDOS) protection as part of the cloud-based WAF solution.
• Relocation of public-facing services away from corporate data center dependency to reduce exposure to DDOS attacks.
6. High availability and resilience
• Support for multi-zone or multi-region resilience to ensure continuity of critical web services.
7. Application migration activities
• Phased migration of in-scope applications to the new WAF platform, beginning with on-premises workloads.
• Migration through development, testing, and production environments using a controlled and staged approach.
• Support for parallel operation and rollback during migration to minimize business disruption.
8. Integration with enterprise services
• Integration of the WAF solution with existing DNS, load balancing, and network infrastructure.
• Integration with agency security monitoring tools for visibility and incident response.
9. Logging, monitoring, and access control
• Enable real-time monitoring, alerting, and audit logging capabilities.
• Ensure that all relevant logs are integrated and forwarded to the enterprise SIEM platform.
• Implementation of role-based access control for administration and operations.
10. Knowledge transfer and operational handover
• Knowledge of transfer and documentation to support operational handover to internal teams.
• Transition of the WAF platform to steady-state operational support following project completion.
Set up free email alerts and get notified when new government bids, tenders and procurement opportunities match your industry and location. Choose daily or weekly delivery.