FIJIAN ELECTIONS OFFICE SYSTEM CONSULTANCY AUDIT. Expression of Interest (EOI) (04/2017)

Similar documents
IT Governance ISO/IEC 27001:2013 ISMS Implementation. Service description. Protect Comply Thrive

ISO : Competence Requirements Clause 7

REQUEST FOR EXPRESSIONS OF INTEREST

Application for Certification

ISO / IEC 27001:2005. A brief introduction. Dimitris Petropoulos Managing Director ENCODE Middle East September 2006

Data Processing Agreement

Minimum Requirements For The Operation of Management System Certification Bodies

_isms_27001_fnd_en_sample_set01_v2, Group A

VOLUNTARY CERTIFICATION SCHEME FOR MEDICINAL PLANT PRODUCE REQUIREMENTS FOR CERTIFICATION BODIES

Error! No text of specified style in document.

SAMPLE REPORT. Business Continuity Gap Analysis Report. Prepared for XYZ Business by CSC Business Continuity Services Date: xx/xx/xxxx

Request for Proposal for Technical Consulting Services

SPECIFIC PROCUREMENT NOTICE IT SERVICES

KENYA SCHOOL OF GOVERNMENT EMPLOYMENT OPORTUNITY (EXTERNAL ADVERTISEMENT)

What is ISO/IEC 27001?

Request for Proposal (RFP)

Areas of impact for client consideration taken from the Rules for achieving IATF recognition Third edition for ISO/TS

falanx Cyber ISO 27001: How and why your organisation should get certified

Regulation for the accreditation of product Certification Bodies

Data Processing Clauses

UNITED NATIONS INDUSTRIAL DEVELOPMENT ORGANIZATION. The National Quality Infrastructure Project for Nigeria (NQIP) Project ID

Data Processor Agreement

Google Cloud & the General Data Protection Regulation (GDPR)

Data Protection. Code of Conduct for Cloud Infrastructure Service Providers

DISTRICT OF COLUMBIA WATER AND SEWER AUTHORITY DEPARTMENT OF PROCUREMENT

ISO/IEC INTERNATIONAL STANDARD

HPE DATA PRIVACY AND SECURITY

ISO/IEC INTERNATIONAL STANDARD

Protecting your data. EY s approach to data privacy and information security

POWER AND WATER CORPORATION POLICY MANAGEMENT OF EXTERNAL SERVICE PROVIDERS

Audit and Certification Process of GUTcert for

CERTIFICATION BODY (CB) APPROVAL REQUIREMENTS FOR THE IFFO RESPONSIBLE SUPPLY (IFFO RS) AUDITS AND CERTIFICATION

FSC STANDARD. Standard for Multi-site Certification of Chain of Custody Operations. FSC-STD (Version 1-0) EN

Master the Audit of Information Security Management Systems (ISMS) based on ISO/IEC 27001

DATA PROCESSING TERMS

SCS FSC Chain-of-Custody Guidance for Certification of Multiple Sites FSC-STD V2-1

POSITION DESCRIPTION

A guide to. exemptions

SPECIFIC PROVISIONS FOR THE ACCREDITATION OF CERTIFICATION BODIES IN THE FIELD OF INFOR- MATION SECURITY MANAGEMENT SYSTEMS (ISO/IEC 27001)

Guide to the implementation and auditing of ISMS controls based on ISO/IEC 27001

Description of the certification procedure MS - ISO 9001, MS - ISO 14001, MS - ISO/TS and MS BS OHSAS 18001, MS - ISO 45001, MS - ISO 50001

ISO Gap Analysis Excerpt from sample report

SLOVAK FOREST CERTIFICATION SYSTEM September 1, 2008

GDPR AMC SAAS AND HOSTED MODULES. UK version. AMC Consult A/S June 26, 2018 Version 1.10

Level Access Information Security Policy

(The mandatory fields are marked with an * asterix)

RFQ OIT-1 Q&A. Questions and Answers, in the order received.

UKAS accredited Certification Bodies

IECEx Guide Guidance for Applications from Service Facilities seeking IECEx Certification

VOLUNTARY CERTIFICATION SCHEME FOR MEDICINAL PLANT PRODUCE

RFQ OIT-1 Q&A. Questions and Answers, in the order received.

Checklist According to ISO IEC 17065:2012 for bodies certifying products, process and services

EXAM PREPARATION GUIDE

WELCOME ISO/IEC 27001:2017 Information Briefing

ITG. Information Security Management System Manual

Critical Cyber Asset Identification Security Management Controls

ADIENT VENDOR SECURITY STANDARD

EXAM PREPARATION GUIDE

Chapter 4 EDGE Approval Protocol for Auditors Version 3.0 June 2017

EXAM PREPARATION GUIDE

Information Security Management System (ISMS) ISO/IEC 27001:2013

Reference Framework for the FERMA Certification Programme

EU GDPR & ISO Integrated Documentation Toolkit integrated-documentation-toolkit

Request for Proposals

What is BS 7799? BS 7799 is the most influential, globally recognised standard for information security management.

IPC Certification Scheme IPC QMS/EMS Auditors

Q&A for Citco Fund Services clients The General Data Protection Regulation ( GDPR )

BPIF Colour Quality Management Certification Scheme factsheet

PROTERRA CERTIFICATION PROTOCOL V2.2

Incentives for IoT Security. White Paper. May Author: Dr. Cédric LEVY-BENCHETON, CEO

Chapter 4. EDGE Approval Protocol for Auditors

IAF Guidance on the Application of ISO/IEC Guide 62:1996

A80F300e Description of the SA8000:2014 certification procedure

EXAM PREPARATION GUIDE

APPROVAL SHEET PROCEDURE INFORMATION SECURITY MANAGEMENT SYSTEM CERTIFICATION. PT. TÜV NORD Indonesia PS - TNI 001 Rev.05

New York Department of Financial Services Cybersecurity Regulation Compliance and Certification Deadlines

ISO LEAD AUDITOR TRAINING

Areas of impact for client consideration taken from the Rules for achieving and maintaining IATF recognition 4 th Edition for ISO/TS 16949

Audit Considerations Relating to an Entity Using a Service Organization

Payment Card Industry (PCI) 3-D Secure (PCI 3DS) Qualification Requirements for 3DS Assessors

KENYA ACCREDITATION SERVICE

South African Forestry Assurance Scheme SAFAS 6:2018. Certification and Accreditation Procedures. Issue SAFAS Council SAFAS

IPC Certification Scheme IPC Management Systems Auditors

EXAM PREPARATION GUIDE

ISO STANDARD IMPLEMENTATION AND TECHNOLOGY CONSOLIDATION

Procedure for the Selection, Training, Qualification and Authorisation of Marine Management Systems Auditors

Course Fees: 850 euro

Data Processing Agreement for Oracle Cloud Services

EVALUATION AND APPROVAL OF AUDITORS. Deliverable 4.4.3: Design of a governmental Social Responsibility and Quality Certification System

Orion Registrar, Inc. Certification Regulations Revision J Effective Date January 23, 2018

Internal Audit Report. Electronic Bidding and Contract Letting TxDOT Office of Internal Audit

UKAS Guidance for Bodies Offering Certification of Anti-Bribery Management Systems

SUBJECT: REQUEST FOR PROPOSALS FOR HARBOR DEPARTMENT CLOUD COMPUTING SERVICES

SECTION 10 CONTRACTING FOR PROFESSIONAL SERVICES CONSULTANT COMPETITIVE NEGOTIATION ACT (CCNA)

QUICKSIGN Registration Policy

Audit & Inspection Department - Head Office: Manipal. Empanelment of CISA qualified individuals on Contract Basis for conducting IS Audits

EXAM PREPARATION GUIDE

Request for Quotations

Master the Audit of Information Security Management Systems (ISMS) based on ISO/IEC 27001

ISO 9000:2015 LEAD AUDITOR

Transcription:

FIJIAN ELECTIONS OFFICE SYSTEM CONSULTANCY AUDIT Expression of Interest (EOI) (04/2017) Closing Date: 4pm Friday 4 August 2017

EXPRESSION OF INTEREST [EOI] SYSTEM CONSULTANCY AUDIT OF FEO s ELECTION MANAGEMENT SYSTEM 1.0 Introduction The Fijian Elections Office [ FEO ] is an independent electoral management body based in Suva, Fiji. The mandate of the FEO is to conduct general and other elections in Fiji in accordance with the laws of Fiji. The FEO has embarked on developing an Election Management System [ EMS ] software for managing Election Operations. It is intended that the system will provide an integrated platform for all aspects of election management. The EMS will integrate with other systems to ensure the flow of necessary data to respective departments within the FEO. As part of the project the FEO would like to undertake an independent security review of its EMS. Therefore, FEO invites reputable companies and/or consultants [ Suppliers ] to determine whether the EMS complies with international best practices including audit testing and verification of security access level pertaining to Security and Compliance Audit. The recommendations submitted would help the FEO in improving its system as a whole. The deadline for all submissions for the EOI is on the 4 th of August, 2017 at 4pm. 2.0 Scope of Work The scope of work will take place at the FEO and includes the following: 2.1. Review the EMS in terms of its usage, capacity, and internal controls including systems integration and advice compliance to the project scope of the EMS; 2.2. Security Management; 2.2..1. Security Equipment Configurations and Policies; 2.2..2. Penetration testing and Vulnerability Assessment (PA/VA) of various zones; 2.2..3. External, Internal and User testing on the software; and 2.2..4. Application Attacks.

2.3. Information and Data security assessment, classifications and awareness levels across the EMS and organisation; 2.4. Risk Assessment on the network and EMS system; and EMS rules and checks are aligned to the 2013 Constitution of Fiji, Electoral Act, 2014 and relevant laws. An Interim Audit report is expected within four (4) weeks of contract sign-off, with any recommendations to be actioned. There will be a follow up period on all recommendations. A final Certificate and Report will then be required at the end of the exercise. 3.0 Expertise Required Competency: As a supplier you or your team are required to: 1. Have relevant qualifications with extensive experiences in the area of IT Development, Information Systems with IT auditing and Security Compliance qualifications; 2. Have a Certified Information Systems Auditor or ISMS Lead Auditor (ISO 27001) or GIAC Systems and Network Auditor; 3. Be an expert in developing organisational IT policy frameworks, IT Governance processes and innovative IT initiatives; 4. Have undertaken business re-engineering processes in an IT and Systems reform Environment; 5. Demonstrated ability in developing specific IT policies; and 6. Have the ability to write clear and concise reports. Qualification: 1. Provide information and or certifications indicating that you are qualified to perform the required services;

2. Proof of some exposure to similar assignments; and 3. The supplier should also provide references and referees for similar private, public or government IT system security compliance audit work. 4.0 Proposed Work Plan A proposed work plan outlining tasks to be carried out with specific key deliverables and completion timelines is required to be submitted by the consultant. The Final Certificate must be provided to the FEO on or before 5 January 2018. 5.0 Costs Total Costs of work with an outline of costs to be tied to specific deliverables in line with the work program and timelines. 6.0 Audit Certification An Audit Certificate and a separate Executive Summary Report to be presented to Executive Management on the final week of the contract. Please note that the audit certificate may be put on public record. 7.0 Confidentiality FEO Confidential Information means all information, typesetting, artwork, colour separation, data, lists, accounts, voter information and process information provided by FEO to the supplier and used by the supplier in providing services. The supplier agrees they will use the Confidential Information for no other purposes other than to provide contractual work and will not use any FEO Confidential Information, or disclose any FEO Confidential Information to any third party without the express prior written consent of FEO. Upon termination of this Agreement, the consultant shall return to FEO all FEO Confidential Information in its possession in whatever form it shall take including without limitation information contained in computer tapes or disks, in written form, or contained on printing blocks, film or moulds. All FEO Confidential Information shall remain the exclusive property of FEO.

8.0 Indemnity Clause The supplier will need to have a current professional indemnity insurance policy valid in Fiji when selected for the work. 9.0 Contacts Upon release of this EOI, all suppliers communications concerning this EOI must be directed to the EOI Coordinator listed below. Riaz Hanif Manager Procurement and Asset Management Fijian Elections Office 59-63 High Street, Toorak, Suva Email: tenders@feo.org.fj Please use the EOI Reference Number and Title in all communications with the Coordinator. Unauthorized communication regarding this request with Fijian Elections Office employees or representative may result in disqualification. Any oral communications will be considered unofficial and non-bidding on Fijian Elections Office. Suppliers should rely only on written statements issued by the EOI Coordinator. All communications and information to be provided electronically.