RFP IDBI/PCell/RFP/2014-15/18 dated 24 th January 2015 1. - - Document 2. - - Document 3. - - Document 4. - - Document 6 A Bid Security of Rs.50,000/- (Rupees Fifty thousand Only)by way of demand draft or pay order in favor of IDBI Bank Limited payable at Mumbai only, to be submitted along with the Bid. A Bid Security of Rs.1,00,000/- (Rupees One lac Only)by way of demand draft or pay order in favor of IDBI Bank Limited payable at Mumbai only, to be submitted along with the Bid. 6 Schedule for Online Reverse Auction Schedule for opening commercial bids 6 Schedule for Receipt of Bids 16-February -2015 14:30 hours 6 Schedule for Opening of Technical Bids 16-February -2015 15:00 hours 5. 1 2 Purpose of RFP 9 The purpose of this RFP is to invite Bids from Bidders for Web Application Firewall (WAF) where the WAF application will be installed on a VM instance on servers at Bank s premises. 6. 1 7 Eligibility Criteria for Bidders 7. 1 7 Eligibility Criteria for Bidders 11 The Bidder should have minimum annual turnover of at least Rs. 20Croresin the last three financial years (i.e.2011-12, 2012-13 & 2013-14) 11 Bidder should have minimum 2CISA/CISM/CISSP/CIHE/CVA/CCSE or Schedule for Receipt of Bids 23-February -2015 14:30 hours Schedule for Opening of Technical Bids 23-February -2015 15:00 hours The purpose of this RFP is to invite Bids from Bidders for Web Application Firewall (WAF) where the WAF application will be installed on a VM instance on servers or an appliance at Bank s premises. The Bidder should have minimum annual turnover of at least Rs. 5 Crores in the last three financial years (i.e.2011-12, 2012-13 & 2013-14) Bidder should have minimum 5 CISA/CISM/CISSP/CIHE/CVA/CCSE or
RFP IDBI/PCell/RFP/2014-15/18 dated 24 th January 2015 8. 1 7 Eligibility Criteria for Bidders similar security related certification holders in the organization. 11 The Bidder should have implemented WAF in at least one organization in the BFSI/e-commerce Sector where the site/sites have around 5000 concurrent users. Necessary documentation justifying having executed such orders should be submitted. 9. 1 10 Payment Terms 14 The WAF is procured on a subscription model. Payment towards the subscription shall be made on quarterly basis. Payment will be processed only after submission of necessary documents like delivery challan, Installation/commissioning report and invoices duly signed by authorized bank person and road permit receipt (if any). 10. 2 2 Documents to be submitted along with the Bid 11. 2 8 Earnest Money Deposit (EMD) 18 The list of documents in the technical bid should be strictly as per Annexure V 20 The EMD is Rs.50,000/- (Rupees Fifty thousand only) by way of demand draft in favor of IDBI Bank Limited similar security related certification holders in the organization. The Bidder should have implemented the proposed WAF in at least one organization in the BFSI/e-commerce Sector where the site/sites have around 5000 concurrent users. Necessary documentation justifying having executed such orders should be submitted. The WAF is procured on a subscription model. Payment towards the subscription shall be made on quarterly basis in advance. Payment will be processed only after submission of necessary documents like delivery challan, Installation/commissioning report and invoices duly signed by authorized bank person and road permit receipt (if any). Payment for the Hardware if taken from the bidder would also be on a subscription model. The list of documents in the technical bid should be strictly as per Annexure IV The EMD is Rs.1,00,000/- (Rupees One lac only) by way of demand draft in favor of IDBI Bank Limited payable at Mumbai.
RFP IDBI/PCell/RFP/2014-15/18 dated 24 th January 2015 12. 2 10 Format and Signing of Bid 13. 3 9 Inspection and quality control tests/check payable at Mumbai. 21 The order of documents in the technical bid should be strictly as per the Annexure V at the end of this RFP. 30 the Acceptance Certificate in the format given in Annexure will be issued by IDBI Bank. 14. 3 40 Termination 45 The payments will be made for all services rendered upto the date the termination becomes effective, at the contracted terms and prices 15. 4 2 Scope of Work 49 Scope is to setup a Web Application Firewall (WAF) where the WAF will be installed at our Bank s premises at CBD Belapur, Navi Mumbai. The Web application Firewall is to be implemented in subscription model 16. 4 2 Scope of Work 49 The WAF should be capable of supporting the minimum throughput of 2 Gbps 17. 4 3 Scope of Work 49 The solution should be capable of providing instant protection from all The order of documents in the technical bid should be strictly as per the Annexure IV at the end of this RFP. the Acceptance Certificate in the format given in 5 will be issued by IDBI Bank. The payments will be made for all services rendered upto the date the termination becomes effective, at the contracted terms and prices. The Hardware and Software would be returned to the Bidder. Scope is to setup a Web Application Firewall (WAF) where the WAF will be installed at one location at our Bank s premises at CBD Belapur, Navi Mumbai. The Web application Firewall is to be implemented in subscription model The WAF should be capable of supporting the minimum throughput of 2 Gbps. Not more than 5 applications would be hosted behind the WAF and these would be internet facing web based applications and the traffic would be http and https. The solution should be capable of providing instant protection from all the
RFP IDBI/PCell/RFP/2014-15/18 dated 24 th January 2015 the known zero day vulnerabilities, which will never block legitimate traffic. 18. 4 3 Scope of Work 49 The solution should be able to prevent any attack from layer 3 to layer 7. 19. 4 3 Scope of Work 50 The Solution should have a vulnerability scanner or support integration with 3rd party vulnerability scanners like Cenzic, Whitehat, Qualys etc. 20. 4 3 Functional requirements 21. 4 4 SERVICE LEVEL EXPECTATIONS FOR WEB APPLICATION FIREWALL 22. 5 1 Technical Bid Form 50 The solution should be Comprehensive, Easy to Deploy, Robust, Scalable, Secure, Reliable, Zero latency, State of art & should be in high availability 50 SERVICE LEVEL EXPECTATIONS FOR WEB APPLICATION FIREWALL 52 We enclose a demand draft of Rs.50,000 (Rupees Fifty thousand only) towards EMD, in favor of "IDBI Bank Limited" drawn on, Branch payable at Mumbai. known zero day vulnerabilities, which will never block legitimate traffic. Base vulnerabilities would be provided by the Bank The solution should be able to prevent any attack to layer 7. The Solution should support integration with 3rd party vulnerability scanners like Cenzic, Whitehat, Qualys etc. The solution should be Comprehensive, Easy to Deploy, Robust, Scalable, Secure, Reliable, latency less than 1 millisecond, State of art & should be in high availability SERVICE LEVEL EXPECTATIONS FOR WEB APPLICATION FIREWALL (Including hardware and software) We enclose a demand draft of Rs.1,00,000 (Rupees One lac only) towards EMD, in favor of "IDBI Bank Limited" drawn on, Branch payable at Mumbai.
RFP IDBI/PCell/RFP/2014-15/18 dated 24 th January 2015 23. 5 2 & 3 COMMERCIAL BID FORM (PRICE LIST) & Price Schedule - Format 53 & 54 Please refer the revised commercial Bid format and price schedule. 24. 5 6 SELF 59 Dated this day of DECLARATIONS 2014 25. 5 7 UNDERTAKING 60 Dated at this FROM OEM day of 2014. 26. 5 10 CONTRACT FORM 65 THIS AGREEMENT made at the day of. 2014 between IDBI BANK 27. - - Annexure II 78 The vendor/bidder must have at least one support office in India. Dated this day of 2015 Dated at this day of 2015. THIS AGREEMENT made at the day of. 2015 between IDBI BANK The vendor/bidder must have at least one support office in Mumbai. Document Required: Utility Bills, Registration Certificate mentioning the office address etc Manufacturer s Authorization Letter from 28. - - Annexure IV 80 Manufacturer s Authorization Letter from the OEM of the Tablet the OEM of the WAF 29. - - Annexure IV 80 Documents to show that the Bidder Documents to show that the Bidder has has been in the business of supply, been in the business of supply, delivery, delivery, operationalization of Tablet operationalization of WAF for the last 2 for the last 2 preceding financial years preceding financial years ( 2012-2013 and ( 2012-2013 and 2013-2014). 2013-2014). 30. - - Annexure IV 80 The Bidder should have implemented Documents to show that the Bidder has
RFP IDBI/PCell/RFP/2014-15/18 dated 24 th January 2015 WAF in at least one organization in implemented WAF in at least one the BFSI/e-commerce Sector where organization in the BFSI/e-commerce the site/sites have around 5000 concurrent users. Sector where the site/sites have around 5000 concurrent users. 31. - - Annexure IV 80 POA as per format provided in RFP. POA as per format provided in RFP on page 32. - - General Query - If solution is in VM instance, will bank provide the VM environment for hosting WAF instances. General Instructions: 55. The Bidder has to bid for the Hardware for the same. In case the Bank find that Banks internal empanelled rates are cheaper for the same processing power and capabilities of the hardware proposed, then Bank would consider providing the same. This Corrigendum1 and its annexure constitutes an integral part of the RFP and shall be read in conjunction with the RFP Where inconsistent with the original RFP, this Corrigendum 1 shall govern. In case of repetition of the above mentioned sections/clauses this Corrigendum1 shall govern. Unless specifically changed herein all other requirements, terms and conditions of the RFP remain unchanged. It is the responsibility of all bidders to the RFP to conform to this Corrigendum1 and its annexure. Bidders shall acknowledge receipt of this Corrigendum 1 in the cover letter. Place: Mumbai Date: 12 February, 2015.