No.Ed.CIL/IS Unit/It Security/2014/1..April, 2014. Quotation for Security Audit for EdCIL house IT infrastructure.



Similar documents
Subject: NOTICE INVITING QUOTATION for repair of AHU Air conditioning unit 6 th floor, RMSA Project, Vijaya Building, B.K. Road, Delhi.

Ref No: / /91/IT/Dir/ Date: 02/02/2012.

SUPPLY AND INSTALLATION OF INTERNET BANDWIDTH SERVICES

For providing Facility Management Services of IT Infrastructure at College of Engineering Pune

Tender document. for. Providing Managed Internet Leased Line Network. at Chandigarh Police Headquarters, Sector 9, Chandigarh

Office of the Competition Commission of India Hindustan Times House, K.G. Marg, New Delhi

2. The Earnest Money Deposit (EMD) of Rs. 50,000/- (Rupees Fifty thousand only) in

Dated 14 July, Director (A&F) NHIDCL

Ref. REC/Adm. (Estate)/ / Dated

FINANCIAL INTELLIGENCE UNIT INDIA 6 th Floor, Hotel Samrat, Kautilaya Marg, Chanakya Puri, New Delhi

Leader Dogs for the Blind 1039 South Rochester Road Rochester Hills, MI 48307

Penetration Testing. Request for Proposal

INDIAN INSTITUTE OF TECHNOLOGY GANDHINAGAR

Development of application Software for Election Commission

State Health Society, Bihar Pariwar Kalyan Bhawan, Sheikhpura, Patna-14

INVITATION FOR LIMITED TENDER FOR SUPPLY OF TECHNICAL MANPOWER

Inviting Quotation for Internet Leased Line Connection

ASDI Full Audit Guideline Federal Aviation Administration

NIT No. : ACS/OP /IS/B-16/11-12 To

भ रत य वम नपत तन धकरण

INVITATION FOR TENDER FOR SUPPLY OF EQUIPMENT

Vector Network Analyzer

FUTURES & OPTIONS SEGMENT Circular No Sub: Securities Trading Using Wireless Technology

INVITATION FOR TENDER FOR WEB DESIGN AND DEVELOPMENT

UNIVERSITY OF CENTRAL ARKANSAS PURCHASING OFFICE 2125 COLLEGE AVENUE SUITE 2 CONWAY, AR 72034

INVITATION FOR TENDER FOR SUPPLY OF EQUIPMENT

Air Compressor (Scroll type oil free), Dryer and all tubing

No /1/2016-Genl. Government of India Ministry of Textiles

Request For Quotation from Service Providers. for. Web Security & Performance Testing for Web-based Applications for UTIITSL

Inviting Tender from Cert-In empanelled agencies for Conducting Load and Security Testing of Web application of UPSDM

SOFTWARE TECHNOLOGY PARKS OF INDIA

SUPPLY, INSTALLATION, TESTING & COMMISSIONING OF SPLIT AIR CONDITIONERS

¼ããÀ ããè¾ã ¹ãÆãä ã¼ãîãä ã ããõà ãäìããä ã½ã¾ã ºããñ à Securities and Exchange Board of India

(RFP) PURCHASE OF BLADE SERVER

FOR PROCUREMENT OF MATERIALS UNDER DEPOSIT / APDRP WORKS

M.P.POWER MANAGEMENT COMPANY LIMITED

TENDER DOCUMENT FOR EXPRESSION OF INTREST FOR STORE AND ASSET MANAGEMENT SOFTWARE AIIMS PATNA

INVITATION FOR TENDER FOR SUPPLY OF EQUIPMENT

Invitation of Expression of Interest (EOI) From Consultancy Organizations For Creating Master Database of Regular Employees

IBM Global Technology Services Statement of Work. for. IBM Infrastructure Security Services - Penetration Testing - Express Penetration Testing

TENDER FOR INSTALLATION OF TEA/COFFEE VENDING MACHINES AND SUPPLY OF MATERIALS/CONSUMABLES AT CORPORATE OFFICE, GURGAON

Request for Proposal Scanning of Policy and non policy documents at SBI Life HO

Please furnish your quotation for the services mentioned in the enclosed quotation form. Your quotation should fulfill the following conditions: -

Oracle Financial Services Applications

SBU: GREASES & LUBRICANTS, KOLKATA

100 mbps dedicated uncompressed symmetric Internet Bandwidth (1:1) connectivity through optic fiber Leased Line at given location:

LIMITED TENDER ENQUIRY FOR RODENT CONTROL SERVICES IN AAAGH

TENDER DOCUMENTS FOR INTERNET LEASED LINE CONNECTION AT HRDG, CSIR COMPLEX, NEW DELHI : ( upto 1500 hrs.)

THE BUDAPEST STOCK EXCHANGE LTD. REGULATIONS ON THE USE OF REMOTE TRADING

SBI FUNDS MANAGEMENT PRIVATE LIMITED REQUEST FOR PROPOSAL FOR WEB SECURITY SOLUTION

REQUEST FOR PROPOSAL FOR DESIGNING AND PRINTING OF NEWSLETTER- SAMVAD

How To Buy Video Conferencing Equipment And Projector From Bhadarwah Campus Of Jammu And Kashmir

CENTRAL ELECTRONICS LIMITED (A Public Sector Enterprise) for the

Tender Notice No.: OIDC/07/DMN/BUS/Uniform/ /179 Dt LIMITED TENDER NOTICE

INVITATION FOR TENDER FOR SUPPLY OF EQUIPMENT

TENDER DOCUMENTS FOR SUPPLY INSTALLATION AND COMMISSIONING OF BIOMETRIC DEVICE FOR FINGERPRINT ATTENDANCE SYSTEM

Government of Jharkhand Department of Science & Technology Nepal House, Doranda, Ranchi Ph , , Fax ,

Prof.& Head, Department of Computer Science & Engineering PEC University of Technology Chandigarh

How To Ensure The C.E.A.S.A

Tender for 30Mbps (1:1) Internet Leased Line on RF for Translational Health Science an Technology Institute, Faridabad

Request For Quotation from Service Providers. for. ISO/IEC 27001:2013 Certification for UTIITSL

No. THSTI/EOI/Securitysystem/ th May, 2015 EXPRESSION OF INTEREST (EOI)

School of Open Learning University of Delhi

BIHAR RURAL DEVELOPMENT SOCIETY (BRDS) RURAL DEVELOPMENT DEPARTMENT GOVERNMENT OF BIHAR MAIN SECRETARIAT PATNA BIHAR (INDIA)

Notice Inviting Open Tender. Tender Enquiry No. IDRBT/SYS/GR/13.10/878/ Dated: Oct 25, 2013

Tender for development, upgradation of web based software application for Student Information System (SIS) INVITATION OF THE BID

TENDER FOR ANNUAL MAINTENANCE CONTRACT OF WEBSITEs OF O/O DIRECTORATE OF FILM FESTIVALS.

4 Mbps Internet connectivity Leased Line (1:1 uncompressed and unshared) for National Small Industries Corporation Ltd, New Delhi for one year.

TENDER NOTIFICATION ENTRY OF DATA FROM I-R/II-R/I-U/II-U FORM INTO DATABASE

School of Open Learning University of Delhi

Network Security Audit. Vulnerability Assessment (VA)

DIRECTORATE OF KNOWLEDGE MANAGEMENT IN AGRICULTURE (Indian Council of Agricultural Research) Krishi Anusandhan Bhavan, Pusa, New Delhi

NOTICE INVITING QUOTATION

SPICES BOARD (Ministry of Commerce & Industry, Govt. of India) Palarivattom.P.O. N H By Pass Kochi

Tender Forimplementationof Asset Management System

INVITATION FOR TENDER FOR SUPPLY OF EQUIPMENT , 15:00 Hrs (Indian time) , 16:00 Hrs (Indian time)

FOR "SELECTION OF SERVICE PROVIDER FOR ESTABLISHMENT OF DEDICATED INTERNET LEASED LINE OF 4 MBPS PRIMARY AND 2 MBPS SECEONDARY"

How To Run A Web Server On A Linux Or Windows Computer (For Free) On A Cheap Server (For Cheap) On Your Own Computer (Free) On An Old Hard Drive (For A Free) Or Ipad (For Low Cost)

No / / CICT / CCTV / AMC Date:

INVITATION FOR TENDER FOR SUPPLY OF EQUIPMENT

ANNEXURE - I MPD/EPC/TIC/ NR logo web application development dated: Page 1

DETAILED OF TENDER PAPER FOR PRINTING & SUPPLY OF FLEXI BOARD UNDER FEEDING PROGRAMMES (SNP/EFP & MDM) FOR THE YEAR

TENDER DOCUMENT FOR RISK MANAGEMENT POLICY (ALM Policy and Hedging Policy)

Tender. for Providing the. 155 MBPS Internet Leased Line Connectivity at. Indian Institute of Technology Jodhpur

Star Union Dai-ichi Life Insurance Company Limited. Request for Proposal (RFP) For. Learning Management System (Online e-learning tool)

1 Scope of Assessment

G-Cloud Definition of Services Security Penetration Testing

Notice for Inviting EOI from Chartered Accountants Firms for Conducting Statutory Audit of DRDA, Malkangiri. For the FINANCIAL YEAR

न शनल ट क सट इल क र प र शन ललल ट ड. 7, Lodhi Road, 7, ल ध र ड, New Delhi

How To Buy 1 Kg Of Maize African Tall

TENDER DOCUMENT FOR SUPPLY OF OMR SCANNER WITH BAR CODE READER

CENTRAL INFORMATION COMMISSION BLOCK IV, 5 TH FLOOR, OLD JNU CAMPUS, NEW DELHI TENDER DOCUMENT

Bidding/Invitation to Tender Documents PROCUREMENT/SUPPLY OF STATIONARY FOR COMPUTERIZED PAYROLL REQUIRED FOR CDA. March 3, 2016

Sub: Tender Enquiry for Sale of Condemned Items.

TENDER NOTICE NO. 04/

OPERATIONAL CAPABILITY TECHNOLOGY QUESTIONNAIRE

Transcription:

TO No.Ed.CIL/IS Unit/It Security/2014/1..April, 2014 Subject: Quotation for Security Audit for EdCIL house IT infrastructure. Dear Sir, This Corporation is interested in security Audit of its IT infrastructure as per TOR given in Annexure - I If you are in a position to meet the above-mentioned requirement, you are requested to submit your quotation based on our terms & conditions as set forth hereunder. The quotation is based on single bid (Techno-commercial) system. The envelope should contain the following documents. 1. Price Bid (format attached at Annexure-II) 2. Letter of acceptance to the terms and conditions of the NIQ. TERMS AND CONDITIONS: - Your quotation will be considered only for above subject matter. Other terms & conditions will be as under: - 1. Since the audit should be conducted at EdCIL House, 18A, Sector -16A, NOIDA, sales tax, service tax to be charged should be shown separately; if no service tax is shown separately, it will be presumed that service tax is included in the rates. 2. You are requested to quote your service Tax No. or Central Sales Tax No. whichever is applicable for the purpose of making payment on account of service tax/central sales tax. 3. The quotation in the enclosed format should reach in a sealed cover superscribed Quotation for IT Security Audit for EdCIL House. addressed to the Deputy General Manager (IS), EdCIL (India) Ltd., Ed.CIL House, 18A, Sector 16A, NOIDA so as to reach not later than 1600 hrs. on 07 h May, 2014. The quotation received after the due date will not be entertained. Any quotation received without the above superscription on the face of the envelop will not be entertained.

-2-4. All the amount shall be indicated by the vendor in figures as well as in words. Where there is any difference between price quoted in figures and words, amount quoted in words shall prevail. 5. Your quotation shall remain open for acceptance for 60 days or as may be specified from the date of opening. No revision / modifications in the quoted rate will be allowed during the period of validity of quotation or the extended period. 6. The successful vendor shall not sub-let or assign this contract or any part thereof without obtaining prior written permission of the Corporation otherwise the Corporation shall have the right to cancel the contract and to get the contract executed with another party and the successful vendor shall be liable to the Corporation for any loss or damage which the Corporation may sustain in consequence or arising out of such contract. 7. The payment will be made within 15 days on receipt of invoice (in duplicate) against the conduct of security audit of IT Infrastructure at EdCIL House, 18A, Sector 16A, Noida in your favor by a crossed a/c payee Cheque. 8. In the event of the quotation being submitted by a firm it must be signed separately by each partner holding Power of Attorney authoring him to do so. 9. In case of a Company the quotation should be submitted in the manner as laid down in the said Company s Articles of Association. 10. You are requested not to erase or mutilate any word(s) or figures occurring in your quotation, otherwise the quotation may be ignored. The overwriting is not allowed. 11. Start of audit should made within 15 days (fifteen days) from the date of receipt of purchase order in this regard positively. 12. This Corporation also reserves the right to accept or reject any quotation in whole or in parts without assigning any reason thereof. 13. Agencies, which have failed to fulfill earlier contractual obligations, may not be considered. 14. Your quotation should be free from overwriting. All corrections and alteration should be duly attested by the vendor/tenderer. 15. The quotation should be unambiguous in all respects. Yours faithfully, (G S Sreedhar) DGM (IS)

Vulnerability Assessment Annexure - I Vulnerability Assessment Methodology: Study & scope the IT architecture & components. Determine the boundary of analysis Identify asset owners & schedule tasks Impact analysis for Active scans, which includes assessment of Service(s) or Server (s) (Six in number), Network devices, Firewalls and Desktops(5) scans in online production. Plan for Downtime & Contingency, if applicable Estimate the scan process, based on the complexity of the target network(s) and host(s) Scan Policy to define the level of scan - Information gathering, Policy checking, Port scanning, Password analysis, Attack stimulation etc. Scan the targeted network(s) and host(s), based on the defined scan policy Collect the scan results and analyze for security loopholes, configuration errors, default installation settings, overlooked setups, password quality, firmware/software revisions, patch fixes, security policy violations etc. Submission of assessment Reports with suggestions and recommendations to fix the vulnerabilities. Fixing the errors in server logs. Any other tests not mentioned above which are necessary. Penetration Testing Methodology (Internal and External) IT A & P shall undertake the following test as a part of the penetration testing (Internal and External (3 IPS)): Port Scanning System & Services Identification Vulnerability Research and Verification Password Cracking Denial of Service Testing Various other attacks and tests Risk Mitigation and Safeguard Recommendation The aim of this phase is to identify remedial solutions and recommend implementation of the same to mitigate all identified risks, the aim being to develop a secure

environment. This shall be done through an in-depth review of the Security Scanner outputs for high to low vulnerabilities. Asset/Threat/Vulnerability mapping and its risk mitigation. Fixing High-Level Security Vulnerabilities IT consultants would then recommend the fixes for the high level vulnerabilities, which need to be implemented by the client s network administration team and Vendor audit team. Sometimes it is necessary to test a patch or other upgrade for compatibility, and it may not be possible to update some patches immediately without testing. However, these need to be implemented for safe operation after testing. Deliverables Vulnerability Assessment & Penetration Testing Report with recommendations for mitigation of risk.

Annexure II PRICE BID format Sl. No. Particular 1. Security Audit of Infrastructure 2. Vulnerability Assesment 3. External Penetration Testing ( 3 IPS) 4 Risk Mitigation Plan 5 Fixing vulnerabilities found TOTAL (Rs.) Total Cost (Rs.) Tax, if any