PUR1308/11 Pre-qualification Questionnaire (PQQ) ------------------------------------------------------------ Provision of E-Mail and File Encryption Technologies ------------------------------------------------------------
1.0 INTRODUCTION The European Bank for Reconstruction and Development (the "EBRD") is an international financial institution. The EBRD was established by treaty in 1990 to foster the transition towards open market oriented economies and to promote private and entrepreneurial initiatives in Central and Eastern Europe, the Baltic States and the Commonwealth of Independent States that are committed to and applying the principles of multiparty democracy, pluralism and market economics. The EBRD has 63 members (61 countries, the European Community and the European Investment Bank). Further information about the EBRD's roles and activities can be found on the EBRD's website: www.ebrd.com. 2.0 OBJECTIVE OF THIS PQQ The objective of this PQQ is to obtain responses to the attached questionnaire from suppliers of encryption software. Responses will be evaluated in order to qualify suppliers to participate in a tender. Only suppliers who answer yes to all of these questions will be deemed qualified for the subsequent tender. 3.0 EBRD CONTACT DETAILS Your sole contact for the purposes of the PQQ is: Tanya Lucas Manager Corporate Procurement Unit EBRD One Exchange Square London EC2A 2JN Email: lucasta@ebrd.com
Mandatory Functional Requirements Y/N Comments Outbound Encryption of E-Mails and Attachments Does the solution allow encryption of e-mails and attachments? Does the solution have the ability to secure unstructured data (i.e. body text in an email)? Does the solution have the ability to apply and read classifications applied to e-mail messages/attachments and thereafter automatically encrypt said e- mail/attachment? Does the solution have the ability to route and split messages based on domain, information classification, and recipient, and also create a whitelist of domains that enforces encryption? Does the solution have the ability to control access to the data and set permissions regarding revocation of recipient access even after the e-mail has been sent? Does the solution have the ability for Bank User s to manage their sent items via a web-portal (using their mobile device if required), changing, adding restrictions etc? Does the solution have the ability to audit sender and recipient activity including showing when a file/attachment is opened by the recipient? Inbound Encryption of E-Mails and Attachments Does the solution have the ability to encrypt inbound e-mail based on predefined criteria?
Inbound Decryption at Gateway and Locally (on desktop, laptop etc) Does the solution have the ability to automatically decrypt incoming messages on behalf of the recipient whilst also having the ability for messages to be decrypted locally by the authorised recipient? Integration with IC Automation Software Does the solution integrate with Information Classification Automation solutions/software, with the encryption solution having the ability to perform functions such as automated encryption based on classification levels? Usability for partners/organisations receiving e-mails/documents from the Bank Does the solution allow Bank clients and partners to send or receive emails and attachments securely with the Bank at no cost to them? BYOD Does the solution support secure email/file exchange between Users accessing from mobile devices? (Mobile phones, tablet devices etc.) Does the solution allow sending, receiving, reading, editing, decrypting data on mobile devices? Mandatory Technical Requirements Y/N Comments Architecture The encryption server (and all encrypted data) must be located on the Bank s infrastructure. Does the solution allow for this requirement? Hosted server solution must be run on Windows or Redhat with SQL server or Oracle database. Does the solution allow for this requirement? File/e-mail encryption should occur on the secure server and not locally on the user s device (e.g. desktop, laptop, mobile device etc). Does the solution allow for this requirement?
Solution should be able to provide controls over local encryption where users are unable to encrypt files and save to their personal drives, network shares etc. If required, solution should allow local encryption for certain groups, individuals with control over this functionality held with administrators. Does the solution allow for this requirement? Infrastructure Integration Does the solution allow integration with EBRD s Internet server protocols (FTP/FTPS, HTTP/HTTPS) to enable users to upload files to the Internet or to local secure servers? Is the solution compatible with EBRD infrastructure standards (e.g. LDAP Compliance, Active Directory, Exchange 2003 or above, Outlook 2000 or above)? Is the solution compatible with Blackberry Enterprise Server (BES)? Does the solution have the ability to give the User control as to whether a recipient is able to forward, download or copy mails or attachments? Does the solution have the ability to stop the forwarding of e-mails and attachments by the recipient? Key Management Does the solution allow, if required by the Bank, for encryption keys to be stored and managed by Bank IT? Management Does the solution provide a central management facility? Data Access Does the solution provide control over data location, i.e. recipient access to data should be through the designated servers with no data residing on the recipient s computer, laptop etc? Third Party/Client Access Please confirm that the solution does not require installation of any software by the recipient (i.e. client or third party receiving e-mail and/or attachment from an EBRD User)?
Please confirm that there no costs for the recipient when accessing an encrypted e-mail and/or attachment? Sent Item Management Does the solution have the ability to manage sent items, i.e. allowing for access to sent items (access permissions) to be amended? (This should include management of encrypted e-mails and files via web-portal and including on mobile devices)