Re-Tender RFP for Providing Dedicated Web Hosting Services for IBA Pre-Bid Queries The pre-bid meeting for clarifications on the Re-Tender RFP for Providing Dedicated Web Hosting Services for IBA was held on 25 th August, 2014 at 03:00 p.m. at the IBA, WTC, Mumbai. Following are clarifications given during the meeting. It was also decided to extend the last date for submission of bids by one week to 9 th September, 2014 and consequently Technical Bids opening date to 10 th September, 2014. Time remains the same. Sr. No. Vendor Query / RFP Clause Clarification sought IBA Comments 1 Digital and IT Infrastructure Management Whether we can propose cloud based solution instead of data centre? Where cloud solution are with more flexibility to use and are more convenient than data centres. No. We have requested for the dedicated infrastructure as per the Annexure-I : Specifications for Dedicated IBA Web Server and Services. Disaster Recovery and Backup Server and Services for Dedicated IBA Web Server and Services with RPO and RTO of 2 hours This may be on the Cloud Services provided by the Bidder. Cyber Futuristics India Private Limited. Need hard disk space locally on the server or can we provide hard disk space on SAN with RAID 6? (Ref. Annexure-1, storage section) We have requested for Storage: 1 TB of RAID 5 Total Hard Disk Space for use of the Website. This can be on the server or exclusively on dedicated SAN. 1
Sr. No. Vendor Query / RFP Clause Clarification sought IBA Comments Do we need to install VNC software on the server, scope of work is not clear? (Ref. Annexure-1, Operating System) VNC will be required for the day-to-day maintenance by our Web Developer Vendor. What is the exact scope of work for Database Management? (Ref. Annexure-1, The 24X7 Monitoring and Managing Services) What would initial data size on the server which we need to replicate on DR site? What would be the network connectivity between primary and DR site for data replication i.e. VPN, Point-2-Point or over the Internet? (Not mentioned in the tender) The 24X7 Monitoring and Managing Services also includes but not limited to the Operating System Management, Data Base Management, Server Management, Network Management, Firewall Management, Patch Management, Change Management, Disaster Recovery and Backup Management for smooth running of the IBA Website. We have requested for Storage: 1 TB of RAID 5 Total Hard Disk Space for use of the Website. We have requested for Disaster Recovery and Backup Server and Services for Dedicated IBA Web Server and Services with RPO and RTO of 2 hours. The Bidder will have to size and provide for the secure network connectivity with necessary bandwidth for meeting the RPO and RTO of 2 hours. 2
2 Netmagic IT Services Pvt. Ltd. What would be the server configuration of DR site, would be same as primary or any other? Do we need to provide VPN, point-2-point connectivity with Application development vendor office and IBA office to access the server? Do we need to provide SSL VPN connectivity to application developer vendor to access the server remotely? What is application architecture? (2 tier OR 3 tier) Will the Application and Database be hosted on the separate Server? Only Shared Firewall is mentioned. Please confirm if dedicated firewall can be provided. Since shared firewall Disaster Recovery and Backup Server and Services for Dedicated IBA Web Server and Services with RPO and RTO of 2 hours will have to same as primary site This may be on the Cloud Services provided by the Bidder. VNC will be required for the day-to-day maintenance by our Web Developer Vendor. The Application Architecture may be 2/3 Tier. The Bidder will have to provide environment for both 2 Tier as well as 3- Tier Architecture. The Database Server, Application Server and Webserver will be hosted on the same server. Annexure-I, Part-I: TECHNICAL BID, Specifications for Dedicated IBA Web Server and Services, Sr. No.4. Firewall - Shared Web Application Firewall (WAF) - 3
has many limitations in terms of policy customization and impact to your business because of someone else s setup compromises. Annexure-I, Part-I: TECHNICAL BID, Specifications for Dedicated IBA Web Server and Services, Sr. No.4. Firewall - Shared Web Application Firewall (WAF) - Recommended IMPERVA shared services Shared Firewall with IPS, IDS monitoring, Recommended IMPERVA shared services The IMPERVA or ANY OTHER SHARED WEB APPLICATION FIREWALL (WAF) should have following features: The WAF should be able to understand the website with respect the changes in the flow of the website in real time and defend the website against Open Web Application Security Project (OWASP) 10 vulnerabilities. The WAF should be agentless with no additional software to be installed on the application or Web servers The WAF should get global threat feeds and learn about new attacks The WAF should be able to block traffic on sources geographic locations. The WAF should be able to integrate with Vulnerability Assessment scanners to block exploitation of the vulnerability identified by the VA Scanner. The WAF should he able to scale up as per the growth of IBA website. 4
Shared Firewall with IPS, IDS monitoring, - This has to be DEDICATED FIREWALL. What is the throughput and number of concurrent connections expected at Firewall? Enterprise Edition of Windows OS and MS SQL 2012 is mentioned? - This can be optimized to STD OR WEB edition of MS SQL if feature list is mentioned We have requested foe Bandwidth 250 GB data transfer 100 MBPS uplink. We have requested for Microsoft Windows Server 2012 Enterprise Edition - 64 bits Edition, IIS Webserver 8.0, Virtual Network Computing (VNC) and MS SQL 2012 Enterprise Edition 64 bits. The Bidder will have to provide the same. M/s. Reliance Communications Infrastructure Ltd. Clause 11.5 Clause 21 Please confirm if the insurance is to be taken only for the material hardware or for the IBA data also. If IBA data is to be insured, what would be the value. Please confirm if the DR should be in the same data center or in The Bidder will have to provide for the necessary Insurance. The Bidder will have to give the document explain the as how he will be meeting the RPO and RTO of 2 hours and how he will be doing and maintaining the data and application software back-ups. The DR Site will have to be at different geographical location. 5
Clause 21 Clause 21 Clause 21 different geographical location. What is the GB per month for backup Should the backup be taken both at DC and DR. For Data replication to the DR from DC, what would be the bandwidth required. The Bidder will have to give the document explain the as how he will be meeting the RPO and RTO of 2 hours and how he will be doing and maintaining the data and application software back-ups. The Bidder will have to give the document explain the as how he will be meeting the RPO and RTO of 2 hours and how he will be doing and maintaining the data and application software back-ups. The Bidder will have to give the document explain the as how he will be meeting the RPO and RTO of 2 hours and how he will be doing and maintaining the data and application software back-ups. Page 14. Technical bid. Server Page 14. Technical bid The 1TB storage can it be provided on shared storage instead of local disk. Since only the OS will be on the disk, can we provide RAID 5 instead of RAID 1 We have requested for Storage: 1 TB of RAID 5 Total Hard Disk Space for use of the Website. This can be on the server or exclusively on dedicated SAN. OS can be on RAID1 or RAID5 as per the configuration provided. 6
Page 14. Technical bid Please confirm why two IP's are required as one is sufficient. Page 14. Technical Can we provide Windows standard bid. perating version instead of enterprise edition system Page 14. Technical bid. Database Page 14. Technical bid. Firewall Can we provide Windows web edition instead of enterprise edition IMPERVA has many modules. Which module IBA wants. Annexure-I, Part-I: TECHNICAL BID, Specifications for Dedicated IBA Web Server and Services, Sr. No.4. Firewall - Shared Web Application Firewall (WAF) - Recommended IMPERVA shared services Shared Firewall with IPS, IDS We have requested for Ethernet - Dual Port Gigabit NIC, 2 IP Addresses. This should be provided. We have requested for Microsoft Windows Server 2012 Enterprise Edition - 64 bits Edition, IIS Webserver 8.0, Virtual Network Computing (VNC) and MS SQL 2012 Enterprise Edition 64 bits. The Bidder will have to provide the same. We have requested for Microsoft Windows Server 2012 Enterprise Edition - 64 bits Edition, IIS Webserver 8.0, Virtual Network Computing (VNC) and MS SQL 2012 Enterprise Edition 64 bits. The Bidder will have to provide the same. Annexure-I, Part-I: TECHNICAL BID, Specifications for Dedicated IBA Web Server and Services, Sr. No.4. Firewall - Shared Web Application Firewall (WAF) - Recommended IMPERVA shared services The IMPERVA or ANY OTHER SHARED WEB APPLICATION FIREWALL (WAF) should have following features: The WAF should be able to understand the website with respect 7
monitoring, the changes in the flow of the website in real time and defend the website against Open Web Application Security Project (OWASP) 10 vulnerabilities. The WAF should be agentless with no additional software to be installed on the application or Web servers The WAF should get global threat feeds and learn about new attacks The WAF should be able to block traffic on sources geographic locations. The WAF should be able to integrate with Vulnerability Assessment scanners to block exploitation of the vulnerability identified by the VA Scanner. The WAF should be able to scale up as per the growth of IBA website. Shared Firewall with IPS, IDS monitoring, - This has to be DEDICATED FIREWALL. Page 14. Technical bid. Bandwidth Please confirm if the data transfer is 250 GB is per month for internet. Pls confirm if any other connectivity is required. PLEASE NOTE THAT IT IS NOT PER MONTH. We have requested foe Bandwidth 250 GB data transfer 100 MBPS uplink. 8
Page 14. Technical bid. Bandwidth If the data transfer exceeds 250GB per month. Pls confirm if IBA will pay for the overage PLEASE NOTE THAT IT IS NOT PER MONTH. We have requested foe Bandwidth 250 GB data transfer 100 MBPS uplink. WEB WERKS India Pvt. Ltd. Do you require any control panel like Plesk on server? AT this stage no please. How much total back-up space you require, kindly also let us know back-up policy and retention period required? The Bidder will have to give the document explain the as how he will be meeting the RPO and RTO of 2 hours and how he will be doing and maintaining the data and application software back-ups. Should DR (disaster recovery) server be of same configuration as Primary Server is? In other words What server configuration/specification you are looking for Disaster recovery server. Disaster Recovery and Backup Server and Services for Dedicated IBA Web Server and Services with RPO and RTO of 2 hours will have to same as primary site This may be on the Cloud Services provided by the Bidder. Trimax IT Infrastructure & Services Limited Page 8, clause 9 The Bids shall be valid for a period of 180 days from the closing date for submission of the bid. It is recommended to reduce the bid validity to 60 days from the last date of submission. The Bidders will have to comply with all the Terms and Conditions given in the Tender Document. Page 9, clause 16.1 The IBA would like to have the It is requested to consider the below time The Bidders will have to comply with all the Terms and Conditions given in the 9
following time schedule for completion of the activities from the date of placement of orders. Delay in providing the Required Systems and Environment and going live of the IBA Website may invite penalties for the bidders. i. Providing the Required Systems and Environment : 5 weeks ii. Going live of the IBA Website : 1 week Page 11, clause 25.1 All payments shall be released directly by the IBA to the Bidder except as otherwise provided in the tender. All payments by the IBA will be effected in Indian Rupees. Subject to any deductions from the Contract price as per Contract, the Bidder shall be entitled to receive the Contract Price Quarterly at the end of the Quarter. Page 11, clause 27 In case IBA Website the down schedule: i. Providing the Required Systems and Environment : 8 weeks ii. Going live of the IBA Website : 2 week It is recommended to consider payment terms in Quarterly advance. In case IBA Website the down due to any failure Tender Document The Bidders will have to comply with all the Terms and Conditions given in the Tender Document The Bidders will have to comply with all the Terms and Conditions given in the 10
due to any failure of the systems and/or environment, the IBA Website should be live within 2 hours from the Bidder s Disaster Recovery bank Backup Site with the RPO and RTO of 2 hours. In case bidder fails to meet the above standards of maintenance, there will be a penalty of Rs.10,000 per day. IBA may also consider termination of the Contract as per provisions of termination clause mentioned in the contract Page 11, clause 28 If the bidder fails to deliver contracted product(s), install/activate, and operationalise all of the equipments or fails to complete the work or does not perform the service(s) within the time schedule stipulated in the Contract, IBA, without prejudice to its other remedies under the Contract, deduct from the Contract price, as liquidated damages, a sum equivalent to 0.5 percent of the total consideration of the systems and/or environment, the IBA Website should be live within 2 hours from the Bidder s Disaster Recovery bank Backup Site with the RPO and RTO of 2 hours. In case bidder fails to meet the above standards of maintenance, there will be a penalty of Rs.2,000 per day. It is recommended to consider liquidated damages @ a sum equivalent to 0.25 percent of the total consideration amount for each and every calendar day of delay, subject to a maximum limit of 2 percent of the total contract price. Tender Document The Bidders will have to comply with all the Terms and Conditions given in the Tender Document 11
amount for each and every calendar day of delay, subject to a maximum limit of 5 percent of the total contract price. Such penalty will be deducted from the bills of the bidder OR from the Security Deposit. IBA may also consider termination of the Contract as per provisions of termination clause mentioned in the contract. Page 26, Annexure V Datacenter where the Disaster Recovery and Backup Server and Services for Dedicated IBA Web Server and Services with RPO and RTO of 2 hours will be provided Page 15, Annexure 1 Disaster Recovery and Backup Server and Services for Dedicated IBA Web Server and Services with RPO and RTO of 2 hours This may be on the Cloud Services provided by the Bidder. Please confirm if the Disaster Recovery Datacenter is required to be at a different seismic / location than that of Primary Datacenter It is recommended to have different RPO & RTO times. For an RPO of 1 hour, RTO could be 2 hour. Kindly confirm. The DR Site will have to be at different geographical location. Disaster Recovery and Backup Server and Services for Dedicated IBA Web Server and Services with RPO and RTO of 2 hours 12
Page 14, Annexure 1 Operating System Microsoft Windows Server 2012 Enterprise Edition - 64 bits Edition, IIS Webserver 8.0, Virtual Network Computing (VNC). As per Microsoft Licensing Policy, Windows Enterprise Edition 2012 is not currently available. Microsoft provides Windows Server 2012 OS in two editions - Standard & Datacenter. Kindly confirm if Windows Standard OS can be provided on the servers We have requested for Microsoft Windows Server 2012 Enterprise Edition - 64 bits Edition, IIS Webserver 8.0, Virtual Network Computing (VNC) and MS SQL 2012 Enterprise Edition 64 bits. The Bidder will have to provide the same. Page 14, Annexure 1 Bandwidth 250 GB data transfer 100 MBPS uplink Page 14, Annexure 1 1 TB of RAID 5 Total Hard Disk As per our understanding, the required bandwidth is for accessing the complete setup at Primary Site & DR site. Separate secure bandwidth needs to be considered for replication of data from Primary to DR site. Kindly confirm. As per our understanding, the total The Bandwidth 250 GB data transfer 100 MBPS uplink is for accessing the Website. The necessary bandwidth required between Primary and Disaster Recovery Site for meeting the RPO and RTO of 2 hours is to be provided by the bidder. In case additional Storage is required, it will be negotiated at appropriate time. 13
M/s Ricoh India Ltd. Space for use of the Website data size will not increase beyond 1 TB for storage & backup in the contract duration of 5 years. Kindly confirm. Also request you to share incremental data size per day / per month Need of Load Balancers? Is SSL Certification also required What would be the rate of data growth. Brand of Firewall, Servers The necessary bandwidth required between Primary and Disaster Recovery Site for meeting the RPO and RTO of 2 hours is to be provided by the bidder. It may be overall infrastructure of the Bidders Data Centres. Bidders may provide the details for the same. Yes. We have requested for Storage: 1 TB of RAID 5 Total Hard Disk Space for use of the Website. We have given our requirements and functionality requirements. The Bidders will have to provide the Firewalls, Servers, etc., which meet the requirements. 14