Development of information technology security (cybersecurity) policy for Fiji D
Procurement Process
IC - Individual contractor
Office
UNCDF - FIJI
Deadline
17-Feb-25 @ 07:11 PM (New York time)
Published on
04-Feb-25 @ 12:00 AM (New York time)
Reference Number
UNCDF-00208
Contact
Raza ur Rehman Qamar - raza.qamar@uncdf.org
If you already have a supplier profile, please access the negotiation using quicklink or please login to the Supplier Portal, then search for the negotiation using the reference number UNCDF-00208, following the instructions in the user guide.
Introduction
Home-based with travels to Fiji
30 working days distributed over 3 months.
Description of the Assignment:
The consultant will undertake the following tasks but not limited to:
1. Assessment and review:
a. Conduct a comprehensive review of FDB’s IT infrastructure, cybersecurity governance, and operational processes to assess current capabilities and identify vulnerabilities.
b. Consult with internal stakeholders (e.g., department heads) and external partners (e.g., vendors, regulatory bodies) to understand cybersecurity risks and align with regulatory standards.
2. Policy development:
a. Create a tailored Cybersecurity Policy Document, focusing on governance, data protection, incident response, access control, cryptographic measures, staff competence, third-party risk management, and business continuity.
b. Develop specific protocols for secure operations and management of financial data, including access control and secure data handling, with emphasis on vulnerable sectors like agriculture.
3. Implementation guidance:
a. Develop Standard Operating Procedures (SOPs) based on a review of existing controls and workflows, defining roles, responsibilities, and secure handling practices.
b. Validate SOPs through stakeholder consultation and align them with internal and regulatory requirements. Develop an implementation roadmap for progressive cybersecurity improvements.
4. Training and capacity building:
a. Conduct a training needs assessment to identify knowledge gaps among staff.
b. Develop and conduct tailored training, including workshops and scenario-based exercises, to enhance staff skills in cybersecurity practices, data handling, and compliance. Follow up with evaluations and refresher sessions.
Proposal should be submitted directly in the portal no later than indicated deadline.
Any request for clarification must be sent in writing via messaging functionality in the portal. UNCDF will respond in writing including an explanation of the query without identifying the source of inquiry.
Please indicate whether you intend to submit a bid by creating a draft response without submitting directly in the system. This will enable the system to send notifications in case of amendments of the tender requirements. Should you require further clarifications, kindly communicate using the messaging functionality in the system. Offers must be submitted directly in the system following this link: http://supplier.quantum.partneragencies.org using the profile you may have in the portal. In case you have never registered before, you can register a profile using the registration link shared via the procurement notice and following the instructions in guides available in UNDP website: https://www.undp.org/procurement/business/resources-for-bidders. Do not create a new profile if you already have one. Use the forgotten password feature in case you do not remember the password or the username from previous registration.
Documents :
Negotiation Document(s) (Before Accessing other negotiations Document(s), please click on this link)Sustainable Procurement Indicators : | Economic - Whole life cycle cost |