Romania - Bucharest: Computer testing services

Release

ID
ocds-pyfy63:2021-287252:2021-287252
Date
2021-06-08
Language
RO
Tags
tender

Release in JSON

Tender

Title
Romania - Bucharest: Computer testing services
Award criteria
ratedCriteria
Award criteria details
The most economic tender

Award criteria for item 1:
- Price (40)
- Quality: Evaluation subfactor name: 1. Qualification and professional experience of the staff designated for the performance of the contract (proposed key experts) for carrying out the activities under the Contract 2. The degree of knowledge and understanding of the object of the contract 3. Planning specific tasks 4. Quality assurance plan 5. The degree of adequacy of the implementation plan (60)

Award criteria for item 2:
- Price (40)
- Quality: Evaluation subfactor name: 1. Qualification and professional experience of the staff designated for the performance of the contract (proposed key experts) for carrying out the activities under the Contract 2. The degree of knowledge and understanding of the object of the contract 3. Planning specific tasks 4. Quality assurance plan 5. The degree of adequacy of the implementation plan (60)

Award criteria for item 3:
- Price (40)
- Quality: Evaluation subfactor name: 1. Qualification and professional experience of the staff designated for the performance of the contract (proposed key experts) for carrying out the activities under Contract 2. The degree of knowledge and understanding of the object of the contract 3. Planning specific tasks 4. Quality assurance plan 5. The degree of adequacy of the implementation plan (60)
Award period
2021-07-12 - ?
Eligibility criteria
Suitability:

The DUAE completed with reference data / information in relation to the provisions of art. 164 of Law no. 98/2016.DUAE will be presented for each entity participating in the award procedure, respectively Tenderer, associate, subcontractor or third party supporter.The supporting documents proving the fulfillment of those assumed by completing the DUAE are to be presented at the contracting authority's request, only by the Tenderers ranked on the first 5 places in the intermediate ranking drawn up at the end of the evaluation of the tenders. Documents that may be requested:— criminal record for the Tenderer and for the persons who are members of the administrative, management or supervisory body of the respective Tenderer or have the power of representation, decision or control within it, as it results from the ascertaining certificate issued by ONRC / act constitutive.For foreign tenderers, any document considered edifying in the country of origin or in the country where it is established is accepted, such as declarations on their own responsibility, certificates, criminal records or other equivalent documents issued by the competent authorities of that country, accompanied by an authorized translation. in Romanian.Requirement no. 2Reasons related to the payment of taxes and social security contributionsThe manner of fulfillment and the applicability within the procedureThe DUAE completed with reference data / information in relation to the provisions of art. 165 of Law no. 98/2016.DUAE will be presented for each entity participating in the award procedure, respectively tenderer, associate, subcontractor, or third party supporter.The supporting documents proving the fulfillment of those assumed by completing the DUAE are to be presented at the contracting authority's request, only by the Tenderers ranked on the first 5 places in the intermediate ranking drawn up at the end of the evaluation of the tenders. Documents that may be requested:— fiscal attestation certificates regarding the payment of taxes, fees or contributions to the general consolidated budget, etc. so as to show the lack of outstanding debts at the date of presentation of the documents,— documents proving that the economic operator can benefit from the derogations provided in art. 166 para. (2), art. 167 para. (2), art. 171 of Law no. 98/2016 (if applicable).For foreign Tenderers, any document considered edifying in the country of origin or in the country where it is established is accepted, such as declarations on their own responsibility, certificates, criminal records or other equivalent documents issued by the competent authorities of that country, accompanied by an authorized translation. in Romanian.Requirement no. 3Reasons related to insolvency, conflicts of interest or professional misconduct.The manner of fulfillment and the applicability within the procedureThe DUAE (Part III - Reasons for exclusion) completed with reference data / information in relation to the provisions of art. 167 of Law no. 98/2016. DUAE will be presented for each entity participating in the award procedure, respectively tenderer, associate, subcontractor or third party supporter.The supporting documents proving the fulfillment of those assumed by completing the DUAE are to be presented, at the request of the contracting authority, only by the Tenderers ranked on the first 5 places in the intermediate ranking drawn up at the end of the evaluation of the tenders:— for the Romanian economic operator - ascertaining certificate issued by the Trade Register Office attached to the competent territorial Tribunal.From the ascertaining certificate / register extract presented it must result:a) the condition of the tenderer;b) the persons representing the tenderer in the relationship with third parties.The information contained in this document must be real / current at the date of submission.Itcano prove the capacity to exercise the professional activity by presenting the ascertaining certificate issued by ONRC in electronic form, signed with the extended electronic signature.— for a foreign economic operator: the tenderer will present edifying documents, translated into Romanian by an authorized translator, real / current at the date of presentation, proving a form of registration as a natural / legal person or registration / attestation or belonging from the point from a professional point of view and in which to mention the persons representing the entity in relations with third parties, in accordance with the legal provisions of the country in which the Tenderer is resident. Also, the submitted documents must include information on the status of the Tenderer.NOTE: The supporting documents will be presented for each entity participating in the award procedure, respectively tenderer, associate, subcontractor or third party supporter.The persons with decision-making positions within the contracting authority, regarding the organization, development and completion of the award procedure are:National Bank of Romania Board of Directors:• Governor - Mugur Isarescu• First Deputy Governor - Florin Georgescu• Deputy Governor - Eugen Nicolaescu• Deputy Governor - Leonardo Badea• Member - Csaba Bálint• Member - Cristian Popa• Member - Dan Radu Rușanu• Member - Gheorghe Gherghina• Member - Virgiliu StoenescuManagement of the Procurement Department• Gabriela Preda - Director• Petre Augustin Dutu - Deputy DirectorManagement of the Budget and Financial Analysis Department• Ion Paduraru - Director• Gabriela Latea - Deputy DirectorManagement of the Accounting Department• Iulia Stanciu - Director• Daniela Ilie - Deputy DirectorManagement of the Legal Department• Alexandru Paunescu - DirectorManagement of the IT Services Department• Ovidiu Dragomir - Director• Tiberiu Parvulescu - Deputy DirectorInformation and formalities necessary for evaluating if the requirements are met:Information regarding the capacity to exercise the professional activityThe manner of fulfillment and the applicability within the procedureThe DUAE (Part IV A - Ability to comply with the requirements) supplemented with reference data / information in relation to the provisions of art. 173 of Law no. 98/2016.The supporting documents proving the fulfillment of those assumed by completing the DUAE are to be presented, at the request of the contracting authority, only by the Tenderers ranked on the first 5 places in the intermediate ranking drawn up at the end of the evaluation of the tenders:— for the Romanian economic operator - ascertaining certificate issued by the Trade Register Office attached to the competent territorial Tribunal.From the ascertaining certificate / register extract presented it must result:a) the main activity object and the secondary activity objects. The object of the contract must have a correspondent in the CAEN code from the Finding Certificate issued by ONRCb) the legal situation of the Tenderer and his condition;c) the persons representing the bidder in the relationship with third parties.The information contained in this document must be real / current at the date of submission.It can prove the capacity to exercise the professional activity by presenting the ascertaining certificate issued by ONRC in electronic form, signed with the extended electronic signature.— for a foreign economic operator: the tenderer will present edifying documents, translated into Romanian by an authorized translator, real / current at the date of presentation, proving a form of registration as a natural / legal person or registration / attestation or belonging from the point professionally and in which to mention the persons representing the entity in relations with third parties, in accordance with the legal provisions of the country in which the bidder is resident. Also, the submitted documents must contain information on the status of the bidder.NOTE: The supporting documents will be presented for each entity participating in the award procedure, respectively tenderer, associate, subcontractor or third party supporter.

Technical/professional eligibility:

Loturile: 1,2,3 For service contracts: performance of services of the specified type For each lot, the Tenderers will fill in the DUAE the following information: Lot 1: List of the main services performed during a period covering a maximum of 3 years, calculated from the deadline set for the submission of tenders, indicating the values, data, and public or private beneficiaries, certifying that the tenderer has provided services similar within a maximum of 3 contracts with object “Penetration test”, whose cumulative value to be at least equal to 494,000 RON without VAT (or equivalent to EUR at a rate of 4.94 Lei / EUR). Lot 2: List of the main services performed during a period covering a maximum of 3 years, calculated from the deadline set for the submission of tenders, indicating the values, data, and public or private beneficiaries, certifying that the tenderer has provided services similar within a maximum of 3 contracts with object “Threat intelligence-led red team tests”, whose cumulative value to be at least equal to 494,000 RON without VAT (or equivalent to EUR at a rate of 4.94 Lei / EUR). Lot 3: List of the main services performed during a period covering a maximum of 3 years, calculated from the deadline set for the submission of tenders, indicating the values, data, and public or private beneficiaries, certifying that the tenderer has provided services similar within a maximum of 3 contracts with object “Threat intelligence-led red team tests”, whose cumulative value to be at least equal to 494,000 RON without VAT (or equivalent to EUR at a rate of 4.94 Lei / EUR).Loturile: 1,2,3 Subcontracting proportion The tenderer must specify the part (s) of the contract which he intends to subcontract, the percentage of the contract corresponding to the activities to be carried out by the subcontractor, for each subcontractor, and the identification data of the subcontractors (at least name, legal form of organization and unique registration code).

Technical/professional minimum level:

The proving documents regarding the fulfillment of the qualification criteria will be requested, respectively the presentation of certificates / documents / recommendations / minutes of reception (dated and signed by the beneficiary) confirming the provision of similar requested services, in the indicated period, as well as any other documents. considered relevant in proving the fulfillment of the requirement by the economic operator.The DUAE Form will be completed with the reference data / information in relation to the provisions of art. 179 lit. k) of Law no. 98/2016. If tenderers subcontract parts of the contract, they shall submit with DUAE, the subcontracting agreement showing at least the information on the subcontractor and the identification data, the part (s) of the contract to be performed by the subcontractor and the actual manner whereby the subcontractor ensures the fulfillment of the assumed obligations. Tenderers are requested to indicate in their tenders the subcontractor / local subsidiary or other entity that could carry out the IT Security Assessment Services (current batch), for each participating institution that could adhere to the framework agreement. Tenderers will not have the right to introduce new subcontractors except with the agreement of the NBR, by presenting the contracts concluded between the contractor and the subcontractor / subcontractors, so that the activities and amounts / percentages related to services are included in the Framework Agreement. The introduction of a subcontractor must not lead to a change in the initial technical or financial proposal. In the case of subcontracting, the contractor will remain obliged to comply with its obligations towards the NBR and the participating Institutions under the framework agreement and will assume sole responsibility for the proper execution of the framework agreement. If it uses subcontractors / affiliates, the contractor guarantees that the subcontractors / affiliates are highly qualified and that the subcontractor / affiliate must provide services to the participating institutions at a very high quality level.
Main procurement category
services
Procurement method
open
Procurement method details
Open procedure

Participants: 5
Tender period
2021-06-08 - 2021-07-12
Value
600 000.00 EUR
Minimum value
600 000.00 EUR

Tender item

ID
ocds-pyfy63:2021-287252:obj:1
Classification
CPV / 72820000
Description
The IT infrastructure of the NBR (as well as that of the other participating institutions), as it is implemented at the time of the tests, available to both internal and external customers is within the purpose of these tests. The IT infrastructure contains the components required to operate and manage the IT environments.These components include hardware, software, networking components, an operating system (OS), and data storage, all of which are used to deliver IT services and solutions.The main objective is to identify the Participating Institution's cybersecurity risks and to take appropriate technical and organizational measures to minimize/mitigate those risks.More granular objectives are defined as follows:— Identify the external exposure in terms of surface attack and determine if the implemented security controls ensure appropriate protection against malicious actors,— Measure the level of responsiveness and capability to identify and react against a cyber-attack targeted to the weakness points,— Determine if the security policy and controls implemented within the internal IT infrastructure are strong enough to be able to identify an ongoing cyber-attack and to take measures to stop it,— Measure the effectiveness of the security awareness program by testing the user’s reaction to a social engineering cyber-attack,— Determine if the sensitive data is well protected against bad actors,— Being compliant with the regulatory requirements in terms of ensuring that the IT infrastructure offers a certain level of security protection.From the point of view of the TIBER - EU methodology:The tests will provide an overview of the existing vulnerabilities in employees, business processes, associated technology (applications and infrastructure) and will provide a detailed threat assessment that can be used to raise awareness of the current situation and the measures to be taken to address it, improve the situation and reduce the associated risks. These tests performed on the basis of the "Red / Blue / White Team" concept are an extended form of the classic concept of penetration testing which usually provides a detailed and useful assessment of technical and configuration vulnerabilities. In the end, the tests will follow a complete scenario for a targeted attack against the entire entity.

Tender item

ID
ocds-pyfy63:2021-287252:obj:2
Classification
CPV / 72820000
Description
The IT infrastructure of the NBR (as well as that of the other participating institutions), as it is implemented at the time of the tests, available to both internal and external customers is within the purpose of these tests. The IT infrastructure contains the components required to operate and manage the IT environments.These components include hardware, software, networking components, an operating system (OS), and data storage, all of which are used to deliver IT services and solutions.The main objective is to identify the Participating Institution's cybersecurity risks and to take appropriate technical and organizational measures to minimize/mitigate those risks.More granular objectives are defined as follows:— Identify the external exposure in terms of surface attack and determine if the implemented security controls ensure appropriate protection against malicious actors,— Measure the level of responsiveness and capability to identify and react against a cyber-attack targeted to the weakness points,— Determine if the security policy and controls implemented within the internal IT infrastructure are strong enough to be able to identify an ongoing cyber-attack and to take measures to stop it,— Measure the effectiveness of the security awareness program by testing the user’s reaction to a social engineering cyber-attack,— Determine if the sensitive data is well protected against bad actors,— Being compliant with the regulatory requirements in terms of ensuring that the IT infrastructure offers a certain level of security protection.Penetration tests are performed usually by following the stages defined below:• Pre-engagement Interactions;• Intelligence Gathering and Threat Modelling;• Vulnerability Identification and Analysis;• Exploitation;• Post Exploitation;• Reporting.

Tender item

ID
ocds-pyfy63:2021-287252:obj:3
Classification
CPV / 72820000
Description
The IT infrastructure of the NBR (as well as that of the other participating institutions), as it is implemented at the time of the tests, available to both internal and external customers is within the purpose of these tests. The IT infrastructure contains the components required to operate and manage the IT environments.These components include hardware, software, networking components, an operating system (OS), and data storage, all of which are used to deliver IT services and solutions.The main objective is to identify the Participating Institution's cybersecurity risks and to take appropriate technical and organizational measures to minimize/mitigate those risks.More granular objectives are defined as follows:— Identify the external exposure in terms of surface attack and determine if the implemented security controls ensure appropriate protection against malicious actors,— Measure the level of responsiveness and capability to identify and react against a cyber-attack targeted to the weakness points,— Determine if the security policy and controls implemented within the internal IT infrastructure are strong enough to be able to identify an ongoing cyber-attack and to take measures to stop it,— Measure the effectiveness of the security awareness program by testing the user’s reaction to a social engineering cyber-attack,— Determine if the sensitive data is well protected against bad actors,— Being compliant with the regulatory requirements in terms of ensuring that the IT infrastructure offers a certain level of security protection.From the point of view of the TIBER - EU methodology:The tests will provide an overview of the existing vulnerabilities in employees, business processes, associated technology (applications and infrastructure) and will provide a detailed threat assessment that can be used to raise awareness of the current situation and the measures to be taken to address it, improve the situation and reduce the associated risks. These tests performed on the basis of the "Red / Blue / White Team" concept are an extended form of the classic concept of penetration testing which usually provides a detailed and useful assessment of technical and configuration vulnerabilities. In the end, the tests will follow a complete scenario for a targeted attack against the entire entity.

Parties

Roles
buyer
Organization name
Banca Națională a României
Street address
Str. Doamnei nr. 8
Locality
Bucureşti
Postal code
030051
Country
RO
Contact name
Petre Tudor
E-mail
elena.ionescu@bnro.ro
Phone
+40 311323253
Fax
+40 213110162
Website
www.e-licitatie.ro

Organization data Organization in JSON