IS4799 Information Systems and Cybersecurity Capstone Project Unit 1 Release of an RFP for Security Assessment Services © ITT Educational Services, Inc. All rights reserved. Learning Objective and Key Concepts Learning Objective Identify the objectives and detailed requirements of an information technology (IT) security services Request for Proposal (RFP) Key Concepts Format of an RFP document Responding to an RFP Skills and capability assessment RFP response project plan IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 2 EXPLORE: CONCEPTS IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 3 RFP Formal solicitation for proposals • “Send us quotes for products or services.” Useful to compare vendors • RFP standards level the playing field. Demonstrates equity • Helps to avoid favoritism • Allows multiple companies to compete for business Helps ensure competency • All vendors must meet standards. IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 4 RFP Key Concepts Applicability • Do the required products or services apply to your organization? • Is there a “good fit”? Competency • Can your organization provide requested products or services? • Is there any history of similar engagements? Response process • Do you understand the response process? • Can your organization respond in a manner consistent with the RFP? IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 5 RFP Key Concepts (Continued) Commitment to process • Authority • Resources Process management • Project management - Response activities - Fulfillment activities Documentation • Documentation standards • Access policies IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 6 RFP Sections Introduction Schedule of events Proposal requirements Vendor requirements Award criteria and process Appendices IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 7 RFP Introduction Statement of purpose Scope Compliance stipulations Communications Initial process IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 8 RFP Schedule Specifies important RFP milestones Provides initial target dates for response project Sets the pace of the response effort Helps organize activities IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 9 RFP Requirements Requirements to successfully fulfill the RFP Specifies required vendor action Sets the expectation for deliverables Provides evaluation criteria IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 10 Vendor Requirements Specifies prerequisites for vendors Defines minimum requirements to “play” Can indicate actions prior to submittal Coalitions can form to satisfy requirements IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 11 EXPLORE: PROCESS IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 12 Response Process Evaluate the RFP. Participate in interim meetings. Plan response activities. Satisfy vendor requirements. Propose solution to RFP requirements. Deliver proposal. IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 13 Award Process Client to receive proposals Possible clarification requests Evaluation Possible additional rounds Final award and announcement IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 14 EXPLORE: ROLES IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 15 Key Roles Client Representative Project Manager IT Manager IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 16 Key Roles (Continued) HR Manager General Management IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 17 EXPLORE: CONTEXT IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 18 Your Firm Security services provider In business since 1995 Started as database specialist Expanded to offer full security services IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 19 Requirements Evaluate RFP to determine: • Vendor requirements • Performance requirements IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 20 Requirements Gaps Any difference between: • What your firm can perform • What the RFP requires Gaps can be: • Vendor requirements gaps • Performance capability gaps Multiple ways to address gaps: • Outsource • Innovate • Upgrade • Cooperate IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 21 Additional Information Needed Missing RFP details Clarification information Alternate/substitute deliverables Any unclear or unknown issues IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 22 EXPLORE: RATIONALE IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 23 Next Step Question list • Produce a list of questions • Include items to address any missing information Bidder’s conference • Meeting of client and potential vendors • Opportunity to ask questions IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 24 Summary An RFP is a common mechanism to solicit proposals from multiple vendors. Responding to an RFP requires cooperation among several roles, including client representative, project manager, IT manager, HR manager, and general management. Responding to an RFP includes identifying vendor and performance requirements. A requirements gap is any difference between what your firm performs and what the RFP requires. After evaluation, you need to prepare a list of questions that include all missing information and clarifications. IS4799 Information Systems and Cybersecurity Capstone Project © ITT Educational Services, Inc. All rights reserved. Page 25