IS4799 Information Systems and
Cybersecurity Capstone Project
Unit 1
Release of an RFP for Security
Assessment Services
© ITT Educational Services, Inc. All rights reserved.
Learning Objective and Key
Concepts
Learning Objective
 Identify the objectives and detailed requirements
of an information technology (IT) security services
Request for Proposal (RFP)
Key Concepts
 Format of an RFP document
 Responding to an RFP
 Skills and capability assessment
 RFP response project plan
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 2
EXPLORE: CONCEPTS
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 3
RFP
 Formal solicitation for proposals
• “Send us quotes for products or services.”
 Useful to compare vendors
• RFP standards level the playing field.
 Demonstrates equity
• Helps to avoid favoritism
• Allows multiple companies to compete for
business
 Helps ensure competency
• All vendors must meet standards.
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 4
RFP Key Concepts
 Applicability
• Do the required products or services apply to
your organization?
• Is there a “good fit”?
 Competency
• Can your organization provide requested
products or services?
• Is there any history of similar engagements?
 Response process
• Do you understand the response process?
• Can your organization respond in a manner
consistent with the RFP?
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 5
RFP Key Concepts (Continued)
 Commitment to process
• Authority
• Resources
 Process management
• Project management
- Response activities
- Fulfillment activities
 Documentation
• Documentation standards
• Access policies
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 6
RFP Sections
 Introduction
 Schedule of events
 Proposal requirements
 Vendor requirements
 Award criteria and process
 Appendices
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 7
RFP Introduction
 Statement of purpose
 Scope
 Compliance stipulations
 Communications
 Initial process
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 8
RFP Schedule
 Specifies important RFP milestones
 Provides initial target dates for response
project
 Sets the pace of the response effort
 Helps organize activities
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 9
RFP Requirements
 Requirements to successfully fulfill the RFP
 Specifies required vendor action
 Sets the expectation for deliverables
 Provides evaluation criteria
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 10
Vendor Requirements
 Specifies prerequisites for vendors
 Defines minimum requirements to “play”
 Can indicate actions prior to submittal
 Coalitions can form to satisfy requirements
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 11
EXPLORE: PROCESS
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 12
Response Process
 Evaluate the RFP.
 Participate in interim meetings.
 Plan response activities.
 Satisfy vendor requirements.
 Propose solution to RFP requirements.
 Deliver proposal.
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 13
Award Process
 Client to receive proposals
 Possible clarification requests
 Evaluation
 Possible additional rounds
 Final award and announcement
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 14
EXPLORE: ROLES
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 15
Key Roles
 Client Representative
 Project Manager
 IT Manager
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 16
Key Roles (Continued)
 HR Manager
 General Management
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 17
EXPLORE: CONTEXT
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 18
Your Firm
 Security services provider
 In business since 1995
 Started as database specialist
 Expanded to offer full security services
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 19
Requirements
 Evaluate RFP to determine:
• Vendor requirements
• Performance requirements
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 20
Requirements Gaps
 Any difference between:
• What your firm can perform
• What the RFP requires
 Gaps can be:
• Vendor requirements gaps
• Performance capability gaps
 Multiple ways to address gaps:
• Outsource
• Innovate
• Upgrade
• Cooperate
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 21
Additional Information Needed
 Missing RFP details
 Clarification information
 Alternate/substitute deliverables
 Any unclear or unknown issues
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 22
EXPLORE: RATIONALE
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 23
Next Step
 Question list
• Produce a list of questions
• Include items to address any missing
information
 Bidder’s conference
• Meeting of client and potential vendors
• Opportunity to ask questions
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 24
Summary
 An RFP is a common mechanism to solicit proposals from
multiple vendors.
 Responding to an RFP requires cooperation among
several roles, including client representative, project
manager, IT manager, HR manager, and general
management.
 Responding to an RFP includes identifying vendor and
performance requirements.
 A requirements gap is any difference between what your
firm performs and what the RFP requires.
 After evaluation, you need to prepare a list of questions
that include all missing information and clarifications.
IS4799 Information Systems and Cybersecurity Capstone Project
© ITT Educational Services, Inc. All rights reserved.
Page 25