GB-London: CON-21-129 Priority Asset Management

A Contract Award Notice
by FINANCIAL CONDUCT AUTHORITY

Source
Contracts Finder
Type
Contract (Services)
Duration
2 year
Value
£37K
Sector
TECHNOLOGY
Published
05 Sep 2022
Delivery
01 Sep 2022 to 31 Aug 2024
Deadline
22 Nov 2021 00:00

Concepts

Location

Geochart for 1 buyers and 1 suppliers

1 buyer

1 supplier

Description

A Privileged Access Management (PAM) Solution that will include contracting with a 3rd party to initially procure their PAM tool and start onboarding some Pilot systems before rollout across the in-scope systems in the organisation. Our IT administrators have complete control over the systems they control and can access large volumes of data, possibly sensitive or insider information. Many are not FCA employees. A large proportion are offshore employees of our suppliers. We place a very high degree of trust in them. Whilst we vet them, this is an imperfect control. Administrator accounts are increasingly being hacked into and used to spread disruptive ransomware within organisations. We have seen examples of high-value bribes being offered to IT administrators by organised criminal gangs. The FCA currently has inadequate controls for privileged access to our systems. Although a range of manual mitigation actions are underway, best practice indicates that managing privileged access, given the evolving threat landscape, is not possible without a specialised PAM tool. It is anticipated that the solution will introduce best practices and more granular control of how IT administrators access FCA systems. It is also expected that the solution will assist in mitigating the identified corporate risks of unauthorised access and the abuse of such access.

Award Detail

1 Softcat (Marlow)
  • Value: £37,330

CPV Codes

  • 48900000 - Miscellaneous software package and computer systems

Other Information

Awarded via G-Cloud 12 Framework Please follow this link to view the notice https://www.delta-esourcing.com/delta/respondToList.html?noticeId=718696329

Reference

Domains