Public tender launched for IT software maintenance

Parliament allocates €116,000 for cyber risk monitoring and management

 (Foto: Skupština Crne Gore)
(Foto: Skupština Crne Gore)

The Parliament of Montenegro has launched a public tender worth €116,000, including VAT, for digital and cybersecurity services.

According to the technical specifications published on the Montenegro Electronic Public Procurement Portal, the subject of the procurement is a comprehensive service for monitoring, assessing and managing cyber risks, which, in addition to automated scanning, includes validation of findings, monitoring of DNS infrastructure, gathering threat intelligence and centralized reporting.

The aim of the procurement is for Parliament to obtain a unified overview of its digital assets and level of exposure to cyber risks, including domains, subdomains, IP addresses, network services, web applications, digital certificates, DNS records, cloud resources, publicly accessible and internal systems covered by the approved testing scope, as well as other relevant digital entities.

The service should also enable the detection of unknown, forgotten or unauthorized assets, such as testing environments, legacy subdomains, outdated applications and misconfigured services that are not recorded in official internal records but may represent a security risk.

Automated and manual testing

The procurement covers external scanning of publicly accessible resources, as well as internal scanning of systems that are included in the approved scope. The results of both types of scanning should be consolidated into a single risk overview.

The bidder will be required to conduct manual external testing of publicly accessible systems, services, applications, domains and subdomains, as well as the internal infrastructure within the scope approved by the contracting authority.

As stated in the documentation, the testing should cover vulnerabilities and weaknesses that cannot be reliably identified solely through automated tools, including configuration errors, weaknesses in access controls, logical vulnerabilities, deficiencies in authentication and authorization, the possibility of privilege escalation, exposure of sensitive information, and the possibility of combining multiple vulnerabilities into more complex attack vectors.

Manual testing should be carried out by qualified cybersecurity experts in order to verify whether the identified vulnerabilities are actually exploitable, determine their actual level of risk and provide concrete recommendations for their remediation.

In addition, manual validation of the results of automated scanning is also required. This entails verifying the accuracy of findings, identifying false positives, confirming actual exposure, assessing exploitability and considering the technical and business context of the affected resource.

According to the tender documentation, Parliament does not want a service that relies exclusively on automated results, but rather an expert analysis that will demonstrate the actual level of risk to the institution.

DNS, threats and compromised data

One of the requirements is continuous monitoring of DNS infrastructure. This includes identifying domains and subdomains associated with Parliament, monitoring changes to DNS records, detecting potentially unauthorized or abandoned subdomains, as well as identifying misconfigurations and other risks that could lead to domain abuse, phishing campaigns or subdomain takeover.

The service should also collect and correlate information on cyber threats from multiple sources. This includes indicators of compromise, information about active campaigns, known malicious infrastructure, exploitation of vulnerabilities, the reputation of IP addresses and domains, as well as other technical indicators associated with the institution’s infrastructure.

The tender specifications also provide for monitoring publicly available and potentially compromised data relating to the contracting authority, including information from threat-intelligence sources and the dark web.

All data should be consolidated into a single platform, that is, a web application, which will enable an overview of digital assets, vulnerabilities, threats, scanning and penetration-testing results, as well as recommended measures for addressing identified problems.

Priorities based on actual risk

One of the key requirements is that findings should not be ranked solely according to the technical severity of a vulnerability, but according to the actual risk to the institution.

When determining priorities, consideration should be given, among other things, to whether the resource is publicly accessible, whether it is connected to a critical domain or service, whether known methods of exploitation exist, whether the vulnerability is actively being used in attacks, whether the finding has been manually confirmed and whether its exploitability has been demonstrated through penetration testing.

The assessment should also take into account connections to compromised data, as well as possible reputational, regulatory and operational consequences.

The platform should enable the display of interdependencies between domains, subdomains, IP addresses, services, certificates, vulnerabilities, threats, compromised data and penetration-testing findings. A single risk assessment should also be provided for each asset, organizational unit, domain, IP range or type of exposure.

For critical and high-risk findings, it should be possible to display the reason why they have been marked as priorities, the affected resource, possible attack vector, relevant threat indicators, known methods of exploitation, information on whether the finding has been manually verified, as well as concrete steps for reducing the risk.

The platform should also enable monitoring of changes in risk over time, including trends in the attack surface, the number of critical findings, the time required to remediate them, the recurrence of previously identified problems and overall progress in reducing cyber exposure.

Up to 1,000 devices on the internal network

According to the documentation, Parliament’s information system includes up to 1,000 devices within its internal network infrastructure and up to 200 devices accessible externally.

The procurement is divided into two phases.

The first is the implementation of the service, which may last no more than three months from the signing of the contract, or from the official commencement of the bidder’s engagement, if so provided for in the contract.

- The implementation phase includes preparation, configuration, definition and validation of the monitoring scope, configuration of user accounts and assignment of roles, initial discovery and mapping of digital assets, establishment of a process for monitoring DNS records, conducting the initial scan, carrying out initial manual internal and external penetration testing within the approved scope, manual validation of identified findings, preparation of the initial report and conducting training for the contracting authority’s users - the tender documentation states.

The second phase is the operational use of the service, lasting six months. This period begins only after implementation has been completed and the contracting authority has confirmed that the service has been successfully put into operation. The implementation period is not included in the six-month operational period.

During this period, the bidder should continuously monitor the client’s external cyber attack surface, detect new or unauthorized resources, conduct internal and external scanning, manually validate critical and high-risk findings, carry out additional penetration testing where necessary, monitor DNS infrastructure and publicly available or compromised data, consolidate findings and notify the institution of critical risks.

- The service must be delivered through an integrated platform and a single web application that provides an overview, reporting and control of all services provided - the documentation states.

Monthly reports and urgent notifications

The supplier is required to provide expert technical support during the implementation and operational periods, including assistance with using the service, interpreting findings, adjusting the scope, manual validation and remediation recommendations.

During the operational phase, at least monthly reports are required, as well as ad hoc notifications when critical findings or significant changes to the institution’s external attack surface are identified.

Monthly reports should include an overview of identified assets, newly discovered findings, critical and high-risk risks, changes compared with the previous period, DNS monitoring results, automated internal and external scanning, manual penetration-testing and validation results, the status of open and closed findings, remediation recommendations and an executive summary for management.

At the end of the contracted period, the supplier is required to submit a final report containing an overview of the activities carried out, trends, main risks, remediation status, remaining open findings and recommendations for further improvement of cybersecurity.

Access control and training

The service must enable the administration of users, user roles and access privileges, applying the principle of least privilege. This means that different user groups should have levels of access to data and functions corresponding to their roles.

The supplier is required to provide training for Parliament’s administrators and end users, as well as technical support, maintenance and updates to the service throughout the duration of the contract.

No favoritism

The documentation specifically states that all requirements are defined as minimum functional, security and operational characteristics of the service.

- The supplier may propose any equivalent solution for providing the service that meets the required functionalities, service-level agreements, security requirements, support requirements, manual-validation requirements, penetration-testing requirements and reporting obligations, regardless of the manufacturer, platform name, implementation technology or commercial delivery model - the tender states.

The technical specifications, as stated, do not refer to specific manufacturers, platforms, modules, commercial packages, proprietary functionalities, user-interface designs or specific marketing terminology that could restrict competition.

The tender is open until 1 October, when the bids will also be opened.

T. K. 

Programska šema

15:00 15:05
INFOINFORMATIVA
15:05 16:00
MINI 24 SATAEMISIJA
16:00 17:00
E - MISIJAEMISIJA
17:00 19:00
UKRŠTENE RIJEČIEMISIJA
19:00 20:00
24 SATAINFORMATIVA
20:00 21:00
PRO ET CONTRAEMISIJA

PRATITE TVe UŽIVO

Obavještenje: Zbog zaštite autorskih prava, u odredjenim terminima live stream neće biti dostupan.