preview

IS4799 - Team RFP Response Report

Better Essays

IS4799 Information Systems And Cybersecurity Capstone Project.

1

Table of Contents
I.

Executive Summary
i.

II.

Layered Security Solution

Research
i.
ii.

III.

Review of Firm’s Qualifications
Review of Requirements and Clarification Questions

Data Analysis
i.

RFP Clarification Questions

ii.

RFP Technical Requirements and Differences from Existing Controls

iii.

Data Privacy Legal Requirements as per RFP’s Compliance

iv.

Security Assessment Project Plan Definition

v.

Risk Assessment Project Plan Definition

vi.

Risk Prioritization and Mitigation Project Plan Definition

vii.

Risk Mitigation Actions Based on Qualitative Risk Assessment’s Risk
Prioritization …show more content…



Cannot have any active managed security service provider contracts with any other agency in this state: We do no have any active contracts and are in the process of expanding our own business in the state of Georgia.

6

We can provide samples of previous reports for other clients that contain four of the five fields you requested:


Risk Assessment



Vulnerability Assessment



Penetration Testing



Business Continuity Plan/Disaster Recovery Plan (BCP/DRP)

SecureTECH has identified gaps in two areas that the state of Georgia’s minimum requirements request:


Must maintain at least one permanent office in this state: We are currently looking to expand our business but have not yet decided on the best location for our organization.



Provide previous reports for other clients for source code review:
SecureTECH does not have the means to assess source code security and does not employ development security specialists.

Data Analysis
RFP Clarification Questions
After reviewing the State of Georgia’s RFP for technology consulting services,
SecureTECH has identified the following questions:
1. The scope of the RFP states the State want a review of its entire system security program. How

Get Access