Information & Cyber Security Consultancy Service

Request for Proposal

 

 

Information & Cyber Security Consultancy Service

RFP LEB//21/04

 

FOR

 

DANISH REFUGEE COUNCIL (LEBANON)

 

The Danish Refugee Council assists refugees and internally displaced persons across the globe: we provide emergency aid, fight for their rights, and strengthen their opportunity for a brighter future. We work in conflict-affected areas, along the displacement routes, and in the countries where refugees settle. In cooperation with local communities, we strive for responsible and sustainable solutions. We work toward successful integration and whenever possible – for the fulfilment of the wish to return home.  

The Danish Refugee Council was founded in Denmark in 1956, and has since grown to become an international humanitarian organization with more than 7,000 staff and 8,000 volunteers. Our vision is a dignified life for all displaced. All of our efforts are based on our value compass: humanity, respect, independence and neutrality, participation, and honesty and transparency.

Operating since 2004 in Lebanon, DRC has addressed the needs and rights of vulnerable populations, working initially with Palestinian refugees (since 2004), Iraqi refugees (2007-2010), Lebanese IDPs (during the 2006 conflict), migrant domestic workers (since 2009) and, since 2011, responding to the Syrian refugee crisis.

DRC Lebanon is currently delivering programming in protection, basic assistance, livelihoods, and community development interventions. This myriad programming seeks to address the immediate needs of displaced populations and concurrently support vulnerable host populations. DRC has three offices spread throughout Lebanon in, Beirut, the Bekaa and North (Halba).  For further information about DRC, please refer to our website: https://drc.ngo/

 

Objectives:

Some of the Danish Refugee Council’s interventions are designed to improve protection and effectiveness of the humanitarian response in Lebanon by enhanced coordination through joint analysis, planning and response. DRC Lebanon has developed a beneficiary centric integrated system for three main sectors Protection, Economic Recovery, and MEAL along with humanitarian common platform to manage referrals between partners in Lebanon. The Referral Information Management System ”RIMS” has the capacity to generate two categories of valuable data that can be used to improve humanitarian response: 1) information on the effectiveness and timeliness of referral processes and 2) gaps in service provision across sectors. To that end, DRC will analyze aggregated information from RIMS partners to produce analysis on relevant trends and gaps. In relation to trends, for example, RIMS can support the identification of bottlenecks at each step of the referral process and DRC can present this data at inter-agency meetings to discuss potential ways to address them. Additionally, RIMS can support analysis of gaps, for example, by cross-referencing needed services against those actually received, and incorporating gender, age, nationality, time and sector variables into the analysis, DRC will have the capacity to capture relevant trends and gaps in service provision. In addition, RIMS has the capacity to link to other online platforms through API.

 

DRC is seeking to appoint an Information and cyber Security Consultant for the following:

The Information Security Consultant is responsible for assessing, analysing and ensuring proper management and protection of beneficiary data processed in DRC Lebanon through DRC’s Information Management Systems ALPHA and the Referral Information Management System “RIMS” in adherence to humanitarian and protection principles. Alpha and RIMS are both online systems hosted on the cloud. RIMS is being used by more than 90 organizations to manage and track internal and external referrals within and across sectors. Also, the information security consultant is responsible for drafting data protection SoPs, and finally he/she should answer audit questions, and advise on security improvements recommendation along with detailed written guidelines.

Responsibilities:

  • In consultation with Programme Managers, IT, IM,and the RIMS team, the consultant will develop, review and update -when necessary- security polices for both Alpha and RIMS including security of personal data, and sharing data with partners;
  • Tests the security of ASP.net published versions by DRC’s Information Management Consultant. The ASP.net published version is hosted on an UBUNTU server on Azure cloud services using Apache2 service.
  • Assesses the current server hosting plan, data storage and management of servers;
  • Assesses the functionalities and features of Alpha and RIMS related to data security driven from global systems such as CPIMS+ and GBVIMS+
  • Tests security vulnerabilities using different accredited tools in Alpha and RIMS to expose system’s shortcomings and flaws, and use the results to improve security and prepare for outside attacks on monthly basis. Additionally recommends good practices to keep IM Systems secure, produces monthly security snapshots, and quarterly full security reports.
  • Supports IM and IT teams in answering cyber security and security audit questions.
  • Provides DRC’s Lebanon IM Team with basic tools to test security vulnerabilities at application, server and database levels and creates procedures in case a data breach is detected;
  • Create data security checklist to gauge if essential practices are in place in programme(s), on how to process data and information in a secure manner;
  • Create backup and recovery plans for online systems and databases;
  • Recommends longterm plan and solution to keep the IM System secure.
  • Other duties as agreed with the Information Management Manger in line with objectives above and weekly work plans.

How to apply

RFP Issuing date: 29th of June 2021

RFP Closure Date: 13th of July 2021 at 14:00 (Beirut time)

Further RFP details are found attached in Annex C_ ToR.

Interested individuals / firms can request the full RFP documents from the below email address: (Kindly read carefully the RFP requirements in the ToR and Cover Letter)

[email protected]

منتهية الصلاحية
آخر مدة للتقديم
الثلاثاء, 13. يوليو 2021
نوع الدعوة
دعوة لتقديم مقترحات
قطاع(ات) التدخل:
اللاجئين