The IETF Administration LLC is soliciting bids for Cybersecurity Testing 
Services.  

Overview:

The IETF Administration LLC is soliciting bids for a cybersecurity testing 
provider to act as our preferred provider until the end of 2027 and to deliver 
two initial projects. 

The work of the new provider will include:

Penetration testing.  We regard penetration testing as the gold standard for 
auditing operational IT systems and require regular penetration tests of our 
systems.

Code and repository reviews.  We operate at a very high level of transparency, 
with most of our code and configurations available in public repositories and 
licensed under open source licenses.

Design and architecture evaluation.  While less common, we are increasingly 
designing new systems from the ground-up and look to early review of the design 
and architecture.

The first initial project is the penetration testing and code review of 
Datatracker, the IETF’s public facing document and workflow management tool.

The second initial project is penetration testing and configuration review of 
the new IETF cloud infrastructure.

Timeline:
3 February  2025        RFP Issued
17 February 2025        Questions and Inquiries deadline
24 February 2025        Answers to questions issued and RFP updated if required
3 March 2025            Bids due
31 March 2025           Preferred bidder selected and negotiations begin
14 April 2025           Contract execution and work begins

Bids are due by 22:00 UTC on the day noted above.

Full details of the RFP, including instructions on how to submit a bid and how 
to ask questions, can be found at 
https://www.ietf.org/media/documents/IETF_RFP_for_Cybersecurity_Testing_Services.pdf.

Please note that in order to maintain a fair and transparent RFP process, all 
questions or feedback regarding this RFP should be made to the email address 
specified in the RFP.

-- 
Jay Daley
IETF Executive Director
[email protected]

_______________________________________________
IETF-Announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to