SOW Ransomware Protection Solution v1
SOW Ransomware Protection Solution v1
(SOW)
Sidra Medicine
Version: 1.0
Contents
1. INTRODUCTION/BACKGROUND...................................................................................................................3
2. OBJECTIVES..................................................................................................................................................3
3. SCOPE OF WORK..........................................................................................................................................3
3.1 Current Enterprise Data Backup Infrastructure:...................................................................................4
3.2 Technical Requirements.......................................................................................................................4
3.2.1 Ransomware Protection Solution Functional Requirements:.......................................................5
3.2.2 Solution Offerings Options:..........................................................................................................6
3.2.3 Ransomware Protection Solution Architecture:...........................................................................7
3.2.4 Data Backup Storage Requirements:............................................................................................8
3.2.5 Data Backup Retention Requirements:........................................................................................8
3.2.6 Ransomware Solution Deployment Scope Details:.......................................................................8
3.2.7 Deliverables:.................................................................................................................................9
3.3 Warranty..............................................................................................................................................9
3.4 Solution Knowledge Transfer & Training..............................................................................................9
3.5 Evaluation Criteria................................................................................................................................9
4. RESPONSE REQUIREMENTS......................................................................................................................9
4.1. Technical Response Requirements.......................................................................................................9
|
IT (I & O) Ransomware Protection Solution Procurement - SOW 2
|
IT (I & O) Ransomware Protection Solution Procurement - SOW 3
1. INTRODUCTION/BACKGROUND
Sidra Medicine (Sidra) is seeking to Procure Ransomware Protection Solution at Sidra Data Center
which will enhance the Current Backup Solution for more resiliency against ransomware protection
as stated in the Scope of Work (SOW). Ransomware attacks pose a significant threat to
organizations, leading to data loss, operational disruptions, and financial consequences. To mitigate
these risks, Sidra Medicine (Sidra) intends to implement a Ransomware Protection Solution that
utilizes backup software with features such as immutable backups and works on automated Air Gap
architecture. The solution will provide reliable data recovery capabilities while ensuring the
integrity and security of backed-up data.
Based on their expertise and capabilities of their Solution, the Vendors are invited to submit their
proposals based on (3) different Options meeting the functional requirements as described in the
SOW.
Sidra is seeking to purchase premium hardware, software and system supports for designated
equipment with an “aggressive” and committed pricing for selected systems as described in the
SOW.
2. OBJECTIVES
Sidra Medicine (Sidra) requires to Procure Ransomware Protection Solution for Sidra Data Center
with 4 Years of Support. The objective is to ensure robust protection against ransomware attacks
by leveraging secure backup practices.
Vendor is responsible for all acts, and services required providing Sidra with a fully functional
System in accordance with the Specifications as per the requirement mentioned in the section 3.
3. SCOPE OF WORK
This document details a Scope of Work (SOW) to Procure Ransomware Protection Solution which
will enhance the Current Backup Solution for more resiliency against ransomware protection.
Vendor shall provide the services necessary to accomplish all of the tasks and subtasks in this
Statement of Work (SOW) and to successfully Install, Configure, Test, and Implement all of the
solution components including, but not limited to, all associated software and/or firmware,
patches/fixes, and interfaces, post implementation support, technical and end‐user
training. Vendor is responsible for all acts, and services required providing Sidra with a fully
functional System in accordance with the Manufacturer’s Specifications.
|
IT (I & O) Ransomware Protection Solution Procurement - 3
SOW
3.1 Current Enterprise Data Backup Infrastructure:
The following are Technical Requirements of the desired Ransomware Protection Solution:
Performance – (Must be able to meet the current and future Ransomware Protection
needs)
Availability – requirements to prevent loss of data content and loss of access to data
required to achieve “6-9’s“(99.9999%) availability. Capability to recover from
catastrophic disasters.
Scalability – the solution must be easy to grow to address the increased demand of future
applications.
|
IT (I & O) Ransomware Protection Solution Procurement - 4
SOW
Cost – the cost of ownership needs to be reduced, including the cost of maintaining and
managing the system.
The Ransomware Protection Solution must ensure robust protection against ransomware attacks
by leveraging secure backup practices with the assumptions mentioned in the compliance matrix
- Schedule 1 – Tab 1.
|
IT (I & O) Ransomware Protection Solution Procurement - 5
SOW
3.2.2 Solution Offerings Options:
The Vendors are allowed to propose their Solution based on (3) different Options based on their
expertise and capabilities of their Solution meeting the functional requirements.
Vendors are required to mention clearly the Options they are proposing as part of their Tender
response.
OPTION-1:
Vendors should propose a Backup Solution with a single-site architecture that complements our
existing backup solution. This option requires the establishment of a secure Vault site for data
storage and recovery which ensures that the proposed vault site seamlessly integrates with our
current backup infrastructure, as per the below Solution Architecture mentioned in Figure 2:
Software requirements:
Hardware requirements:
OPTION-2:
Vendors proposing a comprehensive Backup Solution with a two-site architecture. This option is
for the vendors capable of designing a robust backup system across two separate physical locations
with Production site meeting the production backup requirements of Ransomware Solution and a
Recovery Vault Site to have resiliency against ransomware protection.
Software requirements:
Hardware requirements:
|
IT (I & O) Ransomware Protection Solution Procurement - 6
SOW
OPTION-3:
Vendors proposing a comprehensive Backup Solution within a Single-site. This option is for the
vendors capable of designing a robust backup system with a (2-Tier) Backup architecture within a
single physical hardware having Backup copies residing at the (Tier-1) Backup layer and moving
the copies later to (Tier-2) Protection layer within a virtual air-gap feature to have resiliency
against ransomware protection.
Software requirements:
Software only Vendors:- Vendors proposing this Option needs to submit their proposals
recommending Backup Storage Hardware Vendor as part of their solution offerings; even if
the Vendor is only providing the software.
Hardware requirements:
Vendor specific (OEM) Hardware which meets the solution functional requirements.
Hardware only Vendors:- Vendors proposing this Option needs to submit their proposal
recommending Backup Software Vendor as part of their solution offerings; even if the
Vendor is only providing the Hardware.
|
IT (I & O) Ransomware Protection Solution Procurement - 7
SOW
3.2.4 Data Backup Storage Requirements:
Workloads classification:
|
IT (I & O) Ransomware Protection Solution Procurement - 8
SOW
Conduct thorough testing of the integrated solution and provide comprehensive
documentation for configuration and ongoing maintenance.
Validate the Recovery Data.
Setup & Configure Dial Home/Connect Home for the Ransomware Solution for
remote monitoring.
Hardware Decommisioning:- Upon EOL of Hardware, Vendor to decommission the
Old Hardware from Data Center Rack, Un-plug the Copper/Fiber Cabling, and
perform Copper/Fiber clean-up from the Racks.
3.2.7 Deliverables:
3.3 Warranty
Sidra requires 48 months of premium (24x7) warranty/support.
4. RESPONSE REQUIREMENTS
4.1. Technical Response Requirements
Points to be addressed in the response, which will be closely examined by the Evaluation
committee, are:
|
IT (I & O) Ransomware Protection Solution Procurement - 10
SOW