Aucun total exigé.
Le présent marché est assujetti à l'Accord des marchés publics de
l'Organisation mondiale du commerce.
Le présent marché est assujetti à l'Accord de libre-échange canadien, à l'Entente sur les Marchés Publics de l'Atlantique et à l'Accord de Libéralisation des Marchés Publics du Québec et du Nouveau-Brunswick.
Le présent marché est assujetti à l'Entente sur les Marchés Publics de l'Atlantique. Les fournisseurs sont priés de lire attentivement le document portant sur les conditions générales normalisées des provinces de l'Atlantique pour les marchés de biens et services avant de faire une soumission.
*****Amendment #5*****
This tender has been amended to address the following vendor questions. All other information remains the same.
Q1. Section 7.2.2 "Company Approach" of the RFP lists four (4) requirements (approach to project management, quality of deliverables, risk management, CEC+), none of which specify a requirement for the proponent's management consulting methodology/approach used to develop the business model, operating model, etc. Does CyberNB require end product approach information as part of the RFP response, or does it only require approach information related to those four requirements (project management,
quality of deliverables, risk management and CEC+)?
R1. We only require the information related to the four requirements. Information on your approach to the project can be included but it will not scored in evaluation.
Note the Section 7.3.5 Project Team References where project approach for previous projects is reviewed.
Q2. To ensure we build an appropriate team with the appropriate roles and skill levels, what is the scope of work to be delegated to another vender under separate contract for engaging stakeholders? For example, will this vendor be responsible for engaging (i.e., communicating with) stakeholders for the scheduling of workshops to be conducted by our team? And, given the RFP profile, what are the categories/types of stakeholders (e.g., provincial government, federal government, municipal
government, academia, private sector businesses) for which this vendor will be responsible for engaging?
R2. The Vendor responsible for engaging and communicating with the stakeholders is aimed at the wider ecosystem rather than the specific project team organizations. They will organize workshops for fostering collaboration and transformation that will include the direct project partners. They will not be responsible for scheduling the workshops to be conducted by the RFP vendor's team. As apart of the wider project team it is expected that the two teams will work together to achieve project
*****Amendment #4*****
This tender has been amended to address the following vendor questions. All other information remains the same.
Q1. At the bottom of section 6.5 in the RFP document, there is a statement indicating that "Stakeholder Engagement will be under another contract". Are additional details available regarding this statement?
For example, stakeholder engagement will be an important component of developing some of the key project deliverables such as the CI-SOC business model (consideration for partners, suppliers etc.), the future operating model and the organization structure (from a partners and peers perspective), so the timing of and availability of the stakeholder engagement partner will be material to the execution of this work . Will the stakeholder engagement proponent be named before the awarding of this
contract? It is expected that the winning proponent help select the stakeholder engagement partner? etc.
R1. No the winning proponent will not help select the Stakeholder Engagement Partner - this will be done by CyberNB before the final award of the contract.
Q2. Intellectual Property
The RFP section 6.2 and Amendment 1 Answer 2 suggested that all new Intellectual Property will be owned by CyberNB and shared across a community of "project partners and participants". Vendors may leverage proprietary techniques, methodologies and frameworks (respondent Intellectual Property) as part of the engagement. Most new or developed IP arising under an IT consulting contract will by its nature be supplemental, or constitute a derivative of, the vendor's existing IP rights. In order to
protect the vendor's ability to continue providing such services in the course of its business, vendors must retain the ownership of the derivatives, enhancements, modifications, etc. to existing IP and any new IP created by the vendor during the performance of the work. Granting IP ownership to Cyber NB under the contract (other than copyright on document deliverables) is likely problematic for many vendors. Could CyberNB please provide further explanation as requested below:
- Who the project partners and participants are? Are they limited to the public sector? Will they be bound to confidentiality?
- Will project partners and participants be able to commercialize the new IP in developing new products and services or is the development of such new products and services limited to their internal purposes?
- Is the ownership of new IP (ie. methodologies, tools, techniques, etc.) a mandatory requirement or does CyberNB reserve the right to negotiate appropriate IP rights with the selected vendor?
R2.The project partners are not limited to public sector. Yes they will be bound by confidentiality.
The project partners and participants will be able to commercialize the new IP in developing new products and services.
The IP ownership will be open to negotiation, we are well aware of the issues of background IP.
Note: typically in a Public Sector Project any specified deliverables developed are owned by the public sector body who paid for the services of their creation.
Q3. Travel
Section 6.6 states that the Vendor is responsible to pay for travel costs to and from Fredericton, while section 7.3 states that pricing must be inclusive of out-of-pocket expenses (which we would understand to include travel expenses).
- Respondents may bring in resources from out-of-province or out-of-country. Is it the expectation that costs associated with travel to Fredericton from their work or home out-of-province/out-of-country are to be excluded from the proposed pricing information?
- Will the clauses on travel expenses from section 6.6 take priority over section 7.3?
- Should the quoted per diem rate include out-of-pocket expenses or will these expenses be incurred separately and reimbursed in accordance with the government's policy?
- Could a copy of the applicable expense reimbursement policy be provided to proponents so that they may familiarize themselves with any applicable limitations?
Will vendors also be responsible for travel costs to locations outside Fredericton for the purpose referred to in section 6.6: "Vendor project team may travel throughout the province to meet with key project stakeholders in person."?
R3. Vendors must include all travel and out-of-pocket costs as part of their Per Diem rates for the proposed resources. Should the successful vendor be asked to travel to other areas of the Province, meals and mileage will be reimbursed at standard GNB rates. See new attachment titled GNB Travel Allowances for full details. Note: It is unlikely that there will be province travel beyond the Fredericton area.
Q4. Section 4.3 : This section seems to indicate that the deliveries must be made by hand (4 copies). Alternatively, could the proposal be sent via email to the procurement office?
R4. Electronic bidding is not available for this tender. Hard copies of the proposals are to be delivered to the address listed in the RFP.
Q5. Section 6.1: "The CI-SOC project will create the first "proof of concept" integrated security operations centre that will protect New Brunswick's critical infrastructure, coordinating..." Is the long-term goal to offer the services to all Canadian critical infrastructure, or to limit it to New Brunswick?
R5. The initial objective is to develop a capability to improve the integration of different SOC's to significantly improve Critical Infrastructure Protection in New Brunswick. The potential for exporting the services is one for the commerical CI-SOC partners to take.
Q6. Section 6.5: Our understanding from the scope of work is that there is an existing SOC/NOC and the aim of the services listed in Section 6.5 is to provide guidance to transform the existing infrastructure and related governance to a CI-SOC that will meet CyberNB's strategic objectives, i.e., the successful bidder will not be expected to install/configure equipment and monitor systems. Is our understanding correct? If not, please clarify.
R6. The CI-SOC space will contain three existing SOC functions from different industries, the objective is to develop new ways of working and new protocols for sharing information across SOC's to significantly improve the security for Critical Infrastructure. The successful bidder is not expected to install and configure equipment and monitor systems. There may be work to integrate different vendor tools to provide better intelligence and information for the integrated SOC.
*****Amendment #3*****
This tender has been amended to extend the closing date to November 13, 2018. Proponents are asked to disregard Question #1 of Amendment #2. All other information remains the same.
*****Amendment #2*****
This tender has been amended to address the following vendor question. All other information remains the same.
Q1. We would like to request an extension of the due date of RFP # 3959030-19 to Tuesday November 13 @ 13:30 PM (Atlantic).
R1. Unfortunately, due to the timing of this project, an extension will not be granted and the closing date remains November 5, 2018.
Q2. In section 6.4 of the RFP document, CEC+ certification is listed as a "Must" requirement for all proponents and supply chain partners (either at time of bidding or within 12 weeks of an awarded contract). My question is whether or not ISO 27001 certification would be considered an acceptable substitution for CEC+ certification?
R2. No, ISO 27001 is not considered a suitable substitute. CEC+ certification can be restricted to the office where the team are being provided from. If a vendor has ISO 27001 and all sites follow the controls then achieving CEC+ should be fairly simple.
*****Amendment #1*****
This tender has been amended to upload an attachment titled "Amendment #1" which addresses questions from the Vendor Meeting that took place on October 15, 2018. All other information remains the same.
