RequiredOEM Authorization Certificate Bid to RA enabled Yes VULNERABILITY MANAGEMENT/ASSESSMENT SOFTWARE (VERSION 2.0) ( 1 pieces ) Technical Specifications * As per GeM Category Specification Specification Specification Name Values Bid Requirement (Allowed Values) BASIC INFORMATION Category Software Software Scanner based on Software
RequiredVirtual appliance Software
RequiredVirtual appliance Scanner Deployment modes Standalone Active-Active
RequiredActive- Passive
RequiredStandalone Scanner Functioning Task peering Task peering Type of Centralized Software Software 1/8 Management Type of License Subscription Subscription Duration of Subscription in months (Hint Select zero if not applicable) 12 12.0 - 60.0 Or higher Type of IP Scanning OS
RequiredFirmware
RequiredAppliction
RequiredDatabase OS
RequiredFirmware
RequiredAppliction
RequiredDatabase Number of Licences for IP Scanning 100 1 - 25000 Name of Software Appliance - * Name of the OEM - * OEM Model/Part No - * Software/Appliance Description - * Software/Appliance Version & Date of Launch - * Installation and Demonstration No Yes
RequiredNo No of days Training Provided at Site from OEM 1 1 Number of Years upto which Support is available from OEM during the warranty period 1 1 OEM SUPPORT Features 1) 24 x 7 x 365 Support by respective OEM.
Required2) OEM office in India 1) 24 x 7 x 365 Support by respective OEM.
Required2) OEM office in India IPv6 support and scan by hostname/IP supported Yes Yes Capability of creating users in the offered product unlimited 10
Required50
Required100
Required200
Requiredunlimited Global Threat Intelligence support DBIR( Data Breach Investigations Report)
RequiredSANS TOP20 DBIR( Data Breach Investigations Report)
RequiredSANS TOP20 Agents Size in MB 30 1 - 100 APPLIANCE CAPACITY Hard disk capacity (in TB) (Hint :- Select '0' if not applicable) 0 0 - 100 RAM size (in GB) 0 0 - 10000 2/8 (Hint :- Select '0' if not applicable) Physical CPU core required 0 0 - 128 ASSET INVENTORY ASSET INVENTORY FEATURES 1. Actionable intelligence from ThreatIntel Sources.
Required5. Widgets to be color coded so that user can measure risk appetite.
Required6. Highlight and risk rank criticality of assets. 1. Actionable intelligence from ThreatIntel Sources.
Required5. Widgets to be color coded so that user can measure risk appetite.
Required6. Highlight and risk rank criticality of assets. Asset visibility Features 1.Provision for User to create assets inventory hierarchically like Site:- Data Centre Name
RequiredProject name
RequiredAssets Groups(IPs).
Required2. Continuous discovery of assets 1.Provision for User to create assets inventory hierarchically like Site:- Data Centre Name
RequiredProject name
RequiredAssets Groups(IPs).
Required2. Continuous discovery of assets GENRIC FEATURES of ASSET INVENTORY 1. Single Management Console with RBAC (Role Based Access Control) . User site project/asset group to be able handle scanning reporting quering
Requiredasset group creation and deletion independently.
Required2.Easy deployment.
Required3.Scalable and extendable.
Required4.Minimal impact on systems and networks.
Required5.Ability to handle virtualized environments and Complete coverage for Container host
Requiredimage and registry
Required8.Ability of Database queries to run against reporting data model
Requiredwithout using third-party tools
Requiredwithin the solution.
Required9.Scanning engine to be able to scan IPs simultaneously and the rest of the IP's asset scheduled for scanning (in any site) to be able to put in the scanning queue and 1. Single Management Console with RBAC (Role Based Access Control) . User site project/asset group to be able handle scanning reporting quering
Requiredasset group creation and deletion independently.
Required2.Easy deployment.
Required3.Scalable and extendable.
Required4.Minimal impact on systems and networks.
Required5.Ability to handle virtualized environments and Complete coverage for Container host
Requiredimage and registry
Required8.Ability of Database queries to run against reporting data model
Requiredwithout using third-party tools
Requiredwithin the solution.
Required9.Scanning engine to be able to scan IPs simultaneously and the rest of the IP's/asset scheduled for scanning (in any site) to be able to put in the scanning queue and run 3/8 run automatically.
Required11.S canner to be able to scan duplicate or overlapping IP ranges automatically.
Required11.Scanner to be able to scan duplicate or overlapping IP ranges Minimum volume of IP threat can be scanned simultaneously by each scan engine 10 10
Required20
Required50
Required75
Required100 Support for Container technology 4. NA 4. NA User to be able to handle Scanning
RequiredReporting
RequiredQu ery assets group creation
Requireddeletion Scanning
RequiredReporting
RequiredQuery assets group creation
Requireddeletion Sorting and Filtering Centralized Centralized Scanning and Vulnernability assessment data Fast
RequiredAccurate
RequiredActionabl e Fast
RequiredAccurate
RequiredActionable "Correlated list of features in Vulnerability Management " 1. Metasploit exploit modules available for each vulnerability
Required2. Malware kits available for each vulnerability 1. Metasploit exploit modules available for each vulnerability
Required2. Malware kits available for each vulnerability Capability of the software to calculate risk for each detected vulnerability including Risk scoring 1. CVSS scoring
Required2. Asset exploitability
Required3.S usceptibility to malware kits 1. CVSS scoring
Required2. Asset exploitability
Required3.Susceptibility to malware kits Prioritization capabilities with respect to vulnerabilities and remediation tasks Yes Yes
RequiredNo If yes
Requiredthen mention for available path/solution links/patch link(OEM recommended) - * VULNERABILITY MANAGEMENT Type of detection 2.Agentless detection 1.Agent-based detection
Required2.Agentless detection
Required3.Agent- based detection (On- Premises)
Required4. Agent Support Windows (all client and server versions)
Required5. Agent Supprt Linux and Unix
Required6. Agent Support Mac OS
Required7. Agent Support AIX 4/8 VULNERABILITY MANAGEMENT FEATURES 1. Configurable monitoring and alerting features
Required2.Auto updating & Self managing scanners and agents.
Required3.Ability to Track the status of vulnerability with each iterative scan 1. Configurable monitoring and alerting features
Required2.Auto updating & Self managing scanners and agents.
Required3.Ability to Track the status of vulnerability with each iterative scan GENRIC FEATURES OF VULNERABILITY MANAGEMENT 1. Scanners running on hardened OS with no root or sudo access to it.
Required2. Ability to track ongoing progress against vulnerability management objectives. 1. Scanners running on hardened OS with no root or sudo access to it.
Required2. Ability to track ongoing progress against vulnerability management objectives. Sensors
Requiredscanners
Requiredagents provide visibility for Trend Visibility * MONITORING Provision of Alerts Flags/Reports for 1. Newly opened ports
Required3. New services on ports
Required5.Common vectors for attack and exploit
Required6. Certificate health
Required8. Installation of new or unauthorized software
Required9. Upgrades or downgrades or removals of existing software 1. Newly opened ports
Required3. New services on ports
Required5.Common vectors for attack and exploit
Required6. Certificate health
Required8. Installation of new or unauthorized software
Required9. Upgrades or downgrades or removals of existing software Monitoring FEATURES 1. Provision to detect and alert new assets in the network.
Required2.Provision to Targeted alerts based on a security policy.
Required3.Certificate data insight and certificate based vulner abilities.
Required7.Whenever a asset/IP is scanned multiple time
Requireduser to be able to fetch/download each and every report of that asset/IP. 1. Provision to detect and alert new assets in the network.
Required2.Provision to Targeted alerts based on a security policy.
Required3.Certificate data insight and certificate based vulnerabilities.
Required7.Whenever a asset/IP is scanned multiple time
Requireduser to be able to fetch/download each and every report of that asset/IP. GENRIC FEATURES OF MONITORING 3. Provide alert rule creation using AND OR/ONLY-IF kind of logic.
Required4. Reduced risk of system changes going unnoticed 3. Provide alert rule creation using AND OR/ONLY-IF kind of logic.
Required4. Reduced risk of system changes going unnoticed CONTEXTUAL THREAT CONTEXTUAL 3. Group vulnerabilities 3. Group vulnerabilities 5/8 DASHBOARD THREAT DASHBOARD FEATURES that have public exploit available
Requiredcan result in DoS and can propagate via lateral movement.
Required4. Provision for search results to be further sorted
Requiredfiltered and refined. that have public exploit available
Requiredcan result in DoS and can propagate via lateral movement.
Required4. Provision for search results to be further sorted
Requiredfiltered and refined. Craft ad-hoc queries with multiple variables and asset criteria 1.Asset class
Required2. Vulnerability type
Required3. Operating system 1.Asset class
Required2. Vulnerability type
Required3. Operating system GENRIC FEATURES OF CONTEXTUAL THREAT DASHBOARD 2. Allows fine-tuning of feed list byfiltering and sorting items according to a variety of criteria. * SECURE CONFIGURATION ASSESSMENT Technology coverage 1.Host
Required2.OS
Required3.Networ k Device
Required4.Storage De vice
Required5.Database
Required6.Appli cation 1.Host
Required2.OS
Required3.Network Device
Required4.Storage Device
Required5.Database
Required6.Application Database scanning Coverage 1. MS-SQL(All versions)
Required2. MySQL (All versions)
Required3. Oracle (All versions)
Required4. PostgreSQL (All versions)
Required5. DB2
Required6. Sybase. 1. MS-SQL(All versions)
Required2. MySQL (All versions)
Required3. Oracle (All versions)
Required4. PostgreSQL (All versions)
Required5. DB2
Required6. Sybase. Support reporting 3.CIS(Centre For Internet Security) 3.CIS(Centre For Internet Security) Support CIS(Centre For Internet Security) for 1. Databases
Required2.Network Firewalls
Required3. IPS (Intrusion prevention system)
Required4.DDOS( Distributed denial of se rvice)
Required5.Routers
Required6.Swit ches
Required7.WAF(Web Application Firewall)
Required8.Load Balancer 1. Databases
Required2.Network Firewalls
Required3. IPS (Intrusion prevention system)
Required4.DDOS( Distributed denial of service)
Required5.Routers
Required6.Switches
Required7.WAF(Web Application Firewall)
Required8.Load Balancer Scanner Policy 2.Tamper resistant * Integration with 1. GRC (Governance
RequiredRisk and Compliance) * Optimized Controls for 1. Performance
Required2.Scala bility
Required3. Accuracy
Required4.User management * HARDWARE REQUIREMENT FOR SOFTWARE Hard Disk Space Required - * RAM Size required - * CPU required - * 6/8 Operating Systems supported (Driver) - * Supported Servers - * GENERIC PARAMETERS Free Upgradation to Higher Version within support period including API
RequiredFirmware
RequiredSignatures
Requiredetc YES YES OEM to provide Certification on-site No * If yes
Requiredno of users to certify NA * List of items included in the scope of supply - * Hyper link for Data sheet - * Number of Software deployment/Installed in Govt Department (Cent ral/State/PSU/PSB
Requiredetc) from OEM 400 * Details of Government Department email
Requiredphone no Of concerned authority where Software/Appliance installed for above - * * Specifications highlighted in bold are the Golden Parameters. * Bidders may note that In respect of non-golden Parameters
Requiredthe specifications 'Values' chosen by Buyer will generally be preferred over 'Bid requirement ( allowed Values) by the Buyer.