PatchManagement Aarlon
PatchManagement Aarlon
PatchManagement Aarlon
For
1) Introduction
With assets worth over USD 32.5 billion, bank muscat is the leading financial services provider in Oman
with a strong presence in Corporate Banking, Retail Banking, Investment Banking, Islamic Banking,
Treasury, Private Banking and Asset Management. The Bank has the largest network of 151 branches,
700 ATMs, CDMs & FFMs and more than 17000 PoS terminals. The international operations consist of a
branch each in Riyadh (Kingdom of Saudi Arabia), Kuwait and a Representative Office each in Dubai
(UAE) and Singapore.
Bank Muscat is requesting to procure an enterprise patch management solution that has the capability to fix
vulnerabilities on windows and non-windows platforms. Apart from OS vulnerabilities, the tool should
support fixing third party software vulnerabilities, mobile device vulnerabilities, Wake on LAN feature,
software distribution, operating system deployment, software / hardware inventory, switches /routers
related vulnerabilities and enhanced reporting capabilities.
2.1) Objectives
The Objective of the patch management solution is to fix vulnerabilities in a seamless manner for both
operating system and third party software and network routers /switches and to have a complete centralized
control and operation suite for the proposed patch management solution.
2.2) Requirements
The following are the detailed functionality requirements from the bank, and the vendor must provide
detailed response with appropriate supporting evidence for the below mentioned items.
The Bank reserves the right to reject any or all proposals and to waive informalities in the proposal
process without assigning any reason. The Bank do not intend to enter into an agreement solely
on the basis of a submitted proposal or otherwise pay for the information solicited or obtained.
Subsequent procurement, if any, will be in accordance with appropriate contractual action.
Noncompliance with any condition of this proposal may result in Vendor being disqualified.
3. Independent Contractor
On award of the Contract, the vendor shall confirm acceptance of the work in writing and shall
complete the work in accordance with the Banks standard terms and conditions and under those
terms, which are specific to this project.
The vendor shall not re-assign the work to any third party by way of subcontracts without the
express permission of the Bank in writing.
The vendor shall submit the list of Certified Engineers/Personnel with their CVs who would be
carrying out the work on award of the Contract. The Information Security department will issue
an authorization letter under those names for their access to the Bank premises for the execution
of the assigned work.
Once the bank accepts the design and solution document proposed by the vendor, the vendor
shall be responsible to implement the same without any additional cost to the bank
Requirements detailed above at 2.2. While the intent is to consolidate all the above requirements with
one technology. However, Vendor may submit proposals with a strategy to fulfill all the requirements
with the minimum number of technologies.
The vendor shall submit a detailed financial proposal with a break up of costs.
Prices quoted shall be inclusive of all Taxes, Travel, Stay, Visa what so ever payable by the Vendor.
The Bank is not liable to pay any other costs, which are not included in the proposal. Any taxation
liability of bank should be clearly communicated in cost proposal
Any Payment required to be withheld under the Law by the Bank and paid to the Government shall
be deemed to have been paid to the Vendor.
The Bank shall not be liable for any costs incurred by the Vendor in preparing or submitting a
proposal to the Bank.
5) Validity
Instruction to the vendor: The commercial terms and conditions mentioned in the proposal should be
valid for a minimum period of 60 calendar days.
6) Warranty
7) Maintenance
The gene al e m fo a an i ha he endo hall bmi a d af main enance con ac , hich hall
include spares (in case of H/W) and labor at zero cost to the bank during the warranty period. The terms
for maintenance of S/W shall be specified by he endo .
8) Banks responsibility
The Bank reserves the right to accept or reject any proposal or any item or items proposed by the vendor
a he Bank ole di c e ion i ho a igning an ea on .
Bank Information Security Department will review and deliverables at each Phase and approve for
acceptance before moving forward to the next stage.
The bank will assign a Project manager for the duration of the project and till the work is completed and
handed over to the Information Security Department, all correspondence relating to this project shall be
communicated to the bank through this contact point.
9) Vendor responsibility
On award of the Contract, the vendor shall confirm acceptance of the work in writing and should
complete the work in accordance with the Banks standard terms and conditions and under those terms,
which are specific to this project.
The vendor should not re-assign the work to any third party by way of subcontracts without the express
permission of the Bank in writing. Except the Bank Re pon ibili ie a ci ed cla e 8 abo e, the Vendor
shall ensure to cover all and every aspect of the project to complete it in its entirety.
The vendor shall submit the list of Certified Engineers/Personnel who would be carrying out the work
on award of the Contract. The Information Security department will issue an authorization letter under
those names for their access to the Bank premises for the execution of the assigned work.
Vendo ill info m he bank if an of he Bank emplo ee i ela ed o bank aff. The ill al o info m
he bank e plici l if an of he bank m ca emplo ee ha an direct or indirect interest in the vendor
compan affai .
10) Deliverables
The technical solutions must meet all our requirements as specified in 2.2
On award of the Contract, the vendor shall endeavor to complete the Project as per the mutually agreed
schedules with in the stipulated time. Any difficulties identified by the vendor, which would have an
effect on the target date for completion of the assigned tasks, shall be brought to the attention of the Head
Information Security)
12) Confidentiality
The Vendor shall agree that they shall not disclose or duplicate any information received from the Bank
as a part of the project requirements to any third party unless the Bank specifically authorizes such
disclosure or duplication in writing. The vendor would be required to sign an NDA in this regard.
13) Indemnification
Vendor shall agree to defend, indemnify, and hold harmless the Bank, its officials, officers, employees,
agents and volunteers from any and all claims, actions, judgments, losses, costs (including personnel
related costs, reasonable attorney's fees and all other claim related expenses) and damages whatsoever,
including but not limited to claims made upon the Bank arising by reason of accident, injury, or death to
any person, to Vendor or to Vendor's agents, employees, servants and all subcontractors or by reason of
injury to property arising out of or in connection with work performed under the contract, except upon
a finding of a tier of fact that such loss was caused by the sole negligence of the Bank. This promise of
indemnity shall specifically apply in the case of injuries to Vendor's own employees.