Opportunities Banner

Cobit 19, Nist Cybersecurity Framework Using Cobit & A Digital Transformation Strategy

Country: 
Zambia and Zimbabwe
Reference Number: 
ZRA-ICT-C-04-23
Due Date: 
Wednesday, April 5, 2023
 
1. The Zambezi River Authority (“the Authority”) has set aside funds to finance various operations during the 2023 financial year. It is intended that part of the proceeds of the funds will be used to cover eligible payments for the provision of COBIC 19, NIST Cyber security Framework using COBIT and Digital Transformation Strategy consultancy services.
 
2. The Zambezi River Authority (“the Authority”) was established as a body corporate on 1st October 1987 by parallel legislation in the Parliaments of Zambia and Zimbabwe following the reconstitution of the Central African Power Corporation under the Zambezi River Authority Acts (Chapters 467 and 20:23 respectively). The Authority is jointly owned by the Governments of the Republics of Zambia and Zimbabwe in equal proportions and is mandated with the management of the Kariba Complex and the stretch of the Zambezi River (from Kazungula to Luangwa in Zambia and Kazungula to Kanyemba in Zimbabwe) which forms part of a common border between the two Contracting States.
 
3. The scope for consulting services ("the Services") include;
 
i) Assess and review the current ICT environment & cybersecurity posture, governance and digital strategy.
ii) Develop a Control Objectives for Information and Related Technologies (COBIT), National Institute of Standards & Technology (NIST) cybersecurity framework and digital transformation strategy plan that will include objectives, scope, methodology and schedule.
 
4. The specific objectives of the assignment are;
 
i) to provide a common language for ICT professionals, Authority’s Management and Internal Audit to communicate with each other about IT controls, goals, objectives and outcomes.
ii) Proper alignment of all business and IT-related strategies.
iii) to ensure that IT investments are being prioritized in a way that helps the Authority to achieve its objectives without incurring additional IT risk.
iv) to provide a prioritized, flexible, repeatable, and cost-effective approach to cybersecurity risk
v) to develop strategies to;
  • Identify which assets need protection.
  • Implement appropriate safeguards to protect the identified assets.
  • Implement appropriate safeguards to detect security threats and incidents.
  • Develop techniques to mitigate the impact of these incidents.
  • Implement processes to recover from cyberattacks and restore business-as-usual.

vi) assist the Authority to integrate digital technology in all areas of its operations inorder to deliver value to its stakeholders. The Draft Terms of Reference for the said Consulting Services can be inspected on the Authority’s website: www.zambezira.org

 
5. The Authority now invites eligible Information Technology consulting firms ("Consultants") with specific experience to indicate their interest in providing the required Services. Interested Consultants must provide information demonstrating that they have the required specific experience to perform the services. The shortlisting criteria are:
 
    • The firm’s core business being in the area of the proposed assignment,
    • General experience of the firm (clearly demonstrating the scope, cost and duration in the provision of consulting services relating to COBIC 19, NIST Cyber security Framework using COBIT and Digital Transformation Strategy.
    • Specific experience of the firm in the provision of COBIC 19, NIST Cyber security Framework using COBIT and Digital Transformation Strategy consultancy services for at least two (2) clients in the last seven (7) years with the following details:
i. Name of client to which service/assignment of job evaluation nature was provided and duration.
ii. Name and location of the project or assignment; and,
iii. Value of the assignments.
iv. Contact name, Cell Number and Email for the assignment reference indicated.
    • The firm's company profile, detailing the firm's shareholding structure; names of Directors, Nationality, Address, Telephone and E-mail and firm's Certification of Incorporation or Registration
 
The assignment should start in July 2023 and is expected to be implemented over sixty (60) days. The Consultant will be selected in accordance with the Least Cost Selection (LCS)method set out in the Authority’s Procurement Policy and Procedures Manual.
 
Consultants may associate with other firms in the form of a joint venture or a sub-consultancy to enhance their qualifications.
 
Further information can be obtained at the address below during working hours from 0800 hours to 1630 hours local time or Email: Langton.Pfaira@zambezira.org
 
6. Expressions of interest shall be submitted by E-MAIL ONLY in PDF on or before 5 th May 2023, 1600hrs on the following E-mail Tender Box.
 
 
The Expressions of interest must be addressed to;
The Chief Executive
Zambezi River Authority
Kariba House, 32 Cha Cha Cha Road
Lusaka, Zambia.
Tel.: +260 211 227970-3
 
Att: Manager Procurement
 
Download ToRs COBIT Implementation Here                                Download Final Advert - ZRA COBIT