Ministry of Justice

Joiners, Movers & Leavers (JML) Delivery

26 Incomplete applications

18 SME, 8 large

2 Completed applications

2 SME, 0 large

Important dates

Published
Thursday 30 July 2020
Deadline for asking questions
Thursday 6 August 2020 at 11:59pm GMT
Closing date for applications
Thursday 13 August 2020 at 11:59pm GMT

Overview

Summary of the work
Assessment method: written proposal then followed by an interview adressing a how supplier will delivery summary of work.

Q&A facilities are available to all candidates/suppliers.
Latest start date
Thursday 1 October 2020
Expected contract length
6 months or end in 31/03/2021
Location
London
Organisation the work is for
Ministry of Justice
Budget range
£275,000 Ex VAT

About the work

Why the work is being done
The Ministry of Justice (MOJ) has a diverse and sizable technology estate, where many systems operate independently without shared authentication and authorisation systems. There are many different user management approaches in use, which means account management when staff and contractors join, change roles, or leave the organisation is inherently a manual activity, and thus prone to delay and error. We seek to make tactical and strategic improvements to all of the processes that drive our joiners, movers and leavers activities to make them more resilient with clearly defined roles and responsibility supported via refresh HR policies & guidance and supplemented through continued security messaging.

Digital and Technology Strategic Objective

* Fix the basic
Problem to be solved
Recently in January 2020 an independent consultancy produced an exploration report on the MoJ current Joiners, mover & leavers.

The purpose is to improve overall Group Security by repositioning security culture and messaging at the heart of this.

The problem of inconsistent onboarding and offboarding of employees inc contractors remains that the JML processes and implementations across the MOJ are fragmented and ineffective.
Who the users are and what they need to do
LineManagerPersonal
As manager, I need assurance that users have been removed from IT systems after they have left, so I know that I have fulfilled my responsibilities and the information assets are secure.
• Beable to get joiners access to all necessary systems and shared mailboxes/drives quickly and simply.

Handsoff Manager Persona
As manager, I need assurance that users have been removed from IT systems after they have left, so that I know that I have fulfilled my responsibilities and the information assets
are secure.
• As manager, I need IT processes that rely on little input from me, so that I can concentrate on the strategic and people-related elements of being a manager, not on IT.

Digital Champions Persona
As a Digital Champion, I need to be informed in advance when people join, move or leave so that I can fulfil my role in supporting line managers effectively.
• Have assurance that access to accounts has been revoked if the request for account closure has been accepted and closed.
• I need to know what systems and information assets a user has been accessing, so that I can arrange to close these accounts when they leave or change role.
Early market engagement
None aside from Discovery/Exploration.
Any work that’s already been done
A discovery phase has been concluded.
Discovery/exploration report including high level recomendarion and option assessment. Key findings of the discovery/expolration phases completed including user needs, persona, user journey, andr isk statement.
Existing team
Digital and Technology Security & Privacy Team - Leads (Senior Senior Advisor, CISO & Security Leads)
People Group - HR/Policy/Shared Service and etc
MoJ Digital Service Desk - supports Mac users
MoJ Service Desk - Contracted service desk for Windows 10 users
Digital Champions inc Business Managers
Heads of Dept (Deputy Directors)
Service Owners
Current phase
Alpha

Work setup

Address where the work will take place
Due COVID-19 limited access to MoJ buildings and as default working arrangements will be remote until further guidance from Public Health England.
102 Petty France London SW1H 9AJ or 10 South Colonnade, Canary Wharf E14 4PU
Working arrangements
Following Agile methodology.
Working on site / remote, but assuming remote as default.
Use of standard online collaboration tools Slack, Hangouts, Skype, Google G-Suite or Office 365. Report deliverables can also use word doc/power point.
Supplier to use their own equipment; MoJ equipment to be provided on an exceptional, case-by-case basis.
Access to the Security & Privacy Team Project Manager to provide reviews, direction and clarification on progress on a daily basis.
Access to SMEs for insights and environment-specific details, by arrangement.
Access to colleagues and suppliers working on other (new) IT systems, by arrangement.
Security clearance
Baseline Personnel Security Check (BPSS) as a minimum preferable SC.
See https://www.gov.uk/government/publications/government-baseline-personnel-security-standard for further guidance.

Additional information

Additional terms and conditions
Standard Digital Outcomes and Specialist contract applicable to MoJ.

Payment milestone.

Please see:
https://www.gov.uk/government/publications/digital-outcomes-and-specialists-2-call-off-contract

Skills and experience

Buyers will use the essential and nice-to-have skills and experience to help them evaluate suppliers’ technical competence.

Essential skills and experience
  • Evidence of recent and successful experience in delivering JML onboarding/offboarding of HR content for complex enterprise IT systems, conducted in the last three years.
  • Evidence of recent, demonstrable and successful experience in providing process map/data flow for JML proposed solutions, meeting business needs, conducted in the last three years.
  • Evidence of recent, demonstrable, effective, and successful experience in delivery and developing digital runbooks for onboarding/offboarding in the last three years.
  • Evidence of recent, demonstrable and successful experience in IT account remediation including digital forensic analysis in identifying dormant account based on user and organisational(business)needs, conducted in the last three years.
  • Evidence of recent, demonstrable and successful identification of JML business change ownership (service owners/heads of dept/service desk/HR) across a complex IT systems in the last three years.
Nice-to-have skills and experience
  • Evidence of successfully implementing identity strategy inc O365/G suites based solutions, at an Enterprise scale, in the last three years.
  • Evidence of successfully following, implementing and assessing offerings to standards set-out in the GDS Service Assessment Framework, technology code of practice and Cabinet Office spend-controls, in the last-three years.
  • Knowledge of relevant regulations and guidance relating to security matters in central government

How suppliers will be evaluated

All suppliers will be asked to provide a written proposal.

How many suppliers to evaluate
5
Proposal criteria
  • Describe the method you would propose to use,referencing your experience on how you would conduct research and assessment to meet our user needs and develop pragmatic security designs for JML
  • Describe how you would ensure that designed and implemented solutions meet the security expectations placed on them, both at initial deployment, and through life.
  • Describe how you will ensure that the delivery method will meet applicable legislation, standards, and best practices in cyber security for JML.
Cultural fit criteria
  • Evidence of recent, demonstrable and successful identification of JML business change ownership (service owners/heads of dept/service desk/HR) across a complex IT systems in the last three years.
  • Explain how you’ll ensure collaboration at all levels of the project and programme delivery between users, team members and management. Give examples of where you have successfully applied this approach
  • Explain how you’ll ensure productive and successful collaboration with suppliers to understand how their technology aligns with MOJ business needs, and to ensure the technology addresses those needs
Payment approach
Fixed price
Additional assessment methods
Presentation
Evaluation weighting

Technical competence

60%

Cultural fit

20%

Price

20%

Questions asked by suppliers

1. Is there a current or preferred incumbent?
There is no current provider or a preferred supplier. This is an open invitation to all suppliers registered on DOS.
The deadline for asking questions about this opportunity was Thursday 6 August 2020.