Security Information and Event Management (SIEM) RFI/RFP questionnaire — 0-Doubt
Security Information and Event Management (SIEM) evaluation questionnaire
Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
Build your evaluation
no account needed
Match on your requirements
no account needed
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
1. Weight what matters
100 criteria
baselineWhat data sources and connectors are supported out of the box, how is ingestion priced (data volume / EPS / assets), and can data be tiered or filtered to control cost?
baselineWhat out-of-the-box detection content and MITRE ATT&CK coverage are included, is behavioral analytics (UEBA) native, and how are detections kept current?
baselineDescribe investigation workflows, case management, and built-in SOAR/automation; quantify analyst time-to-investigate improvements.
baselineWhich deployment options (SaaS, self-hosted, hybrid) and data-residency/region controls are offered, and is search performance consistent across them?
baselineWhat AI/agentic capabilities assist triage, investigation, and detection engineering, and how are AI decisions made transparent and auditable?
baselineDetail retention tiers (hot/warm/cold), search performance at scale, and the total cost drivers, with customer-validated figures.
baselineDoes the platform natively correlate endpoint, cloud, identity, and network telemetry (toward XDR), or does that rely on integrations?
baselineDetail migration from an incumbent SIEM: content portability, query language/openness, and lock-in considerations, citing references.
baselineDoes the platform provide compliance-specific log-retention and reporting capability (PCI DSS, HIPAA required retention windows, audit-ready report templates), or does the customer need to build custom reports/retention policy to meet regulatory requirements?
baselineDescribe support for multi-tenant/MSSP deployments — can a service provider manage multiple distinct customer environments from one instance with proper data isolation, and what is the pricing/licensing model for that use case?
baselineWhat professional-services or content-authoring support is available for building custom detection rules specific to the customer's environment, and is this included in the subscription or a separate paid engagement?
baselineDetail the query language and threat-hunting interface — is it approachable for an analyst without deep query-language expertise, and what training/ramp-up time does a customer reference report for a new analyst to become self-sufficient?
baselineHow does the platform handle data normalization across disparate log sources (different field names/formats/timestamps) so that correlation rules work consistently, and is normalization automatic or does it require manual field mapping per source?
baselineWhat is the maximum tested scale (events per second, total daily data volume) the platform has handled for a real customer, and what happens to search/query performance as data volume grows toward that ceiling?
baselineExplain incident-response escalation integration — when the SIEM identifies a likely major incident, does it have a direct, automated escalation path to an IR team or retainer service, or does escalation rely entirely on manual analyst judgment and separate tooling?
baselineWhat alert-tuning support is provided to reduce false-positive fatigue over time — is there a structured tuning methodology/service, or is the customer expected to self-tune through trial and error?
baselineThe bidder would be responsible for replacing out-of-support, out-of-service, end-of-life, or undersized infrastructure elements at no extra cost during the entire 5-year contract period, replacing before the product/service's due date.
baselineProvide centralized logging into a SIEM or SIEM-like system.
baselineBidder shall share detailed information security incident report(s) with details of the incident.
baselineProvide proof of BAS integration with Security Information and Event Management (SIEM) systems and Security Orchestration, Automation, and Response (SOAR) platforms.
baselineImplement monitoring tools for server and workstation health, with 24/7 alerting for proactive issue resolution and concurrent email notification to the airport authority.
baselineProvide the airport authority with access to monitoring tools for transparency and oversight.
baselineEstablish centralized monitoring, alerting, and incident response capabilities across on-premises, cloud, and hybrid environments.
baselineIntegrate with key components of the existing IT ecosystem, including Heimdal EDR, Cisco Meraki, Microsoft 365, Azure AD, and on-prem Active Directory.
baselineSupport compliance and auditing requirements aligned with standards such as NIST CSF, CJIS, ISO 27001, HIPAA, and PCI-DSS.
baselineEnable long-term scalability and adaptability through flexible architecture and support for emerging technologies.
baselineConduct a full assessment of the current IT and security landscape, identifying critical systems, existing log sources, and visibility gaps.
baselineDeploy the SIEM/SOAR platform, including infrastructure provisioning (cloud, on-premises, or hybrid), log pipeline configuration, and baseline use case deployment.
baselineProvide required parsing support for Azure AD, on-prem AD, M365 (Exchange, Teams, SharePoint), Heimdal EDR, Cisco Meraki, and core firewall(s), with future support for identity management platforms, additional/replacement EDR solutions, and third-party SaaS tools (Phase 2+).
baselineUse vendor-recommended or supported connectors and tools for log parsing, normalization, and onboarding.
baselineProvide architecture diagrams, integration mappings, and configuration documentation.
baselineSupport minimum log retention of 30-90 days hot storage, 12 months warm storage, and 5 years cold storage, with options for extended retention if required by regulation.
baselineSupport an initial throughput of up to 5,000 events per second (EPS), scalable to at least 15,000 EPS within three years; specify hardware or cloud resource sizing to meet these thresholds.
baselineInclude compression ratios, indexing strategies, and storage growth estimates in the technical proposal.
baselineAlign with NIST CSF, CJIS, HIPAA, and PCI-DSS requirements.
baselineEnsure encryption in transit and at rest, immutable log storage, and verifiable audit trails.
baselineProvide customizable dashboards and compliance reporting with exportable data.
baselineUtilize identity enrichment and correlation for improved event context and detection fidelity.
baselineProvide at least three examples of comparable SIEM/SOAR deployments within hybrid environments of similar scale (log volume, EPS, and integration complexity).
baselineInclude staff certifications relevant to the proposed solution, such as CISSP, CISM, GIAC, or vendor-specific credentials (e.g., Microsoft, Splunk, IBM, Palo Alto).
baselineIdentify key project personnel and their certifications, roles, and project responsibilities.
baselineDemonstrate successful integrations with Azure AD/on-prem AD (hybrid identity), Microsoft 365 services (Exchange, Teams, SharePoint, OneDrive), and Heimdal EDR, Cisco Meraki, and comparable platforms.
baselineList available native connectors and describe any customization required to achieve full ingestion and correlation.
baselineDeliver role-based training programs tailored for administrators, analysts, and IT staff, with minimum required training hours: Administrators 12 hours, Security Analysts 16 hours, IT/Helpdesk Staff 8 hours.
baselineProvide training deliverables, including recorded sessions and presentation materials, hands-on playbook development labs, and quick-reference guides/SOP documentation.
baselineDefine Service-Level Agreements (SLAs) including critical issue response <1 hour, high severity resolution <4 hours, routine support <24 hours, and patch/update cadence quarterly at minimum.
baselineInclude escalation procedures, after-hours availability, and performance tracking.
baselineProvide post-go-live services for tuning, optimization, and platform health checks during the first 90 days.
baselineDescribe platform scalability for increased log volume, new data sources, and user roles.
baselineHighlight support for machine learning analytics, UEBA, threat intelligence ingestion, and open API integration to accommodate evolving needs.
baselineProvide a detailed pricing breakdown separating licensing/subscription costs, professional services, hardware/infrastructure, ongoing support & maintenance, and multi-year (3-5 year) lifecycle pricing including renewal costs and projected increases.
baselineDeliver a fully operational SIEM/SOAR solution meeting the required parsing support integration scope, documented discovery findings/architecture/integration strategy, configured log sources, custom and baseline correlation rules/detection logic/playbooks, operational runbooks/SOPs/training materials, and a final tuning report and scalability roadmap.
baselineFollow a phased implementation approach: Discovery & Planning; Platform Deployment; Log Source Onboarding & Use Case Development; Playbook Development & Automation; Training, Handoff, & Go-Live — each phase including timeline/milestone tracking, change management artifacts, stakeholder review/sign-off, and UAT/validation reports.
baselineAssign a dedicated Project Manager responsible for coordinating implementation phases, serving as primary point of contact, providing weekly status/risk tracking/documentation updates, and ensuring schedule adherence and proactive issue resolution.
baselineSupport final acceptance testing based on verified log ingestion/normalization from all Day 1 sources, successful correlation rule triggering and playbook automation, confirmed dashboard/reporting functionality, RBAC enforcement validation, completion of role-based training, and signed stakeholder approval.
baselineProvide detailed information on the firm's methodology in meeting the scope of work requirements, including a proposed project plan outline, schedule, and deliverables with an end date on or before September 30, 2026.
baselineSubmit a pricing breakdown including upfront costs, hardware, recurring monthly charges, anticipated/required maintenance, and miscellaneous implementation costs.
baselineProvide an estimate of total project cost including upfront initial costs, equipment, maintenance, communications/network services implementation and recurring costs, monthly services, and implementation services; highest-rated proposer must also provide a detailed fee schedule with direct/indirect labor rates.
baselineDesign the architecture with future expansion in mind, including integration of identity, network, and infrastructure logs to support broader correlation and detection capabilities.
baselineUtilize Microsoft-native tools and services, including Microsoft Defender for Endpoint, Microsoft Sentinel, Microsoft Defender for Office 365, and Microsoft Purview Audit.
baselineSupport integration of telemetry sources including endpoint telemetry (Windows/iOS/Android), M365 audit logs, Azure AD sign-in/activity logs, AD identity/authentication logs, DNS/DHCP logs, firewall logs, and server infrastructure telemetry.
baselineConfigure Microsoft Sentinel within the agency's tenant, including data connectors, initial analytics rules/workbooks/dashboards, RBAC for agency and vendor staff, and alerting/escalation workflows.
baselineUse the latest threat detection and response technologies including SIEM, EDR/MDR, and threat intelligence platforms with a well-defined process for detecting and responding to security threats and vulnerabilities.
baselineDoes your solution accept feeds from security devices, network devices, applications, endpoints, and databases? Describe the devices your solution supports and any it does not support.
baselineDescribe your process for identifying relevant security events from logs feeding into your system. Explain the types of events you process from Windows hosts, Linux hosts, databases, routers, and switches, and how your rules engine correlates these events.
baselineDo you enrich log data with contextual elements such as IP reputation, Geo IP, or assets? If so, describe.
baselineWhat are your analytic and correlation capabilities? Describe the continuum of automated processing and categorizing of threats within your system, and the validation tools/processes utilized.
baselineDoes your solution analyze and correlate data to identify security events and classify events according to severity? Are you able to correlate events across clients/endpoints? Can you correlate events by identity (user)?
baselineMust support log ingestion from at least 2,800 Windows endpoints, 300 MacBooks, 120 Windows servers, 30 Linux servers, 400 Cisco switches/routers, and various security appliances.
baselineMust support log collection from cloud services, including but not limited to Google Workspace (Admin, Drive, Gmail, etc.), Microsoft Entra ID, Microsoft 365 Security logs, and any additional SaaS or IaaS platforms utilized by the school district.
baselineMust allow for ingestion via industry-standard protocols (e.g., Syslog, API, agent-based collection, etc.).
baselineMust provide a robust correlation engine capable of linking disparate logs and events to detect complex attack patterns.
baselineMust support custom rule creation and modification for advanced threat detection.
baselineMust include pre-built correlation rules aligned with industry best practices (MITRE ATT&CK, CIS, etc.).
baselineShould offer machine learning (ML) or AI-based behavioral analytics to detect anomalies.
baselineMust integrate with real-time threat intelligence feeds to detect and alert on known Indicators of Compromise (IOCs).
baselineMust provide customizable alerting via email, SMS, and integrations with ticketing systems.
baselineShould support a log retention period of at least 12 months for critical logs, with configurable options for longer retention if required.
baselineMust handle high-volume log ingestion without performance degradation, and must offer a scalable architecture supporting on-premise, cloud, or hybrid deployment models.
baselineMust provide a user-friendly, web-based interface with intuitive dashboards.
baselineMust include pre-built and customizable reporting for compliance and security analytics, and should provide compliance-specific reports.
baselineMust support role-based access control (RBAC) to restrict SIEM access by role.
baselineMust encrypt logs in transit and at rest.
baselineMust provide API support for seamless integration with other security tools (e.g., EDR, firewall management, IAM solutions), and should support integration with existing ticketing and incident management systems.
baselineVendors should provide pricing for different deployment models and include cost breakdowns for licensing (per user, per endpoint, per GB, etc.), support and maintenance, and additional features (e.g., SOAR, extended retention, custom integrations).
baselineThe bidder should be a company registered in India under the relevant acts (Companies Act 2013, Indian Partnership Act 1932, or LLP Act 2008), with its registered office in India.
baselineThe bidder should have experience of a minimum of 5 years in providing IT/IT services.
baselineThe OEM should be a Software Development, IT Application & Maintenance company registered/incorporated under Indian company Act and must have 10 years of existence in India as on date of submission of bids.
baselineThe Bidder should have an average annual turnover of INR 3 crore in the past three financial years with a positive net worth in at least 2 years, and the OEM should have average annual turnover of INR 300 crore in the past three financial years in India.
baselineThe Bidder should not have been blacklisted at the time of submission of the bid by any Regulator / Statutory Body / any Government Department / PSU / PSE / Financial Institution in India.
baselineThe bidder should be the authorized partner of the OEM, evidenced by a Manufacturer Authorization Form confirming product details, authorization to submit the proposal for the entire contract duration, and OEM's commitment to sign the Agreement and NDA ensuring compliance to the Scope of Work.
baselineThe proposed SIEM solution should be from a single OEM, and the OEM/System Integrator should have experience in the end-to-end implementation of the proposed solution.
baselineThe bidder should have at least 50 Functional/IT Professionals on its payroll as on the date of bid opening.
baselineThe OEM should hold at least 3 industry-recognized certifications for quality management and information security standards (any 3 of ISO 9001, ISO 27001, ISO 27017, ISO 27018 or equivalent).
baselineThe bidder should have experience delivering a SIEM project in BFSI/PSU/PSE/Government Organization in India within the last 3 years as on the date of bid opening, evidenced by a copy of the contract/purchase order and client confirmation.
baselineThe proposed Cloud Service Provider (CSP) must be empaneled with MeitY as on the date of bid submission for the proposed sites, or hold ISO 27001, ISO 27017, ISO 27018, and ISO 20000 certifications; its data centers should be minimum Rated 3 of TIA942 or Tier 3 or equivalent.
baselineThe CSP should have experience of provisioning services on their cloud for at least 3 clients in India during the last 5 years, of which 1 should be PSU/Central Govt/State Govt and 1 should be BFSI; the CSP's primary and secondary sites for the project should be in two different, geographically well-separated locations in India.
baselineBidder is required to design and implement the SIEM tool on Cloud, with all modules sourced from a single OEM, and ensure security updates/upgrades/patches in the production environment.
baselineBidder must ensure that all in-scope application & infrastructure enables generation and monitoring of logs, and provides comprehensive audit trail features with access control list generation.
baselineThe system shall provide daily activity logs as well as history logs (1-2 months online, post which the logs should be archived); it is the bidder's responsibility to ensure the storage, retention and offsite backup of logs.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Platform baseline
neutral · staff-reviewed
RFIWhat data sources and connectors are supported out of the box, how is ingestion priced (data volume / EPS / assets), and can data be tiered or filtered to control cost?Answer key — what a strong answer shows
Strong answers quantify connector breadth, state the pricing model plainly, and show data-tiering/pipeline controls to manage cost. Probe whether security value is gated behind premium ingest tiers.
RFIWhat out-of-the-box detection content and MITRE ATT&CK coverage are included, is behavioral analytics (UEBA) native, and how are detections kept current?Answer key — what a strong answer shows
Look for a maintained detection library mapped to ATT&CK, native UEBA (not a separate product), and a clear content-update cadence. Distinguish vendor-authored content from community rules.
RFPDescribe investigation workflows, case management, and built-in SOAR/automation; quantify analyst time-to-investigate improvements.Answer key — what a strong answer shows
Evidence-backed answers show case management, whether SOAR is native or an add-on, and concrete automation, with measured time-to-investigate/respond from customers rather than marketing.
Neutral strengths and gaps for each vendor in this category, drawn from vendors' own public materials — included so the questions above favor no single vendor. Gaps reflect capabilities not emphasized in public materials, not rankings.
Vendor
Strengths
Gaps / watch-outs
CrowdStrikeAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
Falcon Next-Gen SIEM tied to endpoint/XDR telemetry and threat intelligence on a single platform.
Greatest value when paired with Falcon endpoint; standalone SIEM for heterogeneous estates is documented elsewhere.
ElasticAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.
From other buyers
crowdsourced · anonymized
💬
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
RFIWhich deployment options (SaaS, self-hosted, hybrid) and data-residency/region controls are offered, and is search performance consistent across them?Answer key — what a strong answer shows
Strong answers state deployment models, residency/region controls, and whether search/analytics performance is consistent across them or degrades self-hosted.
RFIWhat AI/agentic capabilities assist triage, investigation, and detection engineering, and how are AI decisions made transparent and auditable?Answer key — what a strong answer shows
Look for AI that summarizes/triages with human-in-the-loop and an auditable rationale, not opaque verdicts. Ask what data trains/grounds the AI and where it runs.
RFPDetail retention tiers (hot/warm/cold), search performance at scale, and the total cost drivers, with customer-validated figures.Answer key — what a strong answer shows
Prefer answers with explicit retention tiers, real scale/search numbers, and transparent cost drivers backed by customer references — not just 'unlimited' or 'predictable' claims.
RFIDoes the platform natively correlate endpoint, cloud, identity, and network telemetry (toward XDR), or does that rely on integrations?Answer key — what a strong answer shows
Strong answers separate first-party/native domains from integrations and explain how correlation works across them and what is lost without the vendor's own endpoint/identity sources.
RFPDetail migration from an incumbent SIEM: content portability, query language/openness, and lock-in considerations, citing references.Answer key — what a strong answer shows
Prefer concrete migration tooling, portable detection content, an open/queryable language, and honest lock-in discussion (e.g., proprietary pipelines or pricing that penalizes egress).
RFIDoes the platform provide compliance-specific log-retention and reporting capability (PCI DSS, HIPAA required retention windows, audit-ready report templates), or does the customer need to build custom reports/retention policy to meet regulatory requirements?Answer key — what a strong answer shows
Native compliance report templates and configurable retention policies matched to specific regulatory windows are materially stronger than a generic log store requiring custom report-building for every audit.
RFPDescribe support for multi-tenant/MSSP deployments — can a service provider manage multiple distinct customer environments from one instance with proper data isolation, and what is the pricing/licensing model for that use case?Answer key — what a strong answer shows
Look for genuine tenant isolation (not just filtered views into one shared dataset) and an explicit MSSP pricing tier if that's the buyer's use case.
RFIWhat professional-services or content-authoring support is available for building custom detection rules specific to the customer's environment, and is this included in the subscription or a separate paid engagement?Answer key — what a strong answer shows
Strong answers are explicit about what's included versus a paid add-on — a customer with no in-house detection-engineering expertise needs to know this cost exists before signing.
RFPDetail the query language and threat-hunting interface — is it approachable for an analyst without deep query-language expertise, and what training/ramp-up time does a customer reference report for a new analyst to become self-sufficient?Answer key — what a strong answer shows
Strong answers give a concrete, customer-validated ramp-up timeline; a powerful but expert-only query language creates a real staffing bottleneck for smaller SOC teams.
RFIHow does the platform handle data normalization across disparate log sources (different field names/formats/timestamps) so that correlation rules work consistently, and is normalization automatic or does it require manual field mapping per source?Answer key — what a strong answer shows
Automatic, well-maintained normalization is a major differentiator — manual per-source field mapping is a significant hidden implementation cost often underestimated during evaluation.
RFIWhat is the maximum tested scale (events per second, total daily data volume) the platform has handled for a real customer, and what happens to search/query performance as data volume grows toward that ceiling?Answer key — what a strong answer shows
Look for a real customer-validated scale figure and honest performance degradation characteristics near capacity, not just a marketing claim of 'infinitely scalable.'
RFPExplain incident-response escalation integration — when the SIEM identifies a likely major incident, does it have a direct, automated escalation path to an IR team or retainer service, or does escalation rely entirely on manual analyst judgment and separate tooling?Answer key — what a strong answer shows
An automated or semi-automated escalation path reduces response time for genuinely critical incidents versus relying purely on an analyst noticing and manually initiating escalation.
RFIWhat alert-tuning support is provided to reduce false-positive fatigue over time — is there a structured tuning methodology/service, or is the customer expected to self-tune through trial and error?Answer key — what a strong answer shows
A structured tuning methodology or dedicated tuning service materially reduces the well-known SIEM alert-fatigue problem faster than unassisted trial-and-error tuning.
RFPThe bidder would be responsible for replacing out-of-support, out-of-service, end-of-life, or undersized infrastructure elements at no extra cost during the entire 5-year contract period, replacing before the product/service's due date.
RFPProvide centralized logging into a SIEM or SIEM-like system.
RFPBidder shall share detailed information security incident report(s) with details of the incident.
RFPProvide proof of BAS integration with Security Information and Event Management (SIEM) systems and Security Orchestration, Automation, and Response (SOAR) platforms.
RFPImplement monitoring tools for server and workstation health, with 24/7 alerting for proactive issue resolution and concurrent email notification to the airport authority.
RFPProvide the airport authority with access to monitoring tools for transparency and oversight.
RFPEstablish centralized monitoring, alerting, and incident response capabilities across on-premises, cloud, and hybrid environments.
RFPIntegrate with key components of the existing IT ecosystem, including Heimdal EDR, Cisco Meraki, Microsoft 365, Azure AD, and on-prem Active Directory.
RFPSupport compliance and auditing requirements aligned with standards such as NIST CSF, CJIS, ISO 27001, HIPAA, and PCI-DSS.
RFPEnable long-term scalability and adaptability through flexible architecture and support for emerging technologies.
RFPConduct a full assessment of the current IT and security landscape, identifying critical systems, existing log sources, and visibility gaps.
RFPDeploy the SIEM/SOAR platform, including infrastructure provisioning (cloud, on-premises, or hybrid), log pipeline configuration, and baseline use case deployment.
RFPProvide required parsing support for Azure AD, on-prem AD, M365 (Exchange, Teams, SharePoint), Heimdal EDR, Cisco Meraki, and core firewall(s), with future support for identity management platforms, additional/replacement EDR solutions, and third-party SaaS tools (Phase 2+).
RFPUse vendor-recommended or supported connectors and tools for log parsing, normalization, and onboarding.
RFPProvide architecture diagrams, integration mappings, and configuration documentation.
RFPSupport minimum log retention of 30-90 days hot storage, 12 months warm storage, and 5 years cold storage, with options for extended retention if required by regulation.
RFPSupport an initial throughput of up to 5,000 events per second (EPS), scalable to at least 15,000 EPS within three years; specify hardware or cloud resource sizing to meet these thresholds.
RFPInclude compression ratios, indexing strategies, and storage growth estimates in the technical proposal.
RFPAlign with NIST CSF, CJIS, HIPAA, and PCI-DSS requirements.
RFPEnsure encryption in transit and at rest, immutable log storage, and verifiable audit trails.
RFPProvide customizable dashboards and compliance reporting with exportable data.
RFPUtilize identity enrichment and correlation for improved event context and detection fidelity.
RFPProvide at least three examples of comparable SIEM/SOAR deployments within hybrid environments of similar scale (log volume, EPS, and integration complexity).
RFPInclude staff certifications relevant to the proposed solution, such as CISSP, CISM, GIAC, or vendor-specific credentials (e.g., Microsoft, Splunk, IBM, Palo Alto).
RFPIdentify key project personnel and their certifications, roles, and project responsibilities.
RFPDemonstrate successful integrations with Azure AD/on-prem AD (hybrid identity), Microsoft 365 services (Exchange, Teams, SharePoint, OneDrive), and Heimdal EDR, Cisco Meraki, and comparable platforms.
RFPList available native connectors and describe any customization required to achieve full ingestion and correlation.
RFPDeliver role-based training programs tailored for administrators, analysts, and IT staff, with minimum required training hours: Administrators 12 hours, Security Analysts 16 hours, IT/Helpdesk Staff 8 hours.
RFPProvide training deliverables, including recorded sessions and presentation materials, hands-on playbook development labs, and quick-reference guides/SOP documentation.
RFPDefine Service-Level Agreements (SLAs) including critical issue response <1 hour, high severity resolution <4 hours, routine support <24 hours, and patch/update cadence quarterly at minimum.
RFPInclude escalation procedures, after-hours availability, and performance tracking.
RFPProvide post-go-live services for tuning, optimization, and platform health checks during the first 90 days.
RFPDescribe platform scalability for increased log volume, new data sources, and user roles.
RFPHighlight support for machine learning analytics, UEBA, threat intelligence ingestion, and open API integration to accommodate evolving needs.
RFPProvide a detailed pricing breakdown separating licensing/subscription costs, professional services, hardware/infrastructure, ongoing support & maintenance, and multi-year (3-5 year) lifecycle pricing including renewal costs and projected increases.
RFPDeliver a fully operational SIEM/SOAR solution meeting the required parsing support integration scope, documented discovery findings/architecture/integration strategy, configured log sources, custom and baseline correlation rules/detection logic/playbooks, operational runbooks/SOPs/training materials, and a final tuning report and scalability roadmap.
RFPFollow a phased implementation approach: Discovery & Planning; Platform Deployment; Log Source Onboarding & Use Case Development; Playbook Development & Automation; Training, Handoff, & Go-Live — each phase including timeline/milestone tracking, change management artifacts, stakeholder review/sign-off, and UAT/validation reports.
RFPAssign a dedicated Project Manager responsible for coordinating implementation phases, serving as primary point of contact, providing weekly status/risk tracking/documentation updates, and ensuring schedule adherence and proactive issue resolution.
RFPSupport final acceptance testing based on verified log ingestion/normalization from all Day 1 sources, successful correlation rule triggering and playbook automation, confirmed dashboard/reporting functionality, RBAC enforcement validation, completion of role-based training, and signed stakeholder approval.
RFPProvide detailed information on the firm's methodology in meeting the scope of work requirements, including a proposed project plan outline, schedule, and deliverables with an end date on or before September 30, 2026.
RFPSubmit a pricing breakdown including upfront costs, hardware, recurring monthly charges, anticipated/required maintenance, and miscellaneous implementation costs.
RFPProvide an estimate of total project cost including upfront initial costs, equipment, maintenance, communications/network services implementation and recurring costs, monthly services, and implementation services; highest-rated proposer must also provide a detailed fee schedule with direct/indirect labor rates.
RFPDesign the architecture with future expansion in mind, including integration of identity, network, and infrastructure logs to support broader correlation and detection capabilities.
RFPUtilize Microsoft-native tools and services, including Microsoft Defender for Endpoint, Microsoft Sentinel, Microsoft Defender for Office 365, and Microsoft Purview Audit.
RFPSupport integration of telemetry sources including endpoint telemetry (Windows/iOS/Android), M365 audit logs, Azure AD sign-in/activity logs, AD identity/authentication logs, DNS/DHCP logs, firewall logs, and server infrastructure telemetry.
RFPConfigure Microsoft Sentinel within the agency's tenant, including data connectors, initial analytics rules/workbooks/dashboards, RBAC for agency and vendor staff, and alerting/escalation workflows.
RFPUse the latest threat detection and response technologies including SIEM, EDR/MDR, and threat intelligence platforms with a well-defined process for detecting and responding to security threats and vulnerabilities.
RFPDoes your solution accept feeds from security devices, network devices, applications, endpoints, and databases? Describe the devices your solution supports and any it does not support.
RFPDescribe your process for identifying relevant security events from logs feeding into your system. Explain the types of events you process from Windows hosts, Linux hosts, databases, routers, and switches, and how your rules engine correlates these events.
RFPDo you enrich log data with contextual elements such as IP reputation, Geo IP, or assets? If so, describe.
RFPWhat are your analytic and correlation capabilities? Describe the continuum of automated processing and categorizing of threats within your system, and the validation tools/processes utilized.
RFPDoes your solution analyze and correlate data to identify security events and classify events according to severity? Are you able to correlate events across clients/endpoints? Can you correlate events by identity (user)?
RFPMust support log ingestion from at least 2,800 Windows endpoints, 300 MacBooks, 120 Windows servers, 30 Linux servers, 400 Cisco switches/routers, and various security appliances.
RFPMust support log collection from cloud services, including but not limited to Google Workspace (Admin, Drive, Gmail, etc.), Microsoft Entra ID, Microsoft 365 Security logs, and any additional SaaS or IaaS platforms utilized by the school district.
RFPMust allow for ingestion via industry-standard protocols (e.g., Syslog, API, agent-based collection, etc.).
RFPMust provide a robust correlation engine capable of linking disparate logs and events to detect complex attack patterns.
RFPMust support custom rule creation and modification for advanced threat detection.
RFPMust include pre-built correlation rules aligned with industry best practices (MITRE ATT&CK, CIS, etc.).
RFPShould offer machine learning (ML) or AI-based behavioral analytics to detect anomalies.
RFPMust integrate with real-time threat intelligence feeds to detect and alert on known Indicators of Compromise (IOCs).
RFPMust provide customizable alerting via email, SMS, and integrations with ticketing systems.
RFPShould support a log retention period of at least 12 months for critical logs, with configurable options for longer retention if required.
RFPMust handle high-volume log ingestion without performance degradation, and must offer a scalable architecture supporting on-premise, cloud, or hybrid deployment models.
RFPMust provide a user-friendly, web-based interface with intuitive dashboards.
RFPMust include pre-built and customizable reporting for compliance and security analytics, and should provide compliance-specific reports.
RFPMust support role-based access control (RBAC) to restrict SIEM access by role.
RFPMust encrypt logs in transit and at rest.
RFPMust provide API support for seamless integration with other security tools (e.g., EDR, firewall management, IAM solutions), and should support integration with existing ticketing and incident management systems.
RFPVendors should provide pricing for different deployment models and include cost breakdowns for licensing (per user, per endpoint, per GB, etc.), support and maintenance, and additional features (e.g., SOAR, extended retention, custom integrations).
RFPThe bidder should be a company registered in India under the relevant acts (Companies Act 2013, Indian Partnership Act 1932, or LLP Act 2008), with its registered office in India.
RFPThe bidder should have experience of a minimum of 5 years in providing IT/IT services.
RFPThe OEM should be a Software Development, IT Application & Maintenance company registered/incorporated under Indian company Act and must have 10 years of existence in India as on date of submission of bids.
RFPThe Bidder should have an average annual turnover of INR 3 crore in the past three financial years with a positive net worth in at least 2 years, and the OEM should have average annual turnover of INR 300 crore in the past three financial years in India.
RFPThe Bidder should not have been blacklisted at the time of submission of the bid by any Regulator / Statutory Body / any Government Department / PSU / PSE / Financial Institution in India.
RFPThe bidder should be the authorized partner of the OEM, evidenced by a Manufacturer Authorization Form confirming product details, authorization to submit the proposal for the entire contract duration, and OEM's commitment to sign the Agreement and NDA ensuring compliance to the Scope of Work.
RFPThe proposed SIEM solution should be from a single OEM, and the OEM/System Integrator should have experience in the end-to-end implementation of the proposed solution.
RFPThe bidder should have at least 50 Functional/IT Professionals on its payroll as on the date of bid opening.
RFPThe OEM should hold at least 3 industry-recognized certifications for quality management and information security standards (any 3 of ISO 9001, ISO 27001, ISO 27017, ISO 27018 or equivalent).
RFPThe bidder should have experience delivering a SIEM project in BFSI/PSU/PSE/Government Organization in India within the last 3 years as on the date of bid opening, evidenced by a copy of the contract/purchase order and client confirmation.
RFPThe proposed Cloud Service Provider (CSP) must be empaneled with MeitY as on the date of bid submission for the proposed sites, or hold ISO 27001, ISO 27017, ISO 27018, and ISO 20000 certifications; its data centers should be minimum Rated 3 of TIA942 or Tier 3 or equivalent.
RFPThe CSP should have experience of provisioning services on their cloud for at least 3 clients in India during the last 5 years, of which 1 should be PSU/Central Govt/State Govt and 1 should be BFSI; the CSP's primary and secondary sites for the project should be in two different, geographically well-separated locations in India.
RFPBidder is required to design and implement the SIEM tool on Cloud, with all modules sourced from a single OEM, and ensure security updates/upgrades/patches in the production environment.
RFPBidder must ensure that all in-scope application & infrastructure enables generation and monitoring of logs, and provides comprehensive audit trail features with access control list generation.
RFPThe system shall provide daily activity logs as well as history logs (1-2 months online, post which the logs should be archived); it is the bidder's responsibility to ensure the storage, retention and offsite backup of logs.
RFPBidder shall store all logs for a minimum period of one year (1-2 months online, then archival), must be capable of being downloaded, and must provide stored logs to the financial institution within one day's notice at no additional cost.
RFPIntegrate and monitor all logs through a SIEM; create correlation rules, customize existing rules and use cases for effective security monitoring and incident reporting; use proven threat feeds to proactively identify threats in the environment.
RFPLog Parsing and Normalization: validate log collection, configure parsers and field mappings, normalize events according to SIEM standards, and ensure timestamp synchronization and data quality.
RFPUse Case Implementation: implement predefined security monitoring use cases, develop custom detection rules and correlation logic, configure MITRE ATT&CK mapping where applicable, and define alert severity and prioritization.
RFPDashboards and Reporting: develop SOC operational dashboards, configure executive and compliance dashboards, and create scheduled security reports.
RFPThreat Intelligence Integration: integrate threat intelligence feeds, configure IOC ingestion and automated enrichment, and enable threat correlation.
RFPAlerting and Incident Integration: configure alert notifications, integrate with ITSM/SOAR platforms (e.g., in-house ticketing, Jira, Zoho), and configure incident workflows and escalation.
RFPPerformance Tuning: optimize log ingestion and correlation performance, reduce false positives, and fine-tune detection rules.
RFPBidder to provide workflow automation so that applications and infrastructure are integrated automatically, with minimal manual intervention.
RFPIn the event of integration challenges with any SaaS application, the bidder shall provide a shared storage location where the SaaS vendor can periodically export and deposit logs, with the SIEM solution integrated to collect and ingest from this location.
RFPSolution should be capable of assisting in finding log entries on originating systems for use in forensic investigations, and logs should be transmitted in encrypted format.
RFPProactively monitor and inform the financial institution's team if logs are not being received at the SOC from a log source.
RFPAll components of the solution must support scalability to provide continuous growth to meet requirements and demands, scaling in a linear fashion and behaving consistently with growth in data and number of concurrent users.
RFPThe solution should be interoperable to support information flow and integration, supporting open architecture such as XML, LDAP and SOA where information/data can be ported to any system.
RFPAll components of the solution must provide adequate redundancy to ensure high availability, with built-in redundancy in both hardware and connectivity so service is available 24x7.
RFPProposed solution should provide role-based security, encryption of data-at-rest, data in use, data-in-transit, and data on backup media.
RFPThe proposed version of the solution should be the latest stable & supported version from the OEM, with support available from the OEM for the entire contract duration, and a clear product roadmap in line with current technology trends.
RFPThe proposed cloud computing solution shall be configured, deployed, and managed to meet security, privacy, legal, ethical and compliance requirements; bidder to enable the financial institution in performing audit/review of IT controls of the CSP as and when required.
RFPThe Bidder should perform periodic Information Security assessments, IT Security audits, Vulnerability Assessment and Penetration Testing (VAPT), and other applicable security assessments for the application and underlying hosting infrastructure, and remediate all identified audit observations and security gaps within timelines specified in the financial institution's IT Audit Policy.
RFPBidder to submit an independent review report for the audit/review of IT controls from a CERT-In empanelled security consultant to ensure it meets the financial institution's information security requirements.
RFPBidder is required to perform security baselining, hardening, and implementation of security-related patches in OS or firmware before putting the application into production, and perform necessary changes to comply with security parameters identified by testing agencies within stipulated timelines.
RFPBidder shall ensure that only its authorized employees/representatives access the financial institution's Data, Logs and configurations, and shall be responsible for protecting its network and subnetworks from which remote access is performed against unauthorized access, malware and other threats.
RFPAvailability of L1 (Level 1) & L2 (Level 2) resource 24x7x365 support for the solution to meet the Service Levels, at no extra cost to the financial institution, including installations, configuration, integrations & log collection.
RFPBidder is required to provide RCA for all Critical and key issues for in-scope applications within 48 hours of the issue being identified/notified, and for significant issues, submit the RCA report within timelines defined by the financial institution.
RFPL2 resources should have good knowledge about the SIEM tool managing, integrating and troubleshooting; deployment of L2 on-premises must be during business hours.
RFPThe financial institution has the right to interview and reject resources deployed by the Bidder during any stage of the contract; bidder shall make necessary arrangement for replacement within defined timelines.
RFPBidder must ensure that DR setup is ready on the date of Go Live of the solution.
RFPBidder shall maintain following documentation and share the same during the contract; each batch job (if any) can, following a failure, be restarted, and bidder shall provide estimates of recovery time.
RFPBidder shall nominate points of contact (with named deputies) for the engagement.
RFPBidder shall comply with the Government of India Guidelines and Act on DPDP (Digital Personal Data Protection) and other acts/guidelines issued by GOI on a regular basis; proposed infrastructure & applications should also conform to standards of Government of India, IRDAI, and other applicable regulatory guidelines.
RFPThe financial institution's client machines do not require direct integration with, or installation of, SIEM agents; visibility into these endpoints will instead be achieved through integration of centralized Antivirus, XDR/EDR, and DLP solutions across approximately 4,000 client machines — confirm the proposed SIEM's ability to ingest telemetry from these existing centralized AV/XDR/EDR/DLP tools rather than deploying its own agents.
RFPThe MSSP should be a current legal entity in India and should have the experience of owning and managing a well-established Security Operations Centre (SOC) for at least five years; vendor shall provide the details of the SOC including the location, infrastructure, tools used, companies served, process and methodology, staff employed in India.
RFPThe MSSP should have performed managed SOC services for at least five clients during the last 3 financial years, with at least two of which should preferably be in the BFSI sector.
RFPThe MSSP's Account should not have been declared as a Non-Performing Asset (NPA) in the Books of any bank or financial institution as on 31.03.2025, and must submit an undertaking that no Government/undertaking organizations have blacklisted the bidder for any reason.
RFPMinimum Annual Turnover should be Rs. 50 Crores in each of the preceding three financial years; the bidder should be a profit-making entity, profitable in 2 years out of the past 3 financial years, with average turnover of Rs. 100 Crores in the last 3 financial years. Audited financial statements for FY2022-23, FY2023-24, FY2024-25 must be submitted.
RFPMSSP should have a remote SOC which is certified in major industry certifications: ISO-27001:2013 (ISMS), ISO-20000-1:2011 (ITSM), ISO-9001:2015 (QMS), ISO-22301:2012 (BCMS), PCI-DSS v3.2.1, CERT-In Empanelment, and Service Organization Control (SOC) 2 Type 2 Report; copy of certification including validity to be provided.
RFPMSSP to have an approved Business Continuity Plan to support the financial institution's group companies for continuity of SOC Operations, and must comply with all requirements in SEBI's Cyber Security and Cyber Resilience Framework (CSCRF) as per applicability, submitting a compliance certificate and audit report by a CERT-In empanelled vendor before onboarding and annually.
RFPVendor should monitor security logs to detect malicious or abnormal events and raise alerts for any suspicious events that may lead to a security breach; vendor should provide log baselines for all platforms under scope that are required to be monitored.
RFPVendor platform should have capability to collect logs from most standard platforms (Windows, Linux, AIX, Solaris, Firewall, network and other security devices), standard network/security devices, databases, web servers, cloud services (AWS/Azure), SaaS solutions, and O365.
RFPVendor should have a tool capable of detecting both internal and external attacks, monitoring security events on databases and servers, and should carry out correlations amongst logs from multiple sources to detect multi-vector attacks.
RFPThe vendor should bring workflows and solutions that can automate the majority of incident response activities such as false positive management, managing whitelists, escalation workflow, and SLA management; alerts should be notified to the financial institution only after a proper triage process and enriched with context data, environmental data, vulnerability data, historical data, and threat intelligence.
RFPService provider should have capability to integrate logs from non-standard applications and devices, processing them for alert/report generation through standard or custom parsers, and should have a Remote SOC certified in Major Industry Certifications (ISO, PCI, SOC1, SOC2, BCMS, ISMS, CERT-IN empanelled).
RFPSolution should have capabilities to define rules on event logs to detect suspicious activities such as failed login attempts, successful logins from suspicious locations, authorization attempts outside approved lists, vendor logins from unauthorized subnets, port scans, traffic from blacklisted IPs, and logins at unusual timings.
RFPThe proposed system shall capture all raw log, event and alert details and normalize them into a standard format; the solution should prevent tampering of any type of logs, log any attempts to tamper logs, and provide encrypted transmission of log data to log management.
RFPVendor should have a tool capable of monitoring, detecting and managing incidents for database security events (access to sensitive/PII data, database logins with client IP/server IP/source program info, admin command auditing) and IT infrastructure security events (buffer overflow, port/vulnerability scans, password cracking, worm/virus outbreak, unauthorized firewall rule changes, SQL injection, XSS, layer 7 web attacks) via integration with the WAF/Firewall solution deployed at the financial institution.
RFPVendor should monitor, detect and manage incidents for business application security events including attempted segregation-of-duties violations, critical user additions/deletions, changes to critical application roles/groups/permissions/parameters, and changes to audit parameters.
RFPThe SOC solution must provide central management of all components and administrative functions from a single web-based user interface for SIEM, NBAD, and UBA; SIEM solution should correlate events and flows together to generate incidents.
RFPSolution should support centralized incident management and triaging of alerts from multiple security products (SIEM, DLP, IPS, WAF, Anti-APT, ETDR); investigation module should integrate with log sources (SIEM, ETDR, EPP, Data Lake) on demand to pull data related to the investigated alert with charting and graphing to analyse data.
RFPSolution should provide case management features to store raw and analysed data for a specific alert or set of alerts, provide run books for investigation steps corresponding to different types of attacks, and support integration with open source or commercial IOC sources — list the supported sources and integration approach.
RFPSolution should support quick response to ongoing incidents with remote configuration of parameters in servers/desktops, firewalls, AD, IPS, WAF, and network switches/routers, and support automated remediation for commodity threats (e.g. recall malicious mails, block bad IPs, disable bad users in AD).
RFPSolution should support full workflow for incident classification, coordination, escalation, exception approvals, and tracking of security exception approvals; SP to provide a ticketing tool with SOC operations access to the financial institution.
RFPUse algorithms and tools to actively hunt for attacks in large volumes of data, create alerts passed to analysts (using a big data platform for collection/analysis), define/develop/implement/update/maintain a Hunting Framework with strategic hunt missions and IOC search from threat intelligence, and create a knowledge base of IOCs.
RFP(Optional) Provide mitigation recommendations for in-scope infrastructure based on vulnerability reports shared by the financial institution, and correlate vulnerability information with the threat management system to get a 360-degree view of assets in scope.
RFPService provider team supporting the financial institution should have security analysts, threat hunters, and SIEM administrators; bidder must have skilled OEM-certified staff at L1/L2/L3 levels with expertise in event monitoring, incident detection/response, threat intelligence, use case engineering, threat hunting, and security analytics — more than 20 OEM-certified engineers scores maximum points; more than 200 cyber security skilled (non-outsourced/franchised) engineers scores maximum points.
RFPVendor shall build SIEM solution capacity to handle log retention of six months online and two years offline, providing 24x7x365 real-time log monitoring, analysis, correlation, threat hunting and threat intelligence including IOCs and other threat intel.
RFPIf connectivity between log collection agents and logger is down, log collector agents should store logs for at least 3 days and forward them once connectivity is re-established (applicable to cloud-based or separate logger/processing configurations).
RFPProvide a daily report of events/incidents/correlation/analysis/recommendations, and a monthly report summarizing events/incidents, correlation analysis, recommendations, status of actions by the financial institution, security advisories, and month-over-month trend analysis; weekly advisory details should also be provided.
RFPSOC setup/infrastructure may be subjected to audit from the financial institution and/or third party and/or regulatory body; the vendor must cooperate, provide information/support to auditors, and ensure audit observations are closed on top priority and not repeated in subsequent audits.
RFPVendor should provide different dashboards/screens for different roles (Top Management, IS Team, Auditors) for viewing real-time incidents, events, alerts and status of actions taken; the offered cyber security product shall assist compliance with SEBI guidelines on cyber security for financial intermediaries.
RFPStandard Operating Procedures (SOPs) shall be developed for all products/solutions/services provided including alert management, incident management, forensics, report management, log storage/archiving, SOC business continuity, operational documents, escalation matrix, change management, use cases, knowledge documents, and playbooks.
RFPThe solution proposed should be in the Gartner Magic Quadrant for SIEM for the last 5 years, must provide canned out-of-the-box reports for compliance regulations (PCI, SOX, FISMA) and control frameworks (NIST, COBIT, ISO), and provide a single portal for dashboards, reports and incidents.
RFPSLA metrics required: Time to Notify (10/15/30/60 min by severity P0-P3), Time to Triage (45/60/90/120 min), Time to Diagnose (90/120/180/240 min); penalties apply on a sliding scale from no credit at 99%+ SLA compliance up to 20% of MRC below 96%, capped at 20% of ARC aggregate.
RFPSubmit a compliance certificate certifying compliance with the SEBI Cyber Security and Cyber Resilience Framework (dated 20 Aug 2024) before onboarding and every year until contract expiration, and submit SOC efficacy testing results on a half-yearly basis per SEBI CSCRF format.
RFPResident Engineer scope of work: coordinate with the financial institution's internal teams to optimize SOC operations and Infosec activities, ensure smooth/complete migration from the existing SOC service platform, manage SOC process/technical documentation, and provide monthly progress reports on new integrations, enhancements and SOC maturity model.
RFPProposer must deliver 24x7 SOC monitoring and incident response, management of the agency's Microsoft Sentinel SIEM platform (configuration and log integration), alert triage/investigation/remediation support and post-incident analysis, security process development and documentation, annual tabletop exercises for incident response testing, and a block of 80 professional services hours for strategic advisory — all within a maximum annual budget of $150,000.
RFPProposer must operate/manage the agency's existing agency-hosted, customer-owned Microsoft Sentinel instance — the RFP does not accept alternative SIEM platforms — performing initial assessment, configuration refinements, integrations, analytics rule tuning, and ongoing SIEM management (all log collection, enrichment, correlation and alerting must occur within agency-hosted Sentinel).
RFPProposer must describe how it will handle log sources across the agency's ~2,500 users and ~3,000 endpoints (all enrolled in EDR, 70% Windows/30% mobile), integrating with M365 E5-licensed platforms (Defender for Endpoint/Identity/Office 365, Azure AD/Entra ID, Defender for Cloud) at an estimated ingestion volume of 100GB/day.
RFPProposer must define connectivity/access method for MSSP SOC access to the Sentinel environment adhering to least privilege (Azure Lighthouse delegation generally preferred, dedicated VPN also acceptable), with access following agency-approved least-privilege principles.
RFPContractor shall provide enterprise cybersecurity and network monitoring support services in a managed services model, furnishing all management, supervision, labor, processes, and associated support necessary to meet continuous monitoring objectives.
RFPTask Area 2: Contractor shall provide integrated 24x7x365 SOC/NOC support to monitor, analyze, triage, escalate, coordinate and report on cybersecurity and network events; perform event intake, triage, initial analysis and escalation per defined priorities/SLAs/SOPs; and provide network monitoring for outages, degradations and anomalous behaviors with cyber/network event correlation.
RFPContractor shall execute hypothesis-driven threat hunting to identify abnormal behavior evading automated detections, conducting daily proactive hunting within all SIEMs and telemetry sources based on vulnerability/threat reports and intelligence feeds; document all hunting investigations in Splunk (or approved mechanism) with a Knowledge Base article created/linked within 5 business days of every closed investigation.
RFPTask Area 3: Contractor shall support administration, configuration, sustainment, enhancement and optimization of SIEM-related capabilities, including onboarding/integrating new data sources, normalizing/validating telemetry, tuning alerts/rules, and supporting correlation logic; conduct detection refinement (tuning SIEM rules, EDR alerts, WAF/CDN policies) and continuously validate telemetry from sources including Zscaler SASE and Microsoft Defender, identifying/correcting configuration drift.
RFPExperience in implementing/supporting a well-established Security Operations Centre (SOC) in the last 3 years for at least 3 BFSI/PSU clients, of which a minimum of one must be a Bank; references of major clients must be provided.
RFPBidder should have a minimum turnover of Rs. 100 crore in each of the last three financial years and be profit-making in at least two of those years; must never have been blacklisted/barred by any Central/State Government or PSU financial institution in India, and must not be an NPA holder in any Bank in India.
RFPThe proposed team should be CISSP/GIAC/CISA/CISM/CCNA/GSEC certified with at least 3 years of defined-scope experience; bio-data of personnel to be deployed must be submitted indicating qualifications, professional experience and projects handled, and key personnel must have been sufficiently involved in similar past projects.
RFPThe bidder must have a direct partnership with the SIEM tool's OEM, evidenced by OEM Associations/support agreement letter on OEM letterhead; a System Integrator may bid with only one OEM for the SIEM solution, and reference SOCs must have been operational in India for a minimum of two years as of 31/12/2016.
RFPThe SOC should be able to integrate various log types and logging options into SIEM, ticketing/workflow/case management, unstructured/big data, reporting/dashboard, and customized use cases/rule design based on risk and compliance requirements, in adherence to RBI cyber security circular RBI/2015-16/418; the SOC setup should meet ISO27001, PCI-DSS and OWASP requirements and the Bank should be able to obtain certification from an independent entity.
RFPThe System Integrator is responsible for AMC, licenses, uptime and management of devices/solutions implemented as part of the SOC; all L2/L3 and device management resources should be on the bidder's own payroll (L1 subcontracting requires prior Bank approval).
RFPFunctional requirements: ability to protect critical infrastructure from ongoing security threats; 24x7 log and security event monitoring across IT infrastructure, WAN, ATM, Internet banking, mobile banking and interfaces (servers, routers, firewalls, IDS); evaluation of cyber security incidents including origin-of-threat identification, chain-of-custody/evidence preservation, and proactive threat intelligence impact assessment.
RFPServices/solutions should be modular and scalable to address a 50% increase in monitored devices/solutions over the 5-year contract period, designed with adequate redundancy/fault tolerance for SLA uptime compliance, and should have no significant impact on existing infrastructure during installation or operation.
RFPBidder shall co-develop threat use-cases and correlation rules with the Bank, integrate alerts/offences with the Bank's existing ticketing tool (CA Service Desk), and provide security intelligence continuously; the SIEM solution proposed must be in the Gartner Leaders' or Challengers' quadrant, with post-sales support through established India-based service centers and OEM-guaranteed support for a minimum of 5 years (extendable by 2).
RFPDeploy SIEM for in-scope infrastructure ensuring fully integrated, customized SIEM Security Analytics, MIS Dashboard, and Forensics functionality including incident forensics/session recreation and packet capture/network forensics; develop parsers for non-standard logs and write custom parsers for unsupported devices (35 custom parsers included, additional parsers billed separately).
RFPSolution should be capable of handling a minimum of 1400+ devices at 30,000 EPS at project start with 100% scalability to 60,000 EPS over 5 years, query response time of 30 seconds, and log monitoring within 30 seconds of capture; bidder must detail cost for scaling beyond 30,000 EPS in 5,000-EPS increments.
RFPLog Management/Storage: logs available for live correlation/analysis online for 3 months and offline for 6 months; restoration of historical logs (at least 180 days) must be demonstrable at any time; historical log analysis must extend to a minimum of 5 years in the past; offline logs archived for regulatory/legal/audit/forensic use; BCP/DR planned with HA log collector in DC (primary site) and DR (secondary site, standby).
RFPSolution should index all original unmodified data (no normalization/reduction) for full-text search across any field including time ranges and regular expressions, support statistical analysis (counts, distinct counts, sums, min/max), and provide easy customizable dashboards (tables, charts, Geo-IP maps) with real-time updates, drill-down/click-through from summaries to raw events within seconds.
RFPSolution should detect multiple event types (inappropriate application use, fraud, advanced low-and-slow threats, APTs), collect Layer 7 network flow data from switches/routers/firewalls/DHCP, correlate global threat intelligence feeds against collected logs to identify IOC activity, and analyze user activity patterns for anomaly/behavioral detection across applications, hosts, users and network.
RFPSolution should integrate cloud-hosted platforms into the SIEM (event and network flow data) and perform deep packet forensics analysis on packets integrated from a packet analysis solution; provide connectors for the full device inventory in Annexure 1 with custom parser coding at no additional fee.
RFPProvide dashboards tailored to Top Management/Board, Department Heads, CISO (complete detailed security-posture dashboard), System Administrator and Network/Security Administrator roles; provide executive summary reports, weekly/monthly/quarterly intelligence summaries, and trend analysis to the Board.
RFPBidder must provide training to identified Bank personnel (10x2) on solution/service architecture pre-implementation, and hands-on training on SIEM policy configuration/alert monitoring post-implementation (train-the-trainer not permitted); provide periodical security-awareness sessions on latest threats/vulnerabilities for Bank staff including executives/Board members.
RFPBidder must provide 24/7 on-site manpower across DC and DR sites with defined L1 (1-3 yrs), L2 (3-8 yrs), and L3 (7+ yrs) staffing levels per shift per the resource allocation table.
RFPProject timelines: Phase I (existing networking/security devices without custom parser needs) implemented within 4 months of PO; Phase II (existing security solutions/DR infrastructure without custom parser needs) within 6 months; Phase III (systems/applications requiring custom parser development) within 8 months; new future solutions must be onboarded within one month of their implementation.
RFPContractor shall ensure audit logs are reviewed and regular audits conducted for security and accountability, and work with IT Security Operations to integrate audit logging into the organization's SIEM tool, if possible.
RFPSecondary Red Team objectives: establish persistent access and maintain stealth, lateral movement across network segments/geographic boundaries, privilege escalation to critical administrative roles, exfiltration of sensitive data without detection, and bypassing of security controls (EDR, SIEM, DLP, MFA).
RFPPhase 2 roadmap: solution should support Role Mining, Fine-Grained Access Control, SIEM/DLP integration, integration with the Cherwell service management tool, Multi-Factor Authentication, advanced Access Review and Certification, and Privileged User Management.
RFPProvide logging: audit logs for all administrative role actions and all user events (claimed account, reset password, added MFA devices, authenticated to application), with support for log export to SIEM, Azure App Insights, or other logging facility.
RFIVendor shall deploy automated tools to collect, correlate, and analyze security event logs from multiple sources and monitor them for suspected security incidents on Vendor networks and information systems used to provide services to the agency.
Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.
Open, search-powered SIEM with native endpoint/XDR and built-in workflows (no separate SOAR), with flexible deployment.
Flexibility and openness can require more in-house engineering to operationalize.
ExabeamAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
Cloud-native New-Scale SIEM with strong UEBA/behavioral analytics and an AI agent for investigation.
Analytics-led positioning; very large raw-log/search use cases are emphasized less than behavioral detection.
IBMAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
QRadar SIEM with long enterprise heritage, strong correlation, and X-Force threat intelligence.
Traditional architecture; modernization toward a cloud-native QRadar Suite is in transition.
MicrosoftAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
Sentinel is a cloud-native SIEM deeply integrated with Azure, M365, and Defender XDR, with consumption pricing.
Value is concentrated in the Microsoft ecosystem; multi-cloud/heterogeneous parity is emphasized less.
Rapid7AI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
InsightIDR cloud SIEM with built-in user behavior analytics, curated detections, and an MDR option for lean teams.
Positioned for mid-market simplicity; very large custom-analytics use cases are less central.
SecuronixAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
Cloud-native Unified Defense SIEM with UEBA, SOAR, and agentic AI on a scalable cloud backend.
Breadth of the platform can add tuning and configuration effort.
SplunkAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
Flexible, powerful SIEM (Enterprise Security) with a vast app ecosystem, the SPL search language, SOAR, and UBA.
Data-volume pricing can be costly at scale, and the platform's power comes with operational complexity.
Sumo LogicAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
Cloud-native log analytics plus Cloud SIEM with elastic scale and security analytics.
Cloud-only; deep on-prem or air-gapped scenarios are less central.