Dynamic purchasing system for consulting services within information security. The system typically includes:
• IT and information security, digital emergency preparedness and privacy, including advise, management system/internal control, emergency preparedness plans, follow-up of legal requirements, etc.
• risk assessments and management;
• security-specific testing, including penetration tests, vulnerability scanning, etc.
• preparation and assessment of ROS analyzes;
• internal control/audit;
• governance security and preparedness;
• compliance with legal requirements and other requirements (method, tools, etc.);
• privacy/GDPR;
• privacy impact assessment (DPIA);
• studies, analyses in general/ad-hoc and development of new security methods/technology;
• behavioral economics, decision making and communication.
There will be a need for expertise in national and international frameworks, standards and concepts within information security and emergency preparedness.
Frequency and scope of competitions is somewhat uncertain, expected value is approx. NOK 15 000 000 per year.