The goal of this tender is to find a contractor who will: • set up a fully operational SOC that takes into account the specifics of the MGS • continuously operate the SOC • provide comprehensive monitoring and incident response services.
In addition to the headquarters in Munich (Haager Str. 5), the MGS has small branch offices in the renovation areas of the state capital. The majority of the IT landscape (e.g., workplace systems, network) is operated by external service providers. Firewalls are used in the network, and Windows Defender is already installed on the workplace systems. Currently, no SOC is in operation, so this needs to be newly conceptualized and implemented. An XDR solution is also not yet in use.
LOT-0001
Managed Security Operations Center (SOC).
Project
The contractor will provide a project manager as a contact person for the MGS for the implementation project. The implementation project must be completed by September 30, 2025, and must include the following points: • Analysis of the current IT infrastructure and security measures • Development of an implementation plan for the SOC • Establishment of clear milestones and schedules for the implementation and commissioning of the SOC • Procurement and establishment of the necessary hardware and software infrastructure • Integration into the existing IT infrastructure of the MGS • Coordination and definition of SOC processes • Coordination of responsibilities, roles, interfaces, and personnel • Creation of playbooks in coordination with the MGS. A milestone plan with clear responsibilities and accountabilities must be agreed upon with the MGS for the implementation of the project.
Operation
The Security Operations Center will be operated until January 31, 2028, and will cover the following aspects: 24/7 monitoring and management of security events and incidents • Proactive threat detection and analysis • Incident response and recovery measures • Continuous review and improvement of security measures • Maintenance and servicing of the SOC infrastructure (including applying patches). For details, see Chapter Requirements for the SOC.