Write a RFP (Request for Proposal) for a vendor.

Firm Details

Your firm is a security services provider. Your clients include organizations of various sizes, but most clients are state and federal government agencies that must demonstrate compliance with specific security-related regulations. Your firm was formed in 2005, as a small corporation with only four employees. At that time, the firm’s focus was to provide database performance tuning and security services for database applications. By 2012, your firm routinely provided complete security services, including assessments, penetration tests, policy creation, and regulatory compliance assistance. The firm’s annual gross sales are currently 2.6 million U.S. dollars.

Currently, your firm seeks opportunities to address security-related issues and prepare government agencies and mid-sized organizations to operate in a more secure manner. You currently have two ongoing contracts for providing managed security services for federal agencies that regulate commerce and land management.

Your firm currently has its headquarters and the only office in a different state from the organization that has issued the Request for Proposal (RFP). You have explored opening another office but have not decided on the best location.

Your organization has grown to 24 full-time employees, including 8 employees who will focus on providing services and products for this new opportunity, should your firm be awarded the contract. These eight people are currently working on a contract that expires in two months and will be available as resources at that time. Of the eight people who will work on the new prospective products and services, five hold Certified Information Systems Security Professional (CISSP) certifications, four hold Certified Information Security Manager (CISM), four hold Global Information Assurance Certification (GIAC) Security Essentials Certification (GSEC), and six hold other GIAC certifications.

Your firm has won four major contracts in the last four years for vulnerability assessments and penetration tests. Your firm does not currently offer services that review source code to assess its security and does not employ development security specialists.