You are on page 1of 8

Communication & Acquisition

Quincey Jackson

CSOL, University of San Diego

CSOL-550-04-FA22 - Management and Cyber Security

December, 12 2022
Request For Proposal

Communication & Acquisition


BioHuman Corp
PROPOSALS DUE BY: February 13, 2023

Company Background

● BioHuman is a Fortune 500 pharmaceutical company located in San Diego,

California. BioHuman has about 500 employees and is still growing with only about

50% of the company fully staffed.

Project Overview

● BioHuman is seeking help from well qualified vendors to develop and deliver a

Cyber Awareness Training program.The program must be delivered as a software

application and must be capable of being deployed to both remote and on-site

employees. With a turnaround time of approximately 2 months to complete a strong

bid for the job and another, more intense turnaround time of about six months to

have the final Cyber Awareness training launched, the selected vendor must have

extensive experience in software development and deployment to win the bid.

Project Goals

The goals of this project include:

i. All BioHuman employees will be trained in cyber security awareness by June 2023.
ii. Selected vendor will deploy a cyber awareness training application and provide 24/7

customer support to BioHuman employees.

iii. BioHuman will own the rights to a cyber awareness training application that can be

reused to train incoming employees.

To reach these goals, BioHuman Corp is now accepting bids from vendors for the next 60
days.

Scope of Work

● BioHuman is in need of a Cyber Awareness Training program.

● BioHuman will need a third-party vendor to develop and deliver the training

program as a software application to be able to deploy the training to both onsite

and remote employees.

● Vendors will have 60 days to create a proposal for the BioHuman bidding process.

● If selected, vendors will have six months to complete the training and deploy to

BioHuman staff.

● Vendors must provide 24/7 customer support for training to accommodate remote

workers.

● Vendors must have full liability insurance in case of a cyber breach.


● BioHuman will own the rights to the cyber awareness training that can be used
multiple times for incoming employees.

Target Deliverable Schedule

Final Project Due: May 13, 2023

The expected project completion date is [May 13, 2023]. BioHuman is giving

candidates 60 days to bid for the project. After 60 days, the final application is expected on
or before May 13, 2023. If this date needs to be adjusted, please include your readjusted

proposed date, as well as your reasoning for shifting the schedule. All proposed date

changes will be considered.

Existing Roadblocks Or Technical Issues

● Vendors must be prepared to offer 24/7 technical support to remote employees from
different time zones.
● BioHuman is a pharmaceutical company that must protect all clients, patients and
employees.
● Vendors will have less than six months to design a cyber awareness training.
● Vendors are prohibited from using any other third party companies.
● BioHuman staff must be trained within 30 days of receiving the training. 24/7
technical support will be required.
● Vendors must showcase prior training that has been deployed by the company.

Budget Constraints

It’s important to be upfront with your budget. The more you can eliminate surprises, the better
for all parties involved.

● Potential vendors must provide an estimate for cost of services upon completion of
the proposal.
● All changes or upcharges must be approved before integration into the new
application.
● Requests for budget increases must be made at least two weeks prior to the changes.
● BioHuman will require a financial report upon completion of the application to
determine the potential costs for patches and updates in the future.
● BioHuman will not be financially responsible for patches and updates to the
deployed software for the first 120 months after deployment.

Evaluation Metrics

BioHuman Corp will evaluate bidders and proposals based on the following criteria:

● Previous experience/past performance history.- BioHuman will avoid any third-party


vendor that has a recent history of cyber attacks or lawsuits due to negligence.
● Samples and/or case studies from previous projects.- BioHuman is only interested in
vendors that have completed similar projects.
● Projected costs.- Vendors will provide an application along with 24/7 customer
support. BioHuman will avoid vendors with hidden costs.
● Experience and technical expertise.- Vendors will provide a sample of related work to
be analyzed during the bidding process.
● Responsiveness and answers to questions in the next section.- Vendors will be
interviewed during the bidding process to ensure they meet all expectations.

Questions Bidders Must Answer To Be Considered

i. Does the potential vendor have full liability insurance in the event that there is a security

breach? Will vendors take full responsibility for being commissioned with the task of

creating company software?

ii. Does the potential vendor have a sample of their applications and software for review?

BioHuman would like to see samples to better understand the vendor and what they will

bring to the table. Examples include recent applications that have been developed by the

vendor with annual reports to show the positive and negative impact of the applications.

iii. Has the potential vendor ever experienced a cyber attack? How long was the system

down? How were daily activities altered? Was the potential vendor deemed liable for the

damage that occurred?

iv. Does the potential vendor meet the budget requirements set out by BioHuman?

v. Will the potential vendor be able to complete the software and test for any vulnerabilities

before deployment?
vi. Will the potential vendor utilize any third-party applications or services at any time

during the designing or deployment of the software?

vi. Will the potential vendor have a backup of all information in the event of a cyber

attack? Are backups in a secure off-site location?

Submission Requirements

Bidders must adhere to the following guidelines to be considered:

● Only bidders who meet all 5 metrics in the evaluation section should submit a

proposal.

● Proposals must be sent in by February 13, 2023. Bidders who are interested in

submitting a proposal should inform Quincey Jackson + qjackson@sandiego.edu no

later than February 13, 2023.

● Include samples and references with your proposal.

● Proposals should not be more than [7] pages. Failure to comply with this guideline

will result in an automatic rejection.

● A proposed schedule must also be included and clearly expressed.

What We’re Looking For in Potential Vendors

The ideal vendor that will create BioHuman’s Cyber Awareness Training must have

expertise on the subject matter. The expertise must be shown in samples and references

used in prior projects. BioHuman is looking to utilize the Cyber Awareness Training until

new laws, regulations and compliance items force the company to update or create another

training. All vendors must be covered by full liability insurance and will be prohibited from
working with any third party companies to complete the software application for

BioHuman.

Vendors must provide a schedule to BioHuman cyber leads for all tasks and test

dates leading up to the six-month deadline of the project. Vendors must keep a log of

activities that will be finalized and added to the final report upon completion of the

software. All logs and software tests must be reported to BioHuman.

Lastly, vendors must be prompt and willing to adjust to needs and requests from

BioHuman at a moment’s notice.

Contact Information

For questions or concerns connected to this RFP, we can be reached at:

Quincey Jackson
qjackson@sandiego.edu
310-940-8534
References

Usmani, F., et al. (2022, October 5). Assumptions and constraints in project management.
Home Page. Retrieved December 11, 2022, from
https://pmstudycircle.com/assumptions-and-constraints-in-project-management/

William, J. (2020, June 9). Council post: Five things to consider when selecting an
outsourcing vendor. Forbes. Retrieved December 11, 2022, from
https://www.forbes.com/sites/forbesbusinesscouncil/2020/06/10/five-things-to-cons
ider-when-selecting-an-outsourcing-vendor/?sh=3a8956c35dea

You might also like