Germany – IT services: consulting, software development, Internet and support – 81322863 - Framework Agreement (FA) for Conducting IT Audits to Cover Capacity Peaks and/or Utilize External Expertise for the Internal Audit Staff Unit
GIZ carries out advisory projects in approximately 90 countries in Africa, Asia, Latin America and Europe. These projects are supported adm by the head offices in Eschborn and Bonn and by the approximately 80 field offices in the partner countries and in Germany
Opportunity description
GIZ carries out advisory projects in approximately 90 countries in Africa, Asia, Latin America and Europe. These projects are supported administratively and professionally by the head offices in Eschborn and Bonn and by approximately 80 field offices in the partner countries and in Germany. GIZ primarily uses public funds. Its main commissioning party is the German Federal Ministry for Economic Cooperation and Development (BMZ). In addition, GIZ also works for other, predominantly international commissioning parties. To obtain these contracts, GIZ competes internationally and participates in corresponding invitations to tender through a separate, fully taxable unit, "International Services". The procedural workflows set out in GIZ's internal rules and regulations, "Processes and Rules" (PuR), the principles of proper accounting (GoB), GIZ's principles of integrity, the legal framework conditions (framework agreement, general contract), and contractual agreements with our commissioning parties are the company-wide binding requirements for all business processes. The Internal Audit Staff Unit reviews compliance with these requirements. The subject of this invitation to tender is the conclusion of a framework agreement (FA) for conducting IT audits to cover capacity peaks and/or utilize external expertise. These IT audits must be conducted in accordance with the relevant International Auditing Standards (such as IIA, ISACA and ISO/IEC). At the contracting authority's request, audits must also be conducted by mixed audit teams consisting of employees of the Internal Audit Staff Unit and the contractor (so-called "Joint Audits"). The aim is to transfer specialist and methodological knowledge/expertise from the contractor to the contracting authority. Audits may require travel on site, including to fragile states and crisis-affected countries. Travel to fragile states and crisis-affected countries is expected of the contractor when GIZ also has employees seconded from Germany on site. If GIZ withdraws this personnel for security reasons, we do not expect the contractor's employees to conduct audits on site. The audit assignment relates to conducting the following audits: IT processes To provide its services, GIZ is critically dependent on adequate, reliable and secure IT support. At the same time, GIZ's strategic objectives include the consistent digitalization of business processes. To this end, extensive digitalization projects with substantial budgets, among other things, have been initiated. The assignment may cover both IT processes and technical IT security aspects. Audit areas corresponding to the IT Audit Universe of the Internal Audit Staff Unit include, among others: - IT Governance, Strategy and Organisation - IT Operations (including Archiving, Hosting, Cloud, License Management, Third-Party Providers, Maintenance) - IT Support - IT Security (including User and Identity Access Management, Screening and Monitoring, Intrusion Detection, ATP, Incident Management) In addition, project-related audits in accordance with the requirements of IDW PS 850 may be commissioned for selected (large-scale) GIZ projects. At the application level, application security audits are planned in particular for the SAP application (currently SAP S/4HANA). The professionally relevant ITGC (IT General Controls) must be applied here, at the application, database and operating-system levels. The commissioning of IT audits may also include partial aspects/audit areas within a larger (IT) audit. For example, the need for a Vulnerability Assessment and Penetration Testing (VAPT) of individual applications may arise as part of a process audit. The respective audits will be accompanied by employees of the Internal Audit Staff Unit, and a corresponding transfer of specialist and methodological knowledge from the contractor to the contracting authority is expected. Procedure: open. Review the original TED notice for the complete requirement, lots, amendments and attachments.
Business details are available after sign in
Codes, capabilities, evidence, buyer details and marketplace actions are withheld from the public HTML and API response.