Provide assessment of a client's operating effectiveness of their ICT environment

Job ID: 34071189

Budget: $750 – $1,500 USD

Objectives will include:
2.1 Evaluate the client's systems and processes to ensure that they are able to secure Fund data;
2.2 Determine whether there are potential risks to the Fund’s information assets and ways to minimise those risks;
2.3 Verify the reliability and integrity of information;
2.4 Check that information management processes are compliant with IT specific laws, policies and standards;
2.5 Determine whether there are any inefficiencies in the ICT systems and management thereof and
2.6 Where any risks/ weaknesses are noted, recommend remedial actions plus any required tools.
3.0 SCOPE OF SERVICES
The Terms of Reference for the ICT assessment and system penetration testing are to provide assurance on the following:
3.1 Operations, programs and systems are appropriately managed to support the scheduling, execution, monitoring, and continuity of ICT programs and processes for the complete, accurate, and valid processing, recording, update and storage of financial and members’ transactions;
3.2 The Management Information system that is currently under development meets the minimum required software development standards;
3.3 In the event of a disaster at the primary site, essential business processes and information systems can be recovered timely;
3.4 Systems security is appropriately implemented, administered, and logged to safeguard against unauthorised access to or modifications of programs and data;
3.5 Configurations and programs, and systems changes are appropriately managed to minimise the likelihood of disruption, unauthorised alterations, and errors which impact the accurate, complete, and valid processing and recording of financial and members’ information.
3.6 The data architecture is appropriately defined and implemented to organise data in a manner supporting the accuracy, completeness, and validity of financial and Members’ information.
3.7 The software applications in use have current and valid licences.
3.8 Carry out Network vulnerability detection and system application penetration testing for the client's systems;
3.9 The information management processes are compliant with IT-specific laws, policies and standards;
3.10 The client has the relevant ICT policies and procedures in place;
3.11 Appropriateness and effectiveness of ICT equipment that includes, servers, laptops, desktop computers, CCTV, and access control, and
3.12 Any risks to the client’s information assets and methods to minimise those risks.
4.0 DELIVERABLES
4.1 Initial draft report highlighting the following:
• A Review of the ICT environment;
• The findings arising from the review;
• Evidence to support the findings as appropriate;
• Recommended strategic ICT goals and operational objectives;
• Recommendations on corrective action to be taken;

The client is based in Zambia