Software development services (Германия - Тендер #47613195) | ||
| ||
| Для перевода текста тендера на нужный язык воспользуйтесь приложением: | ||
Страна: Германия (другие тендеры и закупки Германия) Организатор тендера: SPRIND GmbH Номер конкурса: 47613195 Дата публикации: 31-10-2023 Источник тендера: Единая система закупок Европейского союза TED |
||
Germany-Leipzig: Software development services
2023/S 210-663007
Voluntary ex ante transparency notice
Services
Section I: Contracting authority/entity
Section II: Object
Open Source Technology Improvement Fund, Inc
The Open Source Technology Improvement Fund is a corporate non-profit dedicated to securing open source apps that we all depend on. Responsible for over 10,000 hours of coordinated work, 400+ patched vulnerabilities, and over 50 security engagements of critical open source projects, OSTIF is working toward being a leader in helping improve security in Open Source.
The Soveriegn Tech Fund (STF), whose mission is to support Open Source Infrastructure, is seeking to commission the Open Source Technology Improvement Fund (OSTIF), Inc, and its partners to perform security audits of critical third-party FOSS Infrastructure projects and offer process improvements services to improve security posture. Security audits are crucial for critical open source infrastructure because they help identify and mitigate potential vulnerabilities and weaknesses in the software. By conducting security audits, critical open source software can proactively assess the security posture of their code and infrastructure and address any issues before they are exploited by malicious actors.
These audits provide valuable insights into the overall security of the system, ensuring that it meets the highest standards and reducing the risk of security breaches. Additionally, security audits help build trust among users and industry by demonstrating a commitment to the security and integrity of the open source infrastructure. This assurance based approach complements and builds upon STF’s investments in securing Open Source infrastructure, particularly the Bug Resilience Project, STF’s preventative security program.
OSTIF will execute security engagements for critical third-party FOSS infrastructure as determined by STF and the Managed Audit Program. Our proposed contracting structure would be a Master Services Agreement with particular audits requested via Statement of Work requested by STF. This will allow STF with the capacity for providing audits in collaboration with OSTIF as need arises to secure critical software
infrastructure.
For each audit, deliverables will come in the form of: Audit Reports, Vulnerability and Bug Fixes, and other associated Security Improvements made to the target projects.
Section IV: Procedure
As a research and development service, the contract is excluded from the scope of application of public procurement law (cf. Section 116 (1) No. 2 Act against Restraints on Competition).
Section V: Award of contract/concession
Section VI: Complementary information