Consulting for the evaluation, implementation and comprehensive management of information security in the health sector
Start date
Closing date
Country
El Salvador
Sector
Technology
Project
ES-L1160Important Notice
This action will open an external link.
Description
El Salvador, through the Ministry of Health (MINSAL), has financing from the Inter-American Development Bank (IDB) for the "Smart and Comprehensive Health Program". This call invites eligible consulting firms to submit their expressions of interest for the evaluation, implementation and comprehensive management of cybersecurity in the digital platform of the health sector.
Scope of the consultancy
Main objective: To design and implement a comprehensive regulatory and cybersecurity framework aligned with international best practices to protect the critical infrastructure and digital platform of MINSAL (Integrated Health System, clinical records and laboratory network) against threats such as ransomware and unauthorized access.
Methodological phases of execution:
Phase I: Assessment, maturity diagnosis and mapping of critical risks.
Phase II: Design of the strategic and documentary framework on cybersecurity architecture.
Phase III: Technical assistance plan and sustainable transfer of knowledge and methodologies to institutional staff.
Qualification and Experience Requirements
Certifications and infrastructure of the firm: ISO 27001 certification and possession of its own Security Operations Center (SOC) or, failing that, reliable documentary support of the successful implementation of SIEM solutions in previous clients.
Verifiable technical experience: Projects executed between 2023 and 2025 in cybersecurity, risk diagnosis and implementation of SIEM in the public, private or health sectors (accrediting at least two detailed references with complete contact details and summary of activities).
Competencies of the consulting team: Mastery in security audits, risk analysis, penetration testing (pentesting), network management, operating systems (Windows Server and Linux: Ubuntu, RHEL, CentOS), edge equipment (Firewall, IDS, IPS, EDR, XDR) and auditing tools (open-source and licensed such as OpenVAS, Nmap, OSSEC, Wazuh, Metasploit).
Proposal selection and management
Regulatory framework: Selection made under the IDB's Consulting Policies for the integration of a short list of between five (5) and eight (8) eligible firms.
Modalities of participation: The application of firms is allowed individually, in association (Joint Venture / APCA) or through the inclusion of sub-consultants.
Delivery method: Submission of expressions of interest in physical printed format (electronic bids are not allowed).
Note: Tender documents and annexes are available in the official language of the country.
Follow Us