The Department of Home Affairs (DHA) has announced a tender for a multi-factor authentication and non-repudiation logical access control solution, marking a significant development in the country's cybersecurity landscape. This move comes as a response to the increasing sophistication of cyber threats and the need to protect sensitive government data. The successful bidder will be tasked with developing and implementing a robust system that ensures only authorized personnel have access to core DHA applications, thereby safeguarding against identity abuse and unauthorized transactions.
The tender documentation highlights the DHA's existing biometric access control management system (BACM) deployed in 2005, which has been integrated with various systems such as the National Population Register and Movement Control System. This system, however, is now reaching the end of its lifecycle, necessitating an upgrade to a more advanced, multi-factor authentication solution.
The new system will leverage a combination of smartcards/tokens, advanced digital signatures, and biometrics to provide a multi-layered security approach. It will also include non-repudiation capabilities, ensuring that users are legally bound to their transactions and providing a clear audit trail. This level of security is crucial in preventing unauthorized access and protecting sensitive government data.
One of the key features of the tender is the emphasis on user-centric design. The successful bidder will be expected to perform the enrolment and onboarding of a large number of users (upwards of 6,000) and provide comprehensive training to DHA IT officials nationwide. This approach ensures that the system is not only secure but also user-friendly, with minimal configuration or customization requirements on DHA systems.
The tender also includes a requirement for the bidder to read the authentication and non-repudiation system data currently stored in the vault and produce forensic evidence within a prescribed period. This demonstrates a commitment to transparency and accountability, ensuring that the system can be audited and verified as necessary.
The tender is open to all eligible bidders, with a non-compulsory briefing scheduled for July 20th, followed by the closing of submissions on August 5th. The successful bidder will be expected to integrate the new system with the DHA's core systems, ensuring seamless interoperability and minimal disruption to existing operations.
This tender represents a significant investment in the country's cybersecurity infrastructure, reflecting the DHA's commitment to protecting sensitive government data and ensuring the integrity of its systems. As the bidding process unfolds, it will be interesting to see how the market responds and which bidder emerges as the successful candidate in this critical security upgrade.