Thai
โครงการนี้จัดทำโดยการยางแห่งประเทศไทย (กยท.) เพื่อตอบสนองต่อภัยคุกคามทางไซเบอร์ที่มีความซับซ้อนมากขึ้น โดยมีวัตถุประสงค์หลักเพื่อเพิ่มประสิทธิภาพและเสริมสร้างความมั่นคงปลอดภัยสารสนเทศ ลดความเสี่ยงจากภัยคุกคามไซเบอร์ และเพิ่มขีดความสามารถในการรับมือและตอบสนองต่อเหตุการณ์ด้านความปลอดภัย
ขอบเขตงานหลักประกอบด้วยการจัดหาและดูแลระบบจัดการความปลอดภัยอุปกรณ์ปลายทาง (Endpoint Security) จำนวน 2 ส่วน ได้แก่ ระบบสำหรับเครื่องแม่ข่าย (จำนวนไม่น้อยกว่า 200 เครื่อง) และระบบสำหรับเครื่องลูกข่ายหรือ Client (จำนวนไม่น้อยกว่า 2,000 เครื่อง) โดยระบบที่นำเสนอต้องเป็นโซลูชัน Endpoint Detection and Response (EDR) ที่สามารถใช้งานและบริหารจัดการร่วมกับระบบ EDR และ Management Console เดิมที่มีอยู่ได้ทันที โดยไม่ต้องติดตั้ง agent หรือ console ใหม่
ระบบต้องมีคุณสมบัติขั้นสูงครอบคลุม เช่น การตรวจจับและป้องกันภัยคุกคามประเภทต่างๆ (Ransomware, Malware, Fileless Attack), ความสามารถในการตอบสนองแบบอัตโนมัติและแมนวล, การสืบค้นภัยคุกคาม (Threat Hunting) ที่แมปกับ MITRE Att&CK Framework, การกักกันอุปกรณ์ในเครือข่าย (Network Quarantine), การกู้คืนระบบจาก Ransomware (Rollback) และการบูรณาการกับระบบอื่นๆ เช่น SSO, Syslog และ Threat Intelligence
ผู้รับจ้างมีหน้าที่บำรุงรักษาระบบ จัดทำรายงานสรุปผลการทำงานและเหตุการณ์ความปลอดภัยส่งมอบเป็นประจำทุกเดือน จัดฝึกอบรมการใช้งานให้กับเจ้าหน้าที่ และให้บริการ Helpdesk ผ่านช่องทางออนไลน์ในวันและเวลาทำการ โครงการมีระยะเวลาดำเนินการและให้บริการรวม 1 ปี
English
This project is initiated by the Rubber Authority of Thailand (RAOT) to address increasingly complex cyber threats. The main objectives are to enhance and strengthen information security, reduce risks from cyber threats, and improve incident response capabilities.
The core scope of work involves the procurement and maintenance of an Endpoint Security management system for two segments: one for servers (at least 200 endpoints) and another for client computers (at least 2,000 endpoints). The proposed system must be an Endpoint Detection and Response (EDR) solution that is fully compatible and manageable with the existing EDR system and Management Console currently in use at RAOT, requiring no new agent or console installation.
The system must possess advanced features including detection and prevention of various threats (Ransomware, Malware, Fileless Attacks), automated and manual response capabilities, threat hunting mappable to the MITRE Att&CK Framework, network quarantine for compromised devices, system rollback from ransomware, and integration with other systems such as SSO, Syslog, and Threat Intelligence.
The contractor is responsible for system maintenance, submitting monthly performance and security incident reports, conducting user training for IT staff, and providing online Helpdesk support during business hours. The total project and service period is 1 year.
สถานที่
ไม่ระบุในเอกสาร TOR ที่ให้มา