procureprocess

Vulnerability Management Solution

ProcureProcess - IOM Others Non Governmental 2026-07-23 to 2026-08-12
International Organization for Migration (IOM) invites qualified vendors to submit proposals for the provision, implementation, support and continuous improvement of a cloud-based vulnerability management solution. The proposed solution shall enable IOM to discover, assess, prioritize, report and support remediation of vulnerabilities across globally distributed infrastructure, applications, databases, endpoints, network devices, servers, cloud resources and other in-scope assets. The purpose of this RFP is to identify the proposal that provides the best value for money to IOM, taking into consideration technical quality, functional coverage, security and privacy posture, implementation approach, service support, scalability, sustainability and total cost of ownership. 1. BACKGROUND AND OBJECTIVE IOM seeks to strengthen its vulnerability management capability through an enterprise-grade platform that supports continuous identification, classification, prioritization and reporting of security weaknesses across a large, diverse and geographically distributed technology environment. The solution shall support risk-based decision-making by linking technical findings to asset criticality, exploitability, severity, business impact and remediation status. The selected solution shall support IOM in conducting holistic reviews of existing technical controls and critical applications, as well as the supporting infrastructure required for IOM operations. The solution shall assist IOM in identifying potential vulnerabilities that may affect the confidentiality, integrity or availability of data and systems. 2. SCOPE OF SERVICES The scope includes the provision, configuration, onboarding, operation support and knowledge transfer for a cloud-based vulnerability management solution capable of supporting more than 100,000 managed assets, or unlimited assets where available. The solution shall support internal and external vulnerability scanning, authenticated and unauthenticated scanning, web application assessment, asset discovery, vulnerability prioritization, remediation tracking, dashboards, reporting and integration with enterprise security and IT service management platforms. The vendor shall clearly describe any prerequisites, exclusions, dependencies, licensing assumptions, deployment constraints, scanner or agent requirements, data residency limitations, supported asset types and operational responsibilities required from IOM.

Log in or create an account to view complete details for this procurement opportunity

If you need support, please email us at [email protected]

Sign up to get
the latest Procurement RFXs