TERMS OF REFERENCE
PROCUREMENT OF TRAINING SERVICES FOR THE IMPROVEMENT
OF HGC’S QUALITY AND INFORMATION SECURITY MANAGEMENT SYSTEM (QISMS)

I. OBJECTIVE

The procurement of the services of an ISO-certified Training Service Provider aims to conduct training for the ISO Core Team to improve the HGC’s Quality and Information Security Management System.

The Training Service Provider shall focus on the development and implementation of business continuity management system (BCMS) that will ensure the continuity of core processes allowing the nonstop delivery of products and services to its customers.

The business continuity management system is aligned with ISO standards.

II. SCOPE OF WORK

The Training Service Provider shall act as consultant throughout the project to provide and transfer expert knowledge on BCMS covering its development, implementation and improvement.

Training Course :  

Business Continuity Management System Implementer’s Course

The training Service Provider shall design and deliver a customized training course for the HGC QISMS Core Team of Fifty (50) members, which aims to:

  1. determine criticality of processes and activities to the organization using a structured approach;
  2. identify consequence of disrupted processes through a comprehensive business impact analysis;
  3. understand the mandatory requirements of ISO 22301 BCMS Standards and the strategies for its implementation;
  4. reduce the likelihood and consequence of incidents through a structured and coherent risk assessment process;
  5. determine business continuity metrics to enable the organization to recover and restore its processes;
  6. discuss the governance framework necessary to manage BCMS for the organization; and
  7. draw up an approach in implementing BCMS in the most economical manner with all critical processes and stakeholders taken into consideration.

1. Topics:
The course outline of the 3-day training and workshop session includes the following topics:

  • Introductions and Realities – what’s happening around us?
  • Impacts of Crisis
  • Common Pitfalls
  • Critical Success Factors
  • The BCM Framework using ISO 22301 and BCI GPG 2010
  • The BCM Program Management
    • Understanding the organization
    • Determining the BCM strategy
    • Developing and implementing a BCM response
    • Exercising, maintaining and reviewing BCM arrangements
    • Embedding the BCM in the organization’s culture
  • Continuity Planning Sequence (includes the following practical workshops)
    • Incident management and control
    • Business impact analysis
    • Risk assessment and treatment
    • Determining business continuity strategies
    • Business continuity planning
  • ISO 22301 mandatory Requirements
  • Q&A

2. Learning Outcome:

  • Have a foundation in professional business practices.
    • Describe best practices in business continuity during times of disaster and other emergencies.
    •  Apply business continuity strategies to a simulated disaster.
    • Distinguish differences between private and public sector continuity strategies during disasters and other emergencies.
    • Managing program budgets
  • Communicate effectively.
    • Develop a disaster business continuity plan
  • Identify hazards; monitor those hazards; determine the likelihood of their occurrence to a specific unit; and determine the vulnerability of people, property, the environment, and the entity itself to those hazards.

Recognize and identify the risk and vulnerabilities facing different organizations during disasters.

III. CRITERIA FOR SELECTION
The committee shall decide on the best technical specification offer that will be based on the following criteria:

Criteria Percentage
A. Technical Proposal 70%

1. Quality of Personnel to be Assigned

30%

2. Firm Experience & Capability

30%

3. Plan of Approach & Methodology

40%
B. Cost Proposal   30%
Total   100%

IV. APPROVED BUDGET FOR THE CONTRACT (ABC)

For and in consideration of the services of the consultant, the HGC shall pay the sum of NINETY FIVE THOUSAND PESOS ONLY, inclusive of the 12% VAT, payable as follows:

QISMS TRAINING
Training Description No. of Days No. of Pax Cost
a) Business Continuity Planning 3 days February 50 Pax 95, 000.00
b) BCP Implementation Course (with 3rd Party Trainers)

 

JIMMY B. SARONA
Chairperson
Bids and Awards Committee