NATIONAL IDENTITY MANAGEMENT COMMISSION (NIMC)-REQUEST FOR EXPRESSION OF INTEREST (REOI) ENGAGEMENT OF CONSULTANT TO ENHANCE NIMS SECURITY AND RESILIENCE
FEDERAL REPUBLIC OF NIGERIA
NIGERIA DIGITAL IDENTIFICATION FOR DEVELOPMENT PROJECT
REQUEST FOR EXPRESSION OF INTEREST (REOI) ENGAGEMENT OF CONSULTANT TO ENHANCE NIMS SECURITY AND RESILIENCE
1.0 Background
The Nigeria Digital Identity for Development (ID4D) Project, initiated by the Nigerian Government and co-financed by the World Bank, the French Development Agency (AFD), and the European Investment Bank (EIB), aims to significantly increase the number of citizens with a national ID number by establishing a comprehensive and inclusive foundational ID system. This initiative is designed to enhance access to essential services for the population. To achieve its objectives, the project focuses on improving digital enrolment infrastructure and expanding enrolment mechanisms.
The NATIONAL IDENTITY MANAGEMENT COMMISSION (NIMC), based in Abuja, is responsible for executing the Nigeria Digital Identification for Development (ID4D) Project. The issuance and utilization of digital IDs are expected to foster greater participation in the digital economy and facilitate the delivery of critical services to citizens. Given the importance of the ID ecosystem, it is susceptible to cyber threats, particularly in light of the evolving and increasingly sophisticated landscape of cyber-attacks. The interconnected nature of the project heightens security concerns, making robust security measures essential as digital IDs expand access to both the digital economy and vital services.
NIMC is currently certified under ISO 27001:2022 for its NIMS Backend, ensuring that its information security management practices align with industry standards. In response to the growing need for a unified approach to information security across all offices, NIMC plans to extend the ISO 27001:2022 certification to its frontend operations in the six territorial offices, as well as have an integrated management system certification encompassing multiple standards such as ISO 27001 (Information Security Management), ISO 27701 (Privacy Information Management), and ISO 22301 (Business Continuity Management). This expansion and integrated approach will further strengthen NIMC’s commitment to safeguarding information assets across all operations, thereby enhancing overall governance and risk management.
This extension is vital for maintaining consistent, high-quality information security management throughout the National Identity Management System. It mitigates risks, ensures compliance, boosts stakeholder confidence, enhances business continuity, and supports the organization’s growth. Through this initiative, NIMC reaffirms its dedication to information security while protecting its assets, data, and global reputation
Against this background, the Project Implementation Unit (PIU) now invite qualified Consulting Firm willing to participate in this important Assignment to strengthen the Security and Resilience of Nigeria’s Digital identity Infrastructure to express their Interest by obtaining the Terms of Reference and submit an Expression of Interest Document accordingly. Request for the Terms of Reference can be made by email to the addresses = procurement@nigeriaid4d.org.
2.0 Objectives of the Consultancy Assignment
The objective of this Terms of Reference (ToR) is to engage a qualified consultant (successful vendor) to support the National Identity Management Commission (NIMC) in enhancing the security and resilience of the NIMS. The successful vendor will:
• Assist NIMC in extending its ISO 27001:2022 certification to its frontend operations across six territorial offices, ensuring a unified approach to information security management.
• Facilitate the integration of multiple management standards, including ISO 27701 (Privacy Information Management) and ISO 22301 (Business Continuity Management), to bolster the overall governance and risk management framework.
• Support the development and testing of a robust Business Continuity Plan (BCP) to enhance the resilience of the National Identity Management System (NIMS) against potential cyber threats and operational disruptions.
This comprehensive approach will mitigate risks, ensure compliance, boost stakeholder confidence, and safeguard critical information assets, thereby reinforcing NIMC’s commitment to protecting its data and maintaining its global reputation.
3.0 Scope of Services
The firm is required to perform the following tasks to achieve the overall goal of the assignment.
1. ISO 27001:2022 Certification Extension.
2. Integration of Management Standards.
3. Development and Testing of Business Continuity Plan (BCP).
4. Engagement of Independent Certification Body.
Details are provided in the TOR for the assignment.
No Comments
Sorry, the comment form is closed at this time.