CHECK
|
|
| |
 |
|
CESG are currently unable to consider new applications for
membership of the CHECK Service. The guidance below is for information
only for when CESG lift this temporary suspension and resume accepting
new applications.
The CHECK Service exists for the benefit of HMG and CNI end users
who wish to have their sensitive IT systems and networks checked for
vulnerabilities. A CHECK Company will be invited to renew their membership
of the CHECK Service on an annual basis. However, potential new companies
should note that failure to provide evidence of any work under the
CHECK Service for the proceeding year may result in the CHECK Membership
Contract not being renewed.
If you wish to proceed with your application to join CHECK you will
require a copy of the Application
Form (pdf) and the Service
Provision Guidelines (pdf). All applications must be supported
by the information detailed below.
Company Background
We require the following details regarding the Company applying for
CHECK membership:
- An outline of your Company methodology.
- The number of Health Checks undertaken by your Company in the
last 12 months.
- Evidence that the Company has performed IT Health Checks under
the submitted Company name for a minimum of twelve months.
- Copies of at least two reports of IT
Health Check work conducted by your Company.
- Two independent references from companies/organisations for
which your Company has conducted IT Health Check work.
- Details of current and proposed Company quality procedures (e.g.
ISO accreditations) and how these will be applied to work undertaken
as a CHECK Service Provider.
Staff Resources
You will need to identify all employees who will conduct IT Health
Checks under the terms of CHECK. All members of your CHECK team must
be British nationals (or as a minimum hold dual British nationality)
and be able to obtain and hold SC
clearance (doc). You may include as many of your staff as you
wish, although each one must be able to demonstrate a sound background
in IT Health Check work. The following details should be included
for each prospective team member:
At least one member of the Health Check team will be required to attend
and pass the CHECK Service Assault Course
before the team will be eligible to conduct unsupervised work under
the CHECK Service.
Selection
A panel of CESG personnel will review the company submission and the candidates identified for conducting IT Health Check work under CHECK and confirm their suitability. We will also confirm their current security clearance level and initiate clearance procedures where necessary.
Ultimately, the panel will use the material supplied to understand how the company performs a typical Health Check, interprets the results and communicates these to the customer. We will work with the company to clarify any issues with the submission or to seek further supporting evidence, as necessary. If the panel is satisfied that the company can perform Health Checks in a way that is suitable for HMG customers, then the applicant company will be technically approved. If this is not the case then the submission will be refused. Please note that any applications which are refused cannot be resubmitted within a 12 month period from the date of the refusal by the panel.
The Contract
Once we have received your application and can confirm you meet all
of our qualifying requirements, we will send a Contract Acceptance
Form. This should be signed by an appropriately authorised member
of your organisation. Your contract year will begin when CESG receives
the signed Contract Acceptance Form.
Cost
An annual subscription fee, which is reviewed periodically, is charged
for CHECK membership. With effect from 1st April 2008 fees for Membership
(Firm Non-Refundable Price) is £7,500, VATEX and £1,600, VATEX for
CHECK Service Assault Course (CSAC).
Please contact the CHECK Service Management
Team for further details.
Further Information
If you have any questions about the application process or any other
aspect of the CHECK Service, please e-mail check@cesg.gsi.gov.uk
or telephone (01242) 221491 ext 34557. |