Aurora, Illinois

File #: 18-0577    Version: 1 Name:
Type: Resolution Status: Passed
File created: 7/5/2018 In control: City Council
On agenda: 8/28/2018 Final action: 8/28/2018
Title: A Resolution Authorizing the PAS Global LLC, 16055 Space Center Blvd # 600, Houston, TX 77062 to perform a network vulnerability assessment for the City of Aurora's SCADA (supervisory control and data acquisition) system at the Water Treatment Plant for a cost not to exceed $48,000.
Attachments: 1. PAS Proposal to Provide SCADA Vulnerability Assessment, 2. Crowe Proposal to Provide SCADA Vulnerability Assessment, 3. Sentinel Proposal to Provide SCADA Vulnerability Assessment
cover
TO: Mayor Richard C. Irvin

FROM: Ted Beck, Chief Information Security Officer
Dave Schumacher, Superintendent Water Production Division

DATE: 7-5-2018

SUBJECT:
A resolution authorizing the contracting of PAS Global LLC, 16055 Space Center Blvd # 600, Houston, TX 77062 to perform a network vulnerability assessment on the City of Aurora's critical infrastructure SCADA (supervisory control and data acquisition) system at the Water Treatment Plant for a cost not to exceed $48,000.

PURPOSE:
The SCADA system allows for the operation, management and monitoring of the City's water production resources for the Water Production Department. This system allows the different components of this system to be managed remotely without the need to travel to all sites to make any changes or gather data. The controls provided by this system protect a critical infrastructure for the City of Aurora.

BACKGROUND:
The City has received three informal bids for professional services to include:

1) Sentinel Technologies Inc., 2550 Warrenville Rd, Downers Grove, IL 60515 for $54,890.

2) PAS Global LLC, 16055 Space Center Blvd # 600, Houston, TX 77062 for $48,000.

3) Crowe LLP, 225 West Wacker Drive, Suite 2600, Chicago, IL 60606 for $40,000.

After a thorough due diligence process Information Technology Division considers option # 2 - PAS Global LLC as the preferred option for the following reasons:

Both Sentinel and PAS offer specialized consultants with industrial control and automation experience within their proposals. The SCADA network encompasses a unique combination of industrial controls, automation systems and traditional networking components.

Although the proposal from Sentinel was well composed there were two fundamental concerns:

1) Higher Cost
2) Resource Availability for Industrial Control Systems Expertise

On the other hand while we value Crowe's experience and partnership we would like to ensure vendor diversity for our security audits. Crow...

Click here for full text