Conduct Procurements

The set of activities to solicit and collect bids or proposals from sellers, evaluate them to select a supplier, and finalize and award the contract.

Key Points

  • Involves issuing RFPs/RFQs, answering bidder questions, and receiving proposals or bids.
  • Applies predefined selection criteria and may include bidder conferences, evaluations, and due diligence.
  • Includes negotiations on scope, price, schedule, and terms before deciding on the winning seller.
  • Results in a signed agreement and updates to procurement records and the project management plan as needed.

Example

A project team needs a specialized software component. They publish an RFP, hold a bidder conference, score vendor proposals against technical and cost criteria, negotiate service levels and warranties with the top vendor, and award the contract to the best overall offer.

PMP Example Question

Which action occurs during Conduct Procurements?

  1. Deciding whether to build in-house or buy from a vendor
  2. Evaluating supplier proposals and selecting the winning seller
  3. Monitoring seller performance against the contract
  4. Archiving procurement records after all work is complete

Correct Answer: B — Evaluating proposals and choosing the seller

Explanation: Conduct Procurements focuses on obtaining and assessing seller responses, negotiating, and awarding the contract. Make-or-buy is planning, performance monitoring is control, and archiving occurs at closure.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Build an ICS/OT cybersecurity foundation that fits the real environment

Standard IT controls can disrupt the industrial systems they are meant to protect. Learn how to assess OT risk, design zones and conduits, apply IEC 62443 security levels, use MITRE ATT&CK for ICS, and establish passive asset visibility without risking production. Eight reconstructed incidents connect attacker techniques to the controls that failed, giving you the vocabulary and judgment to make credible security decisions from day one.

Explore the Course