ManageEngine Log360 Cloud - Next Gen SIEM with security analytics and Gen AI insights
Log360 Cloud delivers comprehensive Next generation SIEM and security analytics built for modern public sector SOC teams. We unify log management, ML based UEBA, threat intelligence and CASB into a single, cloud-native platform, ensuring continuous monitoring across cloud and on-premise infrastructure.
Features
- Next generation SIEM for unified security and compliance management.
- Real time, scalable log collection from cloud and on premise.
- Unified, customisable SOC dashboard with object filters and search.
- Native CASB with Shadow IT discovery and app access control.
- Leverage EDR data for enriched context in threat hunting
- ML powered behavior analytics (UEBA) for advanced threat detection.
- Gen AI Assistant (Zia) simplifies complex security investigations
- 2,000+ cloud detections covering MITRE ATT&CK, anomaly models, threat intel.
- Log archival and custom retention for effective forensic analysis.
- In depth Active Directory auditing and monitoring
Benefits
- 24/7 continuous monitoring to stop security breaches.
- Eliminate siloed tools with one unified security console.
- Scalable architecture ensures flexible pricing for dynamic security needs.
- Accelerate investigation with AI generated alert summaries and context.
- Instant, audit ready reports streamline compliance and regulatory adherence.
- Maximise Security ROI with lower operational costs.
- Improve security posture with a proactive threat detection framework.
- Flexible data retention policies and dual tier storage architecture.
- Dark web monitoring for potential supply chain credential leaks.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 6 1 6 0 1 4 7 6 2 7 4 6 7 0
Contact
ZOHO CORPORATION LIMITED
Corie Robinson
Telephone: +44 2038072092
Email: zohouk-gcloud@eu.zohocorp.com
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Location and geospatial data management and analytics
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- As a seamless cloud service, Log360 Cloud handles all upgrades automatically with minimal disruption. The platform remains accessible during maintenance, which typically occurs during non-business hours in an on-premises environment.Log360 Cloud necessitates the installation of an agent on a Windows machine for log collection. Customers are required to whitelist Log360 Cloud URLs to enable seamless communication between the agent and the cloud. This communication relies on specific ports: 443 (TCP), 513, 514 (UDP), and 514 (TCP). The solution is compatible with the Windows platform and operates with web browsers such as Google Chrome, Microsoft Edge, and Mozilla Firefox.
- System requirements
-
- Log360 Cloud requires lightweight agent installation on endpoints.
- 1GHz x86 dual-core processor with 2 GB RAM for 32bit
- 2.80GHz x64 Xeon-class processor with 2 GB RAM for 64bit
User support
- Email or online ticketing support
- Yes
- Support response times
- Depending on the severity of the issue we acknowledge it between 6-18 regional business hours. Severity level 1 (S1) tickets will be acknowledged in 6 regional business hours. Severity level 2 (S2) tickets will be acknowledged in 12 regional business hours. Severity level 3 (S3) tickets will be acknowledged in 18 regional business hours.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
-
Our web chat can be accessed directly from support page. Users can access our web chat support by clicking on the support icon located at the bottom left on our product website. This allows them to seek technical assistance. Alternatively, users can initiate web chat from the product portal's 'Support' tab for access to resources, custom features, support tickets, and personalised pricing quotes.
1. Mouse-less intervention: The application has been designed to be entirely usable without the need for a mouse device. It supports mouse-less intervention, enabling navigation using the following , Tab: Forward navigation, Shift+Tab: Backward navigation, Enter/Return: Option selection
2. Zoom Controls and font size: The application is fully adaptable with Zoom control support ranging from 80% to 125%, regardless of the device being used. This enhances overall product visibility. Additionally, it supports maximum readability by allowing users to adjust the font size of the content/text within (small, medium, or large) as desired, thereby enhancing clarity and legibility.
3. Screen Reader Compatibility:Our text-only application is compatible with screen reader extensions. These extensions enable the focus area on the screen (either through the tab key or mouse click) to be read aloud, making all content accessible. - Web chat accessibility testing
- The application has undergone manual testing for navigation and readability. Compatibility with screen readers has been tested using the ChromeVox extension, which reads aloud the focused content on the screen.
- Onsite support
- Yes
- Support levels
-
We provide three service levels: classic support, premium support, and onboarding/implementation services. Classic support, available 24x5, responds to requests based on severity levels:
Severity Level 1 (S1): The Licensed Software does not function without a fix being provided and the problem has significant effect on the revenue or business operations of the Licensee. Acknowledged within 6 regional business hours.
Severity Level 2 (S2): The Licensed Software can function. However, the Licensed Software functions providing incorrect results or its performance is inconsistent pursuant to the ManageEngine user documentation. Acknowledged within 12 regional business hours.
Severity Level 3 (S3): The functionality of the Licensed Software is not affected by the problem or can be accomplished by using other features of the Licensed Software. Acknowledged within 18 regional business hours. Premium support, available 24x7 for an extra charge, offers rapid response times.
For comprehensive onboarding and implementation, we offer services at a nominal charge. Please refer to our Terms and Conditions for complete support level information. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- In the onboarding journey for Log360 Cloud, our approach revolves around empowering users with comprehensive resources while offering optional professional services. Our extensive knowledge base (KB) articles and guides provide step-by-step instructions, best practices, and troubleshooting tips for setup and configuration. If customers desire additional support, our professional services are available at a nominal cost. These services include a preliminary consultation to align with the client's requirements, implementation assistance, and thorough post-implementation acceptance testing. Documentation such as business requirements, standard operating procedure, and scope of work ensure transparent communication and a clear understanding of the process. Training sessions, lasting up to 4 hours and accommodating a maximum of 5 participants, are offered in English, with options for on-site training at a customised package rate. Product expert certification is also available for desired customers.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Seamless off-boarding is our top priority. Customers will be transitioned to the free edition of Log360 Cloud but will retain access until their contract is terminated. To ensure data continuity, log-forwarding should be setup before the end of subscription. We do offer support for exporting data in PDF and CSV formats even in the free edition.
- End-of-contract process
- Upon contract expiration, customers will retain access to existing log data within the free edition of Log360 Cloud. However, they won't be able to add new log sources, and the application won't process configured sources. Access to resources will remain free, with ongoing support available to customers. Customers have the option to utilise our professional services, wherein a ManageEngine Log360 Cloud technical specialist will manage the entire off-boarding process from start to finish. This service incurs an additional cost.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- We prioritise accessibility in our documentation by using clear language, providing alternative text for images, ensuring colour contrast, and using descriptive headings and links. All documents undergo rigorous reviews before publication, and we offer contact information for personalised assistance.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- Yes
- Compatible operating systems
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The user interface and user experience of Log360 Cloud differ notably between desktop and mobile devices. While accessing the platform on a mobile phone, although there is no reduction in functionalities, users might encounter navigation challenges. Our product is optimised for mobile use, yet it excels particularly when viewed in portrait mode. Our user interface ensures seamless interaction, enhancing accessibility and functionality. Whether on a desktop or mobile device, users can expect an intuitive and efficient experience while navigating through Log360 Cloud's features.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Log360 Cloud offers an intuitive interface for easy navigation and a comprehensive overview of network activities. It features robust tools for managing and analysing logs and security events. Users can effortlessly explore the dashboard, accessing insights into log sources, events, alerts, correlation, compliance, and cloud protection. They can conduct searches, access reports, and configure alert criteria to monitor security events effectively. Detailed breakdowns of log sources, severity events, and recent alerts are readily available, facilitating proactive threat detection and response. Overall, the interface streamlines data organisation, enabling efficient network monitoring, anomaly identification, and threat mitigation.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Log360 cloud is accessible through major web browsers such as Google Chrome, Microsoft Edge, Safari, and others.
- Accessibility testing
- We have not done any interface testing with users of assistive technology. However, we are committed to doing it near future.
- API
- Yes
- What users can and can't do using the API
- Log360 cloud uses APIs to collect logs from cloud sources like AWS and M365.
- API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- Log360 Cloud offers extensive customisation options to suit the unique requirements of our customers. Administrators and operators have the flexibility to personalise dashboards, set up custom alerts, and tailor various aspects of the solution to align perfectly with their needs. Users can customise a wide range of features including dashboards, alert settings, notification preferences, correlation rules, compliance reports, report scheduling, log retention policies, regional business hours, domains, workgroups, cloud accounts, application restrictions, and much more.
Scaling
- Independence of resources
- Log360 Cloud puts throttle limit on each user to ensure that they don't overload the servers with requests so that other users don't get affected by the demand. We have however have a network of severs spread across the globe to make sure such a crisis doesn't occur.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Log360 Cloud is licensed based on storage consumed on a daily basis. The users can view the used and free storage. These insights are provided within the product, inside settings, which gives valuable data and information gathered from monitoring and analysing user interactions and access activities within systems, applications, and resources. All of the reports are placed under the technician audit tab.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Sensitive customer data at rest is encrypted using 256-bit Advanced Encryption Standard (AES). The data that is encrypted at rest varies with the services you opt for. We own and maintain the keys using our in-house Key Management Service (KMS). We provide additional layers of security by encrypting the data encryption keys using master keys. The master keys and data encryption keys are physically separated and stored in different servers with limited access.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Log360 Cloud has a data export feature through which users can export their data in PDF and CSV formats.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
- Log sources
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- All customer data transmitted to our servers over public networks is protected using strong encryption protocols. We mandate all connections to our servers use Transport Layer Security (TLS 1.2/1.3) encryption with strong ciphers, for all connections including web access,API access, our mobile apps, and IMAP/POP/SMTP email client access. Additionally for email, our services leverages opportunistic TLS by default. We have full support for Perfect Forward Secrecy (PFS) with encrypted connections, ensuring no previous communication be decrypted. We have enabled HTTP Strict Transport Security header (HSTS) to all web connections and we flag all our authentication cookies as secure.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- ManageEngine protects data within its network using layered security controls. Data stored in Zoho data centres is encrypted at rest using strong encryption standards. Internal traffic between services, storage systems and disaster recovery sites is encrypted to prevent unauthorised access. ManageEngine operates fully controlled data centres with restricted physical access, continuous monitoring and dedicated security systems. Network protections include firewalls, intrusion detection and prevention, and segmentation to isolate sensitive components and limit lateral movement. Access to production systems is restricted to authorised personnel following strict authentication, logging and approval processes.
Availability and resilience
- Guaranteed availability
- ManageEngine guarantees an average monthly uptime of 99.9% for its Cloud solutions. The standard SLA covers monthly service availability. If the service falls below this threshold, customers may be eligible for service credits according to contract terms
- Approach to resilience
-
Application data is stored on resilient storage that is replicated across data centers. Data in the primary DC is replicated in the secondary in near real time. In case of failure of the primary DC, secondary DC takes over and the operations are carried on smoothly with minimal or no loss of time. Both the centers are equipped with multiple ISPs.
We have power back-up, temperature control systems and fire-prevention systems as physical measures to ensure business continuity. These measures help us achieve resilience. In addition to the redundancy of data, we have a business continuity plan for our major operations such as support and infrastructure management. - Outage reporting
- Planned maintenance will be notified through In-App banners & status pages and unplanned outages will be notified through status pages, blogs, forums and social media handles.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to production environments is maintained by a central directory and authenticated using a combination of strong passwords, two-factor authentication, and passphrase-protected SSH keys. Furthermore, we facilitate such access through a separate network with stricter rules and hardened devices. Additionally, we log all the operations and audit them periodically."
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Other standards include ISO/IEC 27701, ISO/IEC 27017, ISO/IEC 27018, SOC 2 Type II, HIPAA-compliant controls for eligible services, and CSA STAR Level 1 certification. These frameworks cover privacy management, cloud security, protection of personal data, independent assurance reporting, and cloud control transparency.
- Information security policies and processes
- ManageEngine has a dedicated Compliance team and they conduct internal risk assessments to confirm if the policies are followed. Zoho has an established governance framework that supports relevant aspects of information security with policies and standards (Endpoint Central is an offering from ManageEngine, which in turn is a division of Zoho). Roles and responsibilities for the governance of Information Security within Zoho are formally documented and communicated by the management. Zoho shall establish, implement, and maintain an information security program in accordance with the international standard ISO 27001 that includes technical and organizational security and physical measures as well as policies and procedures to protect customer data processed by Zoho against accidental loss, destruction or alteration, unauthorized disclosure or access, or unlawful destruction. Zoho maintains documented information security and data privacy policies and requirements, and communicates them periodically to those employees responsible for the design, implementation and maintenance of security and privacy controls.The policies are reviewed annually to keep them up-to-date. This policy gets verified during our third-party audits like ISO and SOC.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- ManageEngine has Change Management procedures in place that include the following but are not limited to all the changes to the organisation, applications, systems, people, technology, and processes, information processing facilities that affect information security/privacy. For every change, the security impact is analysed. We maintain Audit logs as evidence of all the changes. Fall-back procedures, including procedures and responsibilities for aborting and recovering from unsuccessful changes and unforeseen events, are documented and communicated. Zoho shall notify the customer of any changes that may affect the customer in an adverse manner.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
ManageEngine has a vulnerability management process that actively scans for security threats using a combination of certified third-party scanning and in-house tools with automated and manual penetration testing efforts. Our security team actively reviews inbound security reports and monitors public mailing lists, blog posts, and wikis to spot security incidents that might affect the company’s infrastructure.
Once we identify a vulnerability requiring remediation, it is logged, prioritised according to the severity, and assigned to an owner. We further identify the associated risks and track the vulnerability until it is closed by either patching the vulnerable systems or applying relevant controls. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- ManageEngine ensures to monitor and analyse information gathered from services, internal traffic in our network, and usage of devices and terminals. We record this information in the form of event logs, audit logs, fault logs, administrator logs, and operator logs. These logs are automatically monitored and analysed to a reasonable extent that helps us identify anomalies such as unusual activity in employees’ accounts or attempts to access customer data. We store these logs in a secure server isolated from full system access, to manage access control centrally and ensure availability.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
ManageEngine has a dedicated incident management team. We track and close the incidents with appropriate corrective actions. Whenever applicable, we will identify, collect, acquire, and provide users with necessary evidence in the form of application and audit logs regarding incidents applicable.
We respond to the security or privacy incidents you report to us through incidents@zohocorp.com with high priority. For general incidents, we will notify users through our blogs, forums, and social media. For incidents specific to an individual user or an organisation, we will notify the concerned party through the primary email of the Organisation administrator registered with us. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- ManageEngine provides a free fully functional 30-day free trial for our Services that includes limited capabilities with 50 GB default search storage and 150 GB default archival storage. Once the free trial period is over or the provided storage is completely used, users will have to switch to paid editions.
- Link to free trial
- https://log360cloud.manageengine.com/rest/v1/signup?utm_source=Gcloud_sspr
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Wednesday 3 September 2025
- What the ISO/IEC 27001 doesn’t cover
-
ISO/IEC 27001 certifies our Information Security Management System (ISMS) and confirms that we have appropriate governance, controls, and continual improvement processes in place to manage information security risks within the defined scope of certification.
The certification does not certify individual products or specific technical features in isolation. Instead, it applies to the management framework, policies, processes, and controls that govern how information security is implemented and operated across our in-scope services.
Activities, systems, or services outside the formally defined ISMS scope are not covered by the ISO/IEC 27001 certification. This may include third-party services or infrastructure not operated or controlled by us, or internal systems not directly involved in the delivery of certified services.
ISO/IEC 27001 also does not replace or automatically include other standards (such as ISO/IEC 27017 or ISO/IEC 27018 - Which Zoho Corporation has obtained both certifications), which address cloud-specific controls and protection of personally identifiable information and are assessed separately where applicable. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI
- ISO 9001 accreditation date
- Thursday 23 March 2023
- What the ISO 9001 doesn’t cover
-
ISO 9001:2015 certifies our Quality Management System (QMS) and confirms that we have defined, implemented, and continually improved processes to ensure consistent service delivery within the certified scope.
The certification does not certify individual products, features, or technical performance in isolation. It focuses on the management framework for quality rather than guaranteeing specific service outcomes, configurations, or performance levels for individual services.
Activities, systems, or services outside the formally defined QMS scope are not covered by the ISO 9001 certification. This may include third-party services, customer-managed configurations, or internal processes not directly involved in the delivery and support of in-scope services.
ISO 9001 also does not address information security, privacy, or data protection controls, which are covered separately under standards such as ISO/IEC 27001 and related certifications. - Quality management systems (QMS)
- Yes
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- Monday 4 August 2025
- CSA STAR certification level
- Level 1: CSA STAR Self-Assessment
- What the CSA STAR doesn’t cover
-
Zoho’s listing in the CSA Security, Trust & Assurance Registry (STAR) is based on a STAR Level 1 Self-Assessment, which documents how our cloud security controls align with the Cloud Security Alliance Cloud Controls Matrix (CCM).
The STAR self-assessment applies to the security control framework and governance practices for our cloud services. It does not certify individual products, specific service configurations, or customer-managed settings in isolation.
Activities or services outside the scope of the published STAR self-assessment, including customer-controlled configurations, integrations with third-party services, or infrastructure not operated or controlled by Zoho, are not covered.
CSA STAR also does not replace other standards covering information security, privacy, or quality management, which are addressed separately through certifications such as ISO/IEC 27001 and related standards.
In summary, CSA STAR provides transparency into our cloud security controls within scope, but not independent certification or coverage of out-of-scope services or configurations. - PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Df4a2fb2-58c7-428b-b622-0d1dbd68ae22
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 061e91c4-e56a-4f0c-a09c-66fea8d9c587
- Other security certifications
- Yes
- Any other security certifications
-
- ISO/IEC 27017 (Cloud Security Controls)
- ISO/IEC 27018 (Protection of PII in public cloud)
- ISO/IEC 27701 (Privacy Information Management / PIMS)
- SOC 2 Type II
- CSA STAR (Level 1 Self-Assessment)
- Data Security and Protection Toolkit (DSPT)
- GDPR
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-