IBM Lot 2a: Infrastructure Software as a Service (iSaaS) Services
All IBM Lot 2a Services as per the service definition documents
Features
- Vulnerability analysis and contextual prioritisation
Benefits
- Enable secure remote management of systems and workflows
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 6 7 3 1 1 5 6 3 7 8 0 3 2 2
Contact
SOFTCAT PLC
Public Sector Tenders
Telephone: 01628 403403
Email: psitq@softcat.com
About your service
- Service categories
-
Systems Infrastructure Software
System and service management
- IT operations management
- IT service management
IT automation and configuration management
- Workload management
- Datacentre system and application control
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- Available on request
- System requirements
- Available on request
User support
- Email or online ticketing support
- Yes
- Support response times
-
The response goal is two business hours (8AM to
5PM Monday to Friday). For Severity 1 tickets
(critical business impact) there is 24x7 support - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
-
IBM Cloud includes the following major
accessibility features: - Keyboard-only operation. -
Operations that use a screen reader. IBM Cloud
uses the latest W3C Standard, WAI-ARIA 1.0 to
ensure compliance to US Section 508 and Web
Content Accessibility Guidelines (WCAG) 2.0. To
take advantage of accessibility features, use the
latest release of your screen reader in
combination with the latest Internet Explorer web
browser that is supported by this product. The IBM
Cloud online product documentation and the IBM Cloud user interface framework is enabled for
accessibility - Onsite support
- Yes, at extra cost
- Support levels
-
IBM provides three levels of support : Basic,
Advanced and Premium. Basic does not specify
response objectives. Advanced and Premium
specify the following objectives for initial response
times: ||| Severity 1 (critical business impact or
service down) : Advanced = 1 hour, Premium = 15
minutes ||| Severity 2 (significant business impact)
: Advanced = 2 hours, Premium = 1 hour |||
Severity 3 (minor business impact : Advanced = 4
hours, Premium = 2 hours ||| Severity 4 (query, or
minimal business impact) : Advanced = 8 hours,
Premium = 4 hours ||| ||| Premium also includes an
assigned Technical Account Manager, and
quarterly business reviews. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
IBM can engage with your users in a number of
different ways: A free pre-sales engagement can
be held with you before purchase, to help you
understand the product and map out use cases.
This is useful for product demonstrations and
technical exploration. We have a number of Proofs
of Technology and Proofs of Concept available, to
help you explore. After purchase, IBM can offer a
service engagement. These is a paid service,
offered on a Time and Materials basis, that aims to
help you plan and set up your software, both for
the initial configuration and for the long-term. After
purchase, as part of the support contract, IBM
provides a wealth of FAQ and how-to articles at no
extra charge. IBM also provides web chat and
forums, thus enabling your users to engage with
technical support at no extra charge - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Upon termination or expiration of the Agreement
IBM will either delete or return Client Personal
Data in its possession as set out in the respective
DPA Exhibit, unless otherwise required by
applicable law. See The IBM Data Processing
Addendum at http://www.ibm.com/dpa (DPA) - End-of-contract process
-
At the end of a cloud product subscription, the
products have to adhere to the IBM rules and
regulations, as described in the DPA, DPA Exhibit
for the product, and other policies. The data is
removed based on said policies at the end of the
subscription.
https://www.ibm.com/support/customer/csol/terms/
?id=Z126-7870&lc=en - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
-
Service interface is a web based
dashboard driven console designed for platform
engineers SREs and IT leaders. It provides unified
visibility into application infrastructure and service
health across hybrid cloud environments. The
interface features interactive dashboards
application and service topology maps AI driven
insights and prioritised recommendations related
to performance resiliency security and cost. Users
can drill down from high level health views to
detailed evidence correlate incidents with recent
changes and assess technical debt. The design
emphasises explainable insights role based
access and decision support rather than alert level
operations. - Accessibility standards
- None or don’t know
- Description of accessibility
-
See the attached report for details -
https://www.ibm.com/able/product_accessibility/request/?
requestId=426662d4b74447578d4a365c06c69314 - Accessibility testing
-
See the attached report for details -
https://www.ibm.com/able/product_accessibility/request/?
requestId=426662d4b74447578d4a365c06c69314 - API
- Yes
- What users can and can't do using the API
-
The Concert API is a RESTful API that utilizes
standard JSON requests and responses and
responds with HTTP status codes. You can invoke
the Concert API using a cURL command-line too - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Yes, users can leverage different Pipelines, Tasks,
Policy & Governance Rules, UI Branding &
Layout, Dashboard & Reporting, Integration &
Event Hooks, Authentication & Authorization,
Artifact Store & Retention.
Scaling
- Independence of resources
-
IBM Concert is built on a multi tenant, cloud native
architecture that isolates workloads at several
layers. The platform combines resource level
isolation, dynamic scaling, and traffic shaping
policies to guarantee predictable performance for
every tenant, even when others generate heavy
demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
IBM Concert offers a comprehensive set of service
usage metrics that give you visibility into how the
platform is being consumed across your
organization. The core metrics include API call
volume, data export frequency, workflow execution
counts, user session duration, concurrent active
users, storage utilization (object store and
database), error rate per endpoint, latency per
request, and resource allocation trends (CPU,
memory, and network I/O). Each metric is
captured in near real time, stored in the Concert
telemetry store - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Reseller (no extras)
- Organisation whose services are being resold
- IBM
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
IBM Concert provides several flexible ways to pull
data out of the platform whether you need a quick
one-off export, a programmatic API call, or an
automated, scheduled extraction. - Data export formats
-
- CSV
- Other
- Other data export formats
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- API
- Concert Toolkit for automated data ingestion
- File Upload through UI
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- Other
- Other protection within supplier network
-
Encryption at Rest, Network Segmentation, IAM,
Data Integrity and Tamper Evidence. Continuous
Monitoring, Threat Detection & Incident Response,
Data Residency & Sovereignty
Availability and resilience
- Guaranteed availability
-
IBM Concert on SaaS has a guaranteed 99.8%
availability. This is defined in the cloud services
agreement. [1]
https://www.ibm.com/support/customer/csol/terms/
?id=i126-9828&lc=en - Approach to resilience
-
IBM Concert is built on a multi-zone multi-region,
cloud native architecture that isolates failures and
automatically recovers services. Each tenant runs
in its own Kubernetes namespace, protected by
pod level security policies and Istio service mesh
mTLS , ensuring that a fault in one tenant cannot
affect another. The control plane is replicated
across three Availability Zones (AZs) per region; if
an AZ loses power or network, traffic is instantly
rerouted to the remaining zones via IBM’s global
load balancer. - Outage reporting
-
Real Time Customer Notification – Email, SMS,
Mobile-app Push, Webhook
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
IBM maintains individual role-based authorization
of privileged accounts that is subject to regular
validation. A privileged account is a duly
authorized IBM user identity with administrative
access to a Cloud Service, including associated infrastructure, networks, systems, applications,
databases and file systems - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
-
IBM has an Information Technology (IT) Security
policy that establishes the requirements for the
protection of IBM's worldwide IT systems and the
information assets they contain, including
networks and computing devices such as servers,
workstations, host computers, application
programs, web services, and telephone systems
within the IBM infrastructure. IBM’s IT Security
policy is supplemented by standards and
guidelines, such as the Security Standards for
IBM's Infrastructure, the Security and Use
Standards for IBM Employees and the Security
Guidelines for Outsourced Business Services.
Such are reviewed by a cross-company team led
by the IT Risk organization every six months. IBM
has a dedicated Vice President of IT Security who leads a team responsible for IBM's own enterprise
data security standards and practices.
Responsibility and accountability for executing
internal security programs is established through
formal documented policies. IBM Services teams
also have dedicated executives and teams who
are responsible for information and physical
security in the delivery of our client
services.Information Security Management
System (ISMS) – ISO 27001, Cloud-S pecific
Security – ISO 27017, Privacy for Personal Data –
ISO 27018 - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
IBM maintains policies and procedures to manage
risks associated with the application of changes to
its Cloud Services. Prior to implementation, all
changes to a Cloud Service, including its systems networks and underlying components, will be
documented in a registered change request that
includes a description and reason for the change,
implementation details and schedule, a risk
statement addressing impact to the Cloud Service
and its clients, expected outcome, rollback plan,
and documented approval by IBM management or
its authorised delegate. Our items such as change
management processes are audited via ISO27001
and internal IBM audits related to IBM ITSS. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
With each Cloud Service, as applicable and
commercially reasonable, IBM will a) perform
penetration testing and vulnerability assessments
before production release and routinely thereafter,
b) enlist a qualified and reputable independent
third-party to perform penetration testing and
ethical hacking at least annually, c) perform
automated management and routine verification of
underlying components’ compliance with security
configuration requirements, and d) remediate any
identified vulnerability or noncompliance with its
security configuration requirements based on
associated risk, exploitability, and impact. IBM takes reasonable care to avoid Cloud Service
disruption when performing its tests, assessments,
scans, and execution of remediation activities - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
IBM maintains and follows policies requiring
administrative access and activity in its Cloud
Services’ computing environments to be logged
and monitored, and the logs to be archived and
retained in compliance with IBM’s worldwide
records management plan. IBM monitors
privileged account use and maintain security
information and event management policies and
measures designed to a) identify unauthorized
administrative access and activity, b) facilitate a
timely and appropriate response, and c) enable
internal and independent third party audits of
compliance with such policies. IBM systematically
monitors the health and availability of production
Cloud Service systems and infrastructure at all
times. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
IBM: -maintains and follows incident response
policies aligned with NIST guidelines for computer
security incident handling, and will comply with
data breach notification requirements under
applicable law. -investigates security incidents,
including unauthorised access or use of content or
the Cloud Service, of which IBM becomes aware,
and, if warranted, define and execute an
appropriate response plan. -promptly notifies
Client upon determining that a security incident
known or reasonably suspected by IBM to affect
Client has occurred. -provides Client with
reasonably requested information about such
security incident and status of applicable remediation and restoration activities performed or
directed by IBM. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- 30 Day free Trial
- Link to free trial
- Link to free trial https://www.ibm.com/account/reg/us-en/signup? formid=urx-53025
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- NQA
- ISO/IEC 27001 accreditation date
- Monday 8 April 2024
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- NQA
- ISO 9001 accreditation date
- Monday 8 April 2024
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- SecurityMetrics
- PCI DSS accreditation date
- Friday 10 January 2025
- What the PCI DSS doesn’t cover
- N/A
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- E9fd5f85-7cd1-4ff2-aba9-6f9f5f225b1b
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 181966c9-f0aa-42ed-9271-d1b111bdf43b
- Other security certifications
- Yes
- Any other security certifications
- Security Standards dependant on the vendor solution
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Collection of the views and expertise of disabled people and their representative organisations on successfully supporting disabled employees or applicants
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Introducing transparency to pay and reward processes
- Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Content of the outreach activity is designed to suit the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-