Skip to main content

Help us improve the Digital Marketplace - send your feedback

XEROX (UK) LIMITED

Xerox IT Solutions - HPE Aruba Networking - Secure Access Service Edge (SASE)

Xerox ITS provide a comprehensive Secure Access Service Edge service. Based upon HPE Aruba Networking SASE made up of WAN Edge (SDWAN) and Secure Services Edge (SSE) services that deliver ZTNA, SWG, CASB and DEM. Protection with a Universal ZTNA arhictecture

Features

  • WAN Edge (SDWAN)
  • Zero Trust Network Access (ZTNA)
  • Secure Web Gateway (SWG)
  • Cloud Access Security Broker (CASB)
  • Digital Experience Monitoring (DEM)

Benefits

  • enable network and security teams to enable secure access
  • SDWAN provides next generation firewall capabilities
  • SWG protects the business against advanced attacks
  • CASB enables identification and control of cloud services
  • DEM gives enhanced in-line visibility of devices and users
  • Centralised orchestration of business and security policies
  • WAN optimisation to improve performance.

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at uxb.bidteam@xerox.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 7 0 7 0 6 9 4 1 6 5 3 0 3 7

Contact

XEROX (UK) LIMITED Steve Young
Telephone: 01895251133
Email: uxb.bidteam@xerox.com

About your service

Service categories

Systems Infrastructure Software

Security

  • Cloud native application protection platform
  • Security analytics
  • Governance, risk and compliance

Identity and access management

  • Access
  • Privilege

Network security

  • Trusted network access and protection
  • Active application security

Data security

  • Information protection
  • Digital trust
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
  • Hybrid cloud
Service constraints
SDWAN solution requires HPE Aruba Networking Edgeconnect devices to be managed by centralised orchestrator.
System requirements
  • SDWAN requires connectivity to internet services
  • SSE license tiers enable and unlock SWG, CASB, DEM

User support

Email or online ticketing support
Yes, at extra cost
Support response times
For High severity incidents where an incident is causing an extremely serious impact to the business - 15 minutes
For Medium severity incidents where an incident is causing significant impact to the business - 30 minutes
For Low severity incidents that affect service and where there is small impact to the business - 60 minutes
Where 24x7 service is in place, these response times are consistent throughout the entire service period.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes, at an extra cost
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
None.
Onsite support
Yes, at extra cost
Support levels
Operating a fully managed 24x7 support desk we provide L1 through to L3 support and vendor interface. This can be used in UK office hours or as a 24x7 service, and includes full service management and technical account management. We are ISO 20000 accredited and our service processes align to that and to ITIL.

Support packages are always designed bespoke to fit each clients particular requirements, and typically will comprise one of the following:
a. First and second line service desk - from £500 pcm
b. Third line escalated service desk - from £750 pcm
c. Full service desk offering - from £1,000 pcm
d. Full service desk offering with proactive service management to include monitoring and patching - from £1,500 pcm

Service levels are set for response and resolution by incident severity and are defined to match client needs.

Service and account management encompasses analysis, reporting, major incident response, technology reviews, advice and guidance.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
Onboarding consists of workshops and training, both in person and online.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
Configuration and data extracts are available from the platforms at contract end.
End-of-contract process
Subscription services are terminated and a phase of data extraction if required.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Documentation is accessible and delivered by the Project Management function, at the appropriate phase of deployment

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Accessed via internet browser
Accessibility standards
None or don’t know
Description of accessibility
Accessible through web browser.
Accessibility testing
Orchestrator has operations in light and dark mode.
API
Yes
What users can and can't do using the API
There are several ways for accessing the swagger definitions.

A running instance of Orchestrator 9.3 and EdgeConnect appliance running ECOS 9.3 and using the GUI
Download the APIs directly from the silver-peak.com support site.
Download the definitions from Orchestrator instance and EdgeConnect appliance.
The swagger 3 APIs have a json file that goes with each release, and can be easily copied from the release’s webui directory.
For the Orchestrator, the json object is under:
/home/gms/gms/webcontent/webclient/html/apiDocs/gmsApiInfo.json
For the EdgeConnect appliance it is under:
/opt/tms/lib/web/content/node/apiDocs/vxoaApiInfo.json
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
No

Scaling

Independence of resources
The indepence of service is hosted in public cloud providers. The orchestrator tool when deployed in a private cloud will adhere to Xerox ITS data centre services hosted in a resilient deployment. More information is available upon request

Analytics

Service usage metrics
Yes
Metrics types
Service metrics include complete WAN link statistics for SDWAN service. Including, line performance, application visibility, throughput and complete metrics of users.
SSE provides metrics for all applications, users and complete digital experience.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
HPE Aruba Networking SASE

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
At least every 6 months
Penetration testing approach
In-house
Protecting data at rest
Encryption of all physical media
Data sanitisation process
No
Equipment disposal approach
A third-party destruction service

Data importing and exporting

Data export approach
Via the management platform
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
HPE Aruba Networking Secure Service Edge (SSE) is a cloud-delivered security solution with a committed Service Level Objective (SLO) for 99.9% monthly availability (uptime). This guarantee excludes any scheduled downtime, for which customers are provided advance notice.
Approach to resilience
Available upon request
Outage reporting
Service outage is reported in the public dashboard, through API integration and with email alerts.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
The orchestrator for SDWAN Edgeconnect uses an integrated Identity access managment (IAM) service that will restrict persmissions based on roles. This is integrated with MFA services.
SSE platform has a dedicated IAM service that has role based access for administrators, operators or viewers with restricted access based on policies.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
Information security policies and processes
Available upon request
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Configuration and change management adheres to out ITIL framework aligned, ISO 20000 accredited processes.
All configurations (or assets) are recorded in our configuration management database (CMDB) within our service tooling. These asset records are kept up to date through incident and change processes. Analysis of incident trends is made against these, and management of lifecycle events are automatically triggered.
Change management follows a full change process controlled by the change advisory board and is specifically designed on each engagement to dovetail with the clients own change process.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Security Advisories and Bulletins: Aruba publishes security advisories and a vulnerability response policy on its website. Xerox ITS will monitor these bulletins for information on identified vulnerabilities and recommended actions, such as software upgrades and workarounds. The main location for this information is the HPE Aruba Networking Support Portal.
Patching and Resolution: Advisories typically include recommended software versions or patches to address specific vulnerabilities.
Community and Support: The HPE Aruba Networking Airheads Community and formal support services offer guidance for configuration assistance and addressing potential false positives from vulnerability scanners.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Xerox ITS receive information from HPE Aruba Networking and act accordingly
Incident management type
Supplier-defined controls
Incident management approach
We are ISO 20000 accredited and follow processes that are closely aligned to the ITIL framework, this includes Incident Management.

As part of our managed service process, the customer is provided with full details of how to log a support call, including all logging methods and the required information for the service desk. It is then managed by the team under the service desk based on severity and service levels. Escalations procedures are provided as part of the onboarding.

For major incidents, a Major Incident Report is generated and shared with the client's management representative and includes root cause analysis.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Dependent on size and scale of potential service, a proof of concept (POC) service can be managed by Xerox ITS or directly from HPE Aruba Networking SASE

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0.01%
Between £250,000 and £500,000
0.01%
Between £500,001 and £1,000,000
0.01%
Between £1,000,001 and £2,500,000
0.01%
Between £2,500,001 and £5,000,000
0.01%
Over £5,000,001
0.01%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
BSI
ISO/IEC 27001 accreditation date
Thursday 11 July 2024
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
BSI
ISO 9001 accreditation date
Friday 15 March 2024
What the ISO 9001 doesn’t cover
N/A
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
0eab3d37-9204-413e-9c9c-bd6fd5e69c99
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
Ce7299cc-729f-4f32-81fb-f3bc41540d66
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at uxb.bidteam@xerox.com. Tell them what format you need. It will help if you say what assistive technology you use.