Xerox IT Solutions - HPE Aruba Networking - Secure Access Service Edge (SASE)
Xerox ITS provide a comprehensive Secure Access Service Edge service. Based upon HPE Aruba Networking SASE made up of WAN Edge (SDWAN) and Secure Services Edge (SSE) services that deliver ZTNA, SWG, CASB and DEM. Protection with a Universal ZTNA arhictecture
Features
- WAN Edge (SDWAN)
- Zero Trust Network Access (ZTNA)
- Secure Web Gateway (SWG)
- Cloud Access Security Broker (CASB)
- Digital Experience Monitoring (DEM)
Benefits
- enable network and security teams to enable secure access
- SDWAN provides next generation firewall capabilities
- SWG protects the business against advanced attacks
- CASB enables identification and control of cloud services
- DEM gives enhanced in-line visibility of devices and users
- Centralised orchestration of business and security policies
- WAN optimisation to improve performance.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 7 0 7 0 6 9 4 1 6 5 3 0 3 7
Contact
XEROX (UK) LIMITED
Steve Young
Telephone: 01895251133
Email: uxb.bidteam@xerox.com
About your service
- Service categories
-
Systems Infrastructure Software
Security
- Cloud native application protection platform
- Security analytics
- Governance, risk and compliance
Identity and access management
- Access
- Privilege
Network security
- Trusted network access and protection
- Active application security
Data security
- Information protection
- Digital trust
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- SDWAN solution requires HPE Aruba Networking Edgeconnect devices to be managed by centralised orchestrator.
- System requirements
-
- SDWAN requires connectivity to internet services
- SSE license tiers enable and unlock SWG, CASB, DEM
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
-
For High severity incidents where an incident is causing an extremely serious impact to the business - 15 minutes
For Medium severity incidents where an incident is causing significant impact to the business - 30 minutes
For Low severity incidents that affect service and where there is small impact to the business - 60 minutes
Where 24x7 service is in place, these response times are consistent throughout the entire service period. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes, at an extra cost
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- None.
- Onsite support
- Yes, at extra cost
- Support levels
-
Operating a fully managed 24x7 support desk we provide L1 through to L3 support and vendor interface. This can be used in UK office hours or as a 24x7 service, and includes full service management and technical account management. We are ISO 20000 accredited and our service processes align to that and to ITIL.
Support packages are always designed bespoke to fit each clients particular requirements, and typically will comprise one of the following:
a. First and second line service desk - from £500 pcm
b. Third line escalated service desk - from £750 pcm
c. Full service desk offering - from £1,000 pcm
d. Full service desk offering with proactive service management to include monitoring and patching - from £1,500 pcm
Service levels are set for response and resolution by incident severity and are defined to match client needs.
Service and account management encompasses analysis, reporting, major incident response, technology reviews, advice and guidance. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
- Onboarding consists of workshops and training, both in person and online.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Configuration and data extracts are available from the platforms at contract end.
- End-of-contract process
- Subscription services are terminated and a phase of data extraction if required.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Documentation is accessible and delivered by the Project Management function, at the appropriate phase of deployment
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Accessed via internet browser
- Accessibility standards
- None or don’t know
- Description of accessibility
- Accessible through web browser.
- Accessibility testing
- Orchestrator has operations in light and dark mode.
- API
- Yes
- What users can and can't do using the API
-
There are several ways for accessing the swagger definitions.
A running instance of Orchestrator 9.3 and EdgeConnect appliance running ECOS 9.3 and using the GUI
Download the APIs directly from the silver-peak.com support site.
Download the definitions from Orchestrator instance and EdgeConnect appliance.
The swagger 3 APIs have a json file that goes with each release, and can be easily copied from the release’s webui directory.
For the Orchestrator, the json object is under:
/home/gms/gms/webcontent/webclient/html/apiDocs/gmsApiInfo.json
For the EdgeConnect appliance it is under:
/opt/tms/lib/web/content/node/apiDocs/vxoaApiInfo.json - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
- The indepence of service is hosted in public cloud providers. The orchestrator tool when deployed in a private cloud will adhere to Xerox ITS data centre services hosted in a resilient deployment. More information is available upon request
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Service metrics include complete WAN link statistics for SDWAN service. Including, line performance, application visibility, throughput and complete metrics of users.
SSE provides metrics for all applications, users and complete digital experience. - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- HPE Aruba Networking SASE
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- In-house
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Via the management platform
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- HPE Aruba Networking Secure Service Edge (SSE) is a cloud-delivered security solution with a committed Service Level Objective (SLO) for 99.9% monthly availability (uptime). This guarantee excludes any scheduled downtime, for which customers are provided advance notice.
- Approach to resilience
- Available upon request
- Outage reporting
- Service outage is reported in the public dashboard, through API integration and with email alerts.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
-
The orchestrator for SDWAN Edgeconnect uses an integrated Identity access managment (IAM) service that will restrict persmissions based on roles. This is integrated with MFA services.
SSE platform has a dedicated IAM service that has role based access for administrators, operators or viewers with restricted access based on policies. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
- Available upon request
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Configuration and change management adheres to out ITIL framework aligned, ISO 20000 accredited processes.
All configurations (or assets) are recorded in our configuration management database (CMDB) within our service tooling. These asset records are kept up to date through incident and change processes. Analysis of incident trends is made against these, and management of lifecycle events are automatically triggered.
Change management follows a full change process controlled by the change advisory board and is specifically designed on each engagement to dovetail with the clients own change process. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Security Advisories and Bulletins: Aruba publishes security advisories and a vulnerability response policy on its website. Xerox ITS will monitor these bulletins for information on identified vulnerabilities and recommended actions, such as software upgrades and workarounds. The main location for this information is the HPE Aruba Networking Support Portal.
Patching and Resolution: Advisories typically include recommended software versions or patches to address specific vulnerabilities.
Community and Support: The HPE Aruba Networking Airheads Community and formal support services offer guidance for configuration assistance and addressing potential false positives from vulnerability scanners. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Xerox ITS receive information from HPE Aruba Networking and act accordingly
- Incident management type
- Supplier-defined controls
- Incident management approach
-
We are ISO 20000 accredited and follow processes that are closely aligned to the ITIL framework, this includes Incident Management.
As part of our managed service process, the customer is provided with full details of how to log a support call, including all logging methods and the required information for the service desk. It is then managed by the team under the service desk based on severity and service levels. Escalations procedures are provided as part of the onboarding.
For major incidents, a Major Incident Report is generated and shared with the client's management representative and includes root cause analysis. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Dependent on size and scale of potential service, a proof of concept (POC) service can be managed by Xerox ITS or directly from HPE Aruba Networking SASE
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0.01%
- Between £250,000 and £500,000
- 0.01%
- Between £500,001 and £1,000,000
- 0.01%
- Between £1,000,001 and £2,500,000
- 0.01%
- Between £2,500,001 and £5,000,000
- 0.01%
- Over £5,000,001
- 0.01%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Thursday 11 July 2024
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI
- ISO 9001 accreditation date
- Friday 15 March 2024
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 0eab3d37-9204-413e-9c9c-bd6fd5e69c99
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Ce7299cc-729f-4f32-81fb-f3bc41540d66
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-