Sterling Back Up Solution - Rubrik
Rubrik provides a zero-trust data protection platform across all data and applications, whether on-premises or in the public, private, or hybrid cloud. Rubrik provides Ransomware detection and remediation, Sensitive Data Discovery, Incident containment and Orchestrated Application Recovery all within a single management plane
Features
- backup data on premises, across multi cloud and SaaS environments
- Instantly recover data and applications locally or within the cloud
- Zero Trust Architecture - Fully encrypted and immutable platform
- Ransomware investigation and remediation
- Sensitive data discovery for GDPR and other data classification types
- Malware Threat hunting and containment
- Orchestrated and automated application recovery
- API first architecture for 3rd party integration
- m365 protection with air gap
- Single pain of glass presented via SaaS
Benefits
- Assured Recoverability against ransomware via a Zero Trust immutable platform
- Detect, Identify and Remiediate against Ransomware
- Database and Unstructured Data Protection at Scale
- Policy Based Automation for simplicty of management
- Rapid Recovery of services at Scale
- Orchestrated Recovery of applications and Services
- Single SaaS platform extending from data center to cloud
- Provide intelligence and compliance via senstive data discovery
- Meet and Exceed NCSC and NIST compliant data protection strategies
- Provide a secure by design air gapped environment
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 7 2 7 9 5 9 7 0 5 2 3 6 1 4
Contact
STERLING COMPUTERS CORPORATION (UK) LTD
Luke Flanagan
Telephone: +447557400401
Email: sterlinguk@sterling.com
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Business Intelligence
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- On premises deployment requires specific hardware and/or resource configurations
- System requirements
- Customer provided networking
User support
- Email or online ticketing support
- Yes
- Support response times
-
P1 system down SLA within 30 minutes
P4 query next business day SLA - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes
- Support levels
-
Premium - 24x7x365 follow the sun support
Basic - Mon-Fri 8am-8pm (local time)
optional Customer Experience Manager (cost uplift) - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Install Skills Transfer Handover via Professional Services
Online Free training via Rubrik University
Classroom/virtual training with certifications - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- VIA natural Expiration or manual migration via professional Services
- End-of-contract process
- Customer has recovery only capabilities with no support on product or services. For Rubrik hosted services, customer will have set amount of days to expire/export
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Via Support portal
Using the service
- Web browser interface
- Yes
- Supported browsers
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- CLI based support interface for Rubrik Support personnel - enabled by customer via a secure support tunnel
- Accessibility standards
- None or don’t know
- Description of accessibility
- Via Web Browser, cli or API
- Accessibility testing
- N/A
- API
- Yes
- What users can and can't do using the API
- Any function within Rubrik can be accessed via API's
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
- Through an intelligent and automated task scheduler managed via SLA policies
Analytics
- Service usage metrics
- Yes
- Metrics types
-
SLA compliance metrics
backup and restore
uptime and capacity - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Rubrik
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Multiple export options available via Rubirk interface and chosen cloud storage provider.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- N/A
- Approach to resilience
- Various hardware and software resiliency - details available on request
- Outage reporting
- Yes - public stats
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Rubrik uses MFA and biometric credentials for authentication to applications and baseline access is provisioned via RBAC and internal approvals (break glass) processes
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Sterling - ISO 270001, GDPR.
Rubrik - ISO 27001, 20000, EU/US Privacy shield, EU GDPR, SSAE 16 SOC 2, US HIPAA, US CJIS, UK ICO. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Rubrik has a set standard and processes for configuration and change management which can be provided on request
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Rubrik performs ongoing and constant reviews of its infrastructure and services as well as maintaining a trained staff within InfoSec and Compliance. Details of this can be provided on request
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Rubrik provides regular and proactive monitoring processes. Details of which can be provided on request
- Incident management type
- Supplier-defined controls
- Incident management approach
- Rubrik has a full set of IM and RCA processes. Details of these can be provided on request.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Public Services Network (PSN)
- Police National Network (PNN)
- Joint Academic Network (JANET)
- Scottish Wide Area Network (SWAN)
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 4%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7%
- Between £1,000,001 and £2,500,000
- 8%
- Between £2,500,001 and £5,000,000
- 9%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Perry Johnson Registrars INC
- ISO/IEC 27001 accreditation date
- Friday 13 December 2024
- What the ISO/IEC 27001 doesn’t cover
- Sterling’s ISO/IEC 27001:2022 certification covers our internal Information Security Management System supporting Sales, Solution Engineering, Order Fulfilment, and Professional Services Delivery. It does not extend to customer-owned environments, third-party systems, or customer platforms outside of Sterling’s operational control unless covered under a managed service agreement
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Perry Johnson Registrars INC
- ISO 9001 accreditation date
- Friday 29 December 2023
- What the ISO 9001 doesn’t cover
- Sterling’s ISO 9001:2015 certification covers our Quality Management System as an IT Service Provider and Reseller of IT Products and Services. It does not extend to customer-owned environments, third-party delivery outside Sterling’s contractual control, or customer-operated platforms and services.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- D689C512-D9CF-4BB3-AA95-B29C1B196210
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 46CE9863-70BD-47F7-88AE-2A4AE9DDD3E4
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-