Ivanti Neurons MDM
Neurons for MDM is a cloud-based Unified Endpoint Management platform securing and managing mobile devices, apps, data across iOS/macOS, Android, Windows, ChromeOS, offering end-to-end security, configuration, and lifecycle management. Providing mobile application management (MAM), secure email gateways, zero-trust security, automation, policy enforcement, app deployment, manage access, and protect sensitive information.
Features
- Endpoint Security and Management across multiple operating systems
- Mobile Application Management (MAM)
- Easy Onboarding to provide users with automated device enrolment
- Secure Email Gateway
- App distribution and configuration
- Secure email and personal information management (PIM) app
- Secure web browsing
- Conditional Access with passwordless user authentication
- Trust Engine for adaptive access control
- Reporting for in depth visibility and control of managed devices
Benefits
- Work safely from anywhere on any device
- One platform for any operating system and diverse endpoints
- Every endpoint protected while delivering great user experience
- Privacy and Compliance on any endpoint to protect sensitive data
- Ensure access from anywhere on personal and provided devices
- Provide a superior end-user choice and onboard with ease
- Rationalize IT resources needed for endpoint management
- Certified: FedRAMP Moderate Authority, CSA STAR, SOC 2 Type
- Remote troubleshooting for mobiles
- Integrations with over 400 technology partners
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 6 0 3 1 6 5 5 1 6 0 7 0 0 2
Contact
CW Systems Integration Limited
Robin Tyerman
Telephone: 07840839576
Email: robin.tyerman@cwsisecurity.com
About your service
- Service categories
-
Systems Infrastructure Software
Endpoint management
Output management
- Device Management
Client endpoint management
- Unified Endpoint Management
- IoT Device Management Software
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
-
Ivanti ITSM
Ivanti Security Controls (Patching)
Ivanti Application Control (application whitelisting & privilege management)
Ivanti Neurons Platform (Self Heal, realtime analysis,Remote Control, Discovery)
Ivanti Risk Based Vulnerability Management
Ivanti External Attack Surface Management
AI/Chatbot functionality - Cloud deployment model
-
- Public cloud
- Hybrid cloud
- Service constraints
- Upgrades are performed automatically by Ivanti Software where you will have access to upgraded functionality. Upgrades as part of the new version will not affect any configuration changes done within your environment and you will have the option of turning on or keeping the product enhancement features off as part of the new release. Versions are in-line with Year with quarterly upgrades. Notifications are issued well in advance by email and issued on user login to the Ivanti platform of any major release as part of the standard agreement.
- System requirements
-
- See link for full details:
- https://help.ivanti.com/mi/help/en_us/cld/8x/rn/MICloudReleaseNotes/Support_and_compatibilit.htm
User support
- Email or online ticketing support
- Yes
- Support response times
- P1 & P2 Respond within 15 minutes P3 Respond within 30 minutes P4 Respond within 60 minutes
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Currently meets WCAG 2.2AA standards with out platform provider, Atlassian, actively working to achieve WCAG 2.1AA as soon as possible
- Web chat accessibility testing
- Testing completed by our ITSM platform provider Atlassian
- Onsite support
- Yes, at extra cost
- Support levels
- Assurance Support provides simple break fix support with the addition of 8 hours per annum Experts on Demand for advice, problem solving and minor PS tasks. Retained Expertise is pre-packaged block of professional services time that can be easily consumed and used across all areas of our expertise during a 12 month period. Managed Service contracts provide a complete proactive service, providing break-fix support, platform management, change requests and 16 hours of experts on demand. Services can be provided during Standard Business Hours, Extended Business Hours and 24x7x365. All managed service customers are allocated a Service Assurance Manager and a Technical Account Manager.
- Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
- CWSI provides a full range of professional services from consulting, health checks and assessments to implementation & configuration of the Ivanti Neurons MDM platform. We work with our customers to help define their security and compliance strategies, creating a roadmap that aligns to industry best practice standards. We also offer migration services to support customers moving their devices from an existing MDM platform. Training services are available for customers administrators or a range of support and managed services is available to compliment customers own IT Teams capabilities.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
Data Extraction and Return.
Database Extract: Customers are typically provided with an extract of the SQL database containing their data upon contract termination.
Administrative Support: Ivanti or its service partners support users in securely transferring their data out of the system before services are decommissioned however this may incur additional charges
Self-Service Options: Administrators can manually export lists of users, devices, and reports to CSV files via the Admin Portal at any time during the active term. - End-of-contract process
- At the end of a contract customers have 30 days grace to remove devices before the Ivanti platform is inaccessible. The customer is responsible for extracting any data and configuration information they require from the platform before this period ends. If the customer requires any assistance with migration activities, this can be provided by CWSI as a chargeable professional services activity.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Same tenant URL is accessed via any web browser on a smartphone, tablet or desktop.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Service support is provide by CWSI's managed service team utilising our JIRA ITSM platform
- Accessibility standards
- None or don’t know
- Description of accessibility
- Our ITSM platform currently meets WCAG 2.2AA standards and our JIRA ITSM platform provider, Atlassian, is actively working towards WCAG 2.2AA standards as soon as possible.
- Accessibility testing
- Testing completed by our JIRA platform provider Atlassian.
- API
- Yes
- What users can and can't do using the API
- Full details can be found at: https://help.ivanti.com/mi/help/en_us/CLD/8x/api/LandingPage.htm
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
- The Multi-tenant solution is scaled based on the workflow subjected by each tenant, SQL DB's are unique to each client and not shared. Services are established to automatically deploy additional resources in the event of an increase of requirements.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Licence consumption
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Ivanti
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Ivanti
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- 99.9%
- Approach to resilience
-
Ivanti resides on the highly resilient cloud platform Microsoft Azure. The Ivanti services architecture adopts production and failover system resident within the UK but can also offer a wider platform in EEC or globally.
Azure proactively mitigates potential failures—reducing the failure impact on availability by 50 percent. Using deep fleet telemetry, Microsoft enables failure predictions with machine learning (ML)
and ties them to automatic live migration for several types of hardware failure cases, including disk failures, input/output (I/O) latency, and CPU frequency anomalies. As a result, VMs are live migrated off of “at-risk”
machines before they ever show signs of failing. This means VMs running on Azure are more reliable than the underlying hardware. Furtehr detaisl can be found here: https://azure.microsoft.com/mediahandler/files/resourcefiles/resilience-in-azure-whitepaper/Resilience%20in%20Azure.pdf
Ivanti also complies with many safety framworks upon its platform including SOC2 and ISO27001. Outage reporting, Ivanti solutions do not require systems to be brought offline to perform regular maintenance and system patching. MS Azure's own maintenance and system patching generally do not impact customers. - Outage reporting
-
Ivanti ITSM and Asset Manager solutions do not require systems to be brought offline to perform regular maintenance and system patching. MS Azure's own maintenance and system patching generally do not impact customers.
A public dashboard is available with email alert subscription.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access is restricted by Roles and Groups within the solution to ensure only those authorised can access the system via management interfaces and support channels
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- Less than 1 month
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Other
- Other security governance standards
- SOC2
- Information security policies and processes
- Control Objectives for Information and related Technology (COBIT) framework and have effectively integrated the ISO 27001 certifiable framework based on ISO 27002 controls, American Institute of Certified Public Accountants (AICPA) Trust Services Principles, the PCI DSS v2.0, and the National Institute of Standards and Technology (NIST) Publication 800-53 Rev 3 (Recommended Security Controls for Federal Information Systems).
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- In alignment with ISO 27001 standards, MS Azure Hardware assets are assigned an owner, tracked and monitored by the MS Azure personnel with Azure proprietary inventory management tools. MS Azure procurement and supply chain team maintain relationships with all MS Azure suppliers. Refer to ISO 27001 standards; Annex A, domain 7.1 for additional details. MS Azure has been validated and certified by an independent auditor to confirm alignment with ISO 27001 certification standard.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Ms Azure patches systems supporting the delivery of service to customers, such as the hypervisor and networking services. This is done as required per MS Azure policy and in accordance with ISO 27001, NIST, and PCI requirements. MS Azure Security regularly scans all Internet facing service endpoint IP addresses for vulnerabilities (these scans do not include customer instances). MS Azure Security notifies the appropriate parties to remediate any identified vulnerabilities. In addition, external vulnerability threat assessments are performed regularly by independent security firms. Findings and recommendations resulting from these assessments are categorized and delivered to MS Azure leadership.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- MS Azure's program, processes and procedures to managing antivirus / malicious software is in alignment with ISO 27001 standards. Refer to MS Azure's SOC 2 Type II report provides further details. In addition, refer to ISO 27001 standard, Annex A, domain 10.4 for additional details. MS Azure has been validated and certified by an independent auditor to confirm alignment with ISO 27001 and SOC2 Type 2 certification standards and others.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- MS Azure's and Ivanti's incident response program, plans and procedures have been developed in alignment with ISO 27001 standard. The MS Azure's SOC 2 Type II report provides details on the specific control activities executed by Microsoft. Please also refer
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
Premium Licence covering all MDM functionality for maximum of 30days
*Maybe subject to professional services charges. - Link to free trial
- Request a trial here: https://www.ivanti.com/lp/contact-us
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 2.5%
- Between £2,500,001 and £5,000,000
- 3.75%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Thursday 25 April 2019
- What the ISO/IEC 27001 doesn’t cover
- Nothing
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- E643ad5f-ba03-4c75-a554-5a44532480e6
- Other security certifications
- Yes
- Any other security certifications
- Cybersecurity Made in Europe (CSME)
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-