Defence Information Management Portal (DIMP)
This service provides a secure management information portal that is accessible to all MOD staff with a DII or RLI network connection. The portal provides a single point for delivering management and programme information. The core portal can be enhanced with a number of additional service options.
Features
- Document publication facility
- IL3 secure document transmittal up to and including OS
- Performance dashboard that provides customisable metrics and views
- A full ITIL conformant service desk
- Report creation
- A range of self-service applications
- Additional IL3 secure storage space in 100GB blocks
Benefits
- Secure document publication and delivery
- Enhanced security through CESG accreditation and regular ITSHC
- MOD accessibility provided through DII / RLI hosting
- Enhanced availability & reliability for MOD Customers
- Provision of a collaborative working environment
- Single source of data leading to reduced cost of ownership
- Multiple applications sharing ‘live data’ to all stakeholders
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 0 9 3 0 0 4 5 4 0 1 5 1 5 1
Contact
GENERAL DYNAMICS UNITED KINGDOM LIMITED
Lloyd Davies
Telephone: +44 (0) 771750 8689
Email: lloyd.davies@gd-ms.uk
About the service
- Service categories
-
Applications
Content workflow and management
- Document
Content services
- Content Sharing and Collaboration Applications
Enterprise portals and digital workspaces
- Multi-Audience Portals
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
-
Although each management information Portal is fully customisable and built to meet customer requirements they are based on core infrastructure components that are shared between all user communities. The DIMP infrastructure and feature set has its own agreed maintenance and release schedules.
GDUK will publish a roadmap setting out a schedule for future baseline updates and will ensure all customers are informed. All changes that impact customer services or business processes will be approved by a Change Advisory Board (CAB) that will include representatives from customers and sponsoring agencies. - System requirements
-
- Access to a DII/RLI Service Delivery Point (SDP)
- MOD DII/RLI approved workstation, PC or laptop
User support
- Email or online ticketing support
- Yes
- Support response times
- All requests will receive a response within 30 minutes
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
- GDUK provides a full support service and has a dedicated Service Management team for each DIMP. All support team members have SC level security clearance with DV staff and crypto custodians also available on site. The team covers the full range of ITIL service management processes and project leads are ITIL V3 expert qualified. All DIMP customers receive the same levels of service.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- GDUK will provide full on-boarding as part of the DIMP core service. On-boarding of customers will involve a customer liaison engineer developing a plan that is designed to reduce the risks and complexity of moving to a cloud based service. Initial user training and familiarization will be provided.
- Service documentation
- No
- End-of-contract data extraction
-
Service Off-boarding is initiated by the customer through a request to the Service Desk. The process will usually occur after expiration of the service agreement. If the customer requires that their data is returned then a data extraction service will be required. This service can be requested at any time during service provision.
GDUK will make the required data available using media provided by the customer and in line with the data security classification. Where a database or table is part of the service, a separate data extraction service will be required due to the potential complexity and volumes of data involved. - End-of-contract process
-
Custom portals require a minimum of twelve months’ commitment and a minimum of three months’ notice.
There are no additional fees for extracting and handing over basic customer data that includes such items as documents and individual files from within a storage area.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The customer can assign administrator rights to selected users that allow access to additional functionality and management features
- Accessibility standards
- None or don’t know
- Description of accessibility
- GDUK will provide a secure Defence Information Management Portal that is accessible to all MOD staff with a DII, MODNET or RLI network connection using a standard web interface.
- Accessibility testing
- Service look and feel is built to comply with MOD requirements using agreed formats, layout and colour schemes. MOD conformance testing carried out at Service handover.
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- Our service is aimed at specific MOD users where the capacity of our system exceeds the number of authorised users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Each management Information Portal is provided with a performance dashboard area that details basic contractual performance data including number of support calls, requests and Portal usage statistics along with response and resolution times.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- Less than once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- A data export is requested by the customer through the service desk.
- Data export formats
- CSV
- Data import formats
-
- CSV
- Other
- Other data import formats
Data-in-transit protection
- Data protection between buyer and supplier networks
- Private network or public sector network
- Data protection within supplier network
- Other
- Other protection within supplier network
- Our service and systems run within the MOD DII (Defence Information Infrastructure)
Availability and resilience
- Guaranteed availability
- The target percentage availability for all users of this service will be 98%. All measurements are taken over a rolling 4-week period and exclude downtimes due to Planned Maintenance and non-availability of supporting MOD based remote Services e.g. RLI Services, Network availability, DNS, SMI etc. The financial recompense model is based around a service credits. The model is agreed with the customer for each service deliverable and will typically consist of a service credit of up to 100% of the period’s service payment depending on the duration, cause and impact of the breached SLA.
- Approach to resilience
- Details of our approach to system resilience is available on request.
- Outage reporting
- There is a service notification and availability portal available to users.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Limited access network (for example PSN)
- Username or password
- Access restrictions in management interfaces and support channels
- Management and support channels are not published on the client side
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Limited access network (for example PSN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- No
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Defence Security and Assurance Services (DSAS) – Accreditation to IL3
- Information security policies and processes
-
The DIMP is hosted on DII and is cleared and accredited to hold information up to and including “Official-Sensitive” (IL3). It is accessible to all DII users and MOD industry partners who have an RLI Service Delivery Point (SDP).
The DIMP hosting facility is located within a secure data centre. All infrastructure at the hosting site is subject to a biannual IT Security Health Check (ITSHC). ITHSC activities and schedules have been agreed with the CESG RLI/DFTS Accreditor.
It is important to note that all users of the system must abide by the RLI code of connection. All customers and end users requesting use of any of the services offered must be appropriately Security Cleared and evidence provided to GDUK before service delivery can commence.
In addition the Customer must possess Facility Security Clearances (FSC) premises and ensure that information derived from the DIMP is properly protected. The customer and end user are responsible for the protection and control of any data output produced during the service duration. Data output including all reports will be marked “Official-Sensitive”. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- All service components are managed within ITIL conformant change and configuration management processes. All changes are approved by the CAB and the CESG RLI/DFTS approved accreditor or STO.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- A dedicated security team are tasked with maintaining system security and vulnerability management. Bi-annual penetration testing is carries out with activities and schedules agreed with the CESG RLI/DFTS Accreditor. Team have access to the MOD Vigilant system and respond to all MODCERTs within the agreed timeframe
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- A dedicated security team is tasked with monitoring all systems and services and respond appropriately and in line with MOD guidance.
- Incident management type
- Supplier-defined controls
- Incident management approach
- A fully ITIL conformant service desk is available to all customers to manage Incidents and Service Requests.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Other
- Other public sector networks
- RLI
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- ISO 9001 certification accredited by
- BSI
- ISO 9001 accreditation date
- Friday 2 August 2024
- What the ISO 9001 doesn’t cover
- Our ISO 9001 certification does not cover those elements of our service delivery mechanisms that are under the direct control of MOD or their designated partners or subcontractors
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- D8a08dd7-887d-46c5-8c6a-ed849e0f0b25
- Cyber essentials plus
- Yes
- Cyber Essentials Plus Certificate Number
- 3e7084f0-6a07-4cd8-8fdd-d3933862abbc
- Other security certifications
- No
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications