Azure Infrastructure as Code (IAC)
Managing Microsoft public cloud infrastructure via code to facilitate automation of deployment and configuration. Streamlining processes and consistency via version-controlled templates
Features
- Web-based access
- Code-driven deployment and administration
- Distributed version control system for tracking changes efficiently
- In-depth change control and change tracking
- Command-line interface for managing Azure resources programmatically
Benefits
- Automated resource provisioning and configuration
- Version-controlled templates for consistency
- Scalable infrastructure deployment
- Repeatable processes for reliability
- Collaboration through shared codebase
- Modular architecture for flexibility
- DevOps integration for continuous deployment
- Rapid environment provisioning
- Simplified infrastructure lifecycle management
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 0 2 9 2 1 6 8 7 4 6 9 3 0 3
Contact
WAVENET LIMITED
Paddy Sheridan-Ruddy
Telephone: 07714737991
Email: publicsector@wavenet.co.uk
About your service
- Service categories
-
IaaS
IaaS Compute
Virtualised x86
- General purpose
Service scope
- Service constraints
- Learning complexities arise as users need proficiency in Azure tools and coding languages, and effective cost management necessitates diligent monitoring. Wavenet's expertise in these areas can remove these barriers to facilitate a successful IAC deployment
- System requirements
-
- Internet connectivity to access resources
- Properly configured Azure subscription(s) for provisioning of Azure resources
- A suitably licenced code repository, such as Github
- Cloud deployment model
- Public cloud
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
-
Wavenet provides a Service Desk function for the purpose of handling incidents, events, problems, changes and service requests.
Wavenet will provide the customer with a primary Service Desk contact point for customer service requests - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Any customers on managed support will have a dedicated account manager and will be assigned a support team of engineers ranging from 1st line to 3rd line in ability. Escalation points are available with optional to follow through with issues until resolution. Costs vary depending on the Azure resources being supported.
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
- Wavenet's team of Professional Services Consultants, including Azure Technical Architects, deliver a low-level design and implementation service for Azure Infrastructure as Code (IaC). Typically Wavenet will lead discovery and consultation sessions to establish user requirements before implementing Infrastructure as Code (IaC). This may then be optionally maintained by Wavenet in the form of a managed service or handed over to the User should they retain suitable technical capabilities in-house. In the case of handover, detailed low-level design documentation will be shared with the user and in-depth handover meetings will take place, in addition to securely delegating access to the codebase itself to the user.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Data pertinent to Infrastructure as Code specifically resides within the codebase itself. Typically this would be licenced to the User directly and can be freely extracted or deleted. The resources provisioned from the codebase into Azure itself are subject to Microsoft's terms for data extraction. As of March 2024 Azure now offers free data egress for customers wishing to leave Azure for another cloud or on-premises solution. This is a Microsoft-guided data transfer-out process via Azure support. Wavenet would assist the User with the raising of the initial request and handover to Microsoft support or any new provider as required.
- End-of-contract process
- Please see https://www.microsoft.com/en-us/trustcenter/privacy/you-own-your-data. Microsoft contractually commits to specific processes when a customer leaves a cloud service or the subscription expires. This includes deleting customer data from systems under our control. If you terminate a cloud subscription or it expires (except for free trials), Microsoft will store your customer data in a limited-function account for 90 days (the “retention period”) to give you time to extract the data or renew your subscription. During this period, Microsoft provides multiple notices, so you will be amply forewarned of the upcoming deletion of data. After this 90-day retention period, Microsoft will disable the account and delete the customer data, including any cached or backup copies. For in-scope services, that deletion will occur within 90 days after the end of the retention period.
- Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Using the web interface
- Via a code base such as Github, Privileged users can automate deployment, manage configurations, and collaborate securely with third parties by creating, configuring, updating, and deleting Azure resources using version-controlled templates, ensuring consistency and reliability. A Github repository interfaces with Azure directly via Azure DevOps to execute commands and allow for automated deployment. Users will not be able to store sensitive information such as keys in the code repository itself written in Domain Specific Languages (DSLs) such as Terraform and Bicep, and will instead be required to store them securely within, for example, an Azure Key Vault.
- Web interface accessibility standard
- WCAG 2.2 AA
- Web interface accessibility testing
- See https://www.microsoft.com/en-us/accessibility/
- API
- Yes
- What users can and can't do using the API
- The codebase REST API provides users with a comprehensive interface to interact programmatically with code repositories, users, and organizations. It enables a wide range of operations, including creating, reading, updating, and deleting repository contents, managing issues and pull requests, and accessing user and organization data. Users can integrate codebase functionalities into their applications, automate workflows, and build custom tools for managing and analysing code repositories. The API supports various authentication methods, including OAuth tokens, ensuring secure access to GitHub resources
- API automation tools
- Other
- API documentation
- Yes
- API documentation formats
- HTML
- Command line interface
- No
Scaling
- Independence of resources
- Web-based codebase providers are designed to be highly available. Azure is a hyper-scale public cloud service. Reservation of compute instances where applicable will guarantee availability. Microsoft's vast capacity across multiple datacenters in multiple regions ensures capacity on demand for non-reserved compute instances.
- Usage notifications
- Yes
- Usage reporting
-
- API
- Other
- Other usage reporting
- Emails raised via proactive monitoring tools will also prompt the support desk to contact key stakeholders by telephone if required to authorise changes
- Optimising consumption
- Yes
- Automatic scaling
- Yes
Analytics
- Infrastructure or application metrics
- Yes
- Metrics types
-
- CPU
- Disk
- HTTP request and response status
- Memory
- Network
- Number of active instances
- Other
- Other metrics
-
- Boot diagnostics
- Performance diagnostics
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Azure
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Other
- Other data at rest protection approach
- Data in Azure is encrypted at rest by default. See: https://learn.microsoft.com/en-us/azure/security/fundamentals/physical-security and https://learn.microsoft.com/en-us/azure/storage/common/storage-service-encryption
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Backup and recovery
- What’s backed up
-
- Azure Infrastructure as a Service (IaaS) servers
- Azure Storage Accounts
- Azure Managed Disks
- Azure File Shares
- SQL Databases
- Non-SQL Databases
- Kubernetes/Containers
- Codebase backups to cloud object storage
- Azure Platform as a Service (PaaS) resources
- Backup controls
- Azure Backup is highly configurable, with the capability to create and assign different backup policies to different Azure resources such as File Shares and Virtual Machines. Backup frequency and retention are highly configurable when using Enhanced Backup policies, with the capability to run backups multiple times per day, weekly, monthly or yearly with long-term retention options available using tiered storage for cost optimisation purposes. Backup storage immutability can be enabled to prevent backups from being prematurely deleted.
- Datacentre setup
- Multiple datacentres with disaster recovery
- Scheduling backups
- Supplier controls the whole backup schedule
- Backup recovery
-
- Users can recover backups themselves, for example through a web interface
- Users contact the support team
- Backup and recovery
- Yes
- RPO/RTO
- Yes
Data-in-transit protection
- Data protection between buyer and supplier networks
- Other
- Other protection between networks
- Codebase repositories are securely stored and backed up independently of Wavenet's network. Azure virtual networks entirely segregated from Wavenet's network with no requirement for data to enter Wavenet's network.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Role-Based Access Control (RBAC), Multi-Factor Authentication
Availability and resilience
- Guaranteed availability
- See Microsoft's Service Level Agreements (SLA) for online services: https://www.microsoft.com/licensing/docs/view/Service-Level-Agreements-SLA-for-Online-Services?lang=1
- Approach to resilience
- Numerous options are available to increase resilience subject to workload and business importance including (but not limited to) distribution of data and compute instances across multiple datacentres or Azure regions, synchronous or asynchronous replication of data for disaster recovery, robust encrypted and immutable backups
- Outage reporting
- Platform level outages are reported publicly via: https://azure.status.microsoft/en-gb/status. Individual servers/applications are proactively monitored and incidents raised with Wavenet helpdesk to remedy as required.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Other
- Other user authentication
- Conditional Access governs access based on logon location, device used for access and its compliance status.
- Access restrictions in management interfaces and support channels
- Microsoft Entra ID (Microsoft's cloud-based Identity provider) provides advanced identity management functionality such as Multi-factor authentication, device registration, self-service password management, self-service group management, privileged identity management and role-based access.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Devices users manage the service through
-
- Dedicated device on a segregated network (providers own provision)
- Any device but through a bastion host (a bastion host is a server that provides access to a private network from an external network such as the internet)
Audit information for users
- Access to user activity audit information
- Users receive audit information on a regular basis
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users receive audit information on a regular basis
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Wavenet is an ISO27001 certified company and we adhere to the standard and has an Information security management system drawn from ISO27002 and we follow the NIST standard for cyber security framework, we are audited on this standard annually, Wavenet is also a CE+ certified company.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Wavenet conform to ISO2000
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We conform to and follow the NIST standard and ISO27002
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We have continual monitoring with EDR solution feeding into a SIEM that is monitored 24/7 that is monitored by SOC
- Incident management type
- Supplier-defined controls
- Incident management approach
- Wavenet is ISO27001 certified and we follow the playbooks as part of our certification.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Separation between users
- Virtualisation technology used to keep applications and users sharing the same infrastructure apart
- Yes
- Who implements virtualisation
- Third-party
- Third-party virtualisation provider
- Hyper V
- How shared infrastructure is kept separate
- Logical separation of Azure resources into subscriptions associated with individual client Azure tenants. Access governed by Role-Based Access Control (RBAC), Multi-Factor Authentication (MFA) and Conditional Access.
Energy efficiency
- Energy-efficient datacentres
- Yes
- Description of energy efficient datacentres
- We leverage Power Purchase Agreements (PPAs) and purchase energy attribute certificates (EACs) to increase our renewable energy coverage.
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount
- Provide your minimum discount applicable to your baseline prices
- 1.5%
Formula for calculating price of your services
- Formula for calculating price of your services
-
Which of the core deployment models you intend to offer
- Public Cloud
- Private Cloud
Public Cloud - Formula for calculating price of your services
- Total Cost
- The Total Cost for a buyer's call off requirement in a Public Cloud Deployment
- =
- Baseline Pricing
- Baseline pricing can be found on the Microsoft Azure calculator
- Baseline Pricing - Web link
- https://azure.microsoft.com/en-gb/pricing/
- -
- Minimum Discounting
- 1.5%
- +
- Onboarding Activity
- Onboarding costs may vary based on your specific requirements, please confirm with suppliers during the clarification process
- +
- Additional sources of cost
- Additional sources of cost from the supplied baseline pricing may include Wavenet supplied elements such as: support, managed services, and bespoke requirements
- -
- Additional sources of cost reduction
- Some services may offer discounts and cost reductions based on sector, or for agreeing to a multi-year contract.
Private Cloud - Formula for calculating price of your services
- Total Cost
- The Total Cost for a buyer's call off requirement in a Private Cloud Deployment
- =
- Baseline Pricing
- Baseline pricing for our Private cloud deployments can be found in our G-Cloud service offerings.
- -
- Minimum Discounting
- 1.5%
- +
- Onboarding Activity
- Onboarding costs may vary based on your specific requirements, please confirm with suppliers during the clarification process
- +
- Additional sources of cost
-
Additional sources of cost that may affects deployments include fluctuations in vendor pricing or exchange rates.
Other factors include situations where expectations for level of utilisation, capacity or storage have been specified, and these have then been exceeded by the customer. - -
- Additional sources of cost reduction
- Some services may offer discounts and cost reductions based on sector, or for agreeing to a multi-year contract.
Mandatory certifications
- Mandatory certifications
-
Are you are bidding to offer IaaS and/or PaaS as a reseller or are you in sole control of the infrastructure
ResellerCloud service suppliers you intend to resell with evidence
Organisation 1
Organisation name
MicrosoftWebsite address/upload for organisation
UploadUpload
ProvidedOrganisation 2
Organisation name
Hewlett Packard EnterpriseWebsite address/upload for organisation
Website addressWebsite address
https://partnerconnect.hpe.com/partner/wavenet-gb121801474Organisation 3
Organisation name
Asanti Datacentres LtdWebsite address/upload for organisation
Website addressWebsite address
https://asanti.com/partners/ISO 9001 certification
ProvidedISO 27001 certification
ProvidedISO 20000-1 certification
ProvidedAre you reliant on the Cloud Service Provider for some accreditations
Yes
Cyber Essentials
- Do you have a Cyber Essentials Plus certificate?
- Yes
- Cyber Essentials Plus certificate Number
- 6cc5c85d-03f1-446c-9e9d-7338dfb9f0ce
Non-mandatory Standards and certifications
- ISO 28000:2022 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Plans for positive actions with community groups.
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-