3sixty Web PCN Notice Processing with Self-Service
3sixty Web Notice Processing is Imperial Civil Enforcement Solutions powerful back-office software solution that offers automated, end-to-end notice processing with very little need for manual intervention. 3sixty and its public facing self-service portal, 3sixty Citizen will streamline the way you deliver your parking services and interact with customers.
Features
- End-to-end notice processing for both PCNs and environmental
- Workflow management
- Browser based accessibility
- Reporting and management information tools
- Real-time handheld device using smartphone technology
- Public facing, branded portal offering fully transactional service
- ChallengeSmarti guided self-help appeals tool
- LetterSmarti intelligent letter writing tool
- GeoSmarti geographic information system
- GoSmarti 'call to action' tool
Benefits
- Enables customers to meet digital objectives and transform service delivery
- Introduces significant cost savings and added value
- Provides a fully transactional web service for motorists
- Has additional tools and interfaces that will facilitate community engagement
- Hosting boosts efficiency of budget negating need for capital outlays
- Business processing service offering improved recovery rates
- Flexible solution to accommodate specific customer needs and requirements
- Management tools promote intelligence led enforcement
- Constantly evolving solution with customer led upgrades twice yearly
- Seamless and rapid implementation – integration with multiple third parties
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 6 5 2 8 1 9 1 9 9 5 1 2 6 5
Contact
IMPERIAL CIVIL ENFORCEMENT SOLUTIONS LIMITED
Phil Howell
Telephone: 01179251700
Email: tenders@imperial.co.uk
About your service
- Service categories
-
Applications
Production and operations
- Other operations
Service industry and public sector operations
- Public Order and Safety
- Other
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Hybrid cloud
- Service constraints
- No
- System requirements
- Modern Browser
User support
- Email or online ticketing support
- Yes
- Support response times
- Call and emails are acknowledged immediately. Best practice SLAs apply.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Imperial provides on-site training and technical support. As part of these, a trainer and or consultant is dispatched. For pricing and daily rates, please refer to the SFIA score card.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Following a discovery meeting, where user requirements are assessed, clients are handed over a fully tailored system.
The on-boarding service includes a one day user training. Imperial support services are available from the outset should the client require. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- At the end of the contract, the service is switched off, the client is provided with a copy of their data in an agreed format.
- End-of-contract process
- All client data in possession of Imperial is securely deleted. In case this coincides with decommissioning of hardware then the hardware is also securely disposed of.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Onboarding and offboarding documentation is written in plain English with support from our projects team
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The self-service portal is mobile optimised, no functional differences exist
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
3sixty has a dedicated web portal for the public - 3sixty Citizen. 3sixty Citizen allows the public to instantly pay their PCN, review evidence or contact the Council online. The portal is tailored to match the ‘look and feel’ of the Council’s own website.
ChallengeSmarti is a cloud-based self-service system that provides motorists with an enhanced customer experience, providing transparency of your organisational policies, enabling them to make informed decisions regarding their challenges. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
We visually inspect pages, adjusting browser settings to ensure we can increase/decrease font sizes easily, switching to black and white to ensure elements indicated by colour can also be identified in other ways and using Audio reader/navigation tools such as JAWS.
We check the html mark-up of each screen against a selection of validation tools including:
• AChecker (http://achecker.ca/checker/index.php)
• Wave (http://wave.webaim.org/)
We check the contrast ratios of font colours against their background using tools such as:
http://leaverou.github.io/contrast-ratio/
We inspect the screens visually taking into account the applicable guidelines.
For each new website installation we run the relevant checking tools as part of the system test process to ensure that the Council’s corporate layout and accessibility requirements fit with our website structure. - API
- Yes
- What users can and can't do using the API
- A range of APIs for interacting with enforcement hardware.
- API documentation
- Yes
- API documentation formats
-
- Other
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Users can customise progression trees and letter templates in the back-office notice processing system.
Imperial will tailor the look and feel of the self-service portal according to the client`s requirement
Scaling
- Independence of resources
- Infrastructure is designed with considerable headroom to cope with peak traffic and is monitored for issues.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Standard in-built data export facilities enable users to export DVLA data, enforcement agents` data, any report generated as well as case search results. To allow for 3rd party printing, all required data can be exported
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XLS
- Data import formats
- Other
- Other data import formats
- XML
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
- Other
- Other protection within supplier network
- We have an MPLS link between our offices.
Availability and resilience
- Guaranteed availability
-
Owing to the headroom, redundancies and monitoring incorporated into our infrastructure, we are able to
guarantee 99.5 per cent uptime. Imperial works in accordance with its hosted service SLA, which lays down incident severity levels and resolution times.
Imperial will take all reasonable step to achieve a Resolution of
Incidents within the Target Resolution Times. In the event Imperial fails to meet a service level, service credits will be calculated which can be used for ICES services or training - Approach to resilience
-
The system is operated from one of two Datacentres running in an Active/Active mode, date being replicated continuously between datacentres. Recovery Point Objective (RPO) time is 30 minutes, Recovery Time Objective (RTO) is 4 hours.
Data is backed-up to opposing sites and to off-site tape, as ta vendor-independent backup of last resort. - Outage reporting
- Instant messaging, e-mail and SMS alerts to Support Team.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Access is restricted through elevated accounts in active directory.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Access Control systems are in place to protect the interests of all users of the Company computer systems by providing a safe, secure and readily accessible environment in which to work. A formal process is
conducted at regular intervals by system owners and data owners in conjunction with the Infrastructure Department to review users’ access rights. Confidentiality and data protection clauses are integral part of
the employment contracts as well as contracts with business entities. In addition Imperial has Data Protection and Information Security Policies in place. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
We follow the agile software development methodology. Typically we release 2-3 new versions of our system annually however the release dates depend on when tangible business benefits using the new
version can be delivered.
When a new release is available all users are emailed with a set of detailed release notes documenting the changes, additions and fixes in the release. Where a change, addition or fix is of a particular benefit to a
specific customer they are contacted directly by Imperial Support. - Vulnerability management type
- Undisclosed
- Vulnerability management approach
- Imperial monitors various sources to detect and counter potential threats, vulnerabilities, and exploitation techniques. We regularly review security alerts from accredited bodies including National Cyber Security Centre, applying the latest updates and patches through our Information Security Management System. Leveraging tools like Microsoft's WSUS, NetSparker, Qualys SSL check, NMAP, OpenVAS, Rapid 7 Insight Agents, and CrowdStrike, we conduct comprehensive vulnerability scans and penetration tests, both internally and externally. Our testing frequency includes annual, major release, and architectural change assessments, promptly addressing any critical issues. Following an ISO27001 approach, we aim to eliminate, mitigate, or accept risks while ensuring swift resolution
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- All actions within the 3sixty notice processing system are logged, allowing configuration for document/email production or internal notifications. History logs associated with each case are accessible to back-office users with appropriate privileges, sortable to user preference, and cannot be altered. SAFE reports and system logs provide a comprehensive audit trail, accessible only to administrators. SAFE reports can be cleared in compliance with GDPR, while system configuration audit messages persist. We manually inspect logs for troubleshooting and investigations. Evaluation of Zabbix monitoring tool for real-time system performance tracking and synthetic transaction emulation is underway, enhancing monitoring capabilities.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Imperial maintains robust procedures for managing data breaches, swiftly responding to both internal and external incidents, guided by ITIL principles. A dedicated Data Protection Officer ensures compliance and facilitates communication with the ICO. Any breach is promptly assessed and reported to the Council, potentially involving ICO notification within 72 hours if deemed necessary. Imperial retains detailed incident logs, providing comprehensive information to the Council, supporting customer liaison with the ICO, and implementing remedial actions. Internal escalation involves immediate reporting to senior management for investigation, addressing causes, implementing safeguards, and considering training or disciplinary measures as needed.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Alcumus ISOQAR
- ISO/IEC 27001 accreditation date
- Monday 8 January 2024
- What the ISO/IEC 27001 doesn’t cover
- N/A - Whole organisation covered
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Alcumus ISOQAR
- ISO 9001 accreditation date
- Thursday 29 February 2024
- What the ISO 9001 doesn’t cover
- N/A - Whole organisation covered
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Ad1586d3-9721-472b-81e9-129f503911a3
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Ensuring new workers are informed of their right to join a trade union
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-