Bentley Systems (UK) Limited

BCDE Common Data Environement

Bentley provides the leading AIM CDE for Clients to securely digitise and optimise asset and estate performance. BCDE Common Data Environment supports the capture and assurance of supplier-delivered project information, maintaining this throughout the asset lifecycle, helping Government Departments procure asset information in accordance with UK and international industry standards.

Features

  • Client Asset Information Management Common Data Environment (AIM CDE)
  • Supports CAPEX (project) and OPEX (asset) information lifecycle workflows
  • Templated ISO19650 (PAS1192-2) CDE supporting official/sensitive and secret classifications
  • Supports client and supplier information delivery planning and sssurance
  • Collaborative document, drawing and email management with version control
  • Supports supplier check, review, approve and client acceptance workflows
  • Tendering, procurement and contract communications (NEC, RFIs, TQs, Site Instructions)
  • Real-time visual dashboard reporting of project performance and risk
  • Integration API for third party applications
  • Integrated mapping interface for CDE and external geospatial data

Benefits

  • Quick to mobilise and easy to use facilitating client adoption
  • Secure, controlled access to trusted project and asset related information
  • Reduce mistakes and rework using templates and industry standards (ISO19650)
  • Improve decision making through online searching and real-time reporting
  • Drive project-wide benefits through best practice and knowledge sharing
  • Improve compliance by driving use of industry/organisational standards
  • Structure and track information deliverables across programmes and projects
  • Deliver team-wide access to geospatial information and connected data sources
  • Improve quality of project (PIM) to asset (AIM) digital handover
  • Reduce costs and risks of client and supplier information exchange

Pricing

£18 a user a month

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gcloud@bentley.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 13

Service ID

2 3 7 7 2 9 0 6 9 9 6 4 9 9 8

Contact

Bentley Systems (UK) Limited Andy Bowles
Telephone: +44 7919 892183
Email: gcloud@bentley.com

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
The current and previous release of the software are supported from a maintenance perspective. If defects are found in releases earlier than this an upgrade to a current release will be required to resolve.
System requirements
  • Access to the Internet
  • Up-to-date web browser

User support

Email or online ticketing support
Email or online ticketing
Support response times
As described in the SLA agreement
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
Support shall be provided between the hours of 9:00am and 5:30pm, UK time, Monday to Friday excluding English bank holidays.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Training is primarily e-learning-based for end-users who can use it a job aid to complete tasks. Admin users have access to specific e-learning, which can be topped with consultant coaching as the need requires. Depending on the requirement, this may incur addtional costs.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Any authorised user can download the data to which they have access via a selectable download option at any time. Optionally, we also provide an online archive at an additional cost.
End-of-contract process
Any authorised user can download the data to which they have access via a selectable download option at any time. Optionally, we also provide an online archive at an additional cost.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The interface is a fully responsive HTML 5. The majority of the core functionality is available on both desktop and mobile.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Full secure systems administration via the web.
Accessibility standards
None or don’t know
Description of accessibility
The user interface is built using the Bootstrap 3 interface framework which provides a responsive view across desktops, laptops, tablets and phones. The interface can be zoomed/scaled as required. The interface is partially compliant with WCAG 2.1 A. The interface partially passes items defined in (Web) EN 301 549.
Accessibility testing
There has been no testing with users of assistive technology.
API
Yes
What users can and can't do using the API
A set of worked examples using the API can be found here:
https://gitlab.com/groupbc/webservice-examples

A set of available API endpoints is documented and available for users of a BC server. This is documented in the examples above.
API documentation
Yes
API documentation formats
  • HTML
  • Other
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
Selected Admin users can configure aspects of the look and feel of the system. These include Logo, Home Page Image, Portals and Views. Client Terms and Conditions of use can also be maintained.
Selected Admin users can configure myriad aspects of the solution including folder structures, metadata, workflow and reports.
(Such configurations survive Updates).

Scaling

Independence of resources
Systems are logically separated in a virtual cloud environment. All systems are monitored for performance and availability.

Analytics

Service usage metrics
Yes
Metrics types
Storage summary - by Project, User;
Recent user activity;
User details;
Commonly access items;
and more.
Reporting types
Reports on request

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Up to Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
Physical access control, complying with SSAE-16 / ISAE 3402
Data sanitisation process
Yes
Data sanitisation type
Deleted data can’t be directly accessed
Equipment disposal approach
A third-party destruction service

Data importing and exporting

Data export approach
Download is a standard feature of the application using a web browser
Data export formats
  • CSV
  • Other
Other data export formats
  • In the original format of uploading.
  • XML
Data import formats
  • CSV
  • Other
Other data import formats
No restrictions to the MIME types of associated uploaded files

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Service Credits are due in case of failure to meet the SLA 99.9% uptime assured by contractual commitment.
Approach to resilience
Available on request.
Outage reporting
An emailed report of outages is available on request.

Identity and authentication

User authentication needed
Yes
User authentication
  • 2-factor authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
Bentley IMS may also be used to authenticate users, providing a single identity for all Bentley products.
Access restrictions in management interfaces and support channels
Bastion hosts on a management network.
Access restriction testing frequency
At least once a year
Management access authentication
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
Between 6 months and 12 months

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber essentials plus
Yes
Other security certifications
No

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Bentley has various externally audited programmes including an ISO 27001 programme with certification for our Managed Services hosted deployments, and a SOC 2 programme which includes a report for our cloud services platform. While BCDE is not currently in scope of either of those certifications, Bentley has a mature ISMS program with appropriate corporate and enterprise level polices.
BCDE’s cloud hosting provider Secura carries a current ISO27001 certification. BCDE has Cyber Essentials Plus Certification.
To review Bentley’s third-party audits and certifications by relevant attestation bodies such as ISO, SOC, CSA Star, please visit our Trust Center at https://www.bentley.com/en/trust-center.
Information security policies and processes
All Bentley colleagues are required to review and acknowledge Bentley's Information Security Policy upon hire and thereafter annually. The policies themselves are emailed out at least annually and reside permanently on Bentley's intranet site for quick retrieval.

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Available on request.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Potential threats and information about threats are identified by using Internet Security Communities such as OWASP and by making the knowledge and defensive coding against threats part of the development team responsibilities. The level of threat will determine the speed of the deployment of the patches.
Protective monitoring type
Undisclosed
Protective monitoring approach
Enhanced Intrusion Protection and Detection can be provided at additional cost.
Incident management type
Supplier-defined controls
Incident management approach
Incidents are managed in an Incident Database solution that stores, tracks and reports on incidents. Where an incident involves a customer interaction, the interaction is logged and tracked through the online help-desk system.
The support team will respond in a common fashion to events reported by the automated monitoring tools.

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Social Value

Fighting climate change

Fighting climate change

Bentley’s mission is to leverage our leading software and services to drive impact through the world’s
infrastructure – advancing both the global economy and the environment for improved quality of life. As
part of our Environmental, Social, & Governance (“ESG”) strategy, we are committed to managing our
business in a way that enhances the environmental impacts of our products and mitigates
environmental risks from our operations. Our Environmental Policy details our commitments to
Environmental Responsibility and the ways in which we expect our colleagues to act to drive progress on
our ESG strategy. Bentley expects all colleagues, visitors, vendors, and suppliers to follow the below
practices in order to drive progress on Bentley’s ESG strategy. Bentley's Environmental Policy is here: https://prod-bentleycdn.azureedge.net/-/media/files/documents/miscellaneous/environmental_policy.pdf?la=en&modified=20211021075240
Covid-19 recovery

Covid-19 recovery

When the world locked down to combat the COVID-19 virus, we took immediate action to ensure our colleagues had the equipment and resources they needed to work from home, which also enabled success for our users. Our global taskforce provided continuous communication, education, and support services to our colleagues. Their well-being fueled our response plan, and we created learning resources to support them throughout the pandemic. These resources included guides and practices for managers to lead virtually with empathy, tips for maintaining team collaboration, and resources and support for colleagues to maintain a healthy work-life balance.

As the pandemic continues, and work flexibility is seen as the key to success for the business and our colleagues’ wellbeing, we’ve introduced the Infrastructure Empowered Workforce Plan (IEWP). The IEWP is built on a solid foundation of trust. Colleagues are empowered to make responsible and effective choices on the right balance between working from the office and remotely. This plan does not require colleagues to come into the office at any specific frequency. Rather, it provides colleagues the flexibility to make these choices with their manager and within their teams to achieve business success and maintain a high level of productivity and engagement.
Tackling economic inequality

Tackling economic inequality

As a global company with colleagues of different cultures, backgrounds, and perspectives based in more than 40 countries worldwide, our diversity is what makes us successful. We have developed strategies and programs focused on increasing diversity and equity, as well as fostering a culture of inclusion and wellbeing in the workplace. These initiatives include building a pipeline of diverse candidates by recruiting at and partnering with Historically Black Colleges and Universities.
We also partner with educational and professional organisations to provide internships, scholarships, grants, and projects that support groups underrepresented in technology.
Bentley has active and engaged colleague resource groups within the Inclusion, Diversity, and Equity Alliance (IDEA) that have allowed colleagues, during this pandemic, to join their peers from all regions and departments with the goals of building community and fostering diversity and inclusion. IDEA currently has four focus groups open to all global colleagues: OpenPride, OpenAbilities, People of Color in the U.S., and Women at Bentley. IDEA has been a platform for education and a place to securely have difficult discussions about racism, discrimination, and bias through book clubs, panel discussion, speakers, and global awareness events. Members of executive management are key sponsors of each focus group and have been instrumental as sounding boards and in providing access to resources and the executive team.
We have implemented robust training with topics focused on respect in the workplace, identifying and overcoming bias, and anti-discrimination. We have held interactive sessions with our executives, emerging leaders, and talent acquisition in fostering diversity, equity, and inclusion and eliminating unconscious bias, and have implemented training for hiring managers to ensure fairness in the interview process.
You can find additional information, including our commitment to anti-slavery on our ESG website: https://www.bentley.com/en/esg/data-center
Equal opportunity

Equal opportunity

Bentley is an equal opportunity employer and considers all qualified applicants for employment without regard to race, color, sex, sexual orientation, gender identity, disability, protected veteran status, religion, national origin, age, or any other protected characteristic. This commitment extends to all aspects of employment, including, but not limited to, hiring, placement, promotion, compensation, and training. EEO is the Law and EEO is the Law Supplement documents provide additional information about your rights as an applicant under the law.
Wellbeing

Wellbeing

As a company, it is our goal to ensure our colleagues know they are supported and valued as the first order of business.
Therefore, our Talent Management strategy puts colleagues at the center of the workplace at Bentley. We focus on enriching colleague experience and creating memorable, meaningful, and purposeful connections. We invest in developing an impactful experience that reflects the company’s mission and values. We build practices and programs that deliver on engagement, recognition, communication, and development while rewarding colleagues through our robust total rewards package.

Pricing

Price
£18 a user a month
Discount for educational organisations
No
Free trial available
No

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at gcloud@bentley.com. Tell them what format you need. It will help if you say what assistive technology you use.