Fordway Cloud Security Baseline
Fordway Cloud Baseline is the initial stage to ensuring comprehensive IT security and risk monitoring, event correlation, analysis and management service across multi-vendor, disaggregated cloud, in house and hosted IT services. Security Baseline is aligned to CESG guidelines and complies with ISO27001, Cyber Essentials, PSN/N3 and PCIDSS.
Features
- Security (Risk) management including Business Impact Analysis (BIA)
- Security Monitoring Analysis and Recommendations, Gap analysis and penetration tests
- Host and network based intrusion detection (IDS/IDPS)
- Public Cloud security monitoring, event correlation and analysis
- IT Health checks and Technical Risk Assessment
- Required for Security Incident Management, orchestration and reporting
- Required for proactive and reactive security event monitoring
- Security event consolidation, filtering, forwarding and alerting for cloud models
- IT Service/Business Continuity and Disaster Recovery (DR) policies, procedures
- Forensic isolation, trend analysis and reporting
Benefits
- Define your organisations Security Service Level Requirements
- Detection of high impact threats and vulnerabilities
- Allows consolidation of security across multiple cloud platforms and suppliers
- Ensures remediation of threats and vulnerabilities in an effective manner
- Compliance to standards (i.e. ISO27001:2013) and demonstration of governance
- Managing events aligned to security and service management best practice
- Using current in-depth security intelligence to alerting on real threats
- Provides security assurance for cloud services across multiple suppliers
- Provides compliance for organisational cyber security risk management
- Align and scale security monitoring operations to elasticity of cloud
Pricing
£350.00 to £975.00 a unit a day
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
2 7 5 0 5 9 4 1 3 8 9 5 8 4 3
Contact
FORDWAY SOLUTIONS LIMITED
Richard Blanford
Telephone: 01483 528200
Email: tenders@fordway.com
Planning
- Planning service
- Yes
- How the planning service works
- Fordway have standard engagement documentation and migration templates which will be utilised within their project planning.
- Planning service works with specific services
- Yes
- Hosting or software services the planning service works with
-
- Microsoft Azure
- Microsoft 365
- Amazon Web Services
- Fordway IT as a Service
- Fordway Connectivity and Access Service
- Google Cloud Platform
- Most other public/private cloud providers
- Fordway Security Management
Training
- Training service provided
- Yes
- How the training service works
- The training service is tailored to the buyer and dependent on the service provided
- Training is tied to specific services
- Yes
- Services the training service works with
-
- Amazon Web Services
- Microsoft Azure
- Microsoft 365
- Google Cloud Platform
- Fordway Identity and Authentication Service
- Fordway Data Storage Service
- Fordway Cloud Monitoring as a Service
- Fordway Security Monitoring as a Servcie
- Fordway Security Management as a Service
Setup and migration
- Setup or migration service available
- Yes
- How the setup or migration service works
- Fordway have standard documents and templates to support customers on their security monitoring requirements in the cloud with independent advice and recommendations.
- Setup or migration service is for specific cloud services
- Yes
- List of supported services
-
- Microsoft Azure
- Microsoft 365, Office 365, Dynamics 365
- Amazon Web Services
- Fordway IT as a Service
- Fordway Cloud Connectivity and Access
- Fordway Application and Service Availability Monitoring
- IaaS/PaaS/DaaS from most cloud proividers
- Google Cloud Platform
- Private Cloud services
- Fordway Security Management
Quality assurance and performance testing
- Quality assurance and performance testing service
- Yes
- How the quality assurance and performance testing works
- Fordway have standard quality assurance and performance testing documentation and templates which will be tailored in line with the service design.
Security testing
- Security services
- Yes
- Security services type
-
- Security strategy
- Security risk management
- Security design
- Cyber security consultancy
- Security testing
- Security incident management
- Security audit services
- Other
- Other security services
-
- 24 x 7 Security Monitoring and Event Analysis
- PSNA approved security hosting and design
- List N (Nuclear) Certified organisation and facilities
- Security incident response, containment and remediation
- Virtual CISO Service
- Microsoft 365 Security and Compliance
- Microsoft Azure Security and Compliance
- AWS Security Centre management
- Certified security testers
- Yes
- Security testing certifications
-
- CHECK
- CREST
- Tigerscheme
- Cyber Scheme
Ongoing support
- Ongoing support service
- Yes
- Types of service supported
-
- Buyer hosting or software
- Hosting or software provided by your organisation
- Hosting or software provided by a third-party organisation
- How the support service works
-
Fordway have a wide rage of hosting, software and support services which include:
Fordway IaaS,
Fordway PaaS,
Fordway DaaS,
Fordway Cloud Intermediation Services,
Fordway Identity and Authentication Management,
Fordway Data Storage Service,
Fordway Cloud Monitoring as a Service,
Fordway Cloud Security Management as a Service,
Fordway Security Monitoring as a Service,
Fordway Disaster Recovery as a Service,
Fordway Backup and Restore as a Service,
Fordway Endpoint Protection as a Service,
Fordway Service Management Service,
Fordway Server Hosting Service,
Fordway Patch Management as a Service
Service scope
- Service constraints
- None
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
-
Priority 1 incident 24 x 7, 15 minute response.
Priority 2 incident 24 x 7, 1 hour response Priority 3 incident 12 x 5, 4 hour response. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Support levels
-
Defined according to SLA required.
P1 - major service impact
P2 - significant service impact
P3 - individual users impacted
P4 - no user impact/information
Technical Account management available, service cost dependent on scope of requirements
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Security Clearance (SC)
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- ISOQAR
- ISO/IEC 27001 accreditation date
- 14/03/2022 (recertification) original certification March 2008
- What the ISO/IEC 27001 doesn’t cover
- ISO27001/27017/27018 Scope of Certification available on request
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- Yes
- Other security certifications
- Yes
- Any other security certifications
-
- List N (Nuclear Industry)
- PSN Code of Connection and Compliance
- PAS555
- NHS IGSoC
- ISO27017
- ISO27018
- GCloud Assured
Social Value
- Social Value
-
Social Value
Fighting climate changeFighting climate change
Using Cloud offers considerable efficiency and consumption savings compared to running in house, on premises and hosted environments
Pricing
- Price
- £350.00 to £975.00 a unit a day
- Discount for educational organisations
- No