Idox Hosted iManage Cloud Gazetteer Management Service (Address Data Solutions)
iManage Cloud is designed to deliver comprehensive gazetteer management, our GMS streamlines the creation and maintenance of your Local Land and Property Gazetteer (LLPG), Local Street Gazetteer (LSG), and Additional Street Data (ASD) in a BS7666 compliant web browser.
Features
- A fully BS7666 compliant Gazetteer Management Software
- A fully hosted Gazetteer Management Software service
- Address Searching and Lookups on AddressBase Premium and LLPG data
- Ability to create and manage LLPG, LSG and ASD data
- Full property maintenance life cycle
- Manage location intelligence and spatial boundary information against properties
- Integration with 3rd party systems to share address information
- Address data import and exporting facilities
- Brought to you by the UK's largest Gazetteer supplier
Benefits
- A powerful yet simple solution to maintain streets and properties
- Template Property & Street Creation
- Mature, proven software solution used by over 100 local authorities
- A browser based platform for access anytime, anywhere
- Provision of powerful pattern searching tools across LLPG and LSG
- The ability to perform bulk updates on streets and properties
- Fast and easy implementation of LLPG and LSG
- Ability to add and edit additional data to the LLPG
- An established user group
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 0 2 8 3 6 8 8 2 7 0 7 0 2 1
Contact
IDOX SOFTWARE LTD
Jen.roberts@idoxgroup.com
Telephone: 0333 011 1200
Email: bidteam@idoxgroup.com
About your service
- Service categories
-
Application Development and Deployment
Analytics and business intelligence
- Location and geospatial data management and analytics
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
-
The solution is accessed via a remote desktop environment, further restricted via gateway and IP address. Where Multi-Factor Authentication (MFA) is used this needs access to email to login into the system. MFA (Multi Factor Authentication) requirement needs access to email to login.
We will perform planned maintenance regularly. Where possible, maintenance will be performed outside the period of Service Desk availability. We will provide maintenance details and timescales for completion with a minimum of five working days notice.
Unplanned maintenance will be immediately communicated to Customer along with the action to be taken and an impact assessment where required. - System requirements
- N/A
User support
- Email or online ticketing support
- Yes
- Support response times
- The support desk is available Monday to Friday between the hours of 09:00 to 17:30, excluding weekends and Bank Holidays.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- The customer portal is accessible via a standard web-browser (e.g. Microsoft Edge, Chrome, Firefox and Safari 6.1.5 or above), therefore browser accessibility features may be utilised.
- Web chat accessibility testing
- None or don’t know
- Onsite support
- Yes, at extra cost
- Support levels
-
High priority issues like a total system failure will be subject to a target response time of 2 working hours from request being logged (*elapsed time). The target resolution time is 2 working days from request being logged (*elapsed time).
Medium priority issues like an important or critical component that has failed causing a partial failure will be subject to a target response time of 4 working hours from request being logged (*elapsed time). The target resolution time is 5 business days from request being logged (*elapsed time).
Low priority issues like isolated faults that not falling into the categories above will be subject to a target response time of 4 working hours from request being logged (*elapsed time). The target resolution time is 90 business days from request being logged (*elapsed time).
Enquiries will be subject to a target response time of 1 working day from request being logged (*elapsed time) and will be resolved according to best of endeavours depending on the nature of the enquiry.
* Elapsed time is the duration of the request where it is with Idox Service Desk for action, not including periods when the request is with the customer to action or respond. - Support available to third parties
- Yes
- AI chatbot
- No
Onboarding and offboarding
- Getting started
- Idox provide training in the core products and the additional modules this is undertaken via the consultant and delivered online, this covers accessing the service and using the service. Training manuals are provided in electronic PDF format.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Contract termination will be as detailed in the contract. Exactly 30 days after the notice to terminate has been served, we will cease to support the service. It is the Customer's responsibility to ensure that the appropriate new infrastructure to support any of the functions provided by the service is in place.
- End-of-contract process
- If the Customer chooses to move to an alternative supplier and requires an extract of the data, we can provide this information in a standard dtf format. If the data is required in a different format or there is a bespoke requirement with regards to the data extract, then effort to meet such requirements will need to be estimated and the work costed accordingly.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Onboarding and offboarding documentation will be provided directly via email.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
- Our API service is provided as a separate product that provides Gazetteer searching. Our API is fully documented in HTML and PDF.
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- No
- Customisation available
- No
Scaling
- Independence of resources
- The service has separate resources and persistent storage for each customer.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Using the iExhange module, users can export data to third party solutions and the Geoplace hub, this allows for the automated export of data as a Full file or COU file, the data can be transferred securely using SFTP.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- DTF
- Data import formats
-
- CSV
- Other
- Other data import formats
- DTF
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Legacy SSL and TLS (under version 1.2)
- Other
- Other protection between networks
- As standard legacy SSL is used via windows remote desktop. VPN can be provided at additional cost.
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We will make the service 99.9% available during working hours. We will undertake planned maintenance task outside support hours of 09:00 and 17:30, Monday to Friday excluding Bank Holidays. All planned tasks will be communicated with a minimum of even working days’ notice, all unplanned tasks will be communicated via telephone and email in advance, detailing the unplanned tasks to be undertaken.
- Approach to resilience
- Our services are built upon a highly available, reliable, resilient and secure Azure hosted infrastructure. Nightly backups are undertaken and stored for seven days
- Outage reporting
- Email alerts and telephone contact via support desk.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- IManage has defined roles, these restrict individual users only allowing access to functions and data held within the service.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Username or password
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We recognise that information security important in the development and implementation of all systems delivered to our customers, to Idox as a corporate entity, and to our supply chain.
To ensure a consistent and effective approach, we operate an externally audited and certified, organisation wide Information Security Management System (ISMS) which implements and enforces controls on all business functions covering but not limited to information systems, networks, physical environment, incident/threat management, project and contract management and personnel management.
Our systems and controls are also externally verified and certified annually as part of the ISO 27001 certification process. Risks raised through internal and external audits are reviewed at management meetings by the Information Security Manager, the appropriate Head of Business and a board representative. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- All changes to the service are carried out using change requests and are maintained within the change management system. The change management process incorporates a business case / justification for the change, a backout plan, and a final approval with scheduling for the change to be implemented. They will be assessed for security or service impacts during this process, before deployment to a separate QA environment where they are checked for verification before release to production.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- We monitor OWASP and various vendor alert sources for emerging vulnerability intelligence and patching data. A combination of web application scanning, host vulnerability scanning, and external perimeter proactively identifies any design, configuration, or patching weaknesses. When identified, any threats are assessed in context and where warranted, mitigations are implemented in accordance with their severity. These controls and processes are monitored as part of our ongoing ISMS/ISO27001 auditing programme.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Monitoring tools are used to measure server performance metrics as well as storage and network / bandwidth utilisation and unusual server / network / perimeter activity. Alerts from these systems are actively monitored and reviewed and any potential intrusion attempt is raised in line with our security incident reporting procedure for further investigation.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Our incident management process is central to our ISO 27001 Information Security Management System (ISMS). Per our Incident Management Policy and Process, incidents are raised to the Service Desk or detected by monitoring such as SIEM, triaged and escalated. Tickets are allocated a reference number and tracked to conclusion. Results are monitored, documented and preventative action taken to prevent re-occurrence. The incident team maintain contact with relevant internal and external stakeholders within predefined timeframes (24 hours from confirmation for GDPR related incidents).
Security incidents raised to the internal incident register are subject to regular reviews by the senior team. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Citation ISO Certification Limited
- ISO/IEC 27001 accreditation date
- Monday 27 May 2024
- What the ISO/IEC 27001 doesn’t cover
- Our ISMS is certified and tested to ISO27001 standards annually and covers our entire organisation.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Citation ISO Certification Limited
- ISO 9001 accreditation date
- Thursday 11 April 2024
- What the ISO 9001 doesn’t cover
- Our ISMS is certified and tested to ISO9001standards annually and covers our entire organisation.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 5c6de739-c45d-4eee-916a-013a0c2ce8f7
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 26018f8f-da19-4856-8fd2-b719e0c21047
- Other security certifications
- Yes
- Any other security certifications
- ISO 22301
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-