WordPress Installation and Website Design
WordPress has a 51% marketshare of CMS software. 70% of the web is built on a CMS system. Our service gives you a platform to build your website on. You can engage someone to design your website or ask us. This service entails the integration and configuration of commercial software
Features
- WordPress allows end-uses to quickly create and maintain a website
- Find local people with skills. Bring website content in-house
- WordPress has a Plugin System making wide ranging change possible
- Installed onto our hosting system for a one-stop experience
Benefits
- Lowers the TCO of an Internet presence
- Not tied to a provider. Use G-Cloud supplier to setup
- High levels of online training materials available for free
Pricing
£1,000 a unit a year
Service documents
Request an accessible format
Framework
G-Cloud 13
Service ID
5 7 2 8 9 0 5 1 5 9 9 0 3 0 6
Contact
Answers and Solutions ltd
Christopher Wainwright
Telephone: 02920733722
Email: Christopher.Wainwright@letsdiscuss.co.uk
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Cloud hosting services.
- Cloud deployment model
-
- Private cloud
- Community cloud
- Service constraints
- The software is highly configurable. For all practical purposes, you are unlikely to be constrained by it.
- System requirements
- A web browser is required
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- Usually within a few hours, but our SLA will be 48hrs
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- We shall produce a base system setup. WordPress skills are required. We offer everything from website development thru to onsite training and classroom training. Extensive self-help support is available from the web. Our price includes some "get you going" support - see the service description documentation
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
We can provide an onsite trainer. Online training video's are widely available. Someone with good IT skills but familiar with WordPress can often master the package after 2 or 3 days.
We make sue that the system is fully setup, logon passwords provided and suitable initial designs and themes and plugins are loaded. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- On contract end, once your user has secured new hosting we can migrate the WordPress installation to the new provider.
- End-of-contract process
- On contract end, once your user has secured new hosting we can migrate the WordPress installation to the new provider.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The differences will depend on how you design your deployment.
- Service interface
- Yes
- User support accessibility
- WCAG 2.1 A
- Description of service interface
- The Webbrowser based interface with enhanced access rights allows relatively low skilled staff to maintain a site. Someone with a higher skill set will be needed to set it up initially.
- Accessibility standards
- WCAG 2.1 AAA
- Accessibility testing
- There are so many plugins and mods available for WordPress that it is not possible to comment.
- API
- Yes
- What users can and can't do using the API
-
API's are used by software developers which takes one into the realm of software development beyond the scope of G-Cloud.
This service uses API's for the plugin's used. Please contact us to discuss your requirements - API documentation
- No
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Almost everything can be customised. Please call for details.
Scaling
- Independence of resources
-
The software will be hosted on servers that we own and operate. These can scale out significantly, and additional servers will be added when the need arises.
Our company policy is to over-provision, not under provision.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 3.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v3.0
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Data sanitisation type
-
- Explicit overwriting of storage before reallocation
- Deleted data can’t be directly accessed
- Equipment disposal approach
- In-house destruction process
Data importing and exporting
- Data export approach
- Data can be exported using one of the many WordPress migration tools available.
- Data export formats
- Other
- Other data export formats
- WordPress can be migrated to another server
- Data import formats
- Other
- Other data import formats
- Copy and paste is a frequenly used method
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We aim for 99.9% availability. In the event of an unplanned outage of one or more hours being notified we will provide a week of free operation.
Pre-notified outages do not qualify for refunds since we will liaise with the customer and choose a time mutually acceptable. Planned works are rare, and will be scheduled for out of hours. - Approach to resilience
- This is available on request
- Outage reporting
- A public dashboard
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- N/A in this document. Management interfaces are provided in our cloud hosting document
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Username or password
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Between 6 months and 12 months
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- WorldPay
- PCI DSS accreditation date
- 31/10/2019
- What the PCI DSS doesn’t cover
- We do not store CC details on our servers; CC details are processed by our bank on their PCI DSS certified servers. Our PCI certification was issued with this processing method declared. Most payment processing applications handover to an external CC payment provider, who accepts payment before handing purchase approval back to the application that you would be running on our system. This means that our PCI DSS certification is suitable for eCommerce solutions used by most organisations . If you want to store people CC details on our servers, that can be arranged and our PCI DSS would be amended to suit. Your software solution would need to be PCI DSS compliant. Using a 3rd party processor such as Worldpay [or one of their numerous competitors] is by far the best way to handle PCIO DSS aspects of Credit Card processing.
- Cyber essentials
- Yes
- Cyber essentials plus
- No
- Other security certifications
- No
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Word Press security is passed across to the buyer once the system is installed via the Admin login details
- Information security policies and processes
- Information security is maintained in house and managed via our Information security policies
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We use the ITiL Configuration and Change management appraoch
- Vulnerability management type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Vulnerability management approach
- WordPress systems are scanned for vulnerabilities using entry level Pen Testing tools. WordPress has an an automatic patching features which we ensure was active prior to handover. We are subscribed various services that check the integrity of our hosting platform. We run regular Anti-Virus scans.
- Protective monitoring type
- Undisclosed
- Protective monitoring approach
-
We are subscribed various services that check the integrity of our hosting platform. We run regular Anti-Virus scans. The risks not covered include those from people with valid username/passwords who deface a website / damage data etc. Scanning services that address this risk are available at extra cost.
Our aim is to avoid being compromised. Our response is determined by the type of compromise detected. - Incident management type
- Undisclosed
- Incident management approach
- Users can report incidents via a ticketing system. Reported incidents will be logged and an incident report provided at month end. Reports will not be generated in those months when no incidents occurred unless requested by the buyer
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Social Value
- Fighting climate change
-
Fighting climate change
Climate change is minimised by reducing CO2 emissions. We use an energy provider that has minimized its reliance on fossil fuel power generation and sources as much nuclear energy as possible. Renewable energy is included in the mix (hydro, solar and wind). Any shortfall is topped up by a small top up from fossil fuels. We also minimise power consumption by using shared infrastructures for some clients, and where a client requires a non-shared infrastructure, we minimise energy consumption using virtualisation techniques.
All hardware purchases are required to meet current energy efficiency targets. - Covid-19 recovery
-
Covid-19 recovery
As part of our commitment to CO2 reduction and our commitment to Covid-19 recovery, we allow home working and use virtual meeting technologies as much as possible. - Tackling economic inequality
-
Tackling economic inequality
We place as much business as possible in areas that are short of opportunities. The economic advantages are obvious, but additional business advantages include those that accrue from having a stable workforce. - Equal opportunity
-
Equal opportunity
We provide equal opportunity and recruitment is based solely on ability. Individuals are free to hold any personal view they wish and no discrimination is permitted on those grounds. - Wellbeing
-
Wellbeing
All staff are encouraged to have a healthy work-life balance. Staff are encouraged to exercise regularly and hold diverse interests. We offer a salary sacrifice scheme for all physically active recreational activities that meet this requirement, and undertake occasional team-building events in pursuit of the wellbeing criteria.
Pricing
- Price
- £1,000 a unit a year
- Discount for educational organisations
- No
- Free trial available
- No