RTA OrderPro
RTA OrderPro is a hosted managed service for the creation and updating of Digital TRO's, MTO's, Off street Orders and non TRO geodatabase via an easy to use secure portal. RTAA create and keep your geodatabase up to date on your behalf providing robust business continuity to manage Highway networks.
Features
- Managed service for D-TRO, D-MTO, off-street orders & Non TRO's
- Interactive portals for easy data transfer and requests for change
- Bespoke public consultation module. Bespoke public portal for current orders
- Remedial works packages for procuring contractors
- Remote access 24/7 suporting flexible working patterns and home workers
- Cyber essentials certified and off site disaster recovery
- Continual improvement by facilitating onsite reporting of remedial issues
- Fully digitised TRO and MTO review module to TSRGD standards
- 12 month rolling contract. No excessive tie in period
- Human and professional help desk, personal support during office hours
Benefits
- Improves efficiencies and transparency within the client offices
- Seamlessly keeps TRO records digitally up to date
- Links to DfT D-TRO hub and National Parking Platform
- Real time updates for CEOs, Admin and PCN processing teams
- Provides professionally produced plans for consultation and order making
- Reduced resource demand at client base
- Minimal training required. Simple system to understand and use.
- Cost effective solution to help alleviate budget concerns
- Helps to ensure conformity to relevant current national legislation
- Unlimited licenced users and robust business continuity guaranteed
Pricing
£2.50 a unit
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
6 0 3 7 3 2 3 9 4 3 9 0 6 0 0
Contact
RTA Associates Ltd
Peter Lowe
Telephone: 07900264137
Email: plowe@rtaassociates.co.uk
Service scope
- Service constraints
- This is a managed service which does not require firewalls. Client retains responsibility for their entire website function and RTAA do not have any access to client IT systems. RTAA creates and maintains the geodatabase and the client uses as necessary. The service can update the client corporate GIS. Client chooses how the data is made public and in what format. The service simply builds, stores and manages all the background TRO and non TRO data to ensure consistency, transparency, professional outputs and a robust methodology. No constraints on size of data. GDPR issues are held within the clients configurations.
- System requirements
-
- Internet web browser
- Authority to use client OS data licence
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- Initial response within 1 hour if total loss of service. Otherwise initial response within 3 hours.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Tier 0 Self- Service option via online help documentation. Included in the annual price
Tier 1 Basic help desk resolution & service desk delivery provided by RTAA. Included in the annual price
Tier 2 In-depth technical support provided by RTAA. Regarding RTA OrderPro only, Included in the annual price
Tier 3 Expert product and service support provided by RTAA. Regarding RTA OrderPro only, Included in the annual price
Tier 4 Outside support for problems not supported by RTAA. Costs to be agreed upfront with the client if external to RTA OrderPro. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
- Online training combined with documentation and verbal assistance as necessary. It is a simple to use service and can be taught in 20 minutes.
- Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
- Open format using the clients corporate GIS.
- End-of-contract data extraction
- The GIS data is provided at the end of the contract in whatever format the client requests (eg .shp or .tab). The latest accessible pdfs of the mapped tiles for their current legal orders are provided as well.
- End-of-contract process
- At the end of the contract the price includes for a full release of the clients data to the client in the format they choose to suit their corporate GIS system.
Using the service
- Web browser interface
- Yes
- Using the web interface
- The Project Manager instructs RTAA which users should have what level of access to RTA OrderPro. Nominated users are provided with a login and depending upon their level of authorisation, that dictates what changes they can make to the digital records (eg Project manager, Team leader, Traffic engineer, read-only access). Read only access to view TRO interactive map and pdfs for admin and PCN processing teams. Traffic engineers have the same access as read only but can submit proposals for new orders and authorise them for Team leaders to approve. Team leaders have the same access as Traffic engineers as well being able to approve proposals from all Traffic Engineers, edit and delete proposals across the team. Project managers have the same access as Team leaders and can edit / delete proposals across the whole teams. When a Project Manager approves a proposal, that progression means they are ready for public consultation. Project Managers also seal orders which then become part of the digital TRO, MTO, off-street Orders and Non TRO geodatabase and order history.
- Web interface accessibility standard
- WCAG 2.1 AA or EN 301 549
- Web interface accessibility testing
-
Web interface has been tested with PowerMapper and WAVE Evaluation tool.
It is the clients choice whether to instruct RTAA to map restrictions as polygons instead of polylines to improve accessibility standards on the maps. - API
- Yes
- What users can and can't do using the API
-
RTA OrderPro is a partner to transfer up to date digital orders to the DfT's D-TRO hub and National Parking Platform (NPP) to APDS standards.
Users cannot set up the service or make changes through these API's - API automation tools
- Ansible
- API documentation
- Yes
- API documentation formats
- Command line interface
- No
Scaling
- Scaling available
- Yes
- Scaling type
- Automatic
- Independence of resources
-
The virtual machine is hosted by Microsoft Azure. Resource of the system is monitored and automatic scaling is in place if required. We ask any customers who is having a problem to report it to us so we can investigate further.
Volume of work is dealt with by having a flexible workforce who can increase their hours as necessary, to suit their work life balance. The main demand is on setting up new clients which is controllable and negotiable with the Client. Once the service is up and running, updating a client will be covered under normal working practices. - Usage notifications
- Yes
- Usage reporting
Analytics
- Infrastructure or application metrics
- Yes
- Metrics types
-
- CPU
- Disk
- Network
- Other
- Other metrics
- VM availability
- Reporting types
- Reports on request
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Up to Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Data sanitisation type
-
- Explicit overwriting of storage before reallocation
- Deleted data can’t be directly accessed
- Equipment disposal approach
- A third-party destruction service
Backup and recovery
- Backup and recovery
- Yes
- What’s backed up
-
- GIS database
- Files uploaded by the client
- Files available for download to the client
- Pdfs of mapped tile history and manifest of tile history
- User accounts
- Virtual machine hosting RTA OrderPro
- Backup controls
- None. They save their work in RTA OrderPro during and after each session. The backup procedure is automated by the hosting service provider and by RTAA.
- Datacentre setup
- Multiple datacentres with disaster recovery
- Scheduling backups
- Supplier controls the whole backup schedule
- Backup recovery
- Users contact the support team
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- This is a web application and uses standard data protection provided by web server and client communication (https).
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99.9% SLA in place as per Microsoft Azure standard SLA. A service credit will be granted in the highly unlikely event given the resilience the Microsoft Azure system has, should an unplanned outage occur. The maximum service credit is up to 1% equivalent to 1/12th of the annual contract cost, per 24 hours of service disruption.
- Approach to resilience
- Microsoft Azure data centre with guaranteed uptime and availability 99.9%
- Outage reporting
- In the unlikely event of outages we would expect the Third party supplier to contact us as they have a dashboard and an alert system in place. Should RTAA discover the outage first we would contact the third party supplier who manages the service. RTAA would email an update to affected users describing the issue and the amount of time required to resolve the problem.
Identity and authentication
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- Only selected personnel have access to Azure system management including RTAA developers and third party supplier.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- 2-factor authentication
- Username or password
- Devices users manage the service through
- Dedicated device on a segregated network (providers own provision)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- No
- Other security certifications
- No
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
RTA OrderPro - ISO 27001 compliant and awaiting certification. Cyber Essentials Certified.
ITS the third party supplier of the Microsoft Azure service have ISO 07001 accreditation and Cyber Essentials certification - Information security policies and processes
- Our information security policies and processes comply with ISO 27001. We maintain policies covering data protection, access control, and incident response, overseen by a dedicated CISO. Compliance is ensured through regular audits, awareness training, and automated policy enforcement.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
RTA OrderPro - Our configuration and change management processes align with ISO 27001 standards.
A) We track all service components through a centralised Configuration Management Database (CMDB), maintaining detailed records from procurement to decommissioning.
B) Changes undergo rigorous impact assessments, incorporating security reviews to identify and mitigate potential risks before implementation, ensuring the integrity and availability of our services.
ITS - Microsoft Azure data center - Third party raise formal requests. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
RTA OrderPro - Conforms to recognised standard (ISO 27001)
ITS - Azure system is kept up to date by third party. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
RTA OrderPro - Our protective monitoring process adheres to ISO 27001 standards.
A) We identify potential compromises through continuous monitoring using SIEM systems and predefined threat intelligence feeds.
B) On detection, we initiate a defined incident response plan to investigate, contain, and mitigate the threat promptly. C) We respond within predefined SLAs based on incident severity, ensuring rapid and effective incident management.
ITS - Azure system is managed by third party. - Incident management type
- Supplier-defined controls
- Incident management approach
-
RTA OrderPro - Our incident management approach adheres to ISO 27001.
A) We have pre-defined processes for common events like phishing and malware infections.
B) Users report incidents via a dedicated hotline and an online portal, ensuring swift response.
C) We provide incident reports through secure channels, tailored to stakeholders, with a summary of findings, impact, and corrective measures.
ITS - Third party have an incident management process.
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Separation between users
- Virtualisation technology used to keep applications and users sharing the same infrastructure apart
- No
Energy efficiency
- Energy-efficient datacentres
- Yes
- Description of energy efficient datacentres
- The datacentres use Microsoft Azure. Microsoft has achieved adherence to The EU Data Centres Energy Efficiency CoC. It has 16 datacentres across Europe and all conform to the CoC. Microsoft are partners in the European Energy Efficiency Platform. Their new server cooling methods help minimize the environmental impact of physical datacentres—reducing energy use while providing higher processing power and helping to eliminate water consumption.
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Tackling economic inequality
- Equal opportunity
- Wellbeing
Fighting climate change
RTAA staff all work from our home environments, reducing the impact of travel to work on the climate. RTA OrderPro can be accessed by the client from any location supporting clients to work from home, reducing the impact of travel to work on the climate. RTA OrderPro digitises traffic regulation orders in pdf format reducing the need for large volumes of A3 traffic regulation order tiles to be printed.Tackling economic inequality
We provide opportunities for anyone with an IT and/or cartographic background or with a willingness to learn on the job as a trainee, to join the team as we expand to meet demand. Our current workforce includes two European foreign nationals, a first language Welsh speaker and three beyond the state retirement age limit. We are diverse in nature and welcome anyone who matches our requirements to apply to join us.Equal opportunity
We anticipate as a consequence of being part of this framework, demand for our bilingual managed service will increase. At that point in time, we intend to offer places to graduates from any background, culture or ethnicity from local universities to help them develop their careers bringing community benefits and equal opportunities for all as they start their careers, to compliment RTAA's existing diverse and fully inclusive work force. We strongly believe a diverse work force ensures a broader range of ideas and fosters creativity and innovation.Wellbeing
As we are based in Conwy, North Wales we are fully aware of The Well-being of Future Generations Act and its goals for Wales
A prosperous Wales
A resilient Wales
A healthier Wales
A more equal Wales
A Wales of more cohesive communities
A Wales of vibrant culture and thriving Welsh language
A globally responsible Wales
We believe that our service in the community would contribute to meeting most, if not all of the above goals.
Pricing
- Price
- £2.50 a unit
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- We can provide clients with a test environment populated with dummy data to trial the service so they can familiarise themselves with the processes and features of RTA OrderPro to be sure it provides what they would require from the service.