erwin ER360
erwin ER360 Collaborative Portal, is a self service business user portal for read-only access to
erwin data models. ER360 promotes collaboration
and empowerment of data users, enhances data
literacy and understanding, and accelerates data driven decision making by reducing bottlenecks in
the data modeling process
Features
- Business and technical user interfaces
- High-fidelity diagram visualization
- Metadata reporting and export to CSV
- Advanced metadata search and browse capabilities
- Collaboration services
- erwin Data Modeler integration
- Web-based user and role management
- NoSQL visualization
- Enhanced grouping and security
- SDI visualizations
Benefits
- Improved collaboration
- Enhanced data understanding
- Increased data governance
- Empowered business users
- Accelerated decision making
Pricing
£5,675 a unit
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
6 0 4 5 1 4 4 7 8 9 5 3 4 4 5
Contact
Sandhill Consultants Ltd
Andrew Carter
Telephone: 01476 568708
Email: andrew.carter@sandhill.co.uk
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- Erwin Data Modeler
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- Is only compatible with windows
- System requirements
- Windows
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- https://support.quest.com/essentials/sr-severity-levels-response-times
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.1 AA or EN 301 549
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Web chat
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.1 AA or EN 301 549
- Web chat accessibility testing
- Quest Software has indeed been involved in evaluating user satisfaction with assistive technology. One such assessment tool they’ve used is the Quebec User Evaluation of Satisfaction with Assistive Technology (QUEST). This instrument gauges a patient’s contentment with various assistive devices, considering factors like dimensions, weight, adjustments, safety, durability, simplicity of use, comfort, and effectiveness. Additionally, it assesses service-related aspects such as delivery, repairs, professionalism, and follow-up service
- Onsite support
- Yes, at extra cost
- Support levels
- https://support.quest.com/essentials/sr-severity-levels-response-times
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Full education and training quick start programs
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- CSV export and database backup
- End-of-contract process
- Service ends at end of license subscription period. Data can be made available for 30 days after end of contract. No additional costs at end of contract.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
- Windows
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.1 AA or EN 301 549
- Description of service interface
- Windows thick client UI and Browser based, easy to use
- Accessibility standards
- WCAG 2.1 AA or EN 301 549
- Accessibility testing
- Quest Software has indeed been involved in evaluating user satisfaction with assistive technology. One such assessment tool they’ve used is the Quebec User Evaluation of Satisfaction with Assistive Technology (QUEST). This instrument gauges a patient’s contentment with various assistive devices, considering factors like dimensions, weight, adjustments, safety, durability, simplicity of use, comfort, and effectiveness. Additionally, it assesses service-related aspects such as delivery, repairs, professionalism, and follow-up service
- API
- Yes
- What users can and can't do using the API
- Import files. Create, read, update, delete objects and relationships
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- Representation of the metadata can be customized on the diagram with out of the box information.
Scaling
- Independence of resources
- Fully monitored service through Amazon Cloudwatch
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Quest Software
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- Up to Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 3.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v3.0
- Physical access control, complying with SSAE-16 / ISAE 3402
- Data sanitisation process
- No
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
- CSV export and database backup
- Data export formats
-
- CSV
- Other
- Other data export formats
- Database backup
- Data import formats
- Other
- Other data import formats
- N/A The files are imported from erwin Data Modeler only.
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Erwin shall make the Service available twenty-four (24) hours per day, seven (7) days a week with a minimum uptime level of ninety-nine and nine tenths of a percent (99.9%) measured on an aggregate monthly basis, with no single unscheduled outage exceeding four (4) consecutive hours in a single seven (7) day period. Should Erwin incur an unscheduled outage in excess of four (4) hours or more than two (2) unscheduled outages in excess of two (2) hours or more in duration within a single billing month, upon notice by Customer and confirmation by Erwin, Customer will be credited 10% of that month’s monthly recurring payment. Such service availability does not, however, include regularly scheduled maintenance or any unscheduled downtime due to failures beyond Erwin’s control (such as errors or malfunctions due to Customer’s computer systems, local networks or Internet connectivity).
- Approach to resilience
- Daily back-up of application and database server. RTO (Recovery Time Objective) of 24 hours. AWS Multi-AZ to ensure database is synchronised.
- Outage reporting
- Email alerts. Public dashboard in roadmap.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- There is an option within the account section of the tool, where the client administrator can allow erwin support access, to log into a client’s area and test the issue they are seeing, or test fixes once applied. This access is completely controlled by the customer and is turned off by default. For server maintenance, a Jump server is used to access any AWS remote production environments, including connecting through a provisioning server, requiring private key access. The Jump server is locked to the corporate network ip address and the provisioning server(s) can only be accessed using the Jump server.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Between 1 month and 6 months
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Schellman Compliance, LLC
- ISO/IEC 27001 accreditation date
- 15/08/2023
- What the ISO/IEC 27001 doesn’t cover
- Scope of certification is the provision of SaaS and Hosting Services
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber essentials plus
- No
- Other security certifications
- No
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- https://www.quest.com/docs/information-security-policy-legal-131273.pdf
Operational security
- Configuration and change management standard
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Configuration and change management approach
- All changes are raised via the support ticketing system, Zendesk, and will be added into the development tracking system. Code changes are implemented with build script - we do use automated deployment tools for code movement and roll-backs from our beta, staging and live environments. Changes are approved by Development and Product Manager before being pushed.
- Vulnerability management type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Vulnerability management approach
- Vulnerability scanning tool generates reports, tested against a known database of issues. Rule sets use common vulnerabilities and exposures (CVE), center for internet security (CIS) Operating System configuration benchmarks, and security best practices. High and Medium issues resolved as quickly as possible. Low and Informational issues worked into the normal sprint plans. Security pack covers whole platform of solutions: - Intrusion Detection/Prevention and hosting of agents and manager within remote environment - Security Information and Event Monitoring (SIEM – Manage Engine EventLog Analyzer) - and the hosting of the agents and manager within the remote environment - Quarterly vulnerability testing.
- Protective monitoring type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Protective monitoring approach
- If the advanced security pack is chosen (on single tenant environments), we utilise an IDS/IPS tooling and all events are sent to a central management console, managed by DevOps team. The IPS software will remediate and block issues where they are found. Any alerts will quickly be responded to and remediated by the DevOps team, depending on criticality.
- Incident management type
- Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
- Incident management approach
- Incident record is created in the Quality Log Incident Manager assigned to co-ordinate resolution and communications . Incident manager will work with the account manager to keep the customer informed. Issues will be escalated to Product Management and Development Management. Escalation beyond this is to the senior management team Customer is notified of the issue/incident and the plans to resolve it by the account manager. Development Manager will review the issue, any knock-on effects and devise the best fix method Change management process follows attempts at resolving the issue. Incident Report completed afterwards detailing the cause, lessons learned.
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Tackling economic inequality
Fighting climate change
As a company Sandhill identify and implement activities to reduce emissions in the performance of contracts, such as improving energy efficiency, switching to renewable energy sources, reducing waste, water consumption, promoting low-carbon transport, and offsetting unavoidable emissions.
We'll seek external verification and certification of our carbon reporting, where possible.
Sandhill have committed to the following as part of their efforts toward fighting climate change.
Environmental Awareness - POLICY STATEMENT
It is the policy of Sandhill Consultants Limited (Sandhill) to minimise the potentially significant impacts of our operations and services on the environment. We will promote sustainability and environmental awareness at all levels of decision making.
In defining our program of improved environmental performance and pollution reduction, Sandhill will:
• Comply with the letter and spirit of all relevant environmental legislation.
• Adopt a purchasing program that takes into account the environmental impact of products and services in areas of key concern.
• Implement waste management strategies that promote waste minimisation, re-use, recovery and recycling where appropriate. Where these options are not available we will ensure that our waste is disposed of in a way that minimises its impact on the environment.
• Promote efficient energy use in all areas of business activity.
• Seek to manage and reduce internal and client-facing travel.
• Ensure that our staff are aware of the environmental impacts of their work activities and encourage them through awareness raising and training to minimise those impacts.
• Pursue a program of continuous improvement of our policies and practice.
• Ensure that our policy is available for public review on request.
This policy will be reviewed on a regular basis to evaluate continued relevance and to monitor compliance and in turn look to conform with ISO 14001.
The Sandhill Policy Statement is signed off by Simon Carter, CEO.Tackling economic inequality
Fostering wider diffusion of new technologies and building complementary capabilities in the workforce can deliver both stronger and more inclusive economic growth. Technology offers opportunities for people to acquire new skills, engage in varied livelihoods, and participate in shaping cultural norms and democracy. Ensuring marginalized communities have the necessary skills, access, and tools is essential for inclusive growth. The Introduction of new software will offer potential opportunities for training and retraining and with the use of erwin ER360 should result in more efficient use of IT and open out the results of data modelling and metadata to a broader audience.
Pricing
- Price
- £5,675 a unit
- Discount for educational organisations
- No
- Free trial available
- No