BetterGov

Managed Cloud Services

BetterGov provide Microsoft Cloud Services as an authorised reseller. We offer hosting on the following Microsoft Cloud services: Azure, Office 365, Dynamics and SharePoint. We can deliver planning, design, development, support and managed service.

Features

  • Microsoft Managed Service
  • Experienced Staff

Benefits

  • Pay for What You Use

Pricing

£0.05 a transaction

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at marc@bettergov.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 13

Service ID

6 8 8 9 1 0 1 9 5 7 9 7 0 4 3

Contact

BetterGov Marc Cohen
Telephone: 0203 289 4203
Email: marc@bettergov.co.uk

Service scope

Service constraints
No
System requirements
None

User support

Email or online ticketing support
Email or online ticketing
Support response times
Monday to Friday - 9am - 5.30pm (excluding Public Holidays).

Tiered response, according to the severity of the issue being reported: Severity 1 - 15 minutes, Severity 2 - 30 minutes, all other issues - 60 minutes.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.1 AAA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Support services are agreed with clients on a case by case basis, dependent on requirements.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Onsite training and/or user documentation will be provided to fully support the application.
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
End-of-contract data extraction
https://www.microsoft.com/en-us/trustcenter/privacy
End-of-contract process
https://www.microsoft.com/en-us/trustcenter/privacy/you-own-your-data. In our Online Services Terms, Microsoft contractually commits to specific processes when a customer leaves a cloud service or the subscription expires. This includes deleting customer data from systems under our control. If you terminate a cloud subscription or it expires (except for free trials), Microsoft will store your customer data in a limited-function account for 90 days (the “retention period”) to give you time to extract the data or renew your subscription. During this period, Microsoft provides multiple notices, so you will be amply forewarned of the upcoming deletion of data. After this 90-day retention period, Microsoft will disable the account and delete the customer data, including any cached or backup copies. For in-scope services, that deletion will occur within 90 days after the end of the retention period. (In-scope services are defined in the Data Processing Terms section of our Online Services Terms.) See http://www.microsoftvolumelicensing.com/Downloader.aspx?DocumentId=11745

Using the service

Web browser interface
Yes
Using the web interface
The service is role based. Users can access and perform tasks based on permission levels and access granted.
Web interface accessibility standard
WCAG 2.1 AAA
Web interface accessibility testing
None
API
Yes
What users can and can't do using the API
The Microsoft Cloud Service has several API end point and allows users to setup, make changes, and automate service provision.
API automation tools
  • Chef
  • OpenStack
  • Puppet
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
Command line interface
Yes
Command line interface compatibility
  • Linux or Unix
  • Windows
  • MacOS
  • Other
Using the command line interface
Azure CLI 2.0 is optimized for managing and administering Azure resources from the command line, and for building automation scripts that work against the Azure Resource Manager. See https://docs.microsoft.com/en-us/cli/azure/install-azure-cli

Scaling

Scaling available
Yes
Scaling type
  • Automatic
  • Manual
Independence of resources
Microsoft ensures SLA's are maintained and usage monitored.
Usage notifications
Yes
Usage reporting
  • API
  • Email
  • SMS

Analytics

Infrastructure or application metrics
Yes
Metrics types
  • CPU
  • Disk
  • HTTP request and response status
  • Memory
  • Network
  • Number of active instances
Reporting types
  • Real-time dashboards
  • Reports on request

Resellers

Supplier type
Reseller (no extras)
Organisation whose services are being resold
Microsoft

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Up to Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency
Less than once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v3.0
  • Physical access control, complying with SSAE-16 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Data sanitisation type
  • Explicit overwriting of storage before reallocation
  • Deleted data can’t be directly accessed
  • Hardware containing data is completely destroyed
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001

Backup and recovery

Backup and recovery
Yes
Backup controls
Please see https://docs.microsoft.com/en-gb/azure/backup/backup-azure-vms-first-look
Datacentre setup
  • Multiple datacentres with disaster recovery
  • Multiple datacentres
Scheduling backups
Users schedule backups through a web interface
Backup recovery
  • Users can recover backups themselves, for example through a web interface
  • Users contact the support team

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)

Availability and resilience

Guaranteed availability
http://www.microsoftvolumelicensing.com/Downloader.aspx?DocumentId=11745
Approach to resilience
https://www.microsoft.com/en-us/cloud-platform/global-datacenters and https://www.microsoft.com/en-us/TrustCenter/
Outage reporting
https://azure.microsoft.com/en-us/status/ and https://portal.azure.com/#blade/HubsExtension/ServicesHealthBlade

Identity and authentication

User authentication
  • 2-factor authentication
  • Username or password
Access restrictions in management interfaces and support channels
Username and Password
Access restriction testing frequency
At least once a year
Management access authentication
  • 2-factor authentication
  • Username or password
Devices users manage the service through
  • Dedicated device on a segregated network (providers own provision)
  • Dedicated device on a government network (for example PSN)
  • Dedicated device over multiple services or networks
  • Any device but through a bastion host (a bastion host is a server that provides access to a private network from an external network such as the internet)
  • Directly from any device which may also be used for normal business (for example web browsing or viewing external email)

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber essentials plus
Yes
Other security certifications
No

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
ITIL
Information security policies and processes
https://www.microsoft.com/en-us/TrustCenter/Compliance/ISO-IEC-27001

Operational security

Configuration and change management standard
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Configuration and change management approach
https://www.microsoft.com/en-us/SDL/OperationalSecurityAssurance and https://www.microsoft.com/en-us/sdl
Vulnerability management type
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Vulnerability management approach
CSA CCM v3.0 standards
Protective monitoring type
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Protective monitoring approach
CSA CCM v3.0 standards
Incident management type
Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
Incident management approach
CSA CCM v3.0 standards

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Separation between users

Virtualisation technology used to keep applications and users sharing the same infrastructure apart
Yes
Who implements virtualisation
Supplier
Virtualisation technologies used
Hyper-V
How shared infrastructure is kept separate
https://www.microsoft.com/en-us/TrustCenter/Security/default.aspx

Energy efficiency

Energy-efficient datacentres
Yes
Description of energy efficient datacentres
Microsoft managed

Social Value

Fighting climate change

Fighting climate change

Our Carbon Reduction Plan outlines our current carbon footprint and the way in which we aim to be Net Zero by 2035. We operate a ‘paper free’ office and recycle all IT equipment. New IT purchases are considered with sustainability in mind and only made where necessary. We offset our environment impact through donations to Trees for Life and are in the process of becoming a Silver Partner.
Covid-19 recovery

Covid-19 recovery

We have modified and improved workplace conditions that support the COVID-19 recovery effort including the implementation of effective social distancing, remote working, and sustainable travel solutions.
Tackling economic inequality

Tackling economic inequality

We are a member of the Living Wage UK. Our membership confirms we pay all staff at least the national minimum wage but in addition our membership enables Living Wage UK to promote their agenda to bring more businesses and employers into the scheme.
Equal opportunity

Equal opportunity

We donate to Access UK, a charity that supports BME youth employment and job creation in the community.
Wellbeing

Wellbeing

We provide training opportunities for staff to upskill them in interests related to social care and IT in the workplace but also personal/social interests on a case-by-case basis. These workplace and social training opportunities are part of our package to attract and retain the highest quality staff, improving their working conditions and providing opportunities. We offer and have offered flexible working for many years and operate a bonus structure as well as mentoring by company founders among many other benefits.

Pricing

Price
£0.05 a transaction
Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
To be agreed.

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at marc@bettergov.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.