IOCO SOLUTIONS LIMITED
Amazon Web Services (AWS) Hosting
Full stack of Hosting Services leveraging the AWS Platform.
iOCO can design, implement, manage and maintain your cloud solutions on AWS across all the AWS Services.
Features
- Amazon EC2
- Amazon RDS
- Amazon VPC
- Amazon CloudFront
- Amazon Workspaces
- AWS Glue
- Amazon Athena
- Amazon QuickSight
- Amazon Sagemaker
Benefits
- Compute services to run and scale your applications.
- RDS operate and scale a relational databases in the cloud.
- Amazon VPC lets you provision a logically isolated virtual networks.
- Amazon CloudFront is a fast content delivery network.
- Amazon WorkSpaces is a managed Desktop-as-a-Service solution.
- AWS Glue is a fully managed ETL service.
- Athena is an query service to analyze data in S3.
- Amazon QuickSight is a cloud-powered business intelligence service.
- SageMaker is machine learning service for every data scientist.
Pricing
£0.99 a unit an hour
- Education pricing available
- Free trial available
Service documents
Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format,
email the supplier at michael.morey@ioco.tech.
Tell them what format you need. It will help if you say what assistive technology you use.
Framework
G-Cloud 14
Service ID
7 0 4 2 2 4 1 3 5 0 2 2 2 6 3
Contact
IOCO SOLUTIONS LIMITED
Mick Morey
Telephone: 0118 206 2938
Email: michael.morey@ioco.tech
Service scope
- Service constraints
- You may access and use the Service Offerings in accordance with the AWS Customer Agreement.
- System requirements
-
- AWS Customer Agreement
- https://aws.amazon.com/agreement/
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- Our response times are driven by our Standard Service Level Agreement.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.1 AA or EN 301 549
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
General guidance: < 24 hours
System impaired: < 12 hours
Production system impaired: < 4 hours
Production system down: < 1 hour - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- IOCO will assist their customers to create their AWS Accounts. Account setup and onboarding of users and services will be done in line with the AWS Well Architected Framework. AWS Well-Architected provides a consistent approach for customers and partners to evaluate architectures, and implement designs that can scale over time.
- Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
- Microsoft Word Documents
- End-of-contract data extraction
- Users retain ownership of their AWS Account if they wish to cancel their contract with iOCO. They are in full control of their data and can extract or remove their data from the service at any time.
- End-of-contract process
- AWS Service are billed for on a monthly basis and the services that iOCO provide additional to the AWS Platform is billed on a monthly basis. These services are billed in arrears for services consumed. There are no additional costs at the end of the contract term or notice period.
Using the service
- Web browser interface
- Yes
- Using the web interface
-
The AWS Management Console gives you secure login using your AWS or IAM account credentials. For added security, your login session automatically expires after 12 hours.
The Management Console provides a number of organized and human-friendly ways to review, monitor, and interact with resources that you have created using developer tools, like the AWS Command Line Interface (CLI) and AWS CloudFormation templates. The console can also help you visually discover and get hands-on quickly with the functionality of a service, even if you plan to build and deploy your applications and infrastructure programmatically. - Web interface accessibility standard
- None or don’t know
- How the web interface is accessible
- The Console supports the three latest versions of Google Chrome, Mozilla Firefox, Microsoft Edge, and Apple Safari as well as Microsoft Internet Explorer 11.
- Web interface accessibility testing
- We have not done any testing with assistive technology users.
- API
- Yes
- What users can and can't do using the API
- Software Development Kits (SDK's) are available to remove the complexity out of coding by providing language-specific APIs for AWS services.
- API automation tools
-
- Ansible
- Chef
- OpenStack
- SaltStack
- Terraform
- Puppet
- API documentation
- Yes
- API documentation formats
-
- HTML
- Other
- Command line interface
- Yes
- Command line interface compatibility
-
- Linux or Unix
- Windows
- MacOS
- Using the command line interface
- The AWS Command Line Interface (AWS CLI) is an open source tool that enables you to interact with AWS services using commands in your command-line shell. With minimal configuration, the AWS CLI enables you to start running commands that implement functionality equivalent to that provided by the browser-based AWS Management Console from the command prompt in your favorite terminal program.
Scaling
- Scaling available
- Yes
- Scaling type
-
- Automatic
- Manual
- Independence of resources
- Capacity planning is managed by AWS. Capacity reservations can be made by the customer if required to ensure that scaling capacity is available when required.
- Usage notifications
- Yes
- Usage reporting
-
- API
- SMS
Analytics
- Infrastructure or application metrics
- Yes
- Metrics types
-
- CPU
- Disk
- HTTP request and response status
- Memory
- Network
- Number of active instances
- Reporting types
-
- API access
- Real-time dashboards
- Reports on request
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Amazon Web Services
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 3.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v3.0
- Physical access control, complying with SSAE-16 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Data sanitisation type
-
- Explicit overwriting of storage before reallocation
- Deleted data can’t be directly accessed
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001
Backup and recovery
- Backup and recovery
- Yes
- What’s backed up
-
- Amazon EFS file systems
- DynamoDB tables
- Amazon EC2 instances
- Amazon EBS volumes
- Amazon RDS databases
- Aurora clusters
- AWS Storage Gateway volumes
- Backup controls
- AWS Backup is a fully managed backup service that makes it easy to centralize and automate the backup of data across AWS services in the cloud and on premises. Using AWS Backup, you can configure backup policies and monitor backup activity for your AWS resources in one place. AWS Backup automates and consolidates backup tasks that were previously performed service-by-service, and removes the need to create custom scripts and manual processes.
- Datacentre setup
- Multiple datacentres
- Scheduling backups
- Users schedule backups through a web interface
- Backup recovery
- Users can recover backups themselves, for example through a web interface
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
SLA's are defined by the various services that AWS offer.
Each service has a defined SLA that is based on the implementation and architecture as described by the Well Architected Framework and the relevant SLA document.
https://aws.amazon.com/legal/service-level-agreements/ - Approach to resilience
- AWS infrastructure is designed to be resilient. The resiliency pillar of the AWS Well Architected Framework prescribes the Architetual principals to guide the implementation of resilient architectures.
- Outage reporting
-
The AWS Personal dashboard publishes up-to-the-minute information on service availability.
A public dashboard is available at https://status.aws.amazon.com/
Email alerts and notifications via API is also possible.
Identity and authentication
- User authentication
-
- 2-factor authentication
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- All accounts are configured with the principle of least privilege. The idea is simple: give every user/process/system the minimal amount of access required to perform its tasks.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- 2-factor authentication
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Devices users manage the service through
-
- Dedicated device on a segregated network (providers own provision)
- Dedicated device on a government network (for example PSN)
- Dedicated device over multiple services or networks
- Any device but through a bastion host (a bastion host is a server that provides access to a private network from an external network such as the internet)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- EY CertifyPoint
- ISO/IEC 27001 accreditation date
- 25/10/2019
- What the ISO/IEC 27001 doesn’t cover
- https://aws.amazon.com/compliance/iso-27001-faqs/
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- No
- Other security certifications
- No
Security governance
- Named board-level person responsible for service security
- No
- Security governance certified
- Yes
- Security governance standards
-
- CSA CCM version 3.0
- ISO/IEC 27001
- Information security policies and processes
- IOCO follow the ISO 27001 standard, and AWS follow both ISO 27001 and the Cloud Security Alliance standard.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- IOCO follow the ITIL version 4 Framework.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Amazon Inspector security assessments help you check for unintended network accessibility of your Amazon EC2 instances and for vulnerabilities on those EC2 instances. Amazon Inspector assessments are offered to you as pre-defined rules packages mapped to common security best practices and vulnerability definitions.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
CloudWatch collects monitoring and operational data in the form of logs, metrics, and events, providing you with a unified view of AWS resources, applications, and services that run on AWS and on-premises servers. You can use CloudWatch to detect anomalous behavior in your environments, set alarms, visualize logs and metrics side by side, take automated actions, troubleshoot issues, and discover insights to keep your applications
running smoothly. - Incident management type
- Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
- Incident management approach
-
IOCO leverage services like Amazon GuardDuty alerts or AWS Config to monitor for incidents in real time.
Alerts are configured based on real time events and reports are generated from the real time events that is reported.
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)
Separation between users
- Virtualisation technology used to keep applications and users sharing the same infrastructure apart
- No
Energy efficiency
- Energy-efficient datacentres
- Yes
- Description of energy efficient datacentres
- AWS Datacentres adhere to the EU code of conduct for energy-efficient datacentres. for more information please visit https://aws.amazon.com/about-aws/sustainability/
Social Value
- Social Value
-
Social Value
Fighting climate changeFighting climate change
Innovation is key to achieving sustainability goals—challenges such as decarbonization of operations to water conservation are addressed through technologies that drive sustainable transformation. AWS enables customers to build sustainability solutions ranging from carbon tracking to energy conservation to waste reduction, using AWS services to ingest, analyze, and manage sustainability data.
Pricing
- Price
- £0.99 a unit an hour
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- AWS does offer a Free Tier for a period on 12 months for limited services. More details can be found at https://aws.amazon.com/free
Service documents
Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format,
email the supplier at michael.morey@ioco.tech.
Tell them what format you need. It will help if you say what assistive technology you use.