Skip to main content

Help us improve the Digital Marketplace - send your feedback

GENERAL DYNAMICS UNITED KINGDOM LIMITED

Defence Information Management Portal (DIMP)

This service provides a secure management information portal that is accessible to all MOD staff with a DII or RLI network connection. The portal provides a single point for delivering management and programme information. The core portal can be enhanced with a number of additional service options.

Features

  • Document publication facility
  • IL3 secure document transmittal up to and including OS
  • Performance dashboard that provides customisable metrics and views
  • A full ITIL conformant service desk
  • Report creation
  • A range of self-service applications
  • Additional IL3 secure storage space in 100GB blocks

Benefits

  • Secure document publication and delivery
  • Enhanced security through CESG accreditation and regular ITSHC
  • MOD accessibility provided through DII / RLI hosting
  • Enhanced availability & reliability for MOD Customers
  • Provision of a collaborative working environment
  • Single source of data leading to reduced cost of ownership
  • Multiple applications sharing ‘live data’ to all stakeholders

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at lloyd.davies@gd-ms.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 0 9 3 0 0 4 5 4 0 1 5 1 5 1

Contact

GENERAL DYNAMICS UNITED KINGDOM LIMITED Lloyd Davies
Telephone: +44 (0) 771750 8689
Email: lloyd.davies@gd-ms.uk

About the service

Service categories

Applications

Content workflow and management

  • Document

Content services

  • Content Sharing and Collaboration Applications

Enterprise portals and digital workspaces

  • Multi-Audience Portals
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
Although each management information Portal is fully customisable and built to meet customer requirements they are based on core infrastructure components that are shared between all user communities. The DIMP infrastructure and feature set has its own agreed maintenance and release schedules.
GDUK will publish a roadmap setting out a schedule for future baseline updates and will ensure all customers are informed. All changes that impact customer services or business processes will be approved by a Change Advisory Board (CAB) that will include representatives from customers and sponsoring agencies.
System requirements
  • Access to a DII/RLI Service Delivery Point (SDP)
  • MOD DII/RLI approved workstation, PC or laptop

User support

Email or online ticketing support
Yes
Support response times
All requests will receive a response within 30 minutes
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
GDUK provides a full support service and has a dedicated Service Management team for each DIMP. All support team members have SC level security clearance with DV staff and crypto custodians also available on site. The team covers the full range of ITIL service management processes and project leads are ITIL V3 expert qualified. All DIMP customers receive the same levels of service.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
GDUK will provide full on-boarding as part of the DIMP core service. On-boarding of customers will involve a customer liaison engineer developing a plan that is designed to reduce the risks and complexity of moving to a cloud based service. Initial user training and familiarization will be provided.
Service documentation
No
End-of-contract data extraction
Service Off-boarding is initiated by the customer through a request to the Service Desk. The process will usually occur after expiration of the service agreement. If the customer requires that their data is returned then a data extraction service will be required. This service can be requested at any time during service provision.
GDUK will make the required data available using media provided by the customer and in line with the data security classification. Where a database or table is part of the service, a separate data extraction service will be required due to the potential complexity and volumes of data involved.
End-of-contract process
Custom portals require a minimum of twelve months’ commitment and a minimum of three months’ notice.
There are no additional fees for extracting and handing over basic customer data that includes such items as documents and individual files from within a storage area.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
The customer can assign administrator rights to selected users that allow access to additional functionality and management features
Accessibility standards
None or don’t know
Description of accessibility
GDUK will provide a secure Defence Information Management Portal that is accessible to all MOD staff with a DII, MODNET or RLI network connection using a standard web interface.
Accessibility testing
Service look and feel is built to comply with MOD requirements using agreed formats, layout and colour schemes. MOD conformance testing carried out at Service handover.
API
No
Customisation available
No

Scaling

Independence of resources
Our service is aimed at specific MOD users where the capacity of our system exceeds the number of authorised users.

Analytics

Service usage metrics
Yes
Metrics types
Each management Information Portal is provided with a performance dashboard area that details basic contractual performance data including number of support calls, requests and Portal usage statistics along with response and resolution times.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Supplier type

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
Less than once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Physical access control, complying with another standard
Data sanitisation process
No
Equipment disposal approach
A third-party destruction service

Data importing and exporting

Data export approach
A data export is requested by the customer through the service desk.
Data export formats
CSV
Data import formats
  • CSV
  • Other
Other data import formats
PDF

Data-in-transit protection

Data protection between buyer and supplier networks
Private network or public sector network
Data protection within supplier network
Other
Other protection within supplier network
Our service and systems run within the MOD DII (Defence Information Infrastructure)

Availability and resilience

Guaranteed availability
The target percentage availability for all users of this service will be 98%. All measurements are taken over a rolling 4-week period and exclude downtimes due to Planned Maintenance and non-availability of supporting MOD based remote Services e.g. RLI Services, Network availability, DNS, SMI etc. The financial recompense model is based around a service credits. The model is agreed with the customer for each service deliverable and will typically consist of a service credit of up to 100% of the period’s service payment depending on the duration, cause and impact of the breached SLA.
Approach to resilience
Details of our approach to system resilience is available on request.
Outage reporting
There is a service notification and availability portal available to users.

Identity and authentication

User authentication needed
Yes
User authentication
  • Limited access network (for example PSN)
  • Username or password
Access restrictions in management interfaces and support channels
Management and support channels are not published on the client side
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Limited access network (for example PSN)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
No
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Defence Security and Assurance Services (DSAS) – Accreditation to IL3
Information security policies and processes
The DIMP is hosted on DII and is cleared and accredited to hold information up to and including “Official-Sensitive” (IL3). It is accessible to all DII users and MOD industry partners who have an RLI Service Delivery Point (SDP).
The DIMP hosting facility is located within a secure data centre. All infrastructure at the hosting site is subject to a biannual IT Security Health Check (ITSHC). ITHSC activities and schedules have been agreed with the CESG RLI/DFTS Accreditor.
It is important to note that all users of the system must abide by the RLI code of connection. All customers and end users requesting use of any of the services offered must be appropriately Security Cleared and evidence provided to GDUK before service delivery can commence.
In addition the Customer must possess Facility Security Clearances (FSC) premises and ensure that information derived from the DIMP is properly protected. The customer and end user are responsible for the protection and control of any data output produced during the service duration. Data output including all reports will be marked “Official-Sensitive”.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
All service components are managed within ITIL conformant change and configuration management processes. All changes are approved by the CAB and the CESG RLI/DFTS approved accreditor or STO.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
A dedicated security team are tasked with maintaining system security and vulnerability management. Bi-annual penetration testing is carries out with activities and schedules agreed with the CESG RLI/DFTS Accreditor. Team have access to the MOD Vigilant system and respond to all MODCERTs within the agreed timeframe
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
A dedicated security team is tasked with monitoring all systems and services and respond appropriately and in line with MOD guidance.
Incident management type
Supplier-defined controls
Incident management approach
A fully ITIL conformant service desk is available to all customers to manage Incidents and Service Requests.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
Yes
Connected networks
Other
Other public sector networks
RLI

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
ISO 9001 certification accredited by
BSI
ISO 9001 accreditation date
Friday 2 August 2024
What the ISO 9001 doesn’t cover
Our ISO 9001 certification does not cover those elements of our service delivery mechanisms that are under the direct control of MOD or their designated partners or subcontractors
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber Essentials Certificate Number
D8a08dd7-887d-46c5-8c6a-ed849e0f0b25
Cyber essentials plus
Yes
Cyber Essentials Plus Certificate Number
3e7084f0-6a07-4cd8-8fdd-d3933862abbc
Other security certifications
No

Social value

Mission: Kick start economic growth

To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

  • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
  • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
  • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
  • Plans to engage the contract workforce in deciding the most important workplace issues to address
  • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
  • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
  • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
  • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
  • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
  • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
  • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
  • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
  • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
  • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
  • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at lloyd.davies@gd-ms.uk. Tell them what format you need. It will help if you say what assistive technology you use.