Skip to main content

Help us improve the Digital Marketplace - send your feedback

INSIGHT DIRECT (UK) LTD

Insight - Quest erwin Data Intelligence Suite

An on-premise or SaaS solution.
https://www.erwin.com/products/erwin-data-intelligence/

Features

  • Automated harvesting of metadata from data sources; data at rest
  • Automated harvesting of integration code; data in motion
  • Data lineage impact assessment at a data element level
  • Role based access to appropriate data architecture information
  • Classification of data elements for sensitivity, PII purposes
  • User-defined assets to document processes, actors, regulations, policies, rules
  • Workflow functionality to evaluate and authorise change
  • Web-based-portal to access the DI modules for business users
  • Requirements gathering ability leading to governed lifecycle and release management
  • Professional services to enable swift understanding and deployment

Benefits

  • Swift and accurate documentation of the physical data architecture
  • Change impacts can be assessed and approved at granular level
  • Segregation of duties adhering to compliance expectations
  • Ability to evidence decisions based on laws and critical documentation
  • Easy to use and understand the complexities of data architecture
  • Mitigates risks and siloed working for key actors in processes/teams
  • Provides full visibility of architecture with user-enhanced and enriched information
  • Informed decision making through full understanding of cause and effect

Pricing

£8,993.84 a unit a year

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at pstenderteam@insight.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 14

Service ID

7 3 6 0 1 9 2 7 8 6 5 4 4 9 8

Contact

INSIGHT DIRECT (UK) LTD Public Sector Tender Team
Telephone: 0344 846 3333
Email: pstenderteam@insight.com

Service scope

Software add-on or extension
No
Cloud deployment model
Private cloud
Service constraints
1. The SaaS platform for repository can only be accessible from a pre-defined IP ranges.
2. Other prerequisites (hardware and software) should be adhered to base on the recommendations defined in the installation guide
System requirements
  • Refer to System Requirements provided here....
  • https://erwin-us.s3.amazonaws.com/Support/ADS/v13.2/erwin_DI_Installation_Guide.pdf

User support

Email or online ticketing support
Email or online ticketing
Support response times
For more information please visit our website: https://support.quest.com/essentials/support-offerings
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.1 AA or EN 301 549
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Web chat
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.1 AA or EN 301 549
Web chat accessibility testing
https://support.quest.com/essentials/support-offerings
Onsite support
Onsite support
Support levels
Quest’s Global Support Guide is available online at the following link, including:
• Managing Service Request
• Manage Account
• Product Support Policies
https://support.quest.com/essentials/support-guide

The SLAs are established and defined in our Erwin FAQ:
https://support.quest.com/essentials/erwin-faq
Support available to third parties
No

Onboarding and offboarding

Getting started
Yes, we offer required services and user documentation for our customers based on their needs and project.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Customer can request extract of the entire database backup and a backup will be provided
End-of-contract process
1. Customer can receive their DB backup upon request
2. Customer environment access will be revoked
3. After 30 days of the termination of the contract, customer environment and database backup will be permanently deleted.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
Application to install
Yes
Compatible operating systems
  • Linux or Unix
  • Windows
Designed for use on mobile devices
No
Service interface
No
User support accessibility
WCAG 2.1 AA or EN 301 549
API
No
Customisation available
No

Scaling

Independence of resources
The SaaS platform is a single tenant environment that will be maintained separately for every customer account

Analytics

Service usage metrics
Yes
Metrics types
Platform Usage dashboard capability is provided that shows a visualization of all assets (technical and business), users and roles onboarded in the platform between a selected date range (3 months, 6 months etc.) that can be configured accordingly
Reporting types
Real-time dashboards

Resellers

Supplier type
Reseller (no extras)
Organisation whose services are being resold
Quest

Staff security

Staff security clearance
Other security clearance
Government security clearance
Up to Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Other
Other data at rest protection approach
Data at Rest will be encrypted using Azure SQL storage encryption mechanism
Data sanitisation process
No
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001

Data importing and exporting

Data export approach
Standard Export options for end users are provided via Excel/CSV option.

Additional custom formats (JSON etc.) can be supported via custom connectors and API integration.
Data export formats
  • CSV
  • Other
Other data export formats
  • Excel/CSV for standard import functionalities
  • Additional custom formats (JSON etc.)
Data import formats
  • CSV
  • Other
Other data import formats
  • Excel/CSV for standard import functionalities.
  • Additional custom formats (JSON etc.)

Data-in-transit protection

Data protection between buyer and supplier networks
Other
Other protection between networks
Data in transit and data at rest is encrypted using secure Transmission via SSL/HTTPS and TLS and are encrypted/decrypted via AES 256 algorithm. All the passwords stored in the application's database are secured using FIPS-120 AES 256 algorithms.
Data protection within supplier network
Other
Other protection within supplier network
Data in transit and data at rest is encrypted using secure Transmission via SSL/HTTPS and TLS and are encrypted/decrypted via AES 256 algorithm. All the passwords stored in the application's database are secured using FIPS-120 AES 256 algorithms.

Availability and resilience

Guaranteed availability
Microsoft SLAs:
Postgres SLA: https://azure.microsoft.com/en-us/support/legal/sla/postgresql/v1_3/
App Gateway SLA: https://azure.microsoft.com/en-us/support/legal/sla/application-gateway/v1_2/
AKS SLA: https://azure.microsoft.com/en-us/support/legal/sla/kubernetes-service/v1_1/
Approach to resilience
N/A
Outage reporting
If there are any outages we send an alert via email notifications to key stakeholders

Identity and authentication

User authentication needed
Yes
User authentication
Other
Other user authentication
Authentication to the application is provided via SSO authentication that includes SAML, OKTA, Azure AD options
Access restrictions in management interfaces and support channels
Privileged access is controlled through the access process and monitoring/review of activities
Access restriction testing frequency
At least every 6 months
Management access authentication
Other
Description of management access authentication
Multi-factor authentication is employed to ensure secure access to business sensitive data. Quest employs a least privileged model where employees are only granted the permissions that are necessary to perform their work tasks. Elevated privileges are granted temporarily through a privileged access group model, where the access must first be approved, and its use is audited until it is automatically revoked. Multi-factor authentication is employed to ensure secure access to business sensitive data.

Audit information for users

Access to user activity audit information
Users receive audit information on a regular basis
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
NQA
ISO/IEC 27001 accreditation date
8/26/2022
What the ISO/IEC 27001 doesn’t cover
Scope of certification is the provision of SaaS and Hosting Services
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber essentials plus
No
Other security certifications
Yes
Any other security certifications
  • SOC 2 Type 2 for will be made available
  • SOC 2 Type 2 by accessing Whistic.
  • ERWIN BY QUEST

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
ISO 27001 Standards and Procedures. Reporting structure is Senior Vice President of Products of erwin managed through the Cloud Services teams.

Operational security

Configuration and change management standard
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Configuration and change management approach
Formal, secure Software Development Life-Cycle (SDLC) processes are in place that have been approved by management, communicated to appropriate constituents. These processes include change management and are reviewed and maintained regularly. Dev and Ops Teams are trained to properly configure an Approved Configuration for the Cloud environment (Virtual Networks, NSG, WAF). Benchmarks published by the CIS are followed as baselines and non-compliance is detected by leveraging built-in Azure or AWS tools as well as custom scripts. The deployment process follows a strict Change Management process where all changes are identified, reviewed and approved by the Dev and Ops teams
Vulnerability management type
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Vulnerability management approach
Monthly Vulnerability scans are performed internally. During the yearly Third-Party penetration testing exercise outsourced scans are also performed.
Protective monitoring type
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Protective monitoring approach
Alerts are monitored and reviewed by our 24x7 SOC team
Incident management type
Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
Incident management approach
Quest has established a formal process of preparation, detection, analysis, containment, eradication, recovery, and post-incident activities. As well, in accordance with international privacy laws, Quest has established a Security Breach Notice process.

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Social Value

Social Value

Social Value

  • Covid-19 recovery
  • Tackling economic inequality
  • Equal opportunity
  • Wellbeing

Covid-19 recovery

Please see the link below for more information on COVID 19 -

For more information please visit Quest website: https://www.quest.com/quest-ensures-business-continuity-for-a-remote-workforce/

Tackling economic inequality

See our 'Diversity, Equality and Inclusion' statement attached.

https://www.quest.com/

please see the below for more - https://www.quest.com/legal/promoting-human-rights.aspx

Equal opportunity

Quest is compliant for Equal Opportunity , please see the link below:
https://www.quest.com/combined-t-and-c/

https://www.quest.com/

please see the below for more - https://www.quest.com/legal/promoting-human-rights.aspx

Wellbeing

Quest has a wellbeing program included for all employees.

https://www.quest.com/

please see the below for more - https://www.quest.com/legal/promoting-human-rights.aspx

Pricing

Price
£8,993.84 a unit a year
Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Free trial is provided based on the scope
Link to free trial
Erwin Data Intelligence v13.2 Bookshelf

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at pstenderteam@insight.com. Tell them what format you need. It will help if you say what assistive technology you use.