CollectionsIndex+
CollectionsIndex+ is a standards-compliant collections management system for museums, archives, libraries and other organisations that have a need to catalogue, manage or share collections of objects, documents, images or films.
Features
- Modular, scalable, standards-based collections management system
- Spectrum, ISAD(G), MARC 21 and EN15907 compliant modules
- Integrated Digital Asset Management options
- Public search-the-collections website, REST API and IIIF server
- Powerful reporting functionality
- International text support
- Workflow management
- Role-based permissions model
- Single Sign On integration option
- Data migration, training and collections consultancy services available
Benefits
- Manage object, archive, book and film collections in one system
- Catalogue consistently across collections using shared terminologies and authorities
- Manage images, audiovisual content and other digital assets
- Structure your collections management activities with CollectionsIndex+ workflows
- Create compelling Word and Excel reports
- Publish your collections on the web
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 4 5 3 8 4 1 3 4 7 7 1 9 2 4
Contact
SYSTEM SIMULATION LIMITED
Richard Beales
Telephone: +442078367406
Email: leads@ssl.co.uk
About your service
- Service categories
-
Applications
Content workflow and management
- Capture
- Document
Content services
- Enterprise Content Management Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- CollectionsIndex+ Web Edition is designed for tablet, laptop or desktop use via any current-generation web browser. CollectionsOnline is a responsive website that gives a great user experience on mobile, tablet or laptop/desktop devices.
- System requirements
-
- Current-generation web browser with internet access.
- The optional Office Export module requires a Microsoft Office licence.
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
-
Response times are aligned with our service level agreement.
We will provide a help desk between 09:30 and 17:30 UK time (the support hours).
We respond to the most urgent, 'Critical' queries within four hours during support hours. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- All support is given by our in-house collections consultants and our team of engineers. Overwhelmingly, the people that support your system once you’re live will be the same team that you’ve got to know during the initial project. We do have some mechanisms that we use to help us best manage support requests and conversations, but you’re always more than welcome to phone or email individual members of staff directly. In addition to our standard 'Bronze' support package, we also offer enhanced 'Silver' and 'Gold' packages that come with the same support SLA obligations but also include discounted blocks of pre-paid consultancy time, which can be used for system enhancements, additional configuration, training or other services throughout the year. Support pricing varies according to the specific software modules purchased and the number of concurrent user licences required. For a standard CollectionsIndex+ system with one collections module, licensed for four concurrent users, annual support fees would typically cost between £750 and £2000 per year.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We normally include two training sessions with each system delivery. Training can be delivered remotely, on site or at our London office. Additional training can be purchased as required. We also provide a system manual, and have a growing library of video tutorials that are freely available to all users.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Users can download their data in a number of formats at any time, subject, as always, to their authorisation level in the system. System Simulation are always there to provide help and support and can export data for users when required.
- End-of-contract process
- At contract end System Simulation will update our internal documentation to note the end of the contract. Where we are providing hosting services, we will take down those services, delete data and configuration from public-facing servers and stop backups; old backups will continue to be retained according to the usual backup retention policy which will result in automatic deletion after around several months.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
- As standard, the CollectionsIndex+ API supports read-only search and retrieval of collections records, including authorities and terminology records.
- API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- The CollectionsIndex+ Views Manager allows users to create named subsets of CollectionsIndex+ fields, known as “views”, for themselves and others. Views can be marked as Public, accessible by all users of your CollectionsIndex+ system, or Private, for only that login. The current view is selected from a drop-down of available views. The selected view governs the the record view, the edit form and the field options in the advanced search. Once a view has been selected, that selection persists but is easily changed. Views are particularly useful for constraining the data shown to that required by particular types of users, different tasks or different collections. The Views Manager is flexible and easy to use. Views can be created for any record type including collection records (archives and objects), authority records, activity records etc. Views are normally independent of permissions.
Scaling
- Independence of resources
- Where we are providing hosting services, we aim to over-resource our hosting platforms as well as sharing those resources between users. This means generally there is an excess of provision and allows for peaks of demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
- On request we integrate CollectionsOnline with Google Analytics for tracking of public collections website usage.
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- CollectionsIndex+ has inbuilt facilities for export of data in CSV, XML and RDF-TTL formats. Ingested digital assets can be retrieved in their native formats. The optional Office Export module allows data to be exported in Word or Excel format. We also offer an optional JSON/REST API.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- Our hosting SLA includes a guarantee of at least 99.9% network up-time.
- Approach to resilience
- Available on request.
- Outage reporting
- Service outage and restoration events are reported by email and via a banner in our ticketing system.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access is controlled by username and password which determines the authorisation level of the user and what interfaces and channels they can access. In cases where we implement customer SSO, the customer SSO system might implement further access control such as MFA.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Public key authentication (including by TLS client certificate)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials
- Information security policies and processes
- Our staff are experienced qualified professionals who are required to follow relevant professional codes of practice. During data migration, information is stored on systems with no direct connection to the internet and we make use of encryption-at-rest and encryption-in-transit. We follow a series of industry best practice system hardening steps for all internet-connected servers. Systems are subject to automated monitoring which reports automatically to the supporting engineering staff who respond to anomalies. Multiple monitoring systems are deployed and reports are sent to multiple staff and at different levels of seniority.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Management approach Our software and configurations are held in a source code control system which records all changes. This record keeping is augmented by regular backups with a long-term retention policy. Changes are made in consultation with client user representatives to ensure changes are carried out in full sight. Changes are installed on public-facing systems after internal development, testing and release cycles. Security impact assessment is a permanent part of the development and release process.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Threat monitoring focuses on the different threat sources including internally-derived faults, faults in third-party software including operating system software, malware injection, and configuration errors. Our systems take at least daily updates automatically from reputable software support organisations such as operating system vendors. We run industry standard malware detection software on our servers. We monitor security alerts for any third-party software which can’t be automatically updated. We aim to deploy critical updates within 24 hours of discovery/announcement.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We run automated monitoring both on servers and remotely against our servers and these run continually. Alerts are sent to the relevant hosting and engineering teams and are responses are actioned immediately.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We do not have scripted procedures for incident management, but have an experienced hosting team who divert all attention to incident management when necessary. We have processes for contacting affected clients to ensure they are kept up to date with incident management, and for recovery and restoration of services. Users all have access to our ticketing system which is the standard way to report an incident. Users can also e-mail or phone us.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- We offer access to demonstration CollectionsIndex+ and CollectionsOnline platforms on-request. These are populated with a sample, redacted, demonstration data set kindly provided by several of our existing clients. Users are free to remove, edit or create records for evaluation purposes.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
-