Managed Cloud Services
BetterGov provide Microsoft Cloud Services as an authorised reseller. We offer hosting on the following Microsoft Cloud services: Azure, Office 365, Dynamics and SharePoint. We can deliver planning, design, development, support and managed service.
Features
- Microsoft Managed Service
- Experienced Staff
Benefits
- Pay for What You Use
Pricing
£0.05 a transaction
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
9 0 1 8 2 3 5 2 6 0 0 7 2 4 1
Contact
BetterGov
Marc Cohen
Telephone: 0203 289 4203
Email: marc@bettergov.co.uk
Service scope
- Service constraints
- No
- System requirements
- None
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
-
Monday to Friday - 9am - 5.30pm (excluding Public Holidays).
Tiered response, according to the severity of the issue being reported: Severity 1 - 15 minutes, Severity 2 - 30 minutes, all other issues - 60 minutes. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.1 AAA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Support services are agreed with clients on a case by case basis, dependent on requirements.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Onsite training and/or user documentation will be provided to fully support the application.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
- https://www.microsoft.com/en-us/trustcenter/privacy
- End-of-contract process
- https://www.microsoft.com/en-us/trustcenter/privacy/you-own-your-data. In our Online Services Terms, Microsoft contractually commits to specific processes when a customer leaves a cloud service or the subscription expires. This includes deleting customer data from systems under our control. If you terminate a cloud subscription or it expires (except for free trials), Microsoft will store your customer data in a limited-function account for 90 days (the “retention period”) to give you time to extract the data or renew your subscription. During this period, Microsoft provides multiple notices, so you will be amply forewarned of the upcoming deletion of data. After this 90-day retention period, Microsoft will disable the account and delete the customer data, including any cached or backup copies. For in-scope services, that deletion will occur within 90 days after the end of the retention period. (In-scope services are defined in the Data Processing Terms section of our Online Services Terms.) See http://www.microsoftvolumelicensing.com/Downloader.aspx?DocumentId=11745
Using the service
- Web browser interface
- Yes
- Using the web interface
- The service is role based. Users can access and perform tasks based on permission levels and access granted.
- Web interface accessibility standard
- WCAG 2.1 AAA
- Web interface accessibility testing
- None
- API
- Yes
- What users can and can't do using the API
- The Microsoft Cloud Service has several API end point and allows users to setup, make changes, and automate service provision.
- API automation tools
-
- Chef
- OpenStack
- Puppet
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- Command line interface
- Yes
- Command line interface compatibility
-
- Linux or Unix
- Windows
- MacOS
- Other
- Using the command line interface
- Azure CLI 2.0 is optimized for managing and administering Azure resources from the command line, and for building automation scripts that work against the Azure Resource Manager. See https://docs.microsoft.com/en-us/cli/azure/install-azure-cli
Scaling
- Scaling available
- Yes
- Scaling type
-
- Automatic
- Manual
- Independence of resources
- Microsoft ensures SLA's are maintained and usage monitored.
- Usage notifications
- Yes
- Usage reporting
Analytics
- Infrastructure or application metrics
- Yes
- Metrics types
-
- CPU
- Disk
- HTTP request and response status
- Memory
- Network
- Number of active instances
- Reporting types
-
- Real-time dashboards
- Reports on request
Resellers
- Supplier type
- Reseller (no extras)
- Organisation whose services are being resold
- Microsoft
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 3.0)
- Penetration testing frequency
- Less than once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v3.0
- Physical access control, complying with SSAE-16 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Data sanitisation type
-
- Explicit overwriting of storage before reallocation
- Deleted data can’t be directly accessed
- Hardware containing data is completely destroyed
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001
Backup and recovery
- Backup and recovery
- Yes
- Backup controls
- Please see https://docs.microsoft.com/en-gb/azure/backup/backup-azure-vms-first-look
- Datacentre setup
-
- Multiple datacentres with disaster recovery
- Multiple datacentres
- Scheduling backups
- Users schedule backups through a web interface
- Backup recovery
-
- Users can recover backups themselves, for example through a web interface
- Users contact the support team
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
Availability and resilience
- Guaranteed availability
- http://www.microsoftvolumelicensing.com/Downloader.aspx?DocumentId=11745
- Approach to resilience
- https://www.microsoft.com/en-us/cloud-platform/global-datacenters and https://www.microsoft.com/en-us/TrustCenter/
- Outage reporting
- https://azure.microsoft.com/en-us/status/ and https://portal.azure.com/#blade/HubsExtension/ServicesHealthBlade
Identity and authentication
- User authentication
-
- 2-factor authentication
- Username or password
- Access restrictions in management interfaces and support channels
- Username and Password
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- 2-factor authentication
- Username or password
- Devices users manage the service through
-
- Dedicated device on a segregated network (providers own provision)
- Dedicated device on a government network (for example PSN)
- Dedicated device over multiple services or networks
- Any device but through a bastion host (a bastion host is a server that provides access to a private network from an external network such as the internet)
- Directly from any device which may also be used for normal business (for example web browsing or viewing external email)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- Yes
- Other security certifications
- No
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- ITIL
- Information security policies and processes
- https://www.microsoft.com/en-us/TrustCenter/Compliance/ISO-IEC-27001
Operational security
- Configuration and change management standard
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Configuration and change management approach
- https://www.microsoft.com/en-us/SDL/OperationalSecurityAssurance and https://www.microsoft.com/en-us/sdl
- Vulnerability management type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Vulnerability management approach
- CSA CCM v3.0 standards
- Protective monitoring type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Protective monitoring approach
- CSA CCM v3.0 standards
- Incident management type
- Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
- Incident management approach
- CSA CCM v3.0 standards
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Separation between users
- Virtualisation technology used to keep applications and users sharing the same infrastructure apart
- Yes
- Who implements virtualisation
- Supplier
- Virtualisation technologies used
- Hyper-V
- How shared infrastructure is kept separate
- https://www.microsoft.com/en-us/TrustCenter/Security/default.aspx
Energy efficiency
- Energy-efficient datacentres
- Yes
- Description of energy efficient datacentres
- Microsoft managed
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Covid-19 recovery
- Tackling economic inequality
- Equal opportunity
- Wellbeing
Fighting climate change
Our Carbon Reduction Plan outlines our current carbon footprint and the way in which we aim to be Net Zero by 2050.Covid-19 recovery
We have modified and improved workplace conditions that support the COVID-19 recovery effort.Tackling economic inequality
We are a member of the Living Wage UK. Our membership confirms we pay all staff at least the national minimum wage but in addition our membership enables Living Wage UK to promote their agenda to bring more businesses and employers into the scheme.Equal opportunity
We donate to Access UK, a charity that supports BME youth employment and job creation in the community.Wellbeing
We provide training opportunities for staff to upskill them in interests related to social care and IT in the workplace but also personal/social interests on a case-by-case basis.
Pricing
- Price
- £0.05 a transaction
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- To be agreed.