Sterling Azure Cloud £10K
Sterling provides Azure reselling motion that allows customers to access either a root account or admin account as desired by compliance standards. If amount is reached before renewal, customer can renew through G-Cloud to provide additional funds before account removal.
Features
- IaaS
- Paas
- SaaS
- Serverless
Benefits
- Elasticity to scale as required
- Simple enablement for enterprise services
- Metered on consumption
Pricing
£9,600 to £10,000 a transaction a year
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
9 8 1 2 4 5 1 5 0 5 6 8 4 1 4
Contact
Sterling Computers Corporation
Luke Flanagan
Telephone: +447557400401
Email: luke.flanagan@sterling.com
Service scope
- Service constraints
- Sterling Azure Cloud is limited to only Azure services and does not cover any licensing, or consumption inside or out of Azure services.
- System requirements
- Ther are no system requirements.
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- Sterling provides Azure support through TDS which is priced at £250 per month and 5% of that customers Azure spend
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes, at an extra cost
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- It is available through TDS portal
- Web chat accessibility testing
- N/A
- Onsite support
- No
- Support levels
- Sterling resells TDS Elite support for our Azure customers
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- During the onboarding Sterling supports users by informing them of Azure best practices around Identity Access Management and consumption. This allows customers to have a leg up on Cloud before engaging in consuming products.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Users are able to extract their data from the cloud via internet, VPN, or direct connect. Egress charges will apply and be consumed via the Sterling Cloud Fund.
- End-of-contract process
- At the end of the contract Sterling will reach out for renewal, and if agreed will be renewed for another year. If no renewal is achieved the account will be removed from Sterling and be available to the customers until Microsoft reassigns the account to another reseller or maintains direct integration with the customer. Normal G-Cloud pricing is required upon renewal.
Using the service
- Web browser interface
- Yes
- Using the web interface
- Users can provision, modify, remove and utilize their Azure solutions within their Azure Tenant.
- Web interface accessibility standard
- None or don’t know
- How the web interface is accessible
- Through a web portal allowing both login through normal credentials and MFA.
- Web interface accessibility testing
- N/A
- API
- Yes
- What users can and can't do using the API
- Azure uses Open API (also known as Swagger). All requests fall under that toolset.
- API automation tools
-
- Ansible
- Chef
- SaltStack
- Terraform
- Puppet
- API documentation
- No
- Command line interface
- Yes
- Command line interface compatibility
-
- Linux or Unix
- Windows
- MacOS
- Using the command line interface
- A full list of references can be found here: https://learn.microsoft.com/en-us/cli/azure/
Scaling
- Scaling available
- Yes
- Scaling type
-
- Automatic
- Manual
- Independence of resources
- Azure Terms of service can be found here: https://azure.microsoft.com/en-us/support/legal/
- Usage notifications
- Yes
- Usage reporting
-
- Other
- Other usage reporting
- Phone Call
Analytics
- Infrastructure or application metrics
- Yes
- Metrics types
-
- CPU
- Disk
- HTTP request and response status
- Memory
- Network
- Number of active instances
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Microsoft Azure
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- Never
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Backup and recovery
- Backup and recovery
- Yes
- What’s backed up
- https://azure.microsoft.com/en-us/products/backup
- Backup controls
- Azure Backup is available through this plan and has its capabilities here: https://azure.microsoft.com/en-us/products/backup
- Datacentre setup
- Multiple datacentres with disaster recovery
- Scheduling backups
- Users schedule backups through a web interface
- Backup recovery
- Users can recover backups themselves, for example through a web interface
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
Availability and resilience
- Guaranteed availability
- SLA's can be found here: https://www.microsoft.com/licensing/docs/view/Service-Level-Agreements-SLA-for-Online-Services?lang=1
- Approach to resilience
- Available upon request
- Outage reporting
- A public dashboard: https://azure.status.microsoft/en-us/status
Identity and authentication
- User authentication
-
- 2-factor authentication
- Identity federation with existing provider (for example Google apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Users login to their organization with username and password through their federated settings and MFA through their federated settings.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Other
- Description of management access authentication
- Sterling does not hold management accounts within the customers organization.
- Devices users manage the service through
-
- Any device but through a bastion host (a bastion host is a server that provides access to a private network from an external network such as the internet)
- Directly from any device which may also be used for normal business (for example web browsing or viewing external email)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Schellman LLP
- ISO/IEC 27001 accreditation date
- 28/09/2023
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2007 certification
- No
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- 17/02/2023
- CSA STAR certification level
- Level 1: CSA STAR Self-Assessment
- What the CSA STAR doesn’t cover
- N/A
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- No
- Other security certifications
- Yes
- Any other security certifications
-
- CMMC
- NIST 800-17
- ISO 9001
- ISO 14001
Security governance
- Named board-level person responsible for service security
- No
- Security governance certified
- No
- Security governance approach
- CISO
- Information security policies and processes
- Protecting an institution's critical assets' confidentiality, integrity, and availability is paramount in today's digital landscape. At Sterling, we implement a comprehensive array of physical, technical, and administrative controls to safeguard data and ensure the security of our systems. Our strategies encompass a multifaceted approach addressing various cybersecurity and risk management aspects.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Configuration and change management processes are user defined.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- User vulnerability management is defined within Azure.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- User protective monitoring is defined within Azure.
- Incident management type
- Supplier-defined controls
- Incident management approach
- User incident management is defined within Azure.
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Separation between users
- Virtualisation technology used to keep applications and users sharing the same infrastructure apart
- Yes
- Who implements virtualisation
- Supplier
- Virtualisation technologies used
- Other
- Other virtualisation technology used
- Hyper-V
- How shared infrastructure is kept separate
- N/a
Energy efficiency
- Energy-efficient datacentres
- Yes
- Description of energy efficient datacentres
- Azure adhere to the EU Code of Conduct for Energy Efficient datacentres and documentation is available upon request.
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Covid-19 recovery
- Tackling economic inequality
- Equal opportunity
Fighting climate change
Sterling leverages AWS data centers, and as such, we get the benefit of their state-of-the-art facilities, physical and environmental security. This is detailed in AWS Overview of Security Processes https://aws.amazon.com/architecture/security-identity-compliance/?cards-all.sort-by=item.additionalFields.sortDate&cards-all.sort-order=desc&awsf.reference-architecture=*all&awsf.content-type=*all&awsf.methodology=*all&tma-cards-security.sort-by=item.additionalFields.airDate&tma-cards-security.sort-order=desc Fire Detection and Suppression Automatic fire detection and suppression equipment have been installed to reduce risk. The fire detection system utilizes smoke detection sensors in all data center environments, mechanical and electrical infrastructure spaces, chiller rooms, and generator equipment rooms. These areas are protected by either wet-pipe, double-interlocked pre-action, or gaseous sprinkler systems. Power The data center electrical power systems are designed to be fully redundant and maintainable without impact to operations, 24 hours a day, and seven days a week. Uninterruptible Power Supply (UPS) units provide backup power in the event of an electrical failure for critical and essential loads in the facility. Data centers use generators to provide backup power for the entire facility. Climate and Temperature Climate control is required to maintain a constant operating temperature for servers and other hardware, which prevents overheating and reduces the possibility of service outages. Data centers are conditioned to maintain atmospheric conditions at optimal levels. Personnel and systems monitor and control temperature and humidity at appropriate levels.Covid-19 recovery
Sterling has a formal Business Continuity Plan designed to continue operating the services in the event of different business disruptions. This includes Druva’s pandemic plan that has been activated in the event of the COVID-19 pandemic. In summary, Sterling has a distributed workforce with personnel located in countries around the world. Druva personnel all have the ability to work remotely. Primary business systems are hosted services and can be accessed anywhere over the internet.Tackling economic inequality
Sterling actively supports educational establishments, the wider public sector, and local communities through various initiatives. One notable involvement is as an ambassador for the STEM Learning programme, where Sterling collaborates to improve the educational outcomes of young people in STEM education. This partnership aims to foster collaboration and support within the STEM education ecosystem, ensuring that young learners can access quality educational resources and opportunities. Furthermore, Sterling has extended its support to local schools and universities, such as Lancaster and Manchester. This assistance primarily involves participation in learning events hosted by these universities at the Manchester DiSH office, where Sterling is situated. Manchester DiSH has supported over 4000 youngsters with online safety, accredited female lead VCSEs with Cyber essentials, hosted MPs and supported countless businesses with cyber awareness. An example of Sterling’s involvement, is we actively participated in a 'Dragons Den' event organised for local schools, held at the Manchester DiSH office, hosted by Barclays Eagle Labs. During this event, Sterling engaged with young entrepreneurs, listened to their business ideas, provided valuable feedback, and offered guidance and support to their educational business studies. Sterling is also actively helping with Elective Home Education (EHE), where children between the ages of eight and fifteen come into the office to learn subjects such as Robotics, Cyber Security, and Money Management.Equal opportunity
Sterling is committed to providing free-of-charge skill provision to our Members and Wider Public Sector Contracting Authorities accessing this Framework Agreement. Our aim is to offer a range of workshops, seminars, and online training sessions that are tailored to meet the specific needs of our stakeholders. These sessions will cover a diverse array of topics, including technical skills relevant to our industry and broader soft skills essential for professional development. We will work closely with our partners and stakeholders to identify areas of need and tailor our training offerings accordingly. Sterling proudly hosts a dynamic paid internship program renowned for its enriching experiences. Each summer, interns at Sterling delve into various facets of our operations, honing essential Sales, Accounting, and Operations skills. Moreover, participants enjoy various benefits, including mentorship from seasoned professionals, exposure to real-world projects, and networking opportunities within our vibrant corporate culture. Designed for college students, our internship program is a launching pad for aspiring professionals. It offers invaluable insights and hands-on training that complement academic learning. As a testament to its success, many of our interns seamlessly transition into full-time roles upon graduation, leveraging their internship experience to hit the ground running in their careers. At Sterling, we're committed to nurturing talent and empowering the next generation of leaders. Join us this summer and embark on a journey of growth, learning, and endless possibilities. Sterling currently offers this program globally and will endeavour to extend this opportunity to participants once we are brought on to the framework. This internship program serves as an essential avenue for developing talent and fostering future leaders in our industry.
Pricing
- Price
- £9,600 to £10,000 a transaction a year
- Discount for educational organisations
- No
- Free trial available
- No