Skip to main content

Help us improve the Digital Marketplace - send your feedback

CSI Limited

IBM Apptio Cloudability - FinOps & Cloud Cost Management

IBM Apptio Cloudability is a cloud cost management and optimization solution. It allows FinOps practitioners to automate allocation, showback or chargeback of cloud costs to the business through business mappings, empowers delivery teams to take ownership of their spend and provides optimization recommendations.

Features

  • Cloud cost management for major cloud providers
  • Dashboards & Reporting: Cloud agnostic tagging, views and allocation
  • Budgets & Forecasts: Plan future cloud spend and manage budget
  • Anomaly Detection: Identify surprises in your spend
  • Containers: Accurately identify and optimize container costs, allocate to teams
  • Saving Plans & Reservations: Maximise commitments and save across providers
  • Rightsizing: Match resources to workload needs
  • Workload Placement: Find the optimal location for new workloads

Benefits

  • Proven record of savings of 20-40% on cloud spend
  • Automate invoicing, showback and chargeback
  • Self-service reporting and friendly UI can save 25+hrs a month
  • Cost performance analysis
  • Increase committed coverage to 80%+ with RI/Saving Plan
  • ML recommendations for AWS, Azure and GCP resource wastage
  • Forecasting, budgeting, anomaly detection and alerting by team
  • Automate commitments to increase savings & flexibility whilst reducing risk
  • Best practice cloud cost management using FinOps
  • Migration recommendations (rehost , Azure HB, DB Freedom)

Pricing

£21,000 a licence a year

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at jennifer.billett@csiltd.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 14

Service ID

9 9 0 7 2 3 4 9 2 8 5 8 3 2 8

Contact

CSI Limited Jennifer Billett
Telephone: 08001088301
Email: jennifer.billett@csiltd.co.uk

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Yes but can also be used as a standalone service
Cloud deployment model
Public cloud
Service constraints
N/A
System requirements
https://www.ibm.com/docs/en/security-verify?topic=overview-product-requirements

User support

Email or online ticketing support
Email or online ticketing
Support response times
Initial Response: Critical - 30 min response time High - 1 business hour Medium - 1 business hour Low - 1 business hour Ongoing: Critical - 1 hour High - 8 business hours Medium - 2 business days Low - 3 business days
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Support levels detailed at the following link: https://www.ibm.com/support/pages/node/738881 The advanced support level is included with the product.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Apptio will perform the Professional Services engagement set forth herein toonboard and enable Subscriber on standard Cloudability application functionality. After initial enablement, Apptio will conduct a seriesof work sessions on Financial Operations (FinOps) best practices, designed to help Subscriber establish their FinOps function. Project Tasks Apptio Tasks Kickoff - Conduct Engagement Kickoff call Phase 1: Onboarding and Enablement - Conduct the following four (4) enablement Work Sessions: o Week 1: Implementation & Foundational product training – Review currentsetup, and identify tasks to complete implementation including credentials,user preferences, current activity, and daily mail and API key generation.Review tagging, account groups, views, business mappings, and sharedgoals o Week 2: Foundational product training – Review dashboards, and widgets,reports, alerts, true cost, and tag explorer o Week 3: Foundational product training – Review containers, anomalydetection, scorecards, reservation portfolio, rightsizing, RI planner,automation, and workload placement o Week 4: Foundational product training – Review current month, forecasts,and budgets, and user rollout - Each Work Session is approximately 50 minutes in length
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
Deletion and Return of Content • If requested prior to termination or expiration of the Cloud Service, IBM will return a copy of Content that is accessible to IBM within a reasonable period and in a reasonable format. IBM will delete the Content at the end of the period specified in the 'Duration of Processing' Section above. • Client may also request removal of Content at any time prior to termination or expiration of the Cloud Service. • Where IBM stores Client Personal Data, as part of the cloud service, IBM hereby certifies that all Client Personal Data are deleted at the end of the retention period specified in section • IBM may charge for certain activities performed at Client's request (such as delivering Content in a specific format).
End-of-contract process
Deletion and Return of Content • If requested prior to termination or expiration of the Cloud Service, IBM will return a copy of Content that is accessible to IBM within a reasonable period and in a reasonable format. IBM will delete the Content at the end of the period specified in the 'Duration of Processing' Section above. • Client may also request removal of Content at any time prior to termination or expiration of the Cloud Service. • Where IBM stores Client Personal Data, as part of the cloud service, IBM hereby certifies that all Client Personal Data are deleted at the end of the retention period specified in section • IBM may charge for certain activities performed at Client's request (such as delivering Content in a specific format).

Using the service

Web browser interface
Yes
Supported browsers
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Chrome
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • Linux or Unix
  • MacOS
  • Windows
  • Windows Phone
  • Other
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
N/A
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
The full API guide can be accessed here: https://www.ibm.com/docs/en/qradar-common?topic=api-restful-overview
Accessibility standards
None or don’t know
Description of accessibility
The full API guide can be accessed here: https://www.ibm.com/docs/en/qradar-common?topic=api-restful-overview
Accessibility testing
The full API guide can be accessed here: https://www.ibm.com/docs/en/qradar-common?topic=api-restful-overview
API
Yes
What users can and can't do using the API
The full API guide can be accessed here: https://www.ibm.com/docs/en/qradar-common?topic=api-restful-overview
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
No
Customisation available
No

Scaling

Independence of resources
Each client receives their own dedicated instance of the service. The architecture of IBM cloud services maintains logical separation of client data. Internal rules and measures separate data processing, such as inserting, modifying, deleting, and transferring data, according to the contracted purposes.

Analytics

Service usage metrics
Yes
Metrics types
SaaS solution hosted on containers in the cloud means we scale automatically and have separated tenancy
Reporting types
Real-time dashboards

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
IBM

Staff security

Staff security clearance
Other security clearance
Government security clearance
Up to Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
Less than once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Physical access control, complying with CSA CCM v3.0
Data sanitisation process
Yes
Data sanitisation type
  • Explicit overwriting of storage before reallocation
  • Deleted data can’t be directly accessed
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001

Data importing and exporting

Data export approach
Cloudability has an API first approach that enables integration to pretty much any system/data source and we have a number of out of box integrations to source systems such as AWS, Azure, GCP, Datadog and many others and we can always push/pull through CSV
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Legacy SSL and TLS (under version 1.2)
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
If the System Availability during any given month falls below 99.5% and Subscriber requests an SLA Credit, Apptio will provide Subscriber with a SLA Credit equal to 2% of the monthly subscription fee. If below 99%, the credit is 5%. If below 95%, the credit is 10%.
Approach to resilience
We follow best practices outlined by the certified standards listed above
Outage reporting
Public dashboard

Identity and authentication

User authentication needed
Yes
User authentication
  • 2-factor authentication
  • Username or password
Access restrictions in management interfaces and support channels
In accordance to best practices outlined by the certified standards listed above, IBM takes commercially reasonable measures in compliance with best industry practices to prevent disclosure or dissemination of Subscriber Data to any person not having a need to know of or access to such information. IBM maintains access controls and policies to manage access from each network connection including the use of firewalls or functionally equivalent technology. Least privilege‐based authentication and authorization controls are maintained and periodically reviewed to ensure that access can only be granted to IBM personnel whose function and/or duties justifies such access.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • 2-factor authentication
  • Username or password

Audit information for users

Access to user activity audit information
No audit information available
Access to supplier activity audit information
No audit information available
How long system logs are stored for
At least 12 months

Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
BSI
ISO/IEC 27001 accreditation date
27/03/2023
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
NCC Group Security Services Ltd
PCI DSS accreditation date
01/04/2024
What the PCI DSS doesn’t cover
N/A
Cyber essentials
Yes
Cyber essentials plus
No
Other security certifications
No

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
The Information Security team, Legal department, and Internal Compliance/Audit department all work together to ensure that industry best security practices are met. This cloud service environment follows stringent guidelines to protect the confidentiality, integrity,privacy, and availability of your data. We have the following reporting structures: SOC2 Type II Report and SOC3 Report , ISO27001:2013 Certification, FedRAMP Certification, Cloud Security Alliance – STAR Level One Certification, General Data Protect Requirements (EUGDPR), CaliforniaConsumer Privacy Act (CCPA), EU-US Privacy Shield, ITIL Alignment

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We have specific individuals who are designated as “custodians” over customer data. Our asset management program includes critical assets, asset ownership and critical supplier relationships. Our asset tracking processes allows our company to track what assets, who owns, where each is located,who has it, when it was checked out, when it is due for return, when it is scheduled for maintenance, and the cost and depreciation of each asset. Basic mechanisms for label inheritance are implemented for objects that act as aggregate containers for data where applicable. (Subfolders will retain permissions/settings of parent folders).
Vulnerability management type
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Vulnerability management approach
Vulnerability Assessments & Penetration Testing: We regularly assess our systems and applications for vulnerabilities using industry-standard tools. We subscribe to threat intelligence feeds to stay informed about emerging cybersecurity threats.
Protective monitoring type
Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Protective monitoring approach
Security Incident Monitoring: We continuously monitor our systems for suspicious activity that might indicate a security breach.
Incident management type
Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
Incident management approach
IBM team is alerted automatically by its monitoring services and appropriate operations and development personnel are paged within seconds of a failure or anomaly detection in any service component. These cloud services are built to be resilient to failure with load balancing and re-routing of transactions through redundant service roles deployed at each layer of the topology. These services are actively monitored on a real-time, 24x7 basis. Any service interruption or degradation of service is reviewed internally and improvements made to target faster Time-to-Detection, Time-to-Mitigation, and Time-to-Heal as part of the regular rhythm of operating the service.

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)

Public sector networks

Connection to public sector networks
No

Social Value

Social Value

Social Value

  • Fighting climate change
  • Covid-19 recovery
  • Tackling economic inequality
  • Equal opportunity
  • Wellbeing

Fighting climate change

IBM are committed to achieving net zero greenhouse gas emissions globally by 2030. On this path, IBM are on track to have reduced greenhouse gas emissions by 65% (against 2010 base) in 2025, and 75% of our global electricity consumption will be from renewables by 2025. The IBM UK Carbon Reduction Plan (CRP) is published annually in which we report progress in achieving Net Zero; most recent in September 2023. In fulfilling our responsibilities under our contracts, our staff operate in line with our IBM Environmental Policy and implemented through our worldwide Environmental Management System (EMS), which covers objectives including achieving our net zero greenhouse gas commitment, reduction in water use, reduction in waste going to landfill, creating green space, enhancing the natural environment and improving air quality. Local initiatives are in place around IBM and client’s locations, promoting e.g. shared or zero-carbon travel, various cycle-to-work and car-share initiatives/incentives as well as environmentally focused volunteering. To influence staff, suppliers, customers and communities through the delivery of the contract to support environmental protection/improvement, we include Social Responsibility and Environmental Management requirements in subcontracts and encourage staff to work with the wider teams on improvements. In some locations, an ‘Environmental Business Resource Group’ promotes Green sustainability, also through community-based activities. In 2020 IBM launched the ‘responsible.computing’ initiative, which addresses modern computing challenges and integrates aspects of sustainability, climate, ethics, openness, privacy, and security. We assess proposed technical solutions against efficient energy usage. IBM began detailed tracking and monitoring of our environmental footprint in 1990 - being forthright and transparent in our impact long before it was fashionable or required. We have made significant improvements over the last 30 years and will continue to report transparently on impacts and progress, using ‘Sustainable by Design’ framework and tools such as CO2 Emissions-Estimator and/or Envizi.

Covid-19 recovery

The COVID-19 epidemic brought an unprecedented pace of innovation. Many will attempt to manage this change through a roll-up of Excel spreadsheets submitted by each cost centre owner and aggregated and reconciled at divisional/departmental levels and then across the whole organisation. These solutions are complicated, fragile, time-consuming and prone to errors. And ultimately, they don’t give you the fidelity you need to quickly compare different cost-cutting paths, investment priorities, nor help to understand the various implications to the organisation. This cloud service is uniquely positioned to help organisations address these challenges and enable their teams to react quickly to changing needs and make real-time budgeting decisions, optimise cloud spend and help inform their decision making on what technology investments deliver the best outcomes and provide the greatest value.

Tackling economic inequality

BM invest to understand of the causes and effects of inequality. We run multiple initiatives to attempt to level opportunity, focused on our stated social-responsibility goal to support education and skills development in Science and Technology, with a specific focus on those who may not otherwise be attracted, or have the opportunity, to develop those skills. The ‘IBM Ignite’ scheme, a national Movement to Work programme, offers vocational traineeships and work experience to disadvantaged youth unemployed. Together with City Gateway, our London charity partner, IBM offer 2-week, onsite, workplace programmes to break the cycle of ‘no work experience, no job’. IBM are proud to have created skillsbuild.org. This is a global programme, and for the UK offering IBM have partnered with ACH.org.uk, a social enterprise working to resettle refugees through labour market and social integration, City Gateway, a London charity working with disadvantaged young people, women and families in deprived areas to build skills and ambition, and SaluteMyJob, a charity creating opportunities for ex-Servicemen and women under the armed forces covenant. The SkillsBuild programmes offer training, in-person support, credentials and opportunities to put the learning into practice. In addition to the direct training through charity partners, SkillsBuild is now also available free to all online. The SkillsBuild training gives recognised qualifications to those searching for employment in a digital economy. In addition, the programme gives job-search skills, teaches agile methods and design thinking, and has specific training in growing IT fields, such as cybersecurity, big data, artificial intelligence. IBM UK employ around 100 school-leaver apprentices every year. Our award-winning programme offers apprenticeships ranging from Level 3 to Level 6, with all apprentices employed as permanent employees from Day 1. We also launched Early Professional Affiliates Hiring programme enabling us to further acquire talent from underrepresented groups.

Equal opportunity

In 1942, IBM hired blind psychologist Michael Supa to create a programme for hiring and training people with disabilities. Supa then worked in IBM institutionalising disability representation and equality for 37 years, and 80 years after he was hired IBM continue to lead in Accessibility, Inclusive hiring, and Representation to reduce the disability employment gap. The Accessible Workplace Connection portal makes it easy for managers to accommodate IBMers who consider themselves to have disabilities, and all recruitment activities are accessible and open. IBM support all employees in training and developing new skills relevant to them, with at least 40 hours of structured training required every year; called THINK40. The training can link to recognised, external qualifications, building skills relevant to the contract. IBM is accommodating of those with additional needs, ensuring all training is inclusive. IBM believes that a diverse and inclusive work environment drives higher quality delivery. We have created employment/training opportunities for those with protected characteristics in the UK since 1912. Our 300+ employee-led communities support ethnic minorities, neurodiversity, LGBTQ+, females, veterans and more through regular events within their communities. Every IBMer completes regular mandatory Diversity & Inclusion training, including on unconscious bias. Based on 2022 survey nearly 9 in 10 IBMers felt comfortable being themselves at work with ~5,000 more recommending IBM as a great place to work. IBM run a “BeEqual” campaign and programmes, with tens of thousands of employees making a BeEqual pledge of allyship to colleagues from minority groups and 6000 IBMers globally are certified as LGBT+ Allies, with 90+ events across UK and Ireland in 2023 focusing on inclusion, with approximately 3.5K attendees. IBM have a culture of promotion and recruitment aiming to addresses workforce inequality for all to have the opportunity to fulfil their potential.

Wellbeing

IBM has an advanced Health and Wellbeing Programme, recognising the criticality and benefits of a healthy and supported workforce. A wide-ranging Employee Assistance Program is provided confidentially to all employees 24/7, at no cost to them, backed up by medical insurance with annual health assessments available. IBM operate a Mental Health First Aid Programme, with over 200 qualified mental health first-aiders volunteering in the UK. These colleagues make themselves approachable as a first step. IBM UK have Disability Confident Level 2 status, winning in 2023 UK-IT-Industry Award – DEI and in 2021 the Best Employer for Diversity and Inclusion award from WM UK, due to the broad focus on D&I throughout the pandemic, including hidden disabilities and neurodiversity. IBM has a global neurodiversity hiring program (ND@IBM). In the new model of home/hybrid working, various initiatives have been created to maintain and improve both mental and physical health when working remotely. The IBM Working from Home Pledge includes commitments to take time out for yourself, and to check-in regularly on colleagues. It was recognised that working alone can be challenging for some, and regular sessions, support programmes and training in place to keep people connected. Managers have undertaken training to recognise those struggling and have tools of early support. A “2020 health challenge” was taken up by 20% of the permanent employee population, with 69% of participants reported being less stressed, 74% exceeded 10,000 steps a day. We continue organising ‘Exercise challenges’ on miles walked/weight loss linked to e.g. World Heart Day. Ergonomic equipment to create a better working-from-home environment is available to all. Within projects/programmes, and as part of contract delivery, IBM seek to make these various initiatives available to joint team of staff/suppliers/customers and communities. Project and colleague-based support and health initiatives are expanded where possible to all.

Pricing

Price
£21,000 a licence a year
Discount for educational organisations
No
Free trial available
No

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at jennifer.billett@csiltd.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.