Oracle@GCP
Managed Oracle on Google Cloud Platform (GCP) PaaS. Full cloud hosting for Oracle database workloads on GCP infrastructure. Provides high-performance, secure, and scalable hybrid cloud environments. Includes migration, deployment, database administration, and 24/7 support. Maximise GCP benefits for your essential Oracle applications.
Features
- Oracle Database migration and lift-and-shift to GCP.
- High-performance, scalable IaaS and PaaS for Oracle workloads.
- Managed database administration; patching, backup, and recovery.
- 24/7/365 proactive support and SLA-backed service.
- Optimised architecture for Oracle licensing on Google Cloud.
- Secure, resilient hybrid cloud setup with dedicated interconnect.
- FinOps consultancy and cost optimisation for GCP resources.
- Automation and orchestration using Terraform and Cloud Foundation.
- Disaster recovery (DR) and business continuity planning for Oracle.
- Security compliance and governance for public sector standards.
Benefits
- Guaranteed high-availability and resilience for mission-critical Oracle.
- Achieve maximum cost optimisation via unified GCP billing.
- Seamless integration with GCP AI and Data Analytics tools.
- Accelerated cloud migration with minimal downtime and risk.
- Simplified hybrid cloud management and single vendor accountability.
- Full compliance with UK public sector security standards.
- Reduced operational overhead using fully managed PaaS services.
- Leverage existing Oracle licensing investment on GCP infrastructure.
- Rapid scaling of database resources to meet demand surges.
- Enhanced security using Google Cloud's secure global network.
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 9 1 5 5 7 6 4 0 0 4 4 4 4 8
Contact
DATABASE SERVICE PROVIDER GLOBAL LTD
Matthew Allsop
Telephone: +44 (0) 203 880 1686
Email: enquiries@dsp.co.uk
About your service
- Service categories
-
PaaS
Data Management
- Database management systems
- Databases
- Database administration and development
- Data integration and intelligence
Service scope
- Service constraints
- No such constraints
- System requirements
-
- Bring your own license (BYOL)
- Anti-Virus
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
User support
- Email or online ticketing support
- Yes
- Support response times
- The following defines the measured service levels, incident and problem resolution raised within the contracted hours of service. Priority 1 - 100% within 30 minutes Priority 2 - 100% within 60 minutes Priority 3 - 100% within 4 Hours Priority 4 - No levels required. P1 are 24x7 and P2 to P3 are UK business hours which can be logged out of UK business hours however the SLA will not commence until 08:30 the following working day.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- EN 301 549
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
DSP provides tiered support across infrastructure, database and cloud environments. Our service levels range from Reactive to Comprehensive Managed Services, with the volume and frequency of support increasing as you move up the spectrum.
Support depth is tailored to the environment's criticality. For example, production environments receive more intensive coverage than test or development tiers. To guarantee service excellence, we assign dedicated Account and Service Delivery Managers to ensure the highest levels of focus and performance at all times. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We introduce our colleagues to our onboarding process via the Transition team. This includes a number of regular calls and meetings as well as sharing initial documentation about the service and transition process.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
- Usually there is no real data that an exiting customer needs to extract, but this can be requested and transferred during the off-boarding process if needed.
- End-of-contract process
- A standard off-boarding procedure is carried out when a contract comes to an end. This is worked through closely with the customer.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Delivered via Transition Team.
Using the service
- Web browser interface
- Yes
- Using the web interface
- For Public Cloud users, will be able to perform end-to-end administration from the Cloud portal in relation to the agreement with DSP and its CMSP
- Web interface accessibility standard
- EN 301 549
- Web interface accessibility testing
- None
- API
- Yes
- What users can and can't do using the API
- Users can interact with APIs to provision, manage and update configurations of Cloud resources. The API supports REST via a number of different client libraries such as .NET, Java, Node.js, Python, Go, C++ and Rust. There are no limitations for Public, Hybrid and Private Cloud; limitations are subject to the solutions that are provisioned.
- API automation tools
-
- Ansible
- Chef
- OpenStack
- SaltStack
- Terraform
- Puppet
- Other
- API documentation
- Yes
- API documentation formats
- HTML
- Command line interface
- Yes
- Command line interface compatibility
-
- Linux or Unix
- Windows
- Using the command line interface
- Users can use a CLI for the administration of the environment. Standard installation documents for the CLI will be provided on service commencement. There are no limitations on the service for the CLI.
Scaling
- Independence of resources
- All workloads are logically separated with independent scaling and sizing specifications.
- Usage notifications
- Yes
- Usage reporting
- Optimising consumption
- Yes
- Automatic scaling
- Yes
Analytics
- Infrastructure or application metrics
- Yes
- Metrics types
-
- CPU
- Disk
- HTTP request and response status
- Memory
- Network
- Number of active instances
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Oracle, Microsoft, Google Cloud Platform (GCP), Amazon Web Services (AWS)
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Data Erasure
Backup and recovery
- What’s backed up
-
- Storage (Object, File, Block, Boot)
- Virtual Machines
- Databases
- Code Repositories
- PaaS Services
- IaaS Services
- Backup controls
- All services have configurable backups which can be modified from our standard best practice recommendations.
- Datacentre setup
-
- Multiple datacentres with disaster recovery
- Multiple datacentres
- Single datacentre with multiple copies
- Scheduling backups
- Users schedule backups through a web interface
- Backup recovery
-
- Users can recover backups themselves, for example through a web interface
- Users contact the support team
- Backup and recovery
- Yes
- RPO/RTO
- Yes
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
Availability and resilience
- Guaranteed availability
- Our SLAs will align to the Public Cloud provider of choice
- Approach to resilience
- Available on request.
- Outage reporting
- Public dashboard and email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Access is restricted to users who have completed and approved an onboarding process with DSP.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Devices users manage the service through
-
- Dedicated device on a segregated network (providers own provision)
- Dedicated device on a government network (for example PSN)
- Dedicated device over multiple services or networks
- Any device but through a bastion host (a bastion host is a server that provides access to a private network from an external network such as the internet)
- Directly from any device which may also be used for normal business (for example web browsing or viewing external email)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- Less than 1 month
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
UK Cyber Essentials
UK Cyber Essentials Plus - Information security policies and processes
-
As DSP follows all ISO 27001 requirements and controls, the policies and processes reflect those: Generative AI Tools Usage Policy, Information Security Policy, Asset Management Policy, Acceptable Use Policy, Remote Working Policy, Company Device Usage Policy, Clear Desk & Clear Screen Policy, Change Management Policy, Data Protection Policy, Privacy Notice to Staff, Secure Development Policy, Third Party Management Policy, Quality Manual, Quality Policy, Access Control Policy, Anti Bribery and Corruption, Data Breach Response Plan, Environmental and Sustainability Policy, Information Security Incident Management Policy, Risk Management Policy, Information Transfer Policy, Passwords Policy, Business Continuity Plan, Disaster Recovery and Backups Policy, Company Hardware Policy, Anti-Malware Policy, Logging and Monitoring Policy, Operational Procedures, Threat, Vulnerability and Patch Management Policy, Configuration Management, Information Classification and Retention Schedule, IMS-05 Corrective Action and Continual Improvement SOP, IMS-04 Management Review SOP, IMS-03 Internal Audits SOP, IMS-02 Document Control SOP, IMS-01 Roles, Responsibilities and Authorities, Information Classification and Handling Policy, Cryptography Policy, Physical Security Policy, ISMS-01 Scope of the ISMS, Access Control Standard, Information Governance and Management Framework, Risk Assessment for Information Security, IMS-00 List of Documents.
Our Information Security Manager reports to the Deputy COO that has a direct line to the COO, followed by the CEO.
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- DSP has a configuration policy and a change management policy (covers security and privacy risk assessment). For more details, please get in touch.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- DSP has a threat, vulnerability and patch management policy that defines patching timelines in line with criticality assessment (e.g. critical 1-7 days) and threat intelligence, objectives and sources (e.g. Microsoft Defender for Endpoint, ENISA Threat Landscape, SANS NewsBites, Microsoft Intelligence Reports). Annually, DSP runs a Business Impact Analysis.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We use Microsoft Defender for Endpoint and staff reporting to detect threats, managed by our team via an Incident Management Policy covering detection, triage, investigation, containment, remediation, recovery, and post-incident review. Our SLAs are: Severity 1 (100% response within 30m, 99% resolution within 4h), Severity 2 (60m response, 8h resolution), and Severity 3 (4h response, 12h resolution).
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- DSP has an incident management and major incident management process. Internally, users report incidents to the helpdesk. Externally, customers report incidents via the ITSM tool or call support. Incident reports are provided via tickets to the standard template or a customer template. DSP has knowledge articles on certain types of service issues.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Separation between users
- Virtualisation technology used to keep applications and users sharing the same infrastructure apart
- Yes
- Who implements virtualisation
- Third-party
- Third-party virtualisation provider
- Azure or Oracle
- How shared infrastructure is kept separate
- Organisations sharing the same Public Cloud are kept separate through logical segregation of subscriptions, networks and tenancies.
Energy efficiency
- Energy-efficient datacentres
- Yes
- Description of energy efficient datacentres
- Further information available on request.
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount
- Provide your minimum discount applicable to your baseline prices
- 5%
Formula for calculating price of your services
- Formula for calculating price of your services
-
Which of the core deployment models you intend to offer
- Public Cloud
- Private Cloud
Public Cloud - Formula for calculating price of your services
- Total Cost
- The Total Cost for a buyer's call off requirement in a Public Cloud Deployment
- =
- Baseline Pricing
-
DSP will technically qualify the design and solution with the customer to dictate the IAAS and PAAS costs from the chosen Cloud Software Vendor.
Once the final bill of materials has been agreed, DSP will give transparency on these costs and agree associated services which would be delivered under an associated Rate Card - Baseline Pricing - Web link
- https://www.oracle.com/uk/cloud/price-list/
- -
- Minimum Discounting
- 5%
- +
- Onboarding Activity
- Onboarding costs may vary based on your specific requirements, please confirm with suppliers during the clarification process
- +
- Additional sources of cost
- As previously stated, DSP do not plan to increase costs for our committed contracts and will honour these for the term of service subject to the price certainty clause and provision within.
- -
- Additional sources of cost reduction
- Multi-year and sector-specific strategies can reduce costs by stabilising cloud prices and leveraging volume benefits, making them essential for sustainable financial planning for IaaS and PaaS solutions. DSP cost-decreasing factors extend beyond simple discounting for multi-year agreements, however, and are driven by operational and design/architecture efficiencies, plus actual data-driven consumption analysis and optimisation, e.g., Right-sizing of Compute & Storage.
Private Cloud - Formula for calculating price of your services
- Total Cost
- The Total Cost for a buyer's call off requirement in a Private Cloud Deployment
- =
- Baseline Pricing
-
DSP will technically qualify the design and solution with the customer and this will include IAAS and PAAS costs from the chosen Cloud Software Vendor.
Once the final bill of materials has been agreed, DSP will give transparency on these costs and agree Cloud Support Services based on a fixed % margin. - -
- Minimum Discounting
- 5%
- +
- Onboarding Activity
- Onboarding costs may vary based on your specific requirements, please confirm with suppliers during the clarification process
- +
- Additional sources of cost
- As previously stated, DSP do not plan to increase costs for our committed contracts and will honour these for the term of service subject to the price certainty clause and provision within.
- -
- Additional sources of cost reduction
-
Multi-year and sector-specific strategies can reduce costs by stabilising cloud prices and leveraging volume benefits, making them essential for sustainable financial planning for IaaS and PaaS solutions.
DSP cost-decreasing factors extend beyond simple discounting for multi-year agreements, however, and are driven by operational and design/architecture efficiencies, plus actual data-driven consumption analysis and optimisation, e.g., Right-sizing of Compute & Storage.
Mandatory certifications
- Mandatory certifications
-
Are you are bidding to offer IaaS and/or PaaS as a reseller or are you in sole control of the infrastructure
ResellerCloud service suppliers you intend to resell with evidence
Organisation 1
Organisation name
Oracle CorporationWebsite address/upload for organisation
UploadUpload
ProvidedOrganisation 2
Organisation name
MicrosoftWebsite address/upload for organisation
UploadUpload
ProvidedOrganisation 3
Organisation name
GoogleWebsite address/upload for organisation
Website addressWebsite address
https://cloud.google.com/find-a-partner/partner/dsp-explorerISO 9001 certification
ProvidedISO 27001 certification
ProvidedISO 20000-1 certification
ProvidedAre you reliant on the Cloud Service Provider for some accreditations
Yes
Cyber Essentials
- Do you have a Cyber Essentials Plus certificate?
- Yes
- Cyber Essentials Plus certificate Number
- 135c1e7a-f330-4751-8d3c-38e822b083bb
Non-mandatory Standards and certifications
- ISO 28000:2022 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-