Gaiasoft's Beyond Overload; from too much information to actionable insight
Using G-Cloud Services to reduce information overload and improve effectiveness. Workshops and services enhance ability to access, assimilate, synthesise, and apply evidence and knowledge. Designing document templates for people and algorithms to use in evidence-based decision-making. Addresses accelerated-learning, online-speed reading, information design, instructional design, and data visualisation.
- Speed-reading to access critical information for faster learning.
- Accelerated learning to retain information for re-use.
- The 80/20 principle used in learning to learn.
- Design of information for human and algorithmic analysis.
- Checklists, templates and self-assessments to capture and re-use knowledge.
- Information-design: better document templates for M&E and learning.
- Using instructional design, multichannel content delivery and data visualisation.
- Maturity Models to codify knowledge.
- Knowledge Platforms and the Assess-Identify-Convene-Curate-Scale-up process.
- MIDIR methodology Knowledge Platforms for programmes that learn.
- Overcomes the stress of information overload.
- Expands effective “intelligence” and measurable productivity.
- Faster, more effective processing of complex information for decision-making.
- More effective people working with more effective systems.
- Cross-cutting savings from applying 80/20 principle.
- Better informed evidence-based decision making improves VfM.
- Maximise re-use and synthesis of valuable knowledge.
- Reduce cost of administration and knowledge work through streamlining.
- Plan-Do-Check-Act-Learn and Observe-Orient-Decide-Act processes.
- Build capacity, learning and synergy across complex networked organisations.
£64 per person per month
- Education pricing available
- Free trial available
1 5 3 2 1 7 2 0 9 4 1 4 8 6 3
Gaiasoft International Limited
|Software add-on or extension||No|
|Cloud deployment model||Private cloud|
|Service constraints||Requires browser access.|
|Email or online ticketing support||Email or online ticketing|
|Support response times||Four working hours|
|User can manage status and priority of support tickets||No|
|Phone support availability||9 to 5 (UK time), Monday to Friday|
|Web chat support||No|
|Onsite support||Yes, at extra cost|
Technical support and training of trainers for the configuration, administration and use of Gaiasoft Scorecard for online governance, reporting and performance management systems.
Customisation of a portfolio, programme, process and customer knowledge framework.
Customer administration and project team support.
Data visualisation/infographics design and technical implementation.
Automation of performance contract reporting for evidence based compensation.
Automation of audit reporting to minimise the cost and maximise the value of audit.
Technical integration via “API” and web services of the automation of data capture where appropriate.
|Support available to third parties||Yes|
Onboarding and offboarding
User on boarding.
Configuration of the Knowledge Base.
Integration with other systems.
|End-of-contract data extraction||
Support provides an export file in an agreed format.
An optional peppercorn option is available to ensure ongoing access without using the applications themselves.
|End-of-contract process||This is planned according to the arrangements made at the outset of the service being contracted for. Typically, an end-of-service date is agreed which triggers any data exportation arrangements. Data is then help for six weeks before deletion to allow for emergency access by the customer.|
Using the service
|Web browser interface||Yes|
|Application to install||No|
|Designed for use on mobile devices||Yes|
|Differences between the mobile and desktop service||None|
|What users can and can't do using the API||RestFull API available and Dashboard specific interface.|
|API sandbox or test environment||Yes|
|Description of customisation||Look and feel with underlying dashboard and infographic visualisation.|
|Independence of resources||The private cloud uses a Hyper-V environment in on a major infrastructure that has a substantial capacity to handle upper-quartile processing loads and bandwidth. It has a considerable burst capacity to handle unexpected peak loads and the infrastructure is self- load-balancing.|
|Service usage metrics||Yes|
Basic user and administrator logs.
|Reporting types||Reports on request|
|Supplier type||Not a reseller|
|Staff security clearance||Other security clearance|
|Government security clearance||Up to Developed Vetting (DV)|
|Knowledge of data storage and processing locations||Yes|
|Data storage and processing locations||United Kingdom|
|User control over data storage and processing locations||Yes|
|Datacentre security standards||Complies with a recognised standard (for example CSA CCM version 3.0)|
|Penetration testing frequency||At least once a year|
|Penetration testing approach||‘IT Health Check’ performed by a Tigerscheme qualified provider or a CREST-approved service provider|
|Protecting data at rest||
|Data sanitisation process||Yes|
|Data sanitisation type||Explicit overwriting of storage before reallocation|
|Equipment disposal approach||Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001|
Data importing and exporting
|Data export approach||This is handled by a query to the Knowledge Base, unless for classified materials, this is undertaken by the support function on request.|
|Data export formats||
|Other data export formats||Any contemporary format.|
|Data import formats||
|Other data import formats||Any contemporary format is usable.|
|Data protection between buyer and supplier networks||
|Data protection within supplier network||
Availability and resilience
99.995% is the SLA for availability to users.
A service credits facility is available subject to agreement.
|Approach to resilience||The data centre is located at IoMart a G-cloud recognised supplier. The centre is 'lights out' and equipped with a variety of 'fail-over' features that assure availability is consistent. In three years of operations we have not lost a single hour of user processing or access.|
|Outage reporting||Email alerts would be provided in the event of any service outage. This is by arrangement to the customer's administrators or direct to users.|
Identity and authentication
|User authentication needed||Yes|
|Access restrictions in management interfaces and support channels||Management to the support functions is strictly controlled by the use of VPN security measures, with the system's security functions kept separately from the users applications environment.|
|Access restriction testing frequency||At least every 6 months|
|Management access authentication||Dedicated link (for example VPN)|
Audit information for users
|Access to user activity audit information||Users contact the support team to get audit information|
|How long user audit data is stored for||At least 12 months|
|Access to supplier activity audit information||Users contact the support team to get audit information|
|How long supplier audit data is stored for||At least 12 months|
|How long system logs are stored for||At least 12 months|
Standards and certifications
|ISO/IEC 27001 certification||Yes|
|Who accredited the ISO/IEC 27001||FusionComply Limited|
|ISO/IEC 27001 accreditation date||March 2018|
|What the ISO/IEC 27001 doesn’t cover||None.|
|ISO 28000:2007 certification||No|
|CSA STAR certification||No|
|Other security certifications||No|
|Named board-level person responsible for service security||Yes|
|Security governance certified||Yes|
|Security governance standards||ISO/IEC 27001|
|Information security policies and processes||We have our own internal security policy that covers operations and penetration testing. A copy is available on request.|
|Configuration and change management standard||Supplier-defined controls|
|Configuration and change management approach||Software configuration is undertaken in-house and follows good industry practice within an agile methodology. Code changes and new feature provision are assessed for threat as part of the development cycles for those new features, co-ordinated with a customer's project and security teams. The infrastructure level is a fully managed service on our behalf by Hyperslice Limited under an agreed SLA. The lights-out data centre at IoMart Plc is a G-Cloud recognised supplier and provides our infrastructure under another agreed SLA.|
|Vulnerability management type||Supplier-defined controls|
|Vulnerability management approach||
In our development and operations activities we look for potential threats, vulnerabilities which could affect our services. These 'issues' are assessed at the time and corrective coding employed or preventative action taken in other areas. Relevant details on threats from a number of community resources is used to identify vulnerability and exploitation techniques are assessed. The severity of a threat to the service prioritizes the mitigation or action undertaken at the time.
The underlying nature of our service applications and their architecture means we can respond swiftly in two working days to apply a resolution to the threat or vulnerability.
|Protective monitoring type||Supplier-defined controls|
|Protective monitoring approach||Performance assurance is a function of being continuously involved with users and customer administrators. It is not an arms-length function simply awaiting requests, it is proactive in how it works to continuously improve customer performance. The applications and infrastructure generate log-events events for support to identify suspicious activity or external attacks. These events are monitored to identify potential compromises and prompt for appropriate action to resolve incidents and minimize their impact. A second level of monitoring is provided by our infrastructure managers, the two combined providing a high level of assurance in our processes and observations.|
|Incident management type||Supplier-defined controls|
|Incident management approach||
Incident management processes actively monitor security incidents, using pre-defined processes for responding to common types of incident and attack.
A defined process and contact route exists for reporting security incidents by users and customers, so we are aware of incidents in acceptable timescales and route.
|Approach to secure software development best practice||Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)|
Public sector networks
|Connection to public sector networks||No|
|Price||£64 per person per month|
|Discount for educational organisations||Yes|
|Free trial available||Yes|
|Description of free trial||We will formulate a Proof of Concept that demonstrates the principles and operations of our service. The integration of external data sources to the service is not normally included.|