Callcredit Public Sector Limited

CAMEO

CAMEO helps understand customers in terms of their: Demographics – age, gender, lifestage, education, occupation; Affluence – income, property value, spending, risk; Lifestyle and media - hobbies, interests, holidays, brand affinities; Credit Behaviours - Payday loans, Credit sophistication; Property characteristics - Tenure, Property type, Floor space/no. of bedrooms, on-the-market.

Features

  • Available as standalone UK postcode directories or data append service
  • The widest range of data sources in the market place
  • Interactive microsite provides detailed insight on each CAMEO UK segment
  • Available in MVPLUS to profile and visualise the data spatially
  • CAMEO available at postcode, household and individual level
  • Available with full consultancy support

Benefits

  • Understand the characteristics of your local community and residents
  • Understand ability and attitudes i.e. technology usage or financial literacy
  • Establish household composition, ethnicity, educational attainment level and age profile
  • Map wider trends
  • Personalise your campaigns and strategies
  • Select the right channel/message to improve costs and results
  • Aid local planning

Pricing

£20000 per licence per year

Service documents

G-Cloud 10

167959804158833

Callcredit Public Sector Limited

Mark Pestereff

0777 321 2093

Mark.Pestereff@callcreditgroup.com

Service scope

Service scope
Software add-on or extension Yes, but can also be used as a standalone service
What software services is the service an extension to MVPlus
Cloud deployment model Private cloud
Service constraints No
System requirements Not applicable, data solution

User support

User support
Email or online ticketing support Email or online ticketing
Support response times Acknowledgement response time is within 30 minutes. However, please refer to contract for full details of service levels.
User can manage status and priority of support tickets No
Phone support Yes
Phone support availability 9 to 5 (UK time), Monday to Friday
Web chat support No
Onsite support Onsite support
Support levels As agreed in the contract at the time of purchase.
Support available to third parties Yes

Onboarding and offboarding

Onboarding and offboarding
Getting started Documentation and training will be provided on the CAMEO data variables.
Service documentation Yes
Documentation formats
  • PDF
  • Other
Other documentation formats
  • Word
  • Excel
End-of-contract data extraction Not applicable
End-of-contract process Callcredit data would be deleted by end user.

Using the service

Using the service
Web browser interface No
Application to install No
Designed for use on mobile devices No
Accessibility standards None or don’t know
Description of accessibility Data will be either be delivered via postcode directories (as a flat file) or via a data append/Data profiling service.
Accessibility testing Not applicable
API No
Customisation available No

Scaling

Scaling
Independence of resources Not applicable

Analytics

Analytics
Service usage metrics No

Resellers

Resellers
Supplier type Not a reseller

Staff security

Staff security
Staff security clearance Conforms to BS7858:2012
Government security clearance Up to Developed Vetting (DV)

Asset protection

Asset protection
Knowledge of data storage and processing locations Yes
Data storage and processing locations United Kingdom
User control over data storage and processing locations Yes
Datacentre security standards Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency At least once a year
Penetration testing approach ‘IT Health Check’ performed by a Tigerscheme qualified provider or a CREST-approved service provider
Protecting data at rest
  • Encryption of all physical media
  • Other
Other data at rest protection approach Strong logical access control. Access is given based on least privilege and a need to know basis.
Protective monitoring and event management using LogRhythm as a SIEM
Sourcefire & Palo Alto IDS
Checkpoint firewalls
Monthly vulnerability scanning program of work
ISO27001 and PCI DSS compliant
Data sanitisation process Yes
Data sanitisation type Explicit overwriting of storage before reallocation
Equipment disposal approach A third-party destruction service

Data importing and exporting

Data importing and exporting
Data export approach Not applicable
Data export formats
  • CSV
  • Other
Other data export formats
  • Text files
  • Delimited Files
Data import formats
  • CSV
  • Other
Other data import formats
  • Text files
  • Delimited Files

Data-in-transit protection

Data-in-transit protection
Data protection between buyer and supplier networks Other
Other protection between networks Not applicable
Data protection within supplier network Other
Other protection within supplier network Strong logical access control. Access is given based on least privilege and a need to know basis.
Protective monitoring and event management using LogRhythm as a SIEM
Sourcefire & Palo Alto IDS
Checkpoint firewalls
Monthly vulnerability scanning program of work
ISO27001 and PCI DSS compliant

Availability and resilience

Availability and resilience
Guaranteed availability Not applicable
Approach to resilience Not applicable
Outage reporting Not applicable

Identity and authentication

Identity and authentication
User authentication needed Yes
User authentication
  • 2-factor authentication
  • Other
Other user authentication Each user will have a unique username and password along with company name. Callcredit also utilise the control of IP white listing and 24/7 security monitoring.
Access restrictions in management interfaces and support channels A policy of least privilege access is applied across the Group to ensure employees only have access to what is required, which is regularly reviewed. Any privileged accounts are rigorously checked both prior to granting access, during use and on termination of permissions. Users come under multiple levels of policy regarding accounts and device usage. Networks are highly segmented with monitoring for inter-segment violations. Any sensitive systems are housed in dedicated secure environments.
Access restriction testing frequency At least once a year
Management access authentication 2-factor authentication

Audit information for users

Audit information for users
Access to user activity audit information Users have access to real-time audit information
How long user audit data is stored for User-defined
Access to supplier activity audit information Users have access to real-time audit information
How long supplier audit data is stored for User-defined
How long system logs are stored for User-defined

Standards and certifications

Standards and certifications
ISO/IEC 27001 certification Yes
Who accredited the ISO/IEC 27001 BSI
ISO/IEC 27001 accreditation date 29/05/2015
What the ISO/IEC 27001 doesn’t cover Nothing is out of scope
ISO 28000:2007 certification No
CSA STAR certification No
PCI certification Yes
Who accredited the PCI DSS certification Risk x
PCI DSS accreditation date 08/11/2017
What the PCI DSS doesn’t cover Any area that does not have card data going through it.
Other security certifications Yes
Any other security certifications
  • ISO20000
  • ISO27001
  • ISO9001

Security governance

Security governance
Named board-level person responsible for service security Yes
Security governance certified Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards ISO9001
Information security policies and processes Security Governance is driven from top down from the COO to the Group Security Director following industry standards such as ISO27001 and PCI DSS.

All policies and processes required for ISO27001.

Operational security

Operational security
Configuration and change management standard Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Configuration and change management approach We have a designated change management team in place and certified to ISO20000.
Vulnerability management type Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Vulnerability management approach Monthly vulnerability scanning process
Protective monitoring type Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Protective monitoring approach 24/7 monitoring by SoC team using LogRhythm SIEM technology
Incident management type Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
Incident management approach Aligned to ISO27001 and ISO2000

Secure development

Secure development
Approach to secure software development best practice Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)

Public sector networks

Public sector networks
Connection to public sector networks No

Pricing

Pricing
Price £20000 per licence per year
Discount for educational organisations No
Free trial available No

Documents

Documents
Pricing document View uploaded document
Skills Framework for the Information Age rate card View uploaded document
Service definition document View uploaded document
Terms and conditions document View uploaded document
Return to top ↑