Knowledge Management Systems
Skotkonung KMS is an end-to-end project, personnel, assets and organisational management solution. The Cloud KMS modules facilitate secure information sharing; geospatial mapping; data aggregation, analysis and visualisation; reporting; incident tracking and risk management. Granular access controls and customisable workflows ensure appropriate information flows to support inter-/intra-organisational collaboration and learning.
Features
- Intuitive UI with customisable dashboards and metrics
- Data visualisation and analytics for strategic decision making
- Supports codified data aggregation, analysis and reporting
- Custom ERP and financial software integrations (CostPoint, Xero, Dynamics, Netsuite)
- Geo-spatial mapping, geo-tagged reporting and infographic data representations
- Manage projects, organisations, assets and stakeholders
- Custom interactive reporting through workflows and role-based information dissemination
- Centralised user access and security management
- Accountable management of projects, budgets, assets, tasks and risks
- Additional modules enable procurement & logistics, human resources and vetting
Benefits
- Enables knowledge and learning for effective, flexible and adaptable interventions
- Collaborative workspace to enable quick data find and export
- Assured data repository for digital continuity and full audit trail
- Modular design for scalability and value for money
- Provides real-time verified data for adaptive management and informed decision-making
- Role-based access limits export capability to protect client intellectual property
- Track progress, challenges and atmospherics to deliver effective implementation
- Supports GDPR compliant data management, retention and security
- Tailored integration management for assured data aggregation, reporting and analysis
Pricing
£2,000 a licence a month
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 12
Service ID
3 5 8 8 8 0 6 0 3 9 8 6 1 6 0
Contact
Skotkonung Ltd
Skotkonung
Telephone: +44(0) 33 0088 3933
Email: tenders@skotkonung.com
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Skotkonung Project Dashboards, DeployAdviser and Information Hubs
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- Maintenance is planned in advance (normally to take place between 8pm and 6am) and users are advised of disruption (normally with 48hr notice).
- System requirements
-
- Internet connection and browser
- Service is designed to work on a tablet/laptop/desktop
- Screens will render on a mobile device
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- The help desk is available 09:00 to 17:00 on UK business days. We respond to high priority issues within four working hours. Medium priority within one business day. Low priority as agreed with the Customer on receipt of a service request.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Support level is tailored to client needs and is normally set out in full in a service level agreement with the client. We provide single point of contact for technical support, finance and management. We provide a 24hr monitored single email address for all technical issues and run server monitoring on all client servers to flag connectivity and other issues. We can provide further details on request.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Clients are assigned an account manager. The account manager will organise system setup and initial configuration; managing data migration (subject to additional charge if data is not in ready to import format); setting up initial admin/user accounts; preparing training materials (as agreed with the client) and setting up training for client administrators (and if required users). Copies of training materials (videos, manuals etc.) will be provided to the client to share with new users.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
-
Data export is provided at the end of service as follows:
For database dump provided in MS-SQL export or flat file CSV format.
For documents in the database/library these are provided in zip files containing documents in original format.
For specific data tables from the database these could be provided in MS-Excel worksheets or flat file CSV format. - End-of-contract process
- Based on an agreed end-of-service date, we can provide a copy of the data as described above. We can hold the data for an agreed period, not exceeding one month (or as agreed with the client), and then delete all the data (unless we are legally required to retain it).
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Internet Explorer 10
- Internet Explorer 11
- Microsoft Edge
- Firefox
- Chrome
- Safari 9+
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Pages reformat depending on the size of the device screen.
- Service interface
- No
- API
- No
- Customisation available
- Yes
- Description of customisation
- Knowledge Management Systems are highly customisable, depending on client needs. This is part of setup and on-boarding users.
Scaling
- Independence of resources
- We use Microsoft Azure Cloud servers that scale on real-time demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Metrics are configured depending on client needs. This is part of setup and on-boarding users.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2012
- Government security clearance
- Up to Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 3.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v3.0
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Data sanitisation type
- Explicit overwriting of storage before reallocation
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
- Data export is based on permissions granted for each user and client customisable outputs (to be agreed with client during on-boarding). Data is downloadable in various formats such as PDF reports, MS-Excel Tables and flat file CSVs, via the user interface.
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- HTML
- PNG
- Excel
- Word
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- Word
- Excel
- PNG
- JPEG
- MSG
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- Only named administrators have access to customer databases. Sensitive data for government services can only be accessed by SC cleared personnel.
Availability and resilience
- Guaranteed availability
- 99.5% uptime.
- Approach to resilience
- Available on request.
- Outage reporting
- A public dashboard is used to report outages and email alerts to administrators as required. Planned outages are notified to users via email alerts and or system announcements.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- 2-factor authentication
- Username or password
- Other
- Other user authentication
- Access is restricted to named users and user accounts are subject to strong password policies. Two-factor authentication is enabled.
- Access restrictions in management interfaces and support channels
- Access is restricted to named users and user accounts are subject to strong password policies. 2 Factor Authentication, and validated IP connections.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- 2-factor authentication
- Dedicated link (for example VPN)
- Username or password
- Other
- Description of management access authentication
- Access is restricted to named users and user accounts are subject to strong password policies. Two-factor authentication is enabled.
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Approachable Certification
- ISO/IEC 27001 accreditation date
- 26/09/2017
- What the ISO/IEC 27001 doesn’t cover
- ISO 27001 certification covers all aspects of this service. Details of scope are available on request.
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Other security certifications
- No
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- ISO 9001
- Information security policies and processes
- We have fully documented information security policies. A copy is available on request.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We have internal processes for change control that includes a full cycle of testing and audit from development to production release. Changes are assessed at time of request for security implications and if necessary additional testing or external verification is completed prior to production release. These processes are documented and comply with our ISO 9001 and 27001 quality systems.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Available on request.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Available on request.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Available on request.
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Price
- £2,000 a licence a month
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Proof of concept service giving users an opportunity to test on a small data set (provided by client or if requested by us). Trial period is negotiable but not to exceed 6 weeks. Please contact us to discuss further.