dxw

GovPress

GovPress is a secure, managed WordPress platform for the public sector. GovPress allows you to host WordPress-based sites in the cloud without worrying about security, backups, plugin updates, infrastructure management, monitoring or performance. It's secure, flexible and cost-effective - and ISO27001-certified.

Features

  • Secure, ISO-27001 service suitable for OFFICIAL-SENSITIVE information
  • Fully managed service: we deal with maintenance, updates and monitoring
  • Easy access to WordPress experts when you need help
  • EU-based hosting in the cloud, fully DPA compliant
  • Flexible, on-demand scaling according to your need
  • Cost-effective pay-as-you-use pricing
  • Easy access for your developers via git, if needed

Benefits

  • Reduced information risk: never miss an update
  • Easy access to expert help when you need it
  • Reduced costs compared to physical hosting and in-house staff
  • Wordpress's intuitive publishing experience requires minimal user training
  • Huge variety of additional functionality available via community plugins
  • Wordpress is a flexible CMS, supported by large supplier community
  • Flexible pricing: only pay for the security and capacity needed

Pricing

£350 to £3500 per unit per month

  • Minimum contract period: Month
  • Excluding VAT

Service documents

G-Cloud 8

419694345170978

dxw

Harry Metcalfe

0345 257 7520

sales@dxw.com

Support

Support
Name Content
Support service type
  • Service desk
  • Phone
  • Onsite
Support accessible to any third-party suppliers Yes
Support availability 1000-1800 for routine issues, 24/7 for emergencies
Standard support response times Varies from minutes to days, depending on severity
Incident escalation process available Yes

Open standards

Open standards
Name Content
Open standards supported and documented Yes

Onboarding and offboarding

Onboarding and offboarding
Name Content
Service onboarding process included Yes
Service offboarding process included Yes

Analytics

Analytics
Name Content
Real-time management information available Yes

Cloud features

Cloud features
Name Content
Elastic cloud approach supported No
Guaranteed resources defined Yes
Persistent storage supported Yes

Provisioning

Provisioning
Name Content
Self-service provisioning supported No
Service provisioning time From a couple of hours to a couple of days, depending on complexity
Service deprovisioning time From a couple of hours to a couple of days, depending on complexity

Open source

Open source
Name Content
Open-source software used and supported Yes

API access

API access
Name Content
API access available and supported Yes
API type XMLRPC, REST

Networks and connectivity

Networks and connectivity
Name Content
Networks the service is directly connected to Internet

Access

Access
Name Content
Supported web browsers
  • Internet Explorer 7
  • Internet Explorer 8
  • Internet Explorer 9
  • Internet Explorer 10+
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Offline working and syncing supported No
Supported devices
  • PC
  • Mac
  • Smartphone
  • Tablet

Certifications

Certifications
Name Content
Vendor certification(s) ISO27001:2015

Data storage

Data storage
Name Content
Datacentres adhere to the EU code of conduct for energy-efficient datacentres Yes
User-defined data location No
Datacentre tier TIA-942 Tier 4
Backup, disaster recovery and resilience plan in place Yes
Data extraction/removal plan in place Yes

Data-in-transit protection

Data-in-transit protection
Name Content
Data protection between user device and service TLS (HTTPS or VPN) version 1.2 or later, assured by independent testing of implementation
Data protection within service
  • TLS (HTTPS or VPN) version 1.2 or later
  • VLAN
  • No encryption
Assured by independent testing of implementation
Data protection between services TLS (HTTPS or VPN) version 1.2 or later, assured by independent testing of implementation

Asset protection and resilience

Asset protection and resilience
Name Content
Datacentre location EU, assured by independent validation of assertion
Data management location UK, assured by independent validation of assertion
Legal jurisdiction of service provider UK
Datacentre protection Yes
Data-at-rest protection Physical access control, assured by independent testing of implementation
Secure data deletion Other erasure process, assured by independent testing of implementation
Storage media disposal Other destruction/erasure process, assured by independent validation of assertion
Secure equipment disposal Yes, assured by independent validation of assertion
Redundant equipment accounts revoked Yes, assured by independent validation of assertion
Service availability 99.99

Separation between consumers

Separation between consumers
Name Content
Cloud deployment model Public cloud, assured by independent validation of assertion
Type of consumer Only government consumers, assured by independent validation of assertion
Services separation Yes, assured by independent testing of implementation
Services management separation No, assured by independent testing of implementation

Governance

Governance
Name Content
Governance framework Yes, assured by independent validation of assertion

Configuration and change management

Configuration and change management
Name Content
Configuration and change management tracking Yes, assured by independent validation of assertion
Change impact assessment Yes, assured by independent validation of assertion

Vulnerability management

Vulnerability management
Name Content
Vulnerability assessment Yes, assured by independent validation of assertion
Vulnerability monitoring Yes, assured by independent validation of assertion
Vulnerability mitigation prioritisation Yes, assured by independent validation of assertion
Vulnerability tracking Yes, assured by independent validation of assertion
Vulnerability mitigation timescales Yes, assured by independent validation of assertion

Event monitoring

Event monitoring
Name Content
Event monitoring Yes, assured by independent validation of assertion

Incident management

Incident management
Name Content
Incident management processes Yes, assured by independent validation of assertion
Consumer reporting of security incidents Yes, assured by independent validation of assertion
Security incident definition published Yes, assured by independent validation of assertion

Personnel security

Personnel security
Name Content
Personnel security checks Background checks in accordance with BS7858:2012, assured by independent validation of assertion

Secure development

Secure development
Name Content
Secure development Yes, assured by independent validation of assertion
Secure design, coding, testing and deployment Yes, assured by independent validation of assertion
Software configuration management Yes, assured by independent validation of assertion

Supply-chain security

Supply-chain security
Name Content
Visibility of data shared with third-party suppliers Yes, assured by independent validation of assertion
Third-party supplier security requirements Yes, assured by independent validation of assertion
Third-party supplier risk assessment Yes, assured by independent validation of assertion
Third-party supplier compliance monitoring No, assured by independent validation of assertion
Hardware and software verification Yes, assured by independent validation of assertion

Authentication of consumers

Authentication of consumers
Name Content
User authentication and access management Yes, assured by independent testing of implementation
User access control through support channels Yes, assured by independent testing of implementation

Separation and access control within management interfaces

Separation and access control within management interfaces
Name Content
User access control within management interfaces Yes, assured by independent testing of implementation
Administrator permissions Yes, assured by independent testing of implementation
Management interface protection Yes, assured by independent testing of implementation

Identity and authentication

Identity and authentication
Name Content
Identity and authentication controls
  • Username and two-factor authentication
  • Username and strong password/passphrase enforcement
Assured by independent testing of implementation

External interface protection

External interface protection
Name Content
Onboarding guidance provided Yes, assured by independent validation of assertion
Interconnection method provided Internet, assured by independent validation of assertion

Secure service administration

Secure service administration
Name Content
Service management model Service management via bastion hosts, assured by independent validation of assertion

Audit information provision to consumers

Audit information provision to consumers
Name Content
Audit information provided Data made available by negotiation, assured by independent validation of assertion

Secure use of the service by the customer

Secure use of the service by the customer
Name Content
Device access method
  • Corporate/enterprise devices
  • Partner devices
  • Unknown devices
Assured by independent validation of assertion
Service configuration guidance Yes, assured by independent testing of implementation
Training Yes, assured by independent validation of assertion
Return to top ↑