LEAN ACCELERATE CONSULTANCY LTD
Infrastructure provisioning and platform security
Provisioning cloud infrastructure.
Embedding security in the cloud infrastructure.
Automated security checks in the cloud infrastructure.
Automated compliance checks in the cloud infrastructure.
Automated report generation, auto-remediation.
Features
- Infrastructure as code
- Continuous integration, Continuous delivery, and Continuous deployment
- Automated security checks
- Automated compliance check
- Auto healing feature
- Automated report generation
- Test driven development
- Behaviour driven development
- Agile delivery
- Monitoring and alert solution
Benefits
- You get an early security testing in the delivery pipeline.
- You get an early compliance testing in the delivery pipeline.
- You get a trackable velocity based agile delivery
- You get monitoring capability from mobile devices
- You get automated phone call alert for serious incidents.
- You get visibility of reports.
- You get a resilient, scalable, available, and secure system.
- You get BAU activities supported by us.
Pricing
£795 to £1,195 a person a day
- Education pricing available
Service documents
Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format,
email the supplier at info@leanaccelerate.com.
Tell them what format you need. It will help if you say what assistive technology you use.
Framework
G-Cloud 12
Service ID
5 1 9 1 1 6 7 5 6 2 5 8 0 9 3
Contact
LEAN ACCELERATE CONSULTANCY LTD
Theo Sweeny
Telephone: 07951432398
Email: info@leanaccelerate.com
Service scope
- Service constraints
- We provide you with various solutions and it's cost. You can choose the solution based on your budget.
- System requirements
-
- Amazon AWS account
- Google GCP account
- Microsoft Azure account
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- For production infrastructure, you get weekend support.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support
- Web chat
- Web chat support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Through online.
- Web chat accessibility testing
- N/A
- Onsite support
- Onsite support
- Support levels
- You get a dedicated cloud support engineer available to assist onsite.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- You get documentation, onsite training, online training, and video tutorials.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- All the information and data are stored in your accounts and devices. As contract ends all the information and data reside with you.
- End-of-contract process
- You get 2 months of hand over period. During that handover, you get final documentation, training, and coaching.
Using the service
- Web browser interface
- Yes
- Using the web interface
- Standard cloud console
- Web interface accessibility standard
- None or don’t know
- How the web interface is accessible
- N/A
- Web interface accessibility testing
- N/A
- API
- Yes
- What users can and can't do using the API
- User can authenticate, authorize and access the API
- API automation tools
-
- Ansible
- Chef
- Terraform
- Puppet
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- ODF
- Command line interface
- Yes
- Command line interface compatibility
-
- Linux or Unix
- Windows
- MacOS
- Using the command line interface
- You can use the necessary command-line interface commands.
Scaling
- Scaling available
- Yes
- Scaling type
-
- Automatic
- Manual
- Independence of resources
- Architecting the stateless application to increase high availability and scalability.
- Usage notifications
- Yes
- Usage reporting
-
- API
- SMS
- Other
Analytics
- Infrastructure or application metrics
- Yes
- Metrics types
-
- CPU
- Disk
- HTTP request and response status
- Memory
- Network
- Number of active instances
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- AWS, GCP, Azure, CloudChekr, Fugue, AppCheck, Afi,
Staff security
- Staff security clearance
- Conforms to BS7858:2012
- Government security clearance
- Up to Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 3.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v3.0
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Data sanitisation type
-
- Explicit overwriting of storage before reallocation
- Deleted data can’t be directly accessed
- Equipment disposal approach
- A third-party destruction service
Backup and recovery
- Backup and recovery
- Yes
- What’s backed up
-
- You get automated backup of source code repository.
- You get automated backup of files.
- You get automated backup of databases.
- You get automated backup of machine images.
- You get automated backup of container images.
- You get automated backup of documentation.
- Backup controls
- Scheduled backups with redundancy. You can provide any specific backup to take and the frequency to take.
- Datacentre setup
-
- Multiple datacentres with disaster recovery
- Multiple datacentres
- Single datacentre with multiple copies
- Single datacentre
- Scheduling backups
- Users schedule backups through a web interface
- Backup recovery
-
- Users can recover backups themselves, for example through a web interface
- Users contact the support team
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
Availability and resilience
- Guaranteed availability
- You get the same availability as the cloud provider gives. When availability is not met, you get paid back as per the contract.
- Approach to resilience
- You get a well-designed architecture which introduces resilience, redundancy. Details are available on request.
- Outage reporting
- An online dashboard, alerting mechanism, notification mechanism.
Identity and authentication
- User authentication
-
- 2-factor authentication
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google apps)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
-
Single Sign-On integrated with Active Directory,
Multi factor authentication. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- 2-factor authentication
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Devices users manage the service through
-
- Dedicated device on a segregated network (providers own provision)
- Dedicated device on a government network (for example PSN)
- Dedicated device over multiple services or networks
- Any device but through a bastion host (a bastion host is a server that provides access to a private network from an external network such as the internet)
- Directly from any device which may also be used for normal business (for example web browsing or viewing external email)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Other security certifications
- No
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- You get the security guidelines and regulatory compliance implemented to ensure the governance.
- Information security policies and processes
- We have a detailed information security policy and process. You get them on request.
Operational security
- Configuration and change management standard
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Configuration and change management approach
- Recording the commit history, configuration changes gathered in logs.
- Vulnerability management type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Vulnerability management approach
-
An automated vulnerability assessment tool.
After assessing the patches applying them without impacting the availability.
Patch update and potential threat alert and subscription. - Protective monitoring type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Protective monitoring approach
-
Identifying potential compromises through an automated alert mechanism.
Auto remediation or manual correction. - Incident management type
- Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
- Incident management approach
-
Using ITSM tool for incident management.
User can report incidents manually. Also, the systems can auto-generate the incidents in the ITSM tool.
Scheduled incident report email can be provided.
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)
Separation between users
- Virtualisation technology used to keep applications and users sharing the same infrastructure apart
- Yes
- Who implements virtualisation
- Supplier
- Virtualisation technologies used
- Hyper-V
- How shared infrastructure is kept separate
- You get a separation of concerns in infrastructure based on your need. It could be from a dedicated host, dedicated infrastructure to bare metal servers. Details are available on request.
Energy efficiency
- Energy-efficient datacentres
- Yes
- Description of energy efficient datacentres
- The clouds AWS, Azure, GCP handles the code of conduct for energy-efficient data centres.
Pricing
- Price
- £795 to £1,195 a person a day
- Discount for educational organisations
- Yes
- Free trial available
- No
Service documents
Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format,
email the supplier at info@leanaccelerate.com.
Tell them what format you need. It will help if you say what assistive technology you use.