Tekwurx Limited

BMC Helix Cloud Security on AWS

BMC Helix Cloud Security automates cloud resource configuration testing and remediation, so that cloud services and containers configurations are managed consistently, securely, and with an audit trail. Because it is SaaS, there is nothing to install. You can begin automating the management of your cloud security in minutes.

Features

  • Automated cloud configuration security posture management (CSPM)
  • Automated remediation via a point-and-click UI
  • Ready-to-use policy packs for CIS, PCI, and GDPR
  • Full-stack container security
  • Intelligent security insights including Blast Radius
  • Integration with incident & change management (TrueSight Orchestration required)

Benefits

  • Consistent, secure configuration of PaaS and IaaS services
  • Automation rapidly closes security gaps due to misconfigurations
  • Manage cloud security posture across AWS, Azure, and Google Cloud
  • Configurable frequency of security and compliance checks by cloud environment
  • Exception management and notifications
  • Get started in under 5 minutes

Pricing

£2.80 a device a month

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at keith@tekwurx.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 12

Service ID

5 5 3 7 1 0 1 5 9 3 0 1 1 9 7

Contact

Tekwurx Limited Keith Pound
Telephone: +44 208 148 3717
Email: keith@tekwurx.com

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
None
System requirements
  • Google Chrome browser
  • Cloud Service Provider (CSP) account credentials (keys)
  • - Java OpenJDK 11.0.2
  • - 10 MB disk space, for logging

User support

Email or online ticketing support
Email or online ticketing
Support response times
Response times for requests are based on severity: P1 — 15 mins, P2 — 30 mins, P3 — 4 business hours, P4 — 16 business hours. Tekwurx provides annual support to suit a customer's requirements.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
BMC provides Support via Web, Email and Phone. Initial Response goals are relative to the impact of the reported problem on the customer environment. S1: 15 clock minutes S2: 30 business minutes S3: 4 business hours S4: 16 business hours Tekwurx can provide additional support as costed options
Support available to third parties
Yes

Onboarding and offboarding

Getting started
There are just four simple steps to quickly begin realising value by managing cloud usage and costs.

1. Connect
2. Scan
3. Assess
4. Remediate

Tekwurx has extensive experience in architecting and deploying BMC Sofware solutions. We focus on delivering the highest quality project for each and every client.

A typical engagement consists of:

- Initial discussion to understand the basic requirements
- Review the “as-is”
- Follow-up discussion to clarify details and agree on the scope and estimated project fees
- Deliver an in-depth workshop to better understand the details, develop the design and agree on all major elements of the project deliverables
- Produce the architecture design
- Deploy agreed design
- Undertake UAT testing and production deployment
- Create build and configuration documentation
- Provide knowledge transfer and training sessions
- Work with the customer on initial BAU remediation activities
- Provide on-going support
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
  • Other
Other documentation formats
  • Tekwurx will provide build documentation in the customer's required format
  • Microsoft Word
End-of-contract data extraction
Upon written request by Customer made within 45 days after the effective date of termination, BMC will make the Customer Data available to Customer for retrieval in an industry-standard format. After such 45-day period, BMC shall have no obligation to maintain any Customer Data and will thereafter delete Customer Data
End-of-contract process
Upon termination or expiration, all rights and licenses will terminate and the customer will make no further use of the services. No termination will relieve the customer of the obligation to pay any fees accrued or payable to BMC pursuant to any order. Upon written request by the customer made within 45 days after the effective date of termination, BMC will make the Customer Content available for retrieval in an industry-standard format. After such 45-day period, BMC shall have no obligation to maintain any Customer Content and will thereafter delete Customer Content

Using the service

Web browser interface
Yes
Supported browsers
Chrome
Application to install
No
Designed for use on mobile devices
No
Service interface
No
API
No
Customisation available
No

Scaling

Independence of resources
Refer to AWS

Analytics

Service usage metrics
Yes
Metrics types
The statistics and reporting utilities generate and display various statistics.

By including a utility command in the command line of a job processing definition, you can run the utility at a predetermined time or under a predetermined set of conditions without being present.
Reporting types
  • Real-time dashboards
  • Regular reports

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
BMC Software

Staff security

Staff security clearance
Other security clearance
Government security clearance
Up to Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
At least every 6 months
Penetration testing approach
In-house
Protecting data at rest
Other
Other data at rest protection approach
This is a function of the Cloud provider
Data sanitisation process
No
Equipment disposal approach
In-house destruction process

Data importing and exporting

Data export approach
TBA
Data export formats
  • CSV
  • Other
Other data export formats
PDF
Data import formats
Other
Other data import formats
  • Amazon Web Services connector
  • Microsoft Azure cloud connector
  • Google Cloud Platform connector
  • Java-based custom connector

Data-in-transit protection

Data protection between buyer and supplier networks
Private network or public sector network
Data protection within supplier network
Other
Other protection within supplier network
Not applicable

Availability and resilience

Guaranteed availability
This is a function of the Cloud provider
Approach to resilience
This is a function of the Cloud provider
Outage reporting
This is a function of the Cloud provider https://trust.onbmc.com/trustsite/index.php

Identity and authentication

User authentication needed
Yes
User authentication
Username or password
Access restrictions in management interfaces and support channels
You can manage users and apply role-specific access and permissions.
Access restriction testing frequency
At least every 6 months
Management access authentication
Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Please refer to the specified Cloud provider
ISO/IEC 27001 accreditation date
Please refer to the specified Cloud provider
What the ISO/IEC 27001 doesn’t cover
Please refer to the selected Cloud provider for details https://aws.amazon.com/compliance/iso-27001-faqs/
ISO 28000:2007 certification
No
CSA STAR certification
Yes
CSA STAR accreditation date
Please refer to the specified Cloud provider
CSA STAR certification level
Level 5: CSA STAR Continuous Monitoring
What the CSA STAR doesn’t cover
Please refer to the selected Cloud provider for details: https://aws.amazon.com/compliance/csa/
PCI certification
Yes
Who accredited the PCI DSS certification
Please refer to the selected Cloud provider for details
PCI DSS accreditation date
Please refer to the selected Cloud provider
What the PCI DSS doesn’t cover
Please refer to the selected Cloud provider for details
AWS: https://aws.amazon.com/compliance/pci-dss-level-1-faqs/
Other security certifications
Yes
Any other security certifications
  • https://aws.amazon.com/security/
  • https://www.bmc.com/corporate/trust-center.html

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
This is a function of the Cloud provider
Information security policies and processes
This is a function of the Cloud provider

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
This is a function of the Cloud provider https://docs.bmc.com/docs/display/public/helixsubscriber/BMC+Helix+Change+Management+policy
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
This is a function of the Cloud provider https://www.bmc.com/corporate/trust-center.html#tab-abec2ac6-f57c-4964-a132-46b9511008d4
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
This is a function of the Cloud provider https://docs.bmc.com/docs/display/public/helixsubscriber/System+monitoring
Incident management type
Supplier-defined controls
Incident management approach
This is a function of the Cloud provider https://docs.bmc.com/docs/display/public/helixsubscriber/BMC+Helix+Incident+Response+policy

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Price
£2.80 a device a month
Discount for educational organisations
No
Free trial available
Yes
Description of free trial
The BMC Helix Cloud Cost trial product is a free version of the product that you can use for experimenting purposes. The free trial is available for 14 days.
Link to free trial
https://tekwurx.com/contact-us/

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at keith@tekwurx.com. Tell them what format you need. It will help if you say what assistive technology you use.