CGI

CGI - Analytics and Data Science Platform

The Platform is a cloud based solution for exploratory analytics and data science as well as for hosting production grade analytical products covering whole data journey from data ingestion to interactive visualisation.

Features

  • flexible and open, service-based architecture
  • highly scalable from small deployments to hundreds node clusters
  • supports data from different domains, including geo-spatial, temporal, textual/other.
  • cloud provider agnostic
  • supports streaming and fast data, including big data
  • provides built-in visualisation and dashboarding solutions
  • provides security, privacy and compliance

Benefits

  • start small and scale as needs and usage dictates
  • integrates with number of systems for data ingest /insight delivery
  • covers broad range of domains and data modalities
  • preference to open-source and components
  • state-of-the-art analytical and visualisation techniques
  • cost tailored to usage and requirements

Pricing

£958 per person per day

Service documents

G-Cloud 10

716853637440921

CGI

Roger Baileff

07841 602596

gcloud@cgi.com

Service scope

Service scope
Software add-on or extension No
Cloud deployment model Hybrid cloud
Service constraints None
System requirements See Service Definition

User support

User support
Email or online ticketing support Yes, at extra cost
Support response times Within 1 hour
User can manage status and priority of support tickets No
Phone support Yes
Phone support availability 24 hours, 7 days a week
Web chat support No
Onsite support Yes, at extra cost
Support levels Supports streaming and fast data
Support available to third parties Yes

Onboarding and offboarding

Onboarding and offboarding
Getting started Through series of tutorials
Service documentation Yes
Documentation formats
  • HTML
  • ODF
  • PDF
End-of-contract data extraction Through direct and unrestricted access to storage components or dedicated Import/export APIs
End-of-contract process CGI has standard contract exit processes which ensure that all data is handed back to outgoing customers, and nothing is left available to CGI staff post-contract. These are based on standard checklists, further tailored to each customer's unique constraints.

Using the service

Using the service
Web browser interface Yes
Supported browsers
  • Internet Explorer 9
  • Internet Explorer 10
  • Internet Explorer 11
Application to install No
Designed for use on mobile devices Yes
Differences between the mobile and desktop service Visualisation and interactivity is retained but may require scrolling due to smaller screen estate compared to desktop
Accessibility standards None or don’t know
Description of accessibility N/A
Accessibility testing N/A
API Yes
What users can and can't do using the API Data Access and analytical products are accessible via API, however model building, visualisation creation and customisation require interactive access.
API documentation Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • ODF
  • PDF
  • Other
API sandbox or test environment Yes
Customisation available Yes
Description of customisation By integrating with other services and replacing some of the components specifically around data storage, orchestration and visualisation.

Scaling

Scaling
Independence of resources Through multi-tenant isolation and automated on-demand scaling of underlying cloud platform

Analytics

Analytics
Service usage metrics Yes
Metrics types Both web analytics as well as resources usage monitoring
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request

Resellers

Resellers
Supplier type Not a reseller

Staff security

Staff security
Staff security clearance Other security clearance
Government security clearance Up to Developed Vetting (DV)

Asset protection

Asset protection
Knowledge of data storage and processing locations Yes
Data storage and processing locations
  • United Kingdom
  • Other locations
User control over data storage and processing locations Yes
Datacentre security standards Managed by a third party
Penetration testing frequency At least once a year
Penetration testing approach In-house
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
  • Other
Other data at rest protection approach ISO/IEC 27001
Data sanitisation process Yes
Data sanitisation type Deleted data can’t be directly accessed
Equipment disposal approach Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001

Data importing and exporting

Data importing and exporting
Data export approach Through direct and unrestricted access to storage components or dedicated Import/export APIs
Data export formats
  • CSV
  • Other
Other data export formats Any - can build adapters for exporting to specific format
Data import formats
  • CSV
  • Other
Other data import formats Any - can build adapters for exporting to specific format

Data-in-transit protection

Data-in-transit protection
Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection between networks All data can be, additionally, encrypted in motion and at rest
Data protection within supplier network
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network All data can be, additionally, encrypted in motion and at rest

Availability and resilience

Availability and resilience
Guaranteed availability The minimal availability level for the platform is 99.9% and some components can provide levels above 99.99%
Approach to resilience The platform distributed nature means that its is flexibly scalable and redundent on local and global scale
Outage reporting Through centralized control portal with customisable alerts and analytics

Identity and authentication

Identity and authentication
User authentication needed Yes
User authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels Authorisation is role based and certain users (for example: administrators and support staff) have assigned roles which restrict they ability to execute certain tasks and see certain data.
Access restriction testing frequency At least once a year
Management access authentication
  • 2-factor authentication
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Audit information for users
Access to user activity audit information Users have access to real-time audit information
How long user audit data is stored for User-defined
Access to supplier activity audit information Users have access to real-time audit information
How long supplier audit data is stored for User-defined
How long system logs are stored for User-defined

Standards and certifications

Standards and certifications
ISO/IEC 27001 certification Yes
Who accredited the ISO/IEC 27001 AFNOR UK Ltd (UKAS Registration No.022)
ISO/IEC 27001 accreditation date 19/09/2016
What the ISO/IEC 27001 doesn’t cover Nothing is NOT covered.
The following IS covered from a Technical perspective: Provision of outsourcing sevices including managed infrastructure services, contact centre services, service desk services, management of print and email, application development, maintenance and support services.
The following IS covered from a Business perspective: The provision of outsourcing, project and consultancy services, including development and delivery activities, plus the management of people, technologies and physical security.
ISO 28000:2007 certification No
CSA STAR certification No
PCI certification No
Other security certifications No

Security governance

Security governance
Named board-level person responsible for service security Yes
Security governance certified Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards • ISO9001, ISO27001 and ISO20000
• TickITplus, CMMI-Dev+IPPD v1.2 Maturity Level 3 rating
• ISO/IEC 27001:2005 Audit and Certification SSAE 16/ISAE 3402 Attestation
• E.U. Data Protection Directive - (95/46/EC).
Information security policies and processes CGI has a series of security, integrity, and privacy policies and best practices which relate to facility and personnel security to protect client data. These include:
- Global Privacy and Data Protection Policy
- Member Commitment to the Code of Ethics and Business Conduct
- General Office Security and Facility Design and Construction Standards
- Third Party Access Standards.
Other operational standards include:
- Network Security Standards
- Access Control Standards
- Password Security Standards
- Malicious Code Protection Standards
- Database Security Standards
- Information handling Standards.
Within CGI, compliance and audit activities are performed at multiple levels to ensure our stringent security processes are being followed:
- Self-audit process, automated and manual are put in place to measure the effectiveness of controls and verify that security requirements have been met at the business unit level.
- Enterprise Security performs periodic assessment/review of security controls within the company.
- CGI Internal Audit performs security audits based on enterprise risks.
- CGI Corporate Security Policy establishes the baseline security rules to protect the assets of CGI and our clients.
External auditors assess CGI for SOX compliancy and 5970/SAS 70 audits.

Operational security

Operational security
Configuration and change management standard Supplier-defined controls
Configuration and change management approach Our configuration and change management are based on ITIL. A Change is raised as a result of an incident or problem or addition to the product, Impact Assessed by engineer, Technical Authority given by SME, approved for implementation by Change advisory Board including Technical Design Authority, Service delivery manager and Applications Support.
Vulnerability management type Supplier-defined controls
Vulnerability management approach Systems are regularly patched. Only tested patches are applied. Should a high risk vulnerability be discovered and a patch released out of cycle then it is applied assuming it passes testing.
Systems undergo an annual CHECK Penetration Test and the observations are addressed.
Protective monitoring type Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
Protective monitoring approach CGI SOC is utilised. This gives protective monitoring that is GPG13 compliant as well as 24x7 monitoring. Should a security event be triggered it is given a severity rating. Should the rating be high enough then platform management is immediately notified as well as the CGI Control Bridge. The management will then take advise as to the course of action to take. Other less severe alerts are emailed to platform management. There are monthly meetings between platform management and the SOC to examine trends.
Incident management type Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
Incident management approach Anybody can raise an Incident with the CGI Service Desk. It is then given a priority (1-4). There then follows 6 phases as follows: Detection Phase, Analysis Phase, Confinement/Containment Phase, Eradication/resolution Phase, Recovery Phase and Post Incident Phase.

Secure development

Secure development
Approach to secure software development best practice Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)

Public sector networks

Public sector networks
Connection to public sector networks No

Pricing

Pricing
Price £958 per person per day
Discount for educational organisations No
Free trial available No

Documents

Documents
Pricing document View uploaded document
Skills Framework for the Information Age rate card View uploaded document
Service definition document View uploaded document
Terms and conditions document View uploaded document
Return to top ↑