22

Click here to load reader

 · Web viewWe take potential ICT threats extremely seriously and have numerous security mitigation controls in place in line with both audit and the strict public sector network

  • Upload
    dodan

  • View
    213

  • Download
    0

Embed Size (px)

Citation preview

Page 1:  · Web viewWe take potential ICT threats extremely seriously and have numerous security mitigation controls in place in line with both audit and the strict public sector network

ICT key information

Service delivery

Norwich City Council has delegated its ICT support services to LGSS (http://www.lgss.co.uk/Pages/Home.aspx). These services include infrastructure, desktop, applications, telephony and network. System administration, reporting and client management have been retained in-house.

The ICT strategy can be found here: https://www.norwich.gov.uk/info/20011/about_your_council/1366/council_policies_and_strategies

The Cabinet member for ICT is Cllr Mike Stonard and his contact details can be found on our website here:https://cmis.norwich.gov.uk/live/Councillors/tabid/63/ctl/ViewCMIS_Person/mid/383/id/15/ScreenMode/Alphabetical/Default.aspx

ICT spend

Budget information can be found on our website here:https://www.norwich.gov.uk/info/20189/finance_and_transparency/1322/budgets

Network Servers Desktop Laptop/tablets NumbersApr-13 167,980Oct-13 405,112 800 desktopsMar-14 79,008May-14 60,178 63,324Aug-14 16,526Nov-14 93,508Jul-15 90,422 163,325 20 x Dell 8”

tablets plus 190 x 11” plus 70 x 13”

Oct-16 53,336Jan-17 95,322Mar-17 52,101Nov-17 47,763

Security

A public interest test is likely to be applied in all cases where details pertaining to the Council’s ICT security have been requested.

Cyber-attacksWe have kept an incident log of all cyber-attacks since 13/14:

2013/14 2014/15 2015/16 2016/17Attempted 44 57 301 162Successful 0 0 0 1

Page 2:  · Web viewWe take potential ICT threats extremely seriously and have numerous security mitigation controls in place in line with both audit and the strict public sector network

We do not retain a breakdown of the unsuccessful attack types

Re successful attack:Data compromised? No data was lost or stolenNumber of devices affected? 12Type of attack? RansomwareDemand? NoneIncident reported externally? NoConviction? The council does not hold any such information

Cyber awareness and training

We take potential ICT threats extremely seriously and have numerous security mitigation controls in place in line with both audit and the strict public sector network and payment card industry requirements, including a comprehensive security policy that all users are required to sign up to before access is granted to our systems. We also have regular user awareness campaigns such as the Cyber security week/ plus regular ad hoc messages to encourage vigilance.

A robust incident and management response plan is also in place in the event of an incident.

Details of security solutions that we use

The Council has decided to withhold the security solution model details from disclosure pursuant to the provisions of Section 31 (1) (a) of the Freedom of Information Act (“the Act”) which is a qualified exemption, a public interest test has been applied.

The Council has concluded that the public interest test favours non-disclosure because although disclosure of this information would increase visibility of accountability, promote accountability and transparency and would demonstrate how the Council manages and delivers its functions; how it spends public money, however, disclosure of some of the information requested could place some of the Council's key systems at risk from criminal activity and we consider that on balance the public interest is in favour of not disclosing information that could facilitate crime, for example, specific areas of the Council's network could be targeted resulting in the loss, damage or theft of information, causing disruption to vital services with consequences to the public, damage the Council's internal business operations, its commercial interests, business confidence including reputational loss to the Council.

In conclusion, in all circumstances of this case we are of the opinion that the balance of public interest favours non-disclosure of this information at this time

Spend on cyber security

The council’s ICT services are fully managed via a partnering and delegation agreement with LGSS. All security software is carried out within existing resources as part of this managed service. End user devices

Page 3:  · Web viewWe take potential ICT threats extremely seriously and have numerous security mitigation controls in place in line with both audit and the strict public sector network

Desktop computersSupplier DellName / brand / version info LenovoAnnual average spend £Contract details (start / expiry / review dates)

n/a

Contact for contract Jane AllenService improvement [email protected]

Number of users/licences approx.

OEM per device x 800

Additional information A complete desktop refresh took place in December 2013. No plans for a refresh in 2017

Tablets / laptopSupplier DellName / brand / version info Lenovo Laptops / Dell tabletsAnnual average spendContract details (start / expiry / review dates)

n/a

Contact for contract Jane AllenService improvement [email protected]

Number of users/licences approx.

OEM per device x 300

Additional information Laptops were procured in December 2013. There are no plans for refresh in 2017. Tablets were procured in December 2014. There are no plans for a refresh in 2017.

Smart phones plus mobile device management applicationSupplier VodafoneName / brand / version info Nokia Lumia 640 LTEAnnual average spend £20kContract details (start / expiry / review dates)

Review in 2018

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users/licences approx.

500

Enterprise Telephony

Customer contact telephony support and maintenanceDescription Customer service telephony – multi-channel

contact systemSupplier Intrinsic

Page 4:  · Web viewWe take potential ICT threats extremely seriously and have numerous security mitigation controls in place in line with both audit and the strict public sector network

Name / brand / version info Verint basic/Avaya/Aura contactAnnual average spend £35kContract details (start / expiry / review dates)

Aug 16 – April 21

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users/licences approx.

750 users

Fixed line telephonySupplier Adept Telecom PLCName / brand / version info 5 x ISDN lines plus 204 PSTN and 207

ADSL linesAnnual average spend £113,000Contract details (start / expiry / review dates)

12 month contract from 1 July 2017 – option to extend for up to 2 years

Contact for contract Jane AllenService improvement [email protected]

Number of users/licences approx.

750 users

Core WAN services and internet accessSupplier Updata Infastructure (UK) LtdName / brand / version info EquinixAnnual average spend £62kContract details (start / expiry / review dates)

Aug 16 – Mar 20

Contact for contract Jane AllenService improvement [email protected]

Number of users/licences approx.

7 sites

Additional information

LAN ServicesDescription Support of LANSupplier IntrinsicName/Brand/Version info CiscoAnnual Spend £19kContract details (start / expiry / review dates)

Aug 16-April 21

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users/ licences 750 users

Page 5:  · Web viewWe take potential ICT threats extremely seriously and have numerous security mitigation controls in place in line with both audit and the strict public sector network

Switchboard / customer contact telephone numberSupplier TalkTalkName / brand / version info n/aAnnual average spend £16kContract details (start / expiry / review dates)

Rolling annual service

Contact for contract Jane AllenService improvement [email protected]

Number of users/licences approx.

n/a

Enterprise Licenses

Microsoft Enterprise AgreementsSupplier PhoenixName / brand / version info Microsoft Enterprise AgreementsAnnual average spend £107kContract details (start / expiry / review dates)

Mar 2016 – Mar 2019

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users/licences approx.

800 users

Page 6:  · Web viewWe take potential ICT threats extremely seriously and have numerous security mitigation controls in place in line with both audit and the strict public sector network

Systems

Contact management (CRM), workflow and EDRMSDescription EDRMS, Contact Manager and multiple

Local Govt service modules, e.g Environmental Health, Housing etc.

Supplier CivicaName / brand / version info Contact360 (v20)Annual average spend £160kContract details (start / expiry / review dates)

March 2017 to 2022 with an option to extend for an additional 2 years.

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users / licences approx.

900 users

Income Management (Cash Receipting)Description E-/CPP/CNP Payments, Automated

Telephone Payments, Distribution Management etc.

Supplier CivicaName / brand / version info ICONAnnual average spend £27kContract details (start / expiry / review dates)

Commenced Nov 2013, Renewed annually in Oct

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users / licences approx.

79 users

Additional information Capital costs:Implementation charges of £30k, licence fees of £45k, hardware(Chip and Pin units) £2.1k = £77.1K. Annual maintenance 2016/2017 £18,252. plusUpgrade costs.

Human ResourcesDescription Personnel and Organisation management

systemSupplier FMP GlobalName / brand / version info WorkforceAnnual average spend £10kContract details (start / expiry / review dates)

Rolling annual (April) contract – currently under review

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Page 7:  · Web viewWe take potential ICT threats extremely seriously and have numerous security mitigation controls in place in line with both audit and the strict public sector network

Number of users/licences approx.

Up to 5000 employee records

Additional information A new five year contract with Advanced has been entered into to replace the HR system with iTrent (with a two year extension option). Implementation is in progress and we are in the early stages of mobilisation. The contract was signed on the 30-06-17 and final costings are still being negotiated.

PayrollDescription Fully Managed Payroll ServiceSupplier Arvato LtdName / brand / version infoAnnual average spend £26kContract details (start / expiry / review dates)

July 2013 – July 2018 (review Dec 2017)

Contact for contract [email protected] of users/licences approx.

Cost per pay slip

Additional information additional info can be found on: http://contracts.eelga.gov.uk/contract/?ID=27937

Finance systemDescription Revenue Accounting, General Ledger,

Receivables, Payables, Inventory Management, Discoverer (Reports)

Supplier PDG Consulting LtdName / brand / version info Oracle E-Business SuiteAnnual average spend £17kContract details (start / expiry / review dates)

September 2017 – September 2018

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users/licences approx.

385 users

Additional information A new five year contract with Advanced has been entered into to replace the Finance system with e5 (with a two year extension option). Implementation is in progress and we are in the early stages of mobilisation. The contract was signed on the 30-06-17 and final costings are still being negotiated.

Housing Management systemDescription Housing stock and tenancy managementSupplier CapitaName / brand / version info Academy

Page 8:  · Web viewWe take potential ICT threats extremely seriously and have numerous security mitigation controls in place in line with both audit and the strict public sector network

Annual average spend £81kContract details (start / expiry / review dates)

Rolling annual (April – March)

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users/licences approx.

390 users

Planning systemDescription LLPG, Planning, Licensing, Environmental

HealthSupplier IDOXName / brand / version info UniformAnnual average spend £59kContract details (start / expiry / review dates)

31 March 2018, rolling annual contract

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users/licences approx.

50 concurrent

Revenues and benefits systemDescription Council Tax, NNDR (Business Rates) and

Benefits, e-billingSupplier NorthgateName / brand / version info NorthgateAnnual average spend £91.5kContract details (start / expiry / review dates)

April 2017 – March 2021

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users/licences approx.

150 users

Email serviceSupplier MicrosoftName / brand / version info Microsoft ExchangeAnnual average spend Included with Enterprise licenceContract details (start / expiry / review dates)

April 2015 – March 2018

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Page 9:  · Web viewWe take potential ICT threats extremely seriously and have numerous security mitigation controls in place in line with both audit and the strict public sector network

Number of users/licences approx.

750 users

Contact Centre Repair and Diagnostic ToolSupplier OmfaxName / brand / version info Keyfax repairs diagnostic and online repairsAnnual average spend £9kContract details (start / expiry / review dates)

April 17-Mar 18 rolling contract

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users/licences approx.

390 users

Time Recording & ChargingSupplier PillarName / brand / version info Profess Office Core - City Dev Database

and Planning section databaseAnnual average spend £2.4kContract details (start / expiry / review dates)

April 17- Mar 18, rolling contract

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users/licences approx.

110 users

Printing SoftwareSupplier PrintsoftName / brand / version info Pres ID Bar code and PostscriptAnnual average spend £2.6kContract details (start / expiry / review dates)

Jan 17- Jan 18, rolling contract

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users/licences approx.

1 user

Trees DatabaseSupplier RA Information SystemsName / brand / version info Ezytreev Tree Management and InventoryAnnual average spend £3.9kContract details (start / expiry / review dates)

Nov 17- Oct 18, rolling contract

Contact for contract Paul GoochContract Support and Applications Manager,

Page 10:  · Web viewWe take potential ICT threats extremely seriously and have numerous security mitigation controls in place in line with both audit and the strict public sector network

[email protected]

Number of users/licences approx.

4 licences

Citrix Fobs

Supplier Secure DataName / brand / version info SAS CloudAnnual average spend £13.6kContract details (start / expiry / review dates)

July 17 – July18

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users/licences approx.

525

System SecuritySupplier FOURSYSName / brand / version info Malware and Gateway supportAnnual average spend £6.7kContract details (start / expiry / review dates)

29/4/16-28/4/19

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users/licences approx.

850 users

ElectionsSupplier HalaroseName / brand / version info Elections

1. EROS(6) + VDF(10). 2. Adest Doc Mgt (EROS scan) (5) 3. Avantguard Auto network and non (3)

Annual average spend £16kContract details (start / expiry / review dates)

1- Dec17- Nov 18 – rolling contract2 - Feb 17 – Feb 18 – rolling contract3 – Mar 17 - Feb 18 – rolling contract

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users/licences approx.

As above

Meeting Room ManagerSupplier Gladstone

Page 11:  · Web viewWe take potential ICT threats extremely seriously and have numerous security mitigation controls in place in line with both audit and the strict public sector network

Name / brand / version info MRM and Plus 2 and barcode reading software

Annual average spend £3.8kContract details (start / expiry / review dates)

Nov 17 – Oct 18, rolling contract

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users/licences approx.

7 user licence

GISSupplier ESRIName / brand / version info ArcGIS,EDN,Localview,Fusion Navigator

Flex Geotemplate and webpublisherAnnual average spend £32.6kContract details (start / expiry / review dates)

April 17 – April 18, rolling contract

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users/licences approx.

Desktop users 30, web 750 users

Network SecuritySupplier SBLName / brand / version info Firewall maintenanceAnnual average spend £7.3kContract details (start / expiry / review dates)

June 17 – June 18

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users/licences approx.

750 users

Parking (Permits and PCNs)Supplier ICESName / brand / version info Parking Gateway / Permit GatewayAnnual average spend £32.4kContract details (start / expiry / review dates)

Aug 17- July 18

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users/licences approx.

35 licences

Page 12:  · Web viewWe take potential ICT threats extremely seriously and have numerous security mitigation controls in place in line with both audit and the strict public sector network

WebsiteSupplier Jadu

Name / brand / version info Jadu CMS, XFP and PaybridgeAnnual average spend £18.4kContract details (start / expiry / review dates)

Feb 17 – Feb 18

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users/licences approx.

n/a (site)

Planning DesignSupplier KeysoftName / brand / version info Keyscape, Keylines KeyOSC AutoCAD and

Autodesk, AutoturnAnnual average spend £12kContract details (start / expiry / review dates)

Rolling annual – review Oct 18

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users/licences approx.

50 users

MiddlewareSupplier NDLName / brand / version info awiDX, awiSX

awiMX, awiQX

Annual average spend £42kContract details (start / expiry / review dates)

Aug 17 – Aug 18 – 1 year renewal

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users/licences approx.

DX/SX=250 licences and MX site licence

Web SecuritySupplier SECONName / brand / version info Web FilterAnnual average spend £9kContract details (start / expiry / review dates)

Dec 15 – Nov 18

Page 13:  · Web viewWe take potential ICT threats extremely seriously and have numerous security mitigation controls in place in line with both audit and the strict public sector network

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Number of users/licences approx.

750 users

Hardware support contracts

Description Server maintenanceSupplier ComputacareName / brand / version info DellAnnual average spend £167,980 (procurement)Contract details (start / expiry / review dates)

2013 – 2018

Contact for contract [email protected] information

Description Hardware maintenance for Unix serversSupplier OracleName / brand / version info SunAnnual average spend £5kContract details (start / expiry / review dates)

Sept 17 – Mar 18 (month renewal then review)

Contact for contract Paul GoochContract Support and Applications Manager,[email protected]

Description Server maintenanceSupplier SoftboxName / brand / version info DellAnnual average spend £83,732.29 (procurement spend)Contract details (start / expiry / review dates)

June 2015 – 2020 (review in 2019)

Contact for contract [email protected] of users/licences approx.Additional information

Description Software LicensingSupplier ComputacareName / brand / version info HypervisorAnnual average spend £Inc. in original procurement spendContract details (start / expiry / review dates)

2013 – 2018

Contact for contract [email protected] of users/licences approx.Additional information

Page 14:  · Web viewWe take potential ICT threats extremely seriously and have numerous security mitigation controls in place in line with both audit and the strict public sector network

Description Software LicensingSupplier SoftboxName / brand / version info HypervisorAnnual average spend £Inc. in the original procurement spendContract details (start / expiry / review dates)

June 2015 – 2020 (review in 2019)

Contact for contract [email protected] of users/licences approx.Additional information

Description Hardware & maintenance StorageSupplier ComputacareName / brand / version info EqualogicAnnual average spend £Included in original procurement spendContract details (start / expiry / review dates)

2013 – 2018

Contact for contract [email protected] of users/licences approx.Additional information

Description Hardware & maintenance StorageSupplier SoftboxName / brand / version info EqualogicAnnual average spend £Inc. in original procurement spendContract details (start / expiry / review dates)

June 2015 – 2020 (review in 2019)

Contact for contract [email protected] of users/licences approx.Additional information

Contractor access to information

All external access is managed via a secure method and an Information Sharing Protocol (ISP) is in place for all data sharing arrangements.

Print services

Page 15:  · Web viewWe take potential ICT threats extremely seriously and have numerous security mitigation controls in place in line with both audit and the strict public sector network

Question AnswerPlease confirm if you are in contract for a managed print service. Yes

Does this include Multi-Functional Devices (MFDs) and printers? Yes

Please confirm contract number and dates.

Ref: 9572: 01/08/2016 – 31/07/2020CCS RM1599 Framework Agreement

Please confirm who the contract was awarded to. XEROX LTD

Please confirm the name of the employee that is responsible for the management of the printer estate for your organisation.

Jane AllenService improvement [email protected]

Please confirm if you currently reclaim the VAT on the managed service contract

Yes

Please confirm if you intend to go out to tender next time or call off an existing framework. If so, which one?

Unknown

How many MFDs do you have? 27What is the annual spend on MFDs – including lease costs, consumables, costs per click and service charges?

Annual spend - £13.5k approx.

How many printers do you have? 2 bulk printers, 27 MFDs and 33 desktop printers

Annual lease charges for MFDs and Bulk printers £21.1

Managed Print service Yes – on all MFDs and bulk devicesWhat is the total annual spend on all printers – including lease costs, consumables, costs per click and service charges?

£46k (MFDs and bulk printers) & £2k (consumables for small desktop printers)

Please confirm the total annual volumes of mono and colour prints.

Colour – 800,000Mono – 5,180,000 bulk and MFD printers

How much time a month does the IT team spend on printer queries from end users?

This is not recorded

Do you have any mobile print capabilities? Yes

Do you have any secure print capabilities? Yes

What print management software do you use across the organisation? XEROX PRINT SERVICE