i Compliant Fully managed Encryption Overlay service enabling data sharing across secure networks. Provides operational efficiencies and cost savings through simplified procurement
Get Better Protected... Secure data sharing made possible with Updata s Encryption Overlay Service. Many Public Sector organisations handle sensitive data which needs to be protected. Updata are accredited to provide a fully managed PSN Encryption Overlay service that is suitable for all Public Sector organisations including Central Government, Local Authorities, UK Polices Forces and the Healthcare sector. The Encryption Overlay services is a layered solution which sits on top of an ASSURED PSN Wide Area Network (WAN), and uplifts it to a PROTECTED network service that transparently encrypts and protects all transmitted data. The Updata Encryption Overlay service is suitable for all data classified as OFFICIAL or OFFICIAL-SENSITIVE and data classified as IL3 RESTRICTED under the previous government protective marking scheme. It uses the existing PSN accredited core network for the transport of the IPsec packets and provides availability guarantees through the CAS(T) assurance. The Updata Encryption Overlay service enables customers to access ASSURED and PROTECTED PSN compliant network services, which are designed and optimised to meet the strict information assurance requirements of UK public sector organisations. This service utilises IPsec encryption to provide a strong guarantee of confidentiality for customers who are concerned about their data being intercepted. Why include an Encryption Overlay on your network? Your organisation needs to exchange sensitive data across networks which requires additional security protection There is a requirement to share information with other PSN Accredited organisations The organisation needs to meet the pressures of being compliant Organisations want to simplify procurement and project management overheads via access to a pre-approved compliant managed service. 2
Sharing classified data across secured networks Most organisations handle classified data as part of their daily work. Sharing any level of classified data with other offices involves a secure network and infrastructure setup to enable secure sharing. Public Sector organisations are able to securely share data across the Public Services Network PSN. The PSN acts as a foundation that facilitates data sharing across various groups such as Health, Police and Local & Central Government. This infrastructure ensures information can be securely and easily accessed by Public Sector providers, eliminating high costs and inefficiencies of multiple, incompatible networks. The Inter Provide Encryption Domain (IPED) enables the Encryption Overlay service to be extended via the Government Communications Network (GCN) through an Updata Encryption gateway. It allows information classified as OFFICIAL, OFFICIAL SENSITIVE or classified as IL3 RESTRICTED within Government Departments, Police and Local Authorities to be shared securely with other PSN network providers. Updata also adhere to supplementary controls (Enhanced Regime) required by Policing organisations when utilising the IPED service. Organisations such as the Police require additional security overlays on top of their Assured network, due to the nature of the data they handle. The Updata Encryption Overlay service enables Police to securely share protected data with Force s across the region and with other organisations such as the Home Office via the IPED. Updata Assured NOC Management Updata Protected NOC Management, threat mitigation & analysis Customer LAN PKI RA Portal PKI CA GCN Key: Encryption Endpoint (CPA Assured) Endpoint (CPA Assured) Management IPSec VPN (Protected) Customer IPSec VPN (Protected) PSN Accredited Network (Assured) 3
Features and Benefits Secure IPsec site-to-site encryption Accredited CESG and PSN approved service simplifying the procurement process Security Cleared Support Dedicated support staff are security cleared by National Security Vetting - Security Check (SC) and Non Police Personnel Vetting Level 2 (NPPV2) cleared In addition to Updata WAN features: Fully Managed Service Managed and supported via a dedicated and secure UK Network Operations Centre (NOC) Choice EFM, FTTC and Ethernet Fibre; a choice of scalable and flexible connectivity bandwidth options from 2Mbps 1000Mbps Resilience Resilient access options with availability SLA s of up to 99.99% QoS Prioritise specific application types that require strict delivery guarantees, such as VoIP Monitoring UK based support team 24/7/365, with 85% first time fix record. Proactive monitoring process whereby 85% of network faults are proactively monitored by Updata. Includes customer defined options 4
Case Study Cheshire Constabulary connects to Updata s regional PSN In January 2014 Cheshire Constabulary signed up to the Cheshire and Merseyside Public Services Network (PSN). The Cheshire and Merseyside PSN connects Public Sector partners across the region, including Councils, Schools, Police Forces, Hospitals, and Fire & Rescue services. The network facilitates greater collaborative working, shared services and service transformation throughout Cheshire and Merseyside. Cheshire Constabulary joins partners Cheshire East Council, Cheshire West & Chester Council and Schools in the region which have already signed up to Updata s fully-managed Wide Area Network (WAN). The new communication infrastructure will help to provide a more streamlined and flexible way of working not only for the Constabulary but for our partner agencies as well. In these times of austerity it s vital that we can save money where we can, which we can then put to good use on the frontline, providing an efficient and effective police service. John Dwyer, Police & Crime Commissioner for Cheshire 5
Service Excellence How we support you At Updata we are dedicated in building and maintaining good relationships with our clients. Our Encryption Overlay service is supported by a dedicated team who are both National Security Vetting - Security Check (SC) and Non Police Personnel Vetting Level 2 (NPPV2) cleared. They are on hand 24/7/365, ensuring everything is running smoothly. Our emphasis on transparency, both in terms of the service and the information available to you, enables us to deliver a consistently outstanding support experience. Updata establishes your needs very early on in the engagement process, enabling us to tailor a service programme which meets your individual needs and requirements. Larger network customers also have access to an innovative self-service portal. The portal gives you the flexibility to request quotes, view service catalogues and contact our service desk. Our service excellence and support packages are at the core of every solution we create. 6
Technical Overview The Updata Encryption Overlay service is a fully compliant PSN catalogue service (SRV_0201) which has undergone rigorous assessments by CESG s PAN Government Accreditor. It ensures information classified up to OFFICIAL under the current Government Classification Policy is protected by an IPsec cryptographic security overlay that is designed, managed and operated to comply with the following standards, controls and assurances: This allows us to deliver a fully compliant Encryption Overlay service that protects your data and ensures peace of mind. SO27001 CAS(CA) the PSN and CESG assurance scheme for PSN Certificate Authorities PSN Certificate Policy v1.4 PSN Interim IPSec Profile o Encryption - AES128_ CBC o PRF - SHA-1 o Diffie-Hellman Group - Group 5 (1536 bits) HMG Baseline controls Deter CAS(T) the PSN assurance scheme for telecommunications networks CPA Security Characteristics: IPsec Gateway, Software Disk Encryption and IPsec for Remote Working Software Client v2.3 PSN Interim IPsec Profile Additionally, the Encryption Overlay Service uses: Products certified under the CESG Commercial Product Assurance (CPA) scheme and configured to the requirements of the CPA security characteristics PSN and CESG approved IPsec configuration X509 certificates for network authentication, from our PSN accredited certificate authority A fully segregated management infrastructure providing protection against advanced targeted attacks 7
Why Updata? We specialise in large, complex, fully managed Wide Area Networks that are built with the future in mind. Our solutions are completely flexible and scalable to suit your commercial, technological and business needs. Updata Infrastructure is a part of Capita IT Enterprise Services, one of the largest IT services providers in the UK and a Tier 1 partner of industry leading technology vendors. Our heritage, combined with the capabilities of Capita, means we understand business, technology and processes. We place the customer at the heart of everything we do and have a proven track record in transforming businesses through intelligent IT. All of our networks and solutions are proactively monitored 24/7/365 from our UK based support centre giving you peace of mind from start to finish. Delivering more As one of the UK s leading service integrators we offer more than just a connection. The breadth of our capability means that we can deliver a host of value-added services that you can pick-and-mix to suit your own, or shared, needs. With the ability to add more services as needed you can transform the way you work, securely share information and deliver value to your customers. We have designed and implemented some of the most robust and complex network solutions which have vastly transformed businesses by driving wider organisational initiatives such as mobile and flexible working and property rationalisation. Updata s outstanding engineering saves our biggest Public Sector client 5.1 million annually in property costs, as well as supporting 20,000 remote workers a day through their Virtual Private Network (VPN). As an Updata customer you will experience a seamless journey from initial consultation through to project delivery. At the core of this is an innovative network design that meets all of your business critical needs. One supplier brings simplicity... Why research, specify and buy individual elements of a service when you can buy it all from one supplier? Updata can: Bring the experience gained from over 20 years of delivering projects across the UK for public and private sector clients Design, build, supply and manage network solutions Deliver a robust, scalable and flexible network service that enables access to an extensive value added portfolio - such as Voice & Collaboration and Security Supply the network access service which is a gateway to a range of additional services - these can be shared internally, regionally or nationally Help you reduce costs through price leadership and service excellence Delivering Want to learn more? Contact us on TellMeMore@Updata.net or call 01737 224 422 to arrange a meeting. www.updata.net