NOT PROTECTIVELY MARKED Compute as a Service Test and Development GCloud 4 Version: 1, Issue Date: 19 September 2013 NOT PROTECTIVELY MARKED NOT PROTECTIVELY MARKED ii © Capita Secure Information Solutions Ltd 2016. Other than for the sole purpose of evaluating this Service Description, no part of this material may be reproduced or transmitted in any form, or by any means, electronic, mechanical, photocopied, recorded or otherwise or stored in any retrieval system of any nature without the written permission of Capita Secure Information Solutions Ltd. Capita Secure Information Solutions Ltd, Methuen Park, Bath Road, Chippenham, Wilts SN14 0TW Telephone: 08456 041999, Fax: 08456 042999 Registered Office: 17 Rochester Row, London, SW1P 1QT. Registered in England No. 1593831 Vat Reg No. GB 618 1841 40 File: DOCUMENT1 Doc Reference: CUST-0000-0000 Issue: 1 Document Type: Service Description Copyright: Capita Secure Information Solutions Ltd 2016 NOT PROTECTIVELY MARKED 1 Contents 1 Overview .................................................................................................................... 2 2 Description ................................................................................................................ 2 3 Example use cases ................................................................................................... 2 4 Product features ....................................................................................................... 3 5 Pricing ........................................................................................................................ 3 6 Technical features .................................................................................................... 6 7 Backup / Recovery & Disaster Recovery ............................................................... 8 8 Information assurance – Impact Level (IL) at which the G-Cloud Service is accredited to hold and process information ......................................................... 8 9 On-boarding and off-boarding ................................................................................ 8 10 Service options ......................................................................................................... 9 11 Service management ................................................................................................ 9 12 Service levels ............................................................................................................ 9 13 Service constraints ................................................................................................. 10 14 Training .................................................................................................................... 11 15 Ordering and invoicing .......................................................................................... 11 16 Service lead time .................................................................................................... 11 17 Termination ............................................................................................................. 11 18 Data restoration / service migration ..................................................................... 11 19 Consumer responsibilities..................................................................................... 11 20 Technical requirements ......................................................................................... 12 21 Trial service ...................................................................... Error! Bookmark not defined. File: DOCUMENT1 Doc Reference: CUST-0000-0000 Issue: 1 Document Type: Service Description Copyright: Capita Secure Information Solutions Ltd 2016 NOT PROTECTIVELY MARKED 1 2 Overview Compute as a Service for Test & Development from Capita enables organisations to gain access to fully configurable compute resources as and when they need - significantly reducing the release time of new services or applications. Organisations can create a centralised repository of VM images including different software builds, applications, server configurations or operating systems meaning that testing new applications against legacy operating systems is a simple process to make available. Capita have achieved Pan Government Accreditation for IL2 and IL3 data for this service, meaning that a significant proportion of assurance has already been completed, thus allowing Public Sector Organisations to gain the benefits of secure, purpose build, on-demand compute resources that meet their stringent requirements, all on a true utility (pay for what you use) consumption model. 1.1 Highlights Pan Government Accredited - Suitable for IL0, IL1, IL2 and IL3 data. Exceptional value – lowest cost compute resources (from £0.02 per hour) for workloads which are not performance sensitive Fully supports the GDS Service Design Manual – exceeds the minimum specification of GDS recommended Development environments. Immediately available at all impact levels – zero delay to your project. Flexible and Adaptable – add, remove or change your solution via the Capita Portal or our fully documented API. All datacentres are highly resilient, Tier3 and UK sovereign with >50 miles separation. Connectivity via the Internet or a government secure networks (e.g. PSN, GSI, etc.) is standard – whilst Capita also support dedicated circuits into the Cloud platform such as Leased Lines, MPLS, etc. 2 Description An application developer or tester can easily create and configure VMs (with associated network, storage and application tiers) to enable an application to be developed or tested prior to going live into production. The service is particularly suitable to support Agile development projects as it can rapidly adapt and scale to meet changing requirements. Capita’s service has been designed specifically of for the UK public sector, and is available only to the UK public sector. The service supports and complies with all relevant areas of the Government ICT Strategy and Information Principles for the UK Public Sector. Capita’s datacentres are some of the most energy efficient in the world and as such support the Greening Government ICT Strategy in full. 3 Example use cases Organisations requiring cost effective hosted Test & Development environments, needing responsive deployments with scalable builds, release templates, catalogues and cloning of environments. Organisations with excessive server sprawl being either under or over utilised at any one point in time. Organisations with a distributed development team needing a centralized location with secure remote access for all. Organisations concerned that the physical security and Office environment are not acceptable for their current Test & Development servers. File: DOCUMENT1 Doc Reference: CUST-0000-0000 Issue: 1 Document Type: Service Description Copyright: Capita Secure Information Solutions Ltd 2016 NOT PROTECTIVELY MARKED 3 Organisations requiring an Accredited development environment (IL2 and IL3) without wanting to incur the time, cost and risk of deploying and accrediting a dedicated infrastructure. 4 Product features Compute as a Service for Test & Development provides key benefits to reduce an organisations time to release new hosted applications and services: Build and configure VMs within minutes. Users can autonomously add more (or less) resources when needed. Already Pan Government Accredited to IL2 and IL3 – Organisations gain significant advantages in terms of costs, time and risk compared with how systems and platforms were built in the past. Range of VM sizes – chose the right size, and the right price for what you and your application / data require. Billed by the hour / resources used - enabling significant cost savings if VMs are turned off when not needed and on when they are (e.g. why pay for the environment when it is not being used?). Create complex network tiering to mirror those within Production environments. Create “fenced” clones of whole vApps to help fault replication and isolation. Store Gold VMs images of server builds to help testing / benchmarking. Assured Security – the platform is Pan Government Accredited at both IL2 & IL3 and is hosted in highly resilient Tier3, UK sovereign data centres. Compute as a Service for Test & Development from Capita offers an assured service including monitoring and management of the IaaS platform using ISO20000 certified IT Service Management ITIL methodologies, with a clear SLA. The service is billed on the basis of the resources used or reserved during a period of time (1 hour minimum) based on metrics including VM size (memory, processors, storage), licenses and bandwidth. 5 Pricing 1 2GHz vCPU RAM (GB) IL0 IL2 IL3 1 (500MHz) 0.5 £0.022 £0.033 £0.044 Tiny 1 2 £0.066 £0.077 £0.110 Small 2 4 £0.088 £0.099 £0.132 Medium 4 8 £0.132 £0.165 £0.198 Medium High Memory 4 16 £0.264 £0.308 £0.363 Large 8 16 £0.297 £0.319 £0.418 Large High Memory 8 32 £0.550 £0.583 £0.715 Tier 1 Apps Small 8 48 £0.737 £0.781 £0.979 Tier 1 Apps Medium 8 64 £0.924 £0.979 £1.221 Tier 1 Apps Large 8 96 £1.298 £1.375 £1.716 Micro Additional Storage £0.33 / GB / Month 14 day Backup Retention2 £0.55 / GB / Month 28 day Backup Retention2 £0.825 / GB / Month File: DOCUMENT1 Doc Reference: CUST-0000-0000 Issue: 1 Document Type: Service Description Copyright: Capita Secure Information Solutions Ltd 2016 NOT PROTECTIVELY MARKED 4 Micro has a fixed 10GB storage allocation (no additional storage can be added to Micro VM’s) and a single 500Mhz vCPU. Micro VM’s must reside in a dedicated Virtual Data Centre (VDC) separate from other VM sizes. Consumers can configure a VPN between the Micro VDC and other VDC’s to enable network connectivity if required. 1 2 Backup storage must match the entire storage allocated to the VM being backed up (e.g. a VM with 150GB storage will require 150GB of backup where this option is specified). There is no option to partially backup a virtual machine. Price is per GB per month. The hourly VM charges above are incurred when the VM is running. When the VM is stopped the storage & backup charges are incurred at a pro-rated hourly rate based on the monthly charge above. This applies also to Consumer specific template images. When the VM (and associated storage) is deleted no charges are incurred. The pricing in the above table is based on GBP (£) per hour (part hour charged as a whole hour). Operating Systems If licensing operating systems through Capita, the following charges are applicable; Microsoft Windows (note that Capita must license this as per Microsoft’s standard Terms & Conditions) Micro, Tiny VM Small VM Medium VM Medium High Memory Large VM, Large High Memory, Tier One Apps SPLA Type Per Hour per VM Academic £0.002 G-SPLA £0.008 Academic £0.003 G-SPLA £0.014 Academic £0.006 G-SPLA £0.029 Academic £0.006 G-SPLA £0.029 Academic £0.017 G-SPLA £0.084 RHEL Clients can chose to license through Capita and gain access to the RHEL Support. All VM Sizes Type Per Hour per VM RHEL £0.10 If Linux distributions are not licensing through Capita, Consumers should consider how VMs can be authenticated and patches received. File: DOCUMENT1 Doc Reference: CUST-0000-0000 Issue: 1 Document Type: Service Description Copyright: Capita Secure Information Solutions Ltd 2016 NOT PROTECTIVELY MARKED 5 Software Microsoft SQL If licensing SQL through Capita, the following charges are applicable and are based on the size of the VM: Tiny, Small, Medium, Medium High Memory Large, Large High Memory, Tier One Apps SPLA Type Per Hour per VM Academic £0.09 G-SPLA £0.25 Academic £0.17 G-SPLA £0.50 Connectivity Options Name Notes Price Internet Inbound Data Transfer £0.00p per GB Outbound Data Transfer £0.132p per GB PSN (IL2) Connectivity Access to the PSN on a reserved bandwidth model £48.40 per Mbps per DC per month PSN (IL3) Connectivity Access to the PSN on a reserved bandwidth model £TBA per Mbps per DC per month GSI (IL3) Connectivity Access to the GSI on a reserved bandwidth model £412.50 per Mbps per DC per month IL0/IL2 Inter Data Centre Connectivity Both IL0 and IL2 inter data centre connectivity will utilise Capita’s IL0 inter data centre circuits (IL2 traffic will require a site-to-site VPN to suitably encrypt data) £0.132/GB/month IL3 Inter Data Centre Connectivity Consumers pay for access to Capita’s IL3 accredited resilient multi-gigabit inter data centre connectivity. Usage is not metered but is subject to a Fair Usage Policy £550 per month Dedicated Leased Lines Leased line to be ordered and managed by the Consumer directly with a Capita approved Telco. Connection terminated on a Capita router. Per Data Centre Charge: £2,200 one off setup charge No recurring charge IL3 VPN Solutions CAPS approved or appropriate CPA assured solutions to be ordered and managed by the Consumer directly, requiring VPN devices to be hosted within the Capita data centre(s) Per Data Centre Charge: £2,200 one off setup charge £550 per month IL2-IL3 Data Bridge (aka Guard) Capita uniquely provide a Pan Government Accredited bridge to facilitate access to IL3 systems by the Public/citizens. Requires your application design to be reviewed and approved by the PGA accreditor. Per Data Centre Charge: No one off setup charge £1,100 per month IP addresses IP Addresses over those provided as standard can be provided by requires approval from Capita Administration Charge £220 per IP Address Colocation of equipment See specific Service Description See specific Service Description File: DOCUMENT1 Doc Reference: CUST-0000-0000 Issue: 1 Document Type: Service Description Copyright: Capita Secure Information Solutions Ltd 2016 NOT PROTECTIVELY MARKED 6 Data ingestion and extraction In many circumstances, Capita can help facilitate the bulk import or export of Virtual Machines and associated data to/from the platform. This service option is priced on a time and materials basis form the Capita SFIA rate card. All pricing is exclusive of VAT. 6 Technical features Compute as a Service for Test & Development offers organisations full management of their environment through a secure web portal which will enable users to complete the following; Build VMs either from pre-defined templates or by specifying the exact requirements from memory (256MB to 96GB), processors (1 to 8 vCPU), storage and installing a wide range of operating systems, including Windows Server 2008 R2, Redhat Linux 6 and CentOS 6 – in minutes. Larger VM’s may be available on request Stop, start, clone and delete VMs. Reconfigure virtual hardware “on the fly” – changing memory, processors and storage as and when needed. Manage and define all firewall security rules and/or policies. Set and control access, user profiles and capabilities. Upload your own operating systems, applications and data, or alternatively select from the Capita catalogue of template-based standard OS configurations. Create your own Gold VM images that you can version control and clone from. Unlike Capita Compute as a Service for Production, resources are subject to some contention and so performance is not as predictable. For performance sensitive workloads, please consider the BASIC, STANDARD or ENHANCED Service Levels within the Capita Compute as a Service for Production service description. Users can select from the predefined VMs sizes below: Virtual CPU RAM (GB) Micro 1 (500Mhz) 0.5 Tiny 1 2 Small 2 4 Medium 4 8 Medium High Memory 4 16 Large 8 16 Large High Memory 8 32 Small Tier One Apps 8 48 Medium Tier One Apps 8 64 Large Tier One Apps 8 96 All VMs (except Micro) come with 50GB of storage by default included in the price, additional storage can simply be added as required and is bought on a per GB basis. Micro comes with 10GB. File: DOCUMENT1 Doc Reference: CUST-0000-0000 Issue: 1 Document Type: Service Description Copyright: Capita Secure Information Solutions Ltd 2016 NOT PROTECTIVELY MARKED 7 Other important information: Leased line and site to site VPN connectivity for remote access is available. Each organisation is provided with 3 useable external IP address by default, these are not transferable. Additional IP addresses maybe available on request. Memory and processors are subject to some contention and so performance is not guaranteed (Please consider the BASIC, STANDARD or ENHANCED Service Levels within the Capita Compute as a Service for Production service description if you require guaranteed performance). Each organisation can create their own catalogues of software and operating systems, providing gold images for other users to build and replicate from. VMs and storage are persistent – they are not deleted when the VM is stopped. Data transfer between VMs within an organisations environment is free whilst within the same data centre. When transferring data between data centres (for example for back up), charges will be incurred. Capita use VMware vSphere for its hypervisor. Software The VM templates offer the organisation a default configuration operating system, allowing them to configure it how they require. VM templates do not have third party applications such as Java or Adobe for example. It remains the organisations responsibility to manage, license and install these. Anti-virus is not included. Capita recommend customers deploy an appropriate Antivirus solution as part of their Assurance Plan. Backup This service, by default, does not include backup within the VM price. Consumers can select a backup policy for either 14 or 28 day retention which is charged on a per GB basis matching the size of the VM being backed up. This is backed up either locally or remotely and is priced at the applicable rates. Alternatively, Organisations can purchase capacity on the Capita Storage as a Service platform on which they can keep secondary copies of data. Such data can be replicated for even higher data durability. Licensing Licenses for Microsoft Windows operating systems must be provided by Capita. Other Microsoft licenses on existing agreements have the potential to be used – in line with Microsoft Terms & Conditions. o Capita can provide G-SPLA or Charity & Academic Licensing. o Capita reserve the right to change SPLA pricing in line with Microsoft. Licenses for Red Hat Enterprise Linux Operating Systems can be provided by either party. Licensing for all other software is the responsibility of each Consumer. Billing Billing is per hour, each partial hour consumed will be billed as a full hour. Whilst a VM is stopped, charges will be applied to the persistent storage element. If reconfiguring or resizing a VM outside the pre-defined templates, pricing is based the next closest sized machine in an upwardly fashion. Monitoring File: DOCUMENT1 Doc Reference: CUST-0000-0000 Issue: 1 Document Type: Service Description Copyright: Capita Secure Information Solutions Ltd 2016 NOT PROTECTIVELY MARKED 8 The availability of the Compute as a Service platform and each VM will be monitored by Capita to ensure the Service Level Agreements are met. Capita will not monitor the operating system and applications inside of the VMs, this can be implemented by the Consumer. Organisations have access to online reports including useful statistics such as number of VMs, performance, size, users and real time costs and usage. For VM performance, this requires VM tools to be installed on the operating system. 7 Backup / Recovery & Disaster Recovery As standard, localised component failures are tolerated within the infrastructure by eliminating all single points of failure (including physical server failure or disk failure). Consumers are also advised to consider building in high availability and fault tolerance at the Virtual Machine level (e.g. load balancing across multiple virtual machines). In this way, service will be automatically restored in most situations. Further, organisations have the option to back data up or take “snapshots” and “clones” of VMs which can provide additional protection. Consumers can back-up their data themselves using the Capita Storage as a Service solution or can choose to procure the optional automated backup on a per GB per month basis. Where the consumer has chosen to store back-up data at the remote site, in the event of a major failure in the primary data centre, Capita will endeavour to allow Consumers to provision their environment within the second data centre. Consumers should note that this is subject to available capacity within the second data centre. If consumers require certainty that capacity will be available in the event of DR, it is recommended that VM’s are procured at the second data centre. 8 Information assurance – Impact Level (IL) at which the G-Cloud Service is accredited to hold and process information Compute as a Service has achieved Pan Government Accreditation (PGA) for data at Impact Level 2 and Impact Level 3. Suitable for IL0, IL1, IL2 and IL3 data. In addition of PGA for IL2 and IL3, Capita also hold independent ISO9000, ISO20000 and ISO27001 accreditations which underpin our business operations and Cloud Platform. All datacentres are highly resilient Tier3, UK sovereign and separated by >50 miles for geographical diversity. Capita staff are Security Cleared and based in the UK 9 On-boarding and off-boarding 9.1 On-boarding Within 48 hours of acceptance of an order, Capita will create the Consumers Primary Administrator account and send the consumer a Welcome Pack which includes the URL for the Capita Customer Portal and associated authentication details. The Administrator is then able to create additional user accounts and allocate roles and privileges for users within their project. Each user can then simply log on and begin using the service. As part of the initial order, Consumers can select the Capita FASTstart option on the order form. This is a free service in which Capita will automatically provision the VMs stated at the specification required. File: DOCUMENT1 Doc Reference: CUST-0000-0000 Issue: 1 Document Type: Service Description Copyright: Capita Secure Information Solutions Ltd 2016 NOT PROTECTIVELY MARKED 9.2 9 Off-boarding Prior to terminating the contract, the Consumer is able to transfer all their data out of the solution (e.g. using the Capita portal to export Virtual Machines). When the organisation terminates their agreement with Capita, Capita ensures all of the organisation’s data is deleted. 10 Service options Test & Development compute is hosted in one UK DC with no backup included by default and has contended resources, enabling a lower price point. Typical use cases can include; Low Performance applications or services Quick, disposable development environments that can easily be re-provisioned (e.g. via Puppet, Chef, etc) Backups: When selected, Capita take a snapshot of the VM each day and store that according to the profile chosen (location & retention). A single service option exists; TEST & DEVELOPMENT Service Level Agreement 99.90% Compute Environment Location Single UK DC Storage included1 50GB Backup Not included but optional at above rates Potential Backup location Local or Second DC Performance of VM Contended QinetiQ Protective Monitoring Included for IL3 IaaS Optional for IL2 IaaS and OS/App components 1Micro 11 VM has 10GB of storage included Service management As a true Cloud service aligned to the NIST definition of IaaS, the service is designed to be self managed via the secure online Capita portal (or API) which provides common Service Management functionality and addresses standard requirements. On rare occasions, Capita may decide to assign an experienced, qualified ITIL Service Delivery Manager to some Consumers. In these cases, the SDM will provide additional assistance with reporting, incident escalation and continual service improvement, at all times following Capita’s ISO20000 certified ITIL-based process framework. For Organisations that require more of a managed service, Capita work with a number of Partners which have extensive capability to provide a Managed Service wrapper around the Capita IaaS. Capita will be pleased to make an introduction where appropriate. Capita may use MDS Technologies as a subcontractor. Other subcontracts can / may be used. 12 Service levels Capita provide both an Availability SLA and Response Time SLA for the Compute as a Service for Test & Development service as per the following table. File: DOCUMENT1 Doc Reference: CUST-0000-0000 Issue: 1 Document Type: Service Description Copyright: Capita Secure Information Solutions Ltd 2016 NOT PROTECTIVELY MARKED 10 TEST & DEVELOPMENT Availability (monthly*) 99.90% Incident response P1 – within 15 minutes P2 – within 4 hours P3 – within 24 hours P4 – within 72 hours Incident update P1 – hourly P2 – every 2 hours P3 – every 24 hours P4 – every 24 hours Communication Automated emails with access also via online portal Incident review FAQs via online portal Service credits 3% of monthly fee * Availability indication based on an average 730hrs per month. Excludes planned & emergency maintenance. Unavailability applies to existing VMs where the VM becomes unresponsive due to a fault recognised at the hypervisor layer or lower: i.e. fault is not within the Consumers control (OS, Applications, user networks) fault is within Capita controlled components such as the virtual infrastructure, storage, power and physical firewalls & routers etc. External connectivity providers (e.g. internet, PSN, GSi) and components collocated at Capita are also not included in the availability calculation. 12.1 Financial recompense model if service levels aren't met If the service level falls below the stated availability percentage (excluding Planned and Emergency maintenance periods), consumers will be eligible for service credits. Service credits will be calculated as a percentage of the fees for the monthly billing period during which the failure occurred (to be applied at the end of the billing cycle). 13 Service constraints Capita will adhere to the following in terms of maintenance windows; “Planned Maintenance” means any pre-planned maintenance of any infrastructure relating to the Services. Capita shall provide the Client with at least twenty four (24) hours’ advance notice of any such planned maintenance: Planned maintenance of Capita’s infrastructure relating to the Services shall happen between the hours of 00:00 and 06:00 (UK local time) Monday to Sunday and/or between the hours of 08:00 and 12:00 (UK local time) on a Saturday and/or Sunday. No planned maintenance will take place on a Saturday unless agreed in advance by both parties; Planned Maintenance shall be excluded from any availability calculation in regard to service credits but shall be included in the monthly service reporting; “Emergency Maintenance” means any emergency maintenance of any of the infrastructure relating to the Services. Whenever possible, Capita shall provide the Client with at least six (6) hours’ advance notice: Whenever possible Emergency Maintenance of Capita’s infrastructure will happen between the hours of 00:00 and 06:00 (UK local time) Monday to Sunday and/or between the hours of 08:00 and 12:00 (UK local time)on Saturday and/or Sunday unless there is an identified and demonstrable immediate risk to a Clients environment; File: DOCUMENT1 Doc Reference: CUST-0000-0000 Issue: 1 Document Type: Service Description Copyright: Capita Secure Information Solutions Ltd 2016 NOT PROTECTIVELY MARKED 11 Emergency Maintenance shall be excluded from any availability calculation in regard to service credits but shall be included in the monthly service reporting. 14 Training Capita have created a number of videos, help guides, manuals and FAQs to help train and instruct users so that are up and running quickly and easily. Capita also have a number of Partners who are able to deliver additional services such as training, support and managed services. Capita would be please to introduce you to such partners where appropriate. 15 Ordering and invoicing Billing for the service is monthly in arrears. Payment can be via Purchase Order and Direct Debit. Capita are preparing to be able to accept Debit/Credit Card payments (e.g. Government Procurement Card) – please enquire at time of order to check whether this is available. 16 Service lead time Setting up a new organisation will typically be completed within 48 hours from acceptance of order. Shorter deployment times are typically achieved and can be prioritised upon request. Once set up Organisations have instant access to additional compute and storage resources with no notice period required as they manage this themselves. 17 Termination 17.1 Terms At the point of termination, all consumer data, accounts and access will be permanently deleted, and will not be able to be subsequently recovered or restored. 17.2 Costs There are no termination costs for this Service. Consumers are responsible for extracting their own data from the platform if required. Capita may make an additional charge for transferring data out of the service. 18 Data restoration / service migration For service migration, Capita allows existing VM images built using VMware or Open Virtualisation Format (OVF) to be migrated to and from the platform. In many circumstances, Capita can help facilitate this on to the platform and is priced on a time and materials basis form the Capita SFIA rate card. 19 Consumer responsibilities The control and management of access and responsibilities for end users including appropriate connectivity, security and accreditation as required. Consumers must be aware of the variable nature of the billing based on usage. The consumer is also responsible for ensuring only appropriate data (e.g. IL0-IL2 or IL3) is stored and processed by applications on this environment and that they comply with the Capita Security Operating Procedures (SyOps) and other information assurance requirements as specified in Capita System Interconnect and Security Policy (SISP) and associated accreditation documentation sets. File: DOCUMENT1 Doc Reference: CUST-0000-0000 Issue: 1 Document Type: Service Description Copyright: Capita Secure Information Solutions Ltd 2016 NOT PROTECTIVELY MARKED 20 12 Technical requirements Consumers will require appropriate network connectivity such as internet access (IL0-IL2) or accredited connectivity such as a government secure network (IL3) to the Capita Cloud Platforms. Connectivity via the internet, a government secure network (PSN, GSI) or private leased line is available but may incur additional charges if the hosting of CPE routers is required - see the pricing section for more details. Where required, Consumers are responsible for procuring and managing appropriate devices or software to meet the requirement for data security over the various forms of connectivity. Consumers have a number of options to choose from with Capita to access their environment dependant on their requirement. The below are guides to demonstrate what is possible but may require further engagement to explain further: IL0 – 2 Standard Internet connectivity over common protocols (HTTP, HTTPS, SSH, etc) o Non-standard ports considered via Service Request Secure commercial grade VPN o Self-managed Site-to-Site IPSEC VPN to the Capita compute environment o Self-managed SSL VPN to the Capita compute environment PSN - You will need to assign part of your PSN IP allocation to your services hosted by Capita Leased Line (CAS(T) compliant) or non-CAS(T) using CPA/PEPAS overlay encryption IL3 Preferred connectivity is over a Government Secure Network such as GSI or PSN PSN/GSI - You will need to assign part of your PSN/GSI IP allocation to your services hosted by Capita PSN or CAS(T) Leased Line (IL3 over IL2) o CPA/PEPAS approved solution providing overlay encryption (e.g. Cisco ISR/ASR) IL0 (e.g. Internet or non CAS(T) circuit) to IL3 VPN o Site-to-Site VPN using CAPS approved solutions (e.g. Ultra AEP Xcryptor) o CPA assured solution where Foundation Grade assurance is appropriate (e.g. Cisco ISR/ASR) IL3 Leased Line (assured network connection) Consumers will require appropriate OS/App Patching, Antivirus, Protective Monitoring (for OS, Apps and user networks only), etc as appropriate as part of the assurance plan for the application. File: DOCUMENT1 Doc Reference: CUST-0000-0000 Issue: 1 Document Type: Service Description Copyright: Capita Secure Information Solutions Ltd 2016 NOT PROTECTIVELY MARKED File: DOCUMENT1 Doc Reference: CUST-0000-0000 Issue: 1 1 Document Type: Service Description Copyright: Capita Secure Information Solutions Ltd 2016