easy to adopt, easy to use, easy to leave service description Personal Storage in the Cloud IaaS version 5.1 Open Contents Highlights .............................................................................................................................. 3 Overview ............................................................................................................................... 3 Example use cases ............................................................................................................... 4 Trial service .......................................................................................................................... 4 Information assurance........................................................................................................... 4 Product features.................................................................................................................... 5 Technical features................................................................................................................. 5 Service options ..................................................................................................................... 7 Backup / Recovery & Disaster Recovery ............................................................................... 7 Service levels ........................................................................................................................ 8 Pricing ................................................................................................................................... 8 Appendix ............................................................................................................................. 10 Service description SC-SVC-04, version 5.1 © Skyscape Cloud Services Limited, 2014 Open Personal Storage in the Cloud Page 2 of 13 Open Highlights Amazon S3 compatible storage API – use applications which currently work with S3 and benefit from UK based cloud storage. Pan Government Accredited & PSN Accredited - recommended for all systems at OFFICIAL or systems having IL0-IL3 (IL4 by aggregation) or OFFICIALSENSITIVE assets. Exceptional value – dual site IL3 accredited Storage from 37p per GB. Immediately available at all impact levels – zero delay to your project. All datacentres are highly resilient, Tier3 and UK sovereign with >50 miles separation. Free connectivity via PSN as well as low cost connectivity options via Internet or other government secure networks (e.g. N3, GSI, IPED, etc.). You can also provision your own dedicated connectivity solutions such as X-Kryptors, CPA foundation grade, Leased Lines, MPLS, WAN acceleration, etc. True API driven Object Storage – access your data directly from your locations or from applications you choose to host on the Skyscape Compute-as-a-Service platform. Overview Personal Storage in the Cloud enables a single user or application to access Storage-as-aService instantly from any Microsoft Windows or Linux desktop or server anywhere, without writing a single line of code. By installing a simple, secure and free desktop application, individuals can access their own Personal Storage in the Cloud from most Windows/Linux desktops or servers, anywhere, using a simple and intuitive user-interface. Other solutions are also available such as EMC Syncplicity (at additional cost – purchased separately) which extends support to other platforms and mobile devices. The service is both Pan Government Accredited and PSN Accredited at IL2 and IL3 and hence provides the most robust levels of assurance that the Skyscape cloud platform is designed for IL0-IL3 systems (and IL4 by aggregation) as well as data classified as OFFICIAL or OFFICIAL-SENSITIVE. This enables Public Sector organisations to gain the benefits of secure, purpose build, on-demand resources that meet their stringent requirements, all on a true utility (pay for what you use) consumption model. Further, Skyscape can provide a range of Service Levels – related to data protection and durability – allowing Consumers the ability to match their data needs with an appropriate level and cost instead of designing everything to the highest level when not needed. Skyscape’s service has been designed specifically of for the UK public sector and is available only to the UK public sector. The service supports and complies with all relevant areas of the Government ICT Strategy and Information Principles for the UK Public Sector. Skyscape’s datacentres are some of the most energy efficient in the world and as such support the Green Government ICT Strategy in full. Service description SC-SVC-04, version 5.1 © Skyscape Cloud Services Limited, 2014 Open Personal Storage in the Cloud Page 3 of 13 Open Example use cases Simpler Better Cheaper Organisations wanting to reduce the complexity of managing storage. Personal Storage in the Cloud provides consumers with new levels of simplicity. Simple software installation with ‘set and forget’ configuration which enable secure data synchronisation with the Cloud Organisations seeking a better way to solve the growing problem of protecting data held on desktops and laptops. Personal Storage in the Cloud provides inherently scalable storage with flexible data protection levels on a true utility basis. Organisations looking to implement low cost, Pan Government Accredited storage to avoid expensive Capex solutions. Particularly suited for large data sets and mixed file types Trial service Skyscape offer a 30 day free trial for a single organisation with up to 5TB of storage, available upon request. Free trials are subject to additional terms and conditions which are available on the Cloud Store. Information assurance Skyscape Personal Storage in the Cloud has achieved both Pan Government Accreditation (PGA) and PSN Accreditation for systems at Impact Level 2 and Impact Level 3. The service has also been implemented with the following security features: Provides assurance in excess of the fourteen Cloud Service Security Principles published by Cabinet Office. Suitable for IL0, IL1, IL2 and IL3 assets (and IL4 by aggregation) under the GPMS (Government Protective Marking Scheme). Suitable for OFFICIAL and OFFICIAL-SENSITIVE assets under the GSC (Government Security Classifications). PGA approved Cross Domain Bridge (gateway) – designed to facilitate connectivity between higher security domains (e.g. IL3) and lower security domains (e.g. lower OFFICIAL, IL2). In addition to PGA and PSN Accreditation, Skyscape also hold independent ISO9000, ISO20000 and ISO27001 accreditations which underpin our business operations and Cloud Platform. All datacentres are highly resilient Tier3, UK sovereign and separated by >50 miles for geographical diversity. Skyscape staff are Security Cleared and based in the UK. Protective Monitoring (aligned with GPG13) across all Skyscape platforms at the hypervisor layer and below Service description SC-SVC-04, version 5.1 © Skyscape Cloud Services Limited, 2014 Open Personal Storage in the Cloud Page 4 of 13 Open Product features Personal Storage in the Cloud provides a secure solution to enhance the durability and availability of personal data. The solution offers true Cloud benefits such as: Cloud Sync – the ability for an individual user, multiple laptop and desktop systems to either mirror or cache content to the cloud. Encryption - Ability to encrypt content based on a user defined key. Range of services levels – chose the right service, and the right price for what you and your application / data require. Unified namespace allows objects to live anywhere within our UK data centres, and for multiple sites and app servers to use the same storage. Elasticity – the solution scales indefinitely and on-demand allowing unpredictable capacity growth by never requiring storage provisioning ever again. Metered Billing – the organisation is charged by how much (or how little) storage is consumed. The service is billed on the basis of the resources used during a period of time (1 month minimum) based on metrics including consumed capacity and bandwidth. Assured Security – the platform is Pan Government Accredited and PSN Accredited at both IL2 & IL3, hosted in highly resilient Tier3, UK sovereign data centres and benefits from QinetiQ’s Protective Monitoring solution at IL2 & IL3. Green – the Skyscape service is based in UK data centres which offer market leading efficiency around power and cooling. A Skyscape solution will generate less Carbon than many other solutions. Geodiversity – the platform spans two UK data centres separated by over 50 miles Technical features When using EMC GeoDrive software, Personal Storage in the Cloud provides three (3) modes of operation: Mirror – In mirror mode, files are written to the local machine as well as to the Cloud. All files are accessible whether online or offline. This mode is ideal for users who require optimal performance and offline access to all content whilst also needing the assurance that their data is protected and accessible. Push-to-Cloud – In this mode, files are written to the local machine. After a pre-set time, the files are uploaded to the Cloud and stubbed on the local machine. When stubbed, the actual contents of the file will be held only within the Cloud – the local machine will simply hold a shortcut for ease of use. To access the file, the user would click on the stub and then the EMC Atmos GeoDrive will take care of “pulling” the file back to the local machine. This use case applies for most users who wish to store files remotely and not take up space on their local hard drive. Disconnected – In disconnected mode, users can still use EMC Atmos GeoDrive client when not connected to the Cloud. Files will remain on the local machine while the connection is broken. Once the link is re-established, files will be automatically Service description SC-SVC-04, version 5.1 © Skyscape Cloud Services Limited, 2014 Open Personal Storage in the Cloud Page 5 of 13 Open synced to the Cloud based on the data storage mode chosen (Mirrored or Push-toCloud). Connectivity via a variety of networks; PSN, Internet, GSI/GCF, N3 and Private Circuit options. The EMC Atmos GeoDrive client also offers optional advanced features: Encryption – provides optional AES256 encryption for data at rest. Data is encrypted on the local machine before sending to the Cloud. The data is encrypted using a passphrase which the user determines. Compression – C-EDRS technology provides optional compression of data on the local machine before it is sent to the Cloud. Data Throttling – provides a bandwidth throttling option for users to control the amount of bandwidth the EMC Atmos GeoDrive client is able to consume. Access via HTTP or secure HTTPS. Operating System support: RedHat Enterprise Linux 5.6 and 6.0 (later versions are not supported). SUSE Linux Enterprise Server 10 SP3 and 11 SP1. Windows XP SP3 (32 bit only), Windows Vista SP1 or later (x64 and x86), Windows 7 (x64 and x86). Windows Server 2003 SP2 or later (x64 and x86), Windows Server 2008 (x64 and x86), Windows Server 2008 R2 (x64) Please note that whilst Skyscape can provide access to the Geodrive client, it is a free to use software client that is unsupported by the application developer. For those customers looking to implement a personal storage service, but require an SLA backed solution we can provide advice around commercial solutions. Service description SC-SVC-04, version 5.1 © Skyscape Cloud Services Limited, 2014 Open Personal Storage in the Cloud Page 6 of 13 Open Service options Skyscape provide three Service Levels to choose from: BASIC STANDARD ENHANCED1 Service Level Agreement 99.90% 99.95% 99.99% Protection Level Single copy Local Protection Remote Protection Scalability Unlimited Unlimited Unlimited Retention Configurable Configurable Configurable QinetiQ Protective Monitoring Included for IL3 IaaS Included for IL3 IaaS Included for IL3 IaaS 1 ENHANCED PLUS has greater data durability Backup / Recovery & Disaster Recovery Organisations can choose from a range of protection levels. BASIC data is stored in a single named UK Data Centre with no additional data protection and the most cost-effective price point. This is typically suitable for storing a second copy of data where you can recreate or restore the data from a primary copy in the event of data loss. STANDARD data is stored in a single named UK Data Centre with data protection using EMC GeoParity coding which provides a degree of fault tolerance and so improves data durability. ENHANCED data is stored in two UK sovereign Data Centres, with a copy maintained in a primary named UK Data Centre and copied to a geographically remote UK Data Centre. This provides the highest degree of fault tolerance (including site failure) and corresponding data durability. All service levels also allow for the implementation of versioning which can be useful in allowing data to be reverted to a previous version if the latest version becomes corrupt. Consumers can also implement a Disaster Recovery solution by writing data independently to each data centre at our STANDARD (and BASIC) Service Levels. Service description SC-SVC-04, version 5.1 © Skyscape Cloud Services Limited, 2014 Open Personal Storage in the Cloud Page 7 of 13 Open Service levels Skyscape will use reasonable endeavours to ensure that the availability of the Skyscape service purchased by the Customer in a given calendar month equals the applicable Availability Commitment. To define availability, Skyscape monitors a number of service elements – some generic, some service specific – which collectively enable the Customer to use or access the Service. If the availability of the Service is less than the associated Availability Commitment, the Customer may request Service Credits for the Service within 30 calendar days of the Service being deemed unavailable. For more detailed information on our SLAs, please request the Skyscape SLA Definition Document. Skyscape provide both an Availability SLA and Response Time SLA for Storage as a Service as per the following table. Availability (monthly*) BASIC STANDARD ENHANCED 99.90% 99.95% 99.99% Incident response P1 – within 15 minutes P2 – within 4 hours P3 – within 24 hours P4 – within 72 hours Incident update P1 – hourly P2 – every 2 hours P3 – every 24 hours P4 – every 24 hours Service credits 5% of monthly spend 10% of monthly spend 15% of monthly spend * Availability indication based on an average 730hrs per month. Excludes planned & emergency maintenance. Unavailability applies to existing data where the data becomes inaccessible due to a fault recognised at the IaaS layer or lower: i.e. fault is not within the Consumers control (client applications, user networks, etc). fault is within Skyscape controlled components such as the storage infrastructure, power and physical firewalls & routers etc. External connectivity providers (e.g. internet, PSN, GSi) and components colocated at Skyscape are also not included in the availability calculation. In addition, Skyscape also provide an Availability Service Level Target on the Skyscape Portal i.e. the ability to log into the portal to create support tickets and use other functions. Target Availability (monthly*) Client Portal Availability (monthly) 99.90% Pricing Service Level IL0 IL2 IL3 BASIC £0.11 £0.13 £0.16 STANDARD £0.15 £0.17 £0.21 ENHANCED £0.30 £0.35 £0.37 Service description SC-SVC-04, version 5.1 © Skyscape Cloud Services Limited, 2014 Open Personal Storage in the Cloud Page 8 of 13 Open ENHANCED PLUS £0.42 £0.47 £0.78 Pricing is per GB per month. Ancillary Options The Skyscape Pricing Guide provides a comprehensive catalogue of pricing; including all ancillary service options available to consumers when used in conjunction with Skyscape Compute as a Service. Ancillary options include: Offline facilities to support data ingestion and extraction. Connectivity options including PSN, N3, Internet, data centre interconnect, etc. Other ancillary options are available and can be found in the Skyscape Pricing Guide. Commitment Discount Customers can gain a discount off the standard rates by making a commitment for minimum monthly amounts during a 12 month period. The commitment relates to spend during the period (rather than VM’s or GB’s) as follows: PO Value Discount Level <£250K 0% £250K-£499K 9% £500K-£749K 13% £750K-£1,499k 16% £1,500K + 19% Customers will be required to raise a non-conditional purchase order for the required net amount (after discount) which will entitle them to receive services up to the value of the gross (pre-discount) amount. Customers will be required to break-down the commitment with monthly spend amounts – any amount not consumed within an individual month will not be rolled forward to a subsequent month. Discounts are per purchase order only. Worked Example: If you know that you will spend at least £300,000 per year with Skyscape, you can make that commitment and receive an effective 9% discount. We would require a PO of £273,000 (£300,000 less 9%) which will be payable even if you don’t consume that level of Skyscape services within 12 months. Any consumption in excess of £300,000 will be billable at the standard Skyscape rates unless a new commitment is made. Service description SC-SVC-04, version 5.1 © Skyscape Cloud Services Limited, 2014 Open Personal Storage in the Cloud Page 9 of 13 Open Appendix On-boarding and off-boarding Service constraints On-boarding Skyscape will adhere to the following in terms of maintenance windows; Skyscape will create the consumer’s Primary Administrator account and send the consumer a Welcome Pack which includes the URL for the Storage as a Service API and associated authentication details. The consumer is then able to use these details to configure their application (e.g. GeoDrive, Cloud Tiering Appliance, Documentum, etc) and begin using the service. As Skyscape has two UK DC’s, a consumer can request to be deployed into a specific one at the time of the order if they require. Whilst unlikely to ever be rejected, this remains at Skyscape discretion. Off-boarding Prior to terminating the contract, the consumer is able to transfer all their data out of the solution (e.g. using the Skyscape API to retrieve data). When the organisation terminates their agreement with Skyscape, Skyscape ensures all of the organisation’s data is deleted. Service management As a true Cloud service aligned to the NIST definition of IaaS, the service is designed to be self managed via the secure online Skyscape API and the Skyscape Portal which provides common Service Management functionality and addresses standard requirements. On rare occasions, Skyscape may decide to assign an experienced, qualified ITIL Service Delivery Manager to some Consumers. In these cases, the SDM will provide additional assistance with reporting, incident escalation and continual service improvement, at all times following Skyscape’s ISO20000 certified ITIL-based process framework. For Organisations that require more of a managed service, Skyscape work with a number of Partners which have extensive capability to provide a Managed Service wrapper around the Skyscape IaaS. Skyscape will be pleased to make an introduction where appropriate. Skyscape may use or EMC as a subcontractor. Service description SC-SVC-04, version 5.1 © Skyscape Cloud Services Limited, 2014 “Planned Maintenance” means any pre-planned maintenance of any infrastructure relating to the Services. Skyscape shall provide the Client with at least twenty four (24) hours’ advance notice of any such planned maintenance: Planned maintenance of Skyscape’s infrastructure relating to the Services shall happen between the hours of 00:00 and 06:00 (UK local time) Monday to Sunday and/or between the hours of 08:00 and 12:00 (UK local time) on a Saturday and/or Sunday. No planned maintenance will take place on a Saturday unless agreed in advance by both parties; Planned Maintenance shall be excluded from any availability calculation in regard to service credits but shall be included in the monthly service reporting; “Emergency Maintenance” means any emergency maintenance of any of the infrastructure relating to the Services. Whenever possible, Skyscape shall provide the Client with at least six (6) hours’ advance notice: Whenever possible Emergency Maintenance of Skyscape’s infrastructure will happen between the hours of 00:00 and 06:00 (UK local time) Monday to Sunday and/or between the hours of 08:00 and 12:00 (UK local time)on Saturday and/or Sunday unless there is an identified and demonstrable immediate risk to a Clients environment; Emergency Maintenance shall be excluded from any availability calculation in regard to service credits but shall be included in the monthly service reporting. Training Skyscape have created a number of videos, help guides, manuals and FAQs to help train and instruct users so that are up and running quickly and easily. Skyscape also have a number of Partners who are able to deliver additional services such as training, support and managed services. Skyscape would be pleased to introduce you to such partners where appropriate. Open Personal Storage in the Cloud Page 10 of 13 Open Ordering and invoicing Billing for the service is monthly in arrears. Payment can be via Purchase Order and Direct Debit. Skyscape are preparing to be able to accept Debit/Credit Card payments (e.g. Government Procurement Card) – please enquire at time of order to check whether this is available. Service lead time Setting up a new organisation will typically be completed within 5 days from acceptance of order. Shorter deployment times are typically achieved and can be prioritised upon request. Once set up Organisations have instant access to additional storage resources with no notice period required as they manage this themselves. Termination Terms At the point of termination, all consumer data, accounts and access will be permanently deleted, and will not be able to be subsequently recovered or restored. Costs There are no termination costs for this Service. Consumers are responsible for extracting their own data from the platform if required. Skyscape may make an additional charge for transferring data out of the service. The used of the Geodrive software Client is an example in how customers can access the storage, and whilst Skyscape are able to provide this software, no support or SLA is implied from Skyscape when customers choose to use it. Selecting the appropriate application is the responsibility of the consumer. Management and administration of layers above the IaaS (e.g. the systems that utilise the Storage as a Service platform). As a core benefit of the Cloud Platform, consumers are expected to self-manage the environment including creating and deleting data. Consumers must be aware of the variable nature of the billing based on usage. The consumer is also responsible for ensuring only appropriate data (e.g. IL0-IL2 or IL3) is stored and processed by applications on this environment and that they comply with the Skyscape Security Operating Procedures (SyOps) and other information assurance requirements as specified in Skyscape System Interconnect and Security Policy (SISP) and associated accreditation documentation sets. Financial recompense model If the service level falls below the stated availability percentage (excluding Planned and Emergency maintenance periods), consumers will be eligible for service credits on affected storage only. Service credits will be calculated as a percentage of the fees for the affected services for the monthly billing period during which the failure occurred (to be applied at the end of the billing cycle). Data restoration / service migration For service migration, Skyscape allows existing data to be migrated to and from the platform via the Skyscape API. In many circumstances, Skyscape can help facilitate a bulk migration to the platform using offline data ingest and extraction – please ask Skyscape for details. Service Credit Cap BASIC Service Level 5% of monthly spend 5% of monthly spend STANDARD Service Level 10% of monthly spend 10% of monthly spend ENHANCED Service Level 15% of monthly spend 15% of monthly spend Client Portal 1% of monthly spend per 5% below service level target or part thereof Up to 5% of monthly spend Consumer responsibilities The control and management of access and responsibilities for end users including appropriate connectivity, security and accreditation if required. Where access is required over government secure networks such as N3, GSI or PSN, the consumer is responsible for adhering to the Code of Connection. Service description SC-SVC-04, version 5.1 © Skyscape Cloud Services Limited, 2014 Open Personal Storage in the Cloud Page 11 of 13 Open Technical requirements The consumer is responsible for the procurement or development of the application and the correct implementation of support for the EMC Atmos API or the compatible Amazon S3 API. Consumers have a number of options to choose from with Skyscape to access their environment dependant on their requirement. The list below provides a guide to demonstrate what is possible but may require further engagement with Skyscape to explain and validate further: IL0 – IL2 (Lower security domain) Standard Internet connectivity over common protocols (HTTP, HTTPS, SSH, etc) N3 – for access to the Health and Social Care community. You will be required to complete the N3 Information Governance Statement of Compliance process PSN – You will need to be a PSN Service Provider or a HMG customer that has PSN certification. IL3 (Higher security domain) Preferred connectivity is over a Government Secure Network such as N3, GSI or PSN N3 – for access to the Health and Social Care community. You will be required to complete the N3 Information Governance Statement of Compliance process. (additional controls may need to be implemented to enable N3 access to the higher security IL3 domain) PSN/GSI - You will need to be a PSN Service Provider or a HMG customer that has PSN certification. PSN or CAS(T) Leased Line (IL3 over IL2) o Leased Line (CAS(T) compliant) or nonCAS(T) using CPA/PEPAS overlay encryption Service description SC-SVC-04, version 5.1 © Skyscape Cloud Services Limited, 2014 Open CPA/PEPAS approved solution providing overlay encryption (e.g. Cisco ISR/ASR) IL0 (e.g. Internet or non CAS(T) circuit) to IL3 VPN o Site-to-Site VPN using CAPS approved solutions (e.g. Ultra AEP X-Kryptor) o CPA assured solution where Foundation Grade assurance is appropriate (e.g. Cisco ISR/ASR) IL3 Leased Line (assured network connection) Personal Storage in the Cloud Page 12 of 13 Skyscape Cloud Services Limited A8 Cody Technology Park Ively Road Farnborough Hampshire GU14 0LX +44 (0)1252 303300 info@skyscapecloud.com www.skyscapecloud.com @skyscapecloud © Skyscape Cloud Services Limited. All Rights Reserved. SC-SVC-04