University IT Infrastructure information

Roedd y cais yn rhannol lwyddiannus.

Francois Charles

Dear Buckinghamshire New University,

Under the Freedom of Information Act 2000 may I kindly request the following information about the Universities IT Infrastructure. The information needed is as follows:

IT Compliant Route to purchase?
What Frameworks are used for IT Procurement? (ie. SSSNA, NEUPC, Janet, CCS, CPC)?

Desktop
Number of Desktops?
Do you use VDI?
If so what platform do you use?
Desktop major Refresh date?
Date existing support contract ends?
VDI refresh date (if relevant)?

Datacentre
Servers
Number of Windows Servers?
Number of UNIX/Linux Servers?
Server platform?
Virtualisation platform?
What operating system do you use?
Virtualisation & Licence support refresh dates?
Percentage of infrastructure Virtualised?
Server Refresh Date?
Value of current server support contract?

Storage
Volume of Data in TBs
Storage Vendor?
Storage Virtualisation?
Storage Refresh Date?
Date Storage support contract ends?
Value of storage support contract?

Backup
Tape vendor?
Disk backup?
What backup software do you use?
Backup refresh date?
Date backup support contract ends ?
Value of backup support contract ?
Disaster Recovery contract renewal date?

Network
Network vendor?
If you use Cisco, do you use Smart Collector?
Network speed?
Network contract start date?
Date Network support ends / is refreshed
Value of existing support contract ?
Network virtualisation?

Security
IT Security vendors used?
IT Security Support renewal date?
What web and email filtering is used?
What DLP is in place?
What SIEM solution is used?
What intrusion prevention is used?
What endpoint security is used?

Cloud
Are you using or are interested in AWS/Google or Azure for cloud services?
Do you use any Cloud File Storage? If so, what?

Data Destruction
Is there a Data Destruction Policy in place?
Do you destroy HDD onsite or outsource the service?
Current Supplier of HDD destruction services?
Is the HDD wiped / degaussed before leaving your datacentre?
Approx Number of drives destroyed/wiped per annum?

Thanking You
Yours faithfully,

Francois Charles

Francois Charles

Dear Buckinghamshire New University,

Please could you update me on this request?

Many thanks
Francois Charles

FOI Officer, Buckinghamshire New University

Dear Francois,

Thank you for your email. May you please provide the date your original request was sent?

Kind regards,

FOI Officer________________________
Buckinghamshire New University
Queen Alexandra Road
High Wycombe, Buckinghamshire HP11 2JZ

Dear FOI Officer,

The original FOI request was sent to you on 10th August 2017

Thank You
Francois Charles

Dear FOI Officer,

Happy New Year!
As this FOI request has still not been resolved please may I ask for you to supply me with some alternative dates on which I may come to your offices to conduct an internal review into this FOI request. I am not far from the University and can be available most times.
Thank you

Francois Charles

Nicholas Roussel-Milner, Buckinghamshire New University

Dear Francois

 

Thank you for your email dated 2^nd January 2018 requesting an internal
review to be initiated regarding your FOI request about the University's
IT infrastructure (BNUFOI-10082017).

 

I apologise for the circumstances which have led you to make this
compliant.

 

We aim to deal with complaints promptly and requests for reviews will be
handled in line with current guidance from the Information Commissioner's
Office.  We will try to complete all internal investigations and reviews
within 20 working days following the date of receipt of your complaint.

 

We will write to you if it becomes evident that the response cannot be
provided within this timeline and to indicate when the response is likely
to be issued.

 

After we have concluded the internal review and formally responded to you,
if you still feel your complaint has not been dealt with sufficiently, you
can complain to the Information Commissioner's Office. Full contact
details for the Information Commissioner's Office are available on their
website (https://ico.org.uk/).

 

Please do not hesitate to contact me if you have any queries about this
internal review.

 

Kind regards

 

Nicholas Roussel-Milner

Director of Information Systems & Technology

Buckinghamshire New University

Queen Alexandra Road

High Wycombe, Buckinghamshire HP11 2JZ

 

Telephone: 01494 522141 ext 5064

[mobile number]

Email: [1][email address]

 

Clarity Openness Respect Delivery on commitments

 

References

Visible links
1. mailto:[email address]

Dear Nicholas Roussel-Milner,
Thank you for your reply. I eagerly await your conclusion/information pertaining to this issue
Yours sincerely,
Francois Charles

Dear Nicholas Roussel-Milner,
Further to your response on 5th January 2018, please could you update me on the progress of this FOI request?

Yours sincerely,
Francois Charles

Nicholas Roussel-Milner, Buckinghamshire New University

Dear Francois

 

Thank you for your email.

 

We are progressing the internal review and I am confident that we will be
able to respond to you within the 20 working days (30^th January 2018).

 

In the meantime please do not hesitate to contact me if you have any
queries about the internal review.

 

Kind regards

 

Nicholas

 

Nicholas Roussel-Milner

Director of Information Systems & Technology

Buckinghamshire New University

Queen Alexandra Road

High Wycombe, Buckinghamshire HP11 2JZ

 

Telephone: 01494 522141 ext 5064

[mobile number]

Email: [1][email address]

 

Clarity Openness Respect Delivery on commitments

 

From: Francois Charles [mailto:[FOI #424609 email]]
Sent: 16 January 2018 13:08
To: Nicholas Roussel-Milner <[email address]>
Subject: Re: University IT Infrastructure information BNUFOI-10082017-
FOIA Internal Review

 

Dear Nicholas Roussel-Milner,
Further to your response on 5th January 2018, please could you update me
on the progress of this FOI request?

Yours sincerely,
Francois Charles

dangos adrannau a ddyfynnir

FOI Officer, Buckinghamshire New University

2 Atodiad

Dear Francois,

 

Thank you for your FOI request. Please see the University’s response
below.

[1]---

IT Compliant Route to purchase? 

What Frameworks are used for IT Procurement? (ie. SSSNA, NEUPC, Janet,
CCS, CPC)? JISC, G-Cloud, SLRA, SSSNA

 

Desktop

Number of Desktops?  1024

Do you use VDI? No

If so what platform do you use? N/A

Desktop major Refresh date? Rolling 1/4 per year

Date existing support contract ends?  Standard 3 year manufacturer
warranty

VDI refresh date (if relevant)? N/A

 

Datacentre

Servers? 279

Number of Windows Servers? 174

Number of UNIX/Linux Servers? 37

Server platform? x64; x86

Virtualisation platform? VMware

What operating system do you use? Microsoft Windows Server 2008; Microsoft
Windows Server 2012; Microsoft Windows Server 2016; CentOS; Suse Linux
Enterprise 11; Debian 6 Virtualisation

Licence support refresh dates? 05/2020

Percentage of infrastructure Virtualised? 80%

Server Refresh Date? 10/2020

Value of current server support contract? We are unable to provide
contract information individually for the sections relating to Datacentre,
Storage and Backup as we do not hold the contract information in this way

 

Storage

Volume of Data in TBs? 12TB

Storage Vendor? NetApp

Storage Virtualisation? Yes

Storage Refresh Date? 10/2020

Date Storage support contract ends? 10/2020

Value of storage support contract? We are unable to provide contract
information individually for the sections relating to Datacentre, Storage
and Backup as we do not hold the contract information in this way

 

Backup

Tape vendor? No tape backup

Disk backup? Yes

What backup software do you use? NetApp SnapProtect; Quest vRanger

Backup refresh date? 10/2020

Date backup support contract ends ? 10/2020

Value of backup support contract ? We are unable to provide contract
information individually for the sections relating to Datacentre, Storage
and Backup as we do not hold the contract information in this way

Disaster Recovery contract renewal date? No specific disaster recovery
contract in place

 

Network

Network vendor? Cisco

If you use Cisco, do you use Smart Collector? No

Network speed? 1GB to desktop

Network contract start date? 09/2015

Date Network support ends / is refreshed? 09/2020

Value of existing support contract ? £53,000.00

Network virtualisation? No

 

Security

IT Security vendors used? Sophos; Cisco; Mimecast

IT Security Support renewal date? No contract for IT security support

What web and email filtering is used? Sophos for web filtering; Mimecast
for email filtering

What DLP is in place? Sophos; Mimecast

What SIEM solution is used? Splunk

What intrusion prevention is used? Cisco

What endpoint security is used? Sophos

 

Cloud

Are you using or are interested in AWS/Google or Azure for cloud services?
Azure

Do you use any Cloud File Storage? Yes

If so, what? Office 365; Azure

 

Data Destruction

Is there a Data Destruction Policy in place? Yes

Do you destroy HDD onsite or outsource the service? Both

Current Supplier of HDD destruction services? Shred-it

Is the HDD wiped / degaussed before leaving your datacentre? Yes

Approx Number of drives destroyed/wiped per annum? 100

 

[2]---

Kind regards,

 

FOI Officer________________________

Buckinghamshire New University

Queen Alexandra Road

High Wycombe, Buckinghamshire HP11 2JZ

 

References

Visible links

Nicholas Roussel-Milner, Buckinghamshire New University

Dear Charles

 

Thank you for your request dated 2^nd January 2018 for an internal review
of the Bucks New University’s response to your earlier request under the
Freedom of Information Act 2000 (FOIA) about the organisation’s IT
infrastructure, which was given the reference BNUFOI-10082017 and dated
10th August 2017.

 

The internal review has been completed and has concluded that information
in response to your request was not disclosed within 20 working days
stipulated by the FOIA.  I apologise for this and for any inconvenience
caused.

 

The information in response to your request was sent to you on 18^th
January 2018.

 

Please do not hesitate to contact me if you have any queries about the
internal review.

 

As you will be aware, if you remain dissatisfied with the University’s
response, you have the right of appeal to the Information Commissioner at:
The ICO, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Details
of the appeal procedure can be found on the ICO website:
[1]http://www.ico.org.uk.

 

Kind regards

 

Nicholas

 

Nicholas Roussel-Milner

Director of Information Systems & Technology

Buckinghamshire New University

Queen Alexandra Road

High Wycombe, Buckinghamshire HP11 2JZ

 

Telephone: 01494 522141 ext 5064

[mobile number]

Email: [2][email address]

 

Clarity Openness Respect Delivery on commitments

 

References

Visible links
1. http://www.ico.org.uk/
2. mailto:[email address]

Dear Nicholas Roussel-Milner,

Thank you for the information, albeit very "limited in reality"

As an FYI - you may want to alert the University Compliance Committee that there is no feasible explanation for University of your size having only 12TB of storage in your datacentre. Where is the rest of the Universities storage? Is it in the Cloud? Is the storage replicated? Are there any processes in place to allow for the secure storage of Critical information pertaining to Universities core business? This could only mean one thing: Information is not been protected / stored as per European regulations and has somehow either gone missing or not been properly stored as most other Universities of your size regularly do. This in turn does not constitute Value for money from a Tax payers perspective. (Printer controllers alone will end up with more storage over a prolonged period than you have indicated.)

The information you have provided will of course be accessible to the wider community who regularly use this portal as well as prospective suppliers and I am sure that they will find this quite surprising.

Once again , thank you for the information
Yours sincerely,
Francois Charles