University IT Infrastructure information

Francois Charles made this Freedom of Information request to Glasgow Caledonian University

This request has been closed to new correspondence from the public body. Contact us if you think it ought be re-opened.

The request was successful.

Dear Glasgow Caledonian University,
Under the Freedom of Information Act 2000 may I kindly request the following information about the Universities IT Infrastructure. The information needed is as follows:
IT Compliant Route to purchase
What Frameworks are used for IT Procurement? (ie. SSSNA, NEUPC, Janet, CCS, CPC)?

Desktop
Number of Desktops?
Do you use VDI?
If so what platform do you use?
Desktop major Refresh date?
Date existing support contract ends?
VDI refresh date (if relevant)?

Datacentre
Servers
Number of Windows Servers?
Number of UNIX/Linux Servers?
Server platform?
Virtualisation platform?
What operating system do you use?
Virtualisation & Licence support refresh dates?
Percentage of infrastructure Virtualised?
Server Refresh Date?
Value of current server support contract?

Storage
Volume of Data in TBs
Storage Vendor?
Storage Virtualisation?
Storage Refresh Date?
Date Storage support contract ends?
Value of storage support contract?

Backup
Tape vendor?
Disk backup?
What backup software do you use?
Backup refresh date?
Date backup support contract ends ?
Value of backup support contract ?
Disaster Recovery contract renewal date?

Network
Network vendor?
Do you use Smart Collector?
How many switches?
How many routers?
How many wireless controllers / AP’s?
Network speed?
Network contract start date?
Date Network Support ends / is refreshed?
Value of existing Network support contract?
Network virtualisation?

Security
IT Security vendors used?
IT Security Support renewal date?
Do you use 2FA?
What web and email filtering is used?
What DLP is in place?
What SIEM solution is used?
What intrusion prevention is used?
What endpoint security is used?

Cloud
Are you using or are interested in AWS/Google or Azure for cloud services?
Do you use any Cloud File Storage? If so, what?

Data Destruction
Given the new GDPR Laws taking effect next year………
Is there a Data Destruction Policy in place?
Do you destroy HDD onsite or outsource the service?
Current Supplier of HDD destruction services?
Are they CESG approved and to what level?
Is the HDD wiped / degaussed before leaving your datacentre?
Approx Number of drives destroyed/wiped per annum?

Yours faithfully,

Francois Charles

Freedom of Information Enquiries,

Dear Mr Charles

Glasgow Caledonian University has received your request for information. The University is currently processing this and will get back to you as soon as possible. It will be responded to under the Freedom of Information (Scotland) Act 2002.

Yours sincerely
Linda Reid

Linda Reid
Department of Governance

T: +44 (0)141 273 1451 | F: +44 (0)141 331 8797 | E: [email address]
Glasgow Caledonian University, Cowcaddens Road, Glasgow, G4 0BA,
Scotland, United Kingdom

Freedom of Information Enquiries,

1 Attachment

Dear Mr Charles

I refer to your request for information. The University's response is given below.

IT Compliant Route to purchase

What Frameworks are used for IT Procurement? (ie. SSSNA, NEUPC, Janet, CCS, CPC)?”

•Network Equipment, ITS2001 NEUPC
•Desktop and Notebook (NDNA)
•Apple Equipment and Services (ITS6003 HW)
•IT Peripherals, SP-14-002
•National Workstation Devices, SP-15-011-5
•Desktop Client Devices, SP-15-011-4
•Client Devices, SP-15-011-03
•Mobile Client Devices, SP-15-011-01
•Tablet Client Devices, SP-16-001
•SSNA, ITS4031 SU
•Supplier Guide http://www.gcu.ac.uk/financeoffice/procu...
Desktop
Number of Desktops?
4,512
Do you use VDI?
No
If so what platform do you use?
NA
Desktop major Refresh date?
Year by year basis, depending on age of machine and budget
Date existing support contract ends?
Is this machine warranty?
Supported PCs are purchased with a standard 5 year warranty.
VDI refresh date (if relevant)?
NA

Datacentre Servers
Number of Windows Servers?
324
Number of UNIX/Linux Servers?
82
Server platform?
Mostly Dell Hardware
Virtualisation platform?
Microsoft Hyper-V
What operating system do you use?
Microsoft Windows and Red Hat Enterprise Linux
Virtualisation & Licence support refresh dates?
RedHat 1 year contract, Microsoft 3 year contract
Percentage of infrastructure Virtualised?
73%
Server Refresh Date?
Hardware is procured with 3 years manufacturer’s warranty and is evaluated for replacement after 5 years. No specific refresh date and is evaluated on a case-by-case basis.
Value of current server support contract?
No support contract out with manufacturer warranty, only exception HP1 ~£4k per year

Storage
Volume of Data in TBs
~70 Tb
Storage Vendor?
Dell
Storage Virtualisation?
No
Storage Refresh Date?
Storage will be 5 years old June 2020 and will be considered for replacement/review at that point
Date Storage support contract ends?
5 years manufacturers warrant/support ends June 2020
Value of storage support contract?
Part of initial purchase and not a separate cost

Backup
Tape vendor?
Various based on best price
Disk backup?
Yes, to Dell direct attached storage
What backup software do you use?
CommVault Simpana
Backup refresh date?
Rolling contract
Date backup support contract ends ?
Rolling contract renewed February
Value of backup support contract ?
~£30k
Disaster Recovery contract renewal date?
NA

Network
Network vendor?
CISCO
Do you use Smart Collector?
No
How many switches?
200
How many routers?
50
How many wireless controllers / AP’s?
8/500
Network speed?
1Gb to Desktop
Network contract start date?
Some Core network equipment under support – annual contract (July 2017 – July 2018)
Date Network Support ends / is refreshed?
July 2018
Value of existing Network support contract?
~£90k
Network virtualisation?
No

Security
IT Security vendors used?
McAfee for Anti Virus, Fusemail for email filtering, Trustwave for web filtering
IT Security Support renewal date?
All rolling contracts based on hardware purchase dates
Do you use 2FA?
Currently in pilot. PingFederate MFA.
What web and email filtering is used?
Truswave webfilter, Fusemail email filtering service
What DLP is in place?
None
What SIEM solution is used?
NAGIOS for internal monitoring
What intrusion prevention is used?
Not applicable
What endpoint security is used?
McAfee

Cloud
Are you using or are interested in AWS/Google or Azure for cloud services?
Exploring possibility of Pilot with Azure
Do you use any Cloud File Storage? If so, what?
Onedrive for students as part of Office 365. Exploring possibility of using for staff

Data Destruction
Given the new GDPR Laws taking effect next year……… Is there a Data Destruction Policy in place?
Do you destroy HDD onsite or outsource the service?
Outsourced as part of hardware recycling – recycling is managed by Facilities Management
Current Supplier of HDD destruction services?
CCL (North) Ltd
Are they CESG approved and to what level?
HMG Infosec Standard 5/CESG level.
Is the HDD wiped / degaussed before leaving your datacentre?
No
Approx Number of drives destroyed/wiped per annum?
250 approximately

Please also find attached a review notice setting out the steps you may take if you are not satisfied with the response provided to your request.
If there are any questions in relation to this request, please contact the University at [Glasgow Caledonian University request email].

Yours sincerely
Jean Ash

Jean Ash
Information Compliance, Governance and Records Manager | Department of Governance

T: +44 (0)141 331 3341| F: +44 (0)141 331 8797 | E: [email address]
Glasgow Caledonian University, Cowcaddens Road, Glasgow, G4 0BA,
Scotland, United Kingdom