MaxIron Cloud
MAS environments operated to one build standard.
Dedicated IBM Maximo Application Suite environments on AWS, Azure or Oracle Cloud Infrastructure, operated by named MaxIron engineers under ISOQAR certificate 27274. The tables below are the ones a scoping paper needs: who operates what, which regions, which recovery figures, and who signs before anything reaches production.
The responsibility split
Eight rows, and the contract is written against them
This is the shared responsibility model in the form a reviewer can quote. The third column is the one that decides whether the service fits your operating model.
| Ref | Layer | MaxIron operates | You keep |
|---|---|---|---|
| R1 | Identity and access | Your identity provider federated to MAS, group and site mapping maintained, privileged access held by named MaxIron engineers under multi-factor authentication. | Who is entitled to what. Every access grant is approved by your named access owner. |
| R2 | Patching | Operating system, OpenShift and database patch sets on a calendared path. Maximo fix packs and security patches in line with the IBM support timeline. | The maintenance window, and any freeze period your operation requires. |
| R3 | Encryption and keys | Encryption in transit and at rest, TLS certificates issued and renewed, key rotation on the documented schedule. | Any requirement for customer-managed keys, stated before build. |
| R4 | Network configuration | Private connectivity to your corporate network, VPN with IP allow-listing, ingress and egress rules held as configuration. | The addresses, circuits and firewall changes on your side of the boundary. |
| R5 | Monitoring and incident response | Availability, response times, interface queues, job outcomes and capacity, with thresholds per environment. Incidents classified P1 to P4, P1 carrying a one-hour acknowledgement target. | The journeys you cannot lose, named by you so they are watched as work rather than as hosts. |
| R6 | Backup and restore testing | Backups taken to policy and proven by restore into a scratch environment, at minimum semi-annually per production environment. | Retention beyond policy where a regulator requires it, agreed in the service description. |
| R7 | Production configuration change | Packaged, exercised in a lower environment, promoted by pipeline, versioned and reversible. | The approval. MaxIron does not approve changes to your estate on your behalf. |
| R8 | MAS release and upgrade path | A calendared wave on a known path, rehearsed in non-production, with the regression pack run before production. | The date, and the business validation of the release before it goes live. |
Codes R1 to R8 are stable, so a reviewer can cite one by reference in a questionnaire. The control-level version is in the responsibility matrix below.
Specification
Platform, regions, recovery and assurance
Platform
- Cloud platforms
- AWS, Microsoft Azure and Oracle Cloud Infrastructure, chosen per estate.
- Tenancy
- Dedicated environments per customer. Operated only by named MaxIron staff.
- Versions operated
- IBM MAS 8 and MAS 9, and Maximo 7.6 on the extended support track.
- Provisioning
- Non-production typically within hours of access and commercial prerequisites. Production follows an agreed runbook with security sign-off.
Regions and residency
- Default residency
- United Kingdom and Ireland.
- AWS
- eu-west-2 London, eu-west-1 Ireland.
- Azure
- UK South, North Europe.
- Oracle Cloud
- UK South, EU Frankfurt.
- Other regions
- Agreed per customer and named in the service description.
Recovery and retention
- Restore testing
- Minimum semi-annual per production environment, result kept as evidence.
- Recovery objectives
- Set per environment class and contracted in the service description. Our standard production starting point is a 15-minute recovery point and a 4-hour recovery time, illustrative until agreed against your estate.
- Audit log retention
- Cloud audit logs retained for 12 months.
- Incident classes
- P1 to P4 with response targets. P1 acknowledgement target one hour.
Assurance
- Certification
- ISO/IEC 27001:2022 and ISO 9001:2015, ISOQAR certificate 27274.
- Control coverage
- Statement of Applicability addressing all 93 Annex A controls, including A.5.30 for ICT recovery.
- Threat detection
- AWS GuardDuty, Azure Defender or OCI Cloud Guard on every active environment.
- Sub-processors
- Published by name and region on the Trust Centre, with 30 days notice of change under the data processing agreement.
Regions, retention, incident classes and certification are as published on the MaxIron Trust Centre. The recovery point and recovery time figures are our standard production starting point, illustrative until they are agreed against your environment list and written into the service description.
The signature ledger
What crosses into production, and who signs for it
Six movements, each with a direction and a signature. Two of them are ours to sign and four are yours, which is the distribution serious buyers ask about in the second meeting.
| What moves | From | Direction | To | Signed by |
|---|---|---|---|---|
| Configuration release | MaxIron non-production | → | Your production estate | Your change authority, in the Portal |
| Platform patch set | MaxIron change forum | → | Your production estate | Your change authority, on the calendared window |
| Break-fix on the platform layer | MaxIron duty engineer | → | Your production estate | MaxIron duty engineer, under standing authority in the service description |
| Access grant or revocation | Your access owner | → | MAS security groups | Your named access owner |
| Restore test copy | Production backup | ← | Scratch environment | MaxIron platform engineer |
| Evidence pack | MaxIron Portal | ← | Your auditor | Your accountable officer |
What never crosses
- A change to your estate configuration promoted without an approval recorded against the change.
- Production data copied into a non-production environment without a masking step agreed in writing.
- Third-party operator access. Every operator is named MaxIron staff inside the certified management system.
The line that decides the contract
Three decisions stay with your team: what the estate is for, who has access, and which changes go live. The work that exists because somebody has to be awake sits with us.
You read the same incident and change records we work from, in the MaxIron Portal, while they are still open. Approval of production change stays on your side of the boundary at every hour of the day.
For the assurance pack
The MaxIron Cloud responsibility matrix
9 pages, PDF
- R1 to R8 expanded to control level, with the ISO/IEC 27001:2022 Annex A control against each
- The region and sub-processor map for the residency you are considering
- Backup schedule, restore test cadence and the evidence retained from each test
- Incident classes P1 to P4 with response and update targets, and the escalation path
Sent by email to a named contact, with no gated form. Certificate 27274 and the sub-processor list are already public on the Trust Centre.
Division of responsibility
Four boundaries on an operated estate
Each one is worth settling before signature rather than in month three.
The operating model is yours to set
Asset hierarchy, criticality, work management process and planning discipline. We advise and evidence, you decide and own. Where the process itself is the constraint, that work is scoped under business process optimisation.
The accountable officer is yours to appoint
We produce the change history, the SLA measurement and the evidence pack your auditor asks for. Your officer explains the estate in their own words.
Counterparty systems stay with their own teams
SAP, finance, GIS, historians and field systems keep their own windows. We operate the interface, replay the backlog and report what we find at the boundary, under Maximo integrations.
What we operate has to promote through the pipeline
Bespoke code that cannot build, test and promote is modernised first, under customisation modernisation. Where you keep it as it stands, we price that decision explicitly. Entitlement is sized separately under MAS AppPoints licensing.
MaxIron Cloud, questions procurement and security ask
- What does MaxIron operate, and what stays with our team?
- Rows R1 to R8 above are the whole answer, and they are the rows we contract against. MaxIron operates identity, patching, encryption, network configuration, monitoring, backup and the release path. Your team decides what the estate is for, who has access, and which changes go live.
- Who operates the estate day to day?
- Named MaxIron engineers on a duty rota, inside the ISO/IEC 27001:2022 management system certified under ISOQAR certificate 27274. Privileged access is restricted to a small number of named individuals under multi-factor authentication, and access is revoked within five business days of any personnel change.
- Where is our data hosted?
- Default residency is the United Kingdom and Ireland: AWS eu-west-2 London and eu-west-1 Ireland, Azure UK South and North Europe, or Oracle Cloud UK South and EU Frankfurt. Alternative regions are agreed per customer and named in the service description. Each sub-processor is listed by name and region on the Trust Centre.
- What are the recovery objectives?
- Recovery point and recovery time objectives are set per environment class and contracted in the service description, because a training environment and a control-room production estate do not warrant the same figures. Restore testing runs at minimum semi-annually per production environment and the result is kept as evidence. Any figure quoted before your environment list exists is illustrative.
- How quickly can a MAS environment be provisioned?
- Non-production environments are typically available within hours once commercial and access prerequisites are met. Production follows an agreed runbook including security sign-off and connectivity to your corporate network and identity provider.
- How do we see what is happening on our own estate?
- Through the MaxIron Portal: the same health, incident and change records our engineers work from, the approval queue for production change, and the monthly service report. The products operating underneath are listed on MaxIron products.
Bring your environment list to the first call.
Ninety minutes against the eight rows above. We mark each one as MaxIron-operated, retained by you, or unresolved, and you leave with the responsibility boundary written down and the residency question settled.
What to bring to the estate review
- The environment list: production, non-production, and the ones nobody has closed
- MAS version, or the Maximo version you are moving from, and the modules in scope
- The interfaces that must work on day one, and who owns each counterparty system
- Your residency requirement and the control frameworks your auditor names