DISX FAQs
Below you’ll find a list of frequently asked questions about the DISX Secure Collaboration platform, services, capabilities and restrictions.
If your question is not listed, please reach out via email to: sales.disx@logiq.co.uk or by phone: 0117 457 7463 and a member of the sales team will be happy to answer all queries.
About DISX
DISX Secure Collaboration is a managed secure collaboration service designed for organisations working with sensitive information in defence, government and other regulated environments.
It combines Microsoft 365 collaboration capabilities with managed identities, endpoint options, access controls, security monitoring, operational maintenance, assurance and user support. The precise combination of technology, controls and managed services depends on the deployment profile selected and the customer’s agreed scope.
DISX is typically used by organisations operating across defence, government, critical infrastructure and regulated supply chains where sensitive information needs to be shared securely across organisational boundaries.
It can support small specialist teams as well as larger programmes involving multiple organisations and hundreds of users.
No. Defence remains a primary use case, but DISX can also support organisations handling sensitive information in government, critical infrastructure and other regulated or security-conscious environments.
DISX combines collaboration technology with the security controls and operational services required to manage a sensitive working environment.
Alongside Microsoft 365 capabilities, the service can include managed identities, endpoint controls, access administration, protective monitoring, patching, vulnerability management, incident handling, security assurance and ongoing service management.
This means buyers should consider the complete operating model rather than comparing DISX directly with a standard Microsoft 365 subscription or standalone collaboration application.
Pro, Lite and Air are deployment profiles within DISX Secure Collaboration rather than separate service lines.
The appropriate profile depends on the customer’s operational requirements, endpoint model, applications, integrations, assurance requirements and agreed scope.
Security, Assurance and Compliance
DISX Secure Collaboration is designed to support collaboration and workspace operations involving OFFICIAL and OFFICIAL-SENSITIVE information, subject to the relevant operating model, configuration and customer requirements.
DISX incorporates technical and operational controls that can support an organisation’s wider assurance position, including identity and access management, endpoint controls, monitoring and logging, vulnerability and patch management, incident management and ongoing security review.
Its controls and operating model can support requirements associated with Secure by Design and the MOD Cyber Security Model, but the customer’s overall assurance position also depends on its own people, processes, governance and wider technology environment.
No service can guarantee an organisation’s CSMv4 compliance in isolation.
DISX can provide a substantial part of the technical and operational control environment, while the organisation remains responsible for its wider governance, processes, evidence and assurance obligations.
No. DCC certification belongs to the organisation and depends on the scope of its wider security arrangements.
DISX can underpin relevant technical and operational controls, while the customer remains responsible for certification, contractual scope, governance, people, processes and supply-chain arrangements.
No. DISX provides a managed environment and associated security controls, but the customer retains responsibility for its information, users, contractual obligations and organisational governance.
This includes understanding security requirements, managing information ownership and access decisions, notifying Logiq about joiners, movers and leavers, and ensuring appropriate requirements are flowed through the supply chain.
No. Certification is separate from the DISX service itself.
Logiq can provide support relating to Cyber Essentials, Cyber Essentials Plus or DCC independently where required, working alongside the appropriate certification arrangements.
Deployment and Onboarding
Indicative implementation time depends on the deployment profile and customer requirements.
DISX Air and Lite deployments are typically around two to three weeks, while a DISX Pro deployment is typically around eight weeks.
Timings can vary according to endpoint requirements, applications, integrations, prerequisite information and delivery demand.
The onboarding process begins with a prerequisite pack for the customer’s nominated contact.
This captures information such as in-scope users, vetting or clearance details, applications, external collaborators and any required access to services such as r.mil.uk email or MOD Core Network services where these form part of the agreed scope and relevant approvals are in place.
The DISX team then builds and configures the environment. As go-live approaches, activity moves towards user configuration, identity verification, training and communications.
On the agreed go-live date, users receive the credentials and instructions required to access the service.
Customers need to identify the users and organisations requiring access, confirm relevant clearance or vetting information, specify required applications and services, provide collaboration requirements and nominate operational and security contacts.
Bespoke applications may also require licences, installation media or input from third-party suppliers.
Delays most commonly occur when prerequisite information, licences, application media, user details or clearance information are unavailable when needed.
More complex environments can also take longer where bespoke applications or integrations need to be designed and introduced.
Having a clear customer-side owner and a complete view of users, devices, applications and collaborating organisations helps make deployment easier to plan.
Yes. Go-live is the point at which the agreed service becomes operational for the in-scope users.
Users can authenticate, access the agreed functionality and begin working in the environment without a separate post-deployment waiting period.
Yes. Customers can choose a single go-live or introduce users in phases by project, programme or business unit.
The most appropriate approach normally depends on internal readiness, training, device distribution and programme requirements.
External Organisations and Collaboration
Yes. External organisations can be identified during the initial onboarding process so that approved collaboration arrangements can be prepared as part of deployment.
This allows DISX to support programmes where work crosses organisational and supplier boundaries.
Yes. New collaboration arrangements can be requested through the customer portal.
The DISX service desk works with the customer security assurance function to obtain the information and evidence needed to determine whether the external environment is appropriate to connect.
These requests can typically be completed within a few working days where the required information and evidence are available.
In many cases, yes.
A supplier may be able to use an existing device to access a virtual DISX endpoint through the Windows App or a supported browser.
The suitability of this approach depends on the information being handled, the customer’s assurance obligations and the wider Cyber Essentials, Cyber Essentials Plus or DCC scope.
Where the existing endpoint cannot meet the required control or assurance expectations, a managed physical endpoint may be more appropriate.
Yes, where approved and subject to the relevant security controls, information-handling requirements and destination.
DISX applies controls designed to support authorised information exchange while reducing the risk of sensitive information being shared with inappropriate systems or destinations.
Devices and Access
Yes, depending on the deployment model.
An existing physical device can be used as the access device for a virtual DISX endpoint through the Windows App or a supported browser.
The use of an existing device does not remove the need to consider the security and compliance implications of that device within the wider assurance boundary.
No.
A managed physical endpoint may be appropriate where the organisation cannot apply the required controls to its existing corporate device, where the physical device needs to form part of a Cyber Essentials or Cyber Essentials Plus boundary, or where contractual or DCC requirements make a dedicated managed device the clearer option.
Both physical and virtual endpoint models can be appropriate depending on the customer’s wider control boundary and user requirements.
A virtual endpoint provides access to the DISX environment without requiring a separate physical DISX device in every scenario.
Users connect from an approved access device using the Windows App or a supported browser, with the suitability of the model determined by the security, information-handling and assurance requirements.
No. Each Cloud PC is provisioned for an individual user.
USB and removable-media use depends on the deployment profile and applicable security controls.
In some environments, removable media may be restricted or managed through approved secure devices.
Before first access, users complete an identity-verification process.
The customer provides the user’s details and confirms the relevant vetting position. The user then completes the required verification steps before access to the service is enabled.
Access can be revoked immediately once an authorised request reaches the service desk.
This supports urgent leaver, role-change and security-incident scenarios.
Customers remain responsible for notifying Logiq when someone joins, changes role or leaves.
Permission management is shared between Logiq and the customer.
The service desk can process approved access requests for Microsoft Teams, SharePoint areas, folders and other information stores. Customers can also be enabled to manage access within their own Teams and SharePoint environments.
The customer’s information owners remain responsible for determining who should have access and maintaining appropriate membership.
Applications, Integration and Scaling
Additional applications can be supported where appropriate following technical, operational and security assessment.
Bespoke applications or integrations may require additional design, licensing, installation media or third-party input.
Yes, where there is a valid operational requirement.
DISX can be integrated with existing on-premises environments or specialist operational systems, but these requirements are assessed and designed individually because legacy and operational environments vary significantly.
Yes.
Individual users can be added through routine service requests, while larger expansions can be handled as planned bulk activities.
DISX supports environments ranging from small specialist teams to deployments involving hundreds of users.
Yes. Additional users and services can normally be added during the contract term.
Commercial arrangements can also be structured with agreed capacity to make expansion easier where customer requirements are expected to change.
No. Microsoft Project and Visio are available as additional licence options where required.
Service Management and Support
DISX is managed by appropriately vetted and security-cleared Logiq personnel.
The managed service includes administration and support, operational maintenance, patching, vulnerability management, security assurance coordination and 24/7 security operations monitoring.
Customers also have access to service delivery and customer-success functions to address operational issues, performance and evolving requirements.
Security is treated as an ongoing activity rather than a one-off deployment exercise.
Logiq reviews relevant security notices, MOD and industry guidance, customer requirements and the ongoing performance of the service.
Changes in Microsoft technology and the DISX roadmap are also reviewed to determine whether controls or service arrangements should be updated.
DISX operates within Logiq’s ISO 20000-1 certified service-management system.
Users can raise issues by phone, email or the web portal. The service desk aims to resolve issues at first contact where possible.
Where specialist input is needed, incidents are escalated to the appropriate technical team for further investigation, root-cause analysis and resolution within the applicable service levels.
A lost or stolen device is treated as a security incident.
The appropriate incident-response process is invoked and the DISX team works with the customer’s security contact to manage the risk, protect the service and complete any required investigation and reporting.
A DISX-managed device can be rebuilt for another authorised user, securely wiped and returned to the customer environment, or sanitised for another approved form of reuse or disposal.
The user’s account and access are handled separately to ensure that the departing user can no longer access the service or its information.
DISX brings together identity management, endpoint options, access administration, security monitoring, maintenance, vulnerability management, assurance and support within one managed service.
This means customers do not need to design, assemble and operate every component of the secure collaboration environment independently.
The customer retains responsibility for its information, people and organisational obligations, while Logiq manages the agreed technical and operational service.
