2013
University Information Technology Services
System Assurance Group
Server Co-location Agreement
This document represents an agreement between a client and UITS for server co-location in Indiana University Data Centers. The responsibilities and services provided are outlined which include: equipment installations, data center access and operational procedures.

University Information Technology Services

at Indiana University

SERVER CO-LOCATION Agreement

Last updated 9/10/13

Definitions

ACF: Advanced Cyberinfrastructure Facility (IU Data Centers at IU and IUPUI)

UITS: The party providing service within the ACF.

Client: The IU party receiving service through UITS.

OVERVIEW

This document describes the server co-location services that University Information Technology Services will provide. Departments can lease physical space in the Data Centers for their servers as a transition strategy to standard options provided by UITS that improve efficiency and reduce environmental impact:

·  Virtualization: Intelligent Infrastructure (II) is the recommended path for departmental web, application, and database servers. Moving to IU's virtual environment achieves benefits of hardware efficiencies, reduced environmental impact, and increased flexibility to respond quickly to changing service needs. For more, see IU Intelligent Infrastructure services.

·  Consolidation: A computing condominium service provided by IU's Research Technologies (RT) consolidates physical servers and components into fewer physical entities, achieving economies of scale, and allowing greater flexibility for shifting resources from one application area to another.

UITS will support co-location through current equipment lifecycles, and help devise migration plans to the preferred options. To protect the finite power and cooling capacity, the UITS System Assurance Group (SAG) has final approval for co-location agreements, and will determine the priority for acceptance if multiple requests are pending. The SAG will work with departments to best use the capacity at hand.

The document may be updated or canceled only with the written consent of both parties. The term of this document is for one (1) fiscal year and must be renewed on an annual basis. UITS will not charge or refund for a partial month. Charges will be applied monthly.

ENVIRONMENTAL:

Machine Room environmental services and security in the ACF will be provided by UITS as follows:

Power Backup: UPS service and generator backup are provided as a secondary source of power in the event of utility power failure. UPS service is designed to provide power for seamless transition to an emergency generator. In the event of a lengthy power failure the generator can be refueled as necessary and can be run indefinitely until power is restored. UITS may determine that it is not in the University’s best interest to run the generator for extended periods if power has not been restored and every effort to inform the client will be made.

Fire Protection: Fire suppression is provided via dry pipe, pre-action, sprinkler system in accordance with Indiana University risk management policy. All other fire protection is provided in accordance with Indiana University policy and procedure and Indiana state code.

Cooling: Air conditioning is provided via chilled water coils in computer room air conditioner (CRAC) units.

ACF Indianapolis - the primary source of chilled water is campus (CTE) water with a dedicated backup chiller in case of a loss of primary supply.

ACF Bloomington - dedicated chilled water plant with redundant chillers and cooling towers.

1.  Client will accept and verify that appropriate environmental protections, including power, cooling, fire protection, and uninterruptible power supply, have been provided by UITS.

2.  Client will follow shipping/receiving and storage (equipment, supplies, boxes, etc.) guidelines set forth and provided by UITS.

3.  Client will coordinate their installation activities, including any temporary need for secure storage, with UITS.

4.  Client is responsible for removing debris, supplies, etc. from the area after installation. Only the equipment can be stored in the rack.

5.  Client will be assessed a de-installation fee (not to exceed $500.00) at the end of this agreement. This charge is to cover removal of power, network cables and replacement of floor tile.

SECURITY/ACCESS PROVISIONS:

Security System: Video cameras digitally record activity at each machine room entrance door. Access through the machine room doors are provided to those individuals who possess an authorized proximity card. Proximity card logs are retained for 365 days. Given the sensitive nature of the facility, it is important that access only be granted to those that enter the card-protected areas frequently (i.e., daily or nearly daily). For non-regular visitor access, the procedures outlined in the “Data Center Access Guidelines” document should be followed.

UITS will activate and provide proximity cards per agreement. Additional cards can be requested and will be charged $20 per proximity card. UITS personnel will activate and deactivate proximity card access per the instruction of clients Management.

1.  Clients agree to operate within the security and access policies and procedures of the ACF. This includes access limitations and sign-in procedures. A copy of these procedures will be provided by UITS and updated on a periodic basis.

2.  Clients will provide UITS with a list of personnel who are authorized for access.

3.  Upon termination of this agreement or the resignation/termination of staff it is the clients responsibility to notify UITS of staff changes. UITS will immediately deactivate card access priviledges.

4.  Clients that occupy an entire rack and/or require isolation from shared rack space may install additional physical rack security measures at their own cost, provided these measures have been reviewed and approved by UITS in advance. Examples of such measures include cameras, locked racks, and rack door sensors. If client chooses additional methods then UITS must also have access onsite, i.e. keys for locked racks in case of an emergency.

DATA NETWORK PROVISIONS

All cabinets will have network switches installed at the top of the cabinet to provide 10/100/1000 Mbps Ethernet connections into the ACF switching infrastructure. (10000 Mbps available and priced on an individual request) All public and private Ethernet connections are provided by UITS unless very special circumstances are reviewed and approved by Network Engineering and Campus Network Infrastructure.

1.  Client will not deploy switching gear or other networking devices in their rack unless some specific exception is requested, documented and granted by UITS.

2.  All servers will be place behind the ACF firewall.

EQUIPMENT:

Server rack space will be assigned and all servers will be installed in the standard cabinets provided by UITS unless the server manufacturer specifically dictates the equipment must be housed in their proprietary cabinet. Proof of vendor requirements for the proprietary cabinet will need to be submitted to UITS. Such cabinets should have front, back, and side panels. Doors on the cabinet must be closed when no one is working in the unit. Server racks should not exceed 5 kW per rack. (additional cost to be applied based on power consumption)

1.  Clients will provide a space plan to UITS. The space plan will include the number of servers, equipment, storage devices, and other devices having space and power considerations. UITS will approve these plans before Clients begin installing equipment.

2.  Clients will be responsible for delivery arrangements of equipment to the ACF and notifying UITS of the delivery date. Clients are responsible for all costs associated with this process and are liable for any equipment damaged during transportation.

3.  Clients are responsible for the installation of the equipment in the racks and retain responsibility for the equipment and liability for any damages to that equipment during the installation and through the initial power up process. After installation, UITS assumes responsibilities as outlined in this agreement.

4.  Clients will adhere to the “Data Center Standards” document.

5.  All servers in the ACF are expected to be administered in a secure manner using industry best practices IT Policy 12 including employment of host based firewalls and to be operated behind the ACF firewall. Clients agree to provide UITS with firewall rules which restrict incoming traffic to include only those protocols, ports, and properly sourced packets as needed for operation of each server.

6.  Clients will not store cardholder data on equipment without compliance to Payment Card Industry Data Security Standards (PCI DSS). The PCI DSS security requirements apply to all system components. In the context of PCI DSS, ―system components‖are defined as any network component, server, or application that is included in or connected to the cardholder data environment. ―System components‖also include any virtualization components such as virtual machines, virtual switches/routers, virtual appliances, virtual applications/desktops, and hypervisors. The cardholder data environment is comprised of people, processes and technology that store, process or transmit cardholder data or sensitive authentication data. If there is a exception to process cardholder data you must be compliant with the PCI DSS. This will require review and approval from UISO and the IU Office of the Treasurer.

DISASTER RECOVERY:

The current UITS disaster recovery plan for the ACF does not include replacement of co-located systems. Systems in the ACF are not insured by UITS. In the unlikely event that the ACF is substantially damaged or destroyed, UITS will make a best effort to restore services starting with those systems critical to the business needs of the University. Co-located systems remain the responsibility of their owners. Should the ACF be disabled, but owners' systems remain undamaged, UITS will attempt to find an acceptable alternate site or return the systems temporarily to their owners. UITS may be able to assist owners with disaster recovery planning.

UITS cannot be responsible for system owner's business continuity or any losses directly or indirectly associated with use of UITS co-location services.

OPERATIONAL SUPPORT:

1.  UITS will provide contact information to Clients for use in requesting “eyes and hands” assistance with Clients’ equipment when problems arise. System monitoring and failure notification will be provided by UITS operations staff on site 24 x 7 x 365. There are no service level guarantees for the availability of such resources.

2.  Clients will provide contact information to UITS for use in notifications.

3.  UITS will provide timely notification to Clients for planned and unplanned outages of power and/or cooling.

4.  UITS will make a good faith effort to provide workstation space to Clients. However, the amount of space available to Clients may be minimal. Clients should plan accordingly.

5.  Clients will provide timely notification to UITS for all activities and agrees to coordinate with UITS Data Center Operations for any rack space changes.

6.  Clients will not sublet rack space or resale the functional equivalent the service to another project, department, or third party.

Service / Monthly Rates / One-time Charges
Server Co-location / Rack Space:
One Rack Minimum (42U’s): $362.30 ($4,347.63 / yr.)
Rack U: $8.63 ($103.51 / yr.) / Power cord cost and installation approx. $300.00 / cord.
Floor tile cutout $150.00
Additional proximity cards $20.00 / each.
De-installation fee not to exceed $500.00
**NOTE: These charges are estimates; actual cost will be incurred by client.

Rate Definitions

Rack Space – The rack space is assigned for the server co-location. The rack space may not be continuious and could possibly be shared with other co-location customers. Rate includes standard power consumption, uninterruptible power supply, air cooling charges, environmental monitoring, and Enterprise Infrastructure Operations Group support for system monitoring, incident reporting and notification 24x7.

Rack U – There is a one rack minimum charge. Once a customer exceeds one rack (42 U’s) the charge will be per rack U for the additional space.

One-time

Setup Charges

Date ______

Customer Name ______

Customer Contact ______

System Name ______

Special Power Cords/Receptacles ______

Hardware Setup Charges ______

Floor Tile Cut-Out Charges ______

Total Setup Charges ______

Account Number ______

Customer Signature ______

UITS Signature ______

Annual Charges

Fiscal Year 13/14

Date ______

Customer Name ______

Customer Contact ______

System Name ______

System Size (in rack space units) ______

Rack Space – Supported Charges ______

Total Annual Charges ______

Account Number ______

Customer Signature ______

UITS Signature ______