FAQs
This section is dedicated to answering FAQs (frequently asked questions) about Polo Strategico Nazionale. Review the information here and contact us if you have any further questions.
About us
What is Polo Strategico Nazionale?
Polo Strategico Nazionale is a newly established company owned by: TIM; Leonardo; the Cassa Depositi e Prestiti/CDP (Italian Savings and Loan Fund), through its subsidiary CDP Equity; and Sogei (Società Generale d’Informatica del Ministero dell’Economia e della Finanze /the General IT Company of the Ministry of Economy and Finance). The Hub was set up to provide Public Administration with a highly reliable cloud infrastructure that hosts data as well as critical and strategic services.
What are Polo Strategico Nazionale’s objectives?
We want to enable innovation and Italy’s digital transformation through the secure management of PA data and services. We also want to create a technologically innovative cloud infrastructure that ensures security and economic and environmental sustainability.
What are the guiding principles of Polo Strategico Nazionale?
We want to ensure a technological and operational presence that guarantees the highest standards of both physical and IT security.
We can provide full access to the best technological solutions for Data Center infrastructure, connectivity, platforms, and cloud services, while ensuring expert technology transfer and global leader know-how.
We have an extensive knowledge of PAs and are highly familiar with service delivery dynamics and guaranteeing a rapid response to needs and recommendations.
What are the project phases?
The timeline includes two important deadlines:
- by September 2024 at least 100 Administrations with at least one service migrated to the PSN infrastructure
How is Polo Strategico Nazionale meeting NRRP requirements?
Mission 1.1 of the NRRP includes the allocation of EUR 900 million for cloud migration. These funds were released following infrastructure testing in December. Our ultimate goal is to achieve all Next Generation EU milestones while being guided by two pivotal concepts: security and privacy-by-design. We also take into account the continually increasing number of cyberattacks directed at State, Government and/or Public Institutions.
How to join?
Who can join Polo Strategico Nazionale?
As stipulated in the regulations establishing Polo Strategico Nazionale S.p.A. (Article 33 septies of the Decree-Law of 18 October 2012, No. 179, especially paragraphs 1 and 1a), the Italian Administrations which can join include Central Public Administrations, Local Public Administrations, and Health Authorities.
PAs can join the Agreement without having to use a tendering procedure.
This process is described on the Department for Digital Transformation website (specifically in the section entitled, “The process of joining the Hub and contract activation”).
While in some cases migrating to the Hub’s infrastructure can be financed by accessing Next Generation EU funds, this is not a requirement for membership.
How does one join the Agreement?
The process of a PAs migrating to Polo Strategico Nazionale’s cloud requires a few steps.
The Administration prepares and sends a Needs Plan to the Hub, using the available template. This plan describes the needs and services being requested. Within 60 calendar days of receiving the Needs Plan, Polo Strategico Nazionale prepares and sends back a Needs Project to the involved Administration. This contains a technical-financial proposal addressing the indicated needs.
The Administration may then approve the Needs Project within 10 calendar days of receiving it by signing a User Contract.
This is the Italian section dedicated to the Reserved Area.
The Italian Procurement Portal, however, is accessible at this link.
Where can I find the Needs Plan?
The Needs Plan template is available on Polo Strategico Nazionale website on the Italian pages “How to join” and “Documentation” . You will also find the other useful documents for the migration process there.
What e-mail address should I send the documentation to?
The Needs Plan should be sent to the following certified email address: convenzione.psn@pec.polostrategiconazionale.it
What does the PA need to do?
To proceed with joining, an Administration must:
- prepare and send the Needs Plan to Polo Strategico Nazionale
- await receipt of the Needs Project, which the Hub is required to send back within 60 days
- review the Draft Needs Project and pursue any further comments within 10 days
- if the PA approves the project, they will conclude a contract on the basis of the template attached to the Agreement
What is expected from Polo Strategico Nazionale?
Polo Strategico Nazionale must:
- provide support to the PA in drafting the Needs Plan
- send the Draft Needs Project to the PA with a description of services and their corresponding costs while also attaching the best migration plan
- update the Draft Needs Project accordingly within 10 days should there be any comments submitted by the Administrations
- if the project is approved by the PA, conclude the contract
How to access the Convention Portal?
To access the Reserved Area just visit this section.
How do I access the Supply Portal?
The Supply Portal is accessible at this link.
A cloud for PAs
What is the “Italian Cloud Strategy”?
The Italian Cloud Strategy was created by the Department for Digital Transformation (Dipartamento di trasformazione digitale/DTD) of the Prime Minister’s Office and the National Cybersecurity Agency. The aim is to ensure the country’s technological autonomy, guarantee control over data, and increase digital service resilience.
What does the “Cloud First” principle mean?
This means Administrations should opt for a cloud paradigm over any other technological option when defining new projects and services.
How is PA data classified?
An Administration’s data can be defined as:
- Strategic. Has an impact on national security, for example, data used in preparing the state budget
- Critical. Serves socially relevant functions, such as health, security, and the economic and social well-being of the country, for example, health data
- Ordinary. Does not result in the interruption of essential or important state services, for example, data published on the institutional site of an entity
What is Cloud Computing?
Cloud computing is a service delivery paradigm offered over a network. It is based on a set of pre-existing, configurable, and remotely available resources arrayed in a distributed architecture.
What kind of Cloud Services can a PA choose?
A PA can only purchase qualified Cloud Services, which must meet specific technical and organisational standards, data control measures, and encryption-key management and security controls.
Why migrate to a cloud?
By migrating to Polo Strategico Nazionale’s cloud, Administrations will be able to count on more secure digital services. Migrating to qualified Cloud Services also allows PAs to benefit from the advantages of scalability, elasticity, and strengthened security and resilience against cyberattacks. As such, they can offer better digital services to citizens and businesses.
Can migration be partially financed?
Migration to qualified Cloud Services can be financed by accessing Next Generation EU funds.
Is cloud training for Administrations also planned?
Administrations participating in the project will be able to count on the Business & Culture Enablement training service. This aims to promote full development of the skills needed for digitally transforming a PA. Consulting and system integration will also play a key role in achieving the country’s full digital development in this regard.
Solutions
What solutions do we offer Administrations?
Polo Strategico Nazionale will support Administrations in an end-to-end, turnkey, physical and virtual migration process. The main services offered to PAs are Housing and Hosting, Private Cloud Services, Cloud Services with Cloud Service Providers, and Professional Services.
What is meant by a Housing Service?
Housing allows Administrations to place and use their servers on an equipped space owned by Polo Strategico Nazionale.
What is a Hosting Service?
Administrations also have the option of hosting their applications on rented servers owned by Polo Strategico Nazionale. This Hosting service guarantees interconnectivity with PA systems that are part of other services provided by Polo Strategico Nazionale .
What are Private Cloud Services?
Polo Strategico Nazionale provides Private Cloud services to Public Administrations. These include on-demand and as-a-service solutions, virtual infrastructure, and application management platforms that meet the various demands of Italian PAs.
What is meant by Cloud Services with Cloud Service Providers?
PAs can access services with Cloud Service Providers in public or hybrid modes, depending on their needs. These solutions are currently implemented in partnership with Oracle, Google Cloud, and Microsoft Azure. In the future, they may also be delivered through other Cloud Service Providers.
What are the Professional Services offered?
These are additional, optional, functional options for further developing PA services. They include:
- Re-platforming: solutions for redesigning platforms that host PA applications and which enable cloud transformation.
- Re-architecting: solutions for redesigning application architectures from a cloud perspective.
- Professional Services and Security Compliance: Strategy & Compliance projects aimed at assessing infrastructure and application security as well as supporting continuing high security standards in administrations.
- IT Infrastructure – Service Operations: specialised on-demand services that support operations involved in managing PA infrastructure and applications.
- Business & Culture enablement: training and consultancy services for Administrations. These are designed to help PAs develop highly reliable infrastructure and support them over their technological development path.
What are migration services?
Polo Strategico Nazionale provides 3 cloud migration services: Re-Host, in which the migration does not involve changes to the applications or software, Re-Platform, in which the migration adapts the application components to the cloud infrastructure and Re -Architect, in which migration transforms applications according to the cloud-native paradigm.
What is a Re-Host?
It is a migration service that does not involve changes to applications or software.
What is a Re-Platform?
It is a migration service that adapts the application components to the cloud infrastructure.
What does Re-Architect mean?
It is a migration service that transforms Public Administration applications according to the cloud-native paradigm.
What are the stages of the migration process?
Each migration involves 3 phases:
- Explore: where the Administrations’ applications and software are analysed, to evaluate which cloud migration best meets their needs.
- Make: in which a setup is created that organizes the cloud environment to transfer all data safely.
- Go To Cloud: in which services are activated on the new cloud infrastructure, monitoring the functioning of the entire environment even after activation.
What does the Cloud Storage service consist of?
These are on-demand solutions for archiving large quantities of Public Administration data, then managing access to them in a fast and intuitive way.
What Data Protection services do we use?
In the field of Data Protection, Polo Strategico Nazionale provides the following services:
- Backup: on a single centralized console, so users can manage their data independently.
- Golden Copy: in order to analyze monthly backups to intercept silent malware that would compromise the validity of a restore in production.
- Disaster Recovery: to replicate data and processing in an off-premise location not involved in the disaster event.
What is the Secure Public Cloud?
It is a type of Polo Strategico Nazionale service that allows you to rely on:
- Management of encryption keys external to the control perimeter of the CSP;
- Guaranteed security by policy/design creating a segregated and self-consistent standard environment for each customer;
- Confidential computing, where activated, makes it impossible for cloud service provider operators to access the data during processing;
- The Hub & Spoke solution ensures that all network traffic can be controlled and monitored;
- Sovereignty over data stored through backup management also in the PSN private cloud.
What is Multicloud?
Polo Strategico Nazionale offers integrated Public Cloud, Hybrid & Multicloud solutions through the use of a single Cloud Management Platform with the possibility of adding features that meet the needs of the individual Administration, such as customized workflows or advanced capacity planning.
What does Hybrid Cloud on PSN site mean?
This is a service provided by Cloud Service Provider (Microsoft Azure) via DC and proprietary infrastructure of Polo Strategico Nazionale, which provides a combination of public cloud (always in the Italian region) and private.
What is meant by Business & Culture Enablement?
Business & Culture Enablement is a package of Polo Strategico Nazionale services which consists of:
- Change Management: accompanying organizations and people in the process of learning tools and resources for digital transformation;
- Training: provide an e-Learning platform with basic courses in the catalog and/or customized on specific topics;
- Specialist Support: propose professional support figures, who can be integrated with Change Management and Training services, to further accelerate the understanding of the processes.
What is meant by Public Cloud PSN Managed?
They are a series of services offered by Polo Strategico Nazionale provided by Cloud Service Providers on PSN Data Centers, which include:
- A separation of the components, in particular between the dedicated Cloud part and the public one;
- Complete management (from hardware to software platform) by Polo Strategico Nazionale staff;
- Management of all phases, from software release to hardware and replacement management;
- The provision of services in a completely disconnected manner from the public regions of the Cloud Service Provider.
What are Professional Services and Security Compliance?
They are Strategy & Compliance projects, designed to evaluate the security of an infrastructure and its application park, working on the security standards of the Administrations.
What are IT Infrastructure – Service Operations?
They are a series of on-demand specialist solutions to support Operations for the management of the infrastructure and application park of the Public Administration.
What additional services does Polo Strategico Nazionale provide?
Polo Strategico Nazionale provides the following ancillary services for the Public Administration:
- Dedicated 1 Gbps connectivity: to optimize the migration process; 2 Gbps, 5 Gbps and 10 Gbps bands are also envisaged for which provision must be made in advance because physical access is carried out on Lambda Wave (DWDM optical fibre).
- Multicloud: to add features that meet the needs of the individual Administration, such as customized workflows or advanced capacity planning.
- Antivirus with centralized control: to protect IT environments through a Fully Managed EDR application.
- Windows and Linux operating systems: to meet the needs of Administrations.
What are IaaS services?
Polo Strategico Nazionale provides IaaS Shared and IaaS Dedicated services. In the first case, a virtualized, logically isolated environment is proposed to the Administrations, with resources available when they are needed. In the second, an infrastructural private cloud is made available in a special area dedicated to the Public Administration, which provides private computational resources.
What does the CaaS service consist of?
It is a distribution model of IT services that allows you to run and manage scalable, fast and efficient applications within containers.
What does the PaaS service consist of?
It is a solution that provides for the provision of one or more technological platforms in the cloud where applications and data can be run. The platform then provides application elements and middleware (database, big data, Artificial Intelligence).
Data Center
What are Polo Strategico Nazionale Data Center like?
At the heart of Hub are the National Data Center. These are designed, built, and operated in a way that provides the energy efficiency infrastructures need while lowering environmental impacts.
Where are the Data Center located?
The Hub’s four Data Centers are located in Lazio region (Pomezia and Acilia) and Lombardy region (Rozzano and Santo Stefano Ticino).
What makes the Data Centers efficient?
Energy efficiency in the Data Centers is pursued first and foremost through the targeted design of facilities and industrial plants using energy-efficient and environmentally friendly components and technologies. In addition, we use best-in-class IT equipment and products. These offer greater compactness and lower power consumption alongside high processing capacity.
Do Polo Strategico Nazionale Data Centers meet sustainability criteria?
Polo Strategico Nazionale is actively committed to sustainability. This means meeting the highest infrastructure standards, including a Tier IV and ANSI/TIA 942 Rating 4 and international certifications, such as ISO 50001, ISO 14001, and LEED Gold.
How do the Data Centers comply with environmental sustainability criteria?
Polo Strategico Nazionale optimises operational energy consumption by using renewable energy and free cooling. Our IT equipment and best-in-class products offer greater compactness and lower power consumption, yet high processing capacity. We also work to minimise waste generation and reduce water consumption.
Is Polo Strategico Nazionale Infrastructure Carbon Neutral?
We have set the goal of reducing our overall carbon footprint and becoming carbon neutral by 2030. This means following the climate target plan drawn up and set out by the European Commission.
Security
How is data protected at the physical level?
Polo Strategico Nazionale protects data on a physical level through Data Centers equipped with advanced anti-intrusion systems, perimeter protection sensors and video surveillance, allowing access only to authorized security personnel. They are distributed throughout the country in two regions (Lazio and Lombardy) to guarantee business continuity, flexible management of workloads and resilience to disasters.
How is information safeguarded cybernetically?
We ensure confidentiality, integrity and availability of data, complying with current regulations and adopting technical and organizational measures certified according to ISO/IEC 27001 and ISO 22301 standards. Through periodic risk analyzes and a segmented security architecture, we guarantee the protection of infrastructures and data. Security is further strengthened by a dedicated area in the Data Centers and proactive management of the Security Operation Center (SOC) as well as the Computer Emergency Response Team (CERT).
What is a SOC?
A Security Operation Center (SOC) is a centralized facility where cybersecurity experts monitor, analyze and protect information from cyber threats in real time. Using advanced technologies and security procedures, the SOC is responsible for identifying, evaluating and responding to security incidents, ensuring the defense of IT infrastructures.
What does CERT mean?
A Computer Emergency Response Team (CERT) is a group of experts dedicated to managing computer emergencies, providing prevention, detection and response services to cyber security incidents. It operates as a point of reference for gathering information on vulnerabilities and attacks, offering assistance and consultancy to mitigate and resolve cybersecurity threats.
How is encryption used?
To guarantee a high level of security, at Polo Strategico Nazionale we protect the sovereignty of data stored in the Cloud through the encryption of information and the secure management of cryptographic keys. This ensures that only authorized users can access and decrypt the data.
What are shared responsibility matrices for security?
The responsibility matrices are governance tools that clearly define roles and responsibilities regarding the security of Cloud services between the Public Administration and the Polo Strategico Nazionale. They facilitate collaboration and effective coordination to achieve safety objectives, promoting transparent and shared management of skills.
How does the Shared by default approach work?
The “Shared by default” approach promotes prior sharing of security responsibilities between the cloud service provider and customers. Based on transparency, integration, coordination and measurement, this method aims at effective management of the security of Cloud services for the Public Administration. It facilitates the identification of responsibilities for different service domains, offers additional professional services to improve safety, and proposes a dialogue model for coordination.
What is the Shared Security Responsibility Model?
The Shared Security Responsibility Model (SSRM) is a framework that defines how the Cloud Service Provider and the Cloud Service Customer share responsibility and accountability for the security of data and resources in Cloud services. Through the Shared Responsibility Matrices, the skills of both parties for the application of security controls are detailed.