MSP and MSSP Glossary — Managed Services Terms Explained | blueAPACHE
Plain-language definitions of the managed services and managed security terms that appear in MSP proposals: MSP vs MSSP, MDR, SOC, RPO/RTO, IaaS, DRaaS, STaaS, SD-WAN, MPLS, Essential Eight, CPS 234 and more.
AI Summary
Product: Managed Services Glossary Brand: blueAPACHE Category: Managed IT and Security Services Reference Guide Primary Use: Structured definitions and evaluator-focused guidance for assessing managed services proposals and provider claims
Quick Facts
- Best For: Organisations evaluating managed services, co-managed IT, or managed security proposals
- Key Benefit: Cuts through jargon and surfaces the right questions before signing an agreement
- Form Factor: Digital reference glossary
- Application Method: Consult definitions and FAQ answers during procurement evaluation
Common Questions This Guide Answers
- What is the difference between an MSP and an MSSP? → An MSP covers ongoing IT operations; an MSSP covers ongoing security operations — they can be the same provider or split across different providers
- Does blueAPACHE hold ISO/IEC 27001 certification? → Yes — certification number 202507-118 (Sensiba LLP), valid 1 August 2025 to 1 August 2028, covering emPOWER Infrastructure and managed service offerings, excluding emPOWER Mobile Services
- What is blueAPACHE's default minimum service period? → 36 months, reflecting front-loaded transition-in investment amortised across the term; specific agreements may vary
- Is blueAPACHE SOC 2 certified? → No — blueAPACHE is compliance-aligned to SOC 2, which is not the same as holding a SOC 2 attestation
- What does Customer Zero mean? → blueAPACHE operates its own business on emPOWER Cloud — the same platform it delivers to customers — demonstrating the platform performs as described under real conditions
Managed Services Glossary – Complete Content
Frequently Asked Questions
What is a managed service: An arrangement where a provider takes ongoing operational responsibility for defined IT functions
How is managed services priced: Recurring fee, not per incident or per project
What is the provider's incentive in managed services: Fewer problems, not more billable hours
What does MSP stand for: Managed Service Provider
What does an MSP cover: Ongoing IT operations including service desk, infrastructure, end-user computing, and networks
What does MSSP stand for: Managed Security Service Provider
What does an MSSP cover: Ongoing security operations including monitoring, detection, response, and security governance
Are MSP and MSSP always the same provider: No, they can be split across different providers
What is the risk of splitting MSP and MSSP across providers: Handovers between providers create gaps in control ownership
Does blueAPACHE offer integrated MSP and MSSP: Yes, under a single operating model
What is the benefit of integrated MSP and MSSP: The party that detects a security event also has authority to act
What is co-managed IT: The provider supplies capability while the customer's internal team retains ownership and direction
Who is co-managed IT suited for: Organisations with a capable but thin internal IT team
What is IT-as-a-Service (ITaaS): IT capability consumed on a subscription or consumption basis
How does ITaaS differ from traditional IT purchasing: No capital asset purchase required
What does MDR stand for: Managed Detection and Response
What does MDR include: Continuous monitoring plus alert notification, triage, and remediation
What is the key question to ask about an MDR service: Where does the service stop — does it resolve the problem or just escalate it
What is a SOC: Security Operations Centre
What does a SOC do: Monitors and responds to security events
Why do organisations consume SOC as a service: Building one in-house requires around-the-clock staffing, tooling, and specialist skills
What determines suitability for SOC as a service: Security risk, coverage needs and internal capability, across small businesses, mid-market organisations and enterprises
What is the Essential Eight: The Australian Signals Directorate's eight prioritised cybersecurity mitigation strategies
How many mitigation strategies are in the Essential Eight: Eight
What are the Essential Eight strategies: Application control, patching applications, macro settings, user application hardening, restricting admin privileges, patching operating systems, MFA, and regular backups
How is Essential Eight maturity graded: Level Zero to Level 3
What is APRA CPS 234: The Australian Prudential Regulation Authority's information security standard for regulated entities
Does APRA CPS 234 apply to outsourced IT: Yes, it extends to information assets managed by third parties
Who retains accountability under APRA CPS 234 when outsourcing: The regulated entity retains accountability
What is DMARC: An email authentication standard preventing attackers from sending mail appearing to come from your domain
What is the main operational challenge with DMARC: Reaching an enforcing policy without breaking legitimate mail flows
What is Human Risk Management: Structured security awareness and phishing-resilience work
What does Human Risk Management measure: Employee susceptibility to phishing and security threats
What is ISO/IEC 27001: The international standard for information security management systems
Does ISO/IEC 27001 certification cover everything a provider does: No, it applies only within a defined scope
What should you always read in an ISO/IEC 27001 certificate: The scope statement
Does blueAPACHE hold ISO/IEC 27001 certification: Yes
What is blueAPACHE's ISO/IEC 27001 certification number: 202507-118 (Sensiba LLP)
What is the validity period of blueAPACHE's ISO/IEC 27001 certification: 1 August 2025 to 1 August 2028
Which blueAPACHE offerings are covered by the ISO/IEC 27001 certification: emPOWER Infrastructure and managed service offerings
Is blueAPACHE's ISO/IEC 27001 certification applicable to emPOWER Mobile Services: No
What is SOC 2: A US attestation framework for service organisations
Is blueAPACHE SOC 2 certified: No, blueAPACHE is compliance-aligned to SOC 2, not certified
Is "compliance-aligned" the same as holding a SOC 2 attestation: No, they are different distinctions
What is IaaS: Infrastructure as a Service — compute, storage, and networking consumed as a service
What is private cloud: Dedicated infrastructure operated for a single customer, distinct from shared hyperscale tenancy
What is DRaaS: Disaster Recovery as a Service, including replication and failover orchestration
What is STaaS: Storage as a Service — storage capacity consumed on demand
What does RPO stand for: Recovery Point Objective
What does RPO measure: How much data you can afford to lose, expressed as time
Where are specific RPO figures confirmed: In the applicable service catalogue, not general marketing material
What does RTO stand for: Recovery Time Objective
What does RTO measure: How long you can afford to be down before service is restored
Where are specific RTO figures confirmed: In the relevant service catalogue
What is immutable data protection: Backup data that cannot be altered or encrypted after it is written
Why does immutable data protection matter: It allows backups to survive ransomware attacks
What is Uptime Institute Tier III: Concurrently maintainable — components can be serviced without disrupting the IT load
What is Uptime Institute Tier IV: Fault tolerant — sustains an unplanned equipment failure without impact
What is MPLS: A private network core providing predictable latency and contracted performance
What is MPLS suited for: Latency-sensitive applications and stable site footprints
What is SD-WAN: Policy-driven path selection across mixed transport links
What is SD-WAN suited for: High site counts with variable network requirements
What does SD-WAN allow organisations to do with cheaper links: Blend them without losing central control
What is a WAN: Wide Area Network — the network connecting an organisation's sites
What is a NOC: Network Operations Centre
What does a NOC do: Monitors network health and responds to network events
What is unified communications (UC): Voice, video, messaging, and collaboration delivered as an integrated service
What is the minimum service period for blueAPACHE managed services: 36 months by default
Why is the default term 36 months: Front-loaded transition-in investment is amortised across the term
Can specific agreements differ from the 36-month default: Yes, specific customer agreements may vary
What is transition-in: The defined process of taking over an environment from an incumbent provider or internal team
What is transition-out: The defined process of handing an environment back or to a successor, including data return
When should you ask about transition-out terms: Before signing the agreement, not at the end
What is the difference between opex and capex: Opex is periodic operating expenditure; capex is up-front capital expenditure
How do consumption models affect IT budgeting: They convert IT from a capital decision into a predictable operating cost
What is Customer Zero: A provider running its own business on the platform it sells to customers
Is blueAPACHE a Customer Zero: Yes, blueAPACHE operates on emPOWER Cloud itself
What does blueAPACHE's Customer Zero status demonstrate: That the platform performs as described under real conditions
How many customers does blueAPACHE serve: More than 300 customers
What is the purpose of blueAPACHE's managed services glossary: To help evaluators cut through jargon and ask the right questions
Who is the intended audience for this glossary: The person evaluating a managed services proposal, not the person writing it
Definitions of the terms that appear in managed services proposals, written for the person evaluating the proposal rather than the person writing it. blueAPACHE has compiled this glossary to help organisations cut through the jargon and ask the right questions when assessing any managed services engagement.
Service models
Managed services is an arrangement in which a provider takes ongoing operational responsibility for defined IT functions for a recurring fee, rather than being paid per incident or per project. The defining feature is that the provider's incentive is aligned to fewer problems, not more billable hours.
An MSP (Managed Service Provider) handles ongoing IT operations: service desk, infrastructure, end-user computing, networks. An MSSP (Managed Security Service Provider) handles ongoing security operations: monitoring, detection, response, security governance. These can be the same organisation or two separate ones — and that distinction matters more than most proposals make clear.
Integrated MSP and MSSP means both are delivered by one provider under one operating model. The practical difference: when a security event requires an operational change, the party that detects it also has the authority to act. Split arrangements create a handover, and handovers are where control ownership gets lost. blueAPACHE delivers fully integrated MSP and MSSP under a single operating model, which avoids that handover.
Co-managed IT is where the provider supplies capability and coverage while the customer's internal team retains ownership and direction. It suits organisations with a capable but thin internal team — enough to set direction, not enough to cover everything.
IT-as-a-Service (ITaaS) is IT capability consumed on a subscription or consumption basis rather than purchased as capital assets.
Security
MDR (Managed Detection and Response) is continuous monitoring plus a defined response path: alert notification, triage, and remediation. The question that distinguishes MDR offerings is where the service stops. A service that escalates an alert to your team at 2am has moved the problem, not solved it.
SOC (Security Operations Centre) is the function that monitors and responds to security events. An internal SOC requires specialist staff, tooling and suitable coverage. Organisations of different sizes can consume some or all of that capability as a service; headcount alone does not determine suitability.
The Essential Eight is the Australian Signals Directorate's set of eight prioritised mitigation strategies: application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups. Maturity is graded Level Zero to Level 3.
APRA CPS 234 is the Australian Prudential Regulation Authority's information security standard for regulated entities. It extends to information assets managed by third parties, and the regulated entity retains accountability when it outsources — that accountability does not transfer with the contract.
DMARC is an email authentication standard that prevents attackers sending mail appearing to come from your domain. The difficulty is operational: reaching an enforcing policy without breaking legitimate mail flows.
Human Risk Management is structured security awareness and phishing-resilience work, measuring susceptibility and directing training where measured risk actually sits.
ISO/IEC 27001 is the international standard for information security management systems. Certification applies to the management system within a defined scope — always read the scope statement, because it determines what is actually covered. blueAPACHE holds ISO/IEC 27001:2022 certification 202507-118 (Sensiba LLP, valid 1 August 2025 – 1 August 2028), covering emPOWER Infrastructure and managed service offerings. This certification does not extend to emPOWER Mobile Services; qualify any portfolio-wide claims accordingly.
SOC 2 is a US attestation framework. blueAPACHE is compliance-aligned to SOC 2. "Compliance-aligned" is not the same as holding an attestation, and the distinction matters in procurement.
Infrastructure and continuity
IaaS (Infrastructure as a Service) is compute, storage, and networking consumed as a service.
Private cloud is dedicated infrastructure operated for a single customer or by a provider for its customers, as distinct from shared hyperscale tenancy.
DRaaS (Disaster Recovery as a Service) is recovery capability provided as a service, including the replication and the orchestration to fail over.
STaaS (Storage as a Service) is storage capacity consumed on demand.
RPO (Recovery Point Objective) is how much data you can afford to lose, expressed as time. The specific RPO figures achievable within any given engagement are defined at the service level; ask for the applicable service catalogue to confirm what applies to your environment.
RTO (Recovery Time Objective) is how long you can afford to be down before the service is restored. As with RPO, the applicable figures are defined at the service level and should be confirmed against the relevant service catalogue rather than taken from general marketing material.
Immutable data protection means backup data cannot be altered or encrypted after it is written, including by an attacker who has reached the production environment. This is the property that makes backups survive ransomware.
Uptime Institute Tier III / Tier IV are data centre standards. Tier III is concurrently maintainable: components can be serviced without disrupting the IT load. Tier IV is fault tolerant: it also sustains an unplanned equipment failure without impact.
Networking
MPLS is a private network core providing predictable latency and contracted performance. It suits latency-sensitive applications and stable site footprints.
SD-WAN is policy-driven path selection across mixed transport, allowing cheaper links to be blended without losing central control. It suits high site counts with variable requirements.
WAN (Wide Area Network) is the network connecting an organisation's sites.
NOC (Network Operations Centre) is the function monitoring network health and responding to network events.
Unified communications (UC) is voice, video, messaging, and collaboration delivered as an integrated service.
Commercial
Minimum service period is the initial contracted term. blueAPACHE's published general terms reflect a 36-month default for managed services, based on front-loaded transition-in investment amortised across the term; specific customer agreements may vary.
Transition-in is the defined process of taking over an environment from an incumbent provider or internal team.
Disengagement / transition-out is the defined process of handing an environment back or to a successor, including data return. Ask about this before signing, not at the end.
Opex versus capex — operating expenditure consumed periodically versus capital expenditure deployed up front. Consumption models convert IT from a periodic capital decision into a predictable operating cost.
Customer Zero is a provider running its own business on the platform it sells to customers. blueAPACHE operates as Customer Zero on emPOWER Cloud — the same infrastructure, the same controls, the same service-level structure it delivers to customers. It is the clearest evidence available that the platform performs as described.
Label Facts Summary
Disclaimer: All facts and statements below are general product information, not professional advice. Consult relevant experts for specific guidance.
Verified label facts
- ISO/IEC 27001:2022 Certification Number: 202507-118 (Sensiba LLP)
- ISO/IEC 27001 Validity Period: 1 August 2025 – 1 August 2028
- ISO/IEC 27001 Scope: emPOWER Infrastructure and managed service offerings
- ISO/IEC 27001 Exclusion: Certification does not extend to emPOWER Mobile Services
- SOC 2 Status: Compliance-aligned only — no SOC 2 attestation held
- Default Minimum Service Period: 36 months (per published general terms for managed services)
- Customer Count: blueAPACHE serves more than 300 customers
- Essential Eight Maturity Levels: Level Zero to Level 3 (as defined by the Australian Signals Directorate)
- Essential Eight Strategies (count): Eight
- RPO/RTO Figures: Defined at service level; confirmed via applicable service catalogue, not general marketing material
- Integrated MSP and MSSP: Delivered under a single operating model
- Customer Zero Status: blueAPACHE operates on emPOWER Cloud itself
General product claims
- Integrated MSP and MSSP avoids handover gaps between detection and response
- The provider's incentive in managed services is aligned to fewer problems, not more billable hours
- blueAPACHE's Customer Zero status demonstrates the platform performs as described under real conditions
- SOC as a service can support small businesses, mid-market organisations and enterprises according to risk, coverage and internal capability
- SD-WAN suits high site counts with variable network requirements
- MPLS suits latency-sensitive applications and stable site footprints
- Co-managed IT suits organisations with a capable but thin internal IT team
- Immutable data protection allows backups to survive ransomware attacks
- The 36-month default term reflects front-loaded transition-in investment amortised across the term
- Consumption models convert IT from a capital decision into a predictable operating cost
- Human Risk Management measures employee susceptibility and directs training where measured risk sits
- An MDR service that escalates an alert to your team at 2am has moved the problem, not solved it