Technical and organizational security measures (TOM)
Last update: 21.06.2018
Dieses Rechtsdokument wird in seiner verbindlichen englischen Fassung bereitgestellt.
I. Confidentiality
- Physical access control of the Supplier
- wservices does not have physical access to servers (computers) which are located in a data center.
- The disks of all office computers, laptops and flash drives which contains Personal Data are encrypted.
- Physical access control of Sub-processors
- Physical entry control system with log
- Documented distribution of keys to employees
- Policies for accompanying and designating guests in the building
- Data center staff present 24/7
- Video monitoring at entrances and exits
- Security door interlocking systems and server rooms
- Electronic access control
- E-Mail-Account and SSH user passwords are not known to the Supplier.
- The Customer's password for the administration interface is determined by the Customer himself; the password must comply with predefined guidelines.
- Internal access control
- The Supplier shall prevent unauthorized access by:
- Applying security updates regularly
- By using state of the art technology
- A revision-proof, compulsory process for allocating authorization for supplier employees
- The Customer is responsible for transferred data/software with regard to security and updates.
- The Supplier shall prevent unauthorized access by:
- Isolation control
- For the Supplier's internal administration systems
- Data shall be physically or logically isolated and saved separately from other data.
- Backups of data shall also be performed using a similar system of physical or logical isolation.
- For the Supplier's internal administration systems
- Pseudonymization
- The Customer is responsible for pseudonymization.
II. Integrity (Art. 32 Para.1 Clause b GDPR)
- Data transfer control
- All employees are trained in accordance with Art. 32 Para. 4 GDPR and are obliged to ensure that personal data is handled in accordance with data protection regulations.
- Deletion of data in accordance with data protection regulations after termination of the contract.
- Encrypted data transmission options are provided
- Data entry control
- For the Supplier's administration systems and for the web hosting services, data is entered or collected by the Customer.
III. Availability and Resilience (Art. 32 Para. 1 Clause b GDPR)
- Availability control
- Backup and recovery concept with daily backups of all relevant data depending upon the services booked by the Customer.
- Professional employment of security programs (virus scanners, firewalls, encryption programs, spam filters)
- Employment of disk mirroring on all relevant servers
- Monitoring of all relevant servers
- Employment of an uninterruptible power supply system or emergency power supply system
- Rapid recovery measures (Art. 32 Para. 1 Clause c GDPR)
- For all internal systems, there is a defined escalation chain which specifies who is to be informed in the event of an error in order to restore the system as quickly as possible.