TOM overview

Explain protection areas without exposing the protection architecture.

The public overview shows the areas covered by the TOM control catalogue. Which measures actually apply to a specific service is documented in the engagement-specific contractual version.

Public information
PUBLIC-SAFE
PurposeCustomer transparencywithout operational detail
ScopePrinciples & contractual frameworkpublic
DetailsProvided for the engagementwhere required
Last updated: 30 August 2026 · Public information version 1.0
Public protection areas

Concrete measures depend on the service, processing and risk.

The following categories are intentionally described at principle level.

Organisation & responsibilities

Roles, confidentiality and responsibilities are defined and documented as appropriate for the service.

Access & permissions

Access and permissions are handled according to necessity and appropriate privilege principles.

Customer separation & data minimisation

Customer data and technical evidence are logically or organisationally separated and limited to the required purpose.

Protection in transit & at rest

Protection for transmission and storage is selected according to risk and the actual processing.

System protection & maintenance

Systems are protected against known risks with appropriate measures and maintained in a suitable security state.

Logging & traceability

Security-relevant administrative activity and events are made traceable to the extent required.

Availability & recovery

Where customer data is processed or stored, appropriate availability, backup and recovery measures are considered.

Incidents, deletion & effectiveness

Documented responsibilities and principles cover security/privacy incidents, deletion and review of appropriate measures.

Confidentiality

Security-sensitive detail stays off the public website.

A TOM schedule should provide customers with the necessary transparency. It is not an architecture diagram or an operating manual.

Public

Protection areas, responsibility principles and the existence of an engagement-specific contractual version.

Confidential

Specific products, suppliers, system names, network or access paths, technical parameters, internal review frequencies, detailed configurations and customer-specific evidence.

Contractual principle

Only measures that actually apply to the concrete service may be described as applicable or implemented in the contractual TOM version.

Privacy & information security

More public information

The overview brings together information about data processing, TOMs, subprocessors, retention and deletion.