Explain protection areas without exposing the protection architecture.
The public overview shows the areas covered by the TOM control catalogue. Which measures actually apply to a specific service is documented in the engagement-specific contractual version.
Concrete measures depend on the service, processing and risk.
The following categories are intentionally described at principle level.
Organisation & responsibilities
Roles, confidentiality and responsibilities are defined and documented as appropriate for the service.
Access & permissions
Access and permissions are handled according to necessity and appropriate privilege principles.
Customer separation & data minimisation
Customer data and technical evidence are logically or organisationally separated and limited to the required purpose.
Protection in transit & at rest
Protection for transmission and storage is selected according to risk and the actual processing.
System protection & maintenance
Systems are protected against known risks with appropriate measures and maintained in a suitable security state.
Logging & traceability
Security-relevant administrative activity and events are made traceable to the extent required.
Availability & recovery
Where customer data is processed or stored, appropriate availability, backup and recovery measures are considered.
Incidents, deletion & effectiveness
Documented responsibilities and principles cover security/privacy incidents, deletion and review of appropriate measures.
Security-sensitive detail stays off the public website.
A TOM schedule should provide customers with the necessary transparency. It is not an architecture diagram or an operating manual.
Public
Protection areas, responsibility principles and the existence of an engagement-specific contractual version.
Confidential
Specific products, suppliers, system names, network or access paths, technical parameters, internal review frequencies, detailed configurations and customer-specific evidence.
Only measures that actually apply to the concrete service may be described as applicable or implemented in the contractual TOM version.
More public information
The overview brings together information about data processing, TOMs, subprocessors, retention and deletion.
