Information Security at scdsoft AG
Protecting information is a top priority for scdsoft AG. For us, information security is an essential component of responsible and reliable business practices.
In order to systematically further develop our existing information security measures and processes and align them with an internationally recognized standard, scdsoft AG is currently undergoing the ISO/IEC 27001 certification process.
Another key component of effective information security is the early detection and reporting of potential security incidents.
If you discover an information security incident or suspect a security-related breach, please report it immediately.
What is considered an information security incident?
An incident can be anything that indicates a potential threat to the information security of scdsoft AG. This includes obvious security-critical events, as well as suspicious circumstances or unusual occurrences that you notice. Please report any observations that could indicate potential misuse or a vulnerability so that we can quickly investigate the situation and take appropriate action if necessary.
Possible examples of an incident (non-exhaustive list):
- Unauthorized access to systems or data
- Suspected phishing or other attack attempts
- Loss or theft of scdsoft AG devices or information
- Technical malfunctions with security-critical implications for scdsoft AG data
Contact Information
Email: isb@scdsoft.de
scdsoft AG
Im Technologiepark Karlsruhe
Albert-Nestler-Straße 21
D-76131 Karlsruhe
Information Security and Collaboration with Suppliers
This section describes the basic approach to information security for suppliers, the handling of subcontractors, and the IT security regulations that suppliers of scdsoft AG must observe when using information and IT devices (e.g., desktop computers, laptops, smartphones, tablets).
These guidelines are intended for the management of suppliers, their employees, and their agents (hereinafter referred to as “contractors”).
The supplier is obligated to independently communicate these guidelines to its employees, agents, and, if applicable, any subcontractors.
Exchange of Information
In all discussions involving confidential or classified information of scdsoft AG, including telephone conversations, care must be taken to ensure that such information cannot be overheard by unauthorized persons.
Care must be taken to ensure that all necessary and appropriate precautions (e.g., encryption) are taken to protect the information during transport from being viewed, altered, or deleted by unauthorized persons (including family members and friends).
Physical Transport of Media
As a general rule, media containing information belonging to scdsoft AG must be protected against unauthorized access, misuse, or tampering during transport, including across organizational boundaries.
Care must be taken to ensure that all necessary and appropriate precautions (e.g., encryption) are taken to protect the information from being viewed, altered, or deleted by unauthorized persons (including family members and friends) during transport. Data storage media must be transported in a concealed manner. Data storage media containing confidential information must always be transported under escort by an employee of the supplier or contractor. Documents must be transported in a manner that prevents them from being viewed, such as in a non-transparent folder.
Physical Transport of Laptops
Laptops containing information belonging to scdsoft AG must be transported in such a way that their contents are not visible from the outside. Furthermore, when using a laptop in public, care must be taken to ensure that others cannot read information on the screen and/or spy on the entry of confidential authentication information.
Handling Information Security Incidents and Communication
Serious information security incidents (e.g., system malfunctions, data loss, unlawful acts, cybercrime attacks) must be reported immediately to the information security contact at isb@scdsoft.de. Any suspected loss of confidential or classified information must also be reported to the information security contact.
Audit Rights Regarding Information Security
The Supplier/Contractor grants scdsoft AG the right, exercisable at any time and upon prior notice, to inspect and review at the Supplier’s/Contractor’s premises all data pertaining to business transactions related to information security between the Supplier/Contractor and scdsoft AG, as well as to review IT and data security measures.
Employees of scdsoft AG or third parties commissioned by scdsoft AG may enter the supplier’s/contractor’s premises for this purpose during normal business hours. The supplier/contractor shall bear the costs of the review if violations of information security and/or the terms of the respective engagement are identified, unless such violations are not attributable to the contractor’s fault.
Confidentiality Agreement Between the Supplier/Contractor and Its Employees
The supplier/contractor of scdsoft undertakes to enter into a confidentiality agreement (separately or as part of the employment contract) with all of its employees who, in the course of the collaboration, receive or have access to scdsoft’s information. The burden of proof regarding compliance rests with the supplier/contractor and must be demonstrated at any time upon request by scdsoft.
Subcontractors
If the supplier/contractor engages additional subcontractors, it bears full responsibility for communicating and implementing all information security-related requirements. The supplier is obligated to ensure that the subcontractor complies with these requirements.
Upon request by scdsoft AG, the supplier must provide evidence of compliance with the requirements.
In the event of proven serious breaches of duty or material misconduct on the part of the subcontractor or its agents, scdsoft AG reserves the right to reject the subcontractor.
In addition, scdsoft AG may terminate the contract for cause and/or assert claims for damages.
Compliance with Information Security (Supply Chain)
When engaging subcontractors, the supplier/contractor must ensure that the subcontractor also complies with scdsoft AG’s information security requirements in accordance with ISO 27001. This also includes entering into confidentiality agreements with sub-suppliers. The burden of proof for compliance rests with the supplier/contractor and must be demonstrated at any time upon request by scdsoft AG.
If the supplier/contractor is authorized to award subcontracts, it shall be fully liable for them, regardless of any contractual or statutory limitations or exclusions of liability with respect to such subcontracts.