Verified Security for Your Business Data

Your ESG, supply chain, and GRC data are particularly sensitive. That is why we protect your data using an ISMS certified to ISO/IEC 27001:2022, documented controls, and regularly audited processes.

ISO/IEC 27001:2022

Information Security Management System, certified by TÜV Rheinland

TÜV Rheinland ISO 27001:2022

Scope of Application

Consust GmbH as a whole

Last Audit

April 2026

Appendix A: Controls

93 applicable / 93 implemented

Review

Annual Review Audits

93 / 93

Controls from Annex A of ISO/IEC 27001:2022 are applicable and have been implemented

0

Exclusions in the Statement of Applicability following review during the certification audit

≤ 48 hours

Recovery Time Objective (RTO), the point at which processes are considered critical and are assigned a tested contingency plan

EU

FramesCube is hosted by an ISO 27001-certified data center operator

Standards and guidelines by which we measure ourselves

Certified

ISO/IEC 27001:2022

Certified ISMS based on the PDCA cycle, with risk-based selection of controls, internal audits, and an annual management review.

Implemented

GDPR and BDSG

Technical and organizational measures, data processing agreements, and a record of processing activities. Data minimization and purpose limitation as principles.

Mapped

NIS2UmsuCG

Based on our own assessment, CONSUST is not currently subject to NIS2 requirements. Nevertheless, our Statement of Applicability is mapped to the requirements of the NIS2UmsuCG.

Our ISMS documentation for your supplier audit

The certificate and public SoA are available to everyone. Guidelines and work instructions are classified as “restricted” and will be provided upon completion of a confidentiality agreement.

ISO 27001 Certificate

TÜV Rheinland Certificate, Including Scope and Validity

ISO/IEC 27001

Statement of Applicability (Public Version)

All 93 controls from Appendix A, including applicability, status, and NIS2 mapping

STA.IT.003

ISMS Policy

Security Strategy, Scope, Risk Management, and the PDCA Cycle

POL.IT.003

ISMS Charter

Mission, Objectives, and Governance of the ISMS, signed by management

POL.IT.004

Guidelines for Safe Operation

Technological Controls under Annex A.8: End Devices, Access, Cryptography, Development

POL.IT.001

Information Security and Data Protection

Classification, Password and Information Management, Use of AI Tools

STA.IT.002

Supplier Management Policy

Risk Categories, Contract Requirements, and Annual Supplier Audits

POL.SC.001

Business Continuity Policy

Business Impact Analysis, Emergency and Recovery Plans, Annual Drills

POL.IT.005

Incident Management

Reporting Channels, Classification, Escalation, and Follow-Up of Security Incidents

WI.IT.002

Change Management

Tested and approved changes to production systems

WI.IT.001

Guidelines for Secure HR Processes

Screening, Confidentiality, Training, Onboarding and Offboarding

POL.HR.001

Mobile Work and BYOD Policy

Clean Desk, Screen Lock, Protection of Devices Outside the Premises

POL.HR.002

Physical Security Policy

Access, protection against environmental hazards, safe disposal of operating materials

POL.IT.002

You will receive confidential ISMS documents after signing an NDA.

For your supplier audit, we’re happy to provide you with additional documents from our ISMS, including guidelines and work instructions. These documents are classified as “restricted” by us. Therefore, we’ll send them to you after you’ve signed a non-disclosure agreement (NDA). Please request the documents using the form. We will then send you the NDA and make the documents available once it has been signed.

Here’s How We Protect Your Data in Everyday Life

A selection of the implemented measures, organized by topic. The number refers to the corresponding control in Annex A of ISO/IEC 27001:2022.

Organization and Governance

Source: POL.IT.003, POL.IT.004

Information Security Policy

Approved by management, communicated to all employees, and reviewed annually.

A.5.1

Appointed CISO with clearly defined roles

The roles and responsibilities of executive management, the CISO, BCM, data protection, and supplier management are documented.

A.5.2

Risk-Based Approach

Risks are assessed at least once a year and as needed, recorded in the risk register, and accompanied by corresponding measures.

Kl. 6.1

Classification of Information

Three classification levels: public, restricted, confidential. Documents without a classification designation are considered restricted.

A.5.12

Internal Audits and Management Review

Internal audit conducted by an external auditor and a management review at least once a year.

Kl. 9.2, 9.3

Guided Documentation

All ISMS documents are subject to version control, an approval process, and retention periods.

Kl. 7.5

Staff and Awareness

Source: POL.HR.001, STA.IT.002

Risk-Based Security Review

Roles are classified into risk levels, and the scope of the review is determined accordingly. Consent is obtained in advance.

A.6.1

Confidentiality Agreements

All employees and external parties with access to systems and data sign a confidentiality agreement.

A.6.6

Mandatory Safety Training

Training on phishing, passwords, data protection, and incident reporting, with refresher sessions at least once a year.

A.6.3

Structured Onboarding and Offboarding

Checklists for HR, IT, and management. Access rights are revoked in a timely manner upon termination.

A.5.11, A.6.5

Mandatory Reporting of Security Incidents

Easy-to-use reporting channels via the service portal and email. Guiding principle: Reporting is better than perfection.

A.6.8

Devices and Access

Source: POL.IT.001, STA.IT.002

Centrally Managed Company Devices

All workstation devices are managed using a security baseline via Microsoft Intune. No local administrator rights.

A.8.1, A.8.9

Hard Drive Encryption

End-to-end encryption of mobile devices using BitLocker.

A.8.24

EDR and Host Firewall

Centrally managed Endpoint Detection and Response, as well as an enabled firewall on all company devices.

A.8.7

Timely Patch Management

Security updates are distributed automatically and installed within five business days. Critical vulnerabilities are addressed immediately.

A.8.8

Multi-factor authentication

Required for central cloud services and all privileged accounts. Legacy authentication is disabled.

A.8.5

Least Privilege and Need-to-Know

Access rights are role-based and limited to what is necessary; they are regularly reviewed and logged.

A.5.15, A.5.18

Infrastructure and Operations

Source: POL.IT.001, WI.IT.001

Encrypted Transmission

Access to company information is permitted only through secure protocols such as TLS/HTTPS.

A.8.20, A.8.21

Encrypted Cloud Storage

Data in Microsoft 365 is encrypted at rest. Disabling this feature is not permitted.

A.8.24

Separate Data Backup

Backups are stored separately from production systems, protected against unauthorized access, and encrypted, and are restored on a random basis.

A.8.13

Logging and Monitoring

Security-related events in cloud services and on end devices are centrally recorded and analyzed.

A.8.15, A.8.16

Change Management

Changes to production systems are requested, evaluated, approved, and documented.

A.8.32

Secure Deletion

Destruction of data and data storage media in accordance with DIN 66399, with a minimum security level of 4 for confidential data.

A.8.10

Product and Development

Source: POL.IT.001

Secure Development Lifecycle

Security requirements from planning through design and testing to deployment and maintenance.

A.8.25

Secure Coding

Mandatory coding standards, code reviews, dependency scans. Secrets are never stored in the source code.

A.8.28

Security Review Before Release

Automated analyses, vulnerability scans, and penetration tests. Release only after documented approval.

A.8.29

Separate Environments

Production, development, and test environments are strictly separated from one another.

A.8.31

Protected Source Code

Centrally managed repositories with strong authentication and role-based permissions.

A.8.4

Outsourced Development

External development partners are subject to the same requirements and are audited annually.

A.8.30

Suppliers and Cloud Services

Source: POL.SC.001

Central Supplier Directory

Classification of all suppliers into the risk categories low, medium, high, and critical.

A.5.19

Security Requirements in the Contract

NDA for all suppliers. For high-risk and critical suppliers, additional clauses regarding incident reporting, subcontractors, and data return.

A.5.20

Annual Audit of Critical Suppliers

Verification through an ISO 27001 certificate or a supplier audit based on ISO 27001.

A.5.22

Life Cycle of Cloud Services

The acquisition, use, and discontinuation of cloud services are subject to binding regulations. Private cloud storage is prohibited.

A.5.23

Termination of the Contract in Accordance with the Terms

Data is deleted or returned, access is deactivated, and the final audit is documented.

A.5.20

Incidents and Business Continuity

Source: WI.IT.002, POL.IT.005, STA.IT.005

Defined Incident Process

Incident detection, triage, containment, analysis, recovery, and lessons learned, with a clear RACI assignment.

A.5.24–A.5.27

Rapid Escalation

High-severity incidents are discussed with senior management within 24 hours.

A.5.26

Data Breaches

Immediate review. Notification to the regulatory authority within 72 hours, if required.

A.5.34

Business Impact Analysis

Annual identification of critical processes and their interdependencies.

A.5.29

Emergency Plans and Drills

Documented response, recovery, and communication plans for all processes with an RTO of up to 48 hours, practiced annually.

A.5.30

Physical Security

Source: POL.IT.002, POL.HR.002

Remote-first without our own server rooms

CONSUST does not operate its own data centers. Its systems run on certified cloud and hosting providers.

A.7.1

Clean Desk and Clear Screen

Confidential documents are locked away, and screens lock after five minutes of inactivity at the latest.

A.7.7

Protecting Devices on the Go

Equipment is never left unattended. Any loss or theft is reported immediately.

A.7.9

Safe Disposal

Devices and data storage media are completely wiped before reuse or disposal.

A.7.14

Trust starts with transparency: Check our information security for yourself

Your Questions About Information Security. Our Answers.

Protecting your data is a top priority for CONSUST. Here you’ll find the most important answers.

Scroll to Top