Trust Center
Verified Security for Your Business Data
Your ESG, supply chain, and GRC data are particularly sensitive. That is why we protect your data using an ISMS certified to ISO/IEC 27001:2022, documented controls, and regularly audited processes.
We focus on measurable security
93 / 93
Controls from Annex A of ISO/IEC 27001:2022 are applicable and have been implemented
0
Exclusions in the Statement of Applicability following review during the certification audit
≤ 48 hours
Recovery Time Objective (RTO), the point at which processes are considered critical and are assigned a tested contingency plan
EU
FramesCube is hosted by an ISO 27001-certified data center operator
Standards
Standards and guidelines by which we measure ourselves
Certified
ISO/IEC 27001:2022
Certified ISMS based on the PDCA cycle, with risk-based selection of controls, internal audits, and an annual management review.
Implemented
GDPR and BDSG
Technical and organizational measures, data processing agreements, and a record of processing activities. Data minimization and purpose limitation as principles.
Mapped
NIS2UmsuCG
Based on our own assessment, CONSUST is not currently subject to NIS2 requirements. Nevertheless, our Statement of Applicability is mapped to the requirements of the NIS2UmsuCG.
Documents
Our ISMS documentation for your supplier audit
The certificate and public SoA are available to everyone. Guidelines and work instructions are classified as “restricted” and will be provided upon completion of a confidentiality agreement.
ISO 27001 Certificate
TÜV Rheinland Certificate, Including Scope and Validity
ISO/IEC 27001
Statement of Applicability (Public Version)
All 93 controls from Appendix A, including applicability, status, and NIS2 mapping
STA.IT.003
ISMS Policy
Security Strategy, Scope, Risk Management, and the PDCA Cycle
POL.IT.003
ISMS Charter
Mission, Objectives, and Governance of the ISMS, signed by management
POL.IT.004
Guidelines for Safe Operation
Technological Controls under Annex A.8: End Devices, Access, Cryptography, Development
POL.IT.001
Information Security and Data Protection
Classification, Password and Information Management, Use of AI Tools
STA.IT.002
Supplier Management Policy
Risk Categories, Contract Requirements, and Annual Supplier Audits
POL.SC.001
Business Continuity Policy
Business Impact Analysis, Emergency and Recovery Plans, Annual Drills
POL.IT.005
Incident Management
Reporting Channels, Classification, Escalation, and Follow-Up of Security Incidents
WI.IT.002
Change Management
Tested and approved changes to production systems
WI.IT.001
Guidelines for Secure HR Processes
Screening, Confidentiality, Training, Onboarding and Offboarding
POL.HR.001
Mobile Work and BYOD Policy
Clean Desk, Screen Lock, Protection of Devices Outside the Premises
POL.HR.002
Physical Security Policy
Access, protection against environmental hazards, safe disposal of operating materials
POL.IT.002
You will receive confidential ISMS documents after signing an NDA.
For your supplier audit, we’re happy to provide you with additional documents from our ISMS, including guidelines and work instructions. These documents are classified as “restricted” by us. Therefore, we’ll send them to you after you’ve signed a non-disclosure agreement (NDA). Please request the documents using the form. We will then send you the NDA and make the documents available once it has been signed.
Security checks
Here’s How We Protect Your Data in Everyday Life
A selection of the implemented measures, organized by topic. The number refers to the corresponding control in Annex A of ISO/IEC 27001:2022.
- Organization and Governance
- Staff and Awareness
- Devices and Access
- Infrastructure and Operations
- Product and Development
- Suppliers and Cloud Services
- Incidents and Business Continuity
- Physical Security
Organization and Governance
Source: POL.IT.003, POL.IT.004
Information Security Policy
Approved by management, communicated to all employees, and reviewed annually.
A.5.1
Appointed CISO with clearly defined roles
The roles and responsibilities of executive management, the CISO, BCM, data protection, and supplier management are documented.
A.5.2
Risk-Based Approach
Risks are assessed at least once a year and as needed, recorded in the risk register, and accompanied by corresponding measures.
Kl. 6.1
Classification of Information
Three classification levels: public, restricted, confidential. Documents without a classification designation are considered restricted.
A.5.12
Internal Audits and Management Review
Internal audit conducted by an external auditor and a management review at least once a year.
Kl. 9.2, 9.3
Guided Documentation
All ISMS documents are subject to version control, an approval process, and retention periods.
Kl. 7.5
Staff and Awareness
Source: POL.HR.001, STA.IT.002
Risk-Based Security Review
Roles are classified into risk levels, and the scope of the review is determined accordingly. Consent is obtained in advance.
A.6.1
Confidentiality Agreements
All employees and external parties with access to systems and data sign a confidentiality agreement.
A.6.6
Mandatory Safety Training
Training on phishing, passwords, data protection, and incident reporting, with refresher sessions at least once a year.
A.6.3
Structured Onboarding and Offboarding
Checklists for HR, IT, and management. Access rights are revoked in a timely manner upon termination.
A.5.11, A.6.5
Mandatory Reporting of Security Incidents
Easy-to-use reporting channels via the service portal and email. Guiding principle: Reporting is better than perfection.
A.6.8
Devices and Access
Source: POL.IT.001, STA.IT.002
Centrally Managed Company Devices
All workstation devices are managed using a security baseline via Microsoft Intune. No local administrator rights.
A.8.1, A.8.9
Hard Drive Encryption
End-to-end encryption of mobile devices using BitLocker.
A.8.24
EDR and Host Firewall
Centrally managed Endpoint Detection and Response, as well as an enabled firewall on all company devices.
A.8.7
Timely Patch Management
Security updates are distributed automatically and installed within five business days. Critical vulnerabilities are addressed immediately.
A.8.8
Multi-factor authentication
Required for central cloud services and all privileged accounts. Legacy authentication is disabled.
A.8.5
Least Privilege and Need-to-Know
Access rights are role-based and limited to what is necessary; they are regularly reviewed and logged.
A.5.15, A.5.18
Infrastructure and Operations
Source: POL.IT.001, WI.IT.001
Encrypted Transmission
Access to company information is permitted only through secure protocols such as TLS/HTTPS.
A.8.20, A.8.21
Encrypted Cloud Storage
Data in Microsoft 365 is encrypted at rest. Disabling this feature is not permitted.
A.8.24
Separate Data Backup
Backups are stored separately from production systems, protected against unauthorized access, and encrypted, and are restored on a random basis.
A.8.13
Logging and Monitoring
Security-related events in cloud services and on end devices are centrally recorded and analyzed.
A.8.15, A.8.16
Change Management
Changes to production systems are requested, evaluated, approved, and documented.
A.8.32
Secure Deletion
Destruction of data and data storage media in accordance with DIN 66399, with a minimum security level of 4 for confidential data.
A.8.10
Product and Development
Source: POL.IT.001
Secure Development Lifecycle
Security requirements from planning through design and testing to deployment and maintenance.
A.8.25
Secure Coding
Mandatory coding standards, code reviews, dependency scans. Secrets are never stored in the source code.
A.8.28
Security Review Before Release
Automated analyses, vulnerability scans, and penetration tests. Release only after documented approval.
A.8.29
Separate Environments
Production, development, and test environments are strictly separated from one another.
A.8.31
Protected Source Code
Centrally managed repositories with strong authentication and role-based permissions.
A.8.4
Outsourced Development
External development partners are subject to the same requirements and are audited annually.
A.8.30
Suppliers and Cloud Services
Source: POL.SC.001
Central Supplier Directory
Classification of all suppliers into the risk categories low, medium, high, and critical.
A.5.19
Security Requirements in the Contract
NDA for all suppliers. For high-risk and critical suppliers, additional clauses regarding incident reporting, subcontractors, and data return.
A.5.20
Annual Audit of Critical Suppliers
Verification through an ISO 27001 certificate or a supplier audit based on ISO 27001.
A.5.22
Life Cycle of Cloud Services
The acquisition, use, and discontinuation of cloud services are subject to binding regulations. Private cloud storage is prohibited.
A.5.23
Termination of the Contract in Accordance with the Terms
Data is deleted or returned, access is deactivated, and the final audit is documented.
A.5.20
Incidents and Business Continuity
Source: WI.IT.002, POL.IT.005, STA.IT.005
Defined Incident Process
Incident detection, triage, containment, analysis, recovery, and lessons learned, with a clear RACI assignment.
A.5.24–A.5.27
Rapid Escalation
High-severity incidents are discussed with senior management within 24 hours.
A.5.26
Data Breaches
Immediate review. Notification to the regulatory authority within 72 hours, if required.
A.5.34
Business Impact Analysis
Annual identification of critical processes and their interdependencies.
A.5.29
Emergency Plans and Drills
Documented response, recovery, and communication plans for all processes with an RTO of up to 48 hours, practiced annually.
A.5.30
Physical Security
Source: POL.IT.002, POL.HR.002
Remote-first without our own server rooms
CONSUST does not operate its own data centers. Its systems run on certified cloud and hosting providers.
A.7.1
Clean Desk and Clear Screen
Confidential documents are locked away, and screens lock after five minutes of inactivity at the latest.
A.7.7
Protecting Devices on the Go
Equipment is never left unattended. Any loss or theft is reported immediately.
A.7.9
Safe Disposal
Devices and data storage media are completely wiped before reuse or disposal.
A.7.14
Trust starts with transparency: Check our information security for yourself
FAQ
Your Questions About Information Security. Our Answers.
Protecting your data is a top priority for CONSUST. Here you’ll find the most important answers.
