Your contact information
Natuvion DCS Migrate
DCS Migrate is the central migration module of the Data Conversion Suite and covers the entire data migration value chain in a single solution. Data from various sources is read, processed, enriched, and securely transferred to the target systems. Here you can learn how we ensure information security in DCS Migrate.
Scope and Operation
-
What is the scope of information security and data protection for DCS Migrate?
-
What certifications apply to DCS Migrate?
DCS Migrate is included in the scope of Natuvion's ISO 27001 certification and TISAX assessment.
-
How is DCS Migrate operated?
DCS Migrate is an SAP-based solution that is installed in its own namespace directly within the customer's SAP system and is operated via the SAP interface. Natuvion does not operate its own infrastructure for this purpose.
-
How are responsibilities divided between Natuvion and the customer?
The customer is responsible for the operation, infrastructure, data backup, and monitoring of its SAP system, as well as for the data processed and its users' access permissions. Natuvion provides software, updates, and documentation, and offers support within the scope of agreed-upon project or support services.
-
What does the customer need to keep in mind to ensure safe operation?
The customer installs DCS Migrate using SAP Transport, assigns the provided roles according to the principle of least privilege, and operates the SAP system in accordance with their organization's security policies. Transformations should be tested in test or copy systems before being deployed in production systems.
Data Protection and Data Processing
-
Is personal data processed?DCS Migrate transforms data in the customer’s SAP system; this process may also involve the processing of personal data. The customer remains the data controller; if Natuvion accesses the customer’s systems as part of project or support services, this is done on the basis of a data processing agreement (DPA).
-
Where is data processed and stored?
Processing and storage take place entirely within the customer's SAP system landscape. Data is transferred between systems only if the customer configures this in the transformation.
-
What operational, log, and support data does Natuvion process?
Logs for processing runs are stored in the customer's SAP system.
-
Are AI features used, and what happens to customer data in the process?
DCS Migrate offers optional AI features to support the migration process, the use of which is customized in consultation with the customer.
Retention and Deletion
-
What happens to the data when the contract ends?
Since DCS Migrate runs in the customer's SAP system, all data remains within the customer's environment and under the customer's responsibility even after the contract ends. Once the project is complete, the customer can remove DCS Migrate from their system.
Identity and Access Management
-
How do users log in?Login is handled through the user management system of the customer's SAP system. Procedures set up there, such as single sign-on or multi-factor authentication, also apply to DCS Migrate.
-
How are roles and permissions managed?
Natuvion provides predefined SAP roles for various tasks. The customer is responsible for assigning these roles and reviewing them on a regular basis.
-
How does Natuvion access customer systems?
Natuvion accesses customer systems only through users provided and authorized by the customer and within the agreed-upon scope of the project or support. The customer determines the scope and duration of such access.
Data Security
-
How is data protected during transmission and storage?
The level of protection during storage and transmission depends on the configuration of the SAP system and the customer's infrastructure.
-
How are transformations documented in a way that is easy to follow?
DCS Migrate logs processing runs, including the affected tables, so that transformations can be traced. The logs remain in the customer's SAP system.
Secure Development and Operation
-
How is security addressed in the development of DCS Migrate?
DCS Migrate is developed according to a secure development lifecycle that includes defined security policies, code reviews, and regular security audits. Deployment within a dedicated SAP namespace prevents conflicts with customer-specific developments.
-
How are vulnerabilities and security updates handled?
Natuvion identifies and resolves vulnerabilities and provides fixes and new releases as SAP transports. The customer is responsible for implementing and testing them in the system landscape.
-
How are releases and the termination of use managed?
Releases are versioned and delivered with documentation. Once the project is complete, the customer can remove DCS Migrate from its system; the transformed data remains the customer’s responsibility.
Incident Management
-
How are security incidents handled?
The customer is responsible for handling incidents in the customer's SAP system; Natuvion provides support within the scope of the agreed-upon support services. Product-related security issues are handled in accordance with Natuvion's incident management process.
-
How are customers notified of security incidents?
Natuvion provides information about product-related security issues and available fixes through the agreed-upon channels.
Business Continuity
-
How is the availability of DCS Migrate ensured?
Availability depends on the customer's SAP system and is the customer's responsibility. Natuvion's development and support teams are integrated into Natuvion's emergency and business continuity management.
-
What are the procedures for data backup and recovery?
The customer is responsible for backing up and restoring the SAP system.
Subcontractor
-
Which external service providers are relevant to DCS Migrate?
Since DCS Migrate runs on the customer’s SAP system, Natuvion does not use any external hosting service providers. To the extent that Natuvion engages subcontractors in connection with project or support services, these subcontractors are contractually bound and named in the General Terms and Conditions (AVV).
Contact
Would you like to learn more? Simplyfill out the contact form, and we’ll get back to you as soon as possible.
Contact Us Now