Your contact information
DCS Retire
With DCS Retire, you can decommission outdated systems without losing valuable data. The data is transferred completely and securely while preserving the source data model, is assigned retention periods, and remains available via rights-based access for research, audits, and tax audits. Here, you can learn how we manage information security in DCS Retire, both in Natuvion Hosting and in on-premises operations.
Scope and Operation
-
What is the scope of information security and data protection for DCS Retire?
-
What certifications apply to DCS Retire?
DCS Retire is included in the scope of the ISO 27001 certification.
-
In which operating models is DCS Retire available?
DCS Retire is a web-based application and can be deployed flexibly in various operating models. These include the cloud service operated by Natuvion within the EU, as well as operation within the customer’s infrastructure.
Depending on specific requirements, additional hosting regions can also be arranged. -
How are responsibilities divided between Natuvion and the customer?
Natuvion and the customer share responsibility under the shared-responsibility model. In both operating models, the customer is responsible for the archived data, decisions regarding its retention and deletion, and the management of its users and their permissions, while Natuvion always handles the provision of the software and updates.
Responsibility for operations, infrastructure, backup, and monitoring lies with
Hosting: with Natuvion.
On-premises: with the customer. -
What does the customer need to keep in mind to ensure safe operation?
Hosting: The customer is responsible for the careful management of its users, roles, and permissions, as well as for verifying the configurations it has made or approved.
On-Premises: The customer provides the necessary infrastructure and is responsible for its secure operation. Responsibility for maintenance and updates is determined by the agreed-upon operating model.
Data Protection and Data Processing
-
Can personal data or data requiring special protection be archived?
Depending on the source system, personal data and data requiring special protection may also be archived; the customer, as the data controller, is responsible for determining the lawfulness and classification of such data.
Hosting: Natuvion processes the data on behalf of the customer based on a Data Processing Agreement (DPA).
On-Premises: Processing takes place in the environment specified by the customer. -
Where is data processed and stored?
Hosting: Data is transferred from the source system and, by default, processed and stored on established cloud platforms within the EU. Depending on the agreed-upon hosting requirements, processing may also take place in another region.
On-premises: Processing and storage take place in the environment specified by the customer. -
What operational, log, and support data does Natuvion process?
Hosting: Natuvion processes technical operational and log data only to the extent necessary for operation, security, and support, separately from the archived data.
On-Premises: Natuvion receives diagnostic data only if the customer provides it as part of a support request. -
How are data from different customers kept separate from one another?
Hosting: Each customer operates in its own production environment, isolated from other customers.
On-premises: The customer determines the scope of data and the separation within their own environment. -
Are AI features used, and what happens to customer data in the process?
DCS Retire can optionally be enhanced with AI-powered features. Use of these features is not required. All essential functions of DCS Retire are available even without the use of AI.
Hosting: The AI features are provided via established cloud platforms within the EU. Customer data is not used to train the underlying AI models.
On-Premises: The customer decides for themselves whether and which AI models to integrate.
Identity and Access Management
-
How do users log in?
DCS Retire can be integrated with the customer’s central user management system. This allows the security features and policies for authentication and access control established in that system to also be used for accessing DCS Retire.
Alternatively, user accounts can be managed directly within DCS Retire and protected by additional security mechanisms such as multi-factor authentication. -
How are roles and permissions managed?
Access is controlled through a role-based authorization model that allows for the assignment of permissions according to the principle of least privilege. The customer is responsible for assigning roles and reviewing them on a regular basis.
-
How does Natuvion protect administrative and support access?
Hosting: Administrative access by Natuvion is limited to authorized identities and access paths, and is further secured and traceable.
On-Premises: Access by Natuvion occurs only after approval by the customer and within the scope of the agreed-upon support services.
Data Security
-
How is data protected during transmission and storage?
-
How are the integrity and traceability of archived data ensured?
DCS Retire extracts the relevant data from the source system in a structured manner and ensures its integrity during the extraction process. After successfully verifying that the data is complete and accurate, it is protected against unauthorized modifications.
Retention and Deletion
-
How are retention and destruction periods determined?
-
How are required deletions carried out and documented?
Hosting: Data subject to deletion is reviewed and deleted in accordance with the specified deadlines; the decision to delete is made by the customer.
On-Premises: Deletion is initiated and documented by the customer using the product’s built-in functionality. -
How are legal holds managed?
Authorized roles can apply a deletion lock to data, which suspends deletion until the lock is removed. The decision to apply or remove the lock rests with the customer.
-
How can archived data be searched and exported?
Archived data can be searched and exported via a web-based interface, subject to user permissions. The customer is responsible for selecting and retrieving the data.
-
How does DCS Retire help with regulatory requirements?
DCS Retire supports customers with features for retention, deletion, deletion locks, access control, and traceability to meet regulatory requirements. It is the customer’s responsibilityto determine which requirements apply in each specific case and how they are implemented .
-
What happens to the data when the contract ends?
Hosting: Upon termination of the contract, customer data stored in the environment operated by Natuvion will be transferred to the customer or deleted in accordance with the contractual agreement. The deletion applies exclusively to data stored in the environment operated by Natuvion.
On-Premises: The data remains in the environment operated by the customer and is therefore the customer’s responsibility.
Secure Development and Operation
-
How are vulnerabilities and security updates handled?
Vulnerabilities and security risks are reviewed, assessed, and addressed according to their relevance as part of established development and security processes.
Hosting: Security updates are taken into account and applied as part of the operations managed by Natuvion.
On-premises: The implementation of security updates is based on the agreed-upon operating model and is carried out by Natuvion or the customer. -
How are releases managed?
Releases are versioned, tested prior to delivery, and made available through a controlled release process.
Hosting: Natuvion handles the installation of new releases.
On-Premises: Depending on the agreed-upon operating model, installation is performed by Natuvion or by the customer. -
How are security and operational events monitored?
Hosting: Natuvion monitors the environment it operates for relevant events and anomalies as part of its established operational and security processes.
On-Premises: Monitoring of the customer’s environment is generally the customer’s responsibility and is governed by the customer’s own operational and security processes.
Incident Management
-
How are security incidents handled?
Hosting: Security incidents are detected and assessed according to defined processes, handled appropriately, documented, and followed up on.
On-Premises: Security incidents in the customer’s environment are generally handled by the customer. Natuvion provides support within the scope of the agreed-upon support services. -
How are customers notified of security incidents?
Natuvion notifies affected customers of relevant security incidents in accordance with applicable legal and contractual requirements.
Business Continuity
-
How is the availability of DCS Retire ensured?
Hosting: Natuvion operates DCS Retire via established cloud platforms in a monitored hosting environment. Measures to ensure and restore operations are integrated into the relevant operational and emergency procedures.
On-Premises: Ensuring the availability of DCS Retire is the customer’s responsibility. -
What are the procedures for data backup and recovery?
Hosting: Natuvion performs regular data backups and verifies recoverability in accordance with defined procedures. Established emergency and recovery processes are in place to resume operations.
On-Premises: Data backup and recovery are the customer’s responsibility.
Subcontractor
-
Which external service providers are relevant to DCS Retire?
External service providers are screened against defined requirements before being contracted. Relevant suppliers and service providers are regularly monitored and evaluated as part of the supplier management process.
Hosting: Natuvion uses established cloud platforms to operate DCS Retire, typically within the EU. Subcontractors and relevant processing locations are taken into account within the framework of contractual and data protection agreements.
On-Premises: The selection and management of service providers used by the customer are the customer’s responsibility.
Contact
Would you like to learn more? Simplyfill out the contact form, and we’ll get back to you as soon as possible.
Contact us now