Access control
Role-based permissions, individual accounts, strong authentication, secret management and periodic access reviews limit access.
Transfer and storage
Connections use transport encryption. Operational NOVA data at rest is primarily stored locally. Activated external data flows are limited to the required purpose and documented.
Availability and recovery
Monitoring, protected backups, recovery procedures, patching and vulnerability management support availability and resilience. Concrete intervals and targets appear in the contract schedule.
Logging and incidents
Security-relevant events are logged as appropriate. A process covers assessment, containment, recovery and required notifications.
Review
Measures are reviewed after material changes and periodically. The versioned TOM supplied to the customer are binding.