NetzWerkPlan

Solution

Security

The data centre meets the following standard:

  • Data centre certified to DIN ISO/IEC 27001
  • Redundant broadband cabling with a direct link to the German internet exchange DE-CIX
  • 1 Gbit/s internet connection, 10 Gbit/s internet backbone (see www.ecotel.de)
  • Access control system; entry only after prior registration and authentication
  • Technicians on site 24 hours a day
  • Fire detection and extinguishing system
  • Intruder alarm system
  • Air conditioning
  • Emergency power generator and uninterruptible power supply

The servers administered by NetzWerkPlan use the following security mechanisms:

  • Latest-generation servers with high-quality redundant components
  • Customer and project data is held in encrypted, redundant storage
  • 24/7 monitoring at 60-second intervals; alerts are sent immediately through several channels
  • 99.9% server availability guaranteed, excluding scheduled maintenance
  • Network security: firewall, IP filtering, port scan detection, DoS and DDoS protection, network segmentation, IDS/IPS, IP whitelisting
  • Virus and spam filtering
  • Daily checks for operating system and other security-relevant software updates
  • Daily backups across distributed disks
  • Redundant servers and backups in a geo-redundant data centre
  • Optional daily backup (runtime archiving) to a server provided by the client

The winplan 2.0 system uses the following security mechanisms:

  • Access to the application with username and password
  • Password policies configurable per company
  • Optional two-factor authentication and single sign-on
  • Detailed permission management within the application
  • Encryption of all file path information
  • SSL/TLS encryption of data transfer (https, TLS 1.2 and TLS 1.3)
  • The application is tested regularly with a range of analysis tools for security vulnerabilities, ruling out the following problems:

XSS vulnerabilities, insecure cookie handling (HTTP-Only, Secure attribute), X-Frame headers (where possible), autocomplete on sensitive input fields, and insecure encoding of input characters.

  • Penetration tests carried out regularly by external security companies

Can we help you with security?

Tell us about your project and we'll walk you through winplan using your own requirements.