1. lntroduction
Adtelligence GmbH (ADT) is a mid-sized German technology company based in Mannheim. Since its foundation in 2009, Adtelligence GmbH has been developing SaaS solutions that use state-of-the-art technologies such as Big Data Analysis, Machine Learning and Artificial lntelligence (Al) to significantly improve the customer experience and customer revenues of its clients in the e-commerce and financial services sector.
This document contains excerpts from the global security design document of Adtelligence GmbH. The measures and processes described herein reflect the current status, unless otherwise stated.
2. Personal safety
2.1. Employee recruitment and induction process
The hiring process ensures that both the professional qualifications and the personal requirements of the position are sufficiently covered by the candidate. Permanent employees and freelancers are subject to the same hiring process or freelancers are treated in all respects as permanent employees. Freelancers of Adtelligence GmbH are all persons who work for Adtelligence GmbH as self-employed persons on the basis of a service contract without being integrated into the company. The Human Resources (HR) department of Adtelligence GmbH checks the suitability and trustworthiness of the candidate and finally decides in coordination with the management about the hiring. This is based on the professional qualifications as weil as the security requirements of the respective position.
All employees are made aware of their obligations regarding data protection and confidentiality as part of the hiring process or during the introductory process (onboarding) and are informed about possible consequences.
The hiring process ends with the start of the first working day and flows smoothly into the introductory process. In addition to individual familiarization procedures, the necessary access, entry and access authorizations for the corresponding position or role are assigned in this phase. A corresponding documentation of the authorizations can be found in the current roles and rights concept.
At least always subsequent steps are established in the introduction process:
1. Installation and handover of the security token (chip) / keys.
2. Setup and transfer of the initial access data for e-mail and network sharing.
3. implementation of an information and orientation event with the following contents:
a. lnstruction regarding internal security guidelines
b. Obligation to maintain data secrecy according to §53 BDSG new
c. Obligation to maintain social secrecy according to §35 SGB 1
d. lnstruction and obligation according to §88 TKG 1
e. lnstruction on handling and classification of documents and data
f. Sensitization for information security within the scope of the respective area of responsibility
2.2 Employee leaver process
The employee exit process begins with the termination of the employee. lt basically includes the clarification and timing of formalities, the handover of activities, the issuance of a work certificate, the surrender of all objects that are company property, and the withdrawal of all authorizations, in accordance with the current roles and rights concept. The HR department ensures that the process is adhered to and that the exit process checklist is processed. The checklist includes at least the following points:
1. Interna! information to the employees
2. On demand: external information to customers, partners and suppliers
3. Receipt of business objects:
a. Return of all (access) keys
b. Return of Security Token (chip)
c. Return notebook (if available)
d. Return (mobile) phone (if available)
e. Return of memory sticks, hard drives, CDs/ DVDs (if available)
f. Return of all documents entrusted to the person (in particular internal, confidential or classified documents)
4. locking the central user account.
5. revoking all user privileges.
6. revocation of all user certificates / digital keys.
Since it may become necessary in special cases to withdraw rights from an employee as soon as the termination is known but before the actual termination date, each action on the checklist is marked with an execution time stamp and confirmed by the signature of the person responsible.
2.3. Employee sensitization and staff training
Staff training and employee sensitization is a central topic at Adtelligence GmbH. Basically, a distinction is made between training topics in the following chapters.
2.3.1 Awareness raising and training on information security and internal policies
When the security guidelines came into force, all employees were initially instructed and made aware of information security. In addition, the introduction process ensures that new employees are familiar with the security guidelines of Adtelligence GmbH and have been sufficiently sensitized with regard to information security according to their respective position. Additional information events are held at irregular intervals following major adjustments to the guidelines, when a changed threat situation is identified and according to individual needs.
Topics of information security are in particular data protection and data security, password guidelines, data classification, secure behavior at the workplace as well as specific topics that fit the job profile.
1. Professional training and further education
The competence and motivation of the employees at Adtelligence GmbH is decisive for the company’s success. Employee development through further education and training is therefore of strategic importance for the company.
Each employee is responsible for identifying both his or her technical training needs and the need for safety instructions. The responsible department heads and/or the management ultimately decide on the implementation and form of training. Training opportunities are available both through attending external training courses and conferences and through internal workshops conducted by experienced and qualified employees.
2. Technical and organizational measures
Introduction
The contractor undertakes towards the customer to comply with the following technical and organizational measures which are necessary to comply with the applicable data protection regulations.
- Confidentiality of systems and services
- Integrity of systems and services
- Availability of systems and services
- Pseudonymization
- Encryption
- Resilience of systems and services
- Recovery and Backup
- Review, assessment and evaluation
2.1. Confidentiality of systems and services
Measures to ensure the confidentiality of the systems and services designed to prevent unauthorized access or disclosure of personal data at the controller itself or in transit to processors or third parties. These measures include, among others:
(1) Admittance control
Measures to deny unauthorized persons access to data processing systems with which personal data are processed or used:
- Electronic access control system with logging
- High security fence around the entire data center park
- Documented key allocation
- Guidelines for the escort and identification of guests in the building
- 24/7 staffing of the data centers
- Video surveillance at the inputs and outputs
- Security gates and server rooms
(2) System access control
Measures to prevent the use of data processing systems by unauthorized persons:
Operating system level:
- The server systems are password protected against unauthorized operation and access
- Network maintenance access is via SSH over an encrypted connection using private keys
- As server operating system serves Debian Linux with current patch status
- Access ports are protected by a host firewall and access is only allowed from maintenance systems of Adtelligence GmbH (monitoring, backup, etc.) or the network of Adtelligence GmbH Mannheim
- Access data for customer systems are only accessible to a small circle of persons of the supervising admins
- Access on operating system level is logged by a central IDS system
- Role-based access concept with separation of maintenance on application level and maintenance on operating system level
- Data media are only stored within the data center suite
Application level:
- Role-based access control concept with separation of accounts by name
- Administrative access to the application only for a limited number of employees
- Regular control of the accounts authorized to access
- Logging of accesses through dedicated audit log
- Logging of access attempts through dedicated audit log
- Access only via encrypted SSL connection
(3) Data access control
Measures to ensure that those authorized to use a data processing system can only access the data subject to their access authorization and that personal data cannot be unauthorized, read, copied, changed or removed during processing, use and after storage:
Operating system level:
- The server systems are password protected against unauthorized operation and access
- Network maintenance access is via SSH over an encrypted connection using private keys
- As server operating system serves Debian Linux with current patch status
- Access ports are protected by a host firewall and access is only allowed from maintenance systems of Adtelligence GmbH (monitoring, backup, etc.) or the network of Adtelligence GmbH Mannheim
- Access data for customer systems are only accessible to a small group of administrators
- Access on operating system level is logged by a central IDS system
- Role-based access concept with separation of maintenance on application level and maintenance on operating system level
- Monitoring by central IDS system
Application level:
- Role-based access control concept with separation of accounts by name
- Administrative access to the application only for a limited number of employees
- Regular control of the accounts authorized to access
- Logging of accesses through dedicated audit log
- Logging of access attempts through dedicated audit log
- Access only via encrypted SSL connection
Backup system:
- Separate storage of backups per customer
- Separate access authorization for backups of individual customers
- Administrative access only
(4) Pass on control
Measures to ensure that personal data cannot be read, copied, altered or removed without authorisation during electronic transmission or during their transport or storage on data carriers and that it is possible to check and establish to which bodies personal data are to be transmitted by data transmission equipment:
- Administrative transfer of data only via secure SSH connection or VPN
- Application level access only via encrypted SSL connection
- In case of physical transport by third parties, data systems are only transported encrypted
- The transfer and takeover is recorded
- Defective or no longer needed data carriers are either deleted by multiple overwriting or mechanically destroyed
- The making of copies is documented
- The stock of data media is documented and regularly checked
- For the administrative remote access there is a company internal regulation
(5) Separation control
Measures to ensure that data collected for different purposes can be processed separately:
- Strict separation of production systems, test systems and development systems
- If economically justifiable, physical separation of customer systems, otherwise at least logical separation on system, network and application level
- Data from different customers are not merged at any time
- System access data is assigned restrictively according to the respective tasks
2.2. Integrity of systems and services
Measures to ensure the integrity of the systems and services, which guarantee that personal data cannot be changed (unnoticed) These include, among others:
(1) Input control
Measures to ensure that it can be subsequently checked whether and by whom personal data have been entered, modified or removed in data processing systems:
- Allocation of personal user accounts and access data
- Logging of system accesses through native log files
- Regular checking of the system logs for abnormalities
- Logging of changes through application-specific log file
- Logging of deletion by application’s own log file
- Logging of changes on operating system level by a central IDS system
2.3. Availability of systems and services
Measures to ensure the availability of systems and services, which ensure that personal data is available continuously and without restriction and in particular that it is available when it is needed. These include, among others:
(1) Availability control
Measures to ensure that personal data is protected against accidental destruction or loss:
- Use of uninterruptible power supply
- Emergency diesel for autonomous operation
- Permanently active DDoS protection
- Temperature monitoring of the room air and in server/distribution cabinets
- Server systems are equipped with RAID systems
- Backup and recovery concept with daily backup of all relevant data
- Automated monitoring of servers and backup systems with alerts (monitoring)
- 24/7 on-call service by employees of Adtelligence GmbH
- Redundant design of the systems, if economically justifiable
(2) Order control
Measures to ensure that personal data processed by order can only be processed according to the instructions of the client:
- Contractual and operational regulations
- Regular control of the contractors
- Role-based access concept with separation on user basis
- Regular control of the user accounts authorized to access
- Orders must be placed or confirmed in writing
2.4. Pseudonymization
Measures for pseudonymization of personal data
- Randomly generated identifier as pseudonym for the assignment of otherwise individual personal data
- Separation of data storage in pseudonym and raw data depending on the level of protection of the type of personal data actually processed per business case
- In each individual case the necessity is checked and documented
2.5. Encryption
Measures to encrypt personal data
- Encryption of all system accesses
- Encryption of backups
2.6. Resilience of systems and services
Measures to ensure the resilience of systems and services, ensuring that systems and services are designed to cope with high point loads or high continuous loads on processing operations. (storage, access and line capacities)
- Virtualization platform with dynamically adaptable resource allocation
- Permanent 24/7 monitoring of all processing systems
2.7. Recovery and backup
Measures to rapidly restore the availability of and access to personal data following a physical or technical incident.
- Automated backup system
- Backup and recovery concept
2.8. Review, assessment and evaluation
Procedures for regular review, assessment and evaluation of the effectiveness of the above measures.
- Appointment of a data protection officer
- Obligation of employees to maintain data secrecy
- Sufficient training of employees in data protection matters
- Maintaining an overview of process directories
- Carrying out data protection impact assessments, where necessary
- Maintenance of a security concept and associated processes
- Audits of the data protection officer
- Regular testing of data recovery
- Regular testing of restart procedures
- External & internal checks & audits
- Incident Response Management
3. Classification of documents
At Adtelligence GmbH, documents and documentation are divided into different categories and are subject to the corresponding regulations according to their classification. A change of classification or cancellation is only possible after appropriate consultation and requires the consent of the management. Classifications apply to documents globally, individual approvals do not exist.
The following classifications of documents exist within Adtelligence GmbH:
3.1. Not classified
These documents are not subject to any restrictions and are freely accessible to everyone inside and outside the company. Documents in this category are not to be marked.
3.2. Confidential
Documentation and documents in the category “confidential” contain information that allows conclusions to be drawn about internal processes or technologies used by Adtelligence. These documents must be marked accordingly. These documents may only be released to non company employees after consultation with the respective document manager, if necessary only under certain conditions. Any release to third parties will be recorded. The internal transfer of documents is permitted and is not subject to any regulations.
3.3. Internal
Documents for internal company use. Documents of the category “internal” must be marked accordingly. Under no circumstances may documents be passed on to persons outside the company. Internal company use is permitted and is not subject to any regulations.
3.4. Secret
Documents containing information that should only be accessible to a specific group of people. Documents in this category should be marked as far as possible. Depending on the document, the exchange with external parties is allowed within a certain group of people, e.g. accounting. In general, the transfer is subject to regulations and may only be made from authorized persons to authorized persons. The documents must be handled with appropriate care and kept under lock and key when leaving the office.
3.5. Top Secret
Documents in this category contain top secret information that should only be known to the authorized persons e.g. personal data, account data, passwords, etc.
Documents in this category are to be kept under lock and key when not in use and may not be disclosed under any circumstances without the agreement of the person responsible for the document. Reproduction without express permission is prohibited.
4. Roles and rights concept
A precise documentation of the roles and rights concept is provided by the latest version. This can be requested on request.
4.1. Roles
At Adtelligence GmbH, access rights are assigned according to a role concept, access rights are assigned to roles. A user can have one or more roles. Granting and withdrawal of access rights are logged with date and time.
4.2. Documentation Role-Rights Concept
A detailed documentation of the role rights concept is provided by the latest version of the file “ADT-Role Rights Concept”. Here the following information will be recorded and made available:
- Role-Rights-Listing
- List of employee roles
- Internal system matrix (internally used systems and roles)
- System matrix customer systems (internal and external access authorizations)
5. Access control premises Adtelligence GmbH
The visitor regulation describes regulations and measures which ensure that no unauthorized access to buildings, parts of buildings and offices occurs; furthermore, that unauthorized access to data processing systems is excluded. Furthermore, it is guaranteed that unauthorized persons do not gain access to data and programs.
Organizational measures
- The visitor regulation is documented in the latest version of the “Work instruction visitor regulation” and communicated to all employees of Adtelligence GmbH
6. Information technology security
Responsible for IT security at the Adtelligence GmbH site are the employees of the IT Administration group. In particular, this area includes the planning, implementation, documentation and auditing of adequate security measures to protect the information technology systems and the information stored on them.
The general concept for information technology security was developed in coordination with all departments and is continuously reviewed and updated as necessary.
6.1. Network Security
Adtelligence GmbH distinguishes between Adtelligence’s internal network segments (office network, guest network, infrastructure network) and external networks (server network, customer server network and development network).
The Adtelligence internal and Adtelligence external networks are structured restrictively separately from each other and can run independently of each other. Connections between the individual network segments are strictly regulated by individual firewall rules.
The Adtelligence internal and Adtelligence external networks are distributed over the following locations:
- Adtelligence GmbH, Elisabethstraße 1, 68165 Mannheim
- Hetzner Online GmbH, Data Center Park Falkenstein
Leaseweb Deutschland GmbH, Hanauer Landstraße 121, 60314 Frankfurt am Main
The locations are connected by a site-to-site VPN.
The customer servers themselves are protected from the outside by a central office and additionally by a host-based firewall, which allows administrative access only from Adtelligence’s internal network segments.
The data center is equipped with DDOS protection to ward off attacks before they reach our infrastructure. In addition, individual services can be protected against external access via a web application firewall.
6.1.1. Managed Switches
So-called managed switches are used in the network infrastructure of Adtelligence GmbH. These switches are used to subdivide the respective site networks into logical networks (VLANs). A connection between the individual VLANs is only possible at certain transition points (router/firewall) and is strongly regulated.
6.1.2. Wireless network access
The employees of Adtelligence GmbH are provided with wireless network access (WLAN) for free working within the building with approved devices. The WPA2 protocol with AES encryption is used to secure the wireless network.
6.1.3. VPN
As already documented in chapter 7.1, the respective sites are connected via a site-to-site VPN. The VPN terminates on the respective firewall. In addition to the VPN, the firewall ensures that the respective network resources can only be accessed by authorized groups of people. The VPN was configured with the following security features:
SSL-VPN:
- Software: OpenVPN
- Protocol: SSL-VPN via TLS
- Key exchange and authentication: SSL certificate
6.2. Server protection
6.2.1. Data backup concept
Adtelligence GmbH’s data backup concept provides two backup cycles to ensure that data can be restored up to two weeks into the past.
Data backup plan:
- Weekly backup: Once a week a complete backup of the environment to be backed up is created.
- Daily backups: Once a day a differential backup is created based on the current weekly full backup.
Since all relevant data is managed and stored on the server side, the backup is limited to the data backup of the relevant servers. A data backup of the IT workstations is not provided.
The backup contains at least the following data:
- Databases
- System configuration
- Security relevant log files of the systems
The restoration of backups is tested and verified at regular intervals.
6.2.2. Host-based Intrusion Detection Systems
A host intrusion detection system is used on the server side. The corresponding client is installed on each server. The system monitors and evaluates the local log files, performs integrity checks on system and configuration files, monitors system policies and detects possible rootkits. All findings of the client are reported to a central server and documented.
7. IT Security Management
Responsible for IT security management at the Adtelligence GmbH site are the employees of the IT Administration group. The employees maintain and operate the processes and tools that ensure the smooth operation of our systems and the security of our customers’ data.
7.1. Monitoring
Our systems are constantly monitored by our monitoring systems. The monitoring is divided into an internal monitoring that stores system data in detail centrally and can inform a group of employees in case of exceptions, and an external monitoring that monitors our systems at another location. Stored are status and performance data about our systems, including
- Status via processes and applications
- Status about the patch status and applied patches
- Status on the availability of interfaces
- Performance data such as available RAM, CPU and disk space
- Performance data of the network interfaces
- Access to systems (successful and unsuccessful)
- Occurring errors in log files
The monitoring system can determine the type and importance of an alarm and report it to an appropriate employee group. Critical system errors are logged as incidents in our ticket system and reported to the 24/7 on-call service.
7.2. Asset Management
All hardware and software components are managed in asset databases. In addition to supplier, maintenance and location data, the databases also contain information on license durations and technical information.
7.3. Capacity Management
All host systems and virtual servers are continuously monitored by a central monitoring system. This also includes network components and storage systems. Bottlenecks in one of our systems are reported to the IT administration at an early stage and are eliminated. A regular check of the total capacities ensures that there are enough reserves available. Our private cloud architecture ensures that resources can be easily expanded during operation.
7.4. Change Management
Changes to systems are made by arrangement in the administrator team and documented by a ticket. All changes are done by our infrastructure automation and are versioned and documented. Changes can usually be undone. Exceptions are documented separately.
7.5. Incident Management / Service Request Management
Incidents are managed in our ticket system. Each ticket contains a description including the possibility to trace the problem, the criticality and a detailed process of the trouble shooting. Tickets are assigned a solution period based on their criticality:
- Medium – Tickets that are processed during the day and have no effect on customer systems
- High – Tickets that are processed within 24 hours and have no critical impact on customer systems.
- Highest – Tickets with critical errors that are processed immediately
In a weekly regular meeting the accrued tickets are discussed and corresponding improvement measures are decided upon.
7.6. Patchmanagement
In order to keep our systems up to date, they are updated at fixed intervals. To check the patch status, various sources are available:
- Host systems and hardware in the data center are monitored by the data center operator
- Cloud infrastructure – Security patches are monitored and reported via monitoring
- Virtual servers – Security patches are monitored and reported via monitoring
- Third-party software – Security feeds are available for the software used to report security vulnerabilities
In regular operation our systems are updated every 14 days on Thursdays between 23:00 and 05:00. Maintenance with a non-availability of more than 30 minutes is announced in advance. Critical system patches with a CVE score greater than 7.5 are applied to our systems as quickly as possible.
8. Glossary of terms