Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
pub:trust_center:controls [15.06.2025 22:06] – [Table] Predrag Tasevski | pub:trust_center:controls [15.06.2025 22:09] (current) – [Table] Predrag Tasevski | ||
---|---|---|---|
Line 18: | Line 18: | ||
| Business Controls | | Business Controls | ||
- | | Application Design Controls | + | | Application Design Controls |
- | | Application Design Controls | + | | Application Design Controls |
- | | Application Design Controls | + | | Application Design Controls |
- | | Application Design Controls | + | | Application Design Controls |
- | | Application Design Controls | + | | Application Design Controls |
- | | Application Design Controls | + | | Application Design Controls |
- | | Application Design Controls | + | | Application Design Controls |
- | | Application Design Controls | + | | Application Design Controls |
- | | Application Design Controls | + | | Application Design Controls |
| Application Implementation Controls | List of data | Data types (PII, etc.) documented in EspoCRM. Models versioned in Git and listed in Nextcloud. | | | Application Implementation Controls | List of data | Data types (PII, etc.) documented in EspoCRM. Models versioned in Git and listed in Nextcloud. | | ||
Line 34: | Line 34: | ||
| Application Implementation Controls | Build process | CI/CD pipelines enforce clean builds, no hardcoded secrets. Provenance signed and tracked. | | | Application Implementation Controls | Build process | CI/CD pipelines enforce clean builds, no hardcoded secrets. Provenance signed and tracked. | | ||
- | | Operational Controls | Physical access | Data centers via Hetzner/ | + | | Operational Controls |
- | | Operational Controls | Logical access | RBAC + SSO + MFA enforced. Access reviews quarterly using **Unicis Cybersecurity Controls**. Inactive accounts deactivated by n8n. | | + | | Operational Controls |
- | | Operational Controls | Sub-processors | Public DPA maintained. Sub-processors reviewed annually and stored in Nextcloud. Linked to **Unicis Cybersecurity Controls**. | | + | | Operational Controls |
- | | Operational Controls | Backup & Disaster Recovery | Daily encrypted backups, restore tests monthly. Logged in OpenProject, | + | | Operational Controls |