How To Certify A Security Area Datacenter For A Trustworthy Site Infrastructure



Similar documents
fulfils all requirements for very high protection of the criteria catalogue The appendix is part of the certificate and consists of 4 pages.

fufils all requirements for high protection of the criteria catalogue The appendix is part of the certificate and consists of 4 pages.

fulfils all requirements for medium protection of the criteria catalogue The appendix is part of the certificate and consists of 4 pages.

fulfils all requirements for extended protection of the criteria catalogue The appendix is part of the certificate and consists of 4 pages.

fulfils all requirements for medium protection of the criteria catalogue The appendix is part of the certificate and consists of 4 pages.

fulfils all requirements defined in the technical specification The appendix to the certificate is part of the certificate and consists of 6 pages.

fulfils all requirements of the SIG/TÜViT Evaluation Criteria

to confirm that its document management- and archiving solution fulfils all applicable audit criteria for document management solutions

fulfils all requirements defined in the technical specification The appendix to the certificate is part of the certificate and consists of 6 pages.

Only a matter of power supply and air conditioning? Joachim Faulhaber TÜV Informationstechnik GmbH

fulfils all requirements of the SIG/TÜViT Evaluation Criteria

ANNEXURE 07: CHECK-LIST FOR OFF-SITE STORAGE FACILITIES

MARULENG LOCAL MUNICIPALITY

REVIEWED ICT DATA CENTRE PHYSICAL ACCESS AND ENVIROMENTAL CONTROL POLICY

Corporate ICT Availability

ABB Stotz-Kontakt GmbH ABB safe&smart Project planning of security systems

Integrated Alarm Systems

5162 E. Working in oxygen-reduced atmospheres BGI/GUV-I 5162 E. Information

IBM Twin Data Center Complex Ehningen Peter John IBM BS 2011 IBM Corporation

Chapter 8 Security Systems

Content Index. 1. General Location and Building Telecommunication Feeds Electric Power Climate Control...

National Archives and Records Administration (NARA) Facility Standards for Federal Records Storage Facilities

Component acceptability for CE product Safety

ISO IEC ( ) INFORMATION SECURITY AUDIT TOOL

Security rooms for data centres

How can I protect valuable assets from fire and ensure business continuity?

BRANCH SOLUTION. Automatic fire extinguishing systems for paint spraying plants. Safe for certain.

WASTE Application Form - Dublin Waste to Energy SECTION J ACCIDENT PREVENTION & EMERGENCY RESPONSE

DATACENTER BERLIN Definitely a Good Perspective

Control and Indicating Equipment

FIRE DETECTION SYSTEMS ALARM STRATEGIES 2.0. New Version

Powering the Cloud Desktop: OS33 Data Centers

Current as of 11/10/08 1 of 1

Document Details. 247Time Backup & Disaster Recovery Plan. Author: Document Tracking. Page 1 of 12

How To Use A Sata Dsa Hard Disk Storage System

Appendix E: DEM Record Recovery Plan. From DEM Records Management Policy: A Report of the Records Management Policy Working Group, June 9, 2003.

READ AND SAVE THESE INSTRUCTIONS

CITY UNIVERSITY OF HONG KONG Physical Access Security Standard

Separation of power and information technology cabling

Directorate of Estates and Facilities EPM FM5. Estates Emergency Incident Response Procedure

Risk Engineering Guideline

Datacenter Assessment

Additional Requirements

Security Control Standard

Engineers Edge, LLC PDH & Professional Training

Understanding Emergency Power Off (EPO)

Professional planning and realization of Data Centers and Server Rooms. secure, cost- and energy-efficient.

NATUS NES / NES-H Draw-out Type Medium Voltage Switchgear Systems. Safe energy distribution that meets the highest industrial requirements

Correct Power Institute AUTOMATION CLOUD RCM (FAULT CURRENT MONITORING) INCLUDING POWER AND ENERGY MONITORING AS AN AUTOMATION CLOUD SOLUTION

Rittal the time has come...

3.0 Nonsystem Based Design Descriptions and ITAAC

May 26, 2011, Strategic Planner Circle Innovation Management at Siemens Building Technologies Division Lucas Schmid, Head of Strategy

DATACENTER COLOCATION. Flexible, Secure and Connected

On Quality Enhancement in Seismic Testing Laboratories based on Efficient IT Infrastructure Deployment

We protect IT. Act instead of react. Professional facility & services for your IT infrastructure. Member of the DATA CENTER GROUP

Fire Protection of Data Centres

COMITÉ EUROPÉEN DES ASSURANCES

FIRE DETECTION AND ALARM SYSTEMS

Fire and Explosion Protection for Stationary Extraction Plants

Technical specifications. Containerized data centre NTR CDC 40f+

Distributed Temperature Monitoring of Energy Transmission and Distribution Systems

Physical and Environment IT Security Standards

Understanding Sage CRM Cloud

Liberty Mutual Insurance RISK ENGINEERING PROCEDURE. REP 07 Incident Planning For external use

Town of Horseheads Code Enforcement Vacant and At- Risk Property Registration

Enable Networks UFB Services Agreement Service Description for Central Office and POI Co-location Service

Original Document 10/16/07 Revised 01/30/09 2 nd Revision rd Revision- 12/18/14

Arc Terminator Active Arc-Resistant Switchgear

How To Make Your House Breathe

Short introduction of the services of Millenia Zrt.

BERKELEY NUCLEONICS USER MANUAL BNC MODEL 960. This manual covers installation and operation procedures for BNC AM members:

ISLE OF MAN FIRE & RESCUE SERVICE FIRE PRECAUTIONS LOGBOOK. Website

Georgia Tech Aerospace Server French building Server Room. Server Room Policy Handbook: Scope, Processes and Procedure

SECURITY VULNERABILITY CHECKLIST FOR ACADEMIC AND SMALL CHEMICAL LABORATORY FACILITIES

06150 PORVOO, FINLAND Pelican eco ED(D), Pelican eco EDE(D), Pelican eco EDW(D), Pelican eco EDX(D)

Fire Safety Requirements for Child Care Centre

Profile e-shelter security. Comprehensive Security Solutions from a Single Source

720r Addendum: Siting the 720r

Shunt lock function 3066 Operator Instructions

Transmitter Actuator 230V wave UP 560. Operation

Fire Risk Assessment Safety Checklist

DATACENTER Vienna 1. Scalable, Safe and Innovative

FIRE RISK ASSESSMENT

TECHNOLOGY RESEARCH AND DEVELOPMENT More Than Alarm Anna Kołodziej-Saramak

Constructing a green Datacenter Datacenter NBG 6

Fire Safety Log Book

Solar Weather Station Model: BAR806 / BAR806A

Builders Risk - Sticks & Stones CAN Hurt You! sponsored by

Colocation. Introduction. Structure of the service. Service Description

TAMARAC FIRE RESCUE INSTRUCTIONS FOR FIRE ALARM PRE-SUBMITTAL CHECKLIST

File:Quality-Management Manual-V2

2 Rittal Micro Data Centre

BUILDING OWNERS - SERVICE RELATED ISSUES FOR FIRE ALARM SYSTEMS

Hazard Identification and Risk Assessment for the Use of Booster Fans in Underground Coal Mines

Risk Management Report

Fire Alarm system Installation Guide

Certificate: / 20 August 2013

CBD-233. Fire Alarm and Detection Systems

North York General Hospital Policy Manual

MNS is Switchgear System Technical Overview

Transcription:

The certification body of TÜV Informationstechnik GmbH hereby awards this certificate to the company E.ON IT GmbH Treskowstraße 5 30457 Hannover, Germany to confirm that its security area Datacenter T7 fulfil all requirements for high protection of the criteria catalogue Trusted Site Infrastructure TSI V2.0 Level 3 (extended) of TÜV Informationstechnik GmbH. The requirements are summarized in the appendix to the certificate. The appendix is part of the certificate and consists of 4 pages. The certificate is valid only in conjunction with the corresponding evaluation report until 2012-11-30. Infrastructure TSI66112.11 12 Certificate-Registration-No.: TUVIT-TSI66112.11 Essen, 2011-01-28 Dr. Christoph Sutter Head of Certification Body TÜV Informationstechnik GmbH Langemarckstr. 20 45141 Essen, Germany www.certuvit.de

Appendix to the certificate TUVIT-TSI66112.11 page 1 of 4 Certification System The certification body of TÜV Informationstechnik GmbH performs its certification on the basis of the following product certification system: German document: Zertifizierungsschema für TÜViT Trusted-Zertifikate der Zertifizierungsstelle TÜV Informationstechnik GmbH, version 1.0 as of 2010-05-18, TÜViT GmbH Evaluation Report German document: Prüfbericht Trusted Site Infrastructure, version 1.0 as of 2010-11-29, Report ID: 66112BD_V1.0.doc, TÜViT GmbH Evalution Requirements German document: Trusted Site Infrastructure TSI Kriterienkatalog, version 2.0 as of 2007-01-15, TÜViT GmbH Evaluation Target The target of evaluation is the security area Datacenter T7 of E.ON IT GmbH. It is detailed in the evaluation report. Evaluation Result The result is Level 3 (extended) for the compartments K.401 and K.404 of security area Datacenter T7. All requirements of the evaluation aspects FIR and ORG of the next highest level are fulfilled. The result is Level 2 (extended) for the compartments K.402 and K.403 of security area Datacenter T7. All requirements of the evaluation aspects ENV, CON, FIR, SEC, ACV and ORG of the next highest level are fulfilled.

Appendix to the certificate TUVIT-TSI66112.11 page 2 of 4 Summary of the Evaluation Requirements The requirements for Trusted Site Infrastructure (TSI), version 2.0: 1 ENV Environment There are no surrounding hazard potentials. The decision on the location must be based on the avoidance of floods, explosions, seismic events, shock waves, danger of collapse or pollutants. 2 CON Construction Walls, doors and windows offer protection against access, fire and debris. It has also been ensured that building sections threatened by water, EM/RF interference fields, and dangerous next-door production processes are avoided. The building is protected against lightning. The security area is located in a separate fire protection area and not directly adjacent to the public. IT and technical equipment are separated. 3 FIR Fire Protection / Alarm / Extinguishing Systems A fire alarm system has been installed in the complete security area and linked with the fire brigade. Adjacent rooms, raised floors, suspended ceilings and air ducts are included in the fire monitoring. Apart from signalling an alarm, damage containment measures such as a gas extinguishing system in the security area are triggered. Furthermore appropriate hand fire extinguishers are available.

Appendix to the certificate TUVIT-TSI66112.11 page 3 of 4 4 SEC Security An access control system including appropriate access rules does exist. The protection against breaking and entering features several levels, and all security sensitive areas are monitored by means of an intrusion detection system. These security systems are connected to the emergency power supply and to a permanently manned control room. 5 POW Power Supply The electrical installations are realized in accordance with the relevant DIN standards and VDE regulations. They are protected against over voltage and realized with adapted separations and with protection of the electric circuits. The IT- and the security systems are connected to an uninterruptible power supply. For the supply alternative possibilities exist. 6 ACV Air Conditioning and Ventilation Air conditioning in redundant design for the IT systems is given. It has been ensured that air temperature, humidity and dust content comply with specified limits. The measured values are remotely controlled. Dampers are installed according to the fire protection concept. 7 ORG Organization Periodical functional tests are carried out for all safeguards. A maintenance schedule defines methods and intervals for the wear parts of the infrastructure components. The communication with the exterior is ensured, even if the PBX fails. The data backup media is stored and protected against fire and access in an area separate from the security area.

Appendix to the certificate TUVIT-TSI66112.11 page 4 of 4 8 DOC Documentation A DIM (Documentation of Infrastructure Measures) or a security concept has been provided. Rules of conduct exist, i.e. covering access control with respect to authorization or key / smart card distribution. Up-to-date plans and documentation are available for the building and all infrastructure components. Furthermore a fire protection concept does exist and has been coordinated with the local fire brigade. Additionally emergency and recovery concepts are provided. L Level Level 1 medium protection requirements (according to the BSI infrastructure requirements of the baseline protection manual) Level 2 extended protection requirements (extended requirements to all above mentioned aspects) Level 3 high protection requirements (complete redundancy of essential components, no single point of failures, climate limits according to EN 1047-2) Level 4 very high protection requirements (advanced access control, no adjacent hazard potentials, with minimal intervention time)