Info:Trust and Safety/Certification and compliance

You do not have permission to edit this page, for the following reason:

The action you have requested is limited to users in one of the groups: Users, Administrators, reviewer, ES_editors, Blog_editors, editor.

You can view and copy the source of this page.

Return to Info:Trust and Safety/Certification and compliance.

Here you will find the most important information on dealing with standards and guidelines at Hallo Welt!

==Certifications and standards==

Hallo Welt! follows and implements standards and supports standardized procedures:

*Our '''cloud data centers''' are ISO/IEC 27001 certified. See [https://www.hetzner.com/unternehmen/zertifizierung Hetzner Online Certification] for more information.

*Hallo Welt! works in a process-oriented manner. We have an internal '''organization manual''' and an internally '''documented process management''', which is based on the ISO 9001 standard.

*Furthermore, Hallo Welt! as a software manufacturer orients itself to the [https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/IT-Grundschutz/it-grundschutz_node.html BSI standard for basic IT protection] and the [https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Empfehlungen-nach-Angriffszielen/Cloud-Computing/Kriterienkatalog-C5/kriterienkatalog-c5_node.html Cloud Computing Compliance Criteria Catalogue (C5)] (see the [[Info:Trust and Safety/Cloud - security and reliability/C5 Internal audit status|current C5 status]]):

**'''Emergency management''': We maintain an emergency manual in which all existential threats to the infrastructure and how to deal with them are recorded.

**'''Risk management''': We maintain a risk register.

**'''Business continuity''': for our disaster recovery measures, see [[Info:Trust and Safety/Cloud - security and reliability|Cloud - Security and Reliability]].

**'''Logging, monitoring, and detection''' of security-related events: We have a register of all incidents.

**'''Audits''': All of these are audited on a regular basis.

*Hallo Welt! has a [https://www.ncsc.gov.uk/cyberessentials/overview Cyber Essentials certificate].

*Hallo Welt! '''plans to start certification according to ISO/IEC 27001 in 2024''' and has implemented all necessary processes according to BSI standards for cloud computing.

==Usability and accessibility==

We develop BlueSpice so that the usability of the software is as simple, consistent and intuitive as possible.

Our software development makes every effort to observe and implement the international standard [https://www.w3.org/TR/WCAG21/ WCAG 2.1] and the [https://www.etsi.org/deliver/etsi_en/301500_301599/301549/03.01.01_60/en_301549v030101p.pdf European standard EN 301 549 Accessibility requirements suitable for public procurement of ICT products and services in Europe, - V3.1.1 (2019-11)].

We no longer provide voluntary accessiblity test information, as we strive to conform to German and European accessibility laws. The software is therefore tested by accredited external BITV-testers. The latest BITV test result is posted on our German helpdesk.

*[[:de:Barrierefreiheit/Status|German BITV test results]]

We are grateful for any comments from our customers and users that enable us to continuously improve accessibility.

==Anti-Bribery and Corruption Policy==

Hallo Welt! has implemented an Anti-Bribery and Corruption Policy. This policy serves to uphold and maintain our zero-tolerance position on bribery and corruption.

It also serves as a source of information and guidance for those who work for Hello World! to recognize and deal with bribery and corruption issues and understand their responsibilities. The policy is published on the BlueSpice page: [https://bluespice.com/legal/ Legal information].

<span><br /></span>

[[de:Info:Trust_and_Safety/Zertifizierung_und_Compliance]]