Technical and Organizational Separation of the TERRA Cloud Environment

Aus TERRA CLOUD WIKI
Version vom 20. Juli 2026, 08:06 Uhr von Christian Toedtmann (Diskussion | Beiträge) (Die Seite wurde neu angelegt: „TERRA Cloud implements appropriate technical and organizational measures to partition the cloud environment.<br> The security mechanisms used are documented and regularly reviewed to ensure effective separation of the various system areas. <br> The cloud service infrastructure is separated from the cloud service provider’s internal information systems through appropriate technical security measures.<br> These include, in particular, network segmentation…“)
(Unterschied) ← Nächstältere Version | Aktuelle Version (Unterschied) | Nächstjüngere Version → (Unterschied)

Technical and Organizational Partitioning

TERRA Cloud implements appropriate technical and organizational measures to partition the cloud environment.
The security mechanisms used are documented and regularly reviewed to ensure effective separation of the various system areas.
The cloud service infrastructure is separated from the cloud service provider’s internal information systems through appropriate technical security measures.
These include, in particular, network segmentation, VLAN structures, separate IP ranges, and individually configured firewall rules.

To securely separate the various cloud service customers, isolated network areas with their own security zones are set up.
Depending on the service provided, customer-specific network segments, dedicated IP address ranges, and corresponding firewall rules are used to prevent unauthorized communication between customer environments as well as between customer and internal systems.

Administrative access is restricted to authorized individuals and defined systems.
Permissions are granted according to a role-based authorization model and the need-to-know principle, ensuring that employees have access only to the resources necessary for their tasks.

Separation of Customer Systems and Clients

The TERRA Cloud ensures the secure separation of data and resources belonging to different cloud service customers.
Technical and organizational controls prevent customers from gaining unauthorized access to the data, systems, or resources of other customers.

Client isolation is implemented in particular through network isolation, access controls, firewall rules, and separate security zones.
The effectiveness of the measures in place is reviewed regularly.

Separation of Data Storage and Access Components

Systems for storing customer data are operated separately from components used to manage and control access.
This ensures that a security incident within a data storage component does not automatically compromise the access control mechanisms.
The protective measures implemented include, in particular:

  • Separate management of storage and access components
  • Technical access restrictions
  • Network and system isolation
  • Monitoring of security-related activities
  • Regular review of security configurations

Protection Against Unauthorized Access

TERRA Cloud employs procedures to detect, assess, and address unauthorized access.
Security-related events are monitored, analyzed, and handled in accordance with defined processes.

These include, in particular:

  • Logging relevant accesses and administrative activities
  • Monitoring security-critical processes
  • Assessing potential security breaches
  • Implementing appropriate measures to mitigate and resolve security risks

Employee Access

Access by employees of the cloud service provider is granted exclusively on the basis of defined permissions and in accordance with the need-to-know principle.

Access to customer systems or customer data is granted only with the customer’s prior approval or as part of an agreed-upon support or maintenance procedure.
When necessary, administrative access is performed in a supervised and traceable manner, for example, using supported remote maintenance tools such as TeamViewer.

All relevant access is monitored and documented in accordance with applicable processes.

Notifying Customers in the Event of Security Incidents

If unencrypted customer data is accessed without the customer’s prior consent and there are no legal or contractual restrictions regarding notification, the affected customer will be informed promptly.

Communication takes place via defined reporting channels and includes, where available, information on the nature, scope, and timing of the access, as well as any potential impacts and countermeasures taken.

Through these measures, TERRA Cloud ensures a secure separation of customer environments, controlled access management, and transparent handling of security-related incidents.