Trust Center - Lanes & Planes
Lanes & Planes GmbH
Lanes & Planes ist ein Anbieter einer SaaS-Travel-Management-Lösung für Geschäftsreisen (SaaS-Tool). Die effiziente All-in-one-Lösung bildet den gesamten Geschäftsreiseprozess digital mit einem Ende-zu-Ende-Ansatz ab. Sie umfasst alle Prozessschritte einer Reise, von der Buchung mit Hilfe einer Webanwendung bzw. von mobilen Apps über den Support der Reisenden durch erfahrene Reiseverkehrskaufleute bis hin zum Belegmanagement und der Abrechnung gegenüber den Geschäftskunden.
Die SaaS-Lösung und die Apps werden durch ein eigenes Entwicklungsteam entwickelt und auf firmeneigenen Systemen im Rahmen eines Co-Location-Ansatzes in externen Rechenzentren in Deutschland betrieben.
Controls
Updated 13 minutes ago
Infrastructure security
| Control | Status |
|---|---|
| Information security for use of cloud services Processes for acquisition, use, management and exit from cloud services shall be established in accordance with the organization’s information security requirements. |
|
| Information transfer Information transfer rules, procedures, or agreements shall be in place for all types of transfer facilities within the organization and between the organization and other parties. |
|
| Authentication information Allocation and management of authentication information shall be controlled by a management process, including advising personnel on the appropriate handling of authentication information. |
|
| Privileged access rights The allocation and use of privileged access rights shall be restricted and managed. |
|
| Information access restriction Access to information and other associated assets shall be restricted in accordance with the established topic-specific policy on access control. |
|
| Secure authentication Secure authentication technologies and procedures shall be implemented based on information access restrictions and the topic-specific policy on access control. |
|
| Use of privileged utility programs The use of utility programs that can be capable of overriding system and application controls shall be restricted and tightly controlled. |
|
| Logging Logs that record activities, exceptions, faults and other relevant events shall be produced, stored, protected and analysed. |
|
| Monitoring activities Networks, systems and applications shall be monitored for anomalous behaviour and appropriate actions taken to evaluate potential information security incidents. |
|
| Remote working Security measures shall be implemented when personnel are working remotely to protect information accessed, processed or stored outside the organization’s premises. |
Organizational security
| Control | Status |
|---|---|
| Determining the scope of the information security management system The organization shall determine the boundaries and applicability of the information security management system to establish its scope. When determining this scope, the organization shall consider: a) the external and internal issues referred to in 4.1; b) the requirements referred to in 4.2; c) interfaces and dependencies between activities performed by the organization, and those that are performed by other organizations. The scope shall be available as documented information. |
|
| Return of assets Personnel and other interested parties as appropriate shall return all the organization’s assets in their possession upon change or termination of their employment, contract or agreement. |
|
| Intellectual property rights The organization shall implement appropriate procedures to protect intellectual property rights. |
|
| Security of assets off-premises Off-site assets shall be protected. |
|
| Storage media Storage media shall be managed through their life cycle of acquisition, use, transportation and disposal in accordance with the organization’s classification scheme and handling requirements. |
|
| Secure disposal or re-use of equipment Items of equipment containing storage media shall be verified to ensure that any sensitive data and licensed software has been removed or securely overwritten prior to disposal or re-use. |
|
| User endpoint devices Information stored on, processed by or accessible via user endpoint devices shall be protected. |
|
| Protection against malware Protection against malware shall be implemented and supported by appropriate user awareness. |
|
| Competence The organization shall: a) determine the necessary competence of person(s) doing work under its control that affects its information security performance; b) ensure that these persons are competent on the basis of appropriate education, training, or experience; c) where applicable, take actions to acquire the necessary competence, and evaluate the effectiveness of the actions taken; and d) retain appropriate documented information as evidence of competence. |
|
| Awareness Persons doing work under the organization’s control shall be aware of: a) the information security policy; b) their contribution to the effectiveness of the information security management system, including the benefits of improved information security performance; and c) the implications of not conforming with the information security management system requirements. |
Product security
| Control | Status |
|---|---|
| Secure development life cycle Rules for the secure development of software and systems shall be established and applied. |
|
| Secure coding Secure coding principles shall be applied to software development. |
|
| Security testing in development and acceptance Security testing processes shall be defined and implemented in the development life cycle. |
|
| Separation of development, test and production environments Development, testing and production environments shall be separated and secured. |
|
| Test information Test information shall be appropriately selected, protected and managed. |
Internal security procedures
| Control | Status |
|---|---|
| ICT readiness for business continuity ICT readiness shall be planned, implemented, maintained and tested based on business continuity objectives and ICT continuity requirements. |
|
| Information backup Backup copies of information, software and systems shall be maintained and regularly tested in accordance with the agreed topic-specific policy on backup. |
|
| Redundancy of information processing facilities Information processing facilities shall be implemented with redundancy sufficient to meet availability requirements. |
|
| Capacity management The use of resources shall be monitored and adjusted in line with current and expected capacity requirements. |
|
| Configuration management Configurations, including security configurations, of hardware, software, services and networks shall be established, documented, implemented, monitored and reviewed. |
|
| Planning of Changes When the organization determines the need for changes to the information security management system, the changes shall be carried out in a planned manner. |
|
| Installation of software on operational systems Procedures and measures shall be implemented to securely manage software installation on operational systems. |
|
| Internal Audit - General The organization shall conduct internal audits at planned intervals to provide information on whether the information security management system: a) conforms to 1. the organization’s own requirements for its information security management system; 2. the requirements of this document; b) is effectively implemented and maintained. |
|
| Internal Audit Program The organization shall plan, establish, implement and maintain an audit programme(s), including the frequency, methods, responsibilities, planning requirements and reporting. When establishing the internal audit programme(s), the organization shall consider the importance of the processes concerned and the results of previous audits. The organization shall: a) define the audit criteria and scope for each audit; b) select auditors and conduct audits that ensure objectivity and the impartiality of the audit process; c) ensure that the results of the audits are reported to relevant management; Documented information shall be available as evidence of the implementation of the audit programme(s) and the audit results. |
|
| Nonconformity and corrective action When a Nonconformity occurs, the organization shall: a) React to the nonconformity, and as applicable: 1. take action to control and correct it; 2. deal with the consequences b) evaluate the need for action to eliminate the causes of nonconformity, in order that it does not recur or occur elsewhere, by; 1. reviewing the nonconformity; 2. determining the causes of the nonconformity; and 3. determining if similar nonconformities exist, or could potentially occur c) implement any action needed; d) review the effectiveness of any corrective action taken; and e) make changes to the information security management system, if necessary. Corrective actions shall be appropriate to the effects of the nonconformities encountered. Documented information shall be available as evidence of: f) The nature of the nonconformities and any subsequent actions taken, g) the results of any corrective action. |
Data and privacy
| Control | Status |
|---|---|
| Acceptable use of information and other associated assets Rules for the acceptable use and procedures for handling information and other associated assets shall be identified, documented and implemented. |
|
| Classification of information Information shall be classified according to the information security needs of the organization based on confidentiality, integrity, availability and relevant interested party requirements. |
|
| Labelling of information An appropriate set of procedures for information labelling shall be developed and implemented in accordance with the information classification scheme adopted by the organization. |
|
| Protection of records Records shall be protected from loss, destruction, falsification, unauthorized access and unauthorized release. |
|
| Information deletion Information stored in information systems, devices or in any other storage media shall be deleted when no longer required. |
|
| Data masking Data masking shall be used in accordance with the organization’s topic-specific policy on access control and other related topic-specific policies, and business requirements, taking applicable legislation into consideration. |
|
| Data leakage prevention Data leakage prevention measures shall be applied to systems, networks and any other devices that process, store or transmit sensitive information. |
|
| Privacy and protection of PII The organization shall identify and meet the requirements regarding the preservation of privacy and protection of PII according to applicable laws and regulations and contractual requirements. |