This document is under active development and has not been finalized.
Skip to content

Secure Communication

LEGAL BASIS

§30(2) No. 10 BSIG -- Secured voice, video and text communication, and secured emergency communication systems where appropriate within the entity

Communication Channels

ChannelEncryptionAuthenticationUse
EmailTLS in transit, optional S/MIMESPF/DKIM/DMARCStandard business communication
Encrypted messengerEnd-to-end (E2E)Account-based + MFASensitive internal communication, incident response
Video conferencingTLS, transport encryptionMeeting codes + waiting roomMeetings, customer communication
VPNIPsec / WireGuardCertificate + MFARemote access to internal systems
TelephoneStandard network (unencrypted)Caller IDNot for confidential information

Email Security in Detail

DNS-Based Authentication

MechanismConfigurationPurpose
SPFTXT record with authorized mail serversPrevents sender spoofing
DKIMSigning of outgoing emails (≥ 2048 bit)Integrity verification
DMARCPolicy: reject, reporting to ISOEnforces SPF+DKIM, reports violations
MTA-STSEnforced TLS for incoming emailsPrevents downgrade attacks
DANE/TLSADNS-based certificate bindingAdditional TLS verification

Handling Classified Data via Email

ClassificationPermitted via email?Additional measures
PublicYesNone
InternalYesStandard TLS
ConfidentialOnly if necessaryEncrypted attachment or secure exchange platform
Strictly confidentialNoOnly via E2E-encrypted channels

Emergency Communication

Fallback Channels

In the event that primary communication channels are compromised or unavailable:

PriorityChannelAvailability
1Mobile phone (personal)24/7
2Alternative messenger (predefined)24/7
3Landline telephoneBusiness hours

Preparation Measures

  • Current contact lists of key personnel available offline (printed or on a separate device)
  • Predefined code words for identity verification during telephone communication
  • Annual reachability exercise with all crisis team members
  • Backup communication plan is part of the crisis management documentation

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT