This document is under active development and has not been finalized.
Skip to content

Contractual Security Requirements

Mandatory Clauses

Contracts with service providers that have access to BAUER GROUP systems or data must contain the following minimum requirements:

Information Security

ClauseDescription
Security standardsAdherence to appropriate technical and organizational measures (state of the art)
EncryptionEncryption of sensitive data at rest and in transit
Access controlPersonalized accounts, least-privilege principle, MFA for administrative access
Patch managementTimely remediation of known vulnerabilities

Incident Management

ClauseDescription
Reporting obligationImmediate notification of security incidents (max. 24h)
Cooperation obligationSupport during analysis and remediation
Disclosure obligationComplete information on scope and impact

§30(2) NO. 4 BSIG – SUPPLY CHAIN SECURITY

NIS2 explicitly requires that security measures in the supply chain are addressed, including security-related aspects concerning the relationship between the entity and its direct suppliers or service providers.

Audit and Inspection Rights

ClauseDescription
Audit rightRight to audit security measures (in-house or through third parties)
Certificate submissionObligation to present current security certifications
Compliance evidenceAnnual evidence of adherence to contractual security requirements

Data Handling

ClauseDescription
Data storageStorage location and legal jurisdiction documented
Data deletionSecure deletion after contract termination, with evidence
Data returnReturn of all data in machine-readable format
SubcontractorsApproval required for subcontractors, same security requirements apply

Exit Strategy

ClauseDescription
Transition periodMinimum 90 days of migration support
Data exportComplete data export in open formats
Knowledge transferDocumentation of all relevant configurations and processes
Deletion confirmationWritten confirmation of complete data deletion

Contract Management Schedule

ActivityIntervalResponsible
Contract reviewUpon conclusion / renewalCISO + Procurement
SLA monitoringOngoingIT Operations
Security clause reviewAnnually for critical service providersCISO

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT