Technical and organizational measures (TOM)

As of August 18, 2026

These technical and organizational measures apply to Netstream AG and Netstream Cloud AG.

Subject of the document

This document summarizes the technical and organizational measures required under Article 8(1) of the DSG. It describes the measures that data controllers use to protect personal data.

The measures are integrated into a certified information security management system (ISMS) in accordance with ISO/IEC 27001:2022 and are aligned with the security objectives of confidentiality, integrity, availability, and resilience.

1. confidentiality

1.1 Access control

Measures that prevent unauthorized persons from gaining access to data processing facilities.

  • Automatic access control system with an electronic locking system and individual authorization management
  • Biometric Access Controls in Data Centers
  • Video Surveillance in Security-Sensitive Areas
  • Doorbell system with camera in office space
  • Restrictive access policies and security guards
  • Key management system with a documented key log
  • Visitor escort exclusively by authorized employees
  • Alarm systems at all relevant entrances
  • Contractual safeguards with service providers, including confidentiality agreements
  • Careful selection of cleaning staff and contractual safeguards
  • Work-from-Home Policy with Defined Security Requirements

1.2 Access control

Measures that prevent data processing systems from being used by unauthorized persons.

  • Personal authentication using a username and password in accordance with a recognized industry standard
  • Centralized password policy with complexity requirements and regular password changes
  • Two-Factor Authentication (2FA) for all supported systems
  • Centralized password manager for secure management of all login credentials
  • Endpoint Detection and Response (EDR) on all managed endpoints
  • Use of Firewalls and Network Segmentation
  • Encrypted Wi-Fi using the latest standard with a separate guest network
  • VPN Requirement for All Remote Access
  • Full Encryption of Mobile Storage Devices and Laptops
  • Remote wipe capability for mobile devices in case of loss or theft
  • Automatic Desktop Lock After Inactivity
  • Automatic Account Lockout After Failed Login Attempts
  • Deactivation of Inactive Accounts
  • Separate accounts for administrative tasks

1.3 Access control

Measures that ensure that only data for which authorization has been granted can be accessed.

  • Role-based access control with a documented authorization policy
  • Minimal Assignment of Permissions Based on the "Need-to-Use" Principle
  • Logging of access to applications, particularly when data is entered, modified, or deleted
  • Regular Review of Access Permissions
  • Professional Destruction of Data Storage Media and Files
  • Physical Erasure of Data Storage Media Before Reuse
  • Secure Storage of Data Storage Media in Accordance with the Clean Desk/Clear Desk Policy
  • Controlled Revocation of Access Rights Upon Resignation or Change of Role

1.4 Separation control

Measures that ensure that data collected for different purposes are processed separately.

  • Strict separation of production and test environments
  • Logical client separation in all relevant applications
  • Network Segmentation with Defined Security Zones
  • A granular authorization model that defines database permissions

1.5 Pseudonymization and Data Minimization

  • Principle of data minimization in all data collection
  • Anonymization/pseudonymization of personal data upon disclosure or after the retention period has expired
  • Data masking for test data; exceptions are documented in Exception Management

2. integrity

2.1 Transfer control

Measures that ensure that data cannot be read, copied, altered, or deleted without authorization during transmission or storage.

  • Encrypted data transmission in accordance with current industry standards
  • Encryption of data at rest in accordance with recognized cryptographic standards
  • VPN tunnels for remote access to internal resources
  • Data is provided exclusively via encrypted connections
  • Do not send sensitive data via email; use secure file-sharing platforms
  • Records of Data Recipients and Retention Periods
  • Supplier Management in Accordance with ISO 27001, Including Regular Audits
  • Automated Monitoring of Cryptographic Configurations

2.2 Input Validation

Measures that ensure it is possible to verify retrospectively whether data has been entered, modified, or deleted, and by whom.

  • Logging the Entry, Modification, and Deletion of Data
  • Traceability Through Unique Usernames
  • Centralized logging infrastructure with tamper-proof storage
  • Defined Minimum Retention Periods for Logs
  • Access to logs is restricted to authorized individuals only
  • Regular review and analysis of the logs

3. availability and resilience

3.1 Availability control

Measures that ensure that personal data is protected against accidental destruction or loss.

  • Data centers built in accordance with the Tier IV standard, with full redundancy
  • Fire and smoke detection systems and automatic fire suppression systems
  • Climate Monitoring in Server Rooms
  • Uninterruptible Power Supply (UPS) with Emergency Power System
  • Redundant power supply lines
  • Redundant architecture for all business-critical services
  • Monitoring and Planning System Capacities to Prevent Bottlenecks
  • Regular automated backups with encrypted storage
  • Storage of data backups in a secure, off-site location
  • A documented backup and Recovery plan with regular tests
  • Automated monitoring systems with early warning and escalation processes
  • On-call system for a prompt response to system malfunctions
  • A documented emergency plan with regular drills
  • Incident Management Process with Defined Escalation Levels

4. Procedures for Regular Review, Assessment, and Evaluation

4.1 Information Security and Data Protection

  • ISMS Certified to ISO/IEC 27001:2022
  • Chief Information Security Officer (CISO)
  • External Data Protection Consultant
  • All employees are required to maintain data confidentiality
  • Regular Training on Data Protection and Information Security
  • Regular awareness campaigns, including simulated phishing tests
  • Maintaining a record of processing activities (Art. 12 DSG)
  • Systematic risk management with documented risk analysis and mitigation
  • Classification of all information according to a defined scheme
  • Guidelines for the Safe Use of AI Systems
  • Regular internal and external audits
  • Annual management review, including goal setting and KPI measurement
  • Compliance with the information requirements under Art. 19 et seq. of the DSG

4.2 Incident Response Management

  • Documented incident management with defined escalation levels
  • Process for Reporting Data Breaches to the FDPIC (Art. 24(1) DSG) and to Data Subjects (Art. 24(4) DSG)
  • Involvement of the Data Protection Officer in Data Breaches
  • Endpoint Detection and Response (EDR) on Managed Endpoints
  • Firewalls with Network Segmentation
  • Regular updates to all systems and applications
  • Vulnerability Management with Systematic Identification, Assessment, and Remediation
  • Preservation of evidence in a tamper-proof environment
  • Lessons Learned from Security Incidents

4.3 Privacy-friendly default settings

  • Employee Training on Privacy by Design and Privacy by Default
  • Data collection is limited to the minimum necessary for the purpose
  • Requirements for Secure Software Development and Code Review
  • Data Masking and Anonymization of Test Data

4.4 Order control

  • Written Instructions to Contractors Through Order Processing Agreements
  • Careful selection of contractors based on documented evaluations
  • Ongoing monitoring and regular auditing of suppliers
  • Non-Disclosure Agreements for Suppliers with Access to Confidential Information
  • Ensuring the destruction of data upon completion of the contract
  • Contractors' Obligation to Maintain Data Confidentiality
Netstream White

Do you have any questions about our services or need further information? Feel free to contact us using the form or directly at hello(at)netstream.ch.

Alternatively, you can also use our LiveChat at the bottom right or call us at 058 058 40 00.

Netstream White

Learn more.

Learn more about your options with Netstream Cloud. Leave your contact details and we will get back to you.

Or call us at:
058 058 40 00