Snapshot 72409
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Home Trust Center Security Security at AEB Availability, confidentiality, integrity - these are AEB's top security objectives. This goes beyond the technical nuts and bolts of our IT solutions. It also covers the availability of our contact persons, the confidentiality with which we handle business partner data, and the integrity we ensure through clear data processing workflows. Certified security Login & authentication Secure products Security in HQ Emergency preparedness All documents Contact Certified security The security and protection of your data are part of our AEB DNA and have always been an integral part of our solutions. That's why AEB has had ISO 27001 certification for data center (cloud) operations and product development for over ten years and is also certified as an „Authorized Economic Operator - Security“ (AEO-S). AEB is focused not only on operational and risk management aspects, of course. We also prioritize the modern security mechanisms necessary to protect data. This includes next-generation firewalls, intrusion detection and prevention systems, automatic alerting, and much more - all running with multiple levels of redundancy. AEB performs penetration tests several times a year and also regularly scans all logins and applications in the AEB Cloud, so we're able to proactively identify potential vulnerabilities and attack scenarios. Certified as an „Authorized Economic Operator - Security“ (AEO-S) ISO 27001 certification Authorized Economic Operator - Security“ (AEO-S) certification. View all certificates Role-based login & authentication AEB deploys a central user repository and role-based security model to control the physical and electronic access of customers and employees to resources and solutions. This ensures that users can access only the applications and environments for which they are actually authorized. Users are consolidated in role groups, with access granted strictly to role objects, not individual user objects. Users with special administrative rights or privileges are also consolidated in appropriate role groups, where they are subject to the groups' processes and approvals. Particularly sensitive privileges (such as access to firewalls or admin portals) require the user to have a special personalized administrator account. „Normal“ user accounts are not granted these rights and cannot be assigned to the corresponding roles. Excerpt from the AEB Security Concept: Details on access and access control Last update: 31.10.2024 This document provides an overview of access to areas in the AEB building, as well as access to and use of AEB applications. This document provides an overview of access to areas in the AEB building, as well as access to and use of AEB applications. Secure products Quality assurance at AEB means that before any new code goes live, our test managers perform manual testing for strict compliance with data protection and security requirements and our own in-house specifications. We also run continuous automated testing during the development phase to protect our software against unintended side effects. Access restrictions and role concepts ensure the security of our software products during operation. Excerpt from the AEB Security Concept: Details on the handling of data in general Last update: 08.12.2023 The security concept provides information about the technical and organizational measures taken to ensure appropriate security of data and services. Here you will also find AEB's statements on the controls of ISO 27001 (Annex A / Statement of Applicability (SOA)). The security concept provides information about the technical and organizational measures taken to ensure appropriate security of data and services. Here you will also find AEB's statements on the controls of ISO 27001 (Annex A / Statement of Applicability (SOA)). Security in AEB headquarters Access to AEB offices and infrastructure is generally restricted to AEB employees. All comings and goings are logged. Guests must be announced in advance by the AEB employee who invites them and then register upon arrival at the reception desk. They must remain on the ground floor and visibly display a guest pass so that everyone can recognize them as guests. Only trained AEB employees have physical access to the data centers, with two-factor authentication and video monitoring providing extra layers of security. All employees are encouraged to approach or report unknown or suspicious visitors. After hours, this task is handled by security personnel, who check all rooms and specified points. This ensures that there are no unauthorized people in the building or on the premises. Emergency preparedness: AEB Business Continuity Management Significance When logistics and customs processes come to a standstill, this can have massive consequences for many companies. That's why it's essential that AEB Cloud software, services, and support remain available without any hiccups. AEB has implemented a comprehensive business continuity management system to ensure that this is the case - even when the unexpected occurs. „For us, business continuity management is an essential part of risk management,“ explains Martin Setzler, member of the Board of Directors and responsible for IT at AEB. „That's why we also see it as closely interlinked with our ISO 27001-certified information security management system, in which business continuity is defined as a separate area of regulation.“ Objectives Emergency prevention The structure of AEB's business continuity management (BCM) is described in the AEB Business Continuity Guideline, based on the BCM Standard 100-4 issued by Germany's Federal Office for Information Security (BSI) and the ISO 22301 and ISO 22313 standards. BCM is divided into two core areas of action: emergency prevention and emergency management. The preventive measures are defined in an emergency preparedness concept aimed at reducing both the probability of occurrence and any possible damage. The key question: Which precautions and actions must be taken to immediately restore system availability in the highly improbable event of a partial or complete system failure? Business Continuity Policy Last update: 16.07.2025 The AEB Business Continuity Policy describes the specifications and the scope for implementing continuous operation at the top level. The AEB Business Continuity Policy describes the specifications and the scope for implementing continuous operation at the top level. Emergency management The emergency preparedness concept comprises tools that allow AEB to correctly classify and evaluate its processes by relevance so that emergency measures can be executed smoothly. This includes regular drills. Should an emergency ever actually occur and AEB or its solutions ever suffer a disruption, an Emergency Guide provides a clear definition of processes and responsibilities. The Emergency Guide contains predefined contingency plans for various scenarios to ensure quick, efficient decision-making processes, even during a crisis. These measures help reassure customers that AEB will respond to even a worst-case scenario in an ordered and professional manner to get AEB services up and running again quickly. All documents Basic information Security Concept Last update: 27.01.2026 The security concept provides information about the technical and organizational measures taken to ensure appropriate security of data and services. Here you will also find AEB's statements on the controls of ISO 27001 (Annex A / Statement of Applicability (SOA)). The security concept provides information about the technical and organizational measures taken to ensure appropriate security of data and services. Here you will also find AEB's statements on the controls of ISO 27001 (Annex A / Statement of Applicability (SOA)). Integrated Management System Guideline Last update: 16.07.2025 This guideline describes guiding principles as well as organizational principles of the management systems for quality and information security established in the company. This guideline describes guiding principles as well as organizational principles of the management systems for quality and information security established in the company. Business Continuity Policy Last update: 16.07.2025 The AEB Business Continuity Policy describes the specifications and the scope for implementing continuous operation at the top level. The AEB Business Continuity Policy describes the specifications and the scope for implementing continuous operation at the top level. Details of the security concept Excerpt from the AEB Security Concept: Details on access and access control Last update: 31.10.2024 This document provides an overview of access to areas in the AEB building, as well as access to and use of AEB applications. This document provides an overview of access to areas in the AEB building, as well as access to and use of AEB applications. Excerpt from the AEB Security Concept: Details on AEB Cloud Services API Last update: 01.04.2021 This document provides an overview of the interfaces (APIs) of the AEB Cloud Services and their security concept. This document provides an overview of the interfaces (APIs) of the AEB Cloud Services and their security concept. Excerpt from the AEB Security Concept: Details on cryptography Last update: 23.05.2025 This document provides an overview of the cryptographic methods used in AEB. This document provides an overview of the cryptographic methods used in AEB. Excerpt from the AEB Security Concept: Details on the backup strategy Last update: 01.07.2025 This document describes data backup measures AEB takes to enable data recovery. This document describes data backup measures AEB takes to enable data recovery. Excerpt from the AEB Security Concept: Details on the handling of data in general Last update: 08.12.2023 The security concept provides information about the technical and organizational measures taken to ensure appropriate security of data and services. Here you will also find AEB's statements on the controls of ISO 27001 (Annex A / Statement of Applicability (SOA)). The security concept provides information about the technical and organizational measures taken to ensure appropriate security of data and services. Here you will also find AEB's statements on the controls of ISO 27001 (Annex A / Statement of Applicability (SOA)). Excerpt from the AEB Security Concept: Security event and incident management Last update: 01.11.2024 This document provides an overview of security event management and security incident management. This document provides an overview of security event management and security incident management. Excerpt from the AEB Security Concept: Security vulnerability management Last update: 01.11.2024 This document provides an overview of the security concept vulnerability management. This document provides an overview of the security concept vulnerability management. Certificates: Security Certificate: ISO/IEC 27001:2022 Last update: 13.10.2024 The certificate attests that AEB has implemented and maintains an information security management system in accordance with ISO/IEC 27001:2022. The certificate attests that AEB has implemented and maintains an information security management system in accordance with ISO/IEC 27001:2022. Report IDW PS 951 Last update: 24.04.2025 Since 2019: The standard according to IDW PS 951 has been successfully audited by HKKG GmbH Wirtschaftsprüfungsgesellschaft. Since 2019: The standard according to IDW PS 951 has been successfully audited by HKKG GmbH Wirtschaftsprüfungsgesellschaft. Report ISAE 3402 Last update: 24.04.2025 Since 2019: The standard according to ISAE 3402 has been successfully audited by HKKG GmbH Wirtschaftsprüfungsgesellschaft. Since 2019: The standard according to ISAE 3402 has been successfully audited by HKKG GmbH Wirtschaftsprüfungsgesellschaft. Zertifikat: AEO-S Last update: 05.03.2010 Die AEB erhält das AEO-Zertifikat "Sicherheit" (AEO S) auf Grundlage der Sicherheitsänderungen des Zollkodex der Gemeinschaft (Verordnung (EG) 648/2005). Das Zertifikat wurde 2018 erneut überprüft. Die AEB erhält das AEO-Zertifikat "Sicherheit" (AEO S) auf Grundlage der Sicherheitsänderungen des Zollkodex der Gemeinschaft (Verordnung (EG) 648/2005). Das Zertifikat wurde 2018 erneut überprüft. Our IT Security Manager Maik Bolbeth, IT Security Manager Maik Bolbeth As an IT Security Manager, I ensure that people can rely on the security of their data and systems. With more than 12 years of experience in security-related fields within government agencies and in the automotive industry – including roles as a CISO and auditor for ISO 27001 and TISAX – I am familiar with security requirements from both the implementing and auditing perspective. What keeps me motivated every single day: Security should not be a hindrance, but rather provide guidance and serve as a foundation for reliable and trustworthy collaboration. I am convinced that strong security develops when it is understandable, taken into account early on, and empowers people instead of blocking them. That's why I see my role as that of a mediator and facilitator. With clear guardrails, appropriate tools, and open communication. Questions about IT security at AEB? Contact the IT Security Manager: srvcbcm