We prepare IT systems to process classified information — security documentation, risk assessment and handling of the accreditation proceedings.
Security accreditation of an IT system is the document that authorises the system to process classified information.
Without accreditation, no system may lawfully process classified information. For systems handling information classified "confidential" and above, accreditation is granted by the Internal Security Agency (ABW) or the Military Counterintelligence Service (SKW), each within its remit. For the "restricted" level, accreditation is granted by the head of the organisational unit.
Accreditation is a prerequisite for organisations delivering projects in the security and defence sector, and for contractors applying for a first-level facility security clearance.
A key principle: security documentation is produced in parallel with designing the system, not after it has been built. Attempting to accredit a finished system that was not designed against these requirements usually ends in a costly rebuild.
The document describing the system, its architecture, purpose, the classification level of the information processed and the protection measures applied — organisational, physical, cryptographic and technical. It is the principal document assessed during accreditation.
The set of procedures defining how the system is to be operated securely: managing privileges, backups, incident response, maintenance, disposal of media, and the duties of the system administrator and the security inspector.
We establish what information will be processed and at what classification level, how the system is built, where the security boundaries run and which authority grants accreditation.
Identifying threats and vulnerabilities, assessing risk and selecting appropriate security measures — with the rationale that goes into the accreditation documentation.
Complete system security documentation, consistent with the actual architecture and operating model — not a template detached from the reality of your organisation.
Supervising the implementation of physical security, access control, cryptographic solutions and event logging mechanisms within the system.
Designating and training the system administrator and the IT security inspector, including preparation for their vetting procedures.
Filing the documentation, responding to comments and requests for clarification, and preparing the organisation for the system security audit conducted by ABW or SKW.
Updating documentation when the system changes, periodic compliance reviews and support with re-accreditation once the term expires.
For systems processing classified information at "confidential" level and above, accreditation is granted by ABW or SKW, each within its remit. For the "restricted" level, accreditation is granted by the head of the organisational unit, who approves the system security documentation.
No. Accreditation is granted for a fixed term. In addition, material changes to the system — modifying the architecture, changing the classification level of the information processed, adding new components — require the documentation to be updated and, in some cases, fresh accreditation proceedings.
It can, but this usually entails rebuilding. Systems built without regard to classified information requirements rarely meet them as they stand — most often the network architecture, access control model and cryptographic solutions all have to change. That is why work on the documentation should begin in parallel with designing the system.
It depends on the level of clearance. A first-level clearance covers the capability to process classified information in IT systems and therefore requires an accredited system. At second and third level that requirement does not arise.
The best time to talk is at the design stage. We will review your assumptions and identify what must be accounted for so that accreditation runs smoothly.
Book a consultation