Projects with industry, public authorities and manufacturers that reached their destination together.
Project reports
Insights into our projects – from consulting and penetration testing to product evaluation.
BSI TR-03185
DUX Healthcare
The first TR-03185 certification in Germany
DUX Healthcare was the first company in Germany to be certified under BSI TR-03185. secuvera carried out the gap analysis and the certification audit of the software development process. The certificate was issued by the BSI.
secuvera supported MB connect line from introducing the ISMS through to preparing for the certification audit. This followed earlier cooperation on the development process under IEC 62443-4-1.
We evaluated WundFit alongside its development: from architecture and cryptography to authentication and secure communication. The BSI granted the certificate to 4L Health's health application without conditions.
For kontina, we examined the iOS and Android apps, backend, security architecture and technical documentation. Technical tests and the report to the BSI formed the basis of the security evaluation.
secuvera evaluated the firewall and VPN appliance genugate 11 for its re-certification under Common Criteria 3.1, Revision 5. The BSI issued the certificate.
We evaluated the distribution PLATFORM WDP MX® in our laboratory. The evaluation covered security functions and a vulnerability analysis. On this basis, the BSI certified the platform under Common Criteria EAL2.
Projektron describes how secuvera contributed to the ISMS with training, concept development, gap analysis and internal audits. The software manufacturer also reports on the transition to ISO/IEC 27001:2022 and certification by TÜV.
Assessing the security measures of a smaller company
In the CyberRisikoCheck, we assessed access security, network and data management and emergency measures, among other things. The company received concrete recommendations for improving its IT security.
Over a good year, we tested more than 20 targets in a time- and risk-based model. Briefings and debriefings for each test cycle helped FH Aachen assess and follow up on the findings.
We supported Red Lion Europe on the way to certification of its development process under IEC 62443-4-1. The published reference describes the cooperation on secure industrial product development.
For the engineering service provider FGH, we supported the introduction of the ISMS through to initial certification. Together with the management, the management system was integrated into the existing business processes.
The first CC-certified video conferencing solution
Our evaluation facility evaluated the cross-platform Zoom software client under Common Criteria EAL2. The BSI issued the certificate in December 2021 – according to the project report, a first for video conferencing solutions.
secuvera advised envelio on building its information security management system (ISMS). The customer report records the successful initial certification to ISO/IEC 27001.
Data communication with a certified information domain
We supported the manufacturer of routers and gateways in implementing the IT-Grundschutz requirements until it was ready for certification. The BSI certified the information domain to ISO 27001 on the basis of IT-Grundschutz.
secuvera supported the information domain in developing its information security further. The report documents the successful re-certification based on IT-Grundschutz in 2016.
Our auditors reviewed the internal processes, the premises and connections to cooperation partners. Certification to ISO/IEC 27001 was carried out by PÜG.
Our evaluation facility, then operating as Tele-Consulting, evaluated GeNUScreen. In 2009, the BSI presented the certificate under Common Criteria EAL4+.