In Bearbeitung Fiskal Cloud Portal

beeblebrox_tm

Aktives Mitglied
31. Oktober 2019
20
4
Hallo,

ich nutze die Fiskal Cloud jetzt seit über einem Jahr. Aufgrund des aktuellen Hinweises möchte ich gern weiterführende Informationen zum Umgebungsschutz finden. Es wird dort auf das Documentation Portal der Deutschen Fiskal verwiesen (https://documentation.fiskal.cloud/...ntalprotection-concept-umgebungsschutzkonzept).
Allerdings werden dafür Zugangsdaten verlangt und obwohl ich Kunde bin sind diese mir nicht bekannt.

Wie kann ich an diese Informationen gelangen oder ein entsprechendes Konto eröffnen? Es ist kein Registrierungslink zu finden.
 

lweber

Lars Weber
Mitarbeiter
13. November 2013
733
162
Hallo @beeblebrox_tm ,

ich habe dir die Passage was den Umgebungsschutz betrifft einmal rauskopiert, was die DF dazu schreibt.


Environmental Protection Concept (Umgebungsschutzkonzept)#


DF Deutsche Fiskal GmbH uses the Cloud TSE of D-Trust GmbH in its fiscalisation solution "Fiskal Cloud".

D-Trust GmbH has successfully certified its product D-Trust TSE-Web at the Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik - BSI). The product was developed by Bundesdruckerei / D-TRUST GmbH and is operated in their data centre. It consists of the certified D-TRUST web service TSE-CSP and the certified D-TRUST web service TSE-SMAERS and must be operated on or near the POS system.

The D-Trust TSE-Web Version 3.0 has the following BSI certificates (as of 12/2021):

Certificate according to Technical Guideline TR-03153 No. BSI-K-TR-0474-2021 dated 10.12.2021, valid until 09.12.2029 (functional TSS certification and TSS operating licence).

Certificate according to Technical Guideline TR-03145 No. BSI-K-TR-0382-2020 of 03.04.2020, permanently valid with annual auditing (Public Key Infrastructure (PKI)).

Certificate according to Common Criteria No. BSI-DSZ-CC-1137-V3-2021 of 15.12.2021, valid until 14.12.2029 (security certificate of the SMAERS component).

Certificate according to Common Criteria No. BSI-DSZ-CC-1139-V3-2021 of 10.11.2021, valid until 09.11.2026 (security opinion of the CSP component).

The conditions of the SMAERS certification require the full implementation of an environmental protection concept based on DTRUST SMAERS Umgebungsschutz V6.9 to ensure the protection of the certified SMAERS component.

DF Deutsche Fiskal GmbH points out, that it is imperative that the environmental protection concept is adhered to and implemented. Otherwise, the technical safety device does not fulfil the requirements of the certification and the taxable person does not use a legally compliant technical safety device.

The taxable person or integrator must take care to implement the requirements for environmental protection and document them. DF Deutsche Fiskal GmbH provides an accompanying catalogue of measures for implementation Checkliste Umgebungsschutz V6.9 as well as an annex Anlage Cloud-TSS zur Verfahrensdokumentation to the customer's procedural documentation. The annex shall be attached to the procedural documentation as is, i.e. it is not necessary to alter this document. It is, however, mandatory to fill out the catalogue before attaching it to the procedural documentation. In order to complete the documentation the customer shall attach the current extraction of the ERS/TSS Structure Export out of the Fiskal Cloud Portal as json, csv or pdf (recommended).

For final protection, DF Deutsche Fiskal GmbH also recommends filing an application in accordance with §148 AO for this case. DF Deutsche Fiskal GmbH provides customized support in the preparation of the application. DF Deutsche Fiskal GmbH also provides a Template.

In addition to the SMAERS environment protection, the Fiscal Cloud is effectively protected against manipulation and attacks by a comprehensive, voluntary package of measures. Central measures of the Fiscal Cloud, measures of the FCC and complex, centrally and locally effective measures are used, which record manipulation attempts, block the TSS and set alarm chains in motion. The effectiveness of these measures was confirmed by an independent penetration test. These measures work automatically and independently of the SMAERS environmental protection and are described in the Anlage Cloud-TSS zur Verfahrensdokumentation.

Notwithstanding the above approach, D-Trust GmbH and DF Deutsche Fiskal GmbH are working with the regulator as well as the financial authorities on solution options to facilitate the implementation of the environment protection requirements.