CODESPRING
Delicery Model
HOME » MODELUL DE LIVRARE

Confidentiality

The Confidentiality Bubble

Codespring Delivery Model as many other business models in software development industry did not escape form the so called Confidentiality Bubble with both its negative and positive aspects. Nowadays, confidentiality is a crucial concept for product and service development. As defined by the International Organization for Standardization, “confidentiality” means “ensuring that information is accessible only to those authorized to have access” (ISO/IEC-17799, 2009). Consequently, “access” and “authorization” become major keys in defining what is confidential and what is not.

 

At Codespring, clients and partners may rely on four dimensions of our Confidentiality System:

  • Signing of a corporate NDA (non-disclosure agreement)
  • Security of overall infrastructure
  • Individual NDA (non-disclosure agreement) for team members
  • Internal Regulation

Corporate NDA (non-disclosure agreement)

For the security of software development projects, our procedures foresee the signing of the NDA with our clients, as a legal document defining confidentiality levels, flows of information and authorized access to specific information. Thus, both parties restrict access of third parties to the information that may be the fundament of a future software product or system. It insures comfort in exchanging information and facilitates communication. General issues that an NDA addresses are: definition of what must be kept confidential, exclusions, provisions, the terms of the agreement, mutual obligations, permission to obtain ex-parte injunctive relief, types of permissible disclosures.

Security of Infrastructure

Confidentiality I software development must be ensured by all means. Codespring does not make any exception. The infrastructure of the company is highly secured. The buildings where software development engineers are being situated have controlled access. Only authorized personnel can enter the building, and each individual has defined access sectors. Network communications are secured. Access levels are defined by user. Measures against potential sabotage, information warfare and natural disasters are being in place.

Individual NDA (non-disclosure agreement)

Each software development engineer is made responsible for working with confidential information by signing an individual NDA (non-disclosure agreement). Even if the company implemented a standard individual NDA, sometimes it is necessary that supplementary NDA is signed by the team overtaking a new project. Usually this is done at our clients request and it completes the definitions of confidential information and level of access.

Internal Regulation

Codespring Internal Regulation comprises a set of well defined working procedures. Its’ role is to prevent errors and information leaks or damages that may occur from negligence or human error. Of course, even if the Internal Regulation cannot be exhaustive, it includes the up to date working standards for IT&C industry in Romania and Europe. When procedures are well implemented and applied there is little room for errors.

W3C XHTML 1.0W3C CSSCreative Commons
® Copyright 2010. CODESPRING - Software Development & Outsourcing | Protectia Consumatorilor - A.N.P.C.