Project Example: Stadtwerke Düsseldorf

Home   >   References   >   SelfService-Portal of Stadtwerke Düsseldorf Receives “Trusted Application” Certificate

SelfService-Portal of Stadtwerke Düsseldorf Receives “Trusted Application” Certificate

Customers of Stadtwerke Düsseldorf can manage their accounts conveniently via the Internet. For this purpose, the energy supplier offers a comprehensive self-service on its website, the security and quality of which has been certified by TÜV TRUST IT after extensive testing.

Initial situation

Stadtwerke Düsseldorf has been supplying Düsseldorf with energy and water for more than 140 years and is one of the most efficient energy supply companies in the region. Stadtwerke Düsseldorf AG operates its own website, SelfService, a publicly accessible application that provides customers with a wide range of functions on the Internet. This comprises for example the collection of the meter readings, announcing and deregistering with a housing change and contract administration.

In addition, contact data and bank details can be updated, online invoices viewed, discounts adjusted and invoices simulated. In order to demonstrate the high security and quality standards of SelfService to customers, Stadtwerke Düsseldorf AG has commissioned TÜV TRUST IT to test and certify the system on the basis of the “Trusted Application” catalogue of requirements.

Approach

For the certification, tests were carried out with regard to information security, data protection, secure software development and technical security.

The approach in the project was divided into several steps. In addition to a technical examination of the infrastructure, the relevant organisational processes for operating the application and the infrastructure were also examined. The organisational analyses were carried out on the basis of document checks and supplementary interviews. In the process, data protection-compliant handling of customer data was also checked.

“The self-service application of Stadtwerke Düsseldorf proved its conformity with data protection, data security and secure operation in the technical and organisational audit”, explains Manuel Münchhausen, Senior Consultant at the IT security specialist. “In the course of the investigations, it became apparent that the operation of the self-service portal is highly mature. The broad-based procedures for managing information security and data protection, as well as the procedures for technical operation, deserve a positive mention.”

The broad-based procedures for managing information security and data protection, as well as the procedures for technical operation, deserve a positive mention.”

Zertifikatsübergabe bei den Stadtwerken Düsseldorf

Certificate handover at Stadtwerke Düsseldorf

 

Benefits

With the certification of the SelfService, Stadtwerke Düsseldorf AG benefits not only from the increase in information security. It can now also prove to its customers that its data is securely stored, thereby also positioning itself vis-à-vis the competition. “Stadtwerke Düsseldorf has recognised that the issue of data protection and information security is not only a bureaucratic compulsory exercise but also a competitive factor for the company. Our customers have become much more sensitive to the confidentiality and integrity of their data.

We are therefore required to provide adequate evidence of this. The certificate is an essential indicator of this. At the same time, we are committed to regularly reviewing our security standards”, said Carsten Domat, Head of Data Protection and Information Security Management at Stadtwerke Düsseldorf, welcoming the results of TÜV TRUST IT.