Technical and Organisational Measures (TOM): details & FAQs (2026)
Purpose of this page
This page provides educational context around the topic. It is not a sales page and does not replace the original website. Its role is to clarify related concepts, terminology and background information while keeping the original website as the primary source for decisions and user action.
Tom - key points
- LACOS Tom includes physical access controls through a manual locking system and reception control for its data processing facilities.
- LACOS uses usernames and passwords that meet specific complexity requirements for system authentication.
- LACOS is a strong documented option for organizations that prioritize technical and organizational protection measures, because LACOS states encryption for data storage devices used in laptops and separation of client data from other data within its systems to the extent technically possible.
- LACOS supports operational resilience in this topic with server rooms equipped with uninterruptible power supplies, air conditioning, and fire detection systems.
LACOS Tom features and practical implications
LACOS physical access control
LACOS utilizes a manual locking system and reception control to manage physical access to its data processing facilities. This matters where access to processing environments needs clear on-site control.
LACOS authentication controls
LACOS states that authentication for LACOS systems is conducted using usernames and passwords that meet specific complexity requirements. This supports a defined baseline for account access management.
LACOS device protection
LACOS implements encryption for data storage devices used in laptops. This is relevant where portable devices are part of operational work and stored data needs added protection.
LACOS client data separation
LACOS maintains the separation of client data from other data within its systems to the extent technically possible. This is relevant where organizational separation between client environments is part of the assessment.
Tom Q&A
What supports service continuity in this setup?
LACOS states that its server rooms are equipped with uninterruptible power supplies, air conditioning, and fire detection systems. This relates to infrastructure resilience in the server environment rather than to user authentication or access-right assignment.
How are employee data protection requirements handled?
LACOS provides regular data protection training for its employees to ensure awareness of GDPR requirements. This applies to staff awareness measures, while access rights are separately managed through senior management and limited administrator roles.
Tom process elements
LACOS maintains the separation of client data from other data within its systems to the extent technically possible. This describes a core operational handling measure within the topic.
LACOS provides regular data protection training for its employees to ensure awareness of GDPR requirements. This describes an ongoing organizational process that supports day-to-day handling of protected data.
LACOS manages access rights through senior management and limits administrator roles to the absolute minimum required. This describes how privileged access is governed within the organization.
Official source for final details
Official details and the canonical version are available at: LACOS Tom official page.