Category: IT Glossary

The hard disk: Maximum memory thanks to minimization

There are many competing names for permanent storage media in the IT sector: Hard disk, hard disk drive (HDD) or simply hard disc (HD). These are magnetic storage media with rotating disks ('platters') on which data is stored without contact.

Recently, solid state drives (SSDs) have also become available that no longer contain any moving parts. Although these are faster, they are also more expensive. They require more energy and offer less storage space. However, because they are less sensitive to shocks, they have conquered the mobile sector in particular (MP3 players, USB sticks, smartphones).

With conventional hard disks, storage capacities in the terabyte range are now also easily available for private customers (currently up to 10 TB). The increase in the storage capacity of HDDs roughly follows the increase in standard market computing power. The current standard size is 3.5".

Conventional hard disks are constructed as follows: One or more magnetizable discs ('platters') are mounted on an axis or spindle on a hydrodynamic plain bearing, a small electric motor drives the spindle (which then causes the typical 'hard disk noise'). Movable read-write heads (in principle tiny electromagnets) on an actuator axis take over the fixation of the data on the platters with the help of control electronics coupled to a digital signal processor (DSP), whereby they float 'contact-free' on the rotating air cushion above the disk. A hard disk cache enables the intermediate storage of data, while an interface ensures communication with other components of the computer. A fixed housing protects the electronics and the sensitive data disks.

The number and coating of the disks, as well as the intelligent type of 'labeling', determine the storage capacity. Today, modern hard disks use High Storage Density Media (HSDM), usually a CoCrPt alloy that is protected from damage by a diamond-like carbon coating. The increasing data density means that intensive research is now being carried out into ultra-high storage density media.

Incidentally, data does not have to be stored 'internally'. Many of our customers use b.r.m.'s external storage capacities - firstly because they have access to the most advanced hard disk technology and secondly because their data is protected from unauthorized access in a 'high-security room'.

E-mail: Do without paper

The Internet is the fastest letter carrier in the world. Emails allow text messages and digital documents (e.g. graphics or Office documents) to be delivered anywhere in the world in just a few seconds. In 2012, 3.375 billion people around the world already had an active email account.

Wherever people congregate like this, crime is not far away. File attachments in e-mail messages are one of the most common ways in which Trojans and other malware are spread. As a general rule, you should never open a file attachment from an unknown sender. Customers of b.r.m. are specially warned in such cases: a header of the e-mail warns them that this is a highly dubious e-mail.

Step by step to SMART ISO certification for SMEs

EcoStep was developed together with companies and is an offer to all small and medium-sized enterprises (SMEs) with up to 250 employees that want to optimize their operational processes and take environmental and occupational health and safety aspects into account. EcoStep 5.1 is a practice-oriented alternative to the conventional ISO standards. It uses the most important standard requirements of the following three standards from an SME perspective and combines them in one system:

  •     ISO 9.001 Quality management
  •     ISO 14.001 Environmental management
  •     ISO 45001 Occupational health and safety

Every company is unique. That is why EcoStep 5.1 is not a rigid system, but is based on the actual process flows in the company. In other words, it is based on the actual activities that take place one after the other or in parallel and serve to achieve the same goal (e.g. manufacturing a product or selling a service).

Depending on the industry and the company's field of activity, quality, environmental and occupational health and safety aspects are of greater or lesser importance. Depending on this, they are also weighted differently within the framework of EcoStep 5.1. Nonetheless, all three aspects are important and one aspect will never be completely omitted.

 

Regular recertification guarantees the existing and improved quality of the IT service company in Bremen. The IT service provider's last successful recertification to EcoStep 5.0 took place in December 2019. b.r.m. has now been EcoStep-certified for over 10 years.

Some things clear - and many things unclear in Europe: the GDPR

The new European General Data Protection Regulation (GDPR) was not on the radar of many companies and internet users for too long. The first draft dates back to 2012, the new paragraphs were adopted in April 2016 and the GDPR will now come into force on May 25, 2018. A lot of time has passed since then. The aim of the regulation is to create a uniform basis for data protection across Europe. It is intended to effectively prevent the undermining of standards by individual member states.

A new feature for users of online services is their 'right to be forgotten'. They will be able to obtain information about personal data and can request the deletion of data if storage is overdue, unnecessary or unlawful. Furthermore, all data must be 'portable' from now on: On request, the customer of a service can ask for their data to be handed over in a structured form so that they can pass it on to another provider. In general, two principles apply to all data processing operations on the Internet and in companies: privacy by design and privacy by default: The protection of privacy must already be taken into account when setting up a data processing operation and the default settings must be set up to protect privacy.

Anyone who cooperates with an external service provider for data processing can already rest assured at b.r.m. that we do not violate the new regulation when processing data on our behalf, and that the aforementioned privacy principles are adhered to. We have long since implemented the creation of a 'record of processing activities', which is required by the GDPR. Furthermore, all processing activities are fully documented. We are therefore your competent partner for all questions relating to the GDPR, if only because Harald Rossol, our Managing Director, is also a recognized data protection officer. Advice and support in all matters relating to the new European General Data Protection Regulation (GDPR) are therefore in the best hands with us - from technical and organizational measures (TOM) to security analysis and the register of processing activities through to risk assessment.

Incidentally, anyone who processes personal data online is affected by the GDPR, from small bloggers to global giants such as Facebook. All characteristics such as name, gender, skin color, political views, but also car license plates or clothing sizes are considered 'personal'. As soon as data is collected, stored, modified, read or transmitted, this is considered 'processing'. In future, anyone operating a website must inform every visitor about what data they collect and store and for what purpose. Only the judiciary and law enforcement are exempt from this. Compliance with the GDPR will be monitored by the data protection authorities. The main establishment of an operator or company is decisive for jurisdiction.

Initially, little will change for operators of small websites because the GDPR is in many respects similar to the previously applicable data protection laws. In most cases, it will be sufficient to adapt the data protection declarations and general terms and conditions (GTC). Above all, online data protection declarations should be 'generally understandable' in future, which of course opens up a wide scope for interpretation. Another new feature is 'self-disclosure under data protection law': every company must provide a citizen with information within one month about what information about them is stored there, for what purpose and for how long.
However, the boundary between 'private' and 'commercial' is becoming clearer. If I post pictures of my garden at home, this remains uncritical. However, if I sell garden furniture shown there, for example, then the website will fall under the GDPR in future. This also applies to 'affiliate offers', i.e. where the operator of a website links to another provider. Private operators should better eliminate such plug-ins, whether under WordPress or Firefox, until there is legal clarity.

In any case, it is essential to adapt the privacy policy and the terms and conditions on every website, otherwise you are just opening the door to 'warning lawyers'. There is a wealth of legally compliant text templates available online.

The threat of financial penalties for violations caused a lot of alarm. While the maximum fine was previously 300,000 euros, it can now be up to 20 million euros, depending on the severity of the infringement (Art. 83). An extra rule, which is primarily aimed at the tech giants, also makes a fine of up to four percent of global turnover possible, and ultimately also access to private assets.

However, the first consequence of the GDPR is likely to be ongoing legal uncertainty. What, for example, are a company's 'legitimate interests'? The regulation contains an abundance of such vague formulations, which will only be clarified by court decisions, presumably after years before the European Court of Justice. National data protection law also had to be adapted to the GDPR by means of a new Federal Data Protection Act. On the other hand, there is no longer an escape route from this regulation, for example overseas. The regulation applies to anyone who wants to collect or analyze data within the EU - so it also applies to Google or Facebook.

If you have any questions about the new GDPR and IT service in Bremen, simply contact us ...

DNS: The address book in the network

The 'Domain Name System' (DNS) is essentially an information service that manages addresses in the 'namespace' of the Internet and thus directs user queries to the right destination. The user enters a reasonably comprehensible query - such as the URL 'brm.de' - and the DNS then converts this text into a long number combination in one of hundreds of thousands of 'name servers', which corresponds exactly to the 'connection number' (IP address) of the desired subscriber.

Domain: The letter carrier for all levels

Without a unique address, no message would reach the recipient, even on the Internet. A 'domain' is a coherent sub-area within the Internet hierarchy that allows such exact addressing. The names of the domains - if not already assigned - can be freely chosen by network customers. The responsible registry is the NIC (Network Information Center) of the respective top-level domain, to which the endings on the far right of the Internet address refer (e.g. .de, .com or .org). In Germany, 'DENIC eG' registers all Internet addresses ending in .de.

The domain system resembles a widely ramified root system. At the top of the hierarchy is the root level, followed by the top-level domains and then the subordinate second- and third-level domains. In the address www.brm.de, for example, the 'www' is the root level that refers to the 'World Wide Web', the '.de' determines the German top-level domain, a 'brm' refers to our own domain at second level, and possible further additions at third and fourth level allow precisely defined pages on our homepage to be accessed.

Selecting and registering domains is one of our standard IT service tasks.

Domain: The small network within the large one

A domain - not to be confused with 'domain' - is used in the IT sector when dealing with a closed (company) network. In most cases, this is a 'Windows domain', which is of course also based on this operating system. The system administrator assigns the access data and also monitors the joining of a new 'client' (a new Windows computer). He sets up a Dynamic Host Configuration Protocol (DHCP) and the Domain Name System (DNS), which ensures participation in the local network.

DNSSEC - Protection against 'memory poisoning'

The Domain Name System Security Extensions (DNSSEC) methodology was introduced to provide increased protection against cache poisoning. It should no longer be so easy to attack the Domain Name System (DNS), an abuse that has often redirected data traffic to a foreign computer. Denial of Service (DoS) attacks, IP spoofing and DNS hijacking all originated from this security vulnerability.
DNSSEC secures data traffic using an encryption process. In a nutshell, the owner of the information signs every data traffic on the master server with a secret key ('private key'), which only the recipient can resolve with their 'public key'. The keys used have a limited period of validity. The EDNS capability of a computer is required to participate in the procedure. This 'extended DNS' allows protocol extensions to the Domain Name System (DNS).
It should be noted that with the DNSSEC procedure, only the 'traffic routes' via the participating servers are encrypted. The data or 'content' of a message remains unencrypted.

Digital: The witches' zero times

If the world consisted only of digital data, no one would be able to read these long strings of zeros and ones. The 'digital world' is that mysterious place where only computers can find their way around. Strictly speaking, this is the core meaning of the word 'digital', it refers to the binary world where the language of transistors rules.

Colloquially, we have long used the word 'digital' in a much broader sense. We use it to refer to 'digital technology' as a whole, i.e. those machines and calculators that use gates, counters and flip-flops to generate comprehensible and logical results from zeros and ones, which we then admire on the monitor.

Services: Intangible and indispensable

A service is any support that is not based on an exchange of goods or merchandise. The user does not buy 'tangible things' from service providers, but primarily expertise and experience. Such services are therefore essentially 'immaterial', even if concepts or carrier media are handed over at the end.

Classic services include, for example, tasks such as 'consulting', 'planning' or 'implementation'. Our IT service is one such classic service area. The remuneration is regulated by a contract for work or service. It obliges the contractor to provide the services defined therein, either on a one-off or permanent basis.

At its core, b.r.m. is a classic service provider: with our IT service, we guarantee our customers a problem-free and reliable setup and operation of their electronic data processing and IT communication.