
- legal provisions (e.g. GDPR) are not or not correctly implemented and there are no technical, organisational or other
measures in place to circumvent or rectify such errors,
- known aspects of insufficient IT security, in particular vulnerabilities with a CVSS score of 7.0 or higher (High or Critical).
A defect that impedes operation or a malfunction that impedes operation is present if the use of the overall system is
significantly restricted. Defects in this category mean that an essential function or an essential business process cannot be
executed or is faulty, but no direct subsequent errors occur. There is no failure of the overall system as a whole, working with the
system is possible with restrictions in operation, time-critical functions and business processes are affected. A workaround is
possible. However, bypassing the system involves a great deal of effort or considerable additional manual work, which can only
be expected of the client in the short term. Unreasonableness is also given if the performance of the system is significantly
restricted and time-sensitive functionalities are involved. These include, among others:
- Defects in individual cases which, if they were to occur in several cases, would be deemed to prevent operation,
- Supporting functions, such as plausibility checks, do not recognise all errors,
- Values are not pre-selected or restricted, or not to the extent possible,
- The performance is limited and there are waiting times of more than up to 3 seconds for non-complex activities,
- Incorrect data is provided to other system components or third-party systems via an interface of the overall system,
which must be corrected by means of manual intervention, but this can only be expected of the client in the short term
- legal provisions (e.g. GDPR) are not or not correctly implemented and there are technical, organisational or other
measures to circumvent or rectify such errors, which, however, can only be expected of the client in the short term,
- known aspects of insufficient IT security, in particular vulnerabilities of medium criticality with a CVSS score of 4.0 to
6.9,
- Search functions do not provide the correct result, or search criteria can only be achieved in a different way, for
example through several search steps.
A minor defect or a minor malfunction is deemed to exist if the overall system can be used without or with insignificant
restrictions. These are among others:
- Incorrect placement of UI elements, typing errors in the GUI, colour errors, font errors etc.,
- Errors in documents that do not limit their usefulness (format, alignment, colouring, etc.),
- A functionality is faulty, but can be achieved via alternative functions without significant additional effort,
- Supporting functions are not available, but do not lead to any significant additional work.
A defect or malfunction that impedes operation also exists if the minor defects or malfunctions lead to a significant restriction in
the use of the overall system or one or more system components (CP, HR system). See chapter
3.1 and the associated requirements DT01.08 Permitted number of errors in the system test and DT01.09 Acceptance tests of the
client in chapter 5.8.
13 December 2024 Page 350 of 366