IT Landscape
In operation
Your IT, run by constitution.
We build, run, secure and evolve your entire IT landscape according to a binding IT operations constitution. You focus on your core business and get an IT that does not depend on how individual people are doing on a given day.
Area 5
Commercial operating basis
Domain 14
Area 4
External interfaces and data flows
Domain 13
Area 3
Unified IT workplace
Domains 8–12
Area 2
Structure and continuity
Domains 5–7
Area 1
Sites and platform
Domains 1–4
Starting point
IT is no longer just a technology topic.
A complete IT landscape is a system of operation, protection and order that must be managed continuously. For companies outside the IT sector, running it internally is a special project that is intensive in staff, control and liability and endangers the focus on the core business.
Outsourcing as a leading management decision
Management deliberately decides not to carry the build, operation, staffing, monitoring and further development itself. It still needs a capable, secure, predictable and auditable IT order. That is exactly what we deliver.
Relief for management
Management steers the core business, not the IT.
Clear responsibilities
Every task has a named owner.
Robust continuity
Independent of how individual people are doing on a given day.
Auditability
Documentation that proves due diligence.
The reference model
14 domains in five areas.
The IT operations constitution strictly separates site-bound data center services, a cross-site structure and continuity layer, and the unified IT workplace. Guiding principle: a site ends where the platform begins.
Area 1 · Sites
site-bound
1
Physical basis
Rooms, rack and zone structure, fire protection, access.
2
Power and cooling
Power paths, uninterruptible supply, emergency power, cooling, sensors.
3
Hardware layer
Servers, storage, separate out-of-band management, life cycle.
4
Platform and virtualization
Clusters, high availability, backup capability to separate, tamper-proof targets.
Area 2 · Structure and continuity
cross-site, defined once
5
Replication and failover
Moving workloads between sites in the event of a fault.
6
Backup topology and recovery
Redundant backups, retention, mandatory restore tests.
7
Namespaces and base rules
Naming conventions, time base, certificates, identity anchor.
Area 3 · IT workplace
unified, defined once
8
Systems and roles
Standardized operating systems, hardening, patch rules.
9
Applications and services
Applications, databases, file and communication services.
10
Clients and devices
Policies, software distribution, workplace operation.
11
Identities and access
Permissions, strong authentication, recertification.
12
Security, operations, governance
Security controls, operating processes, separation of duties.
Area 4 · External interfaces
universal, industry-neutral
13
Interfaces and data flows
B2B, customer portals, remote maintenance, cloud, banks, authorities. Handover point, encryption and approval for every flow.
Area 5 · Commercial basis
per landscape
14
Operations and resource management
Contracts, licenses, providers and third parties relevant to IT operations.
Define once, use everywhere
Six global control rules.
Cross-cutting topics are not reinvented in every domain; they are defined once, bindingly, and referenced by all domains.
CTRL-DOC
Documentation and versioning
CTRL-LOG
Logging and retention
CTRL-MON
Monitoring and alerting
CTRL-CHG
Change control
CTRL-EVID
Evidence index and audit package
CTRL-DEV
Deviation management
Principles every landscape rests on
Exposure minimization
Systems are locked by default and only reachable through authorized, encrypted access paths.
Staged service exposure
Visibility after authorization, enabling for defined sources, handover to a protocol gateway.
Stability-oriented changes
Updates and patches are risk-based, tested and controlled. Unnecessary changes are avoided.
Risk-based vulnerability handling
Externally reachable components handled promptly, verifiably and documented.
Risk and evidence
Every requirement has a liability class.
Evidence, tests, approvals and deviations follow the risk. What is business-critical is handled differently from day-to-day operations.
HR1
critical, liability-relevant
Legal obligations. A failure can lead to personal liability of management.
- Evidence mandatory
- Restore and failover tests mandatory
- Deviation only with risk analysis and approval
- Periodic review of access
HR2
essential, duty of care
State of the art. Neglect can count as gross negligence and endanger insurance coverage.
- Evidence largely mandatory
- Tests where dependency is high
- Deviations on protection topics documented
HR3
standard, operational
Important for efficiency and quality. Errors cause disruptions, usually without legal consequences.
- Pragmatic minimum documentation
- Tests as needed
- Deviations handled operationally
Mandatory records per contract
Six sheets. No grey areas.
Every contract includes six binding sheets. Undocumented deviations are deemed not agreed.
C1 Scope
Parameters, exposures, cloud scope, assignment of services.
C2 Applicability
Applicable or not for each domain, with justification.
C3 Responsibilities
Client, service provider and third parties for each domain.
C4 Deviations
With risk analysis, compensating measure, approval and liability class.
C5 Evidence and checks
All logs with retention periods.
C6 Jurisdiction
Data protection, retention, transfers to third countries per jurisdiction profile.
Test and audit framework
Restore tests, failover and replication tests, periodic review of external visibility and access enablements. Results are kept as evidence.
D1 RestoreD2 FailoverD3 VisibilityD4 Access
Jurisdiction profiles
The standard applies worldwide. Country-specific obligations are selected through profiles, such as DACH including Liechtenstein or an international minimum profile.
F1 DACHF2 International
Standards reference
Aligned with recognized standard families for data centers, information security, service management and business continuity. Ready for audits and certifications.
ISO/IEC 22237EN 50600ISO/IEC 27001ISO/IEC 20000ISO 22301
Execution with SIPES
The order is not just described, it is carried out.
SIPES, the Sulek Intelligent Process Execution System, puts the operations constitution into effect in live operations: case handling, role logic, audit trails, approvals, escalations and structured refinement.
Capture
Every case is captured as a ticket and assigned to a role.
Mirror back
The recognized content is shown to the sender for confirmation before it moves on.
Check and approve
Multi-level review, documented approval, defined escalation.
Refine
Insights from logs flow back into rules and work instructions.
Let us talk about your IT landscape.
Briefly describe your current IT and what you would like to hand over. We reply with a clear proposal for the scope.
support@techcenter.infoAddress
“TECHCENTER” MCHJ
Xiyobon ko‘chasi 65-J, Pichoqchi MFY
Marg‘ilon, Farg‘ona viloyati
Uzbekistan

Websites, IT landscapes, software and data centers. Resident of IT Park Uzbekistan.
„TECHCENTER“ MCHJ
ООО «TECHCENTER» · «TECHCENTER» LLC
STIR / ИНН / TIN: 313 318 956
Marg‘ilon sh., Pichoqchi MFY, Xiyobon ko‘chasi, 65-J, Farg‘ona viloyati, O‘zbekiston
Bosh direktor / Генеральный директор / CEO: Sulek Alina
Ro‘yxatdan o‘tgan / Регистрация / Registered: 09.09.2026
© 2026 “TECHCENTER” MCHJ. All rights reserved. ZAVET and SIPES © Frank Sulek.
