Compliance and IT-Security
IT-Security-Management-System · ISMS
Our advisory contribution is especially relevant when considering IT and data protection compliance and the evaluation of central security considerations, such as the analysis of security weaknesses, reaction and crisis management, and the optimization of systems.
The need for “system security” that functions effectively from a business, technical and insurance / legal perspective is often placated and “certified”. However, in practice valid and homogenous synthesis of data and knowledge, which is present to differing extents in each organization, is regularly lacking. Successfully navigating this is challenging. The ability to reflect critically and the implementation of “error management”, i.e. avoiding and dealing with mistakes, should be strived for, if space is to be made for optimization.
Legally and practically sensible procedures, whether it’s a case “security vulnerabilities”, “data breaches”, “data scandals” or “technical or human error”, can rarely be directly copied from an operating manual of be directly obtained by a management consultant. Tried-and-true legal strategies that align with corporate culture and the common good are helpful in this regard.
We offer support in and around IT and data protection compliance, in addition to custom security concepts and frameworks such as information security management systems, ISO/IEC 27001, 27002, 27701, and BSI Basic Protection.