Implementation of ISMS ISO/IEC 27001:
Support in design and compliance with DORA requirements in conjunction with ISO 27001
Support in design and compliance with DORA requirements in conjunction with ISO 27001
Creation of security, risk and emergency concepts for a nationwide operating authority in multiple locations. Conducting data protection impact assessments and completion of data protection concepts.
Creation of security concept, risk analysis, emergency concepts and data protection impact assessment according to:
Revision of documents according to KRITIS standards. Revision and specification of KRITIS-relevant documentation to prepare for next audit:
Consulting according to ICT basic protection, ISDS responsibility for building a new digitization platform according to:
Revision of documents according to KRITIS standards. Revision and specification of KRITIS-relevant documentation to prepare for next KRITIS audit:
Preparation for ISO 27001 and BSI IT baseline protection certification (approx. 60,000 residential units)
Key activities:
Review of security concepts, SFO, guidelines and concepts to prepare for §44 KWG audit:
Creation of security concepts:
Creation of information security and data protection concepts according to Si001 ICT basic protection for a government project in Switzerland according to NCSC requirements. Grouping of protection objects according to NATO C3 taxonomy.
Creation of ISDS concepts for test and production environment as well as emergency concept according to P042-Hi03 for production. Project involves multiple releases with adjusted ISDS concepts and standard documents.
Delivered objects for protection groups and individual objects according to P042 standard for enhanced protection requirements:
Emergency management and emergency concept creation for healthcare benefits billing in public sector according to:
Review of IT security documentation and preparation for BAFIN Banking Act §44 audit:
Review of documents and creation of guidelines in preparation for TISAX audit
Data protection impact assessment for introduction of electronic file management system
Creation of IT security concept for implementation of university management application (ca. 3500 employees, 15000 students):
Creation of IT security concept for 60 locations with approx. 45 servers according to:
IT environment conception according to Zero Trust Architecture model:
Creation of security, risk and emergency concepts for nationwide operating authority:
Pentesting web application and app:
Creation of IT security concept:
Review and revision of security concepts in preparation for audit:
Assessment and optimization of IT security settings
Analysis and security concept creation:
Network zoning concept development:
Mitigation of pentest findings and vulnerability analyses under forensic and incident response aspects
ISO 27001 audit preparation:
5-day training on security concept creation according to BSI basic protection compendium including:
Preparation for ISO 27001 certification:
Post-hack recovery:
Post-hack recovery:
Post-hack recovery:
Post-hack recovery:
Setup of all GDPR-relevant documents and processes as external data protection consultant
Security concept creation for Windows Server 2016/2019, Office 365 and Azure rollout:
Post-hack recovery:
Post-hack recovery:
Post-hack recovery:
Data protection consulting and external data protection officer for various clients according to EU-GDPR
Creation of security processes and review of existing processes:
Review of security concepts and mentoring for new concept creation
Review and optimization of ISMS after one year:
Tools/Methods: ISO 27001, BSI basic protection, security scanners/pentest tools
Security consulting for 3 projects:
Project scope: 8 million Euro
Security analysis, auditing and creation of IT security concepts
Security analysis and auditing:
Security analysis, concept and ISMS implementation based on ISO 27001/BSI basic protection analysis:
Tools/Methods: ISO 27001, BSI basic protection, security scanners/pentest tools
Security analysis, concept and ISMS implementation based on ISO 27001/BSI basic protection analysis for multiple municipalities:
Tools/Methods: ISO 27001, BSI basic protection, security scanners/pentest tools
Process design and consulting for RENITA project (digital radio network):
Tools: ITIL, COBIT, Office products, ServiceNow
Server migration project management:
Tools: HERMES 5, Microsoft Project, Visio, Office Suite
Security analysis and ISMS implementation:
Tools: HERMES 5, BSI basic protection, ISO 27001, COBIT, pentest tools
ISMS auditing and ISO 27001 certification preparation:
ISMS auditing and ISO 27001 certification preparation:
ISMS auditing and ISO 27001 certification preparation:
Administration of LAMP web platform on SLES 9,10,11:
Server migration project management using HERMES 5 methodology
Administration of large SUSE Linux Enterprise Server farm (ca. 500 servers):
Administration of SUSE Linux Enterprise Server farm (ca. 800 servers):
Continual service improvement of existing processes using COBIT, ITIL, PRINCE2
Sub-project management for nationwide migration at 4 of 750 locations
Administration of web platform using Apache Tomcat and Apache web server on SUSE Linux Enterprise Server
Conceptual setup of standardized Linux server systems using RedHat Enterprise and Advanced Server
Sub-project management for large project at SBB
Fine concept creation, test implementation and production deployment of Microsoft Operations Manager 2005
Creation of rough and detailed concepts for Windows Server 2003 migration
Infrastructure migration from NT 4.0 Server to Windows Server 2003
Project management for complete migration of government environment including clients and server infrastructure
Migration of company network from Windows NT 4.0 to Windows Server 2003 and Windows XP including infrastructure services and VMware virtualization
Training, administration (Windows and Linux servers), consulting and coaching
Project implementation for small and medium businesses:
Collaboration with IT retailer:
Administration of student computer pool and Office project consulting
Administration of training and production networks
Setup of Linux servers using SuSE Linux and integration into heterogeneous networks: