IT risk management: Protection requirements analysis for IT systems and individual data processing, identity and access management
Project duration: 1 year, 2 months
Brief description
Consulting and analysis in the area of regulatory framework conditions for a credit institute. On the basis of the protection requirements analysis, processes are structured for individual data processing and for authorization management.
Supplement
1. Protection requirements analysis: identifying IT applications that require protection, on the basis of a catalog of criteria, and introducing targeted measures for reducing potential risks. 2. Individual data processing: introducing a control process for developing, testing, approving and implementing in production processes in order to safeguard data security. 3. Identity and access management (IAM): introducing a suitable IT authorization method that ensures that all employees only have the rights that they require to perform their specific tasks and that comply with the MaRisk requirements.
Subject description
The minimum requirements for risk management (BA), or MaRisk for short (BA), are administration instructions published in a circular from the German Federal Financial Supervisory Authority (BaFin) for structuring of risk management in German credit institutes. (see https://de.wikipedia.org/wiki/Mindestanforderungen_an_das_Risikomanagement_(BA))