

The Kroschke Group combines companies with a strong automotive expertise profile. The focus is on Christoph Kroschke GmbH (CKG), DAD Deutscher Auto Dienst GmbH (DAD) and Kroschke Digital GmbH, which strongly network their competencies. CKG combines innovative automotive services, efficient process solutions and digital services. With over 500 nationwide locations and 17 European partners, the company is the industry leader for vehicle registrations. DAD offers holistic IT-based process and document management for managing large vehicle inventories. Customers include car rental companies, car manufacturers, banks, leasing companies, fleet operators and automotive marketers. As the Kroschke Group's digital innovation incubator, Kroschke Digital offers individual support in the development and implementation of innovative and digital business models in the automotive environment.
We had high requirements because we were looking for a BPM solution for the entire group of companies. Aeneids came out as the winner because, on the one hand, it offers a high level of functionality and, on the other hand, is within a suitable price range for our medium-sized company.

“We chose Aeneis in 2011 and haven't regretted it for a day. The system was also able to implement new requirements quickly and competently, such as the adjustment of ISO 9001:2015 to present process risks. As a result, we were one of the first users to be certified according to the new standard in February 2016. The expansion to ISO 27001:2013 was really enjoyable. Intellior partner SHD has developed a powerful ISMS module, which we were impressed by after a short webinar review, as it significantly simplifies digital information security management. We have documented our risks and IT systems (assets) in all processes and can therefore immediately jump from the process to the IT system with the assessed risks with just one click. Conversely, if a system malfunctions, we can immediately derive all affected processes and customers. GECKO has therefore become an integral part of both auditing and as an organization's knowledge repository.”
Sabine Wunsch, Head of Projects, Processes, Services at Christoph Kroschke GmbH
Since 2013, all processes at Christoph Kroschke GmbH and DAD Deutsche Auto Dienst GmbH have been modelled in “GECKO”. The necessary internal and external audits are carried out annually using the additional “Audit Planning” module. Thanks to a well-trained employee and the cost-efficient support from intellior, all change requests can be implemented promptly. The system is updated daily with the relevant SAP components (tables, BAPIS, etc.). The new ISMS module represents all relevant standard requirements of ISO 27001:2013. It is now paying off that all IT systems have been connected to the processes and that only the risk assessment for the assets had to be supplemented. The integrated management system was born.
Outlook: With the upcoming replacement of the previous Internet and Document Center, the aim is to connect to Confluence.

“Everyone who deals with the challenges of ISO 27001:2013 is looking for a controlled document storage and is therefore usually looking for a system”
In October 2018, the Kroschke Group made the decision to implement ISO 27001:2013 promptly. Based on an implementation analysis carried out, it was clear to all people involved that it wouldn't work without GECKO (name of Aeneis in the Kroschke Group)!
After initial discussions with intellior and its development partner SHD, an ISMS test portal (information security management system) could already be accessed at the end of November. The basis for this expansion was the documentation of all relevant business processes. For Kroschke, this meant that it was able to build on the basis of almost 300 processes, including assessed process risks and managed documentation. In addition, the audit management system from 9001:2015 could be used 1:1 for internal information audits with minimal adjustments.
On this basis, the requirements were discussed intensively and the module was configured accordingly. The information risks could now be identified on the basis of the IT architecture and did not have to be defined in parallel with the process risks. The most important standard requirements — such as a risk analysis, its assessment and the Statement of Applicability (SoA) — were thus met.
This made it possible to draw on a digital basis throughout the audit process and to provide conclusive and uninterrupted evidence of information. After only 7 months of project duration, successful certification without any discrepancies was the “reward” for a well-thought-out system, a competent team and a high level of data and information security.