Success Story

From BPM tool to integrated management system ‒ information security management included

The Aeneis BPM suite is Kroschke's central platform for process-based risk management of all QM, information security and data protection risks, because it integrates ISO 27001:2013 into the existing QM system in accordance with ISO 9001:2015 and also includes the requirements for risk assessment of processes from a data protection perspective. This individual Kroschke solution with Aeneis is called “GECKO” by employees.
Success-Story-Kroschke-with-GRC-Software-Aeneis brand world
Branche
Labeling and security solutions
Anzahl Mitarbeitende
1900
Standort
Ahrensburg
Über das Unternehmen

The Kroschke Group combines companies with a strong automotive expertise profile. The focus is on Christoph Kroschke GmbH (CKG), DAD Deutscher Auto Dienst GmbH (DAD) and Kroschke Digital GmbH, which strongly network their competencies. CKG combines innovative automotive services, efficient process solutions and digital services. With over 500 nationwide locations and 17 European partners, the company is the industry leader for vehicle registrations. DAD offers holistic IT-based process and document management for managing large vehicle inventories. Customers include car rental companies, car manufacturers, banks, leasing companies, fleet operators and automotive marketers. As the Kroschke Group's digital innovation incubator, Kroschke Digital offers individual support in the development and implementation of innovative and digital business models in the automotive environment.

We had high requirements because we were looking for a BPM solution for the entire group of companies. Aeneids came out as the winner because, on the one hand, it offers a high level of functionality and, on the other hand, is within a suitable price range for our medium-sized company.

Sabine Wunsch, Head of Projects, Processes, Services at Christoph Kroschke GmbH

How “GECKO” enables successful ISO 27001:2013 certification in just 7 months

“We chose Aeneis in 2011 and haven't regretted it for a day. The system was also able to implement new requirements quickly and competently, such as the adjustment of ISO 9001:2015 to present process risks. As a result, we were one of the first users to be certified according to the new standard in February 2016. The expansion to ISO 27001:2013 was really enjoyable. Intellior partner SHD has developed a powerful ISMS module, which we were impressed by after a short webinar review, as it significantly simplifies digital information security management. We have documented our risks and IT systems (assets) in all processes and can therefore immediately jump from the process to the IT system with the assessed risks with just one click. Conversely, if a system malfunctions, we can immediately derive all affected processes and customers. GECKO has therefore become an integral part of both auditing and as an organization's knowledge repository.”

Sabine Wunsch, Head of Projects, Processes, Services at Christoph Kroschke GmbH

Kroschke's task

  • ISO 27001:2013 “Information Security Management” covers various requirements that are becoming increasingly important for service providers such as the Kroschke Group, who act as process and digitization experts in the automotive environment: It ensures the appropriate handling of information and data of all types with the help of a management system and ensures appropriate management of risks.
  • When outsourcing business areas to service providers, companies in a regulated environment, such as banks and leasing companies, are required to comprehensively check and ensure the information and data security of the outsourced information and data. Certification of the service provider in accordance with ISO 27001:2013 facilitates these tests.
  • In addition, ever increasing legal requirements such as the General Data Protection Regulation (GDPR) or the new Trade Secrets Act (GeschGehG) pose challenges for the company to adequately implement these requirements.
  • It is ultimately about the identification and appropriate management of information and (personal) data, and risk management with regard to their significance, value and criticality against unauthorized use or publication for the organization or the data subject with regard to data protection.

Short profile

Since 2013, all processes at Christoph Kroschke GmbH and DAD Deutsche Auto Dienst GmbH have been modelled in “GECKO”. The necessary internal and external audits are carried out annually using the additional “Audit Planning” module. Thanks to a well-trained employee and the cost-efficient support from intellior, all change requests can be implemented promptly. The system is updated daily with the relevant SAP components (tables, BAPIS, etc.). The new ISMS module represents all relevant standard requirements of ISO 27001:2013. It is now paying off that all IT systems have been connected to the processes and that only the risk assessment for the assets had to be supplemented. The integrated management system was born.

Outlook: With the upcoming replacement of the previous Internet and Document Center, the aim is to connect to Confluence.

Successful project completion in just 7 months

ISO 27001 & ISO 9001 certificates from Christoph Kroschke GmbH

“Everyone who deals with the challenges of ISO 27001:2013 is looking for a controlled document storage and is therefore usually looking for a system”

In October 2018, the Kroschke Group made the decision to implement ISO 27001:2013 promptly. Based on an implementation analysis carried out, it was clear to all people involved that it wouldn't work without GECKO (name of Aeneis in the Kroschke Group)!

After initial discussions with intellior and its development partner SHD, an ISMS test portal (information security management system) could already be accessed at the end of November. The basis for this expansion was the documentation of all relevant business processes. For Kroschke, this meant that it was able to build on the basis of almost 300 processes, including assessed process risks and managed documentation. In addition, the audit management system from 9001:2015 could be used 1:1 for internal information audits with minimal adjustments.

On this basis, the requirements were discussed intensively and the module was configured accordingly. The information risks could now be identified on the basis of the IT architecture and did not have to be defined in parallel with the process risks. The most important standard requirements — such as a risk analysis, its assessment and the Statement of Applicability (SoA) — were thus met.

This made it possible to draw on a digital basis throughout the audit process and to provide conclusive and uninterrupted evidence of information. After only 7 months of project duration, successful certification without any discrepancies was the “reward” for a well-thought-out system, a competent team and a high level of data and information security.

Benefits from Aeneis

  • Process modeling with standard BPMN, freehand diagrams, customizable
  • Contemporary personalized web portal function
  • Presentation/evaluation of SAP transactions, SAP tables and IT systems used
  • Assignment of process-relevant documents such as checklists, forms, etc. in processes
  • Control of visibilities via user rights and role systems, as well as areas of application
  • Presentation of dependencies and interdependencies between processes
  • Supplemented by the Audit Management module: Definition of responsibility, audit criteria, audit scope, allocation of individual standards, reporting of audit results, tracking of corrective measures, documentation of results
  • Risk management for processes and information security
  • Risk catalogs provided: ISO controls, vulnerabilities and threats, risk scenarios

Weitere spannende Case Studies:

Understanding, optimizing, and securing success-critical processes
Nutzen Sie das verbesserte Verständnis, um eine Grundlage für die Prozessoptimierung zu schaffen.
Risiken minimieren. Prozesse optimieren.
Kostenfreie Erstberatung anfordern