A meeting in a bright meeting room

Coordinating a group-wide IT security program

Guide product teams through a security program, from policy to measurable implementation.

The IT subsidiary of a retail group rolled out group-wide IT security policies. ODCUS coordinated the product teams during implementation and made the progress measurable.

Starting point

Security requirements from several frameworks had to be implemented across many product teams, with no visibility of progress or maturity.

Approach

  • Coordinated product teams in implementing the IT security policies
  • Derived security requirements from ISO 27001, CIS Controls, BSI, MITRE, NIST and Zero Trust
  • Set up the roadmap, project planning and cluster rollout
  • Ran assessments and quality reviews via Microsoft Forms
  • Reported implementation level and KPIs via Power BI

Result

  • Clear security requirements per product team
  • Visible, steered implementation progress
  • Reporting to the program lead with KPIs
  • Data-based evaluation instead of gut feeling

Frameworks and tools used

ISO 27001CIS ControlsNIST CSF 2.0Power BI