Skip to main content

Compliance that holds in an audit

We bring your measures together with the rule books that apply to you: NIS2, ISO 27001, DORA and IT-Grundschutz. Described once, evidenced several times.

Ueberlappende Regelwerke Drei Regelwerke mit grosser Schnittmenge. In der Mitte die Nachweise, die fuer alle drei zaehlen, am Rand die, die nur eines verlangt. NIS2 DORA ISO 27001 NOT COVERED COMPLIANCE · NIS2, DORA, ISO 27001
Trusted by
The starting position

Three rule books, one organisation

Most companies now meet more than one set of requirements at once. NIS2 arrives through the supply chain or through their own classification, ISO 27001 through customers and tenders, DORA through financial supervision, IT-Grundschutz through the public sector. Every rule book brings its own vocabulary, its own numbering and its own deadlines.

What that becomes day to day, we see the same way again and again: three projects side by side, three binders, the same firewall rule described three times. The organisation works on documents rather than on risks, and in the audit it turns out that at the point nobody mapped there is nothing at all.

The effort does not come from the requirements. It comes from working on them separately.

Three shapes

Where you start depends on where you stand

We do not always start with the management system. Usually the fastest route to clarity is an honest survey of where things are.

Taking stock

A gap analysis against the rule book that actually applies to you. The result is a list of gaps, not of topics, and for each gap the effort to close it. Two to four weeks, depending on size.

Building

You have the gaps and need the implementation: policies that fit the organisation, procedures somebody carries out, and evidence that arises in operation rather than before the audit.

Seeing it through

You are on the way to a certificate or an audit. We sit on your side of the table: internal audits, preparing the samples, and the uncomfortable questions beforehand rather than afterwards.

The approach

One piece of evidence, several rule books

Ueberlappende Regelwerke Drei Regelwerke mit grosser Schnittmenge. In der Mitte die Nachweise, die fuer alle drei zaehlen, am Rand die, die nur eines verlangt. NIS2 DORA ISO 27001 NOT COVERED COMPLIANCE · NIS2, DORA, ISO 27001

We do not work along the rule book but along the measures. The access control NIS2 requires is at heart the same one ISO 27001 asks for in A.5.15 and that DORA expects for ICT access. Describe it once properly and evidence it once properly, and three requirements are met.

To do that we lay your measures against every rule book that applies to you and mark two things: what counts more than once, and what is covered by none of them. The second is the more important. That is usually where something sits that happens in operation and is described nowhere.

The result is an order of work: what closes the most gaps per unit of effort.

Approach

How taking stock works

Four steps, four to six weeks in total.

1

Establish the scope

Which rule books really apply, for which entities, for which systems. The answer decides all the effort that follows, so it comes at the start and not in an appendix.

2

Survey the current state

Interviews with the people who run the systems, not only with those responsible for them. Plus a look at configurations, logs and contracts.

3

Compare

Measures against requirements, with an assessment per gap: severity, effort, and whether it concerns one rule book or several.

4

Roadmap

An order of work with owners and dates. A list a management team can plan with.

Where the line is

What we do not do

We issue no certificates. A certification audit to ISO 27001 is carried out by an accredited body, and whoever advises may not audit there. That is precisely why we can stand on your side.

We also sell no tool that promises compliance. A GRC tool helps once the procedures are in place, and only lengthens the list when they are not.

And we do not write a policy that belongs to an organisation you are not. A thirty page template nobody reads is as worthless in an audit as none at all.

Common questions

Common questions about compliance

That is the most common way in. The classification turns on sector, size, and whether you supply something essential to an affected customer. It can be settled in a few days. The detail on deadlines, reporting duties and liability is on our NIS2 page.

Both at once, but not across the full breadth. A management system with no technical substance fails an audit; technical measures with no procedures do not survive the next change of staff. We start with the areas where the two coincide.

Partly. We build procedures, run internal audits and see the audit through. We do not take over running your systems, because that belongs with you. Where you need lasting support, our security monitoring is the better route.

Almost every rule book requires regular technical testing. A penetration test supplies the evidence and finds along the way the gaps that appear in no document. Conversely, a test without that framing is only a list of findings.

Credentials

Certifications and memberships.

Certifications held in the team
Memberships
eco – Verband der Internetwirtschaft
networker NRW
Next step

Talk to us.

A first conversation usually takes 30 minutes. We look at where you stand and tell you frankly whether we are the right partner.

Telephone
0231 39814905
Mon–Fri · 9am–5pm CET
Email
info@yekta-it.de
PGP key available
Location
Dortmund
Ruhrallee 9 · 44139