Due to the constantly growing regulatory requirements for IT, ISB needs external support, especially with regard to a pilot function and in the form of quality assurance support for the further development of the IT management organizational unit. This includes, above all, the coordination of the operationalization of the results of the BAIT implementation project as well as the areas of IT strategy, IT governance, IT outsourcing management, IT emergency management, PMO, management consulting (IT regulation).
The organizational unit IT management needs support and consulting services for the further development of the assigned areas of responsibility and for the operationalization of results of the BAIT implementation project.
Tasks:
- IT strategy (workflow organization, processes, implementation)
- Review and optimization of the IT strategy process
- Annual revision and further development of the IT strategy
- Identification and collection of key figures
- Supporting the bank in the preparation of documents for the board of directors and committees (approval process for the IT strategy)
- IT governance (process organization, processes and controls, conception, implementation, operationalization, RiMaGo software used, BIC tool, IT standards to be observed: BSI and ISO 2700x)
- Revision and further development of policies and procedures (organizational instructions, work instructions, processes, etc.)
- Revision and further development of application inventory and application inventory
- Revision and further development of the IT-internal control system (IT-ICS)
- Operationalisierung der "Second Line of Defense"-Überwachungsfunktion
- Revision and further development of the IT process map (support processes in the entire IT area)
- Preparation of documents for reporting to IT managers and board of directors
- IT emergency management (structural and procedural organization, processes and controls, conception, implementation, operationalization, RiMaGo software used, BIC tool, IT standard to be observed: BSI (200-4)
- Revision and further development of the guidelines and procedures for IT emergency management in compliance with the requirements of business continuity management (overall bank)
- Revision and further development of IT process controls in IT emergency management, taking into account the requirements of business continuity management (entire bank)
- Operationalization of the annual business impact analysis
- Revision and further development of emergency concepts, emergency planning, emergency test planning, implementation and documentation of emergency tests
- Revision and further development of IT emergency management for outsourcing
- Preparation of documentation for reporting
- Project Management Office
- quality assurance
- Management consulting (IT regulation)
- Know-how-Transfer