1 – Consulting activities in the fields of IT / Information Security and operational IT security
- Risk and IT Management Support: Providing assistance for risk and IT management functions,
- Comprehensive and Specific IT and Information Security Risk Analysis: Analyzing risks related to IT and information security comprehensively and specifically,
- Design and Implementation of IT and Information Security Control Plans: Creating and implementing control plans for IT and information security,
- Internal and External Audit Implementation and Follow-Up Recommendations: Executing internal and external audits and providing follow-up recommendations with action plans,
- Monitoring Compliance with Applicable Regulatory Standards: Ensuring compliance with relevant regulatory norm.
2 - ICT Risk Management - Internal Control
- Governance, Risk, and IT Compliance Assessment and Implementation: Evaluating and establishing governance, risk management, and an IT control environment or Information Security (e.g., implementing a security strategy),
- Implementation of IT Management Processes (e.g., ITIL Service Support – Incident, Problem, Change Management): Putting in place processes for managing IT services,
- Regulatory Compliance for IT and Information Security Processes or Activities (e.g., DORA; NIS2):Ensuring compliance with regulations related to IT and information security
3 - IT Management and Chief Internal Audit support
IT Management support
- Operational Implementation of IT Strategic Plans: Putting into practice the strategic plans related to IT,
- Ad Interim Operational IT Responsibility: Temporarily taking on an operational IT role,
- Internal Coordination and Monitoring Activities: Managing and coordinating internal processes and activities and tracking progress.
- Project Management and Oversight: Handling project management tasks and ensuring successful execution.
Chief Internal Audit Support
- Development of an IT / Information Security Audit Framework: Creating a framework for conducting audits related to IT and information security,
- Design of Multi-Year IT / Information Security Audit Plans: Developing audit plans spanning multiple years for IT and Information Security,
- Planning, Coordination, and Audit Oversight: Managing the planning, coordination, and monitoring of audit activities,
- ‘C-Level’ or Operational Reporting: Providing reports at the executive level or operational level.
4 - IT Audit and ICT Maturity evaluation
- IT Process (Cybersecurity) Analysis: Examining and evaluating IT and cybersecurity processes,
- Technical Review of IT and Security for Critical Applications or Infrastructures: Assessing the technical aspects of IT and security for critical applications or infrastructure,
- Execution of IT Process Maturity Assessment Missions: Conducting missions to evaluate the maturity of IT processes,
- Compliance Mission for IT Requested by a Regulatory Authority (e.g., CSSF – High Privilege Account Management): Fulfilling compliance missions related to IT as requested by a supervisory authority,
- Analysis of IT & Security Underpinnings and Risks Associated with Business Processes: Investigating IT and security aspects underlying business processes (e.g., analyzing IT and information security for payment processes, conducting technical reviews of AML applications),
- Execution of Integrated Audit Missions (i.e., IT and Security Assessment in the Context of Functional Business Audits): Carrying out integrated audit missions, evaluating IT and security within functional business audits.