2 Days. 10+ Experts. Countless IAM & GRC Insights. Register for NEXIS INVOLVE | September 9-10 | Regensburg

Energy

DSW21 Unites Data Protection and Information Security Group-Wide with NEXIS GRC

With NEXIS GRC, DSW21 built an integrated data protection and information security management system, replaced heterogeneous in-house tools, and is rolling the solution out step by step across the entire 21GRUPPE.
Energy

About DSW21

DSW21 Dortmunder Stadtwerke has provided services of general interest (Daseinsvorsorge) for the people of Dortmund since 1857. These public services are the core business of the 21GRUPPE. The group includes subsidiaries, holdings, and shareholdings in further companies that take care of the infrastructure and services of daily life.

The group is organized into four areas. Mobility and Logistics covers local public transport, the H-Bahn 21, the Dortmunder Hafen 21 (Dortmund port), and Dortmund Airport 21. The Living Spaces (Lebensräume) area stands for urban development projects such as the Phoenix-See (Lake Phoenix). Energy and Water is the responsibility of DEW21, and the data networks are run by DOKOM21, the largest operator of data centers in the Ruhr region.

  • Location: Dortmund
  • Founded: 1857
  • Group: 21GRUPPE (including DSW21, DEW21, DOKOM21)
  • Areas: Mobility + Logistics, Living Spaces, Energy + Water, Data Networks
  • Local transport: More than 100 million passengers per year
  • Dortmund Airport 21: More than 2.6 million air passengers (2022)

With NEXIS GRC, DSW21 was able to

Unite Data Protection and Information Security

Bring both disciplines together in one integrated management system.

Replace Heterogeneous In-House Tools

Replace Word and Excel templates and Visio org charts with a central system.

Create a Consistent, Valid Data Foundation

Map processes, information, assets, and service providers in a consolidated, traceable way.

Ensure Audit-Proof Documentation

Provide audit-ready evidence for audits and regulatory requirements.

Involve Business Departments through Interview Wizards
Roll out and Expand Across the 21GRUPPE

Bring further modules such as Security Incidents, Measures, and IT Risk into operation step by step.

The Challenge

Before the tool selection, the starting position at DSW21 varied widely. In the areas of information security, data protection, quality management, and organization, the teams implemented the requirements mostly with Word and Excel templates. They maintained org charts in Visio, and processes existed primarily in procedural guidelines and function descriptions.

The goal was a software solution that covers all requirements for data protection and information security management and, at the same time, offers the option to map the organization and further management systems up to business continuity management. The basic requirements were coverage of regulatory specifications, audit-ready documentation, and the integrated, software-based mapping of the management systems.

The goal was to:

  • Cover all requirements for data protection and information security management in one solution
  • Create the option to map the organization and further management systems up to business continuity management
  • Reliably cover regulatory requirements
  • Ensure audit-ready and audit-proof documentation
  • Map the management systems consistently on a software basis

The Approach

The basis for the selection was a detailed requirements catalog with chapters on functional and non-functional requirements, interfaces, data protection, information security, organization, and business continuity management. DSW21 assessed a total of 10 software solutions in several workshops and reviews. NEXIS GRC stood out through the high degree of fulfillment of the requirements catalog, its usability, the implemented methodology, the comprehensive content, and the different user modes for experts and business users. The implementation was then divided into six phases.

Base Configuration

Together with Nexis, the teams set up the base configuration, including rating scales, methodologies, logos, reports, and business units. Already in this phase, the teams implemented company-specific specifications in NEXIS GRC.

Commissioning at the IT Service Provider

Nexis installed the system at the IT service provider, set up access accounts and the Active Directory integration, and prepared training materials for managers and employees. An internal manual defined consistent naming conventions and guidance on data maintenance.

Initial Data Population

DSW21 prepared the existing information on processes, assets, and service providers and imported it. After further detailed configuration and the definition of the nomenclature, the business processes, the associated information, the asset groups, and the service providers were populated in NEXIS GRC.

Rollout at DSW21

Kickoff meetings with the business departments presented the approach and the interview wizard. The coordinators in the business departments took over independent maintenance, and data protection and information security officers reviewed the updated processes via the interview adoption wizard.

Rollout into the 21GRUPPE

The rollout extended to the 21GRUPPE. Important factors were the involvement of the coordinators from the individual companies, the transfer of base and standard processes, and the conduct of the interviews in the same way as at DSW21.

Regular Operation and Continuous Improvement

Finally, the system transitioned into regular operation, and DSW21 established a continuous improvement process. In parallel, during phases 3 to 6, DSW21 brought further modules into operation, including Security Incidents, Measures, and IT Risk.

The Result

DSW21 and the 21GRUPPE look back on a successful project. As key insights, the team names that consistent structures for data transfer are essential and that the business departments should be closely supported when using the software.

  • Consistent, valid data foundation: A consolidated basis for all management systems
  • Traceable relationships: Dependencies are mapped and transparent
  • Audit-proof documentation: Audit-ready evidence is available
  • In-house tools replaced: Word, Excel, and Visio are replaced by an integrated system
  • Self-reliant business departments: Coordinators maintain their processes via the interview wizards
  • Extensible: Planned are the increased use of the reporting module, deployment in upcoming audits, and the business continuity module

See How Integrated Data Protection and Information Security Management Works in Practice

Learn how NEXIS GRC helps municipal groups unite data protection and information security in one system, create an audit-proof data foundation, and roll the solution out group-wide.