Skip to main content Skip to footer
De­prec­ated element
Prinz-Mayweg Group –
IT se­cur­ity with
otris soft­ware

Cer­ti­fied IT se­cur­ity with otris privacy ISMS

The Prinz-Mayweg Group has been sup­ply­ing pre­ci­sion steel tubes to the auto­mot­ive in­dustry for over 100 years. And the company has been meeting the high quality stand­ards of its cus­tom­ers for just as long. Special cer­ti­fic­a­tions are re­quire­ments that auto­mot­ive man­u­fac­tur­ers demand from their sup­pli­ers today. The Prinz-Mayweg Group pre­pared and carried out the complex cer­ti­fic­a­tion process in the area of IT se­cur­ity with otris soft­ware.

Car man­u­fac­tur­ers have always had to protect them­selves against es­pi­on­age, sab­ot­age and data theft. With the in­tro­duc­tion of digital systems, this chal­lenge in­creased. The more complex the systems became in recent years, the more effort was needed to protect them. However, car man­u­fac­tur­ers do not only use their in­form­a­tion assets (e.g. design draw­ings) in­tern­ally, but also pass them on to their sup­pli­ers as re­quired. The man­u­fac­tur­ers there­fore have a great in­terest in en­sur­ing that their sup­pli­ers also operate a func­tion­ing IT se­cur­ity system.

IT Se­cur­ity Stand­ards in the Auto­mot­ive In­dustry.
In the auto­mot­ive in­dustry, there are special stand­ards (e.g. TISAX ®) that sup­pli­ers use to prove that they operate an ef­fect­ive in­form­a­tion se­cur­ity man­age­ment system (ISMS). The audit­ing in the area of IT se­cur­ity is tailored to the re­quire­ments in the auto­mot­ive in­dustry and has become a kind of knock-out cri­terion for sup­pli­ers: Without the re­quired cer­ti­fic­ates, no orders.

Located in Group Data Pro­tec­tion, the Prinz-Mayweg Group formed its own com­pet­ence team to tackle the cer­ti­fic­a­tion process in the area of IT se­cur­ity. The chal­lenge: In order to be ready for the audit, as well as to take ad­vant­age of a group as­sess­ment in group struc­tures, an in­form­a­tion se­cur­ity system (ISMS) ac­cord­ing to ISO/IEC 27001 had to be im­ple­men­ted in a cent­ral­ised manner and func­tion smoothly.

Se­lect­ing a special soft­ware.
The Prinz-Mayweg Group has been using the special data pro­tec­tion soft­ware otris privacy for years. The ad­di­tion of an ISMS module to the soft­ware came in very handy for the com­pet­ence team: “We did look at other products, but quickly real­ised that otris was the right choice. The de­cid­ing factor was not only the fa­mil­i­ar user in­ter­face, but also the fact that otris has been es­tab­lished and re­li­able for many years.

„The ISMS soft­ware from otris was a great help in pre­par­ing for our cer­ti­fic­a­tion.“

Project manager for the IT se­cur­ity cer­ti­fic­a­tion of the Prinz-Mayweg-Group

Ex­tern­al con­sult­ant com­pletes the team.
The com­pet­ence team engaged an ex­tern­al con­sult­ant from T-Systems MMS to be op­tim­ally pre­pared for the cer­ti­fic­a­tion process. One of the first steps was to con­fig­ure the ISMS special solu­tion for the project to­geth­er with otris con­sult­ing. The otris ISMS soft­ware already con­tains the cata­logues for cer­ti­fic­a­tion ac­cord­ing to ISO/IEC 27001 and ISO 27001 based on the BSI’s IT basic pro­tec­tion com­pen­di­um. “In­teg­rat­ing the cata­logue for the special re­quire­ments in the auto­mot­ive in­dustry was pos­sible without much effort. We liked that,” the team members report.

Prepare cer­ti­fic­a­tion
The sub­stant­ive work began with a gap ana­lys­is. To­geth­er with the ex­tern­al con­sult­ant, the project team de­term­ined the current state of the IT se­cur­ity system and checked it for stra­tegic and op­er­a­tion­al gaps. The otris ISMS was used for the con­crete pre­par­a­tion for cer­ti­fic­a­tion: the special soft­ware is used to doc­u­ment the current state of the IT se­cur­ity system. A network plan makes trans­par­ent which pro­cesses and in­form­a­tion values (assets) are in­ter­de­pend­ent. The in­teg­rated risk ana­lys­is func­tions de­term­ine the need for action and link meas­ures for op­tim­isa­tion.

The soft­ware makes it trans­par­ent where the Prinz-Mayweg Group stands and what needs to be done. During the op­er­a­tion­al work, the project team liked, among other things, the un­com­plic­ated in­teg­ra­tion of ex­tern­al service pro­viders: “We send an email with a link to the cor­res­pond­ing check­lists to the service pro­vider. After he has filled them out, the data is auto­mat­ic­ally trans­ferred to the soft­ware.”

The result
At the end of the cer­ti­fic­a­tion project, more than 180 in­di­vidu­al doc­u­ments with process de­scrip­tions were clearly struc­tured and in­ter­linked in the ISMS. The need for meas­ures was de­term­ined and the im­ple­ment­a­tion or­gan­ised. Even all staff train­ing on IT se­cur­ity is con­duc­ted using the system’s e-learn­ing func­tions. So well po­si­tioned, it was perhaps not sur­pris­ing but a great relief when the aud­it­ors an­nounced the result: Präzi­sion­srohre Friedr. Wilhelm Mayweg GmbH & Co. KG passed the audit! “We are pleased to have suc­cess­fully passed the cer­ti­fic­a­tion! The ISMS soft­ware from otris was a great help during the pre­par­a­tion. And cur­rently it helps us with the con­tinu­ous testing and op­tim­isa­tion of our IT se­cur­ity”, sum­mar­ises the project manager.

About the Prinz-Mayweg Group.
For more than 100 years, the Prinz-Mayweg Group has been pro­cessing pre­ci­sion steel tubes for cus­tom­er-spe­cif­ic ap­plic­a­tions in in­dustry and trade. The tra­di­tion­al company with headquar­ters in Wickede, which has been owner-managed since its found­a­tion in 1896, stands for pre­ci­sion, in­nov­at­ive content and ex­cel­lent quality in the cre­ation and pro­cessing of high-quality steel tubes and steel tube com­pon­ents. This per­form­ance strength and the as­so­ci­ated sym­bi­os­is of tra­di­tion and mod­ern­ity can be found, among other things, in the unique product di­versity, the in­nov­at­ive pro­duc­tion methods and the ex­traordin­ary ver­tic­al range of man­u­fac­ture.

Photo credits:
The photos used (banner, quote) were kindly provided by the Prinz-Mayweg Group.

Back to navigation Back to content Back to navigation Back to content