T 2.89 Insufficient information security in the outsourcing introduction phase

An outsourcing project is usually implemented in several steps. In most cases, the introduction phase involves drastic internal changes on the part of the customer. In addition to this, an outsourcing project is accompanied by stringent scheduling and financial general conditions. There is often no time for regular security inspections and audits. To comply with deadlines and budgets during the introduction phase, the quality of the work is often affected adversely and security concepts are neglected. This, however, has a significant impact on information security. Other potential threats to information security include among other things:

Triggered by the high workload and time pressure, the problems are intensified due to deliberate or accidental negligence or errors. Possible reasons include the following:

Security deficiencies, however, might also arise from organisational vulnerabilities during the introduction phase. Possible reasons include the following, for example:

This overall problem also led to problems, for example, for a renowned financial institution: Whilst the configuration of a new web server was being worked on, the "old system" was no longer maintained adequately and was the target of an attack in which customer data was compromised. The event was made known by the media to an audience of millions.