S 2.256 Planning and maintenance of IT security during ongoing outsourcing operations

Initiation responsibility: IT Security Officer, Head of IT

Implementation responsibility: Administrator, Head of IT, IT Security Officer

After an outsourcing project has been implemented, information security must also be ensured during ongoing operations. For this purpose, an operational concept in which the security aspects are also taken into account must be planned for the outsourcing project. In this respect, the IT-related individual tasks do not usually differ from those tasks to be planned and implemented if there is no outsourcing (see S 2.199 Maintaining information security).

However, particularities result from the fact that the tasks are distributed to several parties and thus additional tasks (e.g. coordination talks and checks) arise. These tasks include, among other things:

Review questions: