English Version
IT Governance & More
Projects, Consultancy and Freelance
For IT Governance, Risk, Compliance (GRC), Security and Audit topics at organisations of different industries and sizes.
You are looking for...
- an IT GRC, Security and Audit expert for specific tasks and projects
- a coach, a second opinion, a dialogue partner, support to find creative solutions
- professional support during peak or holiday season, or at short notice
I provide...
- sound (hands on and management) experience in IT GRC areas
- quick comprehension, analytical skills and result-orientation
- high integrity, professionalism and motivation, sound social competencies and communication skills in German and English
About Me
Daniela Gschwend
lic. oec. inform. HSG, CISA, CGEIT, CRISC, CDPSE, ARM
Short CV:
- 11 years IT Auditor (7 years at Credit Suisse in Zurich and London, 4 years setup and lead of IT Audit department of Swiss Re)
- 20 years IT Governance at Swiss Re (setup and lead of the global IT GRC function)
- 20 years president of ISACA Switzerland
- See also: LinkedIn, Xing
Awards and Publications:
- International award "For amazing leadership and exceptional dedication": ISACA Switzerland, ISACA US
- Interview about IT Governance challenges: The Network: Daniela Gschwend (isaca.org)
Contact Details:
Bahnhofstrasse 71, 9320 Arbon
+41 79 207 3534
email: d(at)nie.la
Potential Projects and Tasks
IT GRC, Security and Audit areas in your organisation, for example:
- Small projects or parts of projects
- Special tasks, specific or generic questions and topics
- Consultancy for IT GRC topics in general
- Provision of experience for discussions, finding ideas and solutions
- Reviews of concepts, providing an independent opinion, eg internal IT control system, risks, organisation and processes
- Development and reviews of governance documents like guidelines, standards, charters etc
- Reviews of specific processes and assessment of their effectiveness, eg emergency procedures, crisis management
- Development and reviews of process documentation, controls and assessment of their maturity
- Preparation for internal, external and regulatory assessments and audits
- Preparation and development of a SOC report
- Analysis and translation of regulatory requirements into organisation specific controls and measures, eg GDPR, Finma operational risk
- Preparation of reports for internal / external reporting
- Access to experts in my personal network for additional support where required
Support for (external) Communication:
- Organisation of conferences, round-tables and other forms of information-sharing
- Organisation of networking events
- Publications and presentation of public information, eg websites
Coaching of Individuals:
- Consultancy and mentoring of professionals
- Support of experts, eg preparation of important tasks
Themes
A selection of themes / areas as part of my work experience:
- IT Audit, IT Governance
- IT processes and controls, internal IT control system
- IT / Security / Cyber Risks, ISMS
- Regulators, regulatory requirements, compliance
- International standards, ISO, COBIT, best practice
- SOC reports (ISAE 3402, 3000, SOC2)
- Third party cyber risk (management)
- GDPR, critical data, information governance, records management
- Challenges of technical solutions, cloud, international environment
- ...and many more...