English Version

IT Governance & More

Projects, Consultancy and Freelance

For IT Governance, Risk, Compliance (GRC), Security and Audit topics at organisations of different industries and sizes. 

You are looking for...

  • an IT GRC, Security and Audit expert for specific tasks and projects
  • a coach, a second opinion, a dialogue partner, support to find creative solutions
  • professional support during peak or holiday season, or at short notice

I provide...

  • sound (hands on and management) experience in IT GRC areas
  • quick comprehension, analytical skills and result-orientation
  • high integrity, professionalism and motivation, sound social competencies and communication skills in German and English


About Me



IT GRC expert with 30+ years of experience in the financial industry

Daniela Gschwend
lic. oec. inform. HSG, CISA, CGEIT, CRISC, CDPSE, ARM



Short CV:

  • 11 years IT Auditor (7 years at Credit Suisse in Zurich and London, 4 years setup and lead of IT Audit department of Swiss Re)
  • 20 years IT Governance at Swiss Re (setup and lead of the global IT GRC function)
  • 20 years president of ISACA Switzerland
  • See also: LinkedInXing

Awards and Publications:

Contact Details:

    IT Governance & MoreOwner Daniela Gschwend
    Bahnhofstrasse 71, 9320 Arbon
    +41 79 207 3534
    email: d(at)nie.la


Potential Projects and Tasks

IT GRC, Security and Audit areas in your organisation, for example:

  • Small projects or parts of projects
  • Special tasks, specific or generic questions and topics
  • Consultancy for IT GRC topics in general
  • Provision of experience for discussions, finding ideas and solutions
  • Reviews of concepts, providing an independent opinion, eg internal IT control system, risks, organisation and processes 
  • Development and reviews of governance documents like guidelines, standards, charters etc 
  • Reviews of specific processes and assessment of their effectiveness, eg emergency procedures, crisis management
  • Development and reviews of process documentation, controls and assessment of their maturity 
  • Preparation for internal, external and regulatory assessments and audits
  • Preparation and development of a SOC report
  • Analysis and translation of regulatory requirements into organisation specific controls and measures, eg GDPR, Finma operational risk
  • Preparation of reports for internal / external reporting
  • Access to experts in my personal network for additional support where required

Support for (external) Communication:

  • Organisation of conferences, round-tables and other forms of information-sharing
  • Organisation of networking events 
  • Publications and presentation of public information, eg websites

Coaching of Individuals:

  • Consultancy and mentoring of professionals
  • Support of experts, eg preparation of important tasks 


Themes

A selection of themes / areas as part of my work experience:
  • IT Audit, IT Governance
  • IT processes and controls, internal IT control system
  • IT / Security / Cyber Risks, ISMS
  • Regulators, regulatory requirements, compliance
  • International standards, ISO, COBIT, best practice
  • SOC reports (ISAE 3402, 3000, SOC2)
  • Third party cyber risk (management)
  • GDPR, critical data, information governance, records management
  • Challenges of technical solutions, cloud, international environment
  • ...and many more...


Beliebte Posts aus diesem Blog

Über Mich

Firmenübersicht