DB InfraGO x GBTEC: Effectively managing information security with a tailored ISMS

Information security is not a static set of rules for us, but a continuous process embedded in our day-to-day work. Our tailored ISMS, developed using GBTEC GRC Management, creates transparency, accountability, and efficiency across the organisation while providing our employees with the best possible support.

Simone Klauder Process Modelling Expert & Developer at DB InfraGO

Industry

Transport

Headquarters

Frankfurt am Main, Germany

Employees

Approx. 68,000

Challenge

DB InfraGO has operated an ISMS based on GBTEC GRC Management since 2017 and continues to enhance and optimise it. The customised solution is precisely tailored to the company’s requirements. Around 2,000 users work with the system.

To ensure the solution is used effectively, the following tasks must be carried out consistently:

  • Enhancing the existing application, including system changes and adaptations to internal processes
  • Implementing major projects, such as introducing the new second-generation assessments, which offer additional functionality
  • Support and ticket management to ensure comprehensive user support and efficient system administration
  • Maintaining a knowledge base with relevant documentation and how-to videos to support GBTEC GRC Management end users
  • Administering the system, including managing user accounts and permissions, as well as coordinating and testing updates
  • Coordinating activities with GBTEC through the ticketing system and regular virtual meetings to discuss ongoing matters and future developments

Solution

Given the complexity of its internal processes, a custom solution is the ideal choice for DB InfraGO, as it meets all requirements without compromise. The company has set up its own team to manage the application and implement user-requested changes quickly. A structured change management process allows the team to roll out updates and improvements approximately every six weeks. As a result, the ISMS can realise its full potential and deliver maximum value for DB InfraGO.

  • Standardised asset management process: Assets are recorded with all relevant information, followed by assessments of protection requirements and controls, as well as threat analyses
  • Effective risk mitigation: Risks are systematically identified, assessed, and categorised to determine appropriate treatment strategies and measures
  • Automatic links: Risks are seamlessly linked to controls and threats
  • Accelerated audit management: Findings from internal and external audits are addressed directly as measures or risks
  • Real-time heat maps and status overviews: An up-to-date overview of the risk situation and the progress of related measures
  • Personalised dashboards: Users have access to relevant overviews, pending tasks, and reports based on their permissions
  • Automated RAIS assessment: The Framework for Information Security Requirements (RAIS) is mapped in the system, enabling automated assessments in line with ISO 27001 and railway-specific requirements
  • Efficient control management: Clear icons, filters, and inheritance functions streamline the handling of controls
  • BSI integration: Relevant elementary threats are assessed automatically in accordance with the BSI IT-Grundschutz methodology

DB InfraGO’s comprehensive ISMS has already reached a high level of maturity and continues to evolve. Planned developments, such as asset-related improvements in audit management, the integration of BCM and vulnerability management, and connections to additional systems, including the employee directory, will create lasting synergies. An automation initiative featuring AI-powered employee support, comprehensive data integration, and further system improvements will unlock additional efficiency gains.

Key Highlights

  • Tailored ISMS based on GBTEC GRC Management, designed to map complex, company-specific processes effectively
  • Centralised system that seamlessly links asset management, risks, controls, audits, and measures
  • High level of maturity through continuous development, regular releases, and a structured change management process
  • Around 2,000 active users with role-based dashboards, clear to-dos, and a high level of transparency
  • Tangible efficiency gains through automation, real-time heat maps, and integrated ISO 27001 assessments

Ready to start your own success story?

Over 2,000 companies worldwide trust GBTEC to drive digital transformation and operational excellence. Now it’s your turn. Let us show you how our solutions can help you reach your goals, with expert insights and a personalized demo built around your business needs.

Book a demo callStart free trial