Client Snapshot
An established specialty chemicals manufacturer in India, with multiple manufacturing sites and a diverse product portfolio serving industries worldwide. Its technology ecosystem included SAP S/4HANA and several business-critical SaaS applications supporting enterprise operations. As the organization continued to scale, it engaged Pierag to strengthen technology governance, build its IT control framework, enhance its information security policies, and support alignment with the ISO 27001 standard.
The Challenge
- The organization’s expanding technology landscape made it increasingly difficult to maintain consistent governance across SAP S/4HANA and multiple SaaS applications.
- Its information security policies needed to keep pace with the requirements of ISO 27001:2022.
- Technology risks, control responsibilities, and assessment criteria required clearer definition across critical IT processes.
- Different systems and teams followed varying control practices, limiting enterprise-wide visibility and oversight.
- Internal stakeholders needed stronger awareness and practical capabilities to sustain the security program.
Our Approach
- Conducted stakeholder discussions and reviewed the existing technology and policy environment to identify priority areas.
- Assessed 17 information security policies and revised them to align with ISO 27001:2022 requirements, developing additional policies where gaps were identified.
- Created an ITGC Risk Control Matrix for SAP S/4HANA covering access management, change management, and computer operations.
- Developed standardized templates for control testing, evidence collection, and reporting.
- Designed a testing methodology for ancillary platforms, including OpenText, Darwinbox HR, and Zoho CRM.
- Delivered focused control-testing training for the information security team, followed by a broader awareness session for nominated personnel.
Results Delivered
- Streamlined 17 existing policy documents and developed additional policies in line with ISO 27001:2022, strengthening the client’s information security framework.
- Established a unified approach to IT security controls across the organization’s core technology landscape and ancillary systems.
- Enhanced the internal team’s ability to maintain and monitor the strengthened security posture through focused training and knowledge-transfer sessions.
Impact
The engagement provided the organization with a clearer and more consistent foundation for managing technology risk across its enterprise systems. Improved policies, defined control responsibilities, standardized assessment practices, strengthened governance and supported ISO 27001:2022 readiness.The knowledge transferred to internal teams also enabled more sustainable oversight, helping the organization maintain and evolve its information security program as its technology environment grows.