IT Controls and Policies Advisory for a prominent chemicals manufacturer in India

IT Controls and Policies Advisory for a prominent chemicals manufacturer in India

Follow Us:

Client Snapshot

An established specialty chemicals manufacturer in India, with multiple manufacturing sites and a diverse product portfolio serving industries worldwide. Its technology ecosystem included SAP S/4HANA and several business-critical SaaS applications supporting enterprise operations. As the organization continued to scale, it engaged Pierag to strengthen technology governance, build its IT control framework, enhance its information security policies, and support alignment with the ISO 27001 standard.

The Challenge

  • The organization’s expanding technology landscape made it increasingly difficult to maintain consistent governance across SAP S/4HANA and multiple SaaS applications.
  • Its information security policies needed to keep pace with the requirements of ISO 27001:2022.
  • Technology risks, control responsibilities, and assessment criteria required clearer definition across critical IT processes.
  • Different systems and teams followed varying control practices, limiting enterprise-wide visibility and oversight.
  • Internal stakeholders needed stronger awareness and practical capabilities to sustain the security program.

Our Approach

  • Conducted stakeholder discussions and reviewed the existing technology and policy environment to identify priority areas.
  • Assessed 17 information security policies and revised them to align with ISO 27001:2022 requirements, developing additional policies where gaps were identified.
  • Created an ITGC Risk Control Matrix for SAP S/4HANA covering access management, change management, and computer operations.
  • Developed standardized templates for control testing, evidence collection, and reporting.
  • Designed a testing methodology for ancillary platforms, including OpenText, Darwinbox HR, and Zoho CRM.
  • Delivered focused control-testing training for the information security team, followed by a broader awareness session for nominated personnel.

Results Delivered

  • Streamlined 17 existing policy documents and developed additional policies in line with ISO 27001:2022, strengthening the client’s information security framework.
  • Established a unified approach to IT security controls across the organization’s core technology landscape and ancillary systems.
  • Enhanced the internal team’s ability to maintain and monitor the strengthened security posture through focused training and knowledge-transfer sessions.

Impact

The engagement provided the organization with a clearer and more consistent foundation for managing technology risk across its enterprise systems. Improved policies, defined control responsibilities, standardized assessment practices, strengthened governance and supported ISO 27001:2022 readiness.The knowledge transferred to internal teams also enabled more sustainable oversight, helping the organization maintain and evolve its information security program as its technology environment grows.

Recent Posts
Extending ESG Maturity Across a Diverse Value Chain Network
Extending ESG Maturity Across a Diverse Value Chain Network
Client Snapshot As ESG reporting expectations continue to mature, companies are increasingly expected to demonstrate not only the strength of...
How Pierag Enabled a U.S.-Based Company to Achieve SOX Compliance Across Global Time Zones
How Pierag Enabled a U.S.-Based Company to Achieve SOX Compliance Across Global Time Zones
Client Snapshot An offshore oil and gas drilling services provider, employing more than 4,000 people, was undergoing significant organizational transformation...
SOC 1 and SOC 2 Control Testing Support for a US-Based Audit Firm
SOC 1 and SOC 2 Control Testing Support for a US-Based Audit Firm
Client Snapshot An established US-based audit firm serving global organizations across real estate, chemicals and specialty materials manufacturing, consumer products,...