Data protection, information security, and regulatory requirements are placing increasingly specific demands on identity and access management. We help you understand the implications for your IAM architecture and ensure long-term compliance.
Regulations – Ensuring IAM Compliance
Relevant Regulations
EU-DSGVO
The General Data Protection Regulation sets forth requirements regarding data minimization, purpose limitation, the right of access, and erasure processes - all of which have a direct impact on IAM systems and authorization models.
Swiss DSG
The revised Swiss Data Protection Act (nDSG) imposes stricter requirements regarding data security, data protection impact assessments, and reporting obligations in the event of data breaches.
NIS2 Directive
NIS2 significantly expands the scope of affected companies and sets specific requirements for risk management, access control, and incident reporting.
FINMA / Banking Regulation
Specific Requirements for Financial Institutions: FINMA Circular on IT and Cybersecurity, DORA (EU), and the Requirements for Privileged Access Management in Regulated Environments.
ISO 27001 / ISMS
IAM is a key control area in ISO 27001. We provide support in designing IAM controls as part of ISMS implementations and audits.
Industry-specific
Additional regulations depending on the industry: PCI-DSS (payment processing), HIPAA (healthcare), TISAX (automotive), or industry-specific FINMA requirements.
Request Compliance Consulting
We analyze your regulatory requirements and develop specific IAM measures.