Digitale Fabriek / Engie
ICT & Business
Client company:ENGIE
Bjarne Phaff
Sebastiaan Gaastra
Lars van Laarhoven
Project description
This project is about the engineering and utilities company ENGIE. They offer services for both consumers and businesses. ENGIE is currently not transparent enough to its customers in the BIC (Brainport Industry Campus). This gives customers questions that ENGIE cannot answer clearly.
This project is about how ENGIE can deliver better transparency about their data traffic process. This is a process that transports data from IoT devices into a data hub. For this we made the following main question for our research: “How can ENGIE offer transparency to its customers about the design and existence of the data access?”
Context
This project has to do with IT auditing and framework of standards. The research area is the data traffic between IoT devices, other sensors and the datahub. For this we will look at the design of this process and not the technical part. This is because we would not have enough security knowledge for this.
Results
We found out that there are some problems with internal communication. Employees do not know or don’t follow the policies that are set up by ENGIE. This is because they don’t really have an incentive to do so. We also found a few risks that we described in our audit rapport. These risks can be mitigated by fixing them so that ENGIE can be certified by ISO27001. Other risks that will not be mitigated by ISO27001 have gotten their own policies. These can be added to the policies from ENGIE. However they do need to work on getting their employees to follow them and give them a good incentive to follow the policies.
About the project group
For this project we have worked on it for 50% of the time, maybe more. We had other tasks and learning goals that we had to work on as well. Our groups consists of 3 ICT & B students some with previous IT studies.
For this project we first made an project initiation document. This showed our client what the products will be at the end of this project. Then we made a audit proposal for the data traffic process. This proposal was the executed and worked into a audit rapport with a research document.