18.06.2020

Finance Business Next

What needs to be considered when operating software with regard to BAIT?

18.06.2020  |  Philipp Oberleitner

BAIT stands for the banking supervisory requirementsfor IT and serves to protect companies from potential IT risks and damage.

In this article, we shed light on what should be considered during installation and operation. A distinction must be made between the integration of the application into the IT infrastructure and its operation.

What is the difference between integrating and operating the application?

After the technical setup (i.e. the installation or upgrade of the software and any extensions), a compliance-compliant authorization system must be set up or updated, activated and then continuously maintained. This means that the application must be set up accordingly and, for example, technically secured in compliance with the need-to-know principle and applicable authorization regulations.

When integrating into the infrastructure, the focus is primarily on protection against attacks and risks from outside. This involves monitoring risks from external access and data exchange with external services and establishing protective measures. The documentation, logging and traceability of such measures is an important requirement.

How can I imagine the process?

Software manufacturers offer a solid foundation with their software - as does NAVAX. With HENRI for Leasing and HENRI for Factoring, we offer companies a solution with a comprehensive standard that can be individually adapted to the customer's needs. This enables the technical safeguarding of applicable competence rules and the reduction of operational risks. Implementing a seamless security concept is the responsibility of the financial services institution. HENRI makes it possible for authorized employees or key users at the financial services provider to independently define new features using the integrated authorization and workflow control. Among other things, authorizations in the application can be adapted to new requirements, changes in business processes can be mapped in the system with the help of workflow control and new employees can be guided through the system in the best possible way with simple, program-guided process support.

Who is responsible for IT security?

The data center operator or financial services institution is responsible for IT security. As already described in the first part of our blog series, the quality of our software development is verified by relevant certifications and regular audits. NAVAX supports key users with the setup, rollout of defined processes and implementation. As a manufacturer, we develop the software in accordance with the applicable regulations and offer a documented standard that can also be individually extended as required.

This gives customers the opportunity to check whether the software complies with the processes and regulations that apply to them or whether individual adjustments are required.

According to the new BAIT, a "SOC" (Security Operations Center) must be established, which is responsible for observing IT processes, monitoring irregularities and preventing risks. Our application supports the SOC through the integrated tracking of data as well as the logging and historization of processes. In this way, we provide a basis for evaluating and interpreting relevant information.

Good to know! What else do I need to consider during operation?

We support our customers before, during and after the software goes live - teamwork at eye level. Authorized key users are able to make relevant settings in the system themselves. This significantly increases flexibility for ongoing operations.

We supply the basic and technical equipment - the technical adjustment of the system is carried out by our customers. This means that customers break the system down to their own requirements. We believe that specialist knowledge and technical affinity are particularly important when it comes to setting up and implementing new requirements.

Communication is the be-all and end-all of every software implementation and every project. Customers are assigned specialist contact persons internally - the key users. These in turn support the application, receive and catalyze the requirements. As soon as this step is complete, the requirements can be passed on to us. Requests are submitted in the form of tickets via our customer portal. Our consulting team checks the requests, advises the customer and takes care of the next steps.

Conclusion

We offer standard processes, but these are customized to the customer's needs via the customer's key users and are therefore tailored to the customer's business. In short, we provide a basis that is easy to set up for your needs and is always up to date and future-proof with Microsoft Dynamics 365 Business Central. This reduces risks as far as possible and ensures that nothing stands in the way of BAIT-compliant software use.

Philipp Oberleitner

CEO

Philipp Oberleitner is the CEO of NAVAX Software and has been with the company for about 25 years. He has an in-depth understanding of the needs of financial service providers and NAVAX’s solutions, and combines many years of industry expertise with a keen eye for innovative, future-proof software solutions.

More from Philipp Oberleitner