
Athlon Germany GmbH is a leading company in the field of fleet management and mobility solutions, headquartered in Germany. As part of Mercedes-Benz Mobility AG, the company offers its customers in more than 20 countries comprehensive services for the efficient management of company vehicles and the promotion of sustainable mobility. Athlon Germany’s services cover the entire spectrum of fleet management, including vehicle procurement, financing, maintenance, repairs, insurance, and more. The company places great emphasis on process and cost optimization as well as environmental considerations. Athlon Germany is strongly committed to sustainability and supports companies in transitioning to more environmentally friendly fleet options such as electric vehicles and alternative powertrains.
Athlon Germany is distinguished by its many years of experience and expertise, which enable it to offer customized solutions for companies of various sizes and across different industries. The company relies on innovative technologies and digital platforms to ensure a seamless and user-friendly experience for its customers.
The implementation of VASGARD/IAN aims to strengthen information security at Athlon Germany and enable an efficient process for handling auditors’ inquiries during the annual financial statement audit.
This was implemented based on the following guiding principles:
Assessment and Evaluation
The process began with a comprehensive assessment of Athlon Germany’s current status with regard to BAIT (Banking Supervisory Requirements for Information Technology) and, consequently, the ISMS (Information Security Management System) in accordance with ISO 27001. A detailed analysis was conducted to identify the strengths and weaknesses of the existing structures.
Visualization of the Impact Chain
The impact chains for central systems are visualized in the reporting. This provides a clear overview at all times of the various interrelationships between processes, applications, and IT systems within the company.
Implementation of Information Security Risk Management
An information security risk management system was introduced, based on the results of a security needs assessment. This approach enables the targeted identification and assessment of risks to processes and IT systems.
Elimination of Duplicate Requirements
By combining corporate guidelines and regulatory requirements, a clear structure was created to avoid duplication in security requirements. This increases the efficiency of implementation and reporting.
Reporting to the Auditing Firm
The results of the implementation were presented in clearly structured reports for the auditing firm. This includes a comprehensive overview of the security needs assessments, the resulting risk assessments, and the improvements achieved. The reports are designed to facilitate the auditors’ review and evaluation of information security during the annual financial statement audit. All reports can be generated at the click of a button, with no effort required on the part of the ISB (Information Security Officer).
Sustainability and Updates
The results obtained can be easily reused for future audits. Through regular updates and adjustments to changing conditions, the information security system remains up to date at all times. As a result, the internal effort required for the most recent annual financial statement audit amounted to less than one week.
Conclusion
The clear structure, elimination of duplicate requirements, and visualization of the chain of effects contribute to optimized implementation, while strengthening the ISB’s role and ensuring the sustainability of the measures guarantee long-term security.
Key Figures
- VASGARD/IAN maps approximately 2,500 information assets
- Implementation of two apps