Digital Trust Assessment

Security and protection from the very beginning—an increasingly automated process before digital processes are used in the Group.

Newspaper with the word "PRIVACY" in focus

Protecting the company's attack surface from vulnerabilities and ensuring a good level of data protection in the future are probably the two most important features of the Digital Trust Assessment (DTA). Every software, digital platform or application goes through this increasingly automated process before it can be used at Deutsche Telekom.  

The DTA brings together various aspects such as information security, data protection, secret protection and other regulatory requirements in a common procedure. It accompanies relevant projects from the idea to development and production to operation. 

Objectives:

  • Identify risks and relevant requirements early and transparently.
  • Guide project teams through the requirements relevant to their project.
  • Simplify implementation through standardized and already proven solutions as well as concrete assistance. 
  • Use existing information and technical test results as efficiently as possible and reduce manual effort.
  • Accelerate audits and decisions on a risk-based basis and involve technical experts in a targeted manner where necessary.

Just a few steps to safety and compliance

In contrast to previous approaches, the DTA is designed to reduce complexity for project teams. Existing information is reused and evaluated with the help of artificial intelligence. This prevents the repeated recording of standard information and thus saves time. It goes directly to the often individual, relevant requirements for the respective project. 

The outlined path of the process leads through the three phases: Design, Build and Run. 

In the design phase, the planned project is described and evaluated with regard to the individual risks. From this, the relevant security, data protection and compliance requirements are derived. At the same time, project teams are given orientation on suitable and already proven solution approaches. Before implementation, it is checked whether the planned solution design takes into account the essential requirements. 

In the build phase, the identified requirements are implemented in the digital solution. Concrete implementation instructions, proven procedures and technical support are available. Where possible, technical tests complement the assessment and create transparency about which requirements have already been met and where there is still a need for action.  

In the runphase, the security and compliance status of the digital solution remains transparent even after implementation. Available technical information and test results can be used to identify changes and possible need for action at an early stage. 

Approval processes in the design and build phase ensure that only projects that meet the relevant requirements from the individual compliance areas are put into operation. 

The DTA consistently pursues a risk-based approach: standardised and less critical projects can be processed with a high degree of automation. In the case of complex or high-risk projects, suitable experts are also involved. 

In this way, the DTA combines a high level of security and data protection with a simpler process, clear orientation and faster decisions along the entire life cycle of a digital solution.