09.03.2013 Views

Munich Re Group Annual Report 2006 (PDF, 1.8

Munich Re Group Annual Report 2006 (PDF, 1.8

Munich Re Group Annual Report 2006 (PDF, 1.8

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Munich</strong> <strong>Re</strong> <strong>Group</strong> <strong>Annual</strong> <strong>Re</strong>port <strong>2006</strong> Management report_Other success factors<br />

physically disabled colleagues – a project supported by the<br />

company’s own foundation, Fundación Integral. Inspired<br />

by this idea, ERGO Hestia in Poland has set up a similar<br />

foundation.<br />

Social responsibility is likewise practised by Hamburg-<br />

Mannheimer with its foundation Jugend & Zukunft, which<br />

awarded prizes in <strong>2006</strong> for the first time. Under the motto<br />

“Fußball bewegt” (”Football moves”) it honoured various<br />

initiatives that bring young people together using sport as<br />

a medium of integration.<br />

IT processes<br />

Information security<br />

<strong>Munich</strong> <strong>Re</strong> ensures the security of all its data, computers<br />

and networks worldwide. IT security in primary insurance<br />

and reinsurance is organised in separate, but individually<br />

effective structures.<br />

At the top of our security pyramid in the reinsurance<br />

group is the IS Office, which defines uniform standards<br />

and guidelines applied by all our companies globally. It is<br />

also responsible for information-security crisis management<br />

and for quality assurance in the enforcement of the<br />

relevant directives. In addition, it instructs our Security<br />

Centre of Competence in Toronto, whose functions include<br />

testing the IT infrastructure of the reinsurance group and<br />

central IT applications for weaknesses and possible security<br />

risks. We attach great importance to the security training<br />

of all our staff.<br />

<strong>Re</strong>gular external audits have confirmed that <strong>Munich</strong><br />

<strong>Re</strong>’s information security is at a high level. However, given<br />

that we see security as a process rather than a state, we are<br />

constantly refining our strategies and standards as part of<br />

our information risk management. This process is geared<br />

both to the actual risks and to ways of minimising them in<br />

order to support <strong>Munich</strong> <strong>Re</strong>’s business operations. The<br />

recommended measures are carefully weighed up and<br />

taken into account in the security architecture, which not<br />

only describes the technical and organisational aspects<br />

but also includes risks related to the “human factor” in the<br />

broadest sense.<br />

However, the security organisation does not just concern<br />

itself with protective measures. It also acts as a con-<br />

sultant for the divisional units in jointly assessing information<br />

security risks at potential clients. To this end, it has<br />

delegated a permanent representative to the Information<br />

Technology Topic Network and carries out or partners<br />

information risk assessments.<br />

ERGO’s IT security is part of our cross-corporate IT<br />

security management, which embraces four levels: security<br />

policy, guidelines, concepts and technical implementation.<br />

<strong>Re</strong>sponsibility for the management of information<br />

security in the ERGO <strong>Group</strong> lies with the IT Security Officer,<br />

who is supported by the IT Security Management Board – a<br />

strategy and controlling body.<br />

ERGO’s security management is being continually<br />

improved and extended with a view to gearing it to international<br />

standards – we are aiming for certification to<br />

ISO 27001 by 2009. We are also preparing for the developments<br />

of Solvency II and the requirements of ISO 27001,<br />

which go beyond the basic protection demanded by the<br />

German Federal Office for Information Security, by building<br />

up an information security management system in conjunction<br />

with operational risk management in the IT sector.<br />

This involves investigating all the main points of IT security,<br />

analysing the risks identified in their entirety, and<br />

putting in place security measures where there is a need<br />

for protection.<br />

IT Security Management also supports risks analyses<br />

for future strategic and operational projects in order to<br />

safeguard the ERGO <strong>Group</strong>’s assets long term.<br />

Gloria<br />

With our reinsurance platform Global <strong>Re</strong>insurance Application<br />

(Gloria), we are providing the reinsurance group<br />

with a consistent data basis and an integrated system for<br />

all business-relevant core processes. Building on various<br />

SAP modules, we are thereby harmonising the business<br />

processes in our reinsurance, not only enhancing the quality<br />

and efficiency of individual process steps – such as<br />

underwriting, claims and accounting – but also improving<br />

the analysis, management and administration of our reinsurance<br />

business as a whole. The harmonisation of all core<br />

business processes will also serve our global risk management,<br />

which will have extensive data available even more<br />

quickly.<br />

109

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!