{"id":154580,"date":"2025-02-24T19:45:22","date_gmt":"2025-02-24T17:45:22","guid":{"rendered":"https:\/\/jfrog.com\/blog\/ensuring-finma-compliance-with-jfrog\/"},"modified":"2025-06-23T11:12:44","modified_gmt":"2025-06-23T09:12:44","slug":"ensuring-finma-compliance-with-jfrog","status":"publish","type":"post","link":"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/","title":{"rendered":"FINMA-Compliance: DevSecOps-Strategien zur Absicherung des Schweizer Finanz\u00f6kosystems"},"content":{"rendered":"<p><img decoding=\"async\" class=\"alignnone size-full wp-image-148779\" src=\"https:\/\/media.jfrog.com\/wp-content\/uploads\/2025\/02\/24154010\/FINMA-Compliance_V02b_863x300.png\" alt=\"\" width=\"863\" height=\"300\" \/><\/p>\n<p>Die Eidgen\u00f6ssische Finanzmarktaufsicht (<a href=\"https:\/\/www.finma.ch\/de\/\">FINMA<\/a>) stellt strenge Anforderungen an in der Schweiz t\u00e4tige Finanzinstitute, um sicherzustellen, dass sie \u00fcber eine robuste Sicherheitsarchitektur und betriebliche Resilienz verf\u00fcgen. Die <a href=\"https:\/\/www.finma.ch\/de\/dokumentation\/finma-aufsichtsmitteilungen\/\">Richtlinien der FINMA<\/a> sind entscheidend f\u00fcr den Schutz sensibler Finanzdaten, die Risikominimierung und das Aufrechterhalten des Vertrauens in das Schweizer Finanz\u00f6kosystem. Die Sicherheit der Software-Lieferkette spielt eine zentrale Rolle bei der Einhaltung der Compliance-Vorgaben.<\/p>\n<p>Bei JFrog unterst\u00fctzen wir Unternehmen dabei, die Anforderungen der FINMA zu erf\u00fcllen, indem wir ihre Sicherheitsarchitektur st\u00e4rken, die <a href=\"https:\/\/jfrog.com\/de\/learn\/software-supply-chain\/\">Software-Lieferkette absichern<\/a> und sicherstellen, dass sie den geltenden Standards f\u00fcr Cybersicherheit und Risikomanagement entsprechen.<\/p>\n<h2>Welche Unternehmen m\u00fcssen den Anforderungen der FINMA entsprechen?<\/h2>\n<h3>Die FINMA-Compliance gilt f\u00fcr in der Schweiz ans\u00e4ssige Organisationen sowie f\u00fcr ausl\u00e4ndische Unternehmen, die Dienstleistungen im schweizerischen Finanzmarkt anbieten, dazu z\u00e4hlen:<\/h3>\n<ul>\n<li aria-level=\"1\"><b>Banken und Finanzinstitute: <\/b>Privatkunden-, Investment- und Privatbanken<\/li>\n<li aria-level=\"1\"><b>Versicherungsunternehmen:<\/b> Lebens-, Sach- und R\u00fcckversicherer<br \/>\nVerm\u00f6gensverwalter und Investmentfonds: Unternehmen, die Portfolios f\u00fcr institutionelle und private Investoren verwalten<\/li>\n<li aria-level=\"1\"><b>Anbieter f\u00fcr Finanzmarktinfrastruktur: <\/b>B\u00f6rsen, zentrale Wertpapierverwahrstellen und Zahlungssysteme<\/li>\n<li aria-level=\"1\"><b>Outsourcing-Partner:<\/b> Drittanbieter, die kritische IT-, Software- oder operative Dienstleistungen f\u00fcr regulierte Institute \u00fcbernehmen<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Ausl\u00e4ndische Unternehmen: <\/b><span style=\"font-weight: 400;\">Organisationen, die direkt Dienstleistungen im Schweizer Markt erbringen oder mit FINMA-regulierten Partnern zusammenarbeiten<span style=\"font-weight: 400;\"><br \/>\n<\/span><\/span><\/li>\n<\/ul>\n<h2>Was bedeutet FINMA-Compliance?<\/h2>\n<p>FINMA-Compliance bedeutet, den von der Eidgen\u00f6ssischen Finanzmarktaufsicht definierten Regulierungen zu folgen, um einen sicheren Betrieb, effektives Risikomanagement sowie hohe Standards bei Cybersicherheit, Stabilit\u00e4t und betrieblicher Zuverl\u00e4ssigkeit zu gew\u00e4hrleisten. Seit Januar 2025 ist die Einhaltung der FINMA-Vorgaben f\u00fcr alle Finanzinstitute, die im Schweizer Markt t\u00e4tig sind, verpflichtend \u2013 ein starker Fokus liegt dabei auf Sicherheitsma\u00dfnahmen und <a href=\"https:\/\/jfrog.com\/de\/learn\/devsecops\/\">DevSecOps-Praktiken<\/a>.<\/p>\n<p>Mit der zunehmenden Digitalisierung im Finanzwesen legt die FINMA verst\u00e4rkt Wert auf Cybersicherheit und die Integrit\u00e4t der Software-Lieferkette. Dies erfordert den Einsatz von DevSecOps-Praktiken, die Software-Artefakte absichern und kontinuierlich auf Schwachstellen \u00fcberwachen.<\/p>\n<h2>Zentrale Richtlinien zur Erreichung der FINMA-Compliance und Sicherung der Software-Lieferkette<\/h2>\n<p>Die wichtigsten Themenfelder, die zur Einhaltung der aktuellen Richtlinien ber\u00fccksichtigt werden m\u00fcssen:<\/p>\n<ol>\n<li aria-level=\"1\"><b>Governance und Risikomanagement:<\/b> Sicherheit muss in die Governance-Frameworks und DevOps-Prozesse integriert werden \u2013 f\u00fcr ein proaktives Risikomanagement und durchg\u00e4ngige Compliance im gesamten <a href=\"https:\/\/jfrog.com\/de\/learn\/sdlc\/\">Software-Lebenszyklus (SDLC)<\/a>.<\/li>\n<li aria-level=\"1\"><b>IT- und Cyber-Risiken:<\/b> Diese Risiken m\u00fcssen durch die Einbettung von Security in den SDLC reduziert werden \u2013 einschlie\u00dflich kontinuierlicher \u00dcberwachung, Bedrohungsanalysen und Schwachstellenmanagement.<\/li>\n<li aria-level=\"1\"><b>Inventarisierung und Risikoklassifizierung: <\/b>Eine zentral verwaltete Inventarliste aller Softwarekomponenten und Abh\u00e4ngigkeiten sollte gepflegt werden, inklusive Risikoklassifizierungen und empfohlener Sicherheitsma\u00dfnahmen auf Basis von Bedrohungsanalysen.<\/li>\n<li aria-level=\"1\"><b>Datenqualit\u00e4t f\u00fcr KI: <\/b>Die f\u00fcr KI-Systeme verwendeten Daten m\u00fcssen korrekt, repr\u00e4sentativ und sicher sein, um Schwachstellen, Verzerrungen und operationale Risiken zu vermeiden.<\/li>\n<li aria-level=\"1\"><b>Kontinuierliches Testen und Monitoring:<\/b> \u00dcberwachung und kontinuierliche Tests entlang der gesamten Software-Lieferkette sind essentiell f\u00fcr Sicherheit, Compliance und Performance-Stabilit\u00e4t.<\/li>\n<\/ol>\n<h2><img decoding=\"async\" class=\"alignnone size-full wp-image-148774\" src=\"https:\/\/media.jfrog.com\/wp-content\/uploads\/2025\/02\/24153956\/JFrog-FINMA-image1.png\" alt=\"\" width=\"810\" height=\"387\" \/><\/h2>\n<h2>Wie unterst\u00fctzt die JFrog-Plattform bei der FINMA-Compliance?<\/h2>\n<p>Die Einhaltung regulatorischer Vorgaben wie FINMA kann eine komplexe Herausforderung darstellen \u2013 insbesondere wenn <strong>Sicherheit \u00fcber DevOps-, MLOps- und Software-Supply-Chain-Prozesse hinweg<\/strong> gew\u00e4hrleistet werden muss. Ein Plattform-Ansatz unterst\u00fctzt Unternehmen dabei, Sicherheit, Risikomanagement und Compliance nahtlos in den gesamten Softwareentwicklungszyklus zu integrieren.<\/p>\n<p>Wie k\u00f6nnen zentrale Herausforderungen mithilfe der<a href=\"https:\/\/jfrog.com\/de\/platform\/\"> JFrog-Plattform<\/a> bew\u00e4ltigt werden? Hier die wichtigsten Punkte:<\/p>\n<h3>Governance und Risikomanagement<\/h3>\n<p><b>Herausforderung:<\/b><br \/>\nDie Integration von Security in Governance-Frameworks sowie die Gew\u00e4hrleistung kontinuierlicher Compliance \u00fcber verteilte <a href=\"https:\/\/jfrog.com\/de\/learn\/devops\/\">DevOps<\/a>-Teams hinweg ist anspruchsvoll \u2013 insbesondere angesichts komplexer Software-Lieferketten.<\/p>\n<p><b>Plattform-L\u00f6sung:<\/b><\/p>\n<ul>\n<li aria-level=\"1\"><a href=\"https:\/\/jfrog.com\/de\/rlm\/\">Release Lifecycle Management (RLM)<\/a>: Bietet volle Transparenz und Kontrolle \u00fcber den gesamten Software-Lebenszyklus. Governance-Richtlinien lassen sich in jeder Phase durchsetzen.<\/li>\n<li aria-level=\"1\"><a href=\"https:\/\/jfrog.com\/blog\/evidence-collection-with-jfrog\/\">Beweismittelmanagement (\u201cEvidence Management\u201d)<\/a>: Dokumentiert Builds, Artefakte und Deployments l\u00fcckenlos \u2013 f\u00fcr pr\u00fcfungssichere Nachweise im Rahmen der Compliance.<\/li>\n<\/ul>\n<h3>IT- und Cyber-Risiken<\/h3>\n<p><b>Herausforderung:<\/b><br \/>\nCyberrisiken k\u00f6nnen in jeder Phase des SDLC auftreten \u2013 vor allem durch Open-Source-Komponenten und externe Abh\u00e4ngigkeiten. Kontinuierliche Sicherheits\u00fcberwachung ist entscheidend.<\/p>\n<p><b>Plattform-L\u00f6sung:<\/b><\/p>\n<ul>\n<li aria-level=\"1\"><a href=\"https:\/\/jfrog.com\/de\/curation\/\">JFrog Curation<\/a>: Blockiert automatisch nicht konforme oder sch\u00e4dliche Open-Source-Pakete, bevor sie in die Pipeline gelangen.<\/li>\n<li aria-level=\"1\"><a href=\"https:\/\/jfrog.com\/de\/blog\/announcing-jfrog-runtime-protect-your-applications-with-fast-discovery-and-remediation\/\">JFrog Runtime<\/a>: Sch\u00fctzt Laufzeitumgebungen in Echtzeit und erkennt sowie behebt Schwachstellen unmittelbar.<\/li>\n<\/ul>\n<h3>Inventarisierung und Risikoklassifizierung<\/h3>\n<p><b>Herausforderung:<\/b><br \/>\nEine zentrale, vollst\u00e4ndige \u00dcbersicht \u00fcber alle Softwarekomponenten und deren Risiken ist unerl\u00e4sslich, um Sicherheitsma\u00dfnahmen zu priorisieren und regulatorische Anforderungen zu erf\u00fcllen.<\/p>\n<p><b>Plattform-L\u00f6sung:<\/b><\/p>\n<ul>\n<li aria-level=\"1\"><a href=\"https:\/\/jfrog.com\/de\/artifactory\/\">JFrog Artifactory<\/a>: Zentrale Repository-L\u00f6sung mit vollst\u00e4ndiger Nachverfolgbarkeit aller Komponenten \u00fcber s\u00e4mtliche SDLC-Phasen hinweg.<\/li>\n<li aria-level=\"1\"><a href=\"https:\/\/jfrog.com\/de\/advanced-security\/\">JFrog Advanced Security<\/a>: Bietet eine<a href=\"https:\/\/jfrog.com\/de\/webinar\/container-contextual-analysis-jfrog-advanced-security-workshop\/\"> kontextbasierte Analyse<\/a> zur Priorisierung von Schwachstellen nach tats\u00e4chlichem Risiko \u2013 reduziert Falschmeldungen und fokussiert auf kritische Bedrohungen.<\/li>\n<\/ul>\n<h3>Datenqualit\u00e4t f\u00fcr KI<\/h3>\n<p><b>Herausforderung:<\/b><br \/>\nUnvollst\u00e4ndige oder nicht verifizierte Daten f\u00fchren zu fehlerhaften KI-Modellen, Verzerrungen und Sicherheitsl\u00fccken \u2013 Themen, die FINMA explizit im Kontext von AI-Governance adressiert.<\/p>\n<p><b>Plattform-L\u00f6sung:<\/b><\/p>\n<ul>\n<li aria-level=\"1\"><a href=\"https:\/\/jfrog.com\/de\/mlops\/\">JFrog ML<\/a>: Ende-zu-Ende-Management von KI-Modellen und Datenpipelines \u2013 mit Fokus auf vertrauensw\u00fcrdige, gesicherte Daten f\u00fcr Training und Deployment.<\/li>\n<li aria-level=\"1\"><a href=\"https:\/\/jfrog.com\/de\/blog\/jfrog-brings-devops-best-practices-to-ml-development\/\">Scannen von AI-Repositories<\/a> (z.\u202fB. Hugging Face): Sch\u00fctzt vor <a href=\"https:\/\/jfrog.com\/de\/learn\/devsecops\/backdoor-attack\/\">Backdoor-Angriffen<\/a> und kompromittierten Modellen durch Sicherheitspr\u00fcfung externer Quellen.<\/li>\n<\/ul>\n<h3>Kontinuierliches Testen und Monitoring<\/h3>\n<p><b>Herausforderung:<\/b><br \/>\nCompliance und Sicherheit m\u00fcssen \u00fcber den gesamten Softwarelebenszyklus hinweg kontinuierlich gepr\u00fcft und sichergestellt werden.<\/p>\n<p><b>Plattform-L\u00f6sung:<\/b><\/p>\n<ul>\n<li aria-level=\"1\">Automatisiertes <a href=\"https:\/\/jfrog.com\/de\/learn\/devsecops\/vulnerability-scanning\/\">Schwachstellenscanning<\/a> und Policy Enforcement: Sicherheitsfunktionen von JFrog sorgen f\u00fcr permanente Compliance-Pr\u00fcfung in Entwicklung und Produktion.<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\">Kontinuierliches Monitoring aller Artefakte und KI-Modelle: Erkennt Anomalien, verhindert Datenverf\u00e4lschung und minimiert Betriebsrisiken durch KI-Bias oder Drift.<br \/>\n<span style=\"font-weight: 400;\"><br \/>\n<\/span><\/li>\n<\/ul>\n<h2>JFrogs Plattform-Ansatz zur FINMA-Compliance<\/h2>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-148775\" src=\"https:\/\/media.jfrog.com\/wp-content\/uploads\/2025\/02\/24153959\/JFrog-Software-Supply-Chain-Platform1.png\" alt=\"\" width=\"5334\" height=\"3000\" \/><\/p>\n<p style=\"text-align: center;\"><em>Die JFrog-Plattform bietet Sicherheits- und Compliance-Pr\u00fcfungen in jeder Phase des SDLC<\/em><\/p>\n<p>Durch den Einsatz eines einheitlichen Plattform-Ansatzes k\u00f6nnen Unternehmen die Komplexit\u00e4t reduzieren, die Transparenz erh\u00f6hen und Security nahtlos in ihre DevOps-, <a href=\"https:\/\/jfrog.com\/de\/learn\/mlops\/\">MLOps<\/a>&#8211; und Sicherheitspraktiken integrieren. Sicherheit und Compliance werden dadurch nicht als nachgelagerte Aufgaben betrachtet, sondern sind von Anfang an fester Bestandteil des Entwicklungsprozesses.<\/p>\n<p>Dieser Ansatz entspricht genau dem Fokus der FINMA auf Governance, Risikomanagement und betriebliche Resilienz. Er erm\u00f6glicht es Finanzinstituten, schnell auf neue Bedrohungen zu reagieren und gleichzeitig auditf\u00e4hig zu bleiben \u2013 durch Compliance-Pr\u00fcfungen, die von Aufsichtsbeh\u00f6rden anerkannt werden.<\/p>\n<p>Erleben Sie selbst, wie JFrog bei der Einhaltung der aktuellen FINMA-Richtlinien unterst\u00fctzt \u2013 mit einer interaktiven <a href=\"https:\/\/jfrog.com\/de\/try-generic\/\">Online-Tour <\/a>oder einem pers\u00f6nlichen <a href=\"https:\/\/jfrog.com\/de\/start-free-demo\/\">Demo-Termin<\/a> nach Wunsch.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Die Eidgen\u00f6ssische Finanzmarktaufsicht (FINMA) stellt strenge Anforderungen an in der Schweiz t\u00e4tige Finanzinstitute, um sicherzustellen, dass sie \u00fcber eine robuste Sicherheitsarchitektur und betriebliche Resilienz verf\u00fcgen. Die Richtlinien der FINMA sind entscheidend f\u00fcr den Schutz sensibler Finanzdaten, die Risikominimierung und das Aufrechterhalten des Vertrauens in das Schweizer Finanz\u00f6kosystem. Die Sicherheit der Software-Lieferkette spielt eine zentrale Rolle &hellip;<\/p>\n","protected":false},"author":590,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[10157],"tags":[10837,10838,10839,10840,10841,10842],"class_list":["post-154580","post","type-post","status-publish","format-standard","hentry","category-sicherheit-und-devsecops","tag-cyber-security-de","tag-finma-de","tag-finance-de","tag-cyber-regulations-de","tag-software-regulations-de","tag-compliance-de"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v22.6 (Yoast SEO v22.6) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Ensuring FINMA Compliance with JFrog<\/title>\n<meta name=\"description\" content=\"The Swiss Financial Market Supervisory Authority (FINMA) has strict requirements for financial institutions to ensure they have robust security and maintain operational resilience.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/jfrog.com\/de\/wp-json\/wp\/v2\/posts\/154580\" \/>\n<meta property=\"og:locale\" content=\"de_DE\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"FINMA-Compliance: DevSecOps-Strategien zur Absicherung des Schweizer Finanz\u00f6kosystems\" \/>\n<meta property=\"og:description\" content=\"The Swiss Financial Market Supervisory Authority (FINMA) has strict requirements for financial institutions to ensure they have robust security and maintain operational resilience.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/\" \/>\n<meta property=\"og:site_name\" content=\"JFrog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/artifrog\" \/>\n<meta property=\"article:published_time\" content=\"2025-02-24T17:45:22+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-23T09:12:44+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/media.jfrog.com\/wp-content\/uploads\/2025\/02\/24153943\/FINMA-Compliance_V02b_1200x628-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"628\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"drewt\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@jfrog\" \/>\n<meta name=\"twitter:site\" content=\"@jfrog\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"drewt\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/\"},\"author\":{\"name\":\"drewt\",\"@id\":\"https:\/\/jfrog.com\/de\/#\/schema\/person\/c84b32acf61c0b7c85a306cb03697b28\"},\"headline\":\"FINMA-Compliance: DevSecOps-Strategien zur Absicherung des Schweizer Finanz\u00f6kosystems\",\"datePublished\":\"2025-02-24T17:45:22+00:00\",\"dateModified\":\"2025-06-23T09:12:44+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/\"},\"wordCount\":968,\"publisher\":{\"@id\":\"https:\/\/jfrog.com\/de\/#organization\"},\"image\":{\"@id\":\"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/jfrog.com\/wp-content\/uploads\/2025\/02\/FINMA-Compliance_V02b_863x300.png\",\"keywords\":[\"cyber security\",\"FINMA\",\"finance\",\"cyber regulations\",\"Software Regulations\",\"compliance\"],\"articleSection\":[\"Sicherheit und DevSecOps\"],\"inLanguage\":\"de-DE\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/\",\"url\":\"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/\",\"name\":\"Ensuring FINMA Compliance with JFrog\",\"isPartOf\":{\"@id\":\"https:\/\/jfrog.com\/de\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/jfrog.com\/wp-content\/uploads\/2025\/02\/FINMA-Compliance_V02b_863x300.png\",\"datePublished\":\"2025-02-24T17:45:22+00:00\",\"dateModified\":\"2025-06-23T09:12:44+00:00\",\"description\":\"The Swiss Financial Market Supervisory Authority (FINMA) has strict requirements for financial institutions to ensure they have robust security and maintain operational resilience.\",\"breadcrumb\":{\"@id\":\"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/#breadcrumb\"},\"inLanguage\":\"de-DE\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"de-DE\",\"@id\":\"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/#primaryimage\",\"url\":\"https:\/\/jfrog.com\/wp-content\/uploads\/2025\/02\/FINMA-Compliance_V02b_863x300.png\",\"contentUrl\":\"https:\/\/jfrog.com\/wp-content\/uploads\/2025\/02\/FINMA-Compliance_V02b_863x300.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/jfrog.com\/de\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"FINMA-Compliance: DevSecOps-Strategien zur Absicherung des Schweizer Finanz\u00f6kosystems\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/jfrog.com\/de\/#website\",\"url\":\"https:\/\/jfrog.com\/de\/\",\"name\":\"JFrog\",\"description\":\"Deliver Trusted Software Releases at Speed and Scale\",\"publisher\":{\"@id\":\"https:\/\/jfrog.com\/de\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/jfrog.com\/de\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"de-DE\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/jfrog.com\/de\/#organization\",\"name\":\"JFrog\",\"url\":\"https:\/\/jfrog.com\/de\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"de-DE\",\"@id\":\"https:\/\/jfrog.com\/de\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/speedmedia2.jfrog.com\/08612fe1-9391-4cf3-ac1a-6dd49c36b276\/media.jfrog.com\/wp-content\/uploads\/2025\/05\/27095207\/Logo.svg\",\"contentUrl\":\"https:\/\/speedmedia2.jfrog.com\/08612fe1-9391-4cf3-ac1a-6dd49c36b276\/media.jfrog.com\/wp-content\/uploads\/2025\/05\/27095207\/Logo.svg\",\"width\":74,\"height\":73,\"caption\":\"JFrog\"},\"image\":{\"@id\":\"https:\/\/jfrog.com\/de\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/artifrog\",\"https:\/\/x.com\/jfrog\",\"https:\/\/www.linkedin.com\/company\/455737\",\"https:\/\/www.youtube.com\/channel\/UCh2hNg76zo3d1qQqTWIQxDg\",\"https:\/\/www.wikidata.org\/wiki\/Q98608948\"],\"description\":\"We set out on our Liquid Software journey in 2008, with the mission to transform the way enterprises manage and release software updates. The world expects software to update continuously, securely, non-intrusively and without user intervention. This hyper-connected experience can only be enabled by automation with an end-to-end DevOps platform and a binary-centric focus. With this in mind, we\u2019ve developed the JFrog Platform, ushering in a new era of DevOps and DevSecOps standards that power continuous updates. More than a decade after our founding, with thousands of customers and millions of users globally, JFrog has become the \u201cDatabase of DevOps\u201d and the de-facto standard in release and update management.\",\"legalName\":\"Jfrog, Inc.\",\"numberOfEmployees\":{\"@type\":\"QuantitativeValue\",\"minValue\":\"1001\",\"maxValue\":\"5000\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/jfrog.com\/de\/#\/schema\/person\/c84b32acf61c0b7c85a306cb03697b28\",\"name\":\"drewt\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"de-DE\",\"@id\":\"https:\/\/jfrog.com\/de\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/a9566b6b2e5e2e34deeb94dfeae460f70d7c7d08606c66ebb53f94a07386253c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/a9566b6b2e5e2e34deeb94dfeae460f70d7c7d08606c66ebb53f94a07386253c?s=96&d=mm&r=g\",\"caption\":\"drewt\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Ensuring FINMA Compliance with JFrog","description":"The Swiss Financial Market Supervisory Authority (FINMA) has strict requirements for financial institutions to ensure they have robust security and maintain operational resilience.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/jfrog.com\/de\/wp-json\/wp\/v2\/posts\/154580","og_locale":"de_DE","og_type":"article","og_title":"FINMA-Compliance: DevSecOps-Strategien zur Absicherung des Schweizer Finanz\u00f6kosystems","og_description":"The Swiss Financial Market Supervisory Authority (FINMA) has strict requirements for financial institutions to ensure they have robust security and maintain operational resilience.","og_url":"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/","og_site_name":"JFrog","article_publisher":"https:\/\/www.facebook.com\/artifrog","article_published_time":"2025-02-24T17:45:22+00:00","article_modified_time":"2025-06-23T09:12:44+00:00","og_image":[{"width":1200,"height":628,"url":"https:\/\/media.jfrog.com\/wp-content\/uploads\/2025\/02\/24153943\/FINMA-Compliance_V02b_1200x628-1.png","type":"image\/png"}],"author":"drewt","twitter_card":"summary_large_image","twitter_creator":"@jfrog","twitter_site":"@jfrog","twitter_misc":{"Written by":"drewt","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/#article","isPartOf":{"@id":"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/"},"author":{"name":"drewt","@id":"https:\/\/jfrog.com\/de\/#\/schema\/person\/c84b32acf61c0b7c85a306cb03697b28"},"headline":"FINMA-Compliance: DevSecOps-Strategien zur Absicherung des Schweizer Finanz\u00f6kosystems","datePublished":"2025-02-24T17:45:22+00:00","dateModified":"2025-06-23T09:12:44+00:00","mainEntityOfPage":{"@id":"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/"},"wordCount":968,"publisher":{"@id":"https:\/\/jfrog.com\/de\/#organization"},"image":{"@id":"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/#primaryimage"},"thumbnailUrl":"https:\/\/jfrog.com\/wp-content\/uploads\/2025\/02\/FINMA-Compliance_V02b_863x300.png","keywords":["cyber security","FINMA","finance","cyber regulations","Software Regulations","compliance"],"articleSection":["Sicherheit und DevSecOps"],"inLanguage":"de-DE"},{"@type":"WebPage","@id":"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/","url":"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/","name":"Ensuring FINMA Compliance with JFrog","isPartOf":{"@id":"https:\/\/jfrog.com\/de\/#website"},"primaryImageOfPage":{"@id":"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/#primaryimage"},"image":{"@id":"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/#primaryimage"},"thumbnailUrl":"https:\/\/jfrog.com\/wp-content\/uploads\/2025\/02\/FINMA-Compliance_V02b_863x300.png","datePublished":"2025-02-24T17:45:22+00:00","dateModified":"2025-06-23T09:12:44+00:00","description":"The Swiss Financial Market Supervisory Authority (FINMA) has strict requirements for financial institutions to ensure they have robust security and maintain operational resilience.","breadcrumb":{"@id":"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/#breadcrumb"},"inLanguage":"de-DE","potentialAction":[{"@type":"ReadAction","target":["https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/"]}]},{"@type":"ImageObject","inLanguage":"de-DE","@id":"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/#primaryimage","url":"https:\/\/jfrog.com\/wp-content\/uploads\/2025\/02\/FINMA-Compliance_V02b_863x300.png","contentUrl":"https:\/\/jfrog.com\/wp-content\/uploads\/2025\/02\/FINMA-Compliance_V02b_863x300.png"},{"@type":"BreadcrumbList","@id":"https:\/\/jfrog.com\/de\/blog\/ensuring-finma-compliance-with-jfrog\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/jfrog.com\/de\/"},{"@type":"ListItem","position":2,"name":"FINMA-Compliance: DevSecOps-Strategien zur Absicherung des Schweizer Finanz\u00f6kosystems"}]},{"@type":"WebSite","@id":"https:\/\/jfrog.com\/de\/#website","url":"https:\/\/jfrog.com\/de\/","name":"JFrog","description":"Deliver Trusted Software Releases at Speed and Scale","publisher":{"@id":"https:\/\/jfrog.com\/de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/jfrog.com\/de\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"de-DE"},{"@type":"Organization","@id":"https:\/\/jfrog.com\/de\/#organization","name":"JFrog","url":"https:\/\/jfrog.com\/de\/","logo":{"@type":"ImageObject","inLanguage":"de-DE","@id":"https:\/\/jfrog.com\/de\/#\/schema\/logo\/image\/","url":"https:\/\/speedmedia2.jfrog.com\/08612fe1-9391-4cf3-ac1a-6dd49c36b276\/media.jfrog.com\/wp-content\/uploads\/2025\/05\/27095207\/Logo.svg","contentUrl":"https:\/\/speedmedia2.jfrog.com\/08612fe1-9391-4cf3-ac1a-6dd49c36b276\/media.jfrog.com\/wp-content\/uploads\/2025\/05\/27095207\/Logo.svg","width":74,"height":73,"caption":"JFrog"},"image":{"@id":"https:\/\/jfrog.com\/de\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/artifrog","https:\/\/x.com\/jfrog","https:\/\/www.linkedin.com\/company\/455737","https:\/\/www.youtube.com\/channel\/UCh2hNg76zo3d1qQqTWIQxDg","https:\/\/www.wikidata.org\/wiki\/Q98608948"],"description":"We set out on our Liquid Software journey in 2008, with the mission to transform the way enterprises manage and release software updates. The world expects software to update continuously, securely, non-intrusively and without user intervention. This hyper-connected experience can only be enabled by automation with an end-to-end DevOps platform and a binary-centric focus. With this in mind, we\u2019ve developed the JFrog Platform, ushering in a new era of DevOps and DevSecOps standards that power continuous updates. More than a decade after our founding, with thousands of customers and millions of users globally, JFrog has become the \u201cDatabase of DevOps\u201d and the de-facto standard in release and update management.","legalName":"Jfrog, Inc.","numberOfEmployees":{"@type":"QuantitativeValue","minValue":"1001","maxValue":"5000"}},{"@type":"Person","@id":"https:\/\/jfrog.com\/de\/#\/schema\/person\/c84b32acf61c0b7c85a306cb03697b28","name":"drewt","image":{"@type":"ImageObject","inLanguage":"de-DE","@id":"https:\/\/jfrog.com\/de\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/a9566b6b2e5e2e34deeb94dfeae460f70d7c7d08606c66ebb53f94a07386253c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a9566b6b2e5e2e34deeb94dfeae460f70d7c7d08606c66ebb53f94a07386253c?s=96&d=mm&r=g","caption":"drewt"}}]}},"_links":{"self":[{"href":"https:\/\/jfrog.com\/de\/wp-json\/wp\/v2\/posts\/154580","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jfrog.com\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jfrog.com\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jfrog.com\/de\/wp-json\/wp\/v2\/users\/590"}],"replies":[{"embeddable":true,"href":"https:\/\/jfrog.com\/de\/wp-json\/wp\/v2\/comments?post=154580"}],"version-history":[{"count":3,"href":"https:\/\/jfrog.com\/de\/wp-json\/wp\/v2\/posts\/154580\/revisions"}],"predecessor-version":[{"id":154583,"href":"https:\/\/jfrog.com\/de\/wp-json\/wp\/v2\/posts\/154580\/revisions\/154583"}],"wp:attachment":[{"href":"https:\/\/jfrog.com\/de\/wp-json\/wp\/v2\/media?parent=154580"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jfrog.com\/de\/wp-json\/wp\/v2\/categories?post=154580"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jfrog.com\/de\/wp-json\/wp\/v2\/tags?post=154580"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}