Menü aufrufen
Toggle preferences menu
Persönliches Menü aufrufen
Nicht angemeldet
Ihre IP-Adresse wird öffentlich sichtbar sein, wenn Sie Änderungen vornehmen.
  • Treat deviations directly in the analysis. The review is the central point of risk identification and treatment. Provide detected deviations already here with measures (for elimination) and controls (for monitoring). In this way, deviation, measure and control can be cleanly assigned to the identified risk. If you additionally link the review object with a structure element (e.g. an application), this information also appears in its detail view.
  • Reassessment instead of new assessment. Survey the actual state regularly via a reassessment instead of creating a new analysis each time. In this way old answers and justifications remain visible and the development of a review object becomes traceable.
  • Assess review objects multiple times and name them meaningfully. A review object can occur several times in an analysis. Example: The IT-Grundschutz compendium contains the module "Web applications". If you operate several web applications, answer this module per application and link it with the respective application. Tip: Assign meaningful names such as "Web application 123_Cloud" – in this way you find the review objects easily via the search during reassessments.
  • Prepare self assessment correctly. A self assessment can only be completed if at least one interview partner is stored. The interview partner is also a mandatory field as soon as the review leaves the Draft status.
  • Check before deleting. When deleting a review, the review objects created via it and deviations already assigned to risks are also lost. Completed reviews cannot be deleted.