Menü aufrufen
Toggle preferences menu
Persönliches Menü aufrufen
Nicht angemeldet
Ihre IP-Adresse wird öffentlich sichtbar sein, wenn Sie Änderungen vornehmen.

HITGuard Release Jänner 2021/en: Unterschied zwischen den Versionen

Aus HITGuard User Guide
Sala (Diskussion | Beiträge)
Die Seite wurde neu angelegt: „left <br clear=all> In the graph, the requirements from the protection needs analyses are displayed on the edges between the or…“
Sala (Diskussion | Beiträge)
Die Seite wurde neu angelegt: „Instructions on how to perform data imports can be found here in our documentation.“
 
(43 dazwischenliegende Versionen desselben Benutzers werden nicht angezeigt)
Zeile 61: Zeile 61:
[[Datei:RN Jänner2021 8.png|left]]
[[Datei:RN Jänner2021 8.png|left]]
<br clear=all>
<br clear=all>
Die Ressourcen selbst zeigen in einer grauen Blase jeweils z.B. für die RTO-Erfüllung die „Netto Wiederherstellzeit“ mit einem „N“ der Ressource selbst sowie die „Brutto Wiederherstellzeit“ mit einem „B“ für die summierte Wiederherstellzeit der Ressourcenkette inkl. des jeweiligen Knotens.


Das abgebildete Beispiel zeigt die RTO-Erfüllung. Die Logik für die RPO-Erfüllung ist sehr ähnlich, mit dem Unterschied, dass die Backupzeiten für die gesamte Ressourcenkette nicht summiert werden, sondern hier im Bruttowert immer die höchste Wiederherstellungsdauer einer Ressource in der Kette dargestellt wird.
The resources themselves show in a gray bubble each e.g. for the RTO fulfillment the "Net recovery time" with an "N" of the resource itself as well as the "Gross recovery time" with a "B" for the summed recovery time of the resource chain incl. the respective node.  


Wenn zu einer Ressource noch keine Zeiten eingetragen wurden, dann wird ein gelbes Konfigurationssymbol für die Ressource eingeblendet.
The illustrated example shows the RTO fulfillment. The logic for RPO fulfillment is very similar, with the difference that the backup times for the entire resource chain are not summed up, but the highest recovery time of a resource in the chain is always shown here in the gross value.
 
If no times have been entered for a resource yet, a yellow configuration icon is displayed for the resource.


[[Datei:RN Jänner2021 9.png|left]]
[[Datei:RN Jänner2021 9.png|left]]
<br clear=all>
<br clear=all>
 
Wenn zu einer Ressource bewusst keine Zeiten erfasst werden sollen, dann wird ein graues Symbol wie das folgende angezeigt:
If no times are to be deliberately recorded for a resource, then a gray icon like the following is displayed:


[[Datei:RN Jänner2021 10.png|left]]
[[Datei:RN Jänner2021 10.png|left]]
<br clear=all>
<br clear=all>


=== Darstellung der zugeordneten Überprüfungen zum Audit auf eigenem Registerblatt ===
=== Representation of the assigned checks to the audit on its own tab sheet ===


Unter Risikomanagement > Auditverwaltung > Audit wurde die Strukturierung der einzelnen Registerblätter überarbeitet. Damit sie leichter auffindbar sind, wurden die zugeordneten Überprüfungen auf ein eigenes Registerblatt gelegt.
Under Risk Management > Audit Management > Audit, the structuring of the individual tab sheets has been revised. To make them easier to find, the assigned audits have been placed on their own tab sheet.


[[Datei:RN Jänner2021 11.png|left]]
[[Datei:RN Jänner2021 11.png|left]]
<br clear=all>
<br clear=all>
=== Visualisierung der Auditplanung im Auditprogramm ===


Unter Risikomanagement > Auditverwaltung > Auditprogramme können Sie ein Auditprogramm erstellen oder bearbeiten. Wenn Sie hier ein Auditprogramm öffnen findet sich ein neues Registerblatt, der „Terminkalender“, wieder:
=== Visualization of audit planning in the audit program ===
 
Under Risk Management > Audit Management > Audit Programs you can create or edit an audit program. If you open an audit program here, you will find a new tab sheet, the "Appointment calendar":


[[Datei:RN Jänner2021 12.png|left]]
[[Datei:RN Jänner2021 12.png|left]]
<br clear=all>
<br clear=all>
Diese Darstellung ermöglicht es die unterschiedlichen Audits im Auditprogramm gemeinsam in einem Kalender darzustellen.


=== Neue Strukturierung, Berichte und Optionen für Risikomanagement > Berichte ===
This representation allows the different audits in the audit program to be displayed together in one calendar.
 
=== New structuring, reports and options for risk management > Reports ===


==== Anpassung der Report Administration ====  
==== Report Administration Customization ====  


Die Komponente zur Administration von Berichten wurde überarbeitet bzw. erweitert. Es stehen nun mehr Berichte, -varianten und -optionen zur Verfügung und die Menüführung durch diese Auswahl wurde verbessert.
The report administration component has been revised/extended. More reports, variants and options are now available and the menu navigation through this selection has been improved.


==== Auditplan mit Management-Summary und Konformitätsbericht ====
==== Audit plan with management summary and compliance report ====


Die Berichtsoptionen unter Risikomanagement > Berichte > Auditverwaltung > Auditplan wurden erweitert und bieten nun eine Option „Konformitätsbericht zu Auditplan andrucken“. Damit können im Bericht zum jeweiligen Audit die einzelnen Details zum Auditergebnis aus den Überprüfungen ausgewertet werden.
The report options under Risk management > Reports > Audit management > Audit plan have been extended and now offer an option "Print compliance report for audit plan". This allows the individual audit result details from the reviews to be evaluated in the report for the respective audit.


==== Abweichungen zum Gefährdungslagen Bericht ====
==== Deviations from the Hazard Situation Report ====


Die Berichtsoptionen unter Risikomanagement > Berichte > Gefährdungslagen wurden erweitert und bieten nun eine Option „Abweichungen inkludieren“. Damit können im Bericht zur jeweiligen Gefährdungslage die einzelnen Abweichungen aus den Überprüfungen - sofern solche vorliegen - angedruckt werden.
The report options under Risk management > Reports > Hazard situations have been expanded and now offer an option "Include deviations". This allows the individual deviations from the checks - if any - to be printed in the report for the respective hazard situation.


==== Scope Einschränkungen in diversen Berichten berücksichtigen ====
==== Scope restrictions in various reports ====


In den folgenden Berichten wird die nun Auswertung auf den Geltungsbereich des Standards bzw. der Norm eingeschränkt:
In the following reports, the evaluation is now restricted to the scope of the standard or norm:
*Risikomanagement > Berichte > Konformität > Nach Standards und Normen
*Risk management > Reports > Conformity > By standards and norms.
*Risikomanagement > Berichte > Standards und Normen > Statement of Applicability
*Risk management > Reports > Standards and norms > Statement of applicability
*Risikomanagement > Berichte > Standards und Normen > Management Summary
*Risk management > Reports > Standards and norms > Management summary
Ist dies nicht gewünscht und soll der gesamte Standard bzw. die Norm betrachtet werden, dann ist die Option „Nicht anwendbare Kapitel in der Statistik aufnehmen“ zu aktivieren.
If this is not desired and the entire standard or norm is to be considered, then the option "Include non-applicable chapters in statistics" must be activated.


==== Berichtsoptionen der Standard und Normen Berichte wurden erweitert ====
==== Report options of the standard and norms reports have been extended ====


Die beiden Berichte unter Risikomanagement > Berichte > Standards und Normen wurden dahingehend erweitert, dass man nun konfigurieren kann ob die Statistiken (Donut-Diagramme) zu den Maßnahmen- und Kontrollerfüllungen angezeigt werden sollen oder nicht. Dazu wird die Option „Statistik andrucken“ verwendet.
The two reports under Risk Management > Reports > Standards and norms have been extended to the effect that it is now possible to configure whether the statistics (donut diagrams) for the measure and control fulfillments are to be displayed or not. The option "Print statistics" is used for this purpose.


Zusätzlich kann beim Bericht „Statement of Applicability“ nun auch konfiguriert werden, ob die Maßnahmen und Kontrollen im Detail angedruckt werden sollen. Wenn dies nicht gewünscht ist, so fallen die Berichtskapitel Maßnahmen und Kontrollen weg. Dazu wird die Option „Maßnahmen- und Kontrolldetails andrucken“ verwendet.
In addition, it is now possible to configure whether the measures and controls are to be printed in detail in the "Statement of Applicability" report. If this is not desired, the report chapters Measures and Controls will be omitted. For this purpose, the option "Print measure and control details" is used.


Hinweis: Option „Nur Kapitel auf unterster Ebene als Berechnungsbasis für die Statistik verwenden“ wurde für beide Berichte entfernt. Die Logik verhält sich nun immer so, als wäre die Option „Nur Kapitel auf unterster Ebene als Berechnungsbasis für die Statistik verwenden“ aktiv. Dies gilt auch für den Aufruf dieses Berichts unter Administration > Standards und Normen.
Note: Option "Use only lowest level chapters as calculation base for statistics" has been removed for both reports. The logic now always behaves as if the "Use only lowest level chapters as calculation base for statistics" option is active. This also applies to calling this report under Administration > Standards and Norms.


== Neues im Datenschutz ==
== News in data protection ==


=== Weitere Erfassungsmöglichkeiten für eingesetzte Betriebsmittel ===   
=== Further recording options for operating resources used ===   


Sollten Sie für eine Datenschutz-Folgeabschätzung keine entsprechende Strukturanalyse zu den eingesetzten Betriebsmitteln in HITGuard abgebildet haben oder diese textuell zusätzlich beschreiben wollen bzw. sollte Ihnen ein Dokument vorliegen, in dem die eingesetzten Betriebsmittel im Detail erläutert werden, dann können Sie diese Informationen in der DSFA in HITGuard nun auch erfassen.
If you have not mapped a corresponding structural analysis of the resources used in HITGuard for a data protection impact assessment, or if you want to describe them additionally in text, or if you have a document in which the resources used are explained in detail, you can now also record this information in the DSFA in HITGuard.


[[Datei:RN Jänner2021 13.png|left]]
[[Datei:RN Jänner2021 13.png|left]]
<br clear=all>
<br clear=all>


=== Neue Reports ===  
=== New reports ===  
 
The menu item Data Protection > Reports is new and offers a wide range of possible configurations of reports on processing activities, data protection impact assessments and categories of data subjects:


Der Menüpunkt Datenschutz > Berichte ist neu und bietet eine große Auswahl an möglichen Konfigurationen von Berichten zu Verarbeitungstätigkeiten, Datenschutz-Folgeabschätzungen und Betroffenenkategorien:
[[Datei:RN Jänner2021 14.png|left]]
[[Datei:RN Jänner2021 14.png|left]]
<br clear=all>
<br clear=all>


==== Mehrere Verarbeitungstätigkeiten in einem Report drucken ====
==== Print multiple processing activities in one report ====


Unter Datenschutz > Berichte > Verarbeitungsregister > Eigene Verarbeitungstätigkeit kann nun ein Bericht generiert werden der wahlweise eine oder mehrere oder alle eigenen Verarbeitungstätigkeiten enthält. Dafür werden die Verarbeitungstätigkeiten in der letztgültigen Version mit dem Status „Bearbeitung abgeschlossen“ angeboten.
Under Data Protection > Reports > Processing Register > Own Processing Activity, a report can now be generated that optionally contains one or more or all own processing activities. For this purpose, the processing activities are offered in the latest valid version with the status "Processing completed".


==== Verarbeitungstätigkeiten im Auftrag anderer in einem Report drucken ====
==== Print processing activities on behalf of others in a report ====


Unter Datenschutz > Berichte > Verarbeitungsregister > im Auftrag anderer kann nun ein Bericht generiert werden, der alle Verarbeitungstätigkeiten enthält, die entweder durch eine Organisationseinheit des eigenen Unternehmens oder für einen bestimmten externen Kunden erbracht werden. Dafür werden die Verarbeitungstätigkeiten in der letztgültigen Version mit dem Status „Bearbeitung abgeschlossen“ angeboten.
Under Data Protection > Reports > Processing Register > on behalf of others, a report can now be generated containing all processing activities performed either by an organizational unit of one's own company or for a specific external customer. For this purpose, the processing activities are offered in the latest valid version with the status "Processing completed".


==== Verarbeitungstätigkeiten externer Auftragsverarbeiter drucken ====
==== Print processing activities of external processors ====


Unter Datenschutz > Berichte > Verarbeitungsregister > externe Auftragsverarbeiter kann nun ein Bericht generiert werden, der alle Verarbeitungstätigkeiten enthält, die durch externe Auftragsverarbeiter für das Unternehmen erbracht werden. Dafür werden die Verarbeitungstätigkeiten in der letztgültigen Version mit dem Status „Bearbeitung abgeschlossen“ angeboten.
Under Data Protection > Reports > Processing Register > External Processors, a report can now be generated containing all processing activities performed for the company by external processors. For this purpose, the processing activities are offered in the latest valid version with the status "Processing completed".


== Neues zur Administration ==
== Administration news ==


=== Erfassung des Backup Intervalls sowie der Wiederherstellzeit für Ressourcen ===
=== Acquisition of the backup interval as well as the recovery time for resources ===


Für Ressourcen können nun Wiederherstellzeit und Backup Intervall als Information zum aktuellen Stand der IST-Analyse abgebildet werden.
For resources, recovery time and backup interval can now be mapped as information on the current status of the ACTUAL analysis.


Die Wiederherstellzeit wird in Stunden für diese Ressource (unabhängig von den Wiederherstellzeiten benötigter Systeme) erfasst. Dabei kann dokumentiert werden, ob die Wiederherstellzeit z.B. durch einen SLA gesichert ist. Dazu können Kommentare erfasst und Dokumente abgelegt werden.
The recovery time is recorded in hours for this resource (independent of the recovery times of required systems). It can be documented whether the recovery time is secured by an SLA, for example. Comments can be recorded and documents filed for this purpose.


Auch das Backup Intervall wird in Stunden erfasst. Es ist aber auch möglich für eine Ressource zu kennzeichnen, dann ein Backup dafür nicht relevant ist.
The backup interval is also recorded in hours. However, it is also possible to indicate for a resource that a backup is not relevant for it.


[[Datei:RN Jänner2021 15.png|left]]
[[Datei:RN Jänner2021 15.png|left]]
<br clear=all>
<br clear=all>


=== Konfiguration der proaktiven Fortschrittsmeldung ===
=== Configuration of proactive progress reporting ===


Das proaktive Melden eines Fortschritts durch den Practitioner (zusätzlich zum reaktiven Melden nach Aufforderung durch den Expert) kann über die globalen Einstellungen (Administration > Globale Einstellungen | Optionale Maßnahmeneigenschaften) ein- bzw. ausgeblendet werden.
Proactive reporting of progress by the Practitioner (in addition to reactive reporting when prompted by the Expert) can be turned on or off via the global settings (Administration > Global Settings | Optional Action Properties).


[[Datei:RN Jänner2021 16.png|left]]
[[Datei:RN Jänner2021 16.png|left]]
<br clear=all>
<br clear=all>
=== Erweiterung des Datenimports um Prozesse ===


Unter Administration > Datenimport findet sich die Verwaltung der Importkonfigurationen. Hier können Konfigurationen zu einzelnen Importformaten verwaltet, gepflegt und ausgeführt werden. Nun gibt es auch die Möglichkeit Prozesse zu importieren.
=== Extension of the data import with processes ===
 
The administration of import configurations can be found under Administration > Data Import. Here, configurations for individual import formats can be managed, maintained and executed. Now there is also the possibility to import processes.


[[Datei:RN Jänner2021 17.png|left]]
[[Datei:RN Jänner2021 17.png|left]]
<br clear=all>
<br clear=all>
Once an import configuration has been created, it can be run again and again with new import files. In doing so, fields are also updated if the record ID from the third-party system remains constant.
Eine einmal erstellte Importkonfiguration kann immer wieder mit neuen Importdateien ausgeführt werden. Dabei werden auch Felder aktualisiert, wenn die Datensatz-ID vom Fremdsystem konstant verbleibt.


Eine Anleitung zur Durchführung von Datenimports finden Sie hier in unserer Dokumentation.
Instructions on how to perform data imports can be found here in our documentation.

Aktuelle Version vom 4. Februar 2021, 20:38 Uhr

 == Integration of the online help== The online help has been integrated into HITGuard. You will now find the last item "Help" right after "Administration" in the dark gray menu bar. Under Help > Online Help you can access the detailed user manual for HITGuard


Under Help > First Steps you will also find an introduction to the navigation and interface of HITGuard. When the software is started for the first time, this appears automatically.


In addition, a step-by-step guide has been integrated into HITGuard. This will be successively expanded over the coming months. In the screens where this is already available, an "i" appears in the lower left corner of the software. A click on the "i" starts the step-by-step guide.


New under "My tasks"

Proactive reporting of an action progress

Previously, a Practitioner could only report progress on a measure when prompted to do so by the Expert/Professional. This reactive reporting is still possible. In addition, the practitioner (if configured to do so; see 5.2 Configuring proactive progress reporting) can now also proactively report the progress on a measure. To do this, the practitioner simply has to use the new "Report progress" button in the menu under My Tasks > Action Status and can then select the action for which he or she would like to report progress.


In the measure selection, the practitioner will find all open measures assigned to him/her as the responsible person or as the responsible team member or team leader.

When selecting a measure for which a requested progress note already exists for the Practitioner, it opens for processing. If no progress report has been requested yet, a new progress report is created. This must then be returned immediately. No report can be created for tasks for which a returned progress report currently exists that has not yet been accepted by the expert/professional. This task is listed in the selection, but cannot be selected and is marked with "answered".

Upload evidence for inspections by inspector

In the course of reviewing a control, the reviewer can now also upload evidence. This can be useful, for example, if a reviewer wants to comment on evidence and return the revised document to the implementer for re-editing.

What's new in risk management

Restriction of compliance evaluation on the dashboard

Experts/professionals can visually query compliance with various standards on the dashboard. This query has now been extended to include the option of restricting the display to the defined scope of the standard or norm.


Extensions of the structural analysis for the representation of RTO and RPO

Provided that you collect the protection targets RTO and RPO for your analyses and have activated the option "Display in graph" in the risk policy for this, a new feature is available to you.



Note that for the representation described below, you must also complete the collection of recovery time and backup interval (see 5.1 Collection of backup interval as well as recovery time for) on the resources.

If these requirements are met, you can visually evaluate whether the recorded requirements for Recovery Time Objective (RTO; max. reasonable recovery time) and Recovery Point Objective (RPO; max. reasonable data loss) are met by the actual recovery times or backup intervals of the systems.

In the structural analysis, the following selection appears in the analysis mode in the navigation area, which can be used to trigger an analysis for RTO or RPO fulfillment. To start the analysis, select one of the two options and click the "Apply" button:



In the graph, the requirements from the protection needs analyses are displayed on the edges between the organizational unit and resource at the application level. If the requirements for RTO are met or not met by the underlying path, e.g., recovery times, then the requirement is shown in green, otherwise in red.


The resources themselves show in a gray bubble each e.g. for the RTO fulfillment the "Net recovery time" with an "N" of the resource itself as well as the "Gross recovery time" with a "B" for the summed recovery time of the resource chain incl. the respective node.

The illustrated example shows the RTO fulfillment. The logic for RPO fulfillment is very similar, with the difference that the backup times for the entire resource chain are not summed up, but the highest recovery time of a resource in the chain is always shown here in the gross value.

If no times have been entered for a resource yet, a yellow configuration icon is displayed for the resource.


If no times are to be deliberately recorded for a resource, then a gray icon like the following is displayed:


Representation of the assigned checks to the audit on its own tab sheet

Under Risk Management > Audit Management > Audit, the structuring of the individual tab sheets has been revised. To make them easier to find, the assigned audits have been placed on their own tab sheet.


Visualization of audit planning in the audit program

Under Risk Management > Audit Management > Audit Programs you can create or edit an audit program. If you open an audit program here, you will find a new tab sheet, the "Appointment calendar":


This representation allows the different audits in the audit program to be displayed together in one calendar.

New structuring, reports and options for risk management > Reports

Report Administration Customization

The report administration component has been revised/extended. More reports, variants and options are now available and the menu navigation through this selection has been improved.

Audit plan with management summary and compliance report

The report options under Risk management > Reports > Audit management > Audit plan have been extended and now offer an option "Print compliance report for audit plan". This allows the individual audit result details from the reviews to be evaluated in the report for the respective audit.

Deviations from the Hazard Situation Report

The report options under Risk management > Reports > Hazard situations have been expanded and now offer an option "Include deviations". This allows the individual deviations from the checks - if any - to be printed in the report for the respective hazard situation.

Scope restrictions in various reports

In the following reports, the evaluation is now restricted to the scope of the standard or norm:

  • Risk management > Reports > Conformity > By standards and norms.
  • Risk management > Reports > Standards and norms > Statement of applicability
  • Risk management > Reports > Standards and norms > Management summary

If this is not desired and the entire standard or norm is to be considered, then the option "Include non-applicable chapters in statistics" must be activated.

Report options of the standard and norms reports have been extended

The two reports under Risk Management > Reports > Standards and norms have been extended to the effect that it is now possible to configure whether the statistics (donut diagrams) for the measure and control fulfillments are to be displayed or not. The option "Print statistics" is used for this purpose.

In addition, it is now possible to configure whether the measures and controls are to be printed in detail in the "Statement of Applicability" report. If this is not desired, the report chapters Measures and Controls will be omitted. For this purpose, the option "Print measure and control details" is used.

Note: Option "Use only lowest level chapters as calculation base for statistics" has been removed for both reports. The logic now always behaves as if the "Use only lowest level chapters as calculation base for statistics" option is active. This also applies to calling this report under Administration > Standards and Norms.

News in data protection

Further recording options for operating resources used

If you have not mapped a corresponding structural analysis of the resources used in HITGuard for a data protection impact assessment, or if you want to describe them additionally in text, or if you have a document in which the resources used are explained in detail, you can now also record this information in the DSFA in HITGuard.


New reports

The menu item Data Protection > Reports is new and offers a wide range of possible configurations of reports on processing activities, data protection impact assessments and categories of data subjects:


Under Data Protection > Reports > Processing Register > Own Processing Activity, a report can now be generated that optionally contains one or more or all own processing activities. For this purpose, the processing activities are offered in the latest valid version with the status "Processing completed".

Under Data Protection > Reports > Processing Register > on behalf of others, a report can now be generated containing all processing activities performed either by an organizational unit of one's own company or for a specific external customer. For this purpose, the processing activities are offered in the latest valid version with the status "Processing completed".

Under Data Protection > Reports > Processing Register > External Processors, a report can now be generated containing all processing activities performed for the company by external processors. For this purpose, the processing activities are offered in the latest valid version with the status "Processing completed".

Administration news

Acquisition of the backup interval as well as the recovery time for resources

For resources, recovery time and backup interval can now be mapped as information on the current status of the ACTUAL analysis.

The recovery time is recorded in hours for this resource (independent of the recovery times of required systems). It can be documented whether the recovery time is secured by an SLA, for example. Comments can be recorded and documents filed for this purpose.

The backup interval is also recorded in hours. However, it is also possible to indicate for a resource that a backup is not relevant for it.


Configuration of proactive progress reporting

Proactive reporting of progress by the Practitioner (in addition to reactive reporting when prompted by the Expert) can be turned on or off via the global settings (Administration > Global Settings | Optional Action Properties).


Extension of the data import with processes

The administration of import configurations can be found under Administration > Data Import. Here, configurations for individual import formats can be managed, maintained and executed. Now there is also the possibility to import processes.


Once an import configuration has been created, it can be run again and again with new import files. In doing so, fields are also updated if the record ID from the third-party system remains constant.

Instructions on how to perform data imports can be found here in our documentation.