Menü aufrufen
Toggle preferences menu
Persönliches Menü aufrufen
Nicht angemeldet
Ihre IP-Adresse wird öffentlich sichtbar sein, wenn Sie Änderungen vornehmen.

Hauptseite/en: Unterschied zwischen den Versionen

Aus HITGuard User Guide
Die Seite wurde neu angelegt: „This user help provides you with detailed information on how to use each of these modules. We have designed this user help to be useful for beginners and experienced users alike. If you have any questions or need help, our support team will be happy to assist you.“
Isan (Diskussion | Beiträge)
Keine Bearbeitungszusammenfassung
 
(96 dazwischenliegende Versionen von 3 Benutzern werden nicht angezeigt)
Zeile 3: Zeile 3:
HITGuard offers you comprehensive support in managing and monitoring your risks and compliance requirements. In the menu navigation of HITGuard you will find various modules that support you in meeting your IT governance, risk management and compliance requirements.  
HITGuard offers you comprehensive support in managing and monitoring your risks and compliance requirements. In the menu navigation of HITGuard you will find various modules that support you in meeting your IT governance, risk management and compliance requirements.  


The ''Risk management'' module helps you identify and assess risks and provides you with a central platform to manage your risk assessments. The ''Audit management'' module allows you to conduct internal and external audits, track the results and generate reports. The ''Case management'' module supports you in handling security incidents and breaches of policies and regulations. The ''Measures'' module helps you implement measures to eliminate or reduce risks and security gaps. The ''Controls'' module allows you to manage and evaluate your controls and their effectiveness. The ''Data Protection'' module helps you comply with data protection regulations and policies. In the ''Administration'' module, you can configure HITGuard and adapt it to your specific requirements. Here you will also find functions for managing user accounts, roles and teams as well as for integrating HITGuard into existing systems and processes.
This user help provides you with detailed information on how to use each of the HITGuard modules and describes the contents of the entire available menu.


This user help provides you with detailed information on how to use each of these modules. We have designed this user help to be useful for beginners and experienced users alike. If you have any questions or need help, our support team will be happy to assist you.
We have designed this user help to be useful for beginners and experienced users alike. If you have any questions or need help, our support team will be happy to assist you if you contact us under support@hitguard.at.


We hope that this user guide will help you to get the most out of HITGuard. Thank you for choosing our solution!
We hope that this user guide will help you to get the most out of HITGuard. Thank you for choosing our solution!


<span id="Menüführung"></span>
===<span id="modules"></span> The HITGuard menu ===
== Menu navigation==
Find the help pages for all possible menu items of the individual modules here:


All modules and their menu items are explained here.
{{Card
[[Datei:HitGuard_Menu.png|mini|Main menu items]]
|column=3
|count = 9


<span id="Meine_Aufgaben"></span>
|title1=<span id="Sec_Ass"></span>Risk management
=== <span id="my_act"></span> My Tasks===


----
|text1=*[[Special:MyLanguage/Risikopolitik|Risk policy]]
 
Under "My tasks" you will find the tasks you have to complete in your role as a practitioner. The menu on the left shows you at a glance if you have any pending tasks (orange number badge).
 
[[Datei:Meine Aufgaben Badges2.png|frameless|My tasks]]
 
*[[Special:MyLanguage/Profil|Profil]]
*[[Special:MyLanguage/Dashboard|Dashboard]]
*[[Special:MyLanguage/Maßnahmenstatus|Measure status]]
*[[Special:MyLanguage/Kontrollen|Controls]]
*[[Special:MyLanguage/Überprüfungen|Reviews]]
*[[Special:MyLanguage/Meine Verarbeitungstätigkeiten|PAs]]
*[[Special:MyLanguage/Meine_Aufgaben_Gefährdungslagen|Hazard situations]]
*[[Special:MyLanguage/Meine_Aufgaben_Meldungen|Reports]]
 
=== <span id="cur_man_act"></span> Current management tasks ===
----
 
The envelope in the upper right corner informs professionals and experts about tasks that have been reported completed and are waiting for completion/review. The tasks always refer to the current management system only. In addition, the tasks are only displayed to users who are authorized to edit them.
 
For example, answered processing activities are displayed only to users who are Data Protection professionals or experts and are currently in the Data Protection management system.
 
[[Datei:Management Briefchen.png|left|thumb|500px|Current management tasks]] <br clear=all>
 
The tasks are divided into the following items:
 
* Risk management
** Protection needs analyses
*: Protection needs analyses of the current management system that have been answered.
** Gap analyses
*:: Gap analyses of the current management system that have been answered.
** Hazard situations
*:: Hazard situations of the current management system that have been newly submitted or returned.
* Measures
** Progress reports
*Progress reports of the current management system that have been answered.
* Data protection management systems
** Processing activities
*:: Processing activities of the current management system that have been answered.
* Case management systems
** Unassigned reports
*:: Reports of the current management system to which no user has been assigned yet. If a support team is defined, these will only be displayed to the team members.
** Reports assigned to me
*:: Open reports of the current management system that are assigned to the current user. Closed and answered reports are not displayed.
 
=== My Dashboards ===
----
 
Dashboards are used to get an overview of the management systems. By default, each management system has a dashboard for risk management, for measures, and for controls. Data protection management systems also have a data protection dashboard, and case management systems have a case management dashboard. However, only dashboards for which the user is authorized are displayed.
 
In order for a user to access a dashboard, they need the "Expert", "Professional" or "Observer" role in the respective module. Thus, to view the risk management dashboard, at least the "Professional" role in risk management is required.
 
Additional dashboards can also be created and configured. It is possible to make these accessible only to oneself by marking them as "private". Dashboards that are not marked as "private" are visible to all authorized members of the management system.
 
Users can mark a dashboard as a favorite in each management system. This dashboard will be ranked first for the user and displayed when the user logs in. To mark it, click the star next to the dashboard configuration.
 
[[Datei:DB Favoriten Markierung.png|frameless|395px|mark as favorite]]
 
How to create and edit dashboards, as well as information on the Key Performance Indicators (KPIs) for each dashboard can be found here:
*[[Special:MyLanguage/Dashboards|Create and edit dashboards]]
*[[Special:MyLanguage/Risikomanagement_Dashboard|Risk management]]
*[[Special:MyLanguage/Maßnahmen_Dashboard|Measures]]
*[[Special:MyLanguage/Kontrollen_Dashboard|Controls]]
*[[Special:MyLanguage/Datenschutz_Dashboard|Data protection]]
*[[Special:MyLanguage/Fallmanagement_Dashboard|Case management]]
 
<span id="Risikomanagement"></span>
=== <span id="Sec_Ass"></span>Risk management===
 
----
*[[Special:MyLanguage/Risikopolitik|Risk Policy]]
*[[Special:MyLanguage/Strukturanalyse|Structural analysis]]
*[[Special:MyLanguage/Strukturanalyse|Structural analysis]]
*[[Special:MyLanguage/Schutzbedarf|Protection needs]]
*[[Special:MyLanguage/Schutzbedarf|Protection needs]]
*[[Special:MyLanguage/Schwachstellen|Vulnerabilities]]
*[[Special:MyLanguage/Schwachstellen|Vulnerabilities]]
*[[Special:MyLanguage/Risikobewertung|Risk evaluation]]
*[[Special:MyLanguage/Bedrohungen|Threats]]
*[[Special:MyLanguage/Risikobehandlung|Risk treatment]]
*[[Special:MyLanguage/Risikobewertung|Risks & opportunities]]
*[[Special:MyLanguage/Berichte für das Risikomanagement|Reports for the risk management]]
*[[Special:MyLanguage/Auswirkungen|Impacts]]
*[[Special:MyLanguage/ESG_Themen|ESG topics]]
*[[Special:MyLanguage/Risikobehandlung|Treatment R&O]]
*[[Special:MyLanguage/Berichte für das Risikomanagement|Reports]]
*[[Special:MyLanguage/Risikomanagement_Einstellungen|Settings]]


<span id="Auditmanagement"></span>
|title2=<span id="aud_man"></span>Audit management
=== <span id="aud_man"></span>Audit management===


----
|text2=*[[Special:MyLanguage/Auditkalender|Audit calendar]]
*[[Special:MyLanguage/Auditplanung|Audit planning]]
*[[Special:MyLanguage/Auditplanung|Audit planning]]
*[[Special:MyLanguage/Auditdurchführung|Audit execution]]
*[[Special:MyLanguage/Auditdurchführung|Audit execution]]
*[[Special:MyLanguage/Auditbehandlung|Audit treatment]]
*[[Special:MyLanguage/Externe_Auditoren|External auditors]]
*[[Special:MyLanguage/Externe_Auditoren|External auditors]]
*[[Special:MyLanguage/Auditcluster|Audit clusters]]
*[[Special:MyLanguage/Auditcluster|Audit clusters]]
*[[Special:MyLanguage/Funktionen|Functions]]
*[[Special:MyLanguage/Funktionen|Functions]]
*[[Special:MyLanguage/Berichte für das Auditmanagement|Reports for audit management]]
*[[Special:MyLanguage/Berichte für das Auditmanagement|Reports]]
*[[Special:MyLanguage/Auditmanagement_Einstellungen|Settings]]
*[[Special:MyLanguage/Auditmanagement_Einstellungen|Settings]]


<span id="Fallmanagement"></span>
|title3=<span id="case_man"></span>Case management  
=== <span id="case_man"></span>Case management===
 
----


*[[Special:MyLanguage/Vorfall_melden|Report incident]]
|text3=*[[Special:MyLanguage/Vorfall_melden|Report incident]]
*[[Special:MyLanguage/Fristen|Periods]]
*[[Special:MyLanguage/Fristen|Periods]]
*[[Special:MyLanguage/Meldungen|Reports]]
*[[Special:MyLanguage/Meldungen|Tickets]]
*[[Special:MyLanguage/Akten|Dossiers]]
*[[Special:MyLanguage/Akten|Dossiers]]
*[[Special:MyLanguage/Berichte für das Fallmanagement|Reports]]
*[[Special:MyLanguage/Fallmanagement-Einstellungen|Settings]]
*[[Special:MyLanguage/Fallmanagement-Einstellungen|Settings]]
*[[Special:MyLanguage/Hinweisgebersystem|Whistleblower system]]


<span id="Maßnahmen"></span>
|title4=<span id="Pro_Mon"></span>Measures  
=== <span id="Pro_Mon"></span>Measures===
 
----


*[[Special:MyLanguage/Aktuelle Maßnahmen|Current measures]]
|text4=*[[Special:MyLanguage/Aktuelle Maßnahmen|Current measures]]
*[[Special:MyLanguage/Fortschrittsmeldungen|Progress reports]]
*[[Special:MyLanguage/Fortschrittsmeldungen|Progress reports]]
*[[Special:MyLanguage/Berichte für Maßnahmen| Reports for measures]]
*[[Special:MyLanguage/Historie|History]]
*[[Special:MyLanguage/Historie|History]]
*[[Special:MyLanguage/Auswertungen|Analysis]]
*[[Special:MyLanguage/Auswertungen|Analysis]]
*[[Special:MyLanguage/Einstellungen|Settings]]
*[[Special:MyLanguage/Berichte für Maßnahmen|Reports]]
 
*[[Einstellungen|Settings]]
<span id="Kontrollen"></span>
=== <span id="Pro_Mon_con"></span>Controls===
 
----


*[[Special:MyLanguage/Kontrolldefinitionen|Control definitions]]
|title5=<span id="Pro_Mon_con"></span>Controls


<span id="Datenschutz"></span>
|text5=*[[Special:MyLanguage/Kontrolldefinitionen|Control definitions]]
=== <span id="Da_Pro"></span>Data protection===
*[[Special:MyLanguage/Berichte für Kontrollen| Reports]]


----
|title6=<span id="Da_Pro"></span>Data protection


*[[Special:MyLanguage/Verarbeitungsregister|Processing registers]]
|text6=*[[Special:MyLanguage/Verarbeitungsregister|Processing registers]]
*[[Special:MyLanguage/Datenschutz-Folgenabschätzung|DPIA]]
*[[Special:MyLanguage/Datenschutz-Folgenabschätzung|DPIA]]
*[[Special:MyLanguage/Externe|Externals]]
*[[Special:MyLanguage/Externe|Externals]]
Zeile 149: Zeile 74:
*[[Special:MyLanguage/Betroffenenkategorien|Data subject categories]]
*[[Special:MyLanguage/Betroffenenkategorien|Data subject categories]]
*[[Special:MyLanguage/Berichte für den Datenschutz|Reports]]
*[[Special:MyLanguage/Berichte für den Datenschutz|Reports]]
*[[Special:MyLanguage/Datenschutz Einstellungen|Settings]]
|title7=<span></span>Doc management


=== <span id="administration"></span>Administration===
|text7=*[[Special:MyLanguage/Dokumentenmanagement|Documents]]
*[[Special:MyLanguage/Dokumente|Uploaded attachments]]
*[[Special:MyLanguage/Berichtsarchiv|Report archive]]


----
|title8=<span id="administration"></span>Administration 1


*[[Special:MyLanguage/Benutzer und Benutzerrollen|User and user-role assignment]]
|text8=*[[Special:MyLanguage/Benutzer und Benutzerrollen|Users and user roles]]
*[[Special:MyLanguage/Teams|Teams]]
*[[Special:MyLanguage/Teams|Teams]]
*[[Special:MyLanguage/Globale Einstellungen|Global settings]]
*[[Special:MyLanguage/Globale Einstellungen|Global settings]]
*[[Special:MyLanguage/Managementsysteme|Management systems]]
*[[Special:MyLanguage/Managementsysteme|Management systems]]
*[[Special:MyLanguage/OrgEh - Organisationseinheiten|OrgUnits]]
*[[Special:MyLanguage/OrgEh - Organisationseinheiten|OrgUnits - Organizational units]]
*[[Special:MyLanguage/Ressourcen|Resources]]
*[[Special:MyLanguage/Ressourcen|Resources]]
*[[Special:MyLanguage/Datenkategorien|Data categories]]
*[[Special:MyLanguage/Datenkategorien|Data categories]]
*[[Special:MyLanguage/Prozesse|Processes]]
*[[Special:MyLanguage/Prozesse|Processes]]
*[[Special:MyLanguage/Wissensdatenbanken|Knowledge bases]]
*[[Special:MyLanguage/Lieferanten|Suppliers]]
 
|title9=<span></span>Administration 2
 
|text9=*[[Special:MyLanguage/Wissensdatenbanken|Knowledge bases]]
*[[Special:MyLanguage/Standards und Normen|Standards and norms]]
*[[Special:MyLanguage/Standards und Normen|Standards and norms]]
*[[Special:MyLanguage/Dokumente|Documents]]
*[[Special:MyLanguage/Dokumente|Documents]]
*[[Special:MyLanguage/Berichtsarchiv|Report archive]]
*[[Special:MyLanguage/Berichtsarchiv|Report archive]]
*[[Special:MyLanguage/Textbausteine|Text blocks]]
*[[Special:MyLanguage/Datenimport|Data import]]
*[[Special:MyLanguage/Datenimport|Data import]]
<!---*[[Special:MyLanguage/Module|Moduls]]--->
*[[Special:MyLanguage/Lizenzierung|Licensing]]
<!----*[[Special:MyLanguage/Module|Module]]--->
*[[Special:MyLanguage/Jobs|Jobs]]
*[[Special:MyLanguage/Jobs|Jobs]]
}}
====HITGuard basic modules====
The Risk management, Measures, and Controls, as well as Administration are always available in HITGuard and form the basis of the tool:
{| class="wikitable"
!Risk management
|The ''Risk management'' module helps you identify and assess risks and opportunities, and provides you with a central platform to manage your risk assessments. You can freely configure your risk policy and use different workflows that support you in your risk management.<br><br>Find a rough overview of the risk and opportunity workflow [[Special:MyLanguage/Workflow_Risiko Chance|here]].<br>Find information on risks and opportunities for Practitioners [[Special:MyLanguage/Meine_Aufgaben_Gefährdungslagen|here]].
|-
!Measures
|The ''Measures'' module helps you implement measures to eliminate or reduce risks and security gaps. You can monitor the implementation of your measures with progress reports and test their effectiveness.<br><br>Find a rough overview of the measure workflow [[Special:MyLanguage/Workflow_Maßnahme|here]].<br>Find information on measures for Practitioners [[Special:MyLanguage/Maßnahmenstatus|here]].
|-
!Controls
|The ''Controls'' module allows you to manage and evaluate your controls and their effectiveness. You can create control definitions and track the execution of the corresponding controls.<br><br>Find a rough overview of the control workflow [[Special:MyLanguage/Workflow_Kontrolle|here]].<br>Find information on controls for Practitioners [[Special:MyLanguage/Kontrollen|hier]].
|-
!Administration
|In the ''Administration'' module, you can configure HITGuard and adapt it to your specific requirements. Here you will also find functions for managing user accounts, roles and teams as well as for integrating HITGuard into existing systems and processes.
|-
|}
====HITGuard Add-ons====
There are various extensions for HITGuard in order to cover further use cases.
{| class="wikitable"
!Data protection
|The ''Data Protection'' module helps you comply with data protection regulations and policies.<br><br>With an activated data protection add-on you receive the menu item "Data protection", the contents of which you can find below. Data protection is licensed separately and can be activated under Administration > Management systems for one management system.<br><br>Find a rough overview of the PA workflow [[Special:MyLanguage/Workflow_VT|here]].<br>Find more on working with PAs for Practitioners [[Special:MyLanguage/Meine_Verarbeitungstätigkeiten#Verarbeitungstätigkeit_bearbeiten/erstellen/updaten|here]].
|-
!Audit management
|The ''Audit management'' module allows you to conduct internal and external audits, track the results and generate reports.<br><br>With an activated audit management add-on you receive the menu item "Audit management", the contents of which you can find below. Audit management is licensed separately and can be activated under Administration > Management systems for one or more management systems.
|-
!Case management
|The ''Case management'' module supports you in handling security incidents and breaches of policies and regulations.<br><br>With an activated case management add-on you receive the menu item "Case management", the contents of which you can find below. Case management is licensed separately and can be activated under Administration > Management systems for one or more management systems.
|-
!Doc management
|The module ''Doc management'' encapsulates document control, uploaded attachments, and the report archive.<br><br>With an activated doc management add-on you receive the menu item "Doc management", the contents of which you can find below. Doc management is licensed separately and can be activated for you by your contact person at TogetherSecure.<br><br>Find a rough overview of the doc management workflow [[Special:MyLanguage/Workflow_Doku-Management|here]].<br>Find information on the review and approval workflow [[Special:MyLanguage/Freigabeworkflow|here]].
|-
!ESG management
|The ''ESG'' module supports you in the execution of the double materiality analysis.<br><br>With an activated ESG management add-on your risk management is extended by a few menu items. ESG management is licensed separately and can be activated for you by your contact person at TogetherSecure.<br><br>Find more on ESG management [[Special:MyLanguage/ESG Management|here]].
|-
!Supplier risk management
|The ''Supplier Risk Management'' module allows you to send reviews to suppliers and thus include them in your audit processes.<br><br>With an activated supplier risk management add-on your administration and reviews are extended by a few menu items and options. Supplier risk management is licensed separately and can be activated for you by your contact person at TogetherSecure.<br><br>Find more on supplier risk management [[Special:MyLanguage/Supplier Risk Management|here]].
|-
|}
Under [[Special:MyLanguage/Hauptseite#How_To_Start|How To Start]] you find the first steps for implementing a management system and for all the add-ons.
<span id="Die_HITGuard_Oberfläche"></span>
== The HITGuard interface ==
[[Datei:Oberflächenbeschreibung2.png|right|701px|Click to enlarge]]
The screenshot gives information about the various areas of the HITGuard interface. In the top left corner you find the profile area of the logged-in user and below it the main menu. A click onto the profile picture takes you to the page [[Special:MyLanguage/Profil|Manage account]]. There, a user can modify their data, update their profile picture, or change the password.
The marked areas in the image show:
# Intro for the current page: If the current page has an interactive introduction, it can be started via this icon.
# Collapse/expand menu: With this button, the navigation menu can be collapsed, or expanded again.
# Switch management system: If the user is authorized for multiple management systems, they can switch between them here. This option is not shown for practitioners or users only authorized for a single management system.
# Current management tasks, logout, and change language:
#* You receive information about your [[#cur_man_act|current management tasks]] via the envelope.
#* You can configure a page's accessibility with the person-symbol.
#* The flag can be used to switch between English and German.
#* The logout button logs you out.
<span id="Hauptmenü"></span>
== Main menu ==
The menu starts off with the "personal" menu items [[#my_act|My tasks]] and [[#my_dashboards|My dashboards]]. These are follows by the menu items of the individual HITGuard modules. The user only sees those modules they are authorized for. Following the module menu items is the menu item [[#hilfe|Help]].
<span id="Meine_Aufgaben"></span>
==== <span id="my_act"></span> My tasks====
[[Datei:Meine Aufgaben Badges2.png|right|frameless|My tasks]]
Under "My tasks" you will find the tasks you have to complete in your role as a practitioner. The menu on the left shows you at a glance if you have any pending tasks (orange number badge). This menu shows all items that are activated in at least one management system.
A click into the ''My tasks'' menu opens the [[Special:MyLanguage/Dashboard|Task dashboard]]. Here, you find a summary of all the tasks pending completion. In addition, clicking on ''My tasks'' opens a submenu that lets you view the tasks by type. There, you also find tasks you have already completed. Orange badges show how many taks you need to work on (e.g., requested progress reports or PAs to be reviewed). Blue badges show how many tasks, for which you are also responsible, somebody else needs to work on (e.g., reviews for which you are responsible but not an interview partner).<p>The states of the different elements are also explained here:
{| class="wikitable" style="border-style: solid; border-width: 0px 0px 0px 0px"
!
|-
!Menu items:
|[[Special:MyLanguage/Maßnahmenstatus|Measures]]
|[[Special:MyLanguage/Kontrollen|Controls]]
|[[Special:MyLanguage/Überprüfungen|Reviews]]
|[[Special:MyLanguage/Meine Verarbeitungstätigkeiten|PAs]]
|[[Special:MyLanguage/Meine_Aufgaben_Gefährdungslagen|Risks & opportunities]]
|[[Special:MyLanguage/Meine_Aufgaben_Meldungen|Tickets]]
|}
<span id="Meine_Dashboards"></span>
==== <span id="my_dashboards"></span> My dashboards ====
[[Datei:Rn233 DB KPI-Report hinzufügen.png|right|frameless|300px]]
Dashboards are for getting an overview of the management systems by using key performance indicators (KPIs) and for preparing the reports that are needed regularly. By default, each management system has a dashboard for information related to risk management, to measures, and to controls. Data protection management systems also have a dedicated data protection dashboard, case management systems have a case management dashboard, and audit management systems have an audit management dashboard. However, only dashboards, KPIs, and reports for which the user is authorized are displayed.
In order for a user to access a dashboard and the KPIs and reports of the respective section, they need the "Expert", "Professional" or "Observer" role in the respective module. Thus, to view the risk management dashboard, at least the "Professional" role in risk management is required.
Additional dashboards can also be created and configured. It is possible to make these accessible only to oneself by marking them as "private". Dashboards that are not marked as "private" are visible to all authorized members of the management system. Default dashboards, as in dashboards that are delivered with HITGuard by default, can be edited and reset into their original state, but not deleted. They are marked as vendor-specific dashboards with a "tool" icon. Self-created dashboards can be deleted.
[[Datei:DB Favoriten Markierung.png|right|frameless|380px]]
Users can mark a dashboard as a favorite in each management system. This dashboard will be ranked first for the user and displayed when the user logs in. To mark it, click the star next to the dashboard configuration.
How to create and edit dashboards as well as information on the KPIs can be found here:
{| class="wikitable" style="border-style: solid; border-width: 0px 0px 0px 0px"
!
|-
!Sections:
|[[Special:MyLanguage/Dashboards|Create/edit dashboards]]
|[[Special:MyLanguage/Risikomanagement_Dashboard|Risk management]]
|[[Special:MyLanguage/ESG_Dashboard|ESG]]
|[[Special:MyLanguage/Maßnahmen_Dashboard|Measures]]
|[[Special:MyLanguage/Kontrollen_Dashboard|Controls]]
|[[Special:MyLanguage/Datenschutz_Dashboard|Data protection]]
|[[Special:MyLanguage/Fallmanagement_Dashboard|Case management]]
|[[Special:MyLanguage/Auditmanagement_Dashboard|Audit management]]
|}
The reports that can be created on dashboards are the same as those in the respective menu items in terms of their content and their report options. The explanations for them are found on the help pages of the reports per menu item.<p>
Reports on dashboards offer the following additional functions:
*Prepare multiple versions of one report: Just like KPIs, reports can be added to dashboards multiple times. The "filter" button allows you to save different configurations of the report options in order to then have access to various iterations of the same type of report at the click of a button.
:<u>Example</u>: A risk report called "Risk report - details", with details on measures and control definitions, the overview of the gaps assigned to the risk, and its temporal evolution; so that risk owners can periodically file a detailed status of their risks. And a risk report for the top managers called "Board risk report", containing just a rough overview of the open measures and active controls; for board members to get a grasp on the current risk treatment efforts.
*Set as default report settings: Experts and Professionals can save the option configuration of one report per report type on non-private dashboards (e.g. one risk report or one gross-net-risk report). In doing so, the report is then automatically generated with these settings from index pages (e.g. on the page Risk management → Risk evaluation, where there aren't any report options available). On the report page itself (e.g., Risk management → Reports → Risks → General) the report is also generated with these settings, but users can make individual changes to these settings. The report set as the default is marked with a star on top of the report icon.
:<u>Example</u>: user A configures a risk report on the dashboard and sets the settings as default. User B generates a risk report from the overview on the page Risk management → risk evaluation and the contents match the default settings. User C has already adjusted the settings the way they need them on the page Risk management → Reports → Risk → General. Their individual settings are not overwritten by the default. User D is using the page Risk management → Reports → Risk → General for the very first time and sees that the report options are set the same way as defined by User A's default.
====Module-specific menu items====
Right after the dashboard menu items, you find the [[#modules|module-specific menu items]]. Which modules are shown here depends on the user's authorizations as well as on the features activated for the management system.


<span id="Hilfe"></span>
<span id="Hilfe"></span>
=== <span id="hilfe"></span>Help===
==== <span id="hilfe"></span>Help====
 
----


Under this menu item you will find the introduction "Getting started", which can restart the intro for HITGuard at any time.
Under this menu item you will find the introduction "Getting started", which gives an introduction to HITGuard's interface.


Under the menu item "Online Help" you will find our help directly integrated in HITGuard.
Under the menu item "Online Help" you will find our help directly integrated in HITGuard.
Zeile 181: Zeile 241:
If there is an info icon in the lower left corner, it can be clicked to start a short introduction to the current page.
If there is an info icon in the lower left corner, it can be clicked to start a short introduction to the current page.


<span id="Benutzer_Anleitungen"></span>
<span id="Das_Briefchen:_aktuelle_Managementaufgaben"></span>
== <span id="User_Guides"></span>User guides==  
===<span id="cur_man_act"></span> The letter: current management tasks ===
 
[[Datei:Management Briefchen.png|right|thumb|500px|Management tasks]]
 
The envelope in the upper right corner informs professionals and experts about tasks that have been reported completed and are waiting for completion/review. The tasks always refer to the ''current management system'' only. Thre is also a notice if the current analysis period has expired.


<span id="Oberflächenbeschreibung"></span>
In addition, the tasks are only displayed to users who are authorized to edit them. For example, answered processing activities are displayed only to users who are Data Protection professionals or experts and are currently in the Data Protection management system.
=== Interface description ===


The following screenshot shows the various elements of the HITGuard interface.
The tasks are divided into the following items:


[[Datei:Oberflächenbeschreibung.png|left|900px]] <br clear=all>
{| class="wikitable"
!Section
!Description
|-
!Progress reports
|Progress reports for measures that have been answered.
|-
!Risks
|Newly submitted or returned risks.
|-
!Protection needs analyses
|Answered protection needs analyses.
|-
!Gap analyses
|Answered gap analyses.
|-
!Tickets assigned to me
|Open tickets that are assigned to you. Closed and answered tickets are not displayed.
|-
!Not assigned tickets
|Tickets that have not yet been assigned an advisor. If a support team is configured, these tickets are only shown to members of that team.
|-
!Processing activities
|Answered processing activities.
|-
|}


<b>Legend:</b>
<span id="Benutzer_Anleitungen"></span>
# Intro for the current page
== <span id="User_Guides"></span>User guides==
#* If the current page has an interactive introduction, it can be started via this icon.
# Open/collapse menu
#* This button collapses the navigational menu or reopens it, respectively.
# Change management system
#* If you have been assigned to multiple management systems, you can switch between them here. This option is not visible if you are a practitioner or have only been assigned to one management system.
# Current management tasks, logout, and change language
#* The envelope gives information about your <b>[[#cur_man_act|current management tasks]]</b>.
#* Logout logs you off the system.
#* The flag can be used to switch between German and English.
# Pending tasks
#* In <b>[[#my_act|My tasks]]</b> you find the tasks you have to implement in your role as practitioner.


=== FAQ ===
=== FAQ ===
:*[[Special:MyLanguage/FAQ|FAQ]]
:*[[Special:MyLanguage/FAQ|FAQ]]


=== Glossar ===
=== Glossary ===
:*[[Special:MyLanguage/Glossar|Glossar]]
:*[[Special:MyLanguage/Glossar|Glossary]]


<span id="Arbeiten_mit_den_Tabellen_und_Symbole"></span>
<span id="Arbeiten_mit_HITGuard"></span>
=== Working with the tables and symbols ===
=== Working with HITGuard ===


:*[[Special:MyLanguage/Profil|User profile]]
:*[[Special:MyLanguage/Funktionalität der Tabellen|Table functionality and symbols]]
:*[[Special:MyLanguage/Funktionalität der Tabellen|Table functionality and symbols]]
:*[[Special:MyLanguage/Icons und Buttons|Explanation of the various icons and buttons in HITGuard]]
:*[[Special:MyLanguage/FAQ#Tips,_Tricks_&_Best_Practice|Tips, tricks & best practice]]


<span id="Experten_oder_Professionals"></span>
<span id="Experten_oder_Professionals"></span>
Zeile 238: Zeile 318:
=== Administrators ===
=== Administrators ===
:*[[Special:MyLanguage/REST API| Dataimport/-export Interface]]
:*[[Special:MyLanguage/REST API| Dataimport/-export Interface]]
===External users===
:*[[Special:MyLanguage/Lieferantenportal| HITGuard portal for suppliers]]


===How To Start===
===How To Start===


*[[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Data Protector setzen?|Which first steps should I take to start working with the Data Protector?]]
*[[Special:MyLanguage/Was sind die ersten Schritte des Aufbaus eines Managementsystems in HITGuard?|What are the first steps towards implementing a management system in HITGuard?]]
*[[Special:MyLanguage/Wie sollte ich vorgehen, wenn ich eine Schutzbedarfsanalyse vornehmen möchte?|What should I do if I want to do a protection needs analysis?]]
*[[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Data Protector setzen?|Which first steps should I take to start working with the data protection module?]]
*[[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Auditmanagement setzen?|Which first steps should I take to start working with the audit management module?]]
*[[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Fallmanagement setzen?|Which first steps should I take to start working with the case management module?]]
*[[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Doku-Management setzen?|Which first steps should I take to start working with the doc management?]]
*[[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem ESG Modul setzen?|Which first steps should I take to start working with the ESG module?]]
*[[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Supplier Risk Management setzen?|Which first steps should I take to start working with the supplier risk management?]]
*[[Special:MyLanguage/Wie aktiviere ich die diversen Mailings, wenn ich mit meinen Einstiegstests fertig bin?|How do I activate the various mailings after I've completed my initial tests?]]
 
===Giudes and rough overview of the workflows===
*[[Special:MyLanguage/Workflow Maßnahme|What does the general workflow for measures look like?]]
*[[Special:MyLanguage/Workflow Kontrolle|What does the general workflow for controls look like?]]
*[[Special:MyLanguage/Workflow Überprüfung|What does the general workflow for reviews look like?]]
*[[Special:MyLanguage/Workflow VT|What does the general workflow for processing activities look like?]]
*[[Special:MyLanguage/Workflow Risiko Chance|What does the general workflow for risk and opportunities look like?]]
*[[Special:MyLanguage/Workflow Meldung|What does the general workflow for tickets look like?]]
*[[Special:MyLanguage/Workflow Doku-Management|What does the general doc management workflow look like?]]
*[[Special:MyLanguage/Wie sollte ich vorgehen, wenn ich eine Schutzbedarfsanalyse vornehmen möchte?|How should I proceed if I want to perform a protection needs analysis?]]


== Release Notes ==
== Release Notes ==


*[[Special:MyLanguage/HITGuard Release Oktober 2022 | HITGuard Release October 2022]]
{| class="wikitable"
*[[Special:MyLanguage/HITGuard Release Juni 2022 | HITGuard Release June 2022]]
!Year
*[[Special:MyLanguage/HITGuard Release Jänner 2022 | HITGuard Release January 2022]]
! colspan="3" |Month
*[[Special:MyLanguage/HITGuard Release September 2021|HITGuard Release September 2021]]
|-
*[[Special:MyLanguage/HITGuard Release April 2021|HITGuard Release April 2021]]
!2025
*[[Special:MyLanguage/HITGuard Release Jänner 2021|HITGuard Release January 2021]]
|[[Special:MyLanguage/HITGuard Release April 2025 |April]]
*[[Special:MyLanguage/HITGuard Release Oktober 2020|HITGuard Release October 2020]]
|[[Special:MyLanguage/HITGuard Release August 2025 |August]]
*[[Special:MyLanguage/HITGuard Release Juli 2020|HITGuard Release July 2020]]
|
*[[Special:MyLanguage/HITGuard Release April 2020|HITGuard Release April 2020]]
|-
*[[Special:MyLanguage/HITGuard Release Dezember 2019|HITGuard Release December 2019]]
!2024
*[[Special:MyLanguage/HITGuard Release Juli 2019|HITGuard Release July 2019]]
|[[Special:MyLanguage/HITGuard Release März 2024 |March]]
*[[Special:MyLanguage/HITGuard Release April 2019|HITGuard Release April 2019]]
|[[Special:MyLanguage/HITGuard Release August 2024 |August]]
*[[Special:MyLanguage/HITGuard Release März 2019|HITGuard Release May 2019]]
|[[Special:MyLanguage/HITGuard Release Dezember 2024 |December]]
|-
!2023
|[[Special:MyLanguage/HITGuard Release Februar 2023 |February]]
|[[Special:MyLanguage/HITGuard Release Juni 2023 |June]]
|[[Special:MyLanguage/HITGuard Release Oktober 2023 |October]]
|-
! 2022
|[[Special:MyLanguage/HITGuard Release Jänner 2022 |January]]
|[[Special:MyLanguage/HITGuard Release Juni 2022 |June]]
|[[Special:MyLanguage/HITGuard Release Oktober 2022 |October]]
|-
!2021
|[[Special:MyLanguage/HITGuard Release Jänner 2021|January]]
|[[Special:MyLanguage/HITGuard Release April 2021|April]]
|[[Special:MyLanguage/HITGuard Release September 2021 |September]]
|-
!2020
|[[Special:MyLanguage/HITGuard Release April 2020|April]]
|[[Special:MyLanguage/HITGuard Release Juli 2020|July]]
|[[Special:MyLanguage/HITGuard Release Oktober 2020|October]]
|-
!2019
|[[Special:MyLanguage/HITGuard Release März 2019|March]], [[Special:MyLanguage/HITGuard Release April 2019|April]]
|[[Special:MyLanguage/HITGuard Release Juli 2019|July]]
|[[Special:MyLanguage/HITGuard Release Dezember 2019|December]]
|}


Release Notes from the years 2017 and 2018 were directly integrated into the help.
Release Notes from the years 2017 and 2018 were directly integrated into the help.


==Login options and supported authentication providers==
* [[Special:MyLanguage/Login Möglichkeiten|Login options]]
* [[Special:MyLanguage/Passkeys|Passkeys]]
* [[Special:MyLanguage/2FA|2-factor-authentication]]


== Login Möglichkeiten und unterstützte Authentication Provider ==
== Installation assistance ==
* [[Special:MyLanguage/Login Möglichkeiten|Login Möglichkeiten]]
*[[Special:MyLanguage/Installationshilfe |Installation assistance]]

Aktuelle Version vom 26. August 2025, 07:23 Uhr

Welcome to HITGuard Help!

HITGuard offers you comprehensive support in managing and monitoring your risks and compliance requirements. In the menu navigation of HITGuard you will find various modules that support you in meeting your IT governance, risk management and compliance requirements.

This user help provides you with detailed information on how to use each of the HITGuard modules and describes the contents of the entire available menu.

We have designed this user help to be useful for beginners and experienced users alike. If you have any questions or need help, our support team will be happy to assist you if you contact us under support@hitguard.at.

We hope that this user guide will help you to get the most out of HITGuard. Thank you for choosing our solution!

The HITGuard menu

Find the help pages for all possible menu items of the individual modules here:

HITGuard basic modules

The Risk management, Measures, and Controls, as well as Administration are always available in HITGuard and form the basis of the tool:

Risk management The Risk management module helps you identify and assess risks and opportunities, and provides you with a central platform to manage your risk assessments. You can freely configure your risk policy and use different workflows that support you in your risk management.

Find a rough overview of the risk and opportunity workflow here.
Find information on risks and opportunities for Practitioners here.
Measures The Measures module helps you implement measures to eliminate or reduce risks and security gaps. You can monitor the implementation of your measures with progress reports and test their effectiveness.

Find a rough overview of the measure workflow here.
Find information on measures for Practitioners here.
Controls The Controls module allows you to manage and evaluate your controls and their effectiveness. You can create control definitions and track the execution of the corresponding controls.

Find a rough overview of the control workflow here.
Find information on controls for Practitioners hier.
Administration In the Administration module, you can configure HITGuard and adapt it to your specific requirements. Here you will also find functions for managing user accounts, roles and teams as well as for integrating HITGuard into existing systems and processes.

HITGuard Add-ons

There are various extensions for HITGuard in order to cover further use cases.

Data protection The Data Protection module helps you comply with data protection regulations and policies.

With an activated data protection add-on you receive the menu item "Data protection", the contents of which you can find below. Data protection is licensed separately and can be activated under Administration > Management systems for one management system.

Find a rough overview of the PA workflow here.
Find more on working with PAs for Practitioners here.
Audit management The Audit management module allows you to conduct internal and external audits, track the results and generate reports.

With an activated audit management add-on you receive the menu item "Audit management", the contents of which you can find below. Audit management is licensed separately and can be activated under Administration > Management systems for one or more management systems.
Case management The Case management module supports you in handling security incidents and breaches of policies and regulations.

With an activated case management add-on you receive the menu item "Case management", the contents of which you can find below. Case management is licensed separately and can be activated under Administration > Management systems for one or more management systems.
Doc management The module Doc management encapsulates document control, uploaded attachments, and the report archive.

With an activated doc management add-on you receive the menu item "Doc management", the contents of which you can find below. Doc management is licensed separately and can be activated for you by your contact person at TogetherSecure.

Find a rough overview of the doc management workflow here.
Find information on the review and approval workflow here.
ESG management The ESG module supports you in the execution of the double materiality analysis.

With an activated ESG management add-on your risk management is extended by a few menu items. ESG management is licensed separately and can be activated for you by your contact person at TogetherSecure.

Find more on ESG management here.
Supplier risk management The Supplier Risk Management module allows you to send reviews to suppliers and thus include them in your audit processes.

With an activated supplier risk management add-on your administration and reviews are extended by a few menu items and options. Supplier risk management is licensed separately and can be activated for you by your contact person at TogetherSecure.

Find more on supplier risk management here.

Under How To Start you find the first steps for implementing a management system and for all the add-ons.

The HITGuard interface

Click to enlarge
Click to enlarge

The screenshot gives information about the various areas of the HITGuard interface. In the top left corner you find the profile area of the logged-in user and below it the main menu. A click onto the profile picture takes you to the page Manage account. There, a user can modify their data, update their profile picture, or change the password.

The marked areas in the image show:

  1. Intro for the current page: If the current page has an interactive introduction, it can be started via this icon.
  2. Collapse/expand menu: With this button, the navigation menu can be collapsed, or expanded again.
  3. Switch management system: If the user is authorized for multiple management systems, they can switch between them here. This option is not shown for practitioners or users only authorized for a single management system.
  4. Current management tasks, logout, and change language:
    • You receive information about your current management tasks via the envelope.
    • You can configure a page's accessibility with the person-symbol.
    • The flag can be used to switch between English and German.
    • The logout button logs you out.

The menu starts off with the "personal" menu items My tasks and My dashboards. These are follows by the menu items of the individual HITGuard modules. The user only sees those modules they are authorized for. Following the module menu items is the menu item Help.

My tasks

My tasks
My tasks

Under "My tasks" you will find the tasks you have to complete in your role as a practitioner. The menu on the left shows you at a glance if you have any pending tasks (orange number badge). This menu shows all items that are activated in at least one management system.

A click into the My tasks menu opens the Task dashboard. Here, you find a summary of all the tasks pending completion. In addition, clicking on My tasks opens a submenu that lets you view the tasks by type. There, you also find tasks you have already completed. Orange badges show how many taks you need to work on (e.g., requested progress reports or PAs to be reviewed). Blue badges show how many tasks, for which you are also responsible, somebody else needs to work on (e.g., reviews for which you are responsible but not an interview partner).

The states of the different elements are also explained here:

Menu items: Measures Controls Reviews PAs Risks & opportunities Tickets

My dashboards

Dashboards are for getting an overview of the management systems by using key performance indicators (KPIs) and for preparing the reports that are needed regularly. By default, each management system has a dashboard for information related to risk management, to measures, and to controls. Data protection management systems also have a dedicated data protection dashboard, case management systems have a case management dashboard, and audit management systems have an audit management dashboard. However, only dashboards, KPIs, and reports for which the user is authorized are displayed.

In order for a user to access a dashboard and the KPIs and reports of the respective section, they need the "Expert", "Professional" or "Observer" role in the respective module. Thus, to view the risk management dashboard, at least the "Professional" role in risk management is required.

Additional dashboards can also be created and configured. It is possible to make these accessible only to oneself by marking them as "private". Dashboards that are not marked as "private" are visible to all authorized members of the management system. Default dashboards, as in dashboards that are delivered with HITGuard by default, can be edited and reset into their original state, but not deleted. They are marked as vendor-specific dashboards with a "tool" icon. Self-created dashboards can be deleted.

Users can mark a dashboard as a favorite in each management system. This dashboard will be ranked first for the user and displayed when the user logs in. To mark it, click the star next to the dashboard configuration.

How to create and edit dashboards as well as information on the KPIs can be found here:

Sections: Create/edit dashboards Risk management ESG Measures Controls Data protection Case management Audit management

The reports that can be created on dashboards are the same as those in the respective menu items in terms of their content and their report options. The explanations for them are found on the help pages of the reports per menu item.

Reports on dashboards offer the following additional functions:

  • Prepare multiple versions of one report: Just like KPIs, reports can be added to dashboards multiple times. The "filter" button allows you to save different configurations of the report options in order to then have access to various iterations of the same type of report at the click of a button.
Example: A risk report called "Risk report - details", with details on measures and control definitions, the overview of the gaps assigned to the risk, and its temporal evolution; so that risk owners can periodically file a detailed status of their risks. And a risk report for the top managers called "Board risk report", containing just a rough overview of the open measures and active controls; for board members to get a grasp on the current risk treatment efforts.
  • Set as default report settings: Experts and Professionals can save the option configuration of one report per report type on non-private dashboards (e.g. one risk report or one gross-net-risk report). In doing so, the report is then automatically generated with these settings from index pages (e.g. on the page Risk management → Risk evaluation, where there aren't any report options available). On the report page itself (e.g., Risk management → Reports → Risks → General) the report is also generated with these settings, but users can make individual changes to these settings. The report set as the default is marked with a star on top of the report icon.
Example: user A configures a risk report on the dashboard and sets the settings as default. User B generates a risk report from the overview on the page Risk management → risk evaluation and the contents match the default settings. User C has already adjusted the settings the way they need them on the page Risk management → Reports → Risk → General. Their individual settings are not overwritten by the default. User D is using the page Risk management → Reports → Risk → General for the very first time and sees that the report options are set the same way as defined by User A's default.

Module-specific menu items

Right after the dashboard menu items, you find the module-specific menu items. Which modules are shown here depends on the user's authorizations as well as on the features activated for the management system.

Help

Under this menu item you will find the introduction "Getting started", which gives an introduction to HITGuard's interface.

Under the menu item "Online Help" you will find our help directly integrated in HITGuard.

If there is an info icon in the lower left corner, it can be clicked to start a short introduction to the current page.

The letter: current management tasks

Management tasks

The envelope in the upper right corner informs professionals and experts about tasks that have been reported completed and are waiting for completion/review. The tasks always refer to the current management system only. Thre is also a notice if the current analysis period has expired.

In addition, the tasks are only displayed to users who are authorized to edit them. For example, answered processing activities are displayed only to users who are Data Protection professionals or experts and are currently in the Data Protection management system.

The tasks are divided into the following items:

Section Description
Progress reports Progress reports for measures that have been answered.
Risks Newly submitted or returned risks.
Protection needs analyses Answered protection needs analyses.
Gap analyses Answered gap analyses.
Tickets assigned to me Open tickets that are assigned to you. Closed and answered tickets are not displayed.
Not assigned tickets Tickets that have not yet been assigned an advisor. If a support team is configured, these tickets are only shown to members of that team.
Processing activities Answered processing activities.

User guides

FAQ

Glossary

Working with HITGuard

Experts or Professionals

Administrators or Experts

Administrators

External users

How To Start

Giudes and rough overview of the workflows

Release Notes

Year Month
2025 April August
2024 March August December
2023 February June October
2022 January June October
2021 January April September
2020 April July October
2019 March, April July December

Release Notes from the years 2017 and 2018 were directly integrated into the help.

Login options and supported authentication providers

Installation assistance