Menü aufrufen
Toggle preferences menu
Persönliches Menü aufrufen
Nicht angemeldet
Ihre IP-Adresse wird öffentlich sichtbar sein, wenn Sie Änderungen vornehmen.

Risikomanagement Einstellungen/en: Unterschied zwischen den Versionen

Aus HITGuard User Guide
Isan (Diskussion | Beiträge)
Die Seite wurde neu angelegt: „===Menus=== *Show structural analysis *Show protection needs *Show vulnerabilities *Show threats Define here which menu items are to be included in the risk management and hide those you do not need in your management system. Depending on which menu items you have in use, the corresponding report pages are also shown or hidden, respectively.“
KoKl (Diskussion | Beiträge)
Die Seite wurde neu angelegt: „===Extensions=== Define here whether ESG management is to be included in risk management and whether you would like to enable reviews to be sent to suppliers as self assessments.<p>The permissions of the Experts and Professionals for both are assigned under Administration → User roles.“
 
(8 dazwischenliegende Versionen von 2 Benutzern werden nicht angezeigt)
Zeile 5: Zeile 5:


===Risk/opportunity/impact:===
===Risk/opportunity/impact:===
*Used categories of risks and opportunities:
'''Categories of risks/opportunities used:''' Define here which categories of risks and opportunities are to be used in this management system.
::Define which categories of risks and opportunities are to be used in this management system.
'''Classification of damage extent and benefit:''' Define here the classification used in this management system for the assessment of potential damage and benefits. If you do not make a selection, the standard classification is used. One use case for a separate classification of damage extent and benefit would be, for example, to assess potential damage and benefits in the data protection management system from the perspective of the data subject. As a result, only risks/opportunities and protection need analysis weightings belonging to the associated classification are displayed by default in the risk management dashboard, in risks and opportunities, and in the structure analysis. <br><b>Attention:</b> Changing the classification may affect the informative value of already assessed risks or opportunities as well as protection need analyses already carried out in the management system.
* Extent of damage classification:
'''Show Gaps tab:''' In the risk, this tab lists the gaps, i.e. the review questions answered negatively in the [[Special:MyLanguage/Schwachstellen|gap analysis]].
:: Here, define the classification used in this management system to assess potential damage. If you do not make a selection, the default extent of damage classification will be used.
'''Show Threats tab:''' This tab lists [[Special:MyLanguage/Bedrohungen|threats]] that are linked to the risk. (You can link the threats directly, or a linked gap brings its threats along into the risk.)
:: A use case for your own extent of damage classification would be, for example, to assess potential damage in the data protection management system from the perspective of the affected party. As a result, the Risk Management dashboard, hazard situations, and structural analysis will by default only display hazard situations and SBA weightings for the associated extent of damage classification.
'''Show monetary impact in risks & opportunities:''' If you activate this item, you have an additional property in the master data page of [[Special:MyLanguage/Risikobewertung|risks & opportunities]] with which you can present the possible damage or benefit as a monetary value.<br><b>Attention:</b> Changes to this property must then be justified in the [[Special:MyLanguage/Risikobewertung#Zeitliche_Entwicklung|change log]] of the risk.
:: <b>Caution:</b> Changing the extent of damage classification potentially affects the meaningfulness of previously evaluated risks as well as protection needs analyses made in the management system.
*Show gaps tab
::Define whether the list of assigned gaps should be included in the view of risks and opportunities.
*Show threats tab
::Define whether the list of assigned threats should be included in the view of risks and opportunities.


===Modules===
===Extensions===
Define here whether the ESG management is to be included in the risk management.<p>The authorizations of the experts and professionals for the ESG are distributed under [[Special:MyLanguage/Benutzer_und_Benutzerrollen#Benutzerrollen_zuordnen|Administration → User roles]].
Define here whether ESG management is to be included in risk management and whether you would like to enable reviews to be sent to suppliers as self assessments.<p>The permissions of the Experts and Professionals for both are assigned under [[Special:MyLanguage/Benutzer_und_Benutzerrollen#Benutzerrollen_zuordnen|Administration → User roles]].


===Menus===
===Menus===
Zeile 25: Zeile 20:
*Show threats
*Show threats
Define here which menu items are to be included in the risk management and hide those you do not need in your management system. Depending on which menu items you have in use, the corresponding report pages are also shown or hidden, respectively.
Define here which menu items are to be included in the risk management and hide those you do not need in your management system. Depending on which menu items you have in use, the corresponding report pages are also shown or hidden, respectively.
===ESG thresholds===
The thresholds for the KPI "Double materiality" can be set here. For financial and impact materiality, you can set from what value on a field of action is seen as material and therefore to be reported. This is shown graphically in the KPI.
===Protection needs===
A naming template for protection needs analyses can be configured and its use be activated. If activated, new protection needs analyses are automatically named after the configured schema, but can be renamed at any time (unless they are closed).
[[Datei:SBA_Bezeichnungsvorlage.png|left|thumb|900px]]<br clear=all>
Furthermore you can configure resources of which model segment can be used in the protection needs analysis.

Aktuelle Version vom 6. August 2026, 13:29 Uhr

In "Risk management → Settings", experts can configure the risk management and add further configurations in addition to the risk policy, to adapt the risk management to the requirements of the management system.


Risk/opportunity/impact:

Categories of risks/opportunities used: Define here which categories of risks and opportunities are to be used in this management system. Classification of damage extent and benefit: Define here the classification used in this management system for the assessment of potential damage and benefits. If you do not make a selection, the standard classification is used. One use case for a separate classification of damage extent and benefit would be, for example, to assess potential damage and benefits in the data protection management system from the perspective of the data subject. As a result, only risks/opportunities and protection need analysis weightings belonging to the associated classification are displayed by default in the risk management dashboard, in risks and opportunities, and in the structure analysis.
Attention: Changing the classification may affect the informative value of already assessed risks or opportunities as well as protection need analyses already carried out in the management system. Show Gaps tab: In the risk, this tab lists the gaps, i.e. the review questions answered negatively in the gap analysis. Show Threats tab: This tab lists threats that are linked to the risk. (You can link the threats directly, or a linked gap brings its threats along into the risk.) Show monetary impact in risks & opportunities: If you activate this item, you have an additional property in the master data page of risks & opportunities with which you can present the possible damage or benefit as a monetary value.
Attention: Changes to this property must then be justified in the change log of the risk.

Extensions

Define here whether ESG management is to be included in risk management and whether you would like to enable reviews to be sent to suppliers as self assessments.

The permissions of the Experts and Professionals for both are assigned under Administration → User roles.

  • Show structural analysis
  • Show protection needs
  • Show vulnerabilities
  • Show threats

Define here which menu items are to be included in the risk management and hide those you do not need in your management system. Depending on which menu items you have in use, the corresponding report pages are also shown or hidden, respectively.

ESG thresholds

The thresholds for the KPI "Double materiality" can be set here. For financial and impact materiality, you can set from what value on a field of action is seen as material and therefore to be reported. This is shown graphically in the KPI.

Protection needs

A naming template for protection needs analyses can be configured and its use be activated. If activated, new protection needs analyses are automatically named after the configured schema, but can be renamed at any time (unless they are closed).


Furthermore you can configure resources of which model segment can be used in the protection needs analysis.