Schutzbedarf/en: Unterschied zwischen den Versionen
Weitere Optionen
Isan (Diskussion | Beiträge) Die Seite wurde neu angelegt: „<u>Responsibles:</u> * The responsible user is informed via e-mail a week before the workflow triggers. Should there be any problems or conflicts at that time, they are described in the e-mail and can thus be rectified in time. The responsible user is also informed when the workflow does trigger, so they know what was done and whether there were any problems or conflicts.“ |
KoKl (Diskussion | Beiträge) Keine Bearbeitungszusammenfassung |
||
| (64 dazwischenliegende Versionen von 3 Benutzern werden nicht angezeigt) | |||
| Zeile 10: | Zeile 10: | ||
You can download a report on one or more protection needs analyses as a PDF. This contains all marked protection needs analyses. | You can download a report on one or more protection needs analyses as a PDF. This contains all marked protection needs analyses. | ||
Special columns in the overview of protection needs analyses are: | |||
{| class="wikitable" | |||
!OU / Process | |||
|Where you usually see the organizational unit of a review, in the case of the protection needs analysis that may also be a process. | |||
|- | |||
!Next reassessment | |||
|Shows the date when a linked workflow plan triggers an automated reassessment of the protection needs analysis the next time. | |||
|- | |||
!Linked workflow plans | |||
|Shows whether and with how many workflow plans a protection needs analysis is linked and whether this plan is active, suspended, or deactivated. A click on the link opens a window that shows the workflow plans and within which you can also create new links or edit existing ones. | |||
|- | |||
|} | |||
<span id="Schutzbedarfsanalyse_erstellen/bearbeiten"></span> | <span id="Schutzbedarfsanalyse_erstellen/bearbeiten"></span> | ||
== <span id="Create protection needs analysis"></span>Create/edit protection needs analysis == | == <span id="Create protection needs analysis"></span>Create/edit protection needs analysis == | ||
Create a new protection needs analysis to gather the protection needs requirements for one, some or all of an organizational unit's or process's resources and/or data categories with a defined set of participants. | |||
<b>Create:</b> | <b>Create:</b> | ||
| Zeile 20: | Zeile 35: | ||
* To edit a protection needs analysis, open the required protection needs analysis under "Risk management → Protection needs" by double-clicking on it. | * To edit a protection needs analysis, open the required protection needs analysis under "Risk management → Protection needs" by double-clicking on it. | ||
* Completed protection needs analyses can be viewed, but no longer edited! | * Completed protection needs analyses can be viewed, but no longer edited! | ||
<b>Caution:</b> Make sure that before creating the PNA you have configured the background settings according to your preferences (Organizational form in Global settings, model segments and name generation under [[Special:MyLanguage/Risikomanagement_Einstellungen|Risk management > Settings]], protection goals and extent of damage in the Risk policy). More on this can be found as the article progresses. | |||
<span id="Kopfdaten_der_Schutzbedarfsanalyse"></span> | <span id="Kopfdaten_der_Schutzbedarfsanalyse"></span> | ||
| Zeile 32: | Zeile 49: | ||
<u>Select OrgUnit/Process:</u> | <u>Select OrgUnit/Process:</u> | ||
*In a protection needs analysis, either organizational units or processes can be analyzed | *In a protection needs analysis, either organizational units or processes can be analyzed. | ||
* This selection can only be changed as long as no resources were assigned in step 2. To be able to change the selection, the assigned resources must first be removed in step 2. | * This selection can only be changed as long as no resources were assigned in step 2. To be able to change the selection, the assigned resources must first be removed in step 2. | ||
* In the [[Special:MyLanguage/Globale_Einstellungen|Global settings]] you can configure with the organizational form, whether HITGuard should by default propose organizational units or processes for the analysis. This can be changed when creating the protection needs analysis. | |||
<u>Audit:</u> | <u>Audit:</u> | ||
| Zeile 43: | Zeile 57: | ||
<u>OrgUnit/Process:</u> | <u>OrgUnit/Process:</u> | ||
* Depending on whether an OrgUnit or a process is analyzed, either the organizational unit or the process is selected here. | * Depending on whether an OrgUnit or a process is analyzed (see first decision), either the respective organizational unit or the respective process is selected here. | ||
* This can no longer be changed after the first | * This can no longer be changed after the resources and/or data categories have been assigned! | ||
::<u>Note</u>: If an organizational unit or a process already have a relationship to resources and/or data categories in the structural analysis, those will automatically be proposed to be added in step 2 of the protection needs analysis. Any protection needs analyses already done are also considered here. In addition, it's possible to adopt the previous analysis' results with the click of a button. The results can also be adopted later for each resource/data category. | |||
::<u>Caution</u>: Resources and data categories that already have an as yet open protection needs analysis in connection with the selected organizational unit or process are not automatically proposed and cannot be added manually either. To add them, any open protection needs analyses in the respective constellation must be closed first. | |||
<u>Function:</u> | <u>Function:</u> | ||
| Zeile 53: | Zeile 71: | ||
<u>Name:</u> | <u>Name:</u> | ||
* The name of the protection needs analysis is entered here. | * The name of the protection needs analysis is entered here. | ||
* If you have configured the setting under Risk management > Settings, the name is generated automatically. | |||
<u>Description:</u> | <u>Description:</u> | ||
| Zeile 75: | Zeile 94: | ||
<u>Workflow plans:</u> | <u>Workflow plans:</u> | ||
* | [[Datei:wfpverkn.png|right|thumb|70px|A linked workflow plan]]* Here HITGuard displays how many workflow plans the protection need analysis occurs as active or paused. Here you can create or remove links, or pause existing links. Deactivated workflow plans are not offered for linking. | ||
<br clear=all> | |||
<u>Created by workflow plan:</u> | <u>Created by workflow plan:</u> | ||
| Zeile 92: | Zeile 112: | ||
<b>Draft</b> | <b>Draft</b> | ||
* When the protection needs analysis is saved for the first time or deactivated from the "In progress" status, it is in the "Draft" status. From here, the protection needs analysis can be activated, i.e. set to the "In progress" status. | * When the protection needs analysis is saved for the first time or deactivated from the "In progress" status, it is in the "Draft" status. From here, the protection needs analysis can be activated, i.e. set to the "In progress" status. | ||
* Even in draft status, you can add assets in the protection need analysis. This creates a connection between org unit/process and resource/data category. HITGuard will already create these connections as arrow relationships in the [[Special:MyLanguage/Strukturanalyse|structural analysis]]. However, until the protection need analysis is fully completed, all protection targets in the structural analysis are weighted at 100%. | |||
[[Datei:Schutzbedarfsanalyse Status wechseln.PNG|right]] | [[Datei:Schutzbedarfsanalyse Status wechseln.PNG|right]] | ||
| Zeile 112: | Zeile 134: | ||
<b>Closed</b> | <b>Closed</b> | ||
* If the protection needs analysis is set to the status "Closed" by selecting "Complete review", the protection needs analysis becomes read-only and it can no longer be edited. This sets and weights the links between the resources and/or data to the OrgUnit or process in the structural analysis. | * If the protection needs analysis is set to the status "Closed" by selecting "Complete review", the protection needs analysis becomes read-only and it can no longer be edited. This sets and weights the links between the resources and/or data to the OrgUnit or process in the structural analysis. | ||
* Only after the protection needs analysis is closed, HITGuard will imclude these values int the connections in the [[Special:MyLanguage/Strukturanalyse|structural analysis]]. Before that, the relationships are simply 100%. | |||
<b>Delete a protection needs analysis</b>. | <b>Delete a protection needs analysis</b>. | ||
| Zeile 123: | Zeile 146: | ||
The second step is to select the resources and/or data that will be analyzed in the protection needs analysis. | The second step is to select the resources and/or data that will be analyzed in the protection needs analysis. | ||
[[Datei:Schutzbedarfsanalyse S2 Ressourcen.png|center|thumb|600px|Linking the resources and data]] | |||
<br clear=all> | |||
[[Datei:SBA_Schritt2_ButtonKurz.png|right|thumb|400px|Overview of the resources and data]] [[Datei:BIA_Schritt2Modal_highlighted.png|right|thumb|400px|Adding resources and data]] | |||
* '''Import button:''' With the first button (with the curved arrow, visible in the upper screenshot) you can add ''already connected'' resources or data to the analysis. Resources can already be connected for two reasons: either you have set a manual relationship (e.g. in the [[Special:MyLanguage/Strukturanalyse#Beziehungen_erstellen_/_bearbeiten|structural analysis]]), or you have previously carried out a protection need analysis for this connection. In the latter case, you can also adopt the historical rating results of the old assessment. | |||
* If the connection (org unit/process to resource/data category) is already being assessed in an open protection needs analysis, you cannot add it. In this case, an info text will point this out to you. | |||
* '''Link button:''' To add new resources or data to the analysis, click the second button. A dialogue then opens (in the lower screenshot to the right). Here you select the resources or data categories to be analysed. Resources are available if they belong to those model segment levels that you selected under Risk management > Settings. (By default, the business service level and the application level are activated.) You can switch between resources and data via the tab. | |||
<br clear=all> | |||
<u>Tip</u>: Changes (creation/update/deletion) to resources and data categories lead to an automatic update of open protection needs analyses. This allows you to create or modify resources and data categories in a separate browser tab and then use them in the PNA right away, without havingt to reload it. | |||
<u> | <u>Note</u>: The adding and removing of resources and data categories is also available to Practitioners when answering a PNA as a self assessment. | ||
<u>Tip</u>: If the connection (org unit/process to resource/data category) is already being assessed in an open protection needs analysis, you cannot add it. In this case, an info text will point this out to you. Several protection needs analyses can also exist for one org unit or process, as long as these assess different resources and/or data categories. Resources/data categories that are already being assessed for an org unit/process in an ''open'' protection need analysis cannot be added. If you close the already existing protection needs analysis, you can use the resources/data categories again. | |||
<span id="Mögliche_Schäden_analysieren"></span> | <span id="Mögliche_Schäden_analysieren"></span> | ||
| Zeile 146: | Zeile 172: | ||
In this step, the resources and/or data are analyzed for possible damage that could occur if a protection target is violated. Violations are evaluated by the extent of damage. If there are results from earlier analyses, the justifications can be taken over with a double click into the respective line. The button in the top right corner allows you to adopt all results with one click. | In this step, the resources and/or data are analyzed for possible damage that could occur if a protection target is violated. Violations are evaluated by the extent of damage. If there are results from earlier analyses, the justifications can be taken over with a double click into the respective line. The button in the top right corner allows you to adopt all results with one click. | ||
The extents of damage selected here are used in the structural analysis to set connections between the OrgUnit or process and the assessed resource or data and to weight their protection targets. This makes it possible in the structural analysis to examine the organizational unit or the process for dependencies and to identify risks. | The extents of damage selected here are used in the structural analysis to set connections between the OrgUnit or process and the assessed resource or data and to weight their protection targets. This makes it possible in the structural analysis to examine the organizational unit or the process for dependencies and to identify risks.<p> | ||
<b>Important:</b> This can lead to protection needs analysis evaluations and relationships on different levels. However, resources still always inherit the highest/most critical protection need from their chain of relationships, even if directly in a PNA they were evaluated as less important.<p> | |||
<u>Beispiel:</u> The application BankingPortal has inherited a high protection need from its existing relationships. Now, the application level was activated for protection needs analyses in addition to the business service level, so the FICO department can evaluate how important that application is to them. In the analysis the application is rated as not at all important and a new relationship is created between the department and the resource. Still, the protection need of the application remains high, because a lower protection need does not overwrite a higher one.<p> | |||
To evaluate all resources and data, it is necessary to switch between the added resources and data via the bar to the left or the "Next" button. | To evaluate all resources and data, it is necessary to switch between the added resources and data via the bar to the left or the "Next" button.<p> | ||
The protection targets to be evaluated are specified by the management system and can be configured by experts under [[Special:MyLanguage/Managementsysteme#stam|"Administration → Management Systems → Used protection targets"]]. | The protection targets to be evaluated are specified by the management system and can be created under [[Special:MyLanguage/Risikopolitik|"Risk management → Risk policy"]] and configured by experts under [[Special:MyLanguage/Managementsysteme#stam|"Administration → Management Systems → Used protection targets"]].<p> | ||
Extents of damage can be created and managed by experts under [[Special:MyLanguage/Risikopolitik#Schadensausma.C3.9Fe|"Risk management → Risk policy → Extents of damage"]]. | Extents of damage can be created and managed by experts under [[Special:MyLanguage/Risikopolitik#Schadensausma.C3.9Fe|"Risk management → Risk policy → Extents of damage"]].<p> | ||
<span id="Schutzbedarfsanalyse_neubewerten"></span> | <span id="Schutzbedarfsanalyse_neubewerten"></span> | ||
==Reassess protection needs analysis== | ==Reassess protection needs analysis== | ||
[[Datei:SBA_NeubewertenModal.png|right| | [[Datei:SBA_NeubewertenModal.png|right|600px|thumb|Create reassessment with reassess button]] | ||
A protection needs analysis can be reassessed | A protection needs analysis can be reassessed so long as there is no more current/younger PNA which evaluates at least one same resource or data category for the OrgUnit/process. In addition, the protection needs analysis needs to have been closed for the revaluation. | ||
There are different ways of creating a reassessment: | There are different ways of creating a reassessment: | ||
# Plus button: Create a new protection needs analysis for an organizational unit/a process for which there already exists a closed protection needs analysis. In this case the tool automatically proposes the evaluated resources and/or data categories for adoption in step 2. Any results can be adopted optionally. | # Plus button: Create a new protection needs analysis for an organizational unit/a process for which there already exists a closed protection needs analysis. In this case the tool automatically proposes the evaluated resources and/or data categories for adoption in step 2. Any results can be adopted optionally. | ||
# Revaluate button: Create a revaluation via the revaluate button in the overview of protection needs analyses. In this case the tool creates a new protection needs analysis on the basis of the previous one. Here, too, previous results can be adopted. | # Revaluate button: Create a revaluation via the revaluate button in the overview of protection needs analyses. In this case the tool creates a new protection needs analysis on the basis of the previous one. Here, too, previous results can be adopted. You set the begin date yourself and the end date is calculated from the data of the original protection needs analysis and preset, but can be changed. | ||
Adopt results: | Adopt results: | ||
* If activated, the results of the base protection needs analysis are adopted in the creation of the new one. These are the evaluations of the protection targets that were recorded. <br clear=all> | * If activated, the results of the base protection needs analysis are adopted in the creation of the new one. These are the evaluations of the protection targets that were recorded. <br clear=all> | ||
<u>Example:</u> When do I want to create a new protection needs analysis and when a reassessment? As a rule of thumb, the first protection needs analysis should be done together in the form of an interview. This way, everything can be talked about in detail and any questions can be clarified. When new persons enter the circle of participants or when there is a change in the linked resources and/or data categories, an interview appointment can be helpful as well. For this, a new protection needs analysis is created, even if previous results are adopted. Once this first hurdle is overcome, regular, e.g., annual, reassessments of the same resources and/or data categories can be sent out as self assessments. In this case, the same persons take part in the analysis and the same resources and/or data categories are talked about as before. Basically, you are just checking whether anything has changed in the protection needs in the meantime, e.g., the last year. Here, the workflow plans offer support. | |||
<span id="Workflowpläne"></span> | <span id="Workflowpläne"></span> | ||
==Workflow plans== | ==Workflow plans== | ||
A click on the purple button above the overview of protection | [[Datei:WFPbutton.png|right|thumb|100px]]A click on the purple button above the grid overview of the protection requirement analyses opens a list of all exisiting workflow plans (of this management system).<p> Workflow plans exist to trigger the one-time or recurring execution of workflows in an automated manner. You can find out more about this in the article on [[Special:MyLanguage/Workflowpläne|workflow plans]]. | ||
Workflow plans for protection needs analyses work with reassessments. When the workflow plan is triggered, a new protection needs analysis is created that is based on the template of the old one. The original analysis remains untouched and write-protected in the system. When you link an analysis with the workflow plan, HITGuard will ask for the setting for copying ("taking over") earlier results. If the checkbox is activated, HITGuard copies all values from the old into the new protection requirement analysis. You can later view and edit this checkbox directly in the overview of the linked protection requirement analyses. <p> | |||
== | ==Protection needs analyses can block each other!== | ||
Protection needs analyses (PNAs) can block each other. This means that an already existing PNA prevents you from being able to create another, new PNA. This happens when the old and the new PNA assess the same relationship (e.g. between an OrgUnit and a resource). Even if they assess many other relationships, a single "overlapping" relationship is enough to block the new PNA. | |||
[[ | The blocking can happen within a single management system or across several management systems. However, PNAs always remain in the [[Special:MyLanguage/Managementsysteme|management system]] in which they were created. | ||
<b> | <b>Blocking within a single management system</b> | ||
[[Datei:SBAwarnung.png||right|thumb|500px|Blocking warning from HITGuard]] | |||
Within a single management system, a PNA is blocked if there is already an older PNA that assesses the same relationship and is not yet completed. If, for example, you have already created a PNA that interviews the OrgUnit "Finance" and collects information on the resource "Banking Portal", you cannot create a new PNA that assesses the same relationship (Finance → Banking Portal). In the screenshot on the right you see how HITGuard points this out to you at step two of the new PNA. <p> However, if you complete the PNA, you can carry out a reassessment without any problems. <br clear="all"> | |||
<b>Blocking across several management systems</b><p> | |||
<b> | If there are <i>several</i> management systems in which you carry out protection needs analyses, protection needs analyses can block each other across management systems. As long as a PNA is open somewhere, it is not possible to assess the same relationship in another management system, exactly as in the case of a single management system. | ||
With several management systems, reassessments are also blocked in this way. You could, for example, assess the relationship between the business process "Payroll" and the data category "Employee data" in the two management systems "ISMS" and "Data protection". But if the PNA in "ISMS" is still open, you cannot reassess the PNA in "Data protection". Because these are two different management systems, both the [[Special:MyLanguage/Risikopolitik#Schadensausmaße|impact levels]] and the [[Special:MyLanguage/Risikopolitik#Schutzziele|protection targets]] can be different. However, this has no influence on the behavior described above. | |||
< | [[Datei:PlusNeubew.png||right|thumb|100px|Plus and Reassess button]] Even if you have closed the protection needs analysis in other management systems, you may under certain circumstances not be able to use the <b>Reassess button</b>. This means you have to create the protection needs analysis with the plus button, select the OrgUnit and then, in step two, "Add all connected resources and data categories". Then you can save this PNA. HITGuard will understand that this new PNA is a reassessment. You can only use the Reassess button if the original PNA that you are reassessing is the most recent in the entire system. The Reassess function namely automatically accesses the most recent BIA. | ||
If you use <b>workflow plans</b> for your protection needs analyses, HITGuard will show you warnings if another PNA blocks the reassessment through the workflow plan (see above for more details). You can only add a PNA to a workflow plan if the PNA is the most recent in the system. If your colleagues have in the meantime created a PNA in another management system, your PNA no longer appears in the overview. | |||
<b> | |||
==Tips, | ==Tips, Tricks & Best Practice== | ||
[[Datei:BESTPRACTICE.png|left|thumb|100px]] | [[Datei:BESTPRACTICE.png|left|thumb|100px]] Relationships in the structural analysis generally lead to the highest protection need. These dependences can be reduced with a protection needs analysis. One should therefore start with the analysis of those assets/resources/services that are most important to the organization and evaluate them regarding the requirements of the management system first.<p> | ||
Relationships in the structural analysis generally lead to the highest protection need. These dependences can be reduced with a protection needs analysis. One should therefore start with the analysis of those assets/resources/services that are most important to the organization and evaluate them regarding the requirements of the management system first.<br clear=all> | It makes sense to spread protection needs analyses across multiple workflow plans so they can be reassessed throughout the year, e.g., some in the spring and some in autumn. If, for example, you have created a workflow plan for the spring and one for the fall and those repeat annually, and you have an especially sensitive organizational unit that needs to be reassessed twice a year (in the spring and the fall), you can add the protection needs analysis to both the workflow plans.<p> | ||
If the circle of participants for a protection needs analysis changes, if many new resources/data categories are adde4d, or if there hasn't been a personal interview in a longer while, then we also recommend a manual reassessment as an interview.<p> | |||
If a protection needs analysis is assigned to a workflow plan and a reassessment is triggered manually (via the revaluate button), then this new protection needs analysis is assigned as the basis for the next workflow in the linked protection needs analyses. If the reassessment is deleted, the link is reset to the original protection needs analysis. Caution: if a new protection needs analysis revaluating resources/data categories was created with the plus button, this link is not established and it may cause conflicts.<p> | |||
The validation of which protection needs analysis is the youngest/the most current, considers the start date as well as the moment the protection needs analysis was closed. If multiple PNAs are available at the time ogf reassessing, HITGuard shows which one is the youngest/most current.<br clear=all> | |||
Aktuelle Version vom 5. August 2026, 14:46 Uhr
What is a protection needs analysis?
The protection needs analysis determines the protection needs for data or resources (IT systems, buildings, software, etc.) of organizational units or processes. The results of this analysis, the protection needs of the data and processes, can be examined in the structural analysis, for example, to identify risks and create measures and controls accordingly.

As can be seen in the figure above, professionals and experts can find protection requirement analyses that have been created in the current management system under "Risk management → Protection needs". All protection requirement analyses are displayed, regardless of whether they are completed, in progress or in draft status. Likewise, protection requirement analyses can be created or reassessed here, and workflow plans can be created.
You can download a report on one or more protection needs analyses as a PDF. This contains all marked protection needs analyses.
Special columns in the overview of protection needs analyses are:
| OU / Process | Where you usually see the organizational unit of a review, in the case of the protection needs analysis that may also be a process. |
|---|---|
| Next reassessment | Shows the date when a linked workflow plan triggers an automated reassessment of the protection needs analysis the next time. |
| Linked workflow plans | Shows whether and with how many workflow plans a protection needs analysis is linked and whether this plan is active, suspended, or deactivated. A click on the link opens a window that shows the workflow plans and within which you can also create new links or edit existing ones. |
Create/edit protection needs analysis
Create a new protection needs analysis to gather the protection needs requirements for one, some or all of an organizational unit's or process's resources and/or data categories with a defined set of participants.
Create:
- Protection needs analyses can be created under "Risk Management → Protection needs" via the "Plus" button.
Edit:
- To edit a protection needs analysis, open the required protection needs analysis under "Risk management → Protection needs" by double-clicking on it.
- Completed protection needs analyses can be viewed, but no longer edited!
Caution: Make sure that before creating the PNA you have configured the background settings according to your preferences (Organizational form in Global settings, model segments and name generation under Risk management > Settings, protection goals and extent of damage in the Risk policy). More on this can be found as the article progresses.
Header data of the protection needs analysis
The following section describes the mapping in more detail:

Select OrgUnit/Process:
- In a protection needs analysis, either organizational units or processes can be analyzed.
- This selection can only be changed as long as no resources were assigned in step 2. To be able to change the selection, the assigned resources must first be removed in step 2.
- In the Global settings you can configure with the organizational form, whether HITGuard should by default propose organizational units or processes for the analysis. This can be changed when creating the protection needs analysis.
Audit:
- If this protection needs analysis is carried out in the course of an audit, you can relate the audit to the protection needs analysis here. If the protection needs analysis arises as a result of an audit, the fields lead auditor, interview partner, and start and end date of the audit are populated. Alternatively, the header data can be incorporated via the button on the right. (For more on audits, see Audit planning).
OrgUnit/Process:
- Depending on whether an OrgUnit or a process is analyzed (see first decision), either the respective organizational unit or the respective process is selected here.
- This can no longer be changed after the resources and/or data categories have been assigned!
- Note: If an organizational unit or a process already have a relationship to resources and/or data categories in the structural analysis, those will automatically be proposed to be added in step 2 of the protection needs analysis. Any protection needs analyses already done are also considered here. In addition, it's possible to adopt the previous analysis' results with the click of a button. The results can also be adopted later for each resource/data category.
- Caution: Resources and data categories that already have an as yet open protection needs analysis in connection with the selected organizational unit or process are not automatically proposed and cannot be added manually either. To add them, any open protection needs analyses in the respective constellation must be closed first.
Function:
- Is only displayed, if it was activated under "Audit management → Settings"
- Functions allow you to optionally further define the context of a review.
- Functions can be created and managed under "Audit management → Functions".
Name:
- The name of the protection needs analysis is entered here.
- If you have configured the setting under Risk management > Settings, the name is generated automatically.
Description:
- The purpose of the protection needs analysis should be described here.
Lead auditor:
- The main examiner responsible for the protection needs analysis is entered here. They select the resources and/or data that will be analyzed in the course of the protection needs analysis. They determine additional examiners as well as interview partners.
Co-auditors/Companion(s):
- These are individuals who are included as subject matter experts for the protection needs analysis.
Interview partners:
- Interviews about resources and data are conducted with these individuals during the course of a protection needs analysis. In the course of a self assessment, they are tasked with identifying potential damages (see type).
- The users are pre-filled with those set as responsible for the selected organizational unit or process.
Start and end date:
- The planned time span of the protection needs analysis is entered here.
Type:
- Interview: The protection needs analysis is conducted together with the interview partner. The interview partner themselves cannot change anything in the protection needs analysis, but has insight into the analysis.
- Self assessment: the interview partner is tasked with determining possible damage in the event of violations of protection targets. The auditor requests a response via the "Request response" button (if the protection needs analysis has been activated) and reviews it after it has been answered.
Workflow plans:

* Here HITGuard displays how many workflow plans the protection need analysis occurs as active or paused. Here you can create or remove links, or pause existing links. Deactivated workflow plans are not offered for linking.
Created by workflow plan:
- If the protection needs analysis was created by a workflow, the respective workflow is shown here. You can navigate into the workflow with a simple click and take a look at its details.
Change log:
- Here, it is recorded at what time the protection needs analysis was edited, when the status changed, and when it was completed.
Status and deletion of a protection needs analysis
A protection needs analysis can have different status variations. If the e-mail notifications are active in the management system, all persons relevant in the workflow are prompted to perform their tasks when the status changes. This would be, for example, the interview partner when an auditor requests a response or the auditor themselves when the response is returned.
Draft
- When the protection needs analysis is saved for the first time or deactivated from the "In progress" status, it is in the "Draft" status. From here, the protection needs analysis can be activated, i.e. set to the "In progress" status.
- Even in draft status, you can add assets in the protection need analysis. This creates a connection between org unit/process and resource/data category. HITGuard will already create these connections as arrow relationships in the structural analysis. However, until the protection need analysis is fully completed, all protection targets in the structural analysis are weighted at 100%.
In progress
- If the review is activated, it will be set to the status "In progress". Now it is time for the lead auditor to perform the protection needs analysis or to request a response from the interview partner(s) by "Request response" (only for the type self assessment).
- It can be returned to the "Draft" status by selecting "Deactivate review".
- It can be moved to the "Closed" status by selecting "Close review".
Requested (only for self assessments)
- If the protection needs analysis is requested by the lead auditor, it is placed in the status "Requested". The interview partner(s) will now be prompted via e-mail to perform the protection needs analysis.
- It can be placed in the status "Answered" status by selecting "Submit review".
Answered (only for self assessments)
- If the protection needs analysis is returned by the interview partner via "Submit review", it is set to the status "Answered". The auditors are now prompted via e-mail to check the response.
- It can be returned to the status "Requested" by selecting "Request response" again. The interview partner should then revise their response.
- It can be put back into the status "Draft" by selecting "Disable review". The auditors will be informed of this.
- It can be moved to the status "Closed" by selecting "Close review".
Closed
- If the protection needs analysis is set to the status "Closed" by selecting "Complete review", the protection needs analysis becomes read-only and it can no longer be edited. This sets and weights the links between the resources and/or data to the OrgUnit or process in the structural analysis.
- Only after the protection needs analysis is closed, HITGuard will imclude these values int the connections in the structural analysis. Before that, the relationships are simply 100%.
Delete a protection needs analysis.
- By "Delete review" you can delete protection needs analyses that are not completed yet. Completed protection needs analyses cannot be deleted!
Select resources and/or data for analysis
The second step is to select the resources and/or data that will be analyzed in the protection needs analysis.



- Import button: With the first button (with the curved arrow, visible in the upper screenshot) you can add already connected resources or data to the analysis. Resources can already be connected for two reasons: either you have set a manual relationship (e.g. in the structural analysis), or you have previously carried out a protection need analysis for this connection. In the latter case, you can also adopt the historical rating results of the old assessment.
- If the connection (org unit/process to resource/data category) is already being assessed in an open protection needs analysis, you cannot add it. In this case, an info text will point this out to you.
- Link button: To add new resources or data to the analysis, click the second button. A dialogue then opens (in the lower screenshot to the right). Here you select the resources or data categories to be analysed. Resources are available if they belong to those model segment levels that you selected under Risk management > Settings. (By default, the business service level and the application level are activated.) You can switch between resources and data via the tab.
Tip: Changes (creation/update/deletion) to resources and data categories lead to an automatic update of open protection needs analyses. This allows you to create or modify resources and data categories in a separate browser tab and then use them in the PNA right away, without havingt to reload it.
Note: The adding and removing of resources and data categories is also available to Practitioners when answering a PNA as a self assessment.
Tip: If the connection (org unit/process to resource/data category) is already being assessed in an open protection needs analysis, you cannot add it. In this case, an info text will point this out to you. Several protection needs analyses can also exist for one org unit or process, as long as these assess different resources and/or data categories. Resources/data categories that are already being assessed for an org unit/process in an open protection need analysis cannot be added. If you close the already existing protection needs analysis, you can use the resources/data categories again.
Analyze possible damages
The following figure shows the third step of the protection needs analysis (e.g., 2.1 or 2.2).

In this step, the resources and/or data are analyzed for possible damage that could occur if a protection target is violated. Violations are evaluated by the extent of damage. If there are results from earlier analyses, the justifications can be taken over with a double click into the respective line. The button in the top right corner allows you to adopt all results with one click.
The extents of damage selected here are used in the structural analysis to set connections between the OrgUnit or process and the assessed resource or data and to weight their protection targets. This makes it possible in the structural analysis to examine the organizational unit or the process for dependencies and to identify risks.
Important: This can lead to protection needs analysis evaluations and relationships on different levels. However, resources still always inherit the highest/most critical protection need from their chain of relationships, even if directly in a PNA they were evaluated as less important.
Beispiel: The application BankingPortal has inherited a high protection need from its existing relationships. Now, the application level was activated for protection needs analyses in addition to the business service level, so the FICO department can evaluate how important that application is to them. In the analysis the application is rated as not at all important and a new relationship is created between the department and the resource. Still, the protection need of the application remains high, because a lower protection need does not overwrite a higher one.
To evaluate all resources and data, it is necessary to switch between the added resources and data via the bar to the left or the "Next" button.
The protection targets to be evaluated are specified by the management system and can be created under "Risk management → Risk policy" and configured by experts under "Administration → Management Systems → Used protection targets".
Extents of damage can be created and managed by experts under "Risk management → Risk policy → Extents of damage".
Reassess protection needs analysis

A protection needs analysis can be reassessed so long as there is no more current/younger PNA which evaluates at least one same resource or data category for the OrgUnit/process. In addition, the protection needs analysis needs to have been closed for the revaluation.
There are different ways of creating a reassessment:
- Plus button: Create a new protection needs analysis for an organizational unit/a process for which there already exists a closed protection needs analysis. In this case the tool automatically proposes the evaluated resources and/or data categories for adoption in step 2. Any results can be adopted optionally.
- Revaluate button: Create a revaluation via the revaluate button in the overview of protection needs analyses. In this case the tool creates a new protection needs analysis on the basis of the previous one. Here, too, previous results can be adopted. You set the begin date yourself and the end date is calculated from the data of the original protection needs analysis and preset, but can be changed.
Adopt results:
- If activated, the results of the base protection needs analysis are adopted in the creation of the new one. These are the evaluations of the protection targets that were recorded.
Example: When do I want to create a new protection needs analysis and when a reassessment? As a rule of thumb, the first protection needs analysis should be done together in the form of an interview. This way, everything can be talked about in detail and any questions can be clarified. When new persons enter the circle of participants or when there is a change in the linked resources and/or data categories, an interview appointment can be helpful as well. For this, a new protection needs analysis is created, even if previous results are adopted. Once this first hurdle is overcome, regular, e.g., annual, reassessments of the same resources and/or data categories can be sent out as self assessments. In this case, the same persons take part in the analysis and the same resources and/or data categories are talked about as before. Basically, you are just checking whether anything has changed in the protection needs in the meantime, e.g., the last year. Here, the workflow plans offer support.
Workflow plans

A click on the purple button above the grid overview of the protection requirement analyses opens a list of all exisiting workflow plans (of this management system).
Workflow plans exist to trigger the one-time or recurring execution of workflows in an automated manner. You can find out more about this in the article on workflow plans. Workflow plans for protection needs analyses work with reassessments. When the workflow plan is triggered, a new protection needs analysis is created that is based on the template of the old one. The original analysis remains untouched and write-protected in the system. When you link an analysis with the workflow plan, HITGuard will ask for the setting for copying ("taking over") earlier results. If the checkbox is activated, HITGuard copies all values from the old into the new protection requirement analysis. You can later view and edit this checkbox directly in the overview of the linked protection requirement analyses.
Protection needs analyses can block each other!
Protection needs analyses (PNAs) can block each other. This means that an already existing PNA prevents you from being able to create another, new PNA. This happens when the old and the new PNA assess the same relationship (e.g. between an OrgUnit and a resource). Even if they assess many other relationships, a single "overlapping" relationship is enough to block the new PNA. The blocking can happen within a single management system or across several management systems. However, PNAs always remain in the management system in which they were created.
Blocking within a single management system

Within a single management system, a PNA is blocked if there is already an older PNA that assesses the same relationship and is not yet completed. If, for example, you have already created a PNA that interviews the OrgUnit "Finance" and collects information on the resource "Banking Portal", you cannot create a new PNA that assesses the same relationship (Finance → Banking Portal). In the screenshot on the right you see how HITGuard points this out to you at step two of the new PNA.
However, if you complete the PNA, you can carry out a reassessment without any problems.
Blocking across several management systems
If there are several management systems in which you carry out protection needs analyses, protection needs analyses can block each other across management systems. As long as a PNA is open somewhere, it is not possible to assess the same relationship in another management system, exactly as in the case of a single management system. With several management systems, reassessments are also blocked in this way. You could, for example, assess the relationship between the business process "Payroll" and the data category "Employee data" in the two management systems "ISMS" and "Data protection". But if the PNA in "ISMS" is still open, you cannot reassess the PNA in "Data protection". Because these are two different management systems, both the impact levels and the protection targets can be different. However, this has no influence on the behavior described above.

Even if you have closed the protection needs analysis in other management systems, you may under certain circumstances not be able to use the Reassess button. This means you have to create the protection needs analysis with the plus button, select the OrgUnit and then, in step two, "Add all connected resources and data categories". Then you can save this PNA. HITGuard will understand that this new PNA is a reassessment. You can only use the Reassess button if the original PNA that you are reassessing is the most recent in the entire system. The Reassess function namely automatically accesses the most recent BIA.
If you use workflow plans for your protection needs analyses, HITGuard will show you warnings if another PNA blocks the reassessment through the workflow plan (see above for more details). You can only add a PNA to a workflow plan if the PNA is the most recent in the system. If your colleagues have in the meantime created a PNA in another management system, your PNA no longer appears in the overview.
Tips, Tricks & Best Practice

Relationships in the structural analysis generally lead to the highest protection need. These dependences can be reduced with a protection needs analysis. One should therefore start with the analysis of those assets/resources/services that are most important to the organization and evaluate them regarding the requirements of the management system first.
It makes sense to spread protection needs analyses across multiple workflow plans so they can be reassessed throughout the year, e.g., some in the spring and some in autumn. If, for example, you have created a workflow plan for the spring and one for the fall and those repeat annually, and you have an especially sensitive organizational unit that needs to be reassessed twice a year (in the spring and the fall), you can add the protection needs analysis to both the workflow plans.
If the circle of participants for a protection needs analysis changes, if many new resources/data categories are adde4d, or if there hasn't been a personal interview in a longer while, then we also recommend a manual reassessment as an interview.
If a protection needs analysis is assigned to a workflow plan and a reassessment is triggered manually (via the revaluate button), then this new protection needs analysis is assigned as the basis for the next workflow in the linked protection needs analyses. If the reassessment is deleted, the link is reset to the original protection needs analysis. Caution: if a new protection needs analysis revaluating resources/data categories was created with the plus button, this link is not established and it may cause conflicts.
The validation of which protection needs analysis is the youngest/the most current, considers the start date as well as the moment the protection needs analysis was closed. If multiple PNAs are available at the time ogf reassessing, HITGuard shows which one is the youngest/most current.