Menü aufrufen
Toggle preferences menu
Persönliches Menü aufrufen
Nicht angemeldet
Ihre IP-Adresse wird öffentlich sichtbar sein, wenn Sie Änderungen vornehmen.

Schwachstellen/en: Unterschied zwischen den Versionen

Aus HITGuard User Guide
Isan (Diskussion | Beiträge)
Die Seite wurde neu angelegt: „A new workflow plan can be created with the "plus" button.<br> An existing workflow plan can be copied with the "copy" button, which adopts the contents of the workflow plan definition, but not the executed workflows or the linked reviews.<br> Existing workflow plans can be opened with a double click. left|thumb|900px<br clear=all>“
KoKl (Diskussion | Beiträge)
Die Seite wurde neu angelegt: „=== Initial assessment on a template basis (only for the Audit management add-on) ===“
 
(21 dazwischenliegende Versionen von 3 Benutzern werden nicht angezeigt)
Zeile 1: Zeile 1:
<b>What is a review?</b>


In HITGuard, a review is understood to be the recording of deviations from a target state. For example, a review can be an audit by an external auditor. The findings that the auditor may have handed over to you in the form of a report can be entered in HITGuard as a so-called "review result".  
In HITGuard a vulnerability analysis is a record of deviations from a desired target state. It is also called a "review". It is the central building block for detecting, assessing and specifically treating problems, weaknesses or deviations. This article describes how you carry out a review from initial creation to completion, how you reassess results later and how you evaluate the results.


Review results can also arise from a review with HITGuard. This is done by using knowledge bases in the "gap analyses". Here, a review is guided by structured questionnaires, with the help of which deviations from the desired target state are determined.
As an expert or professional user you will find all reviews under ''Risk management → Vulnerabilities''. You see all reviews that were created in this management system. You can create new reviews or send them out to be answered. Likewise, you can also download the reviews as a PDF or Word report.


The target state is referred to as the target score level in HITGuard and can be set separately for each management system. Only experts or administrators can set and change the target score level under [[Special:MyLanguage/Managementsysteme#Aktiver_Analysezeitraum|"Administration → Management Systems"]].


<span id="Überprüfungen_(Abweichungsanalysen/Prüfergebnisse)"></span>
<span id="Abweichungsanalyse_und_Prüfergebnis"></span>
==<span id="create_überprüfung"></span> Reviews (gap analyses/review results) ==
= Deviation analysis and review result =


Under "Risk management → Vulnerabilities → <u>Reviews</u> | Review objects | Gaps | Clarification needed", professionals and experts can find all reviews that have been created in the management system. All reviews are displayed, regardless of whether they are completed, in progress, or in draft status. New reviews can also be created or requested here. Furthermore, the reviews can also be downloaded as PDF or Word files.
A review records the deviations from the target state. This often takes place in the form of questionnaires, whereby audit questions answered negatively are then treated as deviations. Detected deviations can be provided directly with measures (for elimination) and controls (for monitoring) and assigned to a risk.


[[Datei:Risikoidentifikation Überprüfungen.png|left|thumb|900px|Overview of the reviews]]
HITGuard distinguishes two types, which run largely the same in the wizard:
<br clear=all>


<span id="Überprüfung_erstellen/bearbeiten"></span>
* '''Gap analysis:''' A questionnaire-supported review on the basis of a [[Special:MyLanguage/Wissensdatenbanken|knowledge base]]. With the structured questionnaires you can, for example, determine the degree of fulfillment of a norm. As a result, changes in the template knowledge base later impact the gap analysis, for example when the template is [[Special:MyLanguage/Erstellen_einer_Wissensdatenbank|revised and updated]]. In deviation analyses, this can play a role, for example, in reassessments (see below).
=== Create/edit review ===
* '''Review result:''' Entering findings without a template, for example from the report of an external auditor. Here you do not access a knowledge base, but enter everything - question answer and justiication - directly into the system.


<b>Review result:</b>
''Example:'' You enter the findings from an external pentest as a ''review result''. If you instead want to check the maturity level according to ISO 27001 or the BSI IT-Grundschutz compendium yourself, you choose a ''deviation analysis'' with the appropriate knowledge base.
* A review result means, for example, the findings that were handed out by the auditor in the course of an audit, possibly in the form of a report.  
* These findings can be entered using the "Add review result" button, accessible via the dropdown in the "Plus" button.


<b>Gap analysis:</b>
<span id="Schritt-für-Schritt-Anleitung"></span>
* Gap analyses are questionnaire-based reviews (KB) on specific topics. These questionnaires can be used, for example, to determine the degree of compliance with a standard. In addition to the questionnaire topics, other review results can be recorded.
= Step-by-step guide =
* If a translation of the KB is available in the currently selected language (flag on the top right, next to the "Logout" button), it will be applied.
* To create a gap analysis, click on the "Plus" button.


In terms of procedure, the only difference between the two inspection options is that an inspection result cannot handle inspection objects based on knowledge bases.
[[Datei:Risikoidentifikation_Überprüfungen.png|thumb|right|400px|Overview of the reviews]] Regardless of the type of review, the steps in the wizard are essentially the same:


To edit a review, double-click on it in the overview.
# Create and save review
# Add test objects and activate review
# Answer review objects (or request answering in the self assessment)
# Treat deviations
# Complete review


For more information on creating or editing a review, whether gap analysis or review result, see <b>[[Special:MyLanguage/Überprüfung| Create/Edit review]]</b>.


===Copy review===
<span id="Schritt_1:_Überprüfung_erstellen"></span>
====Create duplicate====
== Step 1: Create review ==
A copy of a review can be created at the click of a button. For this, the structure of the review objects is taken from the original, but not the answers or any linked elements (measures, controls,...). Copies are created with "- Copy" in the name in the state Draft.
====Create reassessment====
A reassessment of a review can be created at the click of a button. For this, not only the structure of the review objects is taken from the original, but you can decide whether you want to also adopt the answers and justifications. Reassessments are created with "- Revaluation" in the name in the state Draft. The original must be in the state Closed for this to work.


===Workflow plans===
Under ''Risk management → Vulnerabilities '' Experts and Professionals can create reviews. To edit, double-click a review. You create a new review via the '''Plus''' button:
A click on the purple button above the overview of protection needs analyses opens a list of all created workflow plans.<p>Workflowplans serve to automatically trigger the one-time or repeated execution of workflows. The objective here is the revaluation of already documented results. For protection needs analyses it is therefore possible to create revaluations of closed assessments to review the ongoing validity of the documented contents. For this they are sent to the interview partners, for example on a yearly basis. The interview partners of course have the option of changing or expanding on any of the results.


A new workflow plan can be created with the "plus" button.<br>
* '''Gap analysis:''' Click directly on the ''Plus'' button.
An existing workflow plan can be copied with the "copy" button, which adopts the contents of the workflow plan definition, but not the executed workflows or the linked reviews.<br>
* '''Review result:''' Open the dropdown menu with the small triangle on the plus button and select ''Enter review results''.
Existing workflow plans can be opened with a double click.
[[Datei:Workflow_WorkflowplanDefinition_AAPE.png|left|thumb|900px]]<br clear=all>


<u>Status:</u>
[[Datei:Abweichungsanalyse_Schritt_1.png|thumb|right|400px|Create review – step 1]] In the first step you record the master data of the review. Here we explain all fields:
* Standardmäßig sind Workflowpläne aktiv. Man kann sie mit diesem Auswahlfeld auch aussetzen oder deaktivieren. Deaktivierte Workflows werden innerhalb der Abweichungsanalyse/Prüfergebnis nicht zur Verknüpfung mit einem Workflow angeboten.  
'''Mandatory fields:'''
* '''OrgUnit:''' The organizational unit responsible for the review, or the organizational unit being reviewed.
* '''Name & description:''' Record here what the purpose of the review is.
* '''Interview partner:''' These are the people who give you the answers to the questions in the review. If you set "Self-Assessment" for the type of review, the users in this field later receive the e-mails that request them to answer the questions. As with the responsible person, HITGuard fills this field with the responsible person from the [[Special:MyLanguage/OrgEh_-_Organisationseinheiten|organizational unit]]. However, you can also enter any number of other regular HITGuard users.
'''Further input fields:'''
* '''Note:''' Further notes, e.g. on the execution.
* '''Lead auditor:''' Main responsible person of a review. When you create the review, HITGuard automatically enters your user here.
* '''Co-auditors / accompaniment:''' Subject matter experts who are brought in to the review for special topics.
* '''Responsible persons:''' The responsible persons of the organizational unit or the area. Just as with the Interview partner field, HITGuard fills this field with the responsible person from the [[Special:MyLanguage/OrgEh_-_Organisationseinheiten|organizational unit]].
* '''Start and end date:''' Planned time span. Every review requires both dates. For self assessments (see below) the end date is called '''answering deadline'''.
* '''Type:''' Controls how the review is carried out (see below). This setting can only be changed in the ''Draft'' status.
* '''Workflow plans:''' Shows in how many workflow plans the review occurs as active or paused. Links can be set, removed or paused here.
* '''Created by workflow plan:''' Refers to the triggering workflow, if the review was created automatically.
* '''Change log:''' Records who edited, changed the status or completed it, and when.


<u>Bezeichnung:</u>
'''Type of review:'''
* Geben Sie hier die Bezeichnung Ihres Workflowplanes ein.
* '''Interview:''' The review is carried out together with the interview partner. The interview partner can view it, but not change it.
* '''Self assessment:''' The interview partner answers the topics independently. The lead auditor requests the answering via the ''Request answering'' button (after activation) and then reviews it.
'''Special fields for the Audit management add-on module:''':
* '''Audit:''' Links the review with an audit. If the review arises from an audit, lead auditor, interview partner as well as start and end date are pre-filled. Via the button next to it, the master data can be loaded from the audit. (See [[Auditplanung|Audit planning]].)
* '''Function:''' Optionally defines the context more precisely. Only appears if the option is activated under [[Auditmanagement Einstellungen|Audit management → Settings]]. You manage functions under [[Funktionen|Audit management → Functions]].
'''Special fields for the Supply Chain Risk Management module:'''
* '''Supplier review:'''By default, only HITGuard users can be selected as interview partners. In a Supply Chain Risk Management (SRM) management system, a checkbox is available for this that marks the review as a supplier assessment. If it is active, only [[Special:MyLanguage/Lieferanten|suppliers]] can be selected instead. This checkbox is only available if the option under ''Risk management → Settings'' is active and the SRM license is present.


<u>Beschreibung:</u>
<span id="Schritt_2:_Prüfobjekte_hinzufügen"></span>
* Geben Sie hier an, was der Zweck des Workflowplanes ist.
== Step 2: Add review objects ==


<u>Verantwortliche:</u>
Review objects are question sets on a special topic. You add these review objects in the second step, because you want to assess them. Review objects that you have added will appear in the upper bar and may be removed there.
* Der Verantwortliche wird eine Woche bevor der Workflow auslöst per E-Mail informiert. Sollte es zu diesem Zeitpunkt Probleme oder Konflikte geben (z.B. auszusendende Überprüfungen sind aktuell in Bearbeitung oder es fehlen die zu hinterlegenden Interviewpartner), werden diese im E-Mail beschrieben und können daher rechtzeitig gelöst werden. Der Verantwortliche wird auch beim Auslösen des Workflows darüber informiert, welche Überprüfungen erfolgreich ausgesendet wurden und ob es Probleme oder Konflikte gegeben hat, die die Aussendung weiterer Überprüfungen verhindert haben.


<u>Managementsystem Verantwortliche informieren:</u>
It is a crucial difference whether a review object is assessed for the first time (initial assessment/new creation) or whether an already existing review object is assessed again ([[#Neubewertungen|reassessment]]), or whether an entirely new review object is created. Several tabs are available for this:
* Ist dieses Häkchen gesetzt, werden zusätzlich zum Verantwortlichen des Workflowplans auch die Verantwortlichen des Managementsystems per E-Mail über den bevorstehenden bzw. den durchgeführten Workflow informiert.


<u>Nächste Durchführung:</u>
<span id="Erstbewertung_mittels_Wissensdatenbank_(für_die_Abweichungsanalyse)"></span>
* Legen Sie hier fest, wann der Workflowplan das nächste Mal auslösen soll. Zu diesem Zeitpunkt werden dann auf Basis der verknüpften Überprüfungen neue Überprüfungen als Self Assessment angelegt und zur Beantwortung an die Interviewpartner geschickt.
=== Initial assessment using a knowledge base (for the gap analysis) ===


<u>Wiederkehrender Workflow:</u>
[[Datei:Abweichungsanalyse_Schritt_2_Erstbewertung_mit_WDB.png|thumb|right|400px|Initial assessment using a knowledge base]] In the tab ''Initial assessment using a knowledge base'', select the desired knowledge base in the dropdown and then look for the topics that you want to assess. To add a topic, click the '''Plus''' next to it.
* Wenn der Workflowplan regelmäßig auslösen soll, kann dies hier eingestellt werden.


====Überprüfungen====
'''Note'''
Dieser Tab zeigt alle verknüpften Überprüfungen. Dies umfasst die Überprüfungen, die als Vorlage gedient haben, sowie auch die daraus erstellten neuen Überprüfungen. An dieser Stelle können einzelne Überprüfungen im Workflowplan pausiert oder wieder aktiviert werden. Für einzelne Überprüfungen kann manuell sofort eine Neubewertung ausgelöst werden. Pausierte Überprüfungen setzen einen Zyklus aus, sind danach aber wieder aktiv. Wenn es Probleme oder Konflikte mit einer Überprüfung gibt, wird dies hier ebenfalls dargestellt.<p>
* The plus only appears for topics that also contain review questions. If topics have no plus, they only serve to structure other topics. Expand them via the triangle arrow to see the topics contained in them.
* If the knowledge base is available in several languages, the translation matching the user language is displayed, provided there is an translation available.
* "Initial assessment" does not mean that the topic from the knowledge base is used for the first time, but only that this review is the first in the series. Let's say you have already used a knowledge base topic "Awareness" to review five other organizational units (OU). If you want to review OU Number six, you have to create the review object via this tab.


<u>Hinweis</u>: Bei der Auswahl der Überprüfungen zum Verknüpfen werden nur jene Überprüfungen angeboten, die keinen oder nur einen gelben Konflikt haben (siehe unten). Überprüfungen mit roten Konflikten (siehe unten) werden nicht zur Auswahl angeboten. Es wird angezeigt, ob die Überprüfung bereits Workflowplänen zugewiesen ist und welchen.<p>
<span id="Erstbewertung_auf_Vorlagenbasis_(nur_für_das_Add-on_Auditmanagement)"></span>
=== Initial assessment based on a template (only for the Audit management add-on) ===


<b>Gelbe Warndreiecke</b>: Besteht ein Konflikt innerhalb der Überprüfung selbst, wird dies mit einem gelben Warndreieck dargestellt. Details zum Konflikt finden sich im Tooltip, wenn man mit der Maus über dem Dreieck hovert. Beispiel: die Überprüfung ist nicht im Status abgeschlossen oder sie hat keinen Interviewpartner hinterlegt.<p>
[[Datei:NeubewertungVorlagenbasis.png|right|thumb|400px]] In the tab ''Initial assessment based on a template'', select the desired topic collection. With the green '''Plus''' you add all contained topics, with a white '''Plus''' individual topics. More on this under [[Auditmanagement Einstellungen#Themensammlungen|topic collections]].
'''Note:''' This option is only available if the Audit management add-on is activated in the management system and the user has the required role.
<br clear="all">


<b>Rote Warndreiecke</b>: Besteht ein Konflikt mit einer anderen Überprüfung im selben Managementsystem, wird dies mit einem roten Warndreieck dargestellt. Details zum Konflikt finden sich im Tooltip, wenn man mit der Maus über dem Dreieck hovert. Zusätzlich wird ein Link zur konfliktierenden AA/PE angeboten. Beispiel: es gibt zwei Überprüfungen, die auf das selbe Prüfobjekt verweisen.<p>
<span id="Neuanlage_eines_Prüfobjekts_(für_Prüfergebnisse)"></span>
==== Create new review object (for review results) ====


<b>Ergebnisse übernehmen</b>
[[Datei:Prüfergebnis_einpflegen_Schritt_2_Neuanlage.png|thumb|right|400px|New creation of a test object]] In the tab ''create new review object' you create a review object without a knowledge base. Assign a name and a responsible user and click ''Add new review object''. With this function you can then create your own review questions in the review object. You can then enter external review results (e.g. pentest) in the questions.
Die Übernahme der Ergebnisse erfolgt in zwei Schritten. Zuerst wird ausgewählt, welche Version der Wissensdatenbank für die Neubewertung verwendet werden soll. Dann wird eingestellt, ob und welche Ergebnisse der vorherigen Überprüfung übernommen werden sollen. Die Einstellungen kann getroffen werden, während man die Überprüfungen zuweist oder wenn sie bereits zugewiesen sind.
[[Datei:Workflow_AA_ErgebnisseÜbernehmen.png|left|thumb|900px]]<br clear=all>


====Durchgeführte Workflows====
<br clear="all">
Dieser Tab zeigt alle vergangenen Workflows des Plans an, die bereits durchgeführt worden sind. Hier wird dargestellt, ob der Workflow funktioniert hat oder fehlgeschlagen ist und was etwaige Probleme waren.


====Workflowplan FAQs====
<span id="Neubewertung_bestehender_Prüfobjekte"></span>
<b>Was passiert bei der Durchführung eines Workflowplans?</b></br>
=== Revaluation of existing review objects ===
Wenn der Workflowplan durchgeführt wird, werden für die verknüpften Überprüfungen Neubewertungen erstellt und die jeweiligen Interviewpartner zur Beantwortung aufgefordert. Eine Neubewertung bewertet dieselben Prüfobjekte für die selbe Organisationseinheit wie die ursprüngliche Überprüfung.<p>
<b>Wann wird keine Neubewertung angefordert?</b><br>
Es wird keine Neubewertung erstellt und angefordert, wenn eine der folgenden Bedingungen zutrifft:
*Die Neubewertung der Überprüfung ist pausiert.
*Die Überprüfung ist nicht abgeschlossen.
*Die Überprüfung hat keine Interviewpartner.
*Es existiert bereits eine andere Überprüfung die eine neuere Version eines Prüfobjektes bewertet und nicht abgeschlossen ist.<p>
<b>Was passiert mit pausierten Überprüfungen?</b></br>
Wenn eine Überprüfung pausiert wurde, wird bei der nächsten Durchführung keine Neubewertung erstellt. Stattdessen wird die Überprüfung für die darauffolgende Durchführung wieder aktiviert.


=== <span id="asses_wiz_nav"></span>Navigation in the wizard ===
Via the tab ''Reassessment of existing review objects'' you look for review objects that have already been fully assessed. instead of creating them anew, you take new versions into the review instead. The options and the exact procedure are described in the section [[#Neubewertungen|Reassessments]]. Alternatively, you can also always use the Reassess button in the grid overview to reassess an entire review.
The following section explains how the navigation in the review wizard works.


[[Datei:Wizard Navigation.png|left|thumb|900px|Review wizard]]
<span id="Schritt_3:_Prüfobjekte_bearbeiten_und_beantworten"></span>
<br clear=all>
== Step 3: Edit and answer review objects ==


The navigation in the wizard for performing checks works as follows:
[[Datei:Abweichungsanalyse_Schritt_3_Übersicht.png|right|thumb|400px|Overview of review objects]]After adding, you see all review objects in the overview under step 3. Here you can only adjust the order. Mark a review object with a click and move it in the order with the arrows at the top right. ''Save'' also transfers the sorting order into the left content overview.
* Clicking on "Next" takes you to the next step or to the next review question.
<br clear="all">


* Clicking on "Back" takes you to the previous step or to the previous review question.
'''Step 3.1: Details of a review object'''


* Clicking in the navigation tree on the left side will take you to the desired location.
[[Datei:Abweichungsanalyse_Schritt_3_Übersicht_eines_Prüfobjekltes.png|right|thumb|400px|Detail view of a review object]]In the detail page of the individual review objects you see its header data as well as a list of the review questions assigned to it.


* At the bottom left of the navigation mask, the review questions can be displayed in the navigation tree via a "Review questions" checkbox. The wizard remembers whether the checkbox was selected or deselected and maintains the desired behavior.
Core data:
* With the ''trash can'' button you remove the review object from the review again.
* The ''responsible person'' and the ''interview partner'' are taken over from the master data page (see above at step 1). However, you can also still make changes here. The interview partner is intended here purely for documentation. HITGuard will automatically take the responsible person and enter them as the measure responsible when you create measures from the review questions of this review object.
* You can link the review object with ''master data'', i.e. the entities in the views of the [[Special:MyLanguage/Strukturanalyse|structure analysis]]. As a result, all review questions including measures and controls are connected directly with the entity and are visible in the entity and in the structural analysis.
* With the ''Clarification needed'' switch you mark the entire review object; in doing so, all associated review questions and review results are marked as requiring clarification.


* If you show the review questions, you can also navigate to them via the tree. In the same way, you are taken back to the review question/result if you have left the review by creating a measure or control. Generally, the left part always shows the review questions/results that are currently visible on the right.
List of review questions:
* Here you see the review questions that were created from knowledge base templates.  
* Via the plus button you can enter additional review results. Even if you originally created the review object from the knowledge base, you can add new questions or results here.


* "Save" and "Close" behave self-explanatorily.
<span id="Detailseiten_der_Prüffragen"></span>
== Detail pages of the review questions ==


Regardless of the type of review you perform (gap analysis using a knowledge base or recording review results) the processing steps in the perform review wizard are essentially the same:
If the review object comes from a knowledge base, you will answer the individual review questons. You will find more details in the dedicated article [[Special:MyLanguage/Prüffragen_beantworten|Answering review questions]]. If you instead enter review results, you will find more information [[Special:MyLanguage/Prüfergebnisse#Prüfergebnisse einpflegen|here]].
# Create and save review
 
# Add topics or review objects and activate review
If you have selected the type ''Interview'', you will answer the review questions as an Expert or Professional. If you have selected the type ''Self-Assessment'', the Practitioner will receive the review and answer the questions [[Special:MyLanguage/Überprüfungen|independently]].
# Answering the review objects or the possibility to request an answer in the "self assessment" by the interview partner
 
# Check responses or identified gaps
*'''Answer:''' Here you can select in the drop-down to what degree you fulfill the review question. Usually this is assessed as Yes/No/Partially or as a maturity level from 1 to 5.
# Complete the review
*'''Unnecessary:''' With this button you remove the question from the assessment. It does not apply to this review.
*'''Justification:'''Here you can, with written information, record and justify why you decided on the answer above.
*'''Clarification needed:''' Mark an review question or a review result with ''Clarification needed'' if you cannot yet determine the answer. This can happen, for example, because you have to ask another person or research information.
*'''Upload document:'''Here you can upload evidence for the answer.
*'''Threats, measures & controls:''' Via these buttons you can directly create elements that are then linked directly with the review question. You can find out more about these elements on the special pages for [[Special:MyLanguage/Aktuelle_Maßnahmen|measures]], [[Special:MyLanguage/Kontrolldefinitionen|controls]] & [[Special:MyLanguage/Bedrohungen|threats]]. If you create a measure, you can afterwards select an ''after value'' that indicates how the answer turns out after the measure has been implemented. You will find more details in the article [[Special:MyLanguage/Prüffragen_beantworten|Answering review questions]]. (Practitioners can only submit suggestions for measures).
* You do not have to answer all review questions or review results to complete a review. However, when completing with open questions, a warning appears.
* In the Audit management add-on you can have a second drop-down "'''determination type'''" displayed next to the answer. With it you can, for example, indicate whether it is a major or minor deviation.
 
<span id="Schritt_4:_Abweichungen_behandeln"></span>
== Step 4: Treat deviations ==
 
[[Datei:Prüfergebnis_einpflegen_Schritt_4_Abweichungen.png|right|thumb|400px|Assigning deviations to a risk]]A deviation is a  review question with a negative answer. Specifically, HITGuard detects these negative answers as follows: <br>
The target score is the defined target value that specifies the desired target state for review questions. It serves as a reference point to detect deviations from the ideal state. Every answer to an review question is compared with the target score. If the answer value is below the target score, the review question is considered a deviation. TO achieve this, the answers "Yes", "No" and "Partially" are translated into the numerical values "5", "1" and "3". You can define the target score in the [[Special:MyLanguage/Managementsysteme|management system]]. <p> Deviations are treated differently by HITGuard. For example, you can assign them to risks in step 4. HITGuard also detects over-fulfillments; these can be useful in opportunity management. To assign these, however, you have to navigate to ''Risk management > Vulnerabilities > Deviations''
 
You can link deviations and risks here in two ways:
* Select an existing risk in the dropdown below, mark the deviations and click ''Assign selected deviations to selected risk''.
* Mark the deviations and click ''Create risk for review object''. In the popup box you create a new risk and assign it to the deviations.
* '''Best practice:''' Since you keep the detailed overview via the deviations anyway, it is advisable to create only a few risks that cover large subject areas. Even for large organizations, a few dozen risks are usually sufficient.
<br = clear"all">
 
<span id="Überprüfung_abschließen"></span>
== Complete review ==
 
A review can be carried out by an Expert or Professional. Optionally they request the answering from the interview partner: The latter receives a request via workflow, answers the review questions and sends the review back. The Expert reviews the results and completes the review.
 
Treating deviations as well as linking of measures and controls is possible at any time – even after completion.
 
<span id="Status_einer_Überprüfung"></span>
== Status of a review ==
 
[[Datei:Überprüfung_Stati_wechseln.PNG|thumb|Change status]]


A review can be performed by an expert or professional. However, he also has the option of requesting the answer to the review from his interview partner in HITguard. Via workflow support, the interview partner receives a request for this and can complete the response and then return it to the expert. The expert checks the results and can mark the review as completed and archive it. The handling of deviations from the review is possible at any time, even if a review has already been completed. Measures and controls can also be linked at any time.
You change the status via the blue button at the top right. If the e-mail notifications are active in the management system, the persons relevant in the workflow are informed at every status change.


<span id="Status_und_Löschen_einer_Überprüfung"></span>
* '''Draft:''' The review has this status when first created (or when deactivated from ''In progress''). The review is not yet active; no one has been informed. With the blue ''Activate review'' button you activate it.
=== <span id="Status"></span>Status and deletion of a review===
* '''In progress:''' Now the review is active. Interview partners and auditors see the review under ''My Tasks'', but cannot yet edit it. The type of review can no longer be changed now. If the type is a ''Self assessment'', the lead auditor can, via ''Request answering'', call on the interview partner to answer the questions. If the type is an ''Interview'', it goes via ''Complete review'' into the status ''Closed''. Via ''Deactivate review'' it goes back to ''Draft''.
* '''Requested (only for self assessment):''' After ''Request answering''. In this status the interview partners are requested by e-mail to answer the review questions. Requested self assessments are marked with a badge. Once the interview partners are finished, they set the status to ''Answered'' with ''Submit review''.
* '''Answered (only for self assessment):''' After submission by the interview partner, the lead auditor is automatically informed by e-mail. The interview partner and the responsible person can now no longer edit the review. Via ''Complete review'', Expert and Professional users can set the review to the status ''Closed''.
* '''Closed:''' The review is now write-protected. No user can edit the review and the review questions in it. However, links of review questions with risks, measures, controls and threats can still be added and edited.


[[Datei:Überprüfung Stati wechseln.PNG|right|thumb|900px]]
'''Changing the review type (Interview and Self-assessment):''' The type can only be changed in the ''Draft'' status. If the type was wrong and the review already activated, you first have to set it back to ''Draft'' via ''Deactivate review'' and then .


A review can have different states. If the e-mail notifications are active in the management system, all persons relevant in the workflow are prompted to perform their tasks when the status changes. This would be, for example, the interview partner if an auditor requests a response, or the auditor themselves if the response is returned.
<span id="Tipps_&amp;_Infos"></span>
= Tips & info =


The status of the review can be changed via the blue button in the upper right corner.
''' Copy review (duplicate)'''


<b>Draft</b>
: Klick the button above the grid overview to create a '''duplicate''' of a review. Only the structure of the review objects is taken over – not the answers and not the linked elements such as measures or controls. The duplicate carries the addition ''- Copy'' and is created in the ''Draft'' status. The original may be in any status.
* When the review is saved for the first time or deactivated from the "In Progress" status, it is in the "Draft" status.
: If you want to take over the answers, use a [[#Manuelle Neubewertung einer Überprüfung|reassessment]] instead.
* "Draft" means that the review is not yet active and no one has been informed about the review by the system.
* From this status, the review can be activated, i.e. set to the "In Progress" status.


<b>In progress</b>
'''Delete review'''
* If the review is activated, it will be set to "In Progress" status. As a result, the interview partner and auditor will see it under "My tasks."
* Now it is time for the lead auditor to perform the review or request a response by "Request Response" from interview partners (only for self assessments).
* It can be set back to the status "Draft" by selecting "Deactivate review".
* It can be set to the status "Closed" by selecting "Close review".


<b>Requested (only for self assessments) </b>.
: Via ''Delete review'' you remove reviews that are '''not yet''' completed.
* If the review is requested by the lead auditor, it will be set to "Requested" status. The interview partner will be prompted via e-mail to perform the review.
: '''Note:''' When deleting, the review objects created via this review as well as deviations already assigned to risks are also deleted.
* The interview partner can set the status to "Answered" by clicking on "Submit review" after the review has been conducted.
* Requested self assessments are marked with a badge.


<b>Answered (only for self assessmentse) </b>.
''' Navigation in the wizard '''
* If the review is returned by the interview partner with "Submit review", it will be set to the status "Answered". The auditors will be prompted by an e-mail to check the response.
* Answered self assessments are marked with a badge.
* It can be returned to the status "Requested" by selecting "Request response" again. The interview partner must then revise their response.
* It can be put back into the status "Draft" by selecting "Deactivate review" (only auditors will be notified).
* It can be moved to the status "Closed" by selecting "Close review".


<b>Closed</b>
[[Datei:Wizard_Navigation.png|thumb|Review wizard]]
* If the review is set to the "Closed" status by "Close review", it is read-only and it can no longer be edited.
* <u>Caution</u>: A self assessment can only be closed if there is at least one interview partner.
* <u>Exception</u>: Even in already closed reviews, measures and controls can still be added to or removed from review questions.


<b>Delete a review</b>.
* '''Next''' / '''Back:''' To the next or previous step or to the next/previous review question.
* With "Delete review" you can delete reviews that are <b>not</b> completed yet.
* '''Navigation tree (left):''' Direct jump to the desired place. The right area always shows the review questions or review results of the selected node.
* Caution: By deleting, the review objects created in this review as well as gaps already assigned to risks will also be deleted!
* '''"Review questions" checkbox (bottom left):''' Shows or hides the review questions in the navigation tree. The wizard remembers this setting. With review questions shown, the wizard automatically jumps back to the correct question if you have left it, for example, to create a measure or control.
* '''Save''' and '''Close''' behave self-explanatorily.


<span id="Überprüfungstyp_wechseln_(Interview_Self_Assessment)"></span>
'''Important terms '''
==== Change review type (interview <=> self assessment) ====


The type of review can be changed only in the "Draft" status. If the type is changed to "Self assessment", the end date changes to the reply deadline.
* '''Review object:''' The object that is reviewed (e.g. a topic from a knowledge base or a freely created object). A review object contains review questions and/or review results.
* '''Review question:''' A single question from a knowledge base.
* '''Deviation:''' An review question or a review result that was assessed worse than the target state.
* '''Knowledge base:''' A structured collection of topics and review questions (e.g. on a norm).
* '''Organizational unit:''' The company area responsible for the review.
* '''Target Score (target state):''' The desired target state is called '''Target Score''' in HITGuard. It determines from when an answer is considered a deviation. An answer with ''No'' corresponds to score 1, ''Partially'' corresponds to score 3, ''Yes'' corresponds to 1. It can be set separately per management system. Only Experts or Administrators can define and change the target score under [[Managementsysteme#Aktiver_Analysezeitraum|Administration → Management systems]].


If the wrong type was set and the check was activated, the check must first be reset to the "Draft" status by "Deactivate check".
<span id="Neubewertungen"></span>
= Reassessments =


====Tips, tricks & best practice====
There are different options for the reassessment, which offer their respective advantages. In any case, however, the original review ''must'' be completed.  
[[Datei:BESTPRACTICE.png|left|thumb|100px]]
*This type of analysis is a powerful tool in HITGuard. It is a central component of risk identification and treatment. Detected gaps can be linked with reduction measures and/or monitoring controls directly within the analysis.
*The crucial benefit of doing this in one step is that any gaps, measures, and controls can be assigned to the identified risk. If the review object is also linked with a structural element, such as an application, this information is also comprehensibly shown in the details of that element.
*Revaluating instead of evaluating again. From time to time, generally at regular intervals, the status quo should be ascertained again. For this, HITGuard offers the revaluation of analyses, which allows the updating of previous analyses instead of having to perform a completely new analysis. Previous answers can be viewed and even carried over. This makes the development of a review object even more apparent.<br clear=all>


<span id="Prüfobjekte"></span>
<span id="Manuelle_Neubewertung_mit_dem_Neubewerten-Button"></span>
== <span id="Prüfobjekte"></span>Review objects ==
== Manual reassessment with the Reassess button ==


Under "Risk management → Vulnerabilities → Review| <u>Objects of review</u> | Gaps | Clarification needed", you will find all the review objects that were created in the course of reviews in the current management system.
[[Datei:PlusNeubew.png||right|thumb|100px|Plus and Reassess button]]If you select a completed review in the grid and click the Reassess button, a new protection needs analysis or vulnerability analysis is created that is based on the template of the old one. The original analysis remains untouched and write-protected in the system. This reassessment carries the addition "''- Reassessment''" and is created in the ''Draft'' status.<p>
This variant is quick and simple to carry out. However, it only allows the reassessment of the entire review with all its review objects.


[[Datei:Prüfobjekte Übersicht.png|left|thumb|900px|Overview of the review objects]]
<span id="Neubewertung_mit_Workflowplänen"></span>
<br clear=all>
== Reassessment with workflow plans ==


Clicking on a review object opens the detailed view.  
[[Datei:WFPbutton.png|right|thumb|100px|Button for workflow plans]] A '''workflow plan''' triggers the reassessment of vulnerability analyses automatically and sends them as a self-assessment to the interview partners. In this way, reassessments can be sent out, for example, annually, in order to check whether the contents are still valid. We discuss details and general information on workflow plans on the page [[Special:MyLanguage/Workflowpläne|Workflow plans]].<p>
Workflow plans for analyses work with reassessments. When the workflow plan is triggered, it works similarly to the manual reassessment with the button. HITGuard creates a new protection needs analysis or vulnerability analysis that is based on the template of the old one. The original analysis remains untouched and write-protected in the system. <p>
This variant lets you plan and automate reassessments in advance.  


[[Datei:Prüfobjekt bearbeiten.png|left|thumb|901px|Edit review object]]
<span id="Manuelle_Neubewertung_bestehender_Prüfobjekte_(im_Assistenten)"></span>
<br clear=all>
== Manual reassessment of existing review objects (in the wizard) ==


Here you can see how the review object was answered. Likewise, if several versions of the review object are available, you can view how the assessment of the review object has developed from one version to the next. Only the header data of a review object can be edited via this mask. This means that this mask cannot be used to answer a review object.
[[Datei:Abweichungsanalyse_Schritt_2_Neubewertung.png|right|thumb|400px|Reassessment of existing review objects]]
When [[#Schritt 2: Prüfobjekte hinzufügen|adding review objects]] you can switch to the tab ''Reassessment of existing review objects''. Here you see all review objects that are in completed reviews. You can select the review objects that you want to reassess and then click ''Subject selected review objects to a reassessment''. <p>
This variant gives you more flexibility when creating the reassessment. If, for example, you want to reassess only one out of several review objects ina review, you can pick out the review object with this variant without having to revise the others.


<span id="Teil-Automatische_Neubewertung_initiieren"></span>
<span id="Ergebnisse_übernehmen"></span>
=== Initiate semi-automatic revaluation ===
== Take over results ==


Due to the implementation of measures, it can happen that review objects are proposed for semi-automatic revaluation. This always happens if the measure was either created in the course of a check for a review object or linked to a review object, the "after" value of the vulnerability reduction was set, and the measure is implemented. If a measure is implemented, the linked review objects are marked with "Revaluation recommended".
With the manual reassessment you have some settings that control how you use the old results.
*<b>Current knowledge base:</b> [[Special:MyLanguage/Wissensdatenbanken|Knowledge bases]] serve as a template for the question sets in vulnerability analyses. Sometimes the template was updated after the original review was created. With this checkbox you determine whether HITGuard should use the <i>old version</i> of the template, or whether it should use the <i>latest version</i> of the knowledge base.
*<b>Answer carry-over:</b> Here you can decide whether HITGuard should take over all answers, no answers or only positive answers from the last review in the reassessment. This controls how thoroughly the reassessment has to be worked through.
*<b>Justification carry-over:</b>Regardless of whether you take over answers or not, you can take over the respective justification texts from the original review. Alternatively, you can enter a default text that HITGuard will place in every justification field.


To avoid having to perform a new review every time a measure is implemented, HITGuard offers the option of subjecting these marked review objects to a semi-automatic revaluation. This means that HITGuard automatically updates the gap of the respective review questions of the review objects. A separate review is created for each individual organizational unit. In this process, the review questions that are affected by the implementation of measures are set to the "after" value of the vulnerability reduction.
<span id="Teil-automatische_Neubewertung"></span>
== Semi-automatic reassessment ==


Execution:
[[Datei: NacherW.png|right|thumb|400px|Specifying the after value]]
# Select review object.
Review questions can be linked with measures. If you create a measure, you can afterwards select an ''after value'' that indicates how the answer turns out after the measure has been implemented. (See also [[Special:MyLanguage/Prüffragen_beantworten|Answering review questions]]) With the semi-automatic reassessment (SAR) you can access these after values.  
# Click the orange arrow "Initiate semi-automatic revaluation".
# Select the gaps to be updated.
# Click the orange arrow "Perform revaluation for selected gaps".


[[Datei:RNDezember2019 4.png|left|thumb|901px|Semi-automatic revaluation]]
For the SAR, you first navigate to Risk management > Vulnerabilities > Review objects. If a linked measure was implemented (for which an after value of the vulnerability reduction was also set), HITGuard marks the affected review objects here with ''Reassessment recommended''.
<br clear=all>
#Start the reassessment by selecting the marked review objects and clicking the yellow reassessment button. (HITGuard will only make the button available if the review object contains measures that are already completed.)
#HITGuard now lists the after values that you specified for the linked measures. (HITGuard only lists the review questions whose measures are already completed.)
#With a second click on the reassessment button you complete the process. HITGuard will now create a new, already closed review with the title "Semi-Automatic Reassessment", in which the "after"-values are entered.
[[Datei:RNDezember2019_4.png|left|thumb|600px|Semi-automatic reassessment]]
<br clear="all">


===Tips, tricks & best practice===
<span id="Übersichten_und_Auswertungen"></span>
[[Datei:BESTPRACTICE.png|left|thumb|100px]]
= Overviews and evaluations =
Review objects can be evaluated multiple times within one analysis. For example, BSI's IT Grundschutz offers a module "Web applications". If various web applications are operated in an organization, it is recommended to answer the module for each one of them. This means the module should be selected multiple times across one or more reviews and linked to the respective resources. Additional tip: Give your review objects meaningful and telling names, such as "Web application 123_Cloud". This allows you to simply search the review objects when doing a revaluation.<br clear=all>


<br clear=all>
In addition to the individual reviews, HITGuard offers overarching lists in order to evaluate results across all reviews. You will find them under '''Risk management → Vulnerabilities''' via the tabs ''Reviews | Review objects | Deviations | Clarification needed''.


<span id="Abweichungen"></span>
<span id="Prüfobjekte"></span>
== <span id="Deviations"></span>Gaps==
== Review objects ==


Under "Risk management → Vulnerabilities → Reviews | Objects of review | <u>Gaps</u> | Clarification needed", you will find all gaps that were identified during the performance of reviews.
[[Datei:Prüfobjekte_Übersicht.png|thumb|Overview of the review objects]]


[[Datei:Abweichungen Übersicht.png|left|thumb|900px|Overview of gaps]]
The review object overview lists all review objects of the current management system. A click opens the detail view.
<br clear=all>


The columns "Measure missing", "Target value missing", "Target value too low" can be used to find out against which gaps nothing or too little has been done. These gaps are tagged in the grid. If a gap does not have a tag, this means that attempts are being made to correct the gap.
[[Datei:Prüfobjekt_bearbeiten.png|thumb|Review object detail view]]


Here you have the option to assign gaps that have not yet been assigned to a risk.
There you see how the review object was answered, and – with several versions – how the assessment has developed from version to version. In this screen only the header data are editable; it is not intended for answering a review object.


Double-clicking on a gap opens the review at the point where the gap was detected. Here, measures and controls for the gap can now be defined. For more information, see [[Special:MyLanguage/Prüffragen_beantworten| Answer review questions]].
<span id="Abweichungen"></span>
== Deviations ==


Optionally, it is possible to display a column that shows whether the line is a review question (from a knowledge base) or a review result (freely entered). This allows experts to then expand their self-developed knowledge bases by review results that are often added to reviews during the interview.
[[Datei:Abweichungen_Übersicht.png|thumb|Overview of the deviations]]


<span id="Abweichungen_filtern"></span>
The deviation overview shows all deviations detected during reviews. Via the columns ''Measure missing'', ''Target value missing'' and ''Target value too low'' you recognize where too little has still been done – affected deviations receive a corresponding tag. A deviation without a tag means that everything has already been created and work is being done on remedying it.
===Filter gaps===


[[Datei:Abweichungsfilter.png|right|thumb|900px|Abweichungsfilter]]
In this overview you can also - as otherwise in [[#Schritt 4: Abweichungen behandeln|step 4]] - assign not-yet-assigned deviations to a risk. A double-click opens the review at the place of the deviation, where you can define measures and controls (see [[Prüffragen beantworten|Answering review questions]]).


With the filter, it can be selected which type of gaps is displayed:
Optionally you show a column that indicates whether it is an review question (from a knowledge base) or a freely created review result. In this way Experts can extend their own knowledge bases by frequently added review results.
*negative: review questions/results that were evaluated < the target score
*none: review questions/results that were evaluated = the target score
*positive: review questions/results that were evaluated > the target score


<span id="Target_Score_Gewichtung"></span>
'''Filter deviations'''
=== <span id="Target score weighting"></span><span id="Zielreifegrad-Gewichtung"></span>Target score weighting===


What the target score level is and where it is set can be found under [[Special:MyLanguage/Managementsysteme#Aktiver Analysezeitraum | Management systems]].
[[Datei:Abweichungsfilter.png|thumb|Deviation filter]]
Wherever gaps occur, there is an additional form of sorting: the target score weighting. This is possible, for example, under "Risk management → Vulnerabilities → Gaps".


If activated, the sorting of protection targets is based on the target score weighting. The greater the deviation from the target score level and the greater the weighting of the protection target, the greater the target score weighting: target score weighting = deviation level * weighting of the protection target.
The filter controls which deviations are displayed – in each case in comparison to the target score:
* '''negative:''' < target score
* '''none:''' = target score
* '''positive:''' > target score


Note: A response of "No" corresponds to score level 1, "Partially" corresponds to score level 3.
'''Target Score weighting'''


Examples for illustration: Protection goal weighting: Mean (3).
[[Datei:Zielreifegrad_Gewichtung_anwenden.gif|thumb|Apply target score weighting]]
*score of deviation = 2, target score = 4 =&gt; Degree of deviation = 2, target score weighting = 2 * 3 = 6.
*score of deviation = 4, target score = 4 =&gt; degree of deviation = 0, target score weighting = 0 * 3 = 0.


[[Datei:Zielreifegrad Gewichtung anwenden.gif|left|thumb|900px|Apply target score weighting]]<br clear=all>
Everywhere deviations occur, HITGuard additionally offers sorting by '''target score weighting'''. You define the target score in the [[Special:MyLanguage/Managementsysteme#Aktiver_Analysezeitraum|management system]]. The greater the deviation from the target score and the higher the weighting of the protection objective, the higher the weighting: <br> Target score weighting = degree of deviation × weighting of the protection objective<p>
''Example'' (weighting of the protection objective: Medium = 3):
* Score of the deviation = 2, target score = 4 → degree of deviation = 2 → weighting = 2 × 3 = '''6'''
* Score of the deviation = 4, target score = 4 → degree of deviation = 0 → weighting = 0 × 3 = '''0'''


<span id="Abklärungsbedarf"></span>
<span id="Abklärungsbedarf"></span>
== <span id="Need for clarification"></span>Clarification needed ==
== Clarification needed ==
 
[[Datei:Abklärungsbedarf_Übersicht.png|thumb|Overview of the review questions / review results requiring clarification]]


Under "Risk Management → Vulnerabilities → Reviews | Objects of review | Gaps| <u> Clarification needed</u>", you will find all review questions/review results that were marked with "Clarification needed" in the course of a review.
The overview ''Clarification needed'' lists all review questions and review results that were marked as requiring clarification in the course of a review. (see [[#Detailseiten der Prüffragen|Detail pages of the review questions]]) A click leads directly to the respective review question or review result. In this way, after a series of reviews, you see at a glance which questions still have to be researched. Via the export button (next to the search bar) you get an easily usable listing.


[[Datei:Abklärungsbedarf Übersicht.png|left|thumb|900px|Overview of review questions/review results requiring clarification]]
<span id="Wichtige_Hinweise_und_Best_Practices"></span>
<br clear=all>
= Important notes and best practices =


This label is necessary in practice if you cannot yet clarify how the question is to be answered when answering a review question. This can happen if, for example, you would need to consult another person or otherwise research the information. Following a series of reviews, the system evaluates which questions still need to be researched. This is exactly what the "Clarification needed" view is for.
[[Datei:BESTPRACTICE.png|thumb|Best practice]]


If you click on a review question/result, you will be redirected to it.
* '''Treat deviations directly in the analysis.''' The review is the central point of risk identification and treatment. Provide detected deviations already here with measures (for elimination) and controls (for monitoring). In this way, deviation, measure and control can be cleanly assigned to the identified risk. If you additionally link the review object with a structure element (e.g. an application), this information also appears in its detail view.
* '''Reassessment instead of new assessment.''' Survey the actual state regularly via a reassessment instead of creating a new analysis each time. In this way old answers and justifications remain visible and the development of a review object becomes traceable.
* '''Assess review objects multiple times and name them meaningfully.''' A review object can occur several times in an analysis. ''Example:'' The IT-Grundschutz compendium contains the module "Web applications". If you operate several web applications, answer this module per application and link it with the respective application. ''Tip:'' Assign meaningful names such as "Web application 123_Cloud" – in this way you find the review objects easily via the search during reassessments.
* '''Prepare self assessment correctly.''' A self assessment can only be completed if at least one interview partner is stored. The interview partner is also a mandatory field as soon as the review leaves the ''Draft'' status.
* '''Check before deleting.''' When deleting a review, the review objects created via it and deviations already assigned to risks are also lost. Completed reviews cannot be deleted.


It is also possible to export a list of all review questions/results requiring clarification via the "Export" button (next to the search bar). This provides an easy-to-use list of the review questions that require clarification.
[[Kategorie:Schwachstellen]]
[[Kategorie:Risikomanagement]]

Aktuelle Version vom 7. Juli 2026, 06:16 Uhr

In HITGuard a vulnerability analysis is a record of deviations from a desired target state. It is also called a "review". It is the central building block for detecting, assessing and specifically treating problems, weaknesses or deviations. This article describes how you carry out a review from initial creation to completion, how you reassess results later and how you evaluate the results.

As an expert or professional user you will find all reviews under Risk management → Vulnerabilities. You see all reviews that were created in this management system. You can create new reviews or send them out to be answered. Likewise, you can also download the reviews as a PDF or Word report.


Deviation analysis and review result

A review records the deviations from the target state. This often takes place in the form of questionnaires, whereby audit questions answered negatively are then treated as deviations. Detected deviations can be provided directly with measures (for elimination) and controls (for monitoring) and assigned to a risk.

HITGuard distinguishes two types, which run largely the same in the wizard:

  • Gap analysis: A questionnaire-supported review on the basis of a knowledge base. With the structured questionnaires you can, for example, determine the degree of fulfillment of a norm. As a result, changes in the template knowledge base later impact the gap analysis, for example when the template is revised and updated. In deviation analyses, this can play a role, for example, in reassessments (see below).
  • Review result: Entering findings without a template, for example from the report of an external auditor. Here you do not access a knowledge base, but enter everything - question answer and justiication - directly into the system.

Example: You enter the findings from an external pentest as a review result. If you instead want to check the maturity level according to ISO 27001 or the BSI IT-Grundschutz compendium yourself, you choose a deviation analysis with the appropriate knowledge base.

Step-by-step guide

Overview of the reviews

Regardless of the type of review, the steps in the wizard are essentially the same:

  1. Create and save review
  2. Add test objects and activate review
  3. Answer review objects (or request answering in the self assessment)
  4. Treat deviations
  5. Complete review


Step 1: Create review

Under Risk management → Vulnerabilities Experts and Professionals can create reviews. To edit, double-click a review. You create a new review via the Plus button:

  • Gap analysis: Click directly on the Plus button.
  • Review result: Open the dropdown menu with the small triangle on the plus button and select Enter review results.
Create review – step 1

In the first step you record the master data of the review. Here we explain all fields:

Mandatory fields:

  • OrgUnit: The organizational unit responsible for the review, or the organizational unit being reviewed.
  • Name & description: Record here what the purpose of the review is.
  • Interview partner: These are the people who give you the answers to the questions in the review. If you set "Self-Assessment" for the type of review, the users in this field later receive the e-mails that request them to answer the questions. As with the responsible person, HITGuard fills this field with the responsible person from the organizational unit. However, you can also enter any number of other regular HITGuard users.

Further input fields:

  • Note: Further notes, e.g. on the execution.
  • Lead auditor: Main responsible person of a review. When you create the review, HITGuard automatically enters your user here.
  • Co-auditors / accompaniment: Subject matter experts who are brought in to the review for special topics.
  • Responsible persons: The responsible persons of the organizational unit or the area. Just as with the Interview partner field, HITGuard fills this field with the responsible person from the organizational unit.
  • Start and end date: Planned time span. Every review requires both dates. For self assessments (see below) the end date is called answering deadline.
  • Type: Controls how the review is carried out (see below). This setting can only be changed in the Draft status.
  • Workflow plans: Shows in how many workflow plans the review occurs as active or paused. Links can be set, removed or paused here.
  • Created by workflow plan: Refers to the triggering workflow, if the review was created automatically.
  • Change log: Records who edited, changed the status or completed it, and when.

Type of review:

  • Interview: The review is carried out together with the interview partner. The interview partner can view it, but not change it.
  • Self assessment: The interview partner answers the topics independently. The lead auditor requests the answering via the Request answering button (after activation) and then reviews it.

Special fields for the Audit management add-on module::

  • Audit: Links the review with an audit. If the review arises from an audit, lead auditor, interview partner as well as start and end date are pre-filled. Via the button next to it, the master data can be loaded from the audit. (See Audit planning.)
  • Function: Optionally defines the context more precisely. Only appears if the option is activated under Audit management → Settings. You manage functions under Audit management → Functions.

Special fields for the Supply Chain Risk Management module:

  • Supplier review:By default, only HITGuard users can be selected as interview partners. In a Supply Chain Risk Management (SRM) management system, a checkbox is available for this that marks the review as a supplier assessment. If it is active, only suppliers can be selected instead. This checkbox is only available if the option under Risk management → Settings is active and the SRM license is present.

Step 2: Add review objects

Review objects are question sets on a special topic. You add these review objects in the second step, because you want to assess them. Review objects that you have added will appear in the upper bar and may be removed there.

It is a crucial difference whether a review object is assessed for the first time (initial assessment/new creation) or whether an already existing review object is assessed again (reassessment), or whether an entirely new review object is created. Several tabs are available for this:

Initial assessment using a knowledge base (for the gap analysis)

Initial assessment using a knowledge base

In the tab Initial assessment using a knowledge base, select the desired knowledge base in the dropdown and then look for the topics that you want to assess. To add a topic, click the Plus next to it.

Note

  • The plus only appears for topics that also contain review questions. If topics have no plus, they only serve to structure other topics. Expand them via the triangle arrow to see the topics contained in them.
  • If the knowledge base is available in several languages, the translation matching the user language is displayed, provided there is an translation available.
  • "Initial assessment" does not mean that the topic from the knowledge base is used for the first time, but only that this review is the first in the series. Let's say you have already used a knowledge base topic "Awareness" to review five other organizational units (OU). If you want to review OU Number six, you have to create the review object via this tab.

Initial assessment based on a template (only for the Audit management add-on)

In the tab Initial assessment based on a template, select the desired topic collection. With the green Plus you add all contained topics, with a white Plus individual topics. More on this under topic collections.

Note: This option is only available if the Audit management add-on is activated in the management system and the user has the required role.

Create new review object (for review results)

New creation of a test object

In the tab create new review object' you create a review object without a knowledge base. Assign a name and a responsible user and click Add new review object. With this function you can then create your own review questions in the review object. You can then enter external review results (e.g. pentest) in the questions.


Revaluation of existing review objects

Via the tab Reassessment of existing review objects you look for review objects that have already been fully assessed. instead of creating them anew, you take new versions into the review instead. The options and the exact procedure are described in the section Reassessments. Alternatively, you can also always use the Reassess button in the grid overview to reassess an entire review.

Step 3: Edit and answer review objects

Overview of review objects

After adding, you see all review objects in the overview under step 3. Here you can only adjust the order. Mark a review object with a click and move it in the order with the arrows at the top right. Save also transfers the sorting order into the left content overview.


Step 3.1: Details of a review object

Detail view of a review object

In the detail page of the individual review objects you see its header data as well as a list of the review questions assigned to it.

Core data:

  • With the trash can button you remove the review object from the review again.
  • The responsible person and the interview partner are taken over from the master data page (see above at step 1). However, you can also still make changes here. The interview partner is intended here purely for documentation. HITGuard will automatically take the responsible person and enter them as the measure responsible when you create measures from the review questions of this review object.
  • You can link the review object with master data, i.e. the entities in the views of the structure analysis. As a result, all review questions including measures and controls are connected directly with the entity and are visible in the entity and in the structural analysis.
  • With the Clarification needed switch you mark the entire review object; in doing so, all associated review questions and review results are marked as requiring clarification.

List of review questions:

  • Here you see the review questions that were created from knowledge base templates.
  • Via the plus button you can enter additional review results. Even if you originally created the review object from the knowledge base, you can add new questions or results here.

Detail pages of the review questions

If the review object comes from a knowledge base, you will answer the individual review questons. You will find more details in the dedicated article Answering review questions. If you instead enter review results, you will find more information here.

If you have selected the type Interview, you will answer the review questions as an Expert or Professional. If you have selected the type Self-Assessment, the Practitioner will receive the review and answer the questions independently.

  • Answer: Here you can select in the drop-down to what degree you fulfill the review question. Usually this is assessed as Yes/No/Partially or as a maturity level from 1 to 5.
  • Unnecessary: With this button you remove the question from the assessment. It does not apply to this review.
  • Justification:Here you can, with written information, record and justify why you decided on the answer above.
  • Clarification needed: Mark an review question or a review result with Clarification needed if you cannot yet determine the answer. This can happen, for example, because you have to ask another person or research information.
  • Upload document:Here you can upload evidence for the answer.
  • Threats, measures & controls: Via these buttons you can directly create elements that are then linked directly with the review question. You can find out more about these elements on the special pages for measures, controls & threats. If you create a measure, you can afterwards select an after value that indicates how the answer turns out after the measure has been implemented. You will find more details in the article Answering review questions. (Practitioners can only submit suggestions for measures).
  • You do not have to answer all review questions or review results to complete a review. However, when completing with open questions, a warning appears.
  • In the Audit management add-on you can have a second drop-down "determination type" displayed next to the answer. With it you can, for example, indicate whether it is a major or minor deviation.

Step 4: Treat deviations

Assigning deviations to a risk

A deviation is a review question with a negative answer. Specifically, HITGuard detects these negative answers as follows:
The target score is the defined target value that specifies the desired target state for review questions. It serves as a reference point to detect deviations from the ideal state. Every answer to an review question is compared with the target score. If the answer value is below the target score, the review question is considered a deviation. TO achieve this, the answers "Yes", "No" and "Partially" are translated into the numerical values "5", "1" and "3". You can define the target score in the management system.

Deviations are treated differently by HITGuard. For example, you can assign them to risks in step 4. HITGuard also detects over-fulfillments; these can be useful in opportunity management. To assign these, however, you have to navigate to Risk management > Vulnerabilities > Deviations You can link deviations and risks here in two ways:

  • Select an existing risk in the dropdown below, mark the deviations and click Assign selected deviations to selected risk.
  • Mark the deviations and click Create risk for review object. In the popup box you create a new risk and assign it to the deviations.
  • Best practice: Since you keep the detailed overview via the deviations anyway, it is advisable to create only a few risks that cover large subject areas. Even for large organizations, a few dozen risks are usually sufficient.


Complete review

A review can be carried out by an Expert or Professional. Optionally they request the answering from the interview partner: The latter receives a request via workflow, answers the review questions and sends the review back. The Expert reviews the results and completes the review.

Treating deviations as well as linking of measures and controls is possible at any time – even after completion.

Status of a review

Change status

You change the status via the blue button at the top right. If the e-mail notifications are active in the management system, the persons relevant in the workflow are informed at every status change.

  • Draft: The review has this status when first created (or when deactivated from In progress). The review is not yet active; no one has been informed. With the blue Activate review button you activate it.
  • In progress: Now the review is active. Interview partners and auditors see the review under My Tasks, but cannot yet edit it. The type of review can no longer be changed now. If the type is a Self assessment, the lead auditor can, via Request answering, call on the interview partner to answer the questions. If the type is an Interview, it goes via Complete review into the status Closed. Via Deactivate review it goes back to Draft.
  • Requested (only for self assessment): After Request answering. In this status the interview partners are requested by e-mail to answer the review questions. Requested self assessments are marked with a badge. Once the interview partners are finished, they set the status to Answered with Submit review.
  • Answered (only for self assessment): After submission by the interview partner, the lead auditor is automatically informed by e-mail. The interview partner and the responsible person can now no longer edit the review. Via Complete review, Expert and Professional users can set the review to the status Closed.
  • Closed: The review is now write-protected. No user can edit the review and the review questions in it. However, links of review questions with risks, measures, controls and threats can still be added and edited.

Changing the review type (Interview and Self-assessment): The type can only be changed in the Draft status. If the type was wrong and the review already activated, you first have to set it back to Draft via Deactivate review and then .

Tips & info

Copy review (duplicate)

Klick the button above the grid overview to create a duplicate of a review. Only the structure of the review objects is taken over – not the answers and not the linked elements such as measures or controls. The duplicate carries the addition - Copy and is created in the Draft status. The original may be in any status.
If you want to take over the answers, use a reassessment instead.

Delete review

Via Delete review you remove reviews that are not yet completed.
Note: When deleting, the review objects created via this review as well as deviations already assigned to risks are also deleted.

Navigation in the wizard

Review wizard
  • Next / Back: To the next or previous step or to the next/previous review question.
  • Navigation tree (left): Direct jump to the desired place. The right area always shows the review questions or review results of the selected node.
  • "Review questions" checkbox (bottom left): Shows or hides the review questions in the navigation tree. The wizard remembers this setting. With review questions shown, the wizard automatically jumps back to the correct question if you have left it, for example, to create a measure or control.
  • Save and Close behave self-explanatorily.

Important terms

  • Review object: The object that is reviewed (e.g. a topic from a knowledge base or a freely created object). A review object contains review questions and/or review results.
  • Review question: A single question from a knowledge base.
  • Deviation: An review question or a review result that was assessed worse than the target state.
  • Knowledge base: A structured collection of topics and review questions (e.g. on a norm).
  • Organizational unit: The company area responsible for the review.
  • Target Score (target state): The desired target state is called Target Score in HITGuard. It determines from when an answer is considered a deviation. An answer with No corresponds to score 1, Partially corresponds to score 3, Yes corresponds to 1. It can be set separately per management system. Only Experts or Administrators can define and change the target score under Administration → Management systems.

Reassessments

There are different options for the reassessment, which offer their respective advantages. In any case, however, the original review must be completed.

Manual reassessment with the Reassess button

Plus and Reassess button

If you select a completed review in the grid and click the Reassess button, a new protection needs analysis or vulnerability analysis is created that is based on the template of the old one. The original analysis remains untouched and write-protected in the system. This reassessment carries the addition "- Reassessment" and is created in the Draft status.

This variant is quick and simple to carry out. However, it only allows the reassessment of the entire review with all its review objects.

Reassessment with workflow plans

Button for workflow plans

A workflow plan triggers the reassessment of vulnerability analyses automatically and sends them as a self-assessment to the interview partners. In this way, reassessments can be sent out, for example, annually, in order to check whether the contents are still valid. We discuss details and general information on workflow plans on the page Workflow plans.

Workflow plans for analyses work with reassessments. When the workflow plan is triggered, it works similarly to the manual reassessment with the button. HITGuard creates a new protection needs analysis or vulnerability analysis that is based on the template of the old one. The original analysis remains untouched and write-protected in the system.

This variant lets you plan and automate reassessments in advance.

Manual reassessment of existing review objects (in the wizard)

Reassessment of existing review objects

When adding review objects you can switch to the tab Reassessment of existing review objects. Here you see all review objects that are in completed reviews. You can select the review objects that you want to reassess and then click Subject selected review objects to a reassessment.

This variant gives you more flexibility when creating the reassessment. If, for example, you want to reassess only one out of several review objects ina review, you can pick out the review object with this variant without having to revise the others.

Take over results

With the manual reassessment you have some settings that control how you use the old results.

  • Current knowledge base: Knowledge bases serve as a template for the question sets in vulnerability analyses. Sometimes the template was updated after the original review was created. With this checkbox you determine whether HITGuard should use the old version of the template, or whether it should use the latest version of the knowledge base.
  • Answer carry-over: Here you can decide whether HITGuard should take over all answers, no answers or only positive answers from the last review in the reassessment. This controls how thoroughly the reassessment has to be worked through.
  • Justification carry-over:Regardless of whether you take over answers or not, you can take over the respective justification texts from the original review. Alternatively, you can enter a default text that HITGuard will place in every justification field.

Semi-automatic reassessment

Specifying the after value

Review questions can be linked with measures. If you create a measure, you can afterwards select an after value that indicates how the answer turns out after the measure has been implemented. (See also Answering review questions) With the semi-automatic reassessment (SAR) you can access these after values.

For the SAR, you first navigate to Risk management > Vulnerabilities > Review objects. If a linked measure was implemented (for which an after value of the vulnerability reduction was also set), HITGuard marks the affected review objects here with Reassessment recommended.

  1. Start the reassessment by selecting the marked review objects and clicking the yellow reassessment button. (HITGuard will only make the button available if the review object contains measures that are already completed.)
  2. HITGuard now lists the after values that you specified for the linked measures. (HITGuard only lists the review questions whose measures are already completed.)
  3. With a second click on the reassessment button you complete the process. HITGuard will now create a new, already closed review with the title "Semi-Automatic Reassessment", in which the "after"-values are entered.
Semi-automatic reassessment


Overviews and evaluations

In addition to the individual reviews, HITGuard offers overarching lists in order to evaluate results across all reviews. You will find them under Risk management → Vulnerabilities via the tabs Reviews | Review objects | Deviations | Clarification needed.

Review objects

Overview of the review objects

The review object overview lists all review objects of the current management system. A click opens the detail view.

Review object detail view

There you see how the review object was answered, and – with several versions – how the assessment has developed from version to version. In this screen only the header data are editable; it is not intended for answering a review object.

Deviations

Overview of the deviations

The deviation overview shows all deviations detected during reviews. Via the columns Measure missing, Target value missing and Target value too low you recognize where too little has still been done – affected deviations receive a corresponding tag. A deviation without a tag means that everything has already been created and work is being done on remedying it.

In this overview you can also - as otherwise in step 4 - assign not-yet-assigned deviations to a risk. A double-click opens the review at the place of the deviation, where you can define measures and controls (see Answering review questions).

Optionally you show a column that indicates whether it is an review question (from a knowledge base) or a freely created review result. In this way Experts can extend their own knowledge bases by frequently added review results.

Filter deviations

Deviation filter

The filter controls which deviations are displayed – in each case in comparison to the target score:

  • negative: < target score
  • none: = target score
  • positive: > target score

Target Score weighting

Apply target score weighting

Everywhere deviations occur, HITGuard additionally offers sorting by target score weighting. You define the target score in the management system. The greater the deviation from the target score and the higher the weighting of the protection objective, the higher the weighting:
Target score weighting = degree of deviation × weighting of the protection objective

Example (weighting of the protection objective: Medium = 3):

  • Score of the deviation = 2, target score = 4 → degree of deviation = 2 → weighting = 2 × 3 = 6
  • Score of the deviation = 4, target score = 4 → degree of deviation = 0 → weighting = 0 × 3 = 0

Clarification needed

Overview of the review questions / review results requiring clarification

The overview Clarification needed lists all review questions and review results that were marked as requiring clarification in the course of a review. (see Detail pages of the review questions) A click leads directly to the respective review question or review result. In this way, after a series of reviews, you see at a glance which questions still have to be researched. Via the export button (next to the search bar) you get an easily usable listing.

Important notes and best practices

Best practice
  • Treat deviations directly in the analysis. The review is the central point of risk identification and treatment. Provide detected deviations already here with measures (for elimination) and controls (for monitoring). In this way, deviation, measure and control can be cleanly assigned to the identified risk. If you additionally link the review object with a structure element (e.g. an application), this information also appears in its detail view.
  • Reassessment instead of new assessment. Survey the actual state regularly via a reassessment instead of creating a new analysis each time. In this way old answers and justifications remain visible and the development of a review object becomes traceable.
  • Assess review objects multiple times and name them meaningfully. A review object can occur several times in an analysis. Example: The IT-Grundschutz compendium contains the module "Web applications". If you operate several web applications, answer this module per application and link it with the respective application. Tip: Assign meaningful names such as "Web application 123_Cloud" – in this way you find the review objects easily via the search during reassessments.
  • Prepare self assessment correctly. A self assessment can only be completed if at least one interview partner is stored. The interview partner is also a mandatory field as soon as the review leaves the Draft status.
  • Check before deleting. When deleting a review, the review objects created via it and deviations already assigned to risks are also lost. Completed reviews cannot be deleted.