Menü aufrufen
Toggle preferences menu
Persönliches Menü aufrufen
Nicht angemeldet
Ihre IP-Adresse wird öffentlich sichtbar sein, wenn Sie Änderungen vornehmen.

Hauptseite/en: Unterschied zwischen den Versionen

Aus HITGuard User Guide
FuzzyBot (Diskussion | Beiträge)
Übernehme Bearbeitung einer neuen Version der Quellseite
KoKl (Diskussion | Beiträge)
Keine Bearbeitungszusammenfassung
 
(8 dazwischenliegende Versionen von 2 Benutzern werden nicht angezeigt)
Zeile 1: Zeile 1:
<big><big>Welcome to HITGuard Help!</big></big>


HITGuard offers you comprehensive support in managing and monitoring your risks and compliance requirements. In the menu navigation of HITGuard you will find various modules that support you in meeting your IT governance, risk management and compliance requirements.  
Welcome to the online help of the GRC software '''HITGuard'''. This help accompanies you in controlling and monitoring your risks and compliance requirements – understandable for beginners and useful for experienced users.


This user help provides you with detailed information on how to use each of the HITGuard modules and describes the contents of the entire available menu.
<div class="cdx-message--warning cdx-message cdx-message--block"><div class="cdx-message__content">
'''Do you need support?''' Our support team will be happy to help you at [mailto:support@togethersecure.at support@togethersecure.at].
</div></div>


We have designed this user help to be useful for beginners and experienced users alike. If you have any questions or need help, our support team will be happy to assist you if you contact us under support@hitguard.at.
<span id="Hilfe_und_Schnelleinstieg"></span>
== Help and quick start ==


We hope that this user guide will help you to get the most out of HITGuard. Thank you for choosing our solution!
In the '''Help''' menu item you will find:
* '''First steps''' – the interactive introduction to the HITGuard interface, which also greets you when you log in for the first time.
* '''Online help''' – The online help you are currently on.
* '''Page introduction''' – if an info symbol is visible at the bottom left, a click starts a short introduction to the current page.


<div class="mw-translate-fuzzy">
Are you new to HITGuard or setting up a new module? Here you will find the right starting point:
===<span id="modules"></span> The HITGuard menu ===
* [[Special:MyLanguage/Was sind die ersten Schritte des Aufbaus eines Managementsystems in HITGuard?|First steps in setting up a management system]]
Find the help pages for all possible menu items of the individual modules here:
* [[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Data Protector setzen?|First steps with the data protection module]]
</div>
* [[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Auditmanagement setzen?|First steps with the audit management]]
* [[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Fallmanagement setzen?|First steps with the case management]]
* [[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Doku-Management setzen?|First steps with the document management]]
* [[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem ESG Modul setzen?|First steps with the ESG module]]
* [[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Supplier Risk Management setzen?|First steps with the Supplier Risk Management]]
* [[Special:MyLanguage/Wie aktiviere ich die diversen Mailings, wenn ich mit meinen Einstiegstests fertig bin?|Activating mailings after completing the initial tests]]
 
<span id="Produktüberblick"></span>
== Product overview ==
 
HITGuard has a modular structure. Which menu items you see depends on your permissions and the activated features of the respective management system. However, the "My Tasks" module exists for <i>every</i> user. If you want to learn more about it, follow this link:
{| class="wikitable"
!style="width:330px"| Help for My Tasks
|-
|style="width:330px;" |
:*[[Special:MyLanguage/Meine_Aufgaben|My Tasks]]
|}
Below you will find explanations of all menu items of the other modules:


<div class="mw-translate-fuzzy">
<span id="Basismodule"></span>
{{Card
=== Base modules ===
|column=3
|count = 9
</div>


----
Risk management, measures, controls, master data and administration are always available in HITGuard and form the basis of the tool.


<div class="mw-translate-fuzzy">
====HITGuard basic modules====
The Risk management, Measures, and Controls, as well as Administration are always available in HITGuard and form the basis of the tool:
{| class="wikitable"
{| class="wikitable"
!Risk management
! Module !! Description
|The ''Risk management'' module helps you identify and assess risks and opportunities, and provides you with a central platform to manage your risk assessments. You can freely configure your risk policy and use different workflows that support you in your risk management.<br><br>Find a rough overview of the risk and opportunity workflow [[Special:MyLanguage/Workflow_Risiko Chance|here]].<br>Find information on risks and opportunities for Practitioners [[Special:MyLanguage/Meine_Aufgaben_Gefährdungslagen|here]].
|-
|-
!Measures
| '''Risk management''' || Identification and assessment of risks and opportunities on a central platform for assessments and treatments. The risk policy is freely configurable, and various workflows support you in this. [[Special:MyLanguage/Workflow Risiko Chance|Risk/Opportunity workflow]] · [[Special:MyLanguage/Meine Aufgaben Gefährdungslagen|For Practitioners]]
|The ''Measures'' module helps you implement measures to eliminate or reduce risks and security gaps. You can monitor the implementation of your measures with progress reports and test their effectiveness.<br><br>Find a rough overview of the measure workflow [[Special:MyLanguage/Workflow_Maßnahme|here]].<br>Find information on measures for Practitioners [[Special:MyLanguage/Maßnahmenstatus|here]].
|-
|-
!Controls
| '''Measures''' || Implementation of measures to eliminate or reduce risks and security gaps. Tracking via progress reports and effectiveness review. [[Special:MyLanguage/Workflow Maßnahme|Measure workflow]] · [[Special:MyLanguage/Maßnahmenstatus|For Practitioners]]
|The ''Controls'' module allows you to manage and evaluate your controls and their effectiveness. You can create control definitions and track the execution of the corresponding controls.<br><br>Find a rough overview of the control workflow [[Special:MyLanguage/Workflow_Kontrolle|here]].<br>Find information on controls for Practitioners [[Special:MyLanguage/Kontrollen|hier]].
|-
|-
!Administration
| '''Controls''' || Management and assessment of controls and their effectiveness. Create control definitions and track execution. → [[Special:MyLanguage/Workflow Kontrolle|Control workflow]] · [[Special:MyLanguage/Kontrollen|For Practitioners]]
|In the ''Administration'' module, you can configure HITGuard and adapt it to your specific requirements. Here you will also find functions for managing user accounts, roles and teams as well as for integrating HITGuard into existing systems and processes.
|-
|-
| '''Master data''' || Maintenance of company data, resources and assets as well as knowledge bases, questionnaire templates and standards.
|-
| '''Administration''' || Configuration and adaptation of HITGuard to your requirements: management of user accounts, roles and teams as well as integration into existing systems and processes.
|}
|}
</div>


====HITGuard Add-ons====
=== Add-ons ===
Es gibt diverse Erweiterungen für HITGuard, um weitere Use Cases abdecken zu können.
 
Various extensions cover additional use cases. Add-ons are licensed separately and are usually activated under '''Administration › Management systems''' for one or more management systems.
 
{| class="wikitable"
{| class="wikitable"
!style="font-size:110%"| Datenschutz
! Add-on !! Description
|Das Modul ''Datenschutz'' unterstützt Sie bei der Einhaltung der Datenschutzvorschriften und -richtlinien.<br><br>Bei aktiviertem Datenschutz Add-on erhalten Sie den Menüpunkt "Datenschutz", dessen Inhalte unten zu finden sind. Der Datenschutz wird separat lizenziert und kann dann unter Administration > Managementsysteme für ein Managementsystem aktiviert werden.<br><br>Eine grobe Übersicht des VT-Workflows finden Sie [[Special:MyLanguage/Workflow_VT|hier]].<br>Mehr zum Arbeiten mit VTs für Practitioner finden Sie [[Special:MyLanguage/Meine_Verarbeitungstätigkeiten#Verarbeitungstätigkeit_bearbeiten/erstellen/updaten|hier]].
|-
|-
!style="font-size:110%"| Auditmanagement
| '''Data protection''' || Support in complying with data protection regulations and guidelines. Activates the "Data protection" menu item. → [[Special:MyLanguage/Workflow VT|Processing activity workflow]] · [[Special:MyLanguage/Meine Verarbeitungstätigkeiten#Verarbeitungstätigkeit bearbeiten/erstellen/updaten|Working with processing activities]]
|Das Modul ''Auditmanagement'' ermöglicht es Ihnen, interne und externe Audits durchzuführen, die Ergebnisse zu verfolgen und Berichte zu generieren.<br><br>Bei aktiviertem Auditmanagement Add-on erhalten Sie den Menüpunkt "Auditmanagement", dessen Inhalte unten zu finden sind. Das Auditmanagement wird separat lizenziert und kann dann unter Administration > Managementsysteme für ein oder mehrere Managementsysteme aktiviert werden.
|-
|-
!style="font-size:110%"| Fallmanagement
| '''Audit management''' || Carry out internal and external audits, track results and generate reports. Activates the "Audit management" menu item.
|Das Modul ''Fallmanagement'' unterstützt Sie bei der Bearbeitung von Sicherheitsvorfällen und Verstößen gegen Richtlinien und Vorschriften.<br><br>Bei aktiviertem Fallmanagement Add-on erhalten Sie den Menüpunkt "Fallmanagement", dessen Inhalte unten zu finden sind. Das Fallmanagement wird separat lizenziert und kann dann unter Administration > Managementsysteme für ein oder mehrere Managementsysteme aktiviert werden.<br><br>Eine grobe Übersicht des Meldungsworkflows finden Sie [[Special:MyLanguage/Workflow_Meldung|hier]].<br>Mehr zum Erstellen von Meldungen für Practitioner finden Sie [[Special:MyLanguage/Meine_Aufgaben_Meldungen|hier]].<br>Mehr zum Hinweisgebersystem finden Sie [[Special:MyLanguage/Hinweisgebersystem|hier]].
|-
|-
!style="font-size:110%"| Doku-Management
| '''Case management''' || Processing of security incidents and violations of guidelines and regulations. Activates the "Case management" menu item. → [[Special:MyLanguage/Workflow Meldung|Report workflow]] · [[Special:MyLanguage/Meine Aufgaben Meldungen|Creating reports]] · [[Special:MyLanguage/Hinweisgebersystem|Whistleblower system]]
|Das Modul ''Doku-Management'' fasst Dokumentenlenkung, hochgeladenen Anhänge und das Berichtsarchiv zusammen.<br><br>Bei aktiviertem Doku-Management Add-on erhalten Sie den Menüpunkt "Doku-Management", dessen Inhalte unten beschrieben sind. Das Doku-Management wird separat lizenziert und kann von Ihrem Ansprechpartner bei TogetherSecure für Sie aktiviert werden.<br><br>Eine grobe Übersicht des Doku-Managementworkflows finden Sie [[Special:MyLanguage/Workflow_Doku-Management|hier]].<br>Information zum Prüf- und Freigabeworkflow finden Sie [[Special:MyLanguage/Freigabeworkflow|hier]].
|-
|-
!style="font-size:110%"| ESG Management
| '''Document management''' || Combines document control, uploaded attachments and the report archive. Activation via your contact person at TogetherSecure. → [[Special:MyLanguage/Workflow Doku-Management|Document management workflow]] · [[Special:MyLanguage/Freigabeworkflow|Review and approval workflow]]
|Das ''ESG'' Modul unterstützt Sie bei der Durchführung der doppelten Wesentlichkeitsanalyse.<br><br>Bei aktiviertem ESG Management Add-on wird Ihr Risikomanagment um neue Menüpunkte erweitert. Das ESG Management wird separat lizenziert und kann von Ihrem Ansprechpartner bei TogetherSecure für Sie aktiviert werden.<br><br>Mehr zum ESG Management finden Sie [[Special:MyLanguage/ESG Management|hier]].
|-
|-
!style="font-size:110%"| Supplier Risk Management
| '''ESG Management''' || Support with the double materiality analysis; extends risk management with new menu items. [[Special:MyLanguage/ESG Management|More about ESG Management]]
|Das ''Supplier Risk Management'' Modul erlaubt es Ihnen, Überprüfungen an Lieferanten zu versenden und sie damit in Ihre Auditabläufe einzubinden.<br><br>Bei aktiviertem Supplier Risk Management Add-on werden Ihre Administration und Ihre Überprüfungen um neue Menüpunkte und Optionen erweitert. Das Supplier Risk Management wird separat lizenziert und kann von Ihrem Ansprechpartner bei TogetherSecure für Sie aktiviert werden.<p>Mehr zum Supplier Risk Management finden Sie [[Special:MyLanguage/Supplier Risk Management|hier]].
|-
|-
!style="font-size:110%"| Business Continuity Management
| '''Supplier Risk Management''' || Send reviews to suppliers and integrate them into your audit processes; extends administration and reviews. → [[Special:MyLanguage/Supplier Risk Management|More about Supplier Risk Management]]
|Das Modul ''Business Continuity Management'' (BCM) erlaubt ihnen --- PLATZHALTER --- <p> Mehr zum BCM-Modul finden Sie hier.
|}
|}
Under [[Special:MyLanguage/Hauptseite#How_To_Start|How To Start]] you find the first steps for implementing a management system and for all the add-ons.


<span id="Die_HITGuard_Oberfläche"></span>
<span id="Die_HITGuard_Oberfläche"></span>
== The HITGuard interface ==
== The HITGuard interface ==


[[Datei:Oberflächenbeschreibung2.png|right|701px|Click to enlarge]]
[[Datei:Oberflächenbeschreibung2.png|thumb|center|600px|The HITGuard interface (click to enlarge)]]


The screenshot gives information about the various areas of the HITGuard interface. In the top left corner you find the profile area of the logged-in user and below it the main menu. A click onto the profile picture takes you to the page [[Special:MyLanguage/Profil|Manage account]]. There, a user can modify their data, update their profile picture, or change the password.
The profile area of the logged-in user is located at the top left, with the main menu below it. Clicking on the profile picture opens the [[Special:MyLanguage/Profil|Manage account]] page, where you can change your data, your profile picture and your password.


The marked areas in the image show:
The highlighted areas in the image show:


# Intro for the current page: If the current page has an interactive introduction, it can be started via this icon.
# '''Intro for the current page''' – starts the interactive introduction, if available.
# Collapse/expand menu: With this button, the navigation menu can be collapsed, or expanded again.
# '''Expand/collapse menu''' – shows or hides the navigation menu.
# Switch management system: If the user is authorized for multiple management systems, they can switch between them here. This option is not shown for practitioners or users only authorized for a single management system.
# '''Switch management system''' – switches between management systems (only visible with permission for several systems; not for Practitioners).
# Current management tasks, logout, and change language:
# '''Current management tasks, administration, accessibility, language, log out:'''
#* You receive information about your [[#cur_man_act|current management tasks]] via the envelope.
#* Envelope symbol → [[#Aktuelle Managementaufgaben (das Briefchen)|Current management tasks]]
#* You can configure HITGuard's [[Special:MyLanguage/Barrierefreiheit|accessibility]] with the person-symbol.
#* Gear icon → [[#Menu Reference by Module|Administration]] for basic central functions
#* The flag can be used to switch between English and German.
#* Person symbol → configure [[Special:MyLanguage/Barrierefreiheit|accessibility]]
#* The logout button logs you out.
#* Flag → switch between German and English
#* Log out → log out


<span id="Hauptmenü"></span>
<span id="Hauptmenü"></span>
== Main menu ==
=== Main menu ===


The menu starts off with the "personal" menu items [[#my_act|My tasks]] and [[#my_dashboards|My dashboards]]. These are follows by the menu items of the individual HITGuard modules. The user only sees those modules they are authorized for. Following the module menu items is the menu item [[#hilfe|Help]].
The menu begins with the personal entries '''My Tasks''' and '''My Dashboards''', followed by the module menu items (only visible for authorized modules) and ends with the '''Help''' item.


<span id="Meine_Aufgaben"></span>
<span id="Meine_Aufgaben"></span>
==== <span id="my_act"></span> My tasks====
==== My Tasks ====
 
[[Datei:Meine Aufgaben Badges2.png|right|frameless|My tasks]]


Under "My tasks" you will find the tasks you have to complete in your role as a practitioner. The menu on the left shows you at a glance if you have any pending tasks (orange number badge). This menu shows all items that are activated in at least one management system.
[[Datei:Meine Aufgaben Badges2.png|thumb|right|My Tasks]] Here you will find all the tasks you have to complete in your role as a Practitioner. A click opens the [[Special:MyLanguage/Dashboard|task dashboard]] with a summary of all open tasks; a submenu organizes the tasks by type (including those already completed).


<div class="mw-translate-fuzzy">
* '''Orange badges''' show how many tasks you have to process yourself (e.g. requested ((Special:MyLanguage/Fortschrittsmeldungen|progress reports]] or processing activities to be reviewed).
A click into the ''My tasks'' menu opens the [[Special:MyLanguage/Dashboard|Task dashboard]]. Here, you find a summary of all the tasks pending completion. In addition, clicking on ''My tasks'' opens a submenu that lets you view the tasks by type. There, you also find tasks you have already completed. Orange badges show how many taks you need to work on (e.g., requested progress reports or PAs to be reviewed). Blue badges show how many tasks, for which you are also responsible, somebody else needs to work on (e.g., reviews for which you are responsible but not an interview partner).<p>The states of the different elements are also explained here:
* '''Blue badges''' show tasks for which you share responsibility, but which someone else is processing (e.g. [[Special:MyLanguage/Kontrolldefinitionen|controls]] where your implementation is still being reviewed).
</div>


{| class="wikitable" style="border-style: solid; border-width: 0px 0px 0px 0px"
Status of the elements per menu item: [[Special:MyLanguage/Maßnahmenstatus|Measures]] · [[Special:MyLanguage/Kontrollen|Controls]] · [[Special:MyLanguage/Überprüfungen|Reviews]] · [[Special:MyLanguage/Meine Verarbeitungstätigkeiten|Processing activities]] · [[Special:MyLanguage/Meine Aufgaben Gefährdungslagen|Risks & Opportunities]] · [[Special:MyLanguage/Meine Aufgaben Meldungen|Reports]]
!
<br clear="all">
|-
!Menu items:
|[[Special:MyLanguage/Maßnahmenstatus|Measures]]
|[[Special:MyLanguage/Kontrollen|Controls]]
|[[Special:MyLanguage/Überprüfungen|Reviews]]
|[[Special:MyLanguage/Meine Verarbeitungstätigkeiten|PAs]]
|[[Special:MyLanguage/Meine_Aufgaben_Gefährdungslagen|Risks & opportunities]]
|[[Special:MyLanguage/Meine_Aufgaben_Meldungen|Tickets]]
|}


<span id="Meine_Dashboards"></span>
<span id="Meine_Dashboards"></span>
==== <span id="my_dashboards"></span> My dashboards ====
==== My Dashboards ====


[[Datei:Rn233 DB KPI-Report hinzufügen.png|right|frameless|300px]]
[[Datei:Rn233 DB KPI-Report hinzufügen.png|thumb|right|Dashboard with KPIs and reports]] Dashboards provide an overview of the management systems based on key performance indicators (KPIs) and make reports available for reporting. By default, there is one dashboard each for KPIs from risk management, measures and controls; the data protection, case and audit management add-ons each have an additional dashboard. You only ever see dashboards, KPIs and reports for which your user is authorized.
Dashboards are for getting an overview of the management systems by using key performance indicators (KPIs) and for preparing the reports that are needed regularly. By default, each management system has a dashboard for information related to risk management, to measures, and to controls. Data protection management systems also have a dedicated data protection dashboard, case management systems have a case management dashboard, and audit management systems have an audit management dashboard. However, only dashboards, KPIs, and reports for which the user is authorized are displayed.


In order for a user to access a dashboard and the KPIs and reports of the respective section, they need the "Expert", "Professional" or "Observer" role in the respective module. Thus, to view the risk management dashboard, at least the "Professional" role in risk management is required.
'''Permissions:''' Access to a dashboard or its KPIs and reports requires the "Expert", "Professional" or "Observer" role in the respective module (e.g. at least "Professional" in risk management for the risk management dashboard).


Additional dashboards can also be created and configured. It is possible to make these accessible only to oneself by marking them as "private". Dashboards that are not marked as "private" are visible to all authorized members of the management system. Default dashboards, as in dashboards that are delivered with HITGuard by default, can be edited and reset into their original state, but not deleted. They are marked as vendor-specific dashboards with a "tool" icon. Self-created dashboards can be deleted.
'''My dashboards:''' You can create additional dashboards. Standard dashboards delivered with HITGuard are marked with a tool icon; they can be edited and reset to their original state, but not deleted. Dashboards you create yourself can be configured as "Private" (only for you) or open (for all authorized members) or can also be deleted.


[[Datei:DB Favoriten Markierung.png|right|frameless|380px]]
[[Datei:DB Favoriten Markierung.png|thumb|right|Mark dashboard as favorite]]'''Favorite:''' Using the star next to the dashboard configuration, you mark one dashboard per management system as a favorite – it is ranked first and displayed after logging in.


Users can mark a dashboard as a favorite in each management system. This dashboard will be ranked first for the user and displayed when the user logs in. To mark it, click the star next to the dashboard configuration.
Further reading: [[Special:MyLanguage/Dashboards|Creating/editing dashboards]] · [[Special:MyLanguage/Risikomanagement Dashboard|Risk management]] · [[Special:MyLanguage/ESG Dashboard|ESG]] · [[Special:MyLanguage/Maßnahmen Dashboard|Measures]] · [[Special:MyLanguage/Kontrollen Dashboard|Controls]] · [[Special:MyLanguage/Datenschutz Dashboard|Data protection]] · [[Special:MyLanguage/Fallmanagement Dashboard|Case management]] · [[Special:MyLanguage/Auditmanagement Dashboard|Audit management]]


How to create and edit dashboards as well as information on the KPIs can be found here:
'''Reports on dashboards''' correspond in content to the reports of the respective menu items (see there for explanations) and additionally offer:
{| class="wikitable" style="border-style: solid; border-width: 0px 0px 0px 0px"
!
|-
!Sections:
|[[Special:MyLanguage/Dashboards|Create/edit dashboards]]
|[[Special:MyLanguage/Risikomanagement_Dashboard|Risk management]]
|[[Special:MyLanguage/ESG_Dashboard|ESG]]
|[[Special:MyLanguage/Maßnahmen_Dashboard|Measures]]
|[[Special:MyLanguage/Kontrollen_Dashboard|Controls]]
|[[Special:MyLanguage/Datenschutz_Dashboard|Data protection]]
|[[Special:MyLanguage/Fallmanagement_Dashboard|Case management]]
|[[Special:MyLanguage/Auditmanagement_Dashboard|Audit management]]
|}


The reports that can be created on dashboards are the same as those in the respective menu items in terms of their content and their report options. The explanations for them are found on the help pages of the reports per menu item.<p>
* '''Prepare several versions:''' Using the "Filter" button, different configurations of a report can be saved – e.g. a "Risk report details" with measure and control details for risk owners and a concise "Board report risks" for the board.
Reports on dashboards offer the following additional functions:
* '''Set as default report setting:''' On non-private dashboards, Experts and Professionals can set one configuration as the default per report type. This is used automatically in overview lists (e.g. under ''Risk management Risk assessment''), but remains individually adjustable on the report page itself. Settings already set individually are not overwritten by the default. The default report is marked on the dashboard with a star on the report icon.
*Prepare multiple versions of one report: Just like KPIs, reports can be added to dashboards multiple times. The "filter" button allows you to save different configurations of the report options in order to then have access to various iterations of the same type of report at the click of a button.
:<u>Example</u>: A risk report called "Risk report - details", with details on measures and control definitions, the overview of the gaps assigned to the risk, and its temporal evolution; so that risk owners can periodically file a detailed status of their risks. And a risk report for the top managers called "Board risk report", containing just a rough overview of the open measures and active controls; for board members to get a grasp on the current risk treatment efforts.
*Set as default report settings: Experts and Professionals can save the option configuration of one report per report type on non-private dashboards (e.g. one risk report or one gross-net-risk report). In doing so, the report is then automatically generated with these settings from index pages (e.g. on the page Risk management Risk evaluation, where there aren't any report options available). On the report page itself (e.g., Risk management → Reports → Risks → General) the report is also generated with these settings, but users can make individual changes to these settings. The report set as the default is marked with a star on top of the report icon.
:<u>Example</u>: user A configures a risk report on the dashboard and sets the settings as default. User B generates a risk report from the overview on the page Risk management → risk evaluation and the contents match the default settings. User C has already adjusted the settings the way they need them on the page Risk management → Reports → Risk → General. Their individual settings are not overwritten by the default. User D is using the page Risk management → Reports → Risk → General for the very first time and sees that the report options are set the same way as defined by User A's default.


====Module-specific menu items====
<span id="KI-Features"></span>
Right after the dashboard menu items, you find the [[#modules|module-specific menu items]]. Which modules are shown here depends on the user's authorizations as well as on the features activated for the management system.
==== AI features ====


====AI features====
[[Datei:SternchenbuttonKI.png|thumb|right|AI functions via the "asterisk" button]]In HTML-editable fields (fields with text formatting) you will find an "asterisk" button, via which you call up AI functions. With it you can, for texts:
[[Datei:SternchenbuttonKI.png|thumb|right|60px]] HITGuard offers a multitude of possibilities of AI support across the application. In html-editable fields, meaning fields in which you can format the text, you find a "starlet" button with which you can call up AI functions. With the help of AI you can
*summarize,
*proofread,
*extend,
*shorten,
*change the style of,
*change the tone of,
*and translate texts between English and German.<br>
Furthermore, you can ask AI questions using your own prompts and thus generate your own texts.<p>A special function is available in gap analyses and review results, where the AI functions can be used in the non-html-editable field of the justification.


<span id="Hilfe"></span>
* summarize
==== <span id="hilfe"></span>Help====
* proofread
* expand
* shorten
* change the style
* change the tone
* translate between German and English


Under this menu item you will find the introduction "Getting started", which gives an introduction to HITGuard's interface.
Using your own prompts, you can also ask the AI questions and generate your own texts. There is a special feature in the '''deviation analysis''' and in the '''review result''': there, the AI functions can also be used in the non-HTML-editable field of the justification.


Under the menu item "Online Help" you will find our help directly integrated in HITGuard.
<span id="Aktuelle_Managementaufgaben_(das_Briefchen)"></span>
=== Current management tasks (the envelope) ===


If there is an info icon in the lower left corner, it can be clicked to start a short introduction to the current page.
[[Datei:Management Briefchen.png|thumb|right|Management tasks]] The envelope at the top right informs Professionals and Experts about tasks that have been reported as completed and are waiting for closure/review. Clicking on the envelope opens the list, which shows them these tasks and expired analysis periods. However, the list only shows the tasks from the '''current management system'''. Tasks only appear to users who are authorized to process them (e.g. answered processing activities only to users with Professional/Expert rights in data protection).
 
<span id="Das_Briefchen:_aktuelle_Managementaufgaben"></span>
===<span id="cur_man_act"></span> The letter: current management tasks ===
 
[[Datei:Management Briefchen.png|right|thumb|500px|Management tasks]]
 
The envelope in the upper right corner informs professionals and experts about tasks that have been reported completed and are waiting for completion/review. The tasks always refer to the ''current management system'' only. Thre is also a notice if the current analysis period has expired.
 
In addition, the tasks are only displayed to users who are authorized to edit them. For example, answered processing activities are displayed only to users who are Data Protection professionals or experts and are currently in the Data Protection management system.
 
The tasks are divided into the following items:


{| class="wikitable"
{| class="wikitable"
!Section
! Section !! Description
!Description
|-
!Progress reports
|Progress reports for measures that have been answered.
|-
|-
!Risks
| Progress reports || Answered progress reports on [[Special:MyLanguage/Maßnahmen|measures]].
|Newly submitted or returned risks.
|-
|-
!Protection needs analyses
| Risks || [[Special:MyLanguage/Risikobewertung|Risks]] that have been newly submitted or returned.
|Answered protection needs analyses.
|-
|-
!Gap analyses
| Protection requirement analyses || Answered [[Special:MyLanguage/Schutzbedarf|protection requirement analysis]].
|Answered gap analyses.
|-
|-
!Tickets assigned to me
| Vulnerability analyses || Answered [[Special:MyLanguage/Schwachstellen|vulnerability analyses]].
|Open tickets that are assigned to you. Closed and answered tickets are not displayed.
|-
|-
!Not assigned tickets
| Reports assigned to me || Open [[Special:MyLanguage/Meldungen|reports]] assigned to you.
|Tickets that have not yet been assigned an advisor. If a support team is configured, these tickets are only shown to members of that team.
|-
|-
!Processing activities
| Unassigned reports || Reports not yet assigned to any user. Only visible to team members if a support team is stored.
|Answered processing activities.
|-
|-
| Processing activities || Answered [[Special:MyLanguage/Verarbeitungstätigkeit|processing activities]].
|}
|}


<span id="Benutzer_Anleitungen"></span>
<span id="HITGuard_Menü-Überblick"></span>
== <span id="User_Guides"></span>User guides==  
== HITGuard module overview ==
 
Below are all menu items of the individual modules. Only modules and items for which you are authorized and which have been activated in the management system are visible.
 
<div class="hg-module-grid" style="display:flex; flex-wrap:wrap; gap:1em; margin-top:1em;">
 
<div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;">
<div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;">Risk management</div>
* [[Special:MyLanguage/Strukturanalyse|Structure analysis]]
* [[Special:MyLanguage/Schutzbedarf|Protection requirement]]
* [[Special:MyLanguage/Schwachstellen|Vulnerabilities]]
* [[Special:MyLanguage/Bedrohungen|Threats]]
* [[Special:MyLanguage/Risikobewertung|Risks & Opportunities]]
* [[Special:MyLanguage/Auswirkungen|Impacts]]
* [[Special:MyLanguage/ESG Themen|Fields of Action]]
* [[Special:MyLanguage/Risikobehandlung|Treatment R&O]]
* [[Special:MyLanguage/Berichte für das Risikomanagement|Reports]]
* [[Special:MyLanguage/Risikomanagement Einstellungen|Settings]]
</div>
 
<div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;">
<div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;">Audit management</div>
* [[Special:MyLanguage/Auditkalender|Audit calendar]]
* [[Special:MyLanguage/Auditplanung|Audit planning]]
* [[Special:MyLanguage/Auditdurchführung|Audit execution]]
* [[Special:MyLanguage/Auditbehandlung|Audit treatment]]
* [[Special:MyLanguage/Externe Auditoren|External auditors]]
* [[Special:MyLanguage/Auditcluster|Audit cluster]]
* [[Special:MyLanguage/Funktionen|Functions]]
* [[Special:MyLanguage/Berichte für das Auditmanagement|Reports]]
* [[Special:MyLanguage/Auditmanagement Einstellungen|Settings]]
</div>
 
<div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;">
<div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;">Case management</div>
* [[Special:MyLanguage/Vorfall melden|Report incident]]
* [[Special:MyLanguage/Fristen|Deadlines]]
* [[Special:MyLanguage/Meldungen|Reports]]
* [[Special:MyLanguage/Akten|Files]]
* [[Special:MyLanguage/Berichte für das Fallmanagement|Reports]]
* [[Special:MyLanguage/Fallmanagement-Einstellungen|Settings]]
* [[Special:MyLanguage/Hinweisgebersystem|Whistleblower system]]
</div>
 
<div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;">
<div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;">Measures</div>
* [[Special:MyLanguage/Aktuelle Maßnahmen|Current measures]]
* [[Special:MyLanguage/Fortschrittsmeldungen|Progress reports]]
* [[Special:MyLanguage/Historie|History]]
* [[Special:MyLanguage/Auswertungen|Evaluations]]
* [[Special:MyLanguage/Berichte für Maßnahmen|Reports]]
* [[Einstellungen|Settings]]
</div>
 
<div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;">
<div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;">Controls</div>
* [[Special:MyLanguage/Kontrolldefinitionen|Control definitions]]
* [[Special:MyLanguage/Berichte für Kontrollen|Reports]]
</div>
 
<div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;">
<div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;">Data protection</div>
* [[Special:MyLanguage/Verarbeitungsregister|Processing register]]
* [[Special:MyLanguage/Datenschutz-Folgenabschätzung|DPIA]]
* [[Special:MyLanguage/Externe|External parties]]
* [[Special:MyLanguage/TOMs|TOMs]]
* [[Special:MyLanguage/Betroffenenkategorien|Data subject categories]]
* [[Special:MyLanguage/Berichte für den Datenschutz|Reports]]
* [[Special:MyLanguage/Datenschutz Einstellungen|Settings]]
</div>
 
<div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;">
<div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;">Document management</div>
* [[Special:MyLanguage/Dokumentenmanagement|Documents]]
* [[Special:MyLanguage/Dokumente|Uploaded attachments]]
* [[Special:MyLanguage/Berichtsarchiv|Report archive]]
</div>


=== FAQ ===
<div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;">
:*[[Special:MyLanguage/FAQ|FAQ]]
<div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;">Master data</div>
* [[Special:MyLanguage/OrgEh - Organisationseinheiten|Organizational units]]
* [[Special:MyLanguage/Ressourcen|Resources]]
* [[Special:MyLanguage/Datenkategorien|Data categories]]
* [[Special:MyLanguage/Prozesse|Processes]]
* [[Special:MyLanguage/Lieferanten|Suppliers]]
* [[Special:MyLanguage/Standards und Normen|Standards and norms]]
* [[Special:MyLanguage/Wissensdatenbanken|Knowledge bases]]
* [[Special:MyLanguage/Dokumente|Uploaded attachments]]
* [[Special:MyLanguage/Berichtsarchiv|Report archive]]
</div>


=== Glossary ===
<div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;">
:*[[Special:MyLanguage/Glossar|Glossary]]
<div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;">Administration (top right)</div>
* [[Special:MyLanguage/Benutzer und Benutzerrollen|Users and user roles]]
* [[Special:MyLanguage/Teams|Teams]]
* [[Special:MyLanguage/Managementsysteme|Management systems]]
* [[Special:MyLanguage/Globale Einstellungen|Global settings]]
* [[Special:MyLanguage/Risikopolitik|Risk policy]]
* [[Special:MyLanguage/KI-Promptverwaltung|AI prompt management]]
* [[Special:MyLanguage/Textbausteine|Text modules]]
* [[Special:MyLanguage/Datenimport|Data import]]
* [[Special:MyLanguage/Lizenzierung|Licensing]]
* [[Special:MyLanguage/Jobs|Jobs]]
</div>
 
</div>
 
<span id="Anleitungen_&amp;_Nachschlagewerke"></span>
== Guides & references ==
 
<span id="FAQ_&amp;_Glossar"></span>
=== FAQ & glossary ===
 
* [[Special:MyLanguage/FAQ|FAQ]]
* [[Special:MyLanguage/Glossar|Glossary]]


<span id="Arbeiten_mit_HITGuard"></span>
<span id="Arbeiten_mit_HITGuard"></span>
=== Working with HITGuard ===
=== Working with HITGuard ===


:*[[Special:MyLanguage/Profil|User profile]]
* [[Special:MyLanguage/Profil|User profile]]
:*[[Special:MyLanguage/Funktionalität der Tabellen|Table functionality and symbols]]
* [[Special:MyLanguage/Funktionalität der Tabellen|Functionality and symbols of the tables]]
:*[[Special:MyLanguage/Icons und Buttons|Explanation of the various icons and buttons in HITGuard]]
* [[Special:MyLanguage/Icons und Buttons|Icons and buttons in HITGuard]]
:*[[Special:MyLanguage/FAQ#Tips,_Tricks_&_Best_Practice|Tips, tricks & best practice]]
* [[Special:MyLanguage/FAQ#Tips,_Tricks_&_Best_Practice|Tips, tricks & best practice]]
 
<span id="Anleitungen_nach_Rolle"></span>
=== Guides by role ===
 
'''Experts or Professionals'''


<span id="Experten_oder_Professionals"></span>
* [[Special:MyLanguage/Audit erstellen|Create/edit audit]]
===Experts or Professionals===
* [[Special:MyLanguage/Auditprogramm erstellen|Create/edit audit program]]
* [[Schwachstellen#create_überprüfung|Create/edit reviews (deviation analyses/review results)]]
* [[Special:MyLanguage/Risikobewertung#create_rsik|Record/edit risk]]
* [[Special:MyLanguage/Maßnahmen#create_measure|Create/edit measure]]
* [[Special:MyLanguage/Kontrolldefinitionen#create_check|Create/edit controls]]
* [[Special:MyLanguage/Fortschrittsmeldungen#req_progress|Request progress reports]]
* [[Special:MyLanguage/Externe#create_external|Create/edit external parties]]


:*[[Special:MyLanguage/Audit erstellen|Create/edit audit]]
'''Administrators or Experts'''
:*[[Special:MyLanguage/Auditprogramm erstellen|Create/edit audit programs]]
:*[[Schwachstellen#create_überprüfung|Create/edit reviews (create gap analyses/record review results)]]
:*[[Special:MyLanguage/Risikobewertung#create_rsik|Enter/edit risk]]
:*[[Special:MyLanguage/Maßnahmen#create_measure|Create/edit measure]]
:*[[Special:MyLanguage/Kontrolldefinitionen#create_check|Create/edit controls]]
:*[[Special:MyLanguage/Fortschrittsmeldungen#req_progress|Request progress reports]]
:*[[Special:MyLanguage/Externe#create_external|Create/edit externals]]


<span id="Administratoren_oder_Experten"></span>
* [[Special:MyLanguage/Risikopolitik|Manage risk policy]]
===Administrators or Experts===
* [[Special:MyLanguage/Einstellungen|Manage settings for measures and controls]]
* [[Special:MyLanguage/Betroffenenkategorien#create_affected|Create/edit data subject categories]]
* [[Special:MyLanguage/Datenimport#import|Import data]]


:*[[Special:MyLanguage/Risikopolitik| Manage risk policy]]
'''Administrators'''
:*[[Special:MyLanguage/Einstellungen| Manage settings of measures and controls]]
:*[[Special:MyLanguage/Betroffenenkategorien#create_affected|Create/edit data subject categories]]
:*[[Special:MyLanguage/Datenimport#import|import Data]]


=== Administrators ===
* [[Special:MyLanguage/REST API|REST API: data import/export interface]]
:*[[Special:MyLanguage/REST API| REST API: Data import/export interface]]


===External users===
'''External users'''
:*[[Special:MyLanguage/Lieferantenportal| HITGuard portal for suppliers]]


===How To Start===
* [[Special:MyLanguage/Lieferantenportal|HITGuard portal for suppliers]]


*[[Special:MyLanguage/Was sind die ersten Schritte des Aufbaus eines Managementsystems in HITGuard?|What are the first steps towards implementing a management system in HITGuard?]]
<span id="Workflows_im_Überblick"></span>
*[[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Data Protector setzen?|Which first steps should I take to start working with the data protection module?]]
=== Workflows at a glance ===
*[[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Auditmanagement setzen?|Which first steps should I take to start working with the audit management module?]]
*[[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Fallmanagement setzen?|Which first steps should I take to start working with the case management module?]]
*[[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Doku-Management setzen?|Which first steps should I take to start working with the doc management?]]
*[[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem ESG Modul setzen?|Which first steps should I take to start working with the ESG module?]]
*[[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Supplier Risk Management setzen?|Which first steps should I take to start working with the supplier risk management?]]
*[[Special:MyLanguage/Wie aktiviere ich die diversen Mailings, wenn ich mit meinen Einstiegstests fertig bin?|How do I activate the various mailings after I've completed my initial tests?]]


<div class="mw-translate-fuzzy">
* [[Special:MyLanguage/Workflow Maßnahme|Measure workflow]]
===Giudes and rough overview of the workflows===
* [[Special:MyLanguage/Workflow Kontrolle|Control workflow]]
*[[Special:MyLanguage/Workflow Maßnahme|What does the general workflow for measures look like?]]
* [[Special:MyLanguage/Workflow Überprüfung|Review workflow]]
*[[Special:MyLanguage/Workflow Kontrolle|What does the general workflow for controls look like?]]
* [[Special:MyLanguage/Workflow VT|Processing activity workflow]]
*[[Special:MyLanguage/Workflow Überprüfung|What does the general workflow for reviews look like?]]
* [[Special:MyLanguage/Workflow Risiko Chance|Risk/Opportunity workflow]]
*[[Special:MyLanguage/Workflow VT|What does the general workflow for processing activities look like?]]
* [[Special:MyLanguage/Workflow Meldung|Report workflow]]
*[[Special:MyLanguage/Workflow Risiko Chance|What does the general workflow for risk and opportunities look like?]]
* [[Special:MyLanguage/Workflow Doku-Management|Document management workflow]]
*[[Special:MyLanguage/Workflow Meldung|What does the general workflow for tickets look like?]]
* [[Special:MyLanguage/Wie sollte ich vorgehen, wenn ich eine Schutzbedarfsanalyse vornehmen möchte?|Procedure for a protection requirement analysis]]
*[[Special:MyLanguage/Workflow Doku-Management|What does the general doc management workflow look like?]]
*[[Special:MyLanguage/Wie sollte ich vorgehen, wenn ich eine Schutzbedarfsanalyse vornehmen möchte?|How should I proceed if I want to perform a protection needs analysis?]]
</div>


== Release Notes ==
== Release Notes ==


{| class="wikitable"
{| class="wikitable"
!Year
! Year !! Releases
! colspan="3" |Month
|-
|-
!2026
| 2026 || [[Special:MyLanguage/HITGuard Release April 2026|April]]
|[[Special:MyLanguage/HITGuard Release April 2026|April]]
|
|
|-
|-
!2025
| 2025 || [[Special:MyLanguage/HITGuard Release April 2025|April]] · [[Special:MyLanguage/HITGuard Release August 2025|August]] · [[Special:MyLanguage/HITGuard Release November 2025|November]]
|[[Special:MyLanguage/HITGuard Release April 2025 |April]]
|[[Special:MyLanguage/HITGuard Release August 2025 |August]]
|[[Special:MyLanguage/HITGuard Release November 2025 |November]]
|-
|-
!2024
| 2024 || [[Special:MyLanguage/HITGuard Release März 2024|March]] · [[Special:MyLanguage/HITGuard Release August 2024|August]] · [[Special:MyLanguage/HITGuard Release Dezember 2024|December]]
|[[Special:MyLanguage/HITGuard Release März 2024 |March]]
|[[Special:MyLanguage/HITGuard Release August 2024 |August]]
|[[Special:MyLanguage/HITGuard Release Dezember 2024 |December]]
|-
|-
!2023
| 2023 || [[Special:MyLanguage/HITGuard Release Februar 2023|February]] · [[Special:MyLanguage/HITGuard Release Juni 2023|June]] · [[Special:MyLanguage/HITGuard Release Oktober 2023|October]]
|[[Special:MyLanguage/HITGuard Release Februar 2023 |February]]
|[[Special:MyLanguage/HITGuard Release Juni 2023 |June]]
|[[Special:MyLanguage/HITGuard Release Oktober 2023 |October]]
|-
|-
! 2022
| 2022 || [[Special:MyLanguage/HITGuard Release Jänner 2022|January]] · [[Special:MyLanguage/HITGuard Release Juni 2022|June]] · [[Special:MyLanguage/HITGuard Release Oktober 2022|October]]
|[[Special:MyLanguage/HITGuard Release Jänner 2022 |January]]
|[[Special:MyLanguage/HITGuard Release Juni 2022 |June]]
|[[Special:MyLanguage/HITGuard Release Oktober 2022 |October]]
|-
|-
!2021
| 2021 || [[Special:MyLanguage/HITGuard Release Jänner 2021|January]] · [[Special:MyLanguage/HITGuard Release April 2021|April]] · [[Special:MyLanguage/HITGuard Release September 2021|September]]
|[[Special:MyLanguage/HITGuard Release Jänner 2021|January]]
|[[Special:MyLanguage/HITGuard Release April 2021|April]]
|[[Special:MyLanguage/HITGuard Release September 2021 |September]]
|-
|-
!2020
| 2020 || [[Special:MyLanguage/HITGuard Release April 2020|April]] · [[Special:MyLanguage/HITGuard Release Juli 2020|July]] · [[Special:MyLanguage/HITGuard Release Oktober 2020|October]]
|[[Special:MyLanguage/HITGuard Release April 2020|April]]
|[[Special:MyLanguage/HITGuard Release Juli 2020|July]]
|[[Special:MyLanguage/HITGuard Release Oktober 2020|October]]
|-
|-
!2019
| 2019 || [[Special:MyLanguage/HITGuard Release März 2019|March]] · [[Special:MyLanguage/HITGuard Release April 2019|April]] · [[Special:MyLanguage/HITGuard Release Juli 2019|July]] · [[Special:MyLanguage/HITGuard Release Dezember 2019|December]]
|[[Special:MyLanguage/HITGuard Release März 2019|March]], [[Special:MyLanguage/HITGuard Release April 2019|April]]
|[[Special:MyLanguage/HITGuard Release Juli 2019|July]]
|[[Special:MyLanguage/HITGuard Release Dezember 2019|December]]
|}
|}


Release Notes from the years 2017 and 2018 were directly integrated into the help.
Release notes from the years 2017 and 2018 have been incorporated directly into the help.


== Login Möglichkeiten und unterstützte Authentication Provider ==
<span id="Anmeldung_&amp;_Authentifizierung"></span>
* [[Special:MyLanguage/Login Möglichkeiten|Login Möglichkeiten]]
== Login & authentication ==
 
* [[Special:MyLanguage/Login Möglichkeiten|Login options]]
* [[Special:MyLanguage/Passkeys|Passkeys]]
* [[Special:MyLanguage/Passkeys|Passkeys]]
* [[Special:MyLanguage/2FA|2-Faktor-Authentifizierung]]
* [[Special:MyLanguage/2FA|Two-factor authentication]]
 
<span id="Installationshilfe"></span>
== Installation help ==


== Installation assistance ==
* [[Special:MyLanguage/Installationshilfe|Installation help]]
*[[Special:MyLanguage/Installationshilfe |Installation assistance]]

Aktuelle Version vom 10. August 2026, 13:32 Uhr


Welcome to the online help of the GRC software HITGuard. This help accompanies you in controlling and monitoring your risks and compliance requirements – understandable for beginners and useful for experienced users.

Do you need support? Our support team will be happy to help you at support@togethersecure.at.

Help and quick start

In the Help menu item you will find:

  • First steps – the interactive introduction to the HITGuard interface, which also greets you when you log in for the first time.
  • Online help – The online help you are currently on.
  • Page introduction – if an info symbol is visible at the bottom left, a click starts a short introduction to the current page.

Are you new to HITGuard or setting up a new module? Here you will find the right starting point:

Product overview

HITGuard has a modular structure. Which menu items you see depends on your permissions and the activated features of the respective management system. However, the "My Tasks" module exists for every user. If you want to learn more about it, follow this link:

Help for My Tasks

Below you will find explanations of all menu items of the other modules:

Base modules

Risk management, measures, controls, master data and administration are always available in HITGuard and form the basis of the tool.

Module Description
Risk management Identification and assessment of risks and opportunities on a central platform for assessments and treatments. The risk policy is freely configurable, and various workflows support you in this. → Risk/Opportunity workflow · For Practitioners
Measures Implementation of measures to eliminate or reduce risks and security gaps. Tracking via progress reports and effectiveness review. → Measure workflow · For Practitioners
Controls Management and assessment of controls and their effectiveness. Create control definitions and track execution. → Control workflow · For Practitioners
Master data Maintenance of company data, resources and assets as well as knowledge bases, questionnaire templates and standards.
Administration Configuration and adaptation of HITGuard to your requirements: management of user accounts, roles and teams as well as integration into existing systems and processes.

Add-ons

Various extensions cover additional use cases. Add-ons are licensed separately and are usually activated under Administration › Management systems for one or more management systems.

Add-on Description
Data protection Support in complying with data protection regulations and guidelines. Activates the "Data protection" menu item. → Processing activity workflow · Working with processing activities
Audit management Carry out internal and external audits, track results and generate reports. Activates the "Audit management" menu item.
Case management Processing of security incidents and violations of guidelines and regulations. Activates the "Case management" menu item. → Report workflow · Creating reports · Whistleblower system
Document management Combines document control, uploaded attachments and the report archive. Activation via your contact person at TogetherSecure. → Document management workflow · Review and approval workflow
ESG Management Support with the double materiality analysis; extends risk management with new menu items. → More about ESG Management
Supplier Risk Management Send reviews to suppliers and integrate them into your audit processes; extends administration and reviews. → More about Supplier Risk Management

The HITGuard interface

The HITGuard interface (click to enlarge)

The profile area of the logged-in user is located at the top left, with the main menu below it. Clicking on the profile picture opens the Manage account page, where you can change your data, your profile picture and your password.

The highlighted areas in the image show:

  1. Intro for the current page – starts the interactive introduction, if available.
  2. Expand/collapse menu – shows or hides the navigation menu.
  3. Switch management system – switches between management systems (only visible with permission for several systems; not for Practitioners).
  4. Current management tasks, administration, accessibility, language, log out:

The menu begins with the personal entries My Tasks and My Dashboards, followed by the module menu items (only visible for authorized modules) and ends with the Help item.

My Tasks

My Tasks

Here you will find all the tasks you have to complete in your role as a Practitioner. A click opens the task dashboard with a summary of all open tasks; a submenu organizes the tasks by type (including those already completed).

  • Orange badges show how many tasks you have to process yourself (e.g. requested ((Special:MyLanguage/Fortschrittsmeldungen|progress reports]] or processing activities to be reviewed).
  • Blue badges show tasks for which you share responsibility, but which someone else is processing (e.g. controls where your implementation is still being reviewed).

Status of the elements per menu item: Measures · Controls · Reviews · Processing activities · Risks & Opportunities · Reports

My Dashboards

Dashboard with KPIs and reports

Dashboards provide an overview of the management systems based on key performance indicators (KPIs) and make reports available for reporting. By default, there is one dashboard each for KPIs from risk management, measures and controls; the data protection, case and audit management add-ons each have an additional dashboard. You only ever see dashboards, KPIs and reports for which your user is authorized.

Permissions: Access to a dashboard or its KPIs and reports requires the "Expert", "Professional" or "Observer" role in the respective module (e.g. at least "Professional" in risk management for the risk management dashboard).

My dashboards: You can create additional dashboards. Standard dashboards delivered with HITGuard are marked with a tool icon; they can be edited and reset to their original state, but not deleted. Dashboards you create yourself can be configured as "Private" (only for you) or open (for all authorized members) or can also be deleted.

Mark dashboard as favorite

Favorite: Using the star next to the dashboard configuration, you mark one dashboard per management system as a favorite – it is ranked first and displayed after logging in.

Further reading: Creating/editing dashboards · Risk management · ESG · Measures · Controls · Data protection · Case management · Audit management

Reports on dashboards correspond in content to the reports of the respective menu items (see there for explanations) and additionally offer:

  • Prepare several versions: Using the "Filter" button, different configurations of a report can be saved – e.g. a "Risk report – details" with measure and control details for risk owners and a concise "Board report risks" for the board.
  • Set as default report setting: On non-private dashboards, Experts and Professionals can set one configuration as the default per report type. This is used automatically in overview lists (e.g. under Risk management › Risk assessment), but remains individually adjustable on the report page itself. Settings already set individually are not overwritten by the default. The default report is marked on the dashboard with a star on the report icon.

AI features

AI functions via the "asterisk" button

In HTML-editable fields (fields with text formatting) you will find an "asterisk" button, via which you call up AI functions. With it you can, for texts:

  • summarize
  • proofread
  • expand
  • shorten
  • change the style
  • change the tone
  • translate between German and English

Using your own prompts, you can also ask the AI questions and generate your own texts. There is a special feature in the deviation analysis and in the review result: there, the AI functions can also be used in the non-HTML-editable field of the justification.

Current management tasks (the envelope)

Management tasks

The envelope at the top right informs Professionals and Experts about tasks that have been reported as completed and are waiting for closure/review. Clicking on the envelope opens the list, which shows them these tasks and expired analysis periods. However, the list only shows the tasks from the current management system. Tasks only appear to users who are authorized to process them (e.g. answered processing activities only to users with Professional/Expert rights in data protection).

Section Description
Progress reports Answered progress reports on measures.
Risks Risks that have been newly submitted or returned.
Protection requirement analyses Answered protection requirement analysis.
Vulnerability analyses Answered vulnerability analyses.
Reports assigned to me Open reports assigned to you.
Unassigned reports Reports not yet assigned to any user. Only visible to team members if a support team is stored.
Processing activities Answered processing activities.

HITGuard module overview

Below are all menu items of the individual modules. Only modules and items for which you are authorized and which have been activated in the management system are visible.

Guides & references

FAQ & glossary

Working with HITGuard

Guides by role

Experts or Professionals

Administrators or Experts

Administrators

External users

Workflows at a glance

Release Notes

Year Releases
2026 April
2025 April · August · November
2024 March · August · December
2023 February · June · October
2022 January · June · October
2021 January · April · September
2020 April · July · October
2019 March · April · July · December

Release notes from the years 2017 and 2018 have been incorporated directly into the help.

Login & authentication

Installation help