Menü aufrufen
Toggle preferences menu
Persönliches Menü aufrufen
Nicht angemeldet
Ihre IP-Adresse wird öffentlich sichtbar sein, wenn Sie Änderungen vornehmen.

Workflowpläne/en: Unterschied zwischen den Versionen

Aus HITGuard User Guide
KoKl (Diskussion | Beiträge)
Die Seite wurde neu angelegt: „<b>Name & Description:</b> * Enter the purpose of the workflow plan here so that you can understand its intention later on.“
 
KoKl (Diskussion | Beiträge)
Keine Bearbeitungszusammenfassung
 
(2 dazwischenliegende Versionen desselben Benutzers werden nicht angezeigt)
Zeile 27: Zeile 27:
* Enter the purpose of the workflow plan here so that you can understand its intention later on.  
* Enter the purpose of the workflow plan here so that you can understand its intention later on.  


<div class="mw-translate-fuzzy">
<b>Responsible User:</b>
<b>Responsible User:</b>
* The responsible user is tasked with preparing the workflow plan, not with responding to the workflows.  
* The responsible user is tasked with preparing the workflow plan, not with responding to the workflows.  
* The responsible user is informed by e-mail one week before the workflow is triggered. If there are problems or conflicts at this point (see below), these are described in the e-mail and can therefore be resolved in good time.  
* The responsible user is informed by e-mail one week before the workflow is triggered. If there are problems or conflicts at this point (see below), these are described in the e-mail and can therefore be resolved in good time.  
* The responsible user is also informed when the workflow is triggered about which reviews were sent out successfully and whether there were any problems or conflicts that prevented further reviews from being sent out.
* The responsible user is also informed when the workflow is triggered about which reviews were sent out successfully and whether there were any problems or conflicts that prevented further reviews from being sent out.
</div>


<b>Notify management system responsible persons:</b>
<b>Notify management system responsible persons:</b>
Zeile 40: Zeile 38:
* Specify here when the workflow plan should be triggered next. At this point, the reassessments/risks are then sent to the interview partners/Advisors based on the linked elements.
* Specify here when the workflow plan should be triggered next. At this point, the reassessments/risks are then sent to the interview partners/Advisors based on the linked elements.


<div lang="de" dir="ltr" class="mw-content-ltr">
<b>Recurring workflow:</b>
<b>Wiederkehrender Workflow:</b>
* If the workflow plan should be triggered regularly, you can set this here.  
* Wenn der Workflowplan regelmäßig auslösen soll, können Sie dies hier einstellen.  
* After being triggered, HITGuard will renew the date and add the time span you have defined here to the old date.
* Nach dem Auslösen wird HITGuard das Datum erneuern und die Zeitspanne die sie hier definiert haben zum alten Datum hinzurechnen.
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
<span id="Tab_2:_Elemente_hinzufügen"></span>
==Tab 2: Elemente hinzufügen==
==Tab 2: Adding elements==
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
[[Datei:SBA_WFP_Schutzbedarfsanalysen.png|right|thumb|600px|Protection needs analyses]][[Datei:WFPüberprüf.png|right|thumb|600px|Vulnerability/GAP analyses]][[Datei:WFPrisikenchancen.png|right|thumb|600px|Risks & Opportunities]]Depending on the variant, the second tab is called "Protection needs analyses", "Reviews" or "Risks & Opportunities". In the three screenshots on the right, you can see that the three pages are structured as a grid. In the following, we address the general basic functions that all workflow plans share.  
[[Datei:SBA_WFP_Schutzbedarfsanalysen.png|right|thumb|600px|Schutzbedarfsanalysen]][[Datei:WFPüberprüf.png|right|thumb|600px|Schwachstellenanalysen]][[Datei:WFPrisikenchancen.png|right|thumb|600px|Risiken & Chancen]]Der zweite Tab heißt je nach Variante "Schutzbedarfsanalysen", "Überprüfungen" oder "Risiken & Chancen". In den drei Screenshots rechts sehen Sie, dass die drei Seiten als Grid aufgebaut sind. Im Folgenden gehen wir auf die allgemeinen Grundfunktionen ein, die alle Workflowpläne teilen.
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
<b>Link button</b>
<b>Link-Button</b>
* To the right above the grid, you can attach the original elements that the workflow plan is to reassess.<p>
* Rechts über dem Grid können Sie die ursprünglichen Elemente anhängen, die der Workflowplan neubewerten soll.<p>
<b>Grid overview of the element</b>
<b>Grid-Übersicht über das Element</b>
* Here you see the title of the element as well as some additional information that defines the analyses or risks in more detail. Using the column selection, you can also hide these properties.
* Hier sehen Sie den Titel des Elements sowie einige Zusatzinformationen, die die Analysen oder Risiken näher definieren. Mit der Spaltenauswal können Sie diese Eigenschaften auch ausblenden.
* The titles of the elements function as links. By clicking the blue text, you can jump directly into the analysis or the risk.
* Die Titel der Elemente funktionieren als Link. Mit einem Klick auf den blauen Text können Sie direkt in die Analyse bzw. das Risiko springen.
* Note: Here you always see the latest version/reassessment of the analyses. If the workflow has just been triggered, the link no longer takes you to the original analysis, but to the reassessment that has already been created automatically.<p>
* Achtung: Hier sehen sie jeweils die neueste Version/Neubewertung der Analysen. Wenn der Workflow gerade ausgelöst hat, gelangen Sie über den Link nicht mehr zur ursprünglchen Analyse, sondern zur Neubewertung, die bereits automatisch erstellt wurde.<p>
<b>Warnings & conflicts</b>
<b>Warnungen & Konflikte</b>
* In the grid, HITGuard points out possible conflicts of the workflow plans. The Conflicts column indicates the origin of the conflict. Details about the conflict can also be found in the tooltip when you hover the mouse over the triangle.<br>
* Im Grid weist HITGuard Sie auf mögliche Konflikte der Workflowpläne hin. DIe Spalte Konflikte weist Sie auf den Ursprung des Konfliktes hin. Details zum Konflikt finden sich auch im Tooltip, wenn man mit der Maus über dem Dreieck hovert.<br>
* <b>Yellow warning triangles</b>: If the risk or the analysis <i>itself</i> is not ready for a reassessment, this is shown with a yellow warning triangle. Usually this is because the vulnerability/GAP or protection needs analysis is not yet completed, or because the risk is already in the assessment workflow. Yellow warning triangles are also shown here when the workflow has just been triggered.
* <b>Gelbe Warndreiecke</b>: Ist das Risiko oder die Analyse <i>selbst</i> nicht bereit für eine Neubewertung, wird dies mit einem gelben Warndreieck dargestellt. Meistens leigt dies daran, dass die Schwachstellen- oder Schutzbedarfsanalyse noch nicht abgeschlossen ist, oder dass das Risiko schon im Bewertungsworkflow ist. Auch wenn der Workflow gerade ausgelöst wurde, werden hier auch gelbe Warndreiecke gezeigt.
* <b>Red warning triangles</b>: If there is a conflict with <i>another element</i>, this is shown with a red warning triangle. The conflict can arise in the same or in another management system (e.g. [[Special:MyLanguage/Schutzbedarf#Schutzbedarfsanalysen_können_sich_gegenseitig_blockieren!|reassessments of protection needs analyses]] in another management system). <p>
* <b>Rote Warndreiecke</b>: Besteht ein Konflikt mit einem <i>anderen Element</i>, wird dies mit einem roten Warndreieck dargestellt. Der Konflikt kann in demselben oder einem anderen Managementsystem kommen (zB [[Special:MyLanguage/Schutzbedarf#Schutzbedarfsanalysen_können_sich_gegenseitig_blockieren!|Neubewertungen von Schutzbedarfsananalysen]] in einem anderen Managementsystem). <p>
<b>Status: Active/Paused</b>
<b>Status: Aktiv/Pausiert</b>
* This status indicates whether the element will be triggered with the workflow plan. Active elements trigger on the date of the workflow plan, paused ones skip a cycle. You control the status with the Play/Pause button on the right side of the grid. In the second screenshot you see a paused review.<p>
* Dieser Status gibt an, ob das Element mit dem Workflowplan auslösen wird. Aktive Elemente lösen mit dem Datum des Workflowplans aus, Pausierte setzen einen Zyklus aus. Sie steuern den Status mit dem Play/Pause Button auf der rechten Seite des Grids. Im zweiten Screenshot sehen sie eine pausierte Überprüfung.<p>
<b>Play/Pause button</b>
<b>Play/Pause Button</b>
* With this button you control the Active/Paused status of the individual element.<p>
* Mit diesem Button steuern Sie den Status Aktiv/Pausiert des einzelnen Elements.<p>
<b>Unlink button</b>
<b>Entlinken-Button</b>
*This permanently removes the review from the workflow plan. <p>
*Hiermit wird die Überprüfung dauerhaft aus dem Workflowplan entfernt. <p>
<b>Reassess button</b>
<b>Neubewerten-Button</b>
* With this button you can manually bypass the workflow plan and create a reassessment manually. For example, you can pause a protection needs analysis and then carry out a reassessment manually. HITGuard will track this, so your manual reassessment will later be visible here in the overview. If you complete the manual reassessment in good time, HITGuard can use it as a template for the next cycle.<p>
* Mit diesem Button können Sie den Workflowplan manuell umgehen und eine Neubewertung manuell anlegen. So können Sie zB eine Schutzbedarfsanalyse pausieren und dann eine Neubewertung manuell durchführen. HITGuard wird das mitverfolgen, also wird später ihre manuelle Neubewertung hier in der Übersicht zu sehen sein. Wenn Sie die manuelle Neubewertung rechtzeitig abschließen, kann HITGuard Sie als Vorlage für den nächsten Zyklus verwenden.<p>
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
==Tab 3: Executed workflows==
==Tab 3: Durchgeführte Workflows==
[[Datei:WFPtab3.png|right|thumb|600px]]This page offers you an overview of the historical cycles of the workflow plan. For protection needs and vulnerability/GAP analyses, you can trace the reassessments and the preceding analyses that served as a template.
[[Datei:WFPtab3.png|right|thumb|600px]]Diese Seite bietet ihnen einen Überblick über die historischen Zyklen des Workflowplans. Bei Schutzbedarfs- und Schwachstellenanalysen können Sie jeweils die Neubewertungen und die vorhergehenden Analysen, die als Vorlage gedient haben nachvollziehen.
<br clear="all">
<br clear="all">
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
<span id="Workflowpläne_für_Schutzbedarfsanalysen_&amp;_Schwachstellenanalysen"></span>
=Workflowpläne für Schutzbedarfsanalysen & Schwachstellenanalysen=
=Workflow plans for protection needs analyses & vulnerability/GAP analyses=
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
Workflow plans for analyses work with reassessments. When the workflow plan is triggered, a new protection needs or vulnerability/GAP analysis is created that is based on the template of the old one. The original analysis remains untouched and write-protected in the system. You can find out more about reassessments on the detail pages of the [[Special:MyLanguage/Schutzbedarf|protection needs analysis]] and [[Special:MyLanguage/Schwachstellen|vulnerability/GAP analysis]]. <br> The workflow plans for the two analyses differ above all in how they take over the results of the preceding analysis. When you attach an analysis to the workflow plan, HITGuard will ask for this setting right away. You can also view and edit it afterwards in the grid.<p>
Workflowpläne für Analysen funktionieren mit Neubewertungen. Wenn der Workflowplan auslöst, wird eine Neue Schutzbedarfs- bzw. Schwachstellenanalyse erstellt, die auf der Vorlage der alten basiert. die ursprüngliche Analyse bleibt unangetastet und schreibgeschützt im System. Mehr zu Neubewertungen erfahren Sie auf den Detailseiten der [[Special:MyLanguage/Schutzbedarf|Schutzbedarfsanalyse]] und [[Special:MyLanguage/Schwachstellen|Schwachstellenanalyse]]. <br> Die Workflowpläne für beide Analysen unterscheiden sich vor allem darin, wie Sie die Ergebnisse der vorangehenden Analyse übernehmen. Wenn Sie eine Analyse in den Workflowplan hängen wird HITGuard diese Einstellung gleich abfragen. Sie können Sie im Nachhinein auch noch im Grid sehen und bearbeiten.<p>
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
:<b>Taking over results for protection needs analyses</b><br>
:<b>Ergebnisse übernehmen bei Schutzbedarfsanalysen</b><br>
For the protection needs analysis there is only a simple checkbox. When it is activated, HITGuard copies all values from the old into the new protection needs analysis. These are the impact-severity ratings of the [[Special:MyLanguage/Risikopolitik#Schutzziele|protection objectives]] that were recorded between the organizational unit or the process and the linked resources and data categories. You can change this checkbox directly in the overview of the linked protection needs analyses. <p>
Bei der Schutzbedarfsanalyse gibt es nur ein einfaches Häkchen. Wenn es aktiviert ist, kopiert HITGuard alle Werte aus der alten in die neue Schutzbedarfsanalyse. Dabei handelt es sich um die Schadensausmaß-Bewertungen der [[Special:MyLanguage/Risikopolitik#Schutzziele|Schutzziele]], die zwischen der Organisationseinheit oder dem Prozess und den verknüpften Ressourcen und Datenkategorien erfasst wurden. Dieses Häkchen können Sie direkt in der Übersicht der verknüpften Schutzbedarfsanalysen ändern. <p>
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
:<b>Taking over results for vulnerability/GAP analyses</b>
:<b>Ergebnisse übernehmen bei Schwachstellenanalysen</b>
[[Datei:Workflow_AA_ErgebnisseÜbernehmen.png|right|thumb|400px]]For the vulnerability/GAP analysis, the taking over of results comes with more options:
[[Datei:Workflow_AA_ErgebnisseÜbernehmen.png|right|thumb|400px]]Bei der Schwachstellenanalyse bietet die Übernahme der Ergebnisse mit mehr Optionen:
*<b>Current knowledge base:</b> [[Special:MyLanguage/Wissensdatenbanken|Knowledge bases]] serve as a template for the question sets in vulnerability/GAP analyses. Sometimes the template has evolved further after the original review was created. With this checkbox you determine whether, during the reassessment, HITGuard should use the <i>old version</i> of the template, or whether it should use the <i>latest version</i> of the knowledge base.  
*<b>Aktuelle Wissensdatenbank:</b> [[Special:MyLanguage/Wissensdatenbanken|Wissensdatenbanken]] dienen als Vorlage für die Fragenbatterien in Schwachstellenanalysen. Manchmal hat sich die Vorlage weiterentwickelt, nachdem die ursprügliche Überprüfung angelegt wurde. Mit diesem Häkchen bestimmen Sie, ob HITguard bei der Neubewertung die <i>alte Version</i> der Vorlage verwenden soll, oder ob es die <i>neueste Version</i> der Wissensdatenbank verwenden soll.  
*<b>Take over Answers:</b> Here you can decide whether HITGuard should take over all answers, no answers or only positive answers from the last review in the reassessment. This controls how thoroughly the Advisor has to work through the reassessment.
*<b>Antwortübernahme:</b> Hier können Sie entscheiden, ob HITGuard in der neubewertung alle Antworten, keine Antwort oder nur positive Antworten der letzten Überprüfung übernehmen soll. Damit steuern Sie, wie gründlich der Sachbearbeiter die Neubewertung durcharbeiten muss.
*<b>Set Justification:</b>Regardless of whether you take over answers or not, you can take over the respective justification texts from the original review. Alternatively, you can enter a default text that HITGuard will place in every justification field.
*<b>Begründungsübernahme:</b>Unabhängig davon, ob Sie Antworten übernehmen, oder nicht können Sie die jeweiligen Begründungstexte aus der ursprünglichen Überprüfung übernehmen. Alternativ können Sie einen Standardtext eingeben, den HITGuard in jedes Begründungsfeld setzen wird.
*You can also change all these settings later by clicking "Edit".
*All diese Einstellungen können Sie später auch noch mit einem Klick auf "Bearbeiten" ändern.
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
<span id="Workflowpläne_für_Risiken/Chancen"></span>
=Workflowpläne für Risiken/Chancen=
=Workflow plans for risks/opportunities=
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
*In the workflow plan with risks and opportunities, you send the risk to the Advisor for reassessment. Unlike with the analyses, no separate reassessment is created here. Therefore, there are also no settings for taking over results.  
*Beim Workflowplan mit Risiken und Chancen schicken Sie das Risiko dem Sachbearbeiter zur Neubewertung. Anders als bei den Analysen wird hier keine eigene Neubewertung erstellt. Daher gibt es auch keine Einstellungen für die Übernahme von Ergebnissen.  
*In the second tab, "Risks and Opportunities", you can link the risks and opportunities whose reassessment the workflow plan is to initiate. After you have added a risk with the Link button, HITGuard will offer you a text field with which you can compose a message to the Advisor. You can also change this afterwards in the grid.  
*Im Zweiten Tab, "Risiken und Chancen" können Sie die Risiken und Chancen verknüpfen, deren Neubewertung der Workflowplan anstoßen soll. Nachdem Sie ein Risiko mit dem Link-Button hinzugefügt haben, wird HITGUard ihnen ein Textfeld anbieten, mit dem Sie eine Nachricht an den Sachbearbeiter verfassen können. Die können Sie auch im Nachhinein noch im Grid ändern.  
*You can find out more about the risk assessment workflow [[Special:MyLanguage/Risikobewertung#Workflow_zur_Risikobewertung|here]].
*Mehr zum Workflow zur Risikobewertung erfahren Sie [[Special:MyLanguage/Risikobewertung#Workflow_zur_Risikobewertung|hier]].
</div>


<div lang="de" dir="ltr" class="mw-content-ltr">
=Workflow plan FAQs=
=Workflowplan FAQs=
<b>What happens when the workflow plan is executed?</b><br>
<b>Was passiert bei der Durchführung des Workflowplans?</b><br>
When the workflow plan is executed, reassessments are created for the linked protection needs analyses and the respective interview partners are requested to respond. A reassessment assesses the same resources and data categories for the same organizational unit or the same process as the original protection needs analysis.<p>
Wenn der Workflowplan durchgeführt wird, werden für die verknüpften Schutzbedarfsanalysen Neubewertungen erstellt und die jeweiligen Interviewpartner zur Beantwortung aufgefordert. Eine Neubewertung bewertet dieselben Ressourcen und Datenkategorien für die selbe Organisationseinheit oder den selben Prozess wie die ursprüngliche Schutzbedarfsanalyse.<p>
<b>When is no reassessment requested?</b><br>
<b>Wann wird keine Neubewertung angefordert?</b><br>
No reassessment is created and requested if one of the following conditions applies:
Es wird keine Neubewertung erstellt und angefordert, wenn eine der folgenden Bedingungen zutrifft:
*The reassessment of the protection needs analysis is paused.
*Die Neubewertung der Schutzbedarfsanalyse ist pausiert.
*The protection needs analysis is not completed.
*Die Schutzbedarfsanalyse ist nicht abgeschlossen.
*The protection needs analysis has no interview partners.
*Die Schutzbedarfsanalyse hat keine Interviewpartner.
*There already exists another protection needs analysis for the same organizational unit or the same process that assesses at least one identical resource or data category and:
*Es existiert bereits eine andere Schutzbedarfsanalyse für dieselbe Organisationseinheit oder denselben Prozess, die zumindest eine gleiche Ressource oder Datenkategorie bewertet und:
**is not yet completed, or
**noch nicht abgeschlossen ist, oder
**has already been completed, but has a more recent start date.<p>
**bereits abgeschlossen wurde, aber ein neueres Startdatum hat.<p>
<u>Note:</u> The last case is particularly relevant if you operate several management systems. If you have scheduled a protection needs analysis via workflow, but a colleague in another management system creates a different protection needs analysis that meets the same conditions, the new protection needs analysis will block the workflow. While it is unlikely that the same OrgUnits and processes are interviewed in different management systems, HITGuard nevertheless checks for this case and warns about conflicts.<p>
<u>Achtung:</u> Der letzte Fall ist besonders relevant, wenn Sie mehrere Managementsysteme betreiben. Falls Sie eine Schutzbedarfsanalyse per Workflow geplant haben, aber ein Kollege in einem anderen Managementsystem eine andere Schutzbedarfsanalyse anlegt, die dieselben Bedingungen erfüllt, wird die neue Schutzbedarfsanalyse den Workflow blockieren. Es ist zwar unwahrscheinlich, dass in verschiedenen Managementsystemen die gleichen OrgEhs und Prozesse interviewt werden, aber HITGuard prüft trotzdem auf diesen Fall und warnt vor Konflikten.<p>
<b>What happens to paused protection needs analyses?</b><br>
<b>Was passiert mit pausierten Schutzbedarfsanalysen?</b><br>
If a protection needs analysis has been paused, no reassessment is created during the next execution. Instead, the protection needs analysis is reactivated for the subsequent execution.<p>
Wenn eine Schutzbedarfsanalyse pausiert wurde, wird bei der nächsten Durchführung keine Neubewertung erstellt. Stattdessen wird die Schutzbedarfsanalyse für die darauffolgende Durchführung wieder aktiviert.<p>
<b>Why can some closed protection needs analyses be added to workflows and some cannot?</b><br>
<b>Warum können manche geschlossenen Schutzbedarfsanalysen zu Workflows hinzugefügt werden und manche nicht?</b><br>
Protection needs analyses that are closed and for which a reassessment is possible can be added to a workflow plan. If a reassessment of the protection needs analysis is not possible for one of the various reasons, it cannot be added to the workflow plan either.
Schutzbedarfsanalysen, die geschlossen sind und bei denen eine Neubewertung möglich ist, können zu einem Workflowplan hinzugefügt werden. Ist eine Neubewertung der Schutzbedarfsanalyse aus einem der verschiedenen Gründe nicht möglich, kann sie auch nicht zum Workflowplan hinzugefügt werden.
</div>

Aktuelle Version vom 2. Juli 2026, 07:52 Uhr

Using workflow plans

Workflow plans are available for three elements (protection needs analyses, vulnerability/GAP analyses and risks & opportunities). You can send each of these three elements to a Practitioner via workflow. With workflow plans, you can plan and automate these workflows for the future.

The automatic workflow plans for protection needs and vulnerability/GAP analyses are about the reassessment of already documented results. HITGuard therefore automatically creates new reviews and sends them as a self-assessment to the interview partners. The interview partners, to whom HITGuard sends the request by e-mail, then have the option of editing the contents of the reassessment. In this way, they can, for example, schedule an annual reassessment of the previously collected information.

With the automatic workflow plans for risks, you can run not only reassessments but also the initial assessment through the automated workflow plan. For risks, HITGuard does not create any new elements, but keeps a detailed record of all changes. Here too, you can reassess on a regular cycle, whereby HITGuard will prompt the users in the "Advisor" field to revise the contents.

In this article, we will address the three variants separately. First, however, we will discuss general points of the workflow plan.

Basic properties of workflow plans

Creating a workflow plan

By clicking the purple button in the control bar above the grid, you open a list of all created workflow plans. With the "Plus" button you can then create a new workflow plan, or you can open an existing workflow plan by double-clicking.
With the "Copy" button, an existing workflow plan can be copied, whereby the contents of the settings of the workflow plan are copied, but not the already executed workflows or the linked reviews.

Tab 1: Master data of the workflow plan

Status:

  • Only active workflow plans actually send out new elements for assessment.
  • By default, workflow plans are active when created. You can also suspend or deactivate them with this selection field.
  • One-time workflows are automatically moved from the Active status to the Deactivated status after they have been executed.

Name & Description:

  • Enter the purpose of the workflow plan here so that you can understand its intention later on.

Responsible User:

  • The responsible user is tasked with preparing the workflow plan, not with responding to the workflows.
  • The responsible user is informed by e-mail one week before the workflow is triggered. If there are problems or conflicts at this point (see below), these are described in the e-mail and can therefore be resolved in good time.
  • The responsible user is also informed when the workflow is triggered about which reviews were sent out successfully and whether there were any problems or conflicts that prevented further reviews from being sent out.

Notify management system responsible persons:

  • If this checkbox is set, in addition to the responsible person for the workflow plan, the responsible persons for the management system are also informed by e-mail about the upcoming or executed workflow.

Next execution:

  • Specify here when the workflow plan should be triggered next. At this point, the reassessments/risks are then sent to the interview partners/Advisors based on the linked elements.

Recurring workflow:

  • If the workflow plan should be triggered regularly, you can set this here.
  • After being triggered, HITGuard will renew the date and add the time span you have defined here to the old date.

Tab 2: Adding elements

Protection needs analyses
Vulnerability/GAP analyses
Risks & Opportunities

Depending on the variant, the second tab is called "Protection needs analyses", "Reviews" or "Risks & Opportunities". In the three screenshots on the right, you can see that the three pages are structured as a grid. In the following, we address the general basic functions that all workflow plans share.

Link button

  • To the right above the grid, you can attach the original elements that the workflow plan is to reassess.

Grid overview of the element

  • Here you see the title of the element as well as some additional information that defines the analyses or risks in more detail. Using the column selection, you can also hide these properties.
  • The titles of the elements function as links. By clicking the blue text, you can jump directly into the analysis or the risk.
  • Note: Here you always see the latest version/reassessment of the analyses. If the workflow has just been triggered, the link no longer takes you to the original analysis, but to the reassessment that has already been created automatically.

Warnings & conflicts

  • In the grid, HITGuard points out possible conflicts of the workflow plans. The Conflicts column indicates the origin of the conflict. Details about the conflict can also be found in the tooltip when you hover the mouse over the triangle.
  • Yellow warning triangles: If the risk or the analysis itself is not ready for a reassessment, this is shown with a yellow warning triangle. Usually this is because the vulnerability/GAP or protection needs analysis is not yet completed, or because the risk is already in the assessment workflow. Yellow warning triangles are also shown here when the workflow has just been triggered.
  • Red warning triangles: If there is a conflict with another element, this is shown with a red warning triangle. The conflict can arise in the same or in another management system (e.g. reassessments of protection needs analyses in another management system).

Status: Active/Paused

  • This status indicates whether the element will be triggered with the workflow plan. Active elements trigger on the date of the workflow plan, paused ones skip a cycle. You control the status with the Play/Pause button on the right side of the grid. In the second screenshot you see a paused review.

Play/Pause button

  • With this button you control the Active/Paused status of the individual element.

Unlink button

  • This permanently removes the review from the workflow plan.

Reassess button

  • With this button you can manually bypass the workflow plan and create a reassessment manually. For example, you can pause a protection needs analysis and then carry out a reassessment manually. HITGuard will track this, so your manual reassessment will later be visible here in the overview. If you complete the manual reassessment in good time, HITGuard can use it as a template for the next cycle.

Tab 3: Executed workflows

This page offers you an overview of the historical cycles of the workflow plan. For protection needs and vulnerability/GAP analyses, you can trace the reassessments and the preceding analyses that served as a template.


Workflow plans for protection needs analyses & vulnerability/GAP analyses

Workflow plans for analyses work with reassessments. When the workflow plan is triggered, a new protection needs or vulnerability/GAP analysis is created that is based on the template of the old one. The original analysis remains untouched and write-protected in the system. You can find out more about reassessments on the detail pages of the protection needs analysis and vulnerability/GAP analysis.
The workflow plans for the two analyses differ above all in how they take over the results of the preceding analysis. When you attach an analysis to the workflow plan, HITGuard will ask for this setting right away. You can also view and edit it afterwards in the grid.

Taking over results for protection needs analyses

For the protection needs analysis there is only a simple checkbox. When it is activated, HITGuard copies all values from the old into the new protection needs analysis. These are the impact-severity ratings of the protection objectives that were recorded between the organizational unit or the process and the linked resources and data categories. You can change this checkbox directly in the overview of the linked protection needs analyses.

Taking over results for vulnerability/GAP analyses

For the vulnerability/GAP analysis, the taking over of results comes with more options:

  • Current knowledge base: Knowledge bases serve as a template for the question sets in vulnerability/GAP analyses. Sometimes the template has evolved further after the original review was created. With this checkbox you determine whether, during the reassessment, HITGuard should use the old version of the template, or whether it should use the latest version of the knowledge base.
  • Take over Answers: Here you can decide whether HITGuard should take over all answers, no answers or only positive answers from the last review in the reassessment. This controls how thoroughly the Advisor has to work through the reassessment.
  • Set Justification:Regardless of whether you take over answers or not, you can take over the respective justification texts from the original review. Alternatively, you can enter a default text that HITGuard will place in every justification field.
  • You can also change all these settings later by clicking "Edit".

Workflow plans for risks/opportunities

  • In the workflow plan with risks and opportunities, you send the risk to the Advisor for reassessment. Unlike with the analyses, no separate reassessment is created here. Therefore, there are also no settings for taking over results.
  • In the second tab, "Risks and Opportunities", you can link the risks and opportunities whose reassessment the workflow plan is to initiate. After you have added a risk with the Link button, HITGuard will offer you a text field with which you can compose a message to the Advisor. You can also change this afterwards in the grid.
  • You can find out more about the risk assessment workflow here.

Workflow plan FAQs

What happens when the workflow plan is executed?

When the workflow plan is executed, reassessments are created for the linked protection needs analyses and the respective interview partners are requested to respond. A reassessment assesses the same resources and data categories for the same organizational unit or the same process as the original protection needs analysis.

When is no reassessment requested?
No reassessment is created and requested if one of the following conditions applies:

  • The reassessment of the protection needs analysis is paused.
  • The protection needs analysis is not completed.
  • The protection needs analysis has no interview partners.
  • There already exists another protection needs analysis for the same organizational unit or the same process that assesses at least one identical resource or data category and:
    • is not yet completed, or
    • has already been completed, but has a more recent start date.

Note: The last case is particularly relevant if you operate several management systems. If you have scheduled a protection needs analysis via workflow, but a colleague in another management system creates a different protection needs analysis that meets the same conditions, the new protection needs analysis will block the workflow. While it is unlikely that the same OrgUnits and processes are interviewed in different management systems, HITGuard nevertheless checks for this case and warns about conflicts.

What happens to paused protection needs analyses?
If a protection needs analysis has been paused, no reassessment is created during the next execution. Instead, the protection needs analysis is reactivated for the subsequent execution.

Why can some closed protection needs analyses be added to workflows and some cannot?
Protection needs analyses that are closed and for which a reassessment is possible can be added to a workflow plan. If a reassessment of the protection needs analysis is not possible for one of the various reasons, it cannot be added to the workflow plan either.