Hauptseite/en: Unterschied zwischen den Versionen
Weitere Optionen
Übernehme Bearbeitung einer neuen Version der Quellseite |
KoKl (Diskussion | Beiträge) Keine Bearbeitungszusammenfassung |
||
| (5 dazwischenliegende Versionen von 2 Benutzern werden nicht angezeigt) | |||
| Zeile 1: | Zeile 1: | ||
Welcome to the online help of the GRC software '''HITGuard'''. This help accompanies you in controlling and monitoring your risks and compliance requirements – understandable for beginners and useful for experienced users. | |||
<div class="cdx-message--warning cdx-message cdx-message--block"><div class="cdx-message__content"> | <div class="cdx-message--warning cdx-message cdx-message--block"><div class="cdx-message__content"> | ||
''' | '''Do you need support?''' Our support team will be happy to help you at [mailto:support@togethersecure.at support@togethersecure.at]. | ||
</div></div> | </div></div> | ||
== | <span id="Hilfe_und_Schnelleinstieg"></span> | ||
== Help and quick start == | |||
In the '''Help''' menu item you will find: | |||
* ''' | * '''First steps''' – the interactive introduction to the HITGuard interface, which also greets you when you log in for the first time. | ||
* '''Online | * '''Online help''' – The online help you are currently on. | ||
* ''' | * '''Page introduction''' – if an info symbol is visible at the bottom left, a click starts a short introduction to the current page. | ||
Are you new to HITGuard or setting up a new module? Here you will find the right starting point: | |||
* [[Special:MyLanguage/Was sind die ersten Schritte des Aufbaus eines Managementsystems in HITGuard?| | * [[Special:MyLanguage/Was sind die ersten Schritte des Aufbaus eines Managementsystems in HITGuard?|First steps in setting up a management system]] | ||
* [[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Data Protector setzen?| | * [[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Data Protector setzen?|First steps with the data protection module]] | ||
* [[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Auditmanagement setzen?| | * [[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Auditmanagement setzen?|First steps with the audit management]] | ||
* [[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Fallmanagement setzen?| | * [[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Fallmanagement setzen?|First steps with the case management]] | ||
* [[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Doku-Management setzen?| | * [[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Doku-Management setzen?|First steps with the document management]] | ||
* [[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem ESG Modul setzen?| | * [[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem ESG Modul setzen?|First steps with the ESG module]] | ||
* [[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Supplier Risk Management setzen?| | * [[Special:MyLanguage/Welche ersten Schritte sollte ich zum Arbeiten mit dem Supplier Risk Management setzen?|First steps with the Supplier Risk Management]] | ||
* [[Special:MyLanguage/Wie aktiviere ich die diversen Mailings, wenn ich mit meinen Einstiegstests fertig bin?| | * [[Special:MyLanguage/Wie aktiviere ich die diversen Mailings, wenn ich mit meinen Einstiegstests fertig bin?|Activating mailings after completing the initial tests]] | ||
== | <span id="Produktüberblick"></span> | ||
== Product overview == | |||
HITGuard | HITGuard has a modular structure. Which menu items you see depends on your permissions and the activated features of the respective management system. However, the "My Tasks" module exists for <i>every</i> user. If you want to learn more about it, follow this link: | ||
{| class="wikitable" | {| class="wikitable" | ||
!style="width:330px"| | !style="width:330px"| Help for My Tasks | ||
|- | |- | ||
|style="width:330px;" | | |style="width:330px;" | | ||
:*[[Special:MyLanguage/Meine_Aufgaben| | :*[[Special:MyLanguage/Meine_Aufgaben|My Tasks]] | ||
|} | |} | ||
Below you will find explanations of all menu items of the other modules: | |||
=== | <span id="Basismodule"></span> | ||
=== Base modules === | |||
Risk management, measures, controls, master data and administration are always available in HITGuard and form the basis of the tool. | |||
{| class="wikitable" | {| class="wikitable" | ||
! | ! Module !! Description | ||
|- | |- | ||
| ''' | | '''Risk management''' || Identification and assessment of risks and opportunities on a central platform for assessments and treatments. The risk policy is freely configurable, and various workflows support you in this. → [[Special:MyLanguage/Workflow Risiko Chance|Risk/Opportunity workflow]] · [[Special:MyLanguage/Meine Aufgaben Gefährdungslagen|For Practitioners]] | ||
|- | |- | ||
| ''' | | '''Measures''' || Implementation of measures to eliminate or reduce risks and security gaps. Tracking via progress reports and effectiveness review. → [[Special:MyLanguage/Workflow Maßnahme|Measure workflow]] · [[Special:MyLanguage/Maßnahmenstatus|For Practitioners]] | ||
|- | |- | ||
| ''' | | '''Controls''' || Management and assessment of controls and their effectiveness. Create control definitions and track execution. → [[Special:MyLanguage/Workflow Kontrolle|Control workflow]] · [[Special:MyLanguage/Kontrollen|For Practitioners]] | ||
|- | |- | ||
| ''' | | '''Master data''' || Maintenance of company data, resources and assets as well as knowledge bases, questionnaire templates and standards. | ||
|- | |- | ||
| '''Administration''' || | | '''Administration''' || Configuration and adaptation of HITGuard to your requirements: management of user accounts, roles and teams as well as integration into existing systems and processes. | ||
|} | |} | ||
=== Add-ons === | === Add-ons === | ||
Various extensions cover additional use cases. Add-ons are licensed separately and are usually activated under '''Administration › Management systems''' for one or more management systems. | |||
{| class="wikitable" | {| class="wikitable" | ||
! Add-on !! | ! Add-on !! Description | ||
|- | |- | ||
| ''' | | '''Data protection''' || Support in complying with data protection regulations and guidelines. Activates the "Data protection" menu item. → [[Special:MyLanguage/Workflow VT|Processing activity workflow]] · [[Special:MyLanguage/Meine Verarbeitungstätigkeiten#Verarbeitungstätigkeit bearbeiten/erstellen/updaten|Working with processing activities]] | ||
|- | |- | ||
| ''' | | '''Audit management''' || Carry out internal and external audits, track results and generate reports. Activates the "Audit management" menu item. | ||
|- | |- | ||
| ''' | | '''Case management''' || Processing of security incidents and violations of guidelines and regulations. Activates the "Case management" menu item. → [[Special:MyLanguage/Workflow Meldung|Report workflow]] · [[Special:MyLanguage/Meine Aufgaben Meldungen|Creating reports]] · [[Special:MyLanguage/Hinweisgebersystem|Whistleblower system]] | ||
|- | |- | ||
| ''' | | '''Document management''' || Combines document control, uploaded attachments and the report archive. Activation via your contact person at TogetherSecure. → [[Special:MyLanguage/Workflow Doku-Management|Document management workflow]] · [[Special:MyLanguage/Freigabeworkflow|Review and approval workflow]] | ||
|- | |- | ||
| '''ESG Management''' || | | '''ESG Management''' || Support with the double materiality analysis; extends risk management with new menu items. → [[Special:MyLanguage/ESG Management|More about ESG Management]] | ||
|- | |- | ||
| '''Supplier Risk Management''' || | | '''Supplier Risk Management''' || Send reviews to suppliers and integrate them into your audit processes; extends administration and reviews. → [[Special:MyLanguage/Supplier Risk Management|More about Supplier Risk Management]] | ||
|} | |} | ||
== | <span id="Die_HITGuard_Oberfläche"></span> | ||
== The HITGuard interface == | |||
[[Datei:Oberflächenbeschreibung2.png|thumb|center|600px| | [[Datei:Oberflächenbeschreibung2.png|thumb|center|600px|The HITGuard interface (click to enlarge)]] | ||
The profile area of the logged-in user is located at the top left, with the main menu below it. Clicking on the profile picture opens the [[Special:MyLanguage/Profil|Manage account]] page, where you can change your data, your profile picture and your password. | |||
The highlighted areas in the image show: | |||
# '''Intro | # '''Intro for the current page''' – starts the interactive introduction, if available. | ||
# ''' | # '''Expand/collapse menu''' – shows or hides the navigation menu. | ||
# ''' | # '''Switch management system''' – switches between management systems (only visible with permission for several systems; not for Practitioners). | ||
# ''' | # '''Current management tasks, administration, accessibility, language, log out:''' | ||
#* | #* Envelope symbol → [[#Aktuelle Managementaufgaben (das Briefchen)|Current management tasks]] | ||
#* | #* Gear icon → [[#Menu Reference by Module|Administration]] for basic central functions | ||
#* | #* Person symbol → configure [[Special:MyLanguage/Barrierefreiheit|accessibility]] | ||
#* | #* Flag → switch between German and English | ||
#* Log out → log out | |||
=== | <span id="Hauptmenü"></span> | ||
=== Main menu === | |||
The menu begins with the personal entries '''My Tasks''' and '''My Dashboards''', followed by the module menu items (only visible for authorized modules) and ends with the '''Help''' item. | |||
==== | <span id="Meine_Aufgaben"></span> | ||
==== My Tasks ==== | |||
[[Datei:Meine Aufgaben Badges2.png|thumb|right| | [[Datei:Meine Aufgaben Badges2.png|thumb|right|My Tasks]] Here you will find all the tasks you have to complete in your role as a Practitioner. A click opens the [[Special:MyLanguage/Dashboard|task dashboard]] with a summary of all open tasks; a submenu organizes the tasks by type (including those already completed). | ||
* '''Orange | * '''Orange badges''' show how many tasks you have to process yourself (e.g. requested ((Special:MyLanguage/Fortschrittsmeldungen|progress reports]] or processing activities to be reviewed). | ||
* ''' | * '''Blue badges''' show tasks for which you share responsibility, but which someone else is processing (e.g. [[Special:MyLanguage/Kontrolldefinitionen|controls]] where your implementation is still being reviewed). | ||
Status | Status of the elements per menu item: [[Special:MyLanguage/Maßnahmenstatus|Measures]] · [[Special:MyLanguage/Kontrollen|Controls]] · [[Special:MyLanguage/Überprüfungen|Reviews]] · [[Special:MyLanguage/Meine Verarbeitungstätigkeiten|Processing activities]] · [[Special:MyLanguage/Meine Aufgaben Gefährdungslagen|Risks & Opportunities]] · [[Special:MyLanguage/Meine Aufgaben Meldungen|Reports]] | ||
<br clear="all"> | <br clear="all"> | ||
==== | <span id="Meine_Dashboards"></span> | ||
==== My Dashboards ==== | |||
[[Datei:Rn233 DB KPI-Report hinzufügen.png|thumb|right|Dashboard | [[Datei:Rn233 DB KPI-Report hinzufügen.png|thumb|right|Dashboard with KPIs and reports]] Dashboards provide an overview of the management systems based on key performance indicators (KPIs) and make reports available for reporting. By default, there is one dashboard each for KPIs from risk management, measures and controls; the data protection, case and audit management add-ons each have an additional dashboard. You only ever see dashboards, KPIs and reports for which your user is authorized. | ||
''' | '''Permissions:''' Access to a dashboard or its KPIs and reports requires the "Expert", "Professional" or "Observer" role in the respective module (e.g. at least "Professional" in risk management for the risk management dashboard). | ||
''' | '''My dashboards:''' You can create additional dashboards. Standard dashboards delivered with HITGuard are marked with a tool icon; they can be edited and reset to their original state, but not deleted. Dashboards you create yourself can be configured as "Private" (only for you) or open (for all authorized members) or can also be deleted. | ||
[[Datei:DB Favoriten Markierung.png|thumb|right| | [[Datei:DB Favoriten Markierung.png|thumb|right|Mark dashboard as favorite]]'''Favorite:''' Using the star next to the dashboard configuration, you mark one dashboard per management system as a favorite – it is ranked first and displayed after logging in. | ||
Further reading: [[Special:MyLanguage/Dashboards|Creating/editing dashboards]] · [[Special:MyLanguage/Risikomanagement Dashboard|Risk management]] · [[Special:MyLanguage/ESG Dashboard|ESG]] · [[Special:MyLanguage/Maßnahmen Dashboard|Measures]] · [[Special:MyLanguage/Kontrollen Dashboard|Controls]] · [[Special:MyLanguage/Datenschutz Dashboard|Data protection]] · [[Special:MyLanguage/Fallmanagement Dashboard|Case management]] · [[Special:MyLanguage/Auditmanagement Dashboard|Audit management]] | |||
''' | '''Reports on dashboards''' correspond in content to the reports of the respective menu items (see there for explanations) and additionally offer: | ||
* ''' | * '''Prepare several versions:''' Using the "Filter" button, different configurations of a report can be saved – e.g. a "Risk report – details" with measure and control details for risk owners and a concise "Board report risks" for the board. | ||
* ''' | * '''Set as default report setting:''' On non-private dashboards, Experts and Professionals can set one configuration as the default per report type. This is used automatically in overview lists (e.g. under ''Risk management › Risk assessment''), but remains individually adjustable on the report page itself. Settings already set individually are not overwritten by the default. The default report is marked on the dashboard with a star on the report icon. | ||
==== | <span id="KI-Features"></span> | ||
==== AI features ==== | |||
[[Datei:SternchenbuttonKI.png|thumb|right| | [[Datei:SternchenbuttonKI.png|thumb|right|AI functions via the "asterisk" button]]In HTML-editable fields (fields with text formatting) you will find an "asterisk" button, via which you call up AI functions. With it you can, for texts: | ||
* | * summarize | ||
* | * proofread | ||
* | * expand | ||
* | * shorten | ||
* | * change the style | ||
* | * change the tone | ||
* | * translate between German and English | ||
Using your own prompts, you can also ask the AI questions and generate your own texts. There is a special feature in the '''deviation analysis''' and in the '''review result''': there, the AI functions can also be used in the non-HTML-editable field of the justification. | |||
=== | <span id="Aktuelle_Managementaufgaben_(das_Briefchen)"></span> | ||
=== Current management tasks (the envelope) === | |||
[[Datei:Management Briefchen.png|thumb|right|Management | [[Datei:Management Briefchen.png|thumb|right|Management tasks]] The envelope at the top right informs Professionals and Experts about tasks that have been reported as completed and are waiting for closure/review. Clicking on the envelope opens the list, which shows them these tasks and expired analysis periods. However, the list only shows the tasks from the '''current management system'''. Tasks only appear to users who are authorized to process them (e.g. answered processing activities only to users with Professional/Expert rights in data protection). | ||
{| class="wikitable" | {| class="wikitable" | ||
! | ! Section !! Description | ||
|- | |- | ||
| | | Progress reports || Answered progress reports on [[Special:MyLanguage/Maßnahmen|measures]]. | ||
|- | |- | ||
| | | Risks || [[Special:MyLanguage/Risikobewertung|Risks]] that have been newly submitted or returned. | ||
|- | |- | ||
| | | Protection requirement analyses || Answered [[Special:MyLanguage/Schutzbedarf|protection requirement analysis]]. | ||
|- | |- | ||
| | | Vulnerability analyses || Answered [[Special:MyLanguage/Schwachstellen|vulnerability analyses]]. | ||
|- | |- | ||
| | | Reports assigned to me || Open [[Special:MyLanguage/Meldungen|reports]] assigned to you. | ||
|- | |- | ||
| | | Unassigned reports || Reports not yet assigned to any user. Only visible to team members if a support team is stored. | ||
|- | |- | ||
| | | Processing activities || Answered [[Special:MyLanguage/Verarbeitungstätigkeit|processing activities]]. | ||
|} | |} | ||
== | <span id="HITGuard_Menü-Überblick"></span> | ||
== HITGuard module overview == | |||
Below are all menu items of the individual modules. Only modules and items for which you are authorized and which have been activated in the management system are visible. | |||
<div class="hg-module-grid" style="display:flex; flex-wrap:wrap; gap:1em; margin-top:1em;"> | <div class="hg-module-grid" style="display:flex; flex-wrap:wrap; gap:1em; margin-top:1em;"> | ||
<div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;"> | <div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;"> | ||
<div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;"> | <div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;">Risk management</div> | ||
* [[Special:MyLanguage/Strukturanalyse| | * [[Special:MyLanguage/Strukturanalyse|Structure analysis]] | ||
* [[Special:MyLanguage/Schutzbedarf| | * [[Special:MyLanguage/Schutzbedarf|Protection requirement]] | ||
* [[Special:MyLanguage/Schwachstellen| | * [[Special:MyLanguage/Schwachstellen|Vulnerabilities]] | ||
* [[Special:MyLanguage/Bedrohungen| | * [[Special:MyLanguage/Bedrohungen|Threats]] | ||
* [[Special:MyLanguage/Risikobewertung| | * [[Special:MyLanguage/Risikobewertung|Risks & Opportunities]] | ||
* [[Special:MyLanguage/Auswirkungen| | * [[Special:MyLanguage/Auswirkungen|Impacts]] | ||
* [[Special:MyLanguage/ESG Themen| | * [[Special:MyLanguage/ESG Themen|Fields of Action]] | ||
* [[Special:MyLanguage/Risikobehandlung| | * [[Special:MyLanguage/Risikobehandlung|Treatment R&O]] | ||
* [[Special:MyLanguage/Berichte für das Risikomanagement| | * [[Special:MyLanguage/Berichte für das Risikomanagement|Reports]] | ||
* [[Special:MyLanguage/Risikomanagement Einstellungen| | * [[Special:MyLanguage/Risikomanagement Einstellungen|Settings]] | ||
</div> | </div> | ||
<div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;"> | <div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;"> | ||
<div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;"> | <div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;">Audit management</div> | ||
* [[Special:MyLanguage/Auditkalender| | * [[Special:MyLanguage/Auditkalender|Audit calendar]] | ||
* [[Special:MyLanguage/Auditplanung| | * [[Special:MyLanguage/Auditplanung|Audit planning]] | ||
* [[Special:MyLanguage/Auditdurchführung| | * [[Special:MyLanguage/Auditdurchführung|Audit execution]] | ||
* [[Special:MyLanguage/Auditbehandlung| | * [[Special:MyLanguage/Auditbehandlung|Audit treatment]] | ||
* [[Special:MyLanguage/Externe Auditoren| | * [[Special:MyLanguage/Externe Auditoren|External auditors]] | ||
* [[Special:MyLanguage/Auditcluster| | * [[Special:MyLanguage/Auditcluster|Audit cluster]] | ||
* [[Special:MyLanguage/Funktionen| | * [[Special:MyLanguage/Funktionen|Functions]] | ||
* [[Special:MyLanguage/Berichte für das Auditmanagement| | * [[Special:MyLanguage/Berichte für das Auditmanagement|Reports]] | ||
* [[Special:MyLanguage/Auditmanagement Einstellungen| | * [[Special:MyLanguage/Auditmanagement Einstellungen|Settings]] | ||
</div> | </div> | ||
<div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;"> | <div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;"> | ||
<div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;"> | <div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;">Case management</div> | ||
* [[Special:MyLanguage/Vorfall melden| | * [[Special:MyLanguage/Vorfall melden|Report incident]] | ||
* [[Special:MyLanguage/Fristen| | * [[Special:MyLanguage/Fristen|Deadlines]] | ||
* [[Special:MyLanguage/Meldungen| | * [[Special:MyLanguage/Meldungen|Reports]] | ||
* [[Special:MyLanguage/Akten| | * [[Special:MyLanguage/Akten|Files]] | ||
* [[Special:MyLanguage/Berichte für das Fallmanagement| | * [[Special:MyLanguage/Berichte für das Fallmanagement|Reports]] | ||
* [[Special:MyLanguage/Fallmanagement-Einstellungen| | * [[Special:MyLanguage/Fallmanagement-Einstellungen|Settings]] | ||
* [[Special:MyLanguage/Hinweisgebersystem| | * [[Special:MyLanguage/Hinweisgebersystem|Whistleblower system]] | ||
</div> | </div> | ||
<div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;"> | <div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;"> | ||
<div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;"> | <div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;">Measures</div> | ||
* [[Special:MyLanguage/Aktuelle Maßnahmen| | * [[Special:MyLanguage/Aktuelle Maßnahmen|Current measures]] | ||
* [[Special:MyLanguage/Fortschrittsmeldungen| | * [[Special:MyLanguage/Fortschrittsmeldungen|Progress reports]] | ||
* [[Special:MyLanguage/Historie| | * [[Special:MyLanguage/Historie|History]] | ||
* [[Special:MyLanguage/Auswertungen| | * [[Special:MyLanguage/Auswertungen|Evaluations]] | ||
* [[Special:MyLanguage/Berichte für Maßnahmen| | * [[Special:MyLanguage/Berichte für Maßnahmen|Reports]] | ||
* [[Einstellungen]] | * [[Einstellungen|Settings]] | ||
</div> | </div> | ||
<div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;"> | <div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;"> | ||
<div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;"> | <div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;">Controls</div> | ||
* [[Special:MyLanguage/Kontrolldefinitionen| | * [[Special:MyLanguage/Kontrolldefinitionen|Control definitions]] | ||
* [[Special:MyLanguage/Berichte für Kontrollen| | * [[Special:MyLanguage/Berichte für Kontrollen|Reports]] | ||
</div> | </div> | ||
<div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;"> | <div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;"> | ||
<div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;"> | <div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;">Data protection</div> | ||
* [[Special:MyLanguage/Verarbeitungsregister| | * [[Special:MyLanguage/Verarbeitungsregister|Processing register]] | ||
* [[Special:MyLanguage/Datenschutz-Folgenabschätzung| | * [[Special:MyLanguage/Datenschutz-Folgenabschätzung|DPIA]] | ||
* [[Special:MyLanguage/Externe| | * [[Special:MyLanguage/Externe|External parties]] | ||
* [[Special:MyLanguage/TOMs|TOMs]] | * [[Special:MyLanguage/TOMs|TOMs]] | ||
* [[Special:MyLanguage/Betroffenenkategorien| | * [[Special:MyLanguage/Betroffenenkategorien|Data subject categories]] | ||
* [[Special:MyLanguage/Berichte für den Datenschutz| | * [[Special:MyLanguage/Berichte für den Datenschutz|Reports]] | ||
* [[Special:MyLanguage/Datenschutz Einstellungen| | * [[Special:MyLanguage/Datenschutz Einstellungen|Settings]] | ||
</div> | </div> | ||
<div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;"> | <div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;"> | ||
<div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;"> | <div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;">Document management</div> | ||
* [[Special:MyLanguage/Dokumentenmanagement| | * [[Special:MyLanguage/Dokumentenmanagement|Documents]] | ||
* [[Special:MyLanguage/Dokumente| | * [[Special:MyLanguage/Dokumente|Uploaded attachments]] | ||
* [[Special:MyLanguage/Berichtsarchiv| | * [[Special:MyLanguage/Berichtsarchiv|Report archive]] | ||
</div> | </div> | ||
<div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;"> | <div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;"> | ||
<div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;"> | <div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;">Master data</div> | ||
* [[Special:MyLanguage/OrgEh - Organisationseinheiten| | * [[Special:MyLanguage/OrgEh - Organisationseinheiten|Organizational units]] | ||
* [[Special:MyLanguage/Ressourcen| | * [[Special:MyLanguage/Ressourcen|Resources]] | ||
* [[Special:MyLanguage/Datenkategorien| | * [[Special:MyLanguage/Datenkategorien|Data categories]] | ||
* [[Special:MyLanguage/Prozesse| | * [[Special:MyLanguage/Prozesse|Processes]] | ||
* [[Special:MyLanguage/Lieferanten| | * [[Special:MyLanguage/Lieferanten|Suppliers]] | ||
* [[Special:MyLanguage/Standards und Normen|Standards | * [[Special:MyLanguage/Standards und Normen|Standards and norms]] | ||
* [[Special:MyLanguage/Wissensdatenbanken| | * [[Special:MyLanguage/Wissensdatenbanken|Knowledge bases]] | ||
* [[Special:MyLanguage/Dokumente|Uploaded attachments]] | |||
* [[Special:MyLanguage/Berichtsarchiv|Report archive]] | |||
</div> | </div> | ||
<div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;"> | <div class="hg-module-card" style="flex:1 1 280px; min-width:240px; background:#eef1fb; border-radius:8px; padding:1em 1.25em;"> | ||
<div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;">Administration</div> | <div style="font-weight:bold; font-size:1.15em; margin-bottom:.4em;">Administration (top right)</div> | ||
* [[Special:MyLanguage/Benutzer und Benutzerrollen| | * [[Special:MyLanguage/Benutzer und Benutzerrollen|Users and user roles]] | ||
* [[Special:MyLanguage/Teams|Teams]] | * [[Special:MyLanguage/Teams|Teams]] | ||
* [[Special:MyLanguage/Managementsysteme| | * [[Special:MyLanguage/Managementsysteme|Management systems]] | ||
* [[Special:MyLanguage/Globale Einstellungen| | * [[Special:MyLanguage/Globale Einstellungen|Global settings]] | ||
* [[Special:MyLanguage/Risikopolitik| | * [[Special:MyLanguage/Risikopolitik|Risk policy]] | ||
* [[Special:MyLanguage/KI-Promptverwaltung| | * [[Special:MyLanguage/KI-Promptverwaltung|AI prompt management]] | ||
* [[Special:MyLanguage/Textbausteine|Text modules]] | |||
* [[Special:MyLanguage/Datenimport|Data import]] | |||
* [[Special:MyLanguage/Textbausteine| | * [[Special:MyLanguage/Lizenzierung|Licensing]] | ||
* [[Special:MyLanguage/Datenimport| | |||
* [[Special:MyLanguage/Lizenzierung| | |||
* [[Special:MyLanguage/Jobs|Jobs]] | * [[Special:MyLanguage/Jobs|Jobs]] | ||
</div> | </div> | ||
| Zeile 264: | Zeile 275: | ||
</div> | </div> | ||
== | <span id="Anleitungen_&_Nachschlagewerke"></span> | ||
== Guides & references == | |||
=== FAQ & | <span id="FAQ_&_Glossar"></span> | ||
=== FAQ & glossary === | |||
* [[Special:MyLanguage/FAQ|FAQ]] | * [[Special:MyLanguage/FAQ|FAQ]] | ||
* [[Special:MyLanguage/Glossar| | * [[Special:MyLanguage/Glossar|Glossary]] | ||
=== | <span id="Arbeiten_mit_HITGuard"></span> | ||
=== Working with HITGuard === | |||
* [[Special:MyLanguage/Profil| | * [[Special:MyLanguage/Profil|User profile]] | ||
* [[Special:MyLanguage/Funktionalität der Tabellen| | * [[Special:MyLanguage/Funktionalität der Tabellen|Functionality and symbols of the tables]] | ||
* [[Special:MyLanguage/Icons und Buttons|Icons | * [[Special:MyLanguage/Icons und Buttons|Icons and buttons in HITGuard]] | ||
* [[Special:MyLanguage/FAQ#Tips,_Tricks_&_Best_Practice| | * [[Special:MyLanguage/FAQ#Tips,_Tricks_&_Best_Practice|Tips, tricks & best practice]] | ||
=== | <span id="Anleitungen_nach_Rolle"></span> | ||
=== Guides by role === | |||
''' | '''Experts or Professionals''' | ||
* [[Special:MyLanguage/Audit erstellen| | * [[Special:MyLanguage/Audit erstellen|Create/edit audit]] | ||
* [[Special:MyLanguage/Auditprogramm erstellen| | * [[Special:MyLanguage/Auditprogramm erstellen|Create/edit audit program]] | ||
* [[Schwachstellen#create_überprüfung| | * [[Schwachstellen#create_überprüfung|Create/edit reviews (deviation analyses/review results)]] | ||
* [[Special:MyLanguage/Risikobewertung#create_rsik| | * [[Special:MyLanguage/Risikobewertung#create_rsik|Record/edit risk]] | ||
* [[Special:MyLanguage/Maßnahmen#create_measure| | * [[Special:MyLanguage/Maßnahmen#create_measure|Create/edit measure]] | ||
* [[Special:MyLanguage/Kontrolldefinitionen#create_check| | * [[Special:MyLanguage/Kontrolldefinitionen#create_check|Create/edit controls]] | ||
* [[Special:MyLanguage/Fortschrittsmeldungen#req_progress| | * [[Special:MyLanguage/Fortschrittsmeldungen#req_progress|Request progress reports]] | ||
* [[Special:MyLanguage/Externe#create_external| | * [[Special:MyLanguage/Externe#create_external|Create/edit external parties]] | ||
''' | '''Administrators or Experts''' | ||
* [[Special:MyLanguage/Risikopolitik| | * [[Special:MyLanguage/Risikopolitik|Manage risk policy]] | ||
* [[Special:MyLanguage/Einstellungen| | * [[Special:MyLanguage/Einstellungen|Manage settings for measures and controls]] | ||
* [[Special:MyLanguage/Betroffenenkategorien#create_affected| | * [[Special:MyLanguage/Betroffenenkategorien#create_affected|Create/edit data subject categories]] | ||
* [[Special:MyLanguage/Datenimport#import| | * [[Special:MyLanguage/Datenimport#import|Import data]] | ||
''' | '''Administrators''' | ||
* [[Special:MyLanguage/REST API|REST API: | * [[Special:MyLanguage/REST API|REST API: data import/export interface]] | ||
''' | '''External users''' | ||
* [[Special:MyLanguage/Lieferantenportal|HITGuard | * [[Special:MyLanguage/Lieferantenportal|HITGuard portal for suppliers]] | ||
=== Workflows | <span id="Workflows_im_Überblick"></span> | ||
=== Workflows at a glance === | |||
* [[Special:MyLanguage/Workflow Maßnahme| | * [[Special:MyLanguage/Workflow Maßnahme|Measure workflow]] | ||
* [[Special:MyLanguage/Workflow Kontrolle| | * [[Special:MyLanguage/Workflow Kontrolle|Control workflow]] | ||
* [[Special:MyLanguage/Workflow Überprüfung| | * [[Special:MyLanguage/Workflow Überprüfung|Review workflow]] | ||
* [[Special:MyLanguage/Workflow VT| | * [[Special:MyLanguage/Workflow VT|Processing activity workflow]] | ||
* [[Special:MyLanguage/Workflow Risiko Chance| | * [[Special:MyLanguage/Workflow Risiko Chance|Risk/Opportunity workflow]] | ||
* [[Special:MyLanguage/Workflow Meldung| | * [[Special:MyLanguage/Workflow Meldung|Report workflow]] | ||
* [[Special:MyLanguage/Workflow Doku-Management| | * [[Special:MyLanguage/Workflow Doku-Management|Document management workflow]] | ||
* [[Special:MyLanguage/Wie sollte ich vorgehen, wenn ich eine Schutzbedarfsanalyse vornehmen möchte?| | * [[Special:MyLanguage/Wie sollte ich vorgehen, wenn ich eine Schutzbedarfsanalyse vornehmen möchte?|Procedure for a protection requirement analysis]] | ||
== Release Notes == | == Release Notes == | ||
{| class="wikitable" | {| class="wikitable" | ||
! | ! Year !! Releases | ||
|- | |- | ||
| 2026 || [[Special:MyLanguage/HITGuard Release April 2026|April]] | | 2026 || [[Special:MyLanguage/HITGuard Release April 2026|April]] | ||
| Zeile 326: | Zeile 342: | ||
| 2025 || [[Special:MyLanguage/HITGuard Release April 2025|April]] · [[Special:MyLanguage/HITGuard Release August 2025|August]] · [[Special:MyLanguage/HITGuard Release November 2025|November]] | | 2025 || [[Special:MyLanguage/HITGuard Release April 2025|April]] · [[Special:MyLanguage/HITGuard Release August 2025|August]] · [[Special:MyLanguage/HITGuard Release November 2025|November]] | ||
|- | |- | ||
| 2024 || [[Special:MyLanguage/HITGuard Release März 2024| | | 2024 || [[Special:MyLanguage/HITGuard Release März 2024|March]] · [[Special:MyLanguage/HITGuard Release August 2024|August]] · [[Special:MyLanguage/HITGuard Release Dezember 2024|December]] | ||
|- | |- | ||
| 2023 || [[Special:MyLanguage/HITGuard Release Februar 2023| | | 2023 || [[Special:MyLanguage/HITGuard Release Februar 2023|February]] · [[Special:MyLanguage/HITGuard Release Juni 2023|June]] · [[Special:MyLanguage/HITGuard Release Oktober 2023|October]] | ||
|- | |- | ||
| 2022 || [[Special:MyLanguage/HITGuard Release Jänner 2022| | | 2022 || [[Special:MyLanguage/HITGuard Release Jänner 2022|January]] · [[Special:MyLanguage/HITGuard Release Juni 2022|June]] · [[Special:MyLanguage/HITGuard Release Oktober 2022|October]] | ||
|- | |- | ||
| 2021 || [[Special:MyLanguage/HITGuard Release Jänner 2021| | | 2021 || [[Special:MyLanguage/HITGuard Release Jänner 2021|January]] · [[Special:MyLanguage/HITGuard Release April 2021|April]] · [[Special:MyLanguage/HITGuard Release September 2021|September]] | ||
|- | |- | ||
| 2020 || [[Special:MyLanguage/HITGuard Release April 2020|April]] · [[Special:MyLanguage/HITGuard Release Juli 2020| | | 2020 || [[Special:MyLanguage/HITGuard Release April 2020|April]] · [[Special:MyLanguage/HITGuard Release Juli 2020|July]] · [[Special:MyLanguage/HITGuard Release Oktober 2020|October]] | ||
|- | |- | ||
| 2019 || [[Special:MyLanguage/HITGuard Release März 2019| | | 2019 || [[Special:MyLanguage/HITGuard Release März 2019|March]] · [[Special:MyLanguage/HITGuard Release April 2019|April]] · [[Special:MyLanguage/HITGuard Release Juli 2019|July]] · [[Special:MyLanguage/HITGuard Release Dezember 2019|December]] | ||
|} | |} | ||
Release | Release notes from the years 2017 and 2018 have been incorporated directly into the help. | ||
== | <span id="Anmeldung_&_Authentifizierung"></span> | ||
== Login & authentication == | |||
* [[Special:MyLanguage/Login Möglichkeiten|Login | * [[Special:MyLanguage/Login Möglichkeiten|Login options]] | ||
* [[Special:MyLanguage/Passkeys|Passkeys]] | * [[Special:MyLanguage/Passkeys|Passkeys]] | ||
* [[Special:MyLanguage/2FA| | * [[Special:MyLanguage/2FA|Two-factor authentication]] | ||
== | <span id="Installationshilfe"></span> | ||
== Installation help == | |||
* [[Special:MyLanguage/Installationshilfe| | * [[Special:MyLanguage/Installationshilfe|Installation help]] | ||
Aktuelle Version vom 10. August 2026, 13:32 Uhr
Welcome to the online help of the GRC software HITGuard. This help accompanies you in controlling and monitoring your risks and compliance requirements – understandable for beginners and useful for experienced users.
Help and quick start
In the Help menu item you will find:
- First steps – the interactive introduction to the HITGuard interface, which also greets you when you log in for the first time.
- Online help – The online help you are currently on.
- Page introduction – if an info symbol is visible at the bottom left, a click starts a short introduction to the current page.
Are you new to HITGuard or setting up a new module? Here you will find the right starting point:
- First steps in setting up a management system
- First steps with the data protection module
- First steps with the audit management
- First steps with the case management
- First steps with the document management
- First steps with the ESG module
- First steps with the Supplier Risk Management
- Activating mailings after completing the initial tests
Product overview
HITGuard has a modular structure. Which menu items you see depends on your permissions and the activated features of the respective management system. However, the "My Tasks" module exists for every user. If you want to learn more about it, follow this link:
| Help for My Tasks |
|---|
Below you will find explanations of all menu items of the other modules:
Base modules
Risk management, measures, controls, master data and administration are always available in HITGuard and form the basis of the tool.
| Module | Description |
|---|---|
| Risk management | Identification and assessment of risks and opportunities on a central platform for assessments and treatments. The risk policy is freely configurable, and various workflows support you in this. → Risk/Opportunity workflow · For Practitioners |
| Measures | Implementation of measures to eliminate or reduce risks and security gaps. Tracking via progress reports and effectiveness review. → Measure workflow · For Practitioners |
| Controls | Management and assessment of controls and their effectiveness. Create control definitions and track execution. → Control workflow · For Practitioners |
| Master data | Maintenance of company data, resources and assets as well as knowledge bases, questionnaire templates and standards. |
| Administration | Configuration and adaptation of HITGuard to your requirements: management of user accounts, roles and teams as well as integration into existing systems and processes. |
Add-ons
Various extensions cover additional use cases. Add-ons are licensed separately and are usually activated under Administration › Management systems for one or more management systems.
| Add-on | Description |
|---|---|
| Data protection | Support in complying with data protection regulations and guidelines. Activates the "Data protection" menu item. → Processing activity workflow · Working with processing activities |
| Audit management | Carry out internal and external audits, track results and generate reports. Activates the "Audit management" menu item. |
| Case management | Processing of security incidents and violations of guidelines and regulations. Activates the "Case management" menu item. → Report workflow · Creating reports · Whistleblower system |
| Document management | Combines document control, uploaded attachments and the report archive. Activation via your contact person at TogetherSecure. → Document management workflow · Review and approval workflow |
| ESG Management | Support with the double materiality analysis; extends risk management with new menu items. → More about ESG Management |
| Supplier Risk Management | Send reviews to suppliers and integrate them into your audit processes; extends administration and reviews. → More about Supplier Risk Management |
The HITGuard interface

The profile area of the logged-in user is located at the top left, with the main menu below it. Clicking on the profile picture opens the Manage account page, where you can change your data, your profile picture and your password.
The highlighted areas in the image show:
- Intro for the current page – starts the interactive introduction, if available.
- Expand/collapse menu – shows or hides the navigation menu.
- Switch management system – switches between management systems (only visible with permission for several systems; not for Practitioners).
- Current management tasks, administration, accessibility, language, log out:
- Envelope symbol → Current management tasks
- Gear icon → Administration for basic central functions
- Person symbol → configure accessibility
- Flag → switch between German and English
- Log out → log out
Main menu
The menu begins with the personal entries My Tasks and My Dashboards, followed by the module menu items (only visible for authorized modules) and ends with the Help item.
My Tasks

Here you will find all the tasks you have to complete in your role as a Practitioner. A click opens the task dashboard with a summary of all open tasks; a submenu organizes the tasks by type (including those already completed).
- Orange badges show how many tasks you have to process yourself (e.g. requested ((Special:MyLanguage/Fortschrittsmeldungen|progress reports]] or processing activities to be reviewed).
- Blue badges show tasks for which you share responsibility, but which someone else is processing (e.g. controls where your implementation is still being reviewed).
Status of the elements per menu item: Measures · Controls · Reviews · Processing activities · Risks & Opportunities · Reports
My Dashboards

Dashboards provide an overview of the management systems based on key performance indicators (KPIs) and make reports available for reporting. By default, there is one dashboard each for KPIs from risk management, measures and controls; the data protection, case and audit management add-ons each have an additional dashboard. You only ever see dashboards, KPIs and reports for which your user is authorized.
Permissions: Access to a dashboard or its KPIs and reports requires the "Expert", "Professional" or "Observer" role in the respective module (e.g. at least "Professional" in risk management for the risk management dashboard).
My dashboards: You can create additional dashboards. Standard dashboards delivered with HITGuard are marked with a tool icon; they can be edited and reset to their original state, but not deleted. Dashboards you create yourself can be configured as "Private" (only for you) or open (for all authorized members) or can also be deleted.

Favorite: Using the star next to the dashboard configuration, you mark one dashboard per management system as a favorite – it is ranked first and displayed after logging in.
Further reading: Creating/editing dashboards · Risk management · ESG · Measures · Controls · Data protection · Case management · Audit management
Reports on dashboards correspond in content to the reports of the respective menu items (see there for explanations) and additionally offer:
- Prepare several versions: Using the "Filter" button, different configurations of a report can be saved – e.g. a "Risk report – details" with measure and control details for risk owners and a concise "Board report risks" for the board.
- Set as default report setting: On non-private dashboards, Experts and Professionals can set one configuration as the default per report type. This is used automatically in overview lists (e.g. under Risk management › Risk assessment), but remains individually adjustable on the report page itself. Settings already set individually are not overwritten by the default. The default report is marked on the dashboard with a star on the report icon.
AI features

In HTML-editable fields (fields with text formatting) you will find an "asterisk" button, via which you call up AI functions. With it you can, for texts:
- summarize
- proofread
- expand
- shorten
- change the style
- change the tone
- translate between German and English
Using your own prompts, you can also ask the AI questions and generate your own texts. There is a special feature in the deviation analysis and in the review result: there, the AI functions can also be used in the non-HTML-editable field of the justification.
Current management tasks (the envelope)

The envelope at the top right informs Professionals and Experts about tasks that have been reported as completed and are waiting for closure/review. Clicking on the envelope opens the list, which shows them these tasks and expired analysis periods. However, the list only shows the tasks from the current management system. Tasks only appear to users who are authorized to process them (e.g. answered processing activities only to users with Professional/Expert rights in data protection).
| Section | Description |
|---|---|
| Progress reports | Answered progress reports on measures. |
| Risks | Risks that have been newly submitted or returned. |
| Protection requirement analyses | Answered protection requirement analysis. |
| Vulnerability analyses | Answered vulnerability analyses. |
| Reports assigned to me | Open reports assigned to you. |
| Unassigned reports | Reports not yet assigned to any user. Only visible to team members if a support team is stored. |
| Processing activities | Answered processing activities. |
HITGuard module overview
Below are all menu items of the individual modules. Only modules and items for which you are authorized and which have been activated in the management system are visible.
Guides & references
FAQ & glossary
Working with HITGuard
- User profile
- Functionality and symbols of the tables
- Icons and buttons in HITGuard
- Tips, tricks & best practice
Guides by role
Experts or Professionals
- Create/edit audit
- Create/edit audit program
- Create/edit reviews (deviation analyses/review results)
- Record/edit risk
- Create/edit measure
- Create/edit controls
- Request progress reports
- Create/edit external parties
Administrators or Experts
- Manage risk policy
- Manage settings for measures and controls
- Create/edit data subject categories
- Import data
Administrators
External users
Workflows at a glance
Release Notes
| Year | Releases |
|---|---|
| 2026 | April |
| 2025 | April · August · November |
| 2024 | March · August · December |
| 2023 | February · June · October |
| 2022 | January · June · October |
| 2021 | January · April · September |
| 2020 | April · July · October |
| 2019 | March · April · July · December |
Release notes from the years 2017 and 2018 have been incorporated directly into the help.
Login & authentication