Menü aufrufen
Toggle preferences menu
Persönliches Menü aufrufen
Nicht angemeldet
Ihre IP-Adresse wird öffentlich sichtbar sein, wenn Sie Änderungen vornehmen.

OrgEh - Organisationseinheiten/en: Unterschied zwischen den Versionen

Aus HITGuard User Guide
Sala (Diskussion | Beiträge)
Die Seite wurde neu angelegt: „OrgUn - Organizational units“
 
FuzzyBot (Diskussion | Beiträge)
Übernehme Bearbeitung einer neuen Version der Quellseite
 
(145 dazwischenliegende Versionen von 4 Benutzern werden nicht angezeigt)
Zeile 1: Zeile 1:


<div class="mw-translate-fuzzy">
<span id="org_unit"></span>
<span id="org_unit"></span>
Ein Unternehmen besteht aus Organisationseinheiten, die sich an den einzelnen Verarbeitungsprozessen beteiligen. Diese finden wiederum in einer bis mehreren Organisationseinheiten statt. Das Erstellen und Verarbeiten von Daten erfolgt in diesen Organisationseinheiten während der einzelnen Prozessschritte überwiegend IT gestützt und unter Verwendung von IT-Systemen.<br>
A company consists of organizational units that participate in the individual processing procedures. These, in turn, take place in one or several organizational units. The creation and processing of data taking place in these organizational units during the individual process steps is predominantly IT-supported and with the use of IT systems. The more vital the organizational unit, the greater the potential damage, and the greater the requirements for availability, confidentiality and integrity of the data or systems.
Je kritischer die Organisationseinheit, desto größer der potenzielle Schaden, umso größer die Anforderungen an Verfügbarkeit, Vertraulichkeit und Integrität der Daten bzw. Systeme.
</div>


Der Aufbau einer OrgEh sollte hierarchisch sein.
<div class="mw-translate-fuzzy">
The structure of the organizational units should be hierarchical.
</div>


[[Datei:Organisationsstruktur.PNG|left|thumb|900px|Darstellung aus der Strukturanalyse vom Risikomanagement]]<br clear=all>
<div class="mw-translate-fuzzy">
<b>Important:</b> To be able to use OrgUnits in a management system, they need to be activated for the active analysis period! When a new OrgUnit is created, it is automatically assigned to all active (current) analysis periods and thereby activated, if the OrgUnit has been subordinated to another one and this superordinate OrgUnit is already activated in the respective management system. If there is no parent OrgUnit, the newly created OrgUnit will not be automatically activated in all management systems. This needs to then be done manually. For more information, see [[Special:MyLanguage/Managementsysteme#analyses_historie|"Administration → Management System → Analysis Periods"]].
</div>


== <span id="orgcre"></span>Organisationseinheit erstellen / bearbeiten / löschen==
[[Datei:Organisationsstruktur.PNG|left|thumb|900px|Display from structural analysis from risk management]]<br clear=all>


Organisationseinheiten können von Administratoren und Experten über "Administration -> OrgEhs" angelegt oder bearbeitet werden.
<span id="Arbeiten_mit_Organisationseinheiten"></span>
<div class="mw-translate-fuzzy">
== <span id="orgcre"></span>Create/edit/delete organizational unit==
</div>


[[Datei:Organisationsstruktur Maske.png|left|thumb|900px|Maske der Organisationsstrukturen]]<br clear=all>
<div class="mw-translate-fuzzy">
OrgUnits can be created or edited by administrators and experts via "Administration → OrgUnits".
</div>


Um eine neue Organisationseinheit anzulegen, klicken Sie auf den Button "Plus".
<div class="mw-translate-fuzzy">
[[Datei:Organisationsstruktur Maske.png|left|thumb|901px|Organizational structures mask]]<br clear=all>
</div>


Um eine bestehende Organisationseinheit zu bearbeiten, klicken Sie doppelt auf die entsprechende Organisationseinheit.
<div class="mw-translate-fuzzy">
To create a new OrgUnit, click the "Plus" button.
</div>


[[Datei:OrgEH bearbeiten.PNG|left|thumb|900px|Maske zum Bearbeiten / Erstellen einer Organisationseinheit]]<br clear=all>
<div class="mw-translate-fuzzy">
To edit an existing OrgUnit, double-click into the corresponding OrgUnit's row.
</div>


<b>Abkürzung und Bezeichnung:</b><br>
<div class="mw-translate-fuzzy">
* Bei der Abkürzung tragen Sie ein wie die OrgEh abgekürzt werden soll.
[[Datei:OrgEH bearbeiten.PNG|left|thumb|901px|Create/edit organizational unit]]<br clear=all>
* Bei der Bezeichnung tragen Sie die Bezeichnung der OrgEh ein.
</div>


<b>Sortierreihenfolge:</b><br>
<div class="mw-translate-fuzzy">
* Diese legt fest wie die OrgEh in linearen Listen (z.B. in einem Bericht) aufgelistet werden.
<b>Code and name:</b><br>
* For the code, enter how the OrgUnit should be abbreviated.
* For the name, enter the name of the OrgUnit.
</div>


<b>Typ:</b><br>
<div class="mw-translate-fuzzy">
* Hier legen Sie fest, um welche Art von Organisationseinheit es sich handelt.
<b>Sort order:</b> This defines how the OrgUnits are listed in linear lists (e.g. in a report).
:- Konzern
</div>
:- Gesellschaft
:- Abteilung
:- Entity


<b>Übergeordnete OrgEh:</b><br>
<div class="mw-translate-fuzzy">
* Hier tragen Sie ein zu welcher GmbH eine Abteilung gehört.
<b>Superordinate OrgUn:</b> Here, you state how the OrgUnit fits into the hierarchy. For example, which company a department belongs to.
</div>


<b>Verantwortlich:</b><br>
<div class="mw-translate-fuzzy">
* Die hier eingetragene Personen ist für die OrgEh verantwortlich. Es ist beispielsweise der Leiter einer Abteilung.
<b>Type:</b> Here, you specify what type of organizational unit it is: Group, Company, Department, Entity, Branch
</div>


<b>Beschreibung:</b><br>
<div class="mw-translate-fuzzy">
* Hier sollten Sie die OrgEh beschreiben.
<b>Division:</b> Here, you define in which divisions the OrgUnit is active.
</div>


<b>Aktiv von / bis</b><br>
<b>Responsible:</b> The person entered here is responsible for the OrgUnit. For example, a department head.
* Hier können Sie eintragen wie lange eine OrgEh in HITGuard aktiv sein soll.


<b>Anschrift:</b><br>
<b>Description:</b> Here, you describe the OrgUnit.
* Hier können Sie die Anschrift der OrgEh eintragen.


'''Gefährdungslagen:'''
<div class="mw-translate-fuzzy">
: Hier werden alle Gefährdungslagen der Organisationseinheit gelistet. Es ist nicht möglich hier Gefährdungslagen zuzuweisen. Mehr zu Gefährdungslagen finden Sie [[Special:MyLanguage/Risikobewertung|hier]].
<b>Closed:</b> If an OrgUnit is closed, it will only be displayed on this page. It can no longer be selected for new audits, reviews, processing activities and so on. Deactivating it has no effect on current assignments. Merely for reports, the OrgUnit can still be selected.
</div>


'''OrgEh löschen:'''
<div class="mw-translate-fuzzy">
* Zum Löschen klicken Sie in der Bearbeitungs-Maske auf den roten Mülleimer.
<b>Active from/to</b> Here you define the time period in which the OrgUnit should be active in HITGuard. If the OrgUnit is no longer active, but not closed, it can still be selected anywhere, but is displayed in italics to signal that it is inactive.
* Um eine OrgEh löschen zu können, müssen zuvor alle zugeordneten Maßnahmen, Kontrolldefinitionen und Verarbeitungs-Meldungen gelöscht werden
</div>


==== Datenschutzmanagementsystem ====
<div class="mw-translate-fuzzy">
<b>ID in third-party systems:</b> This field is used to synchronize an OrgUnit with a third-party system. Synchronization requires a data import, in which the same ID is set.
</div>


Handelt es sich beim aktiven Managementsystem um das Datenschutzmanagementsystem, besteht zusätzlich die Möglichkeit die Kontaktdaten des Datenschutzbeauftragten der Organisationseinheit zu erfassen. Diese werden für die Auswertung im Datenschutzmanagement benötigt.


Wird bei Auswertungen für eine Organisationseinheit kein Datenschutzbeauftragter gefunden, so wird der Beauftragte der übergeordneten Organisationseinheit herangezogen. Das heißt: Gibt es nur einen Beauftragten in der Organisationsstruktur, so muss dieser nur in der obersten Organisationseinheit eingetragen werden.
<div class="mw-translate-fuzzy">
'''Risks:''' All risks of the OrgUnit are listed here. It is not possible to assign risks here. More about risks can be found [[Special:MyLanguage/Risk Assessment|here]].
</div>


[[Datei:Datenschutzbeauftragter.PNG|thumb|left|900px|Datenschutzbeauftragter]]<br clear=all>
<div class="mw-translate-fuzzy">
<b>Address:</b> Here, you enter the address of the OrgUnit and tick whether the organizational unit is outside of the EU.
</div>  


=== Abweichungen / Maßnahmen / Kontrollen ===
<div class="mw-translate-fuzzy">
'''Delete OrgUnit:''' To delete an OrgUnit, click on the red trash can in the edit screen. In order for an OrgUnit to be deletable, nothing can be linked to it. This means that, for example, all assigned measures, control definitions and processing messages have to be linked to a different OrgUnit or be themselves deleted. The OrgUnit must also not be linked to any active or closed analysis period.
</div>


Das Verhalten ist gleich wie bei den Ressourcen. Mehr dazu [[Special:MyLanguage/Ressourcen#entity_mc|hier]].
<span id="Datenschutzmanagementsystem"></span>
==== Data protection management system ====
 
<div class="mw-translate-fuzzy">
If the active management system is the data protection management system, it is possible to record appropriate safeguards (underneath the address) as well as the contact data of the data protection officer of the OrgUnit. These are required for evaluation in data protection management.
</div>
 
<div class="mw-translate-fuzzy">
If no data protection officer is found during evaluations for an OrgUnit, the officer of the higher-level OrgUnit is used. This means that if there is only one officer in the organizational structure, this officer's information only needs to be entered in the top-level OrgUnit.
</div>
 
[[Datei:Datenschutzbeauftragter.PNG|thumb|left|900px|Data Protection Officer]]<br clear=all>
 
<span id="Abweichungen/Maßnahmen/Kontrollen"></span>
=== Deviations/measures/controls ===
 
<div class="mw-translate-fuzzy">
The behavior is the same as for resources. More about this [[Special:MyLanguage/Resources#entity_mc|here]].
</div>
 
<span id="Auditinformation"></span>
=== Audit information ===
 
<div class="mw-translate-fuzzy">
In the tab "Audit information", you record additional information relevant in the context of audits.
</div>
 
<div class="mw-translate-fuzzy">
* Number of employees: The number of employees can be recorded here.
* Local Management Representative: This is the audit coordinator and contact person that should be defined for every OrgUnit of the type company.
* "Proposal to audit this OrgUnit in each audit program": These OrgUnits are proposed when the corresponding filtering checkmark is set when planning in the audit calendar or in the audit creation form.
* Certifications: Here, any standards (from standards and norms) in which the organizational unit is certified can be selected and assigned. A reg. no. and a location number can then be entered for each of these standards.
</div>
 
[[Datei:OrgEh Auditinformationen.png|left|thumb|901px| Audit information ]]
<br clear=all>
 
<span id="Sparten"></span>
== Divisions ==
 
<div class="mw-translate-fuzzy">
OrgUnits can be assigned several divisions, depending on their field of activity.
</div>
 
 
<div class="mw-translate-fuzzy">
Under "Administration → Edit organizational units | <u>Divisions</u>", these divisions can be managed.
</div>
 
[[Datei:OrgEh Sparten.png|left|thumb|900px| Divisions]]
<br clear=all>
 
<span id="Sparte_erstellen/bearbeiten"></span>
=== Create/edit division ===
 
A new division can be created by clicking the "Plus" button.
 
By double-clicking on a division, it can be edited.
 
[[Datei:OrgEh Sparte bearbeiten.png|left|thumb|900px| Edit division]]
<br clear=all>
 
<span id="Themenverantwortung"></span>
== Topic responsibility<span class="anchor" id="ThemVer"></span> ==
 
<div class="mw-translate-fuzzy">
Topic responsibilities are used for the bulk creation of measures in the context of dossiers in the case management. In them, you can designate responsibilities for certain topics by organizational units.
</div>
 
<div class="mw-translate-fuzzy">
===Activate topic responsibilities===
</div>
 
<div class="mw-translate-fuzzy">
To be able to use topic responsibilities, the checkbox "Topic responsibilities" must first be selected under "Measures → Settings → General". This displays the tab under "Administration → OrgUnits".
</div>
 
<div class="mw-translate-fuzzy">
[[Datei:TV_Breadcrumb.png|left|thumb|900px|Topic responsibility]]
<br clear=all>
</div>
 
<div class="mw-translate-fuzzy">
===Create/edit topic responsibility===
</div>
 
<div class="mw-translate-fuzzy">
A new topic responsibility can be created by clicking the "Plus" button.
</div>
 
<div class="mw-translate-fuzzy">
By double-clicking on a topic responsibility, it can be edited.
</div>
 
<div class="mw-translate-fuzzy">
[[Datei:TV_ITIncident.png|left|thumb|900px|Edit topic responsibility]]
<br clear=all>
</div>
 
<div class="mw-translate-fuzzy">
For the topic responsibility, select the desired organizational units for the respective topic.
</div>
 
<div class="mw-translate-fuzzy">
::<u>Note</u>: OrgUnits that are activated in the current analysis period are available for selection; the others are not selectable.
</div>
 
<div class="mw-translate-fuzzy">
A responsible person or a responsible team must be entered for every selected organizational unit. They will received the measures for implementation when those are created in bulk.
</div>

Aktuelle Version vom 13. Februar 2026, 10:53 Uhr

A company consists of organizational units that participate in the individual processing procedures. These, in turn, take place in one or several organizational units. The creation and processing of data taking place in these organizational units during the individual process steps is predominantly IT-supported and with the use of IT systems. The more vital the organizational unit, the greater the potential damage, and the greater the requirements for availability, confidentiality and integrity of the data or systems.

The structure of the organizational units should be hierarchical.

Important: To be able to use OrgUnits in a management system, they need to be activated for the active analysis period! When a new OrgUnit is created, it is automatically assigned to all active (current) analysis periods and thereby activated, if the OrgUnit has been subordinated to another one and this superordinate OrgUnit is already activated in the respective management system. If there is no parent OrgUnit, the newly created OrgUnit will not be automatically activated in all management systems. This needs to then be done manually. For more information, see "Administration → Management System → Analysis Periods".

Display from structural analysis from risk management


Create/edit/delete organizational unit

OrgUnits can be created or edited by administrators and experts via "Administration → OrgUnits".

Organizational structures mask

To create a new OrgUnit, click the "Plus" button.

To edit an existing OrgUnit, double-click into the corresponding OrgUnit's row.

Create/edit organizational unit

Code and name:

  • For the code, enter how the OrgUnit should be abbreviated.
  • For the name, enter the name of the OrgUnit.

Sort order: This defines how the OrgUnits are listed in linear lists (e.g. in a report).

Superordinate OrgUn: Here, you state how the OrgUnit fits into the hierarchy. For example, which company a department belongs to.

Type: Here, you specify what type of organizational unit it is: Group, Company, Department, Entity, Branch

Division: Here, you define in which divisions the OrgUnit is active.

Responsible: The person entered here is responsible for the OrgUnit. For example, a department head.

Description: Here, you describe the OrgUnit.

Closed: If an OrgUnit is closed, it will only be displayed on this page. It can no longer be selected for new audits, reviews, processing activities and so on. Deactivating it has no effect on current assignments. Merely for reports, the OrgUnit can still be selected.

Active from/to Here you define the time period in which the OrgUnit should be active in HITGuard. If the OrgUnit is no longer active, but not closed, it can still be selected anywhere, but is displayed in italics to signal that it is inactive.

ID in third-party systems: This field is used to synchronize an OrgUnit with a third-party system. Synchronization requires a data import, in which the same ID is set.


Risks: All risks of the OrgUnit are listed here. It is not possible to assign risks here. More about risks can be found here.

Address: Here, you enter the address of the OrgUnit and tick whether the organizational unit is outside of the EU.

Delete OrgUnit: To delete an OrgUnit, click on the red trash can in the edit screen. In order for an OrgUnit to be deletable, nothing can be linked to it. This means that, for example, all assigned measures, control definitions and processing messages have to be linked to a different OrgUnit or be themselves deleted. The OrgUnit must also not be linked to any active or closed analysis period.

Data protection management system

If the active management system is the data protection management system, it is possible to record appropriate safeguards (underneath the address) as well as the contact data of the data protection officer of the OrgUnit. These are required for evaluation in data protection management.

If no data protection officer is found during evaluations for an OrgUnit, the officer of the higher-level OrgUnit is used. This means that if there is only one officer in the organizational structure, this officer's information only needs to be entered in the top-level OrgUnit.

Data Protection Officer


Deviations/measures/controls

The behavior is the same as for resources. More about this here.

Audit information

In the tab "Audit information", you record additional information relevant in the context of audits.

  • Number of employees: The number of employees can be recorded here.
  • Local Management Representative: This is the audit coordinator and contact person that should be defined for every OrgUnit of the type company.
  • "Proposal to audit this OrgUnit in each audit program": These OrgUnits are proposed when the corresponding filtering checkmark is set when planning in the audit calendar or in the audit creation form.
  • Certifications: Here, any standards (from standards and norms) in which the organizational unit is certified can be selected and assigned. A reg. no. and a location number can then be entered for each of these standards.
Audit information


Divisions

OrgUnits can be assigned several divisions, depending on their field of activity.


Under "Administration → Edit organizational units | Divisions", these divisions can be managed.

Divisions


Create/edit division

A new division can be created by clicking the "Plus" button.

By double-clicking on a division, it can be edited.

Edit division


Topic responsibility

Topic responsibilities are used for the bulk creation of measures in the context of dossiers in the case management. In them, you can designate responsibilities for certain topics by organizational units.

Activate topic responsibilities

To be able to use topic responsibilities, the checkbox "Topic responsibilities" must first be selected under "Measures → Settings → General". This displays the tab under "Administration → OrgUnits".

Topic responsibility


Create/edit topic responsibility

A new topic responsibility can be created by clicking the "Plus" button.

By double-clicking on a topic responsibility, it can be edited.

Edit topic responsibility


For the topic responsibility, select the desired organizational units for the respective topic.

Note: OrgUnits that are activated in the current analysis period are available for selection; the others are not selectable.

A responsible person or a responsible team must be entered for every selected organizational unit. They will received the measures for implementation when those are created in bulk.