Menü aufrufen
Toggle preferences menu
Persönliches Menü aufrufen
Nicht angemeldet
Ihre IP-Adresse wird öffentlich sichtbar sein, wenn Sie Änderungen vornehmen.

OrgEh - Organisationseinheiten/en: Unterschied zwischen den Versionen

Aus HITGuard User Guide
Sala (Diskussion | Beiträge)
Die Seite wurde neu angelegt: „left|thumb|900px|Display from structural analysis from risk management<br clear=all>“
FuzzyBot (Diskussion | Beiträge)
Übernehme Bearbeitung einer neuen Version der Quellseite
 
(149 dazwischenliegende Versionen von 5 Benutzern werden nicht angezeigt)
Zeile 1: Zeile 1:


<span id="org_unit"></span>.
<span id="org_unit"></span>
A company consists of organizational units that participate in the individual processing procedures. These in turn take place in one to several organizational units. The creation and processing of data takes place in these organizational units during the individual process steps predominantly IT-supported and with the use of IT systems.<br>
A company consists of organizational units that interact with other kinds of master data: [[Special:MyLanguage/Prozesse|Processes]] take place in one or several organizational units. Creation and processing of [[Special:MyLanguage/Datenkategorien|data categories]] takes place in these organizational units during the individual process steps. It is predominantly IT-supported and done with the use of [[Special:MyLanguage/Ressourcen|IT systems]]. The more vital the organizational unit, the greater the potential damage, and the greater the requirements for availability, confidentiality and integrity of the data or systems.</p>
The more critical the organizational unit, the greater the potential damage, and the greater the requirements for availability, confidentiality and integrity of the data or systems.
An organizational unit is a mandatory field in all HITGuard core elements. Every [[Special:MyLanguage/Schutzbedarf|protection needs]]- and [[Special:MyLanguage/Schwachstellen|vulnerability/gap analysis]], as well as all [[Special:MyLanguage/Aktuelle_Maßnahmen|measures]] and [[Special:MyLanguage/Kontrolldefinitionen|controls]] must always refer to an organizational unit that is responsible for them.  


The structure of an OrgUn should be hierarchical.
The structure of the organizational units is hierarchical.


[[Datei:Organisationsstruktur.PNG|left|thumb|900px|Display from structural analysis from risk management]]<br clear=all>
<b>Important:</b> To be able to use OrgUnits in a management system, they must be activated for the [[Special:MyLanguage/Managementsysteme#Aktiver_Analysezeitraum|analysis period]] by ticking a checkbox. The checkbox of the new OrgUnit always inherits the checkbox setting of its parent OrgUnit. If you create a new OrgUnit that has no parent OrgUnit, no checkbox is set automatically. You must therefore activate it yourself under Administration > Management System > Active analysis period.


== <span id="orgcre"></span>Organisationseinheit erstellen / bearbeiten / löschen==
[[Datei:Organisationsstruktur.PNG|left|thumb|900px|How HITGuard displays Organizational Units in the structural analysis]]<br clear=all>


Organisationseinheiten können von Administratoren und Experten über "Administration -> OrgEhs" angelegt oder bearbeitet werden.
<span id="Arbeiten_mit_Organisationseinheiten"></span>
== <span id="orgcre"></span> Working with organizational units ==


[[Datei:Organisationsstruktur Maske.png|left|thumb|900px|Maske der Organisationsstrukturen]]<br clear=all>
OrgUnits can be created or edited by administrators and experts via "Administration → OrgUnits". To create a new OrgUnit, click the "Plus" button. To edit an existing OrgUnit, open it by double-clicking the corresponding row.


Um eine neue Organisationseinheit anzulegen, klicken Sie auf den Button "Plus".
[[Datei:Organisationsstruktur Maske.png|left|thumb|700px|Organizational structures mask]]<br clear=all>


Um eine bestehende Organisationseinheit zu bearbeiten, klicken Sie doppelt auf die entsprechende Organisationseinheit.
[[Datei:OrgEH bearbeiten.PNG|left|thumb|700px|Form for editing/creating an organizational unit]]<br clear=all>


[[Datei:OrgEH bearbeiten.PNG|left|thumb|900px|Maske zum Bearbeiten / Erstellen einer Organisationseinheit]]<br clear=all>
<!--Deleted-->


<b>Abkürzung und Bezeichnung:</b><br>
For each organizational unit, there are several input fields that you can use to further define it:  
* Bei der Abkürzung tragen Sie ein wie die OrgEh abgekürzt werden soll.
* Bei der Bezeichnung tragen Sie die Bezeichnung der OrgEh ein.


<b>Sortierreihenfolge:</b><br>
<b>Abbreviation and designation:</b><br> In the designation, you enter the assigned name of the OrgUnit, while in the abbreviation you enter how the OrgUnit should be abbreviated. Please note that HITGuard will use this abbreviation in the [[Special:MyLanguage/Strukturanalyse|structural analysis]] and when [[Special:MyLanguage/Managementsysteme#Kürzel_Generierung|generating abbreviations for other entities]].  
* Diese legt fest wie die OrgEh in linearen Listen (z.B. in einem Bericht) aufgelistet werden.


<b>Typ:</b><br>
<b>Sort order:</b> Defines the order in which the OrgUnits are listed, e.g., in a report. (e.g. in a report).
* Hier legen Sie fest, um welche Art von Organisationseinheit es sich handelt.
:- Konzern
:- Gesellschaft
:- Abteilung
:- Entity


<b>Übergeordnete OrgEh:</b><br>
<b>Superordinate OrgUnit:</b> Here you establish the hierarchical structure of the organizational units by specifying where the OrgUnit fits into the hierarchy, for example, which company a department belongs to.
* Hier tragen Sie ein zu welcher GmbH eine Abteilung gehört.


<b>Verantwortlich:</b><br>
<b>Type:</b> Here, you specify the type of organizational unit: Group, Company, Department, Entity, Branch
* Die hier eingetragene Personen ist für die OrgEh verantwortlich. Es ist beispielsweise der Leiter einer Abteilung.


<b>Beschreibung:</b><br>
<b>Division:</b> Here, you define in which divisions the OrgUnit is active. Divisions are primarily used in the add-on for [[Special:MyLanguage/Auditplanung|Audit planning]].
* Hier sollten Sie die OrgEh beschreiben.


<b>Aktiv von / bis</b><br>
<b>Responsible:</b> The person entered here is responsible for the OrgUnit. This could be, for example, the head of a department.
* Hier können Sie eintragen wie lange eine OrgEh in HITGuard aktiv sein soll.


<b>Anschrift:</b><br>
<b>Description:</b> Here, you describe the OrgUnit.
* Hier können Sie die Anschrift der OrgEh eintragen.


'''Gefährdungslagen:'''
<b>Closed:</b> If an OrgUnit is closed, it is only displayed on this page. It can no longer be selected for new elements. Deactivating has no effect on current assignments, and the OrgUnit can still be selected for reports.  
: Hier werden alle Gefährdungslagen der Organisationseinheit gelistet. Es ist nicht möglich hier Gefährdungslagen zuzuweisen. Mehr zu Gefährdungslagen finden Sie [[Special:MyLanguage/Risikobewertung|hier]].  


'''OrgEh löschen:'''
<b>Active from/to</b> Here you define the time period in which the OrgUnit should be active in HITGuard. If the OrgUnit is no longer active, but not closed, it can still be selected anywhere, but is displayed in italics to signal that it is inactive.
* Zum Löschen klicken Sie in der Bearbeitungs-Maske auf den roten Mülleimer.
* Um eine OrgEh löschen zu können, müssen zuvor alle zugeordneten Maßnahmen, Kontrolldefinitionen und Verarbeitungs-Meldungen gelöscht werden


==== Datenschutzmanagementsystem ====
<b>ID in third-party systems:</b> HITGuard uses this ID to identify individual OrgUnits during import. It is therefore not possible to store two OrgUnits  with the same ID in the third-party system in a HITGuard instance. <br> If an OrgUnit is imported whose ID matches the ID of an already existing resource, no new OrgUnit is created. Instead, HITGuard enters the import data into the existing OrgUnit. This function enables you to create automated updates. You can find more about this under [[Special:MyLanguage/Datenimport|Data import]].


Handelt es sich beim aktiven Managementsystem um das Datenschutzmanagementsystem, besteht zusätzlich die Möglichkeit die Kontaktdaten des Datenschutzbeauftragten der Organisationseinheit zu erfassen. Diese werden für die Auswertung im Datenschutzmanagement benötigt.


Wird bei Auswertungen für eine Organisationseinheit kein Datenschutzbeauftragter gefunden, so wird der Beauftragte der übergeordneten Organisationseinheit herangezogen. Das heißt: Gibt es nur einen Beauftragten in der Organisationsstruktur, so muss dieser nur in der obersten Organisationseinheit eingetragen werden.
'''Risks:''' All risks of the OrgUnit are listed here. It is not possible to assign risks here. More about risks can be found [[Special:MyLanguage/Risk Assessment|here]].  


[[Datei:Datenschutzbeauftragter.PNG|thumb|left|900px|Datenschutzbeauftragter]]<br clear=all>
<b>Address:</b> Here you can enter the address of the OrgUnit and tick a checkbox if the organizational unit is located outside the EU. If you are in a data protection management system, you can then record the appropriate safeguards (more on this below).


=== Abweichungen / Maßnahmen / Kontrollen ===
'''Delete OrgUnit:''' To delete an OrgUnit, click on the red trash can in the edit screen. An OrgUnit can only be deleted if nothing is linked to it. This means it must not be activated in any active or past analysis period. In addition, all assigned measures, reviews, and other elements must be assigned to another suitable OrgUnit or deleted. If this is not possible, the OrgUnit can be marked as closed (see above).


Das Verhalten ist gleich wie bei den Ressourcen. Mehr dazu [[Special:MyLanguage/Ressourcen#entity_mc|hier]].
<span id="Datenschutzmanagementsystem"></span>
==== Data protection management system ====
 
If the active management system is the data protection management system, you can record appropriate safeguards as well as the contact details of the data protection officer of the OrgUnit. These are required for the data protection management system.
 
If HITGuard does not find a data protection officer when evaluating an OrgUnit, HITGuard will use the officer of the parent OrgUnit. This means: If there is only a single officer in the organizational structure, it only needs to be entered in the highest-ranking Org Unit.
 
[[Datei:Datenschutzbeauftragter.PNG|thumb|left|900px|Data Protection Officer]]<br clear=all>
 
<span id="Abweichungen/Maßnahmen/Kontrollen"></span>
=== Deviations/measures/controls ===
 
In the additional tabs, HITGUard lists[[Special:MyLanguage/Schwachstellen|gaps]], [[Special:MyLanguage/Aktuelle_Maßnahmen|measures]] and [[Special:MyLanguage/Kontrolldefinitionen|controls]] that are linked to the entity via [[Special:MyLanguage/Überprüfung#Prüfobjekte_hinzufügen|review objects]]. These lists only provide an overview. This means that you cannot assign deviations, measures, or controls here.
 
<span id="Auditinformation"></span>
=== Audit information ===
 
In the tab "Audit information", youcan record additional information relevant for the context of audits.
 
* Number of employees: Here you can record the number of employees.
* Local management representative: The LMR is the audit coordinator and contact person who should be defined for each OrgUnit of the type "Company".
* "Proposal to audit this OrgUnit in every audit program": If you set the corresponding checkbox during filtering in the audit calendar or during audit creation, HITGuard will suggest these OrgUnits.
* Certifications: Here you can select and assign standards (from standards and norms) according to which the OrgUnit is certified. For each of these standards, a registration number and a site number can be recorded.
 
[[Datei:OrgEh Auditinformationen.png|left|thumb|901px| Audit information ]]
<br clear=all>
 
<span id="Sparten"></span>
== Divisions ==
 
OrgUnits can be assigned several divisions, depending on their field of activity. You can use these functions in the add-on for [[Special:MyLanguage/Auditplanung|Audit planning]].
 
 
Under "Administration → <u>Divisions</u>", these divisions can be managed.
 
[[Datei:OrgEh Sparten.png|left|thumb|900px| Divisions]]
<br clear=all>
 
<span id="Sparte_erstellen/bearbeiten"></span>
=== Create/edit division ===
 
A new division can be created by clicking the "Plus" button.
 
By double-clicking on a division, it can be edited.
 
[[Datei:OrgEh Sparte bearbeiten.png|left|thumb|900px| Edit division]]
<br clear=all>
 
<span id="Themenverantwortung"></span>
== Topic responsibility<span class="anchor" id="ThemVer"></span> ==
 
Topic responsibilities are used for the [[Special:MyLanguage/Akten#Mehrfachanlage_von_Maßnahmen|bulk creation of measures]] in the context of dossiers in the case management. In them, you can designate responsibilities for certain topics by organizational units.
 
To use topic responsibilities, you must first select the checkbox "Topic responsibility" under "[[Special:MyLanguage/Maßnahmen_Einstellungen|Measures → settings]]". This activates the menu item in the breadcrumb menu under "Administration → OrgUnits". Topic responsibilities allow you to distribute multiple [[Special:MyLanguage/Aktuelle_Maßnahmen|measures]] to many OrgUnits at once. Here you can prepare the responsible users for each OrgUnit.
 
You can create a new topic responsibility by clicking the plus button. You can open an existing topic responsibility by double-clicking it in the list.
 
You can then enter a designation and a description.
 
[[Datei:TV_ITIncident.png|left|thumb|900px|Edit topic responsibility]] <br clear=all>
 
Select the desired organizational units for the respective topic.<br>
::<u>Note</u>: Here, all OrgUnits that are activated for the current analysis period are available to you. The others cannot be selected.
 
For each selected organizational unit, you must then enter a responsible user or team to whom the measures will be assigned for implementation when creating measures in bulk.
 
<div class="mw-translate-fuzzy">
For each selected organizational unit, its responsible user (see above) is entered by HITGUard by default. If no responsible person is defined there, this field is empty. If no OrgUnit responsible person is available, a responsible user <b>must</b> be set so that the organizational unit can be selected.
</div>
 
Even if an OrgUnit responsible person is prepared, the responsible person can be manually replaced here for the respective topic by another user or a team (manually set topic responsibles are shown in bold).
 
::<u>Note</u>: This does not change the responsibility in the organizational unit itself. A change in the organizational unit also does not overwrite topic responsibles that have already been manually set here.
 
The topic responsibilities are then used in case management dossiers for [[Special:MyLanguage/Akten#Mehrfachanlage_von_Maßnahmen|creating measures in bulk]] .

Aktuelle Version vom 5. August 2026, 06:41 Uhr

A company consists of organizational units that interact with other kinds of master data: Processes take place in one or several organizational units. Creation and processing of data categories takes place in these organizational units during the individual process steps. It is predominantly IT-supported and done with the use of IT systems. The more vital the organizational unit, the greater the potential damage, and the greater the requirements for availability, confidentiality and integrity of the data or systems.

An organizational unit is a mandatory field in all HITGuard core elements. Every protection needs- and vulnerability/gap analysis, as well as all measures and controls must always refer to an organizational unit that is responsible for them.

The structure of the organizational units is hierarchical.

Important: To be able to use OrgUnits in a management system, they must be activated for the analysis period by ticking a checkbox. The checkbox of the new OrgUnit always inherits the checkbox setting of its parent OrgUnit. If you create a new OrgUnit that has no parent OrgUnit, no checkbox is set automatically. You must therefore activate it yourself under Administration > Management System > Active analysis period.

How HITGuard displays Organizational Units in the structural analysis


Working with organizational units

OrgUnits can be created or edited by administrators and experts via "Administration → OrgUnits". To create a new OrgUnit, click the "Plus" button. To edit an existing OrgUnit, open it by double-clicking the corresponding row.

Organizational structures mask


Form for editing/creating an organizational unit



For each organizational unit, there are several input fields that you can use to further define it:

Abbreviation and designation:
In the designation, you enter the assigned name of the OrgUnit, while in the abbreviation you enter how the OrgUnit should be abbreviated. Please note that HITGuard will use this abbreviation in the structural analysis and when generating abbreviations for other entities.

Sort order: Defines the order in which the OrgUnits are listed, e.g., in a report. (e.g. in a report).

Superordinate OrgUnit: Here you establish the hierarchical structure of the organizational units by specifying where the OrgUnit fits into the hierarchy, for example, which company a department belongs to.

Type: Here, you specify the type of organizational unit: Group, Company, Department, Entity, Branch

Division: Here, you define in which divisions the OrgUnit is active. Divisions are primarily used in the add-on for Audit planning.

Responsible: The person entered here is responsible for the OrgUnit. This could be, for example, the head of a department.

Description: Here, you describe the OrgUnit.

Closed: If an OrgUnit is closed, it is only displayed on this page. It can no longer be selected for new elements. Deactivating has no effect on current assignments, and the OrgUnit can still be selected for reports.

Active from/to Here you define the time period in which the OrgUnit should be active in HITGuard. If the OrgUnit is no longer active, but not closed, it can still be selected anywhere, but is displayed in italics to signal that it is inactive.

ID in third-party systems: HITGuard uses this ID to identify individual OrgUnits during import. It is therefore not possible to store two OrgUnits with the same ID in the third-party system in a HITGuard instance.
If an OrgUnit is imported whose ID matches the ID of an already existing resource, no new OrgUnit is created. Instead, HITGuard enters the import data into the existing OrgUnit. This function enables you to create automated updates. You can find more about this under Data import.


Risks: All risks of the OrgUnit are listed here. It is not possible to assign risks here. More about risks can be found here.

Address: Here you can enter the address of the OrgUnit and tick a checkbox if the organizational unit is located outside the EU. If you are in a data protection management system, you can then record the appropriate safeguards (more on this below).

Delete OrgUnit: To delete an OrgUnit, click on the red trash can in the edit screen. An OrgUnit can only be deleted if nothing is linked to it. This means it must not be activated in any active or past analysis period. In addition, all assigned measures, reviews, and other elements must be assigned to another suitable OrgUnit or deleted. If this is not possible, the OrgUnit can be marked as closed (see above).

Data protection management system

If the active management system is the data protection management system, you can record appropriate safeguards as well as the contact details of the data protection officer of the OrgUnit. These are required for the data protection management system.

If HITGuard does not find a data protection officer when evaluating an OrgUnit, HITGuard will use the officer of the parent OrgUnit. This means: If there is only a single officer in the organizational structure, it only needs to be entered in the highest-ranking Org Unit.

Data Protection Officer


Deviations/measures/controls

In the additional tabs, HITGUard listsgaps, measures and controls that are linked to the entity via review objects. These lists only provide an overview. This means that you cannot assign deviations, measures, or controls here.

Audit information

In the tab "Audit information", youcan record additional information relevant for the context of audits.

  • Number of employees: Here you can record the number of employees.
  • Local management representative: The LMR is the audit coordinator and contact person who should be defined for each OrgUnit of the type "Company".
  • "Proposal to audit this OrgUnit in every audit program": If you set the corresponding checkbox during filtering in the audit calendar or during audit creation, HITGuard will suggest these OrgUnits.
  • Certifications: Here you can select and assign standards (from standards and norms) according to which the OrgUnit is certified. For each of these standards, a registration number and a site number can be recorded.
Audit information


Divisions

OrgUnits can be assigned several divisions, depending on their field of activity. You can use these functions in the add-on for Audit planning.


Under "Administration → Divisions", these divisions can be managed.

Divisions


Create/edit division

A new division can be created by clicking the "Plus" button.

By double-clicking on a division, it can be edited.

Edit division


Topic responsibility

Topic responsibilities are used for the bulk creation of measures in the context of dossiers in the case management. In them, you can designate responsibilities for certain topics by organizational units.

To use topic responsibilities, you must first select the checkbox "Topic responsibility" under "Measures → settings". This activates the menu item in the breadcrumb menu under "Administration → OrgUnits". Topic responsibilities allow you to distribute multiple measures to many OrgUnits at once. Here you can prepare the responsible users for each OrgUnit.

You can create a new topic responsibility by clicking the plus button. You can open an existing topic responsibility by double-clicking it in the list.

You can then enter a designation and a description.

Edit topic responsibility


Select the desired organizational units for the respective topic.

Note: Here, all OrgUnits that are activated for the current analysis period are available to you. The others cannot be selected.

For each selected organizational unit, you must then enter a responsible user or team to whom the measures will be assigned for implementation when creating measures in bulk.

For each selected organizational unit, its responsible user (see above) is entered by HITGUard by default. If no responsible person is defined there, this field is empty. If no OrgUnit responsible person is available, a responsible user must be set so that the organizational unit can be selected.

Even if an OrgUnit responsible person is prepared, the responsible person can be manually replaced here for the respective topic by another user or a team (manually set topic responsibles are shown in bold).

Note: This does not change the responsibility in the organizational unit itself. A change in the organizational unit also does not overwrite topic responsibles that have already been manually set here.

The topic responsibilities are then used in case management dossiers for creating measures in bulk .