Menü aufrufen
Toggle preferences menu
Persönliches Menü aufrufen
Nicht angemeldet
Ihre IP-Adresse wird öffentlich sichtbar sein, wenn Sie Änderungen vornehmen.

Standards und Normen/en: Unterschied zwischen den Versionen

Aus HITGuard User Guide
Sala (Diskussion | Beiträge)
Die Seite wurde neu angelegt: „But these are not installed automatically!“
KoKl (Diskussion | Beiträge)
Die Seite wurde neu angelegt: „To create a standard mapping, you must do so within the respective element. For example, if you want to link a risk to a chapter in the standard, you must do so within the risk. In the respective element, locate the “'''Standard Mapping'''” option and click on it to open the dialog box.“
 
(49 dazwischenliegende Versionen von 4 Benutzern werden nicht angezeigt)
Zeile 1: Zeile 1:


There are most different standards with whose contents knowledge bases can be related, regarding test questions or threats, measures or controls. Examples of standards: BSI, ISO 27001, ISO 80001, EU-GDPR, etc.
<span id="standard"></span>
[[File:Standards and Norms Overview.png|right|thumb|500px| Standards and Norms]] HITGuard is designed to help you demonstrate your compliance with various standards and norms (e.g., ISO 27001, EU GDPR, ISO 9001, etc.). That is why standards and norms are provided as an ''evaluation tool''. The standards and norms in HITGuard are simply tables of contents and are linked to other elements (e.g., [[Special:MyLanguage/Wissensdatenbanken|knowledge bases]], [[Special:MyLanguage/Aktuelle_Maßnahmen|measures]], [[Special:MyLanguage/Risikobewertung|risks]], etc.) via standard mapping. You can then use these mappings later, for example, with the KPI [[Special:MyLanguage/Risikomanagement_Dashboard#Compliance_Erfüllung|Compliance Achievement]].  


Standards and norms are divided into chapters, which in turn may contain sub-chapters. These chapters (or sub-chapters) can reference other chapters (and sub-chapters), and in principle a reference is unidirectional (bidirectional references can be created). Similarly, chapters can reference chapters and sub-chapters of other standards. This makes it possible to derive one standard from another. Furthermore, this means that, for example, a test question that references such a standard chapter is automatically also related to the chapter of another standard.  
Standards and norms are divided into chapters, which in turn may contain sub-chapters. These chapters (or sub-chapters) can reference other chapters (and sub-chapters), and in principle a reference is unidirectional (bidirectional references can be created). Similarly, chapters can reference chapters and sub-chapters of other standards. This makes it possible to derive one standard from another. Furthermore, this means that, for example, a test question that references such a standard chapter is automatically also related to the chapter of another standard.  


Knowledge bases can map audit questions, controls, threats or measures to standards and norms. This mapping means that certain evaluations can be made against standards and norms, e.g., about measures and controls that have already been implemented. This makes it clear in which areas of the standard a company is particularly active. This allows statements to be made about the degree of compliance with the standard and the maturity of the management system in this area.
You can map knowledge bases, risks, review questions, [[Special:MyLanguage/Kontrolldefinitionen|controls]], or measures to standards and regulations. We explain how to set up this standard mapping later in the chapter “[[Setting Up Standard Mapping]].” This mapping enables specific analyses later on, such as which measures and controls address which chapters of the standard. This reveals which areas of the standard are the focus of a particularly high number of activities carried out by an organization. As a result, conclusions can be drawn about the degree of compliance with the standard and the management system’s score in this area.


The norms and standards provided by TogetherSecure cannot be modified by users. Referencing of these "vendor chapters" of specially created norms and standards is allowed.
The norms and standards provided by TogetherSecure cannot be modified by users. Referencing of these "vendor chapters" of specially created norms and standards is allowed.  


However, a "definition of the scope" for <b>each</b> management system can be recorded for <b>each</b> standard or norm. In the course of this, it can be additionally selected for each standard chapter justified whether it is applicable for the current management system or not. This information can be used to generate a "Statement of Applicability" report under "Risk Management → Reports → Standards and Norms".  
However, a "definition of the scope" for <b>each</b> management system can be recorded for <b>each</b> standard or norm. In the course of this, it can be additionally selected for each standard chapter justified whether it is applicable for the current management system or not. This information can be used to generate a "Statement of Applicability" report under "Risk Management → Reports → Standards and Norms".  


[[Datei:Standards und Normen Übersicht.png|left|thumb|902px| Standards and norms]]<br clear=all>
<span id="Standard_oder_Norm_importieren"></span>
 
== Import standard or norm ==
== Import standard or norm ==


HITGuard provides the following standards and norms as standard:
HITGuard provides the following standards and norms as standard:
* B3S Gesundheit V1.2
* BDSG
* CSC_V6.1
* DSG Österreich
* DSG Schweiz
* DSG-EKD
* DSGVO
* EN IEC 62443-2-1:2024
* ISO 9000-2015
* ISO 9001-2015
* ISO 14001-2015
* ISO 27001-2013
* ISO 27001-2013
* ISO 27001-2022
* ISO 27002-2013
* ISO 27002-2013
* ISO 9000-2015
* ISO 27002-2022
* ISO 9001-2015
* ISO 50001-2018
* IT-basic protection-Compendium 2019
* IT-Grundschutz-Kompendium 2019
* IT-basic protectionz-Compendium 2020
* IT-Grundschutz-Kompendium 2020
* GDPR
* IT-Grundschutz-Kompendium 2021
* CSC_V6.1
* IT-Grundschutz-Kompendium 2022
* IT-Grundschutz-Kompendium 2023
* NIS-2 Richtlinie
* PCI DSS v3.2.1
* PCI DSS v4.0


But these are not installed automatically!
But these are not installed automatically!


Die gewünschten Standards oder Normen können allerdings ganz einfach unter "Administration → Standards und Normen" importiert werden. Dafür muss nur auf den "Standard importieren"-Button geklickt werden und der gewünschte Standard bzw. Norm ausgewählt werden.
However, the desired standards or norms can be easily imported under "Administration → Standards and norms". To do this, simply click on the "Import standard" button and select the desired standard or norm.
 
<span id="Standard_oder_Norm_erfassen"></span>
== Record standard or norm ==
 
Standards and norms can be entered and edited by experts under "Administration → Standards and norms". The goal when entering a standard or norm is to capture the structure of the standard without content.
 
[[Datei:Norm erstellen.png|left|thumb|901px|Record standard/norm]]<br clear=all>
 
=== Standard/Norm ===
 
The header data of the standard or norm is recorded here.
 
<u>Short name:</u> The short name of the standard or standard e.g. ISO/IEC 27001:2017.
 
<u>Long name:</u> The long name of the standard or standard e.g. Information technology - Security techniques - Information security management systems - Requirements.


== Standard oder Norm erfassen ==
<u>Description:</u> Description of the standard.


Standards und Normen können von Administratoren und Experten unter "Administration → Standards und Normen" erfasst und bearbeitet werden. Das Ziel beim Erfassen einer Norm oder eines Standards ist es, die Struktur der Norm ohne Inhalt zu erfassen.
<u>State:</u> Effective date of the standard.


[[Datei:Norm erstellen.png|left|thumb|900px| Standard / Norm erfassen]]<br clear=all>
<u>Scope definition:</u> A "Scope definition" can be entered here for the current management system. This is configurable per management system.


=== Standard / Norm ===
<span id="Kapitel"></span>
=== Chapter ===


Hier werden die Kopfdaten der Norm oder des Standards erfasst.
The chapter structure of the standard is recorded here. On the left side, the structure is displayed hierarchically. The plus button is used to create new chapters. On the right side you enter the header data, parent chapters and outgoing mappings.


<u>Kurzbezeichnung:</u>
<u>Superordinate chapter:</u> If it is a subchapter, the parent chapter must be specified here. Hereby the structure of the standard is reproduced.
* Die Kurzbezeichnung der Norm oder des Standards z.B. ISO/IEC 27001:2017.


<u>Langbezeichnung:</u>
<u>Outline:</u> Here, an outline for the chapters is assigned. The outline normally corresponds to that of the standard e.g. 01 Ch. I, 02 Ch. II, etc.
* Die Langbezeichnung der Norm oder des Standards z.B. Information technology - Security techniques - Information security management systems - Requirements.


<u>Beschreibung:</u>
<u>Short name:</u> The name of the chapter according to the norm or standard.
* Beschreibung der Norm.


<u>Stand:</u>
<u>Description:</u> The description of the chapter according to the standard.
* Stand der Norm.


<u>Definition des Geltungsbereichs:</u>
<u>Not applicable:</u> Here you can enter whether a chapter is applicable for the current management system or not. (Configurable per management system). Please also note the behavior regarding the parent chapters. If a superordinate chapter is set to "not applicable", then the system takes over this setting automatically also for the subchapters assigned to this chapter. In addition, a question appears asking whether the justification text should also be adopted. If a parent chapter is changed to "applicable", then this does NOT automatically overwrite the settings of the assigned subchapters. Here you have to check yourself whether each of the subchapters is actually applicable.
* Hier kann für das aktuelle Managementsystem eine "Definition des Geltungsbereichs" erfasst werden. Diese ist pro Managementsystem konfigurierbar.


=== Kapitel ===
<u>Rationale:</u> A rationale for applicability can be recorded here. (Configurable per management system)


Hier wird die Kapitelstruktur der Norm erfasst. Auf der linken Seite wird die Struktur hierarchisch angezeigt. Über den Plus-Button werden neue Kapitel erstellt. Auf der rechten Seite geben Sie die Kopfdaten, übergeordnete Kapitel und ausgehende Mappings an.
<u>Incoming Mappings:</u> Any standard or norm chapters that map to this chapter are listed here.<br> ::<b>Caution:</b> Only mappings from other standards/norms are shown here. All other incoming mappings such as from a measure, risk or knowledge base are <b>not</b> displayed here.


<u>Übergeordnetes Kapitel:</u>
<u>Outgoing Mappings:</u> Here the norm/standard chapter can be mapped to a chapter of other norms/standards. It can <b>only</b> be mapped to other norm or standard chapters.</p>For both incoming and outgoing mappings in addition to the numbering and name of the chapter, the name of the standard itself is also displayed.
* Handelt es sich um ein Unterkapitel, muss hier das übergeordnete Kapitel angegeben werden. Hiermit wird die Struktur der Norm nachgebaut.


<u>Gliederung:</u>
==Linked elements==
* Hier wird eine Gliederung für die Kapitel vergeben. Die Gliederung entspricht im Normalfall der der Norm z.B. 01 Kap. I, 02 Kap II,etc.
The links of the chapters of individual standards and norms can be viewed on this page.</p>Every chapter level shows the number of its links as well as the links of subordinate chapter levels in the column "#". Expanding the levels shows the individual linked elements in the following column.</p>Available links:
:*risks (red)
:*measures (green)
:*control definitions (purple)
:*documents (blue)</p>
Moving the cursor onto one of the elements reveals a tooltip showing some of the its content. Every element also has a link button for opening it. You can either open the documents directly or, if the license is there, view it in the doc management. Links can be viewed but not edited on this page.</p>The checkbox "Include mapped standard chapters allows you to expand the list of linked elements. It adds those elements that are linked to related standard or norm chapters.</p>The documents displayed here are the ones that have been uploaded via [[Special:MyLanguage/Dokumentenmanagement|Doc management → Documents]].
[[Datei:StaNo_LinkedElements.png|left|thumb|900px|Verknüpfte Elemente]]<br clear=all>


<u>Kurzbezeichnung:</u>
<span id="Norm-Mapping_herstellen"></span>
* Die Bezeichnung des Kapitels laut Norm oder Standard.
== Creating a norm mapping ==


<u>Beschreibung:</u>
To create a standard mapping, you must do so within the respective element. For example, if you want to link a risk to a chapter in the standard, you must do so within the risk. In the respective element, locate the “'''Standard Mapping'''” option and click on it to open the dialog box.
* Die Beschreibung des Kapitels laut Norm.


<u>Nicht anwendbar:</u>
[[Datei:SNDialog.png|right|thumb|500px|Standard mapping dialog box. The blue badge shows the number of selected subchapters]] The dialog is divided into two sections: a default selection on the left and the chapter structure of the selected standard on the right.
* Hier kann erfasst werden ob ein Kapitel für das aktuelle Managementsystem anwendbar ist oder nicht. (Konfigurierbar pro Managementsystem)


<u>Begründung:</u>
The left pane displays all standards enabled for the current [[Special:MyLanguage/Managementsysteme|management system]]: Each standard is shown as a separate entry. Clicking on a standard updates the chapter view on the right. If chapters are selected for a standard, the number of selected chapters is displayed in a blue badge.
* Hier kann eine Begründung für die Anwendbarkeit erfasst werden. (Konfigurierbar pro Managementsystem)
The right-hand pane shows the chapter structure of the currently selected standard. You can select or deselect chapters by checking the boxes. The number of selected chapters for the currently displayed standard is shown in the lower right corner.


<u>Eingehende Mappings:</u>
The search function works across standards.
* Hier werden alle Normen oder Standard-Kapitel angeführt, die auf dieses Kapitel mappen.
* The search covers all available standards and their chapters.
* Standards with no results are hidden.
* Results remain visible within the respective chapter structure.
* The search field includes a button to clear the search term.


<u>Eingehende Mappings:</u>
==Tips, tricks & best practice==
* Hier kann das Norm/Standard Kapitel auf ein Norm/Standard Kapitel anderer Normen/Standards gemappt werden.
[[Datei:BESTPRACTICE.png|left|thumb|100px]]
You can reference further norms: for example, when updating a standard you should map from the current to the previous version. This enables an overview of the norm chapters already treated and any gaps created by new requirements before the first analysis with the new norm or standard is done. Those gaps can then be addressed first.<br clear=all>

Aktuelle Version vom 15. Juli 2026, 11:14 Uhr

Datei:Standards and Norms Overview.png
Standards and Norms

HITGuard is designed to help you demonstrate your compliance with various standards and norms (e.g., ISO 27001, EU GDPR, ISO 9001, etc.). That is why standards and norms are provided as an evaluation tool. The standards and norms in HITGuard are simply tables of contents and are linked to other elements (e.g., knowledge bases, measures, risks, etc.) via standard mapping. You can then use these mappings later, for example, with the KPI Compliance Achievement.

Standards and norms are divided into chapters, which in turn may contain sub-chapters. These chapters (or sub-chapters) can reference other chapters (and sub-chapters), and in principle a reference is unidirectional (bidirectional references can be created). Similarly, chapters can reference chapters and sub-chapters of other standards. This makes it possible to derive one standard from another. Furthermore, this means that, for example, a test question that references such a standard chapter is automatically also related to the chapter of another standard.

You can map knowledge bases, risks, review questions, controls, or measures to standards and regulations. We explain how to set up this standard mapping later in the chapter “Setting Up Standard Mapping.” This mapping enables specific analyses later on, such as which measures and controls address which chapters of the standard. This reveals which areas of the standard are the focus of a particularly high number of activities carried out by an organization. As a result, conclusions can be drawn about the degree of compliance with the standard and the management system’s score in this area.

The norms and standards provided by TogetherSecure cannot be modified by users. Referencing of these "vendor chapters" of specially created norms and standards is allowed.

However, a "definition of the scope" for each management system can be recorded for each standard or norm. In the course of this, it can be additionally selected for each standard chapter justified whether it is applicable for the current management system or not. This information can be used to generate a "Statement of Applicability" report under "Risk Management → Reports → Standards and Norms".

Import standard or norm

HITGuard provides the following standards and norms as standard:

  • B3S Gesundheit V1.2
  • BDSG
  • CSC_V6.1
  • DSG Österreich
  • DSG Schweiz
  • DSG-EKD
  • DSGVO
  • EN IEC 62443-2-1:2024
  • ISO 9000-2015
  • ISO 9001-2015
  • ISO 14001-2015
  • ISO 27001-2013
  • ISO 27001-2022
  • ISO 27002-2013
  • ISO 27002-2022
  • ISO 50001-2018
  • IT-Grundschutz-Kompendium 2019
  • IT-Grundschutz-Kompendium 2020
  • IT-Grundschutz-Kompendium 2021
  • IT-Grundschutz-Kompendium 2022
  • IT-Grundschutz-Kompendium 2023
  • NIS-2 Richtlinie
  • PCI DSS v3.2.1
  • PCI DSS v4.0

But these are not installed automatically!

However, the desired standards or norms can be easily imported under "Administration → Standards and norms". To do this, simply click on the "Import standard" button and select the desired standard or norm.

Record standard or norm

Standards and norms can be entered and edited by experts under "Administration → Standards and norms". The goal when entering a standard or norm is to capture the structure of the standard without content.

Record standard/norm


Standard/Norm

The header data of the standard or norm is recorded here.

Short name: The short name of the standard or standard e.g. ISO/IEC 27001:2017.

Long name: The long name of the standard or standard e.g. Information technology - Security techniques - Information security management systems - Requirements.

Description: Description of the standard.

State: Effective date of the standard.

Scope definition: A "Scope definition" can be entered here for the current management system. This is configurable per management system.

Chapter

The chapter structure of the standard is recorded here. On the left side, the structure is displayed hierarchically. The plus button is used to create new chapters. On the right side you enter the header data, parent chapters and outgoing mappings.

Superordinate chapter: If it is a subchapter, the parent chapter must be specified here. Hereby the structure of the standard is reproduced.

Outline: Here, an outline for the chapters is assigned. The outline normally corresponds to that of the standard e.g. 01 Ch. I, 02 Ch. II, etc.

Short name: The name of the chapter according to the norm or standard.

Description: The description of the chapter according to the standard.

Not applicable: Here you can enter whether a chapter is applicable for the current management system or not. (Configurable per management system). Please also note the behavior regarding the parent chapters. If a superordinate chapter is set to "not applicable", then the system takes over this setting automatically also for the subchapters assigned to this chapter. In addition, a question appears asking whether the justification text should also be adopted. If a parent chapter is changed to "applicable", then this does NOT automatically overwrite the settings of the assigned subchapters. Here you have to check yourself whether each of the subchapters is actually applicable.

Rationale: A rationale for applicability can be recorded here. (Configurable per management system)

Incoming Mappings: Any standard or norm chapters that map to this chapter are listed here.
 ::Caution: Only mappings from other standards/norms are shown here. All other incoming mappings such as from a measure, risk or knowledge base are not displayed here.

Outgoing Mappings: Here the norm/standard chapter can be mapped to a chapter of other norms/standards. It can only be mapped to other norm or standard chapters.

For both incoming and outgoing mappings in addition to the numbering and name of the chapter, the name of the standard itself is also displayed.

Linked elements

The links of the chapters of individual standards and norms can be viewed on this page.

Every chapter level shows the number of its links as well as the links of subordinate chapter levels in the column "#". Expanding the levels shows the individual linked elements in the following column.

Available links:

  • risks (red)
  • measures (green)
  • control definitions (purple)
  • documents (blue)

Moving the cursor onto one of the elements reveals a tooltip showing some of the its content. Every element also has a link button for opening it. You can either open the documents directly or, if the license is there, view it in the doc management. Links can be viewed but not edited on this page.

The checkbox "Include mapped standard chapters allows you to expand the list of linked elements. It adds those elements that are linked to related standard or norm chapters.

The documents displayed here are the ones that have been uploaded via Doc management → Documents.

Verknüpfte Elemente


Creating a norm mapping

To create a standard mapping, you must do so within the respective element. For example, if you want to link a risk to a chapter in the standard, you must do so within the risk. In the respective element, locate the “Standard Mapping” option and click on it to open the dialog box.

Standard mapping dialog box. The blue badge shows the number of selected subchapters

The dialog is divided into two sections: a default selection on the left and the chapter structure of the selected standard on the right.

The left pane displays all standards enabled for the current management system: Each standard is shown as a separate entry. Clicking on a standard updates the chapter view on the right. If chapters are selected for a standard, the number of selected chapters is displayed in a blue badge.

The right-hand pane shows the chapter structure of the currently selected standard. You can select or deselect chapters by checking the boxes. The number of selected chapters for the currently displayed standard is shown in the lower right corner.

The search function works across standards.

  • The search covers all available standards and their chapters.
  • Standards with no results are hidden.
  • Results remain visible within the respective chapter structure.
  • The search field includes a button to clear the search term.

Tips, tricks & best practice

You can reference further norms: for example, when updating a standard you should map from the current to the previous version. This enables an overview of the norm chapters already treated and any gaps created by new requirements before the first analysis with the new norm or standard is done. Those gaps can then be addressed first.