Menü aufrufen
Toggle preferences menu
Persönliches Menü aufrufen
Nicht angemeldet
Ihre IP-Adresse wird öffentlich sichtbar sein, wenn Sie Änderungen vornehmen.

FAQ/en: Unterschied zwischen den Versionen

Aus HITGuard User Guide
Sala (Diskussion | Beiträge)
Die Seite wurde neu angelegt: „ FAQ“
 
Isan (Diskussion | Beiträge)
Die Seite wurde neu angelegt: „====What e-mail settings are there?==== You can find an overview of the various e-mail settings here.“
 
(28 dazwischenliegende Versionen von 3 Benutzern werden nicht angezeigt)
Zeile 1: Zeile 1:


== Allgemein ==
== General ==
==== Obwohl ich Experte bin, werden mir nur die Menüpunkte ''Meine Aufgaben'' und ''Administration'' angezeigt ====
====How can I edit my profile?====
Sie müssen Teammitglied oder Verantwortlicher eines Managementsystems sein, um die Menüpunkte ''Risikomanagement'', ''Maßnahmen'', ''Kontrollen'' oder ''Datenschutz'' angezeigt zu bekommen. Kontaktieren Sie den Verantwortlichen des betreffenden Managementsystems, damit Sie dieser in sein Team aufnimmt. Mehr hierzu unter [[Special:MyLanguage/Managementsysteme| "Administration → Managementsysteme"]]. Sie können dort bei Bedarf auch ein neues Managementsystem für sich erstellen.
Users can navigate to their profile by clicking on their profile picture as well as by clicking on their name (or the little arrow below) and then on "Profile". Find more onm your profile [[Special:MyLanguage/Profil|here]].
==== Although I am an expert, only the menu items ''My tasks'' and ''Administration'' are displayed to me ====
You must be a team member or responsible of a management system to get the menu items ''Risk Management'', ''Measures'', ''Controls'' or ''Data Protection'' displayed. Contact the person responsible for the management system in question so that they can add you to their team. For more information, see [[Special:MyLanguage/Management Systems| "Administration → Management systems"]]. If necessary, you can also create a new management system for yourself there.


== Meine Aufgaben ==
====I only see an empty page when I log in====
==== Warum erscheint unter Meine Aufgaben eine orange unterlegte Zahl neben meinen Kontrollen, Maßnahmen etc.? ====
There are two possibilities as for why a page can look empty. You may either be seeing the text "You do not have user permissions for the modules of HITGuard. Contact your administrator or your organization's service manager." Then you would have user credentials but your user rights were revoked. In this case, you should get in touch with your organization's service owner for HITGuard.<p>
* Dies kann mehrere Bedeutungen haben:
Or you see the text "Now, add KPIs." That means you are currently on a newly created dashboard that has not yet had KPIs added to it. You can add KPIs yourself or do this together with your team.
:# Diese Kontrollen sind von Ihnen durchzuführen.
:# Diese Kontrollen sind von Ihnen zu prüfen. In diesem Fall wird noch ein zusätzlicher Kennzeichner angezeigt.
:# Diese Maßnahmen sind überfällig, das heißt, die Maßnahmen haben ihr Plandatum überschritten. Dieser Fall wird ebenfalls durch einen zusätzlichen Kennzeichner angezeigt.
: Bei Kontrollen können zusätzlich die Spalten "Von mir durchzuführen" und "Von mir zu prüfen" als Option eingeblendet werden.


== Risikomanagement ==
====How can I change my password?====
==== Warum sehen Kollegen aus den anderen Managementsystemen meine Gefährdungslagen? ====
When using local login, you need a username and password. You can change your password in your profile. For this, either click on your profile picture or on the small arrow beneath your name and "Profile". On the new page, you have a "Change password" button. Find more on your profile options [[Special:MyLanguage/Profil|here]].<p>If you are using local login and have forgotten your password, you can have it reset by an expert or administrator.
* Wollen Sie die Gefährdungslage vor den anderen Managementsystemen verbergen, dann müssen sie diese als „Privat“ kennzeichnen. Dazu setzen Sie in der Gefährdungslage rechts oben bei "Privat" ein Häkchen. Mehr Informationen zu Gefährdungslagen finden Sie unter [[Special:MyLanguage/Risikobewertung| "Risikomanagement → Risikobewertung"]].


==== Ich komme bei der Abweichungsanalyse nicht weiter als zu Schritt 2 ====
====What e-mail settings are there?====
* Haben Sie daran gedacht ein Prüfobjekt zu erstellen?
You can find an overview of the various e-mail settings [[Special:MyLanguage/Wie_aktiviere_ich_die_diversen_Mailings,_wenn_ich_mit_meinen_Einstiegstests_fertig_bin%3F|here]].
:: Um in Schritt 3 Prüffragen beantworten zu können, muss zuerst ein Prüfobjekt erstellt bzw. ausgewählt werden. Für eine Erstbewertung mittels Wissensdatenbank, muss dafür über das Dropdown eine Wissensdatenbank ausgewählt werden. Von dieser Wissensdatenbank können anschließend Prüfobjekte erzeugt werden. Dazu klicken Sie auf das "grüne Plus" jener Kapitel, die Sie beantworten möchten. Mehr dazu unter [[Special:MyLanguage/Überprüfung#Erstbewertung_mittels_Wissensdatenbank_.28Nur_bei_Abweichungsanalysen.29| "Erstbewertung mittels Wissensdatenbank"]]


* Können Sie kein Prüfobjekt zum ausgewähltem Thema erstellen bzw. wird kein grünes Plus angezeigt?
====How can I select multiple elements in a list at once?====
:: Das Plus zum Erstellen eines Prüfobjektes wird nur zu Themen angezeigt, die Prüffragen enthalten. Wird keines angezeigt, dann dient dieses Thema lediglich der Strukturierung. Sie können diese Themen durch Klicken auf den (davor befindlichen) Pfeil aufklappen und sich so die untergeordneten Themen anzeigen lassen. Mehr dazu unter [[Special:MyLanguage/Überprüfung#Erstbewertung_mittels_Wissensdatenbank_.28Nur_bei_Abweichungsanalysen.29| "Erstbewertung mittels Wissensdatenbank"]]
If it is a list with a multiselect option, meaning there are little selection boxes on the left side for clicking, you can select multiple elements with Shift+click. First, click on an element and then click on another one with Shift - all elements between them are selected.


==== Wie führe ich eine Abweichungsanalyse durch bzw. Pflege ich ein Prüfergebnis ein? ====
== My Tasks ==
* Informationen über Überprüfungen (Abweichungsanalyse und Prüfergebnis) und wie diese durchzuführen sind, finden sie unter [[Special:MyLanguage/Überprüfung| "Risikomanagement → Schwachstellen"]].
==== Why does an orange number appear next to my controls, actions, etc. under My Tasks? ====
* This can have several meanings:
:# These controls are to be performed by you.
:# These controls are to be checked by you. In this case, an additional indicator is also displayed.
:# These measures are overdue, that is, the measures have exceeded their planned date. This case is also indicated by an additional flag.
For controls, the columns "To be performed by me" and "To be checked by me" can be displayed as an additional option.


==== Ich habe ein Schutzziel erstellt, kann es aber nicht verwenden ====
== Risk management ==
* Haben Sie daran gedacht das Schutzziel für Ihr Managementsystem zu aktivieren?
==== Why do colleagues from the other management systems see my risks? ====
:: Sie bekommen in einem Managementsystem nur die Schutzziele angeboten, die auch für das Managementsystem aktiviert sind. Diese Aktivierung kann <b>nur</b> der Verantwortliche des Managementsystem durchführen. Dafür muss dieser unter [[Special:MyLanguage/Managementsysteme| "Administration Managementsysteme"]] das gewünschte Schutzziel aktivieren. Erst wenn dies erledigt ist, können Sie das Schutzziel verwenden.
* If you want to hide the exposure from the other management systems, you must mark it as "Private". To do this, place a check mark next to "Private" in the top right-hand corner of the risk. For more information on risks, see [[Special:MyLanguage/Risk Assessment| "Risk Management Risk Assessment"]].


==== Ich habe eine zweite Schadensausmaßklassifikation in der Risikopolitik eingepflegt – warum schlägt es mir die neue Klassifikation nicht vor? ====
==== I can't get any further than step 2 in the gap analysis ====
* Haben Sie daran gedacht diese Klassifikation im Managementsystem auszuwählen?
* Did you remember to create a review object?
:: Ein Managementsystem kann nur eine Schadensnausmaßklassifikation haben. Haben Sie eine neue Klassifikation erstellt und wollen diese verwenden, so muss diese auch unter [[Special:MyLanguage/Managementsysteme| "Administration → Managementsysteme"]] im Punkt "Allgemeine Einstellungen" für das gewünschte Managementsystem ausgewählt werden. Dies kann nur vom Verantwortlichen des Managementsystems gemacht werden!
:: In order to be able to answer review questions in step 3, a review object must first be created or selected. For an initial assessment using a knowledge base, a knowledge base must be selected for this via the dropdown. Review objects can then be created from this knowledge base. To do this, click on the "plus" buttons of those chapters that you want to answer. For more information, see [[Special:MyLanguage/verification#Initial_assessment_using_knowledge_base_.28Only_for_deviation_analyses.29| "Initial assessment using knowledge base"]].


==== Warum sehe ich in der Strukturanalyse nicht immer alle Ressourcen, wenn ich unterschiedliche Sichten kombiniere? ====
* Can't create a review object for the selected topic or no plus is displayed?
* Haben Sie alle Ebenen der Ressourcensicht ausgewählt?
:: The plus for creating a review object is only displayed for topics that contain review questions. If none is displayed, then this topic is only used for structuring. You can expand these topics by clicking on the arrow (to the left of it) to display the subordinate topics. For more information, see [[Special:MyLanguage/verification#Initial_assessment_using_knowledge_base_.28Only_for_deviation_analyses.29| "Initial assessment using knowledge base"]].
:: Ist eine andere Sicht als die Ressourcensicht die Hauptsicht, so werden von den Ressourcen standardmäßig nur jene angezeigt, die sich auf der "Anwendungsebene" befinden. Um auch die anderen Ebenen zu sehen, klappen Sie die Ressourcensicht auf und selektieren die gewünschten Ebenen. Danach klicken Sie auf "Anwenden". Mehr Informationen zur Strukturanalyse finden Sie unter [[Special:MyLanguage/Strukturanalyse | "Risikomanagement → Strukturanalyse"]].


== Maßnahmen und Kontrollen ==
==== How do I perform a gap analysis or maintain a review result? ====
==== Warum kann ich meine Maßnahmen und Kontrollen nicht zu einer neu angelegten Organisationseinheit zuweisen? ====
* For information on reviews (gap analysis and review result) and how to perform them, see [[Special:MyLanguage/Review| "Risk management Vulnerabilities"]].
* Haben Sie daran gedacht die Organisationseinheit für Ihr Managementsystem zu aktivieren?
:: Um eine Organisationseinheit für ein Managementsystem verwenden zu können, muss sie dem aktiven Analysezeitraum zugewiesen sein. Diese Zuweisung führt der Verantwortliche des Managementsystems durch. Dieser kann unter [[Special:MyLanguage/Managementsysteme| "Administration Managementsysteme"]] im Tab "Aktiver Analysezeitraum" für den aktiven Analysezeitraum die Organisationseinheiten verwalten.


== Datenschutz ==
==== I have created a protection goal but cannot use it ====
==== Ich bin im Datenschutz-Managementsystem, sehe aber den Menüpunkt Datenschutz nicht ====
* Did you remember to activate the protection goal for your management system?
* Haben Sie sichergestellt, dass Sie für Datenschutz zumindest das Recht "Professional" haben?
:: You will only be offered the protection goals in a management system that are also activated for the management system. This activation can <b>only</b> be performed by the person responsible for the management system. To do this, he must activate the desired protection target under [[Special:MyLanguage/Management Systems| "Administration → Management systems"]]. Only when this has been done can you use the protection target.
:: Experten können dies unter [[Special:MyLanguage/Benutzer_und_Benutzerrollen#Benutzerrollen_zuordnen| "Administration → Benutzerrollen-Zuordnung"]] verwalten.


* Haben Sie sichergestellt, dass das Managementsystem auch als Datenschutz-Managementsystem eingetragen ist?
==== I have added a second extent of loss classification to the risk policy - why is it not suggesting the new classification to me? ====
:: Experten können dies unter [[Special:MyLanguage/Managementsysteme| "Administration → Managementsysteme"]] verwalten.
* Did you remember to select this classification in the management system?
:: A management system can have only one damage extent classification. If you have created a new classification and want to use it, it must also be selected under [[Special:MyLanguage/Management Systems| "Administration → Management systems"]] in the "General Settings" item for the desired management system. This can only be done by the person responsible for the management system!


==== Ich bin im Datenschutz Managementsystem, sehe aber den Menüpunkt Betroffenenkategorien nicht ====
==== Why do I not always see all resources in the structure analysis when I combine different views? ====
* Um diesen Menüpunkt zu sehen, benötigen Sie Experten-Rechte.
* Have you selected all levels of the resource view?
:: Experten können dies unter [[Special:MyLanguage/Benutzer_und_Benutzerrollen#Benutzerrollen_zuordnen| "Administration Benutzerrollen-Zuordnung"]] verwalten.
:: If a view other than the resource view is the main view, only those resources that are on the "application level" are displayed by default. To see the other layers as well, expand the resource view and select the desired layers. Then click on "Apply". For more information on structure analysis, see [[Special:MyLanguage/Structure Analysis | "Risk management Structural analysis"]].


==== Wie kann ich die Berechtigung von Professionals im Verarbeitungsregister auf einzelne Organisationen erweitern? ====
== Measures and controls ==
* Haben Sie für die Organisation ein Organisationsregister erstellt und den gewünschten Professional als den Verantwortlichen eingetragen?
==== Why can't I assign my measures and controls to a newly created organizational unit? ====
:: Professionals sehen grundsätzlich nur die Verarbeitungstätigkeiten, für die sie auch verantwortlich sind. Damit ein Professional alle Verarbeitungen einer Organisation sehen kann, muss er für das Organisationsregister der Organisation verantwortlich sein. Pro Organisationsregister kann immer nur eine Person oder ein Team Verantwortlich sein. Das heißt: Wollen Sie mehrere Personen für ein Organisationsregister verantwortlich machen, müssen Sie diese zuerst einem Team zuweisen und im Anschluss das Team als Verantwortlichen des Organisationsregisters eintragen. Mehr dazu finden Sie unter [[Special:MyLanguage/Verarbeitungsregister| "Datenschutz Verarbeitungsregister"]].
* Did you remember to activate the organizational unit for your management system?
:: In order to use an organizational unit for a management system, it must be assigned to the active analysis period. This assignment is done by the person responsible for the management system. This person can manage the organizational units under [[Special:MyLanguage/Management Systems| "Administration → Management systems"]] in the "Active analysis period" tab for the active analysis period.
 
== Data protection ==
==== I am in the Privacy Management System, but I do not see the menu item Privacy ====
* Have you made sure that you have at least the "Professional" privilege for Privacy?
:: Experts can manage this under [[Special:MyLanguage/User_and_User_Roles#User_Roles_Assign| "Administration → User role assignment"]].
 
* Have you ensured that the management system is also registered as a data protection management system?
:: Experts can manage this under [[Special:MyLanguage/Management Systems| "Administration → Management systems"]].
 
==== I am in the Privacy Management System, but I don't see the Affected Categories menu item ====
* To see this menu item, you need expert rights.
:: Experts can manage this under [[Special:MyLanguage/User_and_User_Roles#User_Roles_Assign| "Administration → User role assignment"]].
 
==== How can I extend the authorization of professionals in the processing register to individual organizations? ====
* Have you created an organization register for the organization and entered the desired Professional as the controller?
:: Professionals generally only see the processing activities for which they are also responsible. In order for a Professional to see all processing activities of an organization, they must be responsible for the organization register of the organization. Only one person or team can be responsible for each organization register. This means: If you want to make more than one person responsible for an organization register, you must first assign them to a team and then enter the team as responsible for the organization register. For more information, see [[Special:MyLanguage/Processing Register| "Data Protection Processing register"]].
 
==Case management==
====I want to report something or ask a question, how can I reach my organization's whistleblower system?====
* You receive the link to the whistleblower system from your organization's HITGuard service manager. The default way to reach the whistleblower system for the anonymous reporting of incidents is to add the suffix <b>/cmwb</b> to your regular HITGuard URL. If your URL is ''examplecompany.hitguard.at'', then you can reach the whistleblower system under ''examplecompany.hitguard.at/cmwb''.
 
=Tips, Tricks & Best Practice=
*[[Special:MyLanguage/Schwachstellen#Tips,_Tricks_&_Best_Practice|Gap analysis]]
*[[Special:MyLanguage/Schwachstellen#Tips,_Tricks_&_Best_Practice_2|Review objects]]
*[[Special:MyLanguage/Schutzbedarf#Tips,_Tricks_&_Best_Practice|Protection need]]
*[[Special:MyLanguage/Standards_und_Normen#Tips%2C_Tricks_%26_Best_Practice|Standards & Norms]]
*[[Special:MyLanguage/Strukturanalyse#Tips,_Tricks_&_Best_Practice|Structural analysis]]
*[[Special:MyLanguage/Teams#Tips%2C_Tricks_%26_Best_Practice|Teams]]
*[[Special:MyLanguage/Wissensdatenbanken#Tips,_Tricks_&_Best_Practice|Knowledge bases]]

Aktuelle Version vom 10. Februar 2025, 10:56 Uhr

General

How can I edit my profile?

Users can navigate to their profile by clicking on their profile picture as well as by clicking on their name (or the little arrow below) and then on "Profile". Find more onm your profile here.

Although I am an expert, only the menu items My tasks and Administration are displayed to me

You must be a team member or responsible of a management system to get the menu items Risk Management, Measures, Controls or Data Protection displayed. Contact the person responsible for the management system in question so that they can add you to their team. For more information, see "Administration → Management systems". If necessary, you can also create a new management system for yourself there.

I only see an empty page when I log in

There are two possibilities as for why a page can look empty. You may either be seeing the text "You do not have user permissions for the modules of HITGuard. Contact your administrator or your organization's service manager." Then you would have user credentials but your user rights were revoked. In this case, you should get in touch with your organization's service owner for HITGuard.

Or you see the text "Now, add KPIs." That means you are currently on a newly created dashboard that has not yet had KPIs added to it. You can add KPIs yourself or do this together with your team.

How can I change my password?

When using local login, you need a username and password. You can change your password in your profile. For this, either click on your profile picture or on the small arrow beneath your name and "Profile". On the new page, you have a "Change password" button. Find more on your profile options here.

If you are using local login and have forgotten your password, you can have it reset by an expert or administrator.

What e-mail settings are there?

You can find an overview of the various e-mail settings here.

How can I select multiple elements in a list at once?

If it is a list with a multiselect option, meaning there are little selection boxes on the left side for clicking, you can select multiple elements with Shift+click. First, click on an element and then click on another one with Shift - all elements between them are selected.

My Tasks

Why does an orange number appear next to my controls, actions, etc. under My Tasks?

  • This can have several meanings:
  1. These controls are to be performed by you.
  2. These controls are to be checked by you. In this case, an additional indicator is also displayed.
  3. These measures are overdue, that is, the measures have exceeded their planned date. This case is also indicated by an additional flag.

For controls, the columns "To be performed by me" and "To be checked by me" can be displayed as an additional option.

Risk management

Why do colleagues from the other management systems see my risks?

  • If you want to hide the exposure from the other management systems, you must mark it as "Private". To do this, place a check mark next to "Private" in the top right-hand corner of the risk. For more information on risks, see "Risk Management → Risk Assessment".

I can't get any further than step 2 in the gap analysis

  • Did you remember to create a review object?
In order to be able to answer review questions in step 3, a review object must first be created or selected. For an initial assessment using a knowledge base, a knowledge base must be selected for this via the dropdown. Review objects can then be created from this knowledge base. To do this, click on the "plus" buttons of those chapters that you want to answer. For more information, see "Initial assessment using knowledge base".
  • Can't create a review object for the selected topic or no plus is displayed?
The plus for creating a review object is only displayed for topics that contain review questions. If none is displayed, then this topic is only used for structuring. You can expand these topics by clicking on the arrow (to the left of it) to display the subordinate topics. For more information, see "Initial assessment using knowledge base".

How do I perform a gap analysis or maintain a review result?

I have created a protection goal but cannot use it

  • Did you remember to activate the protection goal for your management system?
You will only be offered the protection goals in a management system that are also activated for the management system. This activation can only be performed by the person responsible for the management system. To do this, he must activate the desired protection target under "Administration → Management systems". Only when this has been done can you use the protection target.

I have added a second extent of loss classification to the risk policy - why is it not suggesting the new classification to me?

  • Did you remember to select this classification in the management system?
A management system can have only one damage extent classification. If you have created a new classification and want to use it, it must also be selected under "Administration → Management systems" in the "General Settings" item for the desired management system. This can only be done by the person responsible for the management system!

Why do I not always see all resources in the structure analysis when I combine different views?

  • Have you selected all levels of the resource view?
If a view other than the resource view is the main view, only those resources that are on the "application level" are displayed by default. To see the other layers as well, expand the resource view and select the desired layers. Then click on "Apply". For more information on structure analysis, see "Risk management → Structural analysis".

Measures and controls

Why can't I assign my measures and controls to a newly created organizational unit?

  • Did you remember to activate the organizational unit for your management system?
In order to use an organizational unit for a management system, it must be assigned to the active analysis period. This assignment is done by the person responsible for the management system. This person can manage the organizational units under "Administration → Management systems" in the "Active analysis period" tab for the active analysis period.

Data protection

I am in the Privacy Management System, but I do not see the menu item Privacy

  • Have you made sure that you have at least the "Professional" privilege for Privacy?
Experts can manage this under "Administration → User role assignment".
  • Have you ensured that the management system is also registered as a data protection management system?
Experts can manage this under "Administration → Management systems".

I am in the Privacy Management System, but I don't see the Affected Categories menu item

  • To see this menu item, you need expert rights.
Experts can manage this under "Administration → User role assignment".

How can I extend the authorization of professionals in the processing register to individual organizations?

  • Have you created an organization register for the organization and entered the desired Professional as the controller?
Professionals generally only see the processing activities for which they are also responsible. In order for a Professional to see all processing activities of an organization, they must be responsible for the organization register of the organization. Only one person or team can be responsible for each organization register. This means: If you want to make more than one person responsible for an organization register, you must first assign them to a team and then enter the team as responsible for the organization register. For more information, see "Data Protection → Processing register".

Case management

I want to report something or ask a question, how can I reach my organization's whistleblower system?

  • You receive the link to the whistleblower system from your organization's HITGuard service manager. The default way to reach the whistleblower system for the anonymous reporting of incidents is to add the suffix /cmwb to your regular HITGuard URL. If your URL is examplecompany.hitguard.at, then you can reach the whistleblower system under examplecompany.hitguard.at/cmwb.

Tips, Tricks & Best Practice

Inhaltsverzeichnis