Menü aufrufen
Toggle preferences menu
Persönliches Menü aufrufen
Nicht angemeldet
Ihre IP-Adresse wird öffentlich sichtbar sein, wenn Sie Änderungen vornehmen.

OrgEh - Organisationseinheiten/en: Unterschied zwischen den Versionen

Aus HITGuard User Guide
FuzzyBot (Diskussion | Beiträge)
Übernehme Bearbeitung einer neuen Version der Quellseite
FuzzyBot (Diskussion | Beiträge)
Übernehme Bearbeitung einer neuen Version der Quellseite
Markierungen: mobile web edit mobile edit
Zeile 12: Zeile 12:
== <span id="orgcre"></span>Create/edit/delete organizational unit==
== <span id="orgcre"></span>Create/edit/delete organizational unit==


<div class="mw-translate-fuzzy">
OrgUnits can be created or edited by administrators and experts via "Administration → OrgUnits".
OrgUnits can be created or edited by administrators and experts via "Administration → OrgUnits".
</div>


[[Datei:Organisationsstruktur Maske.png|left|thumb|900px|Organizational structures mask]]<br clear=all>
[[Datei:Organisationsstruktur Maske.png|left|thumb|900px|Organizational structures mask]]<br clear=all>
Zeile 22: Zeile 20:
To edit an existing OrgUnit, double-click into the corresponding OrgUnit's row.
To edit an existing OrgUnit, double-click into the corresponding OrgUnit's row.


[[Datei:OrgEH bearbeiten.PNG|left|thumb|903px|Mask to edit/create an organizational unit]]<br clear=all>
[[Datei:OrgEH bearbeiten.PNG|left|thumb|900px|Create/edit organizational unit]]<br clear=all>


<b>Abbreviation and designation:</b><br>
<b>Code and name:</b><br>
* For the abbreviation, enter how the OrgUnit should be abbreviated.
* For the code, enter how the OrgUnit should be abbreviated.
* For the designation, enter the name of the OrgUnit.
* For the name, enter the name of the OrgUnit.


<b>Sort order:</b><br>.
<b>Sort order:</b> This defines how the OrgUnits are listed in linear lists (e.g. in a report).
* This defines how the OrgUnits are listed in linear lists (e.g. in a report).


<b>Superordinate OrgUn:</b><br>.
<b>Superordinate OrgUn:</b> Here, you state how the OrgUnit fits into the hierarchy. For example, which company a department belongs to.
* Here, you state how the OrgUnit fits into the hierarchy. For example, which company a department belongs to.


<b>Type:</b><br>
<b>Type:</b> Here, you specify what type of organizational unit it is: Group, Company, Department, Entity, Branch
* Here, you specify what type of organizational unit it is.
** Group
** Company
** Department
** Entity
** Branch


<b>Division:</b>
<b>Division:</b> Here, you define in which divisions the OrgUnit is active.
* Here, you define in which divisions the OrgUnit is active.


<b>Responsible:</b><br>
<b>Responsible:</b> The person entered here is responsible for the OrgUnit. For example, a department head.
* The person entered here is responsible for the OrgUnit. For example, a department head.


<b>Description:</b><br>
<b>Description:</b> Here, you describe the OrgUnit.
* Here, you describe the OrgUnit.


<b>Closed:</b><br>
<b>Closed:</b> If an OrgUnit is closed, it will only be displayed on this page. It can no longer be selected for new audits, reviews, processing activities and so on. Deactivating it has no effect on current assignments. Merely for reports, the OrgUnit can still be selected.
* If an OrgUnit is closed, it will only be displayed on this page. It can no longer be selected for new audits, reviews, processing activities and so on. Deactivating it has no effect on current assignments. Merely for reports, the OrgUnit can still be selected.


<b>Active from / to</b><br>.
<b>Active from/to</b> Here you define the time period in which the OrgUnit should be active in HITGuard. If the OrgUnit is no longer active, but not closed, it can still be selected anywhere, but is displayed in italics to signal that it is inactive.
* Here you define the time period in which the OrgUnit should be active in HITGuard. If the OrgUnit is no longer active, but not closed, it can still be selected anywhere, but is displayed in italics to signal that it is inactive.


<b>ID in third-party systems:</b><br>
<b>ID in third-party systems:</b> This field is used to synchronize an OrgUnit with a third-party system. Synchronization requires a data import, in which the same ID is set.
* This field is used to synchronize an OrgUnit with a third-party system. Synchronization requires a data import, in which the same ID is set.


'''Hazard situations:'''
'''Hazard situations:''' All hazard situations of the OrgUnit are listed here. It is not possible to assign hazard situations here. More about hazard situations can be found [[Special:MyLanguage/Risk Assessment|here]].  
: All hazard situations of the OrgUnit are listed here. It is not possible to assign hazard situations here. More about hazard situations can be found [[Special:MyLanguage/Risk Assessment|here]].  


<b>Address:</b><br>
<b>Address:</b> Here, you enter the address of the OrgUnit.
* Here, you enter the address of the OrgUnit.


'''Delete OrgUn:'''
'''Delete OrgUn:''' To delete an OrgUnit, click on the red trash can in the edit screen. In order for an OrgUnit to be deletable, nothing can be linked to it. This means that, for example, all assigned measures, control definitions and processing messages have to be linked to a different OrgUnit or be themselves deleted. The OrgUnit must also not be linked to any active analysis period.
* To delete an OrgUnit, click on the red trash can in the edit screen.
* In order for an OrgUnit to be deletable, nothing can be linked to it. This means that, for example, all assigned measures, control definitions and processing messages have to be linked to a different OrgUnit or be themselves deleted. The OrgUnit must also not be linked to any active analysis period.


<span id="Datenschutzmanagementsystem"></span>
<span id="Datenschutzmanagementsystem"></span>
Zeile 89: Zeile 69:
In the tab "Audit information", you record additional information relevant in the context of audits.
In the tab "Audit information", you record additional information relevant in the context of audits.


* Number of employees:
* Number of employees: The number of employees can be recorded here.
:: The number of employees can be recorded here.
* Local Management Representative: This is the audit coordinator and contact person that should be defined for every OrgUnit of the type company.
* Local Management Representative:
* "Proposal to audit this OrgUnit in each audit program": These OrgUnits are proposed when the corresponding filtering checkmark is set in the detailed planning in the audit calendar.
:: This is the audit coordinator and contact person that should be defined for every OrgUnit of the type company.
* Certifications: Here, any standards (from standards and norms) in which the organizational unit is certified can be selected and assigned. A reg. no. and a location number can then be entered for each of these standards.
* "Proposal to audit this OrgUnit in each audit program":
:: These OrgUnits are proposed when the corresponding filtering checkmark is set in the detailed planning in the audit calendar.
* Certifications:
:: Here, any standards (from standards and norms) in which the organizational unit is certified can be selected and assigned. A reg. no. and a location number can then be entered for each of these standards.


[[Datei:OrgEh Auditinformationen.png|left|thumb|901px| Audit information ]]
[[Datei:OrgEh Auditinformationen.png|left|thumb|901px| Audit information ]]

Version vom 7. März 2023, 14:37 Uhr

A company consists of organizational units that participate in the individual processing procedures. These, in turn, take place in one or several organizational units. The creation and processing of data taking place in these organizational units during the individual process steps is predominantly IT-supported and with the use of IT systems. The more vital the organizational unit, the greater the potential damage, and the greater the requirements for availability, confidentiality and integrity of the data or systems.

The structure of the organizational units should be hierarchical.

Important: To be able to use OrgUnits in a management system, they need to be activated for the active analysis period! When a new OrgUnit is created, it is automatically assigned to all active (current) analysis periods and thereby activated, if the OrgUnit has been subordinated to another one and this superordinate OrgUnit is already activated in the respective management system. If there is no parent OrgUnit, the newly created OrgUnit will not be automatically activated in all management systems. This needs to then be done manually. For more information, see "Administration → Management System → Analysis Periods".

Display from structural analysis from risk management


Create/edit/delete organizational unit

OrgUnits can be created or edited by administrators and experts via "Administration → OrgUnits".

Organizational structures mask


To create a new OrgUnit, click the "Plus" button.

To edit an existing OrgUnit, double-click into the corresponding OrgUnit's row.

Create/edit organizational unit


Code and name:

  • For the code, enter how the OrgUnit should be abbreviated.
  • For the name, enter the name of the OrgUnit.

Sort order: This defines how the OrgUnits are listed in linear lists (e.g. in a report).

Superordinate OrgUn: Here, you state how the OrgUnit fits into the hierarchy. For example, which company a department belongs to.

Type: Here, you specify what type of organizational unit it is: Group, Company, Department, Entity, Branch

Division: Here, you define in which divisions the OrgUnit is active.

Responsible: The person entered here is responsible for the OrgUnit. For example, a department head.

Description: Here, you describe the OrgUnit.

Closed: If an OrgUnit is closed, it will only be displayed on this page. It can no longer be selected for new audits, reviews, processing activities and so on. Deactivating it has no effect on current assignments. Merely for reports, the OrgUnit can still be selected.

Active from/to Here you define the time period in which the OrgUnit should be active in HITGuard. If the OrgUnit is no longer active, but not closed, it can still be selected anywhere, but is displayed in italics to signal that it is inactive.

ID in third-party systems: This field is used to synchronize an OrgUnit with a third-party system. Synchronization requires a data import, in which the same ID is set.

Hazard situations: All hazard situations of the OrgUnit are listed here. It is not possible to assign hazard situations here. More about hazard situations can be found here.

Address: Here, you enter the address of the OrgUnit.

Delete OrgUn: To delete an OrgUnit, click on the red trash can in the edit screen. In order for an OrgUnit to be deletable, nothing can be linked to it. This means that, for example, all assigned measures, control definitions and processing messages have to be linked to a different OrgUnit or be themselves deleted. The OrgUnit must also not be linked to any active analysis period.

Data protection management system

If the active management system is the data protection management system, it is possible to record the contact data of the data protection officer of the OrgUnit. These are required for evaluation in data protection management.

If no data protection officer is found during evaluations for an OrgUnit, the officer of the higher-level OrgUnit is used. This means that if there is only one officer in the organizational structure, this officer's information only needs to be entered in the top-level OrgUnit.

Data Protection Officer


Deviations/measures/controls

The behavior is the same as for resources. More about this here.

Audit information

In the tab "Audit information", you record additional information relevant in the context of audits.

  • Number of employees: The number of employees can be recorded here.
  • Local Management Representative: This is the audit coordinator and contact person that should be defined for every OrgUnit of the type company.
  • "Proposal to audit this OrgUnit in each audit program": These OrgUnits are proposed when the corresponding filtering checkmark is set in the detailed planning in the audit calendar.
  • Certifications: Here, any standards (from standards and norms) in which the organizational unit is certified can be selected and assigned. A reg. no. and a location number can then be entered for each of these standards.
Audit information


Divisions

OrgUnits can be assigned several divisions, depending on their field of activity.

Under "Administration → Edit organizational units | Divisions", these divisions can be managed.

Divisions


Create/edit division

A new division can be created by clicking the "Plus" button.

By double-clicking on a division, it can be edited.

Edit division