Workflowpläne/en: Unterschied zwischen den Versionen
Weitere Optionen
KoKl (Diskussion | Beiträge) Die Seite wurde neu angelegt: „<b>Name & Description:</b> * Enter the purpose of the workflow plan here so that you can understand its intention later on.“ |
KoKl (Diskussion | Beiträge) Die Seite wurde neu angelegt: „*In the workflow plan with risks and opportunities, you send the risk to the Advisor for reassessment. Unlike with the analyses, no separate reassessment is created here. Therefore, there are also no settings for taking over results. *In the second tab, "Risks and Opportunities", you can link the risks and opportunities whose reassessment the workflow plan is to initiate. After you have added a risk with the Link button, HITGuard will offer you a text fi…“ |
||
| Zeile 40: | Zeile 40: | ||
* Specify here when the workflow plan should be triggered next. At this point, the reassessments/risks are then sent to the interview partners/Advisors based on the linked elements. | * Specify here when the workflow plan should be triggered next. At this point, the reassessments/risks are then sent to the interview partners/Advisors based on the linked elements. | ||
<b>Recurring workflow:</b> | |||
<b> | * If the workflow plan should be triggered regularly, you can set this here. | ||
* | * After being triggered, HITGuard will renew the date and add the time span you have defined here to the old date. | ||
* | |||
< | <span id="Tab_2:_Elemente_hinzufügen"></span> | ||
==Tab 2: | ==Tab 2: Adding elements== | ||
[[Datei:SBA_WFP_Schutzbedarfsanalysen.png|right|thumb|600px|Protection needs analyses]][[Datei:WFPüberprüf.png|right|thumb|600px|Vulnerability/GAP analyses]][[Datei:WFPrisikenchancen.png|right|thumb|600px|Risks & Opportunities]]Depending on the variant, the second tab is called "Protection needs analyses", "Reviews" or "Risks & Opportunities". In the three screenshots on the right, you can see that the three pages are structured as a grid. In the following, we address the general basic functions that all workflow plans share. | |||
[[Datei:SBA_WFP_Schutzbedarfsanalysen.png|right|thumb|600px| | |||
<b>Link button</b> | |||
<b>Link | * To the right above the grid, you can attach the original elements that the workflow plan is to reassess.<p> | ||
* | <b>Grid overview of the element</b> | ||
<b>Grid | * Here you see the title of the element as well as some additional information that defines the analyses or risks in more detail. Using the column selection, you can also hide these properties. | ||
* | * The titles of the elements function as links. By clicking the blue text, you can jump directly into the analysis or the risk. | ||
* | * Note: Here you always see the latest version/reassessment of the analyses. If the workflow has just been triggered, the link no longer takes you to the original analysis, but to the reassessment that has already been created automatically.<p> | ||
* | <b>Warnings & conflicts</b> | ||
<b> | * In the grid, HITGuard points out possible conflicts of the workflow plans. The Conflicts column indicates the origin of the conflict. Details about the conflict can also be found in the tooltip when you hover the mouse over the triangle.<br> | ||
* | * <b>Yellow warning triangles</b>: If the risk or the analysis <i>itself</i> is not ready for a reassessment, this is shown with a yellow warning triangle. Usually this is because the vulnerability/GAP or protection needs analysis is not yet completed, or because the risk is already in the assessment workflow. Yellow warning triangles are also shown here when the workflow has just been triggered. | ||
* <b> | * <b>Red warning triangles</b>: If there is a conflict with <i>another element</i>, this is shown with a red warning triangle. The conflict can arise in the same or in another management system (e.g. [[Special:MyLanguage/Schutzbedarf#Schutzbedarfsanalysen_können_sich_gegenseitig_blockieren!|reassessments of protection needs analyses]] in another management system). <p> | ||
* <b> | <b>Status: Active/Paused</b> | ||
<b>Status: | * This status indicates whether the element will be triggered with the workflow plan. Active elements trigger on the date of the workflow plan, paused ones skip a cycle. You control the status with the Play/Pause button on the right side of the grid. In the second screenshot you see a paused review.<p> | ||
* | <b>Play/Pause button</b> | ||
<b>Play/Pause | * With this button you control the Active/Paused status of the individual element.<p> | ||
* | <b>Unlink button</b> | ||
<b> | *This permanently removes the review from the workflow plan. <p> | ||
* | <b>Reassess button</b> | ||
<b> | * With this button you can manually bypass the workflow plan and create a reassessment manually. For example, you can pause a protection needs analysis and then carry out a reassessment manually. HITGuard will track this, so your manual reassessment will later be visible here in the overview. If you complete the manual reassessment in good time, HITGuard can use it as a template for the next cycle.<p> | ||
* | |||
==Tab 3: Executed workflows== | |||
==Tab 3: | [[Datei:WFPtab3.png|right|thumb|600px]]This page offers you an overview of the historical cycles of the workflow plan. For protection needs and vulnerability/GAP analyses, you can trace the reassessments and the preceding analyses that served as a template. | ||
[[Datei:WFPtab3.png|right|thumb|600px]] | |||
<br clear="all"> | <br clear="all"> | ||
< | <span id="Workflowpläne_für_Schutzbedarfsanalysen_&_Schwachstellenanalysen"></span> | ||
= | =Workflow plans for protection needs analyses & vulnerability/GAP analyses= | ||
Workflow plans for analyses work with reassessments. When the workflow plan is triggered, a new protection needs or vulnerability/GAP analysis is created that is based on the template of the old one. The original analysis remains untouched and write-protected in the system. You can find out more about reassessments on the detail pages of the [[Special:MyLanguage/Schutzbedarf|protection needs analysis]] and [[Special:MyLanguage/Schwachstellen|vulnerability/GAP analysis]]. <br> The workflow plans for the two analyses differ above all in how they take over the results of the preceding analysis. When you attach an analysis to the workflow plan, HITGuard will ask for this setting right away. You can also view and edit it afterwards in the grid.<p> | |||
:<b>Taking over results for protection needs analyses</b><br> | |||
:<b> | For the protection needs analysis there is only a simple checkbox. When it is activated, HITGuard copies all values from the old into the new protection needs analysis. These are the impact-severity ratings of the [[Special:MyLanguage/Risikopolitik#Schutzziele|protection objectives]] that were recorded between the organizational unit or the process and the linked resources and data categories. You can change this checkbox directly in the overview of the linked protection needs analyses. <p> | ||
:<b>Taking over results for vulnerability/GAP analyses</b> | |||
:<b> | [[Datei:Workflow_AA_ErgebnisseÜbernehmen.png|right|thumb|400px]]For the vulnerability/GAP analysis, the taking over of results comes with more options: | ||
[[Datei:Workflow_AA_ErgebnisseÜbernehmen.png|right|thumb|400px]] | *<b>Current knowledge base:</b> [[Special:MyLanguage/Wissensdatenbanken|Knowledge bases]] serve as a template for the question sets in vulnerability/GAP analyses. Sometimes the template has evolved further after the original review was created. With this checkbox you determine whether, during the reassessment, HITGuard should use the <i>old version</i> of the template, or whether it should use the <i>latest version</i> of the knowledge base. | ||
*<b> | *<b>Answer carry-over:</b> Here you can decide whether HITGuard should take over all answers, no answers or only positive answers from the last review in the reassessment. This controls how thoroughly the Advisor has to work through the reassessment. | ||
*<b> | *<b>Justification carry-over:</b>Regardless of whether you take over answers or not, you can take over the respective justification texts from the original review. Alternatively, you can enter a default text that HITGuard will place in every justification field. | ||
*<b> | *You can also change all these settings later by clicking "Edit". | ||
* | |||
< | <span id="Workflowpläne_für_Risiken/Chancen"></span> | ||
= | =Workflow plans for risks/opportunities= | ||
*In the workflow plan with risks and opportunities, you send the risk to the Advisor for reassessment. Unlike with the analyses, no separate reassessment is created here. Therefore, there are also no settings for taking over results. | |||
* | *In the second tab, "Risks and Opportunities", you can link the risks and opportunities whose reassessment the workflow plan is to initiate. After you have added a risk with the Link button, HITGuard will offer you a text field with which you can compose a message to the Advisor. You can also change this afterwards in the grid. | ||
* | *You can find out more about the risk assessment workflow [[Special:MyLanguage/Risikobewertung#Workflow_zur_Risikobewertung|here]]. | ||
* | |||
=Workflow plan FAQs= | |||
<b>What happens when the workflow plan is executed?</b><br> | |||
<b> | When the workflow plan is executed, reassessments are created for the linked protection needs analyses and the respective interview partners are requested to respond. A reassessment assesses the same resources and data categories for the same organizational unit or the same process as the original protection needs analysis.<p> | ||
<b>When is no reassessment requested?</b><br> | |||
<b> | No reassessment is created and requested if one of the following conditions applies: | ||
*The reassessment of the protection needs analysis is paused. | |||
* | *The protection needs analysis is not completed. | ||
* | *The protection needs analysis has no interview partners. | ||
* | *There already exists another protection needs analysis for the same organizational unit or the same process that assesses at least one identical resource or data category and: | ||
* | **is not yet completed, or | ||
** | **has already been completed, but has a more recent start date.<p> | ||
** | <u>Note:</u> The last case is particularly relevant if you operate several management systems. If you have scheduled a protection needs analysis via workflow, but a colleague in another management system creates a different protection needs analysis that meets the same conditions, the new protection needs analysis will block the workflow. While it is unlikely that the same OrgUnits and processes are interviewed in different management systems, HITGuard nevertheless checks for this case and warns about conflicts.<p> | ||
<u> | <b>What happens to paused protection needs analyses?</b><br> | ||
<b> | If a protection needs analysis has been paused, no reassessment is created during the next execution. Instead, the protection needs analysis is reactivated for the subsequent execution.<p> | ||
<b>Why can some closed protection needs analyses be added to workflows and some cannot?</b><br> | |||
<b> | Protection needs analyses that are closed and for which a reassessment is possible can be added to a workflow plan. If a reassessment of the protection needs analysis is not possible for one of the various reasons, it cannot be added to the workflow plan either. | ||
Version vom 30. Juni 2026, 11:18 Uhr
Using workflow plans
Workflow plans are available for three elements (protection needs analyses, vulnerability/GAP analyses and risks & opportunities). You can send each of these three elements to a Practitioner via workflow. With workflow plans, you can plan and automate these workflows for the future.
The automatic workflow plans for protection needs and vulnerability/GAP analyses are about the reassessment of already documented results. HITGuard therefore automatically creates new reviews and sends them as a self-assessment to the interview partners. The interview partners, to whom HITGuard sends the request by e-mail, then have the option of editing the contents of the reassessment. In this way, they can, for example, schedule an annual reassessment of the previously collected information.
With the automatic workflow plans for risks, you can run not only reassessments but also the initial assessment through the automated workflow plan. For risks, HITGuard does not create any new elements, but keeps a detailed record of all changes. Here too, you can reassess on a regular cycle, whereby HITGuard will prompt the users in the "Advisor" field to revise the contents.
In this article, we will address the three variants separately. First, however, we will discuss general points of the workflow plan.
Basic properties of workflow plans
Creating a workflow plan

By clicking the purple button in the control bar above the grid, you open a list of all created workflow plans. With the "Plus" button you can then create a new workflow plan, or you can open an existing workflow plan by double-clicking.
With the "Copy" button, an existing workflow plan can be copied, whereby the contents of the settings of the workflow plan are copied, but not the already executed workflows or the linked reviews.
Tab 1: Master data of the workflow plan

Status:
- Only active workflow plans actually send out new elements for assessment.
- By default, workflow plans are active when created. You can also suspend or deactivate them with this selection field.
- One-time workflows are automatically moved from the Active status to the Deactivated status after they have been executed.
Name & Description:
- Enter the purpose of the workflow plan here so that you can understand its intention later on.
Responsible User:
- The responsible user is tasked with preparing the workflow plan, not with responding to the workflows.
- The responsible user is informed by e-mail one week before the workflow is triggered. If there are problems or conflicts at this point (see below), these are described in the e-mail and can therefore be resolved in good time.
- The responsible user is also informed when the workflow is triggered about which reviews were sent out successfully and whether there were any problems or conflicts that prevented further reviews from being sent out.
Notify management system responsible persons:
- If this checkbox is set, in addition to the responsible person for the workflow plan, the responsible persons for the management system are also informed by e-mail about the upcoming or executed workflow.
Next execution:
- Specify here when the workflow plan should be triggered next. At this point, the reassessments/risks are then sent to the interview partners/Advisors based on the linked elements.
Recurring workflow:
- If the workflow plan should be triggered regularly, you can set this here.
- After being triggered, HITGuard will renew the date and add the time span you have defined here to the old date.
Tab 2: Adding elements



Depending on the variant, the second tab is called "Protection needs analyses", "Reviews" or "Risks & Opportunities". In the three screenshots on the right, you can see that the three pages are structured as a grid. In the following, we address the general basic functions that all workflow plans share.
Link button
- To the right above the grid, you can attach the original elements that the workflow plan is to reassess.
Grid overview of the element
- Here you see the title of the element as well as some additional information that defines the analyses or risks in more detail. Using the column selection, you can also hide these properties.
- The titles of the elements function as links. By clicking the blue text, you can jump directly into the analysis or the risk.
- Note: Here you always see the latest version/reassessment of the analyses. If the workflow has just been triggered, the link no longer takes you to the original analysis, but to the reassessment that has already been created automatically.
Warnings & conflicts
- In the grid, HITGuard points out possible conflicts of the workflow plans. The Conflicts column indicates the origin of the conflict. Details about the conflict can also be found in the tooltip when you hover the mouse over the triangle.
- Yellow warning triangles: If the risk or the analysis itself is not ready for a reassessment, this is shown with a yellow warning triangle. Usually this is because the vulnerability/GAP or protection needs analysis is not yet completed, or because the risk is already in the assessment workflow. Yellow warning triangles are also shown here when the workflow has just been triggered.
- Red warning triangles: If there is a conflict with another element, this is shown with a red warning triangle. The conflict can arise in the same or in another management system (e.g. reassessments of protection needs analyses in another management system).
Status: Active/Paused
- This status indicates whether the element will be triggered with the workflow plan. Active elements trigger on the date of the workflow plan, paused ones skip a cycle. You control the status with the Play/Pause button on the right side of the grid. In the second screenshot you see a paused review.
Play/Pause button
- With this button you control the Active/Paused status of the individual element.
Unlink button
- This permanently removes the review from the workflow plan.
Reassess button
- With this button you can manually bypass the workflow plan and create a reassessment manually. For example, you can pause a protection needs analysis and then carry out a reassessment manually. HITGuard will track this, so your manual reassessment will later be visible here in the overview. If you complete the manual reassessment in good time, HITGuard can use it as a template for the next cycle.
Tab 3: Executed workflows

This page offers you an overview of the historical cycles of the workflow plan. For protection needs and vulnerability/GAP analyses, you can trace the reassessments and the preceding analyses that served as a template.
Workflow plans for protection needs analyses & vulnerability/GAP analyses
Workflow plans for analyses work with reassessments. When the workflow plan is triggered, a new protection needs or vulnerability/GAP analysis is created that is based on the template of the old one. The original analysis remains untouched and write-protected in the system. You can find out more about reassessments on the detail pages of the protection needs analysis and vulnerability/GAP analysis.
The workflow plans for the two analyses differ above all in how they take over the results of the preceding analysis. When you attach an analysis to the workflow plan, HITGuard will ask for this setting right away. You can also view and edit it afterwards in the grid.
- Taking over results for protection needs analyses
For the protection needs analysis there is only a simple checkbox. When it is activated, HITGuard copies all values from the old into the new protection needs analysis. These are the impact-severity ratings of the protection objectives that were recorded between the organizational unit or the process and the linked resources and data categories. You can change this checkbox directly in the overview of the linked protection needs analyses.
- Taking over results for vulnerability/GAP analyses

For the vulnerability/GAP analysis, the taking over of results comes with more options:
- Current knowledge base: Knowledge bases serve as a template for the question sets in vulnerability/GAP analyses. Sometimes the template has evolved further after the original review was created. With this checkbox you determine whether, during the reassessment, HITGuard should use the old version of the template, or whether it should use the latest version of the knowledge base.
- Answer carry-over: Here you can decide whether HITGuard should take over all answers, no answers or only positive answers from the last review in the reassessment. This controls how thoroughly the Advisor has to work through the reassessment.
- Justification carry-over:Regardless of whether you take over answers or not, you can take over the respective justification texts from the original review. Alternatively, you can enter a default text that HITGuard will place in every justification field.
- You can also change all these settings later by clicking "Edit".
Workflow plans for risks/opportunities
- In the workflow plan with risks and opportunities, you send the risk to the Advisor for reassessment. Unlike with the analyses, no separate reassessment is created here. Therefore, there are also no settings for taking over results.
- In the second tab, "Risks and Opportunities", you can link the risks and opportunities whose reassessment the workflow plan is to initiate. After you have added a risk with the Link button, HITGuard will offer you a text field with which you can compose a message to the Advisor. You can also change this afterwards in the grid.
- You can find out more about the risk assessment workflow here.
Workflow plan FAQs
What happens when the workflow plan is executed?
When the workflow plan is executed, reassessments are created for the linked protection needs analyses and the respective interview partners are requested to respond. A reassessment assesses the same resources and data categories for the same organizational unit or the same process as the original protection needs analysis.
When is no reassessment requested?
No reassessment is created and requested if one of the following conditions applies:
- The reassessment of the protection needs analysis is paused.
- The protection needs analysis is not completed.
- The protection needs analysis has no interview partners.
- There already exists another protection needs analysis for the same organizational unit or the same process that assesses at least one identical resource or data category and:
- is not yet completed, or
- has already been completed, but has a more recent start date.
Note: The last case is particularly relevant if you operate several management systems. If you have scheduled a protection needs analysis via workflow, but a colleague in another management system creates a different protection needs analysis that meets the same conditions, the new protection needs analysis will block the workflow. While it is unlikely that the same OrgUnits and processes are interviewed in different management systems, HITGuard nevertheless checks for this case and warns about conflicts.
What happens to paused protection needs analyses?
If a protection needs analysis has been paused, no reassessment is created during the next execution. Instead, the protection needs analysis is reactivated for the subsequent execution.
Why can some closed protection needs analyses be added to workflows and some cannot?
Protection needs analyses that are closed and for which a reassessment is possible can be added to a workflow plan. If a reassessment of the protection needs analysis is not possible for one of the various reasons, it cannot be added to the workflow plan either.