Schwachstellen/en: Unterschied zwischen den Versionen
Weitere Optionen
Übernehme Bearbeitung einer neuen Version der Quellseite |
Isan (Diskussion | Beiträge) Die Seite wurde neu angelegt: „right|thumb|900px|Abweichungsfilter“ |
||
Zeile 8: | Zeile 8: | ||
<span id="Überprüfungen_(Abweichungsanalysen/Prüfergebnisse)"></span> | <span id="Überprüfungen_(Abweichungsanalysen/Prüfergebnisse)"></span> | ||
==<span id="create_überprüfung"></span> Reviews (gap analyses/review results) == | |||
==<span id=" | |||
Under "Risk management → Vulnerabilities → <u>Reviews</u> | Review objects | Gaps | Clarification needed", professionals and experts can find all reviews that have been created in the management system. All reviews are displayed, regardless of whether they are completed, in progress, or in draft status. New reviews can also be created or requested here. Furthermore, the reviews can also be downloaded as PDF or Word files. | |||
Under "Risk management → Vulnerabilities → <u>Reviews</u> | | |||
[[Datei:Risikoidentifikation Überprüfungen.png|left|thumb|900px|Overview of the reviews]] | [[Datei:Risikoidentifikation Überprüfungen.png|left|thumb|900px|Overview of the reviews]] | ||
<br clear=all> | <br clear=all> | ||
<span id="Überprüfung_erstellen/bearbeiten"></span> | <span id="Überprüfung_erstellen/bearbeiten"></span> | ||
=== Create/edit review === | === Create/edit review === | ||
<b>Review result:</b> | <b>Review result:</b> | ||
* A review result means, for example, the findings that were handed out by the auditor in the course of an audit, possibly in the form of a report. | * A review result means, for example, the findings that were handed out by the auditor in the course of an audit, possibly in the form of a report. | ||
* These findings can be entered using the "Add review result" button, accessible via the dropdown in the "Plus" button. | * These findings can be entered using the "Add review result" button, accessible via the dropdown in the "Plus" button. | ||
<b>Gap analysis:</b> | <b>Gap analysis:</b> | ||
* Gap analyses are questionnaire-based reviews (KB) on specific topics. These questionnaires can be used, for example, to determine the degree of compliance with a standard. In addition to the questionnaire topics, other review results can be recorded. | * Gap analyses are questionnaire-based reviews (KB) on specific topics. These questionnaires can be used, for example, to determine the degree of compliance with a standard. In addition to the questionnaire topics, other review results can be recorded. | ||
* If a translation of the KB is available in the currently selected language (flag on the top right, next to the "Logout" button), it will be applied. | * If a translation of the KB is available in the currently selected language (flag on the top right, next to the "Logout" button), it will be applied. | ||
* To create a gap analysis, click on the "Plus" button. | * To create a gap analysis, click on the "Plus" button. | ||
In terms of procedure, the only difference between the two inspection options is that an inspection result cannot handle inspection objects based on knowledge bases. | In terms of procedure, the only difference between the two inspection options is that an inspection result cannot handle inspection objects based on knowledge bases. | ||
To edit a review, double-click on it in the overview. | To edit a review, double-click on it in the overview. | ||
For more information on creating or editing a review, whether gap analysis or review result, see <b>[[Special:MyLanguage/Überprüfung| Create/Edit review]]</b>. | For more information on creating or editing a review, whether gap analysis or review result, see <b>[[Special:MyLanguage/Überprüfung| Create/Edit review]]</b>. | ||
=== <span id="asses_wiz_nav"></span>Navigation in the wizard === | === <span id="asses_wiz_nav"></span>Navigation in the wizard === | ||
The following section explains how the navigation in the review wizard works. | The following section explains how the navigation in the review wizard works. | ||
[[Datei:Wizard Navigation.png|left|thumb|900px|Review | [[Datei:Wizard Navigation.png|left|thumb|900px|Review wizard]] | ||
<br clear=all> | <br clear=all> | ||
Zeile 79: | Zeile 63: | ||
<span id="Status_und_Löschen_einer_Überprüfung"></span> | <span id="Status_und_Löschen_einer_Überprüfung"></span> | ||
=== <span id="Status"></span>Status and deletion of a check=== | === <span id="Status"></span>Status and deletion of a check=== | ||
[[Datei:Überprüfung Stati wechseln.PNG|left|thumb|900px]] | |||
<br clear=all> | |||
A review can have in different statuses. If the e-mail notifications are active in the management system, all persons relevant in the workflow are prompted to perform their tasks when the status changes. This would be, for example, the interview partner if an auditor requests a response or the auditor themselves if the response is returned. | A review can have in different statuses. If the e-mail notifications are active in the management system, all persons relevant in the workflow are prompted to perform their tasks when the status changes. This would be, for example, the interview partner if an auditor requests a response or the auditor themselves if the response is returned. | ||
The status of the review can be changed via the blue button in the upper right corner. | The status of the review can be changed via the blue button in the upper right corner. | ||
<b>Draft</b> | <b>Draft</b> | ||
Zeile 167: | Zeile 151: | ||
Double-clicking on a gap opens the review at the point where the gap was detected. Here, measures and controls for the gap can now be defined. For more information, see [[Special:MyLanguage/Prüffragen_beantworten| Answer review questions]]. | Double-clicking on a gap opens the review at the point where the gap was detected. Here, measures and controls for the gap can now be defined. For more information, see [[Special:MyLanguage/Prüffragen_beantworten| Answer review questions]]. | ||
Optionally, it is possible to display a column that shows whether the line is a review question (from a knowledge base) or a review result (freely entered). This allows experts to then expand their self-developed knowledge bases by review results that are often added to reviews during the interview. | |||
<span id="Abweichungen_filtern"></span> | |||
===Filter gaps=== | |||
[[Datei:Abweichungsfilter.png|right|thumb|900px|Abweichungsfilter]] | |||
With the filter, it can be selected which type of gaps is displayed: | |||
*negative: review questions/results that were evaluated < the target score | |||
*none: review questions/results that were evaluated = the target score | |||
*positive: review questions/results that were evaluated > the target score | |||
<span id="Target_Score_Gewichtung"></span> | <span id="Target_Score_Gewichtung"></span> |
Version vom 1. März 2023, 12:44 Uhr
What is a review?
In HITGuard, a review is understood to be the recording of deviations from a target state. For example, a review can be an audit by an external auditor. The findings that the auditor may have handed over to you in the form of a report can be entered in HITGuard as a so-called "review result".
Review results can also arise from a review with HITGuard. This is done by using knowledge bases in the "gap analyses". Here, a review is guided by structured questionnaires, with the help of which deviations from the desired target state are determined.
The target state is referred to as the target score level in HITGuard and can be set separately for each management system. Only experts or administrators can set and change the target score level under "Administration → Management Systems".
Reviews (gap analyses/review results)
Under "Risk management → Vulnerabilities → Reviews | Review objects | Gaps | Clarification needed", professionals and experts can find all reviews that have been created in the management system. All reviews are displayed, regardless of whether they are completed, in progress, or in draft status. New reviews can also be created or requested here. Furthermore, the reviews can also be downloaded as PDF or Word files.

Create/edit review
Review result:
- A review result means, for example, the findings that were handed out by the auditor in the course of an audit, possibly in the form of a report.
- These findings can be entered using the "Add review result" button, accessible via the dropdown in the "Plus" button.
Gap analysis:
- Gap analyses are questionnaire-based reviews (KB) on specific topics. These questionnaires can be used, for example, to determine the degree of compliance with a standard. In addition to the questionnaire topics, other review results can be recorded.
- If a translation of the KB is available in the currently selected language (flag on the top right, next to the "Logout" button), it will be applied.
- To create a gap analysis, click on the "Plus" button.
In terms of procedure, the only difference between the two inspection options is that an inspection result cannot handle inspection objects based on knowledge bases.
To edit a review, double-click on it in the overview.
For more information on creating or editing a review, whether gap analysis or review result, see Create/Edit review.
Navigation in the wizard
The following section explains how the navigation in the review wizard works.

The navigation in the wizard for performing checks works as follows:
- Clicking on "Next" takes you to the next step or to the next check question.
- Clicking on "Back" takes you to the last step or to the last review question.
- Clicking in the navigation tree on the left side will take you to the desired location.
- At the bottom left of the navigation mask, the review questions can be displayed in the navigation tree via a "Review questions" checkbox.
- If you show the review questions, you can also navigate to them via the tree.
- "Save" and "Close" behave self-explanatorily.
Regardless of the type of review you perform (gap analysis using a knowledge base or recording review results) the processing steps in the perform review wizard are essentially the same:
- Create and save review
- Add topics or review objects and activate review
- Answering the review objects or the possibility to request an answer in the "self assessment" by the interview partner
- Check responses or identified gaps
- Complete the review
A review can be performed by an expert. However, he also has the option of requesting the answer to the review from his interview partner in HITguard. Via workflow support, the interview partner receives a request for this and can complete the response and then return it to the expert. The expert checks the results and can mark the review as completed and archive it. The handling of deviations from the review is possible at any time, even if a review has already been completed.
Status and deletion of a check
A review can have in different statuses. If the e-mail notifications are active in the management system, all persons relevant in the workflow are prompted to perform their tasks when the status changes. This would be, for example, the interview partner if an auditor requests a response or the auditor themselves if the response is returned.
The status of the review can be changed via the blue button in the upper right corner.
Draft
- When the review is saved for the first time or deactivated from the "In Progress" status, it is in the "Draft" status.
- "Draft" means that the review is not yet active and no one has been informed about the review by the system.
- From this status, the review can be activated, i.e. set to the "In Progress" status.
In progress
- If the review is activated, it will be set to "In Progress" status. As a result, the interview partner and auditor will see it under "My tasks."
- Now it is time for the lead auditor to perform the review or request a response by "Request Response" from interview partners (only for self assessments).
- It can be set back to the status "Draft" by selecting "Deactivate review".
- It can be set to the status "Closed" by selecting "Close review".
Requested (only for self assessments) .
- If the review is requested by the lead auditor, it will be set to "Requested" status. The interview partner will be prompted via e-mail to perform the review.
- The interview partner can set the status to "Answered" by clicking on "Submit review" after the review has been conducted.
Answered (only for self assessmentse) .
- If the review is returned by the interview partner with "Submit review", it will be set to the status "Answered". The auditors will be prompted by an e-mail to check the response.
- It can be returned to the status "Requested" by selecting "Request response" again. The interview partner must then revise their response.
- It can be put back into the status "Draft" by selecting "Deactivate review" (only auditors will be notified).
- It can be moved to the status "Closed" by selecting "Close review".
Closed
- If the review is set to the "Closed" status by "Close review", it is read-only and it can no longer be edited.
- Exception: Even in already closed reviews, measures and controls can still be added to or removed from review questions.
Delete a review.
- With "Delete review" you can delete reviews that are not completed yet.
- Caution: By deleting, the review objects created in this review as well as gaps already assigned to risks will also be deleted!
Change review type (interview <=> self assessment)
The type of review can be changed only in the "Draft" status.
If the wrong type was set and the check was activated, the check must first be reset to the "Draft" status by "Deactivate check".
Review objects
Under "Risk management → Vulnerabilities → Review| Objects of review | Gaps | Clarification needed", you will find all the review objects that were created in the course of reviews in the current management system.

Clicking on a review object opens the detailed view.

Here you can see how the review object was answered. Likewise, if several versions of the review object are available, you can view how the assessment of the review object has developed from one version to the next. Only the header data of a review object can be edited via this mask. This means that this mask cannot be used to answer a review object.
Initiate partial automatic re-evaluation
Due to the implementation of measures, it can happen that review objects are proposed for partial automatic re-evaluation. This always happens if the measure was either created in the course of a check for a review object or linked to a review object, the "after" value of the vulnerability reduction was set and the measure is implemented. If a measure is implemented, the linked review objects are marked with "Re-evaluation recommended".
To avoid having to perform a new review every time a measure is implemented, HITGuard offers the option of subjecting these marked review objects to a semi-automatic revaluation. This means that HITGuard automatically updates the gap of the respective review questions of the review objects. In this process, the review questions that are affected by the implementation of measures are set to the "after" value of the vulnerability reduction.
Execution:
- Select review object.
- Click the orange arrow "Initiate semi-automatic revaluation".
- Select the gaps to be updated.
- Click the orange arrow "Perform re-evaluation for selected gaps".

Gaps
Under "Risk management → Vulnerabilities → Reviews | Objects of review | Gaps | Clarification needed", you will find all gaps that were identified during the performance of reviews.

The columns "Measure missing", "Target value missing", "Target value too low" can be used to find out against which gaps nothing or too little has been done. These gaps are tagged in the grid. If a gap does not have a tag, this means that attempts are being made to correct the gap.
Here you have the option to assign gaps that have not yet been assigned to a hazard situation.
Double-clicking on a gap opens the review at the point where the gap was detected. Here, measures and controls for the gap can now be defined. For more information, see Answer review questions.
Optionally, it is possible to display a column that shows whether the line is a review question (from a knowledge base) or a review result (freely entered). This allows experts to then expand their self-developed knowledge bases by review results that are often added to reviews during the interview.
Filter gaps

With the filter, it can be selected which type of gaps is displayed:
- negative: review questions/results that were evaluated < the target score
- none: review questions/results that were evaluated = the target score
- positive: review questions/results that were evaluated > the target score
Target score weighting
What the target score level is and where it is set can be found under Management systems. Wherever gaps occur, there is an additional form of sorting: the target score weighting. This is possible, for example, under "Risk management → Vulnerabilities → Gaps".
If activated, the sorting of protection targets is based on the target score weighting. The greater the deviation from the target score level and the greater the weighting of the protection target, the greater the target score weighting: target score weighting = deviation level * weighting of the protection target.
Note: A response of "No" corresponds to score level 1, "Partially" corresponds to score level 3.
Examples for illustration: Protection goal weighting: Mean (3).
- score of deviation = 2, target score = 4 => Degree of deviation = 2, target score weighting = 2 * 3 = 6.
- score of deviation = 4, target score = 4 => degree of deviation = 0, target score weighting = 0 * 3 = 0.

Clarification needed
Under "Risk Management → Vulnerabilities → Reviews | Objects of review | Gaps| Clarification needed" you will find all review questions/review results that were marked with "Clarification needed" in the course of a review.

This label is necessary in practice if you cannot yet clarify how the question is to be answered when answering a review question. This can happen if, for example, you would need to consult another person or otherwise research the information. Following a series of reviews, the system evaluates which questions still need to be researched. This is exactly what the "Clarification needed" view is for.
If you click on a review question/result, you will be redirected to it.
It is also possible to export a list of all review questions/results requiring clarification via the "Export" button (next to the search bar). This provides an easy-to-use list of the review questions that require clarification.