Ressourcen/en: Unterschied zwischen den Versionen
Weitere Optionen
Übernehme Bearbeitung einer neuen Version der Quellseite |
Übernehme Bearbeitung einer neuen Version der Quellseite |
||
| Zeile 17: | Zeile 17: | ||
[[Datei:Ressource bearbeiten 1.PNG|left|thumb|902px|Page for editing/creating a resource]]<br clear=all> | [[Datei:Ressource bearbeiten 1.PNG|left|thumb|902px|Page for editing/creating a resource]]<br clear=all> | ||
'''Name:''' The name of the resource. | '''Name:''' The name of the resource. | ||
'''Description:''' Used to describe the resource. | '''Description:''' Used to describe the resource. | ||
'''Type:''' Resources are divided into model segments. In the individual segments, resources can be further structured via resource groups, whereby resource groups only serve the structure and cannot be used for valuations or similar. Resources themselves can be assigned to resource groups. They can be linked to test objects in deviation analyses or test results. This means that they can also be assigned to hazard situations, which means that they can be directly linked to measures and controls. | '''Type:''' Resources are divided into model segments. In the individual segments, resources can be further structured via resource groups, whereby resource groups only serve the structure and cannot be used for valuations or similar. Resources themselves can be assigned to resource groups. They can be linked to test objects in deviation analyses or test results. This means that they can also be assigned to hazard situations, which means that they can be directly linked to measures and controls. | ||
'''Select group color/group:''' | '''Select group color/group:''' | ||
| Zeile 33: | Zeile 27: | ||
Resources: Resources can be assigned to resource groups here. | Resources: Resources can be assigned to resource groups here. | ||
'''Model segment:''' Model segments are used for general grouping of structural elements. They are specified by HITGuard and include: | '''Model segment:''' Model segments are used for general grouping of structural elements. They are specified by HITGuard and include: | ||
:* Application level | :* Application level | ||
| Zeile 39: | Zeile 32: | ||
:* Physical security | :* Physical security | ||
:* Process level | :* Process level | ||
'''Person responsible:''' The user who is responsible for the content of the resource. | '''Person responsible:''' The user who is responsible for the content of the resource. | ||
'''Advisor:''' The user responsible for this at the model segment level (e.g., the IT level or physical security). | '''Advisor:''' The user responsible for this at the model segment level (e.g., the IT level or physical security). | ||
'''Score:''' The score at which the resource is evaluated. | '''Score:''' The score at which the resource is evaluated. | ||
'''Node color:''' The background color of the resource/resource group in the structure analysis. | '''Node color:''' The background color of the resource/resource group in the structure analysis. | ||
'''Protection need class:''' The protection need of the resource/resource group. For more information about protection need classes, see [[Special:MyLanguage/RiskPolicy#prot_need|protection need]]. | '''Protection need class:''' The protection need of the resource/resource group. For more information about protection need classes, see [[Special:MyLanguage/RiskPolicy#prot_need|protection need]]. | ||
'''RTO:''' | '''RTO:''' | ||
| Zeile 66: | Zeile 48: | ||
:''Secured'' means that, e.g., an SLA or another kind of contract exists, in which the provider of the resource assures to keep a certain RTO. This document can also be deposited at this point. | :''Secured'' means that, e.g., an SLA or another kind of contract exists, in which the provider of the resource assures to keep a certain RTO. This document can also be deposited at this point. | ||
:The RTO can be entered in hours but also minutes. In either case it is then converted into hours and shown as a decimal number in the overview. | :The RTO can be entered in hours but also minutes. In either case it is then converted into hours and shown as a decimal number in the overview. | ||
:The RTO is only shown with the resource, if the protection target RTO is used in the [[Special:MyLanguage/Managementsysteme|management system]]. | |||
'''RPO:''' | '''RPO:''' | ||
:RPO oder Recovery Point Objective gibt an, wie viel Datenverlust in Kauf genommen werden kann. Dabei gibt die RPO den Zeitraum an, der zwischen zwei Datensicherungen liegen darf. Das heißt: Wie viele Daten/Transaktionen zwischen der letzten Sicherung und dem Systemausfall höchstens verloren gehen dürfen. | :RPO oder Recovery Point Objective gibt an, wie viel Datenverlust in Kauf genommen werden kann. Dabei gibt die RPO den Zeitraum an, der zwischen zwei Datensicherungen liegen darf. Das heißt: Wie viele Daten/Transaktionen zwischen der letzten Sicherung und dem Systemausfall höchstens verloren gehen dürfen. | ||
:The RPO can be entered in hours but also minutes. In either case it is then converted into hours and shown as a decimal number in the overview. | :The RPO can be entered in hours but also minutes. In either case it is then converted into hours and shown as a decimal number in the overview. | ||
:The RPO is only shown with the resource, if the protection target RPO is used in the [[Special:MyLanguage/Managementsysteme|management system]]. | |||
'''External ID:''' With this ID a resource can be connected with an external resource via updates. That means: If a resource is imported with matching ID, then no new resource is created for it, but the one with matching ID is updated. | '''External ID:''' With this ID a resource can be connected with an external resource via updates. That means: If a resource is imported with matching ID, then no new resource is created for it, but the one with matching ID is updated. | ||
'''Hazard situations:''' For resources only. All hazard layers of the resource are listed here. It is not possible to assign hazard layers here. More about hazard layers can be found [[Special:MyLanguage/Risk Assessment|here]]. | '''Hazard situations:''' For resources only. All hazard layers of the resource are listed here. It is not possible to assign hazard layers here. More about hazard layers can be found [[Special:MyLanguage/Risk Assessment|here]]. | ||
'''Delete resource:''' To delete in the edit screen, click on the red trash can. | '''Delete resource:''' To delete in the edit screen, click on the red trash can. | ||
<span id="Beziehungen"></span> | <span id="Beziehungen"></span> | ||
| Zeile 90: | Zeile 68: | ||
[[Datei:Ressource bearbeiten 2 beziehungen.PNG|left|thumb|600px|Relationships]]<br clear=all> | [[Datei:Ressource bearbeiten 2 beziehungen.PNG|left|thumb|600px|Relationships]]<br clear=all> | ||
'''Incoming connections:''' the resource depends on the listed nodes. | '''Incoming connections:''' the resource depends on the listed nodes. | ||
'''Outgoing connections:''' the listed nodes depend on the resource. | '''Outgoing connections:''' the listed nodes depend on the resource. | ||
'''create a new connection:''' | '''create a new connection:''' | ||
Version vom 14. März 2023, 14:51 Uhr
Resources are systems, people, buildings or other entities that are required for the execution of processes or for the functionality of an organizational unit. HITGuard offers the possibility to build up resource structures and to graphically display their effects and dependencies on other systems via the structure analysis.
Create/edit/delete resources
Under "Administration → Resources" you can manage the resources as an admin or expert.

To create a resource click the "Plus" button.
To edit a resource, double-click on the corresponding resource.
Name: The name of the resource.
Description: Used to describe the resource.
Type: Resources are divided into model segments. In the individual segments, resources can be further structured via resource groups, whereby resource groups only serve the structure and cannot be used for valuations or similar. Resources themselves can be assigned to resource groups. They can be linked to test objects in deviation analyses or test results. This means that they can also be assigned to hazard situations, which means that they can be directly linked to measures and controls.
Select group color/group:
- Resource group: That color with which the resources of this group are outlined in the structure analysis.
Resources: Resources can be assigned to resource groups here.
Model segment: Model segments are used for general grouping of structural elements. They are specified by HITGuard and include:
- Application level
IT infrastructure level
- Physical security
- Process level
Person responsible: The user who is responsible for the content of the resource.
Advisor: The user responsible for this at the model segment level (e.g., the IT level or physical security).
Score: The score at which the resource is evaluated.
Node color: The background color of the resource/resource group in the structure analysis.
Protection need class: The protection need of the resource/resource group. For more information about protection need classes, see protection need.
RTO:
- RTO or Recovery Time Objective specifies how long a business process/system may be down. In this context, the RTO specifies the time that may pass from the time of damage until the complete recovery of the business processes (recovery of: Infrastructure - Data - Reprocessing of data - Resumption of activities) may pass.
- Undefined means that the RTO of this resource is not further relevant.
- Secured means that, e.g., an SLA or another kind of contract exists, in which the provider of the resource assures to keep a certain RTO. This document can also be deposited at this point.
- The RTO can be entered in hours but also minutes. In either case it is then converted into hours and shown as a decimal number in the overview.
- The RTO is only shown with the resource, if the protection target RTO is used in the management system.
RPO:
- RPO oder Recovery Point Objective gibt an, wie viel Datenverlust in Kauf genommen werden kann. Dabei gibt die RPO den Zeitraum an, der zwischen zwei Datensicherungen liegen darf. Das heißt: Wie viele Daten/Transaktionen zwischen der letzten Sicherung und dem Systemausfall höchstens verloren gehen dürfen.
- The RPO can be entered in hours but also minutes. In either case it is then converted into hours and shown as a decimal number in the overview.
- The RPO is only shown with the resource, if the protection target RPO is used in the management system.
External ID: With this ID a resource can be connected with an external resource via updates. That means: If a resource is imported with matching ID, then no new resource is created for it, but the one with matching ID is updated.
Hazard situations: For resources only. All hazard layers of the resource are listed here. It is not possible to assign hazard layers here. More about hazard layers can be found here.
Delete resource: To delete in the edit screen, click on the red trash can.
Relationships
In the "Relationships" tab, all existing connections to the resource are listed. Experts can give the resource new connections or edit or delete already existing ones.
Incoming connections: the resource depends on the listed nodes.
Outgoing connections: the listed nodes depend on the resource.
create a new connection:
- First, you must select whether the connection is incoming or outgoing.
- Secondly, the destination or outgoing node must be selected.
- Now only "Add" must be clicked.
edit/delete connections:
- Each connection is weighted using protection goals. (See protection goals) These protection goals can be set manually if they have not been set by a Protection needs analysis. To change the weighting of the protection target, see Edit protection target.
- Connections, if not weighted by a protection needs analysis, can be deleted by clicking on the red trash can.
Gaps/Measures/Controls
These tabs list deviations, measures and controls that are related to the entity via test objects. These tabs are only overview lists. This means that no deviations, measures or controls can be assigned manually here.
Historical deviations are displayed in gray.