Menü aufrufen
Toggle preferences menu
Persönliches Menü aufrufen
Nicht angemeldet
Ihre IP-Adresse wird öffentlich sichtbar sein, wenn Sie Änderungen vornehmen.

OrgUnits - Organizational units

Aus HITGuard User Guide

A company consists of organizational units that interact with other kinds of master data: Processes take place in one or several organizational units. Creation and processing of data categories takes place in these organizational units during the individual process steps. It is predominantly IT-supported and done with the use of IT systems. The more vital the organizational unit, the greater the potential damage, and the greater the requirements for availability, confidentiality and integrity of the data or systems.

An organizational unit is a mandatory field in all HITGuard core elements. Every protection needs- and vulnerability/gap analysis, as well as all measures and controls must always refer to an organizational unit that is responsible for them.

The structure of the organizational units is hierarchical.

Important: To be able to use OrgUnits in a management system, they must be activated for the analysis period by ticking a checkbox. The checkbox of the new OrgUnit always inherits the checkbox setting of its parent OrgUnit. If you create a new OrgUnit that has no parent OrgUnit, no checkbox is set automatically. You must therefore activate it yourself under Administration > Management System > Active analysis period.

How HITGuard displays Organizational Units in the structural analysis


Working with organizational units

OrgUnits can be created or edited by administrators and experts via "Administration → OrgUnits". To create a new OrgUnit, click the "Plus" button. To edit an existing OrgUnit, open it by double-clicking the corresponding row.

Organizational structures mask


Form for editing/creating an organizational unit



For each organizational unit, there are several input fields that you can use to further define it:

Abbreviation and designation:
In the designation, you enter the assigned name of the OrgUnit, while in the abbreviation you enter how the OrgUnit should be abbreviated. Please note that HITGuard will use this abbreviation in the structural analysis and when generating abbreviations for other entities.

Sort order: Defines the order in which the OrgEhs are listed, e.g., in a report. (e.g. in a report).

Superordinate OrgUnit: Here you establish the hierarchical structure of the organizational units by specifying where the OrgUnit fits into the hierarchy, for example, which company a department belongs to.

Type: Here, you specify the type of organizational unit: Group, Company, Department, Entity, Branch

Division: Here, you define in which divisions the OrgUnit is active. Divisions are primarily used in the add-on for Audit planning.

Responsible: The person entered here is responsible for the OrgUnit. This could be, for example, the head of a department.

Description: Here, you describe the OrgUnit.

Closed: If an OrgUnit is closed, it is only displayed on this page. It can no longer be selected for new elements. Deactivating has no effect on current assignments, and the OrgUnit can still be selected for reports.

Active from/to Here you define the time period in which the OrgUnit should be active in HITGuard. If the OrgUnit is no longer active, but not closed, it can still be selected anywhere, but is displayed in italics to signal that it is inactive.

ID in third-party systems: This field is used to synchronize an OrgUnit with a third-party system. Synchronization requires a data import, in which the same ID is set.


Risks: All risks of the OrgUnit are listed here. It is not possible to assign risks here. More about risks can be found here.

Address: Here, you enter the address of the OrgUnit and tick whether the organizational unit is outside of the EU.

Delete OrgUnit: To delete an OrgUnit, click on the red trash can in the edit screen. In order for an OrgUnit to be deletable, nothing can be linked to it. This means that, for example, all assigned measures, control definitions and processing messages have to be linked to a different OrgUnit or be themselves deleted. The OrgUnit must also not be linked to any active or closed analysis period.

Data protection management system

If the active management system is the data protection management system, it is possible to record appropriate safeguards (underneath the address) as well as the contact data of the data protection officer of the OrgUnit. These are required for evaluation in data protection management.

If no data protection officer is found during evaluations for an OrgUnit, the officer of the higher-level OrgUnit is used. This means that if there is only one officer in the organizational structure, this officer's information only needs to be entered in the top-level OrgUnit.

Data Protection Officer


Deviations/measures/controls

The behavior is the same as for resources. More about this here.

Audit information

In the tab "Audit information", you record additional information relevant in the context of audits.

  • Number of employees: The number of employees can be recorded here.
  • Local Management Representative: This is the audit coordinator and contact person that should be defined for every OrgUnit of the type company.
  • "Proposal to audit this OrgUnit in each audit program": These OrgUnits are proposed when the corresponding filtering checkmark is set when planning in the audit calendar or in the audit creation form.
  • Certifications: Here, any standards (from standards and norms) in which the organizational unit is certified can be selected and assigned. A reg. no. and a location number can then be entered for each of these standards.
Audit information


Divisions

OrgUnits can be assigned several divisions, depending on their field of activity.


Under "Administration → Edit organizational units | Divisions", these divisions can be managed.

Divisions


Create/edit division

A new division can be created by clicking the "Plus" button.

By double-clicking on a division, it can be edited.

Edit division


Topic responsibility

Topic responsibilities are used for the bulk creation of measures in the context of dossiers in the case management. In them, you can designate responsibilities for certain topics by organizational units.

Activate topic responsibilities

To be able to use topic responsibilities, the checkbox "Topic responsibilities" must first be selected under "Measures → Settings → General". This displays the tab under "Administration → OrgUnits".

Topic responsibility


Create/edit topic responsibility

A new topic responsibility can be created by clicking the "Plus" button.

By double-clicking on a topic responsibility, it can be edited.

Edit topic responsibility


For the topic responsibility, select the desired organizational units for the respective topic.

Note: OrgUnits that are activated in the current analysis period are available for selection; the others are not selectable.

A responsible person or a responsible team must be entered for every selected organizational unit. They will received the measures for implementation when those are created in bulk.