Reports for measures
Weitere Optionen
Measure reports
HITGuard offers the possibility to generate reports for measures under "Measures → Reports".

To create a report, first choose a type of report. Subsequently, choose which data to include in the report (e.g. hazard situations or audits). Most reports also have additional report options which allow further specification of the report's contents.
Languages:
Knowledge bases may be available in different languages if there are defined translations for specific knowledge bases. For example, to generate a report with English texts, the language must be changed via the flag icon in the top right corner of the screen, next to the logout button. This will load all content for the reports in the desired language, provided that a translation in that language is available for the knowledge base.
Download options:
Reports are available for download as PDF or DOCX files. To generate a report and download it, click on the pink button. Then, you can choose whether to download the report as PDF or DOCX.
Additionally, there is the option to generate and archive the reports including revision information. In doing this, the report can be viewed, generated anew, or downloaded again by an expert under "Administration → Report archive". More information about this can be found under "Administration → Report archive".
Remembering report options: Some of the report options can be found for various reports. For these, the selected options are remembered within the management system and for the individual user, and then also applied for other reports with that same option. For example, if the option "Table of contents" is selected, then it will already be selected when accessing any other report pages that use this option.
Licenses:
If no valid license for HITGuard is available, this will be displayed in the footer of the report! To change this, an expert or administrator has to request/upload a license under "Administration → Licensing".
The following reports are offered in the measures section of HITGuard:
Progress report
On this page you can create, view, and download reports for measures within a specific analysis period for selected organizational units.
The reports offer an evaluation of the measures and the project progress. The evaluation of the measures deals with their criticality and recommends an implementation timeframe on the basis of that. The evaluation of the project progress shows, using traffic light colors, the evaluation of the progress of individual measures and the project as a whole. Finished measures are displayed as crossed out text in this report, suspended ones in italics.
Reports already created are listed to the left. A click on such an entry shows the report's revision information and it can be generated anew, if any modification is necessary. Clicking the blue name in the list opens an online preview of the report. If the name is blac, the report was prepared but not yet generated. Clicking the download symbol downloads a generated report.

In the tab Data selection, you can configure which organizational units are to be included in the report. The list "Included OUs" shows all organizational units that are currently considered for the report. The list "Current OUs" shows all organizational units that are available in the current analysis period of the active management system. Current OrgUnits that are not yet selected, can be added to to the included OUs via drag & drop.

Evaluation systematics
The following evaluation systematics are applied in the detail report for measures and also added to the report as an appendix.
Evaluation of the measures
Every measure is evaluated as to its criticality. How critical a measure is depends on the potential damage of the recognized vulnerability and the probability of occurrence of the event. The criticality of the measure results in the urgency of that vulnerability's correction.
Measure criticality
The criticality of a measure depends on the affected IT system and the data related to that. This can be ascertained by means of the business impact analysis and risk analyses carried out. If there is no such analysis for the affected serice, the following consideration is to be made:
- If the measure affects IT core services (such as, e.g., the network, the firewall, e-mail services or even physical security such as access to the server room), then the criticality level HIGH is to always be assumed.
- For all IT services not covered by point 1), the following deliberation is to be made:
- The threat potential is LOW, if
- monetary damages of up to EUR 300K for the company are possible,
- an image loss of partially external ramification could occur,
- the physical integrity of persons cannot be guaranteed, even if the occurrence is unlikely.
- The threat potential is MEDIUM, if
- monetary damages from over EUR 300K to up to EUR 5 million for the company are possible,
- an image loss with customers and partners could occur, that would have to be compensated with mid-term measures,
- the physical integrity of persons cannot be guaranteed, and the occurrence is not unlikely.
- The threat potential is HIGH, if
- monetary damages of over EUR 5 million for a company are possible,
- negative media coverage cannot be ruled out (with unavoidable mid- to long-term consequences),
- there is definitely danger to the life and limb of persons.
- The threat potential is LOW, if
- If no associated risk analysis is available, the probability of occurrence of the threat must also be considered. If the probability of occurrence of the risk is estimated to be very unlikely (or would have to be triggered by a chain of events) or compensating measures for the reduction of the risk have already been taken, then the risk level can be reduced. If a vulnerability can be exploited externally, the risk level may not be reduced.
Recommended implementation timeframe
The criticality of the measure informs the resulting proposed start date for the implementation of the measure.
- HIGH: immediately after conveying the audit findings
- MEDIUM: 1 to at most 2 months after conveying the audit findings
- LOW: 2 to at the most 4s months after conveying the audit findings
KO measures always cound as HIGH and are those that must be implemented immediately as the vulnerabilities are linked to a very high attack potential.
Of course, not the same effort can be assumed for the implementation of every measure. Projects are therefore classified as follows, depending on their planned duration and the estimated project days:
- SMALL: <1 month duration; <= 2 PD effort
- MEDIUM: <3 months duration; <= 10 PD effort
- LARGE: >3 months duration; > 10 PD effort
Therefore, only a recommended timeframe is given here.
Considering the factors criticality and effort, the following maximum reocmmended implementation timeframe is given:
Effort | |||
---|---|---|---|
Criticality | LARGE | MEDIUM | SMALL |
LOW | 4 months + project effort | 7 months | 5 months |
MEDIUM | 2 months + project effort | 5 months | 3 months |
HIGH | project effort | 3 months | 1 month |
In projects with a large effort, it should be ensured that short-term risk-reducing measures are implemented at the start of the project in any case. The project duration of any following long-term solution is then to be planned considering the economic factors of the project and the economic situation of the company as a whole.
Evaluation of the project progress
Evaluation of the progress of individual measures
So long as a task is within its defined period, the traffic light showing the project progress is green. When a measure is counted as overdue for the first time, the light becomes yellow. If in the next reporting period the task is still not finished, the light turns red and stays red for as long as it takes to implement the measure or until a follow-up audit resets the evaluation of the project progress. New implementation dates can be agreed in this audit. The "Recognized at"-date, however, always shows when a measure was first opened.
Evaluation of the progress in the project as a whole
The progress of the project as a whole is also evaluated via traffic light colors.
- NONE
- If 0 findings have been reported as finished in the current reporting period.
CAUTION: If “None” is written in red instead of black, this means that there is an impending delay regarding the implementation of findings. Otherwise, it can also mean that measures are being worked on at the moment, but due to their high-effort nature they simply take longer.
- If 0 findings have been reported as finished in the current reporting period.
- LOW
- If less than or exactly 10% of findings have been reported as finished in the current reporting period and/or
- more than 33% of findings are overdue.
- MEDIUM
- If more than 10% but less than or exactly 20% of findings have been reported as finished in the current reporting period and/or
- more than 20% but less than 33% of findings are overdue.
- HIGH
- If more than 20% of findings have been reported as finished in the current reporting period and/or
- no more than 20% of findings are overdue.
Finished/Suspended measures
A crossed out line is a task that is finished in the current analysis period and will not show up in the next report. A line in italics is a task suspended with justification.
Measure report for standard/norm
This report lists the linked measures for a selected standard/norm.
Report options
- Management system (compliance manager only)
- This option controls for which management system the report is generated.
- Analysis period
- This option controls which analysis period the measures included in the report come from.
- Progress overview
- It is possible to configure whether an overview of the progress development of the measure is added in the report:
- The current progress shows the reported progress percentage of the most recent accepted progress report.
- The progress growth shows the percentage change of the progress as compared to the previous analysis period.
- For progress reports, the amount of accepted progress report of the measure is displayed.
- The duration indicates for how long the measure is or was to be processed. It shows the duration in days from the audit date to the date of the report or the date the measure was marked as completed. If no audit date was set, the duration cannot be calculated.
- Overdue indicates for how long the measure is or was overdue. It shows the duration in days from the deadline to the date of the report or the date the measure was marked as completed. If no deadline was set, this timespan cannot be calculated.
- It is possible to configure whether an overview of the progress development of the measure is added in the report:
- Progress protocol
- It is possible to configure whether the protocol of the progress reports of the measure is added in the report.
- Include not applicable chapters in the statistics
- This will add chapters marked as not applicable in the management system in the report.
The remaining options are used to configure the additional report contents, such as table of contents and appendices.

Measure report
This report shows details for one or more selected measures.
Example measure report: measures with progress overview and protocol (DE)
Report options
- Management system (compliance manager only)
- This option controls for which management system the report is generated.
- Analysis period
- This option controls which analysis period the measures included in the report come from.
- Progress overview
- It is possible to configure whether an overview of the progress development of the measure is added in the report:
- The current progress shows the reported progress percentage of the most recent accepted progress report.
- The progress growth shows the percentage change of the progress as compared to the previous analysis period.
- For progress reports, the amount of accepted progress report of the measure is displayed.
- The duration indicates for how long the measure is or was to be processed. It shows the duration in days from the audit date to the date of the report or the date the measure was marked as completed. If no audit date was set, the duration cannot be calculated.
- Overdue indicates for how long the measure is or was overdue. It shows the duration in days from the deadline to the date of the report or the date the measure was marked as completed. If no deadline was set, this timespan cannot be calculated.
- It is possible to configure whether an overview of the progress development of the measure is added in the report:
- Progress protocol
- It is possible to configure whether the protocol of the progress reports of the measure is added in the report.
The remaining options are used to configure the additional report contents, such as table of contents and appendices.
