Monitoring
Continuous monitoring of the Information Security Management System (ISMS) is a central component of ISO 27001 and IT-Grundschutz. Effective monitoring enables organizations to track the progress of their security measures, identify weaknesses in documentation early, and demonstrably fulfill compliance requirements.
The fuentis Suite offers a comprehensive solution with the monitoring module that goes beyond classic dashboards and reports. The module enables detailed evaluations at various ISMS levels and creates transparency about the implementation status of building blocks, requirements, measures, and controls.
The monitoring module of the fuentis Suite enables monitoring at various structural levels:
- Building Blocks: Superordinate security modules according to BSI-Grundschutz or custom structuring
- Requirements: Specific security requirements within the building blocks
- Measures: Concrete implementation steps to fulfill the requirements
- Controls: Review mechanisms for effectiveness control (ISO 27001 Annex A)
- Target Object Groups (TOGs): Grouping of assets and protection objects

How the Monitoring Module Works
Section titled “How the Monitoring Module Works”Template-based Approach
Section titled “Template-based Approach”Monitoring in the fuentis Suite works with a flexible template system:
- Create template: Define the monitoring perspective
- Select source: Determine the elements to be monitored and their relationships
- Define unit: Determine the organizational area
- Configure evaluation: Customize the presentation and metrics

Available Monitoring Sources
Section titled “Available Monitoring Sources”The system offers various source combinations for different analysis purposes:
Hierarchical Monitoring:
- Building Blocks → Requirements: Overview of building blocks with associated requirements
- Building Blocks → Measures: Building blocks with derived measures
- Requirements → Measures: Direct assignment of requirements to measures
Single Element Monitoring:
- Building Blocks: Isolated view of building blocks
- Measures: Focus on measure implementation
- Requirements: Status of individual requirements
- Controls: Overview of control mechanisms
Asset-related Monitoring:
- Building Blocks → Target Object Groups: Building blocks in the context of affected assets
- Measures → Target Object Groups: Measures related to protection objects
- Requirements → Target Object Groups: Requirements for specific asset groups
- Controls → Target Object Groups: Controls structured by target objects
Practice Tip: Choose the source based on your question:
- For compliance evidence: “Building Blocks → Requirements”
- For implementation controlling: “Requirements → Measures”
- For asset risk assessment: Combinations with Target Object Groups
Practical Application
Section titled “Practical Application”Step 1: Create Template
Section titled “Step 1: Create Template”- Navigate to the “Monitoring” tab in the ISMS module
- Click on the dropdown of available templates
- Click on ”+ Add New”
- Enter a meaningful name (e.g., “Q4-2025 Compliance Check”)
- Select the relevant organizational unit
- Important: Careful selection of the appropriate source for the analysis purpose
- Save the template

Step 2: Use Monitoring Overview
Section titled “Step 2: Use Monitoring Overview”After creation, the template appears in the left column of the overview:
- Left column: List of all created templates
- Right side: Detailed view of the selected template
- Upper area: Processed evaluation with key figures
- Main area: Tabular presentation with drill-down capabilities
Interactive Elements:
- Arrows to expand and collapse hierarchical structures
- Direct navigation to linked elements
- Color coding according to implementation status

Step 3: Individualize View
Section titled “Step 3: Individualize View”The gear symbol in the upper right opens the customization options:
Column Management:
- Show/hide individual data fields
- Adjust column order
- Define default views

Save Options:
- “Save”: Individual customization for current template
- “Save All”: Transfer to all templates
- “Reset”/“Reset All”: Restore default view
Step 4: Export and Reporting
Section titled “Step 4: Export and Reporting”The export button enables documentation of the monitoring status:
- Select the desired template
- Click on “Export” (upper right)
- Automatic download as PDF file
- PDF contains:
- Selected key figures and metrics
- Tabular overview according to configuration
- Timestamp and version information
Practice Tip: Create regular exports for:
- Management reports (monthly/quarterly)
- Audit documentation
- Progress evidence for certifications

Step 5: Template Management
Section titled “Step 5: Template Management”Delete Templates:
- Click on the delete symbol in the template overview
- Confirmation in the pop-up dialog
- Final removal of the template

Best Practices for Template Management:
- Create templates for recurring evaluations
- Use descriptive names with date/purpose
- Archive templates that are no longer needed by exporting before deletion
Integration into the ISMS Process
Section titled “Integration into the ISMS Process”Continuous Improvement Process (CIP)
Section titled “Continuous Improvement Process (CIP)”The monitoring module supports the PDCA cycle:
Plan: Definition of monitoring templates for critical ISMS areas Do: Regular execution of monitoring Check: Analysis of results and identification of improvement potential Act: Derivation and implementation of corrective measures
Compliance Review
Section titled “Compliance Review”Goal: Evidence of ISO 27001 conformity
Note: Here, the GAP Analysis module should also be particularly mentioned and used.
Procedure:
- Template “ISO 27001 Compliance” with source “Controls”
- Filtering on Annex A controls
- Export for external audit

Scenario 2: Project Progress
Section titled “Scenario 2: Project Progress”Goal: Monitoring of an ISMS implementation project
Procedure:
- Template “ISMS Project Q4” with source “Requirements → Measures”
- Weekly updates
- Traffic light display for project control
Scenario 3: Asset Risk Management
Section titled “Scenario 3: Asset Risk Management”Goal: Security status of critical assets
Procedure:
- Template “Critical Systems” with source “Measures → Target Object Groups”
- Focus on high-critical TOGs
- Prioritization of protection measures
Additional Resources
Section titled “Additional Resources”Video Tutorial
Section titled “Video Tutorial”Glossary
Section titled “Glossary”ISMS: Information Security Management System - Management system for information security
TOG (Target Object Group): Grouping of assets with similar protection requirements
Building Block: Modular unit in BSI-Grundschutz for structuring security requirements
CIP: Continuous Improvement Process according to PDCA cycle
PDCA: Plan-Do-Check-Act - Management cycle for continuous improvement
Key Messages at a Glance
Section titled “Key Messages at a Glance”-
Flexible Monitoring: The monitoring module offers flexible analysis possibilities for all ISMS levels through various source combinations
-
Template-based: Recurring evaluations can be saved as templates and efficiently reused
-
Compliance Evidence: Export functions enable audit-proof documentation for audits and certifications
-
Customizable: Views can be adapted to specific requirements and saved
-
Integrated: The monitoring module complements dashboard and reports with a detailed analysis perspective for continuous ISMS management