Skip to content

Monitoring

Continuous monitoring of the Information Security Management System (ISMS) is a central component of ISO 27001 and IT-Grundschutz. Effective monitoring enables organizations to track the progress of their security measures, identify weaknesses in documentation early, and demonstrably fulfill compliance requirements.

The fuentis Suite offers a comprehensive solution with the monitoring module that goes beyond classic dashboards and reports. The module enables detailed evaluations at various ISMS levels and creates transparency about the implementation status of building blocks, requirements, measures, and controls.

The monitoring module of the fuentis Suite enables monitoring at various structural levels:

  • Building Blocks: Superordinate security modules according to BSI-Grundschutz or custom structuring
  • Requirements: Specific security requirements within the building blocks
  • Measures: Concrete implementation steps to fulfill the requirements
  • Controls: Review mechanisms for effectiveness control (ISO 27001 Annex A)
  • Target Object Groups (TOGs): Grouping of assets and protection objects

monitoring-1

Monitoring in the fuentis Suite works with a flexible template system:

  1. Create template: Define the monitoring perspective
  2. Select source: Determine the elements to be monitored and their relationships
  3. Define unit: Determine the organizational area
  4. Configure evaluation: Customize the presentation and metrics

monitoring-2

The system offers various source combinations for different analysis purposes:

Hierarchical Monitoring:

  • Building Blocks → Requirements: Overview of building blocks with associated requirements
  • Building Blocks → Measures: Building blocks with derived measures
  • Requirements → Measures: Direct assignment of requirements to measures

Single Element Monitoring:

  • Building Blocks: Isolated view of building blocks
  • Measures: Focus on measure implementation
  • Requirements: Status of individual requirements
  • Controls: Overview of control mechanisms

Asset-related Monitoring:

  • Building Blocks → Target Object Groups: Building blocks in the context of affected assets
  • Measures → Target Object Groups: Measures related to protection objects
  • Requirements → Target Object Groups: Requirements for specific asset groups
  • Controls → Target Object Groups: Controls structured by target objects

Practice Tip: Choose the source based on your question:

  • For compliance evidence: “Building Blocks → Requirements”
  • For implementation controlling: “Requirements → Measures”
  • For asset risk assessment: Combinations with Target Object Groups
  1. Navigate to the “Monitoring” tab in the ISMS module
  2. Click on the dropdown of available templates
  3. Click on ”+ Add New”
  4. Enter a meaningful name (e.g., “Q4-2025 Compliance Check”)
  5. Select the relevant organizational unit
  6. Important: Careful selection of the appropriate source for the analysis purpose
  7. Save the template

monitoring-3

After creation, the template appears in the left column of the overview:

  • Left column: List of all created templates
  • Right side: Detailed view of the selected template
  • Upper area: Processed evaluation with key figures
  • Main area: Tabular presentation with drill-down capabilities

Interactive Elements:

  • Arrows to expand and collapse hierarchical structures
  • Direct navigation to linked elements
  • Color coding according to implementation status

monitoring-4

The gear symbol in the upper right opens the customization options:

Column Management:

  • Show/hide individual data fields
  • Adjust column order
  • Define default views

monitoring-5

Save Options:

  • “Save”: Individual customization for current template
  • “Save All”: Transfer to all templates
  • “Reset”/“Reset All”: Restore default view

The export button enables documentation of the monitoring status:

  1. Select the desired template
  2. Click on “Export” (upper right)
  3. Automatic download as PDF file
  4. PDF contains:
    • Selected key figures and metrics
    • Tabular overview according to configuration
    • Timestamp and version information

Practice Tip: Create regular exports for:

  • Management reports (monthly/quarterly)
  • Audit documentation
  • Progress evidence for certifications

monitoring-6

Delete Templates:

  1. Click on the delete symbol in the template overview
  2. Confirmation in the pop-up dialog
  3. Final removal of the template

monitoring-7

Best Practices for Template Management:

  • Create templates for recurring evaluations
  • Use descriptive names with date/purpose
  • Archive templates that are no longer needed by exporting before deletion

The monitoring module supports the PDCA cycle:

Plan: Definition of monitoring templates for critical ISMS areas Do: Regular execution of monitoring Check: Analysis of results and identification of improvement potential Act: Derivation and implementation of corrective measures

Goal: Evidence of ISO 27001 conformity

Note: Here, the GAP Analysis module should also be particularly mentioned and used.

Procedure:

  1. Template “ISO 27001 Compliance” with source “Controls”
  2. Filtering on Annex A controls
  3. Export for external audit

monitoring-1

Goal: Monitoring of an ISMS implementation project

Procedure:

  1. Template “ISMS Project Q4” with source “Requirements → Measures”
  2. Weekly updates
  3. Traffic light display for project control

Goal: Security status of critical assets

Procedure:

  1. Template “Critical Systems” with source “Measures → Target Object Groups”
  2. Focus on high-critical TOGs
  3. Prioritization of protection measures
Introduction Video Monitoring (YouTube)

The video is hosted on YouTube. Playing it sends data to Google.

ISMS: Information Security Management System - Management system for information security

TOG (Target Object Group): Grouping of assets with similar protection requirements

Building Block: Modular unit in BSI-Grundschutz for structuring security requirements

CIP: Continuous Improvement Process according to PDCA cycle

PDCA: Plan-Do-Check-Act - Management cycle for continuous improvement

  1. Flexible Monitoring: The monitoring module offers flexible analysis possibilities for all ISMS levels through various source combinations

  2. Template-based: Recurring evaluations can be saved as templates and efficiently reused

  3. Compliance Evidence: Export functions enable audit-proof documentation for audits and certifications

  4. Customizable: Views can be adapted to specific requirements and saved

  5. Integrated: The monitoring module complements dashboard and reports with a detailed analysis perspective for continuous ISMS management