Skip to content

Monitoring

Continuous monitoring of the Information Security Management System (ISMS) is a central component of ISO 27001 and IT-Grundschutz. Effective monitoring enables organizations to track the progress of their security measures, identify weaknesses in documentation early, and demonstrably fulfill compliance requirements.

The fuentis Suite offers a comprehensive solution with the monitoring module that goes beyond classic dashboards and reports. The module enables detailed evaluations at various ISMS levels and creates transparency about the implementation status of building blocks, requirements, measures, and controls.

The monitoring module of the fuentis Suite enables monitoring at various structural levels:

  • Building Blocks: Superordinate security modules according to BSI-Grundschutz or custom structuring
  • Requirements: Specific security requirements within the building blocks
  • Measures: Concrete implementation steps to fulfill the requirements
  • Controls: Review mechanisms for effectiveness control (ISO 27001 Annex A)
  • Target Object Groups (TOGs): Grouping of assets and protection objects

Navigation: ISMS → Monitoring

The module starts out empty. The evaluation below only appears once you have created a monitoring template via + Create template and assigned it a source — in the example Building blocks → Requirements. Without a template the view stays empty.

How a template is created is covered below under Step 1: Create Template.

monitoring-1

  1. Navigate to the “Monitoring” tab in the ISMS module
  2. Click on the dropdown of available templates
  3. Click on ”+ Add New”
  4. Enter a meaningful name (e.g., “Q4-2025 Compliance Check”)
  5. Select the relevant organizational unit
  6. Important: Choose the source carefully. It decides what the analysis can show.
  7. Save the template

monitoring-3

After creation, the template appears in the left column of the overview:

  • Left column lists every template you have created
  • Right side shows the details of the template you picked
  • At the top, the evaluation gives you the headline numbers
  • Below that, the table lets you drill down

What you can do here:

  • Expand and collapse the hierarchy with the arrows
  • Jump straight to a linked element
  • Read implementation status off the colour coding

monitoring-4

The gear symbol in the upper right opens the customization options:

Columns:

  • Show or hide individual data fields
  • Reorder the columns
  • Set a default view

monitoring-5

Save Options:

  • Save applies your changes to this template only
  • Save All applies them to every template
  • Reset and Reset All restore the default view

Use the export button to document where monitoring stands:

  1. Select the desired template
  2. Click on “Export” (upper right)
  3. Automatic download as PDF file
  4. PDF contains:
    • Selected key figures and metrics
    • Tabular overview according to configuration
    • Timestamp and version information

Practice Tip: Create regular exports for:

  • Management reports (monthly/quarterly)
  • Audit documentation
  • Progress evidence for certifications

monitoring-6

Deleting a template:

  1. Click the delete icon in the template overview
  2. Confirm in the pop-up
  3. The template is gone for good

monitoring-7

Best Practices for Template Management:

  • Create templates for recurring evaluations
  • Use descriptive names with date/purpose
  • Archive templates that are no longer needed by exporting before deletion

Monitoring in the fuentis Suite runs on templates:

  1. Create a template and decide what you want to look at
  2. Pick a source, which sets both the elements you monitor and how they relate
  3. Choose the unit the template applies to
  4. Configure the evaluation: what is shown, and which numbers

monitoring-2

Which source you pick decides what the analysis can answer.

Hierarchical:

  • Building blocks → requirements: which requirements sit under which block
  • Building blocks → measures: which measures a block has produced
  • Requirements → measures: which measure covers which requirement

Single element:

  • Building blocks on their own
  • Measures: how far implementation has got
  • Requirements: where each one stands
  • Controls: what is in place to check effectiveness

Asset-related:

  • Building blocks → target object groups: which blocks touch which assets
  • Measures → target object groups: which measures protect what
  • Requirements → target object groups: what is required of a given asset group
  • Controls → target object groups: controls arranged by target object

Practice tip: Let the question drive the source.

  • Proving compliance? Building blocks → requirements
  • Tracking implementation? Requirements → measures
  • Judging risk per asset? Anything paired with target object groups

The monitoring module supports the PDCA cycle:

Plan: Define monitoring templates for the ISMS areas that matter most Do: Run the monitoring regularly Check: Analyse the results and work out what could be better Act: Derive corrective measures and carry them out

Goal: Evidence of ISO 27001 conformity

Note: The gap analysis module is worth using here as well.

Procedure:

  1. Template “ISO 27001 Compliance” with source “Controls”
  2. Filter for Annex A controls
  3. Export for external audit

Goal: Monitoring of an ISMS implementation project

Procedure:

  1. Template “ISMS Project Q4” with source “Requirements → Measures”
  2. Weekly updates
  3. Traffic light display for project control

Goal: Security status of critical assets

Procedure:

  1. Template “Critical Systems” with source “Measures → Target Object Groups”
  2. Focus on high-critical TOGs
  3. Prioritization of protection measures
Introduction Video Monitoring (YouTube)

The video is hosted on YouTube. Playing it sends data to Google.

ISMS: Information Security Management System - Management system for information security

TOG (Target Object Group): Grouping of assets with similar protection requirements

Building Block: Modular unit in BSI-Grundschutz for structuring security requirements

CIP: Continuous Improvement Process according to PDCA cycle

PDCA: Plan-Do-Check-Act - Management cycle for continuous improvement