Security Check
In the modern working world, information has become a critical resource. Its protection is not only a technical challenge but a strategic necessity for every organization. ISMS modeling (Information Security Management System) forms the heart of a systematic approach to information security.
Why is ISMS modeling relevant?
Section titled “Why is ISMS modeling relevant?”Information represents the “knowledge” of an organization – an essential resource for modern management systems. The structured modeling of security requirements enables:
- Compliance requirements to be systematically fulfilled (ISO 27001, BSI IT-Grundschutz)
- Security risks to be assessed and treated object-specifically
- Protective measures to be applied specifically to assets (TOGs) and scopes
- Audit capability to be ensured through traceable documentation
Core Concepts of ISMS Modeling
Section titled “Core Concepts of ISMS Modeling”The Four Pillars of Security Modeling
Section titled “The Four Pillars of Security Modeling”ISMS modeling is based on four central security objects that build upon each other:
Attention: This approach is oriented to both standards (ISO) and BSI - however, you can also omit the corresponding functions respectively.
1. Modules
Section titled “1. Modules”Modules are thematic groupings of security requirements, threats, and measures.
Properties:
- Categorization by protection areas (e.g., network security, access control)
- Link with TOGs (Target Objects) and scopes
- Automatic status calculation based on linked requirements
- Audit tracking with documentation of audit cycles

2. Requirements
Section titled “2. Requirements”Concrete security specifications that must be fulfilled to ensure protection.
Properties:
- Detailed description of the security specification
- Implementation status (Implemented, Partial, Not implemented, Dispensable)
- Link with review questions for audits
- Assignment to superordinate modules

3. Measures
Section titled “3. Measures”Practical implementation steps to fulfill the requirements.
Properties:
- Concrete action instructions
- Responsibility assignment
- Temporal planning and prioritization
- Link with multiple requirements possible

4. Controls
Section titled “4. Controls”Review mechanisms to validate measure implementation.
Properties:
- Review criteria and methods
- Audit cycles and evidence
- Effectiveness assessment
- Integration into continuous improvement management

Status Calculation and Assessment Logic
Section titled “Status Calculation and Assessment Logic”The fuentis Suite uses intelligent status calculation that automatically aggregates the implementation level:
Status Logic for Modules
Section titled “Status Logic for Modules”- UNDEFINED: At least one linked element has undefined status
- IMPLEMENTED: All linked elements are implemented or dispensable
- NOT IMPLEMENTED: All linked elements are not implemented
- PARTIAL: Mixed implementation status (standard case)
Practice Tip: Automatic status calculation enables real-time overview of security status. Use dashboard views for management reporting!
Note: Modules calculate from the total status of all linked requirements and measures.

Assessment Cascading
Section titled “Assessment Cascading”Status propagates from bottom to top:
- Measures → Requirements
- Requirements → Modules
- Modules → TOG/Scope overall status
This cascading ensures that the overall status always reflects the weakest point (conservative principle).
Note: You can also shorten the chain directly at requirements and measures.
Working with the Security Check Phase
Section titled “Working with the Security Check Phase”Access Control and Permissions
Section titled “Access Control and Permissions”Access to the modeling phase is controlled through a granular permission system:
Global Role:
ISMS_SECURITY_CHECK_ACCESS: Basic requirement for access
Function-specific Permissions:
- Modules: Read, Create, Edit, Delete, Add Reference
- Requirements: Read, Create, Edit, Delete, Convert to Custom
- Measures: Read, Create, Edit, Delete, Link
- Controls: Read, Edit, Delete
- Review Questions: Create, Edit, Delete
Object Assignment and Referencing
Section titled “Object Assignment and Referencing”A central feature is flexible object assignment:
Direct Assignment:
- Catalog-based objects from standards (ISO, BSI)
- User-defined objects for specific requirements
Referencing:
- Reuse of already assigned objects
- Cross-TOG references for consistent requirements
- Avoidance of redundancies
Practice Tip: Use references for company-wide application! Defined once, applied multiple times.

Review Questions and Audit Integration
Section titled “Review Questions and Audit Integration”Review questions form the bridge between requirements and audits:
Functionality:
- Definition of specific review criteria per requirement
- Structured recording of audit results
- Evidence documentation and document management
- Automatic measure derivation for deviations
Best Practices for Implementation
Section titled “Best Practices for Implementation”1. Structured Approach
Section titled “1. Structured Approach”Phase 1: Foundation Modeling
- TOG structuring and scope definition
- Selection of relevant standard modules
- Initial status survey
Phase 2: Detailing
- Requirement adaptation to organizational context
- Definition of specific measures
- Responsibility assignment
Phase 3: Operationalization
- Implementation of measures
- Setup of controls
- Audit planning
2. Catalog vs. Custom Objects
Section titled “2. Catalog vs. Custom Objects”When to use standard catalogs?
- Basic compliance with ISO/BSI
- Industry standards
- Quick start
When to create custom objects?
- Organization-specific requirements
- Industry specifics
- Internal policies
3. Export/Import Workflow
Section titled “3. Export/Import Workflow”Offline editing enables:
- Bulk updates in Excel
- Review processes without system access
- Archiving for compliance evidence
Workflow:
- Export of relevant security objects (e.g. modules)
- Offline editing in a structured format
- Validation before re-import
- Import with automatic consistency check
Important: The import can only be error-free if the exported file is imported into the same target object group from which it was originally exported.
Practical Tip: Use the export for quarterly reviews! Stakeholders can make changes in their familiar Excel environment.

How the fuentis Suite Supports
Section titled “How the fuentis Suite Supports”The fuentis Suite offers an integrated environment for ISMS modeling:
Automation & Efficiency
Section titled “Automation & Efficiency”- Automatic status calculation reduces manual effort
- Bulk operations for efficient mass maintenance
- Template-based object creation
Collaboration & Workflow
Section titled “Collaboration & Workflow”- Role-based access for distributed teams
- Comment functions for coordination
- Versioning for traceability
Reporting & Compliance
Section titled “Reporting & Compliance”- Dashboard visualizations for management
- Compliance reports for auditors
- Export functions for external stakeholders
Glossary
Section titled “Glossary”TOG (Target Object Group): Grouping of assets with similar security requirements
Scope: Area of application of the ISMS, defines organizational and technical boundaries
Security Object (SO): Generic term for modules, requirements, measures, and controls
Custom Object: User-defined security object outside of standard catalogs
Review Question (RQ): Structured review question for audit execution
Key Messages at a Glance
Section titled “Key Messages at a Glance”✓ Structured Security: ISMS modeling transforms abstract security requirements into concrete, traceable measures
✓ Automated Compliance: Through catalog integration and status calculation, compliance management becomes efficient and transparent
✓ Flexible Adaptation: The combination of standard catalogs and custom objects enables tailored security concepts
✓ Audit-Ready: Integrated review questions and evidence ensure audit readiness at all times
✓ Continuous Improvement: The linking of requirements, measures, and controls creates a closed improvement cycle