Skip to content

Settings

In the ISMS application options, you define basic settings that affect the entire ISMS – from protection goals through risk matrix configurations to import functionalities.

Why is this relevant?

  • Individual adaptation of the ISMS to your organizational requirements
  • Standardization of assessment methods and risk matrices
  • Efficient data transfer from existing systems
  • Consistent protection goal definitions and adjustments

The Three Primary Protection Goals of Information Security

Section titled “The Three Primary Protection Goals of Information Security”

Confidentiality

  • Protection against unauthorized disclosure of information
  • Confidential data may only be accessible to authorized persons in the permissible manner
  • Examples: Customer data, patents, research data, personal data (GDPR)
  • Practical risks: Open flipcharts after strategy meetings, accessible customer data in offices with public traffic

Integrity

  • Ensuring the correctness and integrity of data
  • Protection against unauthorized modification, deletion, or insertion of data
  • Also includes metadata such as author or creation time
  • Practical example: Manipulation of measurement data from medical devices can have serious consequences

Availability

  • Ensuring that systems and information are usable as intended
  • Permanent availability not necessarily required
  • Definition via Service Level Agreements (SLAs)
  • Example: Payroll system only needs to be available at defined times

config-1

In certain contexts, additional protection goals can be defined:

  • Authenticity: Genuineness and credibility of information
  • Non-repudiation: Provability of actions
  • Accountability: Legal binding to transactions
  • Reliability: Consistent system performance

Note: You can also adjust the values (attributes) of individual protection goals in the fuentis Suite.

Accessing the Configuration:

  1. Switch to the ISMS module
  2. Click on the gear symbol (bottom left) for application options
  3. Navigate to the “Protection Goals” category
  4. Click on “Create”

Important Note:

Adding a new protection goal affects ALL target object groups! Already submitted or approved protection requirement assessments will be automatically unlocked and must be edited again.

Configuration Steps:

  1. Assign names: German and English
  2. Define values (minimum 2, recommended 3):
    • Choose weighting level: Very low, Low, Normal, High, Very high, Critical
    • German and English designation for each value
  3. Save: Click on “Create”

config-2

config-3

Editing:

  • Click on the edit symbol in the corresponding row
  • Adjustment of names and values possible
  • Changes affect the entire system

config-4

Deleting:

  • Click on the delete symbol
  • Deletion process takes a moment
  • Push notification confirms successful deletion
  • Caution: Deletion can have far-reaching effects

config-5

The risk matrix is the central element for risk assessment. In the application options, you can:

config-6

Adjust Matrix Dimensions:

  • 3x3, 4x4, 5x5, or 6x6 matrix selectable
  • Adaptation to organization-specific requirements
  • Translations available for all matrix sizes (except for some versions for 5x5)

config-7

Configure Value Ranges:

  • Probability of Occurrence: Percentage or qualitative scales
  • Damage Amount/Impact: Monetary values or categories
  • Risk Categories: Definition of acceptance areas

config-8

GRC Import:

  • Migration from existing GRC system
  • Transfer of risk data and measures
  • Mapping to fuentis Suite 4 structures

Verinice Import:

  • Data transfer from verinice.PRO
  • Preservation of links between objects
  • Automatic assignment to catalogs

Import Process:

  1. Application Options → Import
  2. Choose import type (GRC or Verinice)
  3. Click on “Import”
  4. Select catalog and unit
  5. Upload file via “Browse”
  6. “Import” to execute

Note: Please contact us for migration or import projects.

config-9

Automatic title generation enables:

  • Uniform designations for target objects
  • Entity-specific prefixes for different object types
  • Automatic counters for sequential numbering

Configuration:

  • Access: Application Options → Title Creation
  • Authorization: Role “Manage Title Prefixes” required
  • Settings per Entity:
    • Object type (TargetObject/Asset Group Type)
    • Title prefix
    • Counter value

config-10

Example Configuration:

IT System: IT-SYS-[001]
Network: NET-[001]
Room: ROOM-[001]
Process: PROC-[001]

Responsible parties map the governance structure of the ISMS and define clear responsibilities:

  • Role Assignment: Assignment of persons to functions in the ISMS
  • Decision Makers: Definition of approvers and contact persons
  • Traceability: Documentation of responsible parties for audit and compliance
  • Workflow Integration: Automatic notification in approval processes
  • Management of Responsible Parties
  • Access to Configuration
Name (required): Full name of the person
Function: Professional role or position (e.g., ISMS Manager, IT Security Officer)
Phone: Phone number for direct contact
Email (required): Email address for notifications
Unit (required): Organizational assignment (Units dropdown)

Practical Application:

  • Notifications are sent to the stored email
  • Unit assignment enables organization-specific responsibilities
  • Particularly important for risk acceptances and measure approvals

config-11

Purpose and Benefits ISMS profiles enable the management of different security configurations for different contexts:

  • Multi-tenant Support: Separate profiles for different organizations or departments
  • Best Practice Templates: Predefined profiles for standards (ISO 27001, BSI-Grundschutz)
  • Quick Implementation: Standard configurations for new projects or locations
  • Compliance Variations: Profiles adapted to regulatory requirements
  • Structure and Management of ISMS Profiles
  • Access to Configuration:
  • Switch to the ISMS module
  • Click on the gear symbol (bottom left) for application options
  • Navigate to “ISMS Profiles”
  • Profile Properties (editable):
  • Name (required): Designation of the profile (e.g., “ISO - Mechatec GmbH”)
  • Author: Creator or responsible person of the profile
  • Applicable Business Areas: Categories such as Manufacturing, IT Services, Services
  • Applicable Company Sizes: Size classes (Micro, Small, Medium, Large) for which the profile is relevant
  • Active: Toggle to activate/deactivate the profile
  • Description: Documentation of profile purpose and scope of application
  • Upload: ZIP file with profile configuration and catalogs

Advantages

  • Quick implementation for new organizational units
  • Compliance templates for regulated industries
  • Standardized assessment criteria and risk matrices
  • Export and import of configurations between systems

Note: Attention, this function is only available to Professional customers or Enterprise customers.

Note: You can download any scope as a profile.

config-12

Here you can control and enter the white and black list of emails per unit from which you want to receive incidents.

ISMS: Information Security Management System - Management system for information security

Protection Goal: Security objective for protecting information (confidentiality, integrity, availability)

Risk Matrix: Two-dimensional representation for risk assessment based on probability of occurrence and impact

TOG: Target Object Group - Target object group as structural element in the ISMS

Entity: Organizational unit within the fuentis Suite

Scope: Area of application of the ISMS

SLA: Service Level Agreement - Agreement on availability

  1. Protection goals are fundamental: The definition and weighting of protection goals influences the entire ISMS - plan changes carefully.

  2. Choose risk matrix size consciously: The matrix dimension should match the organization size and risk complexity - more detail also means more effort.

  3. Prepare import well: Ensuring data quality before import saves time and avoids errors in the productive system.

  4. Use automation: Automatic title generation creates consistency and saves time in object creation.

  5. Keep performance in view: For large amounts of data and complex matrices, ensure sufficient system resources.