Settings
In the ISMS application options, you define basic settings that affect the entire ISMS – from protection goals through risk matrix configurations to import functionalities.
Why is this relevant?
- Individual adaptation of the ISMS to your organizational requirements
- Standardization of assessment methods and risk matrices
- Efficient data transfer from existing systems
- Consistent protection goal definitions and adjustments
Configuration Areas
Section titled “Configuration Areas”1. Protection Goals
Section titled “1. Protection Goals”The Three Primary Protection Goals of Information Security
Section titled “The Three Primary Protection Goals of Information Security”Confidentiality
- Protection against unauthorized disclosure of information
- Confidential data may only be accessible to authorized persons in the permissible manner
- Examples: Customer data, patents, research data, personal data (GDPR)
- Practical risks: Open flipcharts after strategy meetings, accessible customer data in offices with public traffic
Integrity
- Ensuring the correctness and integrity of data
- Protection against unauthorized modification, deletion, or insertion of data
- Also includes metadata such as author or creation time
- Practical example: Manipulation of measurement data from medical devices can have serious consequences
Availability
- Ensuring that systems and information are usable as intended
- Permanent availability not necessarily required
- Definition via Service Level Agreements (SLAs)
- Example: Payroll system only needs to be available at defined times

Extended Protection Goals
Section titled “Extended Protection Goals”In certain contexts, additional protection goals can be defined:
- Authenticity: Genuineness and credibility of information
- Non-repudiation: Provability of actions
- Accountability: Legal binding to transactions
- Reliability: Consistent system performance
Note: You can also adjust the values (attributes) of individual protection goals in the fuentis Suite.
2. Managing Protection Goals
Section titled “2. Managing Protection Goals”Creating a New Protection Goal
Section titled “Creating a New Protection Goal”Accessing the Configuration:
- Switch to the ISMS module
- Click on the gear symbol (bottom left) for application options
- Navigate to the “Protection Goals” category
- Click on “Create”
Important Note:
Adding a new protection goal affects ALL target object groups! Already submitted or approved protection requirement assessments will be automatically unlocked and must be edited again.
Configuration Steps:
- Assign names: German and English
- Define values (minimum 2, recommended 3):
- Choose weighting level: Very low, Low, Normal, High, Very high, Critical
- German and English designation for each value
- Save: Click on “Create”


Editing and Deleting Protection Goals
Section titled “Editing and Deleting Protection Goals”Editing:
- Click on the edit symbol in the corresponding row
- Adjustment of names and values possible
- Changes affect the entire system

Deleting:
- Click on the delete symbol
- Deletion process takes a moment
- Push notification confirms successful deletion
- Caution: Deletion can have far-reaching effects

3. Risk Matrix Configuration
Section titled “3. Risk Matrix Configuration”Setting Options
Section titled “Setting Options”The risk matrix is the central element for risk assessment. In the application options, you can:

Adjust Matrix Dimensions:
- 3x3, 4x4, 5x5, or 6x6 matrix selectable
- Adaptation to organization-specific requirements
- Translations available for all matrix sizes (except for some versions for 5x5)

Configure Value Ranges:
- Probability of Occurrence: Percentage or qualitative scales
- Damage Amount/Impact: Monetary values or categories
- Risk Categories: Definition of acceptance areas

4. Import Functionalities
Section titled “4. Import Functionalities”Available Import Options
Section titled “Available Import Options”GRC Import:
- Migration from existing GRC system
- Transfer of risk data and measures
- Mapping to fuentis Suite 4 structures
Verinice Import:
- Data transfer from verinice.PRO
- Preservation of links between objects
- Automatic assignment to catalogs
Import Process:
- Application Options → Import
- Choose import type (GRC or Verinice)
- Click on “Import”
- Select catalog and unit
- Upload file via “Browse”
- “Import” to execute
Note: Please contact us for migration or import projects.

5. Automatic Title Generation
Section titled “5. Automatic Title Generation”Functionality
Section titled “Functionality”Automatic title generation enables:
- Uniform designations for target objects
- Entity-specific prefixes for different object types
- Automatic counters for sequential numbering
Configuration:
- Access: Application Options → Title Creation
- Authorization: Role “Manage Title Prefixes” required
- Settings per Entity:
- Object type (TargetObject/Asset Group Type)
- Title prefix
- Counter value

Example Configuration:
IT System: IT-SYS-[001]Network: NET-[001]Room: ROOM-[001]Process: PROC-[001]6. Responsible Parties
Section titled “6. Responsible Parties”Meaning and Purpose
Section titled “Meaning and Purpose”Responsible parties map the governance structure of the ISMS and define clear responsibilities:
- Role Assignment: Assignment of persons to functions in the ISMS
- Decision Makers: Definition of approvers and contact persons
- Traceability: Documentation of responsible parties for audit and compliance
- Workflow Integration: Automatic notification in approval processes
- Management of Responsible Parties
- Access to Configuration
Name (required): Full name of the personFunction: Professional role or position (e.g., ISMS Manager, IT Security Officer)Phone: Phone number for direct contactEmail (required): Email address for notificationsUnit (required): Organizational assignment (Units dropdown)Practical Application:
- Notifications are sent to the stored email
- Unit assignment enables organization-specific responsibilities
- Particularly important for risk acceptances and measure approvals

7. ISMS Profiles
Section titled “7. ISMS Profiles”Purpose and Benefits ISMS profiles enable the management of different security configurations for different contexts:
- Multi-tenant Support: Separate profiles for different organizations or departments
- Best Practice Templates: Predefined profiles for standards (ISO 27001, BSI-Grundschutz)
- Quick Implementation: Standard configurations for new projects or locations
- Compliance Variations: Profiles adapted to regulatory requirements
- Structure and Management of ISMS Profiles
- Access to Configuration:
- Switch to the ISMS module
- Click on the gear symbol (bottom left) for application options
- Navigate to “ISMS Profiles”
- Profile Properties (editable):
- Name (required): Designation of the profile (e.g., “ISO - Mechatec GmbH”)
- Author: Creator or responsible person of the profile
- Applicable Business Areas: Categories such as Manufacturing, IT Services, Services
- Applicable Company Sizes: Size classes (Micro, Small, Medium, Large) for which the profile is relevant
- Active: Toggle to activate/deactivate the profile
- Description: Documentation of profile purpose and scope of application
- Upload: ZIP file with profile configuration and catalogs
Advantages
- Quick implementation for new organizational units
- Compliance templates for regulated industries
- Standardized assessment criteria and risk matrices
- Export and import of configurations between systems
Note: Attention, this function is only available to Professional customers or Enterprise customers.
Note: You can download any scope as a profile.

8. Incident Management
Section titled “8. Incident Management”Here you can control and enter the white and black list of emails per unit from which you want to receive incidents.
Glossary
Section titled “Glossary”ISMS: Information Security Management System - Management system for information security
Protection Goal: Security objective for protecting information (confidentiality, integrity, availability)
Risk Matrix: Two-dimensional representation for risk assessment based on probability of occurrence and impact
TOG: Target Object Group - Target object group as structural element in the ISMS
Entity: Organizational unit within the fuentis Suite
Scope: Area of application of the ISMS
SLA: Service Level Agreement - Agreement on availability
Key Messages at a Glance
Section titled “Key Messages at a Glance”-
Protection goals are fundamental: The definition and weighting of protection goals influences the entire ISMS - plan changes carefully.
-
Choose risk matrix size consciously: The matrix dimension should match the organization size and risk complexity - more detail also means more effort.
-
Prepare import well: Ensuring data quality before import saves time and avoids errors in the productive system.
-
Use automation: Automatic title generation creates consistency and saves time in object creation.
-
Keep performance in view: For large amounts of data and complex matrices, ensure sufficient system resources.