Structural Analysis
Introduction Video
Section titled “Introduction Video”Overview
Section titled “Overview”Structural analysis is the first step in building an Information Security Management System (ISMS) according to ISO 27001 or IT-Grundschutz. In this phase, the boundaries of the ISMS are defined, all relevant IT assets are inventoried, and their dependencies are documented. The fuentis Suite supports you with a structured, modular approach.
Why is structural analysis important?
- Creates clear responsibilities for information security
- Focuses resources on critical areas
- Forms the basis for systematic risk management
- Facilitates ISO 27001 certification
Navigation: ISMS → Inventory
Structural analysis requires a defined scope and provides the basis for the protection requirements assessment:
- Scope definition (scoping): setting the boundaries of the ISMS
- Protection requirements assessment: assessing the criticality of the recorded target objects
Navigating the main tree
Section titled “Navigating the main tree”When you are in the Structural Analysis phase, the navigation tree on the left side of the screen plays a central role. There you have an overview of all scopes and their target object groups. Using the arrows, you can expand the various scopes or target object types. When you hover over a scope with the mouse, you see an “arrow in circle” symbol; clicking on it takes you to the detail view of the scope. You can search and filter the tree to get to the desired entries faster.


Note: When you click on target object types (e.g., Information, Business processes, etc.), you see a tabular overview of all target objects of this type within the respective scope. When you click on a target object, you see the respective detail view of the target object.
Note: The main tree is only visible for users with the active permission “Structural Analysis – Read Lists.”
The scope defines the boundaries of your ISMS and determines which parts of the organization are covered, including processes, systems and information assets. Every unit in fuentis automatically has a default scope; further ones you create yourself.
How to create and maintain scopes, which tabs the detail view has and how protection requirement categories are defined there is covered on Scope definition (scoping).
Target Object Groups (TOGs)
Section titled “Target Object Groups (TOGs)”TOGs are logical groupings of similar assets or information values. This grouping simplifies management and ensures consistent protective measures.
The 12 TOG Types in fuentis:
- Domain - Superordinate organizational areas
- Information - Data and information stocks
- Business Process - Operational and supporting processes
- Application - Software and applications
- IT System - Servers, clients, network components
- Network - Network infrastructure
- Room - Server rooms, offices
- Employee - Personnel resources
- Physical Facility - Hardware, equipment
- Building - Locations and properties
- Infrastructure - Supporting systems
- Outsourcing - External service providers
Authorization Concept (Structural Analysis)
Section titled “Authorization Concept (Structural Analysis)”For working with the structural analysis, users need specific roles and permissions:
Global Role
Section titled “Global Role”- ISMS_INVENTORY_ANALYSIS_ACCESS - Basic requirement for access
Detailed Permissions
Section titled “Detailed Permissions”Note: You can read more about the authorization concept of the fuentis Suite in the Permissions section. It is important that roles must be created and assigned independently. Simply assigning the “Global Access Roles” is not sufficient to gain access to individual areas.
For Scopes:
- Scopes - Read
- Scopes - Create
- Scopes - Edit
- Scopes - Delete
- Scopes - Link
For Target Object Groups:
- Target Object Groups - Read
- Target Object Groups - Create
- Target Object Groups - Edit
- Target Object Groups - Delete
- Target Object Groups - Link


Practical Implementation
Section titled “Practical Implementation”The scope has to exist before you record target object groups. Creating one is covered on Scope definition (scoping).
1. Create Target Object Groups (TOGs)
Section titled “1. Create Target Object Groups (TOGs)”

Systematic Approach:
-
Record Business Processes (GP001, GP002…)
- Identify core processes
- Document support processes
- Record dependencies
-
Inventory Applications (A001, A002…)
- Identify critical software
- Link with business processes
- Document interfaces
-
Record IT Systems (S001, C001, L001…)
- Group servers
- Consolidate client systems
- Record network components
-
Document Premises (R001, GB001…)
- Server rooms
- Office buildings
- External locations
Best Practice for Naming Conventions:
[Type-Abbreviation][Number] [Description]Examples:- GP002 Quotation Process- A022 CRM System- S015 Exchange Server- R001 Server Room 3rd FloorNote: You can customize the automatic title creation. You can find this setting in the ISMS settings (gear symbol at the bottom left).
Practice Tip: Status: Choose the status of the target object group here.
- Planned/In Conception: Important for the planning phase before implementation.
- Ordered/In Creation: Signals that something is officially ordered or in the manufacturing process.
- Provided: Object or resource is available but not yet in use.
- In Test: Required when tests are necessary before commissioning.
- In Operation: Standard status for actively used resources or processes.
- Defective: Necessary to mark problems or errors.
- In Repair/In Exchange: Important for service and maintenance processes.
- Decommissioned: Required for end-of-life management (e.g., for IT hardware or machines).
Term Definition: The terms Target Object; ZO (Target Object; TO), Target Object Group; ZOG (Target Object Group; TOG) and Asset, Asset Groups are easily confused. The terms Target Object (ZO), Target Object Group (ZOG) as well as Asset and Asset Group are often used similarly but have different meanings:
-
Target Object (ZO / Target Object, TO):
A single, concrete object that is considered within the scope – e.g., a server, a business application, or a building. -
Target Object Group (ZOG / Target Object Group, TOG):
A group of target objects with common properties that can be managed or assessed together – e.g., “Client PCs in Sales” or “Data Center North.” -
Asset / Asset Group:
Assets can be both material (e.g., hardware, rooms) and immaterial (e.g., data, reputation). Assets in the fuentis Suite are “real” unique “Configuration Items” and are also considered as such in Asset Management. You can learn more about Asset Management in the Asset Management section.
Status and Detail View
Section titled “Status and Detail View”In the upper part of this view is the status bar, which displays some basic information about the TOG: Name, Title, etc. You will also find the “Delete” and “Linked Objects” buttons.

Similar to scopes, you will also find several tabs in the detail view area for target objects. Here you can navigate to the individual functions.

In the “Details” tab you will find the following sections:
- Basic Data: Information about the name, title, status, etc. of the TOG.
- IT-Grundschutz: Data on IT-Grundschutz for the selected TOG (protection requirements, relevance for KRITIS, handling of personal data, etc.).
- Reviewed: Information about the review process of the structural analysis (was the structural analysis reviewed, who reviewed, when was this process carried out, etc.).
- Approved: Information about the approval process of the structural analysis (was the structural analysis approved, who approved, when was this process carried out, etc.).
Delete
Section titled “Delete”You can permanently delete a TOG in its detail view using the “Delete” button. Attention: there is no trash function.
Note: You can only delete TOGs that are not linked to other objects. You must first remove all links.
2. Link Target Object Groups
Section titled “2. Link Target Object Groups”Understanding TOG Hierarchies
Section titled “Understanding TOG Hierarchies”fuentis follows a logical hierarchy for TOG linking based on the 12 predefined types. Understanding these relationships is crucial for proper structural analysis:
Hierarchy Overview:
- Domain (highest level) encompasses all organizational areas
- Information and Business Process are core operational elements
- Application supports business processes
- IT System hosts applications
- Network and Infrastructure support IT systems
- Room and Building provide physical housing
- Physical Facility and Employee are foundational resources
- Outsourcing can be subordinate to any other type
Detailed Hierarchy Rules:
- Domain is superordinate to all other TOG types.
- Information is subordinate to Domain and superordinate to Business Process.
- Business Process is subordinate to Domain/Information and superordinate to Application/Outsourcing.
- Application is subordinate to Domain/Information/Business Process and superordinate to IT System, Physical Facility, Employee, Outsourcing.
- IT System is subordinate to Application and superordinate to Network, Infrastructure, Room, Physical Facility, Employee, Outsourcing.
- Network is subordinate to IT System and superordinate to Employee/Outsourcing.
- Room is subordinate to IT System/Infrastructure and superordinate to Building, Physical Facility, Employee, Outsourcing.
- Building is subordinate to Room and superordinate to Employee, Outsourcing, Physical Facility.
- Physical Facility is subordinate to Application, IT System, Infrastructure, Room, Building and superordinate to Employee.
- Employee is superordinate to multiple TOGs but can be subordinate to Outsourcing.
- Outsourcing is always subordinate to other TOGs but cannot be superordinate to any parent TOG.
Linking Rules:
- Domains can be linked with all subordinate ZOG types
- Business processes connect with applications and outsourcing
- IT systems need links to network and infrastructure
- Employees are assigned to relevant systems and rooms




Practice Tip: Use the “Linked Objects” view in fuentis to visualize direct and indirect dependencies. Red arrows show direct, gray arrows show indirect links. You can find this button in the left area below the status bar. There you can switch between table view and tree view.


Practice Tip: Use the blue hierarchy level in the upper area of the screen. Here you can navigate quickly and always keep track of where you currently are. You can also always open a left sidebar via the “Linked Objects” button in the upper right area, which enables quick navigation to all indirect links. You can expand and select objects like in the main navigation tree.
Assign ZOGs to Scopes
Section titled “Assign ZOGs to Scopes”Target object groups can be assigned to one or more scopes.

3. Assign Assets
Section titled “3. Assign Assets”Concrete assets are assigned to TOGs in the “Included Assets” tab:
- Select TOG
- Open “Included Assets” tab
- Click “Add” button
- Select and assign relevant assets


Note: If you do not have permissions for the Asset Management model, you cannot assign assets. Also make sure that you have already added assets to your Asset Management.
Practice Tip: Start without assets first, as these often change faster than the “abstract” form of your security concept through updates or device replacement. You can therefore basically create your ISMS first based on the target object groups.
Integration with ISO 27001 and IT-Grundschutz
Section titled “Integration with ISO 27001 and IT-Grundschutz”ISO 27001 Compliance
Section titled “ISO 27001 Compliance”The structural analysis in fuentis meets the requirements of ISO 27001:
- Clause 4.3: Definition of ISMS scope
- Clause 8.1: Asset inventory
- Annex A.8: Asset Management Controls
IT-Grundschutz Integration
Section titled “IT-Grundschutz Integration”For each TOG, IT-Grundschutz-specific data can be recorded:
- Protection requirements: normal, high or very high, see Protection requirements assessment
- KRITIS Relevance: Critical infrastructures
- Personal Data: Data protection relevance
- Availability Requirements: SLAs and RPO/RTO
How the fuentis Suite Supports
Section titled “How the fuentis Suite Supports”Automation and Efficiency
Section titled “Automation and Efficiency”- Templates: Reusable TOG templates
- Bulk Operations: Mass editing of TOGs (Additional functions are on the roadmap)
- Export: Excel integration for inventory data
- Inheritance: Automatic protection requirements inheritance
Visualization and Reporting
Section titled “Visualization and Reporting”- Main Tree View: Hierarchical display of all elements
- Dependency Diagrams: Graphical link representation
- Audit Trail: Complete change documentation
- Dashboard: Real-time overview of ISMS status
Workflow Integration
Section titled “Workflow Integration”- Review Process: Structured review
- Approval Workflows: Multi-stage approvals
- Notifications: Automatic status updates
- Role-based Views: Customized user interfaces
Common Challenges and Solutions
Section titled “Common Challenges and Solutions”Challenge: Too Detailed Structural Analysis
Section titled “Challenge: Too Detailed Structural Analysis”Problem: Hundreds of individual assets complicate management
Solution: Group similar assets into TOGs, e.g., “Office PCs Floor 3” instead of individual computers
Challenge: Unclear Dependencies
Section titled “Challenge: Unclear Dependencies”Problem: Cascade effects during failures not recognizable
Solution: Systematic linking of all TOGs, regular review of dependencies
Challenge: Missing Documentation
Section titled “Challenge: Missing Documentation”Problem: Existing IT landscape not completely recorded
Solution: Gradual recording, use of automatic discovery tools, workshops with IT managers
Challenge: Import of Existing Information
Section titled “Challenge: Import of Existing Information”Problem: You already have a list of assets you want to import.
Solution: We can work with you to find a solution for how to automatically import this content into the fuentis Suite. Please feel free to contact us!