# fuentis Service Hub — Full Corpus > Knowledge and documentation platform for fuentis trust: ISMS, BCMS, data protection and the related standards. Built: 2026-08-03. 48 pages, source: https://servicehub.fuentis.com/ # General ## All About the Service Hub Source: https://servicehub.fuentis.com/en/allgemein/start/ The Service Hub is your central point of access for everything related to the fuentis Suite – especially for building and operating an ISMS according to ISO 27001 or BSI IT-Grundschutz. ### Understanding the User Interface ![fuentis Suite 4 - User Interface](../../../../assets/docs/allgemein/suite-demo-fuentis-com-isms-ia-0fac37b9-9799-4197-9341-2e8d322718d2-compl-scope-high-res.png) The fuentis Suite consists of seven main areas: **1. Module Display / Homepage** Your personalized homepage with widgets for quick access to relevant information. **2. Global Search & Filter** Full-text search across all items in the fuentis Suite with advanced filter options. **3. Service Hub Menu** Access to guides, quick-start materials, and knowledge on key topics. **4. Main Navigation** Access to individual modules such as ISMS, BCMS, or Support Modules. **5. Settings** Change language, activate dark mode, edit profile, change password, enable 2FA. **6. Module Navigation** The blue sidebar provides navigation for individual module functions (such as risk analysis or gap analysis). **7. Scope Navigation** Switch between scopes and security objects with search and filter functionality. --- ### What is a GRC/ISMS Tool? Imagine your organization is like a castle you want to protect. To do this, you need: - **Overview**: What needs to be protected? - **Assessment**: What threats exist? - **Plan**: Which measures will help? The fuentis Suite supports you as an integrated GRC system with: - **Governance**: Clear responsibilities and rules - **Risk**: Systematic identification and assessment of risks - **Compliance**: Proof of compliance with regulatory requirements --- ### A Pragmatic Starting Point **1. Start Analog** Take a moment to think and outline the framework: - What should your ISMS cover? - What is your initial scope? **2. Create a Scope** Example: "We start with the Hamburg site including data center and cloud connection." **3. Use Demo Environments** Open one of our demo environments to learn, e.g.: - ISO – AutoPart Solutions AG --- ### Next Steps 1. Work through the quick-start guide 2. Create a test project or open a demo environment 3. Contact support if you have questions --- ### Help & Support [**Service Desk**](https://fuentis.atlassian.net/servicedesk/customer/portal/1) If you have questions or run into issues: - Use the support button in the tool - Reach out to our experts We are happy to support you in getting started and in structuring your information security management. ## Demo Instance User Guide Source: https://servicehub.fuentis.com/en/allgemein/demo-instanz-benutzeranleitung/ **In 3 Steps to the Demo Instance:** 1. **Select a Role** → Choose from 7 preconfigured ISMS roles 2. **Test a Demo Company** → Use realistic sample data from 11 organizations 3. **Gain Hands-On Experience** → Walk through typical ISMS and BCMS processes --- ### Overview Our demo instance provides a fully configured ISMS environment with realistic roles, permissions, and sample organizations. You can experience different compliance approaches in practice, based on **BSI IT-Grundschutz** and **ISO 27001**. #### What to Expect: - **7 preconfigured ISMS roles** with specific permissions - **11 demo organizations** from different industries - **Realistic scenarios** for public administration and private sector - **Complete workflows** from risk analysis to certification --- ### ISMS Roles and Permissions #### 1. **Information Security Officer (ISO) / ISMS Owner** **Responsibility:** Full ISMS management and strategic leadership **Full access to:** - Authorization and rights management - Organizational unit and user account management - ISMS structural and protection needs analysis - Modeling and risk analysis - Asset management and reporting - BCMS (Business Continuity Management) **Best Practice:** Use this role for strategic decisions and compliance oversight. --- #### 2. **Risk Manager** **Responsibility:** Risk management and assessment **Permissions:** - Structural analysis (read, edit, create, delete, link) - Protection needs analysis (read, edit, recommend, distribute) - Risk analysis (full access incl. risk matrix management) - Controls management (read, edit, delete, assign) - Risk treatment plan reports (create) **Why important:** Risk management is at the heart of every ISMS – here you’ll learn practical application. --- #### 3. **External Service Provider (Consultant ISMS)** **Responsibility:** External consulting and audit support **Permissions (read-only):** - Structural analysis - Protection needs analysis - Risk analysis - Modeling - Reporting **Use case:** Ideal for consultants or external auditors with restricted access. --- #### 4. **IT and Technical Staff (Admin)** **Responsibility:** Technical implementation and system maintenance **Permissions:** - Organizational unit management (full access) - User and role management - Structural analysis (read) - Modeling (read, export, import) - BSI A1–A5 reports (read) **Pro Tip:** Use import/export functions for efficient model management. --- #### 5. **ISMS Project Manager / ISMS Lead** **Responsibility:** Project coordination and operational ISMS leadership **Full access to:** - Structural analysis - Protection needs analysis - Modeling and risk analysis - Asset management - Reporting - Rights management (read, create, edit, assign users) **Recommendation:** Perfect role for operational ISMS implementation. --- #### 6. **Internal Auditor** **Responsibility:** Internal auditing and compliance review **Permissions (read-only):** - Structural analysis - Protection needs analysis - Risk analysis and modeling - BSI and ISO standard reports **Audit focus:** Use extensive reporting for audit evidence. --- #### 7. **BCMS Manager** **Responsibility:** Business Continuity Management **Full access to:** - BCMS scopes - Initiation and business processes - Analysis/BIA (Business Impact Analysis) - BCMS reporting **Integration:** BCMS complements ISMS for holistic risk management. --- ### Demo Organizations #### BSI IT-Grundschutz Organizations ##### **City Administration Musterstadt** **Scenario:** Medium-sized municipality with digital citizen services **Challenges:** - Integrating legacy IT systems - Aiming for BSI IT-Grundschutz certification - Evolving WiBA basic requirements into a full ISMS - Secure handling of citizen data **Demo Users:** - Anna Schuster (IT Manager): a.schuster - Max Hoffmann (ISO): m.hoffmann - Lisa Weber (ISMS Consultant): l.weber - Daniel König (IT Admin): d.koenig **Learning:** Public sector, e-government, legacy integration --- ##### **University Hospital MediCare** **Scenario:** Large hospital with research and critical infrastructure **Special Features:** - KRITIS compliance - Patient data (GDPR-compliant) - High availability of medical IT systems - NIS2 implementation - ISMS + BCMS + DSMS integration **Demo Users:** - Dr. Julia Wagner (ISO): j.wagner - Thomas Becker (Risk Manager): t.becker - Lisa Weber (ISMS Consultant): l.weber - Daniel König (IT Admin): d.koenig **Learning:** Critical infrastructure, healthcare, multi-domain compliance --- > **Note:** The remaining demo organizations are currently described in the German version of this page only. --- ### Practical Application #### **Step 1: Select Role and Login** 1. Choose one of the 7 ISMS roles based on your interest 2. Log in with the provided demo credentials 3. Explore available menu options #### **Step 2: Explore Demo Organizations** 1. Switch between different demo organizations 2. Compare BSI and ISO approaches 3. Analyze industry-specific requirements #### **Step 3: Run ISMS Processes** 1. **Structural analysis:** Capture organizational structures 2. **Protection needs analysis:** Assess information assets 3. **Modeling:** Build IT-Grundschutz models 4. **Risk analysis:** Identify and evaluate risks 5. **Reporting:** Generate compliance reports --- ### Compliance Standards Compared #### **BSI IT-Grundschutz vs. ISO 27001** | Aspect | BSI IT-Grundschutz | ISO 27001 | |--------|--------------------|------------| | **Target group** | German authorities, critical infrastructure | International, all industries | | **Approach** | Module-based, prescriptive | Risk-based, flexible | | **Certification** | BSI certification | Accredited certifiers | | **Controls** | Predefined modules | Risk-adapted controls | | **Documentation** | Extensive, structured | Leaner, process-oriented | --- ### Key Notes > **Demo environment:** All data is fictional and for demonstration only. Do not use real company or personal data. > **Data reset:** The demo instance is reset regularly. Save your insights externally. > **Support:** For technical issues, please contact our support team. --- ### Next Steps #### **Start Now:** 1. **Choose a role** among the 7 ISMS positions 2. **Test 2–3 demo organizations** to compare approaches 3. **Run a complete ISMS cycle** from analysis to reporting #### **Deep Dive:** - Compare BSI and ISO standards directly - Test role-specific workflows - Explore reporting for different audiences #### **For Your Organization:** - Document best practices from the demo - Identify relevant compliance requirements - Plan your ISMS implementation based on demo experience --- **Start your ISMS demo experience now and discover how effective information security management works in practice!** ## Document Templates and Trainings Source: https://servicehub.fuentis.com/en/allgemein/isms-toolkit/ The ISMS Toolkit provides a comprehensive collection of document templates and training materials for the efficient implementation of an Information Security Management System (ISMS) in accordance with ISO 27001. These proven resources help organizations meet compliance requirements while saving time and resources. ### Why is a structured ISMS Toolkit relevant? Implementing an ISMS requires a wide range of specific documentation and policies. A standardized toolkit ensures: - **Compliance assurance**: Full coverage of ISO 27001 requirements - **Time savings**: Proven templates reduce the need to build documents from scratch - **Quality assurance**: Practical content minimizes the risk of gaps or errors - **Scalability**: Adaptable documentation for organizations of different sizes ### ISMS Document Templates #### Core Information Security Policies ##### Access and Authorization Management - **Policy – Use and Management of Passwords**: Secure password standards and handling - **Policy – Access Control**: Systematic monitoring of access rights - **Policy – Authorization Management**: Assignment and administration of user rights - **Policy – Authorization Principles**: Rules for granting privileges - **Policy – Role Description and Assignment**: Definition and allocation of security roles ##### Risk Management and Compliance - **Policy – Performing Risk Analyses**: Systematic risk identification and evaluation - **Policy – Control of Corrective and Preventive Actions**: Structured approach to deviations - **Policy – Control of Guidance and Evidence Documents**: Documentation management for audit evidence - **Policy – Internal Audits**: Planning and execution of ISMS audits ##### Technical Security Measures - **Policy – Malware Protection**: Prevention and handling of malware - **Policy – Secure Remote Access**: Protection of remote workplaces - **Policy – Use of Cryptographic Measures**: Encryption standards and practices - **Policy – Network Security Documentation Overview**: Security architecture for networks - **Policy – Operation of Printers, Copiers, and MFPs**: Securing peripheral devices ##### Organizational Security - **Policy – Infrastructure Security**: Physical and logical infrastructure protection - **Policy – Personnel Security**: Security aspects in HR processes - **Policy – Physical Security**: Protection of facilities and premises - **Policy – Training and Awareness**: Security awareness programs for employees #### Process and Service Management ##### Change and Configuration Management - **Policy – Change Procedures**: Controlled modifications to IT systems - **Policy – Change Management**: Structured implementation of changes - **Policy – Service Rollout and Go-Live**: Secure service introduction ##### Incident and Problem Management - **Policy – Handling Security Incidents**: Response to security events - **Policy – Information Security Incident Management**: Comprehensive incident process - **Policy – Handling Malfunctions**: Structured problem resolution ##### Service Quality and Control - **Policy – Service Level Management**: Definition and monitoring of SLAs - **Policy – Service Reports**: Regular reporting on service quality - **Policy – Business Relationship Management**: Managing supplier relationships #### Strategic and Governance Aspects ##### Outsourcing and Third Parties - **Policy – Outsourcing and Contractor Management**: Managing external service providers - **Policy – Outsourcing of Security-Related Services**: Requirements for critical services - **Policy – External ISB/DSB**: Integration of external security experts ##### Asset and Value Management - **Policy – Management of Organizational Assets**: Protecting company values - **Policy – Classification and Handling of Information**: Information classification - **Policy – IT Management**: IT governance and oversight #### Organizational Concepts - **Concept – ISMS Process Organization**: Process-level ISMS structure - **Concept – ISMS Organizational Structure**: Structural ISMS organization - **Template – Information Security Policy**: Foundational ISMS security statement ### ISMS Tool Trainings & Workshops #### Introduction and Basics ##### Project Initiation - **Slide Deck – ISMS Tool Introduction Project**: Key success factors for implementation - **Risk Analysis – ISMS Tool Introduction**: Identification and evaluation of implementation risks ##### User and Admin Documentation - **User Handbook**: Target-group-specific instructions in PDF format - **Admin Handbook**: Comprehensive administrator documentation - **Slide Deck – User/Admin Training**: Structured training materials #### Specialized Workshops ##### Strategy Development - **Workshop – ISMS Strategy Development**: Creating an organization-specific ISMS strategy - **Workshop – Central Policy Management for Integrated ISMS**: Establishing unified policy management ##### Emergency and Crisis Management - **Workshop – Emergency Planning**: Basics of business continuity - **Workshop – Building and Operating Crisis Management**: Practical implementation - **Template – Emergency Exercise Concept**: Structured exercise planning ##### Risk Management - **Workshop – Basic Risk Analysis Process**: Fundamentals of risk assessment - **Workshop – Risk Analysis**: Advanced methods and techniques - **Workshop – Structural Analysis and Protection Needs Assessment**: IT-Grundschutz-compliant methodology ##### BSI IT-Grundschutz - **Workshop – Grundschutz Check and Profiles Methodology**: Practical implementation of the BSI approach ### Implementation Aids and Best Practices #### Integration into the fuentis Suite The fuentis Suite supports practical implementation of the ISMS Toolkit with: - **Document Management**: Centralized management of ISMS documentation - **Workflow Integration**: Automated approval workflows for policies - **Version Control**: Full history of all changes - **Audit Trail**: Complete documentation of modifications for compliance evidence #### Practical Tips for Implementation **Phased Implementation** - Start with core policies (passwords, access control, incident management) - Expand gradually to the full documentation landscape - Prioritize by risk and compliance requirements **Tailoring to the Organization** - Use templates as a starting point, not rigid rules - Incorporate organizational specifics - Involve relevant stakeholders in customization **Continuous Improvement** - Establish regular review cycles for all documents - Use audit findings to improve documentation - Keep documentation current through change management ## FAQ Source: https://servicehub.fuentis.com/en/allgemein/faq/ **What does IT-Grundschutz mean?** Approach by the German Federal Office for Information Security (BSI) to identify and implement technical, organizational, personnel, and infrastructural security measures to achieve an appropriate level of protection. Evidence of a systematic approach can be demonstrated through an ISO/IEC 27001 certificate based on IT-Grundschutz. **What is information?** Data used in value-creating processes – both digital and analog (e.g., spoken, paper). An ISMS protects both forms. **Why a dedicated authority (BSI)?** Digitalization creates new threats. The BSI provides standards (including IT-Grundschutz), situation reports, and practical guidance. **What are the protection objectives?** - Confidentiality (only authorized access) - Availability (accessible, functional) - Integrity (unchanged/correct) **What is protection needs determination?** Assigning protection requirements (C, I, A, and possibly Authenticity) to processes/information/objects based on damage scenarios (normal/high/very high). → Inheritance to dependent objects (maximum principle, accumulation, distribution effect). **What is a Grundschutz Check?** Comparison of target vs. actual state against BSI requirements per modeled module. → Snapshot in the ISMS implementation process; completed once all partial requirements are met or justified as “not needed.” **How often to review?** Evaluate security concepts at least every 2 years; provide an updated ISMS version no later than every 3 years. **ISO 27001 certification based on IT-Grundschutz?** An external auditor reviews the ISMS (incl. on-site audit) and recommends certification. The certification body makes the decision. **Role of the auditor?** Checks completeness/effectiveness; issues recommendations (does not certify). Comments on implementation status must always be professionally justified. **What happens during structural analysis/modeling?** - *Structural analysis*: Recording infrastructures, rooms, networks, servers, systems, applications, processes within scope (grouping allowed → sample testing). - *Modeling*: Assignment of elementary threats and modules, forming the basis for the Grundschutz Check. **Elementary threats?** The BSI compendium (currently 47) assigns threats to modules (e.g., fire, espionage, malware). **What happens during risk assessment?** Evaluation = damage × likelihood → expected risk per module/object. **What is an ISMS?** A set of rules and methods to ensure information security; continuous (PDCA cycle). ISO 27001 defines requirements; IT-Grundschutz specifies and extends them. **What exactly is the “Statement of Applicability” (SoA)?** Documents which Annex A controls (with justification for inclusion/exclusion) apply to the ISMS. It must also include additional controls outside Annex A if used for risk treatment (ISO 27001, 6.1.3 d). **How did Annex A change with ISO/IEC 27001:2022?** Annex A now references 93 controls from ISO/IEC 27002:2022, grouped into: - 37 organizational - 8 people-related - 14 physical - 34 technological controls **ISO 27001 vs. ISO 27002 – what’s the difference?** - ISO 27001: Requirements (certifiable). - ISO 27002: Guidelines/implementation advice for controls (not certifiable). Annex A of 27001 references 27002. **How does the certification cycle work (surveillance/recertification)?** Certificates are valid for 3 years. → Annual surveillance audits required, recertification after 3 years. (Applies also to ISO 27001 based on IT-Grundschutz.) **What is the current transition to ISO/IEC 27001:2022?** IAF MD 26:2023 governs the transition. → Deadline for full transition: October 31, 2025. (Practice: complete transition audits by July 2025 to allow certification body decisions in time.) **Multi-site ISMS: Any special rules?** Yes. For multi-site certifications, IAF rules apply, incl. sampling quotas for surveillance audits (typically 30% of sites, rounded up; details in MD 1). **Which mandatory documents does an auditor expect?** ISO 27001 requires “documented information” for: - Scope - ISMS policy/objectives - Risk methodology - SoA - Risk treatment/plan - Performance indicators - Internal audit - Management review (Clauses 4–10; SoA explicitly in 6.1.3 d). **Internal audits vs. management review – what’s the purpose?** - *Internal audits (9.2)*: check effectiveness/conformity. - *Management review (9.3)*: strategic evaluation of the ISMS (performance, risks/opportunities, resources, improvements). **How does Business Continuity (BCMS) fit with ISO 27001?** An ISMS addresses information security; ISO 22301 complements it for business continuity (RTO/RPO, etc.). Both systems should be integrated. ISO 22301 was updated in 2019 and in 2024 with Amd 1: *Climate action*. **Cloud security & privacy – relevant standards?** - ISO/IEC 27017: Cloud-specific security controls (current Ed. 1 confirmed; DIS 27017 successor in progress). - ISO/IEC 27018:2025: Protection of personal data (PII) in public cloud as processor. **ISMS vs. NIS2?** NIS2 requires risk management measures (policies, incident handling, BCM, supply chain security). A mature ISO 27001 ISMS covers many of these but does not replace legal compliance. → See ENISA guidance and EU Implementing Regulation (EU) 2024/2690. **Suppliers & cloud providers: Must they be in ISMS scope?** Yes. Risk-based supply chain management is part of ISMS (Annex A: supplier relationships, cloud guidance via 27017/27018). Contractual/data protection obligations (e.g., GDPR Art. 28 data processing agreements) must also be met. **What does an IT-Grundschutz audit check additionally?** For ISO 27001 based on IT-Grundschutz: structural analysis, modeling, module requirements, elementary threats, and implementation levels (standard/core/basic protection) are audited using a formal schema. **How is audit time planned?** IAF documents (e.g., ID 14, MD 5) define calculation/adjustment of audit times for surveillance and recertification – depending on size, complexity, and risk. **Do additional controls (outside Annex A) need to be documented?** Yes – if used for risk treatment, they must appear in the SoA (ISO 27001 6.1.3 d). ## Terms & Glossary Source: https://servicehub.fuentis.com/en/allgemein/glossar/ **Note on Terminology:** “Werte” ≙ “Assets” “Informationsverbund” ≙ “Scope” (BSI terminology). **Core values/security objectives:** Confidentiality, Integrity, Availability. --- ### A **User (End User):** A person who uses IT services in daily work (not the same as a customer). *Example:* EU Paying Agency BW = processing offices using specialized procedures. **Application (App/Software):** IT support for processes; combines IT resources for a specific purpose. **Work Instruction:** Detailed description for the repeatable, quality-compliant execution of activities. **Assets:** Valuable target objects of an institution (e.g., information, systems, rooms). **Authentication:** Proof of identity (e.g., password, smart card, biometric feature). **Authenticity:** The property of truly matching the authenticated identity. **Authorization:** Validation/approval of access rights to resources. **Availability Management (ITIL):** Ensuring agreed service availability, including planning, measurement, and improvement. --- ### B **Basic Security Check (BSC):** Interview-based target/actual comparison of IT baseline protection implementation (older BSI 100-x standards). **Module (IT Baseline Protection):** Modular content with short description, threat scenario, recommended measures. **Threat:** Condition/event that may cause harm to C, I, A via vulnerabilities. **User Account (Username/Login):** Identification feature of a user towards an IT system. **Best Practices:** Proven practices. **Biometrics:** IT-supported identification based on physical/behavioral features (e.g., fingerprint, iris). **Bugfix / Hotfix / Patch / Update / Upgrade:** Error correction or functional enhancement. - Hotfix = urgent patch - Update = usually minor - Upgrade = major **Federal Office for Information Security (BSI):** German authority for IT security; publisher of IT Baseline Protection; certification body. **Federal Data Protection Act (BDSG):** German federal law on personal data protection (supplements GDPR, state laws). **Business Impact Analysis (BIA):** Assessment of potential impacts of failures on business processes. --- ### C **Capacity Management (ITIL):** Ensuring sufficient capacity/performance (business, service, component levels). **Change Management (ITIL):** Managing changes to IT operations with minimized risk. **Configuration Item (CI):** An asset or IT component. **Configuration Management (ITIL):** Managing/verifying information about CIs. **CMDB (Configuration Management Database):** Database mapping and linking CIs including lifecycle data. --- ### D **Data Protection:** Protection of personal data (fundamental right; GDPR/BDSG). **Data Security:** Technical goal to protect data of any type from loss/manipulation. **Backup:** Full/incremental/differential; ensures C, I, consistency. **Demilitarized Zone (DMZ):** Network zone between different security levels. **Digital Signature:** Verifies authorship and integrity of data. --- ### E **Effectiveness:** Achieving objectives (regardless of effort). **Efficiency:** Economy (effort-benefit ratio). **Supplementary Security Analysis:** Identifies where risk analyses beyond IT Baseline Protection are needed (higher protection needs, special cases, atypical scenarios). **EU Paying Agency Baden-Württemberg:** Administrative units for EGFL/ELER funds (approval, control, payment, accounting). --- ### F **Specialized Application:** Software for specific requirements/industries. **Specialized Task:** Government tasks for planning/operating the EU Paying Agency. **Operational Responsibility (Specialized):** Data administration, user support, responsibility for specialized applications. **Specialized Procedure:** IT support for administrative services; consists of one or more applications. **Financial Management (ITSM):** Budgeting, cost allocation, and service charging. **Firewall (Security Gateway):** Secure network interconnection, filtering allowed connections. --- ### G **Hazard:** Umbrella term; *threat* = specific hazard (e.g., defective storage medium). **Threat:** A hazard exploiting a vulnerability and causing harm. **Core Value/Security Objective:** Confidentiality, Integrity, Availability. **GSTOOL:** Former BSI software for security concepts (discontinued, support until 2016). --- ### H *(—)* --- ### I **Incident Management (ITIL):** Minimizing disruptions, restoring service; prioritization by impact/urgency. **Information Security:** Protecting analog/digital information; absence of unacceptable risks. **CISO / ISB:** Chief Information Security Officer / Information Security Officer; develops/facilitates policies; manages ISMS. **Information Security Event:** An event that may impair security. **Information Security Incident:** (Series of) events with risks for business operations/information security. **ISMS (Information Security Management System):** Rules, processes, measures to manage information security (continuous, PDCA). **IT (Information Technology):** Means for processing/transmitting information. **Scope (Information Network):** All objects (infrastructure, organizational, personnel, technical) in an application area. **Infrastructure (Baseline Protection):** Buildings, rooms, power, climate, cabling (without IT systems). **Institutions:** Companies, authorities, other organizations. **Integrity:** Absence of unauthorized modifications to systems/data. **Internal Audits:** Regular ISMS effectiveness/conformity checks; basis for improvements. **Internal Control System (ICS):** Principles/measures to ensure effectiveness, compliance, and legality. **ISO 27000 Family (ISO27k):** International information security standards. - ISO 27001: ISMS requirements (certifiable). - ISO 27002: Implementation guide for controls (non-certifiable). **Partial IS Revision:** Review of specific processes using baseline modules. **ITIL (IT Infrastructure Library):** Best practices for IT service management (ITSM). **IT Security:** Protection of electronically processed information (subset of InfoSec). --- ### K **Critical Infrastructure (KRITIS):** Facilities vital for supply/safety. **Accumulation Effect:** Higher protection needs from cumulative damages/dependencies. **Customer:** Buyer/contract partner of an IT service provider; SLA addressee. --- ### L **Information Security Policy:** Strategic document defining goals, means, structures, and desired security level. --- ### M **Maximum Principle:** Highest potential damage determines protection needs. **Modeling (Baseline Protection):** Assigning modules to structure elements; basis for target/actual comparison. --- ### N **Traceability:** Complete recording of actions (who/what/when). **Evidence Documents:** Process results (e.g., plans, logs, audits, reviews). **Network Diagram:** Clean overview of elements and connections. **Non-repudiation:** Data origin/receipt cannot be denied. --- ### P **Penetration Test:** Non-destructive test of security measures. **Prioritization:** Resource control by impact/urgency (incident mgmt). **Problem Management (ITIL):** Eliminating/preventing incident root causes. **Proxy:** Intermediary node for data forwarding/filtering. **Process:** Structured activities transforming inputs into outputs. --- ### R **Release Management (ITIL):** Planned, disruption-minimized rollouts of approved components. **Residual Risk:** Remaining risk after treatment. **Audit/Revision:** Independent review of suitability/compliance. **Risk:** Combination of threat + vulnerability; evaluated by probability × impact. **Risk Acceptance:** Deliberate decision to accept risk (temporary/permanent). **Risk Analysis/Assessment/Evaluation/Management:** Identification, analysis, evaluation, treatment, monitoring of risks. --- ### S **Malware (Virus, Worm, Trojan, Rootkit, Spyware):** Software with harmful functions. **Protection Needs/Definition/Assessment:** Classification as normal/high/very high per object; inheritance rules. **Security Objectives:** Confidentiality, Integrity, Availability. **Vulnerability:** Weakness enabling exploitation by threats. **Server:** System providing services to clients. **SLA (Service Level Agreement):** Agreement on service objectives/responsibilities. **Service Level Management (ITIL):** Negotiating/monitoring SLAs; reviews/improvements. **Security Gateway (Firewall):** Network interconnection per policy. **Security Concept:** Plans/documents to achieve security objectives. **Security Measure:** Organizational, personnel, technical, or infrastructural action. **Security Policy:** Official document with security objectives and general measures. **Single Point of Failure (SPOF):** Component whose failure disrupts the entire system. **Structural Analysis:** Recording objects/relationships in the scope. **Structure Elements:** Applications, IT systems, networks, rooms, buildings, connections. **Support (Helpdesk/IT Support):** 1st/2nd/3rd level support. **Technical Operation:** Facilities, infrastructure, hardware, system software, databases. --- ### U **Underpinning Contracts (UC):** Contracts with external providers supporting services. --- ### V **Availability:** Provision of information/services as required. **Encryption:** Transforming plaintext into ciphertext via keys. **Distribution Effect:** Reduced inherited protection needs by spreading across systems. **Confidentiality:** Protection against unauthorized access. **VLAN (Virtual LANs):** Logical network segmentation. **VPN (Virtual Private Network):** Logically separated, authenticated, encrypted network. **Directive Documents:** Binding rules with mandatory implementation. --- ### W–Z **Assets:** Anything valuable to an institution (assets, knowledge, health, objects). **Asset Owner:** Responsible for assessing, protecting, and securing an asset. **Asset Register:** Inventory of relevant asset information supporting security concepts. **WLAN (Wi-Fi):** Wireless networks (IEEE 802.11). **Certification Scope:** Subset of the ISMS scope under certification. **Target Object:** Element within the scope assigned modules. **Access/Entry/Use:** System use / data knowledge / physical entry. --- ### Terms in the fuentis Suite (DE/EN, compact) | Term (DE) | Term (EN) | Definition | | ------------------------------ | ------------------------------ | ----------------------------------------------------------------------------------------------- | | Anforderung | Requirement | Describes **what** must be done; fulfilled by matching **security measures**. | | Assets | Assets | Valuable objects for achieving goals/value (Baseline Protection context). | | Audit | Audit | Review for compliance, identifying gaps, basis for improvement (internal/external). | | Basis-Absicherung | Basic protection | Broad initial protection across all processes/procedures. | | Bausteine | Block | Modular content (threats, requirements, notes) in Baseline Protection. | | Fragebogen | Questionnaire | Standardized protection needs assessment. | | Gefährdungen | Threats | Threats acting through vulnerabilities. | | Geltungsbereich | Scope | All relevant components of an application domain. | | Geschäfts-/Kernprozesse | Business/Core processes | Processes directly creating value. | | Katalog | Catalog | Central publication of security standards (e.g., BSI compendium). | | Kern-Absicherung | Core protection | Focus on particularly vulnerable processes/assets. | | Kumulationseffekt | Accumulation effect | Raised protection needs due to cumulative damages/multiple processing. | | Maßnahme | Security measure | Actions for risk control (organizational, personnel, technical, infrastructural). | | Maximumprinzip | Maximum principle | Highest potential damage sets protection needs. | | Modellierung | Modeling | Assigning modules to objects (with scope/requirements). | | Risiken | Risks | Typically frequency × impact (a form of uncertainty). | | Risikoanalyse | Risk analysis | German usage: overall process of risk assessment + treatment. | | Schutzbedarfsanalyse | Protection needs analysis | Determining protection needs “normal/high/very high” incl. consequences. | | Schwachstelle | Vulnerability | Weakness enabling a risk. | | Sicherheitskonzept | Security concept | Planned approach to achieving objectives; key document. | | Standard-Absicherung | Standard protection | Classical approach (BSI 100-2): broad and deep coverage. | | Steuerungsprozesse | Management process | Set goals and track progress (requirements/evidence). | | Strukturanalyse | Structural analysis | Capturing processes/apps/IT/networks/rooms/buildings/connections. | | Unterstützungsprozess | Support process | Provides resources for business/management processes. | | Vererbung | Propagation | Protection need inheritance (max principle, dependencies, accumulation, distribution). | | Zielobjekt | Target object | Object within the scope assigned modules. | | Top-Down-Prinzip | Top-Down principle | Strategies from leadership; implemented along hierarchy. | | Verwaltung | Governance | Rules/practices for control, compliance, transparency. | | CISO/ISB | CISO/ISB | Chief Information Security Officer / Information Security Officer. | | Risk Owner | Risk Owner | Responsible for identifying, assessing, managing, and reporting a risk. | | RACI-Matrix | RACI matrix | Role clarification: Responsible, Accountable, Consulted, Informed. | | Governance-Gruppe | Governance group | Committee for strategy, policies, compliance, risk management. | | Informationssicherheitsziele | Information Security Objectives| Concrete objectives protecting CIA. | | ISO-Konformität | ISO compliance | Adherence to relevant ISO standards (esp. ISO 27001/27002). | # Quickstart Guides ## BSI IT-Grundschutz - Quickstart Guide Source: https://servicehub.fuentis.com/en/quickstart/bsi-it-grundschutz-quickstart-guide/ ### What awaits you here? **1. Scope (Geltungsbereich)** Define which parts of your organization should be covered by the protective measures of IT-Grundschutz. A clearly defined scope makes it easier for you to structure your security measures later on. **2. Structural analysis** Record all relevant assets and transfer them into a clear structure. This creates the basis for a systematic recording of threats and risks. **3. Determination of protection requirements** Determine the protection requirements of your assets to be able to prioritize in a targeted way. You will receive an assessment of how critical certain processes, systems, or information are. **4. Modeling** Use the BSI building blocks to adapt measures and requirements to your specific infrastructure. Modeling makes it easier for you to select the appropriate security measures. **5. IT-Grundschutz Check (target–actual comparison)** Compare your current security status with the requirements of BSI IT-Grundschutz. This allows you to identify gaps and prioritize targeted improvement measures. **6. Risk analysis** Once you have defined the protection requirements, assess all identified risks and initiate appropriate countermeasures. This continuously increases your organization’s level of protection. #### Next steps - **1. Read the introductory chapter:** Get an initial overview of how BSI IT-Grundschutz is structured. - **2. Define your scope:** Start with a clear delimitation of your project so that you can derive measures in a targeted manner. - **3. Conduct the structural analysis:** Use our guides to record all assets and relevant process building blocks. - **4. Determination of protection requirements & modeling:** Link the results of the structural analysis with the BSI building blocks and determine the necessary protection requirements. - **5. Conclude with the IT-Grundschutz Check:** This ensures that your security level meets current requirements and you know which gaps still need to be closed. --- ### Scope (Geltungsbereich) #### 1. What is the scope for and what is it intended to cover? A scope comprises the entirety of infrastructural, organizational, personnel, and technical components that serve to fulfill tasks in a specific application area of information processing. This means the scope must clearly define which area of the company you want to depict in the ongoing process. In fuentis, you must create at least one scope per unit, but you can also create several. The company **Beispiel GmbH** is used below for illustration, analogous to the BSI’s **RECPLAST GmbH**. > **Important:** The BSI also often refers to the scope as an **Informationsverbund** (information network). > **Practical tip:** “Ongoing process” means: the scope is continuously maintained, reviewed, and adjusted—not defined once and then forgotten. You can create tasks for regular monitoring; for example, for an annual review. #### 2. Why is the scope important? A clearly defined scope is crucial to the success of an ISMS because it: - delineates the boundaries of the ISMS within the organization, - clarifies responsibilities and accountabilities related to information security, - focuses the organization’s resources and efforts on the most relevant and critical areas. #### 3. How do I define a scope? ##### 3.1 Define the scope As described, you must clearly define and delimit the scope. To start, a general definition is sufficient; in the next steps you further narrow down the scope. **Beispiel GmbH** defines the scope as follows: - **Short name:** Beispiel GmbH - **Full designation:** Beispiel GmbH with all business processes, applications, and IT systems used to provide production. With the following points, you will work your way deeper into the scope: ##### 3.2 Organizational structure The organizational structure of the scope is created through an organizational chart. In the case of Beispiel GmbH, this would be an organizational chart of the entire company, since the scope also relates to the entire company. > **Practical tip:** Use whiteboard tools such as Microsoft Vision or Draw.io to create an organizational chart. Update it regularly. You can link or attach this in the scope definition in the fuentis Suite. ##### 3.3 Sites and employees Define which sites and employees belong to the scope. You can create these as target objects in the fuentis Suite. **Example:** The purchasing, marketing, and sales departments are located in the building in Bad Godesberg. The company employs around 500 people in total, 175 of whom work in administration in Bad Godesberg. > **Practical tip:** To avoid losing track, first note down all relevant information outside the tool. Then work through the information step by step and enter it into the fuentis Suite. If you need support, feel free to contact us at any time. ##### 3.3 Network diagram Create a network diagram for the scope. The network diagram is not only helpful for the subsequent phases of establishing an ISMS, but it also helps you in step 5. Alternatively, a network diagram can be created with applications such as Microsoft Visio. ![Network diagram](../../../../assets/docs/quickstart/netzplan.png) ##### 3.4 What must be included in the network diagram? - IT systems, i.e., client and server computers, active network components (switches, routers, WLAN APs), network printers, etc. - ICS and IoT components with network connections (clients, hand scanners, industrial printers, PLCs, control cabinets, etc.) - Network connections between these systems (LAN such as Ethernet, WLAN, backbone technologies, etc.) - Connections to the outside (e.g., dial-in access via ISDN/modem, internet connections, radio links, leased lines to remote sites, etc.) ##### 3.5 Information technology Define the information technology in scope. Describe in detail which components are involved and what they are used for. Briefly describe technology & services with purpose and responsibility: - On-prem: e.g., ERP server (production), file services (docs) - Cloud/SaaS: e.g., CRM, HR suite, ticket system (incl. tenant/region) - OT/ICS: e.g., line PLCs, HMI, historian - Endpoints & peripherals: clients, mobile, printers, scanners - Shared services: AD/Entra ID, PKI, backup, MDM, monitoring > **Practical tip:** In fuentis, create as target objects with owner, criticality, and dependencies. > **Practical tip:** You may be able to use IT inventory lists. #### 4. Scope in fuentis ![Scope in fuentis](../../../../assets/docs/quickstart/scope-in-fuentis.png) --- ### Structural analysis #### 1. Structural analysis The structural analysis is the first step in the process of establishing an ISMS. In this phase, the entire (IT) infrastructure of a scope is recorded and documented. The goal is to gain a clear understanding of the existing (IT) landscape in order to recognize and assess risks on this basis. > **Practical tip:** Use the preparatory work for the scope definition and set up a uniform storage location where you centrally record these documents, e.g., a dedicated SharePoint. #### 2. Preparation ##### 2.1 Does documentation already exist? Check whether inventories/inventory lists, process management tools, software lifecycle tools, or similar are available (possibly spread across multiple sources). Take these into account. If documentation is available: import it into fuentis and still carry out the steps of the structural analysis to avoid errors or missing assets. ##### 2.2 Where do you start? The starting point is to take stock of the physical and virtual IT components. ##### 2.3 How is a structural analysis implemented? By systematically inventorying all hardware and software components as well as analyzing the network structure and business processes. For a detailed description of the fuentis Suite functions that support the structural analysis, please search for “Strukturanalyse” in the Service Hub or speak to our experts personally. ##### 2.4 How are the Target Object Groups (TOG) formed? Target objects are groups of similar assets—that is, things that you can manage together in your information security management. These can be, for example, servers, networks, applications, or sites. Instead of listing each individual device or system separately, you group similar elements together. This saves time and makes your ISMS clearer. Examples: 1. All Windows servers = 1 target object group 2. All office PCs = 1 target object group 3. All routers and switches = 1 target object group __Why this matters:__ If a single device changes (e.g., a server is replaced), you don’t have to adapt your entire security concept anew—the group remains in place. ![TOG](../../../../assets/docs/quickstart/tog.png) **Tips:** - Keep your structural analysis as concise as possible. - Consolidate IT systems as far as possible. - It’s easier to expand the structure later than to shrink it. - The security concept should not be affected by fluctuations in the asset landscape. #### 3. Implementation phase ##### 3.1 Recording business processes, applications, and information Record all business and control processes. This is done in the fuentis tool. The network diagram is an exception. Many of these processes can be further subdivided—for example, server administration into the subprocesses of managing mail, file, and database servers, each of which includes activities such as patch management, backups, configuration, or documentation. Record an asset in fuentis or create a target object: ![Create TOG](../../../../assets/docs/quickstart/zielobjekt.png) ##### 3.2 Record process dependencies Record the dependencies of business and control processes. ##### 3.3 Recording support processes - Recording is analogous to recording business and control processes. Support processes can be linked in fuentis to the process they support. - Linking the support processes becomes important later during the determination of protection requirements, in order to inherit the protection requirements accordingly. ##### 3.4 Recording applications Just like support processes, all applications must be recorded and considered in the structural analysis. A target object is also created for this, but with a different “target object type.” The target object type can be selected when creating the target object, see above. It is important that the applications are linked to all business and control processes with which the application is associated. For example, the payroll application must be linked to the HR management business process. ##### 3.5 Recording IT systems When surveying IT systems, the aim is to compile the existing and planned IT systems and the respective information. These include: - all IT systems present in the network (clients and servers), groups of IT systems and active network components, network printers, but also - telecommunications components (such as PBXs, fax machines, and mobile phones), and - IoT devices such as a voice assistant. **Important** here is also the linking of related assets. For example: accounting clients should be linked to accounting. ##### 3.6 Recording buildings In the structural analysis, all relevant buildings and rooms in which assets, systems, or processes are operated should be recorded. These include, for example: 1. Office and administrative buildings 2. Data centers or server rooms 3. Production halls or storage areas > **Practical tip:** For each building, note the address, usage (e.g., administration, production), and security-relevant areas (e.g., access control, server room). ##### 3.7 Recording service providers Record all external service providers that are relevant for the operation, maintenance, or provision of IT systems, applications, or processes. These include, for example: 1. IT service providers or cloud providers 2. Maintenance and support service providers 3. Data center or hosting partners 4. External administrators or outsourcing partners > **Practical tip:** Record which services the service provider provides and which security measures or contracts (e.g., data processing agreement, SLA) exist. --- ### Determination of protection requirements #### 1. Determination of protection requirements How much protection do information, applications, and associated technical systems/infrastructure need? How is the protection requirement justified in a comprehensible way? Which components require more security, and when are standard protection measures sufficient? Goal: Selection of appropriate security measures for processes, information, applications, IT systems, rooms, and communication links. #### 2. Preparation phase ##### 2.1 Definitions and starting point The protection requirement determines the **maximum damage** that can occur if the CIA objectives for a target object—confidentiality, integrity, or availability—are violated. - **Confidentiality** – Information can be read only by authorized parties. - **Integrity** – Information can be changed only by authorized parties. All changes are authentic (authenticity) and cannot be repudiated. - **Availability** – Information is available at the right time and in the right place. In the steps of implementation planning, these three protection goals are considered and classified into categories. In addition, various damage scenarios and their potential impacts are assigned to the corresponding protection requirement categories. ##### 2.2 Protection requirement categories | Category | Definition | |-----------|---------------------------------------------------------------------------------------------| | normal | The damage effects are limited and manageable. | | high | The damage effects can be considerable. | | very high | The damage effects can be existentially threatening/catastrophic. | ![Protection requirements](../../../../assets/docs/quickstart/schutzbedarf.png) ##### 2.3 Damage scenarios Define thresholds per scenario to separate the categories. Typical scenarios: - Violation of laws/regulations/contracts - Impairment of the right to informational self-determination - Impairment of personal physical integrity - Impairment of task fulfillment - Negative internal or external effects - Financial impact ###### 2.3.1 Damage scenario category “normal”: ![normal](../../../../assets/docs/quickstart/schadensszenario-normal.png) ###### 2.3.2 Damage scenario category “high”: ![high](../../../../assets/docs/quickstart/schadensszenario-hoch.png) ###### 2.3.1 Damage scenario category “very high”: ![very high](../../../../assets/docs/quickstart/schadensszenario-sehr-hoch.png) #### 3. Implementation phase ##### 3.1 Determining protection requirements for business and control processes First, determine the protection requirements for the business processes recorded during the structural analysis. This means that for each business process, using the categories defined above, you must determine how great the need for confidentiality, integrity, and availability is. To properly determine the protection requirements, the management of the responsible department should be involved in the process. - In the dropdown menu, you can set the protection requirement category, for example, confidentiality: high. - Below that, describe the determination of the protection requirements, using your previously defined damage scenarios. ![Determination of protection requirements](../../../../assets/docs/quickstart/schutzbedarfsfeststellung.png) To standardize this process, you can also use questionnaires, i.e., assign them. You can do this in the “Questionnaire” tab. > **Practical tip:** The fuentis Suite combines important and powerful features to simplify and automate the determination of protection requirements. Use the inheritance or recommendation function for this. If you have any questions, feel free to contact us at any time or check our Service Hub for further assistance. ##### 3.2 Determining protection requirements for applications An application’s protection requirement essentially depends on the protection requirements of the business processes for which the application is needed. This protection requirement is inherited by the applications. The following cases can be distinguished in inheritance: - **Maximum principle:** In many cases, the highest protection requirement of all business processes for which the applications are relevant can be adopted. - **Aggregation effect:** The protection requirement of the application can be higher than the protection requirement of the individual business processes. This is the case, for example, when an application is required for several business processes with normal protection requirements. The failure of one of these business processes might be tolerable for Beispiel GmbH. However, if several business processes fail at the same time, high damage can occur. Set protection requirements for applications using the maximum principle and aggregation effect: ![Set protection requirements](../../../../assets/docs/quickstart/schutzbedarf-festlegen-1.png) Apply inheritance of protection requirements to linked target objects: ![Inheritance of protection requirements](../../../../assets/docs/quickstart/schutzbedarf-festlegen-2.png) Manual determination as in 2.1 is also possible. ##### 3.4 Determining protection requirements for IT systems An IT system’s protection requirement essentially depends on the protection requirements of the applications for whose execution it is needed. This protection requirement is inherited by the IT system’s protection requirement. Here, you can again rely on the maximum principle or the aggregation effect as a recommendation. ##### 3.5 Determining protection requirements for communication In the next work step, the aim is to determine the protection requirements for the communication links. Some connections are more vulnerable than others and must be protected by redundancy or special measures against attacks from outside or inside. **Critical connections** include: - Connections that extend from the company into a public network (e.g., telephone network, internet) or across public grounds. Through such connections, malware can be introduced into the company network, company servers can be attacked, or employees can forward confidential data to unauthorized parties. - Connections over which particularly sensitive information is transmitted. Possible threats include eavesdropping, deliberate manipulation, and fraudulent misuse. Outages of such connections are particularly critical for applications that require high availability. - Connections over which confidential information must not be transmitted. For example, personnel data may only be viewed and processed by employees of the HR department. It must therefore be prevented that this data can be viewed by unauthorized employees during transmission. For each of these connections, determine the protection requirements for the three core values based on the information transmitted over them. ##### 3.6 Determining protection requirements for rooms When determining protection requirements for rooms, consider all rooms and sites identified in the structural analysis that are relevant to the information, business processes, applications, and IT systems of the information network under consideration. Here, inheritance principles must again be taken into account. The protection requirement of a room is measured by the protection requirements of the IT systems located in it, as well as the information and data carriers processed and stored in it. Consequently, in most cases, the maximum principle can be applied again (comparable to determining the protection requirements of IT systems). In some cases, however, the large number of objects located in a room results in a higher protection requirement in one of the core values than for each individual object (aggregation effect). This can apply, for example, to rooms containing mirrored servers with normal availability requirements—in the event of failure of one server, there is still a second one, whereas the “failure” of the room (for example, due to a fire) affects both servers. --- ### Modeling #### 1. Modeling according to the building block model In the third step—modeling—the results of the structural analysis and the analysis of protection requirements are transferred into a structured model. This model serves to reduce the complexity of the IT landscape and provide a clear basis for the risk analysis. Modeling can include various organizational processes, applications, and IT systems. Modeling identifies relevant building blocks for the individual target objects. The building blocks describe requirements for ensuring information security and suitable measures. Modeling thus enables a pragmatic and effective approach to achieving the desired level of security. ![Layer model](../../../../assets/docs/quickstart/schichtenmodell.png) #### 2. Where can the building blocks be found and which ones exist? You can find the building blocks in the **IT-Grundschutz Compendium** (GSK). The current version of the IT-Grundschutz Compendium can be downloaded from the BSI web server or purchased from Bundesanzeiger Verlag. #### 3. When should an additional risk analysis be carried out? For target objects with **high** protection requirements. In this case, the BSI requirements are no longer sufficient, as they are geared towards a normal protection requirement. #### 4. Assign building blocks with fuentis You can easily assign the building blocks in the fuentis tool. By assigning the building blocks, the associated measures, requirements, and threats are also assigned to the target object. #### 5. When is a building block applicable? Each GSK building block describes the application area and boundaries in detail. If no building block fits or deviations exist, this must be documented. --- ### IT-Grundschutz Check (target–actual comparison) #### 1. IT-Grundschutz Check In an initial IT-Grundschutz Check—before carrying out the risk analysis—it is determined whether and to what extent the basic and standard requirements of the relevant building blocks of the IT-Grundschutz Compendium are met for the individual target objects of an information network. Requirements for higher protection requirements are checked in a second IT-Grundschutz Check if the security concept has been supplemented by new or changed measures as a result of decisions on risk treatment. The overviews below also contain notes on responsibilities for each building block as well as for requirements. In addition to the responsibilities mentioned, the information security officer (ISO/ISB) should generally be involved in strategic decisions. They are also responsible for ensuring that all requirements are met and reviewed in accordance with the established security concept. Documentation of the IT-Grundschutz Check also includes information on the review process (e.g., interviewer, interviewees, time of the interview). These metadata are not listed below, but are nevertheless indispensable in practice for IT-Grundschutz Checks. #### 2. How should the implementation status options be selected? - **Dispensable:** the requirement cannot be fulfilled - **Implemented:** the requirement is fully (or with only marginal improvements) met - **Partially implemented:** essential aspects of the requirement are met; individual aspects have not been fully implemented - **Open:** the requirement is not or only marginally met In the **Details** tab of a requirement, status and contents can be edited. ![Edit details](../../../../assets/docs/quickstart/details-bearbeiten.png) #### 3. What must be considered when documenting the implementation status? The implementation status must be recorded **in a traceable manner**: - For every **dispensable requirement**, it must be comprehensible why it is dispensable: - Are the conditions not applicable? (For example, disabling microphones on a server is dispensable if no microphones are installed.) - Have equivalent or better measures been implemented? (For example, use of TLS for transport encryption if a SINA VPN with “Geheim” approval is already used.) - Is implementation no longer economically justifiable? (For example, if the implementation time is 6 months but the component’s remaining lifecycle is 3 months.) - For every **implemented measure**, the implementation should be traceable: - Where is the implementation specified? - How is implementation evidenced? (For example, an invoice.) - For every **open measure**, tasks must be recorded in a traceable manner: - What still needs to be done? (**SMART**) - For every **partially implemented measure**, tasks must be recorded in a traceable manner: - How up to date is the implementation? - What still needs to be done? (SMART) #### 4. What is SMART? **S**pecific – Precise wording **M**easurable – Defined measurability criteria **A**ctivating – Engaging **R**ealizable – Realistically achievable **T**imeable – Ability to set a fixed completion date #### 5. Degree of safeguarding ![Degree of safeguarding](../../../../assets/docs/shared/absicherungsgrad.png) The building blocks contain three types of requirements: **basic**, **standard**, and **requirements for increased protection needs**. Which of these requirements you consider in the IT-Grundschutz Check depends on the organization’s requirements: - With the **basic safeguarding** approach, you check only the fulfillment of the basic requirements. Important: An attestation can be issued, but not a certification. - With the **standard safeguarding** approach, IT-Grundschutz is fully implemented, with all assets included. Protection requirements are determined comprehensively and risk analyses are carried out completely. Certification is possible. - With **core safeguarding**, the focus is on the most valuable and exposed resources, with the goal of fully safeguarding a specific core area. Certification is possible. ### Risk analysis In the risk analysis, the remaining risks after the IT-Grundschutz Check are assessed. The goal is to define appropriate measures to reduce or accept remaining risks. > **Note:** You will find further information on risk analysis in the Knowledge section! #### Procedure - Identify risks that remain after the IT-Grundschutz Check. - Assess their likelihood of occurrence and potential damage. - Decide whether the risk will be accepted, reduced, or avoided. - Document the results in fuentis under “Risk Management.” > **Practical tip:** In fuentis, risks can be linked directly to target objects and measures. Use the “Risk Treatment” workflow to create tasks automatically. ## ISO 27001 - Quickstart Guide Source: https://servicehub.fuentis.com/en/quickstart/iso-quickstart-guide/ ### ISO/IEC 27001 (ISMS) – Implementation Guide (revised) > **Goal:** A lean, practical method to establish, certify, and continually improve an ISO/IEC 27001:2022-conformant ISMS. > **Reference:** Structure & terms align with your BSI/IT-Grundschutz guide (Scope, Structural Analysis, Protection Needs, Modeling, Risk Analysis) — mapped here to ISO 27001. --- ### 1) Overview & prerequisites **When to use** - You aim for ISO/IEC 27001 certification or want to improve your ISMS in a structured way. - You want to reuse BSI-Grundschutz artefacts (scope, structure, protection needs) as a solid baseline. **Method outcomes** - Scope, roles & governance - Risk method, risk assessment & treatment - Statement of Applicability (SoA) for Annex A:2022 (93 controls) - Documented information, KPIs, audit & review cycle --- ### 2) Initiation **Objectives** - Collect relevant data (documents, interviews, workshops) - Define the **scope** (ISO §4.3) - Start the **inventory** of target objects/assets (structural analysis) **How to proceed** - Review existing materials (org chart, network diagram, inventories) - Elicit missing data and store centrally (e.g., SharePoint) - In fuentis: create target objects/assets with owner, criticality, and dependencies ![Initiation](../../../../assets/docs/quickstart/initiierung.png) > **Pro tip:** Use the IT-Grundschutz quickstart as onboarding — terminology & artefacts transfer well to ISO. --- ### 3) ISMS framework (ISO 27001 Clauses 4–7) #### 3.1 Context, scope & governance - **Context & stakeholders** (ISO §4.1–4.2): determine internal/external issues, interested parties, and requirements. - **Scope** (ISO §4.3): set organisational/technical boundaries (sites, processes, IT/OT). - **Governance model & roles** (ISO §5.1–5.3): leadership commitment, publish **ISMS policy**, define roles/responsibilities (ISB/CISO, process owners). - Maintain a **RACI** for key functions. ![Information security organisation](../../../../assets/docs/quickstart/organisationsaufbau-nach-iso-und-bsi-beispiel.png) #### 3.2 Objectives & planning (ISO §6) - Set **information security objectives** (measurable, time-bound, responsible, with KPIs) aligned to business goals (ISO §6.2). - Plan **risks & opportunities** (ISO §6.1): define method, criteria, acceptance (see Section 5). #### 3.3 Support (ISO §7) - **Resources** budgeted and periodically reviewed (people, time, tools, locations). - **Competence & awareness** (training, on/offboarding, recurring campaigns). - **Communication** (reporting flows, channels, protection). - **Documented information** control (document control, versioning, retention, access). --- ### 4) Structural analysis & protection needs (ISO-compatible) > Goal: Transparent **asset landscape** and **CIA criticality** as the basis for risk assessment. #### 4.1 Structural analysis (ported from IT-Grundschutz) - Capture business processes, applications, IT/OT systems, buildings/rooms, service providers. - Create **TOG/asset groups** (servers, clients, network, apps, sites) for clarity & maintainability. - Record process/system dependencies (fuentis relations). ![TOG](../../../../assets/docs/quickstart/tog.png) #### 4.2 Determining protection needs (CIA) - Rate **Confidentiality / Integrity / Availability** per asset/process: *normal / high / very high*. - Use inheritance (e.g., process → application → system; watch aggregation effects). ![Protection needs](../../../../assets/docs/quickstart/schutzbedarf.png) --- ### 5) Risk management (ISO §6.1 & §8) #### 5.1 Method & criteria - **Approach:** scenario-based risk identification (threat × vulnerability × impact). - Define **criteria**: likelihood, impact (CIA), scoring model, acceptance thresholds, treatment rules, combined risks. ![Risk](../../../../assets/docs/quickstart/risiko.png) #### 5.2 Risk assessment - Identify → analyse → evaluate risks (consistent, repeatable). - Assign **risk owners**, determine residual risk & priority, maintain the register. #### 5.3 Risk treatment - Choose option (avoid, mitigate, share/transfer, accept) and derive **controls** from **Annex A**. - Build/maintain the **Statement of Applicability (SoA)**: applicable/not applicable + justification, status, references. - Create a **treatment plan** with owners, due dates, and evidence (tests, artefacts). > **Pro tip (fuentis):** Link risks to target objects & measures; use the “Risk Treatment” workflow for automated tasks. --- ### 6) Implementation (DO) #### 6.1 Implement controls - Plan resources & costs (one-off/recurring), sequence by risk & quick wins. - Deploy technical/organisational controls, test effectiveness, collect evidence. - Reassess and document **residual risk**. #### 6.2 Keep the SoA current - Update after every major change/reassessment with status & justifications. - Obtain management confirmation. #### 6.3 Training & awareness - Deliver role-specific training; run campaigns cyclically. - Measure impact via KPIs (e.g., phishing rate, completion scores). --- ### 7) Monitoring & review (CHECK – ISO §9) #### 7.1 Monitoring & KPIs - **What** is monitored (controls, processes, incidents)? - **How** (method), **how often** (frequency), **by whom** (role)? - Define KPIs (e.g., patch SLA, incident MTTR, backup success rate) and report. #### 7.2 Internal audit - Set programme & criteria, ensure independence. - Record findings, nonconformities, and improvement opportunities. #### 7.3 Management review - Inputs: KPI reports, audit results, incidents, status of objectives/SoA/risks. - Outputs: decisions, resources, priorities, improvement directives. --- ### 8) Improvement (ACT – ISO §10) - Manage **nonconformities & corrective actions** (root cause, effectiveness check). - Continual ISMS improvement (objectives, processes, controls, documentation). --- ### 9) Artefacts (minimal set) | Artefact | Purpose | |---|---| | ISMS policy | Guardrails & leadership commitment | | Context, stakeholders, **scope** | ISO §4 evidence, boundaries | | Organisation structure & **RACI** | Transparent roles/responsibilities | | **Asset/structure map** | Basis for protection needs & risks | | **Protection needs (CIA)** | Criticality & inheritance documented | | **Risk method & criteria** | Uniform, repeatable assessment | | **Risk register** | Identification, evaluation, owner, status | | **SoA (Annex A:2022)** | Applicability, justification, status | | Action plan & evidence | Implementation & effectiveness traceable | | KPI set, audit plan, management review | Oversight & steering | --- ### 10) ISO 27001 vs. BSI IT-Grundschutz (at a glance) - **ISO 27001**: Process-oriented, risk-based; certifies **the management system**, not a fixed security level. - **Grundschutz**: Measures catalogue & implementation aids; risk analysis sometimes dispensable; certification reflects a **security level**. - **In practice**: Grundschutz artefacts (structure, protection needs) **accelerate** ISO rollout; ISO always requires formal risk assessment and an SoA. --- ### 11) Annex – examples & snippets #### 11.1 CIA categories | Category | Definition | |---|---| | **normal** | Limited, manageable impact | | **high** | Considerable impact | | **very high** | Existential/catastrophic impact | #### 11.2 Risk prompt (guiding questions) - What is the **acceptable residual risk** per asset/process? - Which **treatment strategy** applies per risk band (red/amber/green)? - How do we measure **effectiveness** (KPIs, tests, evidence)? --- ### 12) Quick checks (for audits & go-lives) - [ ] Scope complete; boundaries & interfaces clear - [ ] Roles/RACI published; responsibilities enacted - [ ] Method & criteria written; consistently applied - [ ] Risk register current; owners & due dates set - [ ] SoA current; justifications traceable - [ ] Controls effective (tests/evidence available) - [ ] KPI reporting, internal audit & management review done - [ ] Corrective actions tracked; effectiveness verified --- # ISMS Module ## Gap-Analysis (SoA) Source: https://servicehub.fuentis.com/en/isms/gap-analyse-soa-isms/ Gap analysis and the Statement of Applicability (SoA) (baseline) form the strategic foundation for the successful establishment of an Information Security Management System (ISMS). These systematic tools enable organizations to objectively assess the current security status and develop a clear roadmap to achieve the desired certification. **Why are these instruments indispensable?** In the complex landscape of information security, they create transparency about existing protective measures and precisely identify where action is needed. This not only saves time and resources but also minimizes the risk of compliance violations and security gaps. ### Gap Analysis: Systematic Inventory #### Definition and Purpose A gap analysis in the ISMS context is a structured method for identifying the difference between an organization's current security level and the requirements of a specific standard (ISO 27001, BSI IT-Grundschutz, or industry-specific requirements). #### Core Objectives of Gap Analysis **1. Capture Current State** - Documentation of existing security measures - Assessment of the effectiveness of implemented controls - Identification of informal security practices **Note:** This is accomplished in the Security Check/Modeling module. ![gap-1](../../../../assets/docs/isms/gap-1.png) **2. Define Target Requirements** - Systematic comparison with standard specifications - Consideration of legal and contractual requirements - Integration of industry-specific best practices **3. Identify Gaps** - Categorization by criticality - Risk assessment of missing measures - Prioritization by implementation effort ![gap-2](../../../../assets/docs/isms/gap-2.png) **Note:** This is handled in the Risk Analysis module. **4. Develop Action Plan** - Concrete action recommendations - Resource planning and budgeting - Temporal roadmap to certification readiness **Note:** This is visible in the Risk Monitoring module (Risk Treatment Plan) #### Implementation Methodology The gap analysis follows a structured process: **Phase 1: Preparation** - Define scope and system boundaries - Assemble project team - Collect relevant documentation **Phase 2: Data Collection** - Interviews with process owners - Review existing policies and procedures - Technical review of IT infrastructure **Phase 3: Assessment** - Comparison with standard catalog - Maturity assessment of controls - Documentation of deviations **Phase 4: Results Preparation** - Creation of gap analysis report - Visualization of results - Derivation of action catalog > **Practice Tip:** Conduct the gap analysis iteratively. An initial rough analysis quickly provides an overview, while subsequent detailed analyses deepen specific areas. ![gap-3](../../../../assets/docs/isms/gap-3.png) ### Statement of Applicability (SoA): The Heart of ISO 27001 #### Concept and Significance The Statement of Applicability is a central document in the ISO 27001 ISMS that lists all 93 controls from Annex A of the standard and documents for each individual measure: - **Applicability:** Is the control relevant for the organization? - **Justification:** Why was this decision made? - **Implementation Status:** What is the current implementation level? - **References:** Reference to supporting documents and evidence #### Functions of the SoA **1. Evidence of Risk Treatment** The SoA documents how identified risks are addressed through specific controls. It creates the connection between risk analysis and measure implementation. **2. Certification Basis** Auditors use the SoA as an audit basis. It defines the scope of certification and serves as a checklist during the audit. **3. Communication Tool** The SoA makes security decisions transparent and comprehensible for management, auditors, and stakeholders. **4. Compliance Evidence** It demonstrates the systematic engagement with all relevant security aspects and justifies conscious decisions. #### Creation and Maintenance of the SoA **Step 1: Control Assessment** Each of the 93 controls from ISO 27001 Annex A is individually assessed: - Check relevance for the business model - Establish risk relationship - Conduct cost-benefit analysis **Step 2: Document Justification** - When applied: How is the control implemented? - When not applied: Why is it not relevant? - Describe compensatory measures ![gap-4](../../../../assets/docs/isms/gap-4.png) **Step 3: Define Status** - Fully implemented - Partially implemented (with schedule) - Planned (with milestone plan) - Not applicable (with justification) **Step 4: Continuous Updates** - Regular reviews (at least annually) - Adjustments when scope changes - Integration of new risks and threats > **Practice Tip:** Use version control for your SoA. Document changes transparently to make the development of your ISMS clear. ### Integration of BSI IT-Grundschutz #### Specifics of IT-Grundschutz While ISO 27001 follows a risk-based approach, BSI IT-Grundschutz works with building blocks and predefined protection requirements: **Basic Protection** - Standardized measures for normal protection requirements - Quick implementation through building block catalog - Suitable for typical IT infrastructures **Standard Protection** - Extended measures for higher protection requirements - Additional organizational controls - More detailed documentation requirements #### Combined Approach Many organizations use a hybrid approach: 1. IT-Grundschutz for IT infrastructure 2. ISO 27001 for organization-wide processes 3. Industry standards for specific requirements ### Practical Implementation with the fuentis Suite #### Digital Gap Analysis The fuentis Suite automates essential steps of the gap analysis. ![gap-7](../../../../assets/docs/isms/gap-7.png) ![gap-8](../../../../assets/docs/isms/gap-8.png) **Note:** In the fuentis flex version, gap analyses can be created directly in scoping. ![gap-5](../../../../assets/docs/isms/gap-5.png) ![gap-6](../../../../assets/docs/isms/gap-6.png) #### SoA Management **Central Administration** - All controls in a clear matrix - Filter and search functions - Versioning and change history **Collaboration** - Assignment of responsibilities - Comment function for coordination - Workflow for approval processes **Export and Reporting** - PDF export for management presentations - Audit-compliant documentation > **Practice Tip:** Use the export functions for regular management reviews. Visual preparation facilitates communication of ISMS progress. ![gap-9](../../../../assets/docs/isms/gap-9.png) ### Best Practices for Successful Gap Analyses #### 1. Secure Top Management Support - Early involvement of senior management - Clear communication of benefits - Document resource commitments #### 2. Realistic Planning - Plan buffer times for unexpected findings - Prefer iterative approach - Identify and implement quick wins #### 3. Include Stakeholders - Involve functional departments early - Reduce resistance through transparency - Communicate successes #### 4. Documentation from the Start - Record decisions transparently - Systematically collect evidence - Build audit trail #### 5. Continuous Improvement - Establish gap analysis as recurring process - Document lessons learned - Define KPIs for progress measurement ### Common Challenges and Solution Approaches #### Challenge 1: Incomplete Inventory **Problem:** Informal security measures are overlooked **Solution:** Structured interviews with operational teams, shadow IT analysis #### Challenge 2: Overambitious Goals **Problem:** Attempt to close all gaps simultaneously **Solution:** Risk-based prioritization, develop phase model #### Challenge 3: Lack of Acceptance **Problem:** Controls are perceived as bureaucracy **Solution:** Communicate benefits, streamline processes, automation #### Challenge 4: Resource Shortage **Problem:** Budget and personnel for implementation are missing **Solution:** Create business case, external support, cloud solutions ### Connection to Other ISMS Components #### Risk Analysis - Gap analysis identifies risks through missing controls - SoA documents risk treatment - Interaction in prioritization #### Process Landscape - Controls are integrated into processes - Process owners defined for controls - KPIs derived from gap analysis #### Internal Audit - SoA as audit basis - Gap analysis results as audit focus areas - Continuous monitoring of implementation #### Management Review - Gap analysis status as agenda item - SoA changes for approval - Resource decisions based on gaps ### Further Steps After Gap Analysis 1. **Specify Action Plan** - Define detailed work packages - Assign responsibilities - Set milestones 2. **Develop Policies** - Create security policy - Derive specific policies - Formulate work instructions 3. **Technical Implementation** - Implement security tools - Harden infrastructure - Set up monitoring 4. **Create Awareness** - Develop training program - Establish security champions - Foster security culture 5. **Certification Preparation** - Conduct pre-audit - Complete documentation - Select certification body ### Key Messages at a Glance ✓ **Gap Analysis as Starting Point:** The systematic inventory creates transparency about the current security status and defines the path to certification ✓ **SoA as Central Control Instrument:** The Statement of Applicability documents conscious security decisions and serves as evidence of systematic risk treatment ✓ **Iterative Approach:** Successful ISMS implementation occurs step by step with regular reviews and continuous improvement ✓ **Tool Support Essential:** Digital solutions like the fuentis Suite significantly simplify administration, tracking, and reporting ✓ **Holistic Approach:** Gap analysis and SoA are not isolated documents but integral components of the entire ISMS lifecycle ## Incident Management Modul Source: https://servicehub.fuentis.com/en/isms/incident-management-modul-fuentis-suite/ The Incident Management Module is an integral component of the Information Security Management System (ISMS) of the fuentis Suite. It enables organizations to systematically capture, manage, and track security incidents – a crucial building block for compliance with ISO 27001, NIS2, and other regulatory requirements. **Why is it relevant?** In today's threat landscape, the ability to respond quickly and effectively to security incidents is business-critical. The module supports you in systematically managing incidents, fulfilling regulatory reporting obligations, and learning from incidents. ### Core Concepts and Requirements #### Integration into the ISMS Incident Management is **not a separate application**, but a dedicated phase within the ISMS structure. Each incident is assigned to a specific entity, whereby all actions, visibilities, and treatments occur at the entity level. You can only access the Incident Management Module in the new trust-platform. #### Core Functionalities ##### 1. **Incident Reporting** - **Multiple Reporting Channels**: Internal employees, external stakeholders, IT monitoring systems - **External Reporting Forms**: Publicly accessible forms for persons without direct system access - **Email Verification**: Protection against misuse through validation of external reports - **Categorization**: Automatic or manual classification (e.g., phishing, ransomware, data leak) - **Prioritization**: Severity assignment based on impact and probability **Note:** You can of course create incidents directly in the user interface. However, you can also use the reporting portal and provide this link to your employees. This way, they don't need to have their own user accounts. To do this, simply click on the "question mark" icon at the top right of the screen and copy the link for the incident portal from the slide-over that opens. ![Vorfall erstellen](../../../../assets/docs/isms/vorfall-erstellen.png) ##### 2. **Incident Lifecycle Management** **Report Status Workflow:** - **Unverified**: Receipt of external report - **Submitted**: Email-verified report - **Accepted**: Accepted as actual incident - **False Positive/Spam**: Rejected reports **Incident Status Progression:** 1. **New Incident**: Initially after acceptance 2. **Under Investigation**: Active analysis in progress 3. **Ongoing**: Confirmed incident, countermeasures in progress 4. **Escalated**: Escalation to higher level (optional) 5. **Mitigated/Contained**: Threat neutralized 6. **Resolved**: Fully resolved ##### 3. **Workflow Management** - **Assignment & Escalation**: Clear responsibilities and escalation paths - **Status Tracking**: Complete tracking of incident progress - **SLA Management**: Monitoring of response and resolution times ##### 4. **Documentation & Audit Trail** - **Central Repository**: Secure storage of all incident records - **Metadata Tracking**: Timestamps, affected systems, actions performed - **ISMS Asset Linkage**: Direct connection to affected TOGs (Target Object Groups) #### NIS2 Compliance Features The module specifically supports the requirements of the NIS2 directive: - **Reporting Obligations**: Predefined templates for regulatory notifications - **Deadline Monitoring**: Automatic reminders for 24h/72h reporting deadlines - **Audit Trail**: Complete documentation for compliance evidence ### Implementation Aids and Best Practices #### Organizational Preparation ##### Define Roles and Responsibilities **Incident Manager** - Triage of external reports - Status overview of all incidents - Escalation decisions **Incident Handler** - Operational processing of assigned incidents - Documentation of measures - Status updates **Crisis Team (for Major Incidents)** - Strategic decisions - External communication - Business continuity coordination ![Rollenverwaltung](../../../../assets/docs/isms/rollenverwaltung.png) ##### Dashboard & Monitoring Recommended Dashboard Widgets: - **Incidents by Status**: Overview of active incidents - **SLA Compliance**: Adherence to response times - **Trend Analysis**: Incident development over time - **Top Threat Categories**: Most frequent incident types ![DSMS Dashboard](../../../../assets/docs/isms/dsms-dashboard.png) #### Practice Tips > **Practice Tip: Incident Response Playbooks** > Create predefined playbooks for common incident types. These can be stored as templates in the system and activated when needed. > **Practice Tip: Regular Exercises** > Conduct quarterly incident response exercises. Use the test environment of the fuentis Suite for realistic simulations. > **Practice Tip: Lessons Learned** > Establish a structured process for post-incident reviews. The insights should flow directly into risk assessment and measure planning. #### Glossary **BAO (Betriebliche Aufbauorganisation)**: Crisis management structure with strategic, tactical, and operational levels **CSIRT (Computer Security Incident Response Team)**: Specialized team for IT security incidents **False Positive**: False alarm; reported incident that turns out to be harmless **Major Incident**: Severe incident with significant impacts on critical business processes **MTTD/MTTR**: Mean Time to Detect / Mean Time to Respond - KPIs for incident response **SLA (Service Level Agreement)**: Agreed response and resolution times **TOG (Target Object Group)**: Target object group in the ISMS; structural unit for asset grouping **Triage**: Initial assessment and prioritization of incoming incident reports ### Key Messages at a Glance **Integral ISMS Component**: Incident Management is not a standalone solution, but deeply integrated into the ISMS structure **Compliance-Ready**: Meets the requirements of ISO 27001, NIS2, and BSI IT-Grundschutz out-of-the-box **Structured Lifecycle**: Clear status progression from report to closure with complete audit trail **Flexible Architecture**: Scales from single tenants (Standard) to complex multi-entity scenarios (Professional/Enterprise) **Practice-Oriented**: Supports real incident response processes with playbooks, escalation, and lessons learned integration ## Inventoryanalysis Source: https://servicehub.fuentis.com/en/isms/trust-inventory-scope/ > Note: In the new Trust interface, these phases are on a content level. There is no longer a separation between the phases "Structural Analysis (Inventory)" and "(Protection Requirements Analysis)". Functions have not been removed. Content has only been merged and redundancies consolidated. --- ### Overview #### Scope Definition (Scoping) – Overview Scope definition (Scoping) is a central module of the ISMS management system. It enables the definition and management of security scopes for organizations in the context of Information Security Management Systems (ISMS) and Data Protection Management Systems (DPMS). **Purpose:** - Defining the boundaries and scope of security concepts - Documenting security responsibilities and roles - Managing different scopes per organizational unit - Classifying protection requirements according to defined categories #### Structural Analysis – Overview Structural analysis is the first step in building an Information Security Management System (ISMS) according to ISO 27001 or IT-Grundschutz. In this phase, the boundaries of the ISMS are defined, all relevant IT assets are inventoried, and their dependencies are documented. The fuentis Suite supports you with a structured, modular approach. **Why is structural analysis important?** - Creates clear responsibilities for information security - Focuses resources on critical areas - Forms the basis for systematic risk management - Facilitates ISO 27001 certification #### Protection Requirements Assessment (PRA) – Overview The Protection Requirements Assessment (PRA) is a central component of the IT security concept according to IT-Grundschutz and ISO/IEC 27001. It answers the fundamental question: **How much protection do our information, applications, and IT systems need?** Through systematic analysis, it is determined which assets are critical for the company and which security measures are appropriate. This creates the foundation for an efficient and effective Information Security Management System (ISMS). --- ### Scope Definition (Scoping) #### 1. Overview (Identical to overview above) #### 2. Main Functions ##### 2.1 Scopes Overview The overview page shows all defined scopes in a card view: **Card Elements:** Each scope is displayed as a card with: - Scope title - Security concept description - Associated organizational unit - Certification standard (e.g., ISO-27001) **Filtering:** Scopes can be filtered by organizational unit **Search Function:** Quick search for scopes via search bar ![str-1](../../../../assets/docs/isms/str-1.png) ##### 2.2 Create Scope New scopes are created via the "+ Create Scope" button. **The creation process runs in 4 steps:** **Step 1: Basic Information** - Select unit: Choose the organizational unit - Name: Unique name for the scope - Title: Technical identifier (e.g., SCP-0001) - Function: Define the role of the scope (Superordinate, Subordinate) - Status: Define the current status (e.g., Draft, Active) - Description: Detailed documentation of the security concept ![str-2](../../../../assets/docs/isms/str-2.png) **Step 2: ISMS Framework and Main Catalog** - Selection of applicable security standard - Definition of security catalog for the scope ![str-3](../../../../assets/docs/isms/str-3.png) **Step 3: Apply ISMS Profile** - Application of predefined security profiles - Automatic assignment of security requirements ![str-4](../../../../assets/docs/isms/str-4.png) **Step 4: Assign Security Objects** - Assignment of systems, processes, and assets - Definition of objects to be protected within the scope ![str-5](../../../../assets/docs/isms/str-5.png) #### 3. Detailed View of a Scope After selecting a scope, the detailed view opens with the following information: ##### 3.1 Tab: Details **Basic Information:** - Name and title - Associated organizational unit - Type (e.g., Scope) - Creation date and user - Validity status (Standard/Current) **Base Data:** - Complete input fields for editing - Responsibility information - Options for using protection requirements questionnaires **Review Management:** - Structural analysis review status - Due dates for reviews - Responsible person for approval **Release Management:** - Release status of structural analysis - Due date for releases - Responsible person and release date ![str-6](../../../../assets/docs/isms/str-6.png) ##### 3.2 Tab: Protection Requirement Categories This tab shows the protection requirement classifications defined for the scope: **Categories by Protection Requirements:** - **Category - Normal:** Standard security requirements - **Category - High:** Increased security requirements with the following aspects: - Violation of laws/regulations/contracts - Impairment of informational self-determination - Impairment of personal integrity - Impairment of task fulfillment - Negative internal or external impact - Financial impacts - **Category - Very High:** Critical security requirements (with the same aspects as "High") **Function:** This categorization enables risk-based assignment of security measures. ![str-8](../../../../assets/docs/isms/str-8.png) #### 4. Important Concepts ##### 4.1 Scope Hierarchy - **Superordinate Scopes:** Define general, company-wide security policies - **Subordinate Scopes:** Specific security concepts for individual business areas or services ##### 4.2 Security Concepts A scope is defined by a security concept that: - Establishes the boundaries of responsibility and authority - Documents security requirements and measures - Correlates with a recognized standard (e.g., ISO 27001) ##### 4.3 Organizational Unit - Defines the affiliation of the scope - Can have superordinate and subordinate relationships - Enable organization-specific security policies ![str-9](../../../../assets/docs/isms/str-9.png) #### 5. Best Practices - Clear demarcation: Ensure that scopes are clearly distinguishable from each other - Documentation: Use meaningful descriptions for each scope - Regular review: Update scopes regularly according to organizational changes - Hierarchical structure: Use the hierarchy to manage complex security landscapes - Protection requirement classification: Use protection requirement categories to prioritize security measures #### 6. Navigation and Operation **Element** | **Function** ---|--- Global Search | Quick search for scopes or other elements Select Unit | Filtering by organizational unit Search Bar | Real-time filtering of displayed scopes Edit Button | Opens edit mode for details Back Button | Return to overview page Tabs | Navigation between different information areas #### 7. Typical Workflows **Workflow 1: Create New Scope** - Click "Create Scope" button - Enter basic information - Navigate through "Framework", "Profile" and "Objects" steps - Save and complete ![str-11](../../../../assets/docs/isms/str-11.png) **Workflow 2: Edit Existing Scope** - Select scope from overview - Click "Edit" button - Change desired fields - Save changes ![str-11](../../../../assets/docs/isms/str-11-7avxry.png) **Workflow 3: Review Protection Requirement Categories** - Open scope - Navigate to "Protection Requirement Categories" tab - View categories and adjust if necessary ![str-12](../../../../assets/docs/isms/str-12.png) --- ### Protection Requirements Assessment (PRA) #### Why is the Protection Requirements Assessment relevant? - **Resource optimization:** Security measures are deployed specifically where they are most needed - **Transparency:** Traceable justification for security investments - **Compliance:** Meeting regulatory requirements (BSI IT-Grundschutz, ISO 27001) - **Risk minimization:** Systematic identification and assessment of protection requirements - **Prioritization:** Clear decision basis for implementing protective measures #### The Three Protection Goals in Detail **Note:** You can adjust the protection goals and values in the settings. The protection requirements assessment is based on the three fundamental protection goals of information security: ##### 1. Confidentiality **Definition:** Information can only be viewed by authorized persons. **Practical meaning:** - Protection against unauthorized access to sensitive data - Preservation of trade secrets - Compliance with data protection regulations - Prevention of industrial espionage ##### 2. Integrity **Definition:** Information can only be modified by authorized persons. All changes are authentic and traceable. **Practical meaning:** - Protection against unauthorized manipulation - Ensuring data accuracy - Traceability of changes - Prevention of data corruption ##### 3. Availability **Definition:** Information and systems are available at the right time and place. **Practical meaning:** - Ensuring business continuity - Minimizing downtime - Guaranteeing critical processes - Compliance with Service Level Agreements (SLAs) #### Protection Requirement Categories Protection requirements are divided into three categories based on potential damage impacts: ##### Normal **Criteria:** - Damage impacts are limited and manageable - Financial losses remain tolerable - Maximum downtime: 24-72 hours - Minor or only internal reputation damage **Typical examples:** - Internal documentation - Non-critical administrative processes - Publicly accessible information ##### High **Criteria:** - Damage impacts can be considerable - Significant financial losses, but not existentially threatening - Maximum downtime: 1-24 hours - Broad reputation or trust impairment possible **Typical examples:** - Personal data - Important business processes - Critical customer information ##### Very High **Criteria:** - Existentially threatening, catastrophic impacts possible - Fundamental violations of laws and regulations - Maximum downtime: < 1 hour - Danger to life and limb possible **Typical examples:** - Critical infrastructure systems - Highly sensitive research data - Systems with potential for personal endangerment #### Damage Scenarios in Practice During protection requirements assessment, various damage scenarios are systematically considered. **Note:** You can store this information in the respective scope. 1. **Violation of Laws/Regulations/Contracts** - Normal: Minor contract violations, minimal penalties - High: Significant legal consequences, high fines - Very High: Fundamental law violations, ruinous liability damages 2. **Impairment of Informational Self-Determination** - Normal: Possible impairment of social standing - High: Significant impairment of economic circumstances - Very High: Danger to personal freedom of the affected person 3. **Impairment of Task Fulfillment** - Normal: Classified as tolerable by those affected - High: Classified as intolerable by individuals - Very High: Classified as intolerable by all 4. **Financial Impacts** - Normal: Tolerable financial damage - High: Considerable but not existentially threatening losses - Very High: Existentially threatening financial damage #### Implementation of Protection Requirements Assessment ##### Phase 1: Preparation 1. **Definition of Protection Requirement Categories** - Adaptation to organization-specific requirements - Definition of concrete threshold values - Coordination with management 2. **Identification of Damage Scenarios** - Consider industry-specific risks - Include regulatory requirements - Analyze historical incidents ##### Phase 2: Implementation **Protection Requirements Assessment for Business Processes – Approach:** 1. Identify all relevant business processes 2. Assess confidentiality, integrity, and availability for each process 3. Involve department management in the assessment 4. Document justification **Practice Tip:** Use standardized questionnaires for uniform assessment. This accelerates the process and ensures comparability. **Protection Requirements Assessment for Applications – Inheritance Principles:** - **Maximum Principle:** The highest protection requirement of all supported business processes is adopted - **Cumulation Effect:** Multiple processes with normal protection requirements can together result in high protection requirements ![str-13](../../../../assets/docs/isms/str-13.png) **Example:** A CRM application supports multiple sales processes. Individually, these have normal protection requirements, but a complete failure would mean significant revenue losses → Availability: high **Protection Requirements Assessment for IT Systems – Special Considerations:** - Protection requirements are inherited from the applications running on them - Shared Resources require special consideration - Virtualization can lead to cumulation effects **Protection Requirements Assessment for Communication Connections – Identifying Critical Connections:** - Internet connections - Connections over public networks - Transmission of sensitive data - Single Points of Failure **Protection Requirements Assessment for Premises – To be considered:** - Physical access protection - Environmental conditions (climate, fire protection) - Concentration of critical systems - Redundancies and alternative locations #### Integration into the fuentis Suite ##### Functionalities in the ISMS Module **1. Structured Recording** - **Protection Requirements Tab:** Central recording of all protection requirements - **Dropdown Menus** for standardized categories - **Free text fields** for detailed justifications - **Custom PR Values:** Extension with organization-specific protection objectives **2. Automated Inheritance (Propagation)** - **Propagation Tab:** Automatic transfer of protection requirements - **Override Functions** for manual adjustments - **Visualization** of inheritance chains - **Bulk Operations** for efficient processing **3. Intelligent Recommendations (Recommendation)** - **Algorithm-based Analysis** of linked assets - **Maximum Principle** and **Cumulation Effect** are automatically considered - **Preview Function** shows effects before adoption - **Multi-Select Options** for flexible selection **4. Workflow Integration (4-Eye Principle)** - **Submit → Review → Approve/Reject → Reopen** - **Status Tracking:** Initial, Submitted, Approved, Rejected, Reopened - **Audit Trail:** Complete documentation of all changes - **Custom Workflows:** Adaptation to organization-specific approval processes **5. Questionnaire Module** - **Standardized Questionnaires** for uniform assessment - **Template Library** with best practices - **Automatic Evaluation** and categorization - **Export Functions** for reports and audits ![str-14](../../../../assets/docs/isms/str-14.png) ##### Authorization Concept for Protection Requirements **Global Roles:** - `ISMS_PROTECTION_REQUIREMENT_ACCESS`: Basic access to PRA functions **Granular Permissions:** - `Scopes - PRA Read`: Read access to scope protection requirements - `Scopes - Edit Protection Requirements`: Editing of scope protection requirements - `TargetObject Groups - PRA Read`: Read access to TOG protection requirements - `TargetObject Groups - Edit Protection Requirements`: Editing of TOG protection requirements - `Propagation of Protection Requirements`: Execution of inheritance - `TargetObject Groups - Recommendation`: Use of recommendation function #### Best Practices for Implementation ##### 1. Preparation and Planning ✓ **Secure Management Commitment** - Involve management early - Clarify budget and resources - Communicate commitment ✓ **Assemble Project Team** - Include department representatives - Ensure IT security expertise - Define clear responsibilities ##### 2. Implementation ✓ **Follow Top-Down Approach** - Start with critical business processes - Gradually progress to technical assets - Identify and implement quick wins ✓ **Strive for Standardization** - Use uniform assessment criteria - Use questionnaires and templates - Conduct regular calibration meetings ✓ **Ensure Documentation** - Justify all decisions - Make assumptions explicit - Document changes in a traceable manner ##### 3. Quality Assurance ✓ **Consistently Apply 4-Eye Principle** - Conduct independent reviews - Build in plausibility checks - Plan regular audits ✓ **Continuous Improvement** - Document lessons learned - Regularly optimize processes - Establish feedback loops ##### 4. Avoid Common Pitfalls **Avoid Overvaluation** - Not everything is "very high" critical - Make realistic assessments - Consider cost-benefit ratio **Prevent Undervaluation** - Don't underestimate cumulation effects - Capture dependencies completely - Think through worst-case scenarios **Control Scope Creep** - Define clear system boundaries - Maintain prioritization - Choose iterative approach #### Connection with Other ISMS Processes - **Risk Analysis:** Identification of relevant threats, assessment of probability of occurrence, prioritization of risk scenarios - **Measure Selection:** Select appropriate security measures, establish implementation priorities, optimally allocate resources - **Business Continuity Management:** Define RTO/RPO, prioritization in recovery - **Compliance Management:** Evidence provision, fulfillment of regulatory requirements, transparency towards stakeholders #### Glossary - **Asset:** Value or resource of an organization (information, system, process) - **Cumulation Effect:** Increase in protection requirements through concentration of multiple assets - **Maximum Principle:** Adoption of the highest protection requirement during inheritance - **Propagation:** Automatic inheritance of protection requirements between linked assets - **TOG (Target Object Group):** Target object group – logical grouping of assets - **4EP (4-Eye Principle):** Four-eye principle for quality assurance --- ### Structural Analysis #### Navigation When you are in the **Structural Analysis** phase, the navigation tree on the left side of the screen plays a central role. There you have an overview of all scopes and their target object groups. Using the arrows, you can expand the various scopes or target object types. When you hover over a scope with the mouse, you see an "arrow in circle" symbol; clicking on it takes you to the detail view of the scope. You can search and filter the tree to get to the desired entries faster. You can use the button at the top right - ![IA_tree_navigation_1](../../../../assets/docs/isms/ia-tree-navigation-1.png) ![IA_tree_navigation_2](../../../../assets/docs/isms/ia-tree-navigation-2.png) **Note:** When you click on target object types (e.g., Information, Business processes, etc.), you see a tabular overview of all target objects of this type within the respective scope. When you click on a target object, you see the respective detail view of the target object. **Note:** The main tree is only visible for users with the active permission "Structural Analysis – Read Lists." #### Scope The **Scope** defines the boundaries of your ISMS (cf. security concept) and determines which parts of the organization – including processes, systems, and information assets – are covered by the ISMS. It encompasses all infrastructural, organizational, personnel, and technical components that serve task fulfillment in a specific application area. **Important Properties:** - Every entity in fuentis automatically has a default scope - Additional scopes can be created manually - Clear delineation of areas to be protected - Basis for the entire ISMS implementation ##### Scope Detail View In the upper part of this view is the status bar, which displays some basic information about the scope: Name, Title, etc. - This status bar can be collapsed using the "arrow up." ![IA_scope_detailview](../../../../assets/docs/isms/ia-de-1-scopes-status-bar.png) Below the status bar are the various attributes and fields that can be filled out. You will find two tabs there, "Details" and "SBF Definitions." ![IA_scope_detailview](../../../../assets/docs/isms/ia-de-1-scopes-other-tabs.png) **Details Tab**: 1. Basic Data - Information about the scope name, title, status, etc. 2. IT-Grundschutz - Data related to IT-Grundschutz for the selected scope (protection level, relevance for KRITIS, handling of personal data, etc.) 3. Reviewed - Information about the review process of the Structural Analysis (was the inventory analysis reviewed, who was reviewed, when was this process carried out, etc.) 4. Approved - Information about the approval process of the Structural Analysis (was the Structural Analysis approved, who was approved, when was this process carried out, etc.) You can collapse the work areas by clicking on the "plus" symbol. **SBF Definitions Tab** On this tab, the protection requirements (PR categories) are defined. Input is made in three sections: - PR Category – Normal - PR Category – High - PR Category – Very High Each section contains identical, editable fields in which the impacts in case of damage can be described. Typical fields are, for example: - Violation of laws, regulations, or contracts - Impairment of the right to informational self-determination - Financial consequences - Physical injury This information helps to make the assessment of individual values in the context of information security comprehensible and consistent. **Note:** You can create multiple scopes and thus map the concept of "services," cf. "modular security concepts." You can add target objects to multiple scopes. You can also link target objects across different scopes and thus map complex organizational structures. If you need help with mapping, please feel free to contact us. In a joint workshop, we can certainly help you. **Note:** Entities are objects in which all relevant information can be stored. This includes in particular users, roles & rights, scopes, and target objects. You can find more information on this topic in the Rights & Roles section. #### Target Object Groups (TOGs) TOGs are logical groupings of similar assets or information values. This grouping simplifies management and ensures consistent protective measures. **The 12 TOG Types in fuentis:** 1. **Domain** - Superordinate organizational areas 2. **Information** - Data and information stocks 3. **Business Process** - Operational and supporting processes 4. **Application** - Software and applications 5. **IT System** - Servers, clients, network components 6. **Network** - Network infrastructure 7. **Room** - Server rooms, offices 8. **Employee** - Personnel resources 9. **Physical Facility** - Hardware, equipment 10. **Building** - Locations and properties 11. **Infrastructure** - Supporting systems 12. **Outsourcing** - External service providers ## Authorization Concept (Structural Analysis) For working with the structural analysis, users need specific roles and permissions: #### Global Role - **ISMS_INVENTORY_ANALYSIS_ACCESS** - Basic requirement for access #### Detailed Permissions **Note:** You can read more about the authorization concept of the fuentis Suite in the Permissions section. It is important that roles must be created and assigned independently. Simply assigning the "Global Access Roles" is not sufficient to gain access to individual areas. **For Scopes:** - Scopes - Read - Scopes - Create - Scopes - Edit - Scopes - Delete - Scopes - Link **For Target Object Groups:** - Target Object Groups - Read - Target Object Groups - Create - Target Object Groups - Edit - Target Object Groups - Delete - Target Object Groups - Link ![IA_roles_1](../../../../assets/docs/isms/ia-de-1-roles.png) ![IA_roles_2](../../../../assets/docs/isms/ia-de-2-roles.png) ### Practical Implementation #### 1. Define Scope **Preparation:** 1. Analyze organizational structure 2. Identify critical business processes 3. Document IT landscape 4. Record locations and employees **In fuentis Suite:** - Navigation: ISMS Module → Structural Analysis - Button "Create" → "Scope" - Fill in mandatory fields: - **Name:** Unique designation - **Title:** Descriptive short form - **Status:** Current state - **IT-Grundschutz Data:** Protection level, KRITIS relevance ![IA_create_scope](../../../../assets/docs/isms/ia-de-1-create-button.png) ![IA_create_scope_view](../../../../assets/docs/isms/ia-de-1-create-scope.png) **Practice Tip:** Start with a manageable scope and expand it gradually. An overly broad initial definition often leads to complexity and resource problems. **Note:** After opening the detail view of a scope, you can permanently delete it there using the ***delete*** button. Attention: there is no trash function. #### 2. Create Target Object Groups (ZOG/TOGs) ![IA_create_tog_1](../../../../assets/docs/isms/ia-de-1-create-tog.png) ![IA_create_tog_2](../../../../assets/docs/isms/ia-de-2-create-tog.png) **Systematic Approach:** 1. **Record Business Processes** (GP001, GP002...) - Identify core processes - Document support processes - Record dependencies 2. **Inventory Applications** (A001, A002...) - Identify critical software - Link with business processes - Document interfaces 3. **Record IT Systems** (S001, C001, L001...) - Group servers - Consolidate client systems - Record network components 4. **Document Premises** (R001, GB001...) - Server rooms - Office buildings - External locations **Best Practice for Naming Conventions:** ``` [Type-Abbreviation][Number] [Description] Examples: - GP002 Quotation Process - A022 CRM System - S015 Exchange Server - R001 Server Room 3rd Floor ``` **Note:** You can customize the automatic title creation. You can find this setting in the ISMS settings (gear symbol at the bottom left). **Practice Tip:** Status: Choose the status of the target object group here. 1. Planned/In Conception – Important for the planning phase before implementation. 2. Ordered/In Creation – Signals that something is officially ordered or in the manufacturing process. 3. Provided – Object or resource is available but not yet in use. 4. In Test – Required when tests are necessary before commissioning. 5. In Operation – Standard status for actively used resources or processes. 6. Defective – Necessary to mark problems or errors. 7. In Repair/In Exchange – Important for service and maintenance processes. 8. Decommissioned – Required for end-of-life management (e.g., for IT hardware or machines). ***Term Definition:*** The terms Target Object; ZO (Target Object; TO), Target Object Group; ZOG (Target Object Group; TOG) and Asset, Asset Groups are easily confused. The terms Target Object (ZO), Target Object Group (ZOG) as well as Asset and Asset Group are often used similarly but have different meanings: 1. **Target Object (ZO / Target Object, TO):** A single, concrete object that is considered within the scope – e.g., a server, a business application, or a building. 2. **Target Object Group (ZOG / Target Object Group, TOG):** A group of target objects with common properties that can be managed or assessed together – e.g., "Client PCs in Sales" or "Data Center North." 3. **Asset / Asset Group:** Assets can be both material (e.g., hardware, rooms) and immaterial (e.g., data, reputation). Assets in the fuentis Suite are "real" unique "Configuration Items" and are also considered as such in Asset Management. You can learn more about Asset Management in the Asset Management section. ##### Status and Detail View In the upper part of this view is the status bar, which displays some basic information about the TOG: Name, Title, etc. You will also find the "Delete" and "Linked Objects" buttons. ![IA_tog_statusbar](../../../../assets/docs/isms/ia-de-1-tog-status-bar.png) Similar to scopes, you will also find several tabs in the detail view area for target objects. Here you can navigate to the individual functions. ![IA_tog_detailview](../../../../assets/docs/isms/ia-de-1-tog-other-tabs.png) In the "Details" tab you will find the following sections: 1. Basic Data: Information about the name, title, status, etc. of the TOG. 2. IT-Grundschutz: Data on IT-Grundschutz for the selected TOG (protection requirements, relevance for KRITIS, handling of personal data, etc.). 3. Reviewed: Information about the review process of the structural analysis (was the structural analysis reviewed, who reviewed, when was this process carried out, etc.). 4. Approved: Information about the approval process of the structural analysis (was the structural analysis approved, who approved, when was this process carried out, etc.). ##### Delete You can permanently delete a TOG in its detail view using the "Delete" button. Attention: there is no trash function. **Note:** You can only delete TOGs that are not linked to other objects. You must first remove all links. #### 3. Link Target Object Groups ##### Understanding TOG Hierarchies fuentis follows a logical hierarchy for TOG linking based on the 12 predefined types. Understanding these relationships is crucial for proper structural analysis: **Hierarchy Overview:** - **Domain** (highest level) encompasses all organizational areas - **Information** and **Business Process** are core operational elements - **Application** supports business processes - **IT System** hosts applications - **Network** and **Infrastructure** support IT systems - **Room** and **Building** provide physical housing - **Physical Facility** and **Employee** are foundational resources - **Outsourcing** can be subordinate to any other type **Detailed Hierarchy Rules:** - **Domain** is superordinate to all other TOG types. - **Information** is subordinate to Domain and superordinate to Business Process. - **Business Process** is subordinate to Domain/Information and superordinate to Application/Outsourcing. - **Application** is subordinate to Domain/Information/Business Process and superordinate to IT System, Physical Facility, Employee, Outsourcing. - **IT System** is subordinate to Application and superordinate to Network, Infrastructure, Room, Physical Facility, Employee, Outsourcing. - **Network** is subordinate to IT System and superordinate to Employee/Outsourcing. - **Room** is subordinate to IT System/Infrastructure and superordinate to Building, Physical Facility, Employee, Outsourcing. - **Building** is subordinate to Room and superordinate to Employee, Outsourcing, Physical Facility. - **Physical Facility** is subordinate to Application, IT System, Infrastructure, Room, Building and superordinate to Employee. - **Employee** is superordinate to multiple TOGs but can be subordinate to Outsourcing. - **Outsourcing** is always subordinate to other TOGs but cannot be superordinate to any parent TOG. **Linking Rules:** - Domains can be linked with all subordinate ZOG types - Business processes connect with applications and outsourcing - IT systems need links to network and infrastructure - Employees are assigned to relevant systems and rooms ![IA_connect_tog_1](../../../../assets/docs/isms/ia-connect-tog-1.png) ![IA_connect_tog_2](../../../../assets/docs/isms/ia-connect-tog-2.png) ![IA_connect_tog_3](../../../../assets/docs/isms/ia-connect-tog-3.png) ![IA_connect_tog_4](../../../../assets/docs/isms/ia-connect-tog-4.png) **Practice Tip:** Use the "Linked Objects" view in fuentis to visualize direct and indirect dependencies. Red arrows show direct, gray arrows show indirect links. You can find this button in the left area below the status bar. There you can switch between table view and tree view. ![IA_tog_linked_graph](../../../../assets/docs/isms/ia-de-1-link-graph.png) ![IA_linked_tog_overview](../../../../assets/docs/isms/ia-de-1-linked-objects.png) **Practice Tip:** Use the blue hierarchy level in the upper area of the screen. Here you can navigate quickly and always keep track of where you currently are. You can also always open a left sidebar via the "Linked Objects" button in the upper right area, which enables quick navigation to all indirect links. You can expand and select objects like in the main navigation tree. ##### Assign ZOGs to Scopes Target object groups can be assigned to one or more scopes. ![IA_add-tog_scope](../../../../assets/docs/isms/ia-de-3-add-to-scope.png) #### 4. Assign Assets Concrete assets are assigned to TOGs in the "Included Assets" tab: 1. Select TOG 2. Open "Included Assets" tab 3. Click "Add" button 4. Select and assign relevant assets ![IA_assign_asset_1](../../../../assets/docs/isms/ia-de-1-assign-asset.png) ![IA_assign_asset_2](../../../../assets/docs/isms/ia-de-2-assign-asset.png) **Note:** If you do not have permissions for the Asset Management model, you cannot assign assets. Also make sure that you have already added assets to your Asset Management. **Practice Tip:** Start without assets first, as these often change faster than the "abstract" form of your security concept through updates or device replacement. You can therefore basically create your ISMS first based on the target object groups. ### Integration with ISO 27001 and IT-Grundschutz #### ISO 27001 Compliance The structural analysis in fuentis meets the requirements of ISO 27001: - **Clause 4.3:** Definition of ISMS scope - **Clause 8.1:** Asset inventory - **Annex A.8:** Asset Management Controls #### IT-Grundschutz Integration For each TOG, IT-Grundschutz-specific data can be recorded: - **Protection Requirements:** Normal, High, Very High - **KRITIS Relevance:** Critical infrastructures - **Personal Data:** Data protection relevance - **Availability Requirements:** SLAs and RPO/RTO ### How the fuentis Suite Supports #### Automation and Efficiency - **Templates:** Reusable TOG templates - **Bulk Operations:** Mass editing of TOGs (Additional functions are on the roadmap) - **Export:** Excel integration for inventory data - **Inheritance:** Automatic protection requirements inheritance #### Visualization and Reporting - **Main Tree View:** Hierarchical display of all elements - **Dependency Diagrams:** Graphical link representation - **Audit Trail:** Complete change documentation - **Dashboard:** Real-time overview of ISMS status #### Workflow Integration - **Review Process:** Structured review - **Approval Workflows:** Multi-stage approvals - **Notifications:** Automatic status updates - **Role-based Views:** Customized user interfaces ### Common Challenges and Solutions #### Challenge: Too Detailed Structural Analysis **Problem:** Hundreds of individual assets complicate management **Solution:** Group similar assets into TOGs, e.g., "Office PCs Floor 3" instead of individual computers #### Challenge: Unclear Dependencies **Problem:** Cascade effects during failures not recognizable **Solution:** Systematic linking of all TOGs, regular review of dependencies #### Challenge: Missing Documentation **Problem:** Existing IT landscape not completely recorded **Solution:** Gradual recording, use of automatic discovery tools, workshops with IT managers #### Challenge: Import of Existing Information **Problem:** You already have a list of assets you want to import. **Solution:** We can work with you to find a solution for how to automatically import this content into the fuentis Suite. Please feel free to contact us! ### Next Steps After completing the structural analysis, the following steps follow: 1. **Protection Requirements Assessment:** Assessment of criticality 2. **Risk Analysis:** Identification of threats 3. **Measure Planning:** Definition of security controls 4. **Implementation:** Implementation of measures 5. **Monitoring:** Continuous improvement ### Introduction Video
Play video

The video is hosted on YouTube. Playing it sends data to Google.

--- ### Key Messages at a Glance 1. **Foundation of Information Security:** Protection requirements assessment is not a bureaucratic obligation, but the basis for effective and efficient security measures. 2. **Three Protection Objectives in Focus:** Confidentiality, integrity, and availability must be individually assessed for each asset and categorized as normal/high/very high. 3. **Consider Inheritance:** Protection requirements are inherited from business processes through applications to IT systems – maximum principle or cumulation effects can lead to higher protection requirements. 4. **Use Tool Support:** The fuentis Suite automates many aspects of protection requirements assessment and ensures consistent implementation through workflows and questionnaires. 5. **Continuous Process:** Protection requirements assessment is not a one-time task but must be updated when IT landscape or business processes change. 6. **Structural Analysis is the Foundation:** No effective ISMS without clear inventory. 7. **Scope Defines Boundaries:** Focusing on the essential saves resources. 8. **TOGs Simplify Management:** Logical grouping instead of individual management. 9. **Links Show Dependencies:** Critical paths become visible. 10. **fuentis Suite Automates:** Workflows and templates accelerate implementation. --- *This article is based on the best practices of ISO 27001:2022 and BSI IT-Grundschutz. The described functions refer to fuentis Suite Version 4.* ## Monitoring Source: https://servicehub.fuentis.com/en/isms/isms-monitoring/ Continuous monitoring of the Information Security Management System (ISMS) is a central component of ISO 27001 and IT-Grundschutz. Effective monitoring enables organizations to track the progress of their security measures, identify weaknesses in documentation early, and demonstrably fulfill compliance requirements. The fuentis Suite offers a comprehensive solution with the monitoring module that goes beyond classic dashboards and reports. The module enables detailed evaluations at various ISMS levels and creates transparency about the implementation status of building blocks, requirements, measures, and controls. The monitoring module of the fuentis Suite enables monitoring at various structural levels: - **Building Blocks**: Superordinate security modules according to BSI-Grundschutz or custom structuring - **Requirements**: Specific security requirements within the building blocks - **Measures**: Concrete implementation steps to fulfill the requirements - **Controls**: Review mechanisms for effectiveness control (ISO 27001 Annex A) - **Target Object Groups (TOGs)**: Grouping of assets and protection objects ![monitoring-1](../../../../assets/docs/isms/monitoring-1.png) ### How the Monitoring Module Works #### Template-based Approach Monitoring in the fuentis Suite works with a flexible template system: 1. **Create template**: Define the monitoring perspective 2. **Select source**: Determine the elements to be monitored and their relationships 3. **Define unit**: Determine the organizational area 4. **Configure evaluation**: Customize the presentation and metrics ![monitoring-2](../../../../assets/docs/isms/monitoring-2.png) #### Available Monitoring Sources The system offers various source combinations for different analysis purposes: **Hierarchical Monitoring:** - Building Blocks → Requirements: Overview of building blocks with associated requirements - Building Blocks → Measures: Building blocks with derived measures - Requirements → Measures: Direct assignment of requirements to measures **Single Element Monitoring:** - Building Blocks: Isolated view of building blocks - Measures: Focus on measure implementation - Requirements: Status of individual requirements - Controls: Overview of control mechanisms **Asset-related Monitoring:** - Building Blocks → Target Object Groups: Building blocks in the context of affected assets - Measures → Target Object Groups: Measures related to protection objects - Requirements → Target Object Groups: Requirements for specific asset groups - Controls → Target Object Groups: Controls structured by target objects > **Practice Tip**: Choose the source based on your question: > - For compliance evidence: "Building Blocks → Requirements" > - For implementation controlling: "Requirements → Measures" > - For asset risk assessment: Combinations with Target Object Groups ### Practical Application #### Step 1: Create Template 1. Navigate to the "Monitoring" tab in the ISMS module 2. Click on the dropdown of available templates 3. Click on "+ Add New" 4. Enter a meaningful name (e.g., "Q4-2025 Compliance Check") 5. Select the relevant organizational unit 6. **Important**: Careful selection of the appropriate source for the analysis purpose 7. Save the template ![monitoring-3](../../../../assets/docs/isms/monitoring-3.png) #### Step 2: Use Monitoring Overview After creation, the template appears in the left column of the overview: - **Left column**: List of all created templates - **Right side**: Detailed view of the selected template - **Upper area**: Processed evaluation with key figures - **Main area**: Tabular presentation with drill-down capabilities **Interactive Elements:** - Arrows to expand and collapse hierarchical structures - Direct navigation to linked elements - Color coding according to implementation status ![monitoring-4](../../../../assets/docs/isms/monitoring-4.png) #### Step 3: Individualize View The gear symbol in the upper right opens the customization options: **Column Management:** - Show/hide individual data fields - Adjust column order - Define default views ![monitoring-5](../../../../assets/docs/isms/monitoring-5.png) **Save Options:** - "Save": Individual customization for current template - "Save All": Transfer to all templates - "Reset"/"Reset All": Restore default view #### Step 4: Export and Reporting The export button enables documentation of the monitoring status: 1. Select the desired template 2. Click on "Export" (upper right) 3. Automatic download as PDF file 4. PDF contains: - Selected key figures and metrics - Tabular overview according to configuration - Timestamp and version information > **Practice Tip**: Create regular exports for: > - Management reports (monthly/quarterly) > - Audit documentation > - Progress evidence for certifications ![monitoring-6](../../../../assets/docs/isms/monitoring-6.png) #### Step 5: Template Management **Delete Templates:** 1. Click on the delete symbol in the template overview 2. Confirmation in the pop-up dialog 3. Final removal of the template ![monitoring-7](../../../../assets/docs/isms/monitoring-7.png) **Best Practices for Template Management:** - Create templates for recurring evaluations - Use descriptive names with date/purpose - Archive templates that are no longer needed by exporting before deletion ### Integration into the ISMS Process #### Continuous Improvement Process (CIP) The monitoring module supports the PDCA cycle: **Plan**: Definition of monitoring templates for critical ISMS areas **Do**: Regular execution of monitoring **Check**: Analysis of results and identification of improvement potential **Act**: Derivation and implementation of corrective measures #### Compliance Review **Goal**: Evidence of ISO 27001 conformity **Note:** Here, the GAP Analysis module should also be particularly mentioned and used. **Procedure**: 1. Template "ISO 27001 Compliance" with source "Controls" 2. Filtering on Annex A controls 3. Export for external audit ![monitoring-1](../../../../assets/docs/isms/monitoring-1.png) #### Scenario 2: Project Progress **Goal**: Monitoring of an ISMS implementation project **Procedure**: 1. Template "ISMS Project Q4" with source "Requirements → Measures" 2. Weekly updates 3. Traffic light display for project control #### Scenario 3: Asset Risk Management **Goal**: Security status of critical assets **Procedure**: 1. Template "Critical Systems" with source "Measures → Target Object Groups" 2. Focus on high-critical TOGs 3. Prioritization of protection measures ### Additional Resources #### Video Tutorial
Introduction Video Monitoring (YouTube)

The video is hosted on YouTube. Playing it sends data to Google.

#### Glossary **ISMS**: Information Security Management System - Management system for information security **TOG (Target Object Group)**: Grouping of assets with similar protection requirements **Building Block**: Modular unit in BSI-Grundschutz for structuring security requirements **CIP**: Continuous Improvement Process according to PDCA cycle **PDCA**: Plan-Do-Check-Act - Management cycle for continuous improvement ### Key Messages at a Glance 1. **Flexible Monitoring**: The monitoring module offers flexible analysis possibilities for all ISMS levels through various source combinations 2. **Template-based**: Recurring evaluations can be saved as templates and efficiently reused 3. **Compliance Evidence**: Export functions enable audit-proof documentation for audits and certifications 4. **Customizable**: Views can be adapted to specific requirements and saved 5. **Integrated**: The monitoring module complements dashboard and reports with a detailed analysis perspective for continuous ISMS management ## Protection Requirements Assessment Source: https://servicehub.fuentis.com/en/isms/schutzbedarfsfeststellung-pra/ The Protection Requirements Assessment (PRA) is a central component of the IT security concept according to IT-Grundschutz and ISO/IEC 27001. It answers the fundamental question: **How much protection do our information, applications, and IT systems need?** Through systematic analysis, it is determined which assets are critical for the company and which security measures are appropriate. This creates the foundation for an efficient and effective Information Security Management System (ISMS). #### Why is the Protection Requirements Assessment relevant? - **Resource optimization**: Security measures are deployed specifically where they are most needed - **Transparency**: Traceable justification for security investments - **Compliance**: Meeting regulatory requirements (BSI IT-Grundschutz, ISO 27001) - **Risk minimization**: Systematic identification and assessment of protection requirements - **Prioritization**: Clear decision basis for implementing protective measures ### The Three Protection Goals in Detail **Note:** You can adjust the protection goals and values in the settings. The protection requirements assessment is based on the three fundamental protection goals of information security: #### 1. Confidentiality **Definition**: Information can only be viewed by authorized persons. **Practical meaning**: - Protection against unauthorized access to sensitive data - Preservation of trade secrets - Compliance with data protection regulations - Prevention of industrial espionage ![pr-1](../../../../assets/docs/isms/pr-1.png) #### 2. Integrity **Definition**: Information can only be modified by authorized persons. All changes are authentic and traceable. **Practical meaning**: - Protection against unauthorized manipulation - Ensuring data accuracy - Traceability of changes - Prevention of data corruption ![pra-2](../../../../assets/docs/isms/pra-2.png) #### 3. Availability **Definition**: Information and systems are available at the right time and place. **Practical meaning**: - Ensuring business continuity - Minimizing downtime - Guaranteeing critical processes - Compliance with Service Level Agreements (SLAs) ![pra-3](../../../../assets/docs/isms/pra-3.png) ### Protection Requirement Categories Protection requirements are divided into three categories based on potential damage impacts: #### Normal **Criteria**: - Damage impacts are limited and manageable - Financial losses remain tolerable - Maximum downtime: 24-72 hours - Minor or only internal reputation damage **Typical examples**: - Internal documentation - Non-critical administrative processes - Publicly accessible information #### High **Criteria**: - Damage impacts can be considerable - Significant financial losses, but not existentially threatening - Maximum downtime: 1-24 hours - Broad reputation or trust impairment possible **Typical examples**: - Personal data - Important business processes - Critical customer information #### Very High **Criteria**: - Existentially threatening, catastrophic impacts possible - Fundamental violations of laws and regulations - Maximum downtime: < 1 hour - Danger to life and limb possible **Typical examples**: - Critical infrastructure systems - Highly sensitive research data - Systems with potential for personal endangerment ### Damage Scenarios in Practice During protection requirements assessment, various damage scenarios are systematically considered: **Note:** You can store this information in the respective scope. #### 1. Violation of Laws/Regulations/Contracts - **Normal**: Minor contract violations, minimal penalties - **High**: Significant legal consequences, high fines - **Very High**: Fundamental law violations, ruinous liability damages #### 2. Impairment of Informational Self-Determination - **Normal**: Possible impairment of social standing - **High**: Significant impairment of economic circumstances - **Very High**: Danger to personal freedom of the affected person #### 3. Impairment of Task Fulfillment - **Normal**: Classified as tolerable by those affected - **High**: Classified as intolerable by individuals - **Very High**: Classified as intolerable by all #### 4. Financial Impacts - **Normal**: Tolerable financial damage - **High**: Considerable but not existentially threatening losses - **Very High**: Existentially threatening financial damage ### Implementation of Protection Requirements Assessment #### Phase 1: Preparation 1. **Definition of Protection Requirement Categories** - Adaptation to organization-specific requirements - Establishment of concrete threshold values - Coordination with management ![pra-5](../../../../assets/docs/isms/pra-5.png) 2. **Identification of Damage Scenarios** - Consider industry-specific risks - Include regulatory requirements - Analyze historical incidents #### Phase 2: Implementation ##### Protection Requirements Assessment for Business Processes **Procedure**: 1. Identify all relevant business processes 2. Assess confidentiality, integrity, and availability for each process 3. Involve department management in the assessment 4. Document justification **Practice Tip**: Use standardized questionnaires for uniform assessment. This accelerates the process and ensures comparability. ![pra-6](../../../../assets/docs/isms/pra-6.png) ##### Protection Requirements Assessment for Applications **Inheritance Principles**: - **Maximum principle**: The highest protection requirement of all supported business processes is adopted - **Cumulation effect**: Multiple processes with normal protection requirements can together result in high protection requirements **Important**: The cumulative effect is only activated when higherordinate target object groups are linked to target object group is 3 or more. ![pra-10](../../../../assets/docs/isms/pra-10.png) ![pra-8](../../../../assets/docs/isms/pra-8.png) **Example**: A CRM application supports multiple sales processes. Individually, these have normal protection requirements, but a complete failure would mean significant revenue losses → Availability: high ![pra-9](../../../../assets/docs/isms/pra-9.png) ##### Protection Requirements Assessment for IT Systems **Special considerations**: - Protection requirements inherit from applications running on them - Shared resources require special consideration - Virtualization can lead to cumulation effects ##### Protection Requirements Assessment for Communication Connections **Identify critical connections**: - Internet connections - Connections over public networks - Transmission of sensitive data - Single points of failure ##### Protection Requirements Assessment for Premises **To be considered**: - Physical access protection - Environmental conditions (climate, fire protection) - Concentration of critical systems - Redundancies and alternative locations ### Integration into the fuentis Suite #### Functionalities in the ISMS Module The fuentis Suite supports protection requirements assessment through: ##### 1. Structured Recording - **Protection Requirements Tab**: Central recording of all protection requirements - **Dropdown menus** for standardized categories - **Free text fields** for detailed justifications - **Custom PR Values**: Extension with organization-specific protection goals ##### 2. Automated Inheritance (Propagation) - **Propagation Tab**: Automatic transfer of protection requirements - **Override functions** for manual adjustments - **Visualization** of inheritance chains - **Bulk operations** for efficient processing ![pra-11](../../../../assets/docs/isms/pra-11.png) ##### 3. Intelligent Recommendations - **Algorithm-based analysis** of linked assets - **Maximum principle** and **cumulation effect** are automatically considered - **Preview function** shows effects before adoption - **Multi-select options** for flexible selection ##### 4. Workflow Integration (Four-Eyes Principle) - **Submit → Review → Approve/Reject → Reopen** - **Status tracking**: Initial, Submitted, Approved, Rejected, Reopened - **Audit trail**: Complete documentation of all changes - **Custom workflows**: Adaptation to organization-specific approval processes ##### 5. Questionnaire Module - **Standardized questionnaires** for uniform assessment - **Template library** with best practices - **Automatic evaluation** and categorization - **Export functions** for reports and audits #### Authorization Concept **Global Roles**: - `ISMS_PROTECTION_REQUIREMENT_ACCESS`: Basic access to PRA functions **Granular Permissions**: - `Scopes - PRA Read`: Read access to scope protection requirements - `Scopes - Edit Protection Requirements`: Editing of scope protection requirements - `TargetObject Groups - PRA Read`: Read access to TOG protection requirements - `TargetObject Groups - Edit Protection Requirements`: Editing of TOG protection requirements - `Propagation of Protection Requirements`: Execution of inheritance - `TargetObject Groups - Recommendation`: Use of recommendation function ### Best Practices for Implementation #### 1. Preparation and Planning ✓ **Secure management commitment** - Involve senior management early - Clarify budget and resources - Communicate commitment ✓ **Assemble project team** - Include department representatives - Ensure IT security expertise - Define clear responsibilities #### 2. Implementation ✓ **Follow top-down approach** - Start with critical business processes - Gradually advance to technical assets - Identify and implement quick wins ✓ **Strive for standardization** - Use uniform assessment criteria - Utilize questionnaires and templates - Conduct regular calibration meetings ✓ **Ensure documentation** - Justify all decisions - Make assumptions explicit - Document changes traceably #### 3. Quality Assurance ✓ **Consistently apply four-eyes principle** - Conduct independent reviews - Build in plausibility checks - Plan regular audits ✓ **Continuous improvement** - Document lessons learned - Regularly optimize processes - Establish feedback loops #### 4. Avoid Common Pitfalls **Avoid overestimation** - Not everything is "very high" critical - Make realistic assessments - Consider cost-benefit ratio **Prevent underestimation** - Don't underestimate cumulation effects - Fully capture dependencies - Think through worst-case scenarios **Control scope creep** - Define clear system boundaries - Maintain prioritization - Choose iterative approach ### Connection with Other ISMS Processes #### Risk Analysis Protection requirements assessment forms the basis for: - Identification of relevant threats - Assessment of probability of occurrence - Prioritization of risk scenarios #### Measure Selection Based on protection requirements: - Appropriate security measures are selected - Implementation priorities are established - Resources are optimally allocated ![pra-12](../../../../assets/docs/isms/pra-12.png) #### Business Continuity Management Protection requirements flow into: - Definition of Recovery Time Objectives (RTO) - Establishment of Recovery Point Objectives (RPO) - Prioritization in recovery #### Compliance Management Documentation supports: - Evidence for auditors - Meeting regulatory requirements - Transparency to stakeholders #### Glossary **Asset**: Value or resource of an organization (information, system, process) **Cumulation Effect**: Increase in protection requirements through concentration of multiple assets **Maximum Principle**: Adoption of the highest protection requirement during inheritance **Propagation**: Automatic inheritance of protection requirements between linked assets **TOG (Target Object Group)**: Logical grouping of assets **4EP (Four-Eye Principle)**: Four-eyes principle for quality assurance ### Key Messages at a Glance 1. **Foundation of Information Security**: Protection requirements assessment is not a bureaucratic obligation but the basis for effective and efficient security measures. 2. **Three protection goals in focus**: Confidentiality, integrity, and availability must be individually assessed for each asset and categorized as normal/high/very high. 3. **Consider inheritance**: Protection requirements inherit from business processes through applications to IT systems - maximum principle or cumulation effects can lead to higher protection requirements. 4. **Use tool support**: The fuentis Suite automates many aspects of protection requirements assessment and ensures consistent implementation through workflows and questionnaires. 5. **Continuous process**: Protection requirements assessment is not a one-time task but must be updated when the IT landscape or business processes change. ## Risk Monitoring Source: https://servicehub.fuentis.com/en/isms/risk-monitoring/ Risk management is a central component of every Information Security Management System (ISMS). It enables organizations to systematically identify, assess, and treat potential threats to their information assets through appropriate measures. The fuentis Suite offers an integrated solution that meets both the requirements of ISO 27001 and BSI IT-Grundschutz. #### Why is risk management relevant? Without structured risk management, organizations can: - Overlook critical security gaps - Use resources inefficiently - Miss compliance requirements - Be unprepared for security incidents - Lose the trust of customers and partners Continuous risk assessment is not only a requirement of international standards but also a business-critical process for protecting sensitive information and maintaining business continuity. **Note:** The risk monitoring module feeds from the information from the risk module of the fuentis Suite. You can get a complete overview here. ![rm-2](../../../../assets/docs/isms/rm-2.png) ![rm-3](../../../../assets/docs/isms/rm-3.png) ![rm-4](../../../../assets/docs/isms/rm-4.png) ![rm-5](../../../../assets/docs/isms/rm-5.png) ### The Risk Overview as a Central Instrument The risk overview in the fuentis Suite offers a **dynamic visualization of ISMS development** over defined time periods. It enables tracking changes in risk positions and documenting the success of risk mitigation measures. ![rm-1](../../../../assets/docs/isms/rm-1.png) #### Risk Treatments **Here you can view all risks and the associated risk treatments of a unit in detail. Simply click on the risk to open a detailed view** ![rm-6](../../../../assets/docs/isms/rm-6.png) **Risk Title & Status** - Display of the **risk name** with matching **icon**. - **Status badge** in color (Red / Orange / Yellow / Green) shows the current risk status. **Interaction & Navigation** - **Collapsible buttons (+/–):** Expand and collapse control and measure lists. - **Asset links:** Direct navigation to linked assets. - **Color coding (consistent):** - Green = Low / Implemented / OK - Yellow / Orange = Medium / In Progress - Red = High / Critical / Overdue ![rm-7](../../../../assets/docs/isms/rm-7.png) ##### Core Functions of Risk Overview: **1. Risk Values Tab** - Selection of organizational units or scopes - Filtering by different target object types (assets) - Display of risk title, risk relationship, and current status - Multiple selection for comparative analyses **2. Risk Matrix Visualization** - Display of the risk matrix defined for the scope - Selection of different risk types (e.g., gross risk, net risk, residual risk) - Color-coded display for quick identification of critical areas **3. Time-based Analysis** - **Predefined time periods**: Quick selection for standard periods - **User-defined time periods**: Flexible adaptation to individual requirements - **Step size configuration**: Granularity of temporal consideration (daily, weekly, monthly) - **Timeline slider**: Interactive navigation through risk history ![rm-1](../../../../assets/docs/isms/rm-1.png) #### Risk Treatment – From Analysis to Action Risk treatment in the fuentis Suite follows a structured workflow: ##### Process Steps of Risk Treatment: **1. Risk Identification and Selection** - Overview of all identified risks in the left navigation area - Status display for quick prioritization (open, in progress, treated) - Direct navigation to critical risks **2. Detailed Analysis** - Complete risk description with all relevant attributes - Link to affected target object groups (assets) - Historical development of risk value **3. Measure Planning** - Definition of risk mitigation measures - Assignment of responsibilities - Setting implementation deadlines - Documentation of expected risk reduction **4. Follow-up** - Monitoring of implementation status - Effectiveness testing of measures - Adjustment when needed #### Practice Tips for Effective Risk Management > **Practice Tip: Regular Risk Reviews** > Establish a fixed rhythm for risk reviews (e.g., quarterly). Use the time progression function to identify trends and act proactively. > **Practice Tip: Optimal Use of Step Sizes** > For strategic considerations, choose larger step sizes (monthly/quarterly). For operational analyses after security incidents, use daily or weekly steps. > **Practice Tip: Multi-Scope Analysis** > Compare risk profiles of different organizational units or locations to identify best practices and leverage synergies. > **Practice Tip: Documentation for Audits** > Regularly export PDF reports to fixed deadlines. These serve as evidence of continuous risk monitoring during certification audits. #### How the fuentis Suite Supports You Specifically The fuentis Suite offers several unique features for risk management: **1. Integrated Compliance Support** - Pre-configured risk catalogs for ISO 27001 and BSI IT-Grundschutz - Automatic linking of risks with requirements (controls) - Gap analysis to identify action needs **2. Flexible Risk Assessment** - Customizable risk matrices (3x3, 4x4, 5x5) - Configurable assessment criteria - Support for different risk types (gross, net, residual risk) **3. Workflow Automation** - Automatic notifications when thresholds are exceeded - Escalation mechanisms for critical risks - Reminder functions for risk reviews **4. Multi-tenant Capability** - Separate risk assessments for different organizational units - Consolidated reporting at corporate level - Role-based access control **5. Historization and Audit Trail** - Complete traceability of all changes - Audit-proof documentation - Compliance-compliant archiving ### Integration with Other ISMS Components Risk management is not an isolated function but closely integrated with other ISMS areas: #### Link with Asset Management - Risks are directly assigned to target objects (assets) - Protection requirement determination flows into risk assessment - Criticality of assets determines prioritization #### Connection to Measure Catalogs - Automatic suggestions from control libraries - Mapping to Annex A (ISO 27001) or BSI building blocks - Effectiveness testing of implemented controls #### Business Continuity Management (BCM) - Identification of business-critical risks - Basis for Business Impact Analysis (BIA) - Emergency planning based on risk scenarios #### Glossary of Important Terms **Gross Risk/Inherent Risk**: Risk assessment without considering existing measures **Net Risk**: Risk assessment considering already implemented measures **Residual Risk**: Remaining risk after implementation of all planned measures **Risk Matrix**: Graphic representation for classifying risks by probability of occurrence and damage amount **Scope**: Defined area of the organization for which the ISMS applies **Target Object (Asset)**: Resource worth protecting (information, system, process) **Control**: Measure for risk mitigation (technical, organizational, or physical) **Gap Analysis**: Systematic identification of gaps between current and target state ### Key Messages at a Glance ✓ **Holistic Approach**: The fuentis Suite offers an integrated risk management solution that seamlessly integrates with all ISMS components and supports both ISO 27001 and BSI IT-Grundschutz. ✓ **Time-based Analysis**: Through the unique time progression function, you can track the development of your risk situation and document the success of measures – essential for audits and management reviews. ✓ **Flexibility and Standards Compliance**: Customizable risk matrices, configurable assessment criteria, and pre-configured catalogs enable both compliance and organization-specific adaptations. ✓ **End-to-end Workflow**: From risk identification through assessment to measure implementation and follow-up – all steps are mapped in one system and documented in an audit-proof manner. ✓ **Decision Support**: Comprehensive export and reporting functions provide the basis for well-founded management decisions and transparent communication with stakeholders. ## Riskanalysis Source: https://servicehub.fuentis.com/en/isms/risikoanalyse-isms/ Risk analysis forms the foundation of every Information Security Management System (ISMS). It is the structured process for the systematic **identification, assessment, and treatment** of risks in the field of information security. Without a sound risk analysis, organizations cannot adequately protect their critical information assets. ![risk-1](../../../../assets/docs/isms/risk-1.png) #### Core Objectives of Risk Analysis * **Create transparency:** Make potential threats to information assets visible * **Enable prioritization:** Focus resources specifically on the greatest risks * **Ensure compliance:** Meet regulatory requirements (ISO 27001, BSI IT-Grundschutz) * **Promote proactivity:** Switch from reactive to preventive security strategy #### Relevance in ISMS Context According to **ISO 27001:2022**, risk analysis is not optional but a **central component** of the ISMS. It serves as the basis for: - The selection of appropriate security measures (Controls from Annex A) - The creation of the Statement of Applicability (SoA) - The continuous improvement of information security > **Practice Tip:** A risk analysis is particularly necessary when assets have high or very high protection requirements regarding confidentiality, integrity, or availability. ### Methodological Approaches: ISO 27001 vs. BSI IT-Grundschutz #### ISO 27001 Approach **Characteristics:** - **Flexible and individual:** Organization defines its own methodology - **Risk-based:** Continuous assessment and adaptation - **Internationally recognized:** Global standard - **Demanding:** Requires methodological maturity **Suitable for:** - Internationally operating companies - Organizations with specific requirements - Industries with high regulatory requirements (finance, healthcare) #### BSI IT-Grundschutz Approach **Characteristics:** - **Structured and comprehensive:** Predefined modules and threat catalogs - **Layer model:** Multiple security levels reduce dependence on precise assessment - **Practice-oriented:** Based on proven standards - **Guided:** Clear specifications and guidelines **Suitable for:** - German authorities and public administration - Companies with complex IT landscapes - Organizations with less experience in risk assessment > **Best Practice:** Many organizations combine both approaches - use the structure of IT-Grundschutz with the flexibility of ISO 27001. ### The Risk Management Process in Detail #### 1. Asset Identification **Objective:** Complete capture of all information assets worth protecting **Procedure:** - **Inventory:** Capture hardware, software, data, processes, and personnel - **Grouping:** Combine similar assets into Target Object Groups (TOG) - **Classification:** Define protection requirements (normal, high, very high) **Practice Example:** Instead of evaluating 500 individual servers, they are grouped by operating system, function, or criticality (e.g., "All Oracle Linux Servers - Production"). ![risk-3](../../../../assets/docs/isms/risk-3.png) #### 2. Risk Identification **Objective:** Systematically capture threats and vulnerabilities **Components:** - **Threats:** What could go wrong? - **Vulnerabilities:** Where are we vulnerable? - **Damage scenarios:** What would be the consequences? **Catalogs and Sources:** - BSI IT-Grundschutz Compendium (Threat catalog) - CVE databases for technical vulnerabilities - Industry-specific threat intelligence ![risk-4](../../../../assets/docs/isms/risk-4.png) #### 3. Risk Assessment **Central Concepts:** ##### Inherent Risk **Definition:** The risk without any protective measures - the "naked" threat situation. **Example:** Unencrypted data transmission during server migration - Probability of occurrence: High - Damage potential: €175,000 - Inherent risk: **High** ##### Target Risk **Definition:** The acceptable risk level after implementation of measures - in accordance with the organization's risk appetite. **Determination based on:** - Regulatory requirements - Business objectives - Stakeholder expectations - Cost-benefit analysis ![risk-5](../../../../assets/docs/isms/risk-5.png) #### 4. Risk Treatment **Four Strategies:** ##### A. Risk Reduction - **Most common strategy:** Implement controls - **Example:** Encryption, access controls, monitoring - **Implementation:** Select controls from ISO 27001 Annex A ##### B. Risk Avoidance - **Stop activity:** Eliminate risk source - **Example:** Renounce cloud storage of critical data - **When sensible:** Risk exceeds any possible benefit ##### C. Risk Transfer - **Shift responsibility:** Insurance or outsourcing - **Example:** Cyber insurance, managed security services - **Important:** Risk remains, only responsibility is shared ##### D. Risk Acceptance - **Conscious decision:** Tolerate risk - **Prerequisite:** Within risk tolerance - **Documentation:** Formal acceptance by management required ![risk-6](../../../../assets/docs/isms/risk-6.png) #### 5. Residual Risk Management **Definition:** The remaining risk after implementation of all measures. **Process:** 1. Assess effectiveness of implemented controls 2. Recalculate residual risk 3. Compare with target risk 4. If necessary, take further measures or formally accept > **Practice Tip:** Residual risk is never zero - it's about an acceptable level, not perfection. ![risk-7](../../../../assets/docs/isms/risk-7.png) #### The 5-Step Workflow 1. **Risk Identification** (Yellow) - Assign threats - Document vulnerabilities - Define damage scenarios 2. **Risk Assessment** (Yellow) - Determine inherent risk - Define target risk - Complete documentation 3. **Risk Treatment** (Yellow) - Choose strategy - Plan measures - Assign responsibilities 4. **Risk Mitigation** (Yellow) - Implement controls - Execute measures - Monitor status 5. **Residual Risk** (Green = Completed) - Assess residual risk - Obtain acceptance - Complete documentation **Color Coding:** - **Green:** Step completed - **Yellow:** In progress - **Gray:** Not yet started ![risk-8](../../../../assets/docs/isms/risk-8.png) #### Authorization Concept **Global Role:** `ISMS_RISKS_ANALYSIS_ACCESS` - Basic requirement for access to risk analysis **Granular Permissions:** - Risks - Read/Create/Edit/Delete - Threats - Assign/Edit/Delete - Measures - Create/Edit/Delete - Controls - Assign/Edit/Delete - Vulnerabilities - Create/Edit/Delete ### Glossary **Asset:** Any value to the organization (hardware, software, data, processes, personnel) **Control:** Security measure for risk mitigation (technical, organizational, physical) **CVE:** Common Vulnerabilities and Exposures - database of known vulnerabilities **GRC:** Governance, Risk Management, and Compliance **Inherent Risk:** Risk without consideration of controls **Residual Risk:** Remaining risk after implementation of measures **SoA:** Statement of Applicability - applicability statement for ISO 27001 **TOG:** Target Object Group - grouping of similar assets in the ISMS **Target Risk:** Desired/acceptable risk level ### Key Messages at a Glance **Risk analysis is mandatory:** No ISO 27001 certification and no effective ISMS without systematic risk analysis. **Choose methodology:** ISO 27001 for flexibility, BSI IT-Grundschutz for structure - or combine both. **5-phase process:** Asset identification → Risk identification → Assessment → Treatment → Residual risk management. **Tool support essential:** Manual risk analysis is no longer contemporary in complex environments. **Continuity instead of project:** Risk analysis is an ongoing process, not a one-time activity. ## Security Check Source: https://servicehub.fuentis.com/en/isms/isms-security-check-fuentis-suite/ In the modern working world, information has become a critical resource. Its protection is not only a technical challenge but a strategic necessity for every organization. **ISMS modeling** (Information Security Management System) forms the heart of a systematic approach to information security. #### Why is ISMS modeling relevant? Information represents the "knowledge" of an organization – an essential resource for modern management systems. The structured modeling of security requirements enables: - **Compliance requirements** to be systematically fulfilled (ISO 27001, BSI IT-Grundschutz) - **Security risks** to be assessed and treated object-specifically - **Protective measures** to be applied specifically to assets (TOGs) and scopes - **Audit capability** to be ensured through traceable documentation ### Core Concepts of ISMS Modeling #### The Four Pillars of Security Modeling ISMS modeling is based on four central security objects that build upon each other: **Attention:** This approach is oriented to both standards (ISO) and BSI - however, you can also omit the corresponding functions respectively. #### 1. **Modules** Modules are thematic groupings of security requirements, threats, and measures. **Properties:** - Categorization by protection areas (e.g., network security, access control) - Link with TOGs (Target Objects) and scopes - Automatic status calculation based on linked requirements - Audit tracking with documentation of audit cycles ![mod-1](../../../../assets/docs/isms/mod-1.png) #### 2. **Requirements** Concrete security specifications that must be fulfilled to ensure protection. **Properties:** - Detailed description of the security specification - Implementation status (Implemented, Partial, Not implemented, Dispensable) - Link with review questions for audits - Assignment to superordinate modules ![mod-2](../../../../assets/docs/isms/mod-2.png) #### 3. **Measures** Practical implementation steps to fulfill the requirements. **Properties:** - Concrete action instructions - Responsibility assignment - Temporal planning and prioritization - Link with multiple requirements possible ![mod-3](../../../../assets/docs/isms/mod-3.png) #### 4. **Controls** Review mechanisms to validate measure implementation. **Properties:** - Review criteria and methods - Audit cycles and evidence - Effectiveness assessment - Integration into continuous improvement management ![mod-5](../../../../assets/docs/isms/mod-5.png) ### Status Calculation and Assessment Logic The fuentis Suite uses intelligent status calculation that automatically aggregates the implementation level: #### Status Logic for Modules 1. **UNDEFINED**: At least one linked element has undefined status 2. **IMPLEMENTED**: All linked elements are implemented or dispensable 3. **NOT IMPLEMENTED**: All linked elements are not implemented 4. **PARTIAL**: Mixed implementation status (standard case) > **Practice Tip**: Automatic status calculation enables real-time overview of security status. Use dashboard views for management reporting! **Note:** Modules calculate from the total status of all linked requirements and measures. ![mod-7](../../../../assets/docs/isms/mod-7.png) #### Assessment Cascading Status propagates from bottom to top: - Measures → Requirements - Requirements → Modules - Modules → TOG/Scope overall status This cascading ensures that the overall status always reflects the weakest point (conservative principle). **Note:** You can also shorten the chain directly at requirements and measures. ### Working with the Security Check Phase #### Access Control and Permissions Access to the modeling phase is controlled through a granular permission system: **Global Role:** - `ISMS_SECURITY_CHECK_ACCESS`: Basic requirement for access **Function-specific Permissions:** - **Modules**: Read, Create, Edit, Delete, Add Reference - **Requirements**: Read, Create, Edit, Delete, Convert to Custom - **Measures**: Read, Create, Edit, Delete, Link - **Controls**: Read, Edit, Delete - **Review Questions**: Create, Edit, Delete #### Object Assignment and Referencing A central feature is flexible object assignment: **Direct Assignment:** - Catalog-based objects from standards (ISO, BSI) - User-defined objects for specific requirements **Referencing:** - Reuse of already assigned objects - Cross-TOG references for consistent requirements - Avoidance of redundancies > **Practice Tip**: Use references for company-wide application! Defined once, applied multiple times. ![mod-8](../../../../assets/docs/isms/mod-8.png) #### Review Questions and Audit Integration Review questions form the bridge between requirements and audits: **Functionality:** 1. Definition of specific review criteria per requirement 2. Structured recording of audit results 3. Evidence documentation and document management 4. Automatic measure derivation for deviations ### Best Practices for Implementation #### 1. Structured Approach **Phase 1: Foundation Modeling** - TOG structuring and scope definition - Selection of relevant standard modules - Initial status survey **Phase 2: Detailing** - Requirement adaptation to organizational context - Definition of specific measures - Responsibility assignment **Phase 3: Operationalization** - Implementation of measures - Setup of controls - Audit planning #### 2. Catalog vs. Custom Objects **When to use standard catalogs?** - Basic compliance with ISO/BSI - Industry standards - Quick start **When to create custom objects?** - Organization-specific requirements - Industry specifics - Internal policies #### 3. Export/Import Workflow Offline editing enables: - **Bulk updates** in Excel - **Review processes** without system access - **Archiving** for compliance evidence **Workflow:** 1. Export of relevant security objects (e.g. modules) 2. Offline editing in a structured format 3. Validation before re-import 4. Import with automatic consistency check > **Important:** The import can only be error-free if the exported file is imported into the same target object group from which it was originally exported. > **Practical Tip:** Use the export for quarterly reviews! Stakeholders can make changes in their familiar Excel environment. ![mod-8](../../../../assets/docs/isms/mod-8-7wq96z.png) ### How the fuentis Suite Supports The fuentis Suite offers an integrated environment for ISMS modeling: #### Automation & Efficiency - **Automatic status calculation** reduces manual effort - **Bulk operations** for efficient mass maintenance - **Template-based** object creation #### Collaboration & Workflow - **Role-based access** for distributed teams - **Comment functions** for coordination - **Versioning** for traceability #### Reporting & Compliance - **Dashboard visualizations** for management - **Compliance reports** for auditors - **Export functions** for external stakeholders #### Glossary **TOG (Target Object Group)**: Grouping of assets with similar security requirements **Scope**: Area of application of the ISMS, defines organizational and technical boundaries **Security Object (SO)**: Generic term for modules, requirements, measures, and controls **Custom Object**: User-defined security object outside of standard catalogs **Review Question (RQ)**: Structured review question for audit execution ### Key Messages at a Glance ✓ **Structured Security**: ISMS modeling transforms abstract security requirements into concrete, traceable measures ✓ **Automated Compliance**: Through catalog integration and status calculation, compliance management becomes efficient and transparent ✓ **Flexible Adaptation**: The combination of standard catalogs and custom objects enables tailored security concepts ✓ **Audit-Ready**: Integrated review questions and evidence ensure audit readiness at all times ✓ **Continuous Improvement**: The linking of requirements, measures, and controls creates a closed improvement cycle ## Settings Source: https://servicehub.fuentis.com/en/isms/isms-settings/ In the ISMS application options, you define basic settings that affect the entire ISMS – from protection goals through risk matrix configurations to import functionalities. **Why is this relevant?** - Individual adaptation of the ISMS to your organizational requirements - Standardization of assessment methods and risk matrices - Efficient data transfer from existing systems - Consistent protection goal definitions and adjustments ### Configuration Areas #### 1. Protection Goals ##### The Three Primary Protection Goals of Information Security **Confidentiality** - Protection against unauthorized disclosure of information - Confidential data may only be accessible to authorized persons in the permissible manner - Examples: Customer data, patents, research data, personal data (GDPR) - *Practical risks*: Open flipcharts after strategy meetings, accessible customer data in offices with public traffic **Integrity** - Ensuring the correctness and integrity of data - Protection against unauthorized modification, deletion, or insertion of data - Also includes metadata such as author or creation time - *Practical example*: Manipulation of measurement data from medical devices can have serious consequences **Availability** - Ensuring that systems and information are usable as intended - Permanent availability not necessarily required - Definition via Service Level Agreements (SLAs) - *Example*: Payroll system only needs to be available at defined times ![config-1](../../../../assets/docs/isms/config-1.png) ##### Extended Protection Goals In certain contexts, additional protection goals can be defined: - **Authenticity**: Genuineness and credibility of information - **Non-repudiation**: Provability of actions - **Accountability**: Legal binding to transactions - **Reliability**: Consistent system performance **Note:** You can also adjust the values (attributes) of individual protection goals in the fuentis Suite. #### 2. Managing Protection Goals ##### Creating a New Protection Goal **Accessing the Configuration:** 1. Switch to the ISMS module 2. Click on the gear symbol (bottom left) for application options 3. Navigate to the "Protection Goals" category 4. Click on "Create" **Important Note:** > Adding a new protection goal affects ALL target object groups! Already submitted or approved protection requirement assessments will be automatically unlocked and must be edited again. **Configuration Steps:** 1. **Assign names**: German and English 2. **Define values** (minimum 2, recommended 3): - Choose weighting level: Very low, Low, Normal, High, Very high, Critical - German and English designation for each value 3. **Save**: Click on "Create" ![config-2](../../../../assets/docs/isms/config-2.png) ![config-3](../../../../assets/docs/isms/config-3.png) ##### Editing and Deleting Protection Goals **Editing:** - Click on the edit symbol in the corresponding row - Adjustment of names and values possible - Changes affect the entire system ![config-4](../../../../assets/docs/isms/config-4.png) **Deleting:** - Click on the delete symbol - Deletion process takes a moment - Push notification confirms successful deletion - **Caution**: Deletion can have far-reaching effects ![config-5](../../../../assets/docs/isms/config-5.png) #### 3. Risk Matrix Configuration ##### Setting Options The risk matrix is the central element for risk assessment. In the application options, you can: ![config-6](../../../../assets/docs/isms/config-6.png) **Adjust Matrix Dimensions:** - 3x3, 4x4, 5x5, or 6x6 matrix selectable - Adaptation to organization-specific requirements - Translations available for all matrix sizes (except for some versions for 5x5) ![config-7](../../../../assets/docs/isms/config-7.png) **Configure Value Ranges:** - **Probability of Occurrence**: Percentage or qualitative scales - **Damage Amount/Impact**: Monetary values or categories - **Risk Categories**: Definition of acceptance areas ![config-8](../../../../assets/docs/isms/config-8.png) #### 4. Import Functionalities ##### Available Import Options **GRC Import:** - Migration from existing GRC system - Transfer of risk data and measures - Mapping to fuentis Suite 4 structures **Verinice Import:** - Data transfer from verinice.PRO - Preservation of links between objects - Automatic assignment to catalogs **Import Process:** 1. Application Options → Import 2. Choose import type (GRC or Verinice) 3. Click on "Import" 4. Select catalog and unit 5. Upload file via "Browse" 6. "Import" to execute **Note:** Please contact us for migration or import projects. ![config-9](../../../../assets/docs/isms/config-9.png) #### 5. Automatic Title Generation ##### Functionality Automatic title generation enables: - Uniform designations for target objects - Entity-specific prefixes for different object types - Automatic counters for sequential numbering **Configuration:** - **Access**: Application Options → Title Creation - **Authorization**: Role "Manage Title Prefixes" required - **Settings per Entity**: - Object type (TargetObject/Asset Group Type) - Title prefix - Counter value ![config-10](../../../../assets/docs/isms/config-10.png) **Example Configuration:** ``` IT System: IT-SYS-[001] Network: NET-[001] Room: ROOM-[001] Process: PROC-[001] ``` #### 6. Responsible Parties #### Meaning and Purpose Responsible parties map the governance structure of the ISMS and define clear responsibilities: - Role Assignment: Assignment of persons to functions in the ISMS - Decision Makers: Definition of approvers and contact persons - Traceability: Documentation of responsible parties for audit and compliance - Workflow Integration: Automatic notification in approval processes - Management of Responsible Parties - Access to Configuration ``` Name (required): Full name of the person Function: Professional role or position (e.g., ISMS Manager, IT Security Officer) Phone: Phone number for direct contact Email (required): Email address for notifications Unit (required): Organizational assignment (Units dropdown) ``` __Practical Application:__ - Notifications are sent to the stored email - Unit assignment enables organization-specific responsibilities - Particularly important for risk acceptances and measure approvals ![config-11](../../../../assets/docs/isms/config-11.png) ### 7. ISMS Profiles __Purpose and Benefits__ ISMS profiles enable the management of different security configurations for different contexts: - Multi-tenant Support: Separate profiles for different organizations or departments - Best Practice Templates: Predefined profiles for standards (ISO 27001, BSI-Grundschutz) - Quick Implementation: Standard configurations for new projects or locations - Compliance Variations: Profiles adapted to regulatory requirements - Structure and Management of ISMS Profiles - Access to Configuration: - Switch to the ISMS module - Click on the gear symbol (bottom left) for application options - Navigate to "ISMS Profiles" - Profile Properties (editable): - Name (required): Designation of the profile (e.g., "ISO - Mechatec GmbH") - Author: Creator or responsible person of the profile - Applicable Business Areas: Categories such as Manufacturing, IT Services, Services - Applicable Company Sizes: Size classes (Micro, Small, Medium, Large) for which the profile is relevant - Active: Toggle to activate/deactivate the profile - Description: Documentation of profile purpose and scope of application - Upload: ZIP file with profile configuration and catalogs __Advantages__ - Quick implementation for new organizational units - Compliance templates for regulated industries - Standardized assessment criteria and risk matrices - Export and import of configurations between systems **Note:** Attention, this function is only available to Professional customers or Enterprise customers. **Note:** You can download any scope as a profile. ![config-12](../../../../assets/docs/isms/config-12.png) ### 8. Incident Management Here you can control and enter the white and black list of emails per unit from which you want to receive incidents. ### Glossary **ISMS**: Information Security Management System - Management system for information security **Protection Goal**: Security objective for protecting information (confidentiality, integrity, availability) **Risk Matrix**: Two-dimensional representation for risk assessment based on probability of occurrence and impact **TOG**: Target Object Group - Target object group as structural element in the ISMS **Entity**: Organizational unit within the fuentis Suite **Scope**: Area of application of the ISMS **SLA**: Service Level Agreement - Agreement on availability ### Key Messages at a Glance 1. **Protection goals are fundamental**: The definition and weighting of protection goals influences the entire ISMS - plan changes carefully. 2. **Choose risk matrix size consciously**: The matrix dimension should match the organization size and risk complexity - more detail also means more effort. 3. **Prepare import well**: Ensuring data quality before import saves time and avoids errors in the productive system. 4. **Use automation**: Automatic title generation creates consistency and saves time in object creation. 5. **Keep performance in view**: For large amounts of data and complex matrices, ensure sufficient system resources. # BCMS Module ## BCMS-Modul Source: https://servicehub.fuentis.com/en/bcms/bcms-business-continuity-management-system/ The Business Continuity Management System (BCMS) is an essential component for ensuring business continuity in crisis situations. It helps organizations maintain their business-critical processes even during disruptions, failures, or disasters. The fuentis Suite offers a comprehensive BCMS module that guides you step by step through the implementation of standards-compliant Business Continuity Management. **Core objectives of BCMS:** - Identification of time-critical business processes - Systematic analysis of damage potential and downtime - Development of emergency plans and recovery strategies - Resource planning for emergency operations - Continuous improvement of crisis resilience ### Main Concepts and Requirements #### 1. BCM Initiation - Laying the Foundation BCM initiation must be initiated by the institutional management, as the decisions to be made have far-reaching consequences. All essential phases are documented in the fuentis Suite: ##### 1.1 Defining Scope **What is the scope?** The scope determines which area of the institution should be secured by the BCMS. This can include: - The entire institution - Individual locations or sub-areas - Specific products or services - Common business processes or production lines **Practice Tip:** The scope includes all infrastructural, organizational, personnel, and technical components that serve task fulfillment. Consider regulatory requirements and institutional objectives. ![bcms-1](../../../../assets/docs/bcms/bcms-1.png) ##### 1.2 Conception - Strategic Alignment The conception phase includes: **Objective Setting:** - Derive individual objectives from business processes - Consider legal framework conditions - Include institutional objectives - Transparent communication within the organization **Decision on Approach - Choice of BCMS Level:** - **Reactive BCMS:** Minimal preparation, reaction in case of emergency - **Standard BCMS:** Complete implementation according to standard (e.g., ISO 22301) ![bcms-2](../../../../assets/docs/bcms/bcms-2.png) ##### 1.3 Roles and Responsibilities **Important roles in BCMS:** **Business Continuity Officer (BC Officer):** - Primarily responsible for building and implementing the BCMS - Supports institutional management - Coordinates all BCM activities **Other roles:** - Crisis managers - Process owners - Members of the Special Organizational Structure (SOS) - Emergency team members **Practice Tip:** Mark mandatory roles and SOS memberships already when creating roles. This facilitates later assignment and documentation. ![bcms-4](../../../../assets/docs/bcms/bcms-4.png) ##### 1.4 Resource Categories **Basic Resources:** Certain resources are essential for the entire business operation: - Power and emergency power supply - Water supply - Climate control/ventilation - IT infrastructure - Telecommunications **Recovery Point Objective (RPO):** Defines the maximum tolerable data loss. Mark resource categories with RPO requirements accordingly. ![bcms-5](../../../../assets/docs/bcms/bcms-5.png) ##### 1.5 Document Types and Key Documents **Document Categories:** - Emergency plans - Recovery plans - Communication plans - Resource lists - Contact lists **Practice Tip:** Mark mandatory document types and link uploaded documents directly with the corresponding categories. ![bcms-7](../../../../assets/docs/bcms/bcms-7.png) ![bcms-8](../../../../assets/docs/bcms/bcms-8.png) #### 2. Business Processes - The Heart of BCMS ##### 2.1 Process Identification and Assignment Business processes form the basis for the Business Impact Analysis (BIA). They must: - Be created in asset management - Be assigned to the BCMS scope - Be linked with other processes (dependencies) - Be connected with relevant assets ##### 2.2 Process Linking **Relationship types between processes:** - **Upstream:** Process A must run before Process B - **Downstream:** Process B follows Process A - **Parallel:** Processes run simultaneously - **Dependent:** Process B needs output from Process A **Important:** In BCMS, only links between business processes are displayed, but complete linking with assets is important for comprehensive analysis. ![bcms-9](../../../../assets/docs/bcms/bcms-9.png) #### 3. Analysis Parameters - Creating Assessment Foundations ##### 3.1 Time Horizons **Standard time horizons for assessment:** - Immediate (0-4 hours) - Short-term (4-24 hours) - Medium-term (1-7 days) - Long-term (> 7 days) **Format for individual time horizons:** - w = weeks - d/t = days - h/s = hours - m = minutes Example: `2w 3d 4h 30m` = 2 weeks, 3 days, 4 hours, 30 minutes ![bcms-10](../../../../assets/docs/bcms/bcms-10.png) ##### 3.2 Damage Scenarios **BSI standard damage scenarios:** - Impairment of personal safety - Impairment of task fulfillment - Violation of laws, regulations, and contracts - Negative internal and external impact (image damage) - Financial impacts ![bcms-11](../../../../assets/docs/bcms/bcms-11.png) ##### 3.3 Damage Categories **Standard damage categories according to BSI:** | Category | Description | Impact | |-----------|--------------|---------------| | **Low** | Minimal, barely noticeable impacts | Insignificant impairment, no consequences | | **Medium** | Noticeable impacts | Work backlogs, tolerable financial damage | | **High** | Intolerable impacts | Massive restrictions, significant consequences | | **Very High** | Existentially threatening impacts | Danger to life and limb, existentially threatening damage | **Intolerability Level:** Defines the threshold above which damage is no longer acceptable. This determines the maximum tolerable downtime (MTPD). ![bcms-12](../../../../assets/docs/bcms/bcms-12.png) #### 4. Business Impact Analysis (BIA) - Assessing Criticality ##### 4.1 BIA Profile and Damage Potential **BIA objectives:** - Identification of time-critical business processes - Determination of failure impacts - Derivation of recovery requirements - Resource needs assessment for emergency operations **Damage potential assessment:** For each time horizon, the damage potential is assessed in the defined categories. The assessment is done graphically by positioning on the damage category scale. ![bcms-13](../../../../assets/docs/bcms/bcms-13.png) ![bcms-14](../../../../assets/docs/bcms/bcms-14.png) ##### 4.2 Critical Metrics **Maximum Tolerable Period of Disruption (MTPD):** - Maximum tolerable downtime of a business process - Calculated automatically based on damage potential and intolerability level **Recovery Time Objective (RTO):** - Target recovery time after a failure - Must be smaller than MTPD - Basis for emergency planning **Recovery Point Objective (RPO):** - Maximum acceptable data loss - Determines backup strategies - Relevant for IT-supported processes ![bcms-15](../../../../assets/docs/bcms/bcms-15.png) ##### 4.3 Dependencies and Resources **Analyze process dependencies:** - Internal dependencies (other processes) - External dependencies (suppliers, service providers) - Technical dependencies (IT systems, infrastructure) - Personnel dependencies (key persons, specialized knowledge) **Determine resource requirements:** - Minimum personnel for emergency operations - Critical IT systems and applications - Workplaces and facilities - Communication means - Special equipment or materials ![bcms-16](../../../../assets/docs/bcms/bcms-16.png) ### Implementation Aids and Best Practices #### Practical Tips for Implementation ##### Step-by-step approach: 1. **Preparation:** - Secure management commitment - Appoint BC officer - Assemble project team 2. **Initiation:** - Define scope - Determine BCMS level - Clarify roles and responsibilities 3. **Analysis:** - Identify business processes - Conduct BIA - Assess criticalities 4. **Strategy Development:** - Define emergency strategies - Create recovery plans - Plan resources 5. **Implementation:** - Document emergency plans - Conduct training - Plan tests and exercises #### Integration with ISO Standards **ISO 22301 - Business Continuity Management:** The BCMS module of the fuentis Suite is oriented to the requirements of ISO 22301: - Plan-Do-Check-Act (PDCA) cycle - Risk-oriented approach - Continuous improvement - Documented information **BSI Standard 200-4:** The implementation follows BSI recommendations for Business Continuity Management: - Level model (Reactive, Building, Standard) - Standardized damage categories - Structured approach #### How the fuentis Suite Supports **Automation and Simplification:** - Automatic calculation of MTPD and RTO - Graphic representation of damage potentials - Link with asset management - Integrated document management **Compliance and Audit:** - Standards-compliant documentation - Traceable processes - Audit trail for all changes - Certification preparation #### Common Challenges and Solutions **Challenge: Incomplete process landscape** - Solution: Gradual capture, starting with critical processes - Practice tip: Workshop-based process identification with functional departments **Challenge: Unrealistic recovery times** - Solution: Conduct realistic tests and exercises - Practice tip: Start with conservative estimates and optimize **Challenge: Lack of resources for emergency operations** - Solution: Define prioritization and minimum operations - Practice tip: Plan alternative strategies and external resources ### Key Messages at a Glance 1. **BCMS is a top management issue:** The initiation and responsibility for a BCMS lies with institutional management, while a BC officer coordinates operational implementation. 2. **Structured approach:** Development occurs in clearly defined phases - from initiation through BIA to strategy development and implementation. 3. **Focus on criticality:** The Business Impact Analysis identifies time-critical processes and determines maximum tolerable downtimes as the basis for emergency planning. 4. **Integration is crucial:** BCMS is not an isolated discipline but closely integrated with asset management, risk management, and ISMS. 5. **Continuity as a process:** Business Continuity Management is an ongoing process with regular tests, exercises, and adaptations to changed framework conditions. ### Further Information #### Glossary of important terms: - **SOS:** Special Organizational Structure - Crisis organization in emergency - **BIA:** Business Impact Analysis - Assessment of failure impacts - **MTPD:** Maximum Tolerable Period of Disruption - Maximum tolerable downtime - **RPO:** Recovery Point Objective - Maximum acceptable data loss - **RTO:** Recovery Time Objective - Target recovery time # Data Protection Module ## Dataprotection Management Source: https://servicehub.fuentis.com/en/dsms/dpms-datenschutz-management-modul/ The **EU General Data Protection Regulation (GDPR)** has imposed high requirements on the handling of personal data since 2018. Organizations must not only work in compliance with data protection regulations, but also **demonstrably document** this. This is exactly where the **Data Protection Management System (DPMS)** of the fuentis Suite 4 comes in: It offers a structured, software-supported solution for managing all data protection-relevant processes. The DPMS module is an **integral component** of the fuentis Suite 4 (codename Phoenix) and works seamlessly with other modules such as ISMS, BCMS, and Incident Management. This integration enables a **holistic governance strategy** where data protection is not considered in isolation, but in the context of overall information security. --- ### Core Concepts of the DPMS #### 1. Register of Processing Activities (RoPA) The **Register of Processing Activities (RoPA)** forms the heart of the DPMS. It documents all processing activities of personal data in your organization in accordance with **Art. 30 GDPR**. **Structural Setup:** - **RoPA** (main level): Represents the entire register of an organizational unit - **Processing Activities (PAs)**: Individual processing activities within the RoPA - **Hierarchical Organization**: Each entity (organizational unit) can maintain its own RoPA **Documented Information per Processing Activity:** - Processing purposes and legal bases - Categories of data subjects and data - Recipient categories (incl. third country transfers) - Deletion periods and retention duration - Responsible departments and contact persons ![VVT](../../../../assets/docs/dsms/vvt.png) #### 2. Technical and Organizational Measures (TOMs) TOMs are essential security precautions for protecting personal data. The DPMS distinguishes between: **Levels of TOM Application:** - **Global TOMs**: At RoPA level (apply to all subordinate processing activities) - **Specific TOMs**: Related to individual processing activities **TOM Categorization by Protection Goals:** - **Confidentiality**: Access control, encryption, pseudonymization - **Integrity**: Input control, transfer control, data carrier destruction - **Availability**: Backup concepts, emergency plans, recovery procedures - **Resilience**: Penetration tests, monitoring, incident response **Practical TOM Library:** The DPMS offers a predefined library with best-practice TOMs based on: - Standard Data Protection Model (SDM) - General Data Protection Regulation (GDPR) ![TOMs](../../../../assets/docs/dsms/toms.png) #### 3. Partner and Processor Management **Contract Management includes:** - **Data Processors**: External service providers who process data on behalf - **Joint Controllers**: Partners with shared data responsibility - **Data Transfers**: Documentation of third country transfers incl. safeguards **Automated Compliance Checks:** - Contract terms and termination periods - Updates of Standard Contractual Clauses (SCC) - Monitoring of adequacy decisions #### 4. Data Breaches **Integration with Incident Management:** Data breaches are initially recorded in the **Incident Management System (IMS)** and transferred to the DPMS when relevant. **72-Hour Notification Obligation Management:** - Automatic deadline calculation from awareness - Escalation mechanisms for critical incidents - Templates for supervisory authority notifications **Risk Assessment according to GDPR Criteria:** - Type of data concerned (special categories acc. to Art. 9 GDPR) - Number of affected persons - Possible consequences for data subjects - Remedial measures taken --- ![Sicherheitsvorfall](../../../../assets/docs/dsms/sicherheitsvorfall.png) ### Practical Application in the DPMS #### Workflow: From Recording to Compliance **1. Initial Inventory:** - Creation of RoPA structure per entity/tenant - Import of existing processing registers (Excel/CSV) - Mapping to business processes from Asset Management **2. Continuous Maintenance:** - Regular reviews by data protection officers - Updates for process changes - Versioning and change history **3. Compliance Evidence:** - Generation of GDPR-compliant reports - Audit trails for audits - Dashboard visualizations for management #### Integration with Other fuentis Modules **ISMS-DPMS Synergy:** - TOMs from the ISMS can be referenced as data protection measures - Joint risk assessment for information security and data protection - Unified controls for ISO 27001 and GDPR **BCMS Integration:** - Recovery times for critical data processing - Emergency plans for data breaches - Business impact analysis under data protection aspects **Asset Management Linkage:** - Automatic assignment of IT systems to processing activities - Hardware lifecycle and data deletion - Location-based data protection requirements ![Verbunden mit Assetmanagement](../../../../assets/docs/dsms/verbunden-mit-assetmanagement.png) --- ### Best Practices for DPMS Usage #### 1. Structured Approach **Practice Tip: Step-by-Step Implementation** > Start with critical processing activities (HR, customer data, health data) and expand gradually. Use the prioritization function by risk and data volume. #### 2. Leverage Automation **Efficiency Gains through:** - Predefined templates for standard processing activities - Bulk import/export functions - Automatic linking of similar TOMs - AI-supported suggestions for legal bases #### 3. Foster Collaboration **Multi-Stakeholder Approach:** - **Departments**: Record their processing activities - **IT Department**: Documents technical TOMs - **Data Protection Officers**: Review and approve - **Management**: Receives aggregated compliance dashboards #### 4. Continuous Improvement **PDCA Cycle in Data Protection:** - **Plan**: Conduct data protection impact assessments - **Do**: Implement and document TOMs - **Check**: Regular audits and reviews - **Act**: Adjust and optimize measures --- ### Reporting and Dashboards #### Operational Reports **Available Report Types:** 1. **Processing Register** (Art. 30 GDPR-compliant) 2. **TOM Overview** by protection goal and status 3. **Partner Register** with contract status 4. **Data Breach Log** for supervisory authorities 5. **Audit Trail** for internal/external audits ### Key Messages at a Glance 1. **Holistic Approach**: The DPMS is not an isolated solution, but deeply integrated into the fuentis Suite 4. Data protection is considered in the context of information security (ISMS), business continuity (BCMS), and incident management. 2. **GDPR Compliance by Design**: All functions are aligned with the requirements of the GDPR and international data protection standards – from processing documentation through TOM management to breach notification. 3. **Scalability**: Whether small organization with few processing activities or corporation with hundreds of companies – the DPMS adapts flexibly through its multi-tenant architecture. 4. **Practice Orientation**: Predefined templates, best-practice TOMs, and automated workflows significantly reduce implementation effort and enable quick successes. 5. **Future-Proofing**: Through open APIs, continuous updates, and integration of new compliance requirements, the DPMS remains current even with changing regulatory frameworks. --- ### Glossary **DPMS**: Data Protection Management System **RoPA**: Register of Processing Activities **PA**: Processing Activity - Individual processing activity **TOM**: Technical and Organizational Measure - Security precaution for data protection **Data Breach**: Data protection violation - Security incident involving personal data **DPO**: Data Protection Officer **DPIA**: Data Protection Impact Assessment **Joint Controller**: Shared data responsibility **Processor**: Data processor - External service provider **SDM**: Standard Data Protection Model - German reference model for data protection **Multi-Tenancy**: Ability to isolate data between organizational units # Support Modules ## Account-Management and Authentication Source: https://servicehub.fuentis.com/en/support/account-management-authentifizierung/ The secure management of user accounts and authentication are central pillars of information security in any ISMS. The fuentis Suite leverages Keycloak as its Identity and Access Management (IAM) system in the fuentis design to ensure secure and user-friendly account management. This page explains the key concepts, functions, and best practices for account management. For more information on rights and roles, see the respective module. **Why is this relevant?** Effective account management reduces security risks caused by weak passwords, unauthorized access, and insufficient authentication. It is a key component for meeting ISO 27001 requirements (A.9 Access Control) and BSI IT-Grundschutz (ORP.4 Identity and Access Management). ### Core Concepts and Functions #### Account Manager (Keycloak) The fuentis Suite uses Keycloak as its central identity management system. Each instance has its own Account Manager accessible via a specific URL: **URL Structure:** `https://auth.fuentis.com/auth/realms/[INSTANCE-NAME]/account/` **Example for the fuentis instance:** `https://auth.fuentis.com/auth/realms/fuentis/account/` ![accountmanager](../../../../assets/docs/support/accountmanager.png) > **Practical Tip:** Bookmark your Account Manager for quick access. #### Password Management The system enables users to manage their passwords independently: - **Self-service password changes** via the Account Manager - **Secure password policies** enforced by the system - **Immediate activation** of new passwords without admin intervention ![accountmanager-1](../../../../assets/docs/support/accountmanager1.png) **Features:** - Access via the "Passwords" tab in the Account Manager - Enter new password in two fields for confirmation - Immediate activation after saving #### Two-Factor Authentication (2FA) The fuentis Suite supports two-factor authentication as an additional security layer: - **TOTP-based authentication** (Time-based One-Time Password) - **Step-by-step setup** via the "Authenticator" tab - **Support for common apps** such as Google Authenticator and Microsoft Authenticator ![accountmanager-2](../../../../assets/docs/support/accountmanager2.png) **Setup process:** 1. Log into the Account Manager with your current credentials 2. Navigate to the "Authenticator" tab 3. Follow the guided setup instructions 4. Scan the QR code or enter the key manually 5. Confirm by entering a generated code ### Implementation Aids and Best Practices #### Password Security **Recommended password policies:** - Minimum length of 12 characters - Combination of uppercase, lowercase, numbers, and special characters - No use of personal information - Regular changes when compromise is suspected **Organizational measures:** - Train employees in secure password practices - Establish policies for handling passwords - Recommend the use of password managers > **Practical Tip:** Start enabling 2FA for privileged accounts (admins, auditors) and then roll it out to all users. ### How the fuentis Suite Supports You The fuentis Suite offers integrated solutions for account management: **Technical integration:** - Seamless SSO (Single Sign-On) - Automated user provisioning - Central user management via Keycloak - API-based integration with existing systems **Compliance support:** - Preconfigured security policies - Audit logs for compliance evidence - Role-based access control (RBAC) - Automatic logging of security events **User-friendliness:** - Self-service portal for password management - Intuitive fuentis design user interface - Mobile support for 2FA apps - Multilingual interface (German/English) **Note:** If you would like to synchronize with your directory service, please contact us. We will help you set it up! **Glossary:** - **2FA/MFA:** Two-/Multi-Factor Authentication - **TOTP:** Time-based One-Time Password - **SSO:** Single Sign-On - **IAM:** Identity and Access Management - **RBAC:** Role-Based Access Control - **Keycloak:** Open-source identity and access management solution ### Key Takeaways at a Glance 1. **Centralized management:** The fuentis Suite uses Keycloak for unified account management via instance-specific URLs. 2. **Self-service features:** Users can change passwords and set up 2FA independently, without admin intervention. 3. **Compliance-ready:** The system meets ISO 27001 and BSI IT-Grundschutz requirements for identity and access management. 4. **Security by design:** Integrated security features such as 2FA, secure password policies, and audit logging. 5. **User-friendliness:** Intuitive fuentis design interface with multilingual support and mobile compatibility. ## Asset Management Source: https://servicehub.fuentis.com/en/support/asset-management/ The Asset Management module in the fuentis Suite is the central platform for the systematic recording, management, and documentation of all information-relevant assets in your company. From IT systems and software licenses to sensitive databases and business processes – here you maintain full visibility over your corporate resources, which you protect through your efforts in ISMS, BCMS, and DSMC. **Note:** Asset Management is not required for using the ISMS. The BCMS module builds directly on assets. There are no target object groups in this module. You start here with the most important business processes. #### Why is structured Asset Management critical? In **ISO 27001** and **BSI IT-Grundschutz**, a complete asset inventory forms the foundation for: - **Risk analyses** and their evaluation - **Compliance evidence** for audits - **Business Continuity Management (BCM)** - **Incident response** and emergency management - **Informed security decisions** based on up-to-date data **Note:** In Asset Management, data can often be imported from IT service management products and other databases. Feel free to contact us for consulting. --- ### The Four Pillars of Asset Management The module structures your corporate assets into four main areas: 1. Scopes, 2. Assets, 3. Business Processes, 4. Organizational Structure. ![asset-management-main-1](../../../../assets/docs/support/screenshot-asset-management-introduction-de-edit.png) #### 1. Scopes – Defining Domains **Purpose:** Organize assets into logical management units (domains = scopes) - Every asset belongs to at least one scope - Scopes enable mapping of organizational structures, projects, or locations - Integration with ISMS/BCMS modules for seamless compliance ![assetmgmt-scope1](../../../../assets/docs/support/assetmgmt-scope1.png) ![assetmgmt-scope2](../../../../assets/docs/support/assetmgmt-scope2.png) ![assetmgmt-scope3](../../../../assets/docs/support/assetmgmt-scope3.png) **Permissions model:** - `ASSM_ACCESS_SCOPES` – Global access rights - Granular rights: Permissions can be set down to individual assets **Practical tip:** Scopes are structured similarly to those in the ISMS module. Permissions can be mirrored here. Typically, you should start with the ISMS, since assets tend to change more frequently. ***Example: A sales MacBook Pro 14" M3 2024 is replaced – the asset group (target object group) "Sales notebooks" remains.*** --- #### 2. Assets – The Core of Asset Management **Scope:** Documentation of all information-relevant assets - IT systems (servers, clients, network components) - Software and licenses - Databases and information systems - Physical assets (buildings, rooms, security technology) **Structure:** - Hierarchical organization into asset groups and types - Standard base attributes across all asset types - Type-specific attributes depending on category - Visual asset tree for intuitive navigation ![assetmgmt-asset1](../../../../assets/docs/support/assetmgmt-asset1.png) --- #### 3. Business Processes – Mapping Your Process Landscape **Focus:** Documentation of critical business processes and information flows - Recording process dependencies - Identifying critical information - Linking to supporting assets ![Business Processes](../../../../assets/docs/support/asset-business-process.png) **Permission:** `ASSM_ACCESS_BUSINESS_PROCESSES` --- #### 4. Organizational Structure – Clarifying Responsibilities **Content:** Mapping organizational units - Departments and teams - Roles and responsibilities - Contact information for emergency management ![Organization](../../../../assets/docs/support/organization.png) **Permission:** `ASSM_ACCESS_ORGANIZATION` --- ### Asset Management in Detail #### Asset Recording and Maintenance **Creation process (wizard-based):** 1. **Type selection**: Determines available attributes and relations 2. **Entity assignment**: Only entities with create permission are displayed 3. **Scope assignment**: At least one scope is mandatory 4. **Base data input**: Name and title (must be unique) 5. **Detail attributes**: Type-specific technical and organizational data ![assetmgmt-asset2](../../../../assets/docs/support/assetmgmt-asset2.png) ![assetmgmt-asset3](../../../../assets/docs/support/assetmgmt-asset3.png) **Batch operations:** - "Create another" checkbox for serial creation - Multi-select for deletion ![assetmgmt-asset4](../../../../assets/docs/support/assetmgmt-asset4.png) - Detailed view of assets - Attribute editing per asset ![assetmgmt-asset5](../../../../assets/docs/support/assetmgmt-asset5.png) --- #### Relationship Management – Linking Assets Assets are linked through two mechanisms: **1. Scope assignments (tab "Scopes"):** - Multi-scope capability: One asset can belong to multiple domains - At least one scope must always remain assigned - Required: Edit permission for scope + read for asset ![assetstructure1](../../../../assets/docs/support/assetstructure1.png) **2. Asset links (tab "Links"):** **General relation types:** - **Hierarchical**: "is parent to" / "is child of" - Universally applicable across all asset types - Multiple link types possible **Specific relation types:** - **Spatial**: "Contains" / "Is in" (for buildings/rooms) - **Technical**: Dependencies between IT components - **Organizational**: Responsibilities and ownership ![assetstructure2](../../../../assets/docs/support/assetstructure2.png) **Visualization:** - **Table view**: Clear list display - **Graph view**: Interactive hierarchy visualization - Asset boxes with direct info - Directed arrows show relation type and direction - Focus function: Recenter on selected asset - Go-to function: Jump directly to detail view ![assetstructure3](../../../../assets/docs/support/assetstructure3.png) --- ### Best Practices for Implementation #### Structuring and Organization **Building an asset hierarchy:** - Start with critical assets (crown jewels) - Use consistent naming conventions - Apply clear asset categories - Establish ownership early **Scope design:** - Align with organizational structure or locations - Separate scopes for projects or temporary structures - Use overlaps purposefully for matrix organizations --- #### Integration with ISMS/BCMS **Leverage synergies:** - Assets as the basis for risk analysis - Link with protection needs assessments - Input for Business Impact Analyses (BIA) - Foundation for contingency planning **Use the Task Manager:** - Schedule regular asset reviews - Automate inventory cycles - Update responsibilities on a schedule --- #### Permissions Management **Role-based approach:** ``` Global roles (module access): - ASSM_ACCESS_SCOPES - ASSM_ACCESS_ASSETS - ASSM_ACCESS_ORGANIZATION - ASSM_ACCESS_BUSINESS_PROCESSES Granular rights (per asset type and entity): - [AssetType] - Read - [AssetType] - Create - [AssetType] - Edit - [AssetType] - Delete ``` #### Ensuring Data Quality **Validation and maintenance:** - Enforce unique identifiers (name/title) - Define required fields sensibly - Perform regular consistency checks - Identify orphaned links --- ### Support from the fuentis Suite The fuentis Suite offers extensive support for efficient Asset Management: #### Automation - **Wizard-guided processes** for error-free data entry - **Batch operations** for mass changes - **Import interfaces** for existing data **Note:** We provide several interfaces to other CMDB and inventory tools. Contact us – we’ve always found a solution. #### Visualization - **Interactive graph views** for dependency analysis - **Hierarchy browser** for structured navigation - **Dashboard integration** for management reporting --- ### Further Resources
Introductory video on Asset Management

The video is hosted on YouTube. Playing it sends data to Google.

--- ### Key Takeaways at a Glance ✓ **Holistic approach**: Asset Management forms the basis for ISMS, BCMS, and risk management – a well-maintained asset inventory is key to effective information security ✓ **Four-pillar principle**: Structured management across scopes, assets, business processes, and organization ensures full transparency of corporate assets ✓ **Relationships matter**: Linking assets to each other and to scopes builds understanding of dependencies and simplifies impact analysis ✓ **Compliance by design**: The fuentis Suite supports ISO 27001 and BSI IT-Grundschutz-compliant asset management through predefined structures and workflows ## Catalog-Manager Source: https://servicehub.fuentis.com/en/support/catalog-manager/ The **Catalog Manager** is the central tool for structured management and utilization of compliance catalogs in your ISMS. It forms the foundation for **systematic, traceable IT compliance** by consistently linking **requirements**, **controls**, **threats**, **vulnerabilities**, **damage scenarios**, and **checks**. --- ### Why Do I Need Catalogs? Catalogs ensure that all stakeholders work with a **unified, reusable data foundation** – for example, in risk analyses, protection needs assessments, or control implementation. They create: - **Structure & Transparency** in security processes - **Comparability** between assessments and units - **Traceability** for audits/certifications - **Efficiency** through reuse of proven content > **Practical Tip:** Use catalogs also for **threats, vulnerabilities, and damage scenarios**. You can **reference** (e.g., use ISO 27001 but derive threats/controls from IT-Grundschutz). > **Note:** Upon request, we provide you with **relevant standard catalogs** and migrate existing content. --- ### Catalog Types & Use Cases The Catalog Manager supports different frameworks/standards: - **BSI IT-Grundschutz** (modules/requirements; incl. B3S/industry-specific standards) - **ISO Standards** (e.g., ISO/IEC 27001, 27002) - **Industry-Specific Standards** (e.g., SOC 2, TISAX®) - **Additional Management Systems** (e.g., ISO 42001 AI Management, ISO 9001) - **Custom Catalogs** (company-specific requirements) --- ### Navigation Overview When opening the module, you see the **catalog overview**. Standard catalogs are **write-protected** (pencil/trash grayed out). The left sidebar offers three main areas: ![katalog-uebersicht](../../../../assets/docs/support/katalog-uebersicht.png) 1. **Catalogs** – Management, import, versioning, content 2. **Structure Categories** – optional technical organization (rarely needed in practice) 3. **Protection Needs Questionnaires** – Templates/creation for standardized protection needs assessments > **Practical Tip:** Use questionnaires to **standardize protection needs**. We are happy to provide templates/best practices (see help section "Protection Needs Assessment"). --- ### Catalog Objects in Detail Catalogs consist of linkable **object types**. The **module principle** serves as a thematic framework (e.g., "Network Security") for related content. #### 1) Modules **Definition:** Thematic grouping (e.g., "Access Control", "Network Security"). **Important Fields:** - **Implementation Order** (prioritization) - **Responsibility** (roles/departments) - **Category** (technical assignment) #### 2) Requirements **Definition:** Specific specifications that must be met. **Important Fields:** - **Responsibility per Catalog** (framework default) - **Additional Responsibilities** (internal) - **Metadata** (description, implementation notes, evidence) #### 3) Controls **Definition:** Action instructions for fulfilling requirements. **Important Fields:** - **Lifecycle** (Planning → Implementation → Operation → Optimization) - **Effectiveness** (protective effect, evidence) - **Implementation Effort** (time/resources) #### 4) Threats **Definition:** Potential threats to information security. **Typical Categories:** - **Elementary Events** (fire, water, electricity) - **Deliberate Actions** (hacking, sabotage) - **Organizational Deficiencies** (missing processes/roles) - **Technical Failure** (hardware/software) #### 5) Vulnerabilities **Definition:** Weaknesses that threats can exploit. **Assessment Criteria:** Exploitability • Impact Potential • Detection Probability #### 6) Damage Scenarios **Definition:** Describe potential impacts. **Categorization by:** Confidentiality • Integrity • Availability • Compliance #### 7) Checks **Definition:** Audit/monitoring mechanisms for control implementation. **Components:** **Control Objective** (Target) • **Purpose** (Why) • **Guidelines** (How) --- ### Practical Implementation #### Creating Catalogs 1. **Catalogs** → **Create** 2. Maintain basic data: **Name**, **Description**, **Catalog Type**, **Scope of Validity** 3. **Save** ![katalog-anlegen](../../../../assets/docs/support/katalog-anlegen.png) #### Managing Content 1. Open catalog → **Create** 2. Select **Object Type** (Module/Requirement/Control/…) 3. Fill in **Fields & Metadata** (incl. responsibilities/evidence) > **Best Practice:** First define **modules**, then assign **requirements** and **controls**. ![katalog-inhalt](../../../../assets/docs/support/katalog-inhalt.png) #### Assigning Catalogs (e.g., in Risk Analysis) 1. Open module → **Catalogs** tab 2. Select **Assign** 3. Select relevant catalogs → Content is available context-specific --- ### Protection Needs Questionnaires The Catalog Manager contains an integrated **questionnaire function** for standardized protection needs assessments. #### Creating Questionnaires 1. **Questionnaires** → **Create** 2. **Type** (Protection Needs Assessment), **Unit**, **Name**, **Description** #### Modeling Questions & Answers **Questions (Core Elements):** - **Number** (ID) - **Protection Goal** (Confidentiality/Integrity/Availability) - **Question** (clear & measurable) - **Description** (explanation/examples) **Answers (Assignment):** - **Category** (normal/high/very high) - **Answer Text** (option) - **Description** (consequences/justification) > **Best Practice:** Per protection goal, at least **as many answer options** as protection needs categories exist. #### Example Items (Excerpt) | # | Protection Goal | Question | Assessment/Guideline | |---|-----------------|----------|---------------------| | 1 | Confidentiality | What would be the consequences of unauthorized access to the processed information? | **Normal:** minor impacts • **High:** significant legal/financial consequences • **Very High:** existential threat | | 2 | Availability | How long can the system/information be unavailable at most? | **Normal:** several days tolerable • **High:** up to 24 h • **Very High:** only a few hours | | 3 | Integrity | What would be the consequences of undetected data changes? | **Normal:** limited disruptions • **High:** significant process errors • **Very High:** security/compliance incident | **Answer Options (Example "Availability"):** - **Only a few hours tolerable** → business-critical → **very high** - **Maximum 24 hours tolerable** → significant impairments → **high** - **Several days tolerable** → non-critical → **normal** #### Activating Questionnaires 1. Open questionnaire → **Status** 2. Set **Active** ![frageboegen aktivieren](../../../../assets/docs/support/frageboegen-aktivieren.png) --- ### Structuring & Governance **Recommendations:** - **Hierarchical Catalog Structure** (topics → subtopics) - **Clear Naming Conventions** (prefixes, IDs, versions) - **Versioning & Change Log** (traceability) - **Roles/Owner per Object** (responsibility & maintenance) --- ### Typical Use Cases #### 1) Introducing New Technology 1. Review relevant standard catalogs 2. Add specific **threats/vulnerabilities** 3. Define **controls**, plan **checks** 4. Integrate into **risk analysis**/ISMS processes #### 2) Audit Preparation 1. Assign standard catalog(s) 2. Compare actual controls 3. Identify & prioritize gaps 4. Bundle evidence/controls --- ### Key Points at a Glance 1. **Central Compliance Platform:** The Catalog Manager combines BSI, ISO 27001, TISAX®, and custom catalogs in **one system**. 2. **Complete Model:** 7 object types (modules, requirements, controls, threats, vulnerabilities, damage scenarios, checks) comprehensively represent compliance. 3. **Flexible & Expandable:** Standard catalogs plus **custom** catalogs – incl. versioning and references. 4. **Standardized Protection Needs Assessment:** Questionnaires accelerate and standardize assessment. 5. **Seamless ISMS Integration:** End-to-end workflows in the fuentis Suite – from modeling to audit. ## Report-Module Source: https://servicehub.fuentis.com/en/support/report-module/ The reporting module of the fuentis Suite enables systematic documentation and communication of your Information Security Management System (ISMS). Reports are essential for the traceability of ISMS status, communication with management level, and fulfillment of compliance requirements according to ISO 27001 and IT-Grundschutz. They create transparency about the progress of individual ISMS phases and serve as a foundation for informed decisions. ### Central Concepts and Requirements > **Practical Tip:** With the ISMS modules Monitoring, Risk Overview, the Dashboards, and the ability to export all tables and information as .csv or .pdf files, the fuentis Suite provides a variety of evaluation and reporting functions. You can often use these better for e.g., management summaries or project updates. You will find more information about these functions in the corresponding help pages. ### Navigation When you navigate to the Reports area via the global navigation, you arrive at the following overview page: ![uebersichtseite-berichte](../../../../assets/docs/support/uebersichtseite-berichte.png) Here you will find all relevant information about the reports already created. You can create them using the button in the top right. In the table, you can download the reports, permanently delete them from the software, and view the metadata. > **Note:** In this module, you can also directly access the support module Workflows via the left navigation bar. This is not covered in this guide; you will find more information on the corresponding page in the Support Modules section. #### Report Types and ISMS Phases The report types in the fuentis Suite are directly oriented to the standardized phases of ISMS development. Each report type systematically documents the status and results of a specific phase: **Overview of Report Types:** | **Report Type** | **Phase (DE)** | **Phase (EN)** | **Focus** | |---|---|---|---| | A1 | Strukturanalyse | Inventory Analysis | Recording of all relevant IT assets, processes, and organizational units | | A2 | Schutzbedarfsfeststellung | Protection requirement assessment | Assessment of the criticality of information and systems | | A3 | Modellierung | Security Check | Assignment of security controls to identified assets | | A4 | IT-Grundschutz-Check | IT-Grundschutz-Check | Review of the implementation of baseline protection requirements | | A5 | Risikoanalyse | Risk analysis | Identification and assessment of security risks | | RTP (A6) | Realisierungsplan | Realisation plan | Planning and prioritization of measures for risk treatment | #### Scope The scope defines the organizational and technical boundaries of the ISMS for which a report is created. This can include the entire organization, individual locations, departments, or specific IT systems. Correct scope definition is crucial for: - The validity and relevance of the report - Fulfillment of regulatory requirements - Targeted communication with stakeholders #### Target Object Types Target object types categorize the various elements within your ISMS scope: - **Applications**: Software and applications - **IT Systems**: Servers, workstations, network components - **Rooms and Buildings**: Physical security areas - **Processes**: Business and IT processes - **Networks**: Network segments and communication connections - **People**: Roles and responsibilities ### Implementation in Practice #### Step-by-Step Process for Report Creation **1. Select Report Type** - Determine the ISMS phase to be documented - Select the corresponding report type (A1-A6) - Consider the current status of your ISMS development ![Report 1](../../../../assets/docs/support/bericht-1.png) ![Report 2](../../../../assets/docs/support/bericht-2.png) **2. Define Scope** - Define the organizational framework - Delimit technical systems - Ensure that the scope matches your ISMS documentation ![Report 3](../../../../assets/docs/support/bericht-3.png) **3. Report Configuration** - **Content Options**: Enable or disable specific report sections - **Design Adjustments**: Adapt the layout to your corporate identity - **Target Object Selection**: Select relevant object types or create a comprehensive report ![Report 4](../../../../assets/docs/support/bericht-4.png) **4. Report Preview and Creation** - Review the overview before final generation - Creation is automated in a few seconds - The report is generated as a PDF file ![Report 5](../../../../assets/docs/support/bericht-5.png) ![Report 6](../../../../assets/docs/support/bericht-6.png) #### Report Management **Download and Distribution** - Reports are stored centrally in the report overview - Download via the download icon - PDF format enables easy sharing and archiving ![Delete report](../../../../assets/docs/support/bericht-loeschen.png) **View Report Details** - Metadata such as creation date and author - Used configuration parameters - Version information for audit purposes ![Report details](../../../../assets/docs/support/berichtdetails.png) **Delete Reports** - Removal via the delete icon - Consideration of retention periods according to compliance requirements ![Delete report](../../../../assets/docs/support/bericht-loeschen.png) > **Practical Tip**: Create regular reports at defined times (e.g., quarterly) to document the development of your ISMS in a traceable manner. This facilitates both internal reviews and external audits. ### Best Practices for Effective ISMS Reporting #### Target Group-Oriented Preparation **For Management:** - Focus on overall status and critical risks - Executive summary with recommendations for action - Visualization of trends and KPIs **For Technical Teams:** - Detailed control lists - Specific technical requirements - Implementation status of individual controls **For Auditors:** - Complete documentation of all ISMS phases - Traceable decision-making processes - Complete audit trails #### Continuous Improvement - **Regular Report Creation**: Establish a fixed reporting cycle - **Comparability**: Use consistent report types for time comparisons - **Feedback Integration**: Use feedback to optimize the report structure - **Automation**: Plan recurring reports for increased efficiency > **Practical Tip**: Define report templates for different occasions (regular reporting, incident reports, audit preparation) to ensure consistent and efficient reporting processes. ### How the fuentis Suite Supports You The fuentis Suite offers an integrated solution for ISMS documentation with the reporting module: **Automation and Efficiency:** - Automatic data collection from all ISMS modules - Report generation in seconds - Consistent formatting and structure **Compliance Support:** - Predefined report types according to standards - Audit-compliant documentation - Complete evidence documentation **Flexibility and Customization:** - Configurable report content - Scope-based filtering - Multilingual support (DE/EN) **Integration and Collaboration:** - Seamless integration into the ISMS workflow - Export functions for external stakeholders - Central report management ### Further Resources #### Introduction Video A visual introduction to the reporting module can be found at: [https://youtu.be/DTY0I2_Z6Jw](https://youtu.be/DTY0I2_Z6Jw) ### Key Points at a Glance 1. **Structured Documentation**: The six report types (A1-A6) systematically map all ISMS phases and ensure complete documentation according to ISO 27001 and IT-Grundschutz. 2. **Flexible Report Configuration**: Through the selection of scope, target object types, and content options, reports can be prepared in a target group-oriented manner. 3. **Efficient Report Creation**: Automated generation in seconds and the PDF format enable quick creation and easy distribution. 4. **Compliance Support**: The predefined report types directly meet the documentation requirements of relevant standards and facilitate audits. 5. **Continuous Improvement**: Regular report creation creates transparency about ISMS development and supports data-based management decisions. ## Role-Based Access Control (RBAC) Source: https://servicehub.fuentis.com/en/support/rbac-fuentis-suite-4/ Role-Based Access Control (RBAC) is the foundation for secure and efficient rights management in Information Security Management Systems. The **fuentis Suite 4** implements a comprehensive RBAC concept that not only meets regulatory requirements but also enables practical work with different organizational structures and tenants. **Why is RBAC relevant?** - **Compliance requirements** - **Principle of least privilege**: Each user receives only the rights they need for their tasks - **Auditability**: Clear traceability of who can access which information - **Scalability**: Efficient management even with complex organizational structures ### Core Concepts of the RBAC System #### The Three Pillars of Rights Management ##### 1. **Entities** Entities map the organizational structure of your company. They serve as: - **Logical separation** of users and roles - **Organizational levels** (e.g., corporate headquarters, national organizations, departments) - **Basis for multi-tenancy** > **Practice Tip**: Use a consistent naming convention for entities, e.g., `[Level]_[Location]_[Function]` like `HQ_GLOBAL` for corporate headquarters or `UNIT_DE_FINANCE` for the German finance department. ![rbac-1](../../../../assets/docs/support/rbac-1.png) ##### 2. **Roles** The system distinguishes two role types: **Global Roles** - Predefined, non-editable permission sets - Apply across entities - Examples from fuentis Suite 4: - `ISMS_INVENTORY_ANALYSIS_ACCESS`: Access to inventory analyses - `ISMS_RISK_ANALYSIS_ACCESS`: Work with risk analyses - `WFM_EDITOR`: Workflow editing - `TSKM_MANAGER`: Task management with board functions - `CATM_READER/EDITOR`: Catalog management - `ASSM_INTEGRATION_MANAGER`: Configuration of external integrations ![rbac-2](../../../../assets/docs/support/rbac-2.png) **Custom Roles** - Flexibly customizable permissions - Entity-specific assignable - Ideal for fine-tuning access rights ![rbac-3](../../../../assets/docs/support/rbac-3.png) ##### 3. **Users** Users are: - Managed via **Keycloak** as central authentication service - Assigned to one or more entities - Provided with global and/or entity-specific roles ![rbac-4](../../../../assets/docs/support/rbac-4.png) #### Scopes and Multi-Tenancy **Scopes** extend the concept of entities: - Each entity has at least one scope - Enable granular separation within an entity - Basis for mapping information networks according to BSI IT-Grundschutz **Multi-Tenancy (Spaces)** enables: - Complete **data isolation** between tenants - **Individual configurations** per tenant - **Cross-tenant access** for collaborative work (controlled) ![rbac-5](../../../../assets/docs/support/rbac-5.png) ### Practical Implementation of the RBAC Concept #### User Lifecycle Management ##### Onboarding Process 1. **Application**: Formal request via IT service portal 2. **Approval workflow**: CISO/ISB approval required 3. **Account creation**: - Option A: Directly in Keycloak with subsequent synchronization - Option B: Via entity management with automatic email notification 4. **Role assignment**: Based on task profile 5. **Training & documentation**: Proof of briefing ##### Offboarding Process 1. **Deactivation request**: Upon departure/contract termination 2. **Immediate access revocation**: At termination date 3. **Monthly cleanup**: Review of inactive accounts #### RACI Matrix for Typical User Groups | Role | Responsible | Accountable | Consulted | Informed | |-------|------------|-------------|-----------|----------| | **CISO** | ✓ | ✓ | ✓ | ✓ | | **ISB** | ✓ | ✓ | ✓ | ✓ | | **External Auditor** | - | - | ✓ | ✓ | | **Inventory Manager** | ✓ | - | ✓ | ✓ | | **Risk Owner** | ✓ | - | ✓ | ✓ | | **IT Admin** | ✓ | ✓ | - | ✓ | | **Task Manager** | ✓ | ✓ | ✓ | ✓ | #### Module Permission Matrix The fuentis Suite 4 structures permissions modularly: ##### ISMS Module **Structural Analysis** - Scopes: Read (SL), Edit (SB), Delete (FA) - Target object groups: Full access for administrators - Asset links: Limited editable **Protection Requirements Analysis** - Protection requirement values: Editing by SiKo editors - Recommendations: Only usable by administrators - Distribution: Administrator rights required **Modeling** - Building blocks/requirements/measures: Read access for all, editing from SB - Custom elements: Creation from SiKo editor role - Import/Export: Permission for editors and higher **Risk Analysis** - Threats/risks: Complete management from SB role - Risk matrices: Exclusively administrators - Controls: Assignment by editors, management by admins > **Practice Tip**: Define role profiles for recurring task areas. Example: A "Risk-Analyst" profile could combine the roles `ISMS_RISK_ANALYSIS_ACCESS`, `ISMS_GAP_ACCESS` and `REPORTING_ACCESS`. ![rbac-6](../../../../assets/docs/support/rbac-6.png) ### Best Practices for RBAC Implementation #### 1. Map Organizational Structure Cleanly - Use **hierarchical entities** for corporate structures - Use **scopes** for functional separation - Apply **naming conventions** consistently #### 2. Optimize Role Assignment - Strictly follow **principle of least privilege** - Conduct **regular reviews** (quarterly) - Avoid **overlapping roles** - Document **deputy arrangements** #### 3. Safely Integrate External Users - Use **separate roles** with `_EXT` suffix - Set up **time-limited access** - Ensure **NDAs** before granting access - Activate **audit trail** for external access #### 4. Manage Multi-Tenant Environments - Ensure **data separation** through separate spaces - **Cross-tenant access** only targeted and documented - Implement **tenant-specific workflows** #### 5. Monitoring and Compliance - Regularly evaluate **access logs** - Document **permission changes** traceably - Establish **recertification** of permissions - Monitor **segregation of duties** (SoD) ### Technical Implementation in fuentis Suite 4 #### Keycloak Integration - **Single Sign-On (SSO)** for all modules - **LDAP/Active Directory** connection possible - **Two-factor authentication** optionally activatable - **Password policies** centrally manageable #### Synchronization and Consistency - **User sync** between Keycloak and fuentis Suite - **Role propagation** across all modules - **Caching mechanisms** for performance optimization ### Common Challenges and Solution Approaches #### Problem: Complex Corporate Structures **Solution**: Use hierarchical entities with inherited permissions. Parent units can define default roles for child units. #### Problem: Temporary Project Access **Solution**: Implement time-controlled roles with expiration date. Automatic deactivation after project end. #### Problem: Compliance Evidence **Solution**: Activate full audit log. Export permission matrix for audits. #### Problem: Performance with Many Users **Solution**: Role-based caching strategies. Asynchronous permission checks for non-critical operations. ### Key Messages at a Glance **RBAC is mandatory**: No ISO 27001 certification without structured rights management **Three-pillar principle**: Entities + Roles + Users = complete access control **Flexibility through hierarchy**: Global roles for basic functions, custom roles for special cases **Multi-tenancy ready**: Complete tenant separation with collaboration option **Compliance by design**: Automatic audit trails and traceable permission assignment --- **Additional Resources**: - Video Tutorial: [RBAC Introduction](https://youtu.be/u35Mdn8popE) ## Task Management Source: https://servicehub.fuentis.com/en/support/aufgaben-management-fuentis-suite/ Task management is a central support module in the fuentis Suite that enables the structured administration and tracking of all ISMS-related tasks. It forms the backbone of efficient team collaboration and ensures that every step required to implement and maintain an Information Security Management System (ISMS) is transparently documented and completed on time. #### Why is structured task management important? - **Compliance requirements**: An ISMS demands verifiable processes and their continuous improvement - **Transparency**: All stakeholders can view the status of measures and responsibilities at any time - **Risk minimization**: Critical security tasks are prioritized and completed on schedule — no more tasks falling through the cracks - **Audit readiness**: Complete documentation of all activities carried out for internal and external audits ### Core Concepts and Features #### Task overview and navigation The module provides three central views for task management: ##### 1. My Tasks - **Personal workspace** with all tasks assigned to the current user - **Filtering options** by status (Open, In Progress, Completed), priority, and task board - **View modes**: - List view for detailed oversight - Kanban board for visual task management with drag-and-drop functionality ![My Tasks 1](../../../../assets/docs/support/meine-aufgaben-my-tasks-1.png) ![My Tasks 2](../../../../assets/docs/support/meine-aufgaben-my-tasks-2.png) ![My Tasks 3](../../../../assets/docs/support/meine-aufgaben-my-tasks-3.png) ##### 2. All Tasks - **Comprehensive overview** of all tasks in the system - Same filtering and sorting functions as in “My Tasks” - Ideal for project leads and ISMS officers for overall coordination ##### 3. Task Boards - **Thematic grouping** of tasks by ISMS phases or projects - Assignment to specific workflows and organizational units - Automatic notifications when new tasks are added to the board #### Task creation and management ##### Creating tasks — two ways **1. Direct creation in the Task Module:** - Click the “Create” button to open the input dialog - Mandatory fields: Title, Description, Assignee (responsible person) - Optional fields: Task board, Priority, Start/End date - “Create more” checkbox for series creation ![Create task 1](../../../../assets/docs/support/create-task-1.png) ![Create task 2](../../../../assets/docs/support/create-task-2.png) ![Create task 3](../../../../assets/docs/support/create-task-3.png) **2. Context-based creation from ISMS phases:** - While working in Structural Analysis, Protection Needs Assessment, Modeling, or Risk Analysis - Via the three-dot menu → “Tasks” → “Create” - The task is automatically linked to the current context - Especially useful when specialist input is missing or additional contributions are needed > **Pro Tip**: When creating a task from a security object, the context (e.g., affected target object) is automatically stored in the task. This saves time and prevents information loss. ![Create a task in a phase 1](../../../../assets/docs/support/aufgabe-in-einer-phase-1.png) ![Create a task in a phase 2](../../../../assets/docs/support/aufgabe-in-einer-phase-2.png) ![Create a task in a phase 3](../../../../assets/docs/support/aufgabe-in-einer-phase-3.png) ##### Editing tasks - Click a task to open the detail view - The “Edit” button activates edit mode - All fields can be adjusted afterward - The change history is logged automatically ![Edit task 1](../../../../assets/docs/support/aufgabe-bearbeiten-1.png) ![Edit task 2](../../../../assets/docs/support/aufgabe-bearbeiten-2.png) ![Edit task 3](../../../../assets/docs/support/aufgabe-bearbeiten-3.png) ##### Deleting tasks - In the detail view via the “Delete” button - Only possible for authorized users - Deleted tasks are permanently removed ![Delete task](../../../../assets/docs/support/aufgabe-loeschen.png) #### Task Boards — Structured organization ##### Creating task boards **Mandatory information:** - **Name**: Unique name of the task board - **Description**: Purpose and scope of the board - **Workflow**: Link to a defined process - **Unit**: Associated organizational unit - **Placement**: ISMS phase (Structural Analysis, Protection Needs Assessment, etc.) **Optional settings:** - “Notify reporter”: Automatically notify the creator when new tasks are added ![Create task board 1](../../../../assets/docs/support/aufgabenfelder-erstellen-1.png) ![Create task board 2](../../../../assets/docs/support/aufgabenfelder-erstelle-2.png) ##### Managing task boards - **Edit**: Adjust all parameters via the edit icon ![Edit task board](../../../../assets/docs/support/aufgabenfeld-bearbeiten-edit-taskboard.png) - **Delete**: Remove via the delete icon (note: tasks assigned to the board must be reassigned first) ![Delete task board](../../../../assets/docs/support/aufgabenfeld-loeschen-delete-taskboard.png) ### Implementation Guidance and Best Practices #### Integration into the ISMS process **1. Structural Analysis phase:** - Task board “Inventory” for asset collection - Assign to specialist departments for detailed information - Set deadlines for complete inventory ![Structural Analysis 1](../../../../assets/docs/support/strukturanalyse-inventory-analysis-1.png) **2. Protection Needs Assessment:** - Separate task boards per security objective (Confidentiality, Integrity, Availability) - Prioritize by asset criticality - Escalation levels for missed deadlines ![Protection Requirements Assessment 1](../../../../assets/docs/support/schutzbedarfsfeststellung-protection-requirements-assessment-1.png) **3. Risk Analysis:** - Tasks for identified risks with risk rating as priority - Link to the measures catalog - Regular review tasks for risk monitoring ![Risk Analysis 1](../../../../assets/docs/support/risikoanalyse-risk-analysis-1.png) #### Workflow integration > **Pro Tip**: Always link task boards to a defined workflow from the Workflow Module. This ensures standardized procedures and makes traceability easier. ![Workflow 1](../../../../assets/docs/support/arbeitsablauf-workflow-1.png) Recommended workflow stages: 1. **New**: Task created but not yet started 2. **In Progress**: Active work is underway 3. **Review**: Quality assurance / four-eyes principle 4. **Completed**: Task successfully finished 5. **Blocked**: Waiting for external factors ![Workflow 2](../../../../assets/docs/support/arbeitsablauf-workflow-2.png) #### Using the Kanban board effectively **Advantages of the Kanban view:** - Visual representation of work progress - Rapid identification of bottlenecks - Easy prioritization via drag-and-drop - WIP limits (Work in Progress) to maintain focus ![Kanban](../../../../assets/docs/support/kanban-1.png) **Recommended column configuration:** - Backlog → To Do → In Progress → Testing → Done - Maximum of 5–7 columns for clarity - Color-coding by priority or task type ### How the fuentis Suite supports you Through its integrated task management module, the fuentis Suite delivers the following benefits: #### Seamless integration - **Context-based task creation** directly from all ISMS phases - **Automatic linking** to affected assets, risks, or measures - **End-to-end documentation** for audit trails and compliance evidence #### Collaboration features - **Multi-user capability** with role-based access control - **Real-time updates** for changes - **Comment function** for asynchronous communication ### Further Information #### Training videos and tutorials
Introductory video: Task Management

The video is hosted on YouTube. Playing it sends data to Google.

### Key takeaways at a glance 1. **Centralized management**: The Task Management module provides complete oversight and control of all ISMS-relevant tasks in one place. 2. **Context-based integration**: Tasks can be created directly from ISMS phases, automatically linking them to assets, risks, and measures. 3. **Flexible visualization**: Switch between list and Kanban views to monitor detailed information or workflow status as needed. 4. **Structured organization**: Task boards enable thematic grouping and improve clarity in complex ISMS projects. 5. **Compliance-ready**: End-to-end documentation of all activities ensures continuous audit readiness and meets ISO 27001 requirements. ## User Profile, Settings, and Dashboards Source: https://servicehub.fuentis.com/en/support/benutzerprofil-einstellungen-dashboards/ The fuentis Suite offers extensive personalization options that allow you to tailor your workspace to your individual needs and workflows. From basic profile settings and visual adjustments to customized dashboards – these features are essential for efficient work in the Information Security Management System (ISMS) and other modules of the Suite. **Why is this relevant?** - **Efficiency boost**: Personalized dashboards and quick access reduce navigation time - **Compliance support**: Clear visualization of measures, risks, and requirements in line with ISO 27001 - **User-friendliness**: Individual adjustments such as dark mode or font size improve ergonomics - **Role-based views**: Different dashboards for different responsibilities within the ISMS --- ### Main Concepts and Functional Areas #### 1. User Profile – Your Personal Control Center The user profile is the central starting point for all personal settings and preferences in the fuentis Suite. It consists of three main areas: ##### 1.1 Personal Data and Profile Picture **How to access profile settings:** 1. Click your user icon in the top-right corner of the interface 2. Select "Edit settings" 3. You will be redirected to your personal user settings ![profile_1](../../../../assets/docs/support/user-profile-1.png) ![profile-2](../../../../assets/docs/support/user-profile-2.png) **Manageable profile data:** - **Profile picture**: Upload via upload icon, remove via delete icon - **Contact details**: Name, email, phone number, and business information - **Organizational affiliation**: Department, position, ISMS responsibilities > **Pro tip**: A meaningful profile picture and complete contact details simplify collaboration, especially when assigning measures and responsibilities. ##### 1.2 Visual and Functional Adjustments **Language setting:** - Available languages: German and English - Instant switch for the entire interface - Important for international teams and auditors **Dark Mode:** - Reduces eye strain during long working sessions - Particularly useful in low-light environments - Switchable anytime in user settings **Font size adjustment:** - Adjustable via plus/minus controls - Accessibility support for users with visual impairments - Optimized readability across devices **Date format:** - Multiple international formats (DD.MM.YYYY, MM/DD/YYYY, etc.) - Important for correct ISMS documentation - Adaptable to regional or corporate standards **Note:** Combining font scaling with browser zoom may cause undesired effects. ##### 1.3 Security and Access **Logout function:** - Securely log out of the fuentis Suite - Essential for shared workstations - Protects sensitive ISMS data --- #### 2. Dashboards – Module-Specific Overviews Dashboards are individually configurable overview pages for specific modules such as ISMS or BCMS (Business Continuity Management System), or for the entire application (Launchpad). They provide quick insights into KPIs, statuses, and tasks. Each user can configure multiple dashboards, which must be activated to be visible. **Pro tip:** Create different dashboards for specific project phases and activate/deactivate them with a single click. ##### 2.1 Creating a Dashboard **Step-by-step:** 1. **Navigation**: User icon → Edit settings → Dashboards 2. **Creation**: Click "Create" 3. **Naming**: Provide a meaningful name and optional description 4. **Positioning**: Choose between: - **ISMS Dashboard** – specific to ISMS - **BCMS Dashboard** – for Business Continuity Management - **Launchpad** – cross-module overview ![dashboard-1](../../../../assets/docs/support/launchpad-1.png) ![dashboard-2](../../../../assets/docs/support/launchpad-2.png) ![dashboard-3](../../../../assets/docs/support/create-dashboard.png) ##### 2.2 Configuring Dashboards After creation, you can add and configure widgets: **Available ISMS widgets:** - **Modeling**: Overview of modules, measures, requirements, controls - **Risk analysis**: Inherent and residual risk display - **Measures by status**: Implementation progress - **Requirements by status**: Compliance overview - **Controls by status**: Effectiveness checks - **My tasks**: Personal to-do list ![dashboard-widgets](../../../../assets/docs/support/dashboard-modellierung-konfiguration-widget-de-10-12-2024.png) **Widget configuration options:** - **Data source**: Choose the information to display - **Unit and scope**: Filter by organizational unit - **Display form**: Chart type, colors, sorting > **Best practice**: Start with 4–6 widgets and expand as your needs evolve. ##### 2.3 Managing Dashboards **Activation/deactivation:** - Toggle switch at bottom left of dashboard card - Only active dashboards appear in modules - Multiple dashboards can be active in parallel **Editing:** - Pencil icon for name/description changes - "Configure" for widget updates - Drag & drop to rearrange widget positions **Deletion:** - Trash icon with confirmation dialog - Deleted dashboards cannot be restored --- #### 3. Launchpad – The Central Homepage The Launchpad is a cross-module overview page serving as the central entry point into the fuentis Suite. It provides quick access to modules and key information at a glance. ![launchpad-1](../../../../assets/docs/support/launchpad.png) ##### 3.1 Launchpad Highlights **Differences from dashboards:** - **Scope**: Entire fuentis Suite instead of a single module - **Widgets**: Cross-module rather than module-specific - **Access**: Via fuentis logo in the top-left - **Purpose**: Starting point and navigation hub ##### 3.2 Launchpad Widgets **Quick Access:** - Configurable shortcuts to frequently used functions - ISMS phase shortcuts - Custom links (e.g., to Service Hub) - Add via "+" in widget **Recent Target Object Groups:** - Displays recently edited assets/scopes - Quick re-entry into ongoing tasks **Cross-module statistics:** - Number of threats by risk value - Target object groups by type - Risks by inherent risk value - Task overview across all modules ![dashboard-launchpad](../../../../assets/docs/support/screenshot-launchpad-shortcuts-de-12-12-2024.png) **Other Launchpad widgets:** - Requirements count by status - Measures count by status - Threat count by inherent risk value - Target object groups by type - Risk count by inherent risk value - My tasks – personal task list with direct links - Control count by status ##### 3.3 Launchpad Quick Start **Recommended setup:** 1. **Quick Access widget** with links to: - All ISMS phases - Service Hub (documentation) - Frequently used reports 2. **Recent Target Object Groups** for quick continuation 3. **My Tasks** for personal task tracking 4. **Asset count by type** for inventory overview --- ### Implementation Aids and Best Practices #### Dashboard Quick Start Guide **Suggested ISMS dashboard setup:** 1. Name dashboard and select ISMS dashboard position 2. Arrange widgets in pairs (2 per row) 3. Configure **Modeling widget**: - Data source: Measures (ideal starting point) - Filter by relevant scope 4. Configure **Risk analysis widget**: - Data source: Inherent risk - Use same scope as Modeling widget 5. Activate dashboard for immediate use #### Dashboard Strategy **For ISMS managers:** - Create separate dashboards for different ISMS phases - Use risk widgets for management reporting - Configure measure widgets for implementation control **For operational staff:** - Focus on "My tasks" and assigned measures - Configure widgets for personal responsibilities - Add quick access for frequently used functions #### Widget Layout and Design **Suggested structure:** - **Row 1**: High-level KPIs (2 widgets) - **Row 2**: Detailed analysis (2 widgets) - **Row 3**: Personal tasks/actions **Visual hierarchy:** - Place most important KPIs top left - Group related widgets together #### Collaboration and Standardization **Team dashboards:** - Develop standard dashboard templates per role - Document widget configurations - Share best practices within teams --- ### Alignment with ISO 27001 and BSI IT-Grundschutz #### ISO 27001 Context Dashboard and personalization features support multiple ISO 27001 requirements: **A.5.1 Information Security Policies:** - Dashboards visualize policy compliance - Measures show implementation progress **A.6.1 Internal Organization:** - Role-based dashboards for responsibilities - Task widgets clarify accountability **A.18.2 Information Security Reviews:** - Risk widgets for ongoing monitoring - Status dashboards for management reviews #### BSI IT-Grundschutz Integration **Module monitoring:** - "Modules" widget shows implementation status - Requirements widget for Grundschutz checks **Protection needs analysis:** - Target object group widget for asset overviews - Risk widgets for protection level assessments --- ### How the fuentis Suite Supports You The fuentis Suite delivers significant value through personalization and dashboard features: #### Compliance Support - Dashboard screenshots for audits - Historical views of progress - Export functions for reporting - Transparent status tracking #### Integration and Interoperability - Unified interface across modules - Consistent usability concepts - Centralized user management - Single Sign-On support --- ### Additional Resources
Play video

The video is hosted on YouTube. Playing it sends data to Google.

#### Support [**fuentis Service Hub**](https://fuentis.atlassian.net/wiki/spaces/FSUG) --- ### Key Takeaways at a Glance 1. **Personalization increases efficiency**: Custom UI settings and dashboards reduce workload and improve ISMS clarity. 2. **Dashboards visualize compliance**: Widget-based display of measures, risks, and controls makes ISO 27001 compliance transparent. 3. **Launchpad as the central entry point**: Provides quick access to ISMS functions and reduces navigation effort. 4. **Role-based configuration**: Dashboards tailored to responsibilities support focused work without overload. 5. **Continuous optimization**: Dashboards should be updated regularly to meet evolving needs; the fuentis Suite offers flexible, no-code customization. ## VTI-Module Source: https://servicehub.fuentis.com/en/support/vti-threat-vulnerability-management/ The **VTI Module (Vulnerability & Threat Intelligence)** of the fuentis Suite 4 is a central component for the systematic identification, assessment, and management of threats and vulnerabilities within the ISMS framework. It forms the foundation for a well-founded risk analysis according to ISO 27001 and BSI IT-Grundschutz by enabling organizations to detect potential threats early and address them proactively. > **Note:** You can access this module as an automatic function in Asset Management. To do so, either click on an asset and then on the "Vulnerabilities (CVE)" tab, or click on the settings icon (gear wheel). Here you can now click on "Vulnerabilities (CVE)". ![Schwachstellen Tab Assets](../../../../assets/docs/support/schwachstellen-tab-assets.png) #### Why is VTI important? In the digital landscape, organizations are exposed to a multitude of cyber threats. The VTI module supports through: - **Proactive Security**: Early detection of vulnerabilities before they are exploited - **Compliance Fulfillment**: Demonstrable fulfillment of regulatory requirements (ISO 27001, BSI Standard 200-3) - **Risk Minimization**: Systematic reduction of the attack surface through structured vulnerability management - **Resource Optimization**: Prioritization of critical vulnerabilities based on actual risk **Attention:** Unfortunately, our VTI cannot yet automatically identify patches and thus already closed vulnerabilities for assets. This feature is still on the roadmap. ### Core Concepts and Definitions #### Threat A **threat** is a potential circumstance or event that can compromise the confidentiality, integrity, or availability of information. In the VTI context, we distinguish: - **Elementary Threats**: Basic threat scenarios from BSI catalogs (e.g., G 0.28 "Software vulnerabilities or errors") - **Specific Threats**: Threats tailored to the organization - **Emerging Threats**: Newly emerging threats from current threat intelligence sources #### Vulnerability A **vulnerability** is a weakness in a system, process, or control that can be exploited by a threat. Important aspects: - **CVE-based Vulnerabilities**: Common Vulnerabilities and Exposures from public databases - **Configuration Weaknesses**: Faulty system settings or processes - **Organizational Vulnerabilities**: Gaps in policies or procedures > **Practice Tip**: A threat only becomes a concrete danger when an exploitable vulnerability exists. Without a vulnerability, no risk can arise. #### Damage Scenario A **damage scenario** describes the concrete impacts when a threat successfully exploits a vulnerability: - **Primary Damages**: Direct impacts (e.g., data loss, system failure) - **Consequential Damages**: Indirect consequences (e.g., reputation loss, legal consequences) - **Cascade Effects**: Impacts on dependent systems and processes **Note:** You can also use the Catalog Manager to access additional functions here, such as reusability. ![Schadensszenario Risikoanalyse](../../../../assets/docs/support/schadensszenario-risikoanalyse.png) ### Practical Implementation with the fuentis Suite #### Asset Integration The VTI module is closely linked with Asset Management: 1. **Asset-based Vulnerability Assignment** - Direct linking of CVEs with affected IT systems - Automatic identification of vulnerable assets based on software inventory - Prioritization according to asset protection requirements 2. **Target Object Group Linkage** - Threats are assigned to target object groups - Inheritance of vulnerabilities along the asset hierarchy - Aggregated risk assessment at process level #### CVE Management and Threat Intelligence **Data Source Integration** - **Fuentis CVE Source**: Curated vulnerability database with verified entries - **NIST NVD Integration**: Automatic import of current CVE data - **MITRE ATT&CK Framework**: Mapping of threats to attack techniques **Automated Processes** ``` 1. Daily import of new CVEs from configured sources 2. Matching against asset inventory (software, versions, configurations) 3. Automatic risk assessment based on CVSS scores 4. Generation of action recommendations and tasks ``` ![CVE](../../../../assets/docs/support/cve.png) #### Workflow Integration **Vulnerability Lifecycle** 1. **Identification**: Automatic detection or manual import 2. **Assessment**: CVSS scoring and context evaluation 3. **Prioritization**: Risk-Based Vulnerability Management (RBVM) 4. **Remediation**: Measure planning and implementation 5. **Verification**: Verification of effectiveness 6. **Documentation**: Audit-compliant evidence documentation #### Risk Analysis Integration The VTI module feeds directly into risk analysis: **Risk Identification** - Threats and vulnerabilities are linked in risk objects - Automatic suggestions based on asset type and configuration - Context-related threat selection from catalogs **Risk Assessment** - Probability of occurrence based on: - CVSS Exploitability Score - Threat Intelligence indicators - Historical incident data - Damage impact derived from: - Asset protection requirements - Business Impact Analysis - Dependency analysis ### Best Practices and Implementation Aids #### Structured Setup 1. **Catalog Setup** - Import relevant threat catalogs (BSI, ISO, industry-specific) - Create organization-specific threats for unique risks - Maintain vulnerability templates for recurring vulnerability types 2. **Asset Preparation** - Complete software inventory (name, version, patch level) - Documentation of system dependencies - Classification by criticality and protection requirements 3. **Process Establishment** - Define clear responsibilities (Threat Owner, Vulnerability Manager) - Establish regular review cycles - Implement escalation paths for critical findings #### Metrics and KPIs > **Practice Tip**: Use the dashboard module of the fuentis Suite to visualize these KPIs. Create separate views for management and operational teams. #### Integration with Other Modules **ISMS Module** - Direct input for risk register - Basis for measure derivation - Evidence documentation for ISO 27001 audits **Task Management** - Automatic task generation for critical vulnerabilities - Workflow-based remediation processes - SLA tracking and escalation **Reporting** - Vulnerability Assessment Reports - Threat Landscape overviews - Compliance evidence for auditors **Catalog Manager** - Management of own threat catalogs - Import of external threat databases - Maintenance of vulnerability categories ### Common Use Cases #### Use Case 1: Patch Management Integration **Scenario**: Monthly Microsoft Patch Tuesday 1. Automatic import of new CVEs via VTI service 2. Matching against Windows assets in Asset Management 3. Risk assessment based on asset criticality 4. Task generation for IT operations with prioritization 5. Tracking and reporting of patch compliance #### Use Case 2: Zero-Day Response **Scenario**: Critical zero-day vulnerability (e.g., Log4Shell) 1. Immediate manual import of CVE 2. Automatic identification of affected systems 3. Impact assessment via dependency analysis 4. Emergency tasks with highest priority 5. Management reporting and communication #### Use Case 3: Compliance Audit Preparation **Scenario**: ISO 27001 recertification 1. Export of all addressed vulnerabilities from the last 12 months 2. Evidence of systematic threat monitoring 3. Documentation of risk treatment decisions 4. KPI dashboard for auditor presentation ### Key Messages at a Glance **Holistic Approach**: VTI integrates threat intelligence and vulnerability management in a coherent system that seamlessly integrates with asset management and risk analysis. **Automation as Key**: Through automated CVE import, asset matching, and task generation, manual effort is significantly reduced while simultaneously improving response time. **Risk-Based Prioritization**: Not every vulnerability is equally critical - context evaluation based on asset criticality and business impact enables focused resource allocation. **Continuous Improvement**: Through metrics and KPIs, the effectiveness of vulnerability management becomes measurable and can be systematically optimized. ## Workflow Management Source: https://servicehub.fuentis.com/en/support/workflow-management/ The workflow functionality of the fuentis Suite enables organizations to individually design and automate their ISMS processes. Instead of rigid procedures, the system offers flexible, customizable process models for different requirements – from protection needs assessment according to BSI-Grundschutz to general task management. **Core Benefits of Workflow Automation:** - Standardization of recurring processes - Transparent traceability of states and transitions - Compliance-compliant documentation of approval steps - Reduction of manual errors through defined process steps - Integration into existing ISMS phases > **Practical Tip:** Start with simple workflows and expand them step by step. An initial standard workflow is already available and can serve as a starting point. ### Workflow Categories and Their Areas of Application #### 1. General Workflows **Area of Application:** Support module "Tasks" **Main Features:** - Foundation for task management - Each task field is assigned a workflow - Standard states: To Do, In Progress, Done - Flexible expansion with any intermediate states possible **Typical Use Cases:** - Incident Management - Change Requests - Project Tasks - Audit Measures #### 2. Workflows for Protection Needs Assessment **Area of Application:** ISMS phase "Protection Needs Assessment" **Main Features:** - Specialized for BSI-Grundschutz requirements - Integration into the protection needs analysis process - Documentation of review steps - Traceable approval chain **Typical Use Cases:** - Evaluation of target object groups - Release processes for protection needs - Four-eyes principle for critical assets ### Structure and Design of Workflows #### Basic Elements of a Workflow ##### 1. **States** Each workflow consists of defined states that an object can go through: - **To Do:** Initial state, task awaiting processing - **In Progress:** Active processing in progress - **Done:** Final state, process completed - **Custom States:** Expandable as needed (e.g., "Review", "Waiting for Approval") ![workflow](../../../../assets/docs/support/workflow.png) ##### 2. **Transitions** Connections between states define possible process steps: - **Unidirectional Transitions:** Only forward movement possible - **Bidirectional Transitions:** Forward and backward movement allowed - **Conditional Transitions:** Dependent on permissions or criteria ##### 3. **Task Types** - **Review:** For release processes and quality assurance - **Task Management:** For operational activities #### Visualization in the Editor The graphical workflow editor enables: - Drag-and-drop positioning of states - Visual connection through click actions - Color coding by categories - Export/Import of workflow definitions ![Workflow editor 7](../../../../assets/docs/support/workflow-editor-7.png) > **Best Practice:** Additionally document complex workflows in a process manual to explain the business logic behind the technical procedures. ### Workflow Creation: Step-by-Step Guide #### Phase 1: Workflow Basic Configuration 1. **Navigate to Support Module "Workflow"** ![Workflow overview](../../../../assets/docs/support/workflow-overview.png) 2. **Click on "Create" button** (top right) ![Workflow overview](../../../../assets/docs/support/workflow-overview.png) 3. **Select Process Assignment:** - "General" for task management - "Protection Needs Assessment" for ISMS processes ![Create workflow 2](../../../../assets/docs/support/create-workflow-2.png) 4. **Define Task Type:** - "Review" for review processes - "Task Management" for operational tasks ![Create workflow 3](../../../../assets/docs/support/create-workflow-3.png) 5. **Add Description** (optional but recommended) 6. **Activation:** "Active" checkbox for immediate use ![Create workflow 4](../../../../assets/docs/support/create-workflow-4.png) #### Phase 2: Unit Assignment 1. **Switch to "Unit" tab** 2. **Click "Add Unit"** 3. **Select Organizational Unit:** - Department/Team - Location - Business Area #### Phase 3: Workflow Design in Editor ##### Create States: 1. **Click "+"-symbol** for new state ![Workflow editor 1](../../../../assets/docs/support/workflow-editor-1.png) 2. **Name State** (e.g., "Protection Needs Assessment pending") 3. **Choose Category** (To Do/In Progress/Done) 4. **Adjust Color** (optional) 5. **"Starts"-checkbox** for initial state 6. **Save** ![Workflow editor 2](../../../../assets/docs/support/workflow-editor-2.png) ![Workflow editor 3](../../../../assets/docs/support/workflow-editor-3.png) ##### Define Transitions: 1. **Click blue connection points** on the source state 2. **Choose target state** by clicking on its connection point 3. **Name Transition** (e.g., "Start Protection Needs Assessment") 4. **Add Description** (optional) 5. **Save** ![Workflow editor 5](../../../../assets/docs/support/workflow-editor-5.png) ![Workflow editor 6](../../../../assets/docs/support/workflow-editor-6.png) ##### Save Positions: - **"Save State Positions"** before leaving the editor ![Workflow editor 4](../../../../assets/docs/support/workflow-editor-4.png) > **Important Note:** When activating a custom workflow, all previous states of the affected objects are lost. Plan migrations carefully! ### Integration into ISMS Processes #### Protection Needs Assessment with Workflows **Integration Process:** 1. **Open ISMS Module** 2. **Select "Protection Needs Assessment" phase** 3. **Select Target Object Group** 4. **Status corresponds to workflow start state** 5. **"Approval" for state transition** ![SBF10](../../../../assets/docs/support/sbf10.png) ![SBF11](../../../../assets/docs/support/sbf11.png) ![SBF12](../../../../assets/docs/support/sbf12.png) **Practical Example:** ``` Start State: "Protection Needs Assessment pending" ↓ [Start Protection Needs Assessment] Intermediate State: "Protection Needs Assessment in progress" ↓ [Complete Protection Needs Assessment] End State: "Protection Needs Assessment completed" ↓ [Re-examination] (optional) Start State: "Protection Needs Assessment pending" ``` #### Task Management with Workflows **Kanban Board Integration:** - Visual representation of workflow states as columns - Drag-and-drop of tasks between states - Filtering by task fields - Permission-controlled transitions ![Workflow editor 8](../../../../assets/docs/support/workflow-editor-8.png) **Prerequisites:** 1. Create task field with workflow assignment 2. Assign tasks to the task field 3. Activate Kanban view 4. Set task field filter ### Best Practices for Effective Workflows #### 1. Workflow Design Principles **Keep it Simple:** - Maximum 5-7 states per workflow - Clear, self-explanatory labels - Avoidance of redundant transitions **Ensure Completeness:** - Map all realistic scenarios - Enable returns for corrections - Define escalation paths > **Practical Tip:** First implement workflow changes in a test environment and simulate critical processes before going live. ### Common Challenges and Solution Approaches #### Problem 1: Missing Return Options **Symptom:** Tasks cannot be reset to previous states **Solution:** - Open editor - Add bidirectional transitions - Create connections in both directions #### Problem 2: Workflow Activation Fails **Possible Causes:** - No start state defined - Missing unit assignment - Conflicts with other active workflows **Solution Steps:** 1. Check start state checkbox 2. Review units tab 3. Deactivate other workflows for the same unit ### Further Resources
fuentis Suite 4 – Dashboard and Task Management (YouTube)

The video is hosted on YouTube. Playing it sends data to Google.

### Key Points at a Glance ✓ **Two Workflow Types:** General workflows for task management and specialized workflows for protection needs assessment ✓ **Graphical Editor:** Intuitive workflow creation through drag-and-drop with visual state modeling ✓ **ISMS Integration:** Seamless integration into existing ISMS processes with compliance-compliant documentation ✓ **Flexibility:** Fully customizable states and transitions for individual business processes ✓ **Best Practice:** Start with simple workflows, gradual expansion, and testing before going live # Standards ## C5 Attestation – Standards and Implementation Guidelines for Secure Cloud Services Source: https://servicehub.fuentis.com/en/standards/c5-testat-standards-sichere-cloud-dienste/ The **Cloud Computing Compliance Criteria Catalogue (C5)** is an audit catalog developed by the Federal Office for Information Security (BSI) for cloud services. It defines minimum requirements for secure cloud systems and is aimed at professional cloud providers, their auditors, and customers. #### Why is C5 relevant? - **First published in 2016**, major revision in 2019 - **Broad acceptance** among large and small providers - **Guidance for risk management** for cloud customers - **Legal obligation in the healthcare sector** since 2024 (§ 393 SGB V) > **Important for healthcare:** Until June 30, 2025, a C5 Type 1 Attestation is sufficient. From July 1, 2025, a C5 Type 2 Attestation or equivalent standard will be mandatory. ### The 17 Requirement Areas of the C5 Catalogue The current **C5:2020 Catalogue** is based on ISO 27001 and covers the following core areas: #### Organizational Requirements - **Information Security Organization** Planning, implementation, and continuous improvement of an information security framework - **Security Policies & Work Instructions** Clear guidelines and instructions to support the security framework - **Personnel** Ensuring employees understand their security-related responsibilities and protecting assets during role changes - **Asset Management** Identification and adequate protection of assets throughout their lifecycle #### Technical Security Requirements - **Physical Security** Protection against unauthorized access and physical damage - **Operations** Secure operations including capacity planning, malware protection, logging, vulnerability management, and incident handling - **Identity & Access Management** Safeguarding authorization and authentication of privileged users - **Cryptography & Key Management** Effective use of encryption to ensure confidentiality, integrity, and authenticity - **Communication Security** Protection of information in networks and systems #### Cloud-Specific Requirements - **Portability & Interoperability** Ensuring data can be exported at contract termination and deleted by the provider - **Product Security** Secure configurations, vulnerability information, error handling mechanisms, and customer authentication/authorization #### Process Requirements - **Development & Change of Information Systems** Integration of information security into development and change processes - **Supplier & Subservice Provider Management** Secure information processing by subcontractors and monitoring compliance with agreed requirements - **Incident Management** Consistent procedures for capturing, evaluating, and handling incidents - **Business Continuity & Disaster Recovery** Planning and testing of business continuity and disaster recovery measures #### Compliance and Governance - **Compliance** Meeting legal, regulatory, and contractual information security requirements - **Handling Government Investigations** Appropriate treatment of governmental investigation requests ### Types of C5 Attestations in Detail #### Type 1 Attestation **Characteristics:** - Reviews the **design of internal controls** at a specific point in time - Does not assess the effectiveness of controls - Suitable for initial audits or when operational data is not yet available - Can serve as a transitional solution **Use Cases:** - New cloud services without operational history - Transitional phase in healthcare (until June 30, 2025) - Preparation for Type 2 certification #### Type 2 Attestation **Characteristics:** - Assesses **design AND effectiveness** of controls - Examination over a defined period (typically 6–12 months) - Requires proof of effective operation - Considered the standard for C5 **Use Cases:** - Regular operations of established cloud services - Mandatory in healthcare from July 1, 2025 - Strong basis for risk management ### Audit Process and Reporting Standards #### ISAE 3000 (Revised) as Foundation C5 audits follow the internationally recognized assurance standard: - **Audit Standard:** ISAE 3000 (Revised) - **Reporting Format:** SOC 2 report with C5-specific additions - **Additional Standards:** ISAE 3402, SOC 2 applied analogously #### Quality Criteria for C5 Attestations Cloud customers should review the following when evaluating a C5 attestation: 1. **Auditor Qualification** - Conducted in accordance with ISAE 3000 - Information about the entire audit team included 2. **Reporting Principles** - Relevance - Completeness - Reliability - Neutrality - Understandability 3. **Type of Opinion** - **Unqualified:** Full compliance with all criteria - **Qualified:** Deviations present, must be assessed 4. **Timeliness** - Attestation should be current (usually renewed annually) - Audited period must be clearly specified ### C5:2025 – The Next Generation The BSI working group is currently developing C5:2025 with key updates: #### International Harmonization - **EUCS Integration:** Assurance level "Substantial" of the European Cloud Certification Scheme - **ISO/IEC 27001:2022:** Alignment with the latest version - **NIS2 Directive:** Incorporation of EU requirements - **CSA Cloud Controls Matrix v4:** Compatibility with international standards #### New Technical Topics - **Container Management** - **Supply Chain Security** - **Post-Quantum Cryptography** - **Confidential Computing** - **Stricter Tenant Separation** - **Digital Sovereignty** #### Structural Improvements - Subcriteria for better auditability - New criteria categories: - "Additional Sharpen" (stricter) - "Additional Complement" (supplementary) ### Relations to Other Standards #### ISO 27001 / ISO 27017 - Many C5 criteria derived from ISO 27001 Annex A - Existing ISO 27001 ISMS serves as a solid foundation - Statement of Applicability (SoA) enables mapping to C5 #### SOC 2 / ISAE 3000 - C5 audit reports issued as SOC 2 reports - SOC 2 covers Trust Service Principles - C5 adds cloud-specific requirements: - Transparency - Tenant separation - Government investigations #### C5 Equivalence Regulation During the transition period, the following may serve as temporary replacements: - **ISO 27001:2022** - **BSI IT-Grundschutz** - **CSA CCM v4** **Conditions:** - Additional measures to close gaps required - Maximum 18-month transition period - Especially for small providers ### Implementation Aids and Best Practices #### Phase 1: Risk-Based Planning and Preparation ##### Secure Management Commitment - Anchor relevance of C5 at executive level - Provide sufficient resources - Clearly define responsibilities ##### Define Scope - Identify affected cloud services - Define regions and customer data - Consider legal requirements (e.g., SGB V) - Document scope decisions ##### Establish Risk Management - Build asset inventory - Analyze threats and vulnerabilities - Assess likelihoods - Use established ISO 27005 methods ##### Conduct Readiness Assessment - Pre-audit (e.g., SOC 2 + C5 readiness) - Identify gaps in existing controls - Develop an implementation roadmap #### Phase 2: Implementing C5 Controls ##### Select and Adapt Controls - Identify relevant C5 criteria - Leverage overlap with ISO 27001 (e.g., access control, incident response) - Implement cloud-specific controls (tenant isolation, portability, investigations) ##### Documentation and Evidence - Create policies and processes - Collect evidence for all controls - For Type 2: provide operational evidence (logs, change management, audit trails) ##### Involve Subservice Providers - Ensure subcontractor C5 compliance - Accept equivalent certificates where applicable - Integrate evidence into own audit ##### Continuous Monitoring - Conduct regular internal audits - Perform management reviews - Test control effectiveness - Implement ongoing monitoring ### Practical Tips for Implementation > **Tip 1: Use Transition Rules** > Small providers can use the C5 Equivalence Regulation for up to 18 months. An ISO 27001:2022 or IT-Grundschutz certificate serves as a temporary replacement for a C5 Type 1 Attestation. A plan for closing remaining gaps is required. Use this period to prepare for full Type 2 certification. > **Tip 2: Implement Tenant Separation Precisely** > A focus of C5:2025 is strict tenant isolation. Ensure your cloud platform technically separates tenant data. Document mechanisms such as tenant isolation and per-tenant encryption clearly. > **Tip 3: Strengthen Supply Chain Security** > New requirements call for tighter supplier and subcontractor controls. Integrate third-party risk management into your ISMS. Review SLAs and require security evidence from all partners. > **Tip 4: Prepare for Post-Quantum Cryptography** > C5:2025 includes post-quantum cryptography. Start evaluating algorithms resistant to quantum attacks, especially for long-term sensitive data. ### How the fuentis Suite Supports You The fuentis Suite offers full support for implementing and operating a C5-compliant ISMS: #### Risk Management Module - Structured ISO 27005 risk assessment - Central risk register with asset mapping - Support for C5-specific risks (tenant separation, supply chain) - Action tracking and effectiveness evaluation #### Asset Management - Detailed asset inventory with classification - Ownership and responsibility mapping - Fulfillment of C5 asset requirements - Lifecycle management from acquisition to disposal #### Compliance Management - Templates for ISO 27001 and ISO 27017 - Customizable C5 criteria catalogues - Integration of C5 controls into existing structures - SoA generation - Implementation tracking #### Audit & Review Modules - Internal audit support - Management review processes - Nonconformity tracking - Evidence collection for Type 2 attestations - Mapping evidence to controls #### Document Management (DMS) - Versioned storage of policies and processes - Centralized storage of attestation reports - Approval workflows - Full audit trail - Automated document distribution #### Online Assessment - Web-based self-assessment questionnaires - Automatic compliance status evaluation - Gap analysis for C5 readiness - Action plan generation ### Key Takeaways at a Glance ✅ **C5 defines minimum requirements for secure cloud services** across 17 areas based on ISO 27001 with cloud-specific additions. ✅ **Type 2 Attestations prove control effectiveness** over time and will be mandatory in healthcare from July 1, 2025; Type 1 Attestations serve only as a transitional solution. ✅ **C5 audits are based on ISAE 3000/SOC 2** – customers should demand unqualified, up-to-date reports and review subcontractor involvement. ✅ **C5:2025 introduces key updates** including container management, supply chain security, post-quantum cryptography, and alignment with EUCS, ISO 27001:2022, and NIS2. ✅ **Structured implementation with proper tools** like the fuentis Suite enables efficient management of risks, assets, compliance, and audits for practical C5 adoption. ## COBIT - IT-Governance und Management Framework Source: https://servicehub.fuentis.com/en/standards/cobit-it-governance-framework-de/ **COBIT (Control Objectives for Information and Related Technologies)** is an internationally recognized framework for IT governance and IT management developed by ISACA. In an increasingly digital business world, COBIT helps organizations plan, direct, and monitor their IT processes in a structured way—with the goal of establishing reliable, secure, and value-adding information systems. **Why is COBIT relevant?** IT governance is now critical to business success. COBIT provides the structure needed to justify IT investments, manage risks, and meet compliance requirements. --- ### The 5 Core Principles of COBIT #### 1) Meeting stakeholder needs IT should deliver targeted value for the enterprise while optimizing risk and resource use. Every IT decision should be aligned with business objectives. #### 2) A holistic enterprise view COBIT involves not just the IT department, but the entire organization—including strategy, culture, and organizational structures. #### 3) A single integrated framework COBIT consolidates other standards and methodologies (such as ISO 27001, ITIL, NIST) into a consistent, integrated framework, avoiding siloed approaches. #### 4) A holistic governance approach (Enablers) Successful IT governance is based on seven categories of enablers: - Processes - Organizational structures - Information - People, skills, and competencies - Culture, ethics, and behavior - Technologies - Services, infrastructure, and applications #### 5) Separation of governance and management COBIT clearly distinguishes: - **Governance:** Goal-setting, direction, and oversight by the governing body - **Management:** Planning, building, running, and monitoring activities --- ### The COBIT Process Model COBIT structures IT governance into **40 governance and management objectives** organized across five domains: #### EDM — Evaluate, Direct and Monitor (5 objectives) - Strategic direction and oversight of IT governance - Ensuring benefits and value contribution - Risk management at the governance level #### APO — Align, Plan and Organize (14 objectives) - Strategic planning and alignment - Architecture and innovation management - People and relationship management #### BAI — Build, Acquire and Implement (11 objectives) - Development and procurement of IT solutions - Program and project management - Change management and system integration #### DSS — Deliver, Service and Support (6 objectives) - Service management and operations - Continuity and availability management - Security and problem management #### MEA — Monitor, Evaluate and Assess (4 objectives) - Performance measurement and evaluation - Compliance monitoring - Internal controls and audit --- ### COBIT and Risk Management COBIT strengthens enterprise-wide risk management by enabling: - **Systematic risk identification** across all IT areas and business processes - **Risk assessment** by likelihood and business impact - **Control objectives and measures** to mitigate risks - **Integration of IT risks** into overall corporate management - **Continuous monitoring** and adjustment as requirements evolve **Pro tip:** Use COBIT’s risk management guidance alongside ISO 27001 for a comprehensive information security strategy. --- ### COBIT in Practice: Implementation Guidance #### Success factors for implementing COBIT - **Stakeholder engagement:** Involve all relevant stakeholders early for goal-setting and prioritization - **Framework literacy:** Solid training in COBIT principles and methods - **Tailored adaptation:** Scale to company size, industry, and maturity level - **Management commitment:** Strong executive sponsorship and clear accountability - **Resource planning:** Adequate capacity for implementation, monitoring, and continuous learning - **Iterative improvement:** Regular reviews to update and optimize processes #### Integration with other standards COBIT aligns particularly well with: - **ISO 27001:** Information security management - **ITIL:** Service management - **NIST Cybersecurity Framework:** Cybersecurity governance - **TOGAF:** Enterprise architecture --- ### COBIT 2019 vs. COBIT 5 **COBIT 2019** delivers significant enhancements over COBIT 5: - **Updated governance and management objectives** reflecting current IT trends - **More flexible performance and capability models** for better adaptability - **Design factors** (e.g., risk profile, enterprise strategy, IT role) enabling more tailored implementations - **Improved integration** with other frameworks and standards - **More detailed implementation guidance** and practical tools - **Focus Areas** for specific challenges such as cybersecurity or DevOps --- ### Relation to the fuentis Suite The **fuentis Suite** supports COBIT-aligned IT governance through: - **Structured documentation** of all COBIT processes and controls - **Risk management modules** for systematic risk identification and assessment - **Compliance tracking** to monitor the implementation of COBIT objectives - **Integrated reporting** for management and stakeholders - **Workflow management** for COBIT processes and approval procedures --- ### Key Takeaways at a Glance 1. **COBIT is a comprehensive framework** for IT governance and management that links IT activities to business goals and integrates risk management. 2. **The 5 COBIT principles** (stakeholder orientation, holistic view, integrated framework, enabler approach, governance/management separation) form the conceptual foundation. 3. **40 structured objectives** across 5 domains (EDM, APO, BAI, DSS, MEA) provide concrete guidance for IT governance activities. 4. **COBIT 2019 expands the framework** with design factors and improved integration with other standards like ISO 27001. 5. **Successful implementation** requires strong management commitment, tailored adaptation, and continuous process improvement. ## CSA STAR – Security, Trust, and Transparency in the Cloud Source: https://servicehub.fuentis.com/en/standards/csa-star-cloud-security/ As more and more sensitive information is stored in the cloud, **trust in the security measures of cloud providers** is more important than ever. The **CSA STAR program** (Security Trust Assurance and Risk) by the **Cloud Security Alliance (CSA)** is recognized globally as one of the most respected standards for cloud security certifications. The STAR program is built on the principles of **transparency**, **rigorous auditing**, and the **integration of established standards**. It helps cloud providers demonstrate their security posture credibly to customers, partners, and auditors—and gives cloud users a reliable tool for risk assessment. > **Practical Tip**: CSA STAR can serve as a centralized security and compliance system, helping organizations eliminate redundancy, reduce risk, and extend existing certifications to cloud-specific contexts. ### Core Concepts and Requirements #### The Three Pillars of CSA STAR CSA STAR builds on three fundamental components: **1. Cloud Controls Matrix (CCM)** - The de facto standard for cloud security controls - Comprehensively defines what a secure cloud service must deliver - Contains 197 control objectives across 17 domains - Mapped to major standards like ISO 27001, NIST, SOX **2. CAIQ – Consensus Assessments Initiative Questionnaire** - Comprehensive set of 295 questions - Systematic evaluation of CCM implementation at cloud providers - Standardized methodology for due diligence assessments - Enables uniform comparisons between providers **3. Code of Conduct for GDPR Compliance** - Practical guidance for General Data Protection Regulation in the cloud - Bridge between general GDPR requirements and cloud specifics - Support for documenting appropriate safeguards #### The Three Levels of CSA STAR Certification The CSA STAR program offers three certification levels, depending on your organization's risk exposure and desired level of transparency: ##### Level 1 – Self-Assessment **Target Group**: Organizations with relatively low risk profile **Process**: - Independent completion of the CAIQ questionnaire - Publication of results in the CSA STAR Registry - Focus on transparency through voluntary disclosure - No external validation required **Benefits**: - Cost-effective market entry opportunity - Initial visibility in global registry - Structured self-reflection of security measures ##### Level 2 – Third-Party Assessment **Target Group**: Companies operating in medium to high-risk environments **Process**: - External audit by accredited auditors - Often in conjunction with existing certifications (ISO 27001, SOC 2, GB/T22080) - Publication of verified results in CSA STAR Registry - Annual re-certification required **Benefits**: - Strong evidence of trust for customers and partners - Competitive advantages in procurement processes - Integration with existing compliance programs - Reduced audit redundancies ##### Level 3 – Continuous Auditing **Target Group**: Full-service cloud providers in highly sensitive or regulated areas **Process**: - Continuous monitoring and evidence collection - Real-time monitoring of security controls - Regular audit processes and updates - Highest transparency and security requirements **Benefits**: - Maximum trust and credibility - Suitable for highly regulated industries - Proactive risk minimization - Automated compliance evidence #### Why CSA STAR? A listing in the **CSA STAR Registry** signals: - **Trust & Competence** in cloud security - **Global Visibility** in a recognized provider registry - **Shortened Sales Cycles** through standardized security evidence - **Seamless Integration** with existing standards (ISO 27001, SOC 2, NIST) - **Competitive Advantages** in vendor selection processes ### Implementation Guidelines and Best Practices #### Preparing for CSA STAR **1. Scope Definition** - Clear delimitation: Which services and systems are covered? - Consideration of data flows and interfaces - Alignment with existing certification scopes - Documentation of system architecture and boundaries **2. Complete CAIQ & Implement CCM** - Systematic establishment of a comprehensive control framework - Mapping existing controls to the Cloud Controls Matrix - Gap analysis and identification of improvement needs - Implementation of missing security measures **3. Structure Evidence** - Central collection of all relevant documents - Assignment of policies and technical measures to CCM controls - Automation of evidence collection where possible - Regular updates of evidence base **4. Prepare for Audit (for Level 2 or 3)** - Selection of qualified and accredited auditors - Readiness checks and internal pre-assessments - Training of involved teams - Establishment of audit management processes **5. Publication in STAR Registry** - Strategic communication of certification - Utilization for marketing and sales - Regular updates and renewals - Integration into corporate communications > **Practical Tip**: Start with Level 1 to gain initial experience and establish internal processes before progressing to higher levels. #### Integration with Existing Standards **ISO 27001 Integration:** - Many CCM controls overlap with ISO 27001 requirements - STAR can function as cloud-specific extension of ISMS - Synergies in audit preparation and execution - Shared use of documentation and evidence **SOC 2 Harmonization:** - Parallel execution of SOC 2 and STAR Level 2 possible - Overlapping controls reduce audit effort - Unified governance structure for both standards **NIST Framework Alignment:** - CCM maps to NIST Cybersecurity Framework - Utilization of existing NIST implementations - Enhancement with cloud-specific aspects #### Particularly Suitable For: - **Cloud Service Providers (CSP)** of all sizes - **SaaS vendors** with high security requirements - **Managed Service Providers** with cloud focus - **Organizations with existing ISO 27001 or SOC 2 certifications** - **Organizations in regulated industries** (finance, healthcare, public sector) ### Support Through the fuentis Suite The **fuentis Suite** can specifically support CSA STAR implementation: **Compliance Management Module:** - Pre-built CCM control catalogs and CAIQ templates - Automated gap analyses between existing standards and CSA STAR - Tracking implementation status for all 197 CCM controls - Integration with ISO 27001 and SOC 2 control frameworks **Asset and Service Management:** - Central capture of all cloud services in scope - Assignment of controls to specific assets and services - Automatic updates when IT landscape changes - Visualization of dependencies and data flows **Risk Management:** - Cloud-specific risk analyses and assessments - Integration of CCM controls into risk management - Automated reporting for management and auditors - Continuous monitoring of risk indicators **Audit and Assessment Modules:** - Structured preparation for STAR audits - Central collection and management of all evidence - Automated generation of audit reports - Tracking of audit findings and corrective actions **Document Management:** - Central repository for all STAR-relevant documents - Version control and approval workflows - Automatic linking to corresponding CCM controls - CAIQ questionnaire as interactive tool ### Position in the Compliance Landscape #### Relationship to Other Standards **Complement to ISO 27001:** - CSA STAR extends general ISMS requirements with cloud specifics - Uses existing ISO 27001 documentation as foundation - Enables seamless integration into established management systems **Distinction from SOC 2:** - SOC 2 focuses on internal controls, STAR on cloud ecosystem - STAR offers more transparency through public registry - Both standards can be implemented in parallel or integrated **Synergy with GDPR:** - Code of Conduct supports GDPR compliance in the cloud - Structured approach to data processing agreements - Evidence of appropriate technical and organizational measures #### Regulatory Recognition - **European Union**: Increasing recognition in public procurement - **USA**: Established with federal agencies and Fortune 500 companies - **Asia-Pacific**: Strong adoption in Singapore, Australia, Japan - **Financial Sector**: Recognition by various financial supervisory authorities ### Further Links and Sources #### Official Resources - **CSA STAR Registry**: Public database of all certified providers - **Cloud Security Alliance**: Official website with current standards - **Cloud Controls Matrix**: Complete control catalog for download - **CAIQ Questionnaire**: Current questionnaire for assessments #### Implementation Guides - **CSA STAR Implementation Guide**: Detailed implementation instructions - **Best Practice Collection**: Success stories from successful implementations - **Webinar Series**: Regular training offerings from CSA - **Community Forum**: Exchange with other STAR participants #### Glossary **Cloud Controls Matrix (CCM)**: Comprehensive control catalog with 197 security controls across 17 domains that serves as reference for cloud security. **CAIQ**: Consensus Assessments Initiative Questionnaire – standardized questionnaire with 295 questions for evaluating cloud security measures. **CSA STAR Registry**: Publicly accessible database of all STAR-certified cloud providers with their security evidence. **Continuous Auditing**: Highest STAR certification level with continuous monitoring and real-time evidence collection. **Code of Conduct**: Practical guidelines for GDPR-compliant cloud services and data processing agreements. **Third-Party Assessment**: External audit by accredited auditors as part of STAR Level 2. ### Key Takeaways at a Glance 1. **Leading Cloud Security Certification**: CSA STAR is globally recognized as one of the most respected standards for cloud security, offering three certification levels from self-assessment to continuous monitoring. 2. **Comprehensive Control Framework**: The Cloud Controls Matrix (CCM) with 197 controls and the CAIQ questionnaire create a structured, standardized approach for cloud security assessments. 3. **Seamless Integration**: STAR harmonizes optimally with existing standards like ISO 27001 and SOC 2, reduces audit redundancies, and enables efficient multi-standard approaches. 4. **Competitive Advantages Through Transparency**: Publication in the CSA STAR Registry builds trust, shortens sales cycles, and provides differentiation in the competitive cloud market. 5. **Tool-Supported Efficiency**: Modern platforms like the fuentis Suite automate essential parts of STAR implementation and maintenance, from gap analysis to continuous compliance monitoring. ## DORA - Digital Operational Resilience Act Source: https://servicehub.fuentis.com/en/standards/dora-digital-operational-resilience-act/ **DORA (Digital Operational Resilience Act)** is an EU regulation (Regulation (EU) 2022/2554) that entered into force on **17 January 2025** and applies directly in all EU Member States. Its goal is to strengthen the digital operational resilience of financial entities and ensure they can withstand, respond to, and recover from ICT disruptions. **Why does DORA matter?** In an increasingly digital financial world, cyberattacks and system outages pose existential threats. DORA harmonizes requirements for digital operational resilience across the EU and creates uniform standards for ICT risk management in the financial sector. **Special relevance for Germany:** As of 17 January 2025, BaFin-regulated institutions are obliged to implement DORA. The regulation gradually replaces existing German IT circulars (BAIT/VAIT/ZAIT/KAIT) and, via the Finanzmarktdigitalisierungsgesetz (FinmadiG), will be extended to additional institutions. --- ### The 5 Pillars of the DORA Regulation DORA structures digital operational resilience into five core areas, all tied to robust governance. #### 1) ICT Risk Management **Comprehensive, proactive risk management** for all ICT systems and processes. ##### Governance and organization - Management is responsible for defining and overseeing ICT risk management frameworks. - Clear roles and responsibilities must be defined and documented. - Regular reporting to the management body is required. ##### Protection and prevention - Implement policies and procedures to protect critical ICT systems. - Regularly update security measures. - Continuous risk analysis and staff awareness. - Asset management and classification of critical systems. ##### Detection, response, and recovery - Early detection of ICT incidents through monitoring systems. - Defined response plans and escalation procedures. - Backup and recovery processes for business continuity. - Regular testing of recovery procedures. ##### Simplified requirements for small financial entities DORA permits simplified ICT risk management under Article 16 and related technical standards (CDR 2024/1774) for smaller institutions. **Pro tip:** Many German institutions already have BAIT/VAIT-aligned risk management. Perform a gap analysis to identify differences between your current framework and DORA requirements. --- #### 2) Reporting and Classification of ICT Incidents **Standardized incident management** for all financial entities. ##### Incident management process - Implement processes to log, monitor, and classify ICT incidents. - Structured documentation of all incidents and threats. - Clear categorization by severity and impact. ##### Reporting obligations - **Initial notification:** Within 4 hours after identifying a major incident. - **Interim reports:** Regular updates during handling. - **Final report:** Full analysis with lessons learned. - **Customer notification:** Inform affected customers in case of major incidents. ##### Report contents - Time and duration of the incident. - Affected systems and services. - Impact on business operations. - Immediate actions taken. - Estimated recovery time. **Pro tip:** Ensure incident data is captured in a structured way and that your reporting processes align with supervisory deadlines. Train staff for rapid escalation. --- #### 3) Digital Operational Resilience Testing **Regular testing** to verify ICT resilience. ##### Comprehensive testing program - **Annual testing** of all critical ICT systems. - Vulnerability assessments and penetration tests. - Performance and capacity tests. - Scenario-based exercises and disaster-recovery tests. ##### Threat-Led Penetration Testing (TLPT) - **At least every three years** for larger institutions. - Simulates real attacker tactics and techniques. - Conducted by qualified external providers. - Comprehensive documentation and follow-up actions. ##### Documentation and follow-up - Detailed documentation of all test results. - Derive concrete improvement measures. - Integrate insights into risk management. - Regularly review implementation progress. **Pro tip:** Plan resilience tests on a multi-year basis and align them with internal and external auditors. Systematically integrate lessons learned into your risk management. --- #### 4) ICT Third-Party Risk Management **Strict requirements** for managing external ICT service providers. ##### Strategy and governance - Develop a strategy and policy for ICT third parties. - Risk assessment and classification of providers. - Define exit strategies and contingency plans. - Regular review of the third-party landscape. ##### Due diligence and contracting - **Pre-contract assessment** before onboarding. - Evaluate security certifications and reliability. - **Minimum contractual clauses** per Article 30, including: - Access security and data classification - Audit rights and compliance oversight - SLAs and performance indicators - Exit arrangements and data return - Sub-contractor management ##### Register of information - Maintain an up-to-date register of all ICT third parties. - Document services and contract terms. - Classify critical functions. - Update and validate regularly. ##### EU-wide oversight of critical third parties - A Lead Overseer may conduct investigations. - Sanctions possible in case of violations. - Harmonized supervision of systemic providers. **Pro tip:** Compare existing outsourcing contracts to DORA’s minimum requirements. Maintain a central third-party register and define clear exit strategies. --- #### 5) Information Sharing and Cooperation **Promoting secure exchange** of cyber threat information. ##### Threat intelligence sharing - Exchange cyber-threat information between financial institutions. - Build a shared situational picture. - Coordination by national and European bodies. - Observe data protection rules and internal processes. --- ### Applicability and Enforcement in Germany #### Timeline - **Effective:** 17 January 2025 – directly applicable. - **Withdrawal of national circulars:** BaFin withdraws VAIT/ZAIT/KAIT on 16 January 2025. - **BAIT transition:** Remains in effect until end of 2026, gradually replaced by DORA. - **Extension:** FinmadiG extends scope to additional institutions from 2027. #### Affected entities - Banks and credit institutions - Insurance companies - Investment firms and asset managers - Payment institutions and e-money institutions - From 2027: also non-CRR institutions such as development banks #### Sanctions and fines - **Financial entities:** Up to 2% of worldwide annual turnover. - **Critical third parties:** Up to €5 million or 1% of annual turnover. - Enforcement by European supervisory authorities. --- ### Implementation Aids and Best Practices #### Organizational preparation ##### 1) Perform a gap analysis - Compare existing IT rules (BAIT/VAIT/KAIT) with DORA requirements. - Identify necessary adjustments. - Develop a structured implementation plan. - Prioritize critical measures. ##### 2) Ensure management commitment - Make the management body aware of DORA requirements. - Clarify management responsibilities. - Provide sufficient resources. - Establish regular reporting. ##### 3) Define responsibilities - Appoint a DORA program lead. - Define roles for risk, incident, and compliance management. - Clarify third-party responsibilities. - Set up coordination mechanisms. #### Implement ICT risk management ##### Establish the framework - Leverage existing ISO 27001 structures. - Adapt risk methodology to DORA. - Integrate protection, detection, response, and recovery. - Consider simplified provisions for smaller entities. ##### Optimize documentation - Maintain current policies and processes. - Create and maintain an asset register. - Document risk analyses and measures. - Use BaFin documentation expectations as guidance. ##### Continuous improvement - Establish a PDCA cycle. - Use lessons learned from incidents and tests. - Regular reviews and process adjustments. - Integrate feedback from audits and examinations. #### Optimize incident management ##### Define processes - Set clear reporting paths and escalation levels. - Define responsibilities and authorities. - Ensure ability to report to supervisors and customers. - Integrate with existing ISMS processes. ##### Technical monitoring - Implement SIEM systems. - Deploy monitoring tools. - Automate incident detection. - Integrate diverse data sources. ##### Training and exercises - Regular staff training. - Incident-response exercises. - Training on reporting obligations and procedures. - Awareness of emerging threats. #### Conduct resilience testing ##### Test planning - Build a multi-year test plan. - Align scope with BaFin. - Integrate into the audit calendar. - Coordinate with business units. ##### Test execution - Use realistic scenarios. - Employ automated tools. - Document all results. - Track remediation actions. ##### Integration with risk management - Use test results to update risks. - Adjust controls based on findings. - Regularly review test effectiveness. - Benchmark against industry standards. #### Strengthen third-party management ##### Intensify due diligence - Conduct security and compliance checks. - Evaluate certifications and standards. - Review financial stability. - Assess contingency and business continuity plans. ##### Optimize contracting - Add DORA minimum clauses. - Define clear service-level agreements. - Agree audit rights. - Set exit strategies and handover procedures. ##### Register and monitoring - Build a central third-party register. - Automate monitoring of contract changes. - Perform regular risk assessments. - Conduct supplier audits. --- ### Relation to Other Standards and Frameworks #### Integration with ISO 27001 - DORA complements existing ISMS structures. - Risk management systems can be extended. - Incident management processes are compatible. - Continuous improvement approaches align. #### Distinction from BAIT/VAIT - DORA gradually replaces national circulars. - Higher demands on third-party management. - More detailed requirements for resilience testing. - EU-wide harmonization of standards. #### Interplay with NIS2 - Overlaps in cybersecurity requirements. - Complementary approaches for critical infrastructures. - Coordinated reporting duties and incident response. - Harmonized EU cybersecurity strategy. --- ### Support with the fuentis Suite The **fuentis Suite** can comprehensively support DORA compliance: #### Risk Management modules - **Asset management:** Record and classify all ICT assets. - **Risk register:** Document threats, vulnerabilities, and controls. - **Action planning:** Track risk-mitigation measures. - **Reporting:** Automated reports for management and supervisors. #### Incident Management system - **Incident capture:** Structured documentation of ICT incidents. - **Classification:** Automated categorization per DORA criteria. - **Regulatory reporting:** Integrated interfaces for BaFin reporting. - **Workflow management:** Automated escalation and processing. #### Third-Party Management (Road map) - **Supplier register:** Central management of all ICT third parties. - **Due diligence:** Structured evaluation procedures. - **Contract management:** Track DORA minimum clauses. - **Risk scoring:** Ongoing monitoring of supplier risks. #### Compliance Management (Road map) - **DORA templates:** Prebuilt documents and checklists. - **Gap analysis:** Automated assessment of implementation status. - **Audit trails:** Full traceability of all activities. - **Regulatory mapping:** Link to other compliance requirements. #### Testing and Audit modules (Road map) - **Test planning:** Manage resilience tests and TLPT. - **Result tracking:** Structured capture of test outcomes. - **Remediation tracking:** Follow-up on improvements. - **Management review:** Automated reporting for the management body. --- ### Key Takeaways at a Glance 1. **DORA has applied directly since 17 January 2025** and is gradually replacing German IT circulars. BaFin-regulated institutions must implement it now. 2. **The 5 DORA pillars** (ICT risk management, incident reporting, resilience testing, third-party management, information sharing) form a comprehensive framework for digital operational resilience. 3. **Management responsibility is central**—the management body is accountable for ICT risks and must establish appropriate governance. 4. **Third-party risks receive heightened attention** with strict due-diligence requirements, minimum contract clauses, and EU-level oversight of critical providers. 5. **Existing BAIT/VAIT frameworks can be extended**—a gap analysis helps identify adjustments and leverage prior compliance investments. ## Grundschutz++ - Digital Transformation of IT-Grundschutz Source: https://servicehub.fuentis.com/en/standards/grundschutz-plusplus/ **Grundschutz++** is the comprehensive modernization of the established IT-Grundschutz of Germany’s Federal Office for Information Security (BSI). Starting January 1, 2026, the current PDF- and Excel-based compendium will be replaced by a largely digitized, process-oriented, and machine-readable version. **Why is Grundschutz++ relevant?** Digital transformation brings new technologies such as cloud services, artificial intelligence (AI), and the Internet of Things (IoT), creating new security requirements and threat scenarios. At the same time, demand is rising for automated compliance processes and better integration into existing ISMS tools. Grundschutz++ addresses these challenges with a fundamentally modernized approach that preserves proven Grundschutz principles while making their application significantly simpler and more flexible. ### The Revolution: From PDF to OSCAL/JSON #### Machine-readable format as a paradigm shift The biggest change in Grundschutz++ is the switch from static PDF and Excel documents to a **machine-readable format** based on the **Open Security Controls Assessment Language (OSCAL)**. This transformation enables: - **Automated compliance checks** via direct tool integration - **Consistent data quality** through a single source of truth - **Dynamic updates** without manual transfer errors - **API-based integration** into existing ISMS landscapes - **Real-time synchronization** between BSI specifications and organizational tools **Pro tip:** BSI will continue to provide Excel exports generated directly from OSCAL data. However, organizations should move early to OSCAL/JSON-compatible tools to realize the full benefits of digitization. #### Technical foundations of OSCAL **OSCAL (Open Security Controls Assessment Language)** is a NIST-developed standard for the structured modeling of: - Security requirements and controls - Compliance information and assessment results - Risk evaluations and remediation plans - System security plans and authorization documents Its JSON structure allows tool vendors and users to access BSI source data directly and integrate it seamlessly into their security architectures. ### Conceptual innovations and structural change #### Modular, process-oriented architecture **From rigid building blocks to flexible practices:** Grundschutz++ replaces the former “building blocks” with **practices**—reusable processes or security measures that can be flexibly combined and adapted to specific organizational structures. ##### New requirement structure **Standardized sentence templates** ensure clarity and consistency: ``` {Practice} [for {Target Object}] {MODAL VERB} {Action Word} ``` **Example:** - **Practice:** “Backup procedure” - **Target object:** “critical business data” - **Modal verb:** “MUST” - **Result:** “restorable copies” - **Action word:** “create” → *“Backup procedure for critical business data MUST create restorable copies.”* #### Hierarchical implementation prioritization Grundschutz++ introduces a **six-level prioritization model** (Levels 0–5): ##### Level 0: Mandatory foundations - **Mandatory requirements** for ISO 27001 compatibility - **Fundamental governance practices** - **Legal minimum requirements** ##### Level 1: Quick wins (~1 day effort) - **Immediately actionable measures** - **Low cost, high security impact** - **Awareness and sensitization** ##### Level 2: Short projects (~1 week effort) - **Policies and procedure documentation** - **Basic technical safeguards** - **Initial monitoring implementations** ##### Level 3: Mid-term projects (~1 month effort) - **Comprehensive technical implementations** - **Process optimization and automation** - **Advanced monitoring and detection systems** ##### Level 4: Long-term transformations (~1 quarter effort) - **Structural organizational changes** - **Complex technical infrastructure projects** - **Comprehensive integration and harmonization** ##### Level 5: Elevated protection needs - **Additional requirements** for critical infrastructures - **Specialized security measures** - **Enhanced monitoring and response capabilities** **Pro tip:** Always begin with Level 0 and work through the levels systematically. This prioritization enables you to quickly achieve a solid security baseline even with limited resources. #### Key performance indicators (KPIs) for measurable security **Quantifying security gains:** Each requirement in Grundschutz++ receives **three indicators** aligned with the classic security objectives: - **C (Confidentiality):** protection against unauthorized disclosure - **I (Integrity):** protection against unauthorized modification - **A (Availability):** protection against outages or impairment ##### How the indicators work - **Point values** show how strongly a measure reduces the respective risk - **Summation** of all implemented measures yields the overall score - **Thresholds** define the desired security level - **Objective measurability** of ISMS fulfillment ##### Practical benefits - **Resource optimization:** focus on measures with the best cost–benefit ratio - **Continuous improvement:** systematic identification of security gaps - **Stakeholder communication:** objective presentation of the security level - **Benchmark comparisons:** positioning against industry standards **Pro tip:** Use the indicators to drive a data-driven security strategy. Define organization-specific thresholds and track their development over time. ### Integration and harmonization #### Stronger ISO 27001 compatibility Grundschutz++ is designed to **seamlessly harmonize** with ISO 27001: ##### Structural alignment - **Control mapping:** direct mapping of Grundschutz++ practices to ISO 27001 controls - **Annex A compatibility:** full coverage of ISO 27001 Annex A requirements - **ISMS process integration:** harmonized governance cycles - **Audit synergy:** joint assessment cycles for both standards ##### Practical advantages - **Reduced effort** for dual certifications - **Consistent documentation** for both standards - **Unified risk assessment methodology** - **Shared KPI dashboards** #### Modular extensibility The new architecture enables **flexible integration** of additional compliance catalogs: ##### Available and planned modules - **KRITIS extensions** for critical infrastructures - **NIS2 compliance** (EU) - **C5 attestation** for cloud security - **Cloud security modules** - **AI security** for AI/ML systems - **IoT security** for connected devices **Pro tip:** Plan your ISMS architecture modularly so you can integrate future compliance requirements without changing the core structure. ### Proven methodology remains **Continuity despite revolution:** Despite all the technical and structural innovations, the **proven IT-Grundschutz methodology** remains fundamentally unchanged: #### The six phases of IT-Grundschutz 1. **Define scope** - Define business processes to be protected - Delimit IT systems and applications - Consider cloud and hybrid infrastructures 2. **Conduct structural analysis** - Record all target objects and their dependencies - Map data flows and system interactions - Document the IT architecture 3. **Determine protection requirements** - Assess the criticality of information and systems - Classify by confidentiality, integrity, and availability - Consider regulatory requirements 4. **Model with Grundschutz++** - Select and configure relevant practices - Tailor to organizational specifics - Integrate additional compliance modules 5. **Grundschutz check** - Systematically verify implementation - Evaluate using KPIs - Identify implementation gaps 6. **Risk analysis** - Assess residual risks - Define additional measures - Document risk acceptance decisions **Pro tip:** Use the continuity of the methodology as the basis for your transformation. Existing processes can largely remain and be supplemented with new digital tools. ### Preparation and implementation strategies #### Strategic preparation ##### Organizational readiness **1. Establish project team and governance** - **Strengthen the ISO/ISB role:** clear assignment of information security responsibilities - **Cross-functional teams:** integrate IT, compliance, risk management, and business - **Change management:** prepare the organization for the paradigm shift - **Budget planning:** allocate resources for tools, training, and external support **2. Build technical prerequisites** - **OSCAL/JSON competence:** train teams on the new data formats - **Tool evaluation:** assess OSCAL-compatible ISMS solutions - **API integration:** prepare IT infrastructure for automated data flows - **Backup strategies:** ensure continuity during migration **3. Rethink scope and architecture** - **Cloud-first approach:** adapt structural analysis to modern IT architectures - **Process orientation:** shift from object- to process-centric views - **Modular planning:** prepare for future compliance extensions #### Implementation approach ##### Phased migration **Phase 1: Foundation (Q4 2025)** - Select and implement tools - Train and certify the team - Analyze and prepare existing documentation - Identify pilot areas for initial testing **Phase 2: Core migration (Q1–Q2 2026)** - Fully implement Level 0 requirements - Systematically deliver quick wins (Level 1) - Establish and measure KPI baselines - Perform initial compliance checks **Phase 3: Optimization (Q3–Q4 2026)** - Implement Levels 2–4 by priority and resources - Establish continuous improvement processes - Integrate extended modules (KRITIS, NIS2) - Prepare for audits and certification **Phase 4: Continuous improvement (from 2027)** - Regular KPI reviews and optimizations - Integrate new BSI modules and updates - Benchmarking and best-practice sharing - Strategic development of the ISMS #### Risk-based implementation ##### Process-oriented risk analysis **Methodological shift:** - **From object- to process-oriented:** focus on end-to-end business processes - **Dynamic risk assessment:** continuous adaptation to changing threats - **Integrated compliance:** harmonize multiple regulatory requirements - **Quantitative metrics:** use KPIs for objective risk quantification ##### KPI-driven steering **Data-driven decisions:** - **Establish baselines:** define organization-specific security goals - **Continuous monitoring:** real-time tracking of security indicators - **Trend analysis:** identify patterns of improvement or deterioration - **Optimize ROI:** prioritize measures with the best security ROI **Pro tip:** Use KPIs not only for compliance but as a strategic instrument for continually optimizing your security architecture. Define organization-specific thresholds and establish regular review cycles. ### Support with the fuentis Suite The **fuentis Suite** is ready for Grundschutz++ and provides comprehensive support: #### OSCAL/JSON integration - **Native OSCAL support:** direct processing of BSI JSON data structures - **Automatic updates:** synchronization with BSI releases without manual intervention - **API-based integration:** seamless connection to existing IT service management tools - **Version control:** full traceability of changes and updates #### Process-oriented risk management - **End-to-end process mapping** - **KPI dashboard:** real-time monitoring of C/I/A indicators - **Dynamic risk evaluation** - **Threshold management:** configurable alerts and escalations #### Asset and target object management - **Central CMDB** - **Dependency mapping:** visualize system dependencies and data flows - **Cloud integration:** support for hybrid and multi-cloud environments - **IoT device management** #### Modular compliance management - **Multi-standard support:** Grundschutz++, ISO 27001, NIS2, KRITIS - **SoA generator:** automated Statement of Applicability - **Gap analysis** and maturity scoring - **Audit trail:** end-to-end change tracking #### Automated assessment workflows - **Grundschutz check automation** - **KPI calculation** and scoring - **Report generation:** standardized and custom compliance reports - **Stakeholder dashboards:** role-based views #### Integration and interoperability - **SIEM integration** - **Ticketing connectors** for service workflows - **Business intelligence export** - **Mobile-first design** ### Bridge to other standards and frameworks #### ISO 27001 harmonization - **Dual compliance** with minimal overhead - **Control mapping** between Grundschutz++ practices and ISO controls - **Shared governance:** integrated management reviews and audit cycles - **Aligned risk treatment** #### NIST framework integration - **CSF compatibility** - **OSCAL synergy** through shared data structures - **Maturity model alignment** #### EU compliance standards - **NIS2 readiness** - **GDPR integration** - **Digital operational resilience:** alignment with DORA for the financial sector ### Key takeaways at a glance 1. **Digital revolution from 2026:** Grundschutz++ replaces the PDF-based compendium with a machine-readable OSCAL/JSON format enabling automated compliance and seamless tool integration. 2. **Process-oriented modernization:** New modular structure with practices instead of building blocks, standardized sentence templates, and a six-level prioritization increases flexibility and efficiency. 3. **Measurable security via KPIs:** Each requirement is linked to C/I/A indicators enabling objective measurement and data-driven optimization. 4. **Seamless ISO 27001 integration:** Designed for maximum harmonization, enabling dual compliance with minimal additional effort and joint audit cycles. 5. **Early preparation is essential:** Organizations should begin strategic preparations in 2025, as migration is not automatic and requires training and tool adjustments. ## ISO 27001 - Comprehensive ISMS Guide Source: https://servicehub.fuentis.com/en/standards/iso-27001-leitfaden/ ISO 27001 is the world's leading standard for Information Security Management Systems (ISMS). This comprehensive knowledge page combines all essential aspects - from fundamentals through implementation to successful audit preparation. ### What is ISO 27001 and Why is it Relevant? ISO 27001:2022 is an internationally recognized standard that helps organizations of all sizes and industries systematically identify, assess, and treat information security risks. A functioning ISMS according to ISO 27001 not only protects sensitive data but also strengthens trust with customers, partners, and regulatory authorities. #### Why Implement ISO 27001? **Business Benefits:** - Demonstrable security and professionalism to stakeholders - Competitive advantages through certification - Reduction of audit fatigue with business partners - Reputation protection during security incidents - Foundation for additional compliance requirements (GDPR, NIS2, SOC 2) **Security Benefits:** - Systematic protection of customer, employee, and company data - Proactive risk identification and treatment - Establishment of a security culture within the organization - Better preparation for cyber threats ### Important Updates: ISO 27001:2022 + Amendment 1 The current version was expanded in February 2024 with **Amendment 1**, which requires organizations to assess **climate change risks** on their information security and integrate them into the ISMS if relevant. **Affected Areas:** - Organizational context analysis (Chapter 4.1) - Risk assessment (Chapter 6.1.2) - Stakeholder engagement (Chapter 4.2) This represents an important step toward sustainable and responsible information security. ### Core Concepts and Requirements #### The PDCA Model (Plan-Do-Check-Act) ISO 27001 is based on the continuous improvement cycle: - **Plan**: Risk assessment and ISMS planning - **Do**: Implementation of controls and processes - **Check**: Monitoring, internal audits, and management review - **Act**: Corrective actions and continuous improvement #### Key Requirements Overview **Chapter 4: Context of the Organization** - Understanding internal and external factors - Identification of relevant stakeholders - Definition of ISMS scope **Chapter 5: Leadership** - Management commitment and responsibilities - Information security policy - Organizational roles and authorities **Chapter 6: Planning** - Risk and opportunity management - Information security risk assessment and treatment - Security objectives and implementation planning **Chapter 7: Support** - Resource provision and competence management - Awareness building and communication - Documented information **Chapter 8: Operation** - Operational planning and control - Conducting risk assessment and treatment **Chapter 9: Performance Evaluation** - Monitoring, measurement, and analysis - Internal audits - Management review **Chapter 10: Improvement** - Treatment of nonconformities - Corrective actions and continuous improvement #### Annex A: The 93 Security Controls Annex A contains 93 control objectives in four categories: - **Organizational Controls** (37 controls) - **People Controls** (8 controls) - **Physical and Environmental Security** (14 controls) - **Technological Controls** (34 controls) **Important**: Not every control must be implemented, but each must be evaluated and justified in the Statement of Applicability (SoA). ### Step-by-Step Implementation #### Phase 1: Preparation and Planning **1. Secure Management Commitment** - Active support from executive leadership - Provision of adequate resources - Appointment of an ISMS responsible person **2. Define Scope** - Determination of business areas, systems, and data to be covered - Consideration of legal and regulatory requirements - Documentation of scope decisions **3. Build Project Team** - Interdisciplinary team from IT, compliance, risk management - Clear roles and responsibilities - Project plan with milestones #### Phase 2: Establish Risk Management **1. Develop Risk Assessment Methodology** - Definition of risk categories and assessment criteria - Setting acceptance thresholds - Documentation of methodology **2. Create Asset Inventory** - Identification of all information-processing assets - Assessment of criticality - Assignment of responsibilities **3. Conduct Risk Assessment** - Systematic identification of threats and vulnerabilities - Assessment of likelihood and impact - Documentation in risk register #### Phase 3: Implement Controls **1. Select Relevant Controls** - Risk-based selection from Annex A - Consideration of existing measures - Prioritization based on risk assessment **2. Create Implementation Plan** - Timeline for control implementation - Resource allocation and responsibilities - Identify quick wins **3. Develop Statement of Applicability (SoA)** - Justification for each control from Annex A - Documentation of implementation decisions - Link with risk assessment #### Phase 4: Documentation and Evidence **Create Mandatory Documents:** - ISMS policy and scope - Risk assessment methodology - Risk Treatment Plan (RTP) - Statement of Applicability (SoA) - Internal audit procedures - Management review procedures **Collect Evidence:** - Training materials and attendance records - Incident response documentation - Monitoring and measurement results - Corrective action evidence ### Audit Preparation and Certification #### Internal Audits as Preparation **Objectives:** - Review ISMS effectiveness - Identify improvement opportunities - Prepare for external audits **Approach:** - Develop audit program and plan - Deploy qualified internal auditors - Systematic review of all ISMS areas - Document nonconformities - Derive and implement corrective actions #### The External Certification Process **Stage 1 Audit (Documentation Review)** - Review of ISMS documentation - On-site readiness assessment - Identification of potential weaknesses - Preparation for Stage 2 **Stage 2 Audit (Implementation Review)** - Comprehensive assessment of practical implementation - Interviews with key personnel - Review of processes and controls - Effectiveness evaluation **Handling Nonconformities:** - **Major Nonconformity**: Critical deficiencies preventing certification - **Minor Nonconformity**: Smaller deviations, certificate issued with conditions - **Opportunity for Improvement (OFI)**: Recommendations for optimization #### Post-Certification **Surveillance Audits (Years 2 & 3):** - Annual review of ISMS maintenance - Sample-based controls - Review of corrective actions **Re-certification (after 3 years):** - Complete re-assessment of ISMS - Consideration of changes and improvements - Update to new standard versions ### Best Practices for Successful Implementation #### Organizational Success Factors **Top Management Engagement** - Visible support from executive leadership - Regular communication of security priorities - Provision of adequate resources **Change Management** - Early involvement of all stakeholders - Communication of benefits and necessity - Employee training and awareness **Pragmatic Approach** - Focus on essential risks - Build on existing structures - Iterative improvement rather than perfection from start #### Avoiding Common Pitfalls **Scope Too Broad** - Risk: Complexity and costs increase disproportionately - Solution: Choose realistic scope, expand later **Incomplete Risk Assessment** - Risk: Important threats are overlooked - Solution: Systematic approach with proven methods **Insufficient Documentation** - Risk: Audit difficulties and missing evidence - Solution: Continuous documentation during implementation **Neglecting Employees** - Risk: Lack of acceptance and poor effectiveness - Solution: Intensive awareness programs and training ### Support Through the fuentis Suite The fuentis Suite provides comprehensive support for ISO 27001 implementation: #### Risk Management Module - Structured risk assessment with customizable methods - Automated risk register management - Linking with assets and controls - Reminders for regular reviews #### Asset Management - Central asset inventory - Responsibilities and classifications - Linking with risks and controls #### Compliance Management - Pre-configured ISO 27001 templates - Statement of Applicability (SoA) generator - Gap analyses and maturity assessments - Automated reporting #### Audit and Review Modules - Internal audit planning and execution - Nonconformity management - Management review support - Corrective action tracking #### Document Management (DMS) - Central management of all ISMS documents - Version control and approval workflows - Automatic review reminders - Audit trail for all changes #### Online Assessment - Questionnaire-based data collection - Automated evaluation - Visualization of compliance status - Integration into risk assessment ### Integration with Other Standards ISO 27001 harmonizes well with other compliance requirements: **GDPR** - Overlaps in data protection controls - Common risk assessment approaches - Integrated incident response processes **SOC 2** - Similar control objectives in security area - Combined audit strategies possible - Shared evidence collection **NIST Framework** - Complementary approaches for cybersecurity - Mapping between frameworks - Integrated risk management strategies **Industry Standards (TISAX, etc.)** - ISO 27001 as basis for specific requirements - Reduction of audit effort - Consistent security architecture ### Continuous Improvement #### Monitoring and Measurement **Key Performance Indicators (KPIs)** - Number and severity of security incidents - Time to remediate vulnerabilities - Employee awareness levels - Control compliance rates **Regular Assessments** - Quarterly risk reviews - Annual ISMS effectiveness assessments - Continuous threat landscape analysis - Stakeholder feedback cycles #### Adapting to Changes **Technological Developments** - Cloud migration and new services - Emerging technologies (AI, IoT, etc.) - New threat scenarios - Regulatory changes **Organizational Changes** - Business expansions or acquisitions - New business models - Structural reorganizations - Stakeholder requirements ### Key Takeaways at a Glance **The 5 Most Important Success Factors for ISO 27001:** 1. **Management Commitment**: Without active support from executive leadership, successful ISMS implementation is impossible 2. **Risk-Based Approach**: Focus on essential information security risks rather than a one-size-fits-all approach 3. **Pragmatic Scope Definition**: Realistic scope that can be expanded later 4. **Continuous Improvement**: ISO 27001 is not a one-time project but an ongoing process 5. **Employee Involvement**: Successful information security is teamwork and requires trained, aware employees **Why ISO 27001 is More Than Just Compliance:** ISO 27001 is a strategic tool for strengthening organizational resilience, optimizing business processes, and building stakeholder trust. With the right approach and modern tools like the fuentis Suite, certification becomes a sustainable competitive advantage. ## ISO/IEC 42001 – Standards for AI Management Systems Source: https://servicehub.fuentis.com/en/standards/iso-42001-ki-managementsysteme/ Artificial intelligence (AI) is permeating more and more products and services, creating new ethical, security, and regulatory challenges. To give organizations a structured framework, **ISO/IEC 42001**—the world’s first standard for Artificial Intelligence Management Systems (AIMS)—was published at the end of 2023. The standard defines requirements for establishing, implementing, maintaining, and continually improving a management system that supports the responsible development, provision, and use of AI systems. ISO/IEC 42001 is intended for organizations of any size and sector that develop, provide, or use AI products or services. > **Pro tip:** An AIMS aligned with ISO 42001 builds trust in AI applications, promotes transparency and traceability, and helps organizations manage risks and opportunities systematically. --- ### Core Concepts and Requirements #### Structure of the Standard ISO 42001 follows the familiar High-Level Structure used by ISO 27001 and ISO 9001. The main clauses form a continuous improvement cycle: **Clause 4 – Context of the organization** - Analysis of internal and external factors - Definition of the AIMS scope - Understanding stakeholder expectations **Clause 5 – Leadership** - Top management commitment - Establishment of an AI policy - Definition of roles and responsibilities **Clause 6 – Planning** - Identification of risks and opportunities related to AI - Setting objectives and planning changes - **Notable feature:** Combination of AI risk assessments and AI system impact assessments **Clause 7 – Support** - Provision of resources and competencies - Awareness and communication - Documented information **Clause 8 – Operation** - Operational control - Regular performance of risk and impact assessments - Implementation of selected controls **Clause 9 – Performance evaluation** - Monitoring and measuring AIMS performance - Internal audits and management reviews **Clause 10 – Improvement** - Continual improvement of the AIMS - Handling nonconformities and corrective actions #### Annexes (A–D) The annexes provide detailed guidance and controls: **Annex A – Reference control objectives and controls** - List of AI-specific control objectives - Areas: policies, governance, data management, AI lifecycle, system impact controls - Organizations select controls to implement based on risk **Annex B – Implementation guidance** - Practical guidance for implementing controls - Examples: drafting an AI policy, assigning responsibilities, conducting AI risk assessments **Annex C – AI-related organizational objectives and risk factors** - Examples of AI-specific objectives and risks - Reference to ISO/IEC 23894 for detailed AI risk management **Annex D – Use of the AIMS in different sectors** - Sector-specific application notes - Encourages a holistic approach #### Roles in the AI Ecosystem ISO 42001 distinguishes between different actors: - **AI Provider:** Provides AI systems - **AI Producer:** Designs, develops, and tests AI products - **AI User:** Uses AI products or services in their own business processes These roles determine specific duties and controls within the AIMS. #### Risk and Impact Assessments A key differentiator from other management system standards is the combination of two assessment types: **AI Risk Assessment** - Analyzes technical threats and vulnerabilities - Evaluates likelihoods affecting the AI system - Focuses on system security and reliability **AI System Impact Assessment** - Evaluates potential impacts on individuals, groups, or society - Considers ethical and social factors - Supports integration of fairness, transparency, and ethics - Assesses discrimination risks and potential harm > **Pro tip:** Combining both assessments enables a holistic view of AI risks—technical and societal. --- ### Implementation Guidance and Best Practices #### Management Engagement and Scope A successful AIMS requires strong leadership support: - **Top management commitment:** Adopt an AI policy and allocate resources - **Realistic scope definition:** Focus on relevant AI products, services, or departments - **Clear governance structure:** Define roles and responsibilities #### Risk-Based Planning **Systematic evaluation** - Combine technical risk assessments with societal impact analyses - Identify threats (data leaks, model manipulation) - Analyze ethical aspects and discrimination risks **Control selection** - Risk-based selection of Annex A controls - Documentation in the Statement of Applicability (SoA) - Rationale for implemented and excluded controls #### Implementing Key Controls **Policies & Governance (A.2)** - Develop an overarching AI policy - Review regularly and align with existing policies - Integrate into corporate strategy **Roles & Responsibilities (A.3)** - Clear responsibilities for AI development, operations, and oversight - Processes to report concerns and incidents - Cross-functional teams and escalation paths **Information for interested parties (A.8)** - Transparent communication about AI capabilities and limitations - Education on risks and terms of use - Feedback channels for users **Third parties & customers (A.10)** - Assign responsibilities across suppliers and customers - Fair risk allocation along the value chain - Contracts with AI-specific clauses #### Documentation, Monitoring, and Training **Comprehensive documentation** - Policies, processes, and risk assessments - Impact analyses and control evidence - Versioning and change history **Continuous monitoring** - Systematic monitoring of AI performance - Regular internal audits and management reviews - KPIs and trend analysis **Training and awareness** - AI-specific training for developers and users - Awareness of ethical and legal aspects - Regular updates on new developments #### Link to the EU AI Act ISO 42001 supports compliance with upcoming regulations: - **Proactive risk management:** Structured governance for AI risks - **Transparency and documentation:** Auditable compliance processes - **Repeatable procedures:** Scalable approaches for different AI systems > **Pro tip:** With ISO 42001, organizations can proactively manage risks and be better prepared for legal requirements such as the EU AI Act. --- ### Support with the fuentis Suite The **fuentis Suite** can specifically support AIMS implementation: **Risk Management module** - Structured capture of AI risks and impact analyses - Automated risk register linked to assets and controls - Templates for AI risk and AI system impact assessments - Integration of different evaluation methods **Asset Management** - Manage data sources, models, and AI systems as assets - Assign owners and classifications - Lifecycle management for AI components - Track dependencies and interfaces **Compliance Management** - Prebuilt templates for ISO 42001 controls - Automated Statement of Applicability - Gap analyses and maturity assessments - Mapping to other standards (ISO 27001, EU AI Act) **Audit & Review modules** - Plan and conduct internal AIMS audits - Track nonconformities and corrective actions - Automated reporting - Management dashboard with KPIs **Document Management** - Central repository for AI policies and risk records - Versioning and approval workflows - Impact analyses and audit logs - Integrated workflow support --- ### Integration with Other Standards **ISO 27001 / ISO 27701** - Shared High-Level Structure eases integration - Risk management as a unifying element - Many controls can be combined and aligned **NIST AI Risk Management Framework (AI RMF)** - ISO 42001 complements the NIST framework - Both aim at responsible AI development - Synergies in risk assessment and governance **EU AI Act** - ISO 42001 provides a solid foundation for regulatory compliance - Likely to serve as a benchmark for AI management systems - Supports demonstration of “due diligence” **Industry and privacy standards** - Combine with GDPR and ISO 27701 for privacy - Integrate sector-specific requirements (healthcare, finance) - Efficient audit strategies through shared controls --- ### Glossary **Artificial Intelligence Management System (AIMS):** A management system of interrelated elements (policies, objectives, processes) for the responsible development, provision, and use of AI systems. **AI Risk Assessment:** Systematic identification and evaluation of technical risks (threats, vulnerabilities, likelihoods) for AI systems. **AI System Impact Assessment:** Evaluation of potential impacts from the use or misuse of an AI system on individuals, groups, or society, including ethical and social factors. **Statement of Applicability (SoA):** Document describing which Annex A controls are implemented or excluded, and why. **AI Policy:** Organization-wide policy for developing and using AI systems; defines principles, objectives, and responsibilities. **Control objective:** The purpose of a control (e.g., ensuring transparency or assigning accountability). --- ### Key Takeaways at a Glance 1. **First AI management standard:** ISO/IEC 42001 is the world’s first AIMS standard, offering a structured framework for the responsible development and use of AI systems. 2. **Holistic risk approach:** Beyond classic risk assessments, the standard requires impact assessments to systematically consider societal and ethical effects of AI. 3. **Flexible control selection:** Annex A lists AI-specific controls to be selected based on context and justified in the Statement of Applicability. 4. **Synergy with existing standards:** ISO 42001 aligns with ISO 27001, ISO 27701, and NIST AI RMF, and provides a solid foundation for complying with the EU AI Act. 5. **Tools as a success factor:** Modern platforms like the fuentis Suite accelerate AIMS deployment with dedicated modules for risk management, asset inventory, compliance, and audits. ## NIS2 - European Cybersecurity Directive Source: https://servicehub.fuentis.com/en/standards/nis2-leitfaden/ The NIS2 Directive (EU 2022/2555) marks a paradigm shift in European cybersecurity legislation. It significantly expands the scope of application and requires all EU member states to create a high common level of security for network and information systems. Germany implements the directive through the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG). ### What is NIS2 and Why is it Relevant? NIS2 replaces the original NIS Directive from 2016 and dramatically expands the scope: from approximately 4,500 operators of critical infrastructures to an estimated 29,000 affected companies in Germany. This massive expansion reflects the reality that cyberattacks now affect all industries and the economy as a whole must become resilient. #### Why Implement NIS2? **Legal Necessity:** - Avoidance of significant penalties (up to 20 million EUR or 2% of global turnover) - Fulfillment of legal compliance requirements - Protection from personal liability of management - Legal certainty in regulated markets **Business Benefits:** - Competitive advantage through early compliance - Trust from customers, partners, and authorities - Facilitated access to public contracts - Synergies with existing standards (ISO 27001, IT Baseline Protection) **Security Benefits:** - Risk-based cybersecurity governance - Proactive incident response processes - Strengthened supply chain security - Anchoring cybersecurity at executive level **Practice Tip: Use Timing** Although Germany missed the EU implementation deadline, companies can gain an advantage by starting preparations now. The law is expected to come into force in early 2026. ### Status of German Implementation #### Current Timeline **Delayed Implementation:** - EU deadline: October 17, 2024 (missed) - Cabinet decision: July 30, 2025 - Planned entry into force: Early 2026 - Registration deadline: 3 months after entry into force **Legal Consequences:** - EU Commission issued reasoned opinion (May 7, 2025) - Infringement procedure threatens - No long transition period for companies #### Competent Authority The Federal Office for Information Security (BSI) will serve as the central supervisory authority with expanded powers: - Registration and monitoring of companies - Ordering and enforcement of measures - Imposing fines - Coordinating incident response ### Scope and Affected Companies #### Three Categories of Entities ##### 1. Operators of Critical Facilities (KRITIS) - Retain existing KRITIS obligations - Thresholds remain unchanged (e.g., supply ≥ 500,000 people) - Additional NIS2 requirements - Mandatory audits every three years ##### 2. Essential Entities **Size Criteria:** - ≥ 250 employees OR - Annual turnover > 50 million EUR AND balance sheet total > 43 million EUR **Affected Sectors:** - Energy and water management - Transport and traffic - Banking and financial market infrastructures - Healthcare - Digital infrastructure - Public administration **Size-Independent Coverage:** - Top-level domain registries - DNS providers - Telecommunications networks - Cloud computing services ##### 3. Important Entities **Size Criteria:** - ≥ 50 employees OR - Annual turnover > 10 million EUR AND balance sheet total > 10 million EUR **Additional Sectors:** - Postal and courier services - Waste management - Chemical industry - Food production - Manufacturing - Digital services - Research organizations #### Sanctions and Penalties | Category | Fine | Assessment Basis | |----------|------|------------------| | **Essential Entities** | up to 20 million EUR | or 2% of global annual turnover | | **Important Entities** | up to 10 million EUR | or 1.4% of global annual turnover | **Personal Liability:** Executive and board members are personally liable for breaches of duty in implementing and monitoring measures. ### Core Concepts and Requirements #### Risk Management Approach NIS2 requires systematic risk management based on "state of the art" considering risks, company size, and costs. ##### Technical and Organizational Measures **Basic Security Measures:** - Risk assessment and IT security concepts - Incident response and business continuity management - Backup management and disaster recovery - Supply chain security and vendor management - Secure development, procurement, and maintenance - Vulnerability management and security assessments **Technical Controls:** - Cryptography and key management - Access management and multi-factor authentication - Secure communication (voice, video, text communication) - Emergency communication systems **Organizational Controls:** - Cyber hygiene and employee training - Management training on cyber risks - Documentation and evidence management ##### Extended Requirements for Essential Entities **Additional Technical Measures:** - Deployment of attack detection systems - Extended monitoring and logging systems - Regular penetration testing **Audit Obligations:** - Proof of measure implementation every three years - Audits, inspections, or certificates as evidence - Possible random BSI audits #### Notification and Registration Obligations ##### Registration with BSI **Self-Identification:** Companies must independently check whether they fall under NIS2 and register within three months. **Required Information:** - Company name and legal form - Contact details and contact persons - IP address ranges - Industry classification - EU countries of business activity - Annual data updates ##### Incident Response Procedures **Three-Stage Notification for Significant Security Incidents:** | Stage | Time Limit | Content | |-------|------------|----------| | **Initial Report** | 24 hours | Basic incident information | | **Follow-up Report** | 72 hours | Detailed analysis and initial measures | | **Final Report** | 1 month | Complete investigation and lessons learned | **Additional Notification Obligations:** - BSI may request interim reports - Public information for significant impacts - Customer warnings in specific sectors (finance, ICT, digital services) #### Governance and Leadership Responsibility **Management Responsibility:** - Personal liability of management - Approval and monitoring of security measures - Mandatory training on cyber risks - Integration into strategic business planning **BSI Supervisory Powers:** - Comprehensive audit and enforcement powers - Imposition of fines and sanctions - Random audits based on risk profiles - Ordering additional security measures ### Integration with Existing Standards #### Synergies with ISO 27001 NIS2 requirements largely overlap with established ISMS standards: **Overlapping Areas:** - Risk management and risk treatment - Incident response and business continuity - Access controls and authentication - Supplier management and outsourcing - Employee training and awareness - Documentation and evidence management **NIS2-Specific Extensions:** - Notification obligations within 24/72 hours/1 month - Management liability and training - BSI registration and monitoring - Sector-specific requirements #### Compatibility with IT Baseline Protection BSI IT Baseline Protection provides a solid foundation for NIS2 compliance: - Building block-oriented implementation - Structured risk assessment - Established security measures - Proven audit procedures **Practice Tip: Combine Standards** Companies with ISO 27001 certification or IT Baseline Protection implementation already have a good starting point. Existing processes only need to be extended with NIS2-specific elements. ### Implementation Strategies and Best Practices #### Phased Implementation ##### Phase 1: Clarify Applicability **Threshold Analysis:** - Review of industry affiliation - Assessment of company size (employees, turnover, balance sheet) - Identification of critical business areas - Consideration of subsidiaries and group structures **Special Attention for:** - DNS, cloud, or TLD service providers (size-independent) - Companies with mixed business areas - International group structures ##### Phase 2: Build or Extend ISMS **Establish Risk Management:** - Systematic threat and vulnerability analysis - Definition of protection objectives and acceptance thresholds - Implementation of risk-based controls - Continuous monitoring and improvement **Cover All NIS2 Topic Areas:** - Business continuity and disaster recovery - Supply chain security and vendor management - Vulnerability management and patch processes - Training programs for all employee levels ##### Phase 3: Operational Implementation **Define Notification Processes:** - Clear responsibilities and escalation paths - Templates for initial, follow-up, and final reports - Integration into existing incident response processes - Regular exercises and tests **Ensure Documentation:** - All security measures and risk assessments - Training records and management training - Audit results and improvement measures - Supplier assessments and contracts #### Avoiding Common Implementation Errors **Insufficient Scope Definition:** - Overlooking subsidiaries or business areas - Incorrect assessment of size criteria - Incomplete coverage of digital services **Lack of Management Involvement:** - Treatment as purely IT-technical topic - Missing executive training - Insufficient resource allocation **Incomplete Supply Chain Analysis:** - Neglecting cloud service providers - Missing contract adjustments with suppliers - Insufficient monitoring of third parties ### Support Through the fuentis Suite The fuentis Suite provides comprehensive support for NIS2 implementation: #### NIS2 Compliance Module - Pre-configured requirements according to § 30 BSIG-E - Automatic applicability check based on size criteria - Gap analysis to existing ISMS standards - Compliance dashboard with implementation status #### Risk Management - Structured capture of all NIS2-relevant risks - Linking with assets and business processes - Automatic risk assessment and prioritization - Integration with existing risk management processes #### Incident Management - Mapping of three-stage notification processes - Automatic reminders for notification deadlines - Templates for BSI notifications - Documentation and tracking of incidents #### Asset Management - Central capture of all information-processing assets - Assignment of responsibilities and criticalities - Monitoring of changes and updates - Integration with configuration management #### Supplier Management - Assessment and monitoring of service providers - Management of security requirements and evidence - Audit planning and execution - Contract management with security clauses #### Audit and Review Functions - Planning and conducting internal audits - Tracking non-conformities and measures - Management review support - Automated reporting for BSI audits #### Training and Awareness - NIS2-specific training modules - Management training on cyber risks - Employee awareness programs - Tracking of training completions and deadlines ### Preparing for BSI Audits #### Audit Types and Procedures **KRITIS Audits (every 3 years):** - Complete review of all measures - On-site audits or remote assessments - Alternative: Recognized certifications (ISO 27001, IT Baseline Protection) **Random BSI Audits:** - Risk-based selection of companies - Focus on specific vulnerabilities or incidents - Short notice periods #### Audit Preparation **Documentation Requirements:** - Complete ISMS documentation - Evidence for all implemented measures - Risk assessments and treatment strategies - Incident response plans and evidence - Training materials and certificates **Practical Tips:** - Regular internal audits as preparation - Continuous documentation updates - Clear responsibilities and contact persons - Practice audit situations with the team ### Future Perspectives and Developments #### European Harmonization **Trends in the EU:** - Further harmonization of national implementations - Increased cross-border cooperation - Integration with other EU cybersecurity initiatives - Possible tightening of requirements #### Technological Developments **New Challenges:** - Artificial intelligence and machine learning - IoT and Industrial IoT security - 5G networks and edge computing - Quantum computing and post-quantum cryptography **Adaptation of Requirements:** - Regular updates of technical standards - Consideration of new threat scenarios - Evolution of "state of the art" definition ### Key Takeaways at a Glance **The 5 Most Important Success Factors for NIS2 Compliance:** 1. **Early Applicability Assessment**: Clarify immediately whether your company falls under NIS2 - the size criteria are complex and capture significantly more organizations than before 2. **ISMS as Compliance Foundation**: An established information security management system according to ISO 27001 or IT Baseline Protection forms the best basis for NIS2 compliance 3. **Secure Management Commitment**: Personal liability of management makes cybersecurity a top management issue - management training and involvement are indispensable 4. **Build Incident Response Capabilities**: The 24-hour notification obligation requires established processes, clear responsibilities, and practiced procedures 5. **Systematically Secure Supply Chains**: Supply chain risks are a central NIS2 topic - assess and monitor all critical service providers and suppliers **Why NIS2 is More Than Just Compliance:** NIS2 marks the transition from voluntary to mandatory cybersecurity for large parts of the economy. Companies that proactively implement NIS2 create not only legal certainty but also a sustainable competitive advantage through increased resilience, customer trust, and operational excellence in digital transformation. ## OT Security Standards – Fundamentals, Requirements, and Practical Implementation Source: https://servicehub.fuentis.com/en/standards/ot-sicherheitsstandards-grundlagen/ Operational Technology (OT) controls and monitors physical processes – from water pumps and production plants to transportation systems. With increasing integration into IT systems, the attack surface grows: ransomware, insider threats, and cyber espionage are real risks in OT as well. OT standards such as ISO/IEC 27001, ISA/IEC 62443, NIST SP 800-82, and NERC CIP help organizations manage these risks and systematically strengthen the security of industrial control and automation systems. ### Core Concepts and Requirements of Key OT Standards #### ISO/IEC 27001 (ISMS) **Overview:** Globally recognized standard for information security management systems, applicable to both IT and OT environments. **Key Requirements:** - Systematic risk analysis for all assets - Clear definition of security objectives and policies - Implementation of controls based on risk assessment - Comprehensive documentation of processes - Regular internal and external audits - Continuous improvement of the management system **Benefit:** Certification builds trust with customers and partners while reducing compliance overhead. #### ISA/IEC 62443 (Industrial Automation and Control) **Objective:** Specific protection of Industrial Automation and Control Systems (IACS) and other OT environments. **Core Concept – Layered Defense:** Facilities are segmented into security zones; connections between zones run through monitored *conduits*. **Four main parts:** 1. **General:** Terms and concepts 2. **Policies and Procedures:** Program structure, patch management, and operational implementation 3. **System:** Assessment methods, security levels, and technical foundations 4. **Component:** Security requirements for individual devices and software **Key Documents:** - 62443-1-1: Terminology and concepts - 62443-2-4: Security program for service providers - 62443-3-2: Risk assessment and system partitioning - 62443-3-3: System security requirements - 62443-4-1/4-2: Secure development and component security **Practical Application:** - Conduct OT-specific risk analyses - Establish IACS security teams - Implement patch and configuration management - Embed security into product lifecycles #### NIST SP 800-82 (Guide to OT Security) **Focus:** Practical guidelines for securing OT systems while addressing unique performance, reliability, and safety requirements. **Covered Systems:** Broad range of programmable systems directly interacting with the physical environment: - Industrial control systems - Building automation systems - Transportation systems - Critical infrastructures **Contents:** Describes typical threats and vulnerabilities, recommending countermeasures tailored to OT environments. #### NERC CIP (Critical Infrastructure Protection) **Scope:** Mandatory security standards for organizations operating parts of the North American power grid. **Goals:** Protect the Bulk Electric System (BES) from physical and cyber threats. Non-compliance leads to fines and reputational damage. **Selected Standards:** - **CIP-002:** Asset identification and categorization (high, medium, low impact) - **CIP-003:** Security management controls (policies, risk assessments, roles) - **CIP-005:** Electronic security perimeter (protecting critical assets) - **CIP-007:** System security management (patching, ports/services, malware defense) - **CIP-008 to CIP-013:** Incident response, recovery, change management, supply chain security #### Other Industry- or Domain-Specific Standards - **ISO/IEC 80001:** Risk management for IT networks with medical devices (healthcare) - **IEC 63154:** Requirements for maritime systems (shipping) - **IEC 62645/62859:** Nuclear facility requirements - **NIST Cybersecurity Framework:** Five functions (Identify, Protect, Detect, Respond, Recover), flexible for OT use ### Implementation Guidance and Best Practices #### Risk-Based Approach **Systematic Risk Assessment:** - Identify and categorize assets - Identify threats and vulnerabilities - Assess likelihood and impact - Prioritize and mitigate risks **Security Zones and Conduits:** - Segment OT networks - Contain attacks within zones - Monitor all inter-zone connections **Defining Security Levels:** - Apply appropriate controls per zone - Align with IEC 62443-3-3 - Graduated protection by criticality #### Governance and Organization **Management Engagement:** - Make OT security a business priority - Allocate sufficient resources - Conduct regular reviews and decisions **Roles and Responsibilities:** - Appoint OT security officers - Establish cross-functional teams - Ensure alignment of engineering, IT, and operations **Practical Tip:** Define clear policies for patch management, access control, and incident response, referencing CIP-003 and CIP-008. #### Technical Measures **Network Segmentation and Access Controls:** - Define network zones - Use firewalls and access rules - Implement multi-factor authentication - Enforce least-privilege principle **Patch and Configuration Management:** - Regular updates for controllers and SCADA - Documented change controls (CIP-007, CIP-010) - Test environments for critical patches **Monitoring and Incident Response:** - Continuous monitoring of OT systems - Log analysis and anomaly detection - Rapid incident response - Regular testing of incident response plans #### People and Culture **Awareness and Training:** - OT-specific security training - Awareness campaigns - Regular refreshers **Continuous Improvement:** - Review security measures regularly - Apply lessons learned from incidents - Adapt to emerging threats ### Support with the fuentis Suite The **fuentis Suite** provides extensive support for OT security programs: **Risk Management Module:** - Structured asset inventory (including OT devices) - Threat and vulnerability assessments - Automated risk registers **Compliance Management:** - Mapping of IEC 62443 controls - NIST guidelines and CIP requirements - Gap analysis and SoA generator **Asset Management:** - Central OT asset directory - Link to risks and responsibilities - Control integration **Audit and Review Modules** *(on roadmap)* - Internal audit planning - Tracking corrective actions - Support for NERC CIP or IEC certification **Document Management** *(on roadmap)* - Manage policies and procedures - Versioning and approval workflows - Centralized evidence repository ### Key Takeaways 1. **Cross-Industry Standards:** ISO/IEC 27001, ISA/IEC 62443, NIST SP 800-82, and NERC CIP address different aspects of OT security – from management systems to technical controls and energy infrastructure. 2. **Layered Defense is Key:** IEC 62443 promotes zone segmentation and monitored conduits to contain attacks. 3. **Risk-Based Approach:** All standards require systematic risk analysis and prioritization of critical assets. 4. **Regulatory Obligations:** NERC CIP is mandatory in North America and increasingly serves as a model for global OT regulation. 5. **Tool Support:** Software such as the fuentis Suite streamlines risk management, compliance mapping, and audit readiness, significantly reducing implementation effort. ## PCI DSS - Payment Card Industry Data Security Standard Source: https://servicehub.fuentis.com/en/standards/pci-dss-leitfaden/ The Payment Card Industry Data Security Standard (PCI DSS) is a globally recognized security standard for protecting credit card data. It was developed to help organizations securely process, store, and transmit cardholder data while minimizing the risk of data breaches and credit card fraud. ### What is PCI DSS and Why is it Relevant? PCI DSS was developed by the PCI Security Standards Council, an organization founded by the major credit card companies including Visa, MasterCard, American Express, and Discover. The standard applies to all organizations that process, store, or transmit credit card data - regardless of size or industry. #### Why Implement PCI DSS? **Business Necessity:** - Protection from financial losses due to data breaches - Avoidance of penalties and damage claims - Maintaining customer trust and brand reputation - Fulfillment of contractual obligations to payment service providers **Security Benefits:** - Systematic protection of sensitive cardholder data - Reduction of identity theft and fraud risks - Establishment of robust security controls - Demonstration of appropriate security measures **Practice Tip: Compliance as Competitive Advantage** Use PCI DSS not just as an obligation, but as an opportunity for differentiation. Customers trust companies more that demonstrably maintain high security standards. ### Core Concepts and Requirements #### The 6 Security Goals and 12 Requirements PCI DSS 4.0.1 (published in June 2024) structures requirements into six overarching security goals: ##### 1. Build and Maintain Secure Networks and Systems **Requirement 1:** Install and maintain firewall configurations - Protection of cardholder data through network segmentation - Control of traffic between trusted and untrusted networks - Documentation and regular review of firewall rules **Requirement 2:** Do not use vendor-supplied defaults - Change all default passwords and security parameters - System hardening by removing unnecessary services - Implementation of secure configuration standards ##### 2. Protect Cardholder Data **Requirement 3:** Protect stored cardholder data - Minimize data storage to what is necessary - Encryption of stored data with strong algorithms - Secure key management and rotation **Requirement 4:** Encrypt transmission over public networks - Use of strong cryptography (TLS 1.2 or higher) - Protection against man-in-the-middle attacks - Secure transmission for mobile applications ##### 3. Maintain a Vulnerability Management Program **Requirement 5:** Protect against malware - Deployment of current anti-malware solutions - Regular updates and scans - Monitoring and incident response for malware detections **Requirement 6:** Develop secure systems and applications - Vulnerability management and patch management - Secure development practices (Secure Coding) - Regular security testing and code reviews ##### 4. Implement Strong Access Controls **Requirement 7:** Restrict access by need-to-know principle - Role-based access controls (RBAC) - Principle of least privilege - Regular access reviews **Requirement 8:** Identify and authenticate users - Unique user IDs for all individuals - Strong authentication mechanisms - Multi-factor authentication for privileged access **Requirement 9:** Restrict physical access - Physical security measures for data centers - Access controls and visitor logging - Secure disposal of data carriers ##### 5. Regularly Monitor and Test Networks **Requirement 10:** Track and monitor all access - Comprehensive logging of security-relevant events - Central log collection and analysis - Protection of log data from manipulation **Requirement 11:** Regularly test security systems - Vulnerability scans by approved vendors (ASV) - Penetration testing for critical changes - Intrusion detection and prevention systems ##### 6. Maintain Information Security Policy **Requirement 12:** Information security policy - Comprehensive security policies for all employees - Regular training and awareness programs - Incident response and business continuity plans ### PCI DSS Validation Levels and Compliance Requirements #### The Four Merchant Levels Validation requirements depend on annual transaction volume: | **Level** | **Transaction Volume** | **Validation Method** | **Frequency** | |-----------|------------------------|----------------------|---------------| | **Level 1** | > 6 million | On-site audit by QSA | Annual | | **Level 2** | 1-6 million | Self-Assessment (SAQ) | Annual | | **Level 3** | 20,000-1 million (e-commerce) | Self-Assessment (SAQ) | Annual | | **Level 4** | < 20,000 (e-commerce) or < 1 million | Self-Assessment (SAQ) | Annual | #### Self-Assessment Questionnaire (SAQ) For most organizations, SAQ is the primary validation method: - **SAQ A:** Card processing exclusively through third parties - **SAQ B:** Manual terminals or standalone devices - **SAQ C:** Web-based payment applications - **SAQ D:** All other merchant environments #### External Vulnerability Scans (ASV) All merchant levels require quarterly scans by an Approved Scanning Vendor (ASV): - Review of all publicly accessible IP addresses - Identification and assessment of vulnerabilities - Confirmation of remediation of critical vulnerabilities ### Implementation Strategies and Best Practices #### Three-Step Compliance Approach **1. Assess** - Complete inventory of all systems with cardholder data - Data flow analysis and scope definition - Gap analysis against PCI DSS requirements - Risk assessment of identified vulnerabilities **2. Remediate** - Prioritized implementation of missing controls - PCI scope reduction through data minimization - Implementation of compensating controls where required - Documentation of all security measures **3. Report** - Creation of required compliance reports - Submission to acquiring bank or payment service provider - Continuous monitoring and maintenance #### Scope Reduction as Key Strategy **Practice Tip: Minimizing the Card Data Environment (CDE)** - Use tokenization to reduce stored card data - Implement point-to-point encryption (P2PE) - Utilize hosted payment solutions (Payment Service Provider) - Strictly segment networks between CDE and other systems #### Avoiding Common Implementation Errors **Data Storage:** - Never store CVV/CVC codes - No full card numbers in logs or backups - Secure deletion of data no longer needed **Network Security:** - Insufficient segmentation between CDE and corporate network - Weak or missing firewall rules - Use of insecure protocols (e.g., outdated TLS versions) **Access Controls:** - Shared or generic user accounts - Missing multi-factor authentication for remote access - Insufficient monitoring of privileged access ### Integration with Other Compliance Frameworks #### Synergies with ISO 27001 Many PCI DSS requirements overlap with ISO 27001 controls: - **Access Controls:** ISO 27001 A.9 complements PCI DSS Requirements 7-8 - **Cryptography:** ISO 27001 A.10 supports PCI DSS Requirements 3-4 - **Operations Security:** ISO 27001 A.12 covers PCI DSS Requirements 5-6 - **Incident Management:** ISO 27001 A.16 complements PCI DSS Requirement 12 #### SOC 2 and PCI DSS Both standards can be implemented in parallel: - Common controls for security and availability - Similar requirements for monitoring and logging - Combined audit strategies for efficiency gains #### GDPR Compatibility PCI DSS complements GDPR requirements in the payment area: - Technical and organizational measures for data protection - Incident response and breach notification - Privacy by design and by default ### Support Through the fuentis Suite The fuentis Suite provides comprehensive support for PCI DSS compliance: #### PCI DSS Compliance Module - Pre-configured PCI DSS 4.0.1 requirements - SAQ templates for all merchant levels - Automated gap analyses and progress tracking - Integration with vulnerability scan results #### Asset and Scope Management - Central management of Card Data Environment - Automated data flow analysis - Scope visualization and documentation - Change management for CDE-relevant changes #### Risk and Vulnerability Management - Integration with ASV scan results - Prioritization of vulnerabilities by PCI relevance - Tracking of remediation measures - Compensating controls management #### Compliance Reporting - Automated SAQ generation - Compliance dashboards and KPIs - Audit trail and evidence management - Schedule management for recurring assessments #### Training and Awareness - PCI DSS-specific training modules - Role-based training for different target groups - Awareness campaigns and communication - Tracking of training completions ### Continuous Compliance and Monitoring #### Ongoing Compliance Strategy **Quarterly Activities:** - ASV vulnerability scans - Review of firewall rules and access controls - Review of log monitoring configuration - Update of risk assessment **Annual Compliance Validation:** - Complete SAQ creation or QSA audit - Penetration testing for Level 1-3 merchants - Review and update of security policies - Employee training and awareness programs #### Change Management **Managing PCI-relevant Changes:** - Assessment of all changes for scope impacts - Security testing before production deployment - Documentation of compensating controls - Communication with QSA or ASV for critical changes #### Key Performance Indicators (KPIs) **Monitoring PCI Compliance:** - Number of open critical vulnerabilities - Time to remediation of identified vulnerabilities - Number of PCI-related security incidents - Compliance rate in internal assessments - Completeness of required documentation ### Future of PCI DSS #### New Requirements in PCI DSS 4.0 **Enhanced Authentication:** - Stronger multi-factor authentication - Customized approach for innovative security solutions - Extended requirements for validated cryptography **Cloud and Modern Technologies:** - Specific requirements for containers and microservices - Enhanced guidance for cloud environments - API security and modern development practices #### Emerging Threats and Adaptations **Current Threat Landscape:** - Ransomware and Advanced Persistent Threats - Supply chain attacks - Zero-day vulnerabilities in widely used systems - Social engineering and insider threats ### Key Takeaways at a Glance **The 5 Most Important Success Factors for PCI DSS Compliance:** 1. **Scope Minimization as Priority**: Reduce your Card Data Environment through tokenization, P2PE, and hosted payment solutions - less scope means less effort and risk 2. **Systematic Approach**: Follow the three-step approach (Assess, Remediate, Report) and treat PCI DSS as a continuous process, not a one-time certification 3. **Build Strong Foundations**: Invest in robust network segmentation, access controls, and monitoring - these form the foundation for sustainable compliance 4. **Integration with Existing Frameworks**: Leverage synergies with ISO 27001, SOC 2, or other standards for efficiency gains and cost reduction 5. **Use Automation and Tools**: Modern ISMS platforms like the fuentis Suite significantly reduce manual effort and improve compliance quality **Why PCI DSS is More Than Just Compliance:** PCI DSS is a proven framework for comprehensive data security. Organizations that take PCI DSS seriously and go beyond minimum compliance create not only trust with customers and partners, but also a robust security foundation that protects against modern cyber threats. ## SOC 2 Standards – Service Organization Control 2 Source: https://servicehub.fuentis.com/en/standards/soc-2-standards-service-organization-control/ **SOC 2** (Service Organization Control 2) is a framework for assessing the internal controls of service organizations that handle customer data. It was developed in 2010 by the American Institute of Certified Public Accountants (AICPA) and defines criteria for how organizations should process data securely and reliably. Unlike strictly prescriptive standards such as PCI DSS, SOC 2 is not a rigid checklist. Instead, each organization designs its own controls, which are then examined by an independent CPA auditor. The goal is to build trust by enabling customers, partners, and regulators to understand how a provider ensures the availability, integrity, and confidentiality of sensitive data. **Why is SOC 2 relevant?** - **Customer trust:** Especially for cloud service providers and SaaS companies, SOC 2 is a key sales argument - **Market requirement:** Many U.S.-based customers demand SOC 2 reports as proof of security competence - **Flexibility:** Unlike rigid certifications, companies can tailor controls to their specific services --- ### Core Concepts and Requirements #### Trust Services Criteria (TSC) SOC 2 is based on five Trust Services Criteria (TSC). The security criteria are **mandatory**; the other four can be included in the audit scope depending on the service. Each category includes Points of Focus that an organization must meet or justify. ##### The Five Trust Services Criteria in Detail **1. Security (Common Criteria)** – *Mandatory* - **Purpose:** Protect information from unauthorized access and misuse - **Key aspects:** - Access controls and permissions management - Authentication methods (e.g., multi-factor authentication) - Network firewalls and intrusion detection systems - Physical security measures - Protection against malware and other threats **2. Availability** – *Optional* - **Purpose:** Ensure systems and services are available to employees and customers - **Key aspects:** - Fault-tolerant design and redundancies - Disaster recovery plans and business continuity management - Performance and network monitoring - Service-level agreements (SLAs) - Capacity planning and scalability **3. Processing Integrity** – *Optional* - **Purpose:** Demonstrate that systems perform their functions correctly, completely, and on time - **Key aspects:** - Clear specification and monitoring of inputs, processing, and outputs - Protection against unintentional manipulation - Data validation and error handling - Transaction integrity - Quality assurance processes **4. Confidentiality** – *Optional* - **Purpose:** Protect confidential information through restricted access, storage, and use - **Key aspects:** - Encryption in transit and at rest (TLS, AES) - Principle of least privilege - Non-disclosure agreements (NDAs) - Secure data disposal - Information classification **5. Privacy** – *Optional* - **Purpose:** Govern the collection, use, storage, and disposal of personal data according to the Generally Accepted Privacy Principles (GAPP) - **Key aspects:** - Definition of what constitutes personal information - Implementation of controls to protect such data - Consent management - Data subject rights (access, deletion, rectification) - Privacy policies and procedures > **Practical tip:** Most companies start with the Security criteria and add further TSCs based on customer requirements. Cloud providers often include "Availability" and "Confidentiality." #### Types of SOC 2 Reports SOC 2 offers two report types that differ in scope and level of assurance: ##### Type I Report – Design of Controls - **Scope:** Evaluates whether control design is suitable at a specific point in time - **Time frame:** Snapshot (as-of date) - **Best for:** Organizations just building a control environment - **Advantage:** Faster to obtain (3–6 months of preparation) - **Drawback:** Lower assurance for customers ##### Type II Report – Design and Operating Effectiveness - **Scope:** Additionally examines the effectiveness of controls over a defined period - **Time frame:** Typically 3–12 months (commonly 6 or 12 months) - **Best for:** Established organizations with functioning controls - **Advantage:** Gold standard – highest level of assurance for customers - **Drawback:** Longer preparation time and higher cost #### Differences from Other SOC Reports ##### SOC 1 - **Focus:** Service organizations whose controls impact their customers’ financial reporting - **Examples:** Payroll providers, payment processors, accounting services - **Standard:** SSAE 18 (U.S.) / ISAE 3402 (International) ##### SOC 3 - **Focus:** Public report based on a SOC 2 examination - **Special feature:** No detailed test descriptions – for marketing and public communication - **Use:** Website seals, sales collateral, general trust building --- ### Distinction from ISO 27001 SOC 2 and ISO 27001 overlap by roughly **80%** in their requirements. Both frameworks require an external assessment and address principles such as security, integrity, and availability of information. #### Key Differences | Aspect | SOC 2 | ISO 27001 | |-------|-------|-----------| | **Target market** | U.S.-centric standard | Internationally recognized | | **Flexibility** | Choose from 5 TSCs; design your own controls | 93 mandatory controls in Annex A | | **Report form** | Attestation report by a CPA | Certificate from an accredited body | | **Validity** | Renewed annually | 3 years with annual surveillance audits | | **Cost** | Generally lower | Higher initial costs | | **Documentation** | System Description | ISMS documentation | #### Leveraging Synergies Many organizations combine SOC 2 and ISO 27001: - **Shared controls:** About 80% overlap in requirements - **Combined audits:** Some auditors offer integrated assessments - **Global coverage:** ISO 27001 for international markets, SOC 2 for U.S. customers - **Efficiency gains:** An ISO 27001 ISMS greatly streamlines SOC 2 preparation --- ### Implementation Aids and Practice #### Project Preparation and Scoping ##### 1. Scoping and TSC Selection - **Define scope:** Which services, systems, and locations will be examined? - **Select TSCs:** Security is mandatory – which additional criteria do your customers require? - **Include supporting systems:** Ticketing tools, change management, incident tracking - **Document exclusions:** Clearly justify why certain areas are out of scope ##### 2. Decide on Type I or Type II - **Start with Type I:** If you don’t yet have established controls - **Go straight to Type II:** If controls and processes already exist (e.g., via ISO 27001) - **Customer expectations:** Many customers only accept Type II reports ##### 3. Perform a Gap Analysis **Self-assessment in four steps:** 1. **Capture the current state:** Which controls already exist? 2. **Define the target state:** What do the selected TSCs require? 3. **Identify gaps:** Where are controls or evidence missing? 4. **Create a remediation plan:** Prioritize by risk and effort > **Practical tip:** Use the AICPA Trust Services Criteria as a checklist. The Points of Focus provide concrete examples of effective controls. ##### 4. Close the Gaps **Typical actions:** - **Create policies:** Information security policy, access control, incident response - **Technical controls:** Enable MFA, implement encryption, set up logging - **Document processes:** Change management, vulnerability management, backup & recovery - **Training:** Security awareness, data protection, clean desk policy - **Adjust contracts:** Supplier agreements, NDAs, data processing agreements ##### 5. Readiness Assessment **Before the official audit:** - **Internal audits:** Test the effectiveness of your controls - **Mock audit:** Have an external advisor perform a dry run - **Collect evidence:** Screenshots, logs, reports, procedural documentation - **Management review:** Involve leadership in preparation #### Best Practices for a Successful SOC 2 Audit ##### Organizational Success Factors **1. Clarify responsibilities** - Appoint an experienced project lead (e.g., CISO, Compliance Manager) - Define clear roles and responsibilities - Establish regular status meetings **2. Engage stakeholders** - **Executive leadership:** Secure budget and resources - **IT:** Implement technical controls - **DevOps:** Secure the CI/CD pipeline, code reviews - **Legal:** Contracts and data protection - **HR:** Staff training and background checks **3. Know your risks and weaknesses** - Document data flows and storage locations - Run regular vulnerability scans - Report security incidents transparently - Implement a risk management system ##### Technical and Process Recommendations **Critical controls for SOC 2:** - **Access control:** Role-based access control (RBAC), regular access reviews - **Encryption:** TLS 1.2+ in transit, AES-256 at rest - **Monitoring:** SIEM, log aggregation, alerting - **Backup & recovery:** 3-2-1 rule, regular recovery tests - **Patch management:** Monthly updates, critical patches within 30 days - **Incident response:** Documented process, escalation path, post-mortems **Documentation and Evidence:** - **Version control:** Version all policies and procedures - **Audit trails:** Comprehensive logging of changes - **Evidence management:** Central repository for audit evidence - **Metrics:** KPIs for availability, incident response times, patch levels > **Practical tip:** Implement a compliance management tool to centrally manage SOC 2 documentation and evidence. This greatly simplifies audit preparation and reduces manual effort. #### Choosing the Right Auditor **Selection criteria:** - **CPA license:** Only licensed CPAs can issue SOC 2 reports - **Industry experience:** Familiarity with your industry and technology - **References:** Successful SOC 2 audits for similar companies - **Advisory approach:** Balance between rigor and pragmatic solutions - **Costs:** Type I: USD 10,000–30,000; Type II: USD 20,000–60,000 (depending on scope) --- ### Integration with Other Frameworks SOC 2 can be effectively combined with other security standards: #### Combination Options **ISO 27001 + SOC 2** - Use the ISMS as the foundation for SOC 2 controls - Combined audits possible with qualified auditors - Roughly 80% requirement overlap **NIST CSF + SOC 2** - Use the NIST Cybersecurity Framework to structure controls - Map NIST functions to TSCs - Particularly relevant for U.S. government contracts **HIPAA + SOC 2** - For healthcare providers and business associates - SOC 2 + HIPAA criteria in a single report is possible - Demonstrates compliance for health data **GDPR + SOC 2** - Privacy TSC covers many GDPR requirements - Document technical and organizational measures (TOMs) - Data processing agreements as part of the examination --- ### Support from the fuentis Suite The fuentis Suite provides comprehensive support for the SOC 2 process and can significantly increase the efficiency of your compliance efforts: #### Risk Management Module - **Risk identification:** Systematic capture of all relevant risks for the selected TSCs - **Risk assessment:** Prioritization by likelihood and impact - **Remediation planning:** Link risks to controls and actions - **Automated reviews:** Reminders for regular risk assessments - **Audit trail:** Complete documentation of all changes #### Asset Management - **Central inventory:** Record all IT assets and information assets - **Classification:** Categorize by protection needs and criticality - **Responsibilities:** Clear assignment of asset owners - **Lifecycle management:** From procurement to secure disposal #### Compliance Management - **SOC 2 templates:** Predefined templates for all five TSCs - **Control checklists:** Points of Focus as auditable checklists - **System Description:** Structured capture of your system environment - **Evidence register:** Central management of all audit evidence - **Gap analysis:** Automated comparison of current vs. target state #### Audit Modules - **Audit planning:** Annual plan for internal audits - **Execution:** Digital checklists and evaluations - **Nonconformities:** Recording and tracking of findings - **Corrective actions:** Workflow for implementation and effectiveness checks - **Reporting:** Automated audit reports #### Document Management - **Version control:** Versioned policies and procedures - **Approval workflows:** Digital approval processes - **Distribution:** Automatic notifications for updates - **Read receipts:** Proof of acknowledgment - **Audit trails:** Full history of all document changes #### Monitoring & Reporting - **Dashboards:** Real-time overview of compliance status - **KPI tracking:** Availability, response times, patch levels - **Trend analyses:** Security posture over time - **Management reports:** Executive-ready summaries - **Auditor access:** Read-only access for external auditors --- ### Key Takeaways at a Glance 1. **Flexible framework:** SOC 2 is based on five Trust Services Criteria, with only the Security criterion mandatory. Companies select additional criteria based on customer needs and design their own controls. 2. **Type II as the gold standard:** While Type I reports assess control design, Type II also tests operating effectiveness over time. A Type II report provides significantly greater assurance and is considered the industry standard. 3. **Structured preparation is crucial:** Careful scope definition, systematic gap analysis, and targeted remediation are the foundation of a successful audit. Plan 6–12 months for preparation. 4. **Documentation and evidence are critical:** Documented policies, implemented technical safeguards, and comprehensive evidence (logs, screenshots, reports) greatly facilitate the audit and strengthen security culture. 5. **Leverage synergies with ISO 27001:** SOC 2 and ISO 27001 overlap by about 80%. By combining them effectively, organizations can reduce effort and serve both international and U.S. customers at the same time. ## TISAX® – Standards for the Automotive Industry Source: https://servicehub.fuentis.com/en/standards/tisax-standards-automobilindustrie/ TISAX® (Trusted Information Security Assessment Exchange) is an industry-specific standard developed for the automotive sector to secure the confidential exchange of development, design, and production data across complex supply chains. The standard is based on ISO 27001 but extends it with automotive-specific requirements such as prototype protection and special data classifications. TISAX was developed by the German Association of the Automotive Industry (VDA) and the ENX Association. With the release of ISA 6.0 in October 2023, the requirements were fundamentally updated and made mandatory as of April 1, 2024. --- ### Why TISAX® Matters The increasing digitalization and interconnectivity of the automotive industry generate massive amounts of sensitive data. OEMs and suppliers continuously exchange development plans, source code, prototype data, and personal information. Without clear and uniform security requirements, each organization would need to conduct its own audits. **TISAX establishes a common standard by:** - Reducing audit overhead across the supply chain - Enabling transparent proof of security levels - Creating competitive advantages through recognized certification - Harmonizing security requirements industry-wide > **Pro Tip:** Companies with a TISAX label signal a high level of information security to their partners – often a prerequisite for contracts in the automotive industry. --- ### Core Concepts and Requirements #### The TISAX® Process in Three Steps 1. **Registration** - Online registration via the ENX portal - Definition of scope - Fee-based registration required 2. **Assessment** - **Self-assessment:** Using the ISA catalog - **External audit:** By accredited providers - **Level selection:** Depending on protection needs (AL 1–3) 3. **Exchange** - TISAX report created after successful audit - Controlled sharing with selected partners - Validity: 3 years (re-assessment required afterward) --- #### Assessment Levels and Protection Needs | Assessment Level | Description | Typical Use | |------------------|-------------|-------------| | **AL 1** | Self-assessment without external verification | Internal confirmation, rarely used | | **AL 2** | Plausibility check incl. document review and remote interviews | Basic IS, normal protection needs | | **AL 2.5** | Full remote audit, transitional step toward AL 3 | Flexible entry with upgrade option | | **AL 3** | Full on-site audit with complete verification | Highest protection (prototypes, PII) | --- #### ISA 6.0 – Current Version (mandatory from April 2024) **Key updates include:** - Stronger focus on IT/OT availability and business continuity - Revised and expanded privacy controls - New incident management requirements - English as the lead language - Mapping to ISO/IEC 27001:2022, NIST CSF 1.1 - New controls for backup/restore, service continuity, secure client management > **Note:** Existing assessments remain valid. New audits from April 1, 2024, must follow ISA 6.0. --- ### TISAX® vs. ISO 27001 | Aspect | ISO 27001 | TISAX® | |--------|-----------|--------| | **Scope** | Industry-neutral, global | Automotive-specific | | **Governance** | ISO-managed, long update cycles | ENX-managed, faster updates possible | | **Audit approach** | Single certification process | Multiple levels (AL 1–3) | | **Special controls** | Generic | Prototype/test vehicle controls | | **Certificate validity** | 3 years + annual surveillance | 3 years, no interim audits | > **Pro Tip:** An existing ISO 27001 ISMS provides a solid foundation and significantly reduces TISAX effort. --- ### Implementation Aids and Best Practices #### Preparation 1. Define **scope** (business areas, sites, data types, customer demands). 2. Conduct a **gap analysis** using ISA as checklist. 3. Choose an **audit provider** (e.g., TÜV, DEKRA, SGS, Bureau Veritas, PwC, KPMG). #### During the Assessment - Secure management commitment - Allocate time, budget, staff - Perform internal audits as rehearsal - Structure documentation for evidence #### After the Assessment - Obtain and share the TISAX label - Address nonconformities systematically - Document lessons learned - Continuously review and update risks and controls --- ### Integration with the fuentis Suite The fuentis Suite supports the TISAX process with: - **Risk management module** (ISA-aligned risk matrices, reporting) - **Compliance module** (ISA 6.0 templates, maturity scoring, gap analysis) - **Asset management** (inventory, classification, accountability) - **Document management** (central repository, versioning, workflows, audit trail) - **Audit modules** (planning, checklists, findings, effectiveness checks) > **Pro Tip:** Centralizing TISAX processes in one tool reduces administrative workload and increases transparency. --- ### Common Pitfalls and Success Factors **Pitfalls:** 1. Underestimating preparation effort (6–12 months for AL 3) 2. Missing documentation 3. Scope defined too broadly 4. Overlooking prototype protection 5. No internal test audits **Success factors:** - Early planning (min. 6 months ahead) - Dedicated TISAX project lead - Pragmatic approach (focus on essentials) - Learn from TISAX-certified peers - Use tool support (e.g., fuentis Suite) ### Key Takeaways 1. **Industry standard:** TISAX is the de facto standard for IS in the automotive supply chain. 2. **Structured process:** Registration, assessment, and exchange with AL 1–3 flexibility. 3. **ISA 6.0:** Mandatory since April 2024, with strong focus on availability, incident management, and privacy. 4. **ISO 27001 synergy:** Existing ISMS greatly eases TISAX implementation. 5. **Competitive edge:** A TISAX label often secures market access and partner trust. # Knowledge ## Best Practice Information Security Guideline Source: https://servicehub.fuentis.com/en/wissen/best-practice-informationssicherheitsleitlinie/ ### Information Security Policy: The Strategic Foundation of Your ISMS ### What is an Information Security Policy? The __Information Security Policy__ is the central __strategic foundation document__ of every Information Security Management System (ISMS). It defines at the highest level the objectives, responsibilities, and framework conditions for information security in your organization. The policy is __adopted and signed by executive management__ and thus documents the leadership's commitment to information security. It is binding for all employees and forms the basis for all further security measures. #### Typical Characteristics * Scope: 3 to 8 pages * Level: Strategic (no technical details) * Scope: Entire organization * Updates: Every 1-5 years * Approval: Executive management --- ### Distinction from Other Security Documents The Information Security Policy is often confused with other security documents. Here are the key differences: #### Information Security Policy vs. Information Security Concept The __Information Security Concept__ (IS Concept) is the central *technical* document of the ISMS and describes: * Asset protection requirements assessment * Risk analysis and risk assessment * Concrete security measures (technical and organizational) * Implementation planning and prioritization The __Policy__, however, defines the strategic framework under which the IS Concept is created. It answers the *"Why"* and *"What"*, while the IS Concept answers the *"How"*. __Rule of thumb:__ You can show the Policy to any employee - the IS Concept only to technical staff. --- ### Distinction: Information Security Policy vs. Security Guideline #### Overview: Two Levels of Control The **Information Security Policy** (IS Policy) and **Security Guidelines** (e.g., Password Guideline) are different document types in the ISMS that complement each other but have clearly distinguishable functions: - The **IS Policy** defines the strategic "WHAT" and "WHY" - The **Security Guideline** defines the concrete "HOW" --- #### Detailed Comparison | Characteristic | Information Security Policy | Security Guideline (e.g., Password Guideline) | |---------|----------------------------------|------------------------------------------------| | **Level** | Strategic | Tactical | | **Purpose** | Commitment to IS, objectives and responsibilities | Concrete behavioral rules for a specific topic | | **Validity** | Entire organization | Topic-specific (e.g., all authentication processes) | | **Target Audience** | All employees and executive management | All password users (can be more specific) | | **Approval** | Executive management | Information Security Officer (ISO), IT Management | | **Level of Detail** | Principles and framework | Concrete rules and requirements | | **Scope** | 3-8 pages | 2-5 pages | | **Updates** | Every 1-5 years | Every 1-3 years, earlier for technical changes | | **Binding Nature** | Overarching commitment document | Directly enforceable instructions | | **Key Question** | "What do we want to achieve?" | "How should employees behave concretely?" | --- ### Why is an Information Security Policy Important? #### 1. NIS2 Compliance and Executive Liability The [NIS2 Directive](https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/NIS2/nis2_node.html) brings a __fundamental change__: The __personal liability of executive management__ for cybersecurity. __What does this mean in practice?__ * Executive management is *personally responsible* for appropriate cybersecurity measures * Fines for violations: Up to __10 million euros__ or __2% of global annual revenue__ * __Personal liability__ of executives possible * Mandatory participation in cybersecurity training An Information Security Policy is therefore __essential__ to: 1. __Clearly define responsibilities__ (who is responsible for what?) 2. __Document management commitment__ (evidence for authorities) 3. __Create legal certainty__ (in case of audits or incidents) 4. __Demonstrate compliance__ (to BSI, regulatory authorities, customers) > __Important:__ Without a clear policy, executives cannot prove in the event of damage that they have fulfilled their duty of care. #### 2. Basis for ISO 27001 and IT-Grundschutz Certification Both [ISO/IEC 27001](https://www.iso.org/standard/27001) and the [BSI IT-Grundschutz](https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/IT-Grundschutz/it-grundschutz_node.html) *explicitly require* an Information Security Policy. Without this document, no certification is possible. #### 3. Trust from Customers and Business Partners In tenders, an Information Security Policy is increasingly required. It signals: * Professional security management * Clear responsibilities * Management commitment #### 4. Internal Clarity and Commitment The policy creates clarity for all employees about: * Security objectives of the organization * Their role and responsibility * Fundamental security principles * Consequences of violations --- ### What Must Be Included in an Information Security Policy? A complete IS Policy contains the following topics: | Section | Must / Should | Content | |-----------|---------------|--------| | __1. Introduction & Scope__ | __Must__ | Purpose of the document, who is affected (employees, locations, systems) | | __2. Importance of Information Security__ | __Must__ | Significance for the organization, IT dependency, threat scenarios | | __3. Security Objectives__ | __Must__ | Confidentiality, Integrity, Availability + organization-specific objectives | | __4. Responsibilities__ | __Must__ | Executive management, ISO, IT management, employees - who does what? | | __5. Compliance with Laws__ | __Must__ | GDPR, national data protection laws, commercial codes, NIS2, industry-specific requirements | | __6. ISMS Organization__ | __Must__ | Roles (ISO, IT management, ISMS team), tasks, reporting lines | | __7. Security Strategy__ | Should | ISMS approach (ISO 27001, IT-Grundschutz), risk analysis, PDCA cycle | | __8. Principles__ | Should | Minimum principle (need-to-know), maximum principle (appropriate protection) | | __9. Consequences of Violations__ | Should | Employment law and possibly criminal law consequences | | __10. Continuous Improvement__ | __Must__ | Review intervals, responsibilities for updates | | __11. Entry into Force__ | __Must__ | Date, signature of executive management | #### Particularly Important for NIS2-Affected Organizations * __Clear designation of the Information Security Officer (ISO)__ * __Resource commitment from executive management__ (personnel, budget, time) * __Annual review by executive management__ (management review) * __Commitment to training__ (for executive management and employees) --- ### Best Practice Examples The German Federal Office for Information Security (BSI) and the State of North Rhine-Westphalia provide practical examples: #### BSI Best Practice: RECPLAST GmbH An excellent example for medium-sized companies and industrial operations. [📄 Download BSI RECPLAST Sample Policy](https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Grundschutz/Hilfsmittel/Recplast/A01_Sicherheitsleitlinie.pdf?__blob=publicationFile&v=2) #### Ministry of Education North Rhine-Westphalia An example from public administration with focus on decentralized structures. [📄 Download NRW Information Security Policy](https://www.schulministerium.nrw/system/files/media/document/file/informationssicherheitsleitlinie_msb_221219.pdf) --- ### Tips for Your Policy __Avoid these common mistakes:__ * **Too generic** → Incorporate organization-specific elements (industry, concrete business processes, specific threats) * **Too technical** → Stay at the strategic level, understandable for all employees - not just IT experts * **No management signature** → Without executive management signature, the policy lacks binding force * **Unrealistic objectives** → Set measurable, achievable goals instead of "100% security" or "zero downtime" * **"Paper tiger" document** → Live the policy actively: communicate, train, sanction violations * **Never updated** → Establish fixed review intervals (at least annually) and maintain them * **Unclear responsibilities** → Name specifically: Who is the ISO? Who is responsible for which areas? --- ### Next Steps #### 1. Analysis Understand your organization: business processes, IT landscape, legal requirements (check NIS2 status!) #### 2. Draft Use the BSI or NRW template as a starting point and adapt it to your organization. #### 3. Coordination Get feedback from IT management, data protection officer, legal department, and works council. #### 4. Adoption Have the policy signed by executive management and set an effective date. #### 5. Communication Make the policy known to all employees (intranet, training, onboarding). #### 6. Live It The policy is not a "paper tiger" - live the content and review it regularly (at least annually). --- ## Business Continuity Management according to BSI Standard 200-4 Source: https://servicehub.fuentis.com/en/wissen/business-continuity-management-bsi-200-4/ Business Continuity Management (BCM) is a systematic approach to ensuring business continuity in emergency and crisis situations. According to BSI Standard 200-4, BCM enables organizations to maintain time-critical business processes even during severe disruptions, thereby minimizing damage. Its relevance is continuously increasing due to growing cyber threats, natural disasters, and complex infrastructure dependencies. ### The BSI Maturity Model for BCMS #### Reactive BCMS – Fast Entry The **Reactive BCMS** is designed for organizations that want to become operational quickly: - **Target Group**: Institutions with no prior BCM experience - **Approach**: Use of existing security measures and available resources - **Scope**: Protection of selected time-critical business processes - **Limitation**: Strongly simplified entry level that must be developed further after one BCM cycle - **Advantage**: Rapid establishment of emergency response capability #### Development BCMS – Structured Growth The **Development BCMS** allows for step-by-step BCMS implementation: - **Target Group**: Organizations with limited resources or little BCM experience - **Approach**: Focus on a limited scope of the most time-critical processes - **Advantage**: Gradual resource planning and adaptation based on experience - **Development Path**: Lays the foundation for a successful transition to the Standard BCMS - **Effectiveness**: Significantly stronger protection than Reactive BCMS #### Standard BCMS – Full Maturity The **Standard BCMS** represents full BCM implementation: - **Scope**: Analysis of all business processes within the BCMS scope - **Safeguards**: Risk-appropriate protection of time-critical processes - **Certification**: Achieves the maturity required for ISO 22301 certification - **Stakeholders**: Meets the requirements of all relevant stakeholders > **Practical Tip**: Start with Development BCMS if you have basic BCM knowledge. Reactive BCMS should only be used as an emergency entry point. ### Organizational Structures in a Crisis #### Special Organizational Structure (BAO) The normal organizational structure (AAO) is often unsuitable in crises because complex coordination paths prevent quick decisions. The BAO addresses this issue by: **Three-Level Structure:** - **Strategic Level**: Defines objectives and priorities - **Tactical Level**: Situation analysis, decision-making, monitoring - **Operational Level**: Execution of measures and feedback **Crisis Team Characteristics:** - Operates outside regular organizational structures - Has predefined decision-making authority - Staffed with subject matter experts from various areas - Each role has at least one deputy **Infrastructure Requirements:** - Secure and well-equipped crisis team room - Backup room for fallback scenarios - Communication technology and alerting systems #### Roles and Responsibilities **Business Continuity Manager (BCM):** - Planning and conducting the Business Impact Analysis - Coordinating BCM processes - Developing emergency plans **BC Officer:** - Overall coordination - Professional support for BCM - Acts as liaison to senior management ### Emergency and Crisis Management #### Terminology - **Disruption**: Short-term interruption with minor damage, resolvable in normal operations - **Emergency**: Intolerable interruption of time-critical processes with significant damage; requires emergency plans and BAO - **Crisis**: Severe interruption with no existing plans or when measures fail; requires extended crisis management structures #### Reporting and Escalation Process **Central Reporting Office:** - Receives and documents all incident reports - Categorizes them as disruptions, emergencies, or crises - Manages contact information and priorities **Escalation Criteria:** - Immediate BAO activation for emergencies and crises - 24/7 availability outside business hours - Clear, precise alerts with action instructions **Emergency Plans:** - **Business Continuity Plans (BCP)**: Maintain critical processes - **Restart Plans**: Reintegrate failed resources - **Recovery Plans**: Return to normal operations ### Business Impact Analysis (BIA) #### Objectives and Benefits The BIA forms the foundation of BCM by: - **Identifying** business-critical processes - **Determining** performance levels in normal and emergency operations - **Defining** maximum tolerable downtime (MTPD) - **Providing Transparency** on process dependencies #### BIA Methodology **Pre-Scoping:** - Hierarchical process identification via the Process Levels Pyramid - Data collection through interviews, workshops, or surveys - Documentation of process attributes and responsibilities **Damage Periods (Standardized):** - From ≤1 hour to ≤14 days - Provides a uniform evaluation basis for all business areas - Considers time-sensitive processes (e.g., annual closing, payroll) **MTPD Determination:** - Assigning damage criticality (1–4) to damage periods - Automated calculation via predefined formulas - Manual input for exceptional time-critical cases **Dependency Analysis:** - **Mandatory**: No alternatives available - **Existing but non-mandatory**: Replaceable within damage period - **No dependency**: Alternatives already in use during regular operations - Differentiates between internal and external dependencies #### Resource Analysis Examines the following resource categories: - **IT**: Servers, networks, applications - **Personnel**: Specialists, key competencies - **Buildings**: Locations, workplaces - **Services**: Deliveries, contracts, construction services - **Infrastructure**: Production resources, utilities ### Implementation with the fuentis Suite The fuentis Suite supports BCM through: **Process Management:** - Central capture and management of business processes - Automated BIA execution and evaluation - Dependency modeling and visualization **Crisis Management:** - Predefined alert chains and escalation paths - Mobile crisis team communication - Documentation and tracking of measures **Compliance and Reporting:** - Automated reports for management and authorities - Continuous monitoring of BCM KPIs - Preparation for ISO 22301 certification ### Best Practices for Successful BCM #### Organizational Anchoring - **Top Management Commitment**: Visible support from leadership - **Clear Responsibilities**: Defined roles and resources - **Regular Exercises**: Testing emergency plans and BAO structures #### Continuous Improvement - **Lessons Learned**: Systematic evaluation after each incident - **Regular BIA Updates**: Adjustments for organizational changes - **Stakeholder Integration**: Involvement of internal and external partners #### Technical Implementation - **Create Redundancies**: Backup systems and alternative sites - **Use Automation**: Reduce manual interventions in critical situations - **Testing and Monitoring**: Ongoing verification of BCM measures > **Practical Tip**: Start with a small pilot group of time-critical processes and gradually expand BCM coverage. This way, you gain valuable experience and can iteratively improve the system. ### Legal and Regulatory Aspects #### KRITIS Relevance - Special requirements for critical infrastructure operators - Mandatory incident reporting - Increased documentation and audit requirements #### ISO 22301 Certification - International recognition of BCM maturity - Requires continuous improvement - External audits and regular recertification #### Integration with ISMS - Alignment with ISO 27001 requirements - Joint risk analysis and treatment - Synergies in documentation and processes ### Key Takeaways at a Glance 1. **Step-by-Step Approach**: Use the BSI maturity model to implement BCM in stages – from Reactive BCMS to Development BCMS to Standard BCMS. 2. **Organizational Flexibility**: Establish a Special Organizational Structure (BAO) with clear decision-making powers for effective crisis response. 3. **Foundation in Business Impact Analysis**: Conduct a systematic BIA to identify time-critical processes and define maximum tolerable downtimes. 4. **Clear Terminology**: Distinguish precisely between disruptions, emergencies, and crises to activate appropriate responses. 5. **Continuous Improvement**: Treat BCM as a living process with exercises, lessons learned, and regular updates. ## Difference between ISO27001 and BSI IT-Grundschutz Source: https://servicehub.fuentis.com/en/wissen/difference-iso-grundschutz/ ### ISO 27001 vs. BSI IT-Grundschutz — **When to use what (and how to combine them)** > A practical, decision-oriented guide for ISO practitioners who want to look beyond their usual toolkit. Short, actionable, and built for momentum. --- ### TL;DR – Quick selector | Situation | Pick | Why | What you produce first | |---|---|---|---| | Global customers, mixed jurisdictions, fast proof needed | **ISO 27001** | Internationally recognized, lighter docs, flexible | Scope, risk method, Risk Register, SoA (Annex A), Objectives & KPIs | | German public sector, KRITIS, tenders expect BSI | **IT-Grundschutz** | Native to DE, prescriptive measures, strong acceptance | Struct. analysis, Schutzbedarf (CIA), Baustein-Modellierung, GS-Check | | Innovative/non-standard tech stack | **ISO 27001** (+ selected BSI controls) | Free to tailor controls to risks | ISO risk process + BSI hardening for the tricky parts | | Small/mid org, lean team, quick wins | **ISO 27001 (lean)** | Minimum viable ISMS possible | 90-day ISO starter (below) | | Mature ISO ISMS, needs concrete hardening | **ISO + Grundschutz** | Keep ISO cert; adopt BSI depth where it matters | Map assets → pick BSI Bausteine for high-risk areas | | You must show an actual “security level” | **Grundschutz** | Certification indicates achieved safeguarding level | GS-Check evidence + Maßnahmennachweise | --- ### Decision tree (fast) 1. **Is a German authority/KRITIS tender in scope?** → Yes: *Grundschutz or Hybrid* → Go to **Hybrid recipe**. → No: continue. 2. **Do you need an internationally recognized certificate quickly?** → Yes: *ISO first* → **ISO 90-day starter**. → No/unclear: continue. 3. **Is your IT mostly standard (Windows, AD, LAN, office apps)?** → Yes: *Grundschutz fits well*. → No (cloud-native, data platforms, OT/IoT mix): *ISO core + selected BSI Bausteine*. --- ### How they differ (only what matters in practice) - **ISO 27001** = *management system* + **risk-based** controls (Annex A). Certifies your **system**, not a fixed security level. - **Grundschutz** = *catalogue of concrete measures* (Bausteine) + **model-driven** coverage. Certification reflects a **safeguarding level**. Use ISO when you need **speed, flexibility, global recognition**. Use Grundschutz when you need **prescriptive depth and German public acceptance**. --- ### ISO 90-day starter (lean but cert-ready) **Goal:** Minimal viable ISMS that scales. **Deliverables (must-have):** Scope (§4.3), Context & stakeholders, Risk method & criteria, Risk Register, **SoA (Annex A:2022 93 controls)**, IS objectives + KPIs, Audit plan, Management review cadence. **Timeline:** - **Weeks 1–3:** Scope, roles/RACI, risk method; inventory top-20 assets/processes; quick CIA. - **Weeks 4–7:** Risk assessment workshops; pick controls; draft **SoA**; treatment plan with owners/dates. - **Weeks 8–10:** Implement top 10 high-impact controls (IDM, backup, vuln mgmt, incident flow, logging). - **Weeks 11–12:** Internal audit (sample), KPI baseline, Mgmt review #1; close gaps. > **Tip:** Borrow BSI depth *surgically*: use Bausteine for Windows/AD, networks, and backup hardening while staying ISO-centric. --- ### Grundschutz fast-track (for ISO folks) **What changes from ISO thinking?** - Start **structure → protection needs → modelling** before deep risk. - Controls come from **Bausteine** (with Basis/Standard/Hoch). - Do a **GS-Check** (Soll/Ist) to show safeguarding level. **Minimal path:** 1. **Strukturanalyse**: group assets into manageable TOGs (servers, clients, networks, apps, sites). 2. **Schutzbedarf (CIA)**: normal/high/very high; apply **inheritance** (process → app → system). 3. **Modellierung**: assign Bausteine to TOGs; record deviations. 4. **GS-Check**: close gaps; for “hoch” add **ergänzende Risikoanalyse**. 5. **Nachweise**: measures implemented, responsibilities, evidence. > **Tip:** Reuse your ISO risk register; tag items that map to Bausteine to avoid double work. --- ### Hybrid recipe (best of both) 1. **ISO as the frame**: scope, governance, risk method, SoA, KPIs, audits. 2. **BSI for depth**: assign Bausteine to high-impact TOGs (AD/Entra ID, servers, networks, backups, remote access). 3. **One register**: keep a single Risk & Control Register; each control is tagged `ISO-A.x` and/or `BSI-`. 4. **SoA + GS-Check**: run both artefacts from the same data: SoA for ISO; GS-Check for BSI stakeholders. 5. **Certification path**: certify ISO first for speed; add Grundschutz later where demanded. --- ### “When to use what” — by scenario - **Public administration / KRITIS:** **Grundschutz or Hybrid** (expect BSI language, Bausteine evidence). - **International group / suppliers abroad:** **ISO** (auditor availability, recognition in supply chains). - **Managed service providers (MSP/MSSP):** **ISO** baseline; **BSI** depth for AD, backups, and remote admin. - **Startups/scaleups:** **ISO** lean; adopt BSI hardening checklists for quick wins. - **OT/IoT environments:** **ISO** risk engine + **BSI** OT-related Bausteine for prescriptive controls. --- ### Picking controls pragmatically **ISO first?** - Build SoA with Annex A; mark *not applicable* with risk-based justifications. - Where your SoA is “thin”, import BSI measures (e.g., hardening checklists) to raise assurance. **Grundschutz first?** - Use Baustein requirements as your default control set. - Where BSI is silent/too generic (e.g., SaaS multi-tenant specifics), add ISO-style, risk-derived controls. --- ### Documentation you actually need (no fluff) | Area | ISO deliverable | BSI deliverable | Hybrid shortcut | |---|---|---|---| | Scope & context | Scope, stakeholder & issues | Geltungsbereich in Strukturmodell | One scope doc, two summaries | | Risk | Method, criteria, register, plan | Ergänzende Risikoanalyse (bei „hoch“) | One risk process; extra BSI section | | Controls | SoA (Annex A) | Baustein-Umsetzung & GS-Check | Unified register with cross-refs | | Evidence | KPIs, audits, mgmt review | Maßnahmennachweise, GS-Check Protokoll | Shared evidence library | --- ### Common pitfalls (and fixes) - **Pitfall:** ISO “paper ISMS” without real controls. **Fix:** Tie every top risk to a tested control + evidence; baseline KPIs early. - **Pitfall:** Grundschutz over-documentation stalls delivery. **Fix:** Group TOGs aggressively; prioritize GS-Check gaps by risk; iterate. - **Pitfall:** Two parallel worlds (ISO vs. BSI). **Fix:** Single taxonomy for assets, risks, controls; tags map to ISO/BSI. - **Pitfall:** SoA/GS-Check not kept current. **Fix:** Update on **every** change window; calendar reminders; owner per control. --- ### Migration playbooks **ISO → Grundschutz** 1. Map assets to TOGs; import ISO CIA → Schutzbedarf. 2. Assign Bausteine; run GS-Check; record deviations. 3. Keep ISO risk method; add BSI “hoch” analyses where needed. **Grundschutz → ISO** 1. Derive ISO scope from Geltungsbereich. 2. Convert GS risks into a **single risk register** with ISO criteria. 3. Build SoA from existing measures; justify N/A items; align KPIs & audits. --- ### KPIs that prove it works (both worlds) - Patch SLA met (%), Backup success (%), Incident MTTR, Access review closure time, Phishing fail rate, Log coverage (% of critical systems), Recovery test success. --- ### Tooling pattern (example) - **One inventory** (assets/TOGs), **one risk register**, **one control catalogue** with tags: `tags: ["ISO:A.5.15", "BSI:SYS.1.1.A5"]` - Reports: **ISO SoA** view, **BSI GS-Check** view, shared evidence links. --- ### One-page recommendations - If you need **speed + global trust** → **ISO**; sprinkle in BSI hardening where high risk. - If you need **German public acceptance + prescriptive depth** → **Grundschutz** or **Hybrid**. - Always keep **one** register (risks & controls) and **tag** for ISO/BSI to avoid duplication. ## Fundamentals of Information Security Source: https://servicehub.fuentis.com/en/wissen/grundlagen-informationssicherheit/ Information security is a complex discipline with a wide range of specific terms, methods, and standards. This knowledge page provides a central overview of key terminology from ISO 27001, BSI IT-Grundschutz, and ISMS management. It serves as a reference for consistent use of terms and as a quick orientation guide in daily security work. Consistent terminology is essential for effective communication between business units, IT, and management, as well as for the successful implementation of security measures. ### Core Concepts of Information Security #### The Three Core Values (Security Objectives) Information security is based on three fundamental objectives: - **Confidentiality**: Protection against unauthorized access to information - **Integrity**: Protection against unauthorized alteration of data and systems - **Availability**: Ensuring that information and services are available as required These core values form the CIA triangle and are central to all security standards. #### ISMS (Information Security Management System) An ISMS is the entirety of policies, processes, and measures used to systematically manage information security. It follows the continuous PDCA cycle (Plan-Do-Check-Act) and ensures: - A structured approach to security risks - Continuous improvement of the security posture - Demonstrable compliance with standards and requirements - Systematic monitoring and adjustment of measures #### IT-Grundschutz vs. ISO 27001 **IT-Grundschutz** is the approach developed by the German BSI to identify and implement appropriate security measures. It offers: - Modular building blocks with concrete implementation recommendations - Proven practice for typical IT environments - A foundation for ISO 27001 certification “based on IT-Grundschutz” **ISO 27001** defines the international requirements for an ISMS and is: - Risk-based and flexibly adaptable - An internationally recognized certification standard - A framework that can be complemented by concrete methodologies such as IT-Grundschutz ### Determining Protection Needs and Risk Analysis #### Methodical Approach Determining protection needs is carried out systematically: 1. **Process Analysis**: Identify business-critical processes 2. **Damage Scenarios**: Assess potential impacts if security objectives are violated 3. **Categorization**: Classify as “normal,” “high,” or “very high” 4. **Inheritance**: Transfer protection requirements to dependent systems and components #### Inheritance Principles - **Maximum Principle**: The highest level of protection need determines the overall requirement - **Cumulative Effect**: Protection needs increase due to combined damages in multiple processing steps - **Distribution Effect**: Reduction of protection needs by distributing across multiple systems **Pro Tip**: Document inheritance transparently and traceably. This greatly simplifies later audits and adjustments. ### ISMS in Practice #### Phases of ISMS Implementation 1. **Structural Analysis**: Document the information network 2. **Determination of Protection Needs**: Assess criticality 3. **Modeling**: Map building blocks to target objects 4. **Baseline Security Check**: Compare actual vs. required measures 5. **Risk Analysis**: Assess additional risks 6. **Implementation of Measures**: Apply required controls #### Modeling and Building Blocks Modeling assigns IT-Grundschutz building blocks to identified target objects. Each block contains: - **Description**: Purpose and scope - **Threat Landscape**: Relevant threats - **Requirements**: Concrete security measures - **Additional Information**: Implementation guidance #### Security Approaches - **Basic Security**: Broad initial coverage across all processes as a starting point - **Core Security**: Focus on particularly exposed processes and assets - **Standard Security**: Classic, comprehensive BSI approach ### Implementation Support and Best Practices #### Consistent Terminology - Use “information network” in IT-Grundschutz contexts - Use “scope” in ISO/international contexts - Distinguish clearly between “data protection” (personal data) and “data security” (technical protection) #### Role Clarification Define clear responsibilities: - **ISB/CISO**: Strategic leadership of the ISMS - **Risk Owner**: Responsibility for specific risks - **Asset Owner**: Responsibility for protecting specific assets - **Governance Group**: Strategic decisions and policies **Pro Tip**: Use RACI matrices for clear role assignment (Responsible, Accountable, Consulted, Informed). #### Documentation and Evidence - Keep all evidence documents version-controlled and immutable - Document decisions and their rationale - Ensure that audit trails are verifiable #### Continuous Improvement - Evaluate security concepts at least every 2 years - Provide an updated ISMS version at least every 3 years - Conduct regular internal audits **Pro Tip**: Use the catalog features of the fuentis Suite for consistent application of IT-Grundschutz building blocks and automated compliance checks. ### Key Takeaways at a Glance 1. **Consistent terminology is fundamental** for successful information security and effective communication within the ISMS. 2. **The three core values – confidentiality, integrity, and availability** – form the foundation of all security measures and standards. 3. **IT-Grundschutz and ISO 27001 complement each other**: IT-Grundschutz provides proven practice, ISO 27001 offers the international certification framework. 4. **Structured phases from structural analysis to continuous improvement** ensure systematic ISMS implementation and sustainable security. 5. **Clear roles, consistent documentation, and regular reviews** are key success factors for effective information security in practice. ## ISMS Implementation – Systematic Development of an Information Security Management System Source: https://servicehub.fuentis.com/en/wissen/isms-implementierung-systematischer-aufbau/ Implementing an **Information Security Management System (ISMS)** according to ISO 27001 is a systematic approach to protecting an organization's most valuable resource: information. An ISMS provides not just technical solutions, but establishes a comprehensive governance structure for information security that minimizes risks, ensures compliance, and strengthens trust with customers and partners. The structured development of an ISMS follows proven methods and standards such as ISO 27001, BSI IT-Grundschutz, and TISAX. The focus is not only on technical aspects, but especially on organizational processes, stakeholder engagement, and continuous improvement of the security posture. > **Practical Tip**: A successful ISMS requires strong management commitment and a systematic approach. Implementation should be done in phases to avoid overwhelm and ensure sustainable success. ### Core Concepts and Requirements #### Phase Model for ISMS Implementation ISMS implementation follows a structured **four-phase model** based on the proven PDCA cycle (Plan-Do-Check-Act): ##### Phase 1: Initialization **Core Activities:** - Kick-off meeting with all relevant stakeholders - Compilation of relevant documents and resources - Creation of comprehensive stakeholder list - Definition of ISMS scope and security policy - Establishment of governance structures and responsibilities - Development of project charter and project plan **Important Document Foundations:** - Existing process descriptions and IT security policies - Current certifications (ISO 9001/27001, TISAX, BSI IT-Grundschutz) - Data protection concepts and TOM documentation (GDPR) - IT operational documentation and system landscapes - Service provider contracts and SLAs - Emergency handbooks and recovery plans ##### Phase 2: Planning (Plan) **Systematic Analysis and Assessment:** - **Structural Analysis**: Capture of IT landscape and assets - **Protection Needs Assessment**: Evaluation of business process criticality - **Business Impact Analysis (BIA)**: Determination of security incident impacts - **Risk Analysis**: Systematic identification and assessment of risks - **Gap Analysis**: Comparison between current and target state **Key Results:** - Risk register with assessed threat scenarios - Statement of Applicability (SoA) - Action plan with prioritized security controls - ISMS roadmap with timelines and milestones - IT security maturity assessment ##### Phase 3: Implementation (Do) **Measure Implementation:** - Implementation of identified security measures - Revision and introduction of security policies - Conducting training and awareness campaigns - Operationalization of processes - Integration into existing organizational structures - Conducting tests and proof-of-concepts ##### Phase 4: Completion and Handover **Finalization and Sustainability:** - Acceptance of all project artifacts - Handover to operational organization - Conducting lessons-learned sessions - Establishment of continuous improvement processes #### Critical Success Factors ##### Stakeholder Management An ISMS requires active involvement of all relevant actors. Stakeholder management follows a **structured maturity model**: 1. **Awareness**: Stakeholders know the project and their role 2. **Understanding**: Understanding benefits and challenges 3. **Acceptance**: Reduction of internal resistance 4. **Adoption**: Active engagement for project goals 5. **Responsibility**: Proactive commitment to project success **Systematic Stakeholder Engagement:** - **Phase 1 – Identification**: Capture and grouping of all stakeholders - **Phase 2 – Classification**: Classification by influence and interest - **Phase 3 – Communication**: Development of targeted communication strategies ##### Process-Based Approach The ISMS builds on **six core processes** that are systematically developed and implemented: #### 1. Risk Analysis and Assessment **Structured Approach:** **Prerequisites:** - List of critical business processes - Determined damage criticality - Involvement of decision makers and process owners - Definition of risk tolerance limits **Threat Categories:** - Elementary hazards (natural disasters, environmental influences) - Force majeure (unforeseeable events) - Organizational deficiencies (process weaknesses, missing controls) - Human errors (operational errors, negligence) - Technical failure (hardware/software failures) - Deliberate actions (cyber attacks, sabotage) **Assessment Methodology:** - Determination of damage extent and probability of occurrence - Assessment of vulnerability exploitability - Implementation through interviews and workshops - Involvement of process owners and risk management #### 2. Process Capture and Documentation **Systematic Approach:** **Preparation Phase:** - Review of existing documents (security concepts, organizational charts) - Adaptation of documentation templates to company language - Scheduling and coordination with stakeholders **Implementation Phase:** - Structured interviews with process owners - Joint completion of process profiles - Respectful and collaborative communication - Focus on current state without evaluation **Post-processing:** - Quality assurance of captured information - Clarification of open questions with contacts - Finalization and handover to project management #### 3. Training and Awareness Planning **Success Factors for Sustainable Learning:** **Clear Goal Definition:** - Conveying fundamental IS and data protection knowledge - Promoting active participation and awareness - Developing methodological and technical skills - Deriving measures from IS objectives **Target Group-Specific Approach:** - Homogeneous grouping by professional tasks - Needs assessment through interviews and analyses - Modular structure of training programs - Consideration of different learning styles **Method Diversity:** - **Face-to-Face Training**: Direct interaction and group dynamics - **E-Learning**: Flexibility in time and location - **Blended Learning**: Combination of different approaches - **Awareness Campaigns**: Continuous sensitization **Sustainability:** - Regular content updates - Management level involvement - Evaluation and continuous improvement - Integration into onboarding processes #### 4. Data Backup and Business Continuity **Comprehensive Backup Strategy:** **Responsibility Matrix:** - **Overall Responsibility**: Management - **Data Storage**: IT users/data owners - **Backup Execution**: Administrators - **Recovery Decisions**: Tiered authorities - **Testing and Review**: Information Security Officer **Multi-Level Backup Concept:** - **Short-term Backup**: Daily backups on disk storage (30 days) - **Long-term Backup**: Weekly tape backup - Weekly backups: 4 weeks retention - Monthly backups: 12 months retention - Annual backups: 5 years retention **Recovery Testing:** - Daily recovery of individual files - Quarterly test recovery in test environment - Documentation and evaluation of test results - Integration into emergency management exercises #### 5. Measure Prioritization **Strategic Approach:** **Measure Categorization:** 1. **ISMS Process Measures**: Establishment of systematic security processes 2. **Operational Security Measures**: Concrete technical and organizational protective measures **Prioritization Criteria:** - **Resource Availability**: Immediate implementation vs. resource procurement - **Security Gain**: Benefit-effort ratio of measures - **Measure Category**: - Organizational measures (highest priority) - Technical measures (medium priority) - Structural measures (most complex implementation) **Maturity-Oriented Implementation:** - Determination of target maturity for ISMS processes - Consideration of process dependencies - Minimization of operational effort with maximum goal achievement #### 6. Security Requirements Management **Systematic Document Management:** **Lifecycle Management:** - **Development**: Creation of new security requirements - **Approval**: Structured approval process - **Rollout**: Communication and training - **Maintenance**: Version control and change management - **Archiving**: Controlled retention and deletion **Continuous Improvement:** - Regular effectiveness reviews - Integration of feedback from audits and incidents - Adaptation to changing threat landscape - Metrics for measuring document quality ### Implementation Guidelines and Best Practices #### Success Factors for ISMS Implementation **Ensure Management Commitment:** - Early involvement of management in conception and implementation - Clear communication of benefits and necessity - Provision of sufficient resources and budget - Regular success measurement and reporting **Choose Pragmatic Approach:** - Start with realistic scope and gradual expansion - Focus on critical business processes and assets - Use existing structures and processes - Avoid over-engineering and excessive maturity levels **Actively Engage Stakeholders:** - Regular communication and feedback rounds - Training and awareness measures - Consideration of professional expertise - Creation of ownership and accountability > **Practical Tip**: Start with a "Minimal Viable ISMS" and build systematically. This reduces complexity and overwhelm while achieving quick wins. #### Integration into Existing Management Systems **Synergy with Other Standards:** - **ISO 9001**: Shared use of documentation processes - **ISO 14001**: Overlaps in risk management and audits - **TISAX**: Special requirements of automotive industry - **GDPR**: Integrated consideration of data protection and security **Efficient Multi-Standard Approaches:** - Establish common governance structures - Integrated audit planning and execution - Harmonized documentation and reporting systems - Cross-cutting training and awareness programs ### Support Through the fuentis Suite The **fuentis Suite** provides comprehensive support for all phases of ISMS implementation: #### Available Functions **Risk and Measure Management:** - Creation and management of risk methodologies (matrix-based) - Structured risk assessment with automatic calculations - Risk Treatment Plan (RTP) with status tracking - Assignment of ISO 27001 controls to identified risks - Automated reports on RTP and SoA **Asset Management:** - Central creation and management of asset inventory - Categorization by protection needs and criticality - Linking with risks and security measures - Lifecycle management for IT assets **Compliance Management:** - Conducting structured gap analyses - Automated creation of Statement of Applicability - Mapping to various standards (ISO 27001, BSI IT-Grundschutz, TISAX) - Collection and management of compliance evidence **Monitoring and Dashboards:** - Real-time monitoring of controls and measures - Task management with deadline and responsibility tracking - Risk dashboards with graphical evaluations - Incident management and tracking #### Planned Extensions The fuentis Suite is continuously extended with additional ISMS-relevant functions: **Scope and Initiation Management:** - Digital support for scope definition - ISMS profile selection and standard mapping - Stakeholder management and communication planning - Project dashboards for ISMS implementation **Policy Management:** - Central creation and management of security policies - Approval workflows and version control - Automatic distribution and training verification - Effectiveness review and update cycles **Audit Management:** - Planning and conducting internal ISMS audits - Audit checklists and questionnaires - Findings management and corrective action tracking - Audit reports and management reviews **Extended Evidence Management:** - Incident management with categorization and escalation - Supplier assessment and supply chain risks - Incident response workflows - Automated reporting for regulators and auditors > **Practical Tip**: Use the fuentis Suite already in the planning phase to work structurally from the beginning. Asset management and risk assessment create a solid foundation for all further ISMS activities. ### Position in the Compliance Landscape #### Standard Reference and Standards **ISO 27001 as Framework:** - International recognition and certification possibility - Clear requirements for management systems - Integration with other ISO standards - Regular updates and development **BSI IT-Grundschutz Integration:** - Detailed building block library for concrete implementation - Officially recognized methodology in Germany - Modular structure enables step-by-step implementation - Connection between strategic planning and operational implementation **Industry-Specific Extensions:** - **TISAX**: Automotive-specific requirements - **KRITIS**: Special obligations for critical infrastructures - **Cloud Security**: Complementary standards like CSA STAR - **Financial Sector**: Integration of MaRisk and other financial regulations #### Legal and Regulatory Requirements **GDPR Compliance:** - Technical and organizational measures (TOM) - Documentation obligations and evidence management - Data Protection Impact Assessments (DPIA) - Integration into ISMS risk management **Additional Compliance Requirements:** - **NIS-2 Directive**: Extended security requirements - **Cyber Resilience Act**: Product security and lifecycle management - **EU Taxonomy**: Sustainability aspects of IT security - **Sector-Specific Regulation**: Depending on industry and field of activity #### Glossary **ISMS**: Information Security Management System – systematic approach to managing information security in an organization. **SoA**: Statement of Applicability – document indicating which security controls have been selected and implemented. **RTP**: Risk Treatment Plan – documented strategy for treating identified risks. **BIA**: Business Impact Analysis – assessment of the impact of operational disruptions on critical business processes. **Gap Analysis**: Systematic comparison between current state and desired target state of security measures. **Stakeholder**: All persons or groups affected by or having influence on ISMS implementation. **PDCA Cycle**: Plan-Do-Check-Act – continuous improvement process for management systems. ### Key Takeaways at a Glance 1. **Structured Phase Approach**: ISMS implementation follows a proven four-phase model (Initialization, Planning, Implementation, Completion) that systematically leads from scope definition to operational introduction. 2. **Stakeholder Management as Success Factor**: Active involvement of all relevant actors through a structured maturity model (Awareness, Understanding, Acceptance, Adoption, Responsibility) is crucial for sustainable ISMS success. 3. **Six Core Processes as Foundation**: Risk analysis, process capture, training planning, data backup, measure prioritization, and security requirements management form the operational backbone of a functional ISMS. 4. **Pragmatic Implementation over Perfection**: A "Minimal Viable ISMS" with realistic scope and appropriate maturity is more successful than perfectionist approaches that lead to complexity and overwhelm. 5. **Tool-Supported Efficiency**: The fuentis Suite automates essential ISMS processes from risk assessment to asset management and creates the foundation for sustainable and efficient security management. ## ISMS Knowledge Source: https://servicehub.fuentis.com/en/wissen/isms-wissen/ Welcome to the Knowledge section of the fuentis Suite. Here you'll find comprehensive information, guides, and best practices covering all aspects of information security management according to current standards and frameworks. ### What You'll Find Here Our knowledge collection covers all important aspects of information security management - from basic concepts to specialized implementation guidance. The content is practice-oriented and shows you how to achieve compliance efficiently and sustainably with the fuentis Suite. #### Available Topic Areas **ISO 27001 - The International ISMS Standard** - Fundamentals and overview of ISO 27001:2022 - Step-by-step implementation guidance - Audit preparation and execution - Practical certification tips **IT-Grundschutz - The BSI Framework** - Introduction to IT-Grundschutz Compendium - Understanding modules and threats - Implementation in the fuentis Suite **Additional Standards and Frameworks** - SOC 2 Compliance - NIST Framework - TISAX Automotive Standard - Industry-specific requirements **Compliance and Governance** - Data Protection (GDPR) - NIS2 Directive - Regulatory Compliance - GRC Approaches (Governance, Risk & Compliance) **Practical Implementation** - Risk management and analysis - Emergency management and Business Continuity - Awareness programs - Incident Response - Continuous Monitoring **Tools and Automation** - Optimizing fuentis Suite functionality - Workflow automation - Reporting and dashboards - Integration with existing systems ### Structure of Knowledge Content Each knowledge page follows a consistent structure for optimal readability: - **Brief Introduction**: What is it about and why is it relevant? - **Key Concepts**: The most important requirements and principles - **Practical Tips**: Concrete implementation guidance and best practices - **fuentis Suite Integration**: How the software supports implementation - **Additional Resources**: Links, templates, and references - **Key Takeaways**: The most important points at a glance ### Who Is This Knowledge Collection For? - **CISO and Security Managers**: Strategic guidance and management perspective - **Compliance Officers**: Regulatory requirements and audit preparation - **IT Managers**: Technical implementation and operational aspects - **Risk Managers**: Risk assessment and treatment - **Project Managers**: Implementation planning and change management - **Auditors**: Audit-relevant aspects and evidence management ### Updates and Quality Our knowledge content is continuously updated to incorporate the latest developments, standard updates, and regulatory changes. All content undergoes a quality assurance process and is reviewed by subject matter experts. ### Feedback and Improvements We continuously work to improve our knowledge collection. Do you have suggestions, requests for additions, or feedback on specific content? Please contact us - your input helps us make our resources even more practical and helpful. **Navigation:** Use the search function or browse through categories to find relevant content. Each page contains references to related topics and practical application examples in the fuentis Suite. ## ISMS Responsibilities Source: https://servicehub.fuentis.com/en/wissen/verantwortlichkeiten-im-isms/ ### Overview A functioning Information Security Management System (ISMS) requires clearly defined roles and responsibilities. The requirements differ depending on the applicable standard: * **ISO 27001** and **BSI IT-Grundschutz**: Basic ISMS roles * **NIS2 Directive**: Additional obligations, especially for executive management --- ### Mandatory Roles According to ISO 27001 & BSI IT-Grundschutz These roles are __mandatory__ for every ISMS: #### 1. Executive Management / Senior Leadership **Responsibilities:** * Overall responsibility for information security * Approval of the Information Security Policy * Provision of resources (budget, personnel, time) * Appointment of the Information Security Officer * Annual management review **Reference:** * ISO 27001: Clause 5.1 (Leadership and commitment) * BSI IT-Grundschutz: ORP.1.A1 --- #### 2. Information Security Officer (ISO) **Responsibilities:** * Central coordination of the ISMS * Advisory to executive management on security matters * Creation and maintenance of security documentation * Monitoring implementation of security measures * Point of contact for all security questions **Reference:** * ISO 27001: Clause 5.3 * BSI IT-Grundschutz: ORP.1.A15 **Typical Time Investment:** 20-50% of full-time position (depending on organization size) --- #### 3. IT Management / IT Operations **Responsibilities:** * Technical implementation of security measures * Configuration and operation of IT systems * Patch management and updates * Incident response (technical level) * Backup and recovery **Reference:** * ISO 27001: Clause 8 (Operation) * BSI IT-Grundschutz: OPS.1.1.2 --- #### 4. Asset Owner **Responsibilities:** * Responsibility for specific information assets * Classification of protection requirements * Approval of access rights * Monitoring proper use **Examples:** Head of Finance (owner of financial data), Production Manager (owner of control systems) **Reference:** * ISO 27001: Annex A.5.9 (Inventory of information and other associated assets) * BSI IT-Grundschutz: ORP.4 --- #### 5. Process Owner **Responsibilities:** * Responsibility for the security of a business process * Integration of security requirements into the process * Business Impact Analysis (BIA) for the process * Approval of process-specific security measures **Examples:** Sales Manager (owner of sales process), Production Manager (owner of production process) **Reference:** * ISO 27001: Clause 6.1.2 (Information security risk assessment) * BSI IT-Grundschutz: ORP.1 --- #### 6. Data Protection Officer (DPO) **Special Note:** Mandatory for public authorities and certain private organizations under GDPR Art. 37 **Responsibilities:** * Monitoring GDPR compliance * Advisory on data protection matters * Training and awareness * Point of contact for supervisory authorities **Reference:** * GDPR: Art. 37-39 * ISO 27001: Annex A.5.2 (Information security roles and responsibilities) --- ### Additional Mandatory Roles for NIS2 The __NIS2 Directive__ imposes additional requirements on affected organizations (essential and important entities): #### Extended Obligations for Executive Management **New under NIS2:** * ⚠️ **Personal liability** for violations (Art. 20 Para. 2) * ✅ **Mandatory training** on cybersecurity (proof required!) * ✅ **Active oversight** of risk management measures * ✅ **Documented responsibility** (non-delegable!) > __Important:__ Fines up to 10 million euros or 2% of global annual revenue possible! --- #### Incident Response Team **Why Mandatory for NIS2:** * Reporting obligations to authorities (early warning: 24h, notification: 72h) * Coordinated response to security incidents required **Responsibilities:** * Detection and assessment of security incidents * Immediate containment measures * Notification to competent authority (CERT/CSIRT) * Forensics and root cause analysis * Documentation and lessons learned **Reference:** * NIS2: Art. 23 (Reporting obligations) * BSI IT-Grundschutz: DER.2.1 --- #### Supplier Manager (Supply Chain Security) **Why Mandatory for NIS2:** * Art. 21 Para. 2 (e) explicitly requires "security in supply chains" **Responsibilities:** * Identification of critical suppliers * Risk assessment of suppliers * Security requirements in contracts * Monitoring supplier compliance * Incident management for supplier incidents **Reference:** * NIS2: Art. 21 Para. 2 (e) * ISO 27001: Annex A.5.19 (Information security in supplier relationships) --- ### Best Practice Roles (Optional, Recommended for Larger Organizations) These roles are not mandatory but **strongly recommended**, especially for: * More than 100 employees * Complex IT landscapes * Regulated industries (finance, healthcare, energy) --- #### Business Continuity Manager (BCM) **Recommended because:** * NIS2 requires "measures to ensure business continuity" * ISO 27001 Annex A.5.29 (Information security during disruption) **Responsibilities:** * Business Impact Analysis (BIA) * Creation of Business Continuity Plans (BCP) * Disaster Recovery Planning (DRP) * Emergency drills and tests * Recovery planning after incidents **Typical Time Investment:** 20-50% of full-time position --- #### Human Resources (HR Security) **Recommended because:** * Employees are the greatest security risk * On-/offboarding processes critical for security **Responsibilities:** * Security-relevant clauses in employment contracts * Coordination of background checks (where permissible) * Onboarding: training, confidentiality agreements * Offboarding: revoke access rights, return of assets * Disciplinary measures for security violations **Reference:** * ISO 27001: Annex A.6.1-6.4 (People controls) * BSI IT-Grundschutz: ORP.2 --- #### Compliance Officer **Recommended because:** * Overlapping requirements (GDPR, NIS2, industry standards) * Central coordination prevents duplication of effort **Responsibilities:** * Overview of all compliance requirements * Coordination between DPO, ISO, executive management * Risk management (cross-functional) * Audit management and follow-up * Reporting to executive management **Typical Time Investment:** 30-100% of full-time position --- #### Change Advisory Board (CAB) **Recommended because:** * Changes are a frequent cause of security incidents * Structured change management reduces risks **Responsibilities:** * Assessment of changes regarding security risks * Approval or rejection of changes * Prioritization of changes * Post-implementation review **Members:** IT Management, ISO, affected business units **Reference:** * ISO 27001: Annex A.8.32 (Change management) * BSI IT-Grundschutz: OPS.1.2.1 --- #### Security Awareness Coordinator **Recommended because:** * NIS2 requires "training in cybersecurity hygiene" * Employee awareness is the most cost-effective security measure **Responsibilities:** * Planning and execution of awareness campaigns * Creation of training materials * Phishing simulations * Measuring awareness (e.g., click rates in phishing tests) * Reporting to ISO and executive management **Typical Time Investment:** 10-30% of full-time position **Reference:** * ISO 27001: Annex A.6.3 (Information security awareness, education and training) * BSI IT-Grundschutz: ORP.3 --- #### Internal Audit **Recommended because:** * ISO 27001 requires internal audits (Clause 9.2) * Independent control increases ISMS quality **Responsibilities:** * Planning and conducting internal ISMS audits * Identification of nonconformities * Follow-up on corrective actions * Preparation for external certification audits **Special Note:** Must be independent (cannot audit own work!) **Reference:** * ISO 27001: Clause 9.2 (Internal audit) * BSI IT-Grundschutz: ORP.5 --- ### Summary by Organization Size #### Small Organizations (< 50 employees) **Minimum:** * ✅ Executive Management * ✅ ISO (20-30%, possibly external) * ✅ IT Operations (can be combined with ISO if external control exists) * ✅ Asset/Process Owner (executive management + department heads) **Additionally for NIS2:** * ✅ Incident Response (can be ISO + IT Operations) * ✅ Supplier Manager (can be ISO) --- #### Medium-Sized Organizations (50-250 employees) **In addition to above:** * ✅ Dedicated ISO (50-100%) * ✅ Clear separation IT Operations ↔ ISO * ✅ HR Security (part of HR department) * ✅ BCM Manager (20-50%, can be ISO) --- #### Large Organizations (> 250 employees) **In addition to above:** * ✅ CISO (full-time) * ✅ Security team (multiple people) * ✅ Compliance Officer (full-time) * ✅ Dedicated Incident Response Team * ✅ Internal Audit * ✅ Security Awareness Coordinator --- ### Avoid Common Mistakes ❌ **"IT handles it"** → Information security is a cross-functional task, not just an IT topic! ❌ **"The ISO does everything alone"** → ISO coordinates, responsibility lies with asset/process owners ❌ **"No time for ISMS tasks"** → Plan realistic time budgets (otherwise it won't work) ❌ **"Roles assigned only verbally"** → Must be documented in writing! ❌ **"For NIS2, appointing an ISO is enough"** → No! Executive management has personal training and oversight obligations --- ### Next Steps 1. **Check your NIS2 status** → Are you affected? 2. **Assign roles** → Which roles do you need? Who takes them on? 3. **Document** → Create a "Roles & Responsibilities" document 4. **Train** → Especially executive management (mandatory for NIS2!) 5. **Provide resources** → Set realistic time budgets 6. **Review regularly** → At least annually --- ## IT Baseline Protection - Systematic Information Security Source: https://servicehub.fuentis.com/en/wissen/it-grundschutz-leitfaden/ IT Baseline Protection (IT-Grundschutz) from the German Federal Office for Information Security (BSI) is a proven methodology for the systematic protection of information and IT systems. It provides a structured approach for organizations of all sizes to implement information security efficiently and comprehensibly. ### What is IT Baseline Protection and Why is it Relevant? IT Baseline Protection is a holistic approach to information security based on the building block principle. Unlike purely risk-based approaches, it offers predefined security measures for typical IT components and business processes. This makes it particularly attractive for organizations that want to create a solid security foundation without conducting extensive individual risk analyses for each area. #### Why Implement IT Baseline Protection? **Practical Benefits:** - Structured, proven approach with concrete measure recommendations - Reduction of analysis effort through predefined building blocks - Combinable with other standards like ISO 27001 - Comprehensive BSI support and free resources - Particularly suitable for German organizations and legal requirements **Compliance Benefits:** - Fulfillment of legal requirements (e.g., KRITIS, NIS2) - Evidence of appropriate technical and organizational measures - Foundation for IT security certifications - Trust with business partners and authorities ### Core Concepts of IT Baseline Protection #### The Building Block Principle IT Baseline Protection works with modular **building blocks** that cover typical IT components, applications, and business processes. Each building block contains: - **Description** of the scope of application - **Threats** and their impacts - **Requirements** for risk minimization - **Additional information** for practical implementation **Building Block Categories:** - **ISMS Building Blocks:** Information Security Management System - **ORP Building Blocks:** Organization and Personnel - **CON Building Blocks:** Concepts and Procedures - **OPS Building Blocks:** Operations - **DER Building Blocks:** Detection and Response - **SYS Building Blocks:** IT Systems - **APP Building Blocks:** Applications - **NET Building Blocks:** Networks and Communication - **INF Building Blocks:** Infrastructure - **IND Building Blocks:** Industrial IT #### Protection Requirements Assessment The **protection requirements assessment** determines how much protection information and IT systems need. It distinguishes three protection requirement categories: - **Normal:** Damage effects are limited and manageable - **High:** Damage effects can be considerable - **Very High:** Damage effects can reach an existentially threatening extent The assessment is conducted for the three basic values of information security: - **Confidentiality:** Protection against unauthorized disclosure - **Integrity:** Protection against unauthorized modification - **Availability:** Ensuring accessibility and usability #### Modeling In **modeling**, the organization's IT landscape is systematically captured and assigned to corresponding IT Baseline Protection building blocks. This process includes: - **Structural analysis:** Recording business processes, applications, and IT systems - **Protection requirements assessment:** Evaluating protection needs - **Selection and adaptation of building blocks:** Assignment of relevant IT Baseline Protection building blocks - **Creating the information network:** Overall picture of assets to be protected ### Approach to IT Baseline Protection Implementation #### Phase 1: Initiation and Preparation **Secure Management Commitment** - Executive support for IT Baseline Protection project - Appointment of an IT Security Officer - Definition of goals and resources **Build ISMS** - Development of a security policy - Establishment of organizational structure for information security - Implementation of security processes #### Phase 2: Structural Analysis and Protection Requirements Assessment **Conduct Structural Analysis** - Recording all business processes - Identification of applications and IT systems - Documentation of network architecture - Survey of premises and personnel **Determine Protection Requirements** - Assessment of critical business processes - Classification of information - Determination of protection requirements for IT systems - Documentation of assessment results #### Phase 3: Modeling **Select Building Blocks** - Assignment of relevant IT Baseline Protection building blocks - Consideration of determined protection requirements - Adaptation to organization-specific circumstances **Compile Requirements** - Compilation of all relevant requirements - Prioritization according to protection requirements - Creation of a measure catalog #### Phase 4: IT Baseline Protection Check The **IT Baseline Protection Check** is the systematic review of security measure implementation: **Preparation** - Review of prerequisites (structural analysis, modeling) - Identification of appropriate contact persons - Scheduling and coordination - Review of existing documentation **Execution** - Systematic target-actual comparison through interviews - Document review and evidence verification - Assessment of implementation level per requirement - Identification of weaknesses and gaps **Follow-up** - Analysis of audit results - Creation of action recommendations - Definition of action plans - Documentation of lessons learned ### Target-Actual Comparison: Systematic Assessment of Measure Implementation #### Assessment Criteria For each IT Baseline Protection requirement, the implementation level is systematically assessed: | Implementation Level | Meaning | Criteria | |---|---|---| | **Yes** | Fully implemented | All measure objectives fulfilled, effective and appropriate | | **Partially** | Partially implemented | Some aspects missing or incomplete | | **No** | Not implemented | Measure objectives are not fulfilled | | **Not Required** | Not necessary | Higher-value controls or irrelevance | #### Documentation and Traceability **Structured Recording** - Use of uniform assessment criteria - Documentation of justifications for each assessment - Referencing relevant evidence documents - Ensuring traceability for third parties **Continuous Updates** - Central documentation to avoid redundancies - Regular review and updates - Integration into existing compliance processes ### Special IT Baseline Protection Approaches #### WIBA - Path to Basic Protection **Target Group:** Small and medium enterprises, associations, municipalities **Features:** - Simplified entry into IT Baseline Protection - Pragmatic path to basic protection level - Reduced initial effort - Step-by-step approach with limited resources #### IT Baseline Protection Profiles **Use Cases:** - Pre-configured building block selection for specific organization types - Use in schools, municipalities, or special scenarios - Basis for rapid implementation in standard environments #### B3S - Sector-Specific Security Standards **Relevance for KRITIS:** - Fulfillment of requirements according to § 8a BSIG - Sector-specific design of IT security - BSI recognition as evidence of appropriate security - Sector-specific implementation for critical infrastructures #### C5 - Cloud Computing Compliance **Scope of Application:** - Audit standard for professional cloud services - Increased transparency and auditability - Consideration of German legal frameworks - Integration with ISO/IEC 27001 ### Best Practices for IT Baseline Protection Implementation #### Organizational Success Factors **Practice Tip: Structured Approach** - Start with basic protection of important systems - Use existing documentation and processes - Implement step by step instead of everything at once - Involve specialist departments early **Change Management** - Employee awareness for information security - Training on new processes and requirements - Communication of benefits and necessity - Building a security culture #### Efficient Implementation **Resource Optimization** - Use of BSI tools and templates - Automation of recurring audit processes - Integration into existing management systems - Bundling of measures by responsibilities **Quality Assurance** - Regular internal audits - Continuous monitoring of measure effectiveness - Adaptation to technological developments - Lessons learned from practical implementation ### Support Through the fuentis Suite The fuentis Suite provides comprehensive support for IT Baseline Protection implementation: #### IT Baseline Protection Module - Pre-configured BSI building blocks and requirements - Automated modeling of IT landscapes - Structured protection requirements assessment - Support in building block selection #### Compliance Management - Target-actual comparison with automated assessment - Progress tracking and dashboard visualization - Integration with other standards (ISO 27001, TISAX) - Measure planning and tracking #### Audit and Review Functions - IT Baseline Protection Check support - Interview management and scheduling - Structured documentation of audit results - Automated report generation #### Asset and Risk Management - Central management of information network - Linking assets with IT Baseline Protection building blocks - Risk register for supplementary security analyses - Change management for IT landscape changes ### Integration with Other Standards IT Baseline Protection can be effectively combined with other security standards: **ISO 27001** - IT Baseline Protection as basic protection, ISO 27001 for risk management - Common ISMS structure and management processes - Combined audit strategies - Efficient resource utilization **TISAX** - IT Baseline Protection as foundation for automotive-specific requirements - Supplementation with industry-specific controls - Shared evidence collection **Data Protection (GDPR)** - Overlaps in technical and organizational measures - Common documentation and evidence obligations - Integrated incident response processes ### Continuous Improvement and Monitoring #### Regular Review **Monitoring Cycles** - Quarterly review of critical measures - Annual complete IT Baseline Protection Check - Event-based adjustments for changes - Integration into management review processes **Metrics and KPIs** - Implementation level of IT Baseline Protection requirements - Number and severity of identified vulnerabilities - Time to remediation of security gaps - Maturity level of information security management #### Adaptation to Changes **Technological Developments** - Integration of new IT systems and applications - Consideration of cloud computing and digitalization - Adaptation to new threat scenarios - Updates of the IT Baseline Protection Compendium **Organizational Changes** - Adaptation for business process changes - Integration of acquisitions or spin-offs - Consideration of regulatory changes - Development of security organization ### Key Takeaways at a Glance **The 5 Most Important Success Factors for IT Baseline Protection:** 1. **Systematic Approach**: Structural analysis, protection requirements assessment, and modeling form the foundation for effective IT Baseline Protection implementation 2. **Building Block-Oriented Implementation**: The modular structure enables pragmatic and comprehensible protection without extensive individual risk analyses 3. **Continuous Target-Actual Comparison**: Regular IT Baseline Protection Checks identify vulnerabilities and ensure measure effectiveness 4. **Integration into Existing Processes**: IT Baseline Protection works best as part of holistic information security management 5. **Use Practical Implementation Aids**: BSI resources, profiles, and modern ISMS tools like the fuentis Suite significantly accelerate implementation **Why IT Baseline Protection is More Than Just Compliance:** IT Baseline Protection offers a proven, practice-tested path to systematic information security. It combines German thoroughness with international standards compatibility and enables organizations not just to "have" security, but to live it and continuously improve it. # Release Notes ## Release Notes fuentis Suite 4 - Trust Plattform Source: https://servicehub.fuentis.com/en/release-notes/fuentis-suite-4-release-notes-oct-2025/ _Last updated: 12 October 2025 · Version: 4.0 · Status: Production_ fuentis Suite 4.0 - trust platform focuses on real-world usability gains and core GRC workflows. This release ships a refreshed UI/UX, a first version of the Data Protection module, an Incident module with portal, bulk editing for modeling, a dedicated Risk Portal, a new ISMS scoping phase with profiles, and configurable infinite‑scroll tables. ### Highlights - **New UI & Guided UX** — faster navigation, fewer context switches, improved in‑context help, and step‑based menus. - **Data Protection (DPMS)** — initial module for GDPR‑aligned records and workflows. - **Incident Management + Portal** — capture, triage, and track incidents via an integrated portal. - **Bulk Edit for Modeling** — change attributes and relations across multiple modeled objects at once. - **Risk Portal** — centralized space to capture, review, and track risks. - **ISMS Scoping (with Profiles)** — new scoping phase enabling reusable scope profiles. - **Configurable Infinite‑Scroll Tables** — tailor columns and layout for large datasets. --- ### Details #### New UI & Guided UX - Streamlined navigation with reduced context jumps. - Step‑by‑step flows for key tasks (guided menus). - Contextual help where you need it. #### Data Protection (DPMS) - Foundation for GDPR‑aligned data inventories and processes. - Designed to connect with existing process/asset data over time. #### Incident Management with Portal - Incident intake via portal; basic triage and tracking. - Ready to connect with risk and remediation flows. #### Bulk Edit for Modeling - Multi‑select modeled objects and apply changes in one action. - Supports batch updates to attributes and relations. #### Risk Portal - Single place to register, view, and manage risks. - Supports end‑to‑end visibility for stakeholders. #### ISMS Scoping with Profiles - New scoping phase to define scope boundaries early. - Profiles to reuse and standardize scope setups across projects. #### Configurable Infinite‑Scroll Tables - Efficient browsing of large lists without paging. - Adjustable columns and density for your role and task.