Running the ISMS

Managing assets and risks

Purpose

The heart of the ISMS: the inventory of everything worth protecting (assets and information), the protection-need assessment, and the assessment and treatment of risks. Where you work in the hub: the Asset Management and Risk Management work areas.

Who does this

Members of the Bearbeiter project role (CISO and ISMS team; Roles and permissions). Beobachter can read and comment.

Recording an asset or information object

  1. Click + New ISMS item at the top of the hub and choose the type: Process, Supplier, ICT Asset, Infrastructure or Information.
  2. Give it a meaningful Summary and describe the object.
  3. Rate the protection objectives: 🔒 confidentiality, 🔗 Integrity, 🕒 Availability — scale 1 - normal / 2 - high / 3 - very high.
  4. For information objects: set 🆔 Personal data (No personal data / Personal data / Special personal data).
  5. Link asset and information via the processes link type (asset → information).
  6. After recording, move the object to status 🟢 Active — only active objects feed the inheritance logic.

Result: once C/I/A are set, the app computes 🛡️ Protection need on the same issue as the maximum of the three values (event-driven). The manual run Inherit Protection Need additionally aggregates C/I/A from linked active information objects onto the asset; Inherit Personal Data carries the data category over (Managing automations).

Asset Management: inventory with asset category, protection need (C/I/A) and personal data.

Creating and assessing a risk scenario

  1. + New ISMS item → type Risk Scenario. Describe the scenario.
  2. Link it via endangers to the affected assets or information (risk scenario → asset).
  3. In status 🔍 Threat analysis, check whether the scenario applies; if yes, move to 👍 Applicable, otherwise 👎 Not applicable.
  4. In status 📊 Risk assessment, rate the current risk: 🎲 Current Likelihood (🟢 1 - rare … 🔴 4 - very frequent) and 💥 Current Impact (🟢 1 - negligible … 🔴 4 - critical).
  5. The app computes 🚦 Current Risk Category automatically: product ≥ 12 → 🔴 4 - very high · ≥ 6 → 🟠 3 - high · ≥ 3 → 🟡 2 - medium · otherwise 🟢 1 - low.
  6. In status 📄 Risk treatment, choose the ↘️ Risk treatment: Avoidance, Reduction, Transfer or Acceptance. For reduction: create an action and link it via mitigates (action → risk; Implementing and reviewing measures).
  7. Enter the target values (🎲 Target Likelihood, 💥 Target Impact) — the 🚦 Target Risk Category is computed the same way.
  8. Finish with status ✅ Accepted (triggers a RACI notification if the rule is enabled).
Risk Management: “Needs attention” bar, tabs and the list of Risk Scenarios with “Current Risk Category”, “Target Risk Category”, “Risk Treatment” and “Next review”.

Verify

  • The dashboard shows the risk in the Risk matrix (current/target) and possibly under Top risks; unassessed risks appear in the Action center.
  • The Explorer shows the chain asset ← endangers ← risk ← mitigates ← action as a graph.

What happens next

  • If the 🚦 Current Risk Category becomes 🟠 high or 🔴 very high, the field alert notifies Responsible and Accountable (Setting up notifications (RACI)).
  • With a 🔄 Review interval set, the review cycle calls the object up for re-assessment regularly; from 🔄 Under review it goes back into assessment.
  • The manual run Accumulate Risk Category to Parent aggregates the child risk scenarios’ values onto the parent object.
  • For management and audits, administrators generate the Risk Report (Generating reports).

Troubleshooting

  • The risk category stays empty: both input fields (likelihood and impact, 1–4 each) must be set, and the Calculate Risk Category automation must be enabled.
  • Protection-need inheritance does not fire: linked information objects must be in status 🟢 Active and connected via processes.

Screenshots from the development environment with sample data.

Documentation baseline: app version 1.1.15 · 2026-08-20