Running the ISMS
Managing assets and risks
Purpose
The heart of the ISMS: the inventory of everything worth protecting (assets and information), the protection-need assessment, and the assessment and treatment of risks. Where you work in the hub: the Asset Management and Risk Management work areas.
Who does this
Members of the Bearbeiter project role (CISO and ISMS team; Roles and permissions). Beobachter can read and comment.
Recording an asset or information object
- Click + New ISMS item at the top of the hub and choose the type: Process, Supplier, ICT Asset, Infrastructure or Information.
- Give it a meaningful Summary and describe the object.
- Rate the protection objectives: 🔒 confidentiality, 🔗 Integrity, 🕒 Availability — scale 1 - normal / 2 - high / 3 - very high.
- For information objects: set 🆔 Personal data (No personal data / Personal data / Special personal data).
- Link asset and information via the processes link type (asset → information).
- After recording, move the object to status 🟢 Active — only active objects feed the inheritance logic.
Result: once C/I/A are set, the app computes 🛡️ Protection need on the same issue as the maximum of the three values (event-driven). The manual run Inherit Protection Need additionally aggregates C/I/A from linked active information objects onto the asset; Inherit Personal Data carries the data category over (Managing automations).
Creating and assessing a risk scenario
- + New ISMS item → type Risk Scenario. Describe the scenario.
- Link it via endangers to the affected assets or information (risk scenario → asset).
- In status 🔍 Threat analysis, check whether the scenario applies; if yes, move to 👍 Applicable, otherwise 👎 Not applicable.
- In status 📊 Risk assessment, rate the current risk: 🎲 Current Likelihood (🟢 1 - rare … 🔴 4 - very frequent) and 💥 Current Impact (🟢 1 - negligible … 🔴 4 - critical).
- The app computes 🚦 Current Risk Category automatically: product ≥ 12 → 🔴 4 - very high · ≥ 6 → 🟠 3 - high · ≥ 3 → 🟡 2 - medium · otherwise 🟢 1 - low.
- In status 📄 Risk treatment, choose the ↘️ Risk treatment: Avoidance, Reduction, Transfer or Acceptance. For reduction: create an action and link it via mitigates (action → risk; Implementing and reviewing measures).
- Enter the target values (🎲 Target Likelihood, 💥 Target Impact) — the 🚦 Target Risk Category is computed the same way.
- Finish with status ✅ Accepted (triggers a RACI notification if the rule is enabled).
Verify
- The dashboard shows the risk in the Risk matrix (current/target) and possibly under Top risks; unassessed risks appear in the Action center.
- The Explorer shows the chain asset ← endangers ← risk ← mitigates ← action as a graph.
What happens next
- If the 🚦 Current Risk Category becomes 🟠 high or 🔴 very high, the field alert notifies Responsible and Accountable (Setting up notifications (RACI)).
- With a 🔄 Review interval set, the review cycle calls the object up for re-assessment regularly; from 🔄 Under review it goes back into assessment.
- The manual run Accumulate Risk Category to Parent aggregates the child risk scenarios’ values onto the parent object.
- For management and audits, administrators generate the Risk Report (Generating reports).
Troubleshooting
- The risk category stays empty: both input fields (likelihood and impact, 1–4 each) must be set, and the Calculate Risk Category automation must be enabled.
- Protection-need inheritance does not fire: linked information objects must be in status 🟢 Active and connected via processes.
Related pages
Screenshots from the development environment with sample data.
Documentation baseline: app version 1.1.15 · 2026-08-20