Zum Hauptinhalt springen

Adding hazards to a self-created audit catalog

In a self-created audit catalog, hazards are first created centrally and then assigned via the respective requirement (checklist → requirement → "Add hazards"). Only this assignment makes the protective purpose of a requirement visible. If hazards are not adopted, the second step – the assignment to the requirement – is usually missing.

Last updated:

When creating your own audit catalog, hazards are used in two steps: first you create the hazards centrally in the audit catalog, then you assign them to the respective requirement. Only through this assignment does it become visible what a requirement protects against – the logic is familiar from BSI IT-Grundschutz and from CISIS12.

  1. Create a hazard: Open the detail view of the audit catalog and click New in the Hazards section. Assign a Designation and optionally a Description and confirm with Create.
  2. Assign a hazard to a requirement: In the audit catalog, open the desired checklist, click the relevant requirement and then click Add hazards in the Hazards section. Select the hazards to be assigned and confirm with Add.

If hazards are not adopted for the audit object, you should check whether the second step – assigning the hazard to the requirement – has been carried out correctly. Hazards that are only created in the catalog but not assigned to any requirement do not take effect in the audit.

Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.

Related glossary terms