Quick Guides for preeco | information security
Here you will find helpful guides, step-by-step instructions, and practical tips for the information security module. From audits to risk analyses – we show you how to use preeco optimally.
Support & Help
How can we help?
FAQ & Guides
Less is more: exclude non-applicable requirements – and fill the SoA automatically
Requirements that are not relevant for an organization can be classified as "not applicable" in the ISMS Cockpit. The ex
Create and edit a data processing system
How to create a data processing system in your ISMS system inventory and maintain its master data: designation and statu
Add evidence to a requirement
How to upload a supporting file directly to a requirement in the ISMS cockpit and give it a designation and a validity d
Answer a checklist and attach evidence
How to answer a released checklist in the answer form, rate risk matrix questions, attach evidence in the “Files” tab an
Answer requirements in an audit
How to assess each requirement of an assigned checklist on the inspection item: set the status, document the facts under
Archive and reactivate a list of requirements
How to archive a superseded list of requirements without losing ratings and evidence, and how to reactivate it when need
Assess a requirement in the ISMS cockpit
How to open the detail view of a requirement in the ISMS cockpit and set its rating status – including maturity level, r
Assess hazards in an audit
How to rate the hazards from the audit catalog for each inspection item: maintain Severity of the impact and Probability
Assess protection requirements via the damage scenarios matrix
How to derive the protection requirement of an asset, data processing system or AI system from the damage scenarios matr
Assign a checklist from the audit catalog
Checklists bring the requirements of your audit catalog to a specific inspection item. Here is how to assign matching ch
Assign hazards to a requirement – remove the assignment again
How to assign one or more hazards to a requirement in the audit catalog and remove the assignment again when needed — so
Build an asset inventory
How to build a complete inventory of all assets requiring protection in the “Assets” view: create assets, review the sys
All guides from A to Z
How to upload a supporting file directly to a requirement in the ISMS cockpit and give it a designation and a validity
The ISMS Cockpit offers a consolidated overview of all activated requirements catalogs and their implementation status.
How to answer a released checklist in the answer form, rate risk matrix questions, attach evidence in the “Files” tab
How to assess each requirement of an assigned checklist on the inspection item: set the status, document the facts under
How to archive a superseded list of requirements without losing ratings and evidence, and how to reactivate it when
How to open the detail view of a requirement in the ISMS cockpit and set its rating status – including maturity level,
How to rate the hazards from the audit catalog for each inspection item: maintain Severity of the impact and Probability
How to derive the protection requirement of an asset, data processing system or AI system from the damage scenarios
Checklists bring the requirements of your audit catalog to a specific inspection item. Here is how to assign matching
How to assign one or more hazards to a requirement in the audit catalog and remove the assignment again when needed — so
How to build a complete inventory of all assets requiring protection in the “Assets” view: create assets, review the
When a new requirements catalog is loaded, the open requirements can be shown selectively in the ISMS Cockpit via the
In the ISMS Cockpit, evidence for requirements can be requested directly via a link, without the person asked needing
How to complete the review of a requirement in the ISMS cockpit: record the result, reviewer, note and follow-up, and
How to create a new AI compliance check in preeco: choose a creation option, enter a designation and use the association
An inspection item is the specific unit you audit – an application, a building, or an ISMS process. This guide shows how
How to create a data processing system in your ISMS system inventory and maintain its master data: designation and
Technical and organizational measures (TOMs) are the documented security concept of your ISMS. This guide shows how to
How to create a new audit and equip it with a designation, association, scope and audit catalog. The catalog determines
Checklists make recurring ISMS reviews reproducible. Here is how to create a checklist, maintain questions with the
Checklists are the structuring level of an audit catalog: they group the requirements of one topic area and define, via
Before you classify individual objects, define the methodology once for the whole team: the number of protection
Requirements that are deliberately not implemented can be documented in the ISMS Cockpit as a justified exception with
How to document the interfaces and handover points of a system in the “Data flow between assets” section: select the
Document the access structure of a data processing system: roles with permissions, users, clients and external operating
How to activate a standard such as ISO/IEC 27001, NIS2 or BSI C5 as a requirements specification in your team: select
How to adjust the designation and the assigned organisations in the detail view of a list of requirements – so that its
How to create your own audit catalog and maintain its master data – designation, status, document ID, language,
How to find a hazard in the audit catalog, open its detail view and adjust the designation and description — or delete
How to change the method framework of an existing risk analysis – events, damage items with their criteria and risk
How to have the measure texts of a TOM document generated by AI: in the detail view you open the “AI actions” menu,
The degree of fulfillment in the ISMS Cockpit measures the share of fulfilled requirements in the total number of
Requirements that are not relevant for an organization can be classified as "not applicable" in the ISMS Cockpit. The
How to attach an existing document — a set of rules, a measure or an audit — to a requirement from your list of
The “Relationships” tab of an audit shows in one place which documents use the audit and which work together with it.
Applicabilities define the protection requirements level from which a requirement applies. Learn how to create the
Requirements are the questions answered during the audit. Learn how to create a requirement in a checklist, phrase it so
How to document the responsible parties and the known vulnerabilities with CVE references for an asset — both are
How to maintain and assess the requirements catalogue of an AI compliance check: create new compliance requirements,
How to keep your directory of technical and organizational measures under control: open the overview, narrow it down
How to open the sets of rules overview in preeco | informationssicherheit, structure your policies with designation,
In the ISMS cockpit, the “Tasks” and “Deadlines” tabs bring together all open to-dos and implementation deadlines of
Instead of deriving the protection requirement from the damage scenarios matrix, you set the level per protection
How to open an asset of your system landscape in the detail view, find your way around its tabs, and recognise what sets
Publishing turns a TOM draft into a versioned, auditable state of your measures. This guide shows how to edit and
How to create a system with AI components in the AI systems module, determine its protection requirements and lay the
How to move an audit to the “Released” status, secure the reviewed state as evidence for your ISMS and use the actions
The Risk analyses overview page shows every risk assessment of your team with its status, association and linked object.
When an audit covers many similar units – several sites or identical applications – you maintain the inspection item
Rule sets such as your information security policy are maintained in the “Contents” tab: General, Association and Text
The detail view is the central record of an audit catalog. This article explains the structure of the page, its tabs and
Quick Guides Overview
All Guides for preeco | information security
Select a topic to go directly to the matching guide. We have documented the most important features and workflows for you.
ISMS Cockpit at a glance
Key figure tiles, assessment status and tabs for requirements, tasks and deadlines – how to read your degree of fulfillment in five minutes.
Assessing requirements
Use the “Not assessed” quick filter to surface open requirements and work through them step by step in the list or heatmap view.
Non-applicable requirements and the SoA
Exclude requirements that are not relevant – the exclusion justification you store flows automatically into the Statement of Applicability.
Collecting evidence
Request records via link, with no user account needed for the person you ask. Or upload evidence yourself and add a validity date.
Exceptions and residual risk
Document requirements you deliberately do not implement as a justified exception with an accepted residual risk.
Reading the degree of fulfillment
How the degree of fulfillment is calculated, and why non-applicable requirements and accepted exceptions do not distort the figure.
FAQ about preeco | information security
Frequently Asked Questions and Answers
After activating the module, begin with the basic steps of the initial setup. First, you capture your organization and IT assets. Then you can start documenting your policies and measures. Our support team is happy to assist you with any questions.
Select an audit catalog (BSI IT-Grundschutz, CISIS12, or VdA ISA) and start a new audit. The software guides you through all checkpoints in a structured manner. Document compliance levels, assign measures, and record deviations. All results are accessible at any time and can be exported.
The generic risk analysis enables flexible assessments for any scenario. Systematically evaluate the probability of occurrence and potential damage. Link risks with assets, TOMs, and audits for a holistic view. All analyses are versioned and tracked.
In the training module, you can create your own training sessions or use pre-built templates. Add learning units with images or videos and include exam questions. Participation can be made mandatory for employees. Certificates of participation are generated automatically.
Document your TOMs systematically in the corresponding section. You can link measures with assets, audits, and risk analyses. Changes are versioned and tracked, so the evolution of your security measures remains transparent.
preeco offers comprehensive export functions for all areas. You can export audit results, risk analyses, TOMs, and training records in various formats. The data is documented traceably and can be used for internal and external reviews.
Still have questions?
Our support team is happy to help with all questions about preeco | information security. You can reach us via email at support@preeco.de or by phone at +49 731 280 651 0 – Monday to Friday from 9 AM to 5 PM.