Zum Hauptinhalt springen

Assess a requirement in the ISMS cockpit

How to open the detail view of a requirement in the ISMS cockpit and set its rating status – including maturity level, responsibility, deadline, reason for inclusion and the reasons for exclusion for requirements that are not applicable.

Last updated:

The detail view of a requirement is where you record how far its implementation has progressed. This guide shows how to open that detail view and set the rating status of a requirement in your list of requirements (for example ISO 27001 or BSI IT baseline protection).

Prerequisites

  • At least one list of requirements has been loaded.
  • You have permission to edit requirements.

Open the detail view

  1. Open the “ISMS cockpit” or the detail view of the list of requirements.
  2. Click the requirement you want to assess. A detail view opens with the tabs “Contents”, “Activities”, “Files”, “Tasks” and “Comments”.
  3. Stay on the “Contents” tab. It is divided into the sections “General”, “Risk acceptance / Exception”, “Standard”, “Evidence”, “Links”, “Cross-references to other standards” and “Reports”.

Set the rating status

  1. Click “Edit” in the “General” section.
  2. Under “Status”, select the rating status, for example Not rated, Not met, Partially met or Fulfilled.
  3. Complete the remaining fields of the section:
    • “Maturity level” – the implementation level of the associated measures.
    • “Data controller” – the person responsible for the requirement.
    • “Deadline (to be implemented by)” – the target date for implementation.
    • “Confidentiality class” – the classification of the requirement.
    • “Implementation description” – how the requirement is implemented in practice.
  4. Fill in the “Reason for inclusion” field. It is mandatory and is documented in the Statement of Applicability (SoA).
  5. If you classify a requirement as “Not applicable”, use the “Reasons for exclusion” field to state why the requirement does not apply to your organisation.
  6. Click “Save and go back”.

What happens next

  • The new rating status is taken into account in the ISMS cockpit immediately.
  • The change is logged in the activity history of the requirement – you can review it on the “Activities” tab.

Tip: write a solid sentence into “Reason for inclusion” the first time you assess a requirement. It is carried over unchanged into the Statement of Applicability and is exactly the place auditors ask about.

Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.

Related glossary terms