Assess hazards in an audit
How to rate the hazards from the audit catalog for each inspection item: maintain Severity of the impact and Probability of occurrence yourself, or adopt the assessment from a parent inspection item.
By the end of this guide, every hazard on an inspection item is rated — either with its own assessment made up of “Severity of the impact” and “Probability of occurrence”, or with a rating adopted from the inspection item hierarchy. These assessments are the data your ISMS uses to build a robust risk register in line with ISO/IEC 27001, BSI IT baseline protection, or CISIS12.
Prerequisites
- You have access to the audit via the organisation assignment or via the “All organisations” setting.
- An “Audit catalog” is assigned to the audit — the hazards are obtained entirely from that catalog.
- You have permission to edit audits.
- The inspection item exists, and its “Inspection object type” and “Applicability” are set.
Step by step
- Open the audit detail view and click the designation of the inspection item in the “Inspection items” section.
- In the page view, go to the “Hazards” section of the “Contents” tab. It lists all hazards relevant to this inspection item.
- Click a line to open the hazard in a page view.
- Click “Edit”.
- Use the “Adopt assessment rating” option field to decide where the rating comes from:
- If you set “Adopt assessment rating” to
yes, “Severity of the impact” and “Probability of occurrence” are removed automatically; the rating follows the source, that is the parent inspection item. - If you set “Adopt assessment rating” to
no, you select “Severity of the impact” and “Probability of occurrence” yourself.
- If you set “Adopt assessment rating” to
- Click “Save and close”.
What the overview shows
Each line of the table in the “Hazards” section shows the “Designation” of the hazard from the audit catalog, the “Source of adoption”, whether the “Assessment is adopted”, the “Severity of the impact”, and the “Probability of occurrence”. This makes it easy to see at a glance which inspection items still need a rating of their own.
How the assessment is used
- Creating, editing, and deleting a hazard assessment is logged in the audit activity history.
- The recorded assessments feed into the higher-level risk management in the “Risk analyses” module and become entries in the risk register there.
- If you delete an inspection item, its hazards are removed with it.
Practical tip: Only adopt hazard assessments via the hierarchy if the parent inspection item is actually substantively representative — for example the same protection requirement class or the same site group. Otherwise the informative value of the later risk analysis suffers, and you lose the main benefit of audit granularity.
Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.