Assess protection requirements via the damage scenarios matrix
How to derive the protection requirement of an asset, data processing system or AI system from the damage scenarios matrix in the “Protection requirements” tab: set a level and a justification per scenario and protection objective, derive the result using the maximum principle, and account for the cumulative effect.
The damage scenarios matrix lets you derive an object’s protection requirement traceably from the possible damage impacts — the basis for every risk assessment and selection of controls in an ISMS according to ISO 27001 or BSI IT baseline protection.
Prerequisites
- You have permission to edit the document. Without edit permission, the values are only displayed; the buttons for classification do not appear.
- The team-wide methodology is maintained — protection objectives, damage scenarios and rating options. If no damage scenarios are active, the matrix cannot be filled in.
- You have opened the object — an asset, a data processing system, an AI system, a processing activity or a processing activity carried out on behalf of — and switched to the “Protection requirements” tab.
Step by step
- In the “Damage scenarios” section, click “Edit” at the top right.
- The “Edit protection requirements” side panel opens. Under “Damage scenarios”, a note explains that the protection objectives and the overall result are derived from the impact classification using the maximum principle.
- For each damage scenario — for example “Breach of laws, regulations or contracts” or “Impairment of the ability to carry out tasks” — rate the protection objectives “Confidentiality”, “Integrity” and “Availability”, plus the fourth protection objective if one is configured. Each selection field offers the levels “Not rated”, “Normal”, “High” and “Very high”.
- Enter a “Justification” for each scenario. Whenever you rate a combination above “Normal”, record the reasoning there.
- Click “Save”. Use “Cancel” to discard the entry.
How the result is produced
- Principle of maximum: below the scenario lines, the line “↑ Maximum — derived classification” shows the highest level per column, that is, per protection objective. The “Overall result” at the top of the tab is in turn the highest protection requirement across all protection objectives.
- Cumulative effect: if it is enabled in the “Rating options”, the additional line “↑ Cumulative effect — revised classification” appears. It raises the classification where many objects, each with a normal protection requirement on its own, act together.
- Inheritance: if the protection requirement is derived from linked objects, the “Sources” section lists every source with its levels and applies the maximum principle and the cumulative effect to them.
- After saving, the overall result, the classification of the protection objectives and the identifier on the tab are recalculated; the level also appears as the “Protection requirements” column in the module’s overview table.
Practical tip: provide a justification for every classification above “Normal”. In an audit, the traceable derivation of the protection requirement matters more than the level itself — a “Very high” classification without a justification is vulnerable.
Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.