Create and edit a data processing system
How to create a data processing system in your ISMS system inventory and maintain its master data: designation and status, type and association, system operations and hosting, protective measures, emergency preparedness and life cycle – and how to save and release it.
A data processing system is one entry in your system inventory. In this article you create such an entry and maintain, in the edit form, the master data your ISMS needs for protection requirements, risk analysis and measure management.
Prerequisites
- Your team has a licence for information security (ISMS).
- You have access to the associated organisation, or the system is released for “All organisations”.
- You have permission to create and edit assets or data processing systems.
- As long as the system has the status “Released”, it can only be changed through a new revision. Save it back to the status “In progress” if necessary.
Create the system
- Set the toggle at the top of the “Main navigation” to “ISMS” and open the entry “Assets” from the “Control” category in the left menu.
- Click “New” at the top right.
- Choose “Create asset” for an empty entry, “Load from sample documents” for a pre-filled sample system, or “Create linked document” to link the new entry to an existing one as its source.
Maintain the master data in the “Contents” tab
- Open the detail page of the system and click “Edit” at the top right – or “Edit” in the “Actions” selection menu. The fields below are located in the “Contents” tab.
- In the “General” section, enter the “Designation” (mandatory field), the “Status” and, optionally, the “Document ID” and the “Description”.
- In the “Association” section, select the responsible organisations in the “Organisations” field or activate “All organisations”. Use “Parent asset” to place the entry in the tree view of your inventory.
- In the “Software & Licence” section, set the “Type” (for example “Application (cloud-hosted)”, “Database” or “Server (virtual)”), the “Categorisation”, the details under “Manufacturer / Supplier” and “Current version”, the “Location of data (countries)” and the “NIS2 relevance”. The field “Relevant to data protection” controls whether the system is additionally maintained in the privacy view.
- In the “System Operations & Hosting” section, record “Operating model / Hosting”, “Hosting location / data centre”, “Can it be accessed from outside the internal network?”, “Access / Accessibility” as well as “Encryption during transmission” and “Encryption and storage”.
- In the “Protective measures” section, link the applicable “Technical and organizational measures” and “Rule sets”, add “Other special measures” and set “Logging (security) enabled?”.
- In the “Emergencies & Availability (BCM)” section, maintain “Maximum tolerable data loss (RPO)”, “Is there a backup?”, “Backup frequency” and “Restore last tested on”; in the “Suppliers & Contract” section, add “Is there a support/maintenance contract in place?”, “SLA / Service Level Agreement” and “The provider’s certifications”.
- In the “Vulnerabilities & Lifecycle” section, enter “Life cycle phase”, “Version used”, “Launch date”, “End-of-Life / End-of-Support” and “Patch and update procedures”. The access control fields “SSO solution”, “Multi-factor authentication” and “Authorisation Policy / Access Control” follow further down the form.
Save and release
- Check your entries; the “Preview” button at the top right displays a formatted preview at any time.
- Click “Save”. The arrow icon next to it may offer “Save and release”; use “Cancel” to discard your changes.
- When the system moves to the status “Released”, a new revision is created automatically. The change appears in the “Activities” tab, and observers and assigned users are notified.
Practical tip: keep “End-of-Life / End-of-Support” and “Restore last tested on” up to date – in an audit against ISO/IEC 27001 or BSI IT baseline protection, both fields are the quickest evidence that your inventory is actively maintained. Create a task or follow-up straight away for systems that are approaching end of support, so that the system documentation does not become outdated.
Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.