Zum Hauptinhalt springen

Create and structure a checklist

Checklists make recurring ISMS reviews reproducible. Here is how to create a checklist, maintain questions with the right response types, structure them with headings and control via the association which organisations may use it.

Last updated:

A checklist gives you a reusable method framework — for example the effectiveness review of a measure, an onboarding review for a new system, or a periodic self-assessment against ISO 27001 or BSI IT baseline protection. You create the checklist, structure its questions and use the association to decide who may work with it in the ISMS.

Prerequisites

  • You are logged into a team that uses the “Checklists” module.
  • You have permission to view checklists as well as the “Edit” permission for checklists.
  • The checklist is in the status “New” or “In progress” — otherwise you additionally need permission to edit published documents.

Step by step

  1. In the left-hand menu, click “Checklists” under “Cooperation”.
  2. At the top right, click the arrow next to the “New” button and choose “Create checklist” for an empty checklist or “Load from sample documents” to apply a predefined template.
  3. In the “General” section, maintain the master data: “Designation” (mandatory field, 1–150 characters), “Status”, optionally “Document ID” following your internal nomenclature, and “Description”.
  4. Tie the review to its object of assessment: under “Type of link”, select the document type — for example “Technical and organizational measures”, “Data processing systems”, “Set of rules” or “Audits” — and then select the specific document under “Linked to”.
  5. In the “Association” section, define which organisations may view and use the checklist. If it applies across the entire group, activate “All organisations”; otherwise select the responsible organisations individually.
  6. In the “Introduction” section, store an “Introductory text” covering purpose, scope and processing notes. It later appears above the questions as well as in the preview and the download.
  7. In the “Contents” section, click the “New” selection menu at the top right and choose “New entry” for a question or “New heading” for a structural chapter. An empty checklist first shows the note “No questions available.”
  8. Click a question in the tree to open the side editing area. Maintain “Text”, optionally “Text colour” and “Explanatory text”, and the “Response type”: “Single selection”, “Multiple choice”, “Text (single line)”, “Text (multi-line)”, “date entry” or “Risk matrix”.
  9. If you choose “Single selection” or “Multiple choice”, also maintain the “Answer options” area with “Answer”, optionally “Answer colour” and “Comments allowed”. Use “Add” to create a further answer option.
  10. Click “Apply” to apply the question to the main form.
  11. Reorder the questions in the tree by drag and drop or sort them under a heading. The “Actions” selection menu in the editing area offers “New heading”, “Duplicate” and “Delete”.
  12. Click “Save” at the bottom. You are redirected to the detail view and the confirmation “The checklist has been successfully updated” appears.

Choose the response type that fits the question

The response type determines how robust the later evaluation is: “Risk matrix” for risk assessments — it rates “Probability of occurrence” and “Severity of the impact” on a four-level scale from “Negligible” to “Maximum value”“date entry” for deadline evidence, and “Multiple choice” for ambiguous circumstances.

Practical tips

  • Always structure longer checklists with headings: in the answer form, each heading is displayed as a separate chapter. Group related questions — such as Awareness, Documentation and Processes — under a heading of their own.
  • Activate “All organisations” only if the checklist really applies across the entire group. For organisation-specific reviews, employees of other organisations would otherwise gain access to ratings that are not relevant to them.
  • Use “Duplicate” for structurally similar questions instead of creating them from scratch.
  • Every change to the method framework is logged in the activity history and visible in the “Activities” tab of the detail view — so it stays traceable which methodological status an earlier response was based on.

Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.

Related glossary terms