Zum Hauptinhalt springen

Define the team-wide protection requirements methodology

Before you classify individual objects, define the methodology once for the whole team: the number of protection objectives, the valid damage scenarios and the derivation rules — principle of maximum, cumulative effect and inheritance. The settings apply to all assets, processing activities and applications.

Last updated:

Determining protection requirements only holds up in an audit if everyone in the team classifies by the same rules. You maintain this base configuration once under “Settings → Protection requirements” – before the first classification of an asset, a processing activity or an application.

Prerequisites

  • You are logged in as an administrator.
  • The team has an active license for privacy or information security management.
  • The settings apply to all “Assets”, “Processing activities” and “Applications” of this association.

Open the settings

  1. In the left sidebar, click “Settings”.
  2. In the settings menu, select the “Protection requirements” entry. The page is divided into the three sections “Protection objectives”, “Damage scenarios” and “Rating options”.

Set the number of protection objectives

  1. In the “Protection objectives” section, click “Edit”.
  2. Under “Number of conservation objectives”, select one of the three options: “3 Security Objectives — Confidentiality, Integrity, Availability” (the classic CIA triad as defined by ISO 27001), “4 Security Objectives — Confidentiality, Integrity, Availability, Authenticity” or “4 Security Objectives — Confidentiality, Integrity, Availability, Binding nature”.
  3. Click “Save”.

If you later change or remove a fourth protection objective that has already been selected, the values, justifications and scenario ratings recorded for it are irrevocably deleted; the system requires explicit confirmation before saving.

Decide which damage scenarios apply

The “Damage scenarios” section contains the scenarios on which every classification is based. The table shows the columns “Damage scenario”, “Source” (“Specified” or “Personalised”) and “Status” (“Active” or “Inactive”) for each scenario.

  1. Click a scenario to review it. For a specified scenario, “Designation” and “Description” are read-only – only the “Enabled” switch can be changed.
  2. For a scenario of your own, click “New”, enter a “Designation” and a “Description”, leave the “Enabled” switch active and click “Save”.
  3. You delete a personalised scenario via the “Actions” menu using “Remove”.

Configure the rating options

  1. In the “Rating options” section, click “Edit”.
  2. Enable the “Principle of Maximum”: the protection requirement for an objective then corresponds to the highest protection requirement of the inflowing sources.
  3. Enable the “Cumulative effect” if required – it raises a protection objective by one level when several sources with a high protection requirement accumulate there. Each objective is considered on its own; the effect only applies when the principle of maximum is in force.
  4. If the cumulative effect is active, fill in “Threshold (number of sources)” and “Threshold (level of protection required)” (Normal, High or Very high).
  5. Under “Inheritance”, define which sources are taken into account: “Processing activities”, “Processing activities carried out on behalf of” and “Subordinate assets”.
  6. Click “Save”.

What happens next

  • Whenever protection objectives, damage scenarios or rating options are changed, the protection requirements of all affected objects are recalculated automatically.
  • When a damage scenario is deactivated or removed, the ratings and justifications recorded for it are irrevocably deleted from all objects – the system requires you to enter the team name as confirmation.

Practical tip: Define the fourth protection objective early, because it then appears system-wide in all matrices and overviews. And finalise the scenario list before the first classification runs: every later deletion costs you ratings that you cannot reconstruct in an audit.

Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.

Related glossary terms