Zum Hauptinhalt springen

Document data flows between assets

How to document the interfaces and handover points of a system in the “Data flow between assets” section: select the linked asset, set the direction and describe the data flow – the basis for propagation analyses in your ISMS.

Last updated:

A system rarely stands alone: data is exchanged via interfaces, exported, imported or replicated. In the “Data flow between assets” section you record these handover points and make visible which systems are reachable from a compromised system.

Prerequisites

  • You have access to the parent data processing system.
  • You have permission to edit the data processing system.
  • At least one additional asset exists in your team – a data processing system or an AI system – that you can link to.

View existing data flows

  1. Open the detail page of the data processing system.
  2. Scroll to the “Data flow between assets” section. The table shows the columns “Linked asset”, “Direction” and “Description of the data flow”.
  3. As long as no handover point has been recorded, the note “No data available.” appears.

Record an interface as a data flow

  1. In the “Data flow between assets” section, click the “New” button. The overlay area “New data flow” opens.
  2. Under “Linked asset”, use the selection menu to choose the counterpart of the interface. The other assets in your team are available for selection.
  3. Under “Direction”, define the handover point: “Incoming” (data flows from the linked asset into this system), “Outgoing” (data flows from this system into the linked asset) or “Bidirectional” (data is exchanged in both directions).
  4. In the “Description of the data flow” text field, describe which data is handed over, for what purpose and by which means – for example interface, export/import or replication.
  5. Click “Create”. Use “Cancel” to discard the entry.

Change or remove a data flow

  1. Click the desired line in the table. The overlay area “Data flow between assets” opens with the “Edit” and “Actions” buttons.
  2. Click “Edit”, change the entries in the “Edit data flow” area and click “Save”.
  3. If you want to remove a handover point, mark the line using the selection box at the start of the line, click “Actions” above the table and select “Delete”. Confirm the security prompt with “Yes, delete”.

What happens next

  • Creating, editing and removing a data flow is logged in the activity history of the parent system and is visible in the “Activities” tab.
  • The full-text search is rebuilt so that the system remains searchable with its data flows.
  • An AI system can also serve as the “Linked asset” – for example a chatbot that obtains master data from the merchandise management system.

Practical tip: describe not only the technical side of the interface, but also the data categories transferred (for example Master data and order items). Only then can you assess how critical the handover point is in the event of an incident or audit – and the documented directions immediately reveal the propagation paths between systems that ISO/IEC 27001 and BSI IT baseline protection expect you to secure for information transfer.

Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.

Related glossary terms