Edit and delete hazards
How to find a hazard in the audit catalog, open its detail view and adjust the designation and description — or delete the hazard once it no longer carries weight in your ISMS risk context.
Hazards are the risk context of an audit catalog: they describe what the requirements actually protect against. In this article you view the hazards of an audit catalog, change the designation and description of an existing hazard, and delete a hazard you no longer need. Creating new hazards is not covered here.
Prerequisites
- You have access to the parent audit catalog.
- You have permission to edit the audit catalog.
- Hazards already exist in the “Hazards” section of the audit catalog.
View hazards
- Open the detail view of the audit catalog.
- Scroll to the “Hazards” section. The table shows the columns “Designation” — the name of the hazard — and “Description” — a detailed explanation.
- Use the column headers to sort the list by “Designation” or “Description”.
- Use the “Search term” field to filter the list by terms.
- Click anywhere in the row to open the hazard in a sidebar. The detail view shows the maintained contents “Designation” and “Description”.
Edit or delete a hazard
- Open the detail view of the hazard.
- Click “Edit” in the top right, or open the “Actions” menu.
- Select “Edit” to adjust the “Designation” and “Description”, then save your change.
- Select “Delete” to remove the hazard. The hazard is deleted after a security prompt.
What happens next
- Editing and deleting a hazard are logged in the activity history of the parent audit catalog.
- Observers and assigned users receive an email notification as well as a notification in the application.
- The full-text search is rebuilt so that the changed contents can be found via the “Search term” field.
- If the audit catalog is in “Published” status, a security prompt appears before every change, because changing a methodological basis affects all ongoing audits against this catalog.
A tip from practice: use the nomenclature of established hazard catalogs for the designations — for example the “Elementary Hazards” from the BSI IT Baseline Protection Compendium (G 0.1 to G 0.47). If you sharpen a designation later on, name it according to the same scheme so that audit reports remain consistently readable. Before deleting, check whether the hazard is still assigned to requirements — without a hazard, the protective purpose of a requirement is no longer documented in the audit report.
Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.