Zum Hauptinhalt springen

Maintain applicabilities in the audit catalog

Applicabilities define the protection requirements level from which a requirement applies. Learn how to create the levels Basic, Standard, High and Very High in your audit catalog, edit them and model their hierarchy.

Last updated:

Applicabilities are master data of your audit catalog. They describe the protection requirements level from which a requirement applies — for example “Basic”, “Standard”, “High” or “Very High”. After following this guide, the levels of your ISMS methodology are stored in the catalog, so that in the audit only the matching requirements have to be answered per inspection item.

Prerequisites

  • You have access to the parent audit catalog.
  • You have permission to edit the audit catalog.
  • The catalog contains at least one “Checklist”, because applicabilities are maintained from the form of a “Requirement”.
  • For audit catalogs with the status “Released”, a security prompt appears before every change, because it affects all ongoing audits against this catalog.

Open the overview of applicabilities

  1. Open the detail view of the checklist and, from there, the form for creating or editing a “Requirement”.
  2. In the “Applicability” field, click the “Edit” button to the right of the selection menu.
  3. The “Applicabilities” sidebar opens with all levels maintained in the catalog.

Create a new applicability

  1. In the “Applicabilities” sidebar, click “New”.
  2. Enter the name of the level under “Designation” — mandatory field, max. 191 characters, for example Standard.
  3. Optionally select an existing level under “Included applicability”. If, for example, “Standard” includes “Basic”, then in an audit at standard level all basic requirements also apply automatically.
  4. Click “Create” to create the applicability, or “Cancel” to discard the entry.

Edit an applicability

  1. In the “Applicabilities” list, click a row to open the detail view.
  2. Click “Edit” at the top right.
  3. Change “Designation” or “Included applicability” and save it.

Effect in the audit

The applicability assigned to a requirement determines whether that requirement has to be answered in the audit. Which checklists are available at all is instead controlled by the “Permitted audit object type” of the checklist. Every change to an applicability is logged in the activity history of the audit catalog.

Practical tip: Map the levels known from BSI IT baseline protection — Basic ⊂ Standard ⊂ High ⊂ Very High — and model this hierarchy explicitly using the “Included applicability” field. This avoids having to maintain every basic requirement additionally in the standard and high levels.

Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.

Related glossary terms