Zum Hauptinhalt springen

Manage measures in the overview

How to keep your directory of technical and organizational measures under control: open the overview, narrow it down with the search term, filters and columns, and check which requirements are actually covered by documented measures.

Last updated:

The overview of technical and organizational measures is where you steer your security concept: it shows all TOM documents of your team in one table, lets you narrow that table down, and reveals where the measure documentation is still thin compared with the requirements of your ISMS. This article takes you from the full list to a meaningful subset.

Prerequisites

  • You are logged into a team that uses the “Technical and organizational measures” module.
  • You have permission to view technical and organizational measures. For bulk actions you also need the permissions to create, edit, share or delete.

Open the overview

  1. In the left menu under “Collateral securities”, click “Technical and organizational measures”.
  2. The overview shows your team's directory with the default columns “Status”, “Designation”, “Association”, “Tasks” and “Tags”.
  3. Use the “All my organizations” button in the top right to switch to a single organization if you only want to review its measures.

Search, filter and sort

  1. Enter a term in the “Search term” field. The search covers all recorded content, including the stored text modules.
  2. Click “Filter” to expand the filter area. Available filters include “Status” (New, In progress, Published, Archived), “Designation”, “Association”, “Client numbers”, “Document ID”, “Tags”, “Created by” and the date filters “Last revision on” and “Follow-up on”.
  3. Use the category filters “Access control”, “Availability (of the data)” and “Pseudonymization” to search specifically in the text modules of those measure categories.
  4. Use the “Columns” button in the top right to show additional columns — for example “Document ID”, “Last revision”, “Follow-up on” or individual measure categories such as “Encryption”, “Resilience (of the systems)”, “Recoverability (of the data / the systems)” and “Incident response management”.
  5. Sort by “Status” or “Designation” using the column headers. The applied sorting appears above the table and can be removed there with “Reset”.
  6. Save a frequently used combination of filters and sorting via the “Views” selection menu so you can call it up again with one click.

Check coverage against requirements

  • Show the measure category columns and filter on “Status” = Published. Empty category columns immediately reveal which protection objectives still lack a solid description of measures.
  • Audit requirements test directly whether the protective measures documented in the TOMs have been implemented in practice. An answer with the status Not implemented or Partially implemented is therefore the typical trigger for updating the TOM document concerned.
  • The link to “Data processing systems” makes visible which systems a TOM document secures. This gap between “we have TOMs” and “the TOMs cover all systems” is the most common audit finding.
  • The “Follow-up on” filter surfaces the documents whose effectiveness is due for its regular review — that periodic review is a mandatory element in both ISO/IEC 27001 and BSI IT baseline protection.

Practical tip: if your group runs different security levels per location or business unit, always review the measures per organization via “All my organizations”. This avoids creating the impression that a standard TOM applies to the entire company — a point that regularly leads to follow-up questions in audits.

Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.

Related glossary terms