Manually classify protection objectives
Instead of deriving the protection requirement from the damage scenarios matrix, you set the level per protection objective directly: enable the “Manually classify conservation objectives” switch and assign a level and a justification per objective.
Sometimes the automatic derivation does not reflect the actual protection requirement of an object. In that case you set the levels of the protection objectives directly – manual classification overrides damage scenarios, inherited protection requirements and AI assessments.
Prerequisites
- You have permission to edit the document. Without edit permission the values are only displayed; the buttons for classification do not appear.
- The team-wide protection requirements methodology is maintained – it defines which protection objectives are available.
- The “Protection requirements” tab is structured identically in all affected modules: data processing systems, assets, AI systems as well as processing activities and processing activities carried out on behalf of.
Step by step
- Open the document – a data processing system, for example – and switch to the “Protection requirements” tab (the second tab next to “Contents”).
- In the “Classification of conservation objectives” section, click “Manually classify conservation objectives” at the top right.
- The “Manually classify conservation objectives” side panel opens with the “Manual classification” section.
- Enable the “Manually classify conservation objectives” switch. While it is enabled, the levels entered below are the ones that count; damage scenarios, inherited protection requirements and AI assessments are ignored.
- In the “Protection objectives” section that now appears, use the “Level” selection field to assign a value for each protection objective – “Confidentiality”, “Integrity”, “Availability” and, if configured, the fourth objective (“Authenticity” or “Binding nature”):
Not rated,Normal,HighorVery high. - Fill in the “Justification” field for each protection objective.
- Click “Save”. Use “Cancel” to discard the entry.
What happens next
- The “Overall result” is recalculated: it equals the highest protection requirement of all protection objectives.
- The identifier on the “Protection requirements” tab and the cards in the “Classification of conservation objectives” section are updated.
- The classification also appears as the “Protection requirements” column in the module’s overview table and serves as the benchmark for the subsequent risk assessment under ISO 27001 or BSI IT baseline protection.
Switching manual classification off again
Disable the “Manually classify conservation objectives” switch and save. The values you entered are retained but ignored – the protection requirement is derived automatically from damage scenarios and sources again.
Practical tip: Manual classification takes precedence over all derived values. Use it deliberately only when automatic derivation does not reflect the actual protection requirement, and disable the switch again as soon as the sources correctly reflect the classification. Any classification above “Normal” should always carry a justification – in an audit, the traceable derivation counts for more than the level itself.
Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.