Zum Hauptinhalt springen

Understand the audit catalog detail view

The detail view is the central record of an audit catalog. This article explains the structure of the page, its tabs and the methodological chain catalog → checklist → requirement → hazard, so you can read and maintain your ISMS framework with confidence.

Last updated:

The detail view of an audit catalog brings the entire methodological framework of your ISMS together in one place. After reading this article you will know which information sits in which section, what each tab is for, and how catalog, checklist, requirement and hazard relate to one another.

Prerequisites

  • You have access to the associated organization, or the audit catalog is shared for “All organisations”.
  • To edit, publish, duplicate or delete, you additionally need the appropriate authorization. Access to the organization is enough to simply read the detail view.

Open the detail view

  1. Open the “Audit catalog” overview.
  2. In the table, click anywhere in the line. The detail page opens on the “Contents” tab.
  3. Above the tabs, check the quick actions “Follow-up”, “Editors”, “Observers” and “Opened by” — they show at a glance who is working on the catalog and when it is due for review again.

Structure of the “Contents” tab

The factual information is divided into four sections:

  • “General”“Designation”, “Status” (New, In progress, Published, Archived), “Document ID”, “Created on” and “Description”.
  • “Association” — the assigned “Organisations” or the note “All organisations”. If no assignment is maintained, “No associated organizations” appears.
  • “Checklists” — a table with the columns “Designation”, “Description” and “Permitted audit object type”. Use “New” to create a checklist; clicking a line opens it together with its requirements in a sidebar.
  • “Hazards” — a table with the columns “Designation” and “Description”. Use “New” to create a hazard; clicking a line opens it in a sidebar.

The tabs of the detail page

  • “Contents” — the factual information described above.
  • “Activities” — the history of all changes, such as editing and publishing.
  • “Files” — supplementary documents such as standards texts or your own interpretations.
  • “Tasks” — follow-up measures anchored directly to the catalog.
  • “Relationships” and “Comments” — links to other objects and discussions about the methodology.
  • “Checklists” and “Surveys” — general checklists and surveys, for example for a structured preliminary survey.
  • “Risk analyses” — the formal risk assessments for the hazards maintained in the catalog.
  • “Revisions” — when you publish, a new revision is created automatically and becomes visible here.

Catalog → checklist → requirement → hazard

The detail view maps two methodological components that work together in the later audit:

  1. The audit catalog is the methodological framework. When you create an audit, you select exactly one catalog.
  2. The checklists divide the catalog into topic areas and define via the “Permitted audit object type” what is inspected — for example ISMS process, Compliance or Asset.
  3. The requirements within a checklist define what is audited.
  4. The hazards provide the risk context and are referenced in individual requirements. In the audit, this makes it traceable for each requirement which hazard it is intended to protect against.

This separation reflects the structure of established audit methods such as CISIS12 or BSI IT baseline protection, in which requirements and hazards are independent building blocks — a prerequisite for a risk-oriented assessment of the audit results.

Preview and further actions

  1. Click “Preview” at the top right to open a page-formatted view of the catalog, as it is also generated for download. Close it using the X at the top right.
  2. Click “Edit” at the top right to change the content. As long as the status is New or In progress, a green “Share” button also appears.
  3. Via “Actions” at the top right you reach “Change affiliation”, “Watch”, “Archive”, “Duplicate”, “Create linked document”, “Download as PDF” or “Download as DOCX”, and “Delete”.

Practical tips

  • Use the “Preview” before every audit preparation as a final visual check: gaps such as a requirement without assigned hazards or a checklist without a permitted audit object type are much easier to spot in the rendered form than in the individual tables.
  • Only publish a catalog once the requirements of at least one checklist have been fully recorded and the relevant hazards have been assigned — in Published status it serves as the verified methodological basis for real audits.

Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.

Related glossary terms