Skip to main content
We build the chain that gives a system its significance: from the department through process and business service to the server. At the end the protection need of the server is derived from this chain, and traceable. Prerequisite: an inventoried estate.

Starting point

Docusnap Sports GmbH runs its merchandise management on an SAP system. The scan has captured operating system, services and hardware. What consequences an outage has for the business does not stand in the scan. We map that now.

1. Create the organization

Four types describe the organization. No scan creates them: All four carry only a name. We create them through Asset in the lists under Organization: the department Sales and the people in that department.
The dialog’s type selection is restricted to the types of the opened list. If the type is missing, the list is the wrong one.
We create several people or departments at once: set the switch to Multiple, paste the name column from a table. See Taking Over an Existing Inventory List.

2. Create application and information

The scan captures installations, not applications. That a database, an application server and a web front end together make up the merchandise management is something we establish with two further types: We create the application Merchandise Management and the information Customer Data.

3. Create process and business service

1

Name the business service

The service the company delivers: Order Processing.
2

Name the process

The business workflow beneath it: Order Entry. Keeping process and business service apart makes sense once several processes carry the same service.

4. Set relations

The types get their meaning through relations. We open Order Entry and its Beziehungen tab.
1

Add a relation

Above the Defined Relations zone we open the Add Relation dialog.
2

Target first, then type

We choose the business service Order Processing as the Target Object, then the Relation Type. If the field reads Determined automatically, a rule from Data Model applies; we choose nothing.
3

Mark the critical connection

We connect Order Entry to the application Merchandise Management, and that to the SAP system. On the connection to the SAP system we set Critical and write into the description why.
4

Connect the department

We connect the department Sales to the process.
A relation type carries a label per direction. From the server the relation reads “trägt”, from the process “läuft auf”. The arrow in the dialog shows the direction.

5. Set the protection need

We open the SAP system and its ISMS tab. For each security objective — Confidentiality, Integrity, Availability — we choose Normal, High or Very High. Total Protection Need results from the highest value. Details: Determining Protection Needs. We set Availability to Very High. The justification stands in the relations: the server carries the merchandise management, that carries the order entry, that carries the order processing.
Through the same relations you rate the server’s Criticality in ITAM, and a risk in the ISMS points to the affected assets.

Next steps

How a risk reaches these assets: Assessing Risks. What the ITAM side makes of the rating: Recording ITAM Data. Labels without an English interface value, kept in German: Beziehungen (the relations tab on an asset), trägt and läuft auf (the two directional labels of a relation type).