Skip to main content
Assets carry their own data layer on the ISMS tab: protection need across three security objectives, plus a responsible person. Protection need later determines a risk’s Impact.

Rate the security objectives

For each security objective you choose one of three levels: Normal, High, Very High. The pencil icon in the header switches the entire tab into edit mode. Example: The Docusnap Sports GmbH SAP database carries Confidentiality High because of the customer data it stores, and Integrity and Availability Very High, because a faulty or unavailable database stops order processing.
A level, once set, can be changed but not reverted to unrated. A security objective without a value shows as Normal — the scale’s default, not an unrated state. Clicking Normal on a still-unrated objective therefore submits nothing, because the display already shows Normal. Keep track outside Docusnap365 of which assets you have already rated.

Overall protection need

The header carries Total Protection Need — the highest of the three individual levels (the Maximum Principle). An asset rated Normal, High, and with no value for availability gets High: the missing value counts as Normal and does not raise the maximum.

Assign the responsible person

In the Responsibility section, the Responsible field lets you search among active users. Unlike protection need, the responsible person is removable: an empty option deliberately clears an existing assignment.
If the current responsible person can no longer be assigned, for example because their account was deactivated, the field shows the empty option in edit mode. If you save the tab without choosing another person, Docusnap365 removes the assignment.

Saving

All changes on the tab are saved together. If saving fails, edit mode and your entries are kept.
Rate protection need before you create risks. Otherwise you assess impact without protection need, silently carrying the default value Normal for every asset.
ISMS Fundamentals places the ISMS tab in the module. Create and Assess Risks shows where protection need feeds into the assessment. For a complete example, see the tutorial Setting the Protection Need.