Assets carry their own data layer on the ISMS tab: protection need across
three security objectives, plus a responsible person. Protection need later
determines a risk’s Impact.
Rate the security objectives
For each security objective you choose one of three levels: Normal, High,
Very High. The pencil icon in the header switches the entire tab into edit
mode.
Example: The Docusnap Sports GmbH SAP database carries Confidentiality
High because of the customer data it stores, and Integrity and
Availability Very High, because a faulty or unavailable database stops
order processing.
A level, once set, can be changed but not reverted to unrated. A security
objective without a value shows as Normal — the scale’s default, not an
unrated state. Clicking Normal on a still-unrated objective therefore submits
nothing, because the display already shows Normal. Keep track outside
Docusnap365 of which assets you have already rated.
Overall protection need
The header carries Total Protection Need — the highest of the three
individual levels (the Maximum Principle). An asset rated Normal, High,
and with no value for availability gets High: the missing value counts as
Normal and does not raise the maximum.
Assign the responsible person
In the Responsibility section, the Responsible field lets you search among
active users. Unlike protection need, the responsible person is removable: an
empty option deliberately clears an existing assignment.
If the current responsible person can no longer be assigned, for example
because their account was deactivated, the field shows the empty option in
edit mode. If you save the tab without choosing another person, Docusnap365
removes the assignment.
Saving
All changes on the tab are saved together. If saving fails, edit mode and
your entries are kept.
Rate protection need before you create risks. Otherwise you assess impact
without protection need, silently carrying the default value Normal for
every asset.
ISMS Fundamentals places the ISMS tab in the
module. Create and Assess Risks shows where protection
need feeds into the assessment. For a complete example, see the tutorial
Setting the Protection Need.