Skip to main content
A risk is assessed through likelihood and Impact. The level of the impact comes from the protection need of the affected assets. We set the protection need for the systems behind one application and find it again in the risk wizard. Prerequisite: an inventoried estate.

Starting point

Docusnap Sports GmbH runs its merchandise management on an SAP system: a database, an application server, a web front end. The scan captured all three. On the ISMS tab all three read Normal — the default value, not an assessment.

1. Decide which assets get a rating

The protection need hangs on the individual asset, not on the application. We rate the three systems that carry the merchandise management.
Not every type carries the ISMS tab. Without the tab, no protection need can be set for that type. In the Assets step, the risk wizard only offers types that carry this tab.

2. Set the security objectives

1

Open the ISMS tab

We open the SAP database, tab ISMS. It has the sections Protection Needs and Responsibility.
2

Switch to edit mode

The pencil icon in the header switches the whole tab into edit mode.
3

Choose the levels

Confidentiality, Integrity and Availability, each Normal, High or Very High. For the database: Confidentiality High (customer data), Integrity Very High (wrong stock levels lead to wrong deliveries), Availability Very High (without it, order processing stands still).
4

Assign responsibility

In the Responsibility section we choose a person in the Responsible field. The field is optional.
5

Save

Save. We then repeat the steps for the application server and the web front end.

3. Check the total value

Total Protection Need in the header is the highest of the three levels (maximum principle). The database therefore has Very High. The value appears as we choose, before saving.
A level once set can be changed, but not withdrawn. A security objective with no entry stands at Normal. The interface does not distinguish between “assessed as Normal” and “not assessed”. Keep a record of which assets you have assessed.

4. Find the protection need again in the risk

Under ISMS › Risk Management › Risks, Risk opens the wizard. In the Assets step we choose the three systems. In the Assessment step, below the matrix, stands the section Protection Needs of Affected Assets: the highest level per security objective across all selected assets, and below it, per asset, the three levels. While setting the Impact, the protection need of the affected systems therefore stands next to the matrix.
The section only appears if systems are chosen in the Assets step. That step is optional.
Assess first, then rate. A protection need changed later does not change an existing risk assessment.

Next steps

The assessed systems turn into a risk: Carrying a Risk Through to Monitoring. The ISMS tab in detail: Determining Protection Needs. Levels and scales: ISMS Reference.