> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Setting the Protection Need

> Set the protection need for the systems behind one application and find it again in the risk wizard as the basis for the impact.

A risk is assessed through likelihood and *Impact*. The level of the impact comes
from the protection need of the affected assets. We set the protection need for
the systems behind one application and find it again in the risk wizard.

**Prerequisite:** an inventoried estate.

## Starting point

Docusnap Sports GmbH runs its merchandise management on an SAP system: a
database, an application server, a web front end. The scan captured all three.
On the *ISMS* tab all three read *Normal* — the default value, not an
assessment.

## 1. Decide which assets get a rating

The protection need hangs on the individual asset, not on the application. We
rate the three systems that carry the merchandise management.

<Note>
  Not every type carries the *ISMS* tab. Without the tab, no protection need can
  be set for that type. In the *Assets* step, the risk wizard only offers types
  that carry this tab.
</Note>

## 2. Set the security objectives

<Steps>
  <Step title="Open the ISMS tab">
    We open the SAP database, tab *ISMS*. It has the sections *Protection Needs*
    and *Responsibility*.
  </Step>

  <Step title="Switch to edit mode">
    The pencil icon in the header switches the whole tab into edit mode.
  </Step>

  <Step title="Choose the levels">
    *Confidentiality*, *Integrity* and *Availability*, each *Normal*, *High* or
    *Very High*. For the database: *Confidentiality* *High* (customer data),
    *Integrity* *Very High* (wrong stock levels lead to wrong deliveries),
    *Availability* *Very High* (without it, order processing stands still).
  </Step>

  <Step title="Assign responsibility">
    In the *Responsibility* section we choose a person in the *Responsible*
    field. The field is optional.
  </Step>

  <Step title="Save">
    *Save*. We then repeat the steps for the application server and the web
    front end.
  </Step>
</Steps>

## 3. Check the total value

*Total Protection Need* in the header is the highest of the three levels
(maximum principle). The database therefore has *Very High*. The value appears
as we choose, before saving.

<Warning>
  A level once set can be changed, but not withdrawn. A security objective with no
  entry stands at *Normal*. The interface does not distinguish between "assessed
  as *Normal*" and "not assessed". Keep a record of which assets you have
  assessed.
</Warning>

## 4. Find the protection need again in the risk

Under *ISMS › Risk Management › Risks*, *Risk* opens the wizard. In the *Assets*
step we choose the three systems.

In the *Assessment* step, below the matrix, stands the section *Protection
Needs of Affected Assets*: the highest level per security objective across all
selected assets, and below it, per asset, the three levels. While setting the
*Impact*, the protection need of the affected systems therefore stands next to
the matrix.

<Note>
  The section only appears if systems are chosen in the *Assets* step. That step
  is optional.
</Note>

<Tip>
  Assess first, then rate. A protection need changed later does not change an
  existing risk assessment.
</Tip>

## Next steps

The assessed systems turn into a risk:
[Carrying a Risk Through to Monitoring](/docs/en/isms/tutorial-risk). The *ISMS* tab
in detail: [Determining Protection Needs](/docs/en/isms/protection-needs). Levels and
scales: [ISMS Reference](/docs/en/isms/reference).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.