Skip to main content
A risk goes through three phase changes from Assessed to Monitoring. Each one has a precondition. We walk the chain through one example and name, for every change, what blocks it.

Starting point

Docusnap Sports GmbH runs its merchandise management on an SAP system. The backup sits on the same network. Ransomware on the application server reaches the backup as well. The protection need of the systems is already set — see Setting the Protection Need.

1. Provide threat and vulnerability

A risk needs at least one threat and one vulnerability. Both are entries of their own, reusable across risks.
1

Import the threat

Under ISMS › Risk Management › Threats, Import opens the Threat Catalog. We search for “Ransomware” and take over the hit. Imported entries show their origin in the Source column.
2

Create the vulnerability

Under Vulnerabilities we create the entry “Backup not network-segregated” through Vulnerability, with Category and a description. There is no catalog for vulnerabilities.

2. Create and assess the risk

Risk opens the wizard. Name Ransomware infection of the SAP database; in the Assets step the three systems of the merchandise management; in the following steps the threat and the vulnerability. All steps: Assessing Risks. In the Assessment step we set both ratings: Current Assessment Possible × Catastrophic, Target Assessment Unlikely × Major. Strategy Mitigate. In the Owner field we enter a person.
With all four assessment values, the risk comes into being in the Assessed phase. If a value is missing, it stands in Identified. The Summary step names the phase.
We open the risk, tab Controls. Control opens a dialog: link an existing control or create a new one. We create Offline backup of the SAP database: Recurrence Recurring, Interval 3, Unit Months.
Only a recurring control has the Evidence tab. With One-time it is missing. See Evidencing Recurring Controls.

4. Carry out the phase changes

The lifecycle stands in the Assessment tab. Every change requires a reason in the Reason for the Phase Change field. If a precondition is not met, the change is not carried out. The hint names the reason; where a control is missing, it offers a jump into the Controls tab.
The risk matrix and the treatment strategy are editable only in the Assessed phase. Change the assessment before you leave the phase. Otherwise the way back leads through another phase change with a reason.

5. Working in monitoring

In Monitoring, the Assessment tab shows the state of the review: overdue, due within the next 28 days, or not due. Complete Review writes an entry into the Review tab with Reviewed on, Reviewed by and Result. The result text is mandatory.
If the review date is removed while in Monitoring, Docusnap365 resets the phase to Assessed on saving and reports this beforehand.

6. Reclassify after the review

Two paths lead from Monitoring back into Assessed:
Review + Reassess cannot be undone. A confirmation appears before it runs. For a reclassification without losing the assessment, use the phase change.

Next steps

Evidencing the control: Evidencing Recurring Controls. The same control for a regulation objective: Assessing Objectives.