Starting point
Docusnap Sports GmbH runs its merchandise management on an SAP system. The backup sits on the same network. Ransomware on the application server reaches the backup as well. The protection need of the systems is already set — see Setting the Protection Need.1. Provide threat and vulnerability
A risk needs at least one threat and one vulnerability. Both are entries of their own, reusable across risks.1
Import the threat
Under ISMS › Risk Management › Threats, Import opens the Threat
Catalog. We search for “Ransomware” and take over the hit. Imported
entries show their origin in the Source column.
2
Create the vulnerability
Under Vulnerabilities we create the entry “Backup not network-segregated”
through Vulnerability, with Category and a description. There is no
catalog for vulnerabilities.
2. Create and assess the risk
Risk opens the wizard. Name Ransomware infection of the SAP database; in the Assets step the three systems of the merchandise management; in the following steps the threat and the vulnerability. All steps: Assessing Risks. In the Assessment step we set both ratings: Current Assessment Possible × Catastrophic, Target Assessment Unlikely × Major. Strategy Mitigate. In the Owner field we enter a person.With all four assessment values, the risk comes into being in the Assessed
phase. If a value is missing, it stands in Identified. The Summary step
names the phase.
3. Link a control
We open the risk, tab Controls. Control opens a dialog: link an existing control or create a new one. We create Offline backup of the SAP database: Recurrence Recurring, Interval 3, Unit Months.Only a recurring control has the Evidence tab. With One-time it is missing.
See Evidencing Recurring Controls.
4. Carry out the phase changes
The lifecycle stands in the Assessment tab. Every change requires a reason in the Reason for the Phase Change field.
If a precondition is not met, the change is not carried out. The hint names the
reason; where a control is missing, it offers a jump into the Controls tab.