Skip to main content
ISMS covers two tasks in Docusnap365: managing risks and demonstrating that your organization meets its laws and standards. Both areas use the same ISMS data on the asset.

Risk management and compliance

Risk Management

Build risks from threats and vulnerabilities, assess them, and treat them with controls.

Compliance

Activate regulations and assess their objectives individually.
Both areas list a Dashboard as their first entry — two different pages with the same name, one for risk metrics, one for how far activated regulations are met. Risk Management Fundamentals and Understanding Compliance cover both areas in depth.

Protection need on the asset

Independent of the ISMS menu, assets carry their own ISMS tab on their detail page: the protection need across the three security objectives, plus a responsible person. The Total Protection Need is the highest of the three individual levels (Maximum Principle). A security objective with no value counts as Normal and does not raise the maximum.
The ISMS tab belongs to the asset, not to the ISMS menu: it appears on the asset’s detail page, not under ISMS › Risk Management.

Threats, vulnerabilities, and regulations

You create threats by hand or take them from the Threat Catalog. You create vulnerabilities by hand. Which regulations apply is something you activate under Compliance. Risks, controls, threats, and vulnerabilities are linked to each other and to assets through relations; the risk is always the source of the relation.

Limits

The risk matrix’s edge length and zone thresholds come from the global settings and apply tenant-wide — without a custom setting, a 5×5 grid applies. Two tenants with different settings can rate the same risk assessment differently. You set the matrix size under Settings. Determine Protection Needs and Create and Assess Risks cover risk management in depth. The quickest entry point needs neither an asset nor a scan: Assessing NIS-2.