User's Guide

User's Guide

Gap Analysis: perform audits

To execute an audit, please click „Gap Analysis" on the left side of the bar. Then, choose an audit template you want to use for your next audit and click on the icon „+” placed on the right side of that template to create a new audit. Provide the necessary information, like a suitable name for this audit, its start and end date, etc., of the new audit and confirm that. Afterward, you will find this new audit in the list of available audits at the top of the page.

Bildschirmfoto 2024-06-18 um 16.48.16.png

For each audit, you can choose between the following actions:

  • click on the icon „play“ to start/continue processing the questionnaire,

  • click on the icon „export“ to generate a PDF report,

  • click on the icon „lock“ to freeze this audit (set to non-editable), or

  • click on the icon „trash“ to delete this audit.

Bildschirmfoto 2024-06-18 um 16.50.13.png

Also, you can modify or extend the collection of audit templates:

  • click on „Create template“ to generate a new one,

  • click on „Import ISO template“ to upload a licensed PDF to extract all relevant controls into a new template,

  • click on „Restore template“ to overwrite an existing template or create one based on the provided definitions or

  • click on „+“ to use this template for generating a new audit,

  • click on „edit“ to modify the definitions of that template by adding or removing controls and sub-controls,

  • click on „export“ to download the definitions of that template as a backup (for custom templates only),

  • click on „trash“ to delete that template (for custom templates only)

 

By editing an audit template, you can easily:

  • click on „+“ to generate a new control as child below the current entry,

  • click on „down“ to push a control one position down,

  • click on „up“ to push a control one position up,

  • click on „trash“ to delete that control,

  • click on the title of the chosen control to update the text,

  • click into the text of the chosen control to maintain this: Use the editor to modify and format your text, or click on the icon „stamp“ to insert certain GRC fields like checkboxes, radio buttons, numbers, or text fields. These are template/audit internal fields, not Jira custom fields! If you have finished the work on all your controls, please click on „save template“ to store your changes.

  • click on „trash“ to delete that template (for custom templates only)

Bildschirmfoto 2024-06-18 um 16.52.52.png

Risk Management

Risk management is a cycle of identifying, assessing, and mitigating risks to achieve an organization's objectives. The process is iterative and continuous, involving several key steps:

  1. Risk Identification: Recognizing potential risks that could affect the organization. This includes identifying internal and external factors that could pose threats.

  2. Risk Assessment: Evaluating the identified risks to understand their potential impact and likelihood. This step often involves qualitative and quantitative analysis to prioritize risks based on their severity.

  3. Risk Mitigation/Control: Developing strategies and actions to reduce the likelihood and/or impact of risks. This might include implementing policies, procedures, or physical controls to manage risks.

  4. Risk Monitoring and Review: Continuously tracking identified risks and the effectiveness of risk mitigation strategies. This step ensures that risks are controlled and any changes in the risk environment are detected and managed promptly.

  5. Risk Communication and Reporting Ensure that relevant stakeholders are informed about risks and the measures in place to manage them. Effective communication helps maintain transparency and supports decision-making processes.

  6. Risk Review and Improvement: Regularly review and update the risk management process to ensure its effectiveness and make necessary adjustments based on new information or changes in the organization's environment.

 

This cyclical process helps organizations proactively manage risks and improve their resilience against potential threats.
As a project administrator, switch to "project settings" and select "Governance, Risk & Compliance" as a sub-menu item of "Apps." Then, choose "objects" to define your company's hazards, processes, and all relevant departments. Finally, specify your email notifications, such as auto-reminders for re-assessments per risk class or email escalations of overdue measures.
Please click „Risk Management“on the left side of the bar. Then, you can create your assets, link them to Jira Insight Assets if available, create asset categories and define hazards per category, create relevant risks per asset/asset group or asset-neutral for your company in general, force risk assessments by all responsible persons in charge, define measures and trace them via Jira workflows. Also, as a responsible person in charge or an information security officer (ISO), you can export your assets into a WORD document containing all related hazards, risks, measures, and findings. Due to the authorization concept, some functionality is limited to all members of the project role "ISO" or the persons responsible for it.

Assets, Hazards & Risks, Measures, IS-Events / -Incidents, and Findings

As a technical or functional responsible, you can only watch and maintain your assets, etc.

Bildschirmfoto 2024-06-18 um 16.59.25.png

In the same manner, you should define your company’s hazards, which become risks being applied to the related assests. Always, you can create finding as part of an audit or during daily recognizations.

As an Information Security Officer (ISO), you are responsible for the information security management system (ISMS) and must create all related entities, such as assets.