Analyze protection needs

Purpose

The protection needs analysis determines the information security and data protection requirements.

Basic idea

A protection needs analysis must be conducted for each IT project. This ensures that the ISDP aspects are taken into account from the start.

HERMES-specific

If the protection needs analysis shows that enhanced protection is necessary, an ISDP concept with an in-depth risk analysis must be designed during solution development.

Basis/prerequisites

Activities

  1. Analyze information security and protection needs.
  2. Perform risk analysis.
  3. Review information security and data protection requirements and assess the impact on the study, project execution, and the envisaged solution.
  4. Coordinate protection needs analysis with the controlling and compliance bodies.

Outcomes

Relationships

Module Task Task responsibility Outcome Involved in creation of outcome
Project foundations Analyze protection needs ISDP manager Protection needs analysis ISDP manager, Project management