| A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | Requirement | Description | refines | Status | Operator Expertise | Scope | ||||||||||||||||||||
2 | Dashboard | |||||||||||||||||||||||||
3 | SRQ42 - The system shall be divided into mutiple assessment sections, called Aggregated Views, where each is dedicated to specific functional requirements during the assessment | Provide a user-friendly web-based interface accessible to the operator that ensures intuitive navigation throughout the different View for competent operators Order Aggregated Views from top-down approach from high-level overview to in-detail analysis accoring to frameworks for auditing incident management (ISO 19011, ISO 19600 and 37301) Define and provide an Aggregated View for: - Accessing the organization's policy for IM process implementation and evaluation against the Integrated IM reference model (SRQ1) - Indent and Process statistics regarding the detection and activation as well as resolving and closure of incidents (SRQ11) - High-Level overview for summarized information (SRQ6) - Compliance development within selected time period (SRQ13) - Characteristics and details of selected incidents (SRQ15) - What-if analysis (SRQ32) - Cost model parameterization (SRQ41) - Global assessment progress (SRQ43) | DRQ1 - User Interface and Competence | Approved | Not required | Interaction Analysis | ||||||||||||||||||||
4 | SRQ1 - The system shall provide an Aggregated View that allows the operator to access the organization's policy for IM process implementation and evaluation against the integrated IM reference model | Display the organization's policy documents related to IM process implementation which are part of the Information Security Management System to the operator Display the integrated IM reference model through visualization tools Support the operator in identifying the specific sections in the organization's policy for IM process implementation that describe how an incident is handled by definition and which data about IM are recorded in logs Allow the operator to access and browse the specific sections of the organization's policy for IM process implementation that describe how an incident is handled by definition, i.e., which incident management steps must/should be taken including activation and closing of an incident, and which variables must/should be carried by an IM log Display the functionalities to map the organization's policy for IM process implementation to the integrated IM reference model | FRQ3 - The operator shall be able to analyse the organization's policy for IM process implementation against a reference model FRQ1 - In order to allow the operator to perform an investigation the system shall provison the accessibility to and adequate handling of resources under investigation and in use DRQ5 - Assessment Execution | Approved | Required | Interaction Analysis | ||||||||||||||||||||
5 | SRQ6 - The system shall provide an Aggregated View to the operator with a high-level overview that displays summarized information on analyzed incidents, average values for key performance metrics, the integrated IM reference model and required assessment activities | Display the functionality to set the time period for which the assessment takes place to the operator Display summarized information on the number and range of selected incidents and different execution variants to the operator Display the average values for the overall incident trace fitness and non-compliance cost for the selected incidents to the operator Display the integrated IM reference model through visualization tools to the operator Display the checklist that contains all the security controls to the operator and allow to modify the list of security controls | FRQ4 - The operator shall be capable to see a high-level overview of analyzed incidents, the reference model and required assessment activities DRQ2 - Assessment Management DRQ5 - Assessment Execution | Approved | Required | Interaction Analysis Visualization | ||||||||||||||||||||
6 | SRQ11 - The system shall provide an Aggregated View that contains incidents and process statistics regarding the activation and detection as well as resolving and closure of incidents | Display incidents with the most deviation errors through visualization tools regarding the activation and detection as well as resolving and closing of incidents Display metrics for time to activation, time to detection, false positive and true negative rate if available Display impact metrics for downtime duration, amount of data loss, estimated costs of damage and SLA violations if available Display tools that allow the operator to highlight and identify areas of concern based on the metrics for detection and activation as well as resolving and closing of incidents Display the functionalities to apply statistical analysis algorithms to the incidents in the selected time period Display the functionalities to apply pattern recognition algorithms to the incidents in the selected time period Display a functionality that allows to define and search for patterns in the incidents of the selected time period Display the found patterns and through appropiate visualization tools Display tools that allow the operator to highlight and identify areas of concern based on the found patterns | FRQ6 - The operator shall be able to identify and analyze procedure and impact metrics of resolved and closed incidents FRQ7 - The operator shall be able to identify the temporal compliance development and areas of concern DRQ5 - Assessment Execution | Approved | Not required | Interaction Analysis | ||||||||||||||||||||
7 | SRQ13 - The system shall provide an Aggregated View that allows to analyze the compliance development within the selected time period | Display a visual representation illustrating the evolution of incident trace fitness and non-compliance cost for incidents against the integrated IM reference model over time that allows filtering for different non-compliance causes to identify trends and patterns Display a visual representation that illustrates the distribution of fitness and non-compliance cost for incidents to the operator to identify trends and patterns Display the trends and through appropiate visualization tools Display tools that allow the operator to highlight and identify areas of concern based on the found trends | FRQ7 - The operator shall be able to identify the temporal compliance development and patterns of concern CMRQ4 - The operator shall be able to analyze how non-compliance cost is distributed in order to identify patterns and trends DRQ5 - Assessment Execution | Approved | Not required | Interaction Analysis Visualization | ||||||||||||||||||||
8 | SRQ15 - The system shall provide an Aggregated View that allows to analyze incident characteristics and details of selected incidents that are critical or belong to areas of concern | Display all incidents that belong to certain identified areas of concern such as trends and patterns or individual traces in critical compliance severity regarding fitness and/or non-compliance costs Display visualization tools to analyze the characteristics of mutiple or individual incidents that belong to the identified areas of concern | FRQ7 - The operator shall be able to identify the temporal compliance development and areas of concern FRQ9 - The operator shall be able to identify and analyze details of the most critical errors CMRQ5 - The operator shall be capable to prioritize and select incidents based on their compliance severity in order to isolate severity ranges and determine their root causes DRQ5 - Assessment Execution | Approved | Required | Interaction Analysis Visualization | ||||||||||||||||||||
9 | SRQ32 - The system shall provide an Aggregaetd View that is dedicated to the What-if analysis | Display a functionality to the operator to enable or disable what-if analysis Display functionality to the operator to interact with the basic and advanced tools that are provided by the system to perform what-if analysis Provide a warning that is displayed system-wide when what-if analysis is currently enabled Display the influence on the overall IM process compliance through percentage changes of metrics against their initial value Display a second data input with different colouring for the time-oriented visualization tools that are used that show the change in temporal compliance development by performing what-if analysis | FRQ8 - The operator shall be capable to control or correct individual or multiple incident traces in order to predict the influence on the overall IM compliance DRQ5 - Assessment Execution | Approved | Required | Interaction Analysis | ||||||||||||||||||||
10 | SRQ41 - The system shall provide an Aggregated View that is dedicated to cost model parameterization | Display the automatically suggested parameterizations and the KPI they are based upon Dispaly a functionality and provide support for the operator to select and load a suggested deviation parameterization from the system Display the defined mechanisms to adjust a suggested deviation parameterization or to define a deviation paramterization from scratch by manually setting each parameter of the cost function | CMRQ2 - The operator shall be able to adjust a suggested deviation parameterization in order to build own parameterization that reflects assessment preferences DRQ5 - Assessment Execution | Approved | Required | Interaction | ||||||||||||||||||||
11 | SRQ43 - The system shall provide an Aggregated View that is dedicated to the global assessment progress | Display the global progress of assessement execution as a summary of findings, areas of concern and non-conformities as well as on the status of security controls contained in the checklist | DRQ7 - Reporting and Analytics | Approved | ||||||||||||||||||||||
12 | Report | |||||||||||||||||||||||||
13 | SRQ20 - The system shall enable the operator to produce an assessment report from the reported sections | Provide the necessary high-level overview of an assessment of an IM log that is required for submission to the governing body or top management Provide the technical in-depth perspective of an assessment of an IM log that is required by an assessor or, if desired, by an auditor Define report section for: - Deviations found between organization's policy for IM process implementation and integrated IM reference model (SRQ5) - Assessment criteria and justification how results will be evaluated (SRQ9) - Detection and activation as well as resolving and closure of incidents (SRQ12) - Temporal compliance development and areas of concern (SRQ16) - Most critical incidents incidents in terms of fitness, non-compliance and execeeded response times (SRQ19) - Assessment time and past assessments (SRQ21) - Assessment results, i.e., findings and non-conformities (SRQ25) - Recommendations from an assessment (SRQ26) - What-if analysis (SRQ33) | FRQ10 - The operator shall be capable to produce an assessment report from analysis and evaluation of the IM log DRQ7 - Reporting and Analytics | Approved | Not required | Reporting | ||||||||||||||||||||
14 | SRQ5 - The system shall generate a report section that lists any deviations found between the organization's policy for IM process implementation and the integrated IM reference model | Generate a section in the assessment report that lists all detected deviations and interesting information between the organization's policy for IM process implementation and the integrated IM reference model Include descriptions for each deviation together with its location within the policy documents Classify detected deviations in the report section based on severity levels from predefined criteria Provide recommendations by the operator for aligning the organization's policy for IM process implementation with the integrated IM reference model based on the detected deviations that are actionable and alllow addressing and resolving deviations Include comments regarding the historical development of the organization's policy for IM process implementation, if considered to be appropiate in the current context, made by the operator | FRQ3 - The operator shall be able to analyse the organization's policy for IM process implementation against a reference model DRQ2 - Assessment Management | Approved | Required | Interaction Reporting | ||||||||||||||||||||
15 | SRQ9 - The system shall generate a report section that includes the assessment criteria and justfies how results will be evaluated against assessment criteria | Include the assessment criteria provided by the operator Include the operators narrative justification on how the assessment results, i.e., findings and non-conformities, will be evaluated against the assessment criteria | FRQ4 - The operator shall be capable to see a high-level overview of analyzed incidents, the reference model and required assessment activities | Approved | Required | Interaction Reporting | ||||||||||||||||||||
16 | SRQ12 - The system shall provide a report section dedicated to the detection and activation as well as resolving and closure procedure of incidents | Include the most common execution variants and most critical incidents regarding non-compliance costs for detection and activation as well as resolving and closing of incidents Include average metrics for time to activation, time to detection, false positive and true negative rate if available Include individual metrics for time to activation, time to detection, false positive and true negative rate if available for incidents that are highlighted as concerning Include average impact metrics for downtime duration, amount of data loss, estimated costs of damage and SLA violations if available Include individual impact metrics for downtime duration, amount of data loss, estimated costs of damage and SLA violations if available for incidents that are highlighted as concerning Include comments by the operator regarding the overall and individual compliance performance of incidents for activation and detection as well as resolving and closure procedure | FRQ6 - The operator shall be able to identify and analyze procedure and impact metrics of resolved and closed incidents FRQ7 - The operator shall be able to identify the temporal compliance development and areas of concern | Approved | Required | Interaction Reporting | ||||||||||||||||||||
17 | SRQ16 - The system shall provide a report section that is dedicated to temporal compliance development and areas of concern | Include the temporal compliance development as well as the average value for the selected incident time period Include areas of concern that were highlighted/flagged by the operator automatically and for each area of concern allow to include the justification in the form of the identified trends and patterns Include comments by the operator for systemic weaknesses and threats and proposed actions that are aimed towards reducing or eradicating areas of concern Include comments by the operator to set the temporal compliance development in context | FRQ7 - The operator shall be able to identify the temporal compliance development and areas of concern | Approved | Required | Reporting Interaction | ||||||||||||||||||||
18 | SRQ19 - The system shall provide a report section dedicated to the most critical incidents in terms of fitness, non-compliance costs and exceeded response times | Include the set thresholds for fitness and non-compliance cost as well as their justification Include all incidents that fall within the set thresholds for fitness and/or non-compliance costs Include for each critical incident, a summary of the execution trace and, if applicable, exceeded response or resolve times that justify the classification as critical Include comments by the operator for each critical incident if desired | FRQ9 - The operator shall be able to identify and analyze details of the most critical errors | Approved | Required | Reporting Interaction | ||||||||||||||||||||
19 | SRQ21-A - The system shall provide a report subsection within a section that is dedicated to the assessed time period, past asessments and changes to the used assessment framework if available | Provide information on whether assessments were regularly performed prior to the current assessment and if not why if those information are available Provide the selected time period for which the assesment takes place Include comments about past assessments if desired by the operator that aim to summarize the improvements or changes to the IM that were implemented based on the results of the past assessments Include comments about past assessments if desired by the operator that give notice if changes to the assessment procedure/workflow are introduced since the last assessment like the assessment against a different framework | FRQ10 - The operator shall be capable to produce an assessment report from analysis and evaluation of the IM log DRQ7 - Reporting and Analytics | Approved | Not required | Reporting Interaction | ||||||||||||||||||||
20 | SRQ21-B - The system shall provide a report subsection within a section that is dedicated to the versioning and, if applicable, changes in the versioning of the currently used assessment framework if available | Include comments about the name and versioning of the currently used assessment framework by the operator Include comments about changes to the versioning of the currently used assessent framework for justification if applicable by the operator | FRQ10 - The operator shall be capable to produce an assessment report from analysis and evaluation of the IM log DRQ7 - Reporting and Analytics | Approved | ||||||||||||||||||||||
21 | SRQ25 - The system shall store all the reports to allow reproducibility of the analyses | Include for each asessment result the assessment criteria it is evaluated against Include comments by the operator that explain assessment findings including referring to past assesment reports in order to communicate recurring issues Include comments by the operator that explain non-conformities as well as grade them qualitative- or quantitative-wise | FRQ10 - The operator shall be capable to produce an assessment report from analysis and evaluation of the IM log DRQ7 - Reporting and Analytics | Approved | Required | Reporting Interaction | ||||||||||||||||||||
22 | SRQ26 - The system shall provide a report section that provides recommendations from an assessment | Include comments by the operator regarding recommendations for an updated organization's policy for IM process implemenation as well as updated and/or new controls to fulfill the organization's policy for IM process implemenation | FRQ10 - The operator shall be capable to produce an assessment report from analysis and evaluation of the IM log | Approved | Required | Reporting Interaction | ||||||||||||||||||||
23 | SRQ33 - The system shall provide a report section that is dedicated to what-if analysis | Include the basic and advanced functions that were used and which impact on the IM log KPIs was observed Include the change in temporal compliance development that was observed from what-if analysis Include comments by the operator that set the what-if analysis into context to the actual assessment | FRQ8 - The operator shall be capable to control or correct individual or multiple incident traces in order to predict the influence on the overall IM compliance | Approved | Required | Reporting | ||||||||||||||||||||
24 | SRQ44 - The system shall provide a functionality to export the produced assessment report | Export the assessment reports in common and well-supported data formats such as PDF, DOCX and XLSX | DRQ7 - Reporting and Analytics | Approved | Not required | Interaction Reporting | ||||||||||||||||||||
25 | Analytics Features | |||||||||||||||||||||||||
26 | SRQ3 - The system shall provide a functionality to compare the organization's policy for IM process implementation with the integrated IM reference model | Provide a functionality to compare specific sections of the organization's policy documents for IM process implementation with corresponding sections of the integrated IM reference model Allow the operator to map sections of the organization's policy for IM process implemenation to states of the integrated IM reference model Enable the operator to highlight differences and similarities between the organization's policy for IM process implementation and the IM reference model in a text-based format | FRQ3 - The operator shall be able to analyse the organization's policy for IM process implementation against a reference model DRQ2 - Assessment Management | Approved | Required | Analysis | ||||||||||||||||||||
27 | SRQ4 - The system shall detect possible deviations between the organization's policy for IM process implementation and the integrated reference model if prior is processable | Detect possible deviations by performing automatic mapping between sections of the organization's policy for IM process implementation and states of the integrated IM reference model if prior is delivered in an appropiate format for automatic processing Consider any instance where the organization's policy for IM process implementation does not align with the requirements or recommendations of the reference model as possible deviation List the possible deviations in a text-based format that enables the operator to manually recitfy possible deviations suggested by the system easily | FRQ3 - The operator shall be able to analyse the organization's policy for IM process implementation against a reference model DRQ2 - Assessment Management | Approved | Not required | Analysis | ||||||||||||||||||||
28 | SRQ7 - The system shall enable the operator to check if information is complete, correct, consistent and current | Verify the completeness of the IM log by ensuring that all required fields are existent and populated Verify the accuracy of the data provided by the IM log by comparing it with trusted sources and implement data verification mechanisms such as checksums or hash functions if applicable Ensure consistency across the different fields and IM events with appropiate consistency checking mechanisms Check timestamps of IM log events to ensure it is up-to-date and implement mechanisms to flag outdated data | FRQ4 - The operator shall be capable to see a high-level overview of analyzed incidents, the reference model and required assessment activities | Approved | Not required | Analysis | ||||||||||||||||||||
29 | SRQ8 - The system shall provide digital checklists as well as the possibility to define and/or automatically suggest assessment security controls | Provide a checklist functionality that may be used by an operator to define the desired asessment security controls Generate a costumizable checklist template that contains common security controls Suggest common assessment security controls based on selected IM framework or standard that the operator may find useful and import in the assessment checklist automatically Evaluate common assessment security controls automatically regarding appropiate ranges of KPIs of the IM log if available Provide a the status of all security controls as a measure of global progress to the operator | FRQ4 - The operator shall be capable to see a high-level overview of analyzed incidents, the reference model and required assessment security controls DRQ3 - Templates DRQ11 - Automated Assessment Security Controls | Approved | Required | Interaction | ||||||||||||||||||||
30 | SRQ10 - The system shall enable the operator to identify the activation and detection as well as resolving and closure procedure of incidents through suitable metrics | Highlight the most common execution variants for activation and detection as well as resolving and closing incidents before context-aware trace alignment Highlight the most critical incidents regarding activation and detection as well as resolving and closure procedure with respect to fitness and non-compliance costs Highlight the metrics for detection and activation as well as resolving and closing of incidents from additional attributes carried in the IM log | FRQ6 - The operator shall be able to identify and analyze procedure and impact metrics of resolved and closed incidents FRQ7 - The operator shall be able to identify the temporal compliance development and areas of concern | Approved | Not required | Analysis | ||||||||||||||||||||
31 | SRQ14 - The system shall enable the operator to analyze multiple incidents to identify trends and patterns as areas of concern | Provide a functionality that allows to explore the number of active/closed incidents and time to activate and resolve over time as well as the correlated Fitness and Non-compliance Cost Provide a functionality that allows to explore the distribution of Fitness and Non-Compliance Cost for incidents Perform trend and pattern analysis on the selected incident time period with appropiate techniques such as statistical analysis (descriptive statistics, time series analysis, etc.) and pattern recognition algorithms (clustering, anomaly detection, frequent pattern mining, etc.) Provide a functionality that allows to define and search for patterns (e.g., variants) in selected incident time period Provide appropiate visualization tools that allow the operator to identify trends and patterns manually Provide a function to highlight/tag areas of concern based on identified trends and patterns | FRQ7 - The operator shall be able to identify the temporal compliance development and areas of concern CMRQ4 - The operator shall be able to analyze how non-compliance cost is distributed in order to identify patterns and trends | Approved | Required | Analysis | ||||||||||||||||||||
32 | SRQ17 - The system shall enable the operator to prioritize and analyze details of the most critical incidents with respect to fitness and non-compliance cost individually | Define a qualitative scale for compliance severity that divides the range of values in fitness and non-compliance costs into categories low, moderate, high, critical Provide a function that allows the operator to filter for incidents in certain compliance severity categories regarding fitness and/or non-compliance costs or previously identified areas of concern in order to allow a prioritization of incidents with higher severity Allow to inspect the details of (selected) incidents individually for technical analysis | FRQ9 - The operator shall be able to identify and analyze details of the most critical errors CMRQ5 - The operator shall be capable to prioritize and select incidents based on their compliance severity in order to isolate severity ranges and determine their root causes | Approved | Not required | Interaction Analysis | ||||||||||||||||||||
33 | SRQ18 - The system shall indicate missing escalation steps when proper response times were exceeded | Define proper response time from detection to closing or activation to resolving for incidents of an IM trace based on average values of the provided IM log or set by operator manually Indicate possible missing internal escalation if time between execution steps is beyond certain threshold or if response time is exceeded Provide, if available, information on wether an interm report after exceeding organiaztion's threshold for response time was generated for an incident | FRQ9 - The operator shall be able to identify and analyze details of the most critical errors | Approved | Required | Interaction Analysis | ||||||||||||||||||||
34 | SRQ23 - The system shall retain assessment findings, areas of concern and non-conformities during an assessment | List assessment findings, ares of concern and non-conformities in tabular way and sort by compliance severity by default Allow managing of assessment findings, ares of concern and non-conformities in such a way that adding/removing/replacing/grouping/enriching issues is possible Document for each finding, area of concern and non-conformity how they have been collected and which corrective actions have been taken to leverage or supress specific results Provide a summary of findings, areas of concern and non-conformitries as a measure of global progress to the operator | FRQ10 - The operator shall be capable to produce an assessment report from analysis and evaluation of the IM log DRQ13 - Issue Tracking DRQ6 - Issue Management | Approved | Required | Interaction | ||||||||||||||||||||
35 | SRQ27 - The system shall implement and maintain the controls to monitor and assess the IM log in order to meet compliance obligations and deduce compliance risks | Support the operator in assessing the IM log against the compliance obligations communicated in the organization's policy for IM process implementation and the integrated IM reference model Allow the operator to deduce compliance risks after assessing the IM log | FRQ5 - The operator shall be able to timely identify and analyze the main process errors using predefined metrics and methods for analysis and evaluation | Approved | Not required | Analysis | ||||||||||||||||||||
36 | SRQ31 - The system shall provide the operator with basic tools to perform what-if analysis towards the IM log to determine if changes to organization's IM affect the IM compliance performance | Provide basic functions such as ignoring or fixing, with respect to fitness or non-compliance cost, specific incidents in the IM log based on their identifier in the overall compliance assessment Provide advanced functions that allow to query for specific patterns in the IM log and exclude the resulting list of incidents based on their identifiers from the overall compliance assessment Provide advanced function to manipulate specific variables of one or mutiple incidents in the IM log | FRQ8 - The operator shall be capable to control or correct individual or multiple incident traces in order to predict the influence on the overall IM compliance | Approved | Required | Interaction Analysis | ||||||||||||||||||||
37 | SRQ38 - The system shall suggest multiple deviation paramterizations based on different IM log KPIs | Provide an explanation to the operator how automatic suggestions for deviation parameterizations work Analyze, if available, different IM KPIs such as the trace fitness, loss due to SLA violations and costs associated with person-hours spend or in relation with organization KPIs, taken from set of additional information of the IM log Deduce a cost function parameterization, for the cost model based on every available IM KPI and suggest to the operator | CMRQ1 - In order to support the operator the system shall be able to suggest mutiple deviation parameterizations based on automated analysis of different IM log KPIs | Approved | Not required | Interaction | ||||||||||||||||||||
38 | SRQ39 - The system shall allow the operator to adjust a suggested deviation parameterization that reflects assessment preferences | Provide an explanation to the operator how the parameters of the deviation parameterization affect the cost function of the cost model Provide mechanisms for each incident state from the integrated reference model for each error category (missing, repitition and mismatch) and error weights for error category that allow to modify the values of each parameter of the cost function | CMRQ2 - The operator shall be able to adjust a suggested deviation parameterization in order to build own parameterization that reflects assessment preferences | Approved | Required | Interaction | ||||||||||||||||||||
39 | SRQ40 - The system shall allow the operator to define a new context-aware deviation parameterization independently | Provide an explanation to the operator of how the deviation parameterization works Provide mechanisms for each incident state from the integrated reference model for each error category (missing, repitition and mismatch) and error weights for error category that allow to set the values of each parameter | CMRQ3 - The operator shall be able to define a new context-aware deviation parameterization in order to handle specific cases for costs of non-compliance causes or if parameterizations shall be based on unidentified IM log KPIs or other reasoning | Approved | Required | Interaction | ||||||||||||||||||||
40 | SRQ47 - The system shall be capable to limit the assessed data of the IM log to a specific time period | Provide functionality to set time period in which the assessment takes place and only consider the incidents within the selected time period Set the default time period to 1 year from the actual current date | DRQ9 - Frontend Scalability | Approved | Not required | Interaction Analysis | ||||||||||||||||||||
41 | Modeling | |||||||||||||||||||||||||
42 | SRQ2 - The system shall model an IM reference model based on a standard or framework for IM processes | Require the definition of a standard reference model for IM processes such as ISO 27035 or NIST SP-800-61 that is to be delivered by the operator and then implemented into the system Implement the reference model in an appropiate representation format so that it can serve as a benchmark for the organization's IM process implementation and IM log | FRQ3 - The operator shall be able to analyse the organization's policy for IM process implementation against a reference model DRQ2 - Assessment Management | Approved | Required | Interaction | ||||||||||||||||||||
43 | SRQ28 - The system shall determine metrics to measure how activities deviate from and impact compliance to the reference model | Define and configure metrics for measuring deviations and impacts on compliance Define and calculate incident trace fitness metric which is delivered by conformance checking as average and individually Define and calculate non-compliance cost metric which is delivered by cost model using context-aware conformance checking as average and individually Define and calculate further metrics such as number and percentage of incidents handled, time per incident until resolved or closed, SLA violations, impact and urgency and priority coupled with affected location, category, subcategory and sympton if available as average and individually Define and calculate further metrics for time to activation, time to detection, false positive and true negative rate if available as average and individually | FRQ4 - The operator shall be capable to see a high-level overview of analyzed incidents, the reference model and required assessment activities FRQ5 - The operator shall be able to timely identify and analyze the main process errors using predefined metrics and methods for analysis and evaluation FRQ6 - The operator shall be able to identify and analyze procedure and impact metrics of resolved and closed incidents FRQ7 - The operator shall be able to identify the temporal compliance development and patterns of concern FRQ9 - The operator shall be able to identify and analyze details of the most critical errors CMRQ4 - The operator shall be able to analyze how non-compliance cost is distributed in order to identify patterns and trends | Approved | Not required | Analysis | ||||||||||||||||||||
44 | Non-Functional | |||||||||||||||||||||||||
45 | SRQ22 - The system shall produce system logs during an assessment to follow all assessment steps taken by the operator | Store detailed system logs including interactions with the system, assessment time, identifier of investigated IM log and operator Store system logs in a secure and human-readable format Generate metadata for creation, modification and operator identification for all data recorded data including assessment documentation Collect all assessment documentation in a centralized repository that supports document history tracking and is secured with access controls | FRQ10 - The operator shall be capable to produce an assessment report from analysis and evaluation of the IM log DRQ4 - Documentation Management | Approved | Not required | Data | ||||||||||||||||||||
46 | SRQ24 - The system shall ensure appropriate identification and description, format and media when creating or updating information | Provide standardized formats for creating and updating information such as fields for description, justification, comments, media etc. Allow the operators to easily identify and update or remove information about assessment findings and non-conformities | FRQ10 - The operator shall be capable to produce an assessment report from analysis and evaluation of the IM log | Approved | Not required | |||||||||||||||||||||
47 | SRQ30 - The system shall maintain a description for each function that processes data of the IM log for analysis and evaluation | Identify all functions that process data of the IM log (prior to visualization) in a tool documentation and describe each in its way of processing data | FRQ5 - The operator shall be able to timely identify and analyze the main process errors using predefined metrics and methods for analysis and evaluation | Approved | ||||||||||||||||||||||
48 | SRQ35 - The system shall ensure Data Protection and Privacy based on EU regulations (GDPR) and directives as well as other mandatory legal requirements | Adhere to the GDPR, NIS 2, ePrivacy, Cybersecurity Act, Digital Operational Resilience Act and Data Governance Act | FRQ11 - The system shall adhere to legal and regulatory documents DRQ4 - Documentation Management | Approved | Not required | Data | ||||||||||||||||||||
49 | SRQ36 - The system shall communicate its Use Policy to the operator prior to start of the assessment | Define a Use Policy and require the acceptance prior to the assessment | FRQ11 - The system shall adhere to legal and regulatory documents DRQ4 - Documentation Management | Approved | Not required | Data | ||||||||||||||||||||
50 | SRQ37 - The system shall provision the accessibility to and adequate handling of the organization's IM process implementation documents and the IM log that is to be assessed | Deliver and make available the necessary resources, i.e., the organization's IM process implementation documents as well as the IM log, along with the system to the operator Ensure that the organization's IM process implementation documents have been validated, signed and dated (electronically) by the Top-Management and IT Security department Ensure that the IM log has been validated, signed and dated (electronically) by the IT Security department of the organization Ensure the appropiate handling of necessary resources throughout the whole assessment process with several measures such as retrieval confirmation, access controls, Use Policy acknowledgement, preservation of legibility and agreements for retention and disposition | FRQ1 - In order to allow the operator to perform an investigation the system shall provison the accessibility to and adequate handling of resources under investigation and in use DRQ10 - Security of Resources | Approved | Not required | Data | ||||||||||||||||||||
51 | SRQ45 - The system shall support real-time capabilities | Alert the operator automatically as soon as there has been changes to the file containing the the IM log Provide a funtionality to refresh all metrics and visualizations if the operator whishes to do so during the assessment Update all assessment results including those that are already part of the assessment report | DRQ8 - Compliance Monitoring | Approved | Not required | Interaction | ||||||||||||||||||||
52 | SRQ48 - The system shall seperate computational resources from resources for UX in order to ensure that neither depletes the other's resources | Remain responsive on user interaction that requires high computational load and signal symbols the operator that indicate that the visualization tool is being refreshed Avoid system freezes Handle increasing amounts of required computations efficiently without compromising performance Support arbitrary sizes for the IM log | DRQ12 - Backend Scalability | Approved | Not required | Interaction | ||||||||||||||||||||
53 | SRQ49 - The system shall maintain a description for each tool of visualization that is used for analysis and evaluation of the IM log | Identify all tools for visualization which are used to assess the IM log in a tool documentation and describe each in terms of shown information, axis-labelling, interaction elements, dimensions, etc. | FRQ5 - The operator shall be able to timely identify and analyze the main process errors using predefined metrics and methods for analysis and evaluation | Approved | ||||||||||||||||||||||
54 | User Interface | |||||||||||||||||||||||||
55 | SRQ29 - The system shall enable the operator to assess the IM log in a timely manner | Identify and provide the neccessary visualization tools, each optimized to highlight one or multiple aspects related to metrics, trends or patterns, that offer advantages over classical tabular assessment of an IM log in order to reduce the overall required assessment time Use state-of-the-art algorithms to calculate key performance metrics of the IM log to reduce interaction lags caused by processing delays in the backend Use efficient visualization tools, designed for live-updates, that allow the operator to make use of real-time interaction without significant degradation to user experience due to processing time | FRQ5 - The operator shall be able to timely identify and analyze the main process errors using predefined metrics and methods for analysis and evaluation DRQ8 - Compliance Monitoring | Approved | Not required | Analysis | ||||||||||||||||||||
56 | SRQ34 - The system shall allow the operator with experience in the domain of IM to use it effectively without prior training by adopting best practices in interface design, naming conventions, help and support, workflows, visual feedback, accessibility and consistency | Provide a clean, intuitive user interface with logical layouts, navigation structures, consistent design patterns and elements Use clear, industry-standard terminology for all labels, buttons and menus and avoid ambiguous terms Provide relevant information through the help of tooltips that offer brief explanations when the operator hovers over buttons or fields Provide step-by-step guidance through the different View of the system to streamline the operator’s workflow Use visual indicators for required fields, progress bars, and completion statuses Ensure that the system is usable by operators with disabilities Use consistent placement of controls and information across different pages of the system and uniform behavior of interactive elements such as buttons and visualization tools | FRQ2 - The operator shall be competent in tool operation and compliance assessment DRQ1 - User Interface and Competence DRQ5 - Assessment Execution | Approved | Not required | Interaction | ||||||||||||||||||||
57 | SRQ46 - The system shall make use of a frontend that is scalable | Support any screen size and ratio Prefer simplicity in visualization tools especially when dealing with larger amount of displayed data | DRQ9 - Frontend Scalability | Approved | Not required | Interaction | ||||||||||||||||||||
58 | ||||||||||||||||||||||||||
59 | ||||||||||||||||||||||||||
60 | ||||||||||||||||||||||||||
61 | ||||||||||||||||||||||||||
62 | ||||||||||||||||||||||||||
63 | ||||||||||||||||||||||||||
64 | ||||||||||||||||||||||||||
65 | ||||||||||||||||||||||||||
66 | ||||||||||||||||||||||||||
67 | ||||||||||||||||||||||||||
68 | ||||||||||||||||||||||||||
69 | ||||||||||||||||||||||||||
70 | ||||||||||||||||||||||||||
71 | ||||||||||||||||||||||||||
72 | ||||||||||||||||||||||||||
73 | ||||||||||||||||||||||||||
74 | ||||||||||||||||||||||||||
75 | ||||||||||||||||||||||||||
76 | ||||||||||||||||||||||||||
77 | ||||||||||||||||||||||||||
78 | ||||||||||||||||||||||||||
79 | ||||||||||||||||||||||||||
80 | ||||||||||||||||||||||||||
81 | ||||||||||||||||||||||||||
82 | ||||||||||||||||||||||||||
83 | ||||||||||||||||||||||||||
84 | ||||||||||||||||||||||||||
85 | ||||||||||||||||||||||||||
86 | ||||||||||||||||||||||||||
87 | ||||||||||||||||||||||||||
88 | ||||||||||||||||||||||||||
89 | ||||||||||||||||||||||||||
90 | ||||||||||||||||||||||||||
91 | ||||||||||||||||||||||||||
92 | ||||||||||||||||||||||||||
93 | ||||||||||||||||||||||||||
94 | ||||||||||||||||||||||||||
95 | ||||||||||||||||||||||||||
96 | ||||||||||||||||||||||||||
97 | ||||||||||||||||||||||||||
98 | ||||||||||||||||||||||||||
99 | ||||||||||||||||||||||||||
100 | ||||||||||||||||||||||||||