ABCDEFGHIJKLMNOPQRSTUVWXYZ
1
RequirementDescriptionrefinesStatusOperator ExpertiseScope
2
Dashboard
3
SRQ42 - The system shall be divided into mutiple assessment sections, called Aggregated Views, where each is dedicated to specific functional requirements during the assessment Provide a user-friendly web-based interface accessible to the operator that ensures intuitive navigation throughout the different View for competent operators

Order Aggregated Views from top-down approach from high-level overview to in-detail analysis accoring to frameworks for auditing incident management (ISO 19011, ISO 19600 and 37301)

Define and provide an Aggregated View for:
- Accessing the organization's policy for IM process implementation and evaluation against the Integrated IM reference model (SRQ1)
- Indent and Process statistics regarding the detection and activation as well as resolving and closure of incidents (SRQ11)
- High-Level overview for summarized information (SRQ6)
- Compliance development within selected time period (SRQ13)
- Characteristics and details of selected incidents (SRQ15)
- What-if analysis (SRQ32)
- Cost model parameterization (SRQ41)

- Global assessment progress (SRQ43)
DRQ1 - User Interface and CompetenceApprovedNot requiredInteraction
Analysis
4
SRQ1 - The system shall provide an Aggregated View that allows the operator to access the organization's policy for IM process implementation and evaluation against the integrated IM reference modelDisplay the organization's policy documents related to IM process implementation which are part of the Information Security Management System to the operator

Display the integrated IM reference model through visualization tools

Support the operator in identifying the specific sections in the organization's policy for IM process implementation that describe how an incident is handled by definition and which data about IM are recorded in logs


Allow the operator to access and browse the specific sections of the organization's policy for IM process implementation that describe how an incident is handled by definition, i.e., which incident management steps must/should be taken including activation and closing of an incident, and which variables must/should be carried by an IM log

Display the functionalities to map the organization's policy for IM process implementation to the integrated IM reference model
FRQ3 - The operator shall be able to analyse the organization's policy for IM process implementation against a reference model

FRQ1 - In order to allow the operator to perform an investigation the system shall provison the accessibility to and adequate handling of resources under investigation and in use

DRQ5 - Assessment Execution
ApprovedRequiredInteraction
Analysis
5
SRQ6 - The system shall provide an Aggregated View to the operator with a high-level overview that displays summarized information on analyzed incidents, average values for key performance metrics, the integrated IM reference model and required assessment activities Display the functionality to set the time period for which the assessment takes place to the operator

Display summarized information on the number and range of selected incidents and different execution variants to the operator

Display the average values for the overall incident trace fitness and non-compliance cost for the selected incidents to the operator

Display the integrated IM reference model through visualization tools to the operator

Display the checklist that contains all the security controls to the operator and allow to modify the list of security controls
FRQ4 - The operator shall be capable to see a high-level overview of analyzed incidents, the reference model and required assessment activities

DRQ2 - Assessment Management

DRQ5 - Assessment Execution

ApprovedRequiredInteraction
Analysis
Visualization
6
SRQ11 - The system shall provide an Aggregated View that contains incidents and process statistics regarding the activation and detection as well as resolving and closure of incidentsDisplay incidents with the most deviation errors through visualization tools regarding the activation and detection as well as resolving and closing of incidents

Display metrics for time to activation, time to detection, false positive and true negative rate if available

Display impact metrics for downtime duration, amount of data loss, estimated costs of damage and SLA violations if available

Display tools that allow the operator to highlight and identify areas of concern based on the metrics for detection and activation as well as resolving and closing of incidents

Display the functionalities to apply statistical analysis algorithms to the incidents in the selected time period

Display the functionalities to apply pattern recognition algorithms to the incidents in the selected time period

Display a functionality that allows to define and search for patterns in the incidents of the selected time period

Display the found patterns and through appropiate visualization tools

Display tools that allow the operator to highlight and identify areas of concern based on the found patterns
FRQ6 - The operator shall be able to identify and analyze procedure and impact metrics of resolved and closed incidents

FRQ7 - The operator shall be able to identify the temporal compliance development and areas of concern

DRQ5 - Assessment Execution
ApprovedNot requiredInteraction
Analysis
7
SRQ13 - The system shall provide an Aggregated View that allows to analyze the compliance development within the selected time periodDisplay a visual representation illustrating the evolution of incident trace fitness and non-compliance cost for incidents against the integrated IM reference model over time that allows filtering for different non-compliance causes to identify trends and patterns

Display a visual representation that illustrates the distribution of fitness and non-compliance cost for incidents to the operator to identify trends and patterns

Display the trends and through appropiate visualization tools


Display tools that allow the operator to highlight and identify areas of concern based on the found trends
FRQ7 - The operator shall be able to identify the temporal compliance development and patterns of concern

CMRQ4 - The operator shall be able to analyze how non-compliance cost is distributed in order to identify patterns and trends

DRQ5 - Assessment Execution
ApprovedNot requiredInteraction
Analysis
Visualization
8
SRQ15 - The system shall provide an Aggregated View that allows to analyze incident characteristics and details of selected incidents that are critical or belong to areas of concernDisplay all incidents that belong to certain identified areas of concern such as trends and patterns or individual traces in critical compliance severity regarding fitness and/or non-compliance costs

Display visualization tools to analyze the characteristics of mutiple or individual incidents that belong to the identified areas of concern
FRQ7 - The operator shall be able to identify the temporal compliance development and areas of concern

FRQ9 - The operator shall be able to identify and analyze details of the most critical errors

CMRQ5 - The operator shall be capable to prioritize and select incidents based on their compliance severity in order to isolate severity ranges and determine their root causes

DRQ5 - Assessment Execution
ApprovedRequiredInteraction
Analysis
Visualization
9
SRQ32 - The system shall provide an Aggregaetd View that is dedicated to the What-if analysisDisplay a functionality to the operator to enable or disable what-if analysis

Display functionality to the operator to interact with the basic and advanced tools that are provided by the system to perform what-if analysis

Provide a warning that is displayed system-wide when what-if analysis is currently enabled

Display the influence on the overall IM process compliance through percentage changes of metrics against their initial value

Display a second data input with different colouring for the time-oriented visualization tools that are used that show the change in temporal compliance development by performing what-if analysis

FRQ8 - The operator shall be capable to control or correct individual or multiple incident traces in order to predict the influence on the overall IM compliance

DRQ5 - Assessment Execution
ApprovedRequiredInteraction
Analysis
10
SRQ41 - The system shall provide an Aggregated View that is dedicated to cost model parameterizationDisplay the automatically suggested parameterizations and the KPI they are based upon

Dispaly a functionality and provide support for the operator to select and load a suggested deviation parameterization from the system

Display the defined mechanisms to adjust a suggested deviation parameterization or to define a deviation paramterization from scratch by manually setting each parameter of the cost function
CMRQ2 - The operator shall be able to adjust a suggested deviation parameterization in order to build own parameterization that reflects assessment preferences

DRQ5 - Assessment Execution
ApprovedRequiredInteraction
11
SRQ43 - The system shall provide an Aggregated View that is dedicated to the global assessment progressDisplay the global progress of assessement execution as a summary of findings, areas of concern and non-conformities as well as on the status of security controls contained in the checklistDRQ7 - Reporting and AnalyticsApproved
12
Report
13
SRQ20 - The system shall enable the operator to produce an assessment report from the reported sectionsProvide the necessary high-level overview of an assessment of an IM log that is required for submission to the governing body or top management

Provide the technical in-depth perspective of an assessment of an IM log that is required by an assessor or, if desired, by an auditor

Define report section for:
- Deviations found between organization's policy for IM process implementation and integrated IM reference model (SRQ5)
- Assessment criteria and justification how results will be evaluated (SRQ9)
- Detection and activation as well as resolving and closure of incidents (SRQ12)
- Temporal compliance development and areas of concern (SRQ16)
- Most critical incidents incidents in terms of fitness, non-compliance and execeeded response times (SRQ19)
- Assessment time and past assessments (SRQ21)
- Assessment results, i.e., findings and non-conformities (SRQ25)
- Recommendations from an assessment (SRQ26)
- What-if analysis (SRQ33)

FRQ10 - The operator shall be capable to produce an assessment report from analysis and evaluation of the IM log

DRQ7 - Reporting and Analytics
ApprovedNot requiredReporting
14
SRQ5 - The system shall generate a report section that lists any deviations found between the organization's policy for IM process implementation and the integrated IM reference modelGenerate a section in the assessment report that lists all detected deviations and interesting information between the organization's policy for IM process implementation and the integrated IM reference model

Include descriptions for each deviation together with its location within the policy documents

Classify detected deviations in the report section based on severity levels from predefined criteria

Provide recommendations by the operator for aligning the organization's policy for IM process implementation with the integrated IM reference model based on the detected deviations that are actionable and alllow addressing and resolving deviations

Include comments regarding the historical development of the organization's policy for IM process implementation, if considered to be appropiate in the current context, made by the operator
FRQ3 - The operator shall be able to analyse the organization's policy for IM process implementation against a reference model

DRQ2 - Assessment Management
ApprovedRequiredInteraction
Reporting
15
SRQ9 - The system shall generate a report section that includes the assessment criteria and justfies how results will be evaluated against assessment criteriaInclude the assessment criteria provided by the operator

Include the operators narrative justification on how the assessment results, i.e., findings and non-conformities, will be evaluated against the assessment criteria
FRQ4 - The operator shall be capable to see a high-level overview of analyzed incidents, the reference model and required assessment activitiesApprovedRequiredInteraction
Reporting
16
SRQ12 - The system shall provide a report section dedicated to the detection and activation as well as resolving and closure procedure of incidentsInclude the most common execution variants and most critical incidents regarding non-compliance costs for detection and activation as well as resolving and closing of incidents

Include average metrics for time to activation, time to detection, false positive and true negative rate if available

Include individual metrics for time to activation, time to detection, false positive and true negative rate if available for incidents that are highlighted as concerning

Include average impact metrics for downtime duration, amount of data loss, estimated costs of damage and SLA violations if available

Include individual impact metrics for downtime duration, amount of data loss, estimated costs of damage and SLA violations if available for incidents that are highlighted as concerning

Include comments by the operator regarding the overall and individual compliance performance of incidents for activation and detection as well as resolving and closure procedure
FRQ6 - The operator shall be able to identify and analyze procedure and impact metrics of resolved and closed incidents

FRQ7 - The operator shall be able to identify the temporal compliance development and areas of concern
ApprovedRequiredInteraction
Reporting
17
SRQ16 - The system shall provide a report section that is dedicated to temporal compliance development and areas of concern Include the temporal compliance development as well as the average value for the selected incident time period

Include areas of concern that were highlighted/flagged by the operator automatically and for each area of concern allow to include the justification in the form of the identified trends and patterns

Include comments by the operator for systemic weaknesses and threats and proposed actions that are aimed towards reducing or eradicating areas of concern

Include comments by the operator to set the temporal compliance development in context
FRQ7 - The operator shall be able to identify the temporal compliance development and areas of concernApprovedRequiredReporting
Interaction
18
SRQ19 - The system shall provide a report section dedicated to the most critical incidents in terms of fitness, non-compliance costs and exceeded response timesInclude the set thresholds for fitness and non-compliance cost as well as their justification

Include all incidents that fall within the set thresholds for fitness and/or non-compliance costs

Include for each critical incident, a summary of the execution trace and, if applicable, exceeded response or resolve times that justify the classification as critical

Include comments by the operator for each critical incident if desired
FRQ9 - The operator shall be able to identify and analyze details of the most critical errorsApprovedRequiredReporting
Interaction
19
SRQ21-A - The system shall provide a report subsection within a section that is dedicated to the assessed time period, past asessments and changes to the used assessment framework if availableProvide information on whether assessments were regularly performed prior to the current assessment and if not why
if those information are available
Provide the selected time period for which the assesment takes place

Include comments about past assessments if desired by the operator that aim to summarize the improvements or changes to the IM that were implemented based on the results of the past assessments

Include comments about past assessments if desired by the operator that give notice if changes to the assessment procedure/workflow are introduced since the last assessment like the assessment against a different framework
FRQ10 - The operator shall be capable to produce an assessment report from analysis and evaluation of the IM log

DRQ7 - Reporting and Analytics
ApprovedNot requiredReporting
Interaction
20
SRQ21-B - The system shall provide a report subsection within a section that is dedicated to the versioning and, if applicable, changes in the versioning of the currently used assessment framework if availableInclude comments about the name and versioning of the currently used assessment framework by the operator

Include comments about changes to the versioning of the currently used assessent framework for justification if applicable by the operator
FRQ10 - The operator shall be capable to produce an assessment report from analysis and evaluation of the IM log

DRQ7 - Reporting and Analytics
Approved
21
SRQ25 - The system shall store all the reports to allow reproducibility of the analysesInclude for each asessment result the assessment criteria it is evaluated against

Include comments by the operator that explain assessment findings including referring to past assesment reports in order to communicate recurring issues

Include comments by the operator that explain non-conformities as well as grade them qualitative- or quantitative-wise
FRQ10 - The operator shall be capable to produce an assessment report from analysis and evaluation of the IM log

DRQ7 - Reporting and Analytics
ApprovedRequiredReporting
Interaction
22
SRQ26 - The system shall provide a report section that provides recommendations from an assessmentInclude comments by the operator regarding recommendations for an updated organization's policy for IM process implemenation as well as updated and/or new controls to fulfill the organization's policy for IM process implemenationFRQ10 - The operator shall be capable to produce an assessment report from analysis and evaluation of the IM logApprovedRequiredReporting
Interaction
23
SRQ33 - The system shall provide a report section that is dedicated to what-if analysisInclude the basic and advanced functions that were used and which impact on the IM log KPIs was observed

Include the change in temporal compliance development that was observed from what-if analysis

Include comments by the operator that set the what-if analysis into context to the actual assessment
FRQ8 - The operator shall be capable to control or correct individual or multiple incident traces in order to predict the influence on the overall IM complianceApprovedRequiredReporting
24
SRQ44 - The system shall provide a functionality to export the produced assessment reportExport the assessment reports in common and well-supported data formats such as PDF, DOCX and XLSX DRQ7 - Reporting and AnalyticsApprovedNot requiredInteraction
Reporting
25
Analytics Features
26
SRQ3 - The system shall provide a functionality to compare the organization's policy for IM process implementation with the integrated IM reference modelProvide a functionality to compare specific sections of the organization's policy documents for IM process implementation with corresponding sections of the integrated IM reference model

Allow the operator to map sections of the organization's policy for IM process implemenation to states of the integrated IM reference model

Enable the operator to highlight differences and similarities between the organization's policy for IM process implementation and the IM reference model in a text-based format
FRQ3 - The operator shall be able to analyse the organization's policy for IM process implementation against a reference model

DRQ2 - Assessment Management
ApprovedRequiredAnalysis
27
SRQ4 - The system shall detect possible deviations between the organization's policy for IM process implementation and the integrated reference model if prior is processableDetect possible deviations by performing automatic mapping between sections of the organization's policy for IM process implementation and states of the integrated IM reference model if prior is delivered in an appropiate format for automatic processing

Consider any instance where the organization's policy for IM process implementation does not align with the requirements or recommendations of the reference model as possible deviation

List the possible deviations in a text-based format that enables the operator to manually recitfy possible deviations suggested by the system easily
FRQ3 - The operator shall be able to analyse the organization's policy for IM process implementation against a reference model

DRQ2 - Assessment Management
ApprovedNot requiredAnalysis
28
SRQ7 - The system shall enable the operator to check if information is complete, correct, consistent and currentVerify the completeness of the IM log by ensuring that all required fields are existent and populated

Verify the accuracy of the data provided by the IM log by comparing it with trusted sources and implement data verification mechanisms such as checksums or hash functions if applicable

Ensure consistency across the different fields and IM events with appropiate consistency checking mechanisms

Check timestamps of IM log events to ensure it is up-to-date and implement mechanisms to flag outdated data

FRQ4 - The operator shall be capable to see a high-level overview of analyzed incidents, the reference model and required assessment activitiesApprovedNot requiredAnalysis
29
SRQ8 - The system shall provide digital checklists as well as the possibility to define and/or automatically suggest assessment security controlsProvide a checklist functionality that may be used by an operator to define the desired asessment security controls

Generate a costumizable checklist template that contains common security controls

Suggest common assessment security controls based on selected IM framework or standard that the operator may find useful and import in the assessment checklist automatically

Evaluate common assessment security controls automatically regarding appropiate ranges of KPIs of the IM log if available

Provide a the status of all security controls as a measure of global progress to the operator
FRQ4 - The operator shall be capable to see a high-level overview of analyzed incidents, the reference model and required assessment security controls

DRQ3 - Templates

DRQ11 - Automated Assessment Security Controls
ApprovedRequiredInteraction
30
SRQ10 - The system shall enable the operator to identify the activation and detection as well as resolving and closure procedure of incidents through suitable metricsHighlight the most common execution variants for activation and detection as well as resolving and closing incidents before context-aware trace alignment

Highlight the most critical incidents regarding activation and detection as well as resolving and closure procedure with respect to fitness and non-compliance costs

Highlight the metrics for detection and activation as well as resolving and closing of incidents from additional attributes carried in the IM log
FRQ6 - The operator shall be able to identify and analyze procedure and impact metrics of resolved and closed incidents

FRQ7 - The operator shall be able to identify the temporal compliance development and areas of concern
ApprovedNot requiredAnalysis
31
SRQ14 - The system shall enable the operator to analyze multiple incidents to identify trends and patterns as areas of concernProvide a functionality that allows to explore the number of active/closed incidents and time to activate and resolve over time as well as the correlated Fitness and Non-compliance Cost

Provide a functionality that allows to explore the distribution of Fitness and Non-Compliance Cost for incidents

Perform trend and pattern analysis on the selected incident time period with appropiate techniques such as statistical analysis (descriptive statistics, time series analysis, etc.) and pattern recognition algorithms (clustering, anomaly detection, frequent pattern mining, etc.)

Provide a functionality that allows to define and search for patterns (e.g., variants) in selected incident time period

Provide appropiate visualization tools that allow the operator to identify trends and patterns manually

Provide a function to highlight/tag areas of concern based on identified trends and patterns
FRQ7 - The operator shall be able to identify the temporal compliance development and areas of concern

CMRQ4 - The operator shall be able to analyze how non-compliance cost is distributed in order to identify patterns and trends
ApprovedRequiredAnalysis
32
SRQ17 - The system shall enable the operator to prioritize and analyze details of the most critical incidents with respect to fitness and non-compliance cost individuallyDefine a qualitative scale for compliance severity that divides the range of values in fitness and non-compliance costs into categories low, moderate, high, critical

Provide a function that allows the operator to filter for incidents in certain compliance severity categories regarding fitness and/or non-compliance costs or previously identified areas of concern in order to allow a prioritization of incidents with higher severity

Allow to inspect the details of (selected) incidents individually for technical analysis
FRQ9 - The operator shall be able to identify and analyze details of the most critical errors

CMRQ5 - The operator shall be capable to prioritize and select incidents based on their compliance severity in order to isolate severity ranges and determine their root causes
ApprovedNot requiredInteraction
Analysis
33
SRQ18 - The system shall indicate missing escalation steps when proper response times were exceededDefine proper response time from detection to closing or activation to resolving for incidents of an IM trace based on average values of the provided IM log or set by operator manually

Indicate possible missing internal escalation if time between execution steps is beyond certain threshold or if response time is exceeded

Provide, if available, information on wether an interm report after exceeding organiaztion's threshold for response time was generated for an incident
FRQ9 - The operator shall be able to identify and analyze details of the most critical errorsApprovedRequiredInteraction
Analysis
34
SRQ23 - The system shall retain assessment findings, areas of concern and non-conformities during an assessmentList assessment findings, ares of concern and non-conformities in tabular way and sort by compliance severity by default

Allow managing of assessment findings, ares of concern and non-conformities in such a way that adding/removing/replacing/grouping/enriching issues is possible

Document for each finding, area of concern and non-conformity how they have been collected and which corrective actions have been taken to leverage or supress specific results

Provide a summary of findings, areas of concern and non-conformitries as a measure of global progress to the operator
FRQ10 - The operator shall be capable to produce an assessment report from analysis and evaluation of the IM log

DRQ13 - Issue Tracking

DRQ6 - Issue Management
ApprovedRequiredInteraction
35
SRQ27 - The system shall implement and maintain the controls to monitor and assess the IM log in order to meet compliance obligations and deduce compliance risksSupport the operator in assessing the IM log against the compliance obligations communicated in the organization's policy for IM process implementation and the integrated IM reference model

Allow the operator to deduce compliance risks after assessing the IM log
FRQ5 - The operator shall be able to timely identify and analyze the main process errors using predefined metrics and methods for analysis and evaluationApprovedNot requiredAnalysis
36
SRQ31 - The system shall provide the operator with basic tools to perform what-if analysis towards the IM log to determine if changes to organization's IM affect the IM compliance performanceProvide basic functions such as ignoring or fixing, with respect to fitness or non-compliance cost, specific incidents in the IM log based on their identifier in the overall compliance assessment

Provide advanced functions that allow to query for specific patterns in the IM log and exclude the resulting list of incidents based on their identifiers from the overall compliance assessment

Provide advanced function to manipulate specific variables of one or mutiple incidents in the IM log
FRQ8 - The operator shall be capable to control or correct individual or multiple incident traces in order to predict the influence on the overall IM complianceApprovedRequiredInteraction
Analysis
37
SRQ38 - The system shall suggest multiple deviation paramterizations based on different IM log KPIsProvide an explanation to the operator how automatic suggestions for deviation parameterizations work

Analyze, if available, different IM KPIs such as the trace fitness, loss due to SLA violations and costs associated with person-hours spend or in relation with organization KPIs, taken from set of additional information of the IM log

Deduce a cost function parameterization, for the cost model based on every available IM KPI and suggest to the operator
CMRQ1 - In order to support the operator the system shall be able to suggest mutiple deviation parameterizations based on automated analysis of different IM log KPIsApprovedNot requiredInteraction
38
SRQ39 - The system shall allow the operator to adjust a suggested deviation parameterization that reflects assessment preferencesProvide an explanation to the operator how the parameters of the deviation parameterization affect the cost function of the cost model

Provide mechanisms for each incident state from the integrated reference model for each error category (missing, repitition and mismatch) and error weights for error category that allow to modify the values of each parameter of the cost function
CMRQ2 - The operator shall be able to adjust a suggested deviation parameterization in order to build own parameterization that reflects assessment preferencesApprovedRequiredInteraction
39
SRQ40 - The system shall allow the operator to define a new context-aware deviation parameterization independentlyProvide an explanation to the operator of how the deviation parameterization works

Provide mechanisms for each incident state from the integrated reference model for each error category (missing, repitition and mismatch) and error weights for error category that allow to set the values of each parameter
CMRQ3 - The operator shall be able to define a new context-aware deviation parameterization in order to handle specific cases for costs of non-compliance causes or if parameterizations shall be based on unidentified IM log KPIs or other reasoningApprovedRequiredInteraction
40
SRQ47 - The system shall be capable to limit the assessed data of the IM log to a specific time periodProvide functionality to set time period in which the assessment takes place and only consider the incidents within the selected time period

Set the default time period to 1 year from the actual current date
DRQ9 - Frontend ScalabilityApprovedNot requiredInteraction
Analysis
41
Modeling
42
SRQ2 - The system shall model an IM reference model based on a standard or framework for IM processesRequire the definition of a standard reference model for IM processes such as ISO 27035 or NIST SP-800-61 that is to be delivered by the operator and then implemented into the system

Implement the reference model in an appropiate representation format so that it can serve as a benchmark for the organization's IM process implementation and IM log
FRQ3 - The operator shall be able to analyse the organization's policy for IM process implementation against a reference model

DRQ2 - Assessment Management
ApprovedRequiredInteraction
43
SRQ28 - The system shall determine metrics to measure how activities deviate from and impact compliance to the reference modelDefine and configure metrics for measuring deviations and impacts on compliance

Define and calculate incident trace fitness metric which is delivered by conformance checking as average and individually

Define and calculate non-compliance cost metric which is delivered by cost model using context-aware conformance checking as average and individually

Define and calculate further metrics such as number and percentage of incidents handled, time per incident until resolved or closed, SLA violations, impact and urgency and priority coupled with affected location, category, subcategory and sympton if available as average and individually

Define and calculate further metrics for time to activation, time to detection, false positive and true negative rate if available as average and individually
FRQ4 - The operator shall be capable to see a high-level overview of analyzed incidents, the reference model and required assessment activities

FRQ5 - The operator shall be able to timely identify and analyze the main process errors using predefined metrics and methods for analysis and evaluation

FRQ6 - The operator shall be able to identify and analyze procedure and impact metrics of resolved and closed incidents

FRQ7 - The operator shall be able to identify the temporal compliance development and patterns of concern

FRQ9 - The operator shall be able to identify and analyze details of the most critical errors

CMRQ4 - The operator shall be able to analyze how non-compliance cost is distributed in order to identify patterns and trends
ApprovedNot requiredAnalysis
44
Non-Functional
45
SRQ22 - The system shall produce system logs during an assessment to follow all assessment steps taken by the operatorStore detailed system logs including interactions with the system, assessment time, identifier of investigated IM log and operator

Store system logs in a secure and human-readable format

Generate metadata for creation, modification and operator identification for all data recorded data including assessment documentation

Collect all assessment documentation in a centralized repository that supports document history tracking and is secured with access controls
FRQ10 - The operator shall be capable to produce an assessment report from analysis and evaluation of the IM log

DRQ4 - Documentation Management
ApprovedNot requiredData
46
SRQ24 - The system shall ensure appropriate identification and description, format and media when creating or updating informationProvide standardized formats for creating and updating information such as fields for description, justification, comments, media etc.

Allow the operators to easily identify and update or remove information about assessment findings and non-conformities
FRQ10 - The operator shall be capable to produce an assessment report from analysis and evaluation of the IM logApprovedNot required
47
SRQ30 - The system shall maintain a description for each function that processes data of the IM log for analysis and evaluationIdentify all functions that process data of the IM log (prior to visualization) in a tool documentation and describe each in its way of processing dataFRQ5 - The operator shall be able to timely identify and analyze the main process errors using predefined metrics and methods for analysis and evaluationApproved
48
SRQ35 - The system shall ensure Data Protection and Privacy based on EU regulations (GDPR) and directives as well as other mandatory legal requirementsAdhere to the GDPR, NIS 2, ePrivacy, Cybersecurity Act, Digital Operational Resilience Act and Data Governance Act FRQ11 - The system shall adhere to legal and regulatory documents

DRQ4 - Documentation Management
ApprovedNot requiredData
49
SRQ36 - The system shall communicate its Use Policy to the operator prior to start of the assessmentDefine a Use Policy and require the acceptance prior to the assessmentFRQ11 - The system shall adhere to legal and regulatory documents

DRQ4 - Documentation Management
ApprovedNot requiredData
50
SRQ37 - The system shall provision the accessibility to and adequate handling of the organization's IM process implementation documents and the IM log that is to be assessedDeliver and make available the necessary resources, i.e., the organization's IM process implementation documents as well as the IM log, along with the system to the operator

Ensure that the organization's IM process implementation documents have been validated, signed and dated (electronically) by the Top-Management and IT Security department

Ensure that the IM log has been validated, signed and dated (electronically) by the IT Security department of the organization

Ensure the appropiate handling of necessary resources throughout the whole assessment process with several measures such as retrieval confirmation, access controls, Use Policy acknowledgement, preservation of legibility and agreements for retention and disposition
FRQ1 - In order to allow the operator to perform an investigation the system shall provison the accessibility to and adequate handling of resources under investigation and in use

DRQ10 - Security of Resources
ApprovedNot requiredData
51
SRQ45 - The system shall support real-time capabilitiesAlert the operator automatically as soon as there has been changes to the file containing the the IM log

Provide a funtionality to refresh all metrics and visualizations if the operator whishes to do so during the assessment

Update all assessment results including those that are already part of the assessment report
DRQ8 - Compliance MonitoringApprovedNot requiredInteraction
52
SRQ48 - The system shall seperate computational resources from resources for UX in order to ensure that neither depletes the other's resourcesRemain responsive on user interaction that requires high computational load and signal symbols the operator that indicate that the visualization tool is being refreshed

Avoid system freezes

Handle increasing amounts of required computations efficiently without compromising performance

Support arbitrary sizes for the IM log
DRQ12 - Backend ScalabilityApprovedNot requiredInteraction
53
SRQ49 - The system shall maintain a description for each tool of visualization that is used for analysis and evaluation of the IM logIdentify all tools for visualization which are used to assess the IM log in a tool documentation and describe each in terms of shown information, axis-labelling, interaction elements, dimensions, etc.FRQ5 - The operator shall be able to timely identify and analyze the main process errors using predefined metrics and methods for analysis and evaluationApproved
54
User Interface
55
SRQ29 - The system shall enable the operator to assess the IM log in a timely mannerIdentify and provide the neccessary visualization tools, each optimized to highlight one or multiple aspects related to metrics, trends or patterns, that offer advantages over classical tabular assessment of an IM log in order to reduce the overall required assessment time

Use state-of-the-art algorithms to calculate key performance metrics of the IM log to reduce interaction lags caused by processing delays in the backend

Use efficient visualization tools, designed for live-updates, that allow the operator to make use of real-time interaction without significant degradation to user experience due to processing time
FRQ5 - The operator shall be able to timely identify and analyze the main process errors using predefined metrics and methods for analysis and evaluation

DRQ8 - Compliance Monitoring
ApprovedNot requiredAnalysis
56
SRQ34 - The system shall allow the operator with experience in the domain of IM to use it effectively without prior training by adopting best practices in interface design, naming conventions, help and support, workflows, visual feedback, accessibility and consistencyProvide a clean, intuitive user interface with logical layouts, navigation structures, consistent design patterns and elements

Use clear, industry-standard terminology for all labels, buttons and menus and avoid ambiguous terms

Provide relevant information through the help of tooltips that offer brief explanations when the operator hovers over buttons or fields

Provide step-by-step guidance through the different View of the system to streamline the operator’s workflow

Use visual indicators for required fields, progress bars, and completion statuses

Ensure that the system is usable by operators with disabilities

Use consistent placement of controls and information across different pages of the system and uniform behavior of interactive elements such as buttons and visualization tools
FRQ2 - The operator shall be competent in tool operation and compliance assessment

DRQ1 - User Interface and Competence

DRQ5 - Assessment Execution
ApprovedNot requiredInteraction
57
SRQ46 - The system shall make use of a frontend that is scalableSupport any screen size and ratio

Prefer simplicity in visualization tools especially when dealing with larger amount of displayed data
DRQ9 - Frontend ScalabilityApprovedNot requiredInteraction
58


59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100