Protection Needs Assessment

A Protection Needs Assessment is the evaluation of how worthy of protection IT systems, applications and data are – measured by the damage that would arise from a loss of confidentiality, integrity or availability.

Methodologically, the term is shaped by the German BSI IT-Grundschutz: for each protection goal, the need is typically classified into the categories normal, high and very high, oriented to possible financial damage, legal violations, impairment of task fulfillment or danger to persons. The inheritance principle is important: the protection needs of an application are transferred to the systems, networks and rooms on which it depends – according to the maximum principle, the most critical use determines the need.

The result controls how much protection is appropriate where: instead of investing equally everywhere, measures are assigned to the actual risk. The protection needs assessment is thus a basic building block of every ISMS – and, at the data level, closely related to Data Classification.