Cyber Risk Compendium

Poor planning or lack of adaptation

BSI ID: G 0.18

If organisational processes that directly or indirectly serve information processing are not designed properly, this can lead to security problems. Even if each individual process step is carried out correctly, damage often occurs because the processes as a whole are defined incorrectly.

Another possible cause of security problems is dependencies on other processes that themselves have no obvious connection to information processing. Such dependencies can easily be overlooked during planning and thus cause disruptions during operation.

Security problems can also arise if tasks, roles or responsibilities are not clearly assigned. Among other things, this can lead to delays in processes, security measures being neglected or regulations being disregarded.

There is also a risk if devices, products, processes or other means of implementing information processing are not used properly. The selection of an unsuitable product or vulnerabilities in the application architecture or network design, for example, can lead to security problems.

Examples:

  • If maintenance or repair processes are not tailored to the technical requirements, this can lead to unacceptable downtimes.

  • There may be an increased risk of attacks on your own IT systems if security requirements are not taken into account when procuring information technology.

  • If necessary consumables are not made available on time, the IT processes that depend on them may come to a standstill.

  • Vulnerabilities can arise if unsuitable transmission protocols are selected when planning an IT process. Information technology and the entire environment of a public authority or company are constantly changing. This may be due to employees leaving or joining the company, new hardware or software being procured, or a supplier going bankrupt. If the necessary organisational and technical adjustments are not taken into account, or are only taken into account to an insufficient extent, risks may arise.

Examples:

  • Structural changes to the building alter existing escape routes. As employees have not been adequately informed, the building cannot be evacuated in the required time.

  • When transmitting electronic documents, care is not taken to use a data format that is readable by the recipient.