BSI-Standard 200-2 §8.2 · ISO/IEC 27005:2022 Annex A.2

Protection needs and asset inheritance

You rate the business process and its information once. Every application, server, room and cable underneath it inherits that rating — and risk travels back up the same dependency graph in the opposite direction.

Select any element to see the clause it comes from.

How a protection need is inherited, and how risk travels back Four stacked layers. At the top, primary or business assets: business processes and the information they handle, where the protection need is determined from six damage scenarios. Below, supporting assets in three tiers: applications, then IT systems, then rooms, communication links and devices. An accent rail down the left shows the protection need inheriting downward per BSI Standard 200-2 section 8.2.2. A dashed teal rail up the right shows risk propagating from supporting assets back to business assets per ISO/IEC 27005:2022 annex A.2.2. Between layers, three adjustments are named: inheritance cascades the need, the maximum principle and cumulation can raise it, and the distribution effect can lower it, mainly for availability. At the foot, a lateral case shows an application inheriting the need of another application that depends on its output, and the rule that an object's overall protection need is the maximum of its confidentiality, integrity and availability ratings. Step 1 — rate the process and its information Judge the damage against these scenarios. The worst one sets the category. 1 Laws, regulations or contracts 2 Informational self-determination 3 Personal safety 4 Task fulfilment 5 Reputation and trust 6 Financial impact BSI's starting set, not a closed list — add any that apply, drop any that do not (§8.2.1). normal — limited and manageable · high — can be considerable very high — can be catastrophic, threatening survival Protection need inherits down — BSI 200-2 §8.2.2 Risk propagates up — 27005 A.2.2 Primary / business assets Business processes and the information they handle. The protection need is determined HERE, from the damage scenarios. Everything below inherits it. Inheritance — the need cascades to whatever processes it Supporting assets — applications The applications used to process them. BSI 200-2 §8.2.3. Maximum principle · cumulation can raise it Supporting assets — IT systems Servers, virtualisation hosts, clients. §8.2.4. Cumulation bites hardest here. Distribution effect can lower it — mainly availability Supporting assets — rooms, links, devices Buildings, communication links, other devices. §8.2.6–8.2.8. Derived last, from everything above. Per object: overall protection need = the highest of C, I and A Lateral propagation — the need also moves sideways Application A minor on its own Application B high need feeds results need transfers back

The model, in words

Open this page on a wider screen for the diagram and the clause explorer. The calculator below works everywhere.

Protection need — inherits downward (BSI) Risk — propagates upward (27005)

Select an element

Every box, rail and label on the diagram is backed by a clause in BSI-Standard 200-2 or ISO/IEC 27005:2022. Choose one to see it.

Try it — the overall need is a maximum

Rate one object against each security objective. The overall figure is the highest of the three, never an average and never a blend. Only very high is marked in accent, because it is the only rating that changes what you have to do next.

Confidentiality
Integrity
Availability

Presets:

Overall protection need: very high

§8.2.9, p. 130

Hand-built inline SVG · no third-party requests · sameerkhairkar.com