Iteration Teil D: Lieferantenmanagement (VDA-ISA 2027 Kap. 6 + NIS2)
Datenmodell (Prisma, RLS): Supplier + SupplierAsset, SupplierAssessment, Contract, Nda, SupplierEvidence, ServiceResponsibility, Subcontractor, ManagementDecision, SupplierControl (globaler Katalog) + SupplierControlMaturity. - VDA-ISA-2027-Kap.-6-Mini-Katalog (Controls 6.1.1–6.1.3) mit Zielbild, Muss/Soll, Anforderungen für hoch/sehr hoch, Simplified Group Assessment, Ziel-Reifegrad 3 und Cross-Referenzen (ISO/NIST/BSI); im Seed befüllt - Lieferantenverzeichnis mit KPIs (gesamt, NIS2-relevant, ablaufend, Reviews fällig), Kritikalität, NIS2-Flag, Review-Fristen - Detail-Popup: Stammdaten (Sektor/Leistung/Datenkategorien/CIA), betroffene Assets, VDA-ISA-Reifegrade je Control (Ziel 3, farbige Balken), Nachweise (Angemessenheit + Ablauf), Assessments, Verträge (AV/DPA, Flow-down, Fristen), NDAs (Fristen), Shared-Responsibility- Matrix, Subunternehmer, Managemententscheidungen - Bearbeiten-Popup: Stammdaten (ein Speichern), Reifegrad je Control, Add/Delete für alle Kind-Entitäten, Löschen im ⋯-Menü - Regel 6.1.1: fehlt geprüfter Audit-/TISAX-Nachweis → Warnung, dass eine dokumentierte risikobasierte Managemententscheidung nötig ist - Server-Actions mit Zod/RBAC/Audit-Log; Seed mit Demo-Lieferant (TISAX-Label, AV/DPA, NDA, Assessment, RACI, Reifegrade) - Menüpunkt „Lieferanten" aktiv; Lieferant ↔ Asset verknüpft (Graph) Verifiziert: Register/Detail/Bearbeiten dunkel & vollständig, Reifegrad- Save (6.1.2→4 mit Audit), Managemententscheidungs-Logik. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
18bd82e54a
commit
32ab91efbf
@@ -341,5 +341,122 @@
|
||||
"legCrit": "Critical (K≥3)",
|
||||
"empty": "No processes/assets available for a graph yet.",
|
||||
"openGraph": "Show in dependency graph"
|
||||
},
|
||||
"suppliers": {
|
||||
"title": "Suppliers & service providers",
|
||||
"sub": "VDA-ISA 2027 ch. 6 · NIS2 supply chain (Art. 21(2)(d))",
|
||||
"crumb": "Core data",
|
||||
"new": "Supplier",
|
||||
"newSupplier": "New supplier",
|
||||
"ref": "ID",
|
||||
"kpiTotal": "Suppliers",
|
||||
"kpiNis2": "NIS2-relevant",
|
||||
"kpiExpiring": "Expiring (90 d)",
|
||||
"kpiReviews": "Reviews due",
|
||||
"name": "Name",
|
||||
"sector": "Sector",
|
||||
"services": "Service / IT services",
|
||||
"criticality": "Criticality",
|
||||
"dataCategories": "Data categories (comma-separated)",
|
||||
"protection": "Protection needs",
|
||||
"nis2": "NIS2-relevant (supply chain)",
|
||||
"status": "Status",
|
||||
"contact": "Contact",
|
||||
"nextReview": "Next review",
|
||||
"notes": "Notes",
|
||||
"empty": "No suppliers recorded.",
|
||||
"detailSub": "Assessment, contracts, evidence & responsibility",
|
||||
"createTitle": "Create supplier",
|
||||
"editTitle": "Edit supplier",
|
||||
"masterPill": "■ Master data",
|
||||
"catalog": "VDA-ISA 2027 · ch. 6 Supplier Relationships",
|
||||
"catalogNote": "Maturity per objective (target 3)",
|
||||
"target": "Target",
|
||||
"maturity": "Maturity",
|
||||
"references": "References",
|
||||
"objective": "Objective",
|
||||
"must": "Must",
|
||||
"should": "Should",
|
||||
"high": "High protection",
|
||||
"veryHigh": "Very high protection",
|
||||
"sga": "Simplified Group Assessment",
|
||||
"assessments": "Security assessments",
|
||||
"addAssessment": "Add assessment",
|
||||
"score": "Score",
|
||||
"result": "Result",
|
||||
"type": "Type",
|
||||
"date": "Date",
|
||||
"contracts": "Contracts",
|
||||
"addContract": "Add contract",
|
||||
"avDpa": "DPA (Art. 28)",
|
||||
"securityClauses": "Security clauses",
|
||||
"flowdown": "Flow-down (subcontractors)",
|
||||
"customerTransparency": "Customer transparency",
|
||||
"validFrom": "Valid from",
|
||||
"validTo": "Valid to",
|
||||
"reference": "Reference",
|
||||
"ndas": "NDA / non-disclosure",
|
||||
"addNda": "Add NDA",
|
||||
"parties": "Parties",
|
||||
"infoScope": "Information type",
|
||||
"subject": "Subject",
|
||||
"obligations": "Obligations",
|
||||
"extensionStatus": "Extension",
|
||||
"evidence": "Evidence & assurance",
|
||||
"addEvidence": "Add evidence",
|
||||
"kind": "Kind",
|
||||
"protectsCia": "Covers (C/I/A)",
|
||||
"adequacy": "Adequacy checked",
|
||||
"expires": "expires",
|
||||
"raci": "Responsibility (shared responsibility)",
|
||||
"addRaci": "Add assignment",
|
||||
"itService": "IT service",
|
||||
"requirement": "Requirement",
|
||||
"responsible": "Responsible",
|
||||
"isaApplicability": "ISA applicability",
|
||||
"localControls": "Local controls",
|
||||
"subcontractors": "Subcontractors (4th party)",
|
||||
"addSub": "Add subcontractor",
|
||||
"flowdownObl": "Flow-down obligation",
|
||||
"decision": "Risk-based management decision",
|
||||
"addDecision": "Record decision",
|
||||
"reasonNoAudit": "Reason (no audit/label)",
|
||||
"decisionText": "Decision",
|
||||
"decidedBy": "Decided by",
|
||||
"recordRef": "Record ref",
|
||||
"decisionNeeded": "No third-party audit/TISAX label with checked adequacy present — a documented risk-based management decision is required.",
|
||||
"assets": "Affected assets",
|
||||
"close": "Close",
|
||||
"none": "—",
|
||||
"add": "Add"
|
||||
},
|
||||
"assessmentType": {
|
||||
"QUESTIONNAIRE": "Questionnaire",
|
||||
"SELF_ASSESSMENT": "Self-assessment",
|
||||
"AUDIT": "Audit"
|
||||
},
|
||||
"assessmentStatus": {
|
||||
"SENT": "Sent",
|
||||
"RECEIVED": "Received",
|
||||
"EVALUATED": "Evaluated",
|
||||
"OVERDUE": "Overdue"
|
||||
},
|
||||
"evidenceKind": {
|
||||
"CERTIFICATE": "Certificate",
|
||||
"TISAX_LABEL": "TISAX label",
|
||||
"ATTESTATION": "Attestation",
|
||||
"AUDIT_REPORT": "Audit report",
|
||||
"SELF_ASSESSMENT": "Self-assessment"
|
||||
},
|
||||
"responsibleParty": {
|
||||
"CLIENT": "Client",
|
||||
"SUPPLIER": "Supplier",
|
||||
"SHARED": "Shared"
|
||||
},
|
||||
"supplierStatus": {
|
||||
"ACTIVE": "Active",
|
||||
"ONBOARDING": "Onboarding",
|
||||
"UNDER_REVIEW": "Under review",
|
||||
"OFFBOARDED": "Offboarded"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user