Delta-Update des VDA-ISA-2027-Vorlagenpakets eingepflegt: - Aktualisiertes Seed-Paket (ersetzt bisherigen Stand): 316 Anforderungen (122 MUSS · 132 SOLL · 43 HOCH · 19 SEHR HOCH) über 45 Controls; VA-01/VA-05 jetzt enthalten (13 Verfahren vollständig). Beschädigte RACI-Tokens (VA-05/08/09/ 10/12/13) repariert. Importer: Umsetzungstext aus den .md-IMPL-Ankern extrahiert (mapping.json führt ihn nicht mehr), neue Obligation-Typen HOCH/SEHR HOCH. - Neue Schutzbedarf-Flags (variables.schema): FLAG_HIGH_PROTECTION, FLAG_VERY_HIGH_PROTECTION, FLAG_ELEVATED_PROTECTION (abgeleitet). Render-Helper applyProtection: HIGH stets an, VERY_HIGH aus Global/Override, ELEVATED = HIGH||VH (nie manuell) — angewandt in Lese-, Bearbeiten-, Handbuch- und Coverage-Rendering. - TISAX-Level-Schalter (AL2/AL3) zentral auf der Bibliothek (setGlobalTisaxLevel); AL2 = MUSS/SOLL/HOCH, AL3 = zusätzlich SEHR HOCH. Override je Richtlinie im Bearbeitungsmodus (setProtectionOverride, Feld protection_override); effektiver Wert = Dokument-Override sonst global. - KPIs zeigen 316 Anforderungen mit Aufschlüsselung; Coverage/Badges für HOCH/SEHR HOCH; Control-Titel-Fallback. Verifiziert: Import 316/45; Rendering rückstandsfrei über AL2/AL3 × Flag-Kombis; Override R04→AL3 zeigt SEHR-HOCH-Inhalt, R02 (global AL2) nicht; global bleibt AL2. Architektur-Hinweis: applyProtection kapselt das Level→Flags-Mapping, sodass die globale Ebene später ohne Umbau zur TISAX-AL2/AL3-Auswahl wird (bereits so gebaut). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
5051 lines
149 KiB
JSON
5051 lines
149 KiB
JSON
{
|
|
"meta": {
|
|
"paket": "ISMS-Vorlagenpaket v2",
|
|
"standard": "VDA ISA 2027 (Information Security)",
|
|
"hinweis": "Anforderungen 1:1 aus ISA; Umsetzung gebuendelt je Control. is_isa=false = kundenspezifische Ergaenzung (z.B. KI).",
|
|
"isa_quelldubletten": [
|
|
{
|
|
"control": "1.6.3",
|
|
"ebene": "high",
|
|
"doppelte_quellzeilen": 3,
|
|
"abgedeckt_durch": [
|
|
"1.6.3-H1",
|
|
"1.6.3-H2",
|
|
"1.6.3-H5"
|
|
],
|
|
"hinweis": "ISA wiederholt Krisenszenario-/Ressourcen-/Test-Zeilen mit/ohne Zusatz \"The following aspects are considered\"."
|
|
},
|
|
{
|
|
"control": "5.2.9",
|
|
"ebene": "high",
|
|
"doppelte_quellzeilen": 1,
|
|
"abgedeckt_durch": [
|
|
"5.2.9-H1"
|
|
],
|
|
"hinweis": "ISA-Zeile \"Backup and recovery concepts exist\" ist redundant zum Must-Konzept und zu H1."
|
|
}
|
|
],
|
|
"coverage": "316 eindeutige ISA-Zeilen; 4 Quelldubletten konsolidiert -> 312 eindeutige Anforderungen (100% inhaltliche Abdeckung). Plus 4 kundenspezifische KI-Anforderungen."
|
|
},
|
|
"anforderungen": [
|
|
{
|
|
"id": "1.1.1-M1",
|
|
"policy": "L00",
|
|
"control": "1.1.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.1.1-M1",
|
|
"impl_anchor": "REQ 1.1.1-M1",
|
|
"condition": null,
|
|
"requirement": "Die Anforderungen der Informationssicherheit sind bestimmt, dokumentiert und an den Zielen der Organisation ausgerichtet.",
|
|
"link": "{{LINK:L00#1.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.1.1-M2",
|
|
"policy": "L00",
|
|
"control": "1.1.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.1.1-M2",
|
|
"impl_anchor": "REQ 1.1.1-M2",
|
|
"condition": null,
|
|
"requirement": "Eine Leitlinie existiert und ist durch die Leitung der Organisation genehmigt.",
|
|
"link": "{{LINK:L00#1.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.1.1-M3",
|
|
"policy": "L00",
|
|
"control": "1.1.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.1.1-M3",
|
|
"impl_anchor": "REQ 1.1.1-M3",
|
|
"condition": null,
|
|
"requirement": "Die Leitlinie benennt Ziele und die Bedeutung der Informationssicherheit innerhalb der Organisation.",
|
|
"link": "{{LINK:L00#1.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.1.1-M4",
|
|
"policy": "L00",
|
|
"control": "1.1.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.1.1-M4",
|
|
"impl_anchor": "REQ 1.1.1-M4",
|
|
"condition": null,
|
|
"requirement": "Die Leitlinien werden den Beschäftigten in geeigneter Form zur Verfügung gestellt (z. B. Intranet).",
|
|
"link": "{{LINK:L00#1.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.1.1-M5",
|
|
"policy": "L00",
|
|
"control": "1.1.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.1.1-M5",
|
|
"impl_anchor": "REQ 1.1.1-M5",
|
|
"condition": null,
|
|
"requirement": "Beschäftigte und externe Geschäftspartner werden über für sie relevante Änderungen informiert.",
|
|
"link": "{{LINK:L00#1.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.1.1-S1",
|
|
"policy": "L00",
|
|
"control": "1.1.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.1.1-S1",
|
|
"impl_anchor": "REQ 1.1.1-S1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Die Informationssicherheitsanforderungen basieren auf der Strategie der Organisation; Gesetze und Verträge werden in der Leitlinie berücksichtigt.",
|
|
"link": "{{LINK:L00#1.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.1.1-S2",
|
|
"policy": "L00",
|
|
"control": "1.1.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.1.1-S2",
|
|
"impl_anchor": "REQ 1.1.1-S2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Die Leitlinie benennt Konsequenzen bei Nichteinhaltung.",
|
|
"link": "{{LINK:L00#1.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.1.1-S3",
|
|
"policy": "L00",
|
|
"control": "1.1.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.1.1-S3",
|
|
"impl_anchor": "REQ 1.1.1-S3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Weitere relevante Sicherheitsrichtlinien sind etabliert.",
|
|
"link": "{{LINK:L00#1.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.1.1-S4",
|
|
"policy": "L00",
|
|
"control": "1.1.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.1.1-S4",
|
|
"impl_anchor": "REQ 1.1.1-S4",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Regelmäßige Überprüfung und ggf. Überarbeitung der Richtlinien sind etabliert.",
|
|
"link": "{{LINK:L00#1.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.2.1-M1",
|
|
"policy": "R01",
|
|
"control": "1.2.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.2.1-M1",
|
|
"impl_anchor": "IMPL 1.2.1",
|
|
"condition": null,
|
|
"requirement": "Der Geltungsbereich des ISMS (die durch das ISMS gesteuerte Organisation) ist definiert.",
|
|
"link": "{{LINK:R01#1.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.2.1-M2",
|
|
"policy": "R01",
|
|
"control": "1.2.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.2.1-M2",
|
|
"impl_anchor": "IMPL 1.2.1",
|
|
"condition": null,
|
|
"requirement": "Die Anforderungen der Organisation an das ISMS sind bestimmt.",
|
|
"link": "{{LINK:R01#1.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.2.1-M3",
|
|
"policy": "R01",
|
|
"control": "1.2.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.2.1-M3",
|
|
"impl_anchor": "IMPL 1.2.1",
|
|
"condition": null,
|
|
"requirement": "Die Organisationsleitung hat das ISMS beauftragt und genehmigt.",
|
|
"link": "{{LINK:R01#1.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.2.1-M4",
|
|
"policy": "R01",
|
|
"control": "1.2.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.2.1-M4",
|
|
"impl_anchor": "IMPL 1.2.1",
|
|
"condition": null,
|
|
"requirement": "Das ISMS stellt der Organisationsleitung geeignete Mittel zur Überwachung und Steuerung bereit (z. B. Managementbewertung).",
|
|
"link": "{{LINK:R01#1.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.2.1-M5",
|
|
"policy": "R01",
|
|
"control": "1.2.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.2.1-M5",
|
|
"impl_anchor": "IMPL 1.2.1",
|
|
"condition": null,
|
|
"requirement": "Die anwendbaren Controls sind bestimmt (z. B. ISO-27001-Anwendbarkeitserklärung oder ausgefüllter ISA-Katalog).",
|
|
"link": "{{LINK:R01#1.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.2.1-M6",
|
|
"policy": "R01",
|
|
"control": "1.2.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.2.1-M6",
|
|
"impl_anchor": "IMPL 1.2.1",
|
|
"condition": null,
|
|
"requirement": "Die Wirksamkeit des ISMS wird regelmäßig durch die Leitung überprüft.",
|
|
"link": "{{LINK:R01#1.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.2.2-M1",
|
|
"policy": "R01",
|
|
"control": "1.2.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.2.2-M1",
|
|
"impl_anchor": "IMPL 1.2.2",
|
|
"condition": null,
|
|
"requirement": "Verantwortlichkeiten für Informationssicherheit sind definiert, dokumentiert und zugewiesen.",
|
|
"link": "{{LINK:R01#1.2.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.2.2-M2",
|
|
"policy": "R01",
|
|
"control": "1.2.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.2.2-M2",
|
|
"impl_anchor": "IMPL 1.2.2",
|
|
"condition": null,
|
|
"requirement": "Die verantwortlichen Beschäftigten sind definiert, qualifiziert und für ihre Aufgabe befähigt.",
|
|
"link": "{{LINK:R01#1.2.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.2.2-M3",
|
|
"policy": "R01",
|
|
"control": "1.2.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.2.2-M3",
|
|
"impl_anchor": "IMPL 1.2.2",
|
|
"condition": null,
|
|
"requirement": "Die erforderlichen Ressourcen stehen zur Verfügung.",
|
|
"link": "{{LINK:R01#1.2.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.2.2-M4",
|
|
"policy": "R01",
|
|
"control": "1.2.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.2.2-M4",
|
|
"impl_anchor": "IMPL 1.2.2",
|
|
"condition": null,
|
|
"requirement": "Die Ansprechpartner sind innerhalb der Organisation und relevanten Geschäftspartnern bekannt.",
|
|
"link": "{{LINK:R01#1.2.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.2.2-S1",
|
|
"policy": "R01",
|
|
"control": "1.2.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.2.2-S1",
|
|
"impl_anchor": "IMPL 1.2.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Es besteht eine Definition und Dokumentation einer angemessenen Informationssicherheitsstruktur innerhalb der Organisation.",
|
|
"link": "{{LINK:R01#1.2.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.2.2-S2",
|
|
"policy": "R01",
|
|
"control": "1.2.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.2.2-S2",
|
|
"impl_anchor": "IMPL 1.2.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Sicherheitsrelevante Rollen, die nicht Teil des ISMS, aber für die Informationssicherheit relevant sind, werden berücksichtigt.",
|
|
"link": "{{LINK:R01#1.2.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.2.2-H1",
|
|
"policy": "R01",
|
|
"control": "1.2.2",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.2.2-H1",
|
|
"impl_anchor": "IMPL 1.2.2-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Eine angemessene organisatorische Trennung von Verantwortlichkeiten ist etabliert, um Interessenkonflikte zu vermeiden (Funktionstrennung). (C, I, A)",
|
|
"link": "{{LINK:R01#1.2.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.2.3-M1",
|
|
"policy": "R01",
|
|
"control": "1.2.3",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.2.3-M1",
|
|
"impl_anchor": "IMPL 1.2.3",
|
|
"condition": null,
|
|
"requirement": "Projekte werden unter Berücksichtigung der Informationssicherheitsanforderungen klassifiziert.",
|
|
"link": "{{LINK:R01#1.2.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.2.3-S1",
|
|
"policy": "R01",
|
|
"control": "1.2.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.2.3-S1",
|
|
"impl_anchor": "IMPL 1.2.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Verfahren und Kriterien für die Klassifizierung von Projekten sind dokumentiert.",
|
|
"link": "{{LINK:R01#1.2.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.2.3-S2",
|
|
"policy": "R01",
|
|
"control": "1.2.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.2.3-S2",
|
|
"impl_anchor": "IMPL 1.2.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "In einer frühen Projektphase wird eine Risikobewertung nach dem definierten Verfahren durchgeführt und bei Projektänderungen wiederholt.",
|
|
"link": "{{LINK:R01#1.2.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.2.3-S3",
|
|
"policy": "R01",
|
|
"control": "1.2.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.2.3-S3",
|
|
"impl_anchor": "IMPL 1.2.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Für identifizierte Informationssicherheitsrisiken werden Maßnahmen abgeleitet und im Projekt berücksichtigt.",
|
|
"link": "{{LINK:R01#1.2.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.2.3-H1",
|
|
"policy": "R01",
|
|
"control": "1.2.3",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.2.3-H1",
|
|
"impl_anchor": "IMPL 1.2.3-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Die abgeleiteten Maßnahmen werden während des Projekts regelmäßig überprüft und bei Änderungen der Bewertungskriterien neu bewertet. (C, I, A)",
|
|
"link": "{{LINK:R01#1.2.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.3.1-M1",
|
|
"policy": "R02",
|
|
"control": "1.3.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.3.1-M1",
|
|
"impl_anchor": "IMPL 1.3.1",
|
|
"condition": null,
|
|
"requirement": "Informationswerte und weitere sicherheitsrelevante Assets der Organisation sind identifiziert und erfasst.",
|
|
"link": "{{LINK:R02#1.3.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-08"
|
|
]
|
|
},
|
|
{
|
|
"id": "1.3.1-M2",
|
|
"policy": "R02",
|
|
"control": "1.3.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.3.1-M2",
|
|
"impl_anchor": "IMPL 1.3.1",
|
|
"condition": null,
|
|
"requirement": "Die unterstützenden Assets, die die Informationswerte verarbeiten, sind identifiziert und erfasst.",
|
|
"link": "{{LINK:R02#1.3.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-08"
|
|
]
|
|
},
|
|
{
|
|
"id": "1.3.1-S1",
|
|
"policy": "R02",
|
|
"control": "1.3.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.3.1-S1",
|
|
"impl_anchor": "IMPL 1.3.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Ein Katalog der relevanten Informationswerte existiert; dabei werden die einschlägigen Aspekte berücksichtigt.",
|
|
"link": "{{LINK:R02#1.3.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-08"
|
|
]
|
|
},
|
|
{
|
|
"id": "1.3.2-M1",
|
|
"policy": "R02",
|
|
"control": "1.3.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.3.2-M1",
|
|
"impl_anchor": "IMPL 1.3.2",
|
|
"condition": null,
|
|
"requirement": "Ein konsistentes Schema zur Klassifizierung von Informationswerten hinsichtlich des Schutzziels Vertraulichkeit ist vorhanden.",
|
|
"link": "{{LINK:R02#1.3.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-08"
|
|
]
|
|
},
|
|
{
|
|
"id": "1.3.2-M2",
|
|
"policy": "R02",
|
|
"control": "1.3.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.3.2-M2",
|
|
"impl_anchor": "IMPL 1.3.2",
|
|
"condition": null,
|
|
"requirement": "Die Bewertung der identifizierten Informationswerte erfolgt nach den definierten Kriterien und wird dem Klassifizierungsschema zugeordnet.",
|
|
"link": "{{LINK:R02#1.3.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-08"
|
|
]
|
|
},
|
|
{
|
|
"id": "1.3.2-M3",
|
|
"policy": "R02",
|
|
"control": "1.3.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.3.2-M3",
|
|
"impl_anchor": "IMPL 1.3.2",
|
|
"condition": null,
|
|
"requirement": "Vorgaben zur Handhabung unterstützender Assets (z. B. Kennzeichnung, Nutzung, Transport, Speicherung, Rückgabe, Löschung/Vernichtung) abhängig von der Klassifizierung sind vorhanden und umgesetzt.",
|
|
"link": "{{LINK:R02#1.3.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.3.2-S1",
|
|
"policy": "R02",
|
|
"control": "1.3.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.3.2-S1",
|
|
"impl_anchor": "IMPL 1.3.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Die Schutzziele Integrität und Verfügbarkeit werden berücksichtigt.",
|
|
"link": "{{LINK:R02#1.3.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-08"
|
|
]
|
|
},
|
|
{
|
|
"id": "1.3.3-M1",
|
|
"policy": "R02",
|
|
"control": "1.3.3",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.3.3-M1",
|
|
"impl_anchor": "IMPL 1.3.3",
|
|
"condition": null,
|
|
"requirement": "Externe IT-Dienste werden nicht ohne ausdrückliche Bewertung und Umsetzung der Informationssicherheitsanforderungen genutzt; dabei werden die einschlägigen Aspekte berücksichtigt.",
|
|
"link": "{{LINK:R02#1.3.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.3.3-M2",
|
|
"policy": "R02",
|
|
"control": "1.3.3",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.3.3-M2",
|
|
"impl_anchor": "IMPL 1.3.3",
|
|
"condition": null,
|
|
"requirement": "Die externen IT-Dienste sind mit dem Schutzbedarf der verarbeiteten Informationswerte abgestimmt.",
|
|
"link": "{{LINK:R02#1.3.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.3.3-S1",
|
|
"policy": "R02",
|
|
"control": "1.3.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.3.3-S1",
|
|
"impl_anchor": "IMPL 1.3.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Anforderungen an Beschaffung, Inbetriebnahme und Freigabe im Zusammenhang mit der Nutzung externer IT-Dienste sind bestimmt und erfüllt.",
|
|
"link": "{{LINK:R02#1.3.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.3.3-S2",
|
|
"policy": "R02",
|
|
"control": "1.3.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.3.3-S2",
|
|
"impl_anchor": "IMPL 1.3.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Ein Verfahren zur Freigabe unter Berücksichtigung des Schutzbedarfs ist etabliert.",
|
|
"link": "{{LINK:R02#1.3.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.3.3-S3",
|
|
"policy": "R02",
|
|
"control": "1.3.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.3.3-S3",
|
|
"impl_anchor": "IMPL 1.3.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Externe IT-Dienste und ihre Freigabe sind dokumentiert.",
|
|
"link": "{{LINK:R02#1.3.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.3.3-S4",
|
|
"policy": "R02",
|
|
"control": "1.3.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.3.3-S4",
|
|
"impl_anchor": "IMPL 1.3.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Es wird regelmäßig überprüft, dass nur freigegebene externe IT-Dienste genutzt werden.",
|
|
"link": "{{LINK:R02#1.3.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.3.4-M1",
|
|
"policy": "R02",
|
|
"control": "1.3.4",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.3.4-M1",
|
|
"impl_anchor": "IMPL 1.3.4",
|
|
"condition": null,
|
|
"requirement": "Software wird vor Installation oder Nutzung freigegeben; dabei werden die einschlägigen Aspekte berücksichtigt.",
|
|
"link": "{{LINK:R02#1.3.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.3.4-M2",
|
|
"policy": "R02",
|
|
"control": "1.3.4",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.3.4-M2",
|
|
"impl_anchor": "IMPL 1.3.4",
|
|
"condition": null,
|
|
"requirement": "Die Softwarefreigabe gilt auch für Spezialsoftware wie Wartungswerkzeuge.",
|
|
"link": "{{LINK:R02#1.3.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.3.4-S1",
|
|
"policy": "R02",
|
|
"control": "1.3.4",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.3.4-S1",
|
|
"impl_anchor": "IMPL 1.3.4",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Die zu verwaltenden Softwarearten (Firmware, Betriebssysteme, Anwendungen, Bibliotheken, Gerätetreiber) sind bestimmt.",
|
|
"link": "{{LINK:R02#1.3.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.3.4-S2",
|
|
"policy": "R02",
|
|
"control": "1.3.4",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.3.4-S2",
|
|
"impl_anchor": "IMPL 1.3.4",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Repositorys der verwalteten Software existieren.",
|
|
"link": "{{LINK:R02#1.3.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.3.4-S3",
|
|
"policy": "R02",
|
|
"control": "1.3.4",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.3.4-S3",
|
|
"impl_anchor": "IMPL 1.3.4",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Die Software-Repositorys sind gegen unbefugte Manipulation geschützt.",
|
|
"link": "{{LINK:R02#1.3.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.3.4-S4",
|
|
"policy": "R02",
|
|
"control": "1.3.4",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.3.4-S4",
|
|
"impl_anchor": "IMPL 1.3.4",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Die Freigabe von Software wird regelmäßig überprüft.",
|
|
"link": "{{LINK:R02#1.3.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.3.4-S5",
|
|
"policy": "R02",
|
|
"control": "1.3.4",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.3.4-S5",
|
|
"impl_anchor": "IMPL 1.3.4",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Softwareversionen und Patch-Stände sind bekannt.",
|
|
"link": "{{LINK:R02#1.3.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.3.4-V1",
|
|
"policy": "R02",
|
|
"control": "1.3.4",
|
|
"level": "vhigh",
|
|
"type": "SEHR HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.3.4-V1",
|
|
"impl_anchor": "IMPL 1.3.4-elev",
|
|
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
|
"requirement": "Zusätzliche Anforderungen an die Softwarenutzung (z. B. Kontroll-/Überwachungsbedarf der Nutzung) sind, sofern vorhanden, bestimmt. (C, I, A)",
|
|
"link": "{{LINK:R02#1.3.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.4.1-M1",
|
|
"policy": "R03",
|
|
"control": "1.4.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.4.1-M1",
|
|
"impl_anchor": "IMPL 1.4.1",
|
|
"condition": null,
|
|
"requirement": "Risikobewertungen werden regelmäßig und anlassbezogen durchgeführt.",
|
|
"link": "{{LINK:R03#1.4.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-09"
|
|
]
|
|
},
|
|
{
|
|
"id": "1.4.1-M2",
|
|
"policy": "R03",
|
|
"control": "1.4.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.4.1-M2",
|
|
"impl_anchor": "IMPL 1.4.1",
|
|
"condition": null,
|
|
"requirement": "Informationssicherheitsrisiken werden angemessen bewertet (z. B. Eintrittswahrscheinlichkeit und mögliches Schadensausmaß).",
|
|
"link": "{{LINK:R03#1.4.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-09"
|
|
]
|
|
},
|
|
{
|
|
"id": "1.4.1-M3",
|
|
"policy": "R03",
|
|
"control": "1.4.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.4.1-M3",
|
|
"impl_anchor": "IMPL 1.4.1",
|
|
"condition": null,
|
|
"requirement": "Informationssicherheitsrisiken werden dokumentiert.",
|
|
"link": "{{LINK:R03#1.4.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-09"
|
|
]
|
|
},
|
|
{
|
|
"id": "1.4.1-M4",
|
|
"policy": "R03",
|
|
"control": "1.4.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.4.1-M4",
|
|
"impl_anchor": "IMPL 1.4.1",
|
|
"condition": null,
|
|
"requirement": "Jedem Informationssicherheitsrisiko ist ein Verantwortlicher (Risk Owner) zugeordnet, der für Bewertung und Behandlung verantwortlich ist.",
|
|
"link": "{{LINK:R03#1.4.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.4.1-S1",
|
|
"policy": "R03",
|
|
"control": "1.4.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.4.1-S1",
|
|
"impl_anchor": "IMPL 1.4.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Ein Verfahren zur Identifikation, Bewertung und Behandlung von Sicherheitsrisiken ist vorhanden.",
|
|
"link": "{{LINK:R03#1.4.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-09"
|
|
]
|
|
},
|
|
{
|
|
"id": "1.4.1-S2",
|
|
"policy": "R03",
|
|
"control": "1.4.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.4.1-S2",
|
|
"impl_anchor": "IMPL 1.4.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Kriterien für Bewertung und Behandlung von Sicherheitsrisiken existieren.",
|
|
"link": "{{LINK:R03#1.4.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.4.1-S3",
|
|
"policy": "R03",
|
|
"control": "1.4.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.4.1-S3",
|
|
"impl_anchor": "IMPL 1.4.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Maßnahmen zur Risikobehandlung und ihre Verantwortlichen sind festgelegt und dokumentiert; ein Maßnahmenplan bzw. eine Umsetzungsübersicht wird nachverfolgt.",
|
|
"link": "{{LINK:R03#1.4.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.4.1-S4",
|
|
"policy": "R03",
|
|
"control": "1.4.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.4.1-S4",
|
|
"impl_anchor": "IMPL 1.4.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Bei Änderungen des Umfelds (z. B. Organisationsstruktur, Standort, Regularien) erfolgt zeitnah eine Neubewertung.",
|
|
"link": "{{LINK:R03#1.4.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.5.1-M1",
|
|
"policy": "R03",
|
|
"control": "1.5.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.5.1-M1",
|
|
"impl_anchor": "IMPL 1.5.1",
|
|
"condition": null,
|
|
"requirement": "Die Einhaltung der Richtlinien wird organisationsweit überprüft.",
|
|
"link": "{{LINK:R03#1.5.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.5.1-M2",
|
|
"policy": "R03",
|
|
"control": "1.5.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.5.1-M2",
|
|
"impl_anchor": "IMPL 1.5.1",
|
|
"condition": null,
|
|
"requirement": "Informationssicherheitsrichtlinien und -verfahren werden regelmäßig überprüft.",
|
|
"link": "{{LINK:R03#1.5.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.5.1-M3",
|
|
"policy": "R03",
|
|
"control": "1.5.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.5.1-M3",
|
|
"impl_anchor": "IMPL 1.5.1",
|
|
"condition": null,
|
|
"requirement": "Maßnahmen zur Korrektur möglicher Abweichungen werden eingeleitet und verfolgt.",
|
|
"link": "{{LINK:R03#1.5.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.5.1-M4",
|
|
"policy": "R03",
|
|
"control": "1.5.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.5.1-M4",
|
|
"impl_anchor": "IMPL 1.5.1",
|
|
"condition": null,
|
|
"requirement": "Die Einhaltung von Informationssicherheitsanforderungen (z. B. technische Vorgaben) wird regelmäßig überprüft.",
|
|
"link": "{{LINK:R03#1.5.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.5.1-M5",
|
|
"policy": "R03",
|
|
"control": "1.5.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.5.1-M5",
|
|
"impl_anchor": "IMPL 1.5.1",
|
|
"condition": null,
|
|
"requirement": "Die Ergebnisse der durchgeführten Überprüfungen werden aufgezeichnet und aufbewahrt.",
|
|
"link": "{{LINK:R03#1.5.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.5.1-S1",
|
|
"policy": "R03",
|
|
"control": "1.5.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.5.1-S1",
|
|
"impl_anchor": "IMPL 1.5.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Ein Plan für Inhalt und Rahmenbedingungen (Zeitplan, Umfang, Controls) der durchzuführenden Überprüfungen liegt vor.",
|
|
"link": "{{LINK:R03#1.5.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.5.2-M1",
|
|
"policy": "R03",
|
|
"control": "1.5.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.5.2-M1",
|
|
"impl_anchor": "IMPL 1.5.2",
|
|
"condition": null,
|
|
"requirement": "Informationssicherheitsüberprüfungen werden durch eine unabhängige und kompetente Stelle regelmäßig und nach grundlegenden Änderungen durchgeführt.",
|
|
"link": "{{LINK:R03#1.5.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.5.2-M2",
|
|
"policy": "R03",
|
|
"control": "1.5.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.5.2-M2",
|
|
"impl_anchor": "IMPL 1.5.2",
|
|
"condition": null,
|
|
"requirement": "Maßnahmen zur Korrektur möglicher Abweichungen werden eingeleitet und verfolgt.",
|
|
"link": "{{LINK:R03#1.5.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.5.2-S1",
|
|
"policy": "R03",
|
|
"control": "1.5.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.5.2-S1",
|
|
"impl_anchor": "IMPL 1.5.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Die Ergebnisse durchgeführter Überprüfungen werden dokumentiert und der Organisationsleitung berichtet.",
|
|
"link": "{{LINK:R03#1.5.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.1-M1",
|
|
"policy": "R04",
|
|
"control": "1.6.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.1-M1",
|
|
"impl_anchor": "IMPL 1.6.1",
|
|
"condition": null,
|
|
"requirement": "Eine Definition für ein meldepflichtiges Sicherheitsereignis oder eine Beobachtung existiert und ist Beschäftigten und relevanten Stakeholdern bekannt.",
|
|
"link": "{{LINK:R04#1.6.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-01"
|
|
]
|
|
},
|
|
{
|
|
"id": "1.6.1-M2",
|
|
"policy": "R04",
|
|
"control": "1.6.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.1-M2",
|
|
"impl_anchor": "IMPL 1.6.1",
|
|
"condition": null,
|
|
"requirement": "Angemessene, risikoorientierte Mechanismen zur Meldung von Sicherheitsereignissen sind definiert, umgesetzt und allen relevanten Meldenden bekannt.",
|
|
"link": "{{LINK:R04#1.6.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-01"
|
|
]
|
|
},
|
|
{
|
|
"id": "1.6.1-M3",
|
|
"policy": "R04",
|
|
"control": "1.6.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.1-M3",
|
|
"impl_anchor": "IMPL 1.6.1",
|
|
"condition": null,
|
|
"requirement": "Angemessene Kanäle zur Kommunikation mit Meldenden existieren.",
|
|
"link": "{{LINK:R04#1.6.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.1-S1",
|
|
"policy": "R04",
|
|
"control": "1.6.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.1-S1",
|
|
"impl_anchor": "IMPL 1.6.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Eine gemeinsame Anlaufstelle für die Ereignismeldung existiert.",
|
|
"link": "{{LINK:R04#1.6.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.1-S2",
|
|
"policy": "R04",
|
|
"control": "1.6.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.1-S2",
|
|
"impl_anchor": "IMPL 1.6.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Verschiedene Meldekanäle je nach wahrgenommener Schwere (Echtzeit für gravierende Ereignisse/Notfälle sowie asynchrone Mechanismen wie Tickets oder E-Mail) sind verfügbar.",
|
|
"link": "{{LINK:R04#1.6.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.1-S3",
|
|
"policy": "R04",
|
|
"control": "1.6.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.1-S3",
|
|
"impl_anchor": "IMPL 1.6.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Beschäftigte sind verpflichtet und geschult, relevante Ereignisse zu melden.",
|
|
"link": "{{LINK:R04#1.6.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.1-S4",
|
|
"policy": "R04",
|
|
"control": "1.6.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.1-S4",
|
|
"impl_anchor": "IMPL 1.6.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Sicherheitsereignisse können auch durch Externe gemeldet werden; die einschlägigen Aspekte werden berücksichtigt.",
|
|
"link": "{{LINK:R04#1.6.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.1-S5",
|
|
"policy": "R04",
|
|
"control": "1.6.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.1-S5",
|
|
"impl_anchor": "IMPL 1.6.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Der Mechanismus und die Information, wie Vorfälle gemeldet werden, sind für alle relevanten Meldenden zugänglich.",
|
|
"link": "{{LINK:R04#1.6.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.1-S6",
|
|
"policy": "R04",
|
|
"control": "1.6.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.1-S6",
|
|
"impl_anchor": "IMPL 1.6.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Ein Rückmeldeverfahren an die Meldenden ist etabliert.",
|
|
"link": "{{LINK:R04#1.6.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.1-V1",
|
|
"policy": "R04",
|
|
"control": "1.6.1",
|
|
"level": "vhigh",
|
|
"type": "SEHR HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.1-V1",
|
|
"impl_anchor": "IMPL 1.6.1-elev",
|
|
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
|
"requirement": "Tests und Übungen der Ereignis- und Beobachtungsmeldung werden regelmäßig durchgeführt. (C, I, A)",
|
|
"link": "{{LINK:R04#1.6.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.2-M1",
|
|
"policy": "R04",
|
|
"control": "1.6.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.2-M1",
|
|
"impl_anchor": "IMPL 1.6.2",
|
|
"condition": null,
|
|
"requirement": "Gemeldete Ereignisse werden ohne unangemessene Verzögerung bearbeitet.",
|
|
"link": "{{LINK:R04#1.6.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-01"
|
|
]
|
|
},
|
|
{
|
|
"id": "1.6.2-M2",
|
|
"policy": "R04",
|
|
"control": "1.6.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.2-M2",
|
|
"impl_anchor": "IMPL 1.6.2",
|
|
"condition": null,
|
|
"requirement": "Eine angemessene Reaktion auf gemeldete Sicherheitsereignisse ist sichergestellt.",
|
|
"link": "{{LINK:R04#1.6.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-01"
|
|
]
|
|
},
|
|
{
|
|
"id": "1.6.2-M3",
|
|
"policy": "R04",
|
|
"control": "1.6.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.2-M3",
|
|
"impl_anchor": "IMPL 1.6.2",
|
|
"condition": null,
|
|
"requirement": "Lessons Learned fließen in die kontinuierliche Verbesserung ein.",
|
|
"link": "{{LINK:R04#1.6.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.2-S1",
|
|
"policy": "R04",
|
|
"control": "1.6.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.2-S1",
|
|
"impl_anchor": "IMPL 1.6.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Gemeldete Ereignisse werden bei der Bearbeitung kategorisiert (z. B. Personal, physisch, Cyber), qualifiziert (z. B. nicht sicherheitsrelevant, Beobachtung, Verbesserungsvorschlag, Schwachstelle, Vorfall) und priorisiert (z. B. gering, mittel, schwer, kritisch).",
|
|
"link": "{{LINK:R04#1.6.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-01"
|
|
]
|
|
},
|
|
{
|
|
"id": "1.6.2-S2",
|
|
"policy": "R04",
|
|
"control": "1.6.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.2-S2",
|
|
"impl_anchor": "IMPL 1.6.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Verantwortlichkeiten für die Behandlung von Ereignissen je Kategorie sind definiert und zugewiesen.",
|
|
"link": "{{LINK:R04#1.6.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-01"
|
|
]
|
|
},
|
|
{
|
|
"id": "1.6.2-S3",
|
|
"policy": "R04",
|
|
"control": "1.6.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.2-S3",
|
|
"impl_anchor": "IMPL 1.6.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Eine Strategie zur Meldung potenziell strafrechtlich relevanter Aspekte an zuständige Behörden, sofern erforderlich, existiert. (C, I, A)",
|
|
"link": "{{LINK:R04#1.6.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.2-H1",
|
|
"policy": "R04",
|
|
"control": "1.6.2",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.2-H1",
|
|
"impl_anchor": "IMPL 1.6.2-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Maximale Reaktionszeiten je Klasse, Kategorie und Schwere sind definiert. (C, I, A)",
|
|
"link": "{{LINK:R04#1.6.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.2-H2",
|
|
"policy": "R04",
|
|
"control": "1.6.2",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.2-H2",
|
|
"impl_anchor": "IMPL 1.6.2-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Nicht prioritätsgerecht bearbeitete Ereignisse werden eskaliert; die einschlägigen Aspekte werden berücksichtigt. (C, I, A)",
|
|
"link": "{{LINK:R04#1.6.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.2-H3",
|
|
"policy": "R04",
|
|
"control": "1.6.2",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.2-H3",
|
|
"impl_anchor": "IMPL 1.6.2-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Gesetzliche, regulatorische und vertragliche Meldepflichten sowie zugehörige Kontaktinformationen sind bekannt. (C, I, A)",
|
|
"link": "{{LINK:R04#1.6.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.2-H4",
|
|
"policy": "R04",
|
|
"control": "1.6.2",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.2-H4",
|
|
"impl_anchor": "IMPL 1.6.2-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Eine Kommunikationsstrategie für sicherheitsrelevante Ereignisse existiert; die einschlägigen Aspekte werden berücksichtigt. (C, I, A)",
|
|
"link": "{{LINK:R04#1.6.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.2-H5",
|
|
"policy": "R04",
|
|
"control": "1.6.2",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.2-H5",
|
|
"impl_anchor": "IMPL 1.6.2-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Verfahren zur Reaktion auf Sicherheitsvorfälle bei Lieferanten sind etabliert; die einschlägigen Aspekte werden berücksichtigt. (C, I, A)",
|
|
"link": "{{LINK:R04#1.6.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.2-V1",
|
|
"policy": "R04",
|
|
"control": "1.6.2",
|
|
"level": "vhigh",
|
|
"type": "SEHR HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.2-V1",
|
|
"impl_anchor": "IMPL 1.6.2-elev",
|
|
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
|
"requirement": "Die Behandlung von Ereignissen unterschiedlicher Kategorien und Prioritäten wird regelmäßig getestet; die einschlägigen Aspekte werden berücksichtigt. (A)",
|
|
"link": "{{LINK:R04#1.6.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.3-M1",
|
|
"policy": "R04",
|
|
"control": "1.6.3",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.3-M1",
|
|
"impl_anchor": "IMPL 1.6.3",
|
|
"condition": null,
|
|
"requirement": "Ein angemessener Plan zur Reaktion auf und Bewältigung von Krisensituationen existiert und die erforderlichen Ressourcen sind verfügbar.",
|
|
"link": "{{LINK:R04#1.6.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-02"
|
|
]
|
|
},
|
|
{
|
|
"id": "1.6.3-M2",
|
|
"policy": "R04",
|
|
"control": "1.6.3",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.3-M2",
|
|
"impl_anchor": "IMPL 1.6.3",
|
|
"condition": null,
|
|
"requirement": "Verantwortlichkeiten und Befugnisse für das Krisenmanagement sind definiert, dokumentiert und zugewiesen.",
|
|
"link": "{{LINK:R04#1.6.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.3-M3",
|
|
"policy": "R04",
|
|
"control": "1.6.3",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.3-M3",
|
|
"impl_anchor": "IMPL 1.6.3",
|
|
"condition": null,
|
|
"requirement": "Die verantwortlichen Beschäftigten sind definiert und für ihre Aufgabe qualifiziert.",
|
|
"link": "{{LINK:R04#1.6.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.3-S1",
|
|
"policy": "R04",
|
|
"control": "1.6.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.3-S1",
|
|
"impl_anchor": "IMPL 1.6.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Methoden zur Erkennung von Krisensituationen sind etabliert; allgemeine Anzeichen und spezifische vorhersehbare Krisen sind identifiziert.",
|
|
"link": "{{LINK:R04#1.6.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-02"
|
|
]
|
|
},
|
|
{
|
|
"id": "1.6.3-S2",
|
|
"policy": "R04",
|
|
"control": "1.6.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.3-S2",
|
|
"impl_anchor": "IMPL 1.6.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Ein Verfahren zur Auslösung und/oder Eskalation des Krisenmanagements ist vorhanden.",
|
|
"link": "{{LINK:R04#1.6.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.3-S3",
|
|
"policy": "R04",
|
|
"control": "1.6.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.3-S3",
|
|
"impl_anchor": "IMPL 1.6.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Strategische Ziele und ihre Priorität in Krisensituationen sind definiert und relevantem Personal bekannt.",
|
|
"link": "{{LINK:R04#1.6.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.3-S4",
|
|
"policy": "R04",
|
|
"control": "1.6.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.3-S4",
|
|
"impl_anchor": "IMPL 1.6.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Ein Krisenstab ist definiert und genehmigt.",
|
|
"link": "{{LINK:R04#1.6.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.3-S5",
|
|
"policy": "R04",
|
|
"control": "1.6.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.3-S5",
|
|
"impl_anchor": "IMPL 1.6.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Krisenrichtlinien und -verfahren sind definiert und genehmigt.",
|
|
"link": "{{LINK:R04#1.6.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.3-S6",
|
|
"policy": "R04",
|
|
"control": "1.6.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.3-S6",
|
|
"impl_anchor": "IMPL 1.6.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Die Krisenplanung wird regelmäßig überprüft und aktualisiert.",
|
|
"link": "{{LINK:R04#1.6.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.3-H1",
|
|
"policy": "R04",
|
|
"control": "1.6.3",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.3-H1",
|
|
"impl_anchor": "IMPL 1.6.3-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Relevante unterschiedliche potenzielle Krisenszenarien sind identifiziert.",
|
|
"link": "{{LINK:R04#1.6.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.3-H2",
|
|
"policy": "R04",
|
|
"control": "1.6.3",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.3-H2",
|
|
"impl_anchor": "IMPL 1.6.3-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Notwendige Ressourcen und Informationen zur Krisenbewältigung (z. B. Kommunikationsinfrastruktur, Verfügbarkeit von Kontakt- und Risikoinformationen) sind identifiziert; angemessene Maßnahmen zur Sicherstellung der Verfügbarkeit bzw. Ausfallplanung sind vorhanden. (A)",
|
|
"link": "{{LINK:R04#1.6.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.3-H3",
|
|
"policy": "R04",
|
|
"control": "1.6.3",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.3-H3",
|
|
"impl_anchor": "IMPL 1.6.3-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Eine Kommunikationsstrategie für Krisensituationen existiert. (A)",
|
|
"link": "{{LINK:R04#1.6.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.3-H4",
|
|
"policy": "R04",
|
|
"control": "1.6.3",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.3-H4",
|
|
"impl_anchor": "IMPL 1.6.3-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Effizienz, Durchführbarkeit und Angemessenheit der Krisenplanung werden regelmäßig bewertet. (A)",
|
|
"link": "{{LINK:R04#1.6.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.3-H5",
|
|
"policy": "R04",
|
|
"control": "1.6.3",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.3-H5",
|
|
"impl_anchor": "IMPL 1.6.3-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Stichprobenbasierte Tests der Krisenplanung werden durchgeführt (z. B. Simulation, Tabletop-Übungen mit Schlüsselpersonal). (A)",
|
|
"link": "{{LINK:R04#1.6.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "1.6.3-V1",
|
|
"policy": "R04",
|
|
"control": "1.6.3",
|
|
"level": "vhigh",
|
|
"type": "SEHR HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 1.6.3-V1",
|
|
"impl_anchor": "IMPL 1.6.3-elev",
|
|
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
|
"requirement": "Krisenübungen und Simulationen unter Einbindung aller relevanten Personen, einschließlich Entscheidungsträger, werden regelmäßig durchgeführt. (A)",
|
|
"link": "{{LINK:R04#1.6.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "2.1.1-M1",
|
|
"policy": "R05",
|
|
"control": "2.1.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 2.1.1-M1",
|
|
"impl_anchor": "IMPL 2.1.1",
|
|
"condition": null,
|
|
"requirement": "Sensible Arbeitsbereiche und Tätigkeiten sind bestimmt.",
|
|
"link": "{{LINK:R05#2.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "2.1.1-M2",
|
|
"policy": "R05",
|
|
"control": "2.1.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 2.1.1-M2",
|
|
"impl_anchor": "IMPL 2.1.1",
|
|
"condition": null,
|
|
"requirement": "Die Anforderungen an Beschäftigte hinsichtlich ihrer Stellenprofile sind bestimmt und erfüllt.",
|
|
"link": "{{LINK:R05#2.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "2.1.1-M3",
|
|
"policy": "R05",
|
|
"control": "2.1.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 2.1.1-M3",
|
|
"impl_anchor": "IMPL 2.1.1",
|
|
"condition": null,
|
|
"requirement": "Die Identität potenzieller Beschäftigter wird verifiziert (z. B. Prüfung von Ausweisdokumenten).",
|
|
"link": "{{LINK:R05#2.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "2.1.1-S1",
|
|
"policy": "R05",
|
|
"control": "2.1.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 2.1.1-S1",
|
|
"impl_anchor": "IMPL 2.1.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Die persönliche Eignung potenzieller Beschäftigter wird mit einfachen Methoden überprüft (z. B. Vorstellungsgespräch).",
|
|
"link": "{{LINK:R05#2.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "2.1.1-S2",
|
|
"policy": "R05",
|
|
"control": "2.1.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 2.1.1-S2",
|
|
"impl_anchor": "IMPL 2.1.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Eine erweiterte Eignungsprüfung abhängig vom Arbeitsbereich und der Tätigkeit wird durchgeführt (z. B. Assessment-Center, Prüfung von Referenzen, Zeugnissen und Führungszeugnissen).",
|
|
"link": "{{LINK:R05#2.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "2.1.2-M1",
|
|
"policy": "R05",
|
|
"control": "2.1.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 2.1.2-M1",
|
|
"impl_anchor": "IMPL 2.1.2",
|
|
"condition": null,
|
|
"requirement": "Eine Vertraulichkeitsverpflichtung ist in Kraft.",
|
|
"link": "{{LINK:R05#2.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "2.1.2-M2",
|
|
"policy": "R05",
|
|
"control": "2.1.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 2.1.2-M2",
|
|
"impl_anchor": "IMPL 2.1.2",
|
|
"condition": null,
|
|
"requirement": "Eine Verpflichtung zur Einhaltung der Informationssicherheitsrichtlinien ist in Kraft.",
|
|
"link": "{{LINK:R05#2.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "2.1.2-S1",
|
|
"policy": "R05",
|
|
"control": "2.1.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 2.1.2-S1",
|
|
"impl_anchor": "IMPL 2.1.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Eine über den Arbeitsvertrag hinausgehende Vertraulichkeitsverpflichtung ist in Kraft.",
|
|
"link": "{{LINK:R05#2.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "2.1.2-S2",
|
|
"policy": "R05",
|
|
"control": "2.1.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 2.1.2-S2",
|
|
"impl_anchor": "IMPL 2.1.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Informationssicherheitsaspekte werden in den Arbeitsverträgen der Beschäftigten berücksichtigt.",
|
|
"link": "{{LINK:R05#2.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "2.1.2-S3",
|
|
"policy": "R05",
|
|
"control": "2.1.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 2.1.2-S3",
|
|
"impl_anchor": "IMPL 2.1.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Ein Verfahren zum Umgang mit Verstößen gegen diese Verpflichtungen ist beschrieben.",
|
|
"link": "{{LINK:R05#2.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "2.1.3-M1",
|
|
"policy": "R05",
|
|
"control": "2.1.3",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 2.1.3-M1",
|
|
"impl_anchor": "IMPL 2.1.3",
|
|
"condition": null,
|
|
"requirement": "Beschäftigte werden geschult und sensibilisiert.",
|
|
"link": "{{LINK:R05#2.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-12"
|
|
]
|
|
},
|
|
{
|
|
"id": "2.1.3-S1",
|
|
"policy": "R05",
|
|
"control": "2.1.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 2.1.3-S1",
|
|
"impl_anchor": "IMPL 2.1.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Ein Konzept für Sensibilisierung und Schulung der Beschäftigten ist erstellt.",
|
|
"link": "{{LINK:R05#2.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-12"
|
|
]
|
|
},
|
|
{
|
|
"id": "2.1.3-S2",
|
|
"policy": "R05",
|
|
"control": "2.1.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 2.1.3-S2",
|
|
"impl_anchor": "IMPL 2.1.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Zielgruppen für Schulungs- und Sensibilisierungsmaßnahmen (z. B. Führungskräfte, Administratoren, Beschäftigte mit Zugang zu Kundennetzen, Fertigungspersonal) sind identifiziert und im Konzept berücksichtigt.",
|
|
"link": "{{LINK:R05#2.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "2.1.3-S3",
|
|
"policy": "R05",
|
|
"control": "2.1.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 2.1.3-S3",
|
|
"impl_anchor": "IMPL 2.1.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Das Konzept ist durch die verantwortliche Leitung genehmigt.",
|
|
"link": "{{LINK:R05#2.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "2.1.3-S4",
|
|
"policy": "R05",
|
|
"control": "2.1.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 2.1.3-S4",
|
|
"impl_anchor": "IMPL 2.1.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Schulungs- und Sensibilisierungsmaßnahmen werden regelmäßig und anlassbezogen durchgeführt.",
|
|
"link": "{{LINK:R05#2.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "2.1.3-S5",
|
|
"policy": "R05",
|
|
"control": "2.1.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 2.1.3-S5",
|
|
"impl_anchor": "IMPL 2.1.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Die Teilnahme an Schulungs- und Sensibilisierungsmaßnahmen wird dokumentiert.",
|
|
"link": "{{LINK:R05#2.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "2.1.3-S6",
|
|
"policy": "R05",
|
|
"control": "2.1.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 2.1.3-S6",
|
|
"impl_anchor": "IMPL 2.1.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Ansprechpartner für Informationssicherheit sind den Beschäftigten bekannt.",
|
|
"link": "{{LINK:R05#2.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "2.1.4-M1",
|
|
"policy": "R06",
|
|
"control": "2.1.4",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 2.1.4-M1",
|
|
"impl_anchor": "IMPL 2.1.4",
|
|
"condition": null,
|
|
"requirement": "Die Anforderungen an mobiles Arbeiten sind bestimmt und erfüllt; dabei werden die einschlägigen Aspekte berücksichtigt.",
|
|
"link": "{{LINK:R06#2.1.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "2.1.4-S1",
|
|
"policy": "R06",
|
|
"control": "2.1.4",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 2.1.4-S1",
|
|
"impl_anchor": "IMPL 2.1.4",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Die einschlägigen Aspekte des mobilen Arbeitens werden berücksichtigt.",
|
|
"link": "{{LINK:R06#2.1.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "2.1.4-S2",
|
|
"policy": "R06",
|
|
"control": "2.1.4",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 2.1.4-S2",
|
|
"impl_anchor": "IMPL 2.1.4",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Sensibilisierung der Beschäftigten.",
|
|
"link": "{{LINK:R06#2.1.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "2.1.4-H1",
|
|
"policy": "R06",
|
|
"control": "2.1.4",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 2.1.4-H1",
|
|
"impl_anchor": "IMPL 2.1.4-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Schutzmaßnahmen gegen Abhören und Einsehen sind umgesetzt. (C)",
|
|
"link": "{{LINK:R06#2.1.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "3.1.1-M1",
|
|
"policy": "R07",
|
|
"control": "3.1.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 3.1.1-M1",
|
|
"impl_anchor": "IMPL 3.1.1",
|
|
"condition": null,
|
|
"requirement": "Ein Sicherheitszonenkonzept einschließlich zugehöriger Schutzmaßnahmen auf Basis der Anforderungen an die Handhabung von Informationswerten ist vorhanden.",
|
|
"link": "{{LINK:R07#3.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "3.1.1-M2",
|
|
"policy": "R07",
|
|
"control": "3.1.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 3.1.1-M2",
|
|
"impl_anchor": "IMPL 3.1.1",
|
|
"condition": null,
|
|
"requirement": "Die definierten Schutzmaßnahmen sind umgesetzt.",
|
|
"link": "{{LINK:R07#3.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "3.1.1-M3",
|
|
"policy": "R07",
|
|
"control": "3.1.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 3.1.1-M3",
|
|
"impl_anchor": "IMPL 3.1.1",
|
|
"condition": null,
|
|
"requirement": "Der Verhaltenskodex für Sicherheitszonen ist allen beteiligten Personen bekannt.",
|
|
"link": "{{LINK:R07#3.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "3.1.1-S1",
|
|
"policy": "R07",
|
|
"control": "3.1.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 3.1.1-S1",
|
|
"impl_anchor": "IMPL 3.1.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Verfahren für die Vergabe und den Entzug von Zutrittsrechten sind etabliert.",
|
|
"link": "{{LINK:R07#3.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "3.1.1-S2",
|
|
"policy": "R07",
|
|
"control": "3.1.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 3.1.1-S2",
|
|
"impl_anchor": "IMPL 3.1.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Richtlinien für das Besuchermanagement (einschließlich Registrierung und Begleitung von Besuchern) sind definiert.",
|
|
"link": "{{LINK:R07#3.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "3.1.1-S3",
|
|
"policy": "R07",
|
|
"control": "3.1.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 3.1.1-S3",
|
|
"impl_anchor": "IMPL 3.1.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Richtlinien für das Mitführen und Nutzen mobiler IT-Geräte und Datenträger (z. B. Registrierung, Kennzeichnungspflichten) sind definiert und umgesetzt.",
|
|
"link": "{{LINK:R07#3.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "3.1.1-S4",
|
|
"policy": "R07",
|
|
"control": "3.1.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 3.1.1-S4",
|
|
"impl_anchor": "IMPL 3.1.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Netzwerk-/Infrastrukturkomponenten (eigene oder Kundennetze) sind gegen unbefugten Zugriff geschützt.",
|
|
"link": "{{LINK:R07#3.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "3.1.1-S5",
|
|
"policy": "R07",
|
|
"control": "3.1.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 3.1.1-S5",
|
|
"impl_anchor": "IMPL 3.1.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Externe Liegenschaften zur Speicherung/Verarbeitung von Informationswerten sind im Zonenkonzept berücksichtigt (z. B. Lagerräume, Werkstätten, Teststrecken, Rechenzentren).",
|
|
"link": "{{LINK:R07#3.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "3.1.1-H1",
|
|
"policy": "R07",
|
|
"control": "3.1.1",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 3.1.1-H1",
|
|
"impl_anchor": "IMPL 3.1.1-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Schutzmaßnahmen gegen einfaches Abhören und Einsehen sind umgesetzt. (C)",
|
|
"link": "{{LINK:R07#3.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "3.1.4-M1",
|
|
"policy": "R06",
|
|
"control": "3.1.4",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 3.1.4-M1",
|
|
"impl_anchor": "IMPL 3.1.4",
|
|
"condition": null,
|
|
"requirement": "Die Anforderungen an mobile IT-Geräte und mobile Datenträger sind bestimmt und erfüllt; dabei werden die einschlägigen Aspekte berücksichtigt.",
|
|
"link": "{{LINK:R06#3.1.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "3.1.4-S1",
|
|
"policy": "R06",
|
|
"control": "3.1.4",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 3.1.4-S1",
|
|
"impl_anchor": "IMPL 3.1.4",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Registrierung der IT-Geräte.",
|
|
"link": "{{LINK:R06#3.1.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "3.1.4-H1",
|
|
"policy": "R06",
|
|
"control": "3.1.4",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 3.1.4-H1",
|
|
"impl_anchor": "IMPL 3.1.4-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Generelle Verschlüsselung mobiler Datenträger bzw. der darauf gespeicherten Informationswerte. Wo technisch nicht machbar, werden Informationen durch gleichwertige Maßnahmen geschützt. (C, I)",
|
|
"link": "{{LINK:R06#3.1.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.1-M1",
|
|
"policy": "R08",
|
|
"control": "4.1.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.1-M1",
|
|
"impl_anchor": "IMPL 4.1.1",
|
|
"condition": null,
|
|
"requirement": "Die Anforderungen an den Umgang mit Identifikationsmitteln über den gesamten Lebenszyklus sind bestimmt und erfüllt; dabei werden die einschlägigen Aspekte berücksichtigt.",
|
|
"link": "{{LINK:R08#4.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.1-S1",
|
|
"policy": "R08",
|
|
"control": "4.1.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.1-S1",
|
|
"impl_anchor": "IMPL 4.1.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Identifikationsmittel können nur unter kontrollierten Bedingungen erstellt werden.",
|
|
"link": "{{LINK:R08#4.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-03"
|
|
]
|
|
},
|
|
{
|
|
"id": "4.1.1-H1",
|
|
"policy": "R08",
|
|
"control": "4.1.1",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.1-H1",
|
|
"impl_anchor": "IMPL 4.1.1-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Eine Strategie zur Sperrung oder Ungültigmachung von Identifikationsmitteln im Verlustfall ist vorbereitet und soweit möglich umgesetzt. (C, I, A)",
|
|
"link": "{{LINK:R08#4.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.2-M1",
|
|
"policy": "R08",
|
|
"control": "4.1.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.2-M1",
|
|
"impl_anchor": "IMPL 4.1.2",
|
|
"condition": null,
|
|
"requirement": "Die Verfahren zur Benutzerauthentifizierung sind auf Basis einer Risikobewertung ausgewählt; mögliche Angriffsszenarien (z. B. direkte Erreichbarkeit über das Internet) wurden berücksichtigt.",
|
|
"link": "{{LINK:R08#4.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.2-M2",
|
|
"policy": "R08",
|
|
"control": "4.1.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.2-M2",
|
|
"impl_anchor": "IMPL 4.1.2",
|
|
"condition": null,
|
|
"requirement": "Verfahren zur Benutzerauthentifizierung nach dem Stand der Technik werden angewandt.",
|
|
"link": "{{LINK:R08#4.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.2-S1",
|
|
"policy": "R08",
|
|
"control": "4.1.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.2-S1",
|
|
"impl_anchor": "IMPL 4.1.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Die Authentifizierungsverfahren sind auf Basis der geschäftlichen und sicherheitsrelevanten Anforderungen definiert und umgesetzt.",
|
|
"link": "{{LINK:R08#4.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.2-S2",
|
|
"policy": "R08",
|
|
"control": "4.1.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.2-S2",
|
|
"impl_anchor": "IMPL 4.1.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Benutzer werden mindestens durch starke Passwörter nach bewährten und anerkannten Praktiken authentifiziert.",
|
|
"link": "{{LINK:R08#4.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.2-S3",
|
|
"policy": "R08",
|
|
"control": "4.1.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.2-S3",
|
|
"impl_anchor": "IMPL 4.1.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Für privilegierte Benutzerkonten werden höherwertige Verfahren genutzt (z. B. Privileged Access Management, Zwei-Faktor-Authentifizierung).",
|
|
"link": "{{LINK:R08#4.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.2-H1",
|
|
"policy": "R08",
|
|
"control": "4.1.2",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.2-H1",
|
|
"impl_anchor": "IMPL 4.1.2-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Abhängig von der Risikobewertung sind Authentifizierung und Zugangskontrolle durch ergänzende Maßnahmen verstärkt (z. B. kontinuierliche Zugriffsüberwachung, starke Authentifizierung, automatische Abmeldung, Sperre bei Inaktivität, Brute-Force-Prävention). (C, I, A)",
|
|
"link": "{{LINK:R08#4.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.2-V1",
|
|
"policy": "R08",
|
|
"control": "4.1.2",
|
|
"level": "vhigh",
|
|
"type": "SEHR HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.2-V1",
|
|
"impl_anchor": "IMPL 4.1.2-elev",
|
|
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
|
"requirement": "Vor dem Zugriff auf Daten mit sehr hohem Schutzbedarf werden Benutzer mittels starker Authentifizierung (z. B. Zwei-Faktor) nach dem Stand der Technik authentifiziert. (C, I)",
|
|
"link": "{{LINK:R08#4.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.3-M1",
|
|
"policy": "R08",
|
|
"control": "4.1.3",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.3-M1",
|
|
"impl_anchor": "IMPL 4.1.3",
|
|
"condition": null,
|
|
"requirement": "Das Erstellen, Ändern und Löschen von Benutzerkonten wird durchgeführt.",
|
|
"link": "{{LINK:R08#4.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-03"
|
|
]
|
|
},
|
|
{
|
|
"id": "4.1.3-M2",
|
|
"policy": "R08",
|
|
"control": "4.1.3",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.3-M2",
|
|
"impl_anchor": "IMPL 4.1.3",
|
|
"condition": null,
|
|
"requirement": "Eindeutige und personalisierte Benutzerkonten werden verwendet.",
|
|
"link": "{{LINK:R08#4.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.3-M3",
|
|
"policy": "R08",
|
|
"control": "4.1.3",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.3-M3",
|
|
"impl_anchor": "IMPL 4.1.3",
|
|
"condition": null,
|
|
"requirement": "Die Nutzung von Sammelkonten ist geregelt (z. B. beschränkt auf Fälle, in denen Nachvollziehbarkeit verzichtbar ist).",
|
|
"link": "{{LINK:R08#4.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.3-M4",
|
|
"policy": "R08",
|
|
"control": "4.1.3",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.3-M4",
|
|
"impl_anchor": "IMPL 4.1.3",
|
|
"condition": null,
|
|
"requirement": "Benutzerkonten werden unmittelbar nach dem Ausscheiden des Nutzers deaktiviert (z. B. bei Vertragsende).",
|
|
"link": "{{LINK:R08#4.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.3-M5",
|
|
"policy": "R08",
|
|
"control": "4.1.3",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.3-M5",
|
|
"impl_anchor": "IMPL 4.1.3",
|
|
"condition": null,
|
|
"requirement": "Benutzerkonten werden regelmäßig überprüft.",
|
|
"link": "{{LINK:R08#4.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.3-M6",
|
|
"policy": "R08",
|
|
"control": "4.1.3",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.3-M6",
|
|
"impl_anchor": "IMPL 4.1.3",
|
|
"condition": null,
|
|
"requirement": "Die Anmeldeinformationen werden dem Nutzer auf sichere Weise bereitgestellt.",
|
|
"link": "{{LINK:R08#4.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.3-M7",
|
|
"policy": "R08",
|
|
"control": "4.1.3",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.3-M7",
|
|
"impl_anchor": "IMPL 4.1.3",
|
|
"condition": null,
|
|
"requirement": "Eine Richtlinie zum Umgang mit Anmeldeinformationen ist definiert und umgesetzt; dabei werden die einschlägigen Aspekte berücksichtigt.",
|
|
"link": "{{LINK:R08#4.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.3-S1",
|
|
"policy": "R08",
|
|
"control": "4.1.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.3-S1",
|
|
"impl_anchor": "IMPL 4.1.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Ein Basiskonto mit minimalen Zugriffsrechten und Funktionalitäten existiert und wird genutzt.",
|
|
"link": "{{LINK:R08#4.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.3-S10",
|
|
"policy": "R08",
|
|
"control": "4.1.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.3-S10",
|
|
"impl_anchor": "IMPL 4.1.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Interaktive Anmeldung für Dienstkonten (technische Konten) wird technisch verhindert.",
|
|
"link": "{{LINK:R08#4.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.3-S2",
|
|
"policy": "R08",
|
|
"control": "4.1.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.3-S2",
|
|
"impl_anchor": "IMPL 4.1.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Vom Hersteller vorkonfigurierte Standardkonten und -passwörter sind deaktiviert (z. B. Sperren oder Passwortänderung).",
|
|
"link": "{{LINK:R08#4.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.3-S3",
|
|
"policy": "R08",
|
|
"control": "4.1.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.3-S3",
|
|
"impl_anchor": "IMPL 4.1.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Benutzerkonten werden durch die verantwortliche Stelle erstellt oder autorisiert.",
|
|
"link": "{{LINK:R08#4.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.3-S4",
|
|
"policy": "R08",
|
|
"control": "4.1.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.3-S4",
|
|
"impl_anchor": "IMPL 4.1.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Das Erstellen von Benutzerkonten unterliegt einem Genehmigungsprozess (Vier-Augen-Prinzip).",
|
|
"link": "{{LINK:R08#4.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.3-S5",
|
|
"policy": "R08",
|
|
"control": "4.1.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.3-S5",
|
|
"impl_anchor": "IMPL 4.1.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Benutzerkonten von Dienstleistern werden nach Abschluss ihrer Aufgabe deaktiviert.",
|
|
"link": "{{LINK:R08#4.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.3-S6",
|
|
"policy": "R08",
|
|
"control": "4.1.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.3-S6",
|
|
"impl_anchor": "IMPL 4.1.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Fristen für das Deaktivieren und Löschen von Benutzerkonten sind definiert.",
|
|
"link": "{{LINK:R08#4.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.3-S7",
|
|
"policy": "R08",
|
|
"control": "4.1.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.3-S7",
|
|
"impl_anchor": "IMPL 4.1.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Die Verwendung von Standardpasswörtern wird technisch verhindert.",
|
|
"link": "{{LINK:R08#4.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.3-S8",
|
|
"policy": "R08",
|
|
"control": "4.1.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.3-S8",
|
|
"impl_anchor": "IMPL 4.1.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Bei starker Authentifizierung ist die Nutzung des Mediums (z. B. Besitzfaktor) sicher.",
|
|
"link": "{{LINK:R08#4.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.1.3-S9",
|
|
"policy": "R08",
|
|
"control": "4.1.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.1.3-S9",
|
|
"impl_anchor": "IMPL 4.1.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Benutzerkonten werden regelmäßig überprüft; dies umfasst auch Konten in IT-Systemen von Kunden.",
|
|
"link": "{{LINK:R08#4.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.2.1-M1",
|
|
"policy": "R08",
|
|
"control": "4.2.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.2.1-M1",
|
|
"impl_anchor": "IMPL 4.2.1",
|
|
"condition": null,
|
|
"requirement": "Die Anforderungen an die Verwaltung von Zugriffsrechten (Autorisierung) sind bestimmt und erfüllt; dabei werden die einschlägigen Aspekte berücksichtigt.",
|
|
"link": "{{LINK:R08#4.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-03"
|
|
]
|
|
},
|
|
{
|
|
"id": "4.2.1-M2",
|
|
"policy": "R08",
|
|
"control": "4.2.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.2.1-M2",
|
|
"impl_anchor": "IMPL 4.2.1",
|
|
"condition": null,
|
|
"requirement": "Die für normale und privilegierte Benutzerkonten sowie technische Konten vergebenen Zugriffsrechte werden regelmäßig überprüft, auch in IT-Systemen von Kunden.",
|
|
"link": "{{LINK:R08#4.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-03"
|
|
]
|
|
},
|
|
{
|
|
"id": "4.2.1-S1",
|
|
"policy": "R08",
|
|
"control": "4.2.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.2.1-S1",
|
|
"impl_anchor": "IMPL 4.2.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Strategien zur Autorisierung von Zugriffen auf Informationen sind vorbereitet.",
|
|
"link": "{{LINK:R08#4.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-03"
|
|
]
|
|
},
|
|
{
|
|
"id": "4.2.1-S2",
|
|
"policy": "R08",
|
|
"control": "4.2.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.2.1-S2",
|
|
"impl_anchor": "IMPL 4.2.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Autorisierungsrollen werden verwendet.",
|
|
"link": "{{LINK:R08#4.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.2.1-S3",
|
|
"policy": "R08",
|
|
"control": "4.2.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.2.1-S3",
|
|
"impl_anchor": "IMPL 4.2.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Rechte werden nach dem Need-to-use-Prinzip und gemäß Rolle und/oder Verantwortungsbereich vergeben.",
|
|
"link": "{{LINK:R08#4.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.2.1-S4",
|
|
"policy": "R08",
|
|
"control": "4.2.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.2.1-S4",
|
|
"impl_anchor": "IMPL 4.2.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Normale Benutzerkonten erhalten keine privilegierten Zugriffsrechte.",
|
|
"link": "{{LINK:R08#4.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.2.1-S5",
|
|
"policy": "R08",
|
|
"control": "4.2.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.2.1-S5",
|
|
"impl_anchor": "IMPL 4.2.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Die Zugriffsrechte des Nutzers werden nach Änderung seiner Verantwortlichkeiten aktualisiert.",
|
|
"link": "{{LINK:R08#4.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.2.1-H1",
|
|
"policy": "R08",
|
|
"control": "4.2.1",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.2.1-H1",
|
|
"impl_anchor": "IMPL 4.2.1-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Die Zugriffsrechte werden durch den verantwortlichen internen Information Officer genehmigt. (C, I, A)",
|
|
"link": "{{LINK:R08#4.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.2.1-V1",
|
|
"policy": "R08",
|
|
"control": "4.2.1",
|
|
"level": "vhigh",
|
|
"type": "SEHR HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.2.1-V1",
|
|
"impl_anchor": "IMPL 4.2.1-elev",
|
|
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
|
"requirement": "Informationen werden auf Inhaltsebene (z. B. Dateiebene) verschlüsselt gespeichert, um unbefugten Zugriff (auch privilegierter Nutzer) zu verhindern. Wo Verschlüsselung nicht machbar ist, greifen gleichwertige Maßnahmen. (C)",
|
|
"link": "{{LINK:R08#4.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.2.1-V2",
|
|
"policy": "R08",
|
|
"control": "4.2.1",
|
|
"level": "vhigh",
|
|
"type": "SEHR HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 4.2.1-V2",
|
|
"impl_anchor": "IMPL 4.2.1-elev",
|
|
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
|
"requirement": "Bestehende Zugriffsrechte werden in kürzeren Abständen (z. B. quartalsweise) überprüft. (C)",
|
|
"link": "{{LINK:R08#4.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.1.1-M1",
|
|
"policy": "R09",
|
|
"control": "5.1.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.1.1-M1",
|
|
"impl_anchor": "IMPL 5.1.1",
|
|
"condition": null,
|
|
"requirement": "Alle eingesetzten kryptografischen Verfahren (z. B. Verschlüsselung, Signatur, Hash-Algorithmen, Protokolle) bieten die im jeweiligen Anwendungsfeld erforderliche Sicherheit nach anerkanntem Industriestandard, soweit rechtlich möglich.",
|
|
"link": "{{LINK:R09#5.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-07"
|
|
]
|
|
},
|
|
{
|
|
"id": "5.1.1-S1",
|
|
"policy": "R09",
|
|
"control": "5.1.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.1.1-S1",
|
|
"impl_anchor": "IMPL 5.1.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Ein Konzept für den Einsatz von Kryptografie ist definiert und umgesetzt; dabei werden die einschlägigen Aspekte berücksichtigt.",
|
|
"link": "{{LINK:R09#5.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-07"
|
|
]
|
|
},
|
|
{
|
|
"id": "5.1.1-H1",
|
|
"policy": "R09",
|
|
"control": "5.1.1",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.1.1-H1",
|
|
"impl_anchor": "IMPL 5.1.1-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Anforderungen an die Schlüsselhoheit (insbesondere bei externer Verarbeitung) sind bestimmt und erfüllt. (C, I)",
|
|
"link": "{{LINK:R09#5.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.1.2-M1",
|
|
"policy": "R09",
|
|
"control": "5.1.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.1.2-M1",
|
|
"impl_anchor": "IMPL 5.1.2",
|
|
"condition": null,
|
|
"requirement": "Die zur Informationsübertragung genutzten Netzdienste sind identifiziert und dokumentiert.",
|
|
"link": "{{LINK:R09#5.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-07"
|
|
]
|
|
},
|
|
{
|
|
"id": "5.1.2-M2",
|
|
"policy": "R09",
|
|
"control": "5.1.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.1.2-M2",
|
|
"impl_anchor": "IMPL 5.1.2",
|
|
"condition": null,
|
|
"requirement": "Richtlinien und Verfahren entsprechend den Klassifizierungsanforderungen für die Nutzung von Netzdiensten sind definiert und umgesetzt.",
|
|
"link": "{{LINK:R09#5.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.1.2-M3",
|
|
"policy": "R09",
|
|
"control": "5.1.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.1.2-M3",
|
|
"impl_anchor": "IMPL 5.1.2",
|
|
"condition": null,
|
|
"requirement": "Maßnahmen zum Schutz übertragener Inhalte gegen unbefugten Zugriff sind umgesetzt.",
|
|
"link": "{{LINK:R09#5.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.1.2-S1",
|
|
"policy": "R09",
|
|
"control": "5.1.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.1.2-S1",
|
|
"impl_anchor": "IMPL 5.1.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Maßnahmen zur Sicherstellung korrekter Adressierung und korrekter Informationsübertragung sind umgesetzt.",
|
|
"link": "{{LINK:R09#5.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-07"
|
|
]
|
|
},
|
|
{
|
|
"id": "5.1.2-S2",
|
|
"policy": "R09",
|
|
"control": "5.1.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.1.2-S2",
|
|
"impl_anchor": "IMPL 5.1.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Elektronischer Datenaustausch erfolgt mittels Inhalts- oder Transportverschlüsselung entsprechend der jeweiligen Klassifizierung.",
|
|
"link": "{{LINK:R09#5.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.1.2-S3",
|
|
"policy": "R09",
|
|
"control": "5.1.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.1.2-S3",
|
|
"impl_anchor": "IMPL 5.1.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Fernzugriffsverbindungen zum Netzwerk der Organisation verfügen über angemessene Sicherheitsmerkmale; dabei werden die einschlägigen Aspekte berücksichtigt.",
|
|
"link": "{{LINK:R09#5.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.1.2-H1",
|
|
"policy": "R09",
|
|
"control": "5.1.2",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.1.2-H1",
|
|
"impl_anchor": "IMPL 5.1.2-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Informationen werden verschlüsselt übertragen (mindestens Transportverschlüsselung) oder durch gleichwertig wirksame Maßnahmen geschützt. (C)",
|
|
"link": "{{LINK:R09#5.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.1.2-V1",
|
|
"policy": "R09",
|
|
"control": "5.1.2",
|
|
"level": "vhigh",
|
|
"type": "SEHR HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.1.2-V1",
|
|
"impl_anchor": "IMPL 5.1.2-elev",
|
|
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
|
"requirement": "Informationen werden inhaltsverschlüsselt übertragen. (C)",
|
|
"link": "{{LINK:R09#5.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.1-M1",
|
|
"policy": "R10",
|
|
"control": "5.2.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.1-M1",
|
|
"impl_anchor": "IMPL 5.2.1",
|
|
"condition": null,
|
|
"requirement": "Informationssicherheitsanforderungen für Änderungen an Organisation, Geschäftsprozessen und IT-Systemen sind bestimmt und erfüllt.",
|
|
"link": "{{LINK:R10#5.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-04"
|
|
]
|
|
},
|
|
{
|
|
"id": "5.2.1-S1",
|
|
"policy": "R10",
|
|
"control": "5.2.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.1-S1",
|
|
"impl_anchor": "IMPL 5.2.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Ein formales Genehmigungsverfahren ist etabliert.",
|
|
"link": "{{LINK:R10#5.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.1-S2",
|
|
"policy": "R10",
|
|
"control": "5.2.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.1-S2",
|
|
"impl_anchor": "IMPL 5.2.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Die möglichen Auswirkungen von Änderungen auf die Informationssicherheit werden bewertet.",
|
|
"link": "{{LINK:R10#5.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.1-S3",
|
|
"policy": "R10",
|
|
"control": "5.2.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.1-S3",
|
|
"impl_anchor": "IMPL 5.2.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Änderungen mit Auswirkung auf die Informationssicherheit werden geplant und getestet.",
|
|
"link": "{{LINK:R10#5.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.1-S4",
|
|
"policy": "R10",
|
|
"control": "5.2.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.1-S4",
|
|
"impl_anchor": "IMPL 5.2.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Verfahren zum Rückfall (Fallback) in Fehlerfällen werden berücksichtigt.",
|
|
"link": "{{LINK:R10#5.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.1-H1",
|
|
"policy": "R10",
|
|
"control": "5.2.1",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.1-H1",
|
|
"impl_anchor": "IMPL 5.2.1-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Die Einhaltung der Informationssicherheitsanforderungen wird während und nach den Änderungen überprüft. (C, I, A)",
|
|
"link": "{{LINK:R10#5.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.2-M1",
|
|
"policy": "R10",
|
|
"control": "5.2.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.2-M1",
|
|
"impl_anchor": "IMPL 5.2.2",
|
|
"condition": null,
|
|
"requirement": "Die IT-Systeme wurden einer Risikobewertung unterzogen, um die Notwendigkeit ihrer Trennung in Entwicklungs-, Test- und Produktivsysteme zu bestimmen.",
|
|
"link": "{{LINK:R10#5.2.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.2-M2",
|
|
"policy": "R10",
|
|
"control": "5.2.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.2-M2",
|
|
"impl_anchor": "IMPL 5.2.2",
|
|
"condition": null,
|
|
"requirement": "Eine Segmentierung ist auf Basis der Ergebnisse der Risikoanalyse umgesetzt.",
|
|
"link": "{{LINK:R10#5.2.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.2-S1",
|
|
"policy": "R10",
|
|
"control": "5.2.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.2-S1",
|
|
"impl_anchor": "IMPL 5.2.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Die Anforderungen an Entwicklungs- und Testumgebungen sind bestimmt und erfüllt; dabei werden die einschlägigen Aspekte berücksichtigt.",
|
|
"link": "{{LINK:R10#5.2.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.3-M1",
|
|
"policy": "R10",
|
|
"control": "5.2.3",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.3-M1",
|
|
"impl_anchor": "IMPL 5.2.3",
|
|
"condition": null,
|
|
"requirement": "Anforderungen zum Schutz vor Schadsoftware sind bestimmt.",
|
|
"link": "{{LINK:R10#5.2.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.3-M2",
|
|
"policy": "R10",
|
|
"control": "5.2.3",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.3-M2",
|
|
"impl_anchor": "IMPL 5.2.3",
|
|
"condition": null,
|
|
"requirement": "Technische und organisatorische Maßnahmen zum Schutz vor Schadsoftware sind definiert und umgesetzt.",
|
|
"link": "{{LINK:R10#5.2.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.3-S1",
|
|
"policy": "R10",
|
|
"control": "5.2.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.3-S1",
|
|
"impl_anchor": "IMPL 5.2.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Unnötige Netzwerkdienste sind deaktiviert.",
|
|
"link": "{{LINK:R10#5.2.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.3-S2",
|
|
"policy": "R10",
|
|
"control": "5.2.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.3-S2",
|
|
"impl_anchor": "IMPL 5.2.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Der Zugriff auf Netzwerkdienste ist durch geeignete Schutzmaßnahmen auf das Notwendige beschränkt.",
|
|
"link": "{{LINK:R10#5.2.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.3-S3",
|
|
"policy": "R10",
|
|
"control": "5.2.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.3-S3",
|
|
"impl_anchor": "IMPL 5.2.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Schutzsoftware gegen Schadsoftware ist installiert und wird regelmäßig automatisch aktualisiert (z. B. Virenscanner).",
|
|
"link": "{{LINK:R10#5.2.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.3-S4",
|
|
"policy": "R10",
|
|
"control": "5.2.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.3-S4",
|
|
"impl_anchor": "IMPL 5.2.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Empfangene Dateien und Software werden vor der Ausführung automatisch auf Schadsoftware geprüft (On-Access-Scan).",
|
|
"link": "{{LINK:R10#5.2.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.3-S5",
|
|
"policy": "R10",
|
|
"control": "5.2.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.3-S5",
|
|
"impl_anchor": "IMPL 5.2.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Der gesamte Datenbestand aller Systeme wird regelmäßig auf Schadsoftware geprüft.",
|
|
"link": "{{LINK:R10#5.2.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.3-S6",
|
|
"policy": "R10",
|
|
"control": "5.2.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.3-S6",
|
|
"impl_anchor": "IMPL 5.2.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Über zentrale Gateways übertragene Daten (z. B. E-Mail, Internet, Fremdnetze) werden automatisch durch Schutzsoftware geprüft.",
|
|
"link": "{{LINK:R10#5.2.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.3-S7",
|
|
"policy": "R10",
|
|
"control": "5.2.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.3-S7",
|
|
"impl_anchor": "IMPL 5.2.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Maßnahmen, die verhindern, dass Schutzsoftware durch Nutzer deaktiviert oder verändert wird, sind definiert und umgesetzt.",
|
|
"link": "{{LINK:R10#5.2.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.3-S8",
|
|
"policy": "R10",
|
|
"control": "5.2.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.3-S8",
|
|
"impl_anchor": "IMPL 5.2.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Für IT-Systeme ohne Schutzsoftware sind alternative Maßnahmen umgesetzt (z. B. besondere Resilienz, wenige Dienste, keine aktiven Nutzer, Netzisolation).",
|
|
"link": "{{LINK:R10#5.2.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.4-M1",
|
|
"policy": "R10",
|
|
"control": "5.2.4",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.4-M1",
|
|
"impl_anchor": "IMPL 5.2.4",
|
|
"condition": null,
|
|
"requirement": "Informationssicherheitsanforderungen an den Umgang mit Ereignisprotokollen sind bestimmt und erfüllt.",
|
|
"link": "{{LINK:R10#5.2.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-13"
|
|
]
|
|
},
|
|
{
|
|
"id": "5.2.4-M2",
|
|
"policy": "R10",
|
|
"control": "5.2.4",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.4-M2",
|
|
"impl_anchor": "IMPL 5.2.4",
|
|
"condition": null,
|
|
"requirement": "Sicherheitsrelevante Anforderungen an die Protokollierung von Aktivitäten von Administratoren und Nutzern sind bestimmt und erfüllt.",
|
|
"link": "{{LINK:R10#5.2.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.4-M3",
|
|
"policy": "R10",
|
|
"control": "5.2.4",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.4-M3",
|
|
"impl_anchor": "IMPL 5.2.4",
|
|
"condition": null,
|
|
"requirement": "Die eingesetzten IT-Systeme werden hinsichtlich der Notwendigkeit der Protokollierung bewertet.",
|
|
"link": "{{LINK:R10#5.2.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.4-M4",
|
|
"policy": "R10",
|
|
"control": "5.2.4",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.4-M4",
|
|
"impl_anchor": "IMPL 5.2.4",
|
|
"condition": null,
|
|
"requirement": "Bei Nutzung externer IT-Dienste werden Informationen zu den Überwachungsmöglichkeiten eingeholt und in der Bewertung berücksichtigt.",
|
|
"link": "{{LINK:R10#5.2.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.4-M5",
|
|
"policy": "R10",
|
|
"control": "5.2.4",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.4-M5",
|
|
"impl_anchor": "IMPL 5.2.4",
|
|
"condition": null,
|
|
"requirement": "Ereignisprotokolle werden regelmäßig auf Richtlinienverstöße und auffällige Probleme geprüft, unter Einhaltung der zulässigen rechtlichen und organisatorischen Vorgaben.",
|
|
"link": "{{LINK:R10#5.2.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.4-S1",
|
|
"policy": "R10",
|
|
"control": "5.2.4",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.4-S1",
|
|
"impl_anchor": "IMPL 5.2.4",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Ein Verfahren zur Eskalation relevanter Ereignisse an die verantwortliche Stelle ist definiert und etabliert.",
|
|
"link": "{{LINK:R10#5.2.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-13"
|
|
]
|
|
},
|
|
{
|
|
"id": "5.2.4-S2",
|
|
"policy": "R10",
|
|
"control": "5.2.4",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.4-S2",
|
|
"impl_anchor": "IMPL 5.2.4",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Ereignisprotokolle (Inhalt und Metadaten) sind gegen Veränderung geschützt (z. B. durch eine dedizierte Umgebung).",
|
|
"link": "{{LINK:R10#5.2.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.4-S3",
|
|
"policy": "R10",
|
|
"control": "5.2.4",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.4-S3",
|
|
"impl_anchor": "IMPL 5.2.4",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Eine angemessene Überwachung und Aufzeichnung aller informationssicherheitsrelevanten Aktionen im Netzwerk ist etabliert.",
|
|
"link": "{{LINK:R10#5.2.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.4-H1",
|
|
"policy": "R10",
|
|
"control": "5.2.4",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.4-H1",
|
|
"impl_anchor": "IMPL 5.2.4-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Sicherheitsrelevante Anforderungen an den Umgang mit Ereignisprotokollen, z. B. vertragliche Anforderungen, sind bestimmt und umgesetzt. (C, I, A)",
|
|
"link": "{{LINK:R10#5.2.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.4-H2",
|
|
"policy": "R10",
|
|
"control": "5.2.4",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.4-H2",
|
|
"impl_anchor": "IMPL 5.2.4-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Ereignisse zu Auf- und Abbau von Fernzugriffssitzungen (z. B. Fernwartung) werden protokolliert. (C, I, A)",
|
|
"link": "{{LINK:R10#5.2.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.4-V1",
|
|
"policy": "R10",
|
|
"control": "5.2.4",
|
|
"level": "vhigh",
|
|
"type": "SEHR HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.4-V1",
|
|
"impl_anchor": "IMPL 5.2.4-elev",
|
|
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
|
"requirement": "Protokollierung jedes Zugriffs auf Daten mit sehr hohem Schutzbedarf, soweit technisch machbar und rechtlich/organisatorisch zulässig. (C, I)",
|
|
"link": "{{LINK:R10#5.2.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.5-M1",
|
|
"policy": "R10",
|
|
"control": "5.2.5",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.5-M1",
|
|
"impl_anchor": "IMPL 5.2.5",
|
|
"condition": null,
|
|
"requirement": "Informationen über technische Schwachstellen der eingesetzten IT-Systeme werden erhoben (z. B. Herstellerinfos, System-Audits, CVE-Datenbank).",
|
|
"link": "{{LINK:R10#5.2.5}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-04",
|
|
"VA-06"
|
|
]
|
|
},
|
|
{
|
|
"id": "5.2.5-M2",
|
|
"policy": "R10",
|
|
"control": "5.2.5",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.5-M2",
|
|
"impl_anchor": "IMPL 5.2.5",
|
|
"condition": null,
|
|
"requirement": "Potenziell betroffene IT-Systeme und Software werden identifiziert und das durch die Schwachstelle verursachte Risiko wird bewertet.",
|
|
"link": "{{LINK:R10#5.2.5}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.5-M3",
|
|
"policy": "R10",
|
|
"control": "5.2.5",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.5-M3",
|
|
"impl_anchor": "IMPL 5.2.5",
|
|
"condition": null,
|
|
"requirement": "Risiken aus Schwachstellen werden behandelt.",
|
|
"link": "{{LINK:R10#5.2.5}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.5-S1",
|
|
"policy": "R10",
|
|
"control": "5.2.5",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.5-S1",
|
|
"impl_anchor": "IMPL 5.2.5",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Ein angemessenes Patch-Management ist definiert und umgesetzt (z. B. Patch-Test und -Installation).",
|
|
"link": "{{LINK:R10#5.2.5}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-06"
|
|
]
|
|
},
|
|
{
|
|
"id": "5.2.5-S2",
|
|
"policy": "R10",
|
|
"control": "5.2.5",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.5-S2",
|
|
"impl_anchor": "IMPL 5.2.5",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Risikominimierende Maßnahmen werden bei Bedarf umgesetzt.",
|
|
"link": "{{LINK:R10#5.2.5}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.5-S3",
|
|
"policy": "R10",
|
|
"control": "5.2.5",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.5-S3",
|
|
"impl_anchor": "IMPL 5.2.5",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Die erfolgreiche Installation von Patches wird in geeigneter Weise verifiziert.",
|
|
"link": "{{LINK:R10#5.2.5}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.6-M1",
|
|
"policy": "R10",
|
|
"control": "5.2.6",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.6-M1",
|
|
"impl_anchor": "IMPL 5.2.6",
|
|
"condition": null,
|
|
"requirement": "Anforderungen an die Prüfung (Audit) von IT-Systemen oder -Diensten sind bestimmt.",
|
|
"link": "{{LINK:R10#5.2.6}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-06"
|
|
]
|
|
},
|
|
{
|
|
"id": "5.2.6-M2",
|
|
"policy": "R10",
|
|
"control": "5.2.6",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.6-M2",
|
|
"impl_anchor": "IMPL 5.2.6",
|
|
"condition": null,
|
|
"requirement": "Der Umfang der Systemprüfung wird rechtzeitig festgelegt.",
|
|
"link": "{{LINK:R10#5.2.6}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.6-M3",
|
|
"policy": "R10",
|
|
"control": "5.2.6",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.6-M3",
|
|
"impl_anchor": "IMPL 5.2.6",
|
|
"condition": null,
|
|
"requirement": "System- oder Dienstprüfungen werden mit Betreiber und Nutzern der IT-Systeme/-Dienste abgestimmt.",
|
|
"link": "{{LINK:R10#5.2.6}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.6-M4",
|
|
"policy": "R10",
|
|
"control": "5.2.6",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.6-M4",
|
|
"impl_anchor": "IMPL 5.2.6",
|
|
"condition": null,
|
|
"requirement": "Die Ergebnisse von System-/Dienstprüfungen werden nachvollziehbar gespeichert und der zuständigen Leitung berichtet.",
|
|
"link": "{{LINK:R10#5.2.6}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.6-M5",
|
|
"policy": "R10",
|
|
"control": "5.2.6",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.6-M5",
|
|
"impl_anchor": "IMPL 5.2.6",
|
|
"condition": null,
|
|
"requirement": "Aus den Ergebnissen werden Maßnahmen abgeleitet und in angemessener Frist umgesetzt.",
|
|
"link": "{{LINK:R10#5.2.6}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.6-S1",
|
|
"policy": "R10",
|
|
"control": "5.2.6",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.6-S1",
|
|
"impl_anchor": "IMPL 5.2.6",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "System- und Dienstprüfungen werden unter Berücksichtigung möglicher Sicherheitsrisiken (z. B. Störungen) geplant.",
|
|
"link": "{{LINK:R10#5.2.6}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.6-S2",
|
|
"policy": "R10",
|
|
"control": "5.2.6",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.6-S2",
|
|
"impl_anchor": "IMPL 5.2.6",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Regelmäßige System- oder Dienstprüfungen werden durchgeführt; dabei werden die einschlägigen Aspekte berücksichtigt.",
|
|
"link": "{{LINK:R10#5.2.6}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.6-S3",
|
|
"policy": "R10",
|
|
"control": "5.2.6",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.6-S3",
|
|
"impl_anchor": "IMPL 5.2.6",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Innerhalb einer angemessenen Frist nach Abschluss der Prüfung wird ein Bericht erstellt.",
|
|
"link": "{{LINK:R10#5.2.6}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.6-H1",
|
|
"policy": "R10",
|
|
"control": "5.2.6",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.6-H1",
|
|
"impl_anchor": "IMPL 5.2.6-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Für kritische IT-Systeme/-Dienste wurden zusätzliche Prüfanforderungen identifiziert und werden erfüllt (z. B. dienstspezifische Tests/Werkzeuge und/oder manuelle Penetrationstests, risikobasierte Intervalle). (A)",
|
|
"link": "{{LINK:R10#5.2.6}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.6-V1",
|
|
"policy": "R10",
|
|
"control": "5.2.6",
|
|
"level": "vhigh",
|
|
"type": "SEHR HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.6-V1",
|
|
"impl_anchor": "IMPL 5.2.6-elev",
|
|
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
|
"requirement": "IT-Systeme und -Dienste werden regelmäßig auf Schwachstellen gescannt. Für nicht scanbare Systeme/Dienste sind geeignete Schutzmaßnahmen umzusetzen. (C, I, A)",
|
|
"link": "{{LINK:R10#5.2.6}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.7-M1",
|
|
"policy": "R10",
|
|
"control": "5.2.7",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.7-M1",
|
|
"impl_anchor": "IMPL 5.2.7",
|
|
"condition": null,
|
|
"requirement": "Anforderungen an das Management und die Steuerung von Netzwerken sind bestimmt und erfüllt.",
|
|
"link": "{{LINK:R10#5.2.7}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.7-M2",
|
|
"policy": "R10",
|
|
"control": "5.2.7",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.7-M2",
|
|
"impl_anchor": "IMPL 5.2.7",
|
|
"condition": null,
|
|
"requirement": "Anforderungen an die Netzsegmentierung sind bestimmt und erfüllt.",
|
|
"link": "{{LINK:R10#5.2.7}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.7-S1",
|
|
"policy": "R10",
|
|
"control": "5.2.7",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.7-S1",
|
|
"impl_anchor": "IMPL 5.2.7",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Verfahren für das Management und die Steuerung von Netzwerken sind definiert.",
|
|
"link": "{{LINK:R10#5.2.7}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.7-S2",
|
|
"policy": "R10",
|
|
"control": "5.2.7",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.7-S2",
|
|
"impl_anchor": "IMPL 5.2.7",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Für eine risikobasierte Netzsegmentierung werden die einschlägigen Aspekte berücksichtigt.",
|
|
"link": "{{LINK:R10#5.2.7}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.7-H1",
|
|
"policy": "R10",
|
|
"control": "5.2.7",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.7-H1",
|
|
"impl_anchor": "IMPL 5.2.7-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Erweiterte Anforderungen an das Management und die Steuerung von Netzwerken sind bestimmt und umgesetzt. (C, I, A)",
|
|
"link": "{{LINK:R10#5.2.7}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.8-M1",
|
|
"policy": "R04",
|
|
"control": "5.2.8",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.8-M1",
|
|
"impl_anchor": "IMPL 5.2.8",
|
|
"condition": null,
|
|
"requirement": "Kritische IT-Dienste sind identifiziert und die Geschäftsauswirkung wird berücksichtigt.",
|
|
"link": "{{LINK:R04#5.2.8}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-02"
|
|
]
|
|
},
|
|
{
|
|
"id": "5.2.8-M2",
|
|
"policy": "R04",
|
|
"control": "5.2.8",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.8-M2",
|
|
"impl_anchor": "IMPL 5.2.8",
|
|
"condition": null,
|
|
"requirement": "Anforderungen und Verantwortlichkeiten für Kontinuität und Wiederherstellung dieser IT-Dienste sind relevanten Stakeholdern bekannt und erfüllt.",
|
|
"link": "{{LINK:R04#5.2.8}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.8-S1",
|
|
"policy": "R04",
|
|
"control": "5.2.8",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.8-S1",
|
|
"impl_anchor": "IMPL 5.2.8",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Kritische IT-Systeme sind identifiziert; dabei werden die einschlägigen Aspekte berücksichtigt.",
|
|
"link": "{{LINK:R04#5.2.8}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-02"
|
|
]
|
|
},
|
|
{
|
|
"id": "5.2.8-S2",
|
|
"policy": "R04",
|
|
"control": "5.2.8",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.8-S2",
|
|
"impl_anchor": "IMPL 5.2.8",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Eine Kontinuitätsplanung existiert und wird regelmäßig überprüft und aktualisiert.",
|
|
"link": "{{LINK:R04#5.2.8}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.8-S3",
|
|
"policy": "R04",
|
|
"control": "5.2.8",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.8-S3",
|
|
"impl_anchor": "IMPL 5.2.8",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Die Kontinuitätsplanung umfasst mindestens (D)DoS-Angriffe, erfolgreiche Ransomware-Angriffe und andere Sabotage, Systemausfallszenarien sowie Naturkatastrophen, die kritische IT-Systeme betreffen.",
|
|
"link": "{{LINK:R04#5.2.8}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.8-H1",
|
|
"policy": "R04",
|
|
"control": "5.2.8",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.8-H1",
|
|
"impl_anchor": "IMPL 5.2.8-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Die Kontinuitätsplanung enthält vordefinierte Zeitrahmen (Recovery Time Objective) für die Wiederaufnahme des Betriebs. (A)",
|
|
"link": "{{LINK:R04#5.2.8}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.8-H2",
|
|
"policy": "R04",
|
|
"control": "5.2.8",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.8-H2",
|
|
"impl_anchor": "IMPL 5.2.8-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Angemessene SLAs mit externen Dienstleistern entsprechend der Kontinuitätsplanung bestehen. (A)",
|
|
"link": "{{LINK:R04#5.2.8}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.8-H3",
|
|
"policy": "R04",
|
|
"control": "5.2.8",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.8-H3",
|
|
"impl_anchor": "IMPL 5.2.8-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Die Kontinuitätspläne umfassen die Koordination vertraglich vereinbarter Kommunikation mit Geschäftspartnern. (A)",
|
|
"link": "{{LINK:R04#5.2.8}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.8-H4",
|
|
"policy": "R04",
|
|
"control": "5.2.8",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.8-H4",
|
|
"impl_anchor": "IMPL 5.2.8-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Die Kontinuitätsplanung wird regelmäßig getestet, inkl. vollständiger Wiederherstellung in einen bekannten Zustand und Einhaltung definierter Zielzeiten. (A)",
|
|
"link": "{{LINK:R04#5.2.8}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.8-H5",
|
|
"policy": "R04",
|
|
"control": "5.2.8",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.8-H5",
|
|
"impl_anchor": "IMPL 5.2.8-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Eine Backup- und Wiederherstellungsstrategie für kritische IT-Dienste und Informationen ist definiert und umgesetzt. (C, I, A)",
|
|
"link": "{{LINK:R04#5.2.8}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.8-H6",
|
|
"policy": "R04",
|
|
"control": "5.2.8",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.8-H6",
|
|
"impl_anchor": "IMPL 5.2.8-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Backups kritischer IT-Dienste und Informationen sind ausreichend gegen unbefugte Veränderung/Löschung durch Schadsoftware geschützt. (I, A)",
|
|
"link": "{{LINK:R04#5.2.8}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.8-H7",
|
|
"policy": "R04",
|
|
"control": "5.2.8",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.8-H7",
|
|
"impl_anchor": "IMPL 5.2.8-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Backups kritischer IT-Dienste und Informationen sind ausreichend gegen unbefugten Zugriff durch Schadsoftware oder Betreiber geschützt. (C, I)",
|
|
"link": "{{LINK:R04#5.2.8}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.8-V1",
|
|
"policy": "R04",
|
|
"control": "5.2.8",
|
|
"level": "vhigh",
|
|
"type": "SEHR HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.8-V1",
|
|
"impl_anchor": "IMPL 5.2.8-elev",
|
|
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
|
"requirement": "Die Kontinuitätsplanung ist mit den Kontinuitätsplänen relevanter externer Dienstleister abgestimmt. (A)",
|
|
"link": "{{LINK:R04#5.2.8}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.8-V2",
|
|
"policy": "R04",
|
|
"control": "5.2.8",
|
|
"level": "vhigh",
|
|
"type": "SEHR HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.8-V2",
|
|
"impl_anchor": "IMPL 5.2.8-elev",
|
|
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
|
"requirement": "Die Fortführung wesentlicher Kern- und Geschäftsfunktionen mit minimalem oder keinem Verlust an Betriebskontinuität ist möglich; dabei werden die einschlägigen Aspekte berücksichtigt.",
|
|
"link": "{{LINK:R04#5.2.8}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.8-V3",
|
|
"policy": "R04",
|
|
"control": "5.2.8",
|
|
"level": "vhigh",
|
|
"type": "SEHR HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.8-V3",
|
|
"impl_anchor": "IMPL 5.2.8-elev",
|
|
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
|
"requirement": "Die Kontinuitätsplanung wird regelmäßig getestet. Testszenarien, Ergebnisse und Lessons Learned werden aufgezeichnet. (I, A)",
|
|
"link": "{{LINK:R04#5.2.8}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.9-M1",
|
|
"policy": "R10",
|
|
"control": "5.2.9",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.9-M1",
|
|
"impl_anchor": "IMPL 5.2.9",
|
|
"condition": null,
|
|
"requirement": "Backup-Konzepte existieren für relevante IT-Systeme. Angemessene Schutzmaßnahmen für Vertraulichkeit, Integrität und Verfügbarkeit der Datensicherungen werden berücksichtigt.",
|
|
"link": "{{LINK:R10#5.2.9}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-05"
|
|
]
|
|
},
|
|
{
|
|
"id": "5.2.9-M2",
|
|
"policy": "R10",
|
|
"control": "5.2.9",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.9-M2",
|
|
"impl_anchor": "IMPL 5.2.9",
|
|
"condition": null,
|
|
"requirement": "Wiederherstellungskonzepte existieren für relevante IT-Dienste.",
|
|
"link": "{{LINK:R10#5.2.9}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-05"
|
|
]
|
|
},
|
|
{
|
|
"id": "5.2.9-S1",
|
|
"policy": "R10",
|
|
"control": "5.2.9",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.9-S1",
|
|
"impl_anchor": "IMPL 5.2.9",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Für jeden relevanten IT-Dienst existiert ein Backup- und Wiederherstellungskonzept. Abhängigkeiten zwischen IT-Diensten und die Reihenfolge der Wiederherstellung werden berücksichtigt.",
|
|
"link": "{{LINK:R10#5.2.9}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-05"
|
|
]
|
|
},
|
|
{
|
|
"id": "5.2.9-H1",
|
|
"policy": "R10",
|
|
"control": "5.2.9",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.9-H1",
|
|
"impl_anchor": "IMPL 5.2.9-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Backup- und Wiederherstellungskonzepte werden methodisch in regelmäßigen Abständen überprüft. (A)",
|
|
"link": "{{LINK:R10#5.2.9}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.9-H2",
|
|
"policy": "R10",
|
|
"control": "5.2.9",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.9-H2",
|
|
"impl_anchor": "IMPL 5.2.9-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Die grundsätzliche Wiederherstellbarkeit wird berücksichtigt und getestet (z. B. Stichprobentests, Testsysteme). (I, A)",
|
|
"link": "{{LINK:R10#5.2.9}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.9-V1",
|
|
"policy": "R10",
|
|
"control": "5.2.9",
|
|
"level": "vhigh",
|
|
"type": "SEHR HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.9-V1",
|
|
"impl_anchor": "IMPL 5.2.9-elev",
|
|
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
|
"requirement": "(Zusätzliche) Backups werden über Offline-Verfahren, unveränderliche (immutable) Backups oder eine isolierte IAM-Lösung durchgeführt. (I, A)",
|
|
"link": "{{LINK:R10#5.2.9}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.9-V2",
|
|
"policy": "R10",
|
|
"control": "5.2.9",
|
|
"level": "vhigh",
|
|
"type": "SEHR HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.9-V2",
|
|
"impl_anchor": "IMPL 5.2.9-elev",
|
|
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
|
"requirement": "Wiederherstellungsverfahren werden methodisch in regelmäßigen Abständen technisch getestet. (I, A)",
|
|
"link": "{{LINK:R10#5.2.9}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2.9-V3",
|
|
"policy": "R10",
|
|
"control": "5.2.9",
|
|
"level": "vhigh",
|
|
"type": "SEHR HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.2.9-V3",
|
|
"impl_anchor": "IMPL 5.2.9-elev",
|
|
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
|
"requirement": "Geografische Redundanz wird in Backup- und Wiederherstellungskonzepten berücksichtigt. (A)",
|
|
"link": "{{LINK:R10#5.2.9}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.3.1-M1",
|
|
"policy": "R11",
|
|
"control": "5.3.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.3.1-M1",
|
|
"impl_anchor": "IMPL 5.3.1",
|
|
"condition": null,
|
|
"requirement": "Die mit Design und Entwicklung eines IT-Dienstes verbundenen Informationssicherheitsanforderungen sind bestimmt und berücksichtigt.",
|
|
"link": "{{LINK:R11#5.3.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.3.1-M2",
|
|
"policy": "R11",
|
|
"control": "5.3.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.3.1-M2",
|
|
"impl_anchor": "IMPL 5.3.1",
|
|
"condition": null,
|
|
"requirement": "Die mit Beschaffung oder Erweiterung von IT-Diensten und -Komponenten verbundenen Informationssicherheitsanforderungen sind bestimmt und berücksichtigt.",
|
|
"link": "{{LINK:R11#5.3.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.3.1-M3",
|
|
"policy": "R11",
|
|
"control": "5.3.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.3.1-M3",
|
|
"impl_anchor": "IMPL 5.3.1",
|
|
"condition": null,
|
|
"requirement": "Informationssicherheitsanforderungen im Zusammenhang mit Änderungen an entwickelten IT-Diensten werden berücksichtigt.",
|
|
"link": "{{LINK:R11#5.3.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.3.1-M4",
|
|
"policy": "R11",
|
|
"control": "5.3.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.3.1-M4",
|
|
"impl_anchor": "IMPL 5.3.1",
|
|
"condition": null,
|
|
"requirement": "Systemabnahmetests werden unter Berücksichtigung der Informationssicherheitsanforderungen durchgeführt.",
|
|
"link": "{{LINK:R11#5.3.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.3.1-S1",
|
|
"policy": "R11",
|
|
"control": "5.3.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.3.1-S1",
|
|
"impl_anchor": "IMPL 5.3.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Anforderungsspezifikationen werden erstellt; dabei werden die einschlägigen Aspekte berücksichtigt.",
|
|
"link": "{{LINK:R11#5.3.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.3.1-S2",
|
|
"policy": "R11",
|
|
"control": "5.3.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.3.1-S2",
|
|
"impl_anchor": "IMPL 5.3.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Anforderungsspezifikationen werden gegen die Informationssicherheitsanforderungen geprüft.",
|
|
"link": "{{LINK:R11#5.3.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.3.1-S3",
|
|
"policy": "R11",
|
|
"control": "5.3.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.3.1-S3",
|
|
"impl_anchor": "IMPL 5.3.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Der IT-Dienst wird vor Produktivnutzung auf Einhaltung der Spezifikationen geprüft.",
|
|
"link": "{{LINK:R11#5.3.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.3.1-S4",
|
|
"policy": "R11",
|
|
"control": "5.3.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.3.1-S4",
|
|
"impl_anchor": "IMPL 5.3.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Die Nutzung von Produktivdaten zu Testzwecken wird soweit möglich vermieden (ggf. Anonymisierung/Pseudonymisierung); dabei werden die einschlägigen Aspekte berücksichtigt.",
|
|
"link": "{{LINK:R11#5.3.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.3.1-S5",
|
|
"policy": "R11",
|
|
"control": "5.3.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.3.1-S5",
|
|
"impl_anchor": "IMPL 5.3.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Testsysteme erhalten Schutzmaßnahmen vergleichbar zur Produktivumgebung, wenn Produktivdaten für Tests genutzt werden.",
|
|
"link": "{{LINK:R11#5.3.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.3.1-V1",
|
|
"policy": "R11",
|
|
"control": "5.3.1",
|
|
"level": "vhigh",
|
|
"type": "SEHR HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.3.1-V1",
|
|
"impl_anchor": "IMPL 5.3.1-elev",
|
|
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
|
"requirement": "Die Sicherheit zweckgebauter oder wesentlich angepasster Software wird bei Inbetriebnahme, bei wesentlichen Änderungen oder regelmäßig getestet (z. B. Penetrationstest). (C, I, A)",
|
|
"link": "{{LINK:R11#5.3.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.3.2-M1",
|
|
"policy": "R11",
|
|
"control": "5.3.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.3.2-M1",
|
|
"impl_anchor": "IMPL 5.3.2",
|
|
"condition": null,
|
|
"requirement": "Anforderungen an die Informationssicherheit von Netzdiensten sind bestimmt und erfüllt.",
|
|
"link": "{{LINK:R11#5.3.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.3.2-S1",
|
|
"policy": "R11",
|
|
"control": "5.3.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.3.2-S1",
|
|
"impl_anchor": "IMPL 5.3.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Ein Verfahren zur Absicherung und Nutzung von Netzdiensten ist definiert und umgesetzt.",
|
|
"link": "{{LINK:R11#5.3.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.3.2-S2",
|
|
"policy": "R11",
|
|
"control": "5.3.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.3.2-S2",
|
|
"impl_anchor": "IMPL 5.3.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Die Anforderungen werden in Form von SLAs vereinbart.",
|
|
"link": "{{LINK:R11#5.3.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.3.2-S3",
|
|
"policy": "R11",
|
|
"control": "5.3.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.3.2-S3",
|
|
"impl_anchor": "IMPL 5.3.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Angemessene Redundanzlösungen sind umgesetzt.",
|
|
"link": "{{LINK:R11#5.3.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.3.2-H1",
|
|
"policy": "R11",
|
|
"control": "5.3.2",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.3.2-H1",
|
|
"impl_anchor": "IMPL 5.3.2-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Verfahren zur Überwachung der Qualität des Netzverkehrs (z. B. Traffic-Flow-Analysen, Verfügbarkeitsmessungen) sind definiert und werden durchgeführt. (A)",
|
|
"link": "{{LINK:R11#5.3.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.3.3-S1",
|
|
"policy": "R11",
|
|
"control": "5.3.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.3.3-S1",
|
|
"impl_anchor": "IMPL 5.3.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Eine Beschreibung des Beendigungsprozesses ist vorhanden, an Änderungen angepasst und vertraglich geregelt.",
|
|
"link": "{{LINK:R11#5.3.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.3.4-M1",
|
|
"policy": "R12",
|
|
"control": "5.3.4",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.3.4-M1",
|
|
"impl_anchor": "IMPL 5.3.4",
|
|
"condition": null,
|
|
"requirement": "Eine wirksame Trennung (z. B. Mandantentrennung) verhindert den Zugriff unbefugter Nutzer anderer Organisationen auf eigene Informationen.",
|
|
"link": "{{LINK:R12#5.3.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-11"
|
|
]
|
|
},
|
|
{
|
|
"id": "5.3.4-S1",
|
|
"policy": "R12",
|
|
"control": "5.3.4",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 5.3.4-S1",
|
|
"impl_anchor": "IMPL 5.3.4",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Das Trennungskonzept des Anbieters ist dokumentiert und an Änderungen angepasst; dabei werden die einschlägigen Aspekte berücksichtigt.",
|
|
"link": "{{LINK:R12#5.3.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-11"
|
|
]
|
|
},
|
|
{
|
|
"id": "5.3.4-KI-M1",
|
|
"policy": "R12",
|
|
"control": "5.3.4-KI",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": false,
|
|
"req_anchor": "REQ 5.3.4-KI-M1",
|
|
"impl_anchor": "IMPL 5.3.4-KI",
|
|
"condition": null,
|
|
"requirement": "Der Einsatz von KI-/GenAI-Diensten ist geregelt; es werden nur freigegebene Dienste genutzt.",
|
|
"link": "{{LINK:R12#5.3.4-KI}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-11"
|
|
]
|
|
},
|
|
{
|
|
"id": "5.3.4-KI-M2",
|
|
"policy": "R12",
|
|
"control": "5.3.4-KI",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": false,
|
|
"req_anchor": "REQ 5.3.4-KI-M2",
|
|
"impl_anchor": "IMPL 5.3.4-KI",
|
|
"condition": null,
|
|
"requirement": "Die Eingabe vertraulicher oder personenbezogener Informationen in nicht freigegebene KI-Dienste ist untersagt; zulässige Datenklassen je Dienst sind definiert.",
|
|
"link": "{{LINK:R12#5.3.4-KI}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-11"
|
|
]
|
|
},
|
|
{
|
|
"id": "5.3.4-KI-M3",
|
|
"policy": "R12",
|
|
"control": "5.3.4-KI",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": false,
|
|
"req_anchor": "REQ 5.3.4-KI-M3",
|
|
"impl_anchor": "IMPL 5.3.4-KI",
|
|
"condition": null,
|
|
"requirement": "Bei freigegebenen KI-Diensten ist geklärt und vertraglich sichergestellt, dass Eingaben nicht zum Training genutzt oder weitergegeben werden.",
|
|
"link": "{{LINK:R12#5.3.4-KI}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-11"
|
|
]
|
|
},
|
|
{
|
|
"id": "5.3.4-KI-S1",
|
|
"policy": "R12",
|
|
"control": "5.3.4-KI",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": false,
|
|
"req_anchor": "REQ 5.3.4-KI-S1",
|
|
"impl_anchor": "IMPL 5.3.4-KI",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Ergebnisse von KI-Diensten werden vor geschäftskritischer Verwendung geprüft (Human-in-the-Loop); der KI-Einsatz wird dokumentiert und regulatorische Anforderungen (z. B. EU AI Act) berücksichtigt.",
|
|
"link": "{{LINK:R12#5.3.4-KI}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-11"
|
|
]
|
|
},
|
|
{
|
|
"id": "6.1.1-M1",
|
|
"policy": "R13",
|
|
"control": "6.1.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.1-M1",
|
|
"impl_anchor": "IMPL 6.1.1",
|
|
"condition": null,
|
|
"requirement": "Auftragnehmer und Partner werden einer Sicherheitsrisikobewertung unterzogen.",
|
|
"link": "{{LINK:R13#6.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-10"
|
|
]
|
|
},
|
|
{
|
|
"id": "6.1.1-M2",
|
|
"policy": "R13",
|
|
"control": "6.1.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.1-M2",
|
|
"impl_anchor": "IMPL 6.1.1",
|
|
"condition": null,
|
|
"requirement": "Ein angemessenes Informationssicherheitsniveau wird durch vertragliche Vereinbarungen mit Auftragnehmern und Partnern sichergestellt.",
|
|
"link": "{{LINK:R13#6.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-10"
|
|
]
|
|
},
|
|
{
|
|
"id": "6.1.1-M3",
|
|
"policy": "R13",
|
|
"control": "6.1.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.1-M3",
|
|
"impl_anchor": "IMPL 6.1.1",
|
|
"condition": null,
|
|
"requirement": "Sofern zutreffend, werden vertragliche Vereinbarungen mit Auftraggebern/Kunden an Auftragnehmer und Partner weitergegeben.",
|
|
"link": "{{LINK:R13#6.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.1-S1",
|
|
"policy": "R13",
|
|
"control": "6.1.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.1-S1",
|
|
"impl_anchor": "IMPL 6.1.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Auftragnehmer und Partner sind vertraglich verpflichtet, Anforderungen an ein angemessenes Informationssicherheitsniveau an ihre Unterauftragnehmer weiterzugeben.",
|
|
"link": "{{LINK:R13#6.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-10"
|
|
]
|
|
},
|
|
{
|
|
"id": "6.1.1-S2",
|
|
"policy": "R13",
|
|
"control": "6.1.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.1-S2",
|
|
"impl_anchor": "IMPL 6.1.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Leistungsberichte und Dokumente von Auftragnehmern und Partnern werden geprüft.",
|
|
"link": "{{LINK:R13#6.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.1-H1",
|
|
"policy": "R13",
|
|
"control": "6.1.1",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.1-H1",
|
|
"impl_anchor": "IMPL 6.1.1-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Es wird nachgewiesen, dass das Informationssicherheitsniveau des Lieferanten dem Schutzbedarf angemessen ist (z. B. geprüfter Fragebogen/Selbstauskunft, Attestierung, Zertifikat, Lieferantenaudit). (C, I, A)",
|
|
"link": "{{LINK:R13#6.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.1-H2",
|
|
"policy": "R13",
|
|
"control": "6.1.1",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.1-H2",
|
|
"impl_anchor": "IMPL 6.1.1-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Der Grad der Erfüllung geforderter Nachweise durch den Lieferanten wird dokumentiert, regelmäßig und bei Änderungen überprüft und überwacht. (C, I, A)",
|
|
"link": "{{LINK:R13#6.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.1-H3",
|
|
"policy": "R13",
|
|
"control": "6.1.1",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.1-H3",
|
|
"impl_anchor": "IMPL 6.1.1-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Die Einhaltung vertraglicher Vereinbarungen durch den Lieferanten wird geprüft, dokumentiert, regelmäßig und bei Änderungen überprüft und überwacht. (C, I, A)",
|
|
"link": "{{LINK:R13#6.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.1-V1",
|
|
"policy": "R13",
|
|
"control": "6.1.1",
|
|
"level": "vhigh",
|
|
"type": "SEHR HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.1-V1",
|
|
"impl_anchor": "IMPL 6.1.1-elev",
|
|
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
|
"requirement": "Das angemessene Informationssicherheitsniveau sollte durch ein Drittparteien-Audit (angemessenes TISAX-Label o. Ä.) oder ein angemessenes Lieferantenaudit nachgewiesen werden. Ohne Audit muss die Leitung eine risikobasierte Entscheidung zur Fortführung treffen; ein Nachweis dieser Entscheidung existiert. (C, I, A)",
|
|
"link": "{{LINK:R13#6.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.1-V2",
|
|
"policy": "R13",
|
|
"control": "6.1.1",
|
|
"level": "vhigh",
|
|
"type": "SEHR HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.1-V2",
|
|
"impl_anchor": "IMPL 6.1.1-elev",
|
|
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
|
"requirement": "Vertragliche Verpflichtungen gegenüber Kunden zur Transparenz von Lieferkettenrisiken werden erfüllt. (C, I, A)",
|
|
"link": "{{LINK:R13#6.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.2-M1",
|
|
"policy": "R13",
|
|
"control": "6.1.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.2-M1",
|
|
"impl_anchor": "IMPL 6.1.2",
|
|
"condition": null,
|
|
"requirement": "Die Vertraulichkeitsanforderungen sind bestimmt und erfüllt.",
|
|
"link": "{{LINK:R13#6.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-10"
|
|
]
|
|
},
|
|
{
|
|
"id": "6.1.2-M2",
|
|
"policy": "R13",
|
|
"control": "6.1.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.2-M2",
|
|
"impl_anchor": "IMPL 6.1.2",
|
|
"condition": null,
|
|
"requirement": "Anforderungen und Verfahren zur Anwendung von Vertraulichkeitsvereinbarungen sind allen Personen bekannt, die schutzbedürftige Informationen weitergeben.",
|
|
"link": "{{LINK:R13#6.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.2-M3",
|
|
"policy": "R13",
|
|
"control": "6.1.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.2-M3",
|
|
"impl_anchor": "IMPL 6.1.2",
|
|
"condition": null,
|
|
"requirement": "Gültige Vertraulichkeitsvereinbarungen werden vor der Weitergabe schutzbedürftiger Informationen abgeschlossen.",
|
|
"link": "{{LINK:R13#6.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.2-M4",
|
|
"policy": "R13",
|
|
"control": "6.1.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.2-M4",
|
|
"impl_anchor": "IMPL 6.1.2",
|
|
"condition": null,
|
|
"requirement": "Die Anforderungen und Verfahren zur Nutzung von Vertraulichkeitsvereinbarungen und zum Umgang mit schutzbedürftigen Informationen werden regelmäßig überprüft.",
|
|
"link": "{{LINK:R13#6.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.2-S1",
|
|
"policy": "R13",
|
|
"control": "6.1.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.2-S1",
|
|
"impl_anchor": "IMPL 6.1.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Vorlagen für Vertraulichkeitsvereinbarungen sind vorhanden und auf rechtliche Anwendbarkeit geprüft.",
|
|
"link": "{{LINK:R13#6.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-10"
|
|
]
|
|
},
|
|
{
|
|
"id": "6.1.2-S2",
|
|
"policy": "R13",
|
|
"control": "6.1.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.2-S2",
|
|
"impl_anchor": "IMPL 6.1.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Vertraulichkeitsvereinbarungen umfassen beteiligte Personen/Organisationen, Art der Informationen, Gegenstand, Gültigkeitsdauer und Verantwortlichkeiten der verpflichteten Partei.",
|
|
"link": "{{LINK:R13#6.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.2-S3",
|
|
"policy": "R13",
|
|
"control": "6.1.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.2-S3",
|
|
"impl_anchor": "IMPL 6.1.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Vertraulichkeitsvereinbarungen enthalten Regelungen zum Umgang mit schutzbedürftigen Informationen über die Vertragsbeziehung hinaus.",
|
|
"link": "{{LINK:R13#6.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.2-S4",
|
|
"policy": "R13",
|
|
"control": "6.1.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.2-S4",
|
|
"impl_anchor": "IMPL 6.1.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Möglichkeiten zum Nachweis der Einhaltung (z. B. Prüfung durch unabhängige Dritte oder Auditrechte) sind definiert.",
|
|
"link": "{{LINK:R13#6.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.2-S5",
|
|
"policy": "R13",
|
|
"control": "6.1.2",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.2-S5",
|
|
"impl_anchor": "IMPL 6.1.2",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Ein Prozess zur Überwachung der Gültigkeitsdauer temporärer Vertraulichkeitsvereinbarungen und zur rechtzeitigen Verlängerung ist definiert und umgesetzt.",
|
|
"link": "{{LINK:R13#6.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.3-M1",
|
|
"policy": "R13",
|
|
"control": "6.1.3",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.3-M1",
|
|
"impl_anchor": "IMPL 6.1.3",
|
|
"condition": null,
|
|
"requirement": "Die betroffenen IT-Dienste sind identifiziert.",
|
|
"link": "{{LINK:R13#6.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-10"
|
|
]
|
|
},
|
|
{
|
|
"id": "6.1.3-M2",
|
|
"policy": "R13",
|
|
"control": "6.1.3",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.3-M2",
|
|
"impl_anchor": "IMPL 6.1.3",
|
|
"condition": null,
|
|
"requirement": "Die für den IT-Dienst relevanten Sicherheitsanforderungen sind bestimmt.",
|
|
"link": "{{LINK:R13#6.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.3-M3",
|
|
"policy": "R13",
|
|
"control": "6.1.3",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.3-M3",
|
|
"impl_anchor": "IMPL 6.1.3",
|
|
"condition": null,
|
|
"requirement": "Die für die Umsetzung der Anforderung verantwortliche Organisation ist definiert und sich ihrer Verantwortung bewusst.",
|
|
"link": "{{LINK:R13#6.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.3-M4",
|
|
"policy": "R13",
|
|
"control": "6.1.3",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.3-M4",
|
|
"impl_anchor": "IMPL 6.1.3",
|
|
"condition": null,
|
|
"requirement": "Mechanismen für geteilte Verantwortlichkeiten sind spezifiziert und umgesetzt.",
|
|
"link": "{{LINK:R13#6.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.3-M5",
|
|
"policy": "R13",
|
|
"control": "6.1.3",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.3-M5",
|
|
"impl_anchor": "IMPL 6.1.3",
|
|
"condition": null,
|
|
"requirement": "Die verantwortliche Organisation erfüllt ihre jeweiligen Verantwortlichkeiten.",
|
|
"link": "{{LINK:R13#6.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.3-S1",
|
|
"policy": "R13",
|
|
"control": "6.1.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.3-S1",
|
|
"impl_anchor": "IMPL 6.1.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Bei IT-Diensten ist die Konfiguration auf Basis der notwendigen Sicherheitsanforderungen konzipiert, umgesetzt und dokumentiert.",
|
|
"link": "{{LINK:R13#6.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.3-S2",
|
|
"policy": "R13",
|
|
"control": "6.1.3",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.3-S2",
|
|
"impl_anchor": "IMPL 6.1.3",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Das verantwortliche Personal ist angemessen geschult.",
|
|
"link": "{{LINK:R13#6.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.3-H1",
|
|
"policy": "R13",
|
|
"control": "6.1.3",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.3-H1",
|
|
"impl_anchor": "IMPL 6.1.3-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Eine Liste der betroffenen IT-Dienste und der jeweils verantwortlichen IT-Dienstleister existiert. (C, I, A)",
|
|
"link": "{{LINK:R13#6.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.3-H2",
|
|
"policy": "R13",
|
|
"control": "6.1.3",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.3-H2",
|
|
"impl_anchor": "IMPL 6.1.3-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Die Anwendbarkeit der ISA-Controls wurde bewertet und dokumentiert. (C, I, A)",
|
|
"link": "{{LINK:R13#6.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.3-H3",
|
|
"policy": "R13",
|
|
"control": "6.1.3",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.3-H3",
|
|
"impl_anchor": "IMPL 6.1.3-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Die Dienstkonfiguration ist in die regelmäßigen Sicherheitsbewertungen einbezogen. (C, I, A)",
|
|
"link": "{{LINK:R13#6.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.3-H4",
|
|
"policy": "R13",
|
|
"control": "6.1.3",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.3-H4",
|
|
"impl_anchor": "IMPL 6.1.3-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Es wird nachgewiesen, dass die IT-Dienstleister ihre Verantwortung erfüllen. (C, I, A)",
|
|
"link": "{{LINK:R13#6.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.3-H5",
|
|
"policy": "R13",
|
|
"control": "6.1.3",
|
|
"level": "high",
|
|
"type": "HOCH",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 6.1.3-H5",
|
|
"impl_anchor": "IMPL 6.1.3-elev",
|
|
"condition": "FLAG_HIGH_PROTECTION",
|
|
"requirement": "Die Integration in lokale Schutzmaßnahmen (z. B. sichere Authentifizierungsmechanismen) ist etabliert und dokumentiert. (C, I, A)",
|
|
"link": "{{LINK:R13#6.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "7.1.1-M1",
|
|
"policy": "R14",
|
|
"control": "7.1.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 7.1.1-M1",
|
|
"impl_anchor": "IMPL 7.1.1",
|
|
"condition": null,
|
|
"requirement": "Rechtliche, regulatorische und vertragliche Vorgaben mit Relevanz für die Informationssicherheit werden regelmäßig bestimmt.",
|
|
"link": "{{LINK:R14#7.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "7.1.1-M2",
|
|
"policy": "R14",
|
|
"control": "7.1.1",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 7.1.1-M2",
|
|
"impl_anchor": "IMPL 7.1.1",
|
|
"condition": null,
|
|
"requirement": "Richtlinien zur Einhaltung der Vorgaben sind definiert, umgesetzt und den verantwortlichen Personen kommuniziert.",
|
|
"link": "{{LINK:R14#7.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "7.1.1-S1",
|
|
"policy": "R14",
|
|
"control": "7.1.1",
|
|
"level": "should",
|
|
"type": "SOLL",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 7.1.1-S1",
|
|
"impl_anchor": "IMPL 7.1.1",
|
|
"condition": "FLAG_INCLUDE_SHOULD",
|
|
"requirement": "Die Integrität von Aufzeichnungen entsprechend rechtlichen, regulatorischen und vertraglichen Vorgaben sowie Geschäftsanforderungen wird berücksichtigt.",
|
|
"link": "{{LINK:R14#7.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "7.1.2-M1",
|
|
"policy": "R14",
|
|
"control": "7.1.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 7.1.2-M1",
|
|
"impl_anchor": "IMPL 7.1.2",
|
|
"condition": null,
|
|
"requirement": "Rechtliche und vertragliche Informationssicherheitsanforderungen an Verfahren und Prozesse bei der Verarbeitung personenbezogener Daten sind bestimmt.",
|
|
"link": "{{LINK:R14#7.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "7.1.2-M2",
|
|
"policy": "R14",
|
|
"control": "7.1.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 7.1.2-M2",
|
|
"impl_anchor": "IMPL 7.1.2",
|
|
"condition": null,
|
|
"requirement": "Regelungen zur Einhaltung rechtlicher und vertraglicher Anforderungen an den Schutz personenbezogener Daten sind definiert und den beteiligten Personen bekannt.",
|
|
"link": "{{LINK:R14#7.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "7.1.2-M3",
|
|
"policy": "R14",
|
|
"control": "7.1.2",
|
|
"level": "must",
|
|
"type": "MUSS",
|
|
"is_isa": true,
|
|
"req_anchor": "REQ 7.1.2-M3",
|
|
"impl_anchor": "IMPL 7.1.2",
|
|
"condition": null,
|
|
"requirement": "Prozesse und Verfahren zum Schutz personenbezogener Daten sind im Informationssicherheits-Managementsystem berücksichtigt.",
|
|
"link": "{{LINK:R14#7.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
}
|
|
],
|
|
"verfahren": [
|
|
{
|
|
"id": "VA-01",
|
|
"title": "Incident-Response- und Meldeverfahren",
|
|
"file": "verfahren/VA-01_Incident-Response-und-Meldeverfahren.md",
|
|
"policy": "R04",
|
|
"fulfills": [
|
|
"1.6.1-M1",
|
|
"1.6.1-M2",
|
|
"1.6.2-M1",
|
|
"1.6.2-M2",
|
|
"1.6.2-S1",
|
|
"1.6.2-S2"
|
|
],
|
|
"link": "{{LINK:VA-01}}"
|
|
},
|
|
{
|
|
"id": "VA-02",
|
|
"title": "IT-Notfall- und Wiederanlaufverfahren (BCM)",
|
|
"file": "verfahren/VA-02_IT-Notfall-und-Wiederanlaufverfahren.md",
|
|
"policy": "R04",
|
|
"fulfills": [
|
|
"1.6.3-M1",
|
|
"1.6.3-S1",
|
|
"5.2.8-M1",
|
|
"5.2.8-S1"
|
|
],
|
|
"link": "{{LINK:VA-02}}"
|
|
},
|
|
{
|
|
"id": "VA-03",
|
|
"title": "Berechtigungsverfahren (Joiner/Mover/Leaver und Rezertifizierung)",
|
|
"file": "verfahren/VA-03_Berechtigungsverfahren.md",
|
|
"policy": "R08",
|
|
"fulfills": [
|
|
"4.1.1-S1",
|
|
"4.1.3-M1",
|
|
"4.2.1-M1",
|
|
"4.2.1-M2",
|
|
"4.2.1-S1"
|
|
],
|
|
"link": "{{LINK:VA-03}}"
|
|
},
|
|
{
|
|
"id": "VA-04",
|
|
"title": "Change- und Patch-Management-Verfahren",
|
|
"file": "verfahren/VA-04_Change-und-Patch-Management-Verfahren.md",
|
|
"policy": "R10",
|
|
"fulfills": [
|
|
"5.2.1-M1",
|
|
"5.2.5-M1"
|
|
],
|
|
"link": "{{LINK:VA-04}}"
|
|
},
|
|
{
|
|
"id": "VA-05",
|
|
"title": "Backup- und Restore-Verfahren",
|
|
"file": "verfahren/VA-05_Backup-und-Restore-Verfahren.md",
|
|
"policy": "R10",
|
|
"fulfills": [
|
|
"5.2.9-M1",
|
|
"5.2.9-M2",
|
|
"5.2.9-S1"
|
|
],
|
|
"link": "{{LINK:VA-05}}"
|
|
},
|
|
{
|
|
"id": "VA-06",
|
|
"title": "Schwachstellenmanagement-Verfahren",
|
|
"file": "verfahren/VA-06_Schwachstellenmanagement-Verfahren.md",
|
|
"policy": "R10",
|
|
"fulfills": [
|
|
"5.2.5-M1",
|
|
"5.2.5-S1",
|
|
"5.2.6-M1"
|
|
],
|
|
"link": "{{LINK:VA-06}}"
|
|
},
|
|
{
|
|
"id": "VA-07",
|
|
"title": "Kryptokonzept und Schlüsselverwaltung",
|
|
"file": "verfahren/VA-07_Kryptokonzept-und-Schluesselverwaltung.md",
|
|
"policy": "R09",
|
|
"fulfills": [
|
|
"5.1.1-M1",
|
|
"5.1.1-M2",
|
|
"5.1.1-S1",
|
|
"5.1.2-M1",
|
|
"5.1.2-S1"
|
|
],
|
|
"link": "{{LINK:VA-07}}"
|
|
},
|
|
{
|
|
"id": "VA-08",
|
|
"title": "Asset- und Klassifizierungsverfahren",
|
|
"file": "verfahren/VA-08_Asset-und-Klassifizierungsverfahren.md",
|
|
"policy": "R02",
|
|
"fulfills": [
|
|
"1.3.1-M1",
|
|
"1.3.1-M2",
|
|
"1.3.1-S1",
|
|
"1.3.2-M1",
|
|
"1.3.2-M2",
|
|
"1.3.2-S1"
|
|
],
|
|
"link": "{{LINK:VA-08}}"
|
|
},
|
|
{
|
|
"id": "VA-09",
|
|
"title": "Risikomanagement-Verfahren",
|
|
"file": "verfahren/VA-09_Risikomanagement-Verfahren.md",
|
|
"policy": "R03",
|
|
"fulfills": [
|
|
"1.4.1-M1",
|
|
"1.4.1-M2",
|
|
"1.4.1-M3",
|
|
"1.4.1-S1"
|
|
],
|
|
"link": "{{LINK:VA-09}}"
|
|
},
|
|
{
|
|
"id": "VA-10",
|
|
"title": "Lieferanten-Onboarding- und Bewertungsverfahren",
|
|
"file": "verfahren/VA-10_Lieferanten-Onboarding-und-Bewertung.md",
|
|
"policy": "R13",
|
|
"fulfills": [
|
|
"6.1.1-M1",
|
|
"6.1.1-M2",
|
|
"6.1.1-S1",
|
|
"6.1.2-M1",
|
|
"6.1.2-S1",
|
|
"6.1.3-M1"
|
|
],
|
|
"link": "{{LINK:VA-10}}"
|
|
},
|
|
{
|
|
"id": "VA-11",
|
|
"title": "Cloud- und KI-Freigabeverfahren",
|
|
"file": "verfahren/VA-11_Cloud-und-KI-Freigabeverfahren.md",
|
|
"policy": "R12",
|
|
"fulfills": [
|
|
"5.3.4-M1",
|
|
"5.3.4-M2",
|
|
"5.3.4-S1",
|
|
"5.3.4-KI-M1",
|
|
"5.3.4-KI-M2",
|
|
"5.3.4-KI-M3",
|
|
"5.3.4-KI-S1"
|
|
],
|
|
"link": "{{LINK:VA-11}}"
|
|
},
|
|
{
|
|
"id": "VA-12",
|
|
"title": "Awareness- und Schulungsverfahren",
|
|
"file": "verfahren/VA-12_Awareness-und-Schulungsverfahren.md",
|
|
"policy": "R05",
|
|
"fulfills": [
|
|
"2.1.3-M1",
|
|
"2.1.3-S1"
|
|
],
|
|
"link": "{{LINK:VA-12}}"
|
|
},
|
|
{
|
|
"id": "VA-13",
|
|
"title": "Logging- und Monitoring-Verfahren",
|
|
"file": "verfahren/VA-13_Logging-und-Monitoring-Verfahren.md",
|
|
"policy": "R10",
|
|
"fulfills": [
|
|
"5.2.4-M1",
|
|
"5.2.4-S1"
|
|
],
|
|
"link": "{{LINK:VA-13}}"
|
|
}
|
|
]
|
|
} |