Basis: Certvia dev@a48c5fb als Fundament für Craftvia
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s

Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-09-14 11:05:39 +02:00
co-authored by Claude Opus 5
commit c8e6f30a27
720 changed files with 140143 additions and 0 deletions
@@ -0,0 +1,81 @@
{
"hinweis": "English texts of the ISO-only sections. Individualisation exclusively via {{VARIABLES}} and baseline IDs (BL-*) — do not enter literal values.",
"abschnitte": {
"ISO-LEITLINIE": {
"titel": "Information security policy, objectives and communication",
"umsetzung": "This policy is approved by {{ROLE_MANAGEMENT}}, published in {{TOOL_NAME}} and made known to all staff and relevant third parties; acknowledgement is recorded per version. It is reviewed at least {{POLICY_REVIEW_CYCLE}} and upon significant change (BL-GOV-03). The thematic policies and the procedures elaborate it and follow the same approval and review cycle. The information security objectives are stated in measurable terms and held in {{TOOL_NAME}} with target value, responsible role and due date; their achievement is evaluated {{MGMT_REVIEW_CYCLE}}. For internal and external communication on information security it is defined what is communicated, when, with whom and by whom; the central point of contact is {{ROLE_ISB}}."
},
"ISO-MS-KONTEXT": {
"titel": "Context, interested parties and scope of the ISMS",
"umsetzung": "Internal and external issues as well as the relevant interested parties and their requirements are maintained in {{TOOL_NAME}} as a context and stakeholder analysis and updated at least {{POLICY_REVIEW_CYCLE}} and upon significant change. The scope of the ISMS ({{ISMS_SCOPE}}) is documented information and names sites, processes, organisational units and IT services as well as interfaces and dependencies on third parties; exclusions are justified. The ISMS is operated according to the PDCA cycle and continually improved. Responsible: {{ROLE_ISB}}; approval: {{ROLE_MANAGEMENT}}."
},
"ISO-MS-CHANGE": {
"titel": "Planning of changes to the ISMS",
"umsetzung": "Changes to the ISMS — scope, organisation, roles, key processes or systems — are planned, assessed before implementation and documented in {{TOOL_NAME}}. The assessment covers the purpose and potential consequences of the change, effects on risks and controls, the resources required and the assignment of responsibilities. Approval is given by {{ROLE_MANAGEMENT}}; technical changes additionally run through change management (BL-OPS-09, see {{LINK:VA-04}})."
},
"ISO-MS-DOKU": {
"titel": "Control of documented information",
"umsetzung": "The documented information of the ISMS is maintained in {{TOOL_NAME}}. Every document carries a title, a unique identifier, version, date, status, responsible role and approver; creation and modification pass through review and four-eyes approval (BL-GOV-03). Control ensures availability to the authorised roles, protection against unauthorised modification, managed distribution, version control with a change history and retention of superseded versions ({{RECORDS_RETENTION}}). Documents of external origin are identified and controlled in the same way. Review cycle: {{POLICY_REVIEW_CYCLE}}."
},
"ISO-KONTAKTE": {
"titel": "Contact with authorities and interest groups",
"umsetzung": "{{ROLE_ISB}} maintains a contact list of the relevant authorities and reporting bodies ({{AUTHORITY_CONTACTS}}) with responsibility, availability and reporting channel; it is checked for currency {{POLICY_REVIEW_CYCLE}} and is available in an emergency without IT access. Reporting obligations and deadlines are held in the incident procedure ({{LINK:VA-01}}). In addition, professional contacts with interest groups, forums and security associations are maintained; the resulting insights feed into the evaluation of threat intelligence."
},
"ISO-SOA": {
"titel": "Statement of Applicability (SoA)",
"umsetzung": "The risk treatment determines which controls are necessary; the result is compared against Annex A to identify controls that may have been overlooked. The Statement of Applicability is maintained in {{TOOL_NAME}} and states for each control: applicability, justification for inclusion, origin (risk ID, legal or contractual requirement), implementation status, responsible role, reference to policy and procedure as well as evidence; where a control is excluded, the justification is documented. The risk treatment plan and the acceptance of residual risks are approved by the respective risk owners; the SoA is approved by {{ROLE_MANAGEMENT}} and updated with every risk assessment ({{RISK_REVIEW_CYCLE}})."
},
"ISO-MS-BETRIEB": {
"titel": "Operational planning and control",
"umsetzung": "The processes required to meet the information security requirements are laid down in the procedures and controlled in {{TOOL_NAME}}; for each process the trigger, responsible role, deadlines and evidence are defined. Planned changes are controlled and their consequences assessed; unintended changes are reviewed and corrected where necessary. Outsourced processes are determined and monitored through supplier management ({{LINK:R13}}). Evidence of execution as planned is kept in the evidence register ({{LINK:NACHWEISREGISTER}})."
},
"ISO-MS-MESSUNG": {
"titel": "Monitoring, measurement, analysis and evaluation",
"umsetzung": "For the evaluation of information security performance and the effectiveness of the ISMS it is defined what is measured (metrics sheet in {{TOOL_NAME}}), by which method and data source, at which interval, who measures, when the results are analysed and who analyses them. The metrics cover at least incident handling, vulnerability and patch remediation, recertification of access rights, restore tests, awareness participation and open actions; each metric has a target value and a responsible role. Results and trends feed into the management review {{MGMT_REVIEW_CYCLE}}; a deviation from the target value triggers an action."
},
"ISO-MS-MGMTREVIEW": {
"titel": "Management review",
"umsetzung": "{{ROLE_MANAGEMENT}} reviews the ISMS at least {{MGMT_REVIEW_CYCLE}} against a fixed agenda (BL-GOV-02). Inputs are at least: status of actions from previous reviews; changes in relevant internal and external issues and in the requirements of interested parties; feedback on information security performance (nonconformities and corrective actions, monitoring and measurement results, audit results, achievement of the information security objectives); feedback from interested parties; results of the risk assessment and status of the risk treatment plan; opportunities for improvement. Outputs are decisions on opportunities for improvement and on any need to change the ISMS, each with a responsible role and a due date. The minutes are retained in {{TOOL_NAME}}."
},
"ISO-MS-CAPA": {
"titel": "Nonconformity, corrective action and continual improvement",
"umsetzung": "Nonconformities arising from audits, controls, incidents, deviations of metrics and reports are recorded in {{TOOL_NAME}}. For each case the immediate correction and the handling of the consequences are decided, the cause is analysed and it is evaluated whether similar nonconformities exist or could occur elsewhere. Necessary corrective actions are implemented with a responsible role and a due date; their effectiveness is evaluated after the defined effectiveness interval and, where necessary, risks, controls and documents are adjusted. The nature of the nonconformity, the actions taken and the result of the effectiveness review are retained. The suitability, adequacy and effectiveness of the ISMS are continually improved; evidence is provided through metrics and the management review."
},
"ISO-THREATINTEL": {
"titel": "Threat intelligence",
"umsetzung": "Information on threats is obtained regularly from named sources ({{THREAT_INTEL_SOURCES}}) and evaluated by {{ROLE_IT_LEAD}} for relevance to the organisation's own systems and services. Relevant findings lead to actions in vulnerability and patch management ({{LINK:VA-06}}), to adjustments of monitoring ({{LINK:VA-13}}) or to a new risk assessment. Evaluation and resulting actions are documented in {{TOOL_TICKET}}."
},
"ISO-BETRIEBSABLAEUFE": {
"titel": "Documented operating procedures",
"umsetzung": "Operating procedures for information processing facilities are documented and accessible to the personnel who carry them out. They cover commissioning and configuration, operation and monitoring, backup, handling of faults, maintenance and decommissioning. The documentation is updated through change management (BL-OPS-09) whenever changes occur and is checked for currency at least {{POLICY_REVIEW_CYCLE}}. Responsible: {{ROLE_IT_LEAD}}."
},
"ISO-KAPAZITAET": {
"titel": "Capacity management",
"umsetzung": "The utilisation of the relevant resources — compute, memory, storage, network bandwidth, licences and staffing in IT operations — is monitored {{CAPACITY_REVIEW_FREQ}} (BL-OPS-11). Exceeded thresholds raise an alert; future demand is taken into account in projects and significant changes. Capacity constraints that affect the availability requirements are recorded and treated as a risk."
},
"ISO-DLP": {
"titel": "Data leakage prevention",
"umsetzung": "For systems, networks and devices that process protected information, measures against unauthorised outflow are in place (BL-OPS-12); at least {{DLP_SCOPE}} are covered. The measures follow the classification ({{LINK:R02}}): rules for disclosure, control of transfer channels, restriction of removable media (BL-EP-03) as well as logging and analysis of conspicuous transfers (BL-OPS-04). Detected violations are handled as security events ({{LINK:VA-01}}); where analysis relates to individuals, co-determination rights are observed."
},
"ISO-ZEITSYNC": {
"titel": "Clock synchronisation",
"umsetzung": "The system clocks of all logging systems are synchronised to {{NTP_SOURCES}} (BL-OPS-10). Deviations are monitored and reported. A uniform time base and time zone is a prerequisite for the analysis of logs ({{LINK:VA-13}}) and for preserving evidence in the event of an incident."
},
"ISO-DISZIPLIN": {
"titel": "Handling of violations",
"umsetzung": "A graduated, documented process applies to violations of the information security requirements and is communicated in advance. It takes into account the nature and severity of the violation, intent or negligence, repetition and the training status of the person concerned. The process is run by {{ROLE_HR_LEAD}} in coordination with {{ROLE_ISB}}; employment law requirements and co-determination rights are observed. Its application is documented confidentially."
},
"ISO-PHY-UMWELT": {
"titel": "Environmental protection, utilities, cabling and maintenance",
"umsetzung": "Sites and technical facilities are protected against physical and environmental threats (BL-PHY-03): early fire detection, protection against water and moisture, temperature and humidity monitoring in technical rooms as well as consideration of site-specific hazards. Equipment is sited so that observation, unauthorised access and environmental risks are minimised. Power and air conditioning for critical systems are designed to be uninterruptible and are tested regularly. Power and data cabling is protected against damage and unauthorised access and is documented. Equipment is maintained according to the manufacturer's specifications; maintenance is carried out only by authorised personnel, is planned and recorded, and is supervised where performed externally."
},
"ISO-PHY-CLEARDESK": {
"titel": "Clear desk and screen lock",
"umsetzung": "Binding rules apply for a clear desk and locked screens (BL-PHY-04): protected documents and media are locked away when unattended; screens are locked when leaving the workplace and lock automatically after {{SESSION_TIMEOUT}}. Printouts are collected immediately and documents no longer required are destroyed according to their protection needs (BL-DEL-01). The rules also apply when working from home and at mobile workplaces ({{LINK:R06}}); compliance is checked on a sample basis."
},
"ISO-MASKIERUNG": {
"titel": "Data masking and pseudonymisation",
"umsetzung": "Where the full information content is not required for the purpose, data is masked, pseudonymised or anonymised. This applies in particular to test, training and development environments ({{LINK:R11}}), to analyses and to displays with a restricted need for access. Extent and method follow the classification and the data protection requirements ({{LINK:R14}}); whether the link to a person may be restored, and how that is safeguarded, is governed explicitly."
}
}
}