Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,135 @@
|
||||
# Statement of Applicability
|
||||
|
||||
| Document information | Value |
|
||||
|-----------------------|------|
|
||||
| Document type | Statement of Applicability |
|
||||
| Scope | {{ISMS_SCOPE}} |
|
||||
| Organisation | {{ORG_NAME}} |
|
||||
| Responsible | {{ROLE_ISB}} |
|
||||
| Approved by | {{ROLE_MANAGEMENT}} |
|
||||
| Version | {{DOC_VERSION}} |
|
||||
| Date | {{DOC_DATE}} |
|
||||
| Status | {{DOC_STATUS}} |
|
||||
|
||||
## Purpose
|
||||
|
||||
For each control of Annex A of ISO/IEC 27001:2022 this statement records whether it is applicable, why it was included or excluded, what it derives from and how far it is implemented (ISO/IEC 27001:2022, 6.1.3 d). It is updated with every risk assessment ({{RISK_REVIEW_CYCLE}}) and approved by {{ROLE_MANAGEMENT}}. The procedure is set out in {{LINK:R03}}.
|
||||
|
||||
**Columns:** *Applicable* = yes/no · *Justification* = reason for inclusion or exclusion · *Origin* = risk ID, legal or contractual requirement · *Status* = implemented / partial / planned · *Evidence* = reference into the evidence register ({{LINK:NACHWEISREGISTER}}).
|
||||
|
||||
## A.5 Organisational controls (37 controls)
|
||||
|
||||
| Control | Title | Applicable | Justification | Origin | Status | Policy | Procedure | Evidence |
|
||||
|---|---|:--:|---|---|---|---|---|---|
|
||||
| A.5.1 | Policies for information security | yes | Determined as necessary by the risk treatment. | | | {{LINK:L00}} | - | |
|
||||
| A.5.2 | Information security roles and responsibilities | yes | Determined as necessary by the risk treatment. | | | {{LINK:R01}} | - | |
|
||||
| A.5.3 | Segregation of duties | yes | Determined as necessary by the risk treatment. | | | {{LINK:R01}} | - | |
|
||||
| A.5.4 | Management responsibilities | yes | Determined as necessary by the risk treatment. | | | {{LINK:R01}} | - | |
|
||||
| A.5.5 | Contact with authorities | yes | Determined as necessary by the risk treatment. | | | {{LINK:R01}} | - | |
|
||||
| A.5.6 | Contact with special interest groups | yes | Determined as necessary by the risk treatment. | | | {{LINK:R01}} | - | |
|
||||
| A.5.7 | Threat intelligence | yes | Determined as necessary by the risk treatment. | | | {{LINK:R10}} | - | |
|
||||
| A.5.8 | Information security in project management | yes | Determined as necessary by the risk treatment. | | | {{LINK:R01}} | VA-19 | |
|
||||
| A.5.9 | Inventory of information and other associated assets | yes | Determined as necessary by the risk treatment. | | | {{LINK:R02}} | VA-08 | |
|
||||
| A.5.10 | Acceptable use of information and other associated assets | yes | Determined as necessary by the risk treatment. | | | {{LINK:R02}} | VA-08 | |
|
||||
| A.5.11 | Return of assets | yes | Determined as necessary by the risk treatment. | | | {{LINK:R11}} | VA-08 | |
|
||||
| A.5.12 | Classification of information | yes | Determined as necessary by the risk treatment. | | | {{LINK:R02}} | VA-08 | |
|
||||
| A.5.13 | Labelling of information | yes | Determined as necessary by the risk treatment. | | | {{LINK:R02}} | VA-08 | |
|
||||
| A.5.14 | Information transfer | yes | Determined as necessary by the risk treatment. | | | {{LINK:R09}} | - | |
|
||||
| A.5.15 | Access control | yes | Determined as necessary by the risk treatment. | | | {{LINK:R08}} | VA-03 | |
|
||||
| A.5.16 | Identity management | yes | Determined as necessary by the risk treatment. | | | {{LINK:R08}} | VA-03 | |
|
||||
| A.5.17 | Authentication information | yes | Determined as necessary by the risk treatment. | | | {{LINK:R08}} | VA-03 | |
|
||||
| A.5.18 | Access rights | yes | Determined as necessary by the risk treatment. | | | {{LINK:R08}} | VA-03 | |
|
||||
| A.5.19 | Information security in supplier relationships | yes | Determined as necessary by the risk treatment. | | | {{LINK:R13}} | VA-10 | |
|
||||
| A.5.20 | Addressing information security within supplier agreements | yes | Determined as necessary by the risk treatment. | | | {{LINK:R13}} | VA-10 | |
|
||||
| A.5.21 | Managing information security in the ICT supply chain | yes | Determined as necessary by the risk treatment. | | | {{LINK:R13}} | VA-10 | |
|
||||
| A.5.22 | Monitoring, review and change management of supplier services | yes | Determined as necessary by the risk treatment. | | | {{LINK:R13}} | VA-10 | |
|
||||
| A.5.23 | Information security for use of cloud services | {{#if FLAG_CLOUD_USED}}yes{{/if}}{{#unless FLAG_CLOUD_USED}}no{{/unless}} | {{#if FLAG_CLOUD_USED}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_CLOUD_USED}}Not applicable - enter justification.{{/unless}} | | | {{LINK:R12}} | VA-11 | |
|
||||
| A.5.24 | Information security incident management planning and preparation | yes | Determined as necessary by the risk treatment. | | | {{LINK:R04}} | VA-01 | |
|
||||
| A.5.25 | Assessment and decision on information security events | yes | Determined as necessary by the risk treatment. | | | {{LINK:R04}} | VA-01 | |
|
||||
| A.5.26 | Response to information security incidents | yes | Determined as necessary by the risk treatment. | | | {{LINK:R04}} | VA-01 | |
|
||||
| A.5.27 | Learning from information security incidents | yes | Determined as necessary by the risk treatment. | | | {{LINK:R04}} | VA-01 | |
|
||||
| A.5.28 | Collection of evidence | yes | Determined as necessary by the risk treatment. | | | {{LINK:R04}} | VA-01 | |
|
||||
| A.5.29 | Information security during disruption | yes | Determined as necessary by the risk treatment. | | | {{LINK:R04}} | VA-02 | |
|
||||
| A.5.30 | ICT readiness for business continuity | yes | Determined as necessary by the risk treatment. | | | {{LINK:R04}} | VA-02 | |
|
||||
| A.5.31 | Legal, statutory, regulatory and contractual requirements | yes | Determined as necessary by the risk treatment. | | | {{LINK:R14}} | VA-18 | |
|
||||
| A.5.32 | Intellectual property rights | yes | Determined as necessary by the risk treatment. | | | {{LINK:R14}} | VA-18 | |
|
||||
| A.5.33 | Protection of records | yes | Determined as necessary by the risk treatment. | | | {{LINK:R14}} | VA-18 | |
|
||||
| A.5.34 | Privacy and protection of PII | {{#if FLAG_PERSONAL_DATA}}yes{{/if}}{{#unless FLAG_PERSONAL_DATA}}no{{/unless}} | {{#if FLAG_PERSONAL_DATA}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_PERSONAL_DATA}}Not applicable - enter justification.{{/unless}} | | | {{LINK:R14}} | VA-18 | |
|
||||
| A.5.35 | Independent review of information security | yes | Determined as necessary by the risk treatment. | | | {{LINK:R03}} | VA-15 | |
|
||||
| A.5.36 | Compliance with policies, rules and standards for information security | yes | Determined as necessary by the risk treatment. | | | {{LINK:R03}} | VA-15 | |
|
||||
| A.5.37 | Documented operating procedures | yes | Determined as necessary by the risk treatment. | | | {{LINK:R10}} | - | |
|
||||
|
||||
## A.6 People controls (8 controls)
|
||||
|
||||
| Control | Title | Applicable | Justification | Origin | Status | Policy | Procedure | Evidence |
|
||||
|---|---|:--:|---|---|---|---|---|---|
|
||||
| A.6.1 | Screening | yes | Determined as necessary by the risk treatment. | | | {{LINK:R05}} | VA-14 | |
|
||||
| A.6.2 | Terms and conditions of employment | yes | Determined as necessary by the risk treatment. | | | {{LINK:R05}} | VA-14 | |
|
||||
| A.6.3 | Information security awareness, education and training | yes | Determined as necessary by the risk treatment. | | | {{LINK:R05}} | VA-12 | |
|
||||
| A.6.4 | Disciplinary process | yes | Determined as necessary by the risk treatment. | | | {{LINK:R05}} | - | |
|
||||
| A.6.5 | Responsibilities after termination or change of employment | yes | Determined as necessary by the risk treatment. | | | {{LINK:R05}} | VA-14 | |
|
||||
| A.6.6 | Confidentiality or non-disclosure agreements | yes | Determined as necessary by the risk treatment. | | | {{LINK:R05}} | VA-14 | |
|
||||
| A.6.7 | Remote working | {{#if FLAG_MOBILE_WORK}}yes{{/if}}{{#unless FLAG_MOBILE_WORK}}no{{/unless}} | {{#if FLAG_MOBILE_WORK}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_MOBILE_WORK}}Not applicable - enter justification.{{/unless}} | | | {{LINK:R06}} | - | |
|
||||
| A.6.8 | Information security event reporting | yes | Determined as necessary by the risk treatment. | | | {{LINK:R04}} | VA-01 | |
|
||||
|
||||
## A.7 Physical controls (14 controls)
|
||||
|
||||
| Control | Title | Applicable | Justification | Origin | Status | Policy | Procedure | Evidence |
|
||||
|---|---|:--:|---|---|---|---|---|---|
|
||||
| A.7.1 | Physical security perimeters | yes | Determined as necessary by the risk treatment. | | | {{LINK:R07}} | VA-17 | |
|
||||
| A.7.2 | Physical entry | yes | Determined as necessary by the risk treatment. | | | {{LINK:R07}} | VA-17 | |
|
||||
| A.7.3 | Securing offices, rooms and facilities | yes | Determined as necessary by the risk treatment. | | | {{LINK:R07}} | VA-17 | |
|
||||
| A.7.4 | Physical security monitoring | yes | Determined as necessary by the risk treatment. | | | {{LINK:R07}} | VA-17 | |
|
||||
| A.7.5 | Protecting against physical and environmental threats | yes | Determined as necessary by the risk treatment. | | | {{LINK:R07}} | VA-17 | |
|
||||
| A.7.6 | Working in secure areas | yes | Determined as necessary by the risk treatment. | | | {{LINK:R07}} | VA-17 | |
|
||||
| A.7.7 | Clear desk and clear screen | yes | Determined as necessary by the risk treatment. | | | {{LINK:R07}} | VA-17 | |
|
||||
| A.7.8 | Equipment siting and protection | yes | Determined as necessary by the risk treatment. | | | {{LINK:R07}} | VA-17 | |
|
||||
| A.7.9 | Security of assets off-premises | {{#if FLAG_MOBILE_DEVICES}}yes{{/if}}{{#unless FLAG_MOBILE_DEVICES}}no{{/unless}} | {{#if FLAG_MOBILE_DEVICES}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_MOBILE_DEVICES}}Not applicable - enter justification.{{/unless}} | | | {{LINK:R06}} | - | |
|
||||
| A.7.10 | Storage media | yes | Determined as necessary by the risk treatment. | | | {{LINK:R06}} | VA-08 | |
|
||||
| A.7.11 | Supporting utilities | yes | Determined as necessary by the risk treatment. | | | {{LINK:R07}} | VA-17 | |
|
||||
| A.7.12 | Cabling security | yes | Determined as necessary by the risk treatment. | | | {{LINK:R07}} | VA-17 | |
|
||||
| A.7.13 | Equipment maintenance | yes | Determined as necessary by the risk treatment. | | | {{LINK:R07}} | VA-04 | |
|
||||
| A.7.14 | Secure disposal or re-use of equipment | yes | Determined as necessary by the risk treatment. | | | {{LINK:R11}} | VA-08 | |
|
||||
|
||||
## A.8 Technological controls (34 controls)
|
||||
|
||||
| Control | Title | Applicable | Justification | Origin | Status | Policy | Procedure | Evidence |
|
||||
|---|---|:--:|---|---|---|---|---|---|
|
||||
| A.8.1 | User endpoint devices | yes | Determined as necessary by the risk treatment. | | | {{LINK:R06}} | - | |
|
||||
| A.8.2 | Privileged access rights | yes | Determined as necessary by the risk treatment. | | | {{LINK:R08}} | VA-03 | |
|
||||
| A.8.3 | Information access restriction | yes | Determined as necessary by the risk treatment. | | | {{LINK:R08}} | VA-03 | |
|
||||
| A.8.4 | Access to source code | {{#if FLAG_DEV_INHOUSE}}yes{{/if}}{{#unless FLAG_DEV_INHOUSE}}no{{/unless}} | {{#if FLAG_DEV_INHOUSE}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_DEV_INHOUSE}}Not applicable - enter justification.{{/unless}} | | | {{LINK:R11}} | VA-16 | |
|
||||
| A.8.5 | Secure authentication | yes | Determined as necessary by the risk treatment. | | | {{LINK:R08}} | VA-03 | |
|
||||
| A.8.6 | Capacity management | yes | Determined as necessary by the risk treatment. | | | {{LINK:R10}} | - | |
|
||||
| A.8.7 | Protection against malware | yes | Determined as necessary by the risk treatment. | | | {{LINK:R10}} | - | |
|
||||
| A.8.8 | Management of technical vulnerabilities | yes | Determined as necessary by the risk treatment. | | | {{LINK:R10}} | VA-06 | |
|
||||
| A.8.9 | Configuration management | yes | Determined as necessary by the risk treatment. | | | {{LINK:R10}} | VA-04 | |
|
||||
| A.8.10 | Information deletion | yes | Determined as necessary by the risk treatment. | | | {{LINK:R11}} | VA-08 | |
|
||||
| A.8.11 | Data masking | {{#if FLAG_PERSONAL_DATA}}yes{{/if}}{{#unless FLAG_PERSONAL_DATA}}no{{/unless}} | {{#if FLAG_PERSONAL_DATA}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_PERSONAL_DATA}}Not applicable - enter justification.{{/unless}} | | | {{LINK:R02}} | - | |
|
||||
| A.8.12 | Data leakage prevention | yes | Determined as necessary by the risk treatment. | | | {{LINK:R10}} | - | |
|
||||
| A.8.13 | Information backup | yes | Determined as necessary by the risk treatment. | | | {{LINK:R10}} | VA-05 | |
|
||||
| A.8.14 | Redundancy of information processing facilities | yes | Determined as necessary by the risk treatment. | | | {{LINK:R04}} | VA-02 | |
|
||||
| A.8.15 | Logging | yes | Determined as necessary by the risk treatment. | | | {{LINK:R10}} | VA-13 | |
|
||||
| A.8.16 | Monitoring activities | yes | Determined as necessary by the risk treatment. | | | {{LINK:R10}} | VA-13 | |
|
||||
| A.8.17 | Clock synchronisation | yes | Determined as necessary by the risk treatment. | | | {{LINK:R10}} | VA-13 | |
|
||||
| A.8.18 | Use of privileged utility programs | yes | Determined as necessary by the risk treatment. | | | {{LINK:R08}} | VA-03 | |
|
||||
| A.8.19 | Installation of software on operational systems | yes | Determined as necessary by the risk treatment. | | | {{LINK:R02}} | VA-04 | |
|
||||
| A.8.20 | Networks security | yes | Determined as necessary by the risk treatment. | | | {{LINK:R10}} | - | |
|
||||
| A.8.21 | Security of network services | yes | Determined as necessary by the risk treatment. | | | {{LINK:R11}} | - | |
|
||||
| A.8.22 | Segregation of networks | yes | Determined as necessary by the risk treatment. | | | {{LINK:R10}} | - | |
|
||||
| A.8.23 | Web filtering | yes | Determined as necessary by the risk treatment. | | | {{LINK:R10}} | - | |
|
||||
| A.8.24 | Use of cryptography | yes | Determined as necessary by the risk treatment. | | | {{LINK:R09}} | VA-07 | |
|
||||
| A.8.25 | Secure development life cycle | {{#if FLAG_DEV_INHOUSE}}yes{{/if}}{{#unless FLAG_DEV_INHOUSE}}no{{/unless}} | {{#if FLAG_DEV_INHOUSE}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_DEV_INHOUSE}}Not applicable - enter justification.{{/unless}} | | | {{LINK:R11}} | VA-16 | |
|
||||
| A.8.26 | Application security requirements | {{#if FLAG_DEV_INHOUSE}}yes{{/if}}{{#unless FLAG_DEV_INHOUSE}}no{{/unless}} | {{#if FLAG_DEV_INHOUSE}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_DEV_INHOUSE}}Not applicable - enter justification.{{/unless}} | | | {{LINK:R11}} | VA-16 | |
|
||||
| A.8.27 | Secure system architecture and engineering principles | {{#if FLAG_DEV_INHOUSE}}yes{{/if}}{{#unless FLAG_DEV_INHOUSE}}no{{/unless}} | {{#if FLAG_DEV_INHOUSE}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_DEV_INHOUSE}}Not applicable - enter justification.{{/unless}} | | | {{LINK:R11}} | VA-16 | |
|
||||
| A.8.28 | Secure coding | {{#if FLAG_DEV_INHOUSE}}yes{{/if}}{{#unless FLAG_DEV_INHOUSE}}no{{/unless}} | {{#if FLAG_DEV_INHOUSE}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_DEV_INHOUSE}}Not applicable - enter justification.{{/unless}} | | | {{LINK:R11}} | VA-16 | |
|
||||
| A.8.29 | Security testing in development and acceptance | {{#if FLAG_DEV_INHOUSE}}yes{{/if}}{{#unless FLAG_DEV_INHOUSE}}no{{/unless}} | {{#if FLAG_DEV_INHOUSE}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_DEV_INHOUSE}}Not applicable - enter justification.{{/unless}} | | | {{LINK:R11}} | VA-16 | |
|
||||
| A.8.30 | Outsourced development | {{#if FLAG_DEV_INHOUSE}}yes{{/if}}{{#unless FLAG_DEV_INHOUSE}}no{{/unless}} | {{#if FLAG_DEV_INHOUSE}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_DEV_INHOUSE}}Not applicable - enter justification.{{/unless}} | | | {{LINK:R11}} | VA-16 | |
|
||||
| A.8.31 | Separation of development, test and production environments | {{#if FLAG_DEV_INHOUSE}}yes{{/if}}{{#unless FLAG_DEV_INHOUSE}}no{{/unless}} | {{#if FLAG_DEV_INHOUSE}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_DEV_INHOUSE}}Not applicable - enter justification.{{/unless}} | | | {{LINK:R10}} | VA-16 | |
|
||||
| A.8.32 | Change management | yes | Determined as necessary by the risk treatment. | | | {{LINK:R10}} | VA-04 | |
|
||||
| A.8.33 | Test information | {{#if FLAG_DEV_INHOUSE}}yes{{/if}}{{#unless FLAG_DEV_INHOUSE}}no{{/unless}} | {{#if FLAG_DEV_INHOUSE}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_DEV_INHOUSE}}Not applicable - enter justification.{{/unless}} | | | {{LINK:R11}} | VA-16 | |
|
||||
| A.8.34 | Protection of information systems during audit testing | yes | Determined as necessary by the risk treatment. | | | {{LINK:R10}} | VA-15 | |
|
||||
|
||||
## Management system requirements (clauses 4-10)
|
||||
|
||||
The requirements of clauses 4 to 10 are not subject to the Statement of Applicability; they apply directly. Their allocation to the policies is held in `mapping-iso.json`.
|
||||
Reference in New Issue
Block a user