Basis: Certvia dev@a48c5fb als Fundament für Craftvia
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s

Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-09-14 11:05:39 +02:00
co-authored by Claude Opus 5
commit c8e6f30a27
720 changed files with 140143 additions and 0 deletions
@@ -0,0 +1,49 @@
# Policy Data Protection
| Document information | Value |
|-----------------------|------|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_DPO}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## 1. Purpose
This policy governs the protection of personal data (assessment objective data protection, VDA ISA chapter 9). It elaborates the information security policy ({{LINK:L00}}) and complements the policy Compliance and Data Protection ({{LINK:R14}}).
## 2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}), insofar as personal data is processed.
## 3. Requirements and implementation
> Structure per section: **Requirement** (1:1 from VDA ISA, chapter 9) and **Implementation at {{ORG_NAME}}**.
{{#if FLAG_PERSONAL_DATA}}
### 3.1 Data protection organisation (ISA 9.1.1)
**Requirement**
<!-- REQ 9.1.1-M1 -->
- **[MUST]** Responsibilities for data protection are appointed and the data protection organisation is documented.
**Implementation at {{ORG_NAME}}**
The role {{ROLE_DPO}} is appointed and integrated into the ISMS organisation. Tasks, reporting paths and escalation are documented.
### 3.2 Lawfulness and record of processing activities (ISA 9.2.1)
**Requirement**
<!-- REQ 9.2.1-M1 -->
- **[MUST]** Processing of personal data is lawful, purpose-bound and recorded in a record of processing activities.
**Implementation at {{ORG_NAME}}**
A record of processing activities is maintained and updated regularly. For each processing activity, the legal basis, purpose and deletion periods are documented.
{{/if}}
@@ -0,0 +1,175 @@
# Information Security Policy
| Document information | Value |
|-----------------------|------|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_ISB}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## 1. Purpose
<!-- REQ 1.1.1-M1 -->
This information security policy describes the fundamental requirements, objectives and responsibilities of {{ORG_NAME}} for protecting information, IT systems, business processes and supporting assets. The information security requirements are defined, documented and aligned with the objectives of {{ORG_NAME}}.
The objective is to ensure an appropriate level of information security and to meet the requirements of VDA ISA 2027 in the area of information security.
## 2. Scope
This policy applies to the defined ISMS scope:
{{ISMS_SCOPE_DESCRIPTION}}
It applies to:
- all employees within the scope,
- managers,
- external service providers, insofar as they have access to the organisation's information, systems or processes,
- relevant IT systems, information, applications, sites and business processes within the ISMS scope.
## 3. Information security objectives
<!-- REQ 1.1.1-M3 -->
The policy states the objectives and the importance of information security. Through the ISMS, the organisation pursues in particular the following objectives:
- protection of confidential information against unauthorised access,
- ensuring the integrity of information and systems,
- ensuring the availability of business-critical information, systems and services,
- compliance with legal, regulatory and contractual requirements,
- appropriate protection of customer information, personal data, trade secrets and other information requiring protection,
- structured identification, assessment and treatment of information security risks,
- continual improvement of information security.
## 4. Information security principles
Information security is based on the following principles:
### 4.1 Risk orientation
Information security measures are planned, implemented, reviewed and improved in a risk-oriented manner. Risks are assessed and tracked in the ISMS tool in use ({{TOOL_NAME}}) (see {{LINK:R03}}).
### 4.2 Appropriateness
Protective measures must be appropriate to the protection needs of the information, systems and processes. Confidentiality, integrity and availability are taken into account.
### 4.3 Responsibility
Information security is a shared responsibility of all employees. {{ROLE_MANAGEMENT}} holds overall responsibility for the ISMS.
### 4.4 Traceability
Decisions, assessments, approvals and material measures relating to information security must be documented in a traceable manner.
### 4.5 Continual improvement
The ISMS is reviewed regularly and adjusted where necessary. Findings from audits, incidents, risks, changes and management reviews feed into the improvement.
## 5. Information security requirements
<!-- REQ 1.1.1-S1 -->
{{#if FLAG_INCLUDE_SHOULD}}The information security requirements are based on the strategy of {{ORG_NAME}}; legal and contractual requirements are taken into account. {{/if}}The organisation determines and documents information security requirements on the basis of:
- legal and regulatory requirements,
- contractual requirements, in particular from customers and partners,
- requirements from the VDA ISA,
- internal business requirements,
- results of risk analyses,
- protection needs of information, processes and IT systems,
- requirements from projects, changes and external IT services.
The relevant requirements in each case are taken into account in the ISMS and implemented through suitable policies, processes, technical measures and evidence.
## 6. Roles and responsibilities
The organisation defines roles and responsibilities for information security. These include at least:
| Role | Fundamental responsibility |
|-------|------------------------------|
| {{ROLE_MANAGEMENT}} | Overall responsibility, approval of the information security policy, provision of appropriate resources |
| {{ROLE_ISB}} | Steering, maintenance and further development of the ISMS |
| Managers | Implementation of the requirements within their respective area of responsibility |
| {{ROLE_IT_LEAD}} | Implementation of technical and organisational security measures in the IT area |
| Asset owners / process owners | Assessment and maintenance of relevant information, processes and assets in the ISMS tool |
| Employees | Compliance with the policies and reporting of security events |
| External service providers | Compliance with contractually agreed security requirements |
The specific assignment of roles and responsibilities is maintained in the ISMS tool ({{TOOL_NAME}}) or in a supplementary role matrix (see also {{LINK:R01}}).
## 7. Binding nature
<!-- REQ 1.1.1-M2 -->
<!-- REQ 1.1.1-S2 -->
This policy is approved by {{ROLE_MANAGEMENT}} and is binding for all affected persons within the scope. {{#if FLAG_INCLUDE_SHOULD}}Violations of information security requirements may lead to organisational, employment-law or contractual measures. {{/if}}All employees are obliged to:
- comply with the applicable information security policies,
- handle information requiring protection appropriately,
- report security events or suspected cases without delay,
- use only approved systems, applications and services,
- report identified vulnerabilities or risks to the responsible body.
## 8. Publication and communication
<!-- REQ 1.1.1-M4 -->
<!-- REQ 1.1.1-M5 -->
The information security policy is made known to the relevant persons in a suitable form; employees and affected external partners are informed about relevant changes. This can be done via:
- publication in the ISMS tool ({{TOOL_NAME}}),
- internal wiki or document management system,
- onboarding process,
- awareness training (see {{LINK:R05}}),
- direct communication to the affected target groups.
## 9. Review and update
<!-- REQ 1.1.1-S4 -->
This policy is reviewed regularly, but at least:
- {{REVIEW_CYCLE}},
- upon material changes to the ISMS scope,
- upon material organisational or technical changes,
- in the event of relevant security incidents,
- upon new or changed regulatory, legal or contractual requirements.
Changes are documented and approved by {{ROLE_MANAGEMENT}}.
## 10. Evidence
The evidence for the implementation of this policy is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
## 11. Related documents
<!-- REQ 1.1.1-S3 -->
Further topic-specific security policies (R01–R14) are established and coordinated with one another.
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- ISMS organisation and roles: {{LINK:R01}}
- All thematic policies: {{LINK:R01}} … {{LINK:R14}}
<!-- Das Mapping der Anforderungen (REQ/IMPL) zu VDA-ISA-Controls ist in mapping.json hinterlegt und wird vom Tool über die Hidden-Anker aufgelöst. Im Lesemodus nicht sichtbar. -->
<!-- FW:ISO-SECTION-START -->
{{#if FLAG_FW_ISO27001}}
## Annex A — Information security policy, objectives and communication
*Requirement reference:* ISO/IEC 27001 5.2, 6.2, 7.4, A.5.1
**Requirement**
<!-- REQ 5.2-1 -->
- **[ISO 5.2]** An information security policy is established that fits the organisation, sets objectives, commits to meeting requirements and to continual improvement, and is communicated and available.
<!-- REQ 6.2-1 -->
- **[ISO 6.2]** Information security objectives are established for relevant functions and levels, and their achievement is planned.
<!-- REQ 7.4-1 -->
- **[ISO 7.4]** The internal and external communications relevant to the ISMS are determined.
<!-- REQ A.5.1-1 -->
- **[ISO A.5.1]** The information security policy and topic-specific policies are defined, approved by management, published, communicated, acknowledged and reviewed at planned intervals.
**Implementation at {{ORG_NAME}}**
<!-- IMPL ISO-LEITLINIE -->
This policy is approved by {{ROLE_MANAGEMENT}}, published in {{TOOL_NAME}} and made known to all staff and relevant third parties; acknowledgement is recorded per version. It is reviewed at least {{POLICY_REVIEW_CYCLE}} and upon significant change (BL-GOV-03). The thematic policies and the procedures elaborate it and follow the same approval and review cycle. The information security objectives are stated in measurable terms and held in {{TOOL_NAME}} with target value, responsible role and due date; their achievement is evaluated {{MGMT_REVIEW_CYCLE}}. For internal and external communication on information security it is defined what is communicated, when, with whom and by whom; the central point of contact is {{ROLE_ISB}}.
{{/if}}
<!-- FW:ISO-SECTION-END -->
@@ -0,0 +1,60 @@
# Policy Prototype Protection
| Document information | Value |
|-----------------------|------|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_ISB}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## 1. Purpose
This policy governs the protection of prototypes and development objects requiring protection (assessment objective prototype protection, VDA ISA chapter 8). It elaborates the information security policy ({{LINK:L00}}) and is operationalised by the procedure {{LINK:VA-20}}.
## 2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}), insofar as prototypes or development objects requiring protection are processed, stored or transported.
## 3. Requirements and implementation
> Structure per section: **Requirement** (1:1 from VDA ISA, chapter 8) and **Implementation at {{ORG_NAME}}**.
{{#if FLAG_PROTOTYPE_PROTECTION}}
### 3.1 Physical security and perimeter (ISA 8.1.1)
**Requirement**
<!-- REQ 8.1.1-M1 -->
- **[MUST]** Areas in which prototypes are processed or stored are protected by defined security zones and an effective perimeter.
**Implementation at {{ORG_NAME}}**
Prototype areas are designated as a dedicated security zone with access control, perimeter protection and logging. Access is limited to authorised persons.
### 3.2 Confidentiality and classification (ISA 8.2.1)
**Requirement**
<!-- REQ 8.2.1-M1 -->
- **[MUST]** Confidentiality obligations exist for prototypes; the associated information is classified and labelled accordingly.
**Implementation at {{ORG_NAME}}**
All persons involved with prototypes (internal and external) sign confidentiality agreements. Prototypes and associated documents are classified as confidential or higher in accordance with the classification scheme.
### 3.3 Transport and storage (ISA 8.3.1)
**Requirement**
<!-- REQ 8.3.1-M1 -->
- **[MUST]** Transport and storage of prototypes are carried out according to documented protection requirements that ensure confidentiality and integrity.
**Implementation at {{ORG_NAME}}**
Transport and storage follow the procedure {{LINK:VA-20}}: secured containers, logged handovers, access and visual protection as well as traceability.
{{/if}}
@@ -0,0 +1,294 @@
# Policy ISMS Organisation and Roles
| Document information | Value |
|-----------------------|------|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_ISB}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## 1. Purpose
This policy governs the structure, steering and responsibilities of the ISMS of {{ORG_NAME}} as well as the consideration of information security in projects. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
## 2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
## 3. Requirements and implementation
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
### 3.1 Steering of information security
<!-- FW:REF-START ORIG:(ISA 1.2.1) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.2.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 5.1, A.5.4{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 1.2.1-M1 -->
- **[MUST]** The scope of the ISMS (the organisation governed by the ISMS) is defined.
<!-- REQ 1.2.1-M2 -->
- **[MUST]** The organisation's requirements for the ISMS are determined.
<!-- REQ 1.2.1-M3 -->
- **[MUST]** The organisation's management has commissioned and approved the ISMS.
<!-- REQ 1.2.1-M4 -->
- **[MUST]** The ISMS provides management with suitable means for monitoring and steering (e.g. management review).
<!-- REQ 1.2.1-M5 -->
- **[MUST]** The applicable controls are determined (e.g. ISO 27001 statement of applicability or a completed ISA catalogue).
<!-- REQ 1.2.1-M6 -->
- **[MUST]** The effectiveness of the ISMS is reviewed regularly by management.
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ 5.1-1 -->
- **[ISO 5.1]** Top management demonstrates leadership and commitment with respect to the ISMS.
<!-- REQ A.5.4-1 -->
- **[ISO A.5.4]** Management requires all personnel to apply information security in accordance with the established requirements.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 1.2.1 -->
The ISMS scope, the requirements and the applicable controls (statement of applicability / ISA catalogue) are documented in the ISMS tool ({{TOOL_NAME}}). {{ROLE_MANAGEMENT}} has commissioned and approved the ISMS by management decision, provides resources and reviews its effectiveness at least {{REVIEW_CYCLE}} in a documented management review; operational steering rests with {{ROLE_ISB}}.
### 3.2 Organisation of information security
<!-- FW:REF-START ORIG:(ISA 1.2.2) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.2.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 5.3, 7.1, A.5.2, A.5.3{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 1.2.2-M1 -->
- **[MUST]** Responsibilities for information security are defined, documented and assigned.
<!-- REQ 1.2.2-M2 -->
- **[MUST]** The responsible employees are defined, qualified and enabled for their task.
<!-- REQ 1.2.2-M3 -->
- **[MUST]** The necessary resources are available.
<!-- REQ 1.2.2-M4 -->
- **[MUST]** The points of contact are known within the organisation and to relevant business partners.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.2.2-S1 -->
- **[SHOULD]** An appropriate information security structure within the organisation is defined and documented.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.2.2-S2 -->
- **[SHOULD]** Security-relevant roles that are not part of the ISMS but are relevant to information security are taken into account.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 1.2.2-H1 -->
- **[HIGH]** An appropriate organisational separation of responsibilities is established to avoid conflicts of interest (segregation of duties). (C, I, A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ 5.3-1 -->
- **[ISO 5.3]** Responsibilities and authorities for security-relevant roles are assigned and communicated.
<!-- REQ 7.1-1 -->
- **[ISO 7.1]** The resources needed for the ISMS are determined and provided.
<!-- REQ A.5.2-1 -->
- **[ISO A.5.2]** Information security roles and responsibilities are defined and allocated.
<!-- REQ A.5.3-1 -->
- **[ISO A.5.3]** Conflicting duties and areas of responsibility are segregated to reduce unauthorised or unintentional modification and misuse.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 1.2.2 -->
Responsibilities are documented in the role/responsibility matrix and in the ISMS tool ({{TOOL_NAME}}) and made known to the role holders as well as to relevant business partners. The role {{ROLE_ISB}} is appointed, qualified, equipped with resources and authority, and reports directly to {{ROLE_MANAGEMENT}}.
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 1.2.2-elev -->
Where the protection need is high, an organisational segregation of duties (e.g. implementation vs. control) is established; unavoidable dual roles are safeguarded by compensating controls (four-eyes principle).
{{/if}}
### 3.3 Information security in projects
<!-- FW:REF-START ORIG:(ISA 1.2.3) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.2.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.8{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 1.2.3-M1 -->
- **[MUST]** Projects are classified taking information security requirements into account.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.2.3-S1 -->
- **[SHOULD]** Procedures and criteria for classifying projects are documented.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.2.3-S2 -->
- **[SHOULD]** A risk assessment following the defined procedure is carried out in an early project phase and repeated upon project changes.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.2.3-S3 -->
- **[SHOULD]** Measures are derived for identified information security risks and taken into account in the project.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 1.2.3-H1 -->
- **[HIGH]** The derived measures are reviewed regularly during the project and reassessed when the assessment criteria change. (C, I, A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.8-1 -->
- **[ISO A.5.8]** Information security is integrated into project management.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 1.2.3 -->
At the outset, projects are classified with regard to their information security needs on the basis of the documented catalogue of criteria (BL-PROJ-01); classification, risk assessment and derived measures are maintained in the project register ({{LINK:REG-PROJECTS}}). In an early project phase and upon changes, a risk assessment is carried out following the procedure Information Security in Projects ({{LINK:VA-19}}); measures are tracked as tasks in {{TOOL_TICKET}} and reviewed before project completion. The project management is responsible; where the protection need is elevated, {{ROLE_ISB}} is involved.
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 1.2.3-elev -->
Where the protection need is high, the derived measures are reviewed continuously over the course of the project and reassessed when the assessment criteria change.
{{/if}}
## 4. Binding nature
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_ISB}}.
## 5. Roles and responsibilities
| Role | Responsibility in this policy |
|-------|-------------------------------------|
| {{ROLE_MANAGEMENT}} | Commissioning, overall responsibility, management review |
| {{ROLE_ISB}} | Operational steering of the ISMS |
| {{ROLE_IT_LEAD}} | Technical implementation |
## 6. Review and update
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_ISB}} and approved by {{ROLE_MANAGEMENT}}.
## 7. Evidence
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
## 8. Related documents
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- Further: {{LINK:L00}}, {{LINK:R03}}, {{LINK:R13}}
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->
<!-- FW:ISO-SECTION-START -->
{{#if FLAG_FW_ISO27001}}
### 3.4 Context, interested parties and scope of the ISMS
*Requirement reference:* ISO/IEC 27001 4.1, 4.2, 4.3, 4.4
**Requirement**
<!-- REQ 4.1-1 -->
- **[ISO 4.1]** Internal and external issues that affect the ability to achieve the ISMS objectives are determined and kept up to date.
<!-- REQ 4.2-1 -->
- **[ISO 4.2]** The interested parties relevant to the ISMS and their information security requirements are determined.
<!-- REQ 4.3-1 -->
- **[ISO 4.3]** The scope of the ISMS is determined considering the issues, requirements and interfaces, and maintained as documented information.
<!-- REQ 4.4-1 -->
- **[ISO 4.4]** An ISMS is established, implemented, maintained and continually improved.
**Implementation at {{ORG_NAME}}**
<!-- IMPL ISO-MS-KONTEXT -->
Internal and external issues as well as the relevant interested parties and their requirements are maintained in {{TOOL_NAME}} as a context and stakeholder analysis and updated at least {{POLICY_REVIEW_CYCLE}} and upon significant change. The scope of the ISMS ({{ISMS_SCOPE}}) is documented information and names sites, processes, organisational units and IT services as well as interfaces and dependencies on third parties; exclusions are justified. The ISMS is operated according to the PDCA cycle and continually improved. Responsible: {{ROLE_ISB}}; approval: {{ROLE_MANAGEMENT}}.
{{/if}}
<!-- FW:ISO-SECTION-END -->
<!-- FW:ISO-SECTION-START -->
{{#if FLAG_FW_ISO27001}}
### 3.5 Planning of changes to the ISMS
*Requirement reference:* ISO/IEC 27001 6.3
**Requirement**
<!-- REQ 6.3-1 -->
- **[ISO 6.3]** Changes to the ISMS are carried out in a planned manner.
**Implementation at {{ORG_NAME}}**
<!-- IMPL ISO-MS-CHANGE -->
Changes to the ISMS — scope, organisation, roles, key processes or systems — are planned, assessed before implementation and documented in {{TOOL_NAME}}. The assessment covers the purpose and potential consequences of the change, effects on risks and controls, the resources required and the assignment of responsibilities. Approval is given by {{ROLE_MANAGEMENT}}; technical changes additionally run through change management (BL-OPS-09, see {{LINK:VA-04}}).
{{/if}}
<!-- FW:ISO-SECTION-END -->
<!-- FW:ISO-SECTION-START -->
{{#if FLAG_FW_ISO27001}}
### 3.6 Control of documented information
*Requirement reference:* ISO/IEC 27001 7.5.1, 7.5.2, 7.5.3
**Requirement**
<!-- REQ 7.5.1-1 -->
- **[ISO 7.5.1]** The ISMS includes the documented information required by the standard and that determined as necessary.
<!-- REQ 7.5.2-1 -->
- **[ISO 7.5.2]** When creating and updating documented information, identification, format and medium as well as review and approval are ensured.
<!-- REQ 7.5.3-1 -->
- **[ISO 7.5.3]** Documented information is controlled: availability, protection, distribution, access, retention and change control.
**Implementation at {{ORG_NAME}}**
<!-- IMPL ISO-MS-DOKU -->
The documented information of the ISMS is maintained in {{TOOL_NAME}}. Every document carries a title, a unique identifier, version, date, status, responsible role and approver; creation and modification pass through review and four-eyes approval (BL-GOV-03). Control ensures availability to the authorised roles, protection against unauthorised modification, managed distribution, version control with a change history and retention of superseded versions ({{RECORDS_RETENTION}}). Documents of external origin are identified and controlled in the same way. Review cycle: {{POLICY_REVIEW_CYCLE}}.
{{/if}}
<!-- FW:ISO-SECTION-END -->
<!-- FW:ISO-SECTION-START -->
{{#if FLAG_FW_ISO27001}}
### 3.7 Contact with authorities and interest groups
*Requirement reference:* ISO/IEC 27001 A.5.5, A.5.6
**Requirement**
<!-- REQ A.5.5-1 -->
- **[ISO A.5.5]** Appropriate contacts with relevant authorities are established and maintained.
<!-- REQ A.5.6-1 -->
- **[ISO A.5.6]** Appropriate contacts with special interest groups, professional forums and security associations are maintained.
**Implementation at {{ORG_NAME}}**
<!-- IMPL ISO-KONTAKTE -->
{{ROLE_ISB}} maintains a contact list of the relevant authorities and reporting bodies ({{AUTHORITY_CONTACTS}}) with responsibility, availability and reporting channel; it is checked for currency {{POLICY_REVIEW_CYCLE}} and is available in an emergency without IT access. Reporting obligations and deadlines are held in the incident procedure ({{LINK:VA-01}}). In addition, professional contacts with interest groups, forums and security associations are maintained; the resulting insights feed into the evaluation of threat intelligence.
{{/if}}
<!-- FW:ISO-SECTION-END -->
@@ -0,0 +1,259 @@
# Policy Asset and Classification Policy
| Document information | Value |
|-----------------------|------|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_IT_LEAD}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## 1. Purpose
This policy governs the identification, classification and protected handling of information assets as well as the approval of hardware and software. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
## 2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
## 3. Requirements and implementation
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
### 3.1 Identification of information assets
<!-- FW:REF-START ORIG:(ISA 1.3.1) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.3.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.9{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 1.3.1-M1 -->
- **[MUST]** The organisation's information assets and other security-relevant assets are identified and recorded.
<!-- REQ 1.3.1-M2 -->
- **[MUST]** The supporting assets that process the information assets are identified and recorded.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.3.1-S1 -->
- **[SHOULD]** A catalogue of the relevant information assets exists; the relevant aspects are taken into account.
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.9-1 -->
- **[ISO A.5.9]** An inventory of information and associated assets, including owners, is established and maintained.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 1.3.1 -->
Information assets and supporting assets are recorded in the ISMS tool ({{TOOL_NAME}}) in the asset inventory with attributes (owner, location, protection need) and maintained as a catalogue (see {{LINK:VA-08}}); additions and removals are triggered via {{TOOL_TICKET}}.
### 3.2 Classification of information assets
<!-- FW:REF-START ORIG:(ISA 1.3.2) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.3.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.12, A.5.13{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 1.3.2-M1 -->
- **[MUST]** A consistent scheme for classifying information assets with regard to the protection goal of confidentiality is in place.
<!-- REQ 1.3.2-M2 -->
- **[MUST]** The identified information assets are assessed according to the defined criteria and assigned to the classification scheme.
<!-- REQ 1.3.2-M3 -->
- **[MUST]** Requirements for handling supporting assets (e.g. labelling, use, transport, storage, return, deletion/destruction) depending on the classification are in place and implemented.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.3.2-S1 -->
- **[SHOULD]** The protection goals of integrity and availability are taken into account.
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.12-1 -->
- **[ISO A.5.12]** Information is classified according to its protection needs (confidentiality, integrity, availability).
<!-- REQ A.5.13-1 -->
- **[ISO A.5.13]** Procedures for labelling information in accordance with the classification scheme are developed and implemented.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 1.3.2 -->
A consistent four-tier classification scheme (Public / Internal / Confidential / Strictly confidential) applies for confidentiality; the classification is carried out according to defined criteria by the asset owner in the ISMS tool and also takes integrity and availability into account. Handling requirements per protection class (labelling, storage, transport, transmission BL-CRY-01/04, deletion BL-DEL-01) are defined, implemented and made known (see {{LINK:VA-08}}).
### 3.3 Use of approved external IT services/hardware
<!-- FW:REF-START ORIG:(ISA 1.3.3) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.3.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.10{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 1.3.3-M1 -->
- **[MUST]** External IT services are not used without an explicit assessment and implementation of the information security requirements; the relevant aspects are taken into account.
<!-- REQ 1.3.3-M2 -->
- **[MUST]** The external IT services are aligned with the protection need of the information assets processed.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.3.3-S1 -->
- **[SHOULD]** Requirements for procurement, commissioning and approval in connection with the use of external IT services are determined and met.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.3.3-S2 -->
- **[SHOULD]** A procedure for approval taking the protection need into account is established.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.3.3-S3 -->
- **[SHOULD]** External IT services and their approval are documented.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.3.3-S4 -->
- **[SHOULD]** It is regularly verified that only approved external IT services are used.
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.10-1 -->
- **[ISO A.5.10]** Rules for the acceptable use and handling of information and assets are defined, documented and implemented.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 1.3.3 -->
External IT services/components are assessed before use, aligned with the protection need and approved via a defined procedure; the approvals are maintained in the register of external IT/cloud/AI services ({{LINK:REG-EXT-SERVICES}}) (supplier {{LINK:VA-10}}, asset {{LINK:VA-08}}) and regularly checked for exclusive use of approved services.
### 3.4 Approval of software
<!-- FW:REF-START ORIG:(ISA 1.3.4) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.3.4{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.19{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 1.3.4-M1 -->
- **[MUST]** Software is approved before installation or use; the relevant aspects are taken into account.
<!-- REQ 1.3.4-M2 -->
- **[MUST]** The software approval also applies to special software such as maintenance tools.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.3.4-S1 -->
- **[SHOULD]** The types of software to be managed (firmware, operating systems, applications, libraries, device drivers) are determined.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.3.4-S2 -->
- **[SHOULD]** Repositories of the managed software exist.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.3.4-S3 -->
- **[SHOULD]** The software repositories are protected against unauthorised manipulation.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.3.4-S4 -->
- **[SHOULD]** The approval of software is reviewed regularly.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.3.4-S5 -->
- **[SHOULD]** Software versions and patch levels are known.
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 1.3.4-V1 -->
- **[VERY HIGH]** Additional requirements for software use (e.g. the need to control/monitor use) are determined where present. (C, I, A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.8.19-1 -->
- **[ISO A.8.19]** Procedures and measures for securely managing software installation on operational systems are implemented.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 1.3.4 -->
Software (incl. special/maintenance software) is approved before use; approved software is maintained in the software whitelist register ({{LINK:REG-SW-WHITELIST}}) with version/patch level, source/supplier ({{LINK:VA-10}}) and approval status and is linked to the asset inventory ({{LINK:VA-08}}); procurement/approval runs via {{TOOL_TICKET}}. Managed software types are determined, repositories protected against manipulation, and approvals are reviewed regularly.
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 1.3.4-elev -->
{{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, additional control/monitoring requirements for software use are determined and implemented.{{/if}}
{{/if}}
## 4. Binding nature
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_IT_LEAD}}.
## 5. Roles and responsibilities
| Role | Responsibility in this policy |
|-------|-------------------------------------|
| {{ROLE_IT_LEAD}} | Asset inventory, approval of hardware/software |
| {{ROLE_ISB}} | Classification scheme |
| Asset owner | Maintenance of individual assets |
## 6. Review and update
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_IT_LEAD}} and approved by {{ROLE_MANAGEMENT}}.
## 7. Evidence
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
## 8. Related documents
- Associated procedures: {{LINK:VA-08}}
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- Further: {{LINK:R01}}, {{LINK:R08}}, {{LINK:R11}}
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->
<!-- FW:ISO-SECTION-START -->
{{#if FLAG_FW_ISO27001}}
### 3.5 Data masking and pseudonymisation
*Requirement reference:* ISO/IEC 27001 A.8.11
**Requirement**
<!-- REQ A.8.11-1 -->
- **[ISO A.8.11]** Data masking is applied in accordance with the access control and privacy requirements.
**Implementation at {{ORG_NAME}}**
<!-- IMPL ISO-MASKIERUNG -->
Where the full information content is not required for the purpose, data is masked, pseudonymised or anonymised. This applies in particular to test, training and development environments ({{LINK:R11}}), to analyses and to displays with a restricted need for access. Extent and method follow the classification and the data protection requirements ({{LINK:R14}}); whether the link to a person may be restored, and how that is safeguarded, is governed explicitly.
{{/if}}
<!-- FW:ISO-SECTION-END -->
@@ -0,0 +1,289 @@
# Policy Risk Management and Audit Policy
| Document information | Value |
|-----------------------|------|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_ISB}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## 1. Purpose
This policy governs the identification, assessment and treatment of information security risks as well as internal and independent reviews. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
## 2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
## 3. Requirements and implementation
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
### 3.1 Risk management
<!-- FW:REF-START ORIG:(ISA 1.4.1) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.4.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 6.1.1, 6.1.2, 8.2, 8.3{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 1.4.1-M1 -->
- **[MUST]** Risk assessments are carried out regularly and on an ad-hoc basis.
<!-- REQ 1.4.1-M2 -->
- **[MUST]** Information security risks are assessed appropriately (e.g. likelihood of occurrence and potential extent of damage).
<!-- REQ 1.4.1-M3 -->
- **[MUST]** Information security risks are documented.
<!-- REQ 1.4.1-M4 -->
- **[MUST]** A responsible person (risk owner) is assigned to each information security risk and is responsible for its assessment and treatment.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.4.1-S1 -->
- **[SHOULD]** A procedure for the identification, assessment and treatment of security risks is in place.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.4.1-S2 -->
- **[SHOULD]** Criteria for the assessment and treatment of security risks exist.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.4.1-S3 -->
- **[SHOULD]** Risk treatment measures and their responsible persons are defined and documented; a measures plan or implementation overview is tracked.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.4.1-S4 -->
- **[SHOULD]** Upon changes in the environment (e.g. organisational structure, location, regulations), a reassessment is carried out promptly.
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ 6.1.1-1 -->
- **[ISO 6.1.1]** When planning the ISMS, risks and opportunities that need to be addressed are determined.
<!-- REQ 6.1.2-1 -->
- **[ISO 6.1.2]** A risk assessment process with defined criteria is established and applied so that it is repeatable and produces comparable results.
<!-- REQ 8.2-1 -->
- **[ISO 8.2]** Risk assessments are performed at planned intervals and upon significant change, and are documented.
<!-- REQ 8.3-1 -->
- **[ISO 8.3]** The risk treatment plan is implemented and the results are documented.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 1.4.1 -->
The documented risk management procedure (see {{LINK:VA-09}}) with assessment and acceptance criteria is implemented in the ISMS tool ({{TOOL_NAME}}): risks are identified regularly ({{REVIEW_CYCLE}}) and on an ad-hoc basis, assessed (likelihood × impact) and documented; for each risk, a risk owner, treatment option and measures with deadlines are recorded and tracked. Residual risks are accepted by {{ROLE_MANAGEMENT}} in a documented manner.
### 3.2 Verification of compliance in IS operations
<!-- FW:REF-START ORIG:(ISA 1.5.1) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.5.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.36{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 1.5.1-M1 -->
- **[MUST]** Compliance with the policies is reviewed organisation-wide.
<!-- REQ 1.5.1-M2 -->
- **[MUST]** Information security policies and procedures are reviewed regularly.
<!-- REQ 1.5.1-M3 -->
- **[MUST]** Measures to correct possible deviations are initiated and tracked.
<!-- REQ 1.5.1-M4 -->
- **[MUST]** Compliance with information security requirements (e.g. technical specifications) is reviewed regularly.
<!-- REQ 1.5.1-M5 -->
- **[MUST]** The results of the reviews carried out are recorded and retained.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.5.1-S1 -->
- **[SHOULD]** A plan for the content and framework conditions (schedule, scope, controls) of the reviews to be carried out is in place.
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.36-1 -->
- **[ISO A.5.36]** Compliance with the information security policy, topic-specific policies, rules and standards is reviewed regularly.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 1.5.1 -->
Compliance with policies, procedures and technical requirements is reviewed organisation-wide and regularly according to the audit programme ({{LINK:REG-AUDIT-PLAN}}) and the audit/compliance review procedure ({{LINK:VA-15}}) through internal audits and controls (cycle BL-GOV-01); results are recorded and retained, deviations are tracked as measures in {{TOOL_NAME}}; responsible: {{ROLE_ISB}}.
### 3.3 Independent review of the ISMS
<!-- FW:REF-START ORIG:(ISA 1.5.2) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.5.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 9.2, A.5.35{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 1.5.2-M1 -->
- **[MUST]** Information security reviews are carried out by an independent and competent body regularly and after fundamental changes.
<!-- REQ 1.5.2-M2 -->
- **[MUST]** Measures to correct possible deviations are initiated and tracked.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.5.2-S1 -->
- **[SHOULD]** The results of the reviews carried out are documented and reported to the organisation's management.
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ 9.2-1 -->
- **[ISO 9.2]** Internal audits are conducted at planned intervals to verify conformity and effective implementation of the ISMS.
<!-- REQ A.5.35-1 -->
- **[ISO A.5.35]** The organisation's approach to managing information security is reviewed independently at planned intervals.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 1.5.2 -->
The ISMS is reviewed regularly and after fundamental changes by an independent, competent body (internal audit or external auditing, e.g. TISAX); results are documented, reported to {{ROLE_MANAGEMENT}} and deviations tracked as measures.
## 4. Binding nature
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_ISB}}.
## 5. Roles and responsibilities
| Role | Responsibility in this policy |
|-------|-------------------------------------|
| {{ROLE_ISB}} | Risk management, audits |
| {{ROLE_MANAGEMENT}} | Risk acceptance |
## 6. Review and update
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_ISB}} and approved by {{ROLE_MANAGEMENT}}.
## 7. Evidence
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
## 8. Related documents
- Associated procedures: {{LINK:VA-09}}
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- Further: {{LINK:R01}}, {{LINK:R04}}
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->
<!-- FW:ISO-SECTION-START -->
{{#if FLAG_FW_ISO27001}}
### 3.4 Statement of Applicability (SoA)
*Requirement reference:* ISO/IEC 27001 6.1.3
**Requirement**
<!-- REQ 6.1.3-1 -->
- **[ISO 6.1.3]** A risk treatment process is defined; necessary controls are determined and compared against Annex A in a Statement of Applicability.
**Implementation at {{ORG_NAME}}**
<!-- IMPL ISO-SOA -->
The risk treatment determines which controls are necessary; the result is compared against Annex A to identify controls that may have been overlooked. The Statement of Applicability is maintained in {{TOOL_NAME}} and states for each control: applicability, justification for inclusion, origin (risk ID, legal or contractual requirement), implementation status, responsible role, reference to policy and procedure as well as evidence; where a control is excluded, the justification is documented. The risk treatment plan and the acceptance of residual risks are approved by the respective risk owners; the SoA is approved by {{ROLE_MANAGEMENT}} and updated with every risk assessment ({{RISK_REVIEW_CYCLE}}).
{{/if}}
<!-- FW:ISO-SECTION-END -->
<!-- FW:ISO-SECTION-START -->
{{#if FLAG_FW_ISO27001}}
### 3.5 Operational planning and control
*Requirement reference:* ISO/IEC 27001 8.1
**Requirement**
<!-- REQ 8.1-1 -->
- **[ISO 8.1]** The processes needed to meet the requirements are planned, implemented and controlled; planned changes are controlled.
**Implementation at {{ORG_NAME}}**
<!-- IMPL ISO-MS-BETRIEB -->
The processes required to meet the information security requirements are laid down in the procedures and controlled in {{TOOL_NAME}}; for each process the trigger, responsible role, deadlines and evidence are defined. Planned changes are controlled and their consequences assessed; unintended changes are reviewed and corrected where necessary. Outsourced processes are determined and monitored through supplier management ({{LINK:R13}}). Evidence of execution as planned is kept in the evidence register ({{LINK:NACHWEISREGISTER}}).
{{/if}}
<!-- FW:ISO-SECTION-END -->
<!-- FW:ISO-SECTION-START -->
{{#if FLAG_FW_ISO27001}}
### 3.6 Monitoring, measurement, analysis and evaluation
*Requirement reference:* ISO/IEC 27001 9.1
**Requirement**
<!-- REQ 9.1-1 -->
- **[ISO 9.1]** The information security performance and the effectiveness of the ISMS are monitored, measured, analysed and evaluated.
**Implementation at {{ORG_NAME}}**
<!-- IMPL ISO-MS-MESSUNG -->
For the evaluation of information security performance and the effectiveness of the ISMS it is defined what is measured (metrics sheet in {{TOOL_NAME}}), by which method and data source, at which interval, who measures, when the results are analysed and who analyses them. The metrics cover at least incident handling, vulnerability and patch remediation, recertification of access rights, restore tests, awareness participation and open actions; each metric has a target value and a responsible role. Results and trends feed into the management review {{MGMT_REVIEW_CYCLE}}; a deviation from the target value triggers an action.
{{/if}}
<!-- FW:ISO-SECTION-END -->
<!-- FW:ISO-SECTION-START -->
{{#if FLAG_FW_ISO27001}}
### 3.7 Management review
*Requirement reference:* ISO/IEC 27001 9.3
**Requirement**
<!-- REQ 9.3-1 -->
- **[ISO 9.3]** Top management reviews the ISMS at planned intervals.
**Implementation at {{ORG_NAME}}**
<!-- IMPL ISO-MS-MGMTREVIEW -->
{{ROLE_MANAGEMENT}} reviews the ISMS at least {{MGMT_REVIEW_CYCLE}} against a fixed agenda (BL-GOV-02). Inputs are at least: status of actions from previous reviews; changes in relevant internal and external issues and in the requirements of interested parties; feedback on information security performance (nonconformities and corrective actions, monitoring and measurement results, audit results, achievement of the information security objectives); feedback from interested parties; results of the risk assessment and status of the risk treatment plan; opportunities for improvement. Outputs are decisions on opportunities for improvement and on any need to change the ISMS, each with a responsible role and a due date. The minutes are retained in {{TOOL_NAME}}.
{{/if}}
<!-- FW:ISO-SECTION-END -->
<!-- FW:ISO-SECTION-START -->
{{#if FLAG_FW_ISO27001}}
### 3.8 Nonconformity, corrective action and continual improvement
*Requirement reference:* ISO/IEC 27001 10.1, 10.2
**Requirement**
<!-- REQ 10.1-1 -->
- **[ISO 10.1]** The suitability, adequacy and effectiveness of the ISMS are continually improved.
<!-- REQ 10.2-1 -->
- **[ISO 10.2]** In the event of nonconformity, corrections are made and corrective actions are taken to eliminate the causes.
**Implementation at {{ORG_NAME}}**
<!-- IMPL ISO-MS-CAPA -->
Nonconformities arising from audits, controls, incidents, deviations of metrics and reports are recorded in {{TOOL_NAME}}. For each case the immediate correction and the handling of the consequences are decided, the cause is analysed and it is evaluated whether similar nonconformities exist or could occur elsewhere. Necessary corrective actions are implemented with a responsible role and a due date; their effectiveness is evaluated after the defined effectiveness interval and, where necessary, risks, controls and documents are adjusted. The nature of the nonconformity, the actions taken and the result of the effectiveness review are retained. The suitability, adequacy and effectiveness of the ISMS are continually improved; evidence is provided through metrics and the management review.
{{/if}}
<!-- FW:ISO-SECTION-END -->
@@ -0,0 +1,383 @@
# Policy Incident, Emergency and Continuity Policy
| Document information | Value |
|-----------------------|------|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_ISB}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## 1. Purpose
This policy governs the reporting and handling of security events, crisis management as well as emergency and continuity planning. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
## 2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
## 3. Requirements and implementation
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
### 3.1 Reporting of security events
<!-- FW:REF-START ORIG:(ISA 1.6.1) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.6.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.24, A.6.8{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 1.6.1-M1 -->
- **[MUST]** A definition of a reportable security event or observation exists and is known to employees and relevant stakeholders.
<!-- REQ 1.6.1-M2 -->
- **[MUST]** Appropriate, risk-oriented mechanisms for reporting security events are defined, implemented and known to all relevant reporters.
<!-- REQ 1.6.1-M3 -->
- **[MUST]** Appropriate channels for communicating with reporters exist.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.1-S1 -->
- **[SHOULD]** A common point of contact for event reporting exists.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.1-S2 -->
- **[SHOULD]** Different reporting channels depending on the perceived severity (real-time for serious events/emergencies as well as asynchronous mechanisms such as tickets or email) are available.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.1-S3 -->
- **[SHOULD]** Employees are obliged and trained to report relevant events.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.1-S4 -->
- **[SHOULD]** Security events can also be reported by external parties; the relevant aspects are taken into account.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.1-S5 -->
- **[SHOULD]** The mechanism and the information on how incidents are reported are accessible to all relevant reporters.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.1-S6 -->
- **[SHOULD]** A feedback procedure to the reporters is established.
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 1.6.1-V1 -->
- **[VERY HIGH]** Tests and exercises of event and observation reporting are carried out regularly. (C, I, A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.24-1 -->
- **[ISO A.5.24]** The management of information security incidents is planned and prepared (roles, processes, responsibilities).
<!-- REQ A.6.8-1 -->
- **[ISO A.6.8]** A mechanism for the timely reporting of observed or suspected information security events is provided.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 1.6.1 -->
A known definition of reportable events and a low-threshold reporting path (report button/form in {{TOOL_TICKET}} or the ISMS tool, email to {{ROLE_ISB}}, real-time channel for serious cases) are available to all employees and external parties; the reporting path is known via onboarding/awareness (BL-HR-01), and a feedback procedure is established (see {{LINK:VA-01}}).
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 1.6.1-elev -->
{{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, tests and exercises of event reporting are carried out regularly.{{/if}}
{{/if}}
### 3.2 Handling of security events
<!-- FW:REF-START ORIG:(ISA 1.6.2) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.6.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.25, A.5.26, A.5.27, A.5.28{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 1.6.2-M1 -->
- **[MUST]** Reported events are processed without undue delay.
<!-- REQ 1.6.2-M2 -->
- **[MUST]** An appropriate response to reported security events is ensured.
<!-- REQ 1.6.2-M3 -->
- **[MUST]** Lessons learned feed into continual improvement.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.2-S1 -->
- **[SHOULD]** During processing, reported events are categorised (e.g. personnel, physical, cyber), qualified (e.g. not security-relevant, observation, improvement suggestion, vulnerability, incident) and prioritised (e.g. low, medium, high, critical).
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.2-S2 -->
- **[SHOULD]** Responsibilities for handling events per category are defined and assigned.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.2-S3 -->
- **[SHOULD]** A strategy for reporting potentially criminally relevant aspects to the competent authorities, where necessary, exists. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 1.6.2-H1 -->
- **[HIGH]** Maximum response times per class, category and severity are defined. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 1.6.2-H2 -->
- **[HIGH]** Events not processed in line with their priority are escalated; the relevant aspects are taken into account. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 1.6.2-H3 -->
- **[HIGH]** Legal, regulatory and contractual reporting obligations and the associated contact information are known. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 1.6.2-H4 -->
- **[HIGH]** A communication strategy for security-relevant events exists; the relevant aspects are taken into account. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 1.6.2-H5 -->
- **[HIGH]** Procedures for responding to security incidents at suppliers are established; the relevant aspects are taken into account. (C, I, A)
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 1.6.2-V1 -->
- **[VERY HIGH]** The handling of events of different categories and priorities is tested regularly; the relevant aspects are taken into account. (A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.25-1 -->
- **[ISO A.5.25]** Information security events are assessed and a decision is taken whether they are to be categorised as incidents.
<!-- REQ A.5.26-1 -->
- **[ISO A.5.26]** Information security incidents are responded to in accordance with documented procedures.
<!-- REQ A.5.27-1 -->
- **[ISO A.5.27]** Knowledge gained from information security incidents is used to strengthen the controls.
<!-- REQ A.5.28-1 -->
- **[ISO A.5.28]** Procedures for the identification, collection, acquisition and preservation of evidence relating to incidents are established and implemented.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 1.6.2 -->
Events are categorised, qualified, prioritised, handled and documented without delay following a defined incident procedure (see {{LINK:VA-01}}) in {{TOOL_TICKET}}; responsibilities and escalation paths are assigned ({{ROLE_ISB}} coordinates, {{ROLE_IT_LEAD}} implements). Lessons learned feed into improvement; a strategy for reporting to authorities/law enforcement exists.
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 1.6.2-elev -->
Where the protection need is high, maximum response times per severity are defined, escalations for events not processed in line with their priority are regulated, reporting obligations and contacts are known, and a communication strategy as well as a procedure for supplier incidents are established. {{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, event handling is tested regularly.{{/if}}
{{/if}}
### 3.3 Crisis management
<!-- FW:REF-START ORIG:(ISA 1.6.3) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.6.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.29{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 1.6.3-M1 -->
- **[MUST]** An appropriate plan for responding to and managing crisis situations exists and the necessary resources are available.
<!-- REQ 1.6.3-M2 -->
- **[MUST]** Responsibilities and authorities for crisis management are defined, documented and assigned.
<!-- REQ 1.6.3-M3 -->
- **[MUST]** The responsible employees are defined and qualified for their task.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.3-S1 -->
- **[SHOULD]** Methods for detecting crisis situations are established; general indicators and specific foreseeable crises are identified.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.3-S2 -->
- **[SHOULD]** A procedure for triggering and/or escalating crisis management is in place.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.3-S3 -->
- **[SHOULD]** Strategic objectives and their priority in crisis situations are defined and known to relevant personnel.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.3-S4 -->
- **[SHOULD]** A crisis team is defined and approved.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.3-S5 -->
- **[SHOULD]** Crisis policies and procedures are defined and approved.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.3-S6 -->
- **[SHOULD]** The crisis planning is reviewed and updated regularly.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 1.6.3-H1 -->
- **[HIGH]** Relevant different potential crisis scenarios are identified.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 1.6.3-H2 -->
- **[HIGH]** The resources and information necessary for crisis management (e.g. communication infrastructure, availability of contact and risk information) are identified; appropriate measures to ensure availability or fallback planning are in place. (A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 1.6.3-H3 -->
- **[HIGH]** A communication strategy for crisis situations exists. (A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 1.6.3-H4 -->
- **[HIGH]** The efficiency, feasibility and appropriateness of the crisis planning are assessed regularly. (A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 1.6.3-H5 -->
- **[HIGH]** Sample-based tests of the crisis planning are carried out (e.g. simulation, tabletop exercises with key personnel). (A)
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 1.6.3-V1 -->
- **[VERY HIGH]** Crisis exercises and simulations involving all relevant persons, including decision-makers, are carried out regularly. (A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.29-1 -->
- **[ISO A.5.29]** The maintenance of information security during disruption is planned and implemented.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 1.6.3 -->
A crisis management with a plan, a defined and approved crisis team, roles, triggering/escalation, communication and decision paths as well as strategic objectives is established (triggering/recovery see {{LINK:VA-02}}); the necessary resources are available and the responsible persons are qualified. Detection methods are in place, the crisis planning is reviewed and updated regularly; the crisis team is convened by {{ROLE_MANAGEMENT}}.
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 1.6.3-elev -->
Where the protection need is high, relevant crisis scenarios are identified, the necessary resources/information and a communication strategy are ensured, and the planning is assessed regularly and tested on a sample basis (tabletop). {{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, crisis exercises involving all relevant persons including decision-makers are carried out regularly.{{/if}}
{{/if}}
### 3.4 Continuity planning for IT services
<!-- FW:REF-START ORIG:(ISA 5.2.8) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.2.8{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.30, A.8.14{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 5.2.8-M1 -->
- **[MUST]** Critical IT services are identified and the business impact is taken into account.
<!-- REQ 5.2.8-M2 -->
- **[MUST]** Requirements and responsibilities for the continuity and recovery of these IT services are known to relevant stakeholders and fulfilled.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.8-S1 -->
- **[SHOULD]** Critical IT systems are identified; the relevant aspects are taken into account.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.8-S2 -->
- **[SHOULD]** A continuity plan exists and is reviewed and updated regularly.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.8-S3 -->
- **[SHOULD]** The continuity planning covers at least (D)DoS attacks, successful ransomware attacks and other sabotage, system failure scenarios as well as natural disasters affecting critical IT systems.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.2.8-H1 -->
- **[HIGH]** The continuity planning contains predefined time frames (recovery time objective) for the resumption of operations. (A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.2.8-H2 -->
- **[HIGH]** Appropriate SLAs with external service providers in line with the continuity planning are in place. (A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.2.8-H3 -->
- **[HIGH]** The continuity plans include the coordination of contractually agreed communication with business partners. (A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.2.8-H4 -->
- **[HIGH]** The continuity planning is tested regularly, incl. full recovery to a known state and adherence to defined target times. (A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.2.8-H5 -->
- **[HIGH]** A backup and recovery strategy for critical IT services and information is defined and implemented. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.2.8-H6 -->
- **[HIGH]** Backups of critical IT services and information are sufficiently protected against unauthorised modification/deletion by malware. (I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.2.8-H7 -->
- **[HIGH]** Backups of critical IT services and information are sufficiently protected against unauthorised access by malware or operators. (C, I)
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 5.2.8-V1 -->
- **[VERY HIGH]** The continuity planning is coordinated with the continuity plans of relevant external service providers. (A)
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 5.2.8-V2 -->
- **[VERY HIGH]** The continuation of essential core and business functions with minimal or no loss of operational continuity is possible; the relevant aspects are taken into account.
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 5.2.8-V3 -->
- **[VERY HIGH]** The continuity planning is tested regularly. Test scenarios, results and lessons learned are recorded. (I, A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.30-1 -->
- **[ISO A.5.30]** ICT readiness is planned, implemented and tested on the basis of the business continuity objectives and requirements.
<!-- REQ A.8.14-1 -->
- **[ISO A.8.14]** Information processing facilities are implemented with sufficient redundancy to meet the availability requirements.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 5.2.8 -->
Critical IT services are recorded with their business impact in the register of critical IT services ({{LINK:REG-CRIT-SERVICES}}) (incl. BIA classification, RTO/RPO, recovery sequence); requirements and responsibilities for continuity/recovery are known and fulfilled. A continuity plan (incl. (D)DoS, ransomware, failure, natural disasters) exists, is reviewed regularly and implemented via the IT emergency procedure (see {{LINK:VA-02}}).
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 5.2.8-elev -->
Where the protection need is high, RTO/RPO, SLAs with service providers, partner communication, regular full tests as well as a protected backup/recovery strategy (immutable/isolated) are established. {{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, the planning is coordinated with external service providers, the continuation of essential functions is ensured, and tests incl. lessons learned are recorded.{{/if}}
{{/if}}
## 4. Binding nature
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_ISB}}.
## 5. Roles and responsibilities
| Role | Responsibility in this policy |
|-------|-------------------------------------|
| {{ROLE_ISB}} | Incident coordination |
| {{ROLE_IT_LEAD}} | Emergency/recovery planning |
| {{ROLE_MANAGEMENT}} | Crisis team |
## 6. Review and update
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_ISB}} and approved by {{ROLE_MANAGEMENT}}.
## 7. Evidence
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
## 8. Related documents
- Associated procedures: {{LINK:VA-01}}, {{LINK:VA-02}}
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- Further: {{LINK:R03}}, {{LINK:R10}}
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->
@@ -0,0 +1,221 @@
# Policy Personnel Security and Awareness
| Document information | Value |
|-----------------------|------|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_HR_LEAD}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## 1. Purpose
This policy governs the suitability, contractual commitment as well as training and awareness of personnel. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
## 2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
## 3. Requirements and implementation
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
### 3.1 Qualification for sensitive activities
<!-- FW:REF-START ORIG:(ISA 2.1.1) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 2.1.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 7.2, A.6.1{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 2.1.1-M1 -->
- **[MUST]** Sensitive work areas and activities are determined.
<!-- REQ 2.1.1-M2 -->
- **[MUST]** The requirements for employees with regard to their job profiles are determined and met.
<!-- REQ 2.1.1-M3 -->
- **[MUST]** The identity of potential employees is verified (e.g. checking of identity documents).
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 2.1.1-S1 -->
- **[SHOULD]** The personal suitability of potential employees is checked using simple methods (e.g. job interview).
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 2.1.1-S2 -->
- **[SHOULD]** An extended suitability check depending on the work area and the activity is carried out (e.g. assessment centre, checking of references, certificates and criminal record certificates).
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ 7.2-1 -->
- **[ISO 7.2]** The necessary competence is determined and ensured; corresponding evidence is retained.
<!-- REQ A.6.1-1 -->
- **[ISO A.6.1]** Background verification of candidates is carried out appropriately to the business requirements and in accordance with the law.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 2.1.1 -->
Sensitive work areas and activities are determined in the register of sensitive activities ({{LINK:REG-SENS-ROLES}}) and recorded with the required depth of checking; requirements for positions are documented in job descriptions and are met. Identity verification as well as the personal and — for sensitive roles — extended suitability check (interview, references, criminal record certificate within the legally permissible scope) are carried out following the suitability and verification procedure ({{LINK:VA-14}}); responsible: {{ROLE_HR_LEAD}}; evidence in the personnel file.
### 3.2 Contractual commitment of personnel
<!-- FW:REF-START ORIG:(ISA 2.1.2) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 2.1.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.6.2, A.6.5, A.6.6{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 2.1.2-M1 -->
- **[MUST]** A confidentiality obligation is in force.
<!-- REQ 2.1.2-M2 -->
- **[MUST]** An obligation to comply with the information security policies is in force.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 2.1.2-S1 -->
- **[SHOULD]** A confidentiality obligation going beyond the employment contract is in force.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 2.1.2-S2 -->
- **[SHOULD]** Information security aspects are taken into account in the employees' employment contracts.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 2.1.2-S3 -->
- **[SHOULD]** A procedure for dealing with violations of these obligations is described.
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.6.2-1 -->
- **[ISO A.6.2]** The employment agreements state the responsibilities for information security.
<!-- REQ A.6.5-1 -->
- **[ISO A.6.5]** Continuing information security responsibilities after termination or change of employment are defined and enforced.
<!-- REQ A.6.6-1 -->
- **[ISO A.6.6]** Confidentiality or non-disclosure agreements are identified, documented and reviewed regularly.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 2.1.2 -->
All employees are contractually obliged upon joining to confidentiality and to compliance with the information security policies ({{ROLE_HR_LEAD}}); information security aspects are part of the employment contracts, and confidentiality continues to apply after termination. A documented procedure for dealing with violations (see {{LINK:VA-14}}) is established; the evidence is kept in the personnel file.
### 3.3 Awareness and training
<!-- FW:REF-START ORIG:(ISA 2.1.3) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 2.1.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 7.3, A.6.3{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 2.1.3-M1 -->
- **[MUST]** Employees are trained and made aware.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 2.1.3-S1 -->
- **[SHOULD]** A concept for the awareness and training of employees is created.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 2.1.3-S2 -->
- **[SHOULD]** Target groups for training and awareness measures (e.g. managers, administrators, employees with access to customer networks, production personnel) are identified and taken into account in the concept.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 2.1.3-S3 -->
- **[SHOULD]** The concept is approved by the responsible management.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 2.1.3-S4 -->
- **[SHOULD]** Training and awareness measures are carried out regularly and on an ad-hoc basis.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 2.1.3-S5 -->
- **[SHOULD]** Participation in training and awareness measures is documented.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 2.1.3-S6 -->
- **[SHOULD]** Points of contact for information security are known to the employees.
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ 7.3-1 -->
- **[ISO 7.3]** Persons under the organisation's control are aware of the policy, their contribution and the consequences of non-conformance.
<!-- REQ A.6.3-1 -->
- **[ISO A.6.3]** Personnel receive appropriate awareness, education and training as well as regular updates of the relevant policies.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 2.1.3 -->
A role-specific training/awareness concept approved by management (BL-HR-01) is established; employees are trained upon joining and thereafter at least {{REVIEW_CYCLE}} and on an ad-hoc basis (process see {{LINK:VA-12}}). Target groups are identified, records of participation are kept in {{TOOL_NAME}}, points of contact for information security are known; the effectiveness is checked (e.g. phishing simulation).
## 4. Binding nature
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_HR_LEAD}}.
## 5. Roles and responsibilities
| Role | Responsibility in this policy |
|-------|-------------------------------------|
| {{ROLE_HR_LEAD}} | Commitment, suitability |
| {{ROLE_ISB}} | Awareness/training |
## 6. Review and update
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_HR_LEAD}} and approved by {{ROLE_MANAGEMENT}}.
## 7. Evidence
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
## 8. Related documents
- Associated procedures: {{LINK:VA-12}}
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- Further: {{LINK:R01}}, {{LINK:R06}}
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->
<!-- FW:ISO-SECTION-START -->
{{#if FLAG_FW_ISO27001}}
### 3.4 Handling of violations
*Requirement reference:* ISO/IEC 27001 A.6.4
**Requirement**
<!-- REQ A.6.4-1 -->
- **[ISO A.6.4]** A disciplinary process for information security violations is established and communicated.
**Implementation at {{ORG_NAME}}**
<!-- IMPL ISO-DISZIPLIN -->
A graduated, documented process applies to violations of the information security requirements and is communicated in advance. It takes into account the nature and severity of the violation, intent or negligence, repetition and the training status of the person concerned. The process is run by {{ROLE_HR_LEAD}} in coordination with {{ROLE_ISB}}; employment law requirements and co-determination rights are observed. Its application is documented confidentially.
{{/if}}
<!-- FW:ISO-SECTION-END -->
@@ -0,0 +1,151 @@
# Policy Mobile Working and Mobile Devices
| Document information | Value |
|-----------------------|------|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_ISB}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## 1. Purpose
This policy governs mobile working as well as the handling of mobile IT devices and data media. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
## 2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
## 3. Requirements and implementation
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
{{#if FLAG_MOBILE_WORK}}
### 3.1 Mobile working
<!-- FW:REF-START ORIG:(ISA 2.1.4) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 2.1.4{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.6.7{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 2.1.4-M1 -->
- **[MUST]** The requirements for mobile working are determined and met; the relevant aspects are taken into account.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 2.1.4-S1 -->
- **[SHOULD]** The relevant aspects of mobile working are taken into account.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 2.1.4-S2 -->
- **[SHOULD]** Awareness of employees.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 2.1.4-H1 -->
- **[HIGH]** Protective measures against eavesdropping and being overlooked are implemented. (C)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.6.7-1 -->
- **[ISO A.6.7]** Security measures for working outside the organisation's premises are implemented.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 2.1.4 -->
Mobile working is defined in this policy and the associated mobile working rule (stored in {{TOOL_NAME}}) and the requirements are met; access is exclusively via {{TECH_VPN}} with MFA (BL-IAM-02) and approved, encrypted devices (BL-CRY-03). Employees are made aware (BL-HR-01).
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 2.1.4-elev -->
Where the protection need is high, protective measures against eavesdropping and being overlooked are implemented (e.g. privacy screen, quiet environment, clean screen).
{{/if}}
{{/if}}
{{#if FLAG_MOBILE_DEVICES}}
### 3.2 Mobile IT devices and data media
<!-- FW:REF-START ORIG:(ISA 3.1.4) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 3.1.4{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.7.9, A.7.10, A.8.1{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 3.1.4-M1 -->
- **[MUST]** The requirements for mobile IT devices and mobile data media are determined and met; the relevant aspects are taken into account.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 3.1.4-S1 -->
- **[SHOULD]** Registration of the IT devices.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 3.1.4-H1 -->
- **[HIGH]** General encryption of mobile data media or of the information assets stored on them. Where technically not feasible, information is protected by equivalent measures. (C, I)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.7.9-1 -->
- **[ISO A.7.9]** Assets used outside the premises are protected.
<!-- REQ A.7.10-1 -->
- **[ISO A.7.10]** Storage media are protected throughout their life cycle (acquisition, use, transport, disposal) in accordance with the classification scheme.
<!-- REQ A.8.1-1 -->
- **[ISO A.8.1]** Information stored on, processed by or accessible via user endpoint devices is protected.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 3.1.4 -->
The requirements for mobile devices and data media are determined and met: devices are registered and centrally managed via {{TECH_MDM}}, only approved devices are used; loss is reported via the reporting path (R04) and {{TOOL_TICKET}}, blocking/wiping upon loss via {{TECH_MDM}} (BL-EP-02).
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 3.1.4-elev -->
Where the protection need is high, mobile data media or the information stored on them are generally encrypted (BL-CRY-03); where not feasible, equivalent protective measures apply.
{{/if}}
{{/if}}
## 4. Binding nature
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_ISB}}.
## 5. Roles and responsibilities
| Role | Responsibility in this policy |
|-------|-------------------------------------|
| {{ROLE_ISB}} | Security requirements |
| {{ROLE_IT_LEAD}} | Technical implementation |
## 6. Review and update
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_ISB}} and approved by {{ROLE_MANAGEMENT}}.
## 7. Evidence
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
## 8. Related documents
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- Further: {{LINK:R05}}, {{LINK:R07}}, {{LINK:R08}}
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->
@@ -0,0 +1,173 @@
# Policy Physical Security
| Document information | Value |
|-----------------------|------|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_IT_LEAD}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## 1. Purpose
This policy governs physical protection through security zones, access protection and the handling of supporting utilities. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
## 2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
## 3. Requirements and implementation
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
### 3.1 Security zones and access
<!-- FW:REF-START ORIG:(ISA 3.1.1) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 3.1.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.7.1, A.7.2, A.7.3, A.7.4, A.7.6{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 3.1.1-M1 -->
- **[MUST]** A security zone concept including associated protective measures based on the requirements for handling information assets is in place.
<!-- REQ 3.1.1-M2 -->
- **[MUST]** The defined protective measures are implemented.
<!-- REQ 3.1.1-M3 -->
- **[MUST]** The code of conduct for security zones is known to all persons involved.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 3.1.1-S1 -->
- **[SHOULD]** Procedures for granting and revoking access rights are established.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 3.1.1-S2 -->
- **[SHOULD]** Policies for visitor management (including registration and escorting of visitors) are defined.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 3.1.1-S3 -->
- **[SHOULD]** Policies for carrying and using mobile IT devices and data media (e.g. registration, labelling obligations) are defined and implemented.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 3.1.1-S4 -->
- **[SHOULD]** Network/infrastructure components (own or customer networks) are protected against unauthorised access.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 3.1.1-S5 -->
- **[SHOULD]** External premises used for storing/processing information assets are taken into account in the zone concept (e.g. storage rooms, workshops, test tracks, data centres).
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 3.1.1-H1 -->
- **[HIGH]** Protective measures against simple eavesdropping and being overlooked are implemented. (C)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.7.1-1 -->
- **[ISO A.7.1]** Security perimeters are defined and used to protect areas containing information and assets.
<!-- REQ A.7.2-1 -->
- **[ISO A.7.2]** Secure entry controls and entry points are established to restrict access to authorised persons.
<!-- REQ A.7.3-1 -->
- **[ISO A.7.3]** Physical security for offices, rooms and facilities is designed and implemented.
<!-- REQ A.7.4-1 -->
- **[ISO A.7.4]** Premises are continuously monitored for unauthorised physical access.
<!-- REQ A.7.6-1 -->
- **[ISO A.7.6]** Measures for working in secure areas are defined and implemented.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 3.1.1 -->
A security zone concept (BL-PHY-01) with implemented protective measures and a known code of conduct is in place; access rights are granted on a needs-oriented basis via {{TOOL_TICKET}}, documented and revoked when no longer needed (BL-PHY-02, process see {{LINK:VA-17}}). Visitor management, rules for mobile devices, protection of network/infrastructure components and external premises are taken into account.
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 3.1.1-elev -->
Where the protection need is high, additional protective measures against simple eavesdropping and being overlooked are implemented.
{{/if}}
<!-- Scope-Hinweis (E2): ISA 3.1.2 ist in VDA-ISA 2027 deprecated; ISA 3.1.3 existiert nicht.
Daher kein Abschnitt/REQ/IMPL für 3.1.2/3.1.3 in R07 und mapping.json. -->
## 4. Binding nature
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_IT_LEAD}}.
## 5. Roles and responsibilities
| Role | Responsibility in this policy |
|-------|-------------------------------------|
| {{ROLE_IT_LEAD}} | Zones, access, utilities |
| {{ROLE_ISB}} | Specifications |
## 6. Review and update
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_IT_LEAD}} and approved by {{ROLE_MANAGEMENT}}.
## 7. Evidence
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
## 8. Related documents
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- Further: {{LINK:R02}}, {{LINK:R06}}
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->
<!-- FW:ISO-SECTION-START -->
{{#if FLAG_FW_ISO27001}}
### 3.2 Environmental protection, utilities, cabling and maintenance
*Requirement reference:* ISO/IEC 27001 A.7.5, A.7.8, A.7.11, A.7.12, A.7.13
**Requirement**
<!-- REQ A.7.5-1 -->
- **[ISO A.7.5]** Protection against physical and environmental threats is designed and implemented.
<!-- REQ A.7.8-1 -->
- **[ISO A.7.8]** Equipment is sited securely and protected.
<!-- REQ A.7.11-1 -->
- **[ISO A.7.11]** Facilities are protected against failure and disruption of supporting utilities such as power and air conditioning.
<!-- REQ A.7.12-1 -->
- **[ISO A.7.12]** Power and data cabling is protected against interception, interference and damage.
<!-- REQ A.7.13-1 -->
- **[ISO A.7.13]** Equipment is maintained properly to ensure availability and integrity.
**Implementation at {{ORG_NAME}}**
<!-- IMPL ISO-PHY-UMWELT -->
Sites and technical facilities are protected against physical and environmental threats (BL-PHY-03): early fire detection, protection against water and moisture, temperature and humidity monitoring in technical rooms as well as consideration of site-specific hazards. Equipment is sited so that observation, unauthorised access and environmental risks are minimised. Power and air conditioning for critical systems are designed to be uninterruptible and are tested regularly. Power and data cabling is protected against damage and unauthorised access and is documented. Equipment is maintained according to the manufacturer's specifications; maintenance is carried out only by authorised personnel, is planned and recorded, and is supervised where performed externally.
{{/if}}
<!-- FW:ISO-SECTION-END -->
<!-- FW:ISO-SECTION-START -->
{{#if FLAG_FW_ISO27001}}
### 3.3 Clear desk and screen lock
*Requirement reference:* ISO/IEC 27001 A.7.7
**Requirement**
<!-- REQ A.7.7-1 -->
- **[ISO A.7.7]** Rules for a clear desk and locked screens are defined and implemented.
**Implementation at {{ORG_NAME}}**
<!-- IMPL ISO-PHY-CLEARDESK -->
Binding rules apply for a clear desk and locked screens (BL-PHY-04): protected documents and media are locked away when unattended; screens are locked when leaving the workplace and lock automatically after {{SESSION_TIMEOUT}}. Printouts are collected immediately and documents no longer required are destroyed according to their protection needs (BL-DEL-01). The rules also apply when working from home and at mobile workplaces ({{LINK:R06}}); compliance is checked on a sample basis.
{{/if}}
<!-- FW:ISO-SECTION-END -->
@@ -0,0 +1,314 @@
# Policy Identity and Access Management
| Document information | Value |
|-----------------------|------|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_IT_LEAD}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## 1. Purpose
This policy governs means of identification, secure log-on, account management as well as the granting and control of access rights. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
## 2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
## 3. Requirements and implementation
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
### 3.1 Handling of means of identification
<!-- FW:REF-START ORIG:(ISA 4.1.1) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 4.1.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.16{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 4.1.1-M1 -->
- **[MUST]** The requirements for handling means of identification throughout the entire lifecycle are determined and met; the relevant aspects are taken into account.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 4.1.1-S1 -->
- **[SHOULD]** Means of identification can only be created under controlled conditions.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 4.1.1-H1 -->
- **[HIGH]** A strategy for blocking or invalidating means of identification in the event of loss is prepared and, as far as possible, implemented. (C, I, A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.16-1 -->
- **[ISO A.5.16]** The full life cycle of identities is managed.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 4.1.1 -->
Means of identification (user IDs, tokens, certificates) are assigned throughout the lifecycle uniquely to a person and under controlled conditions via the central directory ({{TOOL_IAM}}); issuance, withdrawal and blocking are requested, approved and documented in {{TOOL_TICKET}} (BL-IAM-07, see {{LINK:VA-03}}).
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 4.1.1-elev -->
Where the protection need is high, an implemented strategy for blocking/invalidating means of identification in the event of loss is in place.
{{/if}}
### 3.2 Secure log-on
<!-- FW:REF-START ORIG:(ISA 4.1.2) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 4.1.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.5{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 4.1.2-M1 -->
- **[MUST]** The user authentication procedures are selected on the basis of a risk assessment; possible attack scenarios (e.g. direct reachability via the internet) have been taken into account.
<!-- REQ 4.1.2-M2 -->
- **[MUST]** State-of-the-art user authentication procedures are applied.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 4.1.2-S1 -->
- **[SHOULD]** The authentication procedures are defined and implemented on the basis of business and security requirements.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 4.1.2-S2 -->
- **[SHOULD]** Users are authenticated at least by strong passwords in line with established and recognised practices.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 4.1.2-S3 -->
- **[SHOULD]** For privileged user accounts, higher-grade procedures are used (e.g. privileged access management, two-factor authentication).
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 4.1.2-H1 -->
- **[HIGH]** Depending on the risk assessment, authentication and access control are strengthened by supplementary measures (e.g. continuous access monitoring, strong authentication, automatic log-off, lock upon inactivity, brute-force prevention). (C, I, A)
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 4.1.2-V1 -->
- **[VERY HIGH]** Before accessing data with a very high protection need, users are authenticated by means of strong authentication (e.g. two-factor) in line with the state of the art. (C, I)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.8.5-1 -->
- **[ISO A.8.5]** Secure authentication technologies and procedures are used on the basis of the access restrictions and the access control policy.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 4.1.2 -->
The authentication procedures are selected on a risk basis and correspond to the state of the art; password requirements per BL-IAM-01 (at least {{PW_MIN_LENGTH}} characters, {{PW_COMPLEXITY}}, {{PW_ROTATION}}) are enforced via the central directory ({{TOOL_IAM}}). For remote access, administrative access and cloud services, MFA (BL-IAM-02) is enforced via {{TECH_MFA}}; privileged accounts use higher-grade procedures (PAM).
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 4.1.2-elev -->
Where the protection need is high, authentication/access control are strengthened by supplementary measures (access monitoring, auto-logout BL-IAM-03, lock BL-IAM-04, brute-force protection). {{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, access is only granted after strong authentication (two-factor).{{/if}}
{{/if}}
### 3.3 User accounts and log-on information
<!-- FW:REF-START ORIG:(ISA 4.1.3) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 4.1.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.17{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 4.1.3-M1 -->
- **[MUST]** The creation, modification and deletion of user accounts is carried out.
<!-- REQ 4.1.3-M2 -->
- **[MUST]** Unique and personalised user accounts are used.
<!-- REQ 4.1.3-M3 -->
- **[MUST]** The use of shared accounts is regulated (e.g. limited to cases where traceability is dispensable).
<!-- REQ 4.1.3-M4 -->
- **[MUST]** User accounts are deactivated immediately after the user leaves (e.g. upon end of contract).
<!-- REQ 4.1.3-M5 -->
- **[MUST]** User accounts are reviewed regularly.
<!-- REQ 4.1.3-M6 -->
- **[MUST]** The log-on information is provided to the user in a secure manner.
<!-- REQ 4.1.3-M7 -->
- **[MUST]** A policy for handling log-on information is defined and implemented; the relevant aspects are taken into account.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 4.1.3-S1 -->
- **[SHOULD]** A base account with minimal access rights and functionalities exists and is used.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 4.1.3-S2 -->
- **[SHOULD]** Default accounts and passwords preconfigured by the manufacturer are deactivated (e.g. blocking or password change).
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 4.1.3-S3 -->
- **[SHOULD]** User accounts are created or authorised by the responsible body.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 4.1.3-S4 -->
- **[SHOULD]** The creation of user accounts is subject to an approval process (four-eyes principle).
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 4.1.3-S5 -->
- **[SHOULD]** User accounts of service providers are deactivated after completion of their task.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 4.1.3-S6 -->
- **[SHOULD]** Deadlines for deactivating and deleting user accounts are defined.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 4.1.3-S7 -->
- **[SHOULD]** The use of default passwords is prevented technically.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 4.1.3-S8 -->
- **[SHOULD]** In the case of strong authentication, the use of the medium (e.g. possession factor) is secure.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 4.1.3-S9 -->
- **[SHOULD]** User accounts are reviewed regularly; this also includes accounts in customers' IT systems.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 4.1.3-S10 -->
- **[SHOULD]** Interactive log-on for service accounts (technical accounts) is prevented technically.
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.17-1 -->
- **[ISO A.5.17]** Allocation and management of authentication information is controlled by a suitable management process.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 4.1.3 -->
User accounts are managed via a defined lifecycle (joiner/mover/leaver) (see {{LINK:VA-03}}) uniquely personalised in the central directory ({{TOOL_IAM}}); triggers are {{TOOL_TICKET}} requests from HR/manager notifications. Accounts of leavers are deactivated without delay, accounts are reviewed regularly (including in customer systems), shared accounts are regulated. Log-on information is provided securely; default accounts/passwords are deactivated, base accounts with minimal rights are used, creation follows the four-eyes principle, and interactive log-on for technical accounts is prevented.
### 3.4 Access rights
<!-- FW:REF-START ORIG:(ISA 4.2.1) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 4.2.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.15, A.5.18, A.8.2, A.8.3, A.8.18{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 4.2.1-M1 -->
- **[MUST]** The requirements for managing access rights (authorisation) are determined and met; the relevant aspects are taken into account.
<!-- REQ 4.2.1-M2 -->
- **[MUST]** The access rights granted for normal and privileged user accounts as well as technical accounts are reviewed regularly, also in customers' IT systems.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 4.2.1-S1 -->
- **[SHOULD]** Strategies for authorising access to information are prepared.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 4.2.1-S2 -->
- **[SHOULD]** Authorisation roles are used.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 4.2.1-S3 -->
- **[SHOULD]** Rights are granted according to the need-to-use principle and in line with role and/or area of responsibility.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 4.2.1-S4 -->
- **[SHOULD]** Normal user accounts do not receive privileged access rights.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 4.2.1-S5 -->
- **[SHOULD]** The user's access rights are updated after a change in their responsibilities.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 4.2.1-H1 -->
- **[HIGH]** The access rights are approved by the responsible internal information officer. (C, I, A)
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 4.2.1-V1 -->
- **[VERY HIGH]** Information is stored encrypted at content level (e.g. file level) to prevent unauthorised access (including by privileged users). Where encryption is not feasible, equivalent measures apply. (C)
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 4.2.1-V2 -->
- **[VERY HIGH]** Existing access rights are reviewed at shorter intervals (e.g. quarterly). (C)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.15-1 -->
- **[ISO A.5.15]** Rules to control physical and logical access to information and assets are established and implemented on the basis of business and information security requirements.
<!-- REQ A.5.18-1 -->
- **[ISO A.5.18]** Access rights are provisioned, reviewed, modified and removed in accordance with the access control policy.
<!-- REQ A.8.2-1 -->
- **[ISO A.8.2]** The allocation and use of privileged access rights is restricted and closely managed.
<!-- REQ A.8.3-1 -->
- **[ISO A.8.3]** Access to information and application functions is restricted in accordance with the access control policy.
<!-- REQ A.8.18-1 -->
- **[ISO A.8.18]** The use of utility programs capable of overriding system and application controls is restricted and tightly controlled.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 4.2.1 -->
Access rights are granted according to the least-privilege principle (need-to-know/least privilege) on a role basis (RBAC) via the central directory ({{TOOL_IAM}}); request, technical review and approval take place in {{TOOL_TICKET}} (see {{LINK:VA-03}}). Rights are updated or revoked upon change/removal and recertified at least {{RECERT_FREQ}} (BL-IAM-05), also in customer systems; default accounts do not receive privileged rights.
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 4.2.1-elev -->
Where the protection need is high, access rights are approved by the responsible internal information officer. {{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, information is stored with content-level encryption (protection also against privileged users) and access rights are reviewed at shorter intervals (e.g. quarterly).{{/if}}
{{/if}}
## 4. Binding nature
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_IT_LEAD}}.
## 5. Roles and responsibilities
| Role | Responsibility in this policy |
|-------|-------------------------------------|
| {{ROLE_IT_LEAD}} | Technical implementation of IAM |
| Business units | Approval of authorisations |
| {{ROLE_ISB}} | Monitoring |
## 6. Review and update
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_IT_LEAD}} and approved by {{ROLE_MANAGEMENT}}.
## 7. Evidence
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
## 8. Related documents
- Associated procedures: {{LINK:VA-03}}
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- Further: {{LINK:R02}}, {{LINK:R05}}, {{LINK:R10}}
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->
@@ -0,0 +1,156 @@
# Policy Cryptography and Transmission Policy
| Document information | Value |
|-----------------------|------|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_IT_LEAD}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## 1. Purpose
This policy governs cryptographic procedures, key management and protection during information transmission. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
## 2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
## 3. Requirements and implementation
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
### 3.1 Use of cryptographic procedures
<!-- FW:REF-START ORIG:(ISA 5.1.1) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.1.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.24{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 5.1.1-M1 -->
- **[MUST]** All cryptographic procedures used (e.g. encryption, signature, hash algorithms, protocols) provide the security required in the respective field of application according to a recognised industry standard, as far as legally possible.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.1.1-S1 -->
- **[SHOULD]** A concept for the use of cryptography is defined and implemented; the relevant aspects are taken into account.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.1.1-H1 -->
- **[HIGH]** Requirements for key sovereignty (in particular in the case of external processing) are determined and met. (C, I)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.8.24-1 -->
- **[ISO A.8.24]** Rules for the effective use of cryptography, including key management, are defined and implemented.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 5.1.1 -->
The permissible procedures and key lengths per BL-CRY-02 ({{CRYPTO_ALGO}}) correspond to the recognised industry standard and are prescribed; outdated procedures are prohibited. A cryptography concept is documented (see {{LINK:VA-07}}), and keys are securely managed throughout their lifecycle (BL-CRY-05).
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 5.1.1-elev -->
Where the protection need is high, requirements for key sovereignty (in particular in the case of external processing) are determined and met.
{{/if}}
### 3.2 Protection during information transmission
<!-- FW:REF-START ORIG:(ISA 5.1.2) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.1.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.14{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 5.1.2-M1 -->
- **[MUST]** The network services used for transmitting information are identified and documented.
<!-- REQ 5.1.2-M2 -->
- **[MUST]** Policies and procedures in line with the classification requirements for the use of network services are defined and implemented.
<!-- REQ 5.1.2-M3 -->
- **[MUST]** Measures to protect transmitted content against unauthorised access are implemented.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.1.2-S1 -->
- **[SHOULD]** Measures to ensure correct addressing and correct transmission of information are implemented.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.1.2-S2 -->
- **[SHOULD]** Electronic data exchange takes place using content or transport encryption in line with the respective classification.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.1.2-S3 -->
- **[SHOULD]** Remote access connections to the organisation's network have appropriate security features; the relevant aspects are taken into account.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.1.2-H1 -->
- **[HIGH]** Information is transmitted encrypted (at least transport encryption) or protected by equivalently effective measures. (C)
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 5.1.2-V1 -->
- **[VERY HIGH]** Information is transmitted with content encryption. (C)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.14-1 -->
- **[ISO A.5.14]** Rules, procedures and agreements for the secure transfer of information are established for all transfer channels in use.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 5.1.2 -->
The network services used are identified and documented in the network/network services register ({{LINK:REG-NET}}); policies/procedures in line with the classification are implemented. Information is protected during transmission in accordance with the protection need (at least {{TLS_MIN}}, BL-CRY-01), correct addressing is ensured and remote access is safeguarded; rules for email/file encryption are defined (BL-CRY-04, cryptography/key management see {{LINK:VA-07}}).
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 5.1.2-elev -->
Where the protection need is high, information is transmitted at least transport-encrypted or protected equivalently; {{#if FLAG_VERY_HIGH_PROTECTION}}where the protection need is very high, content encryption is applied.{{/if}}
{{/if}}
## 4. Binding nature
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_IT_LEAD}}.
## 5. Roles and responsibilities
| Role | Responsibility in this policy |
|-------|-------------------------------------|
| {{ROLE_IT_LEAD}} | Procedures/keys |
| {{ROLE_ISB}} | Permissible algorithms |
## 6. Review and update
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_IT_LEAD}} and approved by {{ROLE_MANAGEMENT}}.
## 7. Evidence
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
## 8. Related documents
- Associated procedures: {{LINK:VA-07}}
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- Further: {{LINK:R08}}, {{LINK:R10}}, {{LINK:R12}}
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->
@@ -0,0 +1,598 @@
# Policy Operational Security
| Document information | Value |
|-----------------------|------|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_IT_LEAD}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## 1. Purpose
This policy governs secure IT operations: change, environment separation, malware protection, logging, vulnerabilities, technical review, network security as well as data backup. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
## 2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
## 3. Requirements and implementation
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
### 3.1 Change management (change)
<!-- FW:REF-START ORIG:(ISA 5.2.1) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.2.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.9, A.8.32{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 5.2.1-M1 -->
- **[MUST]** Information security requirements for changes to the organisation, business processes and IT systems are determined and met.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.1-S1 -->
- **[SHOULD]** A formal approval procedure is established.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.1-S2 -->
- **[SHOULD]** The possible effects of changes on information security are assessed.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.1-S3 -->
- **[SHOULD]** Changes with an effect on information security are planned and tested.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.1-S4 -->
- **[SHOULD]** Fallback procedures in the event of errors are taken into account.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.2.1-H1 -->
- **[HIGH]** Compliance with the information security requirements is verified during and after the changes. (C, I, A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.8.9-1 -->
- **[ISO A.8.9]** Configurations of hardware, software, services and networks are established, documented, implemented, monitored and reviewed.
<!-- REQ A.8.32-1 -->
- **[ISO A.8.32]** Changes to information processing facilities and systems are subject to change management.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 5.2.1 -->
Changes go through a formal change procedure (see {{LINK:VA-04}}) with request, impact/risk assessment, planning, testing, approval, rollback plan and documentation in {{TOOL_TICKET}} (BL-OPS-09); information security requirements are determined and met.
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 5.2.1-elev -->
Where the protection need is high, compliance with the information security requirements is verified during and after the change.
{{/if}}
### 3.2 Separation of development, test and production systems
<!-- FW:REF-START ORIG:(ISA 5.2.2) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.2.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.31{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 5.2.2-M1 -->
- **[MUST]** The IT systems have been subjected to a risk assessment to determine the need to separate them into development, test and production systems.
<!-- REQ 5.2.2-M2 -->
- **[MUST]** A segmentation is implemented on the basis of the results of the risk analysis.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.2-S1 -->
- **[SHOULD]** The requirements for development and test environments are determined and met; the relevant aspects are taken into account.
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.8.31-1 -->
- **[ISO A.8.31]** Development, test and production environments are separated and protected.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 5.2.2 -->
On the basis of a risk assessment, development, test and production are operated separately and segmented; requirements for development/test environments are determined and met, and production data is used there only in anonymised/pseudonymised form.
### 3.3 Protection against malware
<!-- FW:REF-START ORIG:(ISA 5.2.3) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.2.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.7, A.8.23{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 5.2.3-M1 -->
- **[MUST]** Requirements for protection against malware are determined.
<!-- REQ 5.2.3-M2 -->
- **[MUST]** Technical and organisational measures for protection against malware are defined and implemented.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.3-S1 -->
- **[SHOULD]** Unnecessary network services are deactivated.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.3-S2 -->
- **[SHOULD]** Access to network services is limited to what is necessary through appropriate protective measures.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.3-S3 -->
- **[SHOULD]** Protective software against malware is installed and updated automatically at regular intervals (e.g. virus scanner).
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.3-S4 -->
- **[SHOULD]** Received files and software are automatically checked for malware before execution (on-access scan).
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.3-S5 -->
- **[SHOULD]** The entire data stock of all systems is checked for malware regularly.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.3-S6 -->
- **[SHOULD]** Data transmitted via central gateways (e.g. email, internet, external networks) is automatically checked by protective software.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.3-S7 -->
- **[SHOULD]** Measures preventing protective software from being deactivated or modified by users are defined and implemented.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.3-S8 -->
- **[SHOULD]** For IT systems without protective software, alternative measures are implemented (e.g. special resilience, few services, no active users, network isolation).
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.8.7-1 -->
- **[ISO A.8.7]** Protection against malware is implemented and supported by appropriate user awareness.
<!-- REQ A.8.23-1 -->
- **[ISO A.8.23]** Access to external websites is managed to reduce exposure to malicious content.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 5.2.3 -->
Malware protection is implemented via {{TECH_MALWARE}} on all endpoints and servers (BL-OPS-03); signatures/engines update themselves {{MALWARE_UPDATE}}, on-access and regular full scans as well as gateway checks (email/internet) are active. Unnecessary network services are deactivated, access is limited, and deactivating the protective software is prevented; for systems without protective software, alternative measures apply (isolation).
### 3.4 Logging and evaluation
<!-- FW:REF-START ORIG:(ISA 5.2.4) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.2.4{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.15, A.8.16{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 5.2.4-M1 -->
- **[MUST]** Information security requirements for handling event logs are determined and met.
<!-- REQ 5.2.4-M2 -->
- **[MUST]** Security-relevant requirements for logging the activities of administrators and users are determined and met.
<!-- REQ 5.2.4-M3 -->
- **[MUST]** The IT systems used are assessed with regard to the need for logging.
<!-- REQ 5.2.4-M4 -->
- **[MUST]** When external IT services are used, information on the monitoring options is obtained and taken into account in the assessment.
<!-- REQ 5.2.4-M5 -->
- **[MUST]** Event logs are checked regularly for policy violations and conspicuous problems, in compliance with the permissible legal and organisational requirements.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.4-S1 -->
- **[SHOULD]** A procedure for escalating relevant events to the responsible body is defined and established.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.4-S2 -->
- **[SHOULD]** Event logs (content and metadata) are protected against modification (e.g. by a dedicated environment).
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.4-S3 -->
- **[SHOULD]** Appropriate monitoring and recording of all information-security-relevant actions in the network is established.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.2.4-H1 -->
- **[HIGH]** Security-relevant requirements for handling event logs, e.g. contractual requirements, are determined and implemented. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.2.4-H2 -->
- **[HIGH]** Events relating to the establishment and termination of remote access sessions (e.g. remote maintenance) are logged. (C, I, A)
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 5.2.4-V1 -->
- **[VERY HIGH]** Logging of every access to data with a very high protection need, as far as technically feasible and legally/organisationally permissible. (C, I)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.8.15-1 -->
- **[ISO A.8.15]** Logs of activities, exceptions, faults and events are produced, stored, protected and analysed.
<!-- REQ A.8.16-1 -->
- **[ISO A.8.16]** Networks, systems and applications are monitored for anomalous behaviour and potential incidents are evaluated.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 5.2.4 -->
Security-relevant events (incl. administrator/user activities) are logged centrally via {{TECH_SIEM}} according to determined and assessed requirements and evaluated regularly for violations (BL-OPS-04); for external services, the monitoring options are taken into account. Logs are protected against tampering, retention {{LOG_RETENTION}}, and an escalation procedure is established (see {{LINK:VA-13}}).
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 5.2.4-elev -->
Where the protection need is high, additional (e.g. contractual) logging requirements are implemented and remote access sessions are logged. {{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, every access to corresponding data is logged, as far as technically/legally permissible.{{/if}}
{{/if}}
### 3.5 Handling of vulnerabilities
<!-- FW:REF-START ORIG:(ISA 5.2.5) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.2.5{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.8{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 5.2.5-M1 -->
- **[MUST]** Information about technical vulnerabilities of the IT systems used is collected (e.g. manufacturer information, system audits, CVE database).
<!-- REQ 5.2.5-M2 -->
- **[MUST]** Potentially affected IT systems and software are identified and the risk caused by the vulnerability is assessed.
<!-- REQ 5.2.5-M3 -->
- **[MUST]** Risks arising from vulnerabilities are treated.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.5-S1 -->
- **[SHOULD]** Appropriate patch management is defined and implemented (e.g. patch testing and installation).
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.5-S2 -->
- **[SHOULD]** Risk-mitigating measures are implemented where necessary.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.5-S3 -->
- **[SHOULD]** The successful installation of patches is verified in a suitable manner.
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.8.8-1 -->
- **[ISO A.8.8]** Information on technical vulnerabilities is obtained, exposure is evaluated and appropriate measures are taken.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 5.2.5 -->
Vulnerability information is collected (manufacturer information, CVE, scans BL-OPS-02), affected systems are identified, the risk is assessed and treated on a risk basis according to BL-OPS-01 via patch/change management (see {{LINK:VA-06}}) (critical {{PATCH_SLA_CRIT}}); the successful installation is verified and tracked in {{TOOL_TICKET}}, and risk-mitigating measures apply where necessary.
### 3.6 Technical review of IT systems
<!-- FW:REF-START ORIG:(ISA 5.2.6) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.2.6{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.34{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 5.2.6-M1 -->
- **[MUST]** Requirements for the review (audit) of IT systems or services are determined.
<!-- REQ 5.2.6-M2 -->
- **[MUST]** The scope of the system review is defined in good time.
<!-- REQ 5.2.6-M3 -->
- **[MUST]** System or service reviews are coordinated with the operators and users of the IT systems/services.
<!-- REQ 5.2.6-M4 -->
- **[MUST]** The results of system/service reviews are stored in a traceable manner and reported to the responsible management.
<!-- REQ 5.2.6-M5 -->
- **[MUST]** Measures are derived from the results and implemented within an appropriate period.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.6-S1 -->
- **[SHOULD]** System and service reviews are planned taking possible security risks (e.g. disruptions) into account.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.6-S2 -->
- **[SHOULD]** Regular system or service reviews are carried out; the relevant aspects are taken into account.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.6-S3 -->
- **[SHOULD]** Within an appropriate period after completion of the review, a report is prepared.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.2.6-H1 -->
- **[HIGH]** For critical IT systems/services, additional review requirements have been identified and are met (e.g. service-specific tests/tools and/or manual penetration tests, risk-based intervals). (A)
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 5.2.6-V1 -->
- **[VERY HIGH]** IT systems and services are scanned regularly for vulnerabilities. For systems/services that cannot be scanned, suitable protective measures are to be implemented. (C, I, A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.8.34-1 -->
- **[ISO A.8.34]** Audit tests and similar activities on operational systems are planned and agreed to avoid disruption.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 5.2.6 -->
Requirements and scope of technical reviews are determined and coordinated with operators/users; systems are configured according to hardening requirements (BL-OPS-07, e.g. CIS benchmarks) and reviewed on a risk basis (see {{LINK:VA-06}}). Results are stored in a traceable manner, reported to management, and measures are implemented on time.
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 5.2.6-elev -->
Where the protection need is high, additional reviews (penetration tests {{PENTEST_FREQ}}, BL-OPS-08) are carried out for critical systems. {{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, systems are scanned regularly for vulnerabilities, or systems that cannot be scanned are protected by suitable measures.{{/if}}
{{/if}}
### 3.7 Network security
<!-- FW:REF-START ORIG:(ISA 5.2.7) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.2.7{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.20, A.8.22{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 5.2.7-M1 -->
- **[MUST]** Requirements for the management and control of networks are determined and met.
<!-- REQ 5.2.7-M2 -->
- **[MUST]** Requirements for network segmentation are determined and met.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.7-S1 -->
- **[SHOULD]** Procedures for the management and control of networks are defined.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.7-S2 -->
- **[SHOULD]** For a risk-based network segmentation, the relevant aspects are taken into account.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.2.7-H1 -->
- **[HIGH]** Extended requirements for the management and control of networks are determined and implemented. (C, I, A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.8.20-1 -->
- **[ISO A.8.20]** Networks and network devices are secured, managed and controlled to protect information.
<!-- REQ A.8.22-1 -->
- **[ISO A.8.22]** Groups of information services, users and systems are segregated in networks.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 5.2.7 -->
The network is segmented on a risk basis according to the protection need (BL-NET-01), access-controlled and secured externally via a firewall (default deny, BL-NET-02); management/control procedures and an up-to-date network plan/segmentation concept are maintained in the network/network services register ({{LINK:REG-NET}}).{{#if FLAG_OT_USED}} Production/OT networks are separated from office networks and specially secured.{{/if}}
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 5.2.7-elev -->
Where the protection need is high, extended requirements for network management and control are determined and implemented.
{{/if}}
### 3.8 Data backup and recovery
<!-- FW:REF-START ORIG:(ISA 5.2.9) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.2.9{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.13{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 5.2.9-M1 -->
- **[MUST]** Backup concepts exist for relevant IT systems. Appropriate protective measures for the confidentiality, integrity and availability of the backups are taken into account.
<!-- REQ 5.2.9-M2 -->
- **[MUST]** Recovery concepts exist for relevant IT services.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.9-S1 -->
- **[SHOULD]** For each relevant IT service, a backup and recovery concept exists. Dependencies between IT services and the recovery sequence are taken into account.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.2.9-H1 -->
- **[HIGH]** Backup and recovery concepts are reviewed methodically at regular intervals. (A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.2.9-H2 -->
- **[HIGH]** The fundamental recoverability is taken into account and tested (e.g. sample tests, test systems). (I, A)
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 5.2.9-V1 -->
- **[VERY HIGH]** (Additional) backups are carried out via offline procedures, immutable backups or an isolated IAM solution. (I, A)
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 5.2.9-V2 -->
- **[VERY HIGH]** Recovery procedures are tested technically and methodically at regular intervals. (I, A)
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 5.2.9-V3 -->
- **[VERY HIGH]** Geographical redundancy is taken into account in backup and recovery concepts. (A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.8.13-1 -->
- **[ISO A.8.13]** Backup copies of information, software and systems are created in accordance with the backup concept and tested regularly.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 5.2.9 -->
Backup and recovery concepts for relevant IT services exist (protection of confidentiality/integrity/availability, dependencies and sequence taken into account); backups are performed according to the scheme {{BACKUP_SCHEME}} via {{TECH_BACKUP}} (BL-OPS-05), retention {{BACKUP_RETENTION}}, recovery regulated and tested (see {{LINK:VA-05}}).
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 5.2.9-elev -->
Where the protection need is high, concepts are reviewed methodically and recoverability is tested. {{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, additional offline/immutable backups, methodical technical restore tests and geographical redundancy are carried out.{{/if}}
{{/if}}
## 4. Binding nature
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_IT_LEAD}}.
## 5. Roles and responsibilities
| Role | Responsibility in this policy |
|-------|-------------------------------------|
| {{ROLE_IT_LEAD}} | Secure IT operations |
| {{ROLE_ISB}} | Monitoring |
## 6. Review and update
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_IT_LEAD}} and approved by {{ROLE_MANAGEMENT}}.
## 7. Evidence
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
## 8. Related documents
- Associated procedures: {{LINK:VA-04}}, {{LINK:VA-05}}, {{LINK:VA-06}}, {{LINK:VA-13}}
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- Further: {{LINK:R04}}, {{LINK:R08}}, {{LINK:R11}}
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->
<!-- FW:ISO-SECTION-START -->
{{#if FLAG_FW_ISO27001}}
### 3.9 Threat intelligence
*Requirement reference:* ISO/IEC 27001 A.5.7
**Requirement**
<!-- REQ A.5.7-1 -->
- **[ISO A.5.7]** Information on threats is collected and analysed to produce and use threat intelligence.
**Implementation at {{ORG_NAME}}**
<!-- IMPL ISO-THREATINTEL -->
Information on threats is obtained regularly from named sources ({{THREAT_INTEL_SOURCES}}) and evaluated by {{ROLE_IT_LEAD}} for relevance to the organisation's own systems and services. Relevant findings lead to actions in vulnerability and patch management ({{LINK:VA-06}}), to adjustments of monitoring ({{LINK:VA-13}}) or to a new risk assessment. Evaluation and resulting actions are documented in {{TOOL_TICKET}}.
{{/if}}
<!-- FW:ISO-SECTION-END -->
<!-- FW:ISO-SECTION-START -->
{{#if FLAG_FW_ISO27001}}
### 3.10 Documented operating procedures
*Requirement reference:* ISO/IEC 27001 A.5.37
**Requirement**
<!-- REQ A.5.37-1 -->
- **[ISO A.5.37]** Operating procedures for information processing facilities are documented and made available to the personnel concerned.
**Implementation at {{ORG_NAME}}**
<!-- IMPL ISO-BETRIEBSABLAEUFE -->
Operating procedures for information processing facilities are documented and accessible to the personnel who carry them out. They cover commissioning and configuration, operation and monitoring, backup, handling of faults, maintenance and decommissioning. The documentation is updated through change management (BL-OPS-09) whenever changes occur and is checked for currency at least {{POLICY_REVIEW_CYCLE}}. Responsible: {{ROLE_IT_LEAD}}.
{{/if}}
<!-- FW:ISO-SECTION-END -->
<!-- FW:ISO-SECTION-START -->
{{#if FLAG_FW_ISO27001}}
### 3.11 Capacity management
*Requirement reference:* ISO/IEC 27001 A.8.6
**Requirement**
<!-- REQ A.8.6-1 -->
- **[ISO A.8.6]** Resources are monitored and capacity is adjusted to current and expected demand.
**Implementation at {{ORG_NAME}}**
<!-- IMPL ISO-KAPAZITAET -->
The utilisation of the relevant resources — compute, memory, storage, network bandwidth, licences and staffing in IT operations — is monitored {{CAPACITY_REVIEW_FREQ}} (BL-OPS-11). Exceeded thresholds raise an alert; future demand is taken into account in projects and significant changes. Capacity constraints that affect the availability requirements are recorded and treated as a risk.
{{/if}}
<!-- FW:ISO-SECTION-END -->
<!-- FW:ISO-SECTION-START -->
{{#if FLAG_FW_ISO27001}}
### 3.12 Data leakage prevention
*Requirement reference:* ISO/IEC 27001 A.8.12
**Requirement**
<!-- REQ A.8.12-1 -->
- **[ISO A.8.12]** Measures to prevent data leakage are applied to systems, networks and devices that process sensitive information.
**Implementation at {{ORG_NAME}}**
<!-- IMPL ISO-DLP -->
For systems, networks and devices that process protected information, measures against unauthorised outflow are in place (BL-OPS-12); at least {{DLP_SCOPE}} are covered. The measures follow the classification ({{LINK:R02}}): rules for disclosure, control of transfer channels, restriction of removable media (BL-EP-03) as well as logging and analysis of conspicuous transfers (BL-OPS-04). Detected violations are handled as security events ({{LINK:VA-01}}); where analysis relates to individuals, co-determination rights are observed.
{{/if}}
<!-- FW:ISO-SECTION-END -->
<!-- FW:ISO-SECTION-START -->
{{#if FLAG_FW_ISO27001}}
### 3.13 Clock synchronisation
*Requirement reference:* ISO/IEC 27001 A.8.17
**Requirement**
<!-- REQ A.8.17-1 -->
- **[ISO A.8.17]** System clocks are synchronised to approved time sources.
**Implementation at {{ORG_NAME}}**
<!-- IMPL ISO-ZEITSYNC -->
The system clocks of all logging systems are synchronised to {{NTP_SOURCES}} (BL-OPS-10). Deviations are monitored and reported. A uniform time base and time zone is a prerequisite for the analysis of logs ({{LINK:VA-13}}) and for preserving evidence in the event of an incident.
{{/if}}
<!-- FW:ISO-SECTION-END -->
@@ -0,0 +1,219 @@
# Policy Secure System Procurement and Development
| Document information | Value |
|-----------------------|------|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_IT_LEAD}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## 1. Purpose
This policy governs information security in procurement and development, requirements for network services as well as return and secure deletion. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
## 2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
## 3. Requirements and implementation
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
### 3.1 Security in procurement and development
<!-- FW:REF-START ORIG:(ISA 5.3.1) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.3.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.4, A.8.25, A.8.26, A.8.27, A.8.28, A.8.29, A.8.30, A.8.33{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 5.3.1-M1 -->
- **[MUST]** The information security requirements associated with the design and development of an IT service are determined and taken into account.
<!-- REQ 5.3.1-M2 -->
- **[MUST]** The information security requirements associated with the procurement or extension of IT services and components are determined and taken into account.
<!-- REQ 5.3.1-M3 -->
- **[MUST]** Information security requirements in connection with changes to developed IT services are taken into account.
<!-- REQ 5.3.1-M4 -->
- **[MUST]** System acceptance tests are carried out taking the information security requirements into account.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.3.1-S1 -->
- **[SHOULD]** Requirement specifications are created; the relevant aspects are taken into account.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.3.1-S2 -->
- **[SHOULD]** Requirement specifications are checked against the information security requirements.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.3.1-S3 -->
- **[SHOULD]** The IT service is checked for compliance with the specifications before production use.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.3.1-S4 -->
- **[SHOULD]** The use of production data for test purposes is avoided as far as possible (anonymisation/pseudonymisation where applicable); the relevant aspects are taken into account.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.3.1-S5 -->
- **[SHOULD]** Test systems receive protective measures comparable to the production environment when production data is used for testing.
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 5.3.1-V1 -->
- **[VERY HIGH]** The security of purpose-built or substantially adapted software is tested upon commissioning, upon substantial changes or regularly (e.g. penetration test). (C, I, A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.8.4-1 -->
- **[ISO A.8.4]** Read and write access to source code, development tools and software libraries is appropriately managed.
<!-- REQ A.8.25-1 -->
- **[ISO A.8.25]** Rules for a secure development life cycle of software and systems are established and applied.
<!-- REQ A.8.26-1 -->
- **[ISO A.8.26]** Information security requirements are identified, specified and taken into account when developing or acquiring applications.
<!-- REQ A.8.27-1 -->
- **[ISO A.8.27]** Principles for engineering secure systems are established, documented and applied.
<!-- REQ A.8.28-1 -->
- **[ISO A.8.28]** Secure coding principles are applied to software development.
<!-- REQ A.8.29-1 -->
- **[ISO A.8.29]** Security testing is integrated into the development and acceptance process.
<!-- REQ A.8.30-1 -->
- **[ISO A.8.30]** Outsourced system development is directed, monitored and reviewed.
<!-- REQ A.8.33-1 -->
- **[ISO A.8.33]** Test information is selected, protected and managed with care.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 5.3.1 -->
Information security requirements are an integral part of the design, procurement, extension and modification of IT services (security by design); requirement specification, review and acceptance tests under security aspects are carried out following the procedure Secure Procurement/Development & Acceptance ({{LINK:VA-16}}); production deployment only after review in {{TOOL_TICKET}}. Production data in tests is avoided/anonymised, and test systems are appropriately protected.{{#if FLAG_DEV_INHOUSE}} For in-house development, secure coding requirements apply with code reviews and automated security tests (SAST/dependency scan) in accordance with {{LINK:VA-16}}.{{/if}}
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 5.3.1-elev -->
{{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, the security of purpose-built or substantially adapted software is tested upon commissioning, upon substantial changes or regularly (penetration test).{{/if}}
{{/if}}
### 3.2 Requirements for network services
<!-- FW:REF-START ORIG:(ISA 5.3.2) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.3.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.21{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 5.3.2-M1 -->
- **[MUST]** Requirements for the information security of network services are determined and met.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.3.2-S1 -->
- **[SHOULD]** A procedure for securing and using network services is defined and implemented.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.3.2-S2 -->
- **[SHOULD]** The requirements are agreed in the form of SLAs.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.3.2-S3 -->
- **[SHOULD]** Appropriate redundancy solutions are implemented.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.3.2-H1 -->
- **[HIGH]** Procedures for monitoring the quality of network traffic (e.g. traffic flow analyses, availability measurements) are defined and carried out. (A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.8.21-1 -->
- **[ISO A.8.21]** Security mechanisms, service levels and requirements for network services are identified, implemented and monitored.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 5.3.2 -->
For the network services used (internal/external), security requirements are determined, agreed in SLAs and implemented via a procedure; appropriate redundancies are in place.
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 5.3.2-elev -->
Where the protection need is high, procedures for monitoring network traffic quality (traffic flow analyses, availability measurements) are defined and carried out.
{{/if}}
### 3.3 Return and secure deletion
<!-- FW:REF-START ORIG:(ISA 5.3.3) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.3.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.11, A.7.14, A.8.10{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.3.3-S1 -->
- **[SHOULD]** A description of the termination process is in place, adapted to changes and regulated contractually.
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.11-1 -->
- **[ISO A.5.11]** Personnel and external users return all assets in their possession upon termination of employment or contract.
<!-- REQ A.7.14-1 -->
- **[ISO A.7.14]** Equipment containing storage media is securely sanitised before disposal or re-use.
<!-- REQ A.8.10-1 -->
- **[ISO A.8.10]** Information stored in systems and on media is deleted when no longer required.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 5.3.3 -->
Return and secure deletion/destruction of information and assets (upon end of contract, device decommissioning) are regulated according to BL-DEL-01, agreed contractually, adapted to changes and evidenced (deletion log).
## 4. Binding nature
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_IT_LEAD}}.
## 5. Roles and responsibilities
| Role | Responsibility in this policy |
|-------|-------------------------------------|
| {{ROLE_IT_LEAD}} | Procurement/development |
| {{ROLE_ISB}} | Security requirements |
## 6. Review and update
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_IT_LEAD}} and approved by {{ROLE_MANAGEMENT}}.
## 7. Evidence
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
## 8. Related documents
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- Further: {{LINK:R02}}, {{LINK:R10}}, {{LINK:R12}}
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->
@@ -0,0 +1,117 @@
# Policy Cloud, AI and External IT Services
| Document information | Value |
|-----------------------|------|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_ISB}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## 1. Purpose
This policy governs protection in outsourced/shared external IT services (cloud) as well as the use of AI/GenAI services. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
## 2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
## 3. Requirements and implementation
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
### 3.1 Protection in shared external IT services
<!-- FW:REF-START ORIG:(ISA 5.3.4) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.3.4{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.23{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 5.3.4-M1 -->
- **[MUST]** An effective separation (e.g. tenant separation) prevents unauthorised users of other organisations from accessing one's own information.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.3.4-S1 -->
- **[SHOULD]** The provider's separation concept is documented and adapted to changes; the relevant aspects are taken into account.
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.23-1 -->
- **[ISO A.5.23]** Processes for acquisition, use, management and exit of cloud services are established in line with the information security requirements.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 5.3.4 -->
For shared external IT services, effective tenant separation is required and contractually assured; the provider's separation concept is documented and updated upon changes.{{#if FLAG_CLOUD_USED}} Cloud services are assessed before use (protection need, data location/EU, encryption, exit) and approved by {{ROLE_ISB}}; the approvals are maintained in the register of external IT/cloud/AI services ({{LINK:REG-EXT-SERVICES}}) (see {{LINK:VA-11}}).{{/if}}
{{#if FLAG_AI_USED}}
### 3.2 Use of AI/GenAI services (supplement R12, not ISA)
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 5.3.4-KI-M1 -->
- **[MUST]** The use of AI/GenAI services is regulated; only approved services are used.
<!-- REQ 5.3.4-KI-M2 -->
- **[MUST]** The input of confidential or personal information into non-approved AI services is prohibited; the permissible data classes per service are defined.
<!-- REQ 5.3.4-KI-M3 -->
- **[MUST]** For approved AI services, it is clarified and contractually ensured that inputs are not used for training or passed on.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.3.4-KI-S1 -->
- **[SHOULD]** Results of AI services are reviewed before business-critical use (human in the loop); the use of AI is documented and regulatory requirements (e.g. EU AI Act) are taken into account.
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 5.3.4-KI -->
The use of AI/GenAI services is regulated; only services approved by {{ROLE_ISB}} (maintained in the register of external IT/cloud/AI services {{LINK:REG-EXT-SERVICES}}) may be used (see {{LINK:VA-11}}). The permissible data classes per service are defined, and the input of confidential/personal data into non-approved services is prohibited; upon approval, it is contractually ensured that inputs are not used for training or passed on. AI results are reviewed before critical use (human in the loop), the use is documented and the EU AI Act is taken into account.
{{/if}}
## 4. Binding nature
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_ISB}}.
## 5. Roles and responsibilities
| Role | Responsibility in this policy |
|-------|-------------------------------------|
| {{ROLE_ISB}} | Approval/steering |
| {{ROLE_IT_LEAD}} | Technical safeguarding |
| Business units | Use of approved services |
## 6. Review and update
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_ISB}} and approved by {{ROLE_MANAGEMENT}}.
## 7. Evidence
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
## 8. Related documents
- Associated procedures: {{LINK:VA-11}}
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- Further: {{LINK:R09}}, {{LINK:R11}}, {{LINK:R13}}
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->
@@ -0,0 +1,250 @@
# Policy Supplier and Service Provider Management
| Document information | Value |
|-----------------------|------|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_ISB}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## 1. Purpose
This policy governs ensuring information security at suppliers, confidentiality agreements and the delineation of responsibilities. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
## 2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
## 3. Requirements and implementation
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
### 3.1 Information security at suppliers
<!-- FW:REF-START ORIG:(ISA 6.1.1) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 6.1.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.19, A.5.22{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 6.1.1-M1 -->
- **[MUST]** Contractors and partners are subjected to a security risk assessment.
<!-- REQ 6.1.1-M2 -->
- **[MUST]** An appropriate level of information security is ensured through contractual agreements with contractors and partners.
<!-- REQ 6.1.1-M3 -->
- **[MUST]** Where applicable, contractual agreements with clients/customers are passed on to contractors and partners.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 6.1.1-S1 -->
- **[SHOULD]** Contractors and partners are contractually obliged to pass on requirements for an appropriate level of information security to their subcontractors.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 6.1.1-S2 -->
- **[SHOULD]** Performance reports and documents from contractors and partners are reviewed.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 6.1.1-H1 -->
- **[HIGH]** It is demonstrated that the supplier's level of information security is appropriate to the protection need (e.g. reviewed questionnaire/self-disclosure, attestation, certificate, supplier audit). (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 6.1.1-H2 -->
- **[HIGH]** The degree of fulfilment of the required evidence by the supplier is documented, reviewed and monitored regularly and upon changes. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 6.1.1-H3 -->
- **[HIGH]** The supplier's compliance with contractual agreements is checked, documented, reviewed and monitored regularly and upon changes. (C, I, A)
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 6.1.1-V1 -->
- **[VERY HIGH]** The appropriate level of information security should be demonstrated by a third-party audit (an appropriate TISAX label or similar) or an appropriate supplier audit. Without an audit, management must make a risk-based decision to continue; evidence of this decision exists. (C, I, A)
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 6.1.1-V2 -->
- **[VERY HIGH]** Contractual obligations towards customers regarding transparency of supply chain risks are fulfilled. (C, I, A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.19-1 -->
- **[ISO A.5.19]** Processes to manage the information security risks arising from supplier relationships are defined and implemented.
<!-- REQ A.5.22-1 -->
- **[ISO A.5.22]** The information security of supplier services is monitored and reviewed regularly, and changes are managed.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 6.1.1 -->
Contractors/partners are subjected to a security risk assessment (BL-SUP-01) and contractually obliged to an appropriate level of information security (incl. passing on to subcontractors and customer requirements); the supplier register is maintained in the ISMS tool ({{TOOL_NAME}}), and performance reports are reviewed (see {{LINK:VA-10}}).
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 6.1.1-elev -->
Where the protection need is high, the supplier's level of security is demonstrated (self-disclosure/attestation/certificate/audit) and compliance is documented and monitored regularly and upon changes. {{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, the evidence is provided via a third-party audit (TISAX or similar) or a documented risk-based management decision; transparency obligations regarding supply chain risks are fulfilled.{{/if}}
{{/if}}
### 3.2 Confidentiality agreements
<!-- FW:REF-START ORIG:(ISA 6.1.2) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 6.1.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.20{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 6.1.2-M1 -->
- **[MUST]** The confidentiality requirements are determined and met.
<!-- REQ 6.1.2-M2 -->
- **[MUST]** Requirements and procedures for applying confidentiality agreements are known to all persons who pass on information requiring protection.
<!-- REQ 6.1.2-M3 -->
- **[MUST]** Valid confidentiality agreements are concluded before information requiring protection is passed on.
<!-- REQ 6.1.2-M4 -->
- **[MUST]** The requirements and procedures for using confidentiality agreements and for handling information requiring protection are reviewed regularly.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 6.1.2-S1 -->
- **[SHOULD]** Templates for confidentiality agreements are available and checked for legal applicability.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 6.1.2-S2 -->
- **[SHOULD]** Confidentiality agreements cover the persons/organisations involved, the type of information, the subject matter, the period of validity and the responsibilities of the obligated party.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 6.1.2-S3 -->
- **[SHOULD]** Confidentiality agreements contain provisions for handling information requiring protection beyond the contractual relationship.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 6.1.2-S4 -->
- **[SHOULD]** Ways to demonstrate compliance (e.g. review by independent third parties or audit rights) are defined.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 6.1.2-S5 -->
- **[SHOULD]** A process for monitoring the period of validity of temporary confidentiality agreements and for timely renewal is defined and implemented.
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.20-1 -->
- **[ISO A.5.20]** Relevant information security requirements are agreed with each supplier and recorded contractually.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 6.1.2 -->
Confidentiality requirements are determined and known; before information requiring protection is passed on, valid NDAs based on reviewed standard templates (process see {{LINK:VA-10}}) (with parties, type of information, subject matter, validity, responsibilities and post-contractual provisions) are concluded and stored in the ISMS tool. Requirements/procedures and periods of validity are monitored regularly, and ways to demonstrate compliance are defined.
### 3.3 Delineation of responsibilities
<!-- FW:REF-START ORIG:(ISA 6.1.3) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 6.1.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.21{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 6.1.3-M1 -->
- **[MUST]** The IT services concerned are identified.
<!-- REQ 6.1.3-M2 -->
- **[MUST]** The security requirements relevant to the IT service are determined.
<!-- REQ 6.1.3-M3 -->
- **[MUST]** The organisation responsible for implementing the requirement is defined and aware of its responsibility.
<!-- REQ 6.1.3-M4 -->
- **[MUST]** Mechanisms for shared responsibilities are specified and implemented.
<!-- REQ 6.1.3-M5 -->
- **[MUST]** The responsible organisation fulfils its respective responsibilities.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 6.1.3-S1 -->
- **[SHOULD]** For IT services, the configuration is designed, implemented and documented on the basis of the necessary security requirements.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 6.1.3-S2 -->
- **[SHOULD]** The responsible personnel is appropriately trained.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 6.1.3-H1 -->
- **[HIGH]** A list of the IT services concerned and the respective responsible IT service providers exists. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 6.1.3-H2 -->
- **[HIGH]** The applicability of the ISA controls has been assessed and documented. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 6.1.3-H3 -->
- **[HIGH]** The service configuration is included in the regular security assessments. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 6.1.3-H4 -->
- **[HIGH]** It is demonstrated that the IT service providers fulfil their responsibility. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 6.1.3-H5 -->
- **[HIGH]** The integration into local protective measures (e.g. secure authentication mechanisms) is established and documented. (C, I, A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.21-1 -->
- **[ISO A.5.21]** Processes to manage information security risks in the ICT product and service supply chain are defined and implemented.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 6.1.3 -->
The IT services concerned and their security requirements are identified; responsibilities between the organisation and external IT service providers (incl. mechanisms for shared responsibility) are defined, known and fulfilled (see {{LINK:VA-10}}); the IT services and service providers concerned are maintained in the register of external IT/cloud/AI services ({{LINK:REG-EXT-SERVICES}}). The configuration is implemented on a requirements basis and documented, and the personnel is trained.
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 6.1.3-elev -->
Where the protection need is high, a list of the IT services and responsible service providers exists, the applicability of the ISA controls is assessed/documented, the service configuration is part of regular security assessments, the fulfilment of responsibility is demonstrated, and the integration into local protective measures is documented.
{{/if}}
## 4. Binding nature
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_ISB}}.
## 5. Roles and responsibilities
| Role | Responsibility in this policy |
|-------|-------------------------------------|
| {{ROLE_ISB}} | Supplier management |
| Procurement | Contractual integration |
## 6. Review and update
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_ISB}} and approved by {{ROLE_MANAGEMENT}}.
## 7. Evidence
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
## 8. Related documents
- Associated procedures: {{LINK:VA-10}}
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- Further: {{LINK:R01}}, {{LINK:R12}}
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->
@@ -0,0 +1,129 @@
# Policy Compliance and Data Protection
| Document information | Value |
|-----------------------|------|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_ISB}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## 1. Purpose
This policy governs compliance with regulatory/contractual requirements as well as the protection of personal data. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
## 2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
## 3. Requirements and implementation
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
### 3.1 Regulatory and contractual compliance
<!-- FW:REF-START ORIG:(ISA 7.1.1) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 7.1.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.31, A.5.32, A.5.33{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 7.1.1-M1 -->
- **[MUST]** Legal, regulatory and contractual requirements relevant to information security are determined regularly.
<!-- REQ 7.1.1-M2 -->
- **[MUST]** Policies for complying with the requirements are defined, implemented and communicated to the responsible persons.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 7.1.1-S1 -->
- **[SHOULD]** The integrity of records in accordance with legal, regulatory and contractual requirements as well as business requirements is taken into account.
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.31-1 -->
- **[ISO A.5.31]** Legal, statutory, regulatory and contractual information security requirements are identified, documented and kept up to date.
<!-- REQ A.5.32-1 -->
- **[ISO A.5.32]** Appropriate procedures to protect intellectual property rights are implemented.
<!-- REQ A.5.33-1 -->
- **[ISO A.5.33]** Records are protected against loss, destruction, falsification, unauthorised access and unauthorised release.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 7.1.1 -->
Relevant legal, regulatory and contractual requirements are determined regularly and recorded in a compliance/legal register in the ISMS tool ({{TOOL_NAME}}); policies for compliance are defined, implemented and communicated to the responsible persons, and the integrity of records is taken into account.
{{#if FLAG_PERSONAL_DATA}}
### 3.2 Protection of personal data
<!-- FW:REF-START ORIG:(ISA 7.1.2) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 7.1.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.34{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 7.1.2-M1 -->
- **[MUST]** Legal and contractual information security requirements for procedures and processes when processing personal data are determined.
<!-- REQ 7.1.2-M2 -->
- **[MUST]** Provisions for complying with legal and contractual requirements for the protection of personal data are defined and known to the persons involved.
<!-- REQ 7.1.2-M3 -->
- **[MUST]** Processes and procedures for protecting personal data are taken into account in the information security management system.
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.34-1 -->
- **[ISO A.5.34]** Requirements for the protection of personally identifiable information are identified and met in accordance with applicable obligations.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 7.1.2 -->
Legal and contractual requirements for the processing of personal data (GDPR) are determined; provisions are defined, known to those involved and taken into account in the ISMS. {{ROLE_DPO}} is involved, the record of processing activities is maintained in the ISMS tool ({{TOOL_NAME}}), and TOMs and deletion concepts (BL-DEL-01) are regulated; legal register review, deletion periods and data subject rights are processed following the data protection/compliance maintenance procedure ({{LINK:VA-18}}).
{{/if}}
## 4. Binding nature
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_ISB}}.
## 5. Roles and responsibilities
| Role | Responsibility in this policy |
|-------|-------------------------------------|
| {{ROLE_ISB}} | Compliance register |
| {{ROLE_DPO}} | Data protection |
## 6. Review and update
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_ISB}} and approved by {{ROLE_MANAGEMENT}}.
## 7. Evidence
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
## 8. Related documents
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- Further: {{LINK:L00}}, {{LINK:R03}}
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->