Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
+289
@@ -0,0 +1,289 @@
|
||||
# Policy Risk Management and Audit Policy
|
||||
|
||||
| Document information | Value |
|
||||
|-----------------------|------|
|
||||
| Document type | Policy |
|
||||
| Scope | {{ISMS_SCOPE}} |
|
||||
| Organisation | {{ORG_NAME}} |
|
||||
| Responsible | {{ROLE_ISB}} |
|
||||
| Approved by | {{ROLE_MANAGEMENT}} |
|
||||
| Version | {{DOC_VERSION}} |
|
||||
| Date | {{DOC_DATE}} |
|
||||
| Status | {{DOC_STATUS}} |
|
||||
|
||||
|
||||
## 1. Purpose
|
||||
|
||||
This policy governs the identification, assessment and treatment of information security risks as well as internal and independent reviews. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
|
||||
|
||||
## 2. Scope
|
||||
|
||||
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
|
||||
|
||||
## 3. Requirements and implementation
|
||||
|
||||
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
|
||||
|
||||
### 3.1 Risk management
|
||||
|
||||
<!-- FW:REF-START ORIG:(ISA 1.4.1) -->
|
||||
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.4.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 6.1.1, 6.1.2, 8.2, 8.3{{/if}}
|
||||
<!-- FW:REF-END -->
|
||||
|
||||
**Requirement**
|
||||
|
||||
<!-- FW:TISAX-REQ-START -->
|
||||
{{#if FLAG_FW_TISAX}}
|
||||
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
|
||||
|
||||
<!-- REQ 1.4.1-M1 -->
|
||||
- **[MUST]** Risk assessments are carried out regularly and on an ad-hoc basis.
|
||||
<!-- REQ 1.4.1-M2 -->
|
||||
- **[MUST]** Information security risks are assessed appropriately (e.g. likelihood of occurrence and potential extent of damage).
|
||||
<!-- REQ 1.4.1-M3 -->
|
||||
- **[MUST]** Information security risks are documented.
|
||||
<!-- REQ 1.4.1-M4 -->
|
||||
- **[MUST]** A responsible person (risk owner) is assigned to each information security risk and is responsible for its assessment and treatment.
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 1.4.1-S1 -->
|
||||
- **[SHOULD]** A procedure for the identification, assessment and treatment of security risks is in place.
|
||||
{{/if}}
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 1.4.1-S2 -->
|
||||
- **[SHOULD]** Criteria for the assessment and treatment of security risks exist.
|
||||
{{/if}}
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 1.4.1-S3 -->
|
||||
- **[SHOULD]** Risk treatment measures and their responsible persons are defined and documented; a measures plan or implementation overview is tracked.
|
||||
{{/if}}
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 1.4.1-S4 -->
|
||||
- **[SHOULD]** Upon changes in the environment (e.g. organisational structure, location, regulations), a reassessment is carried out promptly.
|
||||
{{/if}}
|
||||
{{/if}}
|
||||
<!-- FW:TISAX-REQ-END -->
|
||||
<!-- FW:ISO-REQ-START -->
|
||||
{{#if FLAG_FW_ISO27001}}
|
||||
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
|
||||
|
||||
<!-- REQ 6.1.1-1 -->
|
||||
- **[ISO 6.1.1]** When planning the ISMS, risks and opportunities that need to be addressed are determined.
|
||||
<!-- REQ 6.1.2-1 -->
|
||||
- **[ISO 6.1.2]** A risk assessment process with defined criteria is established and applied so that it is repeatable and produces comparable results.
|
||||
<!-- REQ 8.2-1 -->
|
||||
- **[ISO 8.2]** Risk assessments are performed at planned intervals and upon significant change, and are documented.
|
||||
<!-- REQ 8.3-1 -->
|
||||
- **[ISO 8.3]** The risk treatment plan is implemented and the results are documented.
|
||||
{{/if}}
|
||||
<!-- FW:ISO-REQ-END -->
|
||||
|
||||
**Implementation at {{ORG_NAME}}**
|
||||
|
||||
<!-- IMPL 1.4.1 -->
|
||||
The documented risk management procedure (see {{LINK:VA-09}}) with assessment and acceptance criteria is implemented in the ISMS tool ({{TOOL_NAME}}): risks are identified regularly ({{REVIEW_CYCLE}}) and on an ad-hoc basis, assessed (likelihood × impact) and documented; for each risk, a risk owner, treatment option and measures with deadlines are recorded and tracked. Residual risks are accepted by {{ROLE_MANAGEMENT}} in a documented manner.
|
||||
|
||||
### 3.2 Verification of compliance in IS operations
|
||||
|
||||
<!-- FW:REF-START ORIG:(ISA 1.5.1) -->
|
||||
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.5.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.36{{/if}}
|
||||
<!-- FW:REF-END -->
|
||||
|
||||
**Requirement**
|
||||
|
||||
<!-- FW:TISAX-REQ-START -->
|
||||
{{#if FLAG_FW_TISAX}}
|
||||
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
|
||||
|
||||
<!-- REQ 1.5.1-M1 -->
|
||||
- **[MUST]** Compliance with the policies is reviewed organisation-wide.
|
||||
<!-- REQ 1.5.1-M2 -->
|
||||
- **[MUST]** Information security policies and procedures are reviewed regularly.
|
||||
<!-- REQ 1.5.1-M3 -->
|
||||
- **[MUST]** Measures to correct possible deviations are initiated and tracked.
|
||||
<!-- REQ 1.5.1-M4 -->
|
||||
- **[MUST]** Compliance with information security requirements (e.g. technical specifications) is reviewed regularly.
|
||||
<!-- REQ 1.5.1-M5 -->
|
||||
- **[MUST]** The results of the reviews carried out are recorded and retained.
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 1.5.1-S1 -->
|
||||
- **[SHOULD]** A plan for the content and framework conditions (schedule, scope, controls) of the reviews to be carried out is in place.
|
||||
{{/if}}
|
||||
{{/if}}
|
||||
<!-- FW:TISAX-REQ-END -->
|
||||
<!-- FW:ISO-REQ-START -->
|
||||
{{#if FLAG_FW_ISO27001}}
|
||||
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
|
||||
|
||||
<!-- REQ A.5.36-1 -->
|
||||
- **[ISO A.5.36]** Compliance with the information security policy, topic-specific policies, rules and standards is reviewed regularly.
|
||||
{{/if}}
|
||||
<!-- FW:ISO-REQ-END -->
|
||||
|
||||
**Implementation at {{ORG_NAME}}**
|
||||
|
||||
<!-- IMPL 1.5.1 -->
|
||||
Compliance with policies, procedures and technical requirements is reviewed organisation-wide and regularly according to the audit programme ({{LINK:REG-AUDIT-PLAN}}) and the audit/compliance review procedure ({{LINK:VA-15}}) through internal audits and controls (cycle BL-GOV-01); results are recorded and retained, deviations are tracked as measures in {{TOOL_NAME}}; responsible: {{ROLE_ISB}}.
|
||||
|
||||
### 3.3 Independent review of the ISMS
|
||||
|
||||
<!-- FW:REF-START ORIG:(ISA 1.5.2) -->
|
||||
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.5.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 9.2, A.5.35{{/if}}
|
||||
<!-- FW:REF-END -->
|
||||
|
||||
**Requirement**
|
||||
|
||||
<!-- FW:TISAX-REQ-START -->
|
||||
{{#if FLAG_FW_TISAX}}
|
||||
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
|
||||
|
||||
<!-- REQ 1.5.2-M1 -->
|
||||
- **[MUST]** Information security reviews are carried out by an independent and competent body regularly and after fundamental changes.
|
||||
<!-- REQ 1.5.2-M2 -->
|
||||
- **[MUST]** Measures to correct possible deviations are initiated and tracked.
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 1.5.2-S1 -->
|
||||
- **[SHOULD]** The results of the reviews carried out are documented and reported to the organisation's management.
|
||||
{{/if}}
|
||||
{{/if}}
|
||||
<!-- FW:TISAX-REQ-END -->
|
||||
<!-- FW:ISO-REQ-START -->
|
||||
{{#if FLAG_FW_ISO27001}}
|
||||
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
|
||||
|
||||
<!-- REQ 9.2-1 -->
|
||||
- **[ISO 9.2]** Internal audits are conducted at planned intervals to verify conformity and effective implementation of the ISMS.
|
||||
<!-- REQ A.5.35-1 -->
|
||||
- **[ISO A.5.35]** The organisation's approach to managing information security is reviewed independently at planned intervals.
|
||||
{{/if}}
|
||||
<!-- FW:ISO-REQ-END -->
|
||||
|
||||
**Implementation at {{ORG_NAME}}**
|
||||
|
||||
<!-- IMPL 1.5.2 -->
|
||||
The ISMS is reviewed regularly and after fundamental changes by an independent, competent body (internal audit or external auditing, e.g. TISAX); results are documented, reported to {{ROLE_MANAGEMENT}} and deviations tracked as measures.
|
||||
|
||||
## 4. Binding nature
|
||||
|
||||
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_ISB}}.
|
||||
|
||||
## 5. Roles and responsibilities
|
||||
|
||||
| Role | Responsibility in this policy |
|
||||
|-------|-------------------------------------|
|
||||
| {{ROLE_ISB}} | Risk management, audits |
|
||||
| {{ROLE_MANAGEMENT}} | Risk acceptance |
|
||||
|
||||
## 6. Review and update
|
||||
|
||||
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_ISB}} and approved by {{ROLE_MANAGEMENT}}.
|
||||
|
||||
## 7. Evidence
|
||||
|
||||
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
|
||||
|
||||
## 8. Related documents
|
||||
|
||||
- Associated procedures: {{LINK:VA-09}}
|
||||
- Technical security baseline: {{LINK:BASELINE}}
|
||||
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
|
||||
- Evidence register: {{LINK:NACHWEISREGISTER}}
|
||||
- Further: {{LINK:R01}}, {{LINK:R04}}
|
||||
|
||||
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->
|
||||
<!-- FW:ISO-SECTION-START -->
|
||||
{{#if FLAG_FW_ISO27001}}
|
||||
|
||||
### 3.4 Statement of Applicability (SoA)
|
||||
|
||||
*Requirement reference:* ISO/IEC 27001 6.1.3
|
||||
|
||||
**Requirement**
|
||||
|
||||
<!-- REQ 6.1.3-1 -->
|
||||
- **[ISO 6.1.3]** A risk treatment process is defined; necessary controls are determined and compared against Annex A in a Statement of Applicability.
|
||||
|
||||
**Implementation at {{ORG_NAME}}**
|
||||
|
||||
<!-- IMPL ISO-SOA -->
|
||||
The risk treatment determines which controls are necessary; the result is compared against Annex A to identify controls that may have been overlooked. The Statement of Applicability is maintained in {{TOOL_NAME}} and states for each control: applicability, justification for inclusion, origin (risk ID, legal or contractual requirement), implementation status, responsible role, reference to policy and procedure as well as evidence; where a control is excluded, the justification is documented. The risk treatment plan and the acceptance of residual risks are approved by the respective risk owners; the SoA is approved by {{ROLE_MANAGEMENT}} and updated with every risk assessment ({{RISK_REVIEW_CYCLE}}).
|
||||
|
||||
{{/if}}
|
||||
<!-- FW:ISO-SECTION-END -->
|
||||
<!-- FW:ISO-SECTION-START -->
|
||||
{{#if FLAG_FW_ISO27001}}
|
||||
|
||||
### 3.5 Operational planning and control
|
||||
|
||||
*Requirement reference:* ISO/IEC 27001 8.1
|
||||
|
||||
**Requirement**
|
||||
|
||||
<!-- REQ 8.1-1 -->
|
||||
- **[ISO 8.1]** The processes needed to meet the requirements are planned, implemented and controlled; planned changes are controlled.
|
||||
|
||||
**Implementation at {{ORG_NAME}}**
|
||||
|
||||
<!-- IMPL ISO-MS-BETRIEB -->
|
||||
The processes required to meet the information security requirements are laid down in the procedures and controlled in {{TOOL_NAME}}; for each process the trigger, responsible role, deadlines and evidence are defined. Planned changes are controlled and their consequences assessed; unintended changes are reviewed and corrected where necessary. Outsourced processes are determined and monitored through supplier management ({{LINK:R13}}). Evidence of execution as planned is kept in the evidence register ({{LINK:NACHWEISREGISTER}}).
|
||||
|
||||
{{/if}}
|
||||
<!-- FW:ISO-SECTION-END -->
|
||||
<!-- FW:ISO-SECTION-START -->
|
||||
{{#if FLAG_FW_ISO27001}}
|
||||
|
||||
### 3.6 Monitoring, measurement, analysis and evaluation
|
||||
|
||||
*Requirement reference:* ISO/IEC 27001 9.1
|
||||
|
||||
**Requirement**
|
||||
|
||||
<!-- REQ 9.1-1 -->
|
||||
- **[ISO 9.1]** The information security performance and the effectiveness of the ISMS are monitored, measured, analysed and evaluated.
|
||||
|
||||
**Implementation at {{ORG_NAME}}**
|
||||
|
||||
<!-- IMPL ISO-MS-MESSUNG -->
|
||||
For the evaluation of information security performance and the effectiveness of the ISMS it is defined what is measured (metrics sheet in {{TOOL_NAME}}), by which method and data source, at which interval, who measures, when the results are analysed and who analyses them. The metrics cover at least incident handling, vulnerability and patch remediation, recertification of access rights, restore tests, awareness participation and open actions; each metric has a target value and a responsible role. Results and trends feed into the management review {{MGMT_REVIEW_CYCLE}}; a deviation from the target value triggers an action.
|
||||
|
||||
{{/if}}
|
||||
<!-- FW:ISO-SECTION-END -->
|
||||
<!-- FW:ISO-SECTION-START -->
|
||||
{{#if FLAG_FW_ISO27001}}
|
||||
|
||||
### 3.7 Management review
|
||||
|
||||
*Requirement reference:* ISO/IEC 27001 9.3
|
||||
|
||||
**Requirement**
|
||||
|
||||
<!-- REQ 9.3-1 -->
|
||||
- **[ISO 9.3]** Top management reviews the ISMS at planned intervals.
|
||||
|
||||
**Implementation at {{ORG_NAME}}**
|
||||
|
||||
<!-- IMPL ISO-MS-MGMTREVIEW -->
|
||||
{{ROLE_MANAGEMENT}} reviews the ISMS at least {{MGMT_REVIEW_CYCLE}} against a fixed agenda (BL-GOV-02). Inputs are at least: status of actions from previous reviews; changes in relevant internal and external issues and in the requirements of interested parties; feedback on information security performance (nonconformities and corrective actions, monitoring and measurement results, audit results, achievement of the information security objectives); feedback from interested parties; results of the risk assessment and status of the risk treatment plan; opportunities for improvement. Outputs are decisions on opportunities for improvement and on any need to change the ISMS, each with a responsible role and a due date. The minutes are retained in {{TOOL_NAME}}.
|
||||
|
||||
{{/if}}
|
||||
<!-- FW:ISO-SECTION-END -->
|
||||
<!-- FW:ISO-SECTION-START -->
|
||||
{{#if FLAG_FW_ISO27001}}
|
||||
|
||||
### 3.8 Nonconformity, corrective action and continual improvement
|
||||
|
||||
*Requirement reference:* ISO/IEC 27001 10.1, 10.2
|
||||
|
||||
**Requirement**
|
||||
|
||||
<!-- REQ 10.1-1 -->
|
||||
- **[ISO 10.1]** The suitability, adequacy and effectiveness of the ISMS are continually improved.
|
||||
<!-- REQ 10.2-1 -->
|
||||
- **[ISO 10.2]** In the event of nonconformity, corrections are made and corrective actions are taken to eliminate the causes.
|
||||
|
||||
**Implementation at {{ORG_NAME}}**
|
||||
|
||||
<!-- IMPL ISO-MS-CAPA -->
|
||||
Nonconformities arising from audits, controls, incidents, deviations of metrics and reports are recorded in {{TOOL_NAME}}. For each case the immediate correction and the handling of the consequences are decided, the cause is analysed and it is evaluated whether similar nonconformities exist or could occur elsewhere. Necessary corrective actions are implemented with a responsible role and a due date; their effectiveness is evaluated after the defined effectiveness interval and, where necessary, risks, controls and documents are adjusted. The nature of the nonconformity, the actions taken and the result of the effectiveness review are retained. The suitability, adequacy and effectiveness of the ISMS are continually improved; evidence is provided through metrics and the management review.
|
||||
|
||||
{{/if}}
|
||||
<!-- FW:ISO-SECTION-END -->
|
||||
Reference in New Issue
Block a user