Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,173 @@
|
||||
# Policy Physical Security
|
||||
|
||||
| Document information | Value |
|
||||
|-----------------------|------|
|
||||
| Document type | Policy |
|
||||
| Scope | {{ISMS_SCOPE}} |
|
||||
| Organisation | {{ORG_NAME}} |
|
||||
| Responsible | {{ROLE_IT_LEAD}} |
|
||||
| Approved by | {{ROLE_MANAGEMENT}} |
|
||||
| Version | {{DOC_VERSION}} |
|
||||
| Date | {{DOC_DATE}} |
|
||||
| Status | {{DOC_STATUS}} |
|
||||
|
||||
|
||||
## 1. Purpose
|
||||
|
||||
This policy governs physical protection through security zones, access protection and the handling of supporting utilities. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
|
||||
|
||||
## 2. Scope
|
||||
|
||||
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
|
||||
|
||||
## 3. Requirements and implementation
|
||||
|
||||
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
|
||||
|
||||
### 3.1 Security zones and access
|
||||
|
||||
<!-- FW:REF-START ORIG:(ISA 3.1.1) -->
|
||||
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 3.1.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.7.1, A.7.2, A.7.3, A.7.4, A.7.6{{/if}}
|
||||
<!-- FW:REF-END -->
|
||||
|
||||
**Requirement**
|
||||
|
||||
<!-- FW:TISAX-REQ-START -->
|
||||
{{#if FLAG_FW_TISAX}}
|
||||
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
|
||||
|
||||
<!-- REQ 3.1.1-M1 -->
|
||||
- **[MUST]** A security zone concept including associated protective measures based on the requirements for handling information assets is in place.
|
||||
<!-- REQ 3.1.1-M2 -->
|
||||
- **[MUST]** The defined protective measures are implemented.
|
||||
<!-- REQ 3.1.1-M3 -->
|
||||
- **[MUST]** The code of conduct for security zones is known to all persons involved.
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 3.1.1-S1 -->
|
||||
- **[SHOULD]** Procedures for granting and revoking access rights are established.
|
||||
{{/if}}
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 3.1.1-S2 -->
|
||||
- **[SHOULD]** Policies for visitor management (including registration and escorting of visitors) are defined.
|
||||
{{/if}}
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 3.1.1-S3 -->
|
||||
- **[SHOULD]** Policies for carrying and using mobile IT devices and data media (e.g. registration, labelling obligations) are defined and implemented.
|
||||
{{/if}}
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 3.1.1-S4 -->
|
||||
- **[SHOULD]** Network/infrastructure components (own or customer networks) are protected against unauthorised access.
|
||||
{{/if}}
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 3.1.1-S5 -->
|
||||
- **[SHOULD]** External premises used for storing/processing information assets are taken into account in the zone concept (e.g. storage rooms, workshops, test tracks, data centres).
|
||||
{{/if}}
|
||||
{{#if FLAG_HIGH_PROTECTION}}
|
||||
<!-- REQ 3.1.1-H1 -->
|
||||
- **[HIGH]** Protective measures against simple eavesdropping and being overlooked are implemented. (C)
|
||||
{{/if}}
|
||||
{{/if}}
|
||||
<!-- FW:TISAX-REQ-END -->
|
||||
<!-- FW:ISO-REQ-START -->
|
||||
{{#if FLAG_FW_ISO27001}}
|
||||
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
|
||||
|
||||
<!-- REQ A.7.1-1 -->
|
||||
- **[ISO A.7.1]** Security perimeters are defined and used to protect areas containing information and assets.
|
||||
<!-- REQ A.7.2-1 -->
|
||||
- **[ISO A.7.2]** Secure entry controls and entry points are established to restrict access to authorised persons.
|
||||
<!-- REQ A.7.3-1 -->
|
||||
- **[ISO A.7.3]** Physical security for offices, rooms and facilities is designed and implemented.
|
||||
<!-- REQ A.7.4-1 -->
|
||||
- **[ISO A.7.4]** Premises are continuously monitored for unauthorised physical access.
|
||||
<!-- REQ A.7.6-1 -->
|
||||
- **[ISO A.7.6]** Measures for working in secure areas are defined and implemented.
|
||||
{{/if}}
|
||||
<!-- FW:ISO-REQ-END -->
|
||||
|
||||
**Implementation at {{ORG_NAME}}**
|
||||
|
||||
<!-- IMPL 3.1.1 -->
|
||||
A security zone concept (BL-PHY-01) with implemented protective measures and a known code of conduct is in place; access rights are granted on a needs-oriented basis via {{TOOL_TICKET}}, documented and revoked when no longer needed (BL-PHY-02, process see {{LINK:VA-17}}). Visitor management, rules for mobile devices, protection of network/infrastructure components and external premises are taken into account.
|
||||
|
||||
{{#if FLAG_ELEVATED_PROTECTION}}
|
||||
<!-- IMPL 3.1.1-elev -->
|
||||
Where the protection need is high, additional protective measures against simple eavesdropping and being overlooked are implemented.
|
||||
{{/if}}
|
||||
|
||||
<!-- Scope-Hinweis (E2): ISA 3.1.2 ist in VDA-ISA 2027 deprecated; ISA 3.1.3 existiert nicht.
|
||||
Daher kein Abschnitt/REQ/IMPL für 3.1.2/3.1.3 in R07 und mapping.json. -->
|
||||
|
||||
## 4. Binding nature
|
||||
|
||||
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_IT_LEAD}}.
|
||||
|
||||
## 5. Roles and responsibilities
|
||||
|
||||
| Role | Responsibility in this policy |
|
||||
|-------|-------------------------------------|
|
||||
| {{ROLE_IT_LEAD}} | Zones, access, utilities |
|
||||
| {{ROLE_ISB}} | Specifications |
|
||||
|
||||
## 6. Review and update
|
||||
|
||||
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_IT_LEAD}} and approved by {{ROLE_MANAGEMENT}}.
|
||||
|
||||
## 7. Evidence
|
||||
|
||||
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
|
||||
|
||||
## 8. Related documents
|
||||
|
||||
- Technical security baseline: {{LINK:BASELINE}}
|
||||
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
|
||||
- Evidence register: {{LINK:NACHWEISREGISTER}}
|
||||
- Further: {{LINK:R02}}, {{LINK:R06}}
|
||||
|
||||
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->
|
||||
<!-- FW:ISO-SECTION-START -->
|
||||
{{#if FLAG_FW_ISO27001}}
|
||||
|
||||
### 3.2 Environmental protection, utilities, cabling and maintenance
|
||||
|
||||
*Requirement reference:* ISO/IEC 27001 A.7.5, A.7.8, A.7.11, A.7.12, A.7.13
|
||||
|
||||
**Requirement**
|
||||
|
||||
<!-- REQ A.7.5-1 -->
|
||||
- **[ISO A.7.5]** Protection against physical and environmental threats is designed and implemented.
|
||||
<!-- REQ A.7.8-1 -->
|
||||
- **[ISO A.7.8]** Equipment is sited securely and protected.
|
||||
<!-- REQ A.7.11-1 -->
|
||||
- **[ISO A.7.11]** Facilities are protected against failure and disruption of supporting utilities such as power and air conditioning.
|
||||
<!-- REQ A.7.12-1 -->
|
||||
- **[ISO A.7.12]** Power and data cabling is protected against interception, interference and damage.
|
||||
<!-- REQ A.7.13-1 -->
|
||||
- **[ISO A.7.13]** Equipment is maintained properly to ensure availability and integrity.
|
||||
|
||||
**Implementation at {{ORG_NAME}}**
|
||||
|
||||
<!-- IMPL ISO-PHY-UMWELT -->
|
||||
Sites and technical facilities are protected against physical and environmental threats (BL-PHY-03): early fire detection, protection against water and moisture, temperature and humidity monitoring in technical rooms as well as consideration of site-specific hazards. Equipment is sited so that observation, unauthorised access and environmental risks are minimised. Power and air conditioning for critical systems are designed to be uninterruptible and are tested regularly. Power and data cabling is protected against damage and unauthorised access and is documented. Equipment is maintained according to the manufacturer's specifications; maintenance is carried out only by authorised personnel, is planned and recorded, and is supervised where performed externally.
|
||||
|
||||
{{/if}}
|
||||
<!-- FW:ISO-SECTION-END -->
|
||||
<!-- FW:ISO-SECTION-START -->
|
||||
{{#if FLAG_FW_ISO27001}}
|
||||
|
||||
### 3.3 Clear desk and screen lock
|
||||
|
||||
*Requirement reference:* ISO/IEC 27001 A.7.7
|
||||
|
||||
**Requirement**
|
||||
|
||||
<!-- REQ A.7.7-1 -->
|
||||
- **[ISO A.7.7]** Rules for a clear desk and locked screens are defined and implemented.
|
||||
|
||||
**Implementation at {{ORG_NAME}}**
|
||||
|
||||
<!-- IMPL ISO-PHY-CLEARDESK -->
|
||||
Binding rules apply for a clear desk and locked screens (BL-PHY-04): protected documents and media are locked away when unattended; screens are locked when leaving the workplace and lock automatically after {{SESSION_TIMEOUT}}. Printouts are collected immediately and documents no longer required are destroyed according to their protection needs (BL-DEL-01). The rules also apply when working from home and at mobile workplaces ({{LINK:R06}}); compliance is checked on a sample basis.
|
||||
|
||||
{{/if}}
|
||||
<!-- FW:ISO-SECTION-END -->
|
||||
Reference in New Issue
Block a user