Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
+219
@@ -0,0 +1,219 @@
|
||||
# Policy Secure System Procurement and Development
|
||||
|
||||
| Document information | Value |
|
||||
|-----------------------|------|
|
||||
| Document type | Policy |
|
||||
| Scope | {{ISMS_SCOPE}} |
|
||||
| Organisation | {{ORG_NAME}} |
|
||||
| Responsible | {{ROLE_IT_LEAD}} |
|
||||
| Approved by | {{ROLE_MANAGEMENT}} |
|
||||
| Version | {{DOC_VERSION}} |
|
||||
| Date | {{DOC_DATE}} |
|
||||
| Status | {{DOC_STATUS}} |
|
||||
|
||||
|
||||
## 1. Purpose
|
||||
|
||||
This policy governs information security in procurement and development, requirements for network services as well as return and secure deletion. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
|
||||
|
||||
## 2. Scope
|
||||
|
||||
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
|
||||
|
||||
## 3. Requirements and implementation
|
||||
|
||||
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
|
||||
|
||||
### 3.1 Security in procurement and development
|
||||
|
||||
<!-- FW:REF-START ORIG:(ISA 5.3.1) -->
|
||||
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.3.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.4, A.8.25, A.8.26, A.8.27, A.8.28, A.8.29, A.8.30, A.8.33{{/if}}
|
||||
<!-- FW:REF-END -->
|
||||
|
||||
**Requirement**
|
||||
|
||||
<!-- FW:TISAX-REQ-START -->
|
||||
{{#if FLAG_FW_TISAX}}
|
||||
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
|
||||
|
||||
<!-- REQ 5.3.1-M1 -->
|
||||
- **[MUST]** The information security requirements associated with the design and development of an IT service are determined and taken into account.
|
||||
<!-- REQ 5.3.1-M2 -->
|
||||
- **[MUST]** The information security requirements associated with the procurement or extension of IT services and components are determined and taken into account.
|
||||
<!-- REQ 5.3.1-M3 -->
|
||||
- **[MUST]** Information security requirements in connection with changes to developed IT services are taken into account.
|
||||
<!-- REQ 5.3.1-M4 -->
|
||||
- **[MUST]** System acceptance tests are carried out taking the information security requirements into account.
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 5.3.1-S1 -->
|
||||
- **[SHOULD]** Requirement specifications are created; the relevant aspects are taken into account.
|
||||
{{/if}}
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 5.3.1-S2 -->
|
||||
- **[SHOULD]** Requirement specifications are checked against the information security requirements.
|
||||
{{/if}}
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 5.3.1-S3 -->
|
||||
- **[SHOULD]** The IT service is checked for compliance with the specifications before production use.
|
||||
{{/if}}
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 5.3.1-S4 -->
|
||||
- **[SHOULD]** The use of production data for test purposes is avoided as far as possible (anonymisation/pseudonymisation where applicable); the relevant aspects are taken into account.
|
||||
{{/if}}
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 5.3.1-S5 -->
|
||||
- **[SHOULD]** Test systems receive protective measures comparable to the production environment when production data is used for testing.
|
||||
{{/if}}
|
||||
{{#if FLAG_VERY_HIGH_PROTECTION}}
|
||||
<!-- REQ 5.3.1-V1 -->
|
||||
- **[VERY HIGH]** The security of purpose-built or substantially adapted software is tested upon commissioning, upon substantial changes or regularly (e.g. penetration test). (C, I, A)
|
||||
{{/if}}
|
||||
{{/if}}
|
||||
<!-- FW:TISAX-REQ-END -->
|
||||
<!-- FW:ISO-REQ-START -->
|
||||
{{#if FLAG_FW_ISO27001}}
|
||||
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
|
||||
|
||||
<!-- REQ A.8.4-1 -->
|
||||
- **[ISO A.8.4]** Read and write access to source code, development tools and software libraries is appropriately managed.
|
||||
<!-- REQ A.8.25-1 -->
|
||||
- **[ISO A.8.25]** Rules for a secure development life cycle of software and systems are established and applied.
|
||||
<!-- REQ A.8.26-1 -->
|
||||
- **[ISO A.8.26]** Information security requirements are identified, specified and taken into account when developing or acquiring applications.
|
||||
<!-- REQ A.8.27-1 -->
|
||||
- **[ISO A.8.27]** Principles for engineering secure systems are established, documented and applied.
|
||||
<!-- REQ A.8.28-1 -->
|
||||
- **[ISO A.8.28]** Secure coding principles are applied to software development.
|
||||
<!-- REQ A.8.29-1 -->
|
||||
- **[ISO A.8.29]** Security testing is integrated into the development and acceptance process.
|
||||
<!-- REQ A.8.30-1 -->
|
||||
- **[ISO A.8.30]** Outsourced system development is directed, monitored and reviewed.
|
||||
<!-- REQ A.8.33-1 -->
|
||||
- **[ISO A.8.33]** Test information is selected, protected and managed with care.
|
||||
{{/if}}
|
||||
<!-- FW:ISO-REQ-END -->
|
||||
|
||||
**Implementation at {{ORG_NAME}}**
|
||||
|
||||
<!-- IMPL 5.3.1 -->
|
||||
Information security requirements are an integral part of the design, procurement, extension and modification of IT services (security by design); requirement specification, review and acceptance tests under security aspects are carried out following the procedure Secure Procurement/Development & Acceptance ({{LINK:VA-16}}); production deployment only after review in {{TOOL_TICKET}}. Production data in tests is avoided/anonymised, and test systems are appropriately protected.{{#if FLAG_DEV_INHOUSE}} For in-house development, secure coding requirements apply with code reviews and automated security tests (SAST/dependency scan) in accordance with {{LINK:VA-16}}.{{/if}}
|
||||
|
||||
{{#if FLAG_ELEVATED_PROTECTION}}
|
||||
<!-- IMPL 5.3.1-elev -->
|
||||
{{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, the security of purpose-built or substantially adapted software is tested upon commissioning, upon substantial changes or regularly (penetration test).{{/if}}
|
||||
{{/if}}
|
||||
|
||||
### 3.2 Requirements for network services
|
||||
|
||||
<!-- FW:REF-START ORIG:(ISA 5.3.2) -->
|
||||
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.3.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.21{{/if}}
|
||||
<!-- FW:REF-END -->
|
||||
|
||||
**Requirement**
|
||||
|
||||
<!-- FW:TISAX-REQ-START -->
|
||||
{{#if FLAG_FW_TISAX}}
|
||||
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
|
||||
|
||||
<!-- REQ 5.3.2-M1 -->
|
||||
- **[MUST]** Requirements for the information security of network services are determined and met.
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 5.3.2-S1 -->
|
||||
- **[SHOULD]** A procedure for securing and using network services is defined and implemented.
|
||||
{{/if}}
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 5.3.2-S2 -->
|
||||
- **[SHOULD]** The requirements are agreed in the form of SLAs.
|
||||
{{/if}}
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 5.3.2-S3 -->
|
||||
- **[SHOULD]** Appropriate redundancy solutions are implemented.
|
||||
{{/if}}
|
||||
{{#if FLAG_HIGH_PROTECTION}}
|
||||
<!-- REQ 5.3.2-H1 -->
|
||||
- **[HIGH]** Procedures for monitoring the quality of network traffic (e.g. traffic flow analyses, availability measurements) are defined and carried out. (A)
|
||||
{{/if}}
|
||||
{{/if}}
|
||||
<!-- FW:TISAX-REQ-END -->
|
||||
<!-- FW:ISO-REQ-START -->
|
||||
{{#if FLAG_FW_ISO27001}}
|
||||
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
|
||||
|
||||
<!-- REQ A.8.21-1 -->
|
||||
- **[ISO A.8.21]** Security mechanisms, service levels and requirements for network services are identified, implemented and monitored.
|
||||
{{/if}}
|
||||
<!-- FW:ISO-REQ-END -->
|
||||
|
||||
**Implementation at {{ORG_NAME}}**
|
||||
|
||||
<!-- IMPL 5.3.2 -->
|
||||
For the network services used (internal/external), security requirements are determined, agreed in SLAs and implemented via a procedure; appropriate redundancies are in place.
|
||||
|
||||
{{#if FLAG_ELEVATED_PROTECTION}}
|
||||
<!-- IMPL 5.3.2-elev -->
|
||||
Where the protection need is high, procedures for monitoring network traffic quality (traffic flow analyses, availability measurements) are defined and carried out.
|
||||
{{/if}}
|
||||
|
||||
### 3.3 Return and secure deletion
|
||||
|
||||
<!-- FW:REF-START ORIG:(ISA 5.3.3) -->
|
||||
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.3.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.11, A.7.14, A.8.10{{/if}}
|
||||
<!-- FW:REF-END -->
|
||||
|
||||
**Requirement**
|
||||
|
||||
<!-- FW:TISAX-REQ-START -->
|
||||
{{#if FLAG_FW_TISAX}}
|
||||
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
|
||||
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 5.3.3-S1 -->
|
||||
- **[SHOULD]** A description of the termination process is in place, adapted to changes and regulated contractually.
|
||||
{{/if}}
|
||||
{{/if}}
|
||||
<!-- FW:TISAX-REQ-END -->
|
||||
<!-- FW:ISO-REQ-START -->
|
||||
{{#if FLAG_FW_ISO27001}}
|
||||
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
|
||||
|
||||
<!-- REQ A.5.11-1 -->
|
||||
- **[ISO A.5.11]** Personnel and external users return all assets in their possession upon termination of employment or contract.
|
||||
<!-- REQ A.7.14-1 -->
|
||||
- **[ISO A.7.14]** Equipment containing storage media is securely sanitised before disposal or re-use.
|
||||
<!-- REQ A.8.10-1 -->
|
||||
- **[ISO A.8.10]** Information stored in systems and on media is deleted when no longer required.
|
||||
{{/if}}
|
||||
<!-- FW:ISO-REQ-END -->
|
||||
|
||||
**Implementation at {{ORG_NAME}}**
|
||||
|
||||
<!-- IMPL 5.3.3 -->
|
||||
Return and secure deletion/destruction of information and assets (upon end of contract, device decommissioning) are regulated according to BL-DEL-01, agreed contractually, adapted to changes and evidenced (deletion log).
|
||||
|
||||
## 4. Binding nature
|
||||
|
||||
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_IT_LEAD}}.
|
||||
|
||||
## 5. Roles and responsibilities
|
||||
|
||||
| Role | Responsibility in this policy |
|
||||
|-------|-------------------------------------|
|
||||
| {{ROLE_IT_LEAD}} | Procurement/development |
|
||||
| {{ROLE_ISB}} | Security requirements |
|
||||
|
||||
## 6. Review and update
|
||||
|
||||
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_IT_LEAD}} and approved by {{ROLE_MANAGEMENT}}.
|
||||
|
||||
## 7. Evidence
|
||||
|
||||
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
|
||||
|
||||
## 8. Related documents
|
||||
|
||||
- Technical security baseline: {{LINK:BASELINE}}
|
||||
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
|
||||
- Evidence register: {{LINK:NACHWEISREGISTER}}
|
||||
- Further: {{LINK:R02}}, {{LINK:R10}}, {{LINK:R12}}
|
||||
|
||||
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->
|
||||
Reference in New Issue
Block a user