Basis: Certvia dev@a48c5fb als Fundament für Craftvia
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s

Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-09-14 11:05:39 +02:00
co-authored by Claude Opus 5
commit c8e6f30a27
720 changed files with 140143 additions and 0 deletions
@@ -0,0 +1,250 @@
# Policy Supplier and Service Provider Management
| Document information | Value |
|-----------------------|------|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_ISB}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## 1. Purpose
This policy governs ensuring information security at suppliers, confidentiality agreements and the delineation of responsibilities. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
## 2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
## 3. Requirements and implementation
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
### 3.1 Information security at suppliers
<!-- FW:REF-START ORIG:(ISA 6.1.1) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 6.1.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.19, A.5.22{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 6.1.1-M1 -->
- **[MUST]** Contractors and partners are subjected to a security risk assessment.
<!-- REQ 6.1.1-M2 -->
- **[MUST]** An appropriate level of information security is ensured through contractual agreements with contractors and partners.
<!-- REQ 6.1.1-M3 -->
- **[MUST]** Where applicable, contractual agreements with clients/customers are passed on to contractors and partners.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 6.1.1-S1 -->
- **[SHOULD]** Contractors and partners are contractually obliged to pass on requirements for an appropriate level of information security to their subcontractors.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 6.1.1-S2 -->
- **[SHOULD]** Performance reports and documents from contractors and partners are reviewed.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 6.1.1-H1 -->
- **[HIGH]** It is demonstrated that the supplier's level of information security is appropriate to the protection need (e.g. reviewed questionnaire/self-disclosure, attestation, certificate, supplier audit). (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 6.1.1-H2 -->
- **[HIGH]** The degree of fulfilment of the required evidence by the supplier is documented, reviewed and monitored regularly and upon changes. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 6.1.1-H3 -->
- **[HIGH]** The supplier's compliance with contractual agreements is checked, documented, reviewed and monitored regularly and upon changes. (C, I, A)
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 6.1.1-V1 -->
- **[VERY HIGH]** The appropriate level of information security should be demonstrated by a third-party audit (an appropriate TISAX label or similar) or an appropriate supplier audit. Without an audit, management must make a risk-based decision to continue; evidence of this decision exists. (C, I, A)
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 6.1.1-V2 -->
- **[VERY HIGH]** Contractual obligations towards customers regarding transparency of supply chain risks are fulfilled. (C, I, A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.19-1 -->
- **[ISO A.5.19]** Processes to manage the information security risks arising from supplier relationships are defined and implemented.
<!-- REQ A.5.22-1 -->
- **[ISO A.5.22]** The information security of supplier services is monitored and reviewed regularly, and changes are managed.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 6.1.1 -->
Contractors/partners are subjected to a security risk assessment (BL-SUP-01) and contractually obliged to an appropriate level of information security (incl. passing on to subcontractors and customer requirements); the supplier register is maintained in the ISMS tool ({{TOOL_NAME}}), and performance reports are reviewed (see {{LINK:VA-10}}).
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 6.1.1-elev -->
Where the protection need is high, the supplier's level of security is demonstrated (self-disclosure/attestation/certificate/audit) and compliance is documented and monitored regularly and upon changes. {{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, the evidence is provided via a third-party audit (TISAX or similar) or a documented risk-based management decision; transparency obligations regarding supply chain risks are fulfilled.{{/if}}
{{/if}}
### 3.2 Confidentiality agreements
<!-- FW:REF-START ORIG:(ISA 6.1.2) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 6.1.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.20{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 6.1.2-M1 -->
- **[MUST]** The confidentiality requirements are determined and met.
<!-- REQ 6.1.2-M2 -->
- **[MUST]** Requirements and procedures for applying confidentiality agreements are known to all persons who pass on information requiring protection.
<!-- REQ 6.1.2-M3 -->
- **[MUST]** Valid confidentiality agreements are concluded before information requiring protection is passed on.
<!-- REQ 6.1.2-M4 -->
- **[MUST]** The requirements and procedures for using confidentiality agreements and for handling information requiring protection are reviewed regularly.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 6.1.2-S1 -->
- **[SHOULD]** Templates for confidentiality agreements are available and checked for legal applicability.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 6.1.2-S2 -->
- **[SHOULD]** Confidentiality agreements cover the persons/organisations involved, the type of information, the subject matter, the period of validity and the responsibilities of the obligated party.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 6.1.2-S3 -->
- **[SHOULD]** Confidentiality agreements contain provisions for handling information requiring protection beyond the contractual relationship.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 6.1.2-S4 -->
- **[SHOULD]** Ways to demonstrate compliance (e.g. review by independent third parties or audit rights) are defined.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 6.1.2-S5 -->
- **[SHOULD]** A process for monitoring the period of validity of temporary confidentiality agreements and for timely renewal is defined and implemented.
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.20-1 -->
- **[ISO A.5.20]** Relevant information security requirements are agreed with each supplier and recorded contractually.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 6.1.2 -->
Confidentiality requirements are determined and known; before information requiring protection is passed on, valid NDAs based on reviewed standard templates (process see {{LINK:VA-10}}) (with parties, type of information, subject matter, validity, responsibilities and post-contractual provisions) are concluded and stored in the ISMS tool. Requirements/procedures and periods of validity are monitored regularly, and ways to demonstrate compliance are defined.
### 3.3 Delineation of responsibilities
<!-- FW:REF-START ORIG:(ISA 6.1.3) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 6.1.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.21{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 6.1.3-M1 -->
- **[MUST]** The IT services concerned are identified.
<!-- REQ 6.1.3-M2 -->
- **[MUST]** The security requirements relevant to the IT service are determined.
<!-- REQ 6.1.3-M3 -->
- **[MUST]** The organisation responsible for implementing the requirement is defined and aware of its responsibility.
<!-- REQ 6.1.3-M4 -->
- **[MUST]** Mechanisms for shared responsibilities are specified and implemented.
<!-- REQ 6.1.3-M5 -->
- **[MUST]** The responsible organisation fulfils its respective responsibilities.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 6.1.3-S1 -->
- **[SHOULD]** For IT services, the configuration is designed, implemented and documented on the basis of the necessary security requirements.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 6.1.3-S2 -->
- **[SHOULD]** The responsible personnel is appropriately trained.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 6.1.3-H1 -->
- **[HIGH]** A list of the IT services concerned and the respective responsible IT service providers exists. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 6.1.3-H2 -->
- **[HIGH]** The applicability of the ISA controls has been assessed and documented. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 6.1.3-H3 -->
- **[HIGH]** The service configuration is included in the regular security assessments. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 6.1.3-H4 -->
- **[HIGH]** It is demonstrated that the IT service providers fulfil their responsibility. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 6.1.3-H5 -->
- **[HIGH]** The integration into local protective measures (e.g. secure authentication mechanisms) is established and documented. (C, I, A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.21-1 -->
- **[ISO A.5.21]** Processes to manage information security risks in the ICT product and service supply chain are defined and implemented.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 6.1.3 -->
The IT services concerned and their security requirements are identified; responsibilities between the organisation and external IT service providers (incl. mechanisms for shared responsibility) are defined, known and fulfilled (see {{LINK:VA-10}}); the IT services and service providers concerned are maintained in the register of external IT/cloud/AI services ({{LINK:REG-EXT-SERVICES}}). The configuration is implemented on a requirements basis and documented, and the personnel is trained.
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 6.1.3-elev -->
Where the protection need is high, a list of the IT services and responsible service providers exists, the applicability of the ISA controls is assessed/documented, the service configuration is part of regular security assessments, the fulfilment of responsibility is demonstrated, and the integration into local protective measures is documented.
{{/if}}
## 4. Binding nature
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_ISB}}.
## 5. Roles and responsibilities
| Role | Responsibility in this policy |
|-------|-------------------------------------|
| {{ROLE_ISB}} | Supplier management |
| Procurement | Contractual integration |
## 6. Review and update
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_ISB}} and approved by {{ROLE_MANAGEMENT}}.
## 7. Evidence
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
## 8. Related documents
- Associated procedures: {{LINK:VA-10}}
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- Further: {{LINK:R01}}, {{LINK:R12}}
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->