Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
+250
@@ -0,0 +1,250 @@
|
||||
# Policy Supplier and Service Provider Management
|
||||
|
||||
| Document information | Value |
|
||||
|-----------------------|------|
|
||||
| Document type | Policy |
|
||||
| Scope | {{ISMS_SCOPE}} |
|
||||
| Organisation | {{ORG_NAME}} |
|
||||
| Responsible | {{ROLE_ISB}} |
|
||||
| Approved by | {{ROLE_MANAGEMENT}} |
|
||||
| Version | {{DOC_VERSION}} |
|
||||
| Date | {{DOC_DATE}} |
|
||||
| Status | {{DOC_STATUS}} |
|
||||
|
||||
|
||||
## 1. Purpose
|
||||
|
||||
This policy governs ensuring information security at suppliers, confidentiality agreements and the delineation of responsibilities. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
|
||||
|
||||
## 2. Scope
|
||||
|
||||
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
|
||||
|
||||
## 3. Requirements and implementation
|
||||
|
||||
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
|
||||
|
||||
### 3.1 Information security at suppliers
|
||||
|
||||
<!-- FW:REF-START ORIG:(ISA 6.1.1) -->
|
||||
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 6.1.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.19, A.5.22{{/if}}
|
||||
<!-- FW:REF-END -->
|
||||
|
||||
**Requirement**
|
||||
|
||||
<!-- FW:TISAX-REQ-START -->
|
||||
{{#if FLAG_FW_TISAX}}
|
||||
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
|
||||
|
||||
<!-- REQ 6.1.1-M1 -->
|
||||
- **[MUST]** Contractors and partners are subjected to a security risk assessment.
|
||||
<!-- REQ 6.1.1-M2 -->
|
||||
- **[MUST]** An appropriate level of information security is ensured through contractual agreements with contractors and partners.
|
||||
<!-- REQ 6.1.1-M3 -->
|
||||
- **[MUST]** Where applicable, contractual agreements with clients/customers are passed on to contractors and partners.
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 6.1.1-S1 -->
|
||||
- **[SHOULD]** Contractors and partners are contractually obliged to pass on requirements for an appropriate level of information security to their subcontractors.
|
||||
{{/if}}
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 6.1.1-S2 -->
|
||||
- **[SHOULD]** Performance reports and documents from contractors and partners are reviewed.
|
||||
{{/if}}
|
||||
{{#if FLAG_HIGH_PROTECTION}}
|
||||
<!-- REQ 6.1.1-H1 -->
|
||||
- **[HIGH]** It is demonstrated that the supplier's level of information security is appropriate to the protection need (e.g. reviewed questionnaire/self-disclosure, attestation, certificate, supplier audit). (C, I, A)
|
||||
{{/if}}
|
||||
{{#if FLAG_HIGH_PROTECTION}}
|
||||
<!-- REQ 6.1.1-H2 -->
|
||||
- **[HIGH]** The degree of fulfilment of the required evidence by the supplier is documented, reviewed and monitored regularly and upon changes. (C, I, A)
|
||||
{{/if}}
|
||||
{{#if FLAG_HIGH_PROTECTION}}
|
||||
<!-- REQ 6.1.1-H3 -->
|
||||
- **[HIGH]** The supplier's compliance with contractual agreements is checked, documented, reviewed and monitored regularly and upon changes. (C, I, A)
|
||||
{{/if}}
|
||||
{{#if FLAG_VERY_HIGH_PROTECTION}}
|
||||
<!-- REQ 6.1.1-V1 -->
|
||||
- **[VERY HIGH]** The appropriate level of information security should be demonstrated by a third-party audit (an appropriate TISAX label or similar) or an appropriate supplier audit. Without an audit, management must make a risk-based decision to continue; evidence of this decision exists. (C, I, A)
|
||||
{{/if}}
|
||||
{{#if FLAG_VERY_HIGH_PROTECTION}}
|
||||
<!-- REQ 6.1.1-V2 -->
|
||||
- **[VERY HIGH]** Contractual obligations towards customers regarding transparency of supply chain risks are fulfilled. (C, I, A)
|
||||
{{/if}}
|
||||
{{/if}}
|
||||
<!-- FW:TISAX-REQ-END -->
|
||||
<!-- FW:ISO-REQ-START -->
|
||||
{{#if FLAG_FW_ISO27001}}
|
||||
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
|
||||
|
||||
<!-- REQ A.5.19-1 -->
|
||||
- **[ISO A.5.19]** Processes to manage the information security risks arising from supplier relationships are defined and implemented.
|
||||
<!-- REQ A.5.22-1 -->
|
||||
- **[ISO A.5.22]** The information security of supplier services is monitored and reviewed regularly, and changes are managed.
|
||||
{{/if}}
|
||||
<!-- FW:ISO-REQ-END -->
|
||||
|
||||
**Implementation at {{ORG_NAME}}**
|
||||
|
||||
<!-- IMPL 6.1.1 -->
|
||||
Contractors/partners are subjected to a security risk assessment (BL-SUP-01) and contractually obliged to an appropriate level of information security (incl. passing on to subcontractors and customer requirements); the supplier register is maintained in the ISMS tool ({{TOOL_NAME}}), and performance reports are reviewed (see {{LINK:VA-10}}).
|
||||
|
||||
{{#if FLAG_ELEVATED_PROTECTION}}
|
||||
<!-- IMPL 6.1.1-elev -->
|
||||
Where the protection need is high, the supplier's level of security is demonstrated (self-disclosure/attestation/certificate/audit) and compliance is documented and monitored regularly and upon changes. {{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, the evidence is provided via a third-party audit (TISAX or similar) or a documented risk-based management decision; transparency obligations regarding supply chain risks are fulfilled.{{/if}}
|
||||
{{/if}}
|
||||
|
||||
### 3.2 Confidentiality agreements
|
||||
|
||||
<!-- FW:REF-START ORIG:(ISA 6.1.2) -->
|
||||
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 6.1.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.20{{/if}}
|
||||
<!-- FW:REF-END -->
|
||||
|
||||
**Requirement**
|
||||
|
||||
<!-- FW:TISAX-REQ-START -->
|
||||
{{#if FLAG_FW_TISAX}}
|
||||
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
|
||||
|
||||
<!-- REQ 6.1.2-M1 -->
|
||||
- **[MUST]** The confidentiality requirements are determined and met.
|
||||
<!-- REQ 6.1.2-M2 -->
|
||||
- **[MUST]** Requirements and procedures for applying confidentiality agreements are known to all persons who pass on information requiring protection.
|
||||
<!-- REQ 6.1.2-M3 -->
|
||||
- **[MUST]** Valid confidentiality agreements are concluded before information requiring protection is passed on.
|
||||
<!-- REQ 6.1.2-M4 -->
|
||||
- **[MUST]** The requirements and procedures for using confidentiality agreements and for handling information requiring protection are reviewed regularly.
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 6.1.2-S1 -->
|
||||
- **[SHOULD]** Templates for confidentiality agreements are available and checked for legal applicability.
|
||||
{{/if}}
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 6.1.2-S2 -->
|
||||
- **[SHOULD]** Confidentiality agreements cover the persons/organisations involved, the type of information, the subject matter, the period of validity and the responsibilities of the obligated party.
|
||||
{{/if}}
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 6.1.2-S3 -->
|
||||
- **[SHOULD]** Confidentiality agreements contain provisions for handling information requiring protection beyond the contractual relationship.
|
||||
{{/if}}
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 6.1.2-S4 -->
|
||||
- **[SHOULD]** Ways to demonstrate compliance (e.g. review by independent third parties or audit rights) are defined.
|
||||
{{/if}}
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 6.1.2-S5 -->
|
||||
- **[SHOULD]** A process for monitoring the period of validity of temporary confidentiality agreements and for timely renewal is defined and implemented.
|
||||
{{/if}}
|
||||
{{/if}}
|
||||
<!-- FW:TISAX-REQ-END -->
|
||||
<!-- FW:ISO-REQ-START -->
|
||||
{{#if FLAG_FW_ISO27001}}
|
||||
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
|
||||
|
||||
<!-- REQ A.5.20-1 -->
|
||||
- **[ISO A.5.20]** Relevant information security requirements are agreed with each supplier and recorded contractually.
|
||||
{{/if}}
|
||||
<!-- FW:ISO-REQ-END -->
|
||||
|
||||
**Implementation at {{ORG_NAME}}**
|
||||
|
||||
<!-- IMPL 6.1.2 -->
|
||||
Confidentiality requirements are determined and known; before information requiring protection is passed on, valid NDAs based on reviewed standard templates (process see {{LINK:VA-10}}) (with parties, type of information, subject matter, validity, responsibilities and post-contractual provisions) are concluded and stored in the ISMS tool. Requirements/procedures and periods of validity are monitored regularly, and ways to demonstrate compliance are defined.
|
||||
|
||||
### 3.3 Delineation of responsibilities
|
||||
|
||||
<!-- FW:REF-START ORIG:(ISA 6.1.3) -->
|
||||
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 6.1.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.21{{/if}}
|
||||
<!-- FW:REF-END -->
|
||||
|
||||
**Requirement**
|
||||
|
||||
<!-- FW:TISAX-REQ-START -->
|
||||
{{#if FLAG_FW_TISAX}}
|
||||
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
|
||||
|
||||
<!-- REQ 6.1.3-M1 -->
|
||||
- **[MUST]** The IT services concerned are identified.
|
||||
<!-- REQ 6.1.3-M2 -->
|
||||
- **[MUST]** The security requirements relevant to the IT service are determined.
|
||||
<!-- REQ 6.1.3-M3 -->
|
||||
- **[MUST]** The organisation responsible for implementing the requirement is defined and aware of its responsibility.
|
||||
<!-- REQ 6.1.3-M4 -->
|
||||
- **[MUST]** Mechanisms for shared responsibilities are specified and implemented.
|
||||
<!-- REQ 6.1.3-M5 -->
|
||||
- **[MUST]** The responsible organisation fulfils its respective responsibilities.
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 6.1.3-S1 -->
|
||||
- **[SHOULD]** For IT services, the configuration is designed, implemented and documented on the basis of the necessary security requirements.
|
||||
{{/if}}
|
||||
{{#if FLAG_INCLUDE_SHOULD}}
|
||||
<!-- REQ 6.1.3-S2 -->
|
||||
- **[SHOULD]** The responsible personnel is appropriately trained.
|
||||
{{/if}}
|
||||
{{#if FLAG_HIGH_PROTECTION}}
|
||||
<!-- REQ 6.1.3-H1 -->
|
||||
- **[HIGH]** A list of the IT services concerned and the respective responsible IT service providers exists. (C, I, A)
|
||||
{{/if}}
|
||||
{{#if FLAG_HIGH_PROTECTION}}
|
||||
<!-- REQ 6.1.3-H2 -->
|
||||
- **[HIGH]** The applicability of the ISA controls has been assessed and documented. (C, I, A)
|
||||
{{/if}}
|
||||
{{#if FLAG_HIGH_PROTECTION}}
|
||||
<!-- REQ 6.1.3-H3 -->
|
||||
- **[HIGH]** The service configuration is included in the regular security assessments. (C, I, A)
|
||||
{{/if}}
|
||||
{{#if FLAG_HIGH_PROTECTION}}
|
||||
<!-- REQ 6.1.3-H4 -->
|
||||
- **[HIGH]** It is demonstrated that the IT service providers fulfil their responsibility. (C, I, A)
|
||||
{{/if}}
|
||||
{{#if FLAG_HIGH_PROTECTION}}
|
||||
<!-- REQ 6.1.3-H5 -->
|
||||
- **[HIGH]** The integration into local protective measures (e.g. secure authentication mechanisms) is established and documented. (C, I, A)
|
||||
{{/if}}
|
||||
{{/if}}
|
||||
<!-- FW:TISAX-REQ-END -->
|
||||
<!-- FW:ISO-REQ-START -->
|
||||
{{#if FLAG_FW_ISO27001}}
|
||||
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
|
||||
|
||||
<!-- REQ A.5.21-1 -->
|
||||
- **[ISO A.5.21]** Processes to manage information security risks in the ICT product and service supply chain are defined and implemented.
|
||||
{{/if}}
|
||||
<!-- FW:ISO-REQ-END -->
|
||||
|
||||
**Implementation at {{ORG_NAME}}**
|
||||
|
||||
<!-- IMPL 6.1.3 -->
|
||||
The IT services concerned and their security requirements are identified; responsibilities between the organisation and external IT service providers (incl. mechanisms for shared responsibility) are defined, known and fulfilled (see {{LINK:VA-10}}); the IT services and service providers concerned are maintained in the register of external IT/cloud/AI services ({{LINK:REG-EXT-SERVICES}}). The configuration is implemented on a requirements basis and documented, and the personnel is trained.
|
||||
|
||||
{{#if FLAG_ELEVATED_PROTECTION}}
|
||||
<!-- IMPL 6.1.3-elev -->
|
||||
Where the protection need is high, a list of the IT services and responsible service providers exists, the applicability of the ISA controls is assessed/documented, the service configuration is part of regular security assessments, the fulfilment of responsibility is demonstrated, and the integration into local protective measures is documented.
|
||||
{{/if}}
|
||||
|
||||
## 4. Binding nature
|
||||
|
||||
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_ISB}}.
|
||||
|
||||
## 5. Roles and responsibilities
|
||||
|
||||
| Role | Responsibility in this policy |
|
||||
|-------|-------------------------------------|
|
||||
| {{ROLE_ISB}} | Supplier management |
|
||||
| Procurement | Contractual integration |
|
||||
|
||||
## 6. Review and update
|
||||
|
||||
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_ISB}} and approved by {{ROLE_MANAGEMENT}}.
|
||||
|
||||
## 7. Evidence
|
||||
|
||||
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
|
||||
|
||||
## 8. Related documents
|
||||
|
||||
- Associated procedures: {{LINK:VA-10}}
|
||||
- Technical security baseline: {{LINK:BASELINE}}
|
||||
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
|
||||
- Evidence register: {{LINK:NACHWEISREGISTER}}
|
||||
- Further: {{LINK:R01}}, {{LINK:R12}}
|
||||
|
||||
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->
|
||||
Reference in New Issue
Block a user