Basis: Certvia dev@a48c5fb als Fundament für Craftvia
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s

Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-09-14 11:05:39 +02:00
co-authored by Claude Opus 5
commit c8e6f30a27
720 changed files with 140143 additions and 0 deletions
@@ -0,0 +1,70 @@
# Information Security in Projects
| Document information | Value |
|-----------------------|------|
| Document type | Procedure instruction (VA-19) |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Process owner | {{ROLE_ISB}} |
| Approved by | {{ROLE_ISB}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
<!-- FULFILLS 1.2.3-M1, 1.2.3-S1, 1.2.3-S2, 1.2.3-S3, 1.2.3-H1, A.5.8-1 | POLICY R01 -->
## 1. Purpose
This procedure ensures that information security is taken into account in projects from the outset: project classification, risk assessment in an early phase and upon changes, derivation and tracking of measures as well as involvement of the ISO where the protection need is elevated. It operationalises the associated policy ({{LINK:R01}}).
## 2. Scope
Applies within the ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}) for all projects relating to information, IT systems or business processes.
## 3. Trigger
Project start, substantial project change, project completion.
## 4. Inputs
- Catalogue of criteria for project classification ({{LINK:BASELINE}}, BL-PROJ-01)
- Project register ({{LINK:REG-PROJECTS}})
- Risk assessment scale / risk register
## 5. Process
1. At the outset, classify the project with regard to its information security need on the basis of the **documented catalogue of criteria (BL-PROJ-01)**; entry in the **project register ({{LINK:REG-PROJECTS}})**.
2. Carry out a risk assessment in an early project phase and upon changes (coupling with risk management {{LINK:VA-09}}).
3. Derive measures and track them as tasks in {{TOOL_TICKET}}.
4. {{#if FLAG_ELEVATED_PROTECTION}} Where the protection need is elevated, {{ROLE_ISB}} is involved; additional reviews/approvals take place before critical milestones.{{/if}}
5. Before project completion, review the implementation of the measures and document it in the project register.
## 6. RACI
| # | Step | R (Execution) | A (Accountable) | C (Consulted) | I (Informed) |
|---|---------|------------------|------------------|-----------------|----------------|
| 1 | Classify the project | Project management | {{ROLE_ISB}} | {{ROLE_ISB}} | - |
| 2 | Carry out risk assessment | Project management | {{ROLE_ISB}} | {{ROLE_IT_LEAD}} | - |
| 3 | Derive & track measures | Project management | Project management | {{ROLE_ISB}} | - |
| 4 | ISO involvement (elevated protection need) | {{ROLE_ISB}} | {{ROLE_ISB}} | Project management | {{ROLE_MANAGEMENT}} |
| 5 | Final review of measures | Project management | {{ROLE_ISB}} | - | - |
## 7. Result & evidence
Maintained project register with classification, risk assessment and measure status. Evidence is referenced in the central evidence register ({{LINK:NACHWEISREGISTER}}).
## 8. Key performance indicators (KPI)
- Share of classified projects
- Open project security measures
- Share of projects with ISO involvement where the protection need is elevated
## 9. Related documents
- Associated policy: {{LINK:R01}}
- Register: {{LINK:REG-PROJECTS}}
- Risk management procedure: {{LINK:VA-09}}
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
<!-- Erfüllt die oben unter FULFILLS gelisteten Anforderungen; Kopplung in mapping.json. Im Lesemodus nicht sichtbar. -->