{ "meta": { "paket": "ISMS-Vorlagenpaket v2 — Framework-Mapping ISO/IEC 27001:2022", "standard": "ISO/IEC 27001:2022 (Kap. 4-10 + Anhang A)", "framework": "ISO_27001", "version": "2.1", "bibliothek": "gemeinsam mit dem VDA-ISA-Mapping (mapping.json) — ein Dokumentensatz, zwei Mappings", "hinweis": "Anforderungstexte sind eigene Paraphrasen (keine woertlichen Normzitate); die Referenzen sind exakt zum Nachschlagen. Der Umsetzungstext wird ueber impl_anchor aus dem jeweiligen Richtlinienabschnitt aufgeloest und ist mit dem VDA-ISA-Mapping geteilt.", "coverage": "27 Klausel-Anforderungen (Kap. 4-10) + 93 Anhang-A-Controls = 120 Eintraege" }, "anforderungen": [ { "id": "4.1-1", "policy": "R01", "control": "4.1", "kind": "clause", "title": "Understanding the organisation and its context", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 4.1-1", "impl_anchor": "IMPL ISO-MS-KONTEXT", "requirement": "Internal and external issues that affect the ability to achieve the ISMS objectives are determined and kept up to date.", "link": "{{LINK:R01#ISO-MS-KONTEXT}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.2-1", "policy": "R01", "control": "4.2", "kind": "clause", "title": "Needs of interested parties", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 4.2-1", "impl_anchor": "IMPL ISO-MS-KONTEXT", "requirement": "The interested parties relevant to the ISMS and their information security requirements are determined.", "link": "{{LINK:R01#ISO-MS-KONTEXT}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.3-1", "policy": "R01", "control": "4.3", "kind": "clause", "title": "Scope of the ISMS", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 4.3-1", "impl_anchor": "IMPL ISO-MS-KONTEXT", "requirement": "The scope of the ISMS is determined considering the issues, requirements and interfaces, and maintained as documented information.", "link": "{{LINK:R01#ISO-MS-KONTEXT}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.4-1", "policy": "R01", "control": "4.4", "kind": "clause", "title": "Information security management system", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 4.4-1", "impl_anchor": "IMPL ISO-MS-KONTEXT", "requirement": "An ISMS is established, implemented, maintained and continually improved.", "link": "{{LINK:R01#ISO-MS-KONTEXT}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.1-1", "policy": "R01", "control": "5.1", "kind": "clause", "title": "Leadership and commitment", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 5.1-1", "impl_anchor": "IMPL 1.2.1", "requirement": "Top management demonstrates leadership and commitment with respect to the ISMS.", "link": "{{LINK:R01#1.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2-1", "policy": "L00", "control": "5.2", "kind": "clause", "title": "Information security policy", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 5.2-1", "impl_anchor": "IMPL ISO-LEITLINIE", "requirement": "An information security policy is established that fits the organisation, sets objectives, commits to meeting requirements and to continual improvement, and is communicated and available.", "link": "{{LINK:L00#ISO-LEITLINIE}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.3-1", "policy": "R01", "control": "5.3", "kind": "clause", "title": "Roles, responsibilities and authorities", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 5.3-1", "impl_anchor": "IMPL 1.2.2", "requirement": "Responsibilities and authorities for security-relevant roles are assigned and communicated.", "link": "{{LINK:R01#1.2.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.1-1", "policy": "R03", "control": "6.1.1", "kind": "clause", "title": "Actions to address risks and opportunities", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 6.1.1-1", "impl_anchor": "IMPL 1.4.1", "requirement": "When planning the ISMS, risks and opportunities that need to be addressed are determined.", "link": "{{LINK:R03#1.4.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-09" ] }, { "id": "6.1.2-1", "policy": "R03", "control": "6.1.2", "kind": "clause", "title": "Information security risk assessment", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 6.1.2-1", "impl_anchor": "IMPL 1.4.1", "requirement": "A risk assessment process with defined criteria is established and applied so that it is repeatable and produces comparable results.", "link": "{{LINK:R03#1.4.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-09" ] }, { "id": "6.1.3-1", "policy": "R03", "control": "6.1.3", "kind": "clause", "title": "Information security risk treatment", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 6.1.3-1", "impl_anchor": "IMPL ISO-SOA", "requirement": "A risk treatment process is defined; necessary controls are determined and compared against Annex A in a Statement of Applicability.", "link": "{{LINK:R03#ISO-SOA}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-09" ] }, { "id": "6.2-1", "policy": "L00", "control": "6.2", "kind": "clause", "title": "Information security objectives and planning", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 6.2-1", "impl_anchor": "IMPL ISO-LEITLINIE", "requirement": "Information security objectives are established for relevant functions and levels, and their achievement is planned.", "link": "{{LINK:L00#ISO-LEITLINIE}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.3-1", "policy": "R01", "control": "6.3", "kind": "clause", "title": "Planning of changes", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 6.3-1", "impl_anchor": "IMPL ISO-MS-CHANGE", "requirement": "Changes to the ISMS are carried out in a planned manner.", "link": "{{LINK:R01#ISO-MS-CHANGE}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "7.1-1", "policy": "R01", "control": "7.1", "kind": "clause", "title": "Resources", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 7.1-1", "impl_anchor": "IMPL 1.2.2", "requirement": "The resources needed for the ISMS are determined and provided.", "link": "{{LINK:R01#1.2.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "7.2-1", "policy": "R05", "control": "7.2", "kind": "clause", "title": "Competence", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 7.2-1", "impl_anchor": "IMPL 2.1.1", "requirement": "The necessary competence is determined and ensured; corresponding evidence is retained.", "link": "{{LINK:R05#2.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "7.3-1", "policy": "R05", "control": "7.3", "kind": "clause", "title": "Awareness", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 7.3-1", "impl_anchor": "IMPL 2.1.3", "requirement": "Persons under the organisation's control are aware of the policy, their contribution and the consequences of non-conformance.", "link": "{{LINK:R05#2.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-12" ] }, { "id": "7.4-1", "policy": "L00", "control": "7.4", "kind": "clause", "title": "Communication", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 7.4-1", "impl_anchor": "IMPL ISO-LEITLINIE", "requirement": "The internal and external communications relevant to the ISMS are determined.", "link": "{{LINK:L00#ISO-LEITLINIE}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "7.5.1-1", "policy": "R01", "control": "7.5.1", "kind": "clause", "title": "Documented information — general", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 7.5.1-1", "impl_anchor": "IMPL ISO-MS-DOKU", "requirement": "The ISMS includes the documented information required by the standard and that determined as necessary.", "link": "{{LINK:R01#ISO-MS-DOKU}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "7.5.2-1", "policy": "R01", "control": "7.5.2", "kind": "clause", "title": "Creating and updating", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 7.5.2-1", "impl_anchor": "IMPL ISO-MS-DOKU", "requirement": "When creating and updating documented information, identification, format and medium as well as review and approval are ensured.", "link": "{{LINK:R01#ISO-MS-DOKU}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "7.5.3-1", "policy": "R01", "control": "7.5.3", "kind": "clause", "title": "Control of documented information", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 7.5.3-1", "impl_anchor": "IMPL ISO-MS-DOKU", "requirement": "Documented information is controlled: availability, protection, distribution, access, retention and change control.", "link": "{{LINK:R01#ISO-MS-DOKU}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "8.1-1", "policy": "R03", "control": "8.1", "kind": "clause", "title": "Operational planning and control", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 8.1-1", "impl_anchor": "IMPL ISO-MS-BETRIEB", "requirement": "The processes needed to meet the requirements are planned, implemented and controlled; planned changes are controlled.", "link": "{{LINK:R03#ISO-MS-BETRIEB}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "8.2-1", "policy": "R03", "control": "8.2", "kind": "clause", "title": "Information security risk assessment (performance)", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 8.2-1", "impl_anchor": "IMPL 1.4.1", "requirement": "Risk assessments are performed at planned intervals and upon significant change, and are documented.", "link": "{{LINK:R03#1.4.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-09" ] }, { "id": "8.3-1", "policy": "R03", "control": "8.3", "kind": "clause", "title": "Information security risk treatment (performance)", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 8.3-1", "impl_anchor": "IMPL 1.4.1", "requirement": "The risk treatment plan is implemented and the results are documented.", "link": "{{LINK:R03#1.4.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-09" ] }, { "id": "9.1-1", "policy": "R03", "control": "9.1", "kind": "clause", "title": "Monitoring, measurement, analysis and evaluation", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 9.1-1", "impl_anchor": "IMPL ISO-MS-MESSUNG", "requirement": "The information security performance and the effectiveness of the ISMS are monitored, measured, analysed and evaluated.", "link": "{{LINK:R03#ISO-MS-MESSUNG}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-22" ] }, { "id": "9.2-1", "policy": "R03", "control": "9.2", "kind": "clause", "title": "Internal audit", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 9.2-1", "impl_anchor": "IMPL 1.5.2", "requirement": "Internal audits are conducted at planned intervals to verify conformity and effective implementation of the ISMS.", "link": "{{LINK:R03#1.5.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-15" ] }, { "id": "9.3-1", "policy": "R03", "control": "9.3", "kind": "clause", "title": "Management review", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 9.3-1", "impl_anchor": "IMPL ISO-MS-MGMTREVIEW", "requirement": "Top management reviews the ISMS at planned intervals.", "link": "{{LINK:R03#ISO-MS-MGMTREVIEW}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-22" ] }, { "id": "10.1-1", "policy": "R03", "control": "10.1", "kind": "clause", "title": "Continual improvement", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 10.1-1", "impl_anchor": "IMPL ISO-MS-CAPA", "requirement": "The suitability, adequacy and effectiveness of the ISMS are continually improved.", "link": "{{LINK:R03#ISO-MS-CAPA}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-21" ] }, { "id": "10.2-1", "policy": "R03", "control": "10.2", "kind": "clause", "title": "Nonconformity and corrective action", "type": "MUSS", "soa_relevant": false, "applicable": true, "condition": null, "req_anchor": "REQ 10.2-1", "impl_anchor": "IMPL ISO-MS-CAPA", "requirement": "In the event of nonconformity, corrections are made and corrective actions are taken to eliminate the causes.", "link": "{{LINK:R03#ISO-MS-CAPA}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-21" ] }, { "id": "A.5.1-1", "policy": "L00", "control": "A.5.1", "kind": "control", "title": "Policies for information security", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.1-1", "impl_anchor": "IMPL ISO-LEITLINIE", "requirement": "The information security policy and topic-specific policies are defined, approved by management, published, communicated, acknowledged and reviewed at planned intervals.", "link": "{{LINK:L00#ISO-LEITLINIE}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "A.5.2-1", "policy": "R01", "control": "A.5.2", "kind": "control", "title": "Information security roles and responsibilities", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.2-1", "impl_anchor": "IMPL 1.2.2", "requirement": "Information security roles and responsibilities are defined and allocated.", "link": "{{LINK:R01#1.2.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "A.5.3-1", "policy": "R01", "control": "A.5.3", "kind": "control", "title": "Segregation of duties", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.3-1", "impl_anchor": "IMPL 1.2.2", "requirement": "Conflicting duties and areas of responsibility are segregated to reduce unauthorised or unintentional modification and misuse.", "link": "{{LINK:R01#1.2.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "A.5.4-1", "policy": "R01", "control": "A.5.4", "kind": "control", "title": "Management responsibilities", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.4-1", "impl_anchor": "IMPL 1.2.1", "requirement": "Management requires all personnel to apply information security in accordance with the established requirements.", "link": "{{LINK:R01#1.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "A.5.5-1", "policy": "R01", "control": "A.5.5", "kind": "control", "title": "Contact with authorities", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.5-1", "impl_anchor": "IMPL ISO-KONTAKTE", "requirement": "Appropriate contacts with relevant authorities are established and maintained.", "link": "{{LINK:R01#ISO-KONTAKTE}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "A.5.6-1", "policy": "R01", "control": "A.5.6", "kind": "control", "title": "Contact with special interest groups", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.6-1", "impl_anchor": "IMPL ISO-KONTAKTE", "requirement": "Appropriate contacts with special interest groups, professional forums and security associations are maintained.", "link": "{{LINK:R01#ISO-KONTAKTE}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "A.5.7-1", "policy": "R10", "control": "A.5.7", "kind": "control", "title": "Threat intelligence", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.7-1", "impl_anchor": "IMPL ISO-THREATINTEL", "requirement": "Information on threats is collected and analysed to produce and use threat intelligence.", "link": "{{LINK:R10#ISO-THREATINTEL}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "A.5.8-1", "policy": "R01", "control": "A.5.8", "kind": "control", "title": "Information security in project management", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.8-1", "impl_anchor": "IMPL 1.2.3", "requirement": "Information security is integrated into project management.", "link": "{{LINK:R01#1.2.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-19" ] }, { "id": "A.5.9-1", "policy": "R02", "control": "A.5.9", "kind": "control", "title": "Inventory of information and other associated assets", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.9-1", "impl_anchor": "IMPL 1.3.1", "requirement": "An inventory of information and associated assets, including owners, is established and maintained.", "link": "{{LINK:R02#1.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-08" ] }, { "id": "A.5.10-1", "policy": "R02", "control": "A.5.10", "kind": "control", "title": "Acceptable use of information and other associated assets", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.10-1", "impl_anchor": "IMPL 1.3.3", "requirement": "Rules for the acceptable use and handling of information and assets are defined, documented and implemented.", "link": "{{LINK:R02#1.3.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-08" ] }, { "id": "A.5.11-1", "policy": "R11", "control": "A.5.11", "kind": "control", "title": "Return of assets", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.11-1", "impl_anchor": "IMPL 5.3.3", "requirement": "Personnel and external users return all assets in their possession upon termination of employment or contract.", "link": "{{LINK:R11#5.3.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-08" ] }, { "id": "A.5.12-1", "policy": "R02", "control": "A.5.12", "kind": "control", "title": "Classification of information", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.12-1", "impl_anchor": "IMPL 1.3.2", "requirement": "Information is classified according to its protection needs (confidentiality, integrity, availability).", "link": "{{LINK:R02#1.3.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-08" ] }, { "id": "A.5.13-1", "policy": "R02", "control": "A.5.13", "kind": "control", "title": "Labelling of information", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.13-1", "impl_anchor": "IMPL 1.3.2", "requirement": "Procedures for labelling information in accordance with the classification scheme are developed and implemented.", "link": "{{LINK:R02#1.3.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-08" ] }, { "id": "A.5.14-1", "policy": "R09", "control": "A.5.14", "kind": "control", "title": "Information transfer", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.14-1", "impl_anchor": "IMPL 5.1.2", "requirement": "Rules, procedures and agreements for the secure transfer of information are established for all transfer channels in use.", "link": "{{LINK:R09#5.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "A.5.15-1", "policy": "R08", "control": "A.5.15", "kind": "control", "title": "Access control", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.15-1", "impl_anchor": "IMPL 4.2.1", "requirement": "Rules to control physical and logical access to information and assets are established and implemented on the basis of business and information security requirements.", "link": "{{LINK:R08#4.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-03" ] }, { "id": "A.5.16-1", "policy": "R08", "control": "A.5.16", "kind": "control", "title": "Identity management", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.16-1", "impl_anchor": "IMPL 4.1.1", "requirement": "The full life cycle of identities is managed.", "link": "{{LINK:R08#4.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-03" ] }, { "id": "A.5.17-1", "policy": "R08", "control": "A.5.17", "kind": "control", "title": "Authentication information", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.17-1", "impl_anchor": "IMPL 4.1.3", "requirement": "Allocation and management of authentication information is controlled by a suitable management process.", "link": "{{LINK:R08#4.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-03" ] }, { "id": "A.5.18-1", "policy": "R08", "control": "A.5.18", "kind": "control", "title": "Access rights", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.18-1", "impl_anchor": "IMPL 4.2.1", "requirement": "Access rights are provisioned, reviewed, modified and removed in accordance with the access control policy.", "link": "{{LINK:R08#4.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-03" ] }, { "id": "A.5.19-1", "policy": "R13", "control": "A.5.19", "kind": "control", "title": "Information security in supplier relationships", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.19-1", "impl_anchor": "IMPL 6.1.1", "requirement": "Processes to manage the information security risks arising from supplier relationships are defined and implemented.", "link": "{{LINK:R13#6.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-10" ] }, { "id": "A.5.20-1", "policy": "R13", "control": "A.5.20", "kind": "control", "title": "Addressing information security within supplier agreements", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.20-1", "impl_anchor": "IMPL 6.1.2", "requirement": "Relevant information security requirements are agreed with each supplier and recorded contractually.", "link": "{{LINK:R13#6.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-10" ] }, { "id": "A.5.21-1", "policy": "R13", "control": "A.5.21", "kind": "control", "title": "Managing information security in the ICT supply chain", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.21-1", "impl_anchor": "IMPL 6.1.3", "requirement": "Processes to manage information security risks in the ICT product and service supply chain are defined and implemented.", "link": "{{LINK:R13#6.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-10" ] }, { "id": "A.5.22-1", "policy": "R13", "control": "A.5.22", "kind": "control", "title": "Monitoring, review and change management of supplier services", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.22-1", "impl_anchor": "IMPL 6.1.1", "requirement": "The information security of supplier services is monitored and reviewed regularly, and changes are managed.", "link": "{{LINK:R13#6.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-10" ] }, { "id": "A.5.23-1", "policy": "R12", "control": "A.5.23", "kind": "control", "title": "Information security for use of cloud services", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": "FLAG_CLOUD_USED", "req_anchor": "REQ A.5.23-1", "impl_anchor": "IMPL 5.3.4", "requirement": "Processes for acquisition, use, management and exit of cloud services are established in line with the information security requirements.", "link": "{{LINK:R12#5.3.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-11" ] }, { "id": "A.5.24-1", "policy": "R04", "control": "A.5.24", "kind": "control", "title": "Information security incident management planning and preparation", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.24-1", "impl_anchor": "IMPL 1.6.1", "requirement": "The management of information security incidents is planned and prepared (roles, processes, responsibilities).", "link": "{{LINK:R04#1.6.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-01" ] }, { "id": "A.5.25-1", "policy": "R04", "control": "A.5.25", "kind": "control", "title": "Assessment and decision on information security events", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.25-1", "impl_anchor": "IMPL 1.6.2", "requirement": "Information security events are assessed and a decision is taken whether they are to be categorised as incidents.", "link": "{{LINK:R04#1.6.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-01" ] }, { "id": "A.5.26-1", "policy": "R04", "control": "A.5.26", "kind": "control", "title": "Response to information security incidents", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.26-1", "impl_anchor": "IMPL 1.6.2", "requirement": "Information security incidents are responded to in accordance with documented procedures.", "link": "{{LINK:R04#1.6.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-01" ] }, { "id": "A.5.27-1", "policy": "R04", "control": "A.5.27", "kind": "control", "title": "Learning from information security incidents", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.27-1", "impl_anchor": "IMPL 1.6.2", "requirement": "Knowledge gained from information security incidents is used to strengthen the controls.", "link": "{{LINK:R04#1.6.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-01" ] }, { "id": "A.5.28-1", "policy": "R04", "control": "A.5.28", "kind": "control", "title": "Collection of evidence", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.28-1", "impl_anchor": "IMPL 1.6.2", "requirement": "Procedures for the identification, collection, acquisition and preservation of evidence relating to incidents are established and implemented.", "link": "{{LINK:R04#1.6.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-01" ] }, { "id": "A.5.29-1", "policy": "R04", "control": "A.5.29", "kind": "control", "title": "Information security during disruption", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.29-1", "impl_anchor": "IMPL 1.6.3", "requirement": "The maintenance of information security during disruption is planned and implemented.", "link": "{{LINK:R04#1.6.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-02" ] }, { "id": "A.5.30-1", "policy": "R04", "control": "A.5.30", "kind": "control", "title": "ICT readiness for business continuity", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.30-1", "impl_anchor": "IMPL 5.2.8", "requirement": "ICT readiness is planned, implemented and tested on the basis of the business continuity objectives and requirements.", "link": "{{LINK:R04#5.2.8}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-02" ] }, { "id": "A.5.31-1", "policy": "R14", "control": "A.5.31", "kind": "control", "title": "Legal, statutory, regulatory and contractual requirements", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.31-1", "impl_anchor": "IMPL 7.1.1", "requirement": "Legal, statutory, regulatory and contractual information security requirements are identified, documented and kept up to date.", "link": "{{LINK:R14#7.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-18" ] }, { "id": "A.5.32-1", "policy": "R14", "control": "A.5.32", "kind": "control", "title": "Intellectual property rights", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.32-1", "impl_anchor": "IMPL 7.1.1", "requirement": "Appropriate procedures to protect intellectual property rights are implemented.", "link": "{{LINK:R14#7.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-18" ] }, { "id": "A.5.33-1", "policy": "R14", "control": "A.5.33", "kind": "control", "title": "Protection of records", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.33-1", "impl_anchor": "IMPL 7.1.1", "requirement": "Records are protected against loss, destruction, falsification, unauthorised access and unauthorised release.", "link": "{{LINK:R14#7.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-18" ] }, { "id": "A.5.34-1", "policy": "R14", "control": "A.5.34", "kind": "control", "title": "Privacy and protection of PII", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": "FLAG_PERSONAL_DATA", "req_anchor": "REQ A.5.34-1", "impl_anchor": "IMPL 7.1.2", "requirement": "Requirements for the protection of personally identifiable information are identified and met in accordance with applicable obligations.", "link": "{{LINK:R14#7.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-18" ] }, { "id": "A.5.35-1", "policy": "R03", "control": "A.5.35", "kind": "control", "title": "Independent review of information security", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.35-1", "impl_anchor": "IMPL 1.5.2", "requirement": "The organisation's approach to managing information security is reviewed independently at planned intervals.", "link": "{{LINK:R03#1.5.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-15" ] }, { "id": "A.5.36-1", "policy": "R03", "control": "A.5.36", "kind": "control", "title": "Compliance with policies, rules and standards for information security", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.36-1", "impl_anchor": "IMPL 1.5.1", "requirement": "Compliance with the information security policy, topic-specific policies, rules and standards is reviewed regularly.", "link": "{{LINK:R03#1.5.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-15" ] }, { "id": "A.5.37-1", "policy": "R10", "control": "A.5.37", "kind": "control", "title": "Documented operating procedures", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.5.37-1", "impl_anchor": "IMPL ISO-BETRIEBSABLAEUFE", "requirement": "Operating procedures for information processing facilities are documented and made available to the personnel concerned.", "link": "{{LINK:R10#ISO-BETRIEBSABLAEUFE}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "A.6.1-1", "policy": "R05", "control": "A.6.1", "kind": "control", "title": "Screening", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.6.1-1", "impl_anchor": "IMPL 2.1.1", "requirement": "Background verification of candidates is carried out appropriately to the business requirements and in accordance with the law.", "link": "{{LINK:R05#2.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-14" ] }, { "id": "A.6.2-1", "policy": "R05", "control": "A.6.2", "kind": "control", "title": "Terms and conditions of employment", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.6.2-1", "impl_anchor": "IMPL 2.1.2", "requirement": "The employment agreements state the responsibilities for information security.", "link": "{{LINK:R05#2.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-14" ] }, { "id": "A.6.3-1", "policy": "R05", "control": "A.6.3", "kind": "control", "title": "Information security awareness, education and training", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.6.3-1", "impl_anchor": "IMPL 2.1.3", "requirement": "Personnel receive appropriate awareness, education and training as well as regular updates of the relevant policies.", "link": "{{LINK:R05#2.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-12" ] }, { "id": "A.6.4-1", "policy": "R05", "control": "A.6.4", "kind": "control", "title": "Disciplinary process", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.6.4-1", "impl_anchor": "IMPL ISO-DISZIPLIN", "requirement": "A disciplinary process for information security violations is established and communicated.", "link": "{{LINK:R05#ISO-DISZIPLIN}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "A.6.5-1", "policy": "R05", "control": "A.6.5", "kind": "control", "title": "Responsibilities after termination or change of employment", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.6.5-1", "impl_anchor": "IMPL 2.1.2", "requirement": "Continuing information security responsibilities after termination or change of employment are defined and enforced.", "link": "{{LINK:R05#2.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-14" ] }, { "id": "A.6.6-1", "policy": "R05", "control": "A.6.6", "kind": "control", "title": "Confidentiality or non-disclosure agreements", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.6.6-1", "impl_anchor": "IMPL 2.1.2", "requirement": "Confidentiality or non-disclosure agreements are identified, documented and reviewed regularly.", "link": "{{LINK:R05#2.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-14" ] }, { "id": "A.6.7-1", "policy": "R06", "control": "A.6.7", "kind": "control", "title": "Remote working", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": "FLAG_MOBILE_WORK", "req_anchor": "REQ A.6.7-1", "impl_anchor": "IMPL 2.1.4", "requirement": "Security measures for working outside the organisation's premises are implemented.", "link": "{{LINK:R06#2.1.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "A.6.8-1", "policy": "R04", "control": "A.6.8", "kind": "control", "title": "Information security event reporting", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.6.8-1", "impl_anchor": "IMPL 1.6.1", "requirement": "A mechanism for the timely reporting of observed or suspected information security events is provided.", "link": "{{LINK:R04#1.6.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-01" ] }, { "id": "A.7.1-1", "policy": "R07", "control": "A.7.1", "kind": "control", "title": "Physical security perimeters", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.7.1-1", "impl_anchor": "IMPL 3.1.1", "requirement": "Security perimeters are defined and used to protect areas containing information and assets.", "link": "{{LINK:R07#3.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-17" ] }, { "id": "A.7.2-1", "policy": "R07", "control": "A.7.2", "kind": "control", "title": "Physical entry", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.7.2-1", "impl_anchor": "IMPL 3.1.1", "requirement": "Secure entry controls and entry points are established to restrict access to authorised persons.", "link": "{{LINK:R07#3.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-17" ] }, { "id": "A.7.3-1", "policy": "R07", "control": "A.7.3", "kind": "control", "title": "Securing offices, rooms and facilities", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.7.3-1", "impl_anchor": "IMPL 3.1.1", "requirement": "Physical security for offices, rooms and facilities is designed and implemented.", "link": "{{LINK:R07#3.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-17" ] }, { "id": "A.7.4-1", "policy": "R07", "control": "A.7.4", "kind": "control", "title": "Physical security monitoring", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.7.4-1", "impl_anchor": "IMPL 3.1.1", "requirement": "Premises are continuously monitored for unauthorised physical access.", "link": "{{LINK:R07#3.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-17" ] }, { "id": "A.7.5-1", "policy": "R07", "control": "A.7.5", "kind": "control", "title": "Protecting against physical and environmental threats", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.7.5-1", "impl_anchor": "IMPL ISO-PHY-UMWELT", "requirement": "Protection against physical and environmental threats is designed and implemented.", "link": "{{LINK:R07#ISO-PHY-UMWELT}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-17" ] }, { "id": "A.7.6-1", "policy": "R07", "control": "A.7.6", "kind": "control", "title": "Working in secure areas", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.7.6-1", "impl_anchor": "IMPL 3.1.1", "requirement": "Measures for working in secure areas are defined and implemented.", "link": "{{LINK:R07#3.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-17" ] }, { "id": "A.7.7-1", "policy": "R07", "control": "A.7.7", "kind": "control", "title": "Clear desk and clear screen", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.7.7-1", "impl_anchor": "IMPL ISO-PHY-CLEARDESK", "requirement": "Rules for a clear desk and locked screens are defined and implemented.", "link": "{{LINK:R07#ISO-PHY-CLEARDESK}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-17" ] }, { "id": "A.7.8-1", "policy": "R07", "control": "A.7.8", "kind": "control", "title": "Equipment siting and protection", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.7.8-1", "impl_anchor": "IMPL ISO-PHY-UMWELT", "requirement": "Equipment is sited securely and protected.", "link": "{{LINK:R07#ISO-PHY-UMWELT}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-17" ] }, { "id": "A.7.9-1", "policy": "R06", "control": "A.7.9", "kind": "control", "title": "Security of assets off-premises", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": "FLAG_MOBILE_DEVICES", "req_anchor": "REQ A.7.9-1", "impl_anchor": "IMPL 3.1.4", "requirement": "Assets used outside the premises are protected.", "link": "{{LINK:R06#3.1.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "A.7.10-1", "policy": "R06", "control": "A.7.10", "kind": "control", "title": "Storage media", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.7.10-1", "impl_anchor": "IMPL 3.1.4", "requirement": "Storage media are protected throughout their life cycle (acquisition, use, transport, disposal) in accordance with the classification scheme.", "link": "{{LINK:R06#3.1.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-08" ] }, { "id": "A.7.11-1", "policy": "R07", "control": "A.7.11", "kind": "control", "title": "Supporting utilities", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.7.11-1", "impl_anchor": "IMPL ISO-PHY-UMWELT", "requirement": "Facilities are protected against failure and disruption of supporting utilities such as power and air conditioning.", "link": "{{LINK:R07#ISO-PHY-UMWELT}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-17" ] }, { "id": "A.7.12-1", "policy": "R07", "control": "A.7.12", "kind": "control", "title": "Cabling security", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.7.12-1", "impl_anchor": "IMPL ISO-PHY-UMWELT", "requirement": "Power and data cabling is protected against interception, interference and damage.", "link": "{{LINK:R07#ISO-PHY-UMWELT}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-17" ] }, { "id": "A.7.13-1", "policy": "R07", "control": "A.7.13", "kind": "control", "title": "Equipment maintenance", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.7.13-1", "impl_anchor": "IMPL ISO-PHY-UMWELT", "requirement": "Equipment is maintained properly to ensure availability and integrity.", "link": "{{LINK:R07#ISO-PHY-UMWELT}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-04" ] }, { "id": "A.7.14-1", "policy": "R11", "control": "A.7.14", "kind": "control", "title": "Secure disposal or re-use of equipment", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.7.14-1", "impl_anchor": "IMPL 5.3.3", "requirement": "Equipment containing storage media is securely sanitised before disposal or re-use.", "link": "{{LINK:R11#5.3.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-08" ] }, { "id": "A.8.1-1", "policy": "R06", "control": "A.8.1", "kind": "control", "title": "User endpoint devices", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.1-1", "impl_anchor": "IMPL 3.1.4", "requirement": "Information stored on, processed by or accessible via user endpoint devices is protected.", "link": "{{LINK:R06#3.1.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "A.8.2-1", "policy": "R08", "control": "A.8.2", "kind": "control", "title": "Privileged access rights", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.2-1", "impl_anchor": "IMPL 4.2.1", "requirement": "The allocation and use of privileged access rights is restricted and closely managed.", "link": "{{LINK:R08#4.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-03" ] }, { "id": "A.8.3-1", "policy": "R08", "control": "A.8.3", "kind": "control", "title": "Information access restriction", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.3-1", "impl_anchor": "IMPL 4.2.1", "requirement": "Access to information and application functions is restricted in accordance with the access control policy.", "link": "{{LINK:R08#4.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-03" ] }, { "id": "A.8.4-1", "policy": "R11", "control": "A.8.4", "kind": "control", "title": "Access to source code", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": "FLAG_DEV_INHOUSE", "req_anchor": "REQ A.8.4-1", "impl_anchor": "IMPL 5.3.1", "requirement": "Read and write access to source code, development tools and software libraries is appropriately managed.", "link": "{{LINK:R11#5.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "A.8.5-1", "policy": "R08", "control": "A.8.5", "kind": "control", "title": "Secure authentication", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.5-1", "impl_anchor": "IMPL 4.1.2", "requirement": "Secure authentication technologies and procedures are used on the basis of the access restrictions and the access control policy.", "link": "{{LINK:R08#4.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-03" ] }, { "id": "A.8.6-1", "policy": "R10", "control": "A.8.6", "kind": "control", "title": "Capacity management", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.6-1", "impl_anchor": "IMPL ISO-KAPAZITAET", "requirement": "Resources are monitored and capacity is adjusted to current and expected demand.", "link": "{{LINK:R10#ISO-KAPAZITAET}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "A.8.7-1", "policy": "R10", "control": "A.8.7", "kind": "control", "title": "Protection against malware", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.7-1", "impl_anchor": "IMPL 5.2.3", "requirement": "Protection against malware is implemented and supported by appropriate user awareness.", "link": "{{LINK:R10#5.2.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "A.8.8-1", "policy": "R10", "control": "A.8.8", "kind": "control", "title": "Management of technical vulnerabilities", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.8-1", "impl_anchor": "IMPL 5.2.5", "requirement": "Information on technical vulnerabilities is obtained, exposure is evaluated and appropriate measures are taken.", "link": "{{LINK:R10#5.2.5}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-06" ] }, { "id": "A.8.9-1", "policy": "R10", "control": "A.8.9", "kind": "control", "title": "Configuration management", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.9-1", "impl_anchor": "IMPL 5.2.1", "requirement": "Configurations of hardware, software, services and networks are established, documented, implemented, monitored and reviewed.", "link": "{{LINK:R10#5.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-04" ] }, { "id": "A.8.10-1", "policy": "R11", "control": "A.8.10", "kind": "control", "title": "Information deletion", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.10-1", "impl_anchor": "IMPL 5.3.3", "requirement": "Information stored in systems and on media is deleted when no longer required.", "link": "{{LINK:R11#5.3.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-08" ] }, { "id": "A.8.11-1", "policy": "R02", "control": "A.8.11", "kind": "control", "title": "Data masking", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": "FLAG_PERSONAL_DATA", "req_anchor": "REQ A.8.11-1", "impl_anchor": "IMPL ISO-MASKIERUNG", "requirement": "Data masking is applied in accordance with the access control and privacy requirements.", "link": "{{LINK:R02#ISO-MASKIERUNG}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "A.8.12-1", "policy": "R10", "control": "A.8.12", "kind": "control", "title": "Data leakage prevention", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.12-1", "impl_anchor": "IMPL ISO-DLP", "requirement": "Measures to prevent data leakage are applied to systems, networks and devices that process sensitive information.", "link": "{{LINK:R10#ISO-DLP}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "A.8.13-1", "policy": "R10", "control": "A.8.13", "kind": "control", "title": "Information backup", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.13-1", "impl_anchor": "IMPL 5.2.9", "requirement": "Backup copies of information, software and systems are created in accordance with the backup concept and tested regularly.", "link": "{{LINK:R10#5.2.9}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-05" ] }, { "id": "A.8.14-1", "policy": "R04", "control": "A.8.14", "kind": "control", "title": "Redundancy of information processing facilities", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.14-1", "impl_anchor": "IMPL 5.2.8", "requirement": "Information processing facilities are implemented with sufficient redundancy to meet the availability requirements.", "link": "{{LINK:R04#5.2.8}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-02" ] }, { "id": "A.8.15-1", "policy": "R10", "control": "A.8.15", "kind": "control", "title": "Logging", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.15-1", "impl_anchor": "IMPL 5.2.4", "requirement": "Logs of activities, exceptions, faults and events are produced, stored, protected and analysed.", "link": "{{LINK:R10#5.2.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-13" ] }, { "id": "A.8.16-1", "policy": "R10", "control": "A.8.16", "kind": "control", "title": "Monitoring activities", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.16-1", "impl_anchor": "IMPL 5.2.4", "requirement": "Networks, systems and applications are monitored for anomalous behaviour and potential incidents are evaluated.", "link": "{{LINK:R10#5.2.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-13" ] }, { "id": "A.8.17-1", "policy": "R10", "control": "A.8.17", "kind": "control", "title": "Clock synchronisation", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.17-1", "impl_anchor": "IMPL ISO-ZEITSYNC", "requirement": "System clocks are synchronised to approved time sources.", "link": "{{LINK:R10#ISO-ZEITSYNC}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-13" ] }, { "id": "A.8.18-1", "policy": "R08", "control": "A.8.18", "kind": "control", "title": "Use of privileged utility programs", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.18-1", "impl_anchor": "IMPL 4.2.1", "requirement": "The use of utility programs capable of overriding system and application controls is restricted and tightly controlled.", "link": "{{LINK:R08#4.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-03" ] }, { "id": "A.8.19-1", "policy": "R02", "control": "A.8.19", "kind": "control", "title": "Installation of software on operational systems", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.19-1", "impl_anchor": "IMPL 1.3.4", "requirement": "Procedures and measures for securely managing software installation on operational systems are implemented.", "link": "{{LINK:R02#1.3.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-04" ] }, { "id": "A.8.20-1", "policy": "R10", "control": "A.8.20", "kind": "control", "title": "Networks security", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.20-1", "impl_anchor": "IMPL 5.2.7", "requirement": "Networks and network devices are secured, managed and controlled to protect information.", "link": "{{LINK:R10#5.2.7}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "A.8.21-1", "policy": "R11", "control": "A.8.21", "kind": "control", "title": "Security of network services", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.21-1", "impl_anchor": "IMPL 5.3.2", "requirement": "Security mechanisms, service levels and requirements for network services are identified, implemented and monitored.", "link": "{{LINK:R11#5.3.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "A.8.22-1", "policy": "R10", "control": "A.8.22", "kind": "control", "title": "Segregation of networks", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.22-1", "impl_anchor": "IMPL 5.2.7", "requirement": "Groups of information services, users and systems are segregated in networks.", "link": "{{LINK:R10#5.2.7}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "A.8.23-1", "policy": "R10", "control": "A.8.23", "kind": "control", "title": "Web filtering", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.23-1", "impl_anchor": "IMPL 5.2.3", "requirement": "Access to external websites is managed to reduce exposure to malicious content.", "link": "{{LINK:R10#5.2.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "A.8.24-1", "policy": "R09", "control": "A.8.24", "kind": "control", "title": "Use of cryptography", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.24-1", "impl_anchor": "IMPL 5.1.1", "requirement": "Rules for the effective use of cryptography, including key management, are defined and implemented.", "link": "{{LINK:R09#5.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-07" ] }, { "id": "A.8.25-1", "policy": "R11", "control": "A.8.25", "kind": "control", "title": "Secure development life cycle", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": "FLAG_DEV_INHOUSE", "req_anchor": "REQ A.8.25-1", "impl_anchor": "IMPL 5.3.1", "requirement": "Rules for a secure development life cycle of software and systems are established and applied.", "link": "{{LINK:R11#5.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "A.8.26-1", "policy": "R11", "control": "A.8.26", "kind": "control", "title": "Application security requirements", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": "FLAG_DEV_INHOUSE", "req_anchor": "REQ A.8.26-1", "impl_anchor": "IMPL 5.3.1", "requirement": "Information security requirements are identified, specified and taken into account when developing or acquiring applications.", "link": "{{LINK:R11#5.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "A.8.27-1", "policy": "R11", "control": "A.8.27", "kind": "control", "title": "Secure system architecture and engineering principles", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": "FLAG_DEV_INHOUSE", "req_anchor": "REQ A.8.27-1", "impl_anchor": "IMPL 5.3.1", "requirement": "Principles for engineering secure systems are established, documented and applied.", "link": "{{LINK:R11#5.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "A.8.28-1", "policy": "R11", "control": "A.8.28", "kind": "control", "title": "Secure coding", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": "FLAG_DEV_INHOUSE", "req_anchor": "REQ A.8.28-1", "impl_anchor": "IMPL 5.3.1", "requirement": "Secure coding principles are applied to software development.", "link": "{{LINK:R11#5.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "A.8.29-1", "policy": "R11", "control": "A.8.29", "kind": "control", "title": "Security testing in development and acceptance", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": "FLAG_DEV_INHOUSE", "req_anchor": "REQ A.8.29-1", "impl_anchor": "IMPL 5.3.1", "requirement": "Security testing is integrated into the development and acceptance process.", "link": "{{LINK:R11#5.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "A.8.30-1", "policy": "R11", "control": "A.8.30", "kind": "control", "title": "Outsourced development", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": "FLAG_DEV_INHOUSE", "req_anchor": "REQ A.8.30-1", "impl_anchor": "IMPL 5.3.1", "requirement": "Outsourced system development is directed, monitored and reviewed.", "link": "{{LINK:R11#5.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "A.8.31-1", "policy": "R10", "control": "A.8.31", "kind": "control", "title": "Separation of development, test and production environments", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": "FLAG_DEV_INHOUSE", "req_anchor": "REQ A.8.31-1", "impl_anchor": "IMPL 5.2.2", "requirement": "Development, test and production environments are separated and protected.", "link": "{{LINK:R10#5.2.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "A.8.32-1", "policy": "R10", "control": "A.8.32", "kind": "control", "title": "Change management", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.32-1", "impl_anchor": "IMPL 5.2.1", "requirement": "Changes to information processing facilities and systems are subject to change management.", "link": "{{LINK:R10#5.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-04" ] }, { "id": "A.8.33-1", "policy": "R11", "control": "A.8.33", "kind": "control", "title": "Test information", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": "FLAG_DEV_INHOUSE", "req_anchor": "REQ A.8.33-1", "impl_anchor": "IMPL 5.3.1", "requirement": "Test information is selected, protected and managed with care.", "link": "{{LINK:R11#5.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "A.8.34-1", "policy": "R10", "control": "A.8.34", "kind": "control", "title": "Protection of information systems during audit testing", "type": "MUSS", "soa_relevant": true, "applicable": true, "condition": null, "req_anchor": "REQ A.8.34-1", "impl_anchor": "IMPL 5.2.6", "requirement": "Audit tests and similar activities on operational systems are planned and agreed to avoid disruption.", "link": "{{LINK:R10#5.2.6}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-15" ] } ] }