# Policy Personnel Security and Awareness | Document information | Value | |-----------------------|------| | Document type | Policy | | Scope | {{ISMS_SCOPE}} | | Organisation | {{ORG_NAME}} | | Responsible | {{ROLE_HR_LEAD}} | | Approved by | {{ROLE_MANAGEMENT}} | | Version | {{DOC_VERSION}} | | Date | {{DOC_DATE}} | | Status | {{DOC_STATUS}} | ## 1. Purpose This policy governs the suitability, contractual commitment as well as training and awareness of personnel. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027. ## 2. Scope This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}). ## 3. Requirements and implementation > Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary). ### 3.1 Qualification for sensitive activities *Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 2.1.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 7.2, A.6.1{{/if}} **Requirement** {{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}} - **[MUST]** Sensitive work areas and activities are determined. - **[MUST]** The requirements for employees with regard to their job profiles are determined and met. - **[MUST]** The identity of potential employees is verified (e.g. checking of identity documents). {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** The personal suitability of potential employees is checked using simple methods (e.g. job interview). {{/if}} {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** An extended suitability check depending on the work area and the activity is carried out (e.g. assessment centre, checking of references, certificates and criminal record certificates). {{/if}} {{/if}} {{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}} - **[ISO 7.2]** The necessary competence is determined and ensured; corresponding evidence is retained. - **[ISO A.6.1]** Background verification of candidates is carried out appropriately to the business requirements and in accordance with the law. {{/if}} **Implementation at {{ORG_NAME}}** Sensitive work areas and activities are determined in the register of sensitive activities ({{LINK:REG-SENS-ROLES}}) and recorded with the required depth of checking; requirements for positions are documented in job descriptions and are met. Identity verification as well as the personal and — for sensitive roles — extended suitability check (interview, references, criminal record certificate within the legally permissible scope) are carried out following the suitability and verification procedure ({{LINK:VA-14}}); responsible: {{ROLE_HR_LEAD}}; evidence in the personnel file. ### 3.2 Contractual commitment of personnel *Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 2.1.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.6.2, A.6.5, A.6.6{{/if}} **Requirement** {{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}} - **[MUST]** A confidentiality obligation is in force. - **[MUST]** An obligation to comply with the information security policies is in force. {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** A confidentiality obligation going beyond the employment contract is in force. {{/if}} {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** Information security aspects are taken into account in the employees' employment contracts. {{/if}} {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** A procedure for dealing with violations of these obligations is described. {{/if}} {{/if}} {{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}} - **[ISO A.6.2]** The employment agreements state the responsibilities for information security. - **[ISO A.6.5]** Continuing information security responsibilities after termination or change of employment are defined and enforced. - **[ISO A.6.6]** Confidentiality or non-disclosure agreements are identified, documented and reviewed regularly. {{/if}} **Implementation at {{ORG_NAME}}** All employees are contractually obliged upon joining to confidentiality and to compliance with the information security policies ({{ROLE_HR_LEAD}}); information security aspects are part of the employment contracts, and confidentiality continues to apply after termination. A documented procedure for dealing with violations (see {{LINK:VA-14}}) is established; the evidence is kept in the personnel file. ### 3.3 Awareness and training *Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 2.1.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 7.3, A.6.3{{/if}} **Requirement** {{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}} - **[MUST]** Employees are trained and made aware. {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** A concept for the awareness and training of employees is created. {{/if}} {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** Target groups for training and awareness measures (e.g. managers, administrators, employees with access to customer networks, production personnel) are identified and taken into account in the concept. {{/if}} {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** The concept is approved by the responsible management. {{/if}} {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** Training and awareness measures are carried out regularly and on an ad-hoc basis. {{/if}} {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** Participation in training and awareness measures is documented. {{/if}} {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** Points of contact for information security are known to the employees. {{/if}} {{/if}} {{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}} - **[ISO 7.3]** Persons under the organisation's control are aware of the policy, their contribution and the consequences of non-conformance. - **[ISO A.6.3]** Personnel receive appropriate awareness, education and training as well as regular updates of the relevant policies. {{/if}} **Implementation at {{ORG_NAME}}** A role-specific training/awareness concept approved by management (BL-HR-01) is established; employees are trained upon joining and thereafter at least {{REVIEW_CYCLE}} and on an ad-hoc basis (process see {{LINK:VA-12}}). Target groups are identified, records of participation are kept in {{TOOL_NAME}}, points of contact for information security are known; the effectiveness is checked (e.g. phishing simulation). ## 4. Binding nature This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_HR_LEAD}}. ## 5. Roles and responsibilities | Role | Responsibility in this policy | |-------|-------------------------------------| | {{ROLE_HR_LEAD}} | Commitment, suitability | | {{ROLE_ISB}} | Awareness/training | ## 6. Review and update This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_HR_LEAD}} and approved by {{ROLE_MANAGEMENT}}. ## 7. Evidence The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}). ## 8. Related documents - Associated procedures: {{LINK:VA-12}} - Technical security baseline: {{LINK:BASELINE}} - ISA mapping matrix: {{LINK:ISA_MAPPING}} - Evidence register: {{LINK:NACHWEISREGISTER}} - Further: {{LINK:R01}}, {{LINK:R06}} {{#if FLAG_FW_ISO27001}} ### 3.4 Handling of violations *Requirement reference:* ISO/IEC 27001 A.6.4 **Requirement** - **[ISO A.6.4]** A disciplinary process for information security violations is established and communicated. **Implementation at {{ORG_NAME}}** A graduated, documented process applies to violations of the information security requirements and is communicated in advance. It takes into account the nature and severity of the violation, intent or negligence, repetition and the training status of the person concerned. The process is run by {{ROLE_HR_LEAD}} in coordination with {{ROLE_ISB}}; employment law requirements and co-determination rights are observed. Its application is documented confidentially. {{/if}}