# Policy Cloud, AI and External IT Services | Document information | Value | |-----------------------|------| | Document type | Policy | | Scope | {{ISMS_SCOPE}} | | Organisation | {{ORG_NAME}} | | Responsible | {{ROLE_ISB}} | | Approved by | {{ROLE_MANAGEMENT}} | | Version | {{DOC_VERSION}} | | Date | {{DOC_DATE}} | | Status | {{DOC_STATUS}} | ## 1. Purpose This policy governs protection in outsourced/shared external IT services (cloud) as well as the use of AI/GenAI services. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027. ## 2. Scope This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}). ## 3. Requirements and implementation > Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary). ### 3.1 Protection in shared external IT services *Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.3.4{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.23{{/if}} **Requirement** {{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}} - **[MUST]** An effective separation (e.g. tenant separation) prevents unauthorised users of other organisations from accessing one's own information. {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** The provider's separation concept is documented and adapted to changes; the relevant aspects are taken into account. {{/if}} {{/if}} {{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}} - **[ISO A.5.23]** Processes for acquisition, use, management and exit of cloud services are established in line with the information security requirements. {{/if}} **Implementation at {{ORG_NAME}}** For shared external IT services, effective tenant separation is required and contractually assured; the provider's separation concept is documented and updated upon changes.{{#if FLAG_CLOUD_USED}} Cloud services are assessed before use (protection need, data location/EU, encryption, exit) and approved by {{ROLE_ISB}}; the approvals are maintained in the register of external IT/cloud/AI services ({{LINK:REG-EXT-SERVICES}}) (see {{LINK:VA-11}}).{{/if}} {{#if FLAG_AI_USED}} ### 3.2 Use of AI/GenAI services (supplement R12, not ISA) **Requirement** {{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}} - **[MUST]** The use of AI/GenAI services is regulated; only approved services are used. - **[MUST]** The input of confidential or personal information into non-approved AI services is prohibited; the permissible data classes per service are defined. - **[MUST]** For approved AI services, it is clarified and contractually ensured that inputs are not used for training or passed on. {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** Results of AI services are reviewed before business-critical use (human in the loop); the use of AI is documented and regulatory requirements (e.g. EU AI Act) are taken into account. {{/if}} {{/if}} **Implementation at {{ORG_NAME}}** The use of AI/GenAI services is regulated; only services approved by {{ROLE_ISB}} (maintained in the register of external IT/cloud/AI services {{LINK:REG-EXT-SERVICES}}) may be used (see {{LINK:VA-11}}). The permissible data classes per service are defined, and the input of confidential/personal data into non-approved services is prohibited; upon approval, it is contractually ensured that inputs are not used for training or passed on. AI results are reviewed before critical use (human in the loop), the use is documented and the EU AI Act is taken into account. {{/if}} ## 4. Binding nature This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_ISB}}. ## 5. Roles and responsibilities | Role | Responsibility in this policy | |-------|-------------------------------------| | {{ROLE_ISB}} | Approval/steering | | {{ROLE_IT_LEAD}} | Technical safeguarding | | Business units | Use of approved services | ## 6. Review and update This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_ISB}} and approved by {{ROLE_MANAGEMENT}}. ## 7. Evidence The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}). ## 8. Related documents - Associated procedures: {{LINK:VA-11}} - Technical security baseline: {{LINK:BASELINE}} - ISA mapping matrix: {{LINK:ISA_MAPPING}} - Evidence register: {{LINK:NACHWEISREGISTER}} - Further: {{LINK:R09}}, {{LINK:R11}}, {{LINK:R13}}