{ "$schema": "http://json-schema.org/draft-07/schema#", "title": "ISMS Template Package v2 – Wizard Variables (VDA ISA 2027 / Information Security)", "description": "Single source of truth for all wizard variables. Convention: UPPER_SNAKE_CASE, placeholder {{NAME}}. Feature flags control {{#if FLAG_X}} blocks. The developer generates the wizard inputs from this schema.", "version": "2.0", "type": "object", "properties": { "ORG_NAME": { "type": "string", "title": "Organisation (full name)", "example": "Example Ltd" }, "ORG_SHORT": { "type": "string", "title": "Organisation (short name)", "example": "Example" }, "ISMS_SCOPE": { "type": "string", "title": "Scope (short label)", "example": "IT & Development, North Plant" }, "ISMS_SCOPE_DESCRIPTION": { "type": "string", "title": "Scope (description)" }, "ROLE_MANAGEMENT": { "type": "string", "title": "Top management", "default": "Management" }, "ROLE_ISB": { "type": "string", "title": "Information Security Officer / CISO", "default": "Information Security Officer (ISO)" }, "ROLE_IT_LEAD": { "type": "string", "title": "IT management", "default": "IT management" }, "ROLE_HR_LEAD": { "type": "string", "title": "HR management", "default": "HR management" }, "ROLE_DPO": { "type": "string", "title": "Data Protection Officer", "default": "Data Protection Officer (DPO)" }, "DOC_VERSION": { "type": "string", "title": "Version", "default": "1.0" }, "DOC_DATE": { "type": "string", "title": "Date", "format": "date" }, "DOC_STATUS": { "type": "string", "title": "Status", "enum": [ "Draft", "In review", "Approved" ], "default": "Draft" }, "TOOL_NAME": { "type": "string", "title": "Name of the ISMS tool", "default": "ISMS tool" }, "REVIEW_CYCLE": { "type": "string", "title": "Review cycle (free text)", "default": "annually" }, "TECH_MFA": { "type": "string", "title": "MFA solution", "default": "the MFA solution in use" }, "TECH_MALWARE": { "type": "string", "title": "Malware protection solution", "default": "the endpoint protection solution in use" }, "TECH_BACKUP": { "type": "string", "title": "Backup solution", "default": "the backup solution in use" }, "TECH_SIEM": { "type": "string", "title": "Logging/SIEM solution", "default": "the central logging" }, "TECH_MDM": { "type": "string", "title": "MDM solution", "default": "the MDM in use" }, "TECH_VPN": { "type": "string", "title": "VPN/remote access solution", "default": "VPN" }, "TECH_CRYPTO": { "type": "string", "title": "Cryptography requirement/standard", "default": "current BSI/industry recommendations" }, "TOOL_TICKET": { "type": "string", "title": "Ticket/workflow system (documentation location)", "default": "ticketing system" }, "TOOL_IAM": { "type": "string", "title": "Directory/IAM system", "default": "Entra ID / Active Directory" }, "PW_MIN_LENGTH": { "type": "string", "title": "Minimum password length (BL-IAM-01)", "default": "12" }, "PW_COMPLEXITY": { "type": "string", "title": "Password complexity (BL-IAM-01)", "default": "complexity of at least 3 of 4 character categories" }, "PW_ROTATION": { "type": "string", "title": "Password rotation (BL-IAM-01)", "default": "no fixed forced rotation, change on an ad-hoc basis upon suspicion" }, "MFA_SCOPE": { "type": "string", "title": "MFA scope (BL-IAM-02)", "default": "all remote access, administrative access and cloud services" }, "SESSION_TIMEOUT": { "type": "string", "title": "Session timeout (BL-IAM-03)", "default": "15 min inactivity (privileged), 8 hours (standard)" }, "ACCOUNT_LOCKOUT": { "type": "string", "title": "Account lockout (BL-IAM-04)", "default": "temporary lock after 10 failed attempts" }, "RECERT_FREQ": { "type": "string", "title": "Recertification (BL-IAM-05)", "default": "semi-annually" }, "TLS_MIN": { "type": "string", "title": "Minimum TLS (BL-CRY-01)", "default": "TLS 1.2 (recommendation TLS 1.3)" }, "CRYPTO_ALGO": { "type": "string", "title": "Permissible algorithms (BL-CRY-02)", "default": "AES-256, RSA ≥ 3072 / ECC ≥ 256, SHA-256 or stronger" }, "PATCH_SLA_CRIT": { "type": "string", "title": "Patch SLA critical (BL-OPS-01)", "default": "within 72 hours" }, "PATCH_SLA_HIGH": { "type": "string", "title": "Patch SLA high (BL-OPS-01)", "default": "within 14 days" }, "PATCH_SLA_STD": { "type": "string", "title": "Patch SLA standard (BL-OPS-01)", "default": "in the regular monthly patch cycle" }, "VULN_SCAN_FREQ": { "type": "string", "title": "Vulnerability scan (BL-OPS-02)", "default": "monthly" }, "MALWARE_UPDATE": { "type": "string", "title": "Malware update (BL-OPS-03)", "default": "automatically several times a day" }, "LOG_RETENTION": { "type": "string", "title": "Log retention (BL-OPS-04)", "default": "90 days, up to 12 months depending on risk" }, "BACKUP_SCHEME": { "type": "string", "title": "Backup scheme (BL-OPS-05)", "default": "3-2-1 (3 copies, 2 media, 1 offline/offsite)" }, "BACKUP_RETENTION": { "type": "string", "title": "Backup retention (BL-OPS-05)", "default": "daily 30 days, monthly 12 months" }, "BACKUP_TEST_FREQ": { "type": "string", "title": "Recovery test (BL-OPS-06)", "default": "annually" }, "PENTEST_FREQ": { "type": "string", "title": "Penetration test (BL-OPS-08)", "default": "annually" }, "FLAG_INCLUDE_SHOULD": { "type": "boolean", "title": "Include SHOULD requirements (maturity level 3 = true)", "default": true }, "FLAG_HIGH_PROTECTION": { "type": "boolean", "title": "Include additional requirements for HIGH protection need", "default": false }, "FLAG_VERY_HIGH_PROTECTION": { "type": "boolean", "title": "Include additional requirements for VERY HIGH protection need", "default": false }, "FLAG_ELEVATED_PROTECTION": { "type": "boolean", "title": "Derived: HIGH OR VERY_HIGH active (set by the wizard = FLAG_HIGH_PROTECTION || FLAG_VERY_HIGH_PROTECTION)", "default": false }, "FLAG_CLOUD_USED": { "type": "boolean", "title": "Cloud services in use", "default": true }, "FLAG_AI_USED": { "type": "boolean", "title": "AI/GenAI services in use", "default": true }, "FLAG_OT_USED": { "type": "boolean", "title": "Production/OT environment present", "default": false }, "FLAG_DEV_INHOUSE": { "type": "boolean", "title": "In-house software development", "default": false }, "FLAG_MOBILE_WORK": { "type": "boolean", "title": "Mobile working / home office permitted", "default": true }, "FLAG_MOBILE_DEVICES": { "type": "boolean", "title": "Mobile devices / data media in use", "default": true }, "FLAG_CRYPTO_PKI": { "type": "boolean", "title": "Own PKI / certificate management", "default": false }, "FLAG_EXTERNAL_IT": { "type": "boolean", "title": "External IT service providers used", "default": true }, "FLAG_PERSONAL_DATA": { "type": "boolean", "title": "Processing of personal data", "default": true }, "FLAG_CUSTOMER_SYSTEMS": { "type": "boolean", "title": "Access to customer systems (e.g. OEM)", "default": false }, "FLAG_PROTOTYPE_PROTECTION": { "type": "boolean", "title": "Assessment objective prototype protection active (chapter 8.x)", "default": false }, "FLAG_ISB_INTERNAL": { "type": "boolean", "title": "ISO staffed internally", "default": true }, "FLAG_ISB_EXTERNAL": { "type": "boolean", "title": "ISO staffed externally (external service provider)", "default": false }, "FLAG_FW_TISAX": { "type": "boolean", "title": "Framework: apply TISAX / VDA ISA", "default": true }, "FLAG_FW_ISO27001": { "type": "boolean", "title": "Framework: apply ISO/IEC 27001", "default": false }, "POLICY_REVIEW_CYCLE": { "type": "string", "title": "Review cycle for the policy and thematic policies", "example": "annually", "default": "annually" }, "MGMT_REVIEW_CYCLE": { "type": "string", "title": "Management review interval", "example": "annually", "default": "annually" }, "RISK_REVIEW_CYCLE": { "type": "string", "title": "Risk assessment interval", "example": "annually", "default": "annually" }, "RECORDS_RETENTION": { "type": "string", "title": "Retention of superseded document versions", "example": "3 years", "default": "3 years" }, "AUTHORITY_CONTACTS": { "type": "string", "title": "Relevant authorities and reporting bodies", "example": "data protection authority, police, national CERT", "default": "data protection authority, police, national CERT" }, "THREAT_INTEL_SOURCES": { "type": "string", "title": "Sources of threat intelligence", "example": "national CERT advisories, vendor bulletins, CVE feeds", "default": "national CERT advisories, vendor bulletins, CVE feeds" }, "CAPACITY_REVIEW_FREQ": { "type": "string", "title": "Capacity monitoring interval", "example": "monthly", "default": "monthly" }, "NTP_SOURCES": { "type": "string", "title": "Approved time sources", "example": "two independent, trusted NTP sources", "default": "two independent, trusted NTP sources" }, "DLP_SCOPE": { "type": "string", "title": "Channels covered against data leakage", "example": "e-mail, removable media, cloud storage", "default": "e-mail, removable media, cloud storage" } }, "required": [ "ORG_NAME", "ISMS_SCOPE", "ISMS_SCOPE_DESCRIPTION", "DOC_VERSION", "DOC_DATE" ] }