{ "meta": { "paket": "ISMS-Vorlagenpaket v2", "standard": "VDA ISA 2027 (Information Security)", "hinweis": "Anforderungen 1:1 aus ISA; Umsetzung gebuendelt je Control. is_isa=false = kundenspezifische Ergaenzung (z.B. KI).", "isa_quelldubletten": [ { "control": "1.6.3", "ebene": "high", "doppelte_quellzeilen": 3, "abgedeckt_durch": [ "1.6.3-H1", "1.6.3-H2", "1.6.3-H5" ], "hinweis": "ISA wiederholt Krisenszenario-/Ressourcen-/Test-Zeilen mit/ohne Zusatz \"The following aspects are considered\"." }, { "control": "5.2.9", "ebene": "high", "doppelte_quellzeilen": 1, "abgedeckt_durch": [ "5.2.9-H1" ], "hinweis": "ISA-Zeile \"Backup and recovery concepts exist\" ist redundant zum Must-Konzept und zu H1." } ], "coverage": "316 eindeutige ISA-Zeilen; 4 Quelldubletten konsolidiert -> 312 eindeutige Anforderungen (100% inhaltliche Abdeckung). Plus 4 kundenspezifische KI-Anforderungen.", "version": "2.1" }, "anforderungen": [ { "id": "1.1.1-M1", "policy": "L00", "control": "1.1.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.1.1-M1", "impl_anchor": "REQ 1.1.1-M1", "condition": null, "requirement": "The information security requirements are defined, documented and aligned with the objectives of the organisation.", "link": "{{LINK:L00#1.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.1.1-M2", "policy": "L00", "control": "1.1.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.1.1-M2", "impl_anchor": "REQ 1.1.1-M2", "condition": null, "requirement": "A policy exists and is approved by the organisation's management.", "link": "{{LINK:L00#1.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.1.1-M3", "policy": "L00", "control": "1.1.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.1.1-M3", "impl_anchor": "REQ 1.1.1-M3", "condition": null, "requirement": "The policy states the objectives and the importance of information security within the organisation.", "link": "{{LINK:L00#1.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.1.1-M4", "policy": "L00", "control": "1.1.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.1.1-M4", "impl_anchor": "REQ 1.1.1-M4", "condition": null, "requirement": "The policies are made available to employees in a suitable form (e.g. intranet).", "link": "{{LINK:L00#1.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.1.1-M5", "policy": "L00", "control": "1.1.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.1.1-M5", "impl_anchor": "REQ 1.1.1-M5", "condition": null, "requirement": "Employees and external business partners are informed about changes relevant to them.", "link": "{{LINK:L00#1.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.1.1-S1", "policy": "L00", "control": "1.1.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.1.1-S1", "impl_anchor": "REQ 1.1.1-S1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The information security requirements are based on the organisation's strategy; laws and contracts are taken into account in the policy.", "link": "{{LINK:L00#1.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.1.1-S2", "policy": "L00", "control": "1.1.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.1.1-S2", "impl_anchor": "REQ 1.1.1-S2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The policy states the consequences of non-compliance.", "link": "{{LINK:L00#1.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.1.1-S3", "policy": "L00", "control": "1.1.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.1.1-S3", "impl_anchor": "REQ 1.1.1-S3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Further relevant security policies are established.", "link": "{{LINK:L00#1.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.1.1-S4", "policy": "L00", "control": "1.1.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.1.1-S4", "impl_anchor": "REQ 1.1.1-S4", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Regular review and, where necessary, revision of the policies are established.", "link": "{{LINK:L00#1.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.2.1-M1", "policy": "R01", "control": "1.2.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.2.1-M1", "impl_anchor": "IMPL 1.2.1", "condition": null, "requirement": "The scope of the ISMS (the organisation governed by the ISMS) is defined.", "link": "{{LINK:R01#1.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.2.1-M2", "policy": "R01", "control": "1.2.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.2.1-M2", "impl_anchor": "IMPL 1.2.1", "condition": null, "requirement": "The organisation's requirements for the ISMS are determined.", "link": "{{LINK:R01#1.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.2.1-M3", "policy": "R01", "control": "1.2.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.2.1-M3", "impl_anchor": "IMPL 1.2.1", "condition": null, "requirement": "The organisation's management has commissioned and approved the ISMS.", "link": "{{LINK:R01#1.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.2.1-M4", "policy": "R01", "control": "1.2.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.2.1-M4", "impl_anchor": "IMPL 1.2.1", "condition": null, "requirement": "The ISMS provides management with suitable means for monitoring and steering (e.g. management review).", "link": "{{LINK:R01#1.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.2.1-M5", "policy": "R01", "control": "1.2.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.2.1-M5", "impl_anchor": "IMPL 1.2.1", "condition": null, "requirement": "The applicable controls are determined (e.g. ISO 27001 statement of applicability or a completed ISA catalogue).", "link": "{{LINK:R01#1.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.2.1-M6", "policy": "R01", "control": "1.2.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.2.1-M6", "impl_anchor": "IMPL 1.2.1", "condition": null, "requirement": "The effectiveness of the ISMS is reviewed regularly by management.", "link": "{{LINK:R01#1.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.2.2-M1", "policy": "R01", "control": "1.2.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.2.2-M1", "impl_anchor": "IMPL 1.2.2", "condition": null, "requirement": "Responsibilities for information security are defined, documented and assigned.", "link": "{{LINK:R01#1.2.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.2.2-M2", "policy": "R01", "control": "1.2.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.2.2-M2", "impl_anchor": "IMPL 1.2.2", "condition": null, "requirement": "The responsible employees are defined, qualified and enabled for their task.", "link": "{{LINK:R01#1.2.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.2.2-M3", "policy": "R01", "control": "1.2.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.2.2-M3", "impl_anchor": "IMPL 1.2.2", "condition": null, "requirement": "The necessary resources are available.", "link": "{{LINK:R01#1.2.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.2.2-M4", "policy": "R01", "control": "1.2.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.2.2-M4", "impl_anchor": "IMPL 1.2.2", "condition": null, "requirement": "The points of contact are known within the organisation and to relevant business partners.", "link": "{{LINK:R01#1.2.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.2.2-S1", "policy": "R01", "control": "1.2.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.2.2-S1", "impl_anchor": "IMPL 1.2.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "An appropriate information security structure within the organisation is defined and documented.", "link": "{{LINK:R01#1.2.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.2.2-S2", "policy": "R01", "control": "1.2.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.2.2-S2", "impl_anchor": "IMPL 1.2.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Security-relevant roles that are not part of the ISMS but are relevant to information security are taken into account.", "link": "{{LINK:R01#1.2.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.2.2-H1", "policy": "R01", "control": "1.2.2", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 1.2.2-H1", "impl_anchor": "IMPL 1.2.2-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "An appropriate organisational separation of responsibilities is established to avoid conflicts of interest (segregation of duties). (C, I, A)", "link": "{{LINK:R01#1.2.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.2.3-M1", "policy": "R01", "control": "1.2.3", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.2.3-M1", "impl_anchor": "IMPL 1.2.3", "condition": null, "requirement": "Projects are classified taking information security requirements into account.", "link": "{{LINK:R01#1.2.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-19" ] }, { "id": "1.2.3-S1", "policy": "R01", "control": "1.2.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.2.3-S1", "impl_anchor": "IMPL 1.2.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Procedures and criteria for classifying projects are documented.", "link": "{{LINK:R01#1.2.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-19" ] }, { "id": "1.2.3-S2", "policy": "R01", "control": "1.2.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.2.3-S2", "impl_anchor": "IMPL 1.2.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "A risk assessment following the defined procedure is carried out in an early project phase and repeated upon project changes.", "link": "{{LINK:R01#1.2.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-19" ] }, { "id": "1.2.3-S3", "policy": "R01", "control": "1.2.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.2.3-S3", "impl_anchor": "IMPL 1.2.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Measures are derived for identified information security risks and taken into account in the project.", "link": "{{LINK:R01#1.2.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-19" ] }, { "id": "1.2.3-H1", "policy": "R01", "control": "1.2.3", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 1.2.3-H1", "impl_anchor": "IMPL 1.2.3-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "The derived measures are reviewed regularly during the project and reassessed when the assessment criteria change. (C, I, A)", "link": "{{LINK:R01#1.2.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-19" ] }, { "id": "1.3.1-M1", "policy": "R02", "control": "1.3.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.3.1-M1", "impl_anchor": "IMPL 1.3.1", "condition": null, "requirement": "The organisation's information assets and other security-relevant assets are identified and recorded.", "link": "{{LINK:R02#1.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-08" ] }, { "id": "1.3.1-M2", "policy": "R02", "control": "1.3.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.3.1-M2", "impl_anchor": "IMPL 1.3.1", "condition": null, "requirement": "The supporting assets that process the information assets are identified and recorded.", "link": "{{LINK:R02#1.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-08" ] }, { "id": "1.3.1-S1", "policy": "R02", "control": "1.3.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.3.1-S1", "impl_anchor": "IMPL 1.3.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "A catalogue of the relevant information assets exists; the relevant aspects are taken into account.", "link": "{{LINK:R02#1.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-08" ] }, { "id": "1.3.2-M1", "policy": "R02", "control": "1.3.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.3.2-M1", "impl_anchor": "IMPL 1.3.2", "condition": null, "requirement": "A consistent scheme for classifying information assets with regard to the protection goal of confidentiality is in place.", "link": "{{LINK:R02#1.3.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-08" ] }, { "id": "1.3.2-M2", "policy": "R02", "control": "1.3.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.3.2-M2", "impl_anchor": "IMPL 1.3.2", "condition": null, "requirement": "The identified information assets are assessed according to the defined criteria and assigned to the classification scheme.", "link": "{{LINK:R02#1.3.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-08" ] }, { "id": "1.3.2-M3", "policy": "R02", "control": "1.3.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.3.2-M3", "impl_anchor": "IMPL 1.3.2", "condition": null, "requirement": "Requirements for handling supporting assets (e.g. labelling, use, transport, storage, return, deletion/destruction) depending on the classification are in place and implemented.", "link": "{{LINK:R02#1.3.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.3.2-S1", "policy": "R02", "control": "1.3.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.3.2-S1", "impl_anchor": "IMPL 1.3.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The protection goals of integrity and availability are taken into account.", "link": "{{LINK:R02#1.3.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-08" ] }, { "id": "1.3.3-M1", "policy": "R02", "control": "1.3.3", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.3.3-M1", "impl_anchor": "IMPL 1.3.3", "condition": null, "requirement": "External IT services are not used without an explicit assessment and implementation of the information security requirements; the relevant aspects are taken into account.", "link": "{{LINK:R02#1.3.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.3.3-M2", "policy": "R02", "control": "1.3.3", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.3.3-M2", "impl_anchor": "IMPL 1.3.3", "condition": null, "requirement": "The external IT services are aligned with the protection need of the information assets processed.", "link": "{{LINK:R02#1.3.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.3.3-S1", "policy": "R02", "control": "1.3.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.3.3-S1", "impl_anchor": "IMPL 1.3.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Requirements for procurement, commissioning and approval in connection with the use of external IT services are determined and met.", "link": "{{LINK:R02#1.3.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.3.3-S2", "policy": "R02", "control": "1.3.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.3.3-S2", "impl_anchor": "IMPL 1.3.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "A procedure for approval taking the protection need into account is established.", "link": "{{LINK:R02#1.3.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.3.3-S3", "policy": "R02", "control": "1.3.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.3.3-S3", "impl_anchor": "IMPL 1.3.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "External IT services and their approval are documented.", "link": "{{LINK:R02#1.3.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.3.3-S4", "policy": "R02", "control": "1.3.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.3.3-S4", "impl_anchor": "IMPL 1.3.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "It is regularly verified that only approved external IT services are used.", "link": "{{LINK:R02#1.3.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.3.4-M1", "policy": "R02", "control": "1.3.4", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.3.4-M1", "impl_anchor": "IMPL 1.3.4", "condition": null, "requirement": "Software is approved before installation or use; the relevant aspects are taken into account.", "link": "{{LINK:R02#1.3.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.3.4-M2", "policy": "R02", "control": "1.3.4", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.3.4-M2", "impl_anchor": "IMPL 1.3.4", "condition": null, "requirement": "The software approval also applies to special software such as maintenance tools.", "link": "{{LINK:R02#1.3.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.3.4-S1", "policy": "R02", "control": "1.3.4", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.3.4-S1", "impl_anchor": "IMPL 1.3.4", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The types of software to be managed (firmware, operating systems, applications, libraries, device drivers) are determined.", "link": "{{LINK:R02#1.3.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.3.4-S2", "policy": "R02", "control": "1.3.4", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.3.4-S2", "impl_anchor": "IMPL 1.3.4", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Repositories of the managed software exist.", "link": "{{LINK:R02#1.3.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.3.4-S3", "policy": "R02", "control": "1.3.4", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.3.4-S3", "impl_anchor": "IMPL 1.3.4", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The software repositories are protected against unauthorised manipulation.", "link": "{{LINK:R02#1.3.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.3.4-S4", "policy": "R02", "control": "1.3.4", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.3.4-S4", "impl_anchor": "IMPL 1.3.4", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The approval of software is reviewed regularly.", "link": "{{LINK:R02#1.3.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.3.4-S5", "policy": "R02", "control": "1.3.4", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.3.4-S5", "impl_anchor": "IMPL 1.3.4", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Software versions and patch levels are known.", "link": "{{LINK:R02#1.3.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.3.4-V1", "policy": "R02", "control": "1.3.4", "level": "vhigh", "type": "SEHR HOCH", "is_isa": true, "req_anchor": "REQ 1.3.4-V1", "impl_anchor": "IMPL 1.3.4-elev", "condition": "FLAG_VERY_HIGH_PROTECTION", "requirement": "Additional requirements for software use (e.g. the need to control/monitor use) are determined where present. (C, I, A)", "link": "{{LINK:R02#1.3.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.4.1-M1", "policy": "R03", "control": "1.4.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.4.1-M1", "impl_anchor": "IMPL 1.4.1", "condition": null, "requirement": "Risk assessments are carried out regularly and on an ad-hoc basis.", "link": "{{LINK:R03#1.4.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-09" ] }, { "id": "1.4.1-M2", "policy": "R03", "control": "1.4.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.4.1-M2", "impl_anchor": "IMPL 1.4.1", "condition": null, "requirement": "Information security risks are assessed appropriately (e.g. likelihood of occurrence and potential extent of damage).", "link": "{{LINK:R03#1.4.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-09" ] }, { "id": "1.4.1-M3", "policy": "R03", "control": "1.4.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.4.1-M3", "impl_anchor": "IMPL 1.4.1", "condition": null, "requirement": "Information security risks are documented.", "link": "{{LINK:R03#1.4.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-09" ] }, { "id": "1.4.1-M4", "policy": "R03", "control": "1.4.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.4.1-M4", "impl_anchor": "IMPL 1.4.1", "condition": null, "requirement": "A responsible person (risk owner) is assigned to each information security risk and is responsible for its assessment and treatment.", "link": "{{LINK:R03#1.4.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.4.1-S1", "policy": "R03", "control": "1.4.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.4.1-S1", "impl_anchor": "IMPL 1.4.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "A procedure for the identification, assessment and treatment of security risks is in place.", "link": "{{LINK:R03#1.4.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-09" ] }, { "id": "1.4.1-S2", "policy": "R03", "control": "1.4.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.4.1-S2", "impl_anchor": "IMPL 1.4.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Criteria for the assessment and treatment of security risks exist.", "link": "{{LINK:R03#1.4.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.4.1-S3", "policy": "R03", "control": "1.4.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.4.1-S3", "impl_anchor": "IMPL 1.4.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Risk treatment measures and their responsible persons are defined and documented; a measures plan or implementation overview is tracked.", "link": "{{LINK:R03#1.4.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.4.1-S4", "policy": "R03", "control": "1.4.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.4.1-S4", "impl_anchor": "IMPL 1.4.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Upon changes in the environment (e.g. organisational structure, location, regulations), a reassessment is carried out promptly.", "link": "{{LINK:R03#1.4.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.5.1-M1", "policy": "R03", "control": "1.5.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.5.1-M1", "impl_anchor": "IMPL 1.5.1", "condition": null, "requirement": "Compliance with the policies is reviewed organisation-wide.", "link": "{{LINK:R03#1.5.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-15" ] }, { "id": "1.5.1-M2", "policy": "R03", "control": "1.5.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.5.1-M2", "impl_anchor": "IMPL 1.5.1", "condition": null, "requirement": "Information security policies and procedures are reviewed regularly.", "link": "{{LINK:R03#1.5.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-15" ] }, { "id": "1.5.1-M3", "policy": "R03", "control": "1.5.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.5.1-M3", "impl_anchor": "IMPL 1.5.1", "condition": null, "requirement": "Measures to correct possible deviations are initiated and tracked.", "link": "{{LINK:R03#1.5.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-15" ] }, { "id": "1.5.1-M4", "policy": "R03", "control": "1.5.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.5.1-M4", "impl_anchor": "IMPL 1.5.1", "condition": null, "requirement": "Compliance with information security requirements (e.g. technical specifications) is reviewed regularly.", "link": "{{LINK:R03#1.5.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-15" ] }, { "id": "1.5.1-M5", "policy": "R03", "control": "1.5.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.5.1-M5", "impl_anchor": "IMPL 1.5.1", "condition": null, "requirement": "The results of the reviews carried out are recorded and retained.", "link": "{{LINK:R03#1.5.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-15" ] }, { "id": "1.5.1-S1", "policy": "R03", "control": "1.5.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.5.1-S1", "impl_anchor": "IMPL 1.5.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "A plan for the content and framework conditions (schedule, scope, controls) of the reviews to be carried out is in place.", "link": "{{LINK:R03#1.5.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-15" ] }, { "id": "1.5.2-M1", "policy": "R03", "control": "1.5.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.5.2-M1", "impl_anchor": "IMPL 1.5.2", "condition": null, "requirement": "Information security reviews are carried out by an independent and competent body regularly and after fundamental changes.", "link": "{{LINK:R03#1.5.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-15" ] }, { "id": "1.5.2-M2", "policy": "R03", "control": "1.5.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.5.2-M2", "impl_anchor": "IMPL 1.5.2", "condition": null, "requirement": "Measures to correct possible deviations are initiated and tracked.", "link": "{{LINK:R03#1.5.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-15" ] }, { "id": "1.5.2-S1", "policy": "R03", "control": "1.5.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.5.2-S1", "impl_anchor": "IMPL 1.5.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The results of the reviews carried out are documented and reported to the organisation's management.", "link": "{{LINK:R03#1.5.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-15" ] }, { "id": "1.6.1-M1", "policy": "R04", "control": "1.6.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.6.1-M1", "impl_anchor": "IMPL 1.6.1", "condition": null, "requirement": "A definition of a reportable security event or observation exists and is known to employees and relevant stakeholders.", "link": "{{LINK:R04#1.6.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-01" ] }, { "id": "1.6.1-M2", "policy": "R04", "control": "1.6.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.6.1-M2", "impl_anchor": "IMPL 1.6.1", "condition": null, "requirement": "Appropriate, risk-oriented mechanisms for reporting security events are defined, implemented and known to all relevant reporters.", "link": "{{LINK:R04#1.6.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-01" ] }, { "id": "1.6.1-M3", "policy": "R04", "control": "1.6.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.6.1-M3", "impl_anchor": "IMPL 1.6.1", "condition": null, "requirement": "Appropriate channels for communicating with reporters exist.", "link": "{{LINK:R04#1.6.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.1-S1", "policy": "R04", "control": "1.6.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.6.1-S1", "impl_anchor": "IMPL 1.6.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "A common point of contact for event reporting exists.", "link": "{{LINK:R04#1.6.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.1-S2", "policy": "R04", "control": "1.6.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.6.1-S2", "impl_anchor": "IMPL 1.6.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Different reporting channels depending on the perceived severity (real-time for serious events/emergencies as well as asynchronous mechanisms such as tickets or email) are available.", "link": "{{LINK:R04#1.6.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.1-S3", "policy": "R04", "control": "1.6.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.6.1-S3", "impl_anchor": "IMPL 1.6.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Employees are obliged and trained to report relevant events.", "link": "{{LINK:R04#1.6.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.1-S4", "policy": "R04", "control": "1.6.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.6.1-S4", "impl_anchor": "IMPL 1.6.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Security events can also be reported by external parties; the relevant aspects are taken into account.", "link": "{{LINK:R04#1.6.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.1-S5", "policy": "R04", "control": "1.6.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.6.1-S5", "impl_anchor": "IMPL 1.6.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The mechanism and the information on how incidents are reported are accessible to all relevant reporters.", "link": "{{LINK:R04#1.6.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.1-S6", "policy": "R04", "control": "1.6.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.6.1-S6", "impl_anchor": "IMPL 1.6.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "A feedback procedure to the reporters is established.", "link": "{{LINK:R04#1.6.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.1-V1", "policy": "R04", "control": "1.6.1", "level": "vhigh", "type": "SEHR HOCH", "is_isa": true, "req_anchor": "REQ 1.6.1-V1", "impl_anchor": "IMPL 1.6.1-elev", "condition": "FLAG_VERY_HIGH_PROTECTION", "requirement": "Tests and exercises of event and observation reporting are carried out regularly. (C, I, A)", "link": "{{LINK:R04#1.6.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.2-M1", "policy": "R04", "control": "1.6.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.6.2-M1", "impl_anchor": "IMPL 1.6.2", "condition": null, "requirement": "Reported events are processed without undue delay.", "link": "{{LINK:R04#1.6.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-01" ] }, { "id": "1.6.2-M2", "policy": "R04", "control": "1.6.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.6.2-M2", "impl_anchor": "IMPL 1.6.2", "condition": null, "requirement": "An appropriate response to reported security events is ensured.", "link": "{{LINK:R04#1.6.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-01" ] }, { "id": "1.6.2-M3", "policy": "R04", "control": "1.6.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.6.2-M3", "impl_anchor": "IMPL 1.6.2", "condition": null, "requirement": "Lessons learned feed into continual improvement.", "link": "{{LINK:R04#1.6.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.2-S1", "policy": "R04", "control": "1.6.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.6.2-S1", "impl_anchor": "IMPL 1.6.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "During processing, reported events are categorised (e.g. personnel, physical, cyber), qualified (e.g. not security-relevant, observation, improvement suggestion, vulnerability, incident) and prioritised (e.g. low, medium, high, critical).", "link": "{{LINK:R04#1.6.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-01" ] }, { "id": "1.6.2-S2", "policy": "R04", "control": "1.6.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.6.2-S2", "impl_anchor": "IMPL 1.6.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Responsibilities for handling events per category are defined and assigned.", "link": "{{LINK:R04#1.6.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-01" ] }, { "id": "1.6.2-S3", "policy": "R04", "control": "1.6.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.6.2-S3", "impl_anchor": "IMPL 1.6.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "A strategy for reporting potentially criminally relevant aspects to the competent authorities, where necessary, exists. (C, I, A)", "link": "{{LINK:R04#1.6.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.2-H1", "policy": "R04", "control": "1.6.2", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 1.6.2-H1", "impl_anchor": "IMPL 1.6.2-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "Maximum response times per class, category and severity are defined. (C, I, A)", "link": "{{LINK:R04#1.6.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.2-H2", "policy": "R04", "control": "1.6.2", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 1.6.2-H2", "impl_anchor": "IMPL 1.6.2-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "Events not processed in line with their priority are escalated; the relevant aspects are taken into account. (C, I, A)", "link": "{{LINK:R04#1.6.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.2-H3", "policy": "R04", "control": "1.6.2", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 1.6.2-H3", "impl_anchor": "IMPL 1.6.2-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "Legal, regulatory and contractual reporting obligations and the associated contact information are known. (C, I, A)", "link": "{{LINK:R04#1.6.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.2-H4", "policy": "R04", "control": "1.6.2", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 1.6.2-H4", "impl_anchor": "IMPL 1.6.2-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "A communication strategy for security-relevant events exists; the relevant aspects are taken into account. (C, I, A)", "link": "{{LINK:R04#1.6.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.2-H5", "policy": "R04", "control": "1.6.2", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 1.6.2-H5", "impl_anchor": "IMPL 1.6.2-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "Procedures for responding to security incidents at suppliers are established; the relevant aspects are taken into account. (C, I, A)", "link": "{{LINK:R04#1.6.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.2-V1", "policy": "R04", "control": "1.6.2", "level": "vhigh", "type": "SEHR HOCH", "is_isa": true, "req_anchor": "REQ 1.6.2-V1", "impl_anchor": "IMPL 1.6.2-elev", "condition": "FLAG_VERY_HIGH_PROTECTION", "requirement": "The handling of events of different categories and priorities is tested regularly; the relevant aspects are taken into account. (A)", "link": "{{LINK:R04#1.6.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.3-M1", "policy": "R04", "control": "1.6.3", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.6.3-M1", "impl_anchor": "IMPL 1.6.3", "condition": null, "requirement": "An appropriate plan for responding to and managing crisis situations exists and the necessary resources are available.", "link": "{{LINK:R04#1.6.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-02" ] }, { "id": "1.6.3-M2", "policy": "R04", "control": "1.6.3", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.6.3-M2", "impl_anchor": "IMPL 1.6.3", "condition": null, "requirement": "Responsibilities and authorities for crisis management are defined, documented and assigned.", "link": "{{LINK:R04#1.6.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.3-M3", "policy": "R04", "control": "1.6.3", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 1.6.3-M3", "impl_anchor": "IMPL 1.6.3", "condition": null, "requirement": "The responsible employees are defined and qualified for their task.", "link": "{{LINK:R04#1.6.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.3-S1", "policy": "R04", "control": "1.6.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.6.3-S1", "impl_anchor": "IMPL 1.6.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Methods for detecting crisis situations are established; general indicators and specific foreseeable crises are identified.", "link": "{{LINK:R04#1.6.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-02" ] }, { "id": "1.6.3-S2", "policy": "R04", "control": "1.6.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.6.3-S2", "impl_anchor": "IMPL 1.6.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "A procedure for triggering and/or escalating crisis management is in place.", "link": "{{LINK:R04#1.6.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.3-S3", "policy": "R04", "control": "1.6.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.6.3-S3", "impl_anchor": "IMPL 1.6.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Strategic objectives and their priority in crisis situations are defined and known to relevant personnel.", "link": "{{LINK:R04#1.6.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.3-S4", "policy": "R04", "control": "1.6.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.6.3-S4", "impl_anchor": "IMPL 1.6.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "A crisis team is defined and approved.", "link": "{{LINK:R04#1.6.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.3-S5", "policy": "R04", "control": "1.6.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.6.3-S5", "impl_anchor": "IMPL 1.6.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Crisis policies and procedures are defined and approved.", "link": "{{LINK:R04#1.6.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.3-S6", "policy": "R04", "control": "1.6.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 1.6.3-S6", "impl_anchor": "IMPL 1.6.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The crisis planning is reviewed and updated regularly.", "link": "{{LINK:R04#1.6.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.3-H1", "policy": "R04", "control": "1.6.3", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 1.6.3-H1", "impl_anchor": "IMPL 1.6.3-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "Relevant different potential crisis scenarios are identified.", "link": "{{LINK:R04#1.6.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.3-H2", "policy": "R04", "control": "1.6.3", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 1.6.3-H2", "impl_anchor": "IMPL 1.6.3-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "The resources and information necessary for crisis management (e.g. communication infrastructure, availability of contact and risk information) are identified; appropriate measures to ensure availability or fallback planning are in place. (A)", "link": "{{LINK:R04#1.6.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.3-H3", "policy": "R04", "control": "1.6.3", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 1.6.3-H3", "impl_anchor": "IMPL 1.6.3-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "A communication strategy for crisis situations exists. (A)", "link": "{{LINK:R04#1.6.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.3-H4", "policy": "R04", "control": "1.6.3", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 1.6.3-H4", "impl_anchor": "IMPL 1.6.3-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "The efficiency, feasibility and appropriateness of the crisis planning are assessed regularly. (A)", "link": "{{LINK:R04#1.6.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.3-H5", "policy": "R04", "control": "1.6.3", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 1.6.3-H5", "impl_anchor": "IMPL 1.6.3-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "Sample-based tests of the crisis planning are carried out (e.g. simulation, tabletop exercises with key personnel). (A)", "link": "{{LINK:R04#1.6.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "1.6.3-V1", "policy": "R04", "control": "1.6.3", "level": "vhigh", "type": "SEHR HOCH", "is_isa": true, "req_anchor": "REQ 1.6.3-V1", "impl_anchor": "IMPL 1.6.3-elev", "condition": "FLAG_VERY_HIGH_PROTECTION", "requirement": "Crisis exercises and simulations involving all relevant persons, including decision-makers, are carried out regularly. (A)", "link": "{{LINK:R04#1.6.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "2.1.1-M1", "policy": "R05", "control": "2.1.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 2.1.1-M1", "impl_anchor": "IMPL 2.1.1", "condition": null, "requirement": "Sensitive work areas and activities are determined.", "link": "{{LINK:R05#2.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-14" ] }, { "id": "2.1.1-M2", "policy": "R05", "control": "2.1.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 2.1.1-M2", "impl_anchor": "IMPL 2.1.1", "condition": null, "requirement": "The requirements for employees with regard to their job profiles are determined and met.", "link": "{{LINK:R05#2.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-14" ] }, { "id": "2.1.1-M3", "policy": "R05", "control": "2.1.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 2.1.1-M3", "impl_anchor": "IMPL 2.1.1", "condition": null, "requirement": "The identity of potential employees is verified (e.g. checking of identity documents).", "link": "{{LINK:R05#2.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-14" ] }, { "id": "2.1.1-S1", "policy": "R05", "control": "2.1.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 2.1.1-S1", "impl_anchor": "IMPL 2.1.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The personal suitability of potential employees is checked using simple methods (e.g. job interview).", "link": "{{LINK:R05#2.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-14" ] }, { "id": "2.1.1-S2", "policy": "R05", "control": "2.1.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 2.1.1-S2", "impl_anchor": "IMPL 2.1.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "An extended suitability check depending on the work area and the activity is carried out (e.g. assessment centre, checking of references, certificates and criminal record certificates).", "link": "{{LINK:R05#2.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-14" ] }, { "id": "2.1.2-M1", "policy": "R05", "control": "2.1.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 2.1.2-M1", "impl_anchor": "IMPL 2.1.2", "condition": null, "requirement": "A confidentiality obligation is in force.", "link": "{{LINK:R05#2.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-14" ] }, { "id": "2.1.2-M2", "policy": "R05", "control": "2.1.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 2.1.2-M2", "impl_anchor": "IMPL 2.1.2", "condition": null, "requirement": "An obligation to comply with the information security policies is in force.", "link": "{{LINK:R05#2.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-14" ] }, { "id": "2.1.2-S1", "policy": "R05", "control": "2.1.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 2.1.2-S1", "impl_anchor": "IMPL 2.1.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "A confidentiality obligation going beyond the employment contract is in force.", "link": "{{LINK:R05#2.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-14" ] }, { "id": "2.1.2-S2", "policy": "R05", "control": "2.1.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 2.1.2-S2", "impl_anchor": "IMPL 2.1.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Information security aspects are taken into account in the employees' employment contracts.", "link": "{{LINK:R05#2.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-14" ] }, { "id": "2.1.2-S3", "policy": "R05", "control": "2.1.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 2.1.2-S3", "impl_anchor": "IMPL 2.1.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "A procedure for dealing with violations of these obligations is described.", "link": "{{LINK:R05#2.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-14" ] }, { "id": "2.1.3-M1", "policy": "R05", "control": "2.1.3", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 2.1.3-M1", "impl_anchor": "IMPL 2.1.3", "condition": null, "requirement": "Employees are trained and made aware.", "link": "{{LINK:R05#2.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-12" ] }, { "id": "2.1.3-S1", "policy": "R05", "control": "2.1.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 2.1.3-S1", "impl_anchor": "IMPL 2.1.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "A concept for the awareness and training of employees is created.", "link": "{{LINK:R05#2.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-12" ] }, { "id": "2.1.3-S2", "policy": "R05", "control": "2.1.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 2.1.3-S2", "impl_anchor": "IMPL 2.1.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Target groups for training and awareness measures (e.g. managers, administrators, employees with access to customer networks, production personnel) are identified and taken into account in the concept.", "link": "{{LINK:R05#2.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "2.1.3-S3", "policy": "R05", "control": "2.1.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 2.1.3-S3", "impl_anchor": "IMPL 2.1.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The concept is approved by the responsible management.", "link": "{{LINK:R05#2.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "2.1.3-S4", "policy": "R05", "control": "2.1.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 2.1.3-S4", "impl_anchor": "IMPL 2.1.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Training and awareness measures are carried out regularly and on an ad-hoc basis.", "link": "{{LINK:R05#2.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "2.1.3-S5", "policy": "R05", "control": "2.1.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 2.1.3-S5", "impl_anchor": "IMPL 2.1.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Participation in training and awareness measures is documented.", "link": "{{LINK:R05#2.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "2.1.3-S6", "policy": "R05", "control": "2.1.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 2.1.3-S6", "impl_anchor": "IMPL 2.1.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Points of contact for information security are known to the employees.", "link": "{{LINK:R05#2.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "2.1.4-M1", "policy": "R06", "control": "2.1.4", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 2.1.4-M1", "impl_anchor": "IMPL 2.1.4", "condition": null, "requirement": "The requirements for mobile working are determined and met; the relevant aspects are taken into account.", "link": "{{LINK:R06#2.1.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "2.1.4-S1", "policy": "R06", "control": "2.1.4", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 2.1.4-S1", "impl_anchor": "IMPL 2.1.4", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The relevant aspects of mobile working are taken into account.", "link": "{{LINK:R06#2.1.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "2.1.4-S2", "policy": "R06", "control": "2.1.4", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 2.1.4-S2", "impl_anchor": "IMPL 2.1.4", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Awareness of employees.", "link": "{{LINK:R06#2.1.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "2.1.4-H1", "policy": "R06", "control": "2.1.4", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 2.1.4-H1", "impl_anchor": "IMPL 2.1.4-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "Protective measures against eavesdropping and being overlooked are implemented. (C)", "link": "{{LINK:R06#2.1.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "3.1.1-M1", "policy": "R07", "control": "3.1.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 3.1.1-M1", "impl_anchor": "IMPL 3.1.1", "condition": null, "requirement": "A security zone concept including associated protective measures based on the requirements for handling information assets is in place.", "link": "{{LINK:R07#3.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "3.1.1-M2", "policy": "R07", "control": "3.1.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 3.1.1-M2", "impl_anchor": "IMPL 3.1.1", "condition": null, "requirement": "The defined protective measures are implemented.", "link": "{{LINK:R07#3.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "3.1.1-M3", "policy": "R07", "control": "3.1.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 3.1.1-M3", "impl_anchor": "IMPL 3.1.1", "condition": null, "requirement": "The code of conduct for security zones is known to all persons involved.", "link": "{{LINK:R07#3.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "3.1.1-S1", "policy": "R07", "control": "3.1.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 3.1.1-S1", "impl_anchor": "IMPL 3.1.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Procedures for granting and revoking access rights are established.", "link": "{{LINK:R07#3.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-17" ] }, { "id": "3.1.1-S2", "policy": "R07", "control": "3.1.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 3.1.1-S2", "impl_anchor": "IMPL 3.1.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Policies for visitor management (including registration and escorting of visitors) are defined.", "link": "{{LINK:R07#3.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-17" ] }, { "id": "3.1.1-S3", "policy": "R07", "control": "3.1.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 3.1.1-S3", "impl_anchor": "IMPL 3.1.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Policies for carrying and using mobile IT devices and data media (e.g. registration, labelling obligations) are defined and implemented.", "link": "{{LINK:R07#3.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-17" ] }, { "id": "3.1.1-S4", "policy": "R07", "control": "3.1.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 3.1.1-S4", "impl_anchor": "IMPL 3.1.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Network/infrastructure components (own or customer networks) are protected against unauthorised access.", "link": "{{LINK:R07#3.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-17" ] }, { "id": "3.1.1-S5", "policy": "R07", "control": "3.1.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 3.1.1-S5", "impl_anchor": "IMPL 3.1.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "External premises used for storing/processing information assets are taken into account in the zone concept (e.g. storage rooms, workshops, test tracks, data centres).", "link": "{{LINK:R07#3.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-17" ] }, { "id": "3.1.1-H1", "policy": "R07", "control": "3.1.1", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 3.1.1-H1", "impl_anchor": "IMPL 3.1.1-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "Protective measures against simple eavesdropping and being overlooked are implemented. (C)", "link": "{{LINK:R07#3.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "3.1.4-M1", "policy": "R06", "control": "3.1.4", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 3.1.4-M1", "impl_anchor": "IMPL 3.1.4", "condition": null, "requirement": "The requirements for mobile IT devices and mobile data media are determined and met; the relevant aspects are taken into account.", "link": "{{LINK:R06#3.1.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "3.1.4-S1", "policy": "R06", "control": "3.1.4", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 3.1.4-S1", "impl_anchor": "IMPL 3.1.4", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Registration of the IT devices.", "link": "{{LINK:R06#3.1.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "3.1.4-H1", "policy": "R06", "control": "3.1.4", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 3.1.4-H1", "impl_anchor": "IMPL 3.1.4-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "General encryption of mobile data media or of the information assets stored on them. Where technically not feasible, information is protected by equivalent measures. (C, I)", "link": "{{LINK:R06#3.1.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.1-M1", "policy": "R08", "control": "4.1.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 4.1.1-M1", "impl_anchor": "IMPL 4.1.1", "condition": null, "requirement": "The requirements for handling means of identification throughout the entire lifecycle are determined and met; the relevant aspects are taken into account.", "link": "{{LINK:R08#4.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.1-S1", "policy": "R08", "control": "4.1.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 4.1.1-S1", "impl_anchor": "IMPL 4.1.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Means of identification can only be created under controlled conditions.", "link": "{{LINK:R08#4.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-03" ] }, { "id": "4.1.1-H1", "policy": "R08", "control": "4.1.1", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 4.1.1-H1", "impl_anchor": "IMPL 4.1.1-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "A strategy for blocking or invalidating means of identification in the event of loss is prepared and, as far as possible, implemented. (C, I, A)", "link": "{{LINK:R08#4.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.2-M1", "policy": "R08", "control": "4.1.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 4.1.2-M1", "impl_anchor": "IMPL 4.1.2", "condition": null, "requirement": "The user authentication procedures are selected on the basis of a risk assessment; possible attack scenarios (e.g. direct reachability via the internet) have been taken into account.", "link": "{{LINK:R08#4.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.2-M2", "policy": "R08", "control": "4.1.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 4.1.2-M2", "impl_anchor": "IMPL 4.1.2", "condition": null, "requirement": "State-of-the-art user authentication procedures are applied.", "link": "{{LINK:R08#4.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.2-S1", "policy": "R08", "control": "4.1.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 4.1.2-S1", "impl_anchor": "IMPL 4.1.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The authentication procedures are defined and implemented on the basis of business and security requirements.", "link": "{{LINK:R08#4.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.2-S2", "policy": "R08", "control": "4.1.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 4.1.2-S2", "impl_anchor": "IMPL 4.1.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Users are authenticated at least by strong passwords in line with established and recognised practices.", "link": "{{LINK:R08#4.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.2-S3", "policy": "R08", "control": "4.1.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 4.1.2-S3", "impl_anchor": "IMPL 4.1.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "For privileged user accounts, higher-grade procedures are used (e.g. privileged access management, two-factor authentication).", "link": "{{LINK:R08#4.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.2-H1", "policy": "R08", "control": "4.1.2", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 4.1.2-H1", "impl_anchor": "IMPL 4.1.2-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "Depending on the risk assessment, authentication and access control are strengthened by supplementary measures (e.g. continuous access monitoring, strong authentication, automatic log-off, lock upon inactivity, brute-force prevention). (C, I, A)", "link": "{{LINK:R08#4.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.2-V1", "policy": "R08", "control": "4.1.2", "level": "vhigh", "type": "SEHR HOCH", "is_isa": true, "req_anchor": "REQ 4.1.2-V1", "impl_anchor": "IMPL 4.1.2-elev", "condition": "FLAG_VERY_HIGH_PROTECTION", "requirement": "Before accessing data with a very high protection need, users are authenticated by means of strong authentication (e.g. two-factor) in line with the state of the art. (C, I)", "link": "{{LINK:R08#4.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.3-M1", "policy": "R08", "control": "4.1.3", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 4.1.3-M1", "impl_anchor": "IMPL 4.1.3", "condition": null, "requirement": "The creation, modification and deletion of user accounts is carried out.", "link": "{{LINK:R08#4.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-03" ] }, { "id": "4.1.3-M2", "policy": "R08", "control": "4.1.3", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 4.1.3-M2", "impl_anchor": "IMPL 4.1.3", "condition": null, "requirement": "Unique and personalised user accounts are used.", "link": "{{LINK:R08#4.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.3-M3", "policy": "R08", "control": "4.1.3", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 4.1.3-M3", "impl_anchor": "IMPL 4.1.3", "condition": null, "requirement": "The use of shared accounts is regulated (e.g. limited to cases where traceability is dispensable).", "link": "{{LINK:R08#4.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.3-M4", "policy": "R08", "control": "4.1.3", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 4.1.3-M4", "impl_anchor": "IMPL 4.1.3", "condition": null, "requirement": "User accounts are deactivated immediately after the user leaves (e.g. upon end of contract).", "link": "{{LINK:R08#4.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.3-M5", "policy": "R08", "control": "4.1.3", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 4.1.3-M5", "impl_anchor": "IMPL 4.1.3", "condition": null, "requirement": "User accounts are reviewed regularly.", "link": "{{LINK:R08#4.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.3-M6", "policy": "R08", "control": "4.1.3", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 4.1.3-M6", "impl_anchor": "IMPL 4.1.3", "condition": null, "requirement": "The log-on information is provided to the user in a secure manner.", "link": "{{LINK:R08#4.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.3-M7", "policy": "R08", "control": "4.1.3", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 4.1.3-M7", "impl_anchor": "IMPL 4.1.3", "condition": null, "requirement": "A policy for handling log-on information is defined and implemented; the relevant aspects are taken into account.", "link": "{{LINK:R08#4.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.3-S1", "policy": "R08", "control": "4.1.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 4.1.3-S1", "impl_anchor": "IMPL 4.1.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "A base account with minimal access rights and functionalities exists and is used.", "link": "{{LINK:R08#4.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.3-S10", "policy": "R08", "control": "4.1.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 4.1.3-S10", "impl_anchor": "IMPL 4.1.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Interactive log-on for service accounts (technical accounts) is prevented technically.", "link": "{{LINK:R08#4.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.3-S2", "policy": "R08", "control": "4.1.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 4.1.3-S2", "impl_anchor": "IMPL 4.1.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Default accounts and passwords preconfigured by the manufacturer are deactivated (e.g. blocking or password change).", "link": "{{LINK:R08#4.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.3-S3", "policy": "R08", "control": "4.1.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 4.1.3-S3", "impl_anchor": "IMPL 4.1.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "User accounts are created or authorised by the responsible body.", "link": "{{LINK:R08#4.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.3-S4", "policy": "R08", "control": "4.1.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 4.1.3-S4", "impl_anchor": "IMPL 4.1.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The creation of user accounts is subject to an approval process (four-eyes principle).", "link": "{{LINK:R08#4.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.3-S5", "policy": "R08", "control": "4.1.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 4.1.3-S5", "impl_anchor": "IMPL 4.1.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "User accounts of service providers are deactivated after completion of their task.", "link": "{{LINK:R08#4.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.3-S6", "policy": "R08", "control": "4.1.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 4.1.3-S6", "impl_anchor": "IMPL 4.1.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Deadlines for deactivating and deleting user accounts are defined.", "link": "{{LINK:R08#4.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.3-S7", "policy": "R08", "control": "4.1.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 4.1.3-S7", "impl_anchor": "IMPL 4.1.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The use of default passwords is prevented technically.", "link": "{{LINK:R08#4.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.3-S8", "policy": "R08", "control": "4.1.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 4.1.3-S8", "impl_anchor": "IMPL 4.1.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "In the case of strong authentication, the use of the medium (e.g. possession factor) is secure.", "link": "{{LINK:R08#4.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.1.3-S9", "policy": "R08", "control": "4.1.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 4.1.3-S9", "impl_anchor": "IMPL 4.1.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "User accounts are reviewed regularly; this also includes accounts in customers' IT systems.", "link": "{{LINK:R08#4.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.2.1-M1", "policy": "R08", "control": "4.2.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 4.2.1-M1", "impl_anchor": "IMPL 4.2.1", "condition": null, "requirement": "The requirements for managing access rights (authorisation) are determined and met; the relevant aspects are taken into account.", "link": "{{LINK:R08#4.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-03" ] }, { "id": "4.2.1-M2", "policy": "R08", "control": "4.2.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 4.2.1-M2", "impl_anchor": "IMPL 4.2.1", "condition": null, "requirement": "The access rights granted for normal and privileged user accounts as well as technical accounts are reviewed regularly, also in customers' IT systems.", "link": "{{LINK:R08#4.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-03" ] }, { "id": "4.2.1-S1", "policy": "R08", "control": "4.2.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 4.2.1-S1", "impl_anchor": "IMPL 4.2.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Strategies for authorising access to information are prepared.", "link": "{{LINK:R08#4.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-03" ] }, { "id": "4.2.1-S2", "policy": "R08", "control": "4.2.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 4.2.1-S2", "impl_anchor": "IMPL 4.2.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Authorisation roles are used.", "link": "{{LINK:R08#4.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.2.1-S3", "policy": "R08", "control": "4.2.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 4.2.1-S3", "impl_anchor": "IMPL 4.2.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Rights are granted according to the need-to-use principle and in line with role and/or area of responsibility.", "link": "{{LINK:R08#4.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.2.1-S4", "policy": "R08", "control": "4.2.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 4.2.1-S4", "impl_anchor": "IMPL 4.2.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Normal user accounts do not receive privileged access rights.", "link": "{{LINK:R08#4.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.2.1-S5", "policy": "R08", "control": "4.2.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 4.2.1-S5", "impl_anchor": "IMPL 4.2.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The user's access rights are updated after a change in their responsibilities.", "link": "{{LINK:R08#4.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.2.1-H1", "policy": "R08", "control": "4.2.1", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 4.2.1-H1", "impl_anchor": "IMPL 4.2.1-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "The access rights are approved by the responsible internal information officer. (C, I, A)", "link": "{{LINK:R08#4.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.2.1-V1", "policy": "R08", "control": "4.2.1", "level": "vhigh", "type": "SEHR HOCH", "is_isa": true, "req_anchor": "REQ 4.2.1-V1", "impl_anchor": "IMPL 4.2.1-elev", "condition": "FLAG_VERY_HIGH_PROTECTION", "requirement": "Information is stored encrypted at content level (e.g. file level) to prevent unauthorised access (including by privileged users). Where encryption is not feasible, equivalent measures apply. (C)", "link": "{{LINK:R08#4.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "4.2.1-V2", "policy": "R08", "control": "4.2.1", "level": "vhigh", "type": "SEHR HOCH", "is_isa": true, "req_anchor": "REQ 4.2.1-V2", "impl_anchor": "IMPL 4.2.1-elev", "condition": "FLAG_VERY_HIGH_PROTECTION", "requirement": "Existing access rights are reviewed at shorter intervals (e.g. quarterly). (C)", "link": "{{LINK:R08#4.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.1.1-M1", "policy": "R09", "control": "5.1.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.1.1-M1", "impl_anchor": "IMPL 5.1.1", "condition": null, "requirement": "All cryptographic procedures used (e.g. encryption, signature, hash algorithms, protocols) provide the security required in the respective field of application according to a recognised industry standard, as far as legally possible.", "link": "{{LINK:R09#5.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-07" ] }, { "id": "5.1.1-S1", "policy": "R09", "control": "5.1.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.1.1-S1", "impl_anchor": "IMPL 5.1.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "A concept for the use of cryptography is defined and implemented; the relevant aspects are taken into account.", "link": "{{LINK:R09#5.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-07" ] }, { "id": "5.1.1-H1", "policy": "R09", "control": "5.1.1", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 5.1.1-H1", "impl_anchor": "IMPL 5.1.1-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "Requirements for key sovereignty (in particular in the case of external processing) are determined and met. (C, I)", "link": "{{LINK:R09#5.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.1.2-M1", "policy": "R09", "control": "5.1.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.1.2-M1", "impl_anchor": "IMPL 5.1.2", "condition": null, "requirement": "The network services used for transmitting information are identified and documented.", "link": "{{LINK:R09#5.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-07" ] }, { "id": "5.1.2-M2", "policy": "R09", "control": "5.1.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.1.2-M2", "impl_anchor": "IMPL 5.1.2", "condition": null, "requirement": "Policies and procedures in line with the classification requirements for the use of network services are defined and implemented.", "link": "{{LINK:R09#5.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.1.2-M3", "policy": "R09", "control": "5.1.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.1.2-M3", "impl_anchor": "IMPL 5.1.2", "condition": null, "requirement": "Measures to protect transmitted content against unauthorised access are implemented.", "link": "{{LINK:R09#5.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.1.2-S1", "policy": "R09", "control": "5.1.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.1.2-S1", "impl_anchor": "IMPL 5.1.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Measures to ensure correct addressing and correct transmission of information are implemented.", "link": "{{LINK:R09#5.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-07" ] }, { "id": "5.1.2-S2", "policy": "R09", "control": "5.1.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.1.2-S2", "impl_anchor": "IMPL 5.1.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Electronic data exchange takes place using content or transport encryption in line with the respective classification.", "link": "{{LINK:R09#5.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.1.2-S3", "policy": "R09", "control": "5.1.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.1.2-S3", "impl_anchor": "IMPL 5.1.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Remote access connections to the organisation's network have appropriate security features; the relevant aspects are taken into account.", "link": "{{LINK:R09#5.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.1.2-H1", "policy": "R09", "control": "5.1.2", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 5.1.2-H1", "impl_anchor": "IMPL 5.1.2-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "Information is transmitted encrypted (at least transport encryption) or protected by equivalently effective measures. (C)", "link": "{{LINK:R09#5.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.1.2-V1", "policy": "R09", "control": "5.1.2", "level": "vhigh", "type": "SEHR HOCH", "is_isa": true, "req_anchor": "REQ 5.1.2-V1", "impl_anchor": "IMPL 5.1.2-elev", "condition": "FLAG_VERY_HIGH_PROTECTION", "requirement": "Information is transmitted with content encryption. (C)", "link": "{{LINK:R09#5.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.1-M1", "policy": "R10", "control": "5.2.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.1-M1", "impl_anchor": "IMPL 5.2.1", "condition": null, "requirement": "Information security requirements for changes to the organisation, business processes and IT systems are determined and met.", "link": "{{LINK:R10#5.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-04" ] }, { "id": "5.2.1-S1", "policy": "R10", "control": "5.2.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.1-S1", "impl_anchor": "IMPL 5.2.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "A formal approval procedure is established.", "link": "{{LINK:R10#5.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.1-S2", "policy": "R10", "control": "5.2.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.1-S2", "impl_anchor": "IMPL 5.2.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The possible effects of changes on information security are assessed.", "link": "{{LINK:R10#5.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.1-S3", "policy": "R10", "control": "5.2.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.1-S3", "impl_anchor": "IMPL 5.2.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Changes with an effect on information security are planned and tested.", "link": "{{LINK:R10#5.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.1-S4", "policy": "R10", "control": "5.2.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.1-S4", "impl_anchor": "IMPL 5.2.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Fallback procedures in the event of errors are taken into account.", "link": "{{LINK:R10#5.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.1-H1", "policy": "R10", "control": "5.2.1", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 5.2.1-H1", "impl_anchor": "IMPL 5.2.1-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "Compliance with the information security requirements is verified during and after the changes. (C, I, A)", "link": "{{LINK:R10#5.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.2-M1", "policy": "R10", "control": "5.2.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.2-M1", "impl_anchor": "IMPL 5.2.2", "condition": null, "requirement": "The IT systems have been subjected to a risk assessment to determine the need to separate them into development, test and production systems.", "link": "{{LINK:R10#5.2.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.2-M2", "policy": "R10", "control": "5.2.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.2-M2", "impl_anchor": "IMPL 5.2.2", "condition": null, "requirement": "A segmentation is implemented on the basis of the results of the risk analysis.", "link": "{{LINK:R10#5.2.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.2-S1", "policy": "R10", "control": "5.2.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.2-S1", "impl_anchor": "IMPL 5.2.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The requirements for development and test environments are determined and met; the relevant aspects are taken into account.", "link": "{{LINK:R10#5.2.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.3-M1", "policy": "R10", "control": "5.2.3", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.3-M1", "impl_anchor": "IMPL 5.2.3", "condition": null, "requirement": "Requirements for protection against malware are determined.", "link": "{{LINK:R10#5.2.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.3-M2", "policy": "R10", "control": "5.2.3", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.3-M2", "impl_anchor": "IMPL 5.2.3", "condition": null, "requirement": "Technical and organisational measures for protection against malware are defined and implemented.", "link": "{{LINK:R10#5.2.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.3-S1", "policy": "R10", "control": "5.2.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.3-S1", "impl_anchor": "IMPL 5.2.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Unnecessary network services are deactivated.", "link": "{{LINK:R10#5.2.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.3-S2", "policy": "R10", "control": "5.2.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.3-S2", "impl_anchor": "IMPL 5.2.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Access to network services is limited to what is necessary through appropriate protective measures.", "link": "{{LINK:R10#5.2.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.3-S3", "policy": "R10", "control": "5.2.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.3-S3", "impl_anchor": "IMPL 5.2.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Protective software against malware is installed and updated automatically at regular intervals (e.g. virus scanner).", "link": "{{LINK:R10#5.2.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.3-S4", "policy": "R10", "control": "5.2.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.3-S4", "impl_anchor": "IMPL 5.2.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Received files and software are automatically checked for malware before execution (on-access scan).", "link": "{{LINK:R10#5.2.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.3-S5", "policy": "R10", "control": "5.2.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.3-S5", "impl_anchor": "IMPL 5.2.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The entire data stock of all systems is checked for malware regularly.", "link": "{{LINK:R10#5.2.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.3-S6", "policy": "R10", "control": "5.2.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.3-S6", "impl_anchor": "IMPL 5.2.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Data transmitted via central gateways (e.g. email, internet, external networks) is automatically checked by protective software.", "link": "{{LINK:R10#5.2.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.3-S7", "policy": "R10", "control": "5.2.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.3-S7", "impl_anchor": "IMPL 5.2.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Measures preventing protective software from being deactivated or modified by users are defined and implemented.", "link": "{{LINK:R10#5.2.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.3-S8", "policy": "R10", "control": "5.2.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.3-S8", "impl_anchor": "IMPL 5.2.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "For IT systems without protective software, alternative measures are implemented (e.g. special resilience, few services, no active users, network isolation).", "link": "{{LINK:R10#5.2.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.4-M1", "policy": "R10", "control": "5.2.4", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.4-M1", "impl_anchor": "IMPL 5.2.4", "condition": null, "requirement": "Information security requirements for handling event logs are determined and met.", "link": "{{LINK:R10#5.2.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-13" ] }, { "id": "5.2.4-M2", "policy": "R10", "control": "5.2.4", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.4-M2", "impl_anchor": "IMPL 5.2.4", "condition": null, "requirement": "Security-relevant requirements for logging the activities of administrators and users are determined and met.", "link": "{{LINK:R10#5.2.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.4-M3", "policy": "R10", "control": "5.2.4", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.4-M3", "impl_anchor": "IMPL 5.2.4", "condition": null, "requirement": "The IT systems used are assessed with regard to the need for logging.", "link": "{{LINK:R10#5.2.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.4-M4", "policy": "R10", "control": "5.2.4", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.4-M4", "impl_anchor": "IMPL 5.2.4", "condition": null, "requirement": "When external IT services are used, information on the monitoring options is obtained and taken into account in the assessment.", "link": "{{LINK:R10#5.2.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.4-M5", "policy": "R10", "control": "5.2.4", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.4-M5", "impl_anchor": "IMPL 5.2.4", "condition": null, "requirement": "Event logs are checked regularly for policy violations and conspicuous problems, in compliance with the permissible legal and organisational requirements.", "link": "{{LINK:R10#5.2.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.4-S1", "policy": "R10", "control": "5.2.4", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.4-S1", "impl_anchor": "IMPL 5.2.4", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "A procedure for escalating relevant events to the responsible body is defined and established.", "link": "{{LINK:R10#5.2.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-13" ] }, { "id": "5.2.4-S2", "policy": "R10", "control": "5.2.4", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.4-S2", "impl_anchor": "IMPL 5.2.4", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Event logs (content and metadata) are protected against modification (e.g. by a dedicated environment).", "link": "{{LINK:R10#5.2.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.4-S3", "policy": "R10", "control": "5.2.4", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.4-S3", "impl_anchor": "IMPL 5.2.4", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Appropriate monitoring and recording of all information-security-relevant actions in the network is established.", "link": "{{LINK:R10#5.2.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.4-H1", "policy": "R10", "control": "5.2.4", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 5.2.4-H1", "impl_anchor": "IMPL 5.2.4-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "Security-relevant requirements for handling event logs, e.g. contractual requirements, are determined and implemented. (C, I, A)", "link": "{{LINK:R10#5.2.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.4-H2", "policy": "R10", "control": "5.2.4", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 5.2.4-H2", "impl_anchor": "IMPL 5.2.4-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "Events relating to the establishment and termination of remote access sessions (e.g. remote maintenance) are logged. (C, I, A)", "link": "{{LINK:R10#5.2.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.4-V1", "policy": "R10", "control": "5.2.4", "level": "vhigh", "type": "SEHR HOCH", "is_isa": true, "req_anchor": "REQ 5.2.4-V1", "impl_anchor": "IMPL 5.2.4-elev", "condition": "FLAG_VERY_HIGH_PROTECTION", "requirement": "Logging of every access to data with a very high protection need, as far as technically feasible and legally/organisationally permissible. (C, I)", "link": "{{LINK:R10#5.2.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.5-M1", "policy": "R10", "control": "5.2.5", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.5-M1", "impl_anchor": "IMPL 5.2.5", "condition": null, "requirement": "Information about technical vulnerabilities of the IT systems used is collected (e.g. manufacturer information, system audits, CVE database).", "link": "{{LINK:R10#5.2.5}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-04", "VA-06" ] }, { "id": "5.2.5-M2", "policy": "R10", "control": "5.2.5", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.5-M2", "impl_anchor": "IMPL 5.2.5", "condition": null, "requirement": "Potentially affected IT systems and software are identified and the risk caused by the vulnerability is assessed.", "link": "{{LINK:R10#5.2.5}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.5-M3", "policy": "R10", "control": "5.2.5", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.5-M3", "impl_anchor": "IMPL 5.2.5", "condition": null, "requirement": "Risks arising from vulnerabilities are treated.", "link": "{{LINK:R10#5.2.5}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.5-S1", "policy": "R10", "control": "5.2.5", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.5-S1", "impl_anchor": "IMPL 5.2.5", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Appropriate patch management is defined and implemented (e.g. patch testing and installation).", "link": "{{LINK:R10#5.2.5}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-06" ] }, { "id": "5.2.5-S2", "policy": "R10", "control": "5.2.5", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.5-S2", "impl_anchor": "IMPL 5.2.5", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Risk-mitigating measures are implemented where necessary.", "link": "{{LINK:R10#5.2.5}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.5-S3", "policy": "R10", "control": "5.2.5", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.5-S3", "impl_anchor": "IMPL 5.2.5", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The successful installation of patches is verified in a suitable manner.", "link": "{{LINK:R10#5.2.5}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.6-M1", "policy": "R10", "control": "5.2.6", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.6-M1", "impl_anchor": "IMPL 5.2.6", "condition": null, "requirement": "Requirements for the review (audit) of IT systems or services are determined.", "link": "{{LINK:R10#5.2.6}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-06" ] }, { "id": "5.2.6-M2", "policy": "R10", "control": "5.2.6", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.6-M2", "impl_anchor": "IMPL 5.2.6", "condition": null, "requirement": "The scope of the system review is defined in good time.", "link": "{{LINK:R10#5.2.6}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.6-M3", "policy": "R10", "control": "5.2.6", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.6-M3", "impl_anchor": "IMPL 5.2.6", "condition": null, "requirement": "System or service reviews are coordinated with the operators and users of the IT systems/services.", "link": "{{LINK:R10#5.2.6}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.6-M4", "policy": "R10", "control": "5.2.6", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.6-M4", "impl_anchor": "IMPL 5.2.6", "condition": null, "requirement": "The results of system/service reviews are stored in a traceable manner and reported to the responsible management.", "link": "{{LINK:R10#5.2.6}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.6-M5", "policy": "R10", "control": "5.2.6", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.6-M5", "impl_anchor": "IMPL 5.2.6", "condition": null, "requirement": "Measures are derived from the results and implemented within an appropriate period.", "link": "{{LINK:R10#5.2.6}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.6-S1", "policy": "R10", "control": "5.2.6", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.6-S1", "impl_anchor": "IMPL 5.2.6", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "System and service reviews are planned taking possible security risks (e.g. disruptions) into account.", "link": "{{LINK:R10#5.2.6}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.6-S2", "policy": "R10", "control": "5.2.6", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.6-S2", "impl_anchor": "IMPL 5.2.6", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Regular system or service reviews are carried out; the relevant aspects are taken into account.", "link": "{{LINK:R10#5.2.6}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.6-S3", "policy": "R10", "control": "5.2.6", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.6-S3", "impl_anchor": "IMPL 5.2.6", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Within an appropriate period after completion of the review, a report is prepared.", "link": "{{LINK:R10#5.2.6}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.6-H1", "policy": "R10", "control": "5.2.6", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 5.2.6-H1", "impl_anchor": "IMPL 5.2.6-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "For critical IT systems/services, additional review requirements have been identified and are met (e.g. service-specific tests/tools and/or manual penetration tests, risk-based intervals). (A)", "link": "{{LINK:R10#5.2.6}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.6-V1", "policy": "R10", "control": "5.2.6", "level": "vhigh", "type": "SEHR HOCH", "is_isa": true, "req_anchor": "REQ 5.2.6-V1", "impl_anchor": "IMPL 5.2.6-elev", "condition": "FLAG_VERY_HIGH_PROTECTION", "requirement": "IT systems and services are scanned regularly for vulnerabilities. For systems/services that cannot be scanned, suitable protective measures are to be implemented. (C, I, A)", "link": "{{LINK:R10#5.2.6}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.7-M1", "policy": "R10", "control": "5.2.7", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.7-M1", "impl_anchor": "IMPL 5.2.7", "condition": null, "requirement": "Requirements for the management and control of networks are determined and met.", "link": "{{LINK:R10#5.2.7}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.7-M2", "policy": "R10", "control": "5.2.7", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.7-M2", "impl_anchor": "IMPL 5.2.7", "condition": null, "requirement": "Requirements for network segmentation are determined and met.", "link": "{{LINK:R10#5.2.7}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.7-S1", "policy": "R10", "control": "5.2.7", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.7-S1", "impl_anchor": "IMPL 5.2.7", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Procedures for the management and control of networks are defined.", "link": "{{LINK:R10#5.2.7}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.7-S2", "policy": "R10", "control": "5.2.7", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.7-S2", "impl_anchor": "IMPL 5.2.7", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "For a risk-based network segmentation, the relevant aspects are taken into account.", "link": "{{LINK:R10#5.2.7}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.7-H1", "policy": "R10", "control": "5.2.7", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 5.2.7-H1", "impl_anchor": "IMPL 5.2.7-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "Extended requirements for the management and control of networks are determined and implemented. (C, I, A)", "link": "{{LINK:R10#5.2.7}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.8-M1", "policy": "R04", "control": "5.2.8", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.8-M1", "impl_anchor": "IMPL 5.2.8", "condition": null, "requirement": "Critical IT services are identified and the business impact is taken into account.", "link": "{{LINK:R04#5.2.8}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-02" ] }, { "id": "5.2.8-M2", "policy": "R04", "control": "5.2.8", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.8-M2", "impl_anchor": "IMPL 5.2.8", "condition": null, "requirement": "Requirements and responsibilities for the continuity and recovery of these IT services are known to relevant stakeholders and fulfilled.", "link": "{{LINK:R04#5.2.8}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.8-S1", "policy": "R04", "control": "5.2.8", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.8-S1", "impl_anchor": "IMPL 5.2.8", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Critical IT systems are identified; the relevant aspects are taken into account.", "link": "{{LINK:R04#5.2.8}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-02" ] }, { "id": "5.2.8-S2", "policy": "R04", "control": "5.2.8", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.8-S2", "impl_anchor": "IMPL 5.2.8", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "A continuity plan exists and is reviewed and updated regularly.", "link": "{{LINK:R04#5.2.8}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.8-S3", "policy": "R04", "control": "5.2.8", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.8-S3", "impl_anchor": "IMPL 5.2.8", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The continuity planning covers at least (D)DoS attacks, successful ransomware attacks and other sabotage, system failure scenarios as well as natural disasters affecting critical IT systems.", "link": "{{LINK:R04#5.2.8}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.8-H1", "policy": "R04", "control": "5.2.8", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 5.2.8-H1", "impl_anchor": "IMPL 5.2.8-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "The continuity planning contains predefined time frames (recovery time objective) for the resumption of operations. (A)", "link": "{{LINK:R04#5.2.8}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.8-H2", "policy": "R04", "control": "5.2.8", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 5.2.8-H2", "impl_anchor": "IMPL 5.2.8-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "Appropriate SLAs with external service providers in line with the continuity planning are in place. (A)", "link": "{{LINK:R04#5.2.8}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.8-H3", "policy": "R04", "control": "5.2.8", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 5.2.8-H3", "impl_anchor": "IMPL 5.2.8-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "The continuity plans include the coordination of contractually agreed communication with business partners. (A)", "link": "{{LINK:R04#5.2.8}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.8-H4", "policy": "R04", "control": "5.2.8", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 5.2.8-H4", "impl_anchor": "IMPL 5.2.8-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "The continuity planning is tested regularly, incl. full recovery to a known state and adherence to defined target times. (A)", "link": "{{LINK:R04#5.2.8}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.8-H5", "policy": "R04", "control": "5.2.8", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 5.2.8-H5", "impl_anchor": "IMPL 5.2.8-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "A backup and recovery strategy for critical IT services and information is defined and implemented. (C, I, A)", "link": "{{LINK:R04#5.2.8}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.8-H6", "policy": "R04", "control": "5.2.8", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 5.2.8-H6", "impl_anchor": "IMPL 5.2.8-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "Backups of critical IT services and information are sufficiently protected against unauthorised modification/deletion by malware. (I, A)", "link": "{{LINK:R04#5.2.8}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.8-H7", "policy": "R04", "control": "5.2.8", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 5.2.8-H7", "impl_anchor": "IMPL 5.2.8-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "Backups of critical IT services and information are sufficiently protected against unauthorised access by malware or operators. (C, I)", "link": "{{LINK:R04#5.2.8}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.8-V1", "policy": "R04", "control": "5.2.8", "level": "vhigh", "type": "SEHR HOCH", "is_isa": true, "req_anchor": "REQ 5.2.8-V1", "impl_anchor": "IMPL 5.2.8-elev", "condition": "FLAG_VERY_HIGH_PROTECTION", "requirement": "The continuity planning is coordinated with the continuity plans of relevant external service providers. (A)", "link": "{{LINK:R04#5.2.8}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.8-V2", "policy": "R04", "control": "5.2.8", "level": "vhigh", "type": "SEHR HOCH", "is_isa": true, "req_anchor": "REQ 5.2.8-V2", "impl_anchor": "IMPL 5.2.8-elev", "condition": "FLAG_VERY_HIGH_PROTECTION", "requirement": "The continuation of essential core and business functions with minimal or no loss of operational continuity is possible; the relevant aspects are taken into account.", "link": "{{LINK:R04#5.2.8}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.8-V3", "policy": "R04", "control": "5.2.8", "level": "vhigh", "type": "SEHR HOCH", "is_isa": true, "req_anchor": "REQ 5.2.8-V3", "impl_anchor": "IMPL 5.2.8-elev", "condition": "FLAG_VERY_HIGH_PROTECTION", "requirement": "The continuity planning is tested regularly. Test scenarios, results and lessons learned are recorded. (I, A)", "link": "{{LINK:R04#5.2.8}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.9-M1", "policy": "R10", "control": "5.2.9", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.9-M1", "impl_anchor": "IMPL 5.2.9", "condition": null, "requirement": "Backup concepts exist for relevant IT systems. Appropriate protective measures for the confidentiality, integrity and availability of the backups are taken into account.", "link": "{{LINK:R10#5.2.9}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-05" ] }, { "id": "5.2.9-M2", "policy": "R10", "control": "5.2.9", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.2.9-M2", "impl_anchor": "IMPL 5.2.9", "condition": null, "requirement": "Recovery concepts exist for relevant IT services.", "link": "{{LINK:R10#5.2.9}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-05" ] }, { "id": "5.2.9-S1", "policy": "R10", "control": "5.2.9", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.2.9-S1", "impl_anchor": "IMPL 5.2.9", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "For each relevant IT service, a backup and recovery concept exists. Dependencies between IT services and the recovery sequence are taken into account.", "link": "{{LINK:R10#5.2.9}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-05" ] }, { "id": "5.2.9-H1", "policy": "R10", "control": "5.2.9", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 5.2.9-H1", "impl_anchor": "IMPL 5.2.9-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "Backup and recovery concepts are reviewed methodically at regular intervals. (A)", "link": "{{LINK:R10#5.2.9}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.9-H2", "policy": "R10", "control": "5.2.9", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 5.2.9-H2", "impl_anchor": "IMPL 5.2.9-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "The fundamental recoverability is taken into account and tested (e.g. sample tests, test systems). (I, A)", "link": "{{LINK:R10#5.2.9}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.9-V1", "policy": "R10", "control": "5.2.9", "level": "vhigh", "type": "SEHR HOCH", "is_isa": true, "req_anchor": "REQ 5.2.9-V1", "impl_anchor": "IMPL 5.2.9-elev", "condition": "FLAG_VERY_HIGH_PROTECTION", "requirement": "(Additional) backups are carried out via offline procedures, immutable backups or an isolated IAM solution. (I, A)", "link": "{{LINK:R10#5.2.9}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.9-V2", "policy": "R10", "control": "5.2.9", "level": "vhigh", "type": "SEHR HOCH", "is_isa": true, "req_anchor": "REQ 5.2.9-V2", "impl_anchor": "IMPL 5.2.9-elev", "condition": "FLAG_VERY_HIGH_PROTECTION", "requirement": "Recovery procedures are tested technically and methodically at regular intervals. (I, A)", "link": "{{LINK:R10#5.2.9}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.2.9-V3", "policy": "R10", "control": "5.2.9", "level": "vhigh", "type": "SEHR HOCH", "is_isa": true, "req_anchor": "REQ 5.2.9-V3", "impl_anchor": "IMPL 5.2.9-elev", "condition": "FLAG_VERY_HIGH_PROTECTION", "requirement": "Geographical redundancy is taken into account in backup and recovery concepts. (A)", "link": "{{LINK:R10#5.2.9}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.3.1-M1", "policy": "R11", "control": "5.3.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.3.1-M1", "impl_anchor": "IMPL 5.3.1", "condition": null, "requirement": "The information security requirements associated with the design and development of an IT service are determined and taken into account.", "link": "{{LINK:R11#5.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "5.3.1-M2", "policy": "R11", "control": "5.3.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.3.1-M2", "impl_anchor": "IMPL 5.3.1", "condition": null, "requirement": "The information security requirements associated with the procurement or extension of IT services and components are determined and taken into account.", "link": "{{LINK:R11#5.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "5.3.1-M3", "policy": "R11", "control": "5.3.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.3.1-M3", "impl_anchor": "IMPL 5.3.1", "condition": null, "requirement": "Information security requirements in connection with changes to developed IT services are taken into account.", "link": "{{LINK:R11#5.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "5.3.1-M4", "policy": "R11", "control": "5.3.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.3.1-M4", "impl_anchor": "IMPL 5.3.1", "condition": null, "requirement": "System acceptance tests are carried out taking the information security requirements into account.", "link": "{{LINK:R11#5.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "5.3.1-S1", "policy": "R11", "control": "5.3.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.3.1-S1", "impl_anchor": "IMPL 5.3.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Requirement specifications are created; the relevant aspects are taken into account.", "link": "{{LINK:R11#5.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "5.3.1-S2", "policy": "R11", "control": "5.3.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.3.1-S2", "impl_anchor": "IMPL 5.3.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Requirement specifications are checked against the information security requirements.", "link": "{{LINK:R11#5.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "5.3.1-S3", "policy": "R11", "control": "5.3.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.3.1-S3", "impl_anchor": "IMPL 5.3.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The IT service is checked for compliance with the specifications before production use.", "link": "{{LINK:R11#5.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "5.3.1-S4", "policy": "R11", "control": "5.3.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.3.1-S4", "impl_anchor": "IMPL 5.3.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The use of production data for test purposes is avoided as far as possible (anonymisation/pseudonymisation where applicable); the relevant aspects are taken into account.", "link": "{{LINK:R11#5.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "5.3.1-S5", "policy": "R11", "control": "5.3.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.3.1-S5", "impl_anchor": "IMPL 5.3.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Test systems receive protective measures comparable to the production environment when production data is used for testing.", "link": "{{LINK:R11#5.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "5.3.1-V1", "policy": "R11", "control": "5.3.1", "level": "vhigh", "type": "SEHR HOCH", "is_isa": true, "req_anchor": "REQ 5.3.1-V1", "impl_anchor": "IMPL 5.3.1-elev", "condition": "FLAG_VERY_HIGH_PROTECTION", "requirement": "The security of purpose-built or substantially adapted software is tested upon commissioning, upon substantial changes or regularly (e.g. penetration test). (C, I, A)", "link": "{{LINK:R11#5.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "5.3.2-M1", "policy": "R11", "control": "5.3.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.3.2-M1", "impl_anchor": "IMPL 5.3.2", "condition": null, "requirement": "Requirements for the information security of network services are determined and met.", "link": "{{LINK:R11#5.3.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "5.3.2-S1", "policy": "R11", "control": "5.3.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.3.2-S1", "impl_anchor": "IMPL 5.3.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "A procedure for securing and using network services is defined and implemented.", "link": "{{LINK:R11#5.3.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "5.3.2-S2", "policy": "R11", "control": "5.3.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.3.2-S2", "impl_anchor": "IMPL 5.3.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The requirements are agreed in the form of SLAs.", "link": "{{LINK:R11#5.3.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "5.3.2-S3", "policy": "R11", "control": "5.3.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.3.2-S3", "impl_anchor": "IMPL 5.3.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Appropriate redundancy solutions are implemented.", "link": "{{LINK:R11#5.3.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "5.3.2-H1", "policy": "R11", "control": "5.3.2", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 5.3.2-H1", "impl_anchor": "IMPL 5.3.2-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "Procedures for monitoring the quality of network traffic (e.g. traffic flow analyses, availability measurements) are defined and carried out. (A)", "link": "{{LINK:R11#5.3.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-16" ] }, { "id": "5.3.3-S1", "policy": "R11", "control": "5.3.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.3.3-S1", "impl_anchor": "IMPL 5.3.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "A description of the termination process is in place, adapted to changes and regulated contractually.", "link": "{{LINK:R11#5.3.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "5.3.4-M1", "policy": "R12", "control": "5.3.4", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 5.3.4-M1", "impl_anchor": "IMPL 5.3.4", "condition": null, "requirement": "An effective separation (e.g. tenant separation) prevents unauthorised users of other organisations from accessing one's own information.", "link": "{{LINK:R12#5.3.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-11" ] }, { "id": "5.3.4-S1", "policy": "R12", "control": "5.3.4", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 5.3.4-S1", "impl_anchor": "IMPL 5.3.4", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The provider's separation concept is documented and adapted to changes; the relevant aspects are taken into account.", "link": "{{LINK:R12#5.3.4}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-11" ] }, { "id": "5.3.4-KI-M1", "policy": "R12", "control": "5.3.4-KI", "level": "must", "type": "MUSS", "is_isa": false, "req_anchor": "REQ 5.3.4-KI-M1", "impl_anchor": "IMPL 5.3.4-KI", "condition": null, "requirement": "The use of AI/GenAI services is regulated; only approved services are used.", "link": "{{LINK:R12#5.3.4-KI}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-11" ] }, { "id": "5.3.4-KI-M2", "policy": "R12", "control": "5.3.4-KI", "level": "must", "type": "MUSS", "is_isa": false, "req_anchor": "REQ 5.3.4-KI-M2", "impl_anchor": "IMPL 5.3.4-KI", "condition": null, "requirement": "The input of confidential or personal information into non-approved AI services is prohibited; the permissible data classes per service are defined.", "link": "{{LINK:R12#5.3.4-KI}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-11" ] }, { "id": "5.3.4-KI-M3", "policy": "R12", "control": "5.3.4-KI", "level": "must", "type": "MUSS", "is_isa": false, "req_anchor": "REQ 5.3.4-KI-M3", "impl_anchor": "IMPL 5.3.4-KI", "condition": null, "requirement": "For approved AI services, it is clarified and contractually ensured that inputs are not used for training or passed on.", "link": "{{LINK:R12#5.3.4-KI}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-11" ] }, { "id": "5.3.4-KI-S1", "policy": "R12", "control": "5.3.4-KI", "level": "should", "type": "SOLL", "is_isa": false, "req_anchor": "REQ 5.3.4-KI-S1", "impl_anchor": "IMPL 5.3.4-KI", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Results of AI services are reviewed before business-critical use (human in the loop); the use of AI is documented and regulatory requirements (e.g. EU AI Act) are taken into account.", "link": "{{LINK:R12#5.3.4-KI}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-11" ] }, { "id": "6.1.1-M1", "policy": "R13", "control": "6.1.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 6.1.1-M1", "impl_anchor": "IMPL 6.1.1", "condition": null, "requirement": "Contractors and partners are subjected to a security risk assessment.", "link": "{{LINK:R13#6.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-10" ] }, { "id": "6.1.1-M2", "policy": "R13", "control": "6.1.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 6.1.1-M2", "impl_anchor": "IMPL 6.1.1", "condition": null, "requirement": "An appropriate level of information security is ensured through contractual agreements with contractors and partners.", "link": "{{LINK:R13#6.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-10" ] }, { "id": "6.1.1-M3", "policy": "R13", "control": "6.1.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 6.1.1-M3", "impl_anchor": "IMPL 6.1.1", "condition": null, "requirement": "Where applicable, contractual agreements with clients/customers are passed on to contractors and partners.", "link": "{{LINK:R13#6.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.1-S1", "policy": "R13", "control": "6.1.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 6.1.1-S1", "impl_anchor": "IMPL 6.1.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Contractors and partners are contractually obliged to pass on requirements for an appropriate level of information security to their subcontractors.", "link": "{{LINK:R13#6.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-10" ] }, { "id": "6.1.1-S2", "policy": "R13", "control": "6.1.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 6.1.1-S2", "impl_anchor": "IMPL 6.1.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Performance reports and documents from contractors and partners are reviewed.", "link": "{{LINK:R13#6.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.1-H1", "policy": "R13", "control": "6.1.1", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 6.1.1-H1", "impl_anchor": "IMPL 6.1.1-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "It is demonstrated that the supplier's level of information security is appropriate to the protection need (e.g. reviewed questionnaire/self-disclosure, attestation, certificate, supplier audit). (C, I, A)", "link": "{{LINK:R13#6.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.1-H2", "policy": "R13", "control": "6.1.1", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 6.1.1-H2", "impl_anchor": "IMPL 6.1.1-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "The degree of fulfilment of the required evidence by the supplier is documented, reviewed and monitored regularly and upon changes. (C, I, A)", "link": "{{LINK:R13#6.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.1-H3", "policy": "R13", "control": "6.1.1", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 6.1.1-H3", "impl_anchor": "IMPL 6.1.1-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "The supplier's compliance with contractual agreements is checked, documented, reviewed and monitored regularly and upon changes. (C, I, A)", "link": "{{LINK:R13#6.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.1-V1", "policy": "R13", "control": "6.1.1", "level": "vhigh", "type": "SEHR HOCH", "is_isa": true, "req_anchor": "REQ 6.1.1-V1", "impl_anchor": "IMPL 6.1.1-elev", "condition": "FLAG_VERY_HIGH_PROTECTION", "requirement": "The appropriate level of information security should be demonstrated by a third-party audit (an appropriate TISAX label or similar) or an appropriate supplier audit. Without an audit, management must make a risk-based decision to continue; evidence of this decision exists. (C, I, A)", "link": "{{LINK:R13#6.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.1-V2", "policy": "R13", "control": "6.1.1", "level": "vhigh", "type": "SEHR HOCH", "is_isa": true, "req_anchor": "REQ 6.1.1-V2", "impl_anchor": "IMPL 6.1.1-elev", "condition": "FLAG_VERY_HIGH_PROTECTION", "requirement": "Contractual obligations towards customers regarding transparency of supply chain risks are fulfilled. (C, I, A)", "link": "{{LINK:R13#6.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.2-M1", "policy": "R13", "control": "6.1.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 6.1.2-M1", "impl_anchor": "IMPL 6.1.2", "condition": null, "requirement": "The confidentiality requirements are determined and met.", "link": "{{LINK:R13#6.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-10" ] }, { "id": "6.1.2-M2", "policy": "R13", "control": "6.1.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 6.1.2-M2", "impl_anchor": "IMPL 6.1.2", "condition": null, "requirement": "Requirements and procedures for applying confidentiality agreements are known to all persons who pass on information requiring protection.", "link": "{{LINK:R13#6.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.2-M3", "policy": "R13", "control": "6.1.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 6.1.2-M3", "impl_anchor": "IMPL 6.1.2", "condition": null, "requirement": "Valid confidentiality agreements are concluded before information requiring protection is passed on.", "link": "{{LINK:R13#6.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.2-M4", "policy": "R13", "control": "6.1.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 6.1.2-M4", "impl_anchor": "IMPL 6.1.2", "condition": null, "requirement": "The requirements and procedures for using confidentiality agreements and for handling information requiring protection are reviewed regularly.", "link": "{{LINK:R13#6.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.2-S1", "policy": "R13", "control": "6.1.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 6.1.2-S1", "impl_anchor": "IMPL 6.1.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Templates for confidentiality agreements are available and checked for legal applicability.", "link": "{{LINK:R13#6.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-10" ] }, { "id": "6.1.2-S2", "policy": "R13", "control": "6.1.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 6.1.2-S2", "impl_anchor": "IMPL 6.1.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Confidentiality agreements cover the persons/organisations involved, the type of information, the subject matter, the period of validity and the responsibilities of the obligated party.", "link": "{{LINK:R13#6.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.2-S3", "policy": "R13", "control": "6.1.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 6.1.2-S3", "impl_anchor": "IMPL 6.1.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Confidentiality agreements contain provisions for handling information requiring protection beyond the contractual relationship.", "link": "{{LINK:R13#6.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.2-S4", "policy": "R13", "control": "6.1.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 6.1.2-S4", "impl_anchor": "IMPL 6.1.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "Ways to demonstrate compliance (e.g. review by independent third parties or audit rights) are defined.", "link": "{{LINK:R13#6.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.2-S5", "policy": "R13", "control": "6.1.2", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 6.1.2-S5", "impl_anchor": "IMPL 6.1.2", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "A process for monitoring the period of validity of temporary confidentiality agreements and for timely renewal is defined and implemented.", "link": "{{LINK:R13#6.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.3-M1", "policy": "R13", "control": "6.1.3", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 6.1.3-M1", "impl_anchor": "IMPL 6.1.3", "condition": null, "requirement": "The IT services concerned are identified.", "link": "{{LINK:R13#6.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-10" ] }, { "id": "6.1.3-M2", "policy": "R13", "control": "6.1.3", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 6.1.3-M2", "impl_anchor": "IMPL 6.1.3", "condition": null, "requirement": "The security requirements relevant to the IT service are determined.", "link": "{{LINK:R13#6.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.3-M3", "policy": "R13", "control": "6.1.3", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 6.1.3-M3", "impl_anchor": "IMPL 6.1.3", "condition": null, "requirement": "The organisation responsible for implementing the requirement is defined and aware of its responsibility.", "link": "{{LINK:R13#6.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.3-M4", "policy": "R13", "control": "6.1.3", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 6.1.3-M4", "impl_anchor": "IMPL 6.1.3", "condition": null, "requirement": "Mechanisms for shared responsibilities are specified and implemented.", "link": "{{LINK:R13#6.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.3-M5", "policy": "R13", "control": "6.1.3", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 6.1.3-M5", "impl_anchor": "IMPL 6.1.3", "condition": null, "requirement": "The responsible organisation fulfils its respective responsibilities.", "link": "{{LINK:R13#6.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.3-S1", "policy": "R13", "control": "6.1.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 6.1.3-S1", "impl_anchor": "IMPL 6.1.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "For IT services, the configuration is designed, implemented and documented on the basis of the necessary security requirements.", "link": "{{LINK:R13#6.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.3-S2", "policy": "R13", "control": "6.1.3", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 6.1.3-S2", "impl_anchor": "IMPL 6.1.3", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The responsible personnel is appropriately trained.", "link": "{{LINK:R13#6.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.3-H1", "policy": "R13", "control": "6.1.3", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 6.1.3-H1", "impl_anchor": "IMPL 6.1.3-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "A list of the IT services concerned and the respective responsible IT service providers exists. (C, I, A)", "link": "{{LINK:R13#6.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.3-H2", "policy": "R13", "control": "6.1.3", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 6.1.3-H2", "impl_anchor": "IMPL 6.1.3-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "The applicability of the ISA controls has been assessed and documented. (C, I, A)", "link": "{{LINK:R13#6.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.3-H3", "policy": "R13", "control": "6.1.3", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 6.1.3-H3", "impl_anchor": "IMPL 6.1.3-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "The service configuration is included in the regular security assessments. (C, I, A)", "link": "{{LINK:R13#6.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.3-H4", "policy": "R13", "control": "6.1.3", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 6.1.3-H4", "impl_anchor": "IMPL 6.1.3-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "It is demonstrated that the IT service providers fulfil their responsibility. (C, I, A)", "link": "{{LINK:R13#6.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "6.1.3-H5", "policy": "R13", "control": "6.1.3", "level": "high", "type": "HOCH", "is_isa": true, "req_anchor": "REQ 6.1.3-H5", "impl_anchor": "IMPL 6.1.3-elev", "condition": "FLAG_HIGH_PROTECTION", "requirement": "The integration into local protective measures (e.g. secure authentication mechanisms) is established and documented. (C, I, A)", "link": "{{LINK:R13#6.1.3}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "7.1.1-M1", "policy": "R14", "control": "7.1.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 7.1.1-M1", "impl_anchor": "IMPL 7.1.1", "condition": null, "requirement": "Legal, regulatory and contractual requirements relevant to information security are determined regularly.", "link": "{{LINK:R14#7.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-18" ] }, { "id": "7.1.1-M2", "policy": "R14", "control": "7.1.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 7.1.1-M2", "impl_anchor": "IMPL 7.1.1", "condition": null, "requirement": "Policies for complying with the requirements are defined, implemented and communicated to the responsible persons.", "link": "{{LINK:R14#7.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-18" ] }, { "id": "7.1.1-S1", "policy": "R14", "control": "7.1.1", "level": "should", "type": "SOLL", "is_isa": true, "req_anchor": "REQ 7.1.1-S1", "impl_anchor": "IMPL 7.1.1", "condition": "FLAG_INCLUDE_SHOULD", "requirement": "The integrity of records in accordance with legal, regulatory and contractual requirements as well as business requirements is taken into account.", "link": "{{LINK:R14#7.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-18" ] }, { "id": "7.1.2-M1", "policy": "R14", "control": "7.1.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 7.1.2-M1", "impl_anchor": "IMPL 7.1.2", "condition": null, "requirement": "Legal and contractual information security requirements for procedures and processes when processing personal data are determined.", "link": "{{LINK:R14#7.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-18" ] }, { "id": "7.1.2-M2", "policy": "R14", "control": "7.1.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 7.1.2-M2", "impl_anchor": "IMPL 7.1.2", "condition": null, "requirement": "Provisions for complying with legal and contractual requirements for the protection of personal data are defined and known to the persons involved.", "link": "{{LINK:R14#7.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-18" ] }, { "id": "7.1.2-M3", "policy": "R14", "control": "7.1.2", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 7.1.2-M3", "impl_anchor": "IMPL 7.1.2", "condition": null, "requirement": "Processes and procedures for protecting personal data are taken into account in the information security management system.", "link": "{{LINK:R14#7.1.2}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-18" ] }, { "id": "8.1.1-M1", "policy": "P01", "control": "8.1.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 8.1.1-M1", "impl_anchor": "REQ 8.1.1-M1", "condition": "FLAG_PROTOTYPE_PROTECTION", "requirement": "Areas in which prototypes are processed or stored are protected by defined security zones and an effective perimeter.", "implementation": "Prototype areas are designated as a dedicated security zone with access control, perimeter protection and logging.", "link": "{{LINK:P01#8.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-20" ] }, { "id": "8.2.1-M1", "policy": "P01", "control": "8.2.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 8.2.1-M1", "impl_anchor": "REQ 8.2.1-M1", "condition": "FLAG_PROTOTYPE_PROTECTION", "requirement": "Confidentiality obligations exist for prototypes; the associated information is classified and labelled.", "implementation": "All persons involved with prototypes sign confidentiality agreements; prototypes are classified as confidential or higher.", "link": "{{LINK:P01#8.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "8.3.1-M1", "policy": "P01", "control": "8.3.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 8.3.1-M1", "impl_anchor": "REQ 8.3.1-M1", "condition": "FLAG_PROTOTYPE_PROTECTION", "requirement": "Transport and storage of prototypes are carried out according to documented protection requirements that ensure confidentiality and integrity.", "implementation": "Transport and storage follow the procedure instruction VA-20: secured containers, logged handovers, access and visual protection.", "link": "{{LINK:P01#8.3.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [ "VA-20" ] }, { "id": "9.1.1-M1", "policy": "D01", "control": "9.1.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 9.1.1-M1", "impl_anchor": "REQ 9.1.1-M1", "condition": "FLAG_PERSONAL_DATA", "requirement": "Responsibilities for data protection are appointed and the data protection organisation is documented.", "implementation": "The role of data protection officer is appointed and integrated into the ISMS organisation; tasks and reporting paths are documented.", "link": "{{LINK:D01#9.1.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] }, { "id": "9.2.1-M1", "policy": "D01", "control": "9.2.1", "level": "must", "type": "MUSS", "is_isa": true, "req_anchor": "REQ 9.2.1-M1", "impl_anchor": "REQ 9.2.1-M1", "condition": "FLAG_PERSONAL_DATA", "requirement": "Processing of personal data is lawful, purpose-bound and recorded in a record of processing activities.", "implementation": "A record of processing activities is maintained; legal basis, purpose and deletion periods are documented for each processing activity.", "link": "{{LINK:D01#9.2.1}}", "nachweis_link": "{{LINK:NACHWEISREGISTER}}", "verfahren": [] } ], "verfahren": [ { "id": "VA-01", "title": "Incident-Response- und Meldeverfahren", "file": "verfahren/VA-01_Incident-Response-und-Meldeverfahren.md", "policy": "R04", "fulfills": [ "1.6.1-M1", "1.6.1-M2", "1.6.2-M1", "1.6.2-M2", "1.6.2-S1", "1.6.2-S2" ], "link": "{{LINK:VA-01}}" }, { "id": "VA-02", "title": "IT-Notfall- und Wiederanlaufverfahren (BCM)", "file": "verfahren/VA-02_IT-Notfall-und-Wiederanlaufverfahren.md", "policy": "R04", "fulfills": [ "1.6.3-M1", "1.6.3-S1", "5.2.8-M1", "5.2.8-S1" ], "link": "{{LINK:VA-02}}" }, { "id": "VA-03", "title": "Berechtigungsverfahren (Joiner/Mover/Leaver und Rezertifizierung)", "file": "verfahren/VA-03_Berechtigungsverfahren.md", "policy": "R08", "fulfills": [ "4.1.1-S1", "4.1.3-M1", "4.2.1-M1", "4.2.1-M2", "4.2.1-S1" ], "link": "{{LINK:VA-03}}" }, { "id": "VA-04", "title": "Change- und Patch-Management-Verfahren", "file": "verfahren/VA-04_Change-und-Patch-Management-Verfahren.md", "policy": "R10", "fulfills": [ "5.2.1-M1", "5.2.5-M1" ], "link": "{{LINK:VA-04}}" }, { "id": "VA-05", "title": "Backup- und Restore-Verfahren", "file": "verfahren/VA-05_Backup-und-Restore-Verfahren.md", "policy": "R10", "fulfills": [ "5.2.9-M1", "5.2.9-M2", "5.2.9-S1" ], "link": "{{LINK:VA-05}}" }, { "id": "VA-06", "title": "Schwachstellenmanagement-Verfahren", "file": "verfahren/VA-06_Schwachstellenmanagement-Verfahren.md", "policy": "R10", "fulfills": [ "5.2.5-M1", "5.2.5-S1", "5.2.6-M1" ], "link": "{{LINK:VA-06}}" }, { "id": "VA-07", "title": "Kryptokonzept und Schlüsselverwaltung", "file": "verfahren/VA-07_Kryptokonzept-und-Schluesselverwaltung.md", "policy": "R09", "fulfills": [ "5.1.1-M1", "5.1.1-M2", "5.1.1-S1", "5.1.2-M1", "5.1.2-S1" ], "link": "{{LINK:VA-07}}" }, { "id": "VA-08", "title": "Asset- und Klassifizierungsverfahren", "file": "verfahren/VA-08_Asset-und-Klassifizierungsverfahren.md", "policy": "R02", "fulfills": [ "1.3.1-M1", "1.3.1-M2", "1.3.1-S1", "1.3.2-M1", "1.3.2-M2", "1.3.2-S1" ], "link": "{{LINK:VA-08}}" }, { "id": "VA-09", "title": "Risikomanagement-Verfahren", "file": "verfahren/VA-09_Risikomanagement-Verfahren.md", "policy": "R03", "fulfills": [ "1.4.1-M1", "1.4.1-M2", "1.4.1-M3", "1.4.1-S1" ], "link": "{{LINK:VA-09}}" }, { "id": "VA-10", "title": "Lieferanten-Onboarding- und Bewertungsverfahren", "file": "verfahren/VA-10_Lieferanten-Onboarding-und-Bewertung.md", "policy": "R13", "fulfills": [ "6.1.1-M1", "6.1.1-M2", "6.1.1-S1", "6.1.2-M1", "6.1.2-S1", "6.1.3-M1" ], "link": "{{LINK:VA-10}}" }, { "id": "VA-11", "title": "Cloud- und KI-Freigabeverfahren", "file": "verfahren/VA-11_Cloud-und-KI-Freigabeverfahren.md", "policy": "R12", "fulfills": [ "5.3.4-M1", "5.3.4-M2", "5.3.4-S1", "5.3.4-KI-M1", "5.3.4-KI-M2", "5.3.4-KI-M3", "5.3.4-KI-S1" ], "link": "{{LINK:VA-11}}" }, { "id": "VA-12", "title": "Awareness- und Schulungsverfahren", "file": "verfahren/VA-12_Awareness-und-Schulungsverfahren.md", "policy": "R05", "fulfills": [ "2.1.3-M1", "2.1.3-S1" ], "link": "{{LINK:VA-12}}" }, { "id": "VA-13", "title": "Logging- und Monitoring-Verfahren", "file": "verfahren/VA-13_Logging-und-Monitoring-Verfahren.md", "policy": "R10", "fulfills": [ "5.2.4-M1", "5.2.4-S1" ], "link": "{{LINK:VA-13}}" }, { "id": "VA-14", "title": "Personalsicherheit – Eignungsprüfung & sensible Tätigkeiten", "file": "verfahren/VA-14_Personalsicherheit-Eignungspruefung.md", "policy": "R05", "fulfills": [ "2.1.1-M1", "2.1.1-M2", "2.1.1-M3", "2.1.1-S1", "2.1.1-S2", "2.1.2-M1", "2.1.2-M2", "2.1.2-S1", "2.1.2-S2", "2.1.2-S3" ], "link": "{{LINK:VA-14}}" }, { "id": "VA-15", "title": "Interne Audits & Complianceprüfungen", "file": "verfahren/VA-15_Interne-Audits-und-Compliancepruefungen.md", "policy": "R03", "fulfills": [ "1.5.1-M1", "1.5.1-M2", "1.5.1-M3", "1.5.1-M4", "1.5.1-M5", "1.5.1-S1", "1.5.2-M1", "1.5.2-M2", "1.5.2-S1" ], "link": "{{LINK:VA-15}}" }, { "id": "VA-16", "title": "Sichere Beschaffung, Entwicklung & Abnahme", "file": "verfahren/VA-16_Sichere-Beschaffung-Entwicklung-und-Abnahme.md", "policy": "R11", "fulfills": [ "5.3.1-M1", "5.3.1-M2", "5.3.1-M3", "5.3.1-M4", "5.3.1-S1", "5.3.1-S2", "5.3.1-S3", "5.3.1-S4", "5.3.1-S5", "5.3.1-V1", "5.3.2-M1", "5.3.2-S1", "5.3.2-S2", "5.3.2-S3", "5.3.2-H1" ], "link": "{{LINK:VA-16}}" }, { "id": "VA-17", "title": "Zutritts- & Besuchermanagement (physisch)", "file": "verfahren/VA-17_Zutritts-und-Besuchermanagement.md", "policy": "R07", "fulfills": [ "3.1.1-S1", "3.1.1-S2", "3.1.1-S3", "3.1.1-S4", "3.1.1-S5" ], "link": "{{LINK:VA-17}}" }, { "id": "VA-18", "title": "Datenschutz- & Compliance-Pflege", "file": "verfahren/VA-18_Datenschutz-und-Compliance-Pflege.md", "policy": "R14", "fulfills": [ "7.1.1-M1", "7.1.1-M2", "7.1.1-S1", "7.1.2-M1", "7.1.2-M2", "7.1.2-M3" ], "link": "{{LINK:VA-18}}" }, { "id": "VA-19", "title": "Informationssicherheit in Projekten", "file": "verfahren/VA-19_Informationssicherheit-in-Projekten.md", "policy": "R01", "fulfills": [ "1.2.3-M1", "1.2.3-S1", "1.2.3-S2", "1.2.3-S3", "1.2.3-H1" ], "link": "{{LINK:VA-19}}" }, { "id": "VA-20", "title": "Prototypen-Zutritt und -Transport", "file": "verfahren/VA-20_Prototypen-Zutritt-und-Transport.md", "policy": "P01", "fulfills": [ "8.1.1-M1", "8.3.1-M1" ], "link": "{{LINK:VA-20}}" } ] }