# Policy Mobile Working and Mobile Devices | Document information | Value | |-----------------------|------| | Document type | Policy | | Scope | {{ISMS_SCOPE}} | | Organisation | {{ORG_NAME}} | | Responsible | {{ROLE_ISB}} | | Approved by | {{ROLE_MANAGEMENT}} | | Version | {{DOC_VERSION}} | | Date | {{DOC_DATE}} | | Status | {{DOC_STATUS}} | ## 1. Purpose This policy governs mobile working as well as the handling of mobile IT devices and data media. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027. ## 2. Scope This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}). ## 3. Requirements and implementation > Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary). {{#if FLAG_MOBILE_WORK}} ### 3.1 Mobile working *Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 2.1.4{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.6.7{{/if}} **Requirement** {{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}} - **[MUST]** The requirements for mobile working are determined and met; the relevant aspects are taken into account. {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** The relevant aspects of mobile working are taken into account. {{/if}} {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** Awareness of employees. {{/if}} {{#if FLAG_HIGH_PROTECTION}} - **[HIGH]** Protective measures against eavesdropping and being overlooked are implemented. (C) {{/if}} {{/if}} {{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}} - **[ISO A.6.7]** Security measures for working outside the organisation's premises are implemented. {{/if}} **Implementation at {{ORG_NAME}}** Mobile working is defined in this policy and the associated mobile working rule (stored in {{TOOL_NAME}}) and the requirements are met; access is exclusively via {{TECH_VPN}} with MFA (BL-IAM-02) and approved, encrypted devices (BL-CRY-03). Employees are made aware (BL-HR-01). {{#if FLAG_ELEVATED_PROTECTION}} Where the protection need is high, protective measures against eavesdropping and being overlooked are implemented (e.g. privacy screen, quiet environment, clean screen). {{/if}} {{/if}} {{#if FLAG_MOBILE_DEVICES}} ### 3.2 Mobile IT devices and data media *Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 3.1.4{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.7.9, A.7.10, A.8.1{{/if}} **Requirement** {{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}} - **[MUST]** The requirements for mobile IT devices and mobile data media are determined and met; the relevant aspects are taken into account. {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** Registration of the IT devices. {{/if}} {{#if FLAG_HIGH_PROTECTION}} - **[HIGH]** General encryption of mobile data media or of the information assets stored on them. Where technically not feasible, information is protected by equivalent measures. (C, I) {{/if}} {{/if}} {{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}} - **[ISO A.7.9]** Assets used outside the premises are protected. - **[ISO A.7.10]** Storage media are protected throughout their life cycle (acquisition, use, transport, disposal) in accordance with the classification scheme. - **[ISO A.8.1]** Information stored on, processed by or accessible via user endpoint devices is protected. {{/if}} **Implementation at {{ORG_NAME}}** The requirements for mobile devices and data media are determined and met: devices are registered and centrally managed via {{TECH_MDM}}, only approved devices are used; loss is reported via the reporting path (R04) and {{TOOL_TICKET}}, blocking/wiping upon loss via {{TECH_MDM}} (BL-EP-02). {{#if FLAG_ELEVATED_PROTECTION}} Where the protection need is high, mobile data media or the information stored on them are generally encrypted (BL-CRY-03); where not feasible, equivalent protective measures apply. {{/if}} {{/if}} ## 4. Binding nature This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_ISB}}. ## 5. Roles and responsibilities | Role | Responsibility in this policy | |-------|-------------------------------------| | {{ROLE_ISB}} | Security requirements | | {{ROLE_IT_LEAD}} | Technical implementation | ## 6. Review and update This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_ISB}} and approved by {{ROLE_MANAGEMENT}}. ## 7. Evidence The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}). ## 8. Related documents - Technical security baseline: {{LINK:BASELINE}} - ISA mapping matrix: {{LINK:ISA_MAPPING}} - Evidence register: {{LINK:NACHWEISREGISTER}} - Further: {{LINK:R05}}, {{LINK:R07}}, {{LINK:R08}}