# Policy Secure System Procurement and Development | Document information | Value | |-----------------------|------| | Document type | Policy | | Scope | {{ISMS_SCOPE}} | | Organisation | {{ORG_NAME}} | | Responsible | {{ROLE_IT_LEAD}} | | Approved by | {{ROLE_MANAGEMENT}} | | Version | {{DOC_VERSION}} | | Date | {{DOC_DATE}} | | Status | {{DOC_STATUS}} | ## 1. Purpose This policy governs information security in procurement and development, requirements for network services as well as return and secure deletion. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027. ## 2. Scope This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}). ## 3. Requirements and implementation > Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary). ### 3.1 Security in procurement and development *Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.3.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.4, A.8.25, A.8.26, A.8.27, A.8.28, A.8.29, A.8.30, A.8.33{{/if}} **Requirement** {{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}} - **[MUST]** The information security requirements associated with the design and development of an IT service are determined and taken into account. - **[MUST]** The information security requirements associated with the procurement or extension of IT services and components are determined and taken into account. - **[MUST]** Information security requirements in connection with changes to developed IT services are taken into account. - **[MUST]** System acceptance tests are carried out taking the information security requirements into account. {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** Requirement specifications are created; the relevant aspects are taken into account. {{/if}} {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** Requirement specifications are checked against the information security requirements. {{/if}} {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** The IT service is checked for compliance with the specifications before production use. {{/if}} {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** The use of production data for test purposes is avoided as far as possible (anonymisation/pseudonymisation where applicable); the relevant aspects are taken into account. {{/if}} {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** Test systems receive protective measures comparable to the production environment when production data is used for testing. {{/if}} {{#if FLAG_VERY_HIGH_PROTECTION}} - **[VERY HIGH]** The security of purpose-built or substantially adapted software is tested upon commissioning, upon substantial changes or regularly (e.g. penetration test). (C, I, A) {{/if}} {{/if}} {{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}} - **[ISO A.8.4]** Read and write access to source code, development tools and software libraries is appropriately managed. - **[ISO A.8.25]** Rules for a secure development life cycle of software and systems are established and applied. - **[ISO A.8.26]** Information security requirements are identified, specified and taken into account when developing or acquiring applications. - **[ISO A.8.27]** Principles for engineering secure systems are established, documented and applied. - **[ISO A.8.28]** Secure coding principles are applied to software development. - **[ISO A.8.29]** Security testing is integrated into the development and acceptance process. - **[ISO A.8.30]** Outsourced system development is directed, monitored and reviewed. - **[ISO A.8.33]** Test information is selected, protected and managed with care. {{/if}} **Implementation at {{ORG_NAME}}** Information security requirements are an integral part of the design, procurement, extension and modification of IT services (security by design); requirement specification, review and acceptance tests under security aspects are carried out following the procedure Secure Procurement/Development & Acceptance ({{LINK:VA-16}}); production deployment only after review in {{TOOL_TICKET}}. Production data in tests is avoided/anonymised, and test systems are appropriately protected.{{#if FLAG_DEV_INHOUSE}} For in-house development, secure coding requirements apply with code reviews and automated security tests (SAST/dependency scan) in accordance with {{LINK:VA-16}}.{{/if}} {{#if FLAG_ELEVATED_PROTECTION}} {{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, the security of purpose-built or substantially adapted software is tested upon commissioning, upon substantial changes or regularly (penetration test).{{/if}} {{/if}} ### 3.2 Requirements for network services *Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.3.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.21{{/if}} **Requirement** {{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}} - **[MUST]** Requirements for the information security of network services are determined and met. {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** A procedure for securing and using network services is defined and implemented. {{/if}} {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** The requirements are agreed in the form of SLAs. {{/if}} {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** Appropriate redundancy solutions are implemented. {{/if}} {{#if FLAG_HIGH_PROTECTION}} - **[HIGH]** Procedures for monitoring the quality of network traffic (e.g. traffic flow analyses, availability measurements) are defined and carried out. (A) {{/if}} {{/if}} {{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}} - **[ISO A.8.21]** Security mechanisms, service levels and requirements for network services are identified, implemented and monitored. {{/if}} **Implementation at {{ORG_NAME}}** For the network services used (internal/external), security requirements are determined, agreed in SLAs and implemented via a procedure; appropriate redundancies are in place. {{#if FLAG_ELEVATED_PROTECTION}} Where the protection need is high, procedures for monitoring network traffic quality (traffic flow analyses, availability measurements) are defined and carried out. {{/if}} ### 3.3 Return and secure deletion *Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.3.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.11, A.7.14, A.8.10{{/if}} **Requirement** {{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}} {{#if FLAG_INCLUDE_SHOULD}} - **[SHOULD]** A description of the termination process is in place, adapted to changes and regulated contractually. {{/if}} {{/if}} {{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}} - **[ISO A.5.11]** Personnel and external users return all assets in their possession upon termination of employment or contract. - **[ISO A.7.14]** Equipment containing storage media is securely sanitised before disposal or re-use. - **[ISO A.8.10]** Information stored in systems and on media is deleted when no longer required. {{/if}} **Implementation at {{ORG_NAME}}** Return and secure deletion/destruction of information and assets (upon end of contract, device decommissioning) are regulated according to BL-DEL-01, agreed contractually, adapted to changes and evidenced (deletion log). ## 4. Binding nature This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_IT_LEAD}}. ## 5. Roles and responsibilities | Role | Responsibility in this policy | |-------|-------------------------------------| | {{ROLE_IT_LEAD}} | Procurement/development | | {{ROLE_ISB}} | Security requirements | ## 6. Review and update This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_IT_LEAD}} and approved by {{ROLE_MANAGEMENT}}. ## 7. Evidence The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}). ## 8. Related documents - Technical security baseline: {{LINK:BASELINE}} - ISA mapping matrix: {{LINK:ISA_MAPPING}} - Evidence register: {{LINK:NACHWEISREGISTER}} - Further: {{LINK:R02}}, {{LINK:R10}}, {{LINK:R12}}