{ "hinweis": "Englische Paraphrasen der ISO/IEC-27001:2022-Anforderungen (keine Normzitate). Struktur (Zuordnung, Bedingungen, Verfahren) kommt aus _iso_crosswalk.json.", "texte": { "4.1": { "title": "Understanding the organisation and its context", "requirement": "Internal and external issues that affect the ability to achieve the ISMS objectives are determined and kept up to date." }, "4.2": { "title": "Needs of interested parties", "requirement": "The interested parties relevant to the ISMS and their information security requirements are determined." }, "4.3": { "title": "Scope of the ISMS", "requirement": "The scope of the ISMS is determined considering the issues, requirements and interfaces, and maintained as documented information." }, "4.4": { "title": "Information security management system", "requirement": "An ISMS is established, implemented, maintained and continually improved." }, "5.1": { "title": "Leadership and commitment", "requirement": "Top management demonstrates leadership and commitment with respect to the ISMS." }, "5.2": { "title": "Information security policy", "requirement": "An information security policy is established that fits the organisation, sets objectives, commits to meeting requirements and to continual improvement, and is communicated and available." }, "5.3": { "title": "Roles, responsibilities and authorities", "requirement": "Responsibilities and authorities for security-relevant roles are assigned and communicated." }, "6.1.1": { "title": "Actions to address risks and opportunities", "requirement": "When planning the ISMS, risks and opportunities that need to be addressed are determined." }, "6.1.2": { "title": "Information security risk assessment", "requirement": "A risk assessment process with defined criteria is established and applied so that it is repeatable and produces comparable results." }, "6.1.3": { "title": "Information security risk treatment", "requirement": "A risk treatment process is defined; necessary controls are determined and compared against Annex A in a Statement of Applicability." }, "6.2": { "title": "Information security objectives and planning", "requirement": "Information security objectives are established for relevant functions and levels, and their achievement is planned." }, "6.3": { "title": "Planning of changes", "requirement": "Changes to the ISMS are carried out in a planned manner." }, "7.1": { "title": "Resources", "requirement": "The resources needed for the ISMS are determined and provided." }, "7.2": { "title": "Competence", "requirement": "The necessary competence is determined and ensured; corresponding evidence is retained." }, "7.3": { "title": "Awareness", "requirement": "Persons under the organisation's control are aware of the policy, their contribution and the consequences of non-conformance." }, "7.4": { "title": "Communication", "requirement": "The internal and external communications relevant to the ISMS are determined." }, "7.5.1": { "title": "Documented information — general", "requirement": "The ISMS includes the documented information required by the standard and that determined as necessary." }, "7.5.2": { "title": "Creating and updating", "requirement": "When creating and updating documented information, identification, format and medium as well as review and approval are ensured." }, "7.5.3": { "title": "Control of documented information", "requirement": "Documented information is controlled: availability, protection, distribution, access, retention and change control." }, "8.1": { "title": "Operational planning and control", "requirement": "The processes needed to meet the requirements are planned, implemented and controlled; planned changes are controlled." }, "8.2": { "title": "Information security risk assessment (performance)", "requirement": "Risk assessments are performed at planned intervals and upon significant change, and are documented." }, "8.3": { "title": "Information security risk treatment (performance)", "requirement": "The risk treatment plan is implemented and the results are documented." }, "9.1": { "title": "Monitoring, measurement, analysis and evaluation", "requirement": "The information security performance and the effectiveness of the ISMS are monitored, measured, analysed and evaluated." }, "9.2": { "title": "Internal audit", "requirement": "Internal audits are conducted at planned intervals to verify conformity and effective implementation of the ISMS." }, "9.3": { "title": "Management review", "requirement": "Top management reviews the ISMS at planned intervals." }, "10.1": { "title": "Continual improvement", "requirement": "The suitability, adequacy and effectiveness of the ISMS are continually improved." }, "10.2": { "title": "Nonconformity and corrective action", "requirement": "In the event of nonconformity, corrections are made and corrective actions are taken to eliminate the causes." }, "A.5.1": { "title": "Policies for information security", "requirement": "The information security policy and topic-specific policies are defined, approved by management, published, communicated, acknowledged and reviewed at planned intervals." }, "A.5.2": { "title": "Information security roles and responsibilities", "requirement": "Information security roles and responsibilities are defined and allocated." }, "A.5.3": { "title": "Segregation of duties", "requirement": "Conflicting duties and areas of responsibility are segregated to reduce unauthorised or unintentional modification and misuse." }, "A.5.4": { "title": "Management responsibilities", "requirement": "Management requires all personnel to apply information security in accordance with the established requirements." }, "A.5.5": { "title": "Contact with authorities", "requirement": "Appropriate contacts with relevant authorities are established and maintained." }, "A.5.6": { "title": "Contact with special interest groups", "requirement": "Appropriate contacts with special interest groups, professional forums and security associations are maintained." }, "A.5.7": { "title": "Threat intelligence", "requirement": "Information on threats is collected and analysed to produce and use threat intelligence." }, "A.5.8": { "title": "Information security in project management", "requirement": "Information security is integrated into project management." }, "A.5.9": { "title": "Inventory of information and other associated assets", "requirement": "An inventory of information and associated assets, including owners, is established and maintained." }, "A.5.10": { "title": "Acceptable use of information and other associated assets", "requirement": "Rules for the acceptable use and handling of information and assets are defined, documented and implemented." }, "A.5.11": { "title": "Return of assets", "requirement": "Personnel and external users return all assets in their possession upon termination of employment or contract." }, "A.5.12": { "title": "Classification of information", "requirement": "Information is classified according to its protection needs (confidentiality, integrity, availability)." }, "A.5.13": { "title": "Labelling of information", "requirement": "Procedures for labelling information in accordance with the classification scheme are developed and implemented." }, "A.5.14": { "title": "Information transfer", "requirement": "Rules, procedures and agreements for the secure transfer of information are established for all transfer channels in use." }, "A.5.15": { "title": "Access control", "requirement": "Rules to control physical and logical access to information and assets are established and implemented on the basis of business and information security requirements." }, "A.5.16": { "title": "Identity management", "requirement": "The full life cycle of identities is managed." }, "A.5.17": { "title": "Authentication information", "requirement": "Allocation and management of authentication information is controlled by a suitable management process." }, "A.5.18": { "title": "Access rights", "requirement": "Access rights are provisioned, reviewed, modified and removed in accordance with the access control policy." }, "A.5.19": { "title": "Information security in supplier relationships", "requirement": "Processes to manage the information security risks arising from supplier relationships are defined and implemented." }, "A.5.20": { "title": "Addressing information security within supplier agreements", "requirement": "Relevant information security requirements are agreed with each supplier and recorded contractually." }, "A.5.21": { "title": "Managing information security in the ICT supply chain", "requirement": "Processes to manage information security risks in the ICT product and service supply chain are defined and implemented." }, "A.5.22": { "title": "Monitoring, review and change management of supplier services", "requirement": "The information security of supplier services is monitored and reviewed regularly, and changes are managed." }, "A.5.23": { "title": "Information security for use of cloud services", "requirement": "Processes for acquisition, use, management and exit of cloud services are established in line with the information security requirements." }, "A.5.24": { "title": "Information security incident management planning and preparation", "requirement": "The management of information security incidents is planned and prepared (roles, processes, responsibilities)." }, "A.5.25": { "title": "Assessment and decision on information security events", "requirement": "Information security events are assessed and a decision is taken whether they are to be categorised as incidents." }, "A.5.26": { "title": "Response to information security incidents", "requirement": "Information security incidents are responded to in accordance with documented procedures." }, "A.5.27": { "title": "Learning from information security incidents", "requirement": "Knowledge gained from information security incidents is used to strengthen the controls." }, "A.5.28": { "title": "Collection of evidence", "requirement": "Procedures for the identification, collection, acquisition and preservation of evidence relating to incidents are established and implemented." }, "A.5.29": { "title": "Information security during disruption", "requirement": "The maintenance of information security during disruption is planned and implemented." }, "A.5.30": { "title": "ICT readiness for business continuity", "requirement": "ICT readiness is planned, implemented and tested on the basis of the business continuity objectives and requirements." }, "A.5.31": { "title": "Legal, statutory, regulatory and contractual requirements", "requirement": "Legal, statutory, regulatory and contractual information security requirements are identified, documented and kept up to date." }, "A.5.32": { "title": "Intellectual property rights", "requirement": "Appropriate procedures to protect intellectual property rights are implemented." }, "A.5.33": { "title": "Protection of records", "requirement": "Records are protected against loss, destruction, falsification, unauthorised access and unauthorised release." }, "A.5.34": { "title": "Privacy and protection of PII", "requirement": "Requirements for the protection of personally identifiable information are identified and met in accordance with applicable obligations." }, "A.5.35": { "title": "Independent review of information security", "requirement": "The organisation's approach to managing information security is reviewed independently at planned intervals." }, "A.5.36": { "title": "Compliance with policies, rules and standards for information security", "requirement": "Compliance with the information security policy, topic-specific policies, rules and standards is reviewed regularly." }, "A.5.37": { "title": "Documented operating procedures", "requirement": "Operating procedures for information processing facilities are documented and made available to the personnel concerned." }, "A.6.1": { "title": "Screening", "requirement": "Background verification of candidates is carried out appropriately to the business requirements and in accordance with the law." }, "A.6.2": { "title": "Terms and conditions of employment", "requirement": "The employment agreements state the responsibilities for information security." }, "A.6.3": { "title": "Information security awareness, education and training", "requirement": "Personnel receive appropriate awareness, education and training as well as regular updates of the relevant policies." }, "A.6.4": { "title": "Disciplinary process", "requirement": "A disciplinary process for information security violations is established and communicated." }, "A.6.5": { "title": "Responsibilities after termination or change of employment", "requirement": "Continuing information security responsibilities after termination or change of employment are defined and enforced." }, "A.6.6": { "title": "Confidentiality or non-disclosure agreements", "requirement": "Confidentiality or non-disclosure agreements are identified, documented and reviewed regularly." }, "A.6.7": { "title": "Remote working", "requirement": "Security measures for working outside the organisation's premises are implemented." }, "A.6.8": { "title": "Information security event reporting", "requirement": "A mechanism for the timely reporting of observed or suspected information security events is provided." }, "A.7.1": { "title": "Physical security perimeters", "requirement": "Security perimeters are defined and used to protect areas containing information and assets." }, "A.7.2": { "title": "Physical entry", "requirement": "Secure entry controls and entry points are established to restrict access to authorised persons." }, "A.7.3": { "title": "Securing offices, rooms and facilities", "requirement": "Physical security for offices, rooms and facilities is designed and implemented." }, "A.7.4": { "title": "Physical security monitoring", "requirement": "Premises are continuously monitored for unauthorised physical access." }, "A.7.5": { "title": "Protecting against physical and environmental threats", "requirement": "Protection against physical and environmental threats is designed and implemented." }, "A.7.6": { "title": "Working in secure areas", "requirement": "Measures for working in secure areas are defined and implemented." }, "A.7.7": { "title": "Clear desk and clear screen", "requirement": "Rules for a clear desk and locked screens are defined and implemented." }, "A.7.8": { "title": "Equipment siting and protection", "requirement": "Equipment is sited securely and protected." }, "A.7.9": { "title": "Security of assets off-premises", "requirement": "Assets used outside the premises are protected." }, "A.7.10": { "title": "Storage media", "requirement": "Storage media are protected throughout their life cycle (acquisition, use, transport, disposal) in accordance with the classification scheme." }, "A.7.11": { "title": "Supporting utilities", "requirement": "Facilities are protected against failure and disruption of supporting utilities such as power and air conditioning." }, "A.7.12": { "title": "Cabling security", "requirement": "Power and data cabling is protected against interception, interference and damage." }, "A.7.13": { "title": "Equipment maintenance", "requirement": "Equipment is maintained properly to ensure availability and integrity." }, "A.7.14": { "title": "Secure disposal or re-use of equipment", "requirement": "Equipment containing storage media is securely sanitised before disposal or re-use." }, "A.8.1": { "title": "User endpoint devices", "requirement": "Information stored on, processed by or accessible via user endpoint devices is protected." }, "A.8.2": { "title": "Privileged access rights", "requirement": "The allocation and use of privileged access rights is restricted and closely managed." }, "A.8.3": { "title": "Information access restriction", "requirement": "Access to information and application functions is restricted in accordance with the access control policy." }, "A.8.4": { "title": "Access to source code", "requirement": "Read and write access to source code, development tools and software libraries is appropriately managed." }, "A.8.5": { "title": "Secure authentication", "requirement": "Secure authentication technologies and procedures are used on the basis of the access restrictions and the access control policy." }, "A.8.6": { "title": "Capacity management", "requirement": "Resources are monitored and capacity is adjusted to current and expected demand." }, "A.8.7": { "title": "Protection against malware", "requirement": "Protection against malware is implemented and supported by appropriate user awareness." }, "A.8.8": { "title": "Management of technical vulnerabilities", "requirement": "Information on technical vulnerabilities is obtained, exposure is evaluated and appropriate measures are taken." }, "A.8.9": { "title": "Configuration management", "requirement": "Configurations of hardware, software, services and networks are established, documented, implemented, monitored and reviewed." }, "A.8.10": { "title": "Information deletion", "requirement": "Information stored in systems and on media is deleted when no longer required." }, "A.8.11": { "title": "Data masking", "requirement": "Data masking is applied in accordance with the access control and privacy requirements." }, "A.8.12": { "title": "Data leakage prevention", "requirement": "Measures to prevent data leakage are applied to systems, networks and devices that process sensitive information." }, "A.8.13": { "title": "Information backup", "requirement": "Backup copies of information, software and systems are created in accordance with the backup concept and tested regularly." }, "A.8.14": { "title": "Redundancy of information processing facilities", "requirement": "Information processing facilities are implemented with sufficient redundancy to meet the availability requirements." }, "A.8.15": { "title": "Logging", "requirement": "Logs of activities, exceptions, faults and events are produced, stored, protected and analysed." }, "A.8.16": { "title": "Monitoring activities", "requirement": "Networks, systems and applications are monitored for anomalous behaviour and potential incidents are evaluated." }, "A.8.17": { "title": "Clock synchronisation", "requirement": "System clocks are synchronised to approved time sources." }, "A.8.18": { "title": "Use of privileged utility programs", "requirement": "The use of utility programs capable of overriding system and application controls is restricted and tightly controlled." }, "A.8.19": { "title": "Installation of software on operational systems", "requirement": "Procedures and measures for securely managing software installation on operational systems are implemented." }, "A.8.20": { "title": "Networks security", "requirement": "Networks and network devices are secured, managed and controlled to protect information." }, "A.8.21": { "title": "Security of network services", "requirement": "Security mechanisms, service levels and requirements for network services are identified, implemented and monitored." }, "A.8.22": { "title": "Segregation of networks", "requirement": "Groups of information services, users and systems are segregated in networks." }, "A.8.23": { "title": "Web filtering", "requirement": "Access to external websites is managed to reduce exposure to malicious content." }, "A.8.24": { "title": "Use of cryptography", "requirement": "Rules for the effective use of cryptography, including key management, are defined and implemented." }, "A.8.25": { "title": "Secure development life cycle", "requirement": "Rules for a secure development life cycle of software and systems are established and applied." }, "A.8.26": { "title": "Application security requirements", "requirement": "Information security requirements are identified, specified and taken into account when developing or acquiring applications." }, "A.8.27": { "title": "Secure system architecture and engineering principles", "requirement": "Principles for engineering secure systems are established, documented and applied." }, "A.8.28": { "title": "Secure coding", "requirement": "Secure coding principles are applied to software development." }, "A.8.29": { "title": "Security testing in development and acceptance", "requirement": "Security testing is integrated into the development and acceptance process." }, "A.8.30": { "title": "Outsourced development", "requirement": "Outsourced system development is directed, monitored and reviewed." }, "A.8.31": { "title": "Separation of development, test and production environments", "requirement": "Development, test and production environments are separated and protected." }, "A.8.32": { "title": "Change management", "requirement": "Changes to information processing facilities and systems are subject to change management." }, "A.8.33": { "title": "Test information", "requirement": "Test information is selected, protected and managed with care." }, "A.8.34": { "title": "Protection of information systems during audit testing", "requirement": "Audit tests and similar activities on operational systems are planned and agreed to avoid disruption." } } }