Files
craftvia/seed/isms-vorlagenpaket-v2-en/Statement-of-Applicability-ISO.md
msolarczekandClaude Opus 5 c8e6f30a27
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s
Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 11:05:39 +02:00

16 KiB

Statement of Applicability

Document information Value
Document type Statement of Applicability
Scope {{ISMS_SCOPE}}
Organisation {{ORG_NAME}}
Responsible {{ROLE_ISB}}
Approved by {{ROLE_MANAGEMENT}}
Version {{DOC_VERSION}}
Date {{DOC_DATE}}
Status {{DOC_STATUS}}

Purpose

For each control of Annex A of ISO/IEC 27001:2022 this statement records whether it is applicable, why it was included or excluded, what it derives from and how far it is implemented (ISO/IEC 27001:2022, 6.1.3 d). It is updated with every risk assessment ({{RISK_REVIEW_CYCLE}}) and approved by {{ROLE_MANAGEMENT}}. The procedure is set out in {{LINK:R03}}.

Columns: Applicable = yes/no · Justification = reason for inclusion or exclusion · Origin = risk ID, legal or contractual requirement · Status = implemented / partial / planned · Evidence = reference into the evidence register ({{LINK:NACHWEISREGISTER}}).

A.5 Organisational controls (37 controls)

Control Title Applicable Justification Origin Status Policy Procedure Evidence
A.5.1 Policies for information security yes Determined as necessary by the risk treatment. {{LINK:L00}} -
A.5.2 Information security roles and responsibilities yes Determined as necessary by the risk treatment. {{LINK:R01}} -
A.5.3 Segregation of duties yes Determined as necessary by the risk treatment. {{LINK:R01}} -
A.5.4 Management responsibilities yes Determined as necessary by the risk treatment. {{LINK:R01}} -
A.5.5 Contact with authorities yes Determined as necessary by the risk treatment. {{LINK:R01}} -
A.5.6 Contact with special interest groups yes Determined as necessary by the risk treatment. {{LINK:R01}} -
A.5.7 Threat intelligence yes Determined as necessary by the risk treatment. {{LINK:R10}} -
A.5.8 Information security in project management yes Determined as necessary by the risk treatment. {{LINK:R01}} VA-19
A.5.9 Inventory of information and other associated assets yes Determined as necessary by the risk treatment. {{LINK:R02}} VA-08
A.5.10 Acceptable use of information and other associated assets yes Determined as necessary by the risk treatment. {{LINK:R02}} VA-08
A.5.11 Return of assets yes Determined as necessary by the risk treatment. {{LINK:R11}} VA-08
A.5.12 Classification of information yes Determined as necessary by the risk treatment. {{LINK:R02}} VA-08
A.5.13 Labelling of information yes Determined as necessary by the risk treatment. {{LINK:R02}} VA-08
A.5.14 Information transfer yes Determined as necessary by the risk treatment. {{LINK:R09}} -
A.5.15 Access control yes Determined as necessary by the risk treatment. {{LINK:R08}} VA-03
A.5.16 Identity management yes Determined as necessary by the risk treatment. {{LINK:R08}} VA-03
A.5.17 Authentication information yes Determined as necessary by the risk treatment. {{LINK:R08}} VA-03
A.5.18 Access rights yes Determined as necessary by the risk treatment. {{LINK:R08}} VA-03
A.5.19 Information security in supplier relationships yes Determined as necessary by the risk treatment. {{LINK:R13}} VA-10
A.5.20 Addressing information security within supplier agreements yes Determined as necessary by the risk treatment. {{LINK:R13}} VA-10
A.5.21 Managing information security in the ICT supply chain yes Determined as necessary by the risk treatment. {{LINK:R13}} VA-10
A.5.22 Monitoring, review and change management of supplier services yes Determined as necessary by the risk treatment. {{LINK:R13}} VA-10
A.5.23 Information security for use of cloud services {{#if FLAG_CLOUD_USED}}yes{{/if}}{{#unless FLAG_CLOUD_USED}}no{{/unless}} {{#if FLAG_CLOUD_USED}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_CLOUD_USED}}Not applicable - enter justification.{{/unless}} {{LINK:R12}} VA-11
A.5.24 Information security incident management planning and preparation yes Determined as necessary by the risk treatment. {{LINK:R04}} VA-01
A.5.25 Assessment and decision on information security events yes Determined as necessary by the risk treatment. {{LINK:R04}} VA-01
A.5.26 Response to information security incidents yes Determined as necessary by the risk treatment. {{LINK:R04}} VA-01
A.5.27 Learning from information security incidents yes Determined as necessary by the risk treatment. {{LINK:R04}} VA-01
A.5.28 Collection of evidence yes Determined as necessary by the risk treatment. {{LINK:R04}} VA-01
A.5.29 Information security during disruption yes Determined as necessary by the risk treatment. {{LINK:R04}} VA-02
A.5.30 ICT readiness for business continuity yes Determined as necessary by the risk treatment. {{LINK:R04}} VA-02
A.5.31 Legal, statutory, regulatory and contractual requirements yes Determined as necessary by the risk treatment. {{LINK:R14}} VA-18
A.5.32 Intellectual property rights yes Determined as necessary by the risk treatment. {{LINK:R14}} VA-18
A.5.33 Protection of records yes Determined as necessary by the risk treatment. {{LINK:R14}} VA-18
A.5.34 Privacy and protection of PII {{#if FLAG_PERSONAL_DATA}}yes{{/if}}{{#unless FLAG_PERSONAL_DATA}}no{{/unless}} {{#if FLAG_PERSONAL_DATA}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_PERSONAL_DATA}}Not applicable - enter justification.{{/unless}} {{LINK:R14}} VA-18
A.5.35 Independent review of information security yes Determined as necessary by the risk treatment. {{LINK:R03}} VA-15
A.5.36 Compliance with policies, rules and standards for information security yes Determined as necessary by the risk treatment. {{LINK:R03}} VA-15
A.5.37 Documented operating procedures yes Determined as necessary by the risk treatment. {{LINK:R10}} -

A.6 People controls (8 controls)

Control Title Applicable Justification Origin Status Policy Procedure Evidence
A.6.1 Screening yes Determined as necessary by the risk treatment. {{LINK:R05}} VA-14
A.6.2 Terms and conditions of employment yes Determined as necessary by the risk treatment. {{LINK:R05}} VA-14
A.6.3 Information security awareness, education and training yes Determined as necessary by the risk treatment. {{LINK:R05}} VA-12
A.6.4 Disciplinary process yes Determined as necessary by the risk treatment. {{LINK:R05}} -
A.6.5 Responsibilities after termination or change of employment yes Determined as necessary by the risk treatment. {{LINK:R05}} VA-14
A.6.6 Confidentiality or non-disclosure agreements yes Determined as necessary by the risk treatment. {{LINK:R05}} VA-14
A.6.7 Remote working {{#if FLAG_MOBILE_WORK}}yes{{/if}}{{#unless FLAG_MOBILE_WORK}}no{{/unless}} {{#if FLAG_MOBILE_WORK}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_MOBILE_WORK}}Not applicable - enter justification.{{/unless}} {{LINK:R06}} -
A.6.8 Information security event reporting yes Determined as necessary by the risk treatment. {{LINK:R04}} VA-01

A.7 Physical controls (14 controls)

Control Title Applicable Justification Origin Status Policy Procedure Evidence
A.7.1 Physical security perimeters yes Determined as necessary by the risk treatment. {{LINK:R07}} VA-17
A.7.2 Physical entry yes Determined as necessary by the risk treatment. {{LINK:R07}} VA-17
A.7.3 Securing offices, rooms and facilities yes Determined as necessary by the risk treatment. {{LINK:R07}} VA-17
A.7.4 Physical security monitoring yes Determined as necessary by the risk treatment. {{LINK:R07}} VA-17
A.7.5 Protecting against physical and environmental threats yes Determined as necessary by the risk treatment. {{LINK:R07}} VA-17
A.7.6 Working in secure areas yes Determined as necessary by the risk treatment. {{LINK:R07}} VA-17
A.7.7 Clear desk and clear screen yes Determined as necessary by the risk treatment. {{LINK:R07}} VA-17
A.7.8 Equipment siting and protection yes Determined as necessary by the risk treatment. {{LINK:R07}} VA-17
A.7.9 Security of assets off-premises {{#if FLAG_MOBILE_DEVICES}}yes{{/if}}{{#unless FLAG_MOBILE_DEVICES}}no{{/unless}} {{#if FLAG_MOBILE_DEVICES}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_MOBILE_DEVICES}}Not applicable - enter justification.{{/unless}} {{LINK:R06}} -
A.7.10 Storage media yes Determined as necessary by the risk treatment. {{LINK:R06}} VA-08
A.7.11 Supporting utilities yes Determined as necessary by the risk treatment. {{LINK:R07}} VA-17
A.7.12 Cabling security yes Determined as necessary by the risk treatment. {{LINK:R07}} VA-17
A.7.13 Equipment maintenance yes Determined as necessary by the risk treatment. {{LINK:R07}} VA-04
A.7.14 Secure disposal or re-use of equipment yes Determined as necessary by the risk treatment. {{LINK:R11}} VA-08

A.8 Technological controls (34 controls)

Control Title Applicable Justification Origin Status Policy Procedure Evidence
A.8.1 User endpoint devices yes Determined as necessary by the risk treatment. {{LINK:R06}} -
A.8.2 Privileged access rights yes Determined as necessary by the risk treatment. {{LINK:R08}} VA-03
A.8.3 Information access restriction yes Determined as necessary by the risk treatment. {{LINK:R08}} VA-03
A.8.4 Access to source code {{#if FLAG_DEV_INHOUSE}}yes{{/if}}{{#unless FLAG_DEV_INHOUSE}}no{{/unless}} {{#if FLAG_DEV_INHOUSE}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_DEV_INHOUSE}}Not applicable - enter justification.{{/unless}} {{LINK:R11}} VA-16
A.8.5 Secure authentication yes Determined as necessary by the risk treatment. {{LINK:R08}} VA-03
A.8.6 Capacity management yes Determined as necessary by the risk treatment. {{LINK:R10}} -
A.8.7 Protection against malware yes Determined as necessary by the risk treatment. {{LINK:R10}} -
A.8.8 Management of technical vulnerabilities yes Determined as necessary by the risk treatment. {{LINK:R10}} VA-06
A.8.9 Configuration management yes Determined as necessary by the risk treatment. {{LINK:R10}} VA-04
A.8.10 Information deletion yes Determined as necessary by the risk treatment. {{LINK:R11}} VA-08
A.8.11 Data masking {{#if FLAG_PERSONAL_DATA}}yes{{/if}}{{#unless FLAG_PERSONAL_DATA}}no{{/unless}} {{#if FLAG_PERSONAL_DATA}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_PERSONAL_DATA}}Not applicable - enter justification.{{/unless}} {{LINK:R02}} -
A.8.12 Data leakage prevention yes Determined as necessary by the risk treatment. {{LINK:R10}} -
A.8.13 Information backup yes Determined as necessary by the risk treatment. {{LINK:R10}} VA-05
A.8.14 Redundancy of information processing facilities yes Determined as necessary by the risk treatment. {{LINK:R04}} VA-02
A.8.15 Logging yes Determined as necessary by the risk treatment. {{LINK:R10}} VA-13
A.8.16 Monitoring activities yes Determined as necessary by the risk treatment. {{LINK:R10}} VA-13
A.8.17 Clock synchronisation yes Determined as necessary by the risk treatment. {{LINK:R10}} VA-13
A.8.18 Use of privileged utility programs yes Determined as necessary by the risk treatment. {{LINK:R08}} VA-03
A.8.19 Installation of software on operational systems yes Determined as necessary by the risk treatment. {{LINK:R02}} VA-04
A.8.20 Networks security yes Determined as necessary by the risk treatment. {{LINK:R10}} -
A.8.21 Security of network services yes Determined as necessary by the risk treatment. {{LINK:R11}} -
A.8.22 Segregation of networks yes Determined as necessary by the risk treatment. {{LINK:R10}} -
A.8.23 Web filtering yes Determined as necessary by the risk treatment. {{LINK:R10}} -
A.8.24 Use of cryptography yes Determined as necessary by the risk treatment. {{LINK:R09}} VA-07
A.8.25 Secure development life cycle {{#if FLAG_DEV_INHOUSE}}yes{{/if}}{{#unless FLAG_DEV_INHOUSE}}no{{/unless}} {{#if FLAG_DEV_INHOUSE}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_DEV_INHOUSE}}Not applicable - enter justification.{{/unless}} {{LINK:R11}} VA-16
A.8.26 Application security requirements {{#if FLAG_DEV_INHOUSE}}yes{{/if}}{{#unless FLAG_DEV_INHOUSE}}no{{/unless}} {{#if FLAG_DEV_INHOUSE}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_DEV_INHOUSE}}Not applicable - enter justification.{{/unless}} {{LINK:R11}} VA-16
A.8.27 Secure system architecture and engineering principles {{#if FLAG_DEV_INHOUSE}}yes{{/if}}{{#unless FLAG_DEV_INHOUSE}}no{{/unless}} {{#if FLAG_DEV_INHOUSE}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_DEV_INHOUSE}}Not applicable - enter justification.{{/unless}} {{LINK:R11}} VA-16
A.8.28 Secure coding {{#if FLAG_DEV_INHOUSE}}yes{{/if}}{{#unless FLAG_DEV_INHOUSE}}no{{/unless}} {{#if FLAG_DEV_INHOUSE}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_DEV_INHOUSE}}Not applicable - enter justification.{{/unless}} {{LINK:R11}} VA-16
A.8.29 Security testing in development and acceptance {{#if FLAG_DEV_INHOUSE}}yes{{/if}}{{#unless FLAG_DEV_INHOUSE}}no{{/unless}} {{#if FLAG_DEV_INHOUSE}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_DEV_INHOUSE}}Not applicable - enter justification.{{/unless}} {{LINK:R11}} VA-16
A.8.30 Outsourced development {{#if FLAG_DEV_INHOUSE}}yes{{/if}}{{#unless FLAG_DEV_INHOUSE}}no{{/unless}} {{#if FLAG_DEV_INHOUSE}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_DEV_INHOUSE}}Not applicable - enter justification.{{/unless}} {{LINK:R11}} VA-16
A.8.31 Separation of development, test and production environments {{#if FLAG_DEV_INHOUSE}}yes{{/if}}{{#unless FLAG_DEV_INHOUSE}}no{{/unless}} {{#if FLAG_DEV_INHOUSE}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_DEV_INHOUSE}}Not applicable - enter justification.{{/unless}} {{LINK:R10}} VA-16
A.8.32 Change management yes Determined as necessary by the risk treatment. {{LINK:R10}} VA-04
A.8.33 Test information {{#if FLAG_DEV_INHOUSE}}yes{{/if}}{{#unless FLAG_DEV_INHOUSE}}no{{/unless}} {{#if FLAG_DEV_INHOUSE}}Determined as necessary by the risk treatment.{{/if}}{{#unless FLAG_DEV_INHOUSE}}Not applicable - enter justification.{{/unless}} {{LINK:R11}} VA-16
A.8.34 Protection of information systems during audit testing yes Determined as necessary by the risk treatment. {{LINK:R10}} VA-15

Management system requirements (clauses 4-10)

The requirements of clauses 4 to 10 are not subject to the Statement of Applicability; they apply directly. Their allocation to the policies is held in mapping-iso.json.