Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
5352 lines
168 KiB
JSON
5352 lines
168 KiB
JSON
{
|
||
"meta": {
|
||
"paket": "ISMS-Vorlagenpaket v2",
|
||
"standard": "VDA ISA 2027 (Information Security)",
|
||
"hinweis": "Anforderungen 1:1 aus ISA; Umsetzung gebuendelt je Control. is_isa=false = kundenspezifische Ergaenzung (z.B. KI).",
|
||
"isa_quelldubletten": [
|
||
{
|
||
"control": "1.6.3",
|
||
"ebene": "high",
|
||
"doppelte_quellzeilen": 3,
|
||
"abgedeckt_durch": [
|
||
"1.6.3-H1",
|
||
"1.6.3-H2",
|
||
"1.6.3-H5"
|
||
],
|
||
"hinweis": "ISA wiederholt Krisenszenario-/Ressourcen-/Test-Zeilen mit/ohne Zusatz \"The following aspects are considered\"."
|
||
},
|
||
{
|
||
"control": "5.2.9",
|
||
"ebene": "high",
|
||
"doppelte_quellzeilen": 1,
|
||
"abgedeckt_durch": [
|
||
"5.2.9-H1"
|
||
],
|
||
"hinweis": "ISA-Zeile \"Backup and recovery concepts exist\" ist redundant zum Must-Konzept und zu H1."
|
||
}
|
||
],
|
||
"coverage": "316 eindeutige ISA-Zeilen; 4 Quelldubletten konsolidiert -> 312 eindeutige Anforderungen (100% inhaltliche Abdeckung). Plus 4 kundenspezifische KI-Anforderungen.",
|
||
"version": "2.1"
|
||
},
|
||
"anforderungen": [
|
||
{
|
||
"id": "1.1.1-M1",
|
||
"policy": "L00",
|
||
"control": "1.1.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.1.1-M1",
|
||
"impl_anchor": "REQ 1.1.1-M1",
|
||
"condition": null,
|
||
"requirement": "The information security requirements are defined, documented and aligned with the objectives of the organisation.",
|
||
"link": "{{LINK:L00#1.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.1.1-M2",
|
||
"policy": "L00",
|
||
"control": "1.1.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.1.1-M2",
|
||
"impl_anchor": "REQ 1.1.1-M2",
|
||
"condition": null,
|
||
"requirement": "A policy exists and is approved by the organisation's management.",
|
||
"link": "{{LINK:L00#1.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.1.1-M3",
|
||
"policy": "L00",
|
||
"control": "1.1.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.1.1-M3",
|
||
"impl_anchor": "REQ 1.1.1-M3",
|
||
"condition": null,
|
||
"requirement": "The policy states the objectives and the importance of information security within the organisation.",
|
||
"link": "{{LINK:L00#1.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.1.1-M4",
|
||
"policy": "L00",
|
||
"control": "1.1.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.1.1-M4",
|
||
"impl_anchor": "REQ 1.1.1-M4",
|
||
"condition": null,
|
||
"requirement": "The policies are made available to employees in a suitable form (e.g. intranet).",
|
||
"link": "{{LINK:L00#1.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.1.1-M5",
|
||
"policy": "L00",
|
||
"control": "1.1.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.1.1-M5",
|
||
"impl_anchor": "REQ 1.1.1-M5",
|
||
"condition": null,
|
||
"requirement": "Employees and external business partners are informed about changes relevant to them.",
|
||
"link": "{{LINK:L00#1.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.1.1-S1",
|
||
"policy": "L00",
|
||
"control": "1.1.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.1.1-S1",
|
||
"impl_anchor": "REQ 1.1.1-S1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The information security requirements are based on the organisation's strategy; laws and contracts are taken into account in the policy.",
|
||
"link": "{{LINK:L00#1.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.1.1-S2",
|
||
"policy": "L00",
|
||
"control": "1.1.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.1.1-S2",
|
||
"impl_anchor": "REQ 1.1.1-S2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The policy states the consequences of non-compliance.",
|
||
"link": "{{LINK:L00#1.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.1.1-S3",
|
||
"policy": "L00",
|
||
"control": "1.1.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.1.1-S3",
|
||
"impl_anchor": "REQ 1.1.1-S3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Further relevant security policies are established.",
|
||
"link": "{{LINK:L00#1.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.1.1-S4",
|
||
"policy": "L00",
|
||
"control": "1.1.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.1.1-S4",
|
||
"impl_anchor": "REQ 1.1.1-S4",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Regular review and, where necessary, revision of the policies are established.",
|
||
"link": "{{LINK:L00#1.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.2.1-M1",
|
||
"policy": "R01",
|
||
"control": "1.2.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.2.1-M1",
|
||
"impl_anchor": "IMPL 1.2.1",
|
||
"condition": null,
|
||
"requirement": "The scope of the ISMS (the organisation governed by the ISMS) is defined.",
|
||
"link": "{{LINK:R01#1.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.2.1-M2",
|
||
"policy": "R01",
|
||
"control": "1.2.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.2.1-M2",
|
||
"impl_anchor": "IMPL 1.2.1",
|
||
"condition": null,
|
||
"requirement": "The organisation's requirements for the ISMS are determined.",
|
||
"link": "{{LINK:R01#1.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.2.1-M3",
|
||
"policy": "R01",
|
||
"control": "1.2.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.2.1-M3",
|
||
"impl_anchor": "IMPL 1.2.1",
|
||
"condition": null,
|
||
"requirement": "The organisation's management has commissioned and approved the ISMS.",
|
||
"link": "{{LINK:R01#1.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.2.1-M4",
|
||
"policy": "R01",
|
||
"control": "1.2.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.2.1-M4",
|
||
"impl_anchor": "IMPL 1.2.1",
|
||
"condition": null,
|
||
"requirement": "The ISMS provides management with suitable means for monitoring and steering (e.g. management review).",
|
||
"link": "{{LINK:R01#1.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.2.1-M5",
|
||
"policy": "R01",
|
||
"control": "1.2.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.2.1-M5",
|
||
"impl_anchor": "IMPL 1.2.1",
|
||
"condition": null,
|
||
"requirement": "The applicable controls are determined (e.g. ISO 27001 statement of applicability or a completed ISA catalogue).",
|
||
"link": "{{LINK:R01#1.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.2.1-M6",
|
||
"policy": "R01",
|
||
"control": "1.2.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.2.1-M6",
|
||
"impl_anchor": "IMPL 1.2.1",
|
||
"condition": null,
|
||
"requirement": "The effectiveness of the ISMS is reviewed regularly by management.",
|
||
"link": "{{LINK:R01#1.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.2.2-M1",
|
||
"policy": "R01",
|
||
"control": "1.2.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.2.2-M1",
|
||
"impl_anchor": "IMPL 1.2.2",
|
||
"condition": null,
|
||
"requirement": "Responsibilities for information security are defined, documented and assigned.",
|
||
"link": "{{LINK:R01#1.2.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.2.2-M2",
|
||
"policy": "R01",
|
||
"control": "1.2.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.2.2-M2",
|
||
"impl_anchor": "IMPL 1.2.2",
|
||
"condition": null,
|
||
"requirement": "The responsible employees are defined, qualified and enabled for their task.",
|
||
"link": "{{LINK:R01#1.2.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.2.2-M3",
|
||
"policy": "R01",
|
||
"control": "1.2.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.2.2-M3",
|
||
"impl_anchor": "IMPL 1.2.2",
|
||
"condition": null,
|
||
"requirement": "The necessary resources are available.",
|
||
"link": "{{LINK:R01#1.2.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.2.2-M4",
|
||
"policy": "R01",
|
||
"control": "1.2.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.2.2-M4",
|
||
"impl_anchor": "IMPL 1.2.2",
|
||
"condition": null,
|
||
"requirement": "The points of contact are known within the organisation and to relevant business partners.",
|
||
"link": "{{LINK:R01#1.2.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.2.2-S1",
|
||
"policy": "R01",
|
||
"control": "1.2.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.2.2-S1",
|
||
"impl_anchor": "IMPL 1.2.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "An appropriate information security structure within the organisation is defined and documented.",
|
||
"link": "{{LINK:R01#1.2.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.2.2-S2",
|
||
"policy": "R01",
|
||
"control": "1.2.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.2.2-S2",
|
||
"impl_anchor": "IMPL 1.2.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Security-relevant roles that are not part of the ISMS but are relevant to information security are taken into account.",
|
||
"link": "{{LINK:R01#1.2.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.2.2-H1",
|
||
"policy": "R01",
|
||
"control": "1.2.2",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.2.2-H1",
|
||
"impl_anchor": "IMPL 1.2.2-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "An appropriate organisational separation of responsibilities is established to avoid conflicts of interest (segregation of duties). (C, I, A)",
|
||
"link": "{{LINK:R01#1.2.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.2.3-M1",
|
||
"policy": "R01",
|
||
"control": "1.2.3",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.2.3-M1",
|
||
"impl_anchor": "IMPL 1.2.3",
|
||
"condition": null,
|
||
"requirement": "Projects are classified taking information security requirements into account.",
|
||
"link": "{{LINK:R01#1.2.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-19"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.2.3-S1",
|
||
"policy": "R01",
|
||
"control": "1.2.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.2.3-S1",
|
||
"impl_anchor": "IMPL 1.2.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Procedures and criteria for classifying projects are documented.",
|
||
"link": "{{LINK:R01#1.2.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-19"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.2.3-S2",
|
||
"policy": "R01",
|
||
"control": "1.2.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.2.3-S2",
|
||
"impl_anchor": "IMPL 1.2.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "A risk assessment following the defined procedure is carried out in an early project phase and repeated upon project changes.",
|
||
"link": "{{LINK:R01#1.2.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-19"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.2.3-S3",
|
||
"policy": "R01",
|
||
"control": "1.2.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.2.3-S3",
|
||
"impl_anchor": "IMPL 1.2.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Measures are derived for identified information security risks and taken into account in the project.",
|
||
"link": "{{LINK:R01#1.2.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-19"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.2.3-H1",
|
||
"policy": "R01",
|
||
"control": "1.2.3",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.2.3-H1",
|
||
"impl_anchor": "IMPL 1.2.3-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "The derived measures are reviewed regularly during the project and reassessed when the assessment criteria change. (C, I, A)",
|
||
"link": "{{LINK:R01#1.2.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-19"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.3.1-M1",
|
||
"policy": "R02",
|
||
"control": "1.3.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.3.1-M1",
|
||
"impl_anchor": "IMPL 1.3.1",
|
||
"condition": null,
|
||
"requirement": "The organisation's information assets and other security-relevant assets are identified and recorded.",
|
||
"link": "{{LINK:R02#1.3.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-08"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.3.1-M2",
|
||
"policy": "R02",
|
||
"control": "1.3.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.3.1-M2",
|
||
"impl_anchor": "IMPL 1.3.1",
|
||
"condition": null,
|
||
"requirement": "The supporting assets that process the information assets are identified and recorded.",
|
||
"link": "{{LINK:R02#1.3.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-08"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.3.1-S1",
|
||
"policy": "R02",
|
||
"control": "1.3.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.3.1-S1",
|
||
"impl_anchor": "IMPL 1.3.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "A catalogue of the relevant information assets exists; the relevant aspects are taken into account.",
|
||
"link": "{{LINK:R02#1.3.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-08"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.3.2-M1",
|
||
"policy": "R02",
|
||
"control": "1.3.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.3.2-M1",
|
||
"impl_anchor": "IMPL 1.3.2",
|
||
"condition": null,
|
||
"requirement": "A consistent scheme for classifying information assets with regard to the protection goal of confidentiality is in place.",
|
||
"link": "{{LINK:R02#1.3.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-08"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.3.2-M2",
|
||
"policy": "R02",
|
||
"control": "1.3.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.3.2-M2",
|
||
"impl_anchor": "IMPL 1.3.2",
|
||
"condition": null,
|
||
"requirement": "The identified information assets are assessed according to the defined criteria and assigned to the classification scheme.",
|
||
"link": "{{LINK:R02#1.3.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-08"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.3.2-M3",
|
||
"policy": "R02",
|
||
"control": "1.3.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.3.2-M3",
|
||
"impl_anchor": "IMPL 1.3.2",
|
||
"condition": null,
|
||
"requirement": "Requirements for handling supporting assets (e.g. labelling, use, transport, storage, return, deletion/destruction) depending on the classification are in place and implemented.",
|
||
"link": "{{LINK:R02#1.3.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.3.2-S1",
|
||
"policy": "R02",
|
||
"control": "1.3.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.3.2-S1",
|
||
"impl_anchor": "IMPL 1.3.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The protection goals of integrity and availability are taken into account.",
|
||
"link": "{{LINK:R02#1.3.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-08"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.3.3-M1",
|
||
"policy": "R02",
|
||
"control": "1.3.3",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.3.3-M1",
|
||
"impl_anchor": "IMPL 1.3.3",
|
||
"condition": null,
|
||
"requirement": "External IT services are not used without an explicit assessment and implementation of the information security requirements; the relevant aspects are taken into account.",
|
||
"link": "{{LINK:R02#1.3.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.3.3-M2",
|
||
"policy": "R02",
|
||
"control": "1.3.3",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.3.3-M2",
|
||
"impl_anchor": "IMPL 1.3.3",
|
||
"condition": null,
|
||
"requirement": "The external IT services are aligned with the protection need of the information assets processed.",
|
||
"link": "{{LINK:R02#1.3.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.3.3-S1",
|
||
"policy": "R02",
|
||
"control": "1.3.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.3.3-S1",
|
||
"impl_anchor": "IMPL 1.3.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Requirements for procurement, commissioning and approval in connection with the use of external IT services are determined and met.",
|
||
"link": "{{LINK:R02#1.3.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.3.3-S2",
|
||
"policy": "R02",
|
||
"control": "1.3.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.3.3-S2",
|
||
"impl_anchor": "IMPL 1.3.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "A procedure for approval taking the protection need into account is established.",
|
||
"link": "{{LINK:R02#1.3.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.3.3-S3",
|
||
"policy": "R02",
|
||
"control": "1.3.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.3.3-S3",
|
||
"impl_anchor": "IMPL 1.3.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "External IT services and their approval are documented.",
|
||
"link": "{{LINK:R02#1.3.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.3.3-S4",
|
||
"policy": "R02",
|
||
"control": "1.3.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.3.3-S4",
|
||
"impl_anchor": "IMPL 1.3.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "It is regularly verified that only approved external IT services are used.",
|
||
"link": "{{LINK:R02#1.3.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.3.4-M1",
|
||
"policy": "R02",
|
||
"control": "1.3.4",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.3.4-M1",
|
||
"impl_anchor": "IMPL 1.3.4",
|
||
"condition": null,
|
||
"requirement": "Software is approved before installation or use; the relevant aspects are taken into account.",
|
||
"link": "{{LINK:R02#1.3.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.3.4-M2",
|
||
"policy": "R02",
|
||
"control": "1.3.4",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.3.4-M2",
|
||
"impl_anchor": "IMPL 1.3.4",
|
||
"condition": null,
|
||
"requirement": "The software approval also applies to special software such as maintenance tools.",
|
||
"link": "{{LINK:R02#1.3.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.3.4-S1",
|
||
"policy": "R02",
|
||
"control": "1.3.4",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.3.4-S1",
|
||
"impl_anchor": "IMPL 1.3.4",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The types of software to be managed (firmware, operating systems, applications, libraries, device drivers) are determined.",
|
||
"link": "{{LINK:R02#1.3.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.3.4-S2",
|
||
"policy": "R02",
|
||
"control": "1.3.4",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.3.4-S2",
|
||
"impl_anchor": "IMPL 1.3.4",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Repositories of the managed software exist.",
|
||
"link": "{{LINK:R02#1.3.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.3.4-S3",
|
||
"policy": "R02",
|
||
"control": "1.3.4",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.3.4-S3",
|
||
"impl_anchor": "IMPL 1.3.4",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The software repositories are protected against unauthorised manipulation.",
|
||
"link": "{{LINK:R02#1.3.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.3.4-S4",
|
||
"policy": "R02",
|
||
"control": "1.3.4",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.3.4-S4",
|
||
"impl_anchor": "IMPL 1.3.4",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The approval of software is reviewed regularly.",
|
||
"link": "{{LINK:R02#1.3.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.3.4-S5",
|
||
"policy": "R02",
|
||
"control": "1.3.4",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.3.4-S5",
|
||
"impl_anchor": "IMPL 1.3.4",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Software versions and patch levels are known.",
|
||
"link": "{{LINK:R02#1.3.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.3.4-V1",
|
||
"policy": "R02",
|
||
"control": "1.3.4",
|
||
"level": "vhigh",
|
||
"type": "SEHR HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.3.4-V1",
|
||
"impl_anchor": "IMPL 1.3.4-elev",
|
||
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
||
"requirement": "Additional requirements for software use (e.g. the need to control/monitor use) are determined where present. (C, I, A)",
|
||
"link": "{{LINK:R02#1.3.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.4.1-M1",
|
||
"policy": "R03",
|
||
"control": "1.4.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.4.1-M1",
|
||
"impl_anchor": "IMPL 1.4.1",
|
||
"condition": null,
|
||
"requirement": "Risk assessments are carried out regularly and on an ad-hoc basis.",
|
||
"link": "{{LINK:R03#1.4.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-09"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.4.1-M2",
|
||
"policy": "R03",
|
||
"control": "1.4.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.4.1-M2",
|
||
"impl_anchor": "IMPL 1.4.1",
|
||
"condition": null,
|
||
"requirement": "Information security risks are assessed appropriately (e.g. likelihood of occurrence and potential extent of damage).",
|
||
"link": "{{LINK:R03#1.4.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-09"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.4.1-M3",
|
||
"policy": "R03",
|
||
"control": "1.4.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.4.1-M3",
|
||
"impl_anchor": "IMPL 1.4.1",
|
||
"condition": null,
|
||
"requirement": "Information security risks are documented.",
|
||
"link": "{{LINK:R03#1.4.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-09"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.4.1-M4",
|
||
"policy": "R03",
|
||
"control": "1.4.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.4.1-M4",
|
||
"impl_anchor": "IMPL 1.4.1",
|
||
"condition": null,
|
||
"requirement": "A responsible person (risk owner) is assigned to each information security risk and is responsible for its assessment and treatment.",
|
||
"link": "{{LINK:R03#1.4.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.4.1-S1",
|
||
"policy": "R03",
|
||
"control": "1.4.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.4.1-S1",
|
||
"impl_anchor": "IMPL 1.4.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "A procedure for the identification, assessment and treatment of security risks is in place.",
|
||
"link": "{{LINK:R03#1.4.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-09"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.4.1-S2",
|
||
"policy": "R03",
|
||
"control": "1.4.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.4.1-S2",
|
||
"impl_anchor": "IMPL 1.4.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Criteria for the assessment and treatment of security risks exist.",
|
||
"link": "{{LINK:R03#1.4.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.4.1-S3",
|
||
"policy": "R03",
|
||
"control": "1.4.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.4.1-S3",
|
||
"impl_anchor": "IMPL 1.4.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Risk treatment measures and their responsible persons are defined and documented; a measures plan or implementation overview is tracked.",
|
||
"link": "{{LINK:R03#1.4.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.4.1-S4",
|
||
"policy": "R03",
|
||
"control": "1.4.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.4.1-S4",
|
||
"impl_anchor": "IMPL 1.4.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Upon changes in the environment (e.g. organisational structure, location, regulations), a reassessment is carried out promptly.",
|
||
"link": "{{LINK:R03#1.4.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.5.1-M1",
|
||
"policy": "R03",
|
||
"control": "1.5.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.5.1-M1",
|
||
"impl_anchor": "IMPL 1.5.1",
|
||
"condition": null,
|
||
"requirement": "Compliance with the policies is reviewed organisation-wide.",
|
||
"link": "{{LINK:R03#1.5.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-15"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.5.1-M2",
|
||
"policy": "R03",
|
||
"control": "1.5.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.5.1-M2",
|
||
"impl_anchor": "IMPL 1.5.1",
|
||
"condition": null,
|
||
"requirement": "Information security policies and procedures are reviewed regularly.",
|
||
"link": "{{LINK:R03#1.5.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-15"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.5.1-M3",
|
||
"policy": "R03",
|
||
"control": "1.5.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.5.1-M3",
|
||
"impl_anchor": "IMPL 1.5.1",
|
||
"condition": null,
|
||
"requirement": "Measures to correct possible deviations are initiated and tracked.",
|
||
"link": "{{LINK:R03#1.5.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-15"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.5.1-M4",
|
||
"policy": "R03",
|
||
"control": "1.5.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.5.1-M4",
|
||
"impl_anchor": "IMPL 1.5.1",
|
||
"condition": null,
|
||
"requirement": "Compliance with information security requirements (e.g. technical specifications) is reviewed regularly.",
|
||
"link": "{{LINK:R03#1.5.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-15"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.5.1-M5",
|
||
"policy": "R03",
|
||
"control": "1.5.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.5.1-M5",
|
||
"impl_anchor": "IMPL 1.5.1",
|
||
"condition": null,
|
||
"requirement": "The results of the reviews carried out are recorded and retained.",
|
||
"link": "{{LINK:R03#1.5.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-15"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.5.1-S1",
|
||
"policy": "R03",
|
||
"control": "1.5.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.5.1-S1",
|
||
"impl_anchor": "IMPL 1.5.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "A plan for the content and framework conditions (schedule, scope, controls) of the reviews to be carried out is in place.",
|
||
"link": "{{LINK:R03#1.5.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-15"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.5.2-M1",
|
||
"policy": "R03",
|
||
"control": "1.5.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.5.2-M1",
|
||
"impl_anchor": "IMPL 1.5.2",
|
||
"condition": null,
|
||
"requirement": "Information security reviews are carried out by an independent and competent body regularly and after fundamental changes.",
|
||
"link": "{{LINK:R03#1.5.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-15"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.5.2-M2",
|
||
"policy": "R03",
|
||
"control": "1.5.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.5.2-M2",
|
||
"impl_anchor": "IMPL 1.5.2",
|
||
"condition": null,
|
||
"requirement": "Measures to correct possible deviations are initiated and tracked.",
|
||
"link": "{{LINK:R03#1.5.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-15"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.5.2-S1",
|
||
"policy": "R03",
|
||
"control": "1.5.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.5.2-S1",
|
||
"impl_anchor": "IMPL 1.5.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The results of the reviews carried out are documented and reported to the organisation's management.",
|
||
"link": "{{LINK:R03#1.5.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-15"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.6.1-M1",
|
||
"policy": "R04",
|
||
"control": "1.6.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.1-M1",
|
||
"impl_anchor": "IMPL 1.6.1",
|
||
"condition": null,
|
||
"requirement": "A definition of a reportable security event or observation exists and is known to employees and relevant stakeholders.",
|
||
"link": "{{LINK:R04#1.6.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-01"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.6.1-M2",
|
||
"policy": "R04",
|
||
"control": "1.6.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.1-M2",
|
||
"impl_anchor": "IMPL 1.6.1",
|
||
"condition": null,
|
||
"requirement": "Appropriate, risk-oriented mechanisms for reporting security events are defined, implemented and known to all relevant reporters.",
|
||
"link": "{{LINK:R04#1.6.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-01"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.6.1-M3",
|
||
"policy": "R04",
|
||
"control": "1.6.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.1-M3",
|
||
"impl_anchor": "IMPL 1.6.1",
|
||
"condition": null,
|
||
"requirement": "Appropriate channels for communicating with reporters exist.",
|
||
"link": "{{LINK:R04#1.6.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.1-S1",
|
||
"policy": "R04",
|
||
"control": "1.6.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.1-S1",
|
||
"impl_anchor": "IMPL 1.6.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "A common point of contact for event reporting exists.",
|
||
"link": "{{LINK:R04#1.6.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.1-S2",
|
||
"policy": "R04",
|
||
"control": "1.6.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.1-S2",
|
||
"impl_anchor": "IMPL 1.6.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Different reporting channels depending on the perceived severity (real-time for serious events/emergencies as well as asynchronous mechanisms such as tickets or email) are available.",
|
||
"link": "{{LINK:R04#1.6.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.1-S3",
|
||
"policy": "R04",
|
||
"control": "1.6.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.1-S3",
|
||
"impl_anchor": "IMPL 1.6.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Employees are obliged and trained to report relevant events.",
|
||
"link": "{{LINK:R04#1.6.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.1-S4",
|
||
"policy": "R04",
|
||
"control": "1.6.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.1-S4",
|
||
"impl_anchor": "IMPL 1.6.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Security events can also be reported by external parties; the relevant aspects are taken into account.",
|
||
"link": "{{LINK:R04#1.6.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.1-S5",
|
||
"policy": "R04",
|
||
"control": "1.6.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.1-S5",
|
||
"impl_anchor": "IMPL 1.6.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The mechanism and the information on how incidents are reported are accessible to all relevant reporters.",
|
||
"link": "{{LINK:R04#1.6.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.1-S6",
|
||
"policy": "R04",
|
||
"control": "1.6.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.1-S6",
|
||
"impl_anchor": "IMPL 1.6.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "A feedback procedure to the reporters is established.",
|
||
"link": "{{LINK:R04#1.6.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.1-V1",
|
||
"policy": "R04",
|
||
"control": "1.6.1",
|
||
"level": "vhigh",
|
||
"type": "SEHR HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.1-V1",
|
||
"impl_anchor": "IMPL 1.6.1-elev",
|
||
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
||
"requirement": "Tests and exercises of event and observation reporting are carried out regularly. (C, I, A)",
|
||
"link": "{{LINK:R04#1.6.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.2-M1",
|
||
"policy": "R04",
|
||
"control": "1.6.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.2-M1",
|
||
"impl_anchor": "IMPL 1.6.2",
|
||
"condition": null,
|
||
"requirement": "Reported events are processed without undue delay.",
|
||
"link": "{{LINK:R04#1.6.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-01"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.6.2-M2",
|
||
"policy": "R04",
|
||
"control": "1.6.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.2-M2",
|
||
"impl_anchor": "IMPL 1.6.2",
|
||
"condition": null,
|
||
"requirement": "An appropriate response to reported security events is ensured.",
|
||
"link": "{{LINK:R04#1.6.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-01"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.6.2-M3",
|
||
"policy": "R04",
|
||
"control": "1.6.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.2-M3",
|
||
"impl_anchor": "IMPL 1.6.2",
|
||
"condition": null,
|
||
"requirement": "Lessons learned feed into continual improvement.",
|
||
"link": "{{LINK:R04#1.6.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.2-S1",
|
||
"policy": "R04",
|
||
"control": "1.6.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.2-S1",
|
||
"impl_anchor": "IMPL 1.6.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "During processing, reported events are categorised (e.g. personnel, physical, cyber), qualified (e.g. not security-relevant, observation, improvement suggestion, vulnerability, incident) and prioritised (e.g. low, medium, high, critical).",
|
||
"link": "{{LINK:R04#1.6.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-01"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.6.2-S2",
|
||
"policy": "R04",
|
||
"control": "1.6.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.2-S2",
|
||
"impl_anchor": "IMPL 1.6.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Responsibilities for handling events per category are defined and assigned.",
|
||
"link": "{{LINK:R04#1.6.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-01"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.6.2-S3",
|
||
"policy": "R04",
|
||
"control": "1.6.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.2-S3",
|
||
"impl_anchor": "IMPL 1.6.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "A strategy for reporting potentially criminally relevant aspects to the competent authorities, where necessary, exists. (C, I, A)",
|
||
"link": "{{LINK:R04#1.6.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.2-H1",
|
||
"policy": "R04",
|
||
"control": "1.6.2",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.2-H1",
|
||
"impl_anchor": "IMPL 1.6.2-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "Maximum response times per class, category and severity are defined. (C, I, A)",
|
||
"link": "{{LINK:R04#1.6.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.2-H2",
|
||
"policy": "R04",
|
||
"control": "1.6.2",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.2-H2",
|
||
"impl_anchor": "IMPL 1.6.2-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "Events not processed in line with their priority are escalated; the relevant aspects are taken into account. (C, I, A)",
|
||
"link": "{{LINK:R04#1.6.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.2-H3",
|
||
"policy": "R04",
|
||
"control": "1.6.2",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.2-H3",
|
||
"impl_anchor": "IMPL 1.6.2-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "Legal, regulatory and contractual reporting obligations and the associated contact information are known. (C, I, A)",
|
||
"link": "{{LINK:R04#1.6.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.2-H4",
|
||
"policy": "R04",
|
||
"control": "1.6.2",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.2-H4",
|
||
"impl_anchor": "IMPL 1.6.2-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "A communication strategy for security-relevant events exists; the relevant aspects are taken into account. (C, I, A)",
|
||
"link": "{{LINK:R04#1.6.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.2-H5",
|
||
"policy": "R04",
|
||
"control": "1.6.2",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.2-H5",
|
||
"impl_anchor": "IMPL 1.6.2-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "Procedures for responding to security incidents at suppliers are established; the relevant aspects are taken into account. (C, I, A)",
|
||
"link": "{{LINK:R04#1.6.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.2-V1",
|
||
"policy": "R04",
|
||
"control": "1.6.2",
|
||
"level": "vhigh",
|
||
"type": "SEHR HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.2-V1",
|
||
"impl_anchor": "IMPL 1.6.2-elev",
|
||
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
||
"requirement": "The handling of events of different categories and priorities is tested regularly; the relevant aspects are taken into account. (A)",
|
||
"link": "{{LINK:R04#1.6.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.3-M1",
|
||
"policy": "R04",
|
||
"control": "1.6.3",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.3-M1",
|
||
"impl_anchor": "IMPL 1.6.3",
|
||
"condition": null,
|
||
"requirement": "An appropriate plan for responding to and managing crisis situations exists and the necessary resources are available.",
|
||
"link": "{{LINK:R04#1.6.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-02"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.6.3-M2",
|
||
"policy": "R04",
|
||
"control": "1.6.3",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.3-M2",
|
||
"impl_anchor": "IMPL 1.6.3",
|
||
"condition": null,
|
||
"requirement": "Responsibilities and authorities for crisis management are defined, documented and assigned.",
|
||
"link": "{{LINK:R04#1.6.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.3-M3",
|
||
"policy": "R04",
|
||
"control": "1.6.3",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.3-M3",
|
||
"impl_anchor": "IMPL 1.6.3",
|
||
"condition": null,
|
||
"requirement": "The responsible employees are defined and qualified for their task.",
|
||
"link": "{{LINK:R04#1.6.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.3-S1",
|
||
"policy": "R04",
|
||
"control": "1.6.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.3-S1",
|
||
"impl_anchor": "IMPL 1.6.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Methods for detecting crisis situations are established; general indicators and specific foreseeable crises are identified.",
|
||
"link": "{{LINK:R04#1.6.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-02"
|
||
]
|
||
},
|
||
{
|
||
"id": "1.6.3-S2",
|
||
"policy": "R04",
|
||
"control": "1.6.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.3-S2",
|
||
"impl_anchor": "IMPL 1.6.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "A procedure for triggering and/or escalating crisis management is in place.",
|
||
"link": "{{LINK:R04#1.6.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.3-S3",
|
||
"policy": "R04",
|
||
"control": "1.6.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.3-S3",
|
||
"impl_anchor": "IMPL 1.6.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Strategic objectives and their priority in crisis situations are defined and known to relevant personnel.",
|
||
"link": "{{LINK:R04#1.6.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.3-S4",
|
||
"policy": "R04",
|
||
"control": "1.6.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.3-S4",
|
||
"impl_anchor": "IMPL 1.6.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "A crisis team is defined and approved.",
|
||
"link": "{{LINK:R04#1.6.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.3-S5",
|
||
"policy": "R04",
|
||
"control": "1.6.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.3-S5",
|
||
"impl_anchor": "IMPL 1.6.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Crisis policies and procedures are defined and approved.",
|
||
"link": "{{LINK:R04#1.6.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.3-S6",
|
||
"policy": "R04",
|
||
"control": "1.6.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.3-S6",
|
||
"impl_anchor": "IMPL 1.6.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The crisis planning is reviewed and updated regularly.",
|
||
"link": "{{LINK:R04#1.6.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.3-H1",
|
||
"policy": "R04",
|
||
"control": "1.6.3",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.3-H1",
|
||
"impl_anchor": "IMPL 1.6.3-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "Relevant different potential crisis scenarios are identified.",
|
||
"link": "{{LINK:R04#1.6.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.3-H2",
|
||
"policy": "R04",
|
||
"control": "1.6.3",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.3-H2",
|
||
"impl_anchor": "IMPL 1.6.3-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "The resources and information necessary for crisis management (e.g. communication infrastructure, availability of contact and risk information) are identified; appropriate measures to ensure availability or fallback planning are in place. (A)",
|
||
"link": "{{LINK:R04#1.6.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.3-H3",
|
||
"policy": "R04",
|
||
"control": "1.6.3",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.3-H3",
|
||
"impl_anchor": "IMPL 1.6.3-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "A communication strategy for crisis situations exists. (A)",
|
||
"link": "{{LINK:R04#1.6.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.3-H4",
|
||
"policy": "R04",
|
||
"control": "1.6.3",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.3-H4",
|
||
"impl_anchor": "IMPL 1.6.3-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "The efficiency, feasibility and appropriateness of the crisis planning are assessed regularly. (A)",
|
||
"link": "{{LINK:R04#1.6.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.3-H5",
|
||
"policy": "R04",
|
||
"control": "1.6.3",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.3-H5",
|
||
"impl_anchor": "IMPL 1.6.3-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "Sample-based tests of the crisis planning are carried out (e.g. simulation, tabletop exercises with key personnel). (A)",
|
||
"link": "{{LINK:R04#1.6.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "1.6.3-V1",
|
||
"policy": "R04",
|
||
"control": "1.6.3",
|
||
"level": "vhigh",
|
||
"type": "SEHR HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 1.6.3-V1",
|
||
"impl_anchor": "IMPL 1.6.3-elev",
|
||
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
||
"requirement": "Crisis exercises and simulations involving all relevant persons, including decision-makers, are carried out regularly. (A)",
|
||
"link": "{{LINK:R04#1.6.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "2.1.1-M1",
|
||
"policy": "R05",
|
||
"control": "2.1.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 2.1.1-M1",
|
||
"impl_anchor": "IMPL 2.1.1",
|
||
"condition": null,
|
||
"requirement": "Sensitive work areas and activities are determined.",
|
||
"link": "{{LINK:R05#2.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-14"
|
||
]
|
||
},
|
||
{
|
||
"id": "2.1.1-M2",
|
||
"policy": "R05",
|
||
"control": "2.1.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 2.1.1-M2",
|
||
"impl_anchor": "IMPL 2.1.1",
|
||
"condition": null,
|
||
"requirement": "The requirements for employees with regard to their job profiles are determined and met.",
|
||
"link": "{{LINK:R05#2.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-14"
|
||
]
|
||
},
|
||
{
|
||
"id": "2.1.1-M3",
|
||
"policy": "R05",
|
||
"control": "2.1.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 2.1.1-M3",
|
||
"impl_anchor": "IMPL 2.1.1",
|
||
"condition": null,
|
||
"requirement": "The identity of potential employees is verified (e.g. checking of identity documents).",
|
||
"link": "{{LINK:R05#2.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-14"
|
||
]
|
||
},
|
||
{
|
||
"id": "2.1.1-S1",
|
||
"policy": "R05",
|
||
"control": "2.1.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 2.1.1-S1",
|
||
"impl_anchor": "IMPL 2.1.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The personal suitability of potential employees is checked using simple methods (e.g. job interview).",
|
||
"link": "{{LINK:R05#2.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-14"
|
||
]
|
||
},
|
||
{
|
||
"id": "2.1.1-S2",
|
||
"policy": "R05",
|
||
"control": "2.1.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 2.1.1-S2",
|
||
"impl_anchor": "IMPL 2.1.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "An extended suitability check depending on the work area and the activity is carried out (e.g. assessment centre, checking of references, certificates and criminal record certificates).",
|
||
"link": "{{LINK:R05#2.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-14"
|
||
]
|
||
},
|
||
{
|
||
"id": "2.1.2-M1",
|
||
"policy": "R05",
|
||
"control": "2.1.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 2.1.2-M1",
|
||
"impl_anchor": "IMPL 2.1.2",
|
||
"condition": null,
|
||
"requirement": "A confidentiality obligation is in force.",
|
||
"link": "{{LINK:R05#2.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-14"
|
||
]
|
||
},
|
||
{
|
||
"id": "2.1.2-M2",
|
||
"policy": "R05",
|
||
"control": "2.1.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 2.1.2-M2",
|
||
"impl_anchor": "IMPL 2.1.2",
|
||
"condition": null,
|
||
"requirement": "An obligation to comply with the information security policies is in force.",
|
||
"link": "{{LINK:R05#2.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-14"
|
||
]
|
||
},
|
||
{
|
||
"id": "2.1.2-S1",
|
||
"policy": "R05",
|
||
"control": "2.1.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 2.1.2-S1",
|
||
"impl_anchor": "IMPL 2.1.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "A confidentiality obligation going beyond the employment contract is in force.",
|
||
"link": "{{LINK:R05#2.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-14"
|
||
]
|
||
},
|
||
{
|
||
"id": "2.1.2-S2",
|
||
"policy": "R05",
|
||
"control": "2.1.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 2.1.2-S2",
|
||
"impl_anchor": "IMPL 2.1.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Information security aspects are taken into account in the employees' employment contracts.",
|
||
"link": "{{LINK:R05#2.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-14"
|
||
]
|
||
},
|
||
{
|
||
"id": "2.1.2-S3",
|
||
"policy": "R05",
|
||
"control": "2.1.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 2.1.2-S3",
|
||
"impl_anchor": "IMPL 2.1.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "A procedure for dealing with violations of these obligations is described.",
|
||
"link": "{{LINK:R05#2.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-14"
|
||
]
|
||
},
|
||
{
|
||
"id": "2.1.3-M1",
|
||
"policy": "R05",
|
||
"control": "2.1.3",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 2.1.3-M1",
|
||
"impl_anchor": "IMPL 2.1.3",
|
||
"condition": null,
|
||
"requirement": "Employees are trained and made aware.",
|
||
"link": "{{LINK:R05#2.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-12"
|
||
]
|
||
},
|
||
{
|
||
"id": "2.1.3-S1",
|
||
"policy": "R05",
|
||
"control": "2.1.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 2.1.3-S1",
|
||
"impl_anchor": "IMPL 2.1.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "A concept for the awareness and training of employees is created.",
|
||
"link": "{{LINK:R05#2.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-12"
|
||
]
|
||
},
|
||
{
|
||
"id": "2.1.3-S2",
|
||
"policy": "R05",
|
||
"control": "2.1.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 2.1.3-S2",
|
||
"impl_anchor": "IMPL 2.1.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Target groups for training and awareness measures (e.g. managers, administrators, employees with access to customer networks, production personnel) are identified and taken into account in the concept.",
|
||
"link": "{{LINK:R05#2.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "2.1.3-S3",
|
||
"policy": "R05",
|
||
"control": "2.1.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 2.1.3-S3",
|
||
"impl_anchor": "IMPL 2.1.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The concept is approved by the responsible management.",
|
||
"link": "{{LINK:R05#2.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "2.1.3-S4",
|
||
"policy": "R05",
|
||
"control": "2.1.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 2.1.3-S4",
|
||
"impl_anchor": "IMPL 2.1.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Training and awareness measures are carried out regularly and on an ad-hoc basis.",
|
||
"link": "{{LINK:R05#2.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "2.1.3-S5",
|
||
"policy": "R05",
|
||
"control": "2.1.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 2.1.3-S5",
|
||
"impl_anchor": "IMPL 2.1.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Participation in training and awareness measures is documented.",
|
||
"link": "{{LINK:R05#2.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "2.1.3-S6",
|
||
"policy": "R05",
|
||
"control": "2.1.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 2.1.3-S6",
|
||
"impl_anchor": "IMPL 2.1.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Points of contact for information security are known to the employees.",
|
||
"link": "{{LINK:R05#2.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "2.1.4-M1",
|
||
"policy": "R06",
|
||
"control": "2.1.4",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 2.1.4-M1",
|
||
"impl_anchor": "IMPL 2.1.4",
|
||
"condition": null,
|
||
"requirement": "The requirements for mobile working are determined and met; the relevant aspects are taken into account.",
|
||
"link": "{{LINK:R06#2.1.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "2.1.4-S1",
|
||
"policy": "R06",
|
||
"control": "2.1.4",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 2.1.4-S1",
|
||
"impl_anchor": "IMPL 2.1.4",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The relevant aspects of mobile working are taken into account.",
|
||
"link": "{{LINK:R06#2.1.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "2.1.4-S2",
|
||
"policy": "R06",
|
||
"control": "2.1.4",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 2.1.4-S2",
|
||
"impl_anchor": "IMPL 2.1.4",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Awareness of employees.",
|
||
"link": "{{LINK:R06#2.1.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "2.1.4-H1",
|
||
"policy": "R06",
|
||
"control": "2.1.4",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 2.1.4-H1",
|
||
"impl_anchor": "IMPL 2.1.4-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "Protective measures against eavesdropping and being overlooked are implemented. (C)",
|
||
"link": "{{LINK:R06#2.1.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "3.1.1-M1",
|
||
"policy": "R07",
|
||
"control": "3.1.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 3.1.1-M1",
|
||
"impl_anchor": "IMPL 3.1.1",
|
||
"condition": null,
|
||
"requirement": "A security zone concept including associated protective measures based on the requirements for handling information assets is in place.",
|
||
"link": "{{LINK:R07#3.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "3.1.1-M2",
|
||
"policy": "R07",
|
||
"control": "3.1.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 3.1.1-M2",
|
||
"impl_anchor": "IMPL 3.1.1",
|
||
"condition": null,
|
||
"requirement": "The defined protective measures are implemented.",
|
||
"link": "{{LINK:R07#3.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "3.1.1-M3",
|
||
"policy": "R07",
|
||
"control": "3.1.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 3.1.1-M3",
|
||
"impl_anchor": "IMPL 3.1.1",
|
||
"condition": null,
|
||
"requirement": "The code of conduct for security zones is known to all persons involved.",
|
||
"link": "{{LINK:R07#3.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "3.1.1-S1",
|
||
"policy": "R07",
|
||
"control": "3.1.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 3.1.1-S1",
|
||
"impl_anchor": "IMPL 3.1.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Procedures for granting and revoking access rights are established.",
|
||
"link": "{{LINK:R07#3.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-17"
|
||
]
|
||
},
|
||
{
|
||
"id": "3.1.1-S2",
|
||
"policy": "R07",
|
||
"control": "3.1.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 3.1.1-S2",
|
||
"impl_anchor": "IMPL 3.1.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Policies for visitor management (including registration and escorting of visitors) are defined.",
|
||
"link": "{{LINK:R07#3.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-17"
|
||
]
|
||
},
|
||
{
|
||
"id": "3.1.1-S3",
|
||
"policy": "R07",
|
||
"control": "3.1.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 3.1.1-S3",
|
||
"impl_anchor": "IMPL 3.1.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Policies for carrying and using mobile IT devices and data media (e.g. registration, labelling obligations) are defined and implemented.",
|
||
"link": "{{LINK:R07#3.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-17"
|
||
]
|
||
},
|
||
{
|
||
"id": "3.1.1-S4",
|
||
"policy": "R07",
|
||
"control": "3.1.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 3.1.1-S4",
|
||
"impl_anchor": "IMPL 3.1.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Network/infrastructure components (own or customer networks) are protected against unauthorised access.",
|
||
"link": "{{LINK:R07#3.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-17"
|
||
]
|
||
},
|
||
{
|
||
"id": "3.1.1-S5",
|
||
"policy": "R07",
|
||
"control": "3.1.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 3.1.1-S5",
|
||
"impl_anchor": "IMPL 3.1.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "External premises used for storing/processing information assets are taken into account in the zone concept (e.g. storage rooms, workshops, test tracks, data centres).",
|
||
"link": "{{LINK:R07#3.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-17"
|
||
]
|
||
},
|
||
{
|
||
"id": "3.1.1-H1",
|
||
"policy": "R07",
|
||
"control": "3.1.1",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 3.1.1-H1",
|
||
"impl_anchor": "IMPL 3.1.1-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "Protective measures against simple eavesdropping and being overlooked are implemented. (C)",
|
||
"link": "{{LINK:R07#3.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "3.1.4-M1",
|
||
"policy": "R06",
|
||
"control": "3.1.4",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 3.1.4-M1",
|
||
"impl_anchor": "IMPL 3.1.4",
|
||
"condition": null,
|
||
"requirement": "The requirements for mobile IT devices and mobile data media are determined and met; the relevant aspects are taken into account.",
|
||
"link": "{{LINK:R06#3.1.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "3.1.4-S1",
|
||
"policy": "R06",
|
||
"control": "3.1.4",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 3.1.4-S1",
|
||
"impl_anchor": "IMPL 3.1.4",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Registration of the IT devices.",
|
||
"link": "{{LINK:R06#3.1.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "3.1.4-H1",
|
||
"policy": "R06",
|
||
"control": "3.1.4",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 3.1.4-H1",
|
||
"impl_anchor": "IMPL 3.1.4-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "General encryption of mobile data media or of the information assets stored on them. Where technically not feasible, information is protected by equivalent measures. (C, I)",
|
||
"link": "{{LINK:R06#3.1.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.1-M1",
|
||
"policy": "R08",
|
||
"control": "4.1.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.1-M1",
|
||
"impl_anchor": "IMPL 4.1.1",
|
||
"condition": null,
|
||
"requirement": "The requirements for handling means of identification throughout the entire lifecycle are determined and met; the relevant aspects are taken into account.",
|
||
"link": "{{LINK:R08#4.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.1-S1",
|
||
"policy": "R08",
|
||
"control": "4.1.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.1-S1",
|
||
"impl_anchor": "IMPL 4.1.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Means of identification can only be created under controlled conditions.",
|
||
"link": "{{LINK:R08#4.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-03"
|
||
]
|
||
},
|
||
{
|
||
"id": "4.1.1-H1",
|
||
"policy": "R08",
|
||
"control": "4.1.1",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.1-H1",
|
||
"impl_anchor": "IMPL 4.1.1-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "A strategy for blocking or invalidating means of identification in the event of loss is prepared and, as far as possible, implemented. (C, I, A)",
|
||
"link": "{{LINK:R08#4.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.2-M1",
|
||
"policy": "R08",
|
||
"control": "4.1.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.2-M1",
|
||
"impl_anchor": "IMPL 4.1.2",
|
||
"condition": null,
|
||
"requirement": "The user authentication procedures are selected on the basis of a risk assessment; possible attack scenarios (e.g. direct reachability via the internet) have been taken into account.",
|
||
"link": "{{LINK:R08#4.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.2-M2",
|
||
"policy": "R08",
|
||
"control": "4.1.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.2-M2",
|
||
"impl_anchor": "IMPL 4.1.2",
|
||
"condition": null,
|
||
"requirement": "State-of-the-art user authentication procedures are applied.",
|
||
"link": "{{LINK:R08#4.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.2-S1",
|
||
"policy": "R08",
|
||
"control": "4.1.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.2-S1",
|
||
"impl_anchor": "IMPL 4.1.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The authentication procedures are defined and implemented on the basis of business and security requirements.",
|
||
"link": "{{LINK:R08#4.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.2-S2",
|
||
"policy": "R08",
|
||
"control": "4.1.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.2-S2",
|
||
"impl_anchor": "IMPL 4.1.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Users are authenticated at least by strong passwords in line with established and recognised practices.",
|
||
"link": "{{LINK:R08#4.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.2-S3",
|
||
"policy": "R08",
|
||
"control": "4.1.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.2-S3",
|
||
"impl_anchor": "IMPL 4.1.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "For privileged user accounts, higher-grade procedures are used (e.g. privileged access management, two-factor authentication).",
|
||
"link": "{{LINK:R08#4.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.2-H1",
|
||
"policy": "R08",
|
||
"control": "4.1.2",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.2-H1",
|
||
"impl_anchor": "IMPL 4.1.2-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "Depending on the risk assessment, authentication and access control are strengthened by supplementary measures (e.g. continuous access monitoring, strong authentication, automatic log-off, lock upon inactivity, brute-force prevention). (C, I, A)",
|
||
"link": "{{LINK:R08#4.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.2-V1",
|
||
"policy": "R08",
|
||
"control": "4.1.2",
|
||
"level": "vhigh",
|
||
"type": "SEHR HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.2-V1",
|
||
"impl_anchor": "IMPL 4.1.2-elev",
|
||
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
||
"requirement": "Before accessing data with a very high protection need, users are authenticated by means of strong authentication (e.g. two-factor) in line with the state of the art. (C, I)",
|
||
"link": "{{LINK:R08#4.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.3-M1",
|
||
"policy": "R08",
|
||
"control": "4.1.3",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.3-M1",
|
||
"impl_anchor": "IMPL 4.1.3",
|
||
"condition": null,
|
||
"requirement": "The creation, modification and deletion of user accounts is carried out.",
|
||
"link": "{{LINK:R08#4.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-03"
|
||
]
|
||
},
|
||
{
|
||
"id": "4.1.3-M2",
|
||
"policy": "R08",
|
||
"control": "4.1.3",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.3-M2",
|
||
"impl_anchor": "IMPL 4.1.3",
|
||
"condition": null,
|
||
"requirement": "Unique and personalised user accounts are used.",
|
||
"link": "{{LINK:R08#4.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.3-M3",
|
||
"policy": "R08",
|
||
"control": "4.1.3",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.3-M3",
|
||
"impl_anchor": "IMPL 4.1.3",
|
||
"condition": null,
|
||
"requirement": "The use of shared accounts is regulated (e.g. limited to cases where traceability is dispensable).",
|
||
"link": "{{LINK:R08#4.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.3-M4",
|
||
"policy": "R08",
|
||
"control": "4.1.3",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.3-M4",
|
||
"impl_anchor": "IMPL 4.1.3",
|
||
"condition": null,
|
||
"requirement": "User accounts are deactivated immediately after the user leaves (e.g. upon end of contract).",
|
||
"link": "{{LINK:R08#4.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.3-M5",
|
||
"policy": "R08",
|
||
"control": "4.1.3",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.3-M5",
|
||
"impl_anchor": "IMPL 4.1.3",
|
||
"condition": null,
|
||
"requirement": "User accounts are reviewed regularly.",
|
||
"link": "{{LINK:R08#4.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.3-M6",
|
||
"policy": "R08",
|
||
"control": "4.1.3",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.3-M6",
|
||
"impl_anchor": "IMPL 4.1.3",
|
||
"condition": null,
|
||
"requirement": "The log-on information is provided to the user in a secure manner.",
|
||
"link": "{{LINK:R08#4.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.3-M7",
|
||
"policy": "R08",
|
||
"control": "4.1.3",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.3-M7",
|
||
"impl_anchor": "IMPL 4.1.3",
|
||
"condition": null,
|
||
"requirement": "A policy for handling log-on information is defined and implemented; the relevant aspects are taken into account.",
|
||
"link": "{{LINK:R08#4.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.3-S1",
|
||
"policy": "R08",
|
||
"control": "4.1.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.3-S1",
|
||
"impl_anchor": "IMPL 4.1.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "A base account with minimal access rights and functionalities exists and is used.",
|
||
"link": "{{LINK:R08#4.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.3-S10",
|
||
"policy": "R08",
|
||
"control": "4.1.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.3-S10",
|
||
"impl_anchor": "IMPL 4.1.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Interactive log-on for service accounts (technical accounts) is prevented technically.",
|
||
"link": "{{LINK:R08#4.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.3-S2",
|
||
"policy": "R08",
|
||
"control": "4.1.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.3-S2",
|
||
"impl_anchor": "IMPL 4.1.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Default accounts and passwords preconfigured by the manufacturer are deactivated (e.g. blocking or password change).",
|
||
"link": "{{LINK:R08#4.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.3-S3",
|
||
"policy": "R08",
|
||
"control": "4.1.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.3-S3",
|
||
"impl_anchor": "IMPL 4.1.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "User accounts are created or authorised by the responsible body.",
|
||
"link": "{{LINK:R08#4.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.3-S4",
|
||
"policy": "R08",
|
||
"control": "4.1.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.3-S4",
|
||
"impl_anchor": "IMPL 4.1.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The creation of user accounts is subject to an approval process (four-eyes principle).",
|
||
"link": "{{LINK:R08#4.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.3-S5",
|
||
"policy": "R08",
|
||
"control": "4.1.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.3-S5",
|
||
"impl_anchor": "IMPL 4.1.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "User accounts of service providers are deactivated after completion of their task.",
|
||
"link": "{{LINK:R08#4.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.3-S6",
|
||
"policy": "R08",
|
||
"control": "4.1.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.3-S6",
|
||
"impl_anchor": "IMPL 4.1.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Deadlines for deactivating and deleting user accounts are defined.",
|
||
"link": "{{LINK:R08#4.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.3-S7",
|
||
"policy": "R08",
|
||
"control": "4.1.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.3-S7",
|
||
"impl_anchor": "IMPL 4.1.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The use of default passwords is prevented technically.",
|
||
"link": "{{LINK:R08#4.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.3-S8",
|
||
"policy": "R08",
|
||
"control": "4.1.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.3-S8",
|
||
"impl_anchor": "IMPL 4.1.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "In the case of strong authentication, the use of the medium (e.g. possession factor) is secure.",
|
||
"link": "{{LINK:R08#4.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.1.3-S9",
|
||
"policy": "R08",
|
||
"control": "4.1.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.1.3-S9",
|
||
"impl_anchor": "IMPL 4.1.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "User accounts are reviewed regularly; this also includes accounts in customers' IT systems.",
|
||
"link": "{{LINK:R08#4.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.2.1-M1",
|
||
"policy": "R08",
|
||
"control": "4.2.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.2.1-M1",
|
||
"impl_anchor": "IMPL 4.2.1",
|
||
"condition": null,
|
||
"requirement": "The requirements for managing access rights (authorisation) are determined and met; the relevant aspects are taken into account.",
|
||
"link": "{{LINK:R08#4.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-03"
|
||
]
|
||
},
|
||
{
|
||
"id": "4.2.1-M2",
|
||
"policy": "R08",
|
||
"control": "4.2.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.2.1-M2",
|
||
"impl_anchor": "IMPL 4.2.1",
|
||
"condition": null,
|
||
"requirement": "The access rights granted for normal and privileged user accounts as well as technical accounts are reviewed regularly, also in customers' IT systems.",
|
||
"link": "{{LINK:R08#4.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-03"
|
||
]
|
||
},
|
||
{
|
||
"id": "4.2.1-S1",
|
||
"policy": "R08",
|
||
"control": "4.2.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.2.1-S1",
|
||
"impl_anchor": "IMPL 4.2.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Strategies for authorising access to information are prepared.",
|
||
"link": "{{LINK:R08#4.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-03"
|
||
]
|
||
},
|
||
{
|
||
"id": "4.2.1-S2",
|
||
"policy": "R08",
|
||
"control": "4.2.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.2.1-S2",
|
||
"impl_anchor": "IMPL 4.2.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Authorisation roles are used.",
|
||
"link": "{{LINK:R08#4.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.2.1-S3",
|
||
"policy": "R08",
|
||
"control": "4.2.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.2.1-S3",
|
||
"impl_anchor": "IMPL 4.2.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Rights are granted according to the need-to-use principle and in line with role and/or area of responsibility.",
|
||
"link": "{{LINK:R08#4.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.2.1-S4",
|
||
"policy": "R08",
|
||
"control": "4.2.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.2.1-S4",
|
||
"impl_anchor": "IMPL 4.2.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Normal user accounts do not receive privileged access rights.",
|
||
"link": "{{LINK:R08#4.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.2.1-S5",
|
||
"policy": "R08",
|
||
"control": "4.2.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.2.1-S5",
|
||
"impl_anchor": "IMPL 4.2.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The user's access rights are updated after a change in their responsibilities.",
|
||
"link": "{{LINK:R08#4.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.2.1-H1",
|
||
"policy": "R08",
|
||
"control": "4.2.1",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.2.1-H1",
|
||
"impl_anchor": "IMPL 4.2.1-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "The access rights are approved by the responsible internal information officer. (C, I, A)",
|
||
"link": "{{LINK:R08#4.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.2.1-V1",
|
||
"policy": "R08",
|
||
"control": "4.2.1",
|
||
"level": "vhigh",
|
||
"type": "SEHR HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.2.1-V1",
|
||
"impl_anchor": "IMPL 4.2.1-elev",
|
||
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
||
"requirement": "Information is stored encrypted at content level (e.g. file level) to prevent unauthorised access (including by privileged users). Where encryption is not feasible, equivalent measures apply. (C)",
|
||
"link": "{{LINK:R08#4.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "4.2.1-V2",
|
||
"policy": "R08",
|
||
"control": "4.2.1",
|
||
"level": "vhigh",
|
||
"type": "SEHR HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 4.2.1-V2",
|
||
"impl_anchor": "IMPL 4.2.1-elev",
|
||
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
||
"requirement": "Existing access rights are reviewed at shorter intervals (e.g. quarterly). (C)",
|
||
"link": "{{LINK:R08#4.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.1.1-M1",
|
||
"policy": "R09",
|
||
"control": "5.1.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.1.1-M1",
|
||
"impl_anchor": "IMPL 5.1.1",
|
||
"condition": null,
|
||
"requirement": "All cryptographic procedures used (e.g. encryption, signature, hash algorithms, protocols) provide the security required in the respective field of application according to a recognised industry standard, as far as legally possible.",
|
||
"link": "{{LINK:R09#5.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-07"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.1.1-S1",
|
||
"policy": "R09",
|
||
"control": "5.1.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.1.1-S1",
|
||
"impl_anchor": "IMPL 5.1.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "A concept for the use of cryptography is defined and implemented; the relevant aspects are taken into account.",
|
||
"link": "{{LINK:R09#5.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-07"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.1.1-H1",
|
||
"policy": "R09",
|
||
"control": "5.1.1",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.1.1-H1",
|
||
"impl_anchor": "IMPL 5.1.1-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "Requirements for key sovereignty (in particular in the case of external processing) are determined and met. (C, I)",
|
||
"link": "{{LINK:R09#5.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.1.2-M1",
|
||
"policy": "R09",
|
||
"control": "5.1.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.1.2-M1",
|
||
"impl_anchor": "IMPL 5.1.2",
|
||
"condition": null,
|
||
"requirement": "The network services used for transmitting information are identified and documented.",
|
||
"link": "{{LINK:R09#5.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-07"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.1.2-M2",
|
||
"policy": "R09",
|
||
"control": "5.1.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.1.2-M2",
|
||
"impl_anchor": "IMPL 5.1.2",
|
||
"condition": null,
|
||
"requirement": "Policies and procedures in line with the classification requirements for the use of network services are defined and implemented.",
|
||
"link": "{{LINK:R09#5.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.1.2-M3",
|
||
"policy": "R09",
|
||
"control": "5.1.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.1.2-M3",
|
||
"impl_anchor": "IMPL 5.1.2",
|
||
"condition": null,
|
||
"requirement": "Measures to protect transmitted content against unauthorised access are implemented.",
|
||
"link": "{{LINK:R09#5.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.1.2-S1",
|
||
"policy": "R09",
|
||
"control": "5.1.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.1.2-S1",
|
||
"impl_anchor": "IMPL 5.1.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Measures to ensure correct addressing and correct transmission of information are implemented.",
|
||
"link": "{{LINK:R09#5.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-07"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.1.2-S2",
|
||
"policy": "R09",
|
||
"control": "5.1.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.1.2-S2",
|
||
"impl_anchor": "IMPL 5.1.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Electronic data exchange takes place using content or transport encryption in line with the respective classification.",
|
||
"link": "{{LINK:R09#5.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.1.2-S3",
|
||
"policy": "R09",
|
||
"control": "5.1.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.1.2-S3",
|
||
"impl_anchor": "IMPL 5.1.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Remote access connections to the organisation's network have appropriate security features; the relevant aspects are taken into account.",
|
||
"link": "{{LINK:R09#5.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.1.2-H1",
|
||
"policy": "R09",
|
||
"control": "5.1.2",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.1.2-H1",
|
||
"impl_anchor": "IMPL 5.1.2-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "Information is transmitted encrypted (at least transport encryption) or protected by equivalently effective measures. (C)",
|
||
"link": "{{LINK:R09#5.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.1.2-V1",
|
||
"policy": "R09",
|
||
"control": "5.1.2",
|
||
"level": "vhigh",
|
||
"type": "SEHR HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.1.2-V1",
|
||
"impl_anchor": "IMPL 5.1.2-elev",
|
||
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
||
"requirement": "Information is transmitted with content encryption. (C)",
|
||
"link": "{{LINK:R09#5.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.1-M1",
|
||
"policy": "R10",
|
||
"control": "5.2.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.1-M1",
|
||
"impl_anchor": "IMPL 5.2.1",
|
||
"condition": null,
|
||
"requirement": "Information security requirements for changes to the organisation, business processes and IT systems are determined and met.",
|
||
"link": "{{LINK:R10#5.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-04"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.2.1-S1",
|
||
"policy": "R10",
|
||
"control": "5.2.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.1-S1",
|
||
"impl_anchor": "IMPL 5.2.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "A formal approval procedure is established.",
|
||
"link": "{{LINK:R10#5.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.1-S2",
|
||
"policy": "R10",
|
||
"control": "5.2.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.1-S2",
|
||
"impl_anchor": "IMPL 5.2.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The possible effects of changes on information security are assessed.",
|
||
"link": "{{LINK:R10#5.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.1-S3",
|
||
"policy": "R10",
|
||
"control": "5.2.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.1-S3",
|
||
"impl_anchor": "IMPL 5.2.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Changes with an effect on information security are planned and tested.",
|
||
"link": "{{LINK:R10#5.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.1-S4",
|
||
"policy": "R10",
|
||
"control": "5.2.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.1-S4",
|
||
"impl_anchor": "IMPL 5.2.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Fallback procedures in the event of errors are taken into account.",
|
||
"link": "{{LINK:R10#5.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.1-H1",
|
||
"policy": "R10",
|
||
"control": "5.2.1",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.1-H1",
|
||
"impl_anchor": "IMPL 5.2.1-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "Compliance with the information security requirements is verified during and after the changes. (C, I, A)",
|
||
"link": "{{LINK:R10#5.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.2-M1",
|
||
"policy": "R10",
|
||
"control": "5.2.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.2-M1",
|
||
"impl_anchor": "IMPL 5.2.2",
|
||
"condition": null,
|
||
"requirement": "The IT systems have been subjected to a risk assessment to determine the need to separate them into development, test and production systems.",
|
||
"link": "{{LINK:R10#5.2.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.2-M2",
|
||
"policy": "R10",
|
||
"control": "5.2.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.2-M2",
|
||
"impl_anchor": "IMPL 5.2.2",
|
||
"condition": null,
|
||
"requirement": "A segmentation is implemented on the basis of the results of the risk analysis.",
|
||
"link": "{{LINK:R10#5.2.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.2-S1",
|
||
"policy": "R10",
|
||
"control": "5.2.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.2-S1",
|
||
"impl_anchor": "IMPL 5.2.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The requirements for development and test environments are determined and met; the relevant aspects are taken into account.",
|
||
"link": "{{LINK:R10#5.2.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.3-M1",
|
||
"policy": "R10",
|
||
"control": "5.2.3",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.3-M1",
|
||
"impl_anchor": "IMPL 5.2.3",
|
||
"condition": null,
|
||
"requirement": "Requirements for protection against malware are determined.",
|
||
"link": "{{LINK:R10#5.2.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.3-M2",
|
||
"policy": "R10",
|
||
"control": "5.2.3",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.3-M2",
|
||
"impl_anchor": "IMPL 5.2.3",
|
||
"condition": null,
|
||
"requirement": "Technical and organisational measures for protection against malware are defined and implemented.",
|
||
"link": "{{LINK:R10#5.2.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.3-S1",
|
||
"policy": "R10",
|
||
"control": "5.2.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.3-S1",
|
||
"impl_anchor": "IMPL 5.2.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Unnecessary network services are deactivated.",
|
||
"link": "{{LINK:R10#5.2.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.3-S2",
|
||
"policy": "R10",
|
||
"control": "5.2.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.3-S2",
|
||
"impl_anchor": "IMPL 5.2.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Access to network services is limited to what is necessary through appropriate protective measures.",
|
||
"link": "{{LINK:R10#5.2.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.3-S3",
|
||
"policy": "R10",
|
||
"control": "5.2.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.3-S3",
|
||
"impl_anchor": "IMPL 5.2.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Protective software against malware is installed and updated automatically at regular intervals (e.g. virus scanner).",
|
||
"link": "{{LINK:R10#5.2.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.3-S4",
|
||
"policy": "R10",
|
||
"control": "5.2.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.3-S4",
|
||
"impl_anchor": "IMPL 5.2.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Received files and software are automatically checked for malware before execution (on-access scan).",
|
||
"link": "{{LINK:R10#5.2.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.3-S5",
|
||
"policy": "R10",
|
||
"control": "5.2.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.3-S5",
|
||
"impl_anchor": "IMPL 5.2.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The entire data stock of all systems is checked for malware regularly.",
|
||
"link": "{{LINK:R10#5.2.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.3-S6",
|
||
"policy": "R10",
|
||
"control": "5.2.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.3-S6",
|
||
"impl_anchor": "IMPL 5.2.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Data transmitted via central gateways (e.g. email, internet, external networks) is automatically checked by protective software.",
|
||
"link": "{{LINK:R10#5.2.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.3-S7",
|
||
"policy": "R10",
|
||
"control": "5.2.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.3-S7",
|
||
"impl_anchor": "IMPL 5.2.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Measures preventing protective software from being deactivated or modified by users are defined and implemented.",
|
||
"link": "{{LINK:R10#5.2.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.3-S8",
|
||
"policy": "R10",
|
||
"control": "5.2.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.3-S8",
|
||
"impl_anchor": "IMPL 5.2.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "For IT systems without protective software, alternative measures are implemented (e.g. special resilience, few services, no active users, network isolation).",
|
||
"link": "{{LINK:R10#5.2.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.4-M1",
|
||
"policy": "R10",
|
||
"control": "5.2.4",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.4-M1",
|
||
"impl_anchor": "IMPL 5.2.4",
|
||
"condition": null,
|
||
"requirement": "Information security requirements for handling event logs are determined and met.",
|
||
"link": "{{LINK:R10#5.2.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-13"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.2.4-M2",
|
||
"policy": "R10",
|
||
"control": "5.2.4",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.4-M2",
|
||
"impl_anchor": "IMPL 5.2.4",
|
||
"condition": null,
|
||
"requirement": "Security-relevant requirements for logging the activities of administrators and users are determined and met.",
|
||
"link": "{{LINK:R10#5.2.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.4-M3",
|
||
"policy": "R10",
|
||
"control": "5.2.4",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.4-M3",
|
||
"impl_anchor": "IMPL 5.2.4",
|
||
"condition": null,
|
||
"requirement": "The IT systems used are assessed with regard to the need for logging.",
|
||
"link": "{{LINK:R10#5.2.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.4-M4",
|
||
"policy": "R10",
|
||
"control": "5.2.4",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.4-M4",
|
||
"impl_anchor": "IMPL 5.2.4",
|
||
"condition": null,
|
||
"requirement": "When external IT services are used, information on the monitoring options is obtained and taken into account in the assessment.",
|
||
"link": "{{LINK:R10#5.2.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.4-M5",
|
||
"policy": "R10",
|
||
"control": "5.2.4",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.4-M5",
|
||
"impl_anchor": "IMPL 5.2.4",
|
||
"condition": null,
|
||
"requirement": "Event logs are checked regularly for policy violations and conspicuous problems, in compliance with the permissible legal and organisational requirements.",
|
||
"link": "{{LINK:R10#5.2.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.4-S1",
|
||
"policy": "R10",
|
||
"control": "5.2.4",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.4-S1",
|
||
"impl_anchor": "IMPL 5.2.4",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "A procedure for escalating relevant events to the responsible body is defined and established.",
|
||
"link": "{{LINK:R10#5.2.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-13"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.2.4-S2",
|
||
"policy": "R10",
|
||
"control": "5.2.4",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.4-S2",
|
||
"impl_anchor": "IMPL 5.2.4",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Event logs (content and metadata) are protected against modification (e.g. by a dedicated environment).",
|
||
"link": "{{LINK:R10#5.2.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.4-S3",
|
||
"policy": "R10",
|
||
"control": "5.2.4",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.4-S3",
|
||
"impl_anchor": "IMPL 5.2.4",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Appropriate monitoring and recording of all information-security-relevant actions in the network is established.",
|
||
"link": "{{LINK:R10#5.2.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.4-H1",
|
||
"policy": "R10",
|
||
"control": "5.2.4",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.4-H1",
|
||
"impl_anchor": "IMPL 5.2.4-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "Security-relevant requirements for handling event logs, e.g. contractual requirements, are determined and implemented. (C, I, A)",
|
||
"link": "{{LINK:R10#5.2.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.4-H2",
|
||
"policy": "R10",
|
||
"control": "5.2.4",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.4-H2",
|
||
"impl_anchor": "IMPL 5.2.4-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "Events relating to the establishment and termination of remote access sessions (e.g. remote maintenance) are logged. (C, I, A)",
|
||
"link": "{{LINK:R10#5.2.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.4-V1",
|
||
"policy": "R10",
|
||
"control": "5.2.4",
|
||
"level": "vhigh",
|
||
"type": "SEHR HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.4-V1",
|
||
"impl_anchor": "IMPL 5.2.4-elev",
|
||
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
||
"requirement": "Logging of every access to data with a very high protection need, as far as technically feasible and legally/organisationally permissible. (C, I)",
|
||
"link": "{{LINK:R10#5.2.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.5-M1",
|
||
"policy": "R10",
|
||
"control": "5.2.5",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.5-M1",
|
||
"impl_anchor": "IMPL 5.2.5",
|
||
"condition": null,
|
||
"requirement": "Information about technical vulnerabilities of the IT systems used is collected (e.g. manufacturer information, system audits, CVE database).",
|
||
"link": "{{LINK:R10#5.2.5}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-04",
|
||
"VA-06"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.2.5-M2",
|
||
"policy": "R10",
|
||
"control": "5.2.5",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.5-M2",
|
||
"impl_anchor": "IMPL 5.2.5",
|
||
"condition": null,
|
||
"requirement": "Potentially affected IT systems and software are identified and the risk caused by the vulnerability is assessed.",
|
||
"link": "{{LINK:R10#5.2.5}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.5-M3",
|
||
"policy": "R10",
|
||
"control": "5.2.5",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.5-M3",
|
||
"impl_anchor": "IMPL 5.2.5",
|
||
"condition": null,
|
||
"requirement": "Risks arising from vulnerabilities are treated.",
|
||
"link": "{{LINK:R10#5.2.5}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.5-S1",
|
||
"policy": "R10",
|
||
"control": "5.2.5",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.5-S1",
|
||
"impl_anchor": "IMPL 5.2.5",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Appropriate patch management is defined and implemented (e.g. patch testing and installation).",
|
||
"link": "{{LINK:R10#5.2.5}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-06"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.2.5-S2",
|
||
"policy": "R10",
|
||
"control": "5.2.5",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.5-S2",
|
||
"impl_anchor": "IMPL 5.2.5",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Risk-mitigating measures are implemented where necessary.",
|
||
"link": "{{LINK:R10#5.2.5}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.5-S3",
|
||
"policy": "R10",
|
||
"control": "5.2.5",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.5-S3",
|
||
"impl_anchor": "IMPL 5.2.5",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The successful installation of patches is verified in a suitable manner.",
|
||
"link": "{{LINK:R10#5.2.5}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.6-M1",
|
||
"policy": "R10",
|
||
"control": "5.2.6",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.6-M1",
|
||
"impl_anchor": "IMPL 5.2.6",
|
||
"condition": null,
|
||
"requirement": "Requirements for the review (audit) of IT systems or services are determined.",
|
||
"link": "{{LINK:R10#5.2.6}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-06"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.2.6-M2",
|
||
"policy": "R10",
|
||
"control": "5.2.6",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.6-M2",
|
||
"impl_anchor": "IMPL 5.2.6",
|
||
"condition": null,
|
||
"requirement": "The scope of the system review is defined in good time.",
|
||
"link": "{{LINK:R10#5.2.6}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.6-M3",
|
||
"policy": "R10",
|
||
"control": "5.2.6",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.6-M3",
|
||
"impl_anchor": "IMPL 5.2.6",
|
||
"condition": null,
|
||
"requirement": "System or service reviews are coordinated with the operators and users of the IT systems/services.",
|
||
"link": "{{LINK:R10#5.2.6}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.6-M4",
|
||
"policy": "R10",
|
||
"control": "5.2.6",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.6-M4",
|
||
"impl_anchor": "IMPL 5.2.6",
|
||
"condition": null,
|
||
"requirement": "The results of system/service reviews are stored in a traceable manner and reported to the responsible management.",
|
||
"link": "{{LINK:R10#5.2.6}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.6-M5",
|
||
"policy": "R10",
|
||
"control": "5.2.6",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.6-M5",
|
||
"impl_anchor": "IMPL 5.2.6",
|
||
"condition": null,
|
||
"requirement": "Measures are derived from the results and implemented within an appropriate period.",
|
||
"link": "{{LINK:R10#5.2.6}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.6-S1",
|
||
"policy": "R10",
|
||
"control": "5.2.6",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.6-S1",
|
||
"impl_anchor": "IMPL 5.2.6",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "System and service reviews are planned taking possible security risks (e.g. disruptions) into account.",
|
||
"link": "{{LINK:R10#5.2.6}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.6-S2",
|
||
"policy": "R10",
|
||
"control": "5.2.6",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.6-S2",
|
||
"impl_anchor": "IMPL 5.2.6",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Regular system or service reviews are carried out; the relevant aspects are taken into account.",
|
||
"link": "{{LINK:R10#5.2.6}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.6-S3",
|
||
"policy": "R10",
|
||
"control": "5.2.6",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.6-S3",
|
||
"impl_anchor": "IMPL 5.2.6",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Within an appropriate period after completion of the review, a report is prepared.",
|
||
"link": "{{LINK:R10#5.2.6}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.6-H1",
|
||
"policy": "R10",
|
||
"control": "5.2.6",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.6-H1",
|
||
"impl_anchor": "IMPL 5.2.6-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "For critical IT systems/services, additional review requirements have been identified and are met (e.g. service-specific tests/tools and/or manual penetration tests, risk-based intervals). (A)",
|
||
"link": "{{LINK:R10#5.2.6}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.6-V1",
|
||
"policy": "R10",
|
||
"control": "5.2.6",
|
||
"level": "vhigh",
|
||
"type": "SEHR HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.6-V1",
|
||
"impl_anchor": "IMPL 5.2.6-elev",
|
||
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
||
"requirement": "IT systems and services are scanned regularly for vulnerabilities. For systems/services that cannot be scanned, suitable protective measures are to be implemented. (C, I, A)",
|
||
"link": "{{LINK:R10#5.2.6}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.7-M1",
|
||
"policy": "R10",
|
||
"control": "5.2.7",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.7-M1",
|
||
"impl_anchor": "IMPL 5.2.7",
|
||
"condition": null,
|
||
"requirement": "Requirements for the management and control of networks are determined and met.",
|
||
"link": "{{LINK:R10#5.2.7}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.7-M2",
|
||
"policy": "R10",
|
||
"control": "5.2.7",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.7-M2",
|
||
"impl_anchor": "IMPL 5.2.7",
|
||
"condition": null,
|
||
"requirement": "Requirements for network segmentation are determined and met.",
|
||
"link": "{{LINK:R10#5.2.7}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.7-S1",
|
||
"policy": "R10",
|
||
"control": "5.2.7",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.7-S1",
|
||
"impl_anchor": "IMPL 5.2.7",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Procedures for the management and control of networks are defined.",
|
||
"link": "{{LINK:R10#5.2.7}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.7-S2",
|
||
"policy": "R10",
|
||
"control": "5.2.7",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.7-S2",
|
||
"impl_anchor": "IMPL 5.2.7",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "For a risk-based network segmentation, the relevant aspects are taken into account.",
|
||
"link": "{{LINK:R10#5.2.7}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.7-H1",
|
||
"policy": "R10",
|
||
"control": "5.2.7",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.7-H1",
|
||
"impl_anchor": "IMPL 5.2.7-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "Extended requirements for the management and control of networks are determined and implemented. (C, I, A)",
|
||
"link": "{{LINK:R10#5.2.7}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.8-M1",
|
||
"policy": "R04",
|
||
"control": "5.2.8",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.8-M1",
|
||
"impl_anchor": "IMPL 5.2.8",
|
||
"condition": null,
|
||
"requirement": "Critical IT services are identified and the business impact is taken into account.",
|
||
"link": "{{LINK:R04#5.2.8}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-02"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.2.8-M2",
|
||
"policy": "R04",
|
||
"control": "5.2.8",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.8-M2",
|
||
"impl_anchor": "IMPL 5.2.8",
|
||
"condition": null,
|
||
"requirement": "Requirements and responsibilities for the continuity and recovery of these IT services are known to relevant stakeholders and fulfilled.",
|
||
"link": "{{LINK:R04#5.2.8}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.8-S1",
|
||
"policy": "R04",
|
||
"control": "5.2.8",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.8-S1",
|
||
"impl_anchor": "IMPL 5.2.8",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Critical IT systems are identified; the relevant aspects are taken into account.",
|
||
"link": "{{LINK:R04#5.2.8}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-02"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.2.8-S2",
|
||
"policy": "R04",
|
||
"control": "5.2.8",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.8-S2",
|
||
"impl_anchor": "IMPL 5.2.8",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "A continuity plan exists and is reviewed and updated regularly.",
|
||
"link": "{{LINK:R04#5.2.8}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.8-S3",
|
||
"policy": "R04",
|
||
"control": "5.2.8",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.8-S3",
|
||
"impl_anchor": "IMPL 5.2.8",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The continuity planning covers at least (D)DoS attacks, successful ransomware attacks and other sabotage, system failure scenarios as well as natural disasters affecting critical IT systems.",
|
||
"link": "{{LINK:R04#5.2.8}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.8-H1",
|
||
"policy": "R04",
|
||
"control": "5.2.8",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.8-H1",
|
||
"impl_anchor": "IMPL 5.2.8-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "The continuity planning contains predefined time frames (recovery time objective) for the resumption of operations. (A)",
|
||
"link": "{{LINK:R04#5.2.8}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.8-H2",
|
||
"policy": "R04",
|
||
"control": "5.2.8",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.8-H2",
|
||
"impl_anchor": "IMPL 5.2.8-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "Appropriate SLAs with external service providers in line with the continuity planning are in place. (A)",
|
||
"link": "{{LINK:R04#5.2.8}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.8-H3",
|
||
"policy": "R04",
|
||
"control": "5.2.8",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.8-H3",
|
||
"impl_anchor": "IMPL 5.2.8-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "The continuity plans include the coordination of contractually agreed communication with business partners. (A)",
|
||
"link": "{{LINK:R04#5.2.8}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.8-H4",
|
||
"policy": "R04",
|
||
"control": "5.2.8",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.8-H4",
|
||
"impl_anchor": "IMPL 5.2.8-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "The continuity planning is tested regularly, incl. full recovery to a known state and adherence to defined target times. (A)",
|
||
"link": "{{LINK:R04#5.2.8}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.8-H5",
|
||
"policy": "R04",
|
||
"control": "5.2.8",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.8-H5",
|
||
"impl_anchor": "IMPL 5.2.8-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "A backup and recovery strategy for critical IT services and information is defined and implemented. (C, I, A)",
|
||
"link": "{{LINK:R04#5.2.8}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.8-H6",
|
||
"policy": "R04",
|
||
"control": "5.2.8",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.8-H6",
|
||
"impl_anchor": "IMPL 5.2.8-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "Backups of critical IT services and information are sufficiently protected against unauthorised modification/deletion by malware. (I, A)",
|
||
"link": "{{LINK:R04#5.2.8}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.8-H7",
|
||
"policy": "R04",
|
||
"control": "5.2.8",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.8-H7",
|
||
"impl_anchor": "IMPL 5.2.8-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "Backups of critical IT services and information are sufficiently protected against unauthorised access by malware or operators. (C, I)",
|
||
"link": "{{LINK:R04#5.2.8}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.8-V1",
|
||
"policy": "R04",
|
||
"control": "5.2.8",
|
||
"level": "vhigh",
|
||
"type": "SEHR HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.8-V1",
|
||
"impl_anchor": "IMPL 5.2.8-elev",
|
||
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
||
"requirement": "The continuity planning is coordinated with the continuity plans of relevant external service providers. (A)",
|
||
"link": "{{LINK:R04#5.2.8}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.8-V2",
|
||
"policy": "R04",
|
||
"control": "5.2.8",
|
||
"level": "vhigh",
|
||
"type": "SEHR HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.8-V2",
|
||
"impl_anchor": "IMPL 5.2.8-elev",
|
||
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
||
"requirement": "The continuation of essential core and business functions with minimal or no loss of operational continuity is possible; the relevant aspects are taken into account.",
|
||
"link": "{{LINK:R04#5.2.8}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.8-V3",
|
||
"policy": "R04",
|
||
"control": "5.2.8",
|
||
"level": "vhigh",
|
||
"type": "SEHR HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.8-V3",
|
||
"impl_anchor": "IMPL 5.2.8-elev",
|
||
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
||
"requirement": "The continuity planning is tested regularly. Test scenarios, results and lessons learned are recorded. (I, A)",
|
||
"link": "{{LINK:R04#5.2.8}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.9-M1",
|
||
"policy": "R10",
|
||
"control": "5.2.9",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.9-M1",
|
||
"impl_anchor": "IMPL 5.2.9",
|
||
"condition": null,
|
||
"requirement": "Backup concepts exist for relevant IT systems. Appropriate protective measures for the confidentiality, integrity and availability of the backups are taken into account.",
|
||
"link": "{{LINK:R10#5.2.9}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-05"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.2.9-M2",
|
||
"policy": "R10",
|
||
"control": "5.2.9",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.9-M2",
|
||
"impl_anchor": "IMPL 5.2.9",
|
||
"condition": null,
|
||
"requirement": "Recovery concepts exist for relevant IT services.",
|
||
"link": "{{LINK:R10#5.2.9}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-05"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.2.9-S1",
|
||
"policy": "R10",
|
||
"control": "5.2.9",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.9-S1",
|
||
"impl_anchor": "IMPL 5.2.9",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "For each relevant IT service, a backup and recovery concept exists. Dependencies between IT services and the recovery sequence are taken into account.",
|
||
"link": "{{LINK:R10#5.2.9}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-05"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.2.9-H1",
|
||
"policy": "R10",
|
||
"control": "5.2.9",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.9-H1",
|
||
"impl_anchor": "IMPL 5.2.9-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "Backup and recovery concepts are reviewed methodically at regular intervals. (A)",
|
||
"link": "{{LINK:R10#5.2.9}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.9-H2",
|
||
"policy": "R10",
|
||
"control": "5.2.9",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.9-H2",
|
||
"impl_anchor": "IMPL 5.2.9-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "The fundamental recoverability is taken into account and tested (e.g. sample tests, test systems). (I, A)",
|
||
"link": "{{LINK:R10#5.2.9}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.9-V1",
|
||
"policy": "R10",
|
||
"control": "5.2.9",
|
||
"level": "vhigh",
|
||
"type": "SEHR HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.9-V1",
|
||
"impl_anchor": "IMPL 5.2.9-elev",
|
||
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
||
"requirement": "(Additional) backups are carried out via offline procedures, immutable backups or an isolated IAM solution. (I, A)",
|
||
"link": "{{LINK:R10#5.2.9}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.9-V2",
|
||
"policy": "R10",
|
||
"control": "5.2.9",
|
||
"level": "vhigh",
|
||
"type": "SEHR HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.9-V2",
|
||
"impl_anchor": "IMPL 5.2.9-elev",
|
||
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
||
"requirement": "Recovery procedures are tested technically and methodically at regular intervals. (I, A)",
|
||
"link": "{{LINK:R10#5.2.9}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.2.9-V3",
|
||
"policy": "R10",
|
||
"control": "5.2.9",
|
||
"level": "vhigh",
|
||
"type": "SEHR HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.2.9-V3",
|
||
"impl_anchor": "IMPL 5.2.9-elev",
|
||
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
||
"requirement": "Geographical redundancy is taken into account in backup and recovery concepts. (A)",
|
||
"link": "{{LINK:R10#5.2.9}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.3.1-M1",
|
||
"policy": "R11",
|
||
"control": "5.3.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.3.1-M1",
|
||
"impl_anchor": "IMPL 5.3.1",
|
||
"condition": null,
|
||
"requirement": "The information security requirements associated with the design and development of an IT service are determined and taken into account.",
|
||
"link": "{{LINK:R11#5.3.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-16"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.3.1-M2",
|
||
"policy": "R11",
|
||
"control": "5.3.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.3.1-M2",
|
||
"impl_anchor": "IMPL 5.3.1",
|
||
"condition": null,
|
||
"requirement": "The information security requirements associated with the procurement or extension of IT services and components are determined and taken into account.",
|
||
"link": "{{LINK:R11#5.3.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-16"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.3.1-M3",
|
||
"policy": "R11",
|
||
"control": "5.3.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.3.1-M3",
|
||
"impl_anchor": "IMPL 5.3.1",
|
||
"condition": null,
|
||
"requirement": "Information security requirements in connection with changes to developed IT services are taken into account.",
|
||
"link": "{{LINK:R11#5.3.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-16"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.3.1-M4",
|
||
"policy": "R11",
|
||
"control": "5.3.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.3.1-M4",
|
||
"impl_anchor": "IMPL 5.3.1",
|
||
"condition": null,
|
||
"requirement": "System acceptance tests are carried out taking the information security requirements into account.",
|
||
"link": "{{LINK:R11#5.3.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-16"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.3.1-S1",
|
||
"policy": "R11",
|
||
"control": "5.3.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.3.1-S1",
|
||
"impl_anchor": "IMPL 5.3.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Requirement specifications are created; the relevant aspects are taken into account.",
|
||
"link": "{{LINK:R11#5.3.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-16"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.3.1-S2",
|
||
"policy": "R11",
|
||
"control": "5.3.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.3.1-S2",
|
||
"impl_anchor": "IMPL 5.3.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Requirement specifications are checked against the information security requirements.",
|
||
"link": "{{LINK:R11#5.3.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-16"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.3.1-S3",
|
||
"policy": "R11",
|
||
"control": "5.3.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.3.1-S3",
|
||
"impl_anchor": "IMPL 5.3.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The IT service is checked for compliance with the specifications before production use.",
|
||
"link": "{{LINK:R11#5.3.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-16"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.3.1-S4",
|
||
"policy": "R11",
|
||
"control": "5.3.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.3.1-S4",
|
||
"impl_anchor": "IMPL 5.3.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The use of production data for test purposes is avoided as far as possible (anonymisation/pseudonymisation where applicable); the relevant aspects are taken into account.",
|
||
"link": "{{LINK:R11#5.3.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-16"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.3.1-S5",
|
||
"policy": "R11",
|
||
"control": "5.3.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.3.1-S5",
|
||
"impl_anchor": "IMPL 5.3.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Test systems receive protective measures comparable to the production environment when production data is used for testing.",
|
||
"link": "{{LINK:R11#5.3.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-16"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.3.1-V1",
|
||
"policy": "R11",
|
||
"control": "5.3.1",
|
||
"level": "vhigh",
|
||
"type": "SEHR HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.3.1-V1",
|
||
"impl_anchor": "IMPL 5.3.1-elev",
|
||
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
||
"requirement": "The security of purpose-built or substantially adapted software is tested upon commissioning, upon substantial changes or regularly (e.g. penetration test). (C, I, A)",
|
||
"link": "{{LINK:R11#5.3.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-16"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.3.2-M1",
|
||
"policy": "R11",
|
||
"control": "5.3.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.3.2-M1",
|
||
"impl_anchor": "IMPL 5.3.2",
|
||
"condition": null,
|
||
"requirement": "Requirements for the information security of network services are determined and met.",
|
||
"link": "{{LINK:R11#5.3.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-16"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.3.2-S1",
|
||
"policy": "R11",
|
||
"control": "5.3.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.3.2-S1",
|
||
"impl_anchor": "IMPL 5.3.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "A procedure for securing and using network services is defined and implemented.",
|
||
"link": "{{LINK:R11#5.3.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-16"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.3.2-S2",
|
||
"policy": "R11",
|
||
"control": "5.3.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.3.2-S2",
|
||
"impl_anchor": "IMPL 5.3.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The requirements are agreed in the form of SLAs.",
|
||
"link": "{{LINK:R11#5.3.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-16"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.3.2-S3",
|
||
"policy": "R11",
|
||
"control": "5.3.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.3.2-S3",
|
||
"impl_anchor": "IMPL 5.3.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Appropriate redundancy solutions are implemented.",
|
||
"link": "{{LINK:R11#5.3.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-16"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.3.2-H1",
|
||
"policy": "R11",
|
||
"control": "5.3.2",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.3.2-H1",
|
||
"impl_anchor": "IMPL 5.3.2-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "Procedures for monitoring the quality of network traffic (e.g. traffic flow analyses, availability measurements) are defined and carried out. (A)",
|
||
"link": "{{LINK:R11#5.3.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-16"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.3.3-S1",
|
||
"policy": "R11",
|
||
"control": "5.3.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.3.3-S1",
|
||
"impl_anchor": "IMPL 5.3.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "A description of the termination process is in place, adapted to changes and regulated contractually.",
|
||
"link": "{{LINK:R11#5.3.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "5.3.4-M1",
|
||
"policy": "R12",
|
||
"control": "5.3.4",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.3.4-M1",
|
||
"impl_anchor": "IMPL 5.3.4",
|
||
"condition": null,
|
||
"requirement": "An effective separation (e.g. tenant separation) prevents unauthorised users of other organisations from accessing one's own information.",
|
||
"link": "{{LINK:R12#5.3.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-11"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.3.4-S1",
|
||
"policy": "R12",
|
||
"control": "5.3.4",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 5.3.4-S1",
|
||
"impl_anchor": "IMPL 5.3.4",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The provider's separation concept is documented and adapted to changes; the relevant aspects are taken into account.",
|
||
"link": "{{LINK:R12#5.3.4}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-11"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.3.4-KI-M1",
|
||
"policy": "R12",
|
||
"control": "5.3.4-KI",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": false,
|
||
"req_anchor": "REQ 5.3.4-KI-M1",
|
||
"impl_anchor": "IMPL 5.3.4-KI",
|
||
"condition": null,
|
||
"requirement": "The use of AI/GenAI services is regulated; only approved services are used.",
|
||
"link": "{{LINK:R12#5.3.4-KI}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-11"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.3.4-KI-M2",
|
||
"policy": "R12",
|
||
"control": "5.3.4-KI",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": false,
|
||
"req_anchor": "REQ 5.3.4-KI-M2",
|
||
"impl_anchor": "IMPL 5.3.4-KI",
|
||
"condition": null,
|
||
"requirement": "The input of confidential or personal information into non-approved AI services is prohibited; the permissible data classes per service are defined.",
|
||
"link": "{{LINK:R12#5.3.4-KI}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-11"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.3.4-KI-M3",
|
||
"policy": "R12",
|
||
"control": "5.3.4-KI",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": false,
|
||
"req_anchor": "REQ 5.3.4-KI-M3",
|
||
"impl_anchor": "IMPL 5.3.4-KI",
|
||
"condition": null,
|
||
"requirement": "For approved AI services, it is clarified and contractually ensured that inputs are not used for training or passed on.",
|
||
"link": "{{LINK:R12#5.3.4-KI}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-11"
|
||
]
|
||
},
|
||
{
|
||
"id": "5.3.4-KI-S1",
|
||
"policy": "R12",
|
||
"control": "5.3.4-KI",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": false,
|
||
"req_anchor": "REQ 5.3.4-KI-S1",
|
||
"impl_anchor": "IMPL 5.3.4-KI",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Results of AI services are reviewed before business-critical use (human in the loop); the use of AI is documented and regulatory requirements (e.g. EU AI Act) are taken into account.",
|
||
"link": "{{LINK:R12#5.3.4-KI}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-11"
|
||
]
|
||
},
|
||
{
|
||
"id": "6.1.1-M1",
|
||
"policy": "R13",
|
||
"control": "6.1.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.1-M1",
|
||
"impl_anchor": "IMPL 6.1.1",
|
||
"condition": null,
|
||
"requirement": "Contractors and partners are subjected to a security risk assessment.",
|
||
"link": "{{LINK:R13#6.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-10"
|
||
]
|
||
},
|
||
{
|
||
"id": "6.1.1-M2",
|
||
"policy": "R13",
|
||
"control": "6.1.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.1-M2",
|
||
"impl_anchor": "IMPL 6.1.1",
|
||
"condition": null,
|
||
"requirement": "An appropriate level of information security is ensured through contractual agreements with contractors and partners.",
|
||
"link": "{{LINK:R13#6.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-10"
|
||
]
|
||
},
|
||
{
|
||
"id": "6.1.1-M3",
|
||
"policy": "R13",
|
||
"control": "6.1.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.1-M3",
|
||
"impl_anchor": "IMPL 6.1.1",
|
||
"condition": null,
|
||
"requirement": "Where applicable, contractual agreements with clients/customers are passed on to contractors and partners.",
|
||
"link": "{{LINK:R13#6.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.1-S1",
|
||
"policy": "R13",
|
||
"control": "6.1.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.1-S1",
|
||
"impl_anchor": "IMPL 6.1.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Contractors and partners are contractually obliged to pass on requirements for an appropriate level of information security to their subcontractors.",
|
||
"link": "{{LINK:R13#6.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-10"
|
||
]
|
||
},
|
||
{
|
||
"id": "6.1.1-S2",
|
||
"policy": "R13",
|
||
"control": "6.1.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.1-S2",
|
||
"impl_anchor": "IMPL 6.1.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Performance reports and documents from contractors and partners are reviewed.",
|
||
"link": "{{LINK:R13#6.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.1-H1",
|
||
"policy": "R13",
|
||
"control": "6.1.1",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.1-H1",
|
||
"impl_anchor": "IMPL 6.1.1-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "It is demonstrated that the supplier's level of information security is appropriate to the protection need (e.g. reviewed questionnaire/self-disclosure, attestation, certificate, supplier audit). (C, I, A)",
|
||
"link": "{{LINK:R13#6.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.1-H2",
|
||
"policy": "R13",
|
||
"control": "6.1.1",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.1-H2",
|
||
"impl_anchor": "IMPL 6.1.1-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "The degree of fulfilment of the required evidence by the supplier is documented, reviewed and monitored regularly and upon changes. (C, I, A)",
|
||
"link": "{{LINK:R13#6.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.1-H3",
|
||
"policy": "R13",
|
||
"control": "6.1.1",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.1-H3",
|
||
"impl_anchor": "IMPL 6.1.1-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "The supplier's compliance with contractual agreements is checked, documented, reviewed and monitored regularly and upon changes. (C, I, A)",
|
||
"link": "{{LINK:R13#6.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.1-V1",
|
||
"policy": "R13",
|
||
"control": "6.1.1",
|
||
"level": "vhigh",
|
||
"type": "SEHR HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.1-V1",
|
||
"impl_anchor": "IMPL 6.1.1-elev",
|
||
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
||
"requirement": "The appropriate level of information security should be demonstrated by a third-party audit (an appropriate TISAX label or similar) or an appropriate supplier audit. Without an audit, management must make a risk-based decision to continue; evidence of this decision exists. (C, I, A)",
|
||
"link": "{{LINK:R13#6.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.1-V2",
|
||
"policy": "R13",
|
||
"control": "6.1.1",
|
||
"level": "vhigh",
|
||
"type": "SEHR HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.1-V2",
|
||
"impl_anchor": "IMPL 6.1.1-elev",
|
||
"condition": "FLAG_VERY_HIGH_PROTECTION",
|
||
"requirement": "Contractual obligations towards customers regarding transparency of supply chain risks are fulfilled. (C, I, A)",
|
||
"link": "{{LINK:R13#6.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.2-M1",
|
||
"policy": "R13",
|
||
"control": "6.1.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.2-M1",
|
||
"impl_anchor": "IMPL 6.1.2",
|
||
"condition": null,
|
||
"requirement": "The confidentiality requirements are determined and met.",
|
||
"link": "{{LINK:R13#6.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-10"
|
||
]
|
||
},
|
||
{
|
||
"id": "6.1.2-M2",
|
||
"policy": "R13",
|
||
"control": "6.1.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.2-M2",
|
||
"impl_anchor": "IMPL 6.1.2",
|
||
"condition": null,
|
||
"requirement": "Requirements and procedures for applying confidentiality agreements are known to all persons who pass on information requiring protection.",
|
||
"link": "{{LINK:R13#6.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.2-M3",
|
||
"policy": "R13",
|
||
"control": "6.1.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.2-M3",
|
||
"impl_anchor": "IMPL 6.1.2",
|
||
"condition": null,
|
||
"requirement": "Valid confidentiality agreements are concluded before information requiring protection is passed on.",
|
||
"link": "{{LINK:R13#6.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.2-M4",
|
||
"policy": "R13",
|
||
"control": "6.1.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.2-M4",
|
||
"impl_anchor": "IMPL 6.1.2",
|
||
"condition": null,
|
||
"requirement": "The requirements and procedures for using confidentiality agreements and for handling information requiring protection are reviewed regularly.",
|
||
"link": "{{LINK:R13#6.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.2-S1",
|
||
"policy": "R13",
|
||
"control": "6.1.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.2-S1",
|
||
"impl_anchor": "IMPL 6.1.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Templates for confidentiality agreements are available and checked for legal applicability.",
|
||
"link": "{{LINK:R13#6.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-10"
|
||
]
|
||
},
|
||
{
|
||
"id": "6.1.2-S2",
|
||
"policy": "R13",
|
||
"control": "6.1.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.2-S2",
|
||
"impl_anchor": "IMPL 6.1.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Confidentiality agreements cover the persons/organisations involved, the type of information, the subject matter, the period of validity and the responsibilities of the obligated party.",
|
||
"link": "{{LINK:R13#6.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.2-S3",
|
||
"policy": "R13",
|
||
"control": "6.1.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.2-S3",
|
||
"impl_anchor": "IMPL 6.1.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Confidentiality agreements contain provisions for handling information requiring protection beyond the contractual relationship.",
|
||
"link": "{{LINK:R13#6.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.2-S4",
|
||
"policy": "R13",
|
||
"control": "6.1.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.2-S4",
|
||
"impl_anchor": "IMPL 6.1.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "Ways to demonstrate compliance (e.g. review by independent third parties or audit rights) are defined.",
|
||
"link": "{{LINK:R13#6.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.2-S5",
|
||
"policy": "R13",
|
||
"control": "6.1.2",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.2-S5",
|
||
"impl_anchor": "IMPL 6.1.2",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "A process for monitoring the period of validity of temporary confidentiality agreements and for timely renewal is defined and implemented.",
|
||
"link": "{{LINK:R13#6.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.3-M1",
|
||
"policy": "R13",
|
||
"control": "6.1.3",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.3-M1",
|
||
"impl_anchor": "IMPL 6.1.3",
|
||
"condition": null,
|
||
"requirement": "The IT services concerned are identified.",
|
||
"link": "{{LINK:R13#6.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-10"
|
||
]
|
||
},
|
||
{
|
||
"id": "6.1.3-M2",
|
||
"policy": "R13",
|
||
"control": "6.1.3",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.3-M2",
|
||
"impl_anchor": "IMPL 6.1.3",
|
||
"condition": null,
|
||
"requirement": "The security requirements relevant to the IT service are determined.",
|
||
"link": "{{LINK:R13#6.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.3-M3",
|
||
"policy": "R13",
|
||
"control": "6.1.3",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.3-M3",
|
||
"impl_anchor": "IMPL 6.1.3",
|
||
"condition": null,
|
||
"requirement": "The organisation responsible for implementing the requirement is defined and aware of its responsibility.",
|
||
"link": "{{LINK:R13#6.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.3-M4",
|
||
"policy": "R13",
|
||
"control": "6.1.3",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.3-M4",
|
||
"impl_anchor": "IMPL 6.1.3",
|
||
"condition": null,
|
||
"requirement": "Mechanisms for shared responsibilities are specified and implemented.",
|
||
"link": "{{LINK:R13#6.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.3-M5",
|
||
"policy": "R13",
|
||
"control": "6.1.3",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.3-M5",
|
||
"impl_anchor": "IMPL 6.1.3",
|
||
"condition": null,
|
||
"requirement": "The responsible organisation fulfils its respective responsibilities.",
|
||
"link": "{{LINK:R13#6.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.3-S1",
|
||
"policy": "R13",
|
||
"control": "6.1.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.3-S1",
|
||
"impl_anchor": "IMPL 6.1.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "For IT services, the configuration is designed, implemented and documented on the basis of the necessary security requirements.",
|
||
"link": "{{LINK:R13#6.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.3-S2",
|
||
"policy": "R13",
|
||
"control": "6.1.3",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.3-S2",
|
||
"impl_anchor": "IMPL 6.1.3",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The responsible personnel is appropriately trained.",
|
||
"link": "{{LINK:R13#6.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.3-H1",
|
||
"policy": "R13",
|
||
"control": "6.1.3",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.3-H1",
|
||
"impl_anchor": "IMPL 6.1.3-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "A list of the IT services concerned and the respective responsible IT service providers exists. (C, I, A)",
|
||
"link": "{{LINK:R13#6.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.3-H2",
|
||
"policy": "R13",
|
||
"control": "6.1.3",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.3-H2",
|
||
"impl_anchor": "IMPL 6.1.3-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "The applicability of the ISA controls has been assessed and documented. (C, I, A)",
|
||
"link": "{{LINK:R13#6.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.3-H3",
|
||
"policy": "R13",
|
||
"control": "6.1.3",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.3-H3",
|
||
"impl_anchor": "IMPL 6.1.3-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "The service configuration is included in the regular security assessments. (C, I, A)",
|
||
"link": "{{LINK:R13#6.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.3-H4",
|
||
"policy": "R13",
|
||
"control": "6.1.3",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.3-H4",
|
||
"impl_anchor": "IMPL 6.1.3-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "It is demonstrated that the IT service providers fulfil their responsibility. (C, I, A)",
|
||
"link": "{{LINK:R13#6.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "6.1.3-H5",
|
||
"policy": "R13",
|
||
"control": "6.1.3",
|
||
"level": "high",
|
||
"type": "HOCH",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 6.1.3-H5",
|
||
"impl_anchor": "IMPL 6.1.3-elev",
|
||
"condition": "FLAG_HIGH_PROTECTION",
|
||
"requirement": "The integration into local protective measures (e.g. secure authentication mechanisms) is established and documented. (C, I, A)",
|
||
"link": "{{LINK:R13#6.1.3}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "7.1.1-M1",
|
||
"policy": "R14",
|
||
"control": "7.1.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 7.1.1-M1",
|
||
"impl_anchor": "IMPL 7.1.1",
|
||
"condition": null,
|
||
"requirement": "Legal, regulatory and contractual requirements relevant to information security are determined regularly.",
|
||
"link": "{{LINK:R14#7.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-18"
|
||
]
|
||
},
|
||
{
|
||
"id": "7.1.1-M2",
|
||
"policy": "R14",
|
||
"control": "7.1.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 7.1.1-M2",
|
||
"impl_anchor": "IMPL 7.1.1",
|
||
"condition": null,
|
||
"requirement": "Policies for complying with the requirements are defined, implemented and communicated to the responsible persons.",
|
||
"link": "{{LINK:R14#7.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-18"
|
||
]
|
||
},
|
||
{
|
||
"id": "7.1.1-S1",
|
||
"policy": "R14",
|
||
"control": "7.1.1",
|
||
"level": "should",
|
||
"type": "SOLL",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 7.1.1-S1",
|
||
"impl_anchor": "IMPL 7.1.1",
|
||
"condition": "FLAG_INCLUDE_SHOULD",
|
||
"requirement": "The integrity of records in accordance with legal, regulatory and contractual requirements as well as business requirements is taken into account.",
|
||
"link": "{{LINK:R14#7.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-18"
|
||
]
|
||
},
|
||
{
|
||
"id": "7.1.2-M1",
|
||
"policy": "R14",
|
||
"control": "7.1.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 7.1.2-M1",
|
||
"impl_anchor": "IMPL 7.1.2",
|
||
"condition": null,
|
||
"requirement": "Legal and contractual information security requirements for procedures and processes when processing personal data are determined.",
|
||
"link": "{{LINK:R14#7.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-18"
|
||
]
|
||
},
|
||
{
|
||
"id": "7.1.2-M2",
|
||
"policy": "R14",
|
||
"control": "7.1.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 7.1.2-M2",
|
||
"impl_anchor": "IMPL 7.1.2",
|
||
"condition": null,
|
||
"requirement": "Provisions for complying with legal and contractual requirements for the protection of personal data are defined and known to the persons involved.",
|
||
"link": "{{LINK:R14#7.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-18"
|
||
]
|
||
},
|
||
{
|
||
"id": "7.1.2-M3",
|
||
"policy": "R14",
|
||
"control": "7.1.2",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 7.1.2-M3",
|
||
"impl_anchor": "IMPL 7.1.2",
|
||
"condition": null,
|
||
"requirement": "Processes and procedures for protecting personal data are taken into account in the information security management system.",
|
||
"link": "{{LINK:R14#7.1.2}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-18"
|
||
]
|
||
},
|
||
{
|
||
"id": "8.1.1-M1",
|
||
"policy": "P01",
|
||
"control": "8.1.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 8.1.1-M1",
|
||
"impl_anchor": "REQ 8.1.1-M1",
|
||
"condition": "FLAG_PROTOTYPE_PROTECTION",
|
||
"requirement": "Areas in which prototypes are processed or stored are protected by defined security zones and an effective perimeter.",
|
||
"implementation": "Prototype areas are designated as a dedicated security zone with access control, perimeter protection and logging.",
|
||
"link": "{{LINK:P01#8.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-20"
|
||
]
|
||
},
|
||
{
|
||
"id": "8.2.1-M1",
|
||
"policy": "P01",
|
||
"control": "8.2.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 8.2.1-M1",
|
||
"impl_anchor": "REQ 8.2.1-M1",
|
||
"condition": "FLAG_PROTOTYPE_PROTECTION",
|
||
"requirement": "Confidentiality obligations exist for prototypes; the associated information is classified and labelled.",
|
||
"implementation": "All persons involved with prototypes sign confidentiality agreements; prototypes are classified as confidential or higher.",
|
||
"link": "{{LINK:P01#8.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "8.3.1-M1",
|
||
"policy": "P01",
|
||
"control": "8.3.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 8.3.1-M1",
|
||
"impl_anchor": "REQ 8.3.1-M1",
|
||
"condition": "FLAG_PROTOTYPE_PROTECTION",
|
||
"requirement": "Transport and storage of prototypes are carried out according to documented protection requirements that ensure confidentiality and integrity.",
|
||
"implementation": "Transport and storage follow the procedure instruction VA-20: secured containers, logged handovers, access and visual protection.",
|
||
"link": "{{LINK:P01#8.3.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": [
|
||
"VA-20"
|
||
]
|
||
},
|
||
{
|
||
"id": "9.1.1-M1",
|
||
"policy": "D01",
|
||
"control": "9.1.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 9.1.1-M1",
|
||
"impl_anchor": "REQ 9.1.1-M1",
|
||
"condition": "FLAG_PERSONAL_DATA",
|
||
"requirement": "Responsibilities for data protection are appointed and the data protection organisation is documented.",
|
||
"implementation": "The role of data protection officer is appointed and integrated into the ISMS organisation; tasks and reporting paths are documented.",
|
||
"link": "{{LINK:D01#9.1.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
},
|
||
{
|
||
"id": "9.2.1-M1",
|
||
"policy": "D01",
|
||
"control": "9.2.1",
|
||
"level": "must",
|
||
"type": "MUSS",
|
||
"is_isa": true,
|
||
"req_anchor": "REQ 9.2.1-M1",
|
||
"impl_anchor": "REQ 9.2.1-M1",
|
||
"condition": "FLAG_PERSONAL_DATA",
|
||
"requirement": "Processing of personal data is lawful, purpose-bound and recorded in a record of processing activities.",
|
||
"implementation": "A record of processing activities is maintained; legal basis, purpose and deletion periods are documented for each processing activity.",
|
||
"link": "{{LINK:D01#9.2.1}}",
|
||
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
||
"verfahren": []
|
||
}
|
||
],
|
||
"verfahren": [
|
||
{
|
||
"id": "VA-01",
|
||
"title": "Incident-Response- und Meldeverfahren",
|
||
"file": "verfahren/VA-01_Incident-Response-und-Meldeverfahren.md",
|
||
"policy": "R04",
|
||
"fulfills": [
|
||
"1.6.1-M1",
|
||
"1.6.1-M2",
|
||
"1.6.2-M1",
|
||
"1.6.2-M2",
|
||
"1.6.2-S1",
|
||
"1.6.2-S2"
|
||
],
|
||
"link": "{{LINK:VA-01}}"
|
||
},
|
||
{
|
||
"id": "VA-02",
|
||
"title": "IT-Notfall- und Wiederanlaufverfahren (BCM)",
|
||
"file": "verfahren/VA-02_IT-Notfall-und-Wiederanlaufverfahren.md",
|
||
"policy": "R04",
|
||
"fulfills": [
|
||
"1.6.3-M1",
|
||
"1.6.3-S1",
|
||
"5.2.8-M1",
|
||
"5.2.8-S1"
|
||
],
|
||
"link": "{{LINK:VA-02}}"
|
||
},
|
||
{
|
||
"id": "VA-03",
|
||
"title": "Berechtigungsverfahren (Joiner/Mover/Leaver und Rezertifizierung)",
|
||
"file": "verfahren/VA-03_Berechtigungsverfahren.md",
|
||
"policy": "R08",
|
||
"fulfills": [
|
||
"4.1.1-S1",
|
||
"4.1.3-M1",
|
||
"4.2.1-M1",
|
||
"4.2.1-M2",
|
||
"4.2.1-S1"
|
||
],
|
||
"link": "{{LINK:VA-03}}"
|
||
},
|
||
{
|
||
"id": "VA-04",
|
||
"title": "Change- und Patch-Management-Verfahren",
|
||
"file": "verfahren/VA-04_Change-und-Patch-Management-Verfahren.md",
|
||
"policy": "R10",
|
||
"fulfills": [
|
||
"5.2.1-M1",
|
||
"5.2.5-M1"
|
||
],
|
||
"link": "{{LINK:VA-04}}"
|
||
},
|
||
{
|
||
"id": "VA-05",
|
||
"title": "Backup- und Restore-Verfahren",
|
||
"file": "verfahren/VA-05_Backup-und-Restore-Verfahren.md",
|
||
"policy": "R10",
|
||
"fulfills": [
|
||
"5.2.9-M1",
|
||
"5.2.9-M2",
|
||
"5.2.9-S1"
|
||
],
|
||
"link": "{{LINK:VA-05}}"
|
||
},
|
||
{
|
||
"id": "VA-06",
|
||
"title": "Schwachstellenmanagement-Verfahren",
|
||
"file": "verfahren/VA-06_Schwachstellenmanagement-Verfahren.md",
|
||
"policy": "R10",
|
||
"fulfills": [
|
||
"5.2.5-M1",
|
||
"5.2.5-S1",
|
||
"5.2.6-M1"
|
||
],
|
||
"link": "{{LINK:VA-06}}"
|
||
},
|
||
{
|
||
"id": "VA-07",
|
||
"title": "Kryptokonzept und Schlüsselverwaltung",
|
||
"file": "verfahren/VA-07_Kryptokonzept-und-Schluesselverwaltung.md",
|
||
"policy": "R09",
|
||
"fulfills": [
|
||
"5.1.1-M1",
|
||
"5.1.1-M2",
|
||
"5.1.1-S1",
|
||
"5.1.2-M1",
|
||
"5.1.2-S1"
|
||
],
|
||
"link": "{{LINK:VA-07}}"
|
||
},
|
||
{
|
||
"id": "VA-08",
|
||
"title": "Asset- und Klassifizierungsverfahren",
|
||
"file": "verfahren/VA-08_Asset-und-Klassifizierungsverfahren.md",
|
||
"policy": "R02",
|
||
"fulfills": [
|
||
"1.3.1-M1",
|
||
"1.3.1-M2",
|
||
"1.3.1-S1",
|
||
"1.3.2-M1",
|
||
"1.3.2-M2",
|
||
"1.3.2-S1"
|
||
],
|
||
"link": "{{LINK:VA-08}}"
|
||
},
|
||
{
|
||
"id": "VA-09",
|
||
"title": "Risikomanagement-Verfahren",
|
||
"file": "verfahren/VA-09_Risikomanagement-Verfahren.md",
|
||
"policy": "R03",
|
||
"fulfills": [
|
||
"1.4.1-M1",
|
||
"1.4.1-M2",
|
||
"1.4.1-M3",
|
||
"1.4.1-S1"
|
||
],
|
||
"link": "{{LINK:VA-09}}"
|
||
},
|
||
{
|
||
"id": "VA-10",
|
||
"title": "Lieferanten-Onboarding- und Bewertungsverfahren",
|
||
"file": "verfahren/VA-10_Lieferanten-Onboarding-und-Bewertung.md",
|
||
"policy": "R13",
|
||
"fulfills": [
|
||
"6.1.1-M1",
|
||
"6.1.1-M2",
|
||
"6.1.1-S1",
|
||
"6.1.2-M1",
|
||
"6.1.2-S1",
|
||
"6.1.3-M1"
|
||
],
|
||
"link": "{{LINK:VA-10}}"
|
||
},
|
||
{
|
||
"id": "VA-11",
|
||
"title": "Cloud- und KI-Freigabeverfahren",
|
||
"file": "verfahren/VA-11_Cloud-und-KI-Freigabeverfahren.md",
|
||
"policy": "R12",
|
||
"fulfills": [
|
||
"5.3.4-M1",
|
||
"5.3.4-M2",
|
||
"5.3.4-S1",
|
||
"5.3.4-KI-M1",
|
||
"5.3.4-KI-M2",
|
||
"5.3.4-KI-M3",
|
||
"5.3.4-KI-S1"
|
||
],
|
||
"link": "{{LINK:VA-11}}"
|
||
},
|
||
{
|
||
"id": "VA-12",
|
||
"title": "Awareness- und Schulungsverfahren",
|
||
"file": "verfahren/VA-12_Awareness-und-Schulungsverfahren.md",
|
||
"policy": "R05",
|
||
"fulfills": [
|
||
"2.1.3-M1",
|
||
"2.1.3-S1"
|
||
],
|
||
"link": "{{LINK:VA-12}}"
|
||
},
|
||
{
|
||
"id": "VA-13",
|
||
"title": "Logging- und Monitoring-Verfahren",
|
||
"file": "verfahren/VA-13_Logging-und-Monitoring-Verfahren.md",
|
||
"policy": "R10",
|
||
"fulfills": [
|
||
"5.2.4-M1",
|
||
"5.2.4-S1"
|
||
],
|
||
"link": "{{LINK:VA-13}}"
|
||
},
|
||
{
|
||
"id": "VA-14",
|
||
"title": "Personalsicherheit – Eignungsprüfung & sensible Tätigkeiten",
|
||
"file": "verfahren/VA-14_Personalsicherheit-Eignungspruefung.md",
|
||
"policy": "R05",
|
||
"fulfills": [
|
||
"2.1.1-M1",
|
||
"2.1.1-M2",
|
||
"2.1.1-M3",
|
||
"2.1.1-S1",
|
||
"2.1.1-S2",
|
||
"2.1.2-M1",
|
||
"2.1.2-M2",
|
||
"2.1.2-S1",
|
||
"2.1.2-S2",
|
||
"2.1.2-S3"
|
||
],
|
||
"link": "{{LINK:VA-14}}"
|
||
},
|
||
{
|
||
"id": "VA-15",
|
||
"title": "Interne Audits & Complianceprüfungen",
|
||
"file": "verfahren/VA-15_Interne-Audits-und-Compliancepruefungen.md",
|
||
"policy": "R03",
|
||
"fulfills": [
|
||
"1.5.1-M1",
|
||
"1.5.1-M2",
|
||
"1.5.1-M3",
|
||
"1.5.1-M4",
|
||
"1.5.1-M5",
|
||
"1.5.1-S1",
|
||
"1.5.2-M1",
|
||
"1.5.2-M2",
|
||
"1.5.2-S1"
|
||
],
|
||
"link": "{{LINK:VA-15}}"
|
||
},
|
||
{
|
||
"id": "VA-16",
|
||
"title": "Sichere Beschaffung, Entwicklung & Abnahme",
|
||
"file": "verfahren/VA-16_Sichere-Beschaffung-Entwicklung-und-Abnahme.md",
|
||
"policy": "R11",
|
||
"fulfills": [
|
||
"5.3.1-M1",
|
||
"5.3.1-M2",
|
||
"5.3.1-M3",
|
||
"5.3.1-M4",
|
||
"5.3.1-S1",
|
||
"5.3.1-S2",
|
||
"5.3.1-S3",
|
||
"5.3.1-S4",
|
||
"5.3.1-S5",
|
||
"5.3.1-V1",
|
||
"5.3.2-M1",
|
||
"5.3.2-S1",
|
||
"5.3.2-S2",
|
||
"5.3.2-S3",
|
||
"5.3.2-H1"
|
||
],
|
||
"link": "{{LINK:VA-16}}"
|
||
},
|
||
{
|
||
"id": "VA-17",
|
||
"title": "Zutritts- & Besuchermanagement (physisch)",
|
||
"file": "verfahren/VA-17_Zutritts-und-Besuchermanagement.md",
|
||
"policy": "R07",
|
||
"fulfills": [
|
||
"3.1.1-S1",
|
||
"3.1.1-S2",
|
||
"3.1.1-S3",
|
||
"3.1.1-S4",
|
||
"3.1.1-S5"
|
||
],
|
||
"link": "{{LINK:VA-17}}"
|
||
},
|
||
{
|
||
"id": "VA-18",
|
||
"title": "Datenschutz- & Compliance-Pflege",
|
||
"file": "verfahren/VA-18_Datenschutz-und-Compliance-Pflege.md",
|
||
"policy": "R14",
|
||
"fulfills": [
|
||
"7.1.1-M1",
|
||
"7.1.1-M2",
|
||
"7.1.1-S1",
|
||
"7.1.2-M1",
|
||
"7.1.2-M2",
|
||
"7.1.2-M3"
|
||
],
|
||
"link": "{{LINK:VA-18}}"
|
||
},
|
||
{
|
||
"id": "VA-19",
|
||
"title": "Informationssicherheit in Projekten",
|
||
"file": "verfahren/VA-19_Informationssicherheit-in-Projekten.md",
|
||
"policy": "R01",
|
||
"fulfills": [
|
||
"1.2.3-M1",
|
||
"1.2.3-S1",
|
||
"1.2.3-S2",
|
||
"1.2.3-S3",
|
||
"1.2.3-H1"
|
||
],
|
||
"link": "{{LINK:VA-19}}"
|
||
},
|
||
{
|
||
"id": "VA-20",
|
||
"title": "Prototypen-Zutritt und -Transport",
|
||
"file": "verfahren/VA-20_Prototypen-Zutritt-und-Transport.md",
|
||
"policy": "P01",
|
||
"fulfills": [
|
||
"8.1.1-M1",
|
||
"8.3.1-M1"
|
||
],
|
||
"link": "{{LINK:VA-20}}"
|
||
}
|
||
]
|
||
}
|