Files
craftvia/seed/isms-vorlagenpaket-v2-en/richtlinien/L00_Informationssicherheitsleitlinie.md
msolarczekandClaude Opus 5 c8e6f30a27
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s
Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 11:05:39 +02:00

8.8 KiB
Raw Permalink Blame History

Information Security Policy

Document information Value
Document type Policy
Scope {{ISMS_SCOPE}}
Organisation {{ORG_NAME}}
Responsible {{ROLE_ISB}}
Approved by {{ROLE_MANAGEMENT}}
Version {{DOC_VERSION}}
Date {{DOC_DATE}}
Status {{DOC_STATUS}}

1. Purpose

This information security policy describes the fundamental requirements, objectives and responsibilities of {{ORG_NAME}} for protecting information, IT systems, business processes and supporting assets. The information security requirements are defined, documented and aligned with the objectives of {{ORG_NAME}}.

The objective is to ensure an appropriate level of information security and to meet the requirements of VDA ISA 2027 in the area of information security.

2. Scope

This policy applies to the defined ISMS scope:

{{ISMS_SCOPE_DESCRIPTION}}

It applies to:

  • all employees within the scope,
  • managers,
  • external service providers, insofar as they have access to the organisation's information, systems or processes,
  • relevant IT systems, information, applications, sites and business processes within the ISMS scope.

3. Information security objectives

The policy states the objectives and the importance of information security. Through the ISMS, the organisation pursues in particular the following objectives:

  • protection of confidential information against unauthorised access,
  • ensuring the integrity of information and systems,
  • ensuring the availability of business-critical information, systems and services,
  • compliance with legal, regulatory and contractual requirements,
  • appropriate protection of customer information, personal data, trade secrets and other information requiring protection,
  • structured identification, assessment and treatment of information security risks,
  • continual improvement of information security.

4. Information security principles

Information security is based on the following principles:

4.1 Risk orientation

Information security measures are planned, implemented, reviewed and improved in a risk-oriented manner. Risks are assessed and tracked in the ISMS tool in use ({{TOOL_NAME}}) (see {{LINK:R03}}).

4.2 Appropriateness

Protective measures must be appropriate to the protection needs of the information, systems and processes. Confidentiality, integrity and availability are taken into account.

4.3 Responsibility

Information security is a shared responsibility of all employees. {{ROLE_MANAGEMENT}} holds overall responsibility for the ISMS.

4.4 Traceability

Decisions, assessments, approvals and material measures relating to information security must be documented in a traceable manner.

4.5 Continual improvement

The ISMS is reviewed regularly and adjusted where necessary. Findings from audits, incidents, risks, changes and management reviews feed into the improvement.

5. Information security requirements

{{#if FLAG_INCLUDE_SHOULD}}The information security requirements are based on the strategy of {{ORG_NAME}}; legal and contractual requirements are taken into account. {{/if}}The organisation determines and documents information security requirements on the basis of:

  • legal and regulatory requirements,
  • contractual requirements, in particular from customers and partners,
  • requirements from the VDA ISA,
  • internal business requirements,
  • results of risk analyses,
  • protection needs of information, processes and IT systems,
  • requirements from projects, changes and external IT services.

The relevant requirements in each case are taken into account in the ISMS and implemented through suitable policies, processes, technical measures and evidence.

6. Roles and responsibilities

The organisation defines roles and responsibilities for information security. These include at least:

Role Fundamental responsibility
{{ROLE_MANAGEMENT}} Overall responsibility, approval of the information security policy, provision of appropriate resources
{{ROLE_ISB}} Steering, maintenance and further development of the ISMS
Managers Implementation of the requirements within their respective area of responsibility
{{ROLE_IT_LEAD}} Implementation of technical and organisational security measures in the IT area
Asset owners / process owners Assessment and maintenance of relevant information, processes and assets in the ISMS tool
Employees Compliance with the policies and reporting of security events
External service providers Compliance with contractually agreed security requirements

The specific assignment of roles and responsibilities is maintained in the ISMS tool ({{TOOL_NAME}}) or in a supplementary role matrix (see also {{LINK:R01}}).

7. Binding nature

This policy is approved by {{ROLE_MANAGEMENT}} and is binding for all affected persons within the scope. {{#if FLAG_INCLUDE_SHOULD}}Violations of information security requirements may lead to organisational, employment-law or contractual measures. {{/if}}All employees are obliged to:

  • comply with the applicable information security policies,
  • handle information requiring protection appropriately,
  • report security events or suspected cases without delay,
  • use only approved systems, applications and services,
  • report identified vulnerabilities or risks to the responsible body.

8. Publication and communication

The information security policy is made known to the relevant persons in a suitable form; employees and affected external partners are informed about relevant changes. This can be done via:

  • publication in the ISMS tool ({{TOOL_NAME}}),
  • internal wiki or document management system,
  • onboarding process,
  • awareness training (see {{LINK:R05}}),
  • direct communication to the affected target groups.

9. Review and update

This policy is reviewed regularly, but at least:

  • {{REVIEW_CYCLE}},
  • upon material changes to the ISMS scope,
  • upon material organisational or technical changes,
  • in the event of relevant security incidents,
  • upon new or changed regulatory, legal or contractual requirements.

Changes are documented and approved by {{ROLE_MANAGEMENT}}.

10. Evidence

The evidence for the implementation of this policy is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).

Further topic-specific security policies (R01–R14) are established and coordinated with one another.

  • Technical security baseline: {{LINK:BASELINE}}
  • ISA mapping matrix: {{LINK:ISA_MAPPING}}
  • Evidence register: {{LINK:NACHWEISREGISTER}}
  • ISMS organisation and roles: {{LINK:R01}}
  • All thematic policies: {{LINK:R01}} … {{LINK:R14}}

{{#if FLAG_FW_ISO27001}}

Annex A — Information security policy, objectives and communication

Requirement reference: ISO/IEC 27001 5.2, 6.2, 7.4, A.5.1

Requirement

  • [ISO 5.2] An information security policy is established that fits the organisation, sets objectives, commits to meeting requirements and to continual improvement, and is communicated and available.
  • [ISO 6.2] Information security objectives are established for relevant functions and levels, and their achievement is planned.
  • [ISO 7.4] The internal and external communications relevant to the ISMS are determined.
  • [ISO A.5.1] The information security policy and topic-specific policies are defined, approved by management, published, communicated, acknowledged and reviewed at planned intervals.

Implementation at {{ORG_NAME}}

This policy is approved by {{ROLE_MANAGEMENT}}, published in {{TOOL_NAME}} and made known to all staff and relevant third parties; acknowledgement is recorded per version. It is reviewed at least {{POLICY_REVIEW_CYCLE}} and upon significant change (BL-GOV-03). The thematic policies and the procedures elaborate it and follow the same approval and review cycle. The information security objectives are stated in measurable terms and held in {{TOOL_NAME}} with target value, responsible role and due date; their achievement is evaluated {{MGMT_REVIEW_CYCLE}}. For internal and external communication on information security it is defined what is communicated, when, with whom and by whom; the central point of contact is {{ROLE_ISB}}.

{{/if}}