Files
craftvia/seed/isms-vorlagenpaket-v2-en/richtlinien/R02_Asset-und-Klassifizierungsrichtlinie.md
msolarczekandClaude Opus 5 c8e6f30a27
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s
Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 11:05:39 +02:00

260 lines
11 KiB
Markdown

# Policy Asset and Classification Policy
| Document information | Value |
|-----------------------|------|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_IT_LEAD}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## 1. Purpose
This policy governs the identification, classification and protected handling of information assets as well as the approval of hardware and software. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
## 2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
## 3. Requirements and implementation
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
### 3.1 Identification of information assets
<!-- FW:REF-START ORIG:(ISA 1.3.1) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.3.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.9{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 1.3.1-M1 -->
- **[MUST]** The organisation's information assets and other security-relevant assets are identified and recorded.
<!-- REQ 1.3.1-M2 -->
- **[MUST]** The supporting assets that process the information assets are identified and recorded.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.3.1-S1 -->
- **[SHOULD]** A catalogue of the relevant information assets exists; the relevant aspects are taken into account.
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.9-1 -->
- **[ISO A.5.9]** An inventory of information and associated assets, including owners, is established and maintained.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 1.3.1 -->
Information assets and supporting assets are recorded in the ISMS tool ({{TOOL_NAME}}) in the asset inventory with attributes (owner, location, protection need) and maintained as a catalogue (see {{LINK:VA-08}}); additions and removals are triggered via {{TOOL_TICKET}}.
### 3.2 Classification of information assets
<!-- FW:REF-START ORIG:(ISA 1.3.2) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.3.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.12, A.5.13{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 1.3.2-M1 -->
- **[MUST]** A consistent scheme for classifying information assets with regard to the protection goal of confidentiality is in place.
<!-- REQ 1.3.2-M2 -->
- **[MUST]** The identified information assets are assessed according to the defined criteria and assigned to the classification scheme.
<!-- REQ 1.3.2-M3 -->
- **[MUST]** Requirements for handling supporting assets (e.g. labelling, use, transport, storage, return, deletion/destruction) depending on the classification are in place and implemented.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.3.2-S1 -->
- **[SHOULD]** The protection goals of integrity and availability are taken into account.
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.12-1 -->
- **[ISO A.5.12]** Information is classified according to its protection needs (confidentiality, integrity, availability).
<!-- REQ A.5.13-1 -->
- **[ISO A.5.13]** Procedures for labelling information in accordance with the classification scheme are developed and implemented.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 1.3.2 -->
A consistent four-tier classification scheme (Public / Internal / Confidential / Strictly confidential) applies for confidentiality; the classification is carried out according to defined criteria by the asset owner in the ISMS tool and also takes integrity and availability into account. Handling requirements per protection class (labelling, storage, transport, transmission BL-CRY-01/04, deletion BL-DEL-01) are defined, implemented and made known (see {{LINK:VA-08}}).
### 3.3 Use of approved external IT services/hardware
<!-- FW:REF-START ORIG:(ISA 1.3.3) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.3.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.10{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 1.3.3-M1 -->
- **[MUST]** External IT services are not used without an explicit assessment and implementation of the information security requirements; the relevant aspects are taken into account.
<!-- REQ 1.3.3-M2 -->
- **[MUST]** The external IT services are aligned with the protection need of the information assets processed.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.3.3-S1 -->
- **[SHOULD]** Requirements for procurement, commissioning and approval in connection with the use of external IT services are determined and met.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.3.3-S2 -->
- **[SHOULD]** A procedure for approval taking the protection need into account is established.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.3.3-S3 -->
- **[SHOULD]** External IT services and their approval are documented.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.3.3-S4 -->
- **[SHOULD]** It is regularly verified that only approved external IT services are used.
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.10-1 -->
- **[ISO A.5.10]** Rules for the acceptable use and handling of information and assets are defined, documented and implemented.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 1.3.3 -->
External IT services/components are assessed before use, aligned with the protection need and approved via a defined procedure; the approvals are maintained in the register of external IT/cloud/AI services ({{LINK:REG-EXT-SERVICES}}) (supplier {{LINK:VA-10}}, asset {{LINK:VA-08}}) and regularly checked for exclusive use of approved services.
### 3.4 Approval of software
<!-- FW:REF-START ORIG:(ISA 1.3.4) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.3.4{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.19{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 1.3.4-M1 -->
- **[MUST]** Software is approved before installation or use; the relevant aspects are taken into account.
<!-- REQ 1.3.4-M2 -->
- **[MUST]** The software approval also applies to special software such as maintenance tools.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.3.4-S1 -->
- **[SHOULD]** The types of software to be managed (firmware, operating systems, applications, libraries, device drivers) are determined.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.3.4-S2 -->
- **[SHOULD]** Repositories of the managed software exist.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.3.4-S3 -->
- **[SHOULD]** The software repositories are protected against unauthorised manipulation.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.3.4-S4 -->
- **[SHOULD]** The approval of software is reviewed regularly.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.3.4-S5 -->
- **[SHOULD]** Software versions and patch levels are known.
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 1.3.4-V1 -->
- **[VERY HIGH]** Additional requirements for software use (e.g. the need to control/monitor use) are determined where present. (C, I, A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.8.19-1 -->
- **[ISO A.8.19]** Procedures and measures for securely managing software installation on operational systems are implemented.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 1.3.4 -->
Software (incl. special/maintenance software) is approved before use; approved software is maintained in the software whitelist register ({{LINK:REG-SW-WHITELIST}}) with version/patch level, source/supplier ({{LINK:VA-10}}) and approval status and is linked to the asset inventory ({{LINK:VA-08}}); procurement/approval runs via {{TOOL_TICKET}}. Managed software types are determined, repositories protected against manipulation, and approvals are reviewed regularly.
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 1.3.4-elev -->
{{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, additional control/monitoring requirements for software use are determined and implemented.{{/if}}
{{/if}}
## 4. Binding nature
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_IT_LEAD}}.
## 5. Roles and responsibilities
| Role | Responsibility in this policy |
|-------|-------------------------------------|
| {{ROLE_IT_LEAD}} | Asset inventory, approval of hardware/software |
| {{ROLE_ISB}} | Classification scheme |
| Asset owner | Maintenance of individual assets |
## 6. Review and update
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_IT_LEAD}} and approved by {{ROLE_MANAGEMENT}}.
## 7. Evidence
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
## 8. Related documents
- Associated procedures: {{LINK:VA-08}}
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- Further: {{LINK:R01}}, {{LINK:R08}}, {{LINK:R11}}
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->
<!-- FW:ISO-SECTION-START -->
{{#if FLAG_FW_ISO27001}}
### 3.5 Data masking and pseudonymisation
*Requirement reference:* ISO/IEC 27001 A.8.11
**Requirement**
<!-- REQ A.8.11-1 -->
- **[ISO A.8.11]** Data masking is applied in accordance with the access control and privacy requirements.
**Implementation at {{ORG_NAME}}**
<!-- IMPL ISO-MASKIERUNG -->
Where the full information content is not required for the purpose, data is masked, pseudonymised or anonymised. This applies in particular to test, training and development environments ({{LINK:R11}}), to analyses and to displays with a restricted need for access. Extent and method follow the classification and the data protection requirements ({{LINK:R14}}); whether the link to a person may be restored, and how that is safeguarded, is governed explicitly.
{{/if}}
<!-- FW:ISO-SECTION-END -->