Files
craftvia/seed/isms-vorlagenpaket-v2-en/richtlinien/R04_Incident-Notfall-und-Kontinuitaetsrichtlinie.md
msolarczekandClaude Opus 5 c8e6f30a27
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s
Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 11:05:39 +02:00

384 lines
18 KiB
Markdown

# Policy Incident, Emergency and Continuity Policy
| Document information | Value |
|-----------------------|------|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_ISB}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## 1. Purpose
This policy governs the reporting and handling of security events, crisis management as well as emergency and continuity planning. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
## 2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
## 3. Requirements and implementation
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
### 3.1 Reporting of security events
<!-- FW:REF-START ORIG:(ISA 1.6.1) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.6.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.24, A.6.8{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 1.6.1-M1 -->
- **[MUST]** A definition of a reportable security event or observation exists and is known to employees and relevant stakeholders.
<!-- REQ 1.6.1-M2 -->
- **[MUST]** Appropriate, risk-oriented mechanisms for reporting security events are defined, implemented and known to all relevant reporters.
<!-- REQ 1.6.1-M3 -->
- **[MUST]** Appropriate channels for communicating with reporters exist.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.1-S1 -->
- **[SHOULD]** A common point of contact for event reporting exists.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.1-S2 -->
- **[SHOULD]** Different reporting channels depending on the perceived severity (real-time for serious events/emergencies as well as asynchronous mechanisms such as tickets or email) are available.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.1-S3 -->
- **[SHOULD]** Employees are obliged and trained to report relevant events.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.1-S4 -->
- **[SHOULD]** Security events can also be reported by external parties; the relevant aspects are taken into account.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.1-S5 -->
- **[SHOULD]** The mechanism and the information on how incidents are reported are accessible to all relevant reporters.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.1-S6 -->
- **[SHOULD]** A feedback procedure to the reporters is established.
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 1.6.1-V1 -->
- **[VERY HIGH]** Tests and exercises of event and observation reporting are carried out regularly. (C, I, A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.24-1 -->
- **[ISO A.5.24]** The management of information security incidents is planned and prepared (roles, processes, responsibilities).
<!-- REQ A.6.8-1 -->
- **[ISO A.6.8]** A mechanism for the timely reporting of observed or suspected information security events is provided.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 1.6.1 -->
A known definition of reportable events and a low-threshold reporting path (report button/form in {{TOOL_TICKET}} or the ISMS tool, email to {{ROLE_ISB}}, real-time channel for serious cases) are available to all employees and external parties; the reporting path is known via onboarding/awareness (BL-HR-01), and a feedback procedure is established (see {{LINK:VA-01}}).
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 1.6.1-elev -->
{{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, tests and exercises of event reporting are carried out regularly.{{/if}}
{{/if}}
### 3.2 Handling of security events
<!-- FW:REF-START ORIG:(ISA 1.6.2) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.6.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.25, A.5.26, A.5.27, A.5.28{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 1.6.2-M1 -->
- **[MUST]** Reported events are processed without undue delay.
<!-- REQ 1.6.2-M2 -->
- **[MUST]** An appropriate response to reported security events is ensured.
<!-- REQ 1.6.2-M3 -->
- **[MUST]** Lessons learned feed into continual improvement.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.2-S1 -->
- **[SHOULD]** During processing, reported events are categorised (e.g. personnel, physical, cyber), qualified (e.g. not security-relevant, observation, improvement suggestion, vulnerability, incident) and prioritised (e.g. low, medium, high, critical).
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.2-S2 -->
- **[SHOULD]** Responsibilities for handling events per category are defined and assigned.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.2-S3 -->
- **[SHOULD]** A strategy for reporting potentially criminally relevant aspects to the competent authorities, where necessary, exists. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 1.6.2-H1 -->
- **[HIGH]** Maximum response times per class, category and severity are defined. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 1.6.2-H2 -->
- **[HIGH]** Events not processed in line with their priority are escalated; the relevant aspects are taken into account. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 1.6.2-H3 -->
- **[HIGH]** Legal, regulatory and contractual reporting obligations and the associated contact information are known. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 1.6.2-H4 -->
- **[HIGH]** A communication strategy for security-relevant events exists; the relevant aspects are taken into account. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 1.6.2-H5 -->
- **[HIGH]** Procedures for responding to security incidents at suppliers are established; the relevant aspects are taken into account. (C, I, A)
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 1.6.2-V1 -->
- **[VERY HIGH]** The handling of events of different categories and priorities is tested regularly; the relevant aspects are taken into account. (A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.25-1 -->
- **[ISO A.5.25]** Information security events are assessed and a decision is taken whether they are to be categorised as incidents.
<!-- REQ A.5.26-1 -->
- **[ISO A.5.26]** Information security incidents are responded to in accordance with documented procedures.
<!-- REQ A.5.27-1 -->
- **[ISO A.5.27]** Knowledge gained from information security incidents is used to strengthen the controls.
<!-- REQ A.5.28-1 -->
- **[ISO A.5.28]** Procedures for the identification, collection, acquisition and preservation of evidence relating to incidents are established and implemented.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 1.6.2 -->
Events are categorised, qualified, prioritised, handled and documented without delay following a defined incident procedure (see {{LINK:VA-01}}) in {{TOOL_TICKET}}; responsibilities and escalation paths are assigned ({{ROLE_ISB}} coordinates, {{ROLE_IT_LEAD}} implements). Lessons learned feed into improvement; a strategy for reporting to authorities/law enforcement exists.
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 1.6.2-elev -->
Where the protection need is high, maximum response times per severity are defined, escalations for events not processed in line with their priority are regulated, reporting obligations and contacts are known, and a communication strategy as well as a procedure for supplier incidents are established. {{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, event handling is tested regularly.{{/if}}
{{/if}}
### 3.3 Crisis management
<!-- FW:REF-START ORIG:(ISA 1.6.3) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.6.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.29{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 1.6.3-M1 -->
- **[MUST]** An appropriate plan for responding to and managing crisis situations exists and the necessary resources are available.
<!-- REQ 1.6.3-M2 -->
- **[MUST]** Responsibilities and authorities for crisis management are defined, documented and assigned.
<!-- REQ 1.6.3-M3 -->
- **[MUST]** The responsible employees are defined and qualified for their task.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.3-S1 -->
- **[SHOULD]** Methods for detecting crisis situations are established; general indicators and specific foreseeable crises are identified.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.3-S2 -->
- **[SHOULD]** A procedure for triggering and/or escalating crisis management is in place.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.3-S3 -->
- **[SHOULD]** Strategic objectives and their priority in crisis situations are defined and known to relevant personnel.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.3-S4 -->
- **[SHOULD]** A crisis team is defined and approved.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.3-S5 -->
- **[SHOULD]** Crisis policies and procedures are defined and approved.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 1.6.3-S6 -->
- **[SHOULD]** The crisis planning is reviewed and updated regularly.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 1.6.3-H1 -->
- **[HIGH]** Relevant different potential crisis scenarios are identified.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 1.6.3-H2 -->
- **[HIGH]** The resources and information necessary for crisis management (e.g. communication infrastructure, availability of contact and risk information) are identified; appropriate measures to ensure availability or fallback planning are in place. (A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 1.6.3-H3 -->
- **[HIGH]** A communication strategy for crisis situations exists. (A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 1.6.3-H4 -->
- **[HIGH]** The efficiency, feasibility and appropriateness of the crisis planning are assessed regularly. (A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 1.6.3-H5 -->
- **[HIGH]** Sample-based tests of the crisis planning are carried out (e.g. simulation, tabletop exercises with key personnel). (A)
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 1.6.3-V1 -->
- **[VERY HIGH]** Crisis exercises and simulations involving all relevant persons, including decision-makers, are carried out regularly. (A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.29-1 -->
- **[ISO A.5.29]** The maintenance of information security during disruption is planned and implemented.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 1.6.3 -->
A crisis management with a plan, a defined and approved crisis team, roles, triggering/escalation, communication and decision paths as well as strategic objectives is established (triggering/recovery see {{LINK:VA-02}}); the necessary resources are available and the responsible persons are qualified. Detection methods are in place, the crisis planning is reviewed and updated regularly; the crisis team is convened by {{ROLE_MANAGEMENT}}.
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 1.6.3-elev -->
Where the protection need is high, relevant crisis scenarios are identified, the necessary resources/information and a communication strategy are ensured, and the planning is assessed regularly and tested on a sample basis (tabletop). {{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, crisis exercises involving all relevant persons including decision-makers are carried out regularly.{{/if}}
{{/if}}
### 3.4 Continuity planning for IT services
<!-- FW:REF-START ORIG:(ISA 5.2.8) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.2.8{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.30, A.8.14{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 5.2.8-M1 -->
- **[MUST]** Critical IT services are identified and the business impact is taken into account.
<!-- REQ 5.2.8-M2 -->
- **[MUST]** Requirements and responsibilities for the continuity and recovery of these IT services are known to relevant stakeholders and fulfilled.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.8-S1 -->
- **[SHOULD]** Critical IT systems are identified; the relevant aspects are taken into account.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.8-S2 -->
- **[SHOULD]** A continuity plan exists and is reviewed and updated regularly.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.2.8-S3 -->
- **[SHOULD]** The continuity planning covers at least (D)DoS attacks, successful ransomware attacks and other sabotage, system failure scenarios as well as natural disasters affecting critical IT systems.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.2.8-H1 -->
- **[HIGH]** The continuity planning contains predefined time frames (recovery time objective) for the resumption of operations. (A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.2.8-H2 -->
- **[HIGH]** Appropriate SLAs with external service providers in line with the continuity planning are in place. (A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.2.8-H3 -->
- **[HIGH]** The continuity plans include the coordination of contractually agreed communication with business partners. (A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.2.8-H4 -->
- **[HIGH]** The continuity planning is tested regularly, incl. full recovery to a known state and adherence to defined target times. (A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.2.8-H5 -->
- **[HIGH]** A backup and recovery strategy for critical IT services and information is defined and implemented. (C, I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.2.8-H6 -->
- **[HIGH]** Backups of critical IT services and information are sufficiently protected against unauthorised modification/deletion by malware. (I, A)
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.2.8-H7 -->
- **[HIGH]** Backups of critical IT services and information are sufficiently protected against unauthorised access by malware or operators. (C, I)
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 5.2.8-V1 -->
- **[VERY HIGH]** The continuity planning is coordinated with the continuity plans of relevant external service providers. (A)
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 5.2.8-V2 -->
- **[VERY HIGH]** The continuation of essential core and business functions with minimal or no loss of operational continuity is possible; the relevant aspects are taken into account.
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 5.2.8-V3 -->
- **[VERY HIGH]** The continuity planning is tested regularly. Test scenarios, results and lessons learned are recorded. (I, A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.30-1 -->
- **[ISO A.5.30]** ICT readiness is planned, implemented and tested on the basis of the business continuity objectives and requirements.
<!-- REQ A.8.14-1 -->
- **[ISO A.8.14]** Information processing facilities are implemented with sufficient redundancy to meet the availability requirements.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 5.2.8 -->
Critical IT services are recorded with their business impact in the register of critical IT services ({{LINK:REG-CRIT-SERVICES}}) (incl. BIA classification, RTO/RPO, recovery sequence); requirements and responsibilities for continuity/recovery are known and fulfilled. A continuity plan (incl. (D)DoS, ransomware, failure, natural disasters) exists, is reviewed regularly and implemented via the IT emergency procedure (see {{LINK:VA-02}}).
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 5.2.8-elev -->
Where the protection need is high, RTO/RPO, SLAs with service providers, partner communication, regular full tests as well as a protected backup/recovery strategy (immutable/isolated) are established. {{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, the planning is coordinated with external service providers, the continuation of essential functions is ensured, and tests incl. lessons learned are recorded.{{/if}}
{{/if}}
## 4. Binding nature
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_ISB}}.
## 5. Roles and responsibilities
| Role | Responsibility in this policy |
|-------|-------------------------------------|
| {{ROLE_ISB}} | Incident coordination |
| {{ROLE_IT_LEAD}} | Emergency/recovery planning |
| {{ROLE_MANAGEMENT}} | Crisis team |
## 6. Review and update
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_ISB}} and approved by {{ROLE_MANAGEMENT}}.
## 7. Evidence
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
## 8. Related documents
- Associated procedures: {{LINK:VA-01}}, {{LINK:VA-02}}
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- Further: {{LINK:R03}}, {{LINK:R10}}
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->