Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
26 KiB
Policy Operational Security
| Document information | Value |
|---|---|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_IT_LEAD}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
1. Purpose
This policy governs secure IT operations: change, environment separation, malware protection, logging, vulnerabilities, technical review, network security as well as data backup. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
3. Requirements and implementation
Structure per section: Requirement (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and Implementation at {{ORG_NAME}} (consolidated, to be adjusted where necessary).
3.1 Change management (change)
Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 5.2.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.9, A.8.32{{/if}}
Requirement
{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}
- [MUST] Information security requirements for changes to the organisation, business processes and IT systems are determined and met. {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] A formal approval procedure is established. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] The possible effects of changes on information security are assessed. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Changes with an effect on information security are planned and tested. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Fallback procedures in the event of errors are taken into account. {{/if}} {{#if FLAG_HIGH_PROTECTION}}
- [HIGH] Compliance with the information security requirements is verified during and after the changes. (C, I, A) {{/if}} {{/if}}
{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}
- [ISO A.8.9] Configurations of hardware, software, services and networks are established, documented, implemented, monitored and reviewed.
- [ISO A.8.32] Changes to information processing facilities and systems are subject to change management. {{/if}}
Implementation at {{ORG_NAME}}
Changes go through a formal change procedure (see {{LINK:VA-04}}) with request, impact/risk assessment, planning, testing, approval, rollback plan and documentation in {{TOOL_TICKET}} (BL-OPS-09); information security requirements are determined and met.
{{#if FLAG_ELEVATED_PROTECTION}}
Where the protection need is high, compliance with the information security requirements is verified during and after the change. {{/if}}
3.2 Separation of development, test and production systems
Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 5.2.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.31{{/if}}
Requirement
{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}
- [MUST] The IT systems have been subjected to a risk assessment to determine the need to separate them into development, test and production systems.
- [MUST] A segmentation is implemented on the basis of the results of the risk analysis. {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] The requirements for development and test environments are determined and met; the relevant aspects are taken into account. {{/if}} {{/if}}
{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}
- [ISO A.8.31] Development, test and production environments are separated and protected. {{/if}}
Implementation at {{ORG_NAME}}
On the basis of a risk assessment, development, test and production are operated separately and segmented; requirements for development/test environments are determined and met, and production data is used there only in anonymised/pseudonymised form.
3.3 Protection against malware
Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 5.2.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.7, A.8.23{{/if}}
Requirement
{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}
- [MUST] Requirements for protection against malware are determined.
- [MUST] Technical and organisational measures for protection against malware are defined and implemented. {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Unnecessary network services are deactivated. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Access to network services is limited to what is necessary through appropriate protective measures. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Protective software against malware is installed and updated automatically at regular intervals (e.g. virus scanner). {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Received files and software are automatically checked for malware before execution (on-access scan). {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] The entire data stock of all systems is checked for malware regularly. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Data transmitted via central gateways (e.g. email, internet, external networks) is automatically checked by protective software. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Measures preventing protective software from being deactivated or modified by users are defined and implemented. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] For IT systems without protective software, alternative measures are implemented (e.g. special resilience, few services, no active users, network isolation). {{/if}} {{/if}}
{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}
- [ISO A.8.7] Protection against malware is implemented and supported by appropriate user awareness.
- [ISO A.8.23] Access to external websites is managed to reduce exposure to malicious content. {{/if}}
Implementation at {{ORG_NAME}}
Malware protection is implemented via {{TECH_MALWARE}} on all endpoints and servers (BL-OPS-03); signatures/engines update themselves {{MALWARE_UPDATE}}, on-access and regular full scans as well as gateway checks (email/internet) are active. Unnecessary network services are deactivated, access is limited, and deactivating the protective software is prevented; for systems without protective software, alternative measures apply (isolation).
3.4 Logging and evaluation
Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 5.2.4{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.15, A.8.16{{/if}}
Requirement
{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}
- [MUST] Information security requirements for handling event logs are determined and met.
- [MUST] Security-relevant requirements for logging the activities of administrators and users are determined and met.
- [MUST] The IT systems used are assessed with regard to the need for logging.
- [MUST] When external IT services are used, information on the monitoring options is obtained and taken into account in the assessment.
- [MUST] Event logs are checked regularly for policy violations and conspicuous problems, in compliance with the permissible legal and organisational requirements. {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] A procedure for escalating relevant events to the responsible body is defined and established. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Event logs (content and metadata) are protected against modification (e.g. by a dedicated environment). {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Appropriate monitoring and recording of all information-security-relevant actions in the network is established. {{/if}} {{#if FLAG_HIGH_PROTECTION}}
- [HIGH] Security-relevant requirements for handling event logs, e.g. contractual requirements, are determined and implemented. (C, I, A) {{/if}} {{#if FLAG_HIGH_PROTECTION}}
- [HIGH] Events relating to the establishment and termination of remote access sessions (e.g. remote maintenance) are logged. (C, I, A) {{/if}} {{#if FLAG_VERY_HIGH_PROTECTION}}
- [VERY HIGH] Logging of every access to data with a very high protection need, as far as technically feasible and legally/organisationally permissible. (C, I) {{/if}} {{/if}}
{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}
- [ISO A.8.15] Logs of activities, exceptions, faults and events are produced, stored, protected and analysed.
- [ISO A.8.16] Networks, systems and applications are monitored for anomalous behaviour and potential incidents are evaluated. {{/if}}
Implementation at {{ORG_NAME}}
Security-relevant events (incl. administrator/user activities) are logged centrally via {{TECH_SIEM}} according to determined and assessed requirements and evaluated regularly for violations (BL-OPS-04); for external services, the monitoring options are taken into account. Logs are protected against tampering, retention {{LOG_RETENTION}}, and an escalation procedure is established (see {{LINK:VA-13}}).
{{#if FLAG_ELEVATED_PROTECTION}}
Where the protection need is high, additional (e.g. contractual) logging requirements are implemented and remote access sessions are logged. {{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, every access to corresponding data is logged, as far as technically/legally permissible.{{/if}} {{/if}}
3.5 Handling of vulnerabilities
Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 5.2.5{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.8{{/if}}
Requirement
{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}
- [MUST] Information about technical vulnerabilities of the IT systems used is collected (e.g. manufacturer information, system audits, CVE database).
- [MUST] Potentially affected IT systems and software are identified and the risk caused by the vulnerability is assessed.
- [MUST] Risks arising from vulnerabilities are treated. {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Appropriate patch management is defined and implemented (e.g. patch testing and installation). {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Risk-mitigating measures are implemented where necessary. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] The successful installation of patches is verified in a suitable manner. {{/if}} {{/if}}
{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}
- [ISO A.8.8] Information on technical vulnerabilities is obtained, exposure is evaluated and appropriate measures are taken. {{/if}}
Implementation at {{ORG_NAME}}
Vulnerability information is collected (manufacturer information, CVE, scans BL-OPS-02), affected systems are identified, the risk is assessed and treated on a risk basis according to BL-OPS-01 via patch/change management (see {{LINK:VA-06}}) (critical {{PATCH_SLA_CRIT}}); the successful installation is verified and tracked in {{TOOL_TICKET}}, and risk-mitigating measures apply where necessary.
3.6 Technical review of IT systems
Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 5.2.6{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.34{{/if}}
Requirement
{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}
- [MUST] Requirements for the review (audit) of IT systems or services are determined.
- [MUST] The scope of the system review is defined in good time.
- [MUST] System or service reviews are coordinated with the operators and users of the IT systems/services.
- [MUST] The results of system/service reviews are stored in a traceable manner and reported to the responsible management.
- [MUST] Measures are derived from the results and implemented within an appropriate period. {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] System and service reviews are planned taking possible security risks (e.g. disruptions) into account. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Regular system or service reviews are carried out; the relevant aspects are taken into account. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Within an appropriate period after completion of the review, a report is prepared. {{/if}} {{#if FLAG_HIGH_PROTECTION}}
- [HIGH] For critical IT systems/services, additional review requirements have been identified and are met (e.g. service-specific tests/tools and/or manual penetration tests, risk-based intervals). (A) {{/if}} {{#if FLAG_VERY_HIGH_PROTECTION}}
- [VERY HIGH] IT systems and services are scanned regularly for vulnerabilities. For systems/services that cannot be scanned, suitable protective measures are to be implemented. (C, I, A) {{/if}} {{/if}}
{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}
- [ISO A.8.34] Audit tests and similar activities on operational systems are planned and agreed to avoid disruption. {{/if}}
Implementation at {{ORG_NAME}}
Requirements and scope of technical reviews are determined and coordinated with operators/users; systems are configured according to hardening requirements (BL-OPS-07, e.g. CIS benchmarks) and reviewed on a risk basis (see {{LINK:VA-06}}). Results are stored in a traceable manner, reported to management, and measures are implemented on time.
{{#if FLAG_ELEVATED_PROTECTION}}
Where the protection need is high, additional reviews (penetration tests {{PENTEST_FREQ}}, BL-OPS-08) are carried out for critical systems. {{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, systems are scanned regularly for vulnerabilities, or systems that cannot be scanned are protected by suitable measures.{{/if}} {{/if}}
3.7 Network security
Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 5.2.7{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.20, A.8.22{{/if}}
Requirement
{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}
- [MUST] Requirements for the management and control of networks are determined and met.
- [MUST] Requirements for network segmentation are determined and met. {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Procedures for the management and control of networks are defined. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] For a risk-based network segmentation, the relevant aspects are taken into account. {{/if}} {{#if FLAG_HIGH_PROTECTION}}
- [HIGH] Extended requirements for the management and control of networks are determined and implemented. (C, I, A) {{/if}} {{/if}}
{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}
- [ISO A.8.20] Networks and network devices are secured, managed and controlled to protect information.
- [ISO A.8.22] Groups of information services, users and systems are segregated in networks. {{/if}}
Implementation at {{ORG_NAME}}
The network is segmented on a risk basis according to the protection need (BL-NET-01), access-controlled and secured externally via a firewall (default deny, BL-NET-02); management/control procedures and an up-to-date network plan/segmentation concept are maintained in the network/network services register ({{LINK:REG-NET}}).{{#if FLAG_OT_USED}} Production/OT networks are separated from office networks and specially secured.{{/if}}
{{#if FLAG_ELEVATED_PROTECTION}}
Where the protection need is high, extended requirements for network management and control are determined and implemented. {{/if}}
3.8 Data backup and recovery
Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 5.2.9{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.13{{/if}}
Requirement
{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}
- [MUST] Backup concepts exist for relevant IT systems. Appropriate protective measures for the confidentiality, integrity and availability of the backups are taken into account.
- [MUST] Recovery concepts exist for relevant IT services. {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] For each relevant IT service, a backup and recovery concept exists. Dependencies between IT services and the recovery sequence are taken into account. {{/if}} {{#if FLAG_HIGH_PROTECTION}}
- [HIGH] Backup and recovery concepts are reviewed methodically at regular intervals. (A) {{/if}} {{#if FLAG_HIGH_PROTECTION}}
- [HIGH] The fundamental recoverability is taken into account and tested (e.g. sample tests, test systems). (I, A) {{/if}} {{#if FLAG_VERY_HIGH_PROTECTION}}
- [VERY HIGH] (Additional) backups are carried out via offline procedures, immutable backups or an isolated IAM solution. (I, A) {{/if}} {{#if FLAG_VERY_HIGH_PROTECTION}}
- [VERY HIGH] Recovery procedures are tested technically and methodically at regular intervals. (I, A) {{/if}} {{#if FLAG_VERY_HIGH_PROTECTION}}
- [VERY HIGH] Geographical redundancy is taken into account in backup and recovery concepts. (A) {{/if}} {{/if}}
{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}
- [ISO A.8.13] Backup copies of information, software and systems are created in accordance with the backup concept and tested regularly. {{/if}}
Implementation at {{ORG_NAME}}
Backup and recovery concepts for relevant IT services exist (protection of confidentiality/integrity/availability, dependencies and sequence taken into account); backups are performed according to the scheme {{BACKUP_SCHEME}} via {{TECH_BACKUP}} (BL-OPS-05), retention {{BACKUP_RETENTION}}, recovery regulated and tested (see {{LINK:VA-05}}).
{{#if FLAG_ELEVATED_PROTECTION}}
Where the protection need is high, concepts are reviewed methodically and recoverability is tested. {{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, additional offline/immutable backups, methodical technical restore tests and geographical redundancy are carried out.{{/if}} {{/if}}
4. Binding nature
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_IT_LEAD}}.
5. Roles and responsibilities
| Role | Responsibility in this policy |
|---|---|
| {{ROLE_IT_LEAD}} | Secure IT operations |
| {{ROLE_ISB}} | Monitoring |
6. Review and update
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_IT_LEAD}} and approved by {{ROLE_MANAGEMENT}}.
7. Evidence
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
8. Related documents
- Associated procedures: {{LINK:VA-04}}, {{LINK:VA-05}}, {{LINK:VA-06}}, {{LINK:VA-13}}
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- Further: {{LINK:R04}}, {{LINK:R08}}, {{LINK:R11}}
{{#if FLAG_FW_ISO27001}}
3.9 Threat intelligence
Requirement reference: ISO/IEC 27001 A.5.7
Requirement
- [ISO A.5.7] Information on threats is collected and analysed to produce and use threat intelligence.
Implementation at {{ORG_NAME}}
Information on threats is obtained regularly from named sources ({{THREAT_INTEL_SOURCES}}) and evaluated by {{ROLE_IT_LEAD}} for relevance to the organisation's own systems and services. Relevant findings lead to actions in vulnerability and patch management ({{LINK:VA-06}}), to adjustments of monitoring ({{LINK:VA-13}}) or to a new risk assessment. Evaluation and resulting actions are documented in {{TOOL_TICKET}}.
{{/if}}
{{#if FLAG_FW_ISO27001}}
3.10 Documented operating procedures
Requirement reference: ISO/IEC 27001 A.5.37
Requirement
- [ISO A.5.37] Operating procedures for information processing facilities are documented and made available to the personnel concerned.
Implementation at {{ORG_NAME}}
Operating procedures for information processing facilities are documented and accessible to the personnel who carry them out. They cover commissioning and configuration, operation and monitoring, backup, handling of faults, maintenance and decommissioning. The documentation is updated through change management (BL-OPS-09) whenever changes occur and is checked for currency at least {{POLICY_REVIEW_CYCLE}}. Responsible: {{ROLE_IT_LEAD}}.
{{/if}}
{{#if FLAG_FW_ISO27001}}
3.11 Capacity management
Requirement reference: ISO/IEC 27001 A.8.6
Requirement
- [ISO A.8.6] Resources are monitored and capacity is adjusted to current and expected demand.
Implementation at {{ORG_NAME}}
The utilisation of the relevant resources — compute, memory, storage, network bandwidth, licences and staffing in IT operations — is monitored {{CAPACITY_REVIEW_FREQ}} (BL-OPS-11). Exceeded thresholds raise an alert; future demand is taken into account in projects and significant changes. Capacity constraints that affect the availability requirements are recorded and treated as a risk.
{{/if}}
{{#if FLAG_FW_ISO27001}}
3.12 Data leakage prevention
Requirement reference: ISO/IEC 27001 A.8.12
Requirement
- [ISO A.8.12] Measures to prevent data leakage are applied to systems, networks and devices that process sensitive information.
Implementation at {{ORG_NAME}}
For systems, networks and devices that process protected information, measures against unauthorised outflow are in place (BL-OPS-12); at least {{DLP_SCOPE}} are covered. The measures follow the classification ({{LINK:R02}}): rules for disclosure, control of transfer channels, restriction of removable media (BL-EP-03) as well as logging and analysis of conspicuous transfers (BL-OPS-04). Detected violations are handled as security events ({{LINK:VA-01}}); where analysis relates to individuals, co-determination rights are observed.
{{/if}}
{{#if FLAG_FW_ISO27001}}
3.13 Clock synchronisation
Requirement reference: ISO/IEC 27001 A.8.17
Requirement
- [ISO A.8.17] System clocks are synchronised to approved time sources.
Implementation at {{ORG_NAME}}
The system clocks of all logging systems are synchronised to {{NTP_SOURCES}} (BL-OPS-10). Deviations are monitored and reported. A uniform time base and time zone is a prerequisite for the analysis of logs ({{LINK:VA-13}}) and for preserving evidence in the event of an incident.
{{/if}}