Files
craftvia/seed/isms-vorlagenpaket-v2-en/richtlinien/R11_Sichere-Systembeschaffung-und-Entwicklung.md
msolarczekandClaude Opus 5 c8e6f30a27
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s
Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 11:05:39 +02:00

9.6 KiB

Policy Secure System Procurement and Development

Document information Value
Document type Policy
Scope {{ISMS_SCOPE}}
Organisation {{ORG_NAME}}
Responsible {{ROLE_IT_LEAD}}
Approved by {{ROLE_MANAGEMENT}}
Version {{DOC_VERSION}}
Date {{DOC_DATE}}
Status {{DOC_STATUS}}

1. Purpose

This policy governs information security in procurement and development, requirements for network services as well as return and secure deletion. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.

2. Scope

This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).

3. Requirements and implementation

Structure per section: Requirement (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and Implementation at {{ORG_NAME}} (consolidated, to be adjusted where necessary).

3.1 Security in procurement and development

Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 5.3.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.4, A.8.25, A.8.26, A.8.27, A.8.28, A.8.29, A.8.30, A.8.33{{/if}}

Requirement

{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}

  • [MUST] The information security requirements associated with the design and development of an IT service are determined and taken into account.
  • [MUST] The information security requirements associated with the procurement or extension of IT services and components are determined and taken into account.
  • [MUST] Information security requirements in connection with changes to developed IT services are taken into account.
  • [MUST] System acceptance tests are carried out taking the information security requirements into account. {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] Requirement specifications are created; the relevant aspects are taken into account. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] Requirement specifications are checked against the information security requirements. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] The IT service is checked for compliance with the specifications before production use. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] The use of production data for test purposes is avoided as far as possible (anonymisation/pseudonymisation where applicable); the relevant aspects are taken into account. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] Test systems receive protective measures comparable to the production environment when production data is used for testing. {{/if}} {{#if FLAG_VERY_HIGH_PROTECTION}}
  • [VERY HIGH] The security of purpose-built or substantially adapted software is tested upon commissioning, upon substantial changes or regularly (e.g. penetration test). (C, I, A) {{/if}} {{/if}}

{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}

  • [ISO A.8.4] Read and write access to source code, development tools and software libraries is appropriately managed.
  • [ISO A.8.25] Rules for a secure development life cycle of software and systems are established and applied.
  • [ISO A.8.26] Information security requirements are identified, specified and taken into account when developing or acquiring applications.
  • [ISO A.8.27] Principles for engineering secure systems are established, documented and applied.
  • [ISO A.8.28] Secure coding principles are applied to software development.
  • [ISO A.8.29] Security testing is integrated into the development and acceptance process.
  • [ISO A.8.30] Outsourced system development is directed, monitored and reviewed.
  • [ISO A.8.33] Test information is selected, protected and managed with care. {{/if}}

Implementation at {{ORG_NAME}}

Information security requirements are an integral part of the design, procurement, extension and modification of IT services (security by design); requirement specification, review and acceptance tests under security aspects are carried out following the procedure Secure Procurement/Development & Acceptance ({{LINK:VA-16}}); production deployment only after review in {{TOOL_TICKET}}. Production data in tests is avoided/anonymised, and test systems are appropriately protected.{{#if FLAG_DEV_INHOUSE}} For in-house development, secure coding requirements apply with code reviews and automated security tests (SAST/dependency scan) in accordance with {{LINK:VA-16}}.{{/if}}

{{#if FLAG_ELEVATED_PROTECTION}}

{{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, the security of purpose-built or substantially adapted software is tested upon commissioning, upon substantial changes or regularly (penetration test).{{/if}} {{/if}}

3.2 Requirements for network services

Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 5.3.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.21{{/if}}

Requirement

{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}

  • [MUST] Requirements for the information security of network services are determined and met. {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] A procedure for securing and using network services is defined and implemented. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] The requirements are agreed in the form of SLAs. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] Appropriate redundancy solutions are implemented. {{/if}} {{#if FLAG_HIGH_PROTECTION}}
  • [HIGH] Procedures for monitoring the quality of network traffic (e.g. traffic flow analyses, availability measurements) are defined and carried out. (A) {{/if}} {{/if}}

{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}

  • [ISO A.8.21] Security mechanisms, service levels and requirements for network services are identified, implemented and monitored. {{/if}}

Implementation at {{ORG_NAME}}

For the network services used (internal/external), security requirements are determined, agreed in SLAs and implemented via a procedure; appropriate redundancies are in place.

{{#if FLAG_ELEVATED_PROTECTION}}

Where the protection need is high, procedures for monitoring network traffic quality (traffic flow analyses, availability measurements) are defined and carried out. {{/if}}

3.3 Return and secure deletion

Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 5.3.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.11, A.7.14, A.8.10{{/if}}

Requirement

{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}

{{#if FLAG_INCLUDE_SHOULD}}

  • [SHOULD] A description of the termination process is in place, adapted to changes and regulated contractually. {{/if}} {{/if}}

{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}

  • [ISO A.5.11] Personnel and external users return all assets in their possession upon termination of employment or contract.
  • [ISO A.7.14] Equipment containing storage media is securely sanitised before disposal or re-use.
  • [ISO A.8.10] Information stored in systems and on media is deleted when no longer required. {{/if}}

Implementation at {{ORG_NAME}}

Return and secure deletion/destruction of information and assets (upon end of contract, device decommissioning) are regulated according to BL-DEL-01, agreed contractually, adapted to changes and evidenced (deletion log).

4. Binding nature

This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_IT_LEAD}}.

5. Roles and responsibilities

Role Responsibility in this policy
{{ROLE_IT_LEAD}} Procurement/development
{{ROLE_ISB}} Security requirements

6. Review and update

This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_IT_LEAD}} and approved by {{ROLE_MANAGEMENT}}.

7. Evidence

The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).

  • Technical security baseline: {{LINK:BASELINE}}
  • ISA mapping matrix: {{LINK:ISA_MAPPING}}
  • Evidence register: {{LINK:NACHWEISREGISTER}}
  • Further: {{LINK:R02}}, {{LINK:R10}}, {{LINK:R12}}