Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
130 lines
5.6 KiB
Markdown
130 lines
5.6 KiB
Markdown
# Policy Compliance and Data Protection
|
|
|
|
| Document information | Value |
|
|
|-----------------------|------|
|
|
| Document type | Policy |
|
|
| Scope | {{ISMS_SCOPE}} |
|
|
| Organisation | {{ORG_NAME}} |
|
|
| Responsible | {{ROLE_ISB}} |
|
|
| Approved by | {{ROLE_MANAGEMENT}} |
|
|
| Version | {{DOC_VERSION}} |
|
|
| Date | {{DOC_DATE}} |
|
|
| Status | {{DOC_STATUS}} |
|
|
|
|
|
|
## 1. Purpose
|
|
|
|
This policy governs compliance with regulatory/contractual requirements as well as the protection of personal data. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
|
|
|
|
## 2. Scope
|
|
|
|
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
|
|
|
|
## 3. Requirements and implementation
|
|
|
|
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
|
|
|
|
### 3.1 Regulatory and contractual compliance
|
|
|
|
<!-- FW:REF-START ORIG:(ISA 7.1.1) -->
|
|
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 7.1.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.31, A.5.32, A.5.33{{/if}}
|
|
<!-- FW:REF-END -->
|
|
|
|
**Requirement**
|
|
|
|
<!-- FW:TISAX-REQ-START -->
|
|
{{#if FLAG_FW_TISAX}}
|
|
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
|
|
|
|
<!-- REQ 7.1.1-M1 -->
|
|
- **[MUST]** Legal, regulatory and contractual requirements relevant to information security are determined regularly.
|
|
<!-- REQ 7.1.1-M2 -->
|
|
- **[MUST]** Policies for complying with the requirements are defined, implemented and communicated to the responsible persons.
|
|
{{#if FLAG_INCLUDE_SHOULD}}
|
|
<!-- REQ 7.1.1-S1 -->
|
|
- **[SHOULD]** The integrity of records in accordance with legal, regulatory and contractual requirements as well as business requirements is taken into account.
|
|
{{/if}}
|
|
{{/if}}
|
|
<!-- FW:TISAX-REQ-END -->
|
|
<!-- FW:ISO-REQ-START -->
|
|
{{#if FLAG_FW_ISO27001}}
|
|
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
|
|
|
|
<!-- REQ A.5.31-1 -->
|
|
- **[ISO A.5.31]** Legal, statutory, regulatory and contractual information security requirements are identified, documented and kept up to date.
|
|
<!-- REQ A.5.32-1 -->
|
|
- **[ISO A.5.32]** Appropriate procedures to protect intellectual property rights are implemented.
|
|
<!-- REQ A.5.33-1 -->
|
|
- **[ISO A.5.33]** Records are protected against loss, destruction, falsification, unauthorised access and unauthorised release.
|
|
{{/if}}
|
|
<!-- FW:ISO-REQ-END -->
|
|
|
|
**Implementation at {{ORG_NAME}}**
|
|
|
|
<!-- IMPL 7.1.1 -->
|
|
Relevant legal, regulatory and contractual requirements are determined regularly and recorded in a compliance/legal register in the ISMS tool ({{TOOL_NAME}}); policies for compliance are defined, implemented and communicated to the responsible persons, and the integrity of records is taken into account.
|
|
|
|
{{#if FLAG_PERSONAL_DATA}}
|
|
### 3.2 Protection of personal data
|
|
|
|
<!-- FW:REF-START ORIG:(ISA 7.1.2) -->
|
|
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 7.1.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.34{{/if}}
|
|
<!-- FW:REF-END -->
|
|
|
|
**Requirement**
|
|
|
|
<!-- FW:TISAX-REQ-START -->
|
|
{{#if FLAG_FW_TISAX}}
|
|
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
|
|
|
|
<!-- REQ 7.1.2-M1 -->
|
|
- **[MUST]** Legal and contractual information security requirements for procedures and processes when processing personal data are determined.
|
|
<!-- REQ 7.1.2-M2 -->
|
|
- **[MUST]** Provisions for complying with legal and contractual requirements for the protection of personal data are defined and known to the persons involved.
|
|
<!-- REQ 7.1.2-M3 -->
|
|
- **[MUST]** Processes and procedures for protecting personal data are taken into account in the information security management system.
|
|
{{/if}}
|
|
<!-- FW:TISAX-REQ-END -->
|
|
<!-- FW:ISO-REQ-START -->
|
|
{{#if FLAG_FW_ISO27001}}
|
|
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
|
|
|
|
<!-- REQ A.5.34-1 -->
|
|
- **[ISO A.5.34]** Requirements for the protection of personally identifiable information are identified and met in accordance with applicable obligations.
|
|
{{/if}}
|
|
<!-- FW:ISO-REQ-END -->
|
|
|
|
**Implementation at {{ORG_NAME}}**
|
|
|
|
<!-- IMPL 7.1.2 -->
|
|
Legal and contractual requirements for the processing of personal data (GDPR) are determined; provisions are defined, known to those involved and taken into account in the ISMS. {{ROLE_DPO}} is involved, the record of processing activities is maintained in the ISMS tool ({{TOOL_NAME}}), and TOMs and deletion concepts (BL-DEL-01) are regulated; legal register review, deletion periods and data subject rights are processed following the data protection/compliance maintenance procedure ({{LINK:VA-18}}).
|
|
|
|
{{/if}}
|
|
## 4. Binding nature
|
|
|
|
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_ISB}}.
|
|
|
|
## 5. Roles and responsibilities
|
|
|
|
| Role | Responsibility in this policy |
|
|
|-------|-------------------------------------|
|
|
| {{ROLE_ISB}} | Compliance register |
|
|
| {{ROLE_DPO}} | Data protection |
|
|
|
|
## 6. Review and update
|
|
|
|
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_ISB}} and approved by {{ROLE_MANAGEMENT}}.
|
|
|
|
## 7. Evidence
|
|
|
|
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
|
|
|
|
## 8. Related documents
|
|
|
|
- Technical security baseline: {{LINK:BASELINE}}
|
|
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
|
|
- Evidence register: {{LINK:NACHWEISREGISTER}}
|
|
- Further: {{LINK:L00}}, {{LINK:R03}}
|
|
|
|
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->
|