Files
craftvia/seed/isms-vorlagenpaket-v2-en/verfahren/VA-14_Personalsicherheit-Eignungspruefung.md
msolarczekandClaude Opus 5 c8e6f30a27
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s
Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 11:05:39 +02:00

3.4 KiB
Raw Permalink Blame History

Personnel Security – Suitability Check & Sensitive Activities

Document information Value
Document type Procedure instruction (VA-14)
Scope {{ISMS_SCOPE}}
Organisation {{ORG_NAME}}
Process owner {{ROLE_HR_LEAD}}
Approved by {{ROLE_ISB}}
Version {{DOC_VERSION}}
Date {{DOC_DATE}}
Status {{DOC_STATUS}}

1. Purpose

This procedure governs the determination of sensitive activities, the suitability and identity check upon hiring as well as the handling of violations of information security and confidentiality obligations. It operationalises the associated policy ({{LINK:R05}}).

2. Scope

Applies within the ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}) for all hiring, change and leaving processes.

3. Trigger

Hiring, change to a sensitive position, suspicion of a violation, regular review.

4. Inputs

  • Register of sensitive activities ({{LINK:REG-SENS-ROLES}})
  • Job descriptions with security requirements
  • HR notification; legal framework (data protection/co-determination)

5. Process

  1. Determine sensitive activity areas/roles in the register of sensitive activities ({{LINK:REG-SENS-ROLES}}) and define the required depth of checking per role.
  2. Record requirements for positions in job descriptions and ensure their fulfilment.
  3. Upon hiring, verify identity; check personal suitability within the legally permissible scope (job interview).
  4. For sensitive roles, carry out extended checks (references, criminal record certificate) within the legally permissible scope.
  5. Handle violations of information security/confidentiality obligations following a documented procedure; evidence in the personnel file.
  6. Review sensitive roles and depth of checking regularly ({{REVIEW_CYCLE}}).

6. RACI

# Step R (Execution) A (Accountable) C (Consulted) I (Informed)
1 Determine sensitive activities & depth of checking {{ROLE_ISB}} {{ROLE_HR_LEAD}} Business unit -
2 Requirements in job descriptions {{ROLE_HR_LEAD}} {{ROLE_HR_LEAD}} Business unit -
3 Verify identity / check suitability {{ROLE_HR_LEAD}} {{ROLE_HR_LEAD}} {{ROLE_ISB}} -
4 Extended checks (sensitive roles) {{ROLE_HR_LEAD}} {{ROLE_HR_LEAD}} {{ROLE_ISB}} -
5 Handling of violations {{ROLE_HR_LEAD}} {{ROLE_MANAGEMENT}} {{ROLE_ISB}} -
6 Regular review {{ROLE_ISB}} {{ROLE_ISB}} {{ROLE_HR_LEAD}} -

7. Result & evidence

Maintained register of sensitive activities; documented suitability/verification evidence in the personnel file; documented violation cases. Evidence is referenced in the central evidence register ({{LINK:NACHWEISREGISTER}}).

8. Key performance indicators (KPI)

  • Share of sensitive roles with documented depth of checking
  • On-time identity/suitability checks
  • Open violation cases
  • Associated policy: {{LINK:R05}}
  • Register: {{LINK:REG-SENS-ROLES}}
  • Technical security baseline: {{LINK:BASELINE}}
  • ISA mapping matrix: {{LINK:ISA_MAPPING}}