Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
3.4 KiB
3.4 KiB
Personnel Security – Suitability Check & Sensitive Activities
| Document information | Value |
|---|---|
| Document type | Procedure instruction (VA-14) |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Process owner | {{ROLE_HR_LEAD}} |
| Approved by | {{ROLE_ISB}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
1. Purpose
This procedure governs the determination of sensitive activities, the suitability and identity check upon hiring as well as the handling of violations of information security and confidentiality obligations. It operationalises the associated policy ({{LINK:R05}}).
2. Scope
Applies within the ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}) for all hiring, change and leaving processes.
3. Trigger
Hiring, change to a sensitive position, suspicion of a violation, regular review.
4. Inputs
- Register of sensitive activities ({{LINK:REG-SENS-ROLES}})
- Job descriptions with security requirements
- HR notification; legal framework (data protection/co-determination)
5. Process
- Determine sensitive activity areas/roles in the register of sensitive activities ({{LINK:REG-SENS-ROLES}}) and define the required depth of checking per role.
- Record requirements for positions in job descriptions and ensure their fulfilment.
- Upon hiring, verify identity; check personal suitability within the legally permissible scope (job interview).
- For sensitive roles, carry out extended checks (references, criminal record certificate) within the legally permissible scope.
- Handle violations of information security/confidentiality obligations following a documented procedure; evidence in the personnel file.
- Review sensitive roles and depth of checking regularly ({{REVIEW_CYCLE}}).
6. RACI
| # | Step | R (Execution) | A (Accountable) | C (Consulted) | I (Informed) |
|---|---|---|---|---|---|
| 1 | Determine sensitive activities & depth of checking | {{ROLE_ISB}} | {{ROLE_HR_LEAD}} | Business unit | - |
| 2 | Requirements in job descriptions | {{ROLE_HR_LEAD}} | {{ROLE_HR_LEAD}} | Business unit | - |
| 3 | Verify identity / check suitability | {{ROLE_HR_LEAD}} | {{ROLE_HR_LEAD}} | {{ROLE_ISB}} | - |
| 4 | Extended checks (sensitive roles) | {{ROLE_HR_LEAD}} | {{ROLE_HR_LEAD}} | {{ROLE_ISB}} | - |
| 5 | Handling of violations | {{ROLE_HR_LEAD}} | {{ROLE_MANAGEMENT}} | {{ROLE_ISB}} | - |
| 6 | Regular review | {{ROLE_ISB}} | {{ROLE_ISB}} | {{ROLE_HR_LEAD}} | - |
7. Result & evidence
Maintained register of sensitive activities; documented suitability/verification evidence in the personnel file; documented violation cases. Evidence is referenced in the central evidence register ({{LINK:NACHWEISREGISTER}}).
8. Key performance indicators (KPI)
- Share of sensitive roles with documented depth of checking
- On-time identity/suitability checks
- Open violation cases
9. Related documents
- Associated policy: {{LINK:R05}}
- Register: {{LINK:REG-SENS-ROLES}}
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}