Files
craftvia/seed/isms-vorlagenpaket-v2-en/Nachweisregister_zentral.md
T
msolarczekandClaude Opus 5 c8e6f30a27
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s
Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 11:05:39 +02:00

48 lines
3.9 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Central Evidence Register – ISMS {{ORG_NAME}}
| Document information | Value |
|-----------------------|------|
| Document type | Evidence register (applies to all policies) |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
| Responsible | {{ROLE_ISB}} |
## Purpose
This document consolidates **all evidence** for the ISMS in one place. The individual policies do not contain evidence lists but refer to this ({{LINK:NACHWEISREGISTER}}). Registers with ongoing records (asset inventory, risk register, supplier/NDA register, awareness evidence, record of processing activities) are maintained in **{{TOOL_NAME}}**; this register refers to them.
The fine-grained mapping of evidence ↔ individual MUST/SHOULD requirement is done via `mapping.json` (hidden anchors `REQ`/`IMPL`) and is not visible in reading mode. From this, the tool generates an evidence link per requirement.
## Evidence overview
| # | Policy | Evidence | Source | Responsible | Cycle |
|---|-----------|----------|--------|----------------|--------|
| 1 | {{LINK:L00}} | Approved, versioned IS policy incl. communication record | Doc | {{ROLE_MANAGEMENT}} | {{REVIEW_CYCLE}} |
| 2 | {{LINK:R01}} | ISMS scope, role/responsibility matrix, management review | Tool/Doc | {{ROLE_ISB}} | annually |
| 3 | {{LINK:R02}} | Asset inventory & classification matrix; list of approved hardware/software | Tool | {{ROLE_IT_LEAD}} | ongoing |
| 4 | {{LINK:R03}} | Risk register & treatment plan; internal/independent review reports | Tool/Doc | {{ROLE_ISB}} | ≤ annually |
| 5 | {{LINK:R04}} | Incident records; crisis/emergency plan; recovery tests | Tool/Doc | {{ROLE_ISB}} | ongoing |
| 6 | {{LINK:R05}} | Confidentiality obligations; training/awareness evidence | Tool | {{ROLE_HR_LEAD}} | upon joining / annually |
| 7 | {{LINK:R06}} | Rule & approvals for mobile working / mobile devices | Doc/Tool | {{ROLE_ISB}} | ongoing |
| 8 | {{LINK:R07}} | Access concept, zone plan, access logs | Doc | {{ROLE_IT_LEAD}} | ongoing |
| 9 | {{LINK:R08}} | Authorisation concept & recertification evidence | Tool | {{ROLE_IT_LEAD}} | ≤ annually |
| 10 | {{LINK:R09}} | Cryptography concept, key/certificate management | Doc | {{ROLE_IT_LEAD}} | ongoing |
| 11 | {{LINK:R10}} | Change/patch/vulnerability reports, malware status, logging, backup/recovery tests | Tool/rec. | {{ROLE_IT_LEAD}} | ongoing |
| 12 | {{LINK:R11}} | Security requirements procurement/development; deletion evidence | Doc/rec. | {{ROLE_IT_LEAD}} | ongoing |
| 13 | {{LINK:R12}} | Approval list for cloud/AI services, segregation/data-flow evidence | Tool/Doc | {{ROLE_ISB}} | ongoing |
| 14 | {{LINK:R13}} | Supplier register, NDAs, delineation of responsibilities | Tool | {{ROLE_ISB}} | ongoing |
| 15 | {{LINK:R14}} | Compliance/legal register; record of processing activities | Tool | {{ROLE_DPO}} | ≤ annually |
| 16 | {{LINK:VA-22}} | Metrics sheet with targets, owners and measured values per period | Tool | {{ROLE_ISB}} | {{MGMT_REVIEW_CYCLE}} |
| 17 | {{LINK:VA-22}} | Management review minutes with inputs, decisions and due dates | Tool/Doc | {{ROLE_MANAGEMENT}} | {{MGMT_REVIEW_CYCLE}} |
| 18 | {{LINK:VA-21}} | Action register: nonconformities, root cause analysis, effectiveness review | Tool | {{ROLE_ISB}} | ongoing |
| 19 | {{LINK:R03}} | Statement of Applicability with justification, origin and implementation status | Tool/Doc | {{ROLE_ISB}} | {{RISK_REVIEW_CYCLE}} |
| 20 | {{LINK:L00}} | Read receipts of staff per approved policy version | Tool | {{ROLE_ISB}} | {{POLICY_REVIEW_CYCLE}} |
> **Wizard note:** Rows with source `Tool` are not generated as a document but link to the record in {{TOOL_NAME}}. Conditional evidence is shown/hidden based on the feature flags (e.g. row 13 only with flag `FLAG_CLOUD_USED` / `FLAG_AI_USED`, row 10 only with flag `FLAG_CRYPTO_PKI`).
## Related documents
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Information security policy: {{LINK:L00}}