Files
craftvia/seed/isms-vorlagenpaket-v2-en/Technische-Sicherheits-Baseline.md
T
msolarczekandClaude Opus 5 c8e6f30a27
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s
Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 11:05:39 +02:00

114 lines
7.0 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Technical Security Baseline
| Document information | Value |
|-----------------------|------|
| Document type | Requirements document (baseline) |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_IT_LEAD}} |
| Approved by | {{ROLE_ISB}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## Purpose
This document defines the **concrete technical minimum parameters** of information security. It is the central point of maintenance for all measurable values (password lengths, deadlines, procedures). For exact values, the policies R01–R14 refer to the **baseline IDs** assigned here (e.g. `BL-IAM-01`) and repeat the key statement concretely in the respective implementation text.
Changes to parameters are made exclusively here and are approved by {{ROLE_ISB}}. The values are stored as adjustable defaults (variables); they correspond to the state of the art (guided, among others, by BSI IT-Grundschutz and current NIST recommendations).
## 1. Identity and access management
| ID | Parameter | Requirement |
|----|-----------|---------|
| BL-IAM-01 | Password requirements | Minimum length {{PW_MIN_LENGTH}} characters; {{PW_COMPLEXITY}}; check against known/compromised passwords; {{PW_ROTATION}} |
| BL-IAM-02 | Multi-factor authentication (MFA) | Mandatory for {{MFA_SCOPE}} |
| BL-IAM-03 | Session management | Automatic lock upon inactivity: {{SESSION_TIMEOUT}} |
| BL-IAM-04 | Account lockout | {{ACCOUNT_LOCKOUT}} |
| BL-IAM-05 | Recertification of authorisations | {{RECERT_FREQ}}; privileged rights additionally on an ad-hoc basis |
| BL-IAM-06 | Privileged/technical accounts | Separate management, individual assignment, enhanced logging; management via the central directory ({{TOOL_IAM}}) |
| BL-IAM-07 | IAM documentation location | Requests/approvals/blockings in {{TOOL_TICKET}}; account management in the central directory ({{TOOL_IAM}}) |
## 2. Cryptography and transmission
| ID | Parameter | Requirement |
|----|-----------|---------|
| BL-CRY-01 | Transport encryption | At least {{TLS_MIN}}; insecure protocols deactivated |
| BL-CRY-02 | Permissible algorithms/key lengths | {{CRYPTO_ALGO}} |
| BL-CRY-03 | Data media encryption | Full encryption of mobile devices and data media (AES-256) |
| BL-CRY-04 | Email/file exchange | Encryption of content requiring protection; secure exchange paths prescribed |
| BL-CRY-05 | Key management | Defined lifecycle (generation, distribution, storage, revocation, destruction){{#if FLAG_CRYPTO_PKI}}; PKI/certificate management established{{/if}} |
## 3. Operational security
| ID | Parameter | Requirement |
|----|-----------|---------|
| BL-OPS-01 | Patch SLA | Critical: {{PATCH_SLA_CRIT}}; high: {{PATCH_SLA_HIGH}}; standard: {{PATCH_SLA_STD}} |
| BL-OPS-02 | Vulnerability scanning | {{VULN_SCAN_FREQ}}; tracking in {{TOOL_TICKET}} |
| BL-OPS-03 | Malware protection | {{TECH_MALWARE}} on all endpoints/servers; signature/engine update {{MALWARE_UPDATE}} |
| BL-OPS-04 | Logging & retention | Central logging ({{TECH_SIEM}}); retention {{LOG_RETENTION}}; tamper-protected |
| BL-OPS-05 | Data backup | Scheme {{BACKUP_SCHEME}} via {{TECH_BACKUP}}; retention {{BACKUP_RETENTION}} |
| BL-OPS-06 | Recovery tests | {{BACKUP_TEST_FREQ}}; result documented |
| BL-OPS-07 | System hardening | Hardening requirements (e.g. CIS benchmarks) for standard systems |
| BL-OPS-08 | Technical review / penetration test | {{PENTEST_FREQ}} or risk-oriented |
| BL-OPS-09 | Change management | Request/assessment/test/approval/documentation in {{TOOL_TICKET}} |
{{#if FLAG_FW_ISO27001}}
| BL-OPS-10 | Time synchronisation | System clocks of all logging systems synchronised to {{NTP_SOURCES}}; deviations are monitored |
| BL-OPS-11 | Capacity management | Utilisation (compute, memory, bandwidth, licences) monitored {{CAPACITY_REVIEW_FREQ}}; thresholds raise an alert |
| BL-OPS-12 | Protection against data leakage | Measures against unauthorised outflow of protected information for {{DLP_SCOPE}} |
{{/if}}
## 4. Network security
| ID | Parameter | Requirement |
|----|-----------|---------|
| BL-NET-01 | Segmentation | Separation according to protection need; {{#if FLAG_OT_USED}}production/OT networks separated and specially secured; {{/if}}guest/external networks isolated |
| BL-NET-02 | Perimeter & remote access | Firewall with default deny; remote access only via {{TECH_VPN}} with MFA (BL-IAM-02) |
{{#if FLAG_FW_ISO27001}}
| BL-NET-03 | Web filtering | Access to external web content filtered (categories, known malicious sites); exceptions documented and time-limited |
{{/if}}
## 5. Endpoint and mobile use
| ID | Parameter | Requirement |
|----|-----------|---------|
| BL-EP-01 | Device management | Management via {{TECH_MDM}}; only approved devices |
| BL-EP-02 | Device encryption/remote wipe | Full encryption (BL-CRY-03); blocking/wiping upon loss via {{TECH_MDM}} |
| BL-EP-03 | Removable media | Only encrypted and approved; use controlled |
## 6. Physical security
| ID | Parameter | Requirement |
|----|-----------|---------|
| BL-PHY-01 | Security zones | Defined zones; access on a needs-oriented basis, documented, revoked when no longer needed |
| BL-PHY-02 | Access logging | Logging for areas requiring protection; visitors registered and escorted |
{{#if FLAG_FW_ISO27001}}
| BL-PHY-03 | Environmental protection and utilities | Early fire detection, protection against water, temperature/humidity monitoring in technical rooms; uninterruptible power for critical systems, tested regularly |
| BL-PHY-04 | Clear desk and screen lock | Protected documents and media locked away when unattended; automatic screen lock after {{SESSION_TIMEOUT}} |
{{/if}}
## 7. Personnel and suppliers
| ID | Parameter | Requirement |
|----|-----------|---------|
| BL-HR-01 | Awareness/training | Upon joining and thereafter at least {{REVIEW_CYCLE}}; evidence in {{TOOL_NAME}} |
| BL-SUP-01 | Supplier risk classes | Classification according to protection need and access; verification of compliance (evidence/TISAX) |
| BL-DEL-01 | Secure deletion | Deletion/destruction appropriate to the protection need (e.g. according to recognised standards); deletion evidence |
## 8. Governance and projects
| ID | Parameter | Requirement |
|----|-----------|---------|
| BL-GOV-01 | Audit/review cycle | Internal review {{REVIEW_CYCLE}}; independent review/assessment at least every 3 years or after fundamental changes |
| BL-PROJ-01 | Project classification criteria | Documented catalogue of criteria for the IS classification of projects (triggers/thresholds for ISO involvement) |
{{#if FLAG_FW_ISO27001}}
| BL-GOV-02 | Management review | Top management reviews the ISMS {{MGMT_REVIEW_CYCLE}} against a fixed agenda; decisions with owner and due date |
| BL-GOV-03 | Document control | Review cycle of the policy and thematic policies {{POLICY_REVIEW_CYCLE}}; four-eyes approval; retention of superseded versions {{RECORDS_RETENTION}} |
{{/if}}
## Change history
| Version | Date | Author | Change |
|---------|-------|-------|----------|
| {{DOC_VERSION}} | {{DOC_DATE}} | {{ROLE_IT_LEAD}} | Creation |