Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2220 lines
63 KiB
JSON
2220 lines
63 KiB
JSON
{
|
|
"meta": {
|
|
"paket": "ISMS-Vorlagenpaket v2 — Framework-Mapping ISO/IEC 27001:2022",
|
|
"standard": "ISO/IEC 27001:2022 (Kap. 4-10 + Anhang A)",
|
|
"framework": "ISO_27001",
|
|
"version": "2.1",
|
|
"bibliothek": "gemeinsam mit dem VDA-ISA-Mapping (mapping.json) — ein Dokumentensatz, zwei Mappings",
|
|
"hinweis": "Anforderungstexte sind eigene Paraphrasen (keine woertlichen Normzitate); die Referenzen sind exakt zum Nachschlagen. Der Umsetzungstext wird ueber impl_anchor aus dem jeweiligen Richtlinienabschnitt aufgeloest und ist mit dem VDA-ISA-Mapping geteilt.",
|
|
"coverage": "27 Klausel-Anforderungen (Kap. 4-10) + 93 Anhang-A-Controls = 120 Eintraege"
|
|
},
|
|
"anforderungen": [
|
|
{
|
|
"id": "4.1-1",
|
|
"policy": "R01",
|
|
"control": "4.1",
|
|
"kind": "clause",
|
|
"title": "Understanding the organisation and its context",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 4.1-1",
|
|
"impl_anchor": "IMPL ISO-MS-KONTEXT",
|
|
"requirement": "Internal and external issues that affect the ability to achieve the ISMS objectives are determined and kept up to date.",
|
|
"link": "{{LINK:R01#ISO-MS-KONTEXT}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.2-1",
|
|
"policy": "R01",
|
|
"control": "4.2",
|
|
"kind": "clause",
|
|
"title": "Needs of interested parties",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 4.2-1",
|
|
"impl_anchor": "IMPL ISO-MS-KONTEXT",
|
|
"requirement": "The interested parties relevant to the ISMS and their information security requirements are determined.",
|
|
"link": "{{LINK:R01#ISO-MS-KONTEXT}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.3-1",
|
|
"policy": "R01",
|
|
"control": "4.3",
|
|
"kind": "clause",
|
|
"title": "Scope of the ISMS",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 4.3-1",
|
|
"impl_anchor": "IMPL ISO-MS-KONTEXT",
|
|
"requirement": "The scope of the ISMS is determined considering the issues, requirements and interfaces, and maintained as documented information.",
|
|
"link": "{{LINK:R01#ISO-MS-KONTEXT}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "4.4-1",
|
|
"policy": "R01",
|
|
"control": "4.4",
|
|
"kind": "clause",
|
|
"title": "Information security management system",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 4.4-1",
|
|
"impl_anchor": "IMPL ISO-MS-KONTEXT",
|
|
"requirement": "An ISMS is established, implemented, maintained and continually improved.",
|
|
"link": "{{LINK:R01#ISO-MS-KONTEXT}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.1-1",
|
|
"policy": "R01",
|
|
"control": "5.1",
|
|
"kind": "clause",
|
|
"title": "Leadership and commitment",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 5.1-1",
|
|
"impl_anchor": "IMPL 1.2.1",
|
|
"requirement": "Top management demonstrates leadership and commitment with respect to the ISMS.",
|
|
"link": "{{LINK:R01#1.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.2-1",
|
|
"policy": "L00",
|
|
"control": "5.2",
|
|
"kind": "clause",
|
|
"title": "Information security policy",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 5.2-1",
|
|
"impl_anchor": "IMPL ISO-LEITLINIE",
|
|
"requirement": "An information security policy is established that fits the organisation, sets objectives, commits to meeting requirements and to continual improvement, and is communicated and available.",
|
|
"link": "{{LINK:L00#ISO-LEITLINIE}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "5.3-1",
|
|
"policy": "R01",
|
|
"control": "5.3",
|
|
"kind": "clause",
|
|
"title": "Roles, responsibilities and authorities",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 5.3-1",
|
|
"impl_anchor": "IMPL 1.2.2",
|
|
"requirement": "Responsibilities and authorities for security-relevant roles are assigned and communicated.",
|
|
"link": "{{LINK:R01#1.2.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.1.1-1",
|
|
"policy": "R03",
|
|
"control": "6.1.1",
|
|
"kind": "clause",
|
|
"title": "Actions to address risks and opportunities",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 6.1.1-1",
|
|
"impl_anchor": "IMPL 1.4.1",
|
|
"requirement": "When planning the ISMS, risks and opportunities that need to be addressed are determined.",
|
|
"link": "{{LINK:R03#1.4.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-09"
|
|
]
|
|
},
|
|
{
|
|
"id": "6.1.2-1",
|
|
"policy": "R03",
|
|
"control": "6.1.2",
|
|
"kind": "clause",
|
|
"title": "Information security risk assessment",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 6.1.2-1",
|
|
"impl_anchor": "IMPL 1.4.1",
|
|
"requirement": "A risk assessment process with defined criteria is established and applied so that it is repeatable and produces comparable results.",
|
|
"link": "{{LINK:R03#1.4.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-09"
|
|
]
|
|
},
|
|
{
|
|
"id": "6.1.3-1",
|
|
"policy": "R03",
|
|
"control": "6.1.3",
|
|
"kind": "clause",
|
|
"title": "Information security risk treatment",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 6.1.3-1",
|
|
"impl_anchor": "IMPL ISO-SOA",
|
|
"requirement": "A risk treatment process is defined; necessary controls are determined and compared against Annex A in a Statement of Applicability.",
|
|
"link": "{{LINK:R03#ISO-SOA}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-09"
|
|
]
|
|
},
|
|
{
|
|
"id": "6.2-1",
|
|
"policy": "L00",
|
|
"control": "6.2",
|
|
"kind": "clause",
|
|
"title": "Information security objectives and planning",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 6.2-1",
|
|
"impl_anchor": "IMPL ISO-LEITLINIE",
|
|
"requirement": "Information security objectives are established for relevant functions and levels, and their achievement is planned.",
|
|
"link": "{{LINK:L00#ISO-LEITLINIE}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "6.3-1",
|
|
"policy": "R01",
|
|
"control": "6.3",
|
|
"kind": "clause",
|
|
"title": "Planning of changes",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 6.3-1",
|
|
"impl_anchor": "IMPL ISO-MS-CHANGE",
|
|
"requirement": "Changes to the ISMS are carried out in a planned manner.",
|
|
"link": "{{LINK:R01#ISO-MS-CHANGE}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "7.1-1",
|
|
"policy": "R01",
|
|
"control": "7.1",
|
|
"kind": "clause",
|
|
"title": "Resources",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 7.1-1",
|
|
"impl_anchor": "IMPL 1.2.2",
|
|
"requirement": "The resources needed for the ISMS are determined and provided.",
|
|
"link": "{{LINK:R01#1.2.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "7.2-1",
|
|
"policy": "R05",
|
|
"control": "7.2",
|
|
"kind": "clause",
|
|
"title": "Competence",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 7.2-1",
|
|
"impl_anchor": "IMPL 2.1.1",
|
|
"requirement": "The necessary competence is determined and ensured; corresponding evidence is retained.",
|
|
"link": "{{LINK:R05#2.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "7.3-1",
|
|
"policy": "R05",
|
|
"control": "7.3",
|
|
"kind": "clause",
|
|
"title": "Awareness",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 7.3-1",
|
|
"impl_anchor": "IMPL 2.1.3",
|
|
"requirement": "Persons under the organisation's control are aware of the policy, their contribution and the consequences of non-conformance.",
|
|
"link": "{{LINK:R05#2.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-12"
|
|
]
|
|
},
|
|
{
|
|
"id": "7.4-1",
|
|
"policy": "L00",
|
|
"control": "7.4",
|
|
"kind": "clause",
|
|
"title": "Communication",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 7.4-1",
|
|
"impl_anchor": "IMPL ISO-LEITLINIE",
|
|
"requirement": "The internal and external communications relevant to the ISMS are determined.",
|
|
"link": "{{LINK:L00#ISO-LEITLINIE}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "7.5.1-1",
|
|
"policy": "R01",
|
|
"control": "7.5.1",
|
|
"kind": "clause",
|
|
"title": "Documented information — general",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 7.5.1-1",
|
|
"impl_anchor": "IMPL ISO-MS-DOKU",
|
|
"requirement": "The ISMS includes the documented information required by the standard and that determined as necessary.",
|
|
"link": "{{LINK:R01#ISO-MS-DOKU}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "7.5.2-1",
|
|
"policy": "R01",
|
|
"control": "7.5.2",
|
|
"kind": "clause",
|
|
"title": "Creating and updating",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 7.5.2-1",
|
|
"impl_anchor": "IMPL ISO-MS-DOKU",
|
|
"requirement": "When creating and updating documented information, identification, format and medium as well as review and approval are ensured.",
|
|
"link": "{{LINK:R01#ISO-MS-DOKU}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "7.5.3-1",
|
|
"policy": "R01",
|
|
"control": "7.5.3",
|
|
"kind": "clause",
|
|
"title": "Control of documented information",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 7.5.3-1",
|
|
"impl_anchor": "IMPL ISO-MS-DOKU",
|
|
"requirement": "Documented information is controlled: availability, protection, distribution, access, retention and change control.",
|
|
"link": "{{LINK:R01#ISO-MS-DOKU}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "8.1-1",
|
|
"policy": "R03",
|
|
"control": "8.1",
|
|
"kind": "clause",
|
|
"title": "Operational planning and control",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 8.1-1",
|
|
"impl_anchor": "IMPL ISO-MS-BETRIEB",
|
|
"requirement": "The processes needed to meet the requirements are planned, implemented and controlled; planned changes are controlled.",
|
|
"link": "{{LINK:R03#ISO-MS-BETRIEB}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "8.2-1",
|
|
"policy": "R03",
|
|
"control": "8.2",
|
|
"kind": "clause",
|
|
"title": "Information security risk assessment (performance)",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 8.2-1",
|
|
"impl_anchor": "IMPL 1.4.1",
|
|
"requirement": "Risk assessments are performed at planned intervals and upon significant change, and are documented.",
|
|
"link": "{{LINK:R03#1.4.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-09"
|
|
]
|
|
},
|
|
{
|
|
"id": "8.3-1",
|
|
"policy": "R03",
|
|
"control": "8.3",
|
|
"kind": "clause",
|
|
"title": "Information security risk treatment (performance)",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 8.3-1",
|
|
"impl_anchor": "IMPL 1.4.1",
|
|
"requirement": "The risk treatment plan is implemented and the results are documented.",
|
|
"link": "{{LINK:R03#1.4.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-09"
|
|
]
|
|
},
|
|
{
|
|
"id": "9.1-1",
|
|
"policy": "R03",
|
|
"control": "9.1",
|
|
"kind": "clause",
|
|
"title": "Monitoring, measurement, analysis and evaluation",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 9.1-1",
|
|
"impl_anchor": "IMPL ISO-MS-MESSUNG",
|
|
"requirement": "The information security performance and the effectiveness of the ISMS are monitored, measured, analysed and evaluated.",
|
|
"link": "{{LINK:R03#ISO-MS-MESSUNG}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-22"
|
|
]
|
|
},
|
|
{
|
|
"id": "9.2-1",
|
|
"policy": "R03",
|
|
"control": "9.2",
|
|
"kind": "clause",
|
|
"title": "Internal audit",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 9.2-1",
|
|
"impl_anchor": "IMPL 1.5.2",
|
|
"requirement": "Internal audits are conducted at planned intervals to verify conformity and effective implementation of the ISMS.",
|
|
"link": "{{LINK:R03#1.5.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-15"
|
|
]
|
|
},
|
|
{
|
|
"id": "9.3-1",
|
|
"policy": "R03",
|
|
"control": "9.3",
|
|
"kind": "clause",
|
|
"title": "Management review",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 9.3-1",
|
|
"impl_anchor": "IMPL ISO-MS-MGMTREVIEW",
|
|
"requirement": "Top management reviews the ISMS at planned intervals.",
|
|
"link": "{{LINK:R03#ISO-MS-MGMTREVIEW}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-22"
|
|
]
|
|
},
|
|
{
|
|
"id": "10.1-1",
|
|
"policy": "R03",
|
|
"control": "10.1",
|
|
"kind": "clause",
|
|
"title": "Continual improvement",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 10.1-1",
|
|
"impl_anchor": "IMPL ISO-MS-CAPA",
|
|
"requirement": "The suitability, adequacy and effectiveness of the ISMS are continually improved.",
|
|
"link": "{{LINK:R03#ISO-MS-CAPA}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-21"
|
|
]
|
|
},
|
|
{
|
|
"id": "10.2-1",
|
|
"policy": "R03",
|
|
"control": "10.2",
|
|
"kind": "clause",
|
|
"title": "Nonconformity and corrective action",
|
|
"type": "MUSS",
|
|
"soa_relevant": false,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ 10.2-1",
|
|
"impl_anchor": "IMPL ISO-MS-CAPA",
|
|
"requirement": "In the event of nonconformity, corrections are made and corrective actions are taken to eliminate the causes.",
|
|
"link": "{{LINK:R03#ISO-MS-CAPA}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-21"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.1-1",
|
|
"policy": "L00",
|
|
"control": "A.5.1",
|
|
"kind": "control",
|
|
"title": "Policies for information security",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.1-1",
|
|
"impl_anchor": "IMPL ISO-LEITLINIE",
|
|
"requirement": "The information security policy and topic-specific policies are defined, approved by management, published, communicated, acknowledged and reviewed at planned intervals.",
|
|
"link": "{{LINK:L00#ISO-LEITLINIE}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "A.5.2-1",
|
|
"policy": "R01",
|
|
"control": "A.5.2",
|
|
"kind": "control",
|
|
"title": "Information security roles and responsibilities",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.2-1",
|
|
"impl_anchor": "IMPL 1.2.2",
|
|
"requirement": "Information security roles and responsibilities are defined and allocated.",
|
|
"link": "{{LINK:R01#1.2.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "A.5.3-1",
|
|
"policy": "R01",
|
|
"control": "A.5.3",
|
|
"kind": "control",
|
|
"title": "Segregation of duties",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.3-1",
|
|
"impl_anchor": "IMPL 1.2.2",
|
|
"requirement": "Conflicting duties and areas of responsibility are segregated to reduce unauthorised or unintentional modification and misuse.",
|
|
"link": "{{LINK:R01#1.2.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "A.5.4-1",
|
|
"policy": "R01",
|
|
"control": "A.5.4",
|
|
"kind": "control",
|
|
"title": "Management responsibilities",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.4-1",
|
|
"impl_anchor": "IMPL 1.2.1",
|
|
"requirement": "Management requires all personnel to apply information security in accordance with the established requirements.",
|
|
"link": "{{LINK:R01#1.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "A.5.5-1",
|
|
"policy": "R01",
|
|
"control": "A.5.5",
|
|
"kind": "control",
|
|
"title": "Contact with authorities",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.5-1",
|
|
"impl_anchor": "IMPL ISO-KONTAKTE",
|
|
"requirement": "Appropriate contacts with relevant authorities are established and maintained.",
|
|
"link": "{{LINK:R01#ISO-KONTAKTE}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "A.5.6-1",
|
|
"policy": "R01",
|
|
"control": "A.5.6",
|
|
"kind": "control",
|
|
"title": "Contact with special interest groups",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.6-1",
|
|
"impl_anchor": "IMPL ISO-KONTAKTE",
|
|
"requirement": "Appropriate contacts with special interest groups, professional forums and security associations are maintained.",
|
|
"link": "{{LINK:R01#ISO-KONTAKTE}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "A.5.7-1",
|
|
"policy": "R10",
|
|
"control": "A.5.7",
|
|
"kind": "control",
|
|
"title": "Threat intelligence",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.7-1",
|
|
"impl_anchor": "IMPL ISO-THREATINTEL",
|
|
"requirement": "Information on threats is collected and analysed to produce and use threat intelligence.",
|
|
"link": "{{LINK:R10#ISO-THREATINTEL}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "A.5.8-1",
|
|
"policy": "R01",
|
|
"control": "A.5.8",
|
|
"kind": "control",
|
|
"title": "Information security in project management",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.8-1",
|
|
"impl_anchor": "IMPL 1.2.3",
|
|
"requirement": "Information security is integrated into project management.",
|
|
"link": "{{LINK:R01#1.2.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-19"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.9-1",
|
|
"policy": "R02",
|
|
"control": "A.5.9",
|
|
"kind": "control",
|
|
"title": "Inventory of information and other associated assets",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.9-1",
|
|
"impl_anchor": "IMPL 1.3.1",
|
|
"requirement": "An inventory of information and associated assets, including owners, is established and maintained.",
|
|
"link": "{{LINK:R02#1.3.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-08"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.10-1",
|
|
"policy": "R02",
|
|
"control": "A.5.10",
|
|
"kind": "control",
|
|
"title": "Acceptable use of information and other associated assets",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.10-1",
|
|
"impl_anchor": "IMPL 1.3.3",
|
|
"requirement": "Rules for the acceptable use and handling of information and assets are defined, documented and implemented.",
|
|
"link": "{{LINK:R02#1.3.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-08"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.11-1",
|
|
"policy": "R11",
|
|
"control": "A.5.11",
|
|
"kind": "control",
|
|
"title": "Return of assets",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.11-1",
|
|
"impl_anchor": "IMPL 5.3.3",
|
|
"requirement": "Personnel and external users return all assets in their possession upon termination of employment or contract.",
|
|
"link": "{{LINK:R11#5.3.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-08"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.12-1",
|
|
"policy": "R02",
|
|
"control": "A.5.12",
|
|
"kind": "control",
|
|
"title": "Classification of information",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.12-1",
|
|
"impl_anchor": "IMPL 1.3.2",
|
|
"requirement": "Information is classified according to its protection needs (confidentiality, integrity, availability).",
|
|
"link": "{{LINK:R02#1.3.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-08"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.13-1",
|
|
"policy": "R02",
|
|
"control": "A.5.13",
|
|
"kind": "control",
|
|
"title": "Labelling of information",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.13-1",
|
|
"impl_anchor": "IMPL 1.3.2",
|
|
"requirement": "Procedures for labelling information in accordance with the classification scheme are developed and implemented.",
|
|
"link": "{{LINK:R02#1.3.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-08"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.14-1",
|
|
"policy": "R09",
|
|
"control": "A.5.14",
|
|
"kind": "control",
|
|
"title": "Information transfer",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.14-1",
|
|
"impl_anchor": "IMPL 5.1.2",
|
|
"requirement": "Rules, procedures and agreements for the secure transfer of information are established for all transfer channels in use.",
|
|
"link": "{{LINK:R09#5.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "A.5.15-1",
|
|
"policy": "R08",
|
|
"control": "A.5.15",
|
|
"kind": "control",
|
|
"title": "Access control",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.15-1",
|
|
"impl_anchor": "IMPL 4.2.1",
|
|
"requirement": "Rules to control physical and logical access to information and assets are established and implemented on the basis of business and information security requirements.",
|
|
"link": "{{LINK:R08#4.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-03"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.16-1",
|
|
"policy": "R08",
|
|
"control": "A.5.16",
|
|
"kind": "control",
|
|
"title": "Identity management",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.16-1",
|
|
"impl_anchor": "IMPL 4.1.1",
|
|
"requirement": "The full life cycle of identities is managed.",
|
|
"link": "{{LINK:R08#4.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-03"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.17-1",
|
|
"policy": "R08",
|
|
"control": "A.5.17",
|
|
"kind": "control",
|
|
"title": "Authentication information",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.17-1",
|
|
"impl_anchor": "IMPL 4.1.3",
|
|
"requirement": "Allocation and management of authentication information is controlled by a suitable management process.",
|
|
"link": "{{LINK:R08#4.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-03"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.18-1",
|
|
"policy": "R08",
|
|
"control": "A.5.18",
|
|
"kind": "control",
|
|
"title": "Access rights",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.18-1",
|
|
"impl_anchor": "IMPL 4.2.1",
|
|
"requirement": "Access rights are provisioned, reviewed, modified and removed in accordance with the access control policy.",
|
|
"link": "{{LINK:R08#4.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-03"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.19-1",
|
|
"policy": "R13",
|
|
"control": "A.5.19",
|
|
"kind": "control",
|
|
"title": "Information security in supplier relationships",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.19-1",
|
|
"impl_anchor": "IMPL 6.1.1",
|
|
"requirement": "Processes to manage the information security risks arising from supplier relationships are defined and implemented.",
|
|
"link": "{{LINK:R13#6.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-10"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.20-1",
|
|
"policy": "R13",
|
|
"control": "A.5.20",
|
|
"kind": "control",
|
|
"title": "Addressing information security within supplier agreements",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.20-1",
|
|
"impl_anchor": "IMPL 6.1.2",
|
|
"requirement": "Relevant information security requirements are agreed with each supplier and recorded contractually.",
|
|
"link": "{{LINK:R13#6.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-10"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.21-1",
|
|
"policy": "R13",
|
|
"control": "A.5.21",
|
|
"kind": "control",
|
|
"title": "Managing information security in the ICT supply chain",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.21-1",
|
|
"impl_anchor": "IMPL 6.1.3",
|
|
"requirement": "Processes to manage information security risks in the ICT product and service supply chain are defined and implemented.",
|
|
"link": "{{LINK:R13#6.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-10"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.22-1",
|
|
"policy": "R13",
|
|
"control": "A.5.22",
|
|
"kind": "control",
|
|
"title": "Monitoring, review and change management of supplier services",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.22-1",
|
|
"impl_anchor": "IMPL 6.1.1",
|
|
"requirement": "The information security of supplier services is monitored and reviewed regularly, and changes are managed.",
|
|
"link": "{{LINK:R13#6.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-10"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.23-1",
|
|
"policy": "R12",
|
|
"control": "A.5.23",
|
|
"kind": "control",
|
|
"title": "Information security for use of cloud services",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": "FLAG_CLOUD_USED",
|
|
"req_anchor": "REQ A.5.23-1",
|
|
"impl_anchor": "IMPL 5.3.4",
|
|
"requirement": "Processes for acquisition, use, management and exit of cloud services are established in line with the information security requirements.",
|
|
"link": "{{LINK:R12#5.3.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-11"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.24-1",
|
|
"policy": "R04",
|
|
"control": "A.5.24",
|
|
"kind": "control",
|
|
"title": "Information security incident management planning and preparation",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.24-1",
|
|
"impl_anchor": "IMPL 1.6.1",
|
|
"requirement": "The management of information security incidents is planned and prepared (roles, processes, responsibilities).",
|
|
"link": "{{LINK:R04#1.6.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-01"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.25-1",
|
|
"policy": "R04",
|
|
"control": "A.5.25",
|
|
"kind": "control",
|
|
"title": "Assessment and decision on information security events",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.25-1",
|
|
"impl_anchor": "IMPL 1.6.2",
|
|
"requirement": "Information security events are assessed and a decision is taken whether they are to be categorised as incidents.",
|
|
"link": "{{LINK:R04#1.6.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-01"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.26-1",
|
|
"policy": "R04",
|
|
"control": "A.5.26",
|
|
"kind": "control",
|
|
"title": "Response to information security incidents",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.26-1",
|
|
"impl_anchor": "IMPL 1.6.2",
|
|
"requirement": "Information security incidents are responded to in accordance with documented procedures.",
|
|
"link": "{{LINK:R04#1.6.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-01"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.27-1",
|
|
"policy": "R04",
|
|
"control": "A.5.27",
|
|
"kind": "control",
|
|
"title": "Learning from information security incidents",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.27-1",
|
|
"impl_anchor": "IMPL 1.6.2",
|
|
"requirement": "Knowledge gained from information security incidents is used to strengthen the controls.",
|
|
"link": "{{LINK:R04#1.6.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-01"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.28-1",
|
|
"policy": "R04",
|
|
"control": "A.5.28",
|
|
"kind": "control",
|
|
"title": "Collection of evidence",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.28-1",
|
|
"impl_anchor": "IMPL 1.6.2",
|
|
"requirement": "Procedures for the identification, collection, acquisition and preservation of evidence relating to incidents are established and implemented.",
|
|
"link": "{{LINK:R04#1.6.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-01"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.29-1",
|
|
"policy": "R04",
|
|
"control": "A.5.29",
|
|
"kind": "control",
|
|
"title": "Information security during disruption",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.29-1",
|
|
"impl_anchor": "IMPL 1.6.3",
|
|
"requirement": "The maintenance of information security during disruption is planned and implemented.",
|
|
"link": "{{LINK:R04#1.6.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-02"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.30-1",
|
|
"policy": "R04",
|
|
"control": "A.5.30",
|
|
"kind": "control",
|
|
"title": "ICT readiness for business continuity",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.30-1",
|
|
"impl_anchor": "IMPL 5.2.8",
|
|
"requirement": "ICT readiness is planned, implemented and tested on the basis of the business continuity objectives and requirements.",
|
|
"link": "{{LINK:R04#5.2.8}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-02"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.31-1",
|
|
"policy": "R14",
|
|
"control": "A.5.31",
|
|
"kind": "control",
|
|
"title": "Legal, statutory, regulatory and contractual requirements",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.31-1",
|
|
"impl_anchor": "IMPL 7.1.1",
|
|
"requirement": "Legal, statutory, regulatory and contractual information security requirements are identified, documented and kept up to date.",
|
|
"link": "{{LINK:R14#7.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-18"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.32-1",
|
|
"policy": "R14",
|
|
"control": "A.5.32",
|
|
"kind": "control",
|
|
"title": "Intellectual property rights",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.32-1",
|
|
"impl_anchor": "IMPL 7.1.1",
|
|
"requirement": "Appropriate procedures to protect intellectual property rights are implemented.",
|
|
"link": "{{LINK:R14#7.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-18"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.33-1",
|
|
"policy": "R14",
|
|
"control": "A.5.33",
|
|
"kind": "control",
|
|
"title": "Protection of records",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.33-1",
|
|
"impl_anchor": "IMPL 7.1.1",
|
|
"requirement": "Records are protected against loss, destruction, falsification, unauthorised access and unauthorised release.",
|
|
"link": "{{LINK:R14#7.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-18"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.34-1",
|
|
"policy": "R14",
|
|
"control": "A.5.34",
|
|
"kind": "control",
|
|
"title": "Privacy and protection of PII",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": "FLAG_PERSONAL_DATA",
|
|
"req_anchor": "REQ A.5.34-1",
|
|
"impl_anchor": "IMPL 7.1.2",
|
|
"requirement": "Requirements for the protection of personally identifiable information are identified and met in accordance with applicable obligations.",
|
|
"link": "{{LINK:R14#7.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-18"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.35-1",
|
|
"policy": "R03",
|
|
"control": "A.5.35",
|
|
"kind": "control",
|
|
"title": "Independent review of information security",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.35-1",
|
|
"impl_anchor": "IMPL 1.5.2",
|
|
"requirement": "The organisation's approach to managing information security is reviewed independently at planned intervals.",
|
|
"link": "{{LINK:R03#1.5.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-15"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.36-1",
|
|
"policy": "R03",
|
|
"control": "A.5.36",
|
|
"kind": "control",
|
|
"title": "Compliance with policies, rules and standards for information security",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.36-1",
|
|
"impl_anchor": "IMPL 1.5.1",
|
|
"requirement": "Compliance with the information security policy, topic-specific policies, rules and standards is reviewed regularly.",
|
|
"link": "{{LINK:R03#1.5.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-15"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.5.37-1",
|
|
"policy": "R10",
|
|
"control": "A.5.37",
|
|
"kind": "control",
|
|
"title": "Documented operating procedures",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.5.37-1",
|
|
"impl_anchor": "IMPL ISO-BETRIEBSABLAEUFE",
|
|
"requirement": "Operating procedures for information processing facilities are documented and made available to the personnel concerned.",
|
|
"link": "{{LINK:R10#ISO-BETRIEBSABLAEUFE}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "A.6.1-1",
|
|
"policy": "R05",
|
|
"control": "A.6.1",
|
|
"kind": "control",
|
|
"title": "Screening",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.6.1-1",
|
|
"impl_anchor": "IMPL 2.1.1",
|
|
"requirement": "Background verification of candidates is carried out appropriately to the business requirements and in accordance with the law.",
|
|
"link": "{{LINK:R05#2.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-14"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.6.2-1",
|
|
"policy": "R05",
|
|
"control": "A.6.2",
|
|
"kind": "control",
|
|
"title": "Terms and conditions of employment",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.6.2-1",
|
|
"impl_anchor": "IMPL 2.1.2",
|
|
"requirement": "The employment agreements state the responsibilities for information security.",
|
|
"link": "{{LINK:R05#2.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-14"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.6.3-1",
|
|
"policy": "R05",
|
|
"control": "A.6.3",
|
|
"kind": "control",
|
|
"title": "Information security awareness, education and training",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.6.3-1",
|
|
"impl_anchor": "IMPL 2.1.3",
|
|
"requirement": "Personnel receive appropriate awareness, education and training as well as regular updates of the relevant policies.",
|
|
"link": "{{LINK:R05#2.1.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-12"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.6.4-1",
|
|
"policy": "R05",
|
|
"control": "A.6.4",
|
|
"kind": "control",
|
|
"title": "Disciplinary process",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.6.4-1",
|
|
"impl_anchor": "IMPL ISO-DISZIPLIN",
|
|
"requirement": "A disciplinary process for information security violations is established and communicated.",
|
|
"link": "{{LINK:R05#ISO-DISZIPLIN}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "A.6.5-1",
|
|
"policy": "R05",
|
|
"control": "A.6.5",
|
|
"kind": "control",
|
|
"title": "Responsibilities after termination or change of employment",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.6.5-1",
|
|
"impl_anchor": "IMPL 2.1.2",
|
|
"requirement": "Continuing information security responsibilities after termination or change of employment are defined and enforced.",
|
|
"link": "{{LINK:R05#2.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-14"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.6.6-1",
|
|
"policy": "R05",
|
|
"control": "A.6.6",
|
|
"kind": "control",
|
|
"title": "Confidentiality or non-disclosure agreements",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.6.6-1",
|
|
"impl_anchor": "IMPL 2.1.2",
|
|
"requirement": "Confidentiality or non-disclosure agreements are identified, documented and reviewed regularly.",
|
|
"link": "{{LINK:R05#2.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-14"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.6.7-1",
|
|
"policy": "R06",
|
|
"control": "A.6.7",
|
|
"kind": "control",
|
|
"title": "Remote working",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": "FLAG_MOBILE_WORK",
|
|
"req_anchor": "REQ A.6.7-1",
|
|
"impl_anchor": "IMPL 2.1.4",
|
|
"requirement": "Security measures for working outside the organisation's premises are implemented.",
|
|
"link": "{{LINK:R06#2.1.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "A.6.8-1",
|
|
"policy": "R04",
|
|
"control": "A.6.8",
|
|
"kind": "control",
|
|
"title": "Information security event reporting",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.6.8-1",
|
|
"impl_anchor": "IMPL 1.6.1",
|
|
"requirement": "A mechanism for the timely reporting of observed or suspected information security events is provided.",
|
|
"link": "{{LINK:R04#1.6.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-01"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.7.1-1",
|
|
"policy": "R07",
|
|
"control": "A.7.1",
|
|
"kind": "control",
|
|
"title": "Physical security perimeters",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.7.1-1",
|
|
"impl_anchor": "IMPL 3.1.1",
|
|
"requirement": "Security perimeters are defined and used to protect areas containing information and assets.",
|
|
"link": "{{LINK:R07#3.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-17"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.7.2-1",
|
|
"policy": "R07",
|
|
"control": "A.7.2",
|
|
"kind": "control",
|
|
"title": "Physical entry",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.7.2-1",
|
|
"impl_anchor": "IMPL 3.1.1",
|
|
"requirement": "Secure entry controls and entry points are established to restrict access to authorised persons.",
|
|
"link": "{{LINK:R07#3.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-17"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.7.3-1",
|
|
"policy": "R07",
|
|
"control": "A.7.3",
|
|
"kind": "control",
|
|
"title": "Securing offices, rooms and facilities",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.7.3-1",
|
|
"impl_anchor": "IMPL 3.1.1",
|
|
"requirement": "Physical security for offices, rooms and facilities is designed and implemented.",
|
|
"link": "{{LINK:R07#3.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-17"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.7.4-1",
|
|
"policy": "R07",
|
|
"control": "A.7.4",
|
|
"kind": "control",
|
|
"title": "Physical security monitoring",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.7.4-1",
|
|
"impl_anchor": "IMPL 3.1.1",
|
|
"requirement": "Premises are continuously monitored for unauthorised physical access.",
|
|
"link": "{{LINK:R07#3.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-17"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.7.5-1",
|
|
"policy": "R07",
|
|
"control": "A.7.5",
|
|
"kind": "control",
|
|
"title": "Protecting against physical and environmental threats",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.7.5-1",
|
|
"impl_anchor": "IMPL ISO-PHY-UMWELT",
|
|
"requirement": "Protection against physical and environmental threats is designed and implemented.",
|
|
"link": "{{LINK:R07#ISO-PHY-UMWELT}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-17"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.7.6-1",
|
|
"policy": "R07",
|
|
"control": "A.7.6",
|
|
"kind": "control",
|
|
"title": "Working in secure areas",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.7.6-1",
|
|
"impl_anchor": "IMPL 3.1.1",
|
|
"requirement": "Measures for working in secure areas are defined and implemented.",
|
|
"link": "{{LINK:R07#3.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-17"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.7.7-1",
|
|
"policy": "R07",
|
|
"control": "A.7.7",
|
|
"kind": "control",
|
|
"title": "Clear desk and clear screen",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.7.7-1",
|
|
"impl_anchor": "IMPL ISO-PHY-CLEARDESK",
|
|
"requirement": "Rules for a clear desk and locked screens are defined and implemented.",
|
|
"link": "{{LINK:R07#ISO-PHY-CLEARDESK}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-17"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.7.8-1",
|
|
"policy": "R07",
|
|
"control": "A.7.8",
|
|
"kind": "control",
|
|
"title": "Equipment siting and protection",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.7.8-1",
|
|
"impl_anchor": "IMPL ISO-PHY-UMWELT",
|
|
"requirement": "Equipment is sited securely and protected.",
|
|
"link": "{{LINK:R07#ISO-PHY-UMWELT}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-17"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.7.9-1",
|
|
"policy": "R06",
|
|
"control": "A.7.9",
|
|
"kind": "control",
|
|
"title": "Security of assets off-premises",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": "FLAG_MOBILE_DEVICES",
|
|
"req_anchor": "REQ A.7.9-1",
|
|
"impl_anchor": "IMPL 3.1.4",
|
|
"requirement": "Assets used outside the premises are protected.",
|
|
"link": "{{LINK:R06#3.1.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "A.7.10-1",
|
|
"policy": "R06",
|
|
"control": "A.7.10",
|
|
"kind": "control",
|
|
"title": "Storage media",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.7.10-1",
|
|
"impl_anchor": "IMPL 3.1.4",
|
|
"requirement": "Storage media are protected throughout their life cycle (acquisition, use, transport, disposal) in accordance with the classification scheme.",
|
|
"link": "{{LINK:R06#3.1.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-08"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.7.11-1",
|
|
"policy": "R07",
|
|
"control": "A.7.11",
|
|
"kind": "control",
|
|
"title": "Supporting utilities",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.7.11-1",
|
|
"impl_anchor": "IMPL ISO-PHY-UMWELT",
|
|
"requirement": "Facilities are protected against failure and disruption of supporting utilities such as power and air conditioning.",
|
|
"link": "{{LINK:R07#ISO-PHY-UMWELT}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-17"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.7.12-1",
|
|
"policy": "R07",
|
|
"control": "A.7.12",
|
|
"kind": "control",
|
|
"title": "Cabling security",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.7.12-1",
|
|
"impl_anchor": "IMPL ISO-PHY-UMWELT",
|
|
"requirement": "Power and data cabling is protected against interception, interference and damage.",
|
|
"link": "{{LINK:R07#ISO-PHY-UMWELT}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-17"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.7.13-1",
|
|
"policy": "R07",
|
|
"control": "A.7.13",
|
|
"kind": "control",
|
|
"title": "Equipment maintenance",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.7.13-1",
|
|
"impl_anchor": "IMPL ISO-PHY-UMWELT",
|
|
"requirement": "Equipment is maintained properly to ensure availability and integrity.",
|
|
"link": "{{LINK:R07#ISO-PHY-UMWELT}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-04"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.7.14-1",
|
|
"policy": "R11",
|
|
"control": "A.7.14",
|
|
"kind": "control",
|
|
"title": "Secure disposal or re-use of equipment",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.7.14-1",
|
|
"impl_anchor": "IMPL 5.3.3",
|
|
"requirement": "Equipment containing storage media is securely sanitised before disposal or re-use.",
|
|
"link": "{{LINK:R11#5.3.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-08"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.1-1",
|
|
"policy": "R06",
|
|
"control": "A.8.1",
|
|
"kind": "control",
|
|
"title": "User endpoint devices",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.1-1",
|
|
"impl_anchor": "IMPL 3.1.4",
|
|
"requirement": "Information stored on, processed by or accessible via user endpoint devices is protected.",
|
|
"link": "{{LINK:R06#3.1.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "A.8.2-1",
|
|
"policy": "R08",
|
|
"control": "A.8.2",
|
|
"kind": "control",
|
|
"title": "Privileged access rights",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.2-1",
|
|
"impl_anchor": "IMPL 4.2.1",
|
|
"requirement": "The allocation and use of privileged access rights is restricted and closely managed.",
|
|
"link": "{{LINK:R08#4.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-03"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.3-1",
|
|
"policy": "R08",
|
|
"control": "A.8.3",
|
|
"kind": "control",
|
|
"title": "Information access restriction",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.3-1",
|
|
"impl_anchor": "IMPL 4.2.1",
|
|
"requirement": "Access to information and application functions is restricted in accordance with the access control policy.",
|
|
"link": "{{LINK:R08#4.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-03"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.4-1",
|
|
"policy": "R11",
|
|
"control": "A.8.4",
|
|
"kind": "control",
|
|
"title": "Access to source code",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": "FLAG_DEV_INHOUSE",
|
|
"req_anchor": "REQ A.8.4-1",
|
|
"impl_anchor": "IMPL 5.3.1",
|
|
"requirement": "Read and write access to source code, development tools and software libraries is appropriately managed.",
|
|
"link": "{{LINK:R11#5.3.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-16"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.5-1",
|
|
"policy": "R08",
|
|
"control": "A.8.5",
|
|
"kind": "control",
|
|
"title": "Secure authentication",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.5-1",
|
|
"impl_anchor": "IMPL 4.1.2",
|
|
"requirement": "Secure authentication technologies and procedures are used on the basis of the access restrictions and the access control policy.",
|
|
"link": "{{LINK:R08#4.1.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-03"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.6-1",
|
|
"policy": "R10",
|
|
"control": "A.8.6",
|
|
"kind": "control",
|
|
"title": "Capacity management",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.6-1",
|
|
"impl_anchor": "IMPL ISO-KAPAZITAET",
|
|
"requirement": "Resources are monitored and capacity is adjusted to current and expected demand.",
|
|
"link": "{{LINK:R10#ISO-KAPAZITAET}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "A.8.7-1",
|
|
"policy": "R10",
|
|
"control": "A.8.7",
|
|
"kind": "control",
|
|
"title": "Protection against malware",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.7-1",
|
|
"impl_anchor": "IMPL 5.2.3",
|
|
"requirement": "Protection against malware is implemented and supported by appropriate user awareness.",
|
|
"link": "{{LINK:R10#5.2.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "A.8.8-1",
|
|
"policy": "R10",
|
|
"control": "A.8.8",
|
|
"kind": "control",
|
|
"title": "Management of technical vulnerabilities",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.8-1",
|
|
"impl_anchor": "IMPL 5.2.5",
|
|
"requirement": "Information on technical vulnerabilities is obtained, exposure is evaluated and appropriate measures are taken.",
|
|
"link": "{{LINK:R10#5.2.5}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-06"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.9-1",
|
|
"policy": "R10",
|
|
"control": "A.8.9",
|
|
"kind": "control",
|
|
"title": "Configuration management",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.9-1",
|
|
"impl_anchor": "IMPL 5.2.1",
|
|
"requirement": "Configurations of hardware, software, services and networks are established, documented, implemented, monitored and reviewed.",
|
|
"link": "{{LINK:R10#5.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-04"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.10-1",
|
|
"policy": "R11",
|
|
"control": "A.8.10",
|
|
"kind": "control",
|
|
"title": "Information deletion",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.10-1",
|
|
"impl_anchor": "IMPL 5.3.3",
|
|
"requirement": "Information stored in systems and on media is deleted when no longer required.",
|
|
"link": "{{LINK:R11#5.3.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-08"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.11-1",
|
|
"policy": "R02",
|
|
"control": "A.8.11",
|
|
"kind": "control",
|
|
"title": "Data masking",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": "FLAG_PERSONAL_DATA",
|
|
"req_anchor": "REQ A.8.11-1",
|
|
"impl_anchor": "IMPL ISO-MASKIERUNG",
|
|
"requirement": "Data masking is applied in accordance with the access control and privacy requirements.",
|
|
"link": "{{LINK:R02#ISO-MASKIERUNG}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "A.8.12-1",
|
|
"policy": "R10",
|
|
"control": "A.8.12",
|
|
"kind": "control",
|
|
"title": "Data leakage prevention",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.12-1",
|
|
"impl_anchor": "IMPL ISO-DLP",
|
|
"requirement": "Measures to prevent data leakage are applied to systems, networks and devices that process sensitive information.",
|
|
"link": "{{LINK:R10#ISO-DLP}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "A.8.13-1",
|
|
"policy": "R10",
|
|
"control": "A.8.13",
|
|
"kind": "control",
|
|
"title": "Information backup",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.13-1",
|
|
"impl_anchor": "IMPL 5.2.9",
|
|
"requirement": "Backup copies of information, software and systems are created in accordance with the backup concept and tested regularly.",
|
|
"link": "{{LINK:R10#5.2.9}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-05"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.14-1",
|
|
"policy": "R04",
|
|
"control": "A.8.14",
|
|
"kind": "control",
|
|
"title": "Redundancy of information processing facilities",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.14-1",
|
|
"impl_anchor": "IMPL 5.2.8",
|
|
"requirement": "Information processing facilities are implemented with sufficient redundancy to meet the availability requirements.",
|
|
"link": "{{LINK:R04#5.2.8}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-02"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.15-1",
|
|
"policy": "R10",
|
|
"control": "A.8.15",
|
|
"kind": "control",
|
|
"title": "Logging",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.15-1",
|
|
"impl_anchor": "IMPL 5.2.4",
|
|
"requirement": "Logs of activities, exceptions, faults and events are produced, stored, protected and analysed.",
|
|
"link": "{{LINK:R10#5.2.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-13"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.16-1",
|
|
"policy": "R10",
|
|
"control": "A.8.16",
|
|
"kind": "control",
|
|
"title": "Monitoring activities",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.16-1",
|
|
"impl_anchor": "IMPL 5.2.4",
|
|
"requirement": "Networks, systems and applications are monitored for anomalous behaviour and potential incidents are evaluated.",
|
|
"link": "{{LINK:R10#5.2.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-13"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.17-1",
|
|
"policy": "R10",
|
|
"control": "A.8.17",
|
|
"kind": "control",
|
|
"title": "Clock synchronisation",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.17-1",
|
|
"impl_anchor": "IMPL ISO-ZEITSYNC",
|
|
"requirement": "System clocks are synchronised to approved time sources.",
|
|
"link": "{{LINK:R10#ISO-ZEITSYNC}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-13"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.18-1",
|
|
"policy": "R08",
|
|
"control": "A.8.18",
|
|
"kind": "control",
|
|
"title": "Use of privileged utility programs",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.18-1",
|
|
"impl_anchor": "IMPL 4.2.1",
|
|
"requirement": "The use of utility programs capable of overriding system and application controls is restricted and tightly controlled.",
|
|
"link": "{{LINK:R08#4.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-03"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.19-1",
|
|
"policy": "R02",
|
|
"control": "A.8.19",
|
|
"kind": "control",
|
|
"title": "Installation of software on operational systems",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.19-1",
|
|
"impl_anchor": "IMPL 1.3.4",
|
|
"requirement": "Procedures and measures for securely managing software installation on operational systems are implemented.",
|
|
"link": "{{LINK:R02#1.3.4}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-04"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.20-1",
|
|
"policy": "R10",
|
|
"control": "A.8.20",
|
|
"kind": "control",
|
|
"title": "Networks security",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.20-1",
|
|
"impl_anchor": "IMPL 5.2.7",
|
|
"requirement": "Networks and network devices are secured, managed and controlled to protect information.",
|
|
"link": "{{LINK:R10#5.2.7}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "A.8.21-1",
|
|
"policy": "R11",
|
|
"control": "A.8.21",
|
|
"kind": "control",
|
|
"title": "Security of network services",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.21-1",
|
|
"impl_anchor": "IMPL 5.3.2",
|
|
"requirement": "Security mechanisms, service levels and requirements for network services are identified, implemented and monitored.",
|
|
"link": "{{LINK:R11#5.3.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "A.8.22-1",
|
|
"policy": "R10",
|
|
"control": "A.8.22",
|
|
"kind": "control",
|
|
"title": "Segregation of networks",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.22-1",
|
|
"impl_anchor": "IMPL 5.2.7",
|
|
"requirement": "Groups of information services, users and systems are segregated in networks.",
|
|
"link": "{{LINK:R10#5.2.7}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "A.8.23-1",
|
|
"policy": "R10",
|
|
"control": "A.8.23",
|
|
"kind": "control",
|
|
"title": "Web filtering",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.23-1",
|
|
"impl_anchor": "IMPL 5.2.3",
|
|
"requirement": "Access to external websites is managed to reduce exposure to malicious content.",
|
|
"link": "{{LINK:R10#5.2.3}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": []
|
|
},
|
|
{
|
|
"id": "A.8.24-1",
|
|
"policy": "R09",
|
|
"control": "A.8.24",
|
|
"kind": "control",
|
|
"title": "Use of cryptography",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.24-1",
|
|
"impl_anchor": "IMPL 5.1.1",
|
|
"requirement": "Rules for the effective use of cryptography, including key management, are defined and implemented.",
|
|
"link": "{{LINK:R09#5.1.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-07"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.25-1",
|
|
"policy": "R11",
|
|
"control": "A.8.25",
|
|
"kind": "control",
|
|
"title": "Secure development life cycle",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": "FLAG_DEV_INHOUSE",
|
|
"req_anchor": "REQ A.8.25-1",
|
|
"impl_anchor": "IMPL 5.3.1",
|
|
"requirement": "Rules for a secure development life cycle of software and systems are established and applied.",
|
|
"link": "{{LINK:R11#5.3.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-16"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.26-1",
|
|
"policy": "R11",
|
|
"control": "A.8.26",
|
|
"kind": "control",
|
|
"title": "Application security requirements",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": "FLAG_DEV_INHOUSE",
|
|
"req_anchor": "REQ A.8.26-1",
|
|
"impl_anchor": "IMPL 5.3.1",
|
|
"requirement": "Information security requirements are identified, specified and taken into account when developing or acquiring applications.",
|
|
"link": "{{LINK:R11#5.3.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-16"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.27-1",
|
|
"policy": "R11",
|
|
"control": "A.8.27",
|
|
"kind": "control",
|
|
"title": "Secure system architecture and engineering principles",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": "FLAG_DEV_INHOUSE",
|
|
"req_anchor": "REQ A.8.27-1",
|
|
"impl_anchor": "IMPL 5.3.1",
|
|
"requirement": "Principles for engineering secure systems are established, documented and applied.",
|
|
"link": "{{LINK:R11#5.3.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-16"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.28-1",
|
|
"policy": "R11",
|
|
"control": "A.8.28",
|
|
"kind": "control",
|
|
"title": "Secure coding",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": "FLAG_DEV_INHOUSE",
|
|
"req_anchor": "REQ A.8.28-1",
|
|
"impl_anchor": "IMPL 5.3.1",
|
|
"requirement": "Secure coding principles are applied to software development.",
|
|
"link": "{{LINK:R11#5.3.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-16"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.29-1",
|
|
"policy": "R11",
|
|
"control": "A.8.29",
|
|
"kind": "control",
|
|
"title": "Security testing in development and acceptance",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": "FLAG_DEV_INHOUSE",
|
|
"req_anchor": "REQ A.8.29-1",
|
|
"impl_anchor": "IMPL 5.3.1",
|
|
"requirement": "Security testing is integrated into the development and acceptance process.",
|
|
"link": "{{LINK:R11#5.3.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-16"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.30-1",
|
|
"policy": "R11",
|
|
"control": "A.8.30",
|
|
"kind": "control",
|
|
"title": "Outsourced development",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": "FLAG_DEV_INHOUSE",
|
|
"req_anchor": "REQ A.8.30-1",
|
|
"impl_anchor": "IMPL 5.3.1",
|
|
"requirement": "Outsourced system development is directed, monitored and reviewed.",
|
|
"link": "{{LINK:R11#5.3.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-16"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.31-1",
|
|
"policy": "R10",
|
|
"control": "A.8.31",
|
|
"kind": "control",
|
|
"title": "Separation of development, test and production environments",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": "FLAG_DEV_INHOUSE",
|
|
"req_anchor": "REQ A.8.31-1",
|
|
"impl_anchor": "IMPL 5.2.2",
|
|
"requirement": "Development, test and production environments are separated and protected.",
|
|
"link": "{{LINK:R10#5.2.2}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-16"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.32-1",
|
|
"policy": "R10",
|
|
"control": "A.8.32",
|
|
"kind": "control",
|
|
"title": "Change management",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.32-1",
|
|
"impl_anchor": "IMPL 5.2.1",
|
|
"requirement": "Changes to information processing facilities and systems are subject to change management.",
|
|
"link": "{{LINK:R10#5.2.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-04"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.33-1",
|
|
"policy": "R11",
|
|
"control": "A.8.33",
|
|
"kind": "control",
|
|
"title": "Test information",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": "FLAG_DEV_INHOUSE",
|
|
"req_anchor": "REQ A.8.33-1",
|
|
"impl_anchor": "IMPL 5.3.1",
|
|
"requirement": "Test information is selected, protected and managed with care.",
|
|
"link": "{{LINK:R11#5.3.1}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-16"
|
|
]
|
|
},
|
|
{
|
|
"id": "A.8.34-1",
|
|
"policy": "R10",
|
|
"control": "A.8.34",
|
|
"kind": "control",
|
|
"title": "Protection of information systems during audit testing",
|
|
"type": "MUSS",
|
|
"soa_relevant": true,
|
|
"applicable": true,
|
|
"condition": null,
|
|
"req_anchor": "REQ A.8.34-1",
|
|
"impl_anchor": "IMPL 5.2.6",
|
|
"requirement": "Audit tests and similar activities on operational systems are planned and agreed to avoid disruption.",
|
|
"link": "{{LINK:R10#5.2.6}}",
|
|
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
|
|
"verfahren": [
|
|
"VA-15"
|
|
]
|
|
}
|
|
]
|
|
}
|